All episodes

Greg Szewczyk, Attorney at Ballard Spahr

Apple Podcasts Spotify SoundCloud

Greg Szewczyk, Attorney at Ballard Spahr is our feature guest this week. News from: New Belgium, In-N-Out Four Winds Interactive, Coalfire, Red Canary, System76, Ping Identity, VirtualArmour, and a lot more!

Fat Tire riding out of town

New Belgium has a new owner. Colorado has a lot of road work to do. In-N-Out is building a lot of lanes as well. AI might not be all good news for Denver and Boulder’s tech community. Four Winds Interactive has some bad news. Coalfire’s hackers are still in legal limbo. Red Canary sponsors MITRE initiative. System76 is bringing computer manufacturing to town. Ping talks OAuth. VirtualArmour compares OT and IT.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11952 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 143 for the week of— was it November 25th? 25th.

Yes, it's gonna be Monday, November 25th, which means we're just a few days away from Thanksgiving. I know. You doing anything fun, Robb? I am going to have a wonderful time with my family. We're, we're kind of getting out of town and enjoying a small family event.

What about yourself? We are gonna be here. I have family coming into town, so that'll be nice. My parents are coming in and my brother and his wife. Just cooking dinner at home, maybe Making a turkey.

Awesome. Well, I guess that, you know, since we're gonna be doing so much family stuff, we are gonna take off next week from the podcast so people can finally say, ooh, there's some relief. They don't have that work to do next week. I'm glad you told me, Robb. Otherwise I'd have shown up at your house and I would have been confused and who knows.

It is confusing. It is confusing. Well, that is, that's exciting and looking forward to the week of Thanksgiving. Before we jump into the news, just a little bit of housekeeping. We do have a Slack channel with over 1,160 people in it, some of our best friends.

We are, we're, and I actually just sent a note to the Slack channel suggesting that we would love to have someone who's good at web design and kind of does some web work who could help spruce up the front of the Colorado Equal Security webpage. Wait, you mean our website is not amazing and wonderful and dynamic, Robb? Well, what it looks like is it was done by a security guy. That's what it looks like. I can agree with that.

But if you do want to— In fact, it was done by a security guy. If you want to see what we're talking about, go to colorado-security.com and enjoy the UI that we've so painstakingly really put together. And while you're there, you can also sign up for our mailing list. If you scroll to the bottom of that page, there is a form where you can put in your email, sign up. You'll get the show notes delivered to you in your email every week.

Of course, if you're one of those people who would like to help us update the website, send us a note at info@colorado-security.com and let us know. We do have a little bit of that sweet, sweet Patreon money that we could offer for, for the person who does that. So, uh, a couple cents maybe. So, so let us know and we'd be happy to, to get you plugged in and help us do that. Uh, we also, um, are on all of your popular, uh, podcast feeds, uh, including iTunes, Google Play Store.

So if you go there, we would love— Spotify, Spotify. We would love for you to rate us so that other folks know that this is a great podcast. And, uh, and also subscribe so you get the podcast delivered to you in your podcast player every week. And once you're subscribed and you're thinking to yourself, man, I wish there was more I could do. Well, good news is there's a couple more things you could do.

You could tell a friend, go tell a coworker, tell any random stranger you see that Colorado Equals Security is Colorado's best security podcast. That's true. You could also sign up with Patreon to support us monetarily. We do incur some costs for running Colorado Equals Security and putting the podcast together. So if you would like to contribute to defraying some of those costs, please sign up at Patreon.

You can find a link on the website to our Patreon. And finally, we would love it to get more engaged with more of you guys to help do interviews for the podcast. As you guys know, we do the newscast at the beginning, and then we try and do a deep dive interview with someone in the community. And we've had some really great volunteers who've helped do this. I know that they've all really enjoyed being an interviewer.

If you're interested in getting involved, we have plenty of folks for you to go talk to, and we'd be happy to get you in the loop and figure out how to do it. Awesome. Well, let's jump into the news. First, This week there's some big beer news, Robb. New Belgium Brewery, they're sellouts.

They're selling out to, well, technically an Australian conglomerate, but it's owned by Kirin, by a Japanese beer maker. It feels kind of like a flat tire to me. Ooh, been waiting for that. Just been waiting. It's a sweet, sweet pun.

Yeah, so unfortunately, you know, this is one of the big success stories of Colorado, especially, you know, the Colorado beer community. It's number one. You know, I went to, I got my MBA from Collins and the New Belgium Brewery, the way they did business, employee-owned operation. Everyone is, as they hire, get hired on, they're, they're given a new bicycle as a part of the onboarding. Um, it's just really well known for being a really cool company.

Uh, well, no longer is it going to be an independent company with all those things. Yeah, it is, it is sad. Um, it is sort of the state of, uh, of beer today. The, the breweries that have gotten big enough where they are not craft, you know, microbreweries anymore. They're, you know, your New Belgiums, you know, formerly Breckenridge, things like that.

It's getting harder for them to compete with the gigantic beer makers, but they're also being squeezed on the other end from, you know, all of the new small microbreweries that are coming up. So, you know, they need money to compete, and really the only way that they can do that is to sell to a larger brewer. So some interesting facts from the article: New Belgium is the largest craft brewery in Colorado, and it's the 4th largest in the US behind Yuengling, Bud Light, Boston Beer and Sierra Nevada. Um, they had more than 300 of their employee owners are going to receive more than $100,000 through this deal. So, you know, obviously that's, that seems unprecedented to me considering the size of this company that so many people are going to do well.

So it just goes to say what a, what a unique and cool company this is. Um, of course, they also say that none of the employees, neither in Colorado, um, or in Asheville are going to be affected by it. They're not going to get laid off. And in fact, the leadership team is also going to stay on board. Yeah, that is one of the cool things about New Belgium is that they are an employee-owned company.

So the employees do benefit from them selling to a larger company. All right. Next story here is that Colorado has unveiled a $1.6 billion roadmap of highway projects for the next 3 years. We talk a lot about this, maybe not so much on this podcast, but I hear a lot of conversation around the, the fact that the roads in Colorado need a lot of work and we have to— we need some infrastructure investment. Yeah.

So they've put forth a plan for where they are going to put the, the current money that they have to do investment. Some of that is going to be— well, I think they said 70% of that money is going to be towards I-25 in some part or another. But it is going to be in all parts of the state on I-25. Also looking to do some of the— some work on Floyd Hill, which gets backed up from ski traffic. It's westbound I-70.

Yep. And then, and then lots of other places. The interesting thing, though, is that $1.6 billion price tag, I think, is only like 15% of what they actually need to do all of the road improvements. What I saw was a $9 billion road total price tag. So whatever, whatever that would be, 20% or 18%.

Next story here is also about a lot of cars, maybe not quite as many cars. In-N-Out Burger has received official approval from the, from the City Council of Lone Tree to do that build that we talked about, what, a month or so ago on County Line near Park Meadows Mall, right next to the Fidelity. And part of this is that they're going to have a 26-car drive-through lane. So what I wanna know, Robb, is if you're car 26 in the drive-through, how long does it take to get your hamburger? I don't know, but I'm guessing there will be a lot more than 26 cars in that line.

That's true. So it's probably more about what does it take to be car number 70 and what's the wait gonna look like for those guys? So of course they do expect enormous volumes the first year of operation. And interesting to me, In-N-Out has agreed to restripe Westview and Parkland Roads, which are just west of the mall, to create a dedicated left-turn-only lane into this. So even though there's the only, only the 26 spots, they're gonna have a lane outside of the parking lot for those cars to wait in.

It is gonna be a mess over there. I look forward to having an In-N-Out there at least once, but it might be, I don't know, 6 months after it opens or something like that. You just have to go have your In-N-Out at 8:00 AM when they first open. But before everyone realizes they're open. Something.

Yeah, something like that. Yeah, there's also a Chick-fil-A that is right there that is always busy as well. So it's gonna be a lot of traffic in that area. You might end up eating more Chick-fil-A because the In-N-Out line's gonna be so terrible. You never know.

Next, there was an article this week talking about how Boulder and Denver are both highly susceptible to disruption from artificial intelligence for white-collar workers. So this is an interesting article. You know, we hear a lot about automation taking away jobs. And I think the example the article starts off with is, If you go to a fast food restaurant these days, there's, there's a kiosk to order food in addition to your, your cashiers. But this, this new study was— used a different methodology to determine what kind of jobs are most at risk.

They, they actually looked at what patents have been requested and issued in terms of automation and tried to understand what careers those patents are going to impact. Yeah, and I thought that was an interesting approach. I'm also not sure that it is a a realistic approach, because there are so many patents that get issued. There's only a small, small percentage that actually become real technologies. So I don't know how, how representative that is of what's actually going to happen.

But, you know, they did talk about some things like radiologists, for example, you know, it's a very highly coveted, highly paid position, you have to go through a lot of school. But, you know, they've shown recently that that artificial intelligence can find things in radiology images that humans can't. Right, it's better than us, and we can't even figure out why it's better than us in some of those cases. I did think there was some interesting data from here. They saw that 740 out of the 769 occupational groups, basically they lump all jobs into these 769 groups, 740 of those are at risk of losing some jobs due to AI from these patents.

So that's, that's just mind-blowing that such a big percentage is gonna, could be impacted. Of course, to varying degrees. At the top of the list, agriculture had the greatest exposure, which kind of shocked me. Yeah, I was shocked as well. I don't know.

I have heard that like they could use AI to determine when you should plant and when you should harvest and, and do other things like that. But it just didn't, it just feels like there's gotta be a lot of manual effort. I'm surprised that they can get quite such an impact there. Yeah, that was surprising. Science, business, finance, technology, manufacturing, natural resources all made the list of most impacted careers.

I thought it was interesting too that they said that workers with a bachelor's degree face 5 times better chance of being disrupted by AI than someone with just a high school degree. It's kinda counterintuitive, isn't it? Yeah. So it's, I mean, I guess their study was looking at white-collar jobs. And so if you're, if you're looking at white-collar jobs, it probably means you're more educated.

Well, I think they were looking across all jobs and they were just showing that white-collar jobs are more impacted than they expected. So it is, it is surprising to me. Obviously, we're gonna have to see how this shakes out. Hopefully, just like every other previous revolution, it, it doesn't kill jobs. It actually creates new, better jobs.

That's, that's what we've gotta hope for and we gotta work for. I think the AI is going to self-actualize and kill us all, Ryan. Well, I, for one, welcome our new AI overlords. Awesome. Next, not as happy.

Well, another not happy story, I guess. Four Winds Interactive announces layoffs. Including some staff in Denver. So Four Winds Interactive is a company here. They make interactive signage, signboards that you can put in your offices and things like that.

And they announced that they are doing a little bit of restructuring. They have about 450 employees and about 400 of them are in Denver. And I think that they're getting rid of about a little under 10%, about 40 employees. Well, they said they wouldn't comment on how many they are, but the representative said it's fewer than 40. So you would assume that if it was 39, if it was 8, they wouldn't have said fewer than 40.

Right. So you got to figure somewhere in the 30s range. Really disappointing to know. I, I do think that, you know, we have such a vibrant economy here right now that folks should be able to land pretty quickly. Yeah.

Of course, if anyone knows folks at Four Winds who are looking for jobs, get them plugged in and help them find their new— their next landing spot. Hopefully this turns them into a more profitable company. Yeah, I agree. Uh, next, this is a follow-up story around the Coalfire pen testers. We've talked about this several times on the show.

I thought this was interesting and we included it in the show notes this week because it made the Denver Business Journal's main page talking about what's happened here and, and really how the, the impact to these pen testers being arrested is, is really shaking the entire pen testing community, um, and the industry is trying to figure out exactly how do we respond to this. Yeah. If you are, if you're doing one of these tests, uh, whether you're with Coalfire or anybody else, and there is a threat that even though a business has said it is okay to perform one of these tests, that you could be arrested or have other, um, other things happen to you, then people are gonna stop doing, um, the, the tests. Yeah. And then you're gonna be in a worse place.

Just imagine like next time you engage with your pen tester and you tell 'em you wanna do a physical pen test, like, How much more difficult is that gonna be for us to, to scope and, and get them to agree to now, now that, you know, there is this kind of case out there where people have, have been arrested for it? Yeah, I'm still hopeful that it can get resolved in a, a way that it works for everyone. Um, you know, again, this seems to be, to boil down to a, a turf war between different areas of the Iowa government. Um, hopefully they can, they can figure out the right way to handle this. So.

Uh, next, the, uh, there's a blog post from Red Canary and, uh, talking about how they are working with MITRE to start, uh, the Center for Threat-Informed Defense. Yeah, this is interesting. Uh, it's, it's neat to see MITRE trying to put together this, uh, collaboration of good guys to talk around, like, you know, based on the, the threats that are out there, what should we be doing to improve security? The This blog post doesn't give a ton of details on like what we're actually gonna do, right, as a result of this. Uh, the, the initiative sounds right though.

Um, and the groups that are involved are pretty impressive. Uh, they got American Express, Booz Allen Hamilton, Citi, Fujitsu, Microsoft, Siemens, US Bank as other founding sponsors alongside Red Canary. So it's a pretty good group and obviously some, some big brains out there that can help, uh, kind of guide the way the defensive teams should be preparing their security programs. Yeah. And Red Canary has long been a proponent of MITRE ATT&CK framework.

Uh, you know, they have the Atomic Red Team framework, which does testing around that. And so this new group hopefully will continue to make improvements in the ATT&CK framework. Awesome. Uh, next story here is that System76— we've talked about them on the podcast a few times. We have.

They create like high-end Linux workstations here in Colorado. They do the manufacturing, which was unique and interesting. Well, they have announced that starting in January 2020, they're gonna start— they're gonna start designing and building their own Linux laptops in addition to those desktops. Yeah, I believe today that they already sell Linux laptops, but they are laptops that are designed by other companies, so— and manufactured by other companies. Right, right.

So now they are gonna be designing and building their own. One of the original stories that we talked about with System76 is they moved their manufacturing, I believe, back from China here to Colorado. And so they're now touting because they have the manufacturing here, they can potentially do a quicker turnaround on that design and manufacture process of this new laptop. So this story is actually from Forbes. So it's not a, not a Colorado story.

This is a national story. Obviously, big news when a computer manufacturer is making machines in the US. They interviewed the CEO over there, Carl, is it Richel? And he was quick to point out, you know, even though this is cool and big news, he was quick to point out that this whole process is just starting and it's probably gonna take 2 to 3 years before they're actually like putting these laptops out into the market. Right.

I think it's also cool that there is talk about Linux laptops in general. That seems to be something that is just novel. Well, I think 2020 is gonna be the year of the Linux laptop. Yeah. How many years have we been thinking about Linux desktops?

It's been a while. As long as we've been around, right? Yep. Next, there was a blog post from Ping Identity this week talking about setting auth security policies to help secure access for your specific needs. So, you know, I, I've obviously a little self-interested talking about Ping, but I love when we have these kind of blog posts as they give security guys like me who, you know, who don't have 20 years of identity deep experience an opportunity to learn some of the ins and outs of the security standards.

And OAuth is one of those critical standards that you should know about. And I also love the fact that they started this article out talking about threat modeling and, and basically building your identity program and your identity scheme around what are the threats that you're trying to protect against. Makes a lot of sense. It makes it much more approachable for those of us who are coming to identity from a different part of security. And of course, the guy who wrote it, David Waite, is a genius and one of the guys who's really worth knowing.

If you're in Denver, I'd recommend getting to know David, or D-Dub as we call him at Ping. D-Dub. All right. And then our final news story this week is a blog post from Virtual Armor. Talking about operational technology versus information technology and the differences and similarities.

So if you already know the difference, don't read the article, right? That was the— that was my first thought is this is not for you if you already know the difference. But if you're, if you're new and you said, hey, I know what IT is, what's OT? This is a fantastic article to get you introduced to that. Yeah.

For someone that needs to learn the basics, understand what the differences are, it is a good overview. Yeah. So I appreciate them putting that kind of stuff out there. And if you're, you know, someone who's looking to get into security and someone pointed you toward this podcast, take a look at this article. They give you some good info.

Good stuff. All right. That is it for the news. Let us now move over to the Slack Message of the Week. Big thanks to Andre Gaeta.

Andre, you have been a great sponsor for the last few years on this. We really appreciate it. Every week, Andre donates his own funds to recognize one great message from the Slack community. This week, we have kind of a different type of a message, you know, not a celebration, but more of a remembrance. Exactly.

Uh, so the message this week, uh, we are honoring, uh, Jericho who posted a, um, a memorial page that you can, um, add to for Reed Fudge. We learned this week, uh, that Reed had passed away. Uh, Reed was a, a member of the community. He, uh, was currently had been CISO for, uh, Tri-State Generation, but had been at various different places, um, around the area, but has been a great member of the community. Um, I got to know him originally through ISSA.

He used to be a regular member at all the ISSA meetings. Um, it was very sad to hear of his passing. Yeah. Uh, Reed actually was the head of security for Pulte Financial, which, you know, I, I was the CISO there and you were the CISO there. Yeah.

Um, we've had, uh, so a lot of things in common with Reed. He'd come to dinners. I've actually been trying to get him as a, as a guest on the podcast for like 2 years and it's just been timing. We've had it on the calendar several times and gotten scheduled. He's, he was sick intermittently for quite a few years.

Um, certainly, uh, it's, it's always surprising to hear once a friend passes away. Um, so really sad that we're gonna lose this great member of the community. Yeah. And if you would like to, to leave a note, um, a memorial for, uh, for Reed, you can go out to the, the Slack channel, find that post by Jericho. It links to the, the page where you can, uh, leave those memories.

And the page is actually on GitHub. So you can, I think you could probably just do a search of GitHub for Reed Fudge and you'd find him out there too. Thanks to, thanks to Jericho for setting that up. We do appreciate it. And hopefully we can turn that into a useful, useful, worthwhile memorial for those who knew and loved Reed.

All right. Let's move over to events. As you know. Yeah, I was just gonna say this week, since there is nothing this week in terms of events, I actually went 2 weeks further. Oh, all right.

I didn't know what you were about to jump into, but okay. That's what I wanted to make sure you got that out there. Programming note, Robb and I are talking about what we're doing, but while we're doing it, Uh, what I was gonna say is, as you know, we have an event calendar on our website. So go to colorado-security.com, check out the event calendar. Uh, you can see events for more than 2 weeks in advance.

