All episodes

Rob Winter, former CISO of Boulder Community Health

Apple Podcasts Spotify SoundCloud

To celebrate his life, and mourn his passing, we are replaying our interview with Rob Winter, CISO of Boulder Community Health as our feature interview this week. News from: A-LIGN, Ping Identity, Circadence, Coalfire, Qualys, Telstra, CyberGRX and a lot more!

Denver is one of two finalists for the Medal of Honor Museum. No, not the video game

Denver or Arlington will be the home of the new Medal of Honor Museum. We’re rooting for Denver. Telluride is the best small town in America, but Steamboat Springs and Breck aren’t too bad either. Breaking news: Colorado’s new blockchain leader says there are ‘endless’ uses for blockchain in the government. Go figure. 5G is live in Denver, but you probably can’t use it. Women in tech is getting serious. A-LIGN comes to Denver in force. Ping Identity had a big week at Identiverse. Circadence is looking to gamify security training. Coalfire partners with Qualys. Telstra (big telco in Australia) invests in CyberGRX. And we replay last year’s interview with Rob Winter to honor his memory.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12764 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 123 for the week of July 1st. Alex, we are halfway through the year already.

It is hard to believe, Rob. This year is flying. I'm excited this week, 4th of July, get a little extra time off, fireworks, blow some things up. Every year my kids do a— instead of doing a lemonade stand, they do an ice cream sandwich stand. So they make homemade ice cream sandwiches out of these cookies and ice cream, and then they sell them in the neighborhood for a couple bucks each.

You know, they make, they make 100 or so of them, and I think it's like $2.50 a sandwich. So they, you know, they make a couple hundred dollars minus $50 for maybe materials. It's a lot of money for 9 and 10-year-olds. That is. If there's anyone listening who's like, hey, I need some ice cream sandwiches, my kids would love to help you out.

Rob will be happy to give you his home address so you can stop by and grab an ice cream sandwich. There you go. We sit out by the pool on the 4th of July and eat and sell ice cream sandwiches. It's coming up in just a couple of days. Before we dive into the news this week, let's do a reminder.

We have a Slack channel. This is a place where you can all get together, talk to folks in the local security community. We have almost 1,000 people, just shy of 1,000 people there. And if you want to sign up to join. There's no secret invite.

You don't have to reach out to get in. Just go to the front webpage for colorado-security.com and click on the Slack mess— the Slack button there, and you can join in. And while you're there, at the bottom of that webpage, you can sign up for our mailing list. Just enter your email. We will add you to the list, and you will be the first ones to get the show notes when they come out for every new episode.

We would love it if you would subscribe to the podcast on your favorite listener, whether it's iTunes, Google Play, Spotify— not Stitcher yet, but maybe we'll get there someday. Maybe one day. Uh, go ahead and subscribe there and rate us if you wouldn't mind. We only have like 37 ratings on, on iTunes, um, so you could be the 38th. We would love it if you'd be that person, and that's a pretty special number.

Uh, also please tell a friend, just pass the word along, let them know about Colorado Equal Security, the things that we're doing, the podcast, the website, the Slack channel. Just tell them to come participate. And, and the last thing we'd say is if you want to support even more, we do have a Patreon campaign. Uh, this is a way for you to help financially support the show. All this money goes directly back into the security community, uh, but this is so Alex and I aren't having to foot the bill for all of these costs.

We just— a big thanks to the current patrons we have that we really do appreciate your support. It makes a big difference to us knowing that there's folks in the community who will lend their finances to make this work. Sure does. So let's jump into the news first. Denver is named one of the 2 finalist cities for the new National Medal of Honor Museum.

It's between us and Arlington, Texas, right? Yeah. We had talked, I don't know, maybe a couple of weeks ago about this possibility. Governor Polis was pushing for it. And it sounds like we've, we've made the final list.

So we're at worst, we're going to be the number one loser. That's right. Yeah. But pretty cool. It'd be nice to have.

I heard that there's a spot set aside, which is currently a parking lot on Colfax. I don't remember. I think Colfax and Federal. I'm not sure about the Federal part, but somewhere on Colfax. Yeah, I feel like it was closer to downtown.

But in any case, looking forward to hear whether we get that or not. And it would be great if we do get it. All right. Next, you know, there's always these— there's lots of lists in the world, right? And lists make the media go round.

Yes. But here's a new list which says nice things about Colorado, so we might as well talk about it. This is the— I think it's U.S. News and World Report's list of best small towns in America. And would you guess who number 1 on this list is, Alex? Alma, Colorado.

So close. Telluride. Telluride is the number 1 small town in America. That's interesting. You know, I have personally not spent time in Telluride.

Have you? You know, I haven't spent a whole lot of time there either. I have heard good things. And, you know, maybe I'll move it up on my list of places to go in Colorado. You know, there's, there's other spots in Colorado that made the list as well.

I think it was Steamboat Springs was number 8, and Breckenridge at number 13. Really, really cool stuff. As I was looking through this list, the full list of 25, I was thinking, man, going to all 25 of these things might be a good goal for, for me and my wife. Yeah, I did note that a lot of them were on the coasts, many of them on the West and West Coast and some of them on the East. Yeah, I think one in Alaska and a few others that are around.

But it was interesting where the distribution of them was in Florida. And there was actually a few really close to Washington, D.C., like the Virginia, Maryland area. Anyway, interesting stuff. Next, Colorado's new blockchain leader says that potential government applications for blockchain are endless. Well, well, this is, this is a shocker.

The blockchain person found blockchain uses. Uh, anyway, a couple of interesting things from this story. Number one, you might remember from a few weeks ago we talked about Governor Polis saying that his goal is that Colorado is truly the national hub for blockchain innovation. As a result, he hired a blockchain solution architect, Thaddeus, uh, Thaddeus Batt. And so Thaddeus is the guy who was interviewed in this article to talk about you know, how his vision for getting Colorado to, to really work with blockchain.

Yeah. And the article was a little bit interview of, of Thaddeus himself, you know, what he had done. He'd been a consultant previously. And then also about blockchain. I think, Rob, the shocker would have been if he would have said there is exactly one use case for, for blockchain as opposed to that they're endless.

Or if he said there was none and he was resigning and there's no way he would have said that. Yeah. So looking at the, uh, at the quote here, I did pull out one relevant quote, um, and I actually thought this was interesting. He compared this to other technology innovations where things get really decentralized and people are all doing their own stuff in different versions of the government. So Thaddeus's point is, if they have a centralized place to manage the blockchain innovation, they can do it in a more economical way, more scalable way, and really reduce the the cost of rolling this out to all the different agencies.

Well, I don't know about you, Rob, but I am looking forward to our blockchain future. I can't wait. Next, 5G, talking about future technology, is live in Denver now, but not everyone can use it. Yeah, so they actually have 5 different areas that have 5G rolled out. So Highlands, LODO around Coors Field, Central Business District around the Denver Center for the Performing Arts, Capitol Hill, and the Denver Tech Center, the northern section, all have 5G rolled out.

So if you're thinking to yourself, why am I not experiencing this, this high speed? Well, it's because there's only 4 cell phones right now that Verizon has that actually support this. Yeah, and also this is just Verizon, so you have to be a Verizon customer, not one of the other cell providers, and you have to have one of these very few cell phones, which almost no one has. And then if you're really lucky and you happen to have one of those 4 cell phones and you happen to be in one of those 4 areas, you can happen to go through your your data plan in, you know, 15 minutes. Right.

Yeah, there was some discussion on the Slack channel this week about, you know, the expansion of capabilities and speed you can get with 5G and how all of a sudden you'll be using up all of your data because it is that much faster. So, all right. Next story we have is written by the Colorado Sun and it was actually about women in technology. Tamara Chuang, one of our favorite reporters, is talking about the fact that that there's now a group in Colorado, or at least partially in Colorado, that's looking to document and share a list of technology achievements by women so it's not so easy to overlook their achievements. Yeah.

And there are actually a few examples in the article of those, those documentations that they had. One was around the computer science AP test in high school and the increased participation that females have had on that test. Interesting article. Lots of detail in there. Pretty long article.

So I think it's part of the momentum, right? We've seen a lot of momentum over the last couple of years that, you know, we've recognized that there's not enough women in technology. There's not enough diversity from a gender perspective in technology. And this is one way that we can encourage it is by showing the people who have already had success so that, you know, young girls coming up behind them can say, hey, I'm not— I don't need to be the first. There's already good role models for me to pattern myself off of.

So pretty cool stuff. Definitely. Uh, next, the cybersecurity firm A-Line is opening their second office in Denver. So A-Line is based out of Tampa, I believe. Yeah.

And, uh, they're expanding and putting a second office here. So we actually had talked about A-Line, um, a little while ago, I think when they first announced it. What was especially interesting to me out of this is that the, the CEO of this company, um, he, he said, we're opening up our second office in in Denver's Silicon Mountain. He, he said Silicon Mountain. So, uh, I had no idea we were Silicon Mountain, and I'm kind of excited about it.

I had never heard that term before either, so it is nice to know we have a nickname like other places. I, I, I think he came in just like pretending to know, and, and now he just coined an awesome new phrase. Uh, I, I think that's definitely possible. Uh, so he did say that there's going to be 30 of the employees for the company here in Denver out of their total staff of about 250. Uh, pretty cool.

That's a to be a good force, and I'm looking forward to meeting some of those people. I'm sure at some point there'll be 250 here and, uh, you know, none in Tampa. That's why. Yeah, why would you stay in Tampa if you can be here? Except for the beach.

Uh, next, there is a, uh, a press release here from Ping. So, so last week was Ping Identity's, uh, well, it's the identity industry's big security conference called Identiverse out in Washington, DC. And, you know, similar to how security companies will do a lot of press releases during RSA conference, Identity companies will do a lot of press releases during Identiverse. So there was a number of press releases. We kind of condensed down to one here.

This one here is around passwordless login and advanced MFA capabilities for their new solution. I had a chance to, to review all this stuff in advance. So my kind of summary of what Ping did is they made it really easy for developers to incorporate one-click social login into Facebook with their applications. So kind of customer-facing identity improvements made it really easy. Well, they've now released FIDO2 support that allows biometrics.

So you can use the biometrics directly built into your laptop and/or your Android device to authenticate. So pretty cool stuff there. And new intelligent risk capabilities to help deny people, you know, based on risk of their authentication. So a lot of new capabilities coming out in the last week for Ping. Um, and a pretty cool release here.

You can read about it. Yeah, sounds exciting. Next, uh, Boulder-based Circadence has created a program to gamify cybersecurity learning, and it is being used through CU Boulder. Yeah, that was pretty cool. The, the cybersecurity professor at CU Boulder, Laura Lee, who was actually a Circadence employee in the past, brought that gamified experience into her class and says that the kids have really taken to this, you know, versus doing book learning and lecture learning, getting this gamified, uh, experience is probably a good way to teach people.

Yeah, and, uh, there has been some research that shows, uh, sort of multi— multiple modalities of learning help you learn and retain information, uh, better. So that's— it's definitely cool to see that. Uh, next, Coalfire has partnered with Qualys, um, to, to bolster their automated services offering. So, you know, Coalfire, we talked not too long ago about their new scanning in the cloud service. Uh, looks like they're now partnering with Qualys to do scanning as well.

So I'm not sure if this means they have multiple ways to deliver the scanning or if this is taking the place of their other one. But hopefully soon we'll find out. Yeah. And I did notice this was in relation to FedRAMP. So I don't know if maybe it's possible that the Qualys or the Coalfire service is not FedRAMP certified yet and Qualys is.

That could be something like that. Yeah. That kind of augmentation. Yeah. Plus, you know, people may want to have choices.

It's always good to have choice. Love it. Next, Telstra Ventures had an article about their investment in CyberGRX. So This is not a new investment in CyberGRX. It was from their— the previous round that they had.

I want to say like end of the year-ish or something like that. Something like that. But this is just talking about how Telstra is— was involved in that round and essentially how they believe in CyberGRX and maybe we'll have them as a potential customer. So I'm sure there's a lot of folks who don't know Telstra. They are the biggest telecommunications company in Australia.

Think of them like maybe an AT&T or a Verizon of Australia. And as they've taken a stake in CyberGRX, You know, probably CyberGRX can, can nudge them along to, to pushing Telstra's vendors through the CyberGRX process, right? Could be a real shot in the arm for them to, to get more vendors going through it and start to get that adoption that's so critical. You know, enterprises don't want to sign up for a service unless you've got their vendors in there, and vendors don't want to sign up for the service unless you've got their enterprises using it. Yep.

You really have this chicken and egg problem that they can try and use someone like Telstra to help. Get around. Sounds good to me. Uh, finally, the— this is another reminder, the CISO of the Year award voting is open— or not, not voting, the nomination process is open right now. So the link is in the show notes.

Go in there, uh, click your favorite, uh, click to nominate your favorite CISO. Uh, we'd love to have you. There's other categories as well. There's the CIO of the Year and Company of the Year. So anyone— Project of the Year.

Project of the Year, that's great. Uh, lots of good stuff there. Nominate who you think is right for any of those. Uh, and we'd love to, love to see those folks on the stage at APEX Awards in November. Yeah, definitely.

All right, that's the news. Let's move over to the Slack Message of the Week. Thanks again to Andre Gaeta for sponsoring the Slack Message of the Week. We really appreciate that. He has been a great support to us in the community through, um, providing a $25 gift from the Colorado Cool Security Store for the winner of the Slack Message of the Week.

Uh, so our winner this week is Travis Bradford, or Trav Dog as he goes by in Slack channel, uh, he really prompted a conversation around mentoring. And, you know, it turned into a chance for us to open a brand new channel. So we have a mentoring channel for people to talk about, uh, those who want to be mentored, those who are, who are mentors and who want to match up with folks. We are not running a mentoring program at Colorado Equal Security until some volunteer comes and says they want to do it. Uh, I, I have no interest in running a mentoring program.

Um, but it is a nice new conversation and really a thing that we can do to help people with their careers and help the security community in general. Awesome. So congratulations to Travis, and let's jump over and look at the events. All right, we have one event this week. It is Fourth of July week, so not a lot going on, but on the 1st of July, SecureSet is doing one of their capture the flag events.

The following week, ISSA Denver is doing their July chapter meetings on the 9th and the 10th. On the 10th, SecureSet is doing a Hacking 101, an introduction to PowerShell. Oh, that's exciting. Colorado Springs, you know, they normally do a Cybersecurity First Friday, but because of the scheduling with Fourth of July, they're doing a second Friday in July, and that is on the 12th. All right, that is it for events for the next 2 weeks.

Not a lot going on with the holidays, but moving ahead, we do have jobs to go through. There's a couple of open jobs at Ping. I actually have a few jobs in my product security area, so I'm looking to hire a manager of product security and a product security engineer and an associate or a junior engineer in that area. So go out to the website or reach out to me if you have questions, and I'm happy to talk to you about those positions. NREL is looking for a chief information security officer.

So if you care about energy and research and want to be the CISO there, check that out. Yeah, we've talked— we know Desiree Robinson. She was part of the— part of our panel at RMISC. She was the CISO over there, and she's moved over to Survey Gizmo now, right? So, uh, congratulations to her for that move as well.

Kaiser Permanente is looking to hire a cyber risk defense consultant. Comcast is looking for a security operations center lead. Tenable is hiring a security sales engineer in the Southwest. Pivot Point is looking for ISO 27001 lead auditors. VMware is hiring an information security architect.

Canonical is looking for an Ubuntu security engineer. And Presidio is looking to hire an intern. So yeah, we did have some people on the Slack channel this week, uh, looking for internships still. So it looks like Presidio might be an opportunity. Might be an opportunity.

Well, that is it for the news this week. Uh, we do, you know, have a little different— something different we're doing this, this week in terms of our interview. Uh, we mentioned at the beginning of the show last week that Rob Winter, our friend and the CISO over at Boulder Community Health, passed away last week. Um, this week we're gonna, we're gonna rerun the interview that we did with him last year. Rob, you know, he's, he's a close friend, or not a close friend, but a friend of ours and someone who we knew pretty well.

We do have an update on his, on his end of life and wishes from his family. So his body is going to be donated to science. So this was one of Rob's wishes. Obviously, you know, he's been a big supporter of health for, for his whole career. And he's excited to be able to do that, you know, with his body after his life as well.

Yeah. And there are— there's going to be a celebration of life. I don't know that we have a time for that yet. But as we get more information on that, we'll definitely pass that along. Rob definitely wanted it to be about fun and about a celebration as opposed to, you know, sort of a typical funeral or mourning, specifically asking people to wear their Hawaiian shirts.

So make sure you get your Hawaiian shirts ready for that. In lieu of any flowers or cards, the family is working with Boulder Community Health Foundation to set up a donation page for the Center for Integrative Care. Um, once that page is set up, we'll make sure we share that out to you guys as well. Yeah. And, and of course, Rob's family is asking for privacy during this time.

So, um, until we know more about the, uh, the celebration of life, uh, please give them some space and, and, uh, let them mourn. All right. Well, that is it. Uh, enjoy this, this, uh, interview with Rob. Um, and we'll look forward to talking to you guys again next week.

Thanks, Rob. This is Rob Winter, Chief Information Security Officer at Boulder Community Health. Welcome to Colorado Equals Security, for Colorado security professionals, by Colorado security professionals.

All right, welcome to Colorado Equals Security. This is our feature interview this week, and I am sitting down with Rob Winter. Rob, you are the CISO at Boulder Community Health, and I want to hear all about what you're doing up at Boulder Community Health. But first, it's been a little while since you've given me an update. How many miles have you put on the bike in the last few years?

So as of this morning, you tell me, about 6,500— or I'm sorry, 3,500 miles for the year. 3,500 miles so far in 2018. Right now we're just starting September as we're recording, so you're on track for 5,000-ish miles? About 5,000 to 5,500. And so how do you get so many miles in?

When are you finding the time for that? Get up early. The easy answer is you get up at 5:00 a.m. and the second the sun breaks, you're outside. And is this every day? Almost every day.

So usually it's 6 days a week, 1 day off. Wow. And what does a typical ride look like for you? In the morning rides, they tend to be anywhere between 25 to 30 miles. Weekend rides can be up to 75 miles, maybe even up to much as 100.

And is that— it's not going to work, you're riding and going back home and showering and then driving into work? For the most part, yes. You know, commuting-wise, to go from my house to work is about 15 miles, and then coming home, because I go up towards the foothills, ends up being about 20 more miles. So I could still get some in, but you know, then again, I'm a wimp, you know, with the heat. It's, you know, preferred just to get done, too hot, start the day too hot in the afternoon.

Exactly. And then go out there and you start the day already refreshed. So is it— does a 30-mile ride take— is that 2 hours? About an hour and 40. Because that's 20 miles an hour, a little bit somewhere between, you know, 18, 17 to 18 is usually what I average.

Okay. And obviously you're talking road riding. Where— what kind of roads? I don't know what part of town you're living in and riding in. So I live in northwest Longmont, and so a lot of the rides go up towards Lyons.

Yeah. There's a lot of old roads back there, roads that just aren't well traversed with cars. So easier to go back up there and kind of just go get lost and enjoy nature. So what do you do when there's snow and ice on the road? So there's a software package called Zwift, and it allows you to ride your bike.

Think of it as social media for bicyclists. So you're able to ride with people from all around the world indoor cycling. But so they're over there, so a lot of guys I ride with are from Great Britain or Germany, especially in the mornings. That's their evenings. So you'll be having You'll have a lot of people and just you get on there and you can do little chats with them just through instant messaging, and you just start learning about people from around the world.

So you're riding on a stationary bike or are you riding on one of the trainer things for your own bike? So for mine, it's what they call a smart trainer. So as you go up a hill, it gets harder. As you go downhill, it gets easier. So it really mimics the road feel itself.

And this is not using your normal bike though? Free, its own standalone device? You could actually go ahead— there are ones like Peloton that you can go ahead and do that, but there's ones like mine where you go ahead and attach it to your bike, to your normal bike. That's pretty cool. How long you been doing this?

So cycling-wise, I started out when I was in high school going ahead and racing until I blew out my knees shortly after I started college. Okay. Uh, got nice and fat, so got into IT. I don't know which came first, but you know, either way Ended up deciding, you know what, I got to get back in shape. So I started doing that, ended up going to the same hospital, so Boulder Community Health, to what they called at the time Boulder Center Sports Medicine and rehabbing with them.

So even years before I started there, went ahead and started working with those guys to rehab, lost about 50 pounds, started racing, started actually doing fairly well in 2015 where, you know, started placing on the podium again. So, wow. Got nationally ranked in time trial, which is that race against the clock. You think about, you know, years ago what Lance Armstrong or Greg LeMond would win a lot at. Yeah, that's the same type of thing.

It's you versus the clock. Wow. And so just, you know, enjoy it. It's my zen, you know. It's after a hard day at work or, you know, starting the day like I mentioned.

It's the way to go ahead and, you know, keep the mind fresh. That's awesome. Well, let's, let's go ahead and back up. I want to get your story. Where are you from?

So predominantly from Denver. Before that, military brat. My dad was a JAG in the Marine Corps. Yeah, so predominantly was in Camp Lejeune, North Carolina. And then after he got out of the military, moved to Denver, and basically from that point, born and raised.

So you came to Denver as still in school, is that right? What school did you go to? So, you know, for high school, Regis High School. All right, and you graduated from Regis. What did you do after that?

After that, went up to Colorado State, so up to Fort Collins. Well, I was for a whole year. Okay. So, you know, I'm one of those interesting stories where somehow I found myself on the football floor where the quiet hours between about 5 to about 7 in the morning. And so after year one, I was politely asked not to come back to CSU.

So came back down to Denver, dabbled around a little bit, was working at a bike shop, was working here at Turen in Denver. And, you know, started trying out different things. You know, I was pre-law for a little while, finance for a little while. Where were you going to school? Down at Metro.

Metro. Okay. And so just kept dabbling. And then one of my friends who was already in IT went ahead and said, hey, you got to try this. Yeah.

And, you know, we were talking about what to do and we decided to start our own web design firm. And so during lunch hours at the bike shop, I would go up to the roof to sit back, read an old HTML book. This was about 1996. Okay. And so it started doing it.

This is before any WYSIWYG was around where you just started hand coding everything. Yeah. So built the first, uh, my first website was for Turin. So they were the second bike shop in Colorado to have a website. So, you know, it's really kind of cool to actually get it out there.

And we were having people coming from all over the state saying, hey, I saw you on the web. They came in and would buy stuff. I saw your rotating GIFs on the web and I, and I just had to come in. Yeah, because there was no way to buy it on the web, that's for sure. DIF-89 was big at that point.

Uh, so, so you, you kind of taught yourself? I very much taught myself. Yeah. So after a while, um, you know, I decided to leave the bike shop, did some contracting for a little while just to get my feet wet, get some experience. Ended up finding myself down at US West.

I was part of a group called the Law Group Technology Services. They were the offshoot kind of rogue IT for US West. But specialized in supporting the legal group, public policy, which are basically lobbyists, HR, and then security. And so ended up doing a lot of Y2K projects for them, refreshing desktops and servers, and worked my way up to team lead there. After a while, I had some friends tell me that Quest was knocking on the door, get out now.

So went ahead and jumped ship, moved to JP Morgan. They started what they called their Wealth Advisory Center. Was that here in Denver? That was here in Denver. That was in the Tech Center.

And so right over by Oracle. And so we— that lasted about almost a year. So that was supporting their poor millionaires. So poor millionaire was defined as $1 million up to $5 million in assets. To be a poor millionaire, yeah, it's a tough life.

So I'm not sure how those people would feel about being called a poor millionaire. That was the official term, unfortunately. So unfortunately, they deemed it more of a startup, and that was right when the bubble burst. And so it was one of the first casualties that happened with that. So found myself on the job market.

I ended up moving to Perot Systems. And as in H. Ross Perot? That was him. But this is a few years after his presidential election. That was— so it's 2001, moved to Perot Systems, and they had the full outsourcing for Budget Trucks.

So if you remember the old Yellow Ryder trucks, now the Blue Budget trucks, we had the full IT department. So I worked there as a sysadmin, worked myself up into the manager role. I remember a boss one time came to me shortly after I started. She was like, you know something about security? I'm like, yep.

And she's like, great, teach our security administrator. And it was more access control at that point. So I kind of used it to my advantage, said, okay, I need a SPARC station, need a whole bunch of books. And once again, self-taught with the this. I just started reading up more and more, always dabbled in it.

Even at US West, did some investigations with them because EEO Group, which is more the investigative side of HR, had to do work with them on that one. I'd always dabbled in it but never had formalized it. It was at Perot Systems that you really went from being formal IT to really becoming a security professional? That was actually— no, I stayed formal IT. At that point was a sysadmin, became the team lead, became the manager.

Unfortunately, the account moved out to New Jersey and they gave me the option to move there and I said no. I ended up doing other things with Perot, did some project management for a little while, then I made the formal leap back into security. I started doing more SOC transformations, which is basically coming in, take over other companies' SOC units. Security Operations Center, or do you mean like a SOC audit? A SOC is more moving the SOC to Perot systems.

The Security Operations Center? Security Operations Center. Got it. Okay. At that point too, I had started dabbling a little bit back in school, so went to Regis University.

That was right around 2003 is when I started back. That's just when they started their security program. They had started— That's early. It was very early, but what happened is they had partnered up with the Air Force. There's a big presence of Regis down in Colorado Springs where they wanted to go ahead after September 11th to go ahead and start training on more about cybersecurity.

They had started one class down there and then they brought it up here to Denver. I was the first class with that. There were 4 core of us, 4 guys that started in that class. It was 4 classes is all it was. It was basically a Security+ CISSP P training class.

Yeah, it wasn't heavy in technology, it wasn't heavy into a lot of things. And that's when I started going to my professor and going, hey, have you looked at this book? Have you looked at that book? Yeah. And they ended up starting to adopt a lot of that, those books.

Yeah. So it started adding to it, and that's where I started feeling it was great giving back, not just consuming, but that point giving back to the culture, giving back to the community. So it started— did you end up getting a degree from Regis at that point? Got my bachelor's from there. Okay.

And they convinced me to go back for my master's, uh, with pretty much the, hey, we want you to start teaching as well. So I started doing that. When I graduated in 2010, they basically brought me on as an affiliate faculty. Affiliate just basically meaning you have a full-time job but then you teach in the evenings. And so I've been teaching now for 8 years with them.

And you've been doing that continuously for the last 8 years? Uh, this semester is actually the first semester I can recall that I have no classes I'm teaching. Okay. Regis teaches in 8-week chunks, so you're able to go ahead and sometimes I would teach 8-week 1 of a semester and sometimes just 8-week 2. Yeah, but this is the first full semester I don't either.

Now, is that, is that because you're, you're done or you're going to start again next semester, or what? I'll start again next semester, and part of it was because I'm actually redesigning a couple courses, reworking the curriculum. Correct. So is that a job? If if you're reworking curriculum, or is that a job, or is that just something you do so you can teach later?

It's, it's a job. I mean, I definitely get paid for it, but it's also because we have to keep the technology fresh. We have to keep all the curriculum fresh. If we don't, it grows very stale, as you know, very quickly. Sure, sure does.

So, you know, we're jumping around a little bit. The Perot Systems gig, it looks like you did that through the end of 2007 while you, while you were still doing Actually, and then, but I moved to another account in 2008, so I moved out to Stanford Hospital and Clinics. Okay. And so they had the full IT outsourcing as well. And so I was traveling back and forth between Colorado and San Francisco basically half-time.

So, you know, had a nice apartment out there, you know, stayed out there, fly back, you know, every other week to see the family and go right back out. So it was very fun, very educational. Got to play with a lot of toys being the Bay Area. A lot of companies wanted Stanford as a name, so it's great to go ahead and just try different things out, try different technology. You were the security architect there at Stanford?

I was security architect and then eventually moved my way into security manager.

It looks like that was 4 years there. That's a pretty good run. What was the highlight, best thing you did there? Best thing I did there was being told by the CIO that she would put our security team against any other healthcare security team. And so to hear that from— basically Stanford is up to, I believe, the top 7 hospital in the nation.

To be told that, that was very much of a pat on the team's back. Yeah. And knowing that I had a part to play in that with the whole team, you know, that was a great thing. That's really cool.

And you were there through 2011? Till the end of 2011. What happened there? Yeah, so one of my bosses from Stanford moved up, became the CIO for University of California San Francisco Medical Center, so UCSF, and asked me if I'd want to come up there and be their CISO. And so thought about it for a little bit, talked to the family, and decided let's move up there.

Well, was it— is it because it's a, you know, the next step up in your career as in terms of title? Title, and at that point it was the number 5 hospital in the nation, so moving up in the world. Okay. And so it was, you know, kind of getting more exposure and able to run it my own team at that point. So not just under my CISO at Stanford, but running it as the CISO.

And I talked to my boss at Stanford and he said I'd be foolish not to. It was just a great opportunity. Yeah. So did that for 2 years. Very educational.

Even though Stanford was academic, being state academic with UCSF, it was just— it wasn't the right culture for me at that point. You know, I found myself working 16-hour days, very much the Bay Area type of environment, you know, traveling back and forth between Walnut Creek where I lived. I would take the train out at 6 AM, get back somewhere around 9 PM, and then, you know, say goodnight to the kids and immediately start working again. There'd be weekends where I knew my boss was watching— he was a big Texas Rangers and San Francisco Giants baseball fan— so all of a sudden the emails would start flooding in as he's watching the game. So there wasn't a lot of downtime, and it was It definitely— I recognized it back in 2013 when for Christmas I just shut everything off and I could feel my blood pressure coming down.

So I figured at that moment I would go ahead and have a heart attack if I didn't step back. And for the family, they're like, it's time. So ended up moving back. We had our house in Elizabeth, so I moved back in there. So Elizabeth, Colorado, you already had your house ready to come back.

And so, you know, did that, and an opportunity came up with Boulder Community Health. So did you move back before you had the job, or you— I had actually started. So there was also one little other little part, which was they were consolidating IT of both the campus and the Med Center for UCSF. Yeah. And so IT security was also part of that.

Okay. They offered me the campus role, but because it's— you either got it or you didn't. If you didn't, nice knowing you. Yeah. I was applying at that time.

Yeah. And so just for fun, you know, I was already applying back here Colorado. Yeah. And the job opened up. And so, you know, right around Christmas time is when I got the offer, right when I was shutting things down, and it really solidified the decision to move back to Colorado.

And that's the offer from the Boulder Community Health? That's correct. Yeah. Now it sounds like, you know, from what you said, you know, Stanford and UCSF being, you know, top 10 hospitals, I assume Boulder is— Boulder Community Health is a significant step back in terms of size and scope of what you're working on. To an extent.

You know, part of it is being true to yourself. You know, so I looked at kind of where did I have the most fun. Yeah, you know, was it with the big teams that, you know, Stanford, I had a team of 50 people because I had Active Directory underneath me as well, besides access provisioning and operations. And so it was good to have big teams, but then when you can make an influence having small teams, that was really valuable too. And so part of it's because I was teaching, I had to stay technical.

You know, some of these CISOs, they're definitely more administrative points, you start losing a lot of the technical capabilities. I enjoy it, so why not go back to something where it's a smaller team and you can have more direct influence on patient care? Yeah, well, so for those who don't know, why don't you tell us about Boulder Community Health? What's the— what does this health system look like? What's it made up of?

And so we're one hospital and we're just about 30 clinics, so very small. We're Boulder and Broomfield counties only, so we're not going to really extend outward. We're going to open an urgent care clinic in Erie, so that's Weld County, but we're just barely creeping over the county line at that point. We just, we're really serving the community itself. We're one of only 2 community hospitals left in Colorado, so we're very much small but very much focused on the community.

What's the other community hospital? Yeah, there's one down in Pueblo. All right. Everyone else, you know, people, the long holdouts like Estes Park, they finally rolled over to someone else just because they needed help. What does it mean when— what if a hospital is a community hospital?

And then what are the other options? So nonprofit, very much focused on the commercial. So we have a lot of, you know, Centura surrounding us, we have Banner, we have HealthONE, we have University of Colorado Health surrounding our area. And so we're just— we're not a big conglomerate, we're a one-hospital organization. Yeah, I mean, wouldn't University of Colorado Health be nonprofit too?

No, they're state. They're not nonprofit. What's the difference? So just, it's just how the state's not— it's how you contact. They're making money as well though, right?

And you guys are basically a nonprofit organization. We're a 501. And how many employees do you guys have total? Total, we're just hovering right around 2,000. And I assume most of those are in clinics or in the hospital, correct?

Kind of patient-facing. Is there a corporate back office side that's, you know, that's not— I don't know exactly how you break it down. I'm thinking like there is back office. I mean, you have finance, you have departments, uh, like, uh, patient financial services, uh, decision support. You of course have HR on the back end.

Yeah. So you do have those. Is that in— is that in your own like corporate office away from the clinics? They're spread throughout Boulder. In the clinics themselves, it could be in a clinic, it could be like in our building.

It's, you know, so we have what they call HRM So that's medical records is another term for that one. So that's in ours. Just wherever there's room, basically. And where are you set? Is it just a building just for— It's a building about 6 minutes walk from the hospital.

Okay. But for us, it's wherever we can put it because the critical, as you were mentioning, those are the ones that are patient-facing. So we really wanna make sure all the good spaces, those are first and foremost for the frontline. So you got there in January of 2014. It looks like, so you've been coming up on 5 years pretty soon.

That'll be great. What was it like when you got there? Interesting, because I was the first security officer there. They had a security program that was run by the CIO and then the director of infrastructure, but it had never had that true, as a lot of guys know, that true security focus there. I walked in the door, went from my roughly about $4 million budget at UCSF to a whopping $140,000.

Yeah. And one of the first things they did is say, can we take some back? So it's like, how can I— what can I do with that kind of money? Yeah. And what can I do to be creative?

So as most people got— as most security guys do, they go in there, let's do an assessment, let's do an overview of the environment, let's figure out what's working, what's not. A lot of stuff was working right, a lot of stuff needed to be tweaked, and then we have— I was able to build my program from there, right? My experience has been if you go to a place that was run by— where the security was run by IT, what that really means is it's not a program in any way. They do the things that they are aware are important for security, but not necessarily documented, not repeatable, maybe not even actually happening, but maybe they invested at some point. What were the areas that you said, you know, when you first came in, you said, hey, we've really got to get some programmatic, um, some, some programmatic approach to these things?

So, uh, disaster recovery was one. Sure. Uh, back in 2013, they had Meditech, which was their major EHR, so electronic health record system, went down. It was publicized. And, you know, so it's what do we need to do to get that up and running, to get actual tests in place, get it documented?

That was a one. Other ones are security awareness. That's one that we're still constantly doing, of course, because it's a continual effort. Then the other thing is just more formalizing visibility of the network. We started bringing in some technology to see both east-west and north-south.

Getting that visibility, but trying to do that without a budget, really, right? Correct. It's very creative. A lot of it was OpEx started reaching out to a lot of my vendors in the, uh, the Bay Area saying, okay, what can you guys do to help us? You know, and definitely played the, hey, we're a community hospital, right?

We don't have a lot of money. You know, compared to a lot of companies, you know, our margins are 2 to 3% on the high end. You know, if we hit 5% margins, we are doing excellent that year. You know, as a community hospital, you're trying to keep it as close to cost as you can so that it really helps the community. So there's not a lot of money to go out there and go from, like I said, UCSF, I had a $4 million budget, and then going way down and, you know, asking for more isn't always there.

If you have a choice between a million-dollar Nuuk Med machine to help a patient, to scan them, or a million dollars of a security program, which one are you gonna go with, right? And always you should go with patient care. You know, first, I wouldn't say always. I mean, there's, there's got to be an equation there. Right, where you figure out what is the overall good that can be done from these experiences.

Correct. You start being creative. You start figuring out what you can do. Instead of building up a team initially, I outsourced to, at that time it was Solutionary, now NTT Security, just because I had no budget, no team. There are things that they did well and things that, as they became a big company, they had some growing pains as well.

It was able to at least get me by in the meantime, get me visibility where I didn't have to hire a 24/7 staff.

One of the ways that companies might look to save that budget money is if they can go after open source software to perform some of those tasks, using Security Onion versus using Snort. There are lots of examples like that. Do you have an opinion on that? Are you a fan of going after the open source tools, or— we're looking right now possibly going with Bro. Yeah.

So CU's done, from what we've heard, an excellent job, have Bro throughout their environment. Yeah. And so we might actually do the same thing. Just, you know, we have to look at what's the right solution and the right cost for us. So it's looking at everything.

It's not saying commercial only, open source only. What's the nice blend between the two? What is the— what's the risk? What's the risk, uh, the big threats for Boulder Community Health? Obviously, you're thinking about patient safety, but obviously we see a ton of ransomware attacks that are hitting health organizations.

And what kind of things are you most thinking about, you know, maybe the keeping you up at night type of a question here? So everything from, you know, it could be simple loss of data records, nothing malicious happens, to when you look at healthcare on the full spectrum, it can go up as high as death. So, you know, if someone was to modify a pump, some kind of infusion pump at that point, and either give too much or too little medication, at that point someone could die. So it's really looking at the full gamut behind it and then trying to figure out, you know, of course it could be from an insider, it could be from an outsider. Ransomware, you had mentioned that one, that, that's a definite threat because right now hospitals unfortunately have paid it, right?

And so the bad guys know this is an opportunity to go ahead and get paid. You mentioned one of the first things you did was disaster recovery, which I assume starts off with all about backups and figuring out which systems are backed up and do those backups work and all that. How else do you think about defending against these threats? Obviously, there's a lot on the line with potential death and unavailability of health services. What are the key fundamental things you're working on done to try and avoid those?

A lot of those is practice the basics, the blocking, tackling. Yeah, you know, it's football season, so I'll use that as an analogy. It's making sure we have visibility in the network, making sure that we actually have— so we just recently, about almost a year ago, bought LogRhythm. So their part— their office is actually right across the street from our parking lot. Perfect.

Uh, so, you know, it was a great partnership. You know, we're their hospital, so they They definitely helped us out setting it up and getting up and running, so it's getting more visibility into the environment, stuff that we just didn't have fully at that point. With NTT, as good as they were helping us, you paid per system that you had in there, so it got very costly to get more visibility. With LogRhythm, yes, you pay messages per second, but at the same point, we could put a lot more in there, we could go ahead and filter a lot better, and we really were able to do that. That's the basics.

It's making sure we stay up and top with, you know, they didn't have a threat vulnerability management program, so they had no scanning when I came in there. So it's giving them the basic information of what do they need to do, the operations team needs to do, to go ahead and keep the system up to date. You know, we're not doing anything radical there, nothing pseudoscience type of stuff. It's really the basics. Sure.

You know, it's stuff that every security company should be doing. Yeah, every program should be doing that stuff. What about compliance work? Do you— obviously you have to be HIPAA compliant. Is that, is that a big part of your job?

HIPAA and PCR are 2 regulations we got to deal with. Yeah. And so definitely, you know, when I talk to the board, they're always asking about the status of that. You know, I'd say there's things that we— I try to have a critical eye and say we're doing things well, and there's things that we are working our way towards doing things well. As with any company, you're constantly looking at how can I keep improving the program itself.

Yeah. But HIPAA is one. HIPAA though is not as prescriptive as PCI, so there's some stuff inside of HITECH that made it a little bit more prescriptive, but it's, you know, you have a lot of things where they're either required or addressable. Sure. And so it's just, it's the minimum bar is how I look at it, and no one wants to be at the minimum level.

Yeah. Are you— have you guys looked at all at HITRUST? Is that something you guys have gone after or going to go after? Part of it we're seeing where the Office of Civil Rights, OCR, they're the enforcement wing for HIPAA, where they're going to go with it because they're kind of looking like they're going after the NIST framework, but then again, HITRUST has elevated their program to now include part of the NIST framework. Where's the happy medium point?

Our framework right now is kind of a blend of the two. Of the NIST Cybersecurity Framework and HITRUST. HITRUST, from everything I hear, and I haven't ever been HITRUST certified. It sure looks like it's a pretty daunting one. It's more rigorous than something like a SOC 2 or an ISO certification or even PCI from everything I hear.

Is that your impression of it as well? I got certified in HITRUST back in 2010, and from what I've seen, it depends on how far you want to go with it. If you want to self-attest, then, you know, it's— you can go ahead and do it. They get— at least as of a couple years ago, they had a spreadsheet that was really nice. Now they moved more of an online Archer type of system.

But you go ahead and say, I'm this big of an organization, I have these concerns, and it will go ahead and kind of build what requirements of the framework apply to you. Yeah. And so it doesn't have to be fully daunting. So if you're, you know, a couple doctor clinic, you know, standalone clinic, it doesn't have to be 500 questions. For you.

But if you're a big healthcare organization, yes, you're gonna want, of course, to have a deeper look because you're gonna have a lot more avenues where a bad guy could come in. Yeah, so it sounds like the last 4 years or so you've really been focusing on getting the blocking and tackling in place, being able to show a repeatable program. What's next? How are you finishing 2018 and 2019? What's gonna be your priorities?

The priorities, we're switching our electronic medical record system. As I mentioned, Meditech's the big one we have for inpatient, and we have another one called Greenway for ambulatory, but we're going to go to Epic. That's kind of the big name inside. You're replacing those other 2 with Epic? Those other 2 with Epic.

That's the big priority right now for the whole organization is switching over. From a security perspective, how does that impact you? Thankfully, not heavily because access provisioning is not part of my team. That's part of the service desk team. So, you know, a lot of mine is more the architectural design and validation.

So we're going through, you know, the different— both not just Epic but the partners of Epic, making sure they meet our standards. Yeah, but, you know, from a lot of the actual effort itself, it's not a huge impact. It's definitely an impact because there's only 2 of us on my team right now. Yeah, so it's, you know, a lot of work for 2 people, but it's still— it's not as bad as some of the other teams. And is that— does that take you through 2019, or how much?

October 2019. October 1st, 2019 is our target date for go-live. And then you're— so that's gonna be your number one priority. Any other stuff that you're gonna try and squeeze in around the edges there? You know, I thought about it and just finished up my budget predictions for 2019.

We're on the calendar year and decided, you know, a lot of the blinky lights, it's not worth it because a lot of the stuff that we want to do, we would need help from the infrastructure team. Yeah, and they're still working on Epic, focused on Epic. That at that point it's not worth it. So the other gentleman, Brian, and I, we're just gonna be working on taking the systems we currently have and keep getting more out of them. So, you know, keep tweaking it, keep getting better at them.

Yeah, I think, I think that most companies out there could, could do with taking a year to just optimize what you already have and maybe honestly get rid of a couple things you already have and, yeah, and get better at the stuff you don't get rid of. Exactly. And especially nonprofit we always look for areas to, if we can drop something because something else can do the same thing, we do it. What's the biggest lessons you've learned over the last few years there at Boulder Health? One of the biggest lessons, and this is more from a personal level than an information security level, is that it's not worth stressing over things.

When you ask what keeps me up at night, the answer is not much. As long as I go ahead and let my board know, let my, what we call it, management councils, who are VPs and our CEO know, and they accept the risk, not a lot keeps me up. And a lot of that goes back to back in 2015, I was diagnosed with stage 4 colorectal cancer. So had spread from the colorectal region to my lungs, to my liver. And you start realizing what's important in your life.

And the answer is not much, not much. It takes— it's worth that level of stress worth that level of just sleepless nights, right? Uh, short of fighting, you know, I have 3 kids. You know, my eldest now just started college, and so my, uh, I have another son who's in high school, junior in high school, and I have a daughter who's a 7th grader. And it's really, what am I doing to stay around for them?

I've been very fortunate, very lucky. Um, you know, there's hardly any other way to say it. I've been able to, you know, keep riding the bike. You asked me how many miles I've ridden, right? As far as since I was diagnosed 37 months ago, have just about 17,000 miles on the bike.

Yeah, I've been able to race. I've raced 5 times now. I did a time trial in my age category. I took 2 months, or rather 2 weeks rather, off of chemo back in March and placed 7th out of 17 in my age group. So to know that I'm getting hit with that much chemo and I've had radiation now and still be able to work still be able to function, still be able to teach.

You know, that's where I thrive off of this. You know, just not that much stresses me out anymore. It's just not worth it. So that's probably the biggest lesson that any of us can learn, is that at the end of the day, you know, it can be stressful, but how much you have to absorb the stress doesn't have to be there. So would you say that, you know, in the last 3 years since you got the diagnosis, that the, the fundamental change for you has been kind of a percept— a perspective shift.

Is that— oh, is that the biggest change? Tremendously, yes. Yeah. Um, any, any thoughts for how other folks can try and get that kind of a perspective shift without having a diagnosis of cancer? So yeah, yeah, that's one of those things that's part of the club that you never want to join, right?

So that's definitely not a good thing. Um, you know, a lot of it is just realizing that, you know, vendors who call and say, what keeps you up at night, as you just mentioned. Um, you know, if people are saying, hey, this is going down, you know, sometimes you just gotta let work go. You know, there's times that, you know, I look at Brian, my coworker, and I say, you're just looking exhausted right now, go home. You know, I already know he's going to work at home anyways, but it's like, go get a break, you know, take tomorrow off type of thing.

It's not worth stressing, you know, where you can Think of it as we're all running a marathon. You can't run a marathon as a sprint, but so much of us are. And that's— when I was in California at UCSF, that's what I was doing. I was just constantly, you know, work, work, work, work, work. You know, I was— and it wasn't work, it was trying to exercise a little bit, and it was spend time with the family.

But there's a point where you just can't. So you have to learn enough— when there is downtime, take advantage of it. You know, just go ahead and find something. If you don't have a hobby, find one. You know, do what you enjoy.

And it may be security. Security is one of my hobbies. You know, I like to say it's the hobby that pays. But find something else that can take you away. You know, maybe it's reading a good novel.

Maybe it's, you know, in my case, exercise. You know, maybe it's taking— going and taking the kids out back and hitting the ball with them. You know, playing some catch. Whatever you can do, you know, it's finding something that you have is that outlet. Because at the end of the day, you're going to look back and on your tombstone, it's not going to say he was the best security guy he could try to be, right?

You know, it's always going to say trying to be the best husband, the best father, the best son that you can be. From my diagnosis, I have an 8% chance of living past 5 years by the numbers. That means 92 other people have to die for me to live past 5 years. And if you— I mentioned I'm month 37 now. Yeah.

So I have to look and say, what am I going to do with the next 24 months to make an impact? You know, I'm not slowing down with teaching, you know, still doing that, uh, doing some curriculum redevelopment for Regis. And so what can I do to give back to the community itself when you're looking at how much time is there? Now those numbers, of course, they don't define me, right? They don't find any of us unless we let them.

And so if I go ahead and lose, so be it. You know, I was talking to a friend who played football in college, and he's kind of asking, you know, my thought on this tonight. I said, coach never taught me to lose, which is basically— think about when you were playing sports as a kid, or if you have kids in sports. The coach never says, hey, you know, Rob, you got a 33% chance of losing today. Go team, go get clobbered, right?

You know, it's always talk you up, try to do it. And it was very sobering a year ago that the nurse who checked me in taught me initially about what chemo was, because you go through a class of it. She and I were having a very frank conversation, and I was saying, hey, here's how I'm doing on the bike, and here's— I'm still working. And she paused for me for a minute and said, honestly, I didn't expect you to be around right now. So even though she had— she ended up retiring, so with 30-plus years of experience, she didn't think I'd be around.

And so that was kind of very— a somber moment. Sobering statement, isn't it? It was. To think about that. That was part of what made me realize stress isn't worth it.

We're always going to have something with security. We're trying to plug up the 20,000 different holes in the system. The bad guys only need to come through one. How do I prioritize? Can I do all 20,000 at once?

We all know that's impossible. It's really looking at where's the risk behind it, and then where can I go ahead and attack first, second, third, but not try to take on the 100th, the 1,000th hole right away. Yeah, the— I'll say, and obviously as we're talking about it now, your, your approach is amazing, and it's something, you know, you should be very proud of how you're— how you've handled this. But, you know, for the last few years we've talked about this, you know, a dozen times or whatever, and, um, just while widely in the community it's— you're well respected for how, um, just I'd say how straightforward you are about about your diagnosis and the work you're doing and how it has only been a positive thing to see the way you've reacted. I'm sure you must have some really tough days.

I know radiation and chemo do that, but you've been extraordinarily resilient through that. I think you're well aware there's nothing wrong with having tough days, but the ability to bounce back from that. And come back. It's been, it's been something worth, uh, worth admiring. But that's part of it too, is realizing a lot of people have it worse than I do, not just with cancer but other diseases.

Sure. You know, ones that we're, you know, talking about, like Pat Bowlen's in the news a lot and his wife having Alzheimer's. You know, to me that would be so much worse. You know, here I have a fighting chance. You know, right now they don't have the cures.

And so what do you do? And, you know, that's where I find a lot of inspiration is that every time I go in for chemo, and right now as of about 3 months ago they switched me over to an oral version of chemo, but every week I was going in for, they would stick a needle in my chest and I'd get pumped with chemo. I'd go in for 50 hours, they'd come off. The next week I'd go for an hour and just keep repeating that cycle. We've now been through 75 rounds of chemo.

I look at that and go, people have it worse than I do. With those 50 rounds of chemo, you I feel awful. But as part of the security mindset with that, I started trying to figure out how can I hack my own body. You know, when I first started going back and started riding, my oncologist said, hey, be careful, you're on chemo. And I was like, okay, what does that mean?

You know, it's, it's, you don't crash basically, and you're going to be more exhausted. And then after a couple months of him hearing how I was doing and seeing my numbers, he's like, whatever you're doing, keep it up. Yeah. And what I started figuring out is after chemo, I'd get on my indoor bike. So I'd go through chemo from Monday to Wednesday, get on my indoor bike on Thursday, and I'd ride for about 40 minutes.

And it was hellacious. It was not fun whatsoever. But I started figuring out that my body would then start recovering quicker. Once the chemo is in the body, having it hang around in the system doesn't help the body, only keeps tearing it down. So the sooner you can recover, the stronger you good.

So I would go ahead and be able to ride the bike, and then all of a sudden the adrenaline, the endorphins would kick in, and you'd feel better. And then the next day I'd do an hour, and by the time I hit the weekends, I would do a lot more. And it was just— it's learning what the body could and couldn't do. And so on my 50th round of chemo, my oncologist, the main oncology nurse I had, said, hey, why don't you ride your bike into the, into the chemo, to get chemo. And for those that, you know, if you know where Longmont is and I go to Midtown Rocky Mountain Cancer Center, which is over between downtown Denver and City Park, that's about 42 miles each way.

And so I said, you know what, for round 50, let's do 50 miles. So I, according to them, am the first person who ever rode their bike into chemo, but that's hacking that body. So how'd you get back? My wife. After chemo, I know, It was a hot day.

It was in July, so I was like, no, I'm not going to go ahead and ride back. Seems like the right choice. Yeah. Oh, it was definitely it for that day. It inspired other people in the oncology office as well, other patients.

They came up to me afterwards and said, hey, I need to get back on my bike. That's that hacker mindset, that security mindset that a lot of us have is, hey, we can do something that it's been designed to do, but let's do something different with it. It's not taking no as an answer. Taking it to the point of my oncologist was basically— I told him one time what the mileage I was doing, and he's like, that's low for you, isn't it? So we'd done that full pendulum swing.

It's very much— it's doing what we do every day with security. It's taking it to that next level. That's great. I mean, it's such an inspirational story. I thank you for sharing it.

You know, we're getting close on time here. I want to give you the chance— is there, is there anything that I haven't asked you about that you'd like to to talk about a little bit? So other things I've done to, you know, give back to community, and it's more of trying to get other people to do it. So, you know, it's— so I'm also part of the CompTIA Cybersecurity Board, and so their advisory board. And so, you know, if you want to blame me for the Security+, the Cybersecurity Analyst, now coming up the PenTest+ and the CASP, you know, the CASP certification, you know, those are stuff that we talk about.

It's get out there, have every other person get out there, start volunteering, start in the community. You've done a great job. We were talking before the podcast started about I started with ISSA Denver in 2005 and how that's changed so much for the good and how much you and Alex have changed it from being a very vendor-centric environment to being very much security-focused, very much of an secured team member. Yeah, community. It's a community thing.

I do want to give a shout out to James Johnson, who's now running the chapter and continuing on with keeping the vendors out of the talks. And the other thing is, because, you know, like we had talked about me working at Regis, for everyone else, get involved with that. Whether you go volunteer and talk at a class or you go ahead and teach, you know, if you want to do that, give back to the community because you never know what you get out of it. When I went to UCSF, I was told I'd never be able to hire a team out in the Bay Area. And a couple of the people I brought in up from Colorado, you know, people I— another guy I had met.

No more taking Colorado people out of the state. We need to keep them here. Yes, but in a way, it's my own farm team. Yeah. So I very much get to pick and choose because I've been able to watch people as they progress.

Yeah. And that's It's great. As a security leader, you're able to go ahead and give back and get back as well. Yeah, it's awesome. This has been awesome, Rob.

I'm looking forward to seeing what amazing things you do in the next couple of years. We'll keep in touch, and hopefully we can get you on the show again soon. Great. Thanks very much. All right.

Thanks a lot. Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes