Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 165 for the week of May 18th, 2020. Alex, how's your COVID treating you?
Um, it's treating me just fine. I am still COVID-free as far as I'm aware. Um, I did find out that, uh, you can now get some antibody tests, whether they're, uh, accurate or not. It still is up in the air, but I'm going to try and get one of those this week and, uh, see if I have antibodies or not. Uh, would you like me just to ruin it for you?
I'll give you an answer right now if you want. No. Is that the answer? Yeah, you don't. Yeah, that's, that's the answer.
But I'm looking forward to some medical, uh, test that's just as trustworthy as my guess telling you that. I'm willing to throw away $10 on a possibly accurate, possibly not accurate test. So we'll see how it goes. Yeah, I have a friend who, who got a test this last week, and he had been sure he had had COVID previously and was excited to see it come back positive, and it came back negative, and he's very disappointed by that. Oh well.
All right, I'm trying. Let's go. Work hard enough and you'll get there, right? Don't even have to work very hard, I don't think. I think, I think there's some rallies you can go to where they're basically giving out COVID Hey, just head down to the Capitol.
I'm sure you can find something. All right, moving over into actual security things, we have some housekeeping. We have a Slack channel with over 1,400 security folks here in Colorado who, who have all kinds of interesting conversations going. We just created a new channel this week within the Colorado Equal Security Slack to focus on development, those who are either doing dev or AppSec type focus. If you want to join all of the great conversations, go out to colorado-security.com and click the Slack button.
Button there and you can get joined in. Uh, Robb, did you also know we have a mailing list? I did know that. Uh, you know, if you were on that mailing list, you would have gotten the mail a day late last week because I screwed up and didn't send the, the email out when I was supposed to. But if you want to be on that list that gets emails late, then go to our website colorado-security.com, scroll to the bottom, put your email in, and it will get on the list.
I'll try and send things out on time in the future. Would love it if you would. If you like the show, go ahead and rate us and subscribe on your favorite podcast listening application. We'd love to have you bring new folks in, especially if you want to tell a friend to go out and, you know, Slack with someone or, or what are all the kids doing? TikTok.
Why don't you put us on TikTok, somebody? Sure. Let's do it. We're not going to do it. We'll do some.
Yeah, somebody throw some, some TikTok videos of us out there or something. If you can't TikTok, you could tell a friend in any technology you use. That'd be great. If you want to support us financially, we do have a Patreon campaign going on. You can sign up for that.
And there are several different levels of support. Actually, there's an, you know, an infinite amount of levels, but we have several defined. And depending on the level, you would get some free things like a t-shirt or a shout out on the podcast. We'd love it for you to support us financially to help cover the costs of everything that we do. And big thanks to those patrons who are currently supporting us.
We do appreciate you, you ladies and gentlemen, very much. All right, let's go ahead and jump into the stories this week. I love this headline. It's not every day that your listing makes it on TMZ. This is around the controversial Castle Rock restaurant.
The building that that's in is actually up for sale. Yeah, if there's going to be something related to me that showed up on TMZ, this is, you know, sort of like a best-case scenario, right?
So, the— well, now I want to play that. Let's just pause for a second, Alex. Let's, let's think, what is the most way that you could actually make it on TMZ?
I don't know, that's a great question. We can get some listener feedback on that one. All right, send it— send us a note if you're listening and tell us how is Alex and/or Robb most likely to make it on TMZ. We're looking forward to your feedback. We'll let you know next week what we hear.
So the— there's someone that is selling the building that that restaurant is in, and the story is about how they were very excited and started getting calls about people who are interested in the building because they saw the, the article on TMZ. So, pretty good context here. Last week, big story went around, there was this, you know, as soon as the stay-at-home order was lifted, the state— the safer-at-home order was in place here in Colorado still. But there was a restaurant in Castle Rock that basically blew through all of the orders details. They, you know, they didn't— they opened up for people to sit inside, they didn't require people to wear masks, no social distancing, all that stuff.
And, you know, the video, you know, kind of made it viral and made the rounds. That restaurant, CNC Breakfast and Korea Kitchen, they ended up losing their license to operate right after. And this article had some other interesting details, like the fact that those folks were actually planning to leave this building anyway. They had already decided that they'd be leaving in July, but they were planning to move to a different space in Castle Rock. So interesting to see.
Of course, you know, their whole business is up in the air right now with with the orders, but right, interesting news here. Yeah, it did sound like this is only one of their 2 locations, but they, prior to everyone being put on lockdown for COVID, they were planning to move to a new space because they had been doing so well that they needed a larger space with a bigger kitchen. So we'll see what happens with them. Yeah, we'll see. Next, speaking of restaurants, the Downtown Denver Partnership is proposing to close some city streets to allow businesses to expand outside for outdoor seating.
I think it's a great idea. This is one of the solutions we can have to maybe allow those restaurants to continue operating and a going concern. I just don't think restaurants can sustain even 50% capacity, and we're talking less than 50% right now. So this is one idea that there is. If you close Larimer Square and those restaurants can expand and put tables out there on the street, or at least on the sidewalks, it starts to maybe change the equation for those restaurants to stay open.
And I'm excited to see, number one, I actually think I'd like it better if that happened. Yeah, and they actually have a list of the streets that they are proposing to close in this proposal. And actually, this is— just keep in mind, this is the Downtown Denver Partnership proposing it. This is not, you know, the City of Denver saying we're thinking about doing this. It was, you know, sort of an initial proposal, but it was a pretty long list of streets.
I was surprised at the amount that were there that they were talking about closing. Yeah, about 10 different streets. Several of them, I mean, a lot of them downtown— Glenarm Place, Larimer Square— but then a lot of them actually Actually, not, not at all. There's a bunch in RiNo. There's quite a few down in the— or several down in the Cherry Creek type area.
So, like, there was maybe a Highlands one too, or— Yeah, so really interesting different places. I think every neighborhood would probably like to have a street like this. And if we can use this opportunity to make things better, I think that's pretty cool. Hope— I hope that Mayor Hancock takes it seriously and looks into doing this. Yeah, that'd be pretty cool.
All right. Next story we have, speaking of local leaders, Governor Polis suggests that Elon Musk should look no further than Colorado if he wants to move Tesla out of California. Yeah. So some context on this one. Elon Musk was not very happy with California for a number of reasons, including the fact that he wanted to reopen the Tesla factory to start making more cars, even though they were not allowed to open because of lockdown orders.
So he went ahead and did it anyway and said that, well, you know what, screw you, California, we're gonna go somewhere else. And they were talking about Texas and I think Florida. But, you know, Governor Polis said, hey, why not come to Colorado? Yeah, apparently Elon Musk's brother is a Boulder restaurateur, Kimbal Musk. So, you know, when Governor Polis tweeted at Elon that you should come here, he tagged his brother and, you know, talked about the fact that Uh, you know, we think you'd like our policies.
And 6 minutes after Governor Polis tagged him, Elon Musk replied and said, hey Jared, Colorado is great. I think your policies make a lot of sense. Yeah, maybe giving a little bit of hope without actually giving any real hope, right? Right, exactly. Uh, it would be cool if Tesla moved their headquarters here, but you know, I'm not gonna hold my breath either.
Yeah. All right, next story we have is, uh, one of our friends, uh, Mark Weatherford, who, uh, was previously the CISO for the state of Colorado. I think he was— I know he was the CISO for the state of California as well. He was also at V Armor. Um, he was the CISO for, for Bookings.
Um, he actually has just recently stepped up as the National Cybersecurity Center, the NCC's, new Chief Strategy Officer down in Colorado Springs. Yeah, so a pretty cool announcement, uh, for Mark. Uh, you know, he stepped away from being the CISO for, uh, Booking Holdings, and so now it seems like he's trying to get a bunch of other things to fill his time. So recently he was also added to a Department of Homeland Security committee, which is pretty cool. But then, yeah, named to be the Chief Strategy Officer for the NCC.
So I think that that's a great thing. And, you know, I like Mark a lot. I think he does good things. So I'm hoping he's gonna help push the NCC forward. Yeah, it's good to see not only people who have a lot of good skills, but are just good people get to be put in positions like this.
I think NCC could definitely use his guidance and helping, you know, his industry knowledge and credibility That's gonna be a really good thing for them. I'm excited to see that. And of course, Mark's pretty approachable as well. If you guys are interested in getting involved with NCC, I suggest you reach out to him. Definitely.
Next, in another announcement, ThreatX named software executive Tom Hickman as their chief product officer. It feels like a week ago that we were talking about them naming a new CEO. Is that right? It was maybe, maybe 2 weeks ago at the most. Man, it just, you know, I know time's flying in my quarantine, but we just talked about that.
But right after hiring a new CEO, they've hired a new Chief Product Officer. So Tom Hickman, he was previously the VP of Engineering at Edgewise Networks, which I don't know them specifically, but before that, he was the VP of Engineering at Veracode, which is another security company I do know very well, and he helped lead them through an agile transformation. So, you know, probably a really good fit for ThreatX, you know, application security and what they do at ThreatX are obviously, you know, hand in glove, real, real good fit. I hope he'll, you know, he'll get in there and make a big difference for them in the short term. Well, Robb, in case you were wondering, Edgewise does zero trust micro-segmentation.
Uh, could you go further, Alex? Can you tell me more about that? No, I, I cannot, uh, but I bet Tom Hickman can. I bet Tom could. Maybe we get him on the, on the show and he can, he can educate us on that.
I think that would be good. So, uh, congratulations to Tom and congrats to ThreatX. Yeah, uh, moving on here, uh, we have a couple of stories about Red Canary this week. You know, they, they've done a ton of news recently, uh, and 2 of these I thought were really worth talking about. The first one is that they have— what I'd say, they've really kind of changed the way that they're doing some of their alerting.
You know, they for years have, have taken in telemetry from EDR solutions. They started off with Carbon Black, the EDR portion of Carbon Black, then they added the CrowdStrike EDR and Microsoft EDR. And now recently they have added coverage of Carbon Black's endpoint protection, so their antivirus solution, and they're using that to correlate between the antivirus and the EDR and create additional insights that just give a higher level of depth of control and basically starting to solve more of the endpoint solution problem. So it's a pretty big step for them, and I'm excited to see, you know, where this takes them. Yeah, I mean, that's definitely, uh, very cool.
You know, as you can add more, uh, data sources, more telemetry, uh, the alerts that you're going to give to your customers are better, and it's going to result in better protection. So glad to see that they're doing that. Yeah, good stuff. A big, big increase. Go ahead, Alex.
Yeah, and then they, you know, they had a second, uh, article in here that you were mentioning as well. It was a blog entitled A Practical Approach to Threat Modeling, and, uh, I think— thought this was a really, uh, good blog. Um, you know, it's by Katie Nichols, but it was talking about threat modeling in general, what it is, how to do it, some ways to approach it. Um, you know, I think threat modeling is something that everybody should be doing and often it's something that is overlooked. Yeah, and what I love, you know, they do 2 different things here, right?
The first story we just talked about is all about their business and how they make money. This threat modeling stuff is just the way that they really help equip security departments to be more effective. And I love the fact that they take that approach. And this one, if you don't know what threat modeling is, this is a fantastic, what, like 3-minute read, 5-minute read to get a really good grasp of the concepts of threat modeling. And maybe you're not gonna walk out of there with the ability to do it in depth for every system, But man, you get a nice foundation to start that conversation, and if nothing else, you've moved in the right direction.
So it's really interesting stuff, and I appreciate them putting that out there. Yeah, most definitely. All right, next we have actually a story coming from Ping Identity. We also made an announcement this week. Ping Identity has hired a new Chief Product Officer.
Candice Worley comes and joins us. She previously— she had a short stint at Amazon, but a lot of time in the security industry at McAfee, and she's coming in to really run the entire product organization for Ping. That sounds awesome, and I'm sure she will do a great job there. Next, Coalfire had a blog talking about cybersecurity risk management in the healthcare sector, From HIPAA to HITRUST. I thought this was a really good blog as well, and the, you know, one of the things that it was talking about is something that's near and dear to my heart.
One of the things that you have to do under HIPAA is risk assessment. And, you know, they're talking about how the fact that the Office of Civil Rights, or OCR, you know, did a sort of a— I don't want to call it a study, but a survey, a review, whatever you might want to call it— and, you know, came back and said, hey, you know, most organizations are not doing their risk management correctly. They're not really looking at risk. They're maybe looking at security controls and, you know, using that as a proxy for risk management. Yeah, I love this myself.
I, you know, you talk about the fact that we get a lot of blog posts each week that we could talk about. Coalfire continually puts out in-depth, you know, kind of verticalized content that we— I think is really high value. I'm not a healthcare-specific CISO, but I thought that this conversation about how your risk management program is required and how you can correlate the controls that are required from HIPAA and HITRUST trust to each other and show how one program can meet all of those. It's high value, and if you're in that area, you should take a read and make sure you're using these concepts. Yeah, great one right there.
All right, final blog post this week is from Virtual Armor, and this is topical. We don't do a ton of the COVID stories if we can help it, but this one I thought was interesting once again because it gets pretty specific. They talk about how do you retain your PCI and NIST compliance as all your employees shift to working from home? Yeah, I mean, if you had some of your controls built on the fact that people were in the office and, you know, relying on some of your on-premise security controls, you might be in a world of hurt if all of a sudden everyone is at home and processing credit cards there. So they talk through some of the things that you need to think about on, on both of those fronts, you know, both aspects of PCI you need to think about, and then, you know, also controls and NIST that you need to worry about based on those changing environments.
Yeah, it's really cool stuff, and, and, you know, a lot of it you've probably already thought of it, but, but it is nice to have this list and somebody else is thinking to bounce off yourself if, if you're in one of these environments. I think it's worth, it's worth taking the read. Definitely. All right, that is it for the news. Uh, we should jump over to the Slack Message of the Week.
Thanks again to Andre Gaeta, who sponsors the Slack Message of the Week for us each week. We pick a Slack message and Andre will give that person $25 towards a purchase in the Colorado Equals Security store. So Robb, who is our winner for the week? This week, it's kind of a second time that he's posted about this, and he definitely deserves for what he did here. Nathan Riley has shared with us some work he's been doing creating an open-source SIEM product basically only using Raspberry Pis.
And his— I think he said in his post, for approximately like $150 worth of Raspberry Pis, he's created an enterprise-quality SIEM using Elastic as the framework for it, which is mostly open source and free. And he's sharing the details and how he did it with the community. So if you want to build a SIEM, you can do it at your house, you can do it for your work. It's there and obviously high-value stuff. And I'm excited that he gets to be our winner this week and pick one item from the store.
Yeah, that's been a really cool series of posts hearing him talk about that and the stuff that he's been doing. And just, you know, the fact that Raspberry Pis are just amazing as well. So good stuff. Yeah, cool stuff. Anyway, thanks to Nathan and congratulations.
All right, let's go ahead and jump over to— what is it next? Calendar of events, right? Yes, indeed. Over to our calendar of events. You know, I— at the beginning of this, we— I wasn't sure how much we were going to be talking about calendar of events, but my goodness, we have a ton of things going on.
I'd say we have more going on right now than we would outside of the quarantine timeframe? Yeah, people seem to have adapted and there are plenty of events that are now online. As an example, you know, like the ISSA Denver chapter is doing, you know, 1 or 2 events every week as opposed to, you know, an event every month. Yeah, so, and that starts off— well, the reason they're able to do that is they're pulling content that would have been in the Rocky Mountain Information Security Conference and they're just putting it online for anyone to get access to so that those talks aren't wasted. And the first one in the next couple weeks is happening on the 19th.
They have David Foote, who we've had at the conference several times in the past. He's going to be giving his annual update, an analyst view in info cybersecurity risk, jobs, skills, pay review, and forecast. Basically just looking at the industry and what does the job forecast look like, what's the pay look like right now, and it's a great thing to help you keep your career sharp. I wonder if he has enough initial data to show how COVID is going to be affecting that. That'll be interesting.
Also on the 19th, CSA is doing their May virtual meeting. On the 20th, Denver and Boulder OWASP are combining to do a May meeting that's a CTF. On the 21st, SecureSet is doing a virtual Hacking 101 intro to data visualization. Yeah, I don't know, but my guess is that this is a reschedule of a meeting we talked about a couple months ago that I was super excited about, and I told a lot of people to go to, but it was like right in— I think it was like late March, so it probably ended up getting canceled. Anyway, once again, I think it's a great concept.
People should go to this. Data visualization is critically important as you communicate outside of security. Next, there's an ISSA Women in Security meeting that's happening on the 21st. This is going to be talking about the impacts of COVID-19 on our lives, our businesses, and cybersecurity and compliance. Also on the 21st, ISSA Colorado Springs is doing their May online series session number 3.
On the 22nd, DC303 is doing their May meeting. On the 26th, ISSA Denver is doing a presentation from Stephen Black, Cyber Law Year in Review. On the 28th, ISSA Denver is doing another one of their series. This is Michael Wiley doing Continuous Cloud Security Monitoring, CCSM. This is one, you know, I was a part of the program committee for RMISC.
I was super excited about this. Session, and I'm excited to see that we're gonna still get to watch it. And then finally, also on the 28th, ISSA Colorado Springs is doing their May Online Series session number 4. And then I did want to go ahead another week or so after that just to mention one other event. So ISSA Colorado Springs is doing every year roughly about this time, they do a CISSP kind of boot camp where they get together.
I think it's usually about 8 weeks in a row that they bang out a review session. Well, they are doing this online now. And the first one's going to be happening on June 5th. These are high value and really low cost for what you get. I think what we just looked and it said, if you're an ISSA member, it's $100 to attend all of these sessions.
If you're a non-member, I think it was $300 to attend. Highly recommend you take a look at it. Get involved if you're looking to get your CISSP. Yeah, I mean, if you think about it, you can do a, you know, a boot camp course and that's, you know, like say $1,500 or greater. So $100 seems like a pretty good deal.
Yeah, definitely good stuff. All right, moving over to jobs. We do have a couple of jobs at Ping I've talked about recently. We are hiring a product security engineer. This is someone with a development background who can help us embed security into our development practices.
We have a team. You'd be part of a team. You wouldn't be by yourself. And we also have a GRC analyst that's kind of someone really kind of looking across all of GRC, helping out with things like our compliance with ISO and SOC 2, vendor risk management, business continuity, helping answer questions from customers around our security practices, and all those different areas. If you're interested in either of those jobs, you can send me a note on Slack and I'm happy to answer any questions, or just go ahead and apply on the website.
If you want to corral a bunch of crazy undergrad budding engineers, the Colorado School of Mines is looking for a Chief Information Security Officer. Yeah, you know, this week we have a bunch of leadership jobs. I don't know how, but like we went from Not a lot of jobs to— my goodness, a whole bunch of high-level jobs available right now. LogistiCare, which I don't know, but I did a little bit of Googling there. They look like they offer solutions to health providers.
They are also hiring a CISO and VP of Security. VIX Technologies is looking for an Information Security Officer. Insurity, which is— the CISO over there is our friend Joshua Foltz. They're looking to hire a Director of Information Security. Vail Resorts is looking for a senior manager of information security operations.
Another friend, Ian Buxton, runs security over there. I think you'd love working at either of those places. Um, Paylocity is hiring a manager of security incident response remote. Uh, Regions Bank is looking for a cloud security architect. And to kind of bring us full circle back to early in the podcast, ThreatX is looking to hire a security analyst.
You want to work for a security company in town, that's a good opportunity for you. Good stuff. So Alex, we have an interview this week and I think you did it. What can you tell me? I did do it.
Pretty crazy. It was a while ago, but I did an interview with Bryan Becker, who is the Senior Director of IT at Kalnin Ventures. Bryan used to be at Kroenke Sports and moved over and now is doing IT and security. So So this is sort of in the series that I've started talking to IT leaders who previously had been security leaders. So good stuff.
Awesome. Well, looking forward to listening to that. And of course, I am looking forward to catching up with everyone again next week. Stay safe and we'll talk to you guys soon. Thanks, Robb.
This is Clay Parker, Director of Security Operations at Trimble Navigation. Welcome to Colorado Equals Security. For Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is Alex Wood, and this is our feature interview. This week I am continuing our series of interviewing security folks that have made the jump to not just security but general IT leadership as well. I have with me Bryan Becker. Welcome, Bryan.
Hi, how are you? Good. How are you? Great. Dealing with pandemics and all sorts of fun on the IT side.
Yes. You know, there's this whole thing called business continuity planning. Everyone is getting to exercise it now. Not just for security risk people anymore. Yeah, exactly.
It's funny how that, that has kind of came in through security, which, I mean, in my mind, it's barely a security function. Like, you want things to still work, but It's really like a core IT function, right? But it's like still the IT security people that are like pushing it to make sure everyone is doing it. Yeah, and it's like the IT security, definitely your information security people, are really dialed up to do it because they know and understand risk from applications and scans and audit and things like this. And it's just like, hey guys, now this is real-life dollars and cents risk that we should be dealing with.
And it kind of— we're lucky that security people, it kind of translates pretty well. Yeah, for sure. So, before we get into that. Sure. Let's hear about you.
Where are you from? I grew up in a little itty-bitty town in Iowa called Swaledale. There's about 150 people there. We were a family farm growing up. We had cattle and hogs and I won state contests for my chicken operation.
You know, free-range organic chickens that my dad and I We raised and then we butchered them on the farm right in front of people. It was kind of hilarious to see their looks on their face. They went to pick up our chickens. And so, yeah, farm kid, rural Iowa, grew up raising all sorts of livestock, and I kind of got into computers and technology through my dad. Did a little bit of puts and calls advising on the side, and he had an MS-DOS-based computer and things like that that I learned on.
And I learned how to hide games from him and delete all of his things through the command line and stuff like that. So that was kind of a unique little background. Designing schools' web pages, rural Iowa, nobody knew how to do that. Troubleshooting people's printers.
It was just a myriad of things that I got into technology with. So growing up, was your thought, even though I like computers, what's probably gonna happen is I'm gonna grow up I'm gonna, you know, join the family business and continue to farm and do things like that? Or was there always a plan, either by your parents or by yourself, to go do something else? Sure, that's a great question. I think of myself as pretty independent, that I kind of make my own way.
Um, I, I kind of sat and thought, as my options in high school, like, what am I gonna do with my life? And I'm like, well, I'm good at technology and I enjoy that, so do computers, or I could go be an ag teacher, is what I thought, right? And so, uh, my family, my uncles, my uncles run basically all the, the farming operation, the grain and the soybeans and things like that. My other grandparents sold the dairy when I was a little child. So like, we, we had a small hobby farm.
We didn't have a big, big operation. So it was something in the agricultural field I was looking into, but I decided to go to technology, went to school, and, uh, Maryville, Missouri for computer science and ended up going that way. So, uh, which one was it? Maryville? Is that Northwest?
Northwest, yeah. We're a D2 football powerhouse. Yeah. And the computer class, the computer science class sizes are like 10, 15, 20 people. And it was more appealing to me than going to a much bigger school like Iowa State because my class sizes, my high school class was 30 people and there was 18 guys there No, it was just, it was a very unique experience in the small-town Iowa and work ethic, and the people are great, but you like, you have no, you don't have the opportunities you would have if you go to a much bigger school.
Sure. Like that. Yeah, I strangely enough, I knew a few people that went to Northwest Missouri. So yeah, we can reminisce over that. Sure.
When we're done here. All right, so you end up going to school in Missouri. Yep. What happened after that? I actually started my career through an internship through Principal Financial Group in Des Moines.
From there, I got kind of into the first taste of network infrastructure at a Fortune 500 level. Did lots and lots of Cisco. I helped— this is about the time where VMware was starting to get big. I deployed virtual switches and hypervisors and networks throughout Principal Financial, 24,000 or so employees worldwide. Worldwide wide area networks through Chile and China and Singapore.
And it was a really good experience for someone out of college to get hands-on and do some fun local area and wide area networking. So I got really kind of into the packets and the depth of technology. I did a lot of work with like Wireshark and a lot of those network analysis tools and troubleshooting applications when like the retirement investor applications stopped working or they're developing something new. So I got really too far deep in the packets for that, but I got a greater understanding of how communication works and how I can man-in-the-middle and break things and be like, hey, all you have to do is send the right kind of packet here and you can really cause some havoc. That's kind of my little first taste of security.
Yeah, so it was a— my foundations are infrastructure. So yeah, so when did the the turn happened. Yeah. At some point you decided you wanted to be a security guy or maybe fell into it? I fell into it for sure.
So, when I turned 27, 28 years old, all my— this is— all my friends were married and having children in Iowa. And of course in Iowa, you get married young. And I was a single guy, 27, 28. I'm like— They might have had teenagers by that time. Pretty much.
And so, I'm like sitting here thinking in my head. I'm like, you know what? I've lived in Iowa Iowa, or basically rural Missouri, for 28 years. I'm gonna go up and see the world a little bit. So I quit my job just out of the blue, and I went, uh, just said I had some friends in Denver, they really enjoyed it, I'll come out here for a couple years, I'll ski and whatever.
And fell into a great role, um, that I think I still thank Trent Hein and Ned McClain for giving me an opportunity up at their company called Applied Trust at the time. Yeah, yeah. So I worked, uh, Worked there under some phenomenal, phenomenal leadership, brilliant technical minds up there. And I went and I slowly transitioned from doing network installs and designs for big companies around here into more security assessments. It started with, hey, look at this network, tell me how you could break it, is there configurations wrong, into starting to design resilient and architect networks to DevOps to PCI to the full thing on the spectrum, to walking in with pizza pretending to be somebody so I can plug into their network and conference room.
So it was, it was a great, great experience. And I guess that's one of my— if I would tell a young Bryan again, get into consulting a little earlier. You get to see the breadth of tech, breadth of scale of technology that's out there, and you can seek and pick kind of what you want and where you want to go and just learn so fast under them. And so, uh, yeah, I was, I was there for 6 years or so. So when you went to Applied Trust, did you go there for a security role, or did you go there and then while you were there realize that security was the thing?
I went there with a networking role that evolved into a higher-level networking security role, which evolved into a very security-focused with a little bit of the network on the side, right? And so I'm very focused on compliance, very focused on locking down, doing secure networks, secure scaling, helping out with data, data security for HIPAA organizations. And PCI and things like that. So it was, it was a— I wore a lot of hats, but near the end especially, it was a very security compliance, security program building, writing policy, virtual CISO type work. Yeah, well, and you know, Trent is a great friend of the show and a great person, and for sure, I'm sure you're really lucky to work up there with him and the team up there.
Very, very lucky, very thankful. And the one thing that still amazes me about that company and they still have a great company in Rule 4 and great people working there, was not only was the top layer of leadership great, you had a bunch of medium— the people that were underneath Trent and Ned, your Randy Ellis, your Kasim Ismail, your Paul Nelson, your Jim Turpins— those kind of guys that were taking you under their wing. And they were like, hey, Ned and Trent want to go this way, but like, we need to see you grow here, here, and here, and here. And it was a wonderful, wonderful career opportunity. I still talk to those guys.
And thank them all the time. So it was a very, a very great— it was kind of— I like to liken it as the turning point of my career, was my time at Applied Trust. Yeah, so it sounded like you had a good time, did a lot of consulting work there. But what, uh, what is, uh, what's the craziest thing you ever had happen in one of your, one of your, uh, engagements there? They're allowed to talk about it.
Oh my gosh. Oh.
You're gonna put me on the spot. Um, how about a crazy thing? Not— it doesn't have to be the craziest. Oh, PCI credit card data being sent in plaintext on a very, very, very public website. Oh, okay.
Yeah, like unauthenticated everything, like admin credentials, whole backend. Sweet mess. Yes. And so it opens— you know, like, you just— oh, you go into these assessments and you open your eyes as like I was like, wow. And then the other craziest thing I saw was there— I noticed on multiple clients as service providers reuse the same credentials that may have had similar clients.
So we were locked out of a router. I'm like, huh, they were a client of X company. Let me try their credentials they used over here. Sure enough, I had root access everywhere. So sweet.
Yeah, it was the old Huh, good stuff. Wow, great, great OPSEC guys.
So I also know that at one time you became a QSA. Yes. Was that while you were at Applied Trust, or was that— that was while I was at Applied Trust. Yeah, they sponsored me. We got shipped off to Boston for a couple days to do in-person training, learn the rules and the tips and the tricks of a QSA, and then a lot of it from there is, all right, now apply, apply the standard to the clients that are asking you these things the best that you know how, based on what we told you and the guidance that we have.
So, right, which is a lot of gray area. It is a lot of gray area. And I think which is why people like to have a QSA that they like, because there is, there is so much gray area there that if, if you got a good relationship, you can maybe, you know, squeeze a little bit here. And for sure, and like one of the tips and tricks you tell people is that as a former QSA is like, if you don't like your QSA and they're telling you to be too restrictive, you can sometimes ask for another QSA, right? And you might as well do it.
I know that the council probably not put their stamp of approval on that, but these QSA companies are incentivized to keep you in the system that you can have repeat customers and things like that, but they don't want to be too overly harsh and make you change everything. They'd be like, these guys are too hard on us, we better go somewhere else. It's kind of like a relationship that you need to develop, and the QSA, you have to be mindful of that because if you come down too harshly on them, they're going to call you an a-hole and go with some other company, and you're going to lose the consulting rate. I think it's still a broken system, honestly.
It's difficult. It's a catch-22. I know that you are no longer in a consulting role. At some point you changed from consulting to going in-house and building, running security programs. Tell me about that.
Why and where and what? I was starting a family. It was getting a little wearing. A little bit of consulting sometimes can do that to some people. For me it did.
I was ready to say, hey, I'm going to try to start stepping out and try to build my own thing. There was nothing against, no hard feelings with Trent and Ned. And those guys and their team. It was at the point in time they just— they had sold their company to Flexential and culture was changing. I figured, you know what, this is the right time to do it if I'm gonna do it.
Yeah. So did that. I took a role with Kroenke Sports and Entertainment, a very unique company similar to probably where you're at now, where they have their hands in a lot of different types of pots, a lot of different markets, a lot of different business operations that they're doing. They're taking credit cards over here, they're selling wine over here, they're selling tickets over here, and there's a lot of— there's a big risk matrix, a big risk threshold, or a wide range of places where someone could break the whole system, right? And so digging in, understanding their processes, understanding their business in many different areas and different business units and different industries even.
So it was a great challenge there. I was there for 4 years building security programs, writing policy, PCI. We had a lot of different things go on there, including the Madison Square Garden breach while we were there. That kind of shook us up a little bit. Their whole point of— that was when, God, 4 or 5 years ago, their point of sale at Madison Square Garden and all their affiliates were hit, the Forum, and they stole a bunch of money.
I'm like, huh, we should probably earmark some money to replace their whole point of sale. And so all that— never let a crisis go to waste, right? Right. A lot of good, uh, good things and fun things went on well. The people there are great, a fun industry to be in as well.
And so, uh, from there you are now— went into your now current role, which is also an IT role and a security role. Yes. So, um, so tell me a little bit about that. What was the reason for doing that? Was that on purpose?
Was it by coincidence? Was it— it was, it was on purpose. Um, the thing with me sometimes, I'm wired kind of differently, is that I love building things. I love working from the ground up. I love greenfield opportunities.
A role opened up with a small oil and gas company here in Denver. They're not going to be small here in a little bit. We did— we might— my 6th week on the job, they signed a big acquisition. And, uh, and we had a great opportunity— we have a great opportunity to build an IT structure, uh, analytics team, security, uh, security team, automation, Internet of Things, and, and all that using cloud technology. And that just blew my mind up.
And I'm like, you know, I think I, I would like to step away from a much bigger company, slower moving, and less Let's move fast and break some things and see what we can do with some technology. That was very appealing to me. I miss KSE. I miss going to Nuggets and Avalanche games. I miss rooting for the teams.
I miss working with the teams there, but it was the right move for me at the time. I work for a company called Callan Ventures now. I'm the Senior Director of Information Technology. I try to bring my security background into building these processes, selecting these technologies, and doing the Internet of Things deployment that we're doing out in our oil fields for hopefully some automation. It has been a whirlwind.
It's been a lot of fun. My head still spins sometimes with what I'm doing, but it's been a wonderful experience so far. What's been the biggest thing you've seen as a change from going from a dedicated security role to now a more IT role?
It's a great question. It's been the rate of change and the speed of things that we are doing things has been the biggest thing for me is that, okay, we're spinning out and we're standardizing laptops and hardware deployment. We're building standardized deployments for our cloud. We want to utilize some big data analytics and things like that, and it's all going on at the same time as we try to rapidly scale. It's been a gigantic challenge to keep those— keep not only my people happy, but keep these processes in my mind, learn the industry, get a better feel of what are my different functions want to do, try to come to a consensus, and then try to integrate this big asset at the same time.
It's been an enormous challenge of juggling things. Now, compared to my security role, my security role was like, okay, so we need to worry about baseline risk. We ran an assessment. We're, we're taking our attacks on these top 3, 4 things that we want to address. Whereas this is, hey Bryan, we can't operate this asset unless we execute on A, B, C, D, E, and F. So it's been, it's been exhilarating, but a different, definitely a change of pace.
And, uh, and, uh, it's been an adventure too. So nice. Yeah. Have there been any skills that you picked as a security professional that you have said, oh, this is— I'm glad that I know this because it's really helped me in this new IT role? For sure.
So just the idea of risk and assessing that and knowing and understanding is like, hey Bryan, we can choose to do it this way, which is the way we've always done it, or we can choose to do it this way, but we have to pay a premium if we want to do SSO or if we want to do some data encryption or even with vendor selection, I know the right questions to ask. I'm like, are you SOC 2 certified? No? Why not? You're a cloud company.
You're handling people's data. If someone breaks into your system, they could potentially modify your automation systems and bring production to a screaming halt. Knowing and understanding how the system works, where the levers are, where the can be hit, and then explaining to executives, hey, the risk— we, we want to choose this route, but there is slightly a little bit of risk to do that. We can choose to accept it, we can mitigate it, um, those types of decisions and conversations that we have. So nice.
Yeah. Um, how have you— obviously it's been fun. You're still pretty new. Sure. Um, was it the right decision?
Are you happy you did this? 100%. I, I, uh, with all due respect to the KSC team and the talented people there, the leadership and executive team, Stan and Josh, like they have such a unique and fun business model. But like for me and my— in the way that I'm wired, it's the way that I want to run and go. And so, and then you always have, you always have that driver.
I'm wired this way. It's like we get to build something and we can see it grow. It's just like the whole farmer thing in me. You get to grow and nurture it and say, hey, we built this. It's working great.
It's scaling. It's kicking the competition's behind. That's what really gets me motivated to go to work and want to do things. There's been this age-old question of where does security report in the organization?
This is going to be a roundabout way to get to the question I'm getting to. For a long time, we know that security has been in IT, and everyone says it shouldn't be in IT. Maybe it reports to the CFO or to legal or maybe straight to the CEO. Then I've heard some people go as far as to say, well, instead of security reporting to IT, IT should report to security. Based on your experiences now, moving from security into a more IT role.
What are your thoughts on this whole thing? That's a great question, and I actually love that question. From my consulting experience and my experience with KSE, the answer is it depends. It depends how the industry you're in. It depends how the company is wired.
It depends if you're a public or non-public company, but in the end, my preferred answer is Security has a conflict of interest with IT, and it needs to report to, in my opinion, someone who actually can make a change in the organization if the security person waves a red flag, whether that's the COO or the CEO. That's my unofficial or official position, I suppose. IT and security, I think, moving forward in this new world are going to be peers, and that's in medium to large-sized businesses. In small-sized businesses, I think it still makes a lot of sense sense to have them combined or report up to IT, as long as that IT professional knows and understands risks and communicates that and is not being a hindrance to the security program. Yeah, yeah.
And I've seen a lot of times where you have security people that have come up through IT, so they understand, at least at a high level if they're not in the weeds anymore, how that whole thing works. But I think it is less often where someone that has come up through IT understands security and risk. For sure. I see that in my current role too. We have some of the folks that I work with, they are IT folks, but they have security responsibilities as well, and they don't necessarily have that background of risk and security, and it is hard for them to understand those concepts sometimes.
I think the huge advantage that I think I have now in my role is that I came up through security. I know and understand risk. I know, hey, if we're going to operate in the cloud or using applications that are delivered through different kinds of service delivery methodologies, what's the easiest way that we can lock it down? What are the common ingest points that a hacker is going to try to do? Just having that knowledge and background of the risk and the technical background of, hey, we played around with Metasploit, we did this, this, and this, we should be able to lock down those minor controls.
But even in the higher levels of leadership, knowing and understanding security is you know what to ask vendors when you're interviewing them and doing due diligence for a product or a platform or for a service that they're offering and be like, hey, SOC 2, are you concerned about the data. How are you doing encryption? Are you, you know, how is everything architected? And so that's a, in my mind, it's a gigantic advantage that security people can have if they do a transition to an IT services or IT service delivery or applications manager or director role. Yeah, so we touched on it a little bit at the beginning of the interview.
Yeah, but you know, the last couple weeks have been a little trying for everyone, especially around business continuity. Yep. Service delivery, probably too. Service delivery, business continuity. How has that been for you, and what have you learned, or what skills have you brought from your security roles to help make you successful there?
Yeah, just knowing and understanding business continuity has been a great resource. My CEO has asked questions about asking the right questions about policy, or when do we When do we go and migrate to a formal security program and full risk assessment and things like that? So I could kind— I, I got him started down the, down the pipe. He's like, we need to do assessments and tabletops and business continuity just for these types of roles because you never know when it's going to hit. We need to know and understand how to respond.
And so by getting that teed up, I think the company has been definitely more open to it and seeing and understand from other people in the industry as well as like, hey, what we gonna do? How are we gonna work? Well, we are in the process of designing and re-upping kind of how we are going to deliver our applications and services moving forward, and we've been implementing that now. It's going to get a great trial run here when we do, do this business continuity exercise, everybody working from home. So the things that, that, that I've learned in security have helped out writing, writing and updating the remote access policy to make sure, hey, you know, don't work from home and a coffee shop where people can look over your shoulder or listen to your conversation.
Mark and tag your documents if they're sensitive. Don't store them on personal PCs. And then we can help put in transparent policies in the backend, like all sorts of those little implementation and deployment details for a mass business continuity exercise. Are there any things as your preparations have gone on that surprised you that you maybe wouldn't have thought about more from the IT side, coming over from security?
Yeah, it's been like in security, you're head down in policy, procedure, risk assessments, deploying some technical mitigations, maybe looking at logs, a number of different technical things that you're doing, sitting in meetings and just talking about risk, where when I'm over in the IT side, I'm like, okay, business continuity. Well, how are we going to get the data from the engineering system back to the database, and can our people access this stuff from home? It's more about service delivery. I'm like, well, I remember this from like 12 years ago, but I haven't done it. Really getting caught up to speed in a hurry with that, comparing knowledge with our service providers and things like that, making sure that we're deploying those new systems in case we have to ramp up or add more infrastructure in a way that's not going to open up— making a quick hasty change that could open up a vulnerability and things like that.
Those types of things surprise me, is the amount of change that's happened, especially on data integration analytics, how all that has changed in such a quick hurry and how they do it. Just learning that. I don't even think I asked, you know, you said you were a fairly small company before this acquisition. Do you have a large team to help you out doing this stuff? Are you a one-man, small shop?
Great question. So we have 1, 2 people on the IT team that are full-time, and then we heavily utilize a managed service provider in town, Machine Logic. We've been super happy with them. We have a couple people that are full-time staff, Aug. We use architecture kind of on demand and things like that. Then to help us integrate, we've also brought on a Big 4 consulting company.
Going for the big bucks. Big time, yes. It's a big league acquisition, and we are treating it and running it like the company we want to be: effective, efficient, lean, fully process-managed, scalable, secure, all the things we kind of aim for, right, in IT. Nice. Are you guys building any of your own stuff?
Are you just doing off-the-shelf using SaaS, other things like that? Or are you guys, you know, doing anything custom inside? You have to worry about, you know, developers and things like that, or just the same things, tying APIs together if we need to? There's always like creating your data factories and your data lakes and making sure all your applications can talk, which takes a little bit of scripting and whatnot. But for the most part, a lot of the oil and gas has some very specialized IT applications that we just have to make sure that we implement, the services can be received, we can integrate all that data that we're going to be getting from this other company, and just make sure that it's secure, it's serviceable, that we can actually deliver the application without too much security.
Right, and especially remotely now. So yes, there's a lot of things that go into this massive acquisition that are all happening at the same time, but it's been a great fun challenge. Yeah, and I mean, you talked about a little bit a minute ago, but you know, the oil and gas applications usually are extremely graphics and data intensive. Yes. So I'm sure that that has unique challenges for you in trying to get everyone working at home.
For sure, for sure. How are you going to deliver it? Then you're worried about latency and downloading these big oil and gas datasets, well logs and things like that, or how do we deliver that into a way where we can minimize the latency on a remote access connection but make sure that they have a virtual desktop or containerized application or something like that which meets their needs so they can do their job right. Lots of trade-offs, lots lots of discussions and business requirements and things like that. Nice.
Yeah, different, different muscles in the brain that I haven't used in a while. That's— it's always nice to exercise some of those differences. So we're getting close to the end of time. Yeah. Anything that I didn't hit on or anything that you wanted to talk about?
We have no— super. One of the things that helped me really succeed as I was transitioning out of the consulting world and into the leadership role was the resources at Colorado Equal Security. Not only leaning on the team Trent Hein and Dan Mackin and those guys had, but also you guys' dinners and Robb and the Slack channel, picking up some mentors here and there along the way. Eddie Mize, Drew Labbo. I'm probably forgetting people.
Even hooking us up with a network of what I like to call my sanity checkers. You'd be like, hey, Hey Drew, am I being crazy here? What are your thoughts? Like, right, things like that. And so it's been really, really helpful.
It's a great community. I think if you are not taking advantage of it, you are doing yourself a disservice. So, well, thanks. We appreciate that. I'm glad it has been useful for you.
For sure. Um, and Bryan, thank you for your time. I really appreciate it. Yeah, thank you. It's great talking to you.
Thank you, Dan, for— for— you're like, you interview me, you better Schedule something. That's right. Yeah, so when I interviewed Dan a couple weeks ago, he's like, hey, but Bryan put you up to this. If you're gonna interview me, then you gotta interview Bryan. Oh yeah, Dan's been a fantastic resource as well.
It's— he's— I think we started our own user group for doing security for billionaires here in Denver, so there's not too many people that can do that. But welcome to the club. Thanks, Bryan. I appreciate it. For sure.
Alex, thank you so much. Thanks again. This has been Colorado Equals Security, and we will talk to you next time.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.