Um, I think we have stuff all the way out through May already of next year. So as of last night, we have stuff until December of 2020. Wow. Yeah. So, uh, plan your years now.

Uh, but for the short term, um, you get to hear about the next few weeks. Normally we do 2 weeks in advance, but since no one is doing anything for Thanksgiving around security events, you get to hear the 2 weeks after. Yeah. There is literally nothing coming up the last week in November, and we won't be doing a show the week after. So, so in December, on the 4th of December, we have SecureSet doing a capture the flag for beginners.

So this is a way, a good way to get your, your, uh, foot in the ring. I don't know, I'll stop talking now. Splunk is doing their First Thursdays at Topgolf on the 5th of December. On the 6th, uh, Colorado Springs has one of their First Friday cybersecurity events. Uh, On the 7th, uh, SecureSet is doing a You Can Hack It event.

This is a Saturday and it's 10 to 3. So this is meant for those who are thinking about getting into security. I think they did it on a Saturday because they're assuming these people have jobs, but it's a 5-hour event to introduce you into security and basically show you that yes, you too can get in there. So if you know someone who's looking to be a career changer, send them this way. You Can Hack It.

Uh, go ahead. Next, on the 10th, ISSA and ISACA are doing their big holiday bash. Yeah, it's going to be a fun event. It's what, like in the afternoon? I think it's afternoon through like maybe 1 to 4 or something like that at Soil Dove again this year.

This is an event that does sell out, so if you would like to go, you should get tickets. Also on the 10th, later that day, the Cloud Security Alliance is doing their 2019 holiday party because apparently, uh, the 10th of December is the day to do it. That's the day. And once you've done your holiday partying, SecureSet is doing a capture the flag on the 10th as well. ACES Denver, which is once again the physical security group, is doing their December meeting.

They have an election and a Christmas gathering on the 12th. Um, also on the 12th, SecureSet is doing a Hacking 101 Intro to PowerShell. And finally, ISC² Pikes Peak down in the Springs is doing their December chapter meeting on the 13th. That's all we have through December right now. Awesome.

So let's jump over to jobs. Uh, first on the list of jobs this week, Bank of America. Um, they are again hiring lots of people. So, uh, one of those jobs is they're looking for an information security project manager. They're also hiring a cyber program manager.

Not sure what the difference is. One's a cooler word than the other, I guess. So if you like the cybers, go for that job. Ball Corp is hiring a cybersecurity specialist. LogRhythm is looking for a strategic integrations engineer.

IHS Markit is hiring a cybersecurity assessor specialist. Amazon is looking for a senior security engineer. Visa is hiring a senior cybersecurity engineer. Zayo is looking for a cybersecurity analyst 3. You noticing a trend here?

Cyber is taking over these titles. There's a lot of cybers in these jobs. Yeah, we gotta do better. Webroot is hiring a senior global escalation manager on second shift. So you wanna hire a SOC or excuse me, manage a SOC.

This might be a good opportunity for you. And finally, HomeAdvisor is looking for an application security engineer. Fantastic. Alex, uh, we have an interview this week, right? We do.

What, who did you talk to this week? I talked to, uh, Greg, Greg Szewczyk. Um, it, it, if you listen to the interview, it took me a little while to get his name pronounced right, but I believe it is Szewczyk. Yeah. Uh, he is an attorney at Ballard Spahr specializing in privacy.

And information security. So we had a nice conversation and you should stick around and listen to that. Fantastic. Well, thank you for getting the interview ready. And of course, thanks for all those listening.

Have a wonderful Thanksgiving. Hopefully you're with family and loved ones and we'll look forward to talking to you again in December. Happy Thanksgiving, everybody. Hello, this is Ian Buxton, Senior Director of Information Risk and Security at Vail Resorts. This is Colorado Equals Security for Colorado security professionals.

Welcome to Colorado Equal Security. This is our feature interview, and this is Alex Wood. And today I am interviewing a very special guest. And of course, before we started, I didn't ask for your correct pronunciation of your last name, Greg, but I'm gonna go for it. Greg Szewczyk.

Almost. Oh, you were the first person who has ever gotten that wrong. It is pronounced— I'm sure I am. It's pronounced Szewczyk. Szewczyk.

Okay, close enough, close enough. And, uh, and welcome to the show. Appreciate you. Thank you for having me, Greg. Um, so obviously we've been acquainted for a little while, but for those folks that don't know you, who are you?

Uh, so I am an attorney at the Ballard Spahr law firm here in Denver, and I also split some of my time up in Boulder. Um, I've been with this firm for about closing in on 7 years now after spending my first 4 years out at a law firm in New York. Nice. And, you know, over the past 5 to 6 years, an increasingly large part of my practice is devoted to privacy and information security issues. Very, very nice.

So you obviously ended up here. Did you start here? Where are you from originally? So I'm originally from St. Louis, then went to undergrad up at Notre Dame. Okay, and then law school at Harvard, and then down to New York to start my career.

And I started my career at one of the big law firms out in New York doing almost entirely litigation, and especially a lot of trial work. Then about closing in on 7 years ago, my then-girlfriend, now wife, and I came out here. We'd had family in the area for decades and both loved to ski and hike and camp. And back then, as you'll remember, Denver was actually, you know, a much slower, quieter town, right? And that really appealed to us.

So we found our way out here, and that's when I started working for Ballard. Nice. And so it was— sounds like it was location first, firm second, right? It was really the first time in our lives that we picked a city based on what we wanted out of life and then found jobs, or, you know, rather than having school or a job dictate where we lived. That's pretty cool.

So when you were doing the litigation work, was it in a similar field to what you're doing now, or was it just sort of general litigation, or What kind of work were you doing there? It was kind of across the board. The team that I worked on in New York, it was really a team that focused on doing actual trial work more than any substantive specialty. And so that's kind of what I was focused on doing when I first came out here as well. Okay, so what then, what changed your focus?

Why did you end up in information security privacy kind of law? Well, I mean, since the listeners can't necessarily see me, I'm 35. And I'd been interested in following various tech issues for a long time and always was very interested in it. We, uh, we ended up having an attorney start with us named Ed McAndrew, who had been with the Department of Justice for a decade doing cybercrimes prosecution. And he was somebody who really was looking for more people to join what he wanted to grow as a team.

