Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is episode 130 for August 26th, and this is Alex Wood. As you know, Robb almost always introduces the podcast, so if I'm doing it, that probably means we have a guest co-host.
Today we have Brian Beyer. Welcome, Brian. Thank you. Glad to be here. Brian, of course, is the CEO of Red Canary and sometimes stand-in co-host for Colorado Equal Security.
We'll get to it a little bit later. Robb is not on vacation, but had, I don't know, reason why he couldn't, uh, be here today. So, uh, when we get to it in the news, we'll, we'll talk about it a little bit. But anyway, uh, Brian, how's your weekend been? Been a great weekend.
Beautiful Colorado, end of summer heading into fall, probably my favorite time of year. Nice, nice. Me too. Um, I know we both had kids' soccer games this weekend, lots of fun there. And I even found a little time to do some woodworking, which is not something I normally do, but it was actually fun.
So I've enjoyed it. And we're sitting here in your great unfinished bar that will soon be finished at some point. Yeah, we're actually, we're doing something different too. We're recording outside. So we're enjoying the weather while we are recording this podcast.
Exactly. Good stuff. Great weekend. All right, let's jump into the news. First on the list, you know, in the worst kept secret in the whole world, John Hickenlooper announced that he is running for US Senate.
I think that surprises no one. How about you, Brian? Not at all surprised. Yeah, I think after he dropped out of the presidential race, and I think I mentioned it last week, and immediately changed his Facebook group from Hickenlooper for President to Hickenlooper for Senate, even though he didn't officially announce, I think it was pretty obvious that he was going to do it. Absolutely.
We also have news that Space Command is going to be initially homed in Colorado. That's gonna be down at Peterson and hopefully the long-term home of Space Command as well. Yeah, I'm still interested to see what exactly happens with Space Command. I mean, I can see it being an important thing at some point, but until it becomes important, are they just gonna plan? Well, we've actually had a Space Command before.
We have, yes. We had a Space Command and then it was shut down to become the Northern Command and now it's back. And I guess welcome back. Great to have them here. I mean, one of the neat things to me coming from that defense and intelligence space is that includes the, I think it's the 50th Space Wing that controls most of our intelligence satellites.
And it's an awesome team doing really neat things up there on the fringes. Nice. Next, Denver is one of the cities that was a finalist. Obviously, we did not make it for Amazon's HQ2 that is now seeing a cooling of the commercial real estate market. Brian, what experience do you have with that?
That is great news for everyone, except if you own the buildings. Real estate prices were getting kind of crazy and out of control. And so for all of us tech companies and everyone moving into Denver, it's great news to see those slump down and be a little more reasonable as we all try and expand down there. Yeah, I think it's interesting. I guess it is It's a parallel that you can draw, that some of the cities where HQ2 was reportedly going to go are now seeing a cooling.
I'm not sure that it really has anything to do with Amazon. This seems like, hey, we needed a title for this article, and we don't want to just say, commercial real estate markets are cooling a little bit. Denver had been on a huge growth swing for a long time, so I don't think it's any surprise that at some point, it's going to cool a little bit. All right, and we have the Google Impact Challenge has selected Colorado and is going to be giving $1 million to bolster Colorado nonprofits as they build themselves. So great to hear from Google.
Yeah, it looks like they're gonna do $175,000 to 5 nonprofits across Colorado, plus an additional $125,000 for a People's Choice Awards. So they're looking for companies that are going to help increase economic improvement and development. So that seems pretty cool to me. Good on Google for helping us do that. Next, there is an expansion of another Bay Area tech company here in Denver.
Personal Capital is looking to move into a new Denver office with room for 30% growth. So it looks like they are taking on 2 floors at 1099 18th Street in the Granite Tower, and that's nearly 30,000 square feet down there. Personal Capital, they are sort of online investment advisors, money managers, things like that, but it's supposed to be, I believe, sort of more direct consumer than other things like that. Brian, I don't know if you know anything about Personal Capital. Just that they're the next, you know, they're kind of that next-gen generation of capital and wealth advisement solutions targeted toward millennials and that generation who would prefer to deal more with online platforms and guided advice through that rather than driving into big bank offices.
Right, makes sense. And then the big news, which leads to why Robb isn't here today, is that Ping Identity has filed for their IPO, so we have their S-1 out there. From my perspective, super exciting, right? This is really neat to see that one of Colorado's great security companies has made it to that milestone. And coming out of what they've done in the private equity side of things and awesome growth since then, really proud of everything they've done.
And huge congratulations to Andre and Robb and that whole team. Yeah, definitely congratulations to Ping. Um, as part of that filing, it looks like they're going to try and raise an extra $100 million as part of the IPO. Don't have a whole lot of details yet on what that is going to look like, pricing and other things like that. I'm sure we will know as we get closer to that actual IPO date.
I also have not dug into the actual S-1 itself to look at any of the nitty-gritty details that they have to disclose. But as many of you probably probably know, when you're in this time period, the SEC is pretty picky about things that you say. If you work for a company that is in the quiet period, after you've announced an IPO, before you actually go public, there's not a whole lot that you can say other than the official statement that you put out as part of your IPO filing. Robb was not particularly comfortable with talking about this, so here Brian and I are talking it. About it.
I personally think we should have another episode where he comes on and we have him read to us, in the Robb voice, the S-1 statements. If you've ever read an S-1, they are the most wildly exciting statements you've ever seen. Yes, super, super exciting. Anyway, congratulations again to Ping. Good things in the future for them.
Next, we have another technology company that is in that same trajectory. However, SecureSet announced that they are being acquired by the Flatiron School. So the Flatiron School, they are not a cybersecurity training company, but rather just a school where they have a mission of enabling a better life through education. So it seems as though SecureSet is going to become their cybersecurity training arm, which is great for SecureSet. It gives them a much broader reach, helps them expand.
I think we haven't talked to anybody there, but sounds like good stuff for them too. I think it'll be exciting for them to have the whole Flatiron platform and bigger reach throughout the community.
Next, we have a press release from Ping Identity that is not related to their IPO. Ping was actually named a leader once again in Gartner's Magic Quadrant for access management. Great. Congratulations to them. On the blog side of things, Coalfire released an article titled When Checking the Box Results in 2 Zero Days En Route, which sounds about exactly like what will happen if you try to build a security program off of checking a box.
So good read from those guys. Yeah, they're talking about doing a penetration test. Things actually looked pretty decent, but the penetration tester decided, well, you know what? I'm actually gonna look at some stuff and ended up finding a couple zero days as part of the test. Pretty interesting read there.
This one is from Jacob Nelson, so congrats Jacob on finding your zero days and reporting it out here. Next, Webroot had an article about cybersecurity in schools, what families need to know. And this seems to be sort of the trend in the articles we've seen from Webroot. You know, while they have an enterprise business, a lot of their Their products are consumer products with antivirus and things like that. So this is really more a consumer-facing article, but it gives you good information as a parent, as someone with a child in school, maybe even a child in school, some ideas of things that you need to care about when worried about cybersecurity in schools.
Now, one of the things in that article I'd love your opinion on also as a parent is The final guiding bit of advice was to teach your children how to use a VPN and that they should use a VPN for all of their web surfing. What do you think of that? Is that really where we are and what we are teaching our kids? Is that the only way to be safe online is with a VPN? So if I said yes, I'd be a hypocrite.
So I think VPN is a good idea. I use one periodically, but not every time I am connecting. I think it definitely has its place if you're in a public area. If you connect at Starbucks or the airport or something like that, hey, probably a good idea to flip on your VPN. But if you're in someplace where you can expect at least a little bit higher of a bar, maybe not quite as important.
I guess it depends on your own personal risk model and what you think about how secure networks are at various places. Yeah, I'm fascinated to see how this continues to affect that new generation of kids, right? Are we going to teach them that they should be using a VPN before we teach them why they should have multi-factor setup everywhere? Right. This would be a very fascinating curriculum to create.
Honestly, with how you can set up VPNs, mostly kids I think are going to be on their phones, right? You can set that up at the system level. So you could be on a VPN without even knowing it, right? Might not be very intrusive at all, probably a little bit of a slowdown, but besides that, maybe it's not a bad idea. Yeah, great point.
And then finally, we have a blog from Tony Lambert and Brian Donahue from the Red Canary team talking about some of the next level of things we've seen with ransomware, when the ransomware itself starts deleting shadow copies and what you should do about that. Not a highly novel technique, but as always, try and go into a big deep dive as to how do adversaries actually work and what should you be doing to identify it and protect yourself. You know, it's been really interesting to me, Brian. The last 2 years, you know, 2017, 2018, ransomware seems to have, you know, I don't want to say gone away, but dipped in terms either public perception, My feeling is maybe even not seeing it as much. My assumption was with cryptojacking, crooks were going, oh hey, look, here's another way we don't have to actually deal with anybody.
We can just make some money without having to worry about getting caught and ransoming somebody. So it seemed like ransomware went away, not went away, but decreased a little bit there. But now all of a sudden, 2019, it seems like it is back and maybe even much more in force than it was in prior years. What's your thought on that? I think it would be really interesting to see the data.
I'm not sure if it actually went away or if it has decreased or if it simply didn't have the popularity and news reporting and articles because it just sort of became blasé and everybody's getting hit by ransomware, right? So it's just not as interesting to talk about. I'd actually, I'd really like to see that data to see infections of that versus other types of crimeware. Sounds like a forthcoming blog post from Red Canary. Sounds like I've signed their team up for some more work around that, but now I'm interested.
Cool. All right, so that is the news. Let's move over to the Slack Message of the Week. Thank you again to Andre Gaeta for supporting the Slack Message of the Week. If you are selected as the Slack Message of the Week, you get a $25 credit towards something at the Colorado Equals Security Store.
In that store, you can find all kinds of Colorado Equals Security logo merchandise, and we wanted to thank Andre for giving that $25 credit out of his own pocket for anyone that wins this award. Big thanks, Andre. Yeah, good stuff. So the person that won the Slack Master of the Week this, this week goes by Gan Anim, and I wanted to picked this one because on the Slack channel we have a good stuff channel and you go in there and you post things that are good, positive. We also have a rant channel which, you know, people like to go.
And we actually created those at the same time. Someone said, hey, if we're going to have stuff where you can say bad things, we better have a channel where you have good things. And so he posted about a user that works in his organization that reported a legitimate email that was asking for sensitive information, and he reported it because he didn't think that they should actually be asking for that information. So good on that user, and that is definitely good stuff— someone that is paying attention and cares what information that they're giving out, even to legitimate companies. So we will get you hooked up with Andre, and you can get your Slack Message of the Week swag.
So let's move over to events. First on the event calendar for this week, we— following up on last week, we've got a lot of events in the next couple weeks, so there's going to be a bunch here. On the 27th, the GDPR meetup is doing ping pong and food. This is where we play ping pong and decide who's the DPA and who's not, right? Right.
Yes, maybe it's beer pong, and then loser has to be the DPA. There we go. That's it. On the 27th, we have Emerging Tech Fan talking about AI being a team sport. Interesting.
On the 28th, ISC² Pikes Peak is doing their August chapter meeting. On the 28th through the 30th, the CTA is hosting a blockchain training conference. What do you exactly get trained on there? Is it how to do voodoo or it's math? I almost want to go just to find out.
On the 28th— excuse me, 29th, CSA is doing their August 2019 event at the Rockies game. I don't know if they have any tickets left, but check out the CSA website for that. Great. On September 3rd through 5th, ISSA Colorado Springs is hosting Peak Cyber. Ooh, exciting.
On the 4th, SecureSet is doing a capture the flag for all levels. Sounds great. On the 5th, Splunk is hosting their First Thursdays at Topgolf to meet more of the local Splunk team and other people using Splunk. Awesome. On the 5th, Following the Evolution from Deming TPS Lean DevOps to DevSecOps.
That sounds like an interesting one. This is a DevSecOps Boulder meetup. Great. Interface Denver is being held on the 5th as well. On the 6th, First Friday in Colorado Springs is doing their Cybersecurity Social and Mixer.
Followed by the 7th where the CISSP Seminar Series is covering Domains 5, which is Identity and Access Management, and Domain 8, which is Software Development Security. Awesome. And then finally on the 9th, SecureSet is doing a Hacking 101 Intro to Wi-Fi. So that is all we have for events. Let's move over to jobs.
That starts off with Ping Identity is hiring a GRC analyst, which will be all the more important as they continue their path and growth. That's right. You'll not only get to deal with all the stuff they already deal with, but pretty soon you'll get to deal with SOX. Alex's favorite topic. I love SOX.
Next, CHI is hiring a director of security engineering. Visa is hiring a cybersecurity engineer focused on identity and access management. The State of Colorado is looking for a Senior Advisor on Election Security and Preparedness. That sounds like an awesome job. That does.
PwC is looking for a Cybersecurity Cloud Architecture Senior Manager. Charlotte's Web is looking for an Information Technology Security Analyst. QTAC Rock is looking for an Information Security Risk Analyst. The U.S. Department of Defense is looking for a Cybersecurity Management Officer. Code42 is hiring a Security Solutions Relationship Manager.
And Imperva is looking for a Senior Sales Engineer. And that is it for jobs, which brings us to the end of the nude— nude— nudecast for this week. This is what happens when Robb's not around. I know, everything falls apart. That's the end of the newscast for this week.
Brian, Brian, thank you for being our guest co-host for this week. Absolutely. We are now going to kick it over to our feature interview. For this week's interview, I interviewed Steve Winterfeld. Steve is now the Director of Security Strategy at Akamai.
He was not that when I interviewed him. He was actually at a company where he was not allowed to say where he worked, so we'll just go with security strategist at Akamai. Steve and I had a great discussion about many things, including mentoring and just sort sort of the state of people in cybersecurity. So look forward to that. Excellent.
I'm looking forward to it. Awesome. Well, thanks, Brian, and we will talk to everybody next week. Thank you. This is Brian Becker, Director of Information Security at Cronky Sports and Entertainment.
You're listening to Colorado Equal Security, for Colorado security professionals, by Colorado security professionals.
All right. Welcome to Colorado Equal Security. This is Alex And I have a special guest today, Steve Winterfeldt. Hi, Steve. Hi.
How you doing? Great, good to be here. Awesome, beautiful day outside today. Just coming off, off a holiday. Did you have a good time?
Yeah, we did the traditional family barbecue kind of things and just had a nice relaxing thing. Now, one of my favorite jokes is, as a kid, a weekend or a holiday with nothing to do was horrible. As an adult, it's the best thing ever. Exactly. Exactly.
You were saying though that you, uh, you were playing disc golf yesterday and you had something horrible happen. So, so my favorite driver, um, I hooked it into like 3-foot-tall grass and gave up after about 10 minutes of trying to find it. So lost my favorite disc on a, on a hole. So I have played disc golf before, but I am— I would not be categorized as a disc golf player. Um, so do you— when you said your driver, so you have different discs for different things in disc golf?
So, um, I, yeah, I, I do. I have a driver, a short range, and a putter. Uh, in your putter, you don't, you know, don't want to blunt your edge, so you have a specific, uh, putter. Uh, the people I play with, I mean, they have rollers, they have discs that break right, discs that break left. Um, so there'll be guys out there with, you know, 15, 20 discs and pull out a disc for a specific throw.
Wow. So is it like you have like a backpack or how does he, you know, you have a, a golf bag for, you know. So I've seen everything from, uh, play with somebody who just walks there and has 3 discs in their hand. Yeah. To people pulling a bag behind them.
Full of discs. Wow. Is that like a homemade contraption or is it— no, no, no. There's like a commercial market for— there's a commercial market for disc golf bags. Disc golf— yeah, I mean, there's a lot that have, uh, let you separate your discs and then this one kind of blew me away.
You know, he was pulling it behind him and I don't know if he had, you know, beer in there or it was all full of discs, but it seemed like a lot just to have to pull it behind you. It does seem like a lot. Maybe if, you know, if you needed something else, like I need to carry my beer. That's what I'm saying. And my discs.
Okay. Okay. But, uh, but yeah, it seems like a lot for just the discs anyway. Um, so you play a lot then? I try to play every weekend.
Nice. During the summer. Yeah. Uh, well, it's like I said, I have played, but it's not one of those things that I've ever really gotten into. So I just enjoy it because it's just, you know, everybody out there is pretty relaxed.
Yeah. Uh, And, you know, you just kind of go enjoy yourself and, and have a nice group of people out there. Nice. Well, good stuff. So we skipped, you know, some of the important stuff, Steve.
So, so, Steve, who are you? So I am right now, my job is predominantly around incident response. You know, I've had an interesting career. Started out doing the Airborne Ranger thing in the military, so I transitioned out into defense contracting. Was able to follow my passion and, you know, all my work around hobby hacking and that kind of stuff became my profession.
So I've had a chance to work in defense contracting with 3-letter agencies in the military. I've worked with different government agencies like the FAA and their next-gen system and accrediting the Global Hawk unmanned aerial vehicles. So how do you accredit a flight system that can't be patched kind of challenges, right? Moved over and had a chance to go into some of the NERC SIP stuff for the energy grid, which was an interesting field. Ended up recently in retail.
Last couple companies have been Fortune 500 companies, so worked in retail and banking. And again, different set of compliance, different set of operational challenges. It's fascinating to see the different ways in all those industries that the threats either monetize or take advantage. Everything from, you know, nation-states to cybercriminals. It's been a fascinating career.
So when you were still in the Army, did you work on the cybers then, or, or was it— So I did. I transitioned out of combat arms. Yeah. And I remember going to my first course in the military back then. The first half-day lesson was how to load information onto your floppy disk.
And then move it on to another computer. So we had a lot of downtime, you know, back then. Yeah, were these 5¼s? Were they 3½s? 3½s.
3½s, all right. I got the timeframe now. So Steve, you came today and we're— this is a little bit different than a lot of the interviews I do. You actually came with an agenda, which is different than most of our guests. We just kind of, we kind of talk.
So I'm interested to hear what it is that you want to talk about today. Yeah, I, you know, we were, you and I connected at RSA, and we're talking about things that we're passionate about. And I am passionate about mentorship and, you know, developing the next generation of professionals. Yeah. And, you know, paying back for the people that mentored me.
Some people put a lot of work into me. But, you know, and paying that back. That brings up an interesting question. So, you know, I say mentorship, and I'm sure we have a broad range of what people think. So I'll start off by, you know, turning the tables and asking you, what do you think the difference is between a mentor, someone who considers themselves a trainer, a coach, maybe a manager?
How would you define those? Yeah, so I mean, in my mind, Let me think. I'll start with the easiest in my mind. So trainer, I think that's pretty easy. It's, hey, I wanna learn some specific skill.
It could be network intrusion detection. It could be Office documents. It could be something like that. And someone has some knowledge in that and they come and they teach you how to do those particular things. Manager, that's, has to do obviously with, uh, with chain of command, with, you know, being in a job, someone who's giving you direction on a day-to-day basis.
You know, this is your job, this is, you know, uh, what is we need to do, how to get where we need to go. And then mentor, I think, is it's a little bit, um, kind of of all those things, but it's someone that has knowledge in a particular area and an area that maybe you want to have more knowledge about but it's less of a— I don't want to say formal, formal is not the right word. You know, for a trainer it's like hey, train me on something but mentor, it's kind of like hey, you've got experience I guess more than knowledge, although knowledge is important too and you know let me help play off of that experience for me to better myself and figure out where it is that I want to go. So how do you feel about this? So as everybody out here will say, I mean, I have a slightly different view.
So when I think of manager, you know, manager has risk. I can't go to the manager necessarily and say I have this weakness that I want to work on because there's risk there because they're gonna evaluate my value to the company at the end of the year. So I think managers are developing people, but there's a risk factor there that I can't necessarily depend on them to develop me. Trainers or coaches, you know, coach, I tend to think of coaches one-to-many, you know, coaching a team. But, you know, there are life coaches and trainers.
One of the things I think trainers and coaches are usually compensated, you know, you pay them to develop some specific capability. So I'm going to compensate you to make me an expert in Excel or in Kali or in whatever it is that I want. And it's usually fairly narrow. I want to learn this skill and then once I learn this skill, our relationship is over. Where a mentor is, is usually I think of a mentor as somebody you have a relationship with.
And it can be short-term, 6 months. For instance, when I joined my current company, I needed to learn how the company worked and the culture. And so I got a mentor. I went and found somebody that could help me learn how to integrate and understand how to evaluate risk. And we had a relationship for about 6 months.
And I got what I needed out of that relationship. So we still see each other, we still maybe go to lunch or something, but it's— I no longer consider myself to be their mentee, right, because I got something out of that. I have others that I've had relationship with over 5 years, and if I'm stuck on something, I'll call and use them as my sounding board, get advice from them, and I can still consider myself a mentee of that person. So it's a long-term relationship more risk-free I can expose my lack of knowledge and kind of figure out how to grow with them. Yeah, you know, one thing that I hear a lot about from people is the process of getting a mentor, right?
So it's, I know that I need help, I just, I don't know where to go, who to talk to, how to get a mentor. Do you have recommendations in that area for just sort of for general approach? Well, it's interesting you say that. There are a few companies that I've talked to people that work for that have very formal mentor programs. And you put your name into that program and then you are assigned a mentor.
Right. And, you know, those work to some degree, but one of my challenges is a lot of being in a relationship is, does that chemistry work? If you assign me to the wrong person, I'm not going to have that trust. And so I see some benefit to the formal. The other thing we talked about, if it's a relationship, and let's say I came to you for mentorship and you left the company, we could continue that relationship.
If it's formal and you leave the company, then the chances of you willing to stay committed to that relationship are pretty low.
I do think that the person that's going to be mentored has the ownership of going out there and finding that person. And so this kind of goes to what is your goal of being mentored? You know, and I look at this, you know, I want to talk about a couple of things. The first is, is the pillars by which you build your career. So I'll ask you, what do you think are the key skills that you depend on to be successful in your career?
Communication. That's a big one.
You know, from time to time, you know, depending on the job, it's been, you know, specific technical skills, you know, knowledge of the particular area, you know, interpersonal skills, which I think is slightly different than the communications piece, understanding how to interact with people.
I think also the, the ability to listen is a really good skill, so I think a lot of people could work on that one. What about you? So I've kind of, I kind of in my mind have it in 3 buckets. For me to be of value to my company, first of all, I need to be technically competent. Whatever they've hired me to do, I need to be able to do that.
The second thing is I need to either be able to lead people or manage a project. I need to be able to, whatever I'm supposed to get done, I need to be able to get that done. And then the last thing is I need to understand how the company makes money. Because if I don't understand what we do to make money, how can I evaluate the risk to what's happening to the company? Yeah, exactly.
And so I have some employees that are incredibly technically competent, just blow me out of the water. But when I say, okay, now what is the impact? Financial impact to the company if this event happens? They're like, I have no idea. And so it's high.
It's a lot. And so then we set up a program, and I usually set these up in about 6-month blocks, for them to understand how we make revenue and how to evaluate impact of that. Is it impact to the brand? Is it impact of financial fines? Is it impact class action lawsuit?
Is there impact to direct loss? And so, if you take those 3 buckets, somebody else will say, okay, listen, you get your work done, you're technically competent, let's figure out over the next 6 months who to put you with over in the finance organization. Or in the business so you understand how the business works and how we make money. And we set up that relationship and, you know, develop that skill, and 6 months later we determine if that's good. Another thing I'll do in that kind of situation when I'm facilitating it for somebody that is in my chain of command, as you said earlier, I will— once I link them up with that mentor, what I want to do is take that risk factor away.
So the only thing I need to know that both of them come back and say you've set some goals. That's the other part of mentorship, you know, you really need to define an outcome, right? Because otherwise you just kind of wander through this relationship and have some great discussions, but where did you grow? What did you get out of it? Yeah, I think part of that too is that I think the mentees often don't realize that they're the ones that need to drive the relationship.
You know, that I think most often the mentor is the more senior person, so the mentee coming in thinks, oh well, you know, the mentor is in charge, so they're going to tell me all the stuff I need to do. I just need to show up, right? And I think that there's a whole lot more responsibility on the mentee as part of the relationship than there is on the mentor. I couldn't agree more, and I will tell you that both parties will get more out of it if both parties are putting equal effort into it. If you just show up and say, man, you're really cool, I want to be like you when I grow up— and Alex, I know a lot of people say that to you all the time, every day, every day— and so, you know, you're going to commit to them and help mentor them, but, you know, you're not as invested, you're not going to spend as much time, you're not going to have the same outcomes as somebody that comes up and says, Hey, listen, I really appreciate the way you communicate.
I want to spend some time and understand and develop those skills. Can you help me learn to communicate the way you do? Yeah, and I think you just have a better outcome. Yeah, and I think a lot of times you also see where the, the mentor want— if there's not good direction from the mentee, the mentor sort of automatically steps steps in and puts more of their effort and spin towards it. And maybe the mentee doesn't get what they want out of the relationship because the mentor didn't know where it was that you were trying to go, right?
So the other thing I'll see is the mentor will just get disengaged. We're all busy, right? And if, if you're just another thing I have to get done, I'm not going to get penalized if I don't get that done today. And so that's the other thing is I just don't think you get the same quality of engagement. Another thing I like to talk about is, so those are the short-term goals.
The other thing that I work with people on is more the longer career goals. And so I'll have people say, hey, listen, I'm really trying to figure out what I want to do. Or, hey, should I take this job offer that was just given to me? And, you know, over the years I've kind of developed this what I call a North Star philosophy. And what I'll ask them is, I'm like, okay, so what do you want your last job to be?
You know, if you think about the last job, what would be the most fun, most challenging, best financial reward for you? Do you want to be the CEO of your own cyber company, the CTO of a cyber company, or the CISO of a company? Right. And the skills for those 3 things are very different. And so if your passion is to become the CTO of a cyber company and you're being offered a manager position, in compliance, I'm going to advise you that's probably not going to get you to the job you want to retire in, right?
You know, it's a pay raise, it's better visibility. You know, if, if you follow the opportunities that are laid out, that's a great step. Go take that job. But if you know where you want to end up, then you should be conscious about which jobs you accept and which jobs you pursue. And so, I mean, those 3 are kind of really big blocks.
If you want to be a CEO, you should spend more time in finance because you're going to have to run your own company. So you really should have that stuff down and maybe get an MBA rather than an advanced degree in penetration testing. If you want to be the CISO, you're going to need more leadership skills. If you want to be the CTO, you just need to stay focused on technology. And whatever it is, it doesn't have to be one of those 3, but, you know, kind of pick that last job and then make your decisions if they're moving you in that direction.
Yeah, I know that, you know, personally that was something that I always struggled with when I was earlier in my career was I could think of maybe what was like the next thing that I wanted to do, but, you know, 3, 4, 10 jobs from now, you know, whatever that is, that it was often hard for me to visualize what that might be. Do you have suggestions on how people might come to that decision a little bit better? So one great exercise is to go and read some of the job recs out there.
Read some of the articles on people who did their own startup companies. What it took, what the cost was, what they spent their time doing. You know, if you're not interested in going getting your first round of funding, then you may not want to start your own company out. And so I think understanding and reading a lot about those positions, and those 3 generic ones are as good as anything else to start with, which interests you today. And, you know, you can change your North Star over time as you decide discover, oh, I hate management.
I really wanted to be the CEO, but I took this job to get me there, and I realized this is not what I signed up for. I don't want this at all. Yeah, you know, and I do have— it's another thing, you know, for those that are just starting out, that might be a little overwhelming. You know, the first question we work on with someone that's, you know, trying to get, let's say, off the help desk into cybersecurity, You know, that's a little bit of a different discussion because again, you know, which one do I want to be long-term? You kind of know if you want to be the owner of your own company or work for somebody else, but CTO versus CISO is a little harder to determine.
So we talk about what are some of the big buckets that you can move into. And in my mind, you can go in to become a computer security engineer where you focus on the capabilities. You focus on malware detection, and you stand up that capability, and you manage it. You stand up the intrusion detection system, and you tune it, and you make sure it's working. And if you're coming out of sysadmin, that may be a great way to go.
Going from managing the IT tools to the security tools, and just managing that security capability.
You know, people coming from other areas may want to go into compliance, and, you know, that's our version of auditors. And so the payment card industry has PCI. You have to know how to do that. Banking has FFIEC. Energy has the NERC CIP.
I could go on and on. There are so many compliance things out there that you can go in and help make sure your company is, is going to be compliant so it can use credit cards. And that's an in-demand skill. And again, you can go look on, you know, some of these job sites and see what are the compliance jobs require so you know what skills you need to build. So if I'm doing sysadmin, I need to work on computer security tools.
I can go to volunteer organizations and offer my free services to help secure them. And use my time volunteering to develop a skill I want to move into computer security. I mean, that's a pretty direct path. When I see people do that, I'm very impressed by their motivation. And that's pretty easy to look at somebody to hire.
Then the last set is kind of the people that are more hands-on. You have people that are doing deep analysis like forensics. You have people that are doing day in and day out analysis, incident response. You have people doing the penetration testing. These are more hands-on and interacting with the malware.
And so there's some really large buckets of where's your passion for that first step, as well as thinking about where's that passion for the last job I want. Yeah, and I— you were talking about just doing work, you know, either volunteering or something like that, you know, doing work for free. That's not that I, you know, recommend everyone do all their work for free, but, uh, you know, that is something that, that I try and tell people too, is, hey, you want to learn a skill? Okay, well, just go do it.
Figure out some way that you can do that. If that's volunteering for a nonprofit or something that needs help in that area, okay, do that. Whether that's, you know, a lab in your basement doing it, you're probably going to be able to go out and practice those skills, figure this stuff out on your own. You know, you're probably not going to be able to get a job doing that right away, but if you practice those skills, yeah, you're probably going to be able to move into those areas much more likely than if you try and find a job as a penetration tester and then learn how to be a penetration tester. You know, and this brings up another thing.
Let's talk about those certifications.
My favorite. And so certifications are useful to get you through the HR gate. In my mind, they are useful in that way. If you are in a heavily compliance-regulated industry, they're extremely valuable. Because the auditors, be they federal or internal, are going to want to know what the technical skills of your staff are.
And that's an easy thing to produce. Say, here's an artifact. Everybody in the SOC has the following certifications. Right. You know, so there's where the value of those is.
But, you know, if you just go out and get your certification in being a pen tester, we all know you went and took a, you know, a 1-week cram session, you passed the certification. If you're anything like me, you had 1 beer after that and 80% of the knowledge is gone, right? And so, you know, you're gonna, you're gonna get that certification, but then you're gonna run into somebody who wants to interview you and is gonna ask some practical, hands-on, process-based questions. And if you haven't done that, you know, go do the work as you were just saying, saying, then it's going to become quickly apparent. Yeah.
I have found personally that certification can be a motivator in learning those skills. So if, you know, say I wanted to get my CCNA or some other, you know, certification like that, and I don't have that knowledge, I sign myself up to take a certification test at a certain point, I know that I have to figure that out by the time I get to that test, or else there's gonna be a financial impact to me because I now am losing the money that I paid for that test 'cause I'm not gonna pass, right? I'm gonna have to pay for that test again. I think that there are some people that can find that sort of extrinsic motivation because they're, They're forcing themselves to get these certifications. But you can also do that without doing the certification, right?
If you're someone that is internally motivated and you go, oh, this weekend I'm going to learn this skill and by Monday I'm going to be an expert, and there are totally those people, don't worry about the certification, learn the stuff. But if you're somebody that needs that push to go, oh, okay, I'm going to have to learn this stuff, I better force myself, whether that's a certification certification or, you know, signing up for some service that you're paying for that, you know, you can learn from and whatever it might be. Sometimes you need that. I'm right there with you. I create those artificial deadlines.
Yeah, just like you do to drive me to do that. And it may not— sometimes it's just putting it at that goal on my annual review. Right. You know, and that may be enough of a motivator. But yeah, those artificial deadlines I think are great.
You know, and it's interesting when you talk about, you know, people go out and learn. You know, I'm an avid reader, burn through multiple books a month. Other people are doing most of their learning, and I'm starting to transition over to that, a lot of their learning on YouTube. You know, we all went out and bought our drones, so after I got my drone, did not read the manual, went and watched a YouTube video and was able to fly it. You know, you have other people that, like you said, do learn by hands-on.
You know, they can go take a course, they can read a book, it's not going to sink in. They need to go do it. They need a lab. So all those things are very much true. You know, you have to figure out how you learn, and if you're going to be in cybersecurity, you have to be committed to being a lifelong learner.
Definitely. Yeah, things change so fast. You can't sit on your laurels and expect something you know today to be true tomorrow. You know, that's something, you know, now that I'm more senior, I rarely get to touch a keyboard to do anything but technical. And so I actually have a reverse mentor.
Sending emails is technical, Steve. It takes a lot of skill. Well, sometimes I don't get them out correctly, so I'm not going to argue. But I actually have a reverse mentor Somebody who's, you know, I'm not going to spend a lot of time on social media. So if I want, you know, I should probably have a reverse mentor, somebody who's of a generation that does that, thinks that way.
And then I go learn from them what's relevant in that. So I think mentorship for people who are senior, you should really consider doing a reverse mentor, which drives you into learning in a different way. And pulls you back closer to the technology. Well, and I think you can develop mentor-mentee relationships in both directions, right? You find somebody that has a skill that maybe is from a younger generation that you need to get, and you work with that person as a mentee.
But that person might also need some mentorship from skills that you have, right? They might be starting out and might need to learn how to navigate the corporate world, or if they're a security person, to understand risk, or whatever it might be. You're going to have some skill that they can get knowledge from you on in a mentor kind of relationship too. As long as you both are clear about setting some goals, I think that can be very healthy. Yeah, definitely.
Steve, how is it that people can get started on their mentorship journey? Journey? So I mean, it kind of depends on where you are in your career, but, you know, first of all, I think you need to decide, do you need a mentor, do you need different mentors, what are your goals for growth in the near term, and who are you going to engage with either inside or outside your company to achieve those goals through mentorship. So, you You know, there are plenty of people out there that would make great mentors. I think it's up to each one of us to go find that one to help us grow in the area we need at that time.
And like I said, reverse mentor or otherwise. The other part is, as you see junior people out there, I don't know that I would volunteer to be their mentor, but I would engage them in a discussion. Discussion about how they're managing their career and how they're seeking out mentors in their career. And so rather than volunteering to take that on for them, you know, do what we talked about earlier, which is see if they're motivated enough to go do it. And if you can light that fire so they go find somebody or turn around and ask you, great.
And the last thing is If you don't belong to the Colorado Equal Security Slack community, you need to join. And we have a channel in there that was recently stood up on mentoring. Great place to reach out, talk to people about it, and do networking to potentially find somebody or find a path to get into a relationship that works for you. Yeah, yeah, great suggestions. We're just about out of time.
Any other topics that you wanted to hit on, Steve, that we didn't talk about already? No, it's been a great discussion. I appreciate, you know, the chance for us to share perspectives. You know, mentorship means different things to all of us out there, and it's not just our professional life we're mentoring people in there. You know, there's the Big Brother program and there's other type of mentorship programs out there.
So if you're not giving back to the community, just think about the people that have supported you to get you where you are and how you can give back. Awesome. Well, thanks, Steve. It's been a great discussion. Good to talk to you as always.
And this has been Colorado Equal Security. We'll talk to you next time.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.