Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast. This is the first newscast of 2021.
Uh, it's episode 192 for the week of January 4th. Uh, 2021. Alex, happy new year! Happy new year to you, Robb. You know, since we're in 2021 and, uh, the pandemic is officially over, I'm really looking forward to everything that's coming next.
Yeah, I mean, if you, if you look at all the memes, all of the bad things must have stopped because it was all about the year, right? The calendar dictated. Yeah, for sure. Uh, it was a, uh, an interesting holidays though, you know, not quite the same as normal. Uh, anything exciting on your side?
Um, number one, it's, it's, it's kind of interesting because we're already home all the time with work from home, right? So, right, so So staying home a little bit more during the holidays didn't, didn't have as much impact, but my kids were home and that's nice. And we— I was fortunate enough that I was able to see a little bit of family over Christmas. Yeah, I mean, it was good. It was nice to hang with the family and definitely a lot of quality time.
How about you guys? Yeah, about the same here. You know, my wife works for a school district, so she was off and my kids were off. I took some time off. You know, so we had a whole bunch of time sitting around the house hanging out with each other, which, you know, good times.
Lots of TV, movies, things like that, getting some things done around the house, nice and relaxing. And did you watch Wonder Woman 84? I did. Did you hate it like everyone seems to have hated it? You know, Robb, best movie I've ever seen.
You know, I know a lot of people like totally panned it, hated it a lot. I don't know. I— yeah, the premise is, is a stretch, but it's a superhero movie, and I don't know, I thought, I thought it was okay. Whatever, they stretched to get a, you know, a familiar actor into the movie, right? But yeah, I just didn't care that much.
It was fine. Yeah, I think, you know, we talked a little bit about this before, but, um, you know, I expect a superhero movie to have some action, and, you know, for the most part, there wasn't a whole lot of action in the movie. It was pretty slow. So I think that was one of my biggest complaints there. I think that's reasonable.
And I will say what one thing that it did successfully do for me is it made me look at Kristen— is it Kristen Wiig or Kirsten? I think it's Kristen Wiig. Yeah, totally differently than usual. Like, she's, she's like the silly, uh, kind of frumpy, you know, person normally, and she definitely was not in that movie. Yeah, it was a good part for her.
Yeah, it was a good part for her. I agree. Yeah. All right, well, that's exciting. Um, why don't we get some, uh, housekeeping out of the way?
All right, so we're done with the movie review portion of the show. Let's move on to housekeeping. Slack channel, we have a Slack channel. This is a great place to connect. It has been relatively quiet over, over the holidays, but it looks like just this weekend it's kind of picked up again.
I expect that if you're looking to get engaged with your local security folks, this is gonna be a great place to do it. We do have over 1,700 folks in there now, 1,728 as of this very moment. If you wanna join our Slack channel, you can go out to colorado-security.com and click the little Slack link in there. While you're there, sign up for our mailing list at the bottom of the colorado-security.com page, and you will get the show notes emailed to you every week in your email. Also, if you want to, to rate us and subscribe on your favorite podcatcher, that would be wonderful.
Let people know that this is a great podcast and also have this podcast delivered automatically to your listening device every week. You know, I New Year's resolutions are a big thing around this time of the year. And I actually heard from someone recently whose resolution was to tell a new friend about the Colorado Equal Security Movement every day of the year. Whoa. That's— it's not true what I just said, but someone listening, someone listening might be inspired to become that person.
And if so, send me an email and then I can be true in hindsight. You know, if, if you're in search of a resolution, we can come up with one for you pretty easily. So sounds good. Also, if you would like to support us financially, we do have a Patreon campaign. You can go sign up there.
If you sign up for at least $10 a month, you will get some cool swag sent to you. But we love to have people helping us financially with the show, covering the costs that we have, and making sure that we keep this going. And big thanks to the current patrons. We really do appreciate you guys who help keep things moving forward. And we're looking forward to getting to see you in person sometime here this year.
Last thing we'd love if you'd help us do, uh, you know, Janelle Hsia recorded the interview that we're using on this week's show, and we would love to get more volunteers to help do interviews. We have a nice long list of potential, potential interview candidates. If you want to interview someone, you don't know who it should be, let us, let us know and we'll help you get hooked up with somebody for sure. All right, uh, with that, I think it is time to get into the first news of 2021. And of course, we're going to look back on 2020.
Robb, did you know that 2020 was the 8th driest year in Denver history? In, in the 149 years that we've been keeping track, it's the 8th driest year. Only 8.74 inches of precipitation. It's kind of the combination of rain and melted snow. It's only 60% of the yearly normal precipitation level.
Yeah, that's pretty low. I think we all know that it is not— there's not been a lot of precipitation this year. It's been pretty dry. Also, this is just one of 10 years since 1872 that Denver has had less than 9 inches of precipitation in an entire calendar year. So it's definitely, definitely a bummer.
I will say I would have— I think I remember that 2019 was a great year for precipitation, and that basically refilled all of our reservoirs and all. So hopefully, you know, it's gonna, it's gonna bounce back this year, and we're gonna, we're have another stronger year. I do think that there's, you know, some negative trends there, but hopefully, hopefully in the short term we'll be okay. Just one more reason that 2020 sucked. So our next story is actually— it's, it's a story we broke in the past.
Um, the Greyhound Station block, that's what is it, like 22nd and Arapahoe-ish in downtown Denver, has just sold. Um, we, we talked about this, uh, I think about a year and a half ago when it first was under contract. That first deal was supposed to close back in last March. COVID came, killed that deal, and now there's a new buyer who's going to be buying that portion of downtown Denver. Yeah.
This is— it is called the Greyhound Block because that's where the downtown Greyhound bus station was. It is actually between 19th and 20th, and I forget the other the other 2 streets on the side, Arapaho and Curtis. Arapaho and Curtis. There you go. And, you know, this is an attractive parcel because it is a full block parcel.
So, you know, if you're going to build a building, you have the entire block to build something. It is also zoned nicely for builders, and you could make a development that goes as high as 40 stories. And so this, this block has sold for $38 million. And it just occurred to me, I really should have looked up what the last sale was, because my guess is, yeah, significant. Significant discount.
I don't know. I don't know. But man, that the commercial real estate has taken a big dip in the last, well, the last year, right? Yeah, for sure. In the article, they mentioned that they don't have any particular plans yet.
They are still working on that. But, you know, first, get the land, I guess, and then get an architect and, and builder to come in and build something there. All right, well, our next story, uh, we're talking about Denver unicorn EverCommerce. I believe we talked about EverCommerce recently on the show. They just made a new acquisition, and this is interesting, especially in this kind of new remote telehealth world.
They bought a company called UpDocs. Um, what's UpDocs? Um, they, uh, UpDocs is an Ohio-based, uh, telehealth company, um, that does a lot of tele— well, like I said, telehealth, but basically doing like secure online video chat so you can have your doctor's appointments in a secure HIPAA-approved way. They've done over 3.5 million virtual visits just since March. Yeah, and this is something that complements the EverCommerce platform.
They seem to be more a patient office management solution where you can manage patient records and do appointments and things like that. So now adding on this telehealth piece will really help them be a one-stop shop for doctors' offices who want this kind of solution. They didn't say, uh, they didn't say how much they spent on this, did they? I don't know if they did. I didn't, I didn't catch that in there.
Uh, anyway, congratulations to EverCommerce, and probably even more congratulations to UpDocs, who, uh, just had a nice exit, I'm sure. Yeah, good for them. Uh, next we have a story talking about the top 10 tech and startup fundings of 2020, and, uh, on the list are many things that we have talked about in the past, um, but also several cybersecurity startups on here. Yeah, out of the 10, we had 3 security companies, uh, make that list. That's, that's pretty impressive, you know, especially since I would say, what, 2 years ago, even 1 year ago, I hadn't heard of 2 of these.
And, you know, the 3rd one maybe just 2 years ago. So we've got JumpCloud, who, you know, is a new identity, kind of an online directory offering. Um, they, they made— they raised $75 million in Series E funding. Uh, the 2nd one is DeepWatch. This is one that we didn't know who they were What was it, 6 months ago, 9 months ago?
Uh, it turns out they're kind of a spin-out from Guidepoint, I think, but they raised an additional $53 million in funding. Go ahead. Uh, then we also, uh, we had— we had Automox. Sorry, sorry, Automox. I had a little technical problem there.
Uh, I was looking down the list here. Automox was the other cybersecurity startup on there. Um, that was back earlier in the year. They had a $30 million, uh, Series B Also several others that are not security related that we've talked about on here. ColdQuanta, I think we talked about Broomate who raised $20 million.
Pi Insurance. Yeah, Pi Insurance, I know we talked about them. Dispatch Health. Yeah, I don't remember talking about Outrider. Look, anyway, interesting stuff here.
Sondermind, and the last one was Myco Technologies. So if you wanna learn who the up-and-coming tech companies are in town, I think this is a good article to read. And obviously it's just awesome to see security making top of that list. Yeah, for sure. Next, we have an article from 5280 where we— I don't know if we've ever had a 5280 article before.
I don't think we have. But they're talking about 3 Colorado-born next-gen medical wearables. So these are 3 companies that are based here in Colorado that are making medical wearables. One of them we have talked about many times before, and that is CypherSkin. Who makes their smart compression bio sleeve.
They've had— we talked about them getting a contract with the Army, I believe, or some branch of the military. But the other 2 on here are also pretty cool. The first on the list they have is a company called BioIntellisense, and they make— I guess you could call them smart stickers. Yeah, this is really cool. I, you know, my wife is a physician assistant, and as I was studying for the podcast, reading through this, I'm like, wow, you got to check this out.
It's pretty cool. And basically have these little stickers that they call them kind of like applying a Band-Aid that you can put on you to remotely monitor vital signs. And it'll look at things like temperature, blood pressure— wait, heart— sorry, not blood pressure— respiratory rate, heart rate, and temperature. So that's the BioSticker. And then they have BioButton, which is I don't know, some, some little brother of it, um, and it's supposed to be used for contract— it can be used for contact tracing.
Um, so if folks, uh, are all wearing this in the same area, they can talk to each other, and then the system can figure out if anyone who was infected came into contact with you and let you know, kind of like the contact tracing app on your phone, right? Uh, pretty cool. You know, they, they said this was, um, aimed at a little bit more— what was the word that they used? But it was designed to get people back together using these so you could potentially have conferences or other things like that by allowing for the contact tracing. The other company on here is a company called Sana, or Sana maybe, and they are making a direct-to-consumer wearable that helps with pain.
So this is to help wean people off of opiates or other painkillers using this sort of mask to send audio and visual stimulation. Yeah. So, I mean, there's the layman's terms section here. Using coordinated pulses of amber light and sound during 16-minute sessions, the device lulls the wearer into a deep meditative state, frequently promoting sleep. So, I mean, this sounds a little bit like voodoo, but I'm sure there's some science behind it.
I'd love to know that it works. And if so, maybe I buy this and throw out my, my jar of ibuprofen. Yeah, there you go. I think some of it, they seem to be linking sleep and pain. You know, if you're in pain, you're probably not sleeping.
And if you're not sleeping, you're not being able to heal yourself. So I think that getting people to sleep, I think, is also part of this to help them promote healing. Well, I do love getting to learn all about the technology in town. I'll say that that's one of my favorite things about the podcast is we don't just talk about security. I get to learn about other random tech in town, and this is, this is pretty cool for sure.
But now it's time to take a turn and now start talking about the security news. Uh, we have an article this week from eHacking News, which I don't know that site, but they did an interview with Truno. And we've talked about Truno on the show, on the show a couple of times. They're a local, really brand new security startup, and they got their CEO and founder to come talk to eHacking News. Yeah, so, uh, you know, they're building a what they're calling a cyber intelligence platform, but not like intelligence in terms of, you know, feeding to machines, but sort of correlating and bringing together threat intelligence to feed to people.
Yeah, so I've met the CEO and founder Manesh there, and then when he first introduced it to me, he really talked about the fact that there's a knowledge problem out there. And he didn't actually think of it first from security. He was thinking about it from a medical perspective and all of the research and how do you get to the right research quickly enough so that it's usable? And he realized that problem was too big to start with, and he figured he narrowed in on security as a good place to start solving this knowledge problem and making it easier to have the right data at your fingertips when you need to make a decision. I mean, that's a compelling problem to try and solve, and that's what their platform is meant to do, to help give especially security operations teams, incident response teams, kind of your threat intelligence teams, the knowledge necessary quickly around what attacks are out there that might be targeting you, and, and as a result, you can start making some, uh, some preventative measures.
Yeah, and so part of this article is talking about how, uh, they are now moving their platform into a more broad beta version. So, you know, I think that they had a, an early alpha, then it's sort of a closed beta. So now they're kind of bringing this out to the, the larger public to get feedback and get people starting to use it. I'm looking forward to, to getting Manish on our show here relatively soon. We've been emailing about getting them on.
I have had a chance to look at the, at their platform, and it's still a little bit early, but it is, it is clearly going to have some really good value. And, and as they start to, to make it more easily consumable, I'm excited that I think it'll be a really nice thing to add into your security programs to let you know when there's been an attack against an infrastructure like yours. Good stuff. Next, we had a blog from Coalfire announcing that they are one of the first organizations to be authorized to perform CMMC audits. So pretty cool for them.
And I think this is, number one, it's kind of a no-duh. They obviously should be one of the first ones. They have a massive federal practice, but it's also just, you know, yet another validation that they do really good work from a compliance perspective and that, you know, they're at the very fore in terms of helping you get compliance, especially in the government area. So congratulations to them. And if you're looking to do CMMC, which you might want to do if you're a vendor who works with government, uh, Coalfire is probably a good call, our local security company.
Good stuff. Uh, next we have a blog from Virtual Armor. Uh, it is a one of those holiday titled, uh, blogs. This is The Digital Partridges in Cybercrime Pear Tree. And really what they're doing is kind of looking back on what cybercrime attackers were doing in 2020.
You know, how has COVID changed things? Obviously, the move to home had a lot of changes. They threw some interesting stats in here. You know, since the onset of COVID-19, the FBI has seen a 400% increase in the number of reported cyberattacks, and ransomware attacks are increasingly targeting small and medium-sized businesses. I think the other big thing that we've seen increasing since then has been a lot of unemployment fraud.
Lots of interesting stuff going on there. I think, you know, they, they're just pointing out what some of those stats are, and if you want to have a look back at 2020, that's a decent article to do so. Yeah, you know, Robb, I realized, uh, in reading this right now that, um, I'm, I'm disappointed that there's not a soundtrack in the background, um, playing, you know, a, a security version of 12 Days of Christmas. I think that that would have been the thing to do here. I don't think it's too late for you to add it, to add that in, Alex.
I've solar winds.
Well, well done, sir. Well done. Thank you. Thank you. All right, let's keep moving.
Speaking of SolarWinds, um, we have a blog from Dark Owl, and they did some searching through their database of collected things on the darknet and found evidence of many different SolarWinds vulnerabilities on the dark web. So a lot of detail in this, this blog here, but, you know, just them taking a look at what they could find. You know, obviously SolarWinds has been a big deal in the news the past few weeks. You know, just looking for evidence of, you know, how early people might have been targeting SolarWinds. You know, what other things might they have seen that could have given an indication of what was actually going on that we now know about.
What's happened with SolarWinds? This is the first I've heard of this. Uh, is this, you know, you go on vacation for the couple days for the holidays and you shut your brain off and reset? No, it is, it is cool to see that, you know, they're, they're using their database to, uh, to, to look for what's obviously the most, uh, the biggest thing going on right now. And, um, hopefully, hopefully that, that's— hopefully there's not a lot more that comes out of that from, from them.
Not a lot of evidence of breaches of our local friends here. Yeah, for sure. All right, so last story we have here is a blog from— in the security area— is a blog from Webroot. They have a story about how to build a successful security training program in 2021 and beyond. Yes, because you don't want it just for 2021, you want it forever.
And so this is, I think, some good basic information here. You know, first thing they talk about is getting buy-in from stakeholders, and then, you know, starting with a baseline phishing campaign, getting set up with security and compliance training, continuing those phishing campaigns monthly going forward, and making sure that you're communicating those results, raising awareness. I would say maybe even trying to, you know, gamify the results with different departments to make sure people have a stake in trying to be better at doing those sorts of things. Good stuff. You know, we are starting off a brand new year, and it's good to see some of our familiar posters are out there.
Strong work. We had one from Red Canary that kind of mysteriously disappeared from us, but hopefully we'll get something from them next week because they're always a big contributor to the show. I'm sure there'll be more Red Canary blogs very soon. All right, let's hop over— oh, sorry, go ahead, Alex. Before we jump to the Slack Master of the Week, I did do a little research while we were sitting here.
The best I could find on the Greyhound building was an article from October that said that efforts had slowed to sell the property because of COVID but that it was worth more than $32 million. Wow. Well, they did better than that. Seems like they did all right. Yeah, they did better than that.
I will, yeah, whatever. Good enough. Thank you for looking that up. Slack message of the week. Big thanks to Andre Gaeta.
Andre's been doing this for, what is it, 7 years now, 12 years, however long we've been doing this. We do recognize each week one member of the Slack community who inspires conversation, kind of makes us laugh, whatever it is. And that person gets to pick one item from the Colorado Equal Security store, and they can proudly support their Colorado Equal Security swag thanks to Andre's generous donation. Yes, and this week's winner is a new member to the Slack workspace, Coury Ayers. Congratulations, Coury.
Coury got the award for immediately starting a conversation that ended up with a Rickroll, and everyone loves a good Rickroll. Yeah, he definitely helped us degrade the conversation quickly, and of course we appreciate that in the Slack channel. Coury, welcome to the community, and hopefully you can enjoy a new t-shirt, mug, or whatever it is you like. All right, let's jump over to events. We also have events.
Last time we talked, we didn't have any events. That's true. Time has moved on and now we do have some events. Uh, first one coming up on the 5th, ISSA Colorado Springs is having their annual president's address. I think a good thing to start out the year.
So do they gonna have Trump or Biden? Who do they bring in for this? Both. They're both gonna address at the same time. Uh, just to be clear, I suspect it's probably the president of the ISSA Colorado Springs chapter who will be doing that address.
I suspect you are correct. Uh, speaking of ISSA presidents, on the 13th, uh, ISSA is going to be doing their annual CISO panel. They've been doing this for what, 3 or 4 years? And this year, a few former presidents of ISSA Denver are gonna be involved. Yeah, some of those might include you and me.
And James Johnson, I think, will be doing it as well. Yep, I believe James is moderating. Should be a good time. There are also other CISOs that are involved that are not former ISSA presidents, but, you know, we're the only ones that matter. So you should come and listen to us.
You might also want to listen to Artie from DISH or Larissa from the City of Lakewood or Tim from RTD. All quality choices. You know, whichever one that you want to hear the most, come listen to them, but you should come listen. Our final event in the next couple weeks is on the 14th. ACES, the local physical security group, is doing their Mile High Kickoff.
So if you, if you're interested in getting involved more with physical security, if you own both cyber and physical, this would be a good group for you to start to get some familiarity with. Or maybe even cyber-physical. Like a hybrid security. Yeah. All right, that is all of the events we have in the next couple weeks, so we can jump over to jobs.
Robb, I'm going to go out on a limb and say Ping Identity might be hiring for the security team. Oh, I got a slew, a slew of jobs, Alex. Well, we're just highlighting— we do have one new one I'm super excited about. We're hiring a business analyst for the security team, someone to help us with program and project management. If this is something you're looking at doing, either a career changer, um, you know, you don't necessarily have to have a lot of security experience.
We do want to have someone with some either program or project experience or BA experience, of course. We'd love to hear from you. Send me a note on Slack or email, and I'm happy to talk to you about the position. We also have a few others we're hiring, a couple of managers in our GRC team, a product security engineer. If you're interested in any of those roles, reach out.
Sounds good. Uh, KBI Biopharma. Is hiring a director of information security. I actually had 2 people reach out to me about this job, like, hey, do you know anyone good for it? And I'll say the 2 people who asked me, I like both of them pretty well.
So, um, this, this company might be pretty well connected, and it wasn't just from the security side. I, I know some other folks in the tech area there who like it. So if you're looking for a new role, it's up north somewhere, I believe. This might be a good role for you. Uh, speaking of good roles, uh, Denver Health, the, the local kind of, uh, Oh man, what do they call it?
Level 1 trauma provider in Denver. They are hiring a new director of IT security. I think this is a new position for them. Randall Frietzsche is the CISO there. This would be working with Randall.
This person is a little bit more hands-on while Randall's a little bit more on the, on the like policy and legal side, but it'd be a really good opportunity. JumpCloud, who we talked about earlier, is hiring a security engineering manager. And actually, when I looked up the— these jobs, there were a number of different security jobs at JumpCloud. Trustwave is hiring a director of MSS. I assume this is managed security services, but I don't know that for sure.
Uh, I believe that is what it is. Uh, pretty cool for, you know, a big organization like Trustwave to be hiring a director in their MSS group here. Uh, Synoptec is looking for, um, their— it's a security consultant/VCISO. So you're, I think, a security consultant for you know, programmatic sort of things. Yeah, basically working with customers to help them with their own security needs.
Uh, and then finally, Oracle is hiring a cloud incident manager. Um, that's it. I didn't know that that existed anywhere. Uh, good to know Oracle is looking to make sure they're ready for any cloud incidents. Pretty cool.
And, uh, that is the end of the jobs, Robb. All right, well, that— speaking of Oracle, that reminds me, we have an interview this week with someone who used to work for Oracle. She is now more, but Gail Coury, uh, was formerly the CISO of Oracle Cloud. Now she's moved kind of from being strictly CISO to moving over as a GM, uh, for a business unit within F5, uh, called Silverline. I'm super excited to hear how Gail is doing over there, kind of making the move over to the business side.
And a huge thanks to Janelle Hsia for getting us this interview and, um, kind of being diligent and helping make sure we, we have great content for you all. Yeah, this was not the first time that, uh, Gail has been interviewed for the podcast, although The last time she was interviewed, it was both Gail and her husband Steve that were interviewed together, and that was one of the very first episodes that we had. I remember that was sitting in my, uh, in my family room at my house. All right, all right. Well, that is it for this week, Alex.
Uh, happy New Year, and we will look forward to seeing everyone get your vaccines, and let's get together in person. Let's do it. Thanks, Robb. All right, thanks. This is Cole Metzner, IT security and Compliance Officer for Unifocus.
Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals. Well, welcome to Colorado Equals Security. This is Janelle Hsia, and today I'm excited to be introducing and interviewing Gail Coury, who is VP and GM of Silverline at F5 Networks. So Gail, why don't you tell us a little bit about yourself? Thank you, Janelle.
It's nice to be with you all. I know many of the people in Colorado in the area of security because I've been in the business and lived in Colorado for very— such a very long time. But I, just to give a little bit of background on me, I came and moved here to Colorado right out of college and started as an application developer. Actually, my degree is in computer science, and I did that for a while. I think, you know, as people and women particularly, I will say, and back in the day when we didn't have a lot of good access, remote access capability, you know, I was on call for when an application issue or an infrastructure issue would come up and I would have to resolve it.
And I would have to actually, you know, get in a car and go somewhere. Exactly. And when you have little children, that is very difficult for you to be able to manage. And so when I started having children, I realized, gosh, I need to find a more 9-to-5 kind of job where, you know, I can actually use my technology skills and put them to good use. And so I had actually the opportunity to go into IT audit.
Now, this was back in the '80s, so it was before IT audit was really a thing. They— it was required at banks, insurance companies, highly regulated industries, and I would write programs and scripts that would look for fraud. I was working for a banking organization at the time here, here in Denver, and, you know, I would look for credit card fraud, examine many, many records in large databases, and so on. And so I kind of got the bug, if you will. But I stayed in audit, um, probably 8 years maybe, and maybe 9.
Oh, time goes by. I know, I know. So I was working for a company at the time, Galileo International. They were a spin-off from United Airlines and really managed all of, you know, United seat inventory and gates and so on around the world and all of their reservation systems, plus reservation systems for hotels and cars and other airlines and so on. And so I was working in the audit group at the time, and I would, you know, often in my audits identify that there were security issues that needed to be dealt with.
And so there was a time where the security manager decided Because we did a lot of TCP— I'm sorry, we did a lot of SMA, mainframe coins of connections, and because high volume and so on. And the head of security that was running the security team at the time said, you know, this whole TCP thing and firewalls and all of that, I don't get it. I'm just going to retire. So when that happened, My boss came to me and said, have you ever thought about, you know, doing security full-time? And I said, no, not really.
And she said to me, well, we would like you to think about it. We would like you to step in and take this function. And oh, by the way, go fix all that stuff you've written up in all those audit reports. So you found it, now you can fix it. Yeah, exactly.
So that's how I sort of segued, uh, what in my career into security, and I've, I've been in security ever since. I moved on to JD Edwards and became their first CISO in the early 2000s, was acquired by PeopleSoft. Many people in this, in the Colorado area probably remember that, and I stayed on with PeopleSoft as the CISO there. During the 18-month hostile takeover by Oracle, which was in the news everywhere at the time. Eventually, both boards came to an agreement and PeopleSoft was sold to Oracle, and I stayed with Oracle running security teams in varying different kinds of capacities for the— for 13 years.
So 2 years ago, I had the opportunity to move to F5 and actually become a general manager in charge of a business. So Silverline within F5, and of course most people know F5 for its flagship product, BIG-IP, right? And, and, you know, used in thousands and thousands and thousands of organizations around the world. When I was at Oracle, we were a big customer of F5 and And for me, it was a critical component in our security infrastructure. It did reverse proxying for us.
It was a secure device where I would terminate SSL and bring traffic into our data center, you know, and we were also an ASM, Advanced Security Module, user, which is really the web application firewall product that F5 has today. And so I was given the opportunity to come in and run Silverline. Now what Silverline does is it is a cloud-based, uh, service, security, managed security service offering, and we do DDoS mitigation, uh, we do WAF for customers. It's a managed service, so if, if it's too complicated, uh, for you to be able to manage, or if you don't have a a SOC yourself that can monitor 24/7/365. We do that for our customers, and we also do automated bot and anti-fraud detection, and we do that not only on your application estate, but we also do it for mobile, and we, we do things like web scraping and so on.
We can identify when that's happening in your environment, so It was a kind of a startup business within F5 that has grown now significantly in the last couple years I've been there. So I didn't stray too far from my security roots. It's a security service, but I'm probably now more on the business side, which I find very fascinating. And I'm responsible for the overall P&L for Silverline. So that's a little bit about me and my journey and how I got to where I am.
Maybe too much detail for all of you, but that are listening. But, you know, it's interesting how you can move from one kind of point in your career to another. And, you know, who people often ask me, well, did you have a plan? And I'm like, yeah, no, it just sort of happened in the way that it happened. And I'm very happy about it.
You know, I love what I do and love my team I have. You know, multiple security operations centers around the world and so on that are part of our business delivery for our customers. And so I'm, I'm always talking to other CISOs and talking about, you know, the value of the service that we provide for them. So our expertise in this space of application security, which, you know, I think is, is a tough place for security professionals. It's not really how security has grown up.
And many companies struggle at the application layer. So that's what we do. So yeah, no, absolutely. And I think to kind of go back to what you said where you found all these errors and then you were asked, well, do you want to go fix them, right? I think that's something that we see is a segue for a lot of people into security.
And so like when that happened, did they point you in the direction of like, was there classes that you could take or were there mentors or like what was that transition period like, that initial transition period? You know, um, I was always a member of ISACA, um, had been even, you know, when I was in audit. It was obvious I was a certified information systems auditor, so I had a lot of background in, in general controls. And, you know, security is a general control, right? Right.
And so, yeah, no, I, I didn't Really, I stepped in as manager of the security function. I did have a few things, you know, that I had to learn. It was very, you know, interesting because Galileo managed all the seat inventory. This is kind of a little side story for United. And so one of the processes we had in place was if there was ever an airplane crash that happened, then we would lock down the passenger list because we had all of that in our systems.
And there were 2 people in my team that would have access to that list, and there were 2 people from United, and that's it. Because the very first thing everybody wants to know when, and you know, a catastrophe like that happens is who's on the plane, right? And so when you think about how important security can be, In, in many different situations. That's probably a situation most people don't think about, but it was something I inherited in that team. And I, you know, I had amazing people who were on that team that worked as the security issues for the company at the time.
I learned a lot from them. And we talked a lot about where I saw some of the areas that we needed to improve, and we worked on those areas of improvement. You know, those kinds of things that I wrote up in the audit reports. I went on to get my certification, my CISSP. I also— I'm a CSM.
So I believe that's CISM. Yeah, the manager. I can't remember. You know, so I do have that background. You know, but I think you learn a lot on the job.
Yeah. And I remember, you know, when I was, oh, back in the early 2000s at JD Edwards before we got acquired by PeopleSoft, you know, the big thing at that time was all of these network-based worms. Right. And so, you know, we would have, you know, SQL Slammer, you know, we would have issues with, you know, the ILOVEYOU virus and, you know, Code Red and all those things. Things back at the time, at the day.
And so, you know, what we learned is you have to protect your perimeter, right? You have to protect your network, you have to protect things like your mail servers, and so on, you know. So we had all of those challenges that we learned from. I remember particularly the ILOVEYOU virus. I got a call probably at 3 o'clock in the morning, you know, from my head of IT that was working in the APC J or APAC region saying we have a real problem.
And I got up and I got dressed and I went to the office. And, you know, those things used to take down networks and take down systems. That was the big impact. And so we couldn't keep the mail systems up. And I had talked to my team and to the IT guys running the Exchange systems at the time.
I'm like, you have to put antivirus on these Exchange systems. And they were like, oh no, we can't can't do that because Microsoft won't support it, and blah, blah, blah, blah, blah. And so when we got hit with that, and it took a day and a half for us to stabilize the environment, right? There was a big pause at the end, and I had been at the office for 36 hours straight trying to help resolve these issues. We got that antivirus software deployed on those Exchange servers during that period of time.
Like, nobody would run them, and in that 24 hours while that virus was going on, we got it installed and we got the mail system cleaned up and all that, and everything was fine. It didn't fall over, right? IT people are very, uh, they're very protective of their systems, and anytime as a security person you go in and you offer, you know, some new level of control. They're like, oh yeah, no, I don't— I can't do that. Right.
So yes, so the CIO at the time said, next time you need to listen to her. So that was— that's a story from back in the day. Yeah, no, that's awesome. And I think that, you know, one of the things that we learn best from are those situations, right? Um, so yeah, those situations where something bad happened and, you know, we had to recover from it, we learned from it, And then we can, you know, hopefully not make the same mistake again.
So what other changes have you seen over the last 20 years? Oh gosh, a lot. I think the challenges we have today are so much more sophisticated than they've ever been. So, you know, it used to be security was really around controlling system administrator access, you know, internally and then protecting your networks. And many, many people grew up in security in that space.
They came from network engineering, they may have come from being a system administrator, and they had an interest in security, so they moved over into the security world. And they were always very, very, very good technicians, and they were excellent to have on your teams. But I think as you know, we got better at perimeter security and then we got better at host-based security, then all of a sudden, yeah, the, you know, the attackers are looking for, okay, what's the next level of vulnerability that I can exploit, right? And so they started moving up the stack, you know, middleware, then, you know, database, and then you know, application. Then we blew everything up with, you know, not having a perimeter anymore and cloud and, you know, applications being deployed everywhere.
So now, you know, your areas that you have to really manage are— that's still all those things I talked about, but in addition to that, you've got to look at what are your vulnerabilities actually in your application. How are you actually making a secure connection between the user and the application? How are you identifying, you know, that individual user so you know they are who they say they are? And so there's all these new changes that we've had to adjust to over the years because technology is being delivered in such a different way. It's on mobile devices, it's everywhere.
And so, you know, you have to think about what are all of the risks because a security person is the one who looks at how can developers— let me step back a minute— developers develop applications for, I want ease of use for the consumer or the customer. I want to be able, you know, to make sure it has all these fancy features and this functionality to make it as easy as it can be for the individual user to do business with us. What we look at is how can you take what was developed, you know, for good, and how could that turn around and be exploited in a bad way? And what could those hackers actually benefit from if they found a vulnerability somewhere in that environment— excuse me— in the environment? And so I think it's a very different mindset that you have to have.
As a security professional. Yeah, thinking like a bad guy. I think that's actually, for me personally, has spilled over into my personal life, too. I think I look for bad guys in all sorts of situations.
You mentioned that you've had this long career in security and IT, and now you've moved into the GM role. How is it talking to those executives about security? Putting that hat on, what does that look like? You know, I think it's interesting because I have been in the space so long and I have a lot of experience and I've been in their shoes, right? I know how hard the job is and I know how you're trying to be able to do the most you can with the budget dollars you have.
There's always that, right, that weighs heavy on any CISO. And so, you know, having the conversation with them for me is an easy conversation. I can tell them what I think the value of the service offering is. I can say, hey, why don't you give it a try? You know, if it doesn't work for you, that's fine.
You know, we'll do a proof of concept with you. But I do think it's a very different conversation coming from a business leader. I have a security team. That works for me. I obviously have all the SOCs I talked about earlier, but I also have security engineering who makes sure that our services are being delivered with the proper security in place in order for the service itself not to be compromised.
So, you know, I do— I have, like I said, I haven't strayed that far away, but I'm— I have that level of experience that I can have a real sort of heart-to-heart conversation with a VP of security or a CISO because I've done that job for so long. Yeah. And I think that, you know, for a lot of us, it's hard to get that budget, right? You talked about, you know, managing the risk with the budget and getting that importance without using, you know, the fear factor. What, you know, do you have any suggestions for other people who are trying to implement programs That they just can't seem to get, you know, the right ear or the right tone with their executives.
Yeah, yeah, I know early on in my career I struggled with that when I was first in security, and then I started learning more about the business and the company, how we were trying to, you know, engage with customers and so on, and I started thinking, you know, security can really enable the business, um, can help the business move. You know, every company today is going through a digital transformation, every company. And this pandemic that we're— we've been in for the last 9, 10 months has really forced that to even accelerate, right? I see it with our customers all the time because they can't have that one-on-one personal contact with their customers anymore. And the young— younger workforce that's coming in and now becoming the buyers, for example, they're so used to everything being digital and available online.
So your companies have to be able to react and deliver to what the customer expectations are. But how do they do that safeguarding customer information safeguarding PII, safeguarding, you know, the ability to purchase and buy, right? And so security can be there. You know, if you can demonstrate to the business that you are an enabler of the business being more successful in a digital footprint, then you're going to be seen as a valuable member of the team. And when you have then those requests, I think, for some of the other technologies that are behind the scenes helping that security, you know, you have a better chance of making a business case for it.
I think the role of CISO today has moved. I think security— let me step back from that statement a little bit. Security used to be an IT problem, right? And it was really in IT, and IT was responsible for it, and the business they were a blood yes, right? At the end of the day, the business owns the data.
The company is responsible for addressing the risks. They can be, you know, more risk tolerant or risk adverse. It depends if they're highly regulated, not regulated, the industries that they're in. So they can make business choices about that, and I think the CISO role today is more around understanding what the risk paradigm is, having that discussion with your business executives or your board to talk about, here's the risks we see, here's the options that we have to address those risks, you know, educate the board, advise the board, here's a recommendation of what we think we should do, and then talk to them more in business terms. It's more of a business leader position with the ability to translate technical challenges into business language.
Yeah, I recently saw a cute little comic. You know, it was, you know, the Christmas table where there's usually the kids' table and the adult table, and it was the adult coming over and saying, hey, CISO, you can now sit at the adult table, right? That's very funny. It was a cute little cartoon. So yeah, and I think, you know, making sure that the business does understand the risks, right?
That's our job, is to bring that to them and then ensure they have all the information to make a good decision. Um, and, you know, making it their problem. It is a business decision to be made in many cases. Now, there you could argue that some of the basic technical kinds of security is still you know, needs to be what I would call, you know, the basics, table stakes, whatever word you want to give to it. Right.
There are certain things you need to do, right, and that you're expected to do. But if you have, you know, it's interesting, if you are on the board, and I know people who are on boards, organizations that have had very large and significant security breaches that have cost the company not only damage to their reputation, but significant amount of dollars in being able to, you know, put in the right controls, provide the right level of monitoring for victims of the particular issue that occurred. There's, you know, if you just look at that, it would have been so much less expensive to invest in security, right? Right. And so, you know, it's like you don't have enough budget, then you have something bad happen, then all of a sudden you have unlimited budget.
Right. And, and I think boards are, while they're not necessarily technical in nature, Generally, now, if you're in a technology company like I am, our board's very technical, but that's not always the case. You know, many companies, the leader, the board members are, you know, very much business leaders. And so you have to be able to make them understand that there is a trade-off for this, for that, and you have to do it in terms that they can get. You're never going to they're never going to understand firewalls.
They're not going to talk about, well, how many things did we block, right, or whatever in a day. That's, that's not language they understand. So it's really important to, to use the language. Think about who your audience is and where, what level of understanding do they have, and then try to drive your message to their level of understanding. Yeah, I like that a lot.
Think of the audience before you present. That's a really good statement. So you were recently named Woman of the Frontline in Security Magazine. So has that changed anything for you?
You know, I was very honored to be asked to be included in that piece. Has it changed anything? No. I mean, I knew, you know, several of the other women that were also mentioned there. It's a small group of people that are women leaders, you know, and you you cross paths often.
The security profession is small anyway, right? Number of women is even smaller. So, but I do think the important message for me with that article was to say, you know, we really do need to encourage young girls and young women to think about technology as a profession and to think even more seriously about security as a profession in technology. I, you know, oftentimes it's just somebody plants a seed, right? And I remember when I was in high school, um, I was very good at math, uh, that was always my favorite subject, and I was meeting with my counselor And he said, Gail, what do you want to do with your life?
And I said, well, you know, I think I should be a math teacher. That was a very common thing for a female to do. And he looked at me and goes, you should go into computers. Now, I had never thought about it, right? And he said that to me and I thought, oh, that's interesting.
And so my senior year I took a computer class and I was like, I love this. This is problem solving and it's logic and And, you know, I went into college as a computer science major, declared as a freshman, but it was that seed. Had that man, which I don't know that he even knows he had that profound change on me, and, you know, by just that one statement. So I think what we have to do in the security profession is we have to try to plant that seed. In young people, in high school students, in college students, in people who are in a profession that are looking to change, um, that profession.
Have you ever thought about security and IT? We don't have enough people. Yeah, you know, we don't have enough people with skills today, uh, in this space, and it's only getting— the demand is only growing. Because of all the other things I talked about already. Right, the scope is huge now, you know, huge.
So big. Yeah, yeah, it's so big. And so, you know, we've got to find a way to, to, to get that young, younger group interested in this and get them in a position where they can obtain those skills. I think we also have to look at, you know, veterans groups and Lots of other— or, you know, we do some interns in my organization coming out of the military and so on. And then we, you know, oftentimes convert those individuals to full-time employees.
So there's lots of places we can go to try to get this, you know, generating interest, I would say, and get people into this profession. And for me, I think that was a big part of that article is You know, there are women who are very successful here. You know, there are opportunities for you if you're thinking about it as a younger woman. Don't, you know, set aside technology because there's a lot of advantages of being in the technical field. We all are working from home through a pandemic.
There is a lot of flexibility that comes with the job for a woman today. It wasn't always that case when I started out, but today There's certainly a lot more flexibility. And so there's a lot of advantages to this profession and it's a lot of fun, changes every day. Yeah, no, my niece got a VR for her for Christmas and she's all fascinated about how it works. And I was like, absolutely, tech security, tech security.
So I'm planting as many seeds as I can. So, and as we wrap up, so I just wanted to touch on, you are serving as the board chair for ISACA's One in Tech Foundation. And as you said, you've been a member of ISACA for a really long time. So can you let— tell us about the foundation? I know it's kind of new and kind of you're getting it off the ground.
Yeah, and it's a passion I have. Well, I'm at a point in my career where I feel it's really important to give back. I've had a lot of opportunities as I've, you know, made my path through, and a lot of people who provided support and encouragement About 4 or 5 years ago, I was sort of tapped on the shoulder by some of the leaders at ISACA and said, hey, you know, have you— you know, what do you think about starting a women's group within ISACA? So when you look at the membership, and I know probably many of you listening are ISACA members, it's one of the largest organizations of IT, you know, security audit risk professionals, right? And so, 140,000 members around the world.
Only about— we're estimating because we don't have good numbers exactly, but we're thinking about 18 to 20% women and 80% are guys. Right. And so, you know, when you're, you know, you have it— as women, we approach problems differently. Differently. You know, we have different, you know, ebbs and flows around our careers because biologically we are the people who give birth.
So, you know, that's just a fact. So there are times when you can give more to your career and other times where you might have to give less. But how do you, you know, maneuver that? And so we started this group. I think we had a big long name at the beginning.
It was like Connecting Women Leaders in Technology or something that was like a mouthful. We eventually changed that to She Leads Tech. I love that. Yeah, and it was a lot simpler. And, you know, we started having events, networking events, along with conferences.
So the ISACA conferences, they would have a women's networking event. We were trying to encourage women in the organization to actually submit papers to be speakers. We had very few women speaking at these conferences. We wanted to give them a safe place to have, you know, meet other women in the profession, to be able to make those connections, to carry on that connection, you know, outside of the conference. We had a lot of webinars that we, we delivered for, you know, how to develop your leadership skills and, you know, how to, you know, find a mentor and how to work with a mentor.
Or a supporter, different kinds of topics like that. And, you know, we, we couldn't believe how, you know, much interest it generated. I mean, we had huge numbers of women that would join these webinars every month and would come to these networking events at the conference. You know, we'd have hundreds and hundreds of women that would show up and just so happy to be able to meet other women. So as, as we kind of went through that whole process, right, it wasn't really— it was more of a philanthropic kind of thing that ISACA was trying to do versus, you know, I'm trying to, you know, issue more certifications, or, you know, when you think about the business model of a professional service organization.
And so What we started thinking about is, well, should we launch a nonprofit? Would we have a different play in the world of nonprofits to be able to be successful? And so about 2, 3 years ago, we started those conversations. We interviewed a lot of ISACA members. We interviewed ISACA board members.
We asked, what is it that you would like to do? And the surprising thing coming back is, I can support financially this, this kind of endeavor, but what I want to be able to do— I'm passionate about these issues of diversity and inclusion and trying to grow this, the skills in the security profession. I want a service opportunity. I want a way to give back. And so through all of that, we ended up establishing the foundation.
Now, we established the board. About a year and a half ago, and then we spent the first year just getting the foundation off the ground. We had to file a bunch of paperwork with the IRS to be able to become a charitable organization that you could actually donate to, and then we are a 503— 501, sorry, 501. That is the official IRS designation so that, you know, you can actually claim a tax deduction. But we also started with the program.
So She Leads Tech is still the foundational program of One in Tech, the foundation. We officially launched the foundation in July of this year. So just 6 months ago, in the middle of a pandemic, by the way, which is not enough a challenge. Right. And, um, and we've started these programs.
We have a— we not only have, um, She Leads Tech, we have We Lead Tech, which is intended to include, you know, many underrepresented groups, um, and to try to get them interested in this, uh, you know, profession of security and risk and, and to help provide, you know, mentoring and development opportunities there. And then we also started a Young Leaders in Tech, and this is— we've launched a couple of programs that are age-appropriate for middle school to high school-aged kids to help them learn about what is security. We have a Cyber Sleuths program that they can take online, and then trying to engage them as they move on to university and have them actually become sort of the mentors to these young people over time. And so we have a lot of very high aspiration— aspirations with the foundation, but— and it's a very impressive board. I think if you went out to oneintech.org, you'd be able to see the colleagues that I have on the board are amazing in their own right.
To be able to join in this mission to be able to help deliver and maybe level the playing field for people. Technology can really do that, right? And so the whole idea is to be able to, you know, lift up some individuals that might not have an opportunity to think about audit, security, risk as a career and a profession. We can help grow the number of people we have available and give opportunities to those that may not have otherwise had them. So that's the whole goal of the foundation.
Yeah, I think that's awesome. And I, and I think it is, you know, reaching out to those untapped resources, you know, those people who, like you said, maybe didn't think about it or weren't given the opportunity. That's awesome. So are you planning any events here in Colorado with this foundation or any way that the team, the people here listening can support it and learn more about it? Sure.
I mean, any, any person, even if you're not an ISACA member, can go to, you know, oneintech.org. I have talked to the local ISACA chapter. I've also talked to regional chapter presidents. As far as, you know, any kind of activity or event that, you know, we're kind of stuck in doing a lot of things virtual right now. Right.
Right. And so there are webinars. You can go ahead and look at oneintech.org to be able to see when those are. I just spoke at a webinar that was in EMEA. I had to do it at 5 in the morning here in Denver.
So it was like one of those like, whoa, am I awake? I'm not sure. But we did one in EMEA recently. And we have others that are planned. But check out the website, take a look at it and And if you want to get involved, you can certainly reach out to me directly.
I'm, you know, most of you probably know how to contact me, but my email at work is g.cory@f5.com. That's pretty simple. So I'm happy to get you coordinated with what some of our efforts are. And I'm very excited about the foundation. I think it has real opportunity to deliver good.
And so, yeah, no, that, that's exciting. I, I, when I was researching, I looked at it a little bit and I'm excited to do, to learn even more about it. So, well, as we wrap up, is there anything else that you wanted to say? Oh, I'm just so glad to be able to reach out to the group in Colorado again. Um, I, I think I was telling you, Janelle, that when we started that, you know, my husband Steve and I, we've been in the business you know, around the Denver area for so many years.
And we know so many of you personally. And we were actually the very first podcast for Colorado Equal Security a number of years ago. I want to say 3, 4 years ago when it started. And, and, you know, we just are very big supporters of this group. And I'm just so happy that I've had a few minutes to share my thoughts and ideas with you and, and hopefully you know, you've been entertained a little and maybe took away something, some nugget of information that will help you in your job.
So yeah, no, I— for me, it's been awesome. So thank you so much. I appreciate the time that you've taken today, and I wish you have a fabulous new year. Well, thank you. I think we all want to say goodbye to 2020.
I'm looking forward to be more optimistic about what 2021 will bring, and hopefully the end of, of this pandemic is now in sight, and, and that will help us all get back together, see each other. You know, we need that personal touch. We absolutely do. Yeah, no, I agree. So, all right, well, it's been great speaking.
Thank you so much. Bye-bye. Bye-bye. Learn more about the Colorado security scene at colorado-security.org. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.