Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 184 for the week of October 12th, 2020. Alex, good to see you in person this week.
Good to see you as well, Robb. It's always nice to be here in person. And you know, we are in fall officially for a couple weeks now. But man, the weather this weekend is is really nice. It is.
I do have to say though, I'm you know the mornings are getting rough. It's getting to that point now where it's dark when you're getting up, and it's like oh wait, it's dark that I'm not supposed to get up yet. There's an easy solution to that, Alex. Don't get up. Don't get up yet.
Well, you know sometimes although it's dark early too, so it's kind of a pick your poison. It's a lose lose, Robb. That's what they call those. I'm gonna. Wake up at 9:30 and go to bed at 5:30, and I won't have to see any of the dark.
Perfect. Perfect. It'll be like summer. Let's jump into some podcasty type things. We have some, some fun housekeeping we can go through.
Yeah. Did you know we have a Slack channel? Oh, what? Yes, it is. Slack is a— it's a discussion group, if you're not familiar with Slack.
Kind of like IRC, right? But basically just IRC. But it's graphical by now, right? But sort of, yeah, a little graphical. Well, it's in a web browser.
Are we using video at this point? No video? No, no video. Okay. I think you could make phone calls to people in there though.
I think you can. Yeah. Yeah. So that's a little more advanced. Have you ever done that in the Colorado Equal Security Slack channel?
I haven't, but maybe I should try that. Maybe we should try and record a podcast that way. Ooh, that sounds like a lot of technical work. Yes. Not the kind of thing we do.
That's right. Anyway, we have a Slack channel, Robb. Go to colorado-security.com and click the Slack button there and join the over 1,600 people in the Slack workspace. While you are on the website, scroll down near the bottom. There is a little button box you can put your email in, and that will get you on our mailing list.
The mailing list gives you such things as our weekly show notes for the podcast. And that's it. And that's it. Yep. And if I ever have like an angry, angry diatribe I want to send out to the world, that's probably where I'll send it.
And just if people hadn't realized, I'm the email newsletter guy that sends that out. So it makes me really happy when we get new people added to the mailing list. It's, you know, we talked about this before, it makes me happy when people join, but it makes me much more unhappy when they, when they cancel. Exactly. Until I see like it's a recruiter.
Sorry, recruiters. But all I know is when I see them quit, it's like, okay, well, they're no longer doing security recruiting, so they're not paying attention to us anymore. Yeah. Also, we would love it if you subscribe to the podcast on your favorite podcatcher. And while you're there, it would be great if you could rate the show as well.
Maybe some other people will find it because of that great rating. If you want to rate us individually, you can put in 2 ratings and say like Robb-5 stars and then Alex-6 stars. 6 stars. Whatever you think is appropriate. Moving on, we'd love it if you tell a friend.
Obviously, this kind of witty banter is the kind of thing you'd want to be associated with. So tell your friends, colleagues, enemies, whoever you talk to. And if you think this witty banter is so good that you would like to pay for it, we do have a Patreon campaign. We would love for you to be a patron of the show and Colorado Equal Security so that we can help pay for all the things that we do. And we do want to do a big thank you to our current patrons.
We do have a number of folks who have supported the show, some of them for a long time. Yes. Much to those who do it. Keeps us, keeps us going. I'll tell you the truth.
I get, you know, if this was all out of our own pocket, I'm not sure we'd keep going. But you guys have been a big part of keeping this movement moving. And for those of you that have not joined the Patreon campaign, shame, shame on you. Shame. But if you're thinking, man, I'd love to help, but I just don't have the money, what could I do?
You know, you could be a guest interviewer. Yeah, we, you know, we have interviews on the show. We have a hard time keeping up and doing one every week. But if you think you have the chops to sit down and talk to someone in front of a microphone, You're the kind of person we'd like to see do guest interviews for us. And really the chops are you have to be able to speak and you have to have some way to record sound and you have to send us audio that we can understand so we can put it on the podcast.
Yes. Preferably, you know, good sort of high quality audio. But, you know, we take what we get. All right. Good stuff.
Let's move into the news. Starting off there, we have, we have some news from the Denver real estate market. You know, we are a tech podcast, but occasionally there's such a big non-tech story that we've got to share it here. Well, you know, all of us tech folks do have to have houses to live in. So it is applicable, Robb.
So September was the tightest market on record in September for buying houses, the lowest inventory available ever. And it's not always the lowest inventory. It's by a lot. So there were only 3,000 single-family homes for sale in September across the 11-county metro area. The previous low was 5,700.
You're talking like 60%, almost, almost half of the normal inventory. Yeah, that's pretty crazy. Yeah. You know, some of the things they talked about is that people seem to be a little hesitant to list their houses, which seems silly considering this information because of COVID and everything else that's going on. And people still want to move here.
So there's a, you know, it's a hot market for actually buying houses. So if you did list, the average time on MLS Average time, 6 days. And that, that's compared to the previous low, which was 9 days. 6 days is just mind-boggling. That's the average time for houses to be listed on MLS.
Also, the number of closings in September was at 5,850, which was a 16.51% year-over-year increase. So not only do we have a record low number of houses going at a record speed, we also had a record number of closings. It's just, it's mind-boggling that the housing market is, is so intense here right now. It is pretty crazy. I wouldn't want to be buying, but I would love to be selling right now.
Yes, exactly. Next, we have talked several times about Boom Supersonic, company here that is making a new commercial supersonic plane, and they have just unveiled their XB-1 demonstrator aircraft. So this is going to be that supersonic plane that they're hoping will kind of take the place that the Concorde had, you know, flying over to London and What was it, like 3 hours or something like that? I'm really excited. This— they have a scaled-down version of the Overture.
The Overture is going to be the big one. That's— and they're currently able to, to have some pilots fly this around. It's using 3 GE-made engines and it has 12,000 pounds of thrust. And I have no idea if that's a lot. It sounds like it must be a lot, though.
Sounds thrusty to me. I mean, if you told me it had 1 million pounds of thrust, I'd be like, yeah, that sounds like it. 12,000. Okay. So basically, this is— it's going to be very similar to the actual commercial version, the Overture, except they basically just cut out the passenger compartment.
So it's, it's pilots and engines. That's about it. I hope they didn't literally just cut it out. It seems like the test might not go so well for those pilots. They built it without it, Robb.
Yeah. So we are, you know, a tech podcast. And of course, cool tech like, like supersonic planes is worth talking about if it's made here in Colorado. Indeed. Next, we have a story here from the Denver Business Journal.
Talking about how a number of Colorado companies are looking at teleworking in, you know, in the light of COVID and the fact that this might not be temporary for a lot of companies. Yeah, this was an interesting story. There was a survey that was done as part of the story, and one of the things that they said was 81% of senior managers in organizations have a more favorable attitude towards teleworking today than before COVID-19. Yeah, they— the numbers for the increase, they say that somewhere between, well, previously 78% of companies allowed telework and they expect 86% to provide it in the future. And only 30% say that they're planning to develop a formal teleworking policy.
I think that's because the rest of them just have an informal policy that when a pandemic comes, you're going to telework. Right. Or, you know, they allow it already, but it's just not written down anywhere, you know, sort of unofficial company policy. So that's pretty cool to see that people are embracing it more. I think even, you know, some of the companies that are pretty traditional and hadn't really thought about it before.
Yeah. The article spends a lot more time talking about tech companies, which I would expect are much more readily accepting of this kind of a change. I would have been interested for them to really sit down with those more conservative countries and companies and, you know, talk to a DISH and a Teletech and, you know, an Anschutz and understand from those companies, you know, how are they thinking about it? But yeah, they didn't do that. Yeah, there was— they talked to one company in there.
I don't remember the name now, but they mentioned how Um, while they could— that company plans to continue doing more telework in the future. Um, they were afraid that the, um, the water cooler talk, the, uh, the culture kind of things, you know, could be suffering because they weren't in the office. They would still be doing some in-office, but, you know, be more flexible for, you know, some days working remote, things like that. I'm hearing a ton of companies that the way they're looking at this is not either or, but that the long term looks more like a kind of a combination where there's a lot more acceptance and support for people to work regularly out of the office, but then changing the office environment to be less about individual cubes where, you know, where you're, you know, kind of sitting in an aisle full of people and more about group work areas where you do come in for that 1 or 2 days a week. You're collaborating the whole time.
Right. And people, you know, expect that to be the teamwork time and the rest is kind of individual work from home. Yeah, that makes sense. All right. Next.
Colorado Springs SaaS startup Quantum Metric has got $25 million in funding and is gonna hire 80 new people. So I didn't know Quantum Metric. I'll tell you what, what got me interested here. They've been around since 2011, so they're not brand new, but they have a number of great customers. They have Neiman Marcus, Lenovo, Alaska Airlines, Lululemon as some of the customers named there.
So they do some pretty cool stuff. They basically, as a SaaS platform, help other companies build their digital products faster. So they'll, they help other companies capture customer behaviors and understanding what customers need, um, and, and really get that data out there, making their, their online presence more intelligent. Yeah. Uh, pretty cool.
They also just struck up a partnership recently with Dish, uh, to help them build some more, uh, customer-centric applications. Um, so a couple other interesting facts about this company. Um, they were on the, we talked about it before, the, it was the Fortune, the Inc. 5000, which is the fastest growing companies. They were 101, uh, number 124 on the list with a 2,945% growth rate over the last 3 years. Over the last 3 years.
Yep. And, you know, with this new $25 million that they've got from Silicon Valley Bank, they're planning to go hire a bunch of folks and get some new products. They're, they're currently at about 170 employees and they plan to get to nearly 250 by the end of this year. Congrats to them and look forward to seeing them hire some folks. All right.
Next. There is a Denver fitness startup that is launching a new product, ExerLabs. They launched an AI-based app recently that helps you do planks. I know. I— so this article, you know, we see a lot of these headlines and sometimes I'll read them, sometimes I won't.
And this one, get into it. I'm like, wow, this is really kind of interesting. They're a local company that basically uses your smartphone camera to watch how you do exercise and it's giving you guidance, but it's doing it all on your device. Yeah. So the AI is all built into the, into the app.
On your phone. It's not sending your data back out to the cloud. It's, you know, it's gonna look at your form in the plank. It's gonna tell you, hey, stop sticking your butt up in the air, Alex. And, and you're gonna do it, and then you're gonna do better planking.
Yeah. And that's pretty cool. So that was the original app that they put out. The new app that they're doing is more of a platform so that folks can do remote exercise classes, but it also has some of those AI pieces built in so that those remote trainers can help people do the exercises better. Yeah, they're going to be kind of competing with Peloton and the leader-based classes with, with more of that built-in AI to help you get good feedback.
Obviously, it looks really cool. It's a local company. Their name is ExerLabs, Denver-based, and we love to see them win. They're currently at 12 current employees in Denver. They expect 20 to 25, they say, in the near future, which who knows what that means.
Yes, I'm excited though, Robb. I am gonna go download the, the planking app so that I can, you know, keep my butt down. Are we gonna do a plank competition, Alex? Ooh, maybe. Would that be a good podcast episode for us to do a plank competition?
An audio plank?
Maybe not. We'll get back to you guys on whether that ends up happening. All right, next story, moving on. We have a blog from Red Canary this week. This one's a little different than the normal Red Canary blog.
Um, this is around cloud workload security, 7 reasons why it's complicated. Rather than going into their normal, like, in-depth review of an incident or how you capture bad behavior, they're just talking about some of the nuances of trying to do cloud security. Yeah. And, you know, some of the difficulties, frankly. Um, and one of the things that they're focusing on in cloud security, um, really is around, uh, Linux and some of the problems, uh, that you have in securing Linux.
First thing they talk about, Linux attacks are poorly documented and not well understood. Yeah, and that's fair enough. And I think to your point, like they are really focused on Linux here. And because the vast majority of workloads in Linux, or excuse me, workloads in cloud are using Linux. Sure.
One thing that they don't go into here, or they didn't in the part I read, was really getting to that serverless infrastructure and how to do serverless workloads. They did talk a little about containers and Kubernetes and things like that, but yeah, not all the way to serverless. They also talk about the fact that, you know, cloud environments have a lot of cooks in the kitchen. So you're gonna have developers and you're gonna have, you know, your SRE team and these different teams that are interacting might make changes that the others aren't expecting. And so, you know, doing just, you know, hard and fast FIM is, is gonna cause you issues.
Yeah. Uh, licensing can complicate things. So depending on, uh, what it is that you do with various components in Linux, you know, you could run afoul of GPL and other things like that. Yeah. Linux is a diverse ecosystem.
You know, it's not the walled garden that you get with with Macintosh. I was going to— Windows, even Windows is a more well-understood environment. Linux, right? You go a lot of different ways, a lot of different kernels. It's hard to necessarily know what right behavior looks like there.
Security is a moving target, which I think we all know that makes it even harder. The stakes are high. I mean, I think that this is true for all of us everywhere. But I think in the cloud, as we're starting to move more and more critical services to the cloud, making a mistake there is, you know, number one, it's really hard to know that you did it. And number two, it can cause a lot of damage.
Yeah, and because of some of that complexity, deploying software can still be cumbersome. You know, there's lots of moving parts. Even though things can be orchestrated, that doesn't mean it's necessarily easy or straightforward. So good stuff there. All right, moving along, we have a press release from Ping this week.
Ping Identity, they announced this week an acquisition we actually closed back in, man, I want to say February or March, I think one of those two, but it was kind of pretty quiet at the time. Um, really we, we acquired a company called Showcard that does, uh, what is it they do, Robb? Yeah, they, they do personal identity, um, any validation, personal identity on, on your mobile device. And you can think of like basically what they're creating is a wallet you put on your phone that gives you the ability to show verified claims. So I could get like my, my employer Ping could give me a card that says, hey, Robb works here from this date to this date.
And I can show that to someone else, that person can trust that claim. You know, maybe a more useful claim might be, um, from a, from a government saying, I'm a citizen and I'm allowed to drive, right? And I'm able to present that claim. So they've, they've created this technology that allows you to not only do identity validation, but also then to prove all these claims. There's a million different use cases you could use for this.
I'm curious, Robb, how is it that they can, uh, make sure that those claims don't change? You're, you're asking, are there any elements of it that might be immutable? Oh, is that potentially? Is that what you're asking me? Well, there's, there's, there's cryptography behind it.
Oh yeah. What sort of cryptography? I'm not sure exactly what. Do they use some sort of ledger? Is it distributed?
They do use a distributed ledger for the technology. Yeah. That's immutable. It's an immutable distributed ledger. And it does.
It is installed on endpoints. Yeah. Oh, you know, you know what they call those? Well, DLTs is what I call them. It's usually referred to as blockchain, Robb.
I think I might have heard that somewhere. Yeah. Uh, sorry, just giving you a hard time. He's giving me a hard time. He's giving me a hard time.
I will say that you, uh, I think there's no problem that you can't solve with something else, but blockchain has given a way for people to understand the technology better. So potentially a reasonable use for blockchain is what you're saying? I think it's a reasonable use for blockchain. All right, sounds good. All right, uh, next we have a blog from InteliSecure talking about building business-centered data protection.
Uh, so, you know, this was an interesting blog. They, you know, you know, Intel Secure is a lot around DLP. They do a lot of DLP work. So really what they're talking about here is using data as the center of your security program, what you're focusing on, as opposed to, you know, securing the perimeter or endpoints or things like that, really trying to secure the data. So they're talking about, you know, sort of 3 steps that you can take here to kind of kickstart that.
One obviously is identifying that data. Yeah, identifying the data is critical. Second thing is to deploy the appropriate technology controls to monitor the data. Uh, and then the, the final one is invest in people. Show me the money, Alex, to make sure that this continues to happen.
You gotta still have the people. Show me the money. All right. Uh, good to hear from InteliSecure, their CTO, Jeremy Whitcup. We've had him on the show, been a long time.
We should probably get him back on again. Yeah, sounds like a good idea. Uh, but we'd love to hear if we have any volunteers that want to interview Jeremy Whitcup. Yeah, just let us know. And if the InteliSecure team is listening, let's make that happen.
Moving along, we have a blog post from ThreatX this week. It's actually former CEO, and I think he's now like Chief Strategy Officer, Brett Settle over there. He wrote one about denial of service attacks and the 2020 election. Yeah, so there has been a good amount of talk in the news about denial of service attacks and how they could potentially impact the election. And so they go into a little bit of detail about those kind of attacks.
You know, what you might expect to see, you know, what layers on the stack they might try and do denial of service because you can do multiple different kinds of denial of service attacks. And then, you know, how ThreatX plays into that. Yeah, we haven't talked about ThreatX in a while. It's nice to talk about the local WAF company. Anytime you can, we can tie in election security.
I just got my ballot today, by the way. Oh, congratulations. So if you try and take it with you, that'll be fraud. I don't know that I've tried to check my mail yet, so maybe I have my ballot as well. I know they've all been sent out, so pretty cool.
One more big news story this week. Yes, we have a, we have a write-up from Layers, and it's big because Layers doesn't give us a lot of content to go through, and this is one of the rare ones we get, and it's good content. It is. So they are talking about work-from-home lateral movement TTPs, so really walking through some potential scenarios where work-from-home can obviously cause some issues. So pretty in-depth there.
And if you don't have the time to read the entire article, there's a really nice picture near the top. You can just look at the picture and, and you'll know like about 4% of the article. I think that's probably pretty good. Yeah. Is that all you did, Robb, is just look at the picture?
I wouldn't say that. Chris Nickerson, one of our good friends, I've been on the show once or twice. We'd love to have him back on the show as well. Yeah, man, we got to get back to these guys. So I think Talking about the article again, I do appreciate the fact that they actually go into the, uh, the different TTPs as part of the article, you know, talking through the steps.
They list out all of the, the individual, uh, TTPs as well as where they fall into the MITRE ATT&CK framework, um, as part of that. So that's pretty cool. And they also do a step-by-step, uh, walkthrough of how they did the actual attack. So you can see the commands they ran, um, if you want to replicate this in your own your own home in a place that you're not doing anything illegal. Highly recommend not doing anything illegal.
This is a good way for you to learn how to do testing from a really well-respected company. Sweet. So that is our news. Let's move over to the Slack message of the week. Thanks to Andre Gaeta for continuing to support us with the Slack message of the week.
The winner of the Slack message of the week gets to choose one item from the Colorado Equals Security swag store, compliments of Andre. Thank you, Andre, for doing that. This week's winner is Richard Johnson. Richard posted a story which was about John McAfee. John McAfee was arrested recently for tax evasion.
Apparently, he had not been paying it. Well, he's accused of not paying his taxes. And this is especially interesting to us because part of that tax money might have come from— might have come from revenue that we gave him. It's possible. Yeah, it's possible.
Unlikely, but it's possible. Unlikely. I think most of it is centered around cryptocurrency there. I think there are some Concern there that, you know, he had not stated how much cryptocurrency he actually has and was not paying taxes on those kind of things as they are assets that you need to pay taxes on. I was just alluding to the fact that he was a keynote speaker at RMISC a few years ago.
And indeed, we did. We did write him a little bit of a check for that. And he did it. He came and he talked and he was— it was good. We got a good draw out of that.
Not nearly as crazy as you would expect. I was really hoping that he would be crazy. I was hoping he was going to take off his shirt. And I mean, Not, not that he was completely sane either, but he was not nearly as crazy as one might expect. I think that someone told him, hey, this, this conference has a lot of auditors, tone it down a little bit.
And he did. Yeah. Anyway, anyway, congratulations to Richard. Appreciate your— he's a, he's a regular contributor in the Slack channel. Appreciate him continuing to be part of the, part of the gig there.
All right. Uh, Robb, did you know on the website we also have an event calendar? Um, I was aware of that. I schedule all of my family events around what's going on on that calendar. Oh, wow.
Um, did not know that, but that's pretty cool. Yeah. Um, and so it has events from all of the different security organizations around town, some vendor events, other things like that. Um, if you want to get an event on there, just let us know. Well, you can go out to the website and click the link to add an event.
You don't even need to let us know. Just do it on your own. You could let us know in many different ways, right? You could Slack us, email us, call us, but also every week we talk about the events that are on that calendar for the next 2 weeks. So what's on there, Robb?
On the 13th, we have Denver ISSA doing their From Zero to Hero, which is build a data security privacy program from the ground up. On the 15th, ISACA Denver is doing their October chapter meeting talking about a COVID update and resources. Everybody loves COVID. On the 20th, Denver ISSA has another event going. This is Help Someone Slide Down the Rabbit Hole, getting new people to InfoSec.
Also on the 20th, CSA Denver is doing their October chapter meeting. On the 21st, Reuben Brown has an ethics seminar. Kelly Richmond Pope is doing a virtual event to talk about ethics. That's pretty cool. On the 22nd, 22nd, ACES is doing connected communications and smart security solutions.
Sounds so interesting to me. Yeah. Also on the 22nd, ISSA Colorado Springs is doing their October online meeting. And on the 23rd, DC303 is doing their October meeting. All right, let's jump over into jobs.
Um, at Ping, we have a couple of jobs in security open right now. I have a manager in my GRC function available. I'd love to, to talk to you if you have a passion for helping with things like ISO and SOC and policies and and vendor risk management, all that fun stuff that's part of our GRC program. You can apply online, but if you want to send me a note in the Slack channel as well, I'd love to talk to you. Second thing is we're hiring an application security engineer.
We call it a product security engineer because you work in our product development teams, helping make sure that the products that we deliver, for example, Showcard, the new, the new distributed ledger technology that's going to be changing the world, you can help do that as a part of our team. Reach out to me on that as well. So, Robb, you're looking for someone who can do blockchain security. Is that what you're saying? I don't know why you keep saying that.
Uh, next, Spectrum is looking for a Security Engineer III, SOC Analyst. Recharge Payments is hiring a Director of Engineering, Security. Staples is hiring a Senior Cybersecurity Architect II.
Centura Health is hiring a Security Engineer Senior. Lumen is hiring a number of jobs, but including an Incident Response Engineer for Splunk content creation. Lumen. I don't know that I know that name. Is that, is that a brand new startup?
You would think that they might be. But Robb, remember, that is what CenturyLink is now called on the enterprise side. Lumen is now— or CenturyLink is now Lumen. Yes. OwnBackup is hiring a director of cybersecurity.
I don't know OwnBackup. Yeah, they are not local, but this job, they have some people local and it can be remote. Awesome. Maxar is looking for a cybersecurity operations analyst. University of Denver, DU, is hiring an adjunct faculty on information system security and cybersecurity.
Yeah. So if you know stuff and want to teach kids or adults, you should do that. And FlexCentral is hiring a pentester. I love it. Well, that is it for the news this week, right?
We— but we do have an interview. One of those lucky, lucky weeks. We have Jason— more Jason Jaques. It's actually even better because it's not even one of us doing the interview. We got Jason Jaques.
Doing a guest interview with Chris Sundberg. Chris works over at Woodward and they got together and I'm looking forward to hearing all of— number one, I'm looking forward to hearing Jason's dulcet tones and getting to know Chris better. Chris is a member of the Slack community who we've got to see on there and we're going to get to know him in more depth. Good stuff. Looking forward to it.
All right, everyone, have a great week and we'll talk to you again next week. Thanks, Robb. Hi, this is Rich Schliep, the CISO for the Colorado Department of State. This is Colorado Equal Security for Colorado security professionals by Colorado security professionals.
Colorado Equal Security. This is Jason Jaques. I traveled up to Fort Collins recently and interviewed Chris Sundberg at Woodward. Here's the interview. Enjoy.
Chris, thanks for joining me today. Hey, no problem, Jason. Glad you can make it up here. Yeah, this is, this is one of my new favorite things to do is to come up to Fort Collins, which I like anyway. And visit the breweries up here.
So it's a great excuse coming up here so that we can go have a beer. And we got rid of the smoke too for you. Yeah, so beautiful blue sky today. Today, yeah. Is it, is it all gone?
No, of course not. It probably smells a little smoky outside, but, uh, right now there's no haze. Yeah, yeah, I can see the mountains now. Last time we went to Odell's, right? What's in store for us today?
We're gonna go to the classic New Belgium. Nice. Yeah, I'm excited about that. Yep. With, uh, with COVID you had to make reservations to have outside seating, which I did that for us.
So we'll be able to head over New Belgium, have some classic brews. Perfect. And, uh, talk a little more security off the record. Uh, but before we do that, let's, let's talk a little bit, uh, a little bit of shop here. And, uh, sure.
And what you do, where you're from. So where are you from? So I'm from a small town in northwestern North Dakota, Crosby. If you're in the oil and gas industry, you know of Williston. Crosby is about 75 miles north of that, 6 miles out of the Canadian border.
Okay. I do not know of any of these places. So good example, if you go out to Greeley, go up Highway 85, 12 hours to the north. Okay. You're pretty much there.
Yeah, that's a regular drive that everybody here makes. Oh yeah. How was it growing up? Next to the Canadian border? It was a lot of fun.
Um, obviously I play hockey. Um, well, that's one of my hobbies along with curling, uh, and broomball occasionally. But, uh, with hockey, we'd sneak— we'd go across the border, play like 2 or 3 games up there during the school week, and then play scrimmage against American teams on the weekend. Yeah, so we got a really good hockey experience growing up. Would the Canadians ever cross the border on this side come down and play?
Oh yeah, they play. They come down and play all the time. Um, but again, you know, it's 20-minute periods, full-on hockey with them. The American teams, it was 15-minute periods. Yeah, so you're kind of like going, I will show up.
Um, who's better, the Canadians? Oh yeah, it's always much more fun to play them. Uh, the American teams were, you know, it was kind of back and forth. They traveled many hours to get there because nothing's ever short in, uh, Northern North Dakota. I mean, it's 2 hours to the mall.
Yeah. You know, I don't like going to the mall anyway, so that wouldn't bother me. Well, when there's not much in town. Yeah. It was about 75 miles to the nearest Pizza Hut.
Okay. So that was when you're driving, when you're learning how to drive. Yeah. That's a great experience right there. Why don't you go and get pizza?
So how long does it take them to deliver? They don't. You have to go pick it up yourself. Okay. I was going to say that's going to be a long delivery.
That's right. Big delivery charge. Yeah. But it was interesting because when we were growing up, this was before the big Bakken oil boom. And I graduated high school in '92.
So it was really before the internet kind of hit. But we were part of an educational grant up there, which got us a bunch of old NeXT computers. So between like 4 or 5 schools, we tied these NeXT computers all together to make a kind of a mini internet. So every time at midnight, they'd fire off their mail daemons and start trading mails and stuff like that. I was introduced to the C programming language through those computers.
I locked up the computer the first day we got it, uh, doing a video capture of a John Madden video off VHS. Okay. So we had to call Fargo, North Dakota and have them reboot a Linux or a Unix system. Yeah. Which was, which was awesome.
I mean, why not, why not press it, press the, press the envelope? Yeah. Yeah. Um, which it was interesting because at the time, you know, computers were really unheard of in a lot of places. I mean, we had some really cool old 286s and stuff like that, but that's what got me into computers and eventually down here to Colorado.
Yeah. Uh, give me some, uh, some examples of some of the other stuff people in North Dakota do. So there's a lot of farming. Um, and I grew up on a farm. Okay.
My jobs in high school were actually a movie theater manager and a greenskeeper. But growing up on a farm was huge for me because I don't think I'd be in computer engineering or cybersecurity engineering without having that experience on the farm. When you're like in junior high driving a very large combine, you have to kind of be a systems engineer to figure out what's going south when things go wrong. Most of the time they go right, but there's those times that things go wrong and Uh, stopped production is downtime, so you're not making any money. Um, so as a kid, you kind of have to figure some of that stuff out.
So it's a good lesson learning experience. Um, getting tractors stuck, another good lesson learning experience. Yeah, sometimes you just have to hit full throttle and get, get the heck out of there. Um, and then when you do get stuck and you can't get unstuck, you have to call your stepdad. Um, it's long walks.
Yeah, I bet. A lot of time for contemplative thinking. Another thing in North Dakota that was big back then was driving. So there's a lot of cruising at night, just burning gas. And gas at that time was less than a buck.
Okay. Yeah. So that was, those are some of the other big ones. Big hobbies. Big hobbies.
Yeah. So those are some of my favorite ones. Growing up on a farm, you either get into cybersecurity or you continue farming. Is that what I'm hearing? There's always kind of a middle ground, but I've got 2 other brothers and 2 sisters.
One of the brothers is still up there back home. The other one went into fire, wildland fire, and him and I trade stories about incident response all the time. His is a little more predictable, deals with fire. Mine's adversaries. And then my 2 sisters, they both married farmers and are happily farming in their respective farms.
Okay. So yeah, roughly, you know, but I know of other people who've kind of gone into technical fields back home out of that area. At the time, there weren't many computer jobs up there. So that's what kind of brought me down here to Colorado. Are there computer jobs up there now?
Yes. Okay. Especially in operational technology and critical infrastructure, oil and gas. Yeah. Quite a bit, like remote networking, oil well sites monitoring, that type of stuff.
Yeah, it's really gotten big up there because you don't want a person in each one of those sites. Yeah. Before we leave kind of your hometown, so as you're crossing the border up in Canada and North Dakota, how does that work, I guess, pre and post So pre-9/11, it was pretty easy. The Mountie would kind of step out of the drive-up window, ask you the questions, you know, what's your name? What's your business?
Hurry up there. Do you have any alcohol, tobacco, firearms? You basically answer them, going up for a hockey tournament, got all these kids in the back. No, no, no. And he'd pretty much wave you through.
And coming back was pretty much the same way. How'd you guys do in the hockey tournament? We lost. Oh, Not too bad. Go home, eh?
So it was pretty laid back getting up there. You never really realized you were in another country with the different tone of voice sometimes. But after 9/11, it really changed and they were a little more strict. So I went up there one time for a parts run and I was going across the border. It wasn't really any problem.
I brought my North My Colorado pickup, I should say. Yeah. And we get up there, get some ball bearings from a, from a dealership up there for, for a baler repair. And, you know, getting up to Canada, no problem. You know, hey, you know, glad you come from Colorado to visit.
Coming back, the U.S. guy was not so happy. He's like, you're from Colorado? Yeah. What'd you get? Ball bearings.
Let me take a look at those ball bearings, sir. So I, I guess I just exude that, you know, guy from Colorado is not going to come back for ball bearings or anything like that. Yeah. Um, so I kind of told my stepdad, I got, you know, moving back sooner, but I kind of got stopped at the border for bringing back ball bearings and driving a Colorado pickup. He said, oh, I should have let you drive the North Dakota plated pickup.
Yeah. You can't trust Colorado, uh, people, drivers with ball bearings. No, especially post-9/11. Especially post-9/11. That's horrible.
I've always wondered about that crossing the border.
It's only a ditch. It's only a ditch. I mean, there's not— there's no fence up there. It's really kind of a ditch. Oh really?
There's a— there's actually been people that have just like crossed because they've gone the wrong prairie trail. Oh, show up in a farmer's yard and say, hey, I'm looking for Cardiff. Uh, you're a little too far south. Like, how far south? You're in America.
Oh, that is— that is kind of funny. So you left North Dakota, right? What, um, let's talk about that. What— what made you leave? Well, I was really with the NeXT computers.
I was doing quite a bit in distance learning and distance education, and there weren't a lot of degree programs around that in North Dakota. And I kind of wanted to stick with it because it seemed like, you know, something good to get into at the time. Was this something you were working or was this school that you were taking? It was— I was helping out at the school. So I was a senior at the time, but I kind of dove into the NeXT computers that we had.
So, you know, we bring the kind of this consortium of 6 or 7 computers together in one building and kind of go over what we're doing with distance learning and stuff like that. And they brought me along to kind of say, well, I've been doing this and, you know, I was doing video capture. I programmed in C, you know, and these are people that could care less about programming. They're all mathematicians or whatnot, math teachers, until I got to the point where I was describing how I was doing my calculus homework, which was using Mathematica. And at the time, you know, Mathematica was, you know, kind of a relatively new type of thing, especially graphical programming for calculus.
And I did all my senior calculus on Mathematica, got credit for it, and learned more about calculus than I could ever with a textbook. Yeah. So that was, that was kind of cool. That kind of sent me down that road. I looked into Greeley University of Northern Colorado because they had quite the educational lab in that area.
So I kind of pointed my direction that way. Okay. And Greeley wasn't terribly big of a town. In fact, it's about the same size as Fargo, which is the biggest town in North Dakota. Yeah.
So that was, that was kind of what brought me down here in '92 to start going to school at University of Northern Colorado. Okay. So that's your alma mater? Yep. That's my alma mater.
I graduated from the business Um, business department in computer information systems. Okay, very cool. Uh, was one of the last classes to take COBOL out of that class. Yeah, I know, that's how old I am. Um, but it also taught me that, you know, you can always manipulate COBOL code, um, to be several different versions.
Um, that's very— well, because management had to take it. Management class people had to take COBOL, and, uh, they don't like programming. Um, they could care less about— yeah, about it. But if you're a programmer and really into it you can, you know, make several different versions of the same COBOL program. Is that still relevant today?
Does anyone ever do any of that? Probably not. They have one single version they're trying to maintain and keep it running. Yeah. So let's talk about hobbies.
What are some of your hobbies? So one of my big hobbies I'm into right now is vintage racing. I am— I work with Rocky Mountain Vintage Racing. I've done that since '96. My first manager actually got me into that position.
I've been doing first responding or corner marshaling. I do drive. I've got a 1963 Triumph Spitfire. Okay. Um, I am kind of a big guy, so people ask me, why did you buy a go-kart?
But it's a, it's a fun car to just kind of tootle around the track. Um, we've been doing this, uh, for a long time. We used to do street races up in Steamboat. We've done races up in Aspen. Uh, we're actually going to do another street race up here in Estes Park next year.
Yeah. Uh, so we have an annual fundraiser for Morgan Adams Foundation, which supports pediatric cancer research. Oh, that's great. I do the track announcing for that. They— it was kind of funny when we first started doing that 10 years ago.
They're like, well, who would you have go track announce? You know, tell some of the stories about vintage cars and stuff like that. And we started naming names and they're like, ah, he's— he passed away. No, he's no longer talking. You know, all this other stuff.
And they finally said, well, hey, Chris, why don't you— why don't you come over here and do this? It's like, well, why? Well, you have the voice for it. Plus, you know all these cars and you're kind of a car nut. Yeah, sure.
Yeah, I'll do track announcing. So that kind of got me into a kind of a little announcing gig on the side I do occasionally for a race against kids' cancer. Morgan Adams had me do kind of some ringside announcing for the boxing matches they do downtown, or they used to do downtown. But it's just kind of fun. You get to meet a lot of cool people like Travis Pastrana was there one time, you know, and you get to see fast cars.
Yeah. So that's my big hobby right now. Yeah, that's awesome. I still play hockey. I help out with our U8 program up here, Northern Colorado Youth Hockey.
My son plays. He's 6, has a lot more hockey skill than I'll ever have. Oh yeah. But I help coach him. Um, help them out on the ice.
We play stick and puck all the time. Okay. So we kind of try to sharpen each other's skills. Um, so do you coach the team? I, I help coach the team.
Oh, okay. Yeah. Um, I actually, uh, we organized kind of a, a recreational team to go up to the Keystone Pond Hockey Tournament last year. Okay. So it was my first time kind of coaching and responsible for line changes for U8.
Uh, we split, you know, I Didn't know what to do the first 2 games and I finally figured it out the last 2 games and, you know, we had a really good time. Yeah. So Keystone was awesome. That was like the last big fun event before the pandemic hit. Yeah.
Yeah, that sounds fun. I have noticed that youth sports and, and I've heard hockey is definitely this way. They are, they're getting really serious in terms of like competitive nature and getting the kids to practice year round. Yeah, I don't necessarily agree with that. No.
You know, Wayne Gretzky said it best. You have to have more than one sport. And he never played hockey year round. Yeah, he always had something to do in the summer. And I tend to agree with that.
It's good to have another hand-eye coordination sport in there. I can see where, you know, people get serious and play hockey all the time. You know, I'm guilty of it too. Finn plays hockey or my son plays hockey. Whole year round for, you know, just keep the, keep the skate sharp.
But he does all these other athletic activities too. Yeah, I think that's great. Right. So you got to keep it fresh. And, you know, at that age, you're not going to specialize.
You know, don't send them down one path, although that is the path you'd like them to go down. Yeah. You know, just keep the options open. Yeah. Yeah.
You also curl. You mentioned. Yep. Talk to me about curling. So curling is like the last Olympic hope I ever have, but it's a fun sport.
Again, it's kind of like, you know, it's really caught on the last couple of years since they started showing it. You know, when I first moved down here in '92, I was like, so are there any curling rinks around? And everyone's like, no. Well, there's one now by the stockyards. But I mean, I was like, okay.
But it's really kind of taken off here. So it's been a fun sport. I remember growing up where they had the loud brooms. Yeah. Whereas the classic whack, whack, whack, whack, whack.
Big corn brooms. They don't do that anymore. It's all poly brooms. Um, but it's, it's the one sport where I can, you know, play 8 ends, have a 6-pack of beer, um, and be just, just happy. Yeah.
Um, it's, you know, describing it to people that don't know how to curl, um, is also a good time because, you know, you can explain why people yell at each other. Yeah. You know, you're not sweeping hard enough. Um, you're sweeping too hard. You know, aim over here, aim over there.
Um, those are always fun things to do. It's interesting. I watch curling in the Olympics and I think, I could do that. I could do that very terribly, but I could do that. Oh, you can.
It's a matter of aiming the stone, the rocks, but it's kind of all in the hand. And like bowling, as you get used to it, you'll figure out where to put stuff. But you also see that the ice kind of puts in a lot of uncertainty in that whole thing. So rocks shift around. Yeah, they don't move the way you expect them to.
Um, the sweepers don't sweep hard enough, uh, the skip's not yelling loud enough. Um, so you've got a lot of issues you got to contend with, but it's trying to sneak it in through those, through those guards to get to the center, to get as many rocks in the middle as possible. Yeah, yeah. It's kind of like, um, for those unfamiliar, it's like I look at it like shuffleboard. Yes, but like a much larger version of that.
Perfect game for beers. It's shuffleboard for grown-ups. Yeah, yeah. And to show they can— you can still stay upright when you're sliding back across the ice with your can of beer. Are there, are there injuries that occur in curling?
Oh yeah, I'm sure there are. Okay. Um, especially when you get used to trying to slide around. Yeah, on the slider. Um, that's— that was— throws people for a loop.
Um, you know, I suppose repetitive injuries on the sweeping part of it, you know. I think those could probably be issues.
Beer injuries. Beer injuries. Neck-related injuries from the skip trying to wring the neck of the sweeper. That's a classic injury right there. Yeah.
Yeah. Very funny. In terms of the industry that we are in, good old cybersecurity. So you've only had 3 jobs. Is that right?
I have. Right. Okay. They're very— they've each been kind of mini careers. Right.
So my first job I started off doing was localization, and that's basically the act of taking English software and translating it into different languages. Okay. So we, you know, you have vendors that do this. You just make sure that everything kind of fits in the boxes, builds correctly. And that's kind of where I got used to doing build systems and putting stuff together, extracting strings.
That kind of thing. Now, were you doing the translating? No, no, we'd have someone else do the translating. I just made sure that it all worked right. Regression testing, you know, when you look at software, you kind of know where things lie.
So, you know, when you, when you see the file menu, it's file in different languages. Yeah. So you get used to what those different languages look like. Yeah. Um, always realize that, you know, whatever you're putting, put in English, you know, plan on and like 75% more for German.
So that's why some boxes really look weird. Okay. Um, or, you know, double-byte character sets where we have Chinese or, or Cyrillic. Um, so it really got me into the internals on Windows. Okay.
Or on, on operating systems about how they process code pages and stuff like that. Um, so that kind of started, started me going down a deeper path, um, into like a little bit of programming with VB6 and stuff like that. Um, I kind of put together a little management system for that company for projects in VB6. Got me into programming. It was like, oh, this is really cool stuff.
Uh, and then I kind of— I was like, well, I don't want to do programming full-time. So I went to work for a startup, a company called VisionTek. Okay. In Boulder. And, um, it's not the, not the video card company.
Uh, this was a company that did mobile reporting. For law enforcement software. So I did VB6 in that company doing the client-server communications from the cars to the police stations back, the main sites they had and computer-aided dispatch. So that got me into government contracts, long-term sustainment type stuff. It takes forever for good money to come in in a startup environment.
But then I, you know, I worked with VB6 and I was doing all this communication stuff and I started exceeding the capabilities of VB6. So what's the next language? C++. And I pretty much self-taught C++, developed some middleware in C++ to handle the communications piece of it, and then programmed myself into a corner. You know, they were going to go to .NET and really there was no room for C++ programmers.
Okay. You know, so that got me looking up here in Fort Collins with a company called Mototron. Did you live up here at the time? No, I was living in Berthoud. Okay.
So I was kind of in the middle. Yeah. You know, and Berthoud was interesting because I moved there in 2000. It took me about half an hour to get down to Boulder and Superior. But by the time I moved out of that job into Fort Collins, it was taking me 90 minutes.
So it had gone up quite a bit, commute time. So I was kind of looking for a shorter commute, but also kind of a new challenge up here in Northern Colorado.
So, and also my first daughter was just born then too, and I was traveling quite a bit. So I thought this would not make me travel as much. So I applied for a job off the paper, off of paper, with a company up here called Mototron. And, um, it was my first like C programming job to, you know, apply for. Uh, so I ended up passing the phone interview, um, got in for, for a live interview, uh, and, you know, was interviewed by programmers, gave me some problems, uh, kind of wrapping up the interview session.
Um, I was kind of looking and there was a, there's an Edelbrock sticker. Okay. On, on like the thing. And I was like, Oh, you guys know Vic Edelbrock? And, uh, the, the primers were like going, you know Vic Edelbrock?
How do you, how do you know Vic? You know, well, I, I raced with him up in Steamboat. It was part of my vintage racing thing. Yeah, we, you know, raced out, hung out with Vic and his daughters, had some margaritas in the, in the pits. Uh, but I felt, yeah, might as well leverage it, try to get a job out of it.
Um, so we talked a little, kind of a little bit what, what they did for them, and I was like, oh yeah, they, the You know, human-machine interface. What's that? You know, it's a little dashboard that kind of tunes everything together. And I really believe that, you know, with my skills, but also with that Edelbrock story, that kind of what ended up getting me the job at Mototron and eventually here where I work at now is Woodward Incorporated. Mototron was bought up by Woodward in 2008, but really got me into cyber-physical systems.
And even, you know, with that job, that's been like 3 mini careers. In itself, right? Yeah, let's, let's explore that a little bit more. But before we do, so for those unfamiliar with who Vic Edelbrock is, um, so Vic Edelbrock is a manufacturer of aftermarket parts, uh, for cars. Uh, so basically if you have an older car or if you want to replace your ECU, um, Edelbrock makes components for that, um, for that setup basically.
So aftermarket harnesses, tuning kits, electronic throttle assemblies. You know, if you want to computerize your non-computerized car, yeah, for whatever reason you want to do it, you have that capability. So in your vintage car racing, right, have you donated lots of money to his cause, or his lifestyle, I should say? Yes. Okay.
Yes. The, the thing is, if you want a small fortune in racing, start with a large fortune. Um, because you're always dumping parts everywhere. Uh, but with the interesting thing you brought that up, in vintage cars everything's kind of spec the year that they, they've graduated and stuff like that. But you're finding that a lot of the older stuff that we have out there now, uh, you can't find parts anymore.
Yeah. So you have to kind of program your own systems or put your own stuff together in order to run it, uh, which is, you know, kind of makes a gray area for the rules stuff, but you have to be a little bit flexible. Yeah, we're not, we're not gonna win any money vintage racing, but we sure are gonna have a lot of fun, right? That's what it's about. Your 3 mini careers here then at Woodward.
So you started with Mototron, right? So that was the PC Tools interface into, into control modules. Okay. So I was really— what I was working there was basically handling calibration of modules with stuff with PC Tools. Okay, so that enables people to program, change values on those modules, and then service tool folks for, for third parties like engine manufacturers and stuff like that.
You'd make the update packages for them so they can update things in the field. I was coming out of the kind of an IP-based environment going into CAN, and I never really experienced CAN until I got here, which is the controller area network, and you find them in all cars nowadays. But they're also subjects of many hacking articles and DEF CON talks about how to hack into cars. Horribly insecure protocol and platform, but it does the job that you need it to do for control systems on cars. You know, it's low latency, works high and high noise, works well in high noise environments and is just, you know, very UDP-ish to get data back and forth.
So there are a lot of hacks in this. Yeah. In this realm? I did not know that. There are quite a bit.
I think the most famous one was from Black Hat DEF CON a few years ago called the GPAC, where someone got into a telematics unit, they were able to get into the CAN bus and cause havoc with the brake system, the steering system. And everyone kind of had a good, not necessarily chuckle, but we're like, oh, wow, we got to secure this kind of stuff. Right. Which in the vehicle realm, that was one of the things is you know, how do you secure engine control modules? Yeah.
So, you know, you start exploring those kinds of routes, those kinds of routes, not a lot of security on the embedded processors in that regard. So you kind of have to roll your own security in a lot of areas. Yeah. So tell me about the second phase of your career here. So the kind of second phase after kind of the engine modules and stuff like that, I was brought into our applications engineering group as kind of a control systems specialist.
I'd shown an aptitude for Windows operating systems kind of from that localization job, but also IP networking. So that kind of got us into industrial control systems where we have a control module, an embedded control module controlling like some kind of prime mover, like a turbine or a diesel generator, and then attach that to an HMI and a historian, human-machine interface, which is typically a Windows computer with a very expensive package, and a historian, which is just nothing but a database of time data. You have to get all of those items to talk together. So it's in that realm that, you know, you're trying to find synergies to make it easy to develop that kind of stuff. At the time, I started off in XP Embedded, which was their— which was Microsoft's componentized XP system.
So I got really good at building XP Embedded systems, and then Microsoft decided, no, we're going to change it on you and just make it into big image-based systems and make my life difficult. But at the time, XP Embedded was a lot of fun because you can actually cut it down quite a bit, get yourself in trouble, and then figure out what components are you missing and then add those components in later. And then as security requirements kind of come down, So a good example is the Department of Defense. They went through several cybersecurity programs, and I'm familiar with DiACAP and Risk Management Framework. So DiACAP was the forerunner to Risk Management Framework, and that was kind of like NERC CIP, where you had version 3, where you're protecting the electric grid and it's one package and you just extend that life forever for that package.
Where risk management framework is actually a risk-based approach to security. So I started doing some of that stuff, which got me into more of a security role in the industrial control systems area, in the OT area, which is a hugely— it's not as ignored as it used to be. It's actually at the forefront. People keep trumpeting about how we're going to have an attack on the electric grid and stuff like that. But it's a very specialized area of security that is not as wild.
It's, I think, more Wild West actually than enterprise IT security. Yeah. Yeah. And that's kind of where I really specialize in. I did that for a few years.
Okay. You know, working closely with customers, you know, bulk electric system, critical infrastructure, identifying security needs and kind of putting security stuff together in those applications where we had the control system, HMIs and switches and whatnot. And then it kind of blossomed from there because other parts of where Woodward plays at need security as well. So that kind of got me into the position I'm in now in our corporate technology group as the product cybersecurity engineer. Yeah.
And I find that title interesting because You're probably the only person I know that has that title. And when you first told me, I was like, what does that even mean? So, right. What does that actually mean? It's actually kind of exactly what it sounds like.
Okay. Basically, I help out our product or business units with their cybersecurity architecture and cybersecurity needs and try to make that kind of a cohesive look and feel for our product line. So each one, each place where we play at or each place where we have product at has different security requirements kind of handed down based on what we're, you know, what the application is going to be. But there's a lot of similarities. A lot of them have threat modeling.
A lot of them have risk management associated with that. It's just which different flavor do you have and what kind of rigor or what kind of traceability do you have to those security requirements? In your product that you have to prove out to controlling agencies. But the other benefit of having it in that position too is I can work with business units that may have issues with supply chain or they want to work closely with our IT or enterprise IT folks and their enterprise IT security folks and kind of act as a liaison with those other engineers to address some issues that we may have. You know, with security.
Yeah. Um, because security and development sometimes don't always mix, you know. Some tools don't work very well with compiling. Yeah. Um, you know, we've seen that quite a bit.
They rarely mix, right? So you just have to kind of, you know, you, you figure out what your risk, risk matrix is or risk tolerance is going to be and then address those issues. So in terms of securing like your Woodward's products, including products that go into planes, for example. That's kind of your forte, right? Right.
Yeah. So that's actually kind of really, it's starting to become more and more of an issue. In fact, EASA, which is the kind of the European Aviation Association, have now kind of put in cybersecurity rules when you certify aircraft or have to continue to certify aircraft airworthiness. So with aircraft cybersecurity, it's very specialized. Mostly because you don't have ground to back you up when something goes wrong.
It's very much more functional safety oriented. So safety and security are very tied together. And it's kind of a unique flow down because you have an aircraft, which is kind of the whole unit you're trying to secure. And then you have systems inside those aircraft, which have their kind of own mini domains. And then you finally have items at the tail end of that aircraft that will have logic in there, but have to have some security capability.
So charting that course is very, it's a very interesting challenge. You know, looking out, you can't look out, you know, a couple months to see what the next threat's going to be. You have to kind of look out the decades, right? For a lot of those types of threats and see what's kind of coming down the pipe. So you have a lot of trends, trends that you see You know, coming down, how are you going to secure this and how are things going to last a long time?
Yeah. One of the things, you know, that we kind of leverage or you can leverage, especially in like industrial control systems, is things last for 30 years. Right. You know, and we have control systems out there that have lasted a very long time, kind of around that area. And they still run, you know, people aren't going to change it.
If the process is not broken. Yeah. Um, and it's also— that's also a pain because if there's a security issue, people aren't going to patch the next day. Yeah. They have to kind of put a security plan together to figure out when they're going to patch, if they're going to patch at all.
They may just put up some defenses around it to, you know, not have to patch. Right. I mean, these planes are, uh, these planes last 30 years, right? The planes are a little bit different too, um, namely because they're still trying to figure out how to do the continuing, it's called continuing airworthiness. And the discussions are what happens if there is a security vulnerability?
So how much of a recertification effort is that going to be? How are we going to handle it? And they're getting better at trying to figure that out. They don't have it 100% figured out yet. We're still, a lot of the directives that come out of aircraft are still mechanically oriented or wear, maintenance, age, that kind of stuff.
It'll be interesting to see what happens when we start seeing those kinds of cybersecurity type directives start coming out. And I have confidence that the FAA knows what they're doing and will have some pretty good guidance when that does actually happen. Yeah, you have a uniquely challenging job. Keeping these things secure. So do you fly yourself?
No, I don't. Okay. It is one big regret I have. I don't have my license yet. I did grow up with airplanes growing up.
We had 3 airplanes on the farm. So we had a Piper J-3 Sea Cub, which, you know, if you're familiar with aircraft, it's a top speed of 60 miles an hour, fly with the doors open. But we refabricated that plane. Over one winter. So that kind of got me into aviation quite a bit.
We also had a spray plane, and then we had a Cessna 172 that we kept in a garage in town at the airport that we used for parts. I mean, to pick up parts for combines. Yeah, yeah, good stuff. Do you, uh, is there any community involvement things you want to mention? Well, I, I do work with SAE.
Okay. Society of Automotive Engineers. So I'm on the G32 Cyber-Physical Systems Committee. We're trying to put together standards around hardware and software assurance. So I do quite a bit of that.
I also work with the Northern Colorado Manufacturing Partnership. I've been on a couple cyber panels with them, just really helping out small manufacturers in their cybersecurity journey, really from an operational technology or OT slant to, to really kind of help them out as far as, hey, here's some small suggestions on business continuity, you know, how to protect yourselves if things do go south, you know, just small suggestions like that. Yeah. Okay. Very cool.
If you were going to give advice to younger Chris or somebody trying to get into the industry, what advice would you give? Stay flexible. Don't think that you're going around one career path, you're locked into that career path. There are a lot of opportunities here to be in security and you just have to have a passion for it. And you have to kind of keep an open mind.
Read a lot of Tom Clancy and Clive Cussler novels just to make sure your threat models are properly checked. It's really fun. Because if you're really up into current events, if you're really up into threats and what's kind of coming down the pipe, you can really apply that in this field. But just have fun with it. That's one of the nice things about security, especially in industrial control systems, is there are a lot of unique threats, but not all threats always affect you.
It might impact someone else, but it may not always impact you. Yeah. Yeah. Good advice. So how can people follow you?
So I'm on LinkedIn, Chris Sundberg. Yeah. A big happy Chris picture will show up. I'm also on Twitter, @Sundberg272. I will tweet about information security.
I'll tweet about cyber physical security. I will tweet about hockey. So you'll get good stuff. Well worth it. So those are the 2 big ways to follow me.
And you're also on Colorado Equals Security Slack channel. I am on the Slack channel. People can find you there. Right. Good stuff.
Well, thanks again, Chris. This has been a lot of fun. Great conversation. Thanks for coming up, Jason. Thanks.
Happy to talk security. Let's go have a beer. All right, let's go. That concludes my interview with Chris Sundberg. Be sure to follow and support Colorado Equal Security on Patreon.
This is Jason Jaques saying, be safe out there.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.