All episodes

David McGuire, Director of Security at QEP Resources

Apple Podcasts Spotify SoundCloud

In this episode:

David McGuire, Director of Security at QEP Resources is our feature interview this week. News from: Amazon, Crocs, Red Canary, PasswordPing, Convercent, Intelisecure, Coalfire, Optiv, ThreatX and a lot more!

Crocs CFO croaks

I would never have written that if he actually died, what kind of monster do you think I am?... She's just resigning effective 4/1/19. But you've gotta admit that's a strong tabloid headline. Also... Denver is growing (did you already know that?). Amazon keeps teasing us. Red Canary signs on a new EDR technology. PasswordPing hires a new CEO. Convercent gives us the low-down on GDPR's impacts thus far. Intelisecure, Coalfire, Optiv and ThreatX wow us with their blog posts. 

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

Local security news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11611 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 79, the week of August 13th. Alex, happy Sunday.

Happy Sunday, Robb. You made it back from Vegas. I have a little bit of a post-con, uh, cough sickness going on. The con flu, I think, is what they call it. I don't know.

I, I felt great when I was out there and get home and not so great. Yeah, that's the way it goes, you know. It's a giant cesspool out there. I am super excited to record this podcast though. Oh yeah?

Yeah, we got some exciting stuff. We got a lot of good news. We have a great feature interview this week, but first there's some housekeeping. There is. We have a Slack channel, in case you haven't heard.

Great discussion going on on the Slack channel. You should make sure to come and join. Actually, you shouldn't join. There's too many people there now. We don't need you.

That's right. We're well over 500 people at this point. We also have a mailing list, so if you want to get the show notes delivered to your email box every week, sign up to that. You can rate us out on iTunes. Let us know if you like it.

We'd love it if you give us a 5-star. If you have any comments, let us know those as well. And we do also have a Patreon. This is an opportunity for you to help us support the show, help pay the costs of those crazy things that we have to do here to keep the stuff running. We, we do have our commitment to you that none of this goes into our pockets.

It goes right back out to the show and to the community. Speaking of Patreons, we mentioned last week we had a new sponsor, John Hubbard, and John wanted to give a shout out to his employer, Survey Gizmos. They are the, the ones who are actually paying for this Patreon. Yeah, so Survey Gizmo based here. Seems like they are SurveyMonkey-ish.

Yeah. Good stuff. Yep. Thanks a lot to, to them for their support. We appreciate it.

And if you need a survey tool, take a look at Survey Gizmo. First story we have, Colorado is the 2nd highest state for identity theft in the country. So this is interesting. There's a few different ways that they looked at this, you know, per capita, how many people get impacted, how much are you impacted when you are. But anyway, they kind of average it all together and said, you know, number Colorado is number 2 in terms of the most impacted by identity theft.

In Colorado, victims lost an average of $4,480 when they, when they were impacted by this. There are other worst states— Maryland, California, and New York. But also, if you don't want to have your identity stolen, you should live in South Dakota, Indiana, Maine, or Rhode Island. So the very worst was Nevada. They were up at 5,900 per person impacted.

Colorado was second. And then, like you said, Maryland, California, and New York. So, yeah, we have some bad places to live from an identity theft perspective. And apparently maybe people want to steal our identity because they want to live here. Could be.

Is that what's going on here? Could be. It doesn't make sense if Nevada is number one, though. That's right. No one wants to live there.

Next on the list, Denver is a bigger boomtown than Seattle or Dallas. So this is, you know, kind of similar to other lists we've seen. They take a bunch of factors together and say which state comes out at the top. For this, it's population and housing. So the total population and number of housing units, the workforce and earnings, the— they look at this growth, business growth.

Yep. And then paid employees per day period and total receipts for non-employers. So a bunch of different financial measures. Right. And of course, the number one boomtown Yeah, is our arch nemesis Austin, Texas.

Yeah, the rest of the list is a little bit less, uh, forecastable, right? Austin is number 1, but number 2 is Provo, Utah, Raleigh, North Carolina, Charleston, South Carolina, Nashville, Tennessee, and then Denver. Yeah, I know that there is a lot of stuff going on in Nashville too, so that one's not super surprising. Uh, we did beat both Seattle and Dallas on the list, so take that. Yeah, we're better.

Yeah. Uh, Speaking of Denver being awesome, we have another story here about downtown becoming Denver's new tech hub. So this actually really surprised me. Not that downtown was the tech hub that I've seen, you know, we've seen happening over the last decade, but the way that they divide it, they're basically saying that LoDo is not downtown. LoDo is a different section, and LoDo is becoming less the tech hub, and it's the kind of the traditional part of downtown where the big high-rises that were built back in the '70s are.

Yeah, you know, for a while you had tech companies and other startups that would be in the old lofts, you know, small offices there. And now it seems that folks are moving back towards those, those taller buildings, getting spaces in those areas. Yeah, when I first read it, I was thinking they meant, oh, people are, you know, not in the tech center or they're not in Boulder, but they really meant they're not in those other peripheral downtown areas as well. So they give some examples of companies that moved down there. I'd say that the most interesting thing out of here to me was that they say that the analysis says that our tech talent here in Denver is at about 100,000 people, 100,000 people, which is about 6.2% of the total workforce.

And that's up over 23% from 2012. So big growth in tech here in town. Yeah, definitely. Next, Amazon could release another list of their potential HQ2 cities here shortly. So this is narrowing down that initial list the initial shortlist that they had.

I don't know, it's probably been a few months now, 6, 8 months ago. So the interesting thing out of here to me wasn't so much that they're going to maybe have another list. It's, it's this comment that came in the middle of the article about Jeff Bezos. Apparently, one of the insiders who had been working on this project said that Bezos is incentive obsessed, and that his whole team is charged with getting the largest pound of flesh possible out of every jurisdiction they're in. It's about money and about the spreadsheet.

But it's about— it's also about wanting to— about being wanted. And this gesture he expects from the governments where he's blessing with the highways jobs. Yeah. You know, I don't know if that is a little bit cynical by the person who was in the place that did not get to the shortlist. But I could also see where, hey, we've got all this power and we want to go somewhere.

Let's get the— use the most of our power to get all these incentives. Yeah, I mean, this whole process is— I'm definitely become a lot more down about the whole possibility of them coming here and what's the impact going to look like and how long would it take us to figure out how to do it the right way? I'm not so sure it'd be a great thing for us if they did come to Denver. It reminds me of an episode on Silicon Valley last year where Gavin Belson, the fake CEO of their fake Google company, essentially bankrupted an entire town because they wanted to bring a a production facility there. And they made them give all these concessions and essentially wiped out the entire town and then, and then decided that they didn't want to do the manufacturing and left.

Oh, so anyway, fun stuff. Hopefully we don't see that. Hopefully we don't see that. Next, Crocs reported they are closing their manufacturing facilities and their CFO is resigning. This is not quite as bad as it sounds on the surface with that headline.

It's still not good. Well, the first thing you hear when you hear this is it sounds to me as an outsider that like they're going out of business, but that's certainly not what's happening. Most shoe companies, um, don't do their own manufacturing, and, and Crocs had been one that was doing their own, and, and now they're not, right? They're just outsourcing it, having external manufacturers do the manufacturing for them. So as I've learned a little bit more about this and reading and understanding, really the CFO leaving is probably the bigger piece of news here than the manufacturing going away.

Yeah. They also did note in there that they've been closing a number of their company-owned stores as well, which I also think is more concerning than the fact that they're not doing their own manufacturing. So last March they said that they were going to go— they were going to close 160 of the 558 retail stores they had. They're going to do that by the end of this year. So it looks like right now they're about 400.

So they're— they are on track for what they said they were going to do. Um, that I guess maybe some good news that the CFO who's leaving, um, Carrie Tufner, uh, she's not resigning until April 1st. So not, not for another 6 months or so. Um, she's gonna be replaced by Anne Mellman, who's coming from Zappos where she was the CFO. Uh, and apparently before Zappos, she was work— she already worked at Crocs.

Yeah. So that is a positive sign. Um, Zappos seems to do very well. So hopefully they can help things for Crocs. Yep.

Moving over to security news here in town, Red Canary and Endgame have announced a partnership. So Red Canary is the local managed EDR company here in town, and previous to this they supported Carbon Black. Last year they brought on CrowdStrike, and now they brought on a 3rd EDR solution. So they, they build their telemetry and their whole operational model on top of this underlying technology and you know, Endgame gives them some new functionality. Yeah, I think it's pretty cool.

Their whole model is they just need the data. They don't really care how they get the data. And, you know, as they bring on these other partners to be able to get that endpoint data, it makes them a more powerful solution. And I think it's good stuff. Yeah.

Next, there's a new cybersecurity startup that just hired a chief executive, PasswordPing. Uh, which is a Boulder-based startup that they screen online accounts for compromised credentials, hired Michael Green as CEO. So he was previously CEO at a company called ID Watchdog, which was sold to Equifax. I believe that's their identity theft protection service now. Sure.

And, and so they, uh, they moved their previous CEO, Michael Wilson, over to being the CTO. So, you know, scaling up and bringing in a more experienced leader makes sense and kind of what you expect to see as a company starts to grow. Uh, it's interesting to see that there is enough of a market in compromised credentials that you can have an entire startup based just on that. Well, you'd— I would expect that they're, you know, intending to get bought up by somebody to bundle that into their product. Could be.

Um, Conversant has a series of blog posts, 4 different blog posts that are all about lessons learned from GDPR. So I'm not planning to go through all these right here on the podcast, But I do think if you are someone who kind of wants to figure out what has GDPR actually done now that it's in place, and how do I need to be thinking about it, I was waiting to see it in place, but now this is a good time to take a look at what they did, and read it from a compliance perspective. They talk, you know, they're mostly focused on kind of risk from an employee type of a perspective, but it really ties in closely with what we do in security and IT. Yeah, there were some good articles there. Uh, InteliSecure also had a blog on the proper, proper role of cyber insurance in enterprise risk management.

Um, I'll give a really quick summary for you here. Uh, you should do security controls and cyber insurance, not security controls or cyber insurance. Yeah. And I think that the gist of it was they pulled out a stat from the AT&T 2017 Global State of Cybersecurity survey where 20%, 28% of respondents saw cyber insurance as a replacement for defenses. Right.

Yeah. So you don't want to do that. You don't want to— but if there's one single person listening who's like, really, I shouldn't stop doing security because I got insurance, I'm glad you heard this. Now you should still try and protect yourself and have insurance for the instances where you can't. Right.

Fair enough. All right. Next, we have a blog post from Coalfire, which is really just them looking, doing some analysis of a recent Gartner report. It's the hype cycle for risk management in 2018. It's a pretty interesting chart here.

I think you might want to click on this link and look at what they're looking at. Basically, they show which different technologies are in what stage of their hype cycle. Coming up, people are starting to hear about them. They're at that peak of inflated expectations, down into the trough of disillusionment, the slope of enlightenment, and then the plateau of productivity. Other than the cheesy marketing parts that Gartner does with this, I think that the hype cycle is actually one of the more useful things that they do.

Um, if you sort of look historically at these, and they have them for different market segments, you can see, uh, where you remember like 2 years ago, you know, such and such technology, you know, artificial intelligence or whatever it is, you could have seen it at the top of that hype cycle. And then, you know, several years, uh, later on, you can see where, oh, hey, look, it's actually gotten to a place where it's actually useful now. It's not just people saying, oh, it's going to solve all our problems. I will point out that Blockchain for data security is in the innovation trigger. Apparently, that means that people are get really getting really excited about it and working on it right now.

And Sim is is not in the trough of disillusionment, which is what I might have guessed. They are in the slope of enlightenment. Huh. So they've gone through disillusionment, and now they're coming out the other end. Now they're figuring out how to get better.

So that's awesome. That is good. Good stuff. Next, Optiv had a blog. About some new services that they announced, basically using some of their services to help companies see how they are seen by attackers.

That's kind of a good idea, right? Yeah. You want to think about how you're— how the bad guys are targeting you and, and what, what they might be trying to do. It's an interesting spin on things for sure. And then our final story this week is another blog post by ThreatX, and this is Using Android Proxy Browsers: Convenience Without Web Application Security.

Alex, what's this all about? So, uh, basically there's a lot of older Android devices out there. There are a number of applications that are out there that do proxies to help you, uh, do things faster. Essentially that, that, uh, the capacity will be taken up on the proxy side as opposed to on your, your old phone that can't do that anymore. Uh, the bottom line is that you need to be careful because you don't know what these proxy services are really doing.

You may be sacrificing some of your privacy and security for speed. And they're probably selling your, your data to the bad guys, right? Or good guys, or just, you know, using it outright. They're maybe not even selling it. Awesome.

Well, that's it for news. Jumping over to the Slack message of the week first. Thanks so much to Andre Gaeta who sponsors this for us every week. Andre, we do appreciate your ongoing support for this. Um, Slack message of the week this week is going to go to Colin Grady.

Colin, we, uh, we just want to give you a shout out this week specifically. We're going to recognize your post about the DENSEC meeting next Wednesday. But really, I just want to acknowledge, you know, the work you do to keep that group going all on your own. And we certainly appreciate that opportunity for folks to socialize and, and the work you do and keeping it going. And you can congratulate him as well this week at the DENSEC meeting.

So go show up and have a beer and socialize with other security people at the Wine Coop on Wednesday. Exactly. Yeah. Speaking of things happening, what we have an event calendar on our website. Colorado-security.com.

You can go out there and you can see a list of all of the things going on through the end of the year. I would also like to mention that we have entered into a little bit of a sponsorship. So this is not something that we have done previously before, but we are a sponsor of the Ballard Spahr Colorado Cybersecurity Summit. Yeah, we had, we had Ballard Spahr on the podcast a while back and we've appreciated what they're doing around security and they reached out to us to get us involved with their summit and we said, yeah, let's do it. Let's see if we can help it out.

Yeah. So we're going to help promote that. And we think you guys should all come out and hang out at the summit. When is that, Alex? So that summit is on the, I believe, the 18th of September.

So it's a morning event, half-day event at the Ballard Spar offices. And we'll have more information about what the tracks look like as we get more information. Exactly. All right. Do you want to go ahead and jump into next events?

First event, SecureSet is doing their career conversations with Reuben Booker on the 14th. On the 14th and 15th, ISSA Denver has their August chapter meetings. As a reminder, Wednesday the— or excuse me, Tuesday the 14th, it'll be up in Boulder at lunchtime, and it'll be downtown Denver for the evening meeting. And then Wednesday lunch will be in the DTC. And as previously mentioned, DenSec is doing their monthly meetup on the 15th at WinCoop.

Also on the 15th, the Colorado Technology Association is doing their General Assembly at RiNo Industry Station, uh, the 15th. Uh, SecureSet on the 16th is doing an expert series with Cody Cornell, CEO of Swimlane. On the 21st, ISSA Denver has their Women in Security group meeting. This is going to be yet another chance to get together with a lot of women in the area and, and really help each other network and get better. On the 22nd, ISSA Colorado Springs is having one of their big events, the Cybersecurity Training and Technology Forum.

So that's down there in the Springs. Yeah, so this is the big conference of the year in Colorado Springs, you know, like our Rocky Mountain Information Security Conference is in Denver. This is to the Springs. And hopefully, if you're down there or you're just looking for a good full day's training, you might want to drive down there and go through this for, you know, next week for sure. SecureSet is doing another Career Conversations with Scott Bowman.

And Alex Reed on the 22nd of August. Yeah, and I believe that, uh, Scott is with SecureSet and Alex is a former— he's a graduate. Yeah. And then on the 23rd, ISSA Denver is doing one of their monthly happy hours. All right, let's go ahead and jump over to jobs.

Uh, we have some interesting jobs this week, not a lot of the normal, you know, security analyst stuff. Starting off, we do have a position at TeleTech that's focused on cybersecurity principal engineer and GRC span— uh, specialist. Nice. Uh, FINRA is looking for an examiner in their member regulation sales practice. Yeah, this is interesting to me.

It, it, as I was looking through it, this is really going out and do— and running examinations, um, of financial organizations. So if you've worked in financial services and you want to, you know, kind of help make things better, this might be a good opportunity for you. Uh, Coalfire is hiring a penetration tester consultant. CBIZ is looking for a risk and advisory services senior IT audit associate. So I didn't know who CBIZ was.

I don't know if that's COBIZ or what. I looked it up and it's a— they deliver top-level financial and benefits and insurance services to organizations of all sizes. Wow. Yeah, there you go. You don't want to deliver bottom level, so that's good.

Well, that, that is better. Yeah. Uh, Proofpoint is hiring a web security solutions architect focused on the West. Webroot is looking for a field marketing program manager. ThreatX is hiring an account manager.

If you want to go sell ThreatX, there's your chance. Carbon Black is looking for a competitive research analysis. Sounds like a fun job. That does sound like a fun job. Learn about all the other competitors and how they all stack up, and I assume figure out how Carbon Black is better than all of them and write that down in a persuasive way, right?

Exactly. And then finally, Water for People, which is a nonprofit focused on getting water to people, is looking for a director of technology. I like when I have water. So it's good when you get water to people. It especially sucks for people who don't have water.

Yes, a lot. So this, this could be a good thing. So that's it for the news this week. We do have a feature interview with Dave McGuire, who's actually taken your place over at QEP Resources. Yeah, he has some pretty choice things to say about what you left him, Alex.

You know what? I think I'll have to listen to the episode. All right. Well, that's it. We'll talk to you guys next week.

Thanks, Robb. Hi, this is Chad Payne, Executive Director of IT Operations for Kraken Sports and Entertainment. Welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals. This is the Colorado Equals Security feature interview. When you think of Denver, if you— especially if you think 15, 20 years ago and you talk about what are the big industries in Denver, the, the number one industry has always been oil and gas, right?

We— I'd say over the last 20 years, we've had telecommunications has come up and been real high along with it, but oil and gas. And frankly, somehow we haven't had an oil and gas security leader on this show yet, and I'm really excited today to introduce David McGuire, who runs security over at QEP Resources. David, before I start to talk about running security there at QEP and how you got to to a place where you're doing that. I first want to ask about one of your other passions, and it sounds like, you know, more than— gosh, more than 30 years worth of experience now in martial arts. So talk to us about the martial art that you study and a little more detail about that.

Sure, sure. So yeah, I started a style of Southern Chinese kung fu on the East Coast in Virginia when I was 14 years old back in 1982. So what's it called? Shuilong Pai is the name of the system. Shuilong Pai.

It is a small family-based system. It's an eclectic blend primarily founded in one of the original 5 Chinese styles called Li Ka, or Li family. And so being southern Chinese, its hallmarks are shorter movements, closer stances, not a lot of high sweeping wide-ranging kicks. Those were hallmarks of northern kung fu in China, which was all just a source of geography. Congested cities in the south, tighter close-in movements.

Wide open fields in the north, wide open kicks and movements. So is it mostly striking from what I hear you saying? Kicking and punching? It's a traditional striking art. It's not a grappling art.

Yeah. A lot of it has what we call in Chinese qinna moves, which are grappling moves or joint locks. But not to the point of current MMA, you know, choke them out, take them to the mat sort of thing. It was definitely much more striking art. Yeah, more traditional.

Mostly kicking? No, mostly hand movements with kicking. So always in combination. And so the thing people don't recognize about martial arts when they put their kids into a karate school or something, real martial arts was about real fighting. Not tournaments, not, you know, getting physically fit, not improving your self-esteem, but about trying to defend yourself for real.

And so the system I studied was definitely a traditional— it's, you know, street-worthy combat readiness or training. So, but what most people don't realize about martial arts is the martial arts were designed to give a smaller, weaker person an advantage over a larger, stronger person in a fight. And when you approach it that way, the material has to come together and work together. So it's not, do you kick or do you strike? It's, um, how do you set them up, probably with your hands, so that that kick really does damage?

Um, you never want it to be just the pace away. You want to set a base and actually make them absorb the impact. That's interesting. You know, you talked about— I think you said streetworthy might have been the phrase you used. Yep.

My family has been doing taekwondo for the last few years, and it does not seem in any way streetworthy to me. I'm relatively confident that those black belts in there aren't actually learning how to fight, right? They're learning the other things you talked about— fitness and self-control and discipline. And there's all kinds of fantastic advantages to doing it. But it doesn't feel to me like self-defense is very high on that list of goals.

True. Most of the underbelts, and you know, in the old world they didn't even have underbelts. You were given a white belt. When you did enough work that it was black, you were deemed an instructor. But you know, in the modern world everyone needs a short-term goal.

So you know, in the United States we introduced color belt ranks, both kung fu, karate, for jiu-jitsu. So that doesn't exist back in China, the belting? It does today in the modern world. It didn't originally. There was no such concept.

Again, it was just passing along the family style so that you could defend yourself for real. And so Taekwondo is primarily a kicking art. If you go to mainland China today, the official sanctioned martial art is called Wushu. Wushu is not a combat art. China watered that down.

They had multiple rebellions, you know, hundreds and thousands of years ago by martial artists who knew how to really fight the emperor's troops. So, the modern communist regime's like, no, no, we don't need everyone being that capable. So, Wushu is much more gymnastics, much more performance. So, tournament performance. And, you know, even in the United States today, when you go to martial arts tournaments, it's called point fighting, and you're not allowed to actually strike the other person.

You come within an inch or so and you get your point. If you actually hit them, you get penalized because we don't want any injuries. There should be no contact. We've got insurance liability. Which martial art is that that has no striking?

Well, in tournament fighting, there's no actual impact allowed because of liability. For which martial art tournament? All martial art tournaments today. So the Karate Kid was wrong? They're not actually kicking each other?

Not anymore. They used to. All right. You know, back in the '80s and '90s when I was a student, you went to a tournament, you're gonna get your clock cleaned. And in a sparring tournament, you're gonna get hit and you're gonna get hit hard unless you were able to defend yourself.

Today, primarily because of insurance liability, they don't want impact. If there's any impact, it's a bad thing. They'll allow some impact at black belt levels, but underneath that No, it's a bad thing today. So, so what belt are you? So does it work that way with degrees of black?

So, uh, for the comparison, um, most karate systems, um, Japanese karate, have 10 dans of black. My system, family style of kung fu, has 5 levels compared to 10, and I'm a 3rd degree black. Okay. Um, my instructor's a 4th degree, his instructor's a 5th degree. Yeah.

And under my instructor, he's been been teaching since '76. I'm the only one who ever made it to 3rd level. So are you basically like tapped out? You can't go any higher because your instructor is only a 4? No, I— if he decided that I should go to 4, yeah, he would bring in his instructor who, um, would promote me to the next level.

Generally speaking, that's how someone in the upper black levels gets promoted to their next level. If you have enough experience to bring someone up to where you're at, you get the next step. So generally my instructor would get his 5th if I were to go to 4th. Gotcha. Well, that's very interesting and probably time for us to move on to something a little more security-focused.

Of course. Thanks for the background. So I do want to hear how you got into security, how you became the head of security for one of the larger oil and gas companies here in town. Sure. But first, back me up back to, you know, when you're coming right out of school, we were talking offline about how you became the computer guy in your family.

How is that? How did you, out of the 6 of your siblings, become the one who was going to be the computer one? So, function of timing, right? I'm the youngest of 6 children, and I graduated high school in 1985. So in the early '80s, when I was in school, we finally had TRS-80 machines.

The Commodore 64 was out for home. We actually had computers we could lay our hands on when I was still in school. None of my brothers and sisters had that advantage. There was no such thing. They had a typewriter at home.

So by virtue of timing, in the early '80s, I got introduced to computers while I was in school, decided to go into IT back then, data processing, then MIS, today IT. And so I became the computer guy. When I left high school in '85, I started working for Coca-Cola Consolidated. At the time, Coke had one of the first IBM PCs, and it was a dual floppy IBM PC. And then they got in the next generation IBM PC XT that had a 10 megabyte hard drive.

Instead of just 5¼ floppies. So professionally from there forward, I worked in IT at Koch for the next 5 years. Why were you able to get the IT job if you— I mean, there's no training, right? Yeah, so in high school I actually went to— my junior and senior year I went to a vocational school for the data processing program. And so we worked on TRS-80s, Northstar Microsystems, and so I had a little bit more computer savvy than most coming out of high school in '85, and they actually helped place me coming out of that vocational school.

That's awesome. That's a neat program. Half of my day in high school was the vocational school. Yeah, okay. So you worked at Koch as IT desktop support?

I guess there was no desktop support because they didn't all have desktops. Yeah, titles were very different back then. So I think my first title was PC clerk. Eventually computer operator. What did that mean you did?

What was your day-to-day? So my day-to-day was a bit of data entry on the PCs. They had a data entry department. I wasn't in data entry, but on the PCs we had small emerging programs and they had one individual that was, I think his title was PC programmer, and I technically worked for him. And so I was basically his gopher.

Anything he needed, I did. And so at the time Coca-Cola Consolidated was doing something they called the Keystone Survey Program. So they were trying to do market research across their retail footprint and it all came back on paper. I typed it into a PC-based database. I did— I created forms in WordPerfect.

I worked in version 2 of Lotus 1-2-3. Those were my day-to-day functions until I got into computer operations on the IBM System/36. Yeah, okay. So you were at Koch for— how long were you there? I was at Koch for 5 years.

Mostly, I mean, I was the PC clerk maybe for a year. Went into computer operations on the IBM System/36. We kind of had a large region. We had 14 branch locations across Virginia, West Virginia that reported to our division. Divisional office.

Then Koch made one of those great corporate maneuvers called centralization. They decided to centralize all the regional computer ops departments back to the headquarters in Charlotte. I, at that point, became a field support specialist, eventually field support supervisor and manager, managing all of the satellite communications, the route sales equipment, handhelds were a NORAD system back at the time. Route sales guys had a handheld computer terminal and printer in their truck. So they would go to Acme convenience store, drop off X cases, print out the invoice, all that right there in their truck.

And that's how we were doing automation at Coke in the mid to late '80s. That's pretty cool. So it was fun. It was a good time in technology back then. Very important question.

If you had walked in with a Pepsi can, what would have happened? You know, back then it was a little less politically correct. There actually was a person who showed up at an extracurricular ball game wearing Pepsi who was fired. They fired the person for wearing Pepsi? They fired him for wearing it at a public forum because it was the exact competition and he was a representative of Coca-Cola.

Interesting. Back then they could do that. Yeah, so not a lot of love lost there, huh? No. The nice thing about Coke was, you know, we— I think if I remember correctly, we had a nickel Coke machine in the break room.

Yeah. So, you know, I drank a 6-pack of Coke a shift for years and years. And you're still alive to talk about it. Oh, absolutely. It fueled me well, created my digestive system.

All right, let's move on. Move along. What did you do next?

I don't want to run us out of time. Maybe walk me through how you got into security. Yeah, absolutely. I went into IT primarily because it wasn't industry-specific, so I worked across industries. After Coca-Cola and leveraging that experience, I worked for a subsidiary, Campbell Soup, for a little while.

I went to a municipal gas company. I went to a life insurance company. All in technology. That brings us up to the mid-'90s when this thing called the internet caught traction. Sure.

And every company wanted a website to represent their company. Everybody wanted to get connected to the internet in the late '90s. And so I did the web pages for Roanoke Gas Company, the first one for Shenandoah Life Insurance Company.

And connecting to the internet brought me into the realm of security from an access control perspective initially. At the life insurance company, we didn't have an employee workforce of agents selling insurance. Insurance is generally sold through third-party agencies, so they're not employees. They don't have credentials into your stuff, but they need access to sell and work your policies. In the late '90s, we created an extranet for this captive agent workforce, and there was a lot of security wrapped around that from an access control perspective.

They needed to see their policies, not the next agency's or not the employees'.

It was all internet-based. It's pretty high-tech stuff to do in the '90s. It was. It was the star of the annual stockholders meeting that year was when we unveiled— it was called StarNet. This Agent Extranet to give them real timely, fully current information without them doing 14 phone calls over 2 weeks to get paperwork filed.

This is the life insurance company? This was a life insurance company. That's pretty neat. That really made me step into security in a more meaningful way.

Back then, we built that platform in Lotus Notes, probably not the most popular platform these days, but back in the late '90s, it was a good alternatives. You can do everything in Lotus Notes. Absolutely. Once I got my foot into security there, then I was looking for a full-time role in security. At that point, I relocated to Colorado, entered the high-tech space, my grand startup story.

Worked up in Boulder for a couple of years with a startup firm up there. When you came to Colorado, your first gig was working for a startup in Boulder, is that right? They were an established company, but they were bolting on as a startup a whole different strategic initiative, a whole new division that was going to be grown from the ground up. Multiple data centers, we were going to build a nationwide distributed network to reduce the cost of bandwidth. It was a great concept.

Again, this is the dot-com era, so while we were building it, things changed. Like '98, '99, 2000? This is early 2000. Early 2000 into 2001. So by the time we moved into 2001 and we hadn't launched yet, the bubble burst.

We missed the window. It all collapsed, but I was the full-time head of security engineering there. So when we built the team up there, we had database engineering, system engineering, network engineering, and security engineering. I had my own team of engineers. We did build everything out.

We had a data center in Boulder, a redundant data center in Toronto, We had the nationwide network distributed across multiple ISPs that blanketed the country. Everything locked down, secured, monitored. We built a really nice thing that never saw a real paying customer.

How disappointing is that though? That happens in this space. A lot of CISOs I've worked with over the years since, you spend years with a lot of blood, sweat, and tears investing, building things for companies that often don't even exist 3 to 5 years later because they've either been deprecated, upgraded, the company's merged, or the company's gone away. That's not right or wrong. It's not good or bad.

It just is. We spend a lot of hours and a lot of our passion executing things that have a short shelf life sometimes. Or in this case, no shelf life. Sometimes no shelf life. But the experience gained by everyone who built all that, it launched careers.

We did some great, great stuff. So you were there for how long? Were you there before you ended up getting laid off because of the downturn? So I actually left one week in front of the first layoff because being an open-minded individual, I kind of saw it coming and found the next hop because I knew it was coming. And so everyone thought I, as the head of security, had inside knowledge because I left one week to the day before the first layoff.

It was incredible timing. But that opportunity of building all that ran just under 2 years. So we built it all out and again, no revenue at that point. But we went through a couple hundred million dollars of private equity funds that never saw any revenue. So what was next?

So after that high-tech, I went into consulting. Went to work for a consulting company. They're still around now, but in a different permutation here in Denver. They are 5280 Solutions, had just spun out of Unipac back in 2001. Anyhow, they had a contract opportunity at the Department of Energy for a senior security analyst.

So I went over to the Department of Energy for a year, year and a half. Department of Energy at the time had a cybersecurity manager as a one-man functional department. They had multiple federal audits that they had never responded to, that they were required to respond to, that they couldn't get to. And so I came in to do some heavy lifting and help them out. It's always interesting when you walk into the federal space and it's like, we need you to respond to this audit, and you crack open the covers and it's like, this audit was done 24 months ago.

Is any of this even still relevant? You want me to reply to this on a detailed transactional bullet point observations? You deprecated this easily 12 or 18 months ago, probably twice. But that's the Federal Circle. You got to do a lot of paperwork, so we did the paperwork.

The interesting thing at the Department of Energy is I was there, for those who go back that far, when the Nimda worm came through. NIMDA at the Department of Energy was a very interesting experience. I had written their incident response plan for them, and that was the first time we got to actually execute it as a team. For those playing along at home, NIMDA is admin spelled backwards. Those of you who were sysadmins in the early 2000s will remember it very well.

Absolutely. It was a multi-vector propagating worm that It was revolutionary for its time because of how many different ways it could propagate across your environment. Getting your arms around what was actually happening and how many ways it was happening was an interesting exercise. It was a 48 to 72-hour CCERT case for us to truly establish, get contained, and know with a lot of certainty what was going on because even at the time, the AV vendors and the malware vendors were struggling to figure that out themselves. Themselves, so in real time you didn't have a lot to pull from from the community.

But a little easier these days. There's a lot more analysis that comes a lot faster. There's a whole lot more threats now too, though. Absolutely. After the Department of Energy, I became the CISO for a financial services firm in Golden.

At the time I joined them, they were called ProCard, but ProCard was a small shop that had been acquired by a large card player out of Georgia called Total Systems, usually referred to as Tesis. Tesis did eventually rebrand us as Tesis iSolutions and combined us with several other subsidiaries. Tesis was a global firm that did business in a lot of different countries, but they also— the claim to fame I share with people when I talk about the days at Tesis is Tesis ran Verified by Visa. So everyone understood that when they took their Visa card in, and the transaction had to come back approved. That was running on a pair of mainframes at a data center that I'd walked through in southern Georgia at Total Systems.

Blacked-out data center rooms, high security. You're talking millions of dollars a second flowed through those mainframes. Wow. And any downtime was millions of dollars and millions of dollars. I bet.

So it was a great time. This is I was the CISO during the time that Visa was pushing their CISP program, Cardholder Information Security Program. MasterCard had their STP program. American Express had their own. Discover had their own.

Everyone today would recognize those card associations came together and created PCI. So this was the pre-days of PCI before they all came together. They were all doing their own. Visa was probably pushing it the hardest. And it was an interesting time as a small backend credit card transaction processor because Visa wasn't a regulatory authority.

They couldn't impose this on you. Their power was contractual. And so when they first started to propagate the card program, they did what you and I would do in our companies today. They did a risk assessment. And based on that risk assessment, they said we should place this on the card processors first because they have more data than most people.

And so they came on to us and said, you will comply. And we said, why will we comply?

Because if you don't, we're going to pull your authorization to process card transactions that bear the logo Visa. It's like you're flirting with anti-competitive behavior. So this morphed very quickly from a technology discussion into a business discussion. After the paperwork came across my desk as the CISO, I went straight to the head of biz dev and the general counsel who was negotiating the contract with Visa and said, do not ignore this provision. This is a business problem.

This is not an IT problem. They didn't understand at the time, the day I made that statement, but let me tell you that addendum to their business contract, because we were a partner with Visa too, that's what the contract was about. It held up executing this contract for 18 months. Because once they finally understood what it was and what it was going to cost us to go to a compliant posture, it was a real problem. So I ended up in the CEO's office one day and he said, David, just in simple language, tell me why they're doing this?

And I said, Mr. CEO— I'll leave his name out— but Mr. CEO, it's actually very simple. I said, do you know what the annual number, dollar loss is for credit card fraud in the United States today? And he said, you know, I don't know that off the top of my head, but I'm guessing you do. I said, it just hit $50 billion. This is like 2002 or '03, making me think back.

And he said, you just crystallized it for me. I said, exactly. I said, all they're trying to do— I said, today when there's card fraud, the issuing bank has to eat it. All they're trying to do is share the pain. The dollar cost has gotten too high in card fraud.

They want to make different parties in the total chain of processing card transactions accountable for that. If we have a card breach and we lose thousands to millions of different cards and fraudulent transactions are executed against them, they want someone to pay for some of that. That's all it's about. He's like, I got it. We did eventually go there.

We did eventually get certified, KISP at the time, pre-PCI, and shortly around that timeframe, I ended up moving on. As TSYS kind of shifted strategies and started to assimilate some of the subsidiaries more into their core. I was invited to relocate to Georgia and had no interest in that, so I moved on.

Walk us forward. I know you went to another— it looks like healthcare next, is that right? Yes, and we're almost to the end of my resume, I promise. After financial services, I was the CISO there for 5 years.

Went briefly as an independent consultant, and some executives I had worked for in that financial services company had gone into healthcare up in the Twin Cities, needed to build a security program, which I'd done several places, and called me and said, we understand you're leaving. Do you have some time to help us out? Sure. So I did a 2-year contract ultimately as an independent for them, built their security program out. Hired a security manager for them up in Minnesota in the Twin Cities, and then a— I'll call them a larger, more experienced healthcare player came in and wanted to buy the company that I was contracting for and make them the cornerstone of a large growing healthcare conglomerate.

They were going to grow rapidly through M&A. The company I was contracting for was primarily a TPA operation, a third-party administration firm for long-term care insurance policies for many of those providers, the MetLife's, the Northwestern Mutual's of the world. So anyhow, we became Univita Health. We started buying other companies. At that point, I hired on as the Vice President of Risk Management and ended up running the compliance risk management, internal audit, and security functions independent of IT and ultimately reporting to General Counsel.

So we had a plethora of regulatory issues to deal with, compliance issues to deal with. Much like PCI is to security, URAC accreditation in healthcare is a big deal if you're operating hospitals and/or health services in the home. We had acquired a home healthcare company, we had acquired a durable medical equipment company, we had had some legal issues arise out of those operations.

I had an interesting time. I walked into the COO's office one time right after those acquisitions and I said, Mr. COO, you know, before this acquisition, our biggest risk whatever could go wrong, you could solve by writing a simple check because it was all just financial, it was insurance coverage. I said, now that you've bought this, have you thought about the fact that your biggest risk is direct cause of death? And he looked at me and he said, I haven't gone there yet. Why would you say that?

I said, well, that home health company you bought runs a specialty infusion pharmacy. They mix custom narcotics of the prescription flavor, and they do custom blends of them. And then you pay contracted nurses to walk into someone's home and inject them into people's bodies.

So there's a liability there. Yeah. Um, do we need to talk with external counsel? At the time, we didn't have an internal counsel. Yeah.

Shortly thereafter, we hired an internal counsel because They recognized in some discussion we had some challenges there. And in truth, we also had bought a durable medical equipment company. Within 3 to 6 months— within 3 months, I had a Medicaid fraud issue that I was investigating with an external counsel in that operation in South Florida. And within 6 months, we had our first wrongful death suit for a death out of the durable medical equipment company based on equipment we had provided. So it proved me prophetic.

That's not the time you want to be right though, right? Right. So that's healthcare. After healthcare, I came back to Denver. I consulted briefly, but then the opportunity at QEP Resources in oil and gas opened up.

I had worked for 5 years for a municipal gas company in the '90s. I had spent a year to 2 years at the Department of Energy in Lakewood as a senior security resource, as a consultant, and so it was a reasonable fit. I knew a little bit more about the space than some. Yeah. All right.

Well, I'm really interested in hearing about Blue Lake Protection Services. What's that? So Blue Lake Protection Services was a startup venture that I did just prior to QEP. So I had connections A couple of connections. Prior CIO I worked with and a prior CEO that I had worked with who was running a data aggregation company building platforms off of what we call business intelligence or artificial intelligence today.

He was doing— he was an ex-C-level executive of ChoicePoint from back in the '90s and he had built a company here in Colorado and partnered with Entrado up in Longmont to provide some specialized applications for law enforcement. I was on his advisory board for a number of years, and we had talked about the difficulties of working in the law enforcement market. I have an older brother who was a career cop on the East Coast, and there are some unique attributes to, you know, trying to sell software into police departments. I bet. Anyhow, he had had some reasonable luck, but it had definitely gone way slower than his business plan.

Anyhow, I connected him with my other friend, former CIO, who was also an independent consultant at the time. And I said, you know what? I said, I have an interesting idea for a privacy solution. And this is, you know, a few years ago. 3 or 4 years ago, that, you know, you can bring the data to— because he had contracts with all the data aggregators.

He said, you and I can bring the software and security expertise into the platform to create a consumer-targeted privacy platform. Because so much of what has happened since, we foresaw with the privacy violations, with the protection stuff coming out of the EU, we saw a business opportunity and we actually spent a year going after it. We did land a contract with LexisNexis on the data side. We had had conversations with several of the other credit bureaus on the data side. We had piloted and presented to investors, many investors, mockups of what we had in mind conceptually for this solution.

We got a lot of traction at that level. At the end of the day, 12 months in, we just couldn't pull the funding at a reasonable cost, and so we went separate ways. We decided to throw in the towel. CIO was relocating back to Texas. We had a different spin on the data aggregation company, and I was left going, all right, I haven't had any income for, you know, a year to 2 years now.

Um, might be nice to have a job. Might, might be time to go back and get a job and, and re-level set the bank account. So, um, that's when I found QEP. Yeah, so, so when— give me some background on, for those who don't know, QEP. Where do they fit in the market?

So QEP Resources is primarily an upstream oil and gas company. In oil and gas, it's upstream, midstream, and downstream. Upstream are the ones who drill and pull it out of the ground. Midstream are the transport, they're the pipelines. And then downstream is refining or turning it into the next products.

That's where you actually take oil, turn it into gasoline. Simple version. And so QEP, when I hired on in the middle of 2015, had just inked a deal. They were an upstream and midstream company. They had just inked a deal to sell their midstream assets to a company called Tesoro, a larger oil company.

It worked out really well for them timing-wise to have inked that deal and sold the midstream because in 2016 the price of oil collapsed, which is a reality in a commodity market, which is oil and gas. We had the money to weather that collapse just fine because we had the proceeds from the recently sold Midstream. It actually ran a number of the other smaller players here in Denver out of business. It forces consolidation when you see that big a drop in the price of oil for a sustained period of time. Yeah.

So today QEP is, you know, primarily an upstream oil and gas company. Today we're located in basin areas from North Dakota, Utah, Louisiana, and Texas. We are actually making a strategic shift to become primarily focused in the Texas Permian Basin area, and the whole mission is drill and pull oil out of the ground and put it on the market. What are some unique challenges that you have running security at oil and gas? You just went through all kinds of other industries that you've worked in.

What's different about oil and gas? Oil and gas is very different in the respect that it's an unregulated business from an IT security perspective. There is no PCI. There is no HIPAA HITECH. There's no mandate or regulatory body that says thou shalt protect certain classes of data in any way, shape, or form.

So that's thing one, and it's the reason most oil and gas companies that are just SMB-sized businesses, if they have a dedicated function. It's usually a manager of security that reports to a director of IT. QEP is not huge, but a little larger than some players in Denver. So when I joined them, I think our market cap was about $4 billion. We were about a $4 billion company before the collapse of oil price.

And it's amazing, I mean, you can cut your market cap in half just with the shift of oil and in the day-to-day. That's okay, it's It's not a crisis or anything. You still operate the same way every day, pull oil out of the ground and sell it.

I went to QEP with the understanding that they took security more seriously than average in the industry. They proved that to me. A, the CIO that I worked for demonstrated a clear knowledge, had gotten his own CISSP. He got it. We were going to be going on a monthly basis to the senior executives.

We call it the IT Steering Committee in formal governance fashion, and we would go to the board meetings and status them on security. We had several board members at the time. Some have moved on. We've replaced them over the years, but who were very security-minded out of other energy companies that had had security events.

In any industry, when you're talking the C-suites and the board of directors, how much importance the information security function gets is usually a direct outgrowth of their personal professional experience. You do have regulatory drivers and mandates for compliance, and depending on the industry, for financial services, healthcare, and others, but predominantly the guys calling the shots in the day-to-day, if they've suffered events, they get it. If they've worked legal cases, they they get it. If they've had to engage law enforcement, they definitely get it. Having done all of that in my background, I got here, they had never had major issues at QEP, but they got it.

They walk the talk. I'm now the director of IT security there, have been for most of my tenure there. They brought it up a notch compared to many of my peers here in downtown. Would it be fair to say that when you walked in, the previous owner of the security program was a terrible person and a terrible security professional?

You know, I would not make that judgment.

So, you're saying I can quote you that Alex Wood did a terrible job running the security program at QEP? Alex Wood did an admirable job establishing what he established at the time he established it, given the lack of backing he had at the time. So the subtext here, obviously Alex, the co-host of the show, was the guy running security there before you. And Alex runs security at Pulte, where I was previously. Yep, small world.

And so he has the opportunity to give me all kinds of grief, so a little bit of payback here seems fair.

One of the things we hear a lot about is nation-states who are looking to get footholds in critical infrastructure. I think you guys probably are critical infrastructure, maybe peripherally, because you're not actually— it's a little different than being like a generation electrical plant. Do you see any of this in day-to-day activities for you? Is this something you think about much? Not at QEP.

Interestingly, I spent 5 years on the board of directors of the local Denver InfraGard chapter, all about critical infrastructure and public-private partnership. I was the president in '09-'10 of the Denver chapter.

While technically on paper any oil and gas company meets the definition of critical infrastructure, if you're an upstream provider, basically just pulling it out of the ground and putting it into a third-party pipeline. We really have nothing that can take down anything of consequence. It's just a matter of volume of supply at that point. You might stop producing gas, right? That's about it.

It's just volume of supply. That's it. Hypothetically, if evil international hackers penetrated our SCADA ICS systems and shut down our wells or our drilling operations and we had to take it all offline, nobody in the United States would even be aware or see a blip in oil supply or energy supply. It makes it much less likely at our size as a shale drilling upstream provider that we're a target of those firms, nor have I seen it in the monitoring that we do. Now, in fact, I am aware of some non-public cyber events in the oil and gas space that were a little more impactful, involved law enforcement, things had to be very formally investigated and done.

Even those, they can stay unpublic because they had no real impact in the day-to-day.

In my time at the DOE, for those who remember, I think it was probably 2002-ish. We had a big blackout in the northeastern United States. Ohio, yeah. Huge event. Well, I was at the DOE HQ here in Lakewood the day that went down, and CIO came up looking for the cybersecurity manager who, just poking fun as a Fed, had taken the day off.

I was the only one there, and she's like, Come with me, we gotta talk. Yeah. And we were all, of course, watching the news about the blackout. And so she takes me back privately to her office and she says, look, she said, you did one of the technical assessments at one of our SCADA ops centers in South Dakota. I did.

She's like, so given what's going on, tell me we're okay. I said, what? She's like, tell me we're okay. I can't tell you that. I don't have enough information to make that determination or conclusion.

She's like, I need to know that we're okay. I was like, you know, I'm a contractor and a consultant. I'm not a fed. I have to tell you the truth.

She's like, okay, fine. When he gets back, send him my way. Somebody else can tell me we're okay. But it was just a knee-jerk reaction within the Department of Energy. They didn't know how far that was going to cascade.

They didn't know if it could cross. The United States is in 4 separate regional blocks of power administrations, 4 different chunks, 4 or 5 different chunks that run the total grid for the country, Western Area Power Administration being one of them. They didn't know if it could cross, if it was gonna keep coming. They didn't know what the cause was. They didn't know if it was a cyber event.

At the end of the day, we all know now it was not a cyber event. There was a lot of speculation initially that it was. Oh, I have a huge, huge speculation that it was initially. Now, the reason for that speculation and the nervousness within the DOE at the time was because most of the power administrations had finally conceded the economics and shifted some of the SCADA ICS stuff over to TCP/IP. They had connected them to corporate networks.

They had— the air gap was gone. They had enabled them with IP, and they knew they now had some exposure to cyberattack, and that's why they were so edgy back then at the time. So we are just about out of time, David. I know you have a hard stop, you gotta get back to work. I want to talk a little bit more about the InfraGard work you've done.

So if I signed up for InfraGard 7 years ago, is my membership still good? Absolutely. So I'm in, I'm still there. I haven't been to something for a long time. You know, it is one of the less accessible of the groups in town because you do have to go through a background check process and all that.

So those who are interested in getting involved, what do they get out of it? So InfraGard, you know, we had in town, of course, ISSA was very prevalent, and I was a member of ISSA back then, and, you know, a couple others. When InfraGard first launched, again, early 2000s here in Denver, The FBI wasn't doing a very good job of driving this public-private partnership initiative. Yeah. And they basically made the mistake of distributing it to all the field offices who didn't have a lot of skin in the game or need to do that versus work real cases until they mandated that they formally assign a coordinator in each of the chapter cities.

But even then, they didn't give it a lot of mindshare except in the chapters where just by virtue of the local community there was a lot of engagement and passion. So Denver, at the time I was on the board, again, 5 years on the board from 2005 to 2010, we became the 2nd largest chapter in the country right behind New York. And we had regularly, we were having 100 to 150 people at the quarterly meetings. Now, the big complaint at the time was, you only meet quarterly, and if I have a schedule conflict and can't meet, I've gone half a year. It's kind of hard to stay engaged.

Back then, we launched the Sector Chief Program for each of the critical infrastructure sectors and tried to form smaller committees to give people that wanted to get more involved on a more regular basis an ability to do so specifically within their industry niche. What we got out of it at the time, and many people told me after certain chapter meetings, was real case examples.

The CISO challenge in the late 2000s was hypothetically where you have these vulnerabilities and bad things could happen, but if they haven't happened here, I can't get any backing from senior management or business leadership. So what you needed, even if it wasn't in your company, you needed real case examples that bad things had happened. And the FBI would share, you know, non-classified cases of real things they had seen right here in Denver that actually touched many companies in the room who were completely unaware of it at the time.

That to me was the real value prop that InfraGard brought that was different from ISSA and ISACA and the others.

It was a little bit of a law enforcement slant. Unfortunately, you always had people who thought, hey, it's the FBI InfraGard, I get a badge, right? It's like, no, no, we're not empowering you to do anything. Other than to file a SAR and cooperate with us and learn. Well, we are over our allotted time, David.

I really appreciate your time. Absolutely. Looking forward to connecting with you again in the future, and hopefully we can get other folks to come see you at some of these events in town. Sure, absolutely. Are you still going to InfraGard events?

I haven't been myself in a while. Typically when you step down from the board after such a long tenure, you try to turn it over to new folks and you try to avoid it for a while, but enough time has passed. I've been looking forward to getting back. All right, well, thanks again for your time. We'll talk to you soon.

Thank you. Enjoyed it. Till next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes