All episodes

Kerry Matre, Product Marketing at Palo Alto Networks

Apple Podcasts Spotify SoundCloud

In this episode:

Kerry Matre, running Product Marketing for services at Palo Alto Networks is our feature guest this week. News from: Amazon, Zayo, LogRhythm, Coalfire, Richey May, InteliSecure and a lot more!

We’re number 19! (still)

We’ve got 44k new friends and neighbors. Soon apps are going to find us street parking downtown. New CIO for Colorado focuses on opportunities in digital government. Zayo may soon be acquired. LogRhythm, Coalfire, Richey May, and InteliSecure all drop blogs on us this week.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10310 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 114 for the week of April 22nd, 2019. Alex, Easter— are you, are you doing any eggs this year for Easter?

You know, I went out and I searched and I searched and I searched. I didn't find any. Well, I don't know what happened. For bunny eggs? Yeah.

You know, the bunny comes and lays eggs. That's exactly right. My kids were actually just decorating. Actually, one of my kids was decorating eggs. The other one, not so interested.

No. Yeah. And we didn't even try this year. Yeah. Well, my kids are a little bit older, so they didn't want anything to do with it.

But it is beautiful weather Saturday of the weekend. A beautiful, you know, 78 degrees. I got a little sunburned. Did you? Yeah.

Were you— were you out sunbathing? I was actually at a soccer game. That's even better than sunbathing. Yes. I cut down a tree this weekend, as I did last weekend.

2 trees in 2 weekends. Way to go, George Washington. Yeah. I had my sprinkler guy came and said that the roots from one of the trees was destroying my sprinklers and he'd fix it, but why bother? Because he's just gonna do it again soon.

So I had to cut down some trees. He found the root of your problem. I like it. You know, last time you told a dad joke, people were really appreciative. They were.

All right. Hey, let's go ahead and move on. We have some housekeeping to talk about. There is a Slack channel. That's where your dad joke was being appreciated on the Slack channel.

Exactly. We have what, like 870-ish people in the Slack channel. This is a good way for you to come meet local folks in the security community. We also have a mailing list. So if you go to the website colorado-security.com and go all the way to the bottom, you can sign up for the mailing list there.

You will get the show notes in your email. You will be one of the first people to know that there is a new episode. We would love it if you would rate us and review us on your favorite podcast listening app. You know, app— the iTunes podcast, uh, app would be a good place for you to do that. Give us 5 stars.

We get— find more people to listen to us. Uh, we are the number one security podcast in Colorado, and we would appreciate it if you made sure everyone knows it. Um, also, if you would like to tell a friend about how wonderful Colorado Equal Security is, please do so. Point them to the website, have them subscribe to the podcast, Join the Slack channel, all of that good stuff. And finally, if you've done those things and you're thinking, man, is there anything more I can do to help with this podcast?

Robb, is there anything more that I can do to help with this podcast? There is. We have a Patreon set up. This is a way for you to help financially support the podcast. We would love it if you'd go out there and help sign up to, to give, you know, as little as $1 a month, as much as you want to go to help, to help go pay for the cost of the podcast.

None of this money goes back into our pockets. We give it right back out to the community either through the cost of the podcast or occasionally we'll, you know, buy some shirts that we can give out to folks or stickers. You know, we like to have stickers to give out. So we'd love it if you'd give us some support there. Wonderful.

Let's jump into the news first. Denver metro area has had population growth. Shocker. Well, this is, this is a basically we got the 2018 population growth stats now, you know, 4 months into the year we find out. That the, the area grew by about 1.5%, to be specific, 1.53%, uh, during 2018 with 44,188 new residents.

Wow. Denver specifically, by the way, not Colorado, right? Um, also over the past 8 years, the Denver metro area has seen rapid growth. Again, shocking. Uh, from 2010 to 2018, the population grew by 15.3%.

3%. And interestingly enough, we are the 19th largest metro area in the US. So we did not change based on that. We are just behind Tampa, Florida. Oh, yeah.

Who would have thought? Yeah, I didn't know that. I did know that. And I assume we still are. We are the smallest metro area to have all of the major sports teams.

I didn't, I didn't realize that. Yeah. Interesting. Are they counting soccer as a major sport? MLS?

No. No. The 4 big ones. Yeah, 4 big ones. Also, if you live in Cleveland, Pittsburgh, Buffalo, Hartford, Connecticut, or Rochester, New York, congratulations, you have a little more space around you because there are fewer people living there.

I think it's more likely that one of our listeners came from one of those places and they're actually part of these numbers. That is true. All right, moving along. Next story is around the future of digital curbs in Denver. So we have what we expect to be semi— coming soon is GPS driving directions that not only include the, the location where you're going, but also it will tell you when you get there all of the nearest street parking information on what the meter cost is and whether things are open.

And by the way, do you need to move your car for street cleaning? Yeah, it's actually an interesting, interesting idea. So this was a company that got spun out of one of the Alphabet ventures. And basically they have an app and some other things that you can do to go around and sort of map the curbs. You know, where are street signs, where can you park, and things like that.

So some of the stuff that, Robb, you were just talking about is sort of future ideas, but it's really interesting that, you know, you really see all of the stuff that's sort of going on in the city where places are busy, you know, at the curb. Yeah, and the company you're talking about is called Coord, or maybe it's Coord, C-O-O-R-D. Interesting to see what they're doing, and we expect over the next couple years to get some real value from that. It is also— it uses augmented reality for its application. So that's exciting.

I don't know what that means. I mean, I know what augmented reality is. I don't know how they're doing that. Yeah, I don't know either. Next, Amazon leased 125,000 square feet of office space in Q1 as the biggest deal around office space in the first quarter.

So there are— there have been several big deals and office space is continuing to get tight in Denver. The availability of overall space dropped from 18.7% a year ago to 16.9%, marking the 8th consecutive quarter of decline. Doesn't that still seem like a big number? 17%, 16.9%, 17% available office space seems like a lot, right? I have no idea what, what those numbers should be.

I don't know. But I will say I agree with the article that it feels super competitive. You know, the office that Ping is in is actually the same office that Sumo Logic is in. And we have a really hard time getting enough space. And, and actually, maybe that whole 17% is because it takes so long to build out space once you— once you get it.

I know we've had just ridiculous problems getting permits from the city and how long, you know, we're supposed to have moved in in middle of January. And, you know, now it's middle of April and we still haven't got the permitting done just because everything's so backlogged. One of the other things too is it did say that these numbers include areas that are under construction. So it could be, you know, someone is building an, you know, an office tower with a certain amount of space and they're considering that in those numbers. So That makes sense.

Well, good news for us that Amazon is investing here, even though they made a terrible mistake with their HQ2 choice. The number 2 for the quarter was Sunrun, which is the nation's largest residential solar power company. And they leased 118,000 square feet at 1515 Arapahoe Street. I'm sorry, they were at 1515 Arapahoe Street. Now they are at the John Mansfield Plaza Johns Manville.

I always get the S in the wrong place at 717 17th Street. Wow, I didn't know that. All right, well, our next story is actually a Q&A with the new CIO for, for the state of Colorado, Teresa Shizurek. Um, and she was really talking about what are the priorities for her in the new job. Some interesting notes here.

Um, basically, you know, of course the number one priority for her is making sure she supports Governor Polis's number one priorities, which are around things like cost reduction, getting more efficient, and bringing in more entrepreneurial spirit and creativity. Really looking for ways to optimize this pretty large team that they're running and do it so in ways that really, you know, get more efficiencies out of what they're doing. Yeah. And in the article, in several places, she mentions security. One, lauds the office of the CISO under Debbi Blyth and how good of a job that they're doing, but also mentions that they are rolling out MFA to everyone in the state government.

And also later on in the article, they asked her a question about a survey where the 50 state CIOs produced their top 10 priorities list and asked what her top priority would be. And she says that would be security risk. I love it. It's awesome that they're rolling out MFA everywhere. Another priority that they mentioned is getting broadband to all of the rural areas in Colorado, and specifically they think by 2020 they can have it to 92% of all rural areas.

So good stuff. Pretty cool. Next, there was an article in Built in Colorado talking about women sharing what makes working in Colorado technology unique. So they had— they talked to 6 different women who work in tech companies. I hadn't heard of a couple of these.

Havenly, the Turing School of Software and Design. They talked to Xero, the accounting company, RingCentral, Fair Harbor, and then, but one of our favorite local security companies, CyberGRX. Yeah. They had a woman, holy smokes, there it is, Courtney Cohen, who is the senior project manager there, really talking to her about what makes Colorado a great place for tech employees. Yeah, so if you're interested in reading that, go check it out.

It is nice. One of the questions that they asked all of them, are there any local companies or programs, networking events, things like that, that, you know, you have helped you in your career? So check those out. I think that those are some pretty interesting answers. All right.

Next, Xeo, who is Colorado's own local telco company, they have a rumor of being acquired by some local private or by, excuse me, by some private equity firms. So the potential acquisition of them by some equity firms I'd never heard of— Digital Colony Partners, EQT, and Stone Peak Infrastructure— has taken their stock, which was at earlier this year all the way down like $22.82, up about 50% to almost $32, basically on the assumption that it'll go at a premium for whatever the stock value is. Yeah, and it looked like, uh, sometime I think either this year, earlier this year, maybe even late last year, there was a different private equity group that was trying to maybe do the same thing, and they had offered $30 a share and Zayo turned them down. So based on that, you would think that there would be some sort of premium over $30. Pretty cool stuff.

Uh, next, LogRhythm has a blog talking about aligning LogRhythm with the MITRE ATT&CK framework. So I thought this was really interesting. MITRE is a great way to think about, um, you know, kind of every step of the, the kill chain or the ATT&CK framework, the, the ATT&CK process when someone's trying to break into an organization. Once they're in there moving around, when they try and take data out, they what is it, 22 different areas that they want to look at to see if things, bad things are happening. And MITRE has come up with 223 techniques that you could use to say, you know, do we see these bad things happening?

LogRhythm is starting off by, I think it was creating 18, right? Yeah. So they're creating rules in their SIEM. They're going to find these techniques, present them to you so that you can, you know, track potentially what's going on versus the ATT&CK framework in your organization. Yeah, I assume, you know, it's not just a question of getting the rules from LogRhythm to parse your data.

There's probably a lot of work that has to go into making sure you've turned on the right alerts. Exactly. And then, but more than that, right? You have to have the right telemetry that, you know, hey, we might not even have a tool that would let us know that, you know, someone's doing these things on an endpoint and maybe you have to deploy new agents. So this is gonna be a way for you to really do kind of your own gap assessment to say, do we have the things in place that would let us know if these techniques were being used in our environment?

I could also see if you wanted to use it for testing too. If you turn on these techniques and then you go into your environment and say, okay, what if, let's simulate someone, you know, doing some of these attacks and you can see if you can detect those things as part of your monitoring processes. That'd be pretty cool. So, you know, generally I'm not a huge fan of packaged rules from a SIEM. I think that this is a pretty good example of how a SIEM can be a value if you can get these things right.

You know, it'd be really easy to make a lot of noisy alerts here that don't actually mean a bad thing's happening. But if LogRhythm's able to figure out how to, how to actually, you know, narrow it down to someone doing these things, actual exfiltration, and, and even better than that, right? Aggregate between these different rules to say, hey, we saw this one happen earlier, this one happened later. That probably, you know, adds fidelity to, to these alerts. That's a pretty high value thing for sure.

It does say that these are being developed by the LogRhythm Labs team, which is managed by James Carder. So James Carder, get it right. Don't mess it up, James. All right, next we have a blog from Coalfire around processing payments in the cloud. Um, I, I think that the first thing we'd say is, uh, you know, that's a good idea, you know, processing payments in the cloud.

And I think that the, the blog post is basically talking about, you know, 20 years ago it was a, it was a joke. You'd never want to do that. The cloud wasn't going to be secure enough. Over time, we think we've actually got to a place where you can do this a lot better. And, you know, what are the benefits of processing payments in the cloud, Alex?

Well, you know, there's plenty of benefits. One of the things they talk about in the article is even serverless computing. Um, you know, really you're only paying for the transactions that you actually, um, uh, perform, right? So you're not paying for actual infrastructure sitting around waiting for somebody to do something. If someone needs to process a payment, serverless transaction happens and you get, you as the provider get charged, you know, on the backend for that.

So you're really optimizing the amount of, uh, of cost you have for that infrastructure, right? It's, it's good stuff. You know, Coalfire is, I think they are officially the auditor for AWS, so they, talk a little bit about AWS security and, and really how, you know, by offloading this, these processes to AWS, you can not only get it for less money, you can also get it for improved security than what you can probably do internally anyway. Uh, next, Richie Mae. Um, some of you may or may not know Richie Mae.

Uh, they are local here in town and they're talking about, uh, are your passwords too complex? So this blog post really is talking about the NIST password guidance that came out I think it's even back in late 2017 at this point. Um, and in that guidance, they, you know, turned password guidance on its head from what it had been for a long time. Uh, you know, don't require, um, complexity necessarily. Don't require, you know, certain— you have to have one of this and this and this and this.

Um, you know, allow for longer passwords, allow for different kinds of characters. And they're just talking here about you know, what those requirements are and the results that you can get from using it. I do want to give a little caveat here. Don't run off and go take away all the complexity requirements from your passwords. Go read the NIST guidance first.

There's some things that come along with it that are huge mitigations for this. You know, before you turn off complexity rules, you should start turning on the ability to compare your passwords to a list of known breached passwords. So if someone can't use password123, Um, even though you have complexity rules turned off, because that would be something that would have shown up in a breach database. Additionally, the NIST guidance highly recommends using multi-factor authentication, so the ability to guess someone's password becomes a lot less critical if you also are behind MFA, and that keeps you secure there. So great guidance from Richie May here, kind of talking through how this password complexity works.

But be careful as you implement it, make sure you do it right, and keep your company safe that way. Finally, we have a blog post from InteliSecure, our local MSSP that focuses specifically on managing critical data for their customers. This is talking about their, uh, what do they call it, their Gold Nuggets program. Yeah, so it's an interesting concept. Obviously they can't go into war stories about their clients, but what they can do is, you know, collect a lot of the things that they've seen and best practices and talk about Um, you know, some sort of higher-level examples, the golden nuggets that they are pulling out of, uh, all the experience that they have to share, uh, you know, with not only their clients but other folks so that you can, uh, you know, hopefully protect your data better.

Yeah, I really liked this idea. So they have this gold nuggets program where they're using, uh, this as a way to do variable compensation for their SOC analysts versus, you know, instead of saying, you know, what's your mean time to close a ticket, they came up with this idea that Uh, everyone who finds a critical or a super valuable incident within one of their customer environments gets paid for it. If you're gonna go find, you know, that Alex is stealing information from the corporate network, well then, then the person who finds it gets compensated based on that finding. Well, you don't have to look very hard for that. And over time, they've, they started to find so many of these things that they've actually started doing competitions and start recognizing the very best of them.

They did give one example of a manufacturing company that had spent, I think they said like $30+ million developing some new products. And someone was taking that with them and was planning to move overseas and start developing their own competitive product to that. And because of their findings in the, from InteliSecure, that person's actually spending 10 years in federal prison. Uh, that is not overseas. It didn't make it, right?

Didn't make it there. All right. Well, that is it for the news this week. Go ahead and slide over to the Slack message of the week. We'll do a big thanks to Andre Gaeta.

Andre, we appreciate you sponsoring the Slack Message of the Week. And every week we get to recognize one of the folks in the Slack community for how they've contributed. And this week we are going to recognize Ben Ryder. Uh, congratulations, Ben. We appreciate your contributions.

Uh, this week that, uh, contribution was because Ben posted a story, uh, talking about why you should not put stickers on the back of your car. Uh, this is sort of an OPSEC story, right? So if you're You know, putting a, a, a mom and a dad and 3 kids and a dog sticker on the back of your car. Well, you're giving people a lot of information about you. And what school do they go to?

Um, you know, what are your hobbies? It was interesting, you know, to think that, you know, especially the, the example I think that he posted was the dad was in military, you know, was in camo, right? Well, okay, this dad's probably overseas a lot and maybe the home's gonna be empty at these times. You know, interesting OPSEC stuff. And I think, uh, an interesting thing to share and And maybe isn't gonna necessarily make me take my Colorado Equals Security magnet off the back of my car, but it will make us think about what we put on the car.

Well, and what I did say in the Slack channel is, if you do have something Colorado Equals Security on your car, people will clearly leave you alone because they know that you are a badass. So if you're looking for something to put on the back of your car that shows you as a badass, go to the— go to colorado-security.com, click on the shop button, and you can go buy all kinds of stuff from a zip-up hoodie to a sticker for the back of your car to a Colorado Equals Security thong. And this week, Ben Ryder will be able to do that because the prize for Slack Message of the Week is a $20 gift from that store. Good stuff. Well, let's go ahead and move over to our events.

As a reminder, we do have a calendar of events on the website. You can go out there and you can see we are pretty well packed with events through the summer right now. And there are events scheduled all the way out through the end of the year. So go out there and see what's coming up in the next couple of weeks. We'll go through those.

But first, as a reminder, we have a big conference in town, June, 4th through 6th at the Colorado Convention Center, the Rocky Mountain Information Security Conference. Never heard of it. Um, yes, uh, shaping up nicely. Uh, you should definitely go out there and register. Um, if you are at a large company and you have a large group of people that are going to be coming, uh, please reach out.

We would be happy to give you a group discount code. Um, also, you know, we've been giving, uh, some background on different things that are happening at the conference. Um, on the, the first day, we are having some, uh, paid either full-day or half-day trainings, so you should definitely check those out. We have a cloud security training, a threat hunting auditing cybersecurity training. There's one on strategic planning for cybersecurity leaders.

Lots and lots of good stuff there. Definitely go check those out if you want a little more in-depth you know, more than an hour-long talk on something. Should be good. Well, over the next couple of weeks, we also have a lot of stuff going on. On the 23rd of April, ISSA Denver has their Women in Security special interest group that's going to be getting together.

Also on the 23rd, the GDPR Meetup is doing Words of Wisdom from a DPO. On the 24th, ISC² Pikes Peak is having their April chapter meeting. On the 26th, SecureSet is doing a Hacking 101 Intro to AppSec. So generally we do not, uh, we do not put things from vendors directly onto the calendar, but this one seemed especially interesting. So for any of you who are interested in going to see Avengers: Endgame, there is a vendor who's doing an event and they're open to sign up for you.

So this is put together by ITS Partners and Symantec doing a private showing on opening day on the 26th of April. Go to the calendar to see the details. For full disclosure, I have seen a couple other vendors as well that are also doing showings. I believe DurSec You know, they always do it. How do you get access to that one?

A meeting. You go to the DurSec website, probably dursec.com. Go to the events, I would assume. I believe that there was at least one more. So if if you get caught in if this stuff gets caught in your spam filter, this might be a time to actually go through and look at it.

Next, on the 30th at the NCC, they are doing their Cybersecurity Essentials Attacker Target Sony Pictures Case Study. That should be interesting. It should be interesting. On the 30th, SecureSet is doing a capture the flag cybersecurity hackathon. On May 2nd, Splunk is doing their meetup.

This is a new thing that they're doing every month, First Thursday at Topgolf. So if you want to go hit some golf balls and talk about Splunk, check that out. And finally, the Cybersecurity Colorado Springs group is doing their Cybersecurity First Friday event on May 3rd. Go, go there and hang out with some folks from 4 to 6 PM. Sounds good.

Let's jump over to jobs. Robb, do you have any open jobs? I've got 2 open positions right now here available in Denver. Number one, we are looking to hire a junior product security engineer. If you're a developer, hopefully with some Java background, who's been interested in making the move over to security, this is the role for you.

We're looking for someone who will embed with one of our development teams and help make sure their security practices are solid. And if you already have that kind of experience and you've been looking to make a move from individual contributor to a team lead, we've also got a role for you there. We're hiring a team lead for product security that's gonna be actually that person's boss. We're looking forward to hiring that person here in Denver. So reach out to me on the Slack channel or send me an email if you have any questions.

Carbon Black is looking for a SOC manager up in Boulder. Recurly is hiring a senior security compliance analyst. Survey Gizmo is looking for a senior GRC analyst. Also, Survey Gizmo is looking for an information security analyst. Four Winds Interactive is hiring an application security engineer.

Sumo Logic is looking for a security compliance and privacy analyst. And finally, Coalfire is hiring a consultant who is a penetration tester. Nice. All right. Well, that takes us to the end of the news this week, Alex.

This is— I think we've got one of Mary Writz's interviews this week, right? Yeah. So as we talked about a couple of weeks ago, weeks ago, um, you know, we interviewed Mary and she is going to be doing a series of interviews, uh, with other, uh, women in security. Uh, the person she is interviewing this week is Kerry Matre. Uh, Kerry is with Palo Alto Networks.

Uh, she does security portfolio marketing around security and data privacy. Um, Kerry is also somebody that I have known for a long time and, uh, this is going to be a good interview. I'm looking forward to it. I think that takes us to the end for this week. You know, this is a milestone though.

Uh, Robb, this is gonna be the first interview I believe that we have that is not either you or I interviewing somebody. Holy smokes, that's true. That's pretty cool. I think, I think that is awesome. If there's anyone out there listening who's like, hey, I could interview somebody, uh, you're right, you can, and we would love it if you did.

Yeah, for sure. All right, cool. That's it. Well, we'll talk to you guys again next week. Sounds good.

Thanks, Robb. Hi, this is Colin Mariner, VP of Data Center Operations at HomeAdvisor. This is Colorado Equals Security. For Colorado security professionals by Colorado security professionals.

Hey, this is Mary Writz. I'm happy to be here with Kerry Matre. Kerry's had a really interesting career in cybersecurity spanning product development to security intelligence and marketing. So Kerry, it's great to be here. And hey, remind me, what's your current role at Palo Alto Networks?

So right now my job is product marketing. At Palo Alto Networks for their professional services. And in that, I also cover a lot of security operations topics because that's my background and we're kind of moving into that space. And so, yeah, that's where I'm at right now. So you and I have been in security for a long time, over 15 years.

More importantly, we've skied together all that time. Yep. We've done cat trips, we've done heli trips, but you are a mono skier, which is interesting, and you're kind of a big deal in the mono skiing community. You've been in Warren Miller films a few times. So what's the deal with monoskiing?

How'd you get into it? What is it? So I made the brilliant decision when I was about 21 years old that if I kept skiing, I was going to hurt myself. Had knee problems. And so I decided to take the safe route and switch to monoskiing.

Yeah. So, you know, for those who don't know what it is, it's, it's like, um, if you were to glue your skis together. So it's one ski, a little bit wider than a normal ski, longer than a snowboard. Regular ski boots, regular ski bindings, but they're right next to each other. So it's a lot of hockey stops, it's a lot of going really fast and then crashing very, very hard, but I love it.

I've been doing it since then. And you just got back from Monopalooza, where all of the mono skiers unite. I did. Once a year there's about 100 of us that get together from around the world, and we were up in Steamboat, and it was great, great snow, sun. It was a good time.

Yeah, it's been a good year for snow. Okay, well, back to why we're here, security. You've been in this industry since early 2000s, like 2002, 2003, which was before cybersecurity had hit its stride. So how'd you get into it? I took a different route.

Well, I went to school, I went to college for computer science engineering, and so I thought I'm going to be a programmer. And so during college and right out of college, I was a developer and I loved it, you know, creating new things, solving problems. It was great. And then I got an opportunity to join an ethical hack team. I had no idea what this meant, and everyone else on the ethical hack team came from a networking background.

They wanted me on the team because I came from an application background, so if I knew how to create the applications, I would know how to break them. Turns out that's true. That's how I tiptoed into security. Then from there, I got involved in some data warehouse projects, security intelligence projects, still on the development side where a lot of database work, but got more into What is an IDS sensor? What kind of data does it produce?

What can you do with that data? And then I kind of took that into security operations, and I eventually ended up in product marketing. And when I first ended up in product marketing, I shunned it and said, no, no, no, this is not for me. But it turns out I really like taking the technical concepts and putting the story around them so that anybody can understand them. And anybody can understand why I need this technology besides just because it's faster or because it has 6 levers instead of 5.

It's really telling those stories, and I really like it. Yeah, it's interesting because you and I have been in lots of areas of the product side, so managed services, professional services, product. Do you have a favorite? And it sounds like you like the storytelling. Do you like that for all of them?

I don't know, what do you like better? I really like, I really like the storytelling from the, the vendor side, and it's because I get to talk to customers and I get to understand all of their different stories. And they're all, you know, every single customer is different. They all have different, different motivations, different needs, and it's trying to pick out the similarities between them. And so as a vendor, you get to do that because you get to see all of these different customers see their challenges and say, oh, here's an industry trend.

Let's go solve that problem. I really like that side of it. Let's see. What have you been working on or thinking about lately that's interesting in the security space? Well, there are 2 things that are kind of really interesting to me right now.

One of them is I think that our metrics are terrible, and there's no need for them to be. What do you mean by metrics? So, for security operations, for example, we measure things like how quickly we're closing cases or how many cases we're dealing with a day. And then we report those up to C-levels and they don't care. That's not what they're into.

And so, I'm really thinking about the better way to do it, what they actually care about besides red, yellow, green charts. And I think if you just think about a CISO, what do they care about? They care about the that their company doesn't get hacked, that they don't lose their job. Ultimately, that's the motivation. So, you know, how do you get them the information that they need?

How do you build their confidence that when an attack happens, they're going to be able to handle it? So, one of the things I've been thinking about is there's 2 different things of that confidence. One is configuration confidence. So, do you have the right tools in place? Are you using the right features?

Are the tools turned on? If a developer turned off a firewall setting so they could test something, did they turn it back on? Basic things like that. The C-level wants to know, am I configured to best practices? Is my stuff up and running?

The other piece of that is the operational confidence. Do I have the right people in place and the right processes to use that technology to handle a breach? That's one of the things I'm really interested in. Let's find metrics that are actually meaning something, that don't make people scared, and actually inform the business. That makes sense.

The other thing I'm really into is everybody talks about the people problem. We don't have enough people. We don't have enough people. That's been chronic since day one. It's been the number one concern of CISOs for at least a decade.

But, you know, to me it's not just, oh, how are we going to hire them, train them, and retain them? You know, that's not the people problem. The people problem is caused by not using our tools well enough. And so it's finding this, this leap between, you know, if I'm doing a lot of research in how many tools SOCs use, um, and what percentage of the features of those tools do they use. Because if there's an average of, say, 40 tools that an analyst has to use there's no way that they're going to be able to learn all of the features and really utilize those tools.

I mean, they might use a feature or two out of each of them, but you're not fully utilizing all the tools. You have duplicate features that you're paying for. Your analysts are just overwhelmed. And so, what I'm trying to get at is, how do we have less tools, use more of them, and ultimately get smart people doing smart things? And so, that's the other piece.

So, how do you do that? Well, so, you need to have measurements. You need to have metrics. One of the things that we do internally at my company is we put a lot of tools into the tools, measurement tools in there that say, here's the percentage of features that you're actually using. And then we have studies on the side that say, if you did use this one more feature, this is how much time you would save of an analyst's time.

Or this is how much money you would save over a year. Just having that visibility built into a tool is important because then you're going to start using the tool more and you're not relying on the customer themselves to be burdened with figuring this out. Vendors should be able to tell you, yes, you're using all of my product or not. That's how it's going to start, and then we have to drive to— Is that just a trick trying to sell more of your product, or does that really help? No, I think it's actually using the technology that we have.

There's so much amazing technology out in the industry right now, and most companies aren't using it properly. You know, we used to joke about always becoming shelfware. We don't really have shelfware as much anymore, but we have, like, we turn on a firewall, for example, and have the same rule set that we had 10 years ago. I think that's dumb. You know, we should be able to do better as an industry.

So it's It's actually a consolidation of products instead of selling you more.

That's one of the things that's really interesting to me right now. You spent a lot of time— I remember back when we worked at Hewlett-Packard and you were running the customer advisory board, and you would study the CISO persona because part of product development is understanding your buyer. Security, it's often the CISO.

You spent kind of years talking with CISOs and thinking about what they need and want. How's that changing over time? What's the latest with that? It's interesting that my exposure lately has been to some extremely technical CISOs, which 10 or 15 years ago, they were technical but not to the state that they are right now. Not just, hey, how does a firewall work or how does an IDS sensor work, but I mean technical in cloud.

Like, what does cloud actually mean to the entire business? And they know all the little ins and outs of technology for the business, not just security technology. So that's a super interesting change. On the flip side, there are more CISOs that are audit, regulation, and compliance. Focused, and so then they're not the technical side.

So you're seeing this big chasm exist. And then even on the technical side, there's the CISOs that are driving forward, that are learning this technology and learning where their actual business is going, not just security. And then there's ones that are falling behind, really. And they're the ones that throw up the red flags everywhere. Oh, well, I can't adopt that cloud technology because I have compliance issues.

And they just throw up the red flag and say, nope, I can't move forward. That's the difference between the CISOs really leading the industry and those that are just kind of hanging in and trying to make excuses. Yeah. I've seen that too, presenting to CISOs. We always collect feedback when we do those big board meetings.

I have noticed the split of half people wanting more technical and half wanting less technical. And so, threading the needle for what's the right level of engagement in a big group of CISOs. The one thing that they all have in common is they all want to learn something. Now, it might be someone wants to learn something super technical or somebody wants to learn something more business, but they all want to learn something. I think when we're presenting to those CISOs, when we're talking to them, we need to keep that in mind.

They don't necessarily want to learn about the doohickeys of our of our products, but they want to learn like, hey, here's an industry trend, or, hey, here's a new identity and access management approach that people have been using. Here's a new threat hunting methodology. Those are the sorts of things that, oh, cool, that's something new. They can take it back. They can feel like, okay, this meeting was worth my time.

Yeah. So, that's it. Yeah. I found they always like to learn from each other too. Definitely.

CISOs don't nearly get enough time to collaborate with other CISOs. Right. Yeah. And it's fun to watch them too, because if you get, you know, 2 CISOs that are maybe in the same industry that are using some of the same technology, I mean, just the amount of them geeking out, throwing out random, you know, product names, or, did you just try this? Did you try this?

Yeah. You know, experience with different POCs of different technologies. Yeah. Getting to listen in on that is, is great.

I was thinking about— so you and I both were executives while having children, which is— we could generate an entire podcast just on giving birth to a baby and surviving maternity leave and untraveling. But it was interesting because we had kids close to the same time, and 2 months after you delivered your last child, you were flying to LA to record a campaign, an advertising campaign that was going to go on Mr. Robot. And I remember thinking, I never could have pulled that off. I was a hot mess at the 2-month mark.

What's your tips? You know, there's a lot of people that are probably listening thinking about family planning, but they want to grow their careers and think about becoming executives, what's your advice since you've done it? Right. Yeah. Well, first, so the story behind the LA trip was I had written a paper on the business of hacking.

I had written this paper, we did a big campaign on it, and so Mr. Robot in USA and HPE had come together to do this promotion, and I didn't want to miss out on it. This is a big deal. I didn't want to pass it up. You know, I, I made it happen.

Yeah, because I wanted to. And, you know, I think one of the pieces of advice is it's— you got to run your own race. Like, that would not have been the right decision for a lot of people, but for me it was, you know, I was 2 months into having a baby and it was my third child, so, you know, things were a little bit different. But I was like, you know what, we're gonna, we're gonna go on an airplane and we're gonna fly to LA. Yeah.

And we're gonna do this thing because, you know, it's something that you know, I wanted to do. But I think one of the, you know, the biggest piece of advice is if you want to do it, do it. You know, there's, there's people that, oh, I don't want to have a baby yet because I'm working on this piece of my, um, my career. And that's fine, but don't let that stop you. Like, if you want to go have a family, have a family.

It's not, it's not that you're going to have children and then your career is going to go down. Like, that obviously is not the experience with us. Yeah. Um, and so it's, you know, just, just keep going, just keep doing it. Um, if you see an opportunity that you want, do it.

If you want to, you know, start your family, do it, and the rest will fall into place. Yeah. I remember I was so proud of myself because I was thinking, I'm leaning in, I've, I've had a baby, I read Sheryl Sandberg's book, and I'm leaning in. And I remember reporting back to my friends saying, hey, I leaned in and I fell over.

But, you know, I've recovered. You get help and you figure it out. But there's moments of feeling overwhelmed, but a lot of people out there can support you. I agree. It's all possible.

It's all possible. Yeah. And I mean, you know, over the past few years— so I have 3 children— over the past few years, I've flown about 50,000 miles a year. And, you know, there's sometimes when I'm on an airplane being like, what am I doing? I'm going to fall over.

Yeah. And then I get to the end of the year and I'm like, you know what, look at all that, look at all I did. Yeah. Because I didn't, you know, I guess I just kept going one foot in front of the other. You just kind of keep going, uh, and it all does, does work out.

So, you know, for those that are younger in their career trying to figure out when they should have a baby, what's the right time, whatever. Yeah. When you're ready, do it and it'll fall into place. Yeah. So Yeah, I guess we're proof that it can work.

It can work and you can survive and thrive. Even in cybersecurity. Even in cybersecurity. Cybersecurity is male-dominated. I would say it's about like 90/10 split, and really it has been since I started in 2001.

I would say I've seen some changes, but I don't know that that's meaningfully changed.

I often mentor women that are thinking about entering cybersecurity or are new, but I'm curious, you probably do too. What's your advice and thoughts to those ladies? I mean, there are some days where I would say, don't do it. That's joking. I mean, of course, it's a great industry.

I mean, it's served me very, very well. I've gotten to do amazing things. I got to work for great companies, meet cool people.

But I think advice to them is you're not going to have the plan from the beginning. I mean, I didn't think I'd ever end up in security, let alone in security and then in product marketing and in security operations and all of these things. These opportunities came up and I said, yes, let's do that. Why not?

That's a lot of how security happens. Yeah. Especially when we started. I mean, people didn't, you know, go to school for computer security. You just kind of ended up in it somehow.

I was talking to a friend earlier today, and she ended up— what did she study? Anthropology and French. That was her undergraduate degree. She ended up getting a master's in high-tech marketing, but that's how she got into cybersecurity recently, or was that a long time ago? Like 2 years ago.

Yeah. And so even now, it's— people end up in security in random ways. And I think, you know, just take the opportunities that come along. Yeah. If you want to— if you want to do something like— if you want to get into sales, work your way there.

Yeah. Um, you know, there's not going to be the perfect course There's not going to be the perfect person holding your hand, but one of the things that we have between us that's great is you build that community around you. You build those friendships, you build those contacts, and then your career kind of follows the opportunities. A lot of them come from those groups, those industry groups that you're in, or the friends that you meet.

I find my advice ranges depending on the point in a career somebody is. Early days, that network is incredibly meaningful. So finding the people at work that you can connect to and hang out with at conferences and really get close with, not just like, I've worked with you and I would write you a recommendation, but like, I went to your wedding and I know your family. Those are the kind of deep, meaningful connections that can give you really incredible job opportunities. It can be a little tricky gender-wise to do that with the gender imbalance, but I found it possible.

But I think the key really is building out your network. For me, one of them was meeting you, and then we would go to conferences together, and I felt comfortable, and I don't know, it just gave me a nice space to navigate. And having somebody to talk to that you can relate to. Yeah.

Yep. On many different levels. Yeah. I mean, the networks are huge. And also, you don't have to do the same things that the rest of your network does.

So, we have this community that we've kind of built over the last 15 years in Colorado. And I've gone the marketing route. Some people have gone the sales route. Some people have gone the CISO route. Some people have stayed on the vendors.

I mean, the fact that everybody is doing something different is fantastic. That's better for all of our careers that we've all gone in different ways. So, one of the things is run your own race, follow what's important to you, and it's all going to work out for your whole network. Okay. So, with all your years working in different parts of cybersecurity, What are some of the more interesting things you've worked on or things that have been the funnest places to be?

The most fun. Well, so back in the day, we were creating one of the first security data warehouses. So this was before we could handle a ton of data. We were trying to handle a ton of data and trying to figure out how to do that. I mean, it was new and revolutionary.

Nobody had done it. You look back at it now and you're like, shoot, we could have done that in 15 minutes with the cloud. But back then, it was a big deal. So, that was really, really cool being able to do that. I think for a while I was writing the State of Security Operations reports for HP.

I loved those because, you know, you get to— And these were reports that were— remind us what these were. So, these were reports that we did yearly based upon analyzing security operation centers. So, you guys as consultants would go around looking at everybody's SOCs across the globe and get a pulse of what was happening. Exactly. Trends.

Exactly. Find the trends, find what's working, what's not. You get the views into what people have tried and failed at. It's compiling all of that into these yearly reports for the industry. That was super exciting just from the access of seeing all these different companies.

You would never be able to do that as a company itself. You only get to do that as a vendor. I do love that. That is the fun side of the vendor side where you get you get such insight into hundreds of— for me, it's usually large companies, but seeing how everything's working, what tools they're using, what problems they have. Pretty fun to do that.

And then I'd say the other thing is I've gotten to speak at a bunch of conferences, including RSA, and then RSA and APJ, a bunch of just company conferences, healthcare conferences. That's a highlight for me. Because again, you're getting to take what you see as your current state of the world and be able to share it with other people and kind of move the industry forward. That's really exciting to me. What are your tips for getting accepted into RSA?

It's pretty hard to get accepted. Because you got accepted not as a vendor sponsor. Correct. Kerry Beatty herself. That's right.

I think, you know, one, you have to have an interesting topic that's not overwhelming. So, you know, if you want to get totally into the weeds, do it in your presentation, not in your title and your abstract. The other thing is really work on your bio because a lot— 99% of biographies that you read in the speaker bio notes are the exact same. So-and-so has been in the industry for 15 years. They started out in blah.

They graduated from whatever school with whatever degree. They are the exact same. Don't do that. You want to look different. You want to look different.

You want to say, you know, how are you different? Like, you know, one of my biographies just talked about, you know, once I got into ethical hacking, I wanted to burn every piece of code I'd ever written. I mean, that's truthful and people understand that. And so, you know, I think that's a key to getting, you know, it definitely helps you to get accepted to RSA. But again, topics that are different.

Yeah. They like topics that are real use cases. It's going to help you out. Yeah. So it's fun.

It's fun. I like, I like the public speaking thing, which again, just saying yes to opportunities. Yeah. When I started the industry, there's no way I would have ever thought I'd be up in front of people speaking, and now I love it. So you cannot plan out your career from the beginning.

Did you start out scared of public speaking? Oh yeah, I was terrified. And so, um, I just did it over and over and over again. I actually took courses through the Denver Center for Performing Arts, and they offered some really amazing public speaking courses for business. So you have these, um, you know, theater voice trained teachers, and they're teaching business people how not to look like robots up on stage.

And it's, you know, it's beyond Toastmasters and beyond, you know, look over here, picture the audience naked. It's way more of how do you use your voice? Yeah. How do you put in the correct pauses? Right.

How do you make sure that you sound interesting? Yeah. And then it's up to you to actually say something interesting. I once took a public speaking class. I used to do a lot of that too, but early in my career, it was very good for me, but they would actually make us stand up and talk about some security topic because I was in security, and they would videotape you and then make you watch the videotape in front of the class and critique you.

That's terrifying. Oh yeah. That's what these courses did as well. And then they would critique you in front of the rest of the class so that you could learn. But it hurts at the beginning, but after a while, you're just like, okay, this is helpful.

I do think it's a valuable skill if you're on the vendor side of security. You've got to be able to— well, at least a lot of the satisfying parts of my job have been if I'm comfortable enough to speak in front of an intimidating audience, that has served me well. Whether it's a big conference audience or important customers, but being able to, even if you're deeply technical and also leading a pen testing team, you still have to stand up and talk about it. If you can do that effectively, it can be really great for your career. It's good to be able to articulate important ideas in meaningful ways.

Right. Practice is the way that you're going to get there. Just do it and do it and do it until You're not scared of it anymore. Yeah. And you learn how to distill your points down that you want to say, so you're not just blabbering for half an hour because you have a half an hour.

Yeah. But you're actually saying, you know, here's the points I want to get across, and you just get better and better at it the more you do it. Yeah. Speaking of cons, I was just thinking today about— you remember DEF CON? Well, it's still a thing.

Have you gone? Okay, when was the first time you went to DEF CON? Was it at Alexis Park the first time you went? It was. Yeah.

So, early 2000s. Have you gone lately? I went last year. Oh, how was it? Well, I was completely intimidated.

I don't know, man, I'm not sure I could go back. It was so many people. The thing I'd always loved about those conferences was the size where I could— the size of it enabled me to sit at a table and learn how to pick a lock or solder something. So, it ignited the curiosity in me, and it was so big I just felt intimidated. But yeah, but any good stories from the Alexis Park days?

Oh, not that I'm gonna tell publicly.

No. Um, you know, back in those days, there were even less than a 10% female attendance. Um, and it was really funny because people would sit down next to you and just want to tell you about what gear they set up in their basement. And they were so joyous and so excited that they get to talk about this that it just made it a really fun place to be. It's what made me fall in love with cybersecurity was those early cons and just getting excited about the creativity of hacking.

And since I'm excited, I love the— I'll be in cybersecurity my whole life. I love it. But I feel like my love started really at those early Alexis Park DEF CON conferences. And they were also terrifying. They were terrifying times.

When I first got into security, it scared the heck out of me. You become this completely paranoid person, and you get to meet people, and back then it was like, oh, there's this thing called RFID, and you can read RFID tags. And I was like, no! Well, and everything was so hackable then. Totally.

Yeah.

So, so that, you know, the terrifying aspect of it. And at the same time, like, wow, this is really cool. Yeah, it is where I got my healthy fear for cybersecurity and knowing that literally anything can be hacked if you get the right people focused on it for long enough. Yep. And we don't want to become just callous and numb to that.

We still have that, like, a little bit of fear in us. Yeah. But you kind of accept that fear and you move forward and say, okay, what are we gonna do about it? Yeah. And here we are.

Well, what do you think? Did we nail this podcast? Should we talk about anything else? I think, I think we did, we did good for now, but we can do part 2 in the future. Yeah.

How about that? Well, it was fun to be with you, and, um, I'm excited to be on the Colorado Equal Security Podcast. I'm a longtime listener. Alex and Robb, thanks for everything you do. All right, thank you.

Okay.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes