Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 179 for the week of September 7th, 2020. Alex, uh, all of a sudden I think it looks like winter outside.
Well, you know, it will soon, Robb, but today it looks like every other day. It's really hot and I'm at home. Yeah, I was doing a little time traveling assuming someone was listening to this on Tuesday. Here on Saturday when we're recording, it's supposed to be like 97 or something for the high. And then— Too hot.
And then Tuesday we're dropping down to 30-something, right? Yeah, I think that between the high on Monday and the high on Tuesday, I think there's supposed to be over a 50-degree drop. Drop in those highs. Pretty crazy, which is pretty fantastic. And then about snow, I don't know, are we gonna get snow in the Denver metro area?
Or is it just up in the mountains? Or are we gonna get it here too? I personally think it's unlikely, but it's always possible. Well, I thought you were, you were going to be my source for this information. It sounds like you're not it, huh?
Well, I'm just about as accurate as any other weatherman or woman, weather person, weather forecaster. How about we go with that? Let's do that. So yeah, so I can tell you whatever I want, Robb. And, you know, it's a toss-up.
There's no consequences. You just say whatever you want. It's like being a security person.
We're gonna get 3 feet of snow on Tuesday, Robb. That's fantastic. That's a record. Yep. For September 8th.
Just as a public service announcement, it will potentially be cold enough that things could freeze. So You may want to drain the backflow valve on your sprinkler system. You may want to unscrew your hoses from your hose bibs. Yeah. See, this is a community podcast.
We're here to keep an eye on you guys. Yeah, for sure. With that said, we do have some housekeeping. You know, we have our Slack channel where we're coming up on almost 1,600 members there. We would love it if you would join us and be a part of the conversation around Colorado Equal Security.
If you want to get the link to join, go out to colorado-security.com and click on the Slack link there. While you're there, sign up for the mailing list. You will get the show notes delivered to your email every week. At the bottom of the main page at colorado-security.com, there is a form to fill out for that. Also, if you'd like to rate us and subscribe to the podcast while you're doing that, we would love that as well, whether it's iTunes or, you know, the Google Store or Spotify or wherever it is you get your podcasts from.
Craigslist. Craigslist. Yeah, that's my favorite place for podcasts, you know, mostly the illicit seedy kind of podcasts, but exactly, but you know, everything has their place. Next, we'd love it if you tell a friend. Obviously, you know, we love to grow and build the security community here in Colorado.
That's obviously why we're here. And one thing you can do to help is just reaching out to people who you think might be interested in the podcast. Let them know that we're around and hopefully Help us find some new folks. And if you'd like to support us financially, we do have a Patreon campaign that's going on. We would love for you to be a patron, sign up.
If you sign up at the $10 a month level, you will get a shout out on this very show, as well as a t-shirt. These are t-shirts that you can only get through Patreon. They are not the same t-shirts that you get in the Colorado Equal Security swag store.
And, you know, we would love that. We use it to pay for things like hosting and other stuff like that. Awesome. Next thing we have is some community outreach we do is the salary survey. So we did this last year for the first time, and a big thanks to Jeff Ellis who's helping us do it again.
We're surveying the folks in the community to come up with what average salaries look like across disciplines, across years of experience. If you contribute to the survey, you will get a copy of the results. We've got, what, over 200 responses so far. We're expecting to get 1,000 because we know that there's more than 1,000 of you guys out there. So get back to us and let us know, get that in there so we can give that great information back out to the community.
Yeah, the sooner we get those responses, the sooner you'll get the data and the report back. So, if you're on the fence, go ahead and do it now. And you can find the link to that in our— on the main page of our website as well. All right, Robb, I think we have some news. Did you know that 6 months into the pandemic, we should take a look back at how it's been impacting Denver's public companies?
I did know that we should do that, yes, and I've done it. So, there's an article here from the Denver Business Journal that basically just looked at the profit or loss between the companies before COVID and after COVID. They have a great image that I've got up in front of me right now, rating them from those who've done fantastic to those who've done terribly. I'm surprised. A lot of the ones that have done well, I actually would've thought would be in the not-so-good.
Spot because, you know, a couple of them are energy companies. Yeah. I will say though, that most of the energy companies are way down at the bottom in the doing really badly section. Yeah, like Whiting Petroleum and Ultra Petroleum, a bunch of those, QEP Resources, they're down at the very bottom. But at the very top, the company who did the best with 140% growth, Advanced Energy Industries, which is renewable industries, and but PDC Energy is right behind them with almost 50% increase.
Yeah, that is surprising to me. One thing that I did note from the article is that they're looking at the 50 largest public companies here and the net income for these companies fell 150% in Q1 2020 against Q1 2019. It's a little bit of a drop. I'm trying to figure out how your net income can fall by 150%. So if you were making $1 million, now you're losing $1.5 million?
That's how that would happen? I believe that is correct. So the net impact is the companies went from positive to negative then? Yes. Interesting.
It is interesting.
One thing that I noticed on this that reminded me of our conversation last week around Liberty, there's a whole bunch of public companies on here that are Liberty. So there's Liberty Media, GCI Liberty, Liberty TripAdvisor Holdings, Liberty Oilfield Services. Those are all those holding shell companies that are owned by that Liberty Digital that's headquartered in Denver, but not necessarily actually here in Denver in terms of their operations. Don't forget Liberty Global PLC. I did forget.
That's my favorite. Thank you. And right in the middle, the most middlest of the companies on the list is Dish Networks. One of our biggest companies is basically no impact from, in terms of revenue, it looks like from COVID to now. Yeah.
I think that that's probably a good thing. Staying steady in this time is a positive. All right. Next story. There was an Ernst Young, I think they just go by EY these days.
There was an EY team 2020 Entrepreneur of the Year finalist, and there was 14 companies that made that list. Back in my day, Robb, EY was actually called Ernst Young. Yeah, I did. Yeah, so the— this is an interesting article. I think one of the reasons why we picked it is CyberGRX was on the list.
Yeah, Fred, Fred Kneipp from CyberGRX made the Entrepreneur of the Year nomination list, right? The finalists. Really cool to see security companies being recognized. Fred has not only been you know, the head of CyberGRX for several years now, but he has a really nice entrepreneurial background previous to that and expect that, uh, he's going to do good things at CyberGRX in the future. So congrats to Fred.
Yeah, I didn't recognize many of the other people or companies on there, but, uh, there was, uh, someone from Guild Education, which we have talked about a number of times on the show. So that was cool as well. Yeah, CEO and founder over there. Uh, there was, there was some interesting companies, not a lot that I knew. There was a— oh man, I can't remember.
I should have had notes on this, but there was one company with a super young looking CEO and CFO. And it was in the oil industry— excuse me, energy industry, which always surprises me. That's a place where I kind of think of, you know, old money and gray hair. Yeah, for sure. All right, next.
A company we talked about, I don't know, probably a couple months ago moving to Denver to start a tech hub is Contentful. And this article is talking about how they are planning to open that Denver hub while everyone is still working remotely. Yeah. So it would have made sense for them to say, well, we're not doing this right now based on the fact that there's no one going into offices. But they said, nope, we're making the move to Denver.
We still want that market. We still want that talent. We're just going to do it all remote. So they're not even planning to get an office, but they are going to hire 100 new employees here in Denver. Yeah.
And Contentful is based in Berlin. And so it's cool that they chose Denver for this hub here. And also, I thought that what they do was pretty interesting too, that, you know, basically they're sort of an enterprise CMS, but the idea there is that you can use essentially one version of your information and content and publish across multiple platforms, you know, your website, your mobile apps, your Facebook, your wherever else you're publishing things. That's a good idea. Someone should make a company doing that.
Yeah, it seems like a good idea. They, they did have some notes in here about what they're going to be hiring. They're looking to hire customer-facing roles here in Denver to start, uh, customer success and support positions like finance, IT, and legal. Maybe they'll be looking for some security people in that IT hire. All right.
Hey, this next article I thought was actually pretty interesting and new, a new company I'd never heard of. So there's a Denver startup called Honcho. They've raised $4 million on technology that flags risky work communication. And, you know, when you think about risky work communication, you know, we in the security field probably have a little slightly different first thought than this company is actually addressing. Yeah, this is more compliance-based, right?
So my thought when hearing it was, you know, you're typing something that is, you know, potentially inappropriate in one way as opposed to leaking data like we might think.
It's going to look sort of like a spell checker, I think, and try and figure out if you're typing phrases or sentences that maybe you should think about and rephrase. Did you watch the video that they had on the website on this article? I did not. All right. So it's funny.
So it's someone like, you know, IMing with a coworker and that coworker says, oh, how'd it go last night? And the guy writes in his IM chat, oh man, I really screwed up. And when he goes to hit enter, there's a popup that says, oh man, I really screwed up is against corporate policy. And then he tries to type in, oh, what would he say? He said something like, yeah, we didn't end up hooking up.
And then the system says, We didn't end up hooking up is against corporate policy. And then the guy says, we should talk in person, which I assume is the whole point of it. It was just so funny to me that like these guys were like giving examples of people hooking up as the thing they didn't want. Anyway, I don't know. It was amusing.
I think it's worth spending a minute watching if you're interested in this at all and maybe you work with your HR team. It is interesting. I also think it's funny that in that case, You know, the incentive that you're giving is not to actually document the conversations you're having, not to stop having those conversations, right? If you're saying inappropriate things, just say them in person so that no one knows you ever said them. That's exactly how the, how the little video ends where they're like, we'll talk in person over lunch.
Like, yeah, we're gonna have these inappropriate conversations in person. That's much better. Anyway, funny stuff. Good for Honcho. $4 million that they're raising.
They're gonna— they're planning to use that to bring on engineering, product, marketing, sales, and account management folks. Currently, the company is 10 people, so I'm guessing they're going to hire like one each of those different teams. They're not going to be growing a ton, but they are a Denver-based company that's backed by Peter Thiel, co-founder of PayPal and Palantir, interestingly enough. So I didn't remember that Peter Thiel was the co-founder for Palantir, but considering the fact that Palantir just moved here to Denver, that is interesting and makes sense. I guess Peter Thiel likes creepy companies.
Oh, man. I will say, though, that, you know, the technology that they're talking about here, I think it could have some interesting, you know, sort of security compliance angles to it as well, right? So, you know, if you see someone typing a Social Security number in an email, you know, maybe you could pop up a message that says, hey, you're not allowed to send Social Security numbers in email. Use this process instead. I think that to me seems like something that would be pretty cool as opposed to making people talk in person for creepy conversations.
I think I just heard you come up with a really nice product idea for them. I think we can get a hold of Honcho and maybe you can get on their advisory board. Sounds good. I'm open for all invitations. Just reach out.
Give me some of that sweet $4 million. Sweet, sweet cash. All right, next, speaking of startups, StackHawk, who we have talked about several times on the show.
Never gets old, Robb. They have announced general availability of their StackHawk platform. You know, they have been in sort of alpha and beta for several months with people using it, but not GA yet. So now they have gone GA. So congrats to them.
Yeah, this is cool stuff there. I think they're basically using the ZAP open source software, but they're wrapping a whole bunch of nice UI around it, making it a lot easier for development teams to get this integrated during the development process versus a security team that's gonna run it after. So anyway, I think it's good. It's a good idea. I'm excited to see them make some progress and hopefully yet another great security company growing in Denver.
Yeah, definitely good stuff. All right, we're moving over to our blogs. We have a blog from Ping this week. Why DevOps Matters to Identity Teams. I got a chance to read through this and, you know, there's some good points.
I thought I'd, you know, kind of go down to what they said the benefits of identity within DevOps is. So if you're doing DevOps and you're not sure, you know, why do I need to get identity integrated, there's a few different areas they have here. So consistent delivery, being able to do this in a manner where you already have identity implemented within your containers within the systems you're pushing out as code, so it's not having after the fact to go back and retrofit that. Flexibility for the platform, you know, being open standards, tools like Docker and Kubernetes are both agnostic in terms of this, and you should be able to use whatever identity platform you want. Optimizing your deployments and improved velocity.
If you could do it right, you can deploy your identity solution in this DevOps manner a whole lot faster than you could with the old school deployment. Yeah, and I think it is interesting too. There's, you know, some sort of basic definitions too at the beginning of the article. If you aren't as familiar maybe as you need to be with DevOps or what exactly it means, you can read through the beginning of the article to get more information on that as well. Love definitions.
All right, next we have a Red Canary blog this week. Surprise, surprise, they do good stuff, and this was talking about teaming up after an attack to shut down a web server that was spun up as part of the attack. This was, uh, it was an interesting article, I think partially because there were 2 authors, one from Red Canary and then one from, uh, a digital forensics consultant at DFDR, which I don't think I had heard of before, but nonetheless, the way that the article is laid out It is almost like you're running through an incident and you have both authors, you know, taking a turn at speaking about what it is that they were doing during the incident. Yeah, I didn't know, I never heard of DFDR previous to this, but it's a consulting company that does digital forensics and disaster recovery. And they work with Red Canary for the active monitoring for threats.
So the 2 different sides, it was Steve on the DFDR side and Shane on the Red Canary side, just talking through their perspectives on the issue. And then they, as always, what we love about Red Canary's blogs is they get super technical for the operational folks who wanna know what did they actually do to fix this problem. They walk through what the malware looked like and how they found it, what they did to fix it. Yeah, and in case you were wondering, it started with an RCE on Exchange servers. So make sure you patch all your Exchange servers.
There you go. All right, next we have a blog from Zvilo. We've, you know, we haven't talked about them in a little while. What I liked about this blog is they talk about, threat intelligence, what they call cyber threat intelligence, but they talk about threat intelligence and really kind of describe, number one, like why it matters, and then they really get into how you can use it. I think it's— that's one of those areas threat intelligence is where we just have a lot of, hey, sounds good, but practically how do you actually do it?
Well, they try and answer that question. Yeah, and I think, you know, they go through their process a lot of how they do collection. How they validate the intelligence that they've found and, you know, methods that they're using, which I think are methods that can be adopted by anyone who is doing threat intelligence collection. So I think that that's important as well, just thinking through the processes that you might have to make sure you're, you're not missing pieces as part of that collection process. I think it's too easy to, you know, go turn on threat intelligence, have it sitting somewhere, and then but actually not add any value to your security program.
So, you know, the steps that they go through, I think it can help you actually do that. For sure. And then our final blog for this week was from Coalfire. This is from Anne Baer Kohler. She is one of the co-founders of a group called RISE at Coalfire, which is promoting women in security.
And so I did not know this, but this was celebrating Women— International Women in Cyber Day. Which I guess just passed, and, you know, sort of reflecting on RISE and, you know, what they're doing at Coalfire in terms of promoting women in security. So RISE is an acronym, stands for Recruit Women in Cybersecurity Career at Coalfire, Influence leaders within the industry by bringing visibility to women in cyber and participating in community outreach and events, Support women working at Coalfire at all levels in their career by promoting advancement and networking opportunities, and educate and create training opportunities for women in cyber seeking to grow into leadership. So it's cool that they've built that. I mean, it's just ColdFire, right?
Just within their own organization, they've recognized that this is an important thing and they're going to put resources into it. Yeah. I mean, it's one thing to say, you know, we support women, but it's another thing to have a specific organization within your company that is, you know, working on specific items to make that happen. Yeah, it's really cool stuff. Obviously, this is, uh, this is how things get better.
So, uh, really cool that, that Coalfire is doing that, and, uh, I appreciate that, that, uh, Anne posted or wrote this article so the rest of us could see what they're doing. Exactly. All right, uh, that is it for the news this week. That takes us to our next section, which is the Slack Message of the Week. Thanks to Andre Gaeta for sponsoring the Slack Message of the Week.
As he has done since its inception, he, out of his own pocket, provides a $25 gift out of the Colorado Equal Security Store for someone who wins the Slack Message of the Week. Awesome. So this week, Kevin Steere, and, you know, there's a lot of different reasons that one might win the Slack Message of the Week. This week he got it because he started a fun conversation about kind of a gross topic. There was a link this week to new research around fecal transplants.
Heard of fecal transplants before, Alex? I had, although I believe— I think I saw this article and it was specifically talking about fecal transplants to help treat alcoholism. Yeah, that was exactly right. So number one, we know that there's a whole lot of security people who drink way too much, so probably a lot of us who could use alcoholism help, and also we're all full of poop. So between those two things, It's really ripe for the security industry.
It did start a lot of fun conversation, a serious topic that also has a little bit of a fun side to it. So congratulations to Kevin. You'll get one item from the store. Hopefully we'll see you walking around town with your mask on wearing your shirt so we'll know who you are. I was going to try and make a fecal transplant joke, but I, I— anyway, let's move on.
Did you poop your pants? All right. Yeah, I was even trying to come up with a punchline that was not part of the— anyway. I failed miserably, Robb. Let's go over to events.
Hey, we do have events. You know, even though we're in a virtual world, a lot of, a lot of organizations have been doing virtual events, starting with on the 8th of September, the Denver ISSA is doing their chapter meeting that's going to be around Secure Access Service Edge Framework, or SASE. On the 10th, Northern Colorado ISSA is doing their September chapter meeting. Also on the 10th, there is the Cyber— excuse me, Cybersecurity Summit Denver, which is a conference that's— I think that they're one who intends to be in person, but right now they're virtual. And on the 15th, Women in Security and the Cloud Security Alliance are doing an event that is also about SASE, Get SASE with SASE.
That's the 15th. Yeah, and that's— I think that it's the same group kind of doing both of those. I don't know if the content is overlapping or not, but Obviously, it's a good group of folks. The 15th through 17th, the ISSA Colorado Springs is doing their 10th annual Cyber Symposium. This has been, you know, their big conference for a long time.
They've pivoted to doing virtual, and so if you're interested in getting involved or getting a part of that, getting some CPEs and education, you can join that virtually. On the 16th, OWASP is doing their September virtual meeting. And I think the last one here, the 17th, ACES, the physical security group, is doing their first annual ACES sporting clay event. At the Kiowa Creek Sporting Club. This is an awesome opportunity if you're— well, I guess whether you are or are not a fan of sporting, it's a cool opportunity to get to go do something we don't normally get to do.
And you go sign up there. It's not free, and I'm sure registration is limited, so get up there while you can. Yeah, sounds pretty fun though. All right, let's jump over to jobs. We have a few this week.
First, CommonSpirit Health is looking for a Director of Cybersecurity Incident Response and Threat Intelligence. So CommonSpirit, formerly Catholic Health Initiative, CHI, they've been in town for a long time under the CHI brand. Um, that'd be a good opportunity for you to work for a well-known, uh, healthcare company here in town. Bank of America is hiring a— or excuse me, I skipped one. HDR is hiring an OT cybersecurity director focused on transportation.
Bank of America is looking for a senior incident handler. Splunk is hiring a penetration tester. PayPal is looking for an incident response analyst. Anthem is hiring an information security senior advisor. Druva is looking for a security analyst.
And Druva is one of those backup companies. I know that they compete with folks like Code 42. So interesting to know that they're hiring here in Denver as well. Trimble is hiring a product security architect. And Robb, I'm going to take the last 2.
AWS is looking for a senior solutions architect. In the AWS National Security Group. And then the last one is not security related at all, but I put it in here because it looked so cool. Dish Network is looking for a Director of Spacecraft Mission Assurance. So what exactly do I have to have done in the past to get this job?
I have no idea, but I would totally be down for, for helping spacecrafts on their missions. So you feel like you'd be able to direct a spacecraft mission assurance program? No, I have no clue how I would do that. But you're asking me— so much fun. So whoever gets this job, you'd be willing to intern for them?
Is that where you are? Sure. Or at least interview them. I think that, you know, even if it's not security related, that'd probably be pretty interesting for the show. Yeah.
I wonder how many 9s— you know, we talked about 5 9s in the SaaS game. How many 9s do you have to have to launch a person into outer space? Yeah, that would be a lot of nines, I would think. Yeah. All right.
Well, that is it for the show this week. We do not have an interview, but we have a couple scheduled coming up soon. So hold on to the edge of your seats. It's going to be a wild ride when we finally get those. Awesome.
And everyone should be getting this podcast on Monday while they're on vacation for Labor Day. Awesome. Well, everyone have a good one. Enjoy your day off, and we'll talk to you soon next week. Thanks, Robb.
Learn more about the Colorado security scene at coloradosecurity.com. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.