All episodes

Janelle Hsia, Founder of Privacy SWAN Consulting

Apple Podcasts Spotify SoundCloud

Janelle Hsia, President and Founder at Privacy SWAN Consulting is our feature guest this week. News from Empower Retirement, Uncharted, Red Canary, Optiv, Ping Identity, Richey May, Coalfire, and a lot more!

For Colorado=Security members only, through the end of 2020, Janelle Hsia is offering CIPT and CIPM training for $500 per course. Please DM Janelle on the Colorado=Security Slack Workspace for details and to secure this price. Check out our website for more information. https://www.privacyswan.com/privacytraining

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12210 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 183 for the week of October 5th, 2020. Alex, how you doing this week?

I'm good. How are you, Robb? I can't complain. A little bit of a little more smoke in the air the last couple days though. That's been a little unpleasant.

Yeah, I mean, it has been a little bit smoky on and off, and, um, it's very fallish, you know, nice cool evenings and mornings, that kind of thing. I mean, even a little chilly. Yeah, I do like the, the variety of temperatures versus like unrelenting heat that we've had for, right, for months. Yeah, I think this year was the highest number of days over 90 ever in Colorado. Yeah, that's no fun.

It was, it just, it did seem like basically from like early July to all the way through August, we just had 90s every day. Yeah, every day. And basically no rain, no fun. You know, I guess the, the upside to this whole smoke in the air thing is we're already wearing masks. So, you know, you're kind of getting a twofer on your mask right now.

That's right. Just wear it 24/7. Keep that smoke out of your lungs. That'll be good. I actually today was doing some like home improvement things and I was cutting drywall and, man, I'm sure I'm glad I have a mask so handy I can just pop on, deal with that too.

You know, it comes in handy. Yeah. You know, good stuff. Hopefully you're, you know, not doing The— I'm killing it here, Robb.

Just so everyone knows, we never edit the show. So, this is live how it goes. All right. Let's just skip that one and keep going. Hey, housekeeping.

We'll do this quickly. Some kind of housekeeping stuff. We have a Slack channel. Lots of great conversations. I'm definitely struggling to keep up with all the good conversations out there, but if you wanna get to know, what is it, 1,600 of your closest friends here in the Denver and Colorado region, Go out to the colorado-security.com website and click on our Slack button and you'll get in and get to know the community there.

Yeah, I feel like every week we're even like, you know, adding another channel or 2 just by requests from folks to talk about different topics. So that's fun too. We also have a mailing list if you wanna get the show notes delivered to you every week in your email. Go to the website colorado-security.com and put your email into the form there and you will get an email every week with the show notes. Uh, we would also love it if you would rate us and subscribe on your favorite podcatcher.

Um, go out there and just say nice things about us so we get lots of new listeners. Please tell a friend as well. Uh, let them know about Colorado Equal Security, uh, how great of a community we are, and that they should come join. And of course, if you want to support us even more, there's a couple more things you can do. Number one, we do love those— our patrons, those folks who are able to financially support the show.

It makes a big difference to us. I think, you know, As much, you know, there's the financial support, but I think just emotionally, it's great to know there's folks in the community who value what we're doing and wanna be part of the movement we're a part of. If you wanna join that, go out to our website and click on the Patreon campaign. You can give a little bit of money each month to help, you know, pay for the cost of hosting and other stuff. None of this money goes into our pockets.

It's all going right back out to the community, and we definitely appreciate the support we get there. Another thing you can do to help support the show is do those guest interviews. You know, we do love the, you know, there's a few folks who have kind of religiously been helping us with interviews. This week we have an interview with Alex, you did, but I think next week we have one from Jason Jaques. And if you want to be a part of that and do interviews, reach out to us.

We'll help you get figured, you know, help you figure out how to do it, get you set up with someone who you can interview, and we'll look forward to airing that on the show. Good stuff. Let's jump into the news. First, downtown Denver leaders are looking to possibly permanently close some streets for outdoor dining. So, if you've been downtown at all, you've noticed that there are some areas that are closed to driving so that there can be more outdoor seating for restaurants.

And for the short term, they're gonna— well, I guess it depends what you mean by short, but that's gonna be extended for about a year for some areas. Yeah. So, originally, they were gonna have these closures through October 31st. They've now extended it through October of next year. So, like you said, another year.

And I didn't actually know all the places this happened. There's a list of them. Some of them I noted, obviously, Larimer Square, that was the one I was well aware of. I didn't know Glenarm from 15th to 17th was shut down over by Denver Pavilions. Yep.

And then, there's 6 other places near throughout downtown, RiNo, the River North area, Capitol Hill, and Baker neighborhoods. Lots of places that they're doing this. It sounds just like, number one, I love it, right? I love the fact that you get these places where you have more walking, pedestrian locations. I think it gives more flexibility.

And of course, the fact that we've been able to help support those restaurants that are having a hard time in COVID is a good thing as well. Yeah. And this was on the Downtown Denver Partnership, sort of on their long-term plan anyway. They put together a plan several years back about, I think, through 2025 about what they wanted downtown Denver to look like. And some of those things were more pedestrian-friendly outdoor kind of entertainment areas, and this goes right along with that.

Another couple of interesting stats in here I pulled out. The Colorado Restaurant Association said that more than 60% of their member restaurants would do a winter outdoor patio program if they have the chance. But they also mentioned that while it sounds great, it'll cost about $5,500 to prepare the patio for winter. So it's not an easy thing for these restaurants to do. And I think it'd be fantastic if we can find a way to be able to still eat outside during the winter.

I've enjoyed the fact that since things opened up in whatever that was, June, July timeframe, we've been able to get back out and feel a little bit more normal. We can keep that over the winter in a safe way. Yeah, definitely. All right. Next, Charlie Ergen, who is the founder of Dish Network, has launched a new public company for telecom acquisitions.

Yeah, I read through this. This is just such a strange story to me. It's really weird. Yeah. Generally, I think of a public company, I think of a company that was private, started to do something at small scale, they got some level of success, they decided to go to the public markets after that to kind of like, you know, grow bigger and like maintain, you know, maybe their investors get some money out.

But, you know, basically they're just going to become a bigger scale company. It looks like this company he's creating is only created to be public. Like there is no company until they file this S-1 to go public. It's called Conx, C-O-N-X. I assume that's how you pronounce it.

They are looking to raise $1.1 billion, roughly $1.1 billion on their initial public offering. And really, they don't do anything yet. All they are is a an organization that's basically gonna go acquire other companies. It kind of feels like he's spinning up a private equity firm, but he's using the public markets to do it. So I'm, I'm kind of scratching my head after reading this.

I don't know that I understand how this works. Yeah, I don't think I've ever heard of anything like this before. Um, also, my guess, Robb, on the pronunciation is Connex. Um, this is going to be a telecom company. So, uh, I think that that Connex makes sense.

Yeah, Connex. Okay. I get it. The silly wording that they're going to do there. But yeah, it's— I'm not sure.

I mean, I guess, you know, Charlie Ergen has a track record. So maybe you would want to invest in a company that doesn't do anything because Charlie Ergen is behind it. But it just seems very odd. I don't know why you wouldn't just do actual private equity and have people invest that way as opposed to just strictly going to the public market to essentially ask for some money. That said, he does have both DISH and EchoStar that he has.

Those are both public companies and he owns just a little bit more than half of each of them and has had a lot of success. It's made him a very rich man and I think it's probably made their investors really rich as well, to be fair. I guess if he's figured out, he's got the formula figured out, why not do it again? So, good for him. I'm looking forward to seeing what this is gonna be.

They didn't get real specific about what they wanna do, but they do allude to the fact that they're thinking about investing in 5E— sorry, 5G as the kind of wave of the future that they wanna try and get on top of. Yeah, you went the wrong way there, Robb. If you're gonna go past 5G, then it'd be 5H. Thank you. I was thinking like 5th edition.

I don't know what happened right there. We are recording late at night and I've had a long day. Hey, next story is, you know, another one of these, like, I'm not even sure if we should put these in, but I find it interesting. So, I thought maybe the listeners would as well, that there's a prominent San Francisco investor who's leaving San Francisco to come to Colorado. This is interesting.

Basically, we have a new bigwig coming to town. Yeah. So, I thought that this was sort of interesting as well. You know, I guess you have to be a pretty important person to get an entire article written about you moving from one state to the other. But an investor named Ron Suber, who invests largely in fintech companies, has left San Francisco and moved to Boulder.

Yeah, that's pretty cool. I hadn't heard of him before, but as I kind of read through his resume, it really looks like he's done some pretty impressive stuff. He was an early investor in DocuSign. There was a bunch of other ones that I didn't recognize so well, Credible, Quill, Guvo, Unison, but from the way this describes, basically, they called him what, the godfather of fintech or something. Basically, if you want to be a fintech company and you want investors to like you, he's the one you go talk to.

Right. And I think it also said that if he was involved in a company, then he was like the Good Housekeeping seal of approval on the company. Sounds like he's pretty important. Also, I noted that he was at one time president of Prosper, which was a lending marketplace. I think, if I remember right, Prosper, you could put in your own money, sort of microlending and that kind of thing.

One thing that I thought was interesting was that he said he loves San Francisco, but the extra cost there, you know, sort of finally added up, and that it was costing him an extra $750,000 a year to live in San Francisco. Yeah, I, I think if you, if you wanted to do a little math, you could figure out the relative state taxes from California and Colorado and recognize how much money that means he makes. But I thought that would be depressing for me. So I didn't do it. Yeah, but that's just pretty incredible that it is that much extra for him to live in San Francisco.

Yeah, it sure is. So, next story, we have Empower Retirement. Oh, man, I feel like we've been talking about these guys a lot lately. They're continuing on with their kind of their spending spree. They're making a 3rd acquisition in the last few months.

Yeah, this one was, I think, was sort of less acquisition-y than the other ones that they did. They picked up the retirement plans from Fifth Third Bank. And they had already had a relationship with Fifth Third Bank. They were essentially doing the backend recordkeeping still for them. But Fifth Third Bank actually owned the portfolios.

Now, Empower is essentially buying those portfolios. So, they'll own the portfolios and do the bookkeeping. And Fifth Third will continue to do the financial planning front side of that. So, anyone who hasn't been paying attention, Empower Retirement, they're basically like your workforce 401. I think about Fidelity is the other big player in the space.

If you have a 401 program through work, you very likely have one of those 2 companies doing it for you.

We talked about it last time when they acquired the MassMutual ones. So from Fifth Third, they're just getting an extra 476 retirement plans, so 476 companies' plans. If you remember though, the MassMutual deal was for 26,000 workplace plans. And I think that they're over like They're like about half a million overall. So, I mean, this number of 460 or 476 is pretty small in the overall scheme of things, but it does show that they're continuing to aggressively look for new business.

Yeah, pretty cool, and congrats to them. Next story, we've talked about this a couple of times already, but Uncharted, which is a startup here, they'd been piloting a 4-day workweek and a 4-day, 32-hour workweek, just to be specific. And that was a 3-month pilot, and after the pilot, they've decided that they're gonna continue to do this on a permanent basis. Yeah, I think what's— I mean, there's lots of interesting things about this. I think one of the most interesting things is like how transparent they've been about the process.

You know, if you're thinking about, you know, if you run a company and you're thinking, man, maybe it makes sense for us to make a change like this, well, take a look at their blog series 'cause they basically talked about, you know, the positives, the negatives, how they've pulled data to determine whether they're being just as effective. And basically, you know, the resolution. This— I think that this is probably the last blog post in the series. They've decided they're going to keep it full-term and, uh, and kind of give the results of the analysis. Um, there wasn't a lot of negatives that they had to say.

I didn't feel like they— you know, at the end of it, they had some concerns about people maybe not being willing to do meetings, but they suggested that didn't end up being a problem after all. Yeah, I mean, it seemed like everything was pretty positive. Um, and I mean I guess from one perspective, if, you know, if you can get everybody on board with, you know, really concentrating and focusing and working hard for 4 days, you know, cut out the stuff that is sort of fluff in your week. Yeah, you know, maybe you can still get the same amount done in 32 versus 40 hours. I will say that your mileage may vary, especially because they are, you know, they're a very small company.

What I think it was 13 employees. Yeah, really small. And my guess, I don't know this company at all, but my guess would be when you get a 13-employee company that talks about something like this, the level of ownership that you're going to get on all 13 employees to make this work is going to be very high. If you tried that at a company with hundreds of thousands or tens of thousands of people, you're probably not going to see those exact same results. I'm just guessing.

For sure. Nonetheless, they did make it work and they're going to continue to make it work. So, congrats to them. Yeah, pretty cool stuff. I think it's me, Harry.

Yeah. So our next story is from Red Canary, and they have actually announced a new product. And honestly, I'd say it's a little bit of a change from what they've done in the past. You know, Red Canary, who we know very well as the EDR company, basically managing your EDR deployments, started off doing Carbon Black. They've added a whole bunch of products since then.

They've now really kind of pivoted, not pivoted, they're adding more features in addition to just EDR. They're also gonna be giving you like security alert monitoring for, you know, aggregating not just your EDR logs, but just about any other security tool along with it. Right. So, you know, I think it's an interesting way to look at it. You know, if I think in many cases, you know, if you are an MDR player and you, you know, you just take in EDR logs and use that data, you know, maybe someday you might decide, oh, well, let's start taking in, you know, other types of data to, you know, help correlate things and Okay, we'll start taking in firewalls and vulnerability scanning and, you know, so on and so forth.

You know, what they've said instead is we're not going to take in the data necessarily. We'll just take in the alerts and then we can use the alerts to correlate with what we already have in the platform. And then essentially you have a centralized dashboard for alerting and triage and actions. There's a lot of, a lot of good stuff here where they're basically going to prioritize which alerts are interesting, going to give you the ability to filter within those alerts on what things made it interesting or not interesting in the future. So, you know, you don't have to continually squelch alerts, that they'll do that for you.

And then they actually have like their team to do reviews of these alerts to actually add their human intelligence on top of your teams. So you're not going to just have their machine learning algorithms, you're also going to have, you know, their experienced team working to make this better. Yeah, and then, you know, you also have the ability to potentially take actions, right? So if some of these things do involve endpoints that have an EDR agent on it, then you could isolate something or take some other action there. Yeah, pretty cool stuff.

Yeah. I mean, it seems sort of, sort of SOAR-ish, right? Sort of SOAR lite, I guess. Yeah. I would say that they're adding some SOAR functionality within their tool, which is really just good at sorting the wheat from the chaff, right?

I'd say that's what they're best at is not giving, getting rid of false positives. And I don't know, I'd say my whole career, my My biggest challenge has been how do we— how do you get rid of all these false positives? They're good at that. And if they're able to actually get good at getting rid of false positives across other kinds of alerts and other kinds of tools other than EDR, that's a pretty big win for all of us who use them. Yeah, pretty cool.

All right, next we have a blog post from Optiv called There's Gold in Them There Metadata. Other than being a really well-named blog, I'm excited to hear what do you think of this? Yeah, it was interesting. You know, this is sort of a look into metadata in files and how an attacker could potentially use that metadata sort of as seeds to attack your organization. I guess starting at the highest level, what is metadata?

You know, when you think about a file, I think take a Word doc, for example. You know, we probably all think about the content of the Word doc as being, you know, the data of the file. So metadata would be, not the content of it, but like the kind of circumstances, the details around the creation of that file. Maybe you get the name of the user, how they registered in their Microsoft Office license, or you get the domain that they were connected to when they did it. All these things that, you know, that you might not think you're giving away when you share a document external to your company and how attackers can use that data that's not so obvious immediately when you look at the file to learn a lot more about your company.

And they do go through some really interesting examples of, you know, using that to pull out usernames that gives you— that now give us the format of our company's username so we can start to do password spraying against, you know, an internet-facing Outlook web access portal or something like that. Yeah, cool blog. Nice job by Optiv and interesting stuff there. Yeah, Optiv doesn't do a ton of these super technical ones, and I really love it, and I hope we see more of those in the future. For sure.

Alright, so next, this one's actually not really a story so much as kind of a brand new campaign that Ping Identity just launched this week that I, I love the video. In the show notes, we link to one of the new videos that are coming out, but Ping has kind of tapped a new celebrity to be their chief identity champion. So Terry Crews, if you guys maybe remember from, he's on Brooklyn Nine-Nine and lots of other places. He's like the host of a Some talent show now, right? To America's Got Talent or something like that.

Yeah, I think you're right. Anyway, so he's now the, the chief identity champion for Ping, and there's like a whole new brand awareness going around about this. Pretty cool stuff. And I think click the link and watch the 1-minute video to, to see what, what I like to think is one of the cooler marketing things I've seen for a security company. Yeah, it is pretty good, Robb.

Kudos on that. Great video and Love Terry Crews. It was a good choice picking him up. Awesome. Next, we had a blog post from Richie May, and this is talking about cybersecurity in 2020 and the changes we've gone through and challenges with work-from-home culture.

So, you know, they're really looking here at trends that we've seen recently from people working at home as well as just general industry trends. You know, things that have happened recently because of work from home, well, or being exacerbated because of work from home, things like, you know, problems with Zoom calls, problems with, you know, MFA and people being remote, you know, step up in phishing emails around COVID-19, other things like that. And then, you know, talking through some of the things that you can do to potentially, you know, help mitigate those vulnerabilities of people working from home. You know, many of these things we already know. This is a more, you know, end-user or, you know, small-medium-sized business-focused blog, but good information in there nonetheless.

Yeah, it looked like, you know, they were pulling some information from the Verizon Data Breach Report to give us an idea about trends generally and then trying to use that to make, you know, judgments and guidance for what we should do during COVID as there's just a whole lot more work from home, and that we, you know, if we were depending on controls to give us visibility on our endpoints, you know, from the office, you know, from network-based stuff, how are we going to do that thing remotely when everyone's outside the office? Anyway, interesting topic, and we'd love to see Richie May. They continue to put out some high-quality stuff.

And then our final news for the week, we had a blog post from Coalfire talking about Basics of Exploit Development on x86-64 Buffer Overflows. Yeah, we've got several of these, like this series of theirs in the past. We did one of the cross-site scripting recently, or SQL injection. I think it was SQL injection that we did with them a couple of weeks ago. This one's, you know, buffer overflows, and once again, I think both of us would admit it goes into a level of technical detail that's probably too much for us.

But man, if you want to get into the bits and bytes of how you can do a buffer overflow in a 64-bit operating system, a modern operating system, this is really going to go through those details for you. You know, the last time I looked at this, you know, buffer overflows was a long time ago and things have changed a little bit, but the general principles are the same. And I love to see, you know, this kind of education for free, right? You know, if you're just looking to get into the field and you want to dive deep, here's some great content to do that. Yeah, it is a very in-depth article.

You know, there's so much information there that I think maybe my buffers were overflowing. Hey-oh! Hey! But yeah, good stuff there, and if you are on the technical side, definitely check that out. All right, well, that's it for the stories.

Let's jump over to Slack Message of the Week. You know, as always, we get to thank Andre Gaeta, who has been sponsoring us from the beginning. Every week, we get to recognize one person who added value to the Slack channel You know, hopefully started a good conversation or at least made us laugh at one point, and that person gets a free item from the Colorado Equal Security Store. This week we got Tim Simpkins. Tim, you know, posted a couple of things.

I think it was Thursday or Friday, basically talking about the opportunity he had had to do some mentoring for a young— I think it was a security student— which started a conversation in the Good Stuff channel about, you know, how can we help that next generation go. And man, talk about something we want to encourage across the board is more folks helping bring the next generation up. So, Tim, congratulations. Yeah, congrats, Tim. And even more generally, you know, with everything that's been going on right now, more good stuff is good stuff.

Yeah, the rant channel has been beating the good stuff channel, and I don't like that. We gotta ramp up the good stuff channel. For sure. All right. Let's jump over to our event calendar.

As you may know, or you may not, we have a centralized event calendar on the website. So go check that out, see all the events that are happening around town. And in the podcast, we talk about those that are coming up in the next couple weeks. So first, ISSA Colorado Springs is doing the October online series on the 8th of October. Also on the 8th, the Northern Colorado ISSA chapter is doing their October chapter meeting.

On the 13th, Denver ISSA is doing From Zero to Hero: Build a Data Security Privacy Program from the Ground Up. And finally, on the 15th, the ISACA Denver chapter is doing their October chapter meeting, which is on the COBIT updates and resources, and it's a deeper dive. Obviously, they, you know, it looks like they're going to go pretty deep on those COBIT resources. So I will say, you know, It's amazing to me how well and how resiliently all these organizations have just moved online. And it took, what, maybe a month or so before they bounced back.

But man, I feel like we have almost the same cadence and number of meetings as we've had anytime in the past. Yeah. I mean, just like everything else, people are meeting remotely. So, pretty cool and I'm glad stuff is still going. Good stuff.

We'll jump over to jobs. Try and identify 10 jobs that, that we think are worth looking at. There are way more than 10 jobs that were worth looking at across the area, but we just pulled 10 that we want to highlight for you guys each week. And if there are any jobs at our companies, at Ping or Anschutz Corporation, we will talk about those there. And to start off this week, I do have one at Ping to talk about.

I am looking to hire a manager of our GRC program. He's going to be focused on programs for us, kind of doing ISO compliance work, SOC 2, vendor risk management policies, procedures, kind of all the good GRC type stuff, helping lead that program for us. And if you're interested in GRC and that particular one's not for you, we are actually going to be hiring several different positions in GRC soon. And if you want to reach out to me and talk about those, you can hit me up on Slack and I'll, I'll give you all the details. Awesome.

Next, Splunk is hiring several positions. One of those is a Senior DFN. IR analyst, and that can be remote. If you want more information about that job, you can also join Slack and reach out to Douglas Brush. Yeah, Douglas is, uh, is talking about a lot of cool positions at Splunk, and I'm sure he would love to tell you all about those, those jobs.

Um, next we have a position from TaxJar, once, once again a Slack job. Um, oh man, it's Jennifer Corradi. Um, she is hiring an application security engineer. If you want to hear more about that, go talk to Jennifer in Slack. Someone also posted this in Slack.

I don't remember who it was though. Coalfire is hiring an application security practice director for penetration testing. So if you want to do, uh, run an AppSec testing program, uh, for consulting, that sounds good. Yeah, that one was cool. And there was, I think, a couple other practice director Coalfire jobs as well.

Man, there's just a lot of really cool stuff out there right now. Uh, all right, next we have the position from StackHawk. We've talked about StackHawk on the show a number of times. They are looking to hire a customer success engineer. Robb, I am very disappointed that you did not pause for the cocoon.

Thank you. Validity is looking for a senior security analyst. Deloitte is hiring a BISO. That's one grade better than a CISO.

Bing! And that's it. That is a consulting job, not an internal Deloitte job. Survey Gizmo is hiring a director of information security and compliance. Centura Health is hiring a security engineer senior, and RE/MAX is hiring an information security manager.

Good stuff. Well, I think that's it for the news, Alex. We do have an interview this week. You met with Janelle Hsia. I did.

Uh, Janelle is a local privacy guru and trainer and practitioner, and, uh, we talked about her and her past and, uh, lots of stuff about privacy. So It was a good interview and I think people will like it. Look forward to that, Alex. Well, thanks a lot. We'll look forward to talking to everyone again next week.

All right, thanks, Robb. Hi, this is Rich Schliep, the CISO for the Colorado Department of State. This is Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equal Security. This is the interview This is Alex Wood here, and I have a very special guest today, Janelle Hsia. Hi, Janelle. Hi, Alex. How are you?

I'm well. How are you? I am warm in your backyard. Yes, it's nice we get to be outside in beautiful weather. Um, I almost mispronounced your name on purpose, um, so that I could go through the joke of how people probably mispronounce your name all the time.

Um, but what's the percentage of times that people pronounce your last name right? Well, let's start with the times I actually say it. Okay, so I think I have— maybe I've been married over 20 years. I think I have said my last name maybe 10 times in 20 years because for 2 reasons. One, I'm not Chinese, and so when people see my last name, they always assume there's a Chinese person.

And so whenever I check into a restaurant or even when I go to the doctor, they're always like, Janelle, and then they don't know what say. And I'm like, I'm Janelle. And they're like, but you're not Chinese. So there's that reason. And then also, I'm just— it's unique enough that Janelle's a decent enough first name.

So, but did you ask me how to pronounce it? No. Well, you're welcome to give the actual official pronunciation if you want. Oh, but the percentage of people who— yeah, no one gets it right ever. Sometimes they get close if they have friends or family who have a similar similar last name.

But no, the modern spelling is with an X, so X-I-A instead of H-S. And my husband, who's a network engineer, he likes to call it high-speed internet access. So yes, that's a good way to think about it. It is. I like it. Yes.

Well, good. Now that we've gotten that out of the way, thanks for taking a little time to talk with us. Yep. You know, we've known each other for a while through various circles, but I honestly don't know much about you personally or your background. I know that you are married to a person with a Chinese name, and that's it.

So how did you get your start in this industry? Well, I, I grew up in rural Minnesota, so farmer's daughter, and always knew I wanted to be in business. Like, that was always a thing thing for me. Had an opportunity to go to a technical college and started in tech in the '90s. I was implementing software for United Artists, was one of the big clients that I had, installing digiboards and, you know, components and actually true technology, technical things.

Not my sweet spot, right? Much better at testing and then training. I actually fell into training for HR systems. Systems. And then in 2008, I was going to start a company with a friend.

And my friend was— we were sitting at a coffee shop and she was— we were going through stuff and she's like, so how are we going to get paid or who's going to pay us? And I was like, sweetie, we're consultants. We eat what we kill. And she's like, oh, I don't know about this. So a couple months later, she went and found a real job.

I started Tailored Office Solutions with the goal of helping companies, you know, do what they love to do and helping entrepreneurs build their dream, really. And I had a background in technology and security and accounting, privacy, risk, you know, compliance, all these different skill sets. So I helped launch a lot of different businesses. Between 2008 and the— I don't remember when I— and then I actually, one of my clients asked me to take a job with them. And she, her business was federal security.

And so she needed somebody to manage her security projects for the federal government. Right. And I was like, not a small thing. Not a small thing. And a lot of my clients kind of were doing great, or I could do them part-time.

And I took a job for the first time again. And that parlayed into loving security, like true hardcore security. And I became a Deputy Information Systems Security Officer for 2 different federal systems. High-performance computing was one, and the other one was a SCADA system. And I did that for a couple of years.

And that's kind of really where, you know, I started to— was really the first foray into privacy per se, because for the federal government you have to do PTAs and PIAs, privacy impact assessments and privacy threshold analysis. And I was working with foreign nationals at the time as well and dealing with a lot of very sensitive personal data. And that— so from there I actually there was a job that I applied for. It was what I thought was my perfect job if I was not going to be a consultant anymore, which was contracts and compliance and security. So it kind of like was everything for a mid-sized company, and they were a SaaS company.

And so I did that, and I absolutely loved it. And I was implementing a HIPAA program and really in charge of the security program for small SaaS, mid— small to mid-sized SaaS company, um, and also doing contracts management. So like, I was the go-to person, right, for anything that no one else wanted to deal with. If there was a scary word, they were like, go find Janelle. Um, and I put my consulting hat back on, really, you know.

I became the trusted advisor for that organization and also helped some of their clients build security and privacy programs because a lot of their clients were also small. So they would call and they'd be like, what kind of questions are we supposed to ask you to make sure we have good security and privacy? And I was like, well, so then finally I created a checklist. Like, here, let me give you the answers and the questions and then we can just be done. Exactly.

And so, you know, did that and again got the consulting bug back. And I had never stopped my LLC, so I was still doing that a little bit on the side. And then GDPR hit, right? And for me, GDPR was the pinnacle of really everything coming together. It was both the carrot and the stick that I needed to get companies to do what I had been trying to do for years, what we all have been trying to do for years.

That's awesome. And so then GDPR, then you spun back out to do your own consulting again? Yeah, so when I was a consultant, I always built other people's businesses, and I never advertised Tailored Office Solutions. I didn't even have a website. I had business cards, I think, but it was just word of mouth and kind of, you know, I would pick up projects.

And like I said, I built businesses, and so that's kind of, you know, you're in for a while, right? And I'm happy to say that most of the small businesses I started or helped start back even as far as 2008 are still doing well. But I never knew what I wanted to do. It was always helping somebody else build their business. And I was okay with that.

And then last year, I think I really found my voice from a privacy perspective. Really— and I mean, I had always been passionate about it, but it really clicked. And I was kind of playing around with some names. And one of the things I do as a consultant is when I go into companies, I always would say one of two things will happen when we engage. You know, the reason that you bring in a consultant is there's pain, right?

You want to solve a problem, right? And I said, so one of the things that I'm really really good at is helping to define the problem and then help find solutions. Like, there's rarely a problem that I can't help figure out a solution for. And so I would say, if you bring me a problem, one of two things is going to happen. Either I'm going to tell you, oh my goodness, thank God you told us about that because we didn't know, it's not on the radar, we need to go tackle it.

Or I would say You know what? I have a solution. And I'd pull out a form and I'd go, here, problem solved. I said, either way, you're going to sleep well at night. And so I kept saying that over and over again.

And I remember saying it last year and I was like, oh my God, sleep well at night stands for SWAN.

And I was like, Privacy SWAN Consulting, done. Nice. I like it. That was launched. Yeah, that's cool.

So, I mean, I look at you definitely as a sort of a first mover around privacy. You know, there obviously privacy has been around for a long time. It's kind of, I don't know, you know, security was kind of a bigger deal for a little while early on and then privacy kind of in the background like, oh, okay, yeah, we'll take care of stuff too. But clearly you've been on the privacy bandwagon for a while and it's very important to you. What is it about privacy that appeals to you?

So, I was at Black Hat 3 or 4 years ago, maybe it was probably 4 years ago. It was right as GDPR was taking off and I was still at the small SaaS company. And I, was walking around. I love the vendor floor. I know most people think it's a zoo and all of that, but I actually love the vendor floor because I loved learning.

So to me, that's really cool. And I walked around the vendor floor and I was like, so where's your data stored? And they were like, what are you even talking about? And I was like, well, there's new regulation coming out and we're gonna really need to worry. There's this thing called onward transfer, you know, and people— companies are going to actually have be responsible for the data that they collect and store.

And glassy-eyed, no idea. And I was like, this is a problem. Like, this is a— you know, like, I— they would— I would go all the way up to the CEOs of some of the small companies, and they were all oblivious, right? Yeah. And so, so based on that, What did you think was— what do you think was it that needed to be done to get people to understand their obligations and why privacy was important?

It was to get them to understand it's about the data and it's people's data. So a lot of the regulations talk about data subjects, or they have— I can't even remember some of the other terms that the other regulations use, but I don't use those terms. I use mother, I'm like, it could be your mother's data, it could be your daughter's, your dad's data. And I try and make sure that people know it's personal data. And I actually right now have a client that transacts in a lot of HR and payroll types of data.

And I tell them every time I get an opportunity, I said, you count people, and because you count people, everything matters. Everything is in scope. There's not a report that you can show me, there's not a document that you share that's not covered by GDPR, right? Yes, this is all people data, right? I said if you're selling shoes or widgets or Teslas, then you have a small set of personal data, but a lot Companies need— and that's the thing— companies need to understand the type of data and the impact of that data to the people who they're dealing with.

Yeah, definitely. So you obviously work with a lot of different companies around privacy. What— and, you know, as we've matured over the past few years around privacy, at least I would think most people have an idea that they should be doing something about it. Whether they're doing anything is another story. Correct.

But where are the areas that you see that people are still doing things wrong? They're not doing anything at all. Yeah. I'm actually still surprised at the number of conversations I have with businesses who haven't even started GDPR or CCPA or any kind of regulation. And I think the other one, the other sweet spot that I have is I deliberately am going into unregulated areas because I think people who have HIPAA or GLBA or PCI, they get some kind of compliance.

So I'm really trying to hit small to medium-sized businesses that don't even know what the word regulation or compliance means. So to your question, they're not doing anything. Either they don't know that all these regulations exist, or they feel like they're overwhelmed, or that they fly under the radar and that they, you know, it doesn't matter. Yeah, I mean, it's an interesting risk calculation, whether it is, you know, something that they're— they've actually stated, or something that's just kind of in their mind, like, eh, it's not gonna apply to us, we're too small. I've always thought that that's interesting, is how people do the math to justify not doing stuff like that.

But I also think it's interesting that the— there are so many people that don't do that, that kind of thing. I mean, most of the jobs that I've had have been places where you are regulated somehow, right? So maybe I'm a little bit blind to that part, you know, with, with no regulation. But you would think that people would at least, I don't know, do something. Even if it's like, we have specifically decided not to do anything, that's something, right?

Right. As opposed to just, I'm gonna completely ignore it. Well, you can tell. So all you have to do is go to a company's website and go to their privacy notice, and you can see the date on it. And before, I mean, I do that with all I don't necessarily read it because nobody can read them, but just look at the date.

That's the first thing you have to do. That, that's an interesting point that you bring up.

How do you feel about privacy notices, and what do you think could be better about them? So there's— there was a study that was done, and I don't remember the exact number of days. I don't know if this is part of what your question is about, but it would take like 76 days to read all the privacy notices we're subjective to. So, I think the question about privacy notices kind of goes back to the old paradigm of privacy, which was notice and choice. Right.

We have privacy notices so that consumers can be educated and informed and they can make an informed choice. Well, I— that's just not the case. Right. You can be notified of something that you don't understand because the language is too dense and you don't really know what it, what it means. So yes, so it's pretty tough to be informed about that.

Yeah. So have you seen people that are trying to do better in that area? Absolutely. So that actually is— if I had to pick an area of privacy that I was most excited about right now, it would be solving this problem with the consumers. And the only way that I think that we can do that is by implementing technology to help solve that problem.

And there's, there's a specific set of technology called privacy enhancing technology, known as PETs. And going back to the privacy notices, they have a lot of cutting-edge technology that can help notify you if you come into contact, like with Internet of Things devices, right? So wouldn't it be great if your phone or your watch said, oh, you're in the vicinity of, you know, a microphone or some sort of recording device or surveillance devices? Or I was seeing something where, you know, everybody has their phone and they have those apps where you can see the stars, right? So what if they had an app that you could track the drones.

So you could say, oh, that is drone this, you know, because they're supposed to be registered, right? And you could click on it and get their privacy notice if you cared. You could say, I opt out of— make sure you have blurring technology because that's a technology, right, of faces. I don't want my face, you know. So no, there's so many different ways companies can implement notices without having it be a link on the the bottom of the page.

Yeah, I think that it's a really interesting idea because, I mean, that's what you're trying to get to. I think a lot of times the lawyers get in the way of that because they want to make sure that legally they are covered, not just providing an experience, or not even caring about providing an experience to the consumers. It's more about covering themselves. I think that the technology angle is interesting one too, though, because I think a lot of people do think of privacy as a legal problem as opposed to a technology problem. But there are obviously a lot of technology pieces that go into it, whether it's privacy by design or anything like that.

Are you seeing people adopt those sorts of practices, or do people, I think, still view this mostly as a legal problem that we need to have a notice and that, you know, we'll worry about it after the fact? I think that part— so what I— so I was actually supposed to do— I have a presentation that I have been giving which is called Security Needs a PET, Privacy Enhancing Technique or Technology. And I was supposed to speak at 4 different conferences this year. So excited. The reason I bring that up is because I think that it's awareness.

So when I talk to people, they still think that privacy by design are the 7 principles that the Canadian Privacy Commissioner put together, right? They're not actionable, and they don't realize that there are so many technical things that you can do to actually not lose the utility of the data, but actually continue to use it, the data, for what you're collecting it for and preserve privacy. It doesn't have to be an either/or. So I think the problem that I see is just awareness that these other things exist. And I really think that's where academia and the lawyers have been stuck for the last 20 years.

All of the people that have been doing privacy for a long time really come from what I would consider consider that old mentality of notice and choice. And I am coming from technology. I learned about these pets and literally my head blew off. I was so excited because I don't think we can solve this with a technical or with a legal solution. The law is never going to be able to keep up with technology, right?

And while I believe we need regulation, maybe not like GDPR or CCPA. You know, I'm more of a moderate, but we need some guardrails. But to solve the actual problem, we need to implement technology. That's awesome.

So I also think some of the problem is awareness, like you said, understanding more of the details behind principles as opposed— you know, how things can be actionable. How can people mostly technologists learn about that stuff? I have a training. Funny you should ask. So I am— so IAPP is the International Association of Privacy Professionals, and I actually was knocking on their door last year begging to do training for them so that I could bring technology— bring privacy to the technology and security people.

And so, if you don't know about the International Association of Privacy Professionals, IAPP, it's one. There's also the Future of Privacy Forum. There's many other great resources that are out there to help educate people. And I know that ISACA also has started to do some privacy. Deloitte has some privacy training.

So, there's a lot of different— they're starting to get some training out there. But one of the things I'm most excited about for the IAAPP is they have their new course deliberately focused at the technologists and bringing privacy to the people who can actually make the decisions. Because I think that one of the things that has happened is that we know that design impacts everything. And The technology that we're living with today was designed in the late '80s and '90s, basically. And if we look at the people who was doing that design, it was really white men, right, in their 20s, right?

They were right— either they didn't, you know, so young. And a lot of the design decisions we're still living with are from, from 30 years ago. And we need to change that paradigm. Yeah, definitely. Um, the— I love the IAPP.

I think they're a great organization. Um, I will, I will say, you know, it's like an ISACA or an ISSA or something like that. There is a cost to be part of it. However, I do know that they have partnerships at least with ISSA and maybe some other organizations, or at least they did, to give free memberships to IAPP if you're a member of some of those other organizations. So if you folks listening are ISSA members or potentially other associations as well, I would check to see if you can get a free IAPP membership as part of the organization that you're already paying dues to.

Not that I want to take money away from the IAPP, but hey, you know, if you want to add privacy into whatever you're doing and you can do it for free, that's great. And honestly, IAPP champions that. And in fact, IAAPP and ISSA have been partnering for a while, and I'm hoping to bridge that partnership. So, I work with both associations. And just recently, the international branch, or the ISSA national/international, have created a privacy special interest group.

And so, I'm a tri-chair of the national or international ISSA privacy special interest group. So Jason Kronk, who is the author of the Strategic Privacy by Design book, and Beverly Anders Allen, who is a renowned privacy expert in the medical field, and I are leading the charge on that. Nice. And we are next year focusing just on technology, and we already have 2 fabulous speakers lined up to talk about things like homomorphic encryption and multi-party, secure multi-party computation, and technology and techniques that people can implement that they probably don't even know exist. That's awesome.

How do people get involved in the ISSA Privacy SIG? That is a really good question. So if you go to the ISSA, if you're already an ISSA member, You can, you have to do a little bit of digging right now for the Privacy SIG landing page, but I know that they are working on making it easier. So more information to come, and I'll definitely put it out on the Slack channel, make sure that people are aware of it once we get those up and running. Yeah, and once we find it, we can put it in the show notes for the episode too.

That'd be great. Yeah, that would be perfect.

So you also mentioned that, I don't know if we got to the details of it, but you were doing training also. Yep. Are these in-person trainings, online trainings? What kind of stuff? And are these sort of going towards certification trainings?

Tell me more about that. So IAPP offers 6 certifications and I teach 4 of them. And so at a high level, They are CIPM, Certified Information Privacy Manager, which is implementing a program, a privacy program, and really geared to more of the director, executive, somebody who's creating and managing the program. Then there's the CIPP-US, which is a legal class of all of the patchwork of privacy regulations in the United States. Super excited that one of the top, in my opinion, she's humble, privacy lawyers in Colorado has agreed to teach that class on behalf of Privacy SWAN Consulting.

And the other one, we also have a CIPP/E class. The E stands for Europe. So there's some European privacy history and talking about why privacy is different in the EU versus here and why we have these huge debates and we talk about things like SHREMS II and standard contractual clauses. And then we spend probably 70% of the class on GDPR and get into the focus of GDPR. And then the last class that IAPP has just revamped is the CIPT class, Certified Information Privacy Technologist.

Okay. And that's the one that I'm the most excited to teach. And I've actually, I actually have been taught it a couple times for some of the folks here in Colorado, and I'd be willing to give steep discounts for anybody who wants to take that class. And so to answer your question, so they offer certification, and so these classes, if you take them, are certification— they don't call them certification prep classes because they're ANSI certified and they can't do that, but they're geared towards that, right? Or you can just take them for training, and I actually also advocated for the IAPP to let me just do the training because I feel so strongly about the fact that most technical and security folks, we don't need more initials after our names.

And to pay $500 and some for an exam for a cert that you don't need is a little unnecessary. But the training, in my opinion, is life-changing in the industry. Yeah, so that's— it's interesting. I'm glad that you sort of pursued that angle because I've tried to work with the CSA before, and I love CSA, they do great stuff. But if you want to have someone teach their class, then it has to come bundled with a certification attempt, which means the class is much more expensive.

Yep. Right, you got a base level of cost no matter how much you as the teacher want want to charge for it. You know, we've, we've talked about some things like that with RMISC in the past, and it's always been a stumbling block, right? Because we just— well, I would be happy again for people to take the certification, that's great, but our focus is the education part. So we'd rather just be able to provide people education without forcing them to take the certification unless they want to.

Yep, absolutely. And I, again, I, I don't know that I was the only advocate, but I'm kind of loud and obnoxious, and I know how to send a lot of emails. Yeah. So of those, if someone wanted to— they're new and wanted to start in privacy— what would you recommend? Where would they go first?

I guess it would depend on if they're in management or if they're a hands-on person. If you're in management, I would do the CIPM, the Certified Privacy Manager course, because it's an overall arching class. It talks about the different frameworks that there are, It talks about how to integrate a breach notification into an IRP. It talks about how to, you know, kind of like the swim lanes of privacy and security, and kind of like, in my opinion, because I throw in my opinion a lot in the trainings, who should take point and things that are shared together. A lot of privacy training is in there.

If you are technical and you have the ability to impact change, either from a product manager who are writing the requirements for products. If you're in QA, dev, or security, any of those, I would recommend the T class, which is the technologist class. And it is very tech-heavy. I've had a couple lawyers who have taken that class, and they're just— they thought it would just be a few, you know, but they don't understand. Even the lawyers who have been doing this for 20 years, they don't understand that there's technology that can be implemented that can be life-changing for people who need to stay anonymous and for the vulnerable people whose data we're trying to protect.

Yeah, that's awesome. All right, switching gears slightly. Yep. I saw within the last week or so that Brazil has implemented a privacy framework that is fairly similar to GDPR. Yep, some differences, but, but pretty similar.

And there are obviously other countries that have done similar things. Where do you see the future of privacy regulation going? You read David Stauss's article, didn't you? Don't tell anybody.

Dave does all the good stuff that I can't. He does. I love him. I totally agree.

So I would also add SHREMS II to this conversation. Sure. Yeah. Yeah. And I think that— or CCPA II.

Exactly. We could add that on as well. Exactly. Yeah. Any acronym that you can think of.

And I do think that, again, I come from it from a technology perspective, I really don't think that the laws and the regulations can solve the problem. And kind of going back to what we talked about earlier about being regulated, I also think that companies need to understand that privacy, true privacy— and I actually like the European definition of data protection. So sometimes you'll see data protection and you'll see privacy, and there's— in Europe there's a really big distinction between those 2 things. And so if we talk about true data protection, can be a competitive advantage for companies. And there's a study out by Cisco that actually shows the ROI on implementing a privacy program.

So I know everybody wants to talk about the laws and the regulations, and I think that if you implement a good privacy program, you're going to get to like that 80% compliance perspective, if that's what you're concerned about. And then the rest is going to have to be jurisdictional and risk-based. I mean, in some cases, I would even recommend to companies that they, that they don't even look at some pieces of regulations because they have no risk in that. So I definitely take a very risk-based approach to the implementation. But I don't think that can be solved with privacy regulation.

Good perspective. I like that. All right. We're getting a little close on time. What haven't we talked about, Janelle?

I think kind of going back to that same thing of privacy programs. Yeah. So I think that if, you know, you are a company and you don't know what to do, kind of like, you know, do something, right? And building out a privacy program really is the best thing to do. Even if you're not regulated today, we know it's coming.

And figuring out how to put in a governance program— and I also like to embed privacy into existing processes So if you have a security program, you know, figure out how you can add privacy-specific pieces to that. We haven't talked about the— you didn't ask me the difference between privacy and security. I'm assuming that our audience knows that. We're beyond that here, Janelle. Okay.

We could argue that. But adding— so kind of taking that, or if you have a GRC team or an enterprise risk management team, being able to start talking about privacy and putting that in. And I think also the other piece with that is knowing where your data is. That question that I asked like 4 years ago before we really had, you know, Article 30 in GDPR, ROPA, Records of Processing Activities, right?

Actually doing that activity of documenting that and the business processes and then going through that processing activity and maybe descoping some systems. I think people don't realize that, you know, if you pull out specific pieces of data, you actually can descope the risk to the individual. The biggest piece of data that I, that I think gives people the aha moment is date of birth, right? Right. Do you need to collect date of birth?

Because I would, I would argue that 90% of people who collect it don't need to collect it. They need to know one of two things. They need to know— they— or they want to know that they want to send you a birthday card, and then you just need the day and the month. Or I would argue just the month, because I can't even get birthday cards out for my nieces and nephews on the day, right? Right.

Or if you want to know how old somebody is, I would even argue you don't need their date or the year they were born, you just need a range. Right? Am I over 18? Am I over 21? Am I under 45?

Am I whatever that is? Yeah. Or bracket it, right? And so, you know, maybe the audience already knows, but it only takes 3 pieces of data to uniquely identify people, about 80% in a data set. And date of birth is one of them, gender, and zip code.

So people keep talking about, oh, it's anonymous, right? It's actually not anonymous. Yeah. And I think you can do some of that stuff with a little thought too, right? One of the things that comes to mind to me is kids' sports, right?

You know, you need to know how old a kid is so that they can be placed on the right team for age group, right? Now, say you're playing club soccer, it's, you know, 15U. Okay, you have to be under 15 years old to play on the on this team, well, you could, instead of asking for their birthdate, you could say, were you born between these times? Right. Right?

That means you qualify for this team. Or, you know, were you born before this time? You know, it's one of those kind of questions where you're getting the data point that you need without having to collect the data. Yep, and that's called getting the utility from the data while still preserving the privacy. So that's a plus gain, right?

Like, we didn't lose anything there, right? But we preserved that piece of data. I actually was at the optometrist last week because I need new glasses. Yay me! And the date of birth was on my prescription that they printed out of the thing.

And I— well, when I first got there, they wanted to know my height and weight and blood pressure. And I— my, my poor— my son was with me. I feel badly for my children. I was like, scratching it off and they're like, you know, we've never felt comfortable asking those questions. And I— and so I implore people to, when you see things like that, right, why, why are you collecting this data?

Yep, absolutely. Yeah, so in the beginning of that, the statement you just had, you're advocating for creating a privacy program. I think some people, if they hear program, they're thinking that's a lot of work. Yeah. If you wanted to tell somebody to do something that was short of a program, what would be the one thing that they should do to get started on this?

Hopefully everybody has an inventory of their systems. I would find out what data is in those systems. So we're gonna have to start to figure out what systems we have is what you're saying? Yes, well, there's that. I know, that's the joke, right?

So shadow IT, I have some tricks for figuring out how which systems you have if you're curious about those. So yeah, so no, I mean, that's a good, a good start and probably something I would have said too, right, is okay, know what data you have in your systems, and at the very least then you can have a data catalog. Hopefully you would go beyond that, but I think you can kind of ease people into a program by at least doing some of the little things first, right? And I think it's a good cleanup exercise too, you know, like when we go in, some people have like 3 Salesforce accounts, right? So can we consolidate that down?

And we saved them money. We cleaned up their data. I mean, who hates crap or bad data? It's the worst. You know, so we give them an authoritative source of data, and that actually helps from a privacy perspective too.

One of the principles of privacy is having accurate data. Yeah. So we get many wins there. Nice.

The— what about, what about tools? How do you feel about privacy tools? I love privacy tools. Going back to if you don't have a program, I love— you should start with a spreadsheet because you can't— a tool is only as good as the data that you put into it. And so if you buy a tool and you don't know what data you're gonna put into it yet, you really could be buying the wrong tool.

Yeah. So, there's a lot of great free forms, spreadsheets for collecting a lot of the data that you would need to put into these tools. Even like for data subject access requests, everybody's freaking out about, you know, oh, we've got to do data subject access requests for CCPA and GDPR. Well, take a deep breath. How many have you had, right?

It's kind of like with SHREMS too. How many FISA orders have you had, you know, let's take a risk-based approach. If you don't even know what that is, you probably have had none, right? So, same thing with subject access requests, you know, and so take a deep breath is the first piece, and let's document it, and let's work through 3 or 4 or 10, and then figure out what the process is for the organization, and then let's get those requirements. I love requirements.

Did I mention in the '90s I did requirements? Like, literally, we were arguing over should it be an and or a blue button. It was requirements and then buy the system. Got it. Sorry, long answer for— No, that's a good answer.

All right, if people want to find you, where do they look? privacyswan.com. Okay, awesome. Simple. Yep, very simple.

Yep. I do have one really— Sleep well at night. Sleep well at night. Exactly. Yeah, do you like that?

I I like it. Sorry, one more thing. You have one more thing? I just want to give a huge shout out to Joe Dietz. OK.

So he was the one who recommended me. He was. Love Joe. Love Joe. Yes.

So thank you, Joe, for making this happen. Yep. Took us a little while to get it organized, but we made it happen. Yep. Awesome.

Well, thanks, Janelle. It was wonderful talking to you. You too. Thanks for stopping by, and we'll talk to you again soon. Awesome.

Thanks, Alex. This has been Colorado Equals Security, and we'll talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes