Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is a newscast for episode 185 for the week of October 26th, 2020. Alex, we're here in person.
How you doing this week? I am well. How are you, Robb? I can't complain. Everything's good.
It's getting a little bit cold. It's almost like winter here right now. It is almost like winter. I think, is it Sunday into Monday? It's gonna be a low of 5.
That's cold. That is cold. Yeah, that's cold. Hopefully you've winterized, you know, blown out your sprinklers, drained them, all that kind of stuff. Removed the hose from the faucet outside.
Remove your hose, yeah. Big tips. So in the spirit of this last week, Alex, I've decided that whenever I don't wanna hear what you're saying, I'm going to mute you. The only problem is the listeners won't be able to hear it, but I will still hear you ranting and raving in the background as I do my muting. I think it's similar to the debate this week.
We're trying to be topical here, guys. This is a— we are recorded in real time and you're listening to us in the real October. I think instead of that, well, you can, you can mute me while we do this, but you should edit in the Stackhawk caw caw instead of whatever I say. It's basically bleep you with that. Yeah, exactly.
It's not bad. Hey, why don't we talk about some housekeeping? All right, let's do it. So, Robb, did you know we have a Slack channel? A what?
Yes, Slack. It is a messaging chat room. It's like Microsoft Teams, kind of? It is like Microsoft Teams, except sort of functional. Shots fired!
We have over 1,600 people in that Slack workspace, and we would love for you to join us there. So go to colorado-security.com and click on the Slack link and join us. We also have a mailing list. We would love it if you would sign up to our mailing list, and you will get very, very infrequent emails. Once a week we send out our show notes, and we are debating sending out an email to our mailing list telling you all to go vote for the CISO of the Year on the APEX Awards.
Yeah, but we haven't done that yet. You know, that would be the first time we have used it for anything other than sending out the, the one email a week. Yeah, well, you do have to get your nomination in. I think it's by the 31st. So there's just a couple more days.
There are just a couple more days. Go get your nomination in for your favorite CISO. We want to make sure we get recognized there at the APEX Awards coming up, which has been pushed to February, by the way. And when Robb says we, he doesn't mean like, you know, him and I. I mean, while we like being recognized, We mean the security leader community recognized. We want to make sure that the security community is represented at the APEX Awards.
That's what I meant. Exactly. We would also love it if you subscribe to the podcast in your favorite podcatcher and rate us while you're there. You could also tell a friend if you like the podcast. Actually, if you don't like the podcast, you can tell a friend.
Just say all kinds of terrible things, but make it sound like we're kind of controversial so that maybe they'll want to listen. The old press is good press. Yeah, old press is good press. Yeah, exactly. We also have a Patreon campaign if you'd like to support us financially.
Go out to the website as well, and we have a Patreon link. You can sign up there and, and help us cover the costs of the show. And, you know, depending on the level you sign up for, you might get some cool stuff like a t-shirt. All right, let's, let's skip the last one. I'm tired of talking about that.
All right. Hey, there's some news this week. What? After 21 years, the Pepsi Center is no more. Yeah, they've just demolished it.
They're knocking it down. You know, you know, it's COVID. They're not using it. So just get rid of it. Too much rent.
But for real, what are they doing, Alex? So it is no longer going to be called the Pepsi Center. There is a new agreement with Ball Corp. It is going to be the Ball Arena. So we'll have Dick's Stadium and Ball Arena, right?
What are they, a quarter mile away from each other? A little more than a quarter mile. But, you know, in the grand scheme of the earth, it's probably close enough. So, so the arena will now be called Ball Arena. I'm looking forward to that.
You know, I read the article thinking basically I would've got everything I needed to know from the headline, but actually there was some interesting stuff in there as well. This didn't start off as a naming rights negotiation between Ball and Cronkite Sports, which owns the Pepsi Center. It started off talking about how Ball could be the sustainability partner for the arena. You know, we talked about on the show a couple of different times that Ball has created these aluminum single-use cups that are super easily recyclable. They started using it at CU games and now they're using it at Broncos games.
The intention of this is that Ball is going to make sure that those single-use cups are, um, used at all of the Cronky, uh, facilities, which includes the Ball Arena here in Denver. Um, and they're also gonna really do work hard to, to make it a really seamless way for people to, to get those cups while they're there, recycle them, and they'll be back in production. I think they said like 60 days later or something crazy like that. Yeah. They're, they're trying to make it a, an actual closed-loop system.
So, you know, it goes into Pepsi Center, it comes back right back to Ball, and then you get new cups out of it. So that's pretty cool. I, I thought the sustainability part was really neat too. And then, you know, also the fact that they are, they're not just doing it at the new ball arena, but they're also doing it at the other places like SoFi Field in LA. The name of the one in where Arsenal plays in, yeah, in England, which I forget the name.
You know, it's not owned by Anshut, so I don't care.
But, you know, I thought that part was pretty cool too. Yeah, really cool stuff. Exciting to see. And, you know, I'm excited to see our new Ball Arena overlords. Pepsi is not a Denver company, so I'm— that's true.
Get out of here. Pepsi will still be the official drink of the— you're not going to be buying your— you're not going to buy a Coke. No, no, you're not. All right. Next, there is a new flight sharing startup that's helping people get on chartered planes.
So, Alex, have you ever Have you ever used Uber? I have used Uber. I've also used Lyft. Have you ever been like, man, I sure wish I had Uber for my chartered flights that I do? Yes, because I am on a chartered flight all the time.
Yeah. And it could bring— it can bring like that chartered flight cost. I assume usually you're spending somewhere in the $25,000 to $30,000 per flight range. Yes. Bring that down to about a tenth of that if you get enough friends to do it with you.
That's pretty cool. Yeah. So obviously this is not for people like us who fly on Southwest, you know, when we're excited to see those $39 emails coming into our inbox. I only fly when I can get the $39 fares, Robb. That's it.
But this is a— it's a pretty cool thing. And it's— and of course, we're talking about it because it's a Denver company or a Colorado company. Yeah, they're out of Steamboat, actually, called Shared Charter. Steamboat, of course, is up in the mountains where the rich folks like to fly into. So this is a pretty good opportunity where people who want to have the convenience of a chartered flight, you know, no TSA, you know, you know, get your bags immediately without having to spend that, that premium to do it.
Yeah. And also to help make the process easier. You know, if someone is already flying a charter and they have an extra seat, you can jump in there with them. And, you know, hopefully there's someone famous and you get a cool experience as well as paying your, you know, exorbitant amount for a chartered flight, even though it's less than a full flight. But, you know, cool stuff like that.
I assume that if you're a pilot, you could sign up you know, on this as like the, you know, hey, I got a flight I'm going to be doing type of a type of thing. So I know a lot of people in the security world are pilots. So maybe this, maybe this is a possibility. Yeah, pretty cool. Take a look.
Check it out. All right, next. The OSIRIS-REx mission to an asteroid to pick up asteroid dust appears to have been a success. And this is being run by Lockheed Martin here in Littleton. Yeah, it's really cool.
There's, there's a great space industry here in Colorado. You know, obviously we got Space Force headquarters here, but Lockheed has their headquarters for this mission out in Jefferson County. And really, this is, this is one of the neat missions we've had in the last several years because this is the largest amount of material they've taken from anything other than the Moon. And what I was excited to see how much it was, it was about 60 grams. And I don't know if you know how much that is, But it's very, very little.
I snort that much every day, Robb. Oh my gosh.
What's the— what's the name of that? Oh, man. That anti-cold medicine people take to— that's kind of fake. Yes, I know what you're talking about. But anyway, I really won that.
I feel like this is really going well. Good comeback there. Anyway, so I, I thought that the, you know, just in general, the whole mission is cool. I mean, obviously cooler because it's being run out of Colorado and, you know, the folks flying it or hear. But, you know, they sent this spacecraft out into space, landed it on an asteroid, and then used an arm and sort of a gas gun to push this asteroid dust into a little container.
And now they're gonna bring it back. So in order to avoid the flood of emails we would get, I will say they did not land on the asteroid. They did what's called a touch-and-go. Yeah, where I believe they didn't actually stop right there. They continued And just kind of brushed up against it as they went.
And they fire some canister off to, to get all— get the 60 grams of dust in there. Right. And a quarter of that dust is going to be coming back to Colorado. Yeah, that is pretty cool. The other quarter, I think they're going to lose on the way back.
Or the other three-quarters, I mean. Yeah. You know, it'll probably burn up coming through the atmosphere or something. Cool stuff. Exciting to see.
Obviously, you know, as tech geeks, we all find space travel to be pretty awesome. And it's cool to note that this was successful. We have a company name change. So we— I think we all know who Survey Gizmo is. They do surveys, but they do so much more.
And that's why they have changed their name. You know, after more than a decade, they have changed their name to Alchemer. And Alchemer, of course, does all kinds of cool stuff. Yeah. You know, it was an interesting quote in the article.
The CEO said that there's 2 things wrong with our name, survey and gizmo. Yeah. And so that was, you know, part of the reason for, for the change there. Obviously, if you are doing things that are outside of that, maybe people will be confused. Yeah.
They also, they do survey, of course, but they also do workflow and audience communication, um, analytic tools, uh, really to, to help all of our enterprises really do a lot more voice of their customer type interactions. So stuff that, you know, I didn't know they even did. Um, a couple other really interesting things here. Um, while they had a slight dip in business at the beginning of the pandemic, they said, but since then, they've actually posted record sales in August and September. So not only have they, you know, come back from their dip, but they're, they're, they're growing gangbusters.
Yeah. So, you know, folks that are working only online now need more of this survey and workflow and other automation pieces. They are a company up— was it— they just moved recently from Boulder to Louisville, I believe. And they have about 120 employees in town. And interestingly enough, they're all bootstrapped.
They don't, they don't have investments from outside the company. They're growing because they're profitable and sustainably. Pretty cool. And congrats on the name change. All right.
Next, Zayo Group is getting a new CEO. Dan Caruso is stepping down and joining the company's board. Taking his place is Steve Smith, very successful NBA player, if I— if I have my Steve Smith correct. Yeah. You know, also a famous receiver in the NFL for the Panthers.
He's done a lot. Yeah, he's done a lot. Although I guess that was Steve Smith Senior for the Panthers. So maybe this is Steve Smith Junior. It's really hard to keep track of what Steve Smith's done.
He's done a lot of good stuff. Apparently most recently, though, he was a managing director for the private equity firm GI Partners. Of course, he's going to come over and run Zayo. If you remember recently, Zayo was acquired by a different private equity firm. So they've really changed their form.
But the intention is that they're going to continue to grow and be a world a big force in the world around telecommunications. I also noted that Steve Smith was CEO of Equinix, I think, for about 10 years. And I mean, Equinix, that's a pretty big deal. Yeah, well, Equinix, obviously a very similar industry to Zayo, and it makes a lot of sense that his experience there would have made him a great fit for this. And just so everyone knows, we know this is a different Steve Smith.
This is, this is the Stephen A. Smith who's a commentator on ESPN. So we don't need that flood of emails on that either. All right.
All right. ABS Capital Partners, Goldman Sachs have invested in DeepWatch. So DeepWatch is a company that kind of came on us by surprise not too long ago. They were a rebrand from another company that— GuidePoint. Yeah, one of the GuidePoint branches.
But they're an MSSP and they, they say that their headquarters is here in Denver and they recently took on, what was it, another $53 million in capital. And just to be fair, they don't have a headquarters. Their de facto headquarters is here. They are all remote, but they have a number of people here. And so they've, they've said that Denver is basically our headquarters, even though we're not technically headquartered.
So we're going to claim them. We're going to claim them. We'll take it. So they got this $53 million and they're planning to use that investment to further develop their cloud security platform and expand their partner partner ecosystem. They recently said they're also going to have a lot more headcount they're going to hire, including here in Denver.
And speaking of headcount, I don't know that we've ever had anyone from Deepwatch on the show. So if, if you're at Deepwatch and you want to be interviewed for Colorado Equal Security, we'd love hard-hitting questions, though. We're going to ask hard questions like, what are you watching and what is your name?
Why are you talking to me? Hey, we have 2 things from Ping this week. First, uh, Ping had a press release because they got— won a couple of cool awards. Um, so they, they were recently named the, uh, one, one of the Denver top workplaces, which I totally agree with. I, and I've worked there for almost 5 years, and I think it's a fantastic place to work.
Denver Business Journal has recognized us once again as a top workplace, but, but that, that's kind of, you know, every year lots of companies pick for that. Uh, but this year, um, the, the, the one that Most admired CEO is Andre Durand. Andre is my boss over at Ping, the CEO and the founder of Ping, and rightly recognized as a, as a great leader. And most, like I said, most admired this year by the Denver Business Journal. That is pretty cool.
I, every time I have met and talked with Andre, he's been awesome. So I would imagine that he is a pretty good boss and good reason to be admired. It's, it's, he does cool stuff with business, but he's also like awesome in the community. His his wife and he do this court-appointed advocate, court-appointed advocate. It's called CASA.
Basically, we're like, like kids who, kids who, you know, have really tough family situations and need someone to go to the court and help them with cases and work through the system. They do that. And like, that's in addition to being, you know, running a public company and all this stuff. Anyway, super respect the guy, not only for personal but professional, but also personal stuff. Yeah, pretty cool.
Congrats. To Ping and congrats to Andre. Next, we have a blog from Ping. Jeremy Miller is writing, and this is about the SSO practitioner's introduction to decentralized identity. And Robb, I don't get it.
We've been trying all this time to centralize identity. Why are we decentralizing identity? Yeah. So, it's a really interesting model, and Ping recently has announced a new offering here. So, of course, this is why there's a uh, a blog post about it, but I'll talk you through what, what the perspective is and why we think this is important.
You know, the first wave of identity, um, kind of as, you know, everyone's controlling stuff and, and it gets super painful when you're, um, when you're, when you're having to, to sign in to every different site independently. Um, second wave being when we get— got this centralized identity where you can sign in one time and it federates everywhere, but it's controlled by someone else. It's controlled by Microsoft or Google or Ping or A single sign-on. Yeah, single sign-on is a great function for sure, but the, but the challenge is who runs it. So if you're using your Google, your Gmail account to sign into things, well, Google is the one who has all your information, and Google makes a heck of a lot of money by selling that information about what you're doing.
They do not, Robb. I do not believe that. I know, breaking news everybody. Uh, so the, the, this next way, this decentralized identity is where you control your identity and you can use it in a centralized fashion. So you, you have this claim on your, on your device, you know, call it your phone in this case, that's gonna, it's gonna say, hey, I'm Robb, and by the way, I have these, this, these claims from the state of Colorado that says I'm allowed to drive here.
I have a claim from Ping Identity says I'm employed there. I have a claim from my university that says I got my degree from there, and I'm able to share these claims wherever I want to with whatever degree of granularity I want to, not whatever degree of granularity some third party says, right? So a great example of how this works is If you, if you walk into a bar, um, and, and, and they, they want to know— there's a rabbi, a Catholic priest, and— right. But before they got in, people wanted to know that they were 21, and I could submit my, my identity and say, all I would say is, here's my proof I'm over 21. You don't get to see my driver's license with my weight, which is a little bit embarrassing for me, and you don't get to see my eye color, which is important that I hide from you.
Um, you just get to see that I'm over 21, and that, that's what the, you know, owning your own identity and doing it in this decentralized way kind of gives you. A lot of privacy, security, a lot of different use cases that I didn't get into, but that's kind of high level. Yeah. And the embarrassing part about that, Robb, is clearly that on your license it says you're a lot lighter than you actually are. Well, totally.
It really does. It's very embarrassing for people to know how much I lied. Anyway, I really like this blog. It was very interesting that they, you know, they break down the tenets that you have to use for decentralized identity and, you know, at a high level how it works. So if you want to know more about it or you didn't know about it and want to know something about it, it's definitely a good thing to take a look at.
Next, we have a blog post by Red Canary. They had a bunch this week. It was hard to pick between. I picked this one because I thought this is the one that I would most like to be using at work. There's a tool called Surveyor, which is an open source tool that I think that Red Canary developed, that they actually have this blog post is written by one of their customers, a customer who picked this up, up this open source tool and started using it and described how to use it and what it does.
Um, so it was written by Grover, uh, Mewbourne, um, who is at— get the company right— at a company called CoStar, real estate, um, company called CoStar. Um, and he just talks through how you— how they use this tool to get a lot of great, uh, telemetry and information around their organization. Yeah, the tool sounds really cool, and, uh, the way that they— that this company has implemented it, um, also sounded really cool. You know, you could use it, say you have a you know, a file that gets dropped somewhere that is, you know, part of ransomware, you could then use this to check to see if you have that file other places, you know, things like that. It reminds me of what's the Facebook thing, the tool that they developed to go query things?
osquery. Oh yeah, yeah, osquery. Very similar, but it queries things. But the difference is it's using the information you already have from your EDR tool. Yes.
So you're not having to go deploy a new agent to go pull these things out. Functionality-wise, I mean, you're trying to find out this other information. So that was pretty cool. And, you know, if someone is not, um, you know, in your EDR tool or familiar with the EDR tool, they can use this in a much easier way to get information like that. Looks like command line, mostly looks like Python type stuff.
Anyway, yep, good stuff. In our final news for this week, uh, there is a blog post from Coalfire talking about getting around the cybersecurity talent shortage. And this actually is focusing, I think, a little bit on, on the leadership part of, uh, talent shortage. Yeah. So, so This is one that kind of aligns with a Coalfire offering around virtual CISO, and they're talking about what are the use cases where this makes sense to use this kind of service.
I'd say, first of all, this is a high-end service, so you're not talking about, you know, going in and pushing tickets through or doing security analytics work. They're looking for more strategic work on this, and they identify 3 places that companies might want that, starting with if you're looking for a senior security leader to deal with external stakeholders like regulators or your customers. Or I think they, they talk about the board potentially as well there, right? Um, you know, or second, you know, someone who can come in and do some security program leadership either in an interim fashion or, you know, if you don't quite have that, that position inside. And then finally, uh, some leader who can, uh, kind of work with your mid-level, uh, internal stakeholders to give them direction around security and, and give them the, the tactical guidance on how to go implement security throughout the organization.
So a few different ways to use it. I'm not sure that this really solves the cybersecurity skills gap, which is what the headline is, but at least it shows you how, you know, if you need one of these 3, that this might be a good fit. Yeah. I mean, I can see where if, you know, you need one of those skills as part of a person, you don't necessarily have to go out and hire a full person. You know, that you can use part of their person.
Yeah. You hire, you hire a piece of a person for that. So anyway, good stuff. So that's the news. Let's move over to Slack message of the week.
Andre Gaeta, I appreciate what you do on sponsoring the Slack message of the week. Each each week he out of his own pocket buys one item from the Colorado Equal Security Slack store, and that person gets a twenty dollar item delivered directly to them. That is great. This week the winner is either Levia or Levia Nahari talking about the Rockies DevSecOps Days. So that's an event we've been talking about on the show for a week or so.
This is a Uh, you know, every year DevSecOps or the DevOps Days event happens, and this is a really good opportunity for you to learn how do I do security in that CI/CD environment with a new tech stack. Um, so Lavia, thank you for kind of highlighting the fact that this is coming up this next week and, um, bringing folks to it. We're looking forward to seeing how that event goes. Yeah. Um, and I, you know, this has also happened in conjunction with RMISC in the past, so I think along with everything else that has been delayed.
So good to see it's finally getting there. All right, uh, we're gonna jump over to our calendar of events. We do have a, uh, a calendar on the website if you're wondering, man, when should I schedule this new event that I'm thinking about putting, uh, putting together? Well, you should go out to our calendar and you can see what's coming up and make sure you're not putting it on the same day as everything else. Exactly.
Uh, first on the 28th, the ISC2 Pikes Peak chapter is doing their October chapter meeting. On the 29th is the DevSecOps Days Rockies. That's the event we just talked about. On the— excuse me one second— on the 4th, ISSA Denver is doing their Women in Security November meeting. And I'm pretty psyched about this one, Robb.
They'll let anyone into these meetings, won't they? They will let anyone into these meetings. And it's not me we're talking about. 2 people I know are actually presenting at this meeting. They're actually having some sort of breakout sessions with lots of different topics.
My wife is actually presenting at this meeting. She is not a security practitioner. She is a guidance counselor, but she is talking about ways that you can work with your kids, helping them cope with uncertain times using social and emotional learning techniques. Pretty awesome. And also, one of my college roommates, Shannon Heers, is talking about managing anxiety in the workplace.
That's pretty awesome. Yeah. And so both of them are not security professionals, right? Neither of them are security people, so these are non-security topics, but you know, things that are good for everyone. Yeah, good stuff.
I love it. Uh, final event to talk about the next couple weeks is on the 5th. ISSA Colorado Springs is doing their online November meeting. All right, uh, that is it for events. Let's jump over to jobs.
Robb, does Ping Identity have any jobs? Yeah, you know, the floodgates have opened for security positions recently. I have 3 jobs I'm looking to hire right now. First, we are— this is a new one— we're looking to hire a FedRAMP program manager. So if you are interested in helping Ping go through the FedRAMP process and get those FISMA controls in place, we would love to have you join the, join the team.
We're also looking for a manager of GRC to help us with other compliance and kind of policies and governance type activities. And third, we're looking to hire a product security engineer. So we're looking for someone with an application, with a development background and an interest in security. Awesome. Enquire Solutions is looking for a VP of Information and Systems Security.
CISO. Sunflower Bank is hiring an IT risk management director. LogistiCare, in their ongoing saga of trying to hire somebody, is looking for a director of IT security governance, risk, and compliance. Lumen is hiring a senior manager of information security. SnapDocs is looking for a risk and compliance manager.
Cognizant is hiring a manager, information risk manager, corporate security. It's 100% remote. Ooh. Frontier Airlines is looking for a manager of IT security. And finally, in the best title of the week award goes to Deloitte for hiring a cyber risk infrastructure zero trust senior manager.
That is a mouthful, Robb. I wonder if you put commas in different places, I think you could change this title to be all kinds of funny things. That's a good one. Maybe next week we'll do that. Yeah.
Hey, that is it for news. But hey, good news. We do have an interview this week. Yes, we do. We have an interview with Joe Dietz.
Looking forward to hearing about Joe and what he's been up to recently. And of course, Joe is, you know, relatively, he's active in the security Slack channel that we have, and he's also active in the community more broadly. So I'm looking forward to hearing what Joe had to say. Should be good stuff. All right.
Well, that is it. We'll look forward to hearing, seeing you guys in November. It'll be November next time we record. Wow. It is hard to believe that.
Hard to believe. Yeah. All right. Have a good one, guys. All right.
Thanks, Robb.
Security at Alps Fund Services. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Hi, welcome to Colorado Equals Security. This is Janelle, and today I'm excited to do an interview with Joe Dietz, who I consider a pillar in the security community. He's a network security architect at Lumen. Hi Joe, how are you? I'm doing well.
Is it a great day where you're at today? It is. And as I think it's happened to Alex and Robb before, you know, there's lawn mowing and, you know, blowers going on around the house, but I think I can continue through it. Awesome. Good for you.
You're going to power through. That's right. Now we may have a dog in my house too. So yeah, yeah. So if we have a cat come across the screen, I get it, right?
Yep, absolutely. So I think we met about 5 years ago at a security event, but I don't specifically remember. I don't know if you do. I think I do. I mean, my— I think we met at the Cloud Security Alliance here in Denver, and at the time I had a few peers that I was working with and in the industry just saying, hey, you know, we need to get out to some more of these meetups.
And, you know, I was attending ISACA ISSA, the OWASP organization, and then CSA was kind of a new burgeoning chapter, right, in the Denver area for me back in about 2015. And I had gone to a few events, and then I think we really got to know each other, and I got to know other members of the CSA at the holiday party, if any place else. It was kind of just one of those things to have a social. I remember saying hi to Al and Mohammed. I think Al might have been the president at the time, and met some other folks— Trish, Dario.
They know who I'm calling out here, but all great people, very supportive, and obviously Janelle was one of them. And Janelle, I know I listened to your podcast not too long ago, and people are challenged with your last name. I know.
I actually don't see it, and I don't say it, and so yeah. Do you want me to give you a clue? No, I was gonna try, and you can tell me if I got it right. Oh, okay, go ahead. Is it shia?
It's close, it's shia. Shia, all right, one word, all right, one syllable, got it, okay, great. Just to capture that, terrific. Hey, Janelle, before we get too far into it, I just want to do a little bit of housekeeping just because of employers and that sort of thing. I just got to make that kind of slide statement when I do presentations that, you know, during this little chat, the comments are my own and represent my own opinions and not that of my employer.
So I just wanted to get that in and out of the way before we got too much farther along. Yeah, no, I definitely, I understand that, and I've heard you do enough presentations that I was kind of expecting the disclaimer. So, so thanks for that. So, you know, the other thing is I think some people know you as Just Joe, right? So, so who is the Just Joe?
Okay, well, I kind of use that term because it's a little snickety sometimes in that, you know, one thing that's maybe a little intimidating about, you know, doing Colorado Equal Security is we get some real, as you termed it, pillars in the community. A lot of people are quite accomplished and they have good titles or they're business owners. Um, you know, we've had lawyers on, a lot of what I would call accomplished people. And, you know, I kind of sometimes, uh, look at it a little bit more humble. I go, well, I've been at the same company for 20-some-odd years and, you know, I don't have a fancy title and that's okay.
That's not who I'm about. Um, but great for people who are. And, you know, some of it was, you know, I have a big impact in our organization and in different, you know, volunteer positions, but it's just as Joe. So I kind of just coined that name just to kind of just, you know, you don't have to have a big title. And maybe that's something we can encourage more people to participate in some of the Colorado Equal Security interviews.
And I wouldn't normally have volunteered to come if someone didn't ask. And some of that is because, well, I'm I'm not a CSO. Well, you know, who wants to hear from just Joe, right? That sort of thing. And I'm playing some word games there a little bit.
Yeah, no, absolutely. And I think from my perspective, I mean, I agree with you. And I think that we do tout people who are in management or who choose to go that route from a technical perspective as the people to interview and to look up to. But I actually really respect the technical people who try to stay technical, or not try, who stay technical and really become the source of truth and have the expertise for those really difficult technical solutions. And so I really like it when companies don't push technical people to become managers, but they allow them to become principals in their discipline, which, you know, like you said, 20 years in the industry.
Sure, sure. Yeah, and if you know you read my bio or read a, read a, you know, resume of mine, it will say I'm interested in leadership positions. It doesn't say I want to be CSO. It doesn't say I don't want to be CSO. But I think as a technical person, you can be a leader.
And I have a kind of an anecdote about that. I have a peer, a younger gentleman, who said, Joe, you're a rock star when it comes to this stuff. You know all this and that and everything. And I'm like, Gee, I wouldn't have used that terminology for myself, but the context he put it in was kind of what we're talking about. He said, gee, I thought I was going to have to go into management to be a leader, to make an impact in security.
And he says, geez, you're watching you in action in some sense that's kind of changing his mind a little bit, right? And he's kind of looking at, hey, I can do leadership things. I can have an impact. I can partner, collaborate with people who are in those leadership managerial roles and still make an impact as someone who loves to do whatever, you know, pen testing, threat hunting, whatever your specialty is that you're just passionate about. Yeah, no, I absolutely agree with you.
And I think that that's— that is something that, you know, to help bring up the younger generation of security professionals, right, we need to direct them in multiple directions. Absolutely. So is that something that you would recommend? And how would you recommend people kind of get over the idea of having to be a CISO and be able to pick a different path that's just as challenging and rewarding? Well, you know, I think every— I think everyone had to— to your point, I like that word path.
Everybody has their own journey or path. And I always kind of tell people who are looking to get in security, I go, I go, what do you do today? And it might be a sysadmin, they might be a DBA, they might be a PM, right? That sort of thing. Or maybe they're just even an accountant and they say, how do I want to get involved with this?
I would say, take what you're doing and kind of maybe apply, you know, security to it, right? And we as kind of savvy or more experienced people could say, well, apply red team or blue team or purple, you know, those sort of ideas to what you do today. But I even kid my wife who's kind of got a, You know, accounting background. And I said, well, gee whiz, you're really good with numbers. You're really detailed.
And, you know, accounting auditing, some people just love it. And that's glamorous. But I said, you know, if you did some of the right trainings, you could kind of— I always call it pivot or ricochet from what you know. And, you know, somebody like that could make a great, you know, QSA or something like that, right? An auditor of that type.
They have to learn some new skills. But they're leveraging a lot of who they are, right? Yeah, and I think it's kind of like one of the things that we talk about too is you try and turn everybody into some kind of security professional, at least at a little bit of a level, right? Yeah, and what I always tell people too is I go, you're a security professional where you are. You just have to take that mindset.
You know, if you're a sysadmin and go, well, you know, okay, well, you've got the responsibility to secure and harden that system. And some of this is taking the initiative to do that, right? I mean, it's kind of one of those things things, best practices we should be doing, but taking the initiative and maybe being the leader on that system admin team that says, I'm going to be passionate about this. The next thing you know, a year or two later, the security team, right, that division says, wow, so-and-so has been doing a great job with that server infrastructure. Look where he took us.
Can we get him on our team? Right? So there's, there's ways to get there. You'll get noticed. Yeah, absolutely.
So how did you start in security? Well, I did kind of start— gee whiz, you know, I tell people I was kind of born in the telco. And I say that in a sense where I'm from back east originally. I grew up in New Jersey and my dad worked for AT&T and specifically Bell Labs back in the day. And I kid folks, I think I've heard it on the show before, where I thought an office supply company was AT&T because all the staplers and things that they can't.
They don't need to know that. But yeah, but, you know, I struggled as a young person going, what's my career going to be? And back in the day when you had to walk uphill in snow both ways to school, you know, computers sounded like something where no matter what I chose to do would be interesting. So, you know, 9th, 10th grade, I took a class in high school and You know, I'm going to date myself, but, you know, I'll throw a couple of gems at the people who are closer to my age. We worked on a PDP-8, right?
And it was a paper punch machine that made noise when you hit the keys like a typewriter, and it shook and all this stuff. That's how you put your code into a machine back then. And, and they had lots of cool blinky lights, and disk drives were the sizes of, you know, I was going to say an LP, but most people don't know what an LP is anymore either. But right, okay. So you could kind of tell Joe has more gray hair than, and then Noah.
Hair. But yeah, but then, you know, it kind of just went on with that. And I went to— I started with community college. So, you know, go community college, folks. Yep.
Just as a place to start. Yep, absolutely. Yeah. So I kind of got involved with— in our community college, they had, you know, DOS and IBM PC/XTs just came out. And, you know, I volunteered to, you know, help out in the computer lab, which is really you know, at the time dusting the PCs.
I don't want to say it was anything all that technical, but kind of went on from there. And then I had an aptitude for, you know, just programming and that sort of thing. And then, you know, kind of did that, like I said, kind of did that pivot. I kind of remember reading one day about firewalling and network, and this is really before the internet was, you know, what we know with browsers and that sort of thing. You know, kind of had that little bug in the back of my head that says that that might be intriguing.
So I slowly learned about it. Then back in '94, right, just yesterday, at least it feels that way. Yeah, just a short time ago.
I moved out here to Denver. I was single, wanted to ski, have fun, a lot of reasons why a lot of young people move out to Colorado, and got involved at the time with US West. And I got a contract as assistant admin. And kind of after proving myself there, they were like, Hey, you know, we need to kind of get on this internet thing. And, you know, I could tell people we were using Gopher and Mozilla and Netscape.
I mean, those were the browsers of the day. So anyway, we did a fun project where I was able to bring in like the first DIA T1. That was big bandwidth back in the day for the entire organization, and it came with support, right? We had other T1s and little labs and really smart people knew how to make some of these connections, but we made it kind of accessible to the business, right? And then I tell people there wasn't much on the internet other than at the time Yahoo and probably adult material.
Yeah, exactly. No, just to be honest. I know. No, I know. I'm sort of in that gray-haired category with you too, so I remember those days.
And you mentioned, I think you either came when it was Quest or West, but I remember working in downtown when they dropped the big Q over the US West. Yeah. Yeah. So I mean, I'll never forget that. I thought, you know, everyone was like, I think that, you know, the thing was he had to change it from US West to Quest overnight.
And how was he going to do that? And then the next day, the giant banner, you know, down the building. So can you walk us through, like, you know, what AT&T, Bell Labs, like? Oh, yeah, sure, sure. Well, I started with US West.
But yeah, if you rewind probably 10 years before I started, with them. It was AT&T and Mountain Bell and that sort of thing, and there may be even a couple other versions, but I'm not even that old. But yeah, so, so I kind of started with US West, and I kind of take a dogleg because I kind of went over to the phone book side of the house when I was working at US West. So we were decks. What, you know, remember when we had phone books?
There's another thing to date, right? That was when personally identifiable information was publicly available and published, and you paid a lot of money money to make your name big, right? That's right. That's right. So, you know, kind of a notable fun thing, and I still have some of the original material, just kind of a keepsake.
We put the first online Yellow Pages online. I was involved with that team, and most of my involvement tend to be, you know, network security, server architecture, infrastructure, that sort of thing. I wasn't the guy there writing code on the backend per se. I had to understand what the guys were doing, but it was more tuning the servers, having multiple servers, you know, that sort of stuff. And then Dex became Media Group, and a lot of people don't know what that was, but at one point the cable company and the phone company thought they could glue wires together and just become one.
And TW Telecom, or at least a portion of it, Dex became Media Group. It didn't last real long, right? Right. So that was maybe a couple years. It was during the dot-com boom, so people were innovative, creative, trying to do a lot of neat things there and create something.
And then Dex spun back into to US West. They bought them back, and then shortly, very shortly after that, it became Quest. And we all, you know, that's the not-show years we'd rather not remember. Yeah, exactly. And then, you know, things turned around, I would say.
You know, it wasn't overnight, and we merged with CenturyLink, and that seemed to be a really good fit. It's still, at that time, I would say we're a telco, still a telco, right? It's the big thing. They're moving more and more into internet service provider, but that was what that business did. And then, you know, the most recent, about 2017, was the Level 3 and CenturyLink merger, right?
And that one was, I want to say, when I think I saw things turn the corner away from being just pure telco, right? Level 3 had a real passion for service provider. They had a strong practice. I think it complemented a lot of that corner of the business that CenturyLink had, but that wasn't CenturyLink's only focus. And then, you know, current day, and this is, you know, what, you know, less than a month ago we announced we're now Lumen.
And, you know, my leadership is going to probably challenge me on this one, but make sure I get it right. But the idea of a disclaimer— so that's right, that's right. So, you know, lumen is that measure of light. So it kind of moved us forward. You kind of have that fiber optic thing, we're, we're moving that.
And what they did was it was kind of like ABC Corp for Google, right? Google's got all these different companies, but ABC Corp's the holding corp, right? So Lumen's that bigger holding corp, and then we have, you know, CenturyLink proper, which was— it's, it's still, it's phone, it's telco, it's DSL. And then they've got a new division, I think they call it Quantum, and that's the go-forward fiber optics for mainly for business, but I think you can still get it for, uh, uh, you know, residential too. So that's kind of the go-forward, as you know, there's going to be a sunset on copper at some point, you know, at some level.
Um, and then there's the rest of the business that's, you know, I want to say Lumen proper. Everyone's a Lumen employee, but Lumen is really that, hey, this is our growth part of our company, you know, that sort of thing. Um, and, you know, we, like I said, we've kind of turned the corner where it used to be the bulk of the income for the business came from, you know, phones and, and residentials, that type stuff. Now the bulk comes from innovative stuff coming out of Lumen, some of the more exciting stuff. And I'll let people go read, you know, Wall Street stuff on— I won't elaborate, but edge compute is our big bet going forward, and it looks very promising.
So do you see your job changing a lot with this new acquisition? You know, I think like many of us in security and in technology, that's this business's, you know, that's our bread and butter. So yeah, at my current position, you know, what we do as network people, what we do as security people, what we do as, you know, even developers and all that, because, you know, all the network's becoming software right now, right? You're moving towards all that. It's less about buying a router and putting it in.
So I think we're really well positioned with was the talent that got the company to kind of, you know, move the things forward. I'm excited. So, you know, that's one of the reasons I've stayed.
I've been there 25 years and you go, Joe, don't you get bored? Don't you want something more challenging? Every time I even start to get like that, the company does something like Lumen and you're like, oh, I'm gonna hang around for this. Let's see where we can go. Well, what is the most exciting thing that you think is like right around the corner for 2021?
That's a good one. You know, I think where we're heading is probably providing, like I said, that edge compute, which is a little bit different. They're shooting for 5-millisecond response time, which is more akin to what you get in a traditional data center for cloud access. So imagine you had AWS 5 milliseconds away from, you know, your people versus, you know, 40, 50, 70 milliseconds away. I mean, the cloud certainly is becoming more ubiquitous and does have good response time, but there's some sorts of types of applications that, you know, they need that, like, you know, kind of feel like it's in my data center type responses, and I think they have a good play there.
They're not the only ones, you know, it's kind of, you know, others, you know, Akamai, others like that, they've been trying to move content closer to you. This is moving even the application goes to you, not just the content. And so what's your role in that as a network architect? Well, you know, it's a couple-fold. My position tends to focus more on enterprise, right, the enterprise itself, but we have counterparts and I do collaborate with them on product infrastructure, right, and that sort of thing as far as, you know, they're building, they're doing all that sort of thing, and, you know, we kind of, you know, look over the cube and say, hey, what are you guys working on?
And that looks neat. And, you know, we— I think we do a good sanity check of making sure we're not going to shoot ourselves in the foot with whether it's privacy, compliance, regulatory, or just best practices for security. Yeah, well, and, and I have to give you a little bit of a hard time because I remember when you got your smartphone. Ah, so for a long, long time you had the flip phone, and so now you you upgraded to the smartphone. And so how does this new technology, you know, work with where we see 2021 going?
Well, you know, I don't know that I have a strong answer for that, but to your point, I'm a late adopter in my personal life on technology. I just like to squeeze the nickel, right? I was the one— I was the last one to get rid of those brick cell phones that we had back in the day. And, you know, I thought it was cool to have a flip phone. But yeah, and I almost bought another flip phone.
You know that, right? But no, I gave in. I gave in and joined modern technologists, if you will, in society. And I'm enjoying my smartphone. I'm very careful about my privacy on it because I know some good privacy people.
And yeah, and I limit what I do on it. But it is a great, flexible, convenient device. You know, one thing I'd maybe comment on a little bit is I call ourselves maybe moving to the cloud sometimes a cell phone culture. And what I mean by that, Bill, back in the day, again, this kind of telco reference, right? There used to be pin-drop commercials saying our calls were crystal clear, you're never gonna get a dropped call, was all about call quality.
And, you know, let's just face it, society and all of us have kind of just said, said, yeah, you know, if I get a little static because, you know, they're going under through a tunnel or something, as long as I can get the gist of it, it's all good. Drop calls, they'll call right back or they'll send me a text. You know, it's that kind of that mentality. We're okay with that where if the telcos had done that years ago, I want to be compensated for that, right? Yeah, no, absolutely.
And, you know, can you hear me now? I think I have more of those conversations right now than I did, you know, a couple years ago. I'm always whacking Can you hear me now? Yeah. So when I say a culture, it's kind of like, you know, we've had some recent— I'll just say authentication outages with major cloud providers where a lot of us who, you know, count on their authentication, none of us were able to get into our normal data centers or anything else because we were reliant on the cloud.
Right. And I kind of draw a parallel going Well, I want to ask the community, ask themselves, are we okay with that? When the cloud's down, I mean, it's outside our control. So the boss looks at you and you go, well, the cloud's down, I can't fix it, right? That sort of thing.
But the entire company's down, right? Your board can't get on, your operations people can't get on. That's like, now it's infrequent and I'm sure it's going to get better over time, right? But it's one of those things where I kind of tell people, it's like, you know, this is great, it's flexible. I'm pro-cloud.
Don't read anything else into that. But with that, we get some things like we're okay with dropped calls, we're okay if we can't get to our stuff at certain points, or maybe for 4 hours or whatever. It sounds like we're more accepting of that because of the other cost savings and flexibility that the cloud allows for us. So, you know, I kind of just put some caution. I always tell folks, I go, don't do what everyone else is doing with the cloud.
I go, make your journey to the cloud unique and fit your business. Because if you're doing what the other guy's doing, you're probably doing it wrong because your business isn't his— that business, you know, that sort of thing. Yeah, no, I think that's great advice. And I do think that we have seen some major outages recently, and, you know, and over the last couple of years there's been, you know, ones that you can kind of put a marker in of data centers that have gone down or regions that have gone down. So do you think that part of what Lumen is looking at is going to help prevent any of that or help solve some of that problem?
I sure hope so, because, you know, right before the name change, there was a pretty good-sized outage, and I think it was attributed to CenturyLink at the time, or at least some component of it. So yeah, I mean, we're always going to experience them, but, you know, it's kind of that loss of control a little bit. You know, and when everything was in our data centers, we had control of it, and, you know, there was fewer remote workers. Oh my gosh, right, with COVID and everything else, I go, work at home was kind of, you know, I want to say, you know, 20% of the workforce, and I'm just making that number up. I don't have a reference, but, you know, now it's 100% of the workforce, nearly.
So those sort of things matter more, right? So that's very interesting. So redundancy, you know, what other techniques or things can we do to reduce the possibility of having those outages? Yeah, I think you touched on it. You know, if you can have multiple service providers, the service providers themselves, you know, like I said, that edge, right?
So instead of coming and connecting back to your corporate infrastructure, you might in the future have have, you know, 9 or a dozen different edge, you know, termination spots that your company's contracted with, and you hop onto the closest one, right? And that could be regionally in North America, or it could be global, right? So, you know, whether you're traveling or you have workforce internationally, you know, they don't have to go across the pond to get back to corporate and get their resources. Well, kind of on that, is there any new technologies that you're excited that you're working with right now that you want to talk about? Cutting edge?
Yeah, well, I don't know if any of it's cutting edge because a lot of it's not implemented well, but yeah, I am reading and researching a bit more, you know, and everything because, you know, I'm involved with the CSA, it's kind of got a cloud slant, but micro-segmentation is certainly one of them, and, you know, I see that as really maturing technology, and it looks like from a compliance and regulatory and cloud, there's some neat applications for it. So, you know, folks haven't taken a look at that. The other one is zero trust. That's probably the big marketing thing everyone's calling you about going, hey, your VPN's old, you need to do this new zero trust thing. And, you know, I just— again, we're probably a little bit in the hype cycle.
And what I tell people is— it was funny because some of our own people go, where do we buy zero trust and how can we, you know, resell it? Exactly. What product do I buy? Right. And I kind of had to say, well, zero trust is a strategy, and I use it— I have a slightly different definition of it.
I like to call it a collection of architectures that moves us, moves the needle towards zero trust as that strategy, right? Zero trust kind of being that buzzword. But I think a lot of what we've been doing all the years, whether it's for, you know, identity management or our network security, all that has been kind of moving in this direction. And I think zero trust comes together and brings it all together And, you know, NIST has just, you know, come out with their standards for it, so that's a good place to start if you haven't read about it a little bit. It's, it's one of those things where, again, you needed to make it your own journey.
It's very difficult to achieve letter of the definition, so what I tell people is to say when you do a project, look at it through a zero trust lens, and whatever you're doing, whether it's remote access or you're just, you know, deploying into the cloud, or consider the principles that are in zero trust and see if you're hitting some of those checkboxes, right, that sort of thing, because that's where we need to go. It's not going to be easy to get there. Will we get there 100%? It's a tough one because zero trust says you have to monitor every network flow, you have to know where everything is. Oh boy, come on, we all struggle with just our own inventory of systems and applications in larger organizations, so there's a lot of work here to do, and the message hasn't changed.
I think it's just a more holistic Yeah, and it sounds like it's an incremental approach, right? It's not like a giant lift and shift. It's just continuing to make those incremental improvements where you can. Agreed. Yeah.
Yeah. Well, our time is almost up. I think— do you have anything to follow up with? Or I would love to know what your suggestions are for what you think people should do, because I know you do a lot of give back to the community. And so how can people give back?
And then how do we get more security folks like you who are doing the hard work every day, day in and day out, into security? Well, I think we kind of touched on it early in our dialogue today. So, you know, I encourage people to take whatever you're doing today, whatever your job function is today, you know, start reading on security, start listening to Colorado Equals Security, get involved in some of the meetups and groups like that, and kind of learn. It's going to take some time and input on your own time because that's not your title or job today. And I always encourage folks to just whatever you're doing, try to put your time in and do it well, right?
Because like I said, I use that system admin. If you do that well, people recognize that and all of a sudden you become the go-to person for that. And then when this other, you know, we'll just say zero trust security project comes on, they're going to say go grab so-and-so because he's really good at this aspect and we're going to need that component, you know, that sort of thing. Always encourage people to stay curious and keep learning. It doesn't have to be technical, right?
We got GCR, compliance, regulatory, your favorite, privacy, privacy, that sort of thing. Volunteer, right? One comment I make is I've presented, like many who listen, to RMIC, you know, conferences and that sort of stuff, but the same thing I've set up tables at SnowFrock and been totally happy with it. Right? I mean, I mean, don't— I mean, and it's kind of fun because you get really senior people and then you'll get someone who goes, I'm just getting started.
I heard about SnowFrock. I couldn't afford it, so I volunteered and it's great. And you make a connection and next thing you know, you're collaborating with someone.
I tell people to have the service-minded, right? Kind of my approach to being a leader is to serve. Right? The best way you can be a leader in my mind is to serve people, even if you have a title, even if you don't have a title, that sort of thing. Keep a collaborative mindset and obviously good old things like, you know, a good work ethic, hard work, and keep your integrity up.
Yeah, no, I couldn't have said it better myself. And I do think that volunteering, you know, for setting up tables and chairs, like there is, you know, a lot of the associations and even, you know, Colorado Equal Security is volunteer and nonprofit. And so every little pitching in helps. So, well, Joe, thank you so much. It's been a pleasure to get to know you a little bit better, to have a few laughs.
So I wish you well and thanks again. You bet. Anytime. It was a pleasure being here. Alrighty.
Thanks everybody. Take care. Bye-bye. Bye.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.