Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 194 for the week of January 18th, 2021. Alex, uh, how are you doing this week?
I'm doing well. How about you, Robb? Doing fantastic. You know, this— we're just a couple of days away from an inauguration. I don't know if you've heard of any news about that, but there's, uh, there's gonna be a new president for the United States.
Yeah, there is. Um, also, if you are— you're listening to this, uh, recently after it was released, it may actually be Martin Luther King Day as well. Oh, heck yeah! This is a great week. Uh, looking forward to both of those things.
I, I actually have Monday off. I know you don't, sucker. Thank you. I appreciate that. But yeah, I mean, you know, lots of hope and optimism.
Yeah, good stuff. Hey, let's jump into some housekeeping. We have a Slack channel. Speaking of hope and optimism, if you stay in the good stuff channel in Slack, you're going to get lots of optimism. If you go to the rant channel, don't blame me.
Robb, do you know we also have a mailing list? Every week we send out one and exactly one email with the show notes from that week's podcast. So if you want all the details about what we talk about here on the show, Sign up on the website colorado-security.com to get that email sent to you. And if, and if you, uh, while you're on the website signing up for the mailing list, you can also find the link to join Slack there. We'd love it if you would rate us and subscribe to the podcast in your favorite podcatcher.
That's a good way for us to find new listeners and for you to make sure this podcast makes it into your inbox each week. Yeah, and we'd also love for you to tell a friend about Colorado Equal Security, about the Slack channel, about the podcast, about the website. Um, and you know, you're also welcome to tell them that we have a Patreon campaign going on. Uh, we love our patrons and they help defray the costs of what we do for Colorado Equal Security. Awesome.
All right, let's jump into some news starting this week. This is some hard-hitting journalism. We, we're going to talk about the top 10, um, most stolen vehicles in the Denver metro area. Yeah, and if you have one of these, sucks to be you. Uh, or, or I mean, it's great to be them because they have a very desirable car.
Uh, yeah, potentially. I don't know if it's desirable because they want to drive it. It's desirable because it's, I don't know, worth something. Anyway, um, you know, the— these lists seem to come out, you know, once or twice a year or something like that. Um, on the list, um, I don't remember when the last time we talked about this was.
I know we have before, but number 1 is the Chevy Silverado. So very interesting there. And, uh, you know, I was just thinking back, Robb, it may also not be that they're desirable. Maybe it's just they're the easiest to steal. Yeah, I actually couldn't decide as I was reading this.
I'm like, do I want to see a car I like on this list or not on this list? I mean, if they don't steal it, that means they don't like it. But if they do steal it, maybe it means it's easy to steal. I don't know. Um, that, that said, I also think there's a, there's a strong, uh, bias toward cars that have been around for a while.
If it's a brand new car, you— there's only one model year worth of them. There's not as many to steal. Uh, and this is kind of combining all years of those cars being stolen. The list is actually much more, uh, US-centric than I would have guessed, you know, considering the fact that it feels to me like We have a lot more foreign cars than domestic these days. 6 of the 10 cars are US cars.
There's the Silverado, like you said, but then the Ford F-250, F-150, and F-350 all made the list along with the Ram 1500. Yeah. It seems like people like to steal trucks. Chevy Silverado, you mentioned those Fords. Oh, and the GMC Sierra too.
I forgot to mention that, which I think— isn't the Sierra just like a rebranded Silverado? It probably is. Yeah. Yeah. So the other ones are the Honda Civic is number 2, the Accord is number 3, the Hyundai Sonata number 9, and pulling in number 10 is the Honda CR-V. Honda makes the list in 3 different spots as well.
Yeah. I feel like from looking at this list before that Honda Accord and Civic are usually on here. So not sure exactly why, but I guess they are popular cars and they've been around a long time. Yeah. I do.
I think there's just a lot of them on the road. Cool. All right, next, uh, we have an interesting story here. I, this is, I think, one of the more interesting ones, uh, of the week. There is a new tech firm, or newish tech firm, in Denver that is trying to solve the problem of political polling errors by not doing surveys.
Yeah, you know, I actually heard an interview with these guys on the Colorado Matters podcast. I don't know if it was this week or last week, um, he and the CEO was describing how they do this. I mean, there's, there's honestly not a lot of crazy science here. They're using Google— was it search trends? I can't remember what they call that, but you have the ability to go see how different search terms are trending in different geos.
And they're using those trends to figure out what are people's sentiments toward the different candidates. And they actually are suggesting that their results are more accurate than the political polls that people have been using to determine who we believe is going to win elections. Yeah, but, you know, the company's name is Unum or Unum AI. So obviously, they're using artificial intelligence for this, Robb. So it is extremely sophisticated.
Okay. Maybe they are. I didn't catch that. But like I said, maybe I don't understand all the details there. Yeah, one thing though, and it's— they are showing at least their initial results showing better reliability than the typical polls are.
Yeah, it looks like they are cheaper than a typical poll, I think, because you don't have to hire people to go out and stand outside of polling locations or other things like that, and they do seem to be fairly accurate. It said that their methodology led to the correct outcome in 93% of swing US Senate races and 58% of swing US House races. And you might say, ooh, 93 versus 58, that's a pretty big difference, but that 58% is actually twice as accurate as more traditional polling methods. Which is crazy, which it means basically that the polling methods were getting more than half of things wrong last— this last election cycle, which seems like you wouldn't want that kind of polling to exist at all. Yeah, I mean, if, if you're 29% right, is it really worth doing?
I don't know. I don't, I don't think it is. Hey, let's move along. Speaking of another technology, I mean, the only reason this is in the show is because I was surprised to learn that Parler, the now infamous social network, was founded by 2 DU grads. Yeah, and I think we have heard a lot about Parler recently, you know, in the lead-up to the election.
Once Twitter started, you know, doing what they've been doing and people wanted to move somewhere else, everyone seemed to move to Parler or other places. And of course, this last week with Amazon and others pulling the plug on Parler, so basically they're shut down at this point. So yeah, so it was founded by 2 DU grads, but it was actually founded in Nevada. And after kind of all this became famous in the last couple of weeks, DU has issued a statement condemning all acts of violence and really trying to distance themselves from this. So I'm not sure DU appreciates us pointing out this connection, but it's interesting to me to know a couple of Colorado guys were behind this whole thing.
And just to be fair, I'm not sure that creating Parler in and of itself is all that big a deal, bad a thing. Uh, you know, maybe it's been used inappropriately, and that's probably what's more interesting to figure out. Yeah, and I think, you know, the biggest part is their reaction to it being used poorly. So yeah, anyway, next, some not so good news. There was a— it sounds like it's not even an announcement yet, but it's sort of a rumor that there's going to be an announcement that US Space Command is going to move to Alabama and not stay in Colorado, which was what people thought was gonna happen.
Yeah, if you know, we talked a lot about this and how, you know, initially, you know, we got the temporary headquarters for Space Command. We were— you and I were surprised whenever that was a few months ago to hear that it hadn't been finalized as the permanent home. And now it looks like it's going to get moved to Alabama. The hubbub about this is it's because, as one of Trump's last things, he wants to reward one of the states that supported him the most through the election and maybe stick it to one of those states that didn't, which is Colorado. Who knows?
I do think that we'll get formal notification on this here in the next couple of weeks. And hopefully, that decision turns around. If not, whatever. We move on, right? Yeah, and there was actually a good discussion about this in the Slack channel this week, and I personally hadn't realized how much of a space presence there is in Huntsville, Alabama, where this would be.
So some people thought it made sense. In this article, there are lots of Colorado politicians that are complaining, obviously saying it's the wrong move, that it's not fiscally responsible, yada, yada, yada. So hopefully, Um, it, even though, uh, we're thinking it's going to Alabama, maybe it will still end up in Colorado. Who knows? We'll find out.
All right. Next story is, uh, is one of these fun ones from Colorado Inno, uh, and it's going through 21 Colorado startups to watch in 2021. Um, there are a lot of companies on this list that we've talked about in the past, and I don't want to try and go through all of those, but Climber, who we just talked about recently, the indoor exercise company, Company Six. DemoFlow. Yeah, Company Six is that spinoff from Sphero.
Lots of, lots of really good ones, but there was one in here that I specifically wanted to mention, and I'm trying to— here it is. Better not steal mine, Robb. I'm sure I am. Is it Heka? Is that, is that how we would say this?
Heka? It's a rural Colorado startup that's focused on privacy and security micro-training built into Slack. So their platform helps your company meet compliance training requirements for HIPAA, GDPR, SOC 2, CCPA, and more while building a culture of privacy all within your Slack tenant. So I personally, I had not heard of these guys yet. And, you know, as I read the article, I sent a note over to part of my team to say, hey, we should look at this and see if this is something we want to do.
So really cool to see a local security startup that is, that is new and is on the list of companies to watch next year. Yeah, that's pretty cool. And obviously right up our alley. The one actually that I was going to talk about is more utilitarian and fun than compliance training, which was Rocksbox. This company uses shipping containers to make temporary structures, so temporary bars.
They're now doing an offering called Patio Box for restaurants, you know, with all of the indoor dining being disallowed, you know, you can get some of these enclosures and they can seat up to 36 guests depending on the model, and they have other, other things besides that too, but I thought that was pretty cool. That is pretty cool. I'm glad that, that we got to each find something different that speaks to us individually. For sure. All right, next we get to meet the finalists for the Orbi Awards from Colorado CIO.
This is the, the best CIOs in Colorado. Yeah, we've, I think we've talked about this in previous years. I think generally we don't put a ton of focus on these, but I know this year one of the finalists is not only a CIO, but also a CISO. He's working as interim CIO for Holland Hart, and that's James Johnson. James is a friend of the show.
He's a former president of ISSA Denver and an all-around good guy. I think we've had him on as a guest on the show in the past as well. He's one of the finalists in the corporate category, which is kind of like that small-medium size category. Hopefully for— hope James ends up being a winner, but either way, I'm glad to see him recognized. Yeah, that's pretty cool.
Um, one of the other people on the list that I know is, uh, Jamie Cutler, who is now at Air Methods, who used to be my boss, uh, several jobs ago. So, uh, congrats to Jamie, uh, well deserved for him. Yeah, it seems like Jamie just moved not that long ago and it's already on the list. He's— and he was on the list always for these kind of things when he was at Um, at QEP as well. Uh, I guess he's, uh, he either knows the right people or he's just good enough to get recognized wherever he goes.
Uh, he is good, but I'm sure he also has a good PR team behind him. Probably a little bit of each, right? Yep. Yeah, fair enough. All right, uh, next we're moving over to our security news.
We actually have some big news for Swimlane. Um, Swimlane is the local SOAR, you know, security orchestration response, um, company, and they, as of the end of the year, have brought in a new CEO, uh, Cody Cornell, who we've had on the show a couple times over the years and has been a great friend of the show, is he was co-founder and CEO of the company, is moving over to be their Chief Strategy Officer, and they're bringing in a more experienced CEO to lead them through this next level of growth. Yeah, pretty cool. I think it's good news for them. I mean, I don't mean that in anything negative about Cody, but I think Cody at his heart is a technologist, and as they grow, and as you know, startups generally grow, you know, you want to bring in someone that has that experience in terms of leadership and, you know, growing a company and has been through this thing before.
And the new CEO, James Breer, he's definitely done that. He was previously CEO of VeraFlow, which was bought by VMware in 2019, and has a whole list of startups that he's worked with before that. So pretty cool, seems like a good move for them, and hopefully it continues to help them grow and be awesome. Yeah. When you read his bio, it's packed with companies he was at and the great exits he had for them, many of them being acquired, but some of them, actually one of them specifically recently that went public.
And I think if I was someone like Cody and the leadership team at Swimlane and saw this guy's track record, I'd say, yeah, that's exactly the kind of result we want to see, either getting acquired or going public either way. Awesome to see that it has that track record of success. And it's also, a couple other things from this article that I found interesting is just the amount of growth they've had at Swimlane. It's been a while since I've checked in on the numbers, but they're over 100 employees now and they've raised tens of millions of dollars and lots and lots of international customers at this point. So they are kicking butt and this is just a sign of the success that they've had so far and hopefully continues going forward in the future.
Yeah, pretty cool. All right, next story. LogRhythm has some big news. They have acquired the threat detection platform MistNet, and they have done that to help grow their network detection, UEBA capabilities, EDR, as well as additional detections around MITRE ATT&CK. So pretty cool acquisition for them.
Yeah, I read through this release and there was an awful lot of buzzwords and I got a little bit lost in the buzzwords at one point, but overall, you know, the XDR thing always kind of throws me off. Yeah, it is a silly term. But, but it, you know what, the biggest surprise to me was from a LinkedIn post from James Carder, the CISO over there, was that this is the first acquisition that LogRhythm's ever done. Yeah. I mean, obviously they are not just out there trying to acquihire their way to success.
This is a— this must be a very strategic acquisition for them. You know, LogRhythm has been around for, you know, well over a decade, maybe close to 2 decades at this point. And they've now finally decided to do an acquisition. I'm excited to see what this looks like and how this is going to change their go-to-market and their product offerings. Yeah, I mean, it seems like MistNet was definitely a technology that did similar things to what LogRhythm does, but in a, you know, more targeted way.
And I think it'll probably help move their platform forward. So pretty cool there. Good stuff. Speaking of acquisitions, we have another acquisition this week. There's not a ton of details here, but Coalfire has acquired a penetration testing management platform from a company called— or in buying a company called— is it Neuralysis?
Neuralys? Sure, sounds good. Neuralys. Um, and there's not a lot of details here on exactly what this is going to mean, but this is an interesting acquisition for them. You know, they, they bought Verus a few years ago, and I'm sure they have some other acquisitions, but mostly of like services companies.
This is, uh, or You know, this is a technology that they're buying, right? A platform for doing pen testing. So it's going to be interesting to see how they use this to, to kind of make themselves better equipped to, to meet new needs from customers. And I'm excited to see where this is going to go. Yeah, and I didn't look into the details of that platform itself, but, you know, I have seen other platforms that, you know, bill themselves as pen test management platforms.
And a lot of it is the, you know, the workflow and, you know, the back and forth over results and things like that. You know, many times you get a pen test and you say, okay, go test, and then a few weeks later you get handed a Word doc or a PDF, and then you've gotta, you know, sift through that and figure out what the actual results are, and, um, you know, then go, go figure out if they're true and things like that. So I think, uh, my guess is that this platform helps automate that process, makes, uh, penetration testing either easier for both sides. All right, good stuff. Yeah, moving on here.
Ping Identity, uh, announced— had a press release this week announcing that we, uh, we being, uh, Ping because I work there, uh, we were named by Glassdoor as one of the Employees' Choice Award winners. Yeah, that's awesome. Um, we've talked about similar awards like this for Ping in the past. It seems like, uh, people sure like to work there, and, you know, definitely shows with an Employees' Choice kind of award. Yeah, it's pretty cool.
I, I don't know a ton about this. You know, I know Glassdoor is the place you go to look before you go work at a company to see do people like to work there. Um, they— but what they did is they categorized all companies across the US, uh, into either large enterprises or SMB basically, and Ping made the small-medium size. But they were the number 19 company across all SMBs across the country. And frankly, there's a lot of companies on the list I'd never heard of.
Interesting to me that, you know, that it was such a large pool that we were competing against. Anyway, cool stuff to see, and it is nice to work at a company that cares about culture and engagement. That is pretty cool. I'm pretty sure though, Robb, that you mischaracterized Glassdoor. I believe that it is the place where you go to bitch about being mistreated by your company.
Is that what it's for? My bad. My bad. All right. Final story for the week.
We talked about this a couple months ago, but JumpCloud, they had done their Series E for $75 million, and they have now announced that they have oversubscribed that Series E and raised it up to $100 million, as well as using some of that money to add a chief revenue officer. Yeah. I mean, obviously this is just a follow-up on that first raise, but the chief revenue officer is great. This is a huge sign that JumpCloud is becoming a real player. It's nice to see Colorado continue to extend our own security, and specifically here, identity companies to be one of the leaders in the world.
Yeah. Pretty cool. Obviously, $25 million more than they were expecting, which is awesome, but also, uh, Kevin Biggs, who it did not give a whole lot of details for in the article, is now the Chief Revenue Officer. Yeah, I don't know who Kevin Biggs is. Um, you know, maybe, maybe if you talk for a second, I'll look him up on LinkedIn.
We'll see what we can find out. Uh, while you do that, um, that is the end of the news. Uh, we can loop back once you find your— well, this is interesting. He was, he was the Chief Revenue Officer for OneLogin, which my first thought would be, hey, there's a non-compete there, but he's also in California, so non-competes are Not a consideration for someone in California. Cool.
Well, that seems like a good hire for JumpCloud then. Congrats to them. All right, so that is the news. With that, we can move over to the Slack Message of the Week. Thanks to Andre Gaeta for supporting this.
Again, he has supported this all the way since the beginning, even before it was Slack Message of the Week when it was trivia.
And, you know, he does this out of the goodness of his heart and the depths of his pocketbook. Uh, the winner of the Slack message of the week will get one item from the Colorado Equal Security swag store. And Robb, who is the winner this week? It's DJ MacArthur. DJ, uh, you know, we do kind of a little holiday thing with some of the CISOs in town where we let the group kind of vote on each other for a series of different awards.
Well, DJ won one of the awards this year, um, and, and as a kind of a, a fun acceptance speech for his award, he put together a music video with him playing drums and, uh, and posted that music video in Slack and it got a good laugh from me and basically raised the stakes for what's going to be expected from anyone else who wins any awards going forward. For sure, it was an amazing video. DJ was playing the drums, he seems to be a great drummer, and I was pretty impressed with his skills as well as his creativity in the thank you. So congrats to DJ for both things. All right, let's jump over to our holiday— or our calendar of events, that is.
You know, we always look at what's coming up the next 2 weeks in town. Of course, in town these days means virtually in town. You can go look out for— really, there's quite a few things on the calendar now. There weren't a few weeks ago, but things have been filling in. You can look and see things out for the next several months.
But in the next 2 weeks, we start off with on the 19th, the Colorado Springs ISSA chapter is doing their January virtual meeting. Also on the 19th, CSA is doing their January virtual meeting. On the 20th, OWASP is doing a joint chapter meeting, and that's going to be a combination of the Denver and Boulder chapters. Nice. On the 21st, ISACA Denver is doing their January chapter meeting, and that is in conjunction with the IIA.
Also on the 21st in the morning, ISIS, the physical security group in town— I said ISIS again, I did it last time— ACES is doing their Women in Security coffee chat with Dawn Gregory. On the 23rd, Colorado Springs ISSA is doing their January mini seminar. Um, on the 26th, ACES is doing their Young Professional Networking Happy Hour with Taylor Passanello. Nice. And then we have 2 events on the 27th.
ISC² Pikes Peak is doing their chapter meeting for January, and Denver ISSA is doing an event called Your Presence Matter— Matters, excuse me— How to Show Up as Your Best on Video. So not a security talk, it sounds like, but, uh, how to have better meetings. Pretty cool. Pretty relevant for us security people anyway. Yeah, definitely relevant.
All right, uh, jumping over to jobs. You know, we always like to talk about some interesting jobs in the community, and because I am one of the co-hosts, I get to talk about jobs at Ping. And we've got a few in the— in my team. Uh, we're hiring a product security engineer, so if you have an application security background or just a development background with a passion for security, I'd love to talk to you. I'm also looking to hire a business analyst focused on my security program, and finally a manager for our privacy programs, someone to run privacy within Ping.
Nice. Fast Enterprises is looking for an information security analyst. Schenker is looking for an IT governance specialist focused on security. Black Hills Energy is looking for a corporate IT security analyst, parentheses Frederick. So I'm assuming that is in Frederick, Colorado.
Yeah, yeah, I put that note in there because we don't get a lot of jobs in Frederick, and I thought anyone who's, who's thinking about that job, this is a good time to apply. For sure. Slack is hiring an Associate Risk and Compliance Engineer focused on IT governance and compliance. US Department of Interior is looking for an IT Cybersecurity Specialist. That's a GS-2210.
Is that a GS-2900? Is that what that is?
Pretty good. Pretty good. GS-2210 is what that is. Yeah. 2210-12/13.
So, you know, for your government folks, I'm sure that makes all the sense in the world. A lot of sense. Hey, we also have a job from Pulte Group where Alex and I have both worked in the past. Uh, Pulte's looking to hire a senior IT security analyst. Uh, Ball Corp is looking for a manager of IT audit.
And that is it for jobs. We, uh, we made it through the, the news portion of the podcast, but we do have a feature interview this week, Alex. Wow, that's awesome. Who are we talking to, Robb? We've got Joey Stanford coming to talk to us.
Joey is the head of security, compliance, and privacy for platform.sh, which is a company that I suspect most of our listeners have never heard of. But when you hear about their customers, you'll realize you've been working with them on, on their platform quite a bit. Very good. Very good. And this was done by Janelle, correct?
Yeah, Janelle, thank you very much for doing the interview. We look forward to hearing it. And, and of course, any, anybody out there who has ideas for folks you'd like us to talk to, send us a note and we'll definitely consider it. And if we can reach out to them, we probably will. One other note that Janelle had sent us.
One of the things that they talk about on this interview is that Joey is a mentor with Security Career Connections. So we're going to put a link to that in the show notes. Good stuff. All right, Alex, well, have a great week and everyone else, we'll look forward to talking to you guys again next week. Thanks, Robb.
Hi, this is Ed Fuller, CISO of Cloud Elements. This is Colorado Security. For Colorado Security, I'm Robb Security professionals by Colorado Security Professionals.
Welcome to Colorado Equal Security. So this is Janelle Hsia, and today I am super excited to conduct an interview with Joey Stanford, who is the Security Compliance and Data Protection Officer for Platform.sh, which is a company that's located in France. But I'd like to point out that Joey is not in France. In fact, he is in Longmont, Colorado. And before I give the mic over to Joey, I just want to explain why I'm excited to conduct the interview with him.
So we met at a local meetup which was presenting on GDPR before anybody knew what GDPR was. And I can't remember if it was late 2017 or early 2018, and Joey, maybe you remember, but we were in one of those banquet rooms at one of the giant hotels, and we bonded over this inaccurate and incomplete information on GDPR that the speaker was giving. And so I valued your security and privacy expertise ever since then. And I remember in those early years joking that we were like the lone DPO Rangers in the state of Colorado, right? Because DPOs generally aren't stateside.
So with that, why don't you give us a little bit about yourself and a little bit about Platform.sh? Sounds good. I'm super to be here. And hi, everybody on the podcast. Thanks for tuning in.
I have this really interesting title. You mentioned it earlier. I am Security Compliance and Data Protection Officer. That's a mouthful. So I have, because I focus or I specialize in startup security, when you're in a startup you tend to wear multiple hats and that's exactly what I'm doing.
So I'm wearing the security hat, so, and since I am the only information security officer, so I am the Chief Information Security Officer, though I share the traditional CISO duties with my CTO, and then I have— I am the compliance officer, so I'm the chief compliance officer because I'm the only one there, and then I have strangely enough this European Data Protection Officer, which I'm officially designated at my supervisory authority in France, but also in the ICO in the UK, a couple places in Germany, and then to make matters even more confusing, Australia. So I have all these things. Now typically when you think about data protection officer, you know, written into the GDPR, there are some guidelines about how you're not supposed to— you're supposed to be independent. And so it is somewhat of a conflict of interest when you have somebody who is in charge of security and is also the data protection officer, right? You don't want to audit yourself kind of thing.
And so I've tried internally to take steps to limit that as much as possible. And then naturally, as the organization grows and I can hire additional people and I can start taking some of my responsibilities and putting them off to different staff, which then allows me to take a vacation. Vacations are nice for all of us, one of those things that all of us with the C in our title want to do.
Totally true. So Platform, what does Platform do? Platform is a platform as a service provider. What does that mean practically? It means if you're a developer and you write some code and you commit it to your Git branch, You just have to aim your Git branch over to platform, and we do all the rest of the work.
We are your IT department, we are your security department, we are your compliance department, we are your web hosting service, we are your ops people. So you do git push, and presto chango, you have a website and an application live. And we can clone pretty much any workload in— I think we're, we're at 40 seconds now, last time I checked. So it's pretty cool. So you can make you can make multiple copies, multiple branches of your production environment, test things out in staging, and that's really, for me, this is what's really one of the many things that's really interesting about platform is that our development, our staging, and your platform— in your production environments are exactly the same, which is wonderful.
So there's, you know, you completely remove that element from a typical development cycle. Exactly, yeah, no, 100%, and, uh, makes rollback, it makes push out, it makes everything so much easier, that consistency. And so what is it like working for a company in France. That's— I don't think most of us have that opportunity to work for a European country, let alone one in France. I jokingly, but it's true, say that the commute's a bit of a problem.
It's like working from Europe from Colorado is really interesting for a number of different reasons. One, simply just because of the time zone overlap, you know, your days start earlier. But you end earlier too, so that's a good thing. Hahaha, I'm worldwide, so I get up I get a break in the US afternoons. I get a little bit of a break, and then it's on to Asia Pacific.
And so then I catch the Asia Pacific train, and then I go to sleep. And then I come back, and then I wash, rinse, and repeat. So it's really difficult. I mean, I'll have to say this. For those, for those of you in Colorado, working in Colorado and having your teams here or even teams stateside, you don't realize how wonderful that is until you're working in Europe and you realize you get really lonely because your staff is predominantly dominantly in Europe, and you have, you know, this short period, a couple hours, 2, 3, 4 hours of overlap with your staff and the rest of your colleagues and decision makers, and then you're, in my case, like, I don't speak French, but I'm starting to because I have to deal with a French-only speaking supervisory authority and French-only speaking auditors, so it's really interesting from that aspect.
And you're also, like in my case, I am dealing with European law. Right. But I live in a completely different company— country, you know, almost halfway across the world. And so you're— I'm specializing in something that has no practical use in a sense for here in Colorado. But that's really not true, right?
Because you have people in Colorado, companies in Colorado, companies in the United States that want to sell into Europe. And naturally when you want to sell into Europe or do business with Europe, you need to comply with European laws. And so it does. It does actually have some value, which is a nice piece to it. Yeah, and I think definitely, you know, I'm still surprised when I run across companies who are just starting on their GDPR journey, right?
You know, and unfortunately there are quite a few of them that have been selling in Europe for, you know, since, you know, 24 years and didn't realize that they had this obligation. And you mentioned the CNIL. So I work predominantly with the ICO and the DPA DPC, which is the UK and the Irish data protection authorities. I try very hard to stay away from the CNIL, and when I have to, I call my friend Joey on the rare occasions I've had to have French connections. So what is it like?
They're known as a really hard data protection authority. And so, you know, what is it? What's your take on them? How much are you— how familiar are you with their processes? They are really interesting.
So the actual pronunciation, so I made a mistake for many years and I called them the CNIL, and it's actually pronounced the CNIL, which is very difficult for English speakers to say, the CNIL. So they are really interesting. The CNIL started out as an organization with no teeth and very low substance. So in 1978, France passed their data data protection laws, which were revolutionary at the time. Nobody else had them, and the French were at the forefront.
When the CNIL was created, they didn't really provide them any sort of— when I say teeth, there's no real fines, no real action they can take. They were just really a guidance. When GDPR came around, it turned the CNIL into— it really gave them the teeth, and at this point, they really found their mission. And they they struggled for 2017, 2018, and in 2019 or thereabouts, they really got into this and they started to mature really fast, and they went from the back of the pack, and honestly they were laughed at by the other supervisory authorities and people that were in the privacy profession. They went from the back of the pack to the forefront where they were leading and they were tackling interesting and new things, not only items specific to France, but also the larger GDPR and artificial intelligence and coming up with guidelines and rules.
So this was really interesting. And so I've had experience with the— as you have— the ICO, the Information Commissioner's Office in the United Kingdom. Now the Information Commissioner's Office, when they come to you, they typically give you a 1 or 2 word sentence having been on the end of one of their audits, they give you one or two-word sentence— sorry, one or two-line sentence that says, you know, tell us about this, explain to us how you responded to this, and the expectation for you is to come back and give them several paragraphs and some supporting data and whatnot, and then they will render a decision. The CNEIL is a little bit different. They will give you forms to fill out.
They will provide you with several paragraphs of information and requests for services. So they look at a more— where the ICO has traditionally been, let me get your point of view. The CNIL is more systematic and like whole system focused. They will give you the full list of items and say, tell us everything that's going on. And so they're looking across the entire spectrum of GDPR as well as French law to see, has there been any violations?
And also, are you operating in a reasonable and prudent prudent matter. And from that, they will actually give you opportunities for improvements like OFIs, although they don't call them OFIs in particular. So it's really a completely different aspect. The other piece too is that the CNIL is very slow. If you submit a request to them, you might get a response in 2 months.
Oh, that's— yeah, the ICO was 35 days, you know, when I've had to work with them. So you've mentioned audit a couple times. Why have you, or why has the platform had to be audited? So the audit I mentioned with the ICO was for a different company. It was for my last employer.
Platform has not, unfortunately, has not been audited by the supervisory authority. I have made some— what's the right word in English? I've made some early inquiries for decisions that I've had to take, not related to any security breaches or whatnot, but just, hey, I'm thinking about going this way. Could you comment? Could please confirm my approach, what is your preference?
And those take even longer. The CNIL actually has a dedicated DPO hotline for us, which is surprising that it still takes over a month and a half to get back to us. Well, I was going to ask, I know that one of the countries in Europe has a DPO certification. And so I don't know if you know— France does as well. Yeah, so do you, I mean, can you tell us anything about that?
Have you registered with that? So it's all in French and it's good for one calendar year. Oh, that doesn't last very long. Exactly. So when you look at the benefits for having a certified DPO, it really benefits DPO as a service as opposed to, you know, in-house DPO.
Yeah, absolutely. And then these early inquiries, like I think that's kind of, you know, being stateside, most of us that are dealing with GDPR and in the DPO role, we don't have the benefit of being in Europe to kind of see what the boots on the ground there are doing and the DPO camps that they have and the meetups that they have. And so how are you making sure that the documentation that you're providing is going to satisfy the requests for all of the data protection authorities that you're working with? Do you have any strategies for that? Yeah, so we've— I've done 2 things.
The first is I've made sure all the documentation is in English.
And when we have to respond to the CNIL, I have people that are able to translate everything. So our company does everything in English, which is really nice. American English at that, not even UK British English. The other thing I've done is I've taken a selection of— so I've acquired a set of various forms for different things. So here's my report on compliance.
Here's my ROPA. Here's my list of vendors. Here is the breach notification process. And I've taken the requirements that come from the CNIL, from the ICO, from a variety of supervisory authorities that have published, and I've merged all of them together. I've even used stuff from the Federal Trade Commission, so like HIPAA breaches, as a matter of fact.
And I've roped all those up. And so my strategy has been and this is somewhat unique but not terribly unique, my strategy has been to be GDPR compliant everywhere. So I call it GDPR everywhere approach. And when I do that, when you do that, it allows you to very quickly to start satisfying things like CCPA, assuming you don't sell, PIPEDA in Canada, the APA in Australia, New Zealand's privacy laws, etc. Even BDSG in Germany.
So you have— so I built all these and I've tried to say that there's one way of doing things worldwide, and just because we don't need to apply, say, GDPR deletion process in the United States, I don't want to have a local process for that. And there's lots of reasons for that, but if you look on the security side, which a lot of the people listening to this are really focused on security, right? I don't want to carry that personally identifiable information, that personal data around with me. I want to use it, and when I'm done with it, I want to get rid of it. I want to discard it.
So that it limits my— limits the amount of exposure that I have. Yeah, no, I completely agree. And all the clients that I work with, I try and make that case as well, right? Like, there's so much return on investment by just having one program that you have to implement instead of trying to make it jurisdiction or regulation specific. And GDPR is the gold standard.
There doesn't seem to be any reason not to provide the rights unless the company has a hard time doing it, right? So then that kind of transitions right over into security. So being in charge of the privacy program, how does that benefit the security program for platform?
So I have a compliance team and I have a security team, and my joke, internal joke, is that it takes two to make a thing go right. So on my security side, I have the real deep technical security people. They're the traditional people that have CISSPs, they do pen testing, that sort of stuff. And on the compliance side, I have the They're typically, you know, lawyers and compliance people that are really non-technical but really are knowledgeable of the law, contracts, data processing agreements, that sort of stuff. So in order to have privacy, you need security.
You don't need, you know, you don't— privacy itself does not give you security in my book. You have to have security first, and then privacy is like a subset of security. Ready, right, for that. So my 2 teams work hand in hand together to be able to accomplish the mission, and the majority of stuff that I focus on in my current world is oftentimes driven by standards. So SOC 2, PCI, ISO 27000, FISMA, SecNumCloud in Europe.
There's a new European equivalent of FedRAMP that's coming. It's called EUCC, and it combines parts of SecNumCloud. SecNumCloud is France's version, a very thin version of FedRAMP. For those of the— those listening that have FedRAMP experience and FISMA experience, SecNumCloud is a breeze for that, but there are very unique requirements for Europe, such as all of your support has to be— has to be provided out of Europe. Europe, like in Europe, and local countries have to have first-level support in that language, things of that nature.
And so a lot of this stuff that's coming, it's been brewing in Europe, and it's a reaction to a couple things: European nationalism that was there, individual state nationalism that was there prior to the EU, and then the EU formed, and then of course all of the stuff that's happened with the Schrems II decision last July. For those of you not aware, Schrems II was where they said Privacy Shield is no longer valid, and they cited to FISA 702. 702? Yeah, it's been a day already. I know, 702, but— sorry.
Yeah, no, absolutely. I call it being snowblind. Like, literally, there's so many regulations. Like, if I'm not my head down in one particular one, it's challenging. But going back to the security piece, so it sounds like security and privacy is sort of coming together in a marriage there in Europe more than it is in the United States.
Right, so we have this in GDPR, we have this concept of privacy by design. It actually predates GDPR, but GDPR really helped bring it to the forefront, and I use 2 terms. I use privacy by design, but I also use security by design, and security by design is stuff that we're already doing, right? We're looking, we're looking at how we design our systems You know, the current fad, which is actually, I think, a great fad, is zero trust, right, where nothing trusts anything else. So you have these things for security.
We've been doing this for a while. We're saying this is secure and designing. And so now what we're doing is we're bringing in a privacy component that just says, hey, we're going to— what are we doing with the actual data? What's happening there and how do we protect that and how do we protect our users? Is there anything extra that can we do?
Can we employ data minimization? Can we We remove data when it's no longer in use, which causes a big problem when your company needs to do a data lake or data warehouse, and you need to capture all of this data. If the data doesn't include personally identifiable information, which by the way, if you capture an IP address, an IP address is considered PII, but it's only PII when it's in aggregate with something else where you can identify an actual individual, you know, then you have to make exceptions. Well, I'm gonna keep this IP address 'cause I need it. And then you have other standards such as PCI requires log retention for a year, that sort of stuff.
So, and something we don't talk about much at all is that security— privacy is the same in a sense regardless of the size of the organization, but there are different challenges. So the larger you become, the harder it is for you to grasp all the different pieces that are happening, all the different moving parts of where you're storing things. Security has the same problem, and it's something that we don't talk about much, if at all. The security for a 50-person startup is different than— that has nobody assigned to security— to when you get to like 150 people, you start saying, well, I've got a security director, I might have a security guy, I might have a singular compliance person. And then as you get up to about 850, things change.
And now you're, you know, on that scale from 150 to 850, you're looking at how do I How do I replicate? How do I consolidate? How do I uniformly set the standard across everything? And then once you get above 850, then it kind of— it begins to scale and you have harder problems. And this is more complicated when you have not only remote-based, but now you have physical people, right?
Because your challenges are different. We traditionally talk about web security and authentication security, and we don't talk much about these days— we used to talk about it all the time, we don't talk about it much these days— about the physical security and the people in the office and the standard builds that everybody has to have on laptops, and how do you manage laptops and mobile device management, you know, and the variety of exposures because your attack surface expands with the number of people that you have, and that's really the problem. If you can narrow the attack vectors down, then you just have to worry about the volume, right, of what's exposed. So when people like the people that are listening to this podcast, some of them might be probably in larger-scale things, right? It's completely different when you look at a startup versus, say, somebody that works at the state level and has, you know, 450 employees that work for them, right?
So it's different, and that's why it's always— it's the tagline, right? It depends. It really depends on what you're actually looking at going after. Yeah, because I agree. I mean, I think we know how to solve the problem, You know, we know we need the standard builds, we need vendor or vulnerability management, right?
We need to patch. We've got— we know what to do. We've got to have, you know, multiple-factor authentication. But how do you roll that out, I think, is what you're getting at, right? Like, and the scale of that is what's challenging.
Are there any tools that you use or any products that you recommend for helping with that scalability?
That's an interesting question. The first one that comes to mind is my brain. Okay, that's a new one. I haven't heard that one before. Right, so we're always, everybody's always hawking the latest tool, you know.
Oh, hey, we're gonna use this. I know, I saw on your, sorry to interrupt, but I saw on your LinkedIn page, do not, if you're a vendor, do not contact me. I echo that, but yes. I know I get several times, even with that in there, several times a day, I get literally a day, I get messages on LinkedIn, hey, I wanna add you because I wanna introduce you to this brand new tool. And LinkedIn has sort of morphed into this marketing platform as well.
So there are always a number of good tools that you can use to solve a problem, but I think we always like to talk about our favorite tool because oftentimes it really helps us. And where I start is actually just before that, which is I use— I try to invoke my brain, which I don't do very often because I'm not that smart, but by What I mean by that is I want to think through the problem first. Is it really a problem? Do we have to take the commercial, the standard commercial approach to it? Is there some way that I can tweak a setting here, change a process there, which solves my problem without having to deal with it, right?
So maybe your problem is I don't, you know, HR is maintaining personal data from employees on their laptops because they're sharing around spreadsheets and stuff. Well, maybe the Instead of having to go off and buy an expensive piece of mobile device management software, maybe the solution is to get them to stop doing that and put it in the cloud someplace or in a data center where you can control access to it. So I always want to look at it from first principles, which is difficult, especially when you see a tool going, oh, this would really help with incident management. Oh wow, SentinelOne antivirus does behavioral analysis and I can do blah blah blah, right? And so there's lots of things.
So then the next step is when I look for products, I'd look to see how much utility can I get out of it. So in the Unix/Linux world, right, we always are— the main focus is always one program does one thing and it does it really well. So you try not to complicate things. But when I look for a vendor tool, it's actually the opposite. I want to see how much utility can I get, you know, how much bang can I get for my buck.
So I'll use SentinelOne, has been a supporter of Colorado EcoSecurity, so I'm going to use them as an example. Plus I actually use them as my antivirus. Currently. But with SentinelOne Antivirus, you can do— you have the behavioral analytics that come with it. You also have list of app packages.
So good, now I can see what everybody's running on their computer without having to buy mobile device management. It has a network firewall, right? So I can get a couple different things for the same price, which is nice. Yeah, no, I agree. I think that utility is critical, and I do agree that, you know, when you have so many vendors, so many tools in the environment, it's hard to manage all of them, right?
And then you actually are increasing your threat vector because you've got additional products and vendors to manage. So let's highlight this one for just a minute because you just said something very interesting. So you were talking about vendor management, and I will say, here's a unique perspective for me, vendor management is a huge problem when it comes to privacy because you have— even for— so most people that are listening to this probably have SOC 2, right? And SOC 2 says you're going to review all of your vendors. So you have to go through and review your vendors for a couple different reasons.
One, you need to make certain that you've got— especially a new one— you need to make sure that you have a finance approval, you need to make sure you have a business approval. But then the hard part comes in. You need to do a security review on them. And how do you do that? Do you send Do you send them a spreadsheet?
Do you use a separate tool? Do you send a questionnaire? Do you invoke third-party providers like RiskRecon and Security Scorecard, right? And then you have that piece, but you also correspondingly have the compliance side, which we typically haven't done that much of, but GDPR is forcing us to, and that is, do they have good terms and service? Do they have a privacy policy?
Are they GDPR compliant? Can I get a DPA or standard contractual clauses? And my favorite, what is the indemnification limits? 'Cause everybody tries to screw you with indemnification. So how do you deal with this?
And so you end up spending, like for me, it's a huge chunk of my time. I spent, my teams spend an amazing amount of time just working on the prep for vendor management. Once we have the vendors approved, then it becomes the standard monitoring, unless of course they are critical to your infrastructure. If they're critical to your infrastructure, then you have additional problems because you need to make sure that you review them at least annually, if not more, right? And make sure that you have all of your— you understand how they interact and make sure that there's better business continuity and all this other stuff that goes with it.
So it's kind of a nightmare. That's why people have procurement departments to help solve a lot of this. But in smaller shops, they don't have procurement, right? They have finance and they might have a security guy. So it really depends.
Again, it's the size that comes into play, right? How big are you and how much can you support? Yeah, no, I agree. And I think choosing the right vendors, I call them partners, right? Because really they're your partners in business.
And people need to look at them that way. And picking a good partner at the beginning that can grow with you, I do think it's critical. The one thing you didn't mention was breach, right? Like, have they had any incidents? Have they had any breaches?
Are they, you know, like, what is their risk tolerance towards— Do they have business insurance? You'd be surprised how many people have answered no to my security questionnaire. Yeah, so that— there you go. You know, like, there's— it's like, you know, grading papers or resumes. Check, you know, spelling is incorrect, throw them out.
No insurance, throw them out. So one of the other things that we like to do on the podcast is talk about how to get new people into the field, right? So how did you start in security, and what recommendations do you have for new people getting into this field?
Ah, it's a doubleheader. I like it. Yeah, so security was interesting. So I, I started out out in my career as an application developer. I went to college and I said, ooh, I want to be a network engineer.
And when I got in there, I realized all the jobs were application development jobs. So I changed my hat and I started doing application development. And from there, I quickly became like a sysadmin on my own time. I was still doing application development, but I went into project management. So I had this really kind of circuitous route.
So I'm doing project management and And I'm at home, I'm working on my servers. I have a server rack in the basement. And then now I do here in Colorado, I'm the IT director of Rocky Mountain Ham Radio. And we have 240 systems spread out between Wyoming, Colorado, and New Mexico, where we do microwave links off top of mountains. We have routers, repeaters, servers, really fun stuff.
Anyway, I was doing this, I was doing program management. For a company called Linaro, Linux on ARM. They're the ones that put basically Android on new devices, and I started asking, you know, who's patching— simple questions— who's patching this AWS virtual machine that we've got running? How's the authentication working for this? And the next thing I know, the COO of Linaro came to me and said, listen, we'd like you to be our IT director, and I'm like, well, I I don't really have any experience for that, but I'll try it.
I'm going to have the sysadmin experience, but not at scale, which is interesting. So I got into it that way and I was like, well, and it kind of grew from that, from the security point. It's like, oh, this is interesting and how do I secure? And it really, for me, it was driven from the same reason I'm into privacy, which is my desire to protect. I want to protect, strangely enough, not necessarily myself, but I want to protect others.
I want to protect my colleagues that I have really good friendships with. I want to protect our users. I want to protect my family that uses the platform. Now, at the same time this is happening, my wife, My wife was a Facebook admin. Oh no!
And I was hearing, now this was several years ago, but I was hearing all of these wonderful stories from her about how this broke and how that didn't work. So that really kind of drove, it did 2 things. One is it helped me exit the Facebook platform very quickly. And it also really impressed upon me how much this platform was interesting. I mean, how much this was a problem.
And then of course, I was talking with Julian Assange before he got imprisoned and everything. And, you know, he started doing his WikiLeaks and stuff. And I've, you know, I've met— I was a goon at DEF CON for several years. So the 303 guys that are on the call, props out to you. So I got to meet a lot of really interesting people.
And so I realized that I had this passion for it. And then it just sort of took off, and then I got into the security, I got into the privacy piece, and I thought, wow, this is the greatest thing since sliced bread. So since I've gotten into that, what I've done is through— there's this group that I belong to called the Internet Security Leaders Foundation, ISLF, and we have a mentoring program where we go out to various colleges Merit, I think, is our current one in California, where we mentor people that are actually going through their cybersecurity program. And so we give them real-world experiences. So it's a bunch of people that are in— operate in this CISO function to help guide them into different roles.
So how do you get people if you're brand new? Your question was if they're brand new, how do I— what advice do you have for them? And there are a couple different different specialty tracks in security. At the basis of almost all of them are strong system administration skills because system administration skills are a huge chunk of what's needed in the CISSP exam, which I highly recommend.
And so I would start with that, and then it really depends on where you want to branch out to. Do you want to do pen testing? Do you want to do— do you actually want to do development? Because there are people in security that do development. Some of my employees at platform actually code in various different languages to help us.
Some of them are just internal scripts, some of them are actually— we built a wrapper around Tenable so that we could go off and on demand acquire access privileges to a specific VPC so we can scan it and then drop the access privileges again so we don't have to give it read-only. So these are one of the things that you need to consider. So if you were to have a company like Rapid7 based I think they're in Boulder, aren't they? They, you know, companies oftentimes will have an agent that runs on your VPC, and they have basically got access to everything, and there's no way I'm going to put that in my environment. Right.
So how do you get around that? Sorry, I went on a tangent there. Yeah, no, no, that's perfect. And I think, so can you talk a little bit more about the mentoring project? I don't know if everybody's familiar with that, because I think that's a problem we're really trying to solve as a community.
Right, it's been very— it's been highly received by the people that are in it, both the mentors and the mentees. So ISLF in particular, but there's no reason why those of us here at Colorado School of Security couldn't do the same thing for Colorado colleges, like, you know, like Metro, etc. So anybody that— any college that has a security program, we could create a relationship with and provide volunteer mentoring to the people going through that. And it could be anything from, help me, I don't understand I don't understand this piece in class. So like advanced tutoring.
So a case example for that is one of the classes at Merit, they give you a dump of syslog, authlog, a variety of others, and your goal is to recreate, understand what happened in a breach and recreate it. And then, right? And so part of that is walking through that and showing people, here's what happened, this is what happened, look at the timestamps, look at the IP addresses, where is this actually coming from? All the way to, I need some direction on my career. Should I go to— should I get this certification?
Should I go into the government? And what are the responsibilities there? I've got an Information Assurance Level 2 and I want to get an Information Assurance Level 3. Oh wait, I want to get into the management piece, so maybe is the Certified Information Security Manager, maybe that's the way to go. So as part of the mentoring, we do everything from how are you doing in your studies, to some advanced work on pen testing, because that's typically what the majority of these cybersecurity programs are, all the way through where do I go from my, you know, how did you get there and how do I get to be a security information security, certified information security manager?
How do I get to be the CISO of a company? Yeah, it's funny that you mentioned that because I think everybody who goes into security thinks they want to be the CISO, right? And you have to have one CISO and lots of people who are not. And so, I mean, what do you tell people that they're like, I want to be the CISO of the organization?
Yeah, so the real answer is most CISOs love the job, but it is a royal pain. And it's— and you can just see this by looking at how many CISOs— the turnover on CISOs today. They're dropping like flies. And that's because of the— there's an overwhelming amount of responsibility and direction. They're expected to know it all.
They're expected to be almost almost foolproof, and it's difficult for that to happen. So to build your experience up to a CISO, there's plenty of different tracks for that, but ultimately you have to deal with the principle of application security, physical security, incident management, business continuity planning, disaster recovery, all that stuff, along with your whole heart of certifications that go through it just to start. So you have to have the full breadth of what we consider to be security today. And you can't just have surface knowledge. You have to have in-depth knowledge.
And so the way I describe it is, you know, you could teach it if you had to. Right. So once you have that level across the majority of items, that's probably an indicator that you're qualified to go do that role. And what would really help, if you have the opportunity, is to find yourself a mentor before you get into the job and then after you get into the job. There are CISOs who mentor other CISOs because Because the, again, things are different depending on the size of the company and the nature of what you're trying to protect.
So that's really, that's part of the key there.
Let me stop there. Yeah, no, I think that's a great answer. And I think mentorship is probably a great place to kind of land the interview. So is there anything that I haven't asked you or that you wanted to talk about that we haven't already talked about?
I don't know, we've covered a number of different things. I mean, obviously my privacy is my bread and butter because there's so much work there. You would think that security is where the majority of the work is, but the privacy component of it due to the legal obligations is even more. And we haven't really talked about what happens if you're in a regulated environment either. I know we have lots of people in Colorado Equal Security that are in regulated environments and they, you know, right now they're going, oh boy, you have no idea how bad I've got it.
Right, I know. Cloud security versus physical security, so there's many aspects of it. Yeah, I know, I do think that, you know, we could talk for hours as opposed to the 30 minutes, but well, it sounds like we kind of covered everything that at least was on my mind and your mind, so any parting words?
Stay safe and protect your authentication pathway that is probably Probably in today's realm, so far from what I'm seeing, authentication tends to be the most exposed outside of the typical, you know, keeping up with the patch cadence. Yeah, yeah, and I think it goes back to people are the, you know, they can either be your greatest weakness or your greatest asset, right? I mean, absolutely. Yeah, all right. Well, thank you so much, Joey.
It's been a pleasure to chat and talk more. This is Colorado Equals Security. Everybody have a fabulous year. Bye. Thank you.
Bye everybody. Bye.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.