All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from Casa Bonita, AgentSync, zvelo, Ping Identity, Red Canary, Coalfire, Absio and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript5015 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 227 for the week of October 4th. Alex, how you doing?

I'm doing well. How are you, Robb? I'm doing well. As I was saying the episode number, it occurred to me that 227 was a, was a sitcom. It was, was it late '80s, maybe something like that?

Uh, yeah, late '80s, maybe even into the early '90s. I'm trying to remember exactly when it was. Um, it's funny, um, my wife is a fan of a soap opera, and, uh, Days of Our Lives, if you really care, and one of the actresses from 227 is now on Days of Our Lives, and, uh, I was happy to let her know that. Well, that's amazing. And, and now we have a connection, and now we have a great intro to the podcast.

I love it. We do. Uh, you know what else, Robb? What's that? I went to see a movie tonight in a movie theater.

How was that, Alex? It was great. Uh, really enjoyed it. Uh, we saw, uh, Shang-Chi and the Ten Rings. Uh, you know, new Marvel movie, or newish, I guess.

It's probably almost a couple months old at this point. But that's the first movie I've seen in a movie theater since probably February of 2020. And how full was the theater? Maybe half full. Okay, at best.

Yeah. Yeah. Well, I'm glad you got to do that. And you want to give your, your star rating for the movie? I thought it was good.

I enjoyed it. I don't know about a star rating. But It was a good Marvel movie and a good story, slightly different than many of the Marvel stories, so I appreciated that. And then, you know, if you're a Marvel fan or enjoy being tied into the Marvel Universe, you'll want to see it so that you can continue to be tied in. You know, another sitcom tie-in— the, the main actor, the star of Shang-Chi, is from a TV show called Kim's Convenience.

And Kristen and I have watched some significant Kim's Convenience on Netflix over the last year or so. All right, well, there you go. I did not know that. Yeah, so there's all kinds of, uh, interesting and not so interesting tie-ins for us as we get started off. Hey, why don't we get started off?

Well, you know what, Robb, I have one more fact. Okay, hit me. Uh, we have a Slack channel, and, and in that Slack channel we have over 2,000 people who hang out, talk shoot the, the breeze, all things Colorado Equal Security. It's a lot of fun. There's great conversations in there, and we'd love to have you come join us.

Go to colorado-security.com and you can find the link to join there. And after you've clicked the link to join Slack, once you scroll to the bottom of the page and get on our mailing list so you can get the show notes delivered to your inbox once a week. And if you're done with that and you think, man, there's a lot more stuff I want to do, you can go rate us and subscribe on your favorite podcatcher. You can tell a friend about us. Heck, you could even financially support it— support us through our Patreon campaign.

We'd love that. You know, if you were wanting to go above and beyond and also expand, uh, your personal skills, you know, we always do need help with doing interviews for the podcast. As you all know, we do the, the newscast first and then, uh, hopefully have an interview after. And, you know, it's been harder for us to get that done lately. So if anyone else wants to be a guest interviewer we will be happy to help you, uh, get connected with some people to interview and then put you on the podcast.

All right, good stuff. Let's jump into the news. This is a follow-up from a couple of different episodes, but, um, it's the nearly done version. Uh, basically Casa Bonita has been sold to the creators of South Park for $3.1 million. Yeah, you know, we talked about this when this first broke, and then I think a story that was subsequent to that that you know, maybe it wasn't quite all the way done deal yet.

And now it sounds like they have actually signed a deal, and the only thing that they're waiting for, uh, is sign-off from a judge because, uh, the company that owns Casa Bonita right now, uh, is in bankruptcy court. So they need the judge to approve the deal. But once that happens, we will now have, uh, South Park Bonita. Yeah, it sounds like this sign-off from the judge is, is not a significant concern. Folks don't think that this is going to be at risk, but, um, I'm looking, looking forward to having it be official official.

A couple interesting things to me from this, you know, that $3.1 million might sound fairly good. However, they said that the, the owners are— have about $2.9 million worth of debt in relation to Casa Bonita. So really, they're getting about $200,000 out of the sale. Uh, definitely not walking away with a fortune. Well, you know, I'd say if you are in bankruptcy court, getting anything is probably a good deal.

So A fair point. Yeah, and I, I think it's a good thing for everyone all around, and I look forward to Casa Bonita being the vibrant cliff diving, uh, sopapilla restaurant that it used to be. Well, I can't wait for them to improve the food. Once they improve the food, we can do a Colorado Equal Security event there. I think that would be great.

Uh, I do have to say though, I, I really hope that they keep the sopapillas. That was the, the only thing that I appreciated there. So, all right, uh, next story. Uh, DIA has inked some contracts for about $84 million to start the planning for a 7th runway. I guess I didn't realize that there were 6.

Yeah, I didn't see this coming. Um, I, you know, I, I had heard conversations about additional gates and maybe even an additional terminal past— out past the C, you know, maybe going to a D gates. Um, but this is interesting, the, the plan here about adding a 7th runway. And what was also interesting is to say that this is actually just one step on their plan to build total of 12 runways. Yeah, I don't know if they plan to build 12, but I think that there is room for them to build 12.

I suppose if we continue to grow, then maybe we'll get there. Um, also, if we add this runway, we will now be in a tie with Dallas-Fort Worth International for the second-ranked number of, uh, runways for airports in the U.S., just behind O'Hare International, which has 8 active runways. Yeah. And if you're thinking, well, $84 million to get this runway built, that seems awfully cheap, uh, you're right. The, uh, the price tag to actually do the design and construction for the entire runway will be closer to $1.2 billion.

So that $84 million is just, uh, it's just walking around money on the way there. Yeah, I think if I remember right, they said there were 3 contracts that were up to $84 million, and it was things like, you know, environmental assessment and some other planning pieces that have to go in before you can even start about thinking to actually build. I also think it said if they do move forward with this, it would be something like 2028, uh, when the runway would actually be done. Yeah, so not for quite a while. All right, there's the 3rd annual, um, Inno on Fire.

So this is the— now owned by Denver Business Journals, but the, uh, what was the name of the group? Colorado Yeah, Colorado Inno doing their Inno On Fire list of 50, um, on-fire tech companies here in Colorado. There's a, there's a number of interesting names on here we know, and some that were new to me. Yeah, there were. I recognized a lot of these, and definitely a few of them, uh, were new.

They actually have a bunch of different categories that they break these up into as well. Early stage, um, you know, healthcare, uh, established, you know. So some of it's time, some of it's focus. Um, and you know, this, this is sort of like the nominee section, and then they're gonna pick winners from each one of these categories. Um, so I think in the future we'll probably have a story talking about who from each of these categories actually won for who is on the fire the most.

So there's a lot of names on here that, uh, that we, we've talked about on the show in the past, you know, The Last Gameboard and Guild Education and a whole bunch of interesting ones. But you know what was surprising to me is I don't think there was a single security company on the list. I did not see a security company on the list. Um, there's actually a lot of companies that were not even technology companies. I would have figured there would have been more technology companies on here too.

Yeah, anyway, interesting stuff. And the reason we talk about this is because we think the rest of you out there should probably click this link and see what interesting startups are in town, because there's a lot of cool companies that you're not going to know about if you don't spend a few minutes looking through this article. Uh, Robb, speaking of interesting companies, there is a fast-growing insurtech, which is insurance tech, startup that has now opened a new office in Denver. Yeah. And this is— the company's called AgentSync.

And interestingly enough, AgentSync was also on that last list of 50 companies. Um, I, I— if I had heard of AgentSync, I don't remember it, but they moved to Denver in early 2020 from the Bay Area. They're insurance tech, um, as you mentioned, and they started back last year at about 12 employees in Denver, and now they're at almost 100. They've raised $36 million in that time. And they just got a brand new office building in the RiNo District.

Yeah. And so what they do is they're sort of like a back office software for the insurance industry. And so they have a couple of products in that area now, and I think they're continuing to add more products to that. And it looks like they're going to be— they have nearly 115 employees by the end of this year and trying to grow to 175 by the end of next year. Yeah, you know, the only other insurance technology company I know of is Vertafore, which is also headquartered here in town.

And I think they're, they're the biggest or one of the biggest in that field. And it makes me wonder if, you know, if you just get that hub of companies focused on the same thing and, you know, Vertafore being here brings in folks like AgentSync and others in that industry. I don't know, but it's a, it's a hypothesis that I'm going to just pretend is true. I think that's good. If nothing else, we can wait for it to test itself and see whether it's true or not.

Good stuff. Uh, so next article is from Zvilo, and we, we picked this one because I, I think this is a topic that you and I have talked about recently with some other, uh, of the members of the community, and it's becoming more and more interesting to me, um, as we go. So the headline is Cyber Threat Intelligence for Secure Access Service Edge, which is SASE. And, and basically this is Zvilo doing their intro blog to what is Secure Access Service Edge, what is SASE, and, and why does it matter. Yeah, and then, uh, you know, of course they do threat intelligence, and so, uh, them talking about how it is that threat intelligence can play into SASE and why it's important.

Yeah, and I'm, I'm mostly— when I read it, I don't know if you got the same read— I mostly thought it was just, um, the— maybe the author or someone else at the company was like, what is this SASE thing? And they did some research and they're like, Well, uh, now we know what it is, why don't we share that with the rest of the world? Because, uh, because folks will find it interesting. And frankly, it is interesting. And those of you who don't know what SASE is yet, and maybe you've heard the acronym and just like me, you've rolled your eyes most of the times you heard it, I think it's worth understanding.

And, and I, and I'll say, I, I do believe that over the next, I don't know, 10, 15 years, that this is going to take the place of most on-prem network edge devices, you know, your firewalls and your web access gateways and IPSs and all that. Yeah, I hope that it doesn't continue to be called SASE, but, uh, I think that the, the idea and the technologies behind it will probably be around to stay. Um, I, I do think it's interesting too, in general, that, uh, you know, it used to be we would see Zavilo articles that were talking about things that they did, but then it was kind of like, well, you know, go find a provider that actually uses our services on the back end because they You know, they were sort of white-labeled or, you know, added to other devices, but they've recently added, I think, some direct-to-consumer kind of services too. And so we're starting to see more blogs from them talking about these services and how you can plug them into your existing infrastructure. Good stuff from Zvilo.

It's nice to hear them chiming in with some, some good educational content. Indeed. All right, Ping Identity announced an acquisition of a company called SingularKey. And I'm sad, Robb, that I can't just turn to you and say, what's this all about, Robb? You surely know about this because you may not anymore.

Yeah, I had never heard of SingularKey and I was— I actually read this. You know, I'll confess to the world here. I don't read every word of every one of the articles that we go through. I probably read every word of this press release twice. And, and I am still not sure I really understand what SingularKey did or does.

Yeah, this is, um, this is definitely a press release. Uh, there's lots of buzzwords in there, and they, they— there are many, many words in here, and in my opinion, they don't add up to a whole lot. Um, I, I'm glad that they acquired this company. To me, it sounds like, uh, SingularKey is maybe, um, you know, sort of like an API integration engine but for the identity space. And then they've added a, you know, a bunch of other things around it to make it sound cooler than it is.

Yeah, I'll tell you, so I, like I mentioned, I did read it multiple times to really get it, and then I talked to some folks. And so I think I understand the real problem that Singular Key is helping solve is, you know, for any identity provider or anyone who wants to integrate with lots and lots of companies. It's really hard to build, you know, custom integrations that work for your SaaS app because every SaaS app works differently. And, you know, there's a ton of maintenance to make those work. SingularKey has made it easier with the, the no-code, low-code, um, integrations that they have with different SaaS apps.

And this should make integrations easier for Ping customers and, of course, you know, for, for Ping developers as well. Yeah, and I mean, it's nice that they're saying it's no-code, low-code, you know, whatever. But, you know, I really think of those no-code or low-code applications as things that, you know, you can use to make integrations. And, you know, me reading this, it sounds like they have already done those integrations so that it's easier for you to use those things as opposed to you, you know, having it anyway. Um, but I'm glad for Ping.

It seems like this is going to help them integrate with more platforms, and, uh, that's always good. Yeah, I think, I think it should make it a lot easier for Ping customers going forward. All right, from my previous company Ping to my current company Red Canary. We got a Red Canary blog this week. This is by the great Katie Nichols.

If you guys haven't got a chance to check out what Katie produces, you're definitely missing out. This week she wrote a blog, So You're Thinking of Starting a Cyber Threat Intelligence Team. Alex, what is this all about? Yeah, so I thought this was an interesting read, another pretty good in-depth blog from Red Canary, not nearly as technical as some of the other blogs, but great nonetheless. So, you know, this is talking first about, you know, what cyber threat intelligence is, and then how it is that you might go about starting a function in your company for yourself.

So things like understanding what your requirements are and getting the, the people part of the team together, then, you know, figuring out what the data is that, that you're going to use for intelligence and acquiring that. You know, setting up tooling, essentially creating outputs or products from this tooling, and then being able to measure what you're doing to show that you're growing and getting better. Yeah, what I appreciated is that they start off by talking about, you know, some reasons why it might make sense for you to do this. And I think it's useful for, for leaders not to just go build a thing because there's a thing that could be built, but to be thoughtful about, about Are you— do you actually have problems here that are— that this new capability could solve? And if, you know, if the answer is yes, then Katie gives a great roadmap for how do you do it.

And I think for most companies, the answer is probably no. If, you know, you're probably not good enough at vulnerability management and change management and whatever, you know, whatever other core capabilities you need to have in order for it to make sense for you to go build a threat intelligence team. Yeah, I would agree with that. I think most companies, you're probably going to, you know, go to a different company that offers products like this that you can plug into and have them perform this service for you, as opposed to building your own team. I feel like you have to be a little more mature, a little bigger to actually do that, but pretty cool.

But if it is time for you to build it, you know, take a look at this blog post. And, and I bet you, I bet I'm signing her up. I bet if you reached out to Katie on Twitter, she'd probably give you some advice as well. I'm sure. All right, uh, next, um, everyone's favorite topic, uh, blog post this week from Coalfire talking about HITRUST and some changes that are coming up around that.

That is my favorite topic, Alex. I know, that's why I said it, Robb. Yeah, just compliance in general is, is so much fun, and, and HITRUST is, uh, is maybe the best of those. You know, HITRUST, you know, for those who don't know, it really started off almost exclusively, I think, as a healthcare-focused compliance framework. But I'd say over the last, you know, maybe 5 years or so, it's changed from being, you know, just healthcare-focused to really being more comprehensive than that and other industries using it.

And there's a— so number one, a lot of value in terms of just using this as a way to talk about your program. But then this particular blog post is talking about these big changes coming, and they say that these are going to be the broadest changes that that Hightrust has had ever in its existence. Yeah, so, uh, coming up in 2022, version 10 of the Hightrust CSF will be released. But in the interim, uh, with version 9, there have been a number of small changes that have been released, and those are going to also get rolled into version 10. But this blog post breaks down a lot of those small changes that have happened recently so that you can stay up to date and make sure you understand those changes if you are trying to be Hightrust certified or you already are and and need to be recertified.

So I don't know that I'm going to go through many of them here, but, um, but definitely check this out if, uh, HITRUST is in your wheelhouse and you need to know what's going on there. Yeah, you know, you mentioned that Red Canary often has technical blogs. This is a very technical blog, but in a compliance perspective, like, it's, it's very in-depth. There's a lot of information here. If you're someone who needs to know about HITRUST, I highly recommend taking a look at this blog post.

Yeah, lots of detail there. Uh, all right, last one. And I get excited whenever we get a, uh, an article from a company that we haven't talked about in a while. And we haven't talked about AppSecio in— man, I feel like it's been years. Uh, we, we had one of their co-founders on the show, I don't know, maybe 2 or 3 years ago, but we haven't had anything from them in a long time.

Yeah, I feel like that interview may have been in the first year of the podcast. It was very early. Um, and AppSecio, they do data security. And this blog post is talking about— well, the title is The Physicality of Data and the Road to Inherently Safer Computing, which is an interesting topic. And they go on to define what inherently safer computing is and how it related to some non-technology pieces, and then some potential ideas of what we could do around getting there to inherently safer computing.

Yeah, I don't know if you noticed this. We got this article from the AppSEO blog, but it was actually cross-posted. It was originally posted on Forbes.com, written by— is it Dave Krueger, right? It is. Yep.

Yeah. And Dave was the guy who we talked to on the show a couple of years ago as well. It is. You know, I'd say that one of the things I liked about it is this is not a sales pitch. This is a— it's more of like a thought leadership type of a post where he's, you know, talking conceptually about ideas that maybe we don't know how to do at all right now.

This idea of inherently safer computing, the analogy they talk about in the article is back in the, I think it was the '70s, there was a number of chemical engineering accidents that caused human casualties, and they really rethought how engineering for those types of plants, anyone working with that type of material would work. You know, it went from saying, hey, let's put, you know, mitigations in place in the, in the factory, to saying, let's change the way we address this dangerous material from the very beginning. And, you know, when you think of that as a, you know, as a parallel to how the types of problems we have in security, it makes a lot of sense that, that they're thinking that, you know, we need to really rethink how we use data and how we use those, that's those sensitive systems, um, well before we put a WAF in place or we put antivirus place on the computers. Yeah. I think it's a pretty good analogy and a pretty good parallel, comparing data to unsafe chemicals.

Again, to your point, they were talking about how with that industry, they would not really think about it until the end, and you have to build a whole bunch of safety systems and things to clean up messes and everything when there were accidents, as opposed to Uh, really thinking about how to make it safe from the beginning. And, you know, we've talked about that at a high level in security forever, you know, uh, shift left, get, you know, get in front of this, build security in. And, uh, and if you can really make the, the data secure from the beginning, then, uh, it makes it a lot easier in the end. Yeah, well, that is, that is, uh, the, the blog post this week. Let's go ahead and jump over to our— what do we got next?

Our upcoming events. Um, there are just 2 events in the next 2 weeks. Uh, still, I think we're, we're suffering a little bit of that, that gap. I don't know exactly what it was, but early October there wasn't a lot of stuff going on. Uh, but we do on the 13th and 14th have a 2-day job fair that's being put on by Spectrum/Charter, and they're looking for a lot of IT jobs, including a number of security jobs.

And then on the 15th, uh, there is this, uh, Dustin's group talking about application security testing tools. Sure is. Yep. The unnamed application security group. The, the, the group formerly known as, I don't know, Dustin's group.

Exactly. It really— I love that, you know, they're going to be talking about different kinds of tools and when you want to use them in the process. Good stuff. That's great. And all right, jumping over, only 2 events we had.

Yeah, let's go ahead and jump over to jobs. I do have a couple of jobs at Red Canary right now, looking to hire multiple product security engineers. If you're someone with an application security background, um, we'd love to talk to you about those. Reach out to me on Slack if you want to talk And we're also looking for an IT support manager headquartered here in Denver. Fluid Truck, which is— was on the Colorado Inno Hot or 50 on Fire list, they are looking for an application security engineer as well.

AXS, this is the, uh, the ticketing/events company, is looking to hire a security engineer. Alex, is that here in town? Uh, it can be here in town. That is one of the, the companies in the Anschutz portfolio if you want to work in ticketing, it's, it's a pretty cool environment, um, and you're a security engineer, um, you can reach out to me. I might be able to give you a couple other details.

Awesome. Zayo is looking for a senior manager for corporate cybersecurity. This is basically running the security program at Zayo. Oh, awesome. Uh, Gates Corporation is hiring a senior security threat hunter.

That sounds like a lot of fun over there. Yeah. Uh, Regis University is looking for a director of infrastructure operations and security. I posted this one because it could be fun since, uh, Regis had that big ransomware attack not too long ago. I bet that they're a little more well-funded right now and, and have some initiatives around security.

They sure could use it. Absolutely. Dish is hiring an AWS security engineer. Yeah, if you know any of those that aren't working already. Um, Alteryx is looking for an application security engineer.

And finally, Lumen is hiring a vice president of security development. This is, uh, Mike Benjamin's job over there. Mike is moving on to his new thing. We don't know what it is yet, but I, I think we'll find out any day now. Yeah, so if you always wanted to be Mike Benjamin when you grow up, now you can be.

I— they can't be Mike Benjamin, come on. Well, I mean, don't get their hopes up. If you want to wear Mike Benjamin's old shoes when you grow up, then, then you now have that chance. It's a pretty cool job from what I understand. Yeah, I think a lot of— and that is running Black Lotus Labs, which is the coolest part of Lumen.

So, uh, that sounds like a pretty fun job. Yep. All right, well, that takes us to the end of the newscast. We do not have a feature interview this week, so people can go, uh, can go— I don't know what you do in your free time, everyone, you know, clip your toenails or whatever it is you have to do today. Go outside, uh, enjoy this great fall weather.

All right, that's it. Have a good one, Alex. Thanks, Robb. Learn more about the Colorado security scene at colorado-security.com, where you can information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes