All episodes

Dan Eppich, CIO at The Anschutz Corporation

Apple Podcasts Spotify SoundCloud

Dan Eppich, CIO (and former CISO) at The Anschutz Corporation is our feature guest this week. News from: Newmont, Pax8, Richey May, Lares, Coalfire, LogRhythm, Red Canary, Automox, Intelisecure and a lot more!

If you’ve got too much money - slot machines got you covered

Slot machines are going online. Newmont is rolling out autonomous vehicles. Pax8 is hiring a lot of people. Richey May, Lares, Coalfire, LogRhythm, Automox and Intelisecure have news this week.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9609 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 153 for the week of February 24th, 2020. Alex, I guess it's RSA week.

It is RSA week. If you are listening to this, you must be in San Francisco. And hopefully you haven't shaken any hands or kissed any strangers or whatever the things are that people do that give them the coronavirus. Please make sure to stock up on your surgical masks so that you can make sure not to cough on anybody or have anyone cough on you for that matter. So Alex, I heard that both AT&T and Verizon have dropped out of going to RSA conference this week.

You know, Robb, I heard that as well. I'm kind of sad. Do you know what the reason was? No, I don't know. They're known carriers.

Wah wah. Was that— I stole that from Gene Spafford. Yeah. Good one. Yeah.

Good one, Spaff. I like that. Hey, let's talk about some housekeeping stuff. We have a Slack channel. We've got 1,300 people, and you may well have heard that joke on the Slack channel if you've been there.

That's true. If you want to join, you should go to colorado-security.com and find the Slack channel button. Get in there and we'll be happy to talk to you in the Slack channel. We also have a mailing list. If you go to the bottom of the website, colorado-security.com, Put in your email address and hit submit.

It will be added to the mailing list for you to get the show notes in your email every week. We'd love it if you'd rate us and subscribe on your favorite podcast listening application, and maybe go tell a friend, uh, go, go reach out to someone who might be interested in the show and help them get there. That's how we find good new listeners. When you tell them, you can also tell them that it costs us money to produce Colorado Equal Security, and if they want to help contribute to that, they can join our Patreon campaign. Again, check out the website for the link to Patreon.

If you sign up there, you can get wonderful, wonderful gifts as part of your Patreon subscription. We're also looking for volunteers. If you're interested in helping out with the podcast in other ways, we'd love it if you'd help do some interviews for the show. Alex and I try and do interviews. We've had a couple other folks who've helped us do interviews for it.

We do have one this week. Looking forward to that. But, you know, the future is uncertain. So if you're interested in getting involved, we'd love that. We also had a new patron this week, but you know, I didn't get approval to say who it is yet.

He didn't reply back and say, yes, throw my name out there. So we'll have to wait till next week to talk about it. I'm sure he'd be happy with us giving his name, but we'll just, we'll wait anyway, just to be safe. You know, privacy first. We are, we are a privacy-centric group of people here.

That is very true. All right, let's jump into the news. This week, we have a story about slot machines online. Alex, what in the world is this doing in our pod, in our feed? You know, this is sort of a cyber-physical story, Robb.

The, the internet of gambling. So we have a story here where there are actual slot machines, but they are connected to the internet. You can play them through an app, but when you're playing them, you're actually playing a physical machine that lives in a physical casino. So can I do that here in Colorado? Not yet, Robb.

Maybe one day. I can't wait for that. So this is a Denver Post story, which is kind of how it got into our purview. And, you know, you and I are both massive gamblers who've lost many a fortune this way. So I think it appealed to both of us.

I am dead broke, Robb. I have a gambling problem. Please sign up for the Patreon, people. So this is actually through the Hard Rock Casino in Atlantic City. I think, I mean, obviously it's just gimmicky, but, you know, their thought is if someone is a little reticent to do online gambling, maybe if they know that this is linked to an actual physical machine, maybe it will help them get over that hump.

Yeah, and I can't wait till we see the first story about the hackers figuring out how to make as much money as possible off of this. Yeah, that will be interesting to see how that works. I'd love for, for someone to, to see how the security is of those slot machines. But to be clear, you will go to prison if you're, if you're here in Colorado and you do this. That is true.

We expect that the people who will do this will probably be from some other country and where law enforcement is a little bit less rigorous. Speaking of the Internet of Things, Robb, A Colorado mining giant is spending $150 million to roll out autonomous vehicles in 2021. Now, there may be more than one Colorado mining giant, but I can only think of one. I can only think of one. Newmont Mining.

It— you know, I've known Newmont for quite a while. They're actually really close to, to my house. But I didn't really realize that what they mined mostly was gold. They're the biggest gold miner in the world. Yeah.

Interesting, right? Yes, they are. It was like 900 million pounds of gold in 2018. Yeah, I think it's interesting, this story. They are deploying autonomous dump trucks as part of one of their mines in Australia.

And well, for a couple reasons. One, this is a pilot project for them to see how it's going to work. But also, they will be able to gain that much more efficiency through these autonomous dump trucks that it is going to extend the life of the mine and make it more profitable and allow them to continue working there. So this $150 million is to pay for 2 dozen. So 24 Caterpillar trucks.

So obviously these are very expensive dump trucks, not your, not your Tonka trucks that I have never paid $2 million for a dump truck. Robb, the first— this is going to be the first use of autonomous haulers. And then here's the interesting part. It's the first use at an open-pit gold mine. Yeah, I'm sure the closed-pit gold mines maybe use them.

Yeah. The open-pit underground iron mines. I don't know, somewhere else. Coal mines? Probably coal mines too.

Could be. Yeah. Anyway, this is the first time for, for Newmont to do it. And of course, I know you and I are both thinking, well, what about the drivers? What are we doing to them?

So the Newmont is planning to train all of these drivers to be, to do maintenance for these new trucks. So they're, they're not gonna lose any jobs. They're just gonna move into new jobs that are created by this. Yeah. It is interesting.

You know, this is an, an area they're talking about productivity and it's it's just, it's dump trucks, right? You wouldn't think there would be that much of a productivity gain, but just the amount of, you know, variability in someone driving, you know, people having to work in shifts, using the restroom, other things like that. Having an autonomous dump truck really does make it that much more productive so they can continue to work there. Yeah, pretty cool stuff. So next story, this is interesting.

I, I'll read the headline and we'll go from there. So homegrown tech company confirms Colorado expansion with 1,800 new jobs, 1,800 new jobs. When I read 1,800 new jobs, I think, oh, you're talking about someone like Amazon or Facebook, right? So this is Pax8. Pax8 currently has 450 employees.

In 2017, Pax8 had 50 employees. That's a bit of a growth curve there. And you're thinking, well, what is Pax8 that does this? They resell cloud services to enterprises basically to help you get online. So it's not like they're like adding on cheap you know, call center people or something like that.

These are $100,000+ a year jobs, and they have just blown up in the last few years. And they're planning over the next 3 to 5 years to add— what, that'd be like another, you know, 400% growth. Yeah, that's pretty incredible. Um, excited for them. Um, you know, I'm not sure that I would have thought that this would have been that big of a growth market, um, or that if it will continue to be that growth market.

Maybe at one point people will just decide, hey, I can buy cloud services on my own, I don't need a middleman. Um, but, but who knows? But congratulations for them. Um, this is talking about some of the incentives that they are going to receive as part of this. Um, they applied for more than $18.9 million in incentives as part of the Colorado EDC.

So pretty cool. Uh, one of the other things that I thought was cool about those incentives, they are one of the first people to use incentives that are not just based in the Denver metro area. So some of those incentives are for them to hire people in rural areas that can do remote work. Interesting. Did you, did you see where rurally?

I don't think— on the spot here. I don't think that they said specifically, but it was aimed at rural areas. Pretty cool. All right. Congrats to PAX8.

And of course, congrats to Colorado for keeping those jobs. It looks like we were actually competing for that expansion with some other locations. Next, we have a story from Richie May. Richie May is a, a really mortgage insurance focused professional services organization. Is that roughly right to you?

Uh, auditing, insurance, uh, financial services. But really focused on mortgage industry. Um, and they have a story here about the OCIE and some new, um, updated guidance that they provided around cybersecurity. So first of all, I'm going to say I didn't know who the OCIE was. I had to do some Googling on that first.

Is that one you're familiar with? Well, Robb, who is the OCIE? So I don't remember the acronym, but they are the, uh, They are the auditing testing arm of the SEC. So the SEC gives them guidance for how to go out and look at companies and how to enforce regulatory stuff across those companies. It is the Office of Compliance Inspections and Examinations.

There you go. So I did, as I was, as I was looking about across this, I'm like, well, if they do all kinds of different inspections, you know, you know, where does this fall on their priority list? So I found some guidance from middle of January of this year where the SEC provided what are their objectives for 2020? What should they go after? And cybersecurity was actually number 2 on their list of priorities.

Pretty cool. Uh, and as part of the article, uh, Reggie May lays out some of the areas that the OCIE talked about that are priorities for them. Um, I don't think that there's anything shocking in here. This is, uh, you know, pretty standard stuff that you might expect, uh, things from having senior-level engagement, uh, protecting your data, training, um, understanding and managing your assets. All good things.

But they do specifically talk about multifactor, which is, I think, the only really technical requirement on the list. Yeah. Uh, but it's pretty cool to see that, um, that government inspectors are caring about cybersecurity and are, are giving good recommendations for things that people should do. Yeah. Pretty good stuff.

Congratulations to, uh, to that whole industry for getting a little bit better at security. That's right. Uh, next we have an announcement from Lariz. Um, they are a penetration testing, uh, services company here based here in Denver. Um, they are beginning their global expansion, although in the article it says continuing.

I'm not sure that if they have any other offices or not, but, uh, they have opened an office in Canada called Lariz Canada. Yeah, so we've, we've had Chris Nickerson, who is the founder and CEO of Lariz, on the podcast in the past. Um, this is pretty huge. You know, I, I think of Lariz as being a pretty regional business as they're looking to expand and hiring some pretty big name folks. I think the guy who they hired came from Symantec, right?

I think originally he also had, I think, his own firm for a while. But yeah, pretty cool. So, so pretty good expansion. It's good to see them having success. And I love to see good guys, you know, continue to move up and to the right.

Yeah. Congrats to them. Next story we have is about the NIST Privacy Framework. And this is written by Coalfire. So I know, Alex, you know really well the, the NIST Cybersecurity Framework.

And, and recently NIST came out with a NIST Privacy Framework that's kind of complementary to it. Whereas in the NIST Cybersecurity Framework, you know, we go with identify, detect, protect, uh, respond, and recover. Hey, good job. And then for privacy, we go— their functions are identify, govern, control, communicate, and protect. So similar type of a concept where they do those functions and then they have categories underneath it.

With subcategories and then mappings over to reference documents. They do the same basic structure really with more of a focus on privacy. Yeah. So if you are familiar with the Cybersecurity Framework, this will look very familiar to you, obviously with slightly different concepts. Uh, pretty cool there.

The article talks about that as well as Coalfire's opinion on the privacy framework. So check that out if you are interested in the NIST Privacy Framework. Uh, next, LogRhythm was named a leader in the 2020 Gartner Magic Quadrant for SIEM. 8th consecutive time. Pretty cool.

Congratulations to them. I know, we know the Magic Quadrant is, is very heavily used by companies who just want to figure out, okay, who's in this space and who should I talk to as I'm looking into a new space? They stayed up there, you know, not a lot of surprises, um, in, in that regard. But I'll say actually I was surprised by some people who were in the Leaders Quadrant, um, other than the normals. You know, you'd always expect to see IBM and Splunk and LogRhythm up there, maybe expect to see RSA, but Rapid7 has made their way up into the Leaders Quadrant and frankly pretty well into the leader quadrant too.

Yeah, they made a pretty big push with one of their products here over the last couple years, so yeah, it seems to be paying off for them. Um, and Exabeam is also up there, and you know, last time I looked at Exabeam, I thought they weren't quite there. They were really focused much more on EUBA, and, um, now then, you know, they've, they've definitely got themselves up into that area. Um, Securonix is the last one who we haven't mentioned yet, and I don't know them real well personally. Also, um, you know, RSA says Dell Technologies— they have to change that since RSA is getting sold from Dell.

Yeah. Has that officially happened or it's going to happen? I think it's announced. I think it was happening. Happening.

I'm not sure that it's closed yet. Yeah. Good stuff. It's also surprising McAfee now is all the way down in the niche players market. They were, they were a strong leader for, for years.

Yeah. Their Envision product. It does not shock me, but I agree. At one point they were up there in the upper right with everybody else. Cool.

Next we have a blog post from Red Canary talking about The Third Amigo Detecting Ryuk Ransomware. Who are the other 2 amigos? The other 2 amigos, Robb. Emotet and TrickBot. I wasn't trying to trickbot you.

Oh, that's the only thing I happen to remember about the article, though. So this again is one of the pretty in-depth technical articles that Red Canary does. There's a little tongue-in-cheek, a little fun had here with some terminology referencing back to the Three Amigos. So if you are a fan of Three Amigos, you should read the article just for that. But if you— the word plethora does make the blog plethora.

But if you would, if you'd like to learn more about Ryuk and what it does, good in-depth article on that as well. And if you don't know the movie The Three Amigos, I recommend you watch that before you read the blog post. It's a great movie. I don't know that I've ever watched that with my kids. Probably about time to do that.

Probably about time. Next, we have a blog post by InteliSecure, The State of Data Protection. Future-proof your information security technology investments. Uh, Alex, what this is about is, is roughly that, you know, instead of choosing a technology and building a program around it, it's really talking about building your, your processes, building your program, and then finding the technology that fits in there so that, you know, when the technology you procure either gets, you know, gets bought out and closed off or whatever, you, you know, you're not Um, you're not stuck in a situation where there's no one else who can help you solve that problem. For sure.

Great advice, Robb. And I think some of this stems from the fact that, uh, Symantec, which has a, you know, pretty traditionally strong DLP product, which you might use for this function, uh, was sold to, uh, Broadcom. And that I think has people a little bit worried. Yeah. So, 'cause everyone expected Symantec was just too big to, to go away and, and, and it, you know, they're not gonna go away, but they're, you know, things are gonna change and they're, they're no longer a pri— or a freestanding company.

We're talking about government intervention here, Robb. Too big to fail. Too big to fail. Yeah, I love it. Uh, we do have a final blog post this week by Automox, and it is about the difference between patch management and vulnerability management.

Aren't those the same thing, Alex? You know, Robb, I thought the exact same thing. Uh, no, uh, good article here by Automox just giving you some basics around patch management versus vulnerability management. Um, obviously patch management is a little bit more narrow, talking about just applying patches to potentially fix some vulnerabilities. Vulnerability management being a little, a little larger, the lifecycle around identification, fixing, managing all of those vulnerabilities, including things that may not be fixed by patching.

So, you know, just a little bit broader there, and they go into some detail there about what the differences are. And Automox, of course, does automated patch management. I'm shocked. I suspect that they don't do automated vulnerability management though, because that is something that I don't think you can automate. Uh, that's, that's true.

Not completely, at least not today. All right, let's go ahead and move over to the Slack message of the week. Big thanks to Andre Gaeta who sponsors this for us every week and helps kick in $25 towards one item from the Colorado Equal Security store. As a reminder, we have a new logo, so everything in the store is brand new. Yeah, I guarantee you don't have one.

So go out and buy one. So this week's winner is Gene McGowan. Congratulations, Gene. He posted a link to It Doesn't Have to Be Crazy at Work. It started a good conversation.

This is a book and a good conversation about how to make your work environment better. Appreciate Gene helping bring that topic in. And of course, Gene gets to pick one item from the store. Gene is also the president of ISSA Denver and a big volunteer helping out in the community, so we appreciate his volunteer work as well. Yeah, thanks for that, Gene, and we look forward to seeing that item that you get from the Colorado Equal Security Store.

So let's go on and move to events. First event, if you're listening to this, you don't have much time, but ISSA Denver on the 24th is doing a Privacy by Design workshop. This, I believe, was a limited audience, sort of invite only, but you could still check to see if there's any spaces left. Next, you know, and frankly, if it snows, it's snowing now. If it continues snowing, maybe someone's going to not show up.

True story. Just like hang out in front with a will stand here for a spot sign and see if anyone lets you in. Yeah. All right. You should.

On the 26th, I, I, ISC2 Pikes Peak down in the Springs is doing their February chapter meeting. On the 27th, we have a busy day. Swimlane has one of their Soar with Swimlane events at Highland Tappenberger. Salesforce. This is actually an event at RSA but aimed at Colorado Equal Security community members.

They are doing a tour of the Ohana floor, which I guess is in one of the— or the Salesforce buildings there. And finally, if you are still in town, SecureSet is doing Using Vault to Better Protect Your Secrets with Bryce Verdier. I think if you don't know anything about Vault, it's worth learning. This is a technology that's Gonna gonna be more and more common. Derbycom, which is some of the folks who were involved with Derbycon, has their February meeting on the 28th.

Also on the 28th, DC 303 is doing a meeting. So two interesting groups same night. I don't I don't know how you pick between these two meetings. Very tough. In Colorado Springs on the 28th through March 1st, they are doing their Cyberspace Game Jam.

Love it. On the 3rd, CTA is doing Tech Day at the Capitol. This is their big event where they try and get in front of. They don't try to. They succeed.

Successfully get in front of legislators and, and really show that there is a strong Colorado technology contingent in town and help advocate for what we need. On the 4th, SecureSet is doing a capture the flag for all levels. On the 5th, we've got a couple of events. Splunk is doing the First Thursdays at Topgolf, and SnowFROC 2020 is happening. That is the full-day OWASP conference.

I think you should make it there if you can. And then ISSA Colorado Springs is starting their Security+ exam prep seminar on the 7th. This is the first of 3 sessions to get ready for the Security+ exam. We'll keep talking about this one, but we won't talk about the following ones because if you don't go to the first, you're probably not gonna go to the second and third. Uh, moving over to jobs, we have a few jobs at Ping open.

I'm hiring an information— a senior information security analyst, a product security engineer, and a GRC analyst focused on BCP and IR. These kind of spread the across my different teams. If you're interested in being a really technical-focused person, we have a spot for that. If you're AppSec, we have a spot for that. If you're more GRC and programmatic, we've got a spot for that.

So look forward to hearing from folks who are interested in one of those roles. Western Union is looking for an information security governance lead. Optiv is hiring a principal incident management consultant. NREL is looking for a cybersecurity analyst. Janus Henderson is hiring an IT operations risk and business continuity manager.

Guild Education is looking for a Threat and Vulnerability Manager. IHS Markit is hiring an Operational Assurance and Compliance Associate Director. And Zoom is looking for a Senior Security Analyst focused on threat hunting. Fantastic. Alex, that is it for the news, but we do have an interview this week.

We do. And, and I think you sat down with a friend of ours, Dan Eppich. Is that right? I did. I talked to Dan about his experience history, talking about building a security program and then moving more into a more IT role.

He is now the CIO at the Anschutz Corporation. So he just lost a letter. He did lose a letter. He lost a letter. I was going to make a joke, but I can't think of a good joke.

Does he, does he now not care at all about security? Of course. That's exactly how it should be. Immediately dropped all that responsibility. Doesn't care anymore.

Yeah. All right. Well, that's it for this week. We'll look forward to catching up with you guys next week. And if you're in San Francisco, Maybe come by and say hello to Alex and I. I think we'll both be out there at least for part of the week.

Yeah, there's an RSA channel on the Slack workspace, so get in there. And if you're in San Francisco, let people know where you're at if you want to get together. All right. We'll talk to you guys again next week. Thanks, Robb.

This is Michael Stephen, Privacy Security Officer for Connect for Health Colorado. Welcome to Colorado Equals Security for Colorado security professionals by Colorado Welcome to Colorado Equal Security. This is Alex Wood here with our feature interview for the week. I have a very special guest with me today. Welcome, Dan Eppich.

Hi, Dan. Hey, Alex. How's it going? Appreciate you being here. I appreciate you being here.

Some mutual appreciation here. Apparently. Dan, You are maybe the first interview you've had by request. So we can throw— I'll get back at him later. We can throw Brian under the bus for this.

But we're going to be talking about an interesting perspective today, a security person who made the transition to sort of general IT leadership. But before we get there, I know you, but I don't know that other people know you. So why don't you give a little background of yourself? Sure, Alex. I think the first thing I'll tell you is I don't come down through a standard infrastructure lineage as most of the CISOs that I've met and gotten to know.

My origin comes down through development. I was a software developer and then I reached a point where I was implementing ERPs. I came to the Anschutz Corporation in 2000 to consolidate— at that time I think it was 60 entities— into a single ERP solution. So I quickly became the software manager for all of the software at the Anschutz Corp, and what led me into security is in doing that correctly you have to develop a tremendous amount of relationships at an enterprise level because you're one of the only business units effectively that can only succeed if you have those relationships as opposed to just being focused on your particular party per se. Fast forward all the way up until, was it 2013, 2014?

2014 where a few events occurred here that led them to come to me and say, hey, will you go out there and figure out where we stand? You know, it began with PCI and sort of grew from there. Yeah.

So obviously fire hose training begins, understanding and always being as humble to realize that what I know and what I don't know. I tried to roll in as many skill sets like you have that I could to support the project, and then I basically facilitated the relationship management and making sure we were coordinating around everything else. So at that point, it was, it was sort of already a leadership position in the sense that I was finding the skill sets to help me get the work done, but just understanding what the outcome needed to be and that it needed to be relative to us as a private company. Right. Yeah.

Yeah. And it's a really interesting story. But before we get to that, let's go back even farther. I believe that you are one of the few people I know that is actually a Colorado native. Ah, you want to talk about something that has nothing to do with this?

That's right. So, so you were born here? Yeah, I was. I am a generation 4 Native. Do you have one of the license plates with a horse and buggy on it?

I do, but I have— if you want to look, the red and yellow ones are the cheap and cheesy ones because you don't have to prove it. There were 2 years where you actually had to prove a century of residency before they would give you the plates. And so I hold those in my dear hands. The irony is that stopped because the organization that the state was paying to do that defrauded them from a whole bunch of money. So they closed.

So now you can't buy red plates anymore. Oh, well. Oh, well. So, so you grew up here. Have you always lived in Colorado or have you spent time other places?

I, I spent 2 years in Moscow, Idaho. The home of University of Idaho, 7 miles from WSU. I finished and graduated and basically made a lifestyle change. I got a recruiter phone call. I was in work doing a job and somebody said, I'm looking for somebody who knows horses and knows computers.

The guy had been looking for like a year, so he essentially hired me sight unseen. You were able to go up there that day in that life and buy 20 acres, brand new house. It was like $100,000. So my wife and I got married. She got her nursing degree.

We packed up the U-Haul and off to North Idaho we went. It was a blast of a 10— of 2 years. But then had our first child and my wife's trying to get home. Yeah. And is she from here also?

She's actually from North Dakota. Oh, so, okay. Um, the, the story really was there. Um, we're trying to get home. It's $400 a month when you live in a place where there's no people that you just aren't going to find, right?

And so I came down here and got like a 40% raise, so back into the city I came. Nice. Yeah, the joke is my ancestors, when everybody was on the big mining push and headed into the mountains, and my ancestors looked at the mountains and went, here's good. I don't need to mess with that. This is fine.

That's right. We've gone far enough. That's right. So, uh, so that is interesting though. So you— it sounds like you have some, um, I don't know if ranching is the right word, but some, some farm ranch experience.

If they— somebody hired you to do, uh, work with horses and Yes. Yep. Yep. So some farming. I don't know if I want to call it ranching.

In the, in the, in that world, they call it fat farming. You buy, you buy, you buy calves and then you, you fatten them up to eatable weight. Right. And then you sell them off and then you grow the food for them. So that is sort of how I got through my college years just up in Fort Collins.

Yeah. Cool. Go Rams. Go Rams. So you, you eventually came back to Colorado.

At some point during that time, you ended up here at Anschutz. How long have you been here now? It is 20 years minus 2. So I, I call it a sabbatical where I left here and went and sold enterprise software and services for an Oracle partner. Okay.

It was— wow, that's grueling. Whole new respect for the people that do the grind of what is selling. So you got to have a knack for that. I'm not— I don't think I'd do well in that world. It's a lot of work.

But for some people, that's great to do. Yeah, it fits personality. You got to be really competitive, I think. And The beautiful thing is the former CFO here met with me and, you know, we had a couple of quick conversations and they asked for me back and they didn't know I would have begged for my job back at that time. So back I came.

Sweet. So I obviously know a little bit now about Anschutz, but prior to coming here— full disclosure. But prior to coming here, I didn't know a whole lot. And I imagine most people don't know a lot. When I took the job here, most everybody said, oh, are you going to be working at Aurora at the medical center?

Yeah. And I said, no, that is not it. So, so how would you describe Anschutz Corporation? So the Anschutz Corporation, I guess the closest thing you can say is we're a private equity company.

In that sense, but private equity from one man. It's one man's money. We all work for one guy protecting one man's share in his name. The good news is he's an incredible guy. He's incredibly philanthropic.

He's a great guy to work for. He cares a lot about his employees. It's what makes it easy to stay. Um, the other thing is he gets involved and invests in his expressed interests, sometimes not necessarily that they're going to make a fortune, right? You know, when he was developing the MLS, we were here and we owned all the teams at one point in time, and just watching that develop, right, into what it's become— he's a builder, man.

That's That's what he does. Yeah. And it definitely seems like you mentioned MLS. Definitely seems like sports is one of those passions. Lots of, lots of sports teams with logos around here.

Yes, lots of sports teams. You know, there's movies. There are some rumors that, you know, he's trying to watch TV with his grandkids. And, you know, he says, I cannot find anything that I can watch in front of my grandkids. And his wife said, why don't you do something about it?

Their birth swelled in media over time. Pretty cool. You mentioned a little bit previously about the start of the security program here.

It sounds like similar to what happens at many places, people don't care about security until they care about security. Something bad happens and people say, oh, we should probably pay attention to this. Maybe just talk a little bit about the birth of the security program here and your role in that and how that got started. It was kind of iterative. We started off, I think, really when PCI DSS kind of moved into their aggressive role in where they were pushing for some very specific requirements and they had some brand new requirements, 3.0, I think.

They essentially asked me, they said, can you go out and see how we're doing? I kind of started in a sublet down that line. We were kind of working through some ideas, exploring some different ways that we could do it across this entire enterprise and do it in a right-sized sort of way. And then Sony happened, and that was a, that was a tough hit, the Sony breach, for anyone in private equity, for anyone in holding, especially if you're doing that within the entertainment vertical. So they said, will you expand that a little bit and tell us how we're sitting from an entire security perspective?

So that really broadened the scope. So then it was, you know, I spent some time looking for a resource that wouldn't take me down the standardized assessment road because, you know, we had 100+ venues, we had multiple hospitality companies, we had farms and ranches. We had— so it needed to be something we could do fast, but something we could sort of do effectively. And So we started doing some sample, some core sampling, a couple of small entities, a couple of medium size, a hotel, to just sort of get a breadth of where we stood with those samples. And I brought to them a fairly blood-red document, which ironically, that was when I found out that 2 of my 5 board members were colorblind.

So all of my reports had to change after that. Yeah, but yeah, they were like, wow, that's really eye-opening. But it still wasn't enough at that point. I was still working in my role as the enterprise apps manager at that point. And then we had a very unfortunate incident that costs us enough money that Phil became clearly aware of it, and that was the moment where I ended up in an office and they said, we need you to find somebody to replace you.

Why don't you promote somebody and then we're going to put you into a new position.

I truly believe that at that point it was an insurance decision. I think you and I have talked about that. It's, do we lower our deductible and pay a whole bunch more money or do we hire somebody try and do this right. So that was 2016, 2017. Sounds like a reasonable choice.

Yeah, I'm happy with them. I think, was it last year, we were one of the first, one of the only insurance writers with cyber that actually went down a little and not went up. That is good. Yeah, that is good. So you got into it gradually, but, you know, once you got put in charge of, you know, creating a full security program, what was the first thing that you did?

How did you start? I was building a team. It was really— it was trying to find people that could grasp the uniquenesses of this business, find people that could think outside of the box. And sort of build a program, build some ideas, how you could make quick progress, how you could do it across a geographic decentralized structure that we have, and something that was kind of right-sized for a private company. If I'd have gone overboard, it wouldn't have gone well with us or the entities.

If I hadn't done enough, then we still would have had problems. Really, I think it was just all about trying to build the team and finding the knowledge sets that I knew I needed.

I guess fast forward a couple years, you were doing security for, I guess, full-time just about 4 years, a little under 4 years maybe, 3 plus, something like that? It was 4 years. I think by then. What were some big lessons that you learned throughout that process?

I would say relationships are everything in both the positive and the negative. You know, if people trust that you're looking out for their best interests, they're going to be willing to tell you things that they're struggling with. But at the same time, it's the whole trust and verify thing. We were still corporate, so there was an element of you got to continue poking so that you can truly understand where the problems are. You can't always assume that everybody believes you're out to help them all the time.

It's unfortunate because when you're in this space or even in the technology space, I don't know whether it's the amount of salespeople that are coming at you all the time or just a standard relationship between subsidiary and corporates, but you're constantly having to maintain those relationships so that they truly do realize that you're looking out for their best interest because you're telling them to spend money where they've never ever spent money before. Right. I would imagine in some cases it's it's pride or ego or other things like that too. You know, hey, we've been doing just fine, you know, without your help previously. Why are you coming in and telling me to do something different than I've done before?

Never had to do this. You're telling me that I'm not good at my job? That's right. Come on, Dan, get out of here. I don't want to do this.

Yeah, I think the second one was, and this has taken some time because you grow up in a technology field, you grow up with the acronyms, you grow up with the personalities, you grow up with, you know, typically we all aspire to our pragmatic execution-based personalities. When you sit in front of boards that are building companies, they live in risk, but they don't take it apart like that, like we know how to. So being able to translate what you're doing and what you're trying to accomplish into a business risk-based discussion is so much more important than understanding and trying to make them understand what tool you're getting to do what.

That linear line between, am I secure or not secure, and everything in between, it's how do you communicate and partner with them to determine where sufficient is for their businesses. That was hard. Yeah, and I mean, that's a hard thing for everybody, not just in the uniqueness that's here, but I've seen that everywhere. It is very hard for folks that are in technology to understand the concepts of how this relates to business risk, and executives at those companies trying to understand how you know, what you're saying from a technological perspective really is a risk or not. I know that there's a wide variety of different business entities here, some of them large, some of them small.

Did they get on board with the risk approach, or was that something that you had to really push for as well? There were different variants of of acceptance. I think they were all there because I had the backing of the name behind me. Where sort of the resistance kind of came in is, I think you nailed it, is it's like, this isn't something I've ever had to do, which is kind of why we started with a very objective approach around 45 controls. We're going to do these and then we'll move to something because It sort of became an easy, understood, auditable, here's a beginning, here's a middle, and here's an end to just sort of get us to a point.

Then our goal was while we were doing that, iterating the business reason, iterating here's the risk we're mitigating, here's what it's doing, here's what we're accomplishing with the business, here's how This is the new world. It isn't going to be just you, especially because in private industry, people are still picking this stuff up because they haven't been forced to yet.

Being able to explain to these guys that their competitors will also be having to fight these same battles at the same time. I think the summary of all of this is it really didn't have as much to do with security as it had to do with building those relationships. Yeah. So that, you know, you could explain well why you're doing what you're doing. Yeah, for sure.

Relationships make everything happen. Yep. So to my benefit, at the end of last year, you decided to move into a different role here at Anschutz. Maybe give folks a little bit of background on, on that and what, what you're doing now. Sure.

Well, I was upstairs in executive risk. Upstairs is where our board of directors is, and of course Alex is.

We were having a meeting and he, being our chief operation officer, said, I want you people to stay. He acknowledged that our current IT director was retiring and he said, We wanted to know if you had any interest at all in doing that work, because we've watched what you've done in the security space, and we wondered if it's something that you could do more broadly. The answer really was, I would, but not in the same role. I wanted to be able to continue with the enterprise touch and continue with the relationships.

This role was changed from an IT director's role to a CIO role. And so my goal here is, you know, was to get you up to speed and get you everything you need in order to get going, which, by the way, Alex didn't need much. He just hit the ground running. And then to do some discovery around the existing IT department and what we need to do to make sure that stayed in the support level that everyone's used to. Then last phase would be finally starting to get back out into the enterprise and see where I can find some economies of scale or some standardization so that we can create better value for the company as a whole.

Your background is a bit different than many people in security.

My premise of this being a a big shift in your career. It's maybe not as big a shift as it might be for someone that spent much of their career in security. For you, it's a little bit back to your roots.

What have you seen in your transition back from focusing on enterprise risk and security back into a more strictly IT function? I think what I've seen and personally what it's done for me is every decision should be a risk-based decision. Until you get an opportunity to be a security person and live that world exclusively, I find now coming back into this world that there's a lot of choices that the risk-based piece of that decision isn't ever taken into account. And it seems so— stand to reason now after my years up there, but there's a lot of people that just don't think that way. And I don't think it's anyone's fault.

I think it's just because you've never had to historically. And now with the way the new world is, you sort of have to think that way. Yeah, I mean, it's a great mindset, right? It doesn't have to be security risk or compliance risk or those sorts of things, but everything is a trade-off. There's some sort of risk in your decision-making.

If you're deciding to roll out a new ERP or enable Office 365 or something like that, You only have a finite amount of resources, so you're going to have to figure out which is more beneficial. Some people might say ROI or something like that, but really there's— you're talking about the risks and which one is going to bring down those risks the best. Absolutely. I think the only other thing I would say is spending that time on the security side is— been to a few of Robb's wonderful security dinners, and at the same time everybody talks about because of the shortage of resources, how we're a negative in security resources. Be willing to go out to people that have not necessarily been up the infrastructure road.

Be willing to do that. At the same time, you start talking to them about their open reqs and they're requiring a CISSP, they're requiring infrastructure and the ability to manage a firewall. I think what I'm saying is you'll find future leaders out there or people that at least can think right. It's the question of what's the easier thing to teach. Yeah, I would much rather take someone that can think well, that has a great aptitude for learning and a great attitude versus someone that has the best experience but doesn't have those good things, isn't interested in learning something new, isn't— is stuck in their ways in terms of their opinions.

You can take anybody that has a good brain and can make them a good security person, make them a good IT person, make them a good whatever if they're willing to put in the work. Completely agree. Now that you have been in the CIO role I don't know, a couple of months-ish, we'll say, plus a little bit of transition time prior to that. What, what are your plans? What are you doing to get up to speed in that role?

And what sort of things do you have coming, coming forward? Well, I fully complement, you know, there's a lot of writings, Gartner being one of them, and others around. There's a very specific program around a 100-day program of taking over a leadership role. And, you know, been going through a lot of stakeholder interviews trying to get some feedback around, you know, what's working for these business units and leaders, what hasn't been working, what do they aspire to, what are some things that they see and want and desire. Then obviously Obviously the discovery piece around who your staff is and what are their strengths.

Then finally, where does the work come from? It's been real interesting trying to figure out all the different directions that work comes from here and who's doing that work and is there governance around it. The goal is to get through that 100-day with that discovery, make a presentation to the board about here's what I've found, here's what I see, and here's kind of where I'm planning to go. If they're all on board, then I walk out of there with some direction for a charter and at least a 1 to 3 year strategy. I think 3 years in technology is kind of a stretch, but yeah, it's always tough to see what's going to happen in 3 years.

So, but, uh, But, you know, some aspirational goals. You can always try. You can always try. That's right. I hope that's the question you were— No, yeah, that's great.

And for me, I think that the 100-day thing has always been interesting to me because you have the great benefit of not having to leave the organization. So you don't have to figure out all the organizational stuff as part of that 100-day transition. If you're someone new coming into an organization, and especially a complex organization, and someone is expecting you to understand the complete picture of the business, plus, you know, do your stakeholder interviews and, you know, figure out how good your staff is and, you know, where the holes are and so on and so forth, 100 days is pretty fast. It is fast. I had— and I'm sure even for you being here, 100 days is going to be fast.

I had a boss, one of my— one of the best bosses I ever had, and his philosophy was don't make any changes for 6 months. Move into something new. Obviously, if something's on fire or, you know, there are decisions that have to be made, but, you know, don't upend anything or make any big changes until 6 months. That it really, in his mind, takes that long before you have enough knowledge to make an accurate assessment and make good decisions about making changes. I think I would agree with that.

I mean, because, you know, you go through the 100 days, that's really kind of to just get your quick start and say, right, how do I get my feet, my footing right? Right. From there, it's a constant discovery process and a little bit of a maintenance. And I would argue that you've got to do some brand building in that 6 months. Sure.

Find a couple of quick wins where it's really— where it helps out the staff, where it helps out the leaders. I think if you don't do that, you're at risk on the other side. But, you know, I think the goal, like you said, in that 100 days is to find some people that you can hook up to that can give you the fire hose training out of one place instead of trying to pick it up everywhere and say, where's somewhere that I can start to get this 30% a week until I have this whole thing where I can continue to reverberate and reiterate what I think I know to assure that I'm in the right place and I'm headed the right way. I can also see from the analyst perspective, Gartner and whoever else puts these things out, first 100 days. Well, but if they put out, here's your 6-month plan, people would be like, 6 months?

What if you'll be out of work by then? Are these people just gonna sit around for— so I get that they're, you know, yeah, that they're trying to do a baseline skeleton kind of thing for you to get off the ground. I think it's less about the 100 days and more about— and it's a round number. Yeah, it's, it's more about what outcomes are you shooting for? What are some things you want to remember to achieve?

What are some things you want to remember to discover? How do you make determinations who your actual stakeholders are? Because sometimes they're not always sitting in a leadership role. For sure.

You mentioned a couple of things that you've seen coming from security over to general IT. What are, what are a couple of other things that if someone else wanted to make this transition that you would say are important for them to consider?

That's a good question, Alex. I think understand, again, we've hit this ad nauseam, but it's all about the people, not the technology. Recognize that it's what you can do for your partners. I walked into this saying, all right, I see the other business unit leaders as partners and peers as opposed to— I think technology has always laid ourselves down as we're a service organization, and intrinsically we are. That's never going to go away.

But I think you walk into a position like this coming out of security and saying, I'm here to partner with you. And be a peer and help you in the innovation. How can we move forward? How can we leverage technology and try and create efficiencies in your staff or increase your revenue points? You know, if you can walk in and saying, this is how I plan to align with you guys, it positions you better than just saying we're going to be a a McDonald's service organization where somebody pulls up in a drive-thru and says, I need this, and then they drive up and expect you to give it to them.

Yeah, that's a great— it's a rut that gets hard to get out of. For sure. For sure. Well, we are getting close to time. Anything that you wanted to talk about that we haven't hit on yet?

No, I guess I can just, you know, take this last few moments and say Alex has been one of the most incredible lucky hires that I have ever had. I don't want to say lucky. I can, I could probably throw one man under the bus to say right at the end of the conversation he says, you know, there's one other guy that you might want to talk to. Well, I will just let everybody know that I did not set up Dan to kiss my butt as part of this interview, but thank you. I appreciate the the kudos.

So, yeah, well, awesome. Thanks, Dan. Excited for you and your transition. We can check back at some time in the future, see how things are going. Sure.

But, but great conversation and appreciate it again. Yeah. And this Colorado Security is— it's been one of the most amazing pieces of what I use to sort of help me in the transition that I was in. I mean, it's, it's an incredibly active community. The people are phenomenal.

And I just, I don't know how to thank you because, you know, what you guys do helps people like me that are coming into the field. So awesome. Thanks to everybody for being as friendly as to the new guy that was walking in as you could be. So thanks, guys. That's what we love to hear.

Yep. Thanks, Dan. Yep. This has been Colorado Equals Security, and we will talk to you next week.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes