Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 170 for the week of June 29th, 2020. Alex, we're We're about halfway done with the year.
Quarter's over, month's over, all that kind of flying by. Uh, I think you mean we've, we've had, uh, 5 years in 2020. We're, we're more than several times done with 2020, even though it's halfway. Uh, actually, it feels like we should be halfway to 2023 or 2030, doesn't it? It does, it does.
Um, longest year on record. Longest year ever. Yeah, but that said, you know, it's, it is summer, the weather has been, has been nice. You know, it's, if you're gonna have to be trapped in some place, you know, Colorado is not a bad place to be trapped. That's true.
It has definitely been summery with, you know, temperatures in the high 90s. Lots of sun, little rain. Definitely seems like summer. It is literally raining right now as we record this for me. But, but you're right, it's been good.
Besides that. Hey, let's do some housekeeping. You go first. Right. Uh, you know, Robb, we have a Slack channel.
Oh, what? Strange, probably never heard of that. Uh, but we do. Uh, we're getting close to 1,500 of our closest friends, uh, in that Slack channel talking about security, all things Colorado and security. Uh, if you want to be a part of that community, just go to the website colorado-security.com, click the Slack link, and it will take you to that Slack workspace for you to converse with all of the other wonderful folks.
Awesome. While you're at the website getting the link to join Slack, why don't you scroll down to the bottom and join our mailing list? That way you can get the show notes emailed into your inbox every week as soon as Alex remembers to do it. That's right. And once you get those show notes, it should be a trigger to you to think, you know what, this is awesome.
I would love to rate the podcast and also subscribe. So not only do I get the show notes automatically, I get the podcast automatically in my podcast player. So whether it's on the Apple iTunes Store or Google Play or wherever it might be, please make sure to subscribe, get the podcast delivered to you automatically, and give us a wonderful rating. Alex, have you seen the Black Mirror episode where they socially rate each other after each interaction and your rating in that app determines your access in life? I haven't.
I have to say I have not watched too many Black Mirrors, mostly because I'm afraid. Well, don't watch the first episode because that one is disgusting and horrible, but everything after that's pretty good. Well, I have to say that is one that I have seen. So yeah, I'm sorry. I've already been spoiled.
Yeah. Hey, speaking of helping us be successful and be accepted in society when we go into that kind of dystopian future, we would love it if you'd tell a friend about the podcast and hopefully get some more folks involved with the movement. Yeah, I mean, and if this really is our dystopian future, then, you know, please just rate everything related to Colorado Equal Security highly, so then you don't actually have to tell anybody, it automatically upvotes us and, you know, shows up in people's brains. If you'd like to support us financially, we do have a Patreon campaign. If you— there's also information on that on the website.
We would love for you to support us to help cover the costs that we have for producing the podcast and the website and all the other things we do for Colorado Equal Security. So check that out. If you sign up at the $10 a month level, you get a shout out on the show and some free swag. I love it. And then we would love it if you want to do some volunteering to help us get interviews for the podcast.
You know, Alex and I have had a hard time keeping up with doing an interview every week. We would love the volunteers who've helped us. And of course, if you're interested in helping keeping the conversation going and helping us highlight interesting folks security community, you can do your own interview, and if you are a nice person, we would be happy to put it on the show. Exactly. Speaking of nice people, Douglas Brush is putting together a book club that's going to be getting together.
It's the Colorado Equal Security Book Club, and we're going to be talking about the book Start with Why. The first book club meeting is going to get together on July 23rd. This is an update from what we said before. It got pushed back to July 23rd. Yeah, if you remember us saying it was on July 15th, that is now incorrect.
Robb is extremely selfish and made us push the book club back to the 23rd. So there's that. Good stuff.
Maybe, Robb, it's time to get into the news. Let's do that. So starting off with the first news story this week, we have a Boulder robot company who we've talked about before, Misty Robotics. If you remember, we've talked about them several times on the show, creating a robot that's like a, like a front desk person, a receptionist. Their, their new programming for the Misty 2 robot allows this robot to do temperature checks for folks when they come into the office.
Yeah, so that's pretty cool. It's functionally the same robot except now it has an infrared temperature scanner. So you don't even have to touch the robot, you just need to, you know, get somewhat near it, it can take your temperature. It can ask you some standardized questions on how you're feeling or where you been. I think you can pay for an upgraded version of that robot where you can even customize those questions.
So this is pretty cool. I feel like that entry-level robot was like $3,000. So, you know, if you are going to have to have someone manning a front desk and taking temperatures and things like this, that seems like a good solution. So, you know, even that front desk person isn't exposed. I love that.
Of course, it will feel way more human to have a robot doing that than, you know, some mean human doing that. Exactly. Uh, next we have an update from a story we talked about 2 weeks ago on the show. Um, ArcherDX, we, we mentioned that they were— they'd filed for IPO and they were going to be listed here this month. They got swooped up at the very last minute and they are no longer going to be a public company.
Yeah, so, uh, they are being, uh, purchased for $1.4 billion by, uh, Invitae. And, uh, it looks like that, that amount is, you know, right around the same amount that they were expecting to get from their IPO. So maybe once they were priced for the IPO, you know, Invitae thought maybe they were undervalued and went ahead and snatched them up before they were public. So congrats to them. The big difference is this way, the owners get $325 million right off the bat.
And I assume that they're now swimming in their big piles of money there in Boulder. As soon as the deal closes, there will be a giant plane that drops pallets of money at their house. I wonder if there's a business somewhere that will let you borrow money to swim in while you're waiting for your real money to come. It's like the kind of business we got to get into. That sounds like a wonderful Silicon Valley startup.
I'm sure, I'm sure someone will create that now. I can't, I can't see how that wouldn't be an ongoing success. Right. Next. Maxar has announced an acquisition.
They are purchasing a business that they co-started with Saab for doing 3D modeling. Yeah, it's a little strange. It's kind of like if I paid my wife to buy her half of my child, which I've considered doing.
But Maxar already had half of this and Saab had the other half, but now Maxar is going to be the full, you know, own the entire entity here. Yeah, it sounds like when they started this, maybe there was some expertise that Saab had and also splitting it between the 2 companies, obviously, it lowers your risk because you're not the only owner. It also noted that the business unit that we talked about with Maxar that they sold off probably a month ago, 6 weeks ago, they used that money to pay off debt that they previously had. And now they've issued new debt which is cheaper debt and puts them in a better financial position when they're doing this acquisition. So I do love to see local companies succeed and have success like this.
It looks like they are going to be working for the US Army on quite a bit of this work here, the spatial imaging. So it's probably top secret type stuff that we don't know all the details on, but hopefully they're all out there doing good stuff. Sure hope so. All right. So our next story here is about a new company that has picked Denver to be their HQ too.
It's called Is it Marketa? Marketa. They are a global card issuing platform and they're moving to town. Yeah, so that's pretty cool. They are an Oakland-based fintech company.
They do business with companies like DoorDash and Instacart, and I think maybe Uber and some other place like that for, for payment cards. And they are opening their second headquarters here. It sounds like they're gonna try and ramp up pretty quickly and try and hire over 500 people in Colorado. That's a lot. That would make them one of Colorado's largest employers.
There's not that many folks, companies with that many employees here in town. Yeah, that is pretty cool. And, you know, sounds like a good company and glad that they're coming here. You know, on the, on the theme of the hits keep rolling, while they're gonna be coming to town, there's another much smaller company that's relocating their headquarters from New York to Denver. It's called Total.
T-O-D-Y-L, and they're a much smaller company. Right, because in, in today's internet world, you can't spell total T-O-T-A-L. It has to be something different. Guarantee you that total.com was not available if you spelled it correctly. That is true.
Um, so yes, uh, Total is a company that they have a— sounds like a platform of platforms. So they bring together, um, lots of different security and technology and network solutions for cloud platforms that they can then give to managed service providers to offer to small and medium-sized businesses to help consolidate those things and make it easier to get those services to those small and medium-sized businesses. Yeah, it sounds like the kind of company that you and I are going to want to learn a lot about, and I think other security professionals here in town are going to want to know, you know, have they actually figured out how to make a single a single pane of glass, right? That's the claim we've heard for years, and they're trying to move more in that direction, both for IT and for security tools and platforms. Yeah, and I think all the security companies in town are going to want to make sure that they are on the Total dashboard.
So that makes sense. Now, they— like I said, they are kind of the other end of the spectrum, a much smaller company. You know, the article doesn't know how many folks worked at Total, but they say there's only, you know, 5 people connected to the company on LinkedIn. And Total is saying that they're going to— they're planning to hire 5 people in Denver this year and another 10 to 15 by the end of next year. Yes, very, very small startup, but we're still happy to have them here.
Next, we've talked about BioSleeve before, which is one of the startups here in town. It's a product. CypherSkin is the company, BioSleeve is the product. My bad. And yes, so they make BioSleeve, which is a smart fabric, smart extra skin that can do things like tell your temperature and see your CO2 levels and other things like that.
Well, they've gotten a $1.5 million defense grant to provide some of these sleeves to the military. Yeah, this is, this is cool stuff. And we've talked about them, like you mentioned, I think 2 or 3 times on the show. And it just occurred to me as I was reading this that during COVID is the perfect time for this. If you're a coach, if you're, if you're trying to help someone do, you know, sport training, maybe music training, you know, being able to see see the way the person's moving and how those things are working at a distance would make a big difference, give you the ability to, you know, the difference between being able to coach them and not being able to coach them.
And of course, I think that this is only going to accelerate the importance of what these guys are doing. Yeah. So congrats to them. And I look forward to seeing the results of this further testing with the military. Good stuff.
So LogRhythm has an ongoing, a multi-day virtual event that they're in the middle of. And we pulled one of the stories, one of the webcasts from that. This one's around how to map your risk reduction over time and to achieve cost predictability. Yeah. So I think that that is a great topic and there are, I don't know, I saw an awful lot of these that came through, but it's recordings of these sessions.
So not only is it a blog for you to read, but it is a recorded session with some more detail in there too. Yeah. And that's actually a little bit of a trend here this week. Our next story is from Red Canary, and this is a, a whole bunch of, um, videos as a part of this one blog. And really, they've aggregated a bunch of information around process injection, um, and how does process injection work.
It's basically a primer on, you know, how do you look for it, how do they do it, and how do we defend against it. Yeah, uh, I thought that was cool as well. That, that was well done. Lots of videos on there, some in-depth info if you want to learn about process injection. Yeah, I mean, we've talked about this and I just reiterate again, Red Canary, the content that they give out on this blog for free, I mean, this is like a master's level worth of security operations information.
And anyone who you know that's, you know, that does SecOps as their day-in, day-out job who's not reading this, you know, they're really missing out. For sure. Next, we have a press release from the National Cybersecurity Center down in Colorado Springs talking about a partnership that they're getting into with the Cyber Resilience Institute on their Sea-Watch training. So I didn't know, I don't know the Cyber Resilience Institute or the Sea-Watch training that they do, but this looks like an interesting engagement. You know, National Cybersecurity Center is always looking for ways that they can get more involved and add value, and really helping deliver this training is one of the ways they're doing it.
So this is training that you actually, you listening here, yes, you, you could sign up for. It's available for anyone who wants to, students, mid-career professionals, basically anyone who wants to learn more about cyber intelligence. It's got 3 separate tracks. They got social media threat hunting. That's one thing, social media threat hunting.
I assume that means that people are using social media to hunt for threats or to hunt companies. They've got cyber observable hunting and they have cyber policy. Yeah, so definitely interesting training in terms of the topics. I can't say that I've ever heard of other trainings in those areas. So something new.
That, that's always a good thing. Um, we've got a link in the show notes that you should be able to follow to get more information on that and sign up if you are interested. We would love that. Let us know if you go and how it is, because, you know, obviously we talk about these things, but we're not going. So maybe if you go, you could tell us if it's any good.
Speak for yourself, Robb. We don't do anything. That's true, we don't. Hey, our, our last story this week is by the Bite Back Law blog, and it's analyzing the, the California Attorney General's comments about drafting privacy policies. Yeah, David Stauss at Husch Blackwell put this blog post out and, you know, this past week, maybe even a little bit over a week ago, California released their final CCPA regulations with a number of comments and appendices and lots of information there.
And so this is a pretty good summary of some of the things that they were talking about in that that final release, including what it is that you need to do when drafting privacy policies. I think the short of that is that there was a lot of feedback asking for additional clarification on what needed to be in the privacy policies and some other questions, and it sounds like California didn't acquiesce to people's demands for, for things that they wanted, but There's lots of details about that in the blog post itself. Yeah, I mean, I, the way I summarize it is, is folk, the industries wanted to know, well, will you give us, you know, model notifications and model documents we could use so we could, you know, just comply more easily? And like you said, California said no to that. But they did, the industry also asked, will you, you know, can we use the same templates that we use for other reporting like GLBA and COPA?
And the answer to that was, While we're not saying that, you know, you always can, there's no reason you couldn't. And the way I took it is like, yes, of course you can. We're not just going to go out and give you some kind of safe harbor by saying always use that, but, you know, use some common sense and it's fine to do that. Right. I think that basically they said, as long as you meet the requirements that we've put forward, you don't have to have a separate CCPA privacy policy.
You know, if you need a privacy policy for something else, then that's fine as long as it meets the CCPA requirements. Yep, that sounds right to me. All right. That was the news. That's the news.
Let's jump over to the Slack message of the week. Big thanks to Andre Gaeta. Andre is our sugar daddy who's been taking care of this for us for a couple of years now. We do appreciate you, Andre. And every week he buys one item for someone from the Colorado Equal Security Store who has an interesting or thought-provoking comment in the Slack channel.
Oh, that sweet, sweet sugar.
This week, our winner is James Westbrook. Congratulations, James. He posted a link to a blog post about the Maersk Not Petya situation. And this was someone who was there during the time that is now no longer there and has done a nice write-up on what happened and some things that they saw. And, you know, maybe some lessons learned.
And this was actually— they were an IAM person, and so this was definitely in the vein of IAM, but, you know, security in general as well. So I think there's sometimes a tendency to say, well, that's old news, you know, why would I want to read about that old breach from— what was that, 2 years ago? Well, the answer is because now you can actually get the details. You know, 2 years ago we did not have a lot of details on what happened. This is about as good an insight as you're going to get into the kind of the ugly underbelly of what happens during a big breach like this.
Yeah, I think also, um, I might agree that sometimes I don't want to read about old breaches if there's not interesting stuff there, but when the breach essentially causes the entire infrastructure of a major global company to be wiped out, that, that's probably something that you want to get some lessons from. Yeah, it's worth, it's worth reading. Anyway, thanks to James. You get to pick one item from the store. We look forward to seeing more great comments in Slack next week.
Awesome. Let's check out the events, Robb. What do we have coming up? We have— well, you know, 4th of July is coming up pretty soon, so things are calming down a little bit here this week. So there's nothing in the week of the 29th.
The next events we have are all happening on the 9th of July, and there's 3 events. First, we have the Northern Colorado ISSA meeting is doing their July chapter meeting. SecureSet is doing a virtual cybersecurity capture the flag for all levels. And the ISSA Springs— or excuse me, the ISSA Colorado Springs chapter is also doing an event on the 9th, and that's just their July online series. There's no details yet on what that content is.
Yeah, and if you want to see these events and more, you can go to the website and check out our consolidated event calendar there that has all of these and all of the other events that are coming up even past the next 2 weeks. So much good stuff in there. So much, so much. Why don't we jump over and talk about some jobs, Robb? Yeah, so I heard that there's a job at some— is it a hospital organization, some Anschutz company?
Is that what this is? It is not a hospital organization.
I am hiring a security program manager for my team. So if you have some program and project management skills with a little bit of security thrown in there and want to work in a cool program, I would love to hear from you. Additionally, one of the portfolio companies that we own, Zanterra, is hiring a Director of Information Security. So if you don't want to work directly for me but want to work in an adjacent company, would love to have that too. And, and if you're working at Zanterra, you, you could either be the person taking orders directly from Alex or taking orders from the person who's taking orders from Alex.
Is that how this works? Uh, something like that. All right, uh, next job we have is from Spectrum, uh, Charter Communications Spectrum. They're hiring a Director of Connected Home Cybersecurity Projects. It's kind of a mouthful— Connected Home Cybersecurity Projects.
That sounds like it could be pretty cool. Transamerica is looking for a Senior Investigative Analyst. Trimble is hiring a Cloud Security Architect. VMware is looking for a senior information security software engineer, and this is a remote opportunity. DISH Networks is hiring a senior cybersecurity threat hunter.
Maxar, who we just talked about making, making moves, is hiring a manager of network engineering. Not directly security related, but I know a lot of you are networking folks. And then SailPoint is hiring a cloud deployment engineer focused on FedRAMP. And then finally, Ping Identity is hiring a professional services engineer. All right, that is it for the newscast this week, and that is it for the podcast.
We don't have an interview this week. Um, Alex, any parting words to, to leave all of our listeners with? Uh, no, I got nothing, Robb. Uh, that was beautiful. Oh, uh, I was actually— I do have something.
I was on a, a webcast earlier this week, and I'm gonna have to remember the line that the woman said.
She said, stay positive, test negative. That's pretty good. One of my, one of my favorite equations in the world is happiness equals expectations minus reality. So yes, if you can't make your reality any better, just lower your expectations. And that's, that's like the sure path to happiness.
Exactly. If you don't expect much, you're going to be happy. All right. Well, that's it. Everyone have a great week.
Thanks, Robb. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.