Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 119 for the week of May 27th. It's Memorial Day, Alex.
Yeah, here we are spending our Memorial Day together, Robb, holding sparklers and fireworks and watching. We're We're also doing the Pledge of Allegiance and saluting the flag. Those are some tasty hot dogs that your wife is grilling up over there. Sure are. Sure are.
All right. Well, this is a big week. We're only one week away from the Rocky Mountain Information Security Conference, and we'll talk a little bit more about that later. I know you have some exciting news you want to share on that. But before we get into that news, we're going to do a little bit of a cliffhanger there for everybody.
Let's talk about some housekeeping. Um, the— we have a Slack channel. We're at like 925 people on the Slack channel. Yeah, I've got 1,000 firmly in my sights. If you haven't signed up for Slack yet, um, well, you're, you're an idiot.
I think that's— that goes without saying, doesn't it? You know, I don't know that I'd go that far, Robb. Maybe you're just a slow adopter, but there's still time. You can sign up for Slack now. Uh, also you could sign up for our mailing list.
You go to the website colorado-security.com, you Go to the bottom of the page. There is a signup form for the mailing list. Once you sign up, you will get the show notes in your mail whenever there is a new show. And you can also find the Slack link to join Slack on that same page, colorado-security.com. We also would love it if you would rate us and subscribe on your favorite podcast listening application.
We just recently got signed up for Spotify, right? We did. So if you're listening on Spotify, welcome. If you're not listening on Spotify, maybe you should try that out. Yeah.
I'd also say if there are other platforms where you'd like us to be on where you can't find us, please let us know. Also, tell a friend. We would love for you to spread the word about Colorado Equal Security, both the movement itself and the podcast and the website and the Slack channel. Just let everybody know how great it is and how much you enjoy it. If you've done that, you've told everyone you want to tell, but you're thinking, man, I just wish there was more I could do to support the Colorado Equal Security movement.
Well, good news. What would it be, Robb? There is— there's a couple of things. Number one, we would love it if you would help financially support the movement. We've, we've got a Patreon campaign.
You can go out to the main website for the podcast and sign up there. But also, we would love it if you would help us with getting interviews. So, you know, we— half of this podcast, or more than half of the podcast each week, is sitting down and doing interviews with interesting folks in the industry, in the community. We had Mary Writz do a series of 3 podcasts for our interviews for us. We would love it if there's others out there who think they have, you know, know some interesting folks in the community who they'd like to share.
You guys could do interviews, share them with us, as long as they, they pass the, you know, Colorado Equal Security seal of approval process, uh, we'd love to have them on the show. Yeah, exactly. Um, well, I guess let's, uh, jump into the news. Well, before, before news, we have one more announcement here. Uh, we are right in the process of building a salary survey, and, and in fact, in the next week or so, you should see this come out on the Slack channel.
We'll probably put something on the front page of the website, maybe. So I think we might. But Robb, before we do that, yeah, This sounds really weird. Why would we have a salary survey? Why are we?
So we're doing a salary survey because it is incredibly difficult for folks to understand where do they, where should they be in terms of their pay for their job as, you know, as a security professional. What should I expect to make? And, you know, there's, there's different staffing companies out there that give it, but it's not, it's not usually specifically security, specifically in the Denver metro area. And that's what we're building. Or if they give it to you, then you have to jump through a whole bunch of hoops to get the data and who knows how good the data is and yada, yada, yada.
So, so yes, I think that those are great reasons. We do have a lot of discussion on the Slack channel about jobs, and some of that discussion is around salary. I think from both sides, you know, both from hiring managers and from folks that are looking for jobs. So I think getting some real hard data on that would be pretty cool. So expectation is you should have— you should see that out in the next few days.
There'll be a chance for you if you fill out the survey, you'll get the results of the survey. That's the way we're trying to do it. We are anonymizing it so you don't have to map who you are to when you submitted it. You just have to basically submit it and then you confirm that you've done it. You get the results of the survey coming up pretty soon.
Yep. So let's jump into news first. Billionaire Robert F. Smith pledged to pay off the student loans for all of the graduating class at Morehouse College. This is awesome. He is a Denverite.
He's a Denver native. And not only that, he also owns somewhere in the ballpark of like 7 or 8 companies here in Denver. Well, he owns Vista Equity Capital. Yeah, and Vista Equity owns a number of companies here. Yeah, so, so that Vista owns Ping Identity, you know, where I work.
They own Zach Lee, Vertafore, Granicus, Returnpath, Four Winds Interactive, Finastra. They formerly owned Marketo. Um, so lots and lots of, uh, companies, lots of employees in Denver were really proud when we saw this story. I know within Ping it was a big deal. We really felt, um, you know, I guess proud, right?
It's just a really cool thing to see someone, uh, reinvesting back into the next generation. He had a great quote in his, in his speech to say, hey, you know, it's not a question of, you know, trying to get a seat on the bus. It's— he wants— he says you need to own the bus and, and be driving the bus and then make sure you're picking up others on the bus with you. And that, that was his motto and what his message was for those graduating seniors. And I don't think that there is an exact dollar amount that has come out because, you know, some of that information is private.
But, you know, there are, I believe, around 500 students in the graduating class. And, you know, it's going to be multimillions of dollars to pay off the student loan debt. I heard was tens of millions. It kind of made— probably not any more than $40 million. I think that's what I heard.
That's crazy. Yeah. Cool stuff. So obviously, big shout out to Robert Smith for doing that. Next, we have a story from FiveThirtyEight, which is— this is a sponsored story by WeWork.
But it's actually pretty interesting because it's all about Denver. It's about Denver's tech boom and how Denver is building the next generation of thriving businesses. Yeah, so the article goes into many different facets of why Denver is a great place to start a business, talking about the, the people that are here, talking about the low corporate tax rates, talking about lots of different things that they have in Denver infrastructure, you know, public transportation, public transportation, collaboration. You know, balanced work life, lots and lots of things that make Denver the great place that we know it is and the great place to work. Yeah.
So really cool stuff. It actually shows Denver as being the 5th best economy based on their analysis. It looks like it's behind San Jose, San Francisco, Austin, and Seattle. So pretty cool stuff. This is, like I said, sponsored by WeWork.
But, you know, we have talked about the fact that WeWork has become or is about to become the biggest leaseholder for space in all of Denver. So, you know, it's a big, big partner with us here. For sure. Next, Colorado has the lowest foreclosure rate in the country. Pretty cool.
That's pretty cool. They say that only 1.78% of mortgages are more than 30 days past due. That's pretty good. Do you miss more than 2% of your mortgage payments, Alex? I do not miss 2% of my mortgage payments.
I miss less than that. That's pretty good. That's pretty good. So they say that last year, 2018, there were 1,461 homes that were sold in a foreclosed or foreclosure sale. Now, if you look back 12 years ago to 2007, there were about 40,000 homes that went through foreclosure.
So just massive difference. Yeah. Some of the things that they talk about, you know, one, that Colorado has a great economy right now, but also, you know, the mortgage process is much more regulated and stringent now after the crash. So it is— it's much harder to get a bad loan. And they also think because, you know, you look at 2007, there were 40,000.
That was a little bit before the crash. We actually had a lot of foreclosures before the big crash. And they think a lot of those people got pushed out of homeownership. And so now the people that are coming into homeownership are under these sort of new rules. And so it's, you know, that has helped us get that foreclosure rate lower.
There's another interesting stat they threw into this article that Colorado home prices have risen by more than 80% since 2011. 80%. That is pretty crazy. Yeah. Good.
Good for people who bought in 2011, I guess. Exactly. Next, there is a drone training facility that is coming to Garfield County Airport in Rifle. So I didn't even know that drones could learn. That is amazing to me.
Well, you know, you never heard the joke, you can't teach an old drone new tricks. So, so I think maybe they, you know, the editors might have wanted to add drone pilot training Uh, to the, to the head— to the headline here. But really what they're doing is they're building a, a place for folks to get qualified at the Rifle-Garfield County Airport. So this is put together by— it's actually going to be run by the Center of Excellence for Advanced Technology Aerial Firefighting. They're proctoring the training, and you're going to be able to get certifications from DHS, from NIST, And from the American Society for Testing and Materials, the ASTM, really around their certifications for drone piloting.
Yeah, that is pretty cool. I guess I hadn't realized that drones for fighting fires were that big. I mean, I had heard of, you know, using drones for firefighting before, but I guess to have that many people get qualified, it's pretty cool. It sounds like a lot of fun. They also said that they are building a facility to do this.
So it's not, you know, like out in a field or something like that. It's sort of a I think of like sort of a hangar. Yeah. And it's so it's indoor so people can do this all year round. And it looked like it was frames that were covered by, by canvas so that all of the RF waves can go through it.
So you don't have to be able to see something to, to be able to be able to control your drone. Exactly. Next, we have a story about Ibotta. They are a Denver-based tech company that's looking to change the way we do checkout and make checkout at a store fun and memorable. Yeah, so Ibotta really started as a platform for, I don't know, you can call it membership rewards or, you know, something like that.
You get cash back and other rewards. You scan your receipt when you buy something. Right. And based on, you know, scanning your receipt, you get some kind of cash back. Yep.
But they are now turning their platform not only into doing those rewards, but into an actual payment platform itself. So you can pay for these things through the Ibotta platform and get the rewards at the same time. And they already have a lot of big retailers signed on. They are, they're in with Chipotle, Home Depot, and 30 other retailers. Pretty, pretty good footprint.
Yeah, you know, have you ever used Ibotta? I may have once or twice, but I'm not a regular user. I never have. I know headquarters is just a block or two away from my headquarters downtown. I probably should take a look at it.
Yeah, one of the things that they also said in the article was that they are a little bit more privacy-focused. So they are collecting data, as you know, most merchants do directly, but that you have more of an opportunity to opt out and choose what they do with that data as opposed to the merchants who collect it and you don't have any say over it. I like it. Yeah. Uh, next, uh, San Francisco-based CircleCI is opening their second largest office in Denver.
So I've never heard of CircleCI, but they do— they're a platform that lets software developers build, test, and deliver their, their code continuously. Um, and it— right now they have 10 people in Denver and they're going to hire another 15 or so before the end of the year. Pretty cool to have yet another Bay Area tech company opening up here in Denver. Yeah, I hadn't heard of it either, but it's, you know, continuous integration CI platform. So they say it makes it easy to code on the platform and do continuous integration, which is cool.
They do have some, some big-name customers that they lift in here— lift— that they list in here. Lyft being one of them, Spotify, Dollar Shave Club. So it's not a small player. Good stuff. Next, we have a press release from Coalfire.
Coalfire has released a couple of new cloud services. So they already have a few cloud services. They had 3 that they listed before this, but now there's 2 new ones. They've released the Secure Cloud Automation Services, which help enterprises enterprises build customized automated security process— processes for compliant audit-ready cloud environments. Sounds like they're really just trying to, to help you mature the way you build your cloud environments, right?
And the second one is, uh, their, their new Cloud Security Strategy and Maturity Assessment service, which helps you evaluate your organization's current cloud security posture and then make changes based on where you want to go from there. Yeah, and these 2 services add to their portfolio that they already have of other services, including cloud pen testing, cloud compliance, and cloud security risk assessments. Cloud, cloud, cloud, cloud, cloud, cloud, cloud. I didn't hear blockchain in there anywhere. Uh, next, uh, Optiv had a press release about their, uh, new report that is coming out.
This is the, uh, excuse me, Cyber Intelligence Report, Security Cyber Intelligence Report. It looks at the threat landscape, and they had some key findings from the report. First, there has been a rise in cyberattacks from the Netherlands and from Lebanon. I would not have guessed either of those. Neither would I. Cyber social is the next front for nation states.
I don't think that that is any surprise. Right. Social media is a good way for people to, to influence and kind of hide under the radar. Right. Critical infrastructure has been breached.
Again, I don't think that's quite of a shocker to me. I can't believe it. Healthcare IoT is vulnerable. Again, what year is this? This is 2009.
Where are we? Phishing remains the delivery vehicle of choice. I can agree with that. And then finally, protecting the brand rises in importance. I think that that one is interesting.
Maybe not one of the ones that I would have put at the top of the list, but interesting to see that that came out in the report. Yeah, I do. You know, just to not be too hard on them, I think whenever you write a report that's true, which I'm guessing this is, it's going to say the same things every year. Right? Right.
It's not changing all that much. So this report is reflecting the fact that, you know, we're still vulnerable to the same things and the bad guys are still doing mostly the same things. You know, there's a few new trends. I like the fact that they went after the social aspect, which that is relatively new, and this focus on the brand. I think that's pretty good stuff.
But mostly it's the same old every year. Last year there was bad stuff, this year there's bad stuff, mostly the same bad stuff. Uh, well, we also had a press release from Ping Identity this week. We released something talking about, um, the Ping ID MFA focus with the Citrix Analytics and how that gives you better security together. Yeah, so Citrix Analytics is a behavior analysis platform, you know, to detect uh, anomalous behavior.
And they're using— Citrix is using it in their Citrix Workspace. I believe this is sort of like a virtual desktop service. And they have partnered with Ping so that when their analytics detect that something is wrong, you know, maybe that someone is not acting like they should, potentially compromised, they can use Ping MFA to do step-up authentication. I love it. Pretty cool.
Next we have a blog post. It's actually more research even though it isn't a blog post. Research by Red Canary around a Pastebin scraper, stenography, and a persistent Linux backdoor. This is a pretty in-depth technical write-up. It is a very in-depth technical write-up, pretty long.
This is by Dell Armstrong. I don't know that I know Dell, but it's a very good write-up. Basically, Dell started by looking at Pastebin, just searching for a few things, and it sort of led down the path of finding a, you know, an initial infection vector that then downloads what appeared to be a picture that had an executable inside it that then downloaded another executable loader that in another picture and so on and so forth. The result of all of this, if you— if it had been executed by someone, is a Rickroll at the end. Yes, yes, definitely a Rickroll would have been persistent access via SSH into, uh, into a, a host because every time the root account ran, it would replace, um, ls with a backdoored version.
So, uh, pretty cool, interesting write-up. I thought it was, uh, pretty neat to read about. If you, if you like to, to read about the technical inner workings of, of bad guys right now, this is a good chance. And thanks to Del. Del is a local Colorado guy.
He's a detection engineer for Red Canary in Boulder, previously at IBM. Maybe you ran into him at IBM. Maybe I have. Well, good work to you, Dell. That's it for news.
Moving over to our Slack message of the week. We want to start off by saying thanks to Andre Gaeta. Andre is the sponsor for this every week out of his own pocket. Thank you so much for doing this. Thanks to Andre, we do get to give one item from the Colorado Equal Security store to the winner of this Slack message of the week each week.
So this week's winner is Ben Downing for sharing the regex golf site. So there was a question on the jobs channel this week. About how to brush up on your regex, and he shared that site. You can go to there and go there and practice your regex. They give you some tough tasks like, you know, on the left side here are the results that should come back, and on the right side, results we don't want to come back with your query.
And basically you get to practice your regex skills till you can, till you can get only the correct results. Awesome, good stuff. Congratulations to Ben, you'll get to, you'll get an email to pick something from the Colorado Equal Security store. Events. We are on events.
Yes, let's do it. So, uh, we have an event calendar on the website. Go out there and check out all the stuff coming up through the end of the year. We do use this as a way not only for you guys to know what events are coming that you can attend, but also for those groups in town that want to plan events to go out and make sure that they don't schedule their, you know, their meetup right over the top of somebody else's meetup right across town. Exactly.
So first, as you might have noticed, we've been talking a lot about the Rocky Mountain Information Security Conference. That is just a little over a week away. Pretty amazing that it is here already. I've got some news about that. So we have sold out our exhibit hall.
So apologies to any of the sponsors that are out there that wanted a booth. We have no more booths. We do— are there any other opportunities to sponsor? We do have a few other opportunities to sponsor. So please still reach out if you'd like to get involved.
But I do have to say that I'm pretty proud that we sold that out. It's a great thing. We're doing really well on that front. Also, we are on track, we're very close already to getting a record number of attendees. So again, growing, that's a good thing.
Glad to have all of the Denver community participating in Rocky Mountain Information Security Conference. If you haven't signed up to attend yet, please sign up to attend. We would love to have you there. And just as a reminder, I guess reminder for those who do know and for those who don't, is some more information. This is a nonprofit conference.
This is not your RSA conference or your Black Hat that's looking to make, or your SecureWorld, right? That's looking to make money on the event. This is put together by nonprofit groups, ISSA and ISACA. While some profits do come out of it, those profits are all used directly to fund the chapter events in town. So nothing's leaving Colorado.
It's all meant to be used to improve security in the state. So it's a good thing. It is a good thing. And we do keep the cost as low as possible for registration for the attendees and high value, right? 3 days of events for, I think, $250 or something like that.
Yeah. Membership gets you a cheaper price, membership in ISSA or ISACA. And yeah, we look forward to seeing everyone there. All right, well, let's go ahead and go through the events for the next 2 weeks. We have our GDPR meetup, the social event on the 28th, which is the 1 year under GDPR meetup.
I assume lots of drinking and commiserating war stories. I'm sure. On the 30th, ISSA Denver is doing a happy hour. Also on the 30th, Check Point is doing their Cloud Mobile Threat Prevention: Welcome to the Future of Cybersecurity event. I'm glad we're in the future.
On the 31st, CTA is doing an innovative look into ethics. On the 6th of June, IAM is doing their IAM networking event, which I think is actually at RMISC. I think it's actually specifically part of the event. So that would actually be on the 4th. What'd I say?
I said the 6th. You said the 6th. 6 is the month, 4 is the day. Also on the 4th through the 6th is the Rocky Mountain Information Security Conference. Um, just to, just to clarify, that IAM meetup is, is right after the first day of the event over at South Street Social.
Oh, there you go. Yeah. Um, so, uh, on the 5th through the 8th, CTA is doing their Techstars West Slope Startup Week. So if for those, anyone who's listening from Grand Junction or anywhere on the West Slope, they're coming out to you. On the 6th, Splunk is doing their First Thursday meetup for Topgolf.
You can get done attending RMISC and head down to Topgolf. That sounds like fun. And on the 7th, there is down in Colorado Springs, they're doing their First Friday Cybersecurity Social and Mixer. Also on the 7th, is that the 7th or would it be the 8th? They're actually doing the 7th and the 8th.
Oh, the 7th and the 8th. Okay. So ISSA Colorado Springs chapter is doing their CISSP prep class. So this is the first of the prep classes. They will go on for several weeks so they can cover all the different domains in the CISSP.
Yeah, they're doing something like 7th and 8th. And then I think they're taking 2 weeks off and doing 2 more days in a row. It's a little, different schedule this year. All right. But it's, I'll just say, one of the best values you're going to get for training.
You want to learn how to learn the CISSP for a very, very reasonable cost. I think it's just a couple hundred dollars for all of the different sessions. Or you could go, you know, pay for a week-long boot camp and spend several thousand dollars and not get the same level of information. It's good stuff. Uh, obviously we really appreciate ISSA Colorado Springs putting that on for us.
That is it for the rest of the, uh, next 2 weeks. We can go ahead and move over to jobs. Every week we try and, Alex and I, We comb the web looking for the very best jobs in security here in Colorado. We have to make sure that the web's part is in exactly the right place when we comb it. We comb the web.
We do get people reaching out to us on a regular basis to add jobs, and mostly we say, no, that job's not good enough. We only put the best jobs on here. No, just kidding. If you post a job in the jobs channel on the Slack channel, it will probably end up on the podcast because we're lazy and we want to get the easiest way to get the jobs on here. But speaking of the best jobs in Colorado, Ping Identity is hiring a few different product security positions.
So we're looking to hire leaders in product security. If you are a, uh, an application security guru, uh, please reach out to me on the Slack channel. I'd love to talk to you about a management position there. And we're also looking to hire an individual contributor, a junior product security engineer, someone who's got a development background with maybe a passion for security, looking to make that change into security, or a little bit of a background in that area. Reach out to me or apply on the website either way.
Cognizant is looking for a senior IT security analyst. Teletech, or it's actually now called T-Tech, is hiring an information security principal engineer. Rickerly is looking for a lead security engineer. Zayo Group is hiring a cybersecurity analyst 1, 2, 3. Holy cow.
That's Roman numeral 3 right there. I think you mean III. Transamerica is hiring a cybersecurity engineer II.
I got stuck with this word. Is it Cyxtera? It's CYX. Cyxtera. Cyxtera.
Yeah, that's probably it. Cyxtera Technologies is hiring a junior business continuity and disaster recovery analyst. And this specifically looks like someone who maybe is new to the industry looking for their first role. You know, I think that's a good one because I'm all for the junior disasters. None of the senior disasters, just the little teeny junior ones.
So The good news is if it's a big disaster, someone else will take care of it. That's right. This person only deals with the junior disasters. Colorado State University is looking for an intern in security architecture. It's that season.
We've had quite a few intern postings recently. And final job of the week, FireEye is hiring a security consulting project coordinator. Ooh, that's very exciting. Good stuff. Well, Alex, bad news for you.
This is it for the news. What? Yeah, I know. But I guess good news for you is now you get to listen to an interview. Yay.
This is the first time we've ever had a member of the Attorney General's Office on the show. Ooh, that's very exciting. So Daniel Pietragallo, who is the— oh gosh, I'm going to get it wrong here— the Senior Associate Attorney General for Colorado. And he's the one focused on cybersecurity within that office. That's awesome.
So I thought he'd be a perfect fit for us to talk to. I really look forward to hearing that interview. All right. Well, that's it now. Happy Memorial Day, everybody.
Hopefully you're enjoying your Monday off and you're listening to this on your drive in on Tuesday, um, and we'll look forward to talking to you guys next week, and we'll see you in person, uh, next week at RMISC. Awesome, thanks Robb. See ya. Hi, I'm Tim O'Brien, the Director of Information Security at Educause. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is Robb, and I'm sitting with Daniel Pietragallo, Daniel, you are an attorney with the Attorney General's Office here in Denver, Colorado, I guess, for the state, right? We have a new Attorney General, Phil Weiser, and I'm excited to understand really what Attorney General Weiser's focus is in terms of cybersecurity and privacy and where he's going and how your background got you to where you are. But first, I understand that you are something of a of a connoisseur of Pearl Jam concerts, and I'd like to know, question number 1, when did you first attend a Pearl Jam concert? That's a great question.
My first Pearl Jam concert was in 2000, so shortly after I graduated from college. I was not a big Pearl Jam fan or a big rock fan, and somebody handed me one of Pearl Jam's albums, I believe it was Binaural, which is one of the albums that's not popular at all with, you know, musical critics, and I loved it. I took to it. And shortly after I started listening to Pearl Jam, early the next year I met my wife, and we, we kind of bonded over that. That was our initial discussion.
She goes, oh, you like Pearl Jam? I like Pearl Jam. And so here we are 18 years later. So shortly after you were introduced to them, you met a girl, and as a result of the girl, now you're a really big Pearl Jam fan. Is that what I just got out of this?
That's quite a leading question. Are you sure you're not formally legally trained? Yeah, yeah, pretty much. So how many Pearl Jam concerts have you attended? So I've been to probably about 35 Pearl Jam concerts in my life, all since 2000.
So that's almost 2 a year. That's a pretty good rate. It is. You know, they, they tend to ebb and flow. So Pearl Jam will go on tour for a year, and then they'll take a year, 18 months off, and they'll release a new album, and they'll go on tour again.
So, you know, when they go on tour, we'd like to try and catch them 2 or 3 times. You know, really fortunate. We, we got to see them on my honeymoon. Oh, that's awesome. Twice, actually.
We went to Hawaii, and December 9th they were playing— they were playing a show at the Blaisdell Center, which is the University of Hawaii's basketball arena, and there's maybe seats 8,000 people. And, you know, we were 10th row right in the center and just had a blast, and it was a great way to start off our honeymoon. And then we went to Maui for a week and came back to Honolulu, and and saw them at the Hula Bowl where Pearl Jam opened for U2. Oh wow. Yeah, so it was a pretty cool concert.
It was a lot of fun. It was a great way to do a honeymoon. We got to celebrate the thing that we both love and, and I guess celebrate our love together as well. That's really cool. So, favorite Pearl Jam album?
Lost Dogs. Lost Dogs is an album which has a bunch of B-sides and rarities and and the stuff that's deep in the closet. Yeah. And so, uh, I, I really enjoy a bunch of those songs. It's also a double album, so there's 35 songs or 40 songs on there.
A good selection. Yeah, absolutely. Favorite concert you've been to, uh, other than your honeymoon? Uh, we went to see them in Milan, Italy, uh, during the World Cup a few years ago, and that was amazing. We were at San Siro Stadium, uh, which is where AC Milan plays, and the stadium is just gigantic.
It seats like 90,000 people. And the World Cup game was on. Italy was playing right before Pearl Jam took the stage. And in order to see, you had to be further back on the floor. And so in order to see the soccer game, correct?
Yeah, in order to watch the World Cup on the TVs, you had to be further back. So there was a bunch of space right up front at the stage and bumped into a guy in the merch line who said, hey, come on up front with me and my girlfriend. And the next thing I know, I'm, I'm like 2 people from the rail in this giant stadium. You know, watching my favorite band. And it was, it was amazing.
It was a really great experience. That's awesome. So the soccer fans were able to free you up to get best seats in the house? Absolutely. And is that also the furthest you've traveled to see them?
Yes. All right, that's good. If you're gonna have a long trip, it might as well be for the best concert. Good stuff. Okay, well, I love getting to hear this background.
Hopefully they have many more albums and many more tours for you guys to enjoy. So let's talk about where you're from. Where are you from originally? So I was born and raised in Los Angeles, or a suburb of Los Angeles called Northridge. Northridge is where the, the big earthquake happened in '92.
I moved out of there shortly before that. The earthquake was in '93. I moved out in '92. So I was 13 years old. It was right before, right before I started high school.
I moved back to Pittsburgh where my parents were originally from. Yeah. And you went to high school in Pittsburgh? I did. I went to Central Catholic High School in Pittsburgh, which is the home of Dan Marino.
Oh yeah? Yeah. You got a celebrity there. And what did you do after high school? At some point you got involved with law enforcement.
I'm guessing that's college or law school or? Yeah, more post-law school. In undergrad, I went up to Ann Arbor. I went to the University of Michigan, studied political science. Watched the Wolverines win a national title in '97.
That's good timing. Yeah, 4 of the best years of my life. Made great friends, had great experiences, and it was just absolutely wonderful. Yeah. And then post-college, I went back to Pittsburgh to study law.
I went to the University of Pittsburgh School of Law. Yeah. Focused somewhat on criminal justice, did some interning in the DA's office, those sorts of things. And so when I, when I graduated, Once I got barred, I, uh, I decided to go work for the DA's office. And, you know, my plan was to go there and get trial experience, maybe work for a few years, then go to a firm and, you know, become rich and important.
But 3 years into my legal career, uh, it was 2006, 2007, the economy wasn't doing very well. And so I ended up staying at the DA's office, uh, for almost 8 years until I moved out here. But it was, it was a great experience. I did 35 felony jury trials. You know, I did, I did all sorts of cases.
I did homicides, shootings, robberies, and I did some financial crimes as well. Cybercrime really wasn't a thing back then, or at least, you know, not prominent enough that we were prosecuting those kind of cases at the time. So you got to, you got to practice your arguing in front of a jury and jury selection type stuff too, that kind of stuff I see on TV. Yeah, yeah, not, not, not quite as well scripted. No, I, I started practicing my argumentative nature when I was very young, probably in the 3rd grade.
I would argue with my teacher about whether or not my homework was late because I handed it in at the end of homeroom rather than the beginning. And so did you ever win any of those? I did, yes. And then that was the problem, like it only encouraged me to continue arguing more. Good stuff.
So you were, you were in Pittsburgh for the DA there. Um, through— was that 2010-ish then, or what? Uh, so I moved here in 2012. So my wife worked for the city solicitor in Pittsburgh, and, uh, we looked around, and she had never lived outside of Western Pennsylvania. I was looking to get more back to, uh, like that West Coast vibe a little bit.
And, uh, so we looked around, we looked for other economic opportunity. We looked at New York, and we looked at Florida, and, uh, we looked California and Washington. We basically said, where do we want to go? Where do we want to go live? And my college roommate, a guy named Justin Cole, moved out to Denver shortly after we graduated from college.
And finally, during the course of this discussion about where we were gonna move, we went out to visit him. He got married out here. My wife and I came out here, and it was just so gorgeous. Colorado totally swept us away, and we were just like, well, we should move here. And, uh, and so I— the Bar Association really helped us out in that, uh, Colorado has reciprocity with Pennsylvania.
And reciprocity means we don't have to take the bar exam again. And that's a huge benefit because the bar is a real pain. So, uh, Colorado was one of the few western states that had reciprocity with Pennsylvania. So that was really appealing to us. And so we wrote our checks, got our law licenses, and, uh, we were on our way.
Did you have jobs when you came out here? We weren't able to move until we got jobs. Okay. And so you said your wife worked for the city solicitor in Pittsburgh. What did she end up coming out here to do?
Well, she's an environmental attorney, and so Colorado really fits her uniquely well. So is there like a firm that focuses on that? She's a part of the firm? Yeah, the Colorado Attorney General's Office. Oh, okay.
Yeah. So my wife got hired at the AG's office first in the natural resources section. And, um, you know, she did some Parks and Wildlife work, and then she did some, uh, water quality work, and now she is in-house counsel at Metro Wastewater Sanitation District. All right. And then you— she got hired at the AG's office first.
Did you shortly thereafter, or was after you moved here, or what? Yeah, you know, I think we were both kind of targeting the AG's office from out of state, and we had made that known, and she sent a resume out here and got, got an interview did well, did a couple of telephone interviews, and then came out for an in-person. And eventually she just found a fit, and she started January 2nd, 2012. Okay. And then I came out here at the end of March that year.
So we still had a house, I was selling the house, I was wrapping up things at my job at the DA's office, and I was still looking for work too. I very much wanted to get into the AG's office, but, you know, the jobs weren't, weren't there at that point. So I got an opportunity to work for the federal government in the Department of Labor doing mine safety and health work. So MSHA, Mine Safety and Health Administration. So it was, it was an interesting professional transition.
I went from having to prove everything beyond a reasonable doubt to a jury of 12 to doing administrative hearings in front of an ALJ and having an administrative law judge. So just, just one guy making the call. And, and my burden there was strict liability. So it was kind of like shooting fish in a barrel. It was a lot of fun.
Yeah. Yeah. So you say mine, like a mine where you're getting ore out of the ground, basically that's what we're talking about? Correct, yes. And it was for companies headquartered in Colorado or actual mines in Colorado?
No, so how it works is the Mine Safety and Health Administration has inspectors. And so they'll go around and they'll issue citations to mines for safety violations. Those citations will then come to the litigation department at MSHA, and we'll try and figure out how to resolve them. And so given the nature of the proceedings, and they were strict liability, typically the mine operators were encouraged to pay a healthy sum to resolve the cases because they weren't going to do very well at a hearing. Right.
So, I mean, obviously so far, you know, no technology as a part of your background. How do you go from working in you know, MSHA to getting into a technology background. Robb, I want to thank you for pointing that out. So yeah, and well, it's in 2013, after a year at MSHA, sequestration hit, and I'm sure you recognize that buzzword. And effectively what it meant was that federal agencies had to cut 5% across the board.
And so MSHA took a look at the last 10 lawyers they hired and went, who can we get rid of? And so You know, after a year there, I took a job at a local DA's office, and it wasn't necessarily a great fit, probably largely due to my experience. But I was at that DA's office for a few months and then had this opportunity over at the Attorney General's office in the financial fraud unit. Okay. And so this is, this is where my introduction and work with technology really begins.
So I came over to the AG's office in 2014. And what I noticed right away was that there was a huge void in cybersecurity. So I should say, start by saying that the criminal justice section of the Attorney General's Office is probably only about 20 attorneys. So it's highly specialized, but very small. But as the chief law enforcement agency in the state, I figured we'd have some sort of technology practice or some sort of cybersecurity practice.
This while I got there, and they weren't doing any of it. And so my primary mandate was financial fraud, insurance fraud, securities fraud.
So in addition to the, to the white-collar aspect of kind of what I was doing, I— one of my investigators is a guy by the name of Mike Ciavatta. I believe he's a sergeant out in Golden now. And Mike was great. We had some really interesting conversations about cybersecurity. Security and technology, and I said, is there anybody doing any of this in law enforcement?
And he said, yeah, let me hook you up with the Colorado Electronic Crimes Task Force. And at that point, you know, we— I went to a meeting. This was only a few months into my tenure at the Attorney General's Office, and I think pretty early on I knew that the technology and cybersecurity was something that I wanted to get more involved in. And so the one thing I did was I facilitated a a memorandum of understanding with the Electronic Crimes Task Force. So I'll explain what the Colorado Electronic Crimes Task Force is.
It's a private-public partnership funded by a congressional grant that's administered by the United States Secret Service. So the Secret Service runs this group, and their mandate is to go out and to educate people about cybersecurity and best practices. So Included in the group are Secret Service, academia, private sector individuals, and other government agencies like the Attorney General's Office and some of the local DA's offices. And so the primary mission is to educate and to facilitate relationships in the field of cybersecurity and then to train prosecutors in that area. And so I was very fortunate.
One of the benefits of membership in the ECTF is that we got free training. And so I got to go to the National Computer Forensic Institute in Hoover, Alabama twice. I got to go once for a week to do computer forensics for prosecutors, and then I got to go back to do mobile device forensics for prosecutors. At that point, I was hooked because I figured out that there was really no better evidence to present in a courtroom than digital evidence, because digital evidence is very difficult to manipulate. So I'll give you an example of kind of how I put that into practice.
I did a wiretap case against a large national motorcycle gang who will remain nameless. And, you know, when we, when we used this, we hit the search warrant on the target's house, we pulled out a bunch of phones, a bunch of SIM cards, a bunch of computers, and then analyzing all of that information on the hard drives, on the SIM cards that we got, it matched up perfectly to the wiretap, and we were able to prove not only were we intercepting, um, you know, the leader, the leader on, uh, on wiretap, but we also had the simultaneous communications on his phone. And so I'm a big proponent of not only doing electronic interception but also doing computer forensic work to back it up, because then you can close the circle. And if you present that to a jury, I think they would have a hard time ignoring evidence that can conclusive. So, you know, this whole tangent makes me think of one of the best television programs ever made, The Wire, around a wiretap in Baltimore.
And I just got to ask you, you know, I know that that was city police instead of— and you're, you know, you're doing state work. How accurate is The Wire from HBO back 20 years ago? Based on my experience, I would say it's one of the most authentic television shows ever made. Awesome, I love to hear that. Yeah.
Yeah, all right, so you got learned up on how to, how to get digital, uh, forensics evidence, how to start to use that as a part of your, your cases. Um, anything else you want to talk about with ECTF and how they, how they helped? Uh, yeah, just a quick shout out to Ike Barnes, who is the head of the ECTF, um, with the Secret Service. Ike's a tremendous guy. Uh, so based on my involvement with that group and my relationship with Ike, I, I've met a number of people in all sorts walks of life in cybersecurity.
And so he's really been very helpful in facilitating the whole concept of cybersecurity and bringing it to the forefront, certainly in the law enforcement community. And so building those relationships, knowing who I can call at the different agencies is a huge benefit because it allows us to help the people of the state better. Right. There's some other groups in town that I know you've worked with and had some interaction with. So IEPP and Silicon Flatirons.
IEPP, the International Association of Privacy Professionals? That's correct. And then Silicon Flatirons, which I believe is like a local nonprofit legal professional association, right? Can you talk about where those things have influenced you guys and how you do your job? Yeah, those are 2 great organizations, and what they do is they facilitate discussions around privacy and around privacy issues.
And so I think the best way to sort out privacy and to resolve privacy issues is to have a privacy discussion among stakeholders, including the people whose information is out there getting sold and the people who are actually selling the information as well. So you get differing varieties of perspectives in groups like IAPP and Silicon Flatiron. So I got involved with IAPP through one of their leaders, a person by the name of Tracy Lesher. I think you know Tracy. Tracy did a great job of getting me involved and, and allowing me to meet a bunch of the people in IAPP.
You know, these attorneys help to advise companies on policy, on compliance, on best practice, and, and these are important roles certainly for When you, when you talk about the Attorney General's Office as a state regulator, we want to have good working relationships with the privacy community because we want their input. They're valued, they're valued stakeholders, and we want to work with them and not against them. Yeah, so this is great to understand how you got in where you are and the organizations that have helped it out. And I know when we talked, when we first met, it was actually right before our new Attorney General took over, and I wanted to hear, like, where are we going to be going in the future? So I guess that's going to be my question for you now is, like, what's the big picture mission for the Attorney General's Office in general?
And then after that, I want to hear, like, what changes Phil Weiser is going to be bringing in with his new regime. But starting off, what's the big picture for the AG? Well, big picture for the Attorney General is Phil Weiser wants to be the people's lawyer first and foremost. He wants to advocate for and protect consumers in the state of Colorado first and foremost. He also wants to make sure that there is an environment that allows businesses to thrive.
He believes that we can do both, we can both have consumer privacy and a business-friendly environment. And so those are, those are some of his priorities. He's got a deep technology background. He worked in the, in the White House under President Obama, where he was the senior adviser for technology and innovation. For the National Economic Council.
When he left DC, he came back to Colorado and he was, he was a professor, founded Silicon Flatirons. So he's got an incredible technology background and is very well-versed in policy. And so I think you're gonna see that knowledge base really put to work here during his tenure as Colorado Attorney General. So he's been on the job for just a few months. Right?
We're recording this late April, probably gonna go live mid-May, but he'll have been on the job just a few months. Have you seen any changes yet from his approach and, you know, what he's— I heard, you know, big picture, people's lawyer. What has that meant in terms of, you know, day-to-day, any changes we've seen so far? I think the biggest changes you're seeing within the Attorney General's office are that he is raising the bar. He is raising the expectation level for every attorney in that office.
Office and leading by example. Phil works incredibly hard. He is dedicated. And when he has initiatives, he wants to move them forward. He doesn't want to talk about them and let them die.
He wants to really put them into action. And so a couple of changes that I've noticed: Phil appointed the first Chief Innovation Officer for any Attorney General's office in the country. Her name is Lisa Neal Graves. Lisa has been incredible. She's made an amazing impact in our office, and she's doing great work to facilitate relationships and to incorporate more technology into what we do every day at the AG's office.
Interesting. An innovation officer at the AG. That's, that's innovative. I like it. We also started— well, as part of her innovation, we started an internal cybersecurity and data privacy working group.
And so it goes to show that we're taking cybersecurity seriously, and it's something that maybe we haven't seen under past administrations. And so Phil's also taking a multidisciplinary approach. So the Internal Cybersecurity Data Privacy Working Group includes attorneys from Consumer Protection. It includes attorneys from the medical field with HIPAA expertise. Includes me from the criminal justice section.
And so we want to have these discussions internally and we want to set good internal policies because we feel like in order to promulgate regulations statewide, they have to work internally in our office as well. Yeah, to use a, to use a phrase, we have to eat our own dog food, right? Well, I like to say drink our own champagne. It makes it sound a little nicer. It does.
Yeah. All right, so let's get a little bit more specific. What are the Attorney General's Office's priorities specifically in regards to cybersecurity and data privacy? So AG Weiser believes that the AG's Office should be a leader in cybersecurity and data privacy, and I think the question then becomes, how do we lead on those issues? So one glaring absence here is the absence of federal privacy regulations, and so So we're taking a hard look at that.
And, you know, given the absence of those regulations, we're gonna need to support Colorado laws that protect consumer privacy and choice. I think we're long overdue for federal comprehensive privacy legislation. But if we're not gonna have that, then I think we need to take a hard look at what we can do on a state level to better protect consumers.
I couldn't agree more that it'd be great to have a federal mandate on that because of how painful it's going to be for someone like me to manage different state regulations everywhere. However, I think it's not super realistic to expect our federal government to get anything done right now. So what could we do in the interim? What could you guys do in the interim to help, you know, help get something done? Well, I think that's a great question.
You know, we can have discussions, we can contemplate We could do nothing or we can take action. I mean, there's a broad spectrum of different things that we could do. I'll tell you the one thing that we're not going to do is pass a CCPA, California Consumer Privacy Act, type law right now. What we want to do is we want to analyze the issue. We want to figure out what might work best.
We want to get input from the business community. We want to get input from InfoSec. We want to get input from the privacy community. And we want to figure out how best to regulate these issues in the state of Colorado.
I am interested to hear that, you know, the CCPA perspective. As you know, I actually am a fan of GDPR as a template for things, and as I look at what should the U.S. do, I'm like, well, it'd be great if we could use, you know, as close to the GDPR as possible. CCPA, you know, gets part of the way there. My worst-case scenario is we get 50 different CCPAs with just their different nuances, so you can't comply with all of them, right? And I always just get worried that advocates trying to do the right thing make the world a lot worse, which I think we've done with notification requirements, right?
Notifications state to state are so different that you really, you have a hard time complying with all of them. You guys have any thoughts about like, ways that the AG's office can help with that, or is that really more in the legislative area? No, I think the best advice I have in that regard would be to comply with the most restrictive notification requirement, and then you'll be in compliance. Yeah, but they're not always— like, it's a combination of things to get most restrictive, because some of them are based on, you know, when you notify the AG's office and when you notify the people. And it's not just one state that you can say, well, that's the most restrictive state, you know what I mean, it's a hodgepodge of requirements.
So any particular things you guys are planning to do around, other than trying to help raise conversation, anything you guys are going to go after in the next year or so of security and data privacy? Yeah, I think one of the things we'd really like to do is promulgate best practices for small and medium-sized businesses. We feel like there is an underserved contingent there where we might be able to get information to people who can then put it into practice. To, to secure their systems and their, and their businesses. We feel like that's the best thing we can do right now.
Is that something you guys would maybe partner with, like the Secretary of State's office, as they have— they obviously have all those records for all the businesses, right? Yeah, yes, yes and no. Uh, we're kind of looking at this as a little separate initiative, but certainly we want to draw input from them. Yeah. Um, but I think what we're going to do is reach out to the various communities that I just talked about and get their and figure out how best to get these best practices out.
Is it a white paper? Is it just standards on the website? Is it actually reaching out to communities and going in person and giving in-person trainings? All of those are options that are on the table. We want to educate and we want to facilitate.
I love the idea of going to where the people are because a bunch of us writing white papers for each other to read, it just doesn't get us very far. And the people who you most want to see these things, frankly, are not going to the web and Googling white papers for how to improve my security, right? They're people who just don't think of it. So figuring out, like, do they have a professional association? How do we get in front of those small business owners?
That's high value. Yeah, and I think another thing is the statute that we passed here, HB 1128, requires reasonable security measures in light of the size and nature of the business. Well, what does that mean? We'd like to give more specific guidance to some of these businesses, and we're not going to give strict legal advice, but we do think we can point people in the right direction and help them get more into compliance and direct them to the resources they need to get into compliance. What about the enforcement of that cybersecurity law you just referenced?
Is enforcing that thing a priority for you guys? Because, I mean, there's a difference between giving guidance and then going and punishing people who violate it. How do you balance those things? Well, we want to be fair to both consumers and businesses. And so I think part of being fair is giving guidance to the businesses about how to comply, what the expectations are, and give them the resources they need to figure out how to get into compliance.
And maybe that doesn't include giving them formal legal advice. But talking about what some of the best practices are and talking about some of the examples that we think are reasonable security measures for given companies could go a long way to illuminating the issue for companies that are trying to get into compliance. Yeah. Okay, so you help give them some knowledge, but what about enforcement actions? I think right now enforcement actions are not necessarily the first thing that we're looking to do.
But we feel like the right case for an enforcement action will present itself. And what I mean to say is, you don't wanna take an enforcement action against somebody who's trying to comply with the statute, with somebody who's taking steps to get into compliance, that's trying to act in good faith. The type of case that we wanna take an enforcement action on is one where the actors are acting in bad faith.
Poor security practices are so obvious right from the beginning that we're left with no other option but to take an enforcement action. One of Attorney General Weiser's biggest issues is he wants to be fair to businesses, and he wants to enable them to get into compliance, and he does not want to hammer them with enforcement actions if they're trying to act in good faith. So it's important to draw that distinction that we're gonna go after people that act in bad faith and are clearly, you know, implementing improper security procedures. And I think we've seen enough examples in the media over the last year or two to— we all know what those really bad actors look like, and if Colorado has some of those pop up, that might be a good place for you guys to start. Okay, you know, moving outside of strictly Colorado.
Are there some national groups that you guys are working with regarding security and privacy? Yeah, one of the national groups that we work with is the Conference of Western Attorneys General. It's CWAG. CWAG is a nonprofit group that has a— it's comprised of a number of elected state attorneys general. It is the Western Attorneys General, but there's 42 states involved, so really it's most of the attorneys general.
And they have a cybersecurity working group that I get to meet with roughly quarterly, you know, to discuss some pressing issues and also to work on different things. Like, we discussed safe harbor initiatives previously. But one of the real great benefits is that I get to work with national experts, people from Microsoft and Google and Amazon. They're sitting in our small, you know, working groups giving their input, certainly, you know, from their large business perspective, But also, the expertise that they have is extremely valuable because I can then take that back to my state and say, hey, here's what Microsoft, Google, and Facebook are talking about. That's great.
Do you guys also partner with the FBI or the Colorado Bureau of Investigations? We do. I'm part of FBI InfraGard, which is kind of a national security-based cybersecurity working group. Private partnership again? Exactly, yeah.
So the FBI's got theirs, the Secret Service has theirs. And then we, we do work cases with CBI. It's interesting you mentioned CBI. When you talk about doing criminal cases in the state of Colorado, one thing that comes up is jurisdiction. And so what's interesting about the Attorney General's Office is we don't have original jurisdiction over all crimes.
They have to be specific types of crimes, and those crimes are securities fraud, insurance fraud, mortgage fraud, tax fraud, those sorts of things. Anything that falls outside of that domain, we have to partner with a local DA's office in order to file our case into that jurisdiction. So with, with those different types of crimes you just mentioned, you know, what electronic crimes do you guys get— investigate and work on prosecutions for? So primarily the types of cases that we're investigating are, uh, our financial fraud cases, certainly. Myself on the financial fraud unit, and then also my office will do some wiretap and organized crime cases.
So we're investigating traditional crimes. We're not doing network intrusions or DDoS attacks necessarily. We're investigating conventional crimes, but we're using electronic evidence in order to prove them. Gotcha. So, so when, you know, you're looking at a financial crime and all of a sudden it requires someone who understands how to get access to these systems or can, can do, you know, get evidence, forensically sound evidence, out of email or a messaging app or whatever it is.
That's kind of where your expertise would come in. Absolutely, yeah. And then, you know, one other thing that I've, that I've done since getting this forensic training is to, is to get the capabilities to do mobile device and computer forensics in-house at the AG's office, which is something that we didn't have before. And so now we have in-house experts who are trained to do mobile device and traditional computer forensics. That's great.
So, you know, just putting on the devil's advocate for just a second— that's not the right word maybe— but I'll ask you a random question. What is the one crime that I could go commit tomorrow that would most quickly get you to try and investigate me? I don't know, if you threaten somebody on tape, probably. That'd be you? If you go shoot somebody in the middle of Fifth Avenue.
That's not you, that's the police, right? How do I get— how do I get you, you know, personally to come investigate Robb Reck? Well, Robb, if you were to take somebody's money in a joint venture perhaps and commit securities fraud, yeah, and maybe misappropriate that money and put it in your personal bank account and go spend it to yourself. So if I stole Alex's money and he went and complained, he's— you're the one who might help him? That's correct.
Okay, so we'll make sure Alex doesn't listen to this podcast and We'll keep going from there.
Speaking of engaging with the community, what can security professionals listening, regardless of what they do for a day job, what can we do to help you be more effective at your mission of being the people's lawyer? I'm going to give the InfoSec community a chance to do that, specifically on the Slack channel. This is kind of a call for assistance. One of the things that I've been charged with doing is promulgating best practices for small and medium-sized businesses. And, you know, I'd love to get some thoughts from the InfoSec community on what some of the basics are for some of those types of businesses that they could do to secure themselves, the best bang for their buck.
Yeah, so you're looking for tips on, you know, what are the top 10 things a small business can do? Absolutely. And you'll be posting a way for folks to get that feedback to you through the Slack channel? Yes. I love it.
And I'm shooting for Slack message of the week. I'm not afraid to say that. Andre, I'm coming for your merch. I love it. What about local companies?
You know, last question I had written down here, what are local— what can local companies do to help with your mission? You know, I think one of the best things that a local company can do is if they have evidence of a breach, if they feel like they've been breached, pick up the phone and call us. Call the Attorney General's Office, call the FBI, call the Secret Service, but call somebody. And we want to help you, and we want to facilitate getting the right people to you. And so, you know, if you give me a call or you give the FBI a call, either way I can get you to the right person quickly.
And so don't turn a blind eye, you know, where you just upload your backups. If you've been the victim of an attack, please let somebody know. Okay. And what's the— what do you get out of knowing? And then of course, what does the company get out of them having told you?
So it's not necessarily what we can get, but what we can provide. And so we can facilitate those relationships. If it's a criminal situation, if somebody's stolen, I don't know, $10 million, I have good contacts with all of the different local, state, and federal law enforcement agencies around here. We want to get you on the cell phone with the head of the FBI Cyber, with the head of the Secret Service Cyber. We can facilitate those types of conversations and cut down on the lag time between identifying a breach or an incident and then responding to it.
And maybe, I've heard in some cases, the FBI may be able to help get back some of the money that was stolen. And of course, I assume, you know, they're taking this data about these crimes and aggregating them into a larger case so that whenever we do catch the bad guy, there's more data to actually put that person, you know, put the full weight of the law behind whatever action there is. Yeah, that's correct. There's something called the financial fraud kill chain that if you get to the FBI, within 72 hours of sending a wire transfer, they have a really good chance of clawing that back. And so when I talk about facilitating these conversations, you know, if you save an hour, a couple hours, if you save a half day, that might be the difference between you getting your $10 million back and you losing your $10 million.
So pick up the phone and call somebody and we'll get you the right people. Awesome. Well, that was it for questions for me. Is there anything that I should have asked you that, that I didn't that you wanted to talk about? No, I think we covered everything.
You know, I think I'll leave you guys with this. If you need anything, if there's any way the Attorney General's Office can help, please give us a call. The number is 720-508-6000. And again, I'm Daniel Pietragallo. Please feel free to reach out to me if you're a member of this community and listening to this podcast.
We want to help in any way we can. Awesome. Daniel, thanks so much for your time. This has been fun. We'll look forward to hearing, you know, how the AG's mission is going over the next couple of years.
And that's it for now. We'll talk to you guys again next week. Thanks for having me.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.