And we didn't really have anybody out here doing it at that time, so me and another attorney, you know, kind of got in touch with him and started really focusing on that and trying to grow it from out here. Nice.

As you are well aware, that was a good choice. It is a growing and an exciting place to be these days. It is. I mean, it's really exciting and interesting both from the, you know, business side of law, of growing a new practice, but also, as you're well aware, it's kind of been the Wild West as far as generally applicable laws go. And, you know, things are still changing and will continue to change, and it's, you know, fun and exciting to be a part of that.

Yeah, it's got to be one of those interesting things. Um, you know, if you're in, uh, in general litigation or in business law or things like that, there are probably new things that come up, but my guess is that it's probably mostly the same, slight changes, you know, new precedents are set, so on and so forth. But in somewhere like that, like cybersecurity law, or maybe something like, like marijuana law, or, you know, just other things like that where it's like, oh, we've never had anything in this area. It's probably all sort of trailblazing kind of work, and I'm sure that's pretty neat too. Yeah, it's, it's fun.

I mean, you, whether you're trying to figure out new ways to structure a compliance regime to both fit the business need and comply with the laws, or whether you're on the back end and you're in litigation, there's just— there's a lot of flexibility and freedom there because there just isn't the precedent yet. And I mean, that's gonna be changing in coming years, especially with the CCPA coming in with the private right of action with statutory damages. A lot of times data breach litigation hasn't gotten that far because it's just economically difficult for plaintiffs to prove damages and make it worth carrying on the case. Now that there's that statutory damage component, we expect to see cases start getting a little further, and there will be a growing body of case law. But, you know, we don't really know exactly where it's gonna be yet, right?

Yeah, speaking of CCPA, we are— we're recording this near the end, middle end of November. It goes into effect in January. What do you expect is gonna happen come January? I don't think I don't think that the sky is gonna fall. I think that we're gonna see a lot of companies who are maybe not all the way done with their compliance efforts like they'd hoped to be, but they're part of the way there.

They're gonna keep moving forward. You know, I think that the California Attorney General's Office is gonna be reasonable in their enforcement efforts. You know, I think that they're gonna be looking for people or businesses trying to make compliance efforts and doing what they can, but I don't think that they're gonna have a to-the-T approach right off the bat. Yeah, I also think that we're gonna see a lot of plaintiff's lawsuits filed for data breaches. Yeah, I would imagine that will happen, actually.

And now that I think about it, let's step back for one second. I think most people probably know what CCPA is, but for those that are not privacy folks and maybe are more focused on security, can you give a quick overview of what CCPA is and what it means to people? Sure. So, I mean, the CCPA is the first generally applicable consumer privacy law in the United States, passed by California. Like Alex said, goes into effect January 1st.

And so what we're talking about are businesses that cross the threshold for application are going to owe consumers a host of rights, related to their privacy. And, you know, the way that I kind of talk about it with clients who, you know, take a lot of different issues into consideration, you have information security— how are you protecting what is traditionally thought of as sensitive information, so socials, financial numbers. You have data breach law, which is what do you do after that's lost. And then you have privacy law, What are you doing with the information that you legally have? Who are you sharing it with?

Who are you selling it to? What are you doing with it? Right. And so this is really the first generally applicable law that deals with that third piece. And consumers will have the various rights to ask what a business has.

They'll have the right to ask you to delete it. They'll have the right to ask that you don't share it with anybody else. All subject to various exceptions, right? So this obviously is applicable to folks in California. You know, as I think we are both well aware and most people are aware that this applies to California residents.

How do you think this is going to affect probably both in the short term and in the long term everyone else in the U.S. that's not a California resident? Well, if you pass certain thresholds, doesn't matter where you are if you're taking California resident information. So if you're a company here in Colorado who does business online and collects Colorado or California residents, correct, then you're gonna be subject to it, right? Right. But, you know, I think what you may be getting at there is last year we saw, I think, 18 states propose some form of privacy legislation, with some of them getting across the board, you know, until and unless the federal government ever steps in and passes a nationwide law.

We're gonna— I think we're gonna see the same thing here that we've seen in the data breach and InfoSec world, which is each state's gonna pass its own privacy law that's slightly different from the others and probably over time competes to be the strictest law out there. Yeah, like I know Nevada also passed a law that is already in effect, went into effect almost immediately. But was much narrower than the California law is. So it's, you know, I think it's only applicable to people who actually sell data for profit as opposed to the more broader definition of selling data in California. Do you think, where do you think the next contestant will be?

Is it gonna be New York? Is it gonna be Massachusetts? Is it gonna be, where do you think it's gonna be? Gonna come? Yeah, I mean, Massachusetts is a state that a lot of people think is gonna be the next one to get it across the board.

New York had one out this year that did not— I think it died in committee. So that could be coming back. I mean, it really depends on how some— I mean, I think, you know, next year is obviously an election year, right? That could figure into various states, you know, who votes for what bill that they might not otherwise. But from what I've heard, Massachusetts is is up there, Hawaii's up there, and New York could be bringing it back too.

I've also heard that Washington may be bringing back its bill that stalled in around June of last year. Well, and then I've also heard, again, for those that don't know, there was quite a saga around CCPA and how it came into existence. There was originally someone that was pushing a ballot measure, and then at the last minute, the legislature sort of made a compromise. Passed the CCPA with the provision that this person would take the ballot measure away because the ballot measure was more strict. And now that CCPA is in place, that same person has said, hey, I'm coming back next year and I'm gonna do an even stricter version of this that I'm gonna put on the ballot.

And I don't know yet if there have been any, you know, additional discussions with legislators there in California about, you know, additional compromise to, you know, kinda do the same thing that they did last time? Yeah, I haven't heard. I mean, there's gonna have to be some discussions that go on anyway because certain provisions, you know, we've been talking about the CCPA and it's probably worth noting that with the InfoSec and the data breach laws, they tend to apply to, you know, the sensitive information, whereas privacy applies to virtually all personal information. But there were a couple amendments passed towards the end of this year that excluded things like employee data is not treated the same as all other data. Okay.

But it has a 1-year sunset clause on that. Right. There's also the business-to-business exception. Again, it has a 1-year sunset clause. So there's gonna have to be changes or debates going on, and I would expect that that's kind of roped in if the new ballot proposal, you know, gets any kind of traction, right, that they'll do what they can to to make those compromises again.

You know, one other thing that I saw recently, Microsoft put out a press release saying that from their perspective, it doesn't matter if you live in California or not. If you're in the U.S., and maybe, well, I think it was just in the U.S., but maybe it was even broader than that, then you will be able to exercise the same rights under CCPA even if you're a Colorado resident or anywhere else.

I was, well, I was surprised a little bit that someone would, would come out and do that, but I guess, you know, if you're, you're gonna have to comply in California, you may as well just comply everywhere. Do you see other businesses following suit? You know, I've actually had this conversation with almost all of my clients, and, you know, it really comes down to the individual businesses.

Clients that are in the business of you know, not necessarily selling data, but using personal information as a way to sell their product or to run their business have actually been the ones who seem more interested in trying to apply it across the board, whether or not it's because of, you know, compliance costs of trying to parse it out, or because they do build it into their brand and corporate culture of trying to respect privacy. You know, they've been trying to build in. Other companies that don't really collect much data and don't do much with it and don't have much California data, you know, they pick up some just through general website usage, but they're not selling things directly to consumers. They're not selling any data to anybody. They're just basically having pure compliance costs without really providing that much of, you know, I don't wanna say not a meaningful right to the consumer, right?

But to let the consumer demand, you know, send in a verified request of what do you have on us, you say we have your IP address, we can delete it if you want, you know, it's almost pure compliance cost to them without really providing a lot back. They're tending to stick to the we're gonna have a California-only section. So yeah, that makes sense. And the original intent, I think, of the, of the measure was to try and limit the Microsofts and the Googles and the Facebooks and those sorts of folks from doing things with your data that you didn't want them to, but it's much harder to craft something that focuses just on them. You know, where do you draw the line, right?

So you do have a bunch of those businesses where, you know, you probably willingly provided your information to somebody, and now they fall under this, under CCPA. It's maybe not exactly what was intended, but it is still a good thing if you have those rights to be able to exercise them. So I can see where, from those companies' perspectives, it's, oh yeah, we really do have privacy as a core value, or at least want to project that. So let's give this to everybody and make it at the very least look like we care about your privacy. Yeah.

And some of them actually had— You know, the rudimentary ideas, they were already offering that before the CCPA even came in. Right. But it was much more of a, you know, off-the-cuff, here's a paragraph on our website that said, if you want, you know, you control your privacy rights, get in touch with us to let us know. Right. And so this at least, you know, got them to kind of formalize it a little better.

Yeah, I mean, and I guess, you know, Google and Facebook and other things like that, you You know, you can request already what data they have on you, and you can theoretically request to delete it. I think that's a very strong theoretically, but you can request it. So anyway, a couple years back, Colorado passed a— I think what was billed as a data privacy bill, but in my mind is more a data security bill. You were involved early on that, you and, you know, one of the former attorneys here, Dave Stauss. Put out a book on that regulation and, you know, what it was and how it might impact people.

In the time, I guess, has it been a year now, a little over a year since it's been in place? Yeah, it was September of 2018 is when it went into effect. What have you seen now that that's been in effect for a year? I mean, so I know you were out at the cybersecurity summit we hosted in October here, and we had some folks from the Attorney General's Office come out and kind of talk about their enforcement efforts and how things have been ramping up and what they've been doing. What we've seen from clients is, you know, similar to what we've seen with the CCPA in some ways, is it just forces the focus of some of the real decision makers to start looking into what are we doing, what do we have, why are we having this.

You know, something that we'd seen, you know, here in Colorado with some of the companies, but before that law came out is we'd talk to someone in the legal department and the tech department, and they're really honed in on these issues, right? But it was sometimes tough to get the C-suite level people to really focus in because there wasn't much forcing them to. You know, it, it's an issue that you sometimes hear in the news, but you don't think it's going to be applicable to your business. And then with the new law being passed that puts some affirmative obligations, it starts really focusing attention down where I think it should be, and doing a lot of good in that way. Yeah, I'm trying to remember from that presentation, I know they said that there have been a few enforcement actions that have come because of that law.

Were there any notable ones that you remember that have happened that have been a benefit to Colorado consumers because of this law? They were very tight-lipped on anything that happened, because I believe I believe all of them were still ongoing. They talked about numbers of enforcement actions and investigations that they have going on, but they're very serious about keeping things confidential until anything's public. Where, on that same front, where do you think Colorado stands in terms of a data privacy kind of law, an increase in consumers' rights around privacy? For the state?

Yeah, so, um, I know, so Attorney General Weiser was at the summit and gave a quick speech about how Colorado is working in concert and on its own. It's working in concert with some of the other Western AGs and on its own just looking into where Colorado goes with this. They haven't, you know, I spoke to somebody in their office a few weeks ago, and it's my understanding they haven't quite put pencil to paper yet, but they're starting to form their ideas. And what they're really looking to do is see if there's a way to use what's good from the CCPA or the GDPR, you know, things that would drive data minimization and transparency, and make it less of a burden when it doesn't need to be a burden. So try to find another model.

And what Attorney General Weiser was really talking about was You know, we may see something similar to what happened with data breach across the country where we have 40 states with different laws, but maybe they follow 2 or 3 different types of models, and those could eventually serve as the framework after, you know, the laboratories of democracy theory, that if the federal government actually does put something out, then maybe they end up following the Colorado one because it works a little better than the California one. So, you know, that's— I don't know if it's gonna happen next year, but I do think that Colorado is gonna end up getting something out in their legislature within the next couple years, probably. Interesting. So, so you just mentioned potential federal legislation.

What, what is your over-under on when you think any potential federal privacy regulations I think there's virtually zero chance before the 2020 elections. There's just, I mean, the dynamics in Washington right now are not conducive to getting what would need to be a bipartisan, difficult technical bill through. We see principal papers and proposals coming out all the time, and just, they really don't have a whole lot of legs. I know we were talking before we started recording, Yesterday, a group of 4 Democratic senators released a 2-page paper about principles for an eventual bill— excuse me— that included a private right of action. And I think that maybe an eventual bill does have something like that, but for the next year, year and a half, that's not going to be something that can get enough bipartisan support.

What do you think, in your opinion, what are those important principles that would, that would make a successful federal privacy bill? And I think first and foremost is data minimization. I know we've talked, and I've had the conversation with a lot of people, is right now we can craft all of these rights and notices and disclosures, and you can require that they be made without legal jargon and in as much plain English as possible. Possible, but that still puts a lot of the burden on individual consumers to go look and see what their rights are and then take some kind of action to either see what they have specifically or have that deleted or opt out of sharing. And most people are very busy in their lives.

And, you know, it's not necessarily to say that that's a bad thing to have it that way. But really, I think what's going to drive safety is transparency of knowing what you have, but then also having some incentives for businesses not to have large amounts of information that they don't have, because you can't lose what you don't have, right? Yeah, and we were talking about this a little bit before, but you have a whole bunch of competing regulations too, right? So there's, there's lots of regulations that are aiming to do one thing or another. And may require businesses to keep data for a certain amount of time.

You know, in the financial industry, there's a lot of regulations where you have to have stuff for 7 years or, you know, approximate, right? So it could be, you know, fair lending, or it could be, you know, other sort of anti-discrimination kind of things, right? It's like, hey, we want to be able to keep this data so that we can show over time whether or not, you know, you are discriminating against consumers or things like that. And that's a great thing, right? We don't want consumers to be discriminated against.

But then on the other hand, it's okay, well, now I'm going to have to keep all of the data that I get from my customers, you know, all sort of in quotes, for some certain period of time. And even if I want to get rid of it, I can't get rid of it. So where— how do you, you know, weigh that risk between you know, keeping the data to help with one particular potential harm and it having the opposite unintended consequence of causing another harm because we have that data. Yeah, it's a tough question. And I mean, in some ways it comes down to— it reminds me of how in so many information security laws, so many states have avoided going into specifics about what you need to do because there are always these competing balances.

And so you get down to a reasonable standard. And in some ways, that's what regulators have to do when it comes to record retention and data minimization, is what's gonna be reasonable? What do we— how long do we really need to go back to make sure that we're protecting these important goals of avoiding and reducing and policing discriminatory practices with putting all of that data at potential risk of a malicious actor, you know, getting into it? Yeah. Yeah, I mean, I can see something where you, instead of having to keep it for a certain amount of time, you do some sort of compliance activity on a shorter period of time and then you can get rid of the data or something like that.

I can see where there could be incentives again like that. Hey, if you do these compliance activities, one, you can potentially reduce your compliance burden over the long term for this other regulation and you can get rid of this data. So, I don't know, it's not an easy question because it doesn't just affect, you know, one regulation, too, right? You can't just put out a privacy regulation without then going back and touching these other regulations to change them to help with that. Right.

And that's, you know, that's getting back to the over-under on getting something done on the federal level. This is going to be not just on the substance of the, you know, what are the rights that we want to have, but it's going to touch a lot of other regulations and bills, and that's tricky. That's going to take a lot of time and effort to think through all that. So you're saying if I put the over at infinity, you're still taking the over? That's— I would think about it.

So you deal with a lot of clients here. What are some of the other hot-button items that they are talking with you about, or is it Or is everyone just coming to you for CCPA right now? You know, it's not just CCPA. It's kind of trying to read the tea leaves of, you know, we might have this fairly small risk profile for CCPA, but we do need to go through this compliance effort right now. How do we do this in a way that we're not doing it again next year?

And a lot of clients are also using this as an opportunity to to really take a— they're already doing annual risk assessments, but really doing more of a business and legal-oriented assessment of their general information security programs. I think that's a great thing. Yeah, so how would you say that differs between a normal risk assessment and what you just described? What would be the differences there? I think from a technical standpoint, maybe not all that much, with the exception that it might give more buy-in from the business side and the willingness to spend more dollars, um, because the risk assessments were already going in a lot on the technical side.

But with now, you know, the new threats coming in, not just, you know, malicious actor threats, but legal threats, civil litigation enforcement, right, there's the cost-benefit analysis of what you're going to do is, is changing a little bit. And so it gives a little more buy-in from the business side of, we got to make sure we're covered on this, right? Um, I feel like one of the— this is going to sound funny— but one of the sort of solved problems, and it's not solved at all, but it's something that I don't hear about as much anymore, is, um, is people getting— doing the, the breach preparation sort of activities and those sorts of things. Do you still have clients that are coming to you saying, hey, we haven't ever even done this before, you know, we need to either— we need your help in starting a program or starting with help on what we do in case of breach or things like that. Am I naive to think that that may have slowed down a little bit as people have matured?

I don't think you're naive, but I think it all depends on the maturity of the company that you're dealing with. I mean, if you're dealing with a venture company and we do try to, I don't know what the word is, scale our services to startups, so that to help people build privacy and information security into their programs from the ground up. But, you know, some of them, they really are just starting up, or they've been a 2 or 3 employee shop for a year or so, and they're just getting that first real round of funding, and they're turning to these issues as soon as they can. Something in place, right? But they don't really have it from the standpoint that you would expect to see.

So we are still, you know, seeing clients who come from, you know, we need to start from square one. But I do think that as far as the more sophisticated entities, it's— things have been developed a little more for a while. Yeah, no, that is good. I'm glad to hear that there still aren't troves of well-established companies that are completely naive when it comes to these sorts of things. So what other things are clients coming to you for today?

You know, the privacy is really driving it, especially right now going into the fall with a January 1st compliance date. And one area where we're seeing that focus a lot is people are looking really hard at their vendors. Contracts. What used to get kind of scanned over by a general corporate counsel in-house, they're now running it by us with almost every single vendor contract to make sure they're getting things in place. So I think that's actually a really good byproduct of the CCPA.

And what sort of things are they interested in running it by you guys for? General data security, the potential provisions that are needed for CCPA, like, hey, you guys are gonna have to delete data if we tell you to delete data, things like that? What are they coming to you for? Both of those. You know, I think that they'd been doing their general data security reviews with their technical teams in-house, but there's a lot of companies are now starting to square in on, is there something in here from a legal standpoint, from a contractual standpoint, that is letting them off the hook unintentionally, or that we have some kind of exposure here when we didn't expect to.

So I think on that, on that side, a lot of it is more buttoning up from a legal contractual standpoint, and then making sure they have everything in to ensure that it is in fact a service provider under the CCPA, making sure that they have an obligation to comply or cooperate with requests for access to information or deletion or the opt-out. And then, you know, something else that we are seeing clients come in more and more for are actually tabletop exercises, which you would have thought came along with the more sophisticated breach response and incident response regimes. But I think that it's a byproduct of we can spend more time— more than money, but time— of very important C-suite people to come in and make sure that we've done this. And so that's just all kind of getting swept in together. Yeah, that is interesting.

Are they asking you for participation in those events, or are they asking you to sort of run those events for them, come up with scenarios, bring the people together, that kind of thing? More the latter. Yeah, the running them, set it, putting it on for them. Yeah. So do you have a— nothing against lawyers, but they're In my history and experience, you need a sort of special kind of person to come up with a lot of those scenarios and figure out how to run them in the right way.

Do you guys have a specialized group that does that? Well, I'm sorry, our privacy and data security group has been doing these for years now, so we've got a good deck to choose from that's obviously always changing as the threats change. Nice. Yeah, it's, uh, I know that there are, uh, some consultancies that focus on, on those sorts of things as well, but it's interesting to hear that, that law firms are getting into that business too. Yeah, I mean, we're in kind of a, a strange industry where law, business, and tech overlap a lot, right?

And everybody's trying to make sure that they're staying in their appropriate lane, right? But those lanes do overlap from time to time and For sure. It's just kind of how it goes. Yeah. Well, we are, we are running close to time.

We've got a little bit longer. What is it that you wanted to talk about, Greg, that I haven't hit on yet? No, I'd actually be interested hearing from you, from someone who's been, you know, at a very high level on the tech side. Sure. You know, you've asked me a little bit about, you know, what laws, what do I think would drive it in the laws?

What do you see from your side? That would really drive, you know, a stepping outside of our roles that we've had for our jobs? You know, what would be— do you wanna see in a law that would allow for meaningful consumer protection, but not be crippling from a compliance standpoint? Yeah, it's— I think that the— I think anything from the federal level would help at this point. And not that— it would probably hurt in some cases because it would probably water down some areas, but the amount of time that it takes to comply with 50 states' laws, it is just an amazing amount of time from a compliance perspective.

So any sort of narrowing of that amount of work that you have to do to comply with everybody whether it's a national law or some sort of clearinghouse or something like that, I think will positively affect consumers because it will give those security teams time back to do the things that matter instead of performing big compliance activities to make sure that they're in compliance with all the state laws. I mean, in terms of some specific activities. The— I think the thing that I've harped on a lot recently is a little bit about what we talked about before is don't— if I can, if I can get rid of data, I would love to do it. But there are just some times when I am not allowed to get rid of data. If there was, you know, some provision where we could either— I don't know what the right answer is.

I don't know what the right answer is. But if there was a way for regulated industries to be able to get rid of some of that data that they are now required to keep, I think it would be a pretty big deal. So those are things that I think would be useful. I do like the privacy laws from a consumer perspective that are coming in. Obviously, it means more work and more time from a security practitioner's perspective, but I think that we as consumers should have more rights around our data.

I'm worried at how the current feelings and practices we have around data in our country, say versus in Europe, how those will actually interact with privacy laws, right? We are much more free with our data here. There are not nearly as many places where privacy is a right in this country. California is one of those places where privacy is a right versus Europe, where it is a right for pretty much everybody there. So I don't know if— back to my question to you about the over-under on when a federal bill will come in.

I'll take the over also, just because I think it's going to take so long from a cultural perspective for people to even want to make that change. What I hear a lot is people saying, hey, well, you know, if you don't like the, you know, your data being lost, don't use that company. Well, we've seen time and time again big data breaches and maybe a short drop in the stock price of that company, and then it goes back above where it was to start with. So clearly consumers don't have a problem with data breaches. You know, a small percentage maybe are critically affected, and obviously it causes them a lot of pain, but, you know, in general people don't seem to have a problem with that.

So I think it'll be a long time. That kind of gets to when we were talking about case law and precedent coming out, one argument that you do see made, but it hasn't really been adjudicated yet, is, you know, for a data breach, causation of damages. Even if you have concrete damages from an identity theft, say, your information has probably been breached multiple times, right, in the not-so-distant past. How do you prove that it was caused by that? And I hear a lot of people come up with that as Yeah, it's another data breach.

You know, it happens all the time. My info is all over the dark web. So what? Yeah, I think it will— it will take a big shift, one, for us to move away from things like Social Security numbers being an identifier and needing to be a sensitive piece of information. Right.

There are things that the federal government could definitely do so that it is not a big deal that people know your Social Security number. I think also there is— there would have to be an appetite for that because then you're going to have to come up with some sort of other national identifier. And then you're going to have a whole bunch of people saying the government are trying to track me. I don't want them to do that. And, you know, so on and so forth.

I think it is interesting. Some, some countries and I think even some states now are trying to move more into digital identities. You know, Estonia is one. That they have a whole digital identity. On the flip side of that, I think India is another one that has some pieces also, and they had some sort of data breach of their national identity database, which is a bad thing.

But I think North Dakota is also working on some stuff. So I think maybe some outside-of-the-box thinking and some different kind of ideas instead of us trying to bolt on and continually modify the stuff that we already have. Maybe thinking of the problem in a different way could help. Yeah, I mean, I think that that sounds like it is probably the future, especially given like what you said. I mean, most people, it doesn't seem it rises to a level where they're gonna push their representatives or senators to do anything.

I mean, what could be bigger than, you know, the Equifax or Cambridge Analytica or something else, right? There just isn't that much that you can think of that would really shock the public into demanding action. At this point, right? If Equifax, where they basically gave up every person's personal identifiable information, if that's not gonna do it, what would? What would?

Yeah. So I mean, unless— yeah, the only thing worse is that that happens and then immediately everyone suffers from identity theft. That's right. You know, that's the only other consequence that could happen after that. So anyway, well, thanks for that, Greg.

Yeah, on that cheery note. Yeah. No, it is. It's not very often when one of the interviewees asks me a question, so I appreciate that. I'm happy to do it.

Awesome. Anything else we didn't cover? No, I think that was a great conversation. And you know, anytime you'd like to talk more, always happy to come back on. Awesome.

Well, thanks, Greg. I appreciate your time. This has been Colorado Equal Security, and we will talk to you next time.

Learn more about the Colorado security scene at colorado. Security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes