All episodes

Alexis Kirkman, Associate General Counsel, Privacy and Cyber Risk at IHS Markit

Apple Podcasts Spotify SoundCloud

News from: Norwegian Air, Guild Education, OpenText, Carbonite, Webroot, NREL, Ping Identity, Coalfire, Rule4, LogRhythm, and a little bit more!

Rome if you want to…

Rome around the world. Denver is pretty healthy. Technology is a’comin’. Guild Education raises big dollars. A bigger fish buys Webroot parent Carbonite. NREL hosts Cyberforce (2, Electric Boogaloo). Ping Identity releases their first results as a public company. Coalfire says the bad guys are coming for you, mid-sized companies. Rule4 gets their B Corp. And LogRhythm hires new leaders.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9788 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 142 on November 18th. Uh, we have, uh, Brian Beyer here, special guest co-host.

Hi, Brian. Good morning. How you doing? Wonderful. Great to be here.

It's fall in Colorado. I know. Beautiful sunny Sunday.

Sun's out. That probably means I should be outside raking leaves or, you know, picking up apples or doing something like that. Finding whatever animal or Star Wars creature is making that noise in your backyard. Exactly. Could be either of those.

But instead I'm in my garage recording this podcast.

Anything exciting going on lately, Brian? How things been? You know, it's been great. We just wrapped up our 3rd quarter, which means we had the whole Red Canary company out in Denver, which is one of my 4 favorite times per year to get everybody together and get to know a lot of the new faces. Cool.

Good stuff. Good stuff. Glad you guys still are the size where you can bring everybody together all at the same time. It is completely unreasonable to bring everybody together in size. It's way too big, but it's awesome to have everybody There.

Awesome. Well, let's jump into the news. But before we do that, let's do some announcements. We of course have a Slack channel. If you haven't been there, you should be there.

Go to the website colorado-security.com, click on the Slack channel button, it will take you there. That is all you need to do. We've got about 1,150 of your closest Colorado Equal Security friends in there hanging out and chatting. We also have a mailing list. So if you want to get these show notes delivered to your email every week, go to the website, put your email in, and you will get notified when there is a new episode with the show notes.

Also, please rate us and subscribe on the favorite podcasting service of your choice. That way you get the podcast delivered directly to you, and we get to let everyone else know how good the podcast is through the ratings. If you don't want to do that, please tell a friend. Just let them know all the great things that we are doing. Pass them on to the website, the podcast.

Have them show up and hang out with everybody else. If you want to go even farther than that, we would love for you to sign up for our Patreon campaign. Give a couple bucks to help with the costs that we incur from doing the podcast, hosting, and all those sorts of things. And as both Robb and I get busier and busier, we would love it if people would like to step up and be interviewers for the show. If you have listened to some of the past podcasts recently, we have had some guest interviews and they have gone very well.

If you would also like to be one of those interviewers, please let us know. Also, if you think you have an interesting story to tell and want to be an interview subject, please also let us know and we'll try and get someone to interview you. So with that, Brian, let's jump into the news. Norwegian Airlines is going to launch a new international flight in Denver in 2020. Where are we going to get to go to?

We are going to Rome. Nice. And we're going maybe on a Dreamliner if they can fix the engines. Yes. So it's funny, this summer my family and I took a trip to Europe and we took Norwegian to London.

And one of the things that they mentioned in this article is that Those flights were originally supposed to be on the Dreamliner. Right. And then they outsourced them to a Spanish carrier called Wemos. So we actually rode on one of the Wemos planes as opposed to the Dreamliner. I was really looking forward to the Dreamliner, but the plane was just fine.

Direct flight from here to London, you know, good amenities, nice food, all that kind of good stuff. But this is pretty cool. This is going to be the first nonstop flight from Denver to Italy. That's so— that's pretty wild. I think it'd be awesome to fly on one of the Dreamliners as we get the bigger and bigger planes between those and the big Airbus planes.

That'll, that'll be a lot more fun to go overseas in those. Yeah, and I think if nothing else, even if we don't get the Dreamliners right away or there's sporadic issues because of the problems with their engines, we have to fly on Wemos, it's still good for everybody because that means other flights to Rome and Italy are going to be cheaper because of the competition. That's true. Whether or not you fly Norwegian, I think this is great for them to come in and help lower costs, add international flights in Denver. So pretty cool stuff.

Definitely a good sign. We also have Denver is moving up in the ratings of US cities based on healthy policies. So this looked at different policies across affordable housing, the Think like whether or not you're allowed to buy tobacco at certain ages, whether you can smoke indoors, kind of a wide dimension of different policies. And Denver moved up. We're now rated silver across a wide number of different categories.

We're number 2. We're number 2. Oh, just kidding. Um, yeah, so Denver was actually awarded gold on several of the policies. They actually have a number of different policies that they look at and they award them individually, and then there's an aggregate that gives you the overall score.

So Denver was awarded gold for having safer alcohol sales policies, smoke-free indoor air, and raising the minimum legal age for the sale of tobacco products to 21. So those are all good things. They had improved from the previous year. I think last year Denver was a bronze. Right.

So made some public policy changes, and hey, we're moving up in the world. Up and to the right. That is right. Yes, let's get in that magic quadrant. Exactly, the magic quadrant for mid-sized cities in America.

I think right now we're in the visionary quadrant. Okay, we change a couple more of those and we'll move up a little farther. Perfect. Be in the leaders quadrant. That's great.

So good stuff, good stuff. Glad that Denver is moving up. And including moving up, did you know that the floodgates have opened in Denver for tech companies moving in? Sounds right to me. I hadn't noticed personally, but this was based on a survey by CBRE, which is a real estate company, and they are looking for the top 10 cities with tech growth.

And Denver's 2-year tech job growth rate was up 13.8%. So it was— that's a misleading number anyway. I think it was at 13.8%, up from 11.5%, even though that's not how exactly they have it written there. And so last year we were number 13, this year we are number 10. So pretty cool.

Yep, good movement. We also have locally, speaking of those tech companies, Guild Education, which is a Denver-headquartered company, has become the latest female-led company to have a billion-dollar-plus valuation. They just closed their $157 million Series D led by General Catalyst. And really exciting to be— to see more great companies, especially Guild, continue to grow here in Denver. Yeah.

I don't know anyone at Guild personally. But I really do like the mission that they have of trying to get education for people in sort of low-paying entry-level kind of jobs. I think that's a really cool mission. I also think it's cool that it's a female-led company. One of the things that I thought was interesting in the article was they noted that the company didn't need to raise capital, which was the time for them to raise capital.

Brian, what exactly does that mean? That's what we all say when we get to raise money when we want to. There's effectively— someone once described it to me as there are 2 times when you can raise money. One is out of need, because you actually need the money or else you're going to go out of business or something bad's going to happen. Or you do it out of greed, which means things are going well, someone has showed up with an attractive offer, and you say, now's the right time for us to go take in more money, add new partners as a part of that.

That's always the position that Rachel raised out of. That's what Red Canary has tried to do. It's a good spot to be in. You get a lot more leverage. You get to pick who you want to work with.

You don't get stuck with someone or unfavorable terms that's bad for you or your employees. I thought it was interesting that they said that a chunk of that was just going to go right into the bank, right? It's like, hey, we're going to— we have leverage. We're going to get good terms on this. We're just going to take that money and throw it in the bank.

And when we need to use it, we'll use it. But It is. And if you ever want a place to be, if you ever want to do fun math, do the math on what you're like. Think of the interest rate you get in your personal savings account, right? 1.7% or something right now.

Calculate the monthly interest you get if that actually all goes into the bank. Yeah, that's true. We did that after our Series B. It's a staggering amount of money. It's pretty cool.

That is pretty cool. I would like to have some money like that in my bank account to get a little interest on. Well, now you know what to do. And it sounds like we don't know enough about the Guild team. So if anyone's listening from that team, we need to get them on the podcast and learn more.

They actually had a job post recently for a CISO. So I know that they're hiring in their security area. Perfect. I look forward to talking to that person when they're there. That's great.

On other news, OpenText is buying Carbonite. So on first glance, people might think, Well, what does that have to do with us? So as you might remember, Carbonite last year bought Webroot, which is one of our stalwart security companies here in Colorado, to try and pivot a little bit more to, instead of just being a backup company, to being a security company. And now they have been bought for $1.4 billion by OpenText. So pretty cool.

The price was a 78% premium on Carbonite's current share price, which congratulations to Carbonite shareholders. That's great. That's awesome. It'll be interesting to see what happens with the combined Webroot team. I know that they were— that the Webroot offices here were the largest Carbonite office, right?

So I wonder if that is going to continue to be a focus for OpenText now, or what's going to happen. We'll see. It'll be interesting to see and find out. How much do you think Carbonite's growth in value directly relates to everyone getting better at backup and recovery following ransomware? Yeah, I'm sure that is a big part of it.

I also, I think it was a smart decision by them to add more general cybersecurity pieces along with the backup pieces. I think those, there's some synergies there between the 2 different kinds of companies that now made them much more attractive to be purchased. So 5 points for the word synergy. That's how you get millions of dollars in your bank. For those of you playing buzzword bingo out there, Please check your cards.

And check your cards because NREL is hosting the Department of Energy's Cyber Force competition. Yeah, that Cyber Force is only on a few of those cards. It's a good word, but not too many cards. It actually looks like a pretty neat competition combining almost like a red team, blue team type exercise focused around what I think of as like your industrial security controls and your power stations and systems like that. And it looks like they're doing it through a lot of the federally funded research development centers like NREL throughout the United States, and then having local security teams be the blue team to defend those networks against a bunch of NREL and other red teamers.

Yeah, sounded pretty cool. Reminded me a lot of CCDC. Exactly. You know, so this is college focused. And as you mentioned, there's a lot of the national labs are participating in this.

Uh, so I think it's all sort of happening at the same time, and there will be teams at all these different places— excuse me— and there'll be local winners as well as overall winners. Competing locally, there were teams from Carnegie Mellon, Red Rocks Community College, School of Mines, CU Boulder, Colorado State, and CU Colorado Springs. So pretty neat. This is the first time that NREL has participated in the competition, but this is the 5th time that the competition has been held. Glad to see that that is continuing to go and that we're getting some participation here.

Speaking of local security companies, Ping announced their first earnings since going public. Congratulations to them. Too bad Robb isn't here to talk about it, or maybe it's good that Robb isn't here to talk about it. Doesn't want to say anything that he shouldn't say. They had an annual recurring revenue, or ARR, of $206.7 million for the 3rd quarter, which is a 23% increase since that quarter last year.

Revenue was $61.8 million, a 45% increase over the previous year, and subscription revenue grew 49%. Seems like pretty good numbers. Most importantly, they beat their targets that they had proposed, which meant that their stock price jumped 15% afterward. Yes. So congratulations to those at Ping that now own stock.

Good stuff for you guys. Hopefully it stays there for the immediate future. We have Coalfire, an article talking about cybersecurity research, talking about the shift of risk down to midsize businesses. So not just focused on your largest enterprise, but looking at some of these high-risk factors and seeing how it shifts over to midsize businesses. Because they're the ones in part heavily moving to the cloud.

Yeah. Whereas large enterprises have been doing this for half a decade now and learning sometimes painfully how to do that the right or wrong ways. Now you have a lot of mid-sized businesses who are moving there and don't have as many resources to go defend those systems. For sure. Yeah.

So they release, they being ColdFire, release an annual penetration testing report, which is what this is talking about. And, you know, Coalfire is big in penetration testing. They do a lot of penetration tests. And their report last year I thought was interesting in that there were big changes from the year before, but partially because they didn't separate out some of their customers. So Coalfire, which people may or may not know, is a penetration tester and SOC producer for Amazon.

So they do this stuff for Amazon Web Services, right? And so they included those penetration tests at an aggregate in their last year's report, which made it look very, very different from 2017 when all of a sudden it's like, oh hey, we're testing all of AWS. And this year they made sure to note specifically, hey, we put some of this stuff off, you know, in its own little area to make sure that we were comparing apples to apples. And so there were some good things that came out of that. This should not be a surprise, but phishing continues to be a serious issue.

In 71% of their tests, organizations experienced at least one full compromise of credentials. That seems like a low number, even though it's 71%. And in 20% of their tests, organizations saw approximately half of their targeted employees give up their credentials. That seems like a pretty big number to me. That is a scary number right there.

That is a scary number. Yeah, so anyway, um, the report is out now if you would like to read more of the details, but pretty cool stuff from Coalfire. Uh, next, Rule 4 has earned their B Corp certification. So Rule 4 is Trent Hines' new company out of Boulder, and we talked about when they started last year that they were organizing as a B Corp. So B Corps are slightly different than normal corporations in that they have to have a public good as part of their corporate charter.

And so now Rule 4 has been certified as a B Corp by B Lab, which I guess is a company that, that certifies folks to make sure that they are doing what they say that they are doing to take their mission for being a B Corp seriously. I thought that was neat to read about. I had not heard of any security company, or frankly not a lot of tech companies, who've looked to be B Corps before. Yeah, you normally tend to think of brands like Patagonia or Athleta as a part of that, going that way. So this is neat to see.

I'm interested to see how this guides the future decisions they make, you know, how they raise money, how they grow. Be very interesting. Yeah, some of the other companies that have been certified through B Lab include Patagonia, as you mentioned, Ben Jerry's, and New Belgium Brewing Company. There's definitely a public good in beer. I was gonna say, I can't wait to see how they describe that public good.

Yeah, good stuff. So congrats to Trent and the team over there for their certification. And then finally, we have LogRhythm, who has strengthened their executive team, adding a new Chief Marketing Officer and VP of Product. Cindy Zhao is the new Chief Marketing Officer coming in from Back Office Associates, IBM, and several other companies, and going to be focusing on their overall marketing strategy. And then we have Michael Jones, joining to lead product, who has worked at places like Domain Tools, as well as Cisco and McAfee in the past, all focused on how do they better go to market and connect with their customers.

Yeah, pretty cool for LogRhythm. They've been going through some leadership changes over there since being acquired by private equity, so good to see that they're continuing to add to the executive team over there, and hopefully these will be good hires and pushing them forward. So that is it for news. Let's quickly move over to the Slack message of the week. Uh, thanks again to Andre Gaeta for sponsoring the Slack message of the week.

He's been doing this out of his own pocket for a number of weeks now, and we use this to recognize someone in the Slack community who has a good contribution, and we award them with up to $25 in free swag from the Colorado Equal Security Store. So this year's winner— or this year— this week's winner is Daniel Ayala. Congratulations to Daniel. He was chosen because he posted about a website that he is putting together called Privacy Maven, and this is sort of a news aggregation service for privacy-related news. So he is taking the time to do some curation on privacy-related news and putting it out there at the Privacy Maven website.

So if you're interested in getting more details on that, we will include the link in the show notes, or you can go to the Slack channel and check out the GRC and Privacy channel, which many of you may not even have known exists, and find the details in there. So pretty cool. Congrats, Daniel. We'll get him in contact with Andre to get his free stuff. So let's jump over to events.

Of course, we look out 2 weeks in terms of upcoming events. If you wanna see these events or more events, go check out the combined event calendar on the website at colorado-security.com. First event we have on November 18th, the ISC² Pikes Peak chapter is doing their November chapter meeting. On the 19th, we have the Denver ISSA Women in Security November meeting. On the 19th and 20th, ISSA Colorado Springs is doing their November chapter meetings.

Back in Denver, ISSA Denver is having their November happy hour on the 20th. Also on the 20th, OWASP Denver is doing their November meeting. Also on the 20th, so you can hit 3 in 1 night, DenverSec is holding their November meetup at the Rhine House. On the 21st, ISACA Denver is doing their November meeting. Everyone is trying to get everything in this week before you hit Thanksgiving.

Following ISACA, ISC² is having their Denver chapter meeting and focusing on the top 3 services that can help change the security of an organization on the 21st. That's an interesting topic. Might be worth checking out. And finally, also on the 21st, SecureSet is doing an intro to software security with Tremaine Island. And that is the last event we have.

After that, there is a break in the event calendar the week of Thanksgiving, not surprisingly, and then things will pick back up in December. So let's jump over to jobs. Again, we pick some jobs every week that we think are interesting to share with the community. You can find these in the show notes. First, the Department of the Interior is looking for a cybersecurity specialist in Golden.

Comcast is looking for a principal cybersecurity architect. Deloitte is looking for a cyber GRC ServiceNow manager. Travelport is looking for a cybersecurity engineer level 2. You must be twice as good as a level 1 though. Shutterstock is looking for a cloud security architect.

Direct Defense is looking for a security analyst. Western Union is looking for an organizational change manager in cybersecurity. That sounds like a pretty cool job. It does. FirstBank is looking for a network security analyst.

Highly recommend working with that team. They are awesome. And finally, Metro State is looking for a cybersecurity lecturer 2. So if you are slightly more experienced in your lecturing and want to lecture at Metro State, check that one out. So that is it for the newscast.

We are going to jump over to our feature interview, and this week's feature interview is with Alexis Kirkman, who is the Associate Privacy Counsel at IHS Markit. This interview was done by Ty Burke, one of our guest interviewers. So looking forward to hear that. So if you want to hear from Alexis and Ty, stay on for the interview. Otherwise, we'll talk to you next week.

Have a good one. You too. Thanks, Brian.

Hi, this is Vincent Grimard, CSO at Nelnet. Welcome to Colorado Equals Security for Colorado security professionals by security professionals.

Welcome to Colorado Equals Security. I'm Ty Burke here filling in for Alex and Robb, and I've got with me Alexis Kirkman, who is the Associate General Counsel for Privacy and Cyber Risk at IHS Markit. Alexis, it's so good to have you here. Thanks for having me. And it is cyber risk.

We just determined that it's cyber risk, not cyber security. Right. And that was by looking at my, uh, my email signature. So, well, it's so good to have you here, Alexis. Uh, you and I have known each other for a little while now.

Um, you're heavily involved in the privacy world. Um, and, um, you know, we don't have, uh, on the podcast we don't get a ton of attorneys. Um, so hopefully this will be a different kind of wrinkle than, than what we normally have, you know, practitioners within the security field. But before we get to that, tell me a little bit about your upbringing. So I know that you grew up in Colorado, you went to school here.

I'm just kind of curious about, you know, early upbringing into education and how you decided to get into law, and we can start there. Sure. So I am from Denver. I grew up actually in Park Hill and went to East High School. And then University of Colorado.

And I was a sociology major and political science. And like many, you have to kind of, at the end of having a BA, figure out what to do with it. And my parents also told me that at that point that it was time for me to spread my wings and stop giving me money. So I decided that law school seemed like a good way to go. I don't have any lawyers in my family.

My mom was a psychologist and my dad was a mailman. So just kind of took a risk not really knowing what I was getting into. So went to law school. Law school generally is very litigation-focused. And so I ended up going to a firm where I focused on litigation, white-collar crime, and internal investigations.

And so actually, I guess in between that, I did a clerkship, which is in federal court. You clerk for a judge, you work for a judge, help them write opinions, etc. So you do that for a year, and then I went to a firm and did that for about 2 and a half years and was ready kind of to make a transition to being a builder as opposed to somebody who kind of is critical of the work on the back end. So as a litigator, your job is kind of to tear it down, to see, you know, make arguments based on what the flaws are, spot issues, etc. And I was really ready to kind of build and help people in the context of kind of making their goals happen.

And so I went to SendGrid, which was an email company. They went public back in 20— what was it, 2017? While I was there, and then were acquired by Twilio. Which is an SMS company. And while there, I was corporate counsel and data protection officer.

And so I was in charge of the data privacy program. I worked with information security regularly, working on getting, you know, deciding on deciding what we do with data at a time when GDPR, the General Data Protection Regulation, was going into effect and kind of what that means for big data, generally data, how you want to treat data, how you kind of, I guess, what ethos you want to have as a company as it relates to data. Okay. And then from there, I was privacy counsel with Twilio for about 9 months during the transition and then received a great opportunity to go over to IHS Markit and be Associate General Counsel for Privacy and Cyber Risk. That is a lot.

Yeah. Yes. And so it's a big company. There's about 15,000 colleagues. So it's an information company.

So they use, you know, data insights to help people make decisions. So some of the things that IHS does is they help all automobile makers decide what kind of cars to make in the following year. So when you go to the DMV and you register your car and have all your systems, your information there, that's actually being provided by IHS. Really? Yes.

And another, another cool thing— I've learned lots of cool things they do. They have lots of different kinds of business. Another thing they do is they give the information to a lot of federal governments like the Bank of England to decide interest rates for your mortgage, and the U.S. government as well. British company? Uh, so they— IHS was a Denver company and Markit was a UK company, and they merged.

So the headquarters, I think officially are in the UK. Okay. Um, but they're pretty global. Okay, so, uh, that's a lot. And now we're gonna— yeah, we can break it down.

You can always interrupt me too if I'm— but your dad was a mailman. I always wanted to be a mailman. Yeah, I always wanted to understand the inner workings of a post office because at first, when I'm— when I say I always, I'm talking about my 8-year-old self. I I'm so curious about how does a letter from Kansas City that needs to go to Pittsburgh get routed through Chicago and all the interlogistics of it. And that's just in 2 time zones, let alone at a global scale.

But so he walked the streets here in Denver? So he was a rural mailman because he was up near Larkspur. So he drove. And instead of getting out, he invented his own little contraption with like an arm so he could just put it in the mailbox without getting out of the car. But theoretically he should have been walking around.

Yeah. Wow. That's cool. Yeah. Is he still doing that?

No, he's retired. Okay. Yep. Okay. Gotcha.

So he retired when, or stopped doing that when I was in middle school and they actually run. So my parents had invested in the '80s in a bunch of houses in Denver. And he runs those as a landlord. Okay. Did your parents, did they grow up in Denver as well?

My mom's from Cuba and my dad's from Utah. So they met here at an ashram in, I don't know, in the '70s. Okay. So, you know, meditating, they have a guru. So cool.

Yeah. Very cool. All right. So you broke down your kind of high-level background a little bit.

Talk to us a little bit more about your transition into the corporate side, specifically focusing on privacy, data privacy. There's— you saw something, you saw an opportunity there that I think probably gets overlooked quite a bit by by everybody, just in terms of how we're protecting our data and what we need to be doing about it. And, you know, I think a lot of people would agree that here in the United States, we're probably behind Europe and other countries even, or regions, I guess. Europe's not really a country. But just talk to us a little bit about that.

I think, you know, where was the opportunity for you, and then why'd you choose to pursue it? So to be totally honest, the opportunity was there because I was the newest lawyer and nobody else wanted to do it. But it ended up being something that I didn't want to just do, that I really enjoyed. There's a lot to learn. There's also, you know, kind of being on the cutting edge, at least in the US, as, you know, the opportunity to be a thought leader and to find, you know, I think there's always the the aspirational and kind of balancing the aspirational with the business realities of what, you know, because data, you know, it's been said that data is modern, the modern kind of oil, right?

But I think one thing that I found really interesting in learning about all of this, and like you said, is that the US thinks very differently about data, Americans generally, than Europe, for example. So You know, there's been this historical trade-off here that you get things as a consumer, you get things for free because you give them all of your information. And I think there's been a general lack of knowledge and awareness about what information they could have on you, what they— what you willingly give over, what you're consenting to. And you see, I think you see a lot of people being surprised by What kind of monitoring is going on in their everyday life? And so I think that there's a great opportunity in the US to grow there, to thinking about, you know, as states are trying to implement laws, the patchwork of compliance that they're creating, I think will call for a national law.

But just generally kind of what, you know, the ability to be a thought leader and kind of lead a place that I see is inevitably going. Um, when, when do you think that, that federal law is— not to put you on the spot here, but it's something that, uh, lots of people have questions about, and obviously California is doing kind of their own thing. Um, but what do you think the timeline of that is? I would not say in the next year, maybe the year after. I think that, uh, The California CCPA, the California Consumer Protection Act, needs to go into place and see kind of the how it's implemented, what if there's any prosecutions under it, etc.

But I know even like it's an interesting place to be because a lot of companies are proposing legislation to the government to try and have restrictions imposed on themselves. So it's a pretty interesting area to think about because if you think about historically, I wouldn't say most companies get involved kind of on the front end saying, please like create a uniform law to regulate us in our data where that's where we make our money.

So I think that that's a really interesting dynamic that— Who are those companies that are doing that? So, there was, it was last year, they went and testified in front of the House. I can't remember who, but large companies like Google. I want to say Oracle. There were a few that went and testified in front of some committees and had some draft legislation.

Okay. So, given your knowledge of kind of how data is used, especially at IHS Markit, Does that change your purchasing decisions as a consumer? I know for me, I'm like a wacko about this. I just don't— it infuriates my wife because it's like, sign up now and get $10 off the next time. It's just like, nah, it's not really free.

There's all sorts of drawbacks and stuff. And I mean, I think we all know that our data is out there, right? It's just you need to figure out how to corral it. But I'm curious, as someone who knows kind of how these things work and how companies, for lack of a better term, take advantage of consumer data, does that change how you buy things or how you shop online or anything like that? No, it doesn't.

I wish that it did, and I am very well aware of the kind of what I'm signing up for, but I still still do it. I think the US is not necessarily at a place where you are really able to opt out in the way that you should be able to. And also, you know, I'm a millennial. I know I don't really mind. There's no— I guess I haven't suffered consequences yet, maybe, is my— Yes, absolutely yet.

I am sure it will happen, but But my husband is the same as you. He doesn't want to fill out any information anywhere. Has, you know, all kinds of blockers and security checks. You know, like, only browses on incognito. Like, very serious about that.

He shuts off his location on— Yeah, and he has all those apps like the Encrypt.me apps, the things so, you know, even when he's on his phone, you can't do certain things. And he's an engineer, so he's very, very into that. Yeah, okay. But I strongly suggest to anybody listening that they do do that. Don't follow my footsteps.

What does it look like in practice when you say do do that? Like, what are you referring to? So I think a lot of people— so for example, when I think about email, the way that people manage their inbox Sometimes they— I know some people make their own marketing email address where they send things they never check. I would recommend utilizing unsubscribes, mark things as spam, you know, to train your ISP, your email service provider, ESP, so to make sure that they're kind of protecting for you, filtering for you. You know, encrypting on your phone, not accessing things on public Wi-Fi, not joining any regular Wi-Fi.

You know, think, think, be conscious about what you're subscribing to when you are signing up for things.

Okay. When you unsubscribe, I'm a passionate unsubscriber. Yes. I look for it, you know, all the time. Right away, and yet I still get probably too much email.

Are you really unsubscribing, or does it depend on, you know, who the kind of the owner of that data might be? I've kind of been told 2 stories, like, yes, you're being unsubscribed and they're deleting your data. The other is they're unsubscribing— you're being unsubscribed and that means you're just not getting emails anymore, but they still have all of your information. It definitely depends on the sender and what their practices are. So, I mean, in theory, when you unsubscribe, they should keep your name and your information so you can remain unsubscribed.

So you— they're still going to have your information. There's always kind of the discussion of if you, you know, you want to remain unsubscribed, but then what if you— so for example, I do this all the time, like I like to shop at the same places, and as soon as I buy something, then I get more marketing emails, and I unsubscribe subscribe, and then I go back and I want to buy something and I repeat the cycle. So am I reconsenting to have information sent to me by buying?

So it must be a confusing customer for the marketing teams at— Yes, yes. So it kind of depends on, you know, what— how they decide to make those calls, because I still also want to receive my receipts, but That doesn't mean I want to be marketed to, but maybe some days I do. So, and I think that that's a pretty kind of typical user behavior. So, but to adhere to comply with unsubscribe lists, they have to keep your information. Okay, okay, I didn't realize that.

So it kind of depends on who they're using too. If they're using like a mass marketing email, if it's an in-house system, etc. So for example, at SendGrid, they keep your unsubscribe unsubscribed list for you so you can comply. Whereas if, you know, depending on an in-house system, if it just deletes, then they never will know whether they deleted you or not. Okay.

Okay. So, again, you spent time at SendGrid, which became part of Twilio. Talk to us about that acquisition and what that meant for the legal team. Because, you know, I would say over the last 5, 10 years, it's one of the marquee acquisitions, at least for Denver and the Front Range. And I think it meant a lot to a lot of people.

Some people obviously probably did pretty well. But what did— for the work that you were doing, and maybe even get into specifically the type of work that you were doing, but how did that change? I mean, was it just at a much larger scale now? Obviously, you were already public, they're public. Did that change at all?

Or just kind of walk us through that. Well, so by being acquired by a public company, we were no longer public. So we just became at first a subsidiary, and I believe now they're totally subsumed. Okay. Subsumed.

Never heard that word before. Yes. So now they're fully a part, I guess I'll say integrated into Twilio. All right. And I think it was really cool being a part of SendGrid going public.

SendGrid being a great, you know, cool tech startup here and growing and being very Colorado homegrown and going through IPO and then the acquisition. So it was all very interesting. As far as, you know, privacy and cybersecurity, it was great to walk into a program that, you know, as part of it naturally, as part of companies growing, you know, we had put together what we thought was best with the resources and the size and et cetera, but they're a bigger company, more resources, so they had much more developed privacy and cybersecurity programs to learn from. And also to, you know, they were wonderful about also accepting and considering kind of improvements, ways that we could change things, you know, saying we do it this way and this has been very efficient, and also, you know, making their own process improvements, based on what SendGrid did.

So, and I was very impressed with the privacy program there. They had been very thoughtful. They had been very intentional. And my boss, who was Sheila Jambikar, had done a really great job, and her team obviously, of kind of getting company buy-in and education around privacy and why it matters and why, you know, it should be a foundational element of the organization and how they think about data and consumer data and all of those things. So, I was very impressed.

That's super interesting because I think we use the word cost center quite a bit, and not necessarily— Speaking about legal, yes. Well, okay, you said it.

But it was kind of a foundation. It sounds like it was one of the pillars that her team was kind of built on? And how did— was there a lot of buy-in from the top, from the board, from the C-suite around kind of the importance of adhering to privacy regulations and things like that? I would say at both organizations. Because that's not— there's a lot of companies who don't think that way, right?

Yeah, well, and I think there's a lot of companies that put it, especially when it was just GDPR. And now there's GDPR-ish, GDPR-esque, or whatever you call GDPR-light laws kind of going in place all over the world. But it was kind of like, well, some companies even locally I know decided to not be GDPR compliant and just not accept EU data and/or say they're not. But I think that they did a great job of kind of recognizing that this is a global approach. Another thing I really— that is kind of a foundational point for me and something I've learned from and I know that I want to implement everywhere I go is kind of creating a global privacy program and trying to treat all data the same in the highest way.

So in the best way, the most protective way, which was the Twilio and SendGrid approach to data. I wasn't there when they did it at Twilio, but I would definitely say there was executive and upper-level buy-in. I can't tell you how they did it, but they did a really good job. And I do know that at SendGrid, it was the same. We were just smaller, not as well-developed, but generally an appreciation for it, a recognition of it, an understanding of the importance of it and how to treat it, and also that we wanna apply that standard across the world, across all data, and not try and distinguish.

That's so cool. That's really good to hear. Yeah, it was a great learning experience for the short time I was there to see kind of what a very well-built-out program should look like and how to get that buy-in and how to even get people thinking about about data protection at the beginning when you're building a product through the product lifecycle to an end product and going forward. I also think it's a great selling point for customers when you as a vendor can say that you protect data in whatever way. Yeah, definitely.

So you've kind of carved out your niche. Niche as a privacy guru.

And this is also something you and I have talked about, I guess, sort of probably talked about over a year ago. But tell me about what you think makes a good data privacy leader. And this question is rooted in the fact that there's really no template, right? There's not. There's a lot of A lot of large companies have Chief Privacy Officers.

Privacy is all-encompassing. Data privacy is, you know, let's call it a subset.

But individuals can have a really varied background before entering into it. So what are some of the things that, you know, maybe some of the listeners out there who maybe they're thinking about a career change, maybe not, maybe they're adding to their personal repertoire who might be interested to learn about what it takes to become a data privacy officer. So, what courses to take, what skills are needed, and maybe even just background. Is it legal? Is it IT?

Is it cybersecurity? Is it something in there? Talk to us about that. Sure. So, I've actually had quite a few people asking me this lately.

Oh yeah? That's a good sign. Yeah.

I still have a bit of, I guess, impact. Imposter syndrome because I could give— I'm happy to tell you what I have done and what I think are good ideas, what I've seen work, but, you know, I still feel like some days that I'm learning very quickly. But yeah, so I've had people who are lawyers wanting to get into the space, non-lawyers wanting to get into the space, asking, you know, how, what kind of things do. Yeah, and it's been— I'm glad to hear it. Are these people with whom you've worked in the past, or they just reach out to you and say— Both.

Or people who connect me because they know somebody, you know, they know that I do this and that somebody they know is interested. So I think that the IAPP certifications are important. So I think that they're good base education, and I think That is something that everybody's looking for in the space there. You know, when I'm even looking at job postings, they say, you know, IAPP certification is a plus, or they'll, you know, likely want you to have them once you get going. I have found IAPP as a great generally privacy organization.

They provide like lots of resources. A lot of the content, I guess the contributors, the instructors are really really great. And I, you know, in my early days and even now, sometimes a lot of them are the lawyers that I work with as outside counsel when I have— when I need some further expertise that I don't have. And I think that the— I think that it doesn't have to be legal. I think that there are lots of positions within the privacy realm that you can fill without being legal.

I think legal can be of value for giving legal opinions, but I think that it's more of a cross-functional role as far as it reaches across all of the things you mentioned, legal, compliance, information security. I always say InfoSec. IT. And so you kind of being able to speak those languages is, I think, the most important part. I have seen people who have been successful coming from audit backgrounds, program management backgrounds, so all those kinds of things.

I think there's lots of ways to get into it. Having, I guess, kind of the cross-functional knowledge piece is important. That's good to hear. Yeah, IAPP is a great organization. They've got some, some really passionate people over there who you know, just care about making the world a better place, quote unquote.

But there's some really good people and some great resources there. So I'm glad that you brought that up.

So you've worked with big companies, you've worked with, I assume, some smaller companies when you were, you know, earlier in your career. Talk to us a little bit about your advice to those out there who want to start something. They want to start a business, or maybe they already have. And if they already have, chances are they're collecting data somehow. Maybe they're really great security people, but what do they need to know about building a data-first business?

Business with kind of data privacy in mind in 2019, it's going to be different than it was in 2018. It's going to be different than it was in 2008, right? It's a much bigger topic today. And so what are some of the things that, you know, if you're starting a company or if you're early stage, you really, you know, this is free legal advice from one of the experts in the area, you really need to be cognizant of Because you're going to get hit with fines, you're going to get hit with fees, you're going to be put out of business if you're not compliant. So, I guess kind of a big overarching theme that I would say to think about, and this actually comes from my old boss Sheila Jamakar, and I think I've also noticed it in IHS that this is generally their approach, is thinking about data as, I guess when you talk about consumer data or thinking about it in the context of what would you expect or what would you want done with your data?

And that kind of being your gut check or guidepost because, you know, there's always kind of the conflict of people that you're working with or maybe your company, right? You always want more data, you wanna keep more, but what would you expect as an individual if this were your data? How would you want your data treated? What would you expect to be communicated? What would you expect to be done, etc.?

That kind of is the floor and building a program off of that. So I think I would also, I guess, recommend taking a global approach to privacy instead of, you know, being just solely compliant with whatever law you think you're complying with at the time. So having it be an aspirational program, meaning that you want to think about privacy as what, you know, again, what would you want your data— what do you, at the end of the day, if you have to go to a regulator, wherever it may be, or, you know, the government, you want to say these are the reasons we did these things because we thought that that was the best for protecting privacy, protecting data, not because this is what kind of the letter of the law says, if that makes sense. Okay. How about the other side of the coin?

How about a company that's been in business for 20 years, 15 years, whatever, a lead gen marketing agency, let's say, and they probably have a lot of data, and maybe they haven't put as much focus on it right now, but when that federal regulation that we mentioned earlier in the podcast does come into effect, they're probably going to be scrambling. They'll be given a 2 or 3-year window to catch up and become compliant. But what might your advice be to those types of companies who maybe haven't prioritized it, but if they don't do so soon, then some, you know, something bad is going to happen? I guess I would say start with the idea of privacy by design, right? So, thinking about your program with privacy as the fundamentals, designing your program that way.

And so, kind of, I guess when you think about, you know, maybe it would be rolling it back to giving— erring on the side of, I guess, consent is what I would say. So giving people more information about what you're doing with their data than less is always better. Okay. And does that manifest itself in a small link at the bottom of a webpage saying like, this is what we do with your data, or is this like a part of a privacy consent form? So, you know, there can be— you can send There are consents where if we're selling, if somebody's selling business information or so, I know a big thing, for example, what LinkedIn does, right?

They scrape the internet to gather all kinds of data about their users that then they sell to people who wanna market to them.

But providing lots of consents around that and kind of basically at every turn where there is the opportunity to communicate that to the consumer or the user, whatever it may be, doing so. Okay. So open lines of communication, being honest. More transparent. Yes.

Yeah, right. Yes. Okay. And I think that you— I think that people will find that those— that really facilitates a lot of a lot more data sharing because people are, you know, typically don't mind consenting when given the opportunity. And when you come out and when you are kind of approached in good faith almost, when whomever you shop with tells you what they're gonna be doing, you're gonna say, yeah, take it all.

Take all the data you want. Maybe. It depends on the day. Yeah, right, right. That's true.

Okay, so you've had this kind of really interesting career up to this point, and I'm hopeful, and I'm sure you are, that you've got some really interesting things ahead of you. What can you leave the listeners with in terms of why this is so important? And, you know, it's a big question to tackle, but I think there's a lot of different schools of thought thought. I think there's kind of the paranoid group, there's the kind of strict law compliance group, there's the group that doesn't really care, yet this topic of data privacy is kind of infiltrating more and more conversations in the security community every month, every quarter. So why is this so important for us as consumers, for businesses to make sure that we address, Well, okay, so let me give you an example of kind of why I guess why I would think it was— why I think it's important and why I think it's important to have restrictions on what people do do with data.

So one of the big things that GDPR tries to regulate is basically the creation of decisions that significantly impact people's lives being made based on what information they gather about them without any consent, communication. So, for example, gathering— if I take myself as an example, gathering my spending habits online, my activities, what they think my theoretical income is, and deciding whether I can get a mortgage or not without any you know, without my say or without any kind of contribution. So that's kind of already done generally, right? But kind of taking it to the extreme where you're impacting people's livelihoods or major decisions that are being made about them without any kind of— basically unregulated. And the kind of impacts that that can have on people, or for example, having your identity stolen and how you recoup those kinds of losses or recoup, you know, the long-term consequences of those kinds of things.

So, I think finding a balance between the business and the money-making and the importance of kind of how data can also help enrich people's lives, educate, you know, educate companies on consumer preferences, etc., but at the same time that the consumers are protected. Okay. If that makes any sense. That makes sense. That was a long rambling answer.

No, that's really good. That's great. And where do you go from here? So, you've got this new position with a very long title.

And, you know, kind of what's in store for the future for you at IHS Markit? You know, working on their privacy program, trying to— they have a really great program already. But, you know, just working on making improvements, education, working with— I work a lot with their information security and IT teams as they work on growing.

And so, yeah, that's about it. It's just, it's a really exciting role. Lots going on, lots of different issues so far. So kind of jumping right in. And, you know, especially at such a big company, I think it can always feel feel overwhelming at first, but it has been— everybody's been very helpful, been great about kind of stepping back and explaining to me what the purposes are, and responsive to feedback about, you know, how we want to treat data, how— what we want our privacy program to look like.

And so, you know, kind of working with the framework that I have built from my experience and from, you know, past mentors and current mentors of, you know, we want to think about privacy on the ground level. Okay, very good. Now, because you're in-house, do you provide free counsel to listeners who might be interested in asking a question or two? Would you be open to people reaching out? So, as in-house, the only people that I can represent are IHS.

Ah, okay. So, that would be more for a law firm. Right, but then they would charge you. Yes. But I'm happy to provide career advice or, you know, general guidance about places to go or how, you know, how, where you can get help.

But yeah. Okay. Okay. So great. Well, so good having you on the show.

Thank you. It's great seeing you again. And best of luck in the future. Thank you. I'm excited to hear this.

All right. Take care. Thanks. Learn more about the Colorado security scene at colorado.gov/security. Security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.

Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes