Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is a newscast for episode 157 for the week of March 23rd, 2020. Alex, what have you been doing in your social isolation?
What do you mean, Robb? Nothing's going on. Everything's normal. Everything's normal. Well, I know that while we're trying to make things as normal as possible, and this is the new normal, I think we've both been working from home for the last week, right?
We have. And that has been— I mean, it's fine for me. I worked at home for 10 years. No big deal. It has been, I think, less fine for some people that I know who are not used to or have a harder time doing those sorts of things.
And you're looking, you're literally looking right at me and you're figuratively looking right at me. Yeah. It's been, it's been a challenge for me getting used to working from the house, working from the basement. Yeah. It's a little, it's a little restrictive.
Uh, it is. Well, and it's one thing when you are working from home and you have the ability to go do things, but when those freedoms are taken away from you for one reason or another, I mean, you know, you, it's usually house arrest, but you know, in this case it's, it's COVID-19. So Um, you know, it makes it a little harder. Yeah. So the first, the first half of the week, uh, call it like Sunday, Monday, Tuesday, Wednesday, it was pretty good.
Like every day I was getting out and I was going for a run or going for a bike ride and, you know, getting good exercise and feeling like I was part of the world. And then Wednesday night, Thursday, the snow came in and all of a sudden, uh, there was not, not so much freedom anymore. Yeah, it has been interesting. So this week my kids are in school in Jeffco. And this— they were in school this week, even though not physically at school.
So they did remote learning. So I got to do things like PE with my kids. So I have a weight set in the garage. And so I was lifting with one of my sons, which was nice. That's pretty fun.
You know what? I will say it's been a benefit not having the ability to go to restaurants because, you know, I tend to do that, you know, especially working downtown. So, you know, helps for the waistline a little bit, not, not eating the junk food and having to think about the things that you eat because there's only so much food in your house. Yeah. Yeah.
You gotta make it last. Uh, I, I'll tell you, you know, that some of the thoughts we think a lot about social distancing right now, especially with my kids. And, uh, I've, I've been reading a book as one might do when one is sitting in their house a lot. And, and in the book, these people like ran up to each other and hugged them. I'm like, whoa, whoa, whoa, stop it.
Why are you writing about this? Like, oh wait, wait, this wasn't written in 2020. Ban this book. It's taboo. All right, well, let's go ahead and move over to our, uh, our housekeeping.
We do have a Slack channel and I'd say our Slack channel is as vibrant as it's ever been, probably more so. Yeah, it's really been great this week seeing all the conversations happening in there. We did, if you were interested, start a COVID-19 channel to try and get all of that talk in one place instead of having— try and socially isolate the social media, isolate the— yes, exactly. But there have been a lot of good discussions going on there, whether it's people talking about how to best work from home or, you know, just news that's going on. It's been a lot of great discussion there.
We do have a mailing list. So if you go to the website, colorado-security.com, you can sign up for the mailing list. You'll get show notes in the mail. Yeah, yeah. So you can also get access to Slack message or the Slack channel on the website.
We also would love it if you would rate us and subscribe. This is a great time to use the podcast for folks to get connected with the community since they're not going to do a lot of connecting in person. So if you want to tell folks how to how to get a hold of the podcast, we would love it. And of course, rate us on the podcast app and subscribe so it's in your inbox every week. I know it is tough financial times right now for some people, but.
If you do value our community and have a little extra change, we would love for you to support us on Patreon and help us, you know, cover the costs that we have here at Colorado Digital Security. I also flip it around and say, if you've, if you've been impacted by the shutdowns and any layoffs as a part of this, reach out to us. We'll see if we can connect you with folks who might be able to help you find a job. Right now, you know, things are a little weird, but, you know, obviously there's a lot of folks out there who need talent, and I'm sure we can help you get connected if you're impacted here. Yeah, I will say that, you know, we do have a jobs channel on the Slack workspace and there's even been a lot of chatter in there this week, people that are still looking to hire even though it is not normal.
Yeah. Next, we also, we look for people to help us do interviews for the show. I wanted to say a huge thanks to those folks who have stepped up recently and done some interviews for us. John Hubbard and Jason Jaques have really come through with quite a few interviews. We're going to have those running here soon.
Alex and I have had a pretty hard and fast rule that we only do interviews in person over the last 3 years. I think that might change over the next couple months. I have a feeling it'll change, at least for the short term. Yeah, it's, you know, one of the bummers about doing things remotely is you don't get that person-to-person connection. One of the positives is you don't get coronavirus from them.
So it's possible we'll be looking at changing. And if you're interested in getting involved in doing remote interviews, reach out, maybe we can make that work. Awesome. So let's jump into the news. First, the Denver firm Intertek Medical is making key components of a rapid coronavirus test.
Yeah, this is pretty cool. So Intertek Medical is the sister company to Intertek Plastics. They're making the plastic components for 3 different COVID-19 tests. The first test has already received FDA approval on March 12th, and 2 more are expected to come soon. Yeah, pretty cool.
So they're not making the components that actually do the sort of testing itself, but just the components that store the reagents and take the samples and that sort of thing. So pretty cool that that's happening here in Colorado. Yeah. And I thought that one thing that stood out to me was that the test that they're creating, instead of like the normal test, which basically takes a day to get the results, this is about 45 minutes to come back with results. Yeah, that was pretty cool too.
All right. Next one, another company that's helping solve things. And of course, I think there's one thing we can agree about, it's that distilleries are out for the common good. Is that right? I think that that is common wisdom there, Robb.
Yeah, there's a story this week about several distilleries, and I'm sure that there are more since this story came out that are using their abilities instead of making alcohol to drink, but making alcohol to put on your hands. So this story specifically dives in mostly about Spirit Hound, which is up there in the— I think it's Longmont area near Boulder. They, they got glycerin and hydrogen peroxide, and they use the WHO, the World Health Organization's recipe, to make 48 gallons of of hand sanitizer that they've been giving away to the community. Yeah. And a lot of that they've donated to like the local fire and rescue group and other things like that.
So pretty cool. They got some, some containers donated from a local store that makes Green Goo. Green Goo. Thanks. Green Goo that, you know, makes other sort of hand products and things like that.
So pretty cool to see that that's happening as well. Yeah. This, this is interesting to me because it's the legality of this whole thing is a little bit murky, as the story puts it. These dealers are— anyone who's a distillery is regulated by the ATF, right? Alcohol, Tobacco, and Firearms Agency for the federal government.
And it's not really clear that they're allowed to make hand sanitizer. So they're working with Colorado legislators and politicians to figure out how to navigate this. So number one, they can help give back. And number two, you know, for their own financial livelihood, this is not a good time to be to be a distiller, there's just not a lot of ways to sell things and their sales are probably gonna plummet. If they can make hand sanitizer, which is in high demand and, you know, they can't keep it on the shelves at stores, that would probably help them make it through these tough times.
I think there are probably some tax consequences there too, Robb. I think for, you know, however much alcohol they actually distill, I think they have to, you know, pay taxes per gallon or, you know, whatever it is. So if they're just making this and giving it away, they would still probably owe some sort of tax bill Theoretically, based on that. So hopefully that gets resolved as well. Good for those guys.
Appreciate them giving back to the community. Next, a global fintech company needed more than 280,000 square feet of office space here in Denver to expand their office. So number one, I was— my first question is, okay, where are they getting that big a space? Because there's not that many of them. Right.
And it's the old First Data office on Quebec, just north of Arapahoe Road. I think AECOM is the other organization that's in there right now. And the company is called ComputerShare, not CompuShare. Not CompuShare. I assume that this is a distant cousin of— probably.
Who knows? But they have over 1,000 employees in Denver, 1,250 employees here in the Denver area. And that's shocking to me since I don't know them. Yeah, I was not really familiar with them as well. The name sounds, you know, vaguely familiar, but I really didn't know much about them.
This was not their first office in, in the US. They had a couple of their spaces here. I believe they were— they're from Australia originally. That's where they're based. Sounds right.
But yeah, I mean, it sounds like Denver is gonna be by far their biggest office in the US, and they're combining 2 other offices. They had one in Highlands Ranch and one in— right, was it Greenwood Village? I can't remember that. Yeah, sounds right. And they were trying to find a spot that was conveniently located.
Anyway, super conveniently located for me. That's very close to my house over by the Kaiser Building and stuff. Anyway, good for those guys, and it's exciting to see that space be used by another tech company. Yeah, maybe they'll be as big as First Data here. Next, we have the results.
We actually have 2 rounds worth of results for the March— or the, excuse me, the Colorado Inno Tech Madness. So this is that kind of tournament showing off the tech startups here in Colorado and having them face off against each other. We talked about it maybe a month ago. And we've had 2 rounds of results that we can give, we can give here. Yeah, so we are now into the, the Elite 8, Robb.
So Um, we have several, uh, companies that we know that have been involved in this. Uh, CyberGRX, uh, Stackhawk, um, Conga. Conga. Yeah. Uh, lots of, uh, what's the Sphero?
Sphero's on the list. Sphero, JumpCloud. Yeah. You know, lots of, uh, local tech companies that were involved. Um, both, uh, Stackhawk and CyberGRX made it to the Sweet 16, but Sadly, only Stackhawk made it into the Elite Eight.
Stackhawk still alive and flying through the bracket, as it were. They do have a matchup against Conga here in the Elite Eight, though, so that's going to be a tough one for them to make the Final Four. Definitely. And it's also been a pretty good week for Stackhawk, which I think we will talk about up here shortly. I do want to— before we move on, though, the voting is open right now for this.
So if folks want to go out and vote to see Stackhawk make the Final Four, get out there, click the link in our show notes and vote for StackHawk so we can continue cawing for them in the following weeks. If you do vote for them, when you click the button to submit the vote, you have to make the sound. So it's a requirement. I think that's obvious. Next, Mindspark Learning and Girls Who Code partnered to make computer science more accessible to girls across the US.
So I didn't— I knew the name Mindspark Learning, but I don't think I knew a lot about them. So it was nice to read this article to figure out, you know, they're a Denver-based national nonprofit. They work with different educational folks to, to give them resources, especially around technology and education for young folks. They have announced that they're gonna work with Girls Who Code to bring free computer science resources to 3rd to 5th graders and also 6th to 12th graders. Yeah, pretty cool.
So going into this, I was gonna read the story and I was assuming that there was gonna be something that was gonna be available directly to people based out of, out of this, but they— this is stuff that is aimed at schools. So you could potentially reach out to your school and make sure that they know about it so that they could utilize the materials. Absolutely. There were a couple of interesting stats in here. The Bureau of Labor Statistics estimates that computing occupations make about 67% of new jobs in the STEM fields.
Girls Who Code found that less than a quarter of computing jobs are held by women. What was most shocking to me is that they expect that this number is going to be going down over the next 7 years. Huh. From 25% down to 22%. That is crazy.
So this is a trend we obviously want to reverse. And I think you do have to go back to those 8-year-olds, the, you know, 3rd graders and older to start giving them that familiarity and comfort with working with computers. For sure. That's definitely a good thing. Next.
So you alluded to this. Denver startup StackHawk lands $2.5 million funding for their app security product. Go ahead, Alex. Caw caw!
So yeah, so congrats again to Stackhawk. I think this is probably good timing for them getting some funding right before we are going into the, the new world that we are going into. The corona recession. Yes. So congrats to them to getting a new round of funding right before I would imagine that funding is gonna start to dry up.
So that's good. So this round was co-led by Custa Noa Ventures and the Foundry Group. Foundry Group is, of course, a local VC here in town. They also had Flybridge Capital and Matchstick Ventures part of it. This brings their total fundraising up to $4.6 million, and that's only since last July.
So they've definitely been able to— been lucky getting a lot of it. Not lucky. They've been successful getting money to fund their venture. They're currently at 11 employees and they expect to get up to 15 by the end of the year. Yeah, they also noted in the article that they, right now, that they are in sort of their alpha stage.
And if you wanna participate with them, you can, but they expect to have a beta product out before the end of the summer. Is that what it was? Not too long anyway. So pretty cool there. Next, Red Canary released their 2020 Threat Detection Report, and there are some interesting findings in it.
Yeah, so they're talking about really that these, the trend, the biggest trend is around worms and seeing TrickBot as maybe the most popular or the most, notable, uh, worm moving through and, and how that has been impacting and causing significant impacts to the customers of Red Canary. Tricky, tricky, tricky. Yeah, so worms, worms are the, the, the key, the key word here, right? I do think it's cool how they do their threat report, how they link everything back to the ATT&CK, uh, matrix, MITRE's ATT&CK matrix. So you can see, oh hey, these are the techniques that, um, that attackers were using.
So, you know, potentially you can see the areas where you might need to improve based on where attackers are actually attacking. It doesn't do a lot of good to know what the malware is with— if it doesn't help you inform what kind of defenses you put in place and, and really what practices, where are you going to be focusing and looking. I think you could use this report to, to figure out where your own security operations are lacking and hopefully get better before the bad guys get in there. Definitely. Next, we have a webinar by Ping Identity this week.
So this, this is in here because I was one of the people on the webinar. I did a webinar with Richard Byrd, who's a colleague over there, just talking about What has it looked like so far as we've made the very rapid shift from working in the office to working from home and what we've heard from our customers? You know, at Ping, we're high-tech and it wasn't a big technical shift for us to move remote, but we've heard from a lot of customers where it has been a lot more difficult. So we called out some of the stuff that they've learned and we've learned and what you might want to be considering as you make that shift to work from home. Nice.
