Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 200. 200, Robb, that's a big round number.
It sure is, Alex. It's good to get back together in person. It's been a while since we've recorded in person. Nice to see you. Nice to celebrate in, uh, in style rather than remotely.
Uh, we do have a— we're gonna do kind of a different interview this week where we're gonna interview each other and take some questions that we got from, from the community and, and talk about 200 episodes of Colorado Equal Security. But first, we have a newscast. We do. Um, this is going to be, you know, somewhat similar to the other 199 of what— of these that we have done. So Uh, get ready for some, some sameness here.
Ready for the old comfortable newscast. That's right. Uh, speaking of old comfortable things, we have a Slack channel, which is a very comfortable place to hang out if you're a security person here in Colorado. We've got, uh, I just looked today, 1,837 members now. Wow.
That's a lot of people. Uh, Robb, we also have a mailing list. Uh, if you would like to get the show notes emailed to you every week, uh, you can sign up on the website colorado-security.com. And there's a form there. We'll send you one email every week with the show notes, and that is it.
And that's the same place you can find the Slack link on the website, colorado-security.com. We'd also love it if you would rate us and subscribe on your favorite podcatcher— iTunes, Stitcher, Spotify, whatever it is you like. Rate us there and subscribe and get the show in your news or in your inbox every week. Other things you could do is tell a friend, let them know about Colorado Equal Security, what we've got going on. Have them come join us, listen to the podcast, join the Slack channel, all that sort of thing.
And then finally, if you want to support us even more, you could do it with a little bit of cold hard cash. We do have a Patreon campaign, so you could come there and, and support us through Patreon. Depending on the level that you sign up for, you will get some free Colorado Equals Security swag. And we now also have yearly memberships. So if you just want to pay once for a whole year, you can do that.
And Alex, is there a secret menu for our Patreon campaign? There is not a secret menu, but I could probably make one if we really want one. Is there a back massage option or, you know, supporting Colorado Equals Security animal style? Animal style. Hey, speaking of secret menus, the way that segue went couldn't have been better.
There is a new In-N-Out that's being opened in Colorado. It's actually really close to both you and me. Yeah, so down by Park Meadows Mall in Lone Tree, the 3rd In-N-Out location in Colorado is now open. Kind of crazy that these things are happening. I still haven't been to one in Colorado.
I mean, I like In-N-Out, it's fine, but I figure someday when things die down a little bit, I'll probably go and see that. There's also almost next door to that In-N-Out Burger is a Chick-fil-A. So It's going to be a little bit crazy around County Line Road by Park Meadows Mall for a bit. Yeah, I'm— I actually am looking forward to getting an In-N-Out there as soon as I think I can do it in a reasonable amount of time. I don't think spending 2 or 3 hours waiting for a burger is a reasonable decision.
Yeah, I almost thought— what was it, Thursday this week when there was the snow, the sort of unexpected, you know, foot of snow or whatever it was? I thought, hey, Maybe if I just like snuck out and went to In-N-Out right now, there would be nobody there because there was snow. And then I thought, eh, I don't really care that much. It's a good thinking. I like the way you think though.
Yeah. You got to find a way. Now, I don't know what time they open. It might be like if they open at 10 AM, maybe I get a, I get my morning burger. I don't know.
Right. I don't think my kids have ever had one. I'm from California, so I had lots of In-N-Out in my life and I think that they're mediocre burgers and Carl's Jr. might be better. But you know, my kids getting to have their first one here in in town, that'd be nice. Well, you know, I think it was last week we talked about Douglas Brush getting a negative review on the podcast.
I think talking about how bad In-N-Out is, Robb, you might get a couple people that complain now. It's not, no, it's not bad. It's just, it's just fine. It is fine. It is fine.
All right. All right. Moving along. We do have, I didn't actually even know that there was such a thing as a National Scenic Byways list. Basically, you know, we have national forests and we have these highways that are protected as scenic roads throughout the country.
Well, 2 more Colorado roads got added to the National Scenic Byways list. Yeah, so there are now 13 in Colorado. The 2 new ones are the Scenic Highway of Legends and Silver Thread. Also, there are— this confused me for a minute when I read the article at first— there's now 26 scenic byways in Colorado. So 13 of those are now Colorado scenic byways, and then the other 13 are National Scenic Byways.
So we've got 26 in total. So you should go and find, you know, all 26 of these great places to drive. Yeah. And go check them out. It seems like national parks versus state parks, same idea.
And being on these lists does give some protection to the road and additional maintenance dollars, you know, some benefits to it. So I like number one, I thought this was interesting to include because I didn't know it existed and hopefully you didn't either. And this might be a place for folks to go, just go see a new part of Colorado. So the Scenic Highway of Legends is an 82-mile road it down along Highway 12 and US Highway 160. And it features Spanish Peaks and it connects Trinidad, La Veta, Walsenburg, and Aguilar.
Yeah. And then the other one, Silver Thread, is 117 miles and it's along Colorado Highway 149 and US Highway 50. And that goes through the San Juan Mountains, going through South Fork Creed, Lake City, and Blue Mesa Reservoir near Gunnison. And I actually drove that one this summer. I didn't realize that it was a, probably at that time, Colorado Scenic Byway, but it is a beautiful stretch of road to drive on.
And I've had on my list for the last couple of years to try to get to the state parks. And it's nice to have another thing to add to the list. If I'm in that part of the state, let's go try the byways as well. For sure. All right, next.
This is a story that is near and dear to both of us, Robb. There might be 2 people who care about this. Well, 3 if Curtis is listening as well. That's right. Not a lot of people who are going to care about this story, but we care.
Yeah. So national homebuilder Pulte Homes plans to build 200 homes in, in South, South Denver suburb, relaunching their presence in Colorado. Yeah. So, so Alex and I have both been CISO at Pulte in the past. Neither of us are now.
Curtis Lutson is the CISO there now. Pulte is a big national homebuilder, but the headquarters for Pulte Mortgage and Pulte Financial Services is in the Tech Center. They were in Colorado until the Great Recession, 2007, 2008, pulled out entirely. And now they're coming back. I have been to some Pulte home developments in the South.
And I was blown away at how, how nice their houses were. And, you know, I mostly thought, you know, I've really only owned 40-year-old houses my whole life. I've always thought like, yeah, what's the difference between a new house and an old house? And I go into their house and like, the little improvements they've made on design and like livability, they make a big difference. It adds up to a significantly better home than, you know, what we— you and I live in today.
Yeah. And of course, Pulte used to build in Colorado and then back in 2008-ish, it was part of the Great Recession, pulled out of Colorado to focus on fewer markets. And so it's interesting to see them now coming back. And so these developments are going to be part of Sterling Ranch, which is down near Roxboro off of Titan Road. So there's a giant development going in out there and a couple of hundred of the home sites are going to be Pulte Homes, basically in between Roxboro and Highlands Ranch.
So yeah, good way to look at it. Yeah. All right. Moving along, we have another piece of news from a local company, Dish Network. They basically released their results from the previous quarter.
But the interesting part of the story that I wanted to talk about was They have, they've committed to launching their 5G network in a city the 3rd quarter of this year. So 5G from them is going to be out just, just in a few months, really. Yeah. And people might say, oh, well, what's so big about that? You know, we see all these ads from the big mobile carriers already that they're already doing 5G.
Well, I mean, Dish is basically starting from scratch, right? They, they had a bunch of spectrum, but they didn't have a network in place before. They have gotten pieces of network from other companies. I think they got Boost Mobile from Verizon and some other things like that. But as far as I know, all of the 5G parts they're having to build from scratch.
Yeah, that's a pretty big accomplishment. Yeah, it is. They said they'll be out to one city here in Q3. They wouldn't say what city, but it's a big market that does have an NFL city, an NFL team. So you got 32 to guess from there.
Yeah. And then I pulled out one other interesting fact from this. They said that they're planning to have their network accessible to 20% of the US population by 2022. And to 70% of the population by 2023. That's a pretty big increase.
Yeah, that's like half the population. I think that's even more than half the population, Robb. It's even more than two-thirds of the population if they do get to 70%. It's not three-quarters, though. It is not three-quarters, although pretty close.
So pretty cool from them. You know, we know some people over there at Dish and, yeah, you know, trying to make sure that their 5G network is secure when it gets deployed. Yeah, you know, Henry Yu was the director of security at Red Robin, and he's gone over to DISH to help secure the 5G network. And I know Artie, the CISO over there, they're working hard on it. Yeah, I'm excited to see what they, what they do.
A couple of our former employees at Pulte over there now too. Good stuff. Yeah. Hey, um, this next one, I just wanted to say, you know, we, we talk a little bit about random tech companies in the area if they're interesting. It's not security, but it's just cool to know that there's so much tech innovation here happening in Colorado.
Yeah. So this next one, a Boulder startup called Tilde, is helping people with their payment processing. And when I first saw this, I was like, payment processing, isn't that something that's already solved? Stripe and Square are already doing it, right? Got nothing going on here.
Or, you know, you've got on the other hand, the big ones that, you know, Worldpay and First Data, whatever. It's like, why would you do a startup here? So It's, it's pretty cool. And one of the things that, that stood out to me in the article is, uh, their founder was talking about how if you are starting a company and you are very small, then, you know, you can use a Stripe or something like that. And it's, you know, pretty easy, right?
That there, you just go to them and they give you whatever you need and you don't have to do anything. You have a developer spend 1 hour and you're up and running, right? But then, um, you know, until you get to some giant amount of payments where you're essentially building your own infrastructure, There's like a, well, I guess it was an unsweet spot in the middle where you're not big enough to develop things yourself, but, you know, the smaller providers, the easy button stuff like Stripe probably doesn't work for you anymore. Yeah, they say it's roughly between $50 million and $2 billion in processing volume where they saw there wasn't a great solution for those companies. And that's really where Tilde is coming in.
The intention is that companies can use the Tilde platform to monetize their own payment and avoid having to use like a platform like Stripe or get to the big guys. What, what was surprising to me here was this. I'll just read the quote. It gives these companies the ability to monetize their payments and keep 66% of that revenue share. Does that mean that Tilde takes a third of payments?
That means that's what it sounds like to me. And I thought that was a big number, but like, maybe not. I thought it was like 2% usually. I think we're missing— I think I'm missing something here. I think that there probably is something missing there.
But yeah, I mean, it is usually— well, it's also there's like a straight transaction fee plus some percentage, right? That's generally how it works. Yeah. So I don't know if now you're not taking a transaction fee, how does that relate to the 33%? I don't know.
Anyway, it does say that Tild does not have any monthly minimum fees or startup setup fees. So they're really— the quote in the article said, you know, we're not making any money until you're making money. Which is always a good way to have a partner, right? Your partner's not there to hose you before you're getting going. And that sounds like what their commitment here is.
Yeah, so good luck to them. Hopefully they can capitalize on that sweet, sweet middle. One quick other note about them, they currently have nearly 10 full-time employees, which I imagine means 8, and they hope to grow their staff to 25 people by the end of this year. Nice. Good luck to Tild.
All right. Now into the security news. Some probably biggest news of the week that we have. InteliSecure announced that they are going to be acquired by Proofpoint. Yeah.
Congratulations to, you know, we've had several of the folks over there on the show in the past. Stephen Drew, who's the, I guess, the former CEO, current CEO. I don't know if anything's changed on that. Jeremy Whitcop, who's the CTO, has been on the show. And we've had Misha, who was the CISO, who's left.
Has moved on since then. This looks like a good fit for them. I really hope it is. InteliSecure has a really interesting background. They started off doing mostly consulting around DLP and then became a kind of MSP focused solely on DLP.
They were called at the time BEW Global, right? They became InteliSecure maybe, man, quite a while ago, 8 years ago or something like that. And since then, they've really focused on being your kind of critical data identification and protection company, which is pretty close to DLP, but they also did some, some of that CASB-type stuff and some SIEM-type activities as well. And this looks like it's going to give Proofpoint a new offering and hopefully keeps that team intact. Yeah, and I think that this, uh, this fit really makes sense for InteliSecure too.
You know, Proofpoint over the years, I think we all know them for email security, but they have been moving farther and farther into other markets trying to be more of you know, just a data protection company in general. And so getting a company that is focused on data protection and data loss prevention seems to be a good fit with them. So hopefully it's a good thing for both companies. Good stuff. Well, congratulations to those.
And I do hope that, you know, it ends up with new investment into that line of business. And those folks who are there are looking forward to a great career as a part of Proofpoint. Moving forward, we have some Ping Identity news, a press release from Ping this week. On the being named as leaders in 3 separate KuppingerCole— what do they call those? They don't call them magic quadrants.
They call them leadership compass. There you go. I think that is a synonym for magic quadrants, but similar types of things. There's no magical thinking involved here, though. Right.
The 3 areas are consumer identity and access management, or we call CIAM. There is access management and there's enterprise authentication solutions. Those are the 3 areas, and Ping made a leader in all 3 of them. Congratulations to Ping. I'm personally not familiar with the, the KuppingerCole ratings as opposed to the Gartner ratings, but, you know, any company that does this sort of thing and puts you in the leader category is pretty cool.
So having been in this space for a little while now, I can say KuppingerCole is really big in Europe, whereas Gartner obviously has the mindshare here in the US. Forrester with their Waves, you know, North America focused, but I think they'd probably come in third in terms of most most of the the the buzz around them. Yeah. Well, cool. Congratulations to Ping.
Keep doing good stuff. Next, we have a blog post from Coalfire, and this is it's talking a little bit about the the Rise program at at Coalfire. We've talked about this before. This is the I'm not going to remember the recruit, influence, support, and educate women in cybersecurity. And, and this is about a sort of a— I don't know if you call it a case study.
It's a, you know, some examples of success. Examples. Thank you. Someone who has, has been working through, you know, helping mentor women in cybersecurity and some examples of people that have done well through this, this Leadership. Yeah.
Ian Walters is the, is the author of it. And he goes through, how many was it? It was 7 stories. I think he used something like that. 6 or 7.
Oh, 6, 6 stories. And interesting at the end of it, he points out that, you know, he goes through stories about how he hired these folks and what their, you know, what their career path looked like. And at the end he says, you know, 6, 4 of these 6 were women. And he didn't use the pronouns to identify which, and his point is it doesn't matter. Uh, which are which.
And I think it's an interesting perspective. You know, we, uh, there's a balance that we're trying to get between, you know, let's not look at, uh, at gender or race as a defining factor for anything versus, well, we're not going to normalize things unless we're trying to find opportunities to promote and hire, um, people who are less represented. Um, I don't know which side of that I come down. I think I sometimes come down on each side of it. And I think in this, he's just kind of pointing out that you know, let's focus more on the, the individuals versus the groups.
And, and so he tells individual stories. Yeah. Good stuff there. All right. Next, we have a Red Canary blog post.
And I don't want to say we're late on this, but we're a little bit late on this. This came out at the end of last week. And we didn't pick it up as part of the podcast news last week. But then, you know, the mainstream media picked it up and it was kind of everywhere. Yeah, we— I think we missed our chance last week.
But we decided we'd talk about it this week. Uh, so this is talking about, uh, Silver Sparrow. And so if you've been under a rock, this is the, uh, macOS malware that is, uh, sort of pivoted to focus on the new M1 chips from Apple. So, uh, also the malware was on, I think it was 20,000 or 30,000, um, Macs, but didn't appear to actually be doing anything. Yeah, it is.
So they said 29,000 Macs is what they identified. The, the 2 interesting facts, you, you hit them both. It went after M1, although it wasn't just M1, right? But, but it did impact M1 as well. And the fact that there was no payload, so the expectations were this is probably some kind of a service that's looking to get a foothold so that people can pay to get their malware out on that.
And as of yet, as of the day of, you know, the research, and as of even today, there's no indication that that's happened. But I think it's just a wake-up call that, hey, the M1s, they're barely out of the store, out of the, out of the store and in your environment, and now they're being targeted. Yeah, uh, some definitely some good work here by Red Canary. So I saw it on— I saw them, this research quoted on the main story or the main page of CNN.com. So seeing Red Canary on, on the front of CNN, that's pretty cool.
That is pretty cool. Glad to see those Colorado companies making a difference. All right, last story this week from the news section. Um, we have a, a blog from, from LogRhythm, and they, they're giving a Zero Trust Framework Guide to Implementation. I think, you know, this is not unique.
There's, there's lots of zero trust frameworks out there, but I actually think it's really important to see different instances of these because zero trust is such a big topic. And if you decide to implement it at your company or I do it at my company, it's going to look very different, right? And seeing examples of how other folks have done it makes it much easier for us to customize and think about how we're going to do zero trust ourselves. Yeah, I also like how they focused the article. A lot of times you see zero trust articles and it's talking about the specific technical pieces that you need for an implementation, right?
You need to have a user-aware proxy and you need to have this and that. And this is focusing a little bit higher on the areas where you need to think about for Zero Trust. 5 areas. 5 areas. Number 1 is people.
Number 2 is workloads. 3 is devices. 4 is networks. And 5 is data. Yeah.
So I think if you are starting to go down the Zero Trust journey and trying to conceptualize the things that you will need to do, I think this is a really good way to think about it. So I'd say check out this, uh, this article, and, uh, I think it will help you sort of figure out the direction that you would want to go for, for zero trust. All right, good stuff. Uh, that is it for the news this week. Let's jump over to our Slack message of the week.
Big thanks, Andre. We appreciate you, uh, supporting this for, man, not maybe not 200 episodes, but really not too far off. It's pretty close. Uh, I don't remember. We should probably go back and figure that out when it actually started, but we were doing at the beginning trivia.
Yeah. And that was very near to the beginning. Yeah, it was very near. So Andre, thanks for all your support going through this each week. Andre, out of his own pocket, pays up to $25 for swag from the Colorado Equal Security Store for one person who's helping us keep conversation going in the Slack community.
Who do we have this week? This week, our winner is Ryan Jameson. Congratulations, Ryan. He won for a post talking about how he is he has tried to take some purposeful time away from technology. So it's both with his wife and his family.
And, you know, also just personally, you know, not just stepping away, but stepping away completely. When he's doing certain things, it's, you know, no screens, no electronic, just, you know, a non-electronic, non-work time. And he said that's really helped him Uh, you know, sort of focus and, and compartmentalize and rejuvenate. Yeah. Good stuff.
I appreciate that, Ryan. Congratulations. And hopefully we'll see you wearing some sweet, sweet swag. Yes. The other part of that that I appreciated and part of the reason why I picked it is, um, part of the conversation he brought up The NeverEnding Story, which is, you know, an amazing movie, something from our youth.
And, uh, well, I mean, not amazing in a, in a technical sense, right? It's, it's not like there was a lot of effort put into the production of the movie, but it's It's still an amazing movie. I remember it very fondly. Yes. And then I saw it and I don't remember it as fondly recently.
All right, move. Let's jump over to events. Uh, we do have some events coming up this next week. On the 5th, Colorado Springs is doing their First Friday Cybersecurity Social and Mixer. On the 6th, ISSA Colorado Springs, uh, is starting that Security+ review that we talked about.
On the 9th is ZapCon. So this is the first time I think we've talked about it here, but You know, Zap is, is the underlying technology used by StackHawk. Caw caw! Thank you. And, and they're putting together the first ever ZapCon with, you know, the, the founder or the creator of Zap who's going to be there, who's now a StackHawk employee.
So this should be really fun. Hopefully folks who are interested can make it. Next, on the 10th, Denver ISSA is doing a chapter meeting, Zero to One: Building a Security and Privacy Program from the Ground Up. I think Janelle Hsia is part of this. All right.
Good stuff. And last, last event to talk about over the next 2 weeks is ACES is doing their meeting on the 11th, and that is about your personal brand matters and really talking about how to build a brand. Yeah, good stuff. And if you want to see more events going out further into the future, go out to colorado-security.com, click on the events link. There's a calendar of events going out for quite a few months.
Good times. All right. Let's move over to jobs. Robb, any Ping Identity jobs this week? 2 jobs to talk about.
Number one, we are hiring a security program manager. This is someone who is kind of a right-hand man to me or excuse or a woman, right-hand person, either way. I'm happy to have either. My current one is a woman. I'm not sexist.
And, uh, not too much anyway. Be happy to have, uh, someone come talk to me on Slack if you have questions about that role. Uh, number 2 is, uh, we are looking to hire a product security engineer, uh, and that's someone who has a development background with an interest in security. Connect for Health Colorado is looking for a security analyst 1. Uh, MYR Group is hiring a security engineer.
The City and County of Denver is looking for an identity and access security engineer in their technology services group. Air Methods is hiring a senior IT security analyst. AWS is looking for a program security officer. That sounds interesting. This is a— looks like it's probably on their federal side.
As you read it, it's all those acronyms that I've recognized, but I don't know what they mean. Right. The Bellco Credit Union is hiring an OTS security analyst. Four Winds Interactive is looking for an associate security analyst. And finally, Denver Public Schools, they're hiring a Security Systems Administrator 1.
All right, good stuff. Robb, we made it through the news for the 200th time. 200th time, that's pretty good. Why don't we, why don't we take a break and come have a transition and come back and let's do our interview. Sounds good.
Thanks. This is Josh Ryan, Network Manager for Ultra Petroleum. Welcome to Colorado Equals Security. The podcast for Colorado security professionals by Colorado security professionals. All right.
That was a great transition. And now we're back with the second half of the podcast. This is a little bit different in that we're not interviewing someone else, but we're interviewing each other, which we— I think we did one time before. Yeah, early on. So we— I think we sort of did it on the first episode.
Yeah, actually, I think we might have done it twice because then I think we went back and rerecorded a similar episode to the first episode, but that was different. Just talking about why it is that we were starting Colorado Equal Security. Yeah, I think maybe before we start into these questions, it might be worthwhile to say, why did we start Colorado Equal Security? 200 episodes in, why, you know, what, 4 years in, why did we start this thing? Yeah.
And I think, you know, both you and I, we were part of the security community in Colorado in general. And, you know, being part of ISSA, being presidents of ISSA, we had a lot of visibility. I mean, specifically to that organization, but also seeing other things that were going on, especially RMISC as well. So not only were we doing ISSA, but ISSA, you know, co-owns RMISC here in town. And we both did a lot of volunteering there, especially you for many years.
And we would see these other groups like Yeah, we know ISACA. Obviously everyone knows ISACA. They're big and they're a great group, but there's other ones. There's CSA and there's OWASP and then there's all these little smaller ones too, right? Like, you know, DENSEC, which has started while we've been doing this.
And there's 303 or what, DEF CON 303 or 303? Yeah, the 303 group and then DenHack and yeah, all these different groups. And the longer we're in ISSA, the more we see that, my goodness, there's so many different groups. But I know when I Googled security groups in Colorado, I came up with ISACA and ISSA, right? I think the other part is, uh, you know, the longer you're in the community, the more people you meet, you, you realize how big the community is.
And we thought, okay, well, this is great. There's lots of people out there, but, you know, many of them don't know about each other. So let's figure out how we can bring these people together. Um, there's plenty of stuff going on that, you know, there were lots of chapter meetings and happy hours and events like that. So We thought, okay, well, we don't need to create more of that stuff, but, but what is it we can do to, to bring these groups together and let people know about all the stuff that's going on?
Yeah. And the way I put it, and I sat in my office at Ping with several, maybe dozens of people, and I wrote on the whiteboard like this idea of bringing these groups together, be the connective tissue. So if you come into town and you say, I'm interested in security, you don't have to go to ISACA or ISSA. You can go to the one that's the right fit for you. Um, and really get ourselves to be that place where the landing spot.
So that's what, that's the idea. We're the connective tissue to amplify the cool stuff that's already happening in town. Um, you know, if you go to the website, you'll see that's exactly the way it's created. We show you all the groups that are in town, you know, all the security groups we're aware of. We show you all the security companies in town because we think it's cool that we have such a great security company ecosystem.
We've got a calendar of events and then we've got the podcast news. That's basically what we've got on there. Yeah. And I think that really highlights all of the great stuff that is going on. And yeah, so I think it's in that regard we've been very successful.
Yeah. And, you know, continue to grow the community. Hopefully. Hopefully. I've heard personal stories of people who are going to move to Colorado and they find Colorado Equal Security first and it becomes the place where they can get plugged in.
And that's, you know, that's a really great success. Yeah. All right. We've got a whole list of questions here, Robb. So why don't we jump into those?
The first question is, how many episodes do you think Colorado Equal Security will eventually reach? Yeah, there's another question later on that we can probably skip that says something like, how many do you want it to reach? And right. And you and I, before we hit record, we're like, man, I don't know the answer to that. Right.
I can tell you that I don't want to spend the rest of my life doing a weekly podcast. It's kind of a lot. However, I do think that there's value to the community and we, we think of this not as a podcast but as a movement. And the podcast is just one element of that. Yeah.
And when we started, The, the podcast, I'd say, was a, was the core piece of Colorado Equal Security. And partly because we didn't have anything else yet. Right. And we, you know, we used that to, to continually grow who was aware of Colorado Equal Security. But I think we're to the point now where if the podcast did stop, I think the movement would continue.
And, you know, there's plenty of momentum there to keep it going even without the podcast. So, yeah. We're not actually answering the question here, but the, you know, I think there's not a defined number. And, you know, maybe the podcast continues someday, you know, without us, with different hosts. Yeah, that'd be my, that'd be my personal hope is, you know, you and I are 200 in, you know, maybe there's another 100 episodes of this that you and I do, or, or maybe somewhere in the next 50 episodes we bring in another person to join us as a host or to, you know, eventually take one of our places as a host.
It'd be great to me if this podcast goes for years, for decades, and you and I are listening to it versus doing it at some point. Yeah, that would be pretty cool. So millions of episodes is the answer to this question. We want to see— it will never end. Just not with us.
Hey, I'll ask you a question. When we, when we started, how did we define success for the podcast? Let's start there. So I don't remember the exact numbers, but when we started, I— we checked the, the number of subscribers, the number of listens, all this stuff very closely. And, and you were very keen on, right, we need to get to this many listens, we need to get to, you know, and it was, it was more about just growth in general to see that we were making progress.
But we had, you know, we had defined numbers that we wanted to get to in terms of number of listeners, number of subscribers. And that's not what we look at today. Um, I think we do, we can still track that stuff, but it's less important. At some point I stopped tracking, but I do remember my hope was that, you know, in order to feel like we had a good reach, we wanted to have about 1,000 people listening to every episode the first week it came out. We did hit that before the pandemic.
We were pretty regularly in that, in that area. Uh, pandemic has just obliterated, number one, it's obliterated my listening to podcasts, right? Number two, it's obliterated our listeners. I think we're down by about half. Uh, from where we were.
Um, so I thought success would be, you know, if we consistently had 1,000 people listening, that's a, that's a really nice reach. Uh, we're, we're, I think we're less than that today, but we were more than 500. Yeah. I think there were some other smaller things that, uh, were at least informally for us success. One was, um, having an interview as part of every podcast.
And at the beginning that was, you know, it was hard to do because we were doing all of the interviews in person. Right. So that meant that, you know, every week one of us had to go find someone and sit down with them for an hour and do an interview. And that obviously took a lot of time. You know, we've, we've strayed a little bit from that goal recently and that we don't necessarily always have an interview, although I think we've gotten good again having guest interviewers.
But that was also a goal for, for success. The next question is, what is the next goal for the podcast? And I want to reframe it a little bit. You know, we already talked about the podcast is, is one element of the movement and the community. And really the, the community, the idea is get a whole bunch of creative people together, create relationships and see what happens.
And a lot of cool stuff has already happened that were not our goals. Yeah. So we have people organizing poker nights, obviously. I mean, in general, the Slack channel, that was not something that was even on our radar at all as part of this. And that, that's probably the most active area of Colorado Equal Security these days.
You know, and lots of other things in that vein. The book club, the mentoring program, really cool stuff. You know, I do have some ideas for other things I'd like to see. And if you, if you go back to the idea of amplifying the cool stuff that's happening in Colorado around security and in trying to make Colorado the mecca for security, I think that eventually that has to cross from talking to ourselves to talking to a larger audience about how cool Colorado is. Yeah.
And I think that, you know, one way to do that is, is a, a big— doing some kind of broad gestures, big gestures as a community. We're going to get, you know, the leaders of the security programs for the 10 largest companies in Colorado to get together and, and do what, right? Like do a community outreach, do something that we could get the press to cover. And when you, when you start doing events like that, I think you build some real momentum and some real eyes come to it. I've had that idea since the very beginning.
Really what it needs is someone who's willing to put some time into making it happen. And so far we haven't had that volunteer, but if there's someone out here who wants to do it, you know, hit me up and I'm happy to kind of vision with you and figure out how we get there. Yeah. I think the other thing along that same vein is, you know, we've still mostly been focused on internal to the community, right? So it is security people that we're reaching out to.
I think we have an opportunity to go beyond that and do, I don't know if you wanna call it advocacy work, right? Reaching out to areas that are not security, not necessarily to grow our community, but to make people aware of the community, to increase security in general. And I think that there's definitely an opportunity there for outreach from our community to other areas that are not the security community. Yeah, that's good stuff. All right.
Uh, next question. Uh, how has being part of the podcast and thus community changed your view of security and changed you as leaders since it started? You know, I'd say, you know, I've been doing before the podcast, Alex, you and I have been doing these dinners with other security leaders in town for, for quite a few years. And I'd say that just the personal relationships we get through both the dinners and then the interviews and the podcast and the Slack channel, it, It makes what seems like a big community much smaller. You know, the numbers are big, but the ability to reach out, you know, people talk about it's a small— security is a small industry.
Like, it really is incredibly small here. And the ability to talk to anyone at any company, there's very few people who aren't willing to take a question or be willing to help you out. And it's also made, you know, I've had some just great friendships develop through this thing as well, which, you know, otherwise wouldn't have without the community. So I'd say it's changed my view to say that there's really no one who's unapproachable. You know, I don't care what their title is.
They're probably a very nice person who, who wants to help you be successful. Yeah, I think along that exact same line. Yeah. If you ask someone for time, even if they don't know you, they almost always say yes. Which is, which is weird.
I mean, obviously it depends on the request that you're asking. But, you know, when we've gone out and we've asked people to do interviews, We may not even know those people. They may not know us. And we say, hey, can we get half an hour or 45 minutes of your time to do an interview? And almost universally, people are like, sure, I'll sit down with you.
Including Brad Feld, like the richest man in Colorado or thereabout, right? Like, yeah, he's the guy. We told him what he's doing. He's like, yeah, I believe in that. And he was willing to be part of it.
It's pretty cool. Yeah. Or like Zooko Wilcox, you know, the founder of Zcash. Yeah. Right.
And just some, you know, I'm some random guy to him and, and, you know, he's a cryptocurrency, you know, probably millionaire at that point, probably now billionaire, who knows. But, you know, just was willing to sit down and have a chat just because I asked. Yeah. I think the other thing around, you know, being a leader in general is just again, having building the, the confidence of being able to just go out and, and talk to people. Right.
I think before maybe I would have had that barrier in my head, like, oh, I can't go out and reach out to this person. I can't, I can't do this. Just, you know, just for a false barrier that you have just because you think that people aren't open. And now I realize that, hey, just go out and talk to people. They're happy to talk to you.
As a leader, I'd say I also have the flip side of what I talked about where, you know, folks are very accessible and I am very accessible. I try, I think it's a value. And a big part of why I'm so accessible is that I see so much value in everyone in the community and so many cool things people are doing. There's not like a, hey, that person's got a C-level title and this person's got an analyst title. So there's a difference in value.
I don't see that at all. Like there's so many individual contributors on our Slack community who are way smarter than me at so many things. I get a lot of value out of, out of that diversity of thought and relationships. And as a result, I, you know, I ping you back pretty fast on Slack if you reach out because I see so much value there. Yeah.
I also didn't say it specifically, but I agree with your comment at the beginning about relationships. And I have a great example of that. It was just this past week. We have a neighbor in our community and we were hanging out and she said, she asked me some, just some general technology advice. She's like, hey, um, I work at Denver Health and I'm trying to do this thing and I can't do this thing.
And, and it was, uh, it's one of those things where I was like, oh, I could give you advice, but I don't know exactly what the right answer for your organization is going to be. So I said, oh hey, you know what, I know the person in charge of security at Denver Health. Let me connect you to— and I guarantee that he will either have the answer or he can connect you with the right person who has that answer. And he did. You know, I know him.
He— I made an email introduction, and I think that, that she's getting her problem solved and it's helping security as part of that because of just relationships that we have. That's awesome. Yeah. So we, we're going to have to go much faster or we're never going to get through this. So let's, let's pop through these pretty fast here.
How do you think the security industry will have changed at episode number 400 or episode 800? We'll finally have everything on the blockchain, won't we? Everything will be on the blockchain, all controlled by AI. We'll be all good there. We will still not be patching our systems appropriately.
Right. Yeah. So I— so if we're— if we get to 400, if we assume the same pace, that's another 4 years from now. 800, 8, 12 years from now because we got another 8 years after that. Sadly, things in security generally move pretty slowly, at least the big big things.
So my guess, it will be— we'll still be wrestling with the same problems, although it'll be on different technology platforms and things like that. I'm sure we will have made some progress, but I don't know that it's going to look that much different. I don't know if that's a negative opinion, but I think that's probably true. Colorado will have become the number one place for security in the world, undeniably. Well, Of course.
But all right. Next, why do you think Denver is such a magnet for cybersecurity folks and organizations? Yeah, I thought about that quite a bit after seeing this question. Colorado is just a wonderful place to live, right? And it's got this great balance that, you know, balance is probably at risk, but a balance of being relatively affordable compared to the Bay Area at least.
And, you know, New York, D.C. area and this great outdoor life and this amazing culture of people who just love to be here. I think that that brings in interesting people and generally security folks are pretty curious and interesting and it's a pretty good fit. A lot of tech talent with the universities. And frankly, you know, what we're doing with, with this community is just building this, this rumor that Colorado is a pretty good place for security. Yeah.
And I do think it is Colorado or Denver or whatever in general. And it's the quality of people that are here. And many of them just happen to be cybersecurity folks. Yeah. And I think that cybersecurity is growing in general.
And so that ball just keeps rolling. Yeah. Next question. Do you think there will ever be a time when security won't be an issue for organizations, meaning we'd figured it out and there's no more vulnerabilities to exploit? No, I think, you know, we still have security guards at banks.
You know, we still have police officers. There's always going to be someone that is trying to get around the system, break laws, other things like that. If there is— if there's money to be made, there's going to be a criminal that's going to try and make that money, which is where, you know, behind a lot of cybercrime these days. Right. So I think that it won't ever go away.
It'll likely change and be different, but I don't think it'll ever go away. Yeah, I agree. It's not going to go away. And my first thought is, well, if you create fully secure libraries, you can get rid of— you can get rid of cross-site scripting and things. But, but You know, once you just put on your hat as a malicious insider, well, that person can, can write business logic flaws that allow them to manipulate the system and steal things.
You know, the, the Superman II attack, right? So no, security is never going away. And of course, compliance and privacy are only getting bigger. So that element of what we do and risk management, they're only going to get bigger. So no, it's never going away.
Maybe certain parts of it will, but as a function, we're going to be here for a long, long time. Yeah. All right. Um, I'm gonna skip the next question and jump to some, some general fun podcast questions. Uh, this kind of goes back to the original when we started, how many episodes did we envision doing?
I think that we, I think if you'd asked me at the time, I, I would've said 100, which sounds, sounds like a lot. Yeah. That's looking 2 years in the future. That sounded like a lot. I didn't, I didn't expect to get to 200, I don't think.
Yeah. If people haven't figured this out about us yet, um, As we've been doing these things, we haven't been planning too far into the future, right? It's, hey, let's do this thing now and see how it goes. Yeah. You know, I don't know if that's the, you know, fail quickly and move on kind of thing.
But, you know, we've set a fairly short horizon and then, you know, kept going from there. Yeah. Good stuff. What made us do a podcast and how did we decide on the format? So I think going back to some of the original comments that we made at the beginning of this, You know, we were trying to, to do something to help amplify the mission, but that wasn't going on with anyone else, right?
We weren't trying to create another meetup. We weren't trying to do other things like that. But, you know, how is it that we could reach a lot of people and still do that, that amplification? And, you know, we came up with podcasts, I think at the time, not that there weren't podcasts, but not long after we started our podcast, I think podcasts kind of exploded and there were lots and lots and lots of podcasts, casts. But at the time it was, it was still a much less common thing.
Yeah, I think our market is very narrow, right? It's very specific. You got to be a security person in Colorado to be interested. And, and what's a good way to get those folks? Well, there's a few ways you can get them.
You meet with them in person, but that's saturated market. But there's this whole podcast thing no one's doing. Yeah. And I remember sitting with a whiteboard and maybe some virtual whiteboarding as well. Say, well, what are the things that are a part of this?
Well, it's the local groups, it's the local meetups, it's the, it's the local companies, it's the jobs. You know, we just put together these things. We're like, well, how do we talk about those? Let's, let's do a newscast every week where we just highlight those. And then, you know, to the point about we wanted to, we wanted to amplify cool things happening in the community.
Well, that's where interviews came in. There's just so many interesting people in the community and you and I have, Alex, have met with Hundreds of them at this point. And, and getting to let them tell their stories, man, that's just been a neat part of this whole thing. Yeah. And you said people.
I mean, people is the key part right there, right? It's people make up the community and getting with those people is really how you, you continue to build that community. All right. Any challenges kicking off things that you didn't think of when we started? And any big challenges we ran into?
Well, I don't know if it was that we didn't think about, but we just— we didn't know, right? Yeah, we didn't know any of it. Yeah, we didn't know anything. We didn't know how to record a podcast. We didn't know how to publish a podcast.
We didn't know how to edit a podcast. How many different mics have I bought and thrown away? We've gone through a lot of mics. I've probably spent $1,000 on mics that I don't use. So I think the, the first interview that we did outside of us talking to each other was with Brian Beyer.
And that was— we didn't air that one first, but I think we did that one. Remember we had Drew Labo on right off the bat? Yeah. Well, and that— right. And that— so the Brian Behrendt one was, I think, the first one where we went out and met with someone to do an interview separately.
And we used the same setup that we have right now in the studio. And not that it's a gigantic setup, but there are— there's 2 mics and a mixer and other stuff like this. And I brought this big, like, shopping bag to the Red Canary headquarters at the time. And we had to, you know, we spent 15 minutes setting this all up. Right.
You know, I was sort of there as the audio engineer and Robb was doing the interview. Um, I really didn't think about how, how this was going to work about going to meet people with all this equipment. And, uh, you know, we figured out along the way some better ways to do that. So that was, that was something that we definitely learned. Yeah.
At this point I use lapel mics plugged into the USB port on my computer and they cost $10 apiece and they work. They sound much better than, than the big tabletop mics. I think that's another thing too, is we haven't aimed for perfect audio quality. Yeah, it's more about content. Not, not that the audio quality is awful or anything like that, but it's— we're not, you know, spending thousands of dollars on high-end audio and things like that.
Well, I think the point of that is we're not spending hundreds of hours fixing it, figuring it out either. Like, we're both busy people with families and jobs, and, and we have to figure out a way to do this in a reasonable amount of time. And if there's some lingering technical questions we don't figure out. That's just how it is. But we're getting, we're getting them out every week and I know I can hear it when I, when I'm in my car.
Yeah. So next question. What was the most funny or unexpected response to an interview question? Yeah, I don't know if I have anything extremely funny to talk about, but I would say that the most strange and interesting interview that I did was, you know, I mentioned it earlier with Zuko Wilcox. Um, this is like a, an eccentric individual.
Um, you know, he is a, a weird kind of guy and, and I don't mean weird in a bad way. Um, and, uh, you know, just talking to him, um, also very, uh, brilliant guy, you know, very secretive too, right? Very secretive. And so just talking to him and, and you could see like the gears moving in his head as I was talking to him. Uh, that, that was probably the most strange and interesting interview that I did.
Yeah. So I don't have any, any funny ones I can remember right off the top of my head, but you know, speaking of like favorite interviews, I have a couple I'll call out. Number one, I got the chance to interview Cal Fussman, um, who's relatively famous these days. If you Google him, you're going to see him all over the place. And he, we had him come talk at RMISC as a keynote and I got to know him and become friends through that process.
Uh, and hearing his stories, I mean, he's just such an amazing storyteller. That was really neat. And then, and then I got the chance to interview Patrick Quinlan. And this has been 3 years ago probably now, who is one of the co-founders and CEO over at Conversant. And the story he tells about his appreciation for freedom and how his, his life has been about trying to reinforce freedom and make sure people, you know, freedom is, is protected has been— it's just so impactful for me.
He tells a story growing up in West Germany. And, um, he would go to West Berlin and, and I did not realize at the time that West Berlin is not in West Germany, that like the Berlin Wall wasn't between East and West Germany, that Berlin was actually fully inside of East Germany. And the way you would get from West Germany to West Berlin was on a train. I think they called it the Freedom Train, but I don't remember that. And he would tell the story about going from home to West Berlin and seeing the difference of what freedom looks like where he's from and what oppression looks like where he was going through and the people who were desperately trying to get into the, you know, to the free area.
Just, I think, set a vision in his mind of the difference between these two that we don't get growing up in the United States where, you know, where our, our level of injustice is just, it's just not at that same level. And I appreciated his perspective and it was very visceral for me. And probably worth going and relistening to that interview back from the early days. Yeah, good one. Uh, all right, uh, next question.
Were there any interviews that were never released and/or funny stories about them? Yeah, we got a few things we could talk about here. Uh, number one, we've had what, 2 or 3 times where we've done an entire newscast and then at the end realized, yeah, oh, we're not recording, or something crashes or whatever, and I think for 200 episodes, that's a pretty good percentage of things going wrong. And I'm checking to make sure that's not happening right now. It's not.
It's not happening right now. So those are— I tell you, it's a little disheartening to do a second take of an entire newscast. Yeah. And it is funny to me when we tell the same jokes. Like, I already told this joke.
Hahaha. That was a good one, Robb. Hahaha. So that's one kind of funny-ish thing. And then I just recently had this, it's like a marketing or PR person reach out to me for, I'm not going to say the name of the site because I don't need to give them any free marketing.
But they said, hey, we'd really like to have our president on your show. And he has a lot of information about cybersecurity jobs. And I'm like, oh, well, you know, we're not a national show. We'd like to get like Colorado-specific data. Could he come talk about Colorado-specific um, cybersecurity salaries and trends.
And that'd be interesting to my audience. And they're like, oh yeah, we've got that data. He's ready to do it. He gets on the show, I'm recording. I'm like, all right, let's go.
And I'm like, he's, he starts off with like some national information and I'm like, oh, that's great national information. You know, could you give me some deep dive on the Colorado stuff? And he's like, I don't have, I don't have any Colorado data. And I'm like, well, well, you know, can you give me some trends about Colorado? He's like, you know, really we're national.
We're mostly focused in DC. I could tell you about some DC stuff. And, And, and, you know, obviously I got sold a bill of goods and I stopped the interview and said, hey, nice to meet you. Uh, we're not gonna run this interview. Yeah.
Uh, I think another one is, uh, early on we recorded, um, an interview, uh, with the host of a, of a different security podcast that's out of Colorado Springs. And I mean, this was also really early on. Yeah. It was like first couple months. Yeah.
Yeah. First couple months. And We didn't know what to expect. We didn't know him. I don't think we'd listened to his podcast before.
Yeah. But, you know, he billed it to us as, I'm this gigantic, gigantic podcast and I have a ton of listeners. And, and we did the interview and I don't know, it just was not very good. Was not a good interview. You know, the, the questions weren't great and the flow was not good.
Also, I mean, it was the 3 of us and I think, you know, you lose some things when it's just not a one-on-one conversation. And he actually took the interview, I believe, and published it on his podcast. And the idea was we were going to also publish it on our podcast. And, you know, we kind of sat on it for a little while. And we're like, oh, we have this other interview, we have this other interview.
And then eventually it just kind of faded away. And yeah, we never published it. We never, we never read that interview. Yeah. Yeah.
All right. Do you ever go back and listen to your own interviews that you've conducted? You know, I do sometimes. Often it will be you know, the beginning part of the interview once the episode is published, mostly just to listen to audio and how do things sound and stuff like that. But I don't very often listen to the full interview again.
Yeah, I never listen to my interviews. I do occasionally listen to our newscast just to see, you know, does it sound like I think it sounds right? And I don't, I don't usually listen to the whole thing, but I'll always listen to the other interviews. So if you do an interview or, or Jason or Janelle, anyone else does interview, I listen to that whole thing and I really appreciate the I feel like I'm there. It's great.
Yeah, I do have to say, early on, I listened to every episode every week, even if it was my interview. I think just sort of as a solidarity, solidarity to us that I wanted to listen for the whole interview. But I definitely don't do that anymore. Have we ever thought about turning Colorado Equal Security into a video podcast? I mean, we have talked about should we publish to YouTube, which is a video platform.
But I don't think we have any intention of doing a video podcast. Um, no one wants to see us. Uh, I also don't think it really adds much to the conversation. Um, that there's, there's nothing really to see. I think part of it is everything that we create, I am the market for.
Like, I'm, I'm always like, would I like this? I'm always asking myself that question. And I have never had any interest in a video podcast. Occasionally some of the podcasts I've listened to do video streams and I always find it annoying because Like it's just not quite what I'm looking for. I want the audio only.
And mostly I listen to podcasts while I'm driving. So not something we're interested in, but we have been trying to figure out how to get it. Well, 3, 4 years ago, I tried to figure out how to get this thing to get onto YouTube, um, as just audio, maybe with like our logo over it as the video. And, and I failed. And, you know, like we said earlier, didn't put in the hours to figure it out.
Yep. Uh, any regrets about the initial scope of the podcast? As an example, why didn't we do, you know, US equals security or the Earth equals security? Yeah, that's a great question. I feel like we might have missed out on the solar system.
You know, the solar system equals security or something like that. Now, obviously, we are super focused on Colorado as a state. You know, we have probably been more focused on Denver than I would like. And just because we live here, right, that's where our relationships are. But we've been very intentional about including Colorado Springs in And the events and jobs.
And, you know, we've had the Colorado Springs ISSA leadership on the podcast a couple of different times for interviews. And, you know, Fort Collins has become a focus as we've got the Northern Colorado ISSA. We love focusing on Colorado more broadly. There's just— we're not aware of a lot going outside of Denver itself. Yeah, I think the other thing is when we started, there were a number of other sort of general security podcasts that weren't focused on a particular area.
And kind of back to the mission. We didn't really need to focus on something that was already out there, right? If there's somebody that's covering general security stuff as part of their podcast, great. Let them do that. That's what they're good at.
We want to help amplify Colorado, and that's why we chose this. And remember, we're not, we're not making any money on this. And, you know, there's no questions about this, but like, we don't, we don't have advertisers here. You've never heard a commercial on this thing, right? It's just us.
I guess that's not true. There is a commercial. Embedded in this, uh, in the show notes. So we got, um, you know, if you, at the beginning and the end, you have someone reading the intros and the exits. And it's actually interesting.
I don't know if you even know this, Alex, the guy who does it was a like college friend of mine who lives in the Springs. And I saw on Facebook, he does some voice work and I'm like, oh, you want to do this? And he's like, yeah, I'll do that for you. It'll cost $150. Or if you put my name in, in your, in your show notes, I'll do it for $75.
I'm like, ugh, Yeah, save us $75. So his name's in every show notes. I think the only other thing is we have the music that we use as part of the intro and exit is it's free, but you have to include essentially the equivalent of the GPL. Yeah. In the show notes.
Right. So we do have some, some notes about who it is that the band is that plays that music that we found for free on the internet. Yeah. So, so anyway, my point about that was we're not trying to get the biggest market we can so we can get more ad revenue. Right.
This is, this is just about serving our community. Yep. Any wish list or high-profile individuals you'd like to have on the podcast? You know, we've mostly got everyone who we've really wanted on the podcast. We never successfully got Dan— oh man, the CEO of Optiv who's now retired.
Oh yeah. That I can't remember his name off top of my head. Dan. Dan, the CEO. Yeah.
We never got him on the show. We several times almost had him on the show. That might be the one miss we had, but there are some folks outside of security who I'd love to have on the show. You know, the governor, Polis, one of our senators, that'd be really nice folks to get on the show. Maybe Debbi, if you want to help us set that up, we'd love to do that.
Yeah. And I think, as we noted earlier, just about everyone that we've asked has said yes. So it's really just our imagination, essentially, that has limited that. Let's throw that back out to the community. If there's someone you'd like us to have on, reach out, let us know.
Yep. What have you learned about yourselves in doing the podcast?
I never really thought of myself as, as someone who, I don't know, I don't wanna say enjoyed, you know, talking to other people. Yeah. I mean, I like interacting with people, but it was never really in my head like, ooh, I really like talking to people and learning about them. And I think that's really highlighted it for me. And it's a lot of fun to do that.
Yeah, it's, it's neat to, to see the doors that open up through this. You know, I occasionally get access to things as a member of the, the media, whatever that means. Right. It's kind of neat. We'll occasionally get like early release information from one of the local security companies and, you know, when conferences used to happen, could get into places maybe I couldn't otherwise, you know, learn.
But learning about myself, I don't know. I, not really. It's been, uh, it's been a lot, an awful fun thing making relationships though. All right. Um, we have a few other miscellaneous questions, Robb.
How are we doing on time? Do we want to, uh, um, ask a couple of these? We say we've got 5 minutes left. Why don't we say that? All right.
Uh, you want to pick one question out of that, that last list? Yeah, let's do that. All right. I got, I got one from the list here. What's one thing that you would change from your career if you could?
So, uh, the beginning of my career, I spent 10 years at IBM and subsequently 4 years at AT&T. Um, I can, just because of the way it happened, I can bunch those kinds of things together. We'll call it 14 years at the same company. Um, and now I've realized, uh, moving on from that, that I probably should have made a change sooner. Um, not, not that I didn't enjoy my time there, Not that I didn't learn a lot, but I think seeing different companies and doing things at different companies has helped give me different experiences and allowed me to grow more and faster.
Not that I'm encouraging people necessarily to leave your company just to leave your company, but I think you often have better opportunities by not just changing jobs but changing the companies where you're doing that job. So I'd say if I would have realized what, what I should be doing and left and gone somewhere else a little bit earlier, it would have been good. That's a good one. You know, I'm going to cheat a little bit and say I don't think I would actually change anything in my career because I'm so happy with the way things have developed. But I think if I look back and say what's an opportunity that I, that I probably should have jumped on early on in 2000, Uh, really early 2000s, 2002, something like that.
I had the opportunity to become a consultant, um, and, and serve lots of different companies versus doing internal IT and security for a company. And I did not take that opportunity. And I think that the consulting experience is just so incredibly valuable, especially if you can get with a big firm that, that will support you and, and give you that different exposure that you don't get in one place. Um, I, I think that that would be a level of experience that's just really valuable in my career. Yeah, it can be tough work, but I think it could give you a lot of great experience for sure.
It is definitely a grind and maybe not the thing you want to do when you're hoping to have kids, right? The timing on that may or may not have worked out, but that's something I think is, you know, if I'm engineering a career path for someone who wants to get into security, I definitely recommend, see if you can't land as a consultant for one of the big consulting firms for, I don't know, 3 years and get that experience under your belt and then go internally. And I think you just have such a great breadth of experience to bring to that. Yeah. All right.
Last question. Who do you admire or look up to in the industry? Yeah, this is a tough question for me. There's, there isn't, you know, because everyone's pretty humanized, there's no one who I see without their flaws and their strengths. And I think that it's, it's important to acknowledge both.
I, I have a— there's a lot of folks who I think— I'm just gonna keep my question, my answers to Colorado because I think I want to amplify the awesome stuff happening here. Um, and there's a lot of really cool people here in town. You know, I think Chris Nickerson is such a passionate person who helps make the security better. And I love how genuine he is. And he's been successful with, with his, uh, his unique brand.
Um, I'm, I'm envious and admire his, his ability to do that and kind of do it his own way. I think that's awesome. I think Jericho, Brian Martin, who we've had on the show, it's been years since we've had him, another guy who's successful in his way. And, and man, he's invested so much in, you know, calling things as they are. And I really appreciate his candor.
But I go to the other side of like, hey, those guys are kind of on their own. Maybe the, the less PG version, right? The not G version. Go to— I don't know if you know. I know you do.
Brent Phillips, who's the— oh yeah, he actually was the CISO for Aegon, which is the parent company, Transamerica. He's just recently moved into a new thing. Maybe the nicest of the security leaders at, and like a powerhouse security leader, right? I don't know, top 100 companies in the world, top 50 companies in the world, whatever it is, but just so genuinely nice. And he actually, if you remember, he came to an event we were working on and he helped pack giveaway bags for people.
He got there early to help stuff bags and like, you know, just not what you expect from a guy who I assume can buy and sell me and my whole family, uh, just for the fun of it. Yeah. And I, I'm gonna have a similar answer and go a little bit more generally too. Um, you know, for me, the, the things that I admire about people in general or looked up to is, is people that are willing to give of themselves, right? Um, you see them, and this could be in the, the larger security community or, uh, here locally, it's Um, you are, you're doing things to advance the community.
Not, uh, not that it can't advance you too, but like your primary motivation is to advance the community and, and security in general. Maybe that helps you. Maybe it doesn't. But you know, you also can see the people that all, you can call a little more fake or whatever that are, they're out there doing things, but you can tell there's, there's a motive for them to either, either financial or personal other kinds of personal gain or things like that. So, I mean, I admire the people that are willing to just to give their time to make things better.
You know, some local people that are, you know, doing things like that in general, we have so many people in the community that work for government, nonprofits, other things like that. You know, some people that come to mind, Benjamin Edelen in Boulder, Debbi, obviously at the state, you know, lots of people that are— that know they're making less money than they could in the private sector, but, you know, really believe in that kind of mission of giving and trying to make things better and are doing a great job doing it. So that's definitely people that I admire a lot. There's a lot of great stuff going on here. I think, you know, that's one exciting thing that I see for the future of this is going and finding more and more of those stories that are worth telling here and, and being able to share them with the rest of the community.
Yeah. All right, well, that's it for stories. I think we're, we're done. We're done for the week. 200 in the books.
So we're, we're done? The podcast is over? We don't have to do any more of this? We're done. We're done.
As, as at least for, at least for a week. At least for a week. Uh, we, uh, we are not going to have this out by noon on Sunday. I just looked at the clock. It's going to be close.
It's going to be close. It's not going to be close. All right, I don't think anybody's going to make it is gonna notice. Going back to some of the earlier discussions, that was one thing that was a goal for us too. It's like, all right, we have to have the podcast done and published by noon on Sunday every week so you can expect it to be there.
And then occasionally I hit to hit— I forget to hit publish when we're done. Occasionally the show notes don't come out for a week on accident. Oops. These things happen. All right, well, that's it.
We'll look forward to talking to everyone next week and we'll do another 100 of these. Robb, congrats on 200 episodes. This has been a lot of fun. It's been a good time. Thanks.
All right. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security. Security.