Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 133, the week of September 16th. Alex, how's it going?
Things are pretty good. How about you, Robb? Oh man, things are going fantastic. Yeah, weather's getting a little bit better, not quite so hot. Oh man, just a little bit cool at night.
It's so nice. Open the windows, you wake up in the morning, you're maybe even a little chilly. Yeah, gotta cuddle underneath the covers. Gotta cuddle under the covers. That's a lot of information there, Alex.
Uh, let's go ahead and jump into some of our housekeeping. We have a Slack channel with like, what, we have like 2 bajillion people on there now? Is that where we are? Something like 2.5, 2.5 bajillion. 2.5 bajillion.
And if you want to join those people, uh, get us up to 3 bajillion, you go out to colorado-security.com, click on the Slack link there, and you can join and be part of the conversation. I know there's been some really good conversations this week across all of the different channels, general and events and random and rant and news, all kinds of good stuff. All kinds of good stuff all the time. We also have a mailing list, Robb. If you want to get notified about new podcasts and get the show notes in your email, go to colorado-security.com, go to the bottom of the page, put your email in and sign up for that mailing list.
If you like what we're doing, we would love it if you would subscribe to us on your favorite podcast listening app and maybe rate us out there too, especially on, on the iTunes Store. We'd love to have you out there. Give us a 5 stars and say Robb's voice is sexy. I haven't seen a single comment like that yet. We would prefer 5-star ratings.
If you're not going to give us a 5-star rating, maybe just pass on the rating. Or a 6-star rating. Oh, okay. Well, that's fine too. You could also tell a friend about all the great things that are happening at Colorado Equal Security podcast, website, Slack channel.
Tell somebody how great things are. If you want to support us financially, we do have a Patreon campaign where you can help kick in some cash to pay for this thing to keep going. We do appreciate all patrons. Big shout out to those folks who've been supporting us. Yes, faithful supporters.
Thank you very much to all of you. Of course, if you have any feedback for us, we'd love to hear from you guys. And finally, we would love to spread the load. If you are interested in interviewing someone for the podcast, please reach out to us. We can give you some direction on how to do that, and maybe you will get an interview on the podcast.
All right, so Alex, It just occurred to me as we were talking about Slack and I was thinking about some of the stuff this week there. Did you see the story about the Coalfire pen testers? You're smiling, so you must have seen it. Yes. Was it— it was in Iowa?
In Iowa, yes. So apparently, we'll throw a link in the show notes about this. Some Coalfire pen testers were engaged to do an assessment to see if they could get unauthorized access to some court documentation, right? Correct. And I think there may have been some confusion on what the actual scope was because they tried to get that access through physical means.
They apparently broke into the courthouse and were caught there and they tried to pull out their get outta jail free card for doing their pen test and it wasn't received so well. It doesn't literally get you out of jail. I think that is true in this case. So they, we do have mugshots in the link that folks can take a look at. Now they've been let out on bail.
So this is like for real serious stuff. Hopefully it all gets sorted out. Apologies are issued all around. No significant issues, I hope. Assuming that all the legal proceedings go away, maybe we can get those guys on the show.
They're not Colorado guys, but since they work for Coalfire, I bet we could twist them around. We could probably make an exception. We could understand what it's like to be inside a holding cell. Yeah, that's got to be pretty weird. Yeah.
All right. You know where else they have a holding cell, Robb? Where else do they have one? I'm pretty sure they have one at Empower Field at Mile High. Wow, that's a good segue.
Yeah. Didn't we just talk about Empower Field at Mile High last week, though? You know, we did. But this week, the story is about the companies that did not get their names. Oh, so Great West Financial, also known as Empowerment Retirement, they ended up winning.
Right. But there were some losers here as well. Well, I don't know if they're losers that, you know, runners-up maybe, people who didn't end up getting their names on it anyway. Kaiser Permanente and FirstBank, Colorado's Bank for You, were contenders apparently for the naming rights, but for whatever reason did not go forward. Yeah, someone had put in some Freedom of Information requests to see the email for the government group that runs the stadium.
And the emails they got showed that those 2 companies had both sent requests asking what, you know, what it would look like to do a sponsorship. So it could have been First Bank Field or Kaiser Permanente Stadium, something. I don't know. There was also, you know, a lot of hubbub when the naming rights discussion first started about whether a marijuana company would potentially try and get their name on it. I think Native Roots was one that really wanted to get their name up there.
That would've been funny. Oh my gosh. I'm gonna share this thing that hopefully my kids aren't listening for this part. So I was just cruising through social media earlier today and I saw a post that a pornography company had put in a $10 million bid to have the naming rights for a stadium. And it was Bang Brothers.
Oh, you know what? You see this? Now that you say that, I believe I saw that headline as well. So, so speaking of inappropriate companies on stadiums, there we go. But I believe that was for Miami.
So maybe it would've been appropriate. Maybe more appropriate in Miami than Denver. Yeah. Why don't we go ahead and move along? We talked, man, it seems like maybe a year or two ago we talked about these, Old Spaghetti Factory in downtown Denver closing.
And we talked about maybe there's gonna be some kind of mini golf coming in. Well, the, the news is it's, it's come and, and it's about to open, actually opened on last Friday. Yeah. So Urban Putt has opened in that location. They have an 18-hole indoor mini golf course, 2 9-hole courses, and food and drinks and all, all kinds of fun entertainment.
I think people that liked The Old Spaghetti Factory will be happy that the streetcar that was there is still there. My favorite part of this article is there's a quote. Urban Putt describes itself as a mini golf steampunk fantasy come to life. You know, that's my favorite kind of fantasy, Robb. They also talk about some of the holes are going to be created inspired by Colorado landmarks.
Specifically, they call out Red Rocks, Elitch Gardens, and the Denver International Airport as holes. Sounds like a place for a team outing, Robb. I actually am planning to go there for dinner this weekend. So we'll see how that goes. Should be fun.
I'll report back next week. Nice. On a different note, not about mini golf, big left turn here. This is a big turn. There was a story this week in the Colorado Sun, some actual reporting, talking about how there— who was this by?
It was by Tamara Chuang. It was last week's feature interview. Pretty cool. Uh, it was called The Cruel Irony of the Digital Divide, and it was talking about how, uh, there is a big divide between the, uh, the people with money in urban areas and those without money in terms of internet access. And specifically, there's been a big push.
The governor, both Hickenlooper and Polis, have, have really focused on getting broadband for all. And, but when they say broadband for all, what they've really meant is getting broadband installed into all the rural areas where there wasn't great coverage. Um, specifically over the last couple of years, they went from 77% of people in the, in the state being covered with broadband up to 86%. So a really good chunk. But during that same time, there has not been a, a drive to help those who are already in urban areas who already have coverage in their area but just can't afford the broadband.
Yeah. So this talks about some of the programs that are out there, nonprofits that, that help folks get internet access for a much lower cost. Also talked a good bit about, I believe Comcast has a program that, that helps folks, I think for $10 a month or something like that, get, uh, get some high-speed internet. Yeah, there was, there was several different offerings that were, looked like they were somewhere in between like $8 and $13 a month for, for those folks who are, who are low income and, and could use it. So it's cool to know those programs are out there.
And of course, if you know anyone who needs it or you need it yourself, um, I think you should go probably apply. I think you should. Next, Robb, did you know that both Uber and Lyft use Denver as a testing ground for new services? Only because I came to this newscast prepared. That's the, that's the reason I know.
So Lyft in the last several years since 2016, they've debuted at least 6 different programs here in Denver as, as their testing hub. Back in 2016, they created their Express Drive vehicle rental program. They partnered with the city of Centennial for a first mile, last mile, basically to help you get to and from the RTD stations for free. And like I said, 4 other things that they've done in the last couple of years. Yeah.
And Uber, we talked about this, I don't know, maybe a month ago. We had a story about them partnering with RTD so that you could buy your RTD tickets in the Uber app so that you could, you know, take an Uber to RTD and then RTD for part of the way. And Denver was not only the first place, but the only place right now to do that. And as of the article we quote here, they had sold about what looks like 3,600 tickets through the RTD app for, for Uber. Pretty cool.
Um, if you do read the article, there's also an interesting piece at the end, uh, talking about a research study that someone did that is, uh, trying to debate whether or not Uber and Lyft are actually beneficial for us. I think it was something like, you know, 60% of the amount of time that, um, that they drive is not actually with people. It's driving around looking for people and things like that. So beneficial for the drivers or the riders? Beneficial for society more than anything else.
Interesting. Yeah, I definitely think that for as a, as a rider, it's great. I think as a driver, that the money probably doesn't add up. I'm sure that's probably true. All right, moving along.
We have a list. Forbes magazine has their elite cloud company list, their top 100 cloud providers and, or not providers, but cloud security or cloud software companies. You know what that means, Robb? What does it mean? There must be some from Colorado on that list.
There must be because it's not a Colorado list, right? So what do we got? We have 2 companies on there, WellTalk and Guild Education. WellTalk is a healthcare company and Guild Education provides ongoing education for folks that are, you know, say in fast food or, you know, sort of service workers to help them move up. So a really interesting list.
I, I actually ended up going through and kind of paging through the whole list to see what was on there. I struggled to figure out what their criteria were. They didn't, they didn't really get into the specifics of the, of how they judged it. Um, there's some people on the list that I don't think of as a cloud company, like, like Tanium was on the list. And while Tanium is a good company, like, they're not a cloud company.
They're endpoint, they're endpoint company, right? Like, yeah, I guess. Yeah. It would be interesting to know what exactly their definition of cloud is. Anyway, interesting list.
And of course, nice to see a couple of the local companies, uh, called out. Very true. Uh, Coalfire had a blog this week talking about launching their ISO 27701 readiness assessment and certification services. So we all know ISO 27000 series are there, like security and IT series. But what is the 27701, Alex?
So this is something that builds on top of the ISO 27001/2 standard, and it is for protection of PII privacy programs. So this is something that you could do in addition to your, your ISMS, which is, you know, what they call the program in 27000. And it, uh, it allows you to be certified for a privacy program as well. So they call it a PIMS, a Privacy Information Management System. And this was actually the standard, this 27001 standard was just released very recently, just in the last couple of months.
And Coalfire, within 10 days of the standard's release, they had successfully completed their initial certification of, uh, OneTrust, which is actually a privacy offering company. So I'm sure OneTrust had an incentive to be ready first. But pretty cool that within 10 days they were able to get their first assessment done. That is pretty cool. I'm also interested to see how popular the 27701 standard is as privacy is becoming more and more important.
I can tell you we've been looking at that at Ping, so it's good. I'm sure it's just going to get bigger. Next, Secure64, our favorite secure DNS company, has announced a leadership change. So, yeah, you know, they have a new CEO coming in, Steve Goodbard, who is a co-founder and he's actually the chairman of the board. He's going to be stepping in to take over as the CEO.
They've had Thad Duper. He's been the CEO for the last— it's a little bit less than 2 years, I think from October of 2017 where he took over. And from the stats in the article, it looks like they've actually done really well over the last 2 years. They've increased their revenue by, I think it was like 130% or something like that. So some really good progress and they've added numerous new customers, but it looks like they're trying to go a new direction.
Yeah, sounds good. Hey, Robb, did you know that you need modern MFA today? I think that this is the time to get modern MFA. I had a meeting with someone today who was a good friend of ours, who I don't know if he wants me to call him out here on the show. And we were talking about security in the SDLC, and I said something about static analysis and dynamic analysis, and he goes, well, modern thinking on that is you'd want to do this other thing first.
I'm like, did you just call my thinking old? So, so I don't know if that's what this article is trying to do, but it could very well be. Well, at Ping Identity, they want you to have modern MFA. So I actually like this article. This, this one goes through kind of giving 4 really easy to understand examples of what contextual MFA might look like.
So if you're logging in at the coffee shop, you probably need to, to have that second factor. If you're logging in at your desk at work, maybe it's not so important. If it's an IT admin, you don't— you want to get biometrics because you really want to be sure who this person is. I liked the way they give some examples and how you might apply this. Yeah, the how and the when and the where.
I think those are all very important. It talks about all of those in the article. Pretty simple stuff. Yep. Next, we have a blog post from Red Canary, and I don't know if you noticed when looking at this is actually a blog post that they did like 3 years ago.
Yeah, I think we covered on the show. We probably did. But, but I actually— but we put it in the notes again this week because it's a really good topic. And the topic is Endpoint security versus network security and where to invest your budget. And this is just like the topic du jour, right?
Like you can get a lot more bang for your buck at the network if it works. But if you want to get full coverage, probably the network's not going to work because people work remote. I know people have bring your own device. You can't get everything that way. Yeah.
Just to be clear, Red Canary did reissue this blog post. It wasn't that we were going to look for old blog posts from 2016. Um, so this was something that they reissued and noted in there that it was from 2016. Uh, one thing that, as an aside, that I noticed in there also, they talked about how great Carbon Black is and that, you know, that's what they see as the, uh, the best endpoint to get their, uh, their information from, which may still be true. But at that point, I think they only supported Carbon Black.
That was all they offered. Yeah. And now they, uh, support several endpoint solutions as well. But anyway, it's a good topic. Um, you know, network versus endpoint, I think, in the past 3 years, I think people have seen the value of endpoint telemetry over network, especially moving to the cloud and remote workers and all that kind of stuff.
So it's still a valued, valuable blog post. All right. Well, that is it for news. We have one more kind of announcement, though. The— so was it 2 years ago, the Colorado Technology Association, as a part of their APEX Awards, created a CISO of the Year Award.
We talked just a few months ago about nominations being out for that. So there's a whole nomination process. People submit it. There's a judging group. Then the judges come up with who their finalists are for the award.
And just this week, they've announced who the finalists are for each of the awards. And Robb, who are the finalists? Well, the finalists for the CISO of the Year, and I'm not going to tell you about any other awards because there's only one award that matters. There's only one that's important. We have Debbi Blyth, a friend of the show and the CISO for the state of Colorado.
She also nominated last year. And also not— she was a finalist last year. And So she's one of the finalists. James Carder, friend of the show and CISO for LogRhythm. Also a finalist last year.
Also a finalist last year. And the last one, I don't know who this is. Alexi Wood. Yeah, I don't know that person either. So obviously, Alex, you were nominated as a finalist and going to be one of our finalists going into it.
Obviously, you're the CISO for Pulte Financial Services in the Tech Center area. So the 3 of you are going to— I believe what happens is during the APEX Awards, you guys go on the stage and you have a wrestling match. Is that how it works? Uh, you know, I have an advantage because I don't have any hair, so I can't have any hair pulled. Um, I, I think I'm almost also the largest physical human of the 3 of us, so that may also be an advantage.
Well, Debbi, I, I, I think she's got some, some sneakiness in her. I, I, she's scrappy. I wouldn't sleep on Debbi. She, she is very scrappy. All right.
Well, congratulations, Alex, to you. Thank you. Congratulations to Debbi and to James as well. And look, look forward to seeing, uh, how that shakes out. It, it's an honor to be nominated.
Um, even bigger honor to be a finalist. I look forward to the awards ceremony in November. All right. Well, moving on, that is it for news. Now moving over to the Slack Message of the Week.
Big thanks to Andre Gaeta. Andre is our awesome sponsor for the Slack Message of the Week segment. As every week, we nominate or we award one person for an insightful or otherwise interesting comment in the Slack channel, and that person gets to pick one item from the Colorado Equal Security store. This week, our winner is Richard Johnson. For sharing a super scary SIM chip vulnerability.
Did you— did— I don't know if you had a chance to see this yet, but, uh, there is some research basically around the ability to send a text to just about every phone in the world that, that, um, will immediately like own your SIM so they can do all kinds of crazy stuff from your phone. Yeah, it gets all the different handsets, your Apple, your Android. Yeah, we're all owned. It's pretty bad. It is pretty bad.
Um, cell phones, the The underlying cell part of the cell phones, no matter how make— how secure you make the rest of the cell phones, they are still 30 years old. So as soon as we turn off the cell phone part of our cell phones, we'll finally be there, right? Exactly. Yeah, exactly. All right.
Well, congratulations to Richard. We'll get you connected with Andre to pick something from the store. Sweet. So let's move over to events. We've got a lot of great events that we want to talk about.
Where can we find out more info about the events? You know, there is an event calendar on the website, Robb. So I bet if you wanted to find out about them, you could go to colorado-security.com. And click on the link for the event calendar. I like it.
First, the CTA is doing their View from the Top CEO panel on September 16th. On the 18th, DENSEC is doing their September meetup. This is the happy hour late in the evening, I think 7:30 or so. They're once again back at the Rhine House downtown Denver. ISSA Denver is doing an education workshop, The Dark Web: An Interactive Tour, on the 19th of September.
Sounds spooky. They should have put that closer to Halloween. Is that sort of like, you know, the Denver Underground Tour or something? Sounds like it. Next, also on the 19th— 19th is actually a busy day, so be ready for more.
ISACA Denver is doing their September meeting. I think this is their first meeting back from their summer break, so I think that may be true. Also on the 19th, CSA Denver is doing their September 2019 meeting. Also on the 19th, ISC² Denver is doing their September meeting, and they have the FBI doing a cybersecurity presentation there. Again, on the 19th, along with the 20th, the NCC down in Colorado Springs is doing their 2019 Cyber Symposium.
Moving over to the 20th, SecureSet is doing a Capture the Flag for Beginners. So if you've been interested in getting into Capture the Flag, here's your chance. On the 21st, the ISSA Denver chapter is doing their CISSP training. I think we got this clarified this week. We are doing Domains 5 and 7, which are IAM and Security Operations.
You got it. Exciting, Women in Security Denver is meeting on the 24th. This is a great group if, if you're either a woman or you know women. This would be a really good event for you to come and help support women in security. Also on the 24th, SecureSet is doing their Expert Series Dorn Cybersecurity Program Boot Camp.
Sounds exciting. On the 25th, ISSA Denver is doing a happy hour. If you just want to drink and talk security, this is your chance. If you also want to learn something on the 25th, ISC² Pikes Peak chapter down in Colorado Springs is doing their September chapter meeting on the 25th as well. ACES Denver Mile High— ACES is the physical security group here in town— they're doing an Understanding the Security Job Market meeting.
So if you're looking for— I think this is probably more on the physical security side of things— if you're looking to understand the job market there or you want to send someone over there, be a good meeting. On the 26th, the CTA is doing their Insight Series. Next Generation Customer Experience Using Data Analytics and AI to Drive Differentiation. It'd be awesome to see a bunch of security people there figuring out how to use security to make customer experience better. That'd be cool.
And then finally, on the 26th and 27th, there's a 2-day event, a Finance and Accounting Professionals Rocky Mountain Area Conference. So this is really relevant for our auditor types who, who need to get some CPA, CPEs and maybe learn a little bit about auditing. And I think all the security people should show up there and tell the finance and accounting people not to fall for phishing emails and, you know, get money transferred to the wrong places. Have you seen the new video from Javad Malik with— so he did the CISSP one a while back. Yeah.
You see the new one? I have not this week. So it's— so they did a parody of the Ride With Me song and it's It basically lost all the money. And it's the finance guy who wired all the money from a business email compromise. And I'm planning to use it for my next finance training for my— inside my company.
I like it. So that's it for the events. Let's move on to jobs first. And again, of note, Robb does not have any jobs this week. Western Union is looking for a cybersecurity GRC assurance leader.
The Secretary of State is hiring a network security engineer. Rakurly is looking for a security analyst. Goldstone Partners is hiring a security operations specialist. DCP Midstream is looking for a cloud security specialist. Terumo BCT is hiring a software security architect.
Shutterstock is looking for a cloud security architect. TaxJar is hiring a security analyst. Demisto is looking for a cloud security systems engineer. And finally, Encana is hiring an IT analyst intern. Hey, good stuff.
Good way to get in. Yeah. Well, that is it for the news part of the podcast. I sat down this week with Serge Borso. Serge is the founder and CEO of SpyderSec, and he's also been really involved with OWASP here in town for years and worked for a couple of the different local companies as well.
Awesome. I look forward to the interview. All right. Well, that's it. And we'll look forward to talking to you guys again next week.
Thanks, Robb. Hi, this is Chad Payne, executive director of IT operations for Kraken Sports and Entertainment. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is Robb Reck, and I am today sitting with Serge Borso.
Serge, you are a, a man of many talents, and we're going to talk through many of those, including the company that you run, your work in the community, and a new book you've written. But before we do that, I want to take it back And I want to understand, what did it take for you to set the record for the 40-yard dash in high school? Oh man, well, first off, thank you for having me here. I really appreciate that. It's a great opportunity.
And yeah, so that was my first claim to fame, the 40-yard dash in high school. I was a senior in high school and I had to run fast from time to time, and I was always a fast runner ever since elementary school. And, uh, so, you know, just happened one day. We were, you know, in gym class and we're doing the regular tryouts for presidential fitness. I always won those presidential fitness awards.
I always stayed really in shape. You could do pull-ups? Yes. The pull-ups were the hard part for me at that time. I still can do those.
Um, I bought a pull-up bar not too long ago, actually. I can still do the indoor mount ones. Yes, exactly. Yeah, I got myself up to about 12. Nice.
I could do— yeah, that was a while ago. But anyway, yeah, 40-yard dash, just, uh, yeah, I could always run really fast. And I did it that day and I set a new record. So was this the record for the school or the— School. Oh, nice.
School record. But the gym teacher didn't really like me and I tried to, you know, make it official like, hey man, by the way, you just confirmed I set the record here. We should do some celebration maybe or something like that. He's like, yeah, whatever. Just penciled it in and that was the end of it.
Never really heard anything about it again. So, you know, moving up to more recently, I understand you also like to do some woodworking and You said you've made desks. That's, that's pretty hardcore stuff. It's true. It's true.
I've made some desks. And where that came from, I was taking that gym class back in high school. I was also taking woodworking shop back in high school. And I'm thinking, since the gym teacher isn't giving me the accolades I think I deserve for breaking this record for the school, you know, maybe I'll make a little plaque in my woodworking class to commemorate it. I never actually went through with that, I don't think.
But anyway, here I am, however many years later. I do woodworking. I enjoy working with my hands and tools. And yeah, I have created desks. I used to work for a company.
I actually brought in a desk because they didn't have the VariDesks, whatever they're called nowadays, for your sit-stand. Exactly. And so I actually created my own desk and brought it in on top of my desk so I had a stand-up desk. Oh nice. It worked out really well.
I used redwood, I inlaid it with slate tile, grouted it, and kind of a maybe weird combination if you're just thinking you know, wood and slate together, but they're not really nice. So it's the most expensive desk, I'm sure. You, you make your own, it's not, it's not any cheaper that way, right? I, I never really thought about the, the cost piece of it. Um, it's just for me, it's something I enjoy doing.
Anytime I've made something with my own hands, I always spend way too much on the wood and way too much buying new tools to do it. And that's the reality of it. Yeah, you got to get a new chisel, a new router, and, uh, I gotta buy a whole bag of grout this one little project I'm doing, right? But with that, it's, it's cool because you end up getting a high-quality product that you wouldn't necessarily be able to go get from IKEA. Yeah, I, you know, for me, it's, it's not just that it's high quality, it's, it's exactly what I wanted.
There you go. It's built to my specifications, you know, exactly the right height, width. It's gonna fit my use case. So do you have your own studio in your own home, or how do you do this? Yeah, I was doing that in my garage.
I've stepped back for a while, but I like what you said. I mean, you get exactly what you want, which it's like a custom-built cabinet. But more to that point, I really like what you said, that you get exactly what you want. And that's— I think that's a key takeaway because you can create and get to walk away with something tangible. And I really like that.
I really like that thought. But like I said, it's been a while since I've been able to do that. I've been really busy with all the other stuff in my life. Yeah. Well, all right.
So let's talk about how you— how did you become a security professional? Where did this whole thing start? Well, I originally came from the Midwest, believe it or not, like a lot of people currently in Colorado. Yeah, kind of migrated here because it's such an awesome state to be in. I knew that even when I was a teenager.
Like, you know, I'm graduating high school, where am I gonna go? What am I gonna do with my life? And it was like, I've heard good things about Denver, Colorado. I've never heard anything bad about it, certainly. So let's check that out.
And I flew out one time to check out a university to go to. Yeah. And basically fell in love with the whole idea. Of what I met out here and moved. And then from there it was, you know, how'd I get started in security?
It was— or technology even, right? Yeah, that's really what it was. Before I even moved from the Midwest out here, it was, I was, you know, in the days of Napster back in the day. And you had, I had friends. So there's a lot of young people listening.
What is Napster? Napster was the original way to pirate content. No, no. To share music and share files, right? Yeah, a file sharing service.
Just before Kim Dotcom and Megaupload, you know, that type of stuff. It was Napster. And Napster, you know, you could, uh, you could rip your CD, you know, go to Best Buy, buy a CD, and rip it, basically copy it and upload it and share with your friends. Yeah. And everyone could start downloading from yours as you're downloading other people's songs.
And there you go. That's how piracy works. Yeah, exactly. Well, I'm not saying I was doing any of that per se, but yeah, I got my start with like Napster, those type of things, or Doom. And patching Doom and patching Quake so you can play without the CD, have it be installed on your computer, that type of stuff.
So there's a handful of people that know that type of knowledge. I mean, you go to school with people or you meet people on the street, only a certain amount of people know how to do all that. So they might come to me and say, hey, can you help with this? I want some of these songs, or I want whatever the case may be that I can help out with from a technology perspective. And that's even before I moved out here.
So I had a little bit of background, grew up with the computer, grew up with computers in the house. So I had that background information on how to use IT, so to speak. And then from there, moving out to Colorado back around 2003, 2004, when I made that transition, it was, okay, now let's see how I can parlay my knowledge into a career. So was it coming— did you come out for school or a job or both? It was school.
It was school specifically. It was to start a new life, is really what it was, because where I grew up, it wasn't— there wasn't a whole lot of opportunity. Sure. Quite frankly. So I wanted to, you know, start my life and go to get a degree and start doing what I wanted to do.
So what kind of— where did you land for school? I went to Johnson and Wales University. I don't think I know Johnson. I've heard the name, but are they— aren't they like a remote university? Do they have like Denver presence?
Or am I— they're on Quebec and I-70. 70-ish, actually Mountain View Boulevard. Okay. And, uh, in Quebec, they have a campus there, and they're known for culinary arts. Okay.
I didn't go there for culinary arts. I went there for business administration. Okay. And I was paying for it out of pocket in cash because by the time I, I was 18, I moved out here, I had amassed money. I'd saved a lot of money.
I was really good at saving money. Yeah. And I had the money to pay for it for like a couple semesters, and I was like, oh, this isn't really going to work long term. I can't afford this. I could afford like one semester.
So that didn't last too long at Johnson Wales, but I did get a job there working part-time in the IT department. Oh nice. Imaging machines, and I was learning about hardware more and more from people who are much more educated, smarter than I was. And I kept on learning more and more about computers. So you got the job of doing like the desktop support type work for Johnson Wales.
Exactly. And, and you dropped out of school there at some point and just were doing the job still there? Still, they wouldn't let me because It was, uh, you had to be a student to have that job. Okay. So I think I stuck around for another semester while I was taking like one class, and, uh, I couldn't last because like I said, it's paying out of pocket.
I wasn't smart enough to like, oh, I have to get a loan and cosigner and all that stuff. I'm 18 years old, you know. Math is hard too. Yeah, well, yeah, that age, yeah, there's challenges.
So yeah, I kind of took it from there, and, you know, I had that passion though at that, at that age. I kind of already knew what I really enjoyed doing. Yeah. And from there I just took it to the next level, if you will. And yeah, so what was next?
I enrolled in another college and got a cosigner and got some loans. Yeah. And stuck it out, um, quickly. Okay. Very quickly.
Like, I graduated in literally— not like, I graduated in 26 months. Wow. Zero to finish. That's amazing. Good for you.
Where was this? Where'd you go? The now defunct Westwood College. Okay. I don't think I knew what— did they— they were a for-profit that went out of business during that?
Yeah, exactly. Yeah. Okay. Yep. So that was that.
But my master's degree is more reputable. It's from CTU. Nice. But yeah, so I went to Westwood and got in, got out, got my degree, and then immediately got a job. Pretty much.
What was your degree in? Was it still business administration? It was e-business management. E-business. E-business.
Electronic business management. So I was doing website design and some IT and security. We had Windows Server 2003 boxes and some C++ coding. And so IT stuff, and then with a focus on business, like for e-commerce. Yeah, that's really what it was.
So 2006, 2007, you got out with your degree right before the economy turned to poop. Yeah, 2006 I graduated in December, I believe. Okay. And And then within a couple months I had a job in 2007. What was your first gig?
The first, my first real one, I was doing stuff before that on and off, but the first real one was actually at, I wanna make sure I enunciate this properly, Harland Financial Solutions, not Heartland, the big data breach one. Yeah. It was Harland. Did I know this? Did we ever talk about the fact that you worked there and I worked there?
Yes, we did. Okay, so you were down on the tech center over Easter, of 25. That's exactly where I was at. Yeah, yeah, it was cool. And so Harlan acquired Cavion, and I was with Cavion.
And you worked with Alec over there at the time? Yeah, Alec Johnson and Jeff Marshall, Jason Marshall, all those guys. Great, great smart people, brilliant people. That was a— that was really a defining moment in my life, in my career path, because of the tremendous amount of talent and smart people I got to work with. Like, yeah, we just mentioned those are really smart people.
Yeah, I learned so much from all those people over there. So how long were you there?
3 years, I think. And were you doing security or IT or both? I started in web development for that company. Okay. And then one year later, I transitioned into security on the security team.
Yeah. And the reason, the reason why is because I love security. I always had a passion for it. And at that point in time, Heartland had this awesome opportunity where you could do the tuition reimbursement. So I was going to get my master's degree at CTU and they were paying for it.
And then I graduated with my master's degree and said, hey, by the way, Cavion, Harlan, guys, I would love to transition into security if possible. Of course, there was a position that was open and the timing was serendipity, if you will. And just smoothly transitioned right into that for another 2 years. I stayed there until I didn't have to pay back the student loan or the tuition reimbursement anymore. And it's like, okay, give me— I think I'm worth a little bit more money now at this point in my career.
Sure. And I left. I got more money. You're ready to do your next thing. Exactly.
All right, so you were ready to move on. Where did you go next? I followed Vince Gramarne's lead, and Vince was in charge of security over there at Harlan. And he went to a place called Nelnet. And the Nelnet Student Loan Company organization.
And I followed suit with him. I mean, he was a really great leader that I've always respected over the years. And it seemed like a logical choice to make because we had that rapport and that, that, you know, respect. I was like, okay, we got a new opportunity over here. Let's go check it out.
So you were Nelnet. They're down the south side of town as well. So correct. Pretty, pretty close. It wasn't too far.
Yeah, it's like 225 and Parker Road. And the only thing I knew about Nelnet was I had an outstanding student loan with them for a while and I didn't like them. That's the only thing I knew. I used to drive down Parker Road going north and see the Nelnet sign on the logo on the building. It's like, I don't like you guys.
Because they want you to pay them back. That's exactly right. I was like, I don't know who you are very well. I know I don't like you though. That's the only thing I knew about Nelnet.
And then next thing I know, I'm applying for position. I'm doing my fingerprints. And my FBI interview, and the FBI person come to my house and talk to my neighbors about me for my clearance. You had to get cleared for Nelnet, huh? Absolutely, because of the Department of Education contract that Nelnet has.
Okay. They service all the student loans. So what was your responsibility there at Nelnet? What'd you do there? Security analyst for about a year, and that was one of my first cool projects there was actually getting rid of all of our SSL version 3.
Poodle come out or is about to come out somewhere around that time frame. And we had to disable SSL version 3, but it wasn't easy because it wasn't just like, oh, you're a security analyst and you're in charge. No, I didn't have any access to the firewalls other than view only. I didn't have any access to the servers. I couldn't physically do it myself.
So it was more of a, I need to work with the teams at that company, the disparate teams across all the different business units and entities and websites we own and domains we own and servers and locations to get them to do it to their systems. That was one of the first projects I had. And then within a year, I was promoted to a senior security engineer and moved on to IPS, intrusion prevention system, intrusion detection system, penetration testing, more and more of that type of stuff. The vulnerability scanning, vulnerability remediation program, and more stuff than I can even think of right now. A significant amount of work that my, my several years of experience before that had really done a good job of preparing me for.
So I could come in there, hit the ground running, and really take the reins, if you will, to meet the objectives of the organization. So how long did you, did you stay there? I was there for 8 years. Oh wow, that's a good run. It was.
Holy smokes. Best company I've worked for in my life. It was awesome, awesome job underneath With Vince's leadership, we had complete freedom to do what we needed to do to secure the company. That meant complete run of the land, basically. We had the backing of management to get stuff done.
We could basically say, this is the project we want to go with. We want to implement IPSs, or we want to implement whatever it was, a security awareness training program, and we could go from 0 to 100% complete it fully, very high quality, set our own timetables, and just feel like you're really making a great impact. And that was going back to the woodworking thing we talked about to start this podcast off with. It's like you get to create something, then walk away with a tangible, wow, I just built this and it's awesome. And that's how it was at Nelnet for many, many years.
It was just, like I said, the best job I've ever had. So you were there for 8 years. That's, that's, that's pretty good for, for this line of work. Why in the world did you ever leave? That's a great question.
Yeah, it was. So I was getting paid very well. I was getting respected, treated well. I could do whatever I wanted whenever I wanted, and in a very respectful way that I mean that. I mean, it was just awesome.
Yeah, I worked from home, worked remotely, travel if I wanted to, didn't travel if I didn't need to or didn't want to. It was spectacular. Together. And so how do you walk away from something like that? They gave me everything I needed and wanted to be successful and happy.
And the answer is SpyderSec, the company I created. And it was after years and years of doing what I've been doing, I reached like the 10-year decade mark of being a professional of doing information security from system security, application security, penetration testing to enterprise security to so on and so forth. And it's like, yeah, I love what I do. And this is my passion, and now I'm gonna start my own company. So how did I walk away from it?
It was building my company with total permission from the people I'm working with at my— at Nelnet to say, go ahead and start it off, and if you want to stick with it, stick with it. If it fails, it fails. If it's successful, successful. And having that backing and support to go ahead and delve into it feet first. And, and what happened was SpyderSec has become very successful, and to the point where it's like I can, I can walk away and focus on what I love to do for myself.
And that's how I did it. So let's, let's go to the very beginning when you chose to start a side company. Like, what was going through your head that made you think, yeah, I want to add a bunch more work to my life? Talk me through this, this thought process. So a big piece of it was how I could help Nelnet secure our own customers, our own users, our own business.
Units. If I can add more knowledge and get better at what I'm doing with other opportunities such as my side company, then I can take that knowledge back to Nelnet and make them more secure too. So it's kind of the win-win type of situation there. That's kind of the mentality I took when I embarked down this journey because the end goal is the same whether it's my own company or a company I'm working with or for. I want security to become more tight.
I want it to become better. So it doesn't really matter who I'm working for. That's my— that's my overarching goal. So if I can get more knowledge over here in this area and bring it back to home, then we're all getting better because of that. So what kind of work did you do in 2015 when you started doing SpyderSec?
What kind of work were you doing? I chilled. I played it cool. I didn't try to bite off more than I can chew. And I got my paperwork in order.
I got all my red registration for like your ITIN number and how I'm gonna do proposals, how I'm gonna do contracts, and how I'm gonna make sure that I know what I'm doing on the kind of the operational backend paperwork side. Because I already knew how to pen test, I already knew how to do all the professional things I've been doing for, you know, 10+ years at that point in time in my life. And then it was just a matter of how can I make sure I'm not gonna screw up these other things I'm not really that familiar with yet. So I did not go out and hire a salesperson or take out a loan or anything like that. I just played it cool.
I was just like one step at a time and that's how I did it. So 2015, 2016 even, it was like a couple gigs here, a couple gigs there, make sure I'm making my customers happy, the ones that I do have. And how did you find your first customers? Um, good question. I think a lot of it, some of it maybe from just being more of a vocal voice in the community.
So OWASP meetups, ISSA, even speaking at conferences, things like that. So I just try to get my name out there a little bit more. You go talk at a conference, it says SpyderSec on the slide somewhere, and somewhere people hear— maybe, yeah, people hear what you do and they reach out. That was it. Because to this day, I mean, sales isn't usually a huge focus of us.
I mean, it's usually recurring customers. They love what we do. We kept on getting that business. Coming back to us. And that's a big— it's that and word of mouth, right?
Yeah. So 2016, you're, you're still going pretty slow there. Absolutely. At what point did, you know, did you see it going from like a couple of projects here and there to starting to see some momentum? 2017 got some momentum.
2018, I was doing very well. Um, as far as, you know, if you compare my salary to my secondary salary, it's like, oh, this is— this could be just fine. Okay, and you do that for a couple years and it's like you get the confidence, you get the savings, and it's like, I can, I can make this leap now and not be too concerned. Were you able to like replace your full normal salary through the side work stuff? Okay, that's your nodding yes.
Yes, sir. For those listening at home, it's a nodding yes. And that obviously, like you said, makes you feel really confident that if you can do this on a part-time basis, what happens if I'm gonna go full-time at it? You know, it's like, oh, the opportunities that will arise. And that's the reality of it.
It's like, if I can do this as a part-time gig, not getting much sleep, you know, because I've still got a full-time job and all the other duties I have, it's like, if I'm dedicating— and the other thing is, if I'm gonna be true to myself as an entrepreneur and as someone who has the passion for this, I have to kind of let go at some point and dedicate this, dedicate 100% of my time to. Otherwise, I'm not really being fair to myself and the future me. So, you know, 2017 timeframe, 2018, things start picking up. Were you still one, a one-man shop, or you have, you have salespeople helping you, or help to help anybody helping you deliver? Right.
So the answer to that is, at that point in time, and even to this day, it's kind of similar where I'm, I'm kind of the main person. I had a partner, have a partner Shannon, and he's much smarter than I am. I met him actually back at Harlan, so I've known him for all these years, and he helps out when there's need to, need to be. And then contractors, so people I've known over the years, and kind of like you, you meet some people, you keep those contacts, you have respect for them if they're really high quality at what they do. Then in my situation, I reached out to them and said, hey, I got a big pen test coming up or this big engagement I need some help with or an RFP I need to make sure I have people lined up to help out with, and do the background checks.
I already know who they are, they're quality, but do your due diligence, make sure they're good to go. They help out, and that's where I'm at to this day. I've also started a program with SecureSet for apprenticeship, an apprenticeship program. So I teach core at SecureSet. And what does that mean, teach core?
Teach core. So SecureSet has like a Hunt program and a Core program, and Core is more hands-on, in-depth, if you will. And that's the 20-week program, right? There you go. Versus the Hunt program 12 weeks, I think.
Yeah, that sounds about right. So it's the more in-depth— now when you say you teach core, you're not teaching all of the courses there, right? Definitely not. I authored 2 of them. I authored NET 300 and NET 400, which is application security, and I teach those classes.
I try to teach those every single cohort that comes through. I don't always have time to, but it's great. With that, I get to meet the up-and-coming talents, and sometimes you get some really, really great students. They're all great students, But you know what I mean. Sometimes you have some people that are just head and shoulders above the rest.
And I'm thinking, you know, I have some positions I might want to be filling here at some point, and I want to see what I can do to help out the community and, you know, work with SecureSet for that partnership. And so Brett Fund and I came up with the idea for an apprenticeship program where we'll have a student from SecureSet and they'll fit right into SpyderSec. What does an apprenticeship look like? What's that What's that mean? So still being fleshed out.
We do have— I have one right now, and he's been going through the program. It's a 6-month program, and what that entails is basically working on security projects with SpyderSec. So we meet, try to meet once a week physically and talk about kind of the goals and objectives, make sure that the apprentice has what she or he needs to be successful, and I'm meeting kind of their goals and they're meeting my goals while I'm giving them work and paying them. Them to do jobs. Nice.
Yep. So they're getting that hands-on— it's, it's a lot like an internship except, uh, is there just more one-on-one time? How would you say this differs from an internship? Different name. It's called an apprenticeship, but very, very similar.
Very similar. I think it's, yeah, pretty much exactly the same. Okay, awesome. Um, so I do want to definitely hear about this new book. I saw on LinkedIn recently that you, you published a book.
What's that about? So the book's called The Penetration Tester's Guide to Web Applications. And all the way back from the Harland Financial Solutions days, doing— it was online banking, e-commerce for online banking applications. My job was to make sure the application was secure, quite frankly. So it's like, yeah, you take all those years of experience doing that stuff and then doing it for other companies as well.
And that's become my specialty as a SANS instructor. I'm teaching SEC542, Web App Pen Testing and Ethical Hacking, and DEV522, which is the defense side of web applications. And it's an area I know a lot about. So thinking about writing a book and this conversation about the book, it's like the publishing company came to me. They reached out to me and said, hey, it looks like you might know something that could be useful.
Which company reached out? Artech House Publishing. The publishing company is called Artech House. Okay. I'd never heard of them before and I'd never heard of the contact who reached out, but, uh, they said, hey, it might be an opportunity here for you to write a book.
I said, okay, that sounds interesting. I'm super busy right now. And by the way, they told me you need to come up with, uh, some ideas for topics. Yeah. For the book.
I was like, okay, well, like for what the book would be about? Exactly. Or like the chapter? Okay. No, what the book would be about.
Okay. I was like, well, if I'm gonna write a book, I, there's only one thing I can write about. It better be something I know really well. It better be something I, I'm expert in, or a field, you know, I know a lot about. Yeah.
So that's where it naturally came from. It's like, that's kind of my area of expertise. Sure. Among others, but that's how I feel pretty strong there. So when did they reach out to you?
Maybe June of 2018-ish. All right. So just, just over a year ago. And what was the process for you? You said, hey, this is a good idea, but writing a book, I mean, that's a lot of work.
How did you, how did you do this? Right. Writing a book is a significant amount of work. So What I did was I said, hey, this is great, a great idea. We did some back and forth contract negotiations and I said, okay, this, I can start in like 4 months from now cuz I'm super busy.
Yeah. I can dedicate some time. You were still working at Nelnet then, right? Was I? Yeah, I was.
I was. And my own sign company. And it's like, I don't have time for this. I have no time. Yeah.
So a lot of sleepless nights to just to be real with you and, yeah, and the audience out there. Yeah. I mean, if you want something, you gotta push really hard to pursue it. So that's what I did. I lost a lot of sleep, or, you know, I just didn't get it, and worked really hard to write this book.
And the biggest pain point is it wasn't just me writing a book and coming up with sentences and paragraphs and making them flow together and examples. It was I had to format the images in the book and have the left-hand alignment and the page numbers and the title of each page. I had to align all that stuff myself. So the publisher doesn't help with any of that? No.
I tried to negotiate that in the contract. It's like, hey guys, I can write a book. I'm thinking in my head, I'll just use Microsoft Word, open up a new Word document, and I'll type it up, and I'll send in the PDF or the Word document, and they can adjust it as need be. Right. No, no, no, no, no, no.
I'm like, they said, you gotta use TeX, LaTeX, T-E-X. I was like, what the heck is LaTeX? What are you guys talking about? So I'm Googling it. I'm like, oh dude, seriously?
You guys do that. I'll write the book. You guys are the publishing company. You guys can figure out— they're like, no, that's not how it works, Serge. You're gonna have to do that yourself.
So what value do they offer versus just self-publishing on Amazon? I don't know. I couldn't tell you. Okay. I really couldn't tell you.
Well, now that's a crappy answer. I'm sure there's a lot of value in it. I just— I've never self-published, so I can't speak to that. Okay. They publish a real physical hardcover book.
I know that piece, and they help with sales. They have promotions and stuff. There you go. There's, there's, that's a better answer. Marketing and getting your, getting your word out to their, their existing pipeline.
There you go. Exactly. And there, this is available in the UK and Australia and then North American markets and so on and so forth. So they help with that whole component of what really goes into publishing a book and the copy editing and, and all that stuff. So yeah, a bunch of humans looked at it, they checked it out, made sure it was technically high quality because it wasn't just editing, make sure you don't have typos.
It's editing, make sure the is relevant and some other security professional has looked at it. Peer review. There you go. Yeah, that's the word I'm looking for. Yeah, so, so they— so you just published, right?
When did this thing actually go out to the world? July 2019. So beginning this month is when it's officially released. And do you have plans? Is it gonna be a textbook for SecureSet in the future?
You're gonna teach from this? That'd be cool. If I can get into all the colleges and universities in the United States, that'd be great. But no, online Exactly. What I based this book off of was the OWASP Top 10, so the top 10 web application vulnerabilities, and that gets updated by OWASP about every 3 or 4-ish years.
So I'm thinking next one of those might be released in 2020, so I'll update the book accordingly, and at that point maybe try to push it more to other niche components in the community because it's not necessarily a textbook that you can just go in and and it's going to teach you everything you need to know. It's a specialty. It's penetration testing for web applications. But that's what the world is right now. I mean, not to say that there's nothing else to pen test, but that's what a lot of people are looking for, right?
Web application pen testing. APIs, mobile apps, web applications. Do you go into APIs at all in there? Not much. Just the web app itself?
Just the web app. We don't talk about mobile. I do talk a little bit about APIs in the book, but that's not a huge focus. Of it. It's the OWASP Top 10, how to find it, how to exploit it, here's some examples, and here are some hands-on labs.
People don't know that. Nice. You buy the book, you got access to labs for free. So everyone who's listening, well, of the people who are listening, who should most go pick up this book and read it? Who's the right audience for that?
The right audience for that would be people penetration testing right now or want to get into penetration testing or people who want to take a closer look at assessing the security of their web applications specifically. Yeah, that's great. So I'm just thinking, like, there's, there's got to be a part of you that's just like, hey, I just, I just wrote a book. That's pretty awesome. Like, you know, bucket list type of a thing to accomplish in your life, right?
That's pretty awesome. What else do you get from this? What's, you know, I'm guessing some marketing for your business. Hopefully this, this helps your business bring in some customers. It'd be nice.
No, I haven't really thought about this. It's crossed my mind, but But it was going back to the contract negotiations with the publishing company. And I'm thinking, how much effort is it gonna take? I have to learn LaTeX, whatever that is. How much am I gonna get paid for this?
Is it worth my time? These are real things you have to think about, you know, 'cause time is money. I don't get to dedicate time for free. And they're, you know what they told me? They said, this is your first book and it's really about the prestige.
It's like, oh. Okay. It's the bucket list, right? It's the— that's what it was. Yeah.
Like that's, that's why people do this. This is why authors who've never written a book before write their first book is for the prestige. Yeah. So don't expect to get rich off of it, which never went through my mind at all. Don't expect to, you know, get more sales for my company off of it, which would be nice, but I'm not anticipating that either.
So it's, it's just, you know what really another big driver for me for all this was? SANS. Hmm. I'm still, working my way up to becoming a certified SANS instructor. Okay, I'm a community instructor.
I've actually just recently got promoted to certified instructor candidate status. That's why I still have several more runs. Probably if I'm lucky, it'll be next year I'll get certified finally with SANS. It's taking a very, very long time to become certified, a certified SANS instructor. And now with this one more thing underneath my belt, that's one more thing of saying, hey everyone at SANS, by the way, I just wrote a book.
Maybe we can— on the thing that I'm teaching. There you go. There you go. So that was a big driver, just, you know, to get that vector background information. That's awesome.
So what is, you know, what does 2020 look like for you? What, how are you planning to, to move forward from here? So moving forward from here, I really want to focus on maintaining and not a huge amount of growth yet. I'm still playing it cool with that. I don't want to get in over my head.
You know, SpyderSec's been— SpyderSec has been debt-free since day one, been profitable because I had the secondary job at that point in time. But, uh, no loans, no taking out, getting in over my head type of thing. I want to make sure that we keep the, the grassroots efforts working smoothly and continue to improve the current services that we have because we only focus in on a few different things and it's penetration testing awareness training and some discovery services. That's it. We're not trying to be all things to all people.
We're not an ASV or we don't have QSAs. We're not doing anything like that. We have very narrow focus. So I want to make sure that kind of like as someone writes a mobile app or an application, it's like it's never done. You release version 1.0, then 1.1 comes out and 1.2 and so on and so forth.
I think it's the same general idea with the business where it's like I have these services. I want to make sure that they're the best they possibly can be. And just make sure that the customer gets the best quality experience they can get. So you're also involved in the community. I'd love to hear— I know you're the president of the OWASP chapter here in Denver.
Why don't you talk a little bit about what that group's about and what you do there? Sure. So I was recently voted in as the president of the Denver OWASP chapter. I took over from Matt Shufeld and Steve Koston before him. In a long line of great leaders, quite frankly.
And those are some really smart people that I admire a lot. And what we're doing here at OWASP is we're really trying to just educate the community on best practices for securing applications. That's really what it comes down to. But with that, it's not always application-focused. So I talked about the OWASP Top 10.
I wrote the book based on the OWASP Top 10. And for anyone not familiar, it's the Open Web Application Security Project. That's really what it comes down to. It's free open source type of software and solutions and checklists, cheat sheets, that type of stuff for basically securing your application, whether it's a mobile app or an API or a web app. And what we're trying to do at OWASP is keep that community involvement going, make sure we're getting a bunch of people showing up to our meetings all the time.
So tell me about your meetings. How frequently do those happen? We're doing every other month. Okay, and we just had one this month. We— and then July.
Exactly. Sorry, July 2019. And so you have one in September. There you go. And are you moving them around now?
It looks like— now, yep, looks like it used to be at Chinook Tavern and then it was at Dave Buster's for a while, and this last one was downtown. Exactly. So we were at Chinook for— it feels like probably a year, maybe a couple years. Yeah. And then we— it's down south, so Chinook Tavern's like Arapahoe and I-25, which isn't convenient for for anyone who's not in that area, in the DTC area.
So we, we were very lucky to have spectacular sponsors in Solutions 2. Yeah. And they sponsored us for years, you know, Jeff Kowalski, Mick Welling over there at Solutions 2. Great, great partners. And we moved up to, like you said, Dave Buster's off I-25 and Colorado Boulevard.
We were there for years as well, I think a couple years. And now we're trying to make sure that as we continue forward without necessarily that same sponsorship, because Solution 2 isn't able to do it right now, that we're still able to kind of meet the need of the people. So that means moving downtown, trying to find a little bit cheaper stuff to do, and still looking for partnerships and sponsors. So do you know where you're gonna be in the September meeting? Not right now.
Okay, still looking for the location. Yeah, the last one we were at was right downtown like you mentioned. I think it worked out okay. I'm still getting some feedback from people to see if we'd want to do that again. The price was right, but now you're downtown.
If it's a ballgame going on or something, hard to park. There you go. It really is. So how many folks do you normally have coming to your meetings? I know you guys have got pretty big.
We have gotten big. Back in the day at our peak, we had 120+ people showing up regularly. And then that seems to trickle off kind of in the summertime months. And we didn't have anywhere near that this month. But we hope to keep it around 100 people.
Would be nice. And I know you guys have a big conference you put together, I think in conjunction with the Boulder OWASP chapter, right? The SnowFROCK event.
What does SnowFROCK stand for? I know Front Range OWASP Conference. I don't know what the snow part of it is though. So what's that event? Yeah, the Front Range OWASP Conference, and it's our annual get-together for our chapter, so if you will.
Rocky Mountain Information Security Conference. It's a big conference like that, not quite at that scale, but we've been having great success down there at the Cable Center the last few years. It's a great venue. Yeah, it really is nice. It really is.
It's kind of the culmination. So we do, like I said, every other month there's an OWASP meeting, and this is the culmination of, okay, let's get everyone together, get a huge conference going, get some really good food, really good speakers, and just have a great time. This year you guys had Troy Hunt Sort of.
So Troy Hunt is a big journalist slash researcher, Have I Been Pwned owner, who was supposed to be a keynote, and then travel kind of got in the way, right? Snow got in the way. So we lived up to our name with SnowFrac. Absolutely. He was such an awesome guy for coming out and making it.
He was stuck in California. I mean, he's from Australia, right? Everyone knows Australia. That's quite a distance to travel. But he came in and he did it.
And he got expanded over there in Los Angeles. Yeah, it's talking LA because they wouldn't take him into Denver with the big snowstorm we had. He made it though. He made it towards the end of the night and he did this talk and we hung out afterwards, got some good sushi. And for anybody who stuck around, they got to see him.
But yeah, he was our— he's our big keynote from last year. Yeah, that's awesome. Well, you know, any other engagement stuff from the community you want to talk about? Wasn't there one other group? Oh, you're teaching for SANS.
That's what I was thinking of. Anything else you want to share with the community about what you're up to? Yeah, SecureSet, SANS, OWASP, yeah, SpyderSec. If someone wants to reach out to you, how should they do it? linkedin.com/SergeBorso, or I don't tweet very much, but I'm starting to do it more so.
What happened was when I wrote that book, I told you about the free lab access. Yeah, well, I'm thinking, how do I want people to contact me? Do I— how am I gonna do the authentication for this? How am I give out credentials? And hold on to all this stuff.
Yeah, security, you know, you know all about identity a little bit. It's like, I don't want to have to keep people's passwords and hash them, and that's the security. I don't want to deal with all that. So I'm thinking, how am I gonna have this contact thing? I know, I'll have them send me a direct message on Twitter, and I'll give them like a token, and then they get an API key with that.
I don't have to store any personal information. Yay! Yeah, so anyway, long answer to Twitter. You can hit me up on Twitter, and now I'm using that platform a lot more. More than I've ever used to, even though I've had it for quite, quite an amount of years now and almost never tweet.
All right, well, awesome. It's really good getting to talk to you and hear your background. It's a pretty inspirational story of going from a security engineer to, you know, CEO and founder of your own company and published author. So a lot of prestige there— CEO and published author all at once. That's pretty good.
Thank you so much, Robb. It's been a pleasure. All right, Serge, good talking to you. We'll talk to you again soon.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.