All episodes

Diego Silva, CIO @ Gates Corp

Apple Podcasts Spotify SoundCloud

Diego Silva, CIO at Gates Corp, is our feature interview this week, recorded live at Evanta’s Denver CIO/CISO event this week. News from Casa Bonita, Banksy, Wedfuly, Wad-Free, Welltok, Stackhouse, Red Canary, RADICL, Ping Identity, Coalfire, CyberGRX and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11629 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 230. What is it, the week of November?

We're in November, November 22nd. Yeah, you'd think this would be easier, Robb, because this is take 2. Yeah, we just recorded this entire newscast and now we're going to do it again with the— with both mics turned on. Hey, Alex, Thanksgiving is this week. Can you believe that?

Yeah, Thanksgiving is this week. It's hard to believe it is Thanksgiving already. Robb, what are you thankful for? I am thankful for the great weather we've had. You know, the fact that it stayed nice so long.

We haven't had any snow yet. That's true. What about you? What are you thankful for? You know, I'm thankful we've gotten to take a little bit of a break here.

That was nice. Got a little bit of a time back on Sundays. But here we are back together. You know, another thing that'd be nice to talk about this week is our favorite Thanksgiving foods. Mine is stuffing because I don't get stuff.

Oh, Robb. I don't get stuffing very much outside of Thanksgiving dinner. You know, most of the year round, you just don't find that other places. What's your favorite Thanksgiving food? You know, for me, you know, anything, you know, sweet or desserty is really, really what I like.

Oh, everybody, you're going to love this podcast.

You know, there's a sweet potato dish and, you know, really it's covered in brown sugar and molasses and all this other great stuff. And it's— my wife makes something just like that. Oh, really? I really like that. That's crazy.

I really like that. Hey, we have some housekeeping before we jump into serious news.

Do we have a Slack channel? We do. Well over 2,000 people, lots of great conversation. Just because we haven't been on the show a lot lately does not mean that there's not great people talking there. You should join by going to colorado-security.com and clicking the Slack button.

Also, we have a mailing list. Even when there hasn't been a podcast, we've been mostly sending out notes about things that have been going on during the week so you can get some of this podcast stuff in written form even when we're not talking. Uh, we'd also love if you rated us and subscribed on your favorite podcast platform. Uh, hey, tell a friend, let them know how great Colorado Equal Security is. And if you are happy to support us financially, we would love you to join our Patreon campaign.

Also, thanks to our current patrons for supporting us through these years. We love you. All right. Hey, moving into news, we have we have an update on the ongoing Casa Bonitas saga. You know, in the last in the last few months since we've talked about it, the you know the Trey Parker and Matt Stone acquisition is is really going through.

It looks like for sure, and they've announced a new head chef who's going to be taking over the kitchen. Yeah. So Dana Rodriguez, who is a local chef and has a few restaurants here in town, including Work in Class and Super Mega Bien. And I've eaten at Super Mega Bien. It is super mega and bien.

She has her own mezcal brand as well. She does. Yeah. So maybe you'll be able to get that at Casa Bonita. But she is the new executive chef and she is working hard to make sure that the food there is going to be good and also that there will still be sopapillas.

Yeah. The— so the motto of the new partners of the South Park creators is that they want to make it better and they really want to figure out how to change nothing but improve everything. It's kind of an interesting model for them. Yeah. Yeah.

And they're talking about how they are probably going to open in the second half of 2022, which should give them enough time to do things like, you know, clean. Yeah. So another interesting thing they were talking about was that as they're looking to, to replace, really enhance all of the food, the one thing that they've promised is that they are not going to do away with the sopapillas, which some some people seem to like. I do not understand all of you people who think their sopapillas are good. Go have a good sopapilla somewhere.

And then maybe you'll realize that they're still terrible, just like their enchiladas are terrible. Yeah. And I think it's, you know, you made the point earlier that they're just not as bad as the other stuff that's there. But I think it's also just that they're a, you know, a vehicle for powdered sugar and honey. Yeah, just give me a spoon and a bowl of powdered sugar and honey.

And I'm pretty happy with it, I guess. Yep. All right. Next up, there is an art exhibit that is coming to town. A Banksy exhibit with over 100 original artworks is coming to Denver.

Yeah. So Banksy is, you know, well known as the— what do you call him? Like the— he's like a street artist. Yeah, street artist, but like anonymous street artist. No one's supposed to know who he is.

He does— he does art like the Girl with the Balloon, I think is maybe his most famous piece of art. And he doesn't do it in museums. It's not the easy way to get access to. So these pieces of art are things that were collected by various folks over the years, 100+ pieces of art that they are choosing to exhibit. This is not a Banksy organized or sponsored thing.

This is just a bunch of folks who want to share that art. Yeah. And this exhibit is slated to open in the middle of April '22 at a yet-to-be-disclosed venue. And ticket— tickets are gonna go on sale here shortly. So if you want to go, you probably should check that out.

And they're actually on sale now. Oh, They are on sale now. By shortly, I mean now. And tickets range between $30 and $110. Good stuff.

All right. Well, we had a few weeks ago, 2 Denver startups both made ABC's Shark Tank in the same show. It was Wedfully and WadFree. And I was interested to learn about both of these companies. Yeah, Wedfully is a— well, they started out as a company that did virtual wedding planning.

So you could, you know, connect with someone to help plan your wedding. But through the pandemic, they pivoted a little bit and started doing virtual weddings as well. So they have now worked with nearly 1,000 couples to share weddings with 200,000 guests around the world. It's pretty good. So while they were on the show, they pitched, you know, getting an investment of $200,000 for a 5% stake in their company.

After a little bit of counter-offering back and forth, they ended up accepting an offer for $200,000 to get 10% of the company. And that came from Robert Herjavec. And the second company was called WadFree. And this is a device that helps your, your bedsheets stop twisting or, you know, wadding when they're in the washer so that they get cleaner. And the device is, you know, it's a little sort of square device and you put the corners of the sheets in there.

And when I was looking at the whole time, I kept thinking, Well, how do you clean those pieces that are in the device? Now you have a little piece of dirty shit. That never even occurred to me. I know. That's interesting.

That seems like a real concern. Yeah, it is. So on the show, these guys actually also asked for $200,000 for a 5% stake in the company, but they ended up getting their $200,000 for 5%. But in addition to that, from, is it O'Leary, they promised $1.50 per unit they sold up to a million-dollar payout to him. So that's how they ended up getting their deal, and both companies hopefully did great.

I saw that, you know, coming out of this, you know, I think I've always wondered, you know, do they, does the worst terms that they get from the Sharks make sense for these companies? Because they, you know, they presumably would have gotten better terms if they just went to some VC investor, and I don't know the answer to that. What do you think, Alex? Yeah, well, you know, they did say that WadFree, on the day that this show aired, had their best day of sales ever, so, you know, I'm thinking that the built-in sort of marketing and PR you get the show probably offsets the, the worst terms you get from the, the VC side. Keen insight there.

Yeah, I love it. Uh, moving on, we have acquisition news. Um, WellTalk, local tech slash healthcare company, was acquired, um, by Virgin Pulse this, uh, last week, a couple weeks ago. Yeah, and, uh, WellTalk, you know, they've been a little quiet around town recently. They, for a number of years, they were on some of these, you know, fastest growing lists Um, but, you know, they do health analytics and, uh, Virgin Pulse is also a sort of a similar company.

I think they do employee engagement around health. Um, so I think now they're going to come together and make one, uh, bigger and better company. Yeah. WellTalk's an interesting one. You know, they, for years from 2015 to 2019, they made that Forbes fastest growing list and, um, where a lot of folks expected them to be Denver's next tech unicorn.

Something just stopped along the way. I don't know what it was, but they just stopped that trajectory. We've known a few of the security folks over there over the years. The article does specifically say that the 100 people here in Denver for WellTalk will stay here in Denver. This will still be the headquarters for the WellTalk part of the business.

Yeah, and Virgin Pulse, their CISO is Chris Kistler, who used to be the CISO at Centura Health. Centura, and then he went over to Cognizant. Congratulations to Chris for his for his company, getting to have some more Denver roots. Hopefully that maybe this convinces him to stick around here instead of leaving us. There you go.

An update on a story we had talked about previously, the, the Stackhouse project, which was a condo development they were talking about on Colfax where it was made up of shipping containers. So there was sort of a, a giant rack for all these shipping containers and you would buy the shipping container and live in it there as part of this project. Sadly, the project has been scrapped. Yeah, it's definitely bummed me out. They were going to be able to put 62 containers in this building.

I know they have some artist renderings of what it's going to look like. It looked like a neat opportunity and affordable housing, actually, where you could buy, buy one of these for, I think, just over $100,000. So the article goes into some really interesting details about why this didn't work. You know, one element was that the seller wanted to get their money a little bit more quickly than the buyer was able to do it. And that the— but the more interesting thing to me was that, as the people behind this project started to talk about it publicly, like the kind of thing we were sharing, they got some real resistance from maybe community organizers and local representatives in the government who didn't seem like they wanted this project to happen.

Yeah, I think the other thing that I noted as part of that, the They talked about the developer as the gentleman and his girlfriend were the team behind this and that they had never done any sort of development work before. So I think probably coming out of this with some lessons learned about, you know, maybe next time on how to do things differently.

The article does mention that, you know, there was going to be 62 homes here. They had 12 deposits already. So they were, they were on their way and those are getting refunded. Alex, have you got your refund yet? I'm still waiting on the check in the mail.

Yeah, keep waiting. Keep waiting. All right. Next, we have a story about 9 Colorado companies that rank on Deloitte's list of fastest growing tech businesses. So this is another one of those lists we've talked previously, I think, about the Inc. 5000.

And so, yeah, 9 companies here in Colorado. Robb, do you recognize any of these? You know, I just recognize— well, I recognize all 9 of them from, from a few minutes ago when we did this. But, but Red Canary made the list. You know, this is where I work now.

And Red Canary's had some great growth. I cannot vouch for whether the stats in here are accurate. I, I don't even know how they did this, but it's— but it needs to be recognized among a list of other companies that I don't know at all. Yeah, I think Quantum Metric and Billing Platform are 2 ones that I think we may have talked about. Yeah, on the show before.

But yeah, most of them don't recognize. And Red Canary is number 252 out of 500 with a 520% growth rate. So other companies on the list: Maxwell, Liquid, or Liquid, I don't know because there's no U in Liquid, A2 Biopharma, Evolve, Zynex Medical, and Adcelerant. Yeah, good stuff. All right, next we have maybe my favorite story of the week, which is an announcement of a brand new Colorado security company.

This is called RADICL Defense, and radical is spelled radically. R-A-D-I-C-L.

This is created by Chris Peterson. Chris was one of the co-founders of and the CEO for LogRhythm here in town. And they created a new company and they announced their $3 million seed round here. Yeah, just correction. He was CTO of LogRhythm.

CTO at the end, but he was CEO. Was he CEO first? Before that? Yeah. Okay.

Before they brought in Andy. Okay. And yeah, so interesting, interesting announcement here. There's not a whole lot in the announcement itself. I think they're really just getting the company started.

But the focus of RADICL Defense is to help the SMB space to really beef up their security. You know, smaller companies, they really don't have the, the cash or the staff that an enterprise company does to be able to create a good security program. So hopefully these guys will be able to help them in that. Yeah, good stuff. The one thing that, that I think as I was reading through it that I was, I was looking for the whole way was, hey, great mission.

They're going to, they're going to help solve state actor threats for SMBs. How are they going to do it? And as I was reading the announcement, I was looking for, hey, we're going to put a new agent on your device, on your endpoints. We're going to give you network coverage. We're going to be your cloud.

There's no details about what they're actually going to do. Right. Yeah. So maybe we'll have to get Chris back on the show and do an interview about what they're actually going to do. He does have— if you follow the link in the show notes, he does have a video, 90 seconds or so.

It's very stirring, very exciting. If that doesn't make you want to send some some, uh, seed money to them, I don't know what would. Yep. All right, uh, next up, Ping Identity has achieved FedRAMP, uh, process designation— oh, sorry, in-process designation for its cloud identity and access management solution PingOne. Yeah, this is a really big accomplishment, and I'm just really thankful to get to shout this out on the show.

As I came into Ping in 2016, you know, one of the— maybe the second quarter I was there, we started looking into what FedRAMP would do and what kind of market opportunity was behind it and the level of effort to get it. It was a lot of effort. We didn't start the work back then. I think work started in 2019 maybe, but just a ton of really good work done by good folks. I want to shout out to Sean Fredrickson, who's, who's led the charge, and Steve Grierson, who came in and became the program manager for that.

Lauren Russin and Wiley, a lot of good folks have worked on that project over time, and I'm excited to see where this goes. You know, I know that once you're in process, you can actually get customers to sign up. They're able to buy. And so I'm sure this is driving some big growth for Ping. Robb, was the potential market billions of dollars?

Billions. I'm sure it was. Yes. All right. Moving along, we have a story from Coalfire, which is a release about some research that they did jointly with Dark Reading.

Dark Reading, the well-known analyst firm out there that does all kinds of research. I think, you know, maybe using the word research here a little bit loosely as it's more like a survey, but it's a survey of CISOs to understand how their organizational influence is changing and really how their jobs are changing. Yeah, and some interesting notes out of that. First, 20%— excuse me, 27% of top security leaders are now reporting to CEOs, which is higher than I have seen in the past. And you know, frankly, a little surprising to me.

Yeah, it's higher. It makes me wonder, you know, who are the people doing the survey? Is it accurate? You know, I don't know enough about the methodology, but I think it's a good trend to see security leadership moving up in the organization. Another interesting thing I pulled out of here was that the top reason that CISOs leave an organization is not for more money.

It's specifically because they are no longer able to garner support for their security initiatives. Yeah, I— that was an interesting question for me too. And, you know, I haven't read the entire report, and maybe they go into this more. But, you know, I could see some additional questions stemming off of that one. Is it, you know, is it because, as you said, Robb, you're no longer listened to after you've been around for a certain amount of time?

Or, you know, is it that CISOs are just not as effective at their job as they should be? So yeah, hard to know. Or maybe because like, Frankly, companies get to a risk posture that they're comfortable with. And frankly, that might be okay for the company, and this might be an okay situation, but the CISO says, I want to make it better, and the company says, well, we're pretty happy with where we are. It's hard to say.

Right. One other thing to call out here, a local friend of ours, John Hellickson, who is a CXO advisor for Coalfire, he has a quote in the story, so I thought I'd pull that out. John, CISOs who demonstrate added value to the business will be more likely to receive support. We see positive organizational change when the CISO aligns their security program to business objectives. Agreed.

Amen. Yep. All right. Moving on to our last story. CyberGRX has an announcement talking about a new service where they're applying machine learning to transform third-party risk management.

So, you know, the basic idea behind CyberGRX is they create this platform, this this third-party exchange where, where they go out to companies like, like Anschutz and they say, Alex, you know, I'm going to give you a security questionnaire and maybe I'm going to send people on site to review what you guys do for security practices. You fill all that out and, and the results of that go to your customers on a do-once-use-many basis. You know, very similar to the idea of a SOC 2, but it gives you this nice website, this nice portal to do it through, and people can sign up and get access to all their different vendors through that one place. So the idea behind this machine learning, I think, and I'm just trying to read between the lines in this press release, is, you know, they get those results from you and they use that. And maybe in addition to that, some other third-party data like a BitSight score or something else that they add up to say, well, what are they— what is Alex likely to say next time we ask these questions?

Right. You know, what's— what is the 85% confidence response going to look like? Yeah. I mean, and it's interesting, you know, what can you do with that? Right.

So Is 85% confidence, is that good enough? You know, or are the 15% that they don't have the right answer to, are those the key questions that you need answered? Can you just ask them those, that subset of questions? Can you? I don't know.

I don't know the answer. It's the percentage of questions. I think it's the confidence with their answers. Yeah. Like we feel 85% confidence.

So they don't know which 15% are not going to be right. I really struggle with how you use this kind of a model to, to your point, like, do I, well, the ones I'm really confident, I'm 85% confident that their answers are gonna be great. Is that good enough? Right. But like, what if, what if someone quit?

Like, you know, it's just, it's really hard to know how I use that, those types of data. Yeah. I don't know. I mean, can you, if you only do these assessments, you know, in a certain amount of time, every year, every 2 years, every whatever it is, could you use this insight, you know, in the interim to see how answers may have changed? Or something like that.

I don't know. Yeah, maybe it's, maybe it's not to take the place of questionnaires. Maybe it's to give you continuous monitoring instead, in which case it's just a net add, which is right, which is good, right? Like now I have more information and if I see that thing dip, the predictive index says, well, we think Anshutz's answers are going to get worse. Well, I'm kind of curious why, right?

And maybe you do more as a result. Who knows? Anshutz's questions will not get worse, Robb, just FYI. All right. Those are the stories we have for this week.

So why don't we jump along to events? We have a calendar of events on the website. I'll tell you, there's not a lot to look at past December right now. I think most groups think on a calendar basis. They schedule their events through the end of the year, and somewhere in late December, early January, we'll see 2022 start to flesh out.

But, but there's just a few things left this year. I think there is also still some uncertainty, Robb, about what future events might look like. So, yeah, fair point. That could be some of it. So, but we do have a lot of, a handful of things happening in December, and most of them are end-of-year celebratory type things, including on the 1st of December, ACES, the local physical security group, is doing their holiday happy hour.

On the 3rd, ISSA Colorado Springs is doing their annual Star Awards. On the 8th, we have the annual joint holiday get-together between ISACA and ISSA Denver. This is one of my favorite meetings around. It's pretty cool to see the 2 different groups get together. And, and, you know, just have some fun.

Hopefully you guys can make it. On the 9th, ISC² Pikes Peak is doing their annual chapter meeting. And finally, on the 10th, the Let's Talk Software Security group is getting together to talk about software vulnerability management. All right, that sounds like fun. That's it.

So now we'll, we'll go ahead and, uh, move over to the feature interview. This, this feature interview is actually the reason that we're doing a podcast this week. We, you know, we, we've taken a few weeks off, but Um, we, we were asked to do a keynote, uh, at the Avanta CIO CISO event and we figured, hey, let's record it. Let's share it with our community. Yeah.

And we had started this process, you know, probably almost 2 years ago. Um, Avanta had asked us to do the keynote. They do an in-person conference in Denver every year. And then, uh, of course COVID happened. So that got delayed and, uh, we're finally able to meet in person this past week.

And, uh, yeah, we did an interview with Diego Silva, the CIO of Gates. And it was a great interview. I'm sure people will be excited to hear it. Yeah, Diego's doing a lot of good stuff over there. It was good to get to meet him.

All right. Well, that's it for now, Alex. Happy holidays. Enjoy your, your sweet potato casserole and enjoy the stuffing, Robb. And I certainly will.

All right. Sounds good. All right. We'll talk to you soon. Thanks, Robb.

Hi, this is Curtis Letson, the CISO for Pulte Financial Services, and this is Colorado Equal Security. For Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is a very special podcast where we're gonna, we're gonna get to talk to you guys here a little bit, and this is also gonna be broadcast out on our stream afterwards. So I have some bad news.

There actually are 3 security podcasts in Colorado. We're just the best of the 3. Yes, clearly the best.

Um, one, one of the other podcasters, just on a regular basis, uh, he admits that he's the second best. The third guy, uh, he, he doesn't know. He doesn't know what's going on. These are, these are all true facts. These are all true facts, guys.

Um, Alex, you want to say anything before we get kicked off? No, I'm excited to be here. Uh, great to see all of you guys. Excited to be doing this in person, and great to see everybody. All right, so first thing we're going to do is we're going to talk about why the Colorado Security Podcast, or Colorado Security, Equal Security Movement exists.

Alex and I have been pretty involved members of the community for well over a decade. And I think the most, the best way to talk about what we've been trying to accomplish with this movement is to just take the perspective of what's changed. When I first really made a serious effort serious transition from being an IT guy to a security person. I'm like, all right, well, what things are there for me to do in Denver for security? How do I get plugged in?

How do I get to know the community? So I used the best research method I'm aware of, which is Googling it. And what the Google did is it found me ISSA and ISACA. Those are 2 pretty good groups in town. And I went and got plugged.

I actually went to both of them, tried them out. I'm like, well, ISSA is a little bit better fit for me. Alex actually walked up to me at a meeting. He was president at the time. He's like, he shook everyone's hand and he shook my hand and I'm like, well, I should get plugged in.

I said, I think I sent an email and said, hey, I'd like to volunteer. And I was thinking like, I'll like sit at a desk somewhere. He's like, well, we got 4 open board positions. Which board position do you want? You're hired.

So by the way, if you ever wanna volunteer, it's pretty easy to do.

But, you know, fast forward from there 5 years, and I started to see this whole world of things other than ISSA and ISACA that were happening in the community. There's the Den Hack Space, there's the 303 Group, there's CSA, and there's OWASP, and all these other communities that did not show up with my very advanced Google food that I did. And we realized not only are these formal groups there, but there's all these other things that we wanna, that people should know about. If you move to Denver and you wanna get plugged in with the Colorado security community, How do you do it? It was, it was very— it was hidden.

It was the expectation that you're gonna spend 3 years learning what the community looks like before you get plugged in. And we said, that's a problem we can fix. So Alex and I, who had both at different times served as president of ISSA, decided let's, let's create a place where we can amplify the good stuff that's already happening in town and help make it— make a community out of this. We've— one of the things we do is help get security leaders together for dinner. So, you know, either, either you're already a part of it, or if you're not, you should be.

Um, or, or maybe if you're a CIO, you have CISOs who you should get involved with this thing. We've been doing that, and then we've, uh, you know, we're really just looking at success as being letting the community know what's going on, and frankly, letting the rest of the country know that Colorado has a, has a pretty awesome security community. So how did this really manifest itself? You know, what is it that we're actually doing And there are a few pieces to Colorado Equals Security. So I think as Robb mentioned, we didn't want to try and do things that were already being done, but really just to amplify everything that was already out there.

So what is Colorado Equals Security? For one, it's a website. So we have a number of things on those websites, the website including an event calendar. So we're taking everything that's going on in town, Putting it all together there. A listing of all of the groups that we have in town, whether that's ISSA, ISACA, CSA, other things like that.

And we also have a Colorado security company listing. So if there are security companies based in Colorado, then we're getting information about those and posting them on the website as well. We have a weekly newsletter, so we send out information, we curate news, we talk about jobs. We do a bunch of other things like that to try and get word out to the community about what is going on. I think one of the most successful things, which was not something that we had when we started, but we have a community Slack workspace, and it's basically open to anyone in Colorado interested in security.

So pretty easy entrance criteria, but we've got over 2,000 people that are in that Slack workspace, And it's created a really great communication method, a lot of conversation. It's branched out in all kinds of different ways that I don't think that we were really expecting as part of that. And then of course, the final thing is the podcast. So that was one of the first things that we started, and we really just wanted a way to broadcast out all of these different things that were going on in the security community here in Colorado. And the podcast has also been a great success.

It's, you know, it's been over 4 years and we've got 220-ish, I think, episodes under our belts. And, you know, we've done that more or less nonstop every week for the past 4 years. So it's been a lot of fun. Cool. Well, I think that's it.

So generally on the podcast, we do a little bit of news and then we have a feature interview where we talk and get to know someone in the community. And that's what we get to do with Diego. So Diego, would you come on up?

No.

Welcome. Thank you. Welcome, Diego. We're super excited to get to know you better. Excellent.

Thanks for being with us. So one of the things, you know, we all are so defined by our jobs and by this industry we're in. It's really nice to get to know someone as a human a little bit. So before we jump into all of what you do and your very impressive impressive resume. I want to talk about a different accomplishment you've got.

I understand that you have, you have taken it upon yourself to, to, to do, to do a physical endeavor that maybe you couldn't have done most of your life, and you're doing it in multiple places. Why don't you tell us what you've accomplished? Sure. I think you're talking about the, uh, the marathon. Um, so, um, I had the, uh, opportunity— I started in London.

I lived in England for 10 years to run my first marathon. And I grew up with asthma, so I couldn't run for a long time. So it was a difficult challenge. And then we had a number of friends in London and this particular family that they had a situation in the family. And this opportunity came to run the London Marathon to support a charity or a research institution that looks at research into mitochondrial disease and to raise funds for this charity.

So I decided to jump into it, run the marathon, and then I decided to keep that going. And I ended up running 3 marathons in 3 different continents, in South America, in my home country Uruguay, and also in the US in Dallas. Now that I'm moving to Colorado, I need to— I guess the next one is going to be coming. I need to train at altitude now, so I need to get ready for that. But again, I mean, every time I run this marathon was about also raising funds and money for usually for kids' hospitals that support kids or research into genetic disease like in this case.

Yeah. So awesome to know how much you must have put an awful lot of training into that and such a cool thing. You know, pro tip: train here and just go run somewhere else. It's going to feel like a breeze. Yeah, that's wonderful.

Since I've run marathons on zero continents, I'm very impressed. I was not built for running.

But with that, let's get to know you. So maybe first, why don't you tell us a little bit about your background, where you're from, where you grew up? Sure. So as I said, I was I was raised and born in Uruguay. It's a small country in South America, 3.4 million people, so quite small.

But it's quite known around the world because of— we won the, uh, the Soccer World Cup 4 times, and that's a, a big thing for us. Um, also we have 3.4 million people, but we have 12 million cows in the country, so it's like, like a of cows with some people on it. But one of the interesting statistics that also ties into IT and the cyber community is it's actually one of the top 3 countries in software exports per capita. And they started a program a number of years ago, actually 15 years ago, where every kid that goes to school gets— even the public education gets a laptop. So now we have after 15 years, we have an entire generation that they use computers, they're familiar with that.

And looking at the IT industry and cybersecurity, we're creating a nice community there. But my story started before that, right? I'm a little bit older than that. And I started with— when I got my first PC, I was 9 years old and I started programming and then started programming. Database.

And then when I was 15, I had this summer job and I jumped into this company and I realized that their system that they were using to manage customers was not really good. So I offered them to develop a system for them. That was my first gig. $300 was a lot of money at that time. And that's how I started, you know, having customers, developing systems for companies.

When I was 18, I had the opportunity to open an internet startup, an ISP, and we offer internet access and web design, colocation, everything that comes into that. And one interesting story, this was in 1995, so it was a few years after the internet came. In 1997, I had my first play with cybersecurity. I faced my first incident. It was a denial of service attack, 1997.

We didn't know what it was. We just saw this huge amount of traffic in the network. A few years later, we got to know that that's called denial of service attack. And since then, you know, over the past 20, 25 years, I've seen a lot of security incidents, but cybersecurity has been close to me since then. Then.

So I ran that ISP for a number of years and then I came to the US. I did my— I wanted to do a master's degree to get the business side of it. So I went to UT in Austin, did my MBA. I joined a big global manufacturing company in Dallas right after the MBA. And then I had the opportunity to run a massive transformation through that company.

I went to Europe to help that. Initially became responsible for a number of locations in the north of Europe, then the rest of Europe, then Europe, Middle East, Africa, a number of continents. Became the CIO, the mini CIO for one of the divisions. And then it was the time for me to come back to the US. So after spending 10 years in Europe, I came back to the US 4 years ago, initially to Texas and then early, Early this year, Gates reached out to me with a great opportunity, and that's when I decided to jump, come to Colorado, to Denver, and I moved here in May this year.

Was the goal always to end up in a CIO role like you are today, or did you have different goals earlier on? I knew, I knew I was gonna probably end up there. It was not something that I was really pushing to get there every time through my career. I was just focusing on learning something new and doing great at what I was doing. And of course the opportunity just kept coming and I always started moving up.

But I got to a point early this year or after, you know, in my last company I've been there for 15 years and although every 2 years there was something new, it was a different region, it was a different challenge, I realized that I've been pretty much through, you know, all the areas of IT. And I said, okay, maybe this is the time when I should do the change and jump into the CIO. And when Gates came, that was the opportunity. Yeah. So you have the chance to come into Gates earlier this year, about 5 months ago, 4 months ago, something like that.

Yep.

As you come in there your first time as the big boss CIO, what was your plan? How did you come in and think you were gonna tackle the challenge? Yeah, so as everybody says, you spend the first month listening and getting to know people. I will say the first month is more about drinking from the fire hose. You get a lot of information.

You try to figure out what are the opportunities in the company, what you can do to really change the company, and you start to see also small fires here and there, and you try to identify, okay, which one is is gonna be the priority, which one's gonna burn faster and you need to attack first and which one you can delay a little bit. So I started looking at the business, getting to know the ELT, understanding the business, understanding some of the changes that we could drive inside the organization. I started to look at the, also internally I look at people, processes, technologies. So the team that I have, the processes that we run in IT, the technology that we use. And then based on that, you start setting some priorities on the things that you want to change and transform.

And there is a number of areas that, you know, I focus on. I mean, cybersecurity was, for example, one of them. And since then, last 6 months have been a fantastic journey driving some transformation inside the company. In the last 6 months, I'm sure you looked at coming in the door, are there some big wins I could get early to add quick value to the company? Have you identified, have you had any successes so far you can share?

Yeah, sure. So I mean, let's start with the digital side and customer-facing. A massive amount of improvements in this area. So for example, we consolidated the number of CRM systems that we had into one. So we a massive consolidation.

So now the entire company is running the same CRM system. On the digital side, our e-commerce presence, the way we interact with our customers, distributors. Also, we release new versions of our front end and the way we manage that business. IoT, we also did a number of improvements on the IoT infrastructure. I also look at the the infrastructure across the company with massive improvements on servers, PCs.

I mean, 4,000 PCs around the world. We upgraded that as an example. Cybersecurity, actually cyber was one of the biggest priorities. I mean, as we've seen this year, there was a lot of focus from all companies on cybersecurity. There was a number of important cyber events that brought the focus into it.

So things like multi-factor, starting from multi-factor authentication, which we rolled out in 45 days with the team. I mean, I have an amazing team that did a great job with that. Endpoint protection, server protections, web protection, everything. Actually, our BitSight score, we have BitSight here in the room, we managed to increase that from 520 to 650. 700 only in 5 months.

So it was a massive improvement on cybersecurity. But I think the biggest win for me, more than these individual elements and things that we managed to change in the company, is that I think we managed to create an amazing team now that it's, you know, it's really collaborating, it's working as one. And after 6 months, we are at the at a point in time where we can drive and accelerate this transformation. I have done a number of changes in my organization. So when I came into organization, I found that it was quite fragmented.

We were organized by regions and by sites. And one of the first things that I did is I changed the organization to run as an enterprise. I created verticals for infrastructure operations, for application cybersecurity. So already some verticals also digital. And with that, we can now drive standards across the company in a much faster way.

I mean, I went from 4 direct reports to 8 direct reports, so I pretty much doubled the number of direct reports. And approximately 50% of my organization now reports even into a different, into a different line. So now I feel that we have an amazing team that is gonna help us get into the next stage of transformation of Gates. Diego, that is in 6 months. That's an awful lot of things you just said.

That's a lot of work you've done. And you said now you're gonna accelerate and you're gonna go faster. Yeah. Holy smokes, man. Well, we're just starting the journey.

Yeah, yeah. I think a lot of people in their whole careers as CIO probably don't upgrade and renew 4,000 PCs and servers. So just that by itself in 6 months, pretty cool. Pretty awesome. So thinking about security, oftentimes historically there has been friction between IT teams and security teams.

It seems like security has been something that's been part of your journey as you've progressed. What's your take on that and how have you made sure that security and IT are working hand in hand instead of fighting each other? Yeah, I think, I think that's a great question. I think that friction is not needed. And, you know, in my experience, I think this is the role of the leadership team and in this case of the CIO to make sure that he creates a bridge and that that friction goes away.

One of the things that I've seen in my, in my, in my experience is that sometimes when we look at the role of the CIO, Sorry, the role of the CISO, sometimes he plays the role of being like an auditor, right? So he goes through the company and says, this is good, this is bad, this is good, this is bad. And then we take that, gives that to the IT organization, and then the IT organization needs to go and try to fix. And when we look at the IT organization, usually their focus is uptime, is, you know, making sure we don't disrupt the business. So I'm not going to put the patch because if we— I put the patch, I don't know what's going to happen.

And I think sometimes that's, that's what creates some of the friction. So what I mean, for me, this is a leadership— something the leadership needs to address and the CIO needs to address. Bridge that, create a bridge between both of them, get both organizations and get their entire next line, the entire organization to work as one team that collaborates. If I look at the CISO, the CISO needs to have skin in the game, cannot be an auditor. He needs to have the ability to influence and drive change in the organization.

He needs to be able to speak to the CIO, speak to the leadership team and say, we need to do these investments because of ABC and then influence the organization to be able to drive those changes. And then you have the execution arm on the IT which also the CIO needs to say, this weekend we are going to install patches. And I know that 98% of those patches will go fine. Probably 2% are gonna fail and it's gonna be fine. We're gonna address it.

We're just gonna have a team that's gonna respond quickly and we're gonna address it so we don't have an outage or downtime in the organization. So I think I've seen some of that friction before. I think, You know, it's the role of the CIO to create a team that collaborates and works together. And by creating that type of organization, I think you're going to have a much more efficient security organization that you can really have. Usually if you look at cybersecurity team, those are really small teams.

But then you look at the infrastructure team, operations, the applications team, those are much bigger teams. And those are the ones that really can look after the application, look after infrastructure, do the upgrades to the operating systems. You need to make sure that they drive the change. The CISO will help and guide and tell you what the priority is, what you should do first, second, third. But then everybody needs to work to a team and execute.

And this is one of the things that at least at Gates I've been pushing over the last 6 months. And I think this is one of the reasons why we've been so successful. Going back to your point about speed, how we managed to get that much speed in just a short period of time, because everybody works as one. That's great. I think in some instances where there hasn't been that leadership support historically, some security teams have felt like they would be better off not being in the IT organization, being separate you know, having a bigger voice to leadership and other things like that.

What's your feeling on security living either in the IT organization or living outside of the IT organization? Maybe the trade-offs really into that. Yeah, I think, so in my experience, always, I always had security living in the IT organization and I think that's the correct place for security. One of the advantages that IT has is that it has the ability to see all the processes in the organization. It supports all the functions and is probably a function that can speak in the most fluent way about, you know, how we operate as a company.

So when we look at security and how do we optimize processes and how do we secure processes, I think IT is in a unique position to be able to be effective at securing and protecting the company. And for me, this is the reason why I think the security team needs to be part of that. It needs to be one team. I mean, they have the skills, they know what's good, what's bad, what's ugly. They know what the priority is.

They are close to the IT team that can drive those changes. So having them working as a team, I think, is the most effective setup. My concern is that if you have them separate as a different team, it becomes this auditor situation that they're just gonna go and say this is good, bad, and ugly. But then when we look at fixing that, you start to see these frictions between the different groups and throwing things over the fence. So that's my personal opinion.

I think those 2 teams should be one, be together. Thank you. You know, I get to talk about the future. You know, as you look, as you look into how your program is going to change over the next, you know, 24 months, 5 years, you tell me what timeframe makes sense. What trends do you see coming that have you excited for the future of IT?

So I think, I think the first trend that is exciting and should be exciting for everybody is that every company now is becoming a digital company. And what this is making is for everybody from the CIO to the individual contributor that just joined the company, we have an opportunity to drive change and transformation and really reinvent our companies, especially traditional companies. So IT for a long time has been sitting on the, on the back seat. Now we have an opportunity to be in the driver's seat. I mean, it's in every single ELT meeting.

The CIO can articulate the art of the possible, and we have this opportunity that we never had before to really drive change and make a difference. I mean, some of the conversations we had today were around, you know, how COVID really changed the landscape and how all our organizations look at IT to make sure people can work from home. Lots of investments came into IT. But it's not just because of COVID it's just the fact that the environment is changing and companies need to reinvent themselves. So I think we are— number one is we're in an incredible time for IT and we need to take advantage of this opportunity.

I think the other trend that I'm seeing is that we're moving from control into governance. So in the last 10 years, a lot of the policies around IT have been about trying to get control. When we think about shadow IT, how do we bring everything together? Cybersecurity, how do we make sure we control the entire environment? It all comes together.

But the reality is that when we look at IT organizations, they are quite small. And every company, to my previous point, they're trying to become digital companies. So now we start to see all these business technologies in in the organization. We have data scientists, we have BI analysts, we have people that are not part of the IT organization. So I think one of the critical changes for us is to think about instead of how do we control, is how do we move into a new organization?

We set up the rules and we can govern and we can have a force multiplier in the sense that we have the IT organization, but we also have the business driving some of the IT initiatives. For us and we collaborate, we work together and we are able to accelerate some of the change in the company. So that, I think that's a change in philosophy and management style. And I think for a lot of CIOs it's gonna be an interesting dynamic. Another change that I see is on the automation side.

So we need to automate more and more and more. I mean, it's a necessity when we look at the landscape landscape right now, the number of job openings that we have in IT is huge. There isn't enough people for everything that we want to do. And one of the solutions to that is automate. Not only because we can, you know, we can get the low-value tasks and, you know, get people to focus on the ones that add more value, but also we free up capacity, we manage to reduce costs.

So it business sense, it makes IT sense, and it's actually much better for our teams. They're gonna be working on things that are more exciting. I think the last trend, which is not new, but we saw this accelerate in the last 2 years, is the way we're gonna work going forward, right? It's not about the location anymore, it's about the skill, where the person is located.

The different teams that we're going to have around the world. The interesting thing is that if we look at IT, this started 20 years ago in IT when we started doing outsourcing to different countries. So I think in the IT function we are more used to working remote and having this more dynamic style, but it's something that's new for the business. And I think that that way of operation is going to, is going to, is going to bring some new opportunities that we have not seen before. So I would say those, I think those are 4 key changes that we're seeing right now in IT that are gonna totally transform the industry.

I think we have an amazing opportunity right now. We need to really capitalize on this. The future is in our hands, depends on what we want to do. So kind of a follow-up on those, you know, as you think about those 4 categories, Is there one of them that you can give us a takeaway? Like, here's the thing you can do to get prepared to go after that thing.

Yeah, I think I'm gonna go to the first one, which is IT being in the driver's seat. I think one of the things that we need to focus on is don't be afraid of challenging the status quo. One of the things that I see in organizations, especially in traditional organizations, is this resistance to change. Make sure that you empower your team. Create a team that is empowered to drive those changes.

And I think that's what's gonna really, really move the needle. It's gonna create amazing amount of value. The business is gonna see IT making that contribution and it's really what's gonna be great for all of us. Build the right team, empower them, let them, you know, try new things. One of the things that I said in my first communication to my team as I came into Gates, I sent this email to everybody and said, look, we're gonna move faster, we're gonna accelerate a few things, we're gonna learn new things, we're gonna make mistakes, we're gonna fail, but we're gonna learn from that and we're gonna move forward.

And I think that's the key message here. Don't be afraid to make, you know, make changes and drive and make mistakes and learn. We are getting a green card now to do it. So we need to take that opportunity and move forward. That's good.

Yeah. One of the things that you mentioned in there was around digital transformation and, you know, now everything is some sort of a digital or IT function. You know, every business process has it involved in it. That means that now that every one of those businesses, business process has data, is data-driven, right? So how do you make sure that you are, first of all, at the basic level, you know, doing good governance around all of that data?

And then really to some of the other things that you mentioned, taking that and really using the data to enable sort of the next generation of your business. Yeah, that's a great question. So data right now is more valuable than a lot of the commodities that are out there in organizations. So it's critical that we can capture the data, that we have some data governance programs, we have data-enabled initiatives, and it's not just BI, it's not just, analytics. It's important that as we look at the data, we start capturing the data.

We put the ownership of the data also on the people that create the data, and we make sure that those individuals maintain the data and they understand that data is not an IT asset, it's a business asset. One of the things that I see most of— a lot of organizations struggle is because they look at data as an IT thing. They think, oh well, it's IT's responsibility. IT doesn't create any data in the company. It's the business, the different functions that create the data.

So it's critical for the CIOs and the IT organizations to work close to the business to educate them and help them understand this is your data. These are the governance rules or these are the mechanisms and the frameworks we can put in place to try to clean up the data, increase the quality of the data, convert some of the bad data into something that we can really use. And then on top of that we have the analytics, we have the BI, we can enable new processes. But that's a process. It's not a one-time, it's not a one-time data cleanup, it's not a one-time exercise.

It's a philosophy and it's something that it's important that the IT team, the leadership team leadership team, the CIO drives that into the organization, helps the business understand and get the value from that. It's critical for success. Everything is gonna become data-driven going forward. If we look at automation, the automation's gonna be executed based on data. So it's important that the data is right so the automation will run.

Yeah, one of the other things that you mentioned in your trends was around working anywhere. And I think, taking a little bit of a turn here, you know, for the leadership side of executives, how has the change in moving to a different style of work affected the way that you're leading? And, you know, what sort of strategies are you taking on to make sure that your employees are engaged, that you're you're leading them in the way that they need to be led?

It's a different style, right? So you need to adjust to the new style. So, you know, we just spent the last, you know, almost 2 years driving organizations through a monitor, through a conference call, through Zoom, Webex, or Teams. And there is a number of tips that you learn while you go through the process about, you know, how do you keep people engaged while they don't— you don't see them every day. I think one of the key things is you need to constantly focus on maintaining that team, operating as a team, and that community, feeling of community within the organization.

So touching base close to your team, not only to your first direct line, but also people below in the organization. I think at the end of the day, it's, you know, we're gonna end up in a hybrid situation. And I want to see, I want to go back and start seeing people face to face. I want to travel. I think that's important.

I think, I personally think that for management, for execution, for people's careers, it's important to have face-to-face interaction. So I think at the end of the day, we're gonna end up in a hybrid model. Some of the practices, leadership practices of the past are still applicable. You know, when we look at empowering team and what they can do, even for them to do those things remote. But it's, you know, you need to keep a pulse on the organization and you need to make sure that, you know, everybody's engaged, not only the people that's close to you.

And when we look at even more, I mean, Gates, for example, as an organization being in 30 countries, people from APAC, people from the biggest distances from corporate, they're also engaged and motivated. And I think we need to also find a way to connect not just virtually, but also face-to-face once in a while. I think those relationships, to keep that alive is important. Awesome. Moving over, one of the topics that's near and dear to my heart is identity and access management.

You know, it's critical for both IT and security to be effective. What advice do you have, you know, from your own experience about making an effective identity access management program?

So, um, that is a big, big topic, a massive topic, and I think When I look at identity and access management, I think it's gonna be different for different companies. So for example, in our case, we are a manufacturing company. We have multiple systems going from really legacy systems into modern systems that go into cloud. So when we look at creating a system that can coordinate access and authentication across such a big number of systems, it's a complex challenge to resolve. So there are a number of solutions that help with that.

And I think some of the solutions will also take you to a certain level and then over time as you start removing legacy systems and building in new platforms, you're gonna be able to improve and improve over time. So I think in my view about identity and access management, I think is a journey. I think it's gonna be different for each company. My recommendation is sit down and look at the landscape and figure out what's the right plan for you. You may start with simple things like, well, you need to have multifactor authentication.

You need to start from that. Every company now has that. Everybody can enable it. It's not too difficult. But then you need to start looking at things that, for example, well, okay, now when somebody connects to the VPN, what access that person is going to have to— I mean, to which applications I'm going to allow that person to connect.

And then if I select, okay, this individual, for example, needs to connect to those 10 applications, then you go to the next level of detail, which is, okay, to which screens, what are the roles and responsibilities that within this application that person should have access to. So I think you need to be peeling the onion one by and you're starting building these capabilities. But it's important to have a plan and it's important to understand what is gonna work for your company and what's not gonna work for your company. Alex, I know you have 2 more topics left, but we probably have time for one more. Which one's your favorite one?

I'm fine with either of them. Should we talk diversity? Sure, sounds good. So I think, I think it's pretty well proven that diverse teams make better teams. So what is it that you've done in building your team to make sure that you have a diverse workforce to help you guys succeed at your goals?

Yeah, so diversity is very critical. So, you know, for me coming from, you know, different countries, living in different parts of the world, I didn't share this before, I have 3 different passports. So I am quite diverse from that aspect and it has always been top of mind for me. So one of the things that I do is every time I have an opening, an opportunity, not only I look at the skills of the person, but also the diversity and what this person can bring into the team, how this person will complement what I already have in the organization. And some of the things that, for example, there are small things that we can do to increase diversity the organization.

So for example, one of the things that I'm introducing now at Gates that we've not done in IT— I've done this in other companies but not at Gates— is we're going to start internship programs and rotational programs. So starting January, we're going to have people coming from different universities that will join our team. So we're going to have a fresh number of students that are going to come into organization. Those students, in many cases, they come from different countries, so they have but they also bring certain diversity on them in addition to the fact that it's people that's gonna come with a new pair of eyes into your organization. So this is something that I'm very excited about, creating a more diverse environment even within my organization right now because that diversity of opinion is what really helps you come up with the best solutions come up with new questions and new ways to look at things.

And then that's what drives change. People come into organizations and say, why are we doing this this way? We should— I mean, why don't we try this? And those are the opportunities for us to innovate and to really drive change. So I'm very passionate about diversity.

I think that we have a tremendous opportunity. And as I continue to move forward in the organization, it's something that we're going to continue to focus on. Awesome. Well, I think we've gotten to the end of our time here. Diego, is there anything that we didn't touch on that you wanted to touch on before we're done?

No, just a comment. I mean, as I said, I mean, I've been in the organization for 6 months. It's been an amazing journey so far. We will accelerate, as I said, but we have more demand than we can— we really have people. So, you know, If anybody wants to jump into a journey, let me know.

You're hiring is what you're telling us. It's gonna be a nice ride. Yeah. Awesome. Awesome.

All right. Well, thank you so much for opening up. Did he do okay, guys?

I think it was fantastic. You did a fantastic job and it was really good to get to know you. I feel like we missed an opportunity to do like a newlywed game with you and Dan. Dan Garlick is the CSO for Gates. We— I really feel like we missed that opportunity here.

Uh, it's— but maybe we'll get you guys later for that. Um, thanks everyone for, for listening in. Anything else we should say before we sign off? No, this has been great. Thanks everybody.

Appreciate Avanta having us here, and, and thanks to Diego. This has been great. All right, well, that is it. We'll talk to you guys again soon. Thank you.

Good job.

Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes