Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 228. This is for the week of October 11th.
Alex, how's your October going so far? Uh, so far so good, Robb. A good weekend. Uh, went and saw a football game today, uh, went up to UNC in Greeley to watch them play. I was actually watching the, the opponent because I have a friend that's a coach there, but, uh, yeah, it was a good time.
How about you? Uh, I mean, it's great. A good weekend. The, uh, the weather is finally getting a little cooler. I like that.
I've had to bring a coat with me out a few times recently and You know, it feels like maybe we're finally getting out of the summer. Yeah, uh, it's, it's sort of shorts and a long sleeve shirt weather for me. Maybe one of these days we'll get to pants weather. I saw that it was actually snowing in the mountains this morning, Saturday morning. I did see that as well, so we're getting close.
All right, before we jump into news, let's do some housekeeping. As a reminder, we have a Slack channel. The 2,000+ of my closest friends who are out there, I appreciate you guys. And if you want to join the Slack channel. You can go to colorado-security.com and click on the Slack button to join.
We also have a mailing list while you're on the website. Go ahead and sign up there. There's a form, put your email in, you'll automatically get on that mailing list. Also, we'd love it if you would rate us and subscribe. That way the podcast shows up automatically in your podcast listening application and folks know how good the podcast is.
Yep, uh, we would love it if you tell a friend. And you know, speaking of things I love, We love the patron, the Patreon supporters we have. Thank you so much for those of you who donate your own money to keep this movement moving forward. If you would like to join that, that, that movement and help support the Colorado Equal Security podcast and community, you can go out to our website and click on Patreon and get signed up to support us. Sounds good.
Let's jump into the news, Robb. Last weekend there was big news. There was a massive fireball over the Front Range. Uh, prompting more than 50 witness reports. Yeah, I think, I think there's probably more than 50, but that was, I think, to the, uh, this group that tracks those things.
Yeah, so Denver Post had this article, and within the article itself there's a, a video of a, a series showing a series of like, mostly it looked like doorbell cams that picked up, um, the fireball. And it was, it was a pretty impressive fireball effect. It was pretty impressive. Uh, what was amazing to me is, you know, as they, as they talk about, uh, in this article, these are not as— they're not that, um, uncommon. And they're, you know, there's apparently no mystery about what these are.
I guess it's just, you know, meteors, you know, just stuff coming from, you know, space junk that burns up. And this thing burned especially bright. But, uh, if you haven't seen the video, I think it's worth looking at. It definitely looks like something interesting coming at you. Yeah, I think, um, it might have been Jen Wilson who posted a video on on her LinkedIn, which prompted me to go look at my doorbell cam to see if I could see it.
And while I did not actually see the meteor, I did see the bright flash. It was, you know, just out of frame, which was too bad, but, um, I definitely caught it on a little bit on my camera. You know, never having seen a fireball like this, um, now that I've seen it, I can, I can definitely see how this might cause people to think UFO, you know, as we've had, you know, centuries of people not knowing technology well and not understanding what meteors look like, this could be mistaken for something, you know, with a little bit more intelligence behind it, I think. Or, you know, maybe that the world's ending or something else. Yeah, all those good things.
All right, hey, that is, uh, that is an interesting story. Let's jump over to our next one. This is a kind of combined set of different, um, awards. So an article from Denver Business Journal talking about 3 Colorado hotels that were ranked among the 50 best, and also talking about how one, um, Colorado city was, was named— what was it— the, the best small town in America, or a small town in America. Yeah, yeah.
And, uh, that was Aspen, actually. That was the best small town in America. Seems like a, a good choice if you could afford to live there. Um, also several hotels in Denver, including, uh, the Art Hotel which is near the art museum, were ranked on that list of best hotels. Yeah, Lifehouse Lower Highlands, uh, was the number 28.
You know, I actually didn't know these hotels until reading this article, but you know, they look like interesting places. And you know, if you're— maybe if you have someone coming in from out of town, you don't send them to the nearest Marriott. Maybe try out one of these fun, uh, niche-type hotels. Yeah, definitely. Um, those are pretty cool.
Moving on to our, our next story, uh, there is a funding announcement, $50 million Series C for, uh, a Boulder startup that creates non-toxic lawn care. Yeah, so Alex, we've actually talked about this company, it's called Sunday, on the show before. I think it was back in March when they announced their partnership with, with Walmart. Yeah, but what Sunday does is they, they're a service that's going to send you materials to keep your lawn in good shape. You send them a soil sample, they're going to send you non-toxic packages to, to keep your, your yard going in good shape.
They use safe ingredients like organic compost, food waste, molasses, and seaweed. And with this new raise of $50 million, they're also going to be moving on from just lawn care to doing pest control and trying to get rid of the very dangerous chemicals that are used for controlling pests. I mean, pests. Yeah, we don't want to get rid of pets. Um, I think that this is— it's pretty cool.
Um, I see ads all over the place for Sunday. I, I've never tried it myself, but maybe this will lead me to do that. The other thing that they say in here is that they're going to use this funding to expand their footprint in the retail space. So right now they're in about 700 Walmart stores across the country, and they're going to look to get into more retail spots. So, uh, pretty cool to see this Colorado company looking to disrupt what you'd think was a very well-established and maybe undisruptible industry, and I'd love to see it.
They're using AI, they say they're using AI to do it. So as long as the AI is, uh, not turning against us, I'm on Sunday's side. Well, clearly they're going to succeed if they're using AI, so good for them. All right, uh, moving on, we have another Colorado startup. This one is much earlier on.
Um, it's called Cabinet and is a little 3-person company today, but what they're doing is they're building software specifically for executive assistants to help with all the different things that they— those folks have to work on. Yeah, uh, interesting idea, and I'm sure an area that needs some disruption. I feel like, uh, you know, those kind of folks are dealing with, uh, you know, lots of diverse things and, and probably just, you know, point solutions or spreadsheets or whatever else it is that they need to get things done. So, uh, having an application that can help executive assistants do what they need to do sounds like a pretty cool market. Yeah, so one of the co-founders here, Julia Lebowitz, she herself was an executive assistant before she went to graduate school.
And as she was thinking about what she might want to do, she realized that it's a very underserved market where EAs are— they're doing obviously managing calendars and travel, but they're also planning events, doing office management type work, financial reporting, marketing, all things that are very disparate. And, you know, they have to juggle a whole lot of different tools to do it. So they're going to create one tool to be that central place for EAs to do all their work. My first thought is really cool. My second thought is I'm a security guy.
Holy smokes, they're going to want to have one tool that gets access to all these different systems, right? Scary. It is a little scary, but, uh, you know, if, if your executives want their executive assistant— assistants to be more productive, then, uh, they're going to want to use this. So you better figure out how to secure it, Robb. Yeah, well, maybe, maybe someone should go call Julia up and say, hey, I'd like to come help you secure your, your system.
Point number 4. There you go. All right, uh, moving on. Uh, next we had a press release from Optiv. Uh, some big news here.
Uh, they've decided that they are rebranding and they are now in a market category that they, uh, sounds like they were already in and are the leaders in it. Yeah, it's definitely a strange story to me. One— and Dark Reading's headline says Optiv rebrands as cyber advisory and solutions leader. They didn't rebrand, like they're changing their name. What they're trying to do is, is really create a market definition for what they've already been doing, right?
They, you know, I think we all think of Optiv as a reseller who, who has connections and, you know, maybe, maybe the most connections to security companies out there, so they can, they can help you get whatever solution you want. And then they also have services to, to help you assess where your program is and where you should be going. And, you know, they've decided that they're going to create a market um, uh, kind of a niche that, that they were already good at and kind of let every— everyone else come to them. Yeah, I mean, it is brilliant. If, uh, if you're already good at something, you should make sure that that's a market category and that you then become the leader in it.
So good for them. Good stuff. All right, uh, next, this is news for— that's— it's only related to Colorado because I think Trace 3 has had a large Colorado presence, but, um, Trace3, which was headquartered in California, just last week was acquired by American Securities. So Trace3 has been a big presence, at least in my career, and apparently they're going to— I don't know if they're going to rebrand or not, but they certainly are no longer privately owned. Yeah.
Well, or they're differently privately owned. American Securities is a PE firm, so now they're the owner.
My guess is that they will probably still be Trace3, and, um, you know, maybe this will be the start of acquisitions. And I've seen this with some other, uh, resellers and other things like that, starting to consolidate those and bringing people together to make, uh, larger resellers and solution providers to take on the folks like Optiv. Yeah, maybe they'll, they'll, you know, get, get a couple more acquisitions and they'll brand themselves as a cyber advisory and solutions leader. Uh, they won't be the, uh, the leader though, because clearly Optiv is the leader in that category. All right, uh, with that, moving on to the next story.
Coalfire, uh, they have a press release talking about their, uh, it sounds like new service called FedRAMP 360, uh, which is essentially an accelerated service from them to help folks get FedRAMP certified in a much faster way. Yeah, Coalfire has been the leader in FedRAMP since they bought Verus about 3 years ago. It was kind of Coalfire and Verus neck and neck as the 2 leaders. They consolidate into one company. They're obviously very clearly the market leader in FedRAMP.
And I think that due to the government's continuing influence over private sector and a lot more private sector companies choosing to get FedRAMP, this makes a lot of sense for them to invest more on their side. So this FedRAMP 360 service really is, is to accelerate the speed the companies can go. They're— Coalfire walks in with a playbook and a package that says, rather than taking 18 months and $2 million to do this, we can get this done for you in 90 days with a significantly smaller investment. So that, you know, hopefully making the business case for companies considering FedRAMP a whole lot easier. Yeah, and as part of FedRAMP 360, they have sort of 3 phases.
The first is advisory, the second is migration, and the third is operations. I thought it was pretty cool in that migrate phase that, you know, part of this service is they'll actually take your, your current infrastructure and through what they call compliance as code, but, you know, some scripting infrastructure as code pieces, basically move your stuff into a FedRAMP compliant environment. Uh, that sounds really cool. Yeah, they certainly trying to get rid of as much of the configuration and infrastructure work as possible and really just let you focus on the stuff specific to your application. So I think it's a great idea, and, and for a lot of companies, it probably really will make it a lot easier for them to get into the FedRAMP marketplace.
Good stuff. All right, we have a press release from Ping. You know, it occurred to me as we saw a whole bunch of press releases come for Ping recently that they're in the middle of their, their big customer conference week. They— well, I guess it was last week. But, um, I guess called Ping U-Verse now, uh, is their chance to get in front of customers, I think mostly in person now.
Um, and when they do that, they also drop a bunch of news. So, so a couple news stories here in this one press release. Yeah, so they announced a couple new things. One is, uh, Ping One Fraud, which is fraud detection built into the, uh, Ping online system. This was the, uh, Secured Touch product that is now being rebranded as Ping One Fraud.
Uh, so helping to detect online fraud as part of your IAM activities. And then, uh, also some advancements in their API intelligence for their cloud platform. Yeah, so, so both of these are announcements that these new functions have been added to the PingOne Cloud. So PingOne is the, is the Ping Identity, you know, cloud IDaaS product. They're now adding fraud via the integration of Secure Touch, which they only bought back in May.
So, you know, pretty quick to to get that stuff integrated there. And then the API stuff moving into the cloud took a little bit longer. That's been a couple of years since they bought that company. But, you know, that company was on-prem initially. Now they've moved it to the cloud, and they're getting this stuff built into that PingOne IDaaS and, you know, becoming really, you know, very comprehensive solution that I don't— I'm not sure anyone else out there has quite that combination of fraud and API security along with the authentication, MFA, and all the good stuff PingOne has in that IDaaS.
Sounds good. Seems like PingOne is getting stronger and stronger. Good stuff. All right, moving on to our last story. This is a Red Canary blog.
The title is Trust Issues: Building a Strong Foundation in an Ever-Changing Field. Robb, I bet you have a little bit to say about this. Yeah, I'll say this. Authors don't get to pick their headlines. I didn't get to pick the headline, but I did get to approve it.
And I don't have a problem with it, but I, as you say that out loud, I'm like, well, I didn't write that, but I did write everything else in here. So this is my blog post kind of introducing what is this whole thing about being a Chief Trust Officer and why is trust such a key principle for Red Canary? And really, I'd love it if folks here would read it and take a look and let me know what you think. You know, as I've looked at my own career, Moving from— and I was an IT guy for a long time— moving into security and really thinking about what is the next step. And it's enabling trust and helping a company be trustworthy and visible in such a way that customers and the rest of the stakeholders that they have can trust them.
So take a look at that and let me know what you think. It is a great blog, Robb, and I do appreciate the fact that you did let me proofread it before you had it published, even though you didn't take any of my suggestions. Well, the, that, the timing on that, Alex, the timing. Yeah, yeah, that's what they all say. Hey, uh, that is it for the news, but we do wanted to mention some, some other news, not necessarily an article for it.
We've, uh, you know, you and I have been doing this for 4 and a half years, and it's been every week, or, you know, just about every week for that whole time. Um, as we've, as we've been reassessing recently and, uh, thinking about our own schedules, we realized that continuing to do this every week is is probably not going to work for us, not, not going forward here for the next, uh, I don't know, a couple of quarters at least. Yeah, so, uh, while we, we love doing the podcast and, uh, we love the community, I think it is time that we maybe cut back on the frequency of the podcast a little bit. Uh, I think we're still trying to figure out exactly what that's going to look like, but rest assured that does not mean that we're, we're not behind the Collateral Equal Security movement. There's a lot more to the movement than just the podcast.
Yeah. So, so don't look for every Sunday for the next little while to see a podcast in your queue. Uh, we're planning to do it. We're still going to keep doing the podcast. We're going to do it less frequently and, and really put a little bit more effort into each of the shows.
Um, you know, maybe, you know, get, you know, work on having, um, interviews that you and I do and making sure that we really are thoughtful about how we do those and, you know, not having so many newscasts without interviews. Uh, and, and really, we'd love to hear your feedback if there's things that you want to make sure we keep doing and maybe things that you, you don't care so much about, we'd love to hear that. Yeah, or if there are other things that you, uh, you think we could do in lieu of doing a podcast every week, we'd love to hear about that too. All right, so that is it for news. Let's jump over to the events coming up in town over the next couple of weeks.
We have quite a few events, um, starting off on, uh, on the 13th and 14th, Spectrum, uh, formerly known as Charter, is doing a job fair. That's on both the 13th and 14th. On the 15th, uh, the Application Security unnamed group is doing the Application Security Testing Tools meeting. On the 19th, CSA Colorado is doing their October meeting. It's Zero Trust and Cyber Resilience.
Also on the 19th, ISSA Colorado Springs is doing their October meeting. On the 20th, Secureset is doing an Intro to Cybersecurity Certifications virtual event. Also on the 20th, ACES is doing a security innovation tour. That sounds fun. It sure does.
And ISACA is doing an October meeting around API risk management, and that's on the 21st. And our final event on the 23rd, ISSA Colorado Springs is doing one of their mini seminars talking about configuring Red Hat Linux 8.4 server for Ansible control node role. Yeah, so that's 3 hours on how to do that. Uh, man, that's, that's a specific talk. If you need to configure Red Hat Enterprise Linux for, uh, for Ansible control node, make sure you need 8.4, not 8.3 or 8.5.
Uh, that sounds like the perfect meeting to go to. It sure does. I'm sure I sound like an idiot to probably know 8.5, but I don't know. All right, jumping over to jobs. I do have a few jobs here at Red Canary, including a new one.
I'm happy to, to get to share with the community, we're looking to hire a Director of GRC. That would be someone to run our entire GRC program and work directly for me. I'm also looking to hire product security engineers. We have a few openings for that. If you have a passion for securing products, both in the development and operational perspective, I'd love to hear from you on those.
And we still have our IT Support Manager position open, although I'm hoping it closes very, very soon. It's not too late though to send me a note if you're interested in being a part of the process. Awesome. Imagine Communications is looking for a senior director of information security. Build Education is hiring an information security engineer that can be remote.
Uplight is looking for a security engineer. Richie May is hiring a security administrator, and there are actually a couple Richie May jobs this week, so if security administrator doesn't sound right for you, I think there's a couple others too. Uh, Berkshire Hathaway Home State Companies is looking for a senior cybersecurity engineer. Hitachi ABB Power Grids is hiring a cyber defense incident responder. Yeah, I thought that one sounded exceptionally cool.
And finally, called the Colorado Judicial Branch is looking for a system security engineer. Awesome. Well, that takes us to the end of jobs and the end of the newscast. We do have an interview this week. Uh, we have a guest interviewer, Frank Victory, who sat down with VP CISO at Gates Corporation, Dan Garlick.
Dan, who, you know, I think, you know, we know from around the community, you know, he's worked at a few different places previous to Gates, um, NTT, and, uh, he was down at Hitachi Vantara. And what was, what was the one before that? Another big one. Um, I'm having a, having a, uh, yeah, I'm not— brain fart. Um, but anyway, listen to the podcast and soon you'll know.
That's right. Cool. Well, that is it for this week, Alex. Uh, we will not be talking to them next week, but we'll still be around, and send us a note in Slack, and we look for— we look forward to your feedback. Sounds good.
Thanks, Robb.
Hello, this is Stanton Meyer, CSO of Cobank. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
All right everyone, welcome to the Colorado Equal Security Podcast. My name is Frank. I am a guest, uh, interviewer here, and my honor of interviewing the first person, uh, the first person that, uh, I'm going to interview here is Dan Garlick. He is the CISO for the Gates— is it the Gates Foundation? It's the Gates, right?
Gates Corporation. Gates Corporation. He is the CISO and Vice President of Gates Corporation and my former boss. So welcome, Dan.
Nice to meet you again, Frank. See you and meet you again. All right, so, uh, before we get into that, why don't you do a quick introduction? Sure. Uh, yeah, nice to meet everybody here.
Uh, so yeah, I mean, I've been in the cybersecurity field for, you know, over 20 years. I, I started my professional career actually as an officer in the U.S. Air Force, completely in a completely different career field where I was a B-1B bomber bombardier officer, uh, and, uh, decided to go back to school late '90s, uh, into cybersecurity field. Got my master's degree in that, uh, that discipline. And, uh, yeah, started my, my career and, uh, moved on the way up. And, uh, I've been in leadership roles— deputy CISO, CISO, director security ops for over the last 16 years.
Um, and yes, now I'm the fairly new christened, uh, Vice President and Chief Information Security Officer at Gates Corporation based here in Denver, Colorado. And, uh, yeah, that's kind of, uh, the short, uh, version of my entire life on the career side. You were a VC, so though, for a little bit, right? I was. I, uh, I had been a long-term, uh, partner with a managed security service firm, and they had an executive security advisor and virtual CISO program.
And I thought it was something interesting that I hadn't pursued that kind of thing before. So it might be an opportunity for me to try a lot of different other industries. I've been in high tech, had been in finance, but I hadn't been in some of the other fields that I wanted to kind of explore from the business industry side. So that gave me an opportunity get into both, uh, you know, heavy manufacturing, medical equipment manufacturing, areas like that. So yeah, so it was a good opportunity.
And now everything— and then COVID happened and everything was virtual CISO. Gotcha, gotcha. So what would be some of the comparisons you might have between being a, I guess, regular CISO right now and a virtual CISO where you had to deal with different customers? Right. So, uh, and I guess it's less the virtual seat, so it's more of a, uh, probably like any executive that they have these, uh, organizations provide client executives, uh, to, to be on staff.
You see it in the legal field for years where they have senior counsel that are external entities that are hired to, uh, to, to, uh, augment the internal legal function. So you're seeing this now more in other areas of organizations. Security is just the, the most recent one that this is becoming. I think, I think something we'll probably see more of, um, is my expectation. I mean, the big difference is you're an outside party, so to build that level of trust, you know, the, the old, uh, trusted technical advisor That is, uh, going to be more difficult because there's always that component of, uh, of, dude, can we trust an outside entity that, especially if it's a partner, uh, that's provided this resource, you know, you have to— there's, there's— you have to really focus on building that trust between yourself as a CISO and your other executive peers within the organization.
Now, being, as you said, a regular CISO, you know, traditional CISO role, you're hired by the organization you're CISO for, as most places are used to. That, that, that you, you obviously still have to build the trust, but it's— you have a bit more, uh, you know, it's a bit easier, and ability to do that is, is much quicker, I would say. Plus, I think you, you're more empowered internally to be able to make the changes and to drive change as needed, where a third party, at the end of the day, you're, you're an advisor. You know, you're an advisor, and legally, uh, virtual CISOs are still— if they're an independent, if they're an independent third party, then they are, uh, you know, legally not able to attest to certain things within the organization. So, so, but yeah, so I, I, so I, I, so I guess it's probably more of that external third-party CISO, uh, for hire than— which it's, it may, it usually will wind up being called the virtual CISOs from my experience, but Theoretically, it doesn't have to be.
It could be somebody in the same location as that corporation. Yeah, but you see that more now, starting to. I'm going to put you on the spot here, Dan, right? And what I'm going to do is I'm going to ask you, which is the bigger challenge, the internal CISO or the, the CISO or the, uh, the vCISO? So I would say they both have, you know, equal challenges.
They're different, okay? And it kind of goes back to what I just said. One, you're, you're an outside source, you're an outside entity. And if you, even if you're hired internally, and you're almost always virtual, that's, that's a challenge in itself. I do think there is a component to being able to meet with people, certainly at the executive level, I think that's necessary to be in a room together.
If you live your entire executive career on Zoom or Teams, then it's, it's possible to build relationships. But it's, it's, I still think it's, it's, it's not, uh, the traditional expected way with other peers in the executive teams. So, you know, being in person, being able to meet, you know, and if you live in a different location, can't jump on a plane probably realistically every week and fly to the headquarters to meet people. So I think that's still there. Yeah, but, but as we see more remote work, that is certainly something you're seeing more of.
But I think the executive ranks are probably an area that, uh, you know, from my experience, at least, it's, it's, it's still not, not, you're not seeing that as often. So, okay. Well, you know, so we talked a little bit about your professional career here. Let's bring a little personal piece here. And we're going to take a step back.
As I, as I used to make fun of you a lot, I know you're from Boston, right? And you moved here to Colorado for a specific reason. Why don't you tell us about that? So, yes, I relocated from Boston approximately about 15 years ago now, I guess so. And yes, I hide my, my Boston accent, uh, uh, well, so, uh, I, I— people have noticed well.
But I had an opportunity to, uh, to come out to Colorado and to start a professional services, uh, organization here in Denver, Colorado with, with a fairly large security, uh, provider. Uh, en route, however, that, that it was 2007, 2008, so it was during the economic downturn, uh, I think that was the Great Recession, what they call it now, that, um, kind of torpedoed a lot of the consulting work that was being done, especially in security. That was at that time, I think we saw a lot of that dry up pretty fast. Organizations just weren't spending money. So I literally remember getting a call driving across, I think it was Nebraska, and being notified that the organization had decided to basically not pursue operations in Colorado.
So Yep. So, had to pivot pretty quickly career-wise at that point. So, you had— so basically, you packed up everything that you owned in Boston, put it into a moving truck, driving across Nebraska, and I'm assuming middle of pretty much nowhere, you get a phone call that says, oh, by the way, the job you're moving to and your job you're going to no longer exists. Right, right. Wife and family, newborn, into all of that.
So yeah. Okay. So what did you do? I mean, you're, you know, for our listeners that are out there, what did you do or what would you advise either when you were doing it or now that you've had some time to look back at it? You know, if you could talk to yourself back in 2007, what would you tell yourself?
Well, unfortunately, like everybody probably listening, I would assume who's in the cybersecurity field, luckily we're in a field that Even back then, even in a bad economy, jobs were pretty readily available. I mean, you had to— I think it went back to, you know, I worked in a lot of different security industries, a lot of different roles, whether it was— I worked with a Big 4 accounting firm where pen test teams did ISO audits, as well as, you know, security operations management, pen tests. Got my— got myself kind of involved a lot of different areas and, and kept kind of expanding that breadth over time. So when this happened, I didn't have too hard of a time finding other things in the security field that were relevant to what I wanted to do. And it actually, you know, like the old saying goes, you know, every challenge is an opportunity.
I use that as an opportunity to say, I'll challenge myself, let me look at other roles, and then I move more into the Let me get into management leadership and yeah. Okay, so you had a pretty well-rounded background. It sounds like you had some in pen testing and SOC or SIEM and things like that. What do you think from an operations level is the biggest challenge? Probably it was then and it still is, even especially today, it's the people part of it.
Process, You know, the partners you use, the technologies, that's always evolving and changing. But it does come back to the people part of it. We still don't operate with robots rolling around the buildings yet. So it's still at the end of the day, we have to have humans involved with it, whether it's our internal team, Staff Aug, third-party partners, whatever it might be, outsourcers, managed service partners, et cetera. So it's picking the right partners to kind of fill some of those gaps in an organization as well as growing a team, developing a team, you know.
Okay, today it's fine. Even finding people is a challenge right now. It is today. I, I definitely know that one with trying to find the people here. So if you're gonna sit there and try to outsource or build the team, which would you prefer?
Do you like that hybrid model? Do you like the Do you— why would you rather prefer to have an internal team, an external team, or is it that very classic thing of it depends? I think it depends, you know, on the industry, what you're trying to protect, what is your, you know, threat landscape, who are the threats coming from, are you in an, you know, are you a government agency that's doing a lot of nation-state attacks, are you Uh, you know, an industrial company that's worrying about ransomware, thus outages, availability, or somebody's worried about— you have a lot of proprietary data, design data that you need to protect for new products, then you got to worry about some of that confidentiality. You know, medical, you got to worry about all that integrity. So it really depends, I think, one, what industry, and then also the— and that ultimately comes down to what is the risk appetite of the organization.
So at the end of the day, a CISO still has to, uh, you know, from my experience, executives maybe in other fields will, uh, be more likely to accept risk, where the CISOs, one of their primary roles is to make sure the, the risks out there are explained properly in a way that everybody understands it, and so everybody knows what the appropriate posture should be. So, so I think, I think that, that, that from that point, then you can look at Uh, do we build our own SOC and do we staff it? Do we look at a managed SOC? Do we look at, like you said, staff? Do we grow our team to be X number of people, or do we have it, uh, you know, a smaller team?
You know, things like that. Does the GRC function— does it stay within the CISO's hat, or should it be broken out its own organization under legal? So, so there's all those kind of aspects that kind of weigh into how you structure and build an organization, I believe. Okay, that sounds great. All right, um, let's see.
So we talked a little bit about, uh, your past and your history. We talked about some of the challenges that you have right, right now. Uh, what do you think as an industry, uh, where do you think we're going right now? Uh, that's a great question, and it's something that I spend a fair amount of time thinking right now about as I'm You know, Gates, we're transforming cyber. It's a big focus of ours, a cybersecurity organization.
And, you know, with the ransomware and threats that everybody's dealing with, that's kind of— that's what keeps me up late at night. And, and then it's looking at how we built organizations, how we, uh, protected and defended. Uh, some of it's still the same, but now with cloud, with, uh, even not only third-party risk, but even now looking at fourth-party risk Uh, there's even more and more to, uh, you know, to consider. So for me, it's the, you know, I've leveraged managed services a lot in my— throughout my leadership career. Um, SIEM, of course, SOCs are a big part of that.
Now we're seeing a lot more around the— not only EDR, that's been around I think for quite a while, uh, but more so now the MDR, looking at, you know, who can help organizations with that. I think that's a bit of a, a new, uh, aspect to, uh, a CISO's, you know, hat is, is, is, uh, how to, how to view MDR service providers versus traditional SOC as a service or managed security service partners. And again, it goes back to like I just said, what is your, what is your business? What industries are you in? What are, what does the attacks look like that are going to be the type of things you have to consider from a risk posture-wise.
Okay, perfect, perfect. Okay, well, let's go ahead and do a little bit more of a shift here. As you know, I have taught a lot of classes at both the college and the university level. The next question is going to be, is for the person that's doing a career change, what advice would you give them? And then to pivot on that, or to build on that too, the person that's been in this industry, say 3 to 5 years, what kind of advice might you want to give to them?
So maybe a 2-part question here. Um, so the first part for, for people moving into the field, I suppose if it's a, if it's a real career change, it's having the traditional education is always a good basis, you know, whether that's an associate's degree, bachelor's degree, whatever it might be. But, but I certainly think people can, uh, pick up the technical skills on their own. You know, I don't know if it's as common as it once was years ago, perhaps, but still the tinkerers in technology, as I like to say, are still folks that we have. I think CISOs and even CIOs and people who are in the technical operations side of hiring, we have to kind of throw a wide net out and not be very narrow-focused on our job description for roles and who we hire from that point, but say, There are people that can cross into— from other areas of IT.
I've had success with interns or people out of finance who have moved into security roles, and, you know, through coaching and mentoring and the right training, technical training, certifications, or things like that, have been able to grow a pretty successful security career as I kind of keep track of them. Well, one of the things that I tell them, what I tell people that want to get into this industry, whether they've been a career changer, whether they've been in this industry for, you know, in IT, I always tell them, though, you must still have a passion for cybersecurity. Don't do this job if it's only for the money. That's the wrong reason to get into this job. What are your feelings about that?
I think that's true. I mean, and the second part, I know I didn't really answer the second part of your question. Somebody who's already in the field looking to grow. I think it really depends where you are. If you're in a technical field, you know, system administration, threat hunter, whatever it might be, do you wanna stay in that?
And, you know, I think the biggest risk for folks that I see is, you know, managing your career with a very specific technology or product line and, you know, being vendor agnostic to a certain extent, or at least, You know, as opposed to learning one EDR solution or one IPS firewall product or gateway solution, you have general knowledge about all of them and are able to demonstrate that and pivot from, you know, a Cisco shop to a Palo Alto shop, for example. So having that— having again that wide ability to— because you don't know, CISOs are hiring people, for example, when I look at candidates, It's often very hard to find somebody who has the exact set of technologies that the organization I'm with has, so there has to be an ability— does this person have a wider set of knowledge and skills to kind of meet the needs of what will look like now as well as in the future? So, you know, the ability to learn new things is obviously always important, so I think having that. Also, a person who is in a GRC role Doesn't mean they can't cross out of that and go into a more technical role. So I think it's having that flexibility with your career to kind of look at other options and potentials.
It gives you a lot more, you know, a lot more flexibility. And like I said, the contingency plans of life that come up, it gives you more chances to, you know, right now it's a seller's market, so to speak. Everybody, the people in cybersecurity are able to be pretty competitive in where they want to go and what they want to do. That'll probably remain the case for quite a while, but the more skills people have in cyber, I think the better to be able to kind of meet the needs for the organizations. Okay, so maybe in some cases have more of a horizontal piece on your career path versus a pure vertical one.
I know some people prefer that, they prefer to have like just total technical, right, or total policy or etc. But I think having a good base is what you're saying, is being able to sit there and pivot into change. Okay. Yeah, right. Yeah, yeah.
And, and the other part of your question here about the, the financial aspects, uh, you know, generally from what it appears the way as a hiring executive, uh, people should not probably have to worry too much about compensation in the cybersecurity field from the looks of it. So We are definitely on an upswing more than ever in this field. So it's, it's a good line of work to move into. So, you know, I definitely, I definitely see this as more positive for, for college-age people who are looking to get into a technology field. Security's an excellent one to get into.
It's the reason I got into security 20 years ago, and I think in the next 20 years will remain a great field to pursue. You know, the bad news is because there's lots of bad guys and bad, bad people out there that are trying to do bad things to companies, and thus we need more defenders in organizations. So, okay, well, now I'm going to actually give you an open mic here. What would you just— I'm going to give you the totally open mic here. What would you like to say to either a personal level, to a professional level?
You've got the audience here of Colorado Equal Security. So what would you like to say? Uh, well, I would say, you know, kind of back to that, you know, I think right now security, the field of security is growing, you know, and, uh, we, we're having a hard time as, you know, in the leadership side finding candidates. So I think, you know, having the ability to, um, to, to really, you know, find candidates that have open mind about You know, being flexible with the type of work they're going to do. You know, I think that's, that's kind of a big thing right now.
You know, people once again have to really look at— I think managing people's careers, at the end of the day, it's up to everybody to manage their own career. That's the advice I got when I was more junior in my career, and it was good advice. At the same time, you want to— I think it's good to find a mentor at any level that you're at. You don't have to be a CISO or VP or a director to be a, to be a leader. Uh, as well, you know, that there's a lot of, you know, uh, books and articles now that talk about that very, you know, topic that, you know, anybody can be a leader at any level.
And I think that's what I look for when I'm looking to grow my team, is who are the people that are enthusiastic not only about security but their own career growth, are, you know, that they, they are enthusiastic about that, hard workers of course, but also folks that are able to roll their sleeves up and, you know, kind of look at being a problem solver. So, yeah. Awesome. Well, Dan, I want to thank you for your time. I appreciate it.
For everyone else out there, we do have a lot of resources out there. We have the Colorado-Security Slack channel. I myself, I'm with the Denver OWASP group, so we also have a Slack channel out there. You can sit there and find it at Denver-OASP. And we also have the Denver-OASP meetup in person.
So it's meetup.com/denver-owas.
We do have our SnowFROC conference coming up at snowfrog.com. We also have the RMIS conference hopefully next summer going to be in person, and that Colorado Equal Security is a big sponsor of that. So want to thank everyone for your time. Dan, thank you. It's great seeing you again, at least virtually, and we'll definitely have to go get a beer sometime.
Sounds good. Take care, Frank, and goodbye to everybody else. Thank you, guys.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.