Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 152 for the week of February 17th, 2020. Alex, happy President's Day.
Happy President's Day, Robb. This is the day when we get an extra day off work. Absolutely. And of course, you are dressed up in your your best Lincoln garb today with that suit and the the beautiful was it ten gallon hat? Is that what they call that?
Four score and seven years ago, Robb. Keep going. That's all I know. Our forefathers. Yeah.
Okay. Yeah. I don't know that I ever had to memorize that. That's you know one of those things I think some people have to memorize for school. I don't.
I don't know if I memorized it. I definitely knew it. Pretty well in, I don't know, 4th grade, 5th grade, something like that. I am actually halfway through watching Lincoln right now, that 2012 movie with Daniel Day-Lewis. So far, pretty interesting.
I started it a little bit late last night, so I'm gonna finish it up today. Is Lincoln your favorite president, Robb?
I don't know. I think Washington's my favorite president. Yeah? Because that guy had the opportunity to basically become the king, and he's like, nah, I'm good. And he like just quit after 2 terms.
He's like, I'm ready to retire. It's been hard. Yeah, so I mean, it's not a lot of people in the history of humanity who have had the chance to, you know, be a monarch and kind of just gave it up. So that's pretty cool. That is pretty cool.
Congratulations. Do you have a favorite president? You know, I think Charlton Heston.
I think that, that my favorite president is probably Woodrow Wilson. Oh yeah. Just because of the name, you know, you know, Wood and Woodrow. Woodrow. Yeah, I get it.
I had that as a nickname in high school. Some people called me Woodrow. So I get it. Well, Well, good. I'm glad you had a good reason for your favorite one.
I have no idea what Woodrow Wilson did in terms of his actual presidency. You know, was he good or bad? I don't know. But so the college— on a name— the college I went to. So excluding current-day presidents, could you— do you have an idea who the worst president has been?
There's kind of a meme about who the worst one is. Do you know? Yeah, I have seen that meme, but I don't remember off the top of my head. So it's— well, it's known to be Herbert Hoover. Because of the Great Depression, and they kind of— people blamed him for it.
Well, the college I went to, he actually went to that school, you know, well, you know, 100 years before me or whatever. And they're kind of proud of it there. It's really an interesting mix. Like, you know, the hall there is— it's Hubert Hall or Hoover Hall.
Yeah. So there's a lot of talking about this guy. And when I went there, I'm like, oh, he seems like a good guy. And then later in life, I'm like, Like, maybe not such a great president, though. Well, but he's your not great president.
There you go. Right. There you go. All right. Well, let's go ahead and jump in.
We do have some housekeeping. As a reminder, we have a Slack channel. Lots of great conversation, a ton of conversation this week. We're going to need to have a Slack message of the week here pretty soon. We are.
I just noticed that, Robb, that there's not anything on the list. So we're going to figure that out magically before we get to that part of the podcast. We will have that answer. We will. If you want to join the Slack channel, though, there's a link on the the website, you can go click to get in there and we'd be happy to have you join us and have some great conversations.
We're getting close to 1,300 people in there. Pretty cool. Uh, we also have a mailing list if you would like to have the show notes delivered to your inbox every week so that you know exactly what happened on the podcast and when it is released. Sign up on the website colorado-security.com. I also added a new form on there, Robb, recently.
Um, if you want to get something on our events calendar, there's a form now where you can submit something for us to put it on there. If you are not a bot, we would love for you to submit to that form. We would love you guys to get down there. And you don't need to tell us that such a thing as CAPTCHA exists. We know that, right?
It's, it's one of— it's on the backlog. It is on the product backlog. Next, we would love it if you'd rate us and subscribe to the podcast. You know that the more ratings we have, the more folks will know about the podcast. We'll get new listeners.
That's good stuff. Also, you could tell a friend, let folks you know that know about the podcast and maybe get them to come listen and Give us money. Yeah. After you tell them, you can also say, hey, you know, it would be great if you signed up for the Patreon campaign for Colorado Equal Security to help them cover the costs that it takes to run this whole giant campaign that we have. You can find more information about the Patreon campaign on the website as well.
If you sign up at certain levels, you will get cool swag delivered to you in the mail from us. All right. That's going to be it for housekeeping this week. Let's go ahead and move into the news. Number 1, there is a company in Boulder called Misty Robotics that's helping companies make robots that can be front desk workers.
Yeah, this is actually a company that spun out of Sphero, which I hadn't heard of the Misty side of this. But, you know, Sphero is the, the more well-known robot company out of Boulder. You know, they do the, the BB-8 robots and things like that. But the, the Misty robots, this is, I mean, I guess it's, I don't wanna say it doesn't do anything, but it is not where you think like, oh, this is a robot that has a, you know, is moving around and has arms and, you know, is moving stuff. It's more, you know, kind of just, it does move, but sitting there waiting for someone, helping them, you know, checking people in, doing other things like that.
It's absolutely adorable though. I'll say that. What is it like 14 inches tall? I think. Something like that.
And the, so the Misty 2 robots, what we're talking about, it costs about $2,900 to get one of these guys. It comes with an open source programming application on it that you can use to do things like be a front desk person at a hotel, kind of call it call center type, type stuff that, but it's really meant, I guess not call center, it's really meant to be human facing, right? It has to have a human in the room with it, I think. Yeah. I think one of the other examples they gave was you know, checking in like at a medical facility or, you know, retirement home or something like that, you know, meeting people at the front desk.
One of the things they also noted is that, you know, this is the, the sort of position that at least in the news people have said is hard to fill. Yeah. So it, you know, for a mere $2,800, you could have this robot and not have to hire somebody to sit at the desk. And, and I bet you could use this to be your friend. So $2,900 for a friend.
That's not too terrible. Seems like a bargain, Robb. Yeah. All right, let's go ahead and move on. We have some, some bad news.
A cold wind blows in, Alex. Ooh. Yes. Sadly, the Chinook Tavern in the Tech Center has closed. This was a sort of a mainstay down there by Fiddler's Green.
The OWASP chapter had their meetings there for a long time. Yeah. We had an ISSA meeting or two there over the years too. German restaurant. They had been there for— it was like 25 years.
Well, they'd been in that location since 2011, but then they were in like Wash Park or something for 20 years before that. Yeah. So very sad. The taxman gets his money. Yeah.
So if you want some of the things that were in the restaurant, there's going to be a tax auction in a couple of weeks. Yeah. Sad stuff. I got to be honest, though, it was a couple of years ago I read a Denver Health report that gave them an F for some health violations. And ever since then, I've been, I've been kind of unwilling to go there.
Yeah. So, so there's that. Well, in some other happy and I guess sort of sad news, depending on how you're looking at it, a judge has ruled in favor of the T-Mobile Sprint merger, which means that Dish Network will be able to step up to be the 4th major uh, telecom, uh, mobile device carrier in the country. We've been talking about this story for, well, man, it seems like a couple years now, but probably a year or so. And there's just this— I think this was really the last legal hurdle for them to get through.
Um, so Charlie Ergen said in a statement, um, that it's going to allow DISH to build out their plan for 5G. It's going to serve 70% of the U.S. population by June of 2023. So just a little bit under 3 and a half years from now. Probably here in Denver, we're going to have a great Dish Network 5G network. Yeah, the, the headquarters for the mobile carrier is going to be right by my house.
So pretty cool. Sounds pretty good. I should get good cell service. 2,000 jobs were guaranteed as a part of this. I think so.
Yeah. Well, hopefully you get one of those guaranteed jobs. That's right. That's one of the good ones. Next, consider, you know, talking about local telcos.
CenturyLink is considering selling off its consumer business. Yeah, and we talked about this one last year as well. It was mentioned at one of their quarterly early earning calls. And again, at the most recent earning call, they said that they are still considering this. I think that they completed sort of the investigation phase, but didn't really get more details beyond that.
Basically, they're just looking for whatever makes sense for them to be more profitable. There was a quote from their CEO in here talking about their 2020 priorities. And I thought this was interesting.
In this really short paragraph, just like 2 sentences, they're going to transform operations, blah, blah, blah. But then they say they're going to continue to invest in growth for the enablement of products such as embedded security, dynamic connections, cloud application management, and edge computing. So security was the number one thing on their new platforms they're trying to offer. That's cool. I also like how he started the quote.
He was talking to reporters and he said, hey, you'll notice that our 2020 priorities look a lot like our 2019 priorities. Um, my embellishment here, dummies. Um, we, we set a, a strategy and we're following it. Yeah, he seems like he's pretty committed to that, which, which sounds good to me. Hopefully they have some success, uh, based on this.
Uh, next, um, Robb, did you know that in March there is something called March Madness? No, what's that? Well, it's actually a basketball tournament, but this is some kind of coronavirus offspring that's coming. It very well could be this year, but no. And when that time comes around, there are lots of other people that sort of copy that same thing and do their own sort of tournaments.
We should do that. We could do that, like a top 64 security people in Denver and just like make them battle to the death. We give everyone foam swords. Anyway, but there's, there's a website called Colorado Inno, and they are doing their 2020 Tech Madness finalists. So they're doing a tournament of Colorado startups to pit them against each other.
It seems a little bit loose on what, how it is you would pit them against each other, but basically you would get to vote for the 2 that are against each other until finally someone wins in the end. Are there any interesting companies on this list, Alex? There are some interesting companies on that list, Robb. Uh, actually there are lots of interesting ones, but there are 2 that I thought were the most interesting. Uh, one was CyberGRX and the other was StackHawk, 2 of the local— ah, 2 of the local Colorado security startups.
Uh, that's good stuff. There are a bunch of other names on here that we know. We've talked about like Boom Supersonic in the past. Um, Conga's on the list. Uh, who else?
Full Contact's on the list. Guild Education. Um, a lot of good stuff on here. Yeah. Lots of good stuff.
Sphero. We just talked about that. They made the list. Yep. So, uh, you can check that out with the, the link in the show notes.
And, um, I believe this week or, uh, potentially next week they will actually have a reveal of the actual bracket. Oh, um, that was March 5th. Uh, sure. Sounds right. And then, um, And then, and then you'll be able to see the rules and how you can vote on the different folks in the bracket.
So sounds good. And of course, we will give you all the information you need in order for us to stack the bracket for the security companies to win. Moving along here, there is an MIT study about a voting app that Denver used in the 2019 election. It's called Voatz. Was it V-O-A-T-Z?
Correct. Which is pretty awesome the way they spelled that. But the MIT study, believe it or not, did not show that this was an unhackable super secure voting application. Robb, I am shocked. Shocked, I say, that there is a voting app that is insecure.
The, the interesting thing is that Denver used this for, for military voters who were out of the country. And I want to say that in the last election, there were only about 300 people that they, they had use the app. Strangely, there were 12,000 votes that came through the votes. I'm just kidding. That was a joke.
This is all alleged. But, but then they also, they, they said that because of the app, turnout was much higher for those folks as opposed to them having to write it on paper, scan it in, fax it, or, you know, some other weird old technology. So I guess there's trade-offs, right? Yeah. So, Alex, before we started recording today, we were talking a little bit about election security and mobile voting.
It seems like it's coming at some point. I guess the only way you can really push people to figure it out is by, you know, starting with these little experiments. Hopefully we can, we can figure out ways to do it in a secure way or at least a non-reputable way so that, you know, if it does get altered, we have the ability to go back and get some consistency and figure out what it should have been in the first case. Votes, of course, pushed back pretty hard on MIT study and they said that MIT was using an old version of the app and they had made some assumptions on the backend that weren't true. MIT's response is, hey, we used a version of the app we could download from the Play Store.
We made it up. So who knows what's exactly going on here? But it does, you know, it's interesting to know that the app Denver used was in the news. So yes, so votes said, hey, our app was bad and insecure before, but it's fine now. Don't worry about it.
There was a quote in there also that said that people were excited that this, this happened because getting more eyes on this and testing it is the way to make stuff better. It sure is. Next story we have is actually the official launch announcements for Randori and their, what is it, their red team service that they're selling now, right? Yeah, so a couple months ago, they released the first of their services, which I, Randori Recon, which was to discover the assets that you had out there that they could potentially attack. And now they've released the second module, which is Randori Attack, which then can, in a more automated manner, go out there and potentially attack those resources to see where your vulnerabilities are.
So the article says Randori is a Boston-based security company, which just sucks. Come on now. Let's get that fixed. Uh, at least, you know, one of the co-founders we've had on the show, uh, Moose, uh, local, local here in, uh, in the Denver area. Um, and of course we like to think of these guys as, as a Colorado company.
Yeah, I agree. They just need to keep getting more of that, uh, momentum out here and less of it in Boston. Uh, next there was a blog post by Red Canary talking about PUPS. What's a, a pup? I mean, obviously a small dog.
Yeah. What else is a pup? That's my favorite kind of pup. A pup is a potentially unwanted program, Robb. So these are things that are not inherently bad, but could be potentially bad.
This blog post is actually pretty interesting. One of the things that I pulled out of it, as we know, pups are not necessarily bad, but, but they said they ran the numbers based on their customers. And customers who had a larger number of PUP detections could see 5 times the amount of malicious or suspicious detections compared to environments where there weren't those PUP detections. Yeah, so an example of a PUP is, I don't know if you know Caffeine. It's an application people will install on their Linux-based, you know, a Mac machine to keep it active so the screensaver and lock will never come on.
So that's one that You know, it's not, it's not a virus, it's not malware, but it's potentially unwanted, right? And I know I've seen examples of this throughout my environment and gives you something to go get better at. Yeah, I think something else is, you know, programs that can be used in a legitimate way but also can be used in a bad way. Something like, you know, VNC or something like that. It could be that that's legitimate, that someone is remote controlling that device, but it could also be a bad person doing bad things.
All right, next we have a blog post from Optiv this week, the Ask Optiv blog series, which is apparently like kind of like Miss Manners where you write in to ask about your favorite topic. And this week's or this instance of the blog was around AI and asking the question, with attackers using AI, is AI as defense the only way to defend your environment now? Of course, Robb. Everyone needs to go out and get their own artificial intelligence bots so that they can fight off the attackers. Well, that was fast.
Done. Summary. Well, it's a little bit more nuanced answer than that, right? Yeah. I'm a little bit, I'll say a little bit torn on this article.
And, you know, in general, on the, all the talk around AI, while AI and using computers to do things that people aren't good at is great, I think that we really need to focus more on actual good solutions as opposed to how we get to those solutions. Yeah, I think that the key for me is trying to spend less time talking about the technology. So AI is, you know, a type of technology and more time understanding exactly what problem we're trying to solve in a more detailed way. And then creating a framework to help, you know, support those solutions. And AI certainly can help within any of those silos, but man, you don't need AI to be effective.
You might need AI to get more efficient, right? And that's, and I think efficiency is way after you've kind of solved the problem, then you get more efficient at it. I think the other thing is, um, it's probably important for product vendors to embrace AI so that their products can become better. However, the average security team probably isn't gonna worry about using AI directly to do any of their operations. You know, they may use some product that uses AI on the backend, which is great.
Um, but again, it's, it's all about the outcome, not really how you do it. Yeah. And for the, for the security team, all they're thinking about is which of these products best sort of accomplishes my goal. And whether it's using AI or not doesn't matter. Now, to your point, the vendors might want to use AI because they can better accomplish goal that way.
But from a security team buying, I don't need to say AI on your box. I just need to know that your box does what it's supposed to do better than your competitors. Yep, exactly. All right. Last news story is actually a pretty good one here from ThreatX.
We talked, it feels like a month or so ago, we talked about the new OWASP API Top 10. Uh, ThreatX spent some more time diving into that Top 10 and really kind of comparing it to the, the application web security Top 10 and, you know, where the differences are and kind of what the learnings there are. Yeah, and this blog post was by, uh, Chris Brezunas, who we actually interviewed on the show. And, uh, I think it's actually a really good in-depth look at the, the 2 different lists, the OWASP API Top 10 and the regular OWASP Top 10, Comparing them with each other, looking at where there's similar similarities and where there's not, and then getting into some of those details. So if you are interested in API security, which everybody should be, then I'd say check that one out.
All right, well, that is it for the news. Let's go ahead and move over to the Slack message of the week. So big thanks to Andre Gaeta for sponsoring the Slack message of the week. Each week we get to pick one person from the Slack community to get a $25 credit towards buying something from the Colorado Equal Security store. And of course, it's all new logo data now, not data, items now.
So of course the winner gets to pick something awesome and new. Yeah. Also, as a public service announcement, if you had a link to the Colorado Equal Security logo store previously, make sure to go back to our website because the logo or the URL is slightly different now. So if you have the old link, it still will take you to, to old logo merchandise. Anyway, the winner this week is Douglas Brush.
Congratulations, Douglas. Um, he posted an article, uh, talking about the CIA, um, buying the Crypto AG company. And so this was a, a company that, uh, was sort of the leading company in providing crypto services. And, uh, at one point the CIA, CIA, instead of trying to backdoor 'em, just bought them and then backdoored them. So when the US government talks about Huawei and why we shouldn't put them in our critical infrastructure, they speak from experience.
Yes. They know how this works. They, they understand this and they don't want backdoors. This is a playbook that they have seen run. Good.
Well, congratulations, Douglas. You know, pick something awesome from the store. Looking forward to seeing pictures of that on the Slack channel. Let's go ahead and jump over to events. As a reminder, we have an event calendar.
You can go out and see what's coming up here in the next 6 months or so. And what's coming up the next 2 weeks, Alex? Before we get to the next 2 weeks, SnowFROC tickets are on sale. This is the local OWASP Um, AppSec conference that happens every year. So check that out, get a ticket, and, uh, be there on, uh, March 5th.
That's good. Uh, coming up this week on the 18th, CSA is doing their February chapter meeting. Also on the 18th, Emerging Tech Fan is doing a co-event with IoT Colorado. By the way, this is— these 2 weeks are once again super packed. So a 3rd item on the 18th, Northern Colorado is doing their Cybersecurity Professionals Meetup.
Uh, also on the 18th and the 19th, ISSA Colorado Springs is doing their February chapter meetings. I'm just gonna do this whole day, Alex. On the 19th, we've got the OWASP February meeting. We've got the DENSEC get-together that evening. And also during the, uh, during the day, ISSA Denver is doing the Women in Security event.
You know, Rod, there's also a lot of stuff on the 20th. Uh, the IAPP is doing their Denver KnowledgeNet Mr. Young AI, a case study in designing for privacy on the 20th. ISACA Denver is also doing their February chapter meeting on the 20th, and ISSA Denver has a privacy special interest group. So unfortunately, that's an invite-only event. If you're interested in going, you should reach out to the leadership of ISSA Denver, but it looks really good.
Not the one on the 20th. That's the one on the 24th. I'm not quite there yet. Oh, I'm jumping ahead. You are.
Keep going. All right. Well, on the 21st, uh, SecureSet is doing a beginner capture the flag. Uh, on the 22nd, ISSA Colorado Springs is doing a mini seminar. On the 24th, ISSA Denver is doing a Privacy by Design workshop that's invite only.
That looks really good. I think it's a full day event. And if you're interested in going, reach out to the ISSA Denver leadership. On the 26th, ISC² Pikes Peak chapter is doing their February chapter meeting. We got another busy day.
The 27th, we've got SOAR with Swimlane. That's the local company doing an event at the Highland Tap and Burger. We've got at RSA conference, Salesforce is doing an event for Colorado Equal Security. And on the 27th as well, we've got SecureSet doing Using Vault to Better Protect Your Secrets with Bryce Verdier. We also have a few events on the 28th.
DerbyComm, that's with an M. This is the offshoot of local organizations from DerbyCon since the conference no longer exists, is doing their February meeting. And also DC303, the DEF CON local group, is doing a monthly meetup on the 28th. And finally, the 28th through the 1st, Colorado Springs is doing the Cyberspace Jam events. That's a 3-day thing. I don't know what's going on, but it sounds pretty fun.
It's jamming. I assume Michael Jordan will make an appearance based on the name. And Bugs Bunny. There you go. So let's jump over to jobs.
Robb, does Ping Identity have any open jobs? We do have— I have a few jobs within the security team right now. We're looking to hire a GRC analyst focused on business continuity and incident response. We're looking to hire a product security engineer. That's someone with a development background who's passionate about security.
And we're hiring a senior infrastructure security analyst. You know, send me a note if you're interested, and I'm happy to answer any questions. And of course, apply on the website. Next, I have a job that is sort of in my job family. So the Xanterra Travel Collection, which is an Anschutz company, is hiring a director of information security.
So if you want more information on that or would like an intro to the folks hiring for that job, please let me know. Next, Centura— or excuse me, not Centura— CenturyLink is hiring 2 different leaders. They're hiring a head of enterprise security and a head of product security. Got links to both of those in the show notes. Bank of America has a lot of jobs.
A couple of those are senior manager for SSO solutions and information security engineer. You know, that SSO job, one of the requirements or one of the desired qualifications is 5+ years of Ping Identity experience. Hey, Just saying. Elastic is hiring an information security risk management associate. Empower Retirement is looking for a principal security engineer.
The U.S. Department of the Interior is hiring an IT cybersecurity specialist. And then finally, DeepWatch is looking for a threat hunter. Can you sing baritone? I don't know, Robb. Maybe I could.
Maybe, maybe we'll do that after we finish recording. Well, we made it through the news and Alex, Believe it or not, we actually have an interview this week and I actually did it. What? I know it's been months. It has been months, Robb.
Yeah. So we had Howard Haile. Glad you finally got off your butt and did something. Howard Haile, the CISO from SCL Health, came by and we talked, got some really interesting information about his background and how he got to be the leader for one of Colorado's biggest health providers. I look forward to hearing it.
All right. Well, that's it for this week. We'll look forward to talking to you guys again next week. Thanks, Robb. Hi, this is Mary Haynes.
VP of Network Security at Charter Communications. Welcome to Colorado Equal Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. Today, this is Robb. I'm sitting down with Howard Haile. Howard, you are the CISO over at Exempla or SCL Health, I guess it's SCL Health, excuse me, formerly Exempla, and that's the name— I don't know if that's just a Colorado thing, that's the name that kind of stuck stuck with me around what you guys did or bought over the years. It was a big brand name in the Denver area, but actually Exempla was part of SCL for quite some time.
We, uh, back when we were based in Lenexa, Kansas, out in Kansas City, is where SCL's home office was before. St. Joseph's Hospital was always part of Sisters of Charity of Leavenworth Health, but they had an agreement, a management agreement with SCL with Exempla to manage the, uh, the hospital for us out in Colorado. And then as time went on, there was a big need to invest into St. Joseph's Hospital, rebuild that facility, which we've done. And because of that, it caused the 2 health systems to, uh, to come together. And so we became SCL Health and moved all of our operations from Kansas City to Denver.
Awesome. And that's what brought me to Denver. Well, you guys accomplished at least 2 great things. You gave birth to both of my sons at St. Joe's, so I have a couple of positive feelings. Hopefully you've secured their data appropriately.
Absolutely. I haven't done my audit on that yet. Before we dive into the security stuff though, you know, I love to learn a little bit about the personal side, and I know you're a coach, so talk about your background coaching wrestling. Yeah, so wrestling is something that I did in high school. That was one of the sports that I, that I enjoyed.
And when we came out here to Colorado, there's my son, his name's Brett, and he was, uh, just got out of kindergarten, so he was first grade. He, we were looking for just different activities to get him involved in, and there's a, there's a youth program in where we live down in Parker, Colorado with Chaparral High School, which is a Chaparral youth program, the Wolverine Youth Wrestling, and we got into— got him into that, and he's excelled. He really enjoys it. I actually got involved then in coaching the last few years as one of the assistant coaches, as well as being on their board of directors for their program. And so we look to— we have 150, right at 150 50 kids in the program from beginning all the way through our advanced team.
And our advanced team, we travel around and, and go to different team tournaments. In fact, we just came back from University of Nebraska Kearney in Kearney, Nebraska for a big team tournament and going up against programs in Omaha, Nebraska through Iowa, Oklahoma, Wyoming, Kansas, Colorado. We went out there and went 4-1. Wow, congratulations. Won 4, and so it was a great tournament for us.
Kids will be going out to Phoenix, Arizona here in a few weeks to compete again. So they have a, you know, they're a good program, and they have a lot to be proud of. And what ages are involved in the program? We go from 6 years old basically all the way up through 8th grade until they start high school. School.
And so, uh, basically hand them off to a high school team. The goal is that we'll hand them off to Chaparral High School and, and they'll be able to, uh, continue a winning tradition there. That's fantastic. So, you know, since this is an audio podcast, we shouldn't wrestle each other right now, but, but give me, give me like 2 or 3 tips for, you know, if I'm gonna go into my first wrestling match, uh, so I, so I don't get beat as quickly. What do you got to do so you don't get beat as quickly.
Yeah, I assume I'm going to lose because I'm wrestling someone who knows how to wrestle. Okay, well, I would say the first thing is, is, uh, you'll, uh, you want to circle. So you don't want to just stand flat-footed face to face to face. So you want to circle. As soon as you get their leg in a position that is a forward position for you, you, uh, what we call change levels, which is you lower your stance.
You'll want to shoot in on that stance and, uh, get the leg and grab their leg, grab the leg. So single leg and, you know, and look to, uh, take them down to the mat. And then if you just don't want to lose, just, just lay on top of them and get called for stalling.
So, uh, that would be the— that's what we would teach our, uh, our first-year wrestlers is circle, stance in motion, lower your level, shot, and then once you're on top, get your 2 points for takedown and then we'll work moves from there. Awesome, sounds good. And how far did you wrestle? Uh, I came from a very small town in Kansas. My dad was actually in the Navy, so I spent time in Navy bases, um, so, uh, in California, so Oakland, California, San Francisco, which I know, uh, that's near and dear to your heart, and Alameda Air Base, and in Key West, Florida.
And when we moved back to a little town called Parsons, which is where my parents were both from, there isn't a whole lot of sports opportunities in a town of 10,000 in southeast Kansas. So I didn't get to wrestle actually until high school. I played baseball. That was the sport that I grew up loving and playing. And I actually went out for wrestling because I was too short for basketball.
So that's, that's how I got into it. Actually enjoyed it and, and went you know, through high school. And it's not too late to start in high school. It's not too late. I mean, I'll tell you, in Colorado though, there's a lot of youth, really, really strong youth wrestling programs.
Yeah. So chances are hard. It's probably harder here in Colorado than it was for me back in Kansas because it was, uh, it— there just wasn't the, the opportunities in youth. But, uh, no, you can get out there and get after it and, yeah, and, uh, and learn. It seems like in Colorado, kids, or maybe more accurately, kids' parents are much more serious about their sports, and kids are not partially into anything, are they?
No, not at all. But the thing is, I know a lot of kids specialize at young ages, and actually we encourage kids to do multiple sports, develop muscle memory in a lot of different ways. Wrestling is a great sport from multiple, multiple reasons. First of all, it's a great team sport to be with your teammates and help your team, but also, you know, it's just you and the other guy across from you one-on-one. Once you hit that line, you know, put your toe on the line, it's just you against him.
And so, you know, they learn a lot about— it's a tough sport, physically demanding, wears you out fast, and you'll always find somebody that can can beat you on any day. And so they have to learn how to deal with adversity. Yeah. And losing as well. So yeah, losing is such a good thing for everyone in life.
Absolutely. Yeah. And then, you know, you can't let it beat you twice because you got another match in the next round. So you got to get right back on it. Yeah, good.
I like that. Don't let it beat you twice. Yeah. All right, well, why don't we talk a little bit about the security side of things? Um, so how did you— you know, you just told a little bit about your background moving around You know, where did you end up going to high school and/or college?
Yeah, so I went— I graduated from Labette County High School, which is in Altamont, Kansas. Yeah. So actually, where's Altamont? Altamont is very, very southeast corner of the state. Where Parsons is at is about 30 miles from the Missouri border and 30 miles from the Oklahoma border.
So the closest town that we could go and actually have much to do in was Joplin, Missouri. So, okay, about 45 miles from Joplin. I'm just pulling up a map here because I don't, I don't know that part of Kansas at all. There's not much to know. So I was thinking like Wichita, but that's probably quite a— that's quite a ways west.
One of the— it's funny, is there's a Netflix show, I think it was on Netflix, called Kodachrome, and it was a Netflix movie original, I believe. And the, the story is true, and the fact that there was a it was the last place that developed Kodak Kodachrome film, and it was a place called Duane's Photo. And actually, I knew the family because they were well known in town, and their kids went to high school the same time I was in high school. And it's— so if you watch that movie Kodachrome, you'll see a little bit of Parsons, Kansas in it. So that's our one, I guess, one of our claims of What population there?
It was about— well, now it's around 10,000. I was there, it was a little bit higher. My dad was actually a railroad engineer when he got out of the Navy, and so we, we were there for, uh, for the railroad. Gotcha. But the railroad actually— it was Missouri, Kansas, Texas Katy Railroad— got bought by the Union Pacific, and they moved it, uh, out of Parsons.
And that was sort of, that was sort of when the town started— didn't help. It did not help. So, but Aldermont, Kansas is about 9 miles. It's a county high school, and we were, we were 5A back then, so we were actually decent-sized and, and competed, you know, wrestling, right, and tennis. I played tennis there.
So, but, uh, so went to, I went to Labette County High School, graduated there, went to the local community college, which is Labette Community College, and then from there I went to Kansas State University. Go Wildcats. All right. Well, and what did you study? So I was a business finance major.
Yeah. So I was— thought I wanted to be an accountant, like most finance majors were accountants that couldn't hack it. And so went over— my mom works in an accounting office. And so I thought, what I would do and ended up going into, into finance and, but ended up going and joining the police department. So I was actually a police officer.
So you got your business finance degree and then you immediately went to the police academy? I went to the police— yeah, I actually, uh, I actually, well, I actually didn't graduate at that time. I left and went to be a police officer. My wife at the time was in school, and, uh, both of us being in was not very financially viable. So, uh, she, she stayed and was getting her degree, and I to be a police officer, which I was for the Riley County Police Department in Manhattan, Kansas.
Worked there for about 7 years actually, between being a police officer and detective. That's actually how I got into IT. Really?
I'm just surprised that that's a path that's open, right? Most of the way through your degree and you go in and I assume you're just applying, kind of, you know, competing against a bunch of other young men. And I showed up. How's that work? I showed up for 2 positions available.
I applied, there was 2 positions available. I showed up for the first day, which was the physical agility test. Yeah. And there was 357 people there for it. Wow, 357 for 2 positions.
For 2 positions. Yeah. Yeah, I was like, I thought, this is never gonna work. This is not gonna work. So what was the secret?
You know, I think part of it was I think just part of it was, is that as I went through it, I was different. I think it was because I was a little bit different. I was coming from a background of schooling, and, you know, and I'd had a, you know, business background. I'd worked in a bank, and most of the people that were trying out were previous military and such. And I think the other guy that got hired actually was that he was previous military, had just gotten out.
And I think mine was, it was just a little bit different. I did well in the interview processes. I'd love to hear how you feel like that 7 years of law enforcement experience kind of set you up for the rest of your career. Yeah, so a couple of things is one is, I think really if you look at it, whether it's a threat actor, that's somebody you would think about on the streets taking advantage of victimizing people, or a threat actor in cyberspace, somebody who's doing the exact same type of thing. The thought processes are a lot alike.
When you think about people who just want to steal data maybe to monetize it or some other purpose, like I said, there's a lot of the same thought process. It's just a different way in which they go about. So I think that, that gives you— that gave me a really nice insight into how to think about, about getting into security and why it was interesting to me. So that was, that was part of it. A lot of the things that I saw back when I was a homicide detective, back, back during my career, is it was changing back then.
And which computers were— we didn't have the internet like we do today, and we didn't have the— computers weren't the same, they weren't used the same, but it was starting to evolve into that. And so we were starting to see computers being more of a focus of what we needed to take from a search warrant standpoint, but it was before we had digital forensics that we have today. And so it was kind of seeing that evolution and how we gathered evidence, how do we preserve evidence, how do we go about bringing different people to justice who commit crimes, computers became a big part of it. And having that background, I think, played a pretty big role into my wanting to pursue this. And how did the police kind of train you or give you the exposure you needed to gain those skills?
They really didn't. I was helping them define it back then because there wasn't— we didn't have— I mean, the best we had was Symantec Ghost back then. You know, back then, that was about as good as it got, but it wasn't the type of forensic tools that we have today. And honestly, our court systems hadn't caught up to it. I was working with our district attorney on what would a program like this look like.
I was talking with the Kansas Bureau of Investigation and trying to bring all this together. There was, there was some more advanced software that was coming out at the time, which we were able to, to kind of leverage in some different ways. So if you remember back to the BTK Killer back in Wichita, Kansas, the way they caught him is he had, he had, he had put some stuff on a disk, you know, a diskette, and and mailed it to them, they actually had software that was able to see the metadata. Well, that was kind of unheard of. You didn't really know that there was metadata back then.
Remind me, I remember, we don't need to go through his crimes. I remember the story from that level, but remind me what the mailing was. He sent a diskette because he would taunt the police and such, and so he sent a diskette in and when they ran it through this software, they saw the metadata where he wrote it, was back at the church in which he was a deacon. So it showed where the license was attached to. It showed the data of where he actually wrote that disc, and so they were able to solve it in that way.
Those were the kind of things that were just coming out at that time, which kind of led to more of what we see today on how we can gain that type of evidence. That's really what piqued my interest. I went to my chief at the time, uh, and so Alvin Johnson, and said, this is what I think we need to be doing. I've got our DA's, you know, support, and he, he supported as well. And so we started building that program and actually turned it over to Detective Brad Schlurf at the time.
And, uh, so he, he had, he had taken the program on and, and did great things with it. That's great. So, you know, you were there for 7 years. What was the impetus to move on? Well, I had an opportunity.
We were building a new law enforcement center, and we didn't really have an IT department, although we were building this new— what we at that time considered to be this modern law enforcement center. And setting up the infrastructure for IT within that was not going well. It was behind schedule. And so my chief had asked me to step in and kind of program manage that. And, and help bring that in.
And during that, it was to transition 911 services. It was moving— at the time, we had one software program which was called Spillman Data Systems, which is still widely used in law enforcement. And it was all about how do we keep these services up and running during this transition, and how do we, how do we bring this project in on time and on budget. So I was able to do that, and he he offered me the job to come and build the IT department. Are you still a detective at that point then?
I was a detective as well, and I kind of straddled the fence with one foot on the law enforcement side, one foot on the IT side, and then they offered the position to be full-time, and so I went ahead and decided to move on and do that. At that point, did you you still work for the police department or were you looking for the— I worked for the police department at that time and I ran the— I built their IT program and did that for a couple years and then I left and went to the county, Riley County, which is over the emergency services as well and ran and was director of IT for Riley County then at that point. That is not the career path many of us listening are going to go do, right? No, for That's pretty fun and it's pretty cool to have that opportunity. I think it also goes to show that our professions are so new that 20 years ago we were just figuring this stuff out, right?
Absolutely. It's so much different today than what it was when I very first started in IT. Honestly, back then security was— if you had a firewall and antivirus, you were pretty well doing what you could do. You went over to the Director of Technology for Riley County. It looks like you were there for 4 and a half years or so.
Any highlights you want to share from that time? A lot of it was learning how to— who I reported to was actually the elected commission, so it was 3 elected commissioners. I'd go in front of them and the press on a monthly basis and give report-outs on our IT strategy and what we were doing there and how we were delivering services services. At that time, the big push was to move as much as we could from a service perspective online, and so how we were providing services and value to our citizens in different online services. We did a lot of that, as well as how do we automate as much as we could and save costs wherever we could.
It's no different than what we do in healthcare, to be perfectly honest with you. And, and after working, learning to work with elected officials and, and how do you balance IT and, and what, what the elected officials want to get done as well, it was, it was just, I just felt like it was time to, to look at my next, my next journey. Yeah, that's when I looked at how I could get my foot into healthcare. I was interested in getting into healthcare healthcare. Yeah, I see, you know, you went to— was it called Chan?
It was Chan Healthcare. Chan Healthcare. But it looks like you came in as an auditor, so that was a— that's, it's a change, right? Go from hands-on technology to, to really reviewing other folks' stuff. And once again, that's maybe not the most, you know, typical path.
How did you make that change? So I had done auditing work, uh, as well, and so it was, uh, it was like I said, I was interested in getting into healthcare. I ready to get out of government. So I looked at— and actually CHAN reached out to me. There's— they had an opening at SCL back then.
It was Sisters of Charity of Leavenworth in Kansas City. And what does CHAN stand for? CHAN was— at the time it was called CHAN. It was short for Catholic Healthcare Auditors Network. Okay.
It was a joint venture between Ascension Health and CHI. So CHI based here in Denver at the time, and they had started an internal audit department, thought that it would be good to spin it off as its own company, and it focused strictly on Catholic Healthcare internal audit, and that's what I did. So I hired on to Chan, which was based out of St. Louis. I contracted SCL in Kansas City, and my job was to come in and audit their project, the rollout of the first electronic health record. Wow, big project.
It was, and it was not going well. I can imagine, it's a tough one. So that was, that was really what I did. I just, my entire focus was auditing their, their electronic health record project and program and how they're gonna roll that out to all their hospitals. This isn't that long ago, we're talking 2008.
Are you telling me in 2008 that across their network it was all in file folders and paper? That's all they were using? They had some— well, what they were trying to do was get to one single record. So they had some different— like some of their hospitals, absolutely, they were using paper. Some of them were using like a Meditech, an older Meditech system.
But they had no way of sharing the record and having one common health record. And so that was their goal is that there were going to collapse it into, at the time it was the GE Centricity platform, and roll that out to digitize their health record and all their ancillary systems that would tie to it and roll that out across all of their hospitals.
It was tough because it was definitely not mature technology like what we see today. Epic and Cerner are light-years ahead of where we were back in 2008. So you spent, looks like, 3, maybe 4 years as an auditor for Chan and then came on full-time to SEL. Yeah, how'd that happen? I promoted up.
I was actually running the internal audit department on the financial, operational, coding compliance, and IT. And so I had, I think it was 12 internal auditors that reported to me. I did all the board-level reporting. And ensured that we were, you know, doing what the health system needed from a risk perspective. And yes, I actually was looking, we were going through the merger, so we knew that the merger was coming and that we were going to move our offices to Denver.
And I had an opportunity to either, Chan wanted me to move out and continue in my role as the Director of Internal Audit and move to Denver, or I had an opportunity at the time. Eddie Mize was the CISO for Exempla, and so Eddie and I developed a relationship, and he's extremely knowledgeable and a great person, and I had an opportunity to come over and build out the security operations side for Eddie, and so I thought that would be a really nice opportunity to come in and work as his manager. I knew I was moving here one way or another, so I thought it would be a better opportunity. It was good for me to get back into the IT operations side, which is what I was looking to do, and come as a full-time associate, not a contracted associate with SCI. It looks like you were the manager of the security operations function there in 2011, 2012, working for Eddie.
We've actually had Eddie on the show previously. Absolutely love that guy. He's great. It looks like just for a year though. What was the change after a year?
Eddie left. Eddie moved on, and at the time, the CIO, Dave Pecoraro, asked me to take it on as an interim role, and so I did. I absolutely took it on as an interim role, and during that time, I put together what I would consider to be the the next iteration of strategic planning for the health system and where I thought we needed to take the security program going forward, presented that to the executive leadership at the time, and they accepted it and ended up offering me the job. Awesome. That's been, what, like 7, 8 years now?
7, 8 years now. My goodness. It's hard to believe. It goes fast. It's flown by.
Yeah, so then, uh, how many acquisitions have you guys done in the last 7 or 8 years? Well, um, actually, we've— we have— we— our biggest, uh, thing that we've done, honestly, was the merger. And then, as these— you know, as hard as it is to acquire, it's also hard to divest. And so we've gone through a couple divestitures. So one is that we, we used to operate in California, and, uh, we've left— we left California.
And so vesting of the properties in California is a lot of work as well. And then we've— now we're bringing in different, what we consider to be— we call our Community Connect Program, which is where we host for different community hospitals and bring them into our health system. And so we haven't had any, what I'd consider to be, large acquisitions, but we have done different, different build-outs, new hospital like St. Joseph's during that time. We've also built out some, some what our emergency department, we call them community hospitals, which is the kind of the mixture between the— you see a lot of them now. I know like UC Health has quite a few of them around and such, but it's, it's the satellite emergency departments, urgent care type approach, we have those, and we've partnered with others up in Montana as well.
How have you seen the security requirements change over the last 7 years? I think probably the biggest— well, 2 big changes is the first is that compliance is not getting any easier and it's getting more complicated. And so I'd say the, you know, how we, with the Affordable Care Act, which everything then, that's really what started the massive migration to digitization of health records and everything in healthcare. The compliance side of that and how we address that has not gotten any easier. But I think probably the biggest thing that I've seen is probably the velocity of change.
Within healthcare with the Affordable Care Act. It's just everything, it just flipped it on its head. And so all of the changes around digitizing all the health records, everything around it, all of that change, it just flew. And getting security in front of that has not been an easy task. And so everybody in healthcare kind of struggles with with the same thing, and that is it's moving so fast.
How do you keep up? How do you get in front of it? The second thing is I think that I don't know if we felt like maybe we were insulated from some, maybe some of the more advanced threats, but we knew that we were no longer insulated when the Anthem attack happened. And so when that happened— What was that, 2016, 2015? I think it was like 2015 in that area.
You knew at that point you were playing the same game as the financial institutions were and such. I don't know if we were quite prepared at that level to be able to deal with an adversary of that sophistication. Everybody's really been working to mature their programs to be able to meet that type of threat. Now I can tell you that the big one is, just like everybody else's, moving everything to the cloud. How do you deal with this new transformation to the cloud and how do you get in front of all that as well?
I think you talked about the speed of change and how difficult it is. I don't think that's unique to healthcare. I think it's many different organizations, but I'd love to hear your thoughts on how do you get in front of change and what are the tips you use that you've seen some success with? With? Wow, that, that's a— I don't know if, I don't know if I'm, uh, if I'm the expert on ensuring that.
I, I can tell you this, that, um, we, we have a— our organization, and, and what I've seen is that it's, it's very much, uh, forward-thinking, and it wants to, it wants to be very transformational how we go about business. We want to lower costs. We want to bend the cost for our patients, and we're going to do everything we can to get to that point. And so IT is a big role, plays a big role in that. And so they understand, they understand that, and we've been very good at partnering with our program management office, our executive leadership, to ensure that we had a seat at the table to be able to have those conversations up front, to make sure that we could design it in a way that we could be in front of it and So we can allow our organization to take advantage of those types of technologies so we're not a barrier to success, but we're actually a partner in ensuring that we can, you know, give them the technology they need so our physicians can practice medicine the way that they choose.
And so that sounds much easier than what it is. It's actually, you know, it takes a lot because at times security is viewed as a barrier, and we do not want that to happen. That partnership, ensuring that you have a seat at the table, that you're talking with the strategy, you're talking with the infrastructure, you're talking with the program management office, ensuring that you have the right processes and technologies in place upfront to be able to support that move has worked well for me. Yeah, I, I would love to know across your organization, who are the— doctors are challenging. It's like, it's like a— I don't know how many you have, call it 1,000 mini CEOs running around, you know, who you need to, you know, be autonomous and who expect to be able to do what they want to do.
Who are the biggest supporters for you inside the organization? Yeah, well, I would say a couple things. It's number one, that I've worked very hard for on my physician relationships. So actually, my physician leaders are some of my biggest supporters. So whether it's, it's Dr. Vallon or Dr. Dufford, uh, you know, Dr. Lou Capone, our Chief Informatics Officer, they've been very big supporters.
My new CIO, Craig Richardville, he just came here. Actually, he's right at a year. I think it was a year in February last year when he actually started. Came from Atrium Health out in North Carolina, huge supporter. And so, you know, he's very much supportive of me and the program.
And then right down from the top, so Lydia Jumonville, our CEO, Mark Korth, our COO, CFO Janie Wade, they're all big supporters. I do have a reporting relationship to our board audit committee. I get visibility at that level as well.
I have a high level of support at the board level as well. How do you go about building that support? I could say that as a default, the business doesn't think of security as an enabler. That's something that has to be nourished and really built on. How have you done that with those stakeholders?
A lot of it was honestly going out and doing the work. It was meeting, it was talking through their pain points and challenges, working directly with our doctors, having them being part of our program and talking to them about, here's our strategy, here's what we're looking at doing, here's the technologies we're looking to employ, how can we be complementary to your patient, your workflows and not be a barrier. And those are things that have paid off. It really was sitting down and understanding, especially with our doctors, what is your workflow, what is your pain points, and how can we be complementary? Because they are.
They don't want anything that's going to interrupt them. They have a very high level of stress in their working. Anyway, and so what they don't need is something from a technology standpoint that's going to cause them to have some more barrier to them being able to get their work done. I'd like to think we're perfect. We're not, Robb, by any stretch.
We're always learning. We're always looking to improve and how can we simplify what we're doing, how can we look at new technologies to bring in. That can do a better job than what we're doing today. What do you think are going to be the biggest focuses for you throughout 2020? A couple things.
Number one is we are looking to accelerate our move to the cloud. We are absolutely all in. We've definitely hit the beaches and burned the boats, and we are not looking back. That's going to be a big one. For me, a big one, and I'll give Ping Identity the commercial on this one, is that identity is going to be a big one.
How do we transform our identity to not only work with our legacy applications on-prem, but how do we have a strong identity program into the cloud as we move forward? That's going to be a big one. When you think identity, I don't know where your role sits. Do you just think about your workforce or are you also thinking about the patients that you guys serve? Well, it's actually both because our patients do have a touchpoint into our organization through their portal.
We call it MyChart portal, but most healthcare has to have a portal too. We're no different. We have one. We have identity of our patients and how we go about— how do we manage that as well. Awesome.
And I know, I'm sure you hire sometimes. I think I've seen open positions over there. And after this, I'm headed back to beg for more. There you go. So yes.
So what type of roles are you looking to hire? The big— the couple that we have, we just went through a restructuring and reallocation of resources within the team. So it's really, we have a big focus on our identity going forward, a big focus on our governance, risk, and compliance program going forward, and then our security operations. So working in our SOC as well. I just promoted one of my managers to director.
Mitzi McIntyre is director of security operations and identity. Congratulations, Mitzi. Yes, she's awesome. She joined us just a little over— I guess it's right at going to be a year here in a few more months, and she's done outstanding. She's an engineer at heart.
She's been in IT for as long as you and I have been, so she's been a great addition. And so she's bringing some well-needed leadership into those programs, and because of that, I'm looking for a new security operations manager, so somebody who could run the SOC team and really look to take that program forward as well.
Then on the governance, risk, and compliance side, we're always looking for good risk people, people who know compliance, HIPAA, but also we're building out a data governance program across the system, and that's going to be a skill set that we're looking to hopefully look to recruit for. And do you, for those positions, are you looking for folks who've done it before? Are you looking to bring folks up who are new to the field and want to learn? I like both, to be honest with you. I like those who are seasoned and can provide some, you know, can provide some mentorship to those who— but we definitely want to give those who, you know, are looking to break into the field an opportunity that we bring them in more like a level 1 position.
Position and, and allow them to grow. And, uh, so absolutely both sides. We're— I've been, uh, looking at how can we— can maybe forge some, some partnerships with some of our local, uh, higher education as well as high schools to say, you know, how do we, how do we build a pipeline into, into our program? Uh, and what are the skills or personality traits that you'd be looking for in those level 1 folks? Yeah.
Yeah, so for me, I really look, you know, we obviously want skill sets and that's something that helps, but it's also cultural fit. You know, SCL being a not-for-profit healthcare, we're a Catholic identity, so we have some specific skills, you know, the culture there, we have to make sure it's a good fit. For the most part, we have good luck with a lot of different, wide range of people. The skill sets we really like, you don't have to be an expert in TCP/IP. You don't have to be an expert in threat hunting or anything like that.
If you have the ability to learn, if you really, in my opinion, have the curiosity to keep digging for the answer. Those are the things that, that I really like to see. And then if you have the education or the, or the demonstrated experience, or, you know, that, that, that is, that's outstanding. We look for them. How does a candidate demonstrate that curiosity and ability to learn?
Well, a lot of it— well, that's a, that's a good question. That from the last person we just brought on, Jack Pray was the name, came from the state of Colorado. He came over and joined us as a Level 2 for our— he— it just, it comes out when you look at what he had worked on in the past and, and how, how he had approached his work. And, and he, you know, it's, it's one of those things we, we look for as far as demonstrate what projects have you been on, what— how did you, how did you progress in your career, what, you know, dig into a little bit about if you have this type of issue, what, you know, what would you— what steps would you take to solve it? And, and, uh, and it's always that next question of, and then what?
And then what? And then what? Then— and look for, look for that type of, uh, of progression. It's, uh, it's, uh, not an easy thing to, to find, as you know. Skill sets out there are in high demand.
So I, I— it— we all say the same thing, you know, someone who's hungry, wants to learn, and And I've heard feedback from folks who don't know exactly how to show those things. That's why I'm drilling into it a little bit. I think it's a great question, and it's not one that's an easy answer. I think it's almost like when you have that person in front of you that you can just see and feel that passion that they have, and they can demonstrate that they always wanted to be, you know, they wanted to be on different projects, and they have that demonstrated success. Those are the kind of things that that you're looking for.
Yeah, I think one of the ways that I've— one of the things that's always super encouraging to me is if they've contributed to open source projects or they've been available in the community. If you volunteered with SecureSet to help run capture the flag events or just— there's so many different ways, but if I ask the question, what have you been doing, you should be able to list off 2 or 3 things, right? And it doesn't matter all that much what they are as long as you're able to— when I ask 7 or 8 follow-up questions, you're you're engaged and you're listening and interested. I wanted to circle back on something you talked about, how you didn't finish your bachelor's degree, but I think you did go back to school. Absolutely.
Maybe you could close the loop on that. Yeah, yeah, it was— I did go back and finish it up, and so that was after my wife had graduated and got time because I was working. I actually, when I went back, I actually was a detective at the time. I left being an investigator because of the fact that it didn't work into the schedule. I went back and worked midnight patrol.
Oh wow. So I worked midnight patrol and then went to class during the day. Holy smokes. And then tried to fit time in with the family. And so it was, uh, it was, uh, you know, that time, but it was well worth it.
And actually, I'm, I'm working through my MBA through University of Northern Colorado. As we speak. Awesome. So I'm not quite a year away from that one. So that's great.
Looking forward to doing that. That's more of just a personal goal for— yeah, mine. I did my MBA about 5 years ago, and that going back to school, you know, after 20 years of professional experience is such a better— such a better experience for me than it was to go through as a young person who didn't know what was going on and was just trying to get through school. Absolutely. I really, really appreciated that.
I do too, but the problem is that it's been such a long time since I've had to think in that way. It took me a little bit of adjustment to get back into— Probably add 5 years to your life because now all of a sudden you've engaged your brain again like you're young. Yeah, and I would agree with that. It's really kind of like— the way I would say it is I feel like just completely engaged in a different way. It's not just tech all the time.
It's forced me to kind of think differently. I've really enjoyed it so far. That's great. Any final stuff that you wanted to talk about that I didn't get us into? No.
You're a San Francisco Giants fan. I'm a Kansas City Royals fan. We were talking baseball, so we went straight back to the cellar after the 2015 World Series win. We spent some time in the cellar the last few years too. But I'm still, I'm still on cloud nine from 2014.
I am from '15. I still think we should have sent Gordon from third. Yeah, tied it. If we could have tied it, I think we, we had a shot. But, uh, um, I don't know, are the Giants going to do any good this year?
I don't think so.
I'm pretty sure the Royals aren't. So yeah, um, no, I, I've— I think last thoughts are, first of all, is that thank you for having me on the podcast. Absolutely. Uh, this is another amazing podcast, and I've learned a lot from people who've been on it and blazed the trail before me on this. I think the thing I would say is that from a security perspective, it just doesn't seem to stop changing.
The way we deliver things, the way that data is being being used, all the new ways we're going to use data going forward in healthcare, you know, whether it's, you know, through giant datasets from, you know, from like your DNA profile that's going to follow you or whatever. It's just, it's not going to slow down. It's going to continue to accelerate. The way, where we store it's going to continue to move to the cloud. The processing the, the people who need access, everything about it is, is not slowing down.
And I think those challenges going forward are just going to continue to grow. And I, I cannot— I can't imagine in 10 years from now what it will be like. It's, it's going to be, it's going to be a lot of fun. Yeah, I love it. I'm like super excited about the idea of individualized medicine, you know, being able to create a medicine that's genetically right for Howard or Robb versus for everybody.
And it's It's coming fast. I mean, you're already seeing it in cancer treatments. So you will have a more personalized medical treatment based on your DNA profile at some point in the not too distant future. Put on the adversary hat, and if I can create individualized medicine for us, can I also create individualized poison for us? Right, definitely.
Or something negative, and how do we think about those things? All of that is in think about how you're going to push it out to different wearables and how do you ensure that non-repudiation of the data coming back in to ensure that the data is actually, you know, trustworthy, trustworthy to be able to make life and death situation decisions on. So that's awesome. How much fun is that? It doesn't get much more fun than this, right?
Yeah, important for sure. All right, Howard, well, thanks a lot for making it down here. We appreciate it. We'll talk to you soon. And for all those listening, have a great week.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember. Colorado equals security.