I look forward to listening to it, Robb. Uh, finally, the, uh, there was a Coalfire blog this week. This is, uh, going back to one of those, the great Coalfire technical blogs talking about the basics of exploit development, uh, looking at SEH overflows or structured exception handlers. Yeah. So this is, this has been around for a long time, um, uh, as a win— as a 32-bit Windows application vulnerability.
Um, however, even though it's an old vulnerability, it actually is something that is, uh, is still showing up in the wild today and is useful for folks to learn. I think that if you're someone who's just looking to get more into the details of malware, looking to get more into red teaming, this would be a great resource for you. Yeah, definitely check it out. Love it. I love it when the local companies come up with this highly technical content that you just, you just don't find it everywhere.
Exactly. Thanks to ColdFire for that. All right. So that is our news for the week. Let's jump over to the Slack message of the week.
We had a million options this week, Alex. Literally a million. There are lots and lots of messages that were out there. Big thanks to Andre Gaeta. Andre has been a huge supporter of the show.
We appreciate him funding the Slack Message of the Week himself and giving $25 gift credit toward anyone who gets that message. They can, they can use it out of the Colorado EcoSecurity store, right? Any of our swag. Exactly. And Robb, who was our winner for this week?
Chris C. I don't know what the C stands for. Maybe it's Chris Chris. But Chris C shared a link this, this week that Cambridge University has released all of their digital textbooks for free. That's amazing. Wow.
If you want to be edumacated, then you can go check out those textbooks. And over the last week, I've also seen a whole bunch of universities releasing courses for free. And all I can think is at this point, if you are not receiving the highest grade education in the world, it's just because you're not trying to, right? It's, it's available out there. Find the time, go do it.
All of this content is free. It's amazing. Really cool stuff. But Robb, I'm so busy. Where am I going to find the time to do all this stuff?
Thank God you can't leave your house, right? Oh yeah. That's right. Anyway, so congratulations to Chris. I will hook you up with Andre and you can, you can pick one item from the Colorado Equal Security store.
Awesome. So we're going to diverge a little bit right now from our normal, normally scheduled pieces and we're going to skip events. We will remind you we have a calendar of events that you probably shouldn't look at because it's probably wrong. I would say probably just about everything on there is canceled. I know, for example, the ISSA Denver chapter is looking at for ways to do their chapter meetings remotely.
I don't know if there's any details there yet. And I would imagine that other groups are trying to do similar things. So if there's something on the calendar that looks interesting to you, you may want to just go check it out on the website anyway, to see if they have made accommodations to do it remotely. You know, speaking of cancellations, you know, most of the little events are canceled. I can say that the, the RIMS annual conference.
So that's the RISC— I don't remember what RISC stands for, but it's the risk managers, uh, group that gets together and they do enterprise risk management. They were going to do their big annual conference in Denver the first week of May. That has been canceled. We expect, you know, you're going to continue seeing those things, um, at least for the short term, canceled, virtual, whatever it is. Yeah.
All right, so skipping over events, um, let's go ahead and talk about jobs. Yeah, as we mentioned, there are still people hiring. Um, so first, IHS Markit is looking for an operational assurance and compliance associate director. Pretty cool. It's a big mouthful.
AppDynamics, which is a Cisco company, is looking to hire a compliance manager. That's here in Colorado. Oh, really? Empower Retirement is looking for a manager of technology security. Ball Corp is hiring a cybersecurity operations lead.
NREL is looking for a cybersecurity SecOps practitioner slash analyst. Marathon Petroleum is hiring an OT. That's an— oh, holy smokes. Operational technology instead of information technology. Operational technology cybersecurity professional.
I bet that would be a cool job. Spectrum is looking for a principal security engineer. You know, Bank of America is looking for a cybersecurity operations level 1 analyst. So, Robb, did you pick the jobs this week just on how long the, the job title? The longer the title, the more time that takes up.
It's good stuff. Pulte Financial Services is looking for a junior information security specialist. Pretty awesome. They, I know they just hired a new CISO recently. Yep.
And, and I guess this is Curtis's first hire. Yeah. Congrats. Uh, Pulte is a great place. Both Alex and I have worked there.
I think you'd like working there if you got the chance. It's a good company. Uh, finally, DaVita is hiring a corporate counsel for privacy and cybersecurity. Ooh, that sounds exciting as well. So, uh, Robb, I, I think that's it for the moment.
That's a wrap. That's it. Uh, we do have, but we do have an interview. We do. So we have an interview with Brad Judy.
Brad is an information security officer over at the University of Colorado. He sat down with with John Hubbard, and we're going to get to learn all about his background. Awesome. I'd also like to say, you know, while Robb and I are actually recording this in person, we are not touching, and we are keeping a safe distance from each other. Yeah, we are.
We are at least six feet away. Yes. All right. Well, that's it. Thanks, everybody.
We look forward to talking to you soon, and if don't be a stranger, reach out on the Slack channel. All right. Thanks, Robb. This is Robert Wood, VP Security at Alps Fund Services. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Hey, Colorado Equals Security, this is John Hubbard. I'm sitting down with Brad Judy. Brad is the Information Security Officer for the System Administration Division at University of Colorado. Brad, how's it going? It's going great, thank you for having me, John.
Sure, happy to have you here. Can you hear me all right? Are your ears ringing a little bit from the concert you went to last night? Fortunately, they're not. I'm trying to be pretty good about protecting my hearing when I go out.
Do you wear earplugs when you go to concerts? When I remember them, which is like 50% of the time. Okay, all right. Yeah, I do. I love to go out and see live music, local music around just lots of different venues.
Where were you last night and who'd you see? So last night I went up to Fort Collins. First time I've gone up there to Washington's, which is a really cool venue. Yeah, they recently redid it. Yeah, it's really nice.
Okay. And so it was Kiltrove, which is a Denver area band, and then Sun Little and the Seratones. It was part of Colorado Sound. They were doing an anniversary concert thing. Okay, what kind of music?
So it's a little bit of a mix. I mean, so Kiltrove calls themselves Zapata Gaze or something like that. It's kind of a pretty low-key type of music, but then it kind of goes through. I mean, Sun Little's just a guy and his guitar singing, great voice. Then Serotones is really high energy, you know, full band, and it's, you know, some bluesy rock stuff, and they were a lot of fun.
But it was cool to see that venue for the first time. Have you ever been to FOCO MX, the Fort Collins Music Experience? No, I haven't. I think that's every April if they're still doing it. So check that out if you like going to support bands.
Yeah, I've not been up there. I've been mostly doing the Denver stuff. Okay. Done 3 years in a row to the Underground Music Showcase. I don't know if you've ever done that.
No. They take over South Broadway for 3 days and it's like 15 venues for 3 days straight, 250 artists. It's crazy. Is it outdoor? There's 2 or 3 outdoor venues, but mostly it's the bars and stuff that are normally venues down there do it, and then some restaurants and other places will host as well.
It changes a little bit year to year. It's a lot of stuff. What about Boulder's music scene, like the Fox, Boulder Theater? Yeah, Fox, Boulder Theater, done concerts at both of those, which are cool venues, and also done those on CU campus at Mackey Auditorium and Mary Ripon Theater. Yeah, I've been to a show at the Mackey Auditorium.
That was a really pretty venue. Yeah, it's a really nice kind of historic venue there. And then I love the Denver scene, the Colfax Strip and the South Broadway Strip and stuff. Any memorable concerts that jump out to you in recent years? Are you really glad you were there, really glad you were able to attend?
There have been a lot of good ones. A couple years ago, I went and saw Brick and Mortar and Unlikely Candidates down at the Bluebird. I dig Brick and Mortar. It's a fun band to see there. They just have a fun time and they're just doing random costume changes.
It's just like 3 guys just having a lot of fun on stage. That can be infectious in a good way. It can be. There's just a lot of cool small venues. It's also neat going to someplace like Lost Lake, which is right nearby, which is maybe 100 people fit in there.
Okay. So it's just kind of fun to go to those really small places too. Yeah, so it sounds like you're not going to the Red Rocks and the Pepsi Center shows necessarily. I've been— I've certainly been to Red Rock shows. It's a cool venue to do, and so, you know, you get the right name, it's good to go out there.
I've actually never been to a concert at the Pepsi Center. Really? Yeah. Okay. I've been once or twice.
I saw the Black Keys there. Nice. And yeah, they were really high energy, but the sound was not great. I think Pepsi Center is just not meant to be a great concert venue, so you may not be missing out much if you've never been. You go there for sporting events, but yeah, maybe not pay $200 for a concert ticket.
Yeah, that's another thing too. It's a little pricier. Small venues, you see some local bands, and you know, it's a very affordable way to have some fun. Right, right. Well, is that something you did when you were growing up?
Did you grow up here in Colorado? Did you grow up elsewhere in the country? Well, I've lived in Colorado for more than half my life. I kind of grew up all over the place. We moved around a lot when I was a kid, so I've been in Montana, South Dakota, Michigan, Idaho, Washington, Ohio.
Okay. Colorado. All within the US? Yeah, I've never lived outside the US. Right, yeah, but that's kind of all over and that's not just West Coast or anything like that.
That's back and forth, back and forth. Yeah, it was a lot of back and forth, but it's nice to get exposure to like a whole lot of the country and, you know, get a better feel for what it's like out there. And then, you know, even the places I haven't lived, I've traveled to all but 3 of the states. Oh wow. Okay, who's left on your list?
Alaska, Arkansas, and Mississippi. All right, Alaska makes sense. Yeah, once you're out there, it's a special trip planning trip. Yeah, it's a haul. Okay, so then where did you go?
Which state did you live in when you graduated high school? Here in Colorado. So, okay, so you were graduating from high school in Colorado, and then did you go straight into university? Yeah, straight to university. Went to CU Boulder.
Okay, my undergrad there. Okay, what'd you study? I started, long story short, in engineering physics and finished in sociology. All right, I would think those would be in different colleges. They are indeed in different colleges.
I spent, yeah, 2 years doing physics and calc and things like that, decided that really wasn't my game. Sure. Um, but I worked in IT the whole time I was in college. Okay, so, um, getting real-world experience. Yeah, it was, um, You know, my first IT gigs were running the computer labs on the Boulder campus.
All right. Back when they were, you know, DOS and Windows 3.1 and into Windows 95. So this was before virtualization, and maybe there was imaging, but maybe you were loading things from floppy disks? Yeah, there were some, there were some Novell 312 installs from floppy disks. Okay.
Yeah, and what were the students using the labs for at that point? I mean, at that point you had a lot of access to applications because even if you did bring a computer with you, it was a desktop in your dorm or your portable, whatever. It wasn't portable. No one had laptops really at that point. And so, and there wasn't good ways of getting the software on your home computer.
And so even if you wanted to do fairly straightforward stuff we take for granted now of getting a hold of the software and putting it on your own personal computer, you had to go into a lab to do that. There's no way to put it on your own computer. Kids these days don't know how good they have it. Well, plus you had to print all your assignments back then. You couldn't submit them electronically, and so they would also go to the labs to print stuff out.
Sure, sure. Yeah. Okay, so that was in the early days of technology doing DOS and Windows. Did you kind of stay on that path, follow the Microsoft Windows? I did.
It was My first full-time gig for CU was the original design and build of their first Active Directory. We were a Microsoft Rapid Deployment customer, and so, okay, that was '99, 2000. Yeah, Active Directory must have— I think it came out with Windows 2000. Is that right? It got off the NT domain system and moved to DNS-based, right?
Yeah. So you didn't have a whole lot of reference architecture, I'm guessing, right? There wasn't decades of proven AD design that you could draw from. We were making it up as we went. It was also one of the wonderful things about working in higher education is that we talk with our peers all the time, and there's— we don't worry about competition and like don't talk to our competitors or anything.
Yeah, there's more cooperation. There's a lot of cooperation, collaboration, especially in that we were working with folks I knew at Carnegie Mellon and MIT and Stanford and University of Washington and some other places on— they were all doing it at the same time. And so we got together and we eventually formed that into a conference. We started a technology conference, got Microsoft to sponsor it. They still hold it, you know, 18 years later or something like that on the Microsoft campus.
Specifically for higher education? Yeah, higher education, the use of their technologies. Okay. It's neat. Conference that they've had, because it's half the speakers are higher ed peers talking about stuff and half of them are Microsoft folks, right?
We always held it on the Microsoft campus because you can get some pretty awesome speakers when all they have to do is walk out of their office for an hour and then go back to work. They don't have to fly anywhere. Sure, sure. So it was okay. And did you say Microsoft was involved in the design of the AD domain for CU?
Yeah, we were a rapid deployment customer, which is a Microsoft programs where you get involved during the beta phase and they send— they give you some consulting hours. So they sent out to work with us. And so yeah, they were part of the process in the early days. Okay. And the real question is, 20 years later, is that domain still alive and kicking today?
It is. There's a lot of ways it doesn't look quite the same. We consolidated— I don't think we have any child domains anymore. Collapsed it a little bit more. Okay.
There were some pretty tricky things that we did in order to do interop with an extremely Unix-focused environment at the time. Sure. And so, you know, we didn't use Microsoft DNS. We— there were no actual— you know, the authentication is a long explanation, but we actually still used an MIT Kerberos realm as authentication even for the Active Directory, which is a little bit of a complicated thing to set up. Sure, sounds like it.
Yeah, but You know, I really learned those— that Kerberos standard really well. Doesn't do me much good anymore, but man, I can tell you about tickets and to be granted tickets, TGTs. That, you know, if you're into pen testing or something like that, that could certainly be relevant. Yeah, golden tickets I know are a big win if you're trying to pen test an Active Directory domain. And I think that's a great thing for anyone who's doing, you know, attack or defense, but especially pen testers that really understand the fundamentals of how these things work.
To attack them and know how they can be attacked, right? You know, simple things of, yeah, can you attack Active Directory by attacking the underlying DNS SRV records or something like that, right? Or through the Kerberos service or whatever else, or through the fact that it, you know, for various functions, it silently falls back from Kerberos to NTLM unless you change the Group Policy setting or something like that. There are certain functions that cannot use Kerberos. If you map a drive in Windows using an IP address, it cannot use Kerberos to authenticate that.
Huh. Because they don't create Kerberos service principal names for IP addresses. Oh, okay. Yeah, I guess that makes sense. So all these things we had understood, yeah, you found out for the first time.
We do funky things with Kerberos and you break it, really? Sure. So did you ever pursue the MSCE certification? No, I never did. In part because just for myself, I've never cared too much about getting certifications.
I know a lot of people, it's a real interest of them and they get a lot of satisfaction out of pursuing them. This has never been my thing. I got my CISSP when I changed jobs because I knew it was going to be important to put on resumes. Right, right. And I love learning and I think professional development and ongoing learning is critical.
I've just never cared too much about the certifications. Sure, yeah, yeah, there's differing opinions. Some people, like you said, have to get it for the HR validation in order to get some promotion or get a new job or something like that. I just saw on Twitter that Microsoft is retiring the NSE, so even if you had it, it would be going the way of the dodo. I think they're going all in on Azure right now.
Oh yeah. Yeah, so you got— cut your teeth in Active Directory and got a lot of expertise there, and then were you able to like leverage that to work on the larger enterprise networks as well? Yes, after that I moved and did that for about 3 years, then did IT architecture for a few years at CU. Worked on email systems, learning management systems, storage systems, all sorts of different things, which was great to broaden my view of IT services and how they interact with customers.
It was amusing and learning things like UML diagramming. Right. We used to refer to UML use case diagrams as Blair Witch diagrams, little stick figures that were connected to each other. So architect can mean a lot of different things. Were you doing, you know, more technical data center architecture?
Were you doing enterprise architecture where you're talking about where data is going to live and information systems? Or were you doing like application architecture? It's probably most accurate to call it application architecture. Service architecture. Okay.
We did, like I said, worked on some of it was totally new things, but it was like, you know, updating the mail routing flow and mail protection schemes for the campus. Okay. Now, new storage systems, did a major upgrade of learning management system during that time. So yeah, probably most accurate to call it application architecture. Okay.
I'm looking at your LinkedIn and I see WebCT, and I was a WebCT user back in the day and have a little bit of flashback, right? Yeah, that was— we were all at the time. Is that still a product? Is that still around? Blackboard bought them out many years ago.
All right. And then folded it. I think they killed off that product line and folded it in. Um, they really, I think, just wanted to buy the customer base because, right after they bought the company, they, um, my understanding is they closed the Vancouver office and, um, told people they could move to DC if they wanted to. But who moves from Vancouver to DC?
Yeah, that's a, that's a long haul.
Okay, and then after that, uh, looks like you started to develop a specific focus on security while still at CU. Yeah, after I did architecture for a little while, then, um, the security office expanded and was— before I went to it, it was really 2 folks, one of which is still there, is my boss now still, um, Dan Jones. And, uh, they added a couple more people into it, and so it was kind of the first growth step of the security office on the Boulder campus. That was 14 years ago or something. Not many people were talking about security 14 years ago.
Yeah, it was, it was pretty narrow field then. And as someone with a systems background, I suppose a network background, it was a challenge because everyone who was in security at the time were networking folks. Yeah, it was a heavily network-focused field. And we've gone through, I think, those cycles of, oh, we've got a big systems focus, now we're getting big application focus. And so it's been interesting to watch who comes into security evolve over time as that focus has changed, right?
This current crop of candidates might have a sysadmin background one year and then more of a web app development background the next year. And now we've got kind of the first crops of folks with pure academic information, you know, folks getting cybersecurity bachelor's degrees. Mm-hmm. Yeah, that's relatively new. Yeah, it's been just the last 5 years or so has really taken off.
Does CU offer a cybersecurity degree? So we do have— each campus has a little slightly different programs for it. You know, the Colorado Springs campus has— they got a grant a while ago to do a cybersecurity center, research center down there, so they definitely have some focus there. Boulder campus has a cybersecurity master's program. Master's, okay.
And Denver has a cybersecurity emphasis within their IS master's I don't believe they do a specific— okay, like a specialization, but not a full degree. Yeah, okay. So they've each got— it's been a growing thing. A lot of schools gotten into it. That's great, that's great.
So then what were you doing specific to the CU organization in that role? That was— the security office was pretty small at the time, right? It's, you know, a little bit of everything. Yeah, lots of hats. Yeah, everything from incident response to PCI compliance to, you know, policies and standards.
It's a little bit of everything. Less on the net because I was kind of coming in— 2 of us came at the same time. The other one came from the networking team, so he had a lot of the networking-focused stuff. Okay. I handled a lot of the more systems-focused things.
Sure. And yeah, so it was a little bit of lots of hats. When you say incident response, was that, you know, server incidents, malware on endpoints, all of the above. Whatever the software found, you'd have to investigate. Yeah, see where it came from.
You use a large network with a lot of people on it. And so yeah, we've dealt with everything from compromised servers to endpoints, compromised accounts. Of course, these days compromised accounts are just a huge— have been a huge thing for a while, but certainly are a big topic, you know. Lost mobile devices, you know, the intersection of, you know, real-life crime with cyber issues and law enforcement, as sure happens. I imagine in a large network like that, there has to be some level of segmentation between a student's device and what they're downloading versus a faculty device.
And there are, and it's kind of a yes and no, you know. The easy yeses are things like residence halls tend to be separated in most universities. That's pretty clean. We get into things like the wireless networks. Well, very often it's commingled devices within a wireless single wireless network.
Okay, so same SSID potentially. Okay, same subnets. Then you get into things, you know, servers may be segmented off, different types of servers, different types of critical use cases. You know, we have Obviously VLANs for different types of functions that are more sensitive than others. But yeah, there's definitely commingling of devices, and it's hard not to when, you know, researchers, you know, especially grad students or even professors themselves are very commonly using their own personally owned machines to do their research.
Sure. And they're just plugging it into the Ethernet port in their office. And I don't know if anyone's plugged into an Ethernet port in quite a long time. Their servers might be. Their servers, yeah.
I don't think very many people bother to plug in their laptops anymore. But, um, yeah, and it's just a wide variety of devices. And we chuckle sometimes at the BYOD discussions that have come up over time. It's really— that's the whole basis for it. Like, we are essentially landlords for thousands of people.
They're bringing their personal devices from day one. We've been dealing with gaming consoles on the network since gaming consoles had network ports. And, you know, such an interesting variety in, you know, rapid technology adoption. You know, that's a great age group to have people on the cutting edge of technology. Yeah, sometimes they're front-running what the— what your department can keep up with.
Yeah, so we can see them show up with everything from, you know, whatever cool project I cooked up on my Raspberry Pi to, you know, You'd see international students bring, you know, their special VoIP phone that was sold in their country for calling back home. That's, you know, all sorts of network devices that you didn't really expect to deal with. Right. And there's no way to put in a mobile device management MDM solution on student devices. Yeah, that's not— I don't know of any higher education that does that.
Right. Yeah, I don't think that's gonna be viable. Not to just join a Wi-Fi network, at least. Okay, so looks like you also took a detour to Emory and were a security specialist there as well. Was that a big change?
It was. You know, it's also in higher education. Emory University Healthcare was a great place to work down in Atlanta. One of the big differences for me was picking up a healthcare side because I was at CU Boulder. We don't have any medical facilities there.
Down there, the There's 2 major hospitals and I think 24 remote clinics, and so there's a large healthcare side of it, and that was a new thing for me. Um, it was a great team and it was a great place to work. Um, you know, it's a private university, is, you know, fairly well funded, which was kind of nice too. But, uh, we still had lots of, you know, lots of challenges to deal with on security space. Yeah, things involving electronic medical records.
I'm sure that— yeah, patient privacy. Yeah, the medical side, but then we still had the same stuff I was doing before, you know, lots of PCI merchants to deal with compliance on, incident response to deal with, you know, what are we going to replace our IDS/IPS with, what are we going to, you know, went through a few different technology RFPs while I was there. But it was, uh, it was great and it was good in each of the locations to have opportunities to try to inject security into the project or procurement processes where you get into architecture review boards or procurement processes where we're doing anything from technical reviews to contract reviews. Okay. Some of the compliance side of the security team does contract reviews for technology contracts, right, to make sure that there's protections for the organization before procuring things.
And most of the time, it's— there's some protections for the organization, most protections for the personal information.
Yeah, that the organization is dealing with. Patient data. Well, it's patient data, student data, just employee records. There's a lot of personal information when you deal with any large organization, right? And then if there's ever a fight or a breach or something, it depends what the contract says as to who pays and who has what responsibility.
And what terms you get negotiated varies by companies. There's some, especially the really large companies, can kind of take a no-negotiation stance. You get what you get. Yep. There's not much you can do about it.
Yep. Yeah. But at the same time, we've had some little companies that agree to everything in our standard language. That also makes me afraid. You didn't object to anything?
I'm kind of worried that you're actually gonna follow all this. If they're too accommodating, maybe they don't understand, or maybe you worry if they're gonna still be around if they do have a breach. So it's always tricky stuff, but it's nice to be able to be working both sides of it. Work the technical side, work the kind of legal and policy side. Right, right.
And advance the organization forward on both fronts. Let's talk a minute about PCI. It looks like you've had a lot of experience with working with PCI and payment card industry. Yeah, I've been doing payment card industry compliance work for 13-ish years now. I've just kind of stepped out of that role with CU, but I was, you know, Certified Internal Security Assessor.
CU certifies multiple different internal security assessors, kind of helps you be in good standing with your bank. It's an optional step for anyone, but it means that you're trained and redoing your exam every year. And so I've conducted lots of merchant trainings on it. I did a full-day workshop for other IT security folks on PCI compliance a couple years ago. Yeah, done quite a bit of that.
It's definitely an interesting space. I mean, it's a very detailed standard and there's some very specific procedures about auditing it. And with the university, part of the interest is that you have a lot of different merchants that you're dealing with. It's like, well, I work for just this one online store and I know this one thing. Well, we have online stores and in-person stuff and all sorts of mix of different types of businesses and different ways of accepting cards.
And so that definitely made it very challenging, but you also meant that you learned an awful lot about PCI and how credit cards are processed. Sure, sure. Does the University of Colorado have a standard template to say, here is our supported POS, here's our supported merchant, or do those individual storefronts have the option to choose? It's a little bit of both. They're definitely especially for the in-person ones, we've got some standardized devices and those have evolved over the years.
Sure. You know, getting into the space of point-to-point encryption and stuff like that, like we're in these days. And then online we have some standards for particular types of things, but you always end up with a business driver that says, oh, we really want to use this specific application for a lot of business reasons and it doesn't work with the standard payment processing gateway or whatever. Sure, so there's some— there's some compatibility that leads to exceptions. And, and so those are definitely— they're challenging, but, you know, end of the day, there are some good business reasons that they wanted to use something a little bit different that worked way better for the business process.
So any information security professional is probably going to come across PCI at some point in their career. Is there a set of facts that you want to share to say without going into an extreme level of detail, here's what every person should know about PCI. If you're going to be in information security, these sets of facts, these basics, will get you up to speed on at least how to respond to when the business says we want to take credit cards. I think that's, that's a good question. I think first and foremost, remember that PCI is a contractual obligation.
It's not a law. And so It's applied to you with your, you know, your contract with your bank. And so we run into sometimes where people think about PCI applying to credit card numbers. It's not specifically attached to credit card numbers, attached to a business relationship. And so that's one starting point.
I think the— a lot of people talk about how you scope and how do you understand, you know, which SAQ applies. That's a huge topic. PCI is trying to figure out— SAQ stands for Self-assessment questionnaire. So everyone's— most organizations are small enough they self-assess to their bank what their compliance level is, which means filling out a questionnaire online and sort of the bank questionnaire of legitimate. And those are broken down into a half dozen or so different types based on, I do this type of— I accept credit cards in this way, thus a subset of the standard applies to my setup.
So I do online only, this subset applies. I'm doing in-person, this applies. I'm doing point-to-point encrypted, this other subset applies. So there's a lot of thought that goes into making sure you understand which of those really apply and working with the business to help them understand, hey, you know, if we manage to implement some new technology like point-to-point encryption, or we only did online, we didn't also do this other thing, you know, We would actually— our compliance burden would be lowered. Yes.
And so you can have some good conversations if you have a good business partner. That's been one of the great things at CU, you know, the Treasury Office there has been a terrific business partner over the years and how we go about this and how we enforce it. And then just having that really structured— for CU having so many merchant accounts, a lot of it's about having a well-structured workflow process for doing the compliance cycle each year. We have so many different departments we have to work with on that. And so that was a big thing, is how do you structure your process?
How do you, you know, train everyone? How do you get them through their SAQs? How do you work with them on change management when they want to change what application they're using or change their business process on how they take credit cards? The partnerships have been just a huge key thing. And are there multiple merchants in play?
Right, so I'm thinking of, you know, maybe a relationship with Chase Bank and then a relationship with Wells Fargo Bank and a multitude of financial— CU is in general, in terms of the bank side, has a single agreement with Wells Fargo, as does the state of Colorado in general has a single agreement for that, which they just renewed. I think a year or so ago they did the RFP for that. But we do have a whole wide variety of different types of merchants that's really cool. Complexity comes in. Folks who have some familiarity with CU can imagine, you know, like any big university, you've got bookstores, you've got tickets, you've got payments for tuition, you've got a huge variety of types of businesses going on there that some are online, some are in person, and that's really what makes it kind of big and complicated for us is the wide variety of merchants that we have.
So does the team that you're on or a similar team fill out the the SAQs for every single one of those merchants. So every one of the merchants is responsible for filling out— we kind of own the workflow and we're the shepherds or whatever of the process. We're making sure the merchants are completing, right? We're helping them on the certain parts of that we do kind of complete for them. Like, you know, they have requirements around having incident response planning.
Well, that's owned by the security, right? Not them. And so we help them on those things, but mostly we're making sure they're getting it done. We're answering their questions. We're helping them understand, you know, is their network diagram up to date and accurate, things like that.
We're answering technical questions for them about, well, if I do this or I do that, does that meet this requirement? It's a lot of guidance and shepherding. Okay, great. So you came back to Colorado. The old joke about the Flatirons, once you see them you have to return, that got to you as well.
And then about 8 years ago, came back to University of Colorado, and let's talk about your role and what you're doing now. So I came back into an information security officer role for the System Administration Division at CU, which most people aren't aware of. It's, you know, 600-700 people in that division, and it's some of the functions that are centralized between the campuses. We've got procurement folks and legal folks and audit and the president and vice presidents and folks like that over there, and the ERP systems are run out of that group. Okay, so we've got an IT department that runs the ERP systems.
So that, when I came back, it was a security team of one. I was it. Information security officer and all analysts and specialists and everything else, engineers or whatever. Again, wearing a lot of hats. Yeah, and then it's just grown over time.
We've restructured it a couple of times since then, but we've had good support there. We've had a couple different CIOs while I've been there, and they've been very supportive of security in the IT department down in that division. Has been pretty supportive of building security into the project process. We worked over time building some of the technical processes, building into the project process. We've got some pretty security-savvy folks down there, so it's been a good group to work with.
And it's, um, yeah, we've made a good deal of progress. And then we've done some more recent reorganization where my scope of responsibilities now includes security operations for the Boulder campus. So I split my time between the Boulder campus and the System Administration Division down in Denver. All right. And it's— so it's back.
It's kind of nice. I'm coming back to Boulder after being gone for many years. Some familiar faces and a lot of new ones. Sure. I'm sure there's been some growth.
Yeah, over those years. So when you say security operations, what does that mean? What are some of those functions and responsibilities that you have within the team that I have now? We've got folks that work on monitoring, incident response, vulnerability management, web application assessments, forensics. You know, it's kind of the classic firewall policies, the kind of classic security operations— IDS, IPS, things like that.
So different tools underneath each one of those banners as well, right? You've got an incident response toolset, you've got a scanning toolset under vulnerability management, you've got a number of different tools. And in some cases, because I have 2 IT departments, departments between the 2 locations, the tools are different. And so cases like firewalls are different technologies.
And then monitoring could be what the antivirus reports or like a SIEM. Yes, we have a SIEM that we manage within the team, and we just recently replaced that. And for the first time, we're working on a true multi-campus one. So the Denver and Anschutz Medical campuses and the Boulder campus and system administration, all 4 of those locations run not just the same tool but the same instance of the tool. Okay, we're kind of unifying that for the first time.
Yeah, you can get more visibility that way. Yeah, it's been a big project in this past year in 2019. A lot of that was that new SIEM platform. Okay. All right.
And then what are some projects, you know, aside from that, what are some other large-scale projects that you just completed or you have on your plate for 2020? Big— one of the big things for 2020 is AWS, or Infrastructure as a Service cloud, work. Okay. Higher ed's been a little slower to adopt than some other areas, and there's certainly some use— some of it in use now, but it's really starting to ramp up and really getting our tools and our skills within the team ramped up to address that and the processes around, you know, when do we decide whether, whether it goes on-prem or into AWS, right? And who pays for it?
I usually don't have to worry about the who pays for it part of it, which is nice. But I do have to worry about the security side of what sort of data is going to be. Yeah, what sort of data. Large university, you have all sorts of different types of data. And so that's a big thing is understanding what data we have there.
Data inventory, data classification. And we do have a data governance process. It's still relatively young, but it's been really great to bring the business owners of the data into these discussions about whether it's anything from data classification to the risk-based decisions about how we use data, especially not just putting in the cloud, but we use SaaS applications or other third parties. You know, what types of discussions do we need to have before data is provided to a third party to do service for us? When I thought, thought of CU data, my first thought was student data, right?
Student personal information. But you've helped me think of it in terms of Well, it could be researchers' data or it could be faculty data, right, or any other number of data that's collected. Could be personal information, sure, but it could also be weather or it could be market research or it could be any number of data. There's a lot of different types of datasets and within, especially in the research space, it could be all over the place. It could be very, very public information.
It could be just literally analyzing public datasets to— it could be some very confidential stuff, whether it's about people, you know, there's research, human subjects research that goes on, or whether it's about, you know, there's some contractual agreement with the granting agency or something that says you need to protect this data in this way in order to receive your funds. Or maybe a commercial partnership too. Yeah, if there's someone trying to commercialize a product and they've signed an agreement. Yeah, there's certainly that type of stuff going on. There's a lot of— CCU does lots of partnerships with national labs and other aerospace folks in the area, all sorts of people.
Yeah, yeah. Well, do you have any advice for those that are more junior in their careers and are just getting started in information security? It's, I mean, it's an exciting field, and I've talked with a lot of folks who are new into it, and I think largely about the hiring process and the recruiting process and what that's like, which is a whole different thing to talk about, but I think, you know, getting the exposure to try to figure out what you want to, you know, what areas you want to work on, what you enjoy doing. I think asking other people for feedback about— sometimes we don't realize ourselves which things we're enjoying and not enjoying. We can ask our peers or our supervisors, like, you know, they could have some good observation about, you get really excited when I talk about this or that.
I also think that unfortunately, I think sometimes people sell the information security job as being hyper-focused when it isn't always, you know, if you want to do just, you know, malware reverse analysis or something like that, there's a very small set of companies you can work for to be that focused, right? It's very niche. Yeah. And so I think being open to the idea of, you know, do you want to have a hyper-focused job? And if so, which companies is that available from?
Mm-hmm. You want to have a broader job, which types of companies? So starting an idea of what you want to do will help you align to where should you be looking for jobs, because certain companies may not have the type of job that you want. Right, right. If you want to specialize and be really good at one thing or two things, you need to consider the market for that.
Yeah, and there could be some good ones, but if you get really narrow and, you know, you're gonna be looking for a very, very specific opportunity. And then maybe you can freelance with that, or maybe you're stuck working for the one person in town who does that job and does it really, really well. It's— but I think I'm big on having a broad view of things and getting a broad understanding of technology in the business. Sure. So I think it's great to get some technical depth in an area, but understanding where your opportunities are to apply it and how to take best advantage of your skill set requires a broader understanding of, oh, I can help you and this other IT team out.
I know how to do this one thing. Now I understand how it applies to the work you do and how it applies to this other team over here, and I can maybe make more opportunities for myself or be a better partner if I understand how my skill set fits in with everyone else, how it all fits together. Sure, sure. Yeah, lately I've been thinking of, in terms of if someone says I want to get into information security, that's kind of like saying I want to get into medicine. Yeah, I want to be a doctor.
You know, there's so many different specializations and Nobody's a good match for all of them. You kind of have to feel out what you're good at, where you gravitate towards, what gets you excited. Finding people you can talk to who are in spaces you're interested in too and finding out, talking about what's your daily life like doing that and try to imagine yourself doing that. Denver area is great for having lots of, you know, lots of information security stuff going on and lots of community events. And stuff going on.
And so I think it's good to get out there and go to some of those and meet some folks in the field. Where do you think the industry as a whole is heading? You know, we talked a little bit about tool sets, and it seems like there's plenty of folks out there trying to sell technical solutions. And do you think that's where the— where we're headed? Are we going to see a backlash?
Are people going to stop buying from companies that have breaches? Well, I think the track record has shown that breaches don't actually affect business all that much. It's a whole separate discussion, but I think there's pretty good data to support that. And then no one's going to stop selling stuff. I used to track my unsubscribes from companies over the course of 5 years, unsubscribed from sales emails from 1,100 different companies.
There are a lot of companies in our space, and a lot of those don't exist anymore. But I was shocked how many companies there are in the security space. It's still a young field in a lot of ways. It's still changing a lot.
Getting to the point where we are— I don't know how far we'll get in terms of people are following really similar standards or approaches. We've talked for, it feels like, decades now about software development becoming more of a, you know, a discipline that has more security. But it's slowly evolved, but it's been going a lot more slowly than I expected. I mean, I was in a conference 13 years ago or so, and the CISO for Oracle was saying that, you know, she felt that software development should get to a point where it's like architecture, like building architecture, right? You have to get certified, your designs are vetted, the construction itself is vetted.
To make sure that the bridge doesn't fall down once you build it. That was 13 years ago. We still quite haven't gotten there yet. And part of that might be the demand, you know, the market demand for, we need this now, you know, we can deal with bugs, whereas there's less tolerance in the real world for buildings that fall apart and hurt people. Yeah, and you can't— I mean, I was talking about agile and DevOps type work.
You can't build a building in an agile fashion. There's no MVP of the building that, like, there's enough that I can move into this side while you're still building the rest of the building around me. Doesn't quite apply the same way. Yeah, the analogy doesn't work.
But it does give us some opportunity, I think, that shift into how software applications are delivered into You're always living on a dynamic application. It's always evolving in some ways, and there's certainly challenges in the security space on it, but it also gives us the potential to fix those more rapidly than the, well, we got this, you know, ancient system that's, you know, it's a multi-month process to do a software update on it, and there's resistance to it. It's like, you have no choice. It's like tomorrow it's being updated for you. Yeah, as more things become SaaS and more things become cloud, that's most likely the model.
And over the apps on the phones, it's not SaaS, the delivery is the same way. It's getting updated. You're not even thinking about it. It's getting updated automatically behind the scenes. Yeah.
So that has the potential to at least get security fixes out faster. Whether it generated more problems at the same time, I haven't done the math on that. Sure. Sure, there's pros and cons to that approach. Yeah, sometimes you wonder whether it's like that Simpsons episode where they put Homer in charge of safety and they talk about how the safety record got better by the same number of accidents they thought he caused.
Yeah, shifting the problem. Okay, any career goals? You know, when you look 3, 5, 10 years down the road, is there anything you want to do or take on or learn? I know I've— I don't have anything I'd say that's super specific. I've been enjoying getting more into that intersection of the business side of the house and the technology side of the house.
You know, how we articulate the value of what we do to the business side of the house is a very particular interest to me in the last couple of years. So I really like being able to spend some time on that interface and being able to interact with both sides has been really interesting. So I guess I've been a little further, a little more detached from the hardcore tech than I used to be. Well, it's almost like being bilingual. You know, if you're going to be hands-on keyboard looking for indicators of compromise or tracking down some IP address, that's certainly a different skill set than building a roadmap and selling your budget to executives.
And it's definitely not necessarily the same person can do all those roles. Yeah, I've told people a lot that— and we debated, you know, lots of people talk about how do you get budget for information security, and in some ways it's the same thing you get budget for anything, which is that people who get budget for things are the people who prove that they did well with the last money you gave them. Okay, if you're not good at articulating the value you delivered with the last money you got, no one's gonna give you more money. Why should they? Yeah, they want to see how the value was provided through the— if you say the last money I got, or the current budget I have, here's all the awesomeness that comes from that money, and I have reached the limit of awesomeness I can do with the money I have, here's my proposal for the next level of awesomeness, the next tier of money, and come back and demonstrate that you achieved something with that money.
No one wants to give money to a black hole of, I gave you money and I don't know what happened with it. Sure, sure. So transparency, communication, and being able to do that bilingual in the business terms of how do we— not just what did you do with it, I bought hardware, I bought software, I bought a new staff line, whatever. What did that mean for us? What improved?
What got better? Right, and that's a great way to build trust too. Not be the IT person who takes the money and then goes in the server room and to buy more blinky lights, but actually talk in terms of business value. Yeah. Okay, great.
Well, is there anything we didn't cover that you want to be sure to mention? I don't think so. This has been great. It's good talking with you. I think we covered some good ground.
There's— look forward to listening to all of the ones you're recording. All right, well, thanks so much, Brad. Appreciate your time. Have a good afternoon. Thank you, John.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.