All episodes

Leeann Nicolo, Incident Response Lead at Coalition, Inc

Apple Podcasts Spotify SoundCloud

Leeann Nicolo, IR lead at Coalition Inc is our feature guest this week and is interviewed by Janelle Hsia. News from The Beer Spa, mountainFLOW eco-wax, BurstIQ, Ping Identity, Red Canary, Optiv, Webroot and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10068 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 198 for the week of February 15th, 2021. Alex, we're Really close to 200.

You hear that? I know, we're getting, getting really close. You know, we hit the, uh, the anniversary there last week, and now it's going to be another, uh, big number coming up. Milestone. We had another milestone.

Um, we, we also just passed 1,800 people in our Slack community. Yeah, that's a big milestone too. We're, uh, we're just crushing milestones right now. Yeah, we're just crushing it all in general, Robb. My gosh.

I, you know, how do we do it? It, it is, uh, unknown. It is amazing how we've made it this far, this well. Luck and, uh, luck. I think that's what we'll depend on.

Uh, don't forget about that deal with the devil that we made. But oh, and that's how I got to be so good at the guitar. Yes, absolutely. Yes, exactly. You and Ralph Macchio.

Hey, let's, uh, jump over to a little housekeeping. We do have a Slack community with over 1,800 members. You can join that by going out to colorado-security.com and clicking on the Slack button there. While you're on the website, why don't you scroll down to the bottom and fill in the mailing list form, and you'll get the show notes in your inbox every week and nothing more. And while you're thinking about it, you should go to your favorite podcast player, subscribe, Also rate us, you know, we appreciate all the 5-star reviews, all the other ones, yeah, you just forget about.

And, you know, also tell a friend, tell anybody, let them know about Colorado Equal Security. Let's get that Slack channel up to 1,801. Of course, also we do have a Patreon campaign, so if you'd like to support Colorado Equal Security in a monetary fashion, we would appreciate that. You know, anything that doesn't come from Patreon comes out of our pockets. So, uh, we love to have the support from our— all of our patrons, and thanks to them.

And we did actually get a new patron today, but we haven't heard back yet to get to say the person's name. So for now, privacy is being protected. Hopefully next week we can— we can let you know who it is. Yes, uh, looking forward to that. Big thanks to that brand new patron named Beep.

Uh, very excited about beep. Hey, let's jump over to the news. Uh, you know, we love to start with some fun news, and this news was, uh, was interesting and different. There is a new beer spa by Snug that's launching here as, uh, as the pandemic restrictions wind down. This new spa is going to come around.

Alex, what is a beer spa? Uh, well, it's, uh, you, you go in and they pour beer all over you. That, that's what— it's actually not that close, not that far from the truth. It's not that far away. No, they, uh, it's not, uh, you're not bathing in beer, but you are bathing in, uh, a tea of sort of beer ingredients.

It could be hops or, uh, or barley or other things like that, as well as being able to drink your favorite beer while you're there. So the, the founders of this new establishment, uh, they did a tour of Europe to look for business ideas that were doing well in Europe but hadn't made it to the US, which by the way sounds like an amazing reason to go to Europe. And regardless of whether you come back with an idea, it sounds like a good idea. Anyway, while they were there, they came across this idea they'd never heard of in the US. Obviously Denver loves our beer and we, we definitely have the, the, I think hipsters, the folks who would want to use a beer spa here in town, and they're going to give it a shot.

So, Robb, I think what happened was they decided they wanted to go to Europe and they thought, okay, how can we go to Europe but still write off all the expenses for taking a trip to Europe? Man, that's a great idea. And apparently they figured it out. It sounds to me like I have a business trip coming up.

The Colorado Equals Experience, you know, goodwill tour in Europe. I, I think I'm, I'm definitely up for this. Anyway, it is— it actually just opened on Friday the 12th of February. Uh, it's open even during the pandemic. They have lots of good cleaning protocols in place, so it should be safe.

And I would love to hear from any of you who go and tell us what it's like to soak in a beer spa and drink while you're drinking a beer. Yes, the, the first person to go and tell us about it will be the first person to go and tell us about it. That's a good prize to win. Looking forward to it. All right, uh, next, a Colorado company has landed a deal with 2 of the Sharks on ABC's Shark Tank.

So this is pretty exciting. Um, this is a company that makes an eco-friendly ski wax. And, you know, I guess I hadn't really thought about it before reading this article, but it does make sense that you might want an eco-friendly ski wax because, you know, most things in this world ski wax apparently is made from petroleum. And as you're skiing, it comes off your skis and gets into the snowpack, and that's probably not where we want it. That's pretty awesome.

This is not the first time we've had a Colorado company that made a deal with a couple of the Sharks. Uh, this one, it looks like it's going to be, uh, with Barbara— is it Cocoran? Cochran? I don't know. Yeah, I forget her name.

And the other one was Mr. Wonderful, right? There you go. Yeah. And he's making a $300,000 deal and giving up 20% of the equity in his company.

And we didn't even mention the company, right? It's called Mountain Flow. And the product itself is Eco Wax. Yeah. So, pretty cool.

I'm glad to see companies that are doing things that are good for the environment and cool that they're here in Colorado. All right. Jumping forward, you know, we're a little bit of the ways into 2021 now, but it's not too late to talk about some 2020 stats. So, DIA had a pretty big drop in product traffic last year, about a 51% drop. You and I were talking about it, um, you know, and, you know, I think your comment was a little bit of surprise that it was only 51%.

And this, these, uh, this article goes into some interesting detail about, um, how that happened. You know, there was like a 90, 90-plus percent drop in like the April time frame, um, but for the year, dropping of 51% still left DIA as the, the 3rd busiest airport in all of America. Yeah, serving 33.7 million passengers. It's hard for me to imagine that there were still 33 million people that went through DIA during the pandemic. Yeah, I guess that's true.

I, I suspect that they're not making it up, uh, but it is a really big drop. And what I thought was interesting is they, they said the last time there was a comparable number of people who went through was 1997. So you're talking 20-plus years ago is the last time they were that low. Yeah, and that was just when the, the airport was basically brand new. So, uh, pretty amazing.

Uh, and I imagine, you know, we'll get back to a somewhat more normal number this year. Um, you know, maybe not what it, uh, what it was in 2019, but, uh, I would say we'll probably be on an increase from that 51% drop. Yeah, I would, I would expect you're still going to have a pretty significant discount over 2019, but, uh, compared to 2020, they're, they're going to be very thankful. Yeah. I think as soon as people feel like it's safe to travel, everyone is going to be traveling.

So at some point this year, it's going to get pretty crowded, I think. Yeah. All right, uh, next we have an article talking about, uh, downtown tech companies and, you know, what they're going to do in a post-pandemic office world. Yeah, this is an interesting one. I, I'd say that there's not really any news in here.

It's kind of a roundup of different conversations that Denver Business Journal has had around town. Uh, they, they do talk about, you know, 4 of the largest tech employers in downtown, which are Gusto, Vertafore, Ibotta, and Guild Education. And they just talk a little bit about their strategy for what they're going to be doing after. Ibotta, on the one end, is, hey, we want to get people back, everyone back in the office as soon as possible. That's a big part of the culture.

Whereas other employers are looking a little bit more open to the idea of having full-time remote or even hiring people from different states. Going forward? One of the things they talked about with Facebook is that Facebook is trying to generally diversify where they have people, make smaller pockets as opposed to everyone being in California, and Denver's going to be one of those places.

And then they talked a little bit about Guild Education where maybe they'll still focus on having people here, but probably not in the office full-time. Um, but then also expanding to have people in other markets as well. Yeah, pretty good stuff. Pretty good stuff. All right, next, uh, there is a— there's some blockchain news.

Uh, let's— our favorite. Maybe hit the blockchain button, somebody. Uh, is it a clown noise? Is that what that is? Sorry, I don't know.

Uh, so BurstIQ deploys proprietary blockchain-enabled technology to securely track COVID-19 vaccination efforts. Uh, this is, you know, there's an awful lot of work going in right now around COVID-19 vaccinations. And I actually thought this was interesting in that they are looking to track the vaccines from manufacturer all the way, you know, until they get into the arm of the patient and using blockchain as the way, the ledger to do that. Yes, that seems like a good thing to do.

I'm not sure that they needed to use blockchain to do it, but it is a way that you can possibly do it and they appear to be doing it. So congratulations. To them. It was interesting to me, the last paragraph of the article, their sort of summary of why they're doing this is that the more that you can trust the data, the more trust you have in the system, which is true, but again, I don't know that you necessarily need blockchain to trust the data. Well, that's the only way I can trust data.

There's a blockchain to it. Yeah. Hey, jumping ahead into some not quite so fun news. The University of Colorado has reported a breach of their systems. They were the victim of a breach that impacted Aselion, which is an FTP kind of file transfer system that they use internally.

Apparently there was a vulnerability in Aselion and that impacted CU, and it sounds like the impact is going to be pretty widespread. Yeah, this is affecting a lot of Aselion customers, and it sounds like from one of the stories— not this one that I was reading— Um, that, you know, this could have been exploited for a long time, uh, for, for many of these customers. So I think, uh, it's gonna be a big investigation, and I think it's gonna be, uh, you know, a bad few months for Aselion. So it sounds like it's gonna be a bad few months for the security team over at CU as well. So definitely, uh, heart goes out to those guys.

It's no fun to be be having to deal with this. And certainly, you know, sounds like it probably wasn't something that they did, but, uh, you know, they're the ones who have to clean up after it. Yes, it was interesting. One interesting fact they call out in the article is that there was a, uh, there was a breach back in 2005 that exposed about 50,000 records, and the spokesperson from CU said that this attack is expected to certainly exceed that attack. So I mean, it's just a— it's a lot of people who are going to be impacted here.

Yeah, not good news. And another example of the recent examples of problems with third parties and supply chains. So no fun. Yeah. Well, speaking of good news, there's a comparison blog here from Ping this week comparing Ping to Okta, and you're not gonna believe it.

The Ping blog thinks Ping Identity solutions look like they're probably better for most enterprises. You know what, Robb? I don't believe that. I can't believe that a Ping article would say that. Yes, so this is, this is just them talking about, you know, how Ping does enterprise, kind of enterprise-grade identity solutions.

They go across, you know, how they're better suited for enterprises and their cloud migration flexibility and some other stuff. Anything you want to call out of this article? I mean, nothing in particular. I mean, I would say that You know, from what I've seen, you know, Okta excels at the, you know, sort of startup, you know, pure directory and SSO kind of pieces, and, you know, Ping really has their foot in the enterprise side, whether it's customer identity management or, you know, other mixed environments or things like that. So it doesn't surprise me that there are some good reasons why Ping might be better in the enterprise space than Okta.

All right, well, I'm going to keep my mouth shut on this one as I'm obviously not— I'm a little bit biased. I can't believe it. Next, we have a blog from Red Canary. This is another good one from them. This is talking about how to detect process masquerading, and in this case, they give a good and detailed overview of what process masquerading is and the ways that attackers can instantiate that and ways you might look for it.

Well, I, I definitely, uh, feel like you've missed the most important part of this story, which is that it mostly compares Process Masquerading to the— what was it— 2002 movie Catch Me If You Can starring Leonardo DiCaprio, built based on the, the real-life story of Frank Abagnale. Uh, and I thought that that was fantastic. They, they, you know, they go through this story. My guess is somebody just watched this movie and was like, man, I gotta write a blog post about this. But, but it may, you know, it makes it a little bit more fun than just your normal boring security blog.

Yeah, it's always nice to have a little bit of a theme to your, your writing. So, uh, I definitely did enjoy that as well. But, um, as usual, Red Canary has a great sort of in-depth technical blog here for folks that are interested. Yeah, and I think that, you know, this is worth just knowing for you guys who have, uh, SOCs, you know, if you're looking for what kind of bad behavior might happen on a Windows machine Man, this goes into a ton of detail, you know, talking about the different ways that they, they can try and fly under the radar as a process you expect to be on there. I think it's, it's worth sending over to your favorite SOC analyst.

And of course they do match everything up to everyone's favorite MITRE ATT&CK framework. Well, of course they do, 'cause that's, that's where we are these days. Exactly. Hey, speaking of blogs about endpoint security, we have a blog from Optiv this week about Endpoint Detection and Response and How Attackers Have Evolved. This one was a pretty thick reading.

There was no movie quotes in it. It's awfully long and a lot of detail. Sounds like you enjoyed it, Robb. If what you're getting from this is I had a hard time getting through it, that's true. But I do think that there was a lot of good content.

And for those who are looking to understand how attackers might try and circumvent EDR, I think this is the right reading for you. Yeah, I agree as well. It was long, lots of great detail in here talking about EDR, you know, ways that attackers can potentially get around EDR and a little bit of what you can do about it. This is also a, you know, part 1 in a multi-part series, so I'm guessing that they're going to come back with some more details and, you know, maybe some additional pieces around being able to remediate. Yeah, it's going to be such a big series.

They didn't say how many parts, they just said multi-part, right? It's gonna, it's gonna be long. That's the, that's the gist here. Uh, moving forward, our last security story of the week, we have a blog from Webroot, uh, and this is, this is much more my style. I could read this one.

Uh, Enemy Personas Explained: Know Your Enemy and Protect Your Business. They go into, uh, some, some personas that might be looking to, to get into your organization? Yeah, um, again, uh, another good, uh, straightforward blog here by Webroot. Um, you know, the— they talk about a couple here, you know, the imposter— excuse me, impersonator, uh, the opportunist, uh, someone that looks for, you know, uh, public events and other things to, uh, to go for exploits, and the infiltrator, who is, uh, someone that looks for specific organizations and looking for a number of ways and tools and tactics to get into a specific organization. And they do some steps to actually go through giving you more information about each of these types of actors and might— what you might wanna do about it.

Interesting reading. I recommend taking a look if you're interested in a little bit of threat modeling. Yeah, good stuff. All right, that is it for news. Uh, next we get to talk about the Slack Message of the Week.

I want to do a big thanks once again to Andre Gaeta. Andre's been sponsoring us for a long time, and we do appreciate that, Andre. Each week we get to, to give a message or an award, excuse me, to one person who moves the conversation forward in the Slack community. And who do we have this week, Alex? Uh, so this week, um, we gave the award to Ross.

Congratulations, Ross. He posted— Ross Hosman. Yes, Ross Hosman. He posted an article in the Slack channel about the vulnerability that was announced this past week for masquerading dependencies. You know, basically someone figured out that if you create things like npm packages that have similar names to other things that companies actually use, then their automation was actually picking these other packages up and not really looking at them and including them in their builds.

So, uh, pretty interesting there, sort of a novel exploit that, uh, now it seems like is being, uh, patched and fixed in a number of places based on these, uh, this research. So good stuff, definitely good stuff. Uh, congratulations to Ross, you'll get to pick one item from the store. Hopefully he picks something beautiful so we can all see, watch him walking around town wearing, wearing some beautiful Colorado Equal Security swag. Exactly.

All right, uh, with that we can jump over to events. If you want to see all of the events, we have an event calendar on the website at colorado-security.com, and we're going to talk about the ones that are coming up in the next couple weeks. The first one of those is the CSA Colorado chapter is having their February chapter meeting on February 16th. Uh, on the 16th as well, ISSA Colorado Springs has their February meeting. On the 17th, it's a busy day.

OWASP is doing their February meeting. Also, ACES is doing a security and healthcare panel discussion with IAHSS and ACES Mile High. And finally, on the 17th, ISSA Denver is doing their women in security— what do they do, quarterly meetings? Yeah, good stuff. I do love those women in security meetings.

We, on the 18th, we've got ISACA Denver doing their February chapter meeting. On the 20th, ISSA Colorado Springs is doing a mini seminar. The 23rd is the Colorado Equal Security Poker Night. Jason Jaques has been putting this on really throughout most of the pandemic. Uh, this is just a chance for you to get out with folks in the slot community, play a little bit of poker.

I think it's a, it's a pretty small buy-in, $20 or something, and, uh, generally there is a, a bottle of booze and the cash prize for the winner. Uh, hopefully you guys can get joined in if you haven't heard about it yet, take a look at the Slack channel. There's a, there's a channel for poker where you can get signed up. Good stuff. On the 24th, ISC² Pikes Peak is having their February meeting.

Also on the 24th, ISSA Denver is doing a, an event on CCPA 2 and CPRA, which are basically giving you an update on the California privacy laws. And finally, on the 25th, ACES is doing a I'm assuming Young Professional Happy Hour with Colin Doherty. Good stuff. The, you know, we had a while where there were not a lot of events, but man, they got picked up in earnest for sure here in February. Back in droves.

All right, let's move over to jobs this week. You know, each week we do like to highlight some of the jobs we think you might be interested in in the community, either those jobs that are, you know, a good position or at a good company. You know, in this case, there's some, I got some of both. There's some jobs at Ping that I'm hiring for. I'm looking to hire security program manager, someone who I work with very closely on, on how we communicate and prioritize within our program.

We're also looking to hire a business analyst who works directly with that program manager, and I'm hiring a couple of different product security engineers. So that's people who have a development background and, and want to do more security. Good stuff. Metro State is looking for a cybersecurity affiliate/part-time instructor. Jefferson County Public Schools is hiring a senior information security analyst.

NREL is looking for a cybersecurity analyst. You know, NREL has had a lot of positions over the years. Yeah, they have. They, they must be doing a lot of cool stuff in security, or that one person who's there just turns over every, every 2 months. One or the other.

Hard to know from outside. Uh, First Bank is hiring a manager of information security. Front Door is looking for a security engineer for GRC. FireEye is hiring an incident response and red team internship. So this is a remote summer internship this summer.

Yeah, good stuff. And finally, Visa is looking for a cybersecurity analyst in identity and access management. I love it. Uh, that— well, that is it for news. We do have an interview this week.

Uh, we have a big thanks to Janelle Hsia for, for doing an interview. She sat down with Leeann Nicolo. Leeann is in charge of incident response at Coalition Inc., and we're going to get to learn a little about her. She actually worked at Kivu Consulting with Douglas Brush, and I don't know if that's how she got connected to the community, but that would be my hunch. Yeah, and I know Leeann.

She's actually done some work on my behalf in the past. So get out of town. I didn't know that. Looking forward to, to hearing what they have to say. Well, good stuff.

All right, well, thanks everyone. We'll look forward to talking to you next week. Hopefully everyone is not freezing and, uh, yeah, stay warm, whatever. Save whatever plants you've got that made it through the winter so far. Exactly.

Good stuff. All right, Alex, we'll talk to you again next week. All right, thanks, Robb. This is Jay Wilson, CISO of Healthgrades. Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equal Security. This is Janelle Hsia. Today I'm excited to interview Leeann Nicolo. I hope you enjoy our conversation. So Leeann is an incident response leader at Coalition.

Hi, Leeann. Welcome to the podcast. Good morning. How are you doing today? Lovely.

Just another day working from home. Exactly. I know it's pretty overcast and cloudy here. How about for you? It's sunny 7 days a week, and today we do have overcast and clouds, so same bandwagon.

Yep. So, uh, Leeann, can you tell us a little bit about yourself? Sure, absolutely. So I am from New York. I currently reside in Denver, Colorado.

Um, I started my career journey with the path of pre-law, so I went to school in upstate New York. I wanted to be a lawyer as a young kid. My 2 of my aunts were lawyers and they seemed happy and wealthy. So that was my journey in life. Um, and then when I got into school, I realized I was much more of a numbers person rather than reading comprehension.

Um, and after a few law classes, I realized that law school would be daunting for me. Um, so I started taking, um, just random electives to kind of get my interests out there. And I took a networking class. Um, and I remember hearing the professor discuss how text messages got from one cell phone to another. And I was fascinated, so I ended up switching my major, graduated with IT.

I worked for a— I ended up getting my master's degree in cybersecurity specifically, and then I started working for a major broadcasting firm in New York City and then moved over to consulting, really starting in IT consulting, which was definitely a fantastic background And now I work for an insurtech company out of the Bay Area. So like you suggested, I lead an incident response team. So definitely been an interesting 10 years, but it has been fantastic. That's awesome. And I like how, you know, you kind of started on one path and then realized you had a passion in another, and now you're able to really pursue your passion with what you do today.

Absolutely. And cyber was so new then. I remember trying to apply for master's degrees. This is 2010, 2011, and I couldn't find many. A lot of schools didn't offer them.

So I think I got in, and I hate to say, at the right time, but it was such a fantastic transition for me. Yeah, no, absolutely. So tell us a little bit about Coalition. Sure, absolutely. So we are about 2 to 3 years old.

We are ultimately an insurance firm. So we provide cyber insurance to our policyholders. My brilliant CEO had the bright idea of bringing an IR team internally instead of outsourcing all of our policyholders' claims when an incident does occur. So I started that team 2 years ago now, and it has been— July 2019 we started— and it has been fantastic. So we offer incident response cyber services to our policyholders when a claim arises.

So handling a lot of like business email compromise cases and ransomware cases. Um, so yeah, we're definitely a very tech-heavy company. Um, we offer a lot of things that a lot of other insurance folks do not. And so ultimately I work for an insurance firm, but I'm still very much on the IR tech side. So I do always have to remember that I am in the insurance world, although it's not my day-to-day.

So do you have any tips and tricks for those of us that are looking for cybersecurity? I mean, that's such a blanket question that there really are so many things just unique to every environment. I would say if you take 2 things away from this in the cyber preventative space, it is turn on multi-factor authentication. So turn on MFA on every single thing that you can and close down any remote connections that you don't need. So like RDP, Yeah, the Remote Desktop Protocol, that's a really, really big one.

And if you are leaving it in place, turn on MFA. Yeah, we would probably— upwards of 80% of our claims are due to Remote Desktop Protocol brute force attacks, right? And phishing emails that lead to compromise of business email, which MFA would take care of. So easy fix. Yeah, something, you know, again, I think a lot of what we do is just going back to the basics, right?

And probably logging it and auditing the logs and then encryption. So exactly all of that. So do you guys work across like multiple different carriers or is there a carrier preferred? Because I know for some of the companies that I've worked with, they've struggled to find good cyber insurance. Yeah, absolutely.

So we work across multiple different industries in terms of carriers. We only offer IR services to Coalition insured right now. So we are the only carrier that we work for. Eventually we may open kind of those floodgates and offer our services as like a true vendor, but we're not there yet. So yeah, my team offers cyber anything, any sort of cyber service for our policyholders across any industry.

So there's really not even, you know, we deal with education, law firms, other insurance firms, manufacturing, everything. Got it. Okay. Um, and you had said that you had moved from New York to Colorado. So what brought you to Colorado?

Um, I love New York. I'm very much a New Yorker. Um, you could tell probably within the first 5 minutes of speaking with me. Uh, but it, it was— New York's, New York's a different place to live. I've been there my entire life.

Um, I was in New York City for 5 or 6 years prior to moving. And I was just exhausted. I came to Denver for a vacation with a few girlfriends. And I just remember feeling like I was in a city that had fantastic food, but the people were nicer and things were slower. You know, I remember being here and people would talk about what they do after work.

And instead of happy hour, they were going on bike rides. And I was just like, hmm, I love this. And so I started looking into it. Um, the majority of my work at the time, I was traveling. I was working in IT consulting, so I was all over the country anyway, so they didn't really care where I was based.

Um, but I was prepared to switch jobs if, if I needed. I really was just exhausted in New York. I couldn't save money. I couldn't slow down. Um, and so I kind of came forth with my— to my company that I wanted to make a switch, and they were all for it.

So I got up and came in 2017. Yeah, that's awesome. And I think that work-life balance, you know, is something that we really take for granted here in Colorado. And I think we're frequently, you know, in one of the top places to live and work. So that's great.

Any specific thing in Colorado that you really like to do? I just love being outdoors. And, you know, I was looking at photos recently. I was clearing my phone. I was getting a new phone.

I was going back and I realized last February I was outside in a tank top rollerblading. Not only can I never rollerblade on the streets of New York, but I can never be in a tank top in February. Um, the weather's funky, but it really just with the sun, it's, I think we're like the 11th sunniest city or something. Yep. I, I love being outdoors.

I can work outside. I can take midday breaks, take my dogs on a walk. So the weather, I mean, you just can't beat it. Yeah, no, I absolutely agree. And so you had talked about kind of transitioning to security, and right now you're incident response lead, and you did that previously.

And I think that, you know, there's lots of roles in an IR team, and, you know, there's like the incident manager, there's the analyst, there's people kind of who do the recording. So what makes a good incident manager, a good lead?

If I have a single piece of advice, I would say time management. Our jobs become very difficult. You mentioned work-life balance, which you, you know, if you manage your time well, you can definitely have that, especially because we all are remote in today's world. It's very easy to work from home and just get carried away. So you really just need to manage your time.

That becomes very difficult in IR, as you can imagine. Ransomware really likes its 5 PM on a Friday and 2 AM over the weekend. And so it doesn't allow us much time to be checked out. So having a team where we really can manage the time and making sure people are taking vacation, it's inevitable to be— to get burnt out. One of my managers in my earlier career was really big on vacation.

You know, he would actually remove email from our phones if we went away and we were still online. 'Cause he's like, you're going to burn out and quit. And I can't have that. So I need you 100%. And then when you're offline, I need you to be offline.

That's awesome. Yeah. And so I try to bring that mindset wherever I go that, you know, when you're on vacation, you're on vacation, please don't have to be online because in a year you're going to be done. Yeah. 'Cause I think, you know, cybersecurity people generally tend to be kind of a little bit more high-strung.

And then when you add IR, I think they're kind of a little bit of adrenaline junkies. Right?

I did it for, you know, on and off I've been on IR teams and managed them, and one of my bosses said the same thing, like, you know, we're the people that run towards the building, right? Like, we're like, oh, there's a fire! Oh, there's a problem! Let's run towards that, right? And yeah, I mean, I tell my family we're dealing with people whose hair are on fire, and it's potentially one of the worst days of their professional life.

Every day, right? And so it is exciting. It's fast-paced. It's constantly moving. When people, you know, I have people approach me, I would say 2 or 3 times a week, whether it's on LinkedIn or old friends just saying, I want to get into cyber.

And I'm like, okay, listen, it's a fantastic career, but you have to make time for yourself. You know, you have to make sure that you are asking for help and voicing when you, when you need support. So it's very important. Yeah, and, and I think that kind of segues us into a notable investigation that you did back in 2018 with a mutual friend of ours, Doug Brush, right, who is really big into self-care right now. And there was a report that DJI drones were transmitting sensitive information back to their servers without the user's knowledge.

And I think most people are pretty skeptical of drones and untrusting because of how invasive they are. And then you add the component that they were a Chinese company, right? So can you tell us about that investigation? Sure, absolutely. So that was probably my second or third large investigation, but definitely the most exciting.

Doug is fantastic to work with, and that was— I was brand new at the consulting firm at the time working under him. So they were based in— they're in San Francisco. So we took a trip out there, a few trips actually, just to meet with them and kind of get the background. Exactly like you said, they were suggested to have been selling their drones to people all around the world and potentially transmitting data back to their servers in China. So huge accusation.

We were hired through Doug's contacts as the forensic experts to disprove that or confirm that if that was true. We were hired as a third party. So it was a fantastic experience for me. IoT and kind of the Internet of Things is not going away anytime soon. So I think drones was a big one because they work on all sorts of networks and they collect all sorts of data.

So it was really focused on code review and analysis of the drones to confirm whether or not any data was being transmitted back. So we purchased one of all of them. We had to all— it was only a team of 4 at the time. That really worked on this case 24/7, which was fantastic. So we were very, very close.

We purchased one, we all learned how they work, and then we captured and reviewed all of the data on each. So the data that was stored locally on the drone, as well as anything that was transmitted once it was en route and once it was flying. So we were able to, you know, that you could read the report. I believe all of that is public now, but the details of that suggested that you know, all of the infrastructure data. And I don't even know what else was suggested during the lawsuit, but that a lot of the stuff that was being transmitted back to China was in fact not.

So that was all staying on the local system and it was able to be erased, or they had a little memory card on some of them, could be removed. None of that was being sent back to the servers, which was really, really fun project. Yeah. And I like it when you can, you can kind of be on the side of the company, right? Like, I think we always think of companies as being like the bad evil companies.

And so when When you brought that story up, I was really excited to read it and say that, hey, you know what, this is a company, they're doing what they say they were supposed to do. And I think that bodes well for a lot of other companies, right? Absolutely. And DJI, I mean, in the grand scheme of things, is a baby. They haven't been around forever and they made a ton of money and they just have a great product.

And I think the lawsuits are just, that means you're doing something well, right? But when it's US government, and there was a lot of in-between. And so I was just like, you know what, we are completely third party to this. Let's just get the facts. And, you know, we spent a lot of time with them and their team after the fact and just learning what they do.

So it was, it was great that that was the outcome. Yeah, no, absolutely. My husband is a huge drone flyer. We actually have a drone graveyard in our basement. He's been a drone— I don't know how long.

So when I told him about that, he's like, oh yeah, those are too expensive. We don't have one of those. And I was like, okay, I guess that's good. Yeah, we actually— it didn't impact our investigation at all, but we actually broke one and they just, they just fly, you know, and they're— they do. I know.

Yes, they frequently get stuck in trees at our house. I can't tell you all of the mishaps that have happened during our testing, but we got through it. Yep. That's fun. I love that.

Um, so did you do any major investigations for any other companies that, you know, maybe can't just say their name, but kind of describe another investigation for us? Yeah, absolutely. I worked on— and this is probably the first big case of my career, I was kind of thrown into it early on, which is fantastic experience— but I worked on a major litigation matter for one of the biggest data companies in the world. So all of it is not public, obviously, but the project was about how they were collecting, storing, and processing user information and ended up turning into a massive class action lawsuit. I believe they also had a class action lawsuit in Europe, but this was a domestic US one.

And at the time, the company wasn't even thinking of right from wrong. It was more so how to collect as much data as possible. I feel like it was just a race to collect data 5, 6 years ago. Yeah. And so we got involved with a litigation case where we had to basically collect, I think the number was around 350 hard drives and image them and document, you know, serial numbers and just go through what data was being collected and stored.

And it was a fantastic project, but it was years. I mean, they just settled recently. Yeah. And you actually kind of— that's my sweet spot, right? Like that personal data and the fact that everybody collects as much as they can.

So can you describe some of the data that was collected that maybe users don't understand is being collected? Sure, absolutely. So one of the kind of pain points there, and we can really think about this in terms of any company doing this, is when you're sitting at Starbucks or anywhere where you're on a public Wi-Fi and you are handling your banking information or whatever you're doing on your computer, if somebody wants to capture that data, if it is unencrypted, they can. So you have to think about the other people around you and the other cars driving by and the person living across the street. Um, so the data that was concerned is obviously PII.

I don't think we went too much down the path of PCI and PHI, but of course that's relevant, right? So names, birth dates, email addresses, Social Security numbers, bank account information, you know, that's private. And so should you be doing all of that on a public network? Probably not. But if you choose to do that, does it mean that these companies can then collect and use that data?

Probably not. Right, right. Absolutely not. But back in the day, it was— there was— there's no laws around this. So it's like when this first started, everyone was like, let's get as much as we can.

We'll deal with it later. Yep. And, you know, the funny thing with Wi-Fi is, yeah, so one of the teenagers across, you know, across the street, when her dad shuts off the Wi-Fi for her, she just joins our— because we have a guest Wi-Fi, right? So her dad came over and like, you need to turn off your guest Wi-Fi because my, you know, so She's funny. Yeah, she's— but I think that's the thing, right?

Like, I think everybody thinks that Wi-Fi, you know, they don't realize the implications of using that public Wi-Fi. And so, you know, when they were collecting that data, like, what were they— do you know what the intent of the collection of the data was for? No, and that's the most difficult piece because that's hard in a litigation matter to prove, right? What were you doing with it? They were a massive company, like I said, so they're arguably the biggest data collector in the world.

But, and to their point, I think a lot of the litigation was, you know, we weren't doing anything with it. We were just hoping to collect data as much as possible to help us with our product. But it's very difficult to prove intent on a lot of these matters. Litigation forensics is difficult. Yeah, and then the harms, right?

Like, what was the harm to the individual? So I collected all this information, but I didn't really harm them, so therefore I didn't break any laws. Absolutely, but then, you know, you definitely don't want to move this towards supply chain vendor risk, but what about if they suffer a breach and all of that data is now out in the wild? So whether you have it or not, it becomes your responsibility to protect it, and if we don't know you have it, how can we do that? You're speaking my language, girl.

So let's move into the challenges for women in technology. Yeah. So, you know, you mentioned that, you know, for, you know, getting into the field about 10 years ago definitely looked different from when I got into it 20 years ago. So what was that like for you?

You know, all in all, when I look back, I think I was— and I hate to use the word lucky, but I really have been surrounded by fantastic fantastic team members that have been very supportive.

When I look back, I feel like it's a shame to think about all the females that are starting their career dealing with some of the stuff that I dealt with. I feel like it would deter them from tech. You know, and I have plenty of stories. I definitely don't want to take up all of your time here, but just the first one that really woke me up to what I was dealing with was one of my first jobs that I had, I remember having a conversation with some of the new hires. You know, we're all really excited.

It was all one of our either second or third job. And we started talking about salaries. We're out drinking. We started talking about how much money we made. One of my colleagues at the time ended up doubling the salary, moving to tech.

And, you know, it was my first introduction to being like, hmm, I made less than you, but we're doing the same job. And not only was I offered less money, but I was the only one that had a master's green saber. So, you know, that was the first time, and then I was like, okay, well, I'm not just gonna sit around and not say anything, which, like, how many people do that, right? Good for you for that though. I mean, standing up for ourselves, I think, is, is the first step for sure.

But it's, you know, it's a shame that, you know, I being from New York and just being assertive, those things don't sit well with me. I get very uncomfortable. But it's like, if you are introverted, which a lot of people people in the tech side are and you don't fight for your rights, you know, potentially that there are companies taking advantage of that. Um, absolutely. Yeah, there was no reason for that at all.

I mean, I had my master's degree and I was making— I think it was about $5,000 or $6,000 less, but there's no reason, right? Um, and like I said, I've been lucky to be surrounded by very supportive team members, and I believe they've really led me to where I am today. Um, I was attending a conference once. We were a group and I was one of 7 members and I was the only female. And we were introduced to a really important client as a team.

And I recall I was young and this is probably 2, 3 years into my career. And I remember one of the gentlemen asking my boss at the time, oh, is this your wife? And I just remember being embarrassed and I really wasn't sure how to reply. And luckily my manager was able to introduce me as a forensic caterer. You know, talk about all of what I've done and what I do, and then just steer the conversation to avoid any of the awkwardness.

Um, but that's happened to me a few times and I have really thick skin and I've learned how to deal with this to the point I really don't believe it impacts me and my career whatsoever. But the first 5 years are extremely formative and people dealing with that, it's like, no, I'm not a secretary. No, I don't work in marketing. No, I'm not someone's wife. Like those suggestions hurt people.

It makes you think, like, am I in the right career? Yeah, well, I think you are in the right career. If anybody— I mean, I'm sure you've heard that over and over because you've been surrounded, but I think what we need to take away is make sure that the people on the other side don't make those assumptions, right? And it kind of feeds into the bias that people have of what, you know, the people that do this job look like, right? You know, hoodies and men and You know, so I love that you're breaking that stereotype.

Absolutely. Yeah, my manager at the time would just tell me like, just go out and kick ass, that's all you can do. And I remember being sent to like SANS Fire and working so hard to get a SANS coin. And I got my first one and I came back and I had one and nobody else in my group of 7 had any. And then I got 2 and then I got 3 and writing blogs and doing interviews and just doing everything I can to make a name for myself.

And it's like, luckily I have some some of that personality to just not get upset by those things. But it's, you know, it's more so motivation to me, but I feel like that's a hard personality trait to just assume on people, especially in the tech world.

Yeah, no. And I think that, you know, what you've described is you have to fight a little bit harder, right? Like put that more effort in and kind of prove your worth where some people can just sort of arrive and don't have to do that, that extra effort. Absolutely. Yeah.

And so, you know, I always like to talk to our guests about giving back to the community, and you've been doing this for many years now. And I think that kind of says a lot about you and what you just described as, you know, you're a leader and in the forefront of, you know, advocating for women. Um, and so you're part of, uh, an association or a nonprofit called Her Justice. Do you want to talk a little bit about that? Sure, absolutely.

So basically, they're a New York City organization. I worked with them for quite a few years when I was living there. I'm still kind of, you know, loosely in touch with them, but they're basically an organization that stands up for women living in poverty by mentoring volunteer lawyers to give them free legal help. So a lot of them are dealing with child custody, immigration, you know, all sorts of just horrible things. And so a lot of the lawyers that, you know, Breach Council that we work as part of incident responders volunteer their time.

And so I got started, started to kind of move into that direction of just volunteering, whether it's money or time or just going to their meetings. They're a beautiful organization. A lot of the lawyers that we work with ended up volunteering their profession to represent these women. They've made such beautiful impacts, and at every one of their events, they kind of have a woman to tell their story and how they have gotten their child or they've fought to become a citizen. And there's just millions.

It's so beautiful. I can't tell you how many events that I've attended where it just ends in tears. Um, yeah, they're a great one. Um, there's been a lot in New York. I'm still finding kind of the ones in, in Colorado where I can get my groove in and volunteer not only time and money but services in terms of like cyber.

How easy would it be to just go in somewhere and turn on MFA for them? Yeah, it is those simple things. Yeah, and I do like that too because I think, you know, that's, you know, it's Her Justice is women giving back to women. And you described how impactful that is and how needed that is. Any thought of maybe starting something like that here in Colorado?

Maybe we could get a coalition of women to do that here. Yeah, that would be fantastic. There's actually— I really have a lot of colleagues that have come from New York now living in Colorado. And a handful of women. So I feel like we really do have a good group that, you know, New York City just has so much to offer and Denver is really building itself up and making a name for itself, even in the cyber and tech world.

We have a lot of that now. Um, but I think absolutely that's an excellent idea. Yeah. Well, let's pursue that offline for sure. Yeah.

Any other ways that you give back in volunteer activities that you want to talk about? Um, I do a few different volunteering just for like— there's a coalition for the homeless, you know, you know, just along with the beautiful weather out here comes a lot of people who just are trying to make their way in life and find themselves on the streets. So I've done a few of that, a few of those, and then I've done some children's volunteering. So children who are in domestic violence situations or have parents who are drug addicts, just even spending an afternoon with them. Yeah.

And then I've been involved— I don't think I have this posted anywhere— but in Big Brother Big Sister for a long time. And that's another, um, I don't know where they're based, but I've done a lot of stuff with them in New York. And the waitlist to get a child is— was like 2 and a half years when I was living there. Yep. But just donating money and time with them too.

They're a fantastic organization. Yeah, no, I think, you know, there, there are a lot, and, and I'm always uplifted when I talk to people who are giving their time back to the community. Um, so as we kind of wrap up here today, you know, you talked a lot about, you know, the, you know, women in tech and giving back, but what do you do for self-care? You talked about like being outdoors and hiking and biking and especially in incident response and the time management and turning off the cell phones when you're off not working. Are there any other recommendations that can really help people to make sure they take care of themselves?

Yeah, I mean, the biggest one is your time off is your time off. You really don't want to go over the next 60 years and be like, wow, I never took a proper vacation. And it's a shame in tech that being— it's great that we're available 24/7, right? We're always there for our clients. Clients and we're able to help them whenever they need, but you need to offload.

It's okay to ask your team members for help. I like to take long walks by myself and just listen to podcasts not related to cyber. I listen to a lot of cyber podcasts while I'm working or in the background, but just do things that you enjoy. Life is short. I spend a lot of time walking, running, taking my dogs out, hiking.

When I can, uh, you know, when we're on call, I still have my phone on, but when I'm on vacation, I love being by the ocean. I like just not being on technology, being on my computer. And then after work, you know, if you want to play video games or be on my phone or watch a movie, it's screen, screen, screen, screen. Just take a break, even if it's 15 minutes a day. Um, and so I try to tell my team that, like, schedule 15 minutes midday, take a proper lunch break.

Go out to eat one day. Like, it's okay, you know, we'll survive. Yep, I love that, and I completely agree. I think it is, you know, you know, kind of like the natural world as opposed to the digital world and spending time in the natural world. Exactly.

And it's like, how much can we do digitally? It's work, life, in bed on your phone, social media. It's 24/7 if you let it. Um, and so I try to limit you know, my time and put time, app timers, like I am a child on my phone because I don't realize how much time I'm spending, you know, after work. Yep.

But it works. And I noticed that my mental health, you know, like you said, Doug, who is fantastic, is really big on the mental health in the cyber world. And it's so important because when you burn out, not only are you hurting yourself, but you're then hurting your team. And there's just, it can be prevented. Yep, absolutely.

Well, we've talked a lot about many things. Is there one last thing before we wrap up?

I would suggest if you are a female listening to this and you want to get in the tech world, do it. There's absolutely nothing stopping you. There may be a comment here or there, but I promise you will get over it. Feel free to reach out to me. I love talking about people during transition and in school.

Um, yeah, it's a fantastic industry to be in. It definitely has its bumps, But I'm very happy that I am where I am today. And I encourage, you know, anybody can do this. Just, you got to get through. Yep.

Just start, right? Get on the bandwagon. Yeah. Well, I love those words of encouragement. So thank you so much for that, Leeann.

It's been really a pleasure talking to you and I want to thank you so much for your time. Absolutely. So this is the end of our interview until next time. Thanks everyone for listening. Bye-bye.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security. Security.

Back to all episodes