Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 180 for the week of September 14th. Alex, uh, well, we made it through our first snow of the year, huh?
We did. We made it through first snow. This week was also the first week of my kids being back to school in person. Made it through that as well. Was that— what was harder, the snow or the kids being back to school in person?
I'm gonna go with the kids. It was a little difficult getting things going with, you know, they go every other day. Plus Monday was a holiday. So things were shifted and different days started at different times. And is far too confusing.
Well, I think it's really nice that they're able to do that though. It is. It is. Man, the whole virtual full-time is brutal. Yeah.
And I mean, they were of course both very excited to get back in person to see friends and things like that. I don't think they really cared about the learning part of it. But what, there's learning at school? Someone's doing it wrong. Being at school was something that they've been looking forward to.
Awesome. All right, well, let's go ahead and jump into our news. You know, reminders, we do have a Slack channel. That's a great community where you can get to know almost 1,600 of the, of the best security folks in Colorado. We also have a mailing list.
You'll get an email from us once a week if you sign up for that mailing list. It will have the show notes from this week's podcast. If you go to the website colorado-security.com, go to the form at the bottom of the page and sign up, you will get that email to you once a week. Yep, you can also get the Slack link while you're there on the website. I would love it if you would rate us and subscribe on your favorite podcast listener.
They call it a podcatcher, your favorite podcatcher. Ooh, we're using some fancy terminology here, Robb. Also, you could tell a friend, just let them know how awesome Colorado Equals Security is. And, you know, have them come check us out. I actually saw a post from someone on LinkedIn this week saying, hey, does anyone know if there's a community in Utah that's like Colorado Equals Security?
And of course, I said, maybe, but not even close to as good. It couldn't be because Utah does not equal security. That's right. Colorado does. We would love it also if you would help support the podcast financially.
We do have a Patreon campaign. That's a place you can kick a little bit of cash in to help us pay for the cost of hosting and so forth. A big thanks to those people who are already sponsoring or supporting us there. We have 20-something people who kick in a little bit of money each month. And frankly, it means a lot to us.
So, we do appreciate you guys a lot. I think finally, you know, we have been getting around a little bit to do some interviews, but if there are folks out there that would like to do interviews, we would still love to have you volunteer to do that. Or if you want to be interviewed, reach out and let us know or nominate someone to be interviewed, any of those things. All right, last piece of news here is we do have our salary survey that's still open. We're going to be closing that pretty soon, I think, and I would say no later than the end of the month, but we're, we're, we've We've got a lot of responses right now.
We're not too far off from being able to close this up. So if you want to be part of the salary survey and get the results of this, go out and make sure you click that link from our webpage or go to Slack and you can find us there too. That is going to be really just local Colorado security salaries and we'll give that data right back to the community who helped us put it together. Yeah, I think you made an important point there too as well, Robb, that this is not something that we will publish as a general report. You know, you have to be one of the people that puts in data to get that report back to you.
So if you want the data, you need to put data in. All right, uh, the next, uh, kind of jumping into the news, the CTA, Colorado Technology Association, has opened their Apex Award nominations. That is the big annual recognition for technology companies and individuals in the area. And as of a few years ago, I think it was what, 2017 was the first time that they added a CISO of the Year award. And once again, there's an opportunity for you to nominate Nominate your favorite CISO to be the recipient.
And, you know, not that we're partial or anything, but there are, you know, 2 nominees, former nominees for that award on this show. Pretty good stuff. And one winner. We would love to see somebody else who from our community win that. Of course, if you have someone who you think should win, you know, let us know.
Maybe we can encourage someone to do nominations other than yourself. I think multiple nominations for a person does not hurt. Definitely. All right, well, Robb, let's jump into the news. There was an article this week talking about the Colorado Secretary of State and how she is suing the United States Postal Service around some election mailers that they are sending out.
Yeah, this was actually the front headline story on CNN.com. The, you know, Jena Griswold, who is our Secretary of State, was suing the USPS basically because they had sent out a notification to voters suggesting that they had to have their ballots in the mail 7 days before the election in order to make sure they would get counted.
I would guess, if I take the USPS's perspective, they'd say they're just trying to be conservative. If you take Jenna Griswold's perspective, she's discouraging people who don't get the vote in before that from bothering to put it in later, when the fact is, it only has to be sent up to the day of the election. Yeah, I mean, and I think the big story here is that in Colorado, we do voting differently than many other states, and I think they were trying to put out a mailer that was sort of one-size-fits-all, and, you know, we don't— we're the round peg in the square hole. So, I think there were a couple other things in that mailer that were not consistent with the way that we do things here in Colorado as well, so we'll see how this lawsuit goes, and maybe they'll be able to stop some of those cards from being sent and confusing people. It looks like really the purpose, what they're trying to accomplish, what General Griswold is trying to accomplish here is to stop any further from being sent, like you said, so there wouldn't be confusion.
You know, obviously, if that doesn't happen, then we'll continue to make sure we have to look at local news to support that. Exactly. All right, next. A Denver-based buffalo sauce startup is partnering with a local brewery for an IPA Wing sauce. So this is Blonde Beard is the name of the buffalo, excuse me, yeah, the wing sauce.
It was kind of an interesting story. I love to hear about local companies doing interesting things. Really what I liked about this is these are people who later, significantly later in their careers, decided that they just wanted to stop being in the corporate world and make some wing sauce, right? Not your normal success story, certainly not one we talk about on this show very much. They've been launched officially in 2016.
And they use all natural products or ingredients, I mean, like butter, and they're using— they're not using oil-based sauces, which is, I guess, most of the wing sauces out there use that. Yeah, I thought this was pretty cool. First, that this was sort of a hobby for the couple, and then at some point when they decided that they didn't want to be in the corporate world anymore, they made it a career, which is pretty cool. Also, for the sauce that was mentioned in the title, they partnered with Upslope Brewing out of Boulder to make the sauce. And it sounded like that was sort of a fortuitous connection before COVID And then now they've come together and started bottling that sauce.
So pretty cool there too. So they're doing their IPA Buffalo and they say that they are gonna have, well, they may have additional combined sauces with Upslope, but as of today, this is the only one. All right, moving on to our next story. This is a story from the Denver Post around the pandemic. It's called The Pandemic of Work-from-Home Injuries, and I found this really interesting.
You know, it's, it's not necessarily only a Colorado story, although it was in the Denver Post, but it was really about the fact that, uh, the, the— during the work from home and COVID, the, the prevalence of people, you know, getting ergonomic, uh, and, you know, basically physical injuries because they're just working in terrible situations has gone through the roof. Yeah. And it's something that's pretty easy to do, right? If you got sent home at the beginning of COVID and you thought, okay, well, I'll just work off of my couch for a couple of weeks, and then a couple of weeks turned into a couple of months that turned into even more months. All of a sudden, if you're still working on the couch, you're probably not in a good sitting position.
You're probably typing on your little teeny keyboard. On your laptop, your head is craned down looking at the little screen, all those kinds of things can lead to some repetitive stress injuries. The one thing that they pointed out, which I'd never really thought about, is, you know, while laptops are convenient, they're really terrible ergonomically because you either have to have the screen down low, so you're bending your head down to look at it, or you have to have the screen, the whole thing up high, so you're having to bring your arms up too high to be comfortable to type on it. Just based on the way it works, it's not going to be good for long-term working. Yeah, let's outlaw laptops.
I think that's it. I'm going to go back to Ping and I'm going to, I'm going to say we're going back to desktops, everybody. Let's do it. Um, next, uh, we've talked a little bit about, uh, this before, but this is a new story and a new spin on it. Um, Colorado has stopped nearly $1 billion in unemployment benefits from being paid to scammers, which is a really, really large number.
Is that billion with a B? $1 billion. So this, this is all about the unemployment benefits that folks have been trying to, uh, get fraudulently through the, through the COVID process. You know, we talked about it a couple times in the past that, you know, there were a lot of claims that got rejected. This, this goes even, even further, and they say that they've, they've added— they're calling it a mysterious, uh, 18th fraud prevention mechanism, uh, that they added back in August.
And that particular mechanism, um, prevented $750 million— well, between $750 and $1 billion in benefits to being paid to scammers. It stopped 50,000 false claims in a 2-week period. And then they used that measure to look back in the past and they could see back from middle of July to late August, there was another 48,000 that were— that had been put in there that were also fraudulent that they're going back to kick out and try and claw back some of that money. Yeah. This whole thing is just weird to me.
And I think we talked about this the last time that we had a story around this. You know, someone fraudulently filed for benefits on my behalf. Luckily, I still have a job and haven't needed to file for unemployment benefits. But, you know, the way that you get your benefits is that they send you a debit card in the mail to use. So, I don't understand the scam vector there, right?
You know, if you file for benefits, you got to get the card too. So, I don't really understand how that works. I had— I'm glad you asked. I had another person talk to me about this recently. And apparently what they do is after they send out the initial card, they will call the bank and say, hey, I didn't receive my card.
Did you send it to my new address or my old address? And then they will be able to answer questions about you as though it's you. Okay, well, it went to the wrong address. Well, tell me your social, tell me your mother's maiden name, whatever it is that the bank uses for security questions. They'll use it to update your address in the system and resend the card.
Got it. I guess that makes sense. Those smart scammers. Smart, smart bad guys, right? Yeah.
Yeah. So luckily for me, I did follow the instructions that are provided by the state and other folks for, you know, rejecting that stuff and canceling the card and things like that. So if they tried to use my card, they would be hard-pressed to get any money out of it because it was canceled. All right, moving on here. Next story, there is an article in the Business Journal around former ReturnPath veterans.
So if you remember ReturnPath, a local email company recently sold and the the founders are onto something new. Those founders or those veterans from Returnpath have launched a new company that's creating a marketplace for executive talent. Yeah. So I thought it was interesting. They were trying to create a startup that helps other companies and maybe mainly startups where they may need different or additional executive talent.
If you're an early-stage startup and you're— one of your founders is CEO and at some point you need to grow and maybe that founder is not the best fit for a CEO in that type of role, this new company Bolster could help get you that new person to fit that CEO role. Yeah. I mean, it's a whole lot more than just CEO. They have a whole bunch of different skill sets. You wanna have someone who could build out your diversity program, your finance program, your security program.
They have the ability for folks, executives who have done this in the past to sign up as that either, either as a full-time position, or what it looks like more likely to me like a timeshare type of a position where you're going to come in for, you know, a certain amount of time to, to help build this program or as a contractor or part-time, really, really just focused on specific deliverables versus they're not, they don't look like they're really trying to be a headhunter or recruiting company. Right, right. One of the things that I thought was interesting in the article that maybe I wasn't exactly familiar with what ReturnPath did, but they were listed in here as an email marketing company, and that's not sort of the impression that I had. Yeah, I thought they were just email delivery. I guess I didn't really know that part.
Yeah, anyway, but I think it's an interesting idea, and hopefully, there's some success there in this new startup, Bolster. Another interesting element about Bolster is they have 8 co-founders, which is a pretty big number of co-founders. They're gonna have 6 of those folks here in Denver, and I think one was in New York or something, and another one back in Indianapolis. So mostly in Colorado, but not exclusively. Yeah, I mean, I'm wondering if they will be essentially renting themselves out at the beginning as, you know, sort of guinea pigs for the service.
They did say that as of right now, what they're trying to do is get executives to sign up. I think they're trying to get a pool of, you know, people to offer to companies before they try and go get the companies to— who are looking for people. Yeah, pretty cool. All right. Next, Empower Retirement is continuing its spending spree by buying the assets of another retirement company.
It seems like we've been talking about Empower quite a bit on here. You know, they now have their name on Mile High Stadium. They, they, you know, formerly known as Great West Life, they've been making a big splash recently. They bought Personal Capital. What was that, a month, month or two ago?
Right now they have, they've acquired the Retirement Plans for MassMutual. I pulled out a few stats from this article that I thought were interesting. Empower currently administers about 41,000 workplace savings plans. So, that's 41,000 companies' worth of plans. They have about 10 million participants in it with $667 billion in assets.
That number is too big for me to really get, but 10 million people, it tells you kind of as a fraction of the US, they've got a pretty good portion of stuff. They're adding this new one that they're adding is 2.5 million participants with another $167 billion in assets. So they're, you know, they're going to be increasing by, you know, 20% to 25%, you know, on top of their current population of users. Yeah. And I mean, that is nothing to sneeze at.
That is a large increase. So pretty cool there. They are the number 2 biggest retirement plan in the country. The number 1, I'm sure it's Fidelity. I haven't looked, but I'm pretty confident it's Fidelity.
Yeah, it's got to be. I can't imagine it would be anybody else besides Fidelity. But yeah, it's good to see them growing. Of course, they bought Personal Capital. Is that who it was that they bought?
Yeah, Personal Capital. To sort of continue with that path as well. So lots of growth there at Empower Retirement. Personal Capital gets them into the B2C, the business-to-customer market, whereas most of what they do is B2B, selling plans to companies. So probably diversifying and really just trying to become a a massive financial company.
Good for them. Yep. All right, next article we have is around Colorado 2020 Inno on Fire. So this is a bunch of words I don't even know how to say together, but Colorado Inno is doing their, their recognition of the top 50 people in the area who are just crushing it in technology. I don't know if they've done this in past years.
If so, we didn't cover it. This is— I've never heard of this, but it's kind of a cool thing, a way to recognize people who are just having a, having a good good time, good success impacting the market. Yeah, if they did do it, you're right, we didn't cover it. I don't think the Colorado Inno came onto our radar until sometime in the last year. So if they did it previously, we didn't know about it.
Pretty cool. So yeah, you mentioned people, but this is also people and companies, right, that they said that are crushing it. And of course, there, we're talking about this because there's a couple security companies on there. In the early stage category, StackHawk, Uh, is listed, and under the software category, uh, CyberGRX is listed. So pretty cool for both of those startups that they might be crushing it.
They are crushing it. It might be worth clicking the link just to scroll through and look at who else has been recognized. A lot of the companies that we talk about on the show are in there for, for various, uh, things that they're doing. You know, I know Guild Education was on there and Misty Robotics, a whole bunch of others that we talk about regularly. If you want to learn more about those companies, this is the way to do it.
Yeah, I did notice that I knew a lot of the names on the list from things that we've talked about previously. Also, they mentioned that they're going to be doing some more in-depth profiles of some of the people and companies on that 50 list in the near future. So pretty cool there too. Next, moving into our security stories, there was a Red Canary story this week. It's actually a little bit different than the ones we normally cover.
This was posted somewhere else first and then reposted on the Red Canary blog. It was actually built in Colorado first, interestingly enough. There you go. Talking about breaking down a breach with the Red Canary incident handling team. So I think a little similar to the article that we talked about last week, you know, talking through a security incident.
In this case, it's more process-based as opposed to some of the technical details that we normally see in a Red Canary blog. Yeah, this is the kind of thing that I think if you're just thinking, how do I run incident response and you're looking for a good, kind of narrative about, about how it goes, this— I think this is a good way to— place to start. Yeah, uh, good information nonetheless, and, uh, continuing their, their run of good articles. Uh, next, speaking of a company that's got good articles recently, Zvilo has had a lot of interesting stuff. Um, this week we're looking at, uh, an article they called Deciphering Threat Signals: New Domain Registrations, and they just kind of dive deep into, you know, how can you use domain registrations as threat signals to use in your program, and, and, you know, what do you do when you see, uh, you know, a new domain registered?
What— why is that risky? And really, how could you start to think about including those in your security operations programs? Yeah, and I also think it talks a little bit about how they filter things down into, you know, their threat intelligence as well and what they look at when looking at those new domains. So pretty good info there. And then the final blog we have this week is from Managed Methods.
This one is sort of an interesting angle about it. Talking about IT self-harm monitoring in education. So I guess I didn't realize that this was a thing, but after I read this, it makes sense that it's a thing. Of course, Managed Methods is a, you know, CASB solution and they focus a lot on the education market, but this is really talking about using IT to help look for signals when a student might be thinking about suicide. Yeah, I found this article, number one, I was really surprised by the headline, not something I thought about.
But then I found it super timely. You know, at least where I live in South Denver, there's been a ton of suicides from school-aged kids. And if it's something we're afraid to talk about and something we're not willing to try and address, it's not going to get any better. So I appreciate them talking about it. And then, you know, talking about what is the school's place in this, man, I don't even have an answer for that, right?
Like, that's a topic that I'd never thought of. But they do a good job addressing why the school should think this is important. You know, they're using school equipment a lot of times, whether it's school laptops or school email accounts to do, to say things that are risky. And as long as the school is there, that number one, they might have a moral obligation, but if nothing else, they have a legal obligation to help these kids and try and identify those who are at risk. Yeah, and the other thing that they talked about a lot in the article was the balance that you need to have with doing that monitoring versus privacy, right?
So You know, there, it's easy to overreach and you don't want to, to do that. And of course, there are a number of privacy laws that are in place to help protect the information of our kids in education. Yeah, it's really a good article. And I think, especially I have kids who are in middle school now. And, you know, I think once you start to get into middle school, high school, this becomes a topic that parents should really be thinking about and You know, the more we're able to advocate for ways to keep kids safe, I think the better off our schools are going to be, better we're all going to be equipped to help solve that problem.
One sad fact that they mentioned that I was not aware of is that suicide is the number 2 cause of death for children behind accidental death. Yeah, it's brutal. Yeah. All right. Let's move to a happier topic, Alex.
Let's do it. What is happier, Robb? Well, the Slack message of the week, nothing happier than that, is there? Yeah. I mean, you know, that's kind of the point of the Slack message of the week, right?
Absolutely. Well, we got to start off by thanking Andre Gaeta. Andre is the perennial supporter of this, and one of these days he's going to cut us off, but so far he hasn't. So each week we get to spend some of Andre's money and give it to one of you folks who's participating in the Slack channel and get one item from the Colorado Equal Security store to walk around sporting some swag in the area. And we like to see that.
This week's winner is Mike Sabata for creating the Colorado Equals Security reaction emoji in Slack. I was, I went in there and I was like, man, I really wish I had that reaction, and I knew people could create it. I just sent a note like, does anyone know how to do this? And man, like 5 minutes later, the guy's like, yeah, here you go, it's done, and here's how you do it in the future. So big thanks to Mike for stepping up and doing that, and now if you go to Slack, Add a Colorado security emoji and you can, you can be way cooler than me.
Yes, you can. That's not very hard though. So Mike's gonna get to pick something from the Colorado Equal Security store with our not so new logo anymore. You know, we replaced the logo back in February timeframe, but I still think it's new and, and I still have some of the old logo around. So I'm, I'm slowly, slowly getting rid of the old stuff.
Yeah, pretty cool. And congratulations to Mike. With that, let's move on to our event calendar. Hey Robb, did you know on the website we have a calendar of events? You know, I did.
You know, I've spent a lot of time updating that. That's probably— for those of you listening who don't spend time on the calendar, I spend a lot of time there. You guys should go out there and take advantage of it because I spend too much time updating that calendar of events. Yeah, so go to colorado-security.com and go to the events section. You will see a consolidated event calendar with everything going on.
In the Colorado metroplex around security. Let's start talking about what's happening here in the next 2 weeks. On the 15th, the Women in Security group from ISSA is getting together with the Cloud Security Alliance, and they're doing an event called Get SASE with SASE. And I guess that this is really talking about that secure access and secure edge concept, and it's gonna be a good event on the 15th. On the 15th through the 17th, ISSA Colorado Springs is doing their 10th annual Peak Cyber Symposium.
On the 16th, OWASP is doing their September virtual meeting, and this is a combined meeting of OWASP Denver and OWASP Boulder. On the 17th, ACES is doing their first annual sporting clays event at Kiowa Creek Sporting Club. This is an event that costs money, But you'll get to go hang out with some cool ACES folks and shoot sporting clays. If anyone that we— that listens to the show goes to this, let us know. I'd love to see a picture and hear how it is because it sounds like a fun event.
On the 23rd, ISC2 Pikes Peak is doing their September chapter meeting. On the 24th, um, the Colorado Springs ISSA chapter is doing their September 2020 online series. And then on the 25th, uh, The DC 303 group is doing their September meeting. Sweet. And I think that is all the events we have for the next— That's right.
Yep. So let's jump over to jobs. This week we've got some amazing jobs. First, Ball Aerospace is looking for an information security director. The State of Colorado Office of IT is doing— is hiring a manager of security risk and compliance.
Cognizant is looking for a manager of information risk management. In their corporate security group, and this, this job is 100% remote. RE/MAX is hiring an information security manager. Lots of manager jobs this week. Xcel Energy is looking for a senior application security/penetration tester.
Bank of America is hiring a cyber threat hunter information security engineer. Red Canary is looking for an incident handler, so you could be on that team that helped create the blog that we talked about earlier. Universal Studios is hiring a security architect. I thought that one was pretty cool. You know, NBCUniversal has, I think, probably through Comcast or something else, has an office here.
But, you know, that was Universal Studios like the amusement parks that they were hiring for here. So pretty cool. That's pretty cool. And then finally, Ping Identity is hiring, I'm sure, lots of things, but one of the jobs is Head of Diversity, Equity, Inclusion, and Community Involvement. Yeah, I'm super excited that we are hiring this position and it's open right now.
So I wanted to get this out. Anyone who knows someone who'd be a good fit for that, you know, let us know. We've done a lot of equity and inclusion and diversity initiatives, but it's nice to have an actual leader. It's kind of like with security, right? When security belongs to everyone, really no one owns it.
Well, now we're going to have someone who actually owns diversity within Ping. So it's going to be cool. That is pretty cool. Well, that is it for news, Alex. We do have a— excuse me, not a podcast, an interview this week.
We have an— this week I sat down with Randall Frietzsche. Randall is the CISO for Denver Health. If you remember, we had him on the show almost exactly 3 years ago, so we just wanted to catch up and see what's changed as he's been on the job for just over 3 years now. That is a long time, Robb. It's hard to believe we've been doing this that long.
We are getting old, that's for sure. And we've been doing this a long time. All right, well, I think that's it. We'll, we'll throw it over to the interview now, and we'll look forward to talking to everyone again next week. All right, sounds good.
Thanks, Robb. Hi, this is Mary Haynes, VP of Network Security at Charter Communications. Welcome to Colorado Equal Security, for Colorado security professionals by Colorado security professionals. All right, welcome to Colorado Equal Security. Our interview this week This is a fun one.
It's been a while since we've talked, Randall, at least since we've talked in front of people. This is Randall Fritchie, the CISO at Denver Health. Randall, we were just looking, you know, the last time we talked was almost exactly 3 years ago. It was September of 2017, and you had just started as the CISO at Denver Health. You got a few years under your belt.
I wanna hear, you know, compare where you thought you were going to where you've actually gone. And let's talk about how COVID's impacted you. Let's talk about, you know, where you plan to go going forward. Before we do that, I'll give you a chance to tell me what else has changed. I know you do some kind of stuff on the side, some teaching.
You've been involved with ISSA. What have you been doing from a non-professional perspective recently, or not at least working for Denver Health? I mean, well, I've been teaching for 8 years now. When I moved to Colorado, I started teaching for Regis University, and then right after our interview last time 3 years ago, I began teaching the Harvard Cybersecurity Risk Management course, online course, and almost 3 years I've been teaching that now. So that's very cool.
It's a, it's a, it's a pretty nice course. We have a lot of people I've gone through it over the 3 years and learned a lot. I get a lot of high-level people. I had the CISO for an airport one time, which is a really interesting perspective. Certainly a lot of lawyers are taking that, which is very interesting as well.
A lot of privacy people take the course because they want to understand risk from a cyber perspective. So all those things are really cool. I teach— so I teach for Regis and Harvard. I'm also— what do you teach for Regis? Remind me what classes you're doing there.
I teach in their master's program, so they, they have a lot of different courses, you can imagine. Generally, I teach security architecture, risk management, or legal compliance from a cybersecurity perspective. How much of your time— I mean, this sounds like a lot— how much time are you spending on these different teaching endeavors? So the Harvard management course rolls over every 8 weeks. So we have a new course every 8 weeks.
Regis is more traditional semesters. So I may teach one in the spring and one in the fall. So I'm not doing both of those full-time, but I am doing Harvard full-time and it's, it's 20 to 25 hours a week. That's a lot, man. It used to be a lot more when I first started.
We had, I had about 100 students my first go-round, and it was, it was literally 40 hours on top of my regular job. But now we, we've smaller class sizes, which is good for the students, and also it doesn't take up as much time for me. And I'm also, you know, been teaching for 3 years, so I'm not having to learn it each time. Right. So you, so you've been doing that.
Any other, obviously that's, that's plenty, right? You're spending, that's plenty of stuff outside of work. Anything else you wanted to highlight though? Well, I've been involved with the ISSA, I think I've been a member for about 18 years.
I was a chapter president for the Louisville, Kentucky chapter for 8 years and I chaired that conference for 5 years, and then I got ISSA Fellow, Distinguished— ISSA Fellow and then ISSA Distinguished Fellow in 2016. So Now I do a lot more at the international level. I'm on the fellow selection committee. I'm on the cybersecurity lifecycle, which really helps people trying to get in or people who are relatively new to the profession and try to provide them with educational opportunities. We're talking about coming out with a podcast for the ISSA as well, and I may be the host for that, which is kind of cool.
I'm also on a lot of boards like advisory boards for cybersecurity publications or, you know, internet magazines, the Evanta stuff. I'm a co-chair in the governing body for that for Denver. So, but you know, it's really funny because ever since we went virtual, it's like 2 times a day there are these virtual events that you can attend and they're just crazy and out of control. Yeah, there's an awful lot of opportunities, isn't there? Yeah.
Well, so that's great. Let's change— turn over and talk about some of your Denver Health stuff. You know, you came in there, lots of good ideas. What's it been like?
So when I came to Denver Health, Drew Labbo had been the CISO there, and Drew's an amazing cybersecurity guy. And his business was taking off to the point where, you know, he wanted to do it full-time, and I was fortunate enough to be hired for the position. When I went in there, I found a very well-structured cybersecurity program, especially around the technical side. Drew and Ian Lumsden, who's the— now the Director of Security, had done a lot in their time to put together a lot of security controls that they needed, building the support of the organization in order to get that funding and get the approvals for those types of initiatives and to make sure that the security program, you know, was a focus of the organization from a risk standpoint. So, so I came into that I report to general counsel, so my boss is general counsel and I work in legal, so it is seen as a business risk position, and I'm— I wasn't really sure of that when I started.
After 3 years, I find that to be an amazing opportunity because working for general counsel and also seeing it as a cyber risk and business risk position, I have a lot of visibility in the organization. And have a lot of ability to build relationships with leadership, and which I would like to talk, talk about a little bit more later. So that was very cool. And as 3 years have progressed, I've just found that I'm able to be a lot more effective not sitting in IT and not having to be one of the squeaky wheels within IT reporting to a CIO. So that's been really helpful.
And that was a decision made by Denver Health before I got there, but I'm a recipient of that. Yeah. So what's the biggest surprise you've had since getting there? You know, maybe kind of expectations versus reality. I knew it was a complex organization, but I didn't realize how complex it really is.
We have 2 or 3 dozen public schools, so their nurse clinics are Denver Health clinics staffed by Denver Health nurses. We have a presence in the city-county jail. So when you say the schools, are you saying like basically the nurse's office at that school is a Denver Health clinic? Yes, sir. Gotcha, okay.
It absolutely is, and we contract it out to DPS. We also have a presence in the jail, which is more like a nurse clinic in the jail. But then if you have a major medical issue and you need, you need an emergency or an inpatient, they put you in the van, they take you to Denver Health in our basement. We have a correctional care facility in our basement, which is staffed by emergency room physicians and, you know, other hospitalists and so forth. And that's run by the jail.
Inside our hospital. All of the ambulances in Denver Health are Denver Health ambulances, including the ones at DIA that you might see. And one of those things that you ride, the mall cop thing, the Segways. Segway, yeah. So they ride their Segways around and it's kind of little mobile ambulances within DIA.
And then any sort of emergency situation with an airplane, they would roll out with with the fire teams to take care of that as well. So that's pretty cool. That's all Denver Health, huh? That's Denver Health. We have— do you know how many, you know, if you count all those schools and stuff, do you know how many clinics you guys are at?
Well, we have our regular clinics as well. Yeah. I think we have about 15 clinics in and around Denver, including one up in— I can't remember the name of it, but it's up in the mountains. We have a clinic up there near a ski resort. A Westside Clinic, Eastside Clinic, we have a downtown urgent care center now that we just opened in the last year.
So yeah, we have several, 30, 40 clinics probably. We have our own public health department, we have an insurance plan, we are on the Colorado Insurance Exchange, poison control center, we run a nurse line. How many employees do you guys have? It's gotta be a lot. Uh, 7,500.
Okay. Yeah, man, you guys do, you guys do a lot with, you know, I mean, that's not a huge, it's not small for sure, but it's not a huge number of employees. You guys get a lot of stuff done. We are not as big, but we have a different mission. So Denver Health's mission is, um, a safety net, which means we will treat for anyone regardless of their ability to pay.
We are also a level 1 trauma center. Which means if you have a heart attack or you're shot, you drive past 5 hospitals to come to us. So the majority of our payers for healthcare are the state and federal government, so we have a lot of Medicare, Medicaid cases, which means we have to maintain a very large compliance department because it's very, it's very difficult from the government You know, they have these really, I guess you call it, finely detailed regulations that you have to follow. And if you don't, you know, put a period after one sentence or something like that, they totally reject your claim. So we're constantly fighting that and trying to remain compliant with all the— it's not just HIPAA, it's It's the FDA.
We have a ton of research and we work closely. All of our doctors are professors at University of Louisville Medical School. All of your doctors are? Yes. Wow.
What's that about? Well, we just require doctors to also be professors. We're a teaching hospital. So a lot of doctors-to-be or doctors that have not yet passed residency do their residency at Denver Health in all the different disciplines. We also have a lot of nursing students and we teach paramedic classes or EMT classes or basic CPR classes for the general public.
So you name it, we do it. Yeah, I know you guys have student PAs there too. My wife, years ago when she was going through her program, she did one of her rotations there at Denver Health. Yeah, I think she told us that. I think I heard some stories about that place.
I mean, they're just stories about the kind of, you know, you talked about gunshot wounds and like the kind of people they see. It's people who really need medical care right away. Right. Not your— it's not your complaining of a bad shoulder like when I go to the hospital usually. Right.
They wrote a book on Denver Health called The Gun and Knife Club. And it was an author, I don't know if he was a doctor as well, but he He basically stayed at Denver Health for quite a few weeks and experienced— he went on ambulance rides and then he wrote a book about it. Our emergency room on any night, but certainly a Friday or Saturday night, is pretty crazy. We have metal detectors at every entrance. Now we have temperature sensors at every entrance and we have quite a presence of physical security folks, and, and we have the police, as you can imagine, are constantly in and out, certainly from the jail perspective, but also Denver Police Department officers are constantly in our emergency room investigating accidents and shootings.
And so it's a fun place to work. So let's talk a little bit about the security side. What have been the initiatives you've been focusing on? Obviously, you mentioned that you came into a pretty mature program, but every program's got stuff to work on. What's been your priorities?
So when I came in, I had to give a general update to the board, introduce myself, and one of the things about building relationships, right, I, you know, I call it my at-bats with the board.
When I got up there, immediately the first thing I said was, it is not if, but when we will be breached. Everyone will be breached. And what we have to do is build a program that not only sufficiently defends the organization, protects us against those things, but when they do get in, so that we can quickly identify Go after that threat, get rid of that threat, and figure out what happened, recover from it, and improve from that. So I use the NIST Cybersecurity Framework, and I actually show my board the, you know, the logo with the 5 sections in it, the NIST Cybersecurity Framework, and I show them that and I say, this is what our program is built on, and I talk through those areas. So my first was risk management.
Building in a really solid, mature risk management program. We have been rated by our third-party assessor every year, and it has gone up in maturity now. We started out at about a 2 in maturity out of 5, and this year we were a 4. My goal really is for risk management holistically to be a 5 in the NIST CSF. And really that's been largely focused on the third-party or vendor risk, pre-contracting risk.
So the first thing really I did from a third-party risk management perspective is to inject risk stratification into our purchasing processes. And there are 3 key areas that really you have to look for. One is legal because they review, you know, all the big-time contracts, big-dollar contracts, or high-risk contracts. Purchasing, of course, They process most of the contracts. And then IT, because they are involved in the middle of all the data sharing and the SaaS-type vendors or bringing in a solution, and so they're involved in that.
So I injected risk stratification into that process, and risk stratification is just a few questions, 5 to 10 questions at most, that are very critical to know. What kind of data am I sharing? With them? How much of that data am I sharing with them? What's the situation?
Is it going to be a cloud solution? Is it SaaS? Is it on-prem for us?
You know, and you take those indicators together and that builds a sort of that over— overview of your risk. So I know I have patient data living in a vendor cloud somewhere. That to me is the highest risk. So that then is where we tier that vendor. And so we have tiers 1, 2, 3.
As you go down, you go down in risk, but tier 1 is the biggest risk. That also tells me how frequently I reassess my vendors. So in that case with the SaaS portal with patient data, that's a tier 1 vendor. We document all that in our risk assessment. We, we may have a questionnaire for them.
I borrow— for the cloud-type solutions, I borrow questionnaires from the Cloud Security Alliance and I modify those to fit the organization, get those out to the vendor. We will have an interview on the phone with them if needed, and then we will complete that down through, of course, mitigation strategies, but also we have a formal exception management process in place, which you have to have. Because you can't mitigate everything, sometimes the organization has to accept risk, and that's perfectly acceptable. And if they do, you, you know, make sure they're fully aware of that, you get documentation that they've accepted the risk, and then you just document that as an exception that you track on depending on the tier of the vendor. So for me, bringing all that sort of in from scratch has been a challenge.
You know, we talked about a GRC platform where you document your risk assessments and your risk activities and your documentation. We basically built that from scratch within our service desk platform, and so I can tie a risk assessment into an asset. I can tie it to an application. So if we buy XYZ application, SaaS application, and we do a risk assessment on it, then I tie the risk assessment to the application in our, in our service desk platform. Which is really cool because now you have visibility from the IT side, from the application analyst side, and from the security side as well.
So that's been something that, that I've been focused on first. Certainly we do that from an internal change management standpoint, or, you know, if we build something from scratch internally, you know, working on making sure they have solid security processes around their SDLC.
Let me ask you kind of a follow-up there. You have a little bit of a different dynamic, and because you're, you're not responsible for the operational part of security, right? That's in the IT side. How did— how does the relationship between you and IT work? Uh, you mentioned Ian.
How— where does he come in? Like, when you're talking about the third-party risk stuff you were just talking about, like What's his versus what's your responsibilities? Great question. So the CIO and I are peers, and the director of security and the security team is dotted line to me. So I have an oversight function, but practically, you know, Ian and I are on the phone every day.
We build the strategy together. Whenever we're thinking about bringing in this new solution, I'm, I'm involved in that. His team does all the testing, but then we work with the organization to, to make sure that it's, it's set up correctly, that it's communicated out correctly, which is another really important part of the CISO's job is communication. And so yeah, we work as a team even though I'm in a different department, and it's really an amazing partnership. They have great, great people on the team.
And then within IT, it's probably the best IT organization that I've ever personally worked with.
They do a lot with little. They're constantly finding ways to improve, save money, and be more effective. And they give me all the support I need, and so I repay the favor with with them as well. So it's a great partnership.
And then they also do investigations, and I'm looped in as part of the incident response team in terms of oversight and leadership, and then also from a communication standpoint so I can bring in the right people at the right time, you know, for an incident or DR type situation. Yeah, so I mean, I, I hear that there's a lot of teamwork, but there's got to be some distribution of responsibilities between yours and his. And from the way you're talking, it sounds like maybe you're, you're going to be more on the governance and risk and like the third-party risk stuff you talked about. And is Ian more responsible for the hands-on technology sides of things? So Ian and his team are totally responsible for all these security operational and technical aspects of our program.
And then sort of take what I was talking about from third-party risk standpoint.
We've got that automated now to the point where when they want to submit a contract, they have to do that risk stratification. When they submit the risk stratification, it actually opens a ticket for Ian's team within our service desk platform. And then they go ahead, pull that, review the risk stratification, and then they determine from there what needs to be done on top of that. They document it in the GRC, and then it's bumped back up to me. If we need to, you know, have a business associate agreement with this client or with this vendor.
We have an IT security amendment that we may add onto a contract to make sure they have and maintain the controls that they attest to through the process. And then certainly if they redline anything like that, I always, you know, I'm always the one that does that. That's— so that really is— has worked pretty well, but we have considered outsourcing I hope no vendors are listening to this, but we have, we have considered outsourcing that now for 3 years. So we're trying it right now in-house. Sorry, which part are you trying to outsource?
The third-party risk management piece of that. So basically like the follow-up with vendors and getting them to complete your forms, is that what you're talking about? Yeah, sort of. Well, at this point we're really just considering more of a staff type situation for those. You know, pre-contracting risk assessments.
Ian's team does the security and technical assessment for stuff that we do internally. We bring on something new internally, or if we have an internal change, but from that third-party risk assessment before we've ever signed the contract, they're doing that now, and we are considering a staff aug. I've also talked to CISOs who've said that they're using something like a BitSight or a Risk recon or a security scorecard to sort of stratify those vendors from that sort of publicly facing cybersecurity credit score. That's what I would call it. And, you know, and if they're really good on that, then, you know, you may not need to do a whole lot more on them.
But if they, if they kind of suck, then you probably are going to, you know, spend some more time looking at them. And, and, and I've talked to enough CISOs who are doing that, that that I'm thinking it might be something and certainly take some of that workload off of Ian's team. They certainly have, you know, overfull plates.
And then maybe staff AUG on the ones that don't pass the, you know, kind of the BITSite route. Well, I'll say if you talk to your vendors, they will universally tell you how terrible it is. On the receiving end of those things, they are not very smart assessments. Yeah. There's a lot of work that gets added on the other side because of trying to use that.
Yeah, absolutely. Absolutely. And really, to be just one window into it, when we looked at BitSight 3 years ago, we had an awful security score, and I was jumping up and down on my desk about it, and it ended up Being that it was our guest Wi-Fi. So we have a, we have a totally isolated off guest Wi-Fi and a completely different ISP. And we, we do web, we even do web filtering on that.
And it's still, we have so much junk coming in and out of that, that network. And they were assessing us to include the guest Wi-Fi. And, and I said, no, I want to score without our guest Wi-Fi because I want to, I want a real true look at what we're doing. And, you know, we went from like a 570 to like an 820 or something like that in BitSight. So just imagine being on the other side and you don't get to tell them what to include with all the customers who are going to reach out.
Right. It's a painful process from the other side, which, as you know, that's where I sit mostly. Absolutely. Yeah, that would be tough.
So let's talk about what other— you talked a lot about third-party risk and kind of creating a risk program that you're proud of. What other things have you worked on the last 3 years?
So as I started out with talking to the board that it's not if, it's when, and then I also tell them that the average time to detect a breach is 9 months, and that's usually FBI calling you saying you've been breached, and then I talk about the average The last I read, the average time it takes for an APT to become so embedded that you can't ever find them is 19 minutes. So what I talked to the board about is, you know, we have to be much faster at being able to identify these things when they happen, to be able to respond and recover from those things when they happen. So I don't want 9 months. I don't want 19 minutes. I want 9 minutes.
Right? I want less than 10 minutes to spot it, take some action, try to find the holistic view of what's going on with it, and go out, kill it completely, and recover from it. That initial identification and additional— at least first-line mitigation of that to happen within 9 minutes, and I think that that makes us A lot safer than we would if we didn't focus on that. So what we've done is we've certainly begun tabletop exercises. So we do an incident response tabletop that turns into a DR tabletop exercise.
So if you think of ransomware, that certainly would start out as an IR that could quickly turn into a DR. And then the third aspect of that program is And using ransomware as an example, if they get into a system that is required to treat patients and if that system goes offline, then we're on divert. And divert costs healthcare organizations on average about $15,000 a minute. For those who may not know, what does on divert mean? Divert means you can't take patients into your hospital. I'm not talking about appointments.
I'm talking about emergency room. So the emergency room would have to go on divert, and then the hospitals, we would have to reroute ambulances to different hospitals. And so you can imagine that could be a life or death situation. So divert is a nasty word in healthcare, and like I said, $10,000 to $15,000 a minute costs for a hospital that operates a 24/7 emergency room. And so that's a, that's, that's a big time, especially if it's ransomware.
And takes several hours or even several days to, to get back to normal, uh, you know, that's millions and millions of dollars that an organization is— could lose. So the one thing that I've done there is to do those incident response tabletops. We're also talking to our cybersecurity insurer and our third-party cybersecurity partner in helping us to continue to modify those and improve on those tabletop exercises so that we are training.
You know, they always say, you know, under stress you're going to do exactly what you've been trained to do, and if you haven't been trained, you're going to do exactly what you've been trained to do, which is nothing or fight, flight, panic, freeze. Certainly not the most— not the quickest way to deal with it. So training is really important. We've set a standard, a minimum standard of the SANS GCIH certification. So we make sure, yeah, incident handling from SANS, just to make sure everybody's at least a baseline level of competence around incident handling.
We established that for who? Who has to have that? For Ian's team.
And then we're you know, certainly utilizing a third-party MSSP for SOC, and then we have been testing SOAR now for about a year, year and a half maybe, and the promise of that really is— and we have NAC as well— so the promise of that really is if, if one of our systems detects potential issue And we have tested this enough to be able to turn it on. We could potentially disable a user account. We could potentially shut off a network port, and all this could happen even before IT knows there's a ticket. And I find that to be very attractive. So we have been doing a lot with that.
So you guys actually got that implemented, or is that something that you're working on trying to get implemented? We have implemented it to a level, and we have done a lot of testing over time. In healthcare, it's really tough because you have so much different kind of traffic that unless you could totally baseline every bit of traffic for, you know, a month, it's really hard to know exactly what's talking to what and what language they're speaking. You know, we have HL7, we have EDI files for insurance, a lot of different things that are, they're not Just IP traffic. Yeah, you definitely gotta be curious what things have you been able to get orchestration automation around that?
Because it seems like it's awfully tough to do any kind of turning off or blocking in such a dynamic environment like that. Yes, it really is. And even if we never turn on any automatic blocking or any automatic shutting down, we still have the ability to to get a ticket in quicker. I think that's one of the benefits we've seen. Another benefit is take— looking at it from the SOAR perspective.
What's SOAR seeing and how can we more fully integrate that with our SIEM tool or network threat intelligence and our endpoint threat intelligence or EDR they call it today? You know, different traffics from different isolated networks. And really make all those things talk to each other well, which I think is a big problem in security today is all of our different controls don't talk well to each other. So really that, really building a great SOAR foundation has been the most important initially. And then eventually we will, and I could talk more about security context because that's part of that conversation.
Once I can get more security context, And part of that is intelligence on the wire. In other words, I can sniff out a model number of a biomed device. I can sniff out or even decode HL7 traffic to determine what kind of traffic it is, where it's going, even the, you know, the usage of the biomedical devices, right? So How often do you use this particular x-ray machine? And right now we spending, you know, we spending the same amount of money on these x-ray machines that are hardly ever used.
And then we have these, we're spending the same amount of money. So, so really that, that ability to build that context, see what the traffic is, see what the devices are on the network, and then add that context to an overall security, what I would call a security database, a CMDB, and have all that in there and then have that talking to my different tools so it can look in— so a security tool can look in the security context CMDB and we can gather more intelligence and all that intelligence then almost leads itself from ML to AI, right? At some point that machine can make a decision that maybe before it took a human to make and those could be very basic like just disable a user, you know, temporarily until we get to the bottom of it. So it's very exciting. I'm not sure we have the right mix of controls, and SOAR really is still in its infancy.
And over the next 2 or 3 years, I'm really looking forward to where it goes and, you know, find ways to better integrate between those tools and the CMDB with all of our security context in it. There's a ton of promise there. It It does feel like it's still pretty immature. So getting from a ton of promise to actually, you know, delivering on value, right? We're still a ways away.
You know, one of the things I hear most people talk about is, you know, building context around whatever events you're getting alerted on, and that's right, that's great. So your analyst isn't having to do it, have to do the manual review, and I certainly don't question that that's valuable. It just isn't the same as being able to you know, have one less headcount doing, doing SOC work, right? It just doesn't feel like we're there yet. Yeah, and that's not really even our focus for now.
It's really just getting it up to the point where we feel like it really does add some value in terms of driving down the time to detect and even the time to do some immediate remediation steps on that. But, but really my overall bigger picture, bigger picture focus or mission is to build security context because right now we have an application in there in our CMDB and we know who's the vendor. We might know the model number of it. We might know the IP address. We might know the MAC address, but very little in that CMDB around context that's, you know, useful for security, especially in an incident where everybody's under a time crunch.
So what I want to build is a security CMDB with additional context with not only technical, not only, you know, attacker-specific, but business context as well. Like, what's, what's the divert risk of this system? You know, is it, you know, if it goes down, are we going to be on divert or not? Because there are some systems that will never go on divert if they go down, like our HR system. We wouldn't go on divert if that went down, but our imaging system where they take images and they read your, you know, your x-rays, your MRIs to tell you, you know, what the problem that you're having.
If we don't have those, we have to go on divert. So what's the divert risk of this particular thing and what's the cost, you know, per minute of this thing going down? So then we'll feed the BIA process into that, not only uptime requirements but also cost when it does go down. And so I've asked for the top 10 revenue-generating areas. Then from there, I've driven that down into what are the applications that are critical to support those 10 revenue-generating areas.
And then I take those and I put those at a high priority within the CMDB so that we can, you know, it rises to the top if it's affected in any way. You know, and then a lot of other context points around that. You know, like, you know, last update, right? Last vulnerability scan, you know, any specific threats. If you do threat modeling, you can put that in there and add that to the context as well.
Yeah, it sounds like a great foundation that you'll be able to make a lot of intelligent decisions for going forward. Absolutely. Yeah, I mean, it's a, you know, it's something I've been dreaming about, you know, for 10, 15 years and I think we're getting closer to have that ability. One tool, one thing we have to have is a tool to just sort of passively sit on the network and, and kind of check out the traffic. And there are tools out there.
I won't mention any names, but, you know, they can not only, they can see the traffic's unencrypted, they can actually packet scan, packet sniff. They could even get down to the model number of the box, IP, MAC. All the information that's transmitted across the network, this thing will collect, and then I can take that, feed that into my security CMDB to have that additional context on top of that. Yeah, so I want to, you know, we're not going to have a ton more time. I wanted to make sure we had a little chance to talk about how COVID has impacted you guys.
Obviously, you know, as the, the tier 1 hospital in the region, I'm sure you guys have had to do a ton of planning and thinking about this. How have you seen the impact of COVID on the— let's just start on the hospital in general.
So we planned for the worst. The city has had— I don't know if they still have because they never ended up using it, but they— we were working with them to convert the convention center into a surge facility for COVID patients. So, we basically drove, you know, the process standpoint around that. It's certainly from the nursing and healthcare type of processes down to the technical, you know, the medical record and imaging and everything that has to have in a healthcare facility. So, we were primarily the ones doing that for the city.
And then we began— so it was almost overnight, literally 3 days, we got about 200 brand new projects that were all COVID-critical projects. And those were all on top of everything that we already had on our plate. So not only do we have to support those business projects and IT projects, but we also have to support our own internal security projects. And, and then still stand on the wall to protect against the threats that are, you know, more immediate from a cyber perspective. And, and we started to see all the increase of phishing threats using COVID pretense to hit hospitals.
And so my communication efforts really stepped up through the roof in terms of daily communication as part of our daily COVID communication. At the top of that, we had, you know, severely, you know, increase of phishing attacks in the industry. You know, please be aware, don't click on anything, you know, shut your computer off, go home, you know, just don't click on anything. But that was an everyday communication that went out in the daily COVID newsletter, which everybody was reading. So that was important.
Then I was sending out almost a weekly sort of a security awareness email to everybody in the organization. At one point I put in there, I'm deputizing you as a CISO to be on the lookout for these threats. And I got a lot of interesting replies back to that, which is part of that building relationships, I think. So really just stepping that up. You know, we were in the middle of all of these 200 new COVID projects, but we also had 2 new critical needs.
One was to support everybody going home and working remotely of all different modalities of employees that we might have. So we had already set up 2, 2 ways to come in. One is the application publication, which you can hit from any kind of device, and the other is VPN, which you can only come in from a Denver Health device. We already had both of those set up well. We increased our bandwidth to 10 gig to the internet.
And we, we already had multi-factor authentication in front of both remote access methods. We didn't have RDP turned on or anything like that. So we were, we were already prepared. Of course, we didn't realize the scale of it. So we had about 2,200 people working remotely for months.
And so we didn't have— we had some licensing issues. We had to bump up our licensing for VPN. And the multi-factor licenses. But that was really the only thing. Other than that was just getting everybody approved for remote access because they have to submit a form, the manager has to approve it.
And so we were just trying to— we were working really through the weekend. Did you change the process of getting people submitted or approved during COVID No, we did not. We just worked nights and weekends for a couple weeks to get everybody in, you know, sort of, you know, Here, go ahead, take it home and get the form in and we'll make sure that it gets approved and documented, you know, within a week or so. But yeah, that was really the only problem that we saw. The other big deal for us was telehealth because now no one wants to come in the hospital and now we have patients that even the doctors and the nurses don't want to go in too many times into a room because then they increase their exposure to COVID.
They also have to use PPE every time they go in the room and then they have to change it out every single time. So we use telehealth not only for remote people to get a doctor visit, but we also use telehealth within the hospital for people who might be a COVID patient, they might be in the room, they can't have any visitors, and we really have to minimize the people who go in the room. So they had a device, an all-in-one device where they could do a WebEx and then we had doctors who would round on COVID patients using an iPad. And so they would just fire that up and then they would see the patient, talk to the patient, they could see what they could see on a WebEx, and then if they had to go deeper than that, they would go in the room. Certainly if they had to change an IV or something, they would go in the room.
And then they're all totally dressed up in their monkey suit, right, with the face shield and the mask and everything on. So yeah, I never— it never occurred to me that you might do telehealth within the hospital, but now that you describe it, it makes perfect sense. Yeah, absolutely. So we did stop doing like elective stuff. We had to change out a lot of the areas in the hospital into COVID units.
So we had like critical care units, intensive care units, we turned a lot of those into COVID units just to prepare for a surge. I think we may have only used about 40% of those rooms that were transferred over. We also had to set up external testing for COVID. So we would stand up tents outside and you could drive up or walk up. And then we had healthcare workers outside doing COVID testing.
And yeah, so there were a lot of things going on. We had a lot of immediate needs for new sharing of data. And in ways that were not conventional, in ways that really had to be done overnight, and we didn't have a whole lot of time to vet those things. So it was really difficult to keep— at least become aware of everything and keep track of it so that once all this is over, we no longer need it, that we can pull it all back.
And the OCR came out with a with a notice that said we are not going to enforce if you use telehealth methods that are not vetted for HIPAA. So you could use Facebook FaceTime or Apple FaceTime or whatever the Facebook version of that is, and, and, and that's fine to use for telehealth. And we, we chose as an organization to not do that, not allow that, even including Zoom. Zoom was having so many issues then with the security reputational stuff that they had, that we had our own platform. It was already up.
It was— all we had to do is buy a lot more licenses and we said the organization is required to use that for telehealth. You could certainly use other methods if you want to just have standard meetings, but for any patient care, it had to go through our standard approved process which had been vetted. We have the proper agreements under HIPAA and so forth. Yeah, well, I mean, that's awesome, Randall. I know we're running short on time here.
Any other topics that we didn't get to that you wanted to make sure we discussed? I just want to touch on branding and relationships really quickly because I feel like that's probably the biggest thing that's made me successful at Denver Health is just the ability to go to those leaders or really anybody that you interact with on the job and really set that brand in their mind for them. If you don't do that, they're going to set it for you, and you might not always like what— when they think of Fritz, what do they think of? Well, I have a specific image I want them to think of, and I intentionally try to set that with them through conversations and just updating them on the progress of the organizational cybersecurity program and building that that appearance of competence and trust throughout the organization. And that has, that has made it so that when I go to the board meetings, they don't ask me a whole lot of questions.
They, they, they do ask questions, but they don't ask me a whole lot of questions that would lead you to think that they were uncertain or not confident with our program. The last question I got was— I showed them metrics from our last third-party assessment and, and we were just killing it, right? And the chairman of the board of directors actually said, how are we this good? I mean, how are we this much better than all other average healthcare? And I said, it's because of you.
It's because of your support, the understanding from the board and from the leadership of the importance and the risk of cybersecurity. And just start, you know, your ability to allow it, you know, to even allow me to come up here and speak in front of you just speaks volumes about Denver Health. They really get it. They understand that cybersecurity risk is one of their business, biggest business risks, and you can see it. And from that, we can show the results of that.
So building that support and that the reputation and the trust is so critical to being being successful. That's great. Obviously, that to your point, it's reputation and it's also that rep, the relationships, you know, getting to know the people who are going to make you effective. I think that's great feedback. Yes, absolutely.
We're just about out of time here. Anything else before we call it?
No, I kind of want to speak real quick to the new normal around cybersecurity functions. You know, we used to have, you know, annual conference or, you know, you know, at a maximum quarterly. And now we just have every day I have 2 or 3 virtual cyber events that I can attend. And my opinion is that most of those I have not found any value in. And they're really just meeting for the sake of meeting.
And they're meeting for the sake of selling sponsorship, probably. Probably, yeah. I mean, now we have more opportunity and an excuse now to charge more, more often, more frequently. So, you know, I'm just not finding a lot of— and the things that you guys do, the Colorado Equal Security, you know, Rock has his weekly coffee chats, CISO coffee chats. Those are the things that I find the most valuable.
We're just sitting around the table, maybe having coffee, maybe having dinner, and you're talking about a topic. You know, and you're in a room with people that, that you still learn from every day when they talk and most of the other stuff just to me at this point, my career is not valuable. So thank you for what you guys do. That's awesome. Well, Randall, appreciate you being such a great part of the community.
Well, hopefully we'll get together with you. It won't be 3 years before we get you back on the show. But, but thanks for continuing to do the good work there at Denver Health. Thanks for having me, Robb. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.