Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 125 for the week of July 22nd, 2019. Alex, where have you been for the last couple weeks?
I've been MIA, Robb. I decided to leave the country, get out of here. You know, I was I was, I was being chased. I had to, you know, lay low for a little bit, but, uh, but I'm back now. Yeah.
Considering your profile with the law enforcement, I think that was probably a good call. Yeah. You know, uh, things happen. It had a good time while I was gone. Yeah.
Uh, glad to be back. Well, we did take off a week, which, you know, pretty infrequent that we do that. Uh, I also was on vacation for a little bit of the time, but you, you were the, uh, the champion vacationer of the two of us. Uh, congratulations. Welcome back to the United States.
Thanks. And Robb, while I was gone, you also competed in a triathlon. I did. I did, and I completed it, which was that was success for me. So you know, got to check that off the the bucket list of things to do.
Cool. All right. Well, let's jump into the housekeeping stuff. We have a Slack channel, and you know, da da da da. While we were gone, the Slack channel topped a thousand members.
So if we leave again, will we get to two thousand? Is that how it works? I I suspect that's got to be how it works. Well, let's go. Let's go.
Let's let's do that. So if you want to join the Slack channel and one thousand four of our closest friends in the community here, you can go out to Colorado. Colorado-security.com and click on the Slack link there, and that'll get you in. Also on the website, we have a mailing list if you want to get notified of our show notes. You can sign up at the bottom of that at colorado-security.com, get the email every week in your inbox with all of the show notes.
And if you like us and you want to support us, we would appreciate it if you would rate us on your favorite podcast listening app, maybe even subscribe so it gets delivered directly into your phone each week. We'd also love it if you told some other people about us. Tell them about the podcast and the website, everything that we do. Let them know how great the security community in Colorado is and where they can find info at colorado-security.com. And I'm sure there's at least one of you listening going, well, yeah, I've done all that, but I just want to do more.
I wish there was more I could do. Well, the answer is there is more you can do. We would love it if you would be willing to support us financially. The show is all All about going back to the community. Alex and I have done a lot of this out of pocket.
The Patreon campaign we set up does help defray the cost of this, and if you're willing to contribute back, we'd love that. You can join the Patreon also on the front of colorado-security.com. Cool. Uh, one more announcement before we jump into the news. Uh, the CTA's Apex Awards have their nominations open now until August 2nd.
So if you haven't nominated anyone yet, please go do that. There are tons of awards, including CISO of the Year. Uh, CIO of the Year, Project of the Year, Company of the Year, uh, lots of different stuff out there. So go check out, uh, CTA and the Apex Awards, nominate the best folks in the area for those awards. There's also a Student of the Year, right?
Yeah, there's something like that. So yeah, there's Educator of the Year, I think. There's definitely Educator, but then there was for young folks too. Yeah. Um, so yeah, you'll only hear about this for, I think, one more week.
So, uh, you know, this is your second to last chance to to get this done. Let's go ahead and jump over into the news. While you were gone, another piece of news, Alex. The Bureau of Land Management has chosen Colorado to be the headquarters for their department going forward. Yeah, I think that that is pretty cool.
You know, this has been a rumor for a while. There was a— I don't know if you even want to call it a search, but there was a number of places that they talked about moving the headquarters to, and Colorado was one of them, and it's going to be in Grand Junction. Yeah, so it looks like, you know, not a huge number of jobs. I've actually seen a couple different things. This article we have says 27 jobs going to Grand Junction.
I've heard numbers up to like 80 jobs going to Grand Junction. Regardless of what the exact number is, it's really important because it will be the director of the BLM. The senior-most people in the organization will be there. So we expect quite a bit of kind of supplemental, you know, additional jobs that would come out to the area in addition to those direct jobs. Yeah, that's what I would think also.
Additionally, there's going to be 54 jobs that are going to move to the federal center in Lakewood that are related to the BLM. But yeah, I think as you said, Robb, even if it is just 27 they're relocating to begin with, I would imagine that there's going to be organic growth and, you know, people will get hired there along with those 27. Well, you know, in a kind of a normal piece of news for the political climate we're in, there was a big political dustup here in Colorado while you were gone as well. You know, I did hear about it from a number of folks while I was on vacation. Big, big news.
There's been a war brewing between Colorado and New Mexico over chilies. Yeah. So, so apparently Whole Foods has, has started to put the Colorado Pueblo chilies into their stores. And Governor Polis had a little shot across the bow at New Mexico from that, right? Yeah, because of course everything in Colorado is better.
So clearly the, the Pueblo chilies are better than the Hatch chilies from New Mexico. And, you know, Governor Polis was just stating the truth. The, the governor from New Mexico, of course, thinks that their chilies are better. So if you want to go vote with your feet, go buy some Pueblo chilies from Whole Foods. If you don't like them, that's fine to throw them away.
But at least we can win the, win the war in the store. Next, Uber added a new feature to their app recently in Denver that allows you to buy RTD tickets through the Uber app and you can plan your essential, essentially your whole trip through Uber. So this was surprising to me, number one, I had no idea this happened. Number 2, Denver is the only city where this kind of feature is released. And number 3, for me, I didn't know that you could actually buy RTD tickets on an app on your phone anyway.
So I was like, oh, I'm going to have to get the— I'm going to have to use the Uber app. And then I found out there's an RTD app. There is an RTD app. So this is even better because, you know, I'll get to the train like, you know, a minute before it leaves and I'm like, oh, am I going to— am I going to get my ticket in time? And now I don't have to stress about that.
Yeah. Now you can actually get on the train and hopefully buy your ticket before the the conductor comes through to check your ticket. Uh, so that's pretty cool. Um, also in the article they talked about how, um, usage of the, uh, the RTD tickets through the Uber app had actually increased, uh, some of the ridership on RTD. So I think that's pretty cool too.
Um, so if you're looking into Uber and you're trying to figure out how to use this new feature, you, you can't buy the ticket until after you've like planned your trip. So you gotta say where you're trying to go, and then once you say where you're trying to go, then it'll give you that option for getting those tickets. Oh, interesting. So I tried it out after looking at the articles. All right.
All right. So this was— this is super interesting to me. There is a Colorado company that has designed a brand new kind of airplane seat. So this company here, I'm looking it up right now. Molon— it's Molon Lab Seating.
They've designed new seats that actually don't take up any more space in an airplane, but they give significantly more space for the people sitting in them. Yeah, it is pretty cool. And as somebody that just spent about 17 hours on planes in the last 24 hours, having more space in the seat is a good thing. So the way that they did this is the— for the middle seats, they, I believe, moved it back slightly, moved it back and down, right? Or is it up?
I think down. I don't know, whichever. But so basically, it's, it's setting you off of the, the same plane as the 2 people sitting next to you. So you've got a little bit more room for your shoulders. And they also had some innovative armrests so that you can— the middle person has a place for their arms and then the, the people next to them have place for their arms.
Yeah. So by moving you backwards and down, they're able to get your, your shoulders get a little bit more space because your shoulders aren't touching the shoulders of the person next to you. And that armrest, you know, you're the person in the middle has the back part of the armrest, which is a few inches lower. And then the person on the sides has the front half of it. And it's pretty obvious when you look at it, like that's where your arm would go.
It really does look like a pretty nice innovation. And of course, we're all wondering, is anyone going to ever use these things? Well, they're also cheaper from what they're saying to install. So there probably will be some airplanes that are interested in doing this. Seems like a pretty cool innovation to me.
Next, this past week was Tube to Work Day in Boulder. This is an annual tradition that they do in Boulder. And LogRhythm has been a sponsor of Tube to Work Day for the last 8 years. And they have around 100 employees that float down the river to their— to work. So from, from what I hear, it's a really cool experience.
You know, you get to the community experience, right? Lots of different businesses in Boulder getting together. Unfortunately, from my questions, you don't actually get to the Boulder HQ by doing this. So, so basically here, you know, you go drive up the river, you park somewhere, you go tube down, and then someone has to go get your car or, you know, pick you up and drive you back to your car. And then you drive to the office.
Robb, details, details. But it sounds like a lot of fun anyway. Alex just spilled coffee. This is the first time in the history of the podcast that we've had a coffee down in the middle of the recording. Ah, no problem though.
I'm— I only have minor burns. No big deal. A true professional. I will continue. Next, we have a story here from Enzoic.
They're the ones who had previously called PasswordPing. They have announced a new release of their password checking software that integrates directly with Active Directory. Yeah, so the plugin sounds pretty cool. It does automated checking of your passwords, keeping you in compliance with the new NIST 863B guidelines for making sure that you don't have passwords that are compromised. And it seemed interesting in that this— it seems to be an ongoing check.
I'm a little bit curious about how that they do that ongoing check. But so that's, I think, why they're integrated with Active Directory directly. So that they can see it before it turns into the hash, or before it gets— hash gets salted at the very least. Yeah, I mean, the way that I was reading it in the article, it sounded like they can even check later on after you've already set that password. If, say, your password becomes compromised later, if there's another breach, it can come back and tell you.
I assumed it was during authentication time, so if it's actually happening, you know, just at rest in there, then they'd have to— that'd be weird, right? Yeah, so that part did seem a little weird. The, um, The idea that they're getting to is definitely pretty cool. Um, maybe we'll have to dig into some details with, uh, how it is that they actually accomplish that. But anyway, cool plugin.
Yeah. Uh, CyberGRX has announced a new, uh, part of their third-party risk management platform. They call it AIR or the Auto-Inherent Risk Insights. Um, what do you know about AIR? Yeah, so this sounds like a, a little bit of a triage feature that you can do.
So CyberGRX is the platform for third-party risk management. Um, you know, they host the, uh, the reviews of the different vendors that you might be using to determine what their risk might be. Um, and this AIR feature seems like sort of a triage function. So you can answer a few questions at the beginning, uh, figure out which vendors are most important to you to actually do the reviews on, and also have sort of an immediate inherent risk score, uh, that you can use prior to doing a full review of that vendor. So pretty cool.
Next, LogRhythm launched a London-based data center for their cloud AI product. So this is just an expansion of what they currently have to serve their EMEA clients better. They note that they have a number of clients there, and having this EMEA data center is going to provide a much better service for that cloud AI infrastructure. They are in Google Compute, so they're not doing their own data center. They're using Google, which is— makes sense.
I didn't know that they were a Google company. I would have I would guess AWS. Interesting to know. Um, good growth for them. Obviously they've been talking a lot about new services on— rather than just their software, and this looks like a step along, you know, moving that to a more global, wider distributed model.
So good for them. And sorry, go ahead. And then finally, uh, we have a blog from InteliSecure talking about future-proofing your information security strategy. Um, yeah, we're a fan of— we're a fan of InteliSecure. They've been working hard on, uh, really innovating around the DLP and what do they call it?
What's their CAP, Critical Asset Protection Program, right? So this is really talking about how those 2 things change in the new world in a decentralized cloud-first model. So if you're looking for those types of things, open up InteliSecure's blog post here. Cool. So that is it for the news.
Let's jump over to the Slack message of the week. And Robb, I'm going to pass it back to you since I've been on vacation for 2 weeks. I took a break from Slack too. I didn't check Slack for So for 2 weeks you've been a slacker. I have been a Slack slacker.
Yeah. So Andre Gaeta, thank you very much for sponsoring this giveaway every week. We definitely appreciate it and you're helpful encouraging the community on this. This week we're going to recognize Evan Vale. Evan, congratulations.
You are the 1,000th member of the Slack community. You joined while both Alex and I were out of town, so we didn't get to give you a thank you in person at that moment. But now you win the Slack message of the week. That— it's an awesome start. Awesome start.
So you're going to get one of the items from the Colorado Equal Security store delivered directly to your door, uh, courtesy of Andre Gaeta. Thanks a lot, guys. Awesome. So let's jump over to events. Uh, we've got some good events coming up here in the next couple weeks, uh, starting with, uh, the Open Group is having their Open Group Denver event on the 22nd to the 25th.
Uh, The Open Group is— it's a standards organization. They're also the ones that, that have the FAIR standard, the Factor Analysis of Information Risk standard. And so that's going to be part of that event. Awesome. On the 23rd, Denver IAM Group is doing their summer user group.
Also on the 23rd, CSA is doing their July chapter meeting. The 24th is a popular day. It starts off with ACIS doing their top golf event. Ooh, ISC² Pikes Peak is doing their July chapter meeting on the 24th. And also 24th, SecureSet is doing a diversity and cybersecurity expert panel.
On the 31st, we are having the Denver Cybersecurity Conference from FutureCon. FutureCon. This is one of those vendor conferences. They are, I think it's downtown at the Ritz. Um, good opportunity to meet some folks.
Not super great content. Is there, is that slander? Can I get in trouble for saying that? I, you know, it's, it's an opinion. It's an opinion.
Yeah. So anyway, we've been to those in the past. A good way to meet some folks in town at least. Also on the 31st in Colorado Springs, AWS DoD Immersion Day. So if you want to learn more about AWS and their DoD offerings, there you go.
And on the 1st of August, the NCC is doing one of their meet and greets. So if you want to know about the National Cybersecurity Center down in Colorado Springs, that might be your chance. Sweet. So zip over to jobs. There's a couple jobs at Ping that are available.
I have a manager of product security position open, at least for now, and we're also hiring a GRC analyst. So if you want— if you're more experienced and you want to be in the product security area as a leader, that's an opportunity for you. And if you're just looking to get into security, GRC might be the fit for you. We'd love to talk to you about that GRC role. Awesome.
Nelnet is also looking for a deputy chief security officer. And they're, they're also hiring a cybersecurity enterprise architect. So a couple of leadership roles over there at Nelnet. Yeah, pretty cool. Deloitte is looking for an IT security policies and exceptions management manager.
TaxJar is hiring a security analyst and administrator. Ooh. State of Colorado is looking for a program manager for cybersecurity. Trustwave is hiring a security analyst focused on, I don't know if SOC, I assume that that means security operations center. That's what it probably is.
Yes. Arapahoe County is looking for a Homeland Security Planning Exercise and Cybersecurity Support Analyst. Wow. Gets the longest title of the week award. Congratulations to Arapahoe County, my home county.
Metro State is hiring a cybersecurity lecturer. Zavello is looking for head of cybersecurity product strategy. The Department of Energy is hiring a chief information officer, a CIO for the Department of Energy here in Denver. Wow. That is pretty cool.
I know. Uh, nice. And that is it for the jobs. Uh, so we're going to go over to our feature interview for the week. Who did we interview this week, Alex?
Uh, we actually interviewed Beck Larson from Coalfire. Yeah. Um, so I interviewed Beck before going on vacation. Um, and I actually wanted to make a quick note. Um, we had forgotten to discuss something before I, uh, I finished the interview.
And so she sent me a note after. Um, she wanted us to mention that she is looking for ladies in cybersecurity space to join her at Black Hat in Las Vegas and Austin. To help draft a formal annual women in cybersecurity event sponsored by Coalfire. So if you are a woman or know a woman that is interested in joining that conversation, please reach out to her at beck.larson@coalfire.com.
And just to clarify, that's Black Hat in August. That is Black Hat in August. In Las Vegas. Yes. Did I— You said in Austin, which is cute because we haven't mentioned Austin the whole episode.
Las Vegas and Austin, you know. All right. Well, this is your first week back, so we'll cut you a little bit of slack. Uh, it is like, uh, 3:30 in the morning right now in the time zone I'm accustomed to. So, all right, we'll go ahead and close out here and we'll talk to you guys again next week.
All right. Thanks, Robb. This is Tim Coogan, Chief Information Security Officer of Denver International Airport. Welcome to Colorado Equals Security for Colorado security professionals by Colorado Security Plus.
Welcome to Colorado Equal Security. This is Alex Wood, and this is our feature interview. Today I have a very special guest, Beck Larson. Hi. Hi, Beck.
How's it going? It's going. How are you? I'm doing well. Good.
We just passed a big holiday weekend. Did you do anything fun? Well, I took my rambunctious 2 and 3-year-olds to one of their little friend's birthday parties and Nice. Let them run amok for a few hours. So that was fun.
It's chaos, but it's fun. It's managed chaos. Um, you know, I always liked those things because it's, uh, with that managed chaos, you know, going to a birthday party, it's like there's other people around to wrangle the kids. Totally. So like you at least get a couple minutes to like, OK, go off and play with these other kids over there.
Don't get into too much trouble, and I'll relax for a minute. Totally. Or like their father will say, hey, hey, do you have the little one? Yes, I've got the little one. The big one's over there.
Yeah, it's definitely a community effort. Yeah, that's always good. Yeah. So for those that don't know you, Beck, who are you? Well, I'm Beck Larson.
Professionally, I am the director of the Coalfire One scanning services team at Coalfire. Okay. And I've been there for almost exactly 5 years. It'll be 5 years in August. Nice.
I'm pretty excited for it because I get a sabbatical and I haven't had a vacation literally in 4 years, so I am really looking forward to figuring out what I'm going to do with my time off. I have no idea. Let's see, so I've been running their scans platform, owning that part of the business for, since, well, since I was hired. It's heavily invested in the PCI ASV space, so a lot of compliance. 90% of our clients are scanning with us due to compliance requirements.
I'd like to subtle brag and say we're probably one of the best ASVs on the market. We actually do have a couple of differentiators that set us apart from the rest of the ASV crowd. And one of them is our people and the services that we provide through my team. Generally, when you sign up for ASV scans, it's pretty much a point-and-shoot thing and the client has to do all the work themselves. There's really no proactive reach out from the company that they sign up with.
Our team is completely the opposite of that. We actually are the only ASV, to my knowledge, these days that offer full-service scans. So yeah, so a client can come to us and say, we have like 3 people that we can dedicate maybe 20% of their time every month to getting scanning done, and we don't know what we're doing. We don't understand PCI. Can you help?
And we say, yes, we can, dear sir or madam. Let us do everything for you as long as it's cleared by the guidelines that the PCI Council puts forth. The only things we can't do are their own remediation. We can't get into their networks, of course, and we cannot gather dispute evidence. But other than that, we can do everything else for them.
We pretty much handhold through the whole process. So cool. Yeah. So I really love my team. I have 5 people that report up to me, and we are a remote group, but we're really close-knit.
And I also like to subtle brag about them all the time. It's not even subtle. I really like my team. We're all unique, unique, unique individuals, but we all get along really well. So it makes work a lot more fun that way.
And then CoolFire as a whole, you guys know what we do. We've been on the show before, not me specifically, but certain other people within the labs group and just across the board have been on or at least been mentioned a few times. You guys seem to put out a lot of blog posts lately, which is good. Yeah. Keeps us going in the news.
Yeah, definitely. Well, scans especially, right? We just dropped our new released, I should say, our new scanning platform. Super excited about that. It needed a facelift and a backend lift, I guess you would say.
We have a completely new, robust, redundant database, and on the frontend, it's a lot more intuitive and easier to use. So yeah, we're still putting simplicity first, but in regards to Scaling and capacity and being able to take on 100,000 endpoints at a single scan, we can do that now, and it's a beautiful thing. Cool. Yeah. So clearly you are an expert at scanning.
Oh yes. But I'd imagine you haven't been doing scanning your whole career. So how did you start in security? Wow. Well, I've been in security for a little bit more than a dozen years.
Well, it depends on how you define security too, and IT and all that. I have been doing scanning for a long, long time though, but I'll, I'll give you the 3-minute synopsis of college to now. So let's see, the last 20 years. I went to Metro down in Denver when it was still a state school and not a quote-unquote university. Go Roadrunners!
Yeah, yeah, and super old school back then, but they have one of the best aviation programs in the nation, so I really wanted to be a pilot. Nice. Went for 3 years. September 11th happened my senior year. Got my private license and really wanted to, yeah, to recognize that, but the industry didn't seem to take off after that.
No pun intended. So, so I switched majors, believe it or not, to anthropology, and I graduated another 3 years later with a major in anthro, and I double minored in private piloting and elementary ed. So then I became a 5th grade teacher for 5 years. That was fun. I really liked it.
The The kids were great. I love 10-year-olds. They've got a certain snark to them that I vibe with really well. Farts are never not gonna be funny. And then it's just the— I got burned out from that too.
And just, it's the same state as it is today. Our education system has a lot of flaws and it's kind of a mess. I mean, I'm not being too negative, I hope, with it. But it just wasn't for me. I got real tired of trying to fix things not seeing anything stick.
Well, but you know, the, the money that they paid you probably made it all worthwhile, right? Oh my, well, I was having to budget Taco Bell twice a month, so yes. No, I'm joking. No, super sarcastic there. No, I was even— I was about 6 months out from tenure, and I just— I was— it was a real struggle to make ends meet too.
So from there, I still wanted— I've always had a drive to more of a blue team heart versus a red team heart. I always want to protect things, make the world better. Better place, try to fix things. I take on too much constantly, but it's just my nature. After that, I went to a company that primarily dealt in like OSHA security.
So I would go on-site to buildings and do like building inspections and make sure there's a water spigot every 10 feet on the ceiling, or go do a kitchen inspection and write up a report on-site and say, hey, you need to do this, this, this. My territory was downtown Denver. I've been inside almost every single building in Denver, including the morgue, which was interesting every month. And then like high-powered law firms, oil firms. It's— it was pretty cool.
That also though gets on you after a while, and it was constantly on the road, constantly traveling. So I did a heart and soul check, and I said, okay, what do I like? What do I like to do? I like tech. I like math.
I like sciences. Let's get back to that. And a good friend of mine helped me get on at a What was it? It was a cable company that pulled out. Time Warner.
Time Warner Cable. They pulled out a while ago from the Denver market. I started off on the phones helping Grandma and Grandpa reset their router, and I actually really liked it. I like talking to people, believe it or not. And I was just about to be promoted to supervisor, and then they pulled out of the market and my entire building was laid off.
I mean, everyone from the janitor to the CEO was gone in 30 days. Yeah, from there I went on to work for— I got lucky again, and/or skilled, whatever. I'll say luck had at least a part, you know, partial play, role to play in landing my SOC/NOC job at Lehman Brothers during the housing collapse, which was fun. Saw a lot of interesting things, got a lot of exposure to official security and monitoring networks. That's how I met Robb, actually, so shout out to Robb Reck.
That was a fun job. I mean, I'm saying it in air quotes, but I'm also smiling about it. I know you guys can't see me, but it wasn't bad. From there, I went to First Data and got involved with the financial aspect of cybersecurity. Was on a development and release team.
Got to review code, got to write code, and everything from QA all the way up through the cycles to prod. And then, like, a super secret Squirrel Society cyber role opened up, and I'm like, you know what, I'm just gonna go for it. So I did. I went out and got my Security+. I applied for the job, and it was to manage all of First Data's internal scans, and I got hired.
And so the saga began. And the saga began, yep. And then I started having to badge in through, you know, double doors and got to sit with all the pen testers. And I don't know, all these— it was just fun. Like, it was— it's still fun, you know.
So, and then I did that for a few years, and then Coalfire found me through LinkedIn and said, hey, are you looking for a gig? And I'm like, actually, yeah, because First Data, they go through a lot of rounds of layoffs. I'd survived every one, but man, it's a heart stop every time. So then I've been at Coalfire and I've been pretty content ever since. Nice.
Yeah. So, so, so it sounds like a good bit of your career has been scanning. Yes, lots of scans. For people that are running scanning programs themselves, what are some things that you can recommend? Best practices, gotchas, things that they should do, things that they shouldn't do?
Yeah, yeah, I was actually just going to start with just best practices and just knowing what you're scanning and using the tool that you're using to the best of its ability. So if you're using a web app scanner to maybe just scan, you know, a host of some sort, it's not— if the tool isn't designed to scan target that's intended. It's not going to give you the results you're looking for. And also just know what you've got in your network. Understand how it's routed.
Understand how it's connected. Understand where the traffic flows because you may scan something that may come back clean or whatever or manageable, I would say, in the, you know, the risk tolerance, but then it might be connected to something that's filthy and you just maybe overlooked scanning it because it's not in your scope. I think you mentioned how it's routed and things like that. That's important too, because I did security for an oil and gas company at one point, and to get to some assets, you'd have to hop over, you know, 2 or 3 different radio links, right? So you're talking about really, really low bandwidth links.
And if you ever try and do vulnerability scanning over those sorts of things, It does not work very well. You can easily take up all of the bandwidth on those links just doing the scanning, and you're probably not going to get the results that you're looking for. So understanding the path that it's going on too is always a good thing because you don't want to disrupt your network just to get the scans done. Right, and actually if it's a scan for PCI compliance, we're technically not allowed to do that. If we are seen as disruptive or if we, heaven forbid, knock over a server— now work-wise, I can say we never have, at least not in my tenure, not that I've heard in a client's environment, because we've tuned our scanners to not only agree with the compliance set forth by the council, but, you know, we're just cognizant of what we're doing.
I will say though, the ASV lab, which we just found out we passed for 2019, so we get to live and fight another day. Congratulations. Thank you. It's, it's a beast of a lab. I can let you know how that goes, or how— if you'd like to know the details of how it's, how it's run.
But yeah, within that lab, there's a specific lab that's set up with dirty hosts. Every single host on that network that they've set up in this fictitious environment is designed with failure as an intent. One of the hosts is super touchy to network traffic and speed of scan. So if you throw something at it that is intentionally, I wouldn't say as far as disruptive, but if it's like a hard-hitting scan and if it's got a lot of checks going on at the same time and if you don't narrow the bandwidth down, you'll knock it over. So it's one of those challenges every year that, you know, it's there in that lab.
And so the lab is set up by the PCI Council with standards for you that you have to pass to be able to be an ASV scanner? Is that how it works? So the ASV, the PCI SSC and their ASV division, I guess, for lack of a better terminology for them. They actually work with 2 outside assessment labs. The one we typically work with is usually in Canada.
They're wonderful people. They're sweet guys. We've been working with them. And they randomly get assigned, you know, but I remember them most because I think out of the 5 years I've done this, I've worked with them now 3 times. And the other one I believe is in either Nevada or California now.
But they host the lab themselves. They have all the machines up and running while you're in your 22-hour window. So yeah, you are expected to be on-site. Well, at least for our team, everybody comes on-site. My team, we do our testing within our certified ASP solution as we've had it defined and submitted to the council for approval.
And, and you scan and you analyze results and you scan some more. And because of the nature of some of the routing and some of the network, just weird idiosyncrasies within that environment, you do have to scale that scan back. So a scan that may normally take an hour on a healthy system, for an unhealthy system it might take 6 hours. But you want to be careful because you don't want to knock it over. You want to abide by the ruling.
And yeah, so it's fun. It's actually a lot of fun. We see different things every year and we get to identify some really cool stuff that we typically don't see in realistic environments or even genuine environments that we see in our clients every day. So it's, it's kind of a fresh breath of air every year as we take that test. So yeah, yeah.
And so you have to do that every year to be certified still? Yes. Yeah, yeah, that's part of those. So to be a certified ASV at a company level, you have to have 2 full-time at least ASV employees that are also certifiable. Side note, to be certified as an ASV, you have to have at least 5 years experience that are comprised of either having your CISA, CISSP, or CISSP, in addition to a year of pen testing, a year of scanning, a year of audit, and a year of network.
It's a lot. Yeah. So even finding the qualifications for the right person to even be able to do the job is sometimes a needle in a haystack. But then the company itself also has to run and pass that lab, and they have to abide by the— I think it's like a 50-page document that they put out saying this is how you do things and follow these rules. So nice.
Yeah, it's fun. I mean, it really is. It's compliance, you know. So everybody— you say that word and people get a little dry in the mouth. But I mean, it can be, but it's there for a reason.
It's there to make, you know, not to be cheesy again, but the world a better place. We need to have a baseline of standards to follow so that we can remain secure, or at least take best efforts at remaining secure. Do you see, uh, you know, for ASV in particular, I mean, that it has to happen on a regular basis, people know that it's coming, they know that they have to pass those scans, uh, to remain PCI compliant. Yeah. Do you guys, um, do you see people having problems?
Is this maintaining that? Yeah, the frequency. Yeah, so industry best practice is you scan every month, and/or after any major network change. So major network changes, as you know probably because you've got a more extensive background in history than— or history in security than I do— major network changes are expensive, so generally they're rare, right? I mean, so monthly is the best practice.
We advise our clients to scan at the beginning of the month if at all possible so that when your 90-day or 92-, 93-day period of that quarter starts, you're up on top of exactly what's going on in your network at that given moment in time because we update our scanners every week. There are zero-days released all the time. You know, there are new vulnerabilities identified all the time and new checks added to the engine all the time. So you will scan an environment, say, on Wednesday of last week, and then Wednesday of this week, it's gonna be— it might be a whole new animal. You never know.
So once you have that baseline scan, you identify what you need to fix. You fix those things. The ones that you can't, you either prove that the scanner was wrong with a false positive and say, no, it's actually Linux, but you said it was Windows, whatever. Or you have a compensating control in place to protect against that asset so that its risk doesn't, you know, spread to the rest of your environment. Yeah.
So, yeah, but people do. They struggle. They struggle in making sure that they run the scans not only regularly, But minimum is quarterly per ASV guidelines, but then also making sure that they have a pass. So making sure that they actually have a green pass, a green checkmark saying we've done our due diligence, we've made it as secure as we possibly can per this certified ASV. What my team does though is if we notice a company or a client or even just an individual, whoever's out there that's subscribed to us, if we notice that they have not had a passive scan for 2 quarters, we will reach out proactively regardless of whether or not you're a full-service client and we'll say, hey, do you need some help?
Is there anything going on here that we can help you with? And sometimes, sometimes, and it's happened where we'll reach out and they'll say, yeah, we have no idea what's going on with our environment. We've had a lot of turnover. We don't know what's going on. It's fallen through the cracks.
We need some help. We didn't know that you guys were actually scanning us. No one was actually getting the results. That happens. Yeah.
There just is so much chaos sometimes, and then we'll say, you know what, this is unfortunate for you, but we're here to help. And actually, we can extend services out to our SCaaS team or our CRA team, and they can— cyber engineering and other services, pen testing— they can come in and also assist the client with whatever they might need. Nice. Yeah, so one big happy. That's right.
Yeah, gotta have our one big happy scan result. Exactly, exactly. One big happy pen test all as well. Yeah, that too. Yeah, cool.
So scanning is obviously not the only thing that happens at Coalfire, right? Um, what else do you guys have going on? Well, I report up through the labs division, so I know labs best of all. So I can again subtle brag about what we're doing there. Sure.
A couple of the cool things we're doing, uh, within our research and development group— and I believe, um, didn't you speak with Bryce Berchall? We did. It's been a couple years ago now, but we talked to him. He put out a blog post a while back about you guys going through a process to pay a ransom for someone. Yeah, so that was a pretty cool article.
We talked to him about that back in the day. He is a super smart guy, super sweet, super fun to work with. He's the lead of our research and development group. And yeah, that was, that was a cool article. But basically right now we are That group is focusing on experimentation, and I mean, that includes anything from exploits to automation to tooling, other fun things that can go within that realm of development.
And our current initiative is focused on the Internet of Things. And it's, yeah, and so right now we've acquired a 3D printer that is internet-connected. We've found vulnerabilities on it, and there, I can't share too much about it, but let your mind wander with that. And then we've extracted them, we've reverse engineered the firmware, we've gotten the firmware back onto the platform through those vulnerabilities, and we are trying to set it on fire. Sweet.
Yeah. I wish you guys could see Alex's face right now. His eyes just kind of lit up and he has this smirk on his face. And that's what we do too. We watch this thing in action.
It's like, all right, this is neat. So by the end of this week though, we are trying to get the printer to set itself on fire, but we've been able to get it to melt itself, but no fire yet. So we're still cracking at the fire thing. And we're doing this as a proof of concept highlighting some of the dangers of internet-connected devices. So, and it's, you know, that's a big thing.
They're being developed quickly, and I'm sure you know development cycles. Development is about production and getting things out fast and fast doesn't typically relate itself to being secure. So yeah, it's pretty neat. So that's a fun thing that we're doing. Nice.
I wonder if— have you guys even just taken the simple steps of scanning those things to see how fragile they are? Oh yeah, that's generally the first thing that anyone does. And people should know, I'm hoping, what a scan is versus a pen test, but just real quick, my house analogy is if I were to stand on the sidewalk and take a snapshot of your house just with a camera, I would be able to see instantly, like, you've got your front door and you've got a window, and the easiest way inside is to take a brick and toss it through that window and I could get in. Now, if your window has bars on it, it's a little bit less easy. If your door's got a deadbolt lock, it's a little bit less easy.
What a pen test does is identifies those same vulnerabilities and then it exploits them, so they actually will throw the brick or they'll pick the lock and then they'll get in. So yeah, so generally a scan is— again, you've got to match the tool to what you want your output to be. You've got to match what you want to see, like in the report that comes from the scan, based on what your intentions are. But yeah. I've seen that things that are internet-connected but are not computers are generally pretty fragile when they come to automated poking.
Yes. So yeah, I'd imagine that those, those printers probably have a hard time and maybe just fall over just from things poking at it. I would, I would bet so. And if you, if you're lucky enough to get Bryce back on the program, I'm sure he'd be happy to disclose some of the, the information around that. I know that there are— we're going to do a public demo of this also, of this printer, in August.
So more to come on that. I'm not Is that part of Black Hat festivities? I believe so. I believe so. I think they are going to overlap.
I'm hoping so because that would be really cool to do. But yeah, we're going to Black Hat again this year, as we do every year. We've been there for, let's see, just, well, forever. And we're doing another Avant-Garde booth with a lockpicking demo and a challenge similar to last year but better and bigger this year. And then we're also holding our adaptive penetration testing course for our 8th year running.
So we've moved our entire platform to support the adaptive penetration testing course to the cloud. We used to have to haul around this giant server box, actually 2 server boxes, and make sure it would show up like in London or, you know, wherever, and then make sure it all was connected. But now we've got it moved to the cloud, and so it's a lot easier. Everybody's moving to the cloud anyway, so that's where our course is now living. And we're, let's see, featuring tools built by our R&D team as well as others and other things that are also popular in the industry right now like BloodHound, CME, and Empire.
And also one of the tools I want to throw out some recognition to Brad Woodward. He developed a password cracker called NPK.
Built on cloud platforms, and it helps manage the cost and scalability of cracking passwords. So yeah, it's pretty awesome. Brad's another one of those just insanely intelligent, wonderful people that we've hired. Fun to work with, great guy, and he makes really cool things. So yeah.
But I'll be there along with, I believe, 7 others. I'm a backup instructor for the pen testing class, and it'll be a lot of fun. Cool. Do you know, is there still availability for that class? I know that the training at Black Hat usually goes pretty fast.
Yeah, so word around the water cooler when I was in the office, I think a little over a week ago, was that it had sold out. However, I know that the current debate was let's add some more, you know, let's add some more chairs to it because I know it sold out in— I think it sold out in London last year too. Cool. So yeah. Yeah, it's a cool course.
It really is. Yeah. Yeah. So you were talking earlier about how you— your scanning service, you guys recently redid a lot of that. Yeah.
I wonder if you wanted to talk about that at all. It sounds like it is now much more robust than it used to be, and maybe the process you guys went through to get that done. So yeah, I mean, the scanning tool itself, it used to I mean, it worked. It was functional. Is this totally internally developed?
Totally, yeah. It's completely proprietary. In full disclosure, and everyone knows this if you've been keeping a pulse on Rapid7 and Colfer, we've been partners in the ASV scanning space for the last 3 years, and we've actually used Nexpose as our backbone scanning engine for years prior to that. So we have a pretty close business relationship. They're wonderful people to talk with talk with our folks over there pretty much weekly, almost a couple times a week.
But yeah, so we use that as our background. The scan tool, Pulsefire One platform, is a wraparound UI and it has a lot of the same features that Nexpose does, but again, with compliance in mind and simplicity in mind for pretty much our average user. They don't want to have a million ways to tune a template. They don't really want to dig through, you know, 100 different types of reporting. They come in and they say, I need my attestation of scan compliance, I need to scan these specific targets, find out these specific vulnerabilities, and go.
And that's what our tool allows us to do. It's a lot prettier, like I was saying, with this release, and it's a lot more intuitive. It does have more options, but it's not an overwhelming amount. And it's got a lot of really cool new features as well. There's dashboarding at play, there's a lot of widgets, there are reminders that you can set, you can tune specific templates and projects so that you can pick and choose your targets that have been scanned to add to your attestation.
And again, this is all within the bounds of the guidelines set forth by the council. But it's pretty neat. And if anyone listening wants a demo or wants to have their own trial account created, get in touch with Coalfire. Just go to coalfire.com. If you start search for scanning, you're going to find the ColdFire One Scanning Services team's page.
And right on that landing page, you'll be able to see all of our literature, all of our releases, all of the marketing material we've put out there, literature on our other proprietary device, the Lighthouse, so you can do internal scans. And then there's a sign-up box on the right-hand side. It's right above a little screenshot of the Enterprise Security Weekly interview that I was on with Mike Weber back in early April. Cool. So yeah, yeah, it's pretty neat.
So if you would like a trial account, just reach out to us, we can hook you up. Do you guys do more general scanning too, or is it only ASV scanning? So 90% of what we do is ASV, and so per the PCI guidelines, you have to do external scans through an ASV if you're required. Now it's also required that you do internal scans, but you don't necessarily have to do that with an ASV. You can do it yourself Generally though, if clients are in such a way where they're like, I just don't know what to do, let's just push a button, let's get it done, we can help them.
We can do all that for them, and then we can run their internal scans as well. And now we've also expanded our Lighthouse capabilities to the cloud as well. So if you've got an Azure or, you know, Amazon space, we can utilize that as well to scan your environment. Nice. Yeah, it's pretty cool.
We're expanding a lot. I also noticed last week or two you guys had a press release about partnering with Qualys, I think, on, uh, was for FedRAMP stuff. For FedRAMP stuff, yeah. Is that that they are FedRAMP certified and some other solutions you have are not? Is that the— Correct, yeah.
There's, there are some pretty stringent, and I won't say nitpicky, but I kind of mean nitpicky details when, um, let's say you're a client who needs FedRAMP sign-off, right? Yeah. We want to partner with someone that actually is quote-unquote certified instead of just, you know, like, hey, you are okay, you can use this FedRAMP template, but you're not an actual certified company. So, yes, we did partner with Qualys on that front for the FedRAMP certification and their toolset, but that's not to say that we have counted out anyone else in that same space. So, if Rapid7 someday decides to become FedRAMP certified, they'll also be added to the list.
Yeah, but that was a pretty cool thing that we pushed forward the other week. Nice. Yeah. Well, cool. We're getting close to the end of time.
Oh, sure. Is there anything that you wanted to talk about that we haven't talked about yet? Oh man, not that I can think of. We've, we've been chattering for a long time. No, not that I can think of.
Awesome. Well, it's been great talking to you. You too. I appreciate you reaching out and and volunteering to come on the show. Certainly.
And I know we're going to try and get a few other of the interesting Coalfire folks on as well. Definitely. Yeah. And that, that doesn't mean that you're not one of the interesting Coalfire folks. I included myself in that circle.
You're in the interesting group. Yeah. We'll leave the non-interesting people for some other time. Yeah, they're probably interesting too, just in a different way. That's right.
Everyone is interesting in their own way. Right, exactly. Good to say there. Say. Yeah, well, thanks, Beck.
Yeah, thanks. Good talking to you. I appreciate it. Thanks for coming down. And this has been Colorado Equals Security, and we will talk to you next time.
All right, thanks everybody. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.