Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 166 for the week of June 1st, 2020. Alex, it's good to see you.
I know. And Robb, you sound a little different. This is very odd. Is it, is it different when it's coming directly from like in the same room? Is that where it is?
There's no delay. There's— yeah. When we interrupt each other, it will be on purpose this time. That's exactly right. Back to normal rudeness.
Yeah. So it's good to see you again. Yeah. And obviously the world is opening up just a little bit. And I think we decided that being in a room together was probably low enough risk that we could do this whole podcast thing again.
You know, that's what we do, Robb. We just talk about risk. Risk management. Speaking of risk management, let's talk about some of our housekeeping. Yeah, so Robb, did you know we have a Slack channel?
I did. I've been an active participant there. Wow, that's interesting. We've got, I think it's getting up onto 1,500 people almost. It's almost a little bit below that.
1,400 and change. So if you want to join the Slack channel and the conversation, go to colorado-security.com and find the link there and talk with all of the local folks. Yeah, and while you're there, you can scroll to the bottom and click the button to join our mailing list, and you'll get the show notes mailed into your inbox each week, and you'll get all of the links to the stories we talk about, And sometimes we have a little fun stuff in there as well. We would also love it if you would subscribe to the podcast on your favorite podcast solution, whether that is through iTunes or Spotify or wherever else you get your podcasts. And while you're there, if you want to give us a rating, that would be great.
Also let everyone else know how great the podcast is. And they use an interesting system there of stars. And the more stars you give us, the better for us. Wow. So we would appreciate— we're stars, Robb.
12 stars, 13 stars, however many stars you can give us. Speaking of stars, if you have any friends in your life who you think are worthy of listening to this podcast, we'd love it if you tell them about it and, you know, help them find their way over to the, to the podcast, either on our website or wherever else, and help us keep moving the good message of the movement for Colorado Equal Security. Even if they're not friends, you know, just random people or maybe even enemies, as long as they would enjoy the content that we have, we would appreciate the referral depending on what kind of person you are, we might like your enemies. It's hard for us to know. It's this kind of a relationship.
And you know what, Robb? There are some costs that are associated with producing the podcast and Colorado Equal Security in general. I know it. Yeah. Pocketbook gets thinner every day.
So we have a Patreon campaign that if you wish to support us financially, we would love to have your support through Patreon as well. There are different levels in there. At certain levels, you get a shout out on the podcast or a t-shirt or other great stuff like that. We'd like to thank all the people that are supporting us financially through Patreon. It has been a great help for us, and we really appreciate what they're doing.
Echo Alex's thoughts. Thanks so much for those of you who've been sponsoring us. And finally, we do, you know, we do love to have interviews with folks in the community on this as a part of the show. You know, we do the newscast, we do the interviews. This week we don't have an interview.
We haven't been able to get out very much to do this, obviously, due to quarantine-ish things. But if you want to help be a volunteer to do interviewing, you can, you know, sit down with someone who you find interesting, and we're happy to help make those connections for you. Or if you're someone who wants to be interviewed, you know, can reach out either way. We're happy to talk to you about that and see if we can figure out a way to get you involved. Awesome.
Well, Robb, we have some news. We do. Let's get into it. First thing on the news, we talked about Sphero a number of times on the show. They have like a triple banger of news this week.
Oh yeah, Sphero, they're the ones who make like the little robots. They— I think they became famous for making like the BB-8, right, droid after, after whatever, Episode 7 of Star Wars came out. This week though, they had a 3— a news story with 3 pieces of news. Number one, they have spun out a new company called, called Company 6, which is an independent one that's going to be focused on creating intelligence, intelligent robots for public safety uses. So instead of their commercial work, it's going to be really, you know, public safety type focus.
Yeah, that sounds really cool. You know, work for government and first responders and other things like that. And I have no idea exactly what that is. But, you know, in my mind, it's like, you know, bomb robots, or, you know, a robot that can go into a burning building or something like that. So that sounds pretty cool.
Of course, that company will specialize in AI-based software solutions to help those robots. That sounds fantastic. There's another piece of news from them this week is that they have— that Sphero has closed a $3 million seed investment round. So they're getting some additional money as a part of this for them to go do more cool stuff. And then also, Sphero has a new CEO.
Paul Copioli will now take the helm of the company. Yeah, he was brought in last year but not as the CEO, and I'm not clear exactly what he was, but the former CEO is now the executive chairman of the board. So they're going to have both of those guys around to help steer the company in the right direction. Pretty cool. Good stuff for Sphero.
Next, Colorado's unemployment system, which as you know has been a little bit busy with a little bit of a jump in unemployment lately. They inadvertently exposed some people's private data, which is not a good thing. Yeah, so this, this article does get into some of the technical details, which I love to see that. Apparently one of the, or the vendor who ran this for the state is Deloitte. And there was an issue where the users, all of the users in the system were inadvertently given privileged access to be able to do searches across the entire database.
So you can totally imagine this mistake being made. This is a feature that's supposed to be given to admins only. Was given to everyone. There's no testing to look for that because that's security, not functionality. And who tests for security?
And, uh, and all of a sudden this thing gets rolled out. Um, that— I think there was some good news here that they were able to look and see that only 4 people out of the whole time this was open actually used it. And it looked like those 4 people didn't use it to like go, go look at it inappropriately. They just like found the feature and did a search and then kind of moved on. So, so relatively low impact, but a pretty big vulnerability.
Yeah, it looks like the access was available for about a couple, excuse me, a couple weeks. And as you mentioned, a very low amount of people actually even potentially used it. Um, it does look like they are offering credit monitoring to folks that were affected. Um, even though it does not appear that there was, uh, anything that was, that was leaked. So yeah, that's good.
So, so obviously this is a good lesson for us on, on how to do testing for our systems and, uh, hopefully make sure we don't see this ourselves. Definitely. Next, we have some news about pie insurance. This is not insurance for pies. Are you a cake guy or a pie guy?
I'm definitely a pie guy. I like pie. How about you? Well, I really think that you can do good pies or bad pies and good cakes or bad cakes. Yes.
Right. So there's— they're close to me. Like, there are— they can be either way. But like, a really good pie is probably better than a really good cake. Yeah.
And I'm a pie guy, but not to say I exclude cake. Right. If there's a good cake, I'm happy with cake, too. But yeah, I think my preference would be pie. You get a lot more dried out cakes that are no good than you do bad pie.
Yeah, generally. I mean, and you know, if you get a good fruit filling in that pie, nice flaky, crispy, buttery crust, but you could bring that same fruit filling into a cake and that would also be delicious. Yeah, you just— you also can't get as much filling into a cake, right? Because the cake really can't support that kind of filling like a pie crust. Well, if you want more of this talk, please join us on our other podcast, Colorado Equals Dessert, where we'll be talking through our favorite treats.
Uh, so, uh, we're not talking about pie insurance here. Um, we're talking about Pie Insurance. So, uh, they're an insurance tech company. Uh, their headquarters are in Denver and in DC, and they just raised $127 million. Yeah, this is a pretty cool, uh, story.
I had never heard of Pie Insurance. Neither have I. They do workers' comp insurance, which is interesting because we have another big workers' comp insurance company here in town, Pinnacle. Yeah. Um, So I didn't know that we had 2 of them here in town.
Um, they have about 120 employees here in Denver, just in downtown. So kind of cool to see that, a big insurance company that's got a big presence here in town. Yeah, and they do, um, their sort of secret sauce is software that can do better underwriting so that they can, you know, potentially save the folks that are doing the insurance part money. So that's a good thing. As part of this funding, they're also using some of the $127 million to start their own insurance, you know, be their own provider.
Right. So not only are they going to do the underwriting and the— that part of it, but they will also provide the insurance as well. Yeah. So they're using a lot of that money to really rethink the channel, how they go to market, all that good stuff. And there's going to be a lot of hiring as a part of it.
So maybe good opportunities for you guys. Pretty cool. All right. Next story is about Endeavor. Endeavor is a— man, I don't even know how to describe this thing.
It's a group of companies that try and change the world. Yeah. Maybe something like that. Sure. That sounds like a good description.
And it's really— they've announced 10 new companies that they've added to their panel, and a local security company made the list. Yeah. So they are looking for entrepreneurs that are doing cool stuff at companies. And, you know, Fred Kneipp was one of the people that was chosen from CyberGRX. So pretty cool.
They— most of the entrepreneurs were even out of the US. There was also one other from New York, but there was someone from UAE, Nigeria, Indonesia. So pretty cool that Fred from here in little old Colorado got selected. Yeah, obviously it's nice to see that the security mission from Colorado is going strong and CyberGRX is picking up steam. Good stuff for them.
Next, Blueprint, which is formerly Craftsy, is shutting down, which is a sad thing, and laying off 137 employees. Yeah, you know, I've heard— we've talked about Craftsy on the show a couple of times. Yeah, I'm pretty sure. I remember a couple years ago when they were acquired by NBCUniversal, we talked about that. So they were bought back then, and it obviously did not go great because shortly after that they changed the name from Craftsy to Blueprint.
You know, what they do is deliver these online classes for just interesting stuff. Right. And it looks like shortly thereafter, they've now closed the doors. So that's a bummer. Yeah.
Not a lot of detail in the article about why they are closing, but nonetheless, they are closing. So sad for them. It includes, you know, shutting everything down, including founders getting out of there. So, so good. So the, you know, I learned some about this, about what they did there because I never really paid too much attention.
They do. They did classes, video classes on like crochet. And quilting, but also jewelry making, photography, woodworking, and fitness. So then the CEO in his note did say that the company is going to make sure that they honor customers who had already purchased classes and they'll give refunds for those who don't get to finish the class. Yeah.
Yeah. I wonder. I mean, this seems like something where there's probably a little bit of competition in that space now as well. I see ads all the time for MasterClass, you know, which is a— I'm thinking similar sort of provider. So, okay.
Yeah. Well, moving on, our next story here, DeepWatch, which we've talked about once or twice over the last year. They've announced a new CTO. So DeepWatch is kind of interesting. You know, they claim to be Denver.
They're a spinoff from GuidePoint. I think they have some of their leadership team here in town. I don't believe that the new CTO is going to be here in town, but they are a kind of AI SOC enablement type of a business. MDR. MDR.
But it's all, it's all managed. It's all the managed aspect of it. Yeah. Um, so those guys are, uh, uh, have hired a new CTO. Name is, uh, Corey Bosden.
Um, and Corey is, is joining the team from, um, ExtraHop where he was the head of product over there. Uh, previous to that, he was the VP of product operations at Tenable. And before that, he was product VP of product management at Qualys. And I thought, man, how did Qualys not have a non-compete for the guy to go over to Tenable? Yeah.
But anyway, you know, good for him. Good for him. Yeah, they, um, seems like he has a good pedigree and, uh, hopefully that's a good thing for DeepWatch. Um, speaking of, uh, MDR, Red Canary had a blog post this week talking about EDR tools and a buyer's guide to choosing the right vendor. I thought this was pretty interesting.
In the blog post itself, they walk through some potential questions that you might ask when looking for an EDR product for yourself, but then there's also a link in the blog to their, you know, more in-depth sort of buyer's guide, uh, on, uh, getting EDR. So this is, this is great content, and this answers the question, you know, what should I think about as I'm looking at going after EDR? You know, well, what are you trying to accomplish? What's your existing skill set? What's your existing technology deployed?
Lots of good questions. And at the end, they do give recommendations on what's the right technology for you. Yeah, so pretty cool. Uh, next story we have is from Richie May, right? I think I got it right.
Yep. Talking about what are the benefits of doing an internal audit program. Um, you know, I know that there is often something of an adversarial relationship between audit and everyone else, and sometimes security and audit, and sometimes security and everyone else. It's, you know, it is one of the, some of the more challenging groups, but I really like the fact that they can lay out, here's what you get, you know, as a company from doing, um, an internal audit program and how it makes things better. Yeah.
And, you know, Richie May, one of their, uh, functions is that they provide outsourced internal audit functions. So if you know, yeah, so if you wanted to use them for that, you could. But, uh, you know, I always think that that is a good thing to have some sort of actual audit function in your company. I think the article is focused a little bit more on, you know, actual financial internal audit. But, uh, you know, having an IT audit person, uh, on the inside of the company is always very helpful too.
Now I say I love internal audit for IT from the perspective that, you know, they're— they have the time to go through and look at our policies and make sure people are actually adhering to them. That's, that's what they do. That's a big value. Definitely. Uh, and then finally we have a blog post from Swimlane talking about the results of the SANS 2020 Automation and Integration Survey.
Yeah, they do a good job summarizing and pulling out some key takeaways. So quickly pop through some of those. Um, they said 74% of respondents are applying automation to— at medium or high levels for security ops. So that's pretty cool. That's, you know, that's a significant majority.
Seems like a really high number. Well, it depends on what you consider significant automation, right? Like, yeah, people, I would hope that this is, you know, this, what they've done so far is probably a small step into doing automation. Yeah, I know they said they call it high, higher medium, but I bet it's right. It's a starting point.
Well, I think it also depends on the audience, right? If, if you are surveying people that, you know, are doing this to some degree, yeah, then maybe 74% are doing it. Um, you know, in a good amount. Yeah, who's SANS sending it out to and what's the, what's the likelihood of someone replying if they don't do it, right, versus if they do it? Yeah, who knows?
Yeah, it's all that kind of biases. Uh, well, next, uh, next one that they had there was, um, that the automation does continue to rise. In 2019, 12% of respondents had no security automation. In 2020, that dropped to 5%. So just about everyone has something at this point.
Yeah, that's pretty cool. Um, I think we all know that automation is key. Especially with the, you know, potential skills gap and the speed of attacks. What about the jobs? Is it taking away all the jobs?
It is not taking away the jobs, Robb. Yeah, it says that only 5% of respondents expect automation efforts to result in a reduction of staffing. So mostly it's not saving money for that. It's giving you more efficiency. Clearly, it's not automation that's going to take away the jobs.
It's AI. Oh, yeah. Whenever we get, whenever we get the AI, whenever Sphero succeeds, I guess it's Company 6, right? Company 6. Yes.
Whenever those public sector robots are in place, there go all the jobs. Another interesting insight they had from the report was that whether there are separate teams doing your SOC and incident response makes a big difference. Those companies that have a separate SOC and IR team had less automation, and those who have combined those 2 had more automation. Interesting finding. Seems to make sense.
But yeah, good article. So, well, that is it for our news this week. Let's go ahead and jump over to the Slack message of the week. Big thanks to Andre Gato, who's been supporting us, man, for quite a while now on this, on this endeavor. Thank you, Andre, for every week providing one item from the Colorado Equal Security Store to our winner from the Slack message of the week.
Yeah, good stuff. Uh, this week's winner is Chuck Millich. Congratulations, Chuck. Uh, he shared a reading list for aspiring pentesters. It started a good conversation.
Folks who Yeah, so this one's good, this one's not as good, and I really thought that was a good thing to share. And of course, for everyone, there's a lot of people in the Slack channel who are looking to just learn more about security, and that's the kind of content we need. Most definitely. So good stuff. Um, why don't we talk about some events, Robb?
Sure. We have an event calendar on the website at colorado-security.com. You can go see all the good stuff going on here in the community, most of it virtual. I think all of it virtual at this point. Yeah, um, I think it'll all be virtual for a good amount of time.
Uh, first, ISSA Colorado Springs is doing their CISSP online prep, uh, that starts the 5th of June, and that is session 1 of 6. We're not going to talk about the other 5 sessions after this. If you want to get into this, you got to sign up in the next couple of days and go take advantage of really low-cost, high-quality CISSP training. On the 4th of June, ISSA Denver has one of their series that, you know, is kind of taking the sessions that we're going to be a part of RMISC. We have Alex Holden talking about a dark web review, a deep dive into the dark web.
ISSA Denver on the 9th is having Priyank Nigam, Radio Frequency Hacking 101. That sounds really fun. Yeah, I know a lot of, a lot of folks in security have gotten really into RF hacking. On the 11th, ISSA Colorado Springs has the June online series. Also on the 11th, the Northern Colorado ISSA chapter is doing their June chapter meeting.
And finally, the 11th is big for ISSA. ISSA Denver has Zachariah Uleleke. Oh man, I apologize. I don't know how to say his name.
Akinpelu. He is doing a practical approach to application security, cross-site scripting, SQL injection, and web shell exploitation. I also guarantee we butchered that name horribly. Yeah, I apologize. Did my best.
That is it for events for the next couple of weeks. We do have some jobs to talk about though. Um, so, so we do have one at Ping Identity. We're hiring a GRC analyst. Uh, we have some great candidates in the pipeline right now, but if you're interested in working for Ping to help us provide assurance to our customers about our security practices and make sure those practices are working well, go ahead and apply.
Uh, DCP Midstream is looking for a security analyst for— I was, I was just with this week, this week I saw a list of the Fortune 500 company companies here in Colorado, and DCP Midstream was like number 450 or something. So it was— it's there up on the list. I didn't— I don't think I realized how big they were. Uh, Ball Aerospace, speaking of Fortune 500 companies in town, they have an information security director position open. So if you're looking for leadership at a big company, that's a chance.
Netscope is looking for a vulnerability assessment analyst. VMware is hiring a senior product security program manager. DaVita is looking for a director Senior Corporate Counsel of Privacy. Spectrum is hiring a Senior Manager of Network Security Operations. Spectrum actually had several jobs this week, so if that one doesn't sound good to you, there are many more.
A-Line is looking for a Senior IT Auditor. PwC is looking to hire a CyberArk Senior Associate. And up in Longmont, Front Range Community College is looking for a Faculty of Computer Science, Information Technology, and cybersecurity. It sounds like— or cystic.
That's not so good. All right. Well, that is it for the, for the newscast here. This for the podcast this week as well. Alex, good to see you.
Hopefully we'll get to do this more in person coming up soon. Yeah, definitely. And hopefully we get to see some other people in person at some point in the future too. All right. Everyone be well.
Thanks, Robb. Learn more about the Colorado security scene at Colorado Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.