All episodes

Dale Drew from the SecureWorld Stage

Apple Podcasts Spotify SoundCloud

Dale Drew, CSO at Zayo, was our feature interview from the SecureWorld keynote stage this week. News from: Molson Coors, Ping Identity, Coalfire and a little bit more!

Brewed from the waters of Lake Michigan?

Alex is away, so Robb will play. And Molson Coors will leave town. Colorado will introduce digital state IDs. And Coalfire is seriously not happy with a sheriff in Iowa.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11499 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 140 for the week of November 4th, 2019. Alex is on vacation this week, so I actually got myself a new guest host.

I decided I need someone who's a little bit more mature than Alex. So who do I have here? Today? My name is Drew Reck. Drew, and, uh, how old are you and what do you do professionally?

I am 10 and I go to Mark Twain Elementary. And how long have you been in the security industry? My entire life, I could say. You've been around security your whole life? Yes.

Well, I, I don't doubt that you have some serious stuff to teach us about security. Before we give you that chance to teach us about security, I'm going to go through just a little bit of housekeeping. As a reminder, we have a Slack channel. This is the Colorado Equal Security Slack channel where you can connect with over 1,100 of your, your closest friends in the security industry here in the Colorado area. We also have a mailing list where you can get the show notes delivered into your inbox every week.

Those show notes include all the jobs we talk about, all the events that are coming up, and links to all the news stories we go through. You can sign up for both of those by going to colorado-security.com. We'd also love it if you would subscribe and get the podcast delivered directly into your inbox each week. And please go ahead and rate us on your favorite podcast listening application so we can know what you think about us. Don't forget to tell a friend Colorado Equal Security is a great podcast for everyone to listen to.

I love it. Thanks, Drew. Have you been telling your friends at school to listen to us? Yeah, let's say that. All right, moving along.

We— if you've, if you've done all that and you're wondering, you know, how else can I help, we actually have 2 other ways that you can help out with the, with the movement. Number one, if you want to help support Colorado Equal Security, we have a Patreon campaign. You go out to the front page and click on that, and you can support to pay for the funds for this. And number two, Uh, we would love it if you would volunteer to do interviews for us. We've had a great slate of recent interviews that were performed by listeners like yourself who sat down with other interesting folks in the community.

Um, we'd love it if you'd help us do that. With that, why don't we go ahead and run over to the news? Drew, why don't you go ahead and tell us what our first story is? What the Molson Coors news really means for Colorado. So this was a big story that broke this week.

Uh, Molson Coors has announced that they're going to consolidate down from I think they have 4 different offices in North America into 2 offices in North America. And unfortunately for us here in Denver, that's going to do away with the big headquarters we have in downtown Denver. There's a lot of executives that are in that office, including the CISO, Glenn. I hope everything's going well for Glenn. I haven't had a chance to talk with him yet.

So it's bad news in terms of those jobs. And it looks like maybe 500 or so of those jobs leaving. Good news is they have at the same time announced a very large investment that they're gonna make into updating the brewery out there in Golden. I think they said several hundred million dollars worth of investment going into that. So it's going to continue to be their number one facility.

And I guess the good news is we're not going to see their tagline change to, you know, brewed fresh from the waters of Lake Michigan as they move to Chicago for this. So that's good, at least. Drew, what else we got? Colorado is now accepting digital versions of state IDs. This is pretty awesome.

And this just came out in this last week. You can now go out to the iTunes Store or Google Play Store and install the My Colorado application, and you, you can integrate that with your own ID. I've already done this. You get your driver's license in there and you can see your driver's license. There's some other pretty cool stuff, like you can renew your driver's license through that.

It looks like you can very soon be able to do vehicle registration and your insurance card in that same application. What really cool thing— Colorado is leading the way here on this new digital transformation of how we do government IDs. And they actually, very cool, you can, you can tell as you do it, partnered with Ping Identity. Ping Identity is the identity provider for this. So really cool thing for me to get to do as a, as an employee of Ping and as a citizen of Colorado.

I'm pretty excited about it. Drew, how do you feel about this? Well, that's quite interesting. Have you, have you got your ID moved over to it yet? Not yet.

Not yet. Maybe we'll have to wait just a few years till you, till you get an ID. All right. Our last story, Drew, what do we got? Coalfire CEO Tom McAndrews' statement on Iowa cybersecurity trespass case.

Drew, I think you're going to find this one really interesting. So as a way to go back a couple of months ago, there's a company here in town called Coalfire, and they have people who are called penetration testers who go out and try and break into companies to see does the company have security in place? The company hires them to come try and break in to see if their security is good. So this, the State Department in Iowa hired a couple of penetration testers to break into a courthouse, but the courthouse is actually owned by the county instead of the state. So when the pentesters came in, the county arrested them.

The sheriff from the county thought that they were criminals. And then over, over time, it looks like there's kind of a, some bad political, some bad blood in between the state and the county. So the county has not dropped the charges against these guys, even though they were clearly doing their job. And so it's been really ugly. So this statement by the CEO of Cold Hellfire was really kind of over the, you know, just saying how over the top this whole process is and how ridiculous it is that they have not dropped charges against these guys and that they've been kind of being used as pawns in this argument between 2 different government organizations.

Wait, is that interesting? Yeah, that's quite cool. All right. Well, that is it for news. We are definitely doing a shortened version of the podcast this week because we do have the whole interview from SecureWorld earlier this week.

Moving along to our Slack Message of the Week. Who should we thank for their continual support of the Slack Message of the Week? Thanks, Andre Gaeta, for always supporting the Slack Message of the Week. Andre has been a great supporter for us for the last couple of years. This week we're going to recognize Neil Shaw.

Neil not only was, was participating in the Slack channel this week, but he took some, some pictures of the keynote that Alex and I did along with Dale Drew at SecureWorld. So if you want to see Alex's completely bald head and my apparently what everyone's saying ongoing march toward baldness from an overhead view, you go take a look at those pictures out there in the Slack message or in the Slack channel. And of course, congrats to Neil. You will get a free swag item from the Colorado Equal Security store. We appreciate that and look forward to getting more Slack messages next week.

Next, we're going to go ahead and move over to our event calendar. I want to remind everyone that we have a calendar of events on the Colorado Equal Security website, colorado-security. You can go see all the stuff going on for several months in the future. But every week we like to talk through what are the next 2 weeks worth of events. So starting off on the 7th, we have a— oh, sorry, that's actually starting off on the 6th, isn't it?

Starting off on the 6th, the CTA is doing a Cyber Resiliency: Is Your Organization Prepared event. This is interesting because it's, you know, CTA, which is more technical in nature and not security focused, but they're doing a very security-focused event. Um, the 2019 APEX Awards is also on the 6th, and this is the event where Alex and Debbi Blyth and James Carder are finalists for the CISO of the Year Award. So looking, uh, very much forward to seeing how that turns out, and, uh, we'll, we'll definitely let you guys know the news of that next week. On the 7th, we have the Splunk First Thursdays at Topgolf event.

If you want to go get to talk to Splunk and do some golfing, that'd be the event for you. Also on the 7th, there is the CSA Fall Summit. This is a full-day event where you can learn about cloud security. It's up in the, the north area, somewhere off of 36th, I believe. On the 9th, SecureSet is doing an extended capture the flag event, a beginner and professional.

So if you're looking to get into capture the flags, this would be a great place to start. And SecureSet is putting on a Hacking 101, Creating a Virtual Lab on the 12th. The Denver ISSA chapter is doing their November chapter meetings. Those are going to be on the 12th and the 13th. And ISSA Denver, the workshop 12 Ways to Hack MFA is on the 13th also.

Yeah, that's right after the chapter meeting on the 13th, so you can go to the chapter meeting and then stick around for the MFA workshop. On the 16th, the ISSA Colorado Springs is doing their November mini seminar, and that's on Saturday, and you guys can come do a few hours of that. Well, that takes us to the end of the events. We'll go ahead and move over to jobs. At Ping Identity, we are hiring a GSI Alliances Manager.

This is our global systems integrator person who's going to help Ping work on those relationships with big advisory firms. If you have experience doing that and you want to get plugged in with the best security company in Denver, go ahead and send a note over to me and I'm happy to get you connected or apply on the website. And Western Union is needing a security architecture and data protection leader. That's fantastic. Well, Drew, that is it for the news this week.

As I mentioned a little bit earlier, we We do have an interview this week, which is Alex and I on the SecureWorld stage with Dale Drew. Dale is the Chief Security Officer at Xeo Group, and we really talked about his career and really how he's been looking at security in a different way. I know you haven't got a chance to listen yet, but do you have any initial thoughts about Dale Drew? Well, he stole my name for one. Well, he did do that.

That's fair. Well, Drew, I appreciate you being a guest host on the show this week. We'll look forward to having Alex back in the future and a little bit lower level of conversation when he's back. Uh, anything else you want to say before we, before we go? No.

All right, well, have a good one. Hi, this is Ed Fuller, CISO of Cloud Elements. This is Colorado Security for Colorado security professionals by Colorado security professionals.

Those number one security podcasts to go live on the SecureWorld Denver stage here today. So I'm just gonna briefly introduce you to our hosts. We have Robb Reck, who's the CISO of Ping Identity, and we have Alex Wood, the CISO of Pulte Financial Services, who will be leading the way today. So gentlemen, it's all yours.

Hi everybody. Welcome to Colorado Equal Security. How are we doing today? Good, guys. This is, uh, you know, this is obviously the weather has kind of held some folks back, but this is actually the second most people we've had in the audience for a podcast so far.

So this is pretty good for us. We're pretty happy. I'm happy about it. Yeah. Uh, so we're really excited to be with you guys today.

We want to talk a little bit about what Colorado Equal Security is and talk about the security community, and then we'll bring up our featured guest for the podcast? Yeah, so Robb and I have been involved in the security community here for a number of years. Both of us volunteered with the ISSA chapter here in Denver, and I was president for about 4 years, and while I was president, Robb was on the board with me, and then when I left, Robb became president. And while we were there, I think we had a little bit of a narrow focus of what the security security community in Denver looked like. Yeah, so I don't know about you guys, but when I first decided I wanted to get involved with the community, kinda outside of my own little company, I went to Google and I typed like security in Denver or something like that, and what I found was ISSA and ISACA, those 2 groups.

And there are certainly a lot more things than that, but at the time that's all I found and all I knew about. And during my time on ISSA, I started to get exposed to all these other cool things happening in town. The Cloud Security Alliance and the 303-type guys, all these different groups that were in town. And I realized that for someone just coming into Denver or someone who just wanted to learn more about the community, there was really no way for them to find out what the resources in town were. Yeah, and so based on that, when we finished our time with ISSA, we thought, okay, what would be a good way to help bring all of the different people and groups and communities that were happening in the Denver information security scene together?

And that is really what Colorado Equals Security was born out of. Yeah, so what's the problem we're trying to solve? We're trying to make it so anyone who wants to can understand what's happening in Denver, and we can really amplify the voices of the cool stuff that's already going on. What we are not is we're not yet another group that's trying to get your attention and compete for your time to come to our lunch meetings or whatever. We are a group that's really trying to amplify what's going on from other organizations.

So when we started to put together the group, we thought, okay, what is it that we could do that will help kind of make that umbrella, but not, you know, add to that noise and add one more thing that people can do? Yeah, so we do a— what we decided to do is we, number one, created a website. And this website, it should be your landing place for all things Colorado security community. And Robb, what is that website? It's colorado-security.com.

Or if you don't have the time to type all of that, you could type co-sec.co, co-sec.co, and that'll take you right there as well, 'cause I know you're very busy people. And on that website, we have a lot of cool stuff. We have a calendar of events where we get all of the events from all these other groups that are happening in town. So you can go see what's going on in the next 6 months and make sure you schedule your stuff. We have a list of those groups in town.

So we have the big ones like ISSA and ISACA. We have OWASP and CSA, that's Cloud Security Alliance, all these other groups and we talk, links back to their groups. We have our— help me out here— security company list. We have a company list, so if you want to know local Colorado security companies, we have a directory there of all of those. And then we also feature one of the second things that we put together, which is the podcast.

So we started almost 2 years ago. 2 and a half years ago. 2 and a half years ago, yeah, almost 3 years ago, sorry. Wow, time's flying. A weekly podcast, and as part of that podcast, we do news, current events, jobs, other things like that, things that are going on in the community as the first part of that podcast.

And the second part, we do an interview each week with someone in the local community to highlight who they are so that you can get to know them. Yeah, so that's been going on, 139 episodes so far. Go back and take a look. And really, my favorite part of every episode is the interview we do, and you get to learn get to know someone in the community really well. So I think it's worth going through previous episodes and just looking for names or titles of folks who you're interested in talking with.

My personal favorite, if you want to go back, I talked to Cal Fussman about a year and a half ago, who's a national writer who was a keynote speaker at RMISC. It was a really good talk if you're looking for something interesting to listen to. Another one of my favorites is I talked to the founder and CEO of Conversant, which is a Denver-based compliance company. And his background was amazing. This guy was born in West Germany and grew up in West Germany, and the way he talks about his experience going from West Germany and taking what they called the Freedom Train from West Germany into West Berlin.

Well, if you guys are not aware, when Germany was divided, Berlin was divided, but Berlin's not on the border between East and West Germany, it's way into East Germany. So his experience going from West Germany into West Berlin was really interesting, and I think that's one I would listen to if I could. If I were you. I will also say, if you go back to earlier episodes, when we started the podcast, we had absolutely zero experience in podcasting. So we had to kind of figure it out as we went along.

You will probably note a different sound quality in some of the earlier episodes than you do in some of the later episodes. Apologies for that, but there is still good content in those earlier episodes. And then really the third leg of what we're doing at Colorado Equal Security besides, you know, cool t-shirts and sweatshirts, is we have a community Slack channel. We started that, you know, along the way. It was an idea from one of the folks in our community.

Hey, we would love to have a place where all of the folks in the Colorado Equal Security community can converse. And so we started this Slack channel, and we have over 1,100 people that are in that Slack channel now. Really, the only requirement is that you're in Colorado and you care about information security, and you can join that Slack channel. If you go to the website, there is a button on there that you can click. It'll take you to the entry page to join that Slack community.

I think Alex and I have agreed that this Slack community has become maybe the best part about this whole movement. It's just a really good place for you to have conversation, learn about new jobs. If you're thinking about a job at a company, you go ask on that Slack channel, what do you think about this company? And you're gonna find people who know intimately what's going on there. It's a really good place to network.

Yeah, it has been great. So that is what we're doing. You know, we like to think of this as just an opportunity for you all to learn about what's happening in Colorado and find opportunities that are the right fit for you. So I think that's it for our intro, right? I think that's it.

All right, so let's go ahead and bring up Dale. Dale Drew, the Chief Security Officer for Zayo. He's got a fantastic background, and we're gonna ask him some questions and learn about that here. A little bit more intimately. Yes, let's give a hand for Dale and we'll start our conversation.

Right to fireside chat. That's right. It would be nice to have a fire though. Can we work on that? A little fire for keeping us warm up here?

Please don't do that. We have the hackers in the room here. Fake fire. So let's start off, Dale. We'd love to get some background on you personally.

I do want to say for those who aren't aware of it, we actually did interview Dale on the podcast about a year ago. So we went into a lot of his background, where he's from, and how he got into security. So we're not gonna go into that super deep right now. If you want more detail, you can listen to that previous episode. But I think it'd be worth starting off, Dale, where are you from and how'd you get where you are today?

Let's see, so I grew up in Cheyenne, Cheyenne, Wyoming, and went to Arizona, started working for the US Secret Service out of Arizona doing computer crime investigations. And then from there went to Attorney General's Office in Arizona. And then after that went right into private industry. So I started working for a company called TimeNet, which was an X.25 packet switching network, and which was purchased by MCI, which we then built the first public internet network. And worked for Vint Cerf at the time for about 6 years or so.

And then from that, eventually migrated over to Zayo. So I think most, many folks will know who Vint Cerf is, but probably some don't. So would you tell us who Vint is and kind of what his biggest claim to fames are? So Vint has the moniker of Father of the Internet. And so he invented the TCP/IP protocol with 3 other folks.

He's notorious. He wears a 3-piece suit all the time, but he would always have IP over everything t-shirt underneath, which was just awesome. But yeah, so he went from private university research to MCI to take a federally funded and federally run private internet backbone and turn it into a public commercial So it sounds like you had— ooh, there goes the lights again.

So it sounds like even from early on in your career, you were focused at least somewhat on security. Was that always a goal of yours, or did that sort of happen sort of by chance? I'd say it's almost kind of a goal. It really started when I was in college. We were told to do a senior project for college.

I wrote a proposal for the U.S. Secret Service to write a database program that would inventory all the search warrant information. We did that as part of a college project. That turned into another proposal of creating a computer crime division inside the Secret Service. And so they accepted that proposal. They hired me and we built the first Computer Crime Division.

That resulted in something called Operation Sun Devil, which at the time was the largest computer crime investigation in the nation. It was, I don't know, 30 states, 40 or so bad guys. But that's sort of how it started out. Dale, that gives me the perfect opportunity to tell my favorite joke.

So, Dale, why does law enforcement have such a hard time catching cybercriminals? I don't know why. They ransomware.

Don't encourage him, guys. Sorry. I will note, when he first told me that joke, he said, why does the FBI? Yeah, yeah, I made it a little more broad. He's trying to throw the Secret Service in there as well.

So hey, Dale, at some point you came to Colorado, and I think you came for Level 3, is that right? Yeah, that's, that's correct. So I was, I was working for Quest at the time in Virginia, and Quest was moving, moving me out to Denver and found an opportunity to work for Level 3. And when was that, and what did you come out here to do? I was with Level 3 for 18 years.

And so I ran Level 3's corporate security, then eventually their managed security platform. So you must have come out in the late '90s then sometime, huh? Yeah. What was the security community like in Colorado at the time, or was there such a thing? I mean, there was a surprising number of security companies in Colorado even at that time.

There was, you know, Webroot was still here. But I'd say there was probably a handful. I mean, now it's exploded, but even then I was surprised. Usually you find that sort of technology investment on the coast and not in Colorado. What was it like building a security function, it sounds like internal and then customer-facing, within an organization that was focused on being a backbone provider that maybe It's not sort of a traditional kind of security company.

Yeah, that is— I think that's the challenge, right? The issue is, you know, when you work for a backbone provider, backbone provider is really, really good at transmitting data between point A and point B, right? That's what their business model is based on. That's what the executives are thinking about on a regular basis. And so to get involved in other sort of business areas, you have to try to equate or translate that sort of business speak from opportunity to how to take advantage of the assets that the company has.

And so that was really my journey of getting more involved on the business side of security rather than just the, you know, the academics and the execution of it. And I'd love to dive a little bit into, you know, how Level 3 changed over your time there as you matured. And when you came in, I'm guessing it wasn't as big a company, and I know there was mergers and acquisitions along the way. Maybe talk to me about what did it look like when you joined the company, and how did you see those changes affect your job? When I joined the company, there was 500 people in the company.

At the time, we were the largest modem company on the planet. And so Level 3 had a product called Managed Modem. We provided the modems for AOL and PeoplePC and and all that. And so I ran what's called the RADIUS group, which is the group that is responsible for authenticating all those users as well as security. And see, at one point we were 14,000 employees before the bubble burst.

And then after the bubble burst, we went back down to 4,000. Not 4, but 4,000.

And so, you know, there was quite a bit of You know, I'd say every handful of years you develop a theme, right? What you want to be good at and what you don't want to be good at. And making sure that you have those perspectives and keeping that 30,000-foot view of where you're headed as well as being able to execute, those are, you know, pretty critical. We got really good at laying off people during the bubble burst and just not something that you want to be good at.

Near the end of your time there, CenturyLink acquired Level 3, although I think in hindsight some people might question who was actually acquiring who. What was that process like?

Well, I mean, so I'd say pretty normal. I mean, you know, it's what we call a YAM, yet another M&A, but You know, at what my time at Level 3, I think we purchased 64, 65 companies, some of them larger than us. And so, you know, CenturyLink was just, you know, another M&A. In the telecommunications space, at least, there's just a tremendous amount of collapse, a lot of convergence. In fact, some companies are being built explicitly for the purposes of being acquired.

At least from a fiber footprint perspective. So there's a lot of consolidation of that infrastructure. And you were— when you got merged into CenturyLink, you stuck around for a little while, and CenturyLink also had a CSO, Dave Mahan, and both of you guys in Denver here. And interesting, how did that shake out? Obviously, you didn't stick around for all that long, but in the time you were there, what did that look like?

How did you guys end up dividing up the kingdom, as it were? I have a lot of respect for Dave. I think that he built a really good organization. It was like watching a parallel universe where you see 2 organizations have the same opportunity for the same decision, and one goes left and one goes right, and it ends up working out for both of them. So it was a pretty nice perspective to to see how that sort of operated.

But, you know, we made a decision to sort of divide responsibility between corporate security and product security. And then he left the company, and shortly after that, I left the company. So you left and you went to Zayo. Why? Well, first, what is Zayo and what do they do, and why is it that you chose to go there?

So, when I left CenturyLink, I was not going to work for another telecommunications company.

I'd, you know, pretty much sworn that to myself. But, you know, I mean, and the issue is, so, and I'm sure a lot of— I'm sure that this will resonate with a lot of you, is as the security guy, you're responsible for protecting whatever's in the company. Right? So when you work in an industry that is consolidating, that is, you know, going through M&A. So let's say you bought 45 companies.

The company really only cares about the go-forward infrastructure. They only care about the go-forward data center and the go-forward ecosystem. They don't care about the 44 other pieces of infrastructure the company bought. And they're okay with about 50 to 60% integration. But the security guy's got to protect all of it.

So all the money you get is for the new stuff. You don't get any money to protect the old stuff. And so you end up having to be really innovative and really creative about how you protect that infrastructure. And I didn't want to go through that again. And so, you know, I took 4 months off, which was— which, by the way, I don't think I've taken a vacation in 30 years.

But that was a— I got so bored, I started doing home projects and so the wife kicked me out. But, you know, I met with the Zayo management team. Zayo is another telecommunications company. And my goal there was to create some additional social experiments inside of Zayo. So do things that I'm familiar with, But sort of challenge myself by doing things that I'm not familiar with.

And, you know, we can talk about some of those, but like my one goal was to do more open source development. So my objective was to replace all of our security infrastructure at Zayo with open source initiatives and see if open source could protect a Fortune 500 company. I just want to say that the story you just talked about with, you know, the old data centers and the legacy that you had to support without the money. If you go to a different industry, that's not gonna go away. That's not just specific to telco, right?

I'm sure everyone in here has this story about there's that old application that we don't have developers on it anymore, but yeah, we also don't wanna get a pop there, right? So don't be too sad that you didn't get out of telco. It would've followed you. So when you came into Zayo, was there a security function already? Did you have to start that from scratch?

I know you said you were talking about replacing things with open source, but was there something there for you to start with? Yeah, so they had sort of what I would call the basics of security. There was a security function. The other social experiment that I wanted to do was to move the technology function underneath security, sort of a CSIO as opposed to a CIO. So we moved corporate network, corporate data centers, all internal development, you know, so basically the IT function underneath the security organization.

The idea being, or the thesis being, that the hygiene of security would have a significant benefit on the function and effectiveness of the IT group.

Sure. Dale, you and I have talked about this a little bit. I love the idea of a highly high-functioning hygienic IT department. But I worry about IT reporting to security for the same reason that I worry about security reporting to IT, is that when you combine those 2 things into one area, the business's needs for functionality and new project delivery will almost always trump the business's desire for some kind of security. I'd love to hear, you know, how do you think about that problem and how do you manage that type of a problem?

I think the important thing is setting expectations with management. The more transparent you are with management and the more adoption you have from the management structure, the more that they're willing to help you with that balance. What we've seen in the past, in my previous jobs as well as here, is that the need to deliver something quickly tends to overwrite all other common sense and logic. And so getting management team much more familiar with those obstacles and the challenges associated with it, you know, the more opportunity you have on getting more adoption of that sort of framework. And I'll give you an example.

So management thinks in business terms, they think in investment terms, they think in impact terms. And so when you're releasing something, there's some things they know not to cut the cheap on, right? And so whether that's the user interface and what that looks like, whether that's ensuring that you have primary and backup infrastructure. So those conversations are pretty natural. And so ensuring that you can have the conversation with management on the importance of security, how it is not a bolt-on, how it integrates into that framework, and then owning the infrastructure that does it just makes that part of the natural conversation.

So it feels to me— sorry, Alex— it feels to me like this is— it goes to the same thing that hopefully all of us experience, which is if you get security involved early enough in a process, security is not super painful. If you get security on late in the process, they've already run down this road and it comes to you and says, oh, by the way, could you review this? That's when security kind of turns into this— there's a fork in the road, right? Where I get to a point where I look at a project that's most of the way there and I can either choose to be the guy who says, hey, this is a problem and we can't do this. We need to go send it back and do rework.

Or I can go the other way and just be totally worthless at my job and do nothing, right? I can be like, okay, well, go ahead and do it. Like, those are the 2 choices that I get as a security leader if I get into the process too late. And it sounds like what you're doing is really having the conversations to include the security considerations as early in the process as possible. Yeah, I'd say 2 things.

One is my business in particular, my management team in particular, values very highly what's called the NPV analysis, the net present value analysis. So we do all of our security reviews based on NPV to show What happens if you do and what happens if you don't? The other one I'd say is that since we own the technology organization, we've integrated security into that lifecycle ahead of time. And so the security organization is turning more into a compliance validation and threat hunting sort of group as opposed to a QA organization or a validation organization. So when the organization develops code, that security discipline is implemented as part of the development organization, not afterwards as part of the security review.

I'm curious how this has played out from a personnel perspective. I think this is probably the only instance that I've heard of where, you know, general IT folks report up through a security person. How have the personnel in your organization felt about that? How have they adapted to that? I think that there is always that possibility where security has always been the downtrodden.

They've always been the ones that get beat up on, and now they're the ones with power. So I'd like to hear from the security side and from the folks that were on the traditional IT side how they felt about it. Yeah, what I'd say is from a culture perspective, the objective was to show that it's a balance, right? The objective was to show that that 2 things. One is that the technology piece is just as important as the security piece and vice versa.

So this wasn't a balance of power or a shift or anything like that. It was making sure that that lifecycle was treated the same across the board. I'd say the other thing is from another sort of culture perspective is adding security responsibility inside each of the respective organizations so they knew that That just as they had to make sure they do backups and they do, you know, high availability and, you know, they have the user experience set up correctly, that they also have their security responsibilities set up correctly. And so I think it's been pretty widely adopted. We've actually shown about a 30 to 40% increase in productivity as far as releases are concerned.

So from a use case modeling perspective, it's— within the first year, it's working out pretty well. Do you think that this is a model that others should adopt, or do you think that you will see more adoption of this? I would say your mileage may vary. It really depends on your management culture and your organization. I really think that a security organization— I mean, the reason why security exists in so many different places, you know, finance, internal audit, you know, the CTO, the CIO, is because of the culture of that particular organization.

I'd say that making sure that you have security in the mindset of your management team and that it's integrated in the culture of your organization is critical. Dale, we talked about— you and I talked about the fact that I'd like to hear some stories, some things you've gone through over the years. I want to dive into a couple of those, starting off with this building of a threat intelligence function you've done a couple different places. I'd love to hear this threat intel building, especially I think starting at level 3, why did you do it? And maybe you could talk about kind of what that looked like over time and some stories from that.

So I'd say a backbone carrier's got a lot of unique visibility, right? It's pretty much the on-ramp and off-ramp for traffic getting access to enterprises and consumers. And so I've always felt that a backbone provider's got a lot of obligation or responsibility ability to help the progression of cybersecurity by identifying threats, cleaning up their network, not sweeping them to other networks, but working with other network providers and getting those threats identified and removed. You know, at Level 3, we started a threat research function. It wasn't the most popular.

In fact, it was not supported at all. We actually self-funded the development of it.

And, you know, and by the way, what that means from a carrier perspective is you collect something called NetFlow data. And NetFlow data is— think of that like, you know, as IP packets are going across the network, you take a sample of the header, you know, the to and the from, and you analyze that data to look for what looks like a bad guy. And so, you know, we did that experiment at Level 3. It was pretty effective in finding bad guys. We did a lot to be able to proactively clean up the network and work with other providers to have them clean up their networks where the sources of the bad guys were coming from.

And we're recreating that, you know, over at Zayo. So, you know, the goal is for ISPs to cooperate together. The goal is for us to work as an ecosystem. There's not just one way of solving a problem. This really does sort of require a multidiscipline approach and requires all of us to work together to be able to get ahead of the bad guy, get ahead of the threat, and get them off the network and out of the enterprise.

Have you seen a lot of cooperation between the different providers?

I can see where they may want to get some of this bad traffic off their network, but I could also see there, you know, there may be some feelings that there are competitive advantages for them not to share some of this stuff. How was that experience in working with other providers? So I'd say in general, and I'll talk about the difference between ISPs and enterprise enterprises. From a backbone carrier perspective, so long as you're not talking products, everyone wants to do the right thing, right? Everyone wants to stop the bad guy.

Everyone wants to be able to get the bad guy off the network. But the moment that you start talking about competitive advantage and you talk about, you know, we have more visibility than you, then that product discussion turns into, I can't demonstrate that that I rely on you to tell me where my bad guys are. And so a lot of those conversations will stop. From the enterprise perspective, so long as you talk to someone in the IT organization and not security, you tend to be really effective at getting bad guys removed from enterprises. I will tell you that most of the conversations we've had with, with the security side of enterprises has resulted in Um, don't ever tell anyone that you talked to me.

Um, you know, we'll, we'll, we, we, we'll get the bad guy out, but don't tell anyone, including my boss, that, that we had a problem, uh, that, that there was an issue, and, and, uh, and delete all the data you've got. At the moment that we talked to IT, then, then they really focused on not only getting the bad guy out, but also working with security to, to clean up their enterprise. So can you share any examples of— you've had some pretty big takedowns over the years? Any of those you could talk about? I'm sure some names people will be familiar with.

I can talk about some that we made public. Wasn't the Mirai one public? What's that? Mirai was public, right? Mirai was public, yeah.

I mean, in general, I mean, what I'd say is using machine learning algorithms, it's really pretty straightforward to be able to determine the activity of some bad guy activity, as well as be able to weed out known good activity, which is pretty important. And so as a result, you know, we had some really good visibility to nation-states and organized crime. And we were one of the first to be able to— Level 3 was one of the first to be able to see that sort of information sharing exchange between organized crime and nation-states where nation-state employees were making themselves available to organized crime for extra money as well as to hide attribution of attack. And it really sort of set the security industry on its head because they couldn't do attribution any longer to figure out who was behind the attack and why they were behind the attack. In most cases, it turned out that if you were facing an organized crime adversary, then so long as you're As long as your systems were more protected than your competitor, you were okay.

The organized crime would sort of rattle the doorknob, and if they couldn't get in and they didn't really want to extend a whole lot of effort, they'd just move on. Nation-state, when they started a campaign against you, you knew that the next year and a half to 2 years of your life would be hell. And so when they started sharing resources amongst each other, it really changed the game as far as how companies could protect themselves what they were in for, how long they were in for, and it really changed how sophisticated organized crime syndicates became. And so we had a philosophy of— and we knew it was gonna make ourselves a much larger target— but Level 3 had a philosophy of finding the bad guys and filtering them, stopping them on the backbone. And so we used a protocol called FlowSpec to be able to dynamically change filters within the backbone that when we saw ransomware attacks or we saw compromise attacks, to be able to dynamically filter that traffic on the backbone and stop those attacks.

And, and we, we think we stopped a handful of emerging attacks that never made it successfully and never made it publicly. And that was the sort of thing that we really wanted to get everyone behind. I seem to remember though a few years ago you go on publicly talking about the success of the Mirai takedown. And do you remember— I just think specifics are great. If you remember any of the details around what the traffic was before you put your controls in place to what the impact of that was.

Yeah, the problem is I can't remember how much we made that public and how much we didn't. It was pretty public. You talked on the CyberWire about it. Yeah. You don't want to get yourself in trouble, huh?

Yeah, I don't. Anything that we talked about publicly, I'm definitely willing to talk about. I just can't remember how much of that we made public. All right, well, let's fast forward into your role at Zayo. I have a couple questions for you there.

You mentioned earlier that you'd had an initiative to try and incorporate as much open source software into your security stack as possible. Talk about the way you looked at doing that, and what's the result of that been?

Yeah, so the thought was that we would try to go to a a full open source stack across our— we use a protect, detect, defend model. And so there's a security architecture associated with that. And the goal was to use open source in much of that stack as we possibly could. So I'd say we're probably, I don't know, 40% into it right now. There's a number of open source initiatives which we've adopted as part of our security method.

The problem with open source is, um, you have to pick an open source community that has a fair amount of support because the whole goal of that is you want to leverage a larger development team than you could ever support internally that's pretty adaptive to threat, that is pretty responsive to features, and does a fairly good job in Q&A. And so out of the couple thousand open source initiatives, that leaves like 3. And so, you know, we— what we've been doing is we've been doing essentially an internal RFI, right? We go to 3 commercial providers, 3 open source providers for every component of the stack. We do all the functionality review.

We do the business case review and then, you know, determine which open source initiative is best for that area of the stack or not. I'm curious, which areas of technology have you seen successes in going with the open source model, and are there any where you've decided, okay, well, this is not mature enough, this doesn't have what we need for this particular type of technology, and maybe have gone to a commercial model instead? Yeah, I'd say it's all the ones that you would guess. I mean, on the SEM side, we've had a lot of success with open source.

As we try to integrate things like security orchestration into that model, there's a lot of really good open source solutions there. I'd say on the vulnerability assessment and code review, we've had some success in open source. I'd say on endpoint security, EDR and anti-malware, things like that, I'd say that we're not happy with that. Sort of environment from a primetime perspective. So we've had to go commercial in those cases.

One of the elements that makes your open source project probably a little more challenging is your need for, like, you know, commercial support, right? You can't just get an open source project that the community is contributing to and just use it and have your own team support it. You have to have the organization involved. Would you say that that's really filtered the pool down to that 3 that's usable? Is that a requirement for commercial support?

No. So, I mean, we ask for commercial support to make sure that we can be in compliance with federal regulations so that, you know, FISMA, as an example, requires that your software, that your security suite has some vendor support associated with it. And I'd say it's actually been relatively easy. There's a lot of vendors who either do that today or are willing to do that. And so, you know, I don't think that's been a barrier to our success at all.

It's just, it's been 2 things, you know, and I'm sure this exists in other industries as well, but as a telco, you know, you have to support every environment that's ever existed for the past 30 years.

And so, you know, your optical gear, you know, that has a lifespan of 25, 30 years. And then you have support infrastructure that supports that infrastructure. And so, you know, finding a single sort of ecosystem view, like we're a Windows shop or, you know, we're a Unix shop— no, we're an everything shop. And so you've got to find ecosystems that sort of span that diversity of capability. I would think there might also be some scale problems, especially anything that that touches the network.

You know, if you're— it's one thing to do an open source project if you're, you know, a smaller enterprise that has, you know, a few internet links, but when you're, you know, a big provider and you're looking at tons and tons of traffic, I would imagine that is something you have to contend with as well. Yeah, I mean, I'd say open source has done a lot of leaps and bounds in the past handful of years to be able to get to some of those scales. I mean, that is one of the theses that we're trying to prove to see how ready open source is for prime time. I will say we put a lot of pressure on open source providers by saying that we're doing a use case that we want to make public. I mean, our goal is that we want to publish our findings about which solutions that we evaluated and which ones we thought were ready and which ones we didn't think were ready and why.

And so, you know, we're putting a lot of pressure on open source providers to, you know, close those gaps as much as possible. From a scale and integration perspective. I think that those, I guess I'll call them white papers, would be something that everybody would be interested in. Do you have any timelines about when you're going to get some of that information out? I do not.

No, I'd say probably mid-next year is when we're going to be done with that sort of ecosystem analysis, and we'll at least have the first version of that published. All right, moving to the next topic I wanted to discuss. You have testified in D.C., right? Could you talk about what the context of that was and really what— how that went? Uh, so yeah, I mean, it was interesting.

Um, Robb and I have been talking quite a bit because, uh, I went, went to D.C., uh, yesterday. Uh, wasn't sure if I was going to make it back in time for, uh, for our discussion today, uh, but, um, Yeah, so there is— so Xeo's in the process of being purchased by its largest investor, and the goal is to make Xeo a private firm and use that equity to do some more investment. As part of that, the investor that we've got that's going to be one of our owners has foreign ownership, and so U.S. government's got a process. There's one called CFIUS, which is a Committee for Foreign Control and Investment, and then there's something else called Team Telecom, which is one just want to make sure that, that there's no market competitive disadvantage by having a foreign own you. And the other one is a national security review to make sure that the foreign influence can't adversely influence your critical infrastructure.

So I was in DC talking to a panel of, you know, 15 or so government agencies talking about the national security side of us having a 5% ownership from the Swedes. So I think we've— I think we all agreed after that 4-hour panel that there wasn't too much danger. But, you know, it's still a due diligence, you know, vetting process where you basically have to educate— I mean, it's 15 agencies, and you have to basically educate those agencies in really basic terms you know, how security works, what products you sell, what those products mean. I mean, if you watch the testimony of Zuckerberg trying to educate Congress on Facebook, you know, amplify that across a product portfolio with, you know, 15 different government agencies. So that was my day yesterday.

So this conversation is great. This is— This is a cakewalk. Yeah, I am curious what the types of questions that you got were. Obviously, you don't need to tell us the exact questions, but were they technical in nature? Were they sort of policy in nature?

And did the people that were there interviewing you, did they seem like they had a general understanding that the internet is a series of tubes and how it worked? Yeah, you know, I'd say if you— in this specific context, I think what the government is concerned about is, can a foreign influence be able to exert their ownership influence to be able to do 2 things? One is intercept traffic that they wouldn't normally have access to or authorized access to. So can they route your traffic outside the US to be able to get access to it? Can they convince you to intercept the traffic for them and send it to them?

That's one concern, is getting access to content. I'd say the other concern is making sure that the provider can execute lawful requests. And the stupid example is, let's say I provide service to an embassy in the US. And the foreign influence comes in and changes the name of that embassy to Joe's Bait and Tackle. And then when we get a lawful request and we say, we need you to intercept this traffic from this embassy, we look it up and we say, we don't have an embassy.

We only have Joe's Bait and Tackle. So the questions really are surrounding what controls do you have in place to prevent those 2 things from happening. And there's a pretty wide variety of answers. So there's a pretty wide variety of technical acuity within that panel. Okay, another Zayo question for you.

I understand you've reorganized your security team, and it sounds like you really looked at it from a pretty different perspective. Can you talk to me about how you've seen that, why you've seen the need to reorganize and what you've done?

So on the security organization itself, we sort of made 4 divisional functions within security. One is for endpoints and servers, so compute. One's on the network side. One's on governance. And one's on threat research and SIEM.

And so we organize it like that so that people could own essentially cradle to grave the responsibility in each of those areas. So for endpoint and servers, it's, you know, it's patching practices, it's device policies, it's auditing, it's things like that. So the goal is to have groups that have ownership of each of those, you know, from beginning to end. This is instead of your tiered approach, right? Maybe just trying to draw the contrast between your previous approach to this?

Yeah, I, you know, I'd say my previous approach, I don't know how normal it was, but previous approach was more of a Tier 1 through Tier 4 sort of function, right? And so we've automated a lot of the Tier 1, Tier 2 responsibilities with the SEM and with SOAR. And so what we were seeing is we were seeing a lot of sort of blind handoffs between organizations and And so, you know, reorganizing based on sort of ecosystem ownership has plugged them in better with the rest of the technology organization and has also ensured that they're not just answering tickets and they're not just taking things off of a queue. They've got, again, that sort of end-to-end responsibility for an area. I want them to worry about a bad guy breaking in the network.

As much as I do. And so, you know, I want them to be thinking about, I'm responsible for endpoint security, and so what does that mean? And so there's a lot more sort of ingenuity that we've created as a result of people taking that ownership of researching more things and being a bit more innovative as a result. So those teams, instead of doing— like, you have— it sounds like your compute security organization does architecture, engineering, and operations. Is that right?

Yeah, yeah, that's exactly right. Then did they have the freedom— you mentioned ingenuity— they have the freedom to do things in a different way, however they want to do it to get things done? Yeah, so we taught everyone in the organization the net present value business case modeling, and so, you know, we've essentially given them as much freedom as they need to do their job, as creative as they want to do their job, so long as they can present a business case that, you know, shows the investment. And so I'd say that we've probably— we pretty dramatically increased our investment as a result. And I'd say that we've— I mean, we've ripped— in the past year, we've ripped every security infrastructure out of the company and replaced it with something new based on that approach.

Wow. Everything. Holy smokes.

Wow.

That's pretty heavy. That is pretty heavy. So, I mean, I guess that gets you away from your legacy support for at least the security technologies. Now you've got all this stuff. So I think that's the end of what we had for prepared remarks, but we get to do something that we don't normally get to do on the podcast.

And that's take questions. So we have a couple minutes if people in the audience have questions that they would like to ask Dale.

Joe.

Hey Dale, Joe Dietz. Just curious, how scale— what was the scale of your organization, the scale of the infrastructure you have to support, and how'd that impact some of the things you did?

Well, with— so I'd say Um, um, so how do I want to answer this question? Um, I'd say scale is a much different challenge now because, um, we have sort of tied security responsibility inside of each of the technology organizations. So whereas that would be a separate group sort of bolted on, we've sort of integrated that into each of the organizations so that the network team has got a set of security responsibility, the The corporate data center team's got a center of responsibility. And so we've spread that out across those organizations and made everyone sort of a security deputy, as it were, on ensuring that security has an integrated lifecycle across the group. And so, I mean, it's really allowed us to have a much leaner security organization.

Because we know a lot of that's being taken care of as part of the discipline inside the group.

We do have another question. I'm impressed by your net present value assessment in forklifting your security equipment. Do you feel that your position is more secure now after having forklifted everything out?

Do I? Well, With regards to— so the net present value calculation is intended to show here's how much you're currently spending for something, and here's how much the new thing is, and here's sort of the difference between the two, and here's the value the new thing provides the old thing didn't provide. And so we've been able to demonstrate that new security infrastructure actually brings with it more value. I'll give you an example is we wanted a new endpoint solution. And so we took how much we were currently spending on our existing endpoint solution and what it was capable of doing.

We came up with a new endpoint solution and the additional functions that that solution provided and how much more capability it would provide, how faster it would respond to threats, how it wasn't signature-based, it was more sort of threat sensor-based. And how much— I really want to— I really try to stay away from man-hour calculations, because I don't want to throw employee savings into the equation, because you just want to use your resources to do more and more things. But that, you know, what we are essentially showing is— and I'm going to make up numbers— but let's say we were spending $100 on the current solution, And let's say the new solution was $150. So right off the bat, you're able to say, I only need $50 more. I don't need $150.

I only need $50 more because I'm gonna destroy that and take all that money and do this. But the features we get out of it are worth far more than the $50 that we're thinking that we need to spend on it. And so that resonates really well with management who's looking to invest its capital dollars in advancing the business, and they have to take that money away and give it to you, and you're not getting revenue out of it. And so that sort of language, at least in my company, resonates with management on an investment perspective. And we were able to do enough of those business cases over the past year to demonstrate that— I mean, like I said, we ripped out every piece of security infrastructure we had to replace with something brand new.

Dale, we're just about out of time. I have one more question for you. We've talked about You and I have talked about your desire to change the way GRC works, and the way vendor risk management works. I'd love to hear your thoughts about the state of vendor risk management, and how you'd like to see it change here. You have a couple minutes left.

I hate governance, risk, and compliance in this industry. And, um— yeah, exactly. I was not expecting a standing ovation from that, but— What I will say is it's an art form today. It's not a science. Every company who wants— so supply chain management is critically important.

Making sure you know what your vendors do and how they protect data that is in— your data that's in their custody, critically important. But everyone acts differently depending upon their goal, right? So I'm in the data transmission business. I don't have data. And I get asked governance, risk, and compliance questions differently from every industry, and even within industries differently from every customer we do business with.

Some want security certifications. Some want to do their own internal audits. Some just want you to answer a 400-page questionnaire that has nothing to do with your business model. And so, you know, what ends up happening is you as a company end up disclosing significant amount of information about your security architecture. You end up giving them more information about your security controls from a risk perspective than what their risk is in doing business with you, right?

No one ever asks, what are you going to do with all the data I just gave you? Where are you going to store that? Who are you going to give it to? How are you going to protect it? It?

Because I just told you how I'm generating passwords and protecting data and patching systems and, you know, my entire security model. Why is that not more important than the questions you're asking me? So I don't know the answer. I know what we are doing is we're doing some social experience with customers. Some of them we're sort of telling them ahead of time and some of them we're surprising them.

But, you know, my goal is if we could blow that industry up and start from scratch and make it a bit more of a maturity model discipline, that would be my goal.

Awesome. Well, we're just about out of time here. Thanks very much, Dale. We appreciate the conversation. This has been wonderful.

Let's give it up for Dale.

All right, call to action for all you guys. We do have a weekly podcast like we mentioned. You guys can go out to your favorite podcast listening app, iTunes or Google Play, subscribe Colorado Equal Security. We put some stickers on the table by the front door. Grab, grab your Colorado Equal Security sticker, wear it proudly like Alex has on his shirt.

Put it on your laptop instead of your shirt, it'll last a little longer. And we appreciate all your guys' time, and of course stay warm and be safe today, guys. Thanks, enjoy the rest of the day. Learn more about the Colorado security scene at coloradosecurity.org. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.

Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes