Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 162 for the week of April 27th, 2020. Alex, we're what, 7 weeks into this?
This stay-at-home order here in Colorado. How are things going at the Wood household? Is it really only 7 weeks? 7 weeks, 7 years, 7 lifetimes. Man, we're a long time in and there's actually, I guess, some promise that maybe we'll come out the other side.
Yeah, sounds like we've— well, we did just see the stay-at-home order extended another week for our counties, right? To May 8th, I believe. Yeah, the statewide is, is expired, but seems like everybody wants to stay home at least another week or two. Um, and even with that, the— even though they weren't renewing the stay-at-home order, everything, you know, based on the state guidelines was still pretty locked down. Yeah, well, I am, I am looking forward to at some point getting to see people in person.
That will be fun whenever that happens. It sure will be nice. Speaking of seeing people, we do have a Slack channel where you can see over 1,400 of our closest friends there and, and talk to them virtually. Yeah, you can see their little avatars and icons, which is about as close as we can get to people these days. If you want to join Slack, you can go out to colorado-security.com and click the Slack button on there, and that'll get you in.
We also have a mailing list. If you go to the website and scroll to the bottom, there's a form for you to sign up. Put your email address in there, and you'll get the show notes delivered to you every week in your email. We would love it if you would rate us and subscribe on your favorite podcast listening app. That's a good way for us to find new listeners.
And of course, another way we could find new listeners is if if you would be willing to tell a friend, anyone who you talk to in quarantine, who you talk to before quarantine, after quarantine, anytime, let them know about the podcast and hopefully we can get some more folks to come get on the security bandwagon. We, we really need real friends though, not imaginary friends. I would imagine that at this point there are a lot of people that are just sort of talking to themselves. So our online imaginary friends are called Russian bots. Is that what those are?
We'll take Russian bots. That's fine. It'll boost the numbers up a little bit. Um, if you want to contribute financially, you can join our Patreon campaign. There is also a link to that off of the website.
You can sign up and help cover the costs that we have for the show, and depending on the level you sign up for, you might get cool stuff. All right, moving into the news. I will say I have several times this week grumbled at Alex that there is no news worth talking about, so what you're going to get here is just our witty banter about some crappy news. Sound good? So we're going to talk about the news that's not worth talking about.
To start off, uh, the U.S. Space Force, which we have talked about and is interesting here in Colorado, they have added $378 million to Raytheon's Colorado-based GPS contract. It's pretty exciting. Yeah, I, I think one of the funny things here is— well, there's a few things, but this is the the latest modification that makes the contract $3.7 billion. And I believe that the original cost for the contract was something like $800 million, $866 million. So I think they've gone over budget a little bit.
Well, it's good to be Raytheon and it's good to have a government contract in these times, huh? Yes. The other thing is the addition in this cost is to change their hardware from IBM to HP. Are they getting over to some AS/400s? Or getting off some AS/400s, I guess?
Yeah, maybe. Who can say? It's just, I think, an excuse to spend more money. And guys, I would point out that we always put the big story first. So expect, expect the rest of these stories not to be so exciting.
Go ahead, Alex. Next. Robb, there are several Colorado accelerators. And you know what, just like everybody else, they're adjusting during the coronavirus. So I think we all know Techstars in Boulder, which is, you know, we've talked about on the show quite a few times, we've actually had one of their general partners on the show in the past, Brad Feld.
So Techstars, there's an accelerator called Boomtown, and Innosphere Ventures, which is actually up in Fort Collins. Those 3 accelerators have moved online, so they're continuing to, to do their cohorts, but they're giving the support and their meetings online in, you know, kind of virtual Zoom-type meetings instead of in person. Yeah, and the 4th that was talked about in the article, Exponential Impact, which is aligned with the National Cybersecurity Center down in the Springs, they actually postponed their cohort to the summer, and they are reopening applications in June. So that if you are interested what's happening with those accelerators, now you know. 3 of them are still happening, one's postponed.
Moving on to our next story, a Denver-based company called Storexcel has been acquired by the Baltimore firm Chesapeake Systems. I feel like I've heard of Chesapeake Systems before this story, and I can't remember why. Do you recognize that name? Well, I mean, I know Chesapeake Bay. I don't know if I know Chesapeake Systems, but yeah, you know, this is big news, Robb.
Large acquisition here. StoreXL, which does have some names on their clientele list including NASA and Cronkite Sports and Entertainment, they have been acquired. StoreXL has all 4 of their employees will become part of Chesapeake's team. And they will— those 4 jobs will stay in Colorado, which of course is incredibly important to those 4 people and their families, but also just good for the overall Colorado economy. Yes, it is.
In some security-related news, Cognizant, which is not based in Colorado but has a large presence here, has confirmed that they suffered a Maze ransomware attack and is causing some disruption to some of their customers. Yeah, so Cognizant is, uh, they have a big office in the Tech Center area. They were previously Trizetto, or excuse me, Trizetto was headquartered there and was acquired by Cognizant. We don't— I don't know off the top of my head exactly which part of Cognizant was impacted. I've heard, you know, kind of rumors and some updates over the course of the week that it was a really significant impact internally, and like internal email was unavailable for a while.
So they are— they're dealing with a big impact. One of the things that makes the Maze ransomware strain especially pernicious is that rather than just encrypting, they're known for uploading files to servers outside the organization, and if you do not pay, they'll post that information publicly. As of the, the report I saw, um, they had— there has been no public posting of the Cognizant data, so I don't know if that means Cognizant paid or, or, you know, something else has happened in the meantime, but it's interesting to note. Yeah, there are a couple things that I took out of this article. The first was According to Bleeping Computer, the Maze hackers, the folks that run the Maze gang, denied responsibility for the attack.
So even if it was the Maze ransomware that was used, maybe someone else was using it rather than the normal group. And then also there was an update at the bottom of the story. On Monday, Cognizant made an SEC filing and noted that there may continue This attack may continue to cause an interruption in parts of our business and may result in loss of revenue and incremental costs that may adversely affect our financial results. So if you're making an SEC filing about a security event, then it's pretty serious. Yeah, they actually withdrew their guidance for the rest of the year.
Basically, as a public company, you're supposed to tell analysts in the stock market, you know, here's what we expect our revenue to look like this year. And then, you know, you're kind of guiding people toward your revenue, and generally people kind of sandbag a little bit on that. They actually came out and pulled back their guidance and said things are too volatile right now for us to know. Now, this is a combination of the Maze ransomware, but it's probably also related to COVID, as you know, all kinds of companies are not sure what that impact is going to look like, and any of that guidance is probably dated until we figure out exactly what the impact of COVID looks like. Yeah, for sure.
Next, some good news. Randori, they announced a Series A and raised $20 million, which is pretty cool. Yeah, I think this completes a Series A. I believe they, they're now at $30 million total, which is honestly $30 million for a Series A. That's, that's a lot right there. These numbers are, are pretty significant.
Um, good for them. They're— although they're not officially headquartered here in Denver, I think most of their employees are, are in the area. Um, I think their, their number one headquarters out in Boston, is it? Yeah, it's in Waltham near Boston. Yeah, they say that they're going to use this, this new funding to, uh, to invest in innovation on their ATT&CK Anywhere platform, which really looks like they're gonna be hiring more engineers and hackers to join them.
So it does not say they're gonna go staff out marketing and sales, which is what I normally expect from this kind of a round. So I'm looking forward to seeing what they do with that next tech group. Yeah, they do have a bunch of open posts on their website. So I think we even have one of them in jobs this week, but if you're interested in a job, they have some. Fantastic.
We have a blog post from Coalfire this week about privacy by design, building customer trust. I know I put this in the show notes for us to talk about this week because I am— this is something I think about a lot at work. And, and, you know, we've for a long time thought of privacy as maybe a compliance regulation we need to adhere to, something you kind of engineer back into. And the world is changing. And really, for us to be able to build this the right way, it's a lot like having to build security in earlier.
You can't build privacy in at the end of a process. So they're talking about what is privacy by design look like? Why is it important? How does it make a difference in the market? And really, how do you go about it?
So they have a 9-step process or 9 different ways you should think about getting privacy into your product or process lifestyle. And I think it's worth reading if you run security and you care about privacy, or especially if you're someone who, who's responsible for privacy and compliance in your organization. Yeah, most definitely. Next, there was an article in the Business Journal this week about Ping Identity talking about wanting to secure your working from home. It was in the— it was Richard Byrd, who is Ping's Chief Customer Information Officer, really just talking about how do things change when you're working from home and really how essential authentication is as a part of this.
I don't think there's anything in this article that's going to be noteworthy for folks who already know much about security and identity. To me, what's interesting is the fact that this was on the front page of Denver Business Journal. This is, you know, becoming a top-of-mind concern for businesses, not just for security practitioners. Yeah, I did think it was interesting. A lot of times you have articles like this that, you know, talk about wanting to work securely from home and they give you a list of, you know, 5 or 10 different things you need to do.
This was really just pay attention to authentication. Yeah, you know, right up Bing's alley. Well, you got to know who it is, right? And that's basically the point is, do you know who's connecting? Bad guys want to connect as well.
Next, we have a blog post from, uh, from LogRhythm talking about lateral movement and how to detect it. And I thought this was especially interesting because, you know, while we all know lateral movement and the fact that once someone's in there, pivoting around is important, it's really nice to see a company that's in the weeds talk about, well, specifically here's how they do it and here's what you can do to detect it while they're doing it. Yeah, um, they go, uh, pretty in-depth too, and they have a list of lateral movement use cases that you can use. To think about in terms of, you know, what you might be detecting. And so I think that that's a really good resource if you're trying to build out some of these capabilities in your security monitoring stack.
Yeah, and what I appreciate is they also have a list of the most common ways that they do lateral movement, you know, pass the hash, pass the ticket exploitation of remote services. I'm not going to go through all of them, but, but it's nice maybe as you're building out your SOC and you're alerting in your SIEM, this is a way for you to make sure that you're thinking about all the most common types of lateral movement. Anyway, like, it's a nice resource I think you should share with your operations team. Yeah, definitely. Next, we have a post from Webroot talking about DNS being on the verge of a major overhaul, and I don't know if I would agree that it's necessarily on the verge of a major overhaul, but the gist here is that there is a big push to add encryption to DNS, which is definitely a big deal.
Yeah, I think that what they're really getting on board here is this, is this train around moving to DNS over HTTPS, which has been a drive from the web browsers and some of the OSes for what, like the last year or 2? And, and I know Firefox and Brave and Chrome have all been playing around with what should we do here, you know, do you make it the default? Do you— and there's, there's, there's pluses and minuses, right, from a privacy perspective. This is a really good thing. People aren't able to see all the different connection requests you're making for, you know, if I go to espn.com, well, do I want everyone between me and the DNS provider to know that that's what I'm trying to do?
If you do it over HTTPS, it's just an encrypted string, right? They don't know what I'm asking for. So it's interesting to see that on the other side, what the negatives, if you're a security department and you use DNS as a way to look for suspicious activities, to look for command and control servers, to look for people who are doing inappropriate things on your work system, systems, this really gets in the way, and so you don't have the ability to use that as a mechanism anymore. Yeah, I would say that the, the positives probably outweigh the negatives. I think you can probably get around the negatives, but, uh, yeah, there are— nothing is ever perfect.
Yep, agreed. Interesting stuff, and I'm glad that Webroot, they make it approachable, right? Webroot is often writing for your less savvy audience, and I think that if, you know, if you haven't yet thought about HTTP Excuse me, DNS over HTTPS. This is a good way to get an introduction to it for sure. Our last blog here is from Red Canary, and I thought this was interesting.
They always do such a good job, you know, not them— it's not about their product, it's really about the, the kind of community more largely. And they're comparing 3 different open-source attack simulation platforms for red teams, which by the way is awesome that there are 3 of these platforms available to even to talk about, right? Yeah, so MITRE's Caldera, Of course, Atomic Red team from Red Canary, and Hunters Forge has a product called Mordor. I didn't even know, I never heard of Hunters Forge or Mordor, so that's interesting. Yeah, I think I have heard of Mordor before, but I really don't know a whole lot about it.
Caldera was, was really the first tool that came on, on the open source market. They kind of might have put that out sort of along with the ATT&CK framework pretty early on. And so the article is really good though, talking about the pluses and minuses of each of these and, you know, why you would use one over the other, coverage, lots of different things like that. So if you are looking for an open source tool to test your defenses, this is definitely a good read. Yeah, I think it was good, worth looking at.
It looks like Atomic Red Team has, you know, going forward, it does have the best coverage over MITRE. But was it— I think it was Caldera that has a website you know, web app versus having to have an installed application, which is going to be a plus for a lot of folks as well. Definitely. All right, that is it for our stories and, you know, that heap of news that we just dumped on you guys. Sorry that we had to give you so much, uh, big breaking news.
Uh, so let's move over to Slack Message of the Week. Uh, thanks to Andre Gaeta for sponsoring the Slack Message of the Week. If, uh, he does this out of, uh, the goodness of his heart and You know, pays for this out of his own pocketbook. So every week we award someone with a Slack message of the week and they get to choose an item worth $25 from the Colorado Equal Security store. And Robb, who is the winner this week?
It's Wendy, and I don't know Wendy's last name, but she was actually member number 1,400 to join the Colorado Equal Security Slack workspace. So we're excited to get those milestones. And Wendy, not only is she Did she just recently join the workspace? She's also just recently made the move over to security from an HR career and was posting there looking for career advice. So we, you know, want to amplify her voice and those who are interested to help kind of give some guidance for someone who's making that move from HR to security, get out there into Slack and help Wendy out.
And of course, we would love to, to, to have you contribute to the community even more broadly. Definitely. Good stuff. Congratulations. So Wendy will, will get an item from the Colorado EcoSecurity Slack store, excuse me, store, um, to help her with her her move into the security field.
All right, let's move over to events. As a reminder, we do have a calendar of events that are mostly not happening out at colorado-security.com, so go out there and think about the things that you could be going to if they were going to occur. Uh, this week, uh, first DerpCon is happening. This is a virtual conference that has sprung up, uh, locally organized, so you can check that out on April 30th and May 1st. I am actually super excited about this next one too.
The Global Cyber Alliance is doing a DMARC boot camp on the 4th of May, and, and And if you don't know how DMARC works, if your organization isn't leveraging this for email security, I think this is a really worthwhile exercise for your team to learn about. So get out there and do this virtual learning opportunity. Yeah, I'd say definitely check that out. DMARC is, is not something that is extremely hard, but there are some complexities and intricacies to it. So learning about it is a good thing.
All right, let's go ahead and jump over to jobs. We do have 10 jobs worth talking about this week. At Ping, we are hiring a GRC analyst if you're interested in getting involved with a high-tech company growing quickly and really helping us deal with risk and talk to customers about how we do our security program, do compliance work. We're looking for someone to help join that team. You can go swing out to pingidentity.com and look at the listings there for careers.
Trustwave is looking for a TAC senior engineer for SIEM. Akamai is hiring a security consultant. And RAL is looking for an information systems security officer. NTT Data Systems is hiring an information security services manager. SEL Health is looking for an IT risk and compliance analyst.
I think working at SEL Health would be really interesting. Howard Hale, the CISO over there, is a friend, and they have some interesting stuff going on right now, especially as they're dealing with COVID I think you'd, you'd have a fun time working at SEL Health. Uh, next, you did mention this earlier, Randori is hiring a red team security engineer here in Denver. Yeah, they have a number of jobs on their site, so if Red Team Security Engineer doesn't seem like it fits you, go check out some of the other ones. Twilio is looking for a Senior Product Security Engineer.
On Deck is hiring an Application Security Engineer. And Lockheed Martin is hiring a Defensive Cyber Engineer. I like that. That sounds like a lot of fun. Well, that is it for the news.
We do have a feature interview this week. We have, uh, John Hubbard sat down with Mike Smith, who is the Master Technical Architect at Salesforce. So as you listen to this, number one, Mike Smith's obviously a really cool guy, a lot of interesting background to share with us. But you'll notice that this clearly took place before the quarantine hit— went into effect. So some of the things he says is a little bit dated, but just goes to show you what the world used to look like.
It is hard to remember, but this will be a nice trip down memory lane. All right, well, that is it for us, guys. Thanks a lot. We'll look forward to talking to you again next week. Thanks, Robb.
This is Brian Becker, Director of Information Security at Cronkie Sports and Entertainment. You're listening to Colorado Equal Security, for Colorado security professionals, by Colorado security professionals. Hello, Colorado Equal Security. This is John Hubbard. I'm sitting here with Mike Smith.
Mike, how are you today? I'm doing great, John. Good, good. It's springtime in Colorado. You have any upcoming trips planned?
Upcoming trips? I've got a number. All right. Now I've canceled all my work trips, what with the coronavirus going around. Sure, can't be too careful.
Scheduled to go to Mexico next week for a week. For work or for pleasure? For pleasure. Oh, that sounds great. Yeah.
Okay. And then anything past that? Past that, I'm going to Moab in April for four-wheeling. That sounds great. Okay, so are you an outdoorsman?
There's a lot to do in Moab. There is a lot to do. I drive a 4-wheel drive Jeep, a Jeep Wrangler, and try and get out to Moab a couple of times a year. End up in Colorado several times a year on the trails. Is this one of those Jeeps with the monster tires and you could probably crawl underneath it, it's jacked up so high?
Part of the way there. It's monster-ish. Yeah, all right, so 4-wheel drive out on the slickrock of Moab. Are you part of a club or just going out there with the family or what? I'm going out with my family.
I've got an 11 and 13-year-old and my partner come out and we've got some friends that we do this with. There'll probably be about 6 or 7 Jeeps together. Get a little caravan going. Yeah, we kind of need that because we have a tendency, one or the other of us, to break down on the trail and we need us to either winch each other out of a bad situation or to going to town for parts, maybe a mechanic here and there. Right, good to have each other's backs.
Yeah. Okay, any cool stories from the trail? Like, you come across some wildlife or have to spend the night out stranded somewhere? You know, the worst I had— and I'm a good driver, I think, most of the time, but I've done some stupid stuff like trying to drive over a log and you just get high-centered. But the worst thing is, a few years ago, I broke my rear axle.
Trying to get up an obstacle. And oh wow, yeah, it took about probably 8 hours to get off the trail. Had to go into town and find another axle. And in Moab, it's a small town, and it was— I think it was a Sunday. Drove all over that town and there was only one axle to be found.
And finally got it, drove it back out to the trail. My buddy who was good with cars and Jeeps, tried to put it back together, couldn't. We had to go back into town and find a mechanic who would get out and come and put the axle back together. So that sounds like an expensive repair, not just parts, but to get the labor. You know, crazy, crazy thing, I got off the trail for about $300.
Really? Which is really surprising. That's really good because he was doing the repair in the middle of nowhere, not, not in a shop. Yeah, well, that's a good mechanic to know. I kind of ruined the, the day for my friends, but they were good friends.
They waited with me and made sure I got back out. That's good. It's good to have each other's back. Yeah. So did you grow up doing outdoor activities here in Colorado, or did you get into it later in life?
I grew up doing outdoor activities in Oklahoma. Okay. All right, so I lived on a farm, and it was really a ranch. We, we had a couple hundred acres that we leased to a local rancher, so my family wasn't ranchers, but lived down by the creek and by a lake. So I did a lot of fishing, a lot of camping, a lot of trips through the pasture.
Okay, that sounds very rural. Yeah, it is. At what point did you get more involved in the technology space?
Oh, it's been a long journey. I started when I was about 12 years old. I got my first computer, and that was a TI-99/4A, and it's an old computer that plugs into your TV and didn't have a hard drives back then, didn't have floppy disks. What I used for storage was a cassette tape player. So I would load up some games on that.
They were like choose-your-own-adventure games. And, and did they have graphics? It had some very rudimentary graphics, like the pixel was about the size of a quarter. Sure. And I learned to draw on there and I learned TI-BASIC so I could do some BASIC programming.
And I remember I would go down to the bookstore in town. It was called Hastings. And on the magazine rack, you could go through these computer magazines that had sample programs that you could type into your computer and run these programs. I didn't have enough money to buy the magazine, so I'd read through those and memorize techniques and try and memorize the code and go back home and type them in. Type it into the BASIC interpreter and then run the game.
Yeah. So you're a magazine pirate before there was software pirating. Yeah. I guess luckily that wasn't being surveilled at the time. Right, right.
That was before the Digital Millennium Copyright Act. Yeah. All right, so got involved in technology as a teenager, and then did you study technology, computer science, or anything like that in university? You know, not much. I studied finance and accounting very heavily in college.
Lots of numbers. Lots of numbers. And I loved finance and the things that you could do with it. But coming out of college, I got a job offer at a software company and I was lucky enough to get that 6 months ahead of time. So my last semester in college, I loaded up on programming and, and MIS, management information systems classes so that I'd be better prepared when I got into technology.
And then that was, you know, 20-some years ago and I've been in software industry Ever since. So you knew, hey, I'm graduating college, I'm gonna be in a software role, I need to beef up in these areas. So had plenty of advance notice. Yeah, pretty smart. I had dabbled in technology a bit, you know, the years before that, in high school, took some programming classes.
Okay.
So tried to make myself computer savvy, but it was really when I got that job offer, I'm gonna dive in. And what, what languages were they teaching? In high school, I started off with BASIC. I think it was Apple BASIC and maybe an IBM BASIC. Did a little bit of assembly and Pascal.
And then in college, I learned C and some C++. Were they teaching secure coding techniques at that time? I don't remember anything about security. Yeah, no. Yeah, I think that came a lot later.
All right, so first job out of college, you're working at JD Edwards working with code, right? All right. Well, yeah, so I really— I started on the support line there for the financial software, and when we had someone call in with a bug that they were reporting, we would literally go to our filing cabinet and find the code fix if there was one and fax it to them. So they would have to get a programmer, get onto their AS/400 and type that in an RPG. Okay, so you weren't deploying patches.
I wasn't deploying patches. You were telling them how to patch their own systems. Yeah, right about that time was when client-server was becoming a big thing and a brand new software package, OneWorld, was coming out. So spent a lot of time on the product launch of our financial software on JD Edwards OneWorld and became a lot more technical during that time. I started Doing some programming and teaching some tools classes, so how to build apps on the platform.
Okay. All right, and I imagine your customers were pretty big at that point, right? I mean, I think of JD Edwards, I think of large enterprises that would be using that software, not, not a mom-and-pop shop. Generally, yeah, they— I would say mostly small and medium-sized businesses, but there were a lot of big-name brands you'd recognize. Okay.
But they run on AS/400s, which is a mid-range computer, not the big IBM mainframes, somewhere in between that and a laptop. All right, so great place to start your career. And then did you stay in that sort of a software technical track in your next role? Yeah, so I was probably there for about 8 years. Halfway through that time, I moved to a consulting role, and by then I had done some rotations in product development, Q&A, and in consulting I was doing some more mostly deployments of partner or third-party software packages, and there's always some programming involved with the integrations or with the installations of that.
Did that require some travel, like visiting customers? It did, yeah. Okay, so more of a client-facing role. Right. And I imagine you sort of need to be prepared for anything when you walk into the client's site.
They're gonna ask you a whole bunch of questions, right? You want to be confident when you answer. You want to be an expert, right? Sometimes they hit you with stuff that, you know, obviously the expectations are a little bit off. You have to be able to manage that.
But if you know what you're doing better than they do, then you're automatically an expert. So that's the best you can hope for. You don't actually have to be an expert in this industry. I've learned a lot of times in a role like that, you just have to know a little bit more than everybody else around you about whatever it is you're talking about. All right.
So just stay one step ahead. You don't have to be 10 steps ahead the whole time. Right. It's like, what's that old maxim? If you're running, you and your buddy are running from a mountain lion, you don't have to outrun the mountain lion.
You just have to outrun your buddy. Right. Hopefully he's not your buddy anymore. Yeah, you don't have to be the fastest, just not the slowest. Yeah, sure.
All right, and then where'd you go after leaving JD Edwards? After JD Edwards, I went to— well, it had gone through a couple of acquisitions. PeopleSoft bought JD Edwards. I became a PeopleTools programmer for a while. I was in IT at the time, and then Oracle bought PeopleSoft, so I worked for Oracle.
And that wasn't for very long. I decided I'd rather go into the integration space because I had been working a lot in enterprise integration. So connecting systems together, getting them to talk, right? I was making PeopleSoft talk to JD Edwards and lots of other packages I had been doing when I was in consulting. And our main tool for that was web methods.
We had OEM'd that tool, JD Edwards had, and so I went to work for Web Methods. Okay, so you're able to leverage a little bit of experience that you had. Yeah, similar role, customer-facing? I went into solution engineering at that point, so I had at JD Edwards been in support and then consulting and then IT, and then when I went into Web Methods, I was in solution engineering. So that was when I was truly customer-facing the whole, you know, full-time.
Do you enjoy that more than the backend type work?
I do. It is different. I enjoy the backend work too because there's a lot of creativity in programming and I really enjoyed that, right? And being able to come up with solutions from scratch and make things talk with to each other. So I really enjoyed that aspect of it, but I really do like the customer-facing piece as well.
There's a lot of variability, and as long as I'm not on a project for, you know, months or years on end— and I'm not in the solution engineering role, you're going from customer to customer and probably managing many different projects at the same time, right? So it's very dynamic and always moving, right? So there's some variety there that kept you on your toes in a good way. In a good way. And where were you at this time geographically?
Were you in the, in the Colorado area? I was, I was in Denver at the time. So something brought you from, from Oklahoma and Texas out to Denver. Was that the J.D. Edwards?
It was J.D. Edwards. Okay. Oh yeah. All right.
So you spent your whole career in the Denver area. Yeah. All right. And then it looks like you made a jump to Information Builders. Information Builders.
Yeah. So I moved over to Information Builders after a career at Web Methods, who ended up being acquired by Software AG. That was during a recession, so it was kind of hard to move at that time. But when the economy got better, I moved from Software AG to Information Builders, and that was the iWay software division, which does integration. So Information Builders does a lot of business intelligence and analytics, and then the iWay side does the the integration.
So I've stayed in the integration space again in solution engineering. Okay, so similar role. All right, and then what led you to leave there and start looking for a new role? I had a number of former colleagues who had been at Web Methods who had careers at Salesforce, which is where I'm at now. They had been pinging me over the years saying, hey, you ought to come over to Salesforce.
I remember looked and saw that they were successful there, mostly on the platform team. And it looked like a really good role. So I interviewed there, uh, talked to them for probably about a year and a half before I finally decided to come over. All right. They wooed you to join Salesforce and you're working remote or is there a Denver presence for Salesforce?
There is a Denver presence. We've got several hundred employees here. And in fact, just announced an expansion into downtown Denver. So there's 17th Street Plaza, is the old Molson Coors headquarters building we're gonna be moving into later this year. Okay.
That being said, we have a lot of remote employees in Colorado. I am generally remote. I go into the office sometimes, but I also travel a lot out to San Francisco or New York or just really anywhere in North America. When I'm not traveling, I'm usually working remotely. Travel to visit like a Salesforce office or travel to visit other customers?
Both. Both. Yeah, we're headquartered in San Francisco, so I'm out there quite a bit. Also have a lot of customers in the Bay Area and customers throughout the US. Okay.
Is it sort of like an account management model where you're assigned, you know, these are your 10 to 12 customers and you have to manage them, or could you get thrown anything from anybody at any given time? Most of the people in our larger organization are assigned to certain customers. Or territories. My team is the security architects, and for the enterprise team, there's only 6 of us in the whole company, right? For this customer-facing role that we're in, there's another group that we're closely aligned to for a different segment.
There's 3 of them, but it's a small team. So we have one architect assigned to financial services for the East, another for FinServ for the West, right? I'm actually over all North America, so I could get anything. I'm not assigned to a particular customer. All right, so you could get advance notice or no notice at all that you're assigned to a certain customer.
Yeah, yeah, I mean, it typically goes where, where the business is going. Like, my key customer internally at Salesforce is the sales teams, so if they are positioning deal, Salesforce deal, where there are security concerns or where there's security add-ons, then my team will get brought in. Okay. So I really do a lot— my— a lot of my work is at a much higher level of trying to scale myself across my organization and across the broader solution engineering teams. So you're not filling out customer security questionnaires in your role?
You're generally doing whiteboarding. Yeah. Learning the customer's environments and their requirements and that sort of thing? Yeah, so we've got a program called Defend. That's our go-to-market and how we engage generally on my team, where we will spend some time talking to CISOs or InfoSec or privacy professionals to understand what concerns they have about putting data into the cloud, specifically in Salesforce, understand you know, what they perceive as the threats.
And then we'll go out for a day and spend an entire day just going over all of the different controls that we have in Salesforce to match their concerns, to make sure that they understand we do have a secure cloud and that they can securely put their data into the cloud, right? Obviously, cloud computing is a shared security model. As a, as a SaaS provider, we take care of the underlying infrastructure. We also have a platform as a service. We still take care of the underlying infrastructure, but we give the customer a lot of flexibility in how they configure that.
So we spend a lot of time going over the controls that they have to make sure that they put the data in there in a way that is compliant and meets their security needs. Right. And that shared responsibility is really a linchpin of the cloud because, you know, Salesforce can do all they can to secure things, but if I take my Salesforce API key and upload it to GitHub, then that's, that's on me, right? There's very little that Salesforce can do other than say, hey, you shouldn't have done that, right? Was not a smart move, right?
We do everything we can to make sure that our customers have the tools to secure their Salesforce org, but if they don't know that they exist or know how to use them, it doesn't do much good, right? Sure. So you started in 2015, 2014 it looks like, and GDPR became a thing during your tenure at Salesforce. How did GDPR change your role? Did you get a lot of customer questions about that?
Yeah, it was really a big source of anxiety for a lot of customers leading up to that. It was May of 2018 when that went into effect, and it, it changed the way we have conversations around, around data privacy and compliance, and it also changed the product. So I spent a lot of my time with product management on, you know, what type of features do we need in Salesforce to make sure our customers feel comfortable putting their data in Salesforce and being able to manage subject access requests and, and right to be forgotten and all those kind of things. And then educating customers on, on these new tools that we have in place. So it felt like that kind of died down over the next year or so, and then we got CCPA.
Yeah, California Consumer Privacy Act, newest instantiation. Of it. And perhaps there's some carryover between tools that were put in place for GDPR and tools that would also apply to CCPA. Yeah, there are. And a lot of the controls are not necessarily specific to a regulation.
They're more making sure that we build in the flexibility such that if a customer asks you for their information, we have the tools that you'll be able to get it to them. That could apply to a lot of different privacy programs. Including both the GDPR and CCPA. Sure, sure. How far in advance did you have to start planning for GDPR?
Because Salesforce is a large, complex, multifunction product. I imagine it's hard to turn on a dime based on some new legislation that comes out. It is. I mean, we constantly follow the legislation, and in some cases the amendments are not even getting signed off until after the bill has been passed. So you have to kind of structure a flexible software system and the privacy program in a way that it can meet multiple compliance requirements.
And in fact, we have customers around the world that we have to worry about this in multiple jurisdictions. So we focus less on an individual regulation than we do on making sure that we have a very flexible system that allows a customer to comply with many different laws around the world. Okay, so what are you keeping your eyes and ears on now? Like, CCPA is in effect. Is there anything else coming up that you've got— we are looking at the horizon to see what's out there.
We are actually lobbying for and keeping a close eye out for federal privacy legislation that we'd like to see put in place. Right now we're seeing a just a bunch of different privacy laws popping up. Nevada, Washington State, you've got other countries around the world passing privacy laws, and it's really difficult for companies to comply with every single law that's out there. Sure. Look at, for example, data breach notification laws in the US.
There are 50 states and 50 different laws. So the approach many companies take is assuming they have customers in every one of those states, they'll just comply with the strictest. Yeah, the highest watermark, right? And by doing that, they presumably meet all of the others. But it's a really tough landscape to comply with that many.
But if we had a federal privacy law that covered all of the states, then it would make the jobs of our compliance teams, our customers' compliance teams, easier. Sure. And you have to be able to comply with just that one, which makes sense, you know, as a SaaS platform that Salesforce would lobby for that, right? Instead of trying to track down who's changing what law this year, if there was one that applied to all 50 states, and potentially, you know, that would be a landmark for other countries to follow as well, in the same way that GDPR was a front-runner, right, privacy legislation. It would have to have a really catchy acronym though if we're gonna have some US federal privacy legislation.
I'll have to think of what the perfect acronym would be for that. But that makes a lot of sense that GDPR would change your role quite a bit. So how technical do you get with these customers? You know, are they asking about, you know, down to the disk level and encryption algorithms and TLS 1.1 and these sorts of things, or do you keep it at a high level when you're talking? It varies quite a bit.
Many of my conversations are with maybe a business analyst team or Salesforce admins, and they don't go really deep into the technology. But every once in a while, I'll get into a conversation with a cryptographer from InfoSec, and they want to talk about different encryption algorithms that we may or may not offer. Homomorphic encryption, all these other schemes that— okay, let's slow down. Here's how our system works and how you can manage your keys and, and how we encrypt the keys and encrypt the data. And those are fun conversations to have.
Yeah, so you have to be able to speak at a high level and then also really get down in the weeds on the technical nuts and bolts of what's going on. Yeah, yeah, I could see that that'd be challenging. Again, right, you can show up at a customer and not know what they're gonna ask you, and you need to be prepared with some deep technical expertise. Yeah. Okay, so what does success look like in your role?
Are you measured by how many deals you help assist, or are you measured in, you know, this product on the product roadmap, this feature was moved forward, and I tracked how many customers I was affecting? I don't have an individual quota. Myself, but generally it's how successful we make our customers, and we have ways to measure that. Okay, like attrition rates, for example, right? And also the sales team, how well they do, and we're tied to their numbers.
Yeah, I'm— where I sit, I'm kind of distant from that. Okay, but ultimately it's just about helping drive Salesforce business and customers' business success. So you're not Obviously not a sales engineer, but you support the sales team through your talking with customers and assisting them. Yeah, I'm closely aligned with the sales engineering teams, the solution engineers, and the sales teams. They're the ones that would generally give me a call and say, hey, I need you or somebody on your team to come out and have a security conversation.
Okay, so how, how is the product security of Salesforce, how is that market differentiator? From other competitors?
First of all, Salesforce is, is very strong in security. We're known for trust being our number one value. So we have a lot of security capabilities that are built into the product. When it comes to security products, which are add-ons largely around compliance and things that certain customers in highly regulated industries need, We're pretty innovative in how we rolled out, for example, encryption at rest and how you can manage your own keys. We can reach out and grab your keys from your own HSM or key broker service.
The way we do monitoring in real-time transaction security, we're constantly innovating and building on that. But at the end of the day, we don't tend to compete. With other security vendors, right? It's more about helping understand, helping customers understand that we have a very secure platform out of the box. And then if you have compliance needs on top of that, or very strict security controls that you need, then you can add on some of the extra security.
So you're able to go above and beyond? Yeah. Okay. And when you look at the 2020 roadmap and the 2020 plan, are there things that you're able to talk about like, hey, this is what we want to get done this year, this is what the team's going to be focused on, or this is what product features are on the roadmap that are security-related? I can go into that under NDA.
Sure.
Okay, but nothing specific. All right, shifting out of Salesforce a little bit, let's talk about the information security community at large. Very dynamic, technology changes pretty quickly. You've seen that in your career. Are there ways that you stay up to date through books or learning materials or anything like that to stay on top of all the ever-changing technology?
Yeah, so personally I do a lot of reading. I listen to several podcasts in security and privacy space. I go to conferences and trainings. I get new certifications every once in a while. And so I'm constantly trying to stay up to date on the latest.
In fact, a lot of security industry happens outside of my realm of what I do at Salesforce. So to try and keep that broader perspective on what's going on in security space overall, I feel like I have to get out into the community, sure, interact, and keep myself up to date, okay, in different ways. And for the listeners that are listening, he is wearing a Black Hat hoodie, which is the classic hacker gear. So I assume you've attended Black Hat at some point. Yeah, I was at Black Hat last year.
Last year, first time? First time. Okay, I've never actually been. Would you recommend it? I would, yeah.
It's, it's a pretty neat experience. It runs right next to DEF CON, which is a major hacker conference, and many of the attendees go to both of those. I only went to Black Hat this year. I think I probably will try and make it to DEF CON this year. Okay, but it's a, it's a pretty neat experience.
You know, they say you should not take any computers. If you do, don't turn them on. Don't turn your phone on. Don't turn on Bluetooth because apparently people are walking around there with hacker tools and just for fun hacking anybody they can. Yeah, in the casinos, hotels, leave all your corporate-issued and personal devices behind.
Did your company pay for that or was it out of pocket? Yeah, no, company paid for that. I, when I go to these security conferences, I'm almost always meeting with customers and partners as well. It's one of the most valuable things I get out of them. Okay, the networking.
Yeah, so you were able to wear a Salesforce hat, so to speak, and talk to customers from a security perspective. Yeah. Yeah, I was just at RSA last week as well, a couple weeks ago, and spent most of my time with customers and partners, security vendors. Really, that was really valuable. Are you out on the booth floor, or are you doing private meetings and events other than standing at the booth trying to lure people in?
I have spent a fair amount of time at booths, mostly at Salesforce events, but at the security events, I had a couple of speaking sessions in McAfee's booth that was on the floor. They have a— they had a huge booth, and they were a huge sponsor So they had a little theater that they kept running sessions going. So I had a couple of sessions on cloud security there. Otherwise, I'm— I was roaming the floor, meeting up with a number of security vendors that I knew were going to be there, talking about maybe some go-to-market activities. Spent a lot of time out in hotels or restaurants in the vicinity, also meeting up with customers.
Dinners and lunches. Yeah, a lot of parties. Pink Identity was there. I tried to find Robb, he— I couldn't find him that night, but he was hiding from the coronavirus. Yeah, but there are a lot of parties every night, so a lot of networking to be done.
Okay, jumping back to the learning materials, you mentioned podcasts and being an avid reader. Is there anything you want to recommend title-wise for podcasts or books? Podcasts, obviously Colorado Equals Security. My second favorite, or another favorite, is Darknet Diaries with Jack Reesider. He tells stories, hacker stories.
I love that, love that one.
I could talk all day about books. I read a lot. Sure, is it technical books? Is that mostly what you're reading? Mostly not that technical.
I read books about the history of cryptography. I read books about math, but not really technical books. Uh, just for fun. I like, I like books about, uh, pi and irrational numbers and kind of weird that way, but not highly technical. I also read leadership books.
Sure. So one that I'm just finishing up right now is called The Code of Trust. It was written by Robin Dreeke, who is a former FBI spy. I guess for Black, I don't know his real title, but yeah, it's, it's kind of a book on how to establish trust because his career was about recruiting spies and he had to establish trust to be able to do that and get them to flip, if you will. And he talks about it in a way that is really compelling and in a way that helps people drive relationships forward, and not in a phony way, but in a way that we could really have a relationship and work together in the future.
So a genuine way. Yeah. Yeah, some of the other books I just read— well, it was a couple years ago, but one of my favorites is The Code Book by Simon Singh. Mm-hmm. And that probably came out 20 years ago, but it talks about the history of cryptography.
From hundreds or maybe even thousands of years ago up to the modern day, or at least up to the, you know, 20 years ago, right? Yeah, it's a fun read, you know, it doesn't require a lot of technical chops to get through it. Mm-hmm. So I love books like that. Cool.
Anything else you want to be sure to recommend?
Recommend, let's see, another one. Here's a book called Essentialism by Greg McKeown. McGowan or McEwen. It's not about technology or security, but it's about how to prioritize your time and your efforts and about doing only what's essential. So one of the things I've struggled with over my career, and I think I always will, is how do I do the things that are important and that are going to be impactful and not get distracted by these thousand other things on my to-do list, right?
So that's what that one is about. Yeah, I think that's a really valuable thing to learn for anyone working in technology because there's always something to do, right? There's always more work to do, but how do you know what the most important thing is? Yeah, how do you know the best way to spend your workday or your work week, right? And doing what's essential will allow you to become really, really good at one thing, and you can become an absolute expert at that thing if you're not chasing 8 or 10 things, you know, at the same time.
Right, right. Teaches you how to focus. Yeah. So one more that I'll plug, it's Permanent Record by Edward Snowden. Obviously, he's a controversial character, and he writes this memoir of how he became I guess hacker-minded and eventually went to work at the NSA.
And then when he left and what that was like running from the authorities. And of course he's still a fugitive today, but he's a, he's a good writer and it's a very compelling and easy to read book. Sure. Now, as you mentioned, very controversial. Is he still in Russia right now?
He is. Okay. He is. Yeah. No plans to leave?
I don't think so. I think, I think he's a wanted man. If he stepped back on American soil or anywhere with an extradition treaty to the US, I think he'd probably be in jail. Right. Or executed.
Right. If they really wanted to send a message. Yeah. I'm sure that's fascinating, though. Obviously, that was a big political statement and created some waves when that happened in 2013, something like that.
Sounds about right. 2012, 2013 timeframe. Yeah, okay, great. Well, thanks for the reading list. I myself enjoy a good read if I can stay awake in the evenings anymore, but yeah, I'm gonna take some of those book recommendations to heart as well.
So looking forward this year, you mentioned speaking at RSA. Are there other speaking engagements you have later this year that you want to highlight? I will have several, most likely. I speak at a lot of Salesforce conferences like Dreamforce and Salesforce World Tours, but something that our listeners would be interested in is Rocky Mountain Information Security Conference coming up in June. Is it May or June?
I think it's in June. Coming up, and that's in Denver, a large regional conference that attracts a lot of Colorado security professionals. So I'm speaking on the evolution of encryption at rest and key management in the cloud. So I've got a 1-hour speaking session there. Okay.
So look for that. Is that specific to Salesforce or is it generic enough that it would apply to anyone? It is how we do it and have done it in Salesforce. It could be broadly applicable in terms of how we do the key management in this multi-tenant database and because of the way the database is structured. So I think it's interesting to anyone who has an interest in cryptography.
It's not highly technical, but the concepts could be applied to other systems. But it is kind of, here's how we do it in Salesforce. Okay. Yeah, that sounds interesting, especially since you mentioned multi-tenant, right? Like if you're managing multiple keys and you're using one single database, How does that all work?
That's the big challenge, right? Because you've got different customers in a single database with, with rows spread across a table. How does one customer encrypt only the data in their rows and manage the encryption keys so that they can delete the keys, rotate the data as needed, so forth? Right. Well, don't spoil too much because you want people to come to your talk.
It's fascinating material. Yeah, yeah, and I attended RMISC for the first time last year. It was a great experience, highly recommended to those who haven't been before. I think last year was record attendance, so hopefully 2020 will break the record again. Yeah, I hope so.
Yeah, all right, Michael, coming up on time. Is there anything that we didn't cover that you want to be sure to mention? No, I think I just wanted to invite people out to that conference and, and come to my talk if you can. I'd love to have a crowd there. Yeah, to talk about encryption.
Okay, well, thanks so much for your time. Really appreciate it and have a great one. Yeah, thanks for having me on, Jack. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.