All episodes

Newscast & APEX Awards Coverage

Apple Podcasts Spotify SoundCloud

Breaking news from the APEX Awards! News from: DIA, ManagedMethods, Ping Identity, Optiv, Swimlane, Webroot, LogRhythm and a little bit more!

Blucifer isn’t the only scary thing about DIA

Denver’s airport is one of the world’s scariest? Open records laws in Colorado change as technology does. California’s privacy law does impact us. Colorado’s National Guard helped with election security. ManagedMethods grew a bajillion percent. Ping Identity, Optiv, Swimlane and Webroot drop news this week.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript7854 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 141 for the week of November 11th. Alex, it's 11/11.

What's your wish? Oh, you're putting me on the spot, Robb. But you know what? If I tell you my wish, then it won't come true, right? That's the right answer.

So I've got it in my head now. What's your wish? You passed. Well, it's not actually that day yet, so I'll have it tomorrow. I'll be ready.

Okay. Okay. Well, Alex, we are back a week for you being away. I'm glad to have you back with us. Why don't we jump into some of our housekeeping and then we can talk some news?

Before that, I appreciate how you talked me up in last week's video. Continually threw you under the bus in comparison to a 10-year-old. Yes. I appreciate that a lot. So housekeeping.

Hey Robb, did you know we have a Slack channel? We do have a Slack channel and it's been just really lively this last week. A lot of great conversations. I've been struggling to keep up with it all. So I think if you get in there, make sure you join the channels that you're interested in and I think you can find some really relevant talking.

We also have a mailing list. If you go to our website, colorado-security.com, scroll to the bottom, put your email in the form there and hit submit, you will be on our mailing list and get show notes in your email. And that same website is where you would find the link to join the Slack channel. It's a little bit higher up on there. We'd also love it if you would rate us and subscribe to receive the podcast on your favorite podcast listening app.

Your rating of us helps us find new listeners and folks who are interested in finding security in the area. I'm sure they'd love to know what you think of us. Also, please tell everyone that you know, whether they are friends, enemies, acquaintances, random people on the street, let them know about Collateral to Equal Security and that they should subscribe to the podcast and check out all the cool stuff. And if you're wondering what's the easiest way for me to tell random people on the street about the podcast, I would say it's by wearing Colorado Equal Security swag. So you go out to the swag store and you could wear a shirt much like I'm wearing right now.

Robb, what's another way that you could get a shirt? Another way you could get a shirt is if you were to sponsor our Patreon campaign. We are always looking for those who would help us support the show. If you want to be a part of that, why don't you come out and Go to the Patreon campaign also on the website, and you will get a free shirt with a— was it $10 a month sponsorship? Yes, sir.

Also, we do put in a fair amount of time for the podcast. Part of that time is doing interviews of people in the community. And, you know, Robb and I also have limited time. So if you would like to do some of those interviews, we would love to have you. So let us know if you would like to be an interviewer.

For Colorado Equal Security, or if you think you have something, an interesting story, or, you know, you think people would like to hear about you, let us know and we'd be happy to get somebody to interview you. All right. Let's go ahead and jump into the news for this week. First off, Alex, there's a list of the scariest airports in the world. And guess which one's on it?

Poughkeepsie. Savannah, Georgia. You're right. Savannah, Georgia made the list. Yeah.

Interestingly enough, it's on the list because there are, there are graves underneath one of the, one of the runways. I thought that was honestly the most interesting thing in that whole article. They show a picture and there literally are gravestones on a runway. Yeah, they did note, however, that it is down near the end of the runway where planes never actually, you know, travel over them. Well, but they said that if, if the run— the airport's not very busy and there's some extra time, they will sometimes allow planes to taxi over there and that there is a secondary radio frequency they can switch to, which is the, the cemetery tour frequency so people can actually learn about those, about those graves.

But we weren't here to talk to you about the Savannah, Georgia airport. Oh, there's another one on the list? Denver International Airport is on the list, Robb. Did you know that? I did know that.

I got that far in the article. And interestingly enough, that airport is also built on a former burial ground. It used to belong to Native Americans. Wonderful. Also, there are, as you know, lots of conspiracy theories about Denver International Airport, whether there's, you know, aliens underneath the airport or secret tunnels or, you know, whatever military base, whatever it might be.

Some of those construction ads that they're doing now, you know, make fun of that a little bit. And of course, there's also not— it's not a rumor. There is actually a blue horse sitting out front that is a devil horse, right? Lucifer. Lucifer, the devil horse of Denver, which guards our airport or is there to to judge those who come to the airport as worthy or unworthy, depending on your opinions.

And of course, Lucifer's creator was killed in an accident where Lucifer fell on him while he was creating Lucifer. So, yeah, so very sad story and true. And so anyway, it's good to know that we made a national list. And once again, suck it, Austin.

On a, on a different note, there are some holes in the Colorado open records law That means some government data, you know, may not be accessible because it is in electronic form. So I think it's worth just mentioning what is the Colorado Open Records Law. There's the ability, especially for, for media folks, but I think any citizen to make requests for Open Records Act to say, you know, send me, you know, these government documents so they can— we can really get transparency on how our state is run. Yeah, it's like a FOIA request for the federal government, right? Hey, I want to have this for freedom of information.

Yep. And this is, you know, I listen a lot to local podcasts, especially like Colorado Matters, the Colorado Public Radio, and they use these Colorado Open Records Act requests to do their investigations. Well, they've run into— not them specifically, but generally recently we've run into issues where those requests run into data retention requirements, right? Yeah. Some of the things that they mention in there is that there have been times where there have been requests for email from government employees.

And those emails have been deleted either, you know, just because they've gone past retention period, say of 90 days or something like that, or text messages where those are no longer accessible after a certain time. And it is an interesting thought, right? Because we, you know, security professionals, we want as much data to go away as possible. We don't want to keep that around because we don't want to have to protect it. But in a case like this, you probably want to have that for posterity in some cases.

Yeah. They, they specifically talk about how a number of the legislators in Colorado are using Signal and Confide, which are both apps that allow you to automatically delete messages after they've been read, which from the security perspective is pretty stinking great. From, from the open records and, you know, kind of citizen open transparency perspective, it's not good at all. So we do have an interesting balance here. In 1996, The, the state acknowledged that digital records are a part of CORA, that they should be required to be open just like any written records, but they haven't given any guidance around what the retention requirements should be.

So there are, there are some municipalities that are deleting emails within 30 days, making it really tough for anyone to get transparency there. Yeah. And there, along with the guidance, it doesn't say what sort of data should be included in those records. Right. So You know, do conversations over Signal, does that count as an official electronic record?

We don't know, but definitely need some work to figure that out. Yeah. So I found that interesting. I think this, you know, for those of us in security, it's really a perspective that's worth considering. And as citizens, you know, let's try and figure out what is that balance.

I think we all agree, you know, it's probably a bigger deal to have a massive data breach where sensitive citizen information is breached. But at the same time, these communications about how we make decisions is how we hold our leaders accountable. Exactly. Next, we had an article in the Colorado Sun from Tamara Chuang talking about CCPA and how it is going to affect you no matter where you live. Yeah, I read through this.

There wasn't a lot of surprises here. I think this is a great 101 for those who don't know a lot about CCPA and what are the expectations going to be for companies that do business with California residents. You know, it's not just a question of updating your privacy policy, right? I think that was kind of the headline in my perspective. Yeah, and obviously updating your privacy policy is part of it, but there are gonna be lots of other responsibilities that you will have along with that, you know, letting people opt out of you selling their data, data deletion, other things like that.

Yeah, all of those informations, all the data that citizens might wanna know about what you're doing with their data, basically they have those rights in this case, and it's gonna be awfully tough to segment it to just California for most national businesses. Yeah, it'll be interesting to see how many organizations provide the ability for non-California residents to, to exercise those same provisions. Right. I mean, you're still going to have to, to be able to do it for the California residents, but that doesn't necessarily mean that you're going to give that same option to folks that aren't in California. So.

All right. Moving on to the next story. This is actually, you know, last week was election week. It's an off-year election, but there was a number of interesting things going on, some statewide ballot initiatives. Yeah.

Sports gambling. Bring it on, Robb. You know, it passed, right? I believe so. It passed by just a small margin.

I think it was pretty even. Yeah. So, so anyway, this article here is talking about the fact that the Colorado National Guard was aiding in election security on Tuesday. I was not aware of that. Yeah, pretty cool.

Not a whole lot of detail to the article, but just that the, the governor had asked for the National Guard to be, to be on duty. That, you know, this is one of their responsibilities for, for crisis situations. And they They deemed this to be a serious enough effort that they called in the National Guard and had them monitoring for election threats. So when you went into your ballot, was there someone with a rifle sitting there, like, keeping you safe to make the vote? They showed up at my house when I was filling out my paper ballot and made sure everything was cool.

Interesting. The article also notes that the National Guard was also a part of the 2018 election. So they have been— they've definitely been a part of this. And this looks like an ongoing responsibility as they look to 2020. Yeah.

To help maintain the security of our elections. I think in general, it is a great use of an organization like the National Guard. And, you know, we've heard before, too, in talking about the CDOT breach, for example, that, you know, they helped respond to the CDOT breach. You know, this is exactly an extension of what you would think of for an organization like that in cyberspace as opposed to the real space. All right.

Moving on to the next story. What would you say, Alex, would be like a good year-over-year growth for revenue for a quarter? Oh, I don't know, maybe 539%. Wow. Well, I guess to that end, Managed Methods had a good growth quarter.

Wow, that's awesome. Glad to hear it. So they just had a press release saying that their Q3 year-over-year revenue growth was 539%. So if they made, what, $1 in 2018, they made $5.38 in 2019. That is awesome.

Which is actually a pretty small number. I wish they'd done better than $5. Well, but you know, good for them on increasing it so much. Yeah. Presumably it was significantly larger numbers than that.

Great growth. Good to see these guys making some real progress here. Yeah, exactly. We also had a blog post from Ping Identity talking about multifactor authentication and a report that the FBI just came out with. And, you know, maybe what could have been better in that report.

I guess the FBI's report was kind of led off with saying that cybercriminals have figured out a way to circumvent some kinds of multifactor. Um, and, and I think that there was a lot of interesting stuff I thought in this blog post actually. Uh, Andrew Goodman, who's a product marketing guy over at Ping, wrote it. And, you know, product marketing, I don't always think it's gonna be the best content. It was great content.

I, I, I felt like it was most of the way. Um, but, but I think Andrew was pointing out the fact that, hey, you know, the, the research that's out there, and he actually shows a couple different surveys or different, uh, research reports, uh, show that any MFA, even like the ones that can be defeated, um, It, it gets rid of about 99% of the account takeover type things that you get without MFA. And, but it's, it's maybe irresponsible to have an article out there that says, you know, the cybercriminals have figured out how to defeat MFA, right? Instead of just stop using MFA, right? It's over.

Game's over now. Your unintended consequences, FBI. Remember who's, who reads this? It's, it's not just technical people reading it, right? It's a lot of people who, who have been on the fence about whether they should apply MFA in the first place.

And now they're like, well, it's not working anyway. Why should I be inconvenienced? Yeah. Um, and it, it is interesting. There have been a number of news stories around in general, um, about the, uh, the, the fact that MFA can be circumvented, mostly the, uh, the, the text-based, um, code MFA.

Yeah. I even had a friend of mine who was a non-security person reach out to me this week with a link to one of those articles, just asking me what I, what I thought about it. Um, so I think the point of the article is a good one. You know, this friend of mine thought, oh, well, sh— should I really be worried about this? And, You know, generally the answer is no.

Normal person, you probably don't need to be too worried about, um, having someone, you know, SIM jack your phone to get your, uh, get ahold of stuff, but it can happen. So this blog post goes into a little bit more details about the fact that not all MFA is created equally. Obviously SMS is, is known to be maybe the easiest to, to defeat right now, but even the better kind of push-type, uh, notifications, uh, come with some challenges right now, especially with Medliska out there. It's been what, a year or so? Since that attacking tool has been in the wild that allows you to kind of scrape replies and forward it over to the malicious website or the valid website.

So I really appreciate this, and I think you guys should read it. I do think that the only way to really get through these different kinds of defeating MFAs is to move to FIDO2, get the device to website level of assurance. Um, I, I don't think you have to do it for everything though, right? Figure out where are your highest risk transactions and maybe put it in place for that. Right.

I mean, definitely a risk calculation, right? You, you don't necessarily want to have to have a FIDO2, um, device to be able to, you know, I don't know, log into your, you know, King Soopers account for, you know, your grocery— I mean, I would even say maybe you don't need to have it to log into your bank, but when you go to add a new transfer, a new account that you're gonna move money to, right? Well, let's, let's do that step up then. So it's, that's where the, That's where we put the friction. But I can check my balances, you know, with, with the lower level for sure.

Optiv also had an announcement this week that they are launching a service for Microsoft Azure Sentinel. So Azure Sentinel, that's Microsoft's new kind of cloud SIEM, right? Correct. That's part of their, their infrastructure as a service offering. And so Optiv has really bundled some services around how do you manage this, this new tool that I think, I think we're all trying to figure out how do you, how do you do security in the cloud still?

Yeah, and I think that these types of tools, Azure Sentinel and Google Chronicle, they are, they're very interesting in the promise that they have, you know, cloud-based, they, you know, potentially have, you know, a gigantic amount of storage and the ability to do very fast searches. And I've also seen a number of different organizations like Optiv and other of ours, you know, coming to give those sort of support services around them. So interesting to see how that, that's developing and what's gonna happen next. And it looks like Optiv services don't just do security. They also have some operational tasks there.

So consumption models, looking at usage metrics and performance indicators, that's, you know, definitely something that's outside of just security. Exactly. Swimlane had a blog talking about understanding APIs and in this case, particularly SOAP APIs. Yeah. So Swimlane, obviously your automation play here in town, they do all kinds of security operation automation.

I like, I really like The fact that they're trying to get some real technical detail for those folks who are using it. I'm sure you're using a lot of APIs to do integrations to their platform. So that's probably where this plays in. I'd say it went pretty deep. If you're interested in getting more information about how APIs work, this would be a pretty good place to start.

Yeah, and I believe that they have some other ones, probably a REST one and things like that on the blog list as well. Final bit of news for this week. We have a story from Webroot, which is the revival of ransomware. Basically they go through in 2019 what has been the nastiest kinds of malware out in the wild. And they break it down into a few categories.

They start off with ransomware. So the number one biggest ransomware threat this year has been Emotet. Also TrickBot and Ryuk, which I guess are kind of part of the same ransomware ecosystem. Different stages, I believe. And then the second biggest ransomware right now has been GandCrab, which sounds different to me.

GandCrab did take a vacation for a while, but now they're back. Oh, that's that one. Yeah, the one who said, we made $1 billion, now we're retiring. But they came back. Just kidding.

Later. We're taking vacation. Um, also phishing, uh, company impersonation and business email compromise were the, the 2 biggest things for phishing. Not surprising. In the category of botnets, Emotet made the top of the list there.

And in crypto mining and cryptojacking, Hiddenbee, which is one that I was not familiar with, was, uh, top of the list there. Yeah, I'd never heard of that. So I always expect, because, you know, I listen to the SANS Internet Stormcast and CyberWire, and so I, I always think I'm gonna know the names of all of them. So it's, it's interesting to come across one that I'd never heard of. Yeah.

For sure. Well, that's it to the normal news, Alex. This week, in place of doing a feature interview, we've decided to do some more in-depth coverage of the Colorado Technology Association's APEX Awards. So let's do a little bit of time talking about it. You were our reporter on the scene, so I'm going to look for you to add context as we go through these stories.

We have a set of stories in the, in the show notes that you guys can look through. And we, you know, we'll go through the high-level results, but also we'll spend a little bit more time talking about the ones that are most related to security. And of course, uh, the Apex Awards are the big award ceremony every year from the Colorado Technology Association. And they have, uh, awards in, in many different categories. And, uh, I've been to the, uh, the award ceremony now for, for 3 years.

Um, this year was a little bit different. In the previous years, it was a little more of a, a formal event. You know, you had, uh, you had tables where people had to sit down dinner and some speakers and things like that. This year, it was more of a sort of a social event. You know, it was mingling and heavy appetizers and then sitting down for the award ceremony.

Sounds like a lot of fun. Yeah, it was a good time. Were you wearing a black tie? I was not wearing a black tie. I was wearing a suit.

We will get results on the CISO of the Year. I know you were one of the finalists, but we're going to hold that off for the end because it's the most exciting. It is. Starting off with the Lifetime Achievement Award. So the Bob Newman Award goes to someone who's really spent, you know, decades helping with the Colorado Technology Association's— well, the Colorado technology industry.

Right. And this year it was Rich Leiner. He won. Rich has been part of the staffing agency in town for, for quite a while. But I think he's really recognized for building a kids tech program, which is about serving underprivileged youth and getting them into technology.

Yeah. And it was an interesting, interesting story that, that Rich told as part of accepting his award. He was one of the folks that was involved at the very beginning of the founding of the CTA. But, you know, he sort of had to be convinced to start with a nonprofit and donate his time to that. And that really was what got him down the road and eventually to helping start KidsTech.

And so, you know, he's noted how valuable that was. And, you know, I kind of feel the same way in my time working with nonprofits. And I think it's something that they can be really valuable and rewarding, uh, on a personal basis. Yeah, that's awesome. Uh, next they had the, uh, the award for Advocate of the Year.

Uh, this is sort of Technology Advocate of the Year, someone in the community that has been pushing technology in Colorado, uh, forward. And the winner this year was Denver Mayor Michael Hancock. Yeah, I was surprised to see this. I, I, you know, I don't think I knew all of what he had done around technology. From the article here, there's a couple great examples though, stuff that I just didn't know he was a part of.

He helped recruit the U.S. Patent and Trademark Office to open a satellite office in Denver in 2012. I had heard about that. And I think that's— well, while we haven't seen dramatic shifts in the number of intellectual property filings as a result, I still think it's just part of the ecosystem, right? Getting people thinking about that. And another thing he did is he was actually one of the big supporters of the launch of Denver Startup Week back in 2012 as well.

Yeah. He also mentioned some stories about going to various places to help talk to, to companies to recruit them to come to Colorado. You know, we, we do a lot of these stories about the Colorado Economic Development Committee giving people subsidies. But he talked specifically about, I believe it was a trip to Australia and New Zealand because there are a number of startups there that are expanding and they were trying to get Xero. Did he get Xero to come out here?

I don't know. That could have been one of them. He didn't mention specifically, but that could have been one of them. Yeah. But yeah, I mean, there are lots of great things that sound like that he was doing.

And it's his leadership and, you know, the city of Denver in general. And he was nice enough to thank a lot of folks that he worked with at the, at the city. Awesome. Next award was the CEO of the Year. And this year's CEO of the Year went to Angie's List.

The CEO there, Brandon Ridenour. Yes. Yeah. Interesting story about Brandon. Uh, they, they talked about how, you know, he has really been the, the leader for them to bring together, um, Angie's List and HomeAdvisor.

You know, these were 2 competing companies that were brought together to form, uh, one company, and he's kind of led them through that, that transition in apparently a positive way. That's awesome. And that is one of the companies that I think we're going to talk about them in a little bit longer too. Yeah. Uh, go ahead.

Next one. Uh, CIO of the Year. Uh, Xeo's Sandy Mays won for CIO of the Year. Interesting story. I, I don't remember much about it, but, um, uh, good for Sandy.

I actually know Sandy just a little bit. Uh, she's very customer-focused in her CIO, so she's not just in, you know, doing internal technology for Xeo. She's really trying to make sure that the technology supports customers. She and I have talked about, you know, Ping is a customer of Xeo and learning about how how they help and how they're really trying to look to the future for to make things more innovative. I thought she was a good pick, and I'm excited to see Sandy win the award.

Uh, next was the Emerging Leader of the Year, and the winner there was Jamie Cohen, who is Angie List's CFO. Congratulations to Angie. And you mentioned that she was one of the, one of the youngest CFOs at any public company ever, right? In history, it was either the 2nd or 3rd youngest Um, in history at a public company. And she was on the 40 Under 40 list.

So that's, that's all we know, right? Somewhere below 40. So presumably, you know, she's graduated from college, so somewhere probably over 18. Uh, congratulations to Jamie. Uh, next, the Company of the Year is CableLabs, and we'll talk a little bit more about that because CableLabs is one of the companies that, that, that we know, right?

Uh, at least we've known Mike Glenn over there in the past. I know he's moved on, but yeah, they have a strong technology and, uh, security presence as well. Yeah. And you know, they're doing a lot to push, uh, push technology forward. You know, they help create standards for the cable industry.

So, you know, as you are seeing the, the speeds of, uh, of your cable internet go up, you know, they're the ones that are behind the standards for that. And they were talking about, uh, 10 gig cable standards that, uh, that just came out. What? Things like that. I know.

What would the, what would the modem connection sound like, uh, on that? A little too high pitched for me. I don't know. Negotiation phase.

Next, emerging tech company of the year was BlueStack. That was an interesting story. They're out of Colorado Springs, and they started a— it sounded like a sort of a file sharing document management platform that was aimed at the military. And apparently, this has been a really good story for them. To help sharing information between military, civilian contractors, those sorts of things to really help, you know, push the speed that this stuff is happening.

And that sounded like a really good story for them. They started from a, I believe, a team of 4 that started the startup, say, like 2 years ago, maybe 3 years ago, and they're looking to be at like 90 here in the near future. We'll just briefly mention that another finalist for that Emerging Tech Company of the Year was Managed Methods, who we talked about earlier, and I think we have a little bit more news about them in a minute, right? Yes. Come back to that.

Okay, uh, the final category that we have here is the Project of the Year, and this is of course a Technology Project of the Year, and the winner of this was the St. Vrain Schools Innovation Center. Uh, what I, I got a chance to read some details about this, and it's just like a really cool thing. They built this, was it like 50,000-square-foot innovation center where all of the students of the district are welcome to come participate, be a part of it, get their hands on technology. And I love getting students out of the classroom and into getting their, you know, the opportunity to actually try this stuff out. Yeah, it sounds like St. Vrain is doing some really cool stuff around technology for their students.

Yeah, and I'm not sure that it's the most innovative project of the year, but it may be the most impactful project of the year in my mind. You know, other, other places are doing things like this, but man, the more places we can get these innovation centers, the more places we can get students out of books and ended up actually doing, I think the better off we're going to be in the future. Exactly. And then next, Managed Methods was also nominated, I believe, as one of the finalists. Yeah.

Yeah. For the Emerging Tech Company of the Year. Yeah. Yeah. And there's a little more detail on that.

It's a special article just about them, right? Linked in the show notes if you want to read all the details about it. Anything in particular that jumped out to you? Yeah. I mean, I think it is interesting in general that if you want more details on this, there are profiles on all of the finalists.

Analysts in the Denver Business Journal. I think some of this is paywalled, so you'll probably have to find a Denver Business Journal either in print or get a subscription to see some of it. But they talked about how they are, you know, they're very school-focused, and we've seen some of that in the blog posts that we've talked about with them in the past, but that they are now securing over 1 million user accounts for cloud-based apps in over 70 school districts. It sounds like maybe they did make more than $5.39 this year. That's fantastic.

I love to hear that. So another award we didn't talk about yet is the Colorado Entrepreneurial Excellence Award. So this is one of the awards that didn't come from nominations, I think, right? It was actually kind of someone who was just picked, I believe. Yes.

As the winner. So the winner is someone we know pretty well, right? Trent Hein. We've had Trent on the show. Trent is the— one of the co-founders of Applied Trust that was Later acquired by Viya West, later acquired by whatever that— what are they, FlexCentral?

Now they're FlexCentral, right? Yeah. So he, in the last— what, about a year or so ago, started up a new company called Rule4, which is them focusing on cybersecurity around like IoT, blockchain, kind of the harder, newer technologies, right? New things where people may not be focusing today. And there's some interesting things that they talked about.

And, you know, we may have covered it in a little bit when we interviewed Trent for the podcast, but that, you know, he started his, his first technology company at the age of 13, where he was doing soft Apple II software, you know, when he was very young. So he's been entrepreneurial, entrepreneurial for a very long time. And he's also founded, you know, 3 other companies as an adult, including Rule 4, and Applied Trust, and Applied Trust, as we mentioned. Uh, and I really like to call out here in the article that Rule 4— we've talked about this, but they're pending certification as a B Corp, which is a designation that means that the, the company's goal is not just about profit, right? Right.

It's also about some kind of public benefit. So they're, they're identified their purpose, and they're really making sure that this company cannot just turn into, you know, profit-driven, you know, grind them into the ground to make the most money. Yeah, their goal is to make money, but also to make the world a better place while they're doing it. Yeah. So I think we've finally got ourselves to the CISO of the Year conversation, right?

We have. So there were 3 fantastic finalists. We had Debbi Blyth, James Carder, and Alex Wood as our finalists. Alex, should we just start off with the winner? Yeah, let's do that.

All right, so the winner, CISO of the Year, is LogRhythm's James Carder. Big congratulations to James. Yeah, great job, James. Congratulations to you. You know, James, obviously someone who we know well in the community.

He's been an active participant in Colorado Equal Security, really doesn't just stay in his lane within, you know, running a security program within LogRhythm, but it's really helped the bigger company there and of course the bigger community as well. Yeah, they talk about some of his efforts around education, teaching at CU Denver and volunteering some time at University of Denver for some of their advisory groups. And then also some of the work that he's done at LogRhythm, not, you know, from a product perspective, but the, the internal stuff where, you know, he's trying to push a zero trust model inside of LogRhythm, which is pretty cool. That's fantastic. Uh, and so of course, the one of the other finalists is Debbi Blyth.

Debbi is the CISO for the state of Colorado. Um, maybe we could talk a little bit about what we know about Debbi. Yeah, and we've had Debbi on the show before also. A couple times. A couple times.

Um, live, live keynote at RMISC this year. Um, you know, one of the things that they talk about here is some of the accomplishments she's had at the state. Uh, implementing MFA. Um, uh, and I think one of the most interesting things, and which we talked about on that, that live podcast, was that they are doubling the budget for security, um, for this year so that they can get a bunch of those projects that they've been trying to do done. Push them over the line.

Yeah. I mean, I, I know very few places where year to year they will, they've doubled the budget of someone's security program. That is pretty cool. From, from $10 to $20 occasionally. Right.

539%, Robb. Right. So congratulations to Debbi for being a finalist. Really well deserved. And then, of course, the final finalist is you, Alex.

Obviously, we know, we know a little bit about what you do. I would just point out that you have spent, man, just maybe more hours helping the community outside of your job than anyone I know with ISSA and RMISC and of course Color Equal Security. A lot of stuff going on there in addition to a full-time job supporting the company that you're securing. So appreciate that. Well, thanks, Robb.

I know you pulled out a little. It is Halloween time, so I pulled out a Halloween sort of specific thing from the article. Uh, apparently you use your first computer— I did not know this— a Commodore 64 to make a flashing pumpkin, which then you then put on your front porch on Halloween. Yeah, we actually, on my, on our porch, we had a window that faced out from inside, so I didn't actually put the computer outside, but I, I put the monitor in the window so when you came up to the, the, the door to get candy, you would see the flashing pumpkin. I honestly think we should be doing that right now.

This is not, this is not something that should be, that, that should be limited to whatever year, 1982 or whatever this was. Yeah, I'm sure I could go dig up a Commodore 64 and, you know, a couple days reprogram that BASIC program to flash the pumpkin in the window. Well, that is our— that's it for our coverage for the 2019 APEX Awards. Congratulations to all the winners. I do recommend if you're interested in getting involved with the broader technology community here in Denver, you maybe go to this next year.

It's not that expensive. It's a really good way to meet a lot of folks and of course, you know, be part of the future of Colorado's technology. Yeah, I will also say for the APEX Awards, the, the nominations are— these are open nominations, right? If you know someone in the community, um, whether it's a security person or someone else, um, you are free to, to nominate them when the nomination period comes open next year, whether it's your CEO or CIO or CISO, whether it's for a project you've done at work, whatever it might be. Um, there's no special sauce to this.

You just have to fill out a questionnaire to get the nomination in. Um, we would love to see more and more people, uh, from our community get nominated and, you know, anyone else that's doing great stuff. Yeah. Wouldn't it be awesome if the whole slate of everyone up there was all security related somehow? Yeah.

If we can make that happen next year, you got, you know, 1,000 of you guys listening out there. Maybe, maybe when it comes down time next year, maybe you should actually all go do nominations instead of ignoring it. The call for action. Hey, hey, how about that? Hey, let's move over to the Slack message of the week.

Uh, big thanks to Andre Gaeta. Andre has been sponsoring this for, man, a couple years now. I appreciate you doing this, Andre. The winner of the Slack message of the week each week gets to pick one item from the Colorado Equal Security swag store. This week, the winner is Greg Sternberg.

Congratulations, Greg. He posted an article this week talking about the physical effects of ransomware, and I thought this was a really interesting article, um, that ransomware and data breaches, when they happen, they are linked to an uptick in fatal heart attacks. You know that, so that's interesting. Totally random. I listened to a different podcast this week about Ironman and, and that there's an interesting kind of correlation between fitness and heart attacks.

And you go, you know, being not fit, high on heart attacks. And as you get more fit, it gets lower heart attacks. And then you get to like Ironman and it goes back up again. And those people are more likely to have a heart attack. You're pushing yourself a little too hard.

Is that kind of the idea there? Yeah, I know this has nothing to do with ransomware, but, but this is the kind of thing you get from Colorado Equal Security. Exactly. But I could totally see where, you know, your mom or your grandma or somebody, they get a ransomware screen that pops up on their computer. Oh my.

Oh, all the great sound effect there. I love that. You know, all of a sudden you are, you are very concerned because, you know, whatever it was that was on that computer is now lost to you. Right. You think.

Yeah. And it mattered. Yeah. And I think that that could cause some real-world stress, and apparently it does. Yeah.

All right, well, that is it for Slack Masters of the Week. Congrats to Greg. Moving over, we do have an event calendar on the website. A lot of great events coming. You're gonna see in the next 2 weeks, we've got a dozen or so as well.

First, SecureSet is doing a Hacking 101, Creating a Virtual Lab. Oh, that sounds cool. Yeah, I really recommend getting to that. That's on the 12th. On the 12th and 13th, ISSA Denver are doing our November chapter meetings.

That'll be downtown Denver, Boulder and the DTC area. Take a look at the calendar to see where each of them is. And it looks like on the 13th after that meeting, ISSA Denver is doing a workshop, 12 Ways to Hack MFA. On the 16th, the Colorado ISSA— Colorado Springs ISSA chapter is doing their mini seminar. That's the Saturday morning event.

On the 18th, the ISC² Pikes Peak chapter is doing their November chapter meeting. And please note that that moved from the 20th. So if you're kind of in your normal ignoring that part mode because you know when it's going to be, they actually moved it up 2 days. So look for that on the 18th. On the 19th, Denver ISSA's Women in Security SIG is getting together.

That's going to have their November meeting. On the 19th and the 20th, ISSA Colorado Springs is doing their November chapter meetings. A couple of— a lot of events on the 20th. We also have ISSA Denver doing a November happy hour. OWASP is doing their November meeting.

And DENSEC is doing their November hangout. That's going to be at Ryan House once again. On the 21st, ISACA is doing their November meeting. And finally, on the 21st, ISC² is doing their chapter meeting. That's going to be top 3 services that help change the security of an organization starring Chris Nickerson.

Oh, and after that, you can take a week off from events because no one is going to be silly enough to do a wink— an event during the week of Thanksgiving. I do want to jump ahead just a little bit and give a preview. The ISACA ISSA joint Holiday Bash is actually scheduled now and you can get your tickets. That's going to be at the Soiled Dove again. It was a great venue last year.

I really appreciated getting to see folks there. So if you have some free time on the, on the 10th, you can go out there and enjoy that. That's December 10th. December 10th. I believe also that is a limited space event.

So if you want to be able to go, you have to get a ticket. You can't just show up. Buy your tickets today. Yeah. All right.

Let's jump over to jobs. Uh, first, Robb, are there any Ping Identity jobs this week? Uh, there's no jobs on the list for Ping right now. I— that's me knocking on wood. Uh, the team is, is at capacity right now.

Awesome. Uh, but we do have the state of Colorado looking to hire a director of security and investigations. Sounds fun. Centura Health is looking for a director of data security. Cognizant is hiring a senior manager for cybersecurity architecture.

Bank of America is hiring a bunch of people. Uh, but one of those jobs is a VP Tech Manager of Information Security Engineer. Yeah, they got a lot of jobs and, and I think they're in Republic Plaza right now. Uh, and they're gonna be moving into the Optiv building at some point. Oh, okay.

From what I heard in the Slack channel, uh, Dish is hiring a Sling Application Security Engineer and they're also hiring a Cloud Security Engineer. Yeah, I think Dish is also, um, ramping up their hiring. Uh, Nelnet is looking for a Cybersecurity Engineer. Conversant is hiring a senior cyber GRC analyst. Optiv is hiring a security compliance analyst.

And this one was interesting. Red Canary, our, you know, our favorite local managed EDR company, is hiring an in-house counsel. So if you're a lawyer or you know one who would be great for a burgeoning security company, that'd be a good opportunity. Sweet. And that is it for jobs.

All right. Well, that's it for the podcast, right? We got our our kind of feature interview out of the way with our Apex Awards. And we are— we're excited to— I don't know what we're excited for. What are we excited for, Alex?

We're excited to be done recording. We are. I'm excited to go enjoy the rest of my Sunday. Yeah. All right.

Well, that's it for this week. We'll look forward to talking to you guys next week. Thanks, Robb. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes