Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 181 for the week of September 21st, 2020. Alex, good to see you.
Good to see you too, Robb. Any, any exciting news recently? You know, kind of same old, same old. Well, speaking of same old, same old, we have, we have some housekeeping stuff to go through here. Uh, we, we do have a Slack channel.
Uh, go join that by going out to colorado-security.com, clicking the link to get in there. Lots of great conversations, man. Lots of great conversations on there recently. Very busy. Hard to keep up with so many good conversations.
Also, uh, we have a mailing list. Did you know that? I did. I did know that. You know, every week, if you want to get the show notes in your email, you can sign up for that mailing list at colorado-security.com, and you'll get one email a week with show notes.
We would love it if you would rate us and subscribe on your favorite podcast listening app, your favorite podcatcher, if you would. Also, please tell a friend. Let them know all of the great things happening with Colorado Equal Security. Welcome them into the community. We would also love it if you want to support us even more, if you would join join our Patreon campaign.
That's a place where you can donate just a little bit of money each month to help defray the cost of the podcast so that Alex and I are not having to pay for all of it. And of course, we would also love it if you would do interviews for us on the show. We, you know, we generally have the newscast plus an interview, and having folks who help us do the interviews is quite an assistance to us. So big thanks for those who already do it. And of course, if you were interested in getting involved, send us a note either through Slack or at info@colorado-security.com.
Good stuff. One final note, Robb, we are doing a salary survey. We are getting close to closing the link to collect data on that. We've got a number of good responses. We'd love to get a few more.
So please check that out if you are in the Colorado area and would like to contribute. We would love to have your data. This is not a public survey, so it will not be published unless you contribute data into the survey. Yeah, good stuff. And we are planning to close that at the end of September.
So you really have just one more warning after this before, before it's gone. You can get there at, you can find it from, I believe, the website, also the Slack channel, or go to co-sec.co/salarysurvey.
co-sec.co/salarysurvey.
All right, let's jump into the news. This is a different one. I don't think we've ever had a conversation about this topic before. There's a story from the Colorado Sun this week around Colorado's new discrimination law or an edit to our discrimination law that now incorporates hair texture, hairstyle, hair color as one of the things for which people cannot be discriminated against. Yeah, you know, it was, I thought it was an interesting story, Robb.
Not something that we normally talk about here. They had some stats in there about women of color being discriminated against in a much larger percentage because of their hairstyles. You know, asking folks to straighten their hair when it's not naturally straight or other things like that. And so now we have the CROWN Act, which makes that a discriminatory behavior. So CROWN is all capitalized, which makes me think it's an acronym, but the article doesn't say what the acronym is, which I guess I could have Googled it, but I didn't.
Now I'm just wondering what CROWN stands for, you know, and I, of course, am particularly hair sensitive. So I think that this is a good thing. You can definitely be biased against for your hairstyle, right? Is that still safe? That's perfectly fine.
Yes, I don't believe I was considered in that. But all right, we are— it looks like, you know, I was surprised at this. I didn't, I didn't know that this was a thing. But it looks like we're actually like about middle of the road in terms of states to initiate, to have some kind of a law like this. Yeah, definitely not the first.
I think, yeah, I want to say there are 5 or 6 other states, something like that. I think I saw 20-something. Oh, maybe, maybe it was a this state, this state, this state, and a bunch more. And I missed a bunch more. Yeah, details are hard.
Yeah. So far this year, 22 states have considered— they've considered measures. Sorry. So they haven't all passed it. You're right.
There's just a few who've actually passed it. Yeah. So good on us for stamping out discrimination. All right. Next, as you might imagine, this year or this coming year, 2021 is going to be a bad budget year for the state of Colorado.
With tax revenues down. However, based on current projections, we could escape the worst of the worst-case scenarios. Yeah, so they've created, you know, a number of different budget proposals based on how bad things get in terms of how much less revenue they, they end up getting. So we're— it looks like we're actually okay for the foreseeable future, right, for the next year that we can project. So they'd come in expecting a $3 billion— well, having cut already $3 billion worth of spending.
We had a couple of pieces of good news come, though. Number one was that tax revenues came back faster. You know, the bounce back was a little faster than we expected from the shutdown. And number two, the economy was actually even better than we thought before COVID So there was more tax revenues that came in as kind of lagging behind that than they expected. Yeah, I think there were something like an extra almost $900 million in tax revenue that came in from a better than an expected economy before the, uh, before COVID So it's, it's, it's definitely— we're not getting the worst of the worst scenario, although it sounds like, you know, there's a lot of caveats here.
Um, you know, if, if we have another lockdown, if things go bad again, um, it's gonna get bad, right? Right. So, so we think that it's— we should be okay with the current, uh, uh, what are they, the reserves that we have right now, assuming that we, you know, we continue to kind of go get better and not significantly worse over the winter. Yeah, let's, uh, let's hope for things not getting better or not, not getting worse. Uh, everyone wear your masks, socially distance, all that stuff so that we can not go back into lockdown.
All right, so let's play a game, Alex. Uh, next story here. Um, Mountain Bell. Okay. US West.
Okay. Uh, CenturyLink. Okay. No, no, sorry, I missed Quest. Sorry.
Quest. Yeah, yeah. US or Mountain Bell. US West, Quest, CenturyLink, and now Lumen. Lumen Technologies.
Although I was gonna say, you know, if we're playing Jeopardy, what are companies that no longer exist? Yeah, that's fair enough as well. Companies that all sat in the same 5 buildings downtown and have changed the name in there a dozen times. What was the Saturday Night Live skit where it was, you know, You know, sort of fake Jeopardy and they, oh, they named like, you know, 4 people as who are people who haven't been in my living room.
So that was what you just did was actually a quote from, uh, it was a Cheers, it was a Cheers bit with, uh, Cheers. Clavin goes on it and he gets, oh yeah, he gets all the way to the, he gets all the way to Final Jeopardy and he's like, he's got more than twice as much as the next person. Right. And he bets everything and he doesn't know the answer, but he, he, the, the question is, what do these 3 people have in common? And he said, right, they've never been in my living room.
Right. Call, call him and let him know you've never been in my living room. Anyway, yeah, so Lumen Technologies. Yes, uh, so, uh, CenturyLink is rebranding. Uh, they've decided that, uh, at least for the, the enterprise side of the business, CenturyLink is not what they want to go by.
So now they're going to go by Lumen. It sounds like for the consumer side and small business, it will still be CenturyLink. Uh, and also, if you are one of the lucky few that can get the sort of next generation, you know, fiber to your home and things like that, then that is actually going to be a different brand as well, called Quantum Technologies or something like that. So lumen is a measure of light that's generated. So, you know, you can measure how bright a lamp is by how many lumens it puts off.
And the article suggests that, you know, this is based on fiber, which if you know how fiber works, it's actually sending light through the, through the cables. Um, so the, the big competitive advantage that CenturyLink has right now, as, as many, many consumers are moving away from DSL and trying to move to faster either wireless or cable modems, is that they have this great fiber network. So they're kind of doubling down on Lumen as their fiber, uh, as their fiber competitive advantage. Yep, pretty cool. Uh, congrats to them on the rebranding.
Hopefully it, um, is more than just a rebranding and a new start for the company. Yeah. All right. So we talked, we always, we talk about Sphero on here. I feel like, you know, every month or so, Sphero has a new product.
And it's not at all what I would have guessed the product was going to be. Yeah, it's a golf ball, Robb. You know, that's what robotics companies make is golf balls. But I'm pretty sure you're not supposed to hit this golf ball with a golf club. Oh, did I misread this?
Is this— I thought it was just a golf ball. It's a robotic golf ball. Make me much better at golf if I could have a ball like this. Basically, it's a ball that, you know, you've seen BB-8, right? BB-8 is basically just a golf ball with a head.
Well, like 2 golf balls together. So this golf ball is similar to BB-8. You can control it with your phone. You can program it to go do things. And basically you can play mini golf without touching the golf ball directly.
You're basically commanding this thing to go around through your, through your course you make. Pandemic mini golf, Robb. Pandemic mini golf. Although mini golf's probably relatively social distanced. Is safe, right?
Yeah, probably. It's outside, you know. Anyway, yeah. So yeah, so I thought that was pretty cool. It's a, I think, a good, you know, another good thing from Sphero that's, you know, kind of a kid starter kit where you can have them learn how to program something, have them, you know, figure out a mini golf course.
I think that they're having a competition as well in the— that was listed there talking about designing mini golf courses, you know, programming essentially mini golf courses for the, uh, the golf ball to compete on. So if you are either totally confused by our terrible description of this thing, or we kind of whetted your appetite and you're— and you want to actually see what it looks like, you can go into the show notes and click the link because there's a video that shows people playing with this golf ball. Or you can wait till I get mine at my house and, and I'll put a video, you can see that one too. Sounds good. All right, uh, next we have an article from the National Cybersecurity Center Talking about the risks and rewards of smart cities.
I feel like NCC has done a good job coming up with a couple of different areas to focus on in the last year or so. Obviously, election security, it's one of the big things that they're working on and online voting. And then this other one is the smart city initiatives that they've been working on and, and trying to find some— an area that there's just not a lot of great research on. And these are both areas that they could add a lot of value on. Definitely.
And this article is very long and in-depth. Uh, talks a lot about what smart cities are, um, you know, the technology pieces, why you need security in a smart city, um, as well as talking about things like, uh, privacy impacts to smart cities, right? If you are, uh, you're taking in all of these signals from data in your smart city to, you know, help trash collection and, um, traffic and things like that, well, you know, you're probably gonna have, uh, some data that could be used to identify people in there. So you have to be considerate of that as well. Yeah, I love the fact that they're thinking about these things not only through the functionality perspective, but the privacy and security perspective, and really helping build this up at the beginning.
And, you know, they start off by talking about what are the benefits and values of a smart city. So if you wonder, why would I want this anyway? Well, maybe take a look at this and maybe you'll think that it's worth doing. Because it's smart, duh. Duh.
All right, next we have an announcement from LogRhythm. This is actually sort of a third-party announcement, Um, one of the, uh, managed security providers that uses them has acquired, um, another company to help increase their LogRhythm experience and aptitude. So this is the first time I think I've ever seen a third party do a press release. It's a press release about 2 other companies that, what, you know, another company that's acquired another one. It just, it's kind of weird.
But anyway, the, the company is Avertium. Uh, they are an MSP that I guess mostly specializes in LogRhythm. Yep. And, and they have bought a company called, uh, 1440 Security that, that's going to actually get them more in-depth LogRhythm experience. Why are we talking about this here?
Well, 1440 Security does have a Denver SOC. Um, so there's, I'm sure that there's some folks, I hope there's some folks listening from that company who are like, yes, that's us. And hopefully it's good for you guys. I'm, I'm hopeful. And, uh, and of course it's also LogRhythm related.
So a lot of Colorado connections here. Yep. Good stuff. All right. Next, Coalfire has released their 3rd annual penetration risk report, and they have some surprising new trends, Robb.
You know, some of the stuff that's not surprising at all, they, they do show, they do have a couple bullets here, but one that's not surprising is that loud— large cloud providers have seen a lot of security gains over the last year. They are 46% less likely to suffer a data breach than large enterprises. Uh, which I, that doesn't surprise me, but I think it's worth putting near the top like they did. Yeah. I, I think, um, you know, cloud providers have matured and realized, hey, we can get rid of, uh, a lot of this low-hanging fruit that people are getting compromised from pretty easily.
So many of them have done that. Another surprising, not surprising finding is that phishing is the number one way to get a breach. 60, 61% of phishing attempts. Well, wait a second. 61% of phishing attempts result in full compromise of access credentials.
What is that? I wonder what, how they mean by phishing attempts, like year-long campaigns. Yeah. I don't know. Or 61% of emails sent out.
That doesn't count for me. Well, I mean, no, keep in mind that this is from actual penetration tests that Coalfire has done. So I'd imagine as part of their penetration tests, they are doing phishing to try and get credentials as part of the penetration test. So it sounds like 61% of the time they're successful. Man, that's scary.
It, it is scary. Um, I guess not. Too surprising. It may be a little high though, maybe a little high. I don't know.
Um, I guess it depends also on how they're doing that, right? You know, if you and I are doing a phishing campaign, we're probably testing our entire employee base. Uh, since they're doing penetration testing, my guess is that they're probably being a little bit more pointed. So who knows. Um, but, uh, you know, insecure protocols dominated the top vulnerabilities again.
Not surprising. I think we all know that there are still a lot of insecure protocols that are out there. So the other thing, uh, they do break the report down into, uh, verticals as well around compliance and things like that with FedRAMP and PCI. So, uh, I think one of the nice things about this report is you can sort— you can take it and look at what it is that applies to you. You know, um, you— PCI does apply to you, um, you know, what sector, segment, things like that.
And you can figure out what it is that was most successful potentially against you. All right. Next article we have, I love the fact that we can kind of go across different areas of security and different disciplines. This next one is by David Stauss, who's a lawyer and talking about compliance, specifically talking about what US companies need to know about LGPD, which is Brazil's new data privacy law. Oh, I was going to say that that was the new acronym for, you know, non-heterosexual people.
LGBT, non-cis. Is that the— I think that that's probably right. I think that's what they call it. Right. Um, so this is pretty interesting in the fact that I was not particularly aware of, uh, the Brazilian privacy law, but it sounds a whole lot like GDPR.
It does. Uh, I think, you know, because Brazil is, is less, well, much smaller than all of Europe and is, uh, has less of an economic powerhouse behind it, it's got a lot less news, but it is just another big nation that is, uh, is pushing us toward a more privacy-centric approach to data. And of course in the US, you know, I'm hoping that it kind of pushes us towards doing something federally as well. Yeah. One of the other things I like is that this blog is very detailed.
So David goes into all of the different areas of the statute itself. So if you want to look at it and figure out the differences between it and GDPR, if you are familiar with GDPR, then you've got a lot of the information in there. I love it. Our next article is another Red Canary blog, and this one's a— it seems like there's been a lot of threat intelligence stories recently. Yeah, this— but this one is nice because it really kind of gives you a place to start, not, not as a company, but as an individual.
How do you build your career around threat intelligence? Yeah, and I thought that was an interesting spin on it too, um, because, you know, most often when you're thinking about things like this, like the Zvilo blog last week, it's talking about actually collecting cyber threat intelligence and things like this. This is more about how you get your skills and then can make that into a career. Um, starting off with, you know, she— I just— I'll say she has 4 big categories of tips. There's a lot more data underneath these, but worth kind of giving you what those tips are.
Number 1 is that cybersecurity experience is not required, but hard work and curiosity are. You can teach yourself many of the concepts of cyber threat intelligence. When you're trying to get a job, apply to all the jobs. I guess she's saying don't be targeted. I don't know if I agree with her on this.
I personally think You know, it doesn't hurt to apply to lots of jobs, but you're much better off figuring out where you want to go and then getting a relationship with someone over there and getting to know them and ask questions. And they all of a sudden go, oh, this person's interested in our company. And it'll make it much easier to go from applying to actually getting an interview. Um, yeah, I can see that. I think it depends on how much you want to get an actual job.
Is it— are you looking for your dream job or do you need a job? If you're just trying to get a job of course apply to all the jobs. But if you want to get a good job, figure out where a good job is and go meet those people. Go to the Slack channel and meet them. And if you want to do that, then you should do number 4, which is network.
Network people. We're not talking about routers and switches here. We're— no, we're talking about beers and Zoom meetings. Get to know people. Yeah, sounds good.
And then our final blog for the week. We talked about the Coalfire blog last week. Uh, or maybe even the week before, um, about their Women in STEM program. But this is a Webroot blog celebrating, uh, women in STEM at Webroot and around National Coding Week and IT Pro Day. Um, I thought this was interesting.
Um, you have some quotes in here from, uh, folks at Webroot, um, women at Webroot who are, are in the industry. And also I noticed a little snippet at the end of the blog talking about how Um, Webroot and their parent company OpenText is part of the initiative to ensure that there are 30%, uh, women on corporate boards. It's awesome. I do love to see the, uh, kind of showing off the, the women who are— who've been successful in these tech companies as it becomes a great example for girls and, you know, the next generation coming behind them. The, the more companies who are willing to do this— Coalfire's done a good job and now Webroot— I think the better off we're all going to be and the next— how the next generation is going to be more interested in doing this.
For sure. All right, so that's the news. Let's move on to the Slack message of the week. Thanks to Andre Gaeta for sponsoring the Slack message of the week for us. He's been doing this for an awful long time, and we really appreciate that.
So thanks, Andre. And this week's winner of the Slack message of the week is— it's Telecon, also known as JC. JC is one of the volunteers who did a ton of work to get the Denver B-Sides conference off the ground and running. I don't know if you got to attend. I got to attend some of it on Friday.
It was It was good. It's always great to see, you know, that, that little bit less formal approach to security that you get at the cons like that, and to see a lot of, a lot of local folks involved. Awesome. Well, congratulations to Telecon. Um, you'll be able to pick an item from the Colorado Equals Security swag store and, uh, show off your love of everything Colorado Equals Security.
All right, let's jump over to our calendar of events. As a reminder, on the website you can go out to see what's happening over the next 6 months or so. But each week we just go through the events happening in the next 2 weeks. So you don't have to even click on that if you don't want to. First up, ISC2 Pikes Peak is doing their September chapter meeting on the 23rd.
On the 24th, Colorado Springs has the ISSA chapter— Colorado Springs rather— has their September online series meeting. On the 25th, DC303 is doing their September meeting. They do those on Friday nights from 7 to 10 PM. So You can't say that most people's work's going to get in the way of that. No, probably not.
On the 1st of October, NCC is doing an election interference and data breaches webinar. Cool. And then on the 3rd of October, ISACA Denver is doing the ISACA Community Day. Yeah, they're going to actually go out to a park in Denver where they're, where they're removing flowers, turning the soil, basically getting it ready for winter. So if you want to steal some flowers for a park, this is your time to do it.
Good stuff. All right, let's go ahead and jump over into jobs. We have some interesting jobs this week, uh, starting off with one we received from Debbi Blyth, the CISO for the state of Colorado. She emailed this to us. She is looking to hire a Director of Security Operations.
Yeah, and this, uh, this job will, uh, excuse me, will report directly to Debbi. So if you want to work directly for Debbi, this is the job for you. Uh, next, Sunrun is looking for a Director of Security and Compliance. Ibotta is hiring a Head of Information Security. I have to say, I was a little disappointed to see that Ibotta, which is a pretty good-sized tech company, this position is reporting to a Director of Infrastructure.
It's probably not where it should be. So I— if Ibotta people are listening, yeah, you might want to fix that. Yeah, good idea. Optiv is hiring a Director of Security Operations for their managed detection and response service. Marathon TS is hiring a Security Director/Architect.
Ignite Mental Health is hiring a co-chief information security officer. I'm not sure exactly what that is, but I put that other part in there later because it's part-time, remote, and volunteer. So it's, it's not a real job, but they— I'm sure that this is a nonprofit. I believe this is a nonprofit, and they're just looking for someone to help them, you know, not let people's data get stolen. That would be cool.
Praetorian is hiring a VP of Services. The Motley Fool, which is like a an investing stock tip website. I had no idea they had a presence here in Denver. I didn't either. They are hiring a security engineer.
Venmo is looking for an information security engineer 3. I don't think I knew Venmo was here either. Well, Venmo is owned by PayPal, and I know PayPal traditionally has had some people in Denver, so I think that's probably a connection with security people though. Yeah, huh. What's— anyway, a couple of interesting companies here.
Uh, finally, Dish is hiring an information security risk management lead. Cool. That sounds like fun. All right. Well, that is it for the news.
We do have an interview this week. I sat down with Matt Shufeldt. Uh, we had Matt on the show. It was like 3 years ago when he was the— maybe 2 years ago. No, 3 years ago when he was, uh, one of the CISOs, CISO of Cognizant Healthcare in town.
Since then, he's moved on to new stuff and we get to talk about that here on the show. Awesome. Should be fun. All right, everyone have a great day and we'll look forward to talking to you again next week. Thanks, Robb.
This is Michael Stephen. Privacy Security Officer for Connect for Health Colorado. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is our interview this week. I'm getting to sit down with Matt Shufeldt. Matt Shufeldt. Matt, I actually don't know your title now.
I'm gonna let you tell that story. I know you've moved around since we last had you. We were just talking that You were on the show back in 2017, 3 years ago. At the time, you were the healthcare CISO for Cognizant, which, you know, had been Trizetto before. So a lot of folks in town here know Trizetto as a, as a kind of a long-term Denver tech company.
Yeah. Um, you know, it's been a long time. So why don't you talk to me about what's happened? You know, 2017, you were here talking about what you were doing at Cognizant. You know, how— tell me how that ended up, and, uh, let's go from there.
Yeah, so, um, I think last time we spoke I was about a year, year and a half in. I had built up the team, uh, hired quite a few local folks to, to come on board, and, um, the role just kept growing. So it did start off as just Trizetto, but we actually acquired more healthcare companies, uh, as we went on, and there were other parts of the healthcare vertical that weren't previously being managed centrally. So that came over to our team as well. So all that to say is the role continued to grow, continue to grow, and all of it was going very well and continued to go well.
So my typical nature, and you've known me for a while, is I tend to take on any and every challenge that I see. And so as my role started to grow and the team fleshed out in healthcare, we actually looked at what we were doing globally. So I was helping out with several global initiatives such as our, you know, global compliance-related initiatives, our M&A practice, and doing assurances for that. And basically there would be new, new pet projects that come up as all companies have. And you can imagine the size of Cognizant.
They have a lot of those different pet projects. And I continued to take on more and more and more. And eventually I found that I was really enjoying the success we were bringing. As a team, and I was very driven to help with all of it. But I did find that I was kind of burning through my own reserve as far as my ability to keep, keep going at the energetic level that I think that you always should be.
I said something in our last interview, I think around the lines of, hey, if you're burnt out, like, don't stay because you're not going to do anybody any good. And I wasn't at burnout yet. But I didn't want to get to burnout. So several months before I decided I was going to go do something different, I actually had a great talk with my boss who was the global CSO and just said, hey, I want to do something different once we get through these next set of projects. And so we did.
We got through those next set of projects. I said, hey, I'm ready to move on. I'm going to go do this other thing. And he basically said, oh, you're serious about that? I said, yeah, yeah, no, I'm serious.
No, no, no bad tidings at all. Like, I got to help kind of flesh out the strategy for, for replacing me and other functions that had grown. And, and all of that went well. And so I decided I had never, ever taken time off ever since I was a teenager. So I decided, you know, I'm going to take like up to 6 months off.
And I remember talking to you and James and a few other folks about it at one of the award dinners. Yeah. And I made it about 2 months. I made it 2 months and then I got recruited. It was over December, so you had the holidays, so it felt like maybe you'd be able to make it a ways in.
But as soon as you started— I mean, I feel like even when you started taking the time off, you had a few companies that were talking to you about various different things, right? Not going somewhere necessarily as a CISO right away. No, that's true. So Uh, and I picked up an advisory gig that could have turned into something, uh, just, just to keep myself busy. I figured out a weekend that me having nothing to do professionally wasn't great for my sanity.
Yeah. Um, so yeah, no, I definitely kept busy. Um, I want to pause though about on the burnout stuff. Yeah. You know, I think that I think every security person and probably everyone in other fields, but we're talking to security people.
So every security person, I think feels a level of frustration and futility sometimes. And I, while I think that those might be symptoms of burnout, I don't think that they always are, right? So, I would wonder if you have any insights on like, what does it mean when someone feels burnout versus just someone's having, you know, someone's frustrated by inability to get some stuff done in the short term? Yeah, I think it's a matter of a blend of What's your job satisfaction looking like that fuels your engine? What's your work-life balance look like?
And that's different for almost everybody. Yeah. Like, what do you need to, like, still feel recharged occasionally to get that going? And work has always recharged me. So what I'll just tell you for my own self is that I figured out my limit.
Like, I had never hit my limit before, and I'm like, oh, I took on a bit too much. Go to a big enough company and there's a lot of work you could take on. That's right. Yeah. So, you know, I wanted to prove I could do something like I had done previously at a global company.
I did that and then I'm like, well, I can do more. And eventually I looked up and went, oh, I'm doing too much. And I'm not one to— I'm not one to then just bail on things. So I came up with a plan on how to mitigate that for myself. And part of mitigating that for myself was having like an end.
Yeah. It's like, okay, I know I'm working towards something. And once I have all those things cleared up and I have satisfaction that I did the job I said I was going to do, then I can go do something else. Yeah. And it must— there must have been a realization in there for you that, you know, running security programs for, you know, a hundreds of thousands of person kind of conglomerate.
I don't know if that's a fair word for Cognizant, but it feels like they might be. Like that might not be your ideal end state for a job. Is that true? No, it's totally true. I wanted to prove I could do it right.
I definitely wanted to do that. Honestly, I find, and I think you and I have had versions of this conversation in the past, I find that you can make the most significant difference in security at the large end of small-medium business and the lower end of large, right? Because you have funding. And it's not so big. The business isn't so big that it changes constantly and is so expansive that you can't, you can't do everything you want to do all the time.
Yeah. And you can especially, you know, someone like you who I think likes to be very involved in the details, you know, you can still know the details when you get to the, you know, if you're the CISO for Kaiser or Bank of America, there's just no way you can know all those details. And, and I think my guess would be for you, you know, there are so many cycles that you're thinking about as the, you know, because you have such a broad ownership in that large company, you're trying to think about all those things to such a level of detail that you just, you know, that's probably taxing in and of itself. Yeah, it was. I felt like I managed it pretty well because I've always been very program-focused.
So, I created mechanisms fairly early on. You know that I'm a big believer in building out security PMO and all these different things that allow you to scale. So I had built those things out for the areas I was responsible for. So I felt like I was still able to be in the details. But then there's another step, right?
It's like, I'm pretty good at not having people have to do the things the way I think they should be done. But at a certain point, you have— you've expanded across so many different leaders. So I had a lot of different leaders underneath me, and they were all fantastic, but they're all going to do things slightly different than you and slightly different than each other. And I did things slightly different than Central Cognizant, but we always were talking about how to align. So those kinds of differences, it's still very satisfying and everyone's going after the right thing, but at some point you lose your own kind of artistic vision for— hopefully that's not overstating it, but I like things to look a certain way.
Right. And you just can't do that across that many different leaders. It's a challenge, you know, this enabling and empowering of leaders underneath you, but then still having a vision for what your security program should look like. I run into that, you know, on a scale significantly smaller than that. But, you know, a 30-person security team, you know, I see things in one way and I have a director underneath me who has a vision that I don't necessarily see all the time.
And so there's always that kind of push and pull, like between I want this leader to own his function, but I have a vision for it as well. There's a balance. But to your point, like, it's just, it's a lot of back and forth in that, in that case. Yeah, absolutely. Yeah.
One of the things that was really helpful is that I can legitimately say that the leaders that reported to me cared about my well-being and cared about the people underneath them, and my leadership cared about my well-being. And that makes a huge difference. Yeah. Because if you have a leadership structure that doesn't care about each other, that can break down and become, become bad pretty quickly. Yeah.
It becomes toxic. Okay, well, great. Thanks for diving in that a little bit. You know, I know you left Cognizant, you took a couple months off, you, you know, you were fishing and golfing every day, I'm sure. And then after you decided, you know, you got it, I think you had a couple opportunities.
Talk to me about how you ended up going to EVOTEK. Yeah, so it's kind of a cool story. I basically had decided I was gonna take up to 6 months off, and I figured it would be around, you know, the 4-month mark that I'd probably start looking in earnest. And I had companies talking to me right away as soon as I was available. And really those companies, it was a blend of like there was a technology startup I was helping, you know, as a strategic advisor.
There was a couple talking to me about vCISO services because I actually really did want to do vCISO services. I thought that was a need that was out there, especially in like the SMB world. And eventually what ended up happening is a coffee appointment I ended up taking as nothing more than a favor to an industry colleague was with Susan Bullwinkle, who was starting up EVOTEK in Colorado. And my buddy just said, hey, do you mind just meeting with her and telling her what you think the landscape of security looks like in Colorado? And I said, yeah, that's fine.
So I showed up for coffee. Well, The CSO for EVOTEK was with her. He actually traveled out here from San Diego, was taking appointments. And so he came along. We ended up talking the entire time.
Poor Susan didn't get a word in edgewise. And by the end of it, he's like, yeah, you need to come on board. And Susan's like, well, I really want to get to know him too. And I'm like, well, I didn't realize this was an interview, but let's keep talking. And so I did get to have a follow-up lunch with Susan where we got to know each other, which was great.
And then I found out, you know, just everybody that I talked to at EVOTEK was like super passionate and really, really cared about the company growing. And the fact that it was all private backed, like no outside investment, all of that just sounded like a really great situation to try to get into and see if I could do the thing I wanted to try to do, which was that vCISO kind of engagement. Right. So before we get into what you were hired to do for EVOTEK. EVOTEK.
It's EVOTEK. I keep— I know, no, everybody. I always want to say EVOTEK, but it is. It's like evolution. It is EVOTEK.
Yeah. Yeah.
Before we talk about what you were hired to do, talk about what the company does in general. Yeah. So, you know, it grew up with 2 kind of sides to it. So it was a system integrator services company with a VAR component to it. So basically across multiple different practices.
So your traditional like data center types of practices or networking, mobility, cloud, and then security, of course, there basically is this— sorry, there's a services arm and there's a reselling component. And that's evolved since I've even been there. So now it's become much more fused. It's no longer, hey, I just came and advised you on some stuff. By the way, let me introduce you to my sales partner because they might be able to fulfill your needs.
Yeah. And now it's much more of a structured approach. And, you know, we really talk about things upfront and what our intentions are upfront all the way through. And I'd say that the way the business has grown is we've added components since I've been there as well. Like, you know how important architecture is to me.
So We added security architecture when I was still in the security practice because we just found people weren't architecting things appropriately. And we've modified a couple practices since I've been there and brought a few together. So as a company, there's the 2 sides, which you said is services and then there's reselling. And you were brought in to do what? The services side.
So I was definitely brought in to do virtual CISO services, which when I first joined the company, uh, was more about doing assessments and some light advisory. Um, so assessments with very specific, uh, ends, uh, such as, you know, full program assessments or an assessment on a specific part of your program, like your AppSec program. Um, and it's evolved quite significantly since then. Uh, so it's very advisory heavy and the assessments are still there, but we have a lot of running ongoing advisory engagements with clients now. So you were brought in to do these assessments, which you said, like you said, were mostly point-in-time specific deliverables, and now it's turned into ongoing engagements.
So that was what you were brought into, and tell me how that went and maybe how you've seen it evolve since then. Yeah, so, well, it couldn't have gone better. I'm super excited. So basically, not only did I end up engaging with multiple clients that I've now been a vCISO for, for, for a year or more. And some of that is with existing CISOs.
Some of that is with IT leaders. So now I have regular weekly engagements with all of them, helping them kind of move their programs forward, helping them with situations that just pop up that they don't know how to deal with, honestly, helping them with the business side of running a program because honestly, a lot of folks in our industry didn't come up with any kind of business background. Right. And so helping them with that, we've also, like I said, built out new security architecture capability. So now we do multiple— we have multiple architects on board, multiple architects as a services engagements, and as well as the engineering part has grown as well.
So the security group has grown pretty significantly just in the last year. Because of that. And we've actually hired more Colorado people than any other region in the last, in the last year. So 2 years ago, Susan came on roughly 2 years ago, maybe a little bit less than 2 years ago. And you were employee number 2 in Colorado.
Is that true? Yeah. After Susan, I was— I was number 1. She was number 2. And how many do we have now here?
We have 12. Well, that's pretty good growth. That's great growth. And most of that's delivery. And I know Michelle is a sales rep in this, in the territory.
Is there any other sales here? Dan Wood. I don't think I knew. Ah, maybe I knew Dan came there. Yep.
Yeah, interesting. Dan was a longtime Optiv guy. Yep, Acuvant before that. Optiv guy. So you got Dan and Michelle and Susan, um, and then the rest is delivery then?
Yep. The other 9 people, yourself and architects and engineers? Yeah. Yep. That's great.
Uh, and how has your job changed in that time from, from just doing VSO, VCSO work to what else you doing now? Well, so, uh, there for an interim period, I actually was in charge of the security architects. As well because I built that piece out. But now we actually have a full-time leader for them, so I've phased out of that. And 2 and a half, 3 months ago— everything's kind of blending together right now because I'm doing 2 jobs, which you were just doing recently as I remember— I actually got our newest practice.
So I'm launching and have launched our newest practice, which is called Digital Platform Solutions. So previously we had a cloud practice and we had a platform engineering practice, and the platform engineering practice was more of your like DevOps SRE type of work, and the cloud was really about cloud partnerships and, and structuring cloud engagements with partners. Yeah. And so, uh, one of our leaders, uh, moved on, and so the senior leadership team started talking. They asked my opinion because I partnered quite a bit with both, both groups, and I said, well What I think we should do is put them together, and on top of that, I think we need to add enterprise architecture as a key component because most of our clients don't do enterprise architecture well or at all.
And frankly, our engagements are going to get so much better if we're actually doing proper, like, requirement solicitation, capability modeling, and all those pieces, and then it will lead into the other practices as well. And it kind of brings it all together because as a client, you shouldn't have to care that we have 3 practices or 4 practices. It should just be about, you know, doing the right solution. Here's a problem I have, help me solve it. That's right.
So I've taken over that practice, um, and so I've been doing that, uh, and still taking care of my existing security clients. Um, but I'm very, very excited. We actually, uh, had my backfill on the security side. A CISO out of the Bay Area just started with us on Monday. So are you moving into the, the new— this new practice full-time then?
I will be, yes. Wow, you're not going to be doing the vCISO work then? Well, so I have, I have, uh, at least one client, uh, who basically said, hey, I, I, I, I definitely like everything that EVOTEK does for me, but I'm with you guys because of you. Okay. And so I will probably keep at least that client as a vCISO ongoing.
Be nice to keep your— keep a little bit of a foot in the water there to So you stay in that world, right? Well, it'll always be like very close to my heart, as you could probably guess. One of the things I'm excited about though is then in the new practice, I can actually build things the way I think they should be built for clients. And then, you know, and obviously in our CISO world, we influence how things get built. We influence how things will ultimately be structured.
So having the background that I have and then getting to actually build build good solutions for clients is pretty exciting to me. Yeah, that's really cool. And is your— is your team— this new practice, is it distributed all over the country or all over the world? Are you mostly in Colorado? Where's your team?
So none of my new team members are actually in Colorado yet, although I am working on one. I can't say who it is yet, but I'm hoping my first hire— because I had existing team members obviously when I took over the other practices. So my first hire will most likely be here in Colorado. Okay. And it's gonna be on the— sorry, I'm gonna back up and tangent for a second.
You know how I've always liked to hire people that can do more than one thing? Yeah. As opposed to super specialists. Yeah. So I'm looking for people that can do 2 of the 3 major components.
So out of the EA, the DevOps piece, and the cloud architecture piece, I want somebody who can do at least 2 of the 3. So The, this first hire that I'm looking at is actually a very talented DevOps, DevSecOps engineer and has a really strong, uh, cloud background as well. So I'm, I'm excited to go after it. That's a hard skill set to hire. It is.
It's good. It's going to be tough to find. I mean, every company, you know, has a few that they, that they love and don't want to see go. So it's going to be hard to get them and expensive as well. What's funny is, uh, a couple of my existing people that I think are just amazing, are so well loved by one of my clients that's very big.
Yeah. That I can't really get any time other than them working on that client, which is a great problem to have. But yeah, you're, you're so right. Yeah, those are— that's a tough skill set. So glad you have an eye on someone.
Hopefully you can, hopefully you can land that plane. I normally land the plane pretty, pretty well. Uh, well, good. So what do you see in terms of— obviously you're building out a new practice that you're confusing some, some important disciplines together. Any other thoughts about like what is next for Matt?
You know, if we— if you look forward in 3 years, you know, you run this practice for some amount of time and I assume then you help set up another practice at some point. Like maybe I'm putting words into your mouth, but where do you see the future going? No, you know me pretty well. I, I would say that I don't like to pick a destination. Yeah, I, I have new people to learn from and new, new things to learn.
In this new role, as well as I've learned from, I would say, a completely different part of our industry over the last couple of years. Like, I wasn't very familiar— like, obviously Cognizant, I had good exposure to the vendor side of things, but this is very different. And being able to think about it from a pure consulting point of view has taught me a lot, because all my previous consulting, I was still doing a full-time job and doing consulting. And so I know this is a very long answer. Sorry, you wouldn't expect any less.
I just want to keep learning. And so if I get really good at this practice, my natural inclination is going to be to try to groom somebody in the practice to take it over and do something else. And hopefully within EVOTEK, because I really love EVOTEK's culture. It's, it's, it's probably the least constrained I've ever been in my entire career. So that's pretty exciting.
That's pretty great. Yeah.
You know, kind of totally changing topics on you. When we talked 3 years ago, you told us about how you had recently picked up lacrosse. And if I remember correctly, during our conversation, you told a story about how you had identified a coach from the Outlaws. Yep. Yeah.
Who had come and coached you guys. And, you know, you got a team of folks who had either played it never before or, you know, very, very little lacrosse. Yeah. Did you stop playing? Are you still playing?
How has the pandemic impacted that? So the pandemic did, did cut one of our seasons short as everyone was trying to figure out what to do. Colorado hadn't yet set what the rules would be. Yeah. And outdoor sports did come back up a couple of months in.
Yeah. And basically our first season back, we played what's called 7s. And so instead of 3, 3, and 3 and a goalie, So, you know, defense, mid, and attack and a goalie. We had 2, 2, and 2 and a goalie. Okay.
So it made the field more wide open. More offense. A lot more offense. And I play defense, so that was painful. A lot more running for me.
But it, but it felt so good to get out there and do it again. And we just started up a new season a couple of weeks ago. Now we're back at full numbers. Okay. And the season is going really great.
Yeah. And we still use that coach. Oh, yeah, yeah, yeah. Do you mind if I give him a shout out? Of course, please.
So Chris Spangler, who is the strength and conditioning coach for the Outlaws, has hopped in and coached us at multiple points and has been so friggin amazing. Like, he's so awesome. And yeah, it's funny because we also randomly get to work out with other Outlaws and former Outlaws. Like, they just show up sometimes. So that's been pretty cool.
So do you guys do consistent practices in addition to your games? When the season isn't going, we do practices. We don't normally double up. One, I'm too old and I don't know if my body could handle that. I see.
Yeah, sorry. No, it's okay. Go ahead. I definitely get it. I have recently realized that my body is no longer able to do as much working out as I want to.
Yes. Yep. No, but it's been a blast. So when you guys practice, Like not the non-games. Sometimes some of the Outlaws will show up.
We—it's not like multiple show up. It's like we've had random ones. Yeah, show up to different practices. Yeah, that's pretty cool. Yeah, yeah, it was really neat.
And like I said, Coach is just phenomenal. Like he's—he's—you can tell that he teaches at all ages. Yeah, and it was funny because we were so bad when he first started helping us because he can remember we were all brand new to the sport. Yeah, that you could tell he was teaching us like he. Teaches like the peewees.
And then he would check himself. He's like, oh, these are full-grown adults. They just— they're just terrible. But he never said it that way. But no, we've come a long ways.
Like, we actually— we actually just won a game this past weekend against one of the tougher teams in the league. And it was hard and it was fun. It was— it was great. And you're playing people who played in college and stuff, I'm guessing? Oh, yeah.
Yeah. So some— some were like scholarship players, right? A lot of the people that were— so I think I mentioned to you earlier, there's a Masters division, which is experience or age. So if you're under a certain number of years experience or you're older than a certain amount, you play in the Masters division. So we've always played the Masters division.
Okay. And the people that were really tough were playing in the what was called the Young Guns division, which was the which was all the guys like straight out of college. Okay. Well, since the time that we started playing against the Masters Division, the Masters Division steadily gotten much, much harder because people are aging out of the Young Guns Division and those people aren't any worse than they were before. Yeah.
And they never stopped playing, so they're still super fast and everything else. So yeah, most of these guys that are like from the East Coast, they've been playing since they were 8 years old. 8 years old. Yep. Kind of like me with football.
But yeah, it's crazy. So, so you're enjoying it and you have— you're still walking, so no massive injuries yet? Um, nothing, nothing terrible. Uh, honestly, there was about a year period where, uh, my Achilles was messed up enough where I was never fully running, if you know what I mean. It was more of like a dragging yourself along at a quick rate.
And I've finally recovered from all of that, so I'm feeling good. All right. So another topic I wanted to make sure we talk about is a question you usually ask, but I'm the one with the mic, so I get to ask the questions. Fair enough. Usually you ask, what are you doing to help with the next generation of security talent or some other variation of that question?
And I'd love to hear what you've been doing since you're out of the CISO role and into this kind of vendor side. Is there something you're doing there to still continue with that mission? Yeah, I'd like to think I am. I think I could always do better. Uh, but, uh, during my time off, uh, you know, I went to SecurSet.
I've been trying to push people towards like going to trade schools to get people in. I try to recruit every friend I have whoever like contemplates a job change. To be clear, when you say you went to SecurSet, you're not saying you went enrolled in their program, right? Oh no. What did you do?
No, I just went and spoke to the students. Yeah. Um, I, I, you know, every program has flaws, but I always appreciated what, what they're trying to accomplish. Yeah. You know, when I was at Cognizant, we hired folks from SecureSet, and I've now had friends go through their program and now work in security jobs, so that's been great.
I've hired 3 or 4 folks from SecureSet, and, you know, while the education certainly does not give you a whole background in security, it does make you better able to have the conversations, to understand, you know, what are the main themes in security, and really be able to just participate as an active part of any conversation on security. I agree. Yeah. And honestly, it's like every other field. It's like, well, are trade schools more valuable than going to a full college?
And they're different, right? Like, the fact is, if you go and you get full-stack education as a developer versus going to a trade school as a developer, you're probably going to be a better developer if you got full-stack training, but you're not going to be making money as quickly and you're not going to get real-life experiences quickly. So no, I definitely think it has value. So apart from that, you know, of course, we've been trying to do learnings and webinars with our clients. We've done a couple online as well, with a couple of partners.
But I still see it as the— like you say, I ask this question all the time. I still see it as a massive problem. And I still see folks having entry-level positions requiring 6 years of experience in a CISSP. I mean, yeah, I always wonder, like, I have so little respect for that play, whoever does that, that I almost like leave them out of the conversation. Like, they're just clearly not paying attention, right?
So it's the— I think that there are a lot of people who do try, who don't have entry-level positions that require experience in CISSP, but we still have a problem, right? And there's a problem that's Number one, like the, there's just not enough people, supply versus demand. And you could, you could argue whatever, whatever way you want to go, the demand's too high. So we, maybe we need to do less manual work. Maybe we need to do more automated scalable processes, embed more things within business units.
I could, you can make that argument. Yep. I don't think that it'll solve all of it. You know, we're talking about trying to, to work on the supply side. So try and, you know, make more security professionals, but You know, it doesn't feel like that's worked.
Like, it doesn't feel like we brought enough people in to get there. There's got to be, there's got to be some combination of those. And, and maybe the way, you know, the fundamental technologies that we're trying to secure maybe get a little bit better as well. I think you, I think you just touched on 2 of the most important points, which is we need to change how things are being produced because things are produced. And I'm talking about software, I'm talking about end-to-end services.
Things are produced so inherently flawed from a design perspective. That's why we have to do all these extra activities, and that's never going to go away either. But I think we need to attack all those angles. I think appropriate architecture— there's not enough architects, there's not enough builders and designers in our world. We have a lot of people that are very attracted to the offensive side, which makes sense.
I mean, That's the super cool, interesting piece. But that side is never going to be— it's always going to be useful and needed, but it's never going to be revolutionary. Right. It's going to be modeling themselves after other attackers, modeling themselves after different behaviors. And there's a few incredibly gifted folks in that area, don't get me wrong.
And by a few, I actually mean quite a few. Quite a few. Yeah. But that's not going to change the level of vulnerability. Yeah.
Like we have to design and build things better. So I do think attacking it from that point of view is good. I also think that we've kind of gotten away from the basics. Like I use the Top Gun analogy all the time that, you know, Top Gun being invented because, you know, after Vietnam, people lost the ability to dogfight because they have missiles. Yeah, it's the same thing with how our engineers and our admins and et cetera, they don't know their platforms cold anymore.
A lot of them, they're Googling all their answers. It's so easy to get information that I think people have lost kind of the institutionalization of that information. And I think that's made us a little weaker. And I would say on the security side too, if you are a full-time you know, talk to a local company. If you're a full-time LogRhythm admin, you probably know LogRhythm pretty well.
If you're a person who owns LogRhythm and Palo Alto and Ping Identity and Webroot and whatever else, right, if you own all of these different technologies, you probably don't know any of them very well. And that, that's the, the, the challenge with generalization and adding more and more tools into your tool stack. You know, you start turning over old tools and now everything's kind of new and you're more of a you're a Google jockey instead of an expert. Yeah. And you and I have differed pretty much continually on, on this point a little bit.
Okay. Not, not fundamentally. Like, I agree with you fundamentally. Like, if the individuals are not investing in their knowledge, they are not going to ever be good at those toolsets. Whereas if you just work on one tool, you have to get good at that toolset.
You can't— there's no— very few companies have enough people to have one person per tool. That's, that's unrealistic. So, so I do think that really talented super generalists, and I say super generalists because they need to be deep, like they need a fundamental understanding of technology, and then they need to learn a couple of platforms that are really important to their environment, right? I think those folks are more valuable than anyone. Yeah, I think that the— you have to figure out what is the fundamental thing for your environment that they have to know.
So in a, you know, Ping, for example, you have to understand how AWS works and how Linux works. If you don't, if you can't do those 2 things, you probably don't have a good spot on the technical side of the security team. Now there's the product security side, which you don't need those there. And there's the GRC side where it's important. But if you're gonna be one of my infrastructure security people, you have to be good at those things.
And so understanding what are the fundamental technologies for your organization, that's essential. And maybe you can teach it, you probably can teach it, but it has to be someone who's passionate and eager to learn. No. And I'll tell you, probably I've had a lot of folks that I've loved that have been on my various security teams over the years. And I would say that probably 60% of them were crazy passionate about being really good.
And those folks, even though they covered multiple things, I felt were very good in the areas they touched and where they weren't, they were very transparent and they worked well with other groups that did have those deep dive skills. Kind of like, I think you and I talked many, many years ago about how SIEM was really a data science problem. And we were basically trying to throw network engineers at a data science problem. And so we partnered with our BI team to try to get better at that. And I think if we eliminate a lot of those silos and kind of take that kind of original DevOps point of view where there shouldn't be a DevOps group, right?
There should be like partnership across different teams and that you understand each other's weaknesses and strengths and you reinforce those things. Yeah. I think one of the things that you and I have talked about, I don't know, dozens of times over the years is around SIEM. And I have a kind of a visceral negative reaction to SIEM, not because of— there's an important security operations function that SIEM is part of. Yeah, but because SIEM in general makes it simple stupid to do the wrong thing.
Like it's so easy to just go spend all your time chasing after false positives once you put a SIEM in place. And so, you know, I come about it from a side that says I would rather see us create, you know, now we call it a data lake, right? In the past, I would have called it a log repository. Right. You know, now it's a data lake.
Now we create a data lake and I'd rather see us say, all right, we have all these logs here. Let's go identify the top 10 things that— bad things that could happen in my environment and go create alerting and, you know, and monitoring for those types of things. And I now have 10 alerts with zero false positives, right? I would rather see a company start that way than go buy your favorite SIEM solution and turn on their PCI pack and then spend the rest of their careers, you know, tuning out false positives. Yeah.
So when I, when I have like a visceral negative SIEM response, it's because everywhere I've ever worked, People always turn on that stupid PCI pack or whatever the other option is because it's so much easier than doing the hard work that gets you the true value. No, I agree with that fully. I don't have the same negative— and that's why we've talked about it so much. Yeah, I don't have the same negative reaction to SIM simply because I think people have misimplemented it so many times. And I don't disagree.
It's not hard to, to do that. Yeah. To do it wrong. Yeah. But basically there's a few battles in this world where You know, you get the option of choosing not to do something.
And I think I came to the realization several years ago that your program is never going to be looked at as being up to snuff if you don't have that capability. Well, there has to be a capability for monitoring for bad things, and that's what monitoring and overall event correlation and the ability to dig into— there's a forensics capability there as well. Yep. Yeah. And, and I'll tell you that I thought we did a pretty darn good job of it at Sports Authority.
I thought we were, we were really good at it. Yeah. Because we took the time to get good at it. Yeah. But I learned a lot when I was at Cognizant about it because there were, there were really good— back to the specialist point, there were people that were like really good at that specific technology space.
And it taught me quite a bit. And it also taught me that There are things that are not shortcuts, but are definitely multipliers that help a lot, like appropriately identifying based on threat modeling your use cases. You can actually go to some of the partners and actually purchase those use cases because they've already developed them out. They've fleshed them out and they can help you implement them to your technology base. But none of that's easy.
And I'm not saying it is easy. It's just one of those things that It's interesting to me how many technologies get a bad rep because people can't implement them. Yeah, I keep thinking SOAR is going to be the same way. So SOAR is one of those that if you get it right, it's a force multiplier, right? And I have yet to see a lot of companies that have really got it tuned in and feel like they're getting a lot of value there.
Yeah, me either. Yeah. All right, well, that's the questions I had for you. What else do you want to talk about? You know, the mic is yours to, to, uh, well, to preach to the community.
Well, uh, I don't know that I'm gonna get preachy, although I do accidentally do that quite a bit. Um, I, I would just say that, uh, I, I really appreciated you bringing up kind of the journey. You always bring up the journey with folks. Um, I, I think that everyone, whether you're staying on the technical side of things going into leadership, doing both. One, don't look down on the other parts of our industry.
Like, people tend to have negative reactions to different parts of our industry depending on where they come from, and there's just no benefit in that whatsoever.
So I'd love to see that stop. I'd love to see us be able to not only fix the resourcing problem, but kind of fix the diversity problem in our industry. It's, it's still not great, um, and there's lots of reasons for that that would take a whole show just to even talk about. Um, but from a positive point of view, uh, I feel like I have been so fortunate, uh, to get exposed to really great people, like in companies, outside of companies, friends. I think of this, uh, I think of you this way, like we make ourselves better, we make each other better.
And just be open to learning and be open to the fact that you aren't great at everything. Right. And I really valued a conversation that you and I had. I think it was only after, like, I was doing the new gig, like, not the new, new gig, but the original new gig at EVOTEK. I think I'd only been doing it for a few weeks.
And you and I had a great talk on a security topic. And I left that conversation. I'm like, I totally screwed up. Like one entire topic area. And I'm not used to doing that, but we were covering so much ground that I conflated 2 things in my head.
And I remember coming back to you in earnest and saying, man, I just want to tell you, I screwed that up. You're like, yeah, you screwed up one thing. And that made me feel like, even though I'd been doing it forever, it made me feel infinitely better that a peer didn't look down on me admitting that I had not done something well. It's a broad space, security, and, you know, we create all these acronyms and they don't always necessarily say what they do. So yeah, no worries.
Well, Matt, this is great. I appreciate your time. We're gonna go get lunch so we can continue our conversation, but the rest of these folks can't hear this next part of it. That's right. All right.
Thank you. All right. We'll look forward to having you on here on the show in the future too. Appreciate it.
Learn more about the Colorado security scene at coloradosecurity.org.
Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.