All episodes

Brad Rhodes, Head of Cybersecurity at zvelo

Apple Podcasts Spotify SoundCloud

Brad Rhodes, Head of Cybersecurity at zvelo is our feature guest this week. News from: Let’s Roam, WOW!, DaVita, HeartHero, NCC, ManagedMethods, Optiv, TruKnow, Red Canary and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10558 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 159 for the week of April 6th, 2020. Alex, we're in week 2 of our, uh, newscast.

Asked remotely so far. You know, we're having a little bit of technical difficulties, but hopefully, this is the good one. Yeah. Let's hope this is good. Trying to get better audio, but sometimes, the internet doesn't want to play nice with us.

So, I guess we'll see. Well, technology is hard. This is why security exists. That's right. That's good.

Well, how is everything going? You know, I know your kids are back to school, your wife's back to working, she works out of school. You know, my kids just had a few days of getting on to online learning and so far, So far so good. They're pretty enthusiastic about having something to do. How about your kids?

Yeah, well, I think just like actual school, my kids aren't super happy about online learning, but I think that that's to be expected. I don't think it's anything in particular with online learning. Just learning. Just learning in general. But also, you know, the drawback that they don't get to see their friends, which is one of the benefits of actually going to school.

So, right. Oh well, someday. Well, we did, we did have some, some nice weather for the weekend. At least we got out and did a nice bike ride today. It is weird.

So weird to ride around and see everyone wearing face masks everywhere we go. That's, that's gonna take some getting used to. Well, the weather is so nice. I'm actually recording outside right now, Robb. Well, that's, that's why I hear those dogs barking in the background.

Lovely. Exactly. And, you know, the, all of the thousands of people that are out right now making noise outside. All right, well, let's go through some of our housekeeping. You know, we do have a Slack channel still, you know, very vibrant, lots of folks joining on a regular basis.

I think it's become a place for people to, to really come and connect with folks since they're not getting to connect as much. If you want to join the Colorado Equal Security Slack channel, you go to colorado-security.com and click on the Slack button down below. We also have a mailing list if you'd like to get the show notes sent to you each week in your email. Go to colorado-security.com, scroll to the bottom of the page, put your email address in, and sign up for that mailing list. We've had a— we've actually had a pretty significant drop in listeners over the last couple weeks, and my guess is it's because people are not on their commute to work downloading.

So if you don't automatically download the show into your favorite podcast listening app, use this as your reminder. Go get it to automatically download, and maybe while you're there, you could put a nice review for us that'll help us find additional listeners. And of course, we love to do this to connect with as many folks in the community as we can. Also, feel free to tell a friend. If you still have friends at this point and you're still communicating with people, then let them know.

And if you're not, then I suggest that you do that so that you can continue to be happy and healthy in this time of isolation. And a couple other ways you can help us out, if you want to help us, support us financially, you know, we have a Patreon. We're not looking for any of the few who are having a hard time to help us. Of course, we love it if any of you who want to help pay for the cost of the podcast want to go out there though, you can do that. And also, you know, we'd love it if you want to help us do interviews.

We have another guest interview this week. A big thanks to Ty who did the interview and talking to our guest host over from zvelo, excuse me, our feature interview from zvelo. But if you want to help do interviews, whether it's in person or right now it'd be remote, send us a note at info@colorado-security.com and we're happy to connect with you and walk you through how to do that. All right, well, let's jump into the news. First story this week, Let's Roam, which is a Denver-based company, they do sort of citywide scavenger hunts.

They've launched some in-home scavenger hunts since everyone is stuck there. So this is obviously one of those news announcements for any of you who are home and bored out of your mind, looking for creative new things you can do either with your family or virtually with folks at their homes. They have a good set of not only kind of family-oriented in-home scavenger hunt. They also have date-oriented scavenger hunts, which, you know, I don't know exactly what that means, but, you know, it could be interesting. And there's, there's quite a few different options you can choose from.

Yeah, so go check out their website, look for some of those scavenger hunts, and maybe have a good time exploring your house. And think of this as a way to help support a local business that I would imagine they are pretty well devastated by the shutdown, and they could use some support. You would think. Hopefully we can do that for them. Next, speaking of businesses that could use some support, local internet provider WOW, used to be Wide Open West, I think they just call it WOW now, their CEO was diagnosed with COVID-19 and she's actually been hospitalized.

Yeah, so that is no good. This actually came after they had asked all of their employees to go home and self-isolate.

But Teresa Elder, who is the CEO, did catch COVID-19 and was in the hospital. Sounds like she's going to be all right, but while she is there, the CIO, Bill Case, is going to be acting CEO, and then also one of the folks on their board is going to step in to take on some additional responsibilities in the interim. Yeah, obviously wish Ms. Elder a speedy recovery and hopefully gets back to the to work real soon. On a positive note, DaVita is set to hire 15,000 employees across the US in 2020. So yeah, this is kind of the opposite of a lot of the news we've been seeing about companies that are laying folks off or freezing hires.

They, they opened up a massive number of positions, and they're across all kinds of different roles. Lots of healthcare people, so registered nurses, nurse practitioners, social workers, dietitians, but they're also hiring roles such as IT and human resources and executive assistants. So lots of different roles. And, you know, considering the fact that I know a lot of folks have, have all of a sudden been looking for work, that might be a good place to work. I've never heard someone who speaks poorly about working for DaVita.

Yeah, I mean, that is pretty cool. There was also a piece in the article that said that they are working with other kidney care providers to set up a way so they can care for folks that have been diagnosed with COVID-19. Who also need kidney care. So I don't know exactly what they're doing, if it's setting up separate areas or some way to isolate, but just because you've caught something that is communicable doesn't mean you're not gonna need to get your kidney care anymore. So it sounds like they are leading an effort across different providers to help with that as well.

Yeah, that's awesome. I mean, just imagine dialysis is a— it's the definition of essential, right? If you don't get your dialysis, you're gonna die. And if you can't go get it because you're infected and you're gonna infect the people around you, They got to come up with a solution. So it's very cool that they've— I don't know if they've come up with separate buildings that are going to be just for COVID or different entrances or what, but pretty cool stuff.

Definitely. Next, we have a final installation in the ongoing— what's it called— 2020 Tech Madness Finals. So we talked about that unfortunately Stackhawk had lost in the semifinals, but the finals was between Heart Hero and Cirrus MD. And Alex, we have a winner. You want to announce?

Yeah, Heart Hero is the winner. Congratulations to them. This, as they mentioned in the article, was a year of underdogs. So Heart Hero was number 7 seed in their victory over number 3 seed CirrusMD. So pretty awesome.

Obviously, it's just fun. And I'll say it's fun for me because I got to learn about a bunch of new local companies that I didn't know, tech companies. And hopefully for those of you listening, you've learned a little bit more. There's a lot of good stuff going on here in Colorado. Exactly.

Next, we have some news out of the National Cybersecurity Center down in Colorado Springs. They have launched their Secure the Vote Advisory Board to put some effort into securing elections, so that's pretty cool. Yeah, they're going to have a kind of basically a thought leadership group that's going to be able to provide election security guidance for different municipalities and different regions. They have a pretty impressive list of folks who's on the board, kind of a who's who of elections, at least here in Colorado. I know Matt Crane was the— ran elections here in Denver for quite a while, and they got the CEO of Votes.

If you remember, Votes was the app that we had in the news recently for having some security issues, and quite a few other folks, Dominion Voting, they make voting machines. Quite a few others that really, you know, have a lot of experience in the industry. Yeah, and I mean, obviously this is an area that can't get enough attention, uh, so having, you know, someone else looking into election security is definitely a good thing, and I look forward to hearing what comes out of the advisory group. All right, moving along, we have a blog post from Managed Methods. Alex, you got to think that while this is, this is terrible for everyone and no one loves this thing, Managed Methods has got to be like, we told you so about online school security, because this is what they've been saying for what, 2 or, I don't know, at least 2 or 3 years that we've been talking about it, that, you know, schools are using G Suite and they got to get better at security there.

And all of a sudden, now everyone's moving to online school, you know, it's right in their wheelhouse. And, you know, they have a blog post kind of talking about how do you secure your school and your students' information when, you know, you're rapidly moving to an online school situation. Yeah, I mean, it's been interesting to see the evolution of managed methods. When they first came on the scene, they were just sort of a general-purpose CASB like many of the others, but really, they've focused their attention on the K-12 market, and this is right up their alley for helping to secure all those folks that are all now at home doing some sort of education. So, pretty cool to see that.

Yeah. They have a few points in this blog post about how to do it. I don't know if it makes sense for us to go through it. I think it does make sense, though, for those of you who have kids in school or who are talking to educators about how they should secure the environment, this link would be a good resource to share with them and make sure that those who are making those decisions have the knowledge they need. Definitely.

Next, Optiv had a blog post this week talking about defending container compromise. I thought that one was pretty interesting. This is actually the second part in a 2-part blog series. The first part was kind of setting up their premise and the potential way that a container could get compromised, and the second blog post gets into the details of how you could potentially catch and remediate that container compromise. So definitely some good info in there.

Yeah, I think it's especially something that you want to share internally. For most companies, moving to Docker, moving to containerization is a relatively new thing, and most of the folks are thinking more about how do I make it work, how do I start getting efficiencies from it, how do I move my applications applications to support being containerized in microservices, and maybe they're not thinking so much about how could someone misuse this technology. So as your IT teams are learning about how to use containers, it would be really good to show them how containers can be misused as well. Definitely. Alright, next blog post we have is actually around compliance and privacy compliance, so it's from Byteback Law, and it's giving a nice update about the status of CCPA, so the California Consumer Protection Act, and CCPA 2.0.

I think we talked about that a few weeks ago that there is a new law coming that's going to take the place of CCPA, probably, depending on how the elections go. And then there's some other states that have pending legislation as well. I know for us, as my company works across all the different states and different countries as well, this is important for me to know, and I think that it's really worth reading through if you're responsible for compliance. Yeah, and of course, this is the blog put out by David Stause at Husch Blackwell. And I thought one of the interesting things in here talking about CCPA 2.0 specifically was, you know, those new measures for CCPA 2.0 are going to be a ballot measure, but they— the measure had not gotten the number of signatures yet to actually get on the ballot, and they didn't think that would be a problem.

However, you know, the coronavirus has thrown a curveball to that with now everyone being in isolation. You know, I'd say only slightly tougher to get people to sign a petition to get something on the ballot. So I think that they have to have those in sometime near the end of April, so it's possible that they might not be able to get the number of signatures needed, so it may not be on the ballot in California. It's kind of an interesting tangent, right? Edge case, right?

You know, you don't think about that when you say everyone has to stay at home, but now we just stop the ability to get a new measure on the ballot. Interesting. Yeah, you have to wonder if they'll, you know, give an extension or do something along those lines. I've also heard, you know, on different topics about that in Colorado, people trying to get things on the ballot now are having some problems because they can't get out and get petitions. Yeah, interesting.

And of course, you know, moving to online anything is a big change, be tough to do. Yep. We have another announcement this week about Trueno. We talked a little bit about it last week. This is another article about them launching their search engine for cybersecurity.

So good to see the press that they're getting. Yeah, we talked about it last week. Not much more to say other than congrats to them. If you haven't looked it up yet, it's worth looking. It's free.

You know, you can start to search. I'd say it's not there yet, right? It's kind of a beta version. But, you know, you can give feedback and you'll see that feedback incorporated into the platform. And over time, it should become a pretty valuable resource for you guys.

Yeah, looking forward to it. Final, uh, we— what we have here is a blog post from Red Canary, and really what it is is a summary of a whole bunch of free webinars. So I know we've had just a massive number of cancellations over the last few weeks. Um, we expect that that's going to continue for the next couple of months. Well, Red Canary has given you a list of things you can do to get educated, to get learned up for free from your, from your home office.

Um, so take a look at that and maybe look through the their webinars for something that's going to be speaking directly to what you need. Yeah, sort of a meta blog post, right? Talking about all previous things that they now have all in one place. So yeah, definitely check that out. And that takes us to the end of the news for this week.

So we can go ahead and jump over to the Slack message of the week. Of course, every week we pick a Slack message of the week, and that is sponsored by Andre Gaeta. So thanks to Andre. He provides out of his own pocket a $25 credit to the Colorado Equal Security store for our— whoever the winner is of the Slack message of the week. And Robb, who is our winner this week?

This week, Rick Hill. Congrats to Rick. Uh, Rick made me smile with a suggestion around, you know, right after the government announced the, the recommendation for folks to wear face masks in public, he said, you know, when are we going to get some Colorado Equal Security face masks? Alex, we don't have those figured out quite yet, but I know we're, we're eagerly looking to figure out when we can have Colorado Equal Security face masks for all of you to wear with pride as you walk around town. Yeah, I don't want to get anybody's hopes up with the shortage of supplies that there are anyway.

My guess is that by the time we get logoed face masks, we may not be wearing face masks anymore, but gosh darn it, we're gonna try. I, you know, I don't know. I plan to keep wearing face masks if they're comfortable. I saw a recent meme from Princess Bride Do you remember when the Man in Black is fighting Inigo Montoya at the top of the cliff? And yeah, he said, why do you wear a mask?

Well, they're terribly comfortable. I imagine in the future everyone's gonna wear a mask. So very predictive of where we are today. Exactly, exactly. Well, all right, jumping over to Rick.

Oh yeah, congratulations to Rick, you'll get one item from the store. Jumping over to events, you know, our event calendar, you know, it's full. It's actually still full of stuff, but I suspect most of that stuff is not gonna happen, so be really careful. Try— you're not trying to goad anything, but we do have a couple of virtual events that we can call out that we're confident are going to take place. Go ahead, Alex.

Yeah, first, uh, OWASP Denver/Boulder is doing their April meeting in virtual style, so that is happening on the 15th. And on the 20th, we have the Software Freedom School doing a Security+ peer study group. So this is an exam prep. Um, if you're, if you're interested in getting your Security+ certification, this is a good group you can connect with, and I imagine that You know, just the connections you would make there would give you more studying outside of that particular event. Yeah, and this is a multi-weekend or multi-day, definitely, study group.

I believe that there is a suggested cost, but I think that it is also a pay what you feel it is worth sort of thing. All right, jumping over to jobs. You know, it has been a little bit harder to find quite so many jobs in the last few weeks. However, once again, we do have a slate of 10 jobs worth sharing with you, starting off with Ping Identity, of course, the best job on the list. I am hiring a GRC analyst who's going to be focused on business continuity and incident response.

If you're interested in getting involved there, we'd love to hear from you. We'd also love to talk to someone who's got a GRC perspective and maybe some privacy. Either of those, you can send me a note or apply on the website, and I'll talk to you then. LogistiCare is hiring a chief information security officer. The Hersheybeck Group is hiring a network security engineer focused on Palo Alto Networks.

Direct Defense is looking for a security analyst. Caterpillar is hiring an OT security specialist. ULA, or the United Launch Alliance, is looking for an information security architect. Nelnet is hiring an IT security architect focused on application security. USAA is looking for a cyber threat intelligence analyst.

Is it, is it Boe— Boeicor? Boeicor? I think it's however you want to pronounce it, Robb. We're going to call it Boeicor, is hiring a Corporate IT Cybersecurity Manager. And finally, Dark Wolf Solutions is hiring a Penetration Tester/Red Team Tester.

And just as a note, those last 3 jobs are actually all down in Colorado Springs. All right. Well, that is it for the, the show here today. We— well, excuse me, for the newscast. We do have an interview coming up, like I mentioned, with Brad Rhodes.

Brad, thanks for joining us this week. Alex, I guess I won't be seeing you anytime soon, but hopefully we can, we can stay connected. And if nothing else, we'll talk next week to record. Definitely. Thanks, Robb.

This is Tim Coogan, Chief Information Security Officer of Denver International Airport. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. I'm Ty Burke filling in for Robb and Alex, and I'm here with Brad Rhodes of zvelo. Brad, it's wonderful to have you on the show today.

I'm excited to be here. It's always, always good to talk about security and what's happening here in the great state of Colorado. Definitely. I know you, you've done a number of podcasts recently, and you're relatively new at zvelo, and we've got a whole lot of questions and a lot of stuff to talk about as it relates to what's going on with COVID-19 and how that might affect some of the work you're doing today. But on this, on this dismal 25-degree snow sleety day, icing day, let's, let's start with something positive.

I want to hear about what's, what's been going good. What's a silver lining of your— I'm assuming you're working from home or your businesses. And maybe it's time with family, or I don't know, what's some of the good that might be coming out of this virus and this pandemic, rather, in your world? Well, it's obviously good to work from home. I've worked from home for a number of years now, and so that's been— it's always been a plus.

Actually, the big silver lining for me is that I just actually got back from Fort Meade, Maryland, with my cyber protection team out of the Colorado Guard. Gone for about 14 months. And just because of the nature of the deployment and everything like that, I ended up not having a significant amount of time to do reintegration with my family. And so the pandemic came along and has allowed that to happen better. So I see that definitely as a silver lining.

Interesting. Okay. Okay. You know, I think there's so much— I'm so excited to hear about how this is going to change things, um, or, or what things will— how we as a society and as a planet will benefit. Like, you've already heard a lot about pollution in some of the hardest-hit areas, uh, from street traffic.

It's just, it's completely reversed. Um, the, the atmosphere, I've heard, is a lot cleaner because there's 10% of airplanes flying and What that does for the rest of the environment. I think that there's— it'll be really interesting to see once we can resume normal life how this pandemic will have affected us for, you know, for the better, I'm hopeful at least. No, no, I agree. I think that one of the things that you see here is that, you know, I joke with people all the time and say, hey, this is the 21st century.

It's the information age. Yet we still have so many places that are so focused on, oh, you have to be a butt in a chair in an office, right? You know, if, if you trust your employees and trust your folks to do good work, and, and we have the technology to allow folks to work wherever they happen to be and, and get some of that work-life balance that we have heard about for the last 25, 30 years, you know, now's the time. Right? And we're being forced into it.

And I think that'll be a good thing. I think you'll see some folks in some organizations that realize that, hey, our folks continue to do great work, even though they were, you know, quote unquote, in their offices at their homes. So I think that's— I think there's definitely some positive stuff that will come from that. Yeah, it makes me think about like the shared workspaces around the world and how how prevalent those have become and how essential they have become for a lot of, you know, 1 to 5 person businesses. Well, if those 1 to 5 person businesses aren't able to go into that shared space and they're able to do their job from home, maybe just as effectively, who knows?

Like, will that, will that spell a shift in, in the shared workspace going forward? I don't, I don't know. But it's something, it's something to probably consider. Well, I think it's unique. I mean, and you made a really good point.

It's, it's, you know, we have these 1 to 5 person businesses. I mean, this is, this is the unique thing about the era that we live in. You as an individual can have an idea, and you can take that idea to market on the cheap and actually be a success. And I think that those businesses that are able to adapt to the changes that we're seeing right now are the ones that are going to be successful long-term. You know, obviously, we've seen over the years trends where, you know, the typical brick-and-mortar businesses, you know, have have struggled at points and there have been brands that I used to shop at, you know, years ago that are no longer around because they just weren't able to adapt and it's unfortunate and it's hard for obviously the employees and employers out there, but I think that sometimes given, you know, given a crisis in front of us, if we flip that crisis and turn it into an opportunity, good things come.

Yeah, yeah. It'll be interesting for sure. Well, tell us about yourself. Who you are, tell us about zvelo, what you're doing there, you know, kind of about the business. I know that, well, there's a couple of different products, but we'd love to hear about kind of what you guys do best over there.

Sure. So we are— so I'm the head of cybersecurity for zvelo. I started actually on the 9th of March, and then of course, you know, the pandemic blew up and here we are. We categorize the web. So our mission at zvelo is to help make the internet a safer place for everyone.

And the way we do that is our primary product set is where we have something called the Active Web, where we are getting a set of information based on our database. And what we're doing is, is we're categorizing the content of the web. So, for example, if you go to our website, go to tools.zvilo.com, and if you were to put in www.cnn.com, you would get back a tileset that explains, you know, the content of of CNN. You know, it's an international news source. There's stuff related to the International Ad Bureau, right?

Is it brand safe? Is it malicious, et cetera, et cetera, right? And the intent there with that is to provide that service to our customers, and we do that via several means, primarily via our API and our SDK. So our API is obviously a cloud-based capability where folks reach out and can touch that. And then we also have an in-house, and many folks will take our software development kit which is a— is our database basically in their data center, which allows them to have that really quick revisit rate to immediately protect their customers from malicious content.

So it's a pretty big mission. It's a pretty unique opportunity, and we're looking to expand and grow the dataset that we offer to our customers, specifically in the cybersecurity area, to help better categorize and understand what malicious actually means so that our folks can then make better decisions and help protect their customers overall. Okay, so, so, uh, now when did you— I'm sorry, when did you join officially? So I officially started with Zivillu on the 9th of March. Gotcha.

Wow. Uh, so, well, you're really kind of thrown into it, I guess. Yeah, Jeff, we just jump right in. Yeah, and, um, and what's kind of the current state of things? How are— how is Zillow acting, or I guess reacting rather, to what's going on right now?

So, well, so from the standpoint of just sort of day-to-day operations, right, again, we talked earlier about the, the opportunity of the information age and being able to do work from anywhere. We're a very agile business. We have a lot of folks that are remote. We have folks spread across the globe that support and help us to follow the sun, whether it's our dev folks or our QA folks in the Philippines, for example, right? So we're already very remote.

So this is not an unknown to us. We do maintain an office because sometimes, you know, when you're whiteboarding an engineering challenge or something like that, it's It's sometimes something you have to actually whiteboard. But because we have always operated in a fairly remote sense, we've been able to adapt and utilize our existing technologies and move out and do everything from our home offices, which is good. So basically for us, that means that the work continues and we continue to move forward, not only with our existing product offerings, but the things and the new ideas that we're working on to better improve you know, web content categorization for our customers. Okay.

I've heard from a few other folks that a lot of dev teams are— this isn't as fluid as they may have expected it to be. And what I mean by that is, you know, they're used to scrums, they're used to whiteboarding exercises, they're used to kind of being together, figuring something out. You know, a 2-week sprint, whatever it might be, and then, and then, and then going from there. And now, without kind of that, you know, I think, I think there's like a general— I shouldn't— a lot of people, a lot of it, you know, developers can tend to be a little bit more introverted. And so like, there might be thoughts that people would— that a lot of them might be a little more, I don't know, hesitant to be in a group setting.

But What I've heard is the opposite, that now that a lot of developers are working from home, there's a lot of— it's a lot more disjointed than I think some of their managers expected because they're just not used to having to pull up a Zoom or pull up a Skype, or— and that just slows down productivity all around. Is that something— I mean, in your, I don't know, 23 days on the job, have you been able to notice any of that at all? No, I haven't seen any of that. I think we have our teams doing their work as we would expect them to. And because, again, many of our devs are remote, this is not an unknown for us to be able to operate sort of in that kind of construct, right?

I do think that all of us— we were actually on a call with some folks a couple days ago on the team, and we're looking at stuff, and we're like, okay, so how do we whiteboard this when we don't actually have a whiteboard to draw on? So I think one of my guys pulled down an app and started, you know, and said, okay, let's just do it here so we can then— You know, screenshot that out and share it with everybody. So that's, that's always a bit of a challenge. But I think that because we've already operated in that, that construct, we're continuing to move forward, you know, in sort of our standard rhythm of things. You know, we work on sort of a 2-week model, as many organizations do.

But again, I think some of this, some of our challenges really that we've seen is the fact that we actually moved offices in the middle of this. And none of us have actually been into the new office except for one or two people that helped with the move. And so that's, you know, we sit here at our homes and we're ready to go and we want to, you know, at points in time go to the office when we need to, but we can't because of obviously the restrictions that we have here in Colorado. Right. Well, I want to dig into a lot of this a lot more, but I don't want to get away from who you are and your backgrounds.

Can you tell us a little bit about your career before Zivilo and who you are? I believe you're part of the National Guard. Would love to hear about that experience for you. And then also, like, I don't know if you're being called into duty or anything like that, but would love to hear kind of, you know, from education up through March 9th, I guess. Sure.

So the short— so I've got 23 years in the field. Way too many professional certifications because I either get bored or whatever, and I like to do tests and I have fun learning stuff. So that's good. I had— I started out after I graduated from Embry-Riddle Aeronautical University and commissioned as a 2nd lieutenant in the Army, was stationed at Fort Gordon, Georgia for a few years on active duty as a signal officer. That's what you would term in the rest of the world as communications, but signals like, you know, flags, semaphore, that kind of thing.

When I left active duty, I joined the Colorado Guard as a traditional soldier. And so I've commanded multiple units in combat with the Guard deployed to OIF, so Operation Iraqi Freedom, Afghanistan, most recently Fort Meade, but I'll come back to that in a second. In my civilian career, I've been a consultant for, for Air Force Base Command. Army Space Command at times. I've worked in the intelligence community as a government civilian, which is always an interesting experience.

And then I've also done cybersecurity stuff with a couple of, a couple of larger firms, in and out of policy circles, in and out of tech circles. Always been a techie. I've, I cut my teeth with a Trash 80 back in the, in the 1980s and did war dialing back in the day, which probably get me in really big trouble now. So lots of fun in that sort of arena. Most recently, before I came to zvelo, I was actually forward deployed at Fort Meade with my cyber protection team out of the Colorado Guard, and we were there for a national mission supporting, supporting US Cyber Command and Army Cyber.

Heck of an experience, learned a whole heck of a lot. You know, for the audience, definitely Definitely know that the cyber warriors out there are doing good stuff to keep America safe on the cyber front lines. And so that's, that's really what I want to say about that. I am in the Guard. I'm a Lieutenant Colonel, 17 Alpha Cyber Warfare Officer.

So that means that I'm— I've been duly certified by the Army as one of those, you know, quote unquote cyber guys. But I will tell you that none of us across the board, especially on my Guard side of the house, You know, I'm not the smartest guy. All the smartest guys are my warrant officers and my enlisted folks who are way smarter than me and are just absolute wizards. And it was absolutely a pleasure to serve out there with them. The zvelo opportunity was something that I just— great organization, great opportunity, great mission, right?

Rarely do you find an organization, and we're small but mighty at zvelo, that has a mission statement that says we're going to make the internet safer for everybody else. And that is something that really resonated with me, and that's one of the reasons I joined the team. Well, thank you for your service, for starters. That's a really— I'm sure we could have a lot longer conversation just on some of the experiences you've had there. But, but, but, you know, as a fellow American, I'm certainly appreciative, and I know everybody else is.

So, so thank you for what you've done. Have you— are you a Colorado native, or how long have you lived here? So no, I was actually born in Oregon, grew up there, and then Southern California. I've been in Colorado though for better part of 20-plus years now. Okay, okay, gotcha.

How does the— as I said, I'm in the executive recruiting business, and so I'm always thinking about talent and competencies. Given that you've been in a lot of different geographies, a lot of different bases, Um, how, how might it compare in Colorado to some of the other, other places you've been, uh, stationed at, I guess, for, you know, periods of time, I guess? Yeah, I've been, I've been all over the place, and between traveling for, for, for regular work and for Guard, I've seen lots of things. I will tell you that in my experience, some of the talent here in Colorado is unbelievable. Um, we have a great— along the Front Range And across the Rockies, there are some incredibly smart people with just amazing ideas, right?

You know, and I've seen in Colorado, there's so many people that just want to go do that. It's just, it's just awesome. That's one of the things that's been unique in my experience, especially in the Guard, is I've got to meet a lot of these people. We do regular exercises with our mission partners, be they academic, be they critical infrastructure, be they Excuse me, like school districts and local governments, county governments, stuff like that, even the FBI and other organizations that are here in Colorado. Definitely, definitely a lot of value in Colorado and a lot of smart people that are out there every day trying to secure their assets and make sure that the work that they do is protecting their employees, their fellow coworkers, you know, from all of the bad actors that are out there trying to get a leg up.

That is so awesome to hear. That's, you know, we've got listeners all across the state, all across the region, and I'm sure many of those listeners are the people you're referring to. And so that's, that's, that's really encouraging.

So let's, let's shift back to— I think we will give our listener, you know, we gave our listeners 15-20 minutes of respite on the only type of news they've heard lately, which is around the COVID-19 pandemic. But let's shift back to it, especially because I'm curious about what Zillow is doing with a lot of the information that might be in your own datasets. I mean, are there— well, for starters, how are you gathering your information on on how the virus is spreading and specifically within the security community? Well, so it's funny that you, that you couch it that way. Spreading is a good sort of term.

So one of the things that we're doing at zvelo, and this is new, is we're working on looking more proactively at our content categorization and at the web. Right? So we sort of have 2— we have 3 sort of ways we look at our platform. We have the active web, right, which is our several hundred million customers protected that we're actively looking at what they're clicking on and understanding, you know, that content coming in. And then we have the inactive web.

And so the inactive web are those things that are not active anymore. They could have been taken down by law enforcement. They're, they're no longer a registered domain, right? All those things. That's sort of the inactive web.

And then the proactive web, which is really new for us, right, is trying to get out in front of threats before they happen, right? And so that's proactively looking at our dataset, right, and the datasets that we have access to from a proprietary perspective. To understand what's happening, you know, in the space. The good news or the bad news in my mind is that threat actors tend to follow the world situation. So that's helpful, right?

Because so, so just like as a defender, as a proactive guy, I can look at the world and say, okay, what are the 2 big things that are happening, say, in the United States that I'm concerned about? Well, one obviously is coronavirus COVID-19. And so that's, that's put that in a box. And the other thing that's happening obviously is the 2020 elections, right? So at Sivelo, we can go back and then look in our dataset and say, what are we seeing related to those 2 events?

So let's just focus for now on COVID-19.

About It's almost 6 weeks ago now, we started to seeing a massive uptick to the tune of several thousand or more registrations of domains specific to coronavirus. Right. And obviously the threat actors are looking at the situation. Now, there are obviously legitimate reasons why you would register a domain, right? It could be that You want to point people to a specific site, right?

You might want to protect your brand, right? Multiple reasons why you would do that. In the era of generic top-level domains, you know, so you know the standard top-level domains, .com, .org, .net, right? Well, now, for example, I could go out if I wanted to. It's a pretty expensive proposition, but let's say I wanted to buy a gTLD, a generic top-level domain, of .zvlow.

I could do that. And I could register a whole bunch of subdomains under that and things like that. Well, those generic top-level domains, right, are either bought by folks that want to protect their brand, or they're bought by folks that want to make money. And some of the folks out there that are using these domains or managing these generic top-level domains, right, they probably don't have as many scruples as many of us do. And so they're willing to sell to anybody, and many of those sites then get purchased and then are designed or built to deliver, or those domains are built to deliver, you know, potentially malicious content.

Could be malware, could be bots, you know, could be stood up for a command and control channel, you name it. That's the kind of stuff that we're seeing.

Interestingly, it was about 2 weeks ago now, namecheap.com came out and said that they were no longer going to support registrations of domains related to COVID-19 or coronavirus. And that is a unique thing happening out there. But unfortunately, we're looking at several— we're looking at thousands upon thousands of these domains, and not all of them are serving good content. And that's the concern, right? So it goes to the general public, to anybody out there, right?

Hey, be careful what you click on, right? Because Lord knows where you're going to actually get redirected to Right, you could actually get redirected to something legitimate, but more than likely you're going to get redirected to something that's not legitimate that drops something on your, on your desktop or on your computer and then actually starts to steal your data. Right. And unfortunately, that cybercriminal element out there is looking at the world situation and they're looking to take advantage of fear and uncertainty and everything, unfortunately, that's been associated with the coronavirus. Well, there's so much mania around this.

It kind of reminds me of the 2016 election and all the misinformation that was distributed through the internet because, you know, this was kind of like the peak of clickbait. Like, what did this candidate say or what did this candidate's spouse do or anything like that? And people got really excited about it. There's even less kind of well-known information about this virus than there are actual human beings. And so there's so much opportunity for people to be influenced with the wrong material.

But then on the back end of that, for these threat actors to come in and do some damage. So what do you guys— so how does— you're identifying all of these potential, I don't know, malicious threat actors. Whatever it might be. What do you do from there? How do you figure out who do you work with to make sure that their kind of influence is halted or not distributed even further?

Well, so the good news is that the threat actors, just like us on the good side of the— like, it's kind of like Star Wars, right? You got the light side and the dark side, right? So the folks on the dark side, right, have to use the exact same set of standards that we do on the light side, right? And so When a malicious domain gets categorized that way into our database, right, all of our customers that are subscribing to our feed, right, are then protected from that, right? So that means that if they go to, on whatever device it is they happen to have, they're not going to actually be able to get to that specific site.

And so that's how we— that's kind of the magic there, right? And ultimately, all we're using, the fact is that is we're allowing our customers, right, to get to bring in that data feed from zvelo, and then that goes into their content management, content blocking services that they provide to their customers, and then that ultimately is where that stops. And so really in the end, right, if you never get to the malicious content, you don't get served the malicious content, and the actors have to go someplace else, and that's what we're aiming to do. Okay, that makes a lot of sense to me. How about, you mentioned the 2 things going on, obviously COVID-19, but also an election year.

What are you guys doing in terms of— I'm sure this is a big whale of a question, but how are you protecting the internet from the coming presidential election in the US? Obviously, that's something that we're very concerned about, and I think everybody is. And the challenge is that with the current mania, as you so aptly put it, related to coronavirus, COVID-19, right? This is an opportunity that threat actors are gonna take to build out their content, to buy up their domains, to buy up all of that namespace so that they can begin to serve content when this all dies down. And so we're right now, we've already put it on our docket to start digging into that set of data as well from a proactive perspective, right?

So that we can begin to understand what we're seeing out there right now If we start to see malicious stuff served, then those are things that'll get immediately added to the zvelo DB so we can protect our customers.

Really, really an interesting situation that we're in with these 2 monumental, I don't know, events, I guess, happening almost simultaneously. And then also there's just so so much potential out there for bad people that do bad stuff. So it'll be interesting to hear kind of what we're seeing at the end of 2020 when it's all said and done. Yeah, one of the things that we're talking about at Zillow is we want to build out a report that we serve on an annual basis that sort of gives people the sort of the overview of what we're seeing from a content perspective, not only You know, on the good side of content, like what kind of content's out there, but then also the malicious side of things. So that's, that's one of the things we're excited about.

And as we're, as we're tooling up for better understanding those different things, that's going to allow us to do that. Okay, that's cool. That'll be, that'll be really insightful.

So how are— well, let me ask you this. Is your team hiring right now? Are you guys You know, I think that there's a lot of individuals across the state, across the region who've been impacted by this. You know, I don't know that security folks are kind of at the top of it, but there are a lot of people who are looking for their next opportunity. Is— are there opportunities at Civilo for them?

We do. We have— there's definitely some requisitions out on the street today. So definitely go to zivelo.com and check out what's out there. We're looking right now for a number of engineers to help us as we look— we're doing some infrastructure transition right now and then some additional product dev. And so definitely some great opportunities at zvelo to jump into the fray right away and to make things better.

What types of security folks would be successful at zvelo? And I know you You've been there a couple of weeks, so you don't really— you may not know a whole— you know, this may not be a very deep answer in terms of systems experience and/or cultural experience, but what are some of the things that you all typically look for in folks? So we typically look for— because we obviously, we do a lot of cloud stuff, so obviously folks with cloud-based experience is good, both from a dev perspective and a security perspective, but also folks that are willing to, you know, jump in and And, you know, yeah, we have our leadership team, but even our leadership team will roll up our sleeves and jump in. So lots of, lots of, you know, just collaborative folks, right? Folks that have a, you know, a broad set of experiences, right?

Whether it's, you know, some coding stuff, some security stuff, right? Cloud, you know, that's the types of, you know, the types of engineering brains we're looking for right now to fill some of our open spots. Gotcha. Okay. Well, there's, um, hopefully you'll get some, some good, good, you know, candidates and people heading your way soon.

Um, let me ask you this. We're, we're in the middle of it. And, you know, I think depending on what, uh, what metro area you're in, uh, you may have hit the peak, you may not. I don't know that we have in, in, uh, on the Front Range here. Um, but what When you think about, you know, one of the things that I really appreciate about talking to security folks is the opportunity for education, painful education at times when it comes to just learning from mistakes and what they could have done better.

Had you been sitting as the head of security at Twilio for, you know, in let's just say December in January, knowing what you know now, what might you have done differently? Like, how might you have been better prepared as a security practitioner had you known the outbreak would wreak the havoc that it has? What else, what would you have done differently, or what would you have done to supplement the things that you're already doing? Well, I think that, you know, obviously these are those, these are the kinds of things that you're never truly prepared for. But at the same time, you know, things like, you know, having, you know, in general, right, going through with our employees and our partners with, you know, what are good basic cyber hygiene things you can do?

Like, you know, having all of— having everything set up for multifactor authentication, right, because that prevents so many bad things, right? Having VPNs in place for folks to use, whether it's accessing infrastructure, which we have, or, you know, just protecting themselves. Themselves when they do work stuff, right? The thing in the environment right now is that, is that so many, you know, attackers out there realize that we've shifted to this proactive work environment, or this, this not proactive, but this, this work environment from home. And so now you have a focus on online collaboration capabilities, and we're seeing some of them right now.

Showing to have major vulnerabilities, you know, and they're great capabilities, but they have major vulnerabilities. And unfortunately, the only reason we're seeing these vulnerabilities is because we're actually using them, you know, to such a great extent. And oh, by the way, I would think that we'll probably see a whole bunch more of those pop up over time just because that's the nature of the beast. And oh, by the way, attackers take advantage of those things. And so what I've told my folks, and just from an education perspective, right, is You know, make yourself a hard target, right?

You know, pay attention to— it's the typical answer. Be careful what you click on, right? Don't trust anything out there. You know, and those are the kinds of things that I've been telling our folks since I've been on board and even a little bit before I got on board. It's like, hey, these are the kinds of things that we need to do.

Because as we're here, you know, at our houses, at various, you know, our home offices, basements, you know, bedrooms, living rooms, you know, wherever, right? There are people that are out there that want to do nothing but bad. And so, you know, keep on doing the stuff that you're doing to protect yourselves. The other thing that I tell folks, and I've told the Zuvilo team, is that, hey, your cybersecurity team is here, right? Even though we're remote, you know, don't be afraid to reach out to them and ask for help and say, hey, I got this really weird link.

Is it bad? What do you think? Right? And we've had a couple of instances of that. And that teaching our employees to, hey, proactively reach out even though we're spread far apart is really, really important because ultimately all of us have a large set of intellectual property we need to protect.

And the only way that we can do that is if we're asking the right questions and being unafraid to ask those questions.

Yeah, that's some really interesting stuff to me. And, you know, I think back on what we were talking about earlier when it comes to a lot of the web conferencing solutions out there. They're great and they're all over the place right now, but they're not without their own vulnerabilities. So something has to be done about those. So let me turn it around here to you and say, what types of business opportunities might arise from this pandemic?

For Zillow's sake? And maybe you don't know, but certainly you've seen a lot more usage in the last couple of weeks than you first did, you know, probably at the first— at the beginning of the year. So how can you turn that into a bit of a competitive advantage? Well, I mean, I think we're looking to obviously enhance our product offerings already, and I think that's going to be a huge advantage for us. We're also obviously the, you know, you have the external exploits, which I would argue are things that are still out there but have sort of dipped in the pendulum of things because security has improved over the years.

One of the things that we're looking at is really to expand and really, really to get some some really, really good tweak, if you will, to our phishing offerings. So we have a phish block list that we're working to retool right now to better protect our customers across the board, whether it's, you know, specific phishing that they receive, you know, getting out in advance with our proactive web to identify things that could be stood up as phishing domains well in advance and get that into the mix. And so I won't say this necessarily that we're, we, we, are going to get the, I'll say, new opportunities, right? But I think we're looking to improve our offerings, right? Which will then ultimately add to those additional business opportunities.

Yeah, that makes sense. That makes sense. Well, good luck with that. Um, what else? What else haven't, uh, I asked you about your work, what Zevilo is doing in the face of this pandemic that our listeners who, you know, some come from really large organizations, some come from small organizations, some are a one-man or one-woman shop out there.

But what else, you know, haven't I asked you that might be useful for our listeners to hear? Well, I think, I mean, so 2 things. One, if you are concerned about protecting your brand, protecting your employees or yourself from content issues and access to potentially malicious things, please go to zavila.com, reach out to us, let us see how we can help you. I think that's probably the first thing I would say. The second thing I would say is, you know, educate yourself, whether you're a security person or you're not a security person, right?

You know, realize that there is a portion of the internet out there that is not a very nice place that really, really wants to take advantage of this situation, whether it's you personally, your family, your employees, your customers, whatever, right? And their goal is to make some money off of this, whether they do it via traditional means, whether they social engineer you, whether they phish you, whatever the case may be. You know, really, really educate yourself specifically and in particular with so many kids that have had to go to the homeschooling model. We've homeschooled all of our kids up to the point they got to high school. So we're really well aware of what it takes to do that, right?

But there are all of these parents out there right now that have been thrown into this, hey, everybody's doing online stuff. Well, this is a great opportunity to educate your kids of what happens on the internet and teach them that the internet isn't all roses and bunnies, right? There's a lot of people out on the internet that will look to take advantage not only of you but of your kids in particular, right? And so this is a great opportunity for parents to educate their kids about what they should post online, what they shouldn't post online, what they shouldn't share, how they should trust things online, all of those kinds of things. Don't, you know, if I were as a parent, same kind of thing, my parent, my kids are scared of me.

They know that I can track whatever they do, which is great, at least in my own house anyways. You know, so, but I tell you what, man, parents, take advantage of this time to educate your kids on this, right? You're not going to have another opportunity like this in, you know, in the near future after this all settles down. And, you know, I don't want to see kids taken advantage of at all. And I think that— and that's one of the great things about our products at zvelo is that we actually support a lot of parental controls for our customers as well.

And so that's one of the things you get. But again, take advantage of that to help your kids understand what's safe and not safe to do on the internet. Those are great points. Those are great points, really. Well, I sincerely appreciate the work that you all are doing, the work that you have done over the last, I think you said, 23 years.

It's certainly appreciated. You're on the digital front lines of this this historic time that we're all gonna look back on and think about how crazy it was that we were locked in our homes for, for 6, 8 weeks, whatever it was. So thank you for your efforts. Thanks for the time, Brad. It's really, really great getting to know you.

It sounds like you guys are doing some really interesting stuff that everybody in the community will benefit from. So, so thanks again for everything and best of luck to you going forward. Great. Thanks, Ty. I appreciate it.

You have a, have a wonderful rest of your day. All right, you do the same. Take care. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Verado equals security.

Back to all episodes