Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 103 for the week of February 4th, 2019. Yeah, and if you're listening to this, then you know who won the Super Bowl.
If you give me a call right now, I would appreciate that. Alex, I don't know if you're aware, but this episode actually marks our second anniversary. I guess it'd be, yeah, our second anniversary of the podcast. That is pretty cool. It's hard to believe we've been doing this for 2 whole years.
The first one dropped on the 6th of February, 2017. 2 years I will never get back. 2 years of your life that you could have probably found something better to do. You could have by now learned a foreign language. You could speak English fluently.
Barely, barely. But yeah, that's good. So I could probably have learned a couple and, you know, maybe have lived abroad, done a lot of things by now. But we've got this instead. So well, there you go.
And so community, this is Alex's tribute to you that, that he's given up learning Mandarin, which is really his true passion. Yes. And but since we're doing this, we think that all of you should participate with us. And one of the ways that you could do that is through our Slack channel. We've got this great Slack channel.
We've got nearly 800 people in there, and there's lots of great discussion that goes on. So check out the website, colorado-security.com. You can find the link there and lots of other stuff on the website as well. Come chat with us in the Slack channel. Awesome.
We also would love it if you wanna get the show notes delivered into your inbox every week. You know, not only do we have this great banter, but we also write this stuff down. So if you wanna check out the links to the stories we talk about, if you wanna have the links to the jobs that we go through and of course the events in the area, those are all in the show notes and you can have those in your inbox every Sunday afternoon. Also, if you're not signed up for those, you know, you don't know that Rob White writes a witty little headline at the top of the show notes every week. So you should go in there, sign up so that you get them so that you get to know what that is each week.
And if I don't get somebody who comments on my witty headline every week, I'm pretty depressed. And exactly, I say most weeks I don't get any comments at all. So if you want to contribute to Rob's mental health, please subscribe to the mailing list and read the witty headline. And you can also subscribe to the podcast to be downloaded in your favorite listener and rate us out there too, if you want to help out. Exactly.
And we do have some other ways that you can support the show. We have a Patreon campaign if you're willing to contribute some, some of your hard-earned money to help us support this, this effort. And if not, we would love it if you just told a friend, spread the word about the podcast and the website and all the other things that we're doing at Colorado Equal Security. All right. Let's jump into the news.
Alex, did you know that the majority of North American yaks live in Colorado? I did not know that, Rob. What's a yak? So I was going to say, do you know what a yak was? Right.
A yak is basically a long-haired cow. It's kind of the cousin to the cow that looks very similar, but it's different. It is different. There was an article this week talking about the Stock Show and how partially because of the Stock Show, Colorado is that center for yak farming in the U.S. Yaks apparently are a little bit like beef but much leaner, and, you know, a little bit like bison but not as sweet. Yeah.
You know, another thing I found out as a part of the Stock Show this year, which, you know, I've been here for 18 years, I probably should have known this previously, but if you're a, you know, a supporter of all things kind of traditionally Colorado, you don't take down your Christmas lights until after the Stock Show is done. That, that is kind of the tradition in here in Denver. Yeah. So if you're not out on your roof taking your Christmas lights down this week, then shame on you. Yeah.
Some of us might have done it too early and blown the whole thing. Exactly. Next, RTD launches an autonomous shuttle near the airport. It's funny, you know, when I think of shuttles, you know, I'm thinking of basically of a bus. There's a picture in the article of the shuttle and it's, it's kind of like the Mini Cooper of buses, right?
It almost looks like a Smart car. It's not very big. I don't know how many people can get in there, but it's not very many. I want to say it was like 12 or something like that. Maybe 10 to 12.
You'd be all over each other. In that little yellow thing. So anyway, in conjunction with Panasonic, who coincidentally has an office out near the airport, RTD is testing this autonomous shuttle. It has a pretty short loop, but a loop around there that goes from the A Line light rail station, you know, to some of the buildings that are, that are right around there. So if you really, if you want to ride it, you could just go and get off the train at that.
I think it's the 67th, 68th Avenue station and ride that autonomous shuttle. I think they're gonna be testing it for like a year or something like that. So lest you be afraid that this is taking away a job, don't be— don't worry, there's actually someone standing on the shuttle to make sure everything works okay. But that person is not driving. Yeah, it sounded like they could override the controls if they need to in case of an emergency.
Anyway, this is, this is the future that we've all been looking forward to. And I can't wait to get to the point where I don't have to drive and I don't have to pay someone else to drive me either. Next story we have is that Gusto, which is a payroll startup company that's— I don't think that Denver is their headquarters, but it's basically their biggest office. They actually just leased 60,000 more square feet for a big expansion here in Denver. Yeah, they're like a lot of the San Francisco startups that have put offices out here.
You know, their headquarters is technically still in San Francisco, I believe, but the the bulk of their employees are in Denver. And as we can see by the expansion, they're gonna make that even bigger. When they announced opening an office here in Denver, I wanna say it's 2 years ago now, they said that they were gonna try and get as many as 1,000 people in Denver. And I think they only have, you know, 200, 250 in San Francisco or something like that. So the article here says that they will have more than 1,000 with this new expansion.
Obviously, they're not committing to certain numbers, but pretty cool. Uh, on other startup news, uh, Twilio announced the closing of the acquisition of SendGrid. One interesting piece of, uh, to note there is that the original price of the acquisition was $2 billion, but by the time it closed, it was a $3 billion acquisition, uh, because of the, uh, the rising tide of both stocks. Yeah, I think, uh, basically, you know, excuse me, SendGrid had gone public about, call it 16 months ago, 15 months ago, something like that. Um, and their public price at the close of the deal would depend, you know, would determine how much above that they would be selling.
Basically, you know, they're paying a 20% premium or something like that over the public price. So, you know, the price went up significantly for Twilio to buy them. However, Twilio's own stock had gone up during that same time, and since they were doing a stock purchase of SendGrid, you know, it all kind of canceled each other out. Yep. Anyway, big deal.
I, I think it's fair to say that these are no longer startups. Now SendGrid does not get to be called a startup after you go public and then get acquired by, you know, a massive other public company. Agreed. It sounds like SendGrid will, uh, continue to operate as a separate company in, in, you know, in the name, but will be, uh, you know, a subsidiary of Twilio. Yeah.
Uh, so next story, whenever someone asks me what's my favorite episode of our podcast or favorite interview of the podcast, you know, there's a few that that kind of kick around for me, but, you know, one of my very favorites is when I got to sit down with the CEO of Conversant, which is a local ethics and compliance company, and heard him tell his story, you know, just peripherally, very tangentially related to security, but his story was just really compelling. So I was excited to see this, this week there's an article about the Chief Ethics Officer at Conversant that was in the Business Journal, really talking about her career path, and I recommend folks who are interested in knowing more about that company and hearing those stories, number one, go listen to the old podcast from about a year ago, ago with Patrick Quinlan. But number 2, maybe take a look at this article. Yeah, good stuff. Next, an announcement from ThreatX.
They have hired Chris Bradziunas as their new Chief Product Officer. Chris was previously at LogRhythm, where she ran— she was not the head of product, but was one of the higher-ups in product at LogRhythm, and has now left and gone over to ThreatX. So congratulations to her. There's a few details in the press release here, but really it's You know, it's mostly just touting ThreatX and how they're going to be doing some awesome stuff in the future. Yeah, ThreatX has had a lot of hires recently.
I know they raised some money. It does feel to me like they've got a really nice momentum right now where they brought in the new— the CFO and the chief marketing officer, now chief product officer. They have really staffed up. I've heard they made some really good hires in other places as well. You know, it's nice to see that momentum building and hopefully this is really the year for them to take off.
Yeah, good stuff. Our next story here is Swimlane, another one of our favorite startups in town, has started their own podcast, which I guess could make it, you know, in contention to be the second best security podcast in Colorado. Yeah, I mean, I don't think that anyone will ever, ever be the first best other than us. But, you know, at least there's more, you know, more of an ecosystem out there, more choices for people. As long as we're the ones doing the ratings, I think we're in pretty good shape on that number one slot.
For sure. But their podcast is called Listen Up, right? Yep. And it's focused on doing, you know, it's focused on security operations and really talking about how you can use orchestration, automation, and response to improve on your operations practices. Yeah.
And I have to say, I have signed up as a listener but have not started listening yet. So maybe I'll report back in future weeks about, you know, whether it really deserves to be the second best podcast or not. Next, Ping Identity had a blog post this week on the Modlishka phishing tool and MFA. And, you know, what is that really talking about? Yeah, so Modlishka is a— if you go out to GitHub, you can actually look at the code.
It's a proxy that you can use basically to intercept traffic as someone is authenticating. You know, if you're going to set up a phishing site that goes to Gmail and you want to capture someone's credentials, well, what it'll do is it'll not only capture the credentials, it'll also capture any request for a multifactor authentication. And once, you know, once it captures that, it'll pass it through and log in. And then once they're logged in, you know, using your token, they'll actually go in and do things like, you know, adding an app-specific password or whatever it takes to get persistence in the account. So this is a new— it's not, you know, this is a hypothetical threat that's always existed.
However, now we actually see free code out on the web that allows you to do it. Easy to set up your own POC if you're willing to burn a few hours doing it. So most kind of normal, you know, uh, 2-factor methods are suspect for this. Um, you know, one-time passwords, the, the push to authenticate, the, you know, SMS, all of these things are really suspect for it. Really the only one that, that's out there right now that's not, uh, vulnerable to it would be FIDO2 or U2F, which is, um, when you have a hardware token that is bound to a specific website, it would, you know, it would notice that this Um, that this proxy exists in place and it would, it would break the authentication.
Yeah, I think this is just sort of the next step in attackers, you know, upping their game, right? As you know, it was just traditional username and password, it was easy to throw up a phishing site and capture someone's credentials and then go use them. You know, now with MFA they've said, oh well, we're getting less success, we need to do something different. And I think, you know, anytime someone is proxying your traffic and can sniff what you're doing Um, they're going to be able to defeat pretty much any security control that you have. So scary stuff.
Yep. Uh, next, LogRhythm has a blog this week on the road to scalable cloud analytics. Yeah, so I thought this was a pretty interesting article. Um, it's a very long and in-depth article, uh, not necessarily— I mean, it is about LogRhythm, but less about security, but more about them developing, uh, some of the products that they have. They recently announced their cloud AI product, which is sort of a user, uh, user, uh, authenticate— or not authentication, user behavior analysis platform.
And they developed that in the cloud. And it really— the article talks through the lifecycle that they went through, you know, sort of first starting out with an initial architecture and figuring out the problems that they had and how are they going to do this in the cloud. Lots and lots of detail in there about their thought process and what they went through to get to the architecture that they ultimately have today. So if developing in the cloud is something that is interesting to you, I think this is a really good article to read. Awesome.
Thanks, Alex. Uh, our last story this week is a blog post by Webroot, Ashley Stewart over there, talking about what they're trying to do, or one of the ways that they're contributing to fixing the, the cybersecurity skills gap. So they have some stats in this article talking about how employers perceive this gap, and over the last 4 years it's gone, you know, from 40% to 48% to 52% to, I think this last year, 53% or something like that of employee employers recognize that there is a gap for them being able to hire cybersecurity folks. So they've been partnering with the University of California San Diego on some coding challenges that are really meant to help develop the skills, the technical skills, scripting development skills that would be necessary for that next generation of security folks. Yeah.
And, you know, they had lots of quotes from the students that went through the challenges. You know, about how beneficial it was to them to sort of use these, their skills in these real-world problems, you know, uh, figuring out solutions, that, that sort of thing. It was also nice that they, they talked in there that, you know, for the folks that, that won the, the coding challenges, they were, they were invited to apply for an internship. So, you know, pretty good stuff there, right? Uh, well, I, I think it's nice to have the opportunity to get an internship.
You might also wanna throw 'em a t-shirt or something like that. You know, I'm sure that there's some other prizes too. Actually, that's my, my, uh, little nudge to you, maybe a little swag for those folks. My thought was, hey, if you're gonna win the coding challenge, maybe you should just give them an internship instead of, you know, making them apply for it. But hey, what do I know?
Well, that is it for news this week. Let's go ahead and move over to the Slack Message of the Week. A big thanks to Andre Gaeta, who has been sponsoring this for us for quite a while now. Andre, thanks again for your support. The winner of the Slack Message of the Week every week gets something from the Colorado Equal Security swag store.
So this week we get to recognize our friend Rock Lambros. Rock has a Uh, posted this week some news. He actually is the one who broke the news for us about the Apple FaceTime bug, you know, in the last week. And we don't need to go into all the details, but there was a, a relatively easy to exploit vulnerability where you could basically make somebody's phone answer and, and get all the audio and video from 'em. Exactly.
Um, not a, not a super technical bug, but one that, that has a whole lot of impact. Yeah. And, uh, Apple disabled that group FaceTime feature and is putting out a fix apparently. But congrats to Rock. Uh, thanks for participating in the Slack channel.
We'll get you in touch with Andre and you can get your Colorado security swag. Uh, next we will go into our events. As a reminder, we do have a calendar of events on the website, and man, I'll tell you, it just feels to me like we're continually getting more and more activities and things that you have, you know, on the calendar that you guys can do in the area. So, uh, do make sure you go out there and look for what's coming up. Uh, this, this week here on the 5th, we have Secureset doing one of their Hacking 101, uh, events that's focused on social engineering.
On the 8th, the Colorado Technology Association is doing their SheTech event. It's sold out too. I just saw that. Oh, geez. If you didn't already get tickets, it might be too late.
However, you know, I have it on good authority, if you just show up and crash the place, you'll probably get in. Next, on the 12th, SecureSet is doing one of their expert series with Scott Hogg talking about encryption on AWS. Nice. On the 12th and the 13th, ISSA Denver is doing their February chapter meetings. On the 14th, Valentine's Day, very romantic if you want to take your, your sweetie over to ISACA Denver.
They are having their February meeting. On the 15th, SecureSet is doing a capture the flag called Cybersecurity Hackathon. So Alex, generally we stop at 2 weeks out, but we're gonna go just 1 event further to talk about something that's very near and dear to our hearts. The ISSA Denver's Women in Security Special Interest Group that has been going on for— how long has it been now? It's been 2 years.
It's been over a year, maybe getting close to 2 years. I think maybe 2 years in April. That sounds plausible. Yeah. But anyway, on the 19th, it is the February meeting of the Women in Security group and they've reached the bottom of the barrel.
Yeah, they finally ran out of people to speak. And so Rob and I are going to be speaking at the meeting. Yeah. So we'd love it if you guys came out. I think this is a fantastic group to support.
You do not have to be a woman to be there. You have to be someone who wants to help increase diversity in the community and help women, you know, really get more women into the industry. And that's going to be one of the focuses there. But we'd love to see you there at the event, and we'll be talking about all things Colorado security. Yeah, for sure.
So let's go ahead and jump over to jobs. This week there are still some Ping Identity jobs. Yeah, I got 2 jobs from my organization. We're hiring a manager of security operations and engineering. If you are the right person to take some process processes and help mature those and help us really get well integrated with the rest of the organization, I'd like to hear from you.
We're also hiring a GRC analyst who's going to be there to help us with policies, risk assessments, ISO and SOC certifications, vendor risk management, business continuity, disaster recovery, all that good stuff. Once again, go to pingidentity.com, look at the career section, or just go to our show notes and click on the links in there. If you are not interested in working at Ping Identity In Canada is hiring an IT analyst intern. So this is for those people who do not have any experience. We might call this an entry-level opportunity for those who are interested.
