Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 158 for the week of March 30th, 2020. Alex, uh, I This is the first time we're recording and I am not sitting in the same room with you.
I know, that's pretty weird. It's amazing we've gone 150-some episodes without having to do this remotely once. Yeah, we've always, you know, whenever one of us was out of town, we just found a co-host to fill in. And it's, it's, you know, obviously the stay-at-home order from the state has changed things to the point that it just doesn't make sense for us to to get together in person and put people at risk. How are you doing with staying at home?
You know, we're doing pretty well. I've been playing basketball every day with one of my sons, and I'm happy to say that I have not lost every game. So that's a good thing. Nice. How about you, Robb?
Well, I have played a little bit of basketball, but we played Played a little bit of volleyball today and we went for a bike ride. So we're still staying active. You know, I actually think I'm doing a little bit better with the isolation now a couple weeks in than I was at the beginning, getting a little more used to it. So, you know, if we have a couple more months of this in front of us, I think we'll be okay. You know, tonight at just after dinner, we had a rousing family game of Sorry.
Oh wow, did you win that one? Yeah. I did not win. I came in second. Oh well.
Oh, sorry to hear that. We played Quirkle last night. I don't know if you know Quirkle. I didn't come in. I think I might have come in fourth.
I'm pretty sure I got, I got whooped at Quirkle. All right, well, I believe that's last, Robb. Yeah, yeah, there's 4 people in your family, so you're last. Just confirming that. Just to be clear, I did, I did finish the, the, the the number one loser.
All right, we do have some housekeeping here. We have a Slack channel if you guys want to join. It's been like still continuing to be a really vibrant conversation, especially during COVID I think this is one way people are getting their, their socialization on. You can come join the 1,300, 1,400 people that are there. Go out to colorado-security.com and click on the Join Slack button on there.
We also have a mailing list if you would like to get the show notes delivered to you in your mailbox every week. Go to colorado-security.com and use the form at the bottom there to enter your mail, email address and get signed up for the mailing list. And I don't know how you're listening to us right now, but we would love it if you'd be listening to us by subscribing on your favorite podcast listening application, iTunes, Google Play, whatever it is. And while you're at it, while you're subscribing, why don't you go ahead and give us a review? Those reviews do help us find new listeners, and it'd be great to get more folks to be inside the Colorado Equal Security family.
Also tell a friend, just let somebody know, of course within appropriate social distancing norms, let them know about Colorado Equal Security and the podcast and all the stuff that we're doing. Just keep passing that word around. If you want to go even beyond that, you can, you can join our Patreon campaign and donate a couple bucks to help us cover the costs of the podcast and the things that we're doing here. Good stuff. And of course, we would love it if you want to help do interviews for us.
We do have another guest interview this week. Hopefully, I think we have quite a few guest interviews coming up here throughout the COVID stay-at-home order here. Big thanks to John Hubbard and Jason Jaques who have been leading the effort on that. Why don't we go ahead and jump into the news? Alex, you want to start us off?
Sounds good. The owner of Stranahan's and Law's Whiskey have said that they're going to build a $50 million whiskey resort in Blackhawk. That sounds pretty cool. I'm super excited. This is going to be called the Lake Gulch Whiskey Resort.
It's going to be right there just past Central City in Blackhawk, which is a— it's really exciting because there's not a lot up there other than casinos. They're going to have a real large amount of land, and only about 5% of the land is going to be for the distillery itself. Another 5% is going to be for resort amenities, including things such as an axe throwing course. They're also going to have hotel, camping grounds, restaurants, event space, retail, and an outdoor amphitheater, hiking trails, zip lines, and a farm. So lots of stuff that's going to be a part of the Lake Gulch Whiskey Resort.
And they're also going to have some, some residential on the same space. Yeah, sounds pretty cool. It does sound like a bit of a mixed-use development. Uh, retail, um, you know, uh, folks' houses, things like that, um, all there. So that could be pretty cool.
Um, I, I did note that there was a little bit of a snag in this story. Uh, you know, Blackhawk and Central City, while they're right next to each other, I think there's a little bit of competition between them. And Central City wasn't super happy about this going into Blackhawk, so they actually— there was an agreement between Blackhawk and Central City that said this land was supposed to be used for either residential construction or a golf course. So they're, they're fighting this for the time being, but I'm, I'm sure they'll be able to figure out some compromise to get it to go through. Yeah, as long as there's some revenue to Central City, I'm sure they'll work something out.
One other interesting fact from the story, they talk about how the, the owners of, of Sreenehan's had quite a few meetings with the Blackhawk leadership, the politicians there, and they said that one of the long back-and-forth sessions concluded with the companies and the local leaders doing shots of Tin Cup, which is one of their whiskeys. So apparently things are going pretty well there in Blackhawk. I hope that in order to do that, they all walked into a saloon and tipped their cowboy hats up and said, you know, pour me a tall one or something. Give me a shot of whiskey. Yeah, there you go.
Yeah. All right, next. Speaking of resorts, the Gaylord Resort out by DIA is going to be shutting down temporarily and also putting the brakes on the expansion that we had talked about previously. Yeah, we talked about how successful they've been, and I would say that Gaylord out by DIA has been more successful than anyone expected. Unfortunately, through this downturn, they've already lost over $42 million in revenue and 69,000 nights at their hotel due to the restrictions around this travel.
So, they have just seen massive impact. They've shut down and they are planning to be shut down at least through the end of April. Yeah, there were a large amount of cancellations that they've said, not only just within the time since the lockdowns have been put in place, but all the way through June and beyond. So, I think that that's what finally led them to close for the short term, as well as the fact that it sounds like they are at just about zero occupancy right now. So, you don't really need to keep a hotel open if there's nobody there.
Yeah, this sounds like The Shining, right? Good time to close up. Good time. All right, another local— we are not going to talk all about COVID I think this is our last story, at least for a little bit. Um, uh, we do have kind of a good news story though.
Uh, Angie Home Services, you know, Angie List and HomeAdvisor, have offered Congress help to distribute the financial aid to small businesses. So, you know, in the last week, Congress did pass a stimulus that was going to get small business loans out, and Angie Home Services says they're in the unique position to help distribute those loans to small business companies. Yeah, they have, you know, more than 250,000 small businesses that are part of the, the Angie's network, and they have, you know, a platform already in place that they could help distribute some of this money. You know, they said that part of the plan, they're not really looking to make money off of this, but they're, you know, they're using the platform to help get money out to those small businesses so that they can keep working. You know, obviously, and it is in Angie's best interest because as long as those folks are working, then, you know, they're making money through the platform.
Yeah, they were talking about as a part of the plan, they want to make sure that lawmakers have deemed home service professionals like plumbers, electricians, and HVAC repairmen as essential workers. And as someone who needed a plumber quite urgently this week, I can say I think they're right. Those things need to be deemed essential and need to keep working through the shutdown here. Yeah, definitely. If all of a sudden you don't have heat or you don't have— can't flush the toilets or get water, that's not a good thing.
Gotta have those people working still. So next, the— we've been talking about it for several weeks, the Colorado InnoTech Madness Championship. We are now to the finals. So this past week was voting for the final 4. We still had a security horse in the race.
Stackhawk, but sadly they lost this week in the Final Four. So we did— I think we left off last week at the Elite Eight, and they actually did have a significant win over Conga. They actually beat them pretty soundly. And then, and then in the closest matchup of the Final Four, they lost to Heart Hero, which I guess, you know, they're saving lives. Maybe that's more important than security.
I guess we leave it up to the voters, but Security did end up losing that one. Uh, the finals here is going to go between Heart Hero and SiriusMD, and if you want to vote, I think it's just through the end of Monday that you can get your votes in. Uh, isn't SiriusMD like a telehealth startup or something like that? Um, if they don't win in, in this time, then, uh, I think something is wrong with this system. So, well, I think, but really both of the finalists are about saving lives, and I know obviously really good startups that hopefully Hopefully both of them are wildly successful.
All right, next story we have here is from a new launch here in Denver. We've had, you know, a number of security companies in Denver. A new one launched in the last week. It's called TruKno, and that's T-R-U-K-N-O. They have launched their new directory, which gives you access to really a nice database of different threats, different threat actors and different solutions and companies that can help you address those things.
Yeah, so this has been, you know, a little while in the making. They've been working on this platform for, I don't know, probably over a year now, definitely over a year. And, you know, I think that they've pivoted several times on what exactly it was going to be, but it's a, you know, a curated source for cybersecurity news and threats, as you mentioned. So I think everybody should check it out and and use the platform. Yeah, I had a chance to talk with the team about this as they were doing it.
Manish is the CEO and founder over there. It's really cool stuff. You know, it is free, so that should be appealing to you if you're looking to find different solutions to solve different problems. They can help match up your security problems with different solution providers in the market. Awesome.
We had a blog this week from ThreatX talking about fighting the AppSec fight Don't sell products, create partnerships. And I think that, that, you know, whether it's ThreatX or anybody else, that's some great advice if you are a security company or any company for that matter. You want to create partnerships with people and do the selling part second. Yeah, so this blog post is written by Chris— is it Brad Younis? We've had her on the show as a feature interview in the past.
I think she's the Chief Product Officer over there. For ThreatX, and she kind of came back from RSA conference and she experienced a lot of vendors who are just looking to sell technology and really talking about the need to go beyond just a technical solution. I go a little bit back and forth. I'd love to hear your take on this, Alex. There's— they're right that just selling tech, you know, isn't the full solution.
On the other side, and as a buyer, when I hear that, you know, it's a partnership, it kind of makes me think that maybe they're looking for me to put a whole lot of man-hours into this and that the technology is not quite there yet. But it seems like there's a little bit of a mix between those 2 perspectives. Yeah, you know, and that's fair too. You know, sometimes you just want to buy something and, you know, you don't want to put any effort into it. You just want to get something out of the relationship.
But so yeah, I agree. If the goal of a partnership is for for you to give a whole bunch back to the service provider that you're getting something from. Yeah, maybe that's not as attractive. I think in this case, you know, Chris's idea here was that, you know, they have at ThreatX not just a technical product, but they also have a, you know, security operations team and some other folks that, you know, kind of come along for the ride. So, you know, you're, you're in there to get help from AppSec professionals as well as get the ThreatX product.
So a set of humans that can help make it better, right? Right, exactly. All right, so next story is from ZVLO. So ZVLO's story here is a blog around TTPs, so tactics, techniques, and procedures around malicious cyber actors who are trying to exploit the COVID-19 pandemic. Yeah, so as we know, ZVLO, they do URL categorization and And, you know, they took a look at a bunch of the different domains that have come out in the last couple of weeks that malicious actors could potentially be using to help exploit people in this time.
So things that might have COVID in the name or coronavirus in the name.
They did go through a little case study here looking at a sort of a higher top-level domain that is redirecting to some areas that eventually get you to a place to download the malicious COVID tracking app that has been talked about a little bit in the news recently. So basically their advice is, you know, just be careful out there and make sure you're looking at the data around URLs before you're going to these places. Sounds pretty smart, and, you know, it is nice to see folks who are trying to help us track what that bad behavior looks like. I'm just ready to hear about something that doesn't have anything to do with the current pandemic. What do we got next, Alex?
I have something that can help with that, Robb. Coalfire was awarded one of the first ISO 27701 accreditations, so they can give you accreditation for this, which is a privacy standard from ISO, which goes along with the, you know, ISO 27001 security standard. Yeah, we— I think we talked about kind of a similar story a month or two ago when Coalfire started offering their own advisory service around how to get your organization ready to get 27001 certified. This new piece of news is actually that Coalfire themselves are are now able to do the certification process rather than having to have a different third party do it. So they can, they can kind of be your one-stop shop for your privacy ISO certification needs.
Yeah, pretty cool. Congrats to them. And then finally, story here is around CyberGRX. They're talking about what is the risk or value added by doing your third-party risk assessments Onsite? Do you need to go onsite to do them?
Yeah, and I think that the general answer there is that there are a few cases where you may want to, but in general, especially with our— again, with our social distancing that we're doing now, you can probably get most of those done remotely. If this is a, you know, a new relationship potentially where they're going to be handling a lot of sensitive data for you, potentially a time where, you know, they've had a— the vendor has had a breach in the past, or, you know, a couple other reasons. Maybe those are good ideas to go on site. But honestly, for me, you know, most of the time there's not much of a reason to go on site anymore anyway. You know, in the past it was, oh well, you know, I'll go and I'll check out your data center.
I'll see how you process things. I mean, anymore, most of the time you're going to go and they're going to say, yeah, there's nothing actually here, it's all at AWS or Azure or someplace else. So, you know, what are you to look at? Yeah, it's obviously— this is what they do, right? This is what CyberGRX does, but they're absolutely solving a problem here.
It's expensive for the people who send assessors on site. It's also expensive for the service providers who have to go through numerous customers sending folks on site. So when we can find ways to scale it, I think it's a good thing. And yeah, it solves the problem. So I think they're doing a good job there.
Yep. So moving on to the Slack message of the week. Thanks to Andre Gaeta for continuing to sponsor the Slack message of the week. The winner of the Slack message of the week gets a $25 credit to the Colorado Equals Security store where they can buy lots of wonderful merchandise. With the brand new Colorado Equal Security logo on it.
So Robb, who is our winner for the week? This week it's Pete Schaefer. Congrats to Pete. Pete actually had a whole bunch of good shares this week. I'm going to just pick out one from his many in the random channel this week.
He had the parody of Barenaked Ladies' One Week song, which I'm sure you all know. It's the chicken to China song, but it's one week of COVID and talking about what it looks like to be in self-quarantine after a week there. It made me laugh and I thought it was a nice piece of something to share with the community. So thanks to Pete for that. And of course, you'll get to have one item from the Colorado Equal Security store.
In these times, we do need some humor to keep us all sane. So appreciate the parody there. All right, let's go ahead and jump over to events. Just kidding. If there are any events, we don't know about them.
We have an event calendar you can look at and see what things might have been happening if things were still happening. But I would not plan to go to any of those. Instead of that, why don't we jump over to jobs, Alex? Sure. First, Bank of America is looking for a SOC analyst level 1.
The Colorado Department of Public Safety is hiring a cybersecurity intelligence analyst. CHI Health is hiring a security analyst 2 for DLP. Cisco is hiring an enterprise account executive focused on Duo security. Nice. Aetna is looking for a third-party risk analyst.
CenturyLink is hiring a senior manager of information security. Trimble is looking for a cybersecurity risk analyst. Twilio is hiring an enterprise security engineer. American Ag Credit is looking for an identity access management engineer. And finally, Frontier Airlines is hiring an IT security engineer too.
It's nice to see that even with, you know, all of the hiring freezes or hiring slowdowns, that there are still quite a few jobs available. Even a job at an airline. I know, that's, that's shocking. I'm not sure that I'd want to go there right now, but it's great to see that they still have it open. Yep.
All right, well, so it worked moderately well for us to go remote. I only think we talked over each other, what, 3 times, something like that? Could have been worse. Yeah, you know, something could have been worse. Fewer than we do in person, right?
Uh, not nearly as many times as if it was a normal conference call with somebody, so I think we did pretty well. Yeah. All right, well, we do have a feature interview this week. It's with Jeremiah Salzberg. Jeremiah has recently taken the job as the chief security technologist over at Sirius Systems.
So that's gonna be an interesting conversation to hear from him. He's had a few different roles here in town, and I'm looking forward to hearing what he has to say. Awesome, look forward to it. All right, Alex, well, have a great week. Make sure you stay at least 6 feet away from anyone who doesn't live with you, and hopefully we'll get back together again safe next week.
Sounds good, thanks, Robb. Hello, this is Stanton Meyer, CSO of Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Hey, Colorado Equals Security, this is John Hubbard. I'm sitting here with Jeremiah Salzberg. Jeremiah, how are you today? I'm doing pretty good, yourself? Doing alright, thanks.
You look excited for your upcoming ski trip. Oh yeah, gonna be up in Silverthorne all next week, skiing Keystone. Alright, Keystone, I've heard they've gotten some good snow lately. Good snow, I'm excited. I got friends up there, so it'll be a good time.
Good time. Okay, you said ski, not snowboard, right? That's right. I know you can make fun of me, but I've been skiing since I was a little kid. I've tried snowboarding, but it's sort of like once you've done skiing for so long and you're good at it, to go to something you're not good at, you know, I love that doing it in security, but in skiing I'm like, no, no.
Yeah, I understand what you mean. When you've only got so many days on the mountain, you probably don't want to— gotta make the most of it. Gotta get up there and enjoy yourself. And I do that with— and my friends ski too. So yeah, you know, if they were all snowboarding, it might be worse.
Are you an all-mountain? Do you do moguls? I don't do moguls. I am getting older, and moguls and my knees are not friendly. But I do just about the whole mountain.
I don't do as much like, you know, off trail in the trees, right? But, you know, the occasional tree run is fun. Okay. Is skiing your only outdoor activity? No, I do backpacking, hiking, you know, just about everything that you would want to come to Colorado for.
Enjoy the great outdoors. Yeah, exactly. And did you grow up here in Colorado doing that? No, so I'm— long, long history, but I was born in California. I left California because it was getting too fake when I was in kindergarten and moved to Minnesota.
Okay. So I was basically raised in Minnesota from then on. Okay, all right. Land of a thousand lakes. Land of a thousand lakes.
But not very many mountains. Not very many mountains. The skiing in Minnesota was extremely lame. You know, now looking back at it, it's like these little tiny hills and there's a lot of ice because it's very cold. But it does mean that, you know, when I get an icy patch on the mountain, I'm fine.
Like, this is how I grew up. Like, I know how to ski on ice. You know how to handle it. I know how to handle it. And other people wipe out and I'm like, yeah, it's ice, I got it.
Okay, so grew up in Minnesota, graduated high school there? I graduated high school there, and then I went up to college out in Pennsylvania for chemical engineering, but found I like Fortran quite a bit better and started actually taking the Fortran— it was a long time ago— Fortran courses. They still taught Fortran back then? They still taught Fortran back then, exactly. And I had already done some Pascal and some other stuff before that and So I got a lot more interested in that.
And, but then I dropped out because I got a job working at a computer training facility and basically was just able to really, you know, start learning way quicker. Things were more relevant, you know, really cool things were starting to drop like Windows NT 3.51 with a bunch of floppies. It was pretty exciting. And so it was a pretty cool time, a lot of cool stuff happening. And I got to be at a training facility teaching that and helping set up the labs and everything else.
So you're teaching others the technology? Yeah, in fact, I started out just being a lab junkie, but really setting up the classes and the computers and everything else. But then very quickly I learned everything I needed to know and started teaching myself. So they had me start doing a few of the courses, and then they fired their lead instructor, and I started doing quite a bit more. That I can't even remember his name, it was so long ago, but he was just a really very impressive person, really knew his stuff, taught me absolutely everything there was to know about networking at the time.
Token ring was great stuff. Okay, was there TCP/IP prevalent back then? Um, I don't think so. I think it was— I mean, it might have— it must have been, but I— yeah, it's a long time ago, so the timeframe of when these technologies came about, when I learned them, is a little fuzzy in my mind. But I remember token ring, I remember setting this up, up.
I can't remember the actual networking protocols. Okay, I'm picturing like the BNC connectors. Yeah, yeah, the back of network cards. Exactly. And then one person unplugs and the whole thing goes down, right?
And then we'd be like, oh, there's the token, must come out of the wire, you got to go find it. Yeah, it's good times. Yeah, I don't think anyone misses those days. Yeah, no, no, definitely not. Yeah, networking has come a long way.
But that's a good foundation to set you up for a career. It's a good foundation. I really did kind of start out heavily in networking, and really there wasn't a lot of like true security back then. And so, you know, a lot of people came up through networking in those days, and I always like to tell people that I've forgotten more about networking than most network engineers know, but that's because I've forgotten a lot about networking. Most of it might deserve to be forgotten.
Yeah, exactly. Most of it now should probably be forgotten. But yeah, I know I was early on in Cisco and Junos. Okay, and, and I was a Juniper nerd for a long time just because it's such a better experience than Cisco with things like commit confirm and other stuff like that where you could be working and just say, okay, I'm gonna commit this, this configuration, but if I don't talk to you in like 10 minutes, you should revert because something went wrong, right? So it's just little simple things like that, you know, multiple rollbacks and really simple things that just aren't that difficult to put in.
And we're just— and that— and plus the configurations were just beautifully organized, right? It was almost like a JSON file where you have like sections and you have the right stuff in the right sections, right? So it's so much better organized versus, you know, Cisco configs are stored everywhere. Of course, I was heavily into Cisco too, and I was working on CCIE and other stuff like that. So were people doing a lot of WAN, you know, point-to-point or internet?
Yeah, actually, in fact, the funny thing is I set up the first Wide Area network in Wisconsin. So I traveled to every single county in Wisconsin for the Department of Health and Social Services, basically, you know, grabbing and putting in wide area networking and helping the people that I get. So like, we're the only computer people they would see for months on end. And yeah, I would just show up and help. There's a long time ago, a long time.
I don't think it shows up on LinkedIn. But yeah, that was working initially for a company called Network— no, not Network— that's right, Network Computing Architects. That was way later. I can't remember the name of the company now. It was a small company in Wisconsin that got me into that.
And yeah, it was interesting. So I was contracting for the government. Okay, so a little bit of travel. A little bit of travel, and, you know, first experience really traveling and like driving around in a car around the state. And it was really fun and exciting for somebody as young as I was.
And, you know, yeah, going out to these places, they just loved us because like every computer problem they had, we'd sit down and solve for them. And so I, you know, I'd get out there and set up that initial, you know, wide area network and test everything. But then I was basically their computer junkie for a couple days and I helped them out and then left. So yeah, you got to be the hero. I got to be the hero and people loved it.
And it was just sort of a a really just good feeling to be like, yeah, I'm doing something and, you know, I'm helping track down, you know, people that aren't paying their child support and stuff like that. But at the same time, just helping each of the different areas. Sure, sure. Yeah, pretty cool stuff. Yeah, and I've always, you know, I've seen that parallel in help desk and service roles.
I always wonder if people who transition into security, do they still have that same feeling of like I'm the hero, I'm solving people's problems. Because sometimes, let's be honest, security systems are not very popular to roll out. It's true. It's like, I'm the people who are annoying everyone and making pop-ups that annoy you every day. There is some of that, especially with, you know, DLP or other products that are like slowing down systems and blocking what you're trying to do.
And right, I'm just trying to send an email. Why are you— you know, so there's, there's a lot of that. And then also, like, you know, when you're on the blue side, um, You know, when you're doing your job right, nothing happens, right? Hey, look, I did everything perfectly and nothing happened. Isn't that awesome?
That's great. You don't get a line of people out your door to congratulate you that nothing happened. It's a little different in incident response. Like, I've done heavy-duty incident response and forensics where, you know, I fly in and, you know, you walk into a room with people yelling at each other and freaking out and You know, you have to organize them and, you know, tell them, hey, you go do this, get me this information, you go boil water, you take care of this, you know, just get people calm, give them jobs. And then when you're done with some of those incident response things and you've figured out what happened, you've contained it, you've got them to a point where they're able to breathe, they love you.
I mean, it's, it's, you know, people really are appreciative. So that's really doing something. And so incident response is really cool because of that. You know, even pen testing is cool like that too, because, you know, it's nothing like, you know, popping shells and like, hey, I got that, like I did that thing, I got in that system. The people aren't as friendly when you tell them about it, but it's still cool.
It's still like you're doing something real, making things happen, you know, that the, you know, at the end of it. And actually, the real cool thing about pen testing is is when you do multi-year pen tests and you come back the next year and they fixed everything, right? So like, you're not like, uh, it's the same stuff. And then a lot of times it's the same stuff, but like, they've listened to you, they put in the controls, you know, they're, they're at a much better spot. And like, they start making it challenging, and then that's a lot more fun, right?
And you've, you've helped them get better, and you also have a more challenging thing in front of you. Challenging yourself. Yeah, exactly. That's You're right, that's more rewarding than if it's the same vulnerabilities from 12 months ago. Exactly, exactly.
And about what percentage would you say take that feedback seriously and go make those changes and go roll out new policies or controls or things like that? You know, I guess, I don't know, to really— maybe half and half almost. It's really not that good. I mean, they'll do like 1 or 2 very small things and they'll only fix the highest of the high or the criticals or something, but Many of them don't actually do it. Yeah, you come back and you're like, you still aren't patching your stuff.
Why are you still not patching it? That's the simplest thing right there. Like, you know, and, um, you know, for some companies, I'm just telling them like, listen, you don't got this patching down. Just— you're gonna have a much better time if you just set everything on auto-patch, right? Just get patches directly from every vendor, automatically patch everything.
You might have a little downtime here or there, But it's gonna be way better than a breach. Sure, sure. And, and actually there's a couple companies have just done that. They're like, okay, every system is gonna update itself, go and get security updates every single time and be done with it. And if there's fallout, we'll deal with it.
Yeah, I mean, it's how I set up like every system I run at all out there in the world. I just have an auto update. I, you know, and has it broken my Plex server once? Yes. Yes, it has once, but, you know, has it, you know, caused me other issues?
No. Like, these systems I don't want to have to sit and think about, right? And so auto updates, auto updates are your friend. Make it happen. Okay, well, jumping back to the career path, you had a strong foundation in networking, did some engineering work at several different organizations— Cisco, Juniper, Foundry— And then it looks like you took a jump into security.
Yeah, so I, um, I mean, I've always basically done security in one way or the other. A lot of Cisco Foundry, Juniper. I do like Juniper. I like the Foundry, actually. Good switches back in the day.
Anyways, but there's always an aspect of security to it. So like creating access lists. I mean, like access lists were security. That was security a long time ago. Yeah, like, hey, I put some access lists in.
In fact, I did some pretty, you know, exciting things of putting outbound access lists. That was, that was crazy. That was like, they're like, what are you— why are you doubling up all your access lists? Like, somebody was reviewing my configuration. I'm like, well, because I only want things to talk out on things they should talk out on.
Sure. Like, these are servers, they shouldn't be reaching out to the world, you know, they only need to do this, right? Well, I guess that makes sense. Yeah, no, it really makes a lot of sense if you think about it. Yeah, the least privilege.
Yeah, it's basically lived least privileged networking. So yeah, just, you know, that will help you, you know. And it's so— eager scoping is a very good thing. And people don't always have that mindset. I mean, then, you know, in my childhood I started out doing that.
So yeah, I basically grew up— my childhood was war games, right? So I did a lot of war dialing, a lot of, you know, seeing what I could find out. You know, I had access to the University of Minnesota system through my mom's account, and I I took full advantage of those, those access and got access to modem banks, and I was able to do war dialing across the country. You know, most of my friends then— and I had a little brand, a little tiny BBS, and so we were all little kids with really silly names. I think, I think I called myself the Cat Lord or something.
It was something really, really stupid. It was some really stupid early hacker name. But so I had a BBS, we talked about this and they'd be like, okay, we want to try dialing this range of numbers. I'm like, I got it. And so I would go back and I'd go into the university systems.
I would hop on— there was a little bus in between the 2 campuses. I'd go hop on the bus and go in there and go sit in front of a green screen and start doing stuff. And I would set up these ranges for it to dial at night. And so I had written up a little thing to go just start dialing, and they had all these outbound— they had just massive modem banks that I could use. No one was using the outbound very much, and in the middle of the night, no one even cared.
And I'm like, I guess they didn't pay phone bills because I was dialing long distance. Yeah, back in the day, long distance could be a big— exactly. I'm sure somebody's like, what the heck is going on here? Like, they're probably just— that's research. Maybe it wasn't a big enough bill, but I certainly was dialing a lot.
And so I would go, I'd come back the next day and be like, yep, here's everything that responded with something, right? And they're like, how did you do that many calls? I'm like, well, you know, I got my— I got research. I didn't tell them what I had. But yeah, otherwise you're dialing with 1 or 2 modems.
Most people just 1, right? You look at WarGames and he had the one phone.
You know, frightening. Exactly. And it's frightening. And, you know, the login ones, like, you know, they never seem to let you stop you from asking. And so, you know, we, you know, sit there and try for days, like, try this password, you know.
And, you know, sometimes they give you what type of system they were. And we didn't have the internet back then to do any research. But, you know, you could go to the library and do some research. So I mean, we, we did some of that, which is kind of really early hacking. It's— I feel like It was the dark ages when we didn't have just Google to go and say, hey, give me what the default login prompt for XYZ system is, you know.
But, you know, we got into a lot of different systems and, you know, a lot of them didn't have passwords and most of it was just dumb stuff. I was really just playing around. Like, I never like broke anything, right? Never issued a shutdown or format command. No, I never did anything bad.
It's more like, what are these systems and what can I do with them? It's really childhood innocence. Yeah, nothing illegal. And that curiosity, I'm sure, serves you well to like, hey, go explore, go figure out how things work. Exactly.
So that was really like beginning of security, but I was doing all this networking, and then a really good friend of mine, I was working with him, his name is Preston Hogan, he's at F5 these days, but he's like, you know, you should really do security. I'm like, Well, sure, isn't that kind of what I'm doing already? And like, so he really kind of pushed me into like the true security realm and like going down that path. So after just talking with him, I just basically launched fully into security. Okay, and what did that look like?
Like get a CISSP or take courses or get a job with security in the title? Yeah, get a job with security in the title. I mean, that's what I've— I mean, my My background is definitely a lot of job hopping. So, you know, you— I did a lot of that, like, okay, I'm going to get in here, learn as much as I can, get as much fixed and working as possible, and then use that new title to get a better title and a better pay somewhere else. So I did do some of that, just job hopping for title and for skills.
Um, and so it really taught me well. Um, yeah, you can get a lot of exposure that way. Exactly. New environments, new ways of doing things. I did get a CISSP in 2001.
Have you kept it current? I still have it. I know. Do you have all your CPEs filled out? It's not hard to get CPEs.
I've never had a problem. I should probably go check right now. But anyway, yes, I've kept it current. I kept my CSSP. That's been— and back then it was the first year of the Shawn Harris book.
And okay, yeah, you know, her book was fantastic, and I did get a chance to talk to her once. A long time ago. She's passed away since then, but it was the best. Like, and we had all these horrible books, like these really old, horrible, impossible, just impossible books. And we had those books and we had this new Sean Harris book that had just come out.
Like, I think it was the first edition. Anyways, and I'm like, well, I hate all these books. I'm not going to pay attention. I'm just going to do this Sean Harris one. And so I just went through everything, learned all the, you know, How— where's the light need to be?
Where's your fire seat? Whatever. All the crazy stuff you also have to learn for the CSSB. And I took the test and I just blew through it. I went through the whole thing and I spent most of the time arguing about how stupid the questions were at the time.
Like, you know, there's no correct answer to this one. This is like not accurate. Or this is like, you know, I know what you want me to answer here, but that's not right. Sometimes that's the point, right, is you're supposed to want to have a little tension there about it. Exactly.
Well, I think I took it with Preston and a couple other people too, so it was like a fun— I think it was in California, I think it might have been San Francisco. We went out and had fun afterwards, but it was like, it was just a fun time and I was just waiting for them to finish, so I'm like, I just keep writing. Somebody probably got this textbook with like, this is the most annoying person ever. Yeah, but, you know, I felt that was right and I felt I should, you know, educate. Was it a written test?
Yeah, written. So big paper booklets. And so I did the full, you know, write down like first answer that, you know, you know it's right, great. You think it's the answer, you circle it. And then if you don't have a clue, you just move on to the next one, right?
You just do that as your test methodology. And then you go in and you fill everything back in and like the ones that you You know, if you don't think it's better, you can't think of a better answer than when you first came up with, then you just choose that. The ones that are question mark, maybe you learn something from post-test and you fill it in. So yeah, it worked well. Okay, so different jobs, different roles, and some certification, book knowledge.
Yes, yes. And I kind of got ramped into a much quicker pace when I hit pen testing. So, all right, so I didn't. And which company was this? I worked at Foundstone.
They got acquired by McAfee. But yeah, that was, you know, working with like truly intelligent people. Like I was suddenly not the smartest person in the room. And there were people there that are like writing the exploits that we're using. So, you know, it was eye-opening.
It was a challenge. But my networking skills really taught me well. I think that's why I still tell people who want to go into pen testing, get some basic networking knowledge too, because it's good. They sent me out on the first pen test and you just are supposed to be, you know, kind of watching what they're doing, learning the methodology, and they're like, well, let's see what you can do with the network. I'm like, okay, great.
And they're off doing this really extremely interesting SQL injection attack and and they had to send out like a byte at a time to get there. You know, it's this whole, whole process they're going through. And, uh, they're like, okay, we finally have a tunnel, we're going through the system, we're able to see this, this protected network on the other side. I'm like, great, ping this address. They're like, okay, great, I see the address.
Uh, what is that? That's my computer. So I had, I had, uh, so you're already in? I was already in. I got in by taking over the network.
And just putting my port on that VLAN, right? And so like I'm sitting there like, yep, I'm already there. But that was pretty cool. Like I couldn't do what you just did, but you know, and it wasn't like a difficult thing. It was more like I found, I found some default SNMP strings and used that to get the configs and broke a password.
It's very simple stuff, but like Like I was able to get in there and figure out what their actual passwords were and go from there. Yeah, so it was, it was a very— they were very impressed with that. And yet I was very much more impressed with what they were doing because I thought that was like serious hacking that was way better than I was doing. So I definitely felt not as competent as these guys. Sure.
Well, within security, there's so many different disciplines. Within pen testing, there can even be so many different disciplines. There's web application testing, there's network pen testing, there's external network pen testing, there's social engineering, there's physical testing, right? Yeah, and I got to work with some of the, like, the best social engineering guy I've ever worked with, and he did win the DEF CON black badge. Yeah, those contests they have.
Yeah, he was amazing. He's one of those, like, I looked at him like, I'm not even gonna try social engineering because I'm never gonna be there. Like, I always break down. I was doing a pen test at a casino, and we had gotten into the underfloors and, you know, tailgating somebody. And me and another guy were walking down there, and we turn a corner, and there's 2 guards with shotguns.
They're like, are you boys lost? Like, uh, like, uh, where— you know, I just broke down. Like, I had nothing. And like, I know my friend probably could have sweet-talked them and come to like, oh no, we're, you know, whatever. But I was just done.
I, I was I was already like walking down there like my heart is just beating like crazy and like I was just freaking out from it. So, and then they put us in this like storeroom thing with a locked door and we just watched like a horrible movie the night before, like Casino or something where they get locked in a storage room and then like beaten to crap and then thrown out in the street. And so we're sitting there sweating and And the guy opens the door and it's the person we had coordinated with to do the pen test. Oh, okay. He's like, yeah, so you boys got caught, huh?
I'm like, I'm never doing a casino again. Well, I did. I did another casino after that, but it was the— we were pen testing their rooms. So we got put up like hotel rooms, hotel rooms. So we got put up in a brand new casino hotel room and like, we just want to see if there's anything you can do with these rooms.
And we're looking at these things and it's like there's these little sensors on the, you know, like for your, you put a, pick up a bag of peanuts and it automatically charges your room. Oh yeah. Right? And we're like, hmm, what's that? And we're looking around, we can't find anything.
And so it's all this gigantic big wood console. And I'm like, oh, you know what? I think I can get in here. And I start like pulling this thing out and like, like I totally wrecked the wall doing this. I'm like, oh well, I've already wrecked the wall, I might as well keep pulling.
I see wires, I see wires, I'm like, I can't stop. And so I got the whole thing out. The funny thing was that once you got past physical aspect of it, this network, it was connected by a normal network, there's a little device there like Ethernet. Yeah, Ethernet. So it was the Ethernet, and so we just basically have been the internet were on their internal network.
Well, that was easy. And it was basically— I mean, we saw a lot of interesting things on that internal network that I think we should not have been able to see. So you plugged in, sit back and listen, see what's going on? We sat back and listened. We had authorization to do whatever we wanted to, so we not only sat back and listened, but we started talking to a few different systems.
So we were able to get into things and One of the coolest things about Foundstone was their methodology was every single day you write up all your findings and you send that to the customer, right? Okay, so you're not writing a final report. We did write a final report, but, but by the time you get to the final report, you already have all your findings written. They have a little cool macro that would just pull them all in, put them in the final report document. But you didn't have these pen testers that would be like, I kind of forgot what I did out there, right?
Like, you And I've had that when I've purchased pen tester services, and I'm like, that is horrible. Here's how you do it. You write up your findings every day and then you send them to the customer. And so sometimes they're like, well, they're gonna fix something and we won't really do it. I'm like, that's your job is to let them fix things, right?
And so we sent that in and they're like, yeah, that's— you guys gotta stop. Like, we— okay, we got the picture. All the room networks need to be on a segmented thing and they shouldn't— all the servers that deal with them And they came up, they talked to us about their design and we looked at it and we're like, yeah, that's good. Everything room-related has to be completely separate from casino stuff, right? And yeah, and so they did all that and it was good after.
And if this was 10, 12 years ago, the amount of technology in hotel rooms has only increased since then with smart TVs and the conveniences and in-room tablets and all these things. Yeah, I mean, think about it. And actually, the biggest risk is probably to all the people staying there. Like, everyone just is automatically connecting their Netflix account, connecting, you know, everything. Like, every Marriott I go, I do the same thing.
I go to Marriott and I connect my Netflix because I'd like to watch my Netflix, you know. So I should have a burner Netflix account. But, uh, but at the same time, like, you know, there's a— there's just all these networks out there, and it's easy to, you know, say, hey, I— yeah, I'm Marriott. Yeah, talk to me, right? So there's a lot of definite concerns with the security in hotel rooms, especially against customers, but against the hotels, right?
Yeah, pretending to be the official hotel Wi-Fi. Yeah, exactly. What if you're gathering info? Oh yeah, yeah. I mean, you see those like door lock systems that were wirelessly communicating over a different band, and so some of the cool technologies looking at You know, software-defined radios and stuff like that where you can just kind of sit there and look for whatever.
And I haven't really gotten into this, but a friend of mine actually was listening to the door locks and was able to replay a door lock to open a door. Yeah, so some of those aren't that secure either, but right, yeah, so it's definitely interesting what you can find. Great. Okay, so you did pen testing for a couple years and then looks like you moved into security money fraud investigation. Yeah, and that was really exciting.
MoneyGram was probably the most exciting. Like, you think about working for a company that hands out cash at hundreds of thousands of locations worldwide that are all mom-and-pop shops, right? Like, wow, that is not easy security, right? And we had crime rings dedicated to us. So we had a whole Romanian crime ring that was just like, just coming in and taking down agents left and right.
We had a Nigerian crime ring like everyone does, but they were really focused on us and Trying to run scams or trying to get into the network? Well, obviously scams. So we had all this other stuff and I only focused on agent-based fraud that was computer-related. So I only did anything that was computer-related fraud. I was part of some of the fraud teams that dealt with like all the other stuff, like the romance scams and other stuff like that.
And we were looking at some interesting data analytics to look at patterns and things and figure out ways to identify that. But, you know, the most interesting was, you know, that they would basically attack an agent, compromise that agent computer, and then they would take that agent computer and start doing transactions, right? And so it was really difficult to figure out, like, oh, were they just getting busy? Was it like, you know, what were they doing? And we didn't have the systems really to prevent that.
And these remote computers were just the dirtiest computers you've ever seen. Like, I did forensics on a bunch of them and I mean, these, these are people who are working at this mom-and-pop shop and this may be their only internet computer that they have and they're sitting in front of it for like 10, 11 hours a day. These things are dirty. So it might have other applications, other business applications on it. It might have virus applications.
Yeah, business applications are the least dirty. Yes. No, it had other applications, viruses.
Spyware and, you know, files that you don't want to actually ever look at. So, right, definitely a lot of really bad things on this computer. So they were compromised all the time, and, and these attackers were good. They would physically go there and do USB attacks, right? So they did a lot of like, you know, walk in and stick a USB in the back and distract the person.
And they did— they sent out CDs to all of our agents and one country that said, hey, here's your update CD, and it had the MoneyGram logo. The CD, the application on there was like MoneyGram Update. I mean, it was, it was primo, it was perfect. And we had a lot of agents fall for it. They stuck this CD in and they updated their computer, and fraud started happening.
There were massive, massive amounts of fraud there, and I was probably trying to figure out what's happening, how it's happening. And then I came up with a methodology to reduce most of it, which was to authenticate every transaction with multi-factor. So not authenticating users, because tracking all those users and people coming and going and all that, and that big of an uncontrolled environment, just impossible. Sure. But what I could say is I know this computer is a MoneyGram computer and it's for this particular agent, and then now I have a Yubico token and And I associate the token ID with that agent ID.
And then, you know, for every transaction you say, okay, yeah, okay, it's all approved. Okay, hit your token. Boom, done. Super low impact for agents, super easy. And it reduced the fraud by like 99%.
Hmm. We still had a bunch of the social engineering, and they figured out like to call them up, go like, hey, I'm the Ubico inspector, can you press the button 5 times? You know, like boom boom boom boom. Boom, 5 transactions done. Right.
You know, as soon as they got those codes, as soon as they got the codes, they could go in and reuse them. And, you know, this is before some of the cooler new technology out there, but it definitely was very effective. And so it was effective for a long time. And, you know, so it's— it was pretty cool to actually build that, design it, and work with development teams and actually see it have a big reduction. Okay, yeah, that sounds like a great solution that had a minimal impact on— in terms of, you know, productivity or burden for the end user, but had a huge business impact.
Huge business impact, yeah, exactly. And so I always love those low-friction technologies that really add a lot of security, and I'm using marketing's friction term here, so you can smack me if you want. But, um, you know, it's, uh, it is true. Like, I mean, if you can make things easy for people. So if you can make security easy, you know, it's a lot better.
And then suddenly you've got, you know, okay, I'm gonna do this for you, but it's gonna be easy, right? And so, you know, we've, we've come back to some of these super easy things that have bit us. Like SMS is really easy because everyone can get SMS and it's a phone, but it's also a horrible multi-factor authentication method, right? To me, it doesn't even meet multi-factor, uh, qualifications, right? Because I can easily redirect it to another phone and you'd never know.
Spoof or whatever. And so, I mean, we already have enough issues with software tokens on phones. Um, you know, it's better still, but yeah, that's why, I mean, I still love hardware tokens the best, right? It's so old-school, but it's so functional. And the Yubico and other people now are making these software keys I can just tap on my phone and it authenticates, or, you know, you know, easily just fits on the sides.
You just hit it and you're good to go. So it's definitely a lot easier technology, and it's really actually, you know, probably a lot more effective. Sure, sure. And that's an interesting situation because a lot of times as the top security person, you might be able to control the endpoints and say, you know, this is what the agent computer needs to look like, it needs to run this antivirus or endpoint protection or inventory or malware scan or something like that. But in this case, how many different Asian computers were you working with?
Hundreds? Thousands? No, like something like 400,000 or 500,000. Oh, okay. So they're everywhere.
Everywhere. There was no way you can bring those all under your umbrella. And I would— that was my future idea, is that to send out little Android tablets everywhere. And okay, and the idea was the Android tablet could be your secure transactional environment and Not just for yours, but you could also sell that as a service to other companies, right? So all these, these, all these different agents would do, um, money transfer, they do money exchange, they do, you know, all these different services that they can provide.
Well, what if I could tell you as one of those companies, money transfer agent, money exchange, uh, whatever, that I can provide you a super secure environment that we guarantee it, we'll put an insurance claim on it, so, you know, we'll guarantee up to the first million dollars of fraud on this particular device, well, they'd pay money for that, right? Sure. You lock down that tablet to specific functions. Oh yeah, we were working with a company that made a secure Android OS and hardware platform. So like, if you ripped it, no one could use it.
It was just a dead piece of equipment, right? Nice. You know, and so you could only install updates from them. Everything was forced through it. It was really a beautiful design and it gets to that sort of like ultimate level of security, but you're talking about, you know, $100 to $200 per location times, you know, 200,000, you know, you're starting to talk about a little bit of money.
Yeah, big upfront investment. Big upfront investment, but long-term gain and long-term security. So if you could, you know, make that work, and that's kind of where like, you know, I start to run up against all those Layer 8 issues You know, it's, it's where security starts becoming less fun is where, okay, now I have to go and explain this to board level. I have to explain it to the upper level. I have to come up with the finances, the how does it all work, the business case, the ROI.
Business case, and I'm fine with business case and ROI, but there's even more to it, especially when you're talking that much money, and it becomes really complex, and then it becomes really political, you know. And it becomes a lot more difficult. So some of those challenges start to come up when you start getting that far up there. Sure, sure. It's internal selling in a way.
Exactly. And I'm good at that. I enjoy that. But it's the politics I don't like. Yep.
Okay, so at this point you're still in Minnesota. Let's talk about how you came out to Denver. I was in Minnesota and realized that it's very cold in Minnesota, and yet I still like skiing and I like backpacking and all these other things. I did hike the entire Superior Trail, so it's a pretty beautiful thing as long as you have the right mosquito gear. But in the summer, right?
In the summer. Exactly. No, although people have, and I see all these videos of people doing winter camping with -20, I'm like, you are insane. It does not look like fun. Yeah, so I have not done that.
So, you know, obviously this area also had some schools that my kids were interested in, so we kind of decided that it'd be good for the whole family to come down here, and we did. And I spent the next year, I think, still working in Minnesota but living here. So, oh, I was— okay, yeah, I was flying back, and so I was doing like 2 weeks there and one week here. Yeah, it wasn't, wasn't going well. I would think that would get old quick.
It got old quick, exactly. And I was, at the time, I was a CISO at a mid-sized bank, and I had taken them from a truly horrible security environment to, you know, not having a system compromised in 4 years and being able to tell that, like, no, that's true. And so I had been talking with the CFO there, and He's like, well, you know, I don't— you put in your budget for next year, here's all the things you want your team to do, but I think we spent enough. Yeah, we're in a good spot. Like, we haven't had systems compromised, we have these things in place.
I don't think we need to go next level. I'm like, well, you probably don't need me either at that point. And so, yeah, so then parted ways. Yes, I don't think I need you anymore. You have a really big salary.
So, um, yeah, so we parted ways and, uh, I I was able to come back down here and find a local job. Right. A little closer to home. A little closer to home. Okay.
And that was ThreatX? That was ThreatX. Yeah. And that was my first startup. So, you know, there's— I had never in this entire time worked for anything close to a startup.
I had helped friends with their startups and provided consulting advice, but I never jumped in both feet. And so my first startup, definitely learned a lot. You know, I don't think they were quite ready for a CISO or somebody to do what I want to do, and I kind of ended up being more, you know, customer service and customer success than what I wanted to do. Okay. So we also agreed that time to leave there.
I found a different startup now where I'm working right now called Defense Storm, you know, and they're a managed security service provider that helps banks and credit unions. So they only do banks and credit unions, and so it's very focused on that, into that financial niche market. Exactly. Okay. Yeah.
And is this something like an agent that would run on endpoints and report back? Yeah, there's their agents. There's a collection box, so it's pulling all the logs going into their, their system. Okay. The one thing that when I was looking at their product and analyzing it, like, like, these are extremely fast searches.
Like, the searching capability was getting to the point where you could be truly playing, right? And so, you know, we can get to the point where you can just take all of your log data and let people just play in it. That's where we need to get to, right? So in fast queries and responses is really part of that. So you can be like, I'm just going to keep pivoting into more data and getting more and more, you know.
And so that was something I thought was really good that they had designed. Sure. Okay, so you've held many different roles under the security banner. When you think Career goals, you know, other things in the next 5 to 10 years that you want to be sure to do? Yeah, I probably don't want to go back to being a CISO.
The layer 8 issues are just too annoying, and politics. Sure, you know, if there's a place where like politics was not going to be such a big thing, it'd be great, but I don't think a place exists. There's always a people element. Exactly. I think I really want to focus on security strategy and like what's, what's new, what's up and coming.
Come up with designs of interesting new products, technologies, services. You know, I have a lot of fun just talking to companies about their products. So I do have a number of people call me up and say, hey, I'm starting this product, here's what we're doing, here's how it's gonna look, and just kind of sitting down with them. Okay, well, here's where I see problems, here I see where you're, you're, you know, conflicting with other people, or here's other people have already done this and this is what they did. You know, if you want to stand out, here's things I'd recommend.
Some of that consulting of just, you know, hey, this is what I think about your product. As long as people don't get offended. Some people don't like you calling their baby ugly, but I think that it's important when you're first starting out or even later on that you listen to those people that are like, yeah, your baby's ugly, but you know what, a little makeup, a little haircut, you'll be fine, right? Taking that constructive criticism and building it into a better product, I think, is excellent. I've done that and helped a lot of companies with that.
What I found is there can be a lot of cynicism in the information security community, and sometimes that cynicism can be applied towards products that claim to be able to do everything, right? Yeah, so if you put AI on it, I'm very cynical already. So having having that feedback early on about, you know, here's how your mark— here's how your product might be accepted or not accepted by your potential customers. Exactly. That can be a good thing.
Not— again, not everyone wants to hear that if it's a negative message. Or the problem you're trying to solve has already been solved a thousand times. Or it's not really a problem. Sure. Like, I don't see that as a problem.
Okay. Yeah. All right. Looking back, you know, if you were to go back and tell your younger self, any security lessons or career lessons, or are there things you would want to tell a younger Jeremiah? Yeah, I think learn TCP/IP early.
It's been useful knowing just about everything about it. It's not going away. It's not going away, exactly. I did invest early in IPv6 and got the domain name sixbones.com, so Still not really happening yet, right? One of these days, right?
You know, I think, you know, really a younger self telling about, you know, watch out for the politics, learn some of the people skills as well. Sure, get that down. You know, just because it's not all technology, right? You know, a lot of this is how you work with others and how, you know, you help build a team. I think a lot of the things I've learned from being a CISO in other things, having direct reports is really, you know, how to manage people.
And yeah, you know, that's, that's stuff that was really difficult to learn. And so I definitely made mistakes early on. Yeah, and it's not something that's usually taught in technical classes. The CISSP doesn't have anything on team building or building a well-rounded team or performance management or anything like that. Yep.
And then when you make mistakes, you're impacting people's lives. So You know, that's, that's the most difficult thing about it, right? I've had some very big successes. So some people have worked for me that I came in as brand new to security. I've helped build them up and now they're doing fantastic things.
And those, those, you know, those types of experiences are fantastic and excellent. But at the same time, then those ones where, yeah, I hired that person and they're just not performing and you have to make those tough decisions. That's really difficult. And then you don't know if you're making the right decision there too. Right.
Usually time will tell, you know, you have to do what's best for the team and if the team continues to excel after that decision. Exactly. I mean, I think the most important thing is like looking for toxic people who are bringing teams down. And even if they're awesome at tech and doing a great job, you know, that's the most dangerous person you can have on your team. Yep.
Attitude is everything. Attitude is everything. All right, great lesson. Is there anything else we didn't get to cover today that you want to be sure to mention? I can't think of anything.
Okay. All right. Well, Jeremiah, thanks so much for your time. It was great to talk with you. Really appreciate it.
Yeah, thanks so much. All right, have a good one. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.