Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 187 for the week of September— or excuse me, it's not September, is it? It's November 16th.
Alex, do you know what month it is? I do not, Robb. All time and space has seemed to blend together, so it could be September and the year could be 2031 for all I know. Well, this is a different kind of podcast than I expected at the beginning. Sounds like we're getting pretty deep.
I don't know if you are aware, but we did just pass the date, speaking of time travel, where the lightning strikes the clock tower in Back to the Future. Propelling Marty back into the future. So does that mean we're in the future or are we in the past? A little bit of A, a little bit of B. It was November 12th, 1950.
I don't remember the year though. '52? '55? Something like that. Yeah.
Anyway, important stuff that, you know, the hard-hitting news we bring to you on this podcast. That's right. It is amazing as we get older, all these movies that happened in the future and things like that. All of a sudden, they're not so future anymore. And we have no flying cars, no time machines.
We still don't have our hover, our flying cars or our hover skateboards that we can use to get around town. Robb, get off my lawn. I am not on your lawn. All right, let's move. What kind of housekeeping do we have to go through, Alex?
You know, Robb, we have a Slack channel. It's a very active Slack channel as well. We've got, I Way, way too many people. It's— there's so much conversation in there that I can hardly keep up with it anymore. They're stepping all over your lawn, right?
That's right. Get off my lawn. I remember when I was the first one in the Slack workspace.
Anyway, great conversations in there. If you would like to come speak with everyone in there, go to the website colorado-security.com and click the Slack link and you can join as well. And while you're there, we'd love it if you'd sign up for our mailing list. This is a place where you can get the show notes delivered into your inbox each week and just about nothing else. I think sent out a total of one other type of email ever to that mailing list.
That is true. We'd love it if you'd join that and basically make sure you know all of the news that's fit for us to talk about on the radio. Next, we'd also love it if you would rate us and subscribe on your favorite podcatcher. Let folks know that we exist and maybe we'll find some new great listeners. Also, tell a friend.
We love friends and we love friends of friends, so bring them let them know about Colorado Equal Security and, uh, get them involved. Yeah, don't bring your creepy friends either. Bring your good friends. We, we don't want that person who you're kind of like on the fence about. Bring— go find the best, the high-quality A+ friends.
Okay, fair. Uh, uh, a couple more things here. We'd love it if you could support us financially. We do have a Patreon campaign. This is a place where you can, uh, help defray the cost of the show, and, and of course all of that goes right back into the community.
We don't keep any of that for our own, uh, our own pockets. And finally, if you're interested in getting involved with the show on the air, we could use help with doing interviews. You know, this is one of our favorite parts of the show is getting to know someone in the community better. But we sometimes run out of time with our full-time jobs. And we'd love it if one of you guys listening signs up to be an interview for the show.
Love it. All right, let's jump into the news. Denver-based alcohol delivery startup Handoff has been acquired after 18 months after launch. That's pretty fast. So I, I know Drizzly, and I'll be honest, I did not know about Drizzly before the pandemic, but it's become, you know, quite a thing in the social conscious in the last 6 months or so.
I did not know we had our own here in Denver, and it sounds like it's a pretty cool service too. Yeah, it does sound interesting, and I think it's also interesting that they have now been acquired by the sort of merged company of Encompass Technologies and Orchestra Software. So that they can get even bigger. It sounds like those companies are going to give them access directly to some producers of alcoholic beverages, helping them get some new go-to-markets that are going to be unique, and they will not just be competing with other business models in that case. There was one interesting thing in the article that I noted here, that in March, as the pandemic hit, Handoff actually hid all of the non-local beers from their platform so that they could make sure people were getting pushed to to all the local cool stuff here in town.
Specifically, they call out breweries such as Great Divide Brewing, Ten Barrel Brewing, Epic Brewing, Odell Breweries, and others. And I just think it's really awesome that they're— I don't know that they actually got rid of them altogether, but at least you weren't immediately finding those non-local ones and they were helping keep the money here in Colorado. Yeah, I thought that was pretty cool too. All right, next story we have is another company here. Actually, there's a trend here this week, Alex, a bunch of companies that I didn't know existed.
Doing some pretty cool stuff. So this next one is called DemoFlow, and it's another Denver-headquartered company. They have created a collaborative platform for virtual sales presentations. And my first thought was, they do what now? But they do go into some detail here.
You want to take a swat or you want me to? So basically they have a platform that integrates with some other sales tools, but also to help you do strangely enough, do demos. And when I first— I think similar to you, when I first heard this, I thought, why would you need a platform to do that? And then I thought, oh yeah, just about every time someone has tried to demo me a product, it has gone poorly. So maybe there is a need for a platform to do better demos.
Yeah, it is the most obvious thing that no one's ever done before. And but it's clear, right? Like I'd never— before they mentioned this company, I didn't think, hey, we need a platform specifically for helping companies do demos. But now I think we do. And I think anyone who doesn't use it's probably a sucker.
Um, so they do, they do go into some of the details on, um, basically making recordings easier, making it easier to show multiple windows, making it easier to, um, to kind of go through all of your different product features. Um, really cool stuff. And, uh, they did have a few details in here in terms of finances. So the reason this actually came up is because they just announced that they raised a seed round of $1.6 million. They currently have 3 full-time employees, and their CEO says that by the end of this year, they're going to have it up to 10, which it seems pretty aggressive.
We only have like 6 weeks left, so they better start just randomly sending out job offers at this point. Just show up to their door and ask for a job. Yeah, and it's the obvious stuff like that that tends to make good products too, right? And things like they have a built-in browser where you can have multiple windows in their platform so that you can show different roles and other things like that. Again, something that seems pretty easy but doesn't always come across very well when people are doing demos.
One of the other things, I think if you get a demo from people at a company and you go to a different sales team, you're probably going to get a different demo and not have them hit on the same things that the other team did. So having a platform where you can sort of standardize the messaging and other things like that, I think is helpful as well. And we'll say completing or continuing on our theme of companies I'd never heard of that are pretty awesome, let's talk about Josh.ai. So this This is another Denver-headquartered company, but they do home automation. They really are competing against your Alexas and your Google Homes, but they have their own little niche.
Yeah. They are aimed at a more high-end market. They're also trying to be less obtrusive. They have these small little sensors with microphones that you can put lots of places and hopefully will stay out of sight. You know, won't be, you know, sticking out like a sore thumb if you, you know, place your, you know, smart speaker somewhere in your room.
And then they also have a centralized, I guess you can call it a server, that where all the sort of brains live, where it processes the audio information and then can hand off to other things to make your home automation tasks work. I think one of the other cool things about them is that they are very privacy-focused. They're trying to do as much stuff on that local device as opposed to sending everything to the cloud. Yeah, I thought that was pretty awesome. Reading through it, you know, the difference between an Echo Dot or whatever, or even the big one, I can't remember what it's called, but like the Video Echo, which is a pretty good-sized thing sitting on your table.
They're trying to go the exact opposite way where they've— they have their home control device that you're going to talk to, which is 0.1 inch thick by 1.6 in diameter, and it's meant to just sit and blend in on the wall so you don't even notice the thing. Pretty cool difference in terms of how it's— how your home is supposed to showcase these things. So the article itself that we saw said that they raised $11 million in seed funding, and the company has about 30 employees now, most of them here in Denver. Then I found another article out there. I was like, well, how much does this stuff cost?
And I found one that showed the average price to install one of their systems is about $500 per person. And the reason it was hard to find this is because you can't just go buy it from their website. You have to actually You have to go to a professional installer who will then be like the reseller for you. So just a totally different model than, you know, clicking Buy Now on Amazon. Yeah, that— I mean, not that $500 a person is cheap, but that doesn't seem awful if it is a truly great home automation solution.
So, well, my guess is you're not doing a one-room solution. That's probably not an option. You're probably 4 or 5-room solutions to get started. I'm just, just a hunch there. Oh, you know, one, if, uh, you know, if you want to, Robb, just go ahead and get your home all set up and then let us know how it goes.
All right, it sounds like if the Patreons come in, we can use this as an excuse. No, I'm just kidding. Of course, that would be an inappropriate use of Patreon money. All right, uh, let's, let's move on. Um, did you know, Robb, that there are 3 cities in Colorado that are top tech towns in the US for 2020?
No, I didn't read anything for this week, so I had no idea. Um, so, um, I'm gonna let you guess at the 3 surprising Denver towns that are top tech towns. Well, now, before we get into— before we do the big reveal, I'll say that this, uh, this award, this, you know, ranking was given by CompTIA, you know, the, the IT certification company. And they were really looking at, um, a number of things, mostly jobs. There was a cost of living, number of jobs posted for IT positions, and projected growth over the next year and over the next 5 years.
With all that said, Denver did make number 10, Boulder made number 12, and Colorado Springs came in at number 15. Yeah, you know, one of the things that I thought was interesting, um, speaking of CompTIA, um, they list CompTIA as the trade association for the IT industry, um, which is not how I would describe CompTIA, but maybe it is more than I realize. Um, so yeah, uh, I think one of the drawbacks of the story is that, uh, our nemesis Austin is at number 1. Um, but, you know, having, uh, the, the 3 largest cities in Colorado all in the top 20 is pretty cool. Yeah.
The other interesting thing on this list, um, that— so they showed last year's ranking and Denver was number 9 last year, number 10 this year. You know who passed us, who went from number 10 to number 9, is Huntsville, Alabama. So we are now behind Huntsville, Huntsville, Alabama. That, that's not what I expected to say. Yeah, I wouldn't have guessed that either.
I mean, there's a couple other ones on here that, that were interesting as well. You know, they've got Charlotte, which I guess, you know, is a decent tech hub, but Madison, Wisconsin, though, that one that I put at 5. Yeah, Madison, Wisconsin at 18. Trenton, New Jersey at 20. Yeah, a couple surprises.
Baltimore. Well, I guess Baltimore is close to DC. That, that should count. Yeah. All right.
Uh, an interesting list. Of course, it's good to see us represented on the list, you know, taking up, uh, 3 of the 20 slots. Good stuff. Uh, next, a, uh, not so happy story. Um, Vertafore announced, uh, that a human error led to a data breach that impacted 27.7 million people.
So Vertafore is a local software company. Uh, they mostly play— I think they exclusively play in the insurance industry, and it looks like some kind of database of driver's licenses for Texas, which is used as a part of like their insurance rating system, got compromised and somebody exfiltrated the data. They did a bunch of analysis. They don't see any indications that the data has been misused, but, you know, once it's out there, that's the thing you have to notify on, and they are, of course, providing credit monitoring and doing all the, you know, security improvements that go along with this. Yeah, you know, going back to the human error part, this seems like it was a, you know, sort of a permissions problem or something like that.
You know, someone probably made something publicly available that was not supposed to be publicly available, which, you know, sadly happens more often than we would like today. It sure does. Anyway, sorry. We of course know some folks over there at Vertafore and wish well for them going through this. It's no fun to have to go through this kind of incident process.
No, it is not. All right, moving over to our next story. Uh, we have an old friend who's showing up in a new place. Um, so Graylog has appointed Andy Grolnick as the CEO there, and Andy was for about 10 years, he was the CEO of LogRhythm. Yeah, uh, pretty cool, and congrats to Andy.
Um, you know, he left LogRhythm, I don't know what, 2, 3 years ago, something like that. Has it been that long? Um, 2 years maybe. And, uh, we of course, uh, had him on the podcast. Uh, what should have checked this first.
I don't remember the episode number, but he has been on before. Um, and, uh, so exciting for him to, uh, to get back into that CEO role, um, at a company that, you know, he should be familiar with the industry because Graylog is, uh, at least somewhat similar to LogRhythm. Yeah, it's pretty cool stuff. Looking forward to— hopefully we can get another interview with Andy sometime soon and, and learn all the good stuff about Graylog. Yeah, I think the interesting thing too is, um, GreatLog is not based here in Colorado, but I did hear a rumor that they do have a bunch of people here, so maybe they'll have more in Colorado now that the CEO is here.
Good stuff. All right, our next story is around JumpCloud. So JumpCloud, I do think we've talked about them once or twice on the show. They are an identity access management company. I think they're mostly focused on cloud directory, so it's not just any old identity access management, it's the directory side of things.
They have raised another $75 million. That's the announcement here, and they're planning to hire— get this— they're going to go from the current staff of 300 to 500, or excuse me, 500 more to 800, uh, with this new $75 million raise. Yeah, I thought that was funny. In the article, they just sort of casually said that. It was, uh, you know, uh, you know, we're gonna hire some people and, you know, make an additional 500 hires over the next several years.
Whoa, that's a big number. Yeah, that sure is. Uh, they, they are mostly— that two-thirds of the folks are in Colorado right now. And the focus is going to be on building out the JumpCloud team and a lot of new product development. Of course, everyone wants to hire sales and marketing.
I'm sure they'll have a number of different things, but excited for them. And it sounds like from the article that while for every company during the beginning of COVID the Q2 results were not great, but Q3 was a record-setting number for them. And it looks like they're really tearing it up through the COVID world. Yeah, pretty cool. I also noted that, you know, they had recently opened a new headquarters called JumpCloudia just prior to the pandemic.
And because of that, you know, while they still will hire probably a lot of people in Colorado, they are doing a more remote workforce-focused strategy going forward. So they may be hiring people other places as well. Bummer. Well, keep it, keep it in town here, guys. Yep.
All right, uh, next, uh, we had a blog post this week from Ping talking about, uh, securing cloud access and DevOps with Ping and Centrify. So Centrify, of course, is a PAM solution, privileged access management solution, and this is talking about how Ping and Centrify can integrate with each other to, uh, to make DevOps more secure. Yeah, good stuff. Um, it, it really sounds like they have partnered on, on, you know, with Centrify providing the privileged access management part. So, you know, if you have those, those highly sensitive credentials that you don't want people to have access to, they'll handle that part, and then Ping will handle their single sign-on, your directory, your MFA aspects of it.
Good partnership, and especially when you're trying to build an automation, you really need tools that, that work through APIs and seamlessly. Yep, pretty cool. All right, next we have an article from Zwelo around fighting ransomware with defense in depth. And basically, you know, my guess is that they've recognized that ransomware is a big topic recently, and they said, well, let's put out a blog post for folks who are looking for how to defend against ransomware. Yeah, and so I think defense in depth is something that everyone probably knows about.
If not, you probably should know about. And, you know, they talked through defense in depth and what that looks like, and, you know, how threat intelligence and, and what they provide can help with that. You know, in the case of ransomware specifically, you know, when there are command and control or malicious domains that are associated with ransomware— the example they're using is Emotet— you can use that threat intelligence to help with your defense in depth so that you can make sure to block those things. Good stuff. So if you're, if you're looking for, uh, kind of what should I do about ransomware, it's probably worth reading this and, and kind of figure out what assumptions they're built on.
All right, and our last article for the week, um, this is from Coalfire, um, talking about, uh, cloud tech and in this case first floor recommendations. So, so sort of first things that you should, uh, you should always do. Yeah, it took me a little bit of time to figure out what he meant by his first floor recommendations. Uh, he, he's talking in the article about how he was gonna throw himself out the window if he had to make these recommendations one more time, kind of back in previous lives of security. And these are the things that you should be doing at the beginning for cloud security.
And I really appreciate the fact that he goes into a relatively technical perspective on how to get AWS to be secured appropriately, not just starting with like, you know, privilege to act, or excuse me, least privilege, he actually goes into some real technical AWS answers. Yeah, and, uh, there's about 8, uh, things on the cheat sheet here, uh, so if you're interested in those, check them out. Uh, definitely good recommendations there. All right, uh, that's it for news, right? I think that was our last one.
That is it for news. So we can jump over to Slack Message of the Week. Big thanks to Andre Gaeta. Andre has been, as everyone knows, the sponsor of Slack Message of the Week for, for a couple years now. Uh, we appreciate it, and as a result, one One person who makes a witty, insightful, or otherwise engaging comment on Slack will get one item from the Colorado Equal Security store that they can use to, to get whatever swag they want to wear.
Wow, Robb, you said that like we actually have a standard for this. I just make it up as we go. Uh, all right, so this week our winner is Richard Johnson. Congratulations, Richard. Uh, he posted a link to, uh, an exploding whale.
Robb, you want to talk a little more about that? Yeah. You know, I'm looking through the Slack message or Slack channel kind of every week looking for what's, what's interesting. And, and this article, just like in the middle of random, is about a, a whale, um, was, uh, beached— well, he passed away and was on a beach in Oregon. And the, uh, the authorities there, um, decided that they, that they didn't know how to get rid of this thing and they were going to use explosives to make it smaller and easier to move.
Um, and apparently this happened back in the like in 1990 or something, and they blew up a whale. And it was a horrible, horrible decision that ended up with lots of property damage because whales apparently, when they explode, go a really long way. And it became this— it was assumed to be a myth, to be an urban legend, but it's actually true. And this article goes into the facts behind it. And holy smokes, it's worth the 5 minutes to read this because it's so unbelievable.
And I appreciate Richard sharing that link that maybe no one else read through the whole article, but I did, and it was kind of crazy. I— the moral of the story here is don't blow up whales. I think that that's a pretty good life lesson. Yeah, I agree with that. All right, all right.
We, we also have an event calendar on our website. Um, you know, you can go out and see what's coming up here. End of the year, things get a little bit dicey. Make sure you check to make sure your, your regularly recurring meetings are happening. Um, we have a couple of groups on here that I think post recurring meetings, and maybe they're not thinking about the fact that Thanksgiving and Christmas are happening and those might get changed at the last minute.
With that said, this, this coming week there's a few big things. This whole week is the Peak Cyber Symposium down in the Springs, of course virtually. You get to do a week's worth of education around security and I think it's all free. On the 17th, CSA is doing their November virtual meeting. On the 18th, ISC² at Pikes Peak is doing their November chapter meeting.
Also on the 18th, the Splunk meetup is, uh, presenting Not Your Grandma's Ransomware: The Evolution of Crimeware and the Current Risks. I think this is Doug Brush prevent— uh, presenting that. On the 19th, ISSA Colorado Springs is doing their November online meeting. Also, ISACA Denver is doing their November chapter meeting on the 19th. And the last event for this month is on the 27th.
That's the day after Thanksgiving, it's scheduled. Uh, DC303 is doing their virtual online meeting. So Hopefully everyone's showing up with some leftover mashed potatoes and turkey, but maybe not. Make sure you check in with your folks. Good stuff.
All right, let's move over to jobs. Robb, any Ping Identity jobs this week? I got 3 security jobs at Ping. No changes in the last week or so. Hopefully we'll have some changes in the next week or two though.
We're looking to hire a product security engineer focused on our SaaS environment. So if you're someone who's got a back background in development and wants to get involved in a security company, this is a place to do it. We're also hiring a FedRAMP program manager. Love to have you talk to us about that if you're interested and have some FedRAMP experience. And finally, we're looking for a manager of GRC.
This is the person who will run the programs for our GRC side around compliance, you know, SOC 2, ISO, do our policies and standards, vendor risk management, all that good GRC stuff. Once again, you can apply on the website, reach out to me on Slack if you have any questions, and I'm happy to give some background. Awesome. LogRhythm is looking for a Deputy CISO for the Americas. Get to work with our friend James Carder over there.
I'm sure that'd be a fun job. Bank of America is hiring a detect— or excuse me, a Network Detection and Response Analyst. Base 2 Solutions is looking for a Cybersecurity Systems Engineer Level 4. Honeywell is hiring a Senior Cybersecurity Analyst. Western Union is looking for a Leader of Cybersecurity Encryption.
Affirm is hiring a senior director of internal controls. And Optiv is looking for a senior manager of cybersecurity. This is a customer-facing role at Optiv, but it sounds like a fun one. And anyone who's looking to maybe get out of doing the internal security, this might be a good opportunity for you to do that at a well-respected local Colorado company. Cool, good stuff.
All right, well, that is it for the news. We do have an interview this week though. Once again, thanks to one of our fantastic guest interviewers. Alex, who did this guest interview for us? I believe it was Excuse me, Janelle Hsia that did this.
Janelle has been awesome. Thank you very much for doing that, Janelle. Lucia is, I think she's now called the global resident CISO for Proofpoint. Previous to that, she was CISO at Polycom and a friend of mine and a friend of yours, Alex. Looking forward to hearing what she's up to these days, and hopefully everyone can learn a little bit about, about her own background and how others can emulate her success.
Good stuff. Looking forward to it. All right, everyone have a great day. Thanks, Robb. This is Artie Wilkowsky.
CISO at Dish Network. Welcome to Colorado Equal Security, the podcast for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equal Security. This is Janelle, and I'm super excited today to conduct an interview with Lucia Milica Stacy. So we met a couple years ago at the IAPP conference in DC, and then I think in June we ran into each other again at Armist.
And I've seen you speak at a couple conferences, so I was super excited that you've agreed to do this interview today. So how are you doing? I'm doing well. Thank you for having me and happy Friday. Yeah, happy Friday.
Exactly. So we were— before we started to turn on the recording, we were just talking about you have gone back to school. So, and your master's degree. So let's actually start with that because that's cool. So I think you and I had a chance to know each other a little bit, and I'm a professional student.
I love to learn. After, you know, around the time you and I met, I think it was shortly after I finished my law school, I got my JD, and I was very much adamant about I'm done with school, no more degrees, I'm good. But sure enough, a couple of years later, I got the bug again. So I am back in school. I don't know what I was thinking.
This time is really the last degree I'm gonna go after. I'm already 3 out of 5 semesters in, so I'm a little more than halfway through. I'm going for a master's in information and cybersecurity through University of California, Berkeley. Yeah, I think that is so awesome. And I, I kind of agree with you.
Like, I've been toying with the idea of going back to get my master's, but I think my husband would actually kill me. So he's like, not yet, just wait. So no, I'm super excited for you. And I think Berkeley's great. And I think they have a lot of, you know, I— and so again, I want to talk to you about, you know, you're also, in addition to cybersecurity, you also, you mentioned a lawyer, but then you also do privacy.
Um, and I know Berkeley has a lot of privacy lawyer or professors that teach there too. So I don't know, are they integrating any of that into their master's program? Absolutely. Actually, one thing I, I absolutely love about the program, and, and it's definitely probably in many ways It seems like it's even harder than my law school, and I thought that was the hardest school I've ever had to go through. But absolutely, they— I think they're doing a fantastic job between diving in super deep into technology.
So you still have to be able to code. You have to be able to dive in into discrete math. That was my favorite, around cryptography and cryptography algorithms. But they're also bringing in a lot of the legal aspects of cybersecurity. So we're, you know, sort of kicked off the semester with, you know, extremely difficult class in cryptography, just primarily because of all the math, discrete math algorithms, but also looking at beyond the code, right?
What are the various different laws surrounding security and privacy? And, you know, this semester, for example, I'm taking a couple of electives. One of them is in national security and the 5th domain, which is very fitting, you know, given the times and being that this is an election year, but really diving into both the cybersecurity challenges and the legal challenges, you know, across national security and what is cyber warfare, how do we look at that, how do we look at cyber attacks. So, so far I absolutely love it. My next semester I'm fully planning on taking all privacy, usable privacy actually, how to implement that in practice to see if I learn any new tricks, haven't had to build privacy programs in my previous role.
It's, it's always interesting how things change so fast. I feel like privacy today is where cybersecurity was about 10 years ago in terms of everybody starting to pay attention to it, but we're yet to form mature processes. We're yet to truly get the full attention. People are starting to figure out that it matters, but I don't think we're quite where we need to be. So there's still a moment year journey, but really, really excited about the program.
I'm glad I took it. I didn't realize the time commitment in addition to working from home, my full-time job currently as a global resident CISO, and having my kiddo virtual schooled. Right. All of those at the same time. Right.
That is a lot. And I think, so, but kind of going back to what you were talking about, so you've got, there's a lot of privacy in that. And do you want to talk a little bit about Shrem's 2, you know, like, I think that for me that the security components of the Schrems 2— and so for the people who don't know, so with GDPR there's an adequacy required for data to come from Europe to the United States. Like, we don't care where we send our data, but Europeans don't want— they care where they send it. And so we lost our adequacy with Privacy Shield because of Schrems 2.
And we keep talking about all of these ways that, you know, like, what can we do to protect the data? And cryptography, like encrypting the data, is one of the things everybody's talking about. So is that being— is that part of the class? And because I think to me that's huge. Yeah, we haven't actually dove into it.
So I haven't jumped into the specifics around the privacy. But, but I agree with you. And to me, Schrems II should have been no surprise to most privacy professionals. We knew the Privacy Shield was sort of, in my personal opinion, almost a patch to the US Safe Harbor invalidation, sort of taking that easier way out. We do need some, you know, a systematic program from companies to be able to, you know, to do business with Europe and have those safeguards in place and assurances for the European citizens that we are actually safeguarding the data adequately.
But Privacy Shield was, in my opinion, just Safe Harbor 2.0 without the robustness. And a far more effective way is using the standard contractual clauses. I know that might be a little too geeky for some of you listening into this. But, you know, model clauses, standard contractual clauses have always been the golden standard. And that was my approach in my last role when USAF Harbor was invalidated.
It made no sense for the patchwork. We said, let's just go straight for— I mean, you at that time, you had the option between business corporate rule or standard contractual clauses. And we agreed with our outside counsel and internal counsel that standard contractual clauses was the gold standard and the way to go. And sure enough, after Schrems II, and, you know, fast forward a few years later, we're still back to standard contractual clauses, right? And, you know, had most companies taken that approach to begin with, they'll probably have been in a slightly better position.
But at the same token, I fully understand and appreciate that business priorities, you know, take precedence. Oftentimes we, you know, the Safe Harbor invalidation like GDPR for many seemed like it was coming out of nowhere, right? Even though for those of us that have been staying in touch with privacy, we've seen that writing on the wall for years. I mean, just GDPR in itself was being drafted years before it actually was enacted and you still had multiple years to comply, right? So So, it was not out of nowhere, but it did take a lot of folks by surprise.
And when you're trying to juggle business objectives, business priorities, budgets, et cetera, I see and appreciate the fact that we have to cut corners and figure out what's the minimum that we have to do to not get in trouble. But sometimes that rework ends up costing companies a lot more time and money, having to go back to the drawing board years later because of that patchwork approach. Yeah, and I think that that's, you know, going back to help with risk mitigation, like looking forward, you know, kind of seeing the landscape. And I think, so going back to the fact that you're one of the few people that I know that both have a law degree and are in cybersecurity and then do privacy on top of that, right? And so do you feel like you have the ability to kind of do that, like looking ahead sort of thing?
I mean, companies don't necessarily listen to us, but like, you know, talk about how your law degree influenced your technical decisions. Oh, absolutely. I think that— so first and foremost, even outside of just diving into the content of law, the process of going through law school, and I know some folks don't necessarily appreciate it unless— until you get through it, but that process has really, really sharpened and honed in critical thinking skills, that ability to really focus on those specific details, to find that needle in the haystack, to build your case, Right? It's, to me, it's so similar, analogous to security in terms of, you know, threat hunting, finding vulnerabilities, figure out, you know, where the bodies are buried in an organization, etc. They absolutely complement each other in so many different ways.
And I know you and I talked about that, you know, my dream was always to be a prosecutor. I didn't know when I was a kid that you know, prosecutor, what prosecutor meant. All I knew is I wanted to put away the bad guys and I wanted to do the right thing. I wanted to be impactful. And to me, now looking back, it's no surprise that my passion for, you know, for right or wrong and law had translated into the field that I am today, which is cybersecurity and privacy, because I absolutely think they go hand in hand.
Also, I The other part too, there are not many CISOs that are also Chief Privacy Officer. And I think I want to address that because it's not the norm. And in many ways, being a privacy and security, although there are lots of overlaps that are complementary, there's also a conflict of interest in holding both of those roles. And Hugh and I both know this, and I know we talked about it extensively when we were in DC at IPP. You know, it's the same as a CISO reporting into the CIO.
It's that similar concept of conflict of interest, right? If you have someone overseeing and making decisions for your security decision or deprioritizing your budgets or, you know, projects that ultimately is going to impact your risk posture, etc., it's very much the same when it comes to privacy and security. They are separate areas. Yes, there are overlaps. There should be partnership.
The only reason that I was able to hold both roles is because both of my legal and technical background, I was the person that could understand both sides of the fence. And to ensure that there was no conflict, we created an Information Security and Privacy Review Board as an overall organizational board where eStaff members were part of it, and they had designated VPs. There were their spokesfolks, and we had— I had to report to them quarterly, of course report to the audit committee, etc., on both matters. But having that oversight where I could be vetoed by anybody else in that board was key to making sure that there was no conflict between the one person holding both roles. And I had separate teams.
I had a separate team dedicated to privacy. I had multiple teams dedicated to security. But because of that, because of the that oversight, we're able to make sure that we address any perception of conflict. And so what are some of the areas that you think— like, I do think that a lot of people are trying to marry them together. And, you know, and especially because this was at Polycom where you held both roles.
And how big was Polycom? Because I think they were like— so they're close to a $2 billion company. So about 3,500 to 4,000 employees, roughly. Yeah. And so, yeah, like you said, you had lots of team, you know, you had 2 different teams and lots of people to do that.
And I think in smaller companies where they don't, you know, that one person doesn't have all those extra people. So what would you recommend for the things that should be separate? Like what is definitely just privacy and what is definitely just security? So I would say where I'll start with where the 2 overlap. Okay.
Where the 2 overlap. And if you haven't seen it, NIST had actually put together a privacy framework, which I think it's a great guide. A little too complex and convoluted for the state of privacy where we are today, my own personal opinion. And ISO has put one in place as well. But I think where they overlap, where they come together, is securing the data.
But that's pretty much it, right? Security has so many other aspects versus privacy is really goes to, you know, the privacy risk goes to the authority of processing data. That it's absolutely separate than anything to do with security. And if I'm to look at it, I mean, we all talk about, you know, CIA, the confidentiality, integrity, availability. If I'm to, you know, translate privacy and security into those, I will say that, you know, privacy really goes to the confidentiality part of it, which is, you know, you not being able to read my message or not being able to read my information versus security.
And granted, you know, security Integrity covers all of them, but just to kind of bring it into terms that we're all familiar with, integrity really goes to has the data been altered in any way, shape, or form, and that's more security part of defense. So that's kind of how I tend to look at them, right? It's, you know, if you just look at strictly do you have the authority to process this data or see it or read it, etc., that is absolutely the legal part of it, right? Permissions and access. Yeah, so it sounds like what you're saying is like privacy has to like scope the data kind of from the personal data perspective.
So like for data classification, so I know that that historically came from security, but I've seen that the privacy people are kind of taking that on and helping classify the data. And if you can descope the data, so if you can take out personal data out of a system, then the security guys don't have to, or gals don't have to, you know, encrypt it and put it in their secure box. And so, you know, when we look at personal data, how does the privacy professional help security de-scope that?
So the way to do it is really going back to— and obviously there's so— you and I know there's so many different barriers variables and levers, right? So there's not one answer fits all, but the way you scope that is primarily by just looking what is the absolute data that you have to collect. So it goes back to building privacy and security by design in your processes. And fortunately or unfortunately, depending on where you are on your maturity scale or focusing on this, a lot of organizations maybe have not built that as part of their process. But reality is, is looking at, do you absolutely have to collect every one of those data points, right?
The more data you collect, the more responsibility you have, of course. And that's where security and privacy go and, you know, butt heads oftentimes, because from a security perspective, you want all the data, you want all that extensive logs, etc., to be able to do investigation, to be able to figure out, you know, the, you know, the trail that, you know, you need to, uh, to look at across the board in terms of monitoring, response, et cetera, versus on the privacy side of the house, you don't want to keep— it's only the data that you need in order to do the business. And that is the best way to really de-scope that for us, for security folks, by not collecting it to begin with. That's easier said than done. But as leaders, both from a cybersecurity or privacy perspective, I think it's It's our job to make sure that we educate our leadership in terms of, you know, really presenting the risk to collecting that data and really partnering with them and making sure they understand the ramification.
One of my biggest— one of my pet peeves and, you know, something that I'm very passionate about is we tend to go to leadership with every technical jargon possible, which tends to obviously makes a lot of executives and board education is something that I'm very passionate about and I've been working on for a long time. But oftentimes, we just, we don't know how to communicate adequately. We focus on the technicalities and we don't translate that into business risk. We don't translate that into language that our boards can fully understand and our executive teams in order to get that. Support that we need.
And obviously our jobs exist to protect the companies, right? We're there to enable the business to, you know, to protect against, you know, do so securely and protect against any regulatory compliance risks that come associated with, you know, the systems, the data that we collect. Well, and speaking of, you're on a couple of boards. Do you— can you talk about that? Sure.
Absolutely. So, um, I actually am on 4 boards at a time. Wow. Um, that's probably the max stretch that, you know, I've put myself into here. But, um, they all mean a lot to me, and they— I'm, I'm— I joined those boards for, for different reasons.
So the, the 2, 2 of them are local Colorado organizations. So I started out with New Cloud Networks. Um, they're a global cloud provider based in Denver. They really specialize in backup, DR, production clouds, hosted PBX, and security as a service. They have data centers both in the US and Europe.
And for this particular advisory board, you know, together with another fabulous CISO in the Colorado area, my advisory is really centered around helping new cloud networks and their CEOs Kumar in building an offering for security as a service, which so many small and mid organizations need help with. And to your point earlier, right, maybe, you know, those small to mid organizations don't necessarily have the expertise, they don't necessarily have the resources, and we need to have those, you know, security as a service offering. So that's, that's my involvement there, is really to help the broader community with with those services so we can raise security to the next level across the board. Another one which is near and dear to my heart is probably like my favorite technology and one that, you know, one organization that I'm most passionate about is Journey. They are a zero-knowledge technology company based out of Boulder, right in your neighborhood, Janelle.
Yeah. So they have the Journey Identity Platform platform that I created really aims to make it easy for enterprises to establish trusted interactions with their customers that simultaneously solves for security, customer experience, and privacy using an encrypted network and a platform for that best-in-class identity solution that can be dynamically applied using the enterprise's existing mobile apps. So you can So, imagine calling your bank for customer support. Your agent at the bank immediately sees who you are. They have your information.
They can immediately transmit, okay, is this you? You confirm with biometrics that it is you. So, they don't have to store your Social Security number. They don't have to store all this PII and sensitive PII in their systems. You hold that.
And it's you. And through their technology, you can, you can authorize access, or you can connect back with their agents. There's just one example, but I'm really, really excited about this technology and, and the possibility for what it holds in the future. Go ahead. I was gonna say, because I totally agree with you.
So next year, actually, I'm doing a series with ISSA on technology, privacy-enhancing technology, right? Because I totally agree with you. I don't think we can solve the privacy challenges with laws and regulations. I think technology— we have to have technology exactly like you described. So yeah, so after we're done, I want to know more about that because— and if we can, you know, we'll ask Alex or Robb to put out notices or information or whatever because I agree.
Like, and I think the other thing is that most privacy people don't know that there's technical solutions to these problems, right? They just think it's a privacy notice, and I'm all about the technical solutions. So you just like lit me on fire. That's so exciting. Yeah, no, that's great.
Happy to. So the next one, it's more of a newer, newer role that I've taken as a board of director for NextGen Cyber Talent. It's called— it's a nonprofit based out of Silicon Valley, and really the mission of the organization is to help identify and address that knowledge and personnel gap in cybersecurity skills, create strong, innovative, multidisciplinary next-generation professionals by helping people, really focusing on diversity, to learn those relevant cyber technologies and provide a, you know, provide this nonprofit platform for enterprises to hire this trained talent. So, giving, you know, this is my way of giving back. As we know that we all need additional talent, we need, you know, we need to close that skills gap that we talk about extensively in the industry.
And I'm really excited about what this organization has to offer. There are literally a number of CISOs in the Valley coming together to, let's work on this, let's figure it out, we all need more talent. And let's work together to make this happen. And we're in the early startup stage, but I'm really, really excited about, you know, the potential in the future. So just as a quick note, so where— I mean, like, where do you think that talent's gonna come from?
Like, I know that that's probably the million-dollar question, but like, any insight in that? So we're at— just to get started, we're looking at— we just started with taking a look at all the community college throughout. So we're only starting with the Bay Area first, but we're looking— we did an inventory on every single community college in the Bay Area and looking at what cyber classes they have, the interest in those cyber classes, et cetera, and trying to, as a first step, you know, partner with them to help deliver some of that specific content that we're trying to create. So we're not trying to reinvent the wheel, but we're really trying to enable people that have an interest, to take them through that journey. And of course, working in partnership with a lot of the tech companies in the Valley and getting funding for those so we can help pay for those folks to complete their program across the board.
And that's sort of the next stage. Obviously, over time, we wanna be able to attract folks that already have some technical knowledge. So whether there's— and we're doing multi-stage, but if you already have an engineering background or IT background, et cetera, and you wanna focus on security, then we'll have a set of cybersecurity content and classes to get you to start there. If you have no technical background whatsoever, then obviously we need to start with foundational technical skills before you move on to the cybersecurity skills. But as a first starting point, community colleges are our first partners.
I love that. Absolutely love that. And then what's your fourth one? My fourth one is the SC Media Advisory Board. That's a women in IT security advisory board that really focuses on supporting the editorial team through interviews, commentaries, insights into the cybersecurity industry, but really as a way to truly highlight more amazing female security and privacy leaders.
We don't spend enough time in this. So this is another one of my near and dear, you know, topics because I do want to— the more women we bring as role models, the more— and I am a firm believer that this journey towards STEM starts in middle school or early, and that middle school is around the time when a lot of young ladies decide that maybe STEM is not for them. And by having more and more role models out there, I think that, you know, if I'm hoping that it's a little bit that we can do to help encourage young ladies to continue on this path and understand that it's okay if, you know, maybe you're not good at math today or, you know, you name it, right? That, you know, there are so many parts of security that you can you can try that have nothing to do with math, right? You can be a, you know, program manager in the cybersecurity field if you like, or, you know, if you're into compliance, regulatory, whatever, GRC is the path, or if you're more technical, maybe security operations is a better fit, right?
But there's so many parts of security that you can explore that I think it's key in showcasing that it's okay to take this path. It's okay to be uncomfortable. And there are many women that succeeded in this role. And there's no reason why you can't explore it. Yeah.
And I think that having more women in the industry, you know, like you said, there's so many other pieces to it because, you know, as you know, like usually there's 1 or 2 women in it and the rest is all men. And so how can we get more of that diversity? Because I do think we need those voices because I think that we also can— we can shore up the technical people like those guys that want to— or people that really want to stay super technical, right? They need that support from a documentation perspective or like you said, PMing it. And so because that was kind of like my ending questions of suggestions for getting into the field or keeping people in the field, I think you really hit on that.
But any other things that you think we can do to help women to get in the field or stay there? I will say the main thing. So outside of, you know, the main thing is find where your passion lies and go for it. Try the different areas of security. If you don't like one, you may like another.
And then lastly, really don't be afraid to raise your hand and take new challenges. That is what's going to, you know, bring you to the front line in terms of, you know what, this is someone that cares. I think oftentimes, and we talk a lot about this, when it comes to security, it's about the whole package. Right? There's so many aspects of the total you that matter, not just the technical skills.
You know, your personality, your background, your, you know, things that you interned on, or, you know, stuff that you've done early on. So for example, you know, for me, while I was still in law school and running security in my— earlier on in my Polycom days, I also did an internship around information protection or IP and privacy. Which ultimately led me to taking over the entire privacy program and really, you know, brought to forefront my ability to understand and decipher laws and go into complex topics and figure them out with the technology. And that really paved the path to me becoming a Chief Privacy Officer over time, but it really stemmed from me raising my hand, from me you know, ringing that bell like, hey, this is coming, right? We have to look at this.
You know, at the same token, it was like the China Cybersecurity Law came in— it was coming in around the same time with the US— with the GDPR and Russia's cybersecurity law. So there's so much happening that I was— I had to start raising the bell. I had to start making noise. I had to kind of raise my hand and say, we have to do something about this. And I got people's attention.
And I was able to build the support the same way as I had to do to lobby for budgets for my security program, to be able to mature my security program over time. And as well as got— so when I was at Polycom, I took the company through a full ISO 27001 certification process. That was an entire culture shift. And that was a multi-year journey, the same as building a data privacy program. So, you know, I had to leverage a lot of, you know, what I built from a security perspective to extend privacy.
But again, it goes back to raising your hand, taking a stance, and, you know, don't be afraid of the challenge because you never know what that will— where that's going to ultimately lead you. I thought I was going to be an attorney, and I am— I love being a CISO. I love both security and privacy equally. And I'm not ready to step away from the technical aspects of the job. Yeah, I love that, raising your hand and kind of doing what nobody else wants to do, right?
And doing it really well. I love that. That's awesome. Well, we're almost out of time. Is there anything else that you want to talk about before we kind of wrap up?
One thing that I— it's something that I'm extremely passionate about and I hit on a little bit is is really our ability to bring awareness to boards. I think the increase of cyber incidents has really helped us elevate, you know, the level of awareness of cybersecurity oversight to the boardroom. But for many board members, you know, security is daunting, it's overwhelming, and we really truly need, you know, cybersecurity expertise in board. But more so than that, we need gender diversity as a foundational board diversity challenge, and this is a topic of concern across the board, but we really need to— security leaders focus on effectively communicating to boards. I hear this over and over and over again from board members that they get the security matters, they get that security is important, but they have no idea what that CISO came and told them.
As security leaders, we have to start to, you know, being crisp is have to start speaking business— in business terms and business risk in a language our board members are understanding if we want to really be able to fully get the support that we need. We wanted the board's attention. I think we got that attention, right? It is now our job to step up and be able to truly and accurately communicate with them to get the support we need to be able to truly mature our security program. There's so many basics that we're still lacking.
And one thing about my current role as the resident Chief Information Security Officer at Proofpoint is I have the opportunity to impact more than one customer at a time, more than one organization at a time. As an in-house CISO, I help one company, right? As working at a vendor, and I thought that I went to the dark side when I first joined, I had my questions about working for a vendor. But being able to help so many organizations at the same time has been so impactful and so amazing. And I see it over and over and over again.
Many of us are struggling with the basics. We have to get the basics right, and we really need to be able to be clear and crisp with our boards to be able to walk that maturity journey. Yeah, no, I totally agree with you. And we can have a side conversation about being on the vendor side. And the dark side.
But I agree, you can, you can impact so many, all those customers. So, well, I think our time is up and Alex is gonna yell at me if we go much longer. So, but thank you so much. Any final, final words and then we'll wrap it up? Um, no, it's great to be here.
Thank you. It's great seeing you. And, you know, thank you for the time. You too. All right, I'm gonna go ahead and pause.
Everybody in Colorado, stay safe.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security. Security.