All episodes

Rock Lambros, CEO at Rock Cyber

Apple Podcasts Spotify SoundCloud

In this episode:

Rock Lambros, CEO & Founder at Rock Cyber is our feature guest this week. News from: Checkr, NREL, Coalfire, Ping Identity, ThreatX, LogRhythm, Intelisecure and a lot more!

From Cow Town to Tech Town

I like that headline. We are a tech town now! Colorado is the 5th most innovative state! Checkr might be bringing us over 1400 jobs. NREL brings us the dough. Fort Collins Loveland Water District and South Fort Collins Sanitation District got ransomed. DPS has a privacy officer! Coalfire releases a password cracking tool. Ping wins API security awards. ThreatX is a top 25 security company. Blogs from LogRhythm and Intelisecure.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13219 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 110 for the week of March 25th, 2019. This is Robb Reck, the CISO at Ping Identity.

And this is Misha Danisow, the CISO at InteliSecure. Misha's filling in for Alex this week. Alex is, uh, off gallivanting, enjoying spring break. Um, we're gonna go ahead and jump into the news, but before we do, I have a little bit of housekeeping. Uh, we have a Slack channel.

We're well over 800 folks from the community who get together and talk about security in the Colorado area. If you want to get together, there's lots of new channels created. You can create your own channel to talk about whatever it is you're interested in chatting, we'd love to have you join. The link to get on the Slack channel is on the front page of colorado-security.com. We also have a mailing list.

While you're there, you can sign up to have the show notes for each week's episode sent directly into your inbox. If I could figure out how to make it work this week, it'll be going. Usually Alex does that part. Next, we ask if you like the show, we'd love it if you'd rate us on your favorite podcast subscription application. Let us know if there's anything we can do better, and of course we would love to get better.

If you like the show, tell a friend. Let one of your friends know about it, a colleague, a coworker, someone you meet on the street, whoever it is, let them know about the show. Hopefully we can get some new listeners out of that. So Robb, speaking of your favorite podcast subscription service, my car comes with Stitcher and I can't get this podcast on Stitcher. So let's— can we figure out how to get that on Stitcher?

So interesting, Stitcher is one we looked at, Alex and I looked at, that actually, in order for them to run your stuff, they get— they actually get the intellectual property for your podcast. Yeah, we were looking at that, and, you know, not like we do a lot with it, but it just seemed a little weird to us the way that that works. And it's all— it's all really monetized as well. I think we actually would get paid for doing through Stitcher, but we— the whole thing seemed a little bit weird. And, you know, as amateur, you know, spending 15 minutes a week trying to figure these things out, it's a little hard to go after that one.

Well, fair enough. I think then I'm just gonna have to figure out how to hack the system in my car and then put in the Google Podcasts. Maybe we'll look at it again though. Finally, if you really love the show and you want to help keep us going, we'd love it if you'd support us on Patreon.

This is how basically you can help financially support what we do. All the money you give goes directly back to the community either through the fees of things like hosting and bandwidth and also back out to swag for the community when we can. None of this money goes to Alex's or I's Well, all right, with that, let's go ahead and jump over into the news. The first story of the week is, from Cowtown to Tech Town, Denver's startup scene is flourishing. I spent some time taking a look at this article.

It's really fascinating. What I like about this article is it goes through and identifies the things that are unique to Denver as a town that's attracting the kind of talent that we have here. And it's not just about the fact that, let's say, you know, rent is cheap and people are moving in from California, that sort of thing. It talks about really the community and the way that it's a very collaborative community, and it focuses on 4 companies within the Denver community that have started up here, and it's a really fascinating article and makes a great point about the environment that you get here within Denver. Yeah, I had never heard of any of the 4 companies that they focused on.

They certainly have a diverse set of technologies that they focus on, so there was, is it GeoSpiza? Which is a public safety company that looked like it was basically helping people make decisions around public safety. Yeah, it's really fascinating. What they're doing is they're gathering lots of data from various different sources. So if there is a major incident within, let's say, like a natural disaster or something like that within a community, it will give them, the first responders, the ability to determine where their resources are most needed.

Yeah, pretty cool. The next company they talked about was Venxt, which is basically like a Match.com, or I guess that's not right. Indeed.com for marijuana jobs. Yeah, so it's in the green industry without producing any of the green, which is amazing. So they're able to take advantage of all that growth without having to have any of the exposure, right?

Right, and I guess, you know, because they're a, you know, regular non-marijuana business, they actually get to have legit accounting and bank accounts, which is amazing. There was, I'm not sure if I'm gonna say this right, there's, is it Kineshu? It looks like they do like a photo sharing app. But, you know, allows you to create albums and another, you know, I don't know why we need another photo sharing app, but theirs is unique and it's growing. Well, what's unique about it is not just photo sharing, it's actually audio.

So imagine that the story that they tell within the article is about how you may have people within your family, you know, grandparents, great-grandparents, they have stories to tell. And, you know, when they pass away, it's as if this whole section of your history goes with them and the library just closes down. So they give you the ability to get the stories out of them, put them online so they can be shared with generations to generations. Yeah, that's awesome, and it does add something certainly unique to just yet another place to create an online photo album. The final company that they talked through was Repurpose Bowties, which I know you've read about a little bit.

You want to explain what these guys are doing? So Repurpose Bowties is also fascinating. What they end up doing is they work— they create bowties and other textiles by repurposing the textiles from army uniforms or military uniforms. So it's a great way of of making people feel really good about the products that they're wearing. What's really fascinating about it too is, to me, they're also creating this job market within, and they're creating an opportunity for people who work at home who just happen to have a sewing machine or know how to sew, and it gives them an opportunity to actually get a living wage doing something they can do right out of their house very easily.

So it's kind of a gig economy for sewing from your house? It is, and apparently, you know, some of their bow ties are actually featured, like people wore them at the Academy Awards. Right, that's pretty awesome. It's good marketing, right? I'll also mention that there's been at least 22 tech firms that have either moved their headquarters or opened a field office in Colorado between July of 2017 and June of 2018.

We see about 23% growth in terms of tech talent in that time. That's adding about 19,000 new workers. So a lot of growth we've seen, and it doesn't look like it's going to stop anytime soon. Absolutely. And it's great for the town.

It's great for the community. And it's really great for the culture that we're developing here in Denver. Awesome. Next story is from WalletHub that Colorado is number 5 on the list of most innovative states. Do you see this one?

I did see that one. It's a short article. It doesn't go into a whole lot of detail, but it's definitely fascinating. I'd love to understand where it was. It also shows what the top 5 are, and I'm very pleased to know that I've lived in 4 of those places.

Oh, really? So number 1 was Massachusetts, and then Washington, and then District of Columbia. Maryland, and then Colorado. We— so we beat California. The criteria they used here is the share of STEM professionals, projected STEM job demand by 2020, 8th grade math and science performance, which we were number 1 in, by the way.

Number 1, taking it home. Share of science and engineering graduates aged 25+, share of technology companies, R&D spending per capita, and venture capital funding per capita. Kind of coming in at the bottom of the list, number 51, because remember, we had District of Columbia as a part of this too, was Mississippi, Louisiana, West Virginia, Iowa, and Tennessee there. I'm surprised about Iowa considering, you know, they have some pretty good universities and Des Moines, Des Moines is a pretty good tech town as well. It is.

But the state is certainly much bigger and a big agricultural state as well. So our next story is about a Bay Area firm, Checkr, that could bring more than 1,400 jobs to Colorado with its HQ2. I had never heard of Checkr. I had never heard of Checkr either. I think they do background checks.

They speed up background checks. Yep. And what's fascinating to me about it is that they're still telling the story about how a lot of these companies like Checkr, one of the things that attracted them to Denver was the fact that the cost of living was much, much lower. The cost of housing was lower. It's not been my experience.

Well, you didn't come from the Bay Area. That's true. If you move from San Francisco, it's still really cheap here. But there's, at the same time this week, there was an article that I read about how people are actually moving out of the Denver area because of the cost of living. Yeah, cost of living is going up.

Checkr, they're going to bring 1,472 jobs. The average wage for these jobs is $138,000. So that's, that's pretty high pay for average. Holy smokes.

Next, we talk about the economic impact of NREL. So the National Renewable Energy Lab, which is headquartered up in Boulder, has a pretty big economic impact. Title here says more than $1 billion, which is pretty significant. Yeah. So it's $1 billion nationwide.

But specifically, I was shocked to see this. They impact Colorado's economy at $748 million. That's a, that's a pretty significant chunk of our economy. Yeah. The study says that they employed about 1,700 full-time and part-time employees, and about 60% of those employees are involved in core research and development for NREL.

Who says, who says that there is no, no future in renewable energy? This is clearly showing us that's not the case. So lots of jobs coming in. Then we have a little bit of a sad story here with some jobs that are leaving. Oppenheimer Funds, which was just recently acquired by Invesco, is going to cut 850 jobs from their office in Centennial.

They had about 100— they have about 1,000 people here now. So, you know, you're talking about a massive cut across their organization here in town. Yeah, that'll be difficult, I think. But it would seem to me that there are, within this economy nowadays, the fact that we may be losing jobs in one sector, there are plenty of jobs available in other sectors. And I would imagine this is not going to be too difficult a thing for people who are being affected by that cut to go out and find other opportunities here.

Yeah, they'll find new jobs for sure. I know that their security office is there in Centennial. I don't know if those folks are impacted or not. I only know good things about what they're doing there. I think the bigger impact here is this is a company that's been around for a very long time and probably a lot of people with, you know, decades plus of tenure who, you know, might not be ready to find a new job.

So it'll be a, it'll be a little of a challenge and hopefully they have the support they need to be effective there. From a security standpoint, I'm sure that there are enough security companies here in town that are going to be salivating to get any of that security talent that comes out of Oppenheimer. Absolutely. Maybe I can— I don't know if those guys are losing their jobs or not. I don't want to assume they are.

You know, they're keeping 150 people there. That very well could include the entire security team. But if they need help, and hopefully we can, we can help them out. Next, there is a story about a cyber attacker demanding ransom from Colorado utility companies. This is one of the articles that I spent a great deal of time reading because I find it fascinating.

And when I think about the ability of people to actually be resilient to hackers, one of the big issues for me that I see a lot, and I think it's borne out within this article, is the idea of, well, what resources do you have? If I'm a hacker and I'm looking to actually make money, I'm going to target people where I believe that they're not getting the resources that they need within cybersecurity, so they're going to be much easier targets for me. And that makes sense, right? Your utility companies are probably at the top of that list. And these are not like— this is not like Xcel, right?

This is the Fort Collins Loveland Water District and the South Fort Collins Sanitation District. So not the big, the big famous utility companies. Not only not the big famous utility companies, but nothing that you would, you know, put on the top of your mind for people who even live here in Colorado. Right. So this happened on the morning of February 11th.

They came in and they were locked out. The The group said that they never considered paying the ransom, and they say that within about 3 weeks they unlocked the data. The first thing, you know, they were selling this as like, hey, we got through it. I'm like, 3 weeks without the data? Oh my gosh, how do you do business for 3 weeks without access to what I assume is mission-critical data?

Yeah, no, I think so. But what's fascinating is that it didn't affect all their data. There was, uh, it also didn't affect any privacy data, which I think is fascinating because a lot of their billing is actually done through a third party, uh, so it was not affected and they didn't need to send out notification to their customers. Yeah, they specifically typically say that, you know, third parties do all their PCI or their payment type information. You know, I thought there was a little bit of wiggle words on the, on the, you know, whether there was PII that was compromised here.

They say, uh, we have, you know, uh, I'm reading it right now, that we've looked 3 times and we don't believe that information was compromised. Uh, but to make absolutely sure that's the case, they're bringing in additional IT support to look through things a 4th time. Um, so I, you know, I Like I said, I like the word a 4th time. Yeah, they really want to reiterate the fact that they've done their due diligence. Yeah.

So anyway, uh, it sounds like these guys took the right approach. They're not, they're not just gonna, gonna pay a ransom and, and, you know, yet be a victim again shortly thereafter. But it sounds very painful. And hopefully, you know, they get into a place where this doesn't happen to them again in the future. Yeah, I think that that's really the challenge.

And I think this is the ongoing thing that we as cybersecurity professionals are struggling with on a regular basis, which is how do we get the funding that we need when we know that The resources just simply aren't there, and it's a matter of making that case and understanding that risk and balancing with the priorities of the organization. Unfortunately, it often takes events like this to open up people's minds and open up the wallet within the budget cycle. Exactly. So, Alex had added an article a week or so ago that I was a little surprised about, and it was called Chief Privacy Officers: The Unicorns of K-12 Education. So, when he added it, I had no idea why he did.

'Cause it's not from a Denver source. But as I looked into it, it got relevant here. So last month, a nonprofit called the Center for Democracy and Technology published a report arguing why all these schools need to have a chief privacy officer specifically. And then this article goes into saying that even though, I'm gonna get their exact wording here.

Shucks. They, you know, as they looked through all of the different districts across the country, they could not find a single example of a district anywhere that has a chief privacy officer. So, you know, there's this high recommendation to do it. There's no one actually doing it. They did come up with 2 examples of departments that have established leaders to be in charge of privacy.

And Denver actually is on that list, too. Good to know. So we have in Denver, Denver Public Schools appointed a new role called a student data privacy officer, and they filled it with a man named Brian Westerman. And it's his job to make sure that he's looking across all of the schools in their district and understanding how we're keeping data for students secure or private. I think nowadays also with the advent of GDPR and a lot of companies in the United States also looking at the various privacy laws and the potential for maybe a national privacy law, we're going to see a lot more pressure for organizations just in general, schools, all kinds of organizations to have somebody who's within that role because it's critical and it's a lot of work.

Yeah, it is a lot of work. There's also several regulations that are relevant to the schools with FERPA, COPPA, um, is it Colorado? I don't know what CIPA is, but there's also Colorado's— excuse me— Colorado's new privacy law that's relevant. So these people have a lot of work to do. The other example of a district that had a privacy leader is actually in and Baltimore.

So it's Denver and Baltimore as the two, the two who are leading the way on this.

All right. Next story is from Coalfire. Coalfire Labs has developed an open source password cracking tool. Yeah, I read a little bit about this article and to be perfectly honest, I wasn't sure that I fully understand what the, what the biggest benefit of this is going to be. So what was your take on that?

Yeah. So what I got different than, you know, there's other things out there. That do similar stuff. What they did that is unique, and I think probably worthwhile, is they've actually created it as something really simple for you to spin up in AWS. So you don't have to have a rig on site, you know.

And that is the hardest part about breaking hashes, is you need a lot of CPU. And having a rig that expensive, um, you know, just sitting there doing nothing most of the time is, is kind of a waste. So they made it really easy for you to spin up AWS instances with a lot of CPU on it and go after these things aggressively and then turn it right back off again. It's using Cognito, DynamicDB, and S3 as the components within AWS, try to make it as easy as possible to stand it up and run it. Now, as an open source tool though, is this going to, you know, make us more secure?

Is this going to make us less secure? Because it's also something that will be in the hands of people who are looking to, you know, crack your hashes. Yeah. I always, anytime you come up with something like this, right, it's always the question, is it going to be used for bad or for good? I think the argument for folks who release this kind of thing would be that Um, the bad guys are already doing this and the good guys are not.

So trying to make it easy for the good guys, something that we can actually use to defend about what the bad guys are doing. But I would be absolutely shocked if this doesn't get used by bad guys as well. Without a doubt. I get, you know, bad guys maybe don't want to pay for AWS bills, but they'll probably spin it up in somebody else's account and use it and rack it up against them, right? So hard to say.

Uh, next we have a press release from Ping Identity this week, uh, where We won a couple of new awards. Congratulations. Thank you. We won the— our API security award where we will like monitor your APIs, detect your APIs, and actually set up honeypot APIs. We won the 2019 Devies Award.

That's Devies, kind of like the Emmys except for developers, for best innovation in security and networking. And we also won gold for the best API management and security product in the— for the Information Security Product Guide Global Excellence Award. I think in this, in this market nowadays of a lot of development that's being done within the cybersecurity world, those winning those awards is really nothing to sneeze at. There's a lot of competition out there for people who are producing some pretty impressive new tools. So good on Ping Identity for, for staying on top of things.

The next one here that is another local company that won an honor, ThreatX was recognized as a 2019 top 25 cybersecurity company. I was diving into this And, and I, I couldn't figure out much about this list. I did finally get the list in front of me and there were companies I didn't know. So I'm not sure, there wasn't criteria shown for how they got it. Um, but you know, obviously we love to see the local companies recognized.

And, um, even though I don't know much about the list, it's not the Cybersecurity 500 that, you know, Route 9B has, it was, you know, notoriously on the top of for a number of years, but, uh, something that's, that's new. And, uh, of course love to see these guys, um, get recognized for doing something good. Yeah. ThreatX is a good company. They make a good product and it's great to see the, uh, the recognition getting out there.

Next, we have a blog from LogRhythm around exploring legitimate interest within the GDPR. So the GDPR is an interesting beast, and anyone who's doing business in the EU, you know, has to understand how this impacts how they do business. Is this something you guys have had to think about much? This is something we have to think about all the time. So one of the things about legitimate interest, it seems for a lot of people like, oh, this is the easy way out.

This is how I can actually tell people that hey, we have a legitimate interest, that's what we're gonna claim, and that's gonna be the reason for this processing, because you don't have to gather consent. Marketing people love the idea of legitimate interest. However, to actually really claim legitimate interest and not get yourself in trouble, you have to do a legitimate interest assessment, which will then go through and identify whether or not you can actually claim legitimate interest. And a lot of people aren't doing that, they're just writing down legitimate interest is what we want to do. And I think this is, as I was saying before, GDPR and managing, dealing with privacy and all the work that goes into privacy, you really have a lot of work to do.

And this is one of those things that I think people are skipping. Yeah, so I think they do a good job in this, in this LogRhythm blog talking about, you know, how to think about legitimate interest. And, and, you know, for those of you who don't even know what it is, it's probably worth a read. There's quite a bit of detail in there. And as we are going to have a lot of court cases to help show us exactly what's required, I think this will be defined better and better over the next couple of years.

Yes, thank God for the Googles and the Facebooks of the world who are showing us how difficult this is going to be for us smaller guys eventually. Last news story of the week is actually a blog from InteliSecure about evaluating penetration testing companies. Yeah, I think a lot of people don't realize that penetration testing is one of those things that InteliSecure does. We actually have a pretty significant part of our business is penetration testing, vulnerability assessments, application testing. We do a lot of that, and we do it actually very, very well.

It really came out of our organization in the United Kingdom. So a few years back, we acquired a company called Pentura and integrated them into what we do. And I think that when you— the whole purpose of the blog is really to help people when they're looking at penetration testing and evaluating, you know, what they're going to get out of a penetration company when they bring them on, to really objectively go through and identify the things that they really need. Make sure you're getting the right fit. The understanding what it is you're testing, understanding what you want to do with the results, understanding providing the right kind of information to the company and making sure the company can meet your requirements is absolutely key to having a successful penetration test program.

And there's some good details in there worth, worth reading through. All right, that takes us to the end of the news. We'll go ahead and do our Slack message of the week. Big thank you to Andre Gaeta. Andre is the, the one who sponsors this on his own.

We appreciate all your help, Andre. He's also the regional sales leader for Mimecast. So, you know, a little sales pitch for those guys that he, that, you know, he's been a great supporter of the community. Maybe you guys could support him and them. This week we are going to recognize Jen Wilson for her post in, I can't remember, I think Recommendations or Random, where she was talking about, basically she started a conversation around doing assessments as a part of recruiting.

And, you know, her perspective on it was, you know, frustrating as a recruiter to have these you know, gating assessments to get into the process. But I think it turned into a really interesting conversation around the relative merits of assessments versus interviews and, and, you know, job-like work, you know, during this, during the interview process, and, and how, you know, how reliable we think these things are versus how reliable they actually are. Turned into one of my favorite conversations of the week, so I wanted to recognize Jen for that. I probably— that's a subject that I appreciate very much because I think assessments can be, if done properly, it can be very important. I think interviews are very important.

The least effective thing that I can think of that helps me with, uh, with hiring somebody is a resume. Yeah, it's funny. The resume is basically saying, did they even put in the, the bare minimum amount of work to be considered? Right. And did they put a couple buzzwords in so we can, we can talk to them?

Uh, yeah. Anyway, good stuff with that. Uh, Jen, you will get, uh, the opportunity to, to pick something from the Colorado Equal Security swag store. Interestingly enough, we have— I actually just this week got a few new pieces of swag because Alex added so many new things. I got a zip-up hoodie, which I'm a pretty big fan of, and I got a new hat, a trucker's hat.

But I don't have either of them with me right now. I'd love to show them to you. So we actually have these, like, these big magnets that you can put on the side of your car. I haven't had the guts yet to buy and apply one of those to my car, but, you know, hopefully sometime soon I will. All right, go ahead and we'll jump over to events now.

We, you know, we've been starting the events section talking about keynotes for RMISC each week. So we are on the 3rd keynote, which is the closing keynote of the, of Wednesday. And I wish Alex was here to talk about this one because we are actually doing a live version of Colorado Equal Security as a keynote at RMISC this year. I like that. That's, that's great.

I think everybody will be pleased to see that, and it'll be fun for everybody who's really tied to the, to the podcast. So we haven't figured out exactly like how do you do a live version of, you know, the news and events and jobs, but we're going to do it. And we're going to have a featured guest as a part of that who will be interviewing, who is the CISO for the state of Colorado, Debbi Blyth. Debbi's been on the show a few years ago, but, you know, we're going to have that live keynote interview with her basically talking about what has she learned over the last 4+ years as a— I guess maybe even 5 years now as the CISO for our state. So looking forward to that.

Oh, that'd be great. Let's go ahead and jump into the news over the next 2 weeks. On the 26th, SecureSet is doing their women's only beginner's intro to capture the flag. So if you're a lady who has been interested in getting involved here, maybe you want a smaller group or, you know, you'd love to just work with some other women, this is going to be a chance for you. On the— also on the 26th, we're going to have the GDPR meetup, GDPR privacy.

It's the March in-person gathering. On the 27th, ISC² Pikes Peak down in the Springs is doing their March chapter meeting. Uh, on the 28th, the ISSA, uh, COS 6 Annual ISSA COS Cyber Focus Day. Yeah, so that's the Colorado Springs— it's one of their big events of the year. Uh, it is a full-day event, lots of CPEs and, you know, some good quality content if you guys want to— if you guys are in that area.

On the 29th, we have office hours with Davis Graham and Stubbs, and this is a law firm that was happy to answer your questions. So anything you want to talk about in terms of you know, your small business or your tech company, they're there for you. There's nothing quite like free time with a lawyer. On April 1st, we have the NCC meet and greet. On the 2nd, SecureSet has Hacking 101: An Intro to Wi-Fi.

On the 4th, we have the ISSA Denver happy hour. That's going to be at Automox. That's up in Boulder. On the 4th through 6th, there is the Lady Coders Conference. So we talked with Elaine Marino Karen Worsell are both a part of this group getting together in, in Denver and really help— helping, you know, get women more into tech and coding specifically.

On the 5th of April, we have in Colorado Springs the Cybersecurity First Friday event. And finally, last event here is ISSA Colorado Springs is doing their Security+ training exam prep. They actually do, I think it's 3 of these in a row. The first one is on the 6th, uh, and this is a really good opportunity for anyone who wants to get this more formal training. I've sent numerous folks from my various teams down over the years.

Even though it's a drive to the Springs, it's practically free. I think it's something like, like $20 per session, and you get the, you know, the breadth of the content for the Security+ with a really good instructor, a good group of people who you're going to get to work and learn with. So highly recommend those who want to get that education. Sounds like a great opportunity. All right, we'll go ahead and jump over to jobs this week.

I do have one job at Ping to talk about. We have a junior product security engineer. This is someone who's going to help us secure the SDLC for some of our products, our SaaS products specifically. I would love to hear from you if you're a developer who wants to move doing into doing more security stuff, or a recent grad with a CS degree. It's not posted yet, but we're also hiring a, a lead product security engineer This is a team lead for that same team, actually, and that would be here in Denver.

And obviously someone with more experience who's, who's looking to do security for our product development. At Pensco, they have an opening for a senior information security program manager. The Colorado Judicial Branch is hiring a manager of information security. So if you want to keep the court cases safe, that's for you. Recurly is looking for a senior security compliance analyst.

Transamerica is hiring an international information systems security analyst to focus on policies and standards. It's a long title and very specific. Healthgrades is looking for a security analyst. Proofpoint is hiring a senior security engineer. Coalfire is looking for a cloud architect.

The University of Colorado Springs is hiring an instructor focused on cybersecurity. And then finally, Swimlane is looking for a marketing coordinator. And we had one ad here, uh, InteliSecure is hiring a security platform engineer. What is that person going to do? So a security platform engineer is going to have an opportunity to really help work with the, uh, the platform and our various DLP, CASB, SIEM products and help onboard clients and make sure that clients are getting the services that they need in the way that they need them, making sure the configurations are all set up so that the managed security services teams can do their jobs properly.

Awesome. Well, it sounds like a lot of fun. What, uh, what kind of experience do you want them to have in the background to, to apply for this? Um, well, to, to be a platform engineer, you have to have a fairly, uh, extensive amount of experience in, uh, networking is, is important. Uh, understanding, um, really understanding, I would say, uh, DLP can be incredibly helpful and understanding how, uh, those programs work specifically around technologies such as Symantec technologies, Forcepoint, on the SIEM side, technologies such as LogRhythm.

And I think this is a great opportunity for people who are really looking to expand their experience as well and really develop and help build and grow that program. Awesome. Well, Misha, that's it for the news this week. We do have our feature interview. I sat down with Rock Lambros.

Rock, we've talked with Rock in the past. He was running security for Marquess Energy in town. He just a little bit ago actually left there and is started his own company doing consulting. That's right. Um, actually spoke to Rock right after, uh, he left MarkWest and started, uh, doing his consulting.

And at the very— at the beginning, he was, uh, telling me about all the things that he wanted to do. And I think I spoke to him about 2 weeks later, and I feel like he can't keep up with all the work that's coming his way. He's doing a great job and is highly in demand. Yeah, good stuff. All right, well, that's it.

Thanks, thanks for stepping in for Alex this week. I appreciate it. My pleasure. We'll look forward to talking to you again soon. Hi, this is Chad Payne, Executive Director of IT Operations for Karate Sports and Entertainment.

Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is a special interview coming to you from San Francisco. I'm sitting in the Intercontinental Hotel with Rock Lambros. Rock, RSA's officially started, I think.

Not the main track, and the expo hall's not open yet, but we're here on Monday. We thought this would be a good time for us to talk about Colorado security while we're surrounded by the whole security world. So, you know, you have, uh, you've done a lot of different stuff in security, and we're going to get to talk through that. But before we go into security, I would like to understand, how did you put together your own AR-15? How does that happen?

How does that happen? Uh, with a lot of cursing, um, a lot of broken parts that I had to rebuy. Because, uh, I don't know how many of your listeners are into that sort of thing. There are very small parts that go into especially the lower receiver of an AR-15, and I have very fat pudgy fingers, and those 2 things don't necessarily always go together. So lost springs, um, snapped springs.

How many parts are we talking about? In putting this thing together? In all, I don't know, $75, $100-ish by the time it's said and done with both lower and upper receivers and the— and your grip and the buffer and the buffer stock and, and all that kind of stuff, right? So, so why, why put it together yourself? And I assume you could just buy one and it doesn't cost any more to be put together?

Absolutely. I wanted to learn. I wanted to, I wanted to learn about it, learn about the components. Yeah, um, be able to kind of tweak things if I wanted to. If I wanted to replace a barrel because I don't know, I decided to make it more of a long-range rifle than a short-range rifle, I could, as opposed to buying an entire upper receiver.

Although it's probably almost as cost-effective to do that anymore. But, um, that sort of thing. It was really more for an education experience for me. So I'm guessing that's not your, your only or first gun. Any, any favorite, uh, gun?

You're a gun guy. What's your favorite gun? So I am partial to my AR-15, the one you created, that I built. Have you named it? Does it have a name?

No, I have not named— I've not named that one. That one? All right. No, I do have a— I do have a Benelli shotgun, and, and it's, uh, Benelli's an Italian gun company, so her name is Isabella. Isabella.

All right, so I think my wife came up with that one.

But, you know, the— my favorite gun I've ever shot is probably— a friend of mine has, I mean, believe it or not, an old Russian Mosin-Nagant that was built during World War II.

And, you know, you could buy them now for just like a couple hundred bucks. Usually they're surplus, right? And it was just It was just interesting, right? Because it was an older gun. What kind of gun is that?

It's essentially a sniper rifle that the Russians use. It fires a 7.62mm round, so kind of the same round that the AK-47 uses, which is also a Russian gun. It's just something they don't see a lot. And then also I have fired a semi-automatic shotgun before. Um, which is interesting, right?

So semi-automatic shotgun, you know, when I think of a shotgun, I'm thinking about something that you have to— what, what do you call it— pump action or cock effectively, right, between each round. So imagine like an AR-15 where you're just pulling the trigger and rounds come out, but with a shotgun, with a 12-gauge shotgun, right? So there's amount of kick and a certain amount of, uh, liberating power that they feel after, you know, you watch that target go to shreds, right? Like, it's just cool. All right, well, that's— that's— it's always fun to get to hear a little bit about what you enjoy doing, and that's neat.

Do you go to— do you go like to Cherry Creek Reservoir to shoot, or where do you— so I'm a member of Centennial Gun Club. Okay, that's over on Arapahoe, right? Yeah, that's kind of down by the— by the airport. Yeah, almost by Centennial Airport. Yeah, cool.

Awesome. All right, well, let's go ahead and dive into the more traditional stuff. Where are you from? Where are you born? So I was actually born in Aurora, Colorado, but my family left when I was 2, and I grew up pretty much in Ohio and Vegas, mostly in Vegas after my 6th grade year, I think.

So you went to Ohio from age 2 to 6th grade? Yeah. And then to Vegas after that? And then to Vegas. Moving for your parents' work or what?

Yeah. Yeah. So my dad was kind of a chef slash restaurateur growing up. So him and my uncle, my mom's brother, had a bar and restaurant in Ohio. And, you know, it supported us well, but it really got to the point— it was downtown Canton, Ohio.

So Canton's where the Pro Football Hall of Fame is, for people who can kind of pinpoint that. But, you know, small town, so didn't really support both families. So my dad's family was in Las Vegas, much more opportunity. So Packed us up, shipped us to Vegas. Talk about culture shock, you know, going from small-town Midwestern Ohio to Las Vegas.

Yeah, I bet. And that was back in the late '80s. So I've seen, you know, the whole Vegas boom and kind of go through several transformations of family-oriented to adult playground to family-oriented to now the just ridiculous adult playground it is today, right? Yeah. So did your dad do a restaurant in Vegas as well?

He— no, so he never— oh, he did open his own restaurant. I'm sorry, once. It was more like a kitchen inside of a bar, right? So he kind of paid rent to the bar but owned and ran the kitchen part of it. Interesting.

But he primarily just bounced around between various restaurants and hotels at that point. Okay. So basically, you know, from 6th grade on, living in Vegas, that's got to be a little bit unique to, to be exposed to all that stuff? Yes and no. I mean, growing up, I mean, really the only difference would have been that you could walk into a grocery store and there's a slot machine or video poker.

Mm-hmm. But all in all, it was— at least when I was growing up, most of it was contained to the Strip and downtown. And downtown was even before the whole— what the Fremont Experience is now with the canopy and all that. So it was very much smaller and People really didn't go downtown a whole lot. So it was really contained to the Strip.

Yeah. So we lived obviously off the Strip. No, not everybody lives in hotels in Las Vegas. There are houses off of the Strip. Yeah, we lived about 20 minutes away from the Strip.

So all in all, it was normal, right? I mean, but I did go from like, I mean, even more of a culture shock was a private school in Ohio to public school in Las Vegas, right? So junior high, high school. Grew up, you know, I played football, was just kind of, kind of a normal kid. Yeah.

So played football and in school. What did— when did you get into technology? Was that in school? Was that in college or after you got out or what? So I always wanted to be either like an aeronautical or aerospace engineer growing up, right?

Designing planes effectively. I was kind of after Top Gun. I was— I knew I couldn't fly because I had glasses. So I was like, I want to build those. And then so I got into technology really in earnest in high school with my first programming class.

And then I got to college. Where'd you go to college? My freshman year, I went to Arizona State University. Yeah, got to college. I was an aeronautical engineering major and just kind of realized that, you know, between the party scene at Arizona State, quite frankly, and 7 AM physics and calculus classes didn't really mesh.

So kind of burned out there, went back to Vegas and ended up with a degree in what is CIS now, or information systems now. I think it was management information systems. So where'd you end up going to school in Vegas? UNLV. University of Nevada, Las Vegas.

Running Rebels. The Running Rebels. Yeah. And Um, so, you know, got my degree there and got into IT, which was fortunate. I mean, just kind of, you know, looking back from a timing perspective, when I graduated college, uh, Bill Clinton was in office and there were significant cutbacks to the defense industry.

And, you know, the— I— and it was during the dot-com boom, right? So, you know, having that IT degree kind of launched my career. Whereas if I did get that aerospace aeronautical engineering degree, I would have had a very tough time getting a job out of college. So what was your first job? My first job— so let me think about this.

My first internship, I would say, was with a company called Purchase Pro, and they did essentially B2B, uh, uh, help purchasing agents in the hotels, right, connect with their So it's kind of like one of the first B2B platforms and it was awesome. You know, right? They would ship a bunch of these CDs to the customers. They would install and kind of, you know, nothing that you would think of today. Yeah.

And what do you do for them? They ended up— so I did QA, software quality assurance for them. And then, but really my first job in earnest was at the Las Vegas Valley Water District as an Oracle developer. Hmm, so I got my start really as an Oracle developer slash DBA. That's great.

And that was still in Vegas? That was still in Vegas. Fast forward me. What you did that for? How long were you there at Water?

And I think at the Water District, I was there a couple years, and then I went on to— I wanted to take advantage of the dot-com boom, so I went on to a startup in Vegas called TriRiga. TriRiga. And at the time they were essentially creating plugins for AutoCAD type of programs to do geospatial— essentially a project management program that plugged into AutoCAD along with kind of some geospatial things that you could do within your projects, right? They ended up getting acquired after I left by IBM, and now they do, I think, more like property management, construction management type of, type of stuff in their software. I haven't really kept up a whole lot.

And then after— so after TriRiga, that's when I moved to Phoenix, took a job there with another startup called CopperKey. And I would say that they were— this was in the early 2000s— I would say that they were one of the first, almost ahead of their time, kind of data analytics and marketing firms. Right, so their, their goal was to take all the data from the credit bureaus effectively and create very targeted marketing lists for small to medium-sized businesses. Okay, and you know, that kind of had some legs, but I, you know, I ended up leaving a couple years later. They were still going on, and I think they, they exited to another company and essentially rolled in with them.

I don't know how that as it went. And then from there, I did a few kind of contract engagements. So that's at TriRega is when I really started getting into information security. 9/11 hit. I remember that day very vividly.

I got to the office and it was pretty much a waste of day at the office. We were just watching the news all day. But I kind of, one of the few bright moments of my life was I had this kind of epiphany, if you will, that, hey, the next battle space, right, all these companies are going out of business. The next battle space is going to be the internet, right, or what everybody calls cyber today. So, so how do I get into, you know, this security space?

You know, I did have an inclination of like, should I join the military? Should I do this? Should I do that? And was it really feasible for me at the time? So How do I kind of give back in that regard?

So I pivoted from being an Oracle DBA, focusing more on database security. And then from there at the startup company at CopperKey is when I kind of built their, I wouldn't say security program, it was a very small company, but that's where I started putting security policies in place and started what you would consider a security program today or the foundations for it. Yeah. And it just kind of grew from there. Then I went on to— And were you like an IT guy for them who also did security or?

Exactly. Okay. So I was kind of like an IT manager, Their only DBA and security. Gotcha. So, and then from there I bounced around a couple of contract engagements for Honeywell and for Wells Fargo on their security teams.

I built out the SOC for Honeywell. I was on one of the original teams that built out Honeywell Security Operations Center, their global security operations center. Literally my first day there, I mean, the, the room was still being drywalled, right? So it was— that was an interesting experience.

And then I landed at eBay. Okay, you move out to the Bay Area for that? No, I was actually— they were expanding into Phoenix. Okay, and that was their first official Phoenix hire. Hmm.

You know, other people had transferred from the Bay to Phoenix, right? But I was the first official Phoenix hire. And that's where I learned how to do things from a security perspective very rapidly and at scale. And, you know, I kind of credit eBay, A, the people I met at eBay, people I've worked with at eBay, people I've kept in touch with at eBay, and the experience at eBay with kind of giving me that, you know, kind of accelerated foundation, if you will, right? Like really learning baptism by fire.

To be able to do some of the other things I've done to this day. So what year did you join eBay?

I joined eBay in— it was 2005, 2006. Okay, they were still pretty big at that point. Yeah, so it was their 10th year. I joined like just shy of their 10-year anniversary. Okay, and how many folks were doing security for them at that point?

So security was broken up between the operations teams and then an InfoSec team, which you would consider more of kind of GRC today. Okay. Which team were you on? I was on the operations team. So network security, so firewalls, IDS, IPS.

Yeah. All the packets, right? Yeah. We were responsible for all the packets. And so that's why I mean very rapidly at scale, because even back then, I think the calculation was something like $10,000 a minute if people couldn't log into the site, bid on a product, sell a product.

Right. Yeah. So, so I'm wondering what kind of scale the team was because, you know, that's pretty early for a security team to be very big, but that was a pretty big company. We were— so I think the operations team when I came on board, man, you know, I don't have a good memory. I think the operations team when I came on board was like 5 or 6 people.

Okay. And we had expanded to probably 11 or 12 by the time I left. About 6, 6 and a half years later. Yeah, pretty, you know, pretty small for the size company you're talking about. Yeah, absolutely.

And we had at one time— so one time our team, because again, it was a very hot market back then, our team had actually shrunk down to about 4 or 5 people and we were responsible for the eBay site, eBay IT, and PayPal. Right. And needless to say, those on-call rotations were pretty interesting. And the rotations were pretty frequent. Yeah, I mean, we were pretty much on call all the time.

And but, you know, put— quite frankly, put hair on my chest from a professional perspective, right? And fortunately, I had a couple very good managers, good mentors that kind of stepped us through all that, led us through all that while we were able to kind of staff back up. So how long did you— did you stay at eBay? I was there for 6 and a half years. That's a pretty good run.

Yeah. And then during that time, I got my MBA, circle of life, back at Arizona State, and had an opportunity to move out to Colorado to run a security operations center for DHS, Department of Homeland Security, through General Dynamics IT. So if for those of you who aren't aware, the federal government outsources everything pretty much. So we were running the Security Operations Center for the United States Citizenship and Immigration Services out of Westminster. So I ran that for a while.

We were kind of an integrated SOC and NOC. So I was the SNOC manager for about 2 and a half years. And then that contract was coming to an end and they were moving it to Stennis, Mississippi. So there's a NASA— yeah, the NASA Space Center there effectively, you know, there are politics involved that we won't get into, but there are politics and, you know, they kind of got cheap space. Yeah, well, you know, so Stennis is only about 45 minutes out of New Orleans.

So I mean, you hear Stennis, Mississippi, it's like, well crap, are you gonna get talent? There's actually a decent in Talladega down there, but it's still hard. Yeah, right, from what I understand, keeping in touch with some people. So, so you were the— you moved to Denver in the 2011-ish timeframe? Exactly, 2011.

And then you, you did that, you said 2 and a half years running that? Yeah, about 2 and a half years. So 2013, you weren't gonna move to Mississippi, I assume? Exactly, exactly. So no, not, not no, but hell no.

No offense to Mississippians or Or New Orleansites on the channel listening, but just wasn't for me. We love Denver. So then I went to Agilent Technologies for about 14 months. It was a pretty short run there. Is that the same Agilent that is like the, the phone systems and so forth?

Is that right? No. So Agilent Technologies is actually the original, original Hewlett-Packard. So device measurement systems. And then Agilent actually split off into— so like when HP bought Compaq, right, they split and the original HP went off to Agilent and then HP became the compute servers, printers, all that.

And then Agilent then split into different— 2 different companies. So the chemical measurement and analysis stuff stayed Agilent and the electronic measurement stuff became Keysight Technologies. And Keysight has since actually bought Ixia. So Ixia is now a Keysight company. Ixia, we might recognize because they are a security vendor.

They'll be on the floor at RSA. Absolutely. And you'll see Ixia, a Keysight Technologies company. So anyways, I left before that split. I left like in the middle of that split.

So I was running more incident management for them. Then I got the opportunity to build the security program at Marcos Energy Partners. So I was their first security manager hired, CISO role. You don't really get titles in the oil and gas space.

Had a person of one on my team who I inherited from the network team, but he was really doing their firewalls and IPS, IPS type of stuff and was able to grow that team and the program substantially, both on the IT side and on the operational technology side. So when you came into MarkWest, how big was the company at that point? Company was— I couldn't tell you employee-wise, but revenue perspective, probably just shy of $2 billion with about an $11 to $12 billion market cap. Yeah. And your headquarters downtown Denver?

Headquarters downtown Denver in the black building across the street from the Optiv building. Yeah.

And you got to build that program for how long? So I was there 4 and a half years. So we were acquired by Marathon Petroleum about halfway through my tenure there. And, you know, I've lived through the integration, right? Supported the team through the integration, led the team through the integration.

So it's actually interesting because having been at eBay, I was on the M side a lot of M&As, right? On the, on the acquirer side a lot, but not on the acquiree side. So it definitely gave me a different perspective. Yeah. And, you know, going through gap analysis between us and Marathon's standards and, you know, we were, you know, Marcos had been around 12 or 14 years and relatively, I mean, large in the midstream oil and gas space, but not really a large company overall in that space, in the oil and gas space.

And Marathon, Fortune 25, Fortune 30 behemoth, right? It's been around 100+ years, right? Our security programs were vastly different on their maturity levels, right? We did some things better. They did a lot of things better than us, right?

They were just quite frankly more mature, had more resources. So going kind of through that gap analysis, and starting to meld things together was very interesting. So I had had the urge for a little while to, like an entrepreneurial itch for a little while. And really it was about this time last year at RSA last year where I got a lot of encouragement from people as I was talking about it, like thinking about it to like, Rock, just do it, right? There's plenty of businesses going around effectively, right?

Space isn't as saturated as you think, especially for people like you who wouldn't be targeting the Fortune 100, right, the Fortune 500s.

So over the past year, really, I kind of started building that. People have reached out to me. So you said entrepreneurial instinct, but, but to do what? What kind of entrepreneur did you want to be? So really to go off on my own and try, try consulting.

Long story short, and just kind of be the master of my own domain. So Marathon was, you know, obviously as part of M&A's go, taking away more and more of my responsibilities. My responsibilities were shrinking.

They had— then they acquired another large oil company called Andeavor. So there were gonna be some synergies going on there. I kind of saw what the writing on that wall was gonna be. Mm-hmm. So, you know, and the thought of actually doing another job search was nauseating to me.

I mean, I was just, I was, you know, quite frankly just burned out. It's like, am I gonna— I mean, it's not that I was miserable at MarkWest/Marathon, MPLX, or, you know, whatever you want to call it, many, the many names of the company. Um, but, you know, so I was okay there. So it's like, you know, am I gonna trade one corporate problem for another corporate problem, right, at this stage of my career. Because I've been doing it almost 20 years by now, right?

Yeah. And I'm like, you know, maybe I may have some good knowledge to impart, right? I started this career with hair. Right now I have no hair, right? And, and the, the hair I have left is going gray, and I like to attribute that to some wisdom and experience and You know, I'm not the guy who's gonna go in and bang on a keyboard anymore.

It's been a while since I've been that in the weeds. But, you know, I think I could help a lot of struggling companies out there build their programs, you know, define their security program roadmap, help them implement the roadmaps. If there is a technology need, I could bring in people to do so. Yeah. And that's worked out pretty well so far.

So in October, really the end of September, beginning of October, I started Rock Cyber full-time. And what kind of services are you mostly offering? And you just kind of summarized, you know, helping people, but do you go to market with a, hey, I'm going to be a virtual CISO for you, or is it engagement-based risk assessment? Like, talk to me about the kind of things you do. Yeah, so the, you know, how it started so far is pretty much engagement-based, so traditional risk assessments.

You know, my pitch, if you will, is, and we've all heard it before, but it's, I'm really so much against being the department of no, right? It's all, you know, if the business isn't operating, we don't have jobs, right? I can't put it any more bluntly than that. And outside of certain— if there are certain regulatory requirements where you absolutely can't do something, and even then we can have a conversation of do you pay the fine or the investment or put in the investment?

We are maturing enough as a security industry right now to be able to come up with creative solutions to do just about anything to support the business. I still run into a lot of people with that mindset who are, nope, can't do that. Nope, can't do that. Nope, can't do that, and then wonder why IT teams, product teams, business teams go around them.

Really, my pitch has been, let's do an assessment. Let's align your program to the business. And what I've really been finding is people just want, at least the customers, the clients that I've had so far, it's like, hey, we need a baseline traditional risk assessment, right? And we don't have a framework that we have to go model after, so okay, I'll model them after the NIST Cybersecurity Framework. Or I've got one engagement potentially coming up where it's like, we have an ISO 27001 certification, we have to do our interim internal annual audit.

Can you help us with that? Can you help us make sure we're adhering to controls and evaluate our security program in the process?

Or, you know, hey, we had a breach a while ago that seems to be cleaned up. Can you help us reevaluate our security program, make sure that we're aligning properly? Those types of things. Then there's never been a risk assessment on the planet that hasn't had results, risks. I help them define a security roadmap to start addressing those risks.

I prioritize those risks as part of the assessment and then help them define a security roadmap to address those risks. Then it's really up to the organization. I help them through the thought process, but it's really up to the organization if and how much they're going to invest in any and all of those initiatives, right? And then I'm available, right, if they want help moving forward to manage those projects, to implement those projects, whatever. Yeah, we're available.

Awesome. So what's your, you know, what's the long term look like? Is it, you know, you've only been doing it for, you know, what, 4, 5 months, whatever it is right now? Uh, what is, you know, what's your plan 2019, 2020, any thoughts about how this might change? Yeah, so I've been thinking a lot about that.

That's kind of one thing that I've been— I wouldn't say struggling with, but it's been bouncing around in my head a lot.

You know, because in one regard, I have zero interest in being like the next Optiv, right? That's not the path I want to go down or build out something to be that big. But You know, I wouldn't mind having a few consultants under my belt, right? And to do that, I've got to be able to, especially in this market, have them be kind of full-time employees versus 1099 subcontractors because it's hard enough to recruit in this market without being able to provide benefits and all that kind of stuff. But to do that, kind of need a critical mass for revenue, right?

So right now I'm the chief everything officer. Right on the service delivery side and on the business development. Yeah, I, you know, I'm not a sales guy by nature, right? So business development for me is— fortunately, I've been very blessed to have had a great network, and all my work so far has come through referrals.

How does that sustain and scale? We'll see. So 2019, I've told several of my friends that a year from now, ideally, I'd be at out of the service delivery side to mostly an extent and be running quote-unquote a company, you know, a few consultants under me and maybe a salesperson, maybe outsource sales. We'll see. And, and just, you know, kind of building some steam there.

Yeah, I've got— I'm, again, I'm very blessed where I'm gonna be very busy the next few months from a project perspective. Um, and we'll see where that goes. Yeah, I know. I, you know, we've talked in the past. My, my struggle was always that, you know, I, I spend cycles getting the business and then go deliver, and then after delivering, I would always be like, okay, now what?

Like, it was— I hated this, uh, this context switching between trying to be the, the sales guy. And sales doesn't necessarily mean like going out and smiling and lying to people, right? It could just mean like talking about what their needs are and may or may not be happening here at RSA this week, writing up an SOW, and like all those things are just— they're just work, right? And then you go deliver, and, and I always— I found that context switching really difficult. And I think being able to get some specialization makes it a little easier, and of course like smooths out the bumpiness of the business because you're gonna have— like you said, you got a bunch of work the next few months.

If you spend the next few months delivering work and all of a sudden you just— you finished all those deals, you're like, okay, well, now what? I got nothing in the pipeline because you haven't been talking to people because you've been working, right? It's a tough balance. It's almost like a chicken and the egg scenario, right? Because if you're busy delivering, you're not bringing in the pipeline.

But if you don't have the pipeline, then you're not gonna be busy delivering. Yeah, and it is. And I find that I've had to get really good and disciplined about organizing myself Um, especially working from home. Mm-hmm. Um, cuz you know, there are a lot of distractions.

Right. I love my wife. Right. And you know, we've, we've figured out that, did you just call your wife a distraction? No, no, no.

I said, but I've, we have figured out that that's gonna be the headline in this story this week. Oh, I know. I know. I like Mary. I love you.

Okay. So, but you know, we've gotten to the point now where it's like, okay, cuz I'm home, I'm not available. Right. And I'll, I'm able to carve off some time. And, you know, being able to manage my time.

And I find that I have to like book everything in my calendar, even if it's, hey, do admin work or do write this proposal. And then, you know, for 2 hours and then, you know, 3 hours work on this project and 2 hours work on that project. Yeah. And hour and a half do, you know, the rest of the stuff that Rock has to do in his life. Right.

So. And really, so I've been practicing that, right? It's worked out pretty well. That's great. So taking a little bit of a turn now, I didn't meet you through those jobs.

I met you in the security community. Yeah. You've been fairly actively involved in a number of different things in the Colorado security community. I'm trying to— I don't off the top of my head remember exactly Like where we met. I know, you know, somewhere through ISSA somewhere.

And I know you stepped up to be the chair for the Rocky Mountain Information Security Conference for, I think, 2 years. For 3 years, yeah. How did you get plugged into the community in the first place? So when I moved here, so I was an ISSA member in Phoenix. Yeah.

So when I moved here, I reached out to Alex, who was the president at the time. Well, actually I reached out to communications, I think, at issa.com and he replied. Yeah. Because Alex was doing kind of everything at the time and he put me into the community meetings, that sort of thing. So I just started coming to meetings and meetups and happy hours and stuff like that.

I'm not, I'm definitely not the most involved person, right? I'm, you know, or anything like that, but just kind of organically just meeting people and building those relationships. Yeah.

Yeah, so it was really through ISSA, Alex, you, you know, and meeting other individuals in the community. Then, you know, got roped in, roped in to do RMISC. Alex decided that, you know, he needed to take a little bit of a break. So yeah, convinced me to do it for what ended up being a couple years. Then we flipped back.

I'm helping out with RMISC. I took a break. I took a year off last year because I needed to for various reasons.

And now I'm back helping with RMIC this year, running their, their marketing. Yeah. And I think in earnest now after RSA, right? Because nobody has really wanted to focus on RMIC with RSA lingering over their heads. We'll be doing some active marketing, LinkedIn, Facebook, that sort of stuff.

To start bringing in people not only in Colorado but reaching out to, to other states, especially in the region. So for anyone who's listening who maybe had never been to RMISC, you know, they maybe heard it on the show, maybe they never heard of it at all, what would be your pitch for why someone might want to come?

Awesome speakers and trainings, very affordable price, and very community-focused. Right? So it is not— I mean, obviously we have our sponsors and we love our sponsors, but it is not going to be, in my opinion, blasted in your face like you would here at RSA. It is very much community-focused. It is built by the community for the community.

And, and we're fortunate in the fact that we've got a great team that we outsource all of the logistics to, you know, dealing with the conference centers. Shout out to iPlanet. Dealing with the conference centers, the logistics of, you know, getting the speakers here and that sort of thing. And we as an organizing committee can really focus on content and how we're going to drive value to the, to the community and to the members. Yeah.

Those of you listening, just to echo what Rock said, the The conversation that's continually happening with the committee is how do we get more value? How do we deliver more value to the attendees? That's the whole reason we're all there, is get as much value as we can. And you'll very infrequently see us increase prices. It's basically got to be a pretty darn good reason to do it.

We'd much rather figure out some other way. Let the sponsors cover that. Yeah, and truly, I'm not here to bash vendors or bash sponsors. It truly wouldn't be possible without them. But, you know, we put some guardrails up to make sure that it's not, you know, strictly a vendor show.

I think there's absolutely value out of having the vendor floor there and having people kind of see what new products are in the marketplace and, and, or, you know, not new products in the marketplace, but what are they doing now? Right. What are some of the new features and learning about that? But you'll see most of the programming, most of the sessions are not vendor-focused at all, right? There's a vendor track, so when you go, you know it's gonna be a vendor speech.

But other than that, you know, the sessions are vendor agnostic, right? So you can truly learn about trends, you know, TTPs, right? Technique, tactics, and processes, right, in the industry, and, and, uh, without it being kind of a sales thing flung in your face. All right, so I think the question everyone wants me to ask is, why is your name Rock? Why is my name Rock?

You know what, that's a great question. So my real name is Kyriakos, uh, very, very Greek name. Yeah, my parents were born and raised in Greece. Um, somehow kids in high school got rock out of it, right? Long, really long story short.

Yeah, I would say until high school, huh? Yeah, it wasn't until high school, and I'd say really go by— is it Kuriakos? People, you know, would call me Kuriakos. Teachers would take them a little while to figure it out at the beginning of every school year, right? And but they would get it, and it's actually pronounced almost pretty much exactly how it's spelled.

Pretty phonetically. Yeah, and You know, but I've gotten all sorts of Caracas, Kirikos, right? All sorts of different pronunciations. And I don't know, somehow I would say it was later, probably my senior year, where it kind of really started sticking more. And then when I went to college, when I went to ASU, forget it.

It was like, they're like, Kirikou, I'm gonna just rock, right? So that's, that's really my freshman year of college, I would say, is really— you made the choice at that. I made the choice at that point that it's just Rock. So, and it's just stuck, right? It's just stuck.

I wish I'd have trademarked the name, right? I probably— as much as I love you guys in the community, I probably would not be sitting here right now if I had. You're thinking that Dwayne Johnson— I am thinking of Dwayne Johnson. I'm thinking that WWE may have wanted to buy that name off of me, buy the trademark off. So does your wife call you Rock?

Both. Both. And it's not even a When she's angry, right? Right. So she'll call me both.

Awesome. Well, that's all those topics I wanted to make sure we covered. Is there anything that you wanted me to make sure I asked? Any topics you wanted to go through other than that? No, not really.

I appreciate the opportunity. I know it's busy for you here at RSA because you do have to put your CISO of a security company hat on and do your thing here. Right. So I appreciate the time. You know, I just, you know, I love being able to engage in the Denver community and the Colorado community and hopefully give back a little bit.

And, and, you know, I also want to thank the community again. I cannot emphasize it enough now that I've gone off on my own. Like I said earlier, I've been blessed with a great network and all my business so far has been, you know, referral-based. Yeah. So thank you.

Anyone hearing, you know who you are, or anyone listening, I should say, you know who you are.

And I can never, never repay you with enough gratitude for that. So, well, great. So if anyone wants to reach out to you to talk about, talk about risk assessments or other work, how should they reach out? Yeah, obviously I'm on LinkedIn. You can find me Rock Lambros or just rock@rockcyber.com.

Cool. All right, buddy. Thanks for your time. Thank you, Robb. We'll talk to you soon.

And all you listeners, we'll see you again next week.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes