All episodes

Ed Fuller, CISO at Cloud Elements

Apple Podcasts Spotify SoundCloud

Ed Fuller, VP of IT and CISO for Cloud Elements if our feature guest this week. News from: Boom Supersonic, TermScout, LogRhythm, Red Canary, Webroot, Ping Identity, Zvelo, and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10544 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 174 for the week of August 3rd, 2020. Alex, it's good to see you in person.

Good to see you too, Robb. We are recording in person, though. You know, appropriately distanced. And masked? Of course.

I wear my mask everywhere I go. Well, your articulation in your mask is getting better. Well, thank you. Hey, why don't we jump into some housekeeping type stuff? Did you know that there is a place where you can talk to all of your favorite Colorado security people?

I didn't think we were allowed to gather with people, Robb. How does that work? Well, there's a virtual thing. It's a little bit— Oh, it's virtual. It's a little bit like an AOL chat room, which I know is what you usually use for your communication online.

So there's a 2020 version of IRC that we have set up? It's called Slack. Slack. And if you want to get involved, you can join the over 1,500 of our favorite folks here in Colorado who are there actively contributing across, I don't know, dozens of different channels. That's cool.

I didn't realize we'd actually hit 1,500 this week. That's pretty cool. Yeah. So if you want to join, go out to colorado-security.com and click the Slack button. That'll get you in there.

And while you're on the website, why don't you also join, sign up for our mailing list and you'll get the show notes in your inbox every week. Yes. I will send you an email once a week. That's it. Also, we would love for you to subscribe to the podcast.

That way you get it automatically delivered to your favorite podcast listener. And then while you're there, you can rate us and let everyone else know how great the podcast is. It would be also great if you told a friend how awesome Colorado Equals Security is and all the wonderful things that we're doing. And if you want to support us even more, we do have a Patreon campaign where you can financially support the podcast. You know, the I know it's been tough for all the community.

Of course, we'd love your support even in the midst of the tough times as we're continuing to put out the podcast on a regular basis. Of course, you can find the link to that as well on colorado-security.com. And the last thing you could do to help is if you could help do some guest interviews. We've had some fantastic folks do interviews for us, both a, you know, a series. We've had Mary Writz do a series for us, and Jason Jaques has done a series for us, and a couple other folks.

And then just one-off interviews. And if you want to do either of those, we would love that. Yeah, that would be great. We actually have a backlog right now of interviews, Robb, which is what we aim for, but hasn't happened in a while. Yeah, we used to keep a good, you know, month, 2 months of backlog.

But lately, it's been a little bit more difficult to come across interviews for sure. All right. Well, let's jump into the news. First story this week, Boom Supersonic, which we've talked about a bunch on the show, is doing a partnership with Rolls-Royce to try and determine if Rolls-Royce engines make sense for their supersonic jet. I don't, I don't know much about the Rolls-Royce engine.

I do know that they have sweet fenders on their cars. If Boom could somehow get the Rolls-Royce fender used on their, on their plane, that'd be pretty awesome. Does that mean that the planes will have cool hood ornaments? I can't imagine that they wouldn't have this as part of that. That'd be the winning combination here.

Yeah, I mean, I think in general, Rolls-Royce is a pretty big player in the aviation and engine industry. So not surprising that they're partnering here. And I guess I hadn't really thought about it, but my assumption was Boom Supersonic is building their own jet. They would probably build the whole thing. But, you know, it makes sense that if there is already a provider that provides engines, then Boom can take their airplane frame and just put the engines on there and be good to go.

So I do have to cast a little aspersions on this. This is a press release that we picked up, by the way. And what it says, once you get into it, is it says they have agreed to explore the pairing of Right. There's actually no commitment here that they're going to work together, but they're going to give it— they're going to look into it. Yes, I think it's good for both of them.

Get a little press and, you know, maybe they end up with Rolls-Royce engines, maybe they don't. Or maybe they end up with the Rolls-Royces like some kind of part of the bargain. Right. Sounds good to me. That's where instead of using all of their VC money to buy Rolls-Royces, they're just partnering to get them for free.

All right. Moving on. We used to do a lot more of these articles, which basically like rate all the different cities. This week we have a couple, but this is talking about— it's the 2020 STEM Job Growth Index looking at a bunch of different cities where the job growth for STEM jobs has been the biggest. Yeah, I, I think that they're, they're maybe stretching it a little bit in terms of where the job growth is the biggest.

And the factors that they're looking at here are, you know, cost to operate and, you know, education and other things like that. To me, it actually sounds more like potential STEM job growth. Which is also an interesting thing, right? Places where, you know, based on who the population and who wants to go there, where STEM jobs are going to grow the most. I guess, you know, the bottom line is that Denver is number 3.

So that's the thing that we care about. And we are directly behind our old nemesis, Austin. They are— they're number 2 and Charlotte's number 1.

Seattle number 4. Raleigh is number 5. What's interesting to me is somehow they've got San Francisco Francisco, the biggest tech job hub in the, in the world. Yeah. As number 8 on the list.

Like, how can that be like a top 10 grower still? That's, that's just amazing if that's true. Yeah. And I think, again, it's in my mind, it's potential, right? So they've got a lot of people.

They've got, you know, people want to live there. And, you know, based on the story we had last week or the week before, even though it is expensive there, it's not that much more expensive to run a business there than in Colorado. So I guess You know, the numbers don't lie. All right. Next article we have is, is from the Colorado Sun, and it is from our favorite reporter in the Colorado Sun.

It's my favorite reporter, Tamara Chuang. Tamara, if you guys remember, she previously was a reporter for the Denver Post. She's been working for the Sun for, for quite a while, 2 years or so. This is all about— it's kind of a follow-up to the story we talked about maybe 3 weeks ago, 4 weeks ago, around a lot of fraud in the unemployment claims within Colorado. Fraud protection.

Well, this isn't fraud protection. This is fraud discovery. Right. There was a lot of new unemployment claims, but you had the ability to backdate your claims to February. Yeah.

People were asking for 5 months worth of unemployment and a lot of those seems like they got through. So the nice thing about The Sun is they don't just, you know, they're not like us where they just like find a headline and then they, they amplify it and they're like, we're done here. The Sun, they, you know, she's probably spent 2 weeks like really digging in on this. And there's a lot of actual interesting reporting in this. Yeah.

So on a personal note, you know, they're talking about the unemployment fraud here. Someone actually filed for unemployment benefits on my behalf. Just so everyone knows, I still have a job. I didn't file for unemployment, get the money. I did not get the money.

I got the debit card in the mail that allowed me to, to get the money out, but I reported it as fraud. Um, which, you know, I think other people are having this happen to them too. One of the main points in the article is that, you know, based on previous breaches, a lot of people's information is out there enough that you could easily file for these kinds of benefits, um, on someone's behalf and potentially get the money. Um, I honestly don't know the, um, the angle here because like in Colorado, if you file for benefits, I think the way that you get them is through this debit card that they send you. So, that comes to your house, that comes to my house.

So I don't know how they would actually get the money out of this. But I mean, I'm not— did you ask your kids about this? Or your wife? Who knows? But anyway, I mean, this is happening a lot in this.

It's mentioned in here. But also previously, we had talked about the fact that there were 6,000 claims about that were immediately marked as fraudulent in Colorado.

There were some stats in here that they had from like Pennsylvania and a couple other places. Like almost like 60,000 claims in Pennsylvania that they marked as fraudulent, which is crazy. Maryland had 48,000. Yeah, lots of, lots of states getting hit pretty heavy. They did interview Richard Byrd, who's the chief customer information officer over at Ping, one of my coworkers.

So highlighting the local security folks as well. Yeah, this is a great story. Again, I really appreciate all the stuff that the Colorado Sun does. Good article. You should Check it out.

Next, the tech job postings in Denver soared 36% from May to June, which is the 4th highest increase in the country. Yeah, it's interesting. It's good. But, you know, May was terrible, right? Like, right.

Yeah. We had one job post in May. Yeah. And we had 1.36 in June. Right.

I mean, it is, it is good to see the improvements. I love that. It's just I feel like it'd be better to do like a year-over-year comparison versus— sure, middle of pandemic next month, you know? Right. Yeah.

Yeah. It's going to get better. Hopefully that— I guess that maybe the point of the article is, you know, things are starting to recover at least somewhat. Yeah. I mean, and I would love to see if from June to July there's also that much of an increase.

Was it just a blip because everyone stopped hiring in April and May and then started a little bit again in June? So I don't know. We'll see. We'll see. Hopefully we keep moving forward though.

Next story we have, I'm moving over to it. Oh yeah, we're moving over to TermScout. This one's interesting. So they kind of start off with what I consider to be an interesting fact that when a company has to do a negotiation on a contract, even a relatively simple contract, the average to review it is $6,900, almost $7,000. So these guys have created a solution that uses part AI and part lawyer to do reviews for you, you know, very quickly and very inexpensively.

Yeah, it's pretty cool. Um, I've seen several startups that are kind of in this space where it seems like lawyers, um, at least many of the things that lawyers do, um, are going to be outsourced pretty soon. You know, contract review and, you know, simple things like that. Yeah. I don't wanna say simple.

It, it, it's, it is complex, but it's repetitive. Maybe repetitive is probably a better word. Um, where a computer can figure out the same things that people can, uh, figure out. I know that there was some study a little while ago where somebody's AI looked at a bunch of contracts and they had lawyers look at a bunch of contracts. And obviously the lawyers took a lot longer.

And I think they made more mistakes than the computers did. One of the things that I thought was cool in this, that the announcement here is that they got some more funding, Term Scout did. But they're talking about the fact that one of the things that they're going to be doing soon is looking at privacy and security clauses in contracts, which obviously is something that is important to us. Yeah. It's pretty exciting stuff.

So they, they've now raised $1.6 million. They call it a seed round. So they're just getting started. I, I really like the fact that they're doing that combination of AI and people. I think that just going to AI in the short term is probably not gonna solve enough problems, and you're gonna get too much pushback.

Having, you know, a few lawyers on the backend to, to go through whatever the AI identifies as kinda sticky, that's probably a good model. Yeah. It's good to have people review too because you don't want that AI sticking in any clauses in there that say, you know, AI gets, uh, you know, contractual rights and things like that, right? AI now owns humanity. Thank you very much for your, your word, Term Scout.

The contract says it right here. Uh, anyway, uh, next, uh, we're going to start with the, uh, security stories for this week. Uh, LogRhythm, uh, had a blog talking about 5 ways to alleviate stress on security teams. So the 5 ways. Number 1, uh, and I think this is a fantastic one, gain support and alignment from the executive board.

On the objectives of the security program and the value it provides. It reduces a lot of stress when the highest level leaders in your organization, the board of directors or your leadership team, are supportive of what you're doing and really know what your priorities are. Yeah, and I think that that's where a lot of the stress and anxiety comes from, right? Is you don't know if you have support, you don't know what's gonna happen next. So maybe you're gonna be fired tomorrow because people don't agree with what you're doing, that kind of thing.

Yeah, I think a lot of our stress comes from conflicting priorities between security and other departments. And getting, just to be clear, getting support from the board doesn't mean you're not going to have those conflicts, right? But it does mean you're going to know that you can get those resolved if it gets escalated. Second is create a solid plan for your security operations center. That's a good one, being able to react quickly when things do happen.

Well, everyone has to react quickly, but do you know what to do, right? Is it a fire drill that you've practiced or is it, you know, learning on the fly? I think that's really good. Third one is to make a plan to recruit and hire for skilled security talent to build a strong team. Yeah.

I mean, good people makes a big difference. Yeah. Next, on the other side, if you are a part of a board or executive team, do what you can to set your cybersecurity program up for success. Kind of like number one, but sort of the opposite side of that. Yeah.

So I guess we need to send this one over to our board, right? Look, it says support me, please. Logarithm told me to. And then number 5, know that security is everyone's responsibility. Sit back and drink a piña colada.

It doesn't say that last part, but I feel like it should with that. I think it should too. All right. Good stuff from LogRhythm. Next, we had a blog from Red Canary talking about how to break into InfoSec and learning new skills while using the Atomic Red Team.

Yeah. You know, this is a Red Canary blog, but it's really an Atomic Red Team blog. And this is one way that they're really giving back to the community. The Atomic Red Team was a way for them to create atomic, you know, discrete tests around the specific areas of your security program and your controls. And they're— they basically got it.

There's been just a huge amount of support around this. As you know, in the past we've seen like pen test frameworks, but we haven't really seen a defense testing framework like this. And they're using this to build out a really nice network of tests. And now the cool thing is this next step is taking those tests and taking this framework and turning it into a way for folks to get trained up to become new defenders, new security professionals. Yep.

So the first thing in, in the blog is that you can gain experience, uh, in development, which will help you by being a contributor. Yeah. And of course you're going to learn how to, how to use the tools and the technology just by getting in there. Um, the familiarity with things like Power— PowerShell, the, the, the different endpoint protection technologies you're using, that's going to be big as you get into your career as well. It's going to help you hone your analytical skills because as you do these tests, You're gonna figure— have to figure out what happened during the test, uh, to see, uh, if it was successful, how you— it was attacking you, that kind of thing.

You're gonna build out your network, network with other professionals. Yeah, for sure. Uh, so definitely some good things there. And, uh, we love the Atomic Red team. Please go, uh, contribute and support.

All right, moving over. Webroot had a blog post this week, um, the changing face of phishing, how, how one of the most common attacks is changing over time. And And this, this is, you know, Webroot, they really are, are more of a consumer business. And this is more kind of for those who don't know so much about phishing and, and maybe a way for you to introduce to your less technical friends, uh, what the different elements of phishing are. Yeah.

And I would say, um, this is probably not breaking news for any of us that are in the security industry. Um, you know, they're talking about, uh, spear phishing and SMS phishing, business email compromise, stuff like that. Um, so it, it's things that are, that we have, in the industry have seen happening. Um, but you know, those outside might not have, have been experienced or know enough about yet. I do have one part in here I was, I was curious about.

They call it search engine phishing where they'll, they'll buy ads for something that maybe isn't them. So you'll click on a, you know, a Symantec ad and it'll take you to their malware. Um, is that phishing? I thought it was clickjacking. Is it?

Yeah. I don't know. Is that phishing? I don't know. It's, uh, I suppose you could lump it into phishing.

Um, or you— it could be— I don't know. I don't know what the technical term for that is, but, uh, in the end, it's bad things for people, right? So, so it's all bad things for people. It's all phishing. We're all fishing now.

All right, that's it. Everything bad is phishing. So I— so did— all right, I'll keep moving on. Uh, we have a blog post for Ping Identity this week, and this is kind of continuing on their theme around building a great user experience, uh, customer experience, you know. And I, and I I call this out with, you know, we have lots of articles that we can choose from.

I try, try and pick some stuff that is maybe different than what we're going to see in other articles and what we've been seeing in the past. I really think that as security folks, we don't spend enough time thinking about user experience, and this is a, a nice way for you to get introduced to the idea that, hey, we're responsible for creating a good user experience. Identity, and which is often a part of security, can help make that better. Yeah, and this is really looking at sort of digital transformation. If you are going that route, um, what is it that you should look for?

Not necessarily from a security perspective, but, um, you know, metrics that might help you, uh, around that in general. And again, to your point, Robb, knowing that as a security person helps, you know, to— helps you to understand where you can inject security in that process. Um, and of course, you know, one of the things that is important is, uh, customer identity to make sure you know who your customers are. To make sure that you're keeping secure. Good stuff.

I recommend taking a look at that article if you might be able to help out with your customers' experience. And then our final blog this week is from Zavilo, looking at the TTP of living off the land at scale. So they're doing a series of looking at different kinds of TTPs, which is tips, tactics, or no, tricks, tactics, and tools. Tools, tactics, and Yeah, whatever. What's the P?

It's, uh, tactic, technique, and procedure is what they, what they, what they describe TTP is. All right, my bad. Um, anyway, they're, they're doing a series where they're looking at different TTPs and, uh, how bad guys do stuff. Yeah, this is a TTP. Um, and so this is Living Off the Land at Scale.

And really this is about, hey, when you get into an environment, you're not going to, you know, try and download all your own tools onto, onto the laptop. So all of a sudden, we have signatures firing because someone just, you know, opened a Kali Linux image on their Windows machine. It's using what's already there, right? So the scripting and the remote management tools that are already in the environment as the way for you to move around so you don't set off so many alarms. Yeah.

And I think it's interesting. One of the things that they're talking about here, and I totally think about it the same way that you do, they're actually talking in addition about using sort of web services that people can sort of hijack and live off the land that way. Like, you know, Microsoft Forms or other things like that, where you can not put up your own phishing sites, but use what seemed to be trusted sites for things like that as well. So interesting blog post. All right, that is it for the end of— for our news stories this week.

Let's go ahead and jump over to the Slack message of the week. Big thanks to Andre Gaeta, who has been a reliable, loyal supporter of the podcast. Andre recognizes one person each week who's contributed to the conversation there in Slack. Yeah, thanks Andre. So the winner this week is Justin L. for posting an article on a Kickstarter for a Tamagotchi for hackers.

So I mean, I never actually had a Tamagotchi growing up. Was it 20 years ago? What, 30 years ago those things were? Little animals that you had. It was like a little pocket-held, well, basically like a phone except for all it did was play this one game, Tamagotchi, right?

Right. And you had to hit the feed button every once in a while or your thing would die. Right. It was a living, living in quotes thing on your, your little— so this is Tamagotchi for, for hacking and learning how to, how to do pen testing. Um, you know, the gamification of it and the social elements I think will be popular and, and hopefully, uh, there's, there's some level of success there.

Yeah, pretty cool. So Justin gets to pick one item from the Colorado Equal Security store and we'll send a note over to him and hopefully he gets something sweet with the new logo. Awesome. Well, let's move over to events. Uh, we only have a few events this week.

It seems like things have been slowing down Um, through July, end of July and August. Um, and I say that we are in August now, Robb. It's hard to believe. It is amazing that it's not still March. Um, but we've got a couple events coming up.

March the 5th. We're the 5th March right now, right? March the 5th. March the 387th or something like that. Um, uh, Colorado Springs ISSA is doing their August online series session 1 on the 6th of August.

On the 13th, SecureSet is doing a cybersecurity capture the flag for all levels. Of course, it's a virtual event. And also on the 13th, the Northern Colorado ISSA chapter is doing their August chapter meeting. All right. Jumping over to jobs, we like to find jobs that we think are interesting and will be, will be kind of an interest for all of those listening.

Alex did a good job finding some interesting jobs this week, starting off with a job at Wells Fargo. They're hiring a head of insider threat program. This is a business functional manager 3. Yes. Level.

I love the big companies where even when they give it a different name, they still have to make sure that they put in whatever the, like, the official HR title is. Right. I know we have a couple of jobs from Comcast because I thought that these were pretty interesting. They're hiring a senior director of governance, risk, and compliance, which to me sounds fun. To other people might sound awful.

Yeah. And then also they are hiring a senior director of product management for hosted cybersecurity, which I thought sounded really cool. This is, you know, for the Comcast Business Services. Their hosted MSS kind of services for that. So you could help design those products.

Yeah, honestly, both of those jobs sound really good. And of course, they're, they're both able to be hired here in Colorado where they have a pretty good-sized IT function. So pretty good stuff. Next, there's a position at Coalfire, yet another pretty cool job. The— I said Coalfire, I meant Carbon Black.

One of those C's. Carbon Black is hiring a director of product security, and this role can be here in Colorado or Boston, or I think there was like 2 other places. But we're on the shortlist. Nice. CoBank is looking for a senior manager of identity and access management.

Another good job working with Stanton over there. The Super Credit Union, and this is super like King Sooper, S-O-U-P-E-R, is hiring an information technology manager. Valentium is looking for a medical device cybersecurity engineer. So if you want to hack pacemakers or who knows what. Direct Defense is hiring a senior security analyst.

Praetorian is looking for a staff security engineer. And Praetorian is one of those like pen testing firms, kind of a— yeah, one of the more boutique pen testing firms. And finally, Front Door is hiring a security engineering intern. And Front Door, we actually were just talking about one of our old ISSA board members, Marlene Viem, is the head of— well, it's the director of security over there. And hopefully this is working with her.

At Front Door. Good stuff. All right. Well, that is it for the news. Uh, we do have an interview this week though, right?

You sat down with Ed Fuller. I did. Uh, had a chat with Ed, um, former boss of mine at Kaiser Permanente. He's gone on to do some other things as well. So long history in security and, uh, we had an interesting conversation.

Awesome. Well, looking forward to hearing that. Alex, thanks for your time and we'll talk to everyone again next week. Thanks, Robb. Hey, this is James Carter, CISO at LogRhythm.

This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. This is our feature interview, and today I have a very special guest, Ed Fuller. Welcome, Ed. Welcome. Thank you so much for inviting me.

I've been looking forward to it, listened to a lot of the podcasts, so interested to see where our conversation goes. Awesome. Well, obviously I know you, Ed, because at one time I worked for you. Sure. But I'm guessing that many of the people out there don't, so why don't you give a little background on you and where you came from, how you got started, things like that.

Excellent. So it all started— I joined the Navy and was in for 21 years, and really my love of IT started back in '89. When we got our first 8086 onboard ship. Nice. And it was a dual floppy.

It was really cool, had a lot of fun. And then was excited to get my first 5-meg hard drive. And my first IT project was in the Navy where I was at Naval Air Station Dallas setting up Texas Law Enforcement Telecommunications System and the National Crime Information Computer interface with the Navy base there, okay, with those 2 entities. And so it was fun learning inside-outside plant. It was fun learning.

I'd never done project management before, so it was kind of like flying by the seat of my pants, if you will. So it was a lot of fun, but that's kind of where my IT career started. And after the Navy is when I really started coming into cybersecurity and kind of what I do now. Went to work consulting with a boutique company here in Denver and just auditing different government entities because I was familiar with, of course, NIST and DITSCAP/DICAP, and truly enjoyed that. And I'll never forget my first audit was NASA.

They were going through their initial NIST certification. I went out to Alabama to that facility out there and was going to do backbone and firewalls. I'm like, I got this. I understand Cisco. I've done it before.

Looking forward to it. Excited. All dressed up in a suit. Walk into a room, a large room that could probably seat 100 people, and I got a little intimidated. Then people started filing in, 10, 20, and there was like 30 people when it's all said and done.

And we're all just sitting around, casual chitchat, and I'm thinking, should we get started with this? And then this guy walks in, about 6'5, looked like he had just walked off stage from ZZ Top. Leather jacket, long ponytail, and he says, I guess I'm here for some interview. And a suit walked up and said, yeah, you know, they're here to do our initiative certification.

He sits down with me and he goes, well, what do you want to know? I said, well, let's talk about firewalls. He says, well, I helped Cisco build the first one. What do you want to know? Holy crud.

Needless to say, I didn't go too deep there, just enough to complete the assessment, but that was kind of my introduction into it. It was very intimidating, and I didn't want to go down a path of conversation where didn't want to be. Yeah. Well, what I want to know though is, did NASA end up getting accredited? Oh yeah, you passed them.

Yeah, well, obviously with a guy like that, you know, protecting, uh, NASA's backbone and firewalls, it was, uh, it was quite interesting. Interesting facility just to see their SOC and the operations going on. And, uh, and I was actually there when the shuttle was up. Oh cool. Yeah, so it was really neat to see.

So no live testing at that time. No, I'd imagine not. Obviously. Did you get to go into like any of the operations, see mission control kind of stuff? No, they wouldn't let you in there.

No, no, didn't have clearance for that. But we did go into the backup center where they had all the TVs running so you could see what was going on and you could see the network controls and the software that they had monitoring everything in case kind of a disaster recovery site. So Yeah, it was fun. Did they have, um, so not too long ago I watched, uh, Hidden Figures. Okay.

Yeah, the movie where they are, they bring in the big IBM mainframe to calculate the trajectories and all that kind of stuff. And then, you know, and the people can still do it better and things like that. Anyway, so did they still have the, you know, big iron in the back doing, doing the calculations, trying to figure out which way the, the shuttle was supposed to go and stuff like that? You know, I, I imagine there was something to do with that. I did walk by one of their data centers that was on-prem, and it was massive.

It was just rows and rows of cabinets and cabinets, and everything of course locked down. It had a mantrap in there. It's one of those visual inspections. Of course, they're not going to let you go in there and stuff like that. I watched that same movie, and that was pretty interesting to see an entire room for one computer, and now they've got all of that in One little box.

Well, my watch probably has more computing power than this thing now. It definitely does. It definitely does. Yeah. So I'd imagine you did that consulting for a little while.

Where'd you go after that? So after that, I really enjoyed the lady I was working with, but she needed to fill a job for Raytheon Polar Services, and they had the main contract for the National Science Foundation. And that's where I met 2 engineers there that I still work with today, Garrett Padgett being one of them. He's one of my pen testers. He has his own company now.

So we worked there together and really enjoyed that. That contract was coming up for renewal, so I started looking, and that's how I moved on to Bank of America, where I had, of course, more experience in NIST and implementing those controls. And so this was the time of the mortgage industry bust, and that's where Bank of America had bought all these loans from Ginnie Mae and Fannie Mae. And so they had to start meeting government standards. And so I went into Bank of America, hired some guys to go in with me, and we set up and did the first commercial bank NIST certification of their mortgage environment.

And so that was, that was a lot of fun for about 3 and a half years. That sounds exciting, but it doesn't sound as exciting as supporting folks at the South Pole. No, it doesn't. You glossed over that part. I did.

I did. I kind of glossed over that. Did you ever get to go deploy to South Pole? I did. It was a lot of fun.

I went down twice. The first time they were doing an Inspector General audit. And they had invested a couple million dollars in facilities down in McMurdo, which is the, the southern part of Antarctica. And so we had to fly in there, and it was a 20-hour flight, flight time going from here to LAX to Christchurch. And the last leg from Christchurch to McMurdo was on a C-130, and it was pretty loud in a jump I can imagine.

Yeah, it was a lot of fun. Really wasn't— I don't think they build those for comfort. No, they don't. They absolutely don't. And it was interesting because the auditor that was with me was— I felt sorry for the guy.

He was in his early 60s, and this was kind of a glory trip for him to go down, see the South Pole. But he paid the price, just not in flight time and jet lag, but Just the air was a little thin for him. Yeah. When we actually got to South Pole and it was the high of 5 degrees for all of about maybe 15 minutes and wind chill kicked up and yeah, it was pretty brutal. But it was a fun trip.

It was memorable going down there. That was along the same time that they were commissioning the new South Pole Station. And this was around 2007, 2008 timeframe. And it was a lot of fun to go down. Being in the Navy and understanding commissionings, they did a challenge coin for that.

And a lot of people then, they weren't really as familiar with challenge coins as they are maybe today, right? And so we got a challenge coin for that, and it was a lot of fun. So that's pretty cool. It was. How long did you get to stay down there?

I would go down for like 2 or 3 weeks at a time. I had people on my team that would go down and conduct the NIST audits and NIST reviews and gathering evidence, that sort of thing, and doing security awareness training, because at the time, believe it or not, they had a 256K baud modem. So by the time I left Raytheon, they had improved to a 1 meg line. That's a pretty big improvement. It was a big improvement.

And, um, but they used 3 satellites as they would all come in, um, so you'd be doing downloads and they'd pause. Next satellite come, and they'd pick it up. So it was a lot of fun. One of the memorable moments down there for me, the second trip that I went down, is I liked road biking, and so there was 2 other guys that liked to road bike as well, and they said, hey, let's get the Antarctica cycling team together. And I'm like, there's not one, right?

And he pulls out a jersey, and he goes, there is one now. So we all put on our jerseys, and we're riding Not road bikes, of course, because down in McMurdo, it's a, it's a cross between a mining town and a college town. Okay. And the ground, the surface, is volcanic rock. So we had big cruisers with big fat tires.

Yeah, we're cruising around town, McMurdo Town. So I bet now they've got the big fat boy mountain bikes. Oh, absolutely, the giant tires. I bet they do. And I bet they're having a lot of fun because there's There's actually, if you had those bikes then, there's a lot of single-track lines that you could, you know, ride up there.

I bet they're having a lot of fun. Don't fall though. On a volcanic rock? Road rash on volcanic rock. Oh, absolutely.

That would be awful. So from there, let's skip over the bank and the bank was fun, but it was just implementing a program was fun, and having success at that was a lot of fun. But from there, I had the opportunity to go to Kaiser Permanente and set up a risk team, and you and a bunch of other people had a great time putting in and implementing controls and processes that they're still using today, and enjoyed that time. And from there, transitioned— I'd had experience with a lot of large companies. You know, you're going from government to Raytheon to Bank of America to Kaiser.

And so I really wanted to try something different, and so I went to a startup. Yeah. And, uh, went to CyberGRX. Yep, local company. I think many people probably know CyberGRX.

Yep. And won a lot of awards, great platform, third-party risk assessments. And so I worked with a team of 4 or 5 people, and we developed risk criteria and evidence criteria and kind of got that off the ground. They ran into some hard times and got laid off there, but that landed me where I'm at today, where I'm really having a really good time at Cloud Elements, where we're an API integration company.

My entry point there, they didn't have a security team. They had a guy that would implement CIS benchmarks on security groups when he remembered.

Believe it or not, if you want to call it the security person, was the HR director.

That was quite interesting. The whole purpose there was helping them get through their ISO 27000 audit. And that was an eye-opening for them, understanding everything they got to do. And for the first 2 months, it was, who's the guy in the corner with his headphones on? Right.

Because they didn't have a town hall. I came right in the middle of their town hall because they had met every other month. Okay. So they introduced all the new employees at the town hall. Well, I had come right after that, and so needless to say, I was the guy in the corner writing policies, procedures, setting up testing and stuff like that.

I'm sure that was an interesting experience if you're coming in basically with nothing in place.

I don't know if anyone's ever tried to get ISO 27000 certified, but it's a high bar. It's not trivial to to do that, right? So ISO is a pretty tough standard, and then following it is one thing, but actually getting certified is another thing. Showing that you've got everything documented, showing that you're actually doing it, that's a lot of work. It was, and it was myself and 2 contractors and a couple of engineers taking all of the policies and procedures that we drafted.

You're going from that test of design and now you're going to test of effectiveness. Are you doing what you say you're doing, essentially? We were, for 2 and a half months, gathering evidence and screenshots and building the business case and meanwhile preparing for that ultimate because we didn't have a choice. We had contracts that required it, prospects that are saying, hey, in order for us to do business with Cloud Elements, we got to make sure we do this right. And so, yeah, it was— and this was my entry into really understanding and diving deep into cloud and cloud security, really understanding on-prem, but on-prem is different than the cloud, working with the various providers where you've got to understand what they're doing and then how we're implementing our applications in in the infrastructure.

It was very challenging. It was fun. Still researching today just because it's an ever-changing ecosystem that you're having to do. I think that the startup part of it is always interesting too. You mentioned coming in that they had half of a guy or part of a guy that was maybe doing security sometimes.

Even companies that are security companies or that play a critical role, API integration, obviously you're going to think, oh, we need to have some security there. But just the startup mentality is that, hey, we've got to get this thing going. Security is usually one of those things that suffers because if you don't have a product, it doesn't matter if you're securing it or not. You've got to make sure that you can do the business side of it or else it doesn't matter if you can secure it. Oh, absolutely.

Just laying out policies and procedures was one thing, but then it's training everybody to use what was developed, and that was the challenge. You're going to an engineering team, like you said, that's— we've got customer demands that we got to meet. We're not here to meet security and compliance.

We'll get to that on the 2nd Tuesday of next week.

Trying to build rapport with the engineers, it wasn't my first interactions besides the DevOps team was not, hey, let's talk about ISO. Hey, let's talk about security. It was having lunch. It was having a beer. It was getting to know these guys where they would trust and have a relationship.

I think that's where the success the success came from was building that relationship with the application teams, the engineering teams, and the infrastructure teams. You've been at large companies, you've been at small companies. I think most of the time you've come in, there's already been something in place. I mean, even at Kaiser where we were building something, there was stuff in place. Totally was.

Did you find it easier or harder at Cloud Elements where basically you had a blank slate, right? You're coming in, you're sort of starting from scratch, and you're trying to get ramped up super quickly. You know that— let me just start off by saying it was fun and I enjoyed the challenge. And here's why. If I go all the way back to when I started at Raytheon, I walked in I had 6 people on my team.

We went to lunch my first day and one of my engineers said, I'm resigning today. Welcome aboard. Goodbye. So I had 2 out of 6. And so from that point, that was a turnaround situation, but I learned so much in understanding what, just what the team, I had to be more involved in my team and caring for them.

I knew all the technical and security and all that, but it was really about carrying the team. And I took those experiences of all the different places to Cloud Elements, and I'm like, okay, as all of us know, you walk in, you've got to clean up somebody else's best effort, where here it was brand new. Yeah. So it's like, wow, okay, I'm going to do this right so that the next person that comes behind me loan say, what the heck was this guy thinking, right? That's what you— at least I fear that, right?

I want to always try to do my very best. And so it's been thinking of the perspective of what— how would I want to walk into it? You know, if I want a turnkey, if I want to walk into that Cadillac or that nice BMW, whatever it is, you don't want to have to replace the seats, replace the steering wheel, replace all this cosmetic stuff besides the engine. You hope the engine, right? The engine being all the technical security that you've got going on.

And so that was fun too. It was, you know, as a startup, you don't have an unlimited budget, so you're having to really do more with less, literally. And so it was being creative and looking at cloud-native security tools, tools that you could implement A lot of customization, a lot of time. It's not just right plug-and-play sort of thing. So it's been— it's really a lot of fun.

It still is today. Yeah, yeah. I always have this, uh, this fear doing that, coming in and sort of starting something. Um, I haven't had very many opportunities to start from scratch, but you know what, one basically, one or two. And, um, but it's, um, making sure you think through the decisions you're making when you make them?

Because I always have this feeling like, okay, if I make this decision now, maybe it's the right decision now, but next year, yes, 2 years from now, you know, 5, am I gonna regret that we, we chose this as the starting point, right? Right, exactly. Uh, and so that always is in the back of my head when I'm, I'm doing stuff too. It was, it was great. I walked into a an all-Mac shop, which was great.

I didn't have to deal with Microsoft Tuesday, you know, all the updates and all the scanning and testing, regression testing and all that. So that was my one blessing. And I think that's the one thing those guys did is— 2 things they did. One, they had all their business and administration, and then they air-gapped the production environment that all of our customers uses. And so in that regard, they actually set me up for success because I didn't have to do that split, right?

And so it was really good in that regard. And I think that's— as I talked to other practitioners, that that's kind of an ultimate goal, right? That you don't have to worry about that phishing email corrupting and bringing down the entire platform because they don't have access to that platform, right? You know, and there's 3 different layers in our environment that you've got to go through before you even get to that production environment. So it's been fun.

It's— you always think about the tools that you're implementing and the processes that you're implementing, you know, and I go to you and your partner in crime, bounce ideas off in our Slack channel, cloud security Slack channel, and just, hey guys, what do you think about this? What about that? Because you need to make sure you're thinking about it correctly. Yeah, and I think that was definitely a blessing that they segmented things off because anytime you're talking about compliance or audits and stuff too, it's all about scoping, right? You come into some sort of legacy environment where You're trying to get compliance someplace, but then you realize, oh well, this legacy system over here is actually tied into the stuff that I'm trying to segment off.

It's absolutely impossible for me to segment out all the things that I want to to get my scope down. Hard enough doing ISO 27000 compliance, but if you couldn't have segmented and scoped that stuff into its own, I can't imagine how hard that would have been. No, you're absolutely right. In fact, even when the auditors came in, they looked at my scope statement and they were like, where's the rest of the business? Right.

No, just focus on this square, this box, if you will. And it's kind of funny because Cloud Elements, our offices are split by a hallway. On one side of the hallway, you have all the sales administration, and then on the other side, you have all your development application engineers and whatnot. I said, think of it like that. That visual analogy for the auditors made it clear for them that they're over there and we're over here.

It was good.

You've had a long career. You've been in many different verticals, many different size organizations. What's something that you've learned along the way that you think would be of interest to people?

If I'm sitting down and I'm talking with a new engineer, a new security individual that's aspiring to work in security or compliance, whatnot, the biggest thing that I would tell them is your relationships are key.

And understanding how to navigate the murky waters that you're going to run into with those relationships, whether it's your peers, whether it's people in your department, outside your department. It's having to understand how to be kind. Compliance and security don't need to be a billy club, you know. When, when I was first coming up, it was the compliance security billy club. If you don't do this, we're going to fail.

If you don't, you know, the fear that you're trying to put into people.

I think people understand deep down, just because of today's environment, they understand we got to protect stuff. They understand you got to protect customer data. You don't write your password on a sticky and put it under your laptop or your keyboard, something like that, like they used to do.

And I think it's relationships is one, and then really studying your craft. It's really understanding we're never gonna know everything, but be good at something. Yeah, you know, whether it's security— when I tell people, oh, I work in— depending on the audience I work in IT and cybersecurity. Oh, can you fix my laptop? You know, you've heard of those.

And just understanding your limitations. I'm not good at that, but I know that somebody that does. Yep. And I think that's— those are the 2 things that I would do. And just enjoy what you do.

It's not— if there's one thing the military taught me, for the most part, what we do is not life and death. Yeah, and if you just keep it in perspective and enjoy and have fun, it'll be good. Yeah, well, when you're in an area where there are certain times where things are life and death, then you can— I think it's easy to parse out everything else and say, all right, everything else, this isn't quite as important. The life and death stuff, that's important. And I think that carries over to to information security too, right?

It does. It's maybe not life and death. Maybe if you're in healthcare, there could be some life and death stuff in there. But obviously— especially critical systems, environments, and things. There's stuff that's important, and then there's everything else.

I think understanding that is always helpful too. I think you're right. It doesn't need to be overly complicated. I think as we look at ISO, we implement implemented the clauses, and I think it was 215 controls. There's maybe 1 or 2 controls that if I had to only implement those, that's the few that I would do.

I think it's just simplifying it, not oversimplifying it, but understanding and, to a degree, prioritizing.

It's been good. So you mentioned a little bit earlier, you like to, you like to bike. I do.

Tell me about your biking and what other stuff do you like to do? Oh goodness, I love road biking. When I retired from the military, the, the doctor told me, you know, all the running you've done for 21 years, taking a toll on your knees and ankles, try something new. So a buddy of mine said, hey, here's my, uh, I'm not using this road bike anymore, you can use it. And I really enjoyed it.

I could go out, put my headphones on, listen to a podcast, listen to music, whatever the case may be, and just have some chill time for an hour or two. And that kind of led to riding probably anywhere from 300 to probably 600 miles from March to essentially September-ish timeframe. Yeah, enjoy it, go out. And I think the pinnacle for me, I've got buddies that are like, hey, come do this ride, come do this ride. But mine is the Copper Triangle.

It's 80 miles, about 6,900 feet climbing. And enjoy it. It's like when I get done after that 6 hours of riding, I look forward to that nice cold beverage, right, waiting at the end. Do you ever, do you ever do any tours or, you know, uh, Triple Bypass or, you know, any of that kind of stuff? Well, the Triple is, uh, 120-ish miles and almost 10,000 feet climbing, and so this, this guy doesn't bite that.

No, that's too much. That's too much for me. I, I like to enjoy it. I don't I know there's some friends of mine that they'll do the Triple Bypass twice in one day. And they're just workhorses.

And just, you know, when I turn a corner and I see a 12% incline, I just cringe, you know, especially when you're about 30, 40 miles in. But no, the rides are fun. My father-in-law did Ride the Rockies. Which is 500 miles in 6 days. And so he did that for a few years, and so he's kind of done doing those long distance, but we want to kind of do some of the other ones like the Elephant Rock.

And there's another one that goes through wine country, but just enjoying those types of rides, more riding for enjoyment. But when I'm not riding, I enjoy golfing. One of the few things that people can do right now. Exactly. And today's just a beautiful day that if I wasn't here with you, I'd probably try to sneak out on a Friday afternoon and go do that.

So no, enjoy that. And it's trying to hit that little ball, and it's kind of a you versus the ball thing, and it's nobody else's fault. It's just you if you don't do it right. I am horrible at golf. Are you?

There was one year I tried. I took a summer with a friend of mine and I said, okay, I'm gonna, I'm gonna try and get good at golf this summer and played a lot. Um, you know, we actually, they had a deal up at Raccoon Creek up here where, you know, you got some lessons, you got, um, you know, a bunch of tee times and played a bunch of golf. And I got, you know, marginal, like, like the smallest margin you can make. I got better and I was like, all right, 100.

Um, I, most of the time, uh, I've broken 100 a couple times. But, uh, you know, the other thing, it's, um, golf is great when you're good at it. Yeah, it's like, you know, you can go play around in a reasonable amount of time. Um, if you're bad at golf, it just takes forever. True, you know, it does.

Uh, that's— so it'd be nice if I could just be good at golf and then enjoy playing golf. But, uh, and not that I don't enjoy hitting the ball around, but it's just like any hobby we have, right? It takes time. It does take time. And I enjoyed it when I was in Georgia.

I was looking for just some side work, and I lived down the street from a golf course. And so I said, hey, you got any jobs? He's like, what are you doing Saturday and Sunday morning about 5 o'clock? I'm like, I'm used to getting up early. Yeah, sure, what?

He's like, cutting greens and cutting tee boxes. And I got to play as much golf as I wanted to. Nice. So that's kind of where my golf game took off. And of course I got some advice and some tips, you know, from the pro here and there.

And so that's really, to your point, you gotta play. Yeah. And that's where I learned a lot of fundamentals. And I can, I cannot play for 6 months, pick up a club and easily hit 90, 95. Yeah, so not great, right, for, for not playing and being an amateur, you know.

I think it's one of those things too. I didn't play golf a whole lot when I was a kid. Yeah, um, uh, you know, a few times. Yeah, but I think it's one of those things where if you, if you get the kind of muscle memory early, like you develop a couple of those good habits when you're young, then you can you can take that with you forever. And I didn't do that, so it's a lot harder, I think, as an adult to try and get all that coordination down.

I have found that, you know, a lot of business— pardon me— business and sales guys use golf as a means for communication, negotiation. I found that even within security, when I'm doing information security compliance, you have opportunities to go, let's go play some golf. And kind of back to that point of building relationship, breaking the ice. And especially with the business now, I think more so now it's more important for us as practitioners to really understand business. What are we protecting?

Why do we need to do what we're doing? And get their buy-in, right? Because you want to be As I took this job, one of the interview questions was, why should we hire you? Why do we need this? And it was— I sold it as an enabling function for sales team, and it's worked out that way.

Yeah, because of the nature of, you know, API integrations and whatnot, and people, you know, really sensitive about their data being secure and passing through. So, but it all started with a hobby, you know. Know, using that to build a relationship, to open that door for them as well as me, for me to really understand the business, to understand what am I doing. Yeah, well, and to my point before, you know, golf is one of the few social things that, you know, we're quote allowed to do right now because it's outside, you can distance from people. So, you know, I think people need to take the opportunity to go play golf just because it gets you outside.

And you can be around other people just for sanity's sake, right? Yes, exactly, exactly. And enjoy it so much. Cool. Well, uh, we're just about out of time, Ed.

Anything that we didn't touch on that you wanted to touch on? No, I, I've really enjoyed it, and I think it's the, the opportunity for, um, us as peers to really just to dive in to get to know other practitioners and see what's going on. And I really appreciate the time. It's been fun. Listening to the podcast and enjoying just the different conversations.

Awesome. Well, thanks, Ed. Appreciate your time. And like you said, you're on the Slack channel. If anybody wants to talk to Ed, just jump out on the Slack channel and hit him up.

Let me know. So awesome. Thanks. Thank you. This has been Colorado Equals Security, and we'll talk to you next time.

Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes