Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 121 for the week of June 17th. Uh, Alex, it's Father's Day.
Happy Father's Day. It is Father's Day. Happy Father's Day to you, Robb. Um, are you planning to go do something with your kids? Beat them?
Uh, you know, uh, take advantage of the dispensation. We get a dispensation today, right? I, we do. We do. Anything you want to do today is okay.
I'm, I'm actually gonna ignore my kids today, which is my right as a father. I like it. I mean, that's, that's everyday standard, so that's good stuff. Well, right. Yeah.
But today it's okay. Yeah. Because I get a dispensation. So, uh, you know, it's been, it's actually been 2 weeks since our last podcast. We, we planned to record, uh, the, the keynote for RMISC and run it last week.
We had a little technical issues, right? We did. So the company that recorded it for us, interesting IT situation. I think someone pulled the USB drive before undocking it from the computer and so the file got corrupted and it took a little while for them to recover that. The first time in the history of humanity that that's actually caused a problem.
Right. I like it. So good news is they were able to get it restored. We're gonna have it as the feature interview this week but we didn't want to miss 2 weeks worth of news So we're going to jump in and actually do a newscast here. Let's do it.
We have a Slack channel. We do. I think we're almost at 1,000 people now at 980 or something like that. I think we got a little bump from RMISC, some people hearing about the Slack channel. So yeah, almost a good conversation.
I've been struggling to keep on top of everything going on there. Come get to talk to the local folks in the community, get to meet some people, maybe find a new job that way. We also have a mailing list. So if you want to stay up to date on everything that is Colorado Equals Security and get the show notes in your email, sign up for the mailing list at colorado-security.com. That's where you find the link to join the Slack channel as well.
We'd love it if you would rate us and review us on your favorite podcast listener. iTunes, Google Play, SoundCloud. What's the other one we just got? Spotify. Spotify, yeah.
So go out onto any of those, rate us and review us, say nice things, help us find new folks. We'd also love it if you would tell a friend about the podcast. If you like what we're doing, go tell a coworker or a colleague, a random person on the street. I'm sure they'd appreciate the tip. And if you like us so much that you're willing to donate a little money to the cause, we do have a Patreon campaign.
Any money that you donate to that goes right into the podcast hosting fees, swag, all that kind of stuff, everything to promote Colorado Equals Security. So you can again find that at colorado-security.com. And we actually have a big thanks to shout out to a new patron this week. Jason Jaques has joined as a sponsor. Thank you so much for your, your support, Jason.
Since you sponsored us at a higher level, you'll get not only the shout out on the show, but you'll get some awesome Colorado Equals Security swag. Indeed. All right, let's jump into the news. Oh wait, before we do that, one more announcement. Uh, the Colorado Equals Security salary survey is still open.
We're looking for input there to try and get a survey of the landscape for security salaries in Colorado. So go ahead and check that out. There is a link on the website as well. It's also in the show notes. And if you fill out the survey, you get the results of the survey.
So it's, you know, we try and incentivize the right behavior. So, Robb, do you like leprechauns? I love leprechauns. Yeah. Yeah.
Well, you know, there is an island off of Ireland that is inviting you to move there. I am so excited. So I'm sure I've told you that, well, 7 years ago I went to Ireland for an anniversary trip with my wife and I fell in love with Ireland. I would love to move there. But my biggest question is, do they have broadband internet?
Because it'd be hard for me to work remotely if they don't. Not only do they have broadband internet, but they have high speed. Broadband internet, Robb. So this is the island of Aranmore. And they have actually been putting out kind of a media PR blitz to try and get Americans and Australians to move out there because they've been losing a lot of population.
They have. Yes. This island is, I think they said, 3 miles off of the mainland. And they're, they're continually losing population. They want to have people there.
Now they said, you know, it's quaint. There's some, there's stuff to do, but there's high-speed internet. So if you can work remotely, Hey, come move here. So if any of you decide that Colorado is not for you and you want a little bit slower-paced life, move to Erinmore and please send me an invitation. I will come visit you.
I see an opportunity, Robb. Erinmore equals security. I love it. We could move the podcast out there. I think we could get a higher percentage of the population out there than we do in Colorado.
100% coverage. All right. Next story we have is, is an article in the Denver Post around the Colorado cities that have the most breweries per capita. There are breweries here? I hadn't noticed.
There are breweries and we have data. So this is not just compared to cities in Colorado, but really they're doing a national comparison to let us know. And we actually had, was it 4, 5, 5 cities that made the top 20 nationally? Yeah, Boulder came in at number 4 with 14 breweries per 50,000 residents. Fort Collins was next with 11.
Sorry, they were 11 with 8 breweries per 50,000. Loveland was number 12 with 7 per 50,000, and Denver and Longmont tied at 6 breweries per 50,000 residents. So the number one largest or best ratio is in Portland, Maine. So if you really like your booze, maybe you want to move up to the great Northeast. I think that that would be a good idea.
Red Robin is trying to decide what to do with some activist investors. So Red Robin, as you may have heard previously, has been struggling a little bit. Their same-store sales have been continually going down. They've been— they've had a plan to increase their revenue through things like catering and, and other off-site activities, but these activist investors are not particularly happy with how things have been going. The CEO recently left, and they're— they want Red Robin to think about all the possibilities they could do, including selling.
So hopefully they come out of this well. And obviously it's nice to have a national brand headquartered here locally that's thriving and giving good jobs in the area. So hopefully— I don't know what the right thing is to root for in terms of this investor, but I hope it turns out— helps turn things around either way. I hope one of those things is a good option. Next, we have a story from the Colorado Sun where Governor Polis has been trying to lure the National— was it the National Medal of Honor Museum to Denver?
And he's also working to try to get Space Command here, which, you know, I know we've had a lot of conversations about some temporary appointments for Space Command in Colorado. He's trying to get the long-term base to be here. Yeah. So the National Medal of Honor Museum, they're looking at a potential site near the state capitol, which would be pretty cool. And then also talking about a number of different sites for Space Command.
I think Buckley, I think Peterson in Colorado Springs, as well as a few others. Well, hopefully he's successful and we can have some of those great security jobs that I'm sure would come with both of those opportunities. Well, maybe more of Space Command. Yeah, we definitely need to secure space, Robb. Next, Galvanize is announcing that they are laying some folks off, 27 people across their employee base.
And 10 of those people are here in Colorado. The other 17 are across 5 other states. So probably where the largest hit. You know, they, they give the kind of generic language, you know, that this layoff is going to help leadership team have a clearer picture of sustainable path forward for both the students and the employees.
Interesting story. Never good news to see layoffs, right? Yeah. People can come through them better afterwards. But, you know, I have no idea what this means for them in terms of their, uh, you know, their profitability and their success.
Hopefully it does focus them and makes things better going forward. Next, we have a story from the Denver Business Journal, uh, Colorado women execs take on— take aim at the gender gap in cybersecurity. And here they're talking with 3 separate ladies, uh, from who have security-ish jobs, although, you know, I'm not sure that all of them are security in what they do, but working for security companies. Um, so Cassie Brubaker, who's a creative director at Circadence, um, they talked with, with Keenan Skelly, the VP of Global Partnerships, Circadence, and Kristen Norfsker, the EVP of Business Operations for Nexus Tech, um, talking about, you know, what, what makes security attractive and really how do we, uh, position security to help get females into the industry and keep them there. Yeah, some good perspectives in that article.
Next, Denverite had an article this week about the city of Denver's cybersecurity program, that they surprisingly have a few holes, but you can't know about them because we don't want them to get attacked. Yeah, I mean, I think that this story is really more for the general public to start to get information around how vulnerability management works. And, you know, they don't use that phrase in the headline, but that's really what this whole thing is about, right? Knowing what vulnerabilities you have, going after the highest risk ones, and understanding you can't keep everything patched at once. I think that most of the world probably thinks it is relatively binary, like keep your system secure or not, right?
Right. And of course, we know that's not the case. And hopefully this type of an article helps educate on that and get the rest of the population to support what we're doing. I thought it was interesting in the article also how they talked about the partnership between the cybersecurity program and the city auditor's office. How the auditors were spending money on pen testing, for example, to make sure that the, uh, the IT teams were doing what they needed to do.
Yeah, good stuff. Um, all right, moving over to some more local company news. Swimlane— we talked 2 weeks ago about how Swimlane raised a B round of funding at $23 million. Well, no surprise, uh, right after that, they've now named 3 new executives to the team. They've hired Um, Jim Hansen as the president and chief operating officer.
They hired Tom Smith as the SVP of global sales and Susan Warner as the VP of global marketing. Um, so, so obviously, you know, big investments for them as they're trying to, to go from a relatively small, you know, company building their, their tech to starting to sell it and, and have a bigger reach across the world. Yeah. Congratulations to those 3 execs for dividing up that $23 million. Yeah, 7 million each.
Is that how that works? And the other 2 are left over? I don't know how that works. Something like that. Anyway, next, System76, who we've talked about a few times before on the show.
This is a local computer manufacturer. We'd originally talked about them because they were bringing the manufacturing from overseas back here to Colorado. But they just released their supercharged Linux Gazelle laptop. So this is pretty cool. Has some pretty nice specs on it.
Yeah, I, you know, I'm not a Linux desktop type of a guy, but if I was, I think this might be the machine I'd want to play whatever amazing games I want to play, or, or if you want to do some, um, some Bitcoin mining maybe. Um, so they have a, uh, a 9th generation Intel Core i7 processor, NVIDIA GTX 16 series graphics, and it can do even— it can have up to 64 gigs of RAM, which even the MacBook can't support. So they're, uh, they're They're kind of pushing the specs there. Yeah, pretty cool. I also thought it was interesting that the low-end starting price for that laptop is only about $1,100.
So that's pretty cool too. Compared to a MacBook, you can't touch that, right? Yeah, exactly. Next, we have some Ping Identity news this week. Ping released their capabilities framework for zero trust deployments.
Yeah, I was, I actually got to be a part of designing and refining this model. It's really meant to be a framework for you to think about how do you actually implement zero trust in your organization, the different ways things connect together. It doesn't get into the actual technologies you'd use there. You're going to want to map your favorite technologies into those different boxes. And yes, of course, Ping does sell some of those, but you could use this framework with whatever technology provider you want to.
And it's really just a new way to think about, you know, instead of doing my perimeter base where I have a firewall on the outside and all the apps are inside, Here's a way to start doing security at this more zero trust, uh, perspective. Uh, next, Robb, do you know anything about ransomware? Well, I didn't until I read this article, which includes everything I needed to know about ransomware in the 2019 edition. Sweet. Uh, so, uh, Virtual Armor this week had a blog post talking about, uh, everything you need to know about ransomware.
This is an article actually, um, I think more focused towards the average folk. Yeah, you know, uh, non-security people, um, getting them up, you know, up to speed on what ransomware is, how you can prevent against it, what it does, all those sorts of things. I think if you maybe don't necessarily give this to your mother, but maybe you give this to the, uh, to the business people at your company who, who aren't really familiar with it, but maybe they saw the Baltimore story in the news and want to understand what's going on there. So good article. Uh, next Uh, we're actually done with the news, but we have a kind of a fun announcement.
The, the APEX Awards CISO of the Year Award, the nominations are open. So it's time for you to get your, your nomination in for your favorite Colorado CISO and send it into the CTA so one of those people can be recognized in their big event in November as the CISO of the Year. Of course, this is the 3rd year that we are having the CISO of the Year Award at the APEX Awards. The inaugural inaugural winner was Matt Shufeld, and then last year some other guy won. Uh, we are— it's not only the CISO of the Year that's available right now for nominations.
Uh, CIO of the Year, Project of the Year, Company of the Year, all those things are available. So get your nominations in now. Um, if you need help, uh, figuring out who to nominate, reach out to Alex. He is, uh, he's happy to tell you what to do. He's— that's what he's been doing to me for— it's been 2+ years, so he's pretty good at it.
Thanks, Robb. Also some ISACA news. ISACA International announced their new board, and Brennan Babek, who is— excuse me, who was the president of the ISACA board here in Denver for a number of years, is now the chairman of the board for ISACA International, which is pretty cool. Yeah, well earned. He's worked very hard for that organization for a long time.
Really respect what Brennan did, not only building up the Denver ISACA chapter, but also he's done a lot of work in international already, uh, even before this appointment. So congratulations to Brennan on that. Uh, next we have— we also have a new Denver ISSA board. Um, so, you know, kind of every 2 years, or every year they'll have a— have an election. Every 2 years the president goes out, and when the president goes out, we have a new VP coming as well.
And, and that's happened here. So James Johnson, who was previously the The president has, has moved along, and also our VP, who is Drew Labbo, has also moved along. So there's, there's new folks in both of those positions. The president is now Gene McGowan. Congratulations to Gene.
VP is Scott McCandless. Gloria McCubbin is still our treasurer, and she is amazing, and we really appreciate Gloria staying on as the ISSA treasurer for Denver. And membership is Robin Lyons. I don't think I know Robin personally, but excited to have her volunteering and helping with the membership role there. Yeah.
Great new, uh, new partial board for ISSA here in Denver. Looking forward to good things from them. Congratulations on running the biggest chapter in the world. Woo-hoo. We need to mention that every once in a while.
All right. So that's it for news. Uh, let's move over to the Slack message of the week. Of course, we need to thank Andre Gaeta for sponsoring the Slack message of the week. Uh, Andre pays for this out of his own pocket.
Whoever the winner is gets a little bit of swag from the Colorado Eagles. Security Store. So thanks again, Andre, for doing that for us. All right. This, this week, I assume you picked this guy because he's got such a good name.
Uh, he does have a great name. We're going with Alex Wise. Alex past— or posted in the general channel about the new proposed hackback legislation for— it's a national legislation, but it's a really interesting conversation. Um, it actually started an interesting conversation around how, how bad or good is it to have this law on the books? You know, even if it's not usable, which it might not be from the way it's written, you know, what does it mean for us to have that thing written there as a precedent?
Yeah. And I think most people in the security industry think that, you know, legalizing hackback is probably a bad thing. But it is interesting how this debate keeps coming up. And this is not the first time that legislation has been introduced to potentially make it okay. See, the problem is it looks like you're being strong on security by allowing this, right?
Whereas, you know, those of us in the industry know, you know, whoever you're hacking back into is probably an innocent victim of the same bad guys, right? Right. So it's a challenging problem to solve. Anyway, congratulations to Alex. You'll get, you'll get a note and the ability to pick something from the swag store.
So let's jump over to events. We've got a number of events to talk about. The first, the National Cybersecurity Center is having their Cyber Camp July 15th through 19th And we have an announcement about that. Yeah, so this is available, a camp that's available for kids age or grades 6th through 12th. So going into 6th through 12th grade, it's in Colorado Springs.
However, when I reached out to them to find out, do they have any space? They said, yes, we have 6 slots open. And they're willing to give the first 4 people from the podcast who sign up free tuition. What? What?
Free tuition. That's pretty cool. So it's normally $200 to send your kid to this and learn them how to cyber during a week. And now you can have, if you put in the, the promo code scholarship as you sign up, it's free. Get out of here.
That is cool. Yeah. So thanks a lot to those guys for doing that for us. If you're anywhere near the Springs and you have kids in that age, I would highly recommend it. I was like debating, man, is there any way I can get my kids down there to attend this thing?
The answer is no, I can't. But it sounded like it'd be a fun idea if I could. Next, DENSEC is having their monthly meetup at the Rhine House on the 17th of June. On the 18th, the CSA is doing their June chapter meeting. On the 19th, Let's Get Gamified, a new cyber experience cybersecurity learning tour.
That sounds like fun. Let's get gamified. Let's do it. ISSA Denver is having an oil and gas special interest group happy hour on the 19th. So hang out with other people who are in or interested in the oil and gas industry.
On the 20th, ISSA Colorado Springs is doing their June special interest group meeting. On the 24th, the National Cybersecurity Center is doing a Blockchain 102, a case study on Secure the Vote initiative. That sounds like a fun event. On the 25th, the GDPR meetup group is meeting to talk about a case study of how to use data privacy as a competitive advantage. That sounds like a good idea too.
Also on the 20th— or sorry, on the 26th, ISC² Pikes Peak is doing their June chapter meeting. Also on the 26th, SecureSet is doing a women-only beginner's intro Capture the Flag. Uh, we have 2 more events on the— both on the 28th. We have ISC2 doing their Secure Summit Denver. This is a full-day event.
It's kind of their, you know, their— I think it's a— they're doing these in different cities, right? Yeah, sort of a traveling tour. Traveling tour. Um, so this is when they come to Denver, and it should be a good chance to meet folks, uh, in the, in the security industry, local and nationally. And then finally on the 28th, uh, the monthly office hours with Davis, Graham, and Stubbs, if you are looking for legal advice for startups.
All right, let's move over into jobs. Uh, Good news, I have another open opportunity at Ping. So we're hiring, we're hiring 3 open reqs right now. We've got a junior product security engineer, a product security engineer, and a manager of product security. So any of the levels of product security you have, if you're a developer who wants to get into security, we've got a role for you.
And then I have another role that's not quite open yet but should be open this week for a GRC analyst helping us work on SOC 2 compliance, ISO compliance, vendor risk management, policy standards, all that good stuff. And that's a more entry-level role. If you're, if you're looking for a leg into the industry, that might be a spot for you. The Doyle Group is looking for a director of cybersecurity, CISO.
GHR is hiring a senior information security officer. CenturyLink is looking for a lead information security engineer. And that's all in caps. So I think they really mean it or they're angry. Both.
Spectrum is hiring a security engineer 3. Senior Security Risk Assessment Engineer. It's a long title. Yes, it is. IHS Markit is looking for a Cybersecurity Assessor Specialist.
Xcel Energy is hiring a Cybersecurity Engineer. Ibotta is looking for an Infrastructure Security Engineer. And finally, Conversant, our local ethics and compliance software company, is hiring an Application Security Engineer. Get to work with Cole Krems over there. Cole's a good guy.
That would be cool. All right. Well, that— I think that's it for the newscast this week. Next, we have our feature interview, which is us. Yeah.
Wow. But it's us talking from the keynote stage at RMISC. You'll see us start off with kind of an introduction to what is Colorado Equal Security for, I think, about 10 minutes or so. And then we go jump over into an interview with the CISO for the state of Colorado, Debbi Blyth. Yeah, it was a lot of fun.
Glad we got to do it. And I'm looking to— excited to listen to it. All right. Well, thanks, everybody. We'll talk to you again next week.
Thanks, Robb. Hi, I am Justin Cohen, VP of Security at Medkeeper. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.
I don't hear— hi, I hear you. Do you guys hear me now?
No? Now we're good. Welcome to Colorado Equal Security. This is our, this is our inaugural live podcast. We're excited to share with you guys.
Uh, we have, uh, we've been doing a podcast here in the, in the, in the community for a little while, and we're excited. For our listeners at home, this is episode 121. It's a couple of years, right? Um, for, for those of you here, it's our first time doing this, so we're excited. I'm Robb Reck.
I am the, uh, the Chief Information Security Officer for Ping Identity. And I'm Alex Wood. I'm the Chief Information Security Officer for Pulte Financial Services, and together we host Colorado Equal Security. Yeah, we are excited. We're gonna get to share a little bit of who we are and what we're doing here.
We're excited. A little bit later, we're gonna do an interview with the CISO for the state of Colorado, Debbi Blyth. Debbi's here up front. Before we do that though, let's talk about what is Colorado Equals Security. Yeah, so Robb and I have been involved in the community here for a long time.
If you've been to this conference before, you've probably seen us. We were both prior presidents of the ISSA and And, you know, we spent a lot of time seeing how great the community was in Colorado, but we also realized that, you know, there were a lot of different areas of the community that maybe weren't communicating with each other. Yeah, so if you guys— has anyone moved to Colorado and tried to get involved with security here? Yeah, a lot, a lot of hands going up. It's hard to see in the back of the room.
A lot of folks have done that. If you came here more than a year or two ago, it was incredibly difficult to figure out how do I get plugged in. And that was a problem that we identified, and we said let's make it easy because there's so much already going on in town. Let's make it easy for someone to learn what the community looks like and how to get involved, what's the right way to do that. But we also knew that there were a lot of organizations already out there and a lot of things going on, so we didn't want to, you know, create more meetups or, you know, more content necessarily.
We wanted to be that umbrella over everything that was going on. So how do we do that? We do that in a few different ways. Obviously, number one, it is a— we think of it as a movement. I know it's a podcast, it's a website, but it's really a movement.
And what's the goal of the movement? To make Colorado the premier place in the world for Colorado— for security jobs, for security talent, and for funding for those companies. We want everyone to recognize Colorado is the number one place for those things. Yeah, so in addition, all the things that we have, we have a weekly newsletter that we send out, gives you you show notes about what's going on, information, uh, you know, on the community, jobs, sorts of all those sorts of things? Uh, we have, we have a website, and on the website there is a calendar of events.
You can go see what's going on across all these different groups we're going to talk about. Um, we have the show notes on there. We have a Slack channel. This has been pretty exciting. Who's in the Slack channel?
Yeah, so we have over 900 people who are, who are in our Slack channel doing security just here in Colorado. It's a fantastic way for you to connect with people who you want to get to know practicing security and ask them questions that are relevant to you. Yeah, that one wasn't one of the original things that we did, but it turns out that that may be the best thing that we do. It's a constant communication channel for everyone in the area on what's going on. And speaking of the Slack channel, if you can go to the website colorado-security.com, click on the Slack button there to join, and there's an RMISC channel when we're interviewing Debbi, we're going to be taking some questions from that Slack channel to ask Debbi.
So if you go in there and ask questions, we may pull your question to ask her. Yeah. So another thing that we've started doing recently is we do a salary survey. We're helping both security leaders and individual contributors get an idea what does the salary look like across the industry. That's open right now.
If you go out to the Colorado-Security website, uh, get involved. If you, if you contribute, you get the results of that survey right back to you. It's just one way we're trying to help bring community together. And, and finally, we do this podcast. Uh, you know, this is the first time, Robb, that we are— we're recording this in, in front of a live audience.
Usually we're in Robb's basement, so this is a little bit different. Um, but, you know, we have— we do this every week. Uh, the, the podcast is a news segment section followed by an interview, and we've got 120 episodes and counting. So all kinds of interesting folks in the community. We've had founders of security companies, We've had a bunch of different CISOs and security practitioners.
We've had just other interesting folks from the community. It's been a really cool thing. Yeah, so as we mentioned, uh, in that podcast, you know, we have a couple sections. First, you know, we, we start out with news, uh, talk about, you know, current events for the week. And one thing that, uh, as an example we wanted to highlight, last week there was a story in the Colorado Sun, which is a new news outlet here in town, talking about Colorado's effort to try and get veterans into the cybersecurity workforce.
Yeah, so Tamara Chung, she was previously a reporter for Denver Post. She did a really cool story talking about how, you know, obviously we all know that there's a shortage of talent to fill all the security jobs out there, about how there are lots of organizations that are looking to bring veterans in, and they highlighted local security company SecureSet as one of those who's doing it. And it actually kind of read like a— like they had sponsored it. It was such a great fit for them with the Good, good stuff to see, and really a good way for us to show what's, what's happening in security in the state. Yeah, and they also talked about some of the efforts that are happening in Colorado Springs, trying to get veterans coming out of the military down there into the workforce as well.
So each week we also do, we call it the Slack Message of the Week, and each week we try and identify one person who's really contributed something interesting from the Slack channel, and we have just like this awesome supporter, I don't know, Andre Gator, are you in the room somewhere? Somewhere? Yeah, let's clap for Andre. Yeah, so Andre, just on his own, has been sponsoring this Slack Message of the Week every week for the last year and a half, where whoever we pick gets to have a piece of swag from the Colorado Equals Security store. So we thought, this is a little different, rather than doing a Slack Message of the Week in front of all you guys, we'd like to talk the Slack Messenger of the Year, the person who's been the best contributor to the Slack channel over the the year helping drive community, really helping, uh, give us good information there.
Yeah, and so, uh, we wanted to recognize Douglas Brush, who's sitting here in the front row, as our, uh, our biggest slacker. Let's get a little token of appreciation for him. So he gets a piece, a nice sweet piece of Colorado Equals Security swag. Yes. And, and also, since we're mentioning him, uh, you know, Douglas does run the second best podcast about security in Colorado.
So Cybersecurity Interviews, check that out too. When we started the podcast, there was only 2 podcast security podcasts in the state. I think there's like 6 or 7 now or something, but we're still number one. Douglas. Yes, yes, yes.
Uh, we also, we also talk about events on the podcast, so we have a combined event calendar on the website. We talk about what's happening that week, uh, actually the next 2 weeks. But I'd say 2 things about that. Number one, if you want to know what events you can go to in the area, this calendar of events takes us out all the way through the end of the year. And if you're looking to schedule an event in the area, maybe look at, look at the calendar and see if you're about to schedule over the top of other stuff that's going on.
Yeah, and we, we aggregate events from many, many different organizations here in town. We wanted to highlight a couple of those. So ISSA, both Denver, Northern Colorado, which is in Fort Collins, and the Colorado Springs chapter. You know, they have lots and lots of events, you know, sort of general security focused on different areas. Yeah, if you're looking to get involved, we want you to know what groups you should be getting involved with.
Another one is the CTA, the Colorado Technology Association. Not specific— specifically security, but a great view of technology across the area. And they have all kinds of good events like, you know, what's blockchain gonna mean to us, and starting to figure out what is— how is technology gonna impact impact you in security and your business. Also the ISACA Denver chapter. So, you know, they are traditionally IT audit focused but have been expanding their scope as well.
So we have their events. Yeah, they have monthly meetings as well, right? Yep. The, the Cloud Security Alliance has a Colorado chapter. They get together, I think, every month downtown, and they'll be talking obviously cloud focused.
How do we secure in the cloud? OWASP, the Open Web Application Security Project, has a chapter here in Denver and in Boulder. And they have monthly meetings and we get those events on there as well. Yeah, so GDPR Meetup. Carlin, I know Carlin's here somewhere, I think.
They meet on a regular basis, I think it's monthly, to really talk about what is the impact of privacy. And it's GDPR Meetup right now, but as they look at CCPA and other privacy regulations coming down the pike, it's gonna be a really good way for you to understand how privacy is gonna impact you. SecureSet, who has several offices around the area, they have a lot of events. We get those on the calendar. Lots of entry-level kind of events, capture the flags, uh, learning the basics.
Uh, so if you're someone trying to get into cybersecurity, looking at their events is a great idea. And finally, the Women in Security group, which is a special interest group from ISSA Denver. Uh, they get together, I don't know, is it once a quarter? I think maybe a little bit more. Um, this is a fantastic group.
It's only a couple years old and, uh, they've had over 100 people at I think all of their events, or just about. Um, Really a fantastic group for enabling women in the security industry. Guys, that was just a small sample of all the groups that show up on the calendar. There's so much you guys can get involved with here in town, and we really like bringing that to you. The final portion of our news segment every week talks about jobs.
So we go out and we find some interesting jobs that are out there, talk about them in the podcast, get links to them so that you can find them. And it seems like just about every week, you know, Robb has a job that he's trying to hire for. So we usually end up with, with some Ping jobs in the podcast. So if you're looking to be a product security manager at Ping Identity, it's open right now. Uh, we'd love to, love to have you guys, uh, reach out to me, and I'm happy to talk to you about it.
Yeah, so that's what takes us to the end of our news segment. So we have a little bit of a break. Yeah, after the break we're going to come back and we're going to interview Debbi, but during the break we're gonna hear from someone special. Come on up.
So I'm just up here doing their transition for them, so if you've listened to the podcast, you'll know what I'll say. Uh, James Carder, Chief Security Officer for LogRhythm. Uh, welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Uh, for those that never heard of LogRhythm, uh, I think Gartner classifies us as a but really we're a full-stack platform for the modern SOC. And everything from, you know, getting access and visibility to your data, to telling you when bad things are happening to your environment, to empowering you to actually go do something about it quickly and effectively.
And for me as a chief security officer, the ability to detect and respond to things quickly and effectively is the difference between an incident and a breach, otherwise known as me keeping or not keeping my job. So without further ado, I'll turn it back to Robb and Alex their feature interview with Debbi. Awesome. All right, thanks, James. And shout out to LogRhythm for being one of the premier sponsors of the conference here and a Colorado security company.
Yes, exactly. We have a great ecosystem here in town. All right, so Debbi, we're excited to get to know you. We're going to talk about your job as the CISO of the state of Colorado, but before we do that, we really want to know a little bit more about you. I understand— I've heard a rumor that you love to travel.
A lot of people love to travel, but you've gone to some interesting places. So I'm gonna ask you a 2-part question. What's the worst and best experience you've had traveling? Wow, I could probably talk about a lot of worst and best, but I think I could cover both in one trip. So my husband and I went to Moorea in Tahiti several years ago, And first of all, we flew into Papeete, and then you land at like midnight.
And we rented a car, and apparently that's not a common thing to do in Tahiti. So we rented a car, it's called a Twingo. It's the smallest car you've ever seen. It had 2 seats in the front and then like a little open area in the back. It looked like it was probably supposed to have a back seat but didn't.
And so we piled all our luggage in there. And then we drove, we're supposed to catch a ferry to go over to Moorea. And so we drive to the ferry and find out the ferry doesn't leave until 6 in the morning and this is midnight. And so we don't have any place lined up to stay. I mean, it didn't occur to us we couldn't get to where we're trying to go.
And so my husband said, well, we can't leave the car because everything we own is in the car. Car, and we're driving around in Tahiti, and we noticed that there's all these like food truck kind of things, like food stands. And I was like, well, cool, at least we could eat something. And he's like, we're not eating anything, you know, we don't know what this is, and we don't want to get sick on day 1 of trip to Tahiti. Um, so we ended up pulling into the ferry dock.
We were going to be first in line for the ferry, parked the car, just trying to sleep in this little Twingo. Um, so that was So that was kind of crazy. But then when we got there to Moorea, Moorea was a fun place, but only fun during the day. Because at night they have no nightlife at all. So once the sun goes down, everything is just over.
And so we had brought a DVD player and we had to go to the hotel and get like a power converter so that we could play our DVD player. We brought 2 DVDs. And so we watched these same 2 movies over and over and over. And the other thing that happened there, so this is still worst experience I guess, is that we discovered the locals, you know, it's a French island. And so the locals love bread.
And every day we would see people walking down the road with bread, loaves of bread. And we're like, where'd they get the bread? So we would go back to where they came from. And the bread's all gone. So we missed the bread every single day for several days until we narrowed down that window of when bread might be available.
So we went and we thought we're gonna be smart and we bought 2 loaves. Well, you don't buy 2 loaves because we ate one loaf and then we tried to put the other loaf away overnight and we ended up with ants all in our condo. Like, they— this whole line of ants coming in that went up onto the cabinet and up onto the— into the kitchen where the loaf of bread was. So that was pretty crazy. That was a VRBO that we really didn't know what we were doing.
Not so good. So, so it sounds like a bad beginning, but how did it turn out? Yeah, but, um, so in our little Twingo, we discovered, um, we like to pick up hitchhikers. So we would drive— yeah, drive around the island of Moorea. Now this is my husband who's very, you know, risk-averse, who says, look, there's a hitchhiker, let's pick him up.
So we would pick up hitchhikers because we would learn so much about what to do. Like we learned about this little motu, this little island that you could go to and spend the day on. We learned about this place that you could go up that had this amazing view. We learned about fruit you should eat. So we learned so much by picking up hitchhikers, but of course we didn't have a back in the— I mean, backseat.
Seat. So they would just kind of sprawl out in this, you know, back area. And I mean, but it was really a fun— it was such an adventurous trip, and it was probably our most adventurous trip that kind of got us into being a little out of our comfort zone and, and set us up for some more adventurous trips, I think. Well, it sounds like a lot of fun. So Debbi, you are the CISO for the state of Colorado, but you haven't been the CISO forever.
So what was it that you were doing before you got to the state of Colorado? Yeah, so, um, I started my career in IT for a company that was called Covia, then it became Galileo, then it became Travelport. Um, and I did all kinds of things in IT. I started as a mainframe tape operator. Um, I worked in automation, I worked in network, I worked in the Unix team.
Um, that's where I fell in love with security. And then eventually ended up managing the security organization at Travelport. From there, I went to Teletech and I managed their security organization for 5 years. And then from there, I came to the state of Colorado. What was it that made you make that move?
Obviously, going from Teletech to the state of Colorado, that's, that's a big change. What was the motivation for you? Yeah, it was interesting. It just seemed so random, like, at the moment. Is, you know, I saw this job that was posted for the state of Colorado for CISO, and the more I read that job description, I kept thinking, gosh, it sounds like they're looking for me.
And I showed it to my husband. I said, what do you think of this job? And he goes, man, that sounds like you. And so, you know, I was so excited to apply because security is just something I'm so passionate about. I think I'll spend my entire career doing security.
But the opportunity to do my career passion in service for the residents of the state that I love, and I'm a Colorado native, just seemed like I couldn't think of anything more, you know, more rewarding than that. So, you know, when I applied, then I started bugging them right away about, you know, well, I applied, I know you're looking for me, when are you gonna hire me? And so eventually they Eventually, you badgered them into one. You're telling me? I think so.
Yeah, I guess everyone looking for a job. Yeah, that's how it works. Call them every day. I know people appreciate that, being called every day asking if you're ready to hire them. Hire me.
Yeah. Yeah. So, so what's it been like working at the state? And how long have you been there now? Yeah, so I've been there almost 5 years.
So it'll be 5 years in August. So it's been awesome because You know, one of the reasons I went to the state is because Colorado is a very, very innovative state. And in fact, Colorado state government has won numerous awards for, you know, innovative solutions, for upgrading old technology, for embracing public cloud or cloud infrastructure, for being an implementer on the Salesforce application. So applications on the Salesforce platform. So just a lot of innovation.
I was really excited to be able to, you know, to be a part of all of that innovation. But I also have had an opportunity to work with amazing people that honestly, when sometimes when you work in private sector and certainly before Colorado Equals Security and you weren't getting us all together, like I didn't even know this whole public sector community existed. And so to To be able to work with really amazing people, both in my organization but other state government agencies, local governments, Colorado National Guard, I mean, just really amazing security folks that have been, you know, people that I can learn from and people that I can work closely with. It's just been fantastic. I've really enjoyed it.
Do I remember correctly that you came in just before Hickenlooper's second term as governor? Yes. So you've had the chance to have his, his whole second term and, and starting on Governor Polis's term now. Could you give any kind of comparison between, you know, what was it like to work for Governor Hickenlooper and what it is like for Governor Polis? Yeah, so it's still pretty new.
So, um, I'll start with Hickenlooper and then I'll tell you a little bit about Governor Polis as well. But, um, you know, obviously Governor Hickenlooper was passionate about cybersecurity and he was a a visionary for the National Cybersecurity Center. I took an economic development trip with him out to California to do, you know, to visit a lot of cybersecurity companies and really got to spend a lot of time with him. Just really appreciated, definitely appreciated his interest in and his passion for cybersecurity. And I just felt like it was so helpful for my program.
Additionally, when we implemented 2-factor authentication for our Google platform, for G Suite, he was the first to help me pilot 2-factor authentication, and then he was a champion, you know. And he said to his department heads, he said, I implemented it, and I'm not going to tell you that I didn't notice it, Debbi, but I will tell you that you're all going to implement it. And it was so helpful because Because with his support, we were able to implement for 100% of the accounts. Not a single one received an exception, and no one dared push back. If the governor himself was using it, why would they refute it?
So next time one of you are trying to push out MFA in your company and someone says it's too hard, maybe you got a good example. William, you already have the governor. The governor already did it, right? That's the story we share. That's right.
And so I'm really excited about Governor Polis as well. So he's new, just started his position in January, so just a little over 100 days now. But he is a technologist, that's his background. So that's going to, I think, be very, very helpful for the Office of Information Technology because he understands technology. But the other thing is that he's a big proponent and supporter of cybersecurity.
And so one of the things he directed our agency is you will set one of your strategic goals around cybersecurity, around creating a plan to continuously improve cybersecurity. And so I was like, jackpot! That's awesome. So yeah, I'm excited for his support as well. You mentioned your program and some of the initiatives that you've done.
I know, you know, being in government, it's a little bit different than the, the, the, uh, the private sector. And also, you know, you have a whole bunch of different departments that you oversee and sort of consult with. So I wonder if you could just tell us a little bit about, you know, how your department works and the things that you do. Yeah, so the Governor's Office of Information Technology, or OIT we call it, is responsible for technology and infrastructure for 17 executive branch agencies of state government. So these are all the agencies that you think of, you know, revenue, public safety, human services, transportation, corrections, all of those, where we provide all of the technology and also security.
So we set security strategy. We also have a security operations center that manages all of the security infrastructure across all of those agencies and monitors for alerts and responds to security events, all of that. So we are— it's basically what we call a centralized state. Very nice. So I'm going to jump over and take one from the Slack channel, specifically the one about the election security.
Could you compare and contrast the election security posture of Colorado to that of other states? Oh, that is a great question. Thank you. This is from Anthony. Is it Faff, maybe Anthony Faff?
Thank you, Anthony. So Colorado is absolutely a leader in the nation in election security, and I take no credit. I'm almost not even involved in that. So Trevor Timmons is their CIO, and Rich Schliep up until recently was their CISO. For the Secretary of State.
For Secretary of State, for Colorado Department of State. And they have really put a lot of thought into election security, making sure that, you know, there's a way to verify and then verify again. A lot of good— they work with the counties to put a lot of good processes in place, but then they also do a lot of penetration testing and other types of testing to make sure that their equipment is certified and solid. And so going into, you know, the last election cycle, we were so confident— presidential election— we were just so confident that the issue that we would have around, you know, election security is just reassuring the public that the only problem we could potentially have if there's any kind of a cyber incident is maybe a delay in tallying all the votes, but that it, you know, there wouldn't be any risk of the votes aren't accurate, there's not integrity in the results or anything like that. 100% confident, and it's just so awesome to be able to relay that message to our governor, to be able to assure the Secretary of State that, you know, these guys know what they're doing.
And then it was really exciting too because they allowed my team and other teams like Colorado National Guard and Emergency Operations Center to have kind of a view into what's going going on on Election Day. And so, you know, during the election, I was actually watching transactions as they were, you know, I could see the peak time of the transactions and drop-off and peak and drop-off. And so I was watching it the whole day. And I remember when I came home and I was kind of late that night and my husband said, have you seen what's going on with the election? And I said, yeah, I've been watching it all day.
It looks like this and like this and like this. Like, no, I mean results. I was like, well, I don't care about results. I walk through transactions. But yeah, so it was fun to be a part of even though I'm not necessarily responsible for it.
So Debbi, I think you're being a little bit more modest than— I've talked to Rich Schliep about it and he certainly has been very appreciative of the collaboration that they've had between the Secretary of State and your office, and they don't have nearly the staff that you have over at the State of Colorado and OIT. Certainly I know you guys have given a lot of resources for them, especially like you said during the election itself. Yeah. Thanks a lot for doing that. Yeah, you bet.
Yeah, and I'm glad to hear that election security is so good and that we haven't had any incidents around that, but you guys did experience an incident recently at CDOT. So I was wondering if you could talk a little bit about that, what happened there, and how you guys responded. So that was February of 2018, so February of last year, we— so Colorado Department of Transportation was a victim of a SamSam ransomware attack. So it was February 21st. I'll never forget that day or that date.
You know, hundreds of calls to the help desk with pop-up screens on people's workstations saying, I've got this message about, sorry, your files are encrypted, you've got to pay this ransom in Bitcoin. We had all of our, you know, the CDOT business applications were failing, the databases were locked up. It basically encrypted about 1,300 workstations across CDOT's business operations, about almost 400 servers, all of their applications failed. It was a bad day. I can imagine.
And so we started you know, assembling a team to get together. And actually, we didn't even really know the scope of it because CDOT had sent out a message to all of their staff saying, turn off your computers. You know, we've got a malware infection. Turn off your computers. So at this point, we don't even know how big it is.
So we started troubleshooting. We, after about a week, we felt like we were in a good spot. We felt like we, you know, had the right you know, I don't know, anti-malware signatures in place and, you know, all of the right controls in place. We had taken down the network. We had, you know, fixed all the holes that we were aware of and started bringing systems back online, actually walking around the building physically turning workstations on.
So overnight that night, and actually when we came in the next morning, you know, we left feeling very victorious. We're good, we've got this, we're on a path to recovery now. Came back in the next morning and found new attacker activity all over the network, new instances of malware. We weren't 100% sure at that time if it was the same or if it was different. And that's when I escalated to Office of Emergency Management.
And I did it for one reason, which was to get the Colorado National Guard involved, because we do exercises with them twice a year where we, you know, exercise a response to a simulated cyber event, and these guys are just phenomenal cyber warriors. And we have a computer network defense team in Colorado and then a computer protection— and I'm getting the words wrong, but it's more of an advanced team too. So we've got an awesome team and we have an even awesomer team in Colorado. And so I reached out to Office of Emergency Management and said, okay, I need the Guard. And they were ready because we'd been keeping them informed, and the Guard was ready.
The very next day they were on site. And so Colorado National Guard came in, in civilian clothing, they didn't want to intimidate our team, sat down beside us and helped, and really helped us to create a battle plan on how to really find all the holes, get rid rid of all the malware, you know, contain it. We built a test network and we brought clean systems onto that test network, and then we brought on, you know, systems that we knew were infected, turned them on on the network, and we were able to prove that our tools could contain instances of malware if we found additional ones. And so that was, that was instrumental for us to being able to actually recover at that point. So we spent about 2 weeks containing and eradicating the malware, and then 2 weeks restoring CDOT back to about 80% functionality, and then restoration to 100% continued for a couple of weeks after that.
But we did bring CDOT back faster than they even thought was possible. How many people did you have total involved in that response effort? We had at one time 135 people on-site So we actually moved into CDOT's headquarters into their auditorium, brought tables and chairs in, and then put teams together of, you know, we had our network team, we had our security team, we had our endpoint team, we had our, you know, various teams, system administrators. We had 4 different tools vendors on site. We had a professional incident response team.
We had Office of of Emergency Management, Colorado National Guard, we had Department of Homeland Security, we had the US-CERT Hunt and Incident Response Team, we had FEMA, they showed up, we had the FBI. I mean, we had a lot of people there. So it was a huge operation, huge response. What would you say coming out of that was your biggest lesson learned? What did you get from this?
Yeah, so, so there are a couple things that I tell— there's 2, there's 2 things that I like to balance. One is it's, it's a good news story in that we had good network segmentation in place, that it infected all of CDOT's business operations, but it never affected traffic operations. So it was not ever a life safety issue. They were segmented off and There, the security controls in place between the 2 networks caught the malware, and then Traffic Ops just went and unplugged the network. They said, we're not letting it in.
Additionally, we had good segmentation between CDOT's business operations and the rest of the state, so this malware did not bleed over into the rest of the state. So that was one good news story. The other good news story is we had good backups in place that we were 100% confident in. So we knew we had gone through a project that we called Backup Colorado, and we were confident that 100% of our production servers across the state were being backed up and that we could recover and that those backups were secure and offline. And so we, you know, we never considered paying the ransom.
Now, the one big lesson that we learned from a security standpoint that has kind of fed into my strategy at this point is that we are not executing fast enough on our security projects. So when we looked at how the ransomware got in, how the ransomware propagated, and all of the controls that were missing that would have allowed us to detect and respond, we had all these great projects already underway. We had the right strategy, we were headed in the right direction. They just— a project that is a great project that's in a project plan but not completed gives you no value during a security incident. And so in fact, we had acquired an endpoint tool that would've actually detected and stopped the ransomware that we were due to deploy the week after.
So we were executing according to a project plan, kind of agency by agency. We'd implemented about 4 agencies. CDOT was next. We were gonna implement them the week after, and this ransomware event hit. So when that happened, we just threw out the project plan and pushed it just broadly throughout the state.
And we actually implemented a number of things that had been in progress for a while that we just kind of said, sorry, security and gotta protect the state, and, you know, pushed it out. So that's something that, you know, our projects, our security projects get kind of caught up in all of the other infrastructure projects for all of those 17 executive branch agencies. And so what I've determined is I need to bring in dedicated resources to actually complete those security projects. I just can't, you know, I can't afford 4 years to go by and we've just taken little incremental steps. Steps.
So, you know, we've heard about a lot of breaches that are similar to this CDOT breach in other places, you know, City of Atlanta, Baltimore, lots of other places like that that have seen lots of ransomware attacks. What do you think was different? What made the response that you guys have had better? Because, you know, I've seen the stories on those and it's, you know, multimillion-dollar responses. As far as I know, Baltimore isn't even completely back up yet, and it's been weeks.
So what is it that you guys did that was different, or how did you prepare so that you could respond so much better than them? Yeah, I think having that network segmentation in place helped a ton. Having backups that we were confident in helped a ton, but also having good partnerships in place to where, you know, we've practiced our incident response, we have a good plan, we We update it, you know, every time we practice we update it. And just having those partnerships in place to where you could reach out and get that help immediately and already know how you're going to work together, because part of when you bring in even a vendor for incident response, you're establishing who's in charge, who's going to take this, who's going to do that. We already had all that worked out.
You know, when they, when the National Guard showed up, we already knew how that was going to work. And we could just roll up our sleeves and get to work. So I think, you know, part of it is having those partnerships in place. Yeah. So we have a couple more questions in the Slack channel.
The first one, which looks like an interesting one, you know, we were talking about election security previously. This is Dustin Lair. Do you think online voting will ever be possible in the state of Colorado? I think that it will at some point. I think I am confident that is something that the Department of State is looking into, and certainly there is some population like I think overseas military who have the ability to vote remotely, um, currently using I think paper ballots, and they have a longer window of time, but I believe they will be the first use case for potential online voting.
I got another one from the Slack channel from Chris Perkins. I'm gonna reword it a little bit. Do you think at all about zero trust? Is that a concept that you're trying to incorporate? It is, okay.
So what does zero trust mean to you at the State of Colorado and how do you imagine that, you know, being realized there? Yeah, so I wouldn't say we have a complete vision for that yet, but we're kind of chunking away at pieces that are meant to get us there. So implementing two-factor browser authentication broadly for everything. And there are probably people who are listening right now going, what did she say? Because I've told them, all remote access, that's how we're starting.
And then all Google access. And pretty soon it'll be all cloud access. And then pretty soon it'll be all— we're already working on privileged user access. Eventually, it will be all access, period. So in other words, we're not trusting passwords anymore.
Devices, we know, you know, we don't have enough controls to determine is it, is it our device, is it somebody else's device. So we need to get better at device control, and then we also need to recognize that, you know, we may not have the right types of controls on those devices. So we need to be looking at, you know, what controls are on the devices, whether it's our device or somebody else's device. Device, you know, is it up to date on all of its patches? Has it been jailbroken?
Has it, you know, so that we're kind of, we're starting to put all those pieces in place because I do believe that we're not, I mean, you can't trust the internal network, right? You can't trust that all the devices on it are yours. You can't trust that you know everything. You can't always trust that the user, you know, certainly we know with all of the password breaches, we can't trust a password-authenticated user. So we're working in that direction.
So what I think I heard you say was you're moving your controls away from like a network-based, environmental-based controls to having strong identity authentication, strong authentication to factor authentication, and then endpoint controls. So we really trust the configuration in the device itself. Is that a good summary for where you think it's going? And network, network controls. Okay, so that we— so it has to be those devices.
Yeah. Yeah. Awesome. And that we— yeah, I mean, my vision is kind of, you know, the typical NAC solution where if it pops up on the network and it's my device and it meets my standards, it gets this level of access. And if it pops up on the network and I don't know who it is or it doesn't meet my standards, it gets sent another path.
Sure. Yeah. So another question. Question from the Slack channel. I'm gonna reword a little bit also.
So yesterday we had an all-day session on privacy. Privacy is becoming a bigger and bigger topic. Is that an area that's under your purview? And how do you view privacy in relation to security at the state of Colorado? So the agencies actually own privacy at the state.
So each agency who, you know, collects data that's in scope for any privacy regulations, they have their own privacy officer and they own that program. However, with NIST 800-53 Rev 5, the privacy controls are more interwoven into the security controls. And so, I mean, I recognize that technology has a role to play, and so we'll be rewriting our policies to make sure we're kind of weaving in those privacy requirements as it makes sense, as it applies to technology. But our state does not have like a chief privacy officer. There's about maybe 25% of states that do right now.
It's becoming more common, but right now the way that we're running it is each agency is responsible for determining what information they collect and how they're gonna handle privacy for their agency. Sounds like we need to reach out to the governor and get him to hire a chief privacy officer also. Could be. One more, at least one more Slack channel question. Clay Parker asked if you could elaborate on how you're doing 2-factor.
Is that a hardware or software solution?
It is not a hardware solution.
Right. So it's a service. So one additional question from the Slack channel. So what are some unique challenges that you see in the public sector versus, I guess, the private sector? So, you know, pay scale, resources, you know, how has that been different and how have you looked at those challenges?
Yeah, that is a great question, especially you bring up pay scale. We are having a really hard time keeping keeping individuals in our security operations center, keeping individuals on our firewall team. In fact, when the CDOT incident happened, we were really hurting because we had— our entire firewall team had just departed. And so we just didn't have the familiarity with the state firewalls and with the infrastructure the way we had only a few months earlier. And so we were bringing in new people and training them, but we have this problem where we bring in new folks, we train them, they— just when they start to really understand the state environment and they get all those certifications and credentials under their belt, they move on into the private sector where they tell me, you know, I can make so much more money and I get all these other benefits.
And so it's been really, really hard. That has been the the number one, I think, most difficult thing. The second thing that I was a little, you know, maybe taken aback by was the fact that when you centralize IT for 17 executive branch agencies, it's a little bit like running IT or running security for 17 distinctly separate companies. And so if you think about company priorities, you would have maybe you know, 2 or 3 important projects at any given time that you're running for the company, and you're balancing those across the full company. But when it's 17 distinctly different companies, we've got— let's say if even if we had only 2 or 3 important projects for each agency, which I tell you it's a long list, that still you extrapolate that across 17 agencies and you give it all to one IT department to say go and And the problem is we're time slicing in such small increments that it's really hard to get things done.
And that's where I'm really suffering from a security standpoint is, you know, they have all theirs, you know, each agency has their 10 priority projects. So that's, you know, 1,700 projects. What, wait, that's not good math. Feels like 1,700 projects. And then I throw in a bunch of security projects as well.
And, you know, and everybody agrees, you're right, this is high priority, this is top priority, this is urgent, and we'll get it done with everything else that's urgent. And all of this is. So that's what I was really surprised about is how thin for resources we are. Well, we have just a couple more questions for you and then we're gonna, we're gonna let you go and people can go have fun. There's more drinks, I believe.
What is the biggest thing that you want to accomplish over the next couple of years? Yeah, so I'm really excited about fiscal year '20, which starts July 1st. So our fiscal year is July through June. But I have got a lot of security projects teed up. So one of the things that I mentioned is we haven't been executing fast enough.
I was able to take that in front of the legislature and say, you know, I need funding to finish all these projects that we have in flight that are not helping us until we get them completed. And so they actually gave me money for fiscal year '20. I'm actually doubling my budget for one year where I will be able to bring in resources and, you know, fill all those known gaps in our environment, complete all those projects that are in progress, and just kind of make probably the biggest one-year impact that we've ever seen from a security improvement standpoint for the state. So I'm kind of fastening my seatbelt and getting ready for this. But I will tell you, I feel a little bit like I've bit off more than I can chew potentially, because always before when I go to the legislature with an ask, you know, we start that process like a year before it comes to fruition, probably 18 months before.
And I always start with a huge ask, and it always gets narrow it down to a, you know, reasonable size ask. Well, this year they gave me everything I asked for, and I was like, okay, so now we have to deliver on that. Be careful what you wish for, right? Exactly. So next year when you show up to RMISC, you're gonna, you're gonna have a great story about what's happened, or you're gonna be too exhausted to talk.
Yeah, or both. Yeah, something.
So that's awesome. I'm looking forward to hearing about those accomplishments. What does the future hold for you personally? For me personally, well, you know, my husband asked me that too, because when I came to the state, I said, I'm going to be there 4 years. You know, I've committed to 4 years.
I'm going to do 4 years. And every CISO in my role before me has done 2. So I told him it's like 2 terms as a CISO. You know, I'm going to do double. And then I'm probably going to go back to private sector.
Well, so at the end of 4 years, he's like, so do you think you're going to leave? And I was like, what? Why would I leave? You know, I love what I'm doing. So, and then, of course, I have all these projects I'm really excited about.
So I'm going to, you know, see them through, and then probably at some point in my life, I think I'll go back to private sector, but I don't know right now when that is, and it's probably not in the next year. Well, Debbi, we— you have an entire community of people behind you. We want you to be successful. Let us know whatever we can do to help you. Thank you.
Thanks to Debbi. Thank you.
Thank you for taking on that job. I know it's not the job that would get you paid the most, but I think you're probably doing the most good you possibly can. So thank you. Thank you. So before we wrap up, Debbi, is there anything that you want to talk about that we didn't ask you about?
I don't— I can't think of anything. I can't— I should have been prepared for that question, but no, I can't think of anything. And I appreciate your support. I appreciate the support of the community and all of my peers. I love it when I can go into, you know, any leader's office and say, well, here's, here's an issue we're struggling with, and here's an issue that the community at large is struggling with.
It helps so much, and it gives credibility when I say, you know, we're implementing this project because that's what all my peers are doing. So, so yeah, I just appreciate the community involvement. So thank you very much. Awesome. Well, thank you very much for your time.
We appreciate you being here. We love what you're doing, and we look forward to hearing about this again in a year. So it's good. Thanks. Let's give her one more round of applause for Debbi.
And that's all we have for you. Thank you very much. This has been Colorado Equals Security, and we're going to sign off till next time.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time. Until next time, remember, Colorado equals security.