Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 124 for the week of July 8th. And I guess, Alex, our country is now what, 200 and 30-something years old.
Yeah, something like that. You think I might be ready for this conversation, but since I brought it up, right? You know, you know, I was actually listening to an interesting podcast today that was talking about the actual origins of our country and, and how we were just a bunch of smugglers who didn't wanna pay taxes on our tea. Yeah. But not that we, they, we more just wanted to keep smuggling tea as opposed to actually being revolting against the, the government.
Anyway. Well, priorities, right? Priorities. 242, 243. We just turned 243.
You like how I got that rambling for you? Thank you. Do the math. And thank you for giving me that time that it was necessary. Hey, it's, it's good.
You know, you look like you've actually recovered pretty well from what I assume was a very heavy night of drinking. You know, it was— the drinking was not particularly heavy, but the fireworks were heavy. So I am a little hard of hearing still. What was that? What did you lose?
Your finger that's used for biometric authentication? No, my finger is still there. That was not the finger you use for that.
All right. You know, before we jump into the news, we have just a little bit of housekeeping to talk about. We have a Slack channel. This is a great opportunity for you to jump on and talk to other folks in the security community. If you want to join the Slack channel, go out to the front page of colorado-security.com and click on that Join Slack link, and you can see us there.
Also on that website, colorado-security.com, you can find our mailing list. Scroll all the way to the bottom, sign up, and you will get the show notes in your email. Be the first one to know when there is a new episode and everything about it. You know, we could record this part of the show and not even have to do this every week. You know, there are professional podcasts that are out there where you can tell, like, it skips a little bit and it's like, oh, I've heard this before.
But, you know, we do it new every week. But this way people can hear our mistakes and really the truth comes out as we do these, right? We would love it if you would rate and review us on your favorite podcast listening app, be that Google Play or iTunes or Spotify. While you're there, subscribe, make sure you're listening or you're having the show automatically downloaded to your podcast player. See, mistake.
And if you love us, we would love it if you'd tell a friend, talk to one of your coworkers, to one of the people who you met during the 4th of July, maybe whoever you're sitting next to in your current holding cell. Let them know about the podcast. We'd love to have some new listeners. And finally, if you're not in a holding cell and have a little extra cash, would like to support us financially, we would love for you to join our Patreon campaign and help defer the costs that we incur for doing the podcast. All right, let's jump into the news, Alex.
We're not burying the lead this week. We're starting off with the most exciting news of the week. Uh, Little Man Ice Cream is opening up a brand new store in, in Sloan's Lake. You know, Robb, I saw you put this story in the news this week and I thought, really? Uh, and then I read the article.
I was like, whoa, this is actually really awesome. This is like a 6,000 square foot facility with a tasting room and They have a conveyor belt that brings you food on it. They're going— they're actually 10 times their, their ability to make ice cream. Right. The capacity is going to be 10x what it was previous to this.
Not only that, there is a slide. So this sounds like a pretty cool place. It opened up this weekend. I assume you haven't brought the family there yet. I have not either.
I have not. I hope to go soon. I'm looking forward to it. I assume that the lines will be even worse than the other little man. But, you know, it is big.
It's 6 times as big. So 6 times the lines. So I guess wait until, you know, I don't know, give it a month and then go as soon as they open in the early afternoon, I assume. I say start lining up at 3 in the morning. You should get in, you know, promptly as they open.
Hey, Alex, was that phone number, that phone you just got, was that coming from your own area code and prefix? You know, that's strange, Robb. I think it was. I've seen, I've seen a lot of those. And it looks like our federal government is actually starting to do something about all these robocalls.
Yeah. Over the past couple of weeks, there was a crackdown that involved nearly 100 cases, 5 of which are being criminally enforced through the FTC, the Justice Department, Justice Department, and 15 states cracking down on those operations that are doing those illegal robocalls. And you're wondering, dear listeners, I'm sure you're wondering, why is Colorado Equal Security talking about this national issue? Well, because in the list of states that contributed to this, this campaign, Colorado is one. It is.
And Colorado is always number one. The— they also talked about some potential legislation that is happening at the federal level to make it easier to crack down on robocallers, partially by being able to find them more. This— it seems like this might actually be one of the pieces of legislation that could happen because literally every single person who's voting has a phone and is getting bothered by these calls. Everyone, every single one. All right, moving along.
Our next one is actually another kind of interesting Tech Colorado story. This one comes from, strangely enough, energynews.us, but specifically it's about a new data center that's going to be built in Pueblo. What's unique about this data center is it's being specifically made to do cryptocurrency mining, which is so hilarious to me because as an— as a world, we've decided that we want to create the need for people to do proof of of work that's so difficult that they're going to— that they're going to build whole data centers. Right. Just to show that they did the work.
Yeah, it is extremely silly. The point of the article is talking about how in Pueblo, it's actually Black Hills Energy that is providing the power down there. And they'd committed to a certain percentage of renewable energy. And if this new data center comes online, which has a large amount of power requirements, it's possible that they won't be able to meet that with renewable energy and thus won't be able to meet their goals. But I said, you know, that's not a problem.
This data center is going to go out of business five minutes after it opens because you know cryptocurrency isn't profitable anymore. I don't have you seen it. We're back on. We're back on the way up again. Get a buy, buy, buy.
I I predict a very short future for this operation. So I got a I got a note from one of my kind of distant family members asking me, Robb, what do you think about this new cryptocurrency that's being put out by X? Institution, I was thinking about investing in it. And I said, I said, you should invest in it if you would like to lose your money. I said, it's not investments, it's speculation.
And I have no idea if that will go up or down, which is basically what speculation is, right? Hopefully it was the cryptocurrency that's being started by Facebook, because right there, that's a double whammy. It was not Facebook, but that's another good one. All right, that is it for our area news. Let's get into some security news.
So Coalfire had a blog this week, uh, talking about preparing for PCI DSS 4.0. So I guess that the draft, uh, PCI 4.0 is actually out for comments right now, so you can take a look and see what you think. Kind of the exciting news for those of us in the IAM world, or those who just care about IAM, is that they are working to allow new compliance with the NIST 863B guidance that goes into, you know, not having to change your password and getting away from those highly complex passwords into, you know, kind of longer— Right, your standard 8 characters, it's got to be one of each thing, you got to change every 90 days, which I think is really, really exciting because pretty much the only thing that I hear about PCI anymore is people bitching about wanting to change their password policies but not being able to because PCI tells them that they have to have the old-style password. So I'm excited. I wish I had time to have read the draft standard, but if those of you listening, if you have some interesting feedback, send us a note.
We'd be happy to share your thoughts on the show in the future. Next story we have is from SecureSet. It's a blog where they're talking about what are the key soft skills you need in security. We do spend a lot of time talking about what are the technical skills, you know, getting your cloud security experience, getting your DevOps security, and they spend some time talking about what does the soft skills side of things look like. Yeah, so some of those are, uh, talking about communication and active listening, presentation skills, management skills, um, being able to solve problems well, uh, loyalty, humility.
I think humility is a really good soft skill. I'm really good at that. Yeah, you are the most, uh, humble person that I know. I really have been talking about it for quite a while. Um, but anyway, great list of soft skills in here.
Uh, so if you are someone that is, uh, you know, either in the job market or looking for skills to expand, those are good things to try and expand. I think self-awareness should be on that list too. Self-awareness. Yeah, it's a good one. Knowing what you're bad at, what you're good at, that you're socially awkward, and maybe just mention that right off the bat.
All right. Next, we have a story from E! Week. We actually have a really wide variety of sources for stories this week. You know why that is, Robb?
No. There was no news this week. We were scanning the web everywhere looking for news for you people. Everybody's on vacation. Yeah.
So this is an interesting story though. This is by eWeek comparing 2 of the most popular SIEMs out there. They were comparing Splunk versus our own local LogRhythm. Yeah. Uh, they, even though they call this a head-to-head article, it really is describing both SIEMs independently and talking about their strengths and weaknesses.
And then they also give a rating to both of them. Um, and it was fairly close, um, very close actually. LogRhythm scored a 4.7 out of 5 and Splunk got a 4.8. Well, we know the Splunk is way more expensive, so I assume that accounts for the extra point. That's right.
That's right. Is that how that works? Something like that. Next, there was an article from CyberGRX talking about the fact that they've been named to the 2019 Colorado Companies to Watch. Congratulations to them.
Obviously, a lot of buzz being generated. I've heard a lot of positive things in the last year. Alex, were there any other companies on that list that you think are noteworthy for our listeners? You know, my favorite company on the list. Was Laws Whiskey House.
Laws makes great whiskey, and I'm glad to see that they are a growing company. And it's smooth and slick. Now, we could get Laws to be a sponsor for us if we, if we give it a shot, right? I think we should, we should try that. Couldn't hurt.
Couldn't hurt. Couldn't hurt. All right, go ahead. So this was not a technology company list, but just growing Colorado company. Congratulations to CyberGRX for that.
And then finally, we want to remind you again that the APEX Awards nominations are up right now. And if you want to go nominate your favorite CISO of the Year, CEO of the Year, CIO of the Year, Project of the Year, it's open. The link's in the show notes. We'd love to have you out there. That would be great.
All right. Now let's move on to the Slack Message of the Week. Thanks again to Andre Gaeta, who sponsors the Slack Message of the Week. He does this out of his own pocket and provides up to $25 per week to someone who has a great Slack message. $25 for someone to pick an item from the Colorado Equal Security Store.
Very important part of that $25. Which is available to any of you, you know, using your own money on the front of colorado-security.com. This week we are going to recognize Daniel Ayala. He posted about the YouTube recently kind of controversial change they made where YouTube was blocking hacking demonstration videos kind of throughout their platform. Yeah, it seems like they're making some changes to, you know, in general what sort of content is allowed or not.
And hacking videos got caught up in that. There were some that, you know, we might call legitimate, you know, sort of learning videos that were taken down because of that, as opposed to actual demonstrations of what somebody might think of as hacking. Um, I had seen that today they actually started to walk that back a little bit, and, and I think some people were allowed back on the platform, uh, which is a good thing. Well, there was a lot of uproar in the Colorado Equal Security Slack channel about this. There was.
So I can only assume that, you know, that kind of backlash really made a difference for YouTube. I, I think that's probably what did it. Good job, loyal listeners. And thanks to Daniel. Of course, congratulations on your win.
Moving over to upcoming events. On July 9th and 10th, we have the ISSA July chapter meetings. That's going to be in Boulder on Tuesday for lunch, in downtown Denver Tuesday for dinner, and the DTC Wednesday for lunch. Also on the 10th, SecureSet is doing a Hacking 101 Intro to PowerShell. On the 12th, Colorado Springs is doing their 2nd Friday meetup.
It's going to be obviously usually the first Friday, but they had to push it back due to the of July. Um, Colorado Springs ISSA is doing their July chapter meetings on the 16th and 17th. DENSEC is doing their July meetup. That's going to be at Ryan House on the 17th. On the 17th as well, NCC is doing a meet and greet.
Um, the CTA is doing the Future of Work on the 17th. That's a busy day, that 17th. Yes, it is. Uh, on the 18th, the CTA is also doing a tech working the Future of Cybercrime and Insurance event. That sounds interesting.
So if you really want to be future focused, CTA's got your— the future is now, Robb. It literally is. And then finally, on the 20th, Colorado Springs ISSA is doing one of their mini seminars that Saturday morning. Awesome. That is it for events.
Let's jump over to the jobs. Robb, does Ping Identity have any openings? I got— I have 4 open jobs in Denver right now. Can you believe it? I have a new one.
So we'll start with a new one. We are looking for a GRC analyst, and this is a really a pretty entry-level position. We're looking for someone who wants to come in and learn about compliance risk, regulatory stuff, SOC audits, ISO certifications, someone who's interested in research, interested in learning, good communication skills. Like I said, someone who's looking to get their foot into security, that's a good role for you. And then we're also hiring 3 different roles in product security, from more junior-level product security engineers all the way to a manager of that team.
Go to the website at pingidentity.com and, and look for your favorite job. And in case it doesn't sound familiar, product security should read to most people as AppSec. AppSec. Yep. Very similar.
Elevations Credit Union is looking for an information security officer. Comcast is hiring a principal cybersecurity architect. DigitalGlobe is looking for a senior software security architect. Transamerica is hiring a security architect to complete our trifecta of architect roles. Sweet.
Zoom is looking for a security analyst. InteliSecure is hiring a data protection analyst. Code 42 is looking for a security solutions engineer. I think that's— I don't know, I think that's probably like professional services or customer focus. I don't think it's internal.
And Coalfire is hiring a security consultant application web, mobile penetration tester. All right, that's very complex in that job title. And then finally, Wells Fargo is hiring an IT audit manager, uh, in parentheses, IT governance and CIO application. Good stuff. You want to be an auditor for Wells Fargo?
There you go. Sweet. Um, that is it for the news this week. We have a feature interview with Ed Mahoney. Um, Ed, I believe you actually worked with Ed previously.
I did. Um, I got to sit down with him and interview him though. Um, Ed is currently a product manager for, uh, for CenturyLink, but that's not what we were talking about. We were talking about the fact that he has become a, a novelist, and, uh, the, the 2 novels he's written are both about cybersecurity. Kind of realistic spy theme type stuff.
I got— I read the book, I interviewed him, and we get to talk about the process and what it's all like. And I believe this book is about cyberwar. It's— I believe it's full spectrum cyberwar, to be specific. Indeed. Yeah.
Well, that is it for this week. And oh, we need to let you guys know we are not going to be here next week. Both Alex and I have other commitments more important than you all, which doesn't happen very often. Very infrequent. Yeah.
So this must be very important. Yeah. Uh, but we'll be back again in 2 weeks and we'll miss you very much. And, uh, hopefully we'll, we'll send postcards and, and we'll see you then. Sounds good.
Thanks, Robb. Hello, this is Jeremy Cooper-Leavitt, Managing Director of Assurance at Charles Schwab. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is Robb Reck, and today I'm sitting with Ed Mahoney.
Ed, this is a different episode for me. I've never done something quite like this. You are an author. That's not your full-time job. I'm guessing that selling a few books on Amazon is not taking the place of— Not a moneymaker.
So normally I like to start off the interviews by talking about something kind of out of left field, but since we're mostly going to talk about writing a book, which is a little bit out of left field, let's reverse it. Let's talk about your security background. First of all, where are you from natively? You a Coloradan? No, Texas.
Texas, okay. Really born in Iowa, but mostly raised in Texas. Round Rock, Texas. Round Rock. Probably, were you there long enough to have been there when Dell opened, started up?
So my wife, just as we got married, my wife was one of, I think, the first 100 employees. Oh wow. She tells us we would have been Dellionaires had I not made her move to Colorado. So she was there early, and you said, hey, I got a better idea. Let's— Colorado was a better idea.
So what made you choose to go to Colorado? You know, back then it was a similar recession to what we just had back in 2007. I graduated college, and hard to get a good job. I had a liberal arts degree. I decided— What was your degree?
International Studies. It was kind of history and poli sci basically. And I got interested in tech. I got interested in the telecom program, moved up here to go to that ITP program at CU. And so that's the program we talked about a couple weeks ago on the— or maybe a couple months ago on a podcast.
Refresh us, what was the ITP program? So that was interdisciplinary, at least it was at that time because it was out of the engineering school and there was an MS, but it was mixed with their finance school. So it was kind of an MBA engineering degree. Now I listen to that podcast, I guess it's morphed into a cybersecurity program. Yeah, well, at least with an emphasis there.
And that's a master's program, right? Yeah. So you got your master's from CU, and was that while you were working at that time, or was that full-time? Well, you know, first job I moved up here, go to school, get that program, very first job, beer vendor at the CU football games back in the day when they were— So every job after that has been a step down. Been kind of a letdown.
Yeah. I mean, if they And they sell beer again, but they sold it in the stands. Yeah, I would be moonlighting. I'd be totally moonlighting. It was a good gig.
So Ed and I are drinking beers right now in the Ping office. So, you know, life hasn't gone too bad. No, it's just some things never change. All right. So you had the job doing beer vendor.
I got an internship at IBM for a year as a computer operator doing batch jobs, JCL jobs. It's pretty cool that we were getting into outsourcing their first customer was this bank, Bank of Hibernia or something from Louisiana. So very early days in outsourcing and it was very cool, but that program opened up a lot of doors for me. I got a job at what was US West at the time, just down the street where I parked. Yeah, and what were you doing for US West?
So, you know, my title was a data network engineer.
Really what I was doing, I was helping them back at the time kind of migrate people from terminal servers onto a Cisco routed backbone network, taking them into the LANs and networks. But I would really say the job was tech writing. Throughout my career, I mean, yourself, you probably do 50 emails a day, don't you? At least, yeah. I think the job was mostly a tech writer.
That's how I would describe it. Did it for a few years and went back to IBM. What'd you do for IBM then? That's where I got into security. Got into a lot of customer-facing situations, traveled a great deal, but I had that data networking background.
I think my core skill, if you remember, was a network generalist. That's what I was known for. I don't even think they have those anymore. Nobody even knows what one is. We're on switched networks now, so it's much harder.
It's a little harder, I suppose. But those were pretty cool. One day I'm deploying firewalls and realized I was in security. That was around 2000, maybe a year or two before. Security wasn't really much— wasn't a well-known discipline in the '90s.
No. There were people who were doing security but might not have called it doing security. Yeah. At that time, that was right when The people I was working with were building the first managed security services portfolio for IBM. So yeah, it was for them.
That was— they were probably in security a decade or two before that with their antivirus services and stuff, but nobody called it security. So how long were you at IBM? Quite a while. 23 years. Oh, that's a good run.
Yeah, I really just left a couple of years ago, went back to the telco. And I think you crossed paths with Alex The co-host, the second-best co-host of the Colorado Equal Security Podcast. Yeah, I'd put him about number 2. He's a solid number 2 though. Yeah, no, he's really, really number 2.
I remember when I met him. I was walking into some office down in the tech center to take my CISSP exam, and he was taking his CISSP at the same time. Yeah. And went out to lunch right afterward. Did you guys console each other?
You know, I don't know, maybe it's harder now, but I did buy a book, CISSP for Dummies, and I spent a night reading that. I don't know if it's changed, but, you know, if you had a background in IT, not just security, but it was, you know, 10 different disciplines of IT, if you had a broad background in IT, and I did, you could just walk in and take that exam and pass. It's probably gotten harder. So for those listening, I don't recommend that that be your studying approach. No, you should absolutely just sign up, and if you have to go back and again, re-register.
As long as you don't mind paying the money, go for it. It'd be a good way to learn what you don't know. Yeah, try this at home. So you got to know Alex there, and apparently you passed, and maybe he passed. I don't want to start any rumors that he's got a fake CISSP on his resume, so I won't say anything else.
I let mine expire. I just wanted to go get it. I was managing a SOC at the time, and I was just, you know, this silly things a line manager does to motivate their team. I just went to go do it to tell my team, Look how easy it is. Now you guys go do it.
And most of them did. It was good. Yeah. So, so, you know, I do want to get over to the writing as well, but I want to hear a little bit more about, you know, you've managed the SOC there. You guys started having MSSPs.
You know, maybe just broadly describe your career arc at IBM over those 23 years. Yeah, the technical career kind of ended as I started to deploy firewalls. I think maybe management realized that, you know, my dearth of technical skills, they moved me into management. 10 years in line management, but that was mostly in that MSSP area. I was managing all these security teams, picked it up that way.
Then we had a merger, which we were— IBM acquired ISS. That was kind of a reverse merger where they had the big name. We were buying mindshare. A lot of us kind of folded into that outfit. When that happened, after I merged my SOC into their SOC organization, I got into product management.
I was really happy with that. Pretty big change going from, you know, line management of technical staff to product management. It sounds like it is, but, you know, first of all, product management, the role is getting people to do stuff for you, just like line management was, except, you know, fortunately you don't have to do their performance reviews. So a lot easier as far as that goes, but very similar. And then my experience at IBM It was when IBM was growing dramatically and everything was like the role of a product manager.
You're launching new services constantly. I felt like I had that background. I really enjoyed it. I felt like 23 years was too long. I should have left after 10, but I am happy that I moved into product management because I could do this the rest of my life.
I really like it. Any products that you managed at IBM that you can share that I might recognize? Might be relevant here? Yeah, for them, when I first got into product management, I think one of the first things I launched from scratch was Managed Blue Coat. We started to support a secure web gateway product.
Throughout that, I ran their managed firewalls, their Message Labs back in the day, their web email, their web security, mostly around managed firewalls. I feel if I have to think about all the things that I touched, I managed their antivirus team for a while. I think they called them malware defense. Managed, well, before product management, told you I managed the SOC, but different products. God, I can't remember them all.
That's quite a good laundry list right there though. Yeah, I'm back focused on the managed firewall service right now. Let's let you go over the laundry list. Level 3, CenturyLink, I guess. CenturyLink.
And over there you're managing the— or product managing the— product managing the managed firewall service. Yeah. So Cisco, Palo Alto, Fortinet. Check Point? No Check Point?
Well, so we do. We do. I'm kind of scaling back our focus on Check Point, but yeah, all 4 of them. But those 3 or 4, I mean, that is the market. They own 50% of the market.
Market. Yeah, those are the ones you have to, have to manage. Awesome. All right, well, you mentioned that you had a liberal arts emphasis in college. You've done a lot of writing in your career professionally.
At what point did writing for fun enter into the equation for you? Yeah, because we all write every day. Um, 2016, I think. Um, You know, I think anybody who reads, and you seem to be an avid reader, if you read, you probably think at some point you'd like to write a book. It's just like if you work out and you listen to music, you fantasize that, you know, you're the singer-songwriter right there.
You know, you think, I can do this, and I want to. So I finally did about— yeah, in 2014, I came across this story. It was such a good story, and I just knew I'm gonna write a book on that. And I knew I wanted— you know, it was a real story, but I knew I wanted to write fiction. And still, I sat on it for about 2 years, but in 2016 I was working with this lady at IBM, another product manager, Wendy Therrien.
She was a writer, and she just held my hand and said, write the book. Here's how you do it. And I started writing it. 6 months later, self-published. It was a lot of work.
I put— I think I figured I put 800 hours into that. So when you say, when you say she told you to write it and she held your hand, you know, I understand you probably can't give every detail on this podcast, but I'd love to hear, you know, broad strokes. What does that mean? Obviously you could just open up Word on your computer and just type, but I'm guessing there's something more to it than that. What's your process?
I would say, you know, it started with, um, with, uh, you know, I knew my story, so, so I started to write it and, and, uh, gave her the first pages. And she reviewed it and gave me the confidence to go for it. And she wouldn't have lied. So she gave me the confidence to continue with it. And then after that, I didn't really have guidance— too much guidance.
She would say, work with this software package or do that or the other. I came up with my own idea on how I wanted to do it. I learned later that there are 2 methods to writing. One is an outliner and the other is called a pantser. Seater for your pants.
A pantser. So a seater for your pants just sits down and makes shit up, you know, just nonstop, you know, no structure. And then the other one's pure structure. Most people are some sort of hybrid. I'm a hybrid, but I used— are you familiar with Evernote?
Yeah, I thought that I was using Evernote at the time and most people use Word or something. But I just loved that whole navigation thing on the left-hand side. I saw that I could set out my paragraphs— or I'm sorry, my chapters and my scenes. I had an idea. I didn't have to write in a linear fashion.
I was halfway through the book and I figured out my ending. I wrote my ending. So you knew— when you started the book, you didn't know the ending. Halfway through, you figured out the ending. And then you kind of skipped and wrote the ending, and then you filled in the— I knew I had a great story.
I didn't know the ending. That's a little uncomfortable, but, you know, I figured it would come. Same thing with the second book, didn't know the ending till about halfway through. So let's talk— I, you know, I have— you mentioned I have read quite a bit, and I actually, you know, whenever I come across a book around— a novel around technology, I'm more inclined to read those. Like, hey, it's closer to my world.
Yeah, generally. Yeah, but I can't think off the top of my head of any that have been like pretty clearly security-focused. And, and though, you know, you had sent me your second book, um, holy smokes, now I can't remember the name of it. Uh, no, I got it. Full Spectrum Cyberwar.
Thanks. I was going to jump in there, man. I wanted— I didn't want to miss it completely. I, uh, Full Spectrum Cyberwar. Um, and I, and I read that and it's pretty much a security book.
So, so I'd love to know, like, you know, what was your, uh, you know, obviously you have a couple decades here. Are there any other security books that you've read that kind of led you down this, or you saw a gap, or what was your head there? I saw a gap, but it's a yes and no. You know, there's a ton of security books, but I saw a gap. There are a lot of reasons I decided to write that book, and that's one of them.
I didn't think there was anything out there, not much out there like this. Yeah, Neal Stephenson, you know, Reamed or something, but for the most part, the first security book I read was Cuckoo's Egg by Clifford Stoll. Sure. And that was a really long time ago. So Cuckoo's Egg is about the professor from Berkeley who, yeah, kind of came across— maybe you want to summarize for our listeners.
Well, yeah, such a cool guy, right? He's a grad student and he's got this job he's got to do on campus of kind of managing the modems and stuff, and he sees the charges bounce off by like 3 cents. Yeah, and he's got issues with that because he's a rocket scientist. Scientist. And he follows it up in International Intrigue.
Great story, but true story. True story, nonfiction. Yeah, read like fiction, read like a tech thriller. Yeah, it was awesome, but nonfiction. Every story that I've read, every good book I've read just about is nonfiction.
And not everybody's going to read that. Tech guys will read it. Um, well, certain people with that aptitude will read nonfiction, most people will never look at it. The ones that I've enjoyed read like fiction because they'll stretch vectors, you know, do the things that a fictional story will do to be entertaining. Countdown to Zero, that was a pretty good one on Stuxnet.
Zero Day. Yeah. Have you read Cryptonomicon? Yeah, so that was an early one as well, right? And I, you know, I would say it drew in the IT crowd.
IT people read that book and they loved it because it was familiar to them. Not deep into security. It was, you know, it talks about Enigma and stuff. And then it was, and then it was, had 2 time zones, right? It's talking about time travel, basically.
Yeah, it almost was. It took me a couple chapters to figure it out. What's going on? It's another good one. Little Brother.
You got Little Brother? Yeah, it's by Cory Doctorow, who he actually wrote Homeland too. And I don't know if that's from this, if that's the same one. I think it is the same one. I've been told to read that and I haven't.
Yeah. So, so that's really good. Yeah, anyway, there's some good ones, but to your point, like, these are, you know, they're technology-focused, but they don't really get into the security aspect of things too much. They don't, they don't get into the detail that I like. I like tech thrillers.
I like a little bit of detail, and I did want to write a computer security primer, you know, for people who like to read. They're not in our industry, but they're interested in it. A lot of people are interested in it, so I was trying to do a computer security primer. So let's talk a little bit about Full Spectrum Cyberwar. I have a bone to pick with you.
The first bad guy in the book is very clearly the CISO for the wind farm in the UK, who's kind of an incompetent, maybe even unethical person. So thanks a lot. Thanks a lot for that. We, you know, we in the CISO chairs appreciate it. And a woman too, just want to throw me under the meat I was doing my best not to, not to mention that it was a female.
But then I guess, you know, it turns around and the real bad guy is Vladimir Putin. So, yeah, thank you. We are sitting in my office right now. Do you see this calendar right behind me up there? I have on my wall, I have a Vladimir Putin wall calendar.
Did he sign it for you? It was a gift to me. He didn't, but there is a picture of him shirtless. As long as you're not shirtless alongside. I'm not.
Good. So yeah, really good book. There's a few things that I want to call out from it. I thought you did a really good job talking about the details of how they're hacking into these accounts and a lot of getting into financial accounts and trying to gain access and talking about when they run into multi-factor authentication, what the impacts of that were and how that makes it a lot harder. Thank you.
We talked about my technical skills. You know, you might want me on your team, but you probably don't want me touching the keyboard anymore. So I'm only going to get so deep, but I do want to talk at a certain level of process and just show people how doable it is. I want them to understand that, yeah, this can be done. And if you want to do some Googling after you read the book, you could probably do it too.
Yeah, I enjoyed that. What was your— you know, it was a big story, right? You didn't go with like here's a, here's a little incident that happens in, you know, a corner of Texas. It was, you know, here are all of the major nation states in the West coming into conflict with Russia, right? It's a pretty broad thing.
And how do you build confidence for that? Well, well, I don't know. You know, I did have the international studies background, and I'm interested in that stuff. I'll tell you, I don't watch news much anymore, but I love news. I love politics.
Um, and, and I read. But, uh, if you think about it, there wasn't much that I made up there. I just took stuff right out of the paper. Yeah, it wasn't that hard to— that all that stuff was just in my head, not as somebody who's making stuff up. It was just out there.
Yeah, the stuff you're doing, some research, figuring out, you know, how do these countries work together? Yeah, like, like, um, when I, I kind of— when I had the characters Sarah and what was Sarah's boyfriend's name? Joseph.
You know, I weaved in the fact that Greece and Macedonia really don't like the Jackie Chan. And maybe a lot of people wouldn't pick that up, but that's what I was playing on. Yeah, you definitely did. You know, kind of, there is definitely a Colorado tie-in here. Your protagonist, our main character, Robb, right?
Yeah. If I remember correctly. He's a 50-something-ish, 55-ish-year-old entrepreneur who's about to sell his business. And he lives in— is it Estes Park he lives in currently? And he's moving to the mountains?
He was going to retire. He lives in Boulder. He was going to retire at Estes Park. You know, after he sells his business, he's going to be able to upgrade that A-frame. But yeah.
So is this a vision of you and what you want to be? Or what do we got here? You know, everybody asks that. Every character, you know, they want to know and they think, oh, that's you, or that's your wife, or that's this or the other. As a writer, I'm in every one of those characters, and some of my friends are in those characters.
Friends mostly just by their names.
I purposely put some names in there because those are people I worked with, and it's just a nod to them really, and it's kind of fun to do that. But some aspects are Robb or me. But some aspects of the bad guys are me too, you know, except Putin because I, I can't go shirtless. But you have ridden a bear here and there, I assume? Yeah, yeah, one or two.
Yeah. So what, what was the hardest part of the process for you of, you know, creating either of these books? Um, publishing, uh, editing— no, formatting. Formatting. But the writing, you know, it's work, but, uh, I don't know what writer's block is.
I know people talk about it. I've never had an issue with that. It's never felt like work. That was a cool thing. I started writing and I just— it just didn't feel like work.
It was like stamp collecting or something. I just enjoyed doing it. How long did it take you to write it? The first book, 6 months from start to finish to publish. Second one, 2 years because I switched IBM over to CTL and That kind of slowed things down.
But probably— it's actually even a shorter book. But then you go to publish, you got to format that stuff. And I don't know, it's not that difficult. I mean, it's not like it's written out for you either. You got to figure it out.
But you got to format an ebook, you got to format a paperback. It's not as easy as you would think. It's not like you can just use Word. You know, you have to have pages formatted differently for the left side and the right side. I just find it kind of monotonous.
I don't enjoy the formatting part. I hired an editor on my first book, but that just gave me feedback.
If I were to start making money on these things, I'd— well, ideally I'd get it published, but self-publishing you have to decide if you're going to pay for certain services. I would pay for formatting a book. I almost did this time, but I decided to do it myself. I don't enjoy it. Is there a third coming?
Is this a trilogy that we're creating here, or what do you think? Sort of. I'm already writing the third book. I don't know what the conventions are for a trilogy. It's some of the same characters.
The lead character, the protagonist, is somebody who's not even born yet in the first book, but is announced in— I'm sorry, second book. But is announced in that second book. Okay, well, I think I know who that is then. Yeah, and a couple of characters will bleed into it, but it's going to be 20 years in the future, and I changed the genre from tech thriller to cyberpunk. I just want to grow as a writer.
I want to start doing some new things. Instead of tech thriller, it'll be a mystery. Mystery will be a little different for me. I'll have to learn some skills. So if people are interested in picking up your books, talk to me about Was the first one called Cyberwar One?
And your name is Ed Mahoney. So what's the best way for them to find these books? Just, you know, you can Google my name and you'll find it, but go to Amazon. I just went exclusive with Amazon this time because as a new writer, you know, I'm not gonna get any sales anywhere else anyway. So I just went Amazon.
It gives me a better commission. Yeah, go to Amazon Books and you can, you can just type in Cyberwar. I'll be on the first page. At least for the next couple of days. And I check that every day.
And I think I saw, um, I think I saw that if someone has— was it called the Amazon Read? Is that what it's called? There's Kindle Pages or something. I forget what that program is. Some program that they have, you're actually free on that for people who have that subscription.
Yeah, people that subscribe to that. I, I get maybe a quarter of my sales of people just reading pages like that. Yeah, it's kind of weird to add that up, but So if someone's already subscribed to that subscription— excuse me, I'm not sure what it's called— but they can go read your books for free. Yeah, so then at Amazon you don't have to have an e-reader. I've got a paperback there.
Amazon doesn't do hardbacks yet. The first book I went with a different publisher and I've got a hardback on that, but Amazon just softcover paperback and ebooks. But you did move over— you moved the first one over as well though, right? Well, I always had it there. Okay.
I did change and go exclusive with them. Okay, well, that's great. So, you know, for those people who, who are interested in reaching out to you, you have a preferred way if they have questions about the book? Are you open for people reaching out to you? Can Alex take the first call and then he can filter them?
I'd be happy to sign up Alex as the guy. Okay then. Yeah, so alex@colorado-security.com. Because sometimes I'm off where I'm on vacation, there's weekends, there's there's days I could use Alex. Alex is a good buffer for that.
Good. Well, that's great. Anything else you want to talk about, about the process or the book that we can share with the community? Yeah, you know, I've been meeting— excuse me— a lot of writers just on my job at work. One of my beta readers was another product manager on my team, Dave, and he's writing a book.
I just keep running into people who are writing books. It is so much more doable nowadays. It's like, you know, you're doing this podcast. There's a lot that goes on in that. There's a lot of behind the scenes after you're done talking.
You got to edit and publish that thing. Self-publishing is just a lot easier nowadays. It's doable. Like I said, formatting a book is not something I enjoy. It's doable.
It's all very doable, so more people are doing these things. People should certainly reach out to me. I've got a pretty strong digital presence. I'm easy to find and I would love to help people along the way. But Denver has got an awesome conference in September every year where it's the Rocky Mountain Fiction Writers.
Really? Yeah, it's very cool. I went to it the first couple of years. I went to it after the first draft of my first book and it's like any other user conference you would go to. You go to sessions where people are teaching you how to do stuff, but mostly you're just there with your tribe.
You know, you're in there and it's like all these people are writers and so am I. How many folks show up to that thing? Thousands. You know, maybe not the whole— over 1,000, I would say over 1,000, maybe 1,500. But it is pretty cool, and it'll get— it's like the Comic-Con is going on right now.
I had to walk here a couple blocks and I feel a little underdressed. Everybody was in their outfits But a conference like that is something that'll get you excited. Yeah, it's affordable. It's like $400, $500 to register. Yeah, well, anyone who's interested in writing, sounds like a good place to go and learn and experience it.
Well, Ed, thanks so much for your time. It's really been fun catching up, and thanks for keep— for writing the book and sharing it with us. Look forward to seeing what comes next. Yeah, thank you. You think the keg's still open?
I think the keg's still open. All right, thanks, Robb. Thanks a lot. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.