Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 113 for the week of April 15th. Alex, it's tax day.
It is tax day. You know what that means? It means I'm a little less rich than I was before. That's right. Although for most of us, it probably means that, you know, several weeks ago or months ago or whatever it was when we actually did our taxes that we— I did the taxes, but I figure I wait as long as possible to give them my money.
Yeah, that's true. I, you know, I'm pretty excited. I was surprised I actually got a small refund this year. Congratulations. I know it was not expected.
The— I was actually reading one of those articles about people's perception of the tax cuts from the current presidential administration. And, you know, people expected to have bigger tax cuts, and mostly tax cuts are pretty much the same as they were last year. Yeah. But that refunds— excuse me, they expected refunds to be the same, but that the actual tax burden has gone down by about 25% for most people. Well, pretty interesting.
That is interesting. But because you had it kind of distributed throughout the year and your paychecks went up, you're right, your refund actually did not go up. Right. Yes. Which, um, I think overall I would rather have more money throughout the year than have the government hold on to it and give it back to me later.
Right. Giving them a tax or an interest-free loan. Right. But it, you know, that's harder to see. So absolutely.
All right. Well, why don't we go ahead and move into our housekeeping? Uh, we do have a Slack channel. This is a great place for folks who want to chat with folks in the security community to get together. I think I saw we're at 860-ish people, something like that.
So it's a part of it. It's going to be a pretty big number. Uh, we also have a website if you go to colorado-security.com. On that website, there are a whole bunch of cool things including an events page, Colorado security company directory, and a mailing list. So if you want to sign up for our mailing list to get the show notes in the mail, check out that website, sign up, and we will let you know when there are new episodes.
So everything that we're saying in this show is in that mailing list, basically. Well, at least a summary of it is. It's also— that website's also the place you can get the link to join our Slack channel that I just mentioned. For sure. We'd love it if you would rate us and subscribe on your favorite podcast listener.
If you are on an iPhone, go ahead and go to the Apple— the iTunes Store, the Podcasts Store, I guess it is, and rate us and subscribe there. If you're on another device, well, figure it out on your own because I don't know how to do it. Yeah, I'm sure that there's some way to subscribe on those too, so you should do that. If you really like what we're doing, we'd appreciate it if you tell a friend, uh, someone else in security, someone else not in security, uh, anyone who might be interested in Colorado Equal Security. Tell them, uh, give them the website, tell them to check out the podcast.
And finally, if you, uh, are interested in helping us finance this whole thing, which we're, you know, doing out of our own pockets, we would love it if you would join our Patreon campaign. This is a way that you can help defray the costs of hosting and And all the cool stuff we do here has a little bit of financial cost to it. This money does not go into Alex's and my own pockets. We do send it all right back out to the community through what we do on the podcast and other various stuff like that. You can get access to that also through the website there.
So let's jump into the news. First, big announcement. Chevron has agreed to acquire Anadarko Petroleum for $33 billion. So this is actually a single tear for me, Alex. I don't know if you're aware of it, but I actually worked for a company, Western Gas Resources, which was acquired by Anadarko.
It was one of my, my first favorite jobs. I would say that's how I got into security, was working at Western Gas. So I was there right when— I was there when Anadarko bought Western Gas, and I stick around for just a little bit of that. And it's interesting to see what's it been, 13, 14 years later? Yeah, that now they're gonna be part of the behemoth Chevron.
Yeah. And so Anadarko is based in Houston and Denver. So it's going to be a pretty big change for the oil and gas community here in town. I was surprised. I, you know, I knew Anadarko as being just a massively big company, but I was surprised how much smaller than Chevron they are.
So the article here shows that Chevron is number 13 on the Fortune 500 list with about $160 billion in revenue in 2018, 48,000 employees worldwide. Interestingly enough, they have about 8,000 employees in downtown Denver. This is Chevron has 8,000 employees in downtown Denver. And you look at Anadarko, they're 257 on the list at $13 billion. So $160 billion to $13 billion.
And Anadarko has a total of 4,700 employees. So Chevron has 8,000 in downtown Denver. Anadarko's total worldwide is 4,700. Yeah. So much bigger, much bigger presence in Denver even.
I had no idea Chevron even had a presence here. I don't think I realized that either. Now, Anadarko had a large IT presence and a security presence here in town, so that could be a bit of an impact to our community. You know, another company that has a large presence in Denver is Southwest Airlines. This is interesting.
Southwest, who's headquartered in Dallas, has realized that having their shareholder meeting in Dallas sucks because no one wants to go there. So they're actually going to be meeting in Denver here for their, for their annual meeting in May. You know, I read the article. I didn't notice exactly where they said that having their meeting in Dallas sucks, but not that I'm doubting that. This is my commentary on the facts here.
Obviously, they're doing it because Denver is a better place to have their shareholders meeting. Yeah. And one of the notes that was in that article is that Denver is the most active hub for Southwest, which also doesn't surprise me, but it's pretty cool. Yeah, I might have guessed that it was Dallas since that's their headquarters, but pretty cool stuff. The 3rd story this week, Denver— Denver— Denver is ranked number 2 on US News and World Report's list of best places to live.
That's pretty awesome. This is Not just, you know, not just in Colorado-type cities, right? This is anywhere in the US. Denver's number 2, and number 3 was Colorado Springs. Yes.
And that's pretty amazing. It is very amazing. We will not speak of who is number 1. So they have a— they categorize these things, and they rate us based on desirability, value, job market, quality of life, and net migration. And Denver did best on the desirability and job market out of those categories.
Yes, and not surprisingly, they were the lowest on the value category. I think we all know that costs in Denver have gone up in the the recent past, and so that the value on that scale is decreasing slightly. Yeah. Next story here was about a a group. I don't even know if you call it like some kind of an organization called ten dot ten dot ten about this entrepreneurial program.
That's it's really interesting. It sounds like it was put together a while back where the ten was was to say. Um, we're going to have 10, uh, entrepreneurs start 10 companies that are going to help us solve 10 really interesting problems. And it's this organization that comes together with tough problems and smart people to try and solve these problems. Yeah.
And they've been continuing to do this. It sounds like they have a couple of these, um, each year they get a cohort of, uh, of these serial entrepreneurs together. Um, they work on what I, what they called, I think, wicked problems, the really tough problems. And they get 10 days to start a company around solving one of these problems. So this has been going on since 2015.
It was the birthplace of companies like Apostrophe Health and BurstIQ. I have heard of BurstIQ. And this is the 6th cohort, and it actually just presented the solutions this last week on Thursday night. They had the last solutions. I haven't seen what those were yet, but I'm looking forward to seeing what came out of that.
Yeah. And it sounds like they do this a couple of times a year. So I think, you know, in another 6 months or so, we should expect to see another cohort solving 10 problems. Uh, next story here, Amazon acquired, uh, the Boulder robotics startup Canvas Technologies to automate their work— their warehouses. Yeah, so Amazon already has a, a pretty automated, uh, warehouse system.
In the article, they mentioned how Amazon has 100,000 robots already working in their warehouses, um, as part of their automation efforts. But, uh, this company in Boulder is gonna help that, uh, be even more automated. So, so Canvas Technologies had taken on about $19 million previous to this acquisition, and when they last took on that money, they were valued at about $55 million. So you'd assume that this probably came at a premium from that. Yeah, it's been over a year since their last round, so hopefully, you know, they did really well in this exit and Amazon got some good technology.
Next, Bank of America announces a major expansion into the Denver metro area. So Bank of America is actually going to be opening 12 branches in Denver metro by 2021, which is interesting because some other banks are closing branches in Colorado. So when I, when I first saw this, I actually thought that it was going to be Bank of America coming in to like open up jobs in town, because I know we've— you and I have both heard from Bank of America that they are looking to hire quite a few security jobs in town. It looks like they may be bringing in some kind of a security operations center or a center of excellence around security. This is particularly— this article is about their their bank— they call them financial centers instead of being banking branches because it's more than just a branch.
It is. But financial centers that they're opening. Um, but it looks like they're also going to be a bunch of opportunities to work at Bank of America in security. So if this is something you're interested in, you know, maybe keep your eyes open for it. You know, I think a lot of times when you expand into a new market, you put, you know, a regional office there or something like that too.
And as part of having one of those offices, it, you know, it gives you the opportunity to to hire folks not just for that area, but for other parts of the, you know, central support system. Yeah. Well, one of the hallmarks, one of the most well-known MSSPs in town is no longer an MSSP here in town, Alex. Well, I think that they'll still be here in town, but they're merging with another company. So— but they're not going to be.
So GV Protect, which has been historically a Denver-based managed security services provider, has been acquired by a company called Newspire, which I had never heard of, but is apparently an MSSP up in Michigan. Yes, I believe the press release does say merged with, but that's what happens when you get acquired, right? Yes. Well, in the headline it says merger, and the first sentence of the article it says acquired. So I know.
Anyway, hopefully this is a good thing for the folks there at GBProtect and hopefully for their customers as well. They're down in actually pretty close to me here in the Denver Tech Center area, Arapahoe and 25-ish. I know that they've, you know, over the years offered MSSP services for quite a few companies around town. Hopefully this is going to be a good thing for, for all those folks. Maybe they will get some synergy with Newspire and become an even bigger MSSP.
Next, accolades continue to roll in for Ping Identity's— for Ping's identity and access management solutions. There should be another identity in there, right? Yeah, it probably should be. So there's a press release here with a few different awards that Ping won in the last couple of weeks. SC Award during RSA conference for the best identity management solution.
This is the best award, the top-level one came into Ping. There was an InfoSec Award. We were named the Identity and Access Management Editor's Choice winner by Cyber Defense Magazine for their 2019 InfoSec Awards. Cybersecurity Excellence Award for Ping Intelligent Identity Platform, uh, that was a Silver Cybersecurity Excellence Award for best identity and access management product. Boy, that's a mouthful.
And CRN's Security 100, um, put them on the 20 coolest identity management and data protection vendor list for the second year in a row. Love it. Good stuff. Hopefully that keeps happening. Yeah.
And you know, we, we saw some awards articles last week too. I think that, you know, people give out a lot of awards around RSA and then you know, a couple weeks, a month later, then there's all these press releases that come out about how everyone all these won all these awards. Yeah, you don't, because you get lost, maybe get lost in the noise of RSA if you do it right away. Um, next we have an article from Secure64. They are the, the DNS security provider, uh, from the Tech Center slash Fort Collins.
Um, this article is called Why I'm Long DNS. And really what it's about is how changing technology is going to, uh, is going to cause DNS to become way more utilized and become, you know, really more of a bottleneck, I think, or something you need to be investing more in based on the changes. Yeah, so they're talking a lot about 5G and the rise of the things that 5G will enable, including much more data bandwidth and consumption, greater voice over IP, proliferation of IoT devices, which we're already seeing, but I think will even be even more with 5G. Um, and then advances in VR and interactive gaming. So their premise here is that all of this increase in traffic and bandwidth is going to make DNS even more important.
So you should definitely use Secure64 DNS products to make sure your DNS is, uh, is secure and available. And believe it or not, they are not sponsoring this show in any way. We just, uh, we just love them that much. All right, uh, next blog here is from Mitch Tenenbaum. Mitch is one of the local security guys.
He, he writes a blog really a few times a week, and we take a look through it for anything that we think will be relevant to the group. This one's not Colorado-specific, but interesting stuff. He's talking about the FBI and, and how, you know, they are tasked with monitoring, you know, cybersecurity attacks from other countries against the US, and really how what they're currently dealing with far exceeds their bandwidth and what they're actually able to handle. Yeah, it was an interesting article, you know, talked through some of the numbers. And it's not surprising to me that there are many more crimes than there are FBI agents to be able to, to work those crimes.
So I think he said there's 1,981 agents who are focused on cyber investigations. So it seems like a pretty good-sized number. But as you break it down into the fact that they have, you know, 56 field offices, there's only, you know, a few dozen people per place. And it's just not nearly enough to keep up with the flow. And it says each field office is bound to investigate around 300,000 crimes that were reported.
So that's a big number for the number of people that are investigating those. Yeah. So you're— if you think about 30, call it 30 people handling 300,000 crimes, you just don't get enough time to really investigate any one of them. Right, exactly. Finally, we have a blog post from Coalfire.
It's about the death metal suite. This is written by Uh, by Victor— is it, is it Tesler? Teisler, uh, security consultant over there at Coalfire. Um, and it's a, it's a toolkit that he wrote. So he wrote the blog post and he wrote the toolkit.
So pretty cool stuff. Uh, uh, Death Metal Suite is what is this tool that takes advantage of Intel's AMT, their, their remote management tool for their, um, for their chipsets. Um, and he talks about, you know, basically how this toolset enables you to better take advantage of all these features Uh, that maybe the person who owns the system might not want you to be able to take advantage of. Yeah. And AMT is built into Intel chips.
Um, and it, you know, it's used for administration, even if you don't have an operating system on the machine itself. So, uh, at the end of the article, I have some advice, uh, for both blue and red teams. Um, basically, you know, if you're on the, the protect— protection side, make sure that you configure this. Um, so that you guys have control over it. Um, set a password and maybe forget that password so that no one can get into it.
Um, and then on the, the red team side, basically he's saying, um, this is something fun to play with that you should be able to exploit pretty easily. Uh, good stuff. That is it for the news this week. Moving over to our Slack message of the week. Big thanks to Andre Gaeta.
Andre is still our sponsor for this. He hasn't, uh, sent me a cease and desist note yet. Thank you. Thanks for doing that, Andre. Uh, every week we recognize someone who posted Uh, thought-provoking or conversation-starting, uh, post in the Slack channel.
And this week, who do we have, Alex? Uh, our winner this week is Kevin McDermott. So congratulations, Kevin. Uh, we picked Kevin just for his activity in the channel. There's a number of different conversations that, uh, that Kevin has been deeply involved with recently, including, uh, talks around, uh, HackTheBox, uh, pen test certs, OSCP, uh, lots and lots of different things.
Kevin's over at Arrow and, and does AppSec over there for them. Um, so congratulations, Kevin. Good stuff. We'll hook you up with Andre and you'll get to pick one item of swag out of the Colorado Equal Security store. Uh, next we have our events for the week.
So, uh, as we look forward, you know, like to start this conversation talking about, uh, an event that's a couple months off, the— but it's the biggest one in town, right? The Rocky Mountain Information Security Conference. Definitely. And this year, the first day of Rocky Mountain Information Security Conference on the Tuesday Uh, we are doing what we're calling Community Day. So traditionally on that first day, we have paid trainings that you can get in-depth knowledge around specific topics, and we are still doing that this year.
So if you're interested in, in some of the topics that we have there, you can definitely still do that. But we're also offering, um, a couple of free events that are more community-focused, trying to get people into participation with RMISC. So one of those is DevSecOps Days Denver. So DevSecOps Days is an event that happens all around the country, and, and we're partnering with the, the group that puts that together to do a free all-day track on DevSecOps. And then we're also doing the Rocky Mountain Privacy Forum.
So we're doing a whole day track on privacy, different privacy topics. Again, both of these are free. So as you register for RMISC and you want to come on that first day, check that out and looking forward to it. So just as a reminder, RMISC is happening June 4th through 6th this year. So that, that community day is Tuesday, June 4th, and then the tracks are gonna be on the 5th and 6th.
And it is the biggest conference here in town. I think last year we had— oh, do you remember what the number was last year? I just walked myself— 1,300 and change. I don't remember the exact number. 1,330-something, I think.
We expect to be well over 1,500 this year. This, you know, been great growth year over year. This is a great opportunity for you to not only have, uh, well, you get over 16 hours of CPEs if you come to, to the 2 days of tracks, and if you come to the community day, you get even more. But it's also a great way to network with folks in the community and lots of good sponsors. It's a great opportunity to get involved, definitely.
So let's jump into those events. Uh, first on the calendar, SecureSet is doing their Denver Blue Team Workshop Fundamentals of Network Defense, uh, on April 15th. On the 16th, Denver Splunk Meetup is happening. Also on the 16th, CSA Colorado is doing their April chapter meeting. And finally, same day on the 16th, the Denver IAM meetup is happening at the Wynkoop Brewery.
No, no, not finally, Robb. Also on the 16th and the 17th, ISSA Colorado Springs is doing their April chapter meeting. That's the, the 16th in the evening for dinner and then the 17th for lunch. Also on the 17th, ACES is having their April meeting. Also on the 17th, DENSEC is doing their April hangout.
Hangout at Reinhaus. It's amazing how many events April's like, like there's just a ton of things happening all over the top of each other. It's spring. All the security events are blooming. You are.
I like it. You guys are have so many choices for what you want to go to. ACES is the physical security one. There's this IAM group. All these things are interesting, and hopefully you guys can make it to some of the stuff.
On the 18th, CTA is doing their Insight Series on AI-enabled analytics. Business Intelligence and Analytics in an Era of Artificial Intelligence. Also on the 18th, ISACA Denver is doing their April Annual General Meeting. SecureSet is doing a cybersecurity meet and greet at SecureSet on the 18th. On the 19th, PMI is doing their PMI Mile High 21st Annual Symposium.
The Cloud Security Association— CSA Alliance— the Cloud Security Alliance Denver is doing their CCSK training on the 19th and 20th. On the 23rd, ISSA Denver Women in Security Group is doing their quarterly meeting. Also on the 23rd, the GDPR Meetup is doing their Words of Wisdom from a DPO Meetup. On the 24th, ISC² Pikes Peak Chapter is doing their April chapter meeting. On the 26th, SecureSet is doing a Hacking 101: An Intro to AppSec.
And finally, also on the 26th, ITS Partners and Symantec are doing a private screening of Avengers: Endgame. So if you want to go see Avengers: Endgame for the low price of having someone try to sell you something, check it out. Yeah, it looks like it also comes with a free lunch. So you show up at 11:30, you get to eat lunch, get a little bit of a sales pitch, and go watch Endgame. And, and you'll, you'll be one of the first to have seen the movie.
And at this point, if you haven't bought your tickets for the opening weekend, you're probably not gonna see it. So this is a good opportunity. There you go. Uh, let's go ahead and jump over to jobs that we are hiring a couple of folks at Ping Identity. Number one, I'm looking to hire a junior product security engineer.
This is someone with a development background, but, you know, an interest in security, not necessarily a strong security background, but someone who wants to help us work on embedding security into the SDLC for our products. And then we're also hiring a team lead for that same team, a product security team lead, someone who does have some experience with application security, a development background, and wants to help lead several different folks and one half of our product security organization. Vail Resorts is looking for a senior analyst in information security governance, risk, and compliance. CenturyLink is hiring a director of security operations— oh, the director of security operations center on digital transformation. Yeah, Mike Benjamin had posted about this, and I don't remember the details, but it sounded like an exciting opportunity.
Splunk is looking for a principal intelligence analyst. This is a remote position. Chronicle, which is, uh, the company that's owned by Alphabet, formerly Google, right? Um, so Chronicle, they come out with Backstory recently. They also are the ones who do VirusTotal.
VirusTotal. I think they have one more product or two. Uh, so they are hiring a technical security analyst here in Colorado. Yeah, pretty cool. Vitac is looking for an information security analyst.
Western's— Western Governors University is hiring a course instructor focused on IT cybersecurity. Nice. Visa is looking for a senior cybersecurity engineer. And finally, Prologis is hiring a cybersecurity intern. Nice.
Well, that is it for our news this week, Alex. Uh, this week I sat down with Mischa Danaceau. Mischa is the CISO over at InteliSecure. We talk about his background and, and what is next for him and next for InteliSecure as well. Pretty cool.
I look forward to it. All right, we'll talk to you guys again next week. Thanks, Robb.
Hi, this is Mike Kalax, CISO at Western Union. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
All right, this is Robb Reck, and I have a special featured guest this week, Mischa Danaceau. Excuse me, Mischa. Uh, Mischa, you are the CISO for InteliSecure, and, and I'm looking forward to hearing about you know, your career and how you got there. But before we do that, I want to understand, uh, your hobby where it sounds like you, you spend a lot of time assaulting children. Is that, is that appropriate?
Yeah, well, I mean, not that there's anything wrong with that. I think that it, uh, it can be fun if you, you know, if you do it in the right way. And it's a sanctioned assaulting of children too, so, you know, I'm not gonna go to jail for this. But, um, yeah, so my son, uh, we signed him up for taekwondo. Yeah.
About 2 years ago, and he was really reluctant at first. I think he, you know, we took him to a class and he found it a little bit scary. Was it about 5, 6 years old at that time? Yeah, he was about, yeah, so he was about 5 years old at the time. And so I asked him, I said, well, if I do this with you, would that be something that you'd be interested in?
And so he really, that really helped. That sort of got him over his fear of doing it. And, uh, so we go to a, uh, uh, to a taekwondo dojang. Um, it's called Parks Taekwondo, uh, down here in Centennial. And, uh, we go about 2 to 3 times a week.
And it's like that episode of Seinfeld, I think, you know, where Kramer takes karate and he's, you know, the, the oldest guy. You know, we're all at the same skill level, Jerry. Um, and, um, so I, I am probably the oldest person in, in the taekwondo, uh, class on a regular basis by a good 30 years. And, but still, I really enjoy it actually. It kind of makes me feel a little bit younger and a little more youthful.
But we do sparring. So we actually put on sparring gear. And once the sparring gear is on, I'm actually allowed to kick and punch children. I'm not with full force, but still, you know, it's a, I don't know anybody else who gets to do that. You know, get— Without too much trouble coming from there.
Right, exactly. So. It, uh, and it's a great, it's a great experience. Um, uh, really, um, it's not about learning to fight so much. It's really about learning to develop yourself both physically and mentally, uh, as a person.
And I think that anybody who goes through the program all the way through to black belt, and we've probably got about maybe a year and a half to go before we get there, um, I think it's, it's an incredible accomplishment, especially for a kid. It's one of these things that's going to build up confidence, uh, and, uh, and really help also develop self-discipline. Those are 2 great things that are gonna serve you well in life. Yeah, I think, you know, you and I were talking before we hit record, and I have a son who's, who's about 8 months now from getting his black belt. He should get it, you know, assuming all goes well.
And, and I have a lot of the same observations around that, you know, the value of self-discipline and body control and, and like really having to, to focus and work on something for, for a long time to get good at it. Those are, those are immensely positive things that we get from Taekwondo. We do not get the ability to kick butt from Taekwondo. That's not really on the offing for, for that training, but, but it is a super valuable thing and it's pretty cool stuff. Yeah, no, it is.
And I think that's great. And as long as you understand what it is that you're getting out of it and also making sure that you're— the participant understands what they're getting out of it, you know, a good Taekwondo instructor will let them know that, that it's not about learning to kick butt. It's about all these other things, you know, through that medium. Yeah, well, that's great. Um, I'm glad you're doing that.
Are you hoping personally to go get a black belt in the next couple years? Yeah, absolutely. So part of the deal, as I said with the instructor as we signed up, is that, you know, our goal is to go through— actually, our goal is to get to a second-degree black belt. So it's about a 6-year commitment, and both my son and I have made that commitment. And it's a— my thing for me is I want to go along with my son the whole way, so it's something that we can do together.
And so I said to the instructor, you know, I, I don't advance if my son doesn't advance, so we all have to go at the same pace, you know, and do it that way. That's great. All right, well, let's talk about your background. Where are you from? So I grew up in the Washington, DC area, um, in, um, uh, Chevy Chase, Maryland, Chevy Chase-Bethesda area.
Yeah. And, um, I, um, you know, my dad was, uh, originally came to the DC area because he was worked in politics. He worked for Senator Birch Bayh, who actually just passed away the other day. Who's that senator from? Senator Birch Bayh is from Indiana.
So Senator Birch Bayh preceded Dan Quayle in the Senate, and then his son Evan Bayh then came after Dan Quayle at the same position. Yeah, so you grew up in Maryland. How long did you stay there? Did you go to high school there? Yep, so I went to elementary school, high school there.
Yeah. After high school, I went to Ithaca College in Ithaca, New York. For, you know, like a lot of people in the security industry, I pursued and got an English degree. Yeah, exactly. Perfect.
So did you— when did you get interested in computers? Was it during school or was it, you know, after college or what? It was really after college. So I actually came out here, uh, to Colorado because when I was living in DC, I realized it really wasn't the place for me. Um, I didn't want to be involved in politics.
That wasn't something I had a lot of interest in. I didn't want to be an attorney. Um, the, uh, the tech industry was probably just getting developed there through AOL, but it really wasn't something I was involved in. And I was attracted to Colorado because of the outdoors activities here. So I decided I'm going to pack all my stuff up and I'm going to move to Colorado.
Where I knew a couple of people and I'm going to see what happens. So I do notice as I'm looking at your, your background that, you know, your major was English but your minor was in German and you have a, you have an educational, uh, stop on here that looks like you were in, in Germany itself. Is that, is that what it was? Yeah, so I did a junior year abroad in Freiburg, Germany, yeah, studying, uh, studying German, um, and, um, having a string of the weirdest jobs I've ever had. While I was doing that because I needed a way to make money while I was over there and I wasn't really qualified to do anything.
So I got a job working the 3:00 a.m. to 9:00 a.m. shift in a bakery from which I got fired. For sleeping or eating or what? For just being really bad at the job. So trying really hard, but you just didn't make good— yeah, I just, I was like a horrible pretzel maker. I just, I just didn't have the skill.
I was— all your pretzels were straight. Right, it was awful. So I got fired from that job, and then I got a job working in a pet store, which I didn't get fired from, but I should have been fired from that job because I was also really bad at that. I had no idea. The only way you can be really bad in a pet store is if animals are dying.
Well, so yes, that's exactly my point. So I didn't realize that like you just can't put any fish together in the same bag. So people will come be like, I want this and I want that, and I'd say, okay, great, I'll give them what they want. And they go home and they'd have one fish in in the bag.
That's something that they should have gone through during your training though. Well, maybe they did, but it was in German, so I really wasn't that good at it. And maybe just didn't understand. So a string of odd jobs in Germany. That's awesome.
Yeah. And then I, the one that I was finally good at, I was actually did a, I was like a stock boy in a supermarket. And so that one, you know, not too hard. And then I finally, and also by that time I had learned to speak enough German that I kind of knew what I was doing. Good.
Well, that sounds fantastic. So, but why, why German? Why did you pursue that language like this? Uh, yeah, so excellent question. Um, you know, it was just something that was offered in high school and I, back then the only real offerings that I knew of anybody who ever took was French or Spanish.
So I was like, oh, that's something different. Um, so I decided that I would try my hand at German, um, which is a really difficult language and unfortunately, um, is also a language you don't get to use a whole lot. Right. So when I was looking to go abroad in college just for the experience, it just made sense to me that I would go to Germany where it'd be a place where I could actually learn, you know, use the language and actually really learn to speak it. And to me, that was a phenomenal experience because it's— as an adult, as a, you know, I guess at that point I was, I was 21 years old, going through and putting yourself in a position where you feel like a child again because you can barely speak the language, you know, and getting through it, it's one of those experiences.
It's sort of like the taekwondo thing where you feel like you're learning something that you absolutely cannot do and you take the time, you stay with it, and after a while when you get to, you know, within a year I was actually able to have fluent conversations with people in German, which to me was absolutely amazing. And so when you feel, when you go through something like that, you feel like there's nothing that I can't do. Yeah, that's awesome. So you graduated, you headed out to Colorado because it's amazing in Colorado. Um, what, what did you do when you got here?
Do you have a job lined up? Yeah, so it's, um, I didn't have a job lined up at all. Um, I got out here and I started doing temp work. Uh, I worked as a, um, uh, I worked as a, um, a temp in the legal department for, uh, Colorado National Bank, which got bought by US Bank. And then while I was there, I was, uh, correcting, you know, documents, um, or doing editing to legal documents, and then I was applying for jobs.
And one of the jobs that I applied for was in the tech industry. It was a company called CallUS. So it was a technology startup, and it was going to be the next Teletech, as it were. It didn't become the next Teletech. And what was interesting about it is that the people who were starting this company are actually the same people who are the founders of InteliSecure.
Um, you know, long after I had stopped working with them. So it was sort of strange to actually come in and get hired into InteliSecure, which is a company that was built by the people who originally hired me in Colorado and actually built up this successful company. That's pretty awesome. So, so how long did you do that job? So I was at that job, um, until the company went out of business for about a full year.
And then after that, I went and, um, it was interesting. I was a, um, I actually was in a sales role at that job. Um, and one of the things that I found incredibly frustrating was the, uh, ability to go out there and be able to make a sale, and then, uh, for the people who were supposedly able to, you know, supposed to implement the things that I had sold, to have such difficulty doing it. Um, I think that's actually can be pretty common, especially in a smaller company. Um, but I thought to myself, well, how hard can this be, right?
Um, and so before I left the company, I started pursuing knowledge, you know, my knowledge and, and some certifications within the IT world. So I went and I got my MCSE, or I started pursuing my MCSE. And you did that like without having any hands-on experience? You just went after the certification? Yeah, that's a tough one to just do from scratch.
So I started from scratch, and I, you know, and it was— what a weird time, um, to actually learn. So like, I remember it was just so difficult. Like, at the time I was so poor that I didn't have— like, getting— having your own computer was like a luxury. Right? So I would, you know, find these, you know, computers, or I'd go and I'd save up to, you know, and I would build these, you know, computers from scratch, uh, and, you know, using these, like, you know, putting a server on a 486 machine.
One of the things that I did have at the time was I was one of the first people, um, on the, um, uh, it was actually at the time was the AT&T, um, cable network. Um, and so it was one of the very— it was like broadband was just becoming a thing. And so AT&T cable was out and you could actually get that in your home. And I remember I would take DHCP server and I just throw it up on there. And the security was so poor that I was handing out IP addresses to people all over the— yeah, like all over Colorado.
I mean, I could just go and I could, you know, browse around and I could get onto people's networks. The firewalls were not in place anywhere. You just go anywhere and see anything. And it was just sort of amazing to me how, like, I had the pure access to go on and really just take down that network. Wow.
Um, you know, purely by accident. Yeah. So you, you did some self-education, and what did you, you know, what was your intention with that? You know, did you have a goal, or was it just, hey, I wanna get these skills and see what comes next? I wanted to get those skills, and I wanted to get into IT, you know, as a technician, as an engineer.
So I actually got my first full-on IT job working for Centura Health. So I was a desktop analyst in Centura Health, and that was when I actually, during that time is when I finished my MCSE. Um, and it was a, uh, you know, it was a, a great experience. However, it was also, you know, because it's such a large company, you're very pigeonholed in what you do. So you can like, you can be the desktop analyst, or if you want to go, you could work on the server team, you know, or, you know, maybe you could work, you know, in the networking team.
Everything was very siloed and very specific. You kind of did your own thing. And then what I ended up doing is I wanted to get a little bit broader experience, so I applied for a job with a company called Illumin. Illumin was a Microsoft VAR Um, so I was like, okay, this is what I'm learning, these Microsoft skills. I'm going to go work for Microsoft here in Colorado as well.
That was here in Colorado as well. And, uh, and I actually ended up working for them for 12 years. Um, and the beauty for me was on, you know, within the first week I realized I'm like, I don't just get to learn and get my hands and get all this experience doing Microsoft networking. I get exposure to everything. So I learned most of the, my security skills from, you know, I learned there, um, building, managing wide area networks, managing firewalls.
Um, you know, we were working with a lot of technologies that didn't even exist at the time. Um, we worked with one of the very first DLP implementations, um, with a company called VeriSept. We worked with, um, we worked with VPN networks, you know, before they were sort of integrated within the firewalls. So you used to have like a VPN concentrator and you'd know, and it was a great way at the time. A lot of people were— they were setting up wide area networks and spending boatloads of money on circuits to build these wide area networks.
We were able to reduce their costs significantly by building VPNs and just utilizing the internet for it and their primary internet connection. So it was a, uh, it was a great experience, and I worked with them for, um, for a long time and doing various roles in there. So I started out doing security engineering Um, and, and support. And then I ended up becoming the, um, uh, the marketing director, um, and helping the company— pretty big change— grow, right? And I was at the time, I was also getting, uh— so I got a, uh, an MBA with an emphasis on marketing, which is why I wanted to, you know, pursue that route.
But I always found myself in a role or looking for what does the company need me to do. And so, uh, I ended up taking on the job of the chief operating officer because the, the company had gone through so many changes it really needed somebody to provide that role at the company. And I realized that even though marketing was what I thought I wanted to pursue, I was much better at the operations side and I was better at the technology side than I was at the marketing side. Um, and so it was just something where I think I came to the realization that I was either going to stay with this company for the rest of my life or, you know, something was going to have to change after 12 years. Yeah.
And it was at that time where I had the opportunity to apply for a job at Smashburger. Smashburger was building their first, um, they were building as a company and they were hiring their first security professional. So actually, I think the job was Director of Information Technology and Security. So it was kind of a dual role, IT and security. And it was— they didn't, they didn't really have— they had one person, I think, at the time on staff as a full-time IT person.
Hmm, how big was Smashburger at that point? We're talking about 2012 here. Yeah, so at that time Smashburger had— it was probably less than half the size it is now. So maybe had 75 corporate restaurants and about the same number of franchise, so about 150 total restaurants. And now they're close to, close to 400.
So how many employees do you have in a corporate office? For in the corporate office, we had about 80 employees. Okay. Um, and then we also— and then we had a lot of people who worked remote. Yeah.
So, I mean, it wasn't, wasn't huge. I think total, total number of employees, uh, with computers was probably around 120. Okay. Um, at its largest. And, um, and so I did that, you know, for a while.
And then as things grew, um, I got to build out a staff there and build out a team there. I brought them through their first, um, PCI compliance Which was great, a great opportunity for me to learn, great opportunity for Smashburger to be able to continue using credit cards. Yeah, that's important. And having to use cash at a restaurant these days, not so good. And but, you know, as things developed, I ended up heading up the IT department in general.
And then an opportunity came along over at at Intel Secure, and I realized that the piece of, of my role at Smashburger that I really liked was the security piece. And so when the CISO position came up at, um, at Intel Secure, I thought to myself, you know, I could continue working here at Smashburger and enjoy it, but it was never my dream to become like the, the head of the IT at a restaurant company. That's not where I kind of saw my path going, and this gave me the opportunity to get exposure to and work with different areas of security that I didn't otherwise— wouldn't have otherwise had the opportunity to work with, and I've really, really enjoyed that. There's a lot more compliance work that I do. I came— got hired on just as GDPR was coming, so I've learned a lot about privacy, and privacy is a big aspect of me, but I also still— the entire IT department also reports to me, so I was thinking of changing my title from Chief Information Security Officer to Chief Information and Security Officer because it really describes sort of what my title is.
Uh, very interesting. So you've had, you've had some interesting roles, you know, from going at marketing, IT, security, COO, a lot of different stuff. Do you feel like, you know, now that you're working at a company that focuses on security, that you're able to, to leverage those different skill sets you've developed, you know, your MBA focused on marketing, the COO role you were in, that's been something that's impacted how you do work at InteliSecure? It's impacted not just how we do work at InteliSecure, but how I do work in general. I think when you get into a CISO position, you're getting into a leadership position, right?
A leadership position, um, in any business is really more of a business position than it is a technology position, even though a lot of us have come to kind of come up through the ranks of technology. The things that allow people to be successful in those positions are really understanding accounting, understanding marketing, understanding how the business works, understanding relationships, understanding the legal aspects of the business, all the things that you're not gonna learn when you go and get your computer science degree. You're not gonna learn when you go and get your certifications. There are a lot of things that you really have to, learn from a very, um, the experience of working in the business world, but also having a broader, uh, broader exposure to a variety of different things. And I think anybody who's had the opportunity to step outside of their technological role and perform other duties within an organization, such as marketing, such as accounting, such as legal, is going to be far better off in a position, uh, like as a CISO than somebody who's strictly come up through the ranks of technology.
Yeah. Can you think of specifics, you know, in your day-to-day job where, you know, that kind of background and that breadth of experience allows you to do your job differently? And I know it's— that's a tough question, but I'd love to hear, you know, the kind of ways that applies so other folks can think about it in their own jobs. Um, I think one of the ways it— and I think that privacy is probably a good, a good way of understanding it, because when you go through and you do a privacy assessment— so let's say you're doing like a data privacy impact assessment— really you have to think about it from a variety of different ways because ultimately what you're trying to do is you're trying to understand what privacy data we're keeping and how we're using the privacy data. But to really understand that, you need to understand it from a vendor perspective, you need to understand from a technology perspective, and you need to understand from a process perspective.
And to truly understand the process, you need to understand the business's itself. So in other words, you're not just thinking about the process in terms of inputs and outputs. You're thinking about, let's say you're talking about, I'm doing a data privacy impact assessment on background checks. So I have to understand, well, why do we do background checks? What is the information that we have on background checks?
I need to understand and spend a lot of time with the HR department understanding what the HR department does, why they do it, what their reasons are. I have to understand the regulations that HR and is, um, has to adhere to. I have to understand also what is the, what is the financial impact of doing these things? How does this drive the business forward? I think one of the biggest challenges that we have in security in general is that we know what the threats are and we know what it takes to mitigate the threats, but what we oftentimes struggle is helping the business understand how our ability to identify threats and mitigate the threats actually translates to a positive impact to the bottom line.
Because— and that's where a lot of, um, I feel like security professionals really struggle, is they, they feel like they're speaking a different language than the businesses. And the reality is they are. You really need to understand what drives the business and why the business is, uh, making the decisions that it's making, because the decisions that the businesses are making are all about what do they want to build. Oftentimes they're financially driven, and if they're— or it's going to be an investment that they're making for some greater purpose. But you really have to understand what is the thing that motivates the business, why it's doing it, and then how does your piece play into that.
That's hard for a lot of people to really make that, uh, make that connection without having a broader background or a significant amount of experience. Yeah, I think privacy is an especially interesting one there because, you know, if you come at it from a security guy's perspective, you know, or even just a binary perspective of, hey, you can or cannot do that, it makes a big difference for the success of the business, right? And understanding in marketing that, you know, if I'm not allowed to, you know, to require people to opt in when I give them this content, maybe I'm changing my entire business model, right? Maybe the pipeline for my company goes, you know, goes from, uh, you know, $100 million down to $20 million because, you know, 80% of my pipe was generated by this, this type of activity. Um, and, and how does that impact things, right?
And I think with your experience in marketing, you can see both sides of that and you can have a much more nuanced conversation. Yeah, one of the things I think is, is the scariest for us as security professionals is this, uh, concept of that you hear coming out of Silicon Valley a lot, which is, uh, move fast and break things. We all want to help our companies be able to move fast so they can take advantage of the market and take advantage of opportunities, but we're also terrified that the faster we move— if we move so fast that we don't take the time to do all the things that we're supposed to do, we're going to put ourselves in a very vulnerable position. And so figuring out how to do that and helping the company understand what the risks are and what they're going to do and helping them make those decisions Um, is critical. A long time ago, I used to be the guy who would say, no, you know, you can't do this because this, that, and the other thing.
I'm not the no guy anymore. Now I'm, hey, this is what this decision is going to result in, right? Here's the— I'm the— here's the risk. I'm the risk guy and the impact guy, and I explain that, and I say, let's, you know, make sure that we're doing this according to the process. So there's a big part of the governance and risk piece that goes into what I do as security professional that I think is key to helping security benefit the business.
So as you came in there, I think you came in about 6 months before GDPR went into effect into Telesecure, assuming that you had some significant work to do, what did it look like for you to apply privacy by design and really those consumer rights to your organization? How did you go about doing that stuff? Well, the problem is that when you're applying something like privacy to existing processes, you can't apply privacy by design, right? It's already been designed, right? And all of a sudden you're, you're, you're reapplying privacy to it.
So you have to first of all backtrack that way, and you have to go through and say, well, how does privacy fit into all this, and how do we apply that on? And then you go, well, how do I have to change things to then incorporate privacy by design. I think that's— that was one of the big challenges, and a lot of it has to do with how we go about implementing our processes. So everything that we do at— sorry, at Intel Secure is risk-based, right? So everything goes through a risk management process, and now we're designing the privacy piece into the risk management process.
So that's a part of it. So anytime somebody goes Hey, I want to bring on this new vendor, or hey, I want to create this new process, or hey, I want to, you know, use this new technology. There's nothing that can get purchased at Smashburger without first getting approval from the security department. And the security department then makes sure that everything goes through the proper risk assessment, make sure that goes through the proper privacy assessment. And so it allows all that, you know, all that to happen.
Sometimes we get we bring the privacy or the security a little bit later than we want to. And in those cases, what ends up happening is we may have to say no to something. But when we get— usually what happens, and because as an executive at the company, I generally have a seat at the table before things get decided, you know, and say, hey, we're thinking about doing this initiative, this, that, and the other thing, I have the ability to then inject privacy at the feasibility stage so that we can actually talk about the privacy piece before we actually get so far down the road that we're applying it later than we should. I think it'd be useful to take a little bit of a segue for you to describe what InteliSecure does. You know, I think a lot of folks listening will know, but probably not everybody.
So what are the— what's the breadth of the, the things that you guys do over there? I think the best way to describe InteliSecure is that we're a managed services company that focuses on protecting sensitive information. So in the CIA triad, we are heavily C-focused. It's about confidentiality. And so we have a suite of services that are designed to help companies identify the information that they want to protect, you know, what they deem to be sensitive information, be it trade secrets, be it just confidential information, be it privacy information, personal information, and then help them develop a program that actually makes sure that that information doesn't get unintentionally or, um, and sometimes intentionally in the hands of the wrong people.
Yeah. So, um, to that end, uh, the suite of services are focused around things like data loss prevention technologies, probably what we're best known for. There will be CASB solutions that go along with that. We do penetration testing to help identify and help people understand their programs. We do SIEM implementations as part of that.
And I wouldn't say that we're like a SIEM company, like that's not our— our SIEM focus is usually an addition to a lot of things around data loss prevention, CASB. We're starting to look at like behavioral analytics insider threat. We do have insider threat program that we do because— but it's all directed around the idea of protecting sensitive information. And I think that's one of the things that makes InteliSecure unique, is that while we are a managed security services firm, we're very focused on one specific area and being the experts at managing sensitive information. Um, it's, uh, we don't do managed firewalls, we don't do security awareness training, you know, there's a lot of things that people look to and think about us when they go, oh, they're a managed security service provider, you do this, that, and the other thing.
And we're very quick to let people know what it is that we don't do because we're a smaller company and we don't want to be a jack of all trades. We want to be very, very good at the one thing that we do. Yeah. And that's around the data protection. About how big are you guys as a company?
So we have about 150 employees, um, and, um, we have offices in— our main office is here in Denver in Greenwood Village. We have another office in the UK. All the services are offered in both offices. We do a lot more pen testing out of the UK than we do here in the United States. Yeah.
And, but we do the same DLP managed services, the same SIEM managed services in both locations. Okay. So, you know, obviously as a CISO at a company that offers exclusively security services, you know, you're going to have you're gonna have a different role than, you know, than you did at a restaurant, right? Absolutely. So how much do you get to be involved in the development of new services, you know, as the guy responsible for internal security?
You know, what, what part of that is product-focused or service-focused? So, um, I would say it's, um, surprisingly more than I thought it would be, uh, which is nice. Um, so anytime that we're developing, uh, a new offering we realized that in order to— for as a security company, you know, we, we have a responsibility. I mean, everybody has a responsibility, but it's even more of a responsibility as a security company to make sure that you have all of your security concerns addressed, especially if you're going to be working with companies who are evaluating our products and saying, okay, well, help me understand, you know, if I'm you know, going to store data with you, if I'm going to allow you to view some confidential information. And reality is that we have, you know, based on the services that we provide, we have access to potentially some pretty confidential information.
So people need to very much feel assured that we're doing what we need to be doing in order to protect that information. And, and it's a privilege to be able to have access to that information, and people need to feel confident that we don't abuse that privilege and that we are doing all the things that we're supposed to do in order to protect it. So to that end, we don't create a new offering without bringing the security team in. And, and we're in Scrum meetings, you know, on a regular basis that will come in, especially if we're putting together a new product offering where we're evaluating things, going through assessments. We do a lot of assessments on our own, on our own, and we we adhere to certain, um, to certain compliance requirements that require that we do these things.
So we're adhering to PCI compliance, we're adhering to— we're ISO 27001 certified, um, we have to adhere to, uh, to HIPAA and HITRUST, um, and we have to adhere to GDPR. So we have all these things that we need to be able to go through, and anything that we come out with our clients are going to then come back to us and say, show us how you're complying with this, show us how you're protecting this, show us how you're doing that. So unless security is involved from the beginning on those initiatives, there's no way we'd be able to provide that to our clients. Right, that's great. As you look at 2019, the rest of this year, what are your biggest priorities within the internal security program for Intel Secure?
Biggest priorities, uh, this year— we spent— we had a lot of change last year. We had a lot of employees, uh, changing over, and so a lot of the initiatives that we're doing, um, we, we've spent a lot of time going through and updating programs that we've had before. So because I came in, you know, just slightly over a year ago, I came into a program that was actually fairly well developed, but it's aged. And so there are a lot of things that need to be adjusted with how we, uh, how we manage the security program itself, identifying the things that are no longer relevant for us, the things that are, are outdated based on, uh, the, the way that we're doing business today. And so we spent a lot of time going through and just updating processes, policies, and things like that to— not so much policies, but more like processes to match how we're actually doing business today.
So we spend a good amount of time doing that. I'd say that privacy and GDPR is an ever-evolving thing for us. I think spending as much time as we possibly can and making GDPR easier for us. So one of the things that we implemented recently that I'm spending a lot of time on is we just signed with with OneTrust to help us put some structure around our privacy program. And so getting in and making sure that I'm getting all of my assessments in there, making sure that we are using that to track all of our consent records, and in order to also track all of our information about vendors and getting all of our due diligence within that.
It's a it's a labor-intensive thing because it's a lot of copying and pasting and putting things in, but when it's all said and done, it'll be nice because it'd be very well organized for us. That's awesome. Yeah, I've heard it. Maybe just summarize what, what exactly does OneTrust do and, you know, what are you planning to use them for? I know I'm familiar with them, but lots of folks listening might not be.
Yeah, so OneTrust is actually— it's, it's a nice solution. It's, it's an online, um, solution, uh, that is, uh, software as a service basically, that allows you to manage your privacy program. And it actually allows you to manage more than that. So It's a great way of, um, you know, we, we got it for primarily for GDPR compliance, um, in order to make sure that we were adhering to all of the elements of GDPR and that we had it all organized and stored in a way that was very easily accessible for us. But it also makes the process so much easier.
So for instance, vendor management, you, you know, you can use it to send out your questionnaires to vendors, and vendors basically Basically, you know, log in, they fill it out. They also have— Is it just privacy for vendors, or is it all? No, it's privacy and security, and you can put any questionnaires that you want to. So if you have your own personal questionnaires that you do that's unique, you don't have to use their canned questionnaires. So you can do all kinds of assessments, you know, and you can put them in there and really manage your vendors, because I think that's one of the hardest parts about GDPR is making sure that you have all your ducks in a row with all the vendors that you're using.
And not just your security vendors, and we're talking about anybody that you store anybody's name, and we're not just talking PII. The definition of personal information per GDPR is so much broader than how we define PII here, and so it just makes you responsible for doing so much more, especially when you're managing vendors, and, and it's a great tool to help us do that. Uh, as you hire folks within your team at InteliSecure, what are the skills you're looking for? And, and you can go from you know, entry level? I don't know what kind of roles you hire, but at the entry level or more experienced, what is it you're looking for?
Well, I wish that I could say that I get to hire a lot of people on my team all the time, but, um, things being what they are, you know, we have a pretty small team. Um, and so it really depends on the role that, that, that we have. Uh, we have far more— uh, there's far more IT people on my team than there are security people, and there are people who play a dual role. Most of the time when I'm hiring somebody, I'm looking less for, um, less for experience. I'm looking a lot more for aptitude and attitude and a desire to do what you want to do.
I think that the work that we have to do is pretty significant. There's a lot of work that we're doing with a small team, and I— but I think the work is important, and I think you can only be successful doing that kind of work if you really enjoy and want do what you're doing. In other words, you kind of look at this and go, this isn't just a job that I come to, like, this is part of my purpose and what I do, and this is kind of my purpose, and, and I'm making the world a better place because I'm making the world more secure. If you don't see things that way, I think that it's very easy to look at these jobs that— I mean, cybersecurity sounds exciting, but we all know that it's not nearly as exciting as it sounds. There's a lot of, you know, tedious work that goes along with it, what sometimes seems like busywork.
Compliance work, that sort of thing. Change management alone just seems like it's, you know, a lot of work to go through just to make a firewall change, but there's a reason behind it. And so I am always looking for people who've got that, um, that passion, who've also got the desire to work. And then the— I say the one skill set that I think is most fundamental to being successful in this industry is resilience. It's the ability to, uh, recognize when things are changing and to be able to change along with them and not be so rigidly stuck into the way you think things have to be done.
Because if you can't change like that in an industry that is constantly changing, you'll never be able to keep up, and you'll find yourself in a, in a situation where a job that you used to love is now a job that you don't like because they don't do things the way you wanted to do them. Yeah. I guess my last question for you, and then I'll let you share anything else you want to. My last question for you is, how do you see your job or InteliSecure, or even just the industry if you want to, changing over the next couple of years? Where are trends taking us for the big picture?
And, you know, so the rest of us can start to get prepared for that. It's a really good question. You know, I don't know if I'm really the best visionary when it comes to this kind of thing. That's why I spend time listening to the podcast, so I can find out from very smart people who, you know, have their pulse on these sort of things. But, you know, I think that, you know, the biggest change that I've seen so far, and I think it will continue to go that way, at least in the security side of things, is that security becomes less of a technical enterprise.
It becomes much more of a of a business exercise, really focused around risk more than anything, helping people understand and manage risk, being that go-between, you know, from the executives to the technological teams to really help them understand how the technology impacts their business. The reality is that technology is here to stay, um, you know, there's our— and it's, um, changing in such rapid manners. The fact that we now have, you know, apps or things, in fact, we're putting so much in the cloud Um, it's no longer a question of, you know, do we put things in the cloud? Uh, the question is, okay, we have stuff in the cloud, how are we going to manage that? What's the risk that we're going to take?
What are we willing to take? How are we going to deal with that? And, and I, I think as the, um, as we continue to, to move beyond those old days where companies would have, you know, large IT departments to support, uh, the infrastructure for something that really had nothing to do with what they did. Um, it doesn't make sense, right? So we're outsourcing way more, we're relying on vendors way more, and you can't just go, oh, that's not our problem anymore.
It's still our problem. We're still responsible for all the risk. We're still responsible for understanding and putting in the controls that we need. That's where I think from the, from the security perspective, our jobs are going to be much more challenging because we need to be able to provide that information, help the business do the things that they want to do in a way that's going to meet their risk tolerance. That's kind of been our— I felt like that's my job from the beginning, and, and it just continues to be that job even more so going forward.
Awesome. Well, that's it for my questions for you. Anything else you wanted to share with the community? Um, I don't know if there's anything in particular that I want to share with the community. Uh, well, the only thing that I can say is, if anything, I'd like to to thank the community.
I think that, um, the community here in Denver is, is amazing. Uh, there's so many great resources. There are so many brilliant, smart people in here who have, um, had experience seeing the things that, uh, most— none of us, you know, can have seen everything, right? And so it's just the fact that we get to get together, the fact we have something like Colorado Equal Security to bring, uh, groups like us together, the RMISC, that we get to know each other and learn from each other It really allows us to be better professionals. It allows our companies to be more secure and to be managed in a better fashion.
So I'm really thankful that I get to work in this community. So less of a comment for the community, more than a thank you. Awesome. Well, that's great. And we appreciate, you know, your contribution and look forward to getting to talk to you more in the future.
Great. Thank you very much. DC, thanks a lot for your time. And for everyone else, this is it for Colorado EcoSecurity. We'll see you guys next week.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.