Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 147 for the week of January 13th, 2020. Alex, how's the first full week of the year gone for you?
Uh, it was a little weird having to go to work all week, Rob. Um, I gotta say, but, uh, I made it through. Takes some getting used to, doesn't it? You know, all this, all this, you know, 5 days of work stuff. It's— I like the, hey, let's get a day off in the middle of the week at least because it's a holiday.
So, you know, it used to be when a year would change over that I would struggle to write the wrong date for a while. I don't write anything anymore. So, so I no longer have that problem. Like when I used to write checks, right? That was a real problem for me.
You don't write checks anymore? I, I don't know when I last wrote a check. You just cash checks? I, I literally just cash checks. That's the most, uh, that's the most cool thing I think I've ever heard.
Yeah. Um, hey, why don't we talk about some housekeeping? Okay, let's do it. Um, we have a Slack channel. What?
It's a fantastic opportunity for folks to get together. Uh, it seems like it's been booming lately. Like Booming. Yeah, there's a lot of discussion going on there. Now that it is 2020, there is a whole lot of discussion in the GRC and Privacy channel about CCPA and other privacy-related things.
Y'all are talking too much for me to keep up. But if you want to join the Slack channel, go out to colorado-security.com and go to that Slack link on the main page, and that'll get you into the Slack channel. Rob, we also have a mailing list. If you go to that same website, scroll to the bottom, there's a place for you to put your email in, submit that, you will get the show notes in your mail. Every week.
So, and you should know, when you subscribe to that mailing list, Alex and I get a little notification you subscribed, and it heartens— it warms our— it warms our heart. It does. Um, and then when people quit our mailing list, it kind of hurts a little bit. It's like a little jab. Yeah, it does.
It does hurt. If you're looking to, to just subtly deliver a little pain in our lives, that's, that's one way to do it. You know what another way to make us feel good is, Rob? What's that? If you go to your favorite podcast service and rate the podcast there and subscribe, so we know how wonderful we are and so that you get the podcast delivered to you in your podcast player automatically.
So for example, you could do that on the Apple iTunes Store or Google Play, which doesn't offer rating services is what I've heard. Spotify, you could do it there. How's our Stitcher process going, Alex? Uh, we're not yet on Stitcher, Rob. Um, I'll get that back on the list.
Maybe we'll get that done one of these years. Uh, another thing you could do to help us out was if you could tell a friend, we'd love it if you'd, you know, send, send your friends to the show. Um, you know, we don't do this to make any money. In fact, We do this to spend money, uh, and we cash in checks, but, but we do get a lot out of it by helping the community get better. Um, so, you know, if you've got friends out there who'd be interested in the content, of course, send them our way.
Uh, if you would like to support us financially and help us pay for this show, uh, we do have a Patreon campaign. We would love for you to sign up for that, uh, throw us a couple bucks and, uh, we'll use that for, uh, website hosting and podcast hosting and all those other sorts of things. Last and definitely not least, we would love it if you'd help us do interviews for the show. We have another guest interview this week from Jason Jaques. And of course, we would love it if you'd reach out and you wanna help do some interviews.
We will equip you and talk you through how to do that. Help us get some great interviews for the second half of the show. So Rob, let's get to the news. Did you know that there are 25 Colorado tech companies that are gonna be at CES that you should meet? What is CES, Alex?
It is the Consumer Electronics Show. And that's where they have Ivanka Trump speak. Ivanka Trump is a keynote speaker. That was a little controversy there. That was something of a topic of conversation on the Slack channel.
It was. So, so this is obviously where they kind of unveil the new tech gadgets for the year. Like you said, 25 Colorado companies. There are a lot of familiar names for us. I was happy to see like CableLabs and Dish Networks, Sphero on the list.
We just talked about them last week. The Last Gameboard, they made— yeah, they made the CES floor. PopSockets. Everybody loves PopSockets. PopSockets.
A lot of stuff we've heard of. I don't know that you can call PopSockets technology. It's sort of technology adjacent. Well, maybe, but, but maybe they have a new thing. Did you, did you actually dive in deep enough to know?
I know that they released a charger so that you can wirelessly charge your phone when you have a PopSocket on your phone. That's not too bad. They're coming, they're coming along. They are. But there was a, you know, so we just mentioned what, 4 or 5 names?
There's another 20 that I had never heard of on this list. So I challenged us, let's go through it and find something interesting. Yeah. I really, I really thought this one, Heart Heroes. So there's a Colorado-based company that makes these super portable, what do you call them?
Defibrillators. So, you know, kickstart someone's heart when they're having an issue. Kickstart my heart. Mötley Crüe, Vince Neil over here. You actually look a little bit like Vince Neil and, you know, the 2020 version of Vince Neil.
He's not looking good. Have you seen this YouTube video recently? I do not have a bandana on, but the recent YouTube video of him not knowing the lyrics to his own song? Oh, I have not. If you haven't, if you haven't seen it yet, for those listening, just Google Vince Neil.
I don't know, you know, forgot lyrics or something. And you see this video where, where he's, he's singing. It's like Kickstart My Heart. I think it actually might be Kickstart My Heart. He just clearly doesn't know what he's singing anymore.
It's fantastic. That is awesome. So anyway, Heart Hero portable defibrillator, pretty cool thing that they're doing here in town. I wanted to highlight a company called Serenity App. Serenity Now.
This is actually a HIPAA-compliant app that helps families and, and elders work together better in elder care. So I think that that's pretty cool. You know, we've had some, some health issues with some of the elders in, in my family, and I think this is something that could really help with something like that. That's awesome. It's cool to know that not only are we building Uh, things to help you hold your cell phone better, but we are also doing things to help people's health and, and well-being ongoing too.
There, there also, strangely enough, were a couple companies on there that, that do wireless gaming headsets. So, well, 2 of those, apparently that's a big thing here in town. Next, uh, story we have is— this is, uh, so Alex, you and I are both transplants. We neither of us were born in Colorado. That is correct.
Um, and apparently most folks here are not going to be born in Colorado. And in 2019, we have the the first time that we have more people— sorry, I got to reword this. 2019's margin of people moving in versus moving out is larger than it's been since 2008. Wow. Yeah.
So this, this last year, this is actually data from the Atlas Van Lines showing they're moving in and out of the state. They have a 55% inbound to the state versus 45% outbound, which doesn't sound like a big ratio, but apparently it's significant. Yeah, that's what they're saying. That puts you in the big, the big growing states. I think Idaho was number 1 on that list for the, the most inbound.
So congratulations to Idaho. Looks like Idaho is up at 62%. And now, of course, I really want to know where the states that they're leaving the most are. And number 1 state where people are leaving is New York. Apparently, that's the state that people want to get out of.
That is surprising. Right behind them, West Virginia, South Dakota, and Illinois. Oh, all right then. Also, if you want to talk about money in the state, let me think of a good segue here, Rob. Speaking of this state, money coming into the state, the— there was an article about the United States of Venture Capital.
This is talking about the biggest venture capital firms in each of the 50 states, or sorry, the most active venture capital in each of the state. Um, and in Colorado, not surprisingly, it was Foundry Group. So I found this article interesting, not because of the words, but because of the picture. So if you're, if you're listening to this because you don't like words, which by the way, I totally respect, um, you should just go to this article and click on the picture of the country. And it has a, on each of the states, it shows a logo or a name for the, the venture capital firm that's, that's biggest there.
And what was really interesting to me is not that Foundry Group is biggest in Colorado. It's that As far as I could tell, and I didn't, I didn't go into incredible depth, but my, my pretty significant looking through this map shows that none of the states actually have the same thing. Each state has a different number one venture capital firm. Yeah. And the also the biggest thing for me was I did not recognize almost all of those.
I don't know that I would necessarily recognize that many venture capital firms, but I think the only one that I recognize, only 2 were Foundry Group And Andreessen Horowitz, which was California. So, and you and I are matched then. Those are the two. Those are the two I knew as well. Yep.
All right. Our next story, I'm giving myself a moment to go over and see what it was. Oh, it was the one about the privacy law. So we have a story here. Is it the, from the Biteback Law blog from David Stauss, who we've had on the show in the past?
And what this is really going into is kind of a nice I'd say moderate depth review of all of the privacy and security laws that are coming on the books in 2020. Yeah, so, uh, it's a definitely not in-depth but a good coverage of lots of things that you should potentially think about from this area, whether it's, uh, CCPA, uh, whether it's, uh, Washington privacy, whether it's other states that are going to potentially have privacy acts, um, and, you know, even some of the, the cybersecurity laws that are being changed in various different states like Uh, New York State, um, really good, uh, overview of, of what's coming this year. So, uh, definitely something to read and use to, to keep abreast of for this year. You know, I would think this is a really good source for those security folks who are not, you know, always into the compliance books. If, if, you know, this could be your once a year where you just understand where, where are things going for the year and, and get a nice overview.
Uh, next we had a press release from CyberGRX. They were named a niche player in the 2019 Gartner Magic Quadrant for IT vendor risk management tools. Congratulations to CyberGRX. I think it's a little unfair because they're, you know, they only do a small portion of this cyber, or excuse me, vendor risk management Magic Quadrant. So they're competing against folks like Archer, Lockpath, MetricStream, OneTrust, who do a much broader set of GRC functionality.
And of course, All that CyberGRX does is, is just the vendor risk management stuff. Um, so they, they show up on the niche category, but, but really they, you know, for what they do, they're, I think they're about as good as you get for, for that kind of consolidated platform for managing all of your vendors. Yeah. And, uh, congratulations to them. You know, first time on the Magic Quadrant.
They're not the company farthest to the left. They're not. They, they are, uh, you know, in that lower left corner, but, you know, moving their way up, I think. Exactly. Next, we have a blog post from Ping.
This is talking about the OWASP API Security Top 10 Risks and talking about how Ping helps address those. So I guess we start off this conversation by saying, you know, we've all talked about the OWASP Top 10 web risks or web vulnerabilities, right? Right. Well, did you even know that there was an OWASP Top 10 API list? Rob, I did.
I do know that it is fairly new. Well, I'm talking to someone like you. Of course you know this. I know everything, Rob. Were you actually one of the authors of that?
And I wish, okay, uh, then I would actually know something about it, not just that it exists. Um, but yeah, they go through, uh, the first 5 of those top 10 on here, uh, being broken object-level authorization, broken authentication, excessive data exposure, lack of resources and rate limiting, broken function-level authorization. And then they sort of briefly touch on the other 5. But it's a good primer on those first 5 for sure. So, Alex, did you know that Ping sells an API security product?
What? I think, I think it's probably coincidental to the fact that the blog exists, but it does go through the fact that, that, you know, that Ping can help deal with those things as well. It is surprising since we've covered Ping blogs for the last at least 2 weeks that have API topics. I don't know how those things keep getting in the news. I don't know.
It is strange. Next, there was a blog from Red Canary A look ahead to 2020. Yeah, so we were going to highlight a couple of these. So basically what they did is they had a bunch of their leaders go through and talk about either, you know, what they did in 2019 or what they're looking forward to in 2020. So first, I wanted to highlight a 2019 accomplishment.
So Joe Moles, who is the VP of Customer Security Operations, mentioned that they that they, being their incident response team, reached a milestone of 10,000 spec/unit tests to validate their detection logic. That is pretty cool that they have 10,000 tests to make sure that they are detecting things correctly. This really sounds like kind of them building off the Atomic Framework, the Atomic Red Team stuff to have discrete testing. 10,000 tests is, that's pretty impressive. It's a lot of tests.
I mean, they could be more like, I don't know why they stopped there. Like 10,001? I mean, it could be like 100,000. It could be a million. But anyway, congratulations to the team.
Of course, I'm kidding. That's really impressive. Good stuff. I did pull out one that was talking about what do you want your team to accomplish in 2020? And I grabbed one from Jeff Felling, who is a director of intelligence there.
What I really liked is that they're looking to make their intelligence really much more consumable for customers, make it easy for customers to integrate into their own systems, and make actionable decisions. I, you know, I think it's just really common that intelligence right now is, um, is kind of freestanding and, and, and siloed out. And the better they can do to make that easy for us to consume in other places, I think the, the more value to the whole industry. For sure. Uh, next we had a blog from Virtual Armor talking about the 8 most expensive cyberattacks in 2019.
I know the top one on the list did not surprise me at all. It's the Cap One data breach. They estimate the cost to be somewhere between $100 and $150 million. Pretty expensive, uh, number one breach. Breach.
Uh, the second one was Norsk Hydro, uh, which they thought was going to cost at least $52 million. Uh, the, the drop gets pretty big from there. We go down to the Baltimore ransomware attack at about $18 million, to the Texas ransomware attacks at $12 million, and then from there kind of drops off into uncertainty, right? I will say the, the Norsk Hydro one is one that's been really interesting to me, mostly because, uh, you know, they are an aluminum manufacturer, and this, uh, this attack affected their manufacturing plant, one of their manufacturing plants. And so they had to run it manually.
If they weren't able to run it manually, then they would have actually had to shut it down. And if you shut down an aluminum plant, you cannot start it again, ever. Once it is started, it has to continue running until you stop it. Why? I don't know the reasons.
But I heard this in several places. So if it would have gotten bad enough that they had to shut down, that they would have had much greater losses than $52 million. So, so this is an interesting conversation. So if I am the CISO at an aluminum manufacturing plant and I have always heard, why would anyone target us? We're an aluminum manufacturing plant, right?
This might be your opportunity to have some data, right? Exactly. Wherever you work, if that's the message you've been hearing, that'd be a pretty good thing for you to know. Next, we have a blog from Optiv. This is the 3rd in their series of the Cybersecurity ROI.
This one's really focusing on revenue opportunities. I'd really kind of summarize this one. They don't go incredibly into depth on, on this whole blog series, but what I found interesting here is it's really about the digital transformation and letting security enable, you know, remote sales workers, enable customers to do online payments, you know, the confidence that your customers will have if you offer them a secure environment. Yeah, it's really talking about how security can enable business, right? As opposed to telling people, no, if you enable business, then good things can happen.
I'll say the one thing I'm disappointed about with the blog is it doesn't actually help you get an ROI, which is kind of what the whole series was about. At least, at least it tells you, you know, these are the areas you can provide value to your company though. Agreed. Agreed. And then the final that we have today was a blog from Route 9B.
They are talking about threat intelligence around the military actions that happen in, in Iraq and in Iran. So this is a pretty good summary talking about what could potentially happen from retaliation via Iran based on the activities that are happening there. They, they talk about some of the malware that they could be used, and then they give a list of 5 recommendations that you could take to help prevent some of these potential attacks. So good stuff there. Should we go through them or?
Sure. All right. So recommendation number 1, disable unnecessary ports and protocols. Make sure we're reviewing security device logs and looking for any unnecessary stuff that's turned on. Enhance your monitoring of network and email traffic since it sounds like these types of attacks, you know, could be phishing attacks and/or sort of scanning type attacks.
Yeah, phishing attacks are just so brutal. Like, Every, you know, you're always going to have some percentage of people who fall for them, and it just makes it really tough. You have to have something. Fire all those people, Rob. Just fire them.
We're going to fire 10% of the people 10 times. We're going to solve that problem. Uh, number 3, uh, patch your external-facing equipment. This is a good idea for everyone. Yes, it is.
Uh, number 4, log and limit the use of PowerShell. Um, your sysadmins will hate you. Yes. You could also exchange PowerShell for other scripting or things like that. But that's a big one that I think people don't think about a lot.
And I would say the last one, which is surprisingly more difficult than it seems, ensure backups are up to date. And I would say, I would add on to this to say, make sure they work. You would actually do some restores from your backups and not just have backups. Try them out once in a while. They actually say, and stored in an easily retrievable location.
Um, that it should be easy for, uh, the appropriate people to retrieve them, but not for attackers to get to them and delete them or corrupt them. It's tough to do both of those things. It is. Air-gapped means really hard to get to. All right.
That was it for that story. That's it for the news. Let's move over to the Slack message of the week. Uh, big thanks to Andre Gaeta. Andre supports this.
Uh, you know, each week we recognize someone who's posted something that was interesting or maybe made us laugh in the Slack channel for the week. And that person gets to pick one item from the Colorado Equal Security swag store. This week, the winner is Jake Barber. Jake posted a very funny diagram. It's a Venn diagram intersecting Cotton-Eyed Joe with incident response.
So incident response, what in the world does that have to do with Cotton-Eyed Joe? I don't know, Rob, why don't you tell me? Well, in both cases, we wanna know where did you come from and where did you go?
So, so the, the only disappointing part about this really funny post, which was in, by the way, in the random channel if you want to see it, is they actually don't have anything in the part of the Venn diagram for Cotton Eye Joe that is not overlapping with incident response. Right. So, Alex, I put to you what should be in that, that circle, that empty circle. I think it should be some of the other lyrics in that song, of which I know none. I think I only know, where did you come from?
Where did you go? Cotton Eye Joe. He rolled into town like a raging storm. Something like that. Rob, like I said, I have no idea what the other lyrics are, so you're welcome to make up whatever they are.
Well, we should at least give some credit to the Rednecks for giving us a culturally significant song. Indeed. Back in 1996, something. That seems about right. Hey, that's it.
Let's, let's move on. That's, that's enough of that. How about some events? We have a calendar of events on the website. You know, we actually got a lot of stuff going on there for the first half of the year already.
Yeah, um, there's plenty of stuff out there. Please, uh, check it out, look for stuff. But also, if you're scheduling something, make sure you're not stepping on other people's toes. Um, so we, we're making up for the fact that we've been super sparse the last few weeks. Uh, this week on the 14th, SecureSet has an intro to data visualization, which I think you should attend, uh, if you like doing security.
Uh, ISSA Denver is doing their January chapter meetings on the 14th and the 15th. Note, uh, if you're going to the DTC meeting, instead of the Microsoft building, it will be at the Oracle building, which is right next door. Uh, also on the 15th in Colorado Springs is the Cybersecurity Summit and Industry Day. Also on the 15th, uh, DENSEC is doing their January meetup. That'll be at the Rheinhaus downtown.
Um, on the 16th, ISC² is doing their January meeting, and this is actually a board election, and I heard a rumor that their president Michelle Pierce is not running. Oh, so I So you could be in charge if you want. I have no idea if there's like some kind of nomination process and now they're just rubber stamping something, which is kind of how ISSA is. Coup! Coup!
But maybe show up with, with 30 of your best friends and you might become the next president of ISC² Denver. Sweet. Also on the 16th, ISACA Denver is doing their January chapter meeting. On the 21st, the Cloud Security Alliance is doing their January meeting. On the 21st and 22nd, ISSA Colorado Springs is doing their January chapter meetings.
Um, on the 22nd, Pikes— ISC² Pikes Peak has their January chapter meeting. We have a trend here, a lot of January chapter meetings this month. Yes, you know what, it's January, huh? All month long, all month long. Uh, SecureSet is doing a Capture the Flag for Beginners on the 24th.
And finally, ISC² Colorado Springs has one of their mini seminars on Saturday the 25th. This is one of those, you know, 4 hours in the morning where you just get some real serious content, get you some nice CPEs. A good way to start off your day. That's it for events. Let's talk about jobs.
Rob, are there any jobs at Ping Identity? Yeah, 2 jobs we talked about last week. We are hiring a Senior Director of Cloud Operations. This is the head of our SRE team, a lot of overlap with security. I work really closely with this team.
I'd love to talk to you if you're interested in getting that job. Send me a note on Slack or email or however you like to reach out. And I'm also hiring a security intern. Well, I've heard we've got a lot of great applicants, but I haven't talked to any yet, so It's not too late to get in the queue and, and wow us. We'd love to have you come be an intern with us this summer.
Sweet. Otter in Fort Collins is looking for a director of privacy. That sounds like a fun job. I heard that there is an interest in someone who has got some broad security experience and maybe even a JD. Oh, Hunter Douglas is hiring an information security manager.
Spectrum is looking for a security engineer 3. One. 1, 2, 3. Uh, uh, uh, uh, vulnerability scanning, risk and threat management. Uh, Staples is hiring a senior application security architect.
DISH is looking for a senior cloud security engineer. Guild Education, this is our friend Julie Ciccolo's team. She is hiring a senior information security compliance analyst. Coalfire is looking for a senior consultant penetration tester. That's a lot of seniors in a row there.
Yeah. And finally, DaVita is hiring an associate general counsel focused on privacy and cybersecurity. So if you don't want to take that, the job at Otter, you could go work at DaVita instead. Seems like that might be a good fit for the same person, right? Maybe you should apply for both and have them fight over you.
Holy smokes. That sounds like a pretty fun idea. Bidding war. Well, you know, Alex, I think that takes us to the end of the news segment, right? I believe that does.
So that is, that is it for news. We do have an interview this week. Jason interviewed Don Klindt and Rob Clark, and they talked about AI and security. That's a great topic. I'm interested to hear about it.
I'm looking forward to hearing it. I haven't heard it yet, and as soon as I hit stop here, I'll go listen. Sounds like a good idea. Right, Alex? I think that's it for this week.
We'll look forward to talking to everyone again next week. Sounds good. Thanks, Rob. This is Josh Ryan, network manager for Ultra Petroleum. Welcome to Colorado Equals Security.
Security, the podcast for Colorado security professionals by Colorado security professionals. Hello, Colorado Equal Security. This is Jason Jaques. I had an opportunity to interview 2 local gentlemen coming off of a nationwide speaking tour on AI and cybersecurity. I thought this might be an interesting and unusual discussion, so here's my interview with Don Klindt and Rob Clark.
Enjoy. Don, Rob, thanks for joining me. We're going to dive into the world of AI and cybersecurity. I know you guys were speaking at some recent events on the topic, so I'm excited about our conversation today. But first, let's get to know you guys.
Don Klindt, you're the Converge Director of Cybersecurity for the West. What does that mean? That's a mouthful. Yeah, just, it means that I've got a lot of things that I've got to make sure are secure across the nation from the Ohio River west So it's great. It's fun.
It's a lot of, a lot of cool technology solutions that we're putting in place, looking at architectures and just helping our customers across the board. Excellent. So how'd you end up in Colorado? So I was in the military in Japan. I was in the Air Force and I got out of the Air Force and decided that Colorado was a good place to come to.
Never been here before and moved here 20 years ago. It's been great ever since. And you've never left. Never left. Awesome.
Yeah, so tell me about your— how'd you get started in the tech industry or security? So I was doing laser-guided infrared targeting navigation systems. There's another mouthful for you, right? In the Air Force. And then whether you're lasing a target or whether you're putting the same ones and zeros across fiber for communications, it all kind of translates.
And I got into comm that way. And then I was doing security and networking and software. So security just made sense because when you build networks and do software, you inherently should be doing it securely. So that's how I got into security from there. Yeah, I suppose you should.
Do you have any interesting hobbies you want to talk about? You know, I love skiing and scuba diving. So being in Colorado, you wouldn't think scuba diving, right? But Colorado actually has the most certified scuba divers out of all the states in the US. That's an interesting fact.
It is, because you'd think Florida or California, but it's because of our our want for extreme sports out here. That's why everybody is certified. So, okay, where, where do people go? Cozumel, Roatán, Belize, right? Still travel out of, out of the state because there's not a whole lot of diving here in Colorado, but right, you're not driving to a lake somewhere up in the mountain and doing some diving, right?
I guess you could, right? You can, right? They, they have a great certification spot out at the Aurora Reservoir. They've got a little sunken plane down there so you can go check it out. But oh, nice.
Most of the people that do their open water either do it in Utah or they go down to New Mexico. Okay. Blue Hole in Santa Rosa down there. So it's like a 6-hour drive, but I'll have to check that out sometime. Yeah, maybe I'll get into it myself.
So Rob Clark, you're the director of Converge. So let me say that again. You're the Converge director of AI and cognitive for the West, right? That is so. That is so.
Excellent. Tell me what that means. Well, it means I get to play with all the cool toys from a CIO perspective. Everybody these days is looking at AI/ML, so we specialize in doing that, especially on the IBM kind of platform. But really, it's about all the technologies that require human thought.
So anything predictive, anything preventative, anything futuristic. So as I mentioned, it's a lot of those elements. I do cognitive automation too, so I try and take the robot out of the human. Some of those areas that people are doing repetitive tasks, want to get them out of that and let them go do what they went to college for or what their skills are. So We do automation.
And then the one I think is probably the most impactful is the cognitive engagement. So that's using things like natural language processing and intelligent agents to put on top of technology. And, you know, I think nowadays we all, because we're in tech and everybody listens probably in tech, we think it's easy. But there's a lot of people out there, probably 90% of the people that don't interact with tech in a logical way. So how do we humanize tech?
Well, use cognitive engagement, right? Talk to it like it's a human. And it can understand you like you're human. So I get to play with those toys and it's a lot of fun. I do it same geography as Don.
Didn't know that we had the Ohio River in there, but it was the exact same territory. Exactly. So you've got an accent. Now, how— where are you from? Arkansas.
Okay. Okay. Yeah. That sounds exactly like Arkansas. Further east than Arkansas.
Yeah. So actually, funnily enough, I was overstaying my welcome by about 32 years. I came over originally for 12 weeks to do soccer coaching for a living, or football in my world. Okay. And after a couple of weeks, met a guy who was coaching at Boston College, an Irish guy, and he recommended that, hey, why don't you stay and, and coach?
So I coached for a couple of years at Division 1, then had my own soccer club in Dallas, and then had a child and decided that, you know, needed to move to somewhere which had seasons because There's only 2 seasons in Dallas, hot and hotter, right? So, uh, moved out here in, in 2000 and have been, uh, ever since. So, okay. And so you're from England? England, northern England, uh, Yorkshire, God's country, if you ever go there.
I have never been there. Okay, should I go there? Absolutely, everybody should go there and then leave. Okay, there you go, there you go. It's cold, it's wet, and various other elements to it.
So you were coaching soccer or football How'd you get started in the tech industry? I played on a men's team who— one of the guys there, in the world of soccer, you're— it's a very evening practice orientated weekend game. So my golf game was great because I played golf during the day, but it was kind of one of those times where, you know, idle hands find things to do. But he said, you know, did you want to try my hand at kind of sales in the tech world? And there was a friend of his that was looking for somebody in IBM resale.
So I thought I'd give it a shot, nothing to lose. And from there, I went from selling old mainframe memory and terminal controllers and wandered my way through VAR world and then into Cisco network, actually working for Cisco in the network world for a long time and then through consulting and here we are today. So quite the meandering through the tech world and through the educational world. Yeah. Yeah.
And so are you working on cognitive robots to play soccer? Yeah, you know what, they'd be a lot more responsive than some of the children I've coached, probably, right? And maybe a lot more accurate. Yeah, trouble is that, you know, it takes the joy out of the game. Half the fun of sports is unpredictability, and if we, you know, put robots in there, it's going to be highly predictable.
So I don't, I don't think that's a good idea. Oh, okay. Do you have any other hobbies? No, I've become pretty much, uh, an outdoorsman thanks to Colorado, right? So ski, fish, bike, run, all the things that you're meant to do in Colorado, keep us the fittest state in the nation.
So yeah, that's kind of where I've developed all my out, uh, extracurricular activities. Fair enough. And I know that the two of you are avid cyclists of different varieties. I actually move on mine, whereas, okay, Don is just pedaling in place, right? Gotta love that Peloton, you know.
Okay, okay, so you're the Peloton guy. Tell me a little about that. I do plenty of miles, but I never leave my basement, so it's kind of nice. There you go. There you go.
So have you won the Tour de France on the Peloton? No, no, I have not. Okay. All right. But those classes are pretty intense, so— Yeah, it doesn't look as good as the people on the commercials for Peloton either.
No, no. Too many sales calls and happy hours at night, so— Right, right, right. Let's talk about the events that you guys have been doing. I'm interested in really how it got started, how you guys came together and started talking about AI and cognitive and the cybersecurity world, and really that nexus, if you will. You know, we were looking at doing separate events, actually one in security and one for AI, and then it just kind of made sense that, you know, when you're doing security and you want automation for certain things for breaches and responses.
We've proven multiple times eyes on glass doesn't work, so you have to have that automation around it. And we could draw more of an audience if we actually started doing this together. So Rob and I sat down, and Rob was kind of spearheading that, saying, look, here's the data analytics piece, and this is what we've got to do for that. So that's how we came together to say, instead of trying to do separate events, let's really tie this together because there are 2 technologies that everybody wants to know about. Everybody's moving towards automation, so let's talk about security and automation and then automation with security, right?
Yeah, and some of that was to do with, you know, in the world of data and data science, a lot of that's access to data. So everybody, you know, the data scientists are all about curation of datasets, and every company wants to be data-driven. You see that all over the place, right? Data is the new oil or gold or whatever you want to call it, right? Well, you know, because data comes in in velocity now and it comes in varieties and volume.
The data science world is now about how quickly can you turn that into actionable insights for a customer, for their company. Well, those type of things mean that the data scientists need automation in their world. They need to be able to get to the data, and it might not be data that's always in-house. It may be in from outside. They may buy datasets, they may curate datasets in the cloud, they may grab them from internal databases or other silos.
And so that's— their world is about freedom and access to get to the information they want. And then talking to Don and his world, it's like not having access to freedom and information when they want it. It's really, you know, difficult. And because data has become so important in the world of business, other things happen. Like if nefarious people want after it, right?
They know that you value it. What's the first thing they want to do? Steal it and stop it from you. So ransomware or attacks, right? Or just take your data and monetize it for their means.
And then on top of that, then when that happens, you see in the news all these breaches. Well, what happens is the government or somebody comes along and says, I'm gonna regulate that because you're not taking care of your backyard. So when we started talking about how data science needs to work and the freedom for data and how the access for data needs to happen, it was then the one thing that really bubbled up to the top was like, They'd love to have the freedom to do that, but the security guys sometimes find that they're at odds with. But when we got to talking, we found out there's a common ground. There is a— the ability to give them access to data that they need, all the people internally, and then also be compliant and be— have the regulations in place and be able to secure that data.
So we just wanted to take the message to the 2 different groups and kind of bridge them together because within an organization, the cybersecurity or the security group tend to talk amongst themselves, right? The data guys tend to talk amongst themselves, and it doesn't really come to a— like you mentioned, a nexus to a single point. There's very few CDOs, chief data officers, out there that might be the conduit for that conversation. So we went out and decided that we would talk to the 2 different groups, get the, you know, them together and talk and say, you know, data guy, you can have what you need, the freedom and access to your data, and security guy, you can have what you need, which is a locked-down, secure data enterprise. So that's really the, the reason that we put the event together.
And what's the reception been so far? The reception's been great. We've, uh, we had a lot more attendees than what we thought. We even had to turn registration off for the one here in Denver. We had to turn registration off for the one in San Francisco as well, so Okay, it's been, uh, it's rather impressive as how many people were actually interested on the message we were delivering.
And different, different kind of groups too. So we've traveled to the West Coast, we did Southern California, Northern California, we had Denver, and then we were in Cincinnati and Indianapolis. And the— what's interesting is the thought leadership on— or not maybe leadership, but the thought process in those different geographies was, was vastly different. Like in San Francisco, it was probably a room full of data scientists and they got a new appreciation for the security elements that were needed versus what they were doing from their side. And then when you went more into the traditional, more heart of America in Cincinnati and Indianapolis, these guys were very much pragmatic, right?
About, hey, I need to lock this stuff down. I know we want to go fast, but we're not that type of company. It's Manufacturing 101 there, right? So it was interesting to get the inputs not from the leaders, the Silicon Valley mindset in San Francisco, but also get to the practicality of how do you implement that in the Cincinnati, Indianapolis side. Interesting.
But you did have an event here too. Yeah, and it was a blend of kind of two of those thoughts. I mean, within Denver, there's definitely a kind of a West Coast mindset a little bit more seeking in as people migrate kind of towards Denver and we have more tech companies here. But it's still a very pragmatic approach here because we talked about data structure and organization, master data management. Most companies on that data journey are not very far along.
So they've not reached the whole democratization of data. So they're going to need help there. But it was still a good conversation to have with those folks here. From the data scientist's perspective, what are they learning about cybersecurity that I suppose everybody ultimately should be learning? So I want to use a perfect example of this— Facebook, right?
The fines that Facebook got imposed for their data being breached, if you will, or their— the fact that they didn't do enough due diligence to protect data turned everybody in the data science world of Oh my God, we're collecting all this data. How are we using it? What are we doing with it? But outside of that, now I'm going to be responsible for if somebody comes in and uses this data inappropriately or if they somehow get access to this large data lake we have. So we have to make sure we've got the correct protections around it to avoid these fines, which kind of starts spinning up the rest of the security conversation of, well, who has access to this data?
What access do these people have, right? Who's using this data? What are they using it for? And now you've got them talking to the rest of the enterprise because they're understanding why they're now kind of responsible for it. Okay, so data scientists need to be aware of who's accessing their data, which I'm sure most of them really aren't thinking, right?
They, you know, traditionally people didn't care. It was get the data out, use it for what you need to use it for, and move on, go to the next project. Oh, one of the things that came out from the conversation was they don't realize that they might be ingesting data from data sources that's already corrupt. And they don't realize that, right? It didn't go through the correct controls from a security perspective.
So they may go out and grab datasets or collect data from cloud or whatever it might be and not realize that, you know, hidden amongst those nuggets of value that they're looking for is something nefarious that can sit on the system for a while and they would be totally oblivious. So what are cybersecurity IT professionals learning from the data science world, the AI world, that, you know, that they should be, I guess, aware of when it comes to their, their day-to-day operations to enable these people to go out and build a better world, if you will. Right. Yeah. I mean, if you look at security as when, you know, back in the early 2000s, even, even before then, when people were really, no, you don't, you can't have access to it.
It's always been least privilege, right? If you don't need to know, you don't need to see this data. As we keep evolving into this world where data is so important, security's got to work to be able to say, okay, yeah, you may not need this data for this, but the business needs it for everything else. So I can't lock it down because the application that you're building is actually enabling the business to do business for whatever they need to do, right? Whether they're collecting data on stocks or data for pharmaceuticals, other people in the business need to see it where traditionally the group that was developing an application would just need to see certain parts of data and then you would lock everything else down.
And now you need to be able to have the right controls around it. And you can't do that as an individual. You have to have automation and pieces in there that can tag this data, allow it to be used for what it needs to be used for, and then make sure it's locked down so when it gets out of that realm that other people can't see it. So it creates a great challenge to where you have to look at automation. It was a good— it was a great awareness, I think, on both sides.
I think the security guys, you know, felt that the more they locked things down, the more secure the enterprise would be, and didn't realize that they were kind of choking off some of the things that the data science guys needed. And I think it was great on the data science side that they didn't realize that the freedom and mobility they needed and access they needed was something that caused consternation on the security side. So like we said, it was a great platform to have this meeting of the minds so that both sides can understand each other. And I would say that's probably prevalent in almost every organization, right? That you have overall and arching corporate cultural values, but then you get into the different groups that have their own measurements or KPIs or just philosophies, and you end up, you know, without knowing the fact that they are competing and one is stopping the other from actually proliferating.
So It was good to raise that and to be able to say that, you know, security can say yes and data science can say yes, and you could be both happily moving along towards a success for the company versus just your own day-to-day business, so to speak. So how did you kick this off, this event? Well, it was interesting so that we had to capture attention in the beginning. So, what we did, we talked about that when you build a company, you want to build it for the long term. So, historically, if you look in the 1950s, a Fortune 500 company would be on that listing of the Fortune 500 for about 60 years.
If you look at the current Fortune 500, they last about less than 20. And you have to look at that and say, why? What has changed that companies don't last as long as they used to? And so, When you look back at when companies were first kind of formed and when capitalism came about, when you talk about Adam Smith's version of economics, he was all about putting the customer first. And so everything that— every capital asset, every will, every resource of a company goes towards making the customer happy.
Along comes Milton Friedman in the mid-'70s and says every will and resource needs to be going back to the shareholders, to the owners. So it was a very different mindset. And so I'm a big fan of Simon Sinek, and he's got a book out right now called The Infinite Game, and he talks about finite versus infinite games. And a finite game is defined as a specific set of players with a specific set of rules with a specific time set and score. So think all the traditional sports, right?
You know, you play for X amount of time with X number of players, the rules, here's the score, game's finished, it's done. Infinite game has players come in and go. So they drop in, they drop out. The rules are more of a framework so you can play within those rules and you can adapt those rules to your game. And there is no endgame.
There is no time limit. And so when you look at business, business is something that is an infinite game. It's going to go on forever. It's going to go on past our lifetimes. It's going to go on past many other people's lifetimes.
So if you're going to build a company that is not measured— that is measured on finite goals, you're going to lose because if you focus on being the winner for this quarter. I want to be number one in the market. Well, that'll be temporary because somebody will come along and disrupt you from being number one. Somehow your revenues will go up and down, so you may not be number one all the time. But you're trying to measure an infinite game by finite measures.
That doesn't work. So when we talk about data and we talk about, um, security, those are core values of an infinite company. So no matter what your company looks like today, 90 days from now, 9 years from now, 900 years from now, you know, whether it's me, my son, his kids go to work for the same company, security and data are always going to be there. Data is an infinite source. Security doesn't have an endgame.
You're never totally secure. There's always new things coming. So you have to change your mindset when it comes to these things. And that's where we kicked it off and said, because data and because security are infinite resources for what you should build in an infinite company, you have to put a structure in place that makes sure that you can use the data when you need it and you can secure it when you have to. So that's how we kick things off and that's how we tried to bring the— or we did bring the conversation together that no matter when these people stay at that company, leave that company, leave it in a better place so that the company can prosper above and beyond just your work.
That now you have left something that is gonna supersede your tenure there and will be there forever. So that's kind of how we brought the whole subject together in the beginning. Awesome. Okay, so what did you guys learn from this experience, from this event? I mean, it's, it's not just about educating other people, right?
I learned John loves specific types of mints at specific types of restaurants. Okay, yes, mints have to be good at the restaurant. That's, that's a very important thing to learn. Okay, no, we definitely learned, you know, learn about Rob and his, uh, soccer coaching. That was, that was pretty funny.
And plus the fact that, um, if you let Rob have the microphone like he does here, he will talk, which is great. Yes, yes. I don't know, it was, it was very interesting to, to learn how people are along on the journey and where different specific verticals are, because we had digital native companies in there, um, right? So you know, Instacarts and those type of ones. And then we had Stitch Fix and some of those ones in San Francisco.
But then we had traditional manufacturers like GE in. So, and then everything in between. So you got to learn really what their philosophy and what their strategy was in data. And what was fascinating to me was it didn't matter if you were born native as a native company, you still haven't solved these problems. Whereas you have had the opportunity to build using modern tools.
And then you go back to— I mean, we had an 80-year-old company that was probably the furthest along on the journey for data maturity and strategy than any other company that was there. So that was a surprise, right? 8 decades of experience, you would think they would be mired in like legacy process, but they changed all theirs. And so they were actually further along than anybody else. So, so it— what I learned is it doesn't matter the company, it doesn't matter their lineage, it doesn't matter the level of expertise that these kind of problems exist.
Yeah, and then all companies are interested in some sort of data security maturity model, right? Just like we all know CMMI levels 1 through 5. When we were talking about what we can do for data, so both Rob and Rob Sinclair were talking about this maturity model for where your data is and what you think about it, and they want this— our customers want to see that first, the security of their data, as well as where are they at in this journey of moving their data to any point since there's no perimeter anymore. How do they secure it? How do they keep track of it?
And then things like GDPR, where people have the right to be forgotten, and CCPA and everything else, where somebody calls and says, get rid of my data. How do these data scientists quickly identify that and get rid of it like they're supposed to per these regulations that are coming out? So it was really cool to see whether it was Airbnb or Adobe or You know, certain health companies that we had there that were just, they all had different ways they use the data, but then they were all thinking along the same lines of, hey, we need to be able to protect this in this form or fashion. How do we get this message to our owners and to our board members so we can actually get this approved, right? And as much as we learned probably from the attendees, I think just the time together, whereas myself and Rob Sinclair, he was the technical kind of lead, Okay, on my side of data.
And that's, that's a different Rob. That's not— yeah, different. 2 Robs, 2 Bs, Canadian, short for Robbie. And then, uh, so we learned— I learned just as much from them. And then the security guys, so Sean and Don on the security side.
So just the conversations we had, we learned a lot about what their concerns were in the data, the, about the data world. And they learned what the concern was on the data side for the security side. So yeah, so I think, you know, just the time we actually had together, we were able to to coalesce a better argument and almost act like a pseudo-enterprise. And like, oh, that's what you'd be concerned about if I did that. They're like, oh yeah, and so why do you guys do that?
Well, that's why we do this in data science, right? That's why we have datasets here, and that's why we have different machines that we want to do this with, and that's why we need to go to these clouds. And like, oh, that's why. So the learnings on our side as well as with the customers was quite fascinating. You mentioned that the people are sharing how they're protecting some of this data with you at these events.
What are some of those methods? The biggest thing is we find a lot of companies are still in that static 2000 to 2010 timeframe where, hey, I've got a DLP solution that I'm going in there and I'm tagging data, or I'm trying to find how do I keep people from accessing this. Then we do come across some of those companies, right? A lot of companies are very innovative and they're doing a lot of the automation piece. And we ran into some that are saying, yep, we're using automation to identify these types of behaviors that are happening on our network so we can stop it when we see the data doing something that it's not supposed to be doing, if you will.
And what kind of automation are you talking about? So anything from machine learning to user behavioral analytics, right? It just depends as to what they have. I mean, if you use something like or you're looking at, hey, here's where your data is, here's what your data's supposed to do, this is the users that are coming in and taking it, but now here are the anomalies for when those times are not correct or something is driving it to do something different, like move data from this data lake over to Dropbox. Well, that's not supposed to be happening.
So you need some sort of automation to stop that, right? That's the kind of things that you need to have in place for those. That's what we're finding with our customers, just not everybody's moving there, right? That's a very advanced, mature company that can do that type of stuff where 70% of our customers out there are not doing that today. I think one of the areas that was a surprise to a lot of the data scientists was the amount of AI involved in the criminality of security, right?
The guys that are coming after your data, that they're using the same tools that they're meant to be using to create insights for their company. For value for the company. Other people on the other side of that fence are using them to hack into the enterprise and using them against them. So I think it was quite the surprise. They're like, wait, but we're the white light, why shouldn't we be using these for good?
Well, yes, just so you know that you can pretty much turn that to the dark side and use it for various purposes too. So I think they were quite alarmed to hear that their, uh, their potential foes on the other side were using the same techniques and same kind of intelligent technology that they were using for good. Within the world of cybersecurity, how many people that are like the bad actors, if you will, how many are really taking advantage of AI, machine learning? And that was something that our clientele, if you will, at these dinners was very surprised to hear, right? Because you think of the hacker as the picture that you always see of somebody with a hoodie sitting there at the laptop, and that's not the case, right?
I mean, you go on the dark web today and the amount of information that you can find of every security breach, or, you know, so you may think, hey, my data, I don't care if they steal it from this website because what do I care? Well, they're cross-referencing that data that they just stole from that website to data that they have stolen from other websites that they can now correlate and figure out, oh, this is this guy's username. Hey, let me see what patterns are in here for his passwords. Oh, Now I've got maybe what somebody's using for their password and they can go through and now they can start hacking all these other accounts. So our enemies or the hackers, if you will, the bad ones are using this type of AI.
They're using the elastic scalability of the cloud and they're doing the same thing we are to perpetuate our business. They're doing the same thing on their end. They're just stealing the data and selling it on the black market and they're doing it a lot faster than what we're enabling our business to do. To try to protect it. Yeah, on the dark web now you can pretty much find pre-written frameworks that you can buy off the dark web and just implement them on datasets or implement them and have them go attack certain companies or certain IPs or whatever it might be.
But it's totally commoditized on the dark web. And so I don't think people really realize that that type of functionality is out there. How do people position themselves to kind of prevent that? Like, that's— Well, first you got to have the dialogue, and that's, I think, that's what we were bringing together, right? I mean, you got to start with— to me, it's all about transparency, right?
So the data science guys have to go and sit down and say, this is what we want to do. And security has to have a seat at the table. And so they have to not just sit in a room and design something by themselves in a silo. And the same in security is like, hey, we're going to implement these controls. What effect will this have on you guys, right?
And that's the— I don't know how many companies, or it doesn't seem that many companies today have that cross-functional functionality discussion and transparency. So they end up just in conflict. So it really starts at the conference room table of having a conversation of make sure everybody is sitting there and voicing their concerns. And when you walk out that room, have a opinion, consensus, and agreement that this is what we're going to do and this is why. And so everybody understands it.
You just mentioned they voice their concerns. So I'm kind of curious what you've heard from people. I mean, most of the time, data science guys are— I mean, they may be analytical by brain, but I think they're free-spirited internally. And that's what they're really after is how do they take the data and how do they really create something of value out there, right? Nothing better than a great insight they bring.
And so they're about freedom, they're about going unrestricted to do their work and to get things out quickly. Speed, velocity, the things that they want to do. So, you know, those are the things that they're really looking for, and that's really a little bit of a conflict like we talked about in the beginning with the security guys. Yeah, yeah. And then most of the time, right, the business thinks about getting their data out so they can be more profitable.
And find things faster and be able to put marketing campaigns together faster and so on and so forth. They never really sat there and thought about, hey, as we're moving at the speed of business, our, you know, enemies or the attackers are moving as quickly as well. We talk about, you know, when I talked about infinite and finite, right? One of the things that the data science guys will go harass the security guys for, hey, just open up that port right now. I just need it for like And, hey, I don't need it for— well, they need to start thinking about forever too, because it doesn't take a moment in time for somebody to get access inside your enterprise, because you just have to have one moment of thought, one action, one port open, one download that's wrong, and then you've compromised the whole thing.
So I think, you know, instead of thinking with that finite near-term mindset, you have to think for the long term of, hey, it's not about just today, it's about going forward. So let's take a little time, think about what we're doing, how can we solve that problem and not put us in jeopardy the long term versus we just need to do this because I have to run the report for the quarter, so to speak. Right. Not everybody's got huge resources, you know, infinite money to, to throw at the problem. Right.
Well, the, the good thing is there's small, medium to large types of protections for every customer, right? I mean, To quote our good friend Chris Roberts, he always tells you that the user is the one that is always going to cause the problem, and it's true. So no matter what protections you put in place, you still have users that don't understand sometimes when they do make mistakes, and they're honest mistakes. So you have to be able to have protections in place that can flag these or stop these, and it's as simple as a mom-and-pop shop that could be hosting a database just because that's what they're doing, but that database has got information in it that is very critical to maybe the financial world, right? How do they put the right protections around that?
And I'm just going to throw numbers out there. Let's say they make $1,000 on this, but they're protecting— or they now have millions of dollars worth of information, but they only made $1,000 for them to be able to host this. They can't put millions of dollars of protection around it. So they have to be able to figure out, okay, so if we have this data, maybe we Ops— do obfuscation. Geez, wow, uh, it's been a long day.
But, you know, make sure that you encrypt that data or do something to where that data can no longer be used by somebody if they come in and take that data, right? So they have to get creative with the things they do, and it has to be cost-effective as well, right? I think some of it's to do with the frameworks are the same no matter whether you're small or giant, right? You're global or local, it doesn't really make any difference. The framework's still the same.
The principles are all the same. The things you need to protect are still the same. I think the manner you go about it is different. So you have to— I mean, what's good news is a lot of people are looking at democratizing a lot of the AI side of things with like H2O, for example, right? That you don't have to be a data scientist.
You can actually build it kind of like a Lego block, low-code version of data science. Okay. And if you're a small company, you're not going to be dealing with the large datasets and the diversity of a global business. So you're able to use those type of tools and kind of compete in that space. And then automation, we've talked about, right?
I mean, the more you can automate, the better. And it's that there are more and more companies coming out that are offering automation of various elements so you don't have to do all the heavy lifting yourself. Data scientists are a rare resource and very expensive. So the more you can automate certain aspects of their job and dedicate maybe a data scientist or even a consultant to come in and do the heavy lifting cognitive work, then you can compete in that space. I just think, yeah, the more we move down automation and with low and no-code coming to play, that, you know, that difference between having, you know, 10 or 100 data scientists— like we have 50 within our company— you know, you won't need that many because you can now do a lot of the elements that are required by data scientists today.
Through automation or through other low-code applications. So what are the challenges and next steps? So one of the biggest things was the observations we had that, you know, it's okay to say that you need to bring data and security together, but on my side, most companies don't have a real understanding of where data is. So our real next step for most of the people that we were talking to was you've got to be able to see where your data is, you've got to be able to organize it, you've got to understand what it is, whether it's structured or unstructured or semi-structured. It just, you know, in the world that we're all here, I'm not sure the statistic, but the amount of gigs we all create a day is crazy.
There's cows out there creating data that people are trying to get. I mean, almost everything we have creates data. So the first thing is, and the first step is get a handle on that, right? Be able to take that in, be able to organize it even though it comes in different varieties. And then you have to visualize it because if you don't know what you've got, I mean, the chances of something coming in that's nefarious is huge, right?
It's just gonna— it's not gonna be the stuff that comes through the front door, it's going to be the one that comes through the basement door. Maybe it comes through a BIOS or a firmware or something like that that you don't even know. Or maybe that one data scientist just that one day goes, you know what, that's great dataset sitting on an Excel on Google, I'll just bring that in via USB and stick it in my laptop. So the first thing that we recommend of all is like just get that level of understanding, otherwise You know, you can think you're secure all day, but something out there is going to get you. So I'll hand it over to my security colleague.
Yeah, my next step is really to learn how to say obfuscate correctly, but no. As we— there's no way I could have got that right. Yeah, right. As you know, as we talk about what are you doing with the data, how do you identify it, you can't protect it if you don't know what it is, right? The whole you don't know what you don't know.
And in this day and age, When you have the amount of data that companies have, right, and I'm going to go back to the Facebook example. That was a perfect example of everybody volunteered to put their information on a platform that is easily accessible by everybody else in the world. Think of how much data that is. Now, take that into your business and what kind of data are you collecting on your customers or what kind of data are you allowing your customers to enter into your systems? And then, just what kind of data do you use on a daily basis to run your business?
How do you identify that? How do you identify what's sensitive? And then how do you make sure that you've got protections around it? And then how do you make sure those protections are automated so you don't have somebody who wants to, hey, real quickly, I'm gonna take these datasets, spin up this environment. I don't have approval yet, but let me just use my credit card to spin up something in AWS or Azure or Google.
And then by accident you leave open a huge door, which has happened in Equifax and Experian, right? Except for the one the user actually went ahead and exploited that. But still, you want to avoid those types of things from happening, and companies need to realize that, right? So as much as we've talked about trust between security and data, right, it's also about trust from a customer perspective. So if you look at the way people do hyper-personalization, right, I mean, what are we willing to share to get the services that we want?
Right, and it's becoming less and less as when Don's talking about the different breaches. Now we're all very like, really, do I want my information out there or not? So the more that we see these breaches, the more trust individually to individual consumers goes down, the more— less trust in companies goes, and that really affects the bottom line. So, you know, if you don't— if a company doesn't understand that they need to see all the data sources that they have and secure those so that that level of trust and that level of, of confidence is with their customer base and with the people that do business with them, they're going to lose out in that long run, that infinite game. So really it's all about building trust internally between different silos and different technical functions, but it's also about gaining trust from your own customer base too, so that they know that you are secure, that you are providing them the best service you can possibly do and you're doing it securely.
And then if you do that, you'll have customers forever, right? Final question. Let's flash forward to the year 2030. So 10 years from now, what does this world of AI and cybersecurity look like? I think that's a common meme.
What did you look like 10 years ago, right? I was a lot younger, a lot less wrinkles. What are you going to look like in 10 years? 10 years from now? Good God, that's not a pretty picture.
So what does it— I mean, I think you won't have— I think you'll have built-in security controls to AI. I think data and AI will be dominated by cloud. You'll do very little on-prem. So I think all your data will automatically be loaded into the cloud. It'll automatically be sought for insights by machines.
And there'll be some inference put on that. I would imagine that the human is out of the loop in 10 years. That's a bold prediction, but I kind of agree with you. How about you, Don? What do you think?
Well, you know, there's— and I can't remember the author, I wish I did— but there's a book that came out in the '60s about the cybercriminal, and back in the day how they were running away with, you know, cassette tapes or reel-to-reels from these. That's what the picture is, a criminal running away, and it said, oh, you know, eventually they won't even need to be able to do this, they'll be able to do it remotely. And I think You know, we've seen that, right? If you look at the evolution of computers and every time we get a new technology, how great it is for the consumer, but then how great it is for the, you know, cybercriminal as well, right? And I think as we move forward, we're going to see a lot of AI come out with any kind of data that you put in there and things are going to be secure.
We have governance that may not be the correct way to drive how to do things correctly, but it's out there and it's forcing companies to actually take that next step and be more secure with the data, right? So I think we're going to see that evolve a lot more, and I think we're going to see a lot more leaps and bounds with security than what we have in the past. So I see it as an exciting time. So do you see biometrics coming? You know, the problem with biometrics is there's so many ways around it, right?
Um, especially with today's phones. Take out my thumb, take out my eye. I can take a picture of your thumb, I can take a picture of your eye and use that against those retinal scanners, right? And the, the thumbprints and things like that. So that's the scary part of traveling with Don.
Yeah, threatening to take my fingerprints. Yes, biometrics are great as a multi-factor type authentication, but you know, for every time that there's a way to log in or to be secure, there's also a way to steal that information as well, right? And I think on my side, I mean, that's some scary thoughts, but everybody thinks artificial intelligence like I, Robot and Transformers and stuff like that, right? That's not coming. We're still doing all the training, so the whole singularity is not great.
Another great book, Rise of the Robots by Martin Fordyce. Predicts some of these elements. But I think when we look in the future, we imagine hoverboards and all sorts of things. So I think even though we predict these things to come, I think maybe it slows down from an accelerated technical acceleration. You just never know.
That's my 2030. That's my bold prediction. Hoverboards. Hoverboards. Yeah, hoverboards.
Finally. It's going to finally look like the movie Back to the Future. The best thing we got out of Star Trek so far is what, the flip phone, right? Yeah, exactly. Well, this has been awesome, guys.
Thanks. I appreciate you joining me today. Yes, thank you, Jason. Thanks for letting us share our thoughts with everybody. Of course, of course.
And look forward to seeing one of these events sometime. Great. Absolutely. We'll put you on the list. Thanks a lot.
All right. Thanks. See ya. That concludes my interview with Don Klindt and Rob Clark. You can find and follow them on LinkedIn.
Please support Colorado Equal Security on Patreon and follow on Twitter @CO_security. I'm Jason Jaques Tech on social media. Feel free to connect with me, and I'm always open to feedback. Thanks for letting me guest host Colorado Equals Security. I'll see you around.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Security. Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.