All episodes

Erik Huffman, Entrepreneur, Researcher & Cyberpsychologist

Apple Podcasts Spotify SoundCloud

Erik Huffman, Entrepreneur, Researcher & Cyberpsychologist is our feature guest this week. News from: Strava, VF Corp, Arrow Electronics, DaVita, Zayo, Anschutz Corp, Liberty Global, Ball Corp, Vail Resorts, Boston Market, National Cybersecurity Center, Manetu, ThreatX, DarkOwl, Swimlane and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

Other Notable Upcoming Events

  • ???

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11735 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 163, uh, for the week of May 4th, 2020. Uh, Alex, May the 4th be with you.

Thank you, Robb. Are you part of the Force or are you part of the dark side? Well, I, you know, I like to think of myself as a relatively good guy, maybe a little bit near the edge, maybe a little Mace Windu-y, where I might drop an F-bomb with my purple sword, but, you know, mostly be on the good side. How about yourself? Yeah, I think that I'm definitely on the Jedi side of the Force.

You know, it's hard to argue with that considering they end up winning in every movie. Well, they do a lot more losing than winning, but you're right that at the end— well, I guess the first trilogy not so much, right? The prequel trilogy. True. So we just, my family and I just watched the first half of Rogue One tonight.

I've seen, of course, seen it in the past, but first time for my 12-year-old, and I think everyone enjoys it. And, you know, I don't think they appreciate as much as we do as adults how good a job they did making the look and feel of the movie match the original trilogy 30 years later or whatever it is. Yeah, I mean, if it weren't for the much greater video quality, there are things that are quite alike from Rogue One to A New Hope, definitely. Pretty cool stuff. Yeah, Rogue One, one of my favorite Star Wars movies.

Jumping in, sorry to talk over you there. We do have some housekeeping. Of course, we have a Slack channel, a lot of great conversation in there. We'd love to have you join us in there and talk 1,400+ of our favorite folks in the Colorado community. You can go out to colorado-security.com to find the Slack channel link.

We also have a mailing list if you'd like to get an email from us every week letting you know about the new podcast and what is in it. Go to the website colorado-security.com, scroll to the bottom, put your email in the form, and submit it. And if you want to, uh, we would appreciate it if you would subscribe on your favorite podcast listening app and rate us out there. You rating us helps us get new listeners. New listeners makes the world a little better, and it's kind of a way that you can help move the Colorado Equal Security movement forward.

Or you could just tell a friend. I've seen several instances this week on Slack of people showing up there and thanking the person that invited them to come join it. So just tell a friend, let them know about Colorado Equal Security and the podcast and everything that's going on. And there's other ways you can support us if you'd like to, you know, beyond just telling a friend. If you wanna give financial support, there's a Patreon campaign on our website.

And we're also looking for folks to do guest interviews for us. We've had quite a few guest interviews recently. You know, I felt like we had a lot at the beginning of this quarantine, but we've just got a few more. You know, I don't know if we're going to be able to get out and see people in person again anytime soon. So if you want to help us do some remote interviews, or if you happen to live with someone who would either be an interesting interview for you to do or could interview you, we'd love to talk to you about that.

Maybe we can get you on the show. You know, Robb, it doesn't even have to be interesting. I mean, You know, I interviewed my kids. That was clearly not interesting. Well, that's true enough.

Well, you know, jumping over to news, good news, there are golden tickets out in the wild and you can get a tour. It's a tour of a chocolate factory, right? Yes. So if you get a Willy Wonka chocolate bar, peel the foil back and maybe there'll be a golden ticket there. I've got a golden ticket.

You know, I really love Gene Wilder. He was an amazing actor. Um, you're not the Johnny Depp version? Definitely not. Uh, but that's not what we're talking about here, Robb.

Uh, big tangent there. Uh, Strava Coffee is giving 5 $1,000 golden tickets to customers. Um, if you order online between April 27th and May 1st, uh, you may get one of those golden tickets in your order. So this is really us talking about what could have happened if we had talked about this last week on the show. But we think it's interesting anyway.

Strava is a Denver-based company and they make coffee with hemp in it. It's this, I guess, is the CBD coffee, right? So if you need a little pick-me-up along with your pick-me-up, they might be the right coffee for you. Definitely. Also, there's been a lot of good going around, not just the potential of winning $1,000 by ordering coffee.

A number of different organizations, including VF Corp, have been doing good things in terms of launching relief campaigns. Yeah, so this is a pretty cool article. It's in the Denver Business Journal. They had a number of different examples of companies that are, that are doing good and giving back. I pulled out a couple of my favorite examples.

Voodoo Doughnuts has launched a new doughnut called the Brainiac. It's a pastry decked out with strawberry frosting and Nerds candies. And they're going to use the profits from this are going to go to raising money for the Hunger-Based Generosity Feeds. So you can get a limited edition pastry to help support that donation. That's a pretty cool thing that they're doing here right in the middle of COVID That is cool.

The Denver Toyota Dealers Association donated $50,000 to the newly created Colorado Restaurant Response Food Coalition to help with folks that are in need of food. One other one I wanted to call out personally, the Denver law firm Brownstein Hyatt Farber Shrek. They have made a pro bono team to help nonprofits navigate through the PPP, the Paycheck Protection Program. You know, we've heard a lot about the federal government coming up with that program, people running out of money, not knowing if they're— if they should be able to get it. So it's pretty cool that they're helping nonprofits figure out how they can take advantage of that and, you know, not taking any money for doing it.

You know, that law firm has got everyone and the kitchen sink, but they've got Shrek but no donkey. Oh, I tried to come up with a witty response, but I failed. My Eddie Murphy is not so great. Next, next story. I'll tell you about these 13 prominent CEOs here in Denver that are helping form a group of their own to help with the well-being here in the area.

So, these companies, we'll go through who they are, but they created a group called Colorado Thrives, which is a 501 that's really just going to be focusing on making the whole area better and it's really not focused on business improvements. Yeah. It's focused more on individual improvement, which I think is pretty cool and specifically what they were going for. And the thing that they are focusing on first is around economic mobility. Yeah.

Pretty cool stuff. They've been meeting for more than a year with the Boston Consulting Group to figure out how can they make a difference, what's the best way to impact the the area, and they come up with economic mobility as a first place for them to start, but they say that certainly is not where they want to end up. That's just a starting point for them. Yeah, pretty cool. You've got executives from all kinds of different local companies, including Dan Caruso, founder of the Zayo Group, Steve Cohen from Anschutz Corporation, where I happen to work, the president and CEO of Ball Corp, Rob Katz from Vail Resorts, Steve Rendell from VF Corp. Lots and lots of people from big-name companies here in town.

Yeah, Arrow Electronics made it, Liberty Global made it. Really cool to see, to see so many of these big business leaders in town contributing together. We applaud them for what they're doing and look forward to seeing what's next. In other news, Boston Market has been sold to an East Coast restaurant operator, so Boston Market is one of the, I guess, fast casual restaurants that is based here in Colorado. They are a 284-location chain these days, and they were owned by Sun Capital Partners but were sold to Engage Brands, which is part of the Rohan Group.

Yeah, when I mentioned this to my wife Kristen, um, she said, man, weren't they owned by somebody else? And Sure enough, back in 2007, they were owned by McDonald's. McDonald's is the one who sold them to Sun Capital Partners. So interestingly enough, they've been moved around a little bit, but they are still headquartered here in Colorado, and it looks like that's not gonna change through this. They are the biggest of the restaurant chains here in Colorado.

Them and Noodles and Quiznos and Smashburger are some of the other ones. We used to have Chipotle. Those suckers left. You know, that stinks, but it is what it is.

The Rohan Group also owns Pizza Hut and the Checkers and Rally's franchises. Yeah, and they— I think they owned a bunch of other franchises. I can't remember what they were off the top of my head, but they have a whole bunch of different restaurants that they have pieces of. Moving on to our next story. You know, there's— we've had a lot of news about people who have been laid off and folks who are unemployed right now.

We don't cover a lot of that type of news on this show, but I did want to But we did want to focus on this one story that's a little bit good. If you are someone who's looking for work or you know someone who is, there's a number of industries here in Colorado that are hiring large numbers of people right now. Yeah. One of those is grocery stores. Obviously, people still need to get food and maybe even more than normal since eating at home more instead of restaurants.

Yeah. So we got parcel and mail delivery. I know we see a lot of that. It's big increases on all of those. Hardware stores, which of course are still open.

My local hardware store has had a sign out front looking for somebody for a good long while now. They have healthcare industry on here, and I think it kind of depends on what healthcare you're talking about. Some healthcare industry positions have had a lot of pressure, and then some really have had nothing to do because clinics are being shut down and non-elective— or excuse me, elective things have been postponed. So I think it's kind of hit or miss with that, but there's a number of hirings for healthcare. And we focus on one what, a few weeks ago when DaVita announced they're hiring 15,000 people.

Yeah, and I think that was one that was mentioned in this story as well. And, uh, and finally on their list, food delivery. Um, obviously explosion in, in the number of delivery drivers that are needed to deliver, um, all the, the, uh, takeout delivery food that's going on right now. So, you know, obviously not security-related jobs, or not for the most part on these, but if folks are looking, if you're looking to help someone you know and love find a new place to work, there's at least 5 places to start looking at. Big news for Colorado Springs.

The National Cybersecurity Center, the Space ISAC, and Exponential Impact have won a $3 million grant to help expand the facility that they all occupy down in Colorado Springs. Yeah, one of the interesting parts of this is that $2.75 million for the grant, but it can't— they would only be sent if there was a matching fund from the local business as a part of that, and they did get the matching fund. So they're really getting— what would that be about? $5.5 million. And they're going to use that money to create— well, they say that this money will create 360 jobs, which is just amazing, and is going to attract more than $9 million of additional investment.

And that's based on the US Department of Commerce, their announcement. Yeah, pretty cool. So they're going to use this money to do a couple things and build out the building that is down there in Colorado Springs with offices and classrooms. Including a cyber vulnerability lab and watch center that will be part of the Space ISAC that is based there. I mean, for me, the big news coming out of this is there's a Space ISAC.

I had no idea there was, you know, ISAC, Information Sharing and Analysis Center, or an information center. I didn't know there was a Space ISAC, and I didn't know it was in Colorado. That's pretty awesome. And of course, this is, you know, it's really tied at the hip along with NCC and Exponential Impact. So it's pretty cool stuff to see them getting, you know, new resources.

Good stuff. Uh, next story we've got here this week, um, we— there's a new startup in town, a data privacy startup that just raised $3.5 million in seed, in seed, uh, funding, which by the way seems like a massive amount to me, $3.5 million as your kind of your seed. Um, but their name is— I'm going to try and say it— is it, um, Mainetu? Mainetu. Um, they are— they're located here in Colorado, and then they're really focused on helping give consumers the ability to control their own data within an enterprise software platform.

Yeah, this to me sort of reminds me of a OneTrust or some of the other platforms that people are using these days to, to work with data subject requests and, and companies, you know, using it for, for people asking about their data or to remove their data or other things like that.

One of the things they talk about here is being able to sort of be that the middle place where that data can live and be controlled, even though the Maneatu software won't be able to see the data. Yeah, it's interesting. I struggle with understanding how their software wouldn't see the data. The way they describe it in the article is that Maneatu's machine learning algorithm scans data stores for any and all personal information that enterprises hold. It organizes and classifies that data, puts it in encrypted copy in the Mainnet 2 control plane, and then only the enterprise and the consumer can access it.

Really interesting. I'd be curious how the technology works. Either way, it's exactly the kind of moves that we're going to need in order to really work with this new privacy-focused world, and I'm excited to see Colorado have a company that's focused on doing it. Well, Robb, I can tell you how it works. The seed round was led by blockchain-focused Castle Island Ventures.

So clearly it is the blockchain. Well, if the blockchain's taking care of it, then I'm not worried. Uh, next, uh, an announcement from ThreatX. They are, uh, announced a new CEO, Gene Faye, uh, coming in to, uh, replace Brett Settle as CEO. Uh, Brett is not going anywhere.

He is going to assume the role of Chief Strategy Officer. Yeah, so this is exciting news. We've talked with Brett on the show in the past. We've talked about ThreatX a number of times. They are the local WAF player.

Gene Faye, he came over previous to being here at ThreatX, he was the Chief Operating Officer for White Ops, where he worked with the co-founders to help grow that organization. Previous to that, he worked for Resilient Systems as a General Manager and the VP of Sales, and it looks like he helped them double sales over 5 years. So hopefully he can come into ThreatX and, and really give them that shot in the arm and growth that they're looking for. Yeah, um, please don't, uh, sell ThreatX short though, Robb. They are not a WAF provider, they are a next-gen WAF provider.

Well, which gen are we on? The next gen. I guess if you just say next gen, it doesn't matter, right? It's just I'm always— exactly, I'm always one generation above whatever— ahead of whatever you're talking about. I'm completely next.

Uh, our next story, uh, is Dark Owl, another local company. They have selected BlueVoyant to help deliver the managed detection and response service, which is going, which is going to be enabled and enriched with Dark Owl's threat intelligence, which we've talked a lot about on the show. They have that dark web indexing, and they're going to help use that with BlueVoyant to deliver a better service. Yeah, I was a little confused by the article itself in the way that they wrote this out, but I mean, it does sound like the BlueVoyant MDR platform is just going to be enriched with, with the Dark Owl dark web data, but it sounded sort of like Dark Owl is delivering the service, so I was a little confused about that part. What my guess— and I have done zero analysis on this, so we call this a fact-free, what would that be, immature, inappropriate reporting— but my guess is that Dark Owl has some customers who said, hey, I love your, your, your your dark web index, but I don't know how to look through my environment and see if I'm impacted.

And they said, can you help me do this? And Dark Owl said, well, we don't do that. And they went out and found someone who would do that as a managed service for their— for Dark Owl customers. And now they can come to their customers and say, here you go, here's a solution that, that gets you all the way there versus, you know, just our technology. That's my guess.

Yeah, that seems like a pretty reasonable guess considering there are zero facts there. No, we could, we could have gone to the effort of like emailing them or, or trying to get an interview. Uh, we're not those type of reporters, everybody. I think you're stretching it a little bit by saying we are reporters, Robb. Uh, finally in the news this week, uh, we have a blog from Swimlane talking about responding to insider threats with SOAR.

Yeah, you know, we don't always do blogs. I've, I looked through this one and I thought it was really interesting. You know, SOAR has been one of those areas where The idea seems really important, but it's just hard to figure out exactly what does a use case look like that where you can actually go from an alert all the way to an action. And what I really liked about this blog post was that they do walk all the way through that. You know, they go through the, what I would call kind of the relatively easy steps of SOAR where you're, you know, you take the alert and then you do a bunch of enrichment and you get a bunch of analysis.

What I'm used to seeing is you get all this enrichment and analysis and then you send that off to a human to say, okay, what do I want to do about it? In this blog post, they talk about, you know, how you can make the decision at that point to go into Active Directory and maybe disable an account, lock out an account, whatever the access would be. I thought that was interesting, and I like to see the specific use case where they're saying, this is the one that you can actually act on. Yeah, I really like the approach. Anytime you have some sort of blog where they take a use case and sort of implement it end-to-end, either in a, you know, in their product or, you know, some other way, I think that that's really useful for people and can provide value to folks that are reading the blog.

So good stuff. Thanks to those guys for doing that. Well, that's it for news. Let's jump over to our Slack message of the week. Big thanks to Andre Gaeta.

Every week he's kicking in his own money to help buy something from the Colorado Equal Security store for one interesting comment that we get out of the Slack channel. Yeah, and based on that, this week our winner for the Slack message of the week is Frank Vianzon. Congratulations, Frank. He posted a job post from Cisco. They are looking for a Jedi Knight.

So speaking of may the Force be with you, if you want to be a Jedi Knight, go look in the Slack channel to find that Cisco job post. So when I saw it, what I was thinking was it was going to say Jedi Knight and then it was going to be like, you know, you're going to, you're going to practice security and keep You know, the rebel safe or whatever, but it was just like written like for a Jedi Knight, the entire thing. There was no part where it actually talked about a real job. Somebody had a little bit of fun. You know, we're guessing maybe it was posted on April 1st, but we didn't find it for a little while after.

I don't know. Anyway, it was amusing. And thanks to Frank for finding that and sharing it with the community. Of course, at the end they did say, this isn't a real job post, but we have lots of jobs that you can apply for if you're interested in this. Oh, but did you— good on that, Alex.

Uh, I think I am okay right now. Thanks, Laura.

Uh, so we do— moving along, we, we have an event calendar. We've talked about this the last few weeks. Um, there are a number of virtual events that have been spinning up, so we'll talk about a few of those. Still, you know, be cautious as you look on the calendar. Some of the stuff on there has probably been canceled.

Make sure before you try and go to something that it's still legit. But these 4 look good. On May 4th, you know, uh, Monday, we— there is a cyber— excuse me, Global Cyber Alliance DMARC boot camp. I think this is awesome. If you want to learn about email security, go attend that.

On the 5th, ISSA Denver is starting some online virtual meetings. They're doing one called Hang Out a Shingle: Starting Your Own Cybersecurity Company, and Douglas Brush and Daniel Ayala are the ones that are presenting that. Yes, this is cool because the content that they're doing on these is actually from the Rocky Mountain Information Security Conference. You know, that conference has been canceled for the year, and these guys were ready to talk there and have decided just to do that talk for the community virtually. I'm pretty excited they're doing that and looking forward to seeing the content.

On the 7th, we have a similar one, another, another one of those RMISC talks. It's the Hacker Business Models: They're Out-Innovating the Rest of Us, and that's by Steve Winterfell. Looking forward to Steve's talk as well. And then on the 14th, the Northern Colorado chapter of ISSA is doing their May chapter meeting in a virtual fashion. There's a hot tip for all of you guys.

If you think, hey, I've never been to the Northern Colorado chapter, that's a long drive from me, you could go anyway. You could, you could do it even though it's not anywhere near your house. That's right, crash the party. All right, let's move over to jobs. I do have a couple of jobs at Ping and the security team looking to hire a GRC analyst.

This is someone who's, who's really kind of a jack of all trades within GRC, helping us with ISO and SOC audits, business continuity. Helping support incoming questionnaires from customers, even some of our privacy program work. So someone who's looking to get their foot in, into the security area, that'd be a good first opportunity for you. We're also hiring a product security engineer. This is someone with a development background who can help us embed security practices within our product development lifecycle.

Staples is also looking for an AppSec person. They are looking for a senior application security architect. I believe that position is reporting to Dustin Lair, who put out a great post this week on LinkedIn talking about application security testing. Yeah, good stuff. ULA, the United Launch Alliance, is hiring an Information Security Architect 6.

If you want to skip those first 5 levels, jump straight to 6. Synoptec is looking for a Director/CISO. Charter Communications is looking for a Vulnerability Engineer 1, vulnerability and remediation. Zoll Data Systems is looking for an information security engineer. The state of Colorado is hiring a senior cybersecurity engineer.

Arrow is looking for a corporate IT auditor 1. And finally, PwC is hiring a cloud security DevOps engineer. Pretty sweet. Good jobs this week, especially considering, you know, the, the kind of uncertainty in the market. A lot of good opportunities here in Colorado.

I will say, Robb, as the person that's been gathering the jobs for us for the last few weeks, there are fewer jobs out there, but as you can see, there are still some good ones. All right. Well, we do have a guest interview this week. Erik Huffman sat down with Jason Jaques. Looking forward to this interview.

Erik has some kind of an interesting title. You can see how we titled the episode, Entrepreneur, Researcher, and Cyberpsychologist. So that's pretty curious. Ooh, does that pique your interest? It does.

My interest is piqued. Well, looking forward— stick around, listen to it, and let me know what you think about his cyber psychology. Sounds good. All right, well, that is it. Thanks everybody, and we'll look forward to talking to you again next week.

Thanks, Robb. Hi, this is Chad Payne, Executive Director of IT Operations for Kraken Sports and Entertainment. Welcome to Colorado Equals Security, the Colorado security professionals like Colorado security professionals. Colorado equals security. This is Jason Jaques, host of Emerging Tech Fan.

I recently attended the SnowFROC conference put on by OWASP Denver. While I was there, I conducted 2 interviews. The second interview is with Dr. Erik J. Huffman, a cybersecurity researcher and founder of Handshake Leadership. Here's the interview. Enjoy.

Dr. Erik J. Huffman. Can I call you Erik? Yes, sir, please, please. Thanks for being here today. Oh, no problem.

So we are at SnowFROC. You are my second interview, actually. I just interviewed Aaron Cure. Um, what do you think of this conference? It's awesome.

It's, it's different. It's definitely more software-driven than most of the cyber conferences that I've, that I've been to. Much more talking about the the internet and the DevOps and the development process. It's amazing. It's amazing and it's different.

So it definitely has its own space in its own lane within the whole conference realm. So you go conference to conference, a lot of times you hear the same thing from a different person. And that's definitely not here. Yeah. There's very different topics here for sure.

Yes. I've been impressed. This is my first SnowFrock. How about yourself? It's my first kind of.

Okay. The first experience was actually last year during the bomb cyclone. Oh, so I couldn't make it up here. Were you supposed to speak at that one? Yes, I was.

But you couldn't make it up? No, they shut down the interstate, so it was impossible for me. The interstate and even the back route. Yeah, there was no way aside from an airplane, and they weren't even flying at that point in time. Oh wow.

Okay, so then this is technically your, uh, I guess your first. Yeah, but it's supposed to be your second. Yeah. And you, you just got done with, uh, your talk or, or your speech. What was it on?

It was on cyber psychology. Okay, so that's— and this is going to dive into your, uh, your research, right? Yes, sir. Okay, so let's, let's pause on that because I, I do want to dive into that. But, uh, before we kind of go that route, let's talk a little bit about your background.

So are you from Colorado? Yes, sir. Born and raised. Yeah, where at? Fountain, Colorado Springs.

So, okay, down south, south of about an hour south of Denver. Okay, tell me a little bit about what it was like growing up there. Oh, it was, it was fun, you know. Got, got myself into some trouble as a kid just hanging out with family and friends and, you know, but, uh, love, love it. I— it's a hard, it's a hard place to be.

It was, uh, being an hour from Denver, which is a major city, one major interstate, uh, it's a big city, it's small town and it's only growing. So it's so much fun. I, I love it here. But you've never moved up to the big city? No, sir.

No, sir. You've stayed away? Yes, sir. Successfully? Yes, sir.

Right on. I like Colorado Springs. I love going down there. It's, uh, it's always— I always have a good time down there. What's some of your hobbies?

So I, I like to play Mario Kart a lot. That's okay. Is that still a game? Yes, it is. I did not.

Yeah, there's Mario Kart 8 Deluxe on the Nintendo Switch. Okay. Yeah, I love it. I love it. That is, that is my hobby.

Every Wednesday, me and 3 of my best friends, we get together and we're just boys. Yeah, take out all— one's a, one's a police officer, one's a teacher, and so we just need time to not be professionals and just be boys. And so every Wednesday we get together, we play some games, but my favorite is Mario Kart. I know I sound like a nerd, but— No, that's awesome. I am a nerd, so yeah.

So does the police officer chase you around in Mario Kart and try to, I don't know, write you a ticket? Can't catch me. Oh, there you go. There you go. You always win.

Yeah, that's funny. So we're all plugged into the digital world. Do you have any analog hobbies? Specifically, what do you mean? You know, I, I like to unplug and do— this is gonna sound weird— I like to mow my lawn.

Nice. No, that, that is, that's legit. Yes, that's good. My— I like to mow my lawn as well. It's how I decompress.

That's how I, yeah, get away from the digital world. Nice. Being, being in Colorado, I love fishing. Okay, kind of, that's kind of my my thing. I haven't been fishing— well, the past 5 years I haven't fished as much as I wanted to.

Yeah, but last year I made it a point, I went out fishing a lot more and I loved it. I loved it. It's just I'm not very good. I won't say I catch a lot of fish, but just to be terrible— what do you catch? What kind of fish?

Anything. A lot of times a lot of seaweed, but, but it's, uh, bass. Bass, bass, bass and trout. Those are I'm not catching anything crazy or breaking any Colorado records or nothing like that, but it's fun just to get out and just hang out. We live in beautiful Colorado.

You have to get out and hang out. Yes, sir, you certainly do. So how did you get into the industry? Let's talk about that. Well, my dad— when we grow up— when we grew up, uh, it was a— we didn't have a whole lot.

And he was in the Army. He's retired Army. And so I saw him gravitate towards computers and he started programming. He got a bachelor's degree, then he got his master's degree in software engineering. And I saw us go from like about 600 square feet into a house.

And I had a room to my own. Yeah. And then we went to a bigger house and he retired and he's doing fantastic. So I saw that as kind of a way to do it. Like, well, it worked for Dad, so let me give it a shot.

So I got my bachelor's degree in computer science. My master's degree is in the science of management, concentrating in IT management. But then I found cybersecurity to be this thing that I, I love to, to find ways to break things. Because as a kid, that's typically what I would try to do is, uh, find ways to, to break things and get access to stuff that I, I shouldn't have, or they didn't want me to have. And then, uh, and then you've gone beyond your master's.

Yes, sir. Yes, sir. Because I introduced you as doctor. Yes, sir. I have, uh, my, my doctorate is in management.

Um, is concentrating in organizational development and leadership. Uh, but my research is that cyber psychology stuff. Yeah, I think that's awesome, by the way. I rarely interview anyone that, uh, that's a doctor. So this is an honor and a privilege for me.

I appreciate it. It's not as cool as it sounds. It's a whole lot of reading, a whole lot of writing. Well, let's actually, let's dive into it and talk about it. So tell me about, tell me about it and, um, the research that you're involved with.

So cyber psychology is a blend between cybersecurity and neuroscience. I specifically focus on the biological deficiencies of human beings in a cyber environment. So it's not focused on age, race, gender, or anything like that. I'm specifically looking at how do you as a person interact with technology and what are the deficiencies in that? Because In a cyber environment, we're talking about computers and tablets and phones.

Yeah, these are things we built. We're not built for it. So it's not a tree where some animalistic instinct is going to help you out during a phishing attack. That doesn't happen. So with us doing that and this being fairly new, there's got to be some room for growth because if you look at the current rate of attacks, it's just through the roof.

If you look at the rate of technology innovation, it's through the roof. You would think the more we innovate in security, the harder it would get to hack. And actually, information is showing that the more we innovate seems to be the easier it is to hack. So we've been doing this for 30, 40 years. Cyber is just a cool word.

It's been information security forever. So the only thing that hasn't changed is us. It's been people being involved into that. So that's why I focused my research, and that's when I really started looking at the human element, because everyone says the human's the problem, the human, the dumb user, or something like that. But no one really put the pieces together in a way that science embraces.

So the neuroscience on the human brain versus you being a person behind a computer screen. How do you behind a computer screen interface with that technology and how does the brain work with that? And we have some very interesting findings that we're digging through. We're over 10,000, close to 15,000, if not a little over now, 15,000 participants in different studies. Wow.

So the data is actually growing and what we're thinking and the conclusions are starting to become a little more clear. However, I do want to, I do want to state that it's a new study, right? And there's just me and maybe a couple other people out there that are paving the way. We're just hoping more people contribute to find out we're either right or we're off a little bit. But it looks good.

It looks great right now. Can you talk about what some of the findings are, or is it too early to talk about? Um, no, we could, we could talk about it. Uh, so for example, in your brain there's something called the limbic system. Okay.

The limbic system is fight or flight. Um, it's actually fight, flight, or freeze. So with fight or flight, if someone ran into the room acting crazy, uh, immediately you're either gonna fight or you're gonna run faster than what you ever thought in your entire life. That's a biological function. That's not a decision based on your past, your background, or anything like that.

You're either going to fight or flight. Either you're going to feel like you're tough or you're not, or something, something along those lines. However, when you read a phishing email, you don't just like dodge out the way because you're like scared or something like that. So that biological part of your brain shuts off unless you're watching a video or a movie or something like that, which is why you dodge out the way of the screen. Is because that fight-or-flight is kind of kicking in and say, hey, dodge, just, just dodge out the way, move out the way.

Okay, so we partnered that area not being activated with the notion and the fact that when you read, you actually read in your own voice. So you don't read in my voice, you don't read in a stranger's voice, you read in your own voice. And now if I send you an email, Because if you don't know me, you don't know what voice to read in, so you're gonna read in your own. So it breaks that biological barrier down. Yeah, because I couldn't walk up to you and say, hey, can you go buy me a $500 iTunes gift card, scratch the back off of it, and give it to me?

Most people on the planet— I'll be— I'll just pretty much say everyone on the planet would say no. However, that's one of the attacks that are happening and is working. It's because that biological— that biological barrier is broken because you're reading it, you're reading it in your own voice, unless you know the name, or unless you know your loved one. So like your, your wife or your kids, if they send you an email, you begin to read that in their voice, which is even more dangerous because you trust the messenger more than you trust the message. And so as you start to read the message, it doesn't matter what it says.

The messenger is a trusted source. It is a person that you love. It's a person that you trust. And so there is a huge problem with that. So we started working with different organizations in conducting phishing campaigns in a different manner.

I preach that we need to practice how we fight. We typically don't. So we send a phishing campaign with the Nigerian prince or something like that, and no one's really falling for it. So you're the one doing all these phishing campaigns? Is that what you're saying?

I do some of them. I don't— But it's all for research? Yes, exactly. Exactly. I'm not sending them out.

We have approval and there's a scope. So we're not phishing people just to phish people. But every time we conduct one of those phishing campaigns, we interview the participants. And the findings are mind-blowing. You would think that it's not just, hey, you're a dumb user.

So if we, we worked with the organization, we spoofed the CEO, and so the email looked like it came from the CEO. The individual had clicked the link, and during the interview, he told us, he's like, the CEO scares me, that he just laid off 100-some-odd people, and I don't want to be laid off as well. So we partnered this, we talked to the CEO like, hey, unless you do something about this, there's this attack vector that is not going to get fixed by technology. He sees your name, it promotes the feeling of fear. Yeah.

And so he's going to respond just to help you out and because he wants to help you out. So there's an area that we need to fix. We need to fix that gap. That's fascinating. I've never thought about that before.

So how do you go about fixing that, that gap, that attack vector, if you will? Yeah, it sounds a little cheesy, but we, we ask a lot of reflection, a lot of introspection, because if you don't understand yourself, you don't really understand how you're gonna react. And there's all kinds of things that influence that— how you were raised, your cultural, your social norms. We've seen the social engineering practice where people hold a box of donuts and they just follow you into a secured building and you just hold open the door because you're being nice and you're holding open the door and who's gonna deny donuts? And so they walk in and next thing you know you're hacked, or they start dropping thumb drives everywhere and you pick up a thumb drive, you plug it into your computer because you want to find out who to give it back to.

We'll just say you just want to find out who you give it back to, and next thing you know, your computer's compromised. Or you drop a thumb drive and you put layoffs— you write layoffs on it, and of course you're gonna be really interested and you're gonna plug that into your computer and you've been hacked. The largest hack on a military facility came from exactly that. They had a thumb drive, they threw it over a fence, The person plugged it in, then the rest is history. No kidding.

Yeah, so there, there's, uh, there's issues that we need to face as people because the more we innovate, uh, it's, it's not a one-to-one ratio. Just because we innovate and we make it harder for attackers, that innovation is available to the attackers as well. So we developed encryption for different— for data confidentiality so you can't read it. The attacker took that and they developed ransomware. So unless we start addressing us and we start looking at us as a potential problem and a potential solution, we're going to run into some issues.

We did a study recently with over 5,000, like 5,000, about 5,000 participants, and we found cybersecurity professionals click links at a higher rate than the layman. So it's not— you understand cybersecurity, it's not, well, I understand cybersecurity, I'm not gonna fall victim. No, if I get an email— curiosity. Yeah, well, if we think we're safe— you're right, you're right. If you send me an email and you pretend to be my mom, there's no— I'm gonna feel some kind of way.

Yeah, you know, I'm a mama's boy, I love mom, so I'm gonna start reading in her voice and And immediately you have my attention. At least you're going to have my attention. If we go by the notion that I'm a cybersecurity professional, I'm going to never fall victim to a phishing scam. It's not because you're a cybersecurity professional. It's either, are you cold enough to turn off that part of your brain that you're, you see a name of a loved one, you're not going to feel anything, or do they just not know how to reach you?

If you're a sports fan, if you're a Denver Bronco fan, and they say, hey, Von Miller got traded, send in a phishing email. Boom. You're not gonna read it? Yeah, I probably would read it. Yeah, like if you're— just be honest with yourself.

Yeah, that's what we're facing. Attackers, they may not understand the science behind it, but we've seen it since high school, since elementary school, where you have the cool kids spreading rumors about some other kid just to change the outlook on them. There's a whole lot of sociology involved in that. However, in those situations, I can see the problem. I can see the attacker.

Here, we can't see the attacker. We're, we're at their mercy, right? Because they can communicate to us at any point in time. Every organization on the planet accepts email. They just got to get through the spam filter.

And if they get through the spam filter, they just got to get you to be interested and click once. Yeah. And there's, there's a lot of data. So there's a Big 5 for cybersecurity victims. If you're an extrovert, that's a personality trait for a cyber victim.

If you're conscientious, that's a personality trait for a cyber victim. If you're emotionally stable, Not to say that that's a bad thing, but if you're emotionally stable, you're willing to sit down and work with someone. If you're not emotionally stable, you're gonna like, oh, my girlfriend left me or something, start crying or something like that. Like, that's not the mindset that you need to, to victimize someone. So you need to be emotionally stable.

If you're open to new experience, the number one personality trait we found is that impulsiveness. The more impulsive you are, the more likely you are to be a cyber victim. Not because I don't need to fool you for a day or an hour or anything. It's 30 seconds. If I can get you— if I get your attention for 30 seconds and I get you to click and send me information, um, it's, it's, it's a wrap.

Wow. So where is this research taking you? Where do you think you'll, uh, you'll end up 5, 10 years from now based on this? Ah, are you going to be teaching the world about kind of new ways to think through some of these attacks? What do you think?

I hope— hopefully, hopefully it lands somewhere in a place where we change how we do training. Yeah. Okay. Because training is currently right now, it's all computer-based. You click on the link and then you click next 15 times like you're installing Microsoft Office or something like that.

Then it prints you out the certificate, then you're good for the year. That's not right. That's not how we need to do it. Hopefully, 5 years from now, we're changing how we're training, where we're bringing in psychologists, we're bringing in sociologists, we're bringing in people to help people understand themselves so they know how to act and react during a cyberattack. Because if you came from a place where the social norms is to be helpful, to hold open doors, to communicate, to answer questions when asked, or if you see a position— if you see a person of authority, to acknowledge that person of authority at all costs.

Those things can and will be used against you. If you're going to hold open the door for a woman every time because it's just the right thing to do, every woman attacker is going to get into the door every time until you address Not that you're a bad person. It's just there's times and places the enemy— it sounds rough to say, but attackers, they're criminals. They're not playing fair. Yeah, and we need to understand because they're not playing fair, we're, we're leaving ourselves vulnerable, and they're preying on you being a decent person, you being a nice person.

There's people that have gotten the phishing attacks saying, hey, we got video of you watching adult videos, and people are committing suicide because of that. Part of your brain is that limbic system. The other part is your amygdala. And there's something called amygdala hijacking, where your brain literally shuts down and it just focuses on something that needs immediate attention, and you're no longer thinking rationally. And that's a biological function that happens to everyone.

It's not that if you see the same phishing email, you're going to react the same way. That's not it. It's just how do you get to someone? How do you influence their behavior? That's what they're focused on is how do I get you to click?

How do I get you to send over the Amazon— well, the iTunes gift card information? How do I get you to do that? If I could influence your behavior, then you've been had. And we're not really focusing on that in cybersecurity at all. We're focused a lot on the firewalls, the IPS systems, DevOps, and cyber hygiene, all the buzzwords, you know, all the buzzwords that actually get people to click because it's, it's the cool thing rather than, you know what, you are the problem and this is why.

And let's, let's take some time. Let's address that. So I think it's interesting that you mentioned the fix really here is ultimately training and how we go about training, because you have an interesting background. You've been in traditional academia. You were a dean or an assistant dean for a school.

Yes, sir. What's the story there? So for a while, I was a dean and associate dean and associate director. So being in traditional academia was fantastic. Yeah, I enjoy— I really enjoyed it.

Meeting a lot of people, meeting a lot of students. Yeah, seeing people through their journey into this industry or another industry, it didn't really matter to me. Um, it was— it's fun, I love it. And then now you're doing more boot camp style training, right? Because you're, you're teaching at SecureSet.

Yes, sir. So how do you see, uh, you know, the, the world evolving? I guess traditional academia versus boot camp style training versus where it should be going. I guess either one of those things or both. What are your thoughts there?

There's a place for both, and I don't want that to sound like a cop-out answer, but I'm just being honest. Yeah, there's a lot of students that are going to traditional universities that are absolutely amazing and And you don't need 4 years. You don't need history, math, or biology. You don't need those classes. You need to go through a bootcamp, understand the concepts, pick them up extremely quickly, and then apply them because the industry needs you.

But there's also other students that struggle greatly in a bootcamp where 20 weeks isn't enough time. It's not that they're not smart enough. Or they don't belong in the industry. It's honestly, you need to spend more time, dive deeper into particular concepts. That's why the 4-year university will be great for those individuals.

If we stop focusing on the university and just go to the bootcamp, we're leaving a bunch of amazing people out that just learn at a slower pace. The bootcamp is fantastic for those that can get it and get it quickly and want to apply it. I will say the bootcamp is not for everybody because it's not just your easy way into the industry, because if you don't know it, you're going to be found out extremely quickly and you're going to find your way out the industry extremely quickly when you should have been in a 4-year university and really picked it up and really understood it. But if you pick it up extremely quickly, I don't know if I would have made it through a boot camp because I struggled through some of the concepts and I really needed the 8 weeks. I needed a semester of this so I could fully understand it.

Some people need a week of this and they fully understand it. That's who the boot camp's for. But for us regular folk, the university is absolutely fantastic. I highly respect both of them. Being a doctorate, of course, I'm an academic and I love I love 4-year universities, but I teach at a boot camp and I see a place for it.

Yeah, what do you like teaching at better? Um, SecureSet's awesome right now. Yeah, I like the cohort model because you see, you got a group of students and you're seeing them all the way through and you really grow close and you grow attached to those people. At a university, there are so many people. I didn't really feel connected to a lot of them, and if I did, it was probably because you were in my office a lot, and it may not have been on the best terms.

But when you have a group of people that are with you throughout 20 weeks or 12 weeks, you really grow close to those people.

I enjoy teaching there more because of Probably because of that, because I really connect to every one of my students. I know who they are. I know a little bit of their background, know a little bit of their story. Yeah. And so I know every single one of them because there's 40 to 50 of them.

That's about it. Yeah, at a university, it's a couple thousand. So there's no way I get to know— I get to know all of you. Talk to me about Handshake Leadership. What is this?

How did this come about? Well, Handshake Leadership is, uh, my company is a company that I own. We focus on, uh, organizational development, leadership development, and cyber education consulting. Those are the 3 things that we feel we are really good at. Okay.

And it started when I started my doctorate. Every instructor that I met was a consultant, and I looked up and I aspired to be like every single one of them because they're absolutely amazing and fantastic. So figured I'll give my shot. I'll start consulting as well. Little did I know my dissertation, part of my dissertation topic was on a new organizational model.

Now, no hierarchy, because to say, hey, I work below this person, I work above this person, it's kind of demeaning. It's really demeaning. So we focused on a circle on an organizational chart. And so if we follow that, our motto is purpose over profit. So we don't deny any company, we don't deny any organization because they can't pay.

Okay, so that's who we are, and I, I absolutely love it. We're, we're rocking it right now. It's truly, truly a dream come true for us to be in the position where we are. Like, some self-bragging is We won best social impact company in the Colorado Springs Business Journal the past 2 years. Yeah.

Congrats. Appreciate it. Undeserved. 100% undeserved. Why?

To be honest, when I see our name and you see organizations like Pikes Peak United Way, you see organizations like TESSA, I'm like, we're just, we teach kids and stuff. We have some boot camps. We do some fun stuff with kids. But we're not saving lives and those people are. You know, Pikes Peak United Way's doing— they're donating thousands and thousands of laptops to schools and Tessa's helping women and men in abusive situations.

Nothing we do compares to that. So it's totally undeserved. So if anyone's listening, we appreciate it. We love you. We love the support.

Support them. Don't— you can support us as well, but the vote for best social impact company is probably to the most impactful company. They can't win it every year, so it's true, they need to spread it around. So you, you get to win it one year, and I appreciate it. I appreciate it.

So the Handshake Leadership, then it's, it's teaching cybersecurity, right, ultimately to a wide range of organizations, including kids. Like, talk— tell me a little bit more about that. So we We teach— we teach teachers how to teach cybersecurity. Okay, that's the— that's our number one thing. We also teach kids as well.

Okay, because a cybersecurity professional is not going to take a teacher's salary because teachers are grossly underpaid. Yep. So what can we do? We just can't sit here and say, well, tough luck teachers, and then they go to some cool coding boot camp, they go to some cool cybersecurity boot camp, then they go into class And they feel like they're cheated. And so they lose their interest because they spend most of their time in class.

So we teach teachers just how we teach cybersecurity professionals. They go through all the training, they learn how to actually do the stuff, and they certify as well. Okay. And currently we're developing our teach— our certified cyber— certified cyber teacher certification. Okay.

Because we want to certify those teachers that understand education and cyber. Security. Cool. Um, but we also teach kids. Uh, a cool thing we do, we teach Girl Scout troops.

Yeah, because Girl Scouts, they get cybersecurity badges now. And so we teach all 3 levels for all levels of Girl Scouts, from the Brownies to the Juniors and the Daisies. I know more about Girl Scouts now than I ever thought I would. Um, and we teach them just, just how one and the same. Uh, it's amazing.

We go over cryptography, And I remember there was this girl in our last class. I wrote my name up. I was like, if A equals B, B equals C, C equals D, what is this? And she's like, that says hello. And then this other girl in the back, she's like, I wrote my name.

I'm like, already? Like, that's an hour-long session at Securus. And we blew by in like a minute or 2 minutes. Um, to, to be as fun and as engaging, but still be true to the art of cybersecurity, to be true to that and not totally water it down to where it's just totally kiddified and it loses what its real meaning is. So we do that and we help sponsor a Coding in Action competition in Colorado Springs.

And last year we had about 500 kids. This year we're going to have close to about 500 kids. And it's amazing. One thing I do want to note, women in security, it's, it's absolutely vital. And one thing I noticed is that as the younger the kids are, the more girls you see.

The older the kids are, the less girls you see. And I don't know exactly what we're doing as a society. I say that we as a, as a collective to prevent that from happening, because last year The 3 of the winners for the Coding in Action competition is a group of girls. I'm like, dude, don't you girls stop this? Like, it's, it's so fulfilling.

It's so amazing. And we do all of it. We don't— we're not looking to make money off of it. It's always the purpose over— the money will come. If not, it's okay.

We'll, we'll find a way. I love it. I love it. Sorry, that's my passion. No, it's— I think, I think it's incredible.

So it's appreciated. It's stuff that needs to, needs to be done. And, um, I'm seeing it too. I, I'm finding the younger generation, Gen Z, there's definitely far more diversity. Yeah, that's, that's interested in technology, hopefully cybersecurity.

So I, I think it's great that you're seeing it too. I appreciate it. Tell me about TEDx. Because you did a TEDx speech. I did.

In Colorado Springs. Tell me a little bit about that story. I did. It was absolutely fantastic. So one of my friends, he supports me a lot, and he asked, are you gonna ever do a TED Talk?

It was kind of an ongoing joke. Hey, you should do a TED Talk. Hey, we love the research. You speak a lot. You should do a TED Talk.

So I get an email and it's, it's from TEDx. It's like, hey, apply, submit an audition for TED. And so I did. I submitted it and submitted it just how I typically present. And I get a response back that they like it.

And so I'm, I'm into the second round. Okay. And so I submit another talk because it first talk was 3 minutes or something like that. They wanted it really short. And then the next one was gonna be 8 to 9 minutes.

And so I submitted that. And then it was— I got a response, love the talk, way too much research. So I'm like, that's who I am. Like, that's my research. And so they asked if I would submit again to redo it, but add more personal stories to connect to an audience.

Yeah, and so I did, and they loved it, and they said, well, we want to put you on the TED stage. And it was eye-opening to me. I learned a lot. Yeah, I learned a lot. It's a very— it was a very positive experience overall.

What'd you learn? I learned to connect with how to build a talk to connect to more people and not just be so research-driven. Okay, so, so numbers-driven, because I'm always going by the notion men lie, women lie, numbers don't. Like, provide the numbers, provide the science, provide the statistics to solidify what you're saying, when typically everyone else just wants to hear something they can connect to. So I had some great speaker coaches.

I had Jill Davis and Rich Parsons. They, they were my speaker coaches and they helped me out so much to say, hey, move this here, change this. Yeah. Let's make half the talk about your mom and let's make half the talk about your story and how'd you get to the data. Then at the last third of it or the last half of it, It can be the data, but we need to know how you got there.

Okay, the journey. And it helped so— it helped so much. Uh, still to this day, I promise you, and this is not a lie, I have never watched it. No? No.

Why? I don't know. It feels weird. Yeah. Uh, it feels weird to watch myself.

I hear it's good. Yeah. Uh, it came across pretty good. I kind of blacked out on stage, you know, where it's just kind of Yeah, you stop thinking and the talk just kind of flowed. Yeah, and I heard it was really good.

Well, you're in front of a huge audience, right? It's how many people? Yeah, I think it was something like close to like 700 or something. Okay, so it was, it was a, it was a big, a big group. It was nerve-wracking because you just get one chance, right?

You get one shot at it. They do a good job with editing, I guess. They, they, they edit if it's some horrific happens, they try to cut it out. But overall, you get one chance and it's your TED Talk. As a researcher, that's kind of— never thought I'd give a TED Talk, but it's kind of one of the top things, you know, to talk at TED is huge.

And I'm very grateful for it. But the nerves come up. The nerves come up. I was nervous. I was first on stage.

Yeah, you kicked it off. Yeah, I was first on stage. So I was extremely nervous. But the cohort, the group we had, because we all kind of went through it together, even though everyone was from everywhere around the US, we kind of went through it together. So everyone's cheering each other on.

Yeah, everyone's watching the screen to see me go. And it just— it went— it went well. I'm thankful for it. It's funny, in those situations, I prefer to always go first just to get it over with. I think so.

I think that was a good thing. Yeah, because otherwise you're sitting there watching all the other people go and the nerves just keep building and building. Yeah, part of me— and this is gonna sound super vain, just to be honest— part of me wanted to go second or third just so I could hear someone stumble, so I can know it's okay. Because when I think— when I see TED Talks, you think of like the greatest talks you've ever heard, and everyone's just perfect and they don't stumble over any words and don't slur words. I typically slur my words.

You can probably hear it now. And it's— I just wanted to hear that, hear that it's okay. And I went on stage, I wanted to be perfect. I don't think I was absolutely perfect, but there's— after I saw some other people go and they stumbled up and it was okay, it made me feel okay. It's like, we're all human, we're all normal.

You spend so long working on your TED Talk, and I just think of like Simon Sinek and all those amazing people, just flawless talks, flawless. And I'm like, I can't do that. And yet often in their minds, they mess stuff up. So it's, it's all perspective. But I think that's awesome.

It was so fun, so fun though. If you have a story to tell, I definitely recommend it. Yeah, you know, screw it, give a TED Talk. I'm not sure if I have a story to tell. Hmm, I'm sure you do.

I'm sure you do. That might be in my future. That'll be great. My own research, which I got to figure out what that research is, but I'll work on that. Hey, I'm sure you have.

I'm sure everyone has something they've gone through. It may not be research-driven. Yeah, it may just be something you've gone through. There was a young girl in high school that spoke about like veganism and things like, things like that. And it was a very, very solid talk.

There was a woman— you remember the kids that got their lemonade stand shut down? No. Well, it was in Colorado. I think it was in Denver or somewhere up north. Kids were selling lemonade and then police came and they shut down the lemonade stand because they didn't have a permit to sell food.

I don't remember that. Yeah, so that, that happened, and she gave her TED Talk there, and it was fantastic. And that she was one of the kids? No, she was the mom, the kid's mom. Okay.

And so she gave her TED Talk, and it was— I was like, this is, this is cool. So it wasn't always research-driven, it was something personal. She shared her story, she shared what she did, helped changing the laws where kids could sell lemonade without a permit. It was fantastic. So everyone has something they've been through.

I'd love to hear it. What's actually fascinating is there's probably a listener to this particular interview on this podcast that will be a future TED speaker. I would love that. I would love to hear it. Yeah.

If so, just, you know, send it to me. If so, maybe years from now, reach out to Erik. Say, hey, you inspired me to— Hey, if I can inspire one person, that'd be amazing. There you go. Right on.

So how can people follow you? What's, what's a good social media platform that you use? I use LinkedIn and Facebook, really. Those are— okay. I'm not millennial enough for Twitter.

I, I have a Twitter. Yeah. Uh, but I, I suck at tweeting. Um, I'm horrible at it. But on LinkedIn, um, Dr. Erik J. Huffman.

Um, there's a couple Dr. Huffmans out there, so I add the J in there to kind of distinguish myself. Yeah. So you You can, you can find me there. Yeah, you can't miss you, that's for sure. Yeah, definitely.

Okay, so people should find you on LinkedIn. Yes, please. Connect with you or follow you. I do not use Facebook all that much myself. A lot of really smart cyber people don't because it's kind of not a good thing to use Facebook.

Let's just stay away from that topic. Well, it's been awesome having you, Erik. This is— this has been a fun conversation. I've enjoyed it. Oh, thank you so much for having me.

I appreciate it. That concludes my interview with Dr. Erik J. Huffman from the SnowFrock Conference. Thanks for listening. Be sure to follow and support Colorado Equals Security on Patreon. This is Jason Jaques saying be safe out there.

Learn more about the Colorado security scene at coloradosecurity.org. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes