Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 85 for the week of September 24th. Alex, happy weekend.
Happy weekend, Robb. Did you do anything fun? Yeah, I got a chance to go see the KBCO concert over at the Breckenridge Brewery. I got to see Cake play. That was a fun concert.
Nice. That's the group that sings like Cake by the Ocean? That one? No. Going the Distance.
Oh, Going the Distance. Short skirt, long jacket. Hey, that's a good one. Comanche. Yeah, it was fun.
I had a good time. Good stuff. Sort of coincidentally, coincidentally, I was nearby. I was actually eating dinner while that concert was going on sort of next door. Yeah, I was, I was wishing you were there.
We were missing you. And I was wearing my Colorado Equal Security shirt. Nice. Did you get any, any comments? Anyone?
No, not a single one. I actually on Friday night was at the Columbine High School homecoming game and ran into Cole Krebs. Nice. Yeah. Was not wearing my Colorado Equal Security shirt, but he recognized me.
I have now put a magnet on the back of my car, the Colorado Equal Security magnet on my car. So if you see a little white car driving around, It's probably mine. Uh, also there's a, uh, right now a political ad. I can't remember which one it is, but my car goes through on a highway scene. And if you look really closely, you can see the Colorado Equal Security magnet on the side of my car.
Can we get that on the website? Uh, probably. I'll, I'll define it. Although then are we endorsing whatever political ad this is? I don't know.
I don't even know what it's for. It's just a picture of me driving on the highway. That's, that's fantastic. Hey, let's, uh, do a little bit of housekeeping. Hey, let's, we have a, we have a Slack channel.
This is a great place for you to come join, uh, chat with 500+ of your favorite Colorado security professionals, get to ask recommendations, talk about whatever random stuff's going on. We also have a mailing list, so if you go to the website colorado-security.com and sign up there, you will get emailed every week with the show notes, so you'll know exactly when the new show is out and what's in it. So, and if you think the only way to listen to this show is by manually downloading the show every week, have I got some news for you. You can subscribe And this will come directly into your, uh, into your player every week. And, and of course you can rate us and say nice things about us on wherever you get the show from.
And if you really like the show and wanna make sure that it keeps going, you can join our Patreon campaign and provide us with, uh, some funds to keep the show going. So, uh, there's more info on that on the website, colorado-security.com. Uh, if you sign up for at least the $10 a month option, then you get a t-shirt and a shout out on the show. All right. And I guess I'll just do a quick shout out.
We do monthly CISO dinners for those who are security leaders in town. Take a look on the website if you're interested in getting involved. And we're always looking for sponsors for that as well. Sounds good. Speaking of a good weekend, this weekend was the Great American Beer Fest.
And Colorado was well represented there, right? They were. They had took home 30 medals from the judging, including 16 gold medals. We finished, uh, second place to California in terms of total medals overall. At least it wasn't to Austin.
Yeah. Uh, Texas was nowhere near us on that, on that list. Right. Uh, but congratulations to the Colorado brewers. And of course, congratulations to all those of you who have a hangover because of spending the weekend at the Great American Beer Fest.
Yeah. And, uh, if you were one of the people that tried all 8,800 beers, uh, please let me know. I will give you a medal yourself. I think that they probably need a blood transfusion more than they need a medal. All right, moving along.
Colorado's Interstate 70 has ranked in the top 5 for highway routes for driverless truck across the United States. Yeah, so be on the lookout since I-70 between Utah and Kansas appears to be the 4th best route for driverless cars, or excuse me, driverless trucks. Don't be shocked when you see a semi driving down the road with no one sitting in the driver's seat. It looks like basically the idea here is what are the places that have low enough volume but enough— high enough safety that they could actually go driverless? Number 1 on the list is I-5 from Northern California up to Vancouver, which is a place I grew up.
And it's just this long, desolate highway. It makes perfect sense to me. And, you know, I-70 going through the mountains maybe doesn't seem quite so simple, but Um, the rest of it makes a lot of sense. Yeah, you would hope that they would test though that stuff because they're going to have to go through mountains and you wouldn't want it to start failing if you only test it on easy spots. Anyway, uh, next, uh, Techstars and Western Union is teaming up with a new innovation accelerator in the Tech Center.
That's pretty cool. Both companies are contributing $120,000, um, and that they're going to be investing in any startups that come out of there and, and giving them the resources to get going. It's pretty cool stuff. Yeah, and so it's an accelerator focused on fintech and payments technology, obviously, since Western Union is involved. Uh, yeah, pretty, pretty cool.
They're trying to, trying to innovate wherever they can, and I love to see the partnership between 2 native Colorado institutions. Similarly, Arrow Electronics is working on building a Colorado Open Lab in their headquarters that's going to advance smart city technology. Yeah, it looks like this is a place where both private and public groups can come together to test new technologies. So if you're a government or someone in the public sector that's looking to use smart technologies, and you're a private company that has some of those technologies, you could come together at this lab and do your testing. Yeah, it's great to see Arrow taking a leadership role in that.
It looks like the lab's going to open up in mid-2019. So look for news on that. Hopefully, we'll have some cool stuff coming out of the lab. And in some big acquisition news, Adobe is going to buy Marketo for $4.75 billion. Billion.
So Marketo makes marketing software. And while they are headquartered technically in California, they did bring a big presence here into, into Denver, and have, you know, really stepped up their efforts here. And so it's interesting and good for them to see this acquisition. Yeah, pretty cool stuff. Congratulations to Marketo there.
They were previously owned by the same equity firm that owns Ping. So we know the folks over there a little bit and we've talked about some open security positions there in the past as well. Good, good job for those guys. Also, side note, this is the biggest acquisition ever by Adobe. Wow.
Didn't know that. $4.7 billion. Adobe's doing really well. They, you know, we might think of them as the Flash Player people, but they're, they're killing it right now. There's lots of PDFs out there for people to view.
There you go. Moving along, we have a top 100 MSSPs list, managed security service provider list, and 4 Colorado companies made the list. Optiv, InteliSecure, Route 9B, and Virtual Armor all made an appearance. And that, I think, is about all we have to say about that. I'm not sure what the criteria was, but congratulations to those folks for being on the list.
Next, Red Canary had a blog this week detecting MS-XSL abuse in the wild. So MSXSL, which is a mouthful to say, is a, an application, Microsoft application that does XML transforms. And apparently there are some ways that you can abuse it. So the, the blog post talks about that. I love it.
Our next blog post is with one of the luminaries from the Colorado Security Podcast, The Burden of State Data Privacy Laws, a Q&A with, with me from, from Ping. So this was just a questionnaire talking about what is the impact of the new state privacy laws, where— how is it going to push companies to different behaviors? I will say before you open this, it's super boring. Um, this kind of the, the format for the question and answer, it's not real dynamic, but hopefully some interesting information for those who are newer to the state privacy laws. I will say in the article they call Robb a cybersecurity expert, so clearly he has someone fooled.
Well, you know, all you have to do is just, uh, have someone ask you a question or two, and as long as you don't say, uh, then you're an expert. Yeah, good job. Next, Zavelo had a blog this week on malicious cryptocurrency mining. This is actually pretty interesting if you have an interest in that subject. Zavelo, of course, makes URL filtering lists that basically categorize URLs, and they mentioned that they have categories now for this type of behavior.
But the, the article itself goes through you know, what cryptocurrency is and what mining is and, you know, how malicious activity works in these areas. So interesting article, not super technical, but a good overview. Yeah, good stuff. Our last story here, CenturyLink has hired a new chief security officer. So we've talked in the past about both Dave Mahan and— oh man, help me out— Dale Drew, who moved on from CenturyLink recently, and they've now replaced those guys and the new gentleman is named Chris Betts.
I, I don't know Chris, but he's starting as the chief security officer, officer there. He previously worked for Apple where he headed security architecture and engineering for their products. And previous to that, he worked in security intelligence roles for Microsoft, CBS Corp, and the NSA. Wow, that's good credentials there. He sounds like he knows some stuff.
In the article, it does mention that he is moving to Colorado or has moved to Colorado, so we'll have to reach out and say hi to him. Maybe we'll get him on the show. Maybe. If anyone knows Chris, I know Brett listens and Mike listens. If you guys can get him on the show, let's do it.
Sounds good. So that's it for the news. Let's move over to the Slack Message of the Week. Again, thanks to Andre Gaeta for sponsoring the Slack Message of the Week. He gives from his own pocket merchandise for those folks that we award.
Awesome. So this week in the random channel, I had asked for some advice on birthday ideas for my wife, who has a big birthday coming up here in the next few days. And this award goes to Matt Parks, who— Matt responded to my reply by saying, make sure it's not too good because she has a lot of birthdays in the future and you don't want to set the bar too high. So for helping us all keep our expectations low enough in life, Matt, that's the Slack message of the week. Good job, Matt.
We'll get you in contact with Andre and you can get your Colorado Equals Security swag. All right, let's move over. We have a calendar of events on the website. Go out to colorado-security.com and check out the events. This week we have a few things going on.
On the 25th, the Denver Business Journal has their C-Suite Awards celebration. Also on the 25th, there is a GDPR meetup, Encryption for GDPR Compliance: Fact or Fiction. NCC has the Cyber for Executives event on the 26th. On the 28th, SecureSet is doing one of their capture the flag events. On the 4th of October, SecureSet has their Expert Series with Chris Martinez.
Also on the 4th, uh, LockedIn, which I believe is a cyber insurance company, um, is having their Mountain West Cyber Day. And then finally, Colorado Springs has their Cybersecurity First Friday event on the 5th, which is the cybersecurity social and mixer. Yeah, if you're down in the Springs, that should be interesting. Maybe we'll try and make it down there one of these days for that. It's with their local business development group.
Yeah, good stuff. All right, moving over to jobs. There's a couple jobs at Ping Identity this week, one working for me, which is our cloud security architect, looking for someone to help us who's got great experience in AWS security and, and knows security architecture. And a new job that's not reporting to me this week is an API security product marketing manager. So this is someone who does product marketing for our new API security product.
You guys have heard us talk about this on the show recently. And actually, one third job there, which I don't have on our list in front of us, Alex, but I'm gonna put in the show notes, is we have an application security or product security engineer role, which is application security that we're looking to hire on my team as well. Nice. We mentioned Western Union earlier. They are hiring a senior manager for information security incident response.
Transamerica is hiring a manager of IT and information security risk management. RiverPoint is hiring an IT security manager. Journey is hiring a security architect, and they're also hiring a cryptographic software engineer. Why would a, you know, '80s— I've got more than a feeling about this.
Splunk is looking for a security market specialist. Zillow is hiring an IT compliance analyst, and FireEye is looking for a principal penetration tester red team. Pretty good stuff. A lot of good jobs going on this week. Well, Alex, that takes us to the end of our, of our newscast.
We do have our feature interview this week with Vance Brown. Vance is the new CEO over at the National Cybersecurity Center, and I know you sat down with him just a few weeks ago, right? I did. Yeah. So we had a nice discussion, talked about what's going on at the NCC, uh, the direction that they're heading.
So it should be a good interview. Did you guys talk about the blockchain? We did talk a little bit about the blockchain. Can't wait to listen. Yeah.
All right, well, that's it. We'll talk to you next week. All righty. All right, bye-bye. Thanks, Robb.
This is Joshua Foltz, CISO at eFolder. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is Alex Wood, and this is our feature interview for the podcast. We've got some very special guests today. We are recording from the National Cybersecurity Center down here in Colorado Springs, and I have the pleasure to speak with CEO Vance Brown and CEO of Exponential Impact, Hannah Parsons. So thanks to both of you for joining us today.
Appreciate you taking the time. Thank you for being here. Yeah, thanks, Alex. So I think to start off, I'd love to hear how you guys got to where you are today, maybe a little bit about your careers and what you've done, and then we'll kind of jump into the details about NCC and Exponential Impact. And I guess, Vance, you can start.
You start? How far you want me to go back? When I was born? No, that's fine with me. No, no, no, that would be pretty boring.
So, well, most of it was pretty boring, but let me start. I actually started, you know, undergraduate degrees in economics and computer science. I've been in technology for a long time, but I didn't start on the technology side at first. I actually started as an intellectual property attorney dealing with technology and intellectual property. But I got very early on the bug of being in— actually in technology, but not so much from the legal side, but from running software companies.
So I started my first software company in really my late 20s, moved out to Colorado in my early 30s, and ran another software company here in Colorado Springs, which was called— had different names, but Goldmine Software.
We did both IT help desk. Originally it was Bendata, then it became Goldmine. We did both help desk software and also contact management software. It's funny, my uncle ran a software business and I interned for him for a couple summers. And you used Goldmine, right?
And I used Goldmine. Of course you did. It was a very popular product back in the day. Why we didn't then take that and move into Salesforce, I don't know, but hey. Anyway, the progression.
Then yes, I started a software company with 2 others called Sharewell Software, and we do service management. It's also a platform for building any kind of application on. We have customers in 40 countries and partners in 30 countries. We're very proud that Sharewell Software employs almost 500, is actually headquartered here in Colorado Springs. So, and then from that, when we really transitioned to what I call a growth stage of an international company, a scaling stage, I stepped down and was honored and excited to become the CEO of the NCC.
Awesome. So, so what, what was the, the security piece that drew you into NCC? Because Not that you weren't working with security, but it wasn't a direct focus for you from security, it sounds like. Not totally, although very closely related, because what is a cyberattack? It's an attack against IT.
It's a digital attack, and what a service management system does, it takes any kind of event, which could be an event of an attack or noticing on the network that something's going on and creating an incident response and then change management, resolving that and figuring it out. So we were always very closely tied into cybersecurity. But to answer your question more specifically in terms of the why, just very early on, I started thinking more and more about, oh my gosh, everything today is digital. The Internet of Things, where things are going, because I have been in technology now all my life. I've run 3 technology companies.
And so just as things evolve and you see how dependent we are as a society, as a world on the internet, and you realize what can happen with breaches and attacks. So early on I knew it was a big deal, but we certainly now consider it to be the number one threat facing our country and facing the world. So the mission is easy to explain how important it is. Awesome. So Hannah, how about you?
What brought you to where you are today? Well, I similarly, I had an undergraduate background in general business and actually in international business and always thought that that's what I would do is go run businesses somewhere not in the United States. And then ended up doing my master's degree with an emphasis in entrepreneurship because I've always liked the idea of it and starting things. And when we moved to Colorado Springs about 14 years ago, I ended up being self-employed for most of those years, either had a real estate business and then worked in various kind of consulting areas of helping people generally start, fix, or change things, I would say. Kind of in a kind of a— I fell into a little bit of a change management role for several different organizations.
At the same time, I kind of got the community engagement affliction that is, you know, really working in a lot of boards and and different things like that to help build and shape the community. So I worked a lot with the Downtown Partnership Organization and then with— ended up being recruited to work at the Colorado Springs Chamber and EDC. Okay. And that was in 2015. And so I started working in that capacity, really rebuilding and shaping the government affairs policy roles there, and then took the role of the Chief Economic Development Officer there.
So all of my background had kind of become not about building companies, but building place. And so, and that's something I really enjoy doing. So we worked with the— I worked with the Color Springs Chamber and EDC on a new economic development strategic plan for El Paso County in this region. And one of the gaps that was really identified was the pace and funding of startups in our region compared to some of our peer cities, the rest of the state. And so I had also— one of the things I had run and co-founded in 2011 was a co-working space in Colorado, in downtown Colorado Springs.
So I had always been trying to connect and plug in with and support the entrepreneurial community in some way. So when that was pointed out in the strategic plan, it wasn't a surprise to me because we've known that there have been some gaps in the ecosystem here. About the same time was— that collided about the same time was what Vance was telling you and his being able to step away as CEO of Sharewell. And so my, my time at the, in the strategic planning process for economic development with his exiting that everyday role of Sharewell collided where we knew like, well, okay, this is a part of this strategic plan. This is a gap we can fill.
And so those 2 things happened at the same time. We happened to work really well together. And so we decided to go for it. Awesome. So I think our listeners probably know what the NCC is.
You know, we had Ed Rios and Jennifer Ferta as an interview probably about a year ago when, when they were running the NCC down here. But for those that don't, I wonder if you could just give a quick description of what the NCC is and then, Hannah, what exponential impact is. Certainly. Sure. National Cybersecurity Center, if I had to use 3 words, it's secure the world.
We're not arrogant enough to think we're going to do that alone, but we can be an important part of the— I call it an engine for an ecosystem, and an ecosystem actually can. I think that ecosystem started here in Colorado in terms of the governor's vision. After a trip to Israel, he had a vision of how do you bring industry, education, and really government together to solve something together. And so he said, after what he saw in Israel, he thought we should set something like that up in Colorado because he believed this was a very fertile ground for doing something like that in terms of the synergies. And so that's exactly, if you look at those 3 pillars, that's, you know, expand upon it a little bit, but how do we secure Secure the World.
Think of the NCC as a— we're a 501, independent, objective— think of us as a think tank or an institute. You can also think of us as an engine to this ecosystem. And then if you look at these different pillars from the government standpoint and military, shaping public policy. So we've done things like testify before the Joint Technology Committee on what is blockchain for when they're considering blockchain legislation, for example. We're going to be doing— we do a lot of training of elected and government officials, as an example.
We do think we can influence public policy. We have one of the largest and I think best cybersecurity conferences. There will be a lot of elected officials. Last year we had multiple governors attend so that we can really increase awareness related to cyber in the government and military arena. When you look over at what we're doing in the way of— with education, well, if there are— I've heard anywhere from between 1 million to 2 million jobs that are not being filled that need to be filled in the way of cyber in the workforce.
So workforce development is crucial to securing the world. And so we work there in the way of really supporting supporting University of Colorado Springs, UCCS, as the lead institution called out in the legislation that was passed and signed by Governor Hickenlooper. And so they're the lead institution, but there's a consortium of about 20-something universities. And it's not just universities because, you know, they're degree programs mostly. There are a lot of other types of programs from community colleges, etc., that, you know, how fast can we figure out what the workforce needs and then fill that.
That's a big part of it. Then finally, industry for us is all about certainly working with industry and cyber awareness for industry, but it's then also creating this entrepreneurial network of bringing security technologies into our region. Of course, that's Hans' role with exponential impact. You're good at segues. I do want to jump into a lot of that, but before I do, Hannah, so what is Exponential Impact and how does that play into all this?
Absolutely. Entrepreneur— sorry, Exponential Impact is really, it's a nonprofit organization. So it's a separate 501 that was established to really support entrepreneurs that are in the security space or emerging technologies related to security. So AI, blockchain, cybersecurity, other types of security, Internet of Things companies. Early-stage companies.
So it's designed to help them find access to capital, provide mentoring, growth, physical space, those types of things. So the flagship program of Entrepreneurial— of Exponential Impact as an entity is the accelerator program. So we just finished our first cohort of accelerator programs. So we invite teams to apply for the program. They come in, they receive funding from our partner fund.
So they, they give up some equity, they get some seed funding, and then we run them through an accelerator program, which is— in 2018 it was 11 weeks long, next year it'll be 14 weeks. But during that time they go through a pretty intensive curriculum development process, coaching, mentoring, and it ends in Demo Day. So we just had Demo Day on August 17th. Oh nice. Where then they were able to pitch to investors and to the community.
So with the goal of one, helping those companies grow. If we can keep them in Colorado Springs, awesome. If we can keep it in Colorado, good enough. But overall, we want to help grow these companies and emerging technologies. And does that include some physical coworking?
Is it part of the program? You have to be all in, say, here in the building or wherever it is that that is located? Yes. So in 2018, our space here wasn't built out at the time. So we have operated— we actually worked in 2018 in partnership with Colorado College and ran a lot of programs in their Hibbel Community Center, which was fantastic.
We also partnered with Epicentral Coworking, which I no longer own but is located downtown. So some of the teams were working out of that space. So it was great because we were able to run the first program kind of immersed, immersed in the community. And then by the 2019 cohort, we'll have the space built out on the campus here. Awesome.
So jumping back to the NCC portion, so when we talked to Ed and Jennifer, they laid out their vision and the pillars that had been set up for the different areas of the NCC, which sound similar to what you just laid out, Vance. But I know that there's a number of differences and, and a bit of a change in strategy since that. So I wonder if you could talk about, uh, how the NCC has evolved, uh, over the past year and what are the differences in focus. Yeah, I'd say at the core, we're, you If you think about us as a think tank, as an institute, in fact, we're modeling a lot after, if you've ever heard of the Help Desk Institute, it's probably the top institute for IT professionals in the world, chapters all over the world. My business mentor who originally hired me here in Colorado Springs, a guy by the name of Ron Munn, started the Help Desk Institute right here in Colorado, in fact in Colorado Springs.
So I've seen that model. It's a membership-based organization and funded by the membership supported by the membership, very much a think tank, very much respected from that standpoint. So that's just in terms of, you know, that's a thread throughout in terms of how you might look at us. I mean, in terms of tactically some of the differences, like, yes, we had some pillars before that touched upon some of these. I would say we're not in the rapid response business because we don't, you know, we want to partner with industry, partner with universities, and educational institutions partner with the government military, but we don't compete with any of them.
And for instance, rapid response, which we've done before, felt like that's, you know, they're— that's industry, they're doing a good job there, so let's not, let's not take that on. So, so I'd say it's moved much more towards a more of a think tank rather than providing those kinds of direct services. But, you know, in terms of membership, you know, we We're doing a lot to provide a lot of services, so we have both corporate memberships and individual memberships. And I think you're going to see more and more that you don't have to be a cyber professional to realize that you need to know something about cyber and have some of the benefits of being a member in a cybersecurity organization. So we're trying to find more and more benefits, training, etc., related to being an individual member and certainly a corporate member the same of What do our employees need to know related to cyber awareness?
What's appropriate for different people in the organization? Also, all the way to— we have a course coming up here in September, Cyber for Executives, where we'll have, let's say, board level, C-level coming in. What do they need to know? There ought to be more and more of a duty and standard of care. And that goes, you know, that's that, and that goes into our whole public policy too.
So that's just a high-level thing. I would say also we're very, you know, big into— if the 3 pillars are those 3, you know, let's call it our foundation is related to innovation and character. So we do a lot of character, and in fact we have a program for K through 12 of, you know, building this mindset of not only awareness for kids of this type of career, but we're trying to grow and build white hats for the cyber world. That's a good thing. That is a good thing.
On the think tank portion of it, is that being driven by expertise that you guys have in-house, or are you pulling in members of the community, or how is it that you're driving the ideas that are coming out or are going to be coming out of that part of it? Well, first of all, it's very early like everything else. Obviously with some leadership change and with some new funding that we've just— that we're getting now through this via, you know, by way of the state through UCCS, we hope to work with different corporations. For instance, right now we have a signed agreement for doing a think tank with Cisco. We haven't really, you know, worked on the details of what exactly that's going to look like, but yes, we'd like to involve financial organizations, accounting groups, technology companies to participate in our think tank.
And to, you know, but we feel like the big thing we can do is ask the questions that everybody's wondering and then get obviously smart people in a lot of different organizations and collect that, gather that, facilitate that, and disseminate that. I could see the output of that being research papers or other policy statements, that kind of thing? Right, and absolutely research is a big part of what us along with UCCS— in fact, part of this building is going to include the Cyber Institute right next to us. That's actually driven by UCCS, but certainly we want facilities and to collaborate with those that do research. So that will be some through universities and obviously some through the corporate community.
Then on the education side, you mentioned the skills gap, the people gap. I've started to see this interesting sort of catch-22 that we have right now. We've started to ramp up education of people, more cybersecurity education in either higher ed or even in primary education, master's degrees popping up, other things like this. But what I see in industry is even for the most entry-level positions, they're looking for people that have experience in cybersecurity. So you can't get the experience.
Yeah, so it's a chicken and the egg. Is that something that you guys are looking at, and are there ways that you see to help with that? Yeah, Hannah wants to speak to that. I think as part of the overall ecosystem, what you're going to start to see both within— this is where it's going to be really nice to see the partnerships with NCC and UCCS and even Pikes Peak Community College— is the opportunity for a large number of apprenticeship programs. And so I think because often internships don't give students enough time to really qualify as experience.
So employers don't look at an internship as legit experience. But if you put somebody in a 2-year apprenticeship program with graduated pay— and I know the state funding that came through for that, that Vance referenced earlier, includes requirements for a certain number of internships and apprenticeships. And I think that's this— that's the problem they're trying to solve. Yeah. So is that something that there is a plan in place for already, or that this is being developed?
The apprenticeship, it's being developed. Because it has to be, because, I mean, some of the funding metrics require those. And I think, I mean, it tends to be the way that I think a lot of groups are looking at how to develop more apprenticeships, the more European models. I mean, the state of Colorado has something called the BEL Commission, the Business Experiential Learning Commission. So the state Department of Labor, together with the Office of Economic Development and International Trade, identified this as a problem within the security technologies, but other industries as well, and that people are not— that skills gap is wide across the board.
So the state has already been looking at this, of trying— and so I think Colorado is on the front again of looking at how to develop apprenticeships, not just in traditional industries like manufacturing, but how do you take those and apply them to these other areas where we really have these large gaps. So I think you're going to see them, a large number of these apprenticeships across for security technologies. And then I assume it would be some sort of, you know, public-private partnership where you're getting companies in who are willing to have these apprentices for a time. Yes. Yeah, well, yeah, I think you're gonna see companies want to be the ones who want it the most because they have the hardest time finding employees.
So if they can get somebody at a graduated pace, you know, generally they're earning, you know, it's that earn while you learn kind of program. So if they can get them in early, then they have a much higher chance of retaining them. And then you're seeing a lot of, I believe, you know, even with the city, you know, the chamber and the EDC and some of the studies they've done along with, you know, related to like the military that come in. And, you know, like let's say there you can have a very good military career and have a technical background from that, you know, from your military career, but then you come in and there may be some transitional learning that can occur. It doesn't need to be a 4-year program or a master's degree degree.
It's what do you need to augment what you already have in terms of technology related to cyber. And so there are programs like that also. Awesome. So I think you mentioned a couple of the programs that are coming up soon, educational events and other things like that. What are other things that we should look forward to seeing coming out of NCC in the near future?
Well, certainly this month We have the Cyber for Executives program. We have regular, we've had regular classes, for instance, for our community on like blockchain and what is crypto and that's the first application on blockchain. What is blockchain? And we really want to be, we've laid down this, the gauntlet that we want Colorado to be the most well-informed blockchain state in the world or state in the country and then as far as an epicenter for that. Because we believe blockchain, for instance, has huge implications for security in the future.
I mean, it's got a lot of maturity to do, just like the internet did early on, but we see it as a key component potentially of cyber database protection. So we've been doing those kind of classes. We've been doing some other cyber awareness classes for companies. So you can really get on our website and see what you can be a part of. By the way, members get to come free.
So that's a benefit. We have that Cyber for Executives coming up this month on October 7th, 8th. Is that right? We have our Cyber Symposium. General Michael Hayden is going to be a keynote along with Governor Hickenlooper on our first night.
So that's going to be— we will have elected officials, education, business. I mean, that's where we all come together as far as the ecosystem. And learn together and celebrate together and explore together and ask a lot of questions together, but it really is going to be a phenomenal event. We believe certainly one of the top events in the country this year for cyber.
I was going to ask you more about that conference. Who is this aimed at? Who would you expect to come? Is this your normal line-level cybersecurity people? Is this executives?
Executives? Who really should come and participate in the conference? You know, it's not intended for, let's say, the highly technical. It's not that. It would be for really everybody else.
So it will be from elected officials to business executives to managers to educators will be there. So it really looks at the ecosystem, but it's not so tailored for the, let's say, in-depth technical aspects of cyber, but more of the— from the public policy to the workforce development that we're doing to cyber awareness. And you said this is in October. Is this a 1-day, 2-day? It's 2 days, 7th and 8th.
It's at the Broadmoor here in Colorado Springs. You know, if you know of the Space Symposium, which Colorado Springs is very well known for, you're going to see a lot of parallels to what we're trying to build, something similar to be a cyber And really the ecosystem they've done there with their foundation and what they've done as far as facilities here in Colorado Springs. You expect to see something similar. So we're modeling some of the things we're doing after what they've done so successfully. Awesome.
You also beat me to the punch on one of the questions I was going to ask, which was why blockchain?
So I'm glad that you brought that part up. I think it's always been a little bit of, I don't want to say confusing, but I was always curious about the reasoning behind why the NCC was going down the road of blockchain. And it sounds like the thought is this could be something that is very important and transformational, and we want to have security involved at the beginning of that. Yeah, I'd say, you know, in its essence, we're, you know, I said our foundation is a a lot about innovation, right? And you got to look at what are some emerging technologies that are coming out.
And blockchain is definitely one that we get very excited about. I mean, at its core, you got to think about what is data protection. And today, data protection is about a single point of failure. There's a single point of failure in all databases in the world today of how Equifax stored its data. You know, if you— it's the economics of it.
If it's more expensive to attack— to defend than it is to attack, then you're in trouble. And whenever you have a single point of failure, a single database that can be attacked, you're in trouble by definition. And you have to figure out what can change the rules of the game. Well, blockchain is about decentralized, decentralizing these databases so that instead of attacking one, you might have to attack thousands if not millions of nodes in order to, you know, in order to attack the database, right, successfully. So just that core thing of single point of of vulnerability versus decentralized, at its core, that alone could change the rules of the game.
Again, a lot of work to do, it's got to scale, but anybody that wants to bet against technology and how it evolves and matures, good luck with that. It's changing exponentially and we're seeing it today in terms of the Ethereum platform. And again, we're very excited that Denver had the top blockchain, let's say, conference. It was a hackathon last year. It's going to be another one this year.
I mean, Colorado really is becoming that blockchain epicenter, and we're really excited about that because we see just at its essence that simple way I described a single point of failure versus decentralized. That alone can be game-changing where it changes the economics of an attack. Yeah, for sure. And Hannah, I don't want to leave you out. Uh, what should we— in fact, Hannah's on the blockchain, the governor's blockchain council.
There you go. Yeah, perfect. Um, so what should we expect to be seeing from Exponential Impact? What do you guys have coming up? Uh, you did mention that you're going to have another cohort here coming up here.
Um, if someone is an entrepreneur, should they reach out to you? They absolutely should. So we, we are still working with some of the teams who just finished the first, uh, program, and applications will go live for the new 2019 accelerator program. They'll go live in November, and we will— and people can go to our website exponentialimpact.com to apply, to find out more about the program. But definitely that would be the great opportunity for people who have an idea that they want to see if they can— if they need a little bit of seed money and want to see if they can launch their business, that would be a great opportunity for that.
And then because this is our first year of operation, we're now starting to roll out some programs for those that, you know, so it's not just an accelerator program. So you'll start to see year-round programming for people. Some people that have approached us are interested about, from outside of the state of Colorado, interested in seeing how they can grow their startup in Colorado because of the security assets that we have in the region. So wanting to know if there's a way to work with DOD or how do I tap into the talent pool or into some of that. A lot of people from out of state have contacted us about what are the opportunities there, so they should contact us for those things as well, even if they are not interested in the specific accelerator program.
Is there content or things going on for people that maybe aren't entrepreneurs but maybe want to be involved? Absolutely, absolutely. In fact, we plugged— I think one of the things that was really successful about the accelerator program this year was we plugged so many of those companies in with the the greater business community. And initially some people think they don't have a lot to offer, they're not a good mentor for a startup. But what they don't understand is they're still businesses.
So they still have to have a customer base. They may have a product people are interested in using. They may have a— some specialty area of knowledge that they can contribute to some of the entrepreneurs about how they're growing their business. So definitely. And I think that's part of what we want to do is we want to involve the larger community, not just in Colorado Springs but in the state about how do we build an entrepreneurial ecosystem that really connects and drives innovation, grows companies, invests in companies here.
So that's the goal. So people, I think, of all— whether they're entrepreneurial or not— can still be a part of it. Awesome. Alex, one thing I'd like to add, if you don't mind, about blockchain, because once people start talking about blockchain, I'm sorry, it's your fault, but we really get excited about it. Something the NCC is involved in, as some of you know, in the last session Colorado passed blockchain legislation, Senate Bill 086, and that really sets a requirement that state agencies have to at least look at the cost-benefit analysis of can we protect our state records using blockchain, to at least consider, right, consider the use cases.
But there's a use case that we're involved in that we're really excited about that I think have not only national but global impact. And just helping with the elections. The biggest thing today you hear about when you hear about cyberattacks is interference with our elections. Our democracy is at risk when we don't trust our— when there's any suspicion of impropriety related to our election system. So we're just exploring.
It's one of the things that we're doing as the NCC is that's one of the first big initiatives we're looking at as an application, obviously in more of a prototype perspective, but can we use blockchain in, say, a very isolated, for instance, maybe deployed military or whatever, to be able to vote using the blockchain to experiment? And so that's something we're working in and excited about, but that's the type of things we're doing from a think tank/public policy/ blockchain perspective that we think is real important. Awesome. Well, we're just about out of time, so I wanted to just see if you guys had any other comments, questions, anything you need to bring up before we wrap up here. I appreciate you, Alex, and what was your partner's name?
Robb. Robb, that you guys would like— I mean, look, cyber awareness matters, and we can't solve this if we don't ask the questions and start having the dialogue. And we're about that. I'm just thrilled to know that you guys are about that and the state's about that. And so I just appreciate what you guys are doing to secure the world too.
Awesome. Hannah, any final— Yeah, likewise. I think the same. And I think people have been waiting to see what's going to happen overall with NCC and the whole ecosystem that people were talking about. And I think I would tell people to stay tuned because I think people will be really excited about the things that are coming in the next year.
So awesome. Well, thanks you two for your time. I appreciate it. This has been Colorado Equals Security, and we will talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.