All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from: Spire Digital, CenturyLink, Red Canary, Ping Identity, root9B, Swimlane, Optiv, and a lot more!

All the news that’s fit to gossip about

Boulder is the nation’s best tech hub. BLM gives land back to Colorado. CenturyLink is bringing fiber expansion to Denver. Red Canary gives us a holiday treat. Ping Identity adds board members. root9B knows bad passwords. Swimlane announces level-up. Optiv measures security ROI.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4139 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 144. That's right, right?

Yeah, 144, Robb. Wow. Well, Alex, uh, we take a week off. We took a week off. It's like, whoa, what happened?

I don't know how to do this anymore. 144, can it? We've done this 144 times. Wow. It is the week of December 9th that we're talking about.

We are on the home stretch getting to the end of the year. We are very close. We are 11/12ths of the year. I can see next year with 20/20 vision. Oh my gosh.

Oh, that was good, right? Guys, I didn't write that ahead of time. That was just spur of the moment. Alex, how was your Thanksgiving? It was good.

I had some family in town, just Relaxed, didn't do anything too exciting. How about you, Robb? I was on the beach in Mexico, and I did have a turkey empanada on Thanksgiving. So it was very traditional. Instead of corn masa, was it stuffing around the outside?

I can only assume so. Yeah. Yeah, it wasn't actually great. I ate very little of the chicken or turkey empanada. Well, why don't we go ahead and jump into some housekeeping?

We do have a Slack channel with over 1,000 of our closest friends participating in daily conversations around security in the area. How would you find the Slack channel, Alex? What if I don't know what Slack is? Ooh, well, now you're asking a much deeper question. So we could go into the history books and talk about how Slack is really just IRC in the web, but we won't go there.

If you want to find our Slack channel, you can go to the website colorado-security.com. There is a Slack button. It'll allow you to go straight to that Slack channel and join. Also on that website, we have a mailing list. So as you might be aware, since you're listening to this, we have a podcast.

If you want to know when that podcast comes out and get the show notes in your email, sign up for that mailing list. And all the links for the stories we talk about are in that newsletter. We also would love it if you would rate us on your favorite podcast listening app and subscribe. So these things just pop into your inbox every week and you can, you can listen with less thinking. That is the best way by far.

Also, you are encouraged to tell a friend. Let the world know about Colorado Equal Security, the podcast, and everything else that we're doing. We would happy— be happy for you to spread that word. Yeah, this is it. This is your opportunity, your call to action.

Go tell a friend about what we do, uh, maybe get us a couple new listeners. And while you're at it, if you, if you think you want to do more, there's a couple other ways you can help us out. We would love it if you'd financially support the show at Patreon. There's a link to join that on the website. And we would also love it if you would do interviews.

Yeah, so it takes a lot of time for us to put the podcast together, not just doing this lovely repartee, but also the second half, which is the interviews. So if you are interested in interviewing someone, we would love for you to reach out and let us know. We have had a number of guest interviewers on the show already, and we're always happy to have more. All right, let's go ahead and jump into the news. So at the top of the list here, we have a story that shows where is the best hubs for technical talent in the world, or in the US rather.

Alex, who's number 1? I'm gonna guess it's somewhere in Colorado, Robb. You're absolutely right. Number 1 is Boulder, Boulder, Colorado. Suck it, Austin.

Austin's not even on the top 10 list. That is because Austin pales in comparison to us. You know, some of the other cities on the list include what, you know, you'd expect to see, San Jose and San Francisco. Basically what they did is they looked at as a population how What percentage of jobs are STEM jobs? What percentage of people have STEM engineering degrees or STEM degrees?

And then what percentage of folks have higher educational degrees? Right. Yeah. Basically how many jobs and how many people have skills for those jobs. So congrats to Boulder on that.

Um, also Ann Arbor was on the list and, uh, and Washington, DC. They also, if you were interested in it, um, have a link to the parallel survey, which is the the opposite end, which is the, I don't know, the un-tech hubs, right? The least tech hubs, the places that you would not want to go try and hire someone with a tech background, like Cape Girardeau, Missouri. That's not a place I've ever heard of. Me either.

And it's probably pronounced incorrectly. Yeah, probably so. Next, this is an interesting one, Robb. Let's do a throwback news story here, huh? We're going to do a news story from 1876.

I am unhappy that the federal government did not follow through on its promise to give Colorado the 2 blocks of 37 miles that they gave all new states when they joined the Union back in the 1800s after the Confederacy. So the, the Bureau of Land Management is giving Colorado some land. This is to settle a debt. As Robb mentioned, when states join the Union, after the Civil War. The Revolutionary War.

The everything that joined after the Revolutionary War was supposed to get the 37 miles. Well, I clearly did not read the story correctly. Anyway, the— we did not get that land in Colorado. This was supposed to be put in a trust and held mostly for schools and other things like that. And Colorado did not receive everything that it was supposed to receive.

Well, I know, I know. I feel we'll be able to sleep a lot better knowing that they finally paid off this debt. We're going to have our 37 miles. I think it's 28 miles of federal lands and minerals for another 9. So it's 28 miles of land and mineral rights on another 9 miles.

They said that don't worry, these will not get in the way of access to federal lands or anything. These are apparently lands that no one cares about. That's my guess. Yeah, it did look like from another story that I read that these are sort of adjacent to other federal lands that we are— state lands that we already have, you know. So it's not necessarily, oh, all of a sudden, right, right in the middle of downtown Denver, there is now you know, some new land that someone's gonna have to do something with.

Yeah. All right, next story. Spire Digital has been acquired. They are a 21-year-old startup there, and it's a tech organization that's focused on digital transformation, basically developing everything from websites, e-commerce, Internet of Things, and wearables. You know, digital transformation startup who's competing with the likes of Accenture, IBM, and Cognizant.

And they say that The CEO says that the fact that they have to compete with those, you know, big global monoliths, uh, is a big part of why they were ready to be acquired and be a part of a larger organization. Yeah. And I think that they, they wanted to be a bigger, uh, bigger company. They wanted to compete and you got 2 choices, right? You can either continue to grow, which is a much slower process, or you can be, you know, become part of a larger company.

And so they chose the latter. So the company was 100+ employees here in Denver or is, I guess, uh, but now it's part of the new organization from, from London is called Kin Carta. And it looks like the acquisition for this was about $35 million, or £27 million, if you, you know, are one of our British friends. Yeah, and I did think it was interesting sort of reading between the lines. After the acquisition, Mike Gilman, who was the CEO and founder, is going to move into a chairman role.

And someone else is going to be stepping in to be the new CEO. My thinking there is that, you know, maybe Mike, in addition to having the wanting to be a global company, was also ready to cash out a little bit and, and do something else for a little bit. 21 years of building a company, maybe he's ready to do something else. Yeah. Yeah, exactly.

Uh, next, um, sort of breaking news here within the last day or two. Um, there was a, an article by, uh, by Krebs talking about how ransomware has affected a Colorado IT managed service provider that, uh, that does work for dental offices. It's, uh, over in the Park Meadows area, Englewood, Colorado. Complete Technology Solutions, apparently they offer IT services to 100+ dentist offices, including things like IP telephones, data backup, network security. And it looks like, you know, the, the MSP Complete Technology Solutions might have been the way that the attackers got access into all of these hundreds of dentists.

Yeah. And this seems to be a fairly common story lately. You know, the, uh, the attackers for ransomware realize that if they can, well, they could go single company by single company, or they could attack somebody like this who has access to many other companies and then use them as a conduit to put ransomware and then ransomware all those individual companies. So this is definitely not, uh, piling on. I feel very bad for the guys at CTS who are going through this right now.

Um, hopefully they're, you know, they're getting the support they need to be successful. There are all kinds of, uh, unfortunate facts in this story. Yeah. Um, that looks like the CTS customers took to posting about the attack on a private Facebook group, um, sharing the steps that they've taken. And, uh, and one of them was quoted as saying, I would recommend everyone reach out to their insurance provider.

Um, I was told by CTS that I would have to pay the ransom to get my corrupted files back. Yeah. That, that is not a good thing you wanna be told by your service provider. Yeah. Uh, there was also another dentist's office that they had quoted saying that They had reached out to their insurance provider and were not receiving any help.

Um, my assumption there is that their insurance provider did not actually give them cyber insurance coverage, right? And therefore they're like, eh, sorry, we don't have that for you. Um, but in, in any case, it, it is bad stuff. Uh, it sounds like Krebs had called the, the CEO of the company or the president of the company and, and asked for a comment. And the guy said, uh, this is not a good time and, and hung up.

And, and I honestly, that's probably about the right thing to say when you're in the middle of this, right? Yeah, I'm not sure that I would've even answered the phone. I guess maybe he thought I was a customer or something like that, who knows? So next, Ping Identity has added 2 new board members. Alex, tell us about these 2 new board members for Ping.

Robb, these 2 new board members are Yancy Spruill and Lisa Hook. So Yancy is the CEO of DigitalOcean and previously was here local at, Why am I blanking? SendGrid. Thank you. SendGrid.

He was the CFO for SendGrid. Yes. And Lisa is on the National Security Telecommunications Advisory Committee, where she was appointed by President Obama. Yeah. So that was her, her kind of federal appointment.

But she's got a whole bunch of other pretty impressive backgrounds from, from the commercial or private side, where she is on the board of directors for FIS, for Unisys, Uh, I don't know Q by Q, but another one, Philip Morris. And she also was the CEO of Newstar, which you probably know of a little bit. They're a web company that does like DNS data and they're a DNS provider. So she's got a lot of different kind of different backgrounds. All right, sounds good.

Uh, next we have a blog post from Root9B talking about passwords. So, uh, this is just sort of a, a general blog post talking about what it is that you should do for your passwords. And they go into a lot of detail here, uh, talking about how quickly passwords can be cracked, how long you, uh, you should make your passwords, and some advice that they have on, uh, you know, the best way that they think you should, uh, create passwords so that they can be, uh, less cracked. Would it be reasonable to say we could replace this blog post with the advice to go get a password manager? Yeah, I think as long as you're using that password manager to create random passwords.

Right. If you're not just using the password manager to store your crappy passwords, then yeah. My password 2, my password 3. Right. They'll never figure out my password 4.

Well, that's what you have the password manager for. You don't have to worry about that. Next, we have a story from Swimlane. They have launched up what they call their— excuse me, launched their Level Up initiative, which is a— what is it? It's basically a scholarship program they've created for folks who want to get their access to big conferences like RSA and Black Hat.

Oh, I thought Level Up, it sounded like you were gonna get to play video games. Is that, that's not what we're doing? I can only assume that video games are part of this at some point. Yeah. So this is a pretty cool blog post.

Um, Swimlane, they're, they're talking about how, you know, analysts can have problems getting continuing education, how sometimes burnout affects people and, and leads them to leave, leave the industry. And so they're offering scholarships to some folks to, to go to conferences like RSA and Black Hat. Uh, to hopefully, hopefully continue that education and move up. I think if you've never gone to RSA or Black Hat, that you absolutely should do that once in your career. And I think if you've gone once, you probably don't ever need to go again.

It's, it's kind of a, you know, you have to experience the, the craziness that those things are. And then after you've been there once, you say, I think RMISC actually looks pretty darn good. Well, I think it's also a lot easier to go if someone is paying for it, right? So if you do get one of those scholarships, it seems like a good time to go. Really cool thing that, uh, Swimlane's doing.

Thanks for supporting that, guys. Next, there's a blog post by Optiv talking about measuring cybersecurity ROI, and this is a multi-part blog post series. I'm not sure if we'll cover the rest of them, but it was interesting in that they're, they're starting to lay out, um, how it is that they feel like you should figure out the value of your cybersecurity program, really talking about return on security investment. They don't go into a whole lot of details on how exactly to do that, but but in this first blog post kind of lay out the groundwork. Well, they, they start off, I think, in the first one talking about, uh, one particular way you can measure your ROI is the reduction in annualized loss expectancy.

So, you know, one way we can look at risks is by saying, okay, let's— it's going to cost $1 million if this bad thing happens. We think there's a 10% chance of it happening in any given year. So it's, it's a $100,000 expected loss from that risk. By implementing this control, we, we've reduced that $100,000, you know, down to $50,000. So you just save $50,000 on your ROI right now.

Those numbers can get awfully hard to believe at some point because there's a lot of assumptions built into it, but it is a useful way for us to think about, okay, if I'm, if I'm going to go buy a technology that costs me $200,000 and the expected loss annually is, is $100,000, well, obviously it doesn't make any sense for us to buy this, right? Yeah, exactly. Yeah. So, um, looking forward to see what the, the next parts of that blog series talk about and how it is that they think that you can continue to mature that. Next, we have a kind of a holiday special from Red Canary, the 10 Hackers Hacking, a holiday countdown of retail cybersecurity threats.

So they basically are giving us the top 10 ways that they've seen hackers trying to exploit in the retail industry, which apparently they have a good representation of in their customer base. I didn't, I'm not gonna go through all 10, but I did put number 1 here in the list, which is masquerading. More than any other technique, they detected adversaries on retailer systems manipulating file metadata, trying to rename them to appear as legitimate, trusted programs so they can avoid security. So I really think that they should have done this as 12 instead of 10. Yeah.

And then you would have had to sing the blog article as the 12 Days of Christmas. One masquerade. See? Yeah. See, maybe we'll pass this on to the folks at Red Canary, see if they can revise that blog.

I think that's a good idea. All right, so that is the news that we have for this week. Let's jump over to the Slack message of the week. Thanks to Andre Gaeta, as always, Andre, we appreciate your support. You've been a huge contributor to the Colorado community and remain so.

Thank you for all you're doing. Each week we get one folk, one folk? Well, yeah, I think that's technically correct. One folk who we recognize for contributing to the conversation in the Slack community, and that person gets to pick an item from the Colorado Equal Security swag store with their favorite item. This week, Jeremiah Cruitt, uh, he shared a link to a really detailed story about a Chinese bank hack, and it was, it was interesting.

A lot of good technical detail, and I think something we could all learn from. Yeah, congratulations Jeremiah. Uh, we will hook him up with Andre and he can pick any item up to $25 Uh, from the Colorado Equal Security Store. All right, moving over next, we have a calendar of events on the website as well. If you've been thinking, man, is there anything to do in the security community in Colorado?

The answer is yes. This week there is a— there's a lot. Yes, it is all this week and then nothing else till the end of the year. Uh, so, so definitely get ready to go do some partying this week. Um, and then of course we have a lot of stuff already out on the calendar for January, February, March.

Uh, so first on the list, On the 10th, ISSA and ISACA are doing their annual holiday bash, so you should definitely check that out. It's the Soiled Dove, right? Soiled Dove Underground. Yeah, the CSA, Cloud Security Alliance, is doing their 2019 holiday party. It's the same day on the, on the 10th.

I think that ISSA/ISACA is in the afternoon and CSA is in the evening, so you could party all day. SecureSet on the 10th is doing a capture the flag, so after you leave that CSA holiday party, maybe you could, uh, go do some CTF. On the 12th, ACES Denver— and ACES is once again the, the local physical security group— they're doing their election and their Christmas gathering. Also on the 12th, SecureSet is doing a Hacking 101 Intro to PowerShell. And your final event of the year on our calendar at least is the ISC² Pikes Peak.

That's down in the Springs. They're doing their December chapter meeting on the 13th. They moved this to a different day later in the week, I think, so it can be more party-esque. Yes. Gotta love a party.

And I'm sure everyone else is having all kinds of holiday gatherings and happy hours and whatever other parties for their organizations too. Well, let's go ahead and move over into jobs. Holy smokes. What's this top job on here, Alex? Whoa.

Pulte Financial Services is looking for a Chief Information Security Officer. They finally got wise, huh? They figured out that the person there was not any good. And they said, See you later. No, just kidding.

So as one might surmise, that used to be my job. I am no longer at Pulte. I have moved on. I am now running the enterprise security program for the Anschutz Corporation. So pretty exciting.

Looking forward to doing that. Started there recently. And of course, now Pulte is looking for someone to fill my shoes. And I can speak to the Pulte CISO job. It's a great organization, a really good supportive boss, supportive environment.

And those who are looking for a new CISO role could, could do a whole lot worse than, uh, applying there at Pulte. I do have to say, um, I wear a size 14 shoe, Robb, so just about anyone can fill my shoes. Just, you know, they can fit in your shoes. Well, that, that's really what, what counts, right? Uh, next, Red Canary is hiring a technical support engineer, and this is a potentially remote position.

City of Boulder is looking for a security systems administrator, level 1. You can work with Ben Edelman, who's a— Edelman, excuse me. He's, uh, he's the CISO over there and a really good guy. I think you'd enjoy working with Ben. Uh, next, Charter or Spectrum is hiring a security engineer for risk and threat management.

Uh, and next after that, uh, Western Union is looking for a lead cybersecurity application security engineer. Uh, the Mental Health Center of Denver is hiring a HIPAA privacy and information security officer. I gotta say real quick, because HIPAA is here, uh, we did our HIPAA training at Ping this last week. And, and as I was like going into our, our training, our LMS, our learning management system, um, I, you know, they have little like tags on it to see what the word, what, what the topics are. And there was HIPAA with H-I-P-A-A, which is appropriate.

And then there was HIPAA with H-I-P-P-A because people misspell it so much that they had to tag it both ways. They had the typo in the system as well, which I thought was really quite smart. That is pretty cool. I like that. Bank of America is hiring a whole bunch of people, including a cybercrime prevention analyst.

That sounds like a really fun job. HomeAdvisor is hiring an application security engineer at their new Reno office. Caterpillar is looking for a security specialist. And finally, NGL Energy Partners is hiring an IT security compliance analyst. Sweet.

Well, Robb, that is the end of the newscast. That's the end of the newscast this week. I do hope to see some of you guys this week. At one of the many events. Go to all of them and see if I'm there and maybe fill out your bingo sheet for where you find me.

Yeah, and we also— we do not have an interview this week, so this is the end of what you're going to hear from us. All right, everyone have a great week and we'll talk to you again next week. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes