Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 109 for the week of— what is it? It's March 18th.
All right. Well, we just survived— what was the bomb cyclone? Is that what we call this thing? It was the bomb. It was.
It was the bomb. It was, you know, the morning was fine and all. Well, the early morning up to like, what, 9:00, 10:00? And then it was terrible for 5 hours. Yeah, a few hours.
And then it was fine again. Although when I— when you say terrible, like it was windy. Yeah. I wouldn't have wanted to be outside, you know, walking or driving in the wind. Yeah.
But I mean, at my house, we probably only had 8 inches of snow total. It was not crazy in that amount. But I, I have heard some people that I work with who said that they had, you know, near 10-foot snowdrifts at their house. So where is that? Farther south.
Parker. I did hear Colorado Springs got it, got it really bad. So for me, I drove home from work at like 1 in the afternoon, and leaving downtown Denver was fine. Getting to the tech center, all of a sudden, this blowing snow, you could probably see 20, 30 feet in front of you sometimes. It was scary.
Yeah. So anyway, we all— we both survived. We made it. We're still here. And the snowpocalypse did not claim us.
That's right. So we can carry on. So before we jump into the news, this is Robb Reck, the CISO over at Ping Identity. And this is Alex Wood, CISO for Pulte Financial Services. And we are going to just talk about some, some housekeeping stuff now.
First, we have a Slack channel. So not only can you listen to us on this podcast, you can also go Slack with us, chat with us, talk about your favorite, whatever it is you want to talk about on the Slack channel. You can get the link to join that on colorado-security.com. We'd love to have you there. Over 800 people on this channel now.
While you are on colorado-security.com, check out our mailing list. Sign up on that website and you will get the show notes in your email when we release a new show. We'd also remind you to subscribe on your favorite podcast listener so you don't have to go find us every time you want to hear an episode. It'll come downloaded directly in. And if you like what you're, what you're hearing on here, we'd love it if you'd rate us on your favorite podcast listening app.
If you really, really, really like it and you think that we're doing something great, we would love for you to support us financially on our Patreon page. You can sign up to be a patron of ours. We have several different levels of patronage, but all of the money that we get there goes directly back into the podcast and other things that we do to support Colorado Equal Security. And of course, we would, we would love it if you would help us out by telling a friend, tell a coworker, tell a colleague about the show. Help us get more folks listening.
Speaking of Patreon, Robb, we have a new patron this week. That's awesome. Yes, we've been on a roll last few weeks. Lots of new people. Let's keep the momentum up, everybody.
Let's. Do it. So Mark Thompson, he is at Black Lotus Labs of CenturyLink. The newly minted. Newly minted Black Lotus Labs.
They have a fancy new title. And he is in at our $5 a month level. So thank you, Mark. Appreciate the support. Mark, we really do appreciate it.
And for those of you thinking about supporting us, we would appreciate that as well. Why don't we jump over into the news? Well, speaking of money, right, I, I was wondering, Alex, which of the CISOs is most likely to join the Colorado billionaires list? I don't know if it really matters because I have a feeling none of them are going to join that list, Robb. But, you know, I was thinking if we get 1 or 2 more patrons, we might be able to get onto that billionaire list.
Come on, Patreon. We do have a list this week of Colorado's billionaires, and there's actually more billionaires in the state than I would have expected. You know, I knew about the top few, Phil Anschutz, is at the top of— he's actually the 128th richest person in the world with a net worth of about $10.9 billion. Charlie Ergen, that's another one that I think we, we all know, $143 billion. He owns Dish Networks and EchoStar, uh, $9.6 billion.
Uh, media mogul John Malone, that's— he's with, uh, oh man, Liberty Media. Yep. Um, and what, he's at like $7 billion. And then, then there are some who, you know, I don't think I knew that This John LaPrino, I've heard of LaPrino Foods, but I didn't know that that was a guy. So he's a billionaire.
I think it's interesting they call him a cheese mogul. I would love to be a cheese mogul. Pat Stryker, heir to a medical device maker at 962 with net worth of $2.4 billion. Gary Magnus, you know, we all know that. I assume we've all heard of Magnus Arena at DU.
I assume this came from him. He's a cable heir with over $1 billion, $1.3. And then there's a couple Macmillans who are heirs to the Cargill fortune, and they're at 1,717 with a net worth of $1.3 billion. And then finally on the billionaire list is Thomas Bailey, who I don't think I've ever heard that name, but he's one of the— he is the founder of Janus, and he's all the way down the list at 1,818 with only $1.2 billion. I thought it was interesting, however, that this year was the first year, and I can't remember how long they said that there have been— there were fewer total billionaires And fewer average in the amount of money.
Lower amount of money per billionaire. I assume that the list comes out based on last year. So they take the end of the year last year. And with the abysmal December in the stock market, that probably makes sense for how that was. All right.
So let's go ahead and move on to our next story. The Colorado Sun had a story this week, actually, by our friend Tamara Chung. Talking about even though computer science is not a required subject throughout Colorado high schools, people think it's important. And as a result, they're actually training teachers how to do it anyway. Yeah, so there are some free trainings that are out there for teachers.
It actually sounded really interesting. This is a training that teachers take that it's for computer science, but it actually does not involve computers. So it's, you know, thinking about algorithms and how to solve problems, which I think is actually very important. You know, you get those skills early on, And then when you actually use computers to solve those problems, you understand the mechanics of, of how you need to solve the problems. Yeah.
They called it computational thinking versus actually programming. And once you can think computationally, then you can program computers to do the same thing. Yeah. So, pretty cool. Glad that our teachers are getting some training, and hopefully that's gonna carry over to our students.
Next, Broomfield's Science City is touted as the next big regional research park. So this was one of the sites that they had put up for Amazon's HQ2. And now they're looking at what do they do with this facility instead. So it's about 1,100 acres up there. And I don't know the Broomfield area real well, but up north, up yonder.
And, and the way they're doing this, I actually think this is really interesting. They're comparing the resources there and the space and the location to education to RTP, the Raleigh— oh, what's the Research Triangle Park in Raleigh? Yeah, Research Triangle Park, which is, you know, a very well-known industrial parkway out there in North Carolina. And they're saying they They believe they can build a very similar type of a location to that here. Yes, they're trying to do some of the same things, you know, bring in academia and people that are doing research to try and attract talent to the area.
It's also, I believe, a multi-use kind of development. There's going to be some retail and I think some, some residential as well, along with the, the commercial areas. So it sounds pretty cool. So they're saying, you know, RTP is near, you know, Chapel Hill, you know, Duke and North Carolina State. And really, this is going to be near CU, the School of Mines, CSU, and CU School of Medicine in Aurora.
And really saying all of these have strong technology programs. This is an opportunity for us to build our own. But they're talking about over the next 30 years, right? It's not a short-term, long-term vision. Definitely a long-term vision.
I could definitely see too where you might have sort of satellite campuses or, you know, research areas from those schools that pop up in this area. Area as well. Next story is, is about diversity in technology here in Colorado. This is a story from the Denver Business Journal, and the headline, it says, white males dominate Denver's tech center, but some companies are looking to change that. So they have some stats around what the, the breakdown of male versus female is in technology here, where with about 67% of technology industry folks being men and 32% women.
80% are white, 9% Asian, 7% Hispanic, and 2% Black. I thought it was interesting here, Robb, that the— they had 80% white for the tech sector, but for the general workforce, they had it at 83.5% white. So while the headline reads that, that white males dominate the technology sector, it sounds like white males dominate even more just the general population, population and industry. So that is interesting. They do emphasize you know, companies can build more diverse workforces if they, if they make an effort out of it.
And they, they highlight 3 companies that are doing exactly that with Gusto, Guild Education, and Quizlet. Quizlet, right? So those 3 companies, they go into some details about how they're doing that and gives you, you know, gives you as your company some guidance for how you might be able to do a similar diversity program. Yeah. They also note a, a company, sort of a consulting company, I think, that helps other companies try and be more diverse.
So pretty cool. And I'm sure Elaine Marino, who we had on the show a week or two ago, could also help with similar type work. Yep. Next, the CU cybersecurity program is getting the attention of the Secretary of State. So this is interesting.
There's that, you know, we're gonna talk a little bit about that program, but one of the things that popped out in this article to me was CyberSeek, which is a digital tracker of supply and demand for cybersecurity jobs. Can't believe that exists. Anyway, they say that there are over 10,000 cybersecurity job openings in Colorado right now. That's amazing. That's a lot of jobs.
That's also the 4th highest per capita in the country. So that's pretty cool. Good. So as part of this, they talk about CU. They brought in Daniel Massey, who was with the formerly with the Department of Homeland Security and really is is looking to, to update and change that program at CU to bring it more into the, the modern to help with this problem.
So, so they previously had a program called the Interdisciplinary Telecommunications Program, which sounds not sexy at all, right? So he came in to run that and he renamed it to the Technology Cybersecurity and Policy Program, which is still not sexy but significantly more relevant to us. Yeah, in, in the past year they've also developed 10 new cybersecurity courses And they've partnered with several national security agencies to solve real-world national security problems. Yeah. And they've, they've got some folks from industry to come talk there at, at the program.
I know they specifically mentioned that Rich Schliep, our friend and the former CISO for the Secretary of State, now the CTO over there, he came in and addressed some students. So interesting to see that they're, they are reaching out beyond just on the campus. Yeah, for sure. Next, uh, CoBiz Magazine had an article about the 2019 Colorado startups on the rise, and they highlighted a couple in here. One of them, which we have talked about before, is Overwatch ID.
So Overwatch ID is an identity management, uh, privileged access management company here in town, and talking about what they are doing in 2019 to be on the rise. Yep, some pretty cool stuff. They talk about their funding status, you know, what they're up to. So really cool to see a security company making that list, I thought it'd be interesting just to real quickly mention what the other 4 companies— there's only 5 companies on the list total— what the other 4 were. Collective Retreats, which is a glamping company, glamorous camping, also known as glamping.
So if you want to do some glamping, they will help you find your, your very comfortable spot to go camping. There's one called Silvernest, which is basically like going to Craigslist to find a roommate, except it's for elderly folks. And it's not like going to Craigslist. I'm going to swipe left or swipe right on this roommate. Is that how it's going?
I'd be probably, you know, have to have your, your technically literate kids to help you do that, I'm guessing. Right, exactly. The next one was The Prepared. This is awesome. It's basically a website for preppers.
If you want to prepare for disasters, you go to The Prepared. That is, that's a company here in town that's creating a community for those who want to prepare and those who help people prepare. And then finally, Revver, which is a free map app and website for the global community of motorcycle riders. So if you like revving on your motorcycle, then check out Revver. I bet that's pretty seasonal.
I bet, you know, in the middle of January, you know, in blizzard country, there's not a lot of— or maybe, maybe they're more interested in connecting because they don't get to ride their motorcycles. Yes, they want to talk about it. Huh, that would be interesting. Maybe we should reach out to them and see when their busy season is. Yeah, absolutely.
All right, well, so moving, moving along here, we have a press release this week from EVOTEK. We mentioned Susan Bulaway Winkle, who's over there, who's, who's one of our Patreons, our patrons. They recently hired Matt Shufeld. And this press release talks about what Matt's going to do there. Yeah, so Matt was hired on as their Chief Information Security Officer.
And it sounds like to head up their sort of advisory group around security. So Matt obviously has been on the show before and was the inaugural winner of the Colorado Technology Association's Apex Award for, uh, CISO of the Year. So it sounds like a good thing for Matt. Yeah, so he's the CISO and executive advisor over there, really helping them focus on, uh, driving business in Colorado and helping security programs here. Congratulations to Matt, and congratulations to EVOTEK for getting them.
Definitely. Uh, next, there was also an article on Gusto's new Chief Information Security Officer, although I guess it just says Chief Security Officer, so they maybe There is physical security in there also. But this is talking about Frederick Lee, who is known as Flea, formerly CISO of Square, was also at Bank of America and Twilio prior to that. And I think will still be out of their Gusto San Francisco office, but will be, I think, in Colorado a fair amount. Interestingly enough, Gusto is headquartered in San Francisco, but The office in Denver is actually about twice the size of that headquarters in San Francisco, and they're planning to grow it even further.
Yeah, you know, I've seen that sort of trend a bit where companies either start in the Bay Area or feel like they need to have a presence in the Bay Area because of funding, other things like that. But then they want to grow other places like Denver or Austin or, you know, other, other places like that. And so that they may have big presences there as well. Love it. Our next story is is titled Gates Provides Seamless and Secure Access to Over 6,500 Employees.
And this is actually a story off of the Ping Identity website about Gates, the local company, which features Sam Masiello, our friend. And I think he's been on the show twice now, friend of the show, talking about what they've done. So Sam came into Gates, and one of the things he's focused on there is building out a new IAM strategy with, you know, or really a new security strategy with IAM at the base of it. And this story really talks about how he's done that. Yeah, very interesting stuff there.
And so check that out to see what Sam has done along with Ping. There's a second Ping blog talking about WebAuthn and how it is ushering in a new era of internet safety. So, you know, generally we don't do a lot of the, the real company-specific blogs. We try and do more educational stuff, and this one's highly educational. So if you guys don't know WebAuthn yet, this would be a good way for you to read and learn about that.
It's closely related with FIDO2 and the ability for you to, to have that hardware token that allows you to, to have the second factor that's not, you know, a time-based token and really is basically unphishable. And just about every other kind of MFA is phishable. So this talks about WebAuthn and really where MFA is going. Yeah, I'm, I'm really excited about this standard. I think it's gonna be cool when I can have a token that I can tap on my phone and and use MFA there as opposed to, as you mentioned, either an app or, you know, getting a text code or something like that.
And as much as possible, we're trying to build it into the browsers. So, so Chrome, Firefox, and Edge already support FIDO2, and Safari is, you know, kind of in a test mode right now. But we expect that, you know, going forward, we'll be able to use those browsers as your second factor, which will really reduce the friction of that process. Yeah, pretty cool. Uh, next, Coalfire had a blog talking about password spraying, uh, what to do and how to avoid it.
So if it's not obvious by the name, uh, password spraying is, uh, sort of spraying passwords across websites to try and see if you can guess someone's password. You know, a lot of this happens either from known passwords or, you know, compromised password lists, other things like that, uh, just trying to get access to someone's account. So, so generally, like, if I wanted to break into an account The, the typical way you brute force is say, I'm gonna go after Alex Wood, awood@whatever domain, and I try every password in the book against awood. And it'll, now generally I'll get locked out, right? Because, you know, you have, you know, 3 or 5 or 10, uh, failed login attempts before you lock out the account.
With password spraying, we'll use one pretty cop— common password against every possible account in your domain. Yeah. And, and, and try and minimize the, the visibility of that. So this talks about how do you, how do you detect it? How do, and what do you do if you do get password sprayed?
You know, turn on MFA, some stuff that they have in, in, in case here. Uh, I would say that there are technologies out there that will help you identify that you're being impacted by this kind of thing. And you don't have to just, you know, just put MFA in place. You can actually detect these attacks as they're happening as well. Yeah.
I, I think it also, in addition to that, making sure your password policy is strong, having MFA, as you mentioned, other things like that can really help with password spraying. All right. So last story this week is around Red Canary. They have a blog talking about how to use tabletop simulations to improve your information security program. Yeah.
So this, if you have not done a tabletop simulation before, you definitely should. Uh, this talks about the process that, um, that they are recommending to go through, how it is that you develop these scenarios, what you go through when you are doing one of the tabletops. Uh, definitely a good informational article if you are interested in doing those. Basically like playing Dungeons and Dragons, right? It is a lot like playing Dungeons and Dragons.
Yes. Well, nothing wrong with that. As long as you make it fun and have some character sheets, I think everyone will have a good time. Exactly. You know, gotta have a lot of non-player characters to, to help move the, uh, the scenario along and it'll be all good.
All right. Well, that is it for news. Moving over to the Slack message of the week. A big thanks to Andre Gaeta, who's been our sponsor of this segment for well over a year now. Um, Andre, thanks for what you do.
Uh, the winner this week is Travis Shack, and Travis is a winner in multiple ways. Exactly. He posted us a message earlier this week saying that his daughter was actually, you know, hadn't been seen since the storm hit, and she was up in the mountains. So the first message was, my daughter hasn't been seen. Can you guys put out the word?
And the second message a little while later was that she was found safe, safe and sound. Yeah. Great news. So happy for that. I thought it was cool to see that there was— there were a number of people on the Slack channel that once Travis posted that.
It was, oh, hey, I'm going to, you know, put the word out to my community. I'm going to, you know, talk to these people. Lots of community support for helping to try and find Travis's daughter. So congratulations on your daughter being safe and sound. And of course, now, now congratulations for getting a piece of swag from the Colorado Equal Security Store.
Yes, exactly. All right. Let's move on to events.
Let's go ahead and first talk about some events that are a little bit off in the future. The Rocky Mountain Information Security Conference. Yeah. And actually, you know what? Even before we get to that, let's talk about an event in the past.
Okay. Talk to me about it. So, uh, SnowFrock was this week. Was it? Did it, did it happen?
I know there was a big storm. It, it did, you know, and, uh, I was able to attend for a good portion of it. You know, the headliner and keynote for SnowFrock was Troy Hunt. Mm-hmm. Um, of Have I Been Pwned fame.
Yeah. And I, I think it was a little bit comical. The, the blizzard disrupted his travel. He didn't get in until he was supposed to talk in the morning on Thursday. Didn't get in until the afternoon.
I think he ended up doing his keynote between 5 and 6 PM on Thursday after the show was basically supposed to be over. After it was supposed to be over. But he did come and talk and it sounded like it was a good presentation. Well, that's awesome. That is always a great show.
It's a bummer that the snow disrupted the schedule quite a bit from what I hear, but awesome that the organizers were able to pivot and make it work and, and have some success there. So back to what we were originally going to talk about. Rocky Mountain. Last week we talked about the first keynote. Yep.
So what's our second keynote? Second keynote Wednesday morning, uh, Kim Zetter. Uh, she is an author and she is the author of Countdown to Zero Days. So, uh, that is a book about Stuxnet. Yeah.
Um, chronicling Stuxnet and, uh, all that sort of thing. So she is going to come in and talk to us, um, about some of the things that, uh, that she has researched. So Stuxnet is, you know, I'm sure she'll She'll give us lots more insight, but it's unique in so many ways. It's the first time we really saw weaponized state-backed malware, right? Really targeted, really highly customized, really cool stuff.
I'm looking forward to hearing what she has to say there. Yeah, it should be good. Looking forward to it. So we do want to remind you, we have a calendar of events on the website. You can go out and see all the events coming out, you know, well into the future, all the way to the end of the year.
But we're going to go over the events over the next 2 weeks here, first of all. So first, on the 19th, CSA is having their March meeting. On the 20th, DENSEC is doing their March kind of meetup. That's going to be at Wally's Wisconsin Tavern, which I believe is actually physically connected to Reinhaus. Yes, I believe so as well.
Also on the 20th, SecureSet is doing a Hacking 101 Python in Cybersecurity. Highly recommend if you don't know how to— if you don't know Python, this is a really good opportunity. Highly recommend you guys take it. Take a good a chance to go to that one. On the 21st, ISC² Denver is doing their March meeting, um, Who Is Your Hacker and Why Does It Matter?
Oh, I don't know who my hacker is, and maybe I should go check that out. Like, it might matter. Um, also on the 21st, ISACA Denver is doing their March chapter meeting. On the 21st, yet another event, SecureSet is doing a cybersecurity career conversation with Jason Zaffuto. On pen testing.
On the 26th, SecureSet is doing a women-only beginner's intro to capture the flag. Also on the 26th, the GDPR meetup is getting together to talk about, uh, it's an in-person gathering to talk about GDPR and privacy. On the 27th, the ISC² Pikes Peak chapter is doing their March chapter meeting. On the 28th, ISC² Colorado Springs is doing their 6th annual ISSC Colorado Springs Cyber Focus Day. We've talked about this the last couple of years.
This is not quite their biggest event of the year, but it's kind of their, their second biggest event of the year. Yep, yep, definitely. So it's a full-day event, lots of good educational stuff. You guys should try and make it down there if you're in the area. On the 29th, uh, there are office hours with Davis, Graham, and Stubbs.
Yeah, and that's it actually for the next 2 weeks. Um, as we move over to jobs, um, I have one opening right now that I can— that's posted. We have a junior, uh, product security engineer at Ping Identity. We're also right in the process of getting a Product Security Lead Engineer posted. So this would be a team lead, someone who's going to be really managing a few other folks.
Reach out to me if you're interested in either of those and I'll get you hooked up. Carbon Black is hiring a SOC Manager. I know Carbon Black has been hiring like crazy, so good to see more stuff there. Centura Health is hiring a Security Engineer Senior. They kind of slipped the senior at the end here, just a little change of pace.
Yeah. Coalfire is looking for a Business Operations Coordinator. CenturyLink is hiring a lead security engineer focused on penetration testing. Deloitte is looking for a cyber infrastructure engineer for security compliance. Panasonic Automotive, which is interesting to me.
Panasonic, a stereo company. Automotive, I didn't know they— I don't know what that means. They're making stereos for cars? I feel like Panasonic Automotive was involved with some of those smart road initiatives that we talked about in the past. Well, they are Currently hiring an IT security specialist.
Ball Metal Pack is looking for an IT intern in security and risk. So I actually was so curious at the name of the company, Ball Metal Pack. I did a little bit of Googling to figure this out. It is— it was formerly part of Ball Corp. So the company that makes all the cans for, you know, Coors and everything.
But what I can't tell is it— is it just a section that they spun off or did they actually rename Ball? I don't think they renamed Ball Corp. So I'm not sure exactly what the relationship is. Got it. But they're hiring a security intern.
Spectrum is also hiring a summer intern, a security engineer. Denver Community Credit Union is hiring an IT manager who is going to be responsible for a lot of security stuff there. And Cisco Talos is looking for a senior vulnerability researcher. All right. Well, that takes us to the end of our newscast.
Alex, this week's feature interview is with Chris Betz. Chris is the new chief security officer at CenturyLink. He's been here in town for about six months. We got together at RSA conference. You'll hear in the audio there's a little bit of background noise because we're actually in one of those meeting rooms in a booth on the floor.
Gotcha. But I thought the audio was fine, and if you guys disagree, then let me know, and maybe we'll re-record a new one with him. I'm sure we will in the future, whether people say it's good or not. Awesome. All right.
Well, that's it for this week. We'll look forward to talking to you again next week. Thanks, Robb. This is Mike Benjamin, a big fan. Colorado security.
This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is Robb, and I am sitting with a new guest today, Chris Betz. Chris, you are the, the new Chief Security Officer at CenturyLink. Like I said, I say new because I've talked with, with Dave Mahon in the past, and I knew Dale Drew on the show from other stuff as well. So you're newer than they were there, right?
But it's been what, like 6 months? Something like that? Nearly, yeah. 5 and a half, 6, something like that. Long enough that I have fewer excuses now.
So if people hear background noise, we are sitting in the booth for CenturyLink at RSA conference right now, so there might be some background noise, and sorry about that. With that, I like to start off by learning a little bit about your passions And it sounds like one of your passions is making your own beer. So my first question for you, Chris, is can you tell me what's the favorite beer you've ever made? Oh gosh, I think my favorite beer was a clone of Sam Adams Noble Hops. It was a little tweak, but I really— when I found Sam Adams Noble Hops, gosh, it hasn't been out for probably the better part of a decade, but it was one of their seasonal ones that they added in at one point.
Um, I just really like the flavor, and so I, I went out and— so you drank the Sam Adams and you said, I've got to figure out how to make this? Exactly. Is this like a— is this a hoppy IPA type? Is that what that is? It was, it was a— yeah, it was an IPA, um, but it wasn't super hoppy like a lot of the, the modern American IPAs.
Um, so it was, uh— and then of course, I don't think it was unfiltered, but mine certainly was. I didn't bother to filter. Um, so, but it was, uh— it used a bunch of, uh, hops, mostly out of Europe that were more traditional hops and just had a really nice balance. It was a just super drinkable beer. In fact, now that I've moved out to Colorado, I got to get my kit set back up so I can make another batch.
So the— we've had another guy I've had on the show before, John Everson, who's now the CISO for Affinity. He was previously the CISO for Dish Networks. He's also a beer brewer, so I could help you guys get together and share your Curator tips. I have drank some of his beers and they're quite good, so, but I don't know how to make them, so I don't have a lot of insights there. I'm still unpacking, so my kit's all put away and I need to update the house and do other stuff to get it really going.
So it's nice to know there's other people in the area. Are there, are there some beers that are more difficult to brew, or is it all just, hey, there's a recipe and it's all easy either way, or what? I find lagers are more difficult because So ales you can typically ferment at room temperature, etc. Lagers you need to ferment at lower temperatures. So when I do lagers, I tend to do them during the winter so that you can take advantage of the outside.
But 2 different kinds of yeast. So when you lager, you have to use a lower, lower temperature to do it. So that to me is the more complicated side. But so the easier to drink is the more difficult to make. Yeah, pretty much.
I made that up or not? All right. Well, I'd love to get some— to know your background. So starting off, where are you from? So I grew up in Massachusetts.
Okay. Joined the Air Force and spent a couple years in Colorado Springs, which is how I knew about Colorado. From the Air Force? Is that right? Yep.
So I was in Colorado Springs for 4 years and then went down to Texas, then out to Maryland, got out of the Air Force, got into the government, spent about a decade there. This is the Air Force where you got into security or where I got into security? Yeah. So when I was going to school in Colorado, I got into the Academy, Air Force Academy. Okay.
I did some independent study work with the Air Force Information Warfare Center because I knew I had this real big interest. I mean, heck, I had an interest for security back when I was in high school. I was tearing apart malware and that kind of stuff. You were doing that in high school? Yeah.
I didn't say I was doing it well. Well, I'm not saying none of the companies on the floor are doing it very well either, so there's that. It's hard to do, but yeah, I dabbled in it. It was more curiosity of figuring out how to do it than actually doing it well. Yeah.
So when I got to the Academy, I knew that there was a— there were— there had to be people who were doing this work full-time, and so I wanted to keep on figuring it out. And I was fortunate enough to get independent study work with the Air Force Information Warfare Center, so I got to spend some time working with them. Yeah. And then— So how did you go from a guy who's, you know, in your room as a kid learning how to tear apart malware to getting the formal education? What did that look like?
Did the Air Force give you some education to take you where you wanted to go, or was it still self-study, or how'd that work? Like most folks in security, even today, a lot of it's self-study.
I started off as a EE major and realized that with a diff EQ, it was not my forte. Memorization was not as strong as it could have been. So I went computer science, was the right choice to begin with. I should have just been there. And there were a few instructors who really helped me take that passion, and then I was able to leverage some relationships and learn from folks.
In fact, one of my friends today was somebody who was a lieutenant at the Air Force Information Warfare Center in the 92nd Information Warfare Aggressor Squadron. They were doing red teaming for the Air Force at that point in time. And so he was a lieutenant, he helped mentor me a little bit as a cadet, and yeah, I just was texting with him last night, you know, 20 20-plus years later. So that's neat. It's a lot of fun.
So you, you were in the Air Force. Did you— were you assigned to a cyber squad, or was this kind of like a side thing in addition as a part of your service? I got really lucky. My first assignment out, I did certification accreditation, which is not technical security, but it actually— I think it was better for me in learning anyway how to talk to senior leaders and talk to people about security. Yeah.
Were not technical. And so I lucked out. My first job was in a security-related field. And then I caught somebody's attention and got pulled up to NSA for about a decade, both in and out of uniform. And so it got pulled up to NSA, correct?
What does that mean exactly? There's a lot of things NSA does. I'm curious what you're allowed to talk about. So the Air Force assignment process is normally very— well, one, it's opaque, but two, it's very planful. And I got a phone call and I ended up being asked for a resume from it, which is something you rarely do in the Air Force, put together a resume.
And based on that, there was somebody who specifically went and talked to the personnel center about me getting an assignment up there. So it was kind of right place, right time, bumped into the right people. I just just really lucked into an awesome job up there. Yeah. So I got to do cyberspace operations, got to be hands-on keyboard kind of operator, and then did everything from development to analysis to leading development organizations and leading analysis organizations.
Yeah, you had your time there with, with NSA for a decade and going up from hands-on to actually leading teams. What was, what was the last thing you were doing there at the end of your time at NSA? So I was I was the deputy of an analysis organization looking at different kinds of cyber activity and helping plan cyber activity on our behalf. So spent a lot of time just leading large organization and learning what that means. Learning how to lead cyber starts folks is an important skill set, and it's also a very different skill set than I think from leading any other kind of folks.
There's challenges in all parts of technology, there's challenges in leadership of technology, but the folks that get attracted to cybersecurity and to security work in general are a special kind of person, and making sure that you understand how they work, how they think, is incredibly important, making sure that you have a vision for where the organization goes that resonates with security folks is terribly important. So I got a chance to lead some of the— in fact, throughout my career, I've had a chance to lead some of the very, very best, and it's been a lot of fun. So I want to dive in a little bit more into what it takes to be good at leading cybersecurity professionals. You talked about kind of showing them where we're going, setting a vision. For it.
You talked a little bit about understanding how they work. Maybe we could dive into both of those, and maybe there's something else we're missing as well, but how do you set a vision? What does that look like tactically? You have a vision in your head. How do you communicate that?
How do you get people on board with it?
I want to focus a little— I'm going to take this a little bit in a slightly different direction in terms of what's different about in my opinion, about cyber and cyber folks. The folks that are doing security really, really well have a deep appreciation for a field where not only is the technology hard, not only are we continuing to adapt and change, but we've got adversaries that are doing the same thing. I mean, look, we're at RSA, but if you go to any tech trade show, you're going to have tons of people around, and even what's happening here, most people are talking about their products. And IT, technology in general, it's incredibly hard to get a product to work and work correctly, never mind having somebody spend all day long trying to abuse and attack your product. And so the people who can think both about building and advancing security while at the same time have a close enough mindset to the attackers, they can understand how to break things and how to think around them.
It really is a rare and unique talent.
And so what I've found is that being a leader in that field means that you have to not only understand technology and how technology goes together, but you have to understand that mindset, and more importantly, you have to value it, and even more importantly than that, Generally speaking, you have to— in this field, we tend to expect people to have been there or to be able to speak the language and walk the walk, not just talk the talk. And that's one of the things that I see is a big difference between, between the leaders. It comes down to credibility. And so having had some of those experiences and having had leaders that had varying degrees of credibility, that's part of what brought me into built my passion for being a cybersecurity leader and taking on leadership of these organizations. And so, you know, to your point, being able to set a vision and set a direction, I mean, heck, you're a CISO, you know that it's challenging to make something both clear and simple as well as very thoughtful and nuanced.
And yet that's what our focus expect of us, and for good reason. We have to be thoughtful enough to be able to encompass the breadth and the complexity of the space, but a leader who can't communicate clearly and straightforward and ideally make the complex, if not simple, as simple as possible, it's hard to get everybody on the same page and read from the same sheet of music. They can't remember 10 bullet points, can they? Too much. Nobody can.
What's the rule of thumb for a presentation? In 30 minutes, people are going to remember at most 3 points, more likely 2. The first thing you say and the last thing you say, maybe. And so how do you make a vision that easy to consume but that nuanced? Because, you know, we've got folks that are incredibly good at their jobs and love their work and want to go and do their work.
They want to see that fit into a larger vision, but they don't want to spend a ton of time unpacking your vision and figuring out how it works together. So it really does have to be clear, and I think that's one of the most challenging things, especially when you're leading change in an organization, is figuring out how to make that clear, especially when it's very different from how the organization's thought about things in the past. Awesome. Well, let's fast forward a little bit. You left NSA.
Why did you leave the NSA, I guess? Start there. Family reasons. We were working on having a family and my wife stopped work for a while, and so 2 incomes to one, the question was how do we make that work? And so right at that point, I had a friend heading up to CVS to be their first CISO ever, and he said, hey, Chris, come on up, come join me, come help me put together the security team at CBS.
And I said, heck, that's a great opportunity. Yeah, why not? So you went to CBS, and what was your role there? New York City. So yeah, I was a VP of information security.
So over time, I ended up building out and helping build out the cybersecurity team there. Yeah, the, you know, we built everything from policy to app Sec to threat intelligence practices to beefing up our response practices. Kind of when we got there, there was a very small team, and so we built everything tooth and nail. And so that was a ton of fun, great time, and really fun working in New York City. It's a totally different experience.
When I think of CBS, you know, I think of a network that delivers TV programs, And then I'm thinking, okay, there's a lot of newscasts that are a part of that, probably research that goes into that. And I wonder if I'm— what are the big things that you're responsible for securing in CBS's security team? So CBS has everything from large properties to television, films, radio stations, TV stations, 60 Minutes, Letterman, Simon Schuster Books, CNET, ZDNet. It's a lot of stuff. There's a ton of properties there, sports.
And so there's, there's a very, very broad business. It was really neat getting into— I mean, look, I've spent my time in military and government. Yeah, media companies are completely different. Yeah, totally right. But it was a lot of fun, a lot of challenge with diversity.
I especially enjoyed, as you brought up the news, working with 60 Minutes and working with the news and thinking about how securing and protecting those reporters really makes a difference to our country. Yeah. And how tricky that is with some of the things that they have to go report on, especially 60 Minutes, as you can imagine, has a unique set of risks. Yeah. As they get really deep into some really, really, really interesting stories.
So how long were you there at CBS? There, just under 2 years. At that point, I had a friend from Microsoft knock on the door and say, hey, we've got this job that doesn't open up very often, and we think you could be great, good for it. And so it was the head of the Microsoft Security Response Center. And so they're the folks that are responsible for Patch Tuesday, handling all the vulnerabilities that come in.
And so this said, hey, we'd like you to come out and take over this role. And as much fun as I was having at CBS, that's one of those rare jobs in cybersecurity where you can have massive impact and be part of a really cool team that I knew some of the people out there. And so unfortunately, I had to leave CBS and went out to Microsoft. Very different type of a job, you know, from running an internal security program. And really, I mean, Moving from NSA to CBS is pretty different as well, right?
Like, where you're probably engaging in offensive security and really like threat analysis at NSA, to building a security program at CBS, to, you know, at Microsoft, what sounds more like, I guess, more similar to NSA, where you're looking at what bad things are going on, but then how do you fix that within your own products? Is that right? Right. So there's a ton of engineering work that needed to be done. The group leads cyber response, or response for all cyber incidents for the company.
So there's a bunch of cross-company work. There was some work with IT, but there's also, you know, I think within my first few days there, there was an Internet Explorer zero-day in the wild. How do you handle that? And when you've got impact literally globally, It's just, it's massive responsibility. Yeah.
And over time we ended up building out the SOC that brought multiple different teams together, ran the SOC for Azure as well as a bunch of the production systems, all those kinds of things. And so it really turned into a killer job. Yeah. Still got some incredible, incredible people out there, some friends that I stay close to. So did you move from New York to Redmond?
For that then? New York to Redmond, yep. One of the lessons I learned pretty early is that to be an effective senior leader at most companies, you really have to be at the headquarters for better or for worse. So how long did you stay there in that role? I was there for about 4 years.
And at that point in time, Apple had been hunting me for quite a while, and we'd been in a long conversation. And so I went down to Apple to lead security for Apple products, as well as some work on engineering some parts of the operating system and a bunch of other work related to apps and security for apps, etc. So which one's more secure with their external conversations, the NSA or Apple?
You may have noticed that my conversation The pressure on Apple got a lot bigger after Microsoft. Apple is certainly very conscious about being secure about its communications. But Apple does an incredible job of surprising and delighting me, our customers. And so I fully appreciate the degree of secrecy and how that leads to an incredible user experience, as we're both sitting here with our Apple phones and the Mac. Yeah, we're recording this on a Macintosh right now.
Yeah, for sure. And you were there for how long? Were you at Apple? I was at Apple for a couple years. Yeah, but California is awesome.
It wasn't for me. It wasn't for my family. And so we, my wife and I, realized that we were looking to put down roots with our kids. Yeah, and so we were looking for something that was either Colorado or the East Coast. Yeah, literally that, because she'd spent a little time in Colorado, and after 4 years here, I loved Colorado.
So I was, uh, my family's on the East Coast, so it wasn't one or the other. And then, and so CenturyLink came about that time. CenturyLink came up around that time, and, um, it's an incredible job. I mean, when you look at the size of the network CenturyLink has just the pure scale. I mean, second largest provider to enterprises in the world.
I mean, we've just got— I don't even remember how many miles of backbone fiber network. It's just an enormous network. We've got one of the largest IP spaces in the world, and so it's a great place to be part of using that in order to help secure customers. That's also a lot of responsibility. Responsibility to secure it.
And CenturyLink did something rare. There aren't many jobs that I know of in technology, and I really, I'm intentionally calling CenturyLink technology because while it is a communications provider, we are rapidly on the evolution. I fully expect in the next 5 years, it's going to be hard to differentiate between a telecommunications provider at a tech company. I mean, the evolution's happening that fast.
And there aren't many places where a CSO role gets to be responsible for not just the network security, not just the physical security, but also for working on engineering and operations for security products. Gets to run a massive threat intelligence lab, Black Lotus Labs, that focuses on focuses on taking advantage of that network in order to understand what's happening for attackers. And then the best part about being a network provider is I don't just have to look and tell people, I can actually act. And so being able to take that action based on our threat intelligence and based on our partners, you know, 40 or more times a month to knock off command and control networks, it's just, that's a great opportunity. This is, I can tell you, in some ways it feels like I've been here for years, in other ways, man, do I still have a lot to learn, because there is a ton going on and just the opportunity is immense.
Yeah, so what did they bring you in to do? Because you just said a lot of different things, right? There's cool features of the job, but someone probably had said, hey, Chris, when you get here, here's what I want you to accomplish. Could you talk at all about what that is? Sure.
So I come from a school of thought where I think that, I firmly believe actually, that good security should be easy to use. And I think that's true both for our users within the corporation as well as for our customers. And so I talked a little bit about how tech is working to transform to be much more technology looking and feeling, and it's going to have to. And so I think I was brought in, I was asked to do a couple things. One, help lead the transformation of security.
Two, help think about how the user experience in terms of the company can be changed and revamped. How do we make it easy for customers, or easy for our users inside the company to do security? How do we make How do we have security be part of how we engineer our products rather than just an overlay? And then lastly, but certainly not least, how do we help evolve our suite of security products to help make that easier for our customers to use so that, you know, as a network provider, as a communications provider, I wonder sometimes why our customers should have to worry about attacks coming in from the outside. We should be doing, and there's a lot of things that we can do from the network position.
We've got a lot of expertise. How do I make that so easy that the customers just go, yeah, that makes sense. We're just going to use CenturyLink for that. And we're going to worry about the threats within the company rather than working on things outside. So I think it's a combination of things, but a lot of it's about transformation, and a lot of it's about helping move the company forward, both from how we work from an internal perspective, security and having security in our products as well as having security products.
Yeah, so when I hear you talking, you know, you think about the traditional CISO role in most organizations is pretty heavily focused on securing the internal of that organization, right? Of making sure that the emails that come into the workforce are secure. And what I hear you really talking a lot about is that the customer-facing stuff and really what is CenturyLink providing to your customers and as you guys, you know, look to expand into being more of a security service provider. Is that kind of— obviously I believe you're responsible for both, but like as you're thinking, like you're really focused on that transformation on the external-facing?
I like the question. I think that's not entirely accurate in So I left you with a mistaken impression.
I am desperately concerned about our internal networks, making sure that email is secure. That's where I start talking about the user experience inside the company. I think that we've created far too much friction. I think it's easy for security people to create far too much friction. And so how do I create a better security experience?
That doesn't mean less security. It can't mean less security. In fact, we have to increase our security. Security. I've got a handful of key initiatives, about a dozen that I'm tracking right now.
All of them markedly increase security. Many of them help make the security easier for our customers. I'm sorry, I think of internal users as our customers as well. That could be part of the— I know personally, as the CISO for someone who also offers, I have the same exact dynamic, and I know that internally, when I'm talking to other executives, they are much more interested in hearing about how I'm going to impact our customers and how I'm going to help, you know, Ping be successful with customers. So that's the conversation I'm much more likely to have with them, even though internally I probably spend 80-90% of my time really on the internal focus and embedding security into all of our processes.
And you have to. And so I think the The way I try to think about that is, one, you've got to secure the enterprise. Two, there should be security in all of our processes, in all of our products, because we offer a lot of things that are not security products. And that's why I said last but not least is our security products. So it really is a blend across enterprise security, product security, and security products, for lack of a better term.
That's why I said it's a bit of a unique job. You're in the same space. It's a lot of fun. It's amazing. And it is, I think you also pointed out, it's challenging about getting pulled in multiple different directions.
Though, you know, I've been really pleasantly surprised by CenturyLink about how interested the folks are on making sure that our products have security built in from day one. Yeah, that's great. And that they are secure. And so that's actually the most frequent comment conversation I have, and heck, daily, with folks across the company are about making sure that there's security in our products, shortly followed thereafter by the health of our security products. So I'm going to change topics a little bit.
You moved from New York City to Redmond to be at the headquarters. You moved from Redmond to Cupertino or whatever. To be at Apple's headquarters, and then you didn't move to Louisiana to be at CenturyLink's headquarters. Are you here to announce today that the CenturyLink headquarters have moved to Denver?
That is not my decision. I have not heard any conversation on that.
It's cool that there is a lot of tech, a lot of CenturyLink technology in Denver, and so while not at the headquarters, it's there is, there's enough muscle here that I was able to find the city that I love, the state that I love. Louisiana is a lot of fun, but I don't think I could have talked my wife to moving there. Colorado was an easy sell. It's a good place to take her to visit though, right? On one of those work trips, go get her to go see the place.
Some of my best friends are, well, about 2 hours south of Monroe, Louisiana. Thibodeau. Yeah, but so we've certainly got friends there. We do go down periodically. So when you're looking, you know, we have a lot of people listening who are either, you know, career changers or looking to get into security, people who are students right now.
As you're looking to hire various positions across your security program, what kind of skill sets are you looking for? What should these people be getting prepared for if they really want to work at CenturyLink? It's I think it's going to be a rare person that I hire that can't code or script or do something else to work themselves out of work. One of the big things that we're focused on this year is being able to ensure that people are not stuck in a job that they can't make better. So one of the most frequent conversations I have with people is, What are you doing so that a week, a month from now, your job's better than it's ever been?
Some ways that's, they're doing things that are more fun, and for security folks, that normally equates to doing something that's not rote, mundane, I've done before. And so wherever I can speed or accelerate, that's great. What I don't want to do is be in the business of putting in a bunch of requirements for some other engineering group to go and build a solution to make people's jobs better. There are times when you have to do that, but the more I can equip somebody to make their own job better— there's nobody who understands that job better than the person who's doing it. And so I think being able to at least write Python, being able to at least script or code yourself out of a problem and know how to automate a system is a crucial skill.
Understanding how to work that into a larger development environment, a larger development system, while not required for all jobs, required for many jobs, I think is crucially important. And so, while security to some degree is a mindset and a skill set, I think coding is one of those fundamental skills. The other things are more soft skills. I need people who can be collaborative, who can form coalitions, who can build, who can say, hey, we need to go this direction. I'm a strong believer that managers are not the only leaders.
I expect all my managers to be leaders, but I also expect my individual contributors to be leaders, especially my senior ICs. I'm going to hold them accountable to be leaders, and if they're not leaders, they don't have a role as a senior IC. I expect that happens, and the more senior you become, the more of a leader I expect you to be. And so I think leadership skills, communication skills, skills are crucially important. And lastly, we run in a business where you have to fail fast, which means one, you have to be able to own, hey, I made a mistake, made the wrong call here.
That's okay. Identify it, fail fast, move on, work with your leadership on that. So integrity remains a fundamental premise that doesn't go away. People who try to shift the blame aren't going to last very long. Along essentially.
Yeah, that's great. What kind of guidance would you have for security leaders at other organizations who are, you know, what are you seeing as you have a really nice perspective across lots of organizations for things that they could be doing better that we should improve either in our practices or how we present ourselves or any guidance that you have for security leaders out there? I think this has been said probably 100 100 times, but I'll be one of the people who says it again. I don't think you can do security without IT being successful. And so one of the areas that I'm very focused on is how do I help our IT, our development organizations be more successful, because without a firm foundation in technology and in development, all the security work we're doing just is sitting on a pile of sand and will fall down.
And so I think understanding the challenges of IT, understanding how to do development, how to build solutions, and then being part of those teams becoming really, really capable and competent, and making sure that security is part of their processes rather than something separate, really makes a huge difference. So, you know, it's something that I think many of us have said before, but it's being that partner to technology, understanding their business and being able to walk, walk a mile in their shoes, that makes a massive, massive difference. Awesome. Chris, thanks so much for your time. This has been a lot of fun, and hopefully we'll catch up with you again soon and hear what progress you've made after you've been here a year or two and, and really put your stamp on the company.
Sounds great. Thanks a lot.
Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.