Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 84, the week of September— would we say 17th? Yeah, September 17th.
Halfway through the month already. Alex, good to be back. It's been a couple of weeks. I know. Good to see you, Robb.
How you doing? I'm doing well. How about you? Doing fantastic. You're wearing a nice Broncos t-shirt today.
Yeah, I'm going to the Broncos game, which convinced me I should look like a Broncos fan. Yeah, that's probably a good idea. Support my kid. So we're going to get to maybe meet a— we're going to some pregame thing, so maybe autographs. And I don't want— I want my kid to not have an experience of being with a person who's not helping out.
Alternately, you could have dressed up as a Raiders fan. And, you know, experience— we had a different experience at the ball game. Yeah. Uh, well, before we jump over to the news, let's go through some housekeeping. As a reminder, we have a Slack channel.
This is your great opportunity to engage with the security community. We've got 570-ish people that are pretty actively involved in all kinds of channels, lots of conversations going on. I think I've said in the past that I read all of the Slack messages, and it is getting harder and harder for me to keep up and read all of the Slack messages every week. I I don't read every one anymore. I do make sure I clear them out though, so I can, if it's a long conversation about something, I don't necessarily read every message now.
Yeah, oh Robb. Also on the website, we have a mailing list. So if you want to get the show notes emailed to you, go ahead and sign up for that. And the website is colorado-security.com. We'd appreciate it if you would sign up, get this podcast delivered into your inbox every week with iTunes or wherever it is you get your podcasts from.
Of course, rate us and give us 5 stars if you appreciate what we're doing, and let us know if you don't like it. And also, if you like what we are doing and think that we're doing good stuff, we would love you to sign up for our Patreon campaign. Robb and I fund this out of our own pockets, and getting that Patreon campaign going lets some folks give us a little money to help with the costs associated. But it does go directly to the show. None of it goes into our own pockets.
All right, moving on to the news. First is kind of a continuation of a couple different stories we've talked about. It's a new smart road story. Denver is testing new technology to improve traffic and safety. Yeah, so this one is actually, I think they're doing about a mile of road on Brighton Boulevard.
Yeah. Just look at putting in sensors that are gonna be able to track speed and other things like that. Yes, going in this week, and this is CDOT that's doing it. And this is mostly gonna be used for seeing how fast cars are going, but part of this intelligence is it should be able to tell you if a car is going quickly off the side of the road basically means someone's going to crash. And the same technology they're installing will allow them to do things like charge an electric car or send internet connectivity through the road to cars.
They're just not using those features at this point. Wow, that's pretty cool. We have had similar stories in the past doing this on I-70 or other things like that. So it seems like the smart road initiatives are moving forward. Yeah, pretty awesome that Colorado is leading the way there.
Next, office space in downtown Denver is going to increase by more than 1 million square feet annually until 2021, I believe. Well, it looks like that's what, like 3 times the increase we had for the last 20 years or so, right? 30 years even. Yeah, I mean, it looks like the average over that time period was about 320,000 square feet, which I'm sure some of those were, you know, may have been negative numbers as well, right? So in, in bust periods, you're, you're losing some office space and But now we're getting much more office space.
There's lots of buildings being built downtown. It does look like it might slow a little bit starting in 2019 and 2020, but still pretty cool that there's all this construction going on downtown. Very cool. Next story, we're looking at what companies have grown the most in Colorado over the last year or so. Number 1 on the top of the list from a profit perspective is Dish Network.
Dish went from $40 million profit in the same quarter in 2017 to $400 million profit this year. Not too shabby. Uh, also, uh, almost what DISH got, Molson Coors, uh, had a second quarter profit of $424 million. Um, DaVita was actually the number 2 most profitable company at, uh, what, $267 million? So doing, doing really well.
Good stuff. Uh, also in the article, Crocs doubled their profitability. We talked about them not too long ago with, uh, closing some of their manufacturing and other things like that. Yeah, they're, they're looking to get more efficient, but they're, you know, as a company still doing quite well. Exactly.
Uh, the next story, jumping in more to the security sort of stuff, uh, this actually is super interesting and sad at the same time. Uh, we have a story about a printing company in Denver that, uh, has blamed their closure, and not just like temporary closure, permanent closure on a ransomware attack. So Colorado Timberline, which is a 5-year-old printing company, went out of business. And the note that they sent out to all of their customers and partners was, we've recently been plagued by several IT events. Unfortunately, we were unable to overcome the most recent ransomware attack, and as a result, this unfortunate and difficult decision was made.
We greatly appreciate the support and loyalty from each of you over the years. So 100 employees lost their jobs over ransomware, it looks like. Yeah, I think we, we hear a lot of times about companies having losses or other things like that. I don't know that I've heard of a company, at least with a name, you know, maybe sort of anecdotally, but I haven't heard of this much detail around a company actually going out of business and not coming back from a cyber event. The FBI quotes statistics saying something like 60% of small businesses that are hit by these ransomware breaches don't come back from them.
I had never heard a name, and I'd actually asked the FBI for that, and so far have not been able to get a name. It's, it's very useful to now have a data point that we can share and say, look, this is a real thing. Of course, the more we get to see, the more we can talk about this, the more we can hopefully work on fixing the, the root problems here, right? I mean, and we've also heard of lots of events where we've had ransomware attacks and other things like that CDOT and City of Englewood, where it's caused a lot of disruption, but definitely not going out of business. Yeah.
So, so Alex, did you hear we've actually won a big tech company's HQ2 coming here to Denver? We have. Yeah, I hadn't heard this. Carbon Black. Carbon Black is bringing their HQ2.
They're actually not calling it HQ2. But as we were talking, Alex and I were talking about this before the show, we, we, it really does look like they're kind of bringing a second headquarters to Boulder. Their office they have right now can house about 150 people. They've got 84 in there now and getting up to 120, but they're in the talks with the building to get another floor and really kind of maybe double the space there, you know, bringing it up to maybe as many as 300 folks here in Boulder. As part of the move, you know, they offered people in their Boston headquarters the option if they wanted to come out to Colorado, and there was apparently a great response for people that wanted to come in and live in Boulder instead of live in Boston.
I can't imagine why, but, you know, seems like a good thing. Yeah. So this office here in Boulder is going to be focused on DevOps, threat intelligence. They also have some engineering in there. And of course, it is also the West Coast sales headquarters.
And actually, one of my interns from this past summer got a job at Carbon Black and is now working in that brand new office. That's great to hear. Yeah. Next, Overwatch ID announced that they raised another $2.5 million This is still, I guess, what you'd consider angel investment prior to their Series A, which they're trying to do next year. Well, so congratulations to Overwatch ID.
Well done. I assume you take all the credit for that, Alex. It was actually my $2.5 million that I put into the company. Okay. I'm glad you had that available sitting around.
So Webroot has a surprising— a huge press release this week. Huge. It's huge. They are announcing with their 12% annual growth that they have have, uh, had yet another quarter of double-digit growth rate. And this is the 12% for the year, but this is also their— what is it, um, 18th consecutive quarter of double-digit growth.
You know, it, it's hard to keep up, Robb. You know, every quarter with double-digit growth, you know, eventually you can't count that high, right? Yeah. And their business segment ARR, so versus their consumer segment, actually grew by 25%. So that's actually a really healthy tech growth there.
You know, one of the things that I thought was interesting, uh, Webroot, they target a lot of managed security providers now. It, you know, originally they were a sort of consumer antivirus or, um, you know, even any, uh, enterprise antivirus. But now they target a lot of those service providers who then can either resell or, you know, provide on behalf of their customers. And they noted that they now have 12,800 managed, uh, service providers using their products, up from 9,400. Which is a— that's such a big 12,000.
It's big. It's a lot. It's huge. As you said earlier, huge, huge number. So congratulations again to Webroot.
I'm sure in another 3 months we will have another story on their double-digit growth. Next, Ping had a blog about a guide to navigating the California Consumer Privacy Act. So for those that don't know, California passed a law called the Consumer Privacy Act, very similar to GDPR. Sort of following on the heels to that. This goes into effect in January 2020, so people have a little time to get ready for it.
But this blog post sort of summarizes what is in the bill. Yeah, it's, it's really a lot of detail. We're not gonna go through all the detail of it. I will say that what I keep hearing is there's going to be a lot of changes into the bill before it goes into law in January, but it's nice to know where we stand right now and we can start getting prepared for it. Exactly.
Yeah, there was originally a ballot measure that got put on the ballot in California. And lawmakers sort of panicked a little bit, I think, because that ballot measure was pretty strict. And apparently, if you pass something through the popular vote, it is very hard to change it once it is in place. So they went ahead and worked with the people that put that on the ballot to say, hey, if we pass something in the interim, will you take that off the ballot so that they rushed within a couple weeks, I think, to put this bill together and get it passed and signed. So it's probably not where it needs to be in terms of a final bill.
But hopefully they don't gut it too much. There's kind of this balance, right? You want to be business-friendly, but we still want to be able to, you know, start protecting the privacy of U.S. citizens as well. For sure. Moving forward, Optiv has a blog this week about the skills gap, hiring when there are no people.
As a starting point, you know, they point out a couple of stats. There's 747,000 open security jobs right now. Uh, there's a projection by the Global Information Security Workforce Study that we're going to have 1.8 million open jobs in the next few years. It's a lot of jobs. So I think once those 747,000 jobs get filled, there will then be 747,000 jobs open because it's just going to be people moving to new jobs.
There'll be, you know, 850,000 jobs open because we keep opening reqs, right? Uh, they— so, uh, this blog really goes through what are the things that you as a hiring manager managers should do to get prepared for this. I like some of the points, you know, I'm not going to go through all of it, but as you're hiring, maybe rather than looking for, you know, a security analyst from another company, you could look at a different type of field. Look for someone who's got other technical skills, somebody who's smart but maybe hasn't actually done security, somebody who's familiar with privacy or safety, something that's relevant but not necessarily directly the same type of field. Yeah, they also talked a little bit about how to keep people once you have them.
Basically making sure that they have good opportunities, that you're getting them away from their day-to-day jobs out to conferences or other trainings, incentives like tuition payments, other things like that. And then finally, they make a good point that if you can't keep up, if it's just too hard to hire, there's always outsourcing. And outsourcing is a viable solution with all the, you know, 12,000 MSPs that Webroot partners with. Hey, do you know any companies that outsource? I think Optiv might be one of those companies that outsource.
Do they do that? I'm not sure. Next, Red Canary had a blog post. It was actually a Q&A on the MITRE ATT&CK framework and how to use it to mature your threat hunting program. So this is kicking off a 3-part webinar that they're gonna be doing.
So if you guys wanna learn about how to use the MITRE ATT&CK framework, take a look at that. It's gonna be coming up here in the next week or so. Yeah, I think the Q&A was essentially a high level, you know, before building up to the, building up into the webinar. So if you wanna get an idea of what the framework is, what they're gonna be talking about in the webinars, maybe some general ideas about what you could do, You can read the article and then listen to the 3-part series and you'll have a whole bunch of detail. Awesome.
So there's a Coalfire blog here, From OSINT to Internal: Gaining Domain Admin from Outside the Perimeter. And this is actually the 3rd blog that we've had by the same Coalfire consultant, Esteban Rodriguez. So a big shout out to Esteban. This is another good blog post. Yeah, the, the 3 that we've had have all been really interesting.
And I've been impressed by all of them. This one in particular, you know, he talked about a little bit in the past when he was doing one of his early pen tests and wasn't able to get any results. And then did some open source intelligence gathering, you know, took some people and looked at their credentials versus, or their email addresses versus the LinkedIn breach. And then from there was able to get some results through password reuse. Yeah.
No multifactor. Yep. Sons of— Exactly. So anyway, it's a good blog, interesting to look at, and good stuff from Esteban. We look forward to hearing more from him.
All right. Thanks, Esteban. That is the end of the news. Moving over to the Slack message of the week. Big thanks to Andre Gaeta, who is our patron for this and is the reason we are able to do this.
Andre, we appreciate your support. And this week? Yeah, this week we would like to recognize Chris Nickerson for his contributions in the Slack channel. So congratulations, Chris. He had a couple posts this week.
Uh, one of those was a link to a downloadable WHOIS database. So, you know, if you are an offensive, uh, security practitioner and you need to, or I guess even defensive, um, and you need to, to look up WHOIS, you can have this offline database so you can, uh, help research better. And also, uh, link to some proof of conspo— proof of concept exploits. Yeah. Uh, for some of the recent Windows vulnerabilities.
Yeah. Thanks, Chris. We appreciate your, your support in the community there. Moving over to our event calendar, as a reminder, we do have an events section on the colorado-security.com website. Take a look at that.
We go out through the end of the year. We might even be out into January now. First thing is this week on the 18th is the Ballard Spa Colorado Cybersecurity Summit. Yeah, and as you have heard over the last few weeks, Colorado Equal Security is co-sponsoring this event. I will be there.
I think, Robb, you're out of town. I think I could otherwise for a little bit indisposed. Um, and so there are 3 panels there. Ballard Spahr obviously is a, is a law firm. So this is going to be a more legal-focused conference, but it's a half day on the 18th.
I think it'll be good and people should definitely show up if they can. Also on the 18th, SecureSet is doing their expert series with Chris Roberts. He is now over at Layers rather than, uh, rather, rather than Calvio where he had been. Uh, also on the 18th, CTA is doing their Colorado Smart Cities Symposium. I assume you have to be from a smart city to go to this.
Do they list which ones are available? Or maybe you aspire to be a smart city. Oh, that could be it. Okay. ISSA Colorado Springs is doing their September meetings on the 18th and 19th.
That's going to be the dinner meeting on the 18th and the lunch meeting on the 19th. Also on the 19th, OWASP is having their September meeting. And if you want to swing directly from OWASP over to a little bit less formal event, the Densec meeting is happening at Ryan House that evening.
Also this week on the 20th, ISACA is having their monthly meeting, Top Observations Where Suppliers Are Winning and Confessions of a Software Auditor, followed by a happy hour. I think this is their first meeting of the year, right? I think, I think that they took off the summer. Yes. September is like their kickoff event.
Yep. So that's a little bit bigger with the happy hour. And it's a good time to get to go do some socializing. Um, also on the 20th, ISC² is doing their September chapter meeting. That'll be downtown, I think, at the SecureSet campus.
And then also on the, the 20th, OWASP Boulder is doing Building Patterns for Secure Microservices with Joe Gerber. I'm not sure if this is the same one as the Denver meeting or if there's different topics. Different. It's different. Um, so, so I don't want to hear any excuses on the 20th that you don't have anything close to you, right?
If, if you're listening in the Denver metro area We do have plenty of events. We have the Springs, we've got, we've got DTC downtown Boulder this entire week, 18, 19, 20, jam-packed. On the 25th, so, so next week are the CTAs. Excuse me, this is the Denver Business Journal's C-Suite Awards celebration. That's the, that's the 25th.
Also on the 25th, the GDPR meetup group is having their monthly meetup, Encryption for GDPR Compliance: Fact and Fiction. NCC Group is doing cyber for executives. I assume that this is like an Excel tutorial. I don't know for sure. Something like that, Robb.
Something like that. The first half of the meeting will be describing what cyber is and how you can cyber. Sorry, that was a little jab at the word cyber. We have one last meeting. So on the 28th, SecureSet will be doing one of their ongoing capture the flag series.
All right, moving over to jobs. We have 2 fantastic job opportunities at Ping Identity. Number one, I am hiring a cloud security architect, someone to help us build the security structure and monitoring around our AWS environment for a brand new product that we're creating. Number 2, we're hiring a NOC/ SOC manager, and it's called an SRE manager on the website, but it is— it would be managing our 24/7 NOC/ SOC. Cray is looking for a chief security architect.
So if you want to secure supercomputers, you should check that out. Sounds so awesome. That does. It sounds really cool. But you have to know some stuff that you and I don't know.
Probably just a little bit. Probably a little bit. All right. Staples has a couple of interesting positions. I heard from their— the head of their AppSec program, they're hiring a senior application security architect and they're hiring a senior cybersecurity application engineer.
Sounds like fun. Yeah. Spectrum is looking for a senior manager of network security operations. Booz Allen is hiring an analyst around information systems security, senior. Interesting.
TIAA, no longer CREF, is looking for a lead info security analyst. NREL is hiring a cybersecurity research engineer. We just met the, the CISO over there, Desiree Robinson. She seems like a good person. She's building a good team out, so it looks like a fun opportunity.
Coresight is looking for a vice president of IT and digit— that's a tough word— digitization. And Coresight's actually in the same building as me, so if you get this job, let's go get lunch. Sweet. And our final job is with MUFG for a senior enterprise architect director. It's a director-level position.
I'm sure that that has a completely legitimate meaning to that acronym. Yeah. But when you read that, it sure sounds like something bad. So it is. The first word is Mitsubishi.
I know. I remember that, but I don't know what the rest of the words are in the acronym. Well, that takes us to the end of the news, Alex. Our feature interview this week, you sat down with Nancy Phillips, who is the new CISO over at Centura Health. Health, previously at Datavail, and previous to that at Kaiser, right?
Yeah, exactly. I had a nice conversation with Nancy. We talked about her career, things that she's doing. Should be a very interesting interview for folks. All right, well, thanks again.
We'll talk to you next week. Sounds good. Thanks, Robb. This is Sue LaPierre, CISO at Prologis. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is Alex Wood, and I have a feature interview today with a very special guest. I'd like to welcome Nancy Phillips. Hi, Nancy. Hi, Alex.
How are you? I'm great, thanks. Awesome. Appreciate you taking a little time to talk with us today. Absolutely.
So we've known each other for, I don't know, a long time now. Yeah, quite a few years. But I'm sure there's a few people out there that don't know you. So why don't we start by talking about who you are? Hmm.
Who I am? Boy, that's a good question. So from a career perspective, I'm now the Chief Information Security Officer for Centura Health. Awesome. Which means, you know, a long history of jobs and stops along the way to get to here.
So I started out, as many of us have, in the military intelligence community. I was in the Air Force for about 9 years doing intel-type work. Where were you based? Um, I was based in Japan. I was based in Las Vegas, Nevada during the days of the 117 unveiling.
Okay, then the stealth fighters, right? Nice. And then Syracuse, New York, Rome Labs. So another area of interesting intel type work. And when you were there, this is military intelligence, not what we think of, you know, like a security intelligence or, or information security kind of stuff, right?
Before information security was really information security, right? So there wasn't a cybersecurity force as of yet. Those things were just starting as I was coming out of the service. So I was doing traditional military intel. They called it electronic intelligence work.
A lot in the satellite arena is kind of what I focused on. Nice. So yeah, which was an interesting background because, you know, at that time we were doing a lot of development of tactics and techniques. Against our adversaries. So created that mindset that made it easier to apply how to protect, right, against an adversary.
If at one time you had that adversarial mindset, right, it's easier to kind of figure out how you want to protect against those things for sure. So then at some point you obviously got out of the military. I did. And you had to figure out what you wanted to do with yourself. Yeah.
Yeah, I did like most and went right into defense contracting. Okay. Right, so took off my military clothes, put on my civilian clothes, and became a contractor doing very much this, the same type of work. And that's what got me out to Colorado, actually. I went and worked down at the Space Warfare Center, at the time Falcon Air Force Base, which is now Schriever Air Force Base.
So I did a lot of the same work there and continued my education and finished my bachelor's degree in Computer Information Systems Management. And so I had an opportunity to help another side of the organization. So I was on the clearance side, the top secret side of the house. I went to the secret side to help them prep for an audit, and that's because I was able to get hands on keyboards and change directory permissions and file settings and all that other kind of stuff to make sure that the system was locked down before the auditors came. While going through that process, the guy that I was helping out said, hey, you happen to have a knack for this.
Would you like to learn about cybersecurity? And so that's kind of how I made that transition from doing the defense contracting work into the cybersecurity work. And when was that? How long ago was that? Ooh, that was back in I would say about '95, '96 timeframe.
Okay. So did that for a little while, actually for the space— for Air Force Space Command. And here's an interesting story. We developed, because we did a lot of security awareness training for the Space Command bases around the United States, and we developed a traveling hacking demo. To do security awareness.
And so we brought 3 laptops where my boss was the bad guy and I was the good guy, and we had our mail server, and we took somebody's business card and did, you know, the typical— what you could learn from and hack and how you can hack into systems just based off of information from a business card. Nice. And when you say laptops, were these still like, you know, as big as a pizza box and like, right, like 50 pounds? Yeah, my cell phone was a brick at the time too. Yeah, so we did that, but we got an opportunity with all of that to actually give that demo at one of the very first InfraGard meetings at Case Western University.
Oh, that is awesome. Yeah, yeah, so like I said, I've been doing this for for a long time, almost from the beginning. Nice. So you did that for a little bit, and then where did you go next? Then I came up to Denver because I was down in Colorado Springs and started, you know, transitioning out of the contracting world into the corporate world, commercial world.
Went to work for a small up-and-coming boutique security consulting firm called Denver Tech Labs. At the time. Yeah, way back in those days. Which eventually became Inspirix, which eventually got bought by Cyber. So, you know, worked for Cyber in their consulting organization as well.
So did a lot of consulting work through that whole period of time. And then eventually started working for some of the folks we were consulting for. So went to work over at First Data. We consulted at First Data and helped build the security around the electronic federal tax payment system. Had to brief the IRS on why it would be okay to accept tax payments over the internet.
Nice. And then eventually went back at First Data and helped, you know, do another round of improvements and actually worked for them on that system initially. And then eventually came over to work the SOC side of the house. So the other thing during my whole career, especially in the consulting side of things, was developing security operations centers. So either managed security services or building out SOCs for organizations.
So I did a lot of those. I probably built about 4 or 5 SOCs. In my stint between, you know, doing that and then starting to work in the corporate space. Nice. And so you spent some time at First Data and then you left there.
Mm-hmm. And then I ended up over at Kaiser Permanente, which was my initial step into the healthcare arena. Yeah, which was a really fun time too. Be at Kaiser. Where you also helped build a SOC.
Where I also helped build a SOC, and I would have to say probably my, you know, pinnacle of SOCs is the one over at Kaiser. Not only did we get to build, you know, the process, the people, and the technology, but we also got to do a physical SOC build, which was the first time people— somebody actually gave, gave me a money to say, you know, go build a facility that houses people that pay attention to security events. It wasn't like, hey, we want you to have a SOC, here's a closet, right? Figure out how you can shove a dozen people in here. Exactly.
Which is, you know, typically how that goes, right? The poor people that are, you know, in the dark, dank areas of the data center. No, this was actually a very polished facility that became a showplace for the organization. So that was fun. Along came with that, which I didn't really realize, was a bunch of tours.
So half my job was building the SOC and the other half was tour guide. But it was fun because, you know, we were able to do— to really give the organization something to touch and feel and see when it comes to this magic called cybersecurity. Security. And the byproduct of actually building that physical SOC, which we really didn't realize, was the awareness that it raised in the organization, which then allowed us to have really meaningful conversations a little bit easier when it came to talking about security and the improvements we wanted to make and why we wanted to make those. So that was a lot of fun.
And like I said, and we really kind of built what I would call the SOC 2.0, or what people have been calling SOC 2.0. It's probably on our 3rd generation now with AI and everything else. But we were looking at, instead of having level 1, level 2, level 3 type analysts, we were looking at building expertise in the kill chain. So early warning or threat intelligence, exploits, malware, ransomware, Ransomware type teams, lateral movement teams, and then data exfil teams. And the reason we did that, right, is to give us eyes on the same type of data at different times within that process so that we had a better opportunity of catching things when they were going bad.
Nice. And I'm sure if it was a SOC 2.0, it had to have a fancier pew pew map of the attacks going from, from, you know, here to there. I tell you what, right, that traditional map is golden. You just can't argue it. You can't have a sock without a pew pew map.
No, you cannot have a sock without a pew pew map. And half the time, because we did put up the pew pew map, right, people would just sit there and stare at it and start asking a lot of questions. And yeah, it was always a good topic of conversation. Yeah. Seriously though, with, you know, You said that you built this sort of as a next generation.
What were some of the things that you learned along the way that you put into this next generation of SOC that you kind of thought, oh, I always want to do this stuff, and so now you had a chance to kind of do some of that stuff? I think just having a lot of experience on the operations sides of things. It was an opportunity to really put in all the hooks at the beginning. And when I say hooks, those are really kind of the things that allow us to measure metrics. You know, I hate to say it, but right, a lot of those things are important, not only from an effectiveness standpoint of the people, but of the processes and making sure that we had automated workflow that supported how the people worked versus trying to force the people into an off-the-shelf workflow.
So we, we spent a lot of time really kind of developing that out because there are so many integral parts to that lifecycle of an event when it comes into the SOC, right? Because you have the analysts trying to determine whether it's something of importance or not. That often gets escalated to a multitude of teams. Even once it gets escalated and contained, you still have to do that feedback loop and make sure it got remediated to completion, that it got remediated across the organization, that the lessons learned and the root cause got fed back into the system. And then when analysts were looking at things and realizing that maybe the rule that triggered, you know, wasn't quite what they wanted.
Well, then there was that feedback loop that went into the teams that actually tuned those rules or generated the content or made the dashboards. So we, we were really able to put in workflow automation to allow all of those folks to touch things, but also experts the fact that they could react and, and move at a greater speed instead of just traditional ticketing and stuff like that. And then the benefit of all of that is, you know, that's all contained within a database which you can run any type of reporting and metrics from, which is very helpful when you're doing a lot of tours and answering a lot of questions. It just made life a lot easier. So that we could just kind of be able to answer those in a heartbeat instead of, you know, taking a lot of people off of what they do on their daily job to answer the questions that the executives are asking.
That's always the worst when you have to stop people from doing the work that they need to do so that you can report on the work that they're doing, right? Right. You have to be able to report on it. Yeah. But if you don't have some of that stuff built into the process itself, then it's a its own process for those people to come up with that stuff, and that's no fun for anybody.
Yeah, so that was something along the way, like, if I ever got a chance to do it from the ground up, we'd do that. And we did that, and it, it was magic. It really was. Especially too when the auditors would come in, right? We could, we could tell a story or show a dashboard for every question that they ever had, and it just showed the maturity level of what we were doing on That's awesome.
So if somebody was going to start their security operations practice within their organization, maybe they don't have the resources and people and the budget to build out a fancy room like you got at Kaiser, but what are a couple things that you would say where people should start? Yeah, interestingly enough, I'm going through that process myself. So what would I tell myself?
Yeah, you know, you really kind of have to assess, you know, what, what's important to the organization. What I put in at Kaiser fit for what Kaiser was doing. Now, would I put in that same thing at Centura? No. Did I put the same thing in my previous organization at Datavale?
No. Right? So it's really kind of just assessing what makes sense for the organization based on, you know, what technologies you have in place today, what are the skills of the people that you have in your organization, and then trying to assess those gaps to kind of, you know, give you that determination of, you know, which way should you go. I've been in organizations organizations, my last organization, you know, we just didn't have the team, the staff, the wherewithal, right? So outsourcing to a third-party provider made sense.
You know, where I'm at now, you know, we're making that judgment and going back and forth. You know, do we build the team in-house or do we outsource that level 1? You know, I understand from a very big complex organization how it makes sense to often build that in-house. But if your organization isn't as complex and there's a little more maybe simplicity to the architecture, maybe you don't have to. So I just say it's just really doing that assessment and trying to right-size for the organization based on risk tolerance, based on current investments, based on people and the maturity of the organization.
So we kind of— we stopped short a little bit on our tour of your career, so— and you just alluded to it there a little bit. So you left Kaiser and you went to Datavail. Mm-hmm. Maybe talk a little bit about that and your experience, and then— Yeah, so Kaiser, I went in as a principal not managing, and left as the deputy CISO for the organization, right? That's awesome.
And that was just a matter of just continuing to work hard and, you know, driving and producing, right? And being good. You know, I think, you know, having done security for a long time, it allows you to be able to be very calm in situations, which then tends to, you know, help when you're in those leadership positions. So, and then I went to DataVail. So DataVail was the full-on CISO role, managed services company that does database management and other data management services for organizations.
I've been in managed services organizations before, so certainly understood the challenges of what they were trying to do because they're working with a whole bunch of customers and working on their very oftentimes protected information, their databases and their data stores, helping those organizations get the value out of those, right? And our job was to make sure that we did that in a secure manner and we didn't introduce any issues into our customer environments. So the interesting thing going from healthcare, where you have a lot of people that are caregivers and not necessarily technology people, to a company of almost, you know, 1,000 technologists— definitely different organization, different priority, different needs. And like we said, you know, they— we were Our infrastructure— we didn't produce applications at the time, we were just connecting into other organizations. So our concern was really on how we accessed our customers and make sure that we did that in a secure manner.
So things like jump posts and golden images and making sure that we stored customer credentials in a very secure manner, things of that nature were more important So when I was talking about, you know, it made more sense maybe to do level 1 outsourcing or to do 24/7 outsourcing for that organization versus, you know, building something in-house for what we did. Right. And then, so you left there recently and started at Centura to run their program there. Yeah, so I've been at Centura about 4 months now. So we've just wrapped up, as you know you would coming into an organization, is doing the assessments.
We brought in third parties to give us an understanding of our maturity, and so now we're putting together those roadmaps and starting to socialize the transformation that we're going to undergo at Centura. Our organization as a whole is trying to transform is transforming, right? As our consumers are more mobile, on-demand, you know, wanting information to their health data, wanting to share that health data, you know, how do we as an organization start to enable that but do that in a secure manner? So that's my challenge, is to make sure that we can give our patients you know, the transparency that they want but ensure the privacy that they demand all in the same— all at the same time. Yeah, I mean, it's a funny dichotomy, right?
Because people want their information to be secure, but then they're also willing to give it to a lot of other people if they feel like they're getting something from it. And then, you know, from your perspective, you have some pretty strict regulations with HIPAA on what you can and cannot do. And I know that sometimes people get frustrated with, I'll say, the limitations that that puts on, on some of the things that, that a provider can do. Right, right. Yep.
So, and being responsible for that, for all of it, right, from a compliance standpoint, you know, from supporting the infrastructure standpoint point to try and figure out, you know, how are we going to be able to, to move into this digital healthcare age in a way that doesn't pose too much risk to our patients. Yeah, yeah, it's a lot to think about. Yeah. And so you've been doing a lot of assessments, but things are going well, getting your feet under you? Yeah, yep, getting feet— we had a lot of transformation.
There was a lot of senior leadership change. So I'm coming in with, you know, new CEO, new CIO, and now a new CISO, right? So this wave of change, which I think is really positive because there's some exciting things going on at the organization. There's some operational just consolidation, right? Becoming one organization with many hospitals, instead of many hospitals under one umbrella.
So that offers us, from a security standpoint, the opportunity to kind of put in some checks and balances and controls and governance and things of that nature as we kind of build some centralized processes where before they might have been disparate processes. So, so that's fun. And then just working, you know, the digital transformation in healthcare. And what does that mean, right? It means, you know, allowing people to, to do some interesting analytics to produce information, you know, at our providers' fingertips to help them make better decisions about the care of their patients.
It's also, you know, providing patients' access to their information and allowing them to share it in a way that they prefer to share it versus any other way, right? But still giving them the tools to maybe retract that sharing at some point, right? So how are you able to do all that stuff? You know, being able to do the compliance piece— who touched the data and when, and what did they use it for, and how did they use it, right? You know, Maybe there's some opportunities for some ledgering technologies and stuff like that that we're looking into to be able to kind of provide that pedigree or credibility to where that data trail went.
So we're looking at stuff like that, in addition to, right, taking a team and kind of changing it up a little bit from more of a compliance approach to more of a risk-based approach, right? You've got limited resources and you really need to make sure that you're taking care of the things that, that put the business at the most amount of risk. Going from just traditional worrying about the infrastructure of security and learning how to be consultants to the business and the organization about security and integrating security. So, you know, helping the team move from just being implementers of the technology to, to be being consultants to the business. So we're working through all that now.
Yeah, and that's something that's super important, especially in that kind of environment. As you know, when we were at Kaiser, that was sort of one of the roles that, that I played there. And you have, you know, Kaiser was always pushing the envelope in terms of technology and things that they wanted to do. You definitely had to have your finger on the pulse of everything that was going on so that you could partner with those people in the different technology and business areas because they want to— they see this digital transformation coming and they want to move fast. You can't be the one that's holding them back.
You have to be pointing out the risks that are there and helping them to put those risks at the right level and put the proper controls in place so that, you know, they can move forward with what they're doing without essentially stopping them from, from doing that stuff. Because, you know, you're losing your edge, right? You're right. You're not going to be number one in the market. You're not going to be, you know, give that stuff to the customers that they want if you're holding them back.
Yeah. And, and in healthcare right now, that's a dangerous place place to be is not at the leading edge, right? Right. With, with the state of healthcare in the United States and all those other business drivers that says that we really need to be working hard to stay relevant. Yeah, and, you know, obviously the medical side too, right?
It's— you always have to play nice and make friends with, with the folks that are actually doing the care, because if they're not on your side there's always that patient care trump card that's gonna essentially override whatever it is that you wanna do, right? So if you can't get their agreement on stuff, they're gonna say, sorry, this affects patient care, we're not gonna put your security control in. Yeah, yep, it's definitely, that's a whole interesting other piece and part to healthcare that I think a lot of organizations do not face is you know, the— right, our first priority is obviously patient care. And when we talk about putting in security controls and locking things down and, and having issues and wanting to, you know, contain that issue, well, you really have to think a little bit about what's on the other end of that IP address, right? Right.
Because it's not just a laptop in most cases, it's a laptop that's connected to some system that's, you know, monitoring a patient. And therefore, you know, the traditional things that you would be used to doing, you know, you have to think through it a little bit differently in healthcare. Yeah, when someone has to access a computer in a surgical room, you know, while they're scrubbed in and wearing gloves, they're not gonna be really happy with you if the computer gets locked out and every 5 minutes and they have to, you know, enter their 20-character password. That's right. But, you know, all of a sudden they're gonna have to, you know, take all their stuff off, go scrub back in, get back to where they were.
And yeah, yeah, you got to have— I got to think about that kind of stuff. You do have to think about that stuff. And that's where that risk-based approach comes in, right? Because when you look at ORs and you talk about screen timeouts, yes, we would like them to be 5 minutes, 10 minutes, 15 minutes. But to your point, right, they can't be, because the last thing you want is your doctor looking at an x-ray while he's doing surgery on your back and have that x-ray disappear, right?
It's the last thing you want. Yes, I do not. So, you know, when you look at— oh, my doctor to have the map of where he's going. Exactly. And so when you look at OR rooms, right, they're behind, you know, guarded entrances and and secure doors and this.
And so having, you know, 4 8-hour timeout values are reasonable when you look at all those compensating controls and the risk that's associated with that particular piece of equipment. So, and we just went through that same scenario, right? Could we please— like, absolutely you can have 4-hour timeout in your OR, because if I'm laying there, I don't want the screen going dark either. Exactly. Yeah.
Yeah. So what— are there any sort of big projects that you're gonna have coming out of these assessments that you know of already? Yeah, yeah, we got a lot. I mean, all the typical stuff, right, that you would expect. We need to deal with BYOD in a big way.
You know, when we worked at Kaiser, our doctors were employed and you could enforce a MDM on their mobile devices. At Centura, we have some employed doctors and we have some that are not employed, right? So then MDM becomes a little more difficult when you're trying to, you know, put that onto somebody that already has an MDM based on the organization that they work with, right? So that conflict. So how do we give them access without caring about the device that they come into us with?
So, you know, we'll be looking at that more probably from, you know, containerization and application control more so than device and device checking controls. So we have to look at that from an interesting way. One of the most wonderful things that I walked into at Centura from my predecessor was a highly zero trust type deployment in that organization. So we have whitelisting deployed extensively on almost everything that we possibly can, excluding medical devices that won't allow us, but some will. So yeah, surprisingly enough, some will.
Yeah, so we have, you know, good protection. Things don't execute So we don't— we're not chasing things from that standpoint, but I think we still have a visibility gap. So we'll be working on the visibility piece, make sure that things are behaving in our organization the way we would expect them to behave.
We're good on the 2-factor front, but we could do better on the privileged access management. So we will be working on some things there to shore that up. Down. And security awareness. Yeah, I think security awareness can be better, more touchy-feely, you know, that seems to work out well.
We've got a lot of facilities, they don't see our faces much, so we'll probably go on some campaigns a couple of times a year in each of the facilities so they know us. You're gonna dig out those, those old laptops back from the Stone Ages and take those around and and show people how it's done? Gosh, yeah, I don't think those same things back then would work today, and I'm a little stale on being a script kiddie. I would bet that some of them would still work today, as sad as that is. Yeah, you're probably right, right?
Oh my goodness. Yeah, so things like that, improving vulnerability management and remediation governance, getting a better risk view of things. We didn't have a risk management practice before, so we're developing those, you know, to do more of the governance, the vulnerability management, the policy stuff. It was being done, but it was, you know, everybody had a little piece of the pie, and we're gonna provide a little more concentration so I can get my metrics back and start showing the pretty graphs to the board. Yeah, you know, everybody likes to think about how cool and sexy certain parts of security are, but then, you know, you come in and you look at something, you're like, oh, we need to do all the unfun and the people and process parts.
You know, we have to have better governance. We've got to have, you know, better policy, process, procedure, all this kind of stuff. Yeah, none of that, you know, shiny blinky box hacky stuff. We're gonna, you know, we got to do the things that can really move the needle. So yeah, yeah, right.
If you had talked to me early in my career, I would have been on the blinky light side of things.
Probably my big change was in the— probably First Data, you know, really working for the corporate organization organizations and really talking about risk management and governance and kind of what that can do to an organization as far as moving the needle, as you said, makes a big difference for sure. Yeah. So I know one of the other things that you've been involved in in town is the Women in Security group here. Yep. So I'm pretty sure most people know about that group and what it does, but why don't you give us a little background and some of the stuff that's been going on over there?
Well, my involvement in Women in Security, I have all thanks to you, Alex, right? You introduced me to Sarah, and she just really came in with— through Logarithms and said, hey, we did this out in Kansas City, would like to start it up here. You knew I had an interest in kind of that mentorship And that really came from when I left Kaiser. What I didn't realize there, you know, I'd mentioned before coming in as a principal and then being the deputy CISO, is when I chose to leave the organization to take on that full CISO role, was there were a lot of people, a lot of women especially, in the organization kind of keeping a pulse on me and my career there. As someone to aspire aspired to, to see somebody come in and go through and become an executive at the organization like that in a short amount of time.
I think, you know, I didn't realize those people were paying attention. So I really did get a lot of feedback from folks and, you know, actually still chat with and mentor a lot of folks from there today.
And I've always liked the coaching part of things. I've done coaching things in my past for, you know, high school students and stuff like that. So coaching, mentoring, helping people develop a career, you know, what that looks like for them, has always been an interest. So you introduced me to Sarah, and, you know, a few months later we had our first Women in Security meeting, and that was just a little over a year ago that we did that. So we've been holding quarterly meetings ever since and really trying to give a place for women in cybersecurity just to come together and network a little bit and get to know each other.
That's really the primary goal of what we're doing. So we try and make sure that we give them content that's relevant to their career and a little more tech-focused And then the next meeting we might give them a little more content about how they grow their brand or, you know, same thing, the blinky light thing and then, and then, you know, the other things that are a little more touchy-feely. So, so we've, we've been doing that and been very successful. I think, you know, our average attendance is in the 70s to 80s each meeting. Which I think says a lot for the fact, because there are so many competing things that folks can do when it comes to attending after-work events, right?
For sure. And it's really hard when, you know, often you're a working wife or a working mother to be able to find time that you want to be able to do it with something that has a little bit of meaning and whatnot. So we've been trying to provide that. Plus we serve wine, so I think that helps. That's always good.
Everybody likes wine. Yeah, yeah. No, but it's been really great opportunity to get to know some of our younger folks. We've had a lot of interest and have been sponsoring some high school students that are participating in CyberPatriots. Yeah, right.
And they're doing those gaming trying to help them actually find internships with organizations. You know, we talk about a shortage when it comes to cybersecurity professionals, and, you know, if you have a willingness and you have some kind of talent or skill or knack for computers or cybersecurity, I don't see why we shouldn't foster that without the bachelor degree. Yes, right, for sure. And so we're working hard to kind of find avenues, companies that are willing, kids that are mature enough to come into the workplace. And I think that's where Women in Security come in, is we really try and help vet to make sure that, you know, if you are taking a chance on a younger individual, you know, that they have some ability to carry themselves in a corporate environment.
And then what we're really hoping to do is continue to provide that mentorship to that individual. So they're in here working for you, Alex, right? And they might be too timid to ask some questions, so they always have us to fall back on and, and to be able to talk through whatever it is that they're going through as they're trying to adapt to, you know, being in a corporate environment and working a real 9-to-5 type job. So, so it's, it's for women in security, I think it's that ability to provide that guidance, that mentorship, get their interest in and try and keep them engaged in cybersecurity, and, and then, you know, help our community by building more and more folks that might be interested in the career field. Yeah, and the internships are so important right now because we're at this weird time in our industry where there's a bit of a catch-22, I think, right?
So it's— we have this— people keep saying there's this big skills shortage, right? We don't have enough people, we need more people to do all the stuff we want them to do. But then you look at even entry-level jobs that are supposed to be the bottom of the ladder, right? This is where you start. And yet for those bottom-level jobs, they want people with experience, and, you know, they want you to have done some security stuff before.
So it's like, how do you get those entry-level jobs to get the experience if you need to have experience to get the jobs to get the experience?
And then with the internships, which is great, I've seen more and more pop up. But there's just only so many that are out there. So, you know, I think that they're super important. You know, I've had interns the last couple summers and it's been great, but I think, you know, we need even more than that. So it's great to see that you guys are helping push that too.
Yeah, yeah, and I think we as leaders, right, need to support it. It can be inconvenient, I get that, right? And so maybe what we've talked about in Women in Security is for those organizations that don't have a program to deliver them something to follow. Yeah, right. To build the content that says, you know, here's kind of the way that you bring in an intern and be able to make that meaningful for you without you having to reinvent the wheel and figure that out if you haven't gone through that process before.
Right. So really what we're trying to do is help build some tools to make it a little bit easier to, to go down that path. Because yeah, we do need more folks, good folks. You know, get them engaged early, get them interested early. You know, hopefully they'll stick around for a little bit.
Exactly. Yeah. Or get them somewhere, you know, for someone else that needs that skill, right? Yep. You know, I've had that, you know, my 2 interns that I had this past summer both now have full-time jobs.
That's wonderful. You know, so they, we didn't have a full-time spot here for them, But, you know, they stayed with us for the summer, got some experience, got real jobs, and now they're helping somebody else. Yeah, it's a great thing. It is a good thing. So we are just about out of time.
Anything else that you wanted to cover before we wrap this up? No, just been loving what you guys have been doing. You know, thanks for asking me to be a part of that. I appreciate it. And yeah, It's the Denver community I appreciate a lot when it comes to, you know, supporting each other within this space, right?
It's a pretty open, transparent community. You don't often find that, so it's fun to be a part of. Awesome. Well, thanks, Nancy. Thanks.
Appreciate you being here. Yep. And this has been Colorado Equals Security, and we will talk to you next time. Learn more about the Colorado security scene at coloradoequalssecurity.com. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.