All episodes

Jay Wilson, CISO at HealthGrades

Apple Podcasts Spotify SoundCloud

Jay Wilson, CISO at HealthGrades is our feature guest this week. News from: Southwest Airlines, Valyant AI, Checkr, Visser, Foundry Group, LogRhythm, Optiv, Swimlane, Red Canary and a lot more!

Notice anything different about this week’s show notes?

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10585 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 155 for the week of March 9th, 2020. Alex, do you have coronavirus?

Um, well, Robb, I haven't been tested. So there's really no way to say. Well, I, I think that, uh, there is— it's hard to read a news feed right now without coming into, what, a dozen different stories about the coronavirus. And it came to Colorado this week, unfortunately, a couple different places, right? Um, you know, really what I'm trying to do is I'm trying to make contact with as many people as possible and, um, just get this out of the way.

Just get it out of the way. It's, you know, I feel like it's inevitable, so may as well do it now. They said— I read a story today, a projection said that It looks like 90 million Americans will probably get the coronavirus and 500,000 people die from it. So that's a big number. That's a big number.

Yeah, that's a big number. Well, that's not our good news for the week. Hopefully we have something better coming. Oh, I thought that was our good news. And now we're going to talk about security, everyone.

Things are going much better. Before we do that, let's talk about some housekeeping. We have a Slack channel. It's been a very vibrant community recently. A lot of good conversations about coronavirus.

If you want to join our 1,300+ members, go out to colorado-security.com and click the Slack button. We also have a mailing list if you would like to keep updated with what is going on with Colorado Equal Security and get the show notes in your email every week. Sign up on the website colorado-security.com and you will get those in your email every week. We'd also love it if you would rate us and subscribe on your favorite podcast listening app. I was actually just looking at the Apple, the podcast I guess the iTunes store yesterday and saw that it's been quite a while since we've had any new reviews out there.

The reviews have been very nice. You should spend a minute looking if you haven't. But we'd love it if some new folks would go out there and do reviews and help us get new listeners. Sounds like we're going to have to reach out to our Russian bot friends and get some more reviews out there, Robb. Also, you can tell a friend.

If that friend happens to be a bot who wants to give us a rating, that'd be great too. Um, but let people know the great things that we're doing and have them join the Colorado Equal Security community. And those are like the, uh, the entry-level versions of help, you know, telling a friend, going out to podcasts. If you want to go to the advanced level of helping, uh, we could use some support on our Patreon. That's a way for you to help pay for the cost of the podcast.

Or we could use help for guest interviewers, those who want to get to know folks in the community and help provide guest interviews at the end of the show like we're going to have today. Yeah, that interviewee or interviewer is really like the pro level of volunteering. So now that we've got that out of the way, Robb, you know what? We've got some news this week. Did you know that Southwest Airlines has big plans for the gates that they're adding at DIA?

I did know. And I think this is the first time we've had a story from thepointsguy.com as our source website. But lots of interesting stuff in this story. You know, there's going to be— oh, man, what was it like 39 new gates coming to DIA over the next few years? Yeah.

And Southwest is going to get Uh, was it 24 of them? No, no, they're gonna get, uh, 16 of them. They're gonna get 16. I think, uh, United is gonna get an additional 24 or something like that. Yeah.

So 40 new gates, I guess, total. Yep. Um, so yeah, Southwest is gonna get another 16 gates all on Concourse C, and this is gonna take the, their current 24 gates all the way up to, to 40. So they're, they're getting a big increase. Yeah.

One of the things that I thought was interesting is, um, there were some suggestions that there, there might actually, even with these new gates, be some congestion in terms of people wanting additional gates that are not Southwest or United that are essentially taking up entire terminals. Well, it sounded to me like, in fact, some other airlines are going to lose gates. Delta looks like they're going to come out of this with less gates. And did it say Frontier is another one? Possibly.

I know that there was 2 airlines that were losing gates. So really interesting. Somehow, somehow United and Southwest are consolidating their power here. We're going to be a 2-party system here. Oh, man.

You know what happens with a 2-party system, Robb? Just arguing all the time. No one gets anything done. We really need to save those minority airlines so that we can— Oh my gosh. Sorry.

Hey, let's move along here. Next story, Valiant AI is bringing artificial intelligence to fast food. We talked about this about a year ago, I think, this local company that does AI and basically they became the drive-in helper for Good Times, I think over in Golden somewhere, Lakewood maybe. So that was the news about a year ago and it looks like that's been a smashing success with their experiment. Yeah.

So I think when we talked about it last time, they were starting a pilot project to try and figure out if this was going to work or not. And yeah, as you said, it sure sounds like it's going to work. They did come up with a couple of findings. One I saw in the article was that people like to know that it's a robot that they're talking to, as opposed to thinking that it is a person. And then when, you know, maybe something goes wrong, or it's— it is robotic sounding, potentially that the feeling tricked— feeling tricked.

Yeah, I can imagine that. So they have 3 new offerings that they're gonna go to market with. Now that they've been successful with that drive-thru, they're gonna offer one that's substituting voice-activated kiosks for those push-button things that some fast foods have put in. I don't know if you've been to a McDonald's or whatever recently, but you push your buttons to get your food. Now they're gonna do fast food kiosks for that instead.

Second thing they're gonna offer is voice ordering for products on mobile apps. So if you don't want to have to click through on your mobile app, don't, don't worry, they'll do that for you. And the third one is, I don't know why this is an AI company, but they're going to allow texting from the seats in a stadium to order fast food and beer without waiting in line. So you just go directly and pick it up versus having to stand in line. Sounds pretty cool.

Also, the award that we talked about last week for Cody Cornell, who won CEO of the Year for— I don't remember what the award was. Tech Trailblazer. Tech Trailblazers. Yes. Yes.

So the CEO of this company was the other person that was nominated for CEO of the Year. Oh, wow. So this person is pretty good too. Yeah, exactly. All right, moving on.

Go ahead. Next, the Denver Convention Bureau is on alert for potential cancellations of conferences due to coronavirus. And, you know, we have seen, not necessarily in Denver, although there have been a few, You know, throughout the country and throughout the world, more and more large events, conferences, gatherings that are starting to be canceled. And folks in Denver are paying attention to that. Yeah, it looks like we actually do have some in Denver too, right?

We know that this week the Women in Security National event is going to be canceled. We have that on our list to talk about a little bit later. But I guess I just banged that out right here. Way to spoil it, Robb. Yeah, I don't bury the lead here.

Anyway, you know, obviously There's big stuff coming in. And of course, you know, we're as part of the planning group for RMISC, this is something we have to think about. I know both of us have a strong bias towards going forward with things like this and not canceling. But if the state ends up making a decision to close a convention center or, you know, there's significant health concerns, you know, I guess that changes the equation. Yeah, for sure.

And luckily for the RMISC case, it is still a good ways out. So we have some runway to to see what's going to happen before we have to figure out what the plan is. But yeah, definitely thinking about that stuff. Well, we are operating as though the conference is happening. We fully expect it to occur and we're continuing to do all the work it takes to put it on.

All right. Moving along to our next story, Checker. We've talked about Checker as a, as a, as a new way to do background checks. And they moved their— a lot of their staff here to Denver. Checker has hired their first C-level executive here in Denver.

At the new office they put downtown. Yeah, Tim Craycroft, who is a longtime Amazon executive, is going to be Checker's first chief product officer. He actually joined and grew Boulder's— the Amazon Boulder office 3 years ago. Pretty cool. So as we've been talking about Amazon growing, that's— he's been a big part of that, and now he's moving over to Checker.

I'd love to see that. I think as part of their move here, Checker said that they're gonna be bringing 1,500 employees to Denver. So that's a pretty big amount of employees. That is a big— it doesn't— I wouldn't have guessed they were that big based on what they do. That's, that's pretty cool.

Well, you know, somebody's got to do those manual background checks, Robb, with all the fancy front-end software. I love it. Uh, next story we have here is from a company called Visser. They are a parts manufacturer for the automotive and space industries, and they confirm a data breach. I, I didn't know Visser.

They're a Denver-based company though, and they serve some really big customers. Yeah, I didn't know them either. Uh, since they are a parts manufacturer, you know, you're probably not seeing them as in the headlines very often. But, you know, they're making parts for some big and important companies— Tesla, SpaceX, Boeing, Lockheed Martin. And I think this is going to probably be fairly harmful for them because it seems like some of the data that they leaked was fairly sensitive in terms of the parts that they make.

Yeah, it's really disappointing to see. Unfortunate for them. It looks like it was the Doppelganger ransomware that hit them. Um, and they've, some researchers found this and obviously, uh, you know, it got out. Uh, hopefully they can recover and, and, you know, no big, no big impacts to the Colorado, um, scene here.

Yeah. And this is, um, of course the new trend of several of the ransomware strains, not only ransomwaring you, but stealing your data. Uh, so that if you don't pay the ransom or maybe if you even pay the ransom, they'll, uh, get rid, you know, drop your data on the, on the dark web somewhere. Right. All right.

Moving along. Uh, next one, we have a, a bit of maybe sad news. I don't know if this is sad or, you know, happy for him. But one of the founders of Foundry Group, Jason Mendelson, has retired from the venture capital firm. Yeah, I'm sure it's very happy for him.

You know, one of the reasons that he gave in his reason to retire was that the firm is doing really well. So he had taken a sabbatical and I think, you know, during that time reflected on, on what he was doing there and things like that. And everything seemed to be going great without him. So, hey, why not retire? So, so he was one of the 4 founders back in 2007 that they got that brought Colorado, really brought us our first significant significant venture capital.

Since then, the company has raised 7 funds totaling nearly $2.4 billion, and they've invested in 300 companies, including a couple that we know. Denver's SendGrid and Fitbit were 2 of the companies that they were a big supporter of. Pretty cool. So Mendelson, as he's, as he's moving on to his next thing, he's, he's not talking about going and starting a new company or a new fund. He's talking about getting— concentrating more on music.

He says he's, he's long wanted to do music more seriously. He's considering releasing a new single. And if there's anyone out there who needs a drummer or an up-and-coming bassist, he'd love to hear from you. Yeah, pretty cool. If you want somebody who could, you know, potentially fund your band as well as playing it, then I think he's your guy.

So, so we're going to tour in all the backroad places, but we're going to have a private jet taking us there, right? Is that what's happening? That's exactly right. All right. Nicest instruments.

You know, all that kind of stuff. Anyway, um, some other good news. LogRhythm is breaking all kinds of sales, uh, records, including leading to their most successful quarter in company history. Yep. I was hoping to get in here and read all the details of what that meant, uh, but you know, they are a private company.

They don't need to release numbers, so they didn't. But, but it's great to know. I mean, honestly, this— it really is great to know because it seemed like they were struggling there and call it 2018, 2019, to see, you know, Mark Logan come in and, and help turn things around. It's really neat to see them making a move. I think a big part of their success is this kind of unlimited data package that they're offering.

We've talked about that on the show once or twice, you know, compared to some other competitors like a Splunk where the cost per data gets, gets quite high. That's a differentiator for them, and it looks like it's been successful. One thing that I did notice in the article— actually, 2 things. One, there's a long list of awards that they've won. I'm not going to go through those.

But the other thing was, uh, they, they listed all the executives that they had added in 2019, and it was a lot. They changed over CEO Mark Logan, you mentioned CFO, VP of Engineering, Chief Marketing Officer, and VP of Product. Yeah. So that's pretty much an entire change in their executive suite in 2019. Yeah.

Obviously, you know, they saw a need to make some changes and they have, and it looks like they're being dividends for that. So. Good for LogRhythm. Hopefully that continues. All right, moving along, we have a story this week from Optiv, and this is a follow-up to the, the new NIST privacy framework.

We talked about Coalfire's blog on this a week or two ago. Now Optiv is talking about it and really just talking about how this could simplify the way you look at privacy. Yeah, and the article is somewhat similar to Coalfire's last week. I, I do think that they go into a little bit more detail in terms of the privacy framework itself. The components and, and how it links to some other things.

So if you are again interested in that privacy framework, I think it's a decent article to give you an even more in-depth overview. Yeah, obviously I do think that the privacy framework is going to be useful, so getting more resources is never a bad thing. Next, we had a blog from Swimlane, which, you know, was an ode to Dr. Seuss. So we, we only cover hard-hitting serious news on this podcast, and this is no different than the normal Big, big news we have. So an ode to Dr. Seuss, and we'll call it One Team, Two Team, Red Team, Blue Team.

So if you want, if you want to listen to some children's-ish literature, I think you should go out and pick up this link. Hey, Robb, did you know One Team, Two Team, Red Team, Blue Team, this one has a little hack? I did know that. I'm not going to read this whole book on the podcast, but if you'd like to— Oh, come on, Robb. We can do that after.

All right. All right. Uh, moving along here, we have, we have another, uh, story from our local security team, Red Canary. Um, we've talked about how much we appreciate Red Canary's blog. They do such a good job of going into technical depth that frankly, you know, it's, it's just about giving back to the community.

And this is another one talking about the Heaven's Gate malware on Linux. Um, this might be something you want to take a look at. Yeah. So, um, Heaven's Gate was disclosed recently, but the interesting part was It was disclosed for Windows, not for Linux. And it's sort of a novel attack in that you're taking 64-bit code and running it in 32-bit processes.

It's one of those things where I assume this exists because on the face of it, it seems like it's something that shouldn't work. So I think probably whatever protections operating systems had in place for this just overlooked it. Because someone thought, hey, well, you can't run 64-bit code in a 32-bit process, so why would we even protect against that? Yeah, that's great. And I need to errata myself there.

It's not malware. It's a technique. It's an attack technique. All right. Moving over.

That is it for news. We're going to go ahead and move over to the Slack message of the week. Thank you to Andre Gaeta, who is our supporter for this each week. Andre, out of his own pocketbook, pays for us to give a gift to one member of the Slack community each week who says something we think is worth recognizing. And this week's winner is Scott Bowman.

Congratulations, Scott. Scott posted a link to a cybersecurity scholarship program. It's pretty awesome. So anyone who's looking to get involved, I assume SecureSet would take this, but I'm sure there's lots of other places you could use this money. Really awesome.

Thanks for sharing that, Scott. You'll get one item from the Colorado Equal Security Store with our new logo. Yay, new logo. All right, let's go ahead and move over to the event calendar. As a reminder, on our website, we do have a calendar of events that goes out way into the future.

You can see all the things that might be canceled over the next few months. Due to coronavirus, and hopefully none of those will get canceled. In the next 2 weeks, we have quite a few things that might get canceled. Go ahead, Alex. Yeah, so first on the list, on the 10th of March, SecureSet is doing their Creating a Virtual Lab event.

On the 10th and 11th, ISSA Denver is doing their monthly meetings. So that'll be downtown Boulder on Tuesday the 10th, downtown Denver on Tuesday for dinner, and then the DTC area on the 11th. In a little bit of an ironic statement right now, on the 11th, ACES is doing their Pandora's Box emergency preparedness considerations. I think that will not get canceled. But also no one will be there because the preparations for emergency preparedness are you don't join people in a group.

That's funny. That is irony. On the 12th, ISACA Denver is doing their March meeting. The 12th also has the Northern Colorado ISSA doing their March chapter meeting. Uh, on the 13th, CSA is doing their CCSK+ class.

On the 18th, DenSec is doing their meetup. I believe it's at the Rheinhaus, but you might want to confirm on the website or the Twitter before you go. On the 20th, we have a couple events. There is a Lunch and Learn, GDPR, CCPA, and the Extreme Importance of Data Protection Today, as well as SecureSet doing an evening event with a capture the flag for beginners. Awesome.

Go ahead and move over into jobs. That's it for the next couple weeks there. Um, we at Ping, we have a few jobs open, actually more than a few. I think we got 4 or 5 right now. Uh, we are looking to hire a new one, a manager of security and compliance.

This person will also help us with privacy here at Ping. So if you're looking for, you know, managing a small team, I think it's about 4 people on that team, uh, and you'd like to, to come join Ping, you know, that'd be a good role for you. We're also hiring a product security engineer for those with a development background and an infrastructure security analyst for those who want to do kind of more operational security tasks. Nice. Checker, who we just talked about, is heading— hiring a head of information security.

I think this may be a first person in that role kind of job. Awesome. Cardano is hiring a cybersecurity manager. Zayo is looking for a cybersecurity analyst 2. Vertafore is hiring a security analyst 1, and this specifically says entry level.

Uh, the, the new CISO over at Vertafore is a, is a former, uh, is a Ping guy who kind of moved on to run his own program. That's Stephen Edmonds. I think you'll have a lot of fun working over there and helping build out that, that new function. Uh, Slack is also looking for a security analyst. Kaiser Permanente is hiring a cyber risk defense associate intern.

So intern position. We got a lot of nice entry-level positions this week. And Transamerica is also looking for an information security intern. I think this is the time of year where many of the intern positions start to pop up. And by the way, I think the Ping intern position is still open too.

We haven't, we haven't hired someone for that quite yet, so it's not too late to apply. All right, well, that is it for jobs. That's it for the newscast. And this week we have Jay Wilson, who is the CISO from Healthgrades. Jason Jaques was our, was our interviewer for this, and looking forward to hearing what Jason has to say.

Awesome. I look forward to it as well. All right, thanks everybody. Have a great week. Thanks, Robb.

Hi, this is Mike Kalax. CISO at Western Union. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Colorado Equals Security. This is Jason Jaques, host of Emerging Tech Fan. Here's a question for you: How does a musician turn into a CISO? Well, I found out when I had a fun conversation with Jay Wilson, the CISO of Healthgrades. Here's the interview.

Enjoy. Jay, thanks for being here. Yeah, thank you for having me. You know, it's a cold and windy and otherwise terrible day, but it's still better than the last time we attempted to do this podcast interview, which was snowing like crazy. Yeah, that's a good sign, right?

I take a wind chill of 9 degrees over, you know, 4 or 5 inches of snow, right? Yeah. Yeah, exactly. Yeah. Hey, before we get started and talk cybersecurity, I wanted to dive into the fact that you're a musician.

Yeah. Tell me about that. Well, I've been a musician since I was 7 years old. Well, probably before I was born because my dad's a musician and my mom was a musician. So it was preordained.

But I decided to actually go into it when I was young. My parents had a piano in the house and I just started kind of playing with it. And eventually they said, would you like to do some lessons? I said, yes. So when I was 7, they, you know, they put me in lessons.

And, you know, when you're 7, the world is a certain way. You can only see so much of it, right? And so I remember my very first piano lesson, I sit down with my teacher and sit in front of this large piano, somewhat intimidating, right? And my teacher says to me, she says, Jay, play something for me. And I kind of like, you know, gasped, like, what do you mean play something for me?

This is my first lesson. You're supposed to teach me. That's what I was thinking. I don't think I said that. And she said, okay, play something with these 3 keys.

She pointed out 3 white keys on the piano. Play something with these. And that was my first piano lesson. It was a pretty amazing lesson for piano, but also a pretty amazing lesson for life in general, that if you kind of narrow your— Your focus? Yeah, your scope, you can achieve amazing things, right, in that scope.

Right. So I, you know, back to the music part for a second. I kept playing. I still play the piano. I've played in just the kind of like local band here and there for fun, but not really gotten into anything serious.

My intention was never to become a professional musician because it's a tough life. I mean, I love it, but I'm happy to be a technologist by trade and a musician as a hobby. Right. Do you play more than 3 keys? Nowadays on the piano?

Yeah, you know, I play, I play the piano and most of the keys, you know. Okay. I'm scared of key 67 sometimes. I have no idea what key is what. No, I'm just kidding.

There's no— I'm not scared of any of the keys. But yeah, I play all the keys now. Okay. And, you know, I also played some other instruments along the way. For a few years I played the saxophone.

I haven't played it in years, so don't hold me to that or anything, but I did do that for a while. And more recently, I've been trying to get into the electric guitar. Okay. Um, so I'm trying to train myself how to actually play that, which— making some progress. Yeah, yeah.

You know, nothing like, uh, yeah, playing, playing a little Muse, Knights of Cydonia kind of stuff, you know, that, that, uh, rock What do they call that stuff? It's like opera, rock opera kind of stuff. It's fun. It's fun to play on the guitar. Yeah.

Well, I wish I had brought an electric guitar with me so you could plug in and then give us a tune. Hey, so there's a famous piano player that has a connection to you. So Mildred Portney Chase. Yeah. So tell me the story there.

So Mildred, well, Mildred was my teacher. So she was the one that told me— She's the one that said, play 3 keys. Yeah. Okay. Yeah.

And, um, it, you know, I didn't know this at the time being 7 and having the view of the world that I had. Yeah. Um, but I remember when I was in those lessons, she handed me some books to read about, you know, improvisation and the like. Turns out she was a famous improv teacher. Yeah.

Um, so correspondingly, my kind of chosen style on piano is jazz improv. Okay. Um, so yeah, very cool. And then your dad was a musician too? Yeah, he was a prog rock musician back in the day.

I don't even know what that is. Prog rock? Prog rock? Yeah, progressive rock. I mean, okay, I'm thinking the city.

Yeah, sorry. Yeah, never mind. You know, I, I grew up on a steady diet of Yes and ELP and that kind of that kind of stuff. And he, he was close to getting signed by a record label before I was born. It's probably a good thing he didn't because I might not be here if he did.

You would have had a very different lifestyle. So it's interesting that you, uh, you kind of have a— this musician background or side to you because you were born somewhere very interesting from what I hear. That's right. That also kind of lines up with that story. Yeah.

Talk to me about that. Well, you know, there's, there's a double irony there. Um, I didn't— I don't know if I told you about this part, but I was I was actually born in a music studio. Oh, wow. Okay.

No, you did not tell me that. It was inside the house that we owned, and we lived in Woodstock, New York. It was not in any relation to the actual music festival. I was born many, many years after that. But yeah, I was born inside a music studio, inside the house.

I was not in a hospital. So it was Pretty, pretty, uh, ironic, but it worked out. Yeah, no, I mean, no, no complications. Yeah, I think I'm, I think I'm just weird enough. Yeah, that's funny.

So then where, uh, where have you spent most of your time? I mean, you obviously live here nowadays in Colorado, but where, uh, where have you— where's your life, uh, taken you? Yeah, I've bounced around a bit in life, you know. I, uh, when, uh When I was a kid, my, my dad was in the entertainment business, so he, he broke out of music as a business and ended up in video and, you know, was in post-production. So we moved from Woodstock to Los Angeles, naturally.

I lived there for a while, about 7 years, um, and then in, uh, 19— I think it's '93— moved to South Florida. And I spent most of my time down there in Fort Lauderdale, Miami. Okay. That area of the country. Yeah.

What do you like best?

Well, you know, other than Colorado? Yeah. What do I like best? It's tough. I really love Colorado.

I've been here 4 years and it's when people ask me, what part of the country do you like? I'm like, the one I live in. Yeah. Which I think is a pretty common answer for us Denverites and Boulderites, right? It's just we fall in love with this place.

Um, but there's, there's other great parts of the country. It's, uh, you know, California is beautiful. If you, if you don't have any income, you don't have to pay any tax, right? Yeah, there you go.

Your dad worked in the, uh, the entertainment business. Was it TV shows, movies? What are we talking about here? Oh, it was a bunch of different things. Okay, so he was in that business when we lived in Woodstock, actually.

He He helped build one of the country's first green screen studios with an old-time rocker, Todd Rundgren, actually. So Todd's famous for some Muzak tracks you've heard in the retail stores that you probably love, but you just don't know his name.

Anyhow, he's still making music. He's still out there. He's just prolific. He can't stop, right? My dad and Todd built this, this green screen studio, and they were building, you know, the studio to do music videos before MTV existed, because this was, you know, late '70s that they were doing that.

So my dad would say the best thing that ever happened to him is he got to smoke a joint with Mick Jagger when they were shooting music videos. Yeah. So how did you get into the tech industry, the security industry? Well, kind of similar to music, it was really native for me. Parents got me an Apple IIe when I was, you know, like 5 years old, and I started playing around with it.

And then early on, I, I got into PCs, and I started writing software, I think, when I was 10, 10 or 11. And my very first piece of software was A, uh, I got the PC speaker in my computer to spit out the Empire Strikes Back theme song, right? And, uh, I wrote it in QBasic, you know, that was back, back in the day. Yeah. From there, I just, I kind of knew innately I wanted to do something with computers.

I, uh, went to school actually to build computer hardware. So my degree was in computer engineering, not computer science. But I ended up in software development pretty quickly out of college and really loved it once I started doing it. I had this misconception that it would be boring. You just sit in a cubicle and keep to yourself.

And that sounded boring to me. But when I got into the actual act of creating things with software, I found it exhilarating. Because you were, you were kind of in total control. You, you were the alpha and omega to that computer software, right? It was, it was exciting.

Yeah, the artistic nature, the musician, yeah, came out and, uh, came out in you, I suppose. So I, I was good at it. I did it for a while, uh, ended up leading teams of people that did it. Um, and then, then it kind of branched into business a little broader. Um, I at the time worked for a startup, and just kind of through timing and, and luck, I ended up becoming the chief technology officer of the startup.

Okay, um, what's the startup called? The startup was called RMS Networks. Okay, it was a, it was a company that built a network of televisions in retail stores. Okay, and, uh, it was kind of a turnkey agency of sorts. So we had all the technology to send the video across the nascent internet at the time.

We were using DSL and satellites and all sorts of bubble gum and chewing tape kinds of solutions compared to today's internet connectivity. And then we also had a video production house inside the actual agency. So We had kind of an end-to-end solution for clients. It was very interesting to be a part of because you're, you're real close to that creative side, hence, you know, tapping into my creative side, but also very deep technically trying to solve problems that hadn't been solved. So it was almost like an R&D job because back then you couldn't do these things.

It's not like there were predetermined methods for it. You had to invent things to actually make it happen. So it was, it was a total blast, of course. Yeah. Um, but it's a startup, and some startups, you know, blow up.

Some startups, I mean, blow up in a good way. Sometimes they blow up in a bad way. Yeah. And so you, you go through those, those times, and, uh, I ended up doing it again with my CEO, who's, who's a complete visionary. We just kind of took the idea and spun it around and— okay.

Um, started another company together. And, uh, what was that one called? That one was called RView. Oh, okay. It was a, uh, it was a digital out-of-home ad exchange.

So the concept was like take Google AdWords and, and, you know, map it to those screens that we just hung up in all the retail stores, sell the space, right? Yeah. Um, so it was cool. We built a platform from scratch. Yeah, that company may still be around.

I, I don't know. I haven't kept tabs on it. But the first one's not though? First one's not for sure. Okay.

Yeah, yeah, because I was, I was there when it, when it sadly was, was put down. So was this during the dot-com bubble or when was this? It was after. Okay. It was— so the RMS Network started right before the dot-com bubble.

Okay. And then we rode a bubble out, kind of. We rode the pop of the bubble out and and stayed in existence, surprisingly. But yeah, our view was like 2010 or so. And then I ended up at a marketing agency, which was great because, again, kind of real close to creativity.

Ended up at Sapient Nitro down there in Miami and led teams to develop technical solutions for big Fortune 500s and the like. It was a blast. It's interesting you mentioned that because I've noticed you have a marketing background, right? Is that fair to say? Yeah.

How did that come to be? And yet we're on a cybersecurity channel. Right. Confusing all of the listeners right now. Yeah, yeah, yeah.

So what is your marketing background? Oh, well, I mean, mostly just through, you know, adjacency. But when I was at Sapient, they took me through an executive MBA program, and that was a transformative program for me because obviously any schooling like that can be significant for you, but what they really focused on is they took technology folks like me. I mean, I'm a geek through and through, and the goal was to convert us to become marketers. OK. Because the thinking being, if we're both marketers and engineers at the same time, what kind of power is that that Sapient would have under its 4 walls, right?

So they had psychologists, speech pathologists. They had all of these different components to the program, teach us the science of storytelling. It was broad. And it was a year-long program with a global cohort, just like an executive MBA, right? Would typically, but the focus was in that reshaping of us into a marketing mindset.

So that's my technical background in marketing now, that I came from that. And when I came to Healthgrades, I actually came here as their head of marketing technology. That was my first title, was VP of marketing technology, if you look at my LinkedIn profile.

I quickly kind of ventured a little bit more into the technical and product side and took on our CRM system for what we called kind of like our B2B software and started redeveloping that and delving into the product development. We built some new products out of that. One's called HGCRM and it's You know, it's, it's a, it's a product we're proud of. Yeah. And then, uh, about a year and a half after I started that, I, I was asked to fill in kind of in a temporary context as the CISO here.

Okay. And, um, it, uh, it was an interesting experience because I did really kind of like my my teenage perspective of software engineering being boring and you sit in a cubicle and you don't interact with anyone, I had this maybe immature perspective of cybersecurity and especially the role of a CISO, right? What we do as being very one-dimensional. But the more I dug in and I had this kind of opportunity just put in my lap, right? The more I dug in, the more I realized this is a hugely dynamic role where you're interfacing with clients and your internal clients and you're interfacing with kind of that policy governance law perspective, which I almost became a lawyer too, which is another story.

But then you're interfacing with the deep technical solutions and the security infrastructure, and then you're interfacing with the kind of the intelligence side of the business. So if you think about the role, it's really broad. You're playing all these different components. So one meeting or one day you're putting on your client-facing hat and you're talking to clients about the business and the value that the company's providing to them. And another day you're talking about Damn it, you better make sure your password is reset, or is it this long, or whatever, right?

The technical components. And there's a lot more than that, of course. So it's very broad and I've enjoyed it. So I pushed and extended myself to try to take this role on in a permanent context. And I've really enjoyed it.

I've been the CISO here for About, uh, 2, a little over 2 years. Okay. No regrets? No, none, none whatsoever. It's, it's at times stressful.

Yeah. But every, every role is. Any, every role that matters, that's fair, I, I would say is a little stressful at times. Yeah. I, I find it interesting.

I, I heard you mention something before about being in marketing and how you ultimately switched teams between being the user of data to now you're the protector of data. And I kind of thought that was a very interesting way to put it. Yeah, it's true, actually, because when you're building the product or you're on that marketer side, you're really focused on how can I leverage this asset that I have to do the thing that matters to me? When you're on this side of it, you're really focused on, well, how can I allow the business to do what it needs to do to leverage that asset, but do it in the right way? Do it in a way that's compliant, that's contractually compliant, ethically compliant, all of those kinds of— you're looking at it from a completely different perspective.

It's almost like inverse or negative film to the same What do you think marketing people should know or understand about cybersecurity and protecting their data? It's a tough question to answer. Right. Throwing me those really easy 10-cent questions there. Yeah.

I appreciate it. I would say as a marketer thinking about cybersecurity, it's complicated and you shouldn't oversimplify how complicated it really is. There isn't a magic wand and data is, you know, data licensing is complex, data compliance is complex, all of those things are. So don't underestimate that part of the process when you're using data. That isn't to say that you shouldn't be thinking broad and wide and be creative about how to use it.

It just means that maybe you should add that to your thought process a little bit more. Sure. Do you have any mentors in the industry? I've had a few along the way, um, so I would consider my former boss at Sapient a mentor for sure. Okay.

His name is Scott Petrie. Scott, I'll have to send him this link. He runs— I think now he's the CTO of North America for Publicis Sapient. But as far as people that have shaped my view of how to lead people and how to manage people in a more servant leader context and growing me in that way, leaps and bounds, right? Just, um, and I'm still— I still try to stay in touch with Scott from time to time.

He's, he's also probably one of the most fun people to hang out with. Yeah. So, and we've both carried each other, you know, uh, slightly inebriated before. Okay. You know, from, from a car or two.

Sure. So we, we have some innate bonds, right? Yeah. When you've been, you've been in the trench. Right.

Yep. We've all been there. Yep. In terms of cybersecurity, then you've, you've now been doing this. You've been in your role for 2 years.

Um, you've done obviously a lot of things. We've talked about you being a CTO, being involved in multiple startups, being in marketing, a musician. How do we get more people into the world of cybersecurity or interested in cybersecurity, including more diversity. Do you have thoughts there? Yeah, it's an interesting question.

I think that part of it is that we need to think outside of the box from where do these talented individuals come from, right? So traditionally, cybersecurity has been a very— it comes from an infrastructure or it comes from an information services type pool and you look in that area or maybe compliance, right? But because it's such a pivot role where you're playing all sorts of different roles within the role, I think you need to look outside of where you would typically look. In my case, I came from the development background. I think that's definitely an area that we need to spend more time thinking about because cybersecurity is leading more into software development, especially at a product company.

You've got a lot more challenges for cybersecurity. It's not just about protecting your information systems, I say in air quotes. It's about helping those product development teams develop things in a secure way. And there are many industry leaders here, even in the Colorado market, that are really great at demonstrating that. But having that deep background in product development and software development, I think, is a really critical component that we need to be looking more for.

I think as far as other areas, just being open to talent comes in lots of shapes and forms, right?

And I think that generally technologists have had that mindset, but maybe cybersecurity being where it came from more on the legal IT side of it has had less flexibility in how they look for that talent. So when I was hiring software developers, it didn't matter what your resume said. If you could do it, I'd hire you, right? So I think that cybersecurity needs to take more of that mindset of like, do you have the raw talent? Do you have that aptitude?

And we can help shape people into the career path as such. Yeah, yeah. That kind of leads into something that I've heard about, a learning academy that you've set up. What is that? What's the background of that?

Can you— Yeah, so here at Healthgrades, and it's in its infancy. We've only run through this one cycle here. At Healthgrades, we set up what we called the Healthgrades Learning Academy, and it's part of our overall learning development kind of program set. So we have a lot of different components to it. But it was largely inspired by my executive MBA program, and I took a lot of inspiration from specific components of that teaching that I received.

And I said, well, I want to give back on this. It was such an enriching experience for me personally. So my focus with the Learning Academy, which I chair here, is really to develop in key staff. It doesn't really matter what departments or where the talent comes from, so to speak, is the value of leveraging storytelling. So no matter what your function is in the company, being able to clearly articulate and communicate things is a critical skill.

And it makes us a better company if we get better across the board, right? OK. So it's almost like turning these people into marketers? I don't know if it's quite that extreme. I'd say it's more— I had to go there.

Yeah, the goal is not to turn everyone into a marketer. The goal is to turn us into a better, more functioning set of communicators, right? Yeah. So there's a lot of other aspects to marketing beyond communication that you have to learn. I'm not focusing in those areas.

What I am focusing in is the value that clear, concise communication, the science of storytelling components, all of those things matter to people because they're universal. You could be a software developer and you need to communicate your idea. You could be an operations manager and you need to communicate your idea down to your staff. It applies to everyone. What are you learning as you go forward with this learning academy?

Well, every time you work with new people, you always learn things, which is the secret benefit of being the teacher always, right?

Every time you learn something new from each person, makes you a better person effectively as the teacher, if you're open to that. And hopefully you are if you're a good teacher. From each of the, the students, um, you know, I've learned just great things. I, I get creatively inspired by them, like just to see the energy they have in particular ways and shapes and so forth. Yeah.

Were you ever a hacker in your, uh, early days? Let's talk about this. Yes, I was, um, albeit not necessarily a good one, which is probably a good thing. Yeah. In the sense that I never got in trouble because I never really successfully hacked into much of anything.

I was going to say you got away with it.

At least that's the on-the-record story. Yeah. So what's your story? Let's hear it. Well, you know, in high school, early college, my best friend and I, we just, like all geeks who wanted to do this stuff, just decided one day, well, we're gonna, we're gonna start trying different things, right?

We, uh, we had modems and landlines and we knew what to do with them. I don't know, I, I, we, we tried war dialing one night, which was hilariously stupid. Um, many of you probably don't even know what that means, but I'm sure you basically— yeah, you basically take your modem and you point it at a a bottom set of numbers and you say, okay, I want you to dial these 10,000 numbers in the middle of the night and try to connect to a modem on the other end. Of course, that resulted in a lot of angry calls the next morning because we did it in the middle of the night and it wasn't very discriminate about who it called. So that was a one and done.

Never did that again because I'm not sure we were bettering the world in that moment in time by calling people at 3 in the morning with a modem on the other end. And it was pretty dumb. Pretty dumb. I don't know. We also attempted to build, and were not successful, but attempted to build what was called a blue box, which is a set of analog electronics to insert, so-called insert a quarter into the old analog payphones.

Gosh, what are payphones? I don't even know what they are anymore. I know. Where did they all go? Yeah.

Where did they— is there a payphone graveyard somewhere? I don't know. Be, right? Because they're like— you don't even see the, the empty little areas where they used to exist. I, I don't know.

There's got to be a payphone graveyard. We got to find it. We got to figure out where that is and find the link and post it as part of this podcast. There's lots of quarters out there still. They're ready to be collected in the graveyard of payphones.

Yeah, I'm not sure. Or at least, or at least phone handsets, right? I'm not sure about— I'm sure somebody cleared out the quarters. Yeah, fair enough. As CISO here at Healthgrades, what are some of the challenges that you're finding relative to your kind of niche in the industry, healthcare?

Yeah. Are there some things you can talk about? Sure. I mean, I think that like any CISO in a product company, there's challenges in that your enterprise needs to develop new product and needs to move fast. And that's always a challenge, just in slowing down just enough to do security at the same time, right?

So there's always that push and pull and tension. I would say in healthcare especially, there's added pressure and added focus. And our team across the board, our executive management team, our engineering leadership, they definitely understand that. But that doesn't necessarily eliminate the tension associated with the sensitivity of healthcare data. And Healthgrades, by and large, handles quite a bit of sensitive data.

So it's critical that we stay focused and have that tension in place because otherwise it could yield to bad results, right? Yeah. And you have the added challenge of integrating other acquisitions that you guys have. Yeah, we've been rather acquisitive in the last few years. Is that the word for it?

I, I don't know. If not, I just made it up. Okay, I like that word. Let's go with that. Yeah.

But, you know, that always brings challenge to integrate teams, integrate another enterprise, of course. And I'm sure a lot of listeners have done that Personally.

What's great about it, just like what I mentioned before, is you learn from the process. So in the context of recent acquisitions, we've got new talent and new staff and some real brilliance on that side that we can bring in now into the larger Borg. What's DraperBot? Let's talk about that. DraperBot.

So I mentioned the executive MBA program that I was a part of. And like any good MBA program, there was a thesis component, right? And my thesis was focused on how do you use machine learning or artificial intelligence with globalization. Okay. And so where I ended up focusing after, you know, you circle around when you get into these big topics and what you're going to write about and try to prophesize, right, to some degree.

I ended up writing a white paper. It's available on the website, Draper Bot.

And the focus was on data analysis against global values perspectives, meaning does someone who comes from a particular background, they were raised in a certain family unit shape, size, do they have a different perspective from someone on another side of the world who grew up in a different set of circumstances? And how does that influence how you would communicate to someone? Do you shift your communication around Do you change it, et cetera? The data yielded an interesting result, which was that we all tend to care about family, and we all tend to care about the things we think matter most, like family and those that we love, friends and family. So in a lot of ways, our core values at the deep heart of it are very similar, even though we express them in wildly different ways across the globe.

So instead of trying to get into the minutia of that, what I broke apart was that the communication device we use, the words that we use, those semantics, there's still nuance in how we do it. And the software— so I wrote a white paper, and I also wrote some software that's on GitHub. The software basically analyzes a set of words against a graph database that I had extracted from one of the dictionaries. And I would take a set of core values that are published. You could start with whatever.

Everyone's heard of Maslow's theory of needs. But I used a different core value set. I used these 5 core values that we all have as human beings— a desire to learn, a desire to bond, a desire to acquire, a desire to protect. And what was the last one? Oof, it's been a little while.

It's been a minute. In any case, it's on the site and in my white paper. And what it would do is it would analyze a website and say, okay, well, this website's angling towards these core values in the tone that it's using. And to prove it out, I would take Associated Press articles, and I would take the same article on, say, Fox News against the same article on CNN. And they should be the same, right?

But they're not. They're tonally different. They use different semantics to appeal to different parts of who we are, right? So CNN angled more towards desire to learn and desire to acquire. Fox News angled towards desire to protect and desire to bond.

Um, it was, it's fascinating. You take the same AP article and get those results. Yeah. Um, and it was just using— it was just measuring a score against how many words off a synonym set, right? So what did you learn from that?

Well, something that we all already know but don't practice, which is it matters which words you use and which order you use them. Yeah, right. I mean, how you say what you say matters almost as much as the, the what you are trying to say part, right? Okay, right. So if you're— if you say it in the wrong way, you can— it can mean something different.

Harder to practice than to know, but, um, but it was an interesting result and Again, the software— I put the software out there hoping that maybe somebody would extend it and do something interesting with it because there were a lot of applications for it because you could take it and translate things effectively from one emotional state to another or whatever, but have the same meaning, right? Yeah. So let's talk about something that I know you're heavily involved with, a 405 committee. First of all, what is that? Can you explain that to our listeners?

Yes. So some of you may know if you're in the healthcare space or have heard of this, but there's a government-run subcommittee. It's called 405 Task Group officially. It's a, you know, they definitely had some marketers on the team when they came up with that name. Oh, sure.

Of course they did. Or lack thereof. Yeah. Um, and it's a group of about, I think it's about 500 individuals such as myself. Okay.

Wow. That many. Yeah. And we're all volunteers. And the, the purpose of the group is to help define cybersecurity standards for smaller to mid-sized healthcare organizations.

One of the big challenges is that cybersecurity problems don't really scale in the shape and size of a business, right? So you could be a smaller healthcare organization, you still have all the same constraints and requirements of a bigger organization, maybe, and hopefully some less, but you still have to be HIPAA compliant and you still need to have a cybersecurity position and approach, even if you're just a single physician in an office handling patient data, right? So how do you do that? How can we help people do that in a way that makes the most sense? That's effectively the purpose of 405.

And both myself and our privacy officer, Seth Cedars, are on the committee, and we attend the meetings and try to help craft some of the the communications. And it's effectively just a community-driven group that's trying to get the right message out for all of these smaller, mid-sized healthcare organizations. Is there— have you noticed a positive impact or outcome to the efforts you guys are putting in? It's early for me. So I joined in Q4 last year.

Okay. But I've been, you know, looking through the materials that we publish and they're great because they take a lot of what we do that's technical and detailed and takes time to learn and simplify it and kind of take it down from, okay, maybe I'm not a cybersecurity expert, but I can understand what this, what this is teaching me or trying to teach me. Yeah, it's still a little overwhelming. I think that's the, that's the hard part, is, um, if I were, uh, you know, in the shoes of a single physician trying to, to manage this problem, it would be over— very overwhelming. Um, so can't solve that problem necessarily, but we're trying to make it simpler and trying to say, hey, this is how you could prioritize.

These are the things that matter most. These are the things that matter next most, and so forth. In the single physician scenario or even a startup scenario, how do they know this information's out there? Well, hopefully from us discussing it is one avenue. So getting the message out in every format.

The government subcommittee is— it's a government subcommittee. So the government doesn't spend a lot of dollars in marketing and so forth. But the information is available if you Google it. So, okay, you know, it's out there and you can download all these materials. And non-technical people, non-cybersecurity people can digest this information and put it into practical use?

I don't know. It's a great question, and that could be a component that I end up helping and working on with the committee. It's certainly probably an area that needs more focus, I would say. The challenge is you're over here, you're a 1 or 5-doctor practice. How do you go from running your practice to knowing that you even need to care about this?

Right. It's kind of a bit of a jump. I think if you start thinking about HIPAA compliance, you might make that leap because the organization is intertwined with OCR and Health and Human Services. OK. So it's funded predominantly from them.

So if you start going down that train of information on the government websites to learn about HIPAA, you may see this or you may find it upon a Google search. But if you don't even care, you're, you're, you know, and you're not thinking about HIPAA, then you probably won't find it, right? So if people are going to follow you, what should they follow you on? Oh gosh, I don't know. I guess I have a Twitter account.

I'm not on Twitter too much, but every once in a while I read an amazing article, uh, and I tweeted yesterday actually, which is like the first time in I don't know, six months. I'll have to go out and check it out. Your handle is JW Inspire. That's right, JW Inspire. So you can definitely follow me there.

You can find me on LinkedIn. Those are probably the two best places to find me. Awesome. Yeah, Jay, this has been a lot of fun. Yeah, thanks for joining me today.

Thank you. That concludes my interview with Jay Wilson. Thanks for listening. Be sure to follow and support Colorado Equal Security on Patreon. This is Jason Jaques saying, be safe and secure out there.

The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood.

Back to all episodes