All episodes

Rich Schliep (CTO) and Craig Buesing (CISO) at Secretary of State's Office

Apple Podcasts Spotify SoundCloud

Rich Schliep (CTO) and Craig Buesing (CISO) at Secretary of State's Office are our feature guests this week and are interviewed by Jason Jaques. News from The Gondola Shop, Otter, Red Canary, Ping Identity, LogRhythm, Optiv and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12766 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 199 for the week of— what is it? That's, uh, February 22nd, I think.

That's true. Alex, we are so close to episode 200. It is amazingly close. We've got— we're on the brink. Plans.

We got big plans for episode 200. Yeah, you know, we've been planning this for a long time. It's been literally minutes that we've been working on that plan. You know, we came up with a plan, so good stuff. This is— we're way more ahead on this than we are on most things.

We have more than a week before that episode needs to air. That's true. Usually we're stumbling into things as they happen. So I think a week of planning is pretty good for us. But it's going to be exciting.

I think it's worth giving people a little preview to say we are going to— we're going to interview each other and we're going to take some questions from the community via the Slack channel. So if you have questions about the Colorado security scene, about what it's like to do a pod— the best security podcast in Colorado for the last 4 years— go out to the Slack channel and ask your questions and we'll make sure we get them in. Yeah, I mean, other things like, you know, how you can stand being with Robb for, you know, 200 episodes? That's a valid question. Should I bring my wife in to help with that answer?

Hopefully it's been more than 200 episodes for you guys. So yeah, but she's been around. Yeah, she's, she's had to be interrupted by a lot of these episodes. So that's true. That's true.

Um, you know, it is a burden on families and things like that too. So, uh, but yeah, so I think probably the, the podcast channel in our Slack workspace, um, I think we'll probably make some announcements in there. Uh, in Slack in general, but if you want to go start asking questions that we can answer for next week's episode, feel free to go do that. All right. That said, you know, that means we do have a Slack channel.

What is a Slack channel? It's a, it's a place where you can talk to 800 of the best Colorado security professionals there are. Um, and then, uh, 900 of the not best. Is that, uh, uh, so we've got a— what is it, 1,700 now or 1,800? I think we're over 1,800 now.

Yeah. Yeah, so we've got, um, a lot of people in there, a lot of great conversations. I mean, so many good conversations it's hard to keep up. Um, but yeah, lots of great people in there. If you want to be connected to the Colorado security community, go hang out with, with people there.

You can go to the website colorado-security.com and find the link to the Slack channel. And while you're on the website, once you go ahead and sign up for our mailing list, that'll keep you abreast of all of our show notes that come out, which basically, if you don't want to— if you want to have all the news from the show but none of the witty banter, just click the link and you don't have to listen to us. Yeah, also, um, we would love it if you went to your favorite, uh, podcast player or, uh, podcast store, whatever that might be— iTunes, uh, Spotify, one of the other ones— and subscribe to the podcast so that you get this delivered to your inbox every week. And we'd love to have a rating there as well. One of the Slack conversations on the Slack channel this week was from Douglas Brush, who is, uh, host of the, the second best Colorado, uh, security podcast.

Um, and he was mentioning that he got a negative review, which he was excited about because it was, it was his first negative review. So we don't want negative reviews, but, um, we don't, we don't have any negative reviews, do we? I think that he's ahead of us in that one. Yeah, you know, please don't run out and give us a negative review just because of that though. But if you want to help us, there's a couple things you could do to help us.

Number one, you could tell a friend, tell a coworker, tell a lover that we, that we exist and that we're worth listening to. And number 2, if you want to financially support the show, uh, we would love it. Uh, you know, we do pay for this out of our own pocket, and— but we have some fantastic patrons who are, who are helping with that. Um, those folks who give us a little bit of money each month to keep things moving, it's, it's very motivating and it helps defray the cost of this whole thing. Yeah, I do have to say it's been wonderful having the Patreon folks.

Um, we, we pay less and less out of our own pocket, uh, because of their support, so that, that is great. Um, and speaking of Patreon. Last week we mentioned we had a new patron, and we have gotten confirmation from him that we can talk about him on the air. So thank you, David Nectarline from Serious Computer Solutions, for signing up for— actually, this is an interesting thing too. He asked if we can do yearly memberships as opposed to monthly on Patreon, which we hadn't set up before, and I figured out how to do that.

So now if you want to do a yearly membership and only have to pay once a year as opposed to every month, you can do that. So thanks to David for the support, um, and everyone else, if you want to go sign up for a yearly membership, go ahead. All right, let's jump over into the news. A big thank you to David. David, thanks for your support, we appreciate it.

Jumping into the news, uh, Alex, I don't know if you're aware, but last week was really cold. Uh, it was, it was extremely cold, and it was the 5th coldest week in 3 decades. Um, so that should tell you how cold it actually was. Yeah, it was the coldest we've been in 7 years. Uh, so between, between, uh, February 10th and February 17th is the dates we're specifically talking about.

Um, the average temperature during that time was 6.5 degrees. Yeah, that, that's low. Um, I, I have to say it was not very fun. Uh, I tried not to go out. Um, although last Saturday, I think it was, we did go out.

We actually ate outdoors in a bubble. Um, it wasn't too bad. Was it? It wasn't the gondola though, huh? It was not a gondola.

Don't, don't give that away yet, Robb. But, but yeah, so, um, very cold the last week. Um, luckily it's going to be a little bit warmer here. Um, I think we, we were happy though that we got a little bit of snow along with that cold. We need the moisture.

Um, I also, uh, in this, this list they have the 5 coldest weeks in the past 30 years. Uh, the coldest was back, uh, December 18th to 25th in 1998. I remember that one. The average for that week was 3 degrees, um, and I was living in an old house at that time, and man, it was really cold. Well, now, now you have that nice warm house that is not probably quite so drafty.

That's right. Um, I did one more thing I was going to point out in this article. The, the coldest morning of that last week was on the 15th, and the temperature was -16 degrees. Oh man, uh, sounds like you want to just go outside and run around in your underwear. Well, all the time, but yes, fair point.

Even more. All right, uh, next story. Um, Robb gave it away already, but, uh, this is a story talking about how old ski gondolas are finding new life as private dining rooms for restaurants. Yeah, there's a company in Fruita, Colorado called The Gondola Shop that refurbishes and repairs gondolas. And I think actually their main business before the pandemic was going out to ski resorts and refreshing and cleaning up, polishing the gondolas that are being in use.

And the owner of that business had realized these companies, when they're done with their gondolas, they don't have anything to do with them. And she had started buying them 3 years ago, buying these gondolas and just keeping them on a property they have in Fruta, not really having a plan for exactly what they're going to do, but thinking there's got to be a use for these things. And all of a sudden comes the pandemic. And she gets a call from a village up near Telluride. I can't— was it the Village at Mountain Town, something like that?

Sounds right. Who'd asked, like, can you, can you create some outdoor seating from your gondolas? And she's like, that's a great idea. They did it. There was some social media recognition about this really cool idea that, you know, even in the really cold weather, you can put a heater in these things.

People can have 4 to 6 folks eating a meal, and, and it looks really cool, and it looks really cool on social media. And the whole thing just blew up, and her business has been going crazy. Crazy. So I think my favorite part of this article was her talking about the fact that she really had no clue of what she was going to do with these gondolas when she bought them. Just thought, hey, we can get these and repurpose them for something maybe someday, and bought, I think, 60 from a resort in Vermont.

It was actually like 100 from a resort in Steamboat, and just had these sitting around until fate intervened and Uh, the pandemic really highlighted a use for them. Yeah, it's really cool that the article also shows that you could buy them a couple different ways. You could spend just under $5,000, $4,800 to get one as is, which means, you know, right off of the, right off of the, the lift. Um, and they— and her quote says, I don't recommend this, it smells like 30 years of use when you open the door. Yeah, that was funny to me.

But I guess the more common way to sell it is they, they'll disassemble, clean, sandblast, fix, repaint, upholster, uh, and spiff up the gondola to specification of the restaurant. And that process basically takes 5 to 6 weeks and costs $15,000 to $20,000 per gondola. Um, which it seems like— I was thinking, man, in the middle of pandemic, I don't know if these restaurants have $15,000 to $20,000 to spend. But they also say she will rent the gondolas for about $500 a month, um, which kind of seems like a no-brainer considering, you know, hopefully this pandemic's not going to go forever. Yeah, I mean, but I think, you know, if you're thinking a little more long-term too, $10,000 to $20,000.

I mean, maybe you don't have that cash right now, but in the long run, it's maybe not that awful if you're going to get a couple of them and keep them on your property as a novelty seating forever. So that's pretty cool. Yeah. All right. So next article we've got is from the Denver Business Journal, where Denver has proposed a plan.

Basically, the article says, Denver eyes turning off natural gas and requiring all-electric new buildings. In order to help address climate change. Yeah. And I think that the headline is a little bit misleading. However, it is mostly true.

Denver is working on some building code changes that will require new construction to be net-zero energy. And as part of that, they will require, assuming this all goes through, electric heating and water heating as part of that. I don't think that they're saying you can't have natural gas to the building, but they're saying for the building itself, most of the main systems like heating and water have to be electric. Theoretically, you can still run gas to the building, and if someone wants a gas stove or something like that, you can still do it. But yeah, it's very interesting considering the history that Denver and Colorado has with the oil and gas industry and being a center for natural gas for a long time.

Yeah. I will clarify that this is just a plan at this point. It's a plan that's going to go before some hearings this summer, and then the city council will later in the year address the plan and consider whether we want to adopt it. Yeah. I would guess that there will be some heavy lobbying from the oil and gas industry to maybe soften this a little bit, but I think, you know, in general, it's good to see, you know, new, more energy-efficient building codes being put forward.

Good stuff. All right. Next, we have an announcement from OtterBox along with Katana Safety. They've announced a product collaboration. So the OtterBox Universe modular case for phones now works with a module from Katana Safety so that you can have essentially a personal safety device built into your phone case.

Yeah, you know, I, I did not know anything about Katana Safety before this, or if I did, I'd forgotten it. Um, it looks like kind of— I'm not clear exactly what it does, but it looks like it's, it's a way for folks to easily, um, notify people if they're in trouble in some way, either medical trouble or maybe they're, you know, they're in some kind of risk of danger, violence. Um, there's, there's buttons that allows for an instant bypass of the lock screen on your phone, connects to a 24/7 response center, um, to help with any situation at hand. I'm wondering if it's kind of like like a Life Alert type of a situation. Yeah, it sounds like there's, um, you know, like a silent alarm, uh, possibility built into it too.

And they mention, you know, people in certain, uh, job types that, you know, might need this. One I think that they said, you know, like an airline attendant or something, if you need, you know, need to be able to do something, um, alert people really quickly and not have to sit there and, you know, open your phone and call somebody or, you know, do things like that. So pretty cool. So they basically are building in their smart wallet technology into the Otter case. And as I look at at the Katana website.

Like, there's a, there's a strap that can go around your wrist, so if someone tries to take your phone from you, it'll pull that out and it'll set off the alarm. Um, they're really interesting, I, I guess, high, high security situation that, you know, most of us probably aren't dealing with, but for those who need it, it's interesting. And it's cool to know that Otter is, uh, partnering with these guys. Yeah, I think the other cool part is that I don't know I realized, um, that OtterBox has a sort of a modular case, right? That this Katana piece I think you can swap in and out as part of the case.

So, um, you know, maybe you could have the katana module and put that in when you, you know, need to have it with you, um, you know, if you're, if you're on the job and you need that, that safety piece, and, you know, maybe put something else in when you don't. So that's pretty cool too. All right, jump over to our next story, uh, and this is a, this is a story from Business Journal as well. Um, could Denver be the next great destination for esport events? Apparently, the Denver local tourist leaders think that that's definitely the case.

Yeah. Esports is a giant industry already, and I think there are lots of places where they're trying to get in on some of that cold, hard cash that's being generated by people playing video games for money. This is the local Visit Denver Tourism Board thinking about, okay, how is it that we can attract some of these events to Denver? And maybe on a recurring basis. So thinking about one of the examples they said, it's in April, you go to Augusta for golf, and we wanted people to think in July or whatever that you come to Denver for esports.

Yeah. That's exactly the part of this that caught my eye too. I imagine it's got to be that the pandemic has just been a huge accelerator for esports as a way to get entertainment, excuse me, and of course, for profit as well, like you mentioned. It's interesting to see Denver do that. It always seems a little strange to me that the combination of esports and getting together in person, like, well, it's all virtual, can we do it all virtually?

But I'm sure people love to be around the community of folks that they're with in person. And, you know, it's hard to drink with someone when you're across the globe from them. So this is going to be a chance. Hopefully Denver can land one of these big ones and you and I can go to it and be like, yeah, this is pretty cool. Yeah.

I mean, and I think, you know, there is some spectator capacity as part of this too, right? I think we've seen through the pandemic where you're having basketball and football and other games, soccer games being played without any fans. It's just not the same experience without a whole bunch of people cheering during whatever's going on. Even though I do also understand where it's like, well, why don't we just play these games remotely? I do understand that there is a different level when you're in an arena with hundreds or thousands of people cheering why you're doing this stuff.

Yeah, well, good stuff. Let's pivot over to our security news for the week. Uh, first is an article from one of our favorite companies in town, Red Canary. Um, they have, uh, raised a C round and, and really good valuation for this company. Yeah, so they raised another $80 million or $81 million in their Series C. Um, looks like it's led by many of the same, uh, partners that they have used before.

