All episodes

Alex, Robb, and Andre celebrate #100

Apple Podcasts Spotify SoundCloud

In this episode:

Robb, Alex and Andre Gaeta talk 100 episodes of Colorado = Security. News from: Radish Systems, Apple, Hosting.com, Red Canary, Ping Identity, DarkOwl, Webroot and a lot more!

What’s the traditional gift for a 100th anniversary?

Millennials can’t even afford bowling in Denver, yeesh. But there’s been a lot of investment in Colorado lately. The state got a new CIO to go with that new governor. The Woz got in trouble in Boulder and made it benefited us all. Hosting and Hostway are merging. Red Canary and Ping Identity have blogs we like this week. DarkOwl talks dark web. Dale Drew makes some predictions. And Webroot wants to make sure your students know what tech to take to school.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript18886 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 100. 100.

100 for the week of January 14th, 2019. Alex, congratulations. Thanks, Robb. Appreciate that. I have to insert some sound effects here with like fireworks and, yeah, you know, noisemakers, all that kind of stuff.

I did a little bit of searching to see what's the traditional gift for the 100th anniversary, and believe it or not, they don't go that high. Is it a casket? Hey, they actually stop at 60, which seems a little, a little conservative to me. Yeah, you would think maybe, I don't know, 70, 75. I mean, if you get married at age, you know, 16, which, you know, 100 years ago people did.

Yeah. You should be able to get to the 70th anniversary occasionally. 80th anniversary occasionally. You would think so. Yeah.

Well, hey, this is, this is fun. We have a fun interview later today with Andre Gaeta interviewing us. Right. Talk about the show and what it's been like to do 100 episodes of this. But, you know, generally we have a normal newscast today.

And maybe we should have, you know, something even more spectacular than we are, but really it's just business as usual. It's, it's really hard to believe there could be something more spectacular than this. Well, Robb, here's to another 100 episodes. Another 100 episodes. Uh, and, and this time we can do it in, in half the time.

There you go. Let's, let's pick it up. Uh, all right, let's go into, so we have some housekeeping. Uh, there is a Slack channel. We'd love to get you guys engaged in the Slack channel where, uh, you can come chat with, with other security folks from, from Denver and all across Colorado.

There's even some folks from outside of the state. We also have a mailing list. Sign up for the mailing list if you want us to sell your information to marketers. Oh, no, no, no, no. Just kidding.

We don't do that. In case you want to get the show notes in email. Also, we have on the different services, we'd love for you to rate us, tell everyone how wonderful the podcast is, and of course, subscribe through those services. Get your automatic downloads. And if you want to support the show and let us, you know, help us offset the costs of running the show, we have a Patreon campaign set up.

And we— number one, big thanks to our current patrons. Uh, we really do appreciate you guys. Thanks for continuing every month to, to give to the show and help support us. None of the money we get from that ever goes into our own pockets. It goes directly back out to the community through the podcast, through the, the hard costs of hosting and all that stuff.

Uh, and we would love it if, you know, more of you'd be interested in supporting. And if you are unable to support through financial means, we would love you to support us by just telling a friend, passing along the message. Tell everybody about Colorado Equals Security. Send them to the website colorado-security.com or have them subscribe to the podcast. Awesome.

Well, moving forward here, our first story is that there is a— there's a survey of the top 100 or the top largest cities in the United States looking for what is the most active city in the United States. And where do you think Denver came in? I would have to say we came in number one, Robb. You'd be right, except for the cost of bowling in Denver is just too high. What?

I know this is, uh, this is maybe not what I would have thought of as the number one prerequisite for an active lifestyle, but cost of bowling was one of the things, and that one got hit pretty hard here in Denver. Uh, I think there are a couple other things that help drive it down as well. The number of Little Leagues per capita, number of pickup soccer meetups per capita, public golf courses per capita. That, that one really surprises me because we have a lot of golf courses. Yeah, well, but I think the places that are sunnier probably your Phoenixes and Florida and things like that.

But it is $6.12 per game for bowling, which is pretty significant. It is significant. I have to say, I have experienced this myself. It is very expensive to go bowling in Denver. There is another element to this survey, which is around the cities with the lowest percentage of physically inactive residents.

I think you could also say the percentage of most active residents. We prefer double negatives. Yeah. And Colorado Springs was number 3 on that list. Denver and were tied for 4.

So really, the 3 big cities in Colorado made the top 4 list. If you're interested, number 1 and number 2 were Seattle and Portland— actually Portland and Seattle. Next, in 2018, there was $1.6 billion of venture capital that was lent out, which breaks a record for Colorado. That's pretty awesome. And in Q4, Denver saw $207 million in VC funding, and Boulder saw, uh, $136 million.

So those numbers were up from $187 million and $67 million, relatively so, respectively. I mean, a little, little tick up in Denver, but nearly doubled in Boulder. That's pretty crazy. Yeah. And then they went through the list of the top deals from 2018, and a couple of those were security companies.

Yeah. So, uh, CyberGRX in the 4th quarter raised $30 million, and ProtectWise raised $15 million. So I think we've talked about both of those when they, when they happened, but again, good news to see more and more venture capital happening here in the Denver, Colorado area. And it's good to see that those, those deals were actually among the biggest in the state. They weren't just big for security.

Next, you know, we talked, I think we talked on the podcast that Suma left as the CIO for the state of Colorado. She left a little bit ago and she's now been replaced. We know with a new governor coming in, he has named a new CIO to to be, you know, the head of his technology group. And her name is, I'm not sure if I can say her last name, Teresa Szczurek, maybe? I think that's a pretty good guess at that.

And she's leaving Radish Systems, which is actually a fairly good-sized tech company here in town that I didn't know. I came across this as a part of the press release. But she's gonna be going over there and hopefully, you know, she'll be Debbie Blythe's new boss. And hopefully that's a really good thing for both of them. Yeah.

Glad to have someone in that role now for CIO for State of Colorado and get that moving under the new administration. Next, we— so this is not news, just to be fair, but it's interesting. Okay. It was, it was a news article. So I guess that counts as news.

The course of human history could have been altered if only CU Boulder was a little bit more forgiving in the amount of computing time that they would give people. So Steve Wozniak, who was the co-founder of Apple Computer, originally enrolled and was taking classes at CU Boulder in computer science. And apparently, he ran into a little bit of trouble there. Back then, for those of you that were not around in those times, you actually had to pay for computing time. And he apparently, I don't know, was a little overzealous in the amount of computing time that he used and racked up what could have been quite a bill, around $50,000 worth of computing time, which then drove him to drop out of CU and go back to California.

His professor thought— said that Woz was out to get him and suggested that he was going to make Woz pay that $50,000 bill. That's $50,000 in today's dollars. He was gonna make Woz pay that bill. Of course, he did not have the money to do it. So rather than come back and deal with the looming threat of this computer fee, he just didn't come back to CU and instead went out to California.

And I went to Berkeley, right? Yep. And ended up, you know, meeting this high school kid at the time, Steve Jobs, and ended up, you know, the rest is history. So this is an interesting story. I'm not sure why this came up right now, but Woz has actually been out to speak at CU.

He's had 2 of his kids went to CU. So he does not have ill will towards the institution at this point. I think it said he has a scholarship there as well. Yeah, pretty cool stuff. Yep.

So, you know, it could— he did get his degree from CU eventually. It was one of those emeritus, right? Right. He didn't, he didn't actually have to earn it, but you show up and give a speech and they're like, here you go, here's a degree. Here's your degree.

Maybe one day I'll get one of those too. Hey, here's an extra degree. But, you know, it could have been that, you know, while Boulder is a great startup community now, it could have been if he would have stayed, you know, Apple Computer could have been founded there and would have been a lot different. Yeah, very different. Anyway, next story.

There is a merger for one of our local companies. So Hostway, which is not a Colorado company, is merging with hosting.com. We all see hosting.com right there on I-25 in one of the old Gates buildings there. They're merging. There's not a lot of details yet on what this is gonna look like.

Couple of facts. Number one, they haven't said what the joint go-to-market name is going to be. I think it's gonna be Hostingway. Hostingway, I like that. But they did say that the CEO from Hostway is gonna be the CEO of the new org.

Organization. So, what, you know, does that mean there's going to be a couple of headquarters, one headquarters somewhere else? We don't know the answers to those things yet. Yeah, but it sounds like they do similar types of things. So good synergy between the 2 companies.

It also said that they're going to be running as separate brands for a little while until they figure out exactly what that go-forward is going to look like. Next, there was a Red Canary blog this week entitled Detecting All of the Things with Limited Data. How's that possible? Uh, that is a good question, Robb. Uh, no, if you read the blog, they're talking about, um, some basically some blind spots or difficult things to detect, uh, through EDR and other products like that.

Uh, basically known vulnerabilities, known attacks that the, the current set of tools that you might have have a difficult time of detecting. So it's a good thing to know those things so that you can potentially look out for 'em. There's not a whole lot of detail in there about how it is that you can better detect them outside of EDR, but you know, you can always go talk to Red Canary and I'm sure that they can help you out with that. All right, next we have a blog post from Ping Identity this week. It's actually a guest blog post from a Google engineer talking about JWT security.

So, you know, neither of us are necessarily the experts on JWT security, and I will tell you what, this is an expert-level blog post for those of you who are looking to actually do this. This is a really good resource. So in the, in the blog post, they go into a number, number of different things you might want to consider when you're doing security for your JWTs. They look at symmetric JWT signatures, asymmetric JWT signatures, JWT validation beyond signatures, cryptographic key management, using JWTs in practice. And then they also very interestingly provide a cheat sheet on JWT security to help keep track of this stuff.

So if you are going to be doing it or you have a team that's going to be doing JWT security, It's a good resource. So Robb, I have a very important question for you. What's a JWT? JSON Web Token. Oh, hey.

And it's basically just a token that's being used for access validation within an application. Yeah. You could have written this blog, Robb. Oh man, no, I couldn't. It is very detailed, so I'd suggest taking a look at it if that is your area of interest.

Next, we had a blog post from Dark Owl. I don't know if we've ever had a Dark Owl blog post or news item on the, the show before, but Dark Owl is a, a threat intelligence company, I guess you, you would call them. They, something of a reboot from, from Owl, right? One World Labs. Yeah.

Where they're using the intellectual property that Owl had created. I think Owl went bankrupt or somehow restructured. Yep. And became Dark Owl. But so they do things like mine data on the dark web and other things like that to provide you threat intelligence.

So this was, Basically a look at the Kickass forum, which is an underground forum. And is that your favorite underground forum? It kicks ass. And the potential takedown by law enforcement of the forum. So there's a lot of detail in there about what they were looking at to determine what was going on with the forum, other things like that.

Again, this is if you're into threat intelligence, if you're into looking at dark web research, this is probably an interesting blog for you. Yeah, it's cool to know that there is a local company doing that kind of work, um, and, you know, publishing what they find. So that's fun. Up next, we've had a lot of predictions articles already, and in fact, like, I, I think I— we didn't put a couple in this week that got posted. There was one from Pang, and I think there was one for ProtectWise or somebody else.

You scared? You don't want to put your predictions out there, Robb? I feel like there are a lot of prediction articles out there. So, you know, well, we did pick one more because this, this one is actually not from a company, it's from a local security guy, right? Uh, Dale Drew posted his, uh, his own security predictions out on LinkedIn.

So I feel like we should definitely hold Dale accountable for whether he hits on these predictions. I think he needs to like put some money down on the table. Hey, I'm putting my own personal reputation and financial wealth behind this. Yeah, I think that's only fair. So just now going through the topics, I'm not gonna go through all the details because he actually did quite a few.

Privacy regulations will be a significant distraction to the actual security in 2019. I would say I would agree with that in the sense that there will be a lot of focus on privacy regulations in 2019. Next, zero-trust environments will continue to grow. That's not much of a— that's not going out on a limb there, right? That's going to happen, but it's awfully hard to measure, and I do think it's going to keep growing, though, as well.

It says, turn the dial to 11, and really what he's saying here is the attacks are just going to continue to increase, that what we saw in 2018 more and more of those things this year. Cybercriminals will continue to use big data analytics to target you and corporations. Nation states will increase their investment in cybercrime. The rollout of 5G will make it compelling for the first mobile DDoS network. Not something I had thought of.

This is kind of the first one that popped up here that I'm like, oh, that's an interesting, interesting perspective. And why is my phone slow? Oh yeah, you're DDoSing Amazon. Yeah. Maybe I shouldn't have installed that app, right?

Attacks on cloud providers will grow. Authentication and authorization will be tied to your phone more in 2019. I think that's absolutely true. The more and more we can use all these different data we get about people, the better authentication is going to be. Supply chain security will become your new core competency.

And finally, we will reach critical mass of cybersecurity solutions. Requiring a more ecosystem approach to security. Sounds like what we've been saying every year for the last decade. Yeah, I think, uh, I don't know if it'll reach critical mass. I think more likely there will be a market correction and the market will contract as opposed to us realizing that there's too many solutions.

I don't know if that will happen in 2019, but I think that's more likely to be what would happen anyway. That sounds lame. I don't want that to happen. I don't want it to happen either. Next, there is a Webroot blog, The Must-Have Tech Accessories for Students.

So the first thing I thought when I saw this headline was, why would I care about this? And then when you actually look at the blog post, the must-have tech accessories is like security skills. So they go through what are the security skills that you really need as you're going off to school. And really, if you have a student, I think sharing these— there's some basics in here and there's a little bit more advanced stuff that you can share to help people be secure. Yeah, awareness for one thing, just, you know, general awareness of security practices.

2-factor authentication, I think, yeah, that's very, very important. Multiple passwords, I think that— not sharing your password— could be read as better password practices. Yeah, and then they have the kind of— those are the basics, and then they have the deeper dive. They go into antivirus software, password managers, message encryption, and virtual private networks. Um, you know, teaching your students about these things will help keep them secure and probably keep yourself secure as well.

Cool. So that is the news. Let's move over to the Slack message of the week. Again, big thanks to Andre Gaeta for sponsoring the Slack message of the week. Not only, uh, this, but you'll hear more from him again, as we mentioned in our, our interview coming up.

He interviews us for the, the 100th episode, but, uh, we, he sponsors this, provides it out of his own pocket. Gets an award to someone on the Slack channel who provides some good content that week. Yeah, and it's been doing it for over a year, every week for over a year. So Andre, we really do appreciate that very much. Recognizing this week's winner, Douglas Brush.

Douglas received one of those text scams that pretends to be from the CEO saying that they, you know, hey, I need gift cards, go buy some gift cards for me and send me a picture of them, you know, scratch off the thing on the back and send me a picture of them. What was amazing about this, number one, is he, you know, he, he tried to scam the scammer, keep him engaged in that fun. I ended up using Douglas's scam text message as a security awareness email to my whole company because it made me laugh, and I thought I could make some other people laugh as, as they enjoyed it as well and got some awareness about these attacks that are going on in the wild. Congrats, Douglas, Douglas, and we'll get you connected with Andre to get your prize. Alright, so as a reminder, we have an event calendar on the website.

2019 is absolutely getting started with a flurry. There's a lot of things going on throughout the entire year right now. We have a lot of stuff in January, and you'll see as we go through the next 2 weeks' events, there's a lot going on. First on the list, CSA is having their January chapter meeting on the 15th. On the 16th, CitySec is doing their January meeting.

I think that's at the Wine Coop. Um, I think they have that scheduled. Uh, they did post a note in the Slack channel though that the 2 normal leaders are unable to attend due to some conflicts, and they're looking for someone to step up and, you know, just be that person who, who hosts and welcomes people to the table. Um, so if you can do this, if you, if you want to attend and, and just be that person to help make this be successful, jump over to the Slack channel and let folks know so, so they can, uh, they can lean on you there. Yeah, I think it's a pretty low overhead responsibility, just making sure that if someone who's wandering around looking for the group of security people, you wave them down and say, hey, come over here.

Yeah, pretty good. Uh, next, uh, the National Cybersecurity Center is doing a meet and greet on the 16th. Uh, also on the 16th, SecureSet is doing one of their capture the flags. On the 17th, ISC² Denver is doing their January chapter meeting. Same day, on the 17th, the CTA, the Colorado Technology Association, is doing one of their Insight Series, Keeping Up with Innovation.

The 2019 top emerging technologies to watch. I'm sure blockchain and AI made it on there somewhere. Only AI blockchain, not the regular blockchain. Next, also on the 17th, ISACA Denver is doing their January chapter meeting. On the 23rd, the ISC² chapter down in Colorado Springs, the Pikes Peak chapter, is doing their January chapter meeting.

On the 24th, SecureSet is doing an information night at Swimlane. Kind of fun that they're doing a meeting there. That is cool. Also on the 24th, there is a Splunk meetup, Boss of the SOC competition. And finally, on the 25th, the CTA is doing a meeting, office hours with Davis Graham and Stubbs and the Foundry Group.

So Davis Graham and Stubbs is a law firm, and they're going to be doing monthly meetings either downtown Denver at the Davis Stubbs or whatever it is, uh, law office, or in Boulder at the Foundry Group office. And it's a chance for entrepreneurs or potential entrepreneurs to come ask legal questions and, and understand, you know, what, what are my legal exposures? And since it's going to be, you know, partially with Foundry Group as well, you know, there's probably some really good access to smart entrepreneurs who know how to do this stuff. Yeah, that sounds like a really great opportunity if you're thinking about a startup or some other kind of entrepreneur. Let's move on to jobs.

Uh, we have a couple jobs this week from Ping Identity. Yeah, so number one, we've talked about it a couple weeks in the past, but, uh, at Ping I am hiring a manager of security operations and engineering. If you're interested in that, I'd love to have you reach out and, and talk to me. This works directly with me, so I, I'd love to get to know you. Uh, number 2, we are hiring a GRC analyst.

This is someone— it's a more entry-level role— someone to help support our Compliance efforts around SOC 2 and ISO also help with vendor risk management, business continuity, incident response, kind of all the typical business continuity— excuse me, GRC internal focus stuff. Next, Charles Schwab is looking for a managing director of cyber resiliency. Western Union is hiring a director of application security and risk. CableLabs is looking for a VP of security technologies. Red Canary is hiring a director of intelligence.

Elastic is looking for a senior security analytics and detection lead. There are actually, I don't know, 5 or 6 jobs at Elastic that were— yeah, there's a bunch. Adams 12 is— 5-star schools is hiring a cybersecurity engineer. PDC Energy is looking for a security GRC specialist. And finally, GuidePoint Security is hiring a systems administrator.

Sweet. I think that's it for, for the news this week. I think it is. We're all newsed up. Now you're gonna hear, you're gonna hear a sound effect shortly of a, of a cork popping.

It's not a sound effect, it's real. It real, it actually happened. Yeah, good stuff. All right, well, that's it. We'll look forward to talking to you again next week.

Hopefully you enjoy the interview. All right, on to the next 100 episodes. Thanks, Robb.

This is David McGuire, Director of IT Security at QEP Resources. This is Colorado equals security. For Colorado security professionals, by Colorado security professionals.

Happy 100th.

Well guys, happy New Year. Happy New Year. Happy New Year. Happy New Year to everybody. Cheers.

Cheers. Cheers. Cheers. And also happy 100th episode. Thank you.

That, that pop, the popping of the cork did not sound as, uh, poppy as we expected, maybe. No, no, it did not. But for the listeners out there, we are raising a glass of champagne to celebrate the 100th podcast. That being said, I think I want to start by just saying thank you guys on behalf of the entire Colorado Equal Security community. What you guys have built is very unique and there's really nothing else like it.

And I think we all have to take a giant step back and think about the efforts that go into making this possible. Um, I think everyone knows, but this is not the only thing that you guys do, right? You have demanding jobs. You both travel. You have families with young children and after-school programs, and you spend weekends on the football fields and soccer fields and after-school programs.

Uh, and it's important to note too that, you know, this has all been funded mostly out of your pockets, right? The mics, the stands, the cables, the software, the gear, the domain, the hosting. Um, so for the community that benefits, I think a collective thank you to you guys for building this and keeping it going is, uh, is due. So, you know, cheers to you guys. At least we didn't have to fund the champagne.

Thanks for that, Andre. Yeah, Andre, we, you know, one of the reasons that we asked you to do this interview is, is because you've been such a supporter from the beginning of the show and we, we've appreciated that the whole way through. Um, obviously as a, as a patron of the show, but also, you know, doing for a while it was the trivia question of the week and then, um, doing Slack message of the week recently. We, we really appreciate your help to to drive, uh, this, this movement forward. So thanks a lot for what you're doing.

Yeah, I think that the support you have given us really has helped with the engagement and getting people involved. So cheers to you as well. Oh, thank you very much. It's been my pleasure and it's been a ton of fun. So, so that being said, um, I get to be the boss today and I'm not the boss very often, but I get to be the boss today.

So I get to, to ask whatever I want. And, um, I'm going to start with like, I think for the listeners out there, Let's get to know you guys, you know, personally. I think one of the things about this show that's enjoyable for me and for the others that I've spoken to about you guys is some of the banter. But you guys have known each other for a little while, so I think it'd be interesting, right, for you guys to share a little bit about how you guys met. Like, how did we get here?

And give us a little bit of background.

I'm trying to remember exactly when it is that we first met. I remember the first time I met you in person. Is I was like, wow, I leave an impression. Yeah, I was, I was a guest. I think I was a member, but it was my first time coming to an ISSA meeting in quite a while.

And you, you were the president of ISSA at the time, and, or you were about to become president. I think you went around to all of the people at all of the tables and said hello and shook hands. And I was one of those people. So you walk up to me and introduced yourself and said, hello there. Which is funny because that was something that I really made a point of doing when I was president.

I think ISSA was, was really sort of the common thread between us, definitely at the beginning. And, you know, I, I was ISSA president, the, the chapter was floundering a bit and I, I had to do all the stuff that I could do to, to try and build that up. And one of those things was to try and, you know, make nice with people. So if you showed up to a meeting, I was gonna come over and say hi and, and, you know, shake hands, kiss babies, all that kind of stuff, try and get people to come back. So he was really, at the time, I, I am something of an introvert by nature and, and his, Alex is, coming around and saying hello and, you know, kind of just, you know, being willing to step out there and do that made an impression on me.

And shortly thereafter, I sent an email to the, to the website. And I think it was while Paul was still president because the email actually went to Paul. Paul Herpker was the president before Alex. And I said, hey, I'd like to volunteer. And what I was thinking was I was going to get something like, hey, um, why don't you come, you know, like stuff envelopes or, you know, sit at a table somewhere.

And what the reply I got back was, here's the 3 board positions that are open. Which of these 3 do you want? A little different than stuffing envelopes. You know, it's funny that it was a similar thing that happened to me too, starting at ISSA. I went to a meeting and, uh, you know, I, I thought, oh, this is, this is great.

And Paul asked, Paul was president then as well, and asked for volunteers. I said, oh, this is great. And I, I also sent an email and said, hey, can I, can I help with something? And he said, oh, hey, we're, we're doing this conference and there's no one volunteered yet. To help with organizing the Rocky Mountain Information Security Conference.

You're in charge. So, guy I don't know, here's the biggest conference in Colorado for you to go run. Exactly. So roughly what year is this? Like circa— I think it was probably me and you was 2010 or 2011.

I'm not sure which one. Yeah, it was, I think, 2008-ish for me when I got involved with the chapter. So what were some of the driving reasons that you got involved with ISSA? Clearly you've been in information security for a while, but Why ISSA? Yeah, so I worked at IBM for a long time, and IBM is a very big company.

There are a lot of security people internal, so I had lots of security contacts at IBM. But I, at some point, I realized, hey, I, I don't know anything outside of, of IBM. That was my first job, was with IBM. Um, and so I thought, hey, you know, I should probably know some people that are in the community. There's actually someone that I had worked with that was on the board of ISSA.

He had left IBM at that time. Um, and he said, hey, you should come down and, uh, and, you know, check the meetings out. And actually it was a meeting where, uh, where Chris Triolo was, was speaking, um, someone who Andre and I both know. And so I went down and I thought, oh, this is interesting. There's some people here.

Maybe I'll get involved and, you know, go to a few meetings. And that's kind of how I got involved, but just try and, and learn what the community was and to get involved outside of the company that I was at. Yeah, so, so Robb, let me ask you a question. Yeah, how did you get involved in information security? Like, like, did you go to school for it?

Did you just wake up one day and say, I want to go do this? Or were you voluntold like so many people, like, hey, go, go do this thing? Yeah, so I was— I had an IT career for a decade or so starting in '98. I was doing IT through probably in the 2000 4 timeframe, I, I really got involved with some, some systems that had a real security bent to them, and I started to have to understand security better. So I, I installed the, the wireless network for an enterprise.

I did SSL VPNs, and I did BlackBerry Enterprise Server, if you guys know that stuff. And I had to learn security through that. So I kind of picked up the new tools that were security-focused because there was already an Exchange guy, there was already a SQL Server guy, and I could be the guy of the new tools. But then in 2008, call it 2008-ish time frame, I really was at, at a point where I did not want to be the guy, um, responsible for patching the systems and logging in to reboot servers in the middle of the night. And I had this, you know, career decision to make, and I want to go in a different path.

And the paths that I was looking at were project management or security. And honestly, it was almost as much a coin flip as anything else that, you know, as I looked at those 2 paths, what career opportunities were in front of me, where were the Where were there good jobs? And I saw better opportunities with security and I went and got my CISSP. After I got my CISSP, I did some Google searching like, well, what's the, what is the networking? What does the community look like for security?

And that's where I found ISSA was that I found ISSA and ISACA at the same time. And I, I tried out both groups. Um, I went to a couple of meetings of both. ISSA was much smaller in Denver at the time. Um, and had a, it was a little easier to get connected and really focused on security more than ISACA's audit community.

And also not nearly as boring as all those auditors. I wasn't gonna say that, but that might have been going through my head as well. So, so, um, you know, we, we've, we've reached the 100-episode mark, and, um, for those that, that watch a lot of TV, that's a significant milestone in TV. Uh, in TV, if you make 100 episodes, right, then it's usually about 5 years and you get syndicated and it becomes a It becomes like money. Are we gonna get syndicated, Robb?

It becomes a commercially successful enterprise. Clearly, drop some news on us that you sold our syndication rights. So, so there's been some commercial success here for you guys, depending on the measure. But, but that being said, what was the genesis for starting Colorado Equals Security? Okay.

So, you know, I think it really does go back to both Alex and I's experience in ISSA. I would tell you, before I got really involved in ISSA, and just as some background, Alex was president for, what, 4 years? 4 years. And I was the president directly after Alex. So we had 6 years between us of running the chapter.

And before I started in ISSA, I would have said to you, maybe there's, I don't know, maybe there's 1,000 security people in Denver and maybe there's 50 CISOs across the network. And, you know, I could find all of them. That made my very naive understanding of the community. And as I got into ISSA and I started meeting people, and we did Rocky Mountain Information Security Conference, and we did, um, you know, just other engagements with other groups, I started to, you know, continually every month be surprised by either this new group of people who were doing security conversations in town, or this new company that sold security solutions, or this new event that got together. And, and I kept saying, well, how could I possibly have known about this?

Right? How could I have known that there was a group of people in Boulder doing, doing, you know, meetups to get together and talk about security or the 303, you know, the hacker type guys that we have in town, that, that whole issue that we're a part of ISSA, we're part of this chapter, which by the way, we love ISSA and the ISSA Denver chapter is amazing. 800-ish members at this point, biggest chapter in the world. We love what ISSA is doing. But the security community in Denver is so much bigger than that.

It's, you know, what did we come up with? Like 18,000? Yeah. I think that was the last number that we saw was 18,000 people. And we started to realize that what we were doing with ISSA is never going to touch, you know, a significant percentage of that 18,000 people.

And then that's fine. Right. Um, ISSA is focused on a certain group of people and there are, there are other groups that are doing different things that are great for the groups that they're attracting, but we needed you know, there's a market for somebody to come in and sort of put an umbrella over all of those things, over the whole community, to talk about, you know, everything that was going on, not just groups, but startups, you know, all the people that are involved. There's lots more just beyond the surface there. So if you were coming into Colorado, if you moved to Colorado, which we want lots of people with security backgrounds to do, we want to bring in the top talent of security folks in the world.

Um, if you're moving to Colorado and you want to get involved in the security community, well, how do you do it? Maybe you've heard of ISSA and you look them up, but what if ISSA is not it for you? But if that's too, you know, shirt and tie for those folks, um, maybe they don't know that there is an OWASP chapter here. Maybe they don't know that CSA exists or the DENSEC. There's no DENSEC, you know, national or international charter.

So we decided what we wanted to create was a central place not to go create more meetings, create more ways to get together, but to really share and and amplify the message, the signal for the other groups that are already doing interesting things in Colorado. And that became both Alex and I's mission for let's finish our ISSA terms. He was on the international board at the time and I was doing the Denver chapter. So let's finish that up and then let's really focus on more broadly letting the Colorado security community really talk about what we do here. It's been impressive to see the results in the community change and the participation continuing to increase.

Both in the Slack channel as well as members, right, of Colorado Eco Security. You know, again, a testament to you guys and your passion and what you're investing personally, right, to bring the community together. As mentioned before, it's, it's not like anything I've seen anywhere else. I want to do a real quick thank you to Travis Shack. Travis is the CISO or Director of Security over at WellTalk.

Yeah, he's the one who came up with the Slack channel idea, and, and both Alex and I are like, it's a great idea, but we don't have a cycle to go do this. And, you know, he spent what, 10 minutes standing up a Slack channel, which may very well be the best thing that we do right now as a group. Yeah, I would agree. The Slack channel is awesome. If you're not on there, you should be there.

We'd been thinking, you know, for a while we need to have some way for people to converse. And I think Slack might've come up as an idea, but in my mind it was like, oh, this is going to be, you know, a lot of overhead. There's going to be a new thing, learn a new thing. There's going to be a whole bunch of administrative work with it. Um, I'm thinking about, you know, like chat rooms, we're gonna have to be moderating people and I don't want anything to do with that.

And then one day Travis is like, hey, we should have a Slack channel, I'll create one. And then it was like, oh, okay. And, and it's just grown from there. It's been awesome. Over 800 people in there, over 800 people in there.

It's great. So, so I've met people outside of the Denver community on Colorado Equal Security. As you guys know, I travel quite a bit and I work, you know, East Coast to West Coast and I've met people Houston, Chicago, other places. What do you know today is like the most distant member of the Colorado Equal Security chapter? I know for sure of a CTO who listens to us in Houston that I recently talked to him about it.

Do you, what do you know, Alex? Yeah, I don't know about, uh, about distant, but I have heard, you know, random things from people like, oh, you know, people who are, are, you know, trying to sell me something or, you know, things like that. It's like, oh, hey, yeah, I was in, you know, such and such place and they said, Oh yeah, you're from Colorado. I know Colorado equals security. And it's like, really?

The person out there listens to the podcast? That's crazy. We could probably go into the stats, the stats, and figure out where people are downloading. I think those are mostly Russian bots, though. Yeah, that's true.

You know, the Russians are monitoring everything. So North Carolina, I know there's some listeners from North Carolina. Shout out to you guys there. That's awesome. But, but I'm actually not sure of any international listeners.

So if you're an international listener, let us know. Yeah, we want to know that right now. That'd be fun. So I want to dig in more on you guys, uh, on you guys personally, and we'll pivot back to the, the podcast. But, you know, again, 100 episodes is, is a pretty big milestone.

You guys have spent a lot of time together, both in studio, out of your studio, at events. Um, so I, I want to start with you, Robb. What is Alex's most annoying habit? Oh man, annoying habit. Alex is amazing.

Uh, I, I, I don't think I'm going to give you what you want to hear here, Andre. Um, what, what Alex and I are able to do is, is really, uh, trust, I think, trust one another that, that when someone's going to do something, it's going to get done. And, and this is not either of our full-time jobs, as you mentioned earlier. So it's a, it's a, it's a challenge to, to figure out what's the right level of expectations, but always knowing if something said is going to get done. And, uh, Alex and I have very different skill sets and his ability to go after Um, you know, solving the problems that, you know, maybe frustrate me and I don't feel like doing.

Uh, and, and maybe I'll be the one who's willing to go, you know, run down that person or whatever. You know, we just kind of tag team on stuff like that. Uh, in terms of annoyance, uh, what, what do you do that's annoying for me? Uh, I want to give him something. I was looking for some good banter here.

Yeah. Well, you had one loaded. He's ugly. I give him that. So if you heard the podcast last week, you know, you could hear my kids make fun of me because I'm bald.

Um, uh, so, you know, there's that. He makes me look good. That's the thing is Alex took my job at Pulte and, you know, he comes in behind me and they're like, well, yeah, Robb really was a good CISO. The longer Alex is there, man, man, shots fired. Um, I'm hoping that next this is, this is going to come to me.

So I get to do the other side. So the next, the next question is, so Alex, what's Robb's most annoying habit? You know, I, I will echo the, the same thing that, that Robb said. I, I think we do work really well together. You know, before we started the Colorado Equal Security thing, uh, we, we sort of dipped our toe in the water of, of trying to see if it would make sense for us to, to start a consulting company.

And I, you know, I think through that we, we kind of learned each other's strengths and weaknesses. Uh, we also learned that it's a lot of work to do that stuff and, and, and it's a lot more fun to work at an actual company and, and not have to worry about having money come in the door and things like that. Um, But, you know, I think I'm probably a more conservative person. I will, you know, wait a little bit longer to do something, think about it a little bit more. And Robb just jumps right in.

And it's like, all right. Oh, should we do this thing? Maybe I'll— and then Robb's like, okay, we're doing this thing. I'm gonna start doing it right now. Let's go.

I've already started. Yeah, this— I did 3 things on the 10 steps that we're gonna do. Here's the 3 things that you need to do. So I sent Alex, I sent Alex a note a week ago saying, hey, what if we turn our December CISO get-together into a really massive event? And he's like, well, what are we trying to accomplish?

You know, how do we measure success for this? And I'm like, ah, this is too much work. Let's talk about it later. I just wanted to get together, have fun. Now it sounds like work.

Yeah. So I, I, you know, it's happened sort of organically, but I think Robb and I complement each other really well. You know, we get along. You know, we can give each other crap and not take it personally. We can spend a lot of time with each other and not annoy each other too much.

So it's been good. That's awesome. So again, in the interest of getting to know you guys personally, I'll start with you, Alex, this time. What is the most ridiculous thing that someone's tricked you into doing or believing? Oh, you know, I fall for phishing emails all the time.

You know, I've sent millions of dollars to Nigeria. Uh, the most ridiculous thing someone has tricked me into. Um, well, you know, you know, usually if someone, you know, dares me to do something or asks me to do it, they don't necessarily have to trick me into doing it. I'm, I'm usually pretty game for that kind of stuff. Okay.

Um, so, uh, I don't know. You ever made any really bad decisions, financial decisions or personal decisions that you wanna share with the audience? Yeah. Well, you know, I'm, I'm broke. I've given away all my money.

No. Um, you know, I, I can't think of anything great, but, you If someone is, is, well, right here, Colorado Equal Security thing. So, uh, when we started the Slack channel and, and Andre, you were giving away things every week from, uh, from our store. Um, the trivia, the trivia, trivia, the trivia stuff. You know, someone said, oh, hey, uh, we, on our store, we, we have a Colorado Equal Security thong.

So if you wanna buy a thong, you can, it's there. Um, and so someone said, hey, I'm gonna buy this thong and I'm gonna send it to Alex and he can wear it. And I'm like, okay, whatever, send it to me and, and I'll wear it. And then it's some, that person won and, and they got the thong and it never ended up with me until the Rocky Mountain Information Security Conference. Um, I, I believe it was last year.

And, uh, and I, for full disclosure, I did not wear it. Um, but we do have some pictures of me holding the thong, the Colorado Eco Security thong. So, you know, is that, that kind of goes along with, with your question, I think. Is that unfinished business then the actual Wearing it right now. Besides that, I've never worn it.

Well, it's a celebratory event, so I expect you to be wearing it. There's one more thing he needs to do, it sounds like, then, right? Yeah. Unfinished business. Unfinished business.

Robb, anything from from you? Yeah, I do. I my I remember my my dad telling me, and my dad was has always been like my role model for finances and how to handle a family's really money, right? And I remember him telling me. Either before I was born or when I was very young about them, like hearing about a really amazing investment opportunity from somebody trusted from work.

And he gave this guy some money and, you know, never got anything back. And that kind of, that was his way of learning a tough financial lesson. And I always wondered like, what was my way of learning a financial lesson going to be? And, and I haven't had a terrible one, but I did have one where I had one of those high-pressure ADT salespeople come to my my— then it was a townhouse that I had just bought. And like, you know, you know, fearmongering.

I was just— I just got married and talking about this. And I'm like, yeah, sign me up. And, and the numbers of what I paid per month was astronomical, right? Like you're paying installation fees, but it's half off because you signed right now, you know, all that. And, and I remember thinking at the end of that, like, I will never make this mistake again.

The, the whole short time, uh, you know, limited availability for some kind of service like that just makes no sense. And the fact that I, the fact that I bought into that, I, it's always made a difference for me. Every time I think about a decision in the future, I'd rather run the very limited risk of missing a limited opportunity than sign up for something that I'm going to regret for, for years thereafter. That's a good one. Yeah, no, absolutely.

So, so another one, um, before I, I move back to Colorado equals security. For the listeners, right, as they get to know you through the podcast, not everyone has the opportunity to spend time with you face to face. Robb, what is the most useless talent you have? Oh, well, as we were coming in here, I showed you guys my son juggling. Yeah.

I'm a very good juggler. I used to be able to juggle 5 balls. I can very consistently juggle 4. I could probably get 5 going if you gave me some room and and some time to get back into it. It's been a while, but as my 9-year-old son is getting into juggling, I'm like, you know, I'm getting a little bit, a little bit better at it again.

And, but I'm pretty good, you know, from a normal person anyway. And that's probably the most useless skill I've got. Well, juggling things, right, for work, right? You're juggling more than 5 things. So maybe it is useful.

But, but as, as your son continues to improve, my question is, do you now begin looking at like, you know, fiery sticks to juggle, to like keep one-upping him. Chainsaws. There you go. So bowling balls. So let's, uh, let's just get this out here, guys.

Juggling fire, not impressive to a juggler. Impressive to everyone who's not a juggler. It's really easy. Like it's a little teeny bit of the stick is on fire. The rest of it you could catch safely.

Juggling a machete, that's a much more impressive thing to juggle. I've got a scar to show you that I have juggled machetes. Um, wow. I've juggled hatchets in front of people before. Um, the, but really what I'm looking forward to with my son is when he gets good enough that we can start passing.

Passing, juggling back and forth. That'll be kind of a fun thing for me and him to do. That's awesome. We're not gonna get into it now, but I am interested in how you got into, tricked into juggling machetes. Like, I don't know how that happens, right?

Like, it seems like a bad idea to start. Like, hmm. It's a bad idea, yeah. Yeah, yeah, no. Kids, don't try this at home.

Yeah, that's why you have 4 fingers on one hand. Exactly. Perfect. Alex? Yeah.

So from my perspective, I don't consider it useless, but I think most people would probably consider it useless. I'm a really good bowler. That's what I did growing up. I spent a lot of time bowling. Not, not quite good enough to be a professional, but kind of on the edge of that.

These days, it doesn't really do a whole lot for me other than when I go bowling with people and I don't shoot 300, then there's lots of disappointment. Wow. How many 300s have you bowled? 8. 8?

Yeah. So one nice thing about Alex's bowling skills is when we, you know, one of the reasons you start your own company, just so everyone knows, is so you can buy your own swag. That's right. And it's all tax deductible because it's marketing materials. Everyone should have their own LLC.

So we have our LLC that we share. And when we decided, of course, we want to buy some swag for ourselves. We bought bowling shirts, which I think are pretty, pretty stylish and awesome. And he was very excited to have them. I was very excited.

Should we add those to the Colorado Equal Security store? Is that an option? Because that would be— we can look into it. We'll look into it for sure. Yeah, it's a little bit limited based on the platform we use, which products you can pick, but I'd love to have some Colorado Equal Security bowling shirts.

I think that'd be awesome. I'm all in. Count me in. So interestingly, If you were not in information security today, what would you be doing? What'd you want to be when you were a kid?

So, um, you know, it's funny you asked that back on the bowling part. Yeah. So, uh, I grew up, uh, my parents were both teachers. Education was very important. Um, I knew very early on I was going to college.

Um, I grew up in a, in a small town that had a, an elite liberal arts college. And, um, I thought, okay, well, I could go to someplace like this. But as I was in high school, I thought, oh, hey, you know, I would also love to go to college for bowling. It is a sport in college. And I thought, hey, I could go to someplace major.

It's not a major, but it's, you know, I could be on the bowling team. Is there like a D1, like, like the U of bowling? It wasn't when I was of that age, but it is today. So there are D1 bowling programs. You can get scholarships, all that kind of stuff.

Anyway, it's changed a little bit. But back in the day, Wichita State was, uh, was the center of bowling for college. So I thought, hey, you know, maybe I could go to Wichita State and, uh, and do bowling there. I actually had some friends in high school that went to, uh, some places to do bowling in college. Anyway, um, I— that would have been the other thing that I would have done.

Instead, I went to a small liberal arts college and, and got a degree and then, you know, went off into the workforce. So that, that's probably what I would have pursued if I hadn't done this. All right. All right. That, that sounds like it would've been a, maybe a little more fun.

Uh, maybe. You know, what's, what's the, what's the tenure like of bowling career? Like pro football players generally don't get into their mid-30s. Yeah. Yeah.

And certainly like infrequently into their 40s. Right. Like, like what's the lifespan of a pro bowler? It can be, you know, it can be pretty long. As you know, bowling is not a, um, high impact sport.

It's not a high impact sport. You don't have to be hugely athletic. The way I do it is, um, So, uh, yeah, there's a senior bowling tour. So, you know, you can go keep going on. Uh, could have been my career for a long time.

All right. I'll ask the same question of you, Robb. Uh, so what would I be doing if I wasn't doing security? Yeah. Um, obviously we talked about the IT path, the project management path I considered.

Um, but if you go back even further, I was a history major. So, so what did you want to do when you were a kid? Like, wow. I wanted to be a police officer when I was a kid. All right.

Like most kids. Yeah. I wanted, and I really wanted to ride motorcycles. I want to be like a CHiPs. You remember CHiPs, the TV show?

I'm from California, the CHiPs, you know, the highway patrol in California driving around on the motorcycles, stopping people. I wonder what orchestra— wasn't Ponch one of the characters? Yeah. Yeah. Now I've seen my fair share.

I wonder what the percentage of kids growing up in California that are our age are that wanted to be a highway patrol person was pretty awesome. Um, but if you fast forward from that, I was a history major in college. I had this vision of becoming a professor and, you know, being an expert on, um, Western European history and being able to teach that. I think when I, when I realized that I'm a white male, who wants to talk about white male history? That puts me in a very large group of candidates for jobs and really very competitive and something that I, that I decided not necessarily to go after.

I'm really fortunate that security came along when it did, and it's been a really fun career. But when I look for, you know, to the future, I, you know, anytime I choose to end up leaving security, um, or security decides it's done with me, either way, um, there's a lot of stuff that sounds interesting to me out there and really more about like broadening a skill set, becoming good at things that I'm just not as good at yet. Maybe it's sales or even something that's kind of random. Like maybe I'll become a locksmith so I can learn how to, how to get better at, you know, a real mechanical skill, lockpicking and helping people with that, or become a mechanic or working on cars. I don't really know exactly, but something that's just very different from what I'm currently doing sounds like kind of an interesting way to go in the future.

Yeah. Maybe new challenge, right? You know, new platform. It's interesting because you were interested in, in, you know, California Highway Patrol, CHiPs. And that's law enforcement.

And here you are in information security, which is right. Not that— not that different, right? There's a connection there somewhere. Yeah. Stopping bad guys, right?

That's right. There you go. Stopping bad guys. Just not riding motorcycles. I did ride a motorcycle for quite a while.

I had a motorcycle until my, my oldest son was about a year old. And then I realized I have not ridden my motorcycle in about a year. So we decided that that was a good time for me to stop wasting garage space for that motorcycle. And increase your safety as well, for sure. It's not very practical with a baby.

No. So I'm going to change gears and shift back to some stuff about the podcast and stuff about information security.

Alex, I'll start with you. As you think about what you do on a daily basis, what is the greatest thing about the position that you hold today for Pulte? You know, I, I've, I really enjoy it because I get to do a little bit of everything. Uh, you know, we have a, a small enough team that I get to put my fingers in all kinds of different pots. Um, I've worked for large companies where I've been very siloed and done a very specific thing all day long for months and, and years.

Uh, having that breadth to look at all different facets of security risk management, compliance, audit, all that kind of stuff. That's the thing that's the most fun for me is not being a one-man shop, but being small enough where I, you know, I can be in a little bit of everything.

Robb, I'll ask you the same question. Sure. I love, number one, I love the people I get to work with. So it's the people who work in the security team with me, and I have some just amazing people on the team. You know, there's about 25 people in security now, and all 25 of those people is significantly better at something than I am, right?

And that's, that's amazing to get to work with these people who are, who are exceptionally good at, you know, I have Ryan Ivis, who's the guy in charge. We are opening cans of beer now, everyone. It is, it is, is it officially afternoon? It is afternoon. So this is the right time to start drinking.

Getting to work with people like Ryan, who's an expert on infrastructure security and cloud security, and working with Steven Edmonds, who's the, the guy who does our privacy and GRC program, and Richard Cardona, who does my product security, the AppSec guy. But, you know, those guys are just amazing at something, and they're much better at that thing than I am, right? And that's really cool, really fun to get to learn from the people who are on my team. And then on the other side, I get to partner with the head of sales for, for all of Ping, or the head of products, the guys responsible for creating our identity products, the finance. I report to the CFO, getting to learn from him.

How does he look at risk? How does he look at, you know, what the future of the company looks at? It's amazing to get to work with these people who are just, you know, exposing me to a level of skill at things that I've never seen in the past. So, conversely then, right, it's not always sunshine rainbows and unicorns, uh, in the world that you live in. You can walk into the office on any given day, morning, afternoon, and, and it's, you know, chaotic.

What's the most challenging thing about the position you hold today, uh, at Ping Identity? The expectations are really high, right? I'm working with this very large group of, you know, 800-ish employees who expect um, excellence in everything we do. So, you know, we, we have the opportunity to fail, but man, you got to recover quickly. You got to, you got to move fast on everything we do.

And it's not always easy to move fast in this world of uncertainty. Security is a kind of a world of not knowing what's going on out there. It's a challenge to be able to move at the speed the business needs. And of course, anytime you have any kind of security incident and things really refocus very heavily on, you know, understanding the environment, what happened there, doing your due diligence on what does this security mean, this incident mean, your response, your recovery, all that stuff is a big challenge as well. That's probably the worst day of the week, right, is if you have some kind of an incident going on.

Alex? I mean, from my perspective, I think we all know that it is very hard to keep up with everything that is going on. The landscape is always changing. New vulnerabilities, new attacks, new technologies, whatever it might be. Lots of stuff that can keep you busy to try and stay on top of it.

I think that's sort of the fun part and the bad part about being in security is you have to know a little bit about everything. And it is always a challenge to make sure that you are on top of everything, at least at the same point or before everybody else is. What's always funny to me is when I've, if I've been at a place for long enough to say that the decision I made to implement, you know, that process, that technology, that vendor, that that decision now looks bad, right? To be there long enough to see, hey, I chose to implement vendor X's product and say, actually, you know what? That vendor is now stale.

And that You know, it maybe wasn't bad when I did it, but right now looking at it, you know, I sure wish I had a different technology doing that space. That's an interesting thing. And, uh, it, it really humbles you, right? To say, hey, what looks good right now, it's going to change. And you really need to be open to accepting that just because it was the right decision in January of 2016 when I went over to Ping doesn't mean it's the right decision in January of 2019.

Yeah. And, you know, having taken over Robb's job, I have to live with all of his bad decisions.

The most annoying thing about Robb, having to live with all of his bad decisions. Exactly. So, um, let me, let me ask you guys this question. What should the future of information security look like? Right.

It's, it's, it's an interesting time right now. You know, when I think about, you know, when you guys were getting started, when I was getting started, a lot of what we did was driven by compliance. Right? And it was like, hey, there's money for PCI. So we get money for PCI and we would spend it as meaningfully as we could, but try to save some to then go invest in other areas.

And compliance-driven security was a thing for a long time. Now, I'm not going to say the money is flowing freely because it's not, but it's certainly been a bigger part of the investment in the portfolio and we have board-level visibility.

One would say it has the pendulum swung too far to the other side, and is there a point of coming back to the middle? So what do you think, Robb, the future of information security look like— should look like? So before I answer that, can you answer for me how far into the future? Because I have, I have a couple different answers based on how far out we go. Well, so, so I mean, I was, I was kicking around the notion, and I don't want to influence your answer, it's not fair for me to do, um, but let's just say the next 10 years, right, right now, right?

And then let's say the next 30 years. And, and I don't wanna, again, feed your answer, but let's both answer 10 years first, and then, and then I, I have a different answer for 30 years. Yeah. Because, like, should we tear down the internet, literally, not IPv6, but, like, rebuild the whole thing? Because none of this stuff was built with security in mind.

I mean, so whether, whether we should or not, I'm not even gonna address because that's whether, whether we should or not is not, is not, is not fair. What I'm gonna say, what I'm gonna say is get well, as a security leader right now out there, what they should be doing is— and I know I said this when I moved to Ping, and I wholeheartedly believe it— zero trust is the future of security. And if you don't know what zero trust is, you'll go look up Google's BeyondCorp or zero trust from Forrester. There's stuff out there on the internet. The basic concept is, you know, just because you're plugged into any given network doesn't mean you have access to anything.

I don't want it to be that, hey, they're on the corporate network, So now they can get to our file servers or now they can, you know, make unauthenticated queries to whatever database. It really needs to be that we say we don't trust anyone based on where they're coming from. We trust based on a factor of, you know, what, how confidently do we know who the person is? So really strong authentication, web access controls on this, on the service that they're getting access to. So whether that's a WAF or, you know, something, you know, web access management, whatever it is, You want to really control the resource there and then really control whatever device they're connecting from.

That last aspect, you know, high— a high level of assurance that that laptop or PDF or, uh, mobile device is, uh, is secure and trustworthy is only important as long as, um, we don't, you know, have a better way to obfuscate data. Because if you have a compromised laptop getting access to my system, they can get all the screenshots, they can pull all the data eventually, right? So I think those 3 components really are the, the next 10 years of future of security. How I think it changes over the next decade is this move to the cloud is gonna, you know, reach— and I don't think we're too far away from peak cloud. And then we're gonna realize that there's some real drawbacks to peak cloud, peak public cloud at least.

And we're gonna see this drawback where people are, are, you know, rebalancing what it is to, you know, how much cloud do you have? How much internal do you have? And I think that's gonna be an interesting thing over the next decade to see Not everything's going to the cloud, but a lot of commoditized services will be. So it's interesting you say that. And Alex, I want to get your point of view as well.

But if we draw the aperture back a little bit, mainframe distributed computing, right? And then all of a sudden it was no centralized, like, sorry, decentralized, like desktop. I need it on my machine. I need my PC. And now it's back to decentralized computing.

And at some point in time, right, does it make sense from a risk perspective, right, to have a more balanced approach towards security. I think the pendulum is going both ways, and I would not be surprised to see us end up back to some sort of rebalanced portfolio. I would agree with that as well. Thinking about the long term, we as humans don't do a good job of learning from history. And I think if you look back in history, we— the pendulum for lots and lots of things swings way to one side and then way back to the other side and then way back to the first side.

Uh, so I would, uh, it would not surprise me at all if it, as Robb said, we get to peak cloud and then people say, ooh, there's all this stuff that's wrong with this. Let's make a giant reaction to this and go completely the other way and start going back the other direction. Thinking about more of the, uh, I'll call it short-term, but if we're saying 10 years, um, I completely agree with what Robb said, but I also think that we are in a transition in security. If you look at IT in general and kind of parallel it with that, Um, you know, thinking from, for myself as a CISO, you, you look at the CIO, uh, maybe 10 years ago, you know, people looked at the CIO as somebody, you know, they were the, the person in charge of, you know, managing the computers. They were not a strategic person.

They did not help move the business forward. Um, they just made sure that all the IT assets were there and, and that they ran correctly. And, and, you know, they were sort of, um, a second-tier kind of person. And that is still where the CISO and the security program is today. We are not at the same level in most cases as other executives, as well as being thought of as a business driver.

I think that in the next 10 years, that is going to change, but I think we have to embrace looking at real risk You know, as I've grown up through IT and then in security, a lot of it has been, you know, you mentioned compliance, but a lot of it has been security for security's sake is sort of the way that I think about it. It's like, hey, I see all of these bad things. There's lots of bad things out there. We gotta fix all of the bad things and not really looking at what the risk of those bad things actually is. Uh, when we can get to the point where security risk is thought of in the same context as financial risk and other sorts of risks, then, uh, I think that we are going to be at that same level and be more of a strategic partner with the business.

Um, and there are lots of people that are moving in that direction. And I see that really moving forward in the next 10 years. So, so Robb, you had another answer, um, for future, future, like the future beyond like potentially us being in it. Yeah, so, you know, in the next 20, 30 years, I do think it's a little bit of a play on what Alex just said about the evolving role of the CISO, where I actually think that all the security operations that we currently do within security departments, most of that should actually move into the business. And it's, you know, whatever the operations is should be incorporated into the function of whatever, whoever owns that function for the company.

So if we're talking about, you know, firewall management, that's a networking, it's a networking capability. It needs to be a networking capability. And the fact that we have this delineation between security and networking is based on the fact that networking doesn't do it reliably, right? They're just not, they're not able to deliver that with the security we need. I think all of those things should get embedded into the teams that do them.

And this is the DevOps world that we're moving into where everything is handled, you know, somebody owns it from soup to nuts. I think security should be embedded into all those requirements. And, and the CISO doesn't— never goes away though. The CISO becomes this person who, who's creating those requirements, who's create— who's understanding what the compliance and legal landscape is, understanding the organization's risk tolerance, and it has the ability to measure and report on and really become the person who can speak to the business's ability to deliver on those security requirements and communicate with those business leaders, but not have— not be the one who's got hands on keyboard, like know, it's currently right now this hybrid where we're trying to do both. I see the future as security is embedded into the functions.

There's this oversight that the CISO is doing, and it really moves to more business risk, right? I don't think the CISO as it's currently created is a top-level executive in most organizations because it frankly is a subset of something else. But as it becomes a risk— is it a risk leader, right? Someone who understands the risk across the organization. That seems like a really top tier executive to me and where I, where I think we need to be moving.

Amen. Yeah, no, I think organizational design and reporting structures matter a lot and probably move the needle quite a bit for the industry going forward. Um, let me ask you guys this question. It's in the same, same vein, but maybe a little bit different. Um, what do you think that the information security industry today is doing right?

Like, there's— we're easy, we're pessimists by nature. We're skeptical by nature. We like to point out flaws and vulnerabilities. But on the other side of the coin, what are we doing that's good right now? And you think about where we came from, right?

Like, in your mind, I'll start with you, Robb. And if you want to pass to Alex, what are we doing that's really like, this, this makes sense. This is right. This is good. I don't know that I have a great answer.

It's a tough one. I think we can do a lot better in a lot of areas. So what we're really— I think I could start off by saying what we need to be doing better of is actually practicing what we preach, right? You look at the SANS Top 20 or any framework that says you need to understand your environment you're working in. The top number one control of the critical security controls or SANS Top 20, it used to be called, is to know your asset inventory, right?

And then your staff, that's your hardware asset inventory, your software asset inventory. We don't do that very well. We don't do vulnerability management and patching. We don't do what I would call the fundamentals very well. So those people who are focusing on that, and it really, you actually have a huge leg up, right?

If you can get good at those fundamentals, you can stop the vast majority of bad things from happening to your environment. Network segmentation, knowing what your perimeter looks like, those types of things. I'm not sure I'm answering your question, Andre, about what we do very well. I think that that's what we need to be doing very well. Um, and here we go.

Here's what we do really well. We, we distract CISOs with really shiny new technologies that sound cool, and they're willing to spend money on those things, right? That is the, that is what the security vendor market does really well. So I have one thing that we do well, and, and while we do it well, I think it is also something that hinders us. We do culture really well.

Um, that's a good point. Security is a really defined culture and And if you're a security person, you take that to your core. I don't necessarily think that that fits in a lot of other disciplines. Hey, if I'm an IT guy, all right, okay, I'm an IT guy, I work with computers. But security, it's like, hey, I'm a security guy, I belong with all the security people.

Yeah. And there's no competitive on that, right? So if I run into Alex or we run into some other CISO from, you know, Pulte's biggest competitor or Ping's biggest competitor in the market, I don't think there's any competition there, right? It's right. Hey, what do you do to be successful and how can I help you be better at stopping the bad guys?

And I think that's a great thing, but it is also a hindrance in that it's, it keeps us separated from everything else, right? So it's, oh, security. We are security. We're not, uh, we're not IT. We're not part of the business.

We're not this, we're security. And, and while I think it is great that we have this great culture, I think that we need to expand also and think outside our security bubble. It's definitely a badge of honor, right? For those that are in information security, risk compliance, we're proud of what we do, right? And we need to expand that community.

And you guys are doing that here through the podcast, through the Slack channel. It's happening. Love to see it happen even faster. So that being said, I want to switch over because again, we are in a celebratory mood here. Right?

It's 100 episodes. I kind of want to pivot back to the podcast in and of itself, right? Some, some fact-finding, some, some, some laughs, right? Looking back, looking forward. Um, one of the questions I, I want to ask you guys, because I personally want to know, um, besides Colorado Equals Security, what other names were considered?

Oh, that's a good question. So I remember I, uh, I sat down with 5 or 6 other local security people as we were coming up with this idea, and the name was always really hard. So there was this placeholder where we'll just, for now, we'll put Colorado Equals Security on the board and we'll come up with a better name later. That was, that was literally how it went. Like, I don't know what the name is, but we'll put this because I gotta put something.

Um, and spent, I don't know, a significant amount of time talking about other ideas. Um, but no other, I, I don't remember any other ideas being significantly considered. Yeah, I don't remember either. I do remember we had a list, but I, I'd be hard pressed to tell you what any other things on the list were. Yeah, I remember the domain, the, the, the day we did all the domain searches and tried to figure out what we could get.

Colorado Security, not available. Just so y'all know, not available. Are, are you squatting on any other domains right now in and around yours? We have, uh, we have colorado-security.com and we have co-sec.co because that was, that fit really nicely on like on a, on a really small logo. So you could click that link and it would pop you out to the main website.

That was one of my biggest concerns was, you know, we were trying to get colorado-security.com. Well, we wanted Colorado Security, but colorado-security.com was the best we could do. And I thought, man, that's a really long domain name for people to try and type in. I remember Alex, saying, I'm like, oh yeah, color dash security, that sounds good. He's like, you mean Colorado minus security?

Not what we're looking to accomplish. Sadly, you can't put an equals in a domain name. Oh well, maybe in the future. Maybe next year, maybe in the future of the next internet, we'll have the ability to use the equal sign in there. So, so in previous episodes, Robb's talked about the intro song and the band and— right.

It's actually a good segment of a song. As a musical band, maybe their other works aren't as interesting, right? Just generally saying. Has there been discussion about updating after 100 episodes? Are we entertaining new music, new intro music?

So I'll say from our perspective, Everything we do is about the least amount of effort that we have to do to get it done. Um, so unless there was some driving force that people were like, ooh, this music is horrible, we need something else, we're probably going to stick with the same stuff. I think with that said, if there is a listener who has a band here in Colorado who thinks they could put together a, what was it, 30-second intro and a 30-second transition piece for us, I'd be happy to, to hear what that is and, and see if it makes a difference. I'd love to have a Colorado band do it. Yeah.

So, so any musicians out there, do, do, do a, a 30-second bit, submit it, we'll listen to it, and, and these guys will decide. Um, it's been great. It's been 100 episodes, right? Maybe, maybe it's time for some other considerations. It needs to be good at 2x speed as well though.

That's right. That's right. A lot of people listen to the podcast fast. But, you know, Robb has said this many times, if you— and I think you can follow the link that's at the bottom of the show notes to get to the actual song and the band that we use the little clip of. And it's not even— I don't even know if it's 30 seconds.

It's really, really short. But if you listen to that whole song, it's pretty terrible. It's not the best. But that little bit, that is great. So what I hear you saying is that we're not going to use them at the RMISC or the holiday party to entertain.

No, we're probably not bringing them in as entertainment. I'm hoping they're not listening to this episode because I would feel bad for them if they are. Yeah, well, I mean, if they have new stuff, we'd love to hear it. It's royalty-free music, you know, what can you expect? Yeah, there's a website out there that has the royalty-free music like Alex said, so that's where we found this.

So as you guys came up with the logo and we've distributed, right, t-shirts and mugs and thongs out to the community at large. Any consideration for updates to the logo? You know, honestly, that is one thing that I have thought about. You know, you see properties where the logo morphs over time or they get different versions of the logo. Our logo was actually created on a free logo website.

So AI, right? AI, right? I was expecting to hear cocktail napkin. Well, no, so we didn't, honestly didn't have anything to do with the actual picture itself. You, you go to the website, you put in like the terms that you want it to think about when creating the logo, and it spits out a bunch of potential logos.

And then we, we went through and, you know, narrowed it down to a few and then finally settled on the one that we have. I would say the only difference, Alex, is, is if you remember, we couldn't put an equal sign in the, in the search terms. That's true. And so you added the equal sign. So yes, my Photoshop skills, after the logo came out, I put the equals in the background.

So I'd be totally down for that coming up with, with other new or, you know, one-off or limited time kind of logos, whatever it might be. So a call to the community once again, if you're a musician, send us some music. And if you're an artist and you have an idea for what the logo could or should look like, submit it to Robb and Alex. They'll check it out. Sweet.

Awesome. So as we look forward, it's, it's 2019. Let me— yet. No, it is 2019. What does the future of Colorado Equals Security look like?

Are we now, are we now staring down episode 200, 500? Are, are we going international? Like, I don't, I don't know, like what's happening next. You know, I think, I think at this point we don't really know, but we're really looking at still at the same mission, right? The mission is to bring the community together and whatever it is that's going to make that happen.

Uh, I think that that's what we're going to go for. That's kind of been my motto, you know, through, you know, being at the ISSA chapter and now doing this stuff. It's, hey, put forth a compelling product that people want and you will get a community and an audience there. So, uh, if that continues to be the podcast, to be what people think is a compelling, um, mission and, and, uh, thing to put out, then yes, we will continue to do it. At this point, I don't think we have any, um, any desire to stop, but, uh, but yeah, I mean, I think we're just going to try and keep bringing the community together, do things to bring the community together, uh, and move forward.

Yeah. I'd say a few things. There's, we have been, we've worked really hard to make sure that this is not about Um, you know, creating just yet another competitive organization to the groups that are already in town, right? We're really trying to augment what's already happening and show off what's already happening. You know, we have a company's webpage that shows you the security vendors who are here in town and an orgs page that shows you all the groups you can go meet with in person, because we want to be a part of that.

We think there's a lot more room for other things that really show off what's happening in town. And we've, we've actually brainstormed ideas of things we'd love to do that we just don't do because of because of capacity issues, right? We, we feel like we're pretty well at capacity for what we can do there. I'd say if there's people in the community who want to get involved, um, reach out. I, I say I'm probably not going to respond to your email and say, here, you're on the board.

It's more of a relationship type of a thing at this point where we want to, where we want to get involved. But I think there's opportunities for us to, to really expand what Colorado Equal Security means, um, and we'd love to, to get some help with that. Um, cause like I said, we are at capacity. Another thing, if folks are listening, if they want to help out is the, the interview segments we do. That is probably the hardest thing for Alex and I to do is scheduling those weekly interviews where we sit down with someone, you know, with our lives, you know, it's, it's just hard to prioritize that time and sit down with folks.

Uh, we would love it if there's some folks out there who are interested in helping us do the interviews, help us sit down with someone and record an interview. On your own, send it to us and, you know, we could even include that as a part of the show as long as it's relevant, as long as it's somebody who we, we think would be, you know, interesting to the audience. Yeah, exactly.

So that, that brings up something that I've been thinking about a lot and I've been wanting to ask you guys. And what are, what are some of the funnier moments from Colorado Equal Security that like lands on the cutting room floor that like doesn't make. There's always the behind the scenes stuff, right? There's a lot of stuff that goes on, right? Is there a story out there throughout the 100 episodes where you're like, oh man, I'm so glad we got that, or, oh man, I'm so glad we didn't get that, or, can you believe that didn't happen or did happen?

Give the listeners some behind the scenes stuff. Yeah, so generally we record Sunday mornings. That's a time that Alex and I are able to get together. Sunday mornings, you know, we'll get together. We, we, we're pretty quick.

We, we go right through our— we use a collaboration tool for all of our show notes. We go through the show notes, talking through, record it, we post the show, we're done. Right. That's generally it. But if we, you know, Sunday mornings are busy when we record occasionally on a Friday night or a Saturday night, it's a very different, it's a very different environment.

That's when, um, drinks come out. Usually a couple of drinks before you hit record. If you've listened to all the episodes, you could probably pick out the ones where we, where we recorded on a Friday or Saturday night. And, and yes, those are the times that we're also editing things out of the show because maybe that was a little more than we meant to share there. Or, you know, occasionally some of those things even slip through.

Yeah, I think you would be surprised that there are very few pieces that are sort of behind the scenes or that were cut out though. You know, if you were in a big sort of commercial production, you know, they might record, you know, say an hour's worth of stuff to get down to 15 minutes of show, right? We hit record, we talk, and then we hit stop and we're done. Our goal again is as little work as possible. So if we don't have to do any editing, That's awesome for us, right?

So I think most of the time what you hear is what actually happened. And when I say 90+% of the time, there was no editing done in terms of cutting pieces out of the stuff. The vast majority of the time. And when I did my solo episode, whenever it was, a few weeks ago when you were on vacation and I didn't have time to get a sub, that was the most editing I'd ever done. I think I stopped 3 times and backed up and started again because it was It was kind of hard to do on my own.

Um, whenever I interview somebody, a feature interview, I tell them, listen, making mistakes and like even like verbal flubs is a good thing. It's a humanizing thing. It makes everyone, you know, feel like you're not part of a polished, you know, professional thing, but actually getting to know the real person. So we, we try and follow the same thing. You know, we make a mistake when we're talking here, we, we let it go and we don't worry about it.

Yeah. I think also, um, There have been a few times where we have recorded a show and then realized that, oh, you know, it wasn't recording or the sound was off or, you know, one of the mics wasn't on or something like that. It's, it's been pretty rare, but there have been, I don't know, at least 2 or 3 times where we've recorded a whole show, including the first show, right? Including the first show. Um, episode 1 and got done and we're like, oh, uh, this either doesn't sound good or it didn't record or, you know, whatever it was.

That's happened a few times, but that sucks when that happens. It does suck. It does suck. Um, you know, again, we try and do the least amount of time possible, and when you have to re-record something completely, yeah, that's no fun. What's funny is if you do one of those and on the second run-through, if you use the same joke, the other person, the other person still laughs, but it's because, Jesus, you just used the same joke again.

I thought it was because the laugh sign in the, in the, in the studio lit up and it said laugh and oh, I laugh now. Okay. Hahaha. You know, the laughter from the studio audience isn't nearly as good though. No, no, not nearly as good.

So, so we're coming close on time here. I want to be sensitive to that. I want to thank you guys again for, you know, A, for me inviting me in to have the opportunity to interview you guys. You guys have done an amazing job and to be affiliated and associated with the organization is pretty awesome. And it's a privilege and honor to spend time with you guys doing this.

I truly enjoy it. As you think back on 100 episodes, 100 podcasts, what are some of the most memorable things that stand out to you? I'll ask each of you for your top 2 things, right? There's a lot of great moments in there. Maybe there's a learning, maybe there was a funny experience, but What would you like to share with the users when you think back across 100 podcasts?

Um, right? Like what's, what's number one in your mind, then number 2 and, and, and Robb will have you do the same. So, uh, we can go back and forth. I'll do one and then Robb, you can do one. I think the biggest thing for me has been that we'll record something and we'll go, ooh, this is really awesome.

People are going to love this. And then you go look at the numbers of downloads and things like that and it's like, Why, why is no one actually listening to this? I think this should be awesome. And then we go, um, you know, nothing against any people that we've, uh, interviewed, but it's like, yeah, this probably wasn't the best interview we've ever had. And then all of a sudden it's like through the roof and it, it sort of defies, uh, logic.

Yeah. Uh, I'd say I have, I have 2 pretty clear favorites. Um, if you guys were around, it was early 2017. We had Cal Fussman on the show. So if you, I don't know, you guys are familiar with the Tim Ferriss podcast.

Tim Ferriss interviewed this guy, Cal Fussman. I don't, I don't listen. I did not at the time listen to Tim Ferriss at all. Jonathan Wood, who actually works for RiskIQ, sent me a text saying, hey, you should listen to this podcast. And I'm like, all right, I'll give it a shot.

I'll trust you. And it was an amazing podcast, just an amazing storyteller. And I kind of fell in love with this guy's ability to tell a story. Story. Um, and as a part of, you know, being a part of the Rocky Mountain Information Security Conference, I was able to get Cal to become a keynote speaker for us.

And I used that to be like, hey, maybe I can get him on the podcast. Right. And he came on the podcast and it turned into, you know, I think friendship might be too strong a word, but at least an acquaintanceship with him, this guy who I got to hear on this massive podcast, who I was able to use to, um, to help the security community, but also then get to know a little bit. And we actually went to dinner a couple of times and he's invited me to, to come out to Los Angeles and, and meet with him. Um, and it's just a really neat thing that, you know, way beyond what you'd expect being part of the Colorado security community, um, getting to know this guy in, um, really a personal way.

Didn't he fight Muhammad Ali? Uh, it was— no, it wasn't him. It was, um, he, he interviewed Muhammad Ali. He fought— oh shoot. Uh, what was it?

Uh, Roberto Duran? Who was it? It was Julio Cesar Chavez. Yes. Yes.

And so, and that's insane. So anyone listening, do a Google search for, for Cal Fussman and Julio César Chávez. And you're going to, there's an image, you're going to see the image of this guy fighting him. It's an amazing story. I'm not going to ruin his story.

Listen to it as he trains for that fight. One of my favorite things I've listened to. It's fantastic. So I think the other thing that, that I think has been the most awesome. And it's not a specific moment, but it's just the amount of people that I have been able to talk to that I probably would not have talked to if it wasn't for the podcast.

And along with that, it's really amazing how open people are. And I don't know if it's our community or just in general, but if you ask someone, hey, would you like to be on the podcast? Can I come talk to you? Almost, almost all the time someone is just, sure, I'd be happy to. And you're like, oh, I don't know you.

Why would you say that to me? You don't know my podcast. You don't, you don't know anything. But for the most part, you ask somebody to be on the podcast, they're like, great, I would love to be on the podcast. I'm happy to talk to you.

And I've met so many people that I wouldn't have met otherwise by doing these interviews. And if I go to a specific moment, You know, whenever I start my feature interviews, when I'm playing the Andre Gaeta role, I usually start talking about something that's just not related to security at all, right? So, and that's probably my favorite part of the whole interview. I've heard the security story a lot of times, and of course there's a lot to learn from them, but I love to hear about the personal aspect of it. And sitting with Patrick Quinlan, Patrick is the founder and CEO, or I guess he's a CEO, I'm not sure he's a founder, of Conversant.

Local company. And when I kind of got into the personal side with him, I had no idea what I was going to get into. And he tells me about growing up in a divided Germany. He grew up in West Germany and the trip that he would make. So personally, when I think of, you know, there's East and West Germany, and then there's East and West Berlin, right?

The countries each owned half of Berlin, but Berlin is not in West Germany. It's not on the border. Berlin is like 2 hours into East Germany. I didn't know that. So he tells the trip, the story about the trip on the train from West Germany into Berlin, into West Berlin, and seeing the difference between freedom and oppression.

And it's just this visceral, like vivid thing that he gets to see and how that has defined his entire life. And if you guys haven't listened to the Patrick Quinlan interview, which is another one that Alex said, like Alex said, like to me, that's maybe the best, one of the best interviews we've ever done. Maybe not the best numbers for listeners. That's worth listening to, his story talking about that experience. That was a real big thing for me and something that I just didn't see coming.

And it was really an honor to be a part of that. Yeah, it's always fun when you don't see it coming, when you don't anticipate it, right? And all of a sudden there's that magical moment where it captivates you and you're hanging on every word and the experience you went into, like expectations, Right? And then it defies all expectations, something totally different. That's a fun experience.

And a really cool thing is Conversant actually uses that interview as an onboarding thing for their employees. Everyone who gets hired at Conversant is given this interview. I think it's probably an optional, I'm just guessing, an optional listen to like, you want to know about the company and the guy, here you go. And that's kind of a cool thing too. You know, I'm going to add one more thing, um, even though I'm going out of turn a little bit here at a third thing.

So, When Robb and I started this, you know, neither of us had had any experience doing podcasting. None. Um, no audio experience. Um, no, you know, we are in true Robb fashion, right? It's like, let's just do this.

We'll, we'll buy some stuff. We'll jump in. We'll do it. Um, so, so since we started this, um, at my, my day job, um, myself and another person, we started an, an internal podcast at my company. So, um, you know, we had some, some HR initiatives that, um, that I won't go into, but based on those, um, along with this other person, we thought, hey, it would be cool to have an internal podcast to talk about some of these specific things that we're doing here in the office.

And so he and I started this podcast internally at the company, and that's not something that I would have ever thought of doing before, but now all of a sudden it's like, hey, I mean, you're a podcaster. I'm a podcaster. I have experience in this. He also has his own podcast on, on another topic. Shout out to, to Rich and the, the Mile High Endurance Podcast.

So if you're, you're into triathlon, triathlons, go ahead and listen to that. But that's been a, a really cool thing for me too, is that we've sort of made a difference in our own company from doing the, the podcast stuff that was not complete at all related to things that I do on, on a day-to-day basis. Yeah. So, so, so we're going to start to wind it down. Uh, I had a whole slew of questions around like, so what was it like on day one when you showed up and like, like, okay, we're going to do this.

Like, like, is it like just like a wireless mic? Is like, how do you build a podcast? Like, what do you do? What you do is you send Alex a note saying, hey, could you find us some mics for a podcast? Uh, yes, exactly.

So, um, So again, I want to thank you guys for your time, and on behalf of all the listeners and the folks that get the benefit of Colorado Equal Security, the events, the job postings, the current news, right, the banter, the informality, right, that you guys bring to the space is well received by the community. And again, I think we're all extremely appreciative of it, and we're seeing that by the numbers continuing to grow. I want to encourage you guys to please keep doing it, have fun doing it, and the more fun that you have, I think the more fun that we have, and I think it's just a reciprocal thing that just keeps getting better over time. As we get ready to depart for today, I guess I'll ask each of you for any final thoughts, and it's an open canvas of anything, right, as we depart on the interview for the 100th podcast. Anything at all that you'd like to share top of mind?

It could be personal, it could be professional, whatever you got. Uh, we'll start with you, Robb. Um, yeah, I, I, same message I gave when I, when I left ISSA and, and, and actually when I, when I had the chance to talk in front of the Apex Awards, uh, a couple months ago, the, this is not a participate, or excuse me, this is not a, a spectator sport, right? Security community life, Right? As much as possible, we should all be looking for ways to spend less time binge watching on Netflix, which is, by the way, not a bad thing.

I recently watched that new, that new Black Mirror. Was it Bender? Bender Snatch? Bender Snatch? Whatever.

Scooter Bender something. It is a choose your own adventure Netflix horror movie, whatever. And anyway, life is not a spectator sport. As much as we can, let's move away from watching TV and getting involved and And Colorado Equals Security, you know, you're listening to the podcast. We really appreciate that.

We want you to keep listening on your drives, but let's get involved as well, right? The Slack channel is a good way to start to meet people, but then there's another step after that, right? How do we, how do we go from beyond that to making a difference, to helping, you know, teach some kids about security, to helping, you know, get some, get some less represented groups as a part of security? I don't know what your personal passion is, but Man, find something and get involved. I know Alex and I, we're not going to do this forever.

We would love to have somebody else get really involved with us and help us, you know, build this thing out and look for a way for Colorado Equal Security to become something that lasts beyond, beyond when we're the ones running the whole thing. Yeah. And I think one of the things that I have learned a lot from Robb is just go do something. You know, he's talking about getting involved. A lot of times people feel like there's some barrier to doing something.

Hey, you have an idea, just go start doing it. Just do something. Doesn't really matter exactly what it is. Go start doing something. The whole DENSEC community came exactly that way.

Exactly. What, you know, you'll start doing it and things will evolve and it may change. You may find out that it's not the right thing to do and you'll go do something else. But just start and go do something. You don't have to have something formal or permission or whatever.

Just do it. Take action. Do it. Take action. Right?

Don't, you know, have a plan, but go do something. And doing nothing, not really a viable option, right? The thing may not go as well as you'd hoped, right? But then you pick yourself up, you dust yourself off, and you, right, you keep trying. Great learning.

It's great learning when it sucks. Sure is. Yeah, for sure. Well, as we wind it down here, you know, Happy New Year again. 2019 is here.

Thank you guys for all you do. From all of us to all of you, we really appreciate it. Looking forward to a great 2019 and beyond. And for all listeners out there, have a happy new year and look forward to seeing you out there. Thanks, Andre.

Thanks, Andre.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes