Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 118 for the week of May 18th. This is Robb.
This is Alex. And Alex, could you believe the surprise ending to Game of Thrones last night? You know, it was really, really hard to believe that Superman flew in like that and destroyed everyone with his heat vision. I know, and really he did realize that they were a bunch of terrible, terrible people who needed to be ended. You know, he is a superhero, so those are the sorts of things that he did, does, you know, he relieves oppression.
But you know, I guess the way they tied it all in and shows how it fulfilled the prophecy, really, you know, it was a pretty good ending. You know, he is a prince, you know, we're looking for the prince who was promised. Yeah, so it was all perfect. All right, well, uh, before we dive into the news, why don't we do a little bit of housekeeping? Uh, as a reminder, we have a Slack channel, and Slack is a communication vehicle you can use to have live chatting with over 900 local security people in the Colorado area.
You know what? We also have a mailing list, Robb. If you go to our website, colorado-security.com, you can sign up for the mailing list at the bottom of the page. Well, you'll get the show notes in the email just as soon as they are available. You'll get all those behind-the-scenes insights into the podcast.
And while you're signing up for things arbitrarily, why don't you also sign up to receive this podcast in your favorite player every week if you subscribe. And we'd love it if you'd also rate us. Last week we put out the call for people to rate us on iTunes, and guess how many people we had? How many? We had a big showing.
We went from 30 to 32. So 2 people reviewed us last week. That is wonderful. Thanks to those who did it. For those of you who haven't, the other hundreds of you who haven't, that'd be awesome if you'd spend a couple minutes reviewing us in the iTunes Pod Store or Podcast Store.
Speaking of arbitrarily rating us, um, if you want to give that rating to a friend so that they know how wonderful we are, we would appreciate that also. Spread the word, get them involved in Colorado Equal Security. And finally, uh, if you want to help support the show financially, we do have a Patreon campaign. This is a way you can help defray the costs of this that Alex and I have been paying. We did have a new supporter this week who prefers to remain anonymous, uh, but we, we have a big thanks to you for doing that, sir.
Thank you, anonymous supporter. Although you just outed their gender, Robb. Oh, I can't believe you. Hey, hey, Alex, is that a beer you're holding in your hand? Um, it's not, but I wish it were.
Uh, now I don't know if you've heard, but in 2019 through January, we already set the record for the best beer sales, um, with a 20% increase over the previous record. What? Uh, that's pretty amazing. Uh, I guess it's not completely surprising. You know, we've recently transitioned from only being able to sell 3.2 beer in grocery stores to now selling full-strength beer.
I have seen a proliferation of beer into those places. So I guess it doesn't surprise me that people are buying more beer. So 9.8 million gallons of beer were sold in Colorado in January. 9.8 million gallons. That's a lot of beer.
So like, you know, there's what, 5 million people in Colorado? So there's 2 gallons per person in the month. That seems reasonable, including men, women, and children. Yeah. Yeah, that's about right.
So that means you had like 4 or 5 gallons in January, didn't you, Robb? No. No. Okay. Next, Denver is getting workers from other places.
That's not a surprise. So the city is drawing workers away from other major metros, according to LinkedIn data. So we look— they basically look to see how each city has compared against other cities and getting more or less People moving between them, and we are kicking the pants off of Chicago, New York, and San Francisco. They are sending their workers to Denver at the highest rate of any cities in the U.S. We're also a very popular relocation site for folks from Washington, D.C., Dallas, Boston, Houston, of course, and Minneapolis. Also, there are some areas that are winning the migration battle against Denver.
So Cities like Las Vegas, Salt Lake City, Boise, and Missoula and Great Falls, Montana are getting some of those folks from Denver. Seems like there seems like a trend that it's going from bigger cities to smaller cities. That's kind of what it sounds. The bigger cities are all coming to us, and then the smaller cities are pulling away from Denver more. Seems about right.
All right. Next, we have a story about the. The smart highway system that could revolutionize travel in Colorado. So we have talked many times about the smart roads that are coming. This is the best story I've read about what they're doing on this.
And interestingly enough, this was in the Westword, not our normal source. I think this is the first Westword story we've ever had. Could be. But really, they're talking about this combination that CDOT is building with a first-in-class system that allows the vehicles to communicate with the infrastructure of the roadways. Um, what I really liked on here is they gave a lot of specific examples about what this is going to do.
Um, so a couple of things. Number one, they're going to have these things built out in the next few years, all these roads built out. And then the car manufacturers are going to start delivering cars that have these communication capabilities in 2021. So just 2 years away. And Toyota is the first one committed to having those cars out in 2021.
Yeah, it was pretty cool. So I think the, the communication protocol that gets built into the cars, it can then talk to these sensors that are being installed on the roadways. And so if your car is, you know, losing traction, it can communicate that out. If you're, if you've been in an accident and your airbag goes off, it can communicate that out. And then the, the roadway can automatically alert folks and there can be action taken based on that.
And there, there's a lot of interesting examples here. Airbag goes off, then there's gonna be, you know, an ambulance sent out or, If they're losing traction, they'll deploy a snowplow to that area of the road. If there's a— if there's an accident around a blind curve, the roadway can communicate with the folks who are approaching that blind curve what's coming, automatically rerouting motorists based on road conditions. And then there's— they talk a lot about automation for truck drivers and the ability to remove human errors and improve the safety of those truck drivers who are driving around all the time. They do have one mention in here about our line of work.
They talk about the, the community, the transactions that are being broadcast between the vehicles and the road. They say that it will be done securely and privately. And then they have a little picture that looks like maybe encryption on the, on the, in the video showing, showing that. And then they do make the claim that the individual vehicle cannot be identified based on these transactions. It's more like, you know, there is a vehicle sending this versus saying here is, you know, Alex's vehicle sending it.
I'm sure security researchers will, will challenge that assumption. Exactly. I'd love to see those details. Usually when people think, oh, I can't do that, it's maybe it was not natively meant to do that. Right.
But that doesn't mean you can't do it. It might be super easy. Yeah. That said, there's a really interesting video in this link. I'd recommend folks taking, you know, 3 minutes to watch the video that shows how this is going to work.
It's kind of a, you know, a prep for what all of our tax monies are going for and what the world may look like. Awesome. Next, uh, speaking of smart things, there are several smart communities that are in the Denver area that were talked about in this next article. So the 2 communities that they talk about are Sterling Ranch, which is, uh, sort of west of Highlands Ranch, and, uh, Peña Station next to that exit off of the light rail in, uh, at DIA. So, uh, pretty cool.
They're talking about how these, these communities natively have some of the smart capabilities built in. Sterling Ranch, for example, when they built this out, they built a full fiber network throughout the entire development so that all of the houses could be hooked up to fiber communications. Also using things like, you know, smart garage doors and buses being driven by computers instead of people. Interesting stuff. They, they give one interesting fact in here that surprised me.
They say if you provide consumers with real-time data on their energy energy and water consumption that they will voluntarily choose to save about 10%. So, so that's one thing they built into this. So you have, you know, up-to-the-minute details on your usage. They also talk about the smart lighting system that they have there. So it's obviously efficient LED bulbs, but way more than that.
They— each pole has a security camera and it will change colors based on emergency situations. A flashing light means that a home behind it was broken into, for example. Wow. They give It does sound like kind of the future, right? Really interesting.
Yeah, pretty cool. Sterling Ranch is being built out now. So if you want to live in a smart community, I'm sure that you could buy a house there. All right. Well, our next story is around what we learned from our cyberattack of the CDOT.
Basically, it's called What Colorado Learned by Treating a Cyberattack Like a Disaster. But this is talking about the CDOT breach, SamSam breach that we had about a year ago, a little over a year ago. Yeah, the article, it rehashes some of the things that we've heard about already. You know, they went into, into disaster mode, they engaged the National Guard, you know, lots of people working, bringing in pizza to try and recover from this ransomware attack. Some of the other things that they mentioned, you know, they came out with a couple sort of lessons learned.
You know, one was, because they had treated this like a disaster, some of the protocols they had were, uh, for people that, that worked for CDOT to bring their equipment into sort of the, the headquarters office. And so if people were bringing in laptops and trying to, you know, plug them into their, their network, um, at CDOT, which is not what you wanted to do in a ransomware attack, you wanted to stay as far away from that as possible. Um, so definitely some things that they figured out that they could do better, but it, it sure sounded like things went pretty well. Awesome. It's good to get those details out there so other people can, can get better at dealing with their own incidents as well.
Next, we have a story from the Denver Post about the top workplaces in 2019. This one's focused on mid-sized companies, and on the list of the top 50 companies, there are 2 security companies. Number 49 on the list is Coalfire, our local services and consulting company up in the north Broomfield area. Yeah, and I think we had an article a couple weeks ago about this where they had, you know, sort of preemptively put a press release out about it before I think the actual list was out. And now we've got the list.
Now we got the list. And Ping Identity was number 13 on the list. Interestingly enough to me, you know, I work at Ping. I was surprised to know that Ping has been a 5-time winner of the award. So there you go.
They're so good at Ping that you don't even need to advertise how good it is. It is that good. Next, LogRhythm had an announcement this week, a pretty big one. They have released their next-gen SIEM platform in the cloud. So now if you don't want to deal yourself with managing the hardware or software of installing LogRhythm, you can now do it in a cloud-based instance.
That's pretty, pretty nice. Not have to pay for the hardware, not have to have the people actively managing all of the configuration around that. I— it— and one thing that they say here is that unlike some other vendor solutions that are going to have limited functionality in the cloud, this is going to have full, you know, feature parity with their on-premise appliance functionality. So yeah, that's pretty cool for them. Next, we have a blog from InteliSecure.
If you remember last week, we talked about their digital transformation series. We went through it kind of defining what digital transformation was And this week we were able to dive in and see how do you secure that. So he stayed with the same kind of breakdown of using people, process, and technology, and talked about them in that way, actually process, people, and technology. So for process, really the focus is on securing rapid change and how executives must think about data protection in smaller, rapid, ongoing development cycles instead of the large discrete project. Um, and they also made the point, uh, Jeremy also made the point that, um, business executives embracing digital transformation are going to find it increasingly difficult to get resources for projects that don't show benefit to the business, quantifiable benefit to the business.
And he specifically says, you know, security is going to have that same challenge. Uh, for people, uh, I'm not sure if, if I got his point here. He, for people, the only real point that they put in was that, um, there's changes for CISO, specifically changes around where the CISO is reporting. Um, and he says historically most CISOs are reported to CIOs and, and that organizations, uh, going through the digital transformation journey are reconsidering that relationship and moving them to different parts of the business. Um, I'm not sure that I agree that that's related to digital transformation necessarily as, as it is just kind of market forces.
However, um, it's an interesting trend and the one he calls out here. The, the final aspect for technology is, uh, basically moving away from perimeter-based security. Being focused more on the data. Where is your sensitive data? How do you know if people are using it in the right way or the wrong way?
So interesting article here, kind of closing up the, the series on digital transformation. I feel transformed. Uh, DexWeb wrote a blog talking about cloud services in the crosshairs of cybercrime. Uh, so this is a thing, again, one of a more, uh, consumer-facing, uh, sort of article here. Webroot, as being a at least partially consumer company, tends to do a number of those.
But, you know, just talking here about how the risks in the cloud are not that different than, uh, the risks not in the cloud. You see a lot of the same, uh, trends happening, uh, from ransomware and phishing campaigns, um, you know, DDoS, crypto mining, all those sorts of things happening in the cloud. Um, you know, basically you need to take care when using the cloud just like you would anywhere else. Um, while the cloud can provide a great, great platform to be secure, um, it does take effort on your part to make sure that you are making it secure. Sounds like something we should be able to share with those folks who are not doing security full-time.
Yes, exactly. All right, our final story this week is a blog post by Security Pursuit. I think this maybe is just our second time we've done a story by Security Pursuit, and this is how artificial intelligence is helping cybersecurity professionals. They specifically, you know, talk through The bad guys are already using AI. And what, what can the defenders do?
They have 3 bullets about where it is right now. They say AI helps gather threat analysis data, highlight vulnerabilities, and mitigate potential attacks at rapid speed. So kind of that, you know, really the SOAR aspect where you're, you're just doing all of the data gathering all at once and having it there for the analyst to review. Second bullet, AI-assisted network access control that enables device visibility through accurate inventory and monitoring of company devices. All right, uh, the last one is automated response to a breach through AI means corrupted systems can be taken offline in near real time, greatly reducing the damage done and the cost of a breach.
It sounds like, you know, the difference between AI and automation here— they don't really go into it, but I'm guessing automation would just mean if this then that, a rule we create somewhere. And, and maybe with AI there's some kind of evaluation, some kind of judgment that's being applied by the system to say, yes, this is, this is enough, right? I'm not sure exactly if there's no specifics in the article, but that's, that's kind of my take on the difference there. Well, Robb, I look forward to our new AI overlords. I think that's fair.
Absolutely. So that's our news. Let's move on to the Slack message of the week. Thanks to Andre Gaeta for sponsoring the Slack message of the week. He's been doing this for an awfully long time, and we appreciate that support.
So here we go. This Slack message of the week, I'm just going to read it before we even say who it is. So a QA engineer walks into a bar. Orders a beer, orders zero beers, orders 9 trillion, 999 billion. A lot of beers.
A lot of beers. Orders a lizard, orders negative one beers, orders a gibberish word. And then the first real customer walks in and asks where the bathroom is. The bar bursts into flames and everyone dies. Good job, QA engineer.
Way to test all the scenarios. So Slack message of the week this week is to Flint Gatrell. Flint posted this, this joke in the Slack channel. Made me chuckle. Made me share it with my work folks.
So you get to have one free item from the Colorado Equal Security Store. Thanks to Andre Gaeta for doing that. Awesome. And congratulations to Flint. Moving over to our events.
As a reminder, we do have a calendar of events on the website. You can go out and see what's going on here over the next weeks and months locally. We also, we love to talk about the next couple of weeks here on every show each week. So before we dive into the next 2 weeks, we do want to do a little bit of a spotlight on the Rocky Mountain Information Security Conference. Yeah, we're getting awfully close here.
The conference is June 4th through 6th. We've got, you know, like 3 weeks, I think, now a little under 3 weeks. And I think we had, we had like 2 more sponsorship spots left. Is that right? Yeah, as of Thursday, we had 2 sponsor booths left.
So really close to selling out. I haven't heard that we've sold out. But I think that we may have sold one of those. So there may only be one left. If you're sitting there thinking, yeah, maybe I should sponsor Uh, this is your time.
That's, that is very true. Um, we do have some other sponsorship opportunities. Um, if you don't want an actual booth, so don't let that deter you. Even if you can't get one of those last booths, um, there still are other opportunities. I think the biggest thing now is if you're someone who wants to learn, you need to go in and get signed up now.
We're, we're getting really close to this. And so sign up, uh, get your, your stuff in there and, uh, and let's see you at the conference. We'll be there. We have a couple of different sessions. We talked about, we talked about it last week.
Alex and I will be walking around. And if you need autographs, make sure, make sure you bring a pen because, because we've never been asked for one before. I'll have to learn how to sign my signature again. I don't ever write anything. We'll have, we'll have Colorado Equal Security stickers with us, which, you know, we could sign.
Okay. All right. Let's go ahead and jump into the next events for the next 2 weeks. On the 21st, the Cloud Security Alliance Colorado is doing their May chapter meeting. On the 21st and 22nd, ISSA Colorado Springs is doing their May meetings.
On the 22nd, ACES, the physical security group, is doing their May meeting, Behind the Scenes of Video Analytics. Ooh. On the 22nd, the ISC² Pikes Peak chapter is doing their May chapter meeting. On the 23rd, ISSA Denver is doing an education workshop on incident response and disaster recovery. On the 23rd, SecureSet is doing a capture the flag cybersecurity hackathon.
On the 24th, NCC, the National Cybersecurity Center down in the Springs, is doing a secure GPS for critical infrastructure and key resources seminar. Nice. The GDPR meetup group is doing a social event, one year under GDPR, on the 28th. ISSA Denver is doing a happy hour on the 30th of May. Also on the 30th, Check Point is doing a cloud mobile threat prevention event.
Welcome to the future of cybersecurity. And finally, CTA is doing an innovative look into ethics on the 31st. Nice. If you're not sure what ethics are, maybe you should go. You should definitely go.
All right. Well, that is it for the news. No, no, no. Why don't we talk about jobs? Jobs first, then we'll end the news.
All right. I have a couple of jobs at Ping. I am hiring a product security engineer focused on helping embed security into our development process. If you have a development background and an interest in security, this is the job for you. Similarly, we're also hiring a lead for that group.
If you're someone who wants to help run the product security function at Ping, this is a good chance for you. You could drop me a note and I'm happy to talk to you about it on the Slack channel. Charles Schwab is looking for a senior manager of risk and maturity assessment. SCL Health is hiring a manager of information security operations. The University of Colorado is looking for an incident response and monitoring lead.
Lockheed Martin is hiring a cybersecurity engineer. Shutterstock is looking for a risk analyst, cyber risk governance and analytics. It's kind of funny because the word risk and analyst are in it twice each. Yes. Made it very confusing there, Robb.
Ironcore Labs is hiring a DevOps engineer. Ironcore Labs is a local security company, a local startup that's doing some pretty cool stuff. This is, it might be a fun chance to to work at a very small company that's solving a good problem. Nice. Wells Fargo is looking for an IT senior lead auditor.
And finally, Dish Networks is hiring a program manager focused on IT security. Sweet. So that is the end of the news. And speaking of Dish, I actually put that job last on purpose. Speaking of Dish Networks, we— Sneaky, Robb.
Yeah, very sneaky. The segue is what it's called. The feature interview this week is with Artie Wilkowsky. Artie is the CISO at Dish Networks. Segway.
Isn't that one of those things, those scooters that you ride on? Are those still around? Probably. I know people do Segway tours of cities. Yeah.
Have you ever done a Segway tour? I've never done a— I've never been on a Segway either. Maybe we'll have to do that. Maybe we should do a Segway tour around Denver during RMISC. Yeah, but see, now Segways are passé.
Now you need scooters. You need— I've done scooters. Yeah. What about those one— those big Onewheel things? You know what I'm talking about?
I don't know what you call those things. A gentleman at our work has one of those Onewheeled skateboards. Those things are amazing. They are pretty cool. I was going You know, I was riding my bike and some guy was on one of those going up a hill at like 15 miles an hour or something like that.
Apparently, they have a lot of juice in there. Yeah. So anyway, I feel bad here for Artie because we just, you know, buried the lead on his interview. So Artie Wilkowsky, just great work. And we'll talk to the rest of you guys next week.
All right.
Hi, this is Sam Masiello, Chief Information Security Officer at Gates Corporation. This is Colorado Equal Security for Colorado security professionals. By Colorado security professionals.
Welcome to Colorado Equals Security. This is Robb Reck, and I am sitting in the studio today with the CISO from DISH Networks, Artie Wilkowsky. Artie, how you doing today? Robb, I'm well. How are you doing?
Doing fantastic. We have some beautiful spring weather, which doesn't narrow it down too much. You know, it could have been a month ago, could be a month in the future. No one knows when we're recording. Before we dive into, you know, how you became the CISO from DISH Networks, and I want to talk today about your priorities for the program and and really where you see security going.
But before we do that, I want to talk about working with your hands, with woodworking. Talk to me about your hobby. What is it you like to do with wood? I love to build furniture, and what's unique about my hobby is that my wife fully supports it. So I have a lot of friends that are into woodworking, and, and their, their significant other will actually treat it as some sort of nuisance and not support it.
My wife thinks it's great because because she finds a picture of something that she wants, points at it, and I'll sort of design it and build it for her, right? So, so give me examples of things you've made in the past. Um, I made a— I've made patio furniture. Uh, I made a sideboard with, uh, with barn doors. Um, I've made a sideboard like a buffet for your dining room, basically?
Yeah, yeah, yep. Um, I've made, uh, I don't know, all kinds of tables and things of that nature, right? I made a a whole cabinet and bookshelf set up in my— when I lived in Atlanta, in my home there, uh, I, I really fell into, uh, uh, listening to LP and vinyls. Vinyl, right? And so what I, what I decided I need to do— I had a spare room in the basement.
I decided I was going to make this really cool listening room. So I did cabinets, I did shelves, I did, you know, sort of the centerpiece area for the record player, for the turntables. It was cool. So it sounds like you've been quite productive with your woodworking. It's not like me.
I've made a handful of pieces of furniture and it's always been like, here's a specific thing we want and it's got to be like these measurements, right? It can't just be anything random from the store. So I've made a few things like that and maybe I'll show you before you leave. You should. Yeah.
But I've only made a few, right? It sounds like you've gone way above and beyond. Yeah, I like it. And I've gotten to the point where if it's my mom's birthday or my wife's birthday, part of what I do is I just say, hey, pick anything and I'll make it for you. Right.
Wow. That's awesome. Yeah, I owe my mom something right now. I'm gonna get to work on that soon. So is your experience similar to mine in that making your own piece of furniture costs, you know, a couple times as much as it would have if you bought it from the store?
Well, yeah, because if you factor in you need special tools, that's the other reason you do it, right? You you get a chance to— every new piece of furniture is at least one more tool, right? Yeah, exactly. So, um, you know, last time my wife wanted this, uh, sofa table recently, and I decided— so I went and bought this exotic wood, and, um, and I went and bought a jointer along with it because I figured I don't have a jointer and I really need to make sure this is perfect. So it turned into a, I don't know, $500 project, right?
Should have, should have been $75. Right. Yep. Yeah, that's exactly my experiences. I don't do it enough that I have all of the tools, but I have enough tools to make myself think that I have enough tools, right?
Yeah. Right. Well, that's fun. And like I said, I'm happy to share some pictures of furniture with you and stuff. But let's go ahead and dive into, you know, your background.
Where are you actually from? So I was born in Houston, moved around a bunch as a child. I lived in Singapore for a year. Wow. What took you to Singapore?
So my dad was in oil and gas, which makes, makes the Houston thing make sense. And then he was not Singapore so much. Yeah, well, he was asked to— he worked for, um, uh, Geophysical Services Incorporated, which was a part of Texas Instruments, and they asked him to go out there and, I don't know, uh, start some, some operation, uh, in Singapore. So I was relatively small. I think I moved there when I was 3 and a half and stayed till I was about 5, but I still have a lot of, a lot of memories from it.
It was great and I want to go back. So I'm going to expose some ignorance here that I probably shouldn't be ignorant. What language do they speak in Singapore? Malaysian. And so did you, did you learn any Malaysian?
I did. Um, I can't tell you a word of it now. Um, at the time though, you had it. At the time I had it down. Um, you know, we had a, we had a live-in housekeeper, which was very common and she taught me everything.
And I, I became friends with her daughter and we still actually communicate occasionally. Yeah, we'll send in English, it sounds like. And well, yeah, or, you know, letters or, or, uh, you know, pictures or something like that. Yeah, yeah, awesome. Um, so Singapore from 3 to 5 years old.
Yeah, so then I went back to Texas, uh, but I really consider I became a Coloradan, uh, when I was about 10 or 11 years old. This would have been in the, uh, this was, this was the year that Elway was drafted, so '83, '84. Okay, is when I is when I moved to, uh, Colorado. And I've— I moved to Arvada, um, moved around a little bit, but I basically stayed here. I went to school out here at Northern Colorado up in Greeley.
Um, I moved down to Dallas for about 3 years, missed Colorado after college. Yeah, graduated. What was your undergrad? Undergrad was, uh, business. I took— I took some, uh, some, I, you know, MIS-type courses, although I never, I never really took a lot.
I didn't— I wasn't particularly interested in coding or, yeah, you know, COBOL or Fortran or any of that stuff at the time. So it was more statistics and just general IT. I was always just interested in, in computers. I had them growing up. I was, I was the person everyone would call if they had a problem or questions, and that's kind of how I fell Yeah, so your, your first jobs out of college, what did you, what'd you do?
So my first job out of college— well, okay, my very first job out of college, when I graduated, I, I did on-campus interviewing. I didn't really have what a lot of kids today have, which is like a plan, right? I was just kind of figuring it out as, as I went along. And I did on-campus interviewing. I got a job offer to go into the management program at Kmart, believe it or not.
And so I went And they moved me to El Paso, Texas, and I lasted all of, I don't know, 4 or 6 weeks before I realized that that was not— wasn't the future you wanted. Yeah. Nothing, nothing, nothing bad to say with, with Kmart. It was just— they're all bankrupt and gone now. Yeah.
Yeah, right. But, you know, so there's a couple of bad things to say about Kmart. That is true. That is true. But for any of you that have been at Kmart, I actually like the people.
Yeah. I just— I didn't like the work in retail. Right. So So I left, I went to Dallas, and that's really where I got my first job in IT. I worked at a small company and we basically developed and sold these Linux-based business systems that were then deployed at ag dealerships across the country, all in the heartland, right?
So they would do accounts payable, accounts receivable, whole goods, point of sale, all that stuff. And you were implementing these or what? Both. I— so half my time I worked on a help desk, which was interesting, and so that's how I learned how to troubleshoot, right? Um, half the time I was in the field installing these.
Yeah. Uh, and then I would, you know, train the— train the owner and, and the farmers there on how to use them. Yeah. And that sort of thing. And it was interesting because, um, you know, just kind of this, this new world, right?
Very, very nice, salt-of-the-earth, kind people. But you're, you're blowing their minds with your, with your digital transformation for their businesses, right? Exactly. Good one. Good, good one.
Digital transformation. Buzzword bingo. Yeah, first, there's your first box. So where you went to some thriving metropolises, I'm sure, to implement these systems. Can you give me some examples of places you went?
Oh, sure. I went to every state in Middle America that you wouldn't just decide you wanted to visit. And not to say that any of them are bad, but I— every, you know, Arkansas, Iowa, Missouri, you know, Idaho, South Dakota, you name it, right? I was there. As far east as New York.
In fact, I was at an ag dealership that was right, right by where the original Woodstock occurred, which was kind of interesting. But yeah, a bunch of a bunch of that sort of stuff. So I've been to— actually, this is, this is one I don't know if it's interesting. My kids don't seem to think it is, but I've been to 47 of the 50 states. So what are you missing right now?
I am missing Vermont, which is kooky because I've spent a lot of time in New England. But yeah, but Vermont's like out of the way. I went to Maine and I'm like, oh, I'll swing by Vermont. And I looked at the map and I'm like, no, I'm not going to swing 3 hours west just to Just to say I was there. So it's hard to get to Vermont.
Maine is— Maine, by the way, is fantastic. I loved it. My wife's from the Boston area, so we actually go to Maine to vacation a lot. Yeah, just, we love it there. So Vermont.
Yeah, so Vermont, Delaware. Delaware. Okay. And Alaska. So Alaska makes sense.
Delaware, I'm surprised as well though, because it's so easy to get to if you're in DC. If you're in DC. And I've actually thought about building it into a trip where I just, where I just go out there and I don't know, Go get a meal and try to get a meal and try to actually make it official and not just pass through it. Yeah, I always— there's like the initial list I made back when I, when I, when I would count anything in the state. And then there was the list I made later.
I'm like, okay, I can't count that stopover in the airport. I got to actually like go into the place. So a good friend of mine was once stuck in O'Hare Airport and he traveled a lot. He was a consultant and he and a friend determined rules, right, for if you could actually claim if you visited a state. Yeah.
And the 2, the 2 most prevalent ones are you either spend a night there or you have a meal there, but it can't be in the airport, right? You have to actually leave. So yeah, I feel like I have to have like experienced the culture in some way, like that I actually feel like I've seen it, not just physically been in the place. Yeah. Which is tough, tougher to define.
Yep. All right. So you got to travel to a lot of states as a part of this ag business. You know, what's next? Um, so from there, Let me think.
I did some software training, right? A lot of Access and, you know, Unix and Windows and, you know, so OS and, and I would say applications like Access and Excel. I did that for about a year. Then I became a network administrator. So I worked for about a year just doing a lot of just general network support, um, for a place down in Dallas.
Then I became an IT consultant. And is that what brought you back to Denver? Right. Looking at your LinkedIn, it looks like about that time. Yeah.
Yeah. So I was, uh, so let me think about this. I was an IT consultant in Dallas in around, I don't know, '96, maybe '97. And, um, I happened to go to a conference in New Orleans. It was a CA conference.
And at the time, I was doing a lot of Unicenter-type implementations. Sales guy from CA took me out, and he took out a bunch of other clients at the same time. And I met this guy who owned a security firm in Denver, of all places, where I had lived for a really long time as a kid and really wanted to get back, right? And so this guy and I, uh, guy by the name of Mark Baisley, really good guy, we hit it off. He offered me a job shortly thereafter, and I I picked up and I moved back to Denver and started initially doing just IT consulting, but then quickly got sucked into security and I haven't looked back since.
Was this InSpherix? Looking at your resume, InSpherix is the, is the company we're talking about. I haven't heard of them. I assume somewhere along the line they've, they've gone away. That's right.
So we were initially Denver Tech Labs, uh, and then we rebranded and we were InSpherix. And this was Uh, I— let me think, I was there from, uh, from the late '90s through— oh gosh, December 2000. Yeah. And that was right before the dot-com bust, right? And so I— we had started doing security, uh, I, I started doing a lot of it.
Basically what happened is, uh, the owners sold, and I was, I was like employee number 1, I think, uh, or 2 or something like that, but the owners sold the company does cyber, C-I-B-E-R, based here in Denver, and they wanted a security capability, right? Yeah. So then I went, I worked at cyber for a few years. Yeah, it looks like between the two you had, God, man, like 7, 8 years. Yeah, yeah, big chunk of my life.
And that's kind of when I learned, you know, uh, first I was firewall admin, and then I, uh, I did a lot of threat and vulnerability management. Yeah. And then I started running delivery for cyber, right? So I had all the, all the consultants reporting up to me, and I'd design all the engagements and, and do client sat and all that kind of fun stuff. So there you were, there through 2005.
What, what made you leave? Um, so in 2005, I got an opportunity to go to Raytheon. I wasn't there very long, um, but, but it was, uh, you know, at the time sounded very exciting and, and sexy and kind of you know, that, that in-depth, uh, sort of security immersion that you would get in a place like that. Um, and I actually joined the owner of InSpherix, uh, who kind of recruited me over to Raytheon. So anyway, I was at, I was at Raytheon for a little while.
Um, didn't, didn't love it. Didn't totally work out. I went back to cyber, uh, in, in the, I guess, 2005, 2006 timeframe. Is that? Yeah, 2006.
Yep. And then I was there through about 2008 when I transitioned to First Data. Yeah. So First Data, obviously we've had a lot of folks who we know, you and I both know, go through First Data over the years. Yet another good run there, 5 years or so.
Global information assurance and risk. What does that mean you did? So I really did 2 distinct things. And this is, for me, was a kind of a transformational time in my career. The first thing I did is I was the information security officer, basically like a BISO for EFTPS, Electronic Federal Tax Payment System, which is obviously a government— it's an IRS system that is— the financial agent is Bank of America, now BA Merrill Lynch.
And then they at the time had First Data actually operating the system, right? And so I was the security guy. I was completely embedded with the business, right? With the technology organization, with the business. It was the best, most aware security culture I've ever been a part of.
It's just, it was kind of this little segregated island within First Data, right? Where we just did EFTPS and other government things. So anyway, I really enjoyed that. You know, I spent a lot of time working with the government and with the bank. I grew the team, right?
When I got there, it was just me. I grew it. And by the time I left, I had 5 or— there were 5 or 6 of us, I believe. Along this time, I was getting my MBA, right, at Regis. And I had all these ideas about how I could— and I was basically studying strategy and strategic transformation.
I started thinking, you know, I could really combine security and strategy. And wouldn't that be kind of a cool career, right? So, graduated, got my MBA. At the same time, I got an opportunity. So, this would be the last 2 years I was at First Data to basically set strategy for the security organization there.
So, at that point, I stepped out of the government world within First Data, and I worked for the enterprise security organization there. And, you know, a lot of our good friends and mutual contacts Uh, you know, I spent a lot of time with them and I was, I was doing a lot of road mapping and helping people identify strategic initiatives and stuff like that. Right. Did that for another couple of years. That seems like a great place to have, to have really, you know, shared the experience with other folks.
I, I know that, you know, I've worked a number of companies and I haven't worked at a lot of places that had a lot of, um, security leaders at it that really, you know, understood where you're coming from. Most places it's, you know, you're the only security guy or there's just a few of you and First Data, I know there's like a dozen just really smart folks running the team there. Any, anything takeaways you got from that, from that experience of working with, with all those great folks? You know, I would say when you, when you work in financial services, you get to see security on a, on a very grand scale, right? And you're a threat and all that, or there are many threats rather.
So that part of it was interesting. I also learned how to navigate in a big organization and how to get initiatives done and how to get consensus and things like that. And I also learned to rely on people and teams that knew more than I did, right? I would say that's the other big takeaway. We had so many smart folks doing niche things within security that were just so good at it that I really learned how to, you know, how to work with them, even though they didn't report to me organizationally, how to influence and get their help.
Not have to be the expert on everything. That's right. And get the confidence where you don't feel like you have to know everything, right? So you were there, it looks like, through mid-2013. That's correct.
What was next for you? Why'd you end up leaving? So I was— I kept sort of hitting the top. I was a director the whole time I was there. And never got a chance to move up anymore.
And I just decided I wanted a little bit of a change. And I, at the same time, was a little bit— I was missing consulting, right? So I've had this theme in my career where I bounce between industry and consulting. Yeah. Um, and so I decided I, I wanted to get back into consulting.
And, and some of the same folks that I had worked with in the past, uh, were running, uh, GBProtect, right, which is a an MSSP which just recently merged, right, with another, another firm. But anyway, I went over there to run professional services and consulting basically, and had a, had a team of people doing stuff. And I created a bunch of offerings including a sort of CISO-for-hire type offering, um, which I, you know, spent a lot of time putting that together, which was a lot of fun, and selling it. Yeah. And that was, you know, one of the kind of like maybe the biggest or one of the biggest Denver-only MSSPs really, right?
Yeah, you guys and InteliSecure. I'm not sure off top of my head, I'm not thinking of the other ones that are local, but you know, it's nice to have those kind of companies in, in the area. Yeah, yep, it was, yeah, it was, it was cool. Uh, so I did that and then I, um, I ran a kind of client, client relationship management CRM, but not, not, not so much technology, but just the the culture, right? I was, uh, you know, sometimes I joke and say it was a complaint department, but I was, I was good at working with clients and trying to find resolution on tough things.
So I, I spent a lot of time, uh, doing that. So not really account management, more like escalation management? Exactly. Okay. Yeah, when things weren't going well or, you know, when we needed to sort of change how an engagement was going or relationship was going, I'd get involved and, and try to help it.
Well, it's great that you could help solve the problem, but it doesn't sound like a very fun job. It was really challenging. Yeah, you know, it, it was— it's a lot of times, I mean, we all struggle with this in security, right? It's— you're— you normally only hear things when things are going wrong, and, and there it was the same thing. It was when things weren't going as well as they could, that's when I got contact, and I was usually dealing with unhappy people, maybe on the client side, and and, and maybe on, on the company side, and which is very challenging, but it was a good, good experience.
So I know that GBProtect— we're going to skip forward to your next job, but before we do, I know GBProtect, uh, you know, merged slash got acquired by, uh, Newspire, which I, I'd never heard of before. Uh, so it looks like they're a little bit bigger than GB. Do you have any idea, like, you know, is the team still in Denver? Do you have— you keep in touch with anyone if it's a good thing for them or a bad thing for them? I do.
Um, I've talked to a few of the folks. I think it's a it's a good thing. I think it's an opportunity for them. Uh, you know, I think, I think GB had a lot of big, uh, you know, big really national clients and they could bring that to bear. And they also had some, some consulting capability to maybe, to maybe bring to the relationship as well.
But from the people I've talked to that I still keep in touch with, they view it as positive. Okay. You know, upwardly mobile opportunity for them to do bigger. So the office in Denver, as far as you know, is not going anywhere or anything, right? It's not.
And in fact, that, you know, GB spent spent a lot of money on this really, this showpiece SOC that was there. And I think, I think that's part of the future plans for them. Yeah. Awesome. Yeah.
Okay. Well, I know you left GB in 2014, 2015, or early 2015. You started with PwC. What were you doing over there? Uh, so I was in their cybersecurity and privacy practice.
Um, I had, back in the first data days, I had, I'd gotten to know PwC very well. I was doing this global ISO 27000 certification effort for First Data. Got to know PwC through that. When I decided to make a change, I called the partner that I'd worked with a lot and got an opportunity to move out to Atlanta and just do security on a very, very big scale at a Big 4 like that, right? Which was really, really interesting and taught me a lot.
Yeah. Yeah. What's the, what's the best thing you learned from that process? Um, wow, that's, that's a really good question. I, I think I, I became comfortable being uncomfortable, right?
You know, you're as a, as a consultant in a place like that, especially in a leadership type role, you're put into so many dynamic situations that you don't have time to, to prepare for as much as you would if if you knew it was coming. Yeah, that you just, you know, I, I, I really became comfortable. I don't really get anxious. I may get a little anxious before big things now, but not the way I used to, right? I'm, I'm relatively comfortable, uh, with, you know, C-suite.
I mean, I should be given my role now, but I'm comfortable in those kinds of things. I don't, you know, I don't clam up, right? So it's a— I'd say that's the biggest thing, and I'd also say, you know, just solving the toughest problems at the biggest clients, right? Big 4 doesn't, you know, mess around with, with, uh, with small easy stuff, right? So a lot of these things were very, very complex and difficult and, you know, nuanced.
Um, and I was doing a lot of GRC work, a lot of PCI work, a lot of ISO work. Um, you know, I did some, some implementation work as well, but mostly on the strategy side. You know, if a new CISO came in and needed an assessment, an agenda, a roadmap, I would lead teams to go and figure all that stuff out for them. So I've heard, you know, so you talked good side, some really cool experiences. On the other side, I've heard some stories that like something like 90-plus percent of people who do that job end up getting divorced.
You know, obviously I know you didn't get divorced. Um, what's, you know, were you on the road all the time? Is it, is it just a real work-life balance challenge? It is. I'll say PwC is really cognizant of that.
And I think, you know, they— it's more than just talk. They actually try to back it up and give people, you know, adequate time to not just have time away from work, but vary what they're doing at work and not, not travel all the time. Yeah. Um, you know, there were— I would travel in stints, right? I If I had, I'd have a couple of projects that were in different cities and I'd travel quite a bit for those.
But for me, I've traveled my whole life, so it wasn't that big of a deal. And it wasn't a big impact on my wife either because she was used to it when we met back in the, in the, in Spherix days. Um, you know, she was used to me traveling. I did it back then, right? So, so it wasn't a huge, wasn't a huge impact.
I liked the travel. I liked the dynamic nature of what I was doing. And really going to PwC was a, was a path. I figured it would open doors and give me an opportunity to become a CISO. And I think, you know, just before that, by the way, Robb, is one of the first times you and I started talking, probably back in 2014.
It was when you were at GB. I know that. Yeah, probably 2013, 2014, something like that. And I remember after leaving GB talking to you, we went to lunch. Yeah.
Um, and, you know, I was, I was talking about how, uh, you know, path to being CISO, and I figured you know, working a place like PwC was really going to give me an opportunity and open some doors I didn't know existed. Yeah. I mean, the relationships you build, right? That it's all just such great relationships you get through those type of organizations. So I know you were at PwC for 3 years and then what happened in March of last year?
So in March of last year, I joined Dish Network as the CISO and I'm just hit about a year. Was that through, you know, your PwC experience, or how did you get this opportunity? Great question. Yeah, it's actually— I, I would say it's— it was identified from a relationship that I had with a guy that I worked with at First Data. A guy by the name of, uh, Rob Dravenstadt was, uh, was the CIO at the time of Dish Network.
Yeah, Robb and I were very close. Uh, he called me and, and said, hey, uh, my, my CISO just turned in his notice. Yeah, would you like to talk to us? And I said, sure, I'd love to. And, and the rest is history.
And what I would say is, although it was a, it was a contact, uh, from my First Data days, I think what I did at PwC really positioned me well for that. Um, you know, I wouldn't have been— I, I'm not sure I would have gotten the job had I not worked at PwC and, and learned as much as I did then, right? So I felt like the time was right. I mean, even if the guy likes you, you know, he has to be able to justify why is this the right guy for the role, right? Yeah.
And, and I think having that international— maybe not international for PwC, but internationally recognized, you know, experience at PwC and, and any other, you know, kind of back and forth between consulting and internal really gives him the credibility to say this is our guy. He's a PwC consultant, he also helps run a security program for First Data. That's That's a good combo. Yeah, yeah, it certainly helped. And, you know, it was a great, great opportunity for me, not just because of the leadership role, but because Dish is such an interesting place.
There's so many things going on there. You know, some CISOs really are attracted to building things and others want to maintain things. And I get to do a little bit of both. At Dish. So it's, it's very exciting, uh, different business units at various stages in their evolution, and, and just supporting that is, is really a lot of fun.
But yeah, it was, it was, it was great. And then unfortunately Robb left, uh, you know, I don't know, maybe 4 or 5 months after I joined. Um, but, uh, so I was sad to see him go. He's working at a startup now. But anyway, it was a, you know, I'm, I'm still loving it.
Yeah. So I, you know, I think everyone, a lot of people in town hear DISH and they think of a culture that's been, you know, kind of built over a couple decades of a place that's not necessarily so easy to work with for customers and, or excuse me, for employees. And, you know, I'm sure you'd heard that before you went to DISH. And I'd love to hear, number one, like how that cultural reputation impacted your conversations with them and then, you know, what your experience has been like working there so far. Yeah, yeah, that's a good question.
So I, you know, I had heard things and, you know, everyone reads Glassdoor and that sort of thing, right? So I'll say that when I was interviewing, I kind of had my guard up and I was looking for this and I was just really, really impressed, surprised, blown away by the caliber of folks that I talked to. They were engaging. They asked tough questions, but I could tell there was a lot of unity. So I view it as a unique culture that values people that work really hard, that are intelligent, and that are really entrepreneurial.
It's really the kind of place where you're really challenged to come up with new and different ways to do things, and there's a lot of people that are recognized recognized for that, right? So, you know, in terms of all the negative stuff that, that, um, that, that I had heard, uh, throughout the years, I, I've honestly not experienced that, right? Well, I mean, some of the stuff that I— and I'm not going to dwell on the negative because I, because I actually think I've heard a lot of positive stuff too. But some of the stuff you hear is, you know, you have to clock in by a certain time or have an exception from your manager. Like, you know, kind of, uh, you know, those structures that are built around like being there in person.
Right. I've heard those conversations. Sure, sure. On the, on the positive side, to reiterate what you were saying, you know, I've known quite a few people in the security program over there and IT more generally over the years, and the feedback that I, I get time and time again is that it's, it's a company with a huge amount of resources to go invest in technology that prioritizes technology really highly, but small enough that people are able to go explore and learn and, and be challenged to go to go be responsible for not just their really narrow silo. Yeah, totally agree.
I mean, it's a, it's certainly a culture and an organization that values having people at headquarters or at the office, and there's a lot of, there's a lot of benefit that comes from that. It's very— everyone's very closely knit. There's a lot of good communication on what's going on, um, you know, so, so that part of it's great. I think, I think we're able to do things on a, on a very large scale. That part of it's interesting to me, and I think really it's the kind of place that you can really go and thrive if you, if you have an interest, uh, at Dish.
You've got a lot of opportunities. People move around all the time and are challenged all the time, and, you know, all kinds of folks with, with patents and, and new ideas and, and great things. And we've con— you know, continually transformed ourselves as an organization throughout the years too. Yeah. You know, big, big satellites to small to over-the-top with what we do with Sling and what we're doing now with wireless and all that kind of fun stuff.
There is just a lot of really cool opportunity there and I really like it. Awesome. Well, I'd love— I want to talk some more about your, your experience there at Dish and really what you're focusing on. So what has been your focus over the last You know, what's it been, a year and a few months now? Yeah.
What's the first thing you did? You know, get your, you know, get your feet under you and then what do you go after? Yeah. Yeah. So, well, first thing I did is I went to Basecamp for— Oh yeah.
Tell everyone about Basecamp. I love this. Basecamp is so cool. Yeah. I've never heard of a company that does this.
Yeah. So Charlie Ergen designed Basecamp to give everyone— Who's Charlie Ergen? You know, I know who he is. I know you know who he is. So Charlie design Basecamp to get everyone an appreciation and understanding of what all of our frontline folks do and to really understand who our clients are.
And so it's this immersive experience where you basically go away, you start your job, and then you go away for effectively 4 and a half weeks and you are trained on sales, And, you know, you listen in to sales calls and you get an idea of who the customers are and what the sales agents go through. Then you work the phones for customer service, both from a DISH perspective as well as a Sling perspective when people call in. You go out in the field for installs with a tech and, you know, they don't let you climb ladders for liability reasons, but you build dishes, you You're, you're not just there watching. You've got a tool belt on and you're out there helping, right, during your ride-along. So that, that part of it I thought was— so you do sales, uh, customer support, and installs.
Is that the 3 rotations? Yep, yep. Um, and it— and then it culminates with this big, uh, presentation at the end as far as what you learn. But what's good about it, uh, first of all, you have, you have You just can't replicate that kind of exposure, right? Both to the customers as well as the customer-facing folks that we have.
You understand what their challenges are. As a security person, I saw things that I put on my list saying, hey, I need to look into this, right? So it was great from that perspective too, but it's just something that you cannot replicate unless you're immersed, right? And for someone that's new at DISH, your cohort, the other folks that are in your class that you're going through all this with, you become very close and you build a network and that sort of thing. So I think it's been a great success.
Is it every single new employee or is it just certain— every single— or departments? It's every— yeah, it's every single new employee. Yeah. Um, we even put interns, uh, summer interns through an abbreviated version of that. And, and then existing folks, there's a lot of tenure at Dish, so there's people that have been there 20 years before we had Basecamp, and they all try to go through as well.
Yeah, they're cycling through as they can get away from their job. That's right. That's right. And it's, you know, look, it's not easy to get away from your job for, for that long. Yeah.
So you have to plan it and everything like that. And that's why for new joiners, we recommend just do it right away. Yeah. Because I think if you, you know, if you start working, it's hard to pull away. Hard to pull away.
Yeah. So, so Ping, you know, where I work, we hired one of VP of HR from Dish who had helped build the program, and I'm trying to twist his arm to implement the same thing at Dish because I— or excuse me, at Ping, I mean— because I think it is such a cool idea. And I worked for Pulte Mortgage before this, and I actually kind of made my own where I sat down with our loan processors and our mortgage brokers, and I listened in and saw what they did so I could really understand how I was impacting their day when I said, make sure, you know, it's just one extra click, right? It was great to be able to understand their workflow. And I think all security people, and of course everyone would be great, but at least all security people would really, you know, get value from seeing how they're impacting their coworkers with their security policies and practices.
Yep, absolutely. It's great. And I think the other benefit for DISH is that since this program has been in place, we've started winning all sorts of customer service awards. Awards, JD Power, a big, big recognition, right? And this is, this is in no small part due to Basecamp and the, and the fact that everyone understands how, how challenging it is to be a sales agent.
How— and so you go back and you say, how can I— what can I do as CISO? What can I do as a, as someone who works in IT that can make their job easier, right? That, that can eliminate some of the roadblocks, that sort of thing. So it's, you know, I think that's, that's a real challenge for everyone that goes through it, and it's just a, just a really neat program. All right, I'm gonna, I'm gonna give myself a note right now.
We're gonna create our own security Basecamp, even if the rest of my company doesn't do it. Yeah. All right, anyone who's at Ping Works who works with me, you know, hold me accountable to that. All right, um, so after you got through Basecamp, what have you been doing for the last year? So First thing I did, like a true consultant, is I did an assessment, right?
And used the NIST Cybersecurity Framework. And I went through and I looked at the program and figured out where some opportunities were to make some tweaks and changes and that sort of thing. I shortly thereafter started adding staff in key areas, right? Big initiatives. There are some things that we're doing with event monitoring and increasing visibility.
There's a lot that we're doing with revamping our security awareness program and adding, adding some tweaks to that, some, you know, changing the cadence of the training, making sure that we, that we hit everyone that we need to. Yeah. I'd love to talk about that a little bit more. I know you and I have talked about like the, the operational side and there's the more GRC programmatic side. And I personally put awareness more on the programmatic side.
Yeah. And, and, you know, a focus on that. How do you think about what's the goal of the different awareness/training that you do? Yeah, well, it's, it's about ultimately it's about training people, right? It's, you know, security is everyone's responsibility.
We all know that. So if you don't, if you don't adequately train folks, if you don't make people aware of what all the policies are, if you don't make sure that people can recognize a phishing email and a social engineering attempt and stuff like that, ultimately you're kind of rolling the dice, right? So it's never 100% effective, but the better you get at that, as we all know, you know, your risk, your risk, at least in some of those areas, is gonna, is gonna be mitigated to an extent. I'm just thinking, you know, the typical— I don't know when it happened, a decade ago, we got to the point where most companies just recorded or bought an hour-long training that everyone hates, that there's a quiz, you know, maybe throughout it or maybe at the end. Yeah.
And, and it's basically like a, you know, that, that's what it was. And, and, you know, that is giving people the training slash awareness that's required. However, you know, they're probably not retaining it and it's not role specific and it's probably not even all that company specific. You know, it's probably, you know, you could— I could use yours and you could use mine and no one would really be able to tell much of a difference. So how do you look at, you know, going from that, you know, kind of preexisting state of the industry, maybe not at Dish, I don't know, but to where we want to be and where do you want to be?
Yeah. So, you know, you hit it on the head. It's not enough just to give everyone the same training once a year, right? It's about this continuous effort to reach people through different mediums and ensure that they're getting the message, whether it's online training, whether it's posters, whether it's a CISO newsletter, whether it's just general awareness announcements. Lunch and learns, all these things that are designed to make sure that you reach people.
You mentioned specialized security training, role-based training. That's a big part of it, right? That's one of the things we focused on, not just because you should for things like PCI or you're required to for things like PCI, but because it's the right thing to do. We know about— look, we've all got a lot of developers out there. We've got people that are that are in people's homes installing things, and it's about ensuring that they understand all the right things to do.
I firmly believe, you know, we all think about malicious insiders, and certainly that happens from time to time. I think those things are relatively isolated. I think most of the time it's just awareness issues, and people want to do the right thing, they don't, they, they don't know what the right thing is. Yeah. So I think it's our job to, to teach them what that is.
You said one thing in there that, that really triggered for me, you know, talking about trying to get to people, lots of different communication channels. And, um, you know, there's this marketing buzzword out there, omnichannel. I don't know, I don't know how much it gets into your world. It's something I see on a regular basis when I'm, you know, because we're on the vendor side, I see these things sometimes, omnichannel, and how you get at people from different things. And I think it's, you know, just as applicable to us and security people trying to get out our message as it is to, you know, marketers trying to hit us.
You know, what does omnichannel look like? Well, there is a CBT and there probably needs to be a CBT for some reasons. But there's also, you know, I know at Dish you guys have some posters that you've had over the years, you know, that are just kind of fun stuff on the walls that look like movie posters because you had, you know, bought Blockbuster. And maybe there's town halls where everyone's in person and maybe there's a lunch and learn and maybe there's, I don't know, like what does omnichannel look like? But I think it's as we get from this unichannel to a whole lot more ways of connecting that people are gonna, it's gonna be stickier and hopefully one of the messages really is gonna resonate with everybody.
Yeah, you're right. And the marketing adage is that you've got, someone's gotta hear something 3 times to remember it, right? What those 3 times are, I mean, everyone's a little bit different, right? But ultimately, our job as CISOs is to ensure that we have some mindshare and that people are security aware, understand what's expected of them, what they need to do if they see something that's amiss. And the way that you do that is through the omnichannel approach.
Yeah, it's interesting. I was on a panel at Code42 recently, at their user conference, and a security leader from— I guess maybe I shouldn't say it— from a different company, um, was talking about their own security training and how they had sent out internal messages basically saying, hey, you know, we have DLP, we see what you're doing, you know, you're, you know, don't do the— don't do personal stuff you don't want to have seen on these systems. And he saw like, like a 2% decrease in personal use of systems, like, you know, inconsequential. And then they went and did town hall meetings where he said the exact same message but, you know, in a room with people, and they saw a 70% decrease. Like, yeah, like everyone heard it in person, and they just— when they either didn't read the emails or they didn't really parse the emails.
And I think that it goes to show that the way you deliver the content, you know, the more personal you can get, the more effective it's gonna be, and the more they're actually listening to what you have to say. Yeah, you're right. And so I look for— and I assume we're gonna talk about, you know, what sort of people do you look for— but one of the things I really value Uh, people with, with communication skills, people that are comfortable talking to groups, people that— because I think that's always more effective than an email. You need to do the email stuff, you need to do the CBT stuff, but it resonates more, uh, when it's a person and a face with a name and they actually hear the message. That's great.
I mean, our job isn't that hard in terms of technical— technically, like, you know, the technical solutions for most of what we want to do are created by somebody else. We're just implementing. And what do you need to do to be a good implementer? You got to be a people person, right? That's right.
You got to be a project manager or program manager. A lot of that. I do want to get to your advice for new hires, but first, let's finish talking about what do you see over— what would make 2019 wildly successful for you and your security program? Yeah. So one of the things I mentioned earlier was what we're doing on the wireless side.
So First Data, Excuse me. Boy, that's a nice slip. DISH owns a lot of wireless spectrum that we've purchased throughout the years in auctions and things like that. And we're doing a lot with wireless. So we're gonna start with a narrowband IoT rollout, which is gonna, by this time next year, we'll be up and active on that, both from things that we manufacture and design ourselves that ride on the spectrum as well as partnerships that we make.
And then eventually 5G is going to be sort of the next phase in the evolution of what we're doing. So I would say what's going to make me successful is if I can continue to integrate into what we're doing from a wireless perspective, you know, help with guardrails and standards and things like that. But really enable what it is that they're trying to do. I can't use the same approach for wireless that I can for DISH, right? They're different phases of their evolution.
Security is every bit as important, but I've got to implement it a little bit differently. The methods that you use are a little bit different, but what would make me successful is if I could get all the right controls and mindset in place without, without putting the brakes on a lot of things, right? Which really in that space, we, you know, we're time-bound on a lot of stuff. So it's critical that we get this stuff out when we need to. So that's what's going to be success for me.
Um, what I think I just heard you say is the success of your program is based on your ability to be agile and flexible enough to let the business go where it's going to go otherwise without you messing it up, right? Is that about what you're saying? Exactly. And, and how— and we, we talked about this a couple weeks ago too, right? How do you do that?
Yeah, well, how can you position yourself to not be either an impediment to their success or a really bad CISO who just lets them do bad choices, right? I mean, yeah, it's about, it's about getting integrated and having people that are focused on, on this so that when, when things are in ideation and, you know, when requirements are being developed we've gotta, we've gotta have a seat at the table. We've gotta have people that are helping, helping advise, right? The earlier on in the process that we get involved, the smoother it goes, right? If we find out late, then, you know, I don't view that as, well, the business didn't tell us until recently.
I view that as we didn't do our job. I didn't do my job as a CISO if, if I find about— find out about something the day before it's going to go live, right? It's my job to get in there and ensure that my team gets in there and understands what it is that we're doing and helps be part of the solution early on. Yeah, that's great. Shift left as far as we can.
Shift left. Yeah, that's great. Yep.
I'll move on to the next couple topics I have for you. Any other things you want to talk about in 2019, or we got— that kind of captured it? Well, I mean, yeah, I have a big roadmap of things, but it's— I would say my big platform is Consistency, repeatability, right? Process in the sense that we ought to make it easy for people. We ought to say, you know, we generally need to be involved here, here, and here in the SDLC, right?
You know, if you want to get a firewall change request approved, show up the following types of information. If you want to accept payments, credit card payments online, uh, here are some approved methods of doing it. So just making it easy and not, not arduous. Service-based approach. That's right.
I love it. Yeah. Okay. Um, we have a couple different audiences who listen. One audience that we get a lot of listeners is folks who are looking to make a shift into security careers.
Um, some, you know, SecureStat students, some CU students, some folks who are, you know, just IT folks who are ready to make a change. What do you think are the keys for them to not only, um, well, number one, how do they even get an interview, right? Yeah, with a guy like you. Number two, how can they be successful once they get the job? Sure, uh, great question.
So first of all, I am, I am a believer in core skills that don't have anything to do with security. And that's, you know, if someone wants to enter into security, I look for things like a sense of curiosity. I look for things like problem-solving skills, and I look for things like communication skills. And if I can get those 3, I can teach someone security, right? I can teach them the principles.
I don't, I don't think security is particularly hard to pick up. I think the hard part is connecting with people and communicating the message and, you know, diagnosing things when they're going wrong, right? So for people starting off, I think, I think when I meet individuals like that, that can connect with people, that can articulate a message, that can write, for me, it's, it's extremely valuable. And I look for those folks. What I would say is, you know, I think there are a lot of cool programs out there through colleges and, and, you know, 6 and 8 week starter programs at different academies and things like that where you can you can get some of the basics.
What I always counsel people on is, you know, don't specialize too early in the process, right? I think, I think if we think about the CISSP and the domains in the CISSP, that's security, right? And so having an understanding of what each— what happens in each of those domains is, is important. And, uh, you know, everyone's got to pick a path. And so you know, starting on a, on a SOC and doing, doing, you know, event monitoring, or starting in compliance and learning a standard and learning how to go and, and assess risk and stuff like that.
I mean, those are good places to begin in security, but I think understanding the big picture a little bit and how things fit together is critical. Yeah, I always, when I talk about the understanding the big picture, I'm thinking it's as much about vernacular, you know, that the taxonomy of security. And, and when I say risk, you shouldn't say— you shouldn't think threat, right? You need understanding that we do have a common language that makes us effective. Um, that's really what I get out of someone like getting a Security+ certification, right?
Like, that's not going to make you better at your job, but it's going to make you better able to communicate about your job, which, you know, in the end does make you better at your job, you know, in terms of effectiveness. I think that, that, that's the way I think of it, is it's It's understanding the concepts, the ideas across our whole area. And then you're going to have to at some point dive in and say, well, what am I going to actually be good at doing? Which is like to your point, going after being a SOC analyst or being a compliance person focused on a specific standard. Yeah.
And I think that's where the gap is, right? I mean, we're getting better. Schools are getting better with the degree programs and these academies are new, but they're teaching the fundamentals and the basics. But I'll never forget, I mean, I did all sorts of recruiting on-campus stuff when I was at PwC. And since I was in Atlanta, I did stuff not just with the University of Georgia, but at Georgia Tech.
I remember this one time I was talking to this kid and he was brilliant. He had a 4.0 and a double major in medical device engineering and physics or something like that. He owned patents. And he loved security, but he couldn't tell me what a firewall was, right? And there's a— and he had taken security courses throughout his time.
And I think that's a miss, right? I think there are some fundamentals that we can do. So I agree. I think the vernacular, the taxonomy, the, you know, what everything means is certainly important. And then just having at least a foot-deep understanding of all the domains and what they really mean, how they sort of tie together and complement each other.
So I heard what you said about what makes someone interesting to you. I think that the pushback we might get from them is that it's really hard to differentiate skills like curiosity and hardworking on a resume and actually to get through a filtering process. So do you have any recommendations for how they can demonstrate those things in such— in a way that show up through your application process? I'm not sure. I'm not sure I have a lot.
I, I would say, you know, for me it's less about an education and where you went to school, and it's more about how the, how the resume is organized and what sort of brand are you projecting with your resume. It's, you know, I'm not crazy about keyword searches and all that. I mean, I realize we have to— I don't do those, but our recruiting team does, and that, that's, that's part of it. But if I can look at a resume and understand the image that someone's trying to convey, um, I'm interested, right? If it's, if it's a, if it's a, if it's a good image, if I can see someone that has put thought, uh, into how it's organized, how the information is, is portrayed, um, for me that's enough.
I, I can see someone's put the thought and care and skill into, into a resume I'll usually take an interview at that point and then, and then try to go from there. One thing that I've suggested to folks in the past is for them to, to show their, their passion and curiosity about security by doing something like getting involved with an open source project. You know, get on to OWASP or get on to GitHub and start contributing to those projects, or, or get involved with a local community association. Yes, that kind of stuff shows to me that it's not just, hey, I wrote a resume that I can change into 6 different resumes for 6 different industries and say I'm interested in all of you, but there's actually some time in behind it. Right.
Does that resonate with you as well? Absolutely. I mean, you know, if someone's not immersing themselves in it and what I say is when I have a new joiner in security, I like people that go home and they want to learn more security. Right? And they're not just focused on it while they're, while they're at work, right?
So seeing that effort is big. I think, um, I think that's a, I think that's a key part of it. Yeah, right. Um, associations like that, I, I always, you know, even when people, you can tell people do something like read Krebs, right? I mean, to me, that's a, I don't care what you're doing and where in security or, or in IT for that matter, you ought to be keeping up on on where the industry is going and pay attention to this stuff.
Or dark reading or CSO, or there's a million different options, right? Just pick the thing that— or you can listen to the Colorado Equals Security podcast, right? And that, right? Yeah. And that.
All right. Well, so the other audience that, especially when I get someone like yourself, a CISO for one of the big companies in town, there's always a bunch of salespeople listening. So for those salespeople listening, what's your advice to them? They want to sell you their service product, you know, doohickey, how should they go about it? Yeah, I— you know, it's funny, we just corresponded on some of this.
I, I don't do well with just blind, uh, you know, cold call type, uh, things where someone's pitching yet another type of technology, right? I, I don't have time to consume all this anyway. Yeah, I don't frankly, I don't read it. It's not effective. And I don't enjoy when people just send me stuff blindly that it seems kind of slimy to me.
So for me, it's if I have a relationship with a vendor, then I'll talk to that vendor and I'll take their call anytime. If I have a problem to solve, I will seek out some of these different solutions and And, you know, and, and I try to give everyone a fair shake. So, um, so we'll do proofs of concept and things like that to, to, to see if these things, these things have technical merit. But what I don't do well with is just the, you know, the cold calling, the, the barrage of things, the general messages about how this wonderful new technology is silver, silver bullet, is going to make my job super easy. I I don't even— number one, I don't consume it.
Number two, if I do see it, I, I don't believe it. So when— if, let's say, put yourself in the shoes of this, you know, just out of school salesperson who's been told you got to go close some deals in Denver, a brand new product no one's ever heard of. Do you have any, any advice for those folks how they should do it? Um, you know, learn it, learn it very well. Um, figure out what it does that is unique and better maybe than other competitors in that space and be able to somehow apply that to a particular problem, right?
Because when I do look, I'm not always looking for the biggest and the people in the— they're always top right in the Gartner Magic Quadrant. I'll look at startups, and in fact, I like new technology when I have a need for it because you can help influence where it goes, right? Which is really powerful, and you can kind of get in on the ground floor, and, you know, especially when you're a big organization. So I don't mind doing that, but I would say for those folks, don't give just general vague messages about how things are wonderful and perfect and going to solve all my problems. Be descriptive and talk about specifically what does this do.
Yeah, right. What problems does it solve in what sectors, right? Right. Figure out what problems people are experiencing and figure out how your, how your solution makes their life better. Yeah, I've noticed that there's a— I'm sure you get the exact same emails— there's a lot, a flood of emails that say something like Hey, I have this new, you know, cloud security solution.
I'd like to get 30 minutes of your time to talk to you about it, right? And if you ever did take their call, which I'm sure you don't, but if you ever did, what they would say is, tell me about all your problems. And then they'd expect you to talk about your infrastructure and all your problems, and then they'd say, well, here's how I address those problems. Yeah, I feel like you— what you just described is basically the opposite of that. You know, I understand that the salespeople really want to understand your problem so they can cater their pitch to it, but you're so busy.
And, and of course there's a trust issue for us too, right? I don't, I don't trust you to tell you what my problems are in my security program. Yeah, those things sound like social engineering. Totally. Yeah.
And so what I think that the first— and I'll tell you the guidance I give within Ping and with anyone who asks me, you know, the subject of your email needs to specifically say what problem you're going to solve for them. So that if Artie is sitting at his desk thinking, you know, today I could really use a doohickey that'll stop bots from getting to my website, and the subject says, we stop bots from getting to your website, you might click it. You might not, but you might, right? You're not gonna click one that says, you know, improve your web security now, right? 'Cause that doesn't mean anything to anybody.
Anyway, I'm preaching. Yeah, I, you know, personal referrals, I mean, if I, you know, Colorado Equal Security does a lot of great stuff for, for the security community here. If, if I, if I talk to you, if I talk to Alex, if I talk to one of our peers, uh, and they have good things to say about something, I pay attention. Yeah. Um, if, if someone I work with, uh, you know, brings something to me, um, I'm— I'll take a look at it, right?
Yeah. I'd rather, I'd rather do things that way. So, so rather than them sending a cold email, they should spend more time trying to get their current customers to advocate, make sure their current customers are extremely happy and become their salespeople for them. That's, that's it. Yeah.
Yeah. That makes a lot of sense. Yeah. And it's funny, you know, you talk about when we hear from our peers how it really sticks. It's— I think it's mostly because we spend most of our time complaining about our vendors to our peers.
Yeah. About how unhappy we are that whenever someone's really happy, you're like, oh, I got to, I got to figure this out. That's right. Yeah. Yeah.
I got all the topics I had to kind of specifically to go through. Is there something that you want that I didn't ask that I should have asked? You? Um, that's a good question. Uh, where maybe— where do I see security going?
Yeah. And where, you know, where are we going? Yeah, where are we going? And, and what are the hardest things to— skills to find? Sure.
Stuff like that. Um, you know, we're, we're headed— we're, we're headed toward more automation and more sophisticated attacks and all that kind of stuff. So So, you know, to a large extent, I think things like, in some cases, machine learning and AI are just sort of buzzwords, right? That there may be some of that, right? There may not.
But I do think our job is going to get increasingly more complex and we're going to have to have more, not just more tools, but more people in process. I don't think people and humans are ever going to go away. Right? You still need a decision maker. You need somebody, uh, you need somebody that can connect disparate pieces of information.
Even though the promise of AI is, is great, you still need someone to decide, yeah, I'm going to do this, or no, I'm not. Um, so, so I think much more automation is, is where we're headed. And I think, you know, the other thing I'd say is skill-wise, right, cloud, cloud anything, cloud security is That is the single hardest skill for me to fill. It's not even security, right? It's just cloud skills in general.
Yeah. I mean, we could teach them the security part. You talked about that earlier, right? But they got to understand the difference between a VPC and a security group. And not a lot of folks do, right?
Right. Yeah. And then application security and DevSecOps and finding developers with, with, uh, with security expertise or finding security people that have been developers, right? All that stuff is— I think we've recently talked about that huge challenge as well. Yeah, that's great.
Yeah. Um, any, anything else you want to talk about where you see us going? Um, no, I mean, what, what do you think? Oh, well, I mean, I'm a big fan of, uh, number one, the cloud is the best enabler of improved security we're ever going to get when we do it right. Now you lift and shift into the cloud, you just made your security worse, not better.
That's right. But you do it right, and I actually think it's a massive improvement. And then, you know, I've talked about it before, zero trust. I personally believe that our move away from perimeter security into, you know, maybe it's not— we don't have it one— we don't have one big perimeter, we have 1,000 little perimeters everywhere around every endpoint, around every identity, around every web application. I think zero trust is where we're going.
Yeah, and, and that's, you know, there's 3 big components to zero trust, right? There's, in my model, Robb Reck's personal model, which is pretty close to the Ping Identity model but not exactly. Um, I, I start off with the endpoint, the laptop or the phone or whatever it is. If I'm going to give that device access to my most sensitive systems, I, I need to really trust it. I need to have assurance that there's no screen scraper that's taking off, you know, all of my, you know, acquisition plans and screenshots going, going off to bad guys, right?
I want to have a level of assurance there. Um, then, then I say that on the, in the middle, there's a highly sophisticated identity access management tool that gives you just-in-time access, authenticate, adaptive authentication, you know, step up when you need to, risk-based everything in the middle. And then on the other side is our, our resources that we're connecting to, the workloads. So whether that's your SaaS applications, whether it's your data center applications, doesn't matter all that much. You should be able to access them from anywhere with the right controls in front of it.
And it's not to say that there's no firewall, it's just that the firewall isn't the normal way. We're not VPNing in and getting everything, right? We're getting access based on, you know, the, the context of the user. Hey, they're connecting from a kiosk machine somewhere, they can only get view-only for these really low-risk systems. Or they're connecting from, you know, from their trusted machine, from their trusted IP address.
Oh, we're gonna give it— we're gonna open up the world to them. Them. Yeah, all those things add up to me to where we're going, and we're going to deliver it mostly in the cloud. Not all, but mostly in the cloud. And that'll make it easier, and it's going to be faster and faster.
CI/CD, it's all going to have to be built in. And, and those of us who are used to having security gates at the end are, are going to have to get used to not having them there, right? Yeah, yeah. No, I, I, you know, great, great point. And I think, I think the, I think the challenge with Zero Trust is, is getting your getting your stuff together so that you can implement something like that, right?
I mean, I, you know, I, as a former consultant, I see so many organizations take leaps and invest in technology and things like that without figuring out the basics first, right? And so that's, I think, our challenge is making sure that we've thought everything through ahead of time and then we go and we find the technical controls that we're going to use to accomplish Yeah, you know, what we've already figured out, right? Well, I think— I personally think that that's— it's the most fun topic to think about because you can actually, like, you can make the user experience better while you improve security. And, you know, most of the time it's, it's a trade-off, right? There's an opportunity for us.
Yeah. Well, I know it's, it's been awesome having you back in the security community the last year and a little bit. You know, we lost you for a couple years, uh, you're back. Hopefully I— we're gonna see you talking at RMISC, I think. Yep.
Did I make that up? You're going to be on the Colorado CISO panel? I am going to be on this panel. That's right. Yeah.
So that should be a lot of fun. Folks can come say hi to you there, I hope. Yes. And, you know, we'll see you around town. Anything else for the community you want to share before we call it a day?
We are, as most places are, we are hiring. We will have a presence at some of the recruiting tables and the job fair at the RMISC. We're always looking for energetic, curious people, right? Awesome. I think all of us are hiring all the time, right, with the skill shortage.
But yeah, absolutely. I'm looking forward to the RMISC. I'm looking forward to the panel. I'm looking forward to meeting some new individuals. And I recently had someone tell me that he felt like the security community in Colorado was a little standoffish with, with new joiners.
I thought that was funny. I think, I think we're welcoming. It's, it's relatively closely knit and it's still, it feels small. Like you run into the same people all the time. But I think when new people do come in, we, we, we embrace them.
I'm hungry for new people. That's right. Who's not? Get them, get them invited. Yeah.
Yeah. That's awesome. Yeah. Cool. All right, Artie.
Well, thanks so much. Well, hopefully we'll talk to you in a year or so and see how things have changed. I appreciate it. And Robb, Alex, guys, I really appreciate what you do for the security community in Colorado. I think it's fantastic and truly unlike the experience anywhere else.
Thanks, Artie. I appreciate it. Yeah. All right, guys, that's it for this week. We will talk to you again next week.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.