Summit Partners and a couple others. And this takes them to a little over $125 million that they have raised so far, and they're going to use this to just continue to, to build out the service and, uh, you know, grow the demand for, for their MDR services. Yeah, they— the, the headline says that they're going to triple down on security operations, which is great because it's better than doubling down. Although I do have to wonder why they're not quadrupling down, because it, it feels like, you know, it's probably time for that. Yeah, you know, they might have had to raise more than $81 billion if they were gonna quadruple down.

That's probably the only difference. That's probably what happened there. Yeah. Yeah. So, um, congratulations to Red Canary.

I'm sure this is gonna bring in some, uh, you know, great new people and, uh, products and keep them moving forward. Yeah, good stuff for those guys. Congratulations, guys. All right, next we have a, a blog from Ping, uh, talking about their Project COVID Freedom Um, which is going to make vaccination verification easy. So I need to, need to do one quick correction for you there.

This is actually a press release. Uh, this is a new product that got released, yeah, this, this last week, and it's the announcement of that, that new product. Um, as you mentioned, it's called COVID, uh, COVID Freedom, or Project COVID Freedom. And basically the idea is, uh, you know, combining the the ability to do personal identity on your device, where you have your phone that controls claims you want to make about yourself with the vaccination. So when you get vaccinated, the person who gives you the vaccine will give you a claim on your phone that you can show to other people, whether it's an airline, an employer, a— I don't know, whoever else wants to know you're vaccinated, and you can choose who sees it, but they can do so in a way that gives a high level of credibility.

Yeah, and that's pretty cool. Um, you know, I think seeing people now that have gone through the process of getting a shot, you know, or both shots, you know, when you're done, you know, they hand you essentially a piece of paper that says, you know, you've done this. Um, and you probably don't want to, A, carry that around with you so you can, you know, hand a piece of paper to somebody saying that you've gotten vaccinated. Um, and of course it probably has more information on that vaccination record than you necessarily want to share. So I think having this electronically, uh, in a secure way with, uh, with minimal personal data sharing is pretty cool too.

Yeah, good stuff. Uh, moving over to our next story, there is a, a blog post from Husch Blackwell on the Bite Back Law, um, blog. David Strauss— Stouse, excuse me— are one of our friends. Um, it's, it's a blog post talking about a new tool they created, and I'm actually looking at the tool right now. It's their, their 2021 State Privacy Law Tracker.

And basically they got a map of the US and they show you where all of the new privacy laws are and gives you a really easy way to click on the state you're interested in and learn more about what those laws look like. Yeah, it, you know, not anything super fancy, but a pretty cool tool so that you can keep track of this stuff. State privacy laws are constantly changing. You know, some states right now have multiple laws that are going through the process to, you know, see which one is going to come out on top. So you can, you know, track that kind of stuff, see, uh, you know, get directly to the, the, uh, the language of a particular bill that's going through, and lots of other stuff like that.

So pretty neat. Yeah, you know, it just occurred to me, it's been so long since we've had David on here, we probably should, uh, we should probably try and get him back on again. It's probably a good idea. Um, you know, we'll have to see if he's actually a listener of the podcast still and if he reaches out. Otherwise, we can talk to him because we need to play hard to get, apparently.

Good. That's right. I like that. All right, good stuff. Next, moving on to a LogRhythm blog post talking about threat detection in the public cloud and cloud security solutions related to that.

So this blog is really talking about some of the threats and challenges that go along with the public cloud, you know, whether it's making sure that you have proper identity access management, compliance, you know, misconfigurations, what we see a lot with cloud configurations in public cloud. And talking about how some of the ways that LogRhythm can help in that monitoring of public cloud. Yeah, you know, this is, you know, no surprise from a security company. They're looking to talk about how they help you solve this problem, but this, I think, is the first I've seen from LogRhythm that's really touting their new acquisition. This gets into their Misty XDR acquisition and showing how that's going to further help LogRhythm solve these types of problems.

Yeah, and I mean, I think it's talking also about, um, you know, some of the, the newer and more novel ways that you can monitor these things in the public cloud. I think, you know, both AWS and Azure both have sort of, you know, a virtual tap feature now where you can tap different areas of the network and run it through other tools. Um, and, you know, that's great, but, uh, really having a tool that can capture that data and look for analytics and things that are going on in those areas is important. And so good to know LogRhythm has that with their, their MistNet purchase. All right, moving on.

Uh, you know, there's a lot of national news or even global news that we totally ignore on this show because we are a Colorado security podcast. But occasionally, you know, there's a bigger story that we want to talk about, and it's nice when one of our local security companies talks about it so we can, we can use that as an excuse. And that's exactly what's happening here. Optiv has a blog this week around, um, around the attempted, uh, malicious— well, how do you say it— like, uh, change, you know, that an attacker who got into the, the Florida water system and tried to put too much lye in the water and poison all those, all those folks. Uh, here's an article just talking about the reality of that and what folks can do to prevent it.

Yeah, and, um, I think, I think we're still not sure exactly what the intent was, um, know, obviously they got in and changed some settings. We don't know if they were actually trying to poison someone, or if they were— or people— or if they were just seeing if they could change these settings or anything like that. Um, but yes, um, the attack was caught by a, you know, a human, uh, monitor, someone that was sitting there trying to monitor the water quality for their job. And so glad that that happened. But, you know, it does bring up, uh, concerns that have been around for a long time around control systems and control system security.

I think as long as there have been control systems, the security has been lacking and bad. Um, and, you know, again, this sort of highlights it. In the article, they talk about, uh, you know, this is, this is maybe a wake-up call for people in the critical, critical infrastructure space. I don't know if I believe it's going to be a wake-up call, um, but it is yet again highlighting some of the problems that are in that industry. Yeah, you and I have both worked in that space, and it is, uh, it's hard to get folks to take it too seriously.

I'd say that. Yeah, for sure. Um, you know, they do offer some, uh, some suggestions here on things you can do around training and visibility, um, also segmentation, which are all great things. Um, in this particular case, uh, maybe the training but not necessarily the, the other ones would have, uh, would have helped. You know, it was an unsecured remote access connection that allowed the attacker to get in, and you know, if you're going to do that then you're probably going to get owned 6 ways to Sunday, you know, every week.

So, all right, moving on. That is the end for news. Our next element, though, is the Slack message of the week. And as everyone who listens knows, we have a big thank you to Andre Gaeta, who has been sponsoring this for us. Andre each week allows us to acknowledge one person from the community who, who says something in the Slack community that we, that we want to call out.

And basically, that person gets to pick one free item from the Colorado Equal Security Store. Yeah, um, thanks again to Andre, and I think we've got a great winner this week. Uh, Michael Stephen is our winner, and, uh, he won because he put a comment in around the, the Perseverance rover that just landed on Mars and noting the fact that his name is actually etched on that rover. So apparently when this was being built, uh, you could submit to have your name put on the rover Um, I think is sort of part of a fundraising effort. Um, and he did, and his name is on that rover that is now on Mars.

Yeah, and he put it— he posted a picture of his— I don't know what you call that, like certificate of being on the rover. Uh, and, uh, and, and I think with the rest of us, we're pretty jealous that we didn't know that that was an option that one could have done. Yeah, uh, I think that is pretty cool. When, when aliens someday find that rover on Mars, they'll go, who's this Michael Stephen guy? I guess that's a good point.

Now you and I are safe from the alien retribution for that whole thing. That's right, uh, we are still anonymous to those aliens. So, all right, well, so Michael, you'll get to pick one item from the store, and, uh, look forward to seeing your new Colorado Equal Security swag. Awesome, congrats, Michael. All right, uh, with that, let's move over to events.

Uh, we've got some great events coming up on the calendar. The first one is a fun event, and this is on the 23rd It's the Colorado Equals Security Poker Night. Jason Jaques has been organizing this for us, and if you're interested in getting involved, there is a poker channel on the Slack workspace. Um, I think that they, uh, this event is full currently, but I believe that they are taking spots for the waiting list, uh, to get people added if, uh, if someone doesn't show. Yeah, I'd say, you know, if you want to get involved, even though this particular one's full, there's going to be another one next month.

This is your time to, to get on the list and make sure you, you get on there next time. Yep. Uh, next on the 24th, ISC2 Pikes Peak is doing their February meeting. On the 25th, ACES is doing their young professional happy hour with Colin Doherty. Uh, I think we skipped one on the 24th, right?

ISSA Denver on the 24th is doing, um, the CCPA to CPRA, California's privacy law update. Uh, we've been doing this 199 episodes, Robb, and I still can't get it right. And that might be the first time that particular thing's happened. That's pretty good. Possible.

Um, and then the final event, ISSA Colorado Springs is starting their Security+ review on the 6th of March. This is a great thing that ISSA Colorado Springs has been doing for a long time. It's an extremely inexpensive way to have a prep class for the Security+, and they also do a similar class at a different time for CISSP. So if you're interested in getting Security+, you should check that out. Yeah, I've sent a number of my employees to do this over the years, back when they had to drive down to the Springs.

It was so valuable, it was worth the drive. If you can do this thing virtually online, man, it's well worth your time. If you're looking to get into security, get that educational background, definitely recommend you do it. It is a multi-week, I think it's 3 or 4 week long exercise. We're only showing the first one on here because we don't need to show the same, you know, week 2, week 3, week 4, but get signed up before it's too late.

Like we said, it's going to be on the 6th of March. Good times. All right, uh, let's move over to jobs. Robb, any Ping Identity jobs this week? Absolutely.

I got a couple of jobs that are, that are worth calling out. Number one, I am hiring a security program manager that's kind of a right-hand person for me, helping run and communicate the program internally and externally. I'm also looking to hire product security engineers. I have a couple of positions for those. If you have an application security background and you're interested in— excuse me, an application development background and you're interested in security, this is the right fit for you.

You can reach out to me on Slack and I'll make sure to answer any questions you have. Awesome. Moogsoft is looking for a security AppSec engineer. Uh, DB Shankar is hiring an IT governance specialist in security. Direct Defense is looking for a security analyst night shift.

So if you're someone looking to get into security, that might be a good thing. Or if you just have a hard time sleeping and you want to turn that into cold hard dollars, this is an opportunity for you. Probably better than driving an Uber. There you go. Insurity is hiring an application security analyst.

Insurity, Joshua Foltz is our friend over there who's the CISO, and a good opportunity to get onto his team. SquareTrade is looking for a security engineer. The Hersheybeck Group is hiring an incident response specialist. Uh, Coalfire is looking for a senior consultant for application security penetration testing. You know, I put these jobs together this week and I didn't even notice the trend that we've got an awful lot of AppSec.

Yeah, good job. Um, Greenberg— is it Traurig? Traurig? I think— I feel like they don't— good enough. Yeah, well, Greenberg is hiring a data privacy and cybersecurity temporary summer student law clerk.

So this is a really cool opportunity for someone in law school who wants to get security experience. Um, yeah, honestly, Greenberg is well respected, and I think it'd be a great opportunity for anyone who wants to get into that field. Yeah, that's pretty cool. I'm glad to see we're having more of these. You know, we had the one a couple weeks ago with the Attorney General's office doing a similar type internship.

Yeah, well, good stuff. That is it for the news. We do have a feature interview this week. Once again, thanks to Jason Jaques for doing an interview for us. He sat down with a couple of our friends.

Um, we've, we've got Rich Schliep, who is the CTO and former CISO for the Secretary of State's office. You know, who's responsible for election security here in Colorado. And also at the same— in the same interview, we've got Craig Buesing, who is the current CISO. So the 2 of them talking about how we— the technology and security around our election system. Nice, I'm looking forward to that.

It should be good. All right, well, Alex, have a good one. We'll get back together again next week with tough questions from our audience on episode 200. Sounds good. Thanks, Robb.

All right, see ya. Hello, this is Jeremy Cooper-Leavitt, managing director Director of Assurance at Charles Schwab. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals. Hello, Colorado Equals Security. This is Jason Jaques.

I had the rare opportunity to interview 2 key people here in the state, Rich Sleipe and Craig Bezing of the Secretary of State's office. Here's the interview. Enjoy. Rich, Craig. Welcome to, uh, the podcast, or I should say welcome back for you, Rich.

Glad to be here. Thanks for inviting us back. Yeah, thank you for having us, Chase. So Rich, you were episode 68. Uh, that's, that's been quite a while ago, a couple of years, right?

Yeah, it's been a little bit. I remember going down and meeting when we could actually see people in person and meeting Robin doing the podcast. It was a fun— it was fun. Good opportunity. Yeah, yeah.

Let's start with you. What's changed for you since then? Quite a bit. Just recently moved houses. Nice.

That's been exciting. I've moved from being the Chief Information Security Officer to being the CTO. Right. And we have a new and improved CISO, Craig. So that's exciting.

Yeah, yeah, very cool. So the community definitely knows you because you've been on the podcast, you're, you're on the Colorado Equal Security Slack channel. I think most of the community also knows you as well, Craig. You have— this is your first time the podcast, which is cool. Yeah, it is.

For the— I suppose for the 2 or 3 people that don't know you, tell us about yourself. Who are you? Well, as Rich said, I'm the new and improved CISO for the Colorado Department of State. Right. I was an engineer for about 6 years before Rich moved up to CTO position, and then I filled the CISO role.

I've been doing that for almost 2 years now. Excellent. This episode's going to be a lot of fun because there's a ton of community crowdsourced questions, and I'm excited to be able to ask you those. But before we do that, let's talk hobbies. What are your hobbies?

Uh, personally, I like anything with skiing. Like, I like snow skiing, water skiing. We've done a lot of that past couple years. Okay. And recently picked up mountain biking as well, doing a lot of mountain biking with my son, so that's been a lot of fun.

Yeah, I love the water though. Yeah, yeah, yeah. So when you go skiing, where do you go? So we— I'm from Grand Lake, so we— I grew up in Grand County. And as far as snow skiing, I spent a lot of time at Granby Ranch.

Okay. Which is a pretty small little resort, but it's great because there's no lift lines and it's fantastic for teaching your kids how to ski. Yeah, I started my kids out never really skiing, and by the end of the season I'm going down the hardest stuff there, which isn't super hard, but it's, you know, they got some black diamonds. It's been a lot of fun. I love being on the slopes and then of course Winter Park.

Okay. So what about water skiing? Where do you go for that? We used to drive up to Glendale and Guernsey, but I just actually moved up to, um, Longmont area and we have a house that is actually on water. So we're going to be able to go out right out our back door and go water skiing whenever we want, which is perfect when you're in COVID times, because yeah, you can step out and go.

That's awesome. I want an invite for that for sure. Definitely. So Craig, how about yourself? What are your hobbies?

I'm not quite the daredevil that Rich is. I, I don't get into the mountain biking, but I do enjoy skiing, hiking. I also get into various construction projects. I recently built a Murphy bed for new home office. So Murphy bed with a desk attached to it, save some space working from home.

A couple years ago, I built a full-motion flight simulator, and I've drawn up some plans for a steam engine for a go-kart, but haven't quite gotten the guts to build that one yet. Wow. The, uh, a little bitter because I've never been invited over to get in the flight simulator, but you know, whatever. That's fair. But to rewind a little bit, the Murphy bed situation, that tells me, uh, you probably work too much if that's in your office.

Is that a fair statement? Yeah, and more just wanted to make a new space for our daughter to move her into another bedroom. So the guest room and office kind of got merged. Okay, needed a way to still have a home office and have a guest room. I gotta add to this though, this thing's awesome.

He did a video of it. Yeah, it's like it— when it folds up, his computer desk folds down and his computer and everything is already set up and on it. Wow. Yeah, so it's a Murphy bed slash computer desk built into one that converts. Yeah, you should post some pictures of that.

That sounds pretty sweet. Thanks. How did you guys get into the tech and security industry? Let's start with you, Rich. You know, I've always loved computers.

Um, as a kid, Atari 800, I remember writing my first program, of course, to try and play a video game, you know, copying out of a book and trying to do that downhill skier game. Moving on from that, I grew up building log homes, so I got really into AutoCAD and 3D Studio and trying to design the homes and put them into different places, which back then was really difficult, more difficult than it is now. And then after, after that period of time going to college, I actually got a degree in construction, got out and thought, well, I'm going to be outside working. And I wasn't. I was at a desk and I ended up doing the computer work all the time.

So I ended up setting the VPNs up for remote job sites and kind of just moved into the computer industry and never looked back. Very cool. How about, how about yourself, Craig? Well, I, uh, started out in the military as an aircraft mechanic and then retrained over to be a paralegal. And when I was working in the office job as a paralegal, I learned that I had a decent aptitude for computers.

And I was teaching a lot of the attorneys and other paralegals how to do things. Um, when I got out of the military and the civilian job, I started to shadow the IT guy for the firm. The contractor that they had, and he taught me how to be the system admin, and I basically took over all those roles of being the sysadmin and network admin for the firm. And that got my foot in the door and got me excited about the computer arena. And I learned that there are so many things that you can do in computers, and that's what really hooked me in.

In law and maintenance and all that stuff, you're kind of locked into a job. With computers, sky's the limit. Yeah. So you had— I gotta point out, in that time, since that period, he's also got his master's in cybersecurity and all his certifications. So he doesn't slack off.

He's always busy reading and learning. Yeah. I was gonna say you had the option of becoming a lawyer or getting into tech. So you chose wisely. Yes, don't have $100,000 in, you know, law school debt.

And yep, very cool. So your, um, your current role then, Rich, you're the CTO at the Colorado Secretary of State's office. Uh, tell me about like what surprised you the most in your role and, uh, maybe what's your biggest challenge? Well, of course everyone thinks CTO, technology, you know, and I love technology, but it's The, the biggest key to technology is the people and realizing that people are the most important asset you really have. Caring about those people and building a culture of trust has been the most important thing for me.

And we've— I've got some great people I work with and continuing to get those teams working together on a regular basis, whether it be cybersecurity, you know, your Linux guys, your Windows people, your business managers, building that culture of trust so that you have people that are caring about that technology. When they put a system live, they aren't like, oh man, we got to meet the security requirements. They want to do it because they know we're part of a team. And so really it's a culture of trust and really focusing on people and processes rather than the technology behind it. That makes sense.

And then, uh, Craig, as the CISO for the Colorado Secretary of State's office, what's— I guess same question to you— what's, you know, your biggest challenge and what surprised you the most about this role? Well, I'll start out with the surprises of— there really wasn't too much of a surprise. As I said, I was an engineer for 6 years, so I knew mostly what to expect moving into the job. Right. But what surprised me is how much I miss doing the engineer stuff.

I mean, I enjoy the role of the CISO. I enjoy more of the broad scope planning, but I do miss that hands-on keyboard digging into a system and actually doing the work rather than planning it out for others to do.

Challenges as I moved up into this role, we had another one of our engineers that got promoted as well and moved into another role. So we kind of started fresh with a whole new security staff, and then COVID hit. So that's been a huge challenge of trying to train a new staff while doing it remotely and just getting everybody up to speed. Yeah, yeah, that's a— and that's a perfect segue because I wanted to ask you guys about COVID and the quarantine and the pandemic in general. So how has that changed you know, you guys personally first, but then secondarily, like the office, the workforce.

Tell me a little about that. Well, some of the biggest challenges for me is, you know, I got kids in school, so, you know, dealing with that at home and trying to keep them on track. Uh, they do really well. Thankfully, I have slightly older kids. You know, they're, they're all teenagers at this point, so it hasn't been as difficult as some people and their challenges of having to teach their kids as much.

They come more for help rather than having to have that minute-by-minute attention. The, uh, it's been a challenge. You know, we had a— I think everyone had a pretty challenging year. I mean, on top of the pandemic, um, unfortunately my parents' house burnt down in Grand County. Oh no.

So the fires impacted us, and of course, as everyone has been impacted, not seeing people really gets frustrating. Are they okay? Was it just the— Yeah, they're all doing good. Um, you know, I will say it's challenging, you know, when you have parents that are in their 60s and 70s and they lose their house that they've been in for 30, 40, 50 years. There's definitely some challenges we have ahead, but they're pretty amazing people.

Um, they've turned around and they're— my stepdad's already got logs ordered and is getting ready to build his house. Okay. And he's in his 70s, so he's a pretty tough dude. And my real dad, for lack of a better term, biological dad, he is well on his way to getting a house built. So they're doing well.

Are they building on the same land? Are they going to build the same structure again? Yeah. I was actually surprised. I think after you've been in an area like Grand Lake, you were up in the mountains, you kind of become pretty attached.

Yeah, I figured they might move down here, but there's no way. They're, they're going right back to where they were, and they're excited about it. Well, that's good to hear for sure. Um, Craig, what are your thoughts on, you know, how has, how has this affected you personally and, and, um, and I suppose the office and your job? Personally, I've actually been very fortunate.

I love not having to commute into work every day. I've got a 4-year-old daughter, so I get to spend a lot more time with her, not having to drive in and out. I get to see her every morning. I get a coffee with my wife in the morning. It is a little bit more of a challenge when you have a, you know, at the time, 3-year-old that walks in in the middle of your meeting and wants to interact with everybody on the screen.

You know, trying to tell her no, and she just can't understand why she can't talk to the people on the screen. Right, right. So yeah, it hasn't been that much of a challenge other than things being closed down and can't really take her to the museums or the parks as much. But for the most part, she's been a trooper and it's just life as usual. Do you, do you guys think, uh, the— your office will ever go back to normal, or do you think like being remote is kind of the new normal?

I think remote is going to be the new normal. Um, we will definitely go back into the office To a certain extent. We do have a front counter for customers to come in, so we will definitely need to staff that. There's other business functions that will function better being back in the office, but my prediction is that we'll be at more of like 3 days on, 2 days off, or 2 days on, 3 days off type thing, and just have a rotating schedule of when people are in the office. And overall, I think it's— this is, you know, if you're going to look at the silver lining in all this, we were headed towards having more of a the ability to work from anywhere before we left.

And thankfully, we were already well on our way to doing that, getting people laptops, moving to platforms like Atlassian Jira Service Desk, using different tools that were online-based to track our work and our DevOps processes. So really, our teams have learned to work from anywhere, and overall, it's going to really benefit the office. So there will definitely be some people in the office, but it won't be the same ever again. And in a lot of ways, I'm pretty thankful that we were able to push forward in that direction. I think we're going to end up being more productive and more successful.

And I personally don't like having a, you know, hour and a half in the car every day. Right. And more attractive to new employees too. We've struggled with that of trying to bring in newer developers and things like that, and they want to work you know, their own schedule. They don't want that Monday through Friday, 9 to 5.

Yeah. So now that we've finally gotten that culture accepted in the office, it'll make us a little bit more appealing for bringing in new talent. Yeah, that makes a lot of sense. The— I'm definitely never going to miss the long commutes. Although surprisingly, I— or maybe unsurprisingly, I listen to a lot less podcasts than I used to because that was— my commutes are always my podcast time.

Oh, that's funny. Yeah. So let's shift gears and let's talk voting because I know that that is a topic of conversation. There was a recent election. And my first question to you guys is, I want to talk about misinformation, disinformation from where you guys sit.

What actually is that and how does it happen? Um, so mis- and disinformation are very similar, but they've got a slightly different flavor. So misinformation is mostly when somebody just doesn't really know better. You hear something and you repeat it, and it just might not be the truth. So you're misleading somebody in what you're saying.

Okay. Disinformation is more of an intentional, I am providing you false information with a purpose to mislead you. So we handle them both the same because they can both be equally detrimental, but one is a little more malicious intended than the other.

Rich and I learned that in— back in the 2016 election, that mis- and disinformation were going to be a huge, huge part of securing the elections going forward. Yeah, we had several incidents during that election that came out of social media. People claiming that they had hacked a county site and changed all the voting records for McAfee to say that McAfee was going to win the election. We had others on the dark web claiming that they had Colorado voter information that they were selling on the dark web. Well, through investigation, we were able to find— well, Rich was able to find that the dark web selling voter information was publicly available data.

It wasn't actually— didn't have Social Security numbers, didn't have all this, all the PII to it. It was just basic information that you can get through public record search, and that the other claim was just completely false. You know, they provided screenshots and all this stuff, but we were able to take it down. The lesson, the main lesson learned from that was that it took us about 24 hours to get that tweet removed, After we proved that it was fraudulent. Leading into this election, there was a lot of groundwork laid with the social media agencies, Twitter, Facebook.

We had direct contact with those agencies so that we could more quickly combat mis- and disinformation. We went from 24 hours to take down a post to 1 to 2 hours. Wow. Now, our focus for this was specifically things that were misleading about the election process itself. We weren't going to touch anything regarding, you know, specific candidates or anything like that, personal opinion on individual people.

It was more like, hey, this voting center is closed. And one of the examples we had from this last year was, you know, at this drop box, there are armed personnel preventing people, people of color from dropping off their ballots. And so that was going all over on Nextdoor and Twitter. So we were able to look at the camera footage, or the county was able to look at the camera footage and show that no, nobody's actually there. There's no armed personnel.

So they could actually take down those posts. So having those relationships was great for combating that type of mis- and disinformation. So has there always been mis- and disinformation, or is this kind of a new concept within just the last, you know, several election cycles? I'm pretty sure misinformation and disinformation has been happening for the past, you know, well, since our country was formed and before. But I mean specific to, I guess, kind of an election.

Well, yeah, like, you know, election challenges. I think that's been common practice for a very long time. I think it's become highlighted more because we have technology that allows us to communicate faster over a broader range of people. Okay, yeah, yeah. So you, you guys have always had to kind of deal with that.

That makes, that makes sense. So how can the public find out if something is like misinformation or disinformation? There's a— yeah, of course First of all, you can go to our website, govotecolorado.gov. Okay. We'll link to the Secretary of State's website.

And right off of that page, you can link to several sources that, that cover misinformation and disinformation, what it is. And actually, the Secretary of State formed a whole campaign around that to stop misinformation and disinformation, which has been fantastic. On top of that, you got the cybersecurity infrastructure If you go to cisa.gov, C-I-S-A dot gov, forward slash rumor control, they have an excellent website where they're constantly updating and talking about the different rumors and stating what the actual truth is. In addition to that, there's on that same site, there's an election disinformation toolkit published by CISA, which is a great resource. And then our CIO Trevor Timmons pointed out that There's an Elections Infrastructure Partnership, eipartnership.net.

It's housed by Stanford Internet Observatory and several other— the University of Washington— who put a lot of good information out there on disinformation and defeating it. Okay, awesome. Yeah, that's good info for the community to hear and learn about. Again, from your perspectives, what role do you think social media has really played and contributed to, I guess, the misinformation and disinformation? As far as social media goes, you know, I think that no matter what, the biggest thing is education.

Yeah. Social media has been involved, but whether you're on social media or you're going to a news site, No matter what, you got to consider your source and you need to be making sure that you're fact-checking, that they're referencing the material, that they're backing up their supposed facts. It doesn't matter what news source you go to. I won't name them, but there's, there's news sources that are mainstream on both sides. Yeah.

And every side that you can possibly think of, whether it's a conspiracy theory or extremely right or extremely left. The key is paying attention and I think it's really important that the American people and our kids learn to check their facts, check their sources, and determine who they trust. And not only that, but go to more than one news source. You know, why are we limiting ourselves to— people like to feed what they want to believe, right? So instead of going to the news source that's your favorite every day, check out some other ones.

One of the sites I really like is allsides.com. They try and do that. They try and show you the different news sources, whether they're very far left or very far right, and then kind of give you the story on all sides. Yeah, it's the name of the site. Interesting.

I'll have to check that out. allsides.com. And piggyback a little bit on what Rick was saying of the media campaign that was put out by our office. One of the things that they kept pushing is the Go to the source. Find your source of truth.

So when you're talking elections, absolutely, the Secretary of State website should be your source of truth, or your county website, because they are the ones running the election. They are your source of truth. So the best way to combat it is find the source. Where is the information coming from? Good advice.

Let's talk technology. In relation to voting. So do you think it will ever be possible to be paperless when it comes to voting? I think that's an interesting question. I think lots of famous technology people have said that certain things would never happen, and then they regretted it later, or they said, you know, no one will ever need more RAM than, you know, 120 meg.

And so I don't want to ever say it won't be possible. I will say that it's a ways out at a minimum, and that there's some definitely obstacles ahead. Absolutely. Our saving grace for this last election, well, for all of our elections, is our risk-limiting audit process, which we use to compare the paper ballot, which is what's actually counted, that piece of paper, not what's marked into the computer when you go into the voting center. It's that paper ballot, and we can compare that to the electronic record from the scanner.

So if there is any question, do the numbers match, you can go back and verify whenever, however many times you want. You can keep going back and verifying. If we get rid of that paper record, it makes it much, much more difficult to say, yeah, no, nobody changed those little bits, the ones and zeros. I can say definitively that it hasn't changed. It makes it much harder.

So perhaps 200 years from now, the only functional use of paper will be for votes. Who knows? I like it. Let's, uh, I, I do kind of want to explore a couple other, um, wacky far-out technology ideas, and, and if you guys have any thoughts on that. So blockchain, or, you know, artificial intelligence, machine learning, do these have any roles in today's days, I guess, operations of— and maybe not just voting, but Secretary of State's office in general, or in the future?

I don't know. What are your thoughts? I'm gonna let Rich handle blockchain because that is one of his favorite topics in the entire world. Perfect. So it is interesting.

I mean, I think there's a lot of good solutions out there for blockchain. There's a lot of things that we're going to see continue to be implemented with that. And I like the technology in a lot of ways. As long as we don't, you know, melt down the power plants trying to support it. Yeah.

As far as voting right now, there's some considerable obstacles it has ahead of it. First of all, we've noticed that a lot of times companies are using private blockchain and saying that that's the solution. I would tend to argue that once you make it private blockchain in this instance, you might as well have a private database, not a whole lot different. In addition to that, we have some major issues depending on accessibility. You know, you have the expense of a device that can defeat client-side malware attacks or BIOS attacks.

And we have different companies that are saying that, you know, software running on top of the BIOS can be secure. And, you know, to some degree I get it. You know, we can detect maybe if there's a rooted device, but one of the fundamentals that we learned early on in security world was If the lower label— lower level is compromised, the whole system is compromised. And I have a hard time getting away from that concept. I think it's an important one that we've seen hold true a lot of the time.

There are also voter authentication, denial of service attacks, disruption attacks. There's a lot of issues there that we'll have to address. And then the fundamental piece is the cost of the device. Who are the people that are really having a hard time getting to the polls or getting to be able to vote? And getting affordable devices in those people's hands to be able to vote.

There's a lot of challenges there. Definitely makes sense. So, you know, great white paper I want to mention too. I forgot about this. A group called Common Cause, which you can email, wrote a white paper called Email and Internet Voting: The Overlooked Threat to Election Security.

And it's not necessarily what our office is promoting or whatever, but it's an interesting read. Good to hear that and know about that. So I guess projecting into the future, 50 years from now, what's voting going to look like? Jason, I don't know what computers are going to look like 50 years from now. I mean, just your wildest dreams or guesses.

Secure voting that keeps confidentiality, privacy, and democracy alive. That's what I want to see. And other than that, I can't— I don't know. But still paper? Yeah, I'm not saying necessarily paper.

I'm saying I don't know. As of today, we need that auditable, yeah, auditable trail. And, and with anything, computers are a tool, right? With any system, including our government, we have this great thing called checks and balances. You know, that's why we have branches of government, and it works effectively.

It was designed well. So maybe it won't be paper, but we want to make sure those checks and balances are in place because our democracy and our right to vote— this country is the best thing we've got going. It is still the best country in the world, in my opinion, and it— we got to fight for those rights. Yeah. And as far as what elections are going to look like in 50 years, I can't say.

I mean, I've been doing this for about 8 years and it's changed drastically in the last 8 years. However, mobile voting, online voting, things like that are going to continue to be pushed. I don't know if they'll actually be in place, but people are going to keep pushing them because they want that voter accessibility and the ease of use and just what people are used to. They've gotten used to online shopping and online registrations for everything. Our office at the Department of State You can do almost everything online.

Yeah, that's what people want. So that's what they keep pushing for. But as Rich said, we need that audit trail. We're government, we cannot be on the bleeding edge of things. We cannot do the— this is the cool, fancy, most fun way to do it.

We've got to focus on what's the most secure, most transparent, and most auditable way to do it. Yeah. That makes sense. Let's get into the crowdsourced questions from the Colorado Equal Security community, and there's some good ones out there. What are the emerging threats you guys see in the future?

As far as elections are concerned, I can see the same thing we've seen in '16 and 2020. It's just going to continue to ramp up with foreign countries getting involved in social media trying to fan the flames. We saw a lot of social media posts that might have been started by an American, but then it gets picked up by these bots that are being sponsored by other countries and spread like wildfire through these. And some of them are getting started by other countries, and it's, it's an easy way for them to maintain or to spread false information. So here's another question.

What technologies have allowed Colorado to be at the forefront of election security? So primarily when we look at that, we implemented a lot of stuff. We were the first state to implement multi-factor authentication on our voter registration database, which was huge back in the 2016 election. We're the first state to implement risk-limiting audits so that we can show that the machines were not hacked. We can show statistically and see that the paper trail against what the machine said is accurate.

That's incredible. Along with that, of course, with Debbi Blyth in the state of Colorado, we've really focused on the critical controls and hardening systems and continual penetration testing, continual audits to make sure we're on top of them all? One of the things specifically with the election or the voting equipment is we make sure that all the voting systems are air-gapped, so there is no internet access. It is just impossible to secure a system if it has internet access. We have to have some crossover to be able to upload the results and things like that.

We've provided each one of the counties with an encrypted secured USB drive, that has firmware protections so that they can use that for the transfer between internet-connected and air-gapped systems to help make sure that those systems stay air-gapped. So every time that USB plugs into an internet-connected machine, it gets completely reconfigured and blown away before it touches another voting system. So those are some of our major— our big controls. And then I can't stress enough what Rich said of the risk-limiting audit. Just being able to validate.

There's always going to be vulnerabilities, there's always going to be ways to mess with the system. The ability to validate the results at the end is the key thing, to prove that they're accurate. Right, that makes sense. So here's another crowdsourced question, and I don't think this one is necessarily just election stuff. I think it's Just in general, what would you like to see when it comes to security?

So, in general, I think it's still the fundamentals. I mean, multifactor authentication, strong passwords, password vaults, patching, and when I look at the other things outside of elections, when we're looking at small business and other pieces like that, it's those same fundamentals. Things that we've talked about with small businesses, identity theft monitoring, or even individuals and credit monitoring, Audits and alerts on your bank accounts, setting up multi-factor authentication on your bank accounts, uh, for phishing protection. One of the things that Craig's been working hard on is browser isolation. Yeah, and I'll throw out there also sharing of information.

We've had several other events over the last few years with vendors, with whatever. I mean, SolarWinds is on top of everybody's mind. And, you know, FireEye has been phenomenal with sharing the information. We've had other, not quite to this level, but similar incidents with other vendors, and it's, you know, they've got to protect their investment, so it's very close, very closed off, not very good information sharing. So that's what I would really love to see with security is more information sharing, getting stuff down from the ISACs, from various other threat intel, feeds is great, but by the time we get it, it's, you know, 2, 3 months after whatever happened, right?

So we need a better collaboration, sharing, get out there in front of things. When you notice something is bad, let the community know so we can protect ourselves. Yeah, it's interesting you bring that up because another of the crowdsourced questions was, how are you coordinating with local businesses around threat intel and sharing? So it sounds like that's That's, you know, that's an area that can be improved, right? But what is happening today?

Well, as far as sharing within government, it's been much easier. We've been able to work with different jurisdictions to start the Colorado Threat Information Sharing Group that a number of the people on the Colorado Cybersecurity Group are members of, but we have limited that to government. There's definitely legal and other challenges when it comes to sharing threat information with businesses from our perspective. OK, so we want to do it and we're wanting to approach that, but we aren't there yet. Yeah, makes sense.

Here's another question. What are the biggest steps businesses can take to protect themselves and their customers' data? Multi-factor authentication. We harp on that all the time. It's a great Great benefit because passwords just— you can't make them long enough and people don't remember them when they are long enough.

So having that multi-factor authentication, penetration testing, making sure stuff is secure— we miss stuff all the time, so having that second set of eyes come back and look at it. Patching. All right, every security training course that I've ever been through, that is the number one thing that is always touted: patching, patching, patching. Because every breach that you hear, oh yeah, they got in through this, you know, 3-year-old vulnerability. I know it doesn't always work, but patch as much as you can.

And if you can't patch it, mitigate it. Who do you guys look up to in the industry? And have you had any mentors? So I don't know if I can really list off people that I look up to because I know I'll leave somebody off the list. Yeah.

It's always hard. As far as mentors, Rich, he's been a huge mentor for me. He's actually the one that got me into cybersecurity. As I said, I started out as an admin at a firm, you know, working as a network admin, so he kind of pulled me into the security side and showed me how exciting that was. Debbi Blyth, the state CISO, she has been an amazing partner, great resource, very smart lady.

Our CIO, at the Department of State, Trevor Timmons. He's involved in so many different things at the state and the federal level.

Amazingly sharp guy, very quick, and just getting a lot of positive movement on various projects to help us secure not only our office, but the state and the country. Awesome. How about yourself, Rich? From my perspective, again, I gotta emphasize that this community, Colorado Equal Security, I'm so thankful this was started. I'm really thankful to Robb and team.

Amazing stuff that you guys have done. The— I don't know, everyone here is my friend, you know, and everyone has each other's back, and it's really a strong community. So there's a number of people. Again, I gotta emphasize Debbi and Trevor. Debbi Blyth is an amazing leader.

Leads by example. And Trevor, man, he dwarfs our knowledge when it comes to election security. You got to have him on here someday because he can read faster than anyone I've ever met. Oh yeah. And retains information like you wouldn't believe, and he's good with it.

And then, you know, this person that really encouraged me to move down the security track was Mike Weber. I believe he's with Pulsefire now. He's a pretty amazing guy. Yeah, great stuff. I'm glad that you both kept mentioning Debbi Blyth.

So I think we should end on this particular crowdsourced question, which comes courtesy of Douglas Brush. And the question is, if you challenged Debbi Blyth to a dance-off, what song would you use? I'm gonna leave that up to Craig. Yeah, I can't dance. Yeah, that's— so she's just gonna win by default?

You're not even gonna compete or challenge her to this dance-off? I'm sure she'd spank us in whatever we chose, but I've got a 4-year-old daughter, so I'll throw down with anything from the Frozen soundtrack. I'm sure I could go toe to toe. There we go. There we go.

So if she also— if Debbi had to dance to that same soundtrack, who would win? I don't know. I'd probably have to give the props to Debbi. Okay. All right.

I could put up a good fight with that one, but Great stuff. Good stuff. I'm glad we could end on kind of a fun note. How can people find or follow you on social media? Or do you guys stay off of it because of, you know, what it is?

I'm still involved in social media. I am under the impression that if you're not on it, someone else will create an account for you. So I would rather have an involvement on there and be aware of what's on there, plus knowing the platform. So I'm Cyber Summit on Twitter. I do not tweet a lot, so don't expect, you know, like daily updates.

And then of course you can find me on LinkedIn and the Colorado Equal Security Slack channel. Great. How about yourself, Craig? I'm also on the Colorado Equal Security Slack channel and LinkedIn. I do tend to shy away from social media.

We do have a Twitter and Facebook page for the office. So I tend to let them handle most of our tweets and posts. If anybody needs to reach out to me, they can connect via those, the LinkedIn or the Slack channel. Very good. Very good.

Well, I appreciate it, guys. Thanks for joining me today. And, you know, I hope you have a great rest of your day. Thank you. That concludes my interview with Rich and Craig.

Be sure to follow and support Colorado Equals Security on Patreon. This is Jason Jaques saying be safe out there. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes