All episodes
Episode 229 October 31, 2021

Mike Pedrick, VP of Cybersecurity Consulting at Nuspire

A longtime pillar of the Colorado security community. Interviewed by Frank Victory.

Our featured guest on this special episode is Mike Pedrick, VP of Cybersecurity Consulting for Nuspire. Mike has been a longtime pillar of the security community in Colorado. He sat down with Frank Victory for this interview.

Read the transcript6666 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood.

Welcome to Colorado Equals Security. This is a special Halloween episode. We do not have a newscast for you. You know, we're still taking a little bit of a break, but we did have a feature interview we wanted to share, and I figured I'd jump on and say happy Halloween. If you're not signed up for our newsletter, you should probably get signed up on that mailing list at colorado-security.com, as we have been sending out show notes.

I guess it's not show notes, it's just, it's just news each week in the mailing list. So you can find out what's going on, even though you don't have me and Alex to give you our witty and ignorant commentary on those things. Anyway, this week we do have a special interview Frank Victory sat down with Mike Pedrick for you. 2 great community members here in Colorado, and it's a great conversation. Look forward to sharing it with the rest of you, and we'll talk to you again soon.

Hi, this is Curtis Letson, the CISO for Pulte Financial Services, and this is Colorado Equals Security, for Colorado security professionals by Colorado security professionals. Welcome, Colorado Equal Security. My name is Frank Victory. I am a senior security consultant and a member of the Denver OWASP board. I'm also an educator, and I have— I'm lucky enough to have with me today Mike Pedrick.

I'm saying that correct, hopefully, right? Yep, absolutely right. Right. And Mike believes that all businesses are at risk— hackers, crackers, nation-states, and bad actors. Uh, small and medium-sized businesses have to defend themselves against the same threats as major corporations, but they have a lot fewer resources at their disposal.

Who helps small business leaders navigate these murky waters of risk management, governance, compliance, privacy, and guerrilla marketing campaigns? Well, the answer is Mike is one of those people. So welcome, Mike, to Colorado Equal Security. Thank you. Thanks for having me.

Thank you. So, Mike, Before we got started with the podcast, we were talking a little bit about you. And, uh, you know, for those of you that can see on camera here, right, you have a— looks like a Corvette and a Tesla breakdown model. Is that what you call it? Yeah, I think, uh, blueprint, uh, blueprints, uh, they're, they're more art than they are technical specifications, of course.

Okay. But, uh, Um, I like the way, I like the way they tie together a couple of my interests, current and, and in the past. And of course they look good on, on camera as well. Okay, awesome, awesome. So, uh, Mike, before we start talking about some of the cars and your background, uh, what did I miss in your introduction here?

Can you tell us a little bit more about what you're doing now? Yeah, no, absolutely. So, uh, you didn't miss much, uh, generally speaking. I transitioned into IT security, um, gosh, a handful of years ago, uh, 2013 or so, uh, when I moved into security almost exclusively, largely because I feel like the small and medium-sized business space is grotesquely underserved in this capacity. There's a lot of folks who, uh, you know, are, are, you know, they don't necessarily know what they don't know, and they've been, you know, making it, making it away, or making their way, uh, keeping the lights on but not really doing service to, to risk or security.

And then bam, they wake up one day and there's a ransomware outbreak, or, you know, something is down as the result of an attack, you know, whatever the case may be. And actually, that's, that was one of the motivating factors for me. I was running IT for a manufacturing firm, and we had a audit requested, I will say requested politely, by our insurance provider. And they ate me alive. They asked what I was doing.

And I thought, you know, admittedly smugly, I'm doing all the right things. I've got a good firewall, kind of end of list, right? And, you know, again, not a great score, not a great score at all. And so at the time, I decided, boy, I gotta I've got to get a whole lot more, you know, smart about these concepts. I got to get a lot better at this as soon as possible.

And at that time, again, I sort of woke up to the notion that, gosh, if I'm, if I'm feeling this way, you know, others have got to be feeling this way as well. And absolutely, that's been my experience. Okay, so you mentioned, you know, you don't know what you don't know, or what, at least they don't know what they don't know. They didn't get a great score. So that was a motivating factor to try to go out there and help other people really understand what's happening in their cybersecurity space.

Absolutely. And, and, you know, one thing I want to put out there too is that, uh, I'm very strongly of the belief that most of these folks, most of the folks that, you know, we're talking about, we're talking about IT folks, right? Mid-market space, small and medium-sized business space. These are CIOs, CTOs, but they're often wearing just a director title because the organization doesn't have a C-suite to speak of. They're not big enough.

They're not you know, they're not willing to wear those titles, right? So these are small, small organizations just trying to keep the doors open to grow the business and keep going to the next day. We're not talking about the big guys that have seemingly limitless budgets, et cetera. And these folks are, they want to do the right thing. They want to do, they want to protect the environment.

They want to make sure that everything is up and running. But it merits mention, of course, that that's a very different charter than what we talk about, right, as security professionals. Security professionals, we have, you know, in our lexicon, we have things like forensics, we have things like, you know, I want to do an analysis, I want to go through and, you know, the eradication, containment— I've got that a little out of order, but anyway, we think in those terms, right? These are folks who are thinking in terms of availability. Their charter is, you know, lives and dies by availability.

If it's the middle of the night and something has gone down, these guys are trying to figure out how can I get this up and running now instantaneously, because the business is suffering. They're not thinking in terms of forensics. They're not thinking in terms of, you know, what does this mean? Is this part of a larger attack that I'm going to find out about down the road? Right?

Okay. And, uh, for better or for worse, I think there's nothing wrong with this, right? This is, this is their charter to keep things up and running. And so what I, what I try to do is, is just bring a perspective to organizations to say there's, there's a little bit more at stake here because, you know, something like 50% of all attacks are on small and medium-sized businesses. You know, they are an easy target.

They're not an organization that's going to absorb a major attack in the news, you know, do a little bit of PR, uh, you know, maneuvering, and then be back to status quo the day after. That's just not the case for a lot of these guys. It's, it's closing the doors immediately after what some of us would consider a fairly mundane ransomware attack, for example. Okay, so basically they're, they're focused on their business, they know how to run their business, but cybersecurity might just be something totally different to them that they don't have any expertise in. Exactly.

It just hasn't been a priority. They haven't needed it. It's like the, uh, you know, the, the notion of, um, extended warranties or insurance or whatever. There's folks, you know, here, actually, I'll give you a different example, right? The folks that have and maintain a fire extinguisher in their kitchen have experienced fire in the kitchen, guaranteed, right?

Okay. And, and the folks that, uh, you know, have never experienced a fire in the kitchen, this is not top of mind for them.

That is actually, I think, a really, really great analogy there is, you know, they've been hit once and now they know how to prepare for it. So some of the things that as cybersecurity professionals, especially those that want to help the community, we try to get them to say, well, there might be a fire, maybe you should have a fire extinguisher in the kitchen before you actually, you know, have that fire. Exactly, exactly right. And that's what I try to do. And it's, you know what, my part of my philosophy is that, uh, um, I don't try to sell FUD— fear, uncertainty, and doubt.

And I'm never going to threaten a client and say, if you don't sign this 7-figure statement of work, gosh, I don't know what's going to happen. You know, the Russians are going to come in, or, you know, whatever. Um, I don't like that model. I really don't. Uh, I think that that's a It's a gamble that's paid off for, for some in the industry, I suppose, but I feel like there's a date with destiny.

Eventually it's not going to work. Okay. Okay. Well, you know, before we dive more into the subject here, let's talk a little bit more about your past. Uh, I understand that at one point before you got into IT security, actually, you were an architect.

Well, I never was a licensed architect, but I thought I wanted to be. And so I got as far as, uh, participating on some really great teams that, that had really good projects in the, in the Denver area. For example, I was on the team that did the complete and total renovation of what used to be the Denver Auditorium Theater and now is the Ellie Calkins Theater, uh, in the Denver Performing Arts Complex. An interesting footnote, uh, you know, I lived and breathed that project for, gosh, the better part of 3 years I have still never been inside of the building since the renovation was completed in 2005. So you designed it, but you'd never been inside the building, right?

I can't take credit for doing the design. That goes to Peter Lucking, brilliant architect. I think actually today's his birthday. But again, I was on, I was on the team, very definitely a participant in that process. But man, I can't take any, I can't take any design credit for that.

But I washed out of that career because You know, it turns out, in a lot of cases, this is sort of the minutiae of architecture. A lot of folks think that architecture is becoming the next Frank Lloyd Wright or the next Frank Gehry, and your designs are going to be talked about and discussed as paragons of the industry for, for decades. And the truth of the matter is, even if you cornered a Frank Lloyd Wright, You know, it's like art, it's like Picasso's art, or, you know, you're famous long after you're dead. And realistically speaking, especially for architects, you have to pay the bills. And what I was— what I got frustrated with, I think, was the notion, the, you know, really mundane notion of sitting across the table from a client and discussing paint colors and discussing, you know, how many seats they could get into a restaurant, you know, the dining space of a restaurant, when I was worried about getting a certificate of occupancy based on a number of other challenges.

And I decided at that point, I'm not, I'm not cut out for this because I'm more focused on the project and more focused on completion. I'm more focused on making sure that it's done in an efficient manner so, so that we don't burn through all of our fees. In the process than I am again getting the exact right Pantone color for the paint that's going on the wall. I just, I don't, I don't care. So, okay, well, obviously that, that attitude has helped you in your current career.

Yeah. But how do you go from designing things to cybersecurity, or even, or I guess even IT? That seems to be kind of a little bit of a totally different turn, right? It does. Yeah.

And actually, I can pinpoint it, um, pretty well. I was doing a brief internship for an HVAC engineering organization. And they did plumbing and electrical as well. But I had a— the computer that I was tasked with using or was trying to complete my day with was an old Pentium. It was a Pentium, I think, 100 at the time, and Pentium 100 MHz.

And it was constantly breaking, like there was always something wrong. And so there was always a, you know, I would get a little bit of work done, and then I have to, you know, throw my hand in the air and say, you know, IT guy, I need you to come, you know, make this work again. And so that pushed me into computers. Before that, I didn't even own a computer. I had never even, you know, owned one myself.

Worked with them a little bit in high school, but otherwise, you know, not, not a whole lot of exposure. But that notion that this thing could get in the way of productivity, you know, shoved me into technology, into working with computers, etc. Okay, so I myself have had a similar experience. I was actually studying to be an attorney and my computer kept breaking and I kept— I called the company, they're like, oh, it'll be, you know, $150 for someone to come out and fix it. I'm like, I can't afford that, I'll just figure it out myself.

And great, I did. And then I started helping other people and, well, started my career. So perfect. Uh, okay, so Mike, I also understand that you've been married for a while, right? Yeah, uh, you know, I— my wife and I both pass for, you know, being in our 30s at best, but we've been together for 24 years now, married for 21.

Um, I could not possibly have gotten where I am without her. Okay, well, I think a lot of us feel that way about our wives. Now, uh, any marriage advice that you can give, and specifically maybe, uh, a spouse where, you know, one's working in cybersecurity? Is there anything specific about that? Yeah, uh, some hills are not worth dying on, which I think is a good general statement for anybody who wants to stay married.

But also, my wife is not tech savvy. She is certainly not security-minded. Every time I see her on her phone just scrolling through random videos, I'm thinking, oh God, you know, or, you know, she starts complaining because what the controls I have on the network are blocking something she's trying to get access to. Like I said, some hills are not worth dying on. Sometimes you just say, okay, show me what you're trying to click on again.

Let me, let me take a look at that. Let me, let me just make sure that that's okay and safe to click on. Maybe we find an alternative for you, you know?

Yeah, definitely. Yeah, I definitely know that one. My wife, I think you and I are in the same boat with that. You know, I actually had to remove and put DHCP back on my network because it was driving my wife crazy. So Okay.

So when we started the conversation, we talked a little bit about Teslas and Corvettes. You're a car nut then, a car guy? I am, yeah. And that actually goes back a really long way and not dissimilar to how I got into technology. I bought my first car.

I had to buy my first car in order to learn how to drive. And, you know, limited resources at the time, I bought a 1976 Pontiac LeMans that didn't run, and I proceeded to sink all of my money, all of my working, you know, all of my paychecks into trying to get that car to run and learned a lot in the process and sort of got hooked. And so it's been, you know, 25, 26 years, something like that, since then that Very seldomly do I leave a car alone, right? Like, I'll buy cars and I'll, you know, hey, I'm gonna modify it in some fashion. I'm wrenching in the garage.

I have friends come over and, and we have, uh, you know, you know, drink beer and tell jokes and throw wrenches around the garage and cuss and swear a lot. Um, and then actually might work on the car at one point, right? Yeah, sometimes, right? Yeah, sometimes, right? This will only take an hour, and then 9 hours later, you know, it's still not done, right?

So 9 hours and maybe a case of beer, right? Yeah. And it's funny, you know, you learn somewhere along the line that you never modify the car that needs to get you to work the next morning because Sunday night at 10:30 when you're, you know, your forearms are covered in grease and it's still not right, you know, you're just beaten. But it's part of the love. Well, that's a good lesson learned, right?

Don't work on the car that needs to get you to work. Exactly. Exactly right. Perfect. So Outside of work, while working with your cars, you also participate in some rallies, something like a multi-state rally?

Yeah, actually, uh, in 2012, a friend of mine through, uh, a car club that I was a member of at the time had reached out and said, we're doing this, uh, this thing for charity and, uh, I want you to participate. And so that first year, actually, hold on, uh, the group is called Rally North America, right? rallynorthamerica.com is their website. But what they do is they set up these these multi-state rallies, and it's always off of major highways. We try to stick to, you know, more rural areas, but, you know, for example, you know, Route 66 was a rally, I think their first rally, and some of the rallies I've participated on have been from, you know, Billings, Montana to Portland, Oregon, all across the Pacific Northwest in the process.

We started one year in Um, Erie, Pennsylvania, and ended up in Old Orchard Beach, Maine. Now, the, the really great thing about the rally events, of course, is that, uh, we don't know where we're going until we get to the starting line in the morning and they give us a route card. And the route card has clues, uh, you know, you got to figure out what the clues mean, where the, the thing is that you're trying to find, and how to get there. It's And it's, it's a game of navigation because if you get a speeding ticket, you're disqualified. If you get caught being, you know, uh, you know, driving, driving recklessly or whatever, you're disqualified.

You can't participate anymore. And so, um, you know, like I said, you get to the, you get to the starting line, they give you your route card, you figure out where you're going on the fly. So you're reliant on a good navigator. Uh, your place in the grid— this is where this matters— your place in the grid every morning is dictated by how much money you raised for the charity for the event. And so it's become, it's become a bit of a competition amongst a lot of us.

You know, there's 85 teams that, you know, in this event, right? Uh, there's a bit of a competition between us on how much money we can raise. And it's, it's gotten brutal. In 2012, I won pole position, you know, first in line, uh, on $3,500. I raised $3,500 for the, for the charity.

And now $3,500 puts you somewhere around 50th in line. Okay. And it's— so it's insane. I mean, it's— there's guys that have raised $20,000 for the charity just to get, uh, you know, pole position. And, and it's— and it— there's no money in this.

There's no— we don't win anything, um, other than, you know, pride and, and the, the joy of doing this thing. They often say that, um, the organizers of the event say that, you know, we plan your vacation for you. Thank you for, for participating. We've seen parts of the country that we otherwise would never have gone to. You know, I won't say voluntarily, but never would have known that would be worthwhile to go to, uh, if not for these events.

Well, I think you do win something, or at least the charity wins something. Do you want to talk a little bit more about this charity? Yeah, absolutely. So we pick a different charity every year. Um, there's been multiple sclerosis charities, there's been Um, you know, charities for like Hope for the Warriors, for example, has been a recurring charity.

And actually, one of the recurring charities that I have, uh, you know, that I think about a lot is Camp Sunshine. Camp Sunshine is a— there's a lake in Maine where they have, you know, they own a significant amount of the property around the lake. And what they do is children with life-threatening illnesses who have been diagnosed with life-threatening illnesses and their families go to Camp Sunshine and spend a week for free in the presence of, you know, doctors and psychosocial professionals who can, you know, help them with their conditions and also other families in the same, in the same boat, so to speak, right? And so the kids get to do hiking and fishing and boating and, you know, activities, etc., again, in a very inviting location. And I was fortunate enough, my wife and I were both fortunate enough in 2019 That year's rally took us into Camp Sunshine, and we got to talk with the folks.

And, you know, kids— we were giving out Hot Wheels cars to kids. And, um, it's a very— it's a humbling experience. It's very, uh, you know, it brings perspective, I'll say. And, uh, the, the doing things for these charities, doing really, really good things for these folks— the first several days of the rally, you're thinking about finding checkpoints and driving around and seeing things and, you know, checking out each other's cars, and it's the camaraderie of being in a car club. And then you hit Camp Sunshine and everything, you know, everything crystallizes and you understand really why you're doing this thing.

And I'm saying Camp Sunshine specifically, but I mean, every year it's the same thing. We figure out why we're doing the thing that we're doing and then go have fun, you know, seeing rural America and finding checkpoints, etc. Well, that sounds really awesome. I mean, especially you're doing what you love, you are helping people that are in need. Um, are you always successful though in, in, in this rally?

I'm never successful in the rally. I guess it depends on how you, how you define success, right? Because, uh, you know, I've done a really good job of raising a lot of money over the years. Uh, since 2012, I've not been able to capture the first, uh, you know, first place anymore, but Um, I've raised, you know, most years I raise around $6,000, $6,500, and I'm comfortable with that. I think that's a good contribution to the cause.

Um, but, you know, when you, when you get to the end of the day, you know where your hotels are. When you get to the hotel and they start, uh, figuring out who gets trophies, I'm not competitive. I'll roll into the hotel like 4 hours after the first time did, uh, the first team did. Because I'm taking my time, right? It's not about racing to the checkpoint, documenting the thing, and racing to the next one.

I'll, I'll take a minute, look around, you know, hey, this is a really, really great space. Smoky Mountains down south, for example, I spent a lot of time just drinking in the scenery down there, or whatever checkpoint you're at, right? The first year I tried to be competitive, I was running between checkpoints, I was gassing up as quickly as possible. And, uh, I got to the first night, the first hotel. This is my first rally, and I, I, you know, rolled into the parking lot, you know, uh, Smokey and the Bandit style, you know, and run up to the, to the hotel, and I'm 13th, 13th in line.

I was like, what the heck? I did a drive-through for lunch, I ran between the checkpoints, I kind of bent the speed limit between places. Uh, how am I 13th? And they clued me in. They said, you know, this is a game of navigation and like feet count, you know, feet and seconds count.

So after that first one, I decided it's, it's the journey, not the destination. Okay. Well, I think that's actually some really, really good advice right there. You know, the journey, not the destination. Um, okay.

So we know that you've worked as an architect, you like cars, and I believe that you also have a military background, right, as well? Actually, I was a military brat. I didn't actually serve myself. My mother was in the Air Force. We moved around a bit as when I was, when I was a kid.

My folks had separated when I was young. And so I was, you know, really bouncing between wherever my mother was stationed and my father in upstate New York as a child. And in, uh, right as I was starting high school, my mother gave me a choice, you know, hey, I'm, I'm getting stationed in England. Do you want to go or do you want to go, you know, live in New York again? And I thought, whatever, I'll go to England, you know, whatever.

Okay. Different, different eyes, right? High school kid versus an adult. An adult would be like, oh heck yes, I want to go live in England. And as a teenager, I was like, oh man, this is a, this is a tough call, you know?

Um, but, uh, really, really great experience. I miss everybody, uh, all the friends I made when I was there. Um, but actually, that's where my first job was as well, uh, was in England. Uh, we had a summer jobs program to keep kids, you know, on track, or they did rather. And so I got paid $3.22 an hour.

And make no mistake, as a teenager, you know, I get paid on Friday and it was converted into, you know, rare vinyl and alcohol by Sunday. And but, you know, we would, we would do things around the base. And it was just odd jobs. It was just stupid odd jobs like picking up roadkill from the flight lines, or, you know, I painted hangar doors or AM2 matting, which is portable, you know, portable matting. They put us in the 6-pack, and they take us out to where AM2 matting is piled up.

And they would say, okay, move the matting from here to there. And, you know, we're all, you know, skinny little teenagers, and it takes like 6 of us to move this big thing, you know, 6 feet from one spot to the next. Okay, but you said $3 an hour, something like that? Yeah, so being overseas, I think we had to pay into Social Security, but we didn't have to pay taxes. I don't recall at the time, you know, I guess, uh, early to mid-'90s.

I don't recall at the time what the minimum wage actually was, but getting any wage was, was a big thing for me. So, um, yeah, that's, that's pretty much the extent of it. I, I got a raise when I came back to the States, and I got paid $4.75 an hour to wash dishes. So, wow, wow. Yeah, right.

I can, I can see how rich you are. I can see how you can afford those cars now. How about that? Took a long time. $4 an hour times 26 years.

Yeah, 28 years. Yeah, whatever it is. All right, so, uh, you've been a, uh, you were work— you were an Air Force brat, you were an architect, um, but now you of course work in cybersecurity. And I understand that you're a trainer for ISACA. Yes, uh, actually, um, I teach— I currently teach the CISM and the C-Risk.

And so I do CISM in the fall and the spring and C-Risk in the summer. That's a recent addition, I guess 2 years ago now. Um, I guess that's recent. Um, and then I may be picking up CISA, the, the auditor cert, uh, in 2022. Okay.

The genesis of this, I think, is that when I pursued, when I initially pursued any of those, either the CISM and CISA, the ISACA Denver chapter was providing classes under the tutelage and leadership of Chance Folmar. Chance is Front Range Community College now and just a phenomenal guy. You know, a lot of folks in the local community probably know him as Man in the Hat. If you see him, he's probably got his hat on, and just a super, super great cat to know. And I got a lot of value out of the classes.

And so the first thing right out of the gate after I earned the CISA and the CISSM was, okay, how can I help, right? How can I, how can I participate? How can I give back? And started teaching CISSM in 2016. And then somewhere in 2017, ISACA decided that trainers for their certifications need to go through an accreditation process with APMG.

And because I'm a glutton for punishment, I said, well, shucks, I can teach CCISM and CRISC. I'll go ahead and go through the accreditation process for all 3 of those. And, and so I, so I did. It's a, it's a volunteer gig. We don't get paid as trainers, but it is a fantastic way to, you know, give back to the community, earn CPEs, network with folks, meet some really fantastic folks in the local community, and I just, I enjoy doing it.

I mean, as clichéd as that sounds. Well, I think that's great. I mean, I'm, I'm an educator myself, mostly on the university and the college levels. Uh, definitely give back to the community. Well, one with the Denver OWASP chapter and, well, this podcast as well, right?

I'm hoping that these, these podcasts help people get into their, uh, get into their respective careers, help them out a little bit. I do have one last thing maybe for you here. You know, you like to sit there and say that, you know, of course that cybersecurity is a never-ending risk, right, or a never-ending list of things to do. You know, you focus on education obviously with the ISACA stuff, and you have a strong dialogue with the GRC folks as well, or at least you think that having a strong dialogue with GRC and the executive suite is paramount. What can you close this out with and let us know, what do you feel like, you know, can you explain that a bit better?

Yeah, and I'll start out by saying that generally speaking, and this is going to sound like textbook ISACA, you know, propaganda, is that the word I want to use? I'm going to go ahead, I put it out there, I'm going to go ahead and stick with it. Security is security, risk, governance, compliance, etc. These are business concerns. These are business processes, right?

I believe strongly in the notion that we all perceive cybersecurity as, you know, people, process, and technology, but a lot of folks have them in a different order. Some folks focus more closely on technology. And again, nothing wrong with that. I think that's— we need folks to, you know, zero in on technology. But this is a people business first and foremost.

In fact, going all the way back to when I started in IT, one of the more pervasive clichés was, you know, at the time SNL had the skit with Jimmy Fallon where the IT guy, you know, you call the IT guy to your desk, you're like, move You know, and I hated seeing that. I hated seeing professionals out in the industry because, you know, hey, listen, you get more flies with honey than you do with vinegar, right? And realistically speaking, it's not a threat to your job security to teach somebody how to do a thing and do so in a manner that makes them want to call you back, right? Like, if you are abrasive, if you are, you know, confrontational with users, they're not going to call you. Guess what's going to happen next?

They're going to have an issue. They don't want to talk to you. They're going to let it fester. It's going to become a bigger issue. Let's just be, you know, people people first and technology people second, you know.

So really work on that relationship piece out there. Exactly, exactly right. And it's the same thing. My perspective is that it's the same thing in security, but even more so if you perceive cybersecurity really as a risk exercise. The only people or the only groups within the organization who can decide where our risk appetite lies are the executives or the business process owners.

Get in front of them, get into conversations with them, make sure that you're speaking the same language. And it is a two-way street, right? You need to learn the language of the business. I don't want to be so, you know, pointed with that reference, but as professionals, we need to learn the language of the business. And find a mechanism for speaking to the business in the terms that we want them to hear, right?

We want them to be, we want to meet in the middle, right? We want to acclimate on an understanding of what risk is together. And then we're working together. We're not the, you know, the, we're not stuck in a back room, you know, come out only when they ring the bell or whatever the case may be. We're actually a part of the organization.

We're part of the business. And as soon as you foster those relationships and find a way to do so successfully, you, you know, there's a path to success as a security professional. I will also say, and this is something that I have to tell my candidates in my classes, as well as folks that I work with, you have to try to find a mechanism for divorcing yourself of the emotional component. And this is what I mean by that and why I like consulting so much. As a consultant, organizations reach out to me and say, I have this issue, or I have this concern, or I've read this thing in the news.

I need you to tell me what I should think about it or how I should react, et cetera. And, you know, here's my advice. I will respond with, here's my advice, but I have the sometimes dubious honor of if I make a recommendation to a client and the client declines, they say, I don't want to do that, right? One of two things is true. Either I have failed to describe the thing in the terms that they need to hear in order to agree with me that it's a thing they should do, or I have described the risk in sufficient terms and they've decided it's just not that big a deal to me, right?

But either way, I should be able to go home that night and say, I've done my job, I've done my part, and sleep fine, right? We have a tendency as professionals, I think, to get emotionally involved in certain things. I told the company they should do this and they didn't do it, and now, oh my gosh, it's all messed up. And, you know, there's an anxiety that builds in that, in that way. And so I would, you know, I guess I would advise security professionals and risk management professionals, you know, divorce yourself of that emotional piece, right?

Do you do Do your due diligence, get the risk out there, foster those relationships, get the risk known. But again, the decision lies with others, and it's just not worth getting wrapped around the axle needlessly if you can get away with it. Well, I think that's excellent advice, although I think it's a lot easier to say the advice than to actually follow it. So much so. Yes.

So much so. Yeah. Especially if you don't want to introduce all that FUD and other components that you talked about earlier. Exactly. Cool.

Well, any final thoughts, Mike, for the group, for Colorado Equal Security? Um, longtime listener, uh, first-time caller. I think that the, the community has been super, super great for security professionals in Colorado, and I really like what's been, what's been happening or what I've seen in the Colorado Equal Security Group. And I will say I'm very, very honored to be here and looking forward to whatever comes next. Awesome.

Well, thank you so much. And I do want to actually add on to that. I think that Alex and Robb are great guys, especially for everything they've done for the community for as long as they've done this for the community. And I just think they are great guys. I am, of course, a guest interviewer here.

So want to definitely thank you for your time. For your, for your time, Mike. And, you know, just to sit there, we've been listening to Mike Pedrick and he is out on LinkedIn. If you want to reach out to him, feel free. Right.

And of course, my name is Frank. I am a guest interviewer with Colorado Equal Security. Frank Victory. You'll see me up on the Denver OWASP board as well. We do have a couple of upcoming events, including the SnowFROC Conference and the— hopefully we'll have the Armist Conference in June, in what, summer of 2022?

So excellent. Well, thank you again for your time, Mike, and I'll see you around. Thanks, Frank. Have a great one. Thank you.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com. At colorado-security.com.

Until next time, remember, Colorado equals security.