Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 188 for the week of November 23rd. Alex, uh, we are once again socially distanced.
Um, it looks like the world is shutting down again. Yeah, sad but true, Robb. You know, things are getting worse. I read the other day that 1 in 48 Coloradans is infected with COVID That seems like a lot of people. So that means we have multiple COVID-infected people listening to us right now.
That's true. And if you are, get well, rest, all that kind of good stuff. But yeah, I think you're right. That's a bummer. That's a scary thought.
For the whatever double-digit number of you who have COVID, let us know how you're doing. Hopefully, it's not too bad. We love to know how this is impacting people. I know I've had a number of coworkers who have been infected. And so far, I haven't heard a lot of negative stories from those folks.
Most of them have been okay. But obviously, when you see the news, it looks like there are some folks who get really impacted badly by this stuff. Robb, I think you might be overestimating our listener base if you think that they're double-digit. Well, if you say there's— if it's 48 times, you know— Are you saying like 2? I mean, 2 is sort of a double-digit.
Oh, yeah. I see what you did there. You were ready to be a dad early on, weren't you? I was. I was.
Good at the dad jokes. Anyway. You know what, we do have housekeeping, Robb. Did you know we have a Slack channel? There are— yeah, Slack.
It's a, it's a thing where you talk through text, kind of like chatting online. That's way more efficient than having to talk with words. It is, it is. I can type much faster than I can talk. We've got a lot of great people on that, that Slack channel, and if you're not there, we'd love to have you join, join us there.
So go to the website colorado-security.com, click the Slack button, and join up with everybody else. While you're there, go down to the bottom of the page and join our mailing list. You'll get the show notes in your inbox every week. That'll keep you up on, up on the news here in the Colorado region. And of course, we'd also love it if you would rate us and subscribe in your favorite podcatcher.
If you're on your— if you're using Apple Podcasts, or if you're using Google Play or Spotify or whatever other thing you might be using, we'd love it if you'd subscribe and rate us so people can find the show. Yes, that would be wonderful. We'd also love for you to tell a friend, um, probably virtually at this point. Don't, uh, you know, keep your distance, uh, don't go around, you know, telling people, you know, in person or anything like that, but make sure you let people know about Colorado Equal Security and, and have them come join the fun with us. We also have a Patreon campaign.
This is a website you can use to financially support the show. You know, we do this show, uh, out of our own pocketbook and But we have a great set of patrons who have been helping sponsor us and help pay for the, the hosting fees, the websites, the all the various costs that come along with this. Uh, we really appreciate those folks. And of course, if you want to join that group, go out to our website and join on Patreon. Awesome.
You know, Robb, there were some pretty big news this week, um, and we're going to kick it off with a really hard-hitting, um, you know, super important story. Well, for anyone, anyone that hasn't heard In-N-Out Burger opened their first locations in Colorado this week. This is the culmination of, of what, 2 or 3 years of us talking about In-N-Out coming to town. Um, the good news is, I mean, if you have not yet had In-N-Out, you can do it. All you have to do is invest 12 to 14 hours of your time to get in line, and, and at the end of that, you will have had what is probably the most mediocre burger you're ever gonna have.
Yeah, you know, there are a lot of people that really like In-N-Out. I think it's good, but definitely not 12 hours worth good. If I was nearby and wanted something to eat, I'd probably do it. There are definitely times when I've traveled and thought, oh, hey, I'm near an In-N-Out Burger, let me go have one. But I mean, I think that there are places that are better.
I do like the sort of big greasy style like Five Guys, I think, better than In-N-Out. I mean, if— what are you gonna do if you, if you're pulling off the freeway and there's a McDonald's and an In-N-Out and a Taco Bell next to each other? I think, I think you're, you're probably making the right, uh, decision by going to In-N-Out. However, if you're choosing between, I don't know, watching 2 movies, reading half of a book, and, you know, spending time with your family and having In-N-Out, maybe go with, uh, the not In-N-Out option there. Yeah, I, I did hear that the, uh, the 12-hour time was drive-through wait time.
And I believe that they were also doing walk-up orders too, which I think were less, but still, even if you're going to wait several hours in line to get a hamburger, you can do much better. I did see some people post this week on social media saying, hey, we've got all these great local restaurants that are super struggling. So why don't you go to one of them instead of spending 12 hours waiting for In-N-Out? Was actually the Aurora Police Department's Twitter account that was saying that, which I thought was super funny. Uh, I did see one— please go away, we don't want you.
All right, one interesting tip I saw was to order your french fries extra crispy at In-N-Out, and I agree. I, I've never liked the fries there, but I didn't know that you could order them extra crispy, so that's an interesting option to go with. Yeah, good stuff. Hey, we've talked enough about that. Moving on, um, we— our next story this week is, uh, a list that Deloitte has put out about the fastest-growing tech businesses in the U.S., and 8 Colorado companies made their list.
Yeah, uh, sadly there weren't any security companies on this list. That would have been pretty cool. Um, but we do have a number of Colorado companies on here. Uh, the, the top of the list for Colorado companies, uh, at number 45 is GCI Liberty with, uh, 3,867% growth. Yeah, this is a— so GCI is a telco provider up in Alaska, and Liberty is like Liberty Media there.
I, I actually don't know if this is like a subsidiary of Liberty Media or this is like a renamed version of Liberty Media or what. I'm not sure. Um, but that is the, the telco up there. Um, the rest of the companies on the list, I had never heard of any of them. Um, we have Dispatch Health, Quantum Metric.
Oh, did we talk about Quantum Metric? No, I don't think we did. We talked about some other cool quantum. There was— yes, there was a quantum one up near older recently, but I don't think that's the name. Yeah, that's different.
Helix Technologies, Billing Platform, Liquid with no U, Immersive Technologies, and Zynex Medical. So I'd never heard of any of these companies other than GCI Liberty, but those— they've all grown really huge from Dispatch up at the top with 2,500% growth down to Zynex Medical, which only had 242% growth, still doing great. Yeah, um, I, I think, you know, if you told me, uh, just the name of the last one, Xynex, um, I would know it was a medical thing because that sounds like a bad drug name. And then if you're, if you're sitting here thinking, well, it's interesting to know that Colorado had, um, what was that, 8 companies on that, on that list, but I want to know who number 1 on the list was, well, I got you covered. Uh, Pasadena, California's, um, Arrowhead Pharmaceuticals was the top on the list, and they only had 106,000% growth over the last few years.
Wow. That's a pretty good percentage there, Robb. 1,000— 106,000. That's a big number. That is a big number.
I don't even know how you can grow that much. Anyway, you start off small. I know that. Yeah. We made $1 4 years ago, and we've grown 106,000% since.
Anyway. Uh, well, good stuff. Uh, moving on. Next, uh, Colorado Springs has been named a finalist for the U.S. Space Command headquarters, um, which of course will be the headquarters for the Space Force. Now, I am— I gotta admit, I'm a little embarrassed here.
I thought we had already got this, um, and what we had already got was the provisional location for Space Command, um, and we've had that for— was it a year or so? And I know we talked about it on the show. For some reason, I thought that that was permanent. Not permanent. We're still in, in competition with, uh, 5 other locations.
Yeah, while I could let you be embarrassed on your own, I felt kind of the same way myself too. Um, so I was a little confused before reading this. But yes, uh, we are in competition with, uh, Kirtland Air Force Base in Albuquerque, Patrick Air Force Base in Brevard, Florida, Offutt Air Force Base in Bellevue, Nebraska, Redstone Arsenal in Huntsville, Alabama, and the Joint Base San Antonio in San Antonio, Texas. Uh, one thing that I pulled out of the article that, you know, I was not aware of— well, Space Force is— it actually falls under the Air Force's purview, um, but similar to how the Marine Corps falls under the Navy, um, the Marine Corps is still its own branch, and it actually has a seat at the Joint Chief of Staff. So, uh, it's gonna fall under the Air Force like like, uh, Marines falls under Navy, but they're, they're going to be represented at the Joint Chiefs.
Yeah, and I mean, I think we've got a pretty good shot for the headquarters to stay here considering that, um, you know, it has been— Peterson Air Force Base here has been head to, uh, Air Force Space Command, um, which is the predecessor of the Space Command since 1982. So I don't know, it seems pretty logical to me. All right, moving forward, we have news from a Denver company Strava, which is the, what, kind of like share your exercise social media app. They have raised $110 million and they have, they're touting that they are growing at over 2 million new users each month this year. Yeah, I think that that's pretty cool.
Yeah, Strava is an exercise app. You can, you know, track your workouts on there. I think, you know, mostly it is for, you know, people who bike or run, Um, or I think you can do swimming on there as well, you know, so it'll, it'll not only track, you know, the number of calories and distance and things like that, but it'll, you know, show you a map of where it is that you went. Um, you know, Strava opened a, a pretty big office here a couple of years ago. Um, so, uh, pretty cool that, that they're continuing to grow.
Some of the growth it sounds like is because of, uh, the pandemic and, you know, everyone being at home and all of a sudden going, well, I need to do, do something, may as well go for a run or ride a bike. And And they want to track that. So, if you weren't aware, they are headquartered in downtown Denver. They now have 70 million members and they have a presence in 195 countries globally. So, they're doing pretty well.
Yeah, that is pretty cool. Next, a Denver AI property insurance startup called Flywheel has landed $10 million in Series A funding. Yeah. Flywheel, another company that I was not aware of that's doing great here in Denver. They are an AI solution for residential and commercial property insurance.
Basically, reading the article, what it looks like is they allow policyholders to take pictures with their smartphone as they're doing applications for insurance, and that's going to get the info over to the insurance companies to make decisions around coverage and all that good stuff. Yeah. I think the key here is they're trying to make better underwriting decisions and make better policies and better claim processes, and that AI part is, I imagine, taking the, the photos and trying to parse out the things from the photos as opposed to having to have a human do that. So pretty cool there. The company currently has 23 employees, uh, and they expect to grow to about 50 by the end of next year.
Um, so they are a Denver-based company looking to hire. If you're interested in getting involved with an up-and-coming, uh, company, that's probably a good one to reach out to. Sounds pretty cool. Uh, next, uh, we have a partnership announcement, and Zoic which is— you may not know the name— formerly known as PasswordPing, is partnering with OneLogin to help prevent cyberattacks caused by compromised passwords. So, and Zoic provides a service where you can check a password to see if it has been part of a breach before, and then, you know, take actions based on that, you know, potentially not let a user use that password and force them to change it, other things like that.
And I think we're all aware of the Have I Been Pwned database. They've basically taken the same idea and, you know, added supportability around it, made it kind of commercialized. So rather than, you know, using a free database out there on the web that may or may not be available, they're kind of making a commercial version and then making nice integrations. So basically they're going to work with OneLogin to make, you know, to help OneLogin look for compromised passwords in your users' passwords. Good stuff.
All right, moving forward, we have a blog this week from Red Canary, and this is looking into the, the modern SOC, the Security Operations Center, and really what are the different elements of responsibilities that the SOC has. Robb, what are the different elements? Well, thanks for throwing that right back to me. I appreciate it. Really what they're trying to do is break down the different areas.
So this first one is looking at threat intelligence and what are the security operation elements of threat intelligence. I actually had a chance to talk with Keith, the one who wrote this, before he published it. And it's interesting to think about the— there's an enablement and kind of architecture that goes in before the SOC gets involved. So creating the infrastructure for what threat intelligence you're gonna have, how it's gonna get integrated into your system, kind of the engineering behind it is probably outside of the SOC's purview. But once those things are set up and you have that intelligence coming in, that's when it's the SOC's responsibility to start figuring it out.
When they get intelligence coming in, you know, presumably you're gonna have, you know, something either integrated to your SIEM or some other technology. When you get new intelligence that's interesting, there's gonna have to be steps taken. So I'm gonna get intelligence that says, you know, someone's looking to attack my company, or, you know, there's attacks out in the world that are attacking companies like mine, and here's some indicators of compromise. Well, you're gonna look for your SOC analysts to start looking in your environment for either those indicators of compromise or those vulnerabilities that would let that attack be successful. Yeah, I mean, and then a second area building on that that they have here is threat research.
So, you know, not necessarily the, the infrastructure to take in the threat intelligence or the threat intelligence itself, itself, but doing research around that, finding new threats, you know, looking for blind spots or assumptions that you might have that you still need to cover. And then, you know, providing a level of depth, whether it's, you know, techniques or, you know, malware that is associated with those sorts of threat intelligence and things like that. Good stuff. You know, as always, I think Red Canary's putting out content that's not salesy at all. It's just a value add.
I think if you're running a SOC and you're trying to figure out how to really look at threat intelligence, you've got to— this is a must-read. And of course, this is starting a series. There's gonna be more coming out. So I'm sure we'll cover those as they come out as well. Good stuff.
Uh, LogRhythm had a blog talking about security awareness and remote workers, so they have a checklist here talking about the things that, that you need to think about when thinking about security awareness for your remote workers. Yeah, it's a relatively short list, and, and I actually like that for the sake that, uh, they're, they're trying to give you a, an easily digestible list of things that you'd want to do while working remote. Starting at the top of the list, make sure you're logged into the company's VPN. To connect to the network. I think they're trying to avoid, you know, the potential perils of being on an untrusted network.
Yep, making sure that your software is up to date or do any updates if they're needed. And I would, I would say that this is no less important if you're not working remotely, but certainly important remote as well. Change any passwords that you may be reusing and make stronger ones if needed. And they give some guidance for what a strong password looks like. You know, once again, good guidance whether you're remote or not.
Yeah, one thing that I think is sort of a given but often gets overlooked is making sure that your home Wi-Fi network has a strong password and other security associated with your, your home Wi-Fi. They recommend disabling Bluetooth discovery on your mobile devices. Also disabling Wi-Fi auto-connect on your mobile devices so they don't accidentally join a network that is malicious. And the final one, another one that I'm not sure people would have thought of, is make sure that you have the contact information for your IT department so you can immediately notify them about anything suspicious or ask for help. Yeah, good stuff there.
Uh, thanks, Logarithm, for that one. All right, next, uh, we have a, a press release from CyberGRX, the local third-party risk management company, um, who's created— they created a platform where, uh, you, you kind of basically bring in all of your service providers to do, um, a security, um, like security questionnaire or risk assessment, and then that can be reused by all of their different customers rather than having every customer do their own. Anyway, they released a press release this week about a new report they've released. Yeah, um, and I think it's, it's interesting, and, you know, they're going to have a whole lot of, uh, data based on, uh, all the companies that, that they look at. And, you know, they identified 5 key insights.
Uh, the first, 20% of an organization's third parties are rated as a high risk. Second insight is that third parties in certain industries are more likely to have mature cybersecurity programs but still have significant gaps. Uh, number 3, company size correlates with security maturity and coverage. Are you telling me that size does matter, Alex? Uh, that's what she said.
Uh, insight number 4 is that the most common third-party security gaps are desktop and laptop protection, server protection, and virtualization protection. Basically, it sounds like it's endpoint protection. Yeah, um, that one, I mean, I'm not gonna argue with the fact that is true, but the— I think the finding there was probably a little more vague than it could have been. Um, you know, that just saying protection doesn't necessarily mean a whole lot. Yeah, it could be a lot more detail there.
Uh, and then number 5, organizations tend to focus on the same set of vendors, but it's often the vendors they aren't looking at that pose the greatest risk. That's interesting. It's probably the, the target AC or HVAC vendor, right? They— you just don't think about the, the fact that, you know, this low-risk-seeming activity requires more access than you'd expect and, and as a result gets you in trouble. Yeah, so good luck.
The ones you're looking at aren't the ones you need to look at. Good luck. So look at it at the other ones. Uh, anyway, hey, uh, go ahead. Finally, we have a blog this week from, uh, Ping Identity talking about webhooks, what they are and how to use them.
Yeah, I got— this is great. This is similar to how Red Canary did their kind of just, you know, general knowledge, making things better. I love this blog from Ping. Basically, if you don't know what a webhook is, you should read this because 3 minutes later you will understand a webhook. And I, strangely enough, just last week or 2 weeks ago, I was talking to someone about how I wanted to see a webhook from their system.
And it was, it was the CEO. He didn't— he doesn't know the technology real well. He's like, well, I don't understand what you're asking for. So I tried to give him a description, but Man, I could have just sent over this blog post to him, which by the way, I did email afterwards. I think he would have been really happy to understand, okay, and go to his development team and say, this is what we need, let's create it.
This is, this is a really good way to serve your customers. Yeah, and again, this is not necessarily a security-related item, but, you know, webhooks are super important for notification and automation and other things like that. And especially now with, you know, Slack and Teams and you know, other communication channels like that supporting, you know, incoming webhooks, then I think it's awesome and a great way for, you know, you to provide a way to be alerted on various things that are happening. Good stuff. Well, that is it for news.
Let's jump over to our Slack message of the week. First of all, let's thank Andre Gaeta. Andre has been a great sponsor of this. And then this week, who do we have as our winner? Yeah, this week our winner is Sundbug, or Chris Sundberg.
And I picked Chris this week because he's basically single-handedly manning the operational technology channel in Slack. So he is posting, you know, 1 or 2 articles in there a day that are awesome based on SCADA, you know, industrial IoT, operational technology security. So if that is an interest of yours, I would say go check out that channel in the Slack workspace and hang out and enjoy that stuff. And, you know, maybe post some stuff of your own. So congrats to Sunbug for getting that going and making sure that there's good content in there.
And as the winner, he will be able to pick one item from the Colorado Equal Security store. That's fantastic. Looking forward to seeing what he picks and hopefully, you know, after pandemic, seeing him around town wearing something awesome. Indeed. All right.
That is it for the Slack message. Let's jump over to— is it events next or jobs? I can't remember. Events. It's like we haven't done this before, Robb.
Yeah, this is my first time. Uh, so, um, not surprisingly, we're a little bit light on events, but we do have a few coming up. Uh, first, uh, on the 27th, DC303 is doing their November meeting. Uh, good stuff. On the 3rd of December, we have 2 events.
First, ISSA Colorado Springs is doing their December online meeting. Uh, and then also on the 3rd, ACES is doing a 2021 voting happy hour trivia. Basically, they're voting for their chapter leadership. I think that's what it is. It's like their annual meeting.
So if you want to crash the party and, uh, become a leader in the ACES group, you bet this is your time to do it. It's time to shine. You might want us to get working on your politicking. Exactly. All right, let's jump over to jobs.
I have a few jobs here at, at Ping that I think I've talked about, and I, I believe we're gonna have, uh, some of these filled here real soon, but for now they're still open. Um, number one, we are hiring a product security engineer. This is application security expert. You need to have some development background. And you help get embedded with one of our development teams to, to make sure security is considered throughout the SDLC.
Second, we're hiring a FedRAMP program manager. And third, we're hiring a manager of GRC programs. This is someone to help kind of run the, the program side of our, of our GRC function under security. Lots of good stuff. SOC 2 audits, vendor risk management, policies, standards, exceptions, risk assessments, all kinds of good stuff.
Good things. All right. Next, Fast Enterprises is looking for an information security analyst. Spectrum is hiring a senior director over connected home cybersecurity products. Sounds pretty cool.
Oh, that does sound cool. Transamerica is looking for a senior cybersecurity investigative analyst. Another good one. I, I thought those are number, number one, those are both cool jobs. Number two, there are a lot of words and we love jobs with a lot of words in them.
Exactly. Speaking of a lot of words in a job, Xcel Energy is hiring a senior application security penetration tester. Uh, Pinsight— I don't know who that is— is looking for a cloud systems and security lead. Uh, this next one I picked just because of the company. It's Fluid Truck.
And the first time I saw a Fluid Truck driving to either mine or one of my neighbor's houses, I thought, is that a truck that's delivering like oxygen or something? And apparently, you know, now, now I know Fluid Truck is just like a, a truck share app, you know, that you rent out these trucks like a, um, I don't know, like, like Hertz or whatever, right? But for, for commercial truck rental, um, and mostly they're being rented by Amazon, I think. But they, they are hiring a senior security engineer here in Denver. Crazy.
That is crazy. Uh, CommonSpirit Health, uh, formerly CHI, is looking for a Security Analyst 2 in Cyber Fusion Advancement. Wow. Uh, I, I don't know that you need to know, uh, anything about nuclear fusion, but, uh, that might not be a bad thing to know. It probably wouldn't be a bad thing.
Hey, I think we need to start keeping track of the longest job titles and, uh, have some kind of a reward for these because there are a lot of good long job titles this week. There are. Um, you did some good picking this week, Robb. And yeah, I think— what is that? Uh, it's 6-ish, 6, 7, uh, 6 or 7 words there, I think, is our big this week.
But this is riveting podcasting. We're looking forward to seeing someone coming in with a longer— a lot longer podcast— a longer job title. Hey, I think we should just stop this podcast now. No one wants a longer podcast. Let's be done.
All right, well, that is it. We do not have an interview this week. Of course, it's Thanksgiving coming up. We're gonna skip next week and be back to see you guys in early December. Alex, any final words of wisdom before we call it a day?
Happy Thanksgiving, everyone. Enjoy your turkey or whatever else it is that you might eat, and stay safe out there. All right, thanks guys. Thanks, Robb. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Shadow equals security.