Yeah, and I think this is that time when we're going to start seeing lots of posts for summer internships. Yeah, Platform SH is hiring a security and compliance engineer. Arapahoe County is looking for an IT cybersecurity analyst. Marathon Petroleum is hiring an IT/OT cybersecurity framework specialist. Wow.
The US federal government is hiring an information technology specialist. The US federal government. That's pretty broad. It is pretty broad. I'm trying to remember, trying to remember when I read the posting if they gave a department or not, but it was listed as US federal government.
And this is actually a fairly entry-level job as well.
Next, Raytheon is hiring a cybersecurity engineer intern.
SCL Health, formerly Exempla, is hiring a security analyst too. This actually reports to our friend Grant Sturgis over there. This is someone who's going to be a general purpose security analyst focused on projects, technologies, a variety of tasks, but they do use an ELK-based SIEM. So if you're used to Elastic Logstash and Kibana, this would be a good opportunity for you and really just helping get security operations improved over there. And then finally, PDC Energy is looking for a security GRC specialist.
Awesome. And so that's the end of jobs. I think we wanted to spend just a moment saying that the RMISC keynote speakers have been announced. I actually looked at the website. I didn't see them all up there, but I know we have finalized it all, right?
I think we are waiting for maybe one contract still to be signed, but for the most part, they are, they are finalized. So go check out the website for that, rmisc.org. Um, before we jump into those actual keynotes, the, uh, also the call for papers is closing this week. So if you are interested in speaking, please go, uh, put your, uh, your submission in. Uh, we would love to have you come speak at the conference.
Uh, we are as always looking for sponsors. So if you are a company that is, uh, interested in reaching out to the Colorado security community, come sponsor the conference. And finally, uh, registration is open if you want to attend. Uh, go to the website and sign up. Awesome.
Well, I think, you know, why don't we just go dive into the keynotes in a different week? Cause we're going to, we're running a little bit late on news right now. Sounds good. Um, we do have a feature interview this week with Stig Ravdal. I sat down with Stig just a couple of weeks ago.
Um, he has been in security in Colorado for a long time. He runs his own company and, uh, really helps multiple other companies in town with their security programs. It was a really fun conversation. Awesome. I look forward to hearing it.
All right. Well, that's it for this week. We will look forward to talking to you guys again next week. Thanks, Rob. This is Rob Winter, Chief Information Security Officer at Boulder Community Health.
Welcome to Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.
Welcome to Colorado Equals Security. This is Robb Reck, and I am sitting today with Stig Ravdal. Stig, it's good to get to sit down, and we've been talking for like an hour before we recorded. I think that that footage would have been the most valuable. For the rest of the world to listen to.
But let's start off by telling a story here. I understand that you proposed to your wife in kind of a unique place and uniquely. So maybe explain to me how that happened. Yeah, so I've been interested in flying pretty much my whole life. And when I started my own company, I also decided, okay, it's time to get my pilot's license.
So I went out and got my pilot's license. And then when I met my wife, the first thing I did with her, I mean, we had been dating for about 2 weeks, is I took her flying. I was like, I gotta test this. You can't have someone, you know, with you that doesn't like flying if that's what you like. So we took off flying and that was all good.
And then about maybe another 4 weeks in, we actually went, we flew down to a dirt strip down in In the, uh, the— what is it called there? I call it the Alamosa Valley, but it's the— what is that area down by Alamosa and Southwest? Yeah, Durango. It's right by the— it's right by the sand dunes. Yeah.
Okay, so we flew down. There's a place there called the Sand Dunes Hot Springs, and they have a dirt strip. So, you know, so you're not flying from Centennial to Jeffco airports. You're— you're landing in the middle of nowhere. Yeah, if there's tar under or concrete under my wheels, I'm unhappy.
I like it when it's like bumpy and dirt and rocks are flying. So anyway, flew down there. This was a real test with her, and it was one of my earlier trips into this kind of flying. But we camped for a couple of days. I had rented planes, so I was nervous.
We had some nasty weather around, and I was concerned my plane's gonna be flipped, you know, when I got back out there. And I don't think I was essentially legally, you know, or per the rental place, I probably shouldn't have been doing what I was doing, but you know, you do what you do. So, so that was kind of our foray. And then about a year later, we flew out to a place called Dolores Point. Dolores Point is right on the border really of Utah and Colorado, on the Colorado side.
It's near a place called Gateway, Colorado, which some people may have been to or heard of. Palisades— there it is. You're basically in a rock cave. Where the pieces come from, yeah, there's a resort down there called Gateway Colorado that has like an auto museum and pretty neat place. But anyway, we flew out to Dolores Point and it's about a 3,000-foot drop from Dolores Point down into the valley, about an 8-hour hike, and that's where I asked my wife to marry me.
That's awesome. So how did she— before we get to the proposal, how did she like the flying?
She was— the first time we went out flying, you know, we hit a little bit turbulence and I could tell she didn't really like that. But as we took more and more trips, you know, she started liking it. And actually, between the proposal and this trip, we had been up to Idaho a couple of times. We went to a place called Sulphur Creek in Idaho. It's a one-way-in strip, horses running around.
You know, we had a cabin. You know, they give you 3 square meals. Beautiful place and all this kind of stuff. I think really it was just starting to grow on her. And in fact, you know, I'm kind of jumping ahead here, but, but she's now actually 3, 4, or 5 days, she's taking her instrument rating because she's gonna be an airline pilot.
Holy smokes. Yeah, she's got— yeah, yeah, yeah. A year ago she got her pilot's license. She did that in 3 months, and she's been working on getting you know, time and, and, uh, and whatnot. So we go out sometimes flying 2 planes.
I'll fly in one and she'll fly in the other. So your kids aren't— you're spending time together apart. Yeah, yeah, exactly, exactly. So anyways, we flew out to Dolores Point and, uh, you know, I kind of made— typically when I land at these dirt strips, I'll always walk and look for big rocks, look for divots that I didn't necessarily see when I landed, just, just so I know what's there for the takeoff. And I sort of went off, you know, kind of busy and stuff, but I pulled out a ring Got down on my knees and I videotaped this, so I have a little video on my Facebook page as well with, with this whole thing.
But yeah, and she said yes. And, you know, the alternative was an 8-hour hike down to the valley and, you know, get some sort of bus out of there. So I was gonna ask that question. If she said no, you know, what's the, what's the plan? It's a pretty miserable flight back together, or apparently not, I guess, in this case.
No, no, it worked out pretty good. It's awesome. Yeah, for you. Yeah. Well, that's a great story.
Thanks for starting that way. I do have one thing. I, I've not too long ago had the opportunity to get on a, on a seaplane, and I got to land. I got to land in a river, uh, which was— I haven't even done that. I dream of that.
So I, and then I did get to sit in the, the co-pilot seat and, you know, kind of sort of fly a little bit for part of it. And then pretty, pretty cool situation. Where and what kind of plane was it? Um, it was in Alaska. It was a rural spot in Alaska.
Nice. Um, I could show you a picture of the plane. Yeah, but I, I don't remember the, the kind of plane, but it was really old. We'll say, yeah, like 1950s, maybe a Beaver. I'll show you a picture.
Yeah. All right, all right, moving us ahead here. Let's talk, you know, let's get into, you know, your background and all that. So where are you from originally? Steve Robdell, that sounds like a Mexican name.
Is that right? Yeah, that is. Yeah, right. Mexico City, where I was born. Yeah.
No, I'm Norwegian, born in Norway, spent the first 5 years of my life there. And then my, my dad's an engineer, and he got an opportunity to, to do water and sanitation development in East Africa. So 5 years old, we moved to Kenya, and over the next several years— holy smokes. Yeah, very different. Did you have lions around in your, in your neighborhood?
Yeah. Did you see, did you see lions? When you lived in Kenya? Oh yeah, many, many times. Like in the wild?
Oh yeah. Yeah. Wow. No, you know, safari is what you do there, so you go on trips and, and whatnot, but I've camped, you know, where you hear something around your tent at night, and then the next day you get out of your tent, and some of the guy wires and stuff have been knocked down, and these big— I call them sandal prints, but they're elephant prints. You've had elephants that came right by your tent.
So Stig is holding his hands about 2 feet apart from each other showing me how big these footprints are. Oh my gosh. Yeah, and you're kind of hoping that they're not gonna step onto the tent that you're in. And it's just— tent's not gonna do a lot of good. It's not, no.
And you'll hear lions at night and stuff like that. Yeah, we used to do these traditional trips around the holidays. My dad and some of the other folks he worked with would kind of get a bunch of people together, and we were probably 20 to 30 people, multiple Land Rovers and Toyota Land Cruisers kind of stuff. We'd go to the Serengeti and celebrate the holidays there. And we would get a pig carcass and basically hang it in a tree more or less right next to the campsite.
And then at night, a leopard would show up. And you basically have the cars, you know, pointing towards the tree. And when you hear something up there, flip it on, and there you got a leopard on that carcass up in the tree. And aren't leopards like the most dangerous of all the animals out there? Actually, the most dangerous is a buffalo, the water buffalo.
So, so these things are rather aggressive. It doesn't take too much to kind of tick them off, and they'll knock over your car. I mean, that's— yeah, more people die— actually, I should say more people die by hippos, but, but if you're driving around where lions are, yeah, it's honestly the buffalo. If you're in the car, the buffalo is a risk. Lion's probably not a risk to a car.
Not really. So most cars, when you travel around in Africa in those those parks will have a roof hatch so you can kind of stick your head up, particularly if you're shooting pictures and stuff. They'll have that. So there have been incidents where people have been kind of out of the hatch right next to a lion and they've attacked. And leopards too have kind of gotten into cars, and that can get pretty ugly.
But, but really, your, your buffalo is, is, uh, is more of a concern. I, I've been on my feet, you know, with elephants. My dad has many more stories than I have, but he's walk through a pride of lions with all but a pen, you know, because he's been out checking out some well or some water situation, trying to get back to the car, and there comes a pride of lions. Oh my God. You know, he said, what did I do?
I pulled out my ballpoint pen and just continued walking like we're there. We're supposed to be there. The Maasai and many other tribes, they live like this, you know. They do have some security, you know, for night and what have you, but I mean, it's just, it's sort of part of, part of life there. And then a lot of the stories you hear are, you know, people just doing stupid stuff.
And Westerners come and want to pet, you know, animals. Pet a lion. Pet a lion. I've seen it on Discover Channel, so I'm gonna go out there, you know, that kind of stuff. Don't do that.
But the hippo is probably the one that kills the most people because of the proximity to where people are. Yeah. Well, super interesting you got to grow up in Kenya. So how long were you there? So Kenya and Tanzania.
I went to boarding school in Tanzania. My dad spent 25 years there. I was there for a total of 9 years, between 5 years old and 18 was the last time I lived there. Okay, and then you were there until 18. Then where'd you go?
Went back to Norway, finished up kind of high school in Norway, and then went to university. Spent 2 years at the University of Bergen, which is on the west coast of Norway. Okay. And had a real desire to, to study marine biology, actually, since I was a little kid. So on the coast in Kenya, there's a, there's a town called Mombasa.
That's where kind of everyone goes. And the reef is, you know, about 2 miles wide. And so I spent, you know, 6, 7, 8 years old, I would walk around on that reef and, and, you know, bring a tub with me and, and pick up, you know, little fish and octopus and eels and whatever I could and make these little aquaria. And of course, you know, some of these poor animals would eventually succumb to the lack of oxygen and the temperature going up in a very shallow little tub I had, right? But regardless, that's where I kind of got the passion for, for marine biology, and that's what I wanted to do.
And that took me through 2 years of university in Norway, and then I decided, you know, hey, I'm, I'm in school, it's a great time to see the world, you know, where can I go? Australia Australia was one of those places I really wanted to go, you know, Great Barrier Reef, all this kind of stuff. But it's really hard to actually go to Australia. They have so many restrictions and policies and stuff like that. So I didn't make that work.
And then it was really US was, was the other alternative. And I applied to schools in the US Virgin Islands, Guam, Hawaii, and Florida. And Florida was what I could really afford. Honestly, Guam was Guam was, uh, would have been really interesting, but I got a student loan through the Norwegian government, and Guam didn't really have accredited schools that I could get loans for. They're just not kind of at that level.
Yeah. And so anyway, it took me to Florida. And, uh, so I moved to Melbourne on the East Coast to go to what was then called Florida Institute of Technology. Uh, it changed to Florida Tech the year I got there, and I think it's actually changed back to Florida Institute of Technology. But it's a private school.
They were on a quarter system. It got really expensive, so I eventually transferred to USF. Okay. And there I finished my bachelor and then got a master's in ecology. Wow.
So, and then of course I barely even finished that and I was already, you know, hacking away, building networks, doing computers. And, and I got a job. I got a job paying more than my professor, and it was like that was the end of my biology career. So did you get your job there in Florida? I did.
I had it all of 3 weeks until I got an offer. This was in the '90s. Okay. Uh, so I had a job for about— graduated with your ecology degree? I wasn't finished with that yet.
You're still going. Okay. Yeah, yeah. So I got a job, uh, for a company called Romack International Consultancy. I have no idea really.
I've actually looked at to see what happened to them, but I haven't figured out where they got gobbled up. But very quickly, there was a job offer in the DC area, and so we moved to DC. Double your salary kind of stuff, crazy stuff you did in the '90s. And so I went to work for a software developer there, small. I was employee number 9.
We got to about 75 before we got the wrong investors and all this kind of stuff, and it started imploding. And that was really where my cybersecurity security career started. As an IT guy there, I was responsible for firewalls and VPNs and whatnot. When I left, and I had taken on— it's a small software company. I was the customer service manager at one point, director of IT at another point.
I did our training. I developed a bunch of those kinds of things for the company. How long were you there? 4 years, I think that was. Pretty good run.
Oh yeah, you know, it was a good run. I enjoyed it. Yeah. Um, but eventually, um, uh, it was kind of just, you know, the writing was on the wall. Uh, we kind of went through the, the dot-com bust or boom or whatever.
And those are pretty different. The boom and the bust are pretty different. Well, you went through the— you went through the boom to get from 9 to 75 and then the bust, huh? Yes, exactly. Yeah.
Okay. So, and, and again, it was sort of Eventually, the company got sold to some company that really just services contracts. So it was a sort of sad ending on this. And we had some really cool software.
The software we had was you could take a browser and basically look at an engineering diagram. So if you were used to using Pro/E or AutoCAD or something like that to view diagrams, you could use a browser. So that's a difference of $2,000 per user in terms of licensing costs. There's nothing for the browser, $2,000 for every Pro/E station or AutoCAD station back then. And so we could come in, take all their diagrams, you know, basically we put them in a tiled GIF essentially in the browser, some really cool technology that the, the smart guys who started the company had developed.
And then we very early on had an alliance with Xerox Engineering Systems that sold these large, you know, super large format printers and folders and everything. So we were this nice piece of software that could now make these tools accessible, or these pictures accessible, to all sorts of different departments. And, and a lot of cool things kind of came out of that. But, but, um, you know, there was an end to this. There were investors and directions that we probably shouldn't have taken because they didn't know what they were doing.
So anyway, that, that's on end. And at that point in time, I decided I wasn't just an IT person. I was really in cybersecurity. I'd already gotten my CISSP. I think I got that like in '99 or 2000.
So you just defined yourself, you know, I'm now— I'm taking this path, right? Yeah, and I looked for those kinds of jobs. So again, I was, I was in a good position. I had a job and I was looking, and so I ended up going to consulting. E&Y had just gone from being E&Y to Capgemini Ernst Young, CG&E&Y.
I ended up getting a job there in their security practice. Awesome. Still based out of DC? Yeah, I was based out of DC, but I never worked in DC, right? I was on a plane.
I hop on a plane, go all over, and anytime you're in a consulting environment, I think you learn a lot, particularly if you think about the security, information security as we called it back then. You're typically not doing very long and large projects. I had contemporaries in the company that were focused on, let's say, imagery or something like that, and they'd stick with a hospital for 2, 3 years, embedded essentially. The security team, I call the smokejumpers, would come into an account, do pen tests, risk assessments, regulatory type stuff. We were in and out of there in anywhere from 3 to 12 weeks.
You get to work with a lot of different companies, a lot of different problem sets.
Our practice was based out of the healthcare group when I started, because that's where it was with E&Y. But then we were reorganized under the technology services group. And while I was there, they sent me to Paris. So I got software architect training there with a specialization in security, which was very interesting. The company invested a lot in that.
Kind of stuff. But at the same time, it was, you know, early 2000s, and, and, you know, as many consultancies did back then, they kind of, you know, cut at the bottom, and so you ended up sort of an upside-down shape. So we struggled. I, I didn't— I ended up managing the practice before I left, and I had about 25 resources, and we had more projects than we could handle, but they wouldn't let me hire anyone because I couldn't, I couldn't demonstrate where they were going going to be for the next 9 months? And I'm like, well, they're going to be in these 10 different projects, you know, something like that is what I would typically say.
But yeah, it was hard. So we ended up contracting out a lot of work, um, and kind of kept busy. Um, but eventually that sort of just— the, the constant layoffs and the constant sort of reorging in the consultancy kind of took its toll. Yeah. So how long were you there?
Uh, just over 2 years. Okay. So the first year I was you know, kind of one of the team members. And then my boss who managed the practice left. He went to a company called Legg Mason.
And then I took over the practice and ran it for the year that I was there and then left. And we grew during that time, but again, the biggest challenge was just we had more work than we could handle. Sounds like dog years. Those 2 years sound like 13 years worth of experience. It truly is, yeah.
And I, you know, since then I've typically recommended to people that are getting into the business that are young and don't mind the travel. It's a great way to really gain experience. The funny thing is, you meet people today that have a little bit of anxiety or apprehension about talking to executives. I was a senior consultant. I would be talking to CEOs and CIOs all the time.
I didn't even think anything about it until later. And I'm around other people who clearly have that sort of like, oh, I'm talking to the CEO now. You kind of get that as a consultant, you know. Um, and we did, we did a lot of interesting projects. Uh, you know, some of it was sort of mundane and whatnot.
That's where I kind of cut my teeth on HIPAA. I wrote our opinion paper on HIPAA security when the rule came out. We did a lot of HIPAA work. So we were working with hospitals. We had a HIPAA working group we were part of.
Uh, working with hospital consortiums, you know, all up and down the East Coast. Yeah. Um, so, but it was, it was a great time. And then along comes an opportunity to essentially do this on a contract basis as a 1099. So I started my first— still for them?
No, no, no, this— yeah, someone was coming out, a company here in Denver actually, uh, Dex Media. Okay. They needed someone to— yeah, directory company. The directory company. Yeah.
Yeah, so they needed someone to kind of put their cybersecurity program into some sort of a shape. And so I did that for about— Were you doing that from DC or what? No, no. Actually, while I was with Capgemini is when I moved here. What brought you here?
Air quality in DC, the lack of kind of outdoors opportunities. You've got about a 2-hour drive out to the Shenandoahs if you want to go hiking. Those are hills compared to what we have here. Yeah. And then the air quality.
The year that we moved out here, you know, we hit 3 purple days, you know, over the summer. You know, these are smog days. And so we had little kids and we're kind of like, I don't really want to live here. Yeah. And have kids grow up.
So we looked at places, you know, Maine, Vermont, places that had more outdoorsy opportunities, even North Carolina. We came out to Colorado a little bit to check it out. My wife at the time had been here. I had not. Um, so we came out, we hiked, uh, you know, camped, you know, did a little bit of bed and breakfast kind of stuff.
Um, and then we just happened to look at some real estate like literally our last day here. Yeah. Um, and we found our house. And so we, we had no— we really didn't have a plan together. Um, so we, you know, we kind of— the price was right and, and we were kind of dealing with a realtor and saying, well, how the hell do we do this?
Wait. Our house isn't ready to go on the market, whatever. Month and a half later, I lived in Colorado. Wow. Best decision I ever made.
Where did you— where'd you guys move to? Where was your house? So Boulder. I looked at it at the time because I was flying everywhere. It was kind of like, all right, you know, where's an airport?
And what's about the longest commute I want to do to the airport? So it literally took kind of, you know, did a circle around DIA, took a compass and and did a circle and I said, what kind of falls within that circle? Um, E-470 had just opened up, and so that was probably a contributor. But I, you know, we looked at Golden, Arvada, Parker, you know, just kind of looked around. We— I, I had no, you know, no idea.
Um, my, my wife at the time had family, but, you know, um, nothing really significant. So we kind of just moved here on a bit of a whim. Yeah, very cool. In fact, when we were doing all the closing, I was doing a project for, uh, for, uh, um, oh, now I'm never gonna remember what they're calling it. I want to say Needless Markups, uh, Neiman Marcus.
Yeah, uh, those guys. Yeah, hopefully they won't be too annoyed. But I had a project going on there, and I kind of, you know, went out there Monday, came up here to sign the papers, back down there, back home, drove the truck out and back there on Monday. Kind of crazy. That was probably one of the craziest weeks I've done.
That's great. Yeah. And that got me to Colorado. So you were living here, and then you got a deal, an opportunity with Dex Media to put their security program in shape. And that was a short-term or long-term?
I think it would have been long-term. So Helen— oh, I forget her last name now. She's at Fiserv now, or was at Fiserv. But, but we had a great relationship, and I think I would have stayed there for a while, but Quiznos came knocking. Quiznos needed someone to manage their security practice, so I was their first At the time it was just called Chief Security Officer.
There wasn't an I in there. So I was their CISO for almost 4 years. That was your full-time gig? That was my full-time gig, yeah. When you went and worked at DAX, you started your own business?
That was my own business, yeah. Rabdoll Consulting at that point? It was an earlier iteration, yeah. So it was an LLC. I lived close to Baseline in in Boulder.
So I called it Baseline— what did I call it? Baseline Security, something like that. Baseline LLC. Um, and I still love the concept, and that's all, you know, you have to start with that baseline and measure yourself from it. So it had a lot of sort of, you know, coolness.
Um, but then, uh, but then I did that for I think 6 months. Uh, that was, that was the length of that contract. Um, good job, loved, loved the guys there working both kind of the outsourcing piece as well They had Amdocs as their outsourcer, so there's working with a service provider to— think about it, you're trying to implement a security program that all the resources are not internal, so it has to stretch over to them. You have to negotiate back and forth. It's really a vendor management process more than anything else.
A big portion of it was working within their systems. It was a good experience, but then again, it was like this nice title came knocking, and I was like, well, Quiznos, well-known company. Chief Security Officer, awesome title. I'm going to do this. About 3 weeks in, I regretted that decision.
Quiznos was a tough company to work for. Nice in terms of benefits and everything like that, but private company, did things its own way. It was a hard company to work for. Technology probably wasn't an enabler for them necessarily. It was kind of janitorial?
No, I wouldn't say that. Say that, but I think it was— there was a lot of lip service to stuff. So, you know, by now they've changed it, or I was able to change it. But my first project was to implement the password policy. Seemed pretty straightforward.
Prior to me joining, they actually had a company that came in and had, you know, basically done an assessment, and that was one of the recommendations they had. But at the time when I came in, there were 5 passwords in the company. It was either Quiznos, Sorry, three passwords in the company: Quiznos, Toasty, or um um um um um. I kid you not. Everyone's password was one of those three.
And so the first objective was to say, "Hey, we need a new password policy." That just doesn't work. Yeah. And and that was so much harder than I thought it would be. Yeah. And then a lot of it was really just trying to educate the organization on the importance of security.
We had PCI issues to deal with because, of course, we're taking credit cards. So doing a lot of that kind of stuff. And then literally about the last 6 months I was there is when I felt like I gained the most traction. We were actually finally able to implement some of the things I'd been advocating for. How long did you say you were there?
3 and a half years. Yeah, almost 4 years.
But it was— my boss and I— great relationship. I say my boss, I reported to the CIO, and the CIO I think found me to be pretty prickly. I gave him just problems all the time. My day-to-day go-to guy was a guy named Michael DeRogier. He was my VP of infrastructure, and he and I worked the show together, so to speak.
Every now and then I'd toss some nasty hot potato over to the CIO, and he hated me for that. Um, but other than that, my day-to-day stuff, my boss was good. It was just there was weird stuff in the company, you know, just you get that with private companies, you know, that's just kind of the nature of it. Little company as well. Yeah.
So, so what, 3 and a half years in, almost 4 years in, what, what happened? Consulting came calling, and honestly, uh, I was missing consulting. Like, the, the— I called my time as a, as a, an employee bondage, right? You know, you're kind of, you know, you're stuck in your seat and whatever gets piled on you have to deal with. Whereas consulting, you kind of have that contract that says what you're there to do.
And so I love that. A company called North Highland came in and said, hey, you know, would you be interested? I had 2 colleagues from, uh, from the E&Y Capgemini days that, uh, had basically said, hey, you need to come over. You know, it was at the time we called it, it's where all consultants want to come and die. It's sort of a consultant's consultancy where all the politics of the Accentures and the E&Ys and the KPMGs didn't exist.
This was, you know, a lot of senior consultants were there, and the projects we did and whatnot were pretty amazing, but I didn't get to practice as much security as I liked. So, so I spent 3 years there. What years are we at now? So now we're basically 2007 through 2010. It wasn't really until 2009 that I did a new security project.
Prior to that, I redid Core's network here in the Valley and also out in Shenandoah. I did those kinds of things, DR plans, those things, but they were always peripheral really to security. They played well to my background as infrastructure and server-type stuff, but I missed security. My first project for them was actually with Walt Disney. Ended up traveling out to Glendale to help Walt Disney with several projects.
And about that time, one of my reports at Capgemini went on— he went to KPMG, but he came calling and said, hey, let's go do something together. And I said, well, I need money, right, at the end of the day, so, you know, let's find a couple of projects. And we did. Naively, I sort of jumped into that going, yeah, we'll figure this stuff out. And, and very quickly, about 2 weeks in, I figured, well, we should have gone through the paperwork on this arrangement before I jumped.
So you— so you— did you guys start a new LLC for this, or— he had, he had an LLC. Okay. So yeah, uh, he's a, he's a friend of mine. His name is, uh, Greg Porter, and he's out of Pittsburgh, um, and he had an LLC. What I like to say is I couldn't really tell the difference difference between the company and him.
Yeah, uh, you know, so, you know, cars, motorcycles, boats were kind of all bought out of the same pile. Yeah. And I kind of said, yeah, we need some structure here, you know. I, I want to know what, you know, part of this company that I have and other things like that. And, and that's when it sort of broke down and there wasn't really a plan.
And, and I said, you know, let's do this. I'll start my own company. I'll just— on these projects that we already have, I'll contract back I'll go win some deals, which I did, and then when you've seen me perform and you're ready to do something, let me know. That never really happened. I think he wasn't ready to have someone share in the company.
Typical founder's dilemma kind of stuff. Honestly, I deal with that stuff even now. That was the start of my company. I reformed the company not as Baseline Security, but as Baseline Digital. Just trying to keep it a little bit open, and as an S corp as well for, for better tax structure basically.
And that was in 2010, August of 2010. So I just turned, you know, 7 years last— uh, sorry, 8 years last August here, which is pretty amazing. So initially, you know, single shingle kind of journey. Very soon after, uh, so that was in 2010. In 2011, I landed a subcontract deal through a company here in town working for DIA.
The CIO out there, a guy named Robert Kastelitz, really just wanted to know what are our risks, what should we be concerned about, and then is our organization essentially set or positioned to deal with that risk? I did both a risk assessment and an org assessment. On top of that, in the fall of 2011, I wrote the cybersecurity budget and got that approved. We went from— that team at the time was really just spending on Coalfire compliance and some other things, so the budget was really slim. There was a lot of use of open source tools and things of that nature.
I went in kind of swinging, asked for $9 million, and I think everyone was jaw dropped. But ultimately we got the money. And so over the next, um, 5 years, we had $9 million to spend basically, um, in, in investment projects. And I spent another 4 years basically there shepherding some of those projects through and seeing kind of the organization change and, in my opinion, you know, evolve and really blossom into, to what it is today. So who was the first CISO over there?
So technically, well, so you have to sort of recognize this is government titles. And so the title there, you know, has to do with a job level and whatnot, right? And the CISO really doesn't exist. But the first— when I came there, a guy named Brian Monroe had essentially the functional title of CISO. He left ended up going to DataLogix, which is now Oracle Data Cloud.
And we hired a guy that I'd worked with at Coors, a guy named Chris Larrabee. And so he was, I think, the next CISO, or maybe the first one that was officially called a CISO. But he ended up taking on the network team about a year after he got there, I think. And then we had another guy for a while, and then if I'm not mistaken, I think Tim Coogan is probably still— Tim's over there now. Yeah, Tim's still the CISO there.
He's been there for a few years, right? He's— yeah, it's got to have been, I think it's maybe 4 or 5 years, but Tim was part of the team when I first got there. Okay, so he was already there. Yeah, yeah. I met Tim when he was essentially a security engineer, and then pretty much everyone else that was part of that team, I think Tim has the oldest one there now.
Yeah. Yeah. So you did that for— are you still working with those guys? No, I'm not. No.
So I did that for about 4 years, and this is about the time where I was like, all right, I'm done with a single shingle thing, I'm gonna grow a business. Yeah. And so I started taking on other clients, trying to expand projects and then bring, you know, 1099 contract resources onto those. That's still what I'm doing. It's really growing the company.
We used to do everything, like anything security, hey, we're on it, kind of like flies on shit, I guess.
Anything security. Since then, probably last 3 years, we've been narrowing to say, this is really who we are. Where we like to play is in that security advisor role, where we can help shape programs. We'll often do— I call them remedial projects, but things that we identify weaknesses. Third-party risk is one that we see quite a bit, so we'll help build a third-party risk program for them.
Typically, it's coming in and helping them put their arms around it and saying, okay, what do we do here? How do we make this into a solid program that's based on risk risk, data-driven, tied typically to a framework, and so on and so forth. That's really where we play well, I think. We come in and help organizations get their stuff in line. People who are either lacking maturity who are looking to help get to the next step, or people who are mature who need some help for project work, sounds like that's up your alley.
Cool. I'm trying to remember when we met. Was it when we both volunteered for B-Sides? Back. Is that what it was?
I'm actually— I'm pretty sure that's what it was. So, so this was, uh, this was— was it 2011? 2012? 2011? Yeah, something like that.
I know Chris Nickerson put on, I think, the very first B-Sides here in Denver. Wasn't Jobo helping him do that? Yeah, it was you, Jobo, uh, a few— I wasn't there for the first— I came to the first one and attended it, but I was not helping. No, but then there was a year that went by. There was a gap following years.
That's when we got put on. Yeah, yeah, that's what it was. So yeah, that's where we got— so how did you get involved in the community? I mean, at that point you already knew those guys, right? And I think I just sent a note like, hey, I want to help because I think because we missed a year.
I'm like, well, let's not miss another year. Yeah, I hope I'm not taking credit from, from someone, but I'd been— a friend of mine organized the B-Sides in Austin. And so I kind of came back energized from the Austin conference, I think in 2011. And I was like, you know, what's going on with Denver? So I reached out to find out who had done it.
And it seemed like it had been done just that one time. And so I think I just started pinging people, and I can't really remember. Jeff helped us too. Yeah, Jeff. And I think he's helped many years.
Yeah, I know somebody— some people kept doing it. I, I did it 2 or 3 years, and then I was— no, and I, I kind of dropped off, I think, after about 3 years myself. Um, yeah, I mean, that's, that's, uh, I think the, the great thing about those community initiatives is like people come and go, and you bring new blood in and introduce people. But I mean, it went from that one event which we did at Alchemy, Security Alchemy, to where we had to get a bigger place the next year, and then it's really just continued to grow. It's been huge, yeah.
Last year, they really had a problem last year. There's not enough room for it. Well, and that almost seems to have been the case every year. I remember, I think it was the second year where we had a limited number of tickets and we were sold out. Everyone hates that.
It doesn't matter what you do, right? A bunch of volunteers putting on a meeting, we get a lot of shit. No matter what we do. But that was probably the most fun in terms of those kinds of events. Very rewarding, for sure.
So how did you get into the community at all? Was it just go to meetups? A lot of it has been that, just networking and whatnot, and going to the Armisk conference and whatnot. And then Secure World and some of these other events as well. I branched out and I'll go to more targeted conferences these days.
So we target 3 industries: retail, healthcare, and finance. And then, you know, kind of energy is here in town, so we do a bit of that too. But we're going to a conference in 2019 that's geared towards rural hospitals. So it's gonna be in Phoenix, but it's basically all what they call critical access hospitals. So if you, if you take Colorado and you look at, you know, we got a bunch of hospitals obviously here in Denver, but once you get out in the boonies, you get what's called a critical access hospital.
So they're smaller and, you know, they serve a community. So typically people are driving maybe an hour, 2 hours to this hospital and then whatever town it's in, but, but they're not driving that distance to get to Denver, right? So, so if they need something, you know, that specialty, then typically they'll do a flight for life into Denver. But, you know, you need hospitals in the rural areas. So Colorado has some 30-something.
Next door to us is Kansas that has about 50-plus critical access or smaller hospitals. Yeah. And it's really true for all the states around us. And I kind of look at, you know, we start in Colorado, but the states that surround us are great markets for us. Yeah.
So we're looking at that, and that particular industry, you know, they're not getting the best cybersecurity experts in a little town like Colby, Kansas, so they struggle. They're barely doing their IT functions, and so it's a good market for us to come in and help. We do regulatory assessments. They typically have HIPAA, PCI, maybe some other thing, and then really just look at best practice security. We've done a lot of ransomware recovery type stuff for for these organizations.
But, but anyway, so, uh, financial conferences as well. We've spoken at several. There's an organization here in town that puts on a conference for banks. So they're a banker's bank, if you wish. They're the pipes between the feds and the, and the community banks.
And Bankers Bank of the West, is that the one you're talking about? That's one of them, yeah. And, uh, and they put on a conference, and so we've spoken at that a couple of times. Systems, and it's really just more direct to these community banks, for example. Then also, a couple years ago, a few years ago, at the financial— what's it called again?
The Financial Health Managers Conference. Trying to get outside of where it's super dense security. Don't just talk to the security people about security. Don't talk to security, but talk to the people that really need it. Yeah, that's great.
We've experienced better connections really there because people are very interested and they're typically there to focus on whatever their job is, and so security is something a little bit different and so they're interested. There too, we're seeing the vendors are showing up now. They didn't used to. We're seeing that they're getting busier and obviously security is something that everyone's concerned about. Most recently, we've been investing and spending time even in IoT.
We think that's going to be a very, very interesting space. The question is, do you jump on right now? Are you at the top of the wave or are you going to be left behind? It's hard to tell, but it'll be a very, very interesting space. Just the amount of data, the amount of connectivity, and of course, everything is just launch it and we'll think about security afterwards.
Nothing new. We did this in the '90s. We've always done that. We've always done that. In fact, I don't know, at one of the BSides I was at, When you get together with security people, I think we sometimes have the tendency to start talking about, oh, if they'd only listen to us.
But they don't. The business doesn't. They listen a little bit, but at the end of the day, I don't know why we should complain about that. We're giving good advice. It's advice.
They can choose not to take it. If they took and did everything we asked them to do, we'd be out of a job. The fact that they don't— They'd still get hacked. No, no, I'll give you that, right? But, but, but the reality is because they don't do everything we ask them, we still have a job.
We still have a job. Yeah, I mean, it's very simplistic, but yeah, but I joke, I was like, don't be jaded. Don't, don't complain about it, you know. So what's your 2019 schedule? What do you— not for events, but like, what are you focusing on next year?
So we're doing something very different. We've actually— well, today is when I sign the paper, but we're gonna do an ecommerce site for B2B, and we're going to sell certain services. We're productizing our services and selling them through a shopping cart. So it's a big experiment. That seems risky.
Absolutely, yeah. Well, here's the philosophy or thinking behind it anyway.
I kind of go from— I do pen tests for enterprise organizations, big, big companies, but we also do pen tests for the small guys. And honestly, the sales cycle is almost the same, and I always feel like it's a lot of money that we're asking for these guys for pen tests. So we've designed a box that can essentially do most of what we do when we physically come on site, and it's basically scripts that are kicking off other scripts, collecting data, feeding them back into tools, and so on and so forth. But we think that what we can do is basically deploy this box. It the very next day.
You hit that shopping cart, that box is going to go the next day. Then have essentially guys, sort of your typical pen testing lab. Many companies have done this in the past where you've got guys remoting into networks and they're working multiple customers at the same time or clients at the same time. Now we're going to turn this over and really kind of make it simple. This is what you get.
There's no sales call where we sit and negotiate, you know, what you need. It's kind of a, here's a fixed service, you pay for it with a credit card or a PO. And this all exists, the, the shopping cart exists, um, this, the scope of work and, and terms are all part of that whole, whole, you know, shopping experience, uh, if you wish. And, uh, yeah, and you push the button and, and it's amazing, we send a device off. Amazing.
And then we have a guy that basically will, you know, connect to that, or the box phones home, but it'll connect into the device and do a few other things. So, you know, one of the things that, that I want to be clear about is we're not offering the same pen testing service for that price point. Like, this is a, you know, call it, you know, it's much better than a vulnerability scan. It's more than, way more than that, but it's also much more reliant on automated activities. Yeah.
And then the other thing that we're putting in the shopping cart are policies.
We started selling tools last year, so we'll put some of the tools that we sell in, in the shopping cart as well. And then pretty much we've gone through all the services that we typically do and productized them, meaning we can say, here's what you get, it's, it's a fixed price point, fixed outcomes. So it's less consultative, and in turn what we get to do is we, we can, you know, do this more repetitively and bring down the price point. And now what we're doing is we're offering solutions to smaller businesses, the SMB space, up to 2,000-3,000 employees, that typically will maybe do one pen test every 3 years, but for that price we can get them a pen test every year, and so on and so forth. So it's going to be very interesting.
The company that we're using for this is a company called Inception, with an X. They've built this— UPS is a partner, so as part of the whole process when we ship a box, there's a label, just gets printed out, drops, and UPS picks it up the next day.
They looked at this— a bunch of investors behind this company and whatnot, but they looked at it and said, Atlassian has been able to sell JIRA and other products with no sales staff. It's all shopping cart. And they think this is really where the economy is going. And on the back end, you've got to have a little bit of— you got to have a little bit of blockchain. So there's a blockchain component to this as well.
We're gonna get through a whole episode without talking about blockchain. Exactly, exactly. Yep. So there's a component to that which will allow us to do some, let's say, trading of services using a different kind kind of currency effectively down the road. So very interesting stuff.
We're excited about it, and we think it's a way for us to reach a larger market, and particularly kind of the underserved market. So if you think about, you know, go from the super enterprises to the SMB space, the SMB space is growing the fastest, and it's also where your big companies really struggle to provide services, right, for the same reasons I It takes just as long to get a sale signed. So, you know, you're probably, you know, if you're Optive, you're probably leaving deals, you know, that are under $100,000. Like, they're not even worth it. Yeah, because of all the churn around the deal.
Yeah. Oh yeah, yeah. So, and I think that's true of, you know, large companies. So we're thinking the more we can commoditize services and make them easy to buy, and again, kind of box them in a little bit. But we do want to make sure that they don't think they're getting the same thing as like an enterprise, but it's laid out there, so we'll see how it goes.
I think that one of the risks there is that you're making it easier for the checkbox mentality for pen testing. Most certainly. Oh, yeah. Which I think most of the folks in the business are not fans of that mentality. However, it is out there, right?
Yeah, and I would agree. Many organizations, one of the first things we often do is some sort of an assessment, very often a maturity assessment. Big companies and small companies typically are compliance-oriented when we come in. They're already doing the checkbox. In fact, sometimes they're doing it very poorly.
It's a lot of sleight of hand and don't look at the wizard behind the curtain here. Auditor, just buy what I'm telling you kind of stuff. I think that's where we are, and this is an opportunity for us to go in and say, yeah, let's meet the checkbox, but we do find stuff. There are things that they otherwise wouldn't have found that could lead to ransomware and other things. Then now we're engaged with these organizations, and we can start thinking or helping them change their mentality around security, but they all struggle.
They don't have time for this. First, they need to engage, and that first, whether it's a regulatory risk assessment or a pen test, gets that conversation started. With every pen test, we always put in a roadmap. It might seem strange that when you're doing a pen test where you're finding there's a hole here or a patch missing there that you get to a roadmap, but one of the things I like about what we do is we look at the findings themselves and try to analyze why did they even Why did we get these findings? Why is a patch missing?
It's not that the patch is missing because, typically anyway, that the business said, oh, you can't apply that patch. It's probably because their patch management program just is not very solid. Those are the kinds of findings that we try to read between the lines of the pen test findings, and then we lay that out on a roadmap. We're always thinking or bringing to the table this, here, Here are these issues, go fix them, but there's some more important things, and that's to fix your processes. That's where we then ultimately engage with a more consulting-oriented engagement and help them.
Fantastic. I love that. We're coming close to the end of time here. I have one more question for you.
In my MBA program, I do a report about one country, and we did Norway. One of the things I learned about Norway Norway was it's the happiest country in the world. So now I have to ask you, why would you leave the happiest country in the world? So this is a, this is a question I get asked a lot, and I ask myself the same question, particularly when I go home. So I'll go home about every 2 to 3 years or something and visit.
And, and, you know, the happiest is only one thing. I mean, prosperous, uh, you know, healthcare. I tell people that, you know, if my kids lived in Norway, they have a dentist in their school. So your dental costs are covered until you're 18. When I first moved to the States, I, you know, I'm in college, right?
And I see all these college kids— I mean, these are, you know, anywhere from like 19 to mid-20s— with braces. And I was like, that's so weird for me to see because everyone has braces when they're like 9 to 12 in Norway because it's done in school. Yeah, here they do it when they can afford it, which is often when they're a little bit older. So for those who don't know, I'm sure you're well aware, those who don't know, Norway has these massive natural resources off the coast, this huge natural gas, oil, oil, mostly oil. Yeah.
And as all of the funds from that natural resources goes into like a national fund, right? Largest, largest rainy day fund in the world. Yeah. So they, they fund all of this stuff through this. Well, 50% of it goes to a rainy day fund.
It's untouched. It's just invested. Yeah. And so every Norwegian has approximately approximately $2 to $3 million attached to their head in this fund. Every Norwegian.
And there's something like, I don't know, we're coming up on $6 million now. When I left, we were just under $4 million. There's lots of politics about how that's invested and whatnot, but that's— in the '70s or '60s when Norway struck oil, because it's a very— you talk about European management styles, that's Norway to a T. So a bunch of smart people came together and said, how, you know, how, what should we do with all this money that we're gonna make? And decision was made, we need to put half of it away and just leave it and not invest it. If you look at, you know, countries in the Middle East, they use that money and they invest it back into their own economy.
And what happens when that, when the oil market drops? Well, those countries really struggled. We saw that, you know, in, in '07-'08, and then again, you know, not too long ago here, just in— what was that now— 2015, 2016, you saw these countries really struggle because they're so dependent on the oil economy. Norway chose not to do that, and so instead they put it in there. And of course, you know, they're making lots of money on the oil as well, but we have other natural resources.
We produce a lot of electricity through damming up rivers, which probably we couldn't do today, and then also very rich in bauxite, and, and, you know, basically we could produce aluminum— or aluminum, excuse me, there's my English coming in— aluminum and magnesium also from seawater. So yeah, and then fisheries. So all of this is a lot of reasons you would be living in Norway. So what— why are you not living in Norway? So Norway has a sort of a policy, if you wish, of evening things out.
When I was a truck driver delivering soda pop to stores, I made as much as a doctor does in Norway. And if a doctor wants to work 45 hours, they're taxed at 150% the, the regular tax rate for the, the hours of overtime. So, so it has sort of a way of not letting anyone get too far ahead. Yeah. Um, and, and no one is left behind either.
If you're a single mom, you know, whatever, the, the government will put you an apartment and a stipend. So, you know, even if you don't have a job, you'll be fine and you'll eat healthy and whatnot. So there's a big, big safety net. Yeah. Um, but at the same time, it's really hard to kind of get ahead.
So starting a small business in Norway is super tough. And then the other thing is, you know, Norway is not part of the, the European Union. It's, it's, it's part of a sort of union of countries or group of countries that have very lax regulations or tariffs, if you wish, with the European Union, but it's not part of the European Union. So if you think about it, if I start with a product here in Colorado, I've got a marketplace of almost 400 million right here. And it's very easy if you were producing a consumer-type product, you can get it to everyone in this country.
If you're in Norway, you've got a much smaller— you've got 6 million people. And then to get it to Sweden is a little bit harder, and to get it into Europe's a little bit harder. And oh, by the way, the language has changed, so now you've got to have language and stuff like that. So the marketplace here is easier, and it's just, you know, uh, it takes about 5 minutes to start a company in Colorado. Uh, in Norway, it's a lot of paperwork.
Yeah, it's just more regulated. Yeah, right, for good and for bad. Um, but, but I toy around with it all the time. I, I'll probably end up moving there again at some point in time. Uh, my kids love it.
My oldest son is actually coming from Norway tomorrow. He's going to school there right now. Yeah, so he, uh, he is 18 and he decided to do an exchange year as part of his junior high school year. Okay, uh, so he went there. He's going to an international school in a tiny little town called Sandefjord, um, and there's— I think there's like 150 students or something in the school.
Small school, and he had his own apartment. This is as a junior in high school. Holy smokes. Yeah. My parents— my parents are divorced, but they're both about 2 and a half hours away, and my sister also lives in Norway, and she's in a different direction, but he basically did that all on his own, and then when he came back for the summer, he's like, I want to finish my high school there, so he's finishing there.
He'll be showing up tomorrow, but he loves it. Of course, you know, he speaks Norwegian now and everything. About a year and a half. So this has been really fun. We've gone long, which is no problem, but it's been too much fun to stop.
Any final stuff you want to say to the listeners before we call it a show? No, not really. I think just, you know, enjoy a great 2019. I think we're gonna have a great year. Kill it.
Yeah, totally. Thanks, Steve. All right, we'll look forward to talking to you soon. Thanks for your time.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.