All episodes

Chris Nickerson of LARES (Part Deux)

Apple Podcasts Spotify SoundCloud

Chris Nickerson, founder and CEO of LARES Consulting is our feature guest this week and is interviewed by Jason Jaques. News from Molson Coors, Carvana, ULA, DISH, Red Canary, Ping Identity, LogRhythm, Convercent and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13893 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 202, uh, for the week of March 15th, uh, 2021. Alex, how are you doing this week?

Well, you know, Robb, we are right in the middle of Snowmageddon 2021, so I'm hunkered down at home and, uh, still waiting for the snow. Yeah, I hope this isn't the middle because it's so far been a pretty big disappointment. There is a lot of snow falling out of the sky, but when I look to the ground, there's no real evidence of it, or very little, right? And I'm sure that there are other places, slightly higher altitudes maybe, where it is actually sticking and they probably have a decent amount of snow, but Right now, for, uh, it sounds like for you and for me too, it's, it's not really much different than rain. And we're, uh, Saturday afternoon right now.

So maybe tonight when the temperature drops, maybe we'll start to see some, some actual accumulation. Uh, maybe we'll get a couple of feet. I'm still rooting for, I'm still rooting for 4 feet. Like, let's just blow this thing out and have some fun with it. But I'm, you know, I'm personally still rooting for 23.3 inches.

That's just me. Alex says that's Alex's number in the pool. There you go. All right, uh, let's jump over and do some, uh, some housekeeping. You know, I'll do a couple reminders.

We have a Slack channel. This is a great place for you to go, uh, connect with the Colorado security community and, uh, get to meet over 1,800 of your closest Colorado security friends. You can get the link to join the Slack community on the website colorado-security.com. And while you're there, once you go ahead and scroll down to the bottom, put your email address in for our mailing list, and you'll get the show notes delivered to you once a week in a completely different place. Wherever you get your podcasts from, whether that's, uh, Apple Podcasts or Stitcher or Spotify or Google Play or anything else, uh, make sure you subscribe to get this automatically delivered to your player every week.

And also, we would love if you rated us, uh, just so everyone knows how great the podcast is. And, uh, you know, maybe it'll do things like push us up a list or something like that. Ooh, up a list. That sounds exciting. Yeah.

Hey, speaking of things they can do for us, why don't you tell a friend? You know, help the community grow. You know, we are just doing this because we want to build the community, and hopefully you're in the same place. You want to help get the Colorado security community to be the best in the world. One way you can do that is by letting other folks know about the podcast.

Let's grow the influence here and help keep moving things forward. If you want to help even more, more tangibly, uh, you could join our Patreon campaign. That's a way you can financially support the show and help defray the cost that we, uh, we get for doing this stuff. Good times. All right, uh, let's jump into the news, Robb.

Uh, trouble is brewing. Molson Coors— you definitely could have written this headline. Yeah, I think we could have. Uh, Molson Coors is in the, uh, the midst of a cyber incident, uh, that is causing problems with their operations. So Not going to get any new beer, it sounds like, from them until they get this resolved.

Yeah, we, you know, we have known the last couple of CISOs over there. I don't know who the current one is. I know that when the headquarters moved to Chicago, that the CISO who was here in Denver, Glenn, he ended up choosing not to go along with the company. And before him, of course, Christine Vanderpool, both local folks here. I don't know who's doing it now, but I'm guessing they're having a pretty rough week.

Certainly have them in our thoughts and hoping that they can recover quickly and get those Coors Lights and Miller Lights back into the market. Yeah, I mean, and to be fair, there's not a whole lot of detail on exactly what's going on other than, uh, there is an incident and it's affecting their production. Um, there's some speculation that it was ransomware, but, uh, no details exactly on that. So hopefully it does get resolved quickly and more beer for everybody. Scuttlebutt.

It's scuttlebutt that it's— it is scuttlebutt. That's, that's the word I prefer. Speaking of, anyone knows Yeah. Hey, um, you know, we— this is just a small update on a story we talked about a few other times. The car vending machine that, that Carvana is, is proposing to bring to Denver, uh, a vote for the rezoning that's required to do that came before the, uh, the city council, the Denver City Council, this last week, and they approved the decision.

Yeah, the, uh, the wheels of government spin slowly, and, uh, 2 months ago or whenever it was when we talked about the, the preliminary hearing for getting this approved, uh, now we are finally to the approval part. Uh, it was approved. Um, looks like they're going to be building this car vending machine. No details on when exactly that's going to start, but it sounds like everything is clear for them to go ahead now. So we will continue bringing you this story because we think a car vending machine is kind of fun and, uh, has nothing to do with technology, but it is a fun story.

I really want to find somebody who's going to buy from the car vending machine, and then, you know, maybe we can go watch or something like that. But how do returns work? Can I buy a car and just return it? Do you have to like put it back in the vending machine? Is it like when something comes out of a normal vending machine and, you know, maybe it gets stuck, you can stick your hand in there and maybe get it loose?

You could put the car back in through— I mean, I know hackers who have— and when I say hackers, I mean like 12-year-olds who figured out how to get multiple things out of vending machines pretty effectively. I would imagine that, you know, that same skill set could get you a free car here. And tend to life in prison, maybe, I don't know. Yeah, you never know. Hey, look, moving forward, we have another local news here.

This is around the outer space world though. It's about travel, but a different kind of vehicle. The Space Force, which, you know, their headquarters isn't here in Colorado, but we still have a lot of companies supporting that industry. They have chosen ULA, the United Launch Alliance, for $224 million in launch missions here in the next few years. This is not one specific mission, it's a series of missions.

Uh, and, and the, the business was split between ULA and, and SpaceX. Um, there was a total of 385, so ULA got most of it. Uh, so a lot of that money is going to stay here in Colorado. Yeah, I mean, it is obviously too bad that Space Force left. This could have been a double Colorado story.

Um, but, you know, one-piece Colorado is still good. And, uh, you know, $224 million, that's not chump change. So good stuff there. And, you know, they were In the article, they talked a little bit about how they can't talk about what these missions are because they, they look like they're probably, uh, military slash intelligence in nature, right? So we won't know what they're doing, and if we do know, they'll have to kill us.

And no one needs to die on this podcast, so, uh, we'll just have to, to guess. All right, uh, next story. Um, I think everybody knows that through the pandemic, there were all these— and I guess even maybe a little before it, there was reports of tech companies leaving Silicon Valley because it's so expensive and crowded and everything else to go other places. But this article says those reports are greatly exaggerated. Yeah, I'm not sure that the headline's quite right either, because what this report's getting into is the fact that a very small number of startups left.

They basically say 96.9% of startups did not leave the Bay Area. So call that 3% that did leave. But what I think is the story here is some really big tech companies did choose to leave California. Oracle, I mean, one of the biggest, and all of Elon Musk's companies, and HP is another one. None of those would be considered startups in my mind.

So this isn't about what percentage of 5-person tech companies stayed around, it's how much power left California. So I actually think there's a little bit missed here, but it's still interesting either way. I think the other part is, in my opinion, it's less about the number of companies that left, but about people. So you can keep your mailing address and your official headquarters in the Bay Area, but if 95% of the people for your company are now located other places, I mean, that seems like a big deal to me too. And this doesn't address that either.

Yeah, so I mean, actually, the main part of the story that makes it interesting to us though is, you know, the narrative was, hey, all these companies are leaving the Bay Area and going to Austin, to Texas. Um, well, the data from this particular study came out and said not only is it, you know, only 3% of companies left, of those that did leave, Austin was not the city with the biggest growth. And surprise, surprise, drum roll please, uh, number 1 was Denver, Colorado, with 21% growth of these startups. Yeah, and I guess the other part is, uh, what is the total number that makes up that 100% of startups? And then the, you know, the 3.1%, uh, you know, how many actual companies is that?

And, you know, for us, 21% growth, is that, uh, is that 3 companies? Is that 30 companies? Is it 300 companies? Anyway, this sounds like real journalism you're talking about here, Alex, and I'm not sure you've come to the right place for that. Yeah, yeah, I think you're probably right.

You're probably right. But anyway, good news is we got more startups. There was one other little factoid thrown in here that I found interesting. The survey found that venture capital investment was actually up in 2020, even with the pandemic, from 2019 numbers, it was up 4%. So the pandemic did not slow that new capital coming in.

And I think it just goes more to this kind of crazy world we live in where the markets, whether that's the stock market or the venture capital market, equity markets, just do not align with the experience of many people. It's a problem. It's a problem that hopefully we're able to figure out because I think that the more bifurcation we get there, the more pain we're going to be feeling. Funding was up 4%. I would bet for security companies and their funding, it was probably even more than 4%.

It seems like all kinds of security companies are getting money and lots of it and crazy valuations. We were talking about that the other day. So yeah, all right, uh, next, uh, we have a story about Dish Network, um, and this is not on the TV side, this is on the wireless side. They have acquired another retail wireless brand, uh, Republic Wireless. And so this adds to their portfolio of brands that they are putting together to, uh, build out their 5G network.

Yeah, this one's interesting to me because it doesn't really— it doesn't feel like it's actually about building out the 5G network. It feels like it's just about getting subscribers. It's because Republic Wireless actually just operates on the T-Mobile network. So they're not actually getting any new network, they're just getting subscribers. Sure.

Which, which I assume what, you know, what they would plan to do is make sure they offer those folks what, you know, the, the right kind of, um, incentives to move them over to Dish's new 5G when it's ready. And, you know, that 200,000 customers they have is, you know, a significant number and probably just a way for them to build that business going forward. Anyway, I found it interesting that they wasn't actually getting any more network itself. Yeah. Well, I don't even think it's incentives, Robb, because since they essentially control on the backend what these people connect to, Republic, it does run on the T-Mobile network now, but it's not like their members have to sign up for T-Mobile.

That's all handled by Republic. So at some point, I'm sure Republic will just switch over and be on the Dish Network network. Whenever that is available. Nice. So buying customers.

I like it. All right, moving forward, uh, we're moving over to the security side of things. We have a blog post this week from Red Canary, uh, and this is diving into, uh, it's an article by a few of their folks, um, really diving into the details of the Exchange attack. You know, obviously one of the biggest pieces of news we've had in the last couple of weeks, these zero days within Exchange, uh, and, and this team just going into what are you going to do if you were popped as a part of this? Yeah, I think, uh, one of the interesting things in the article too was, you know, we've heard the initial report from Microsoft about the, the group that they called Hafnium, uh, but part of this blog talks about that there were multiple groups, uh, that were— some of them maybe coordinated, some of them separate, uh, some of them that are sort of unattributed still, um, but there was a lot of activity that was going around, uh, on the Exchange attacks.

I think also At the end of this article, there are a bunch of links which are all really good to other articles that have specific details on some of those groups and other specific things about the exchange attacks. Yeah, I, I found this particular attack interesting because it is one of the biggest attacks. I mean, just like in terms of sheer impact, it's one of the biggest we've ever been through in our careers, and it has been like almost not at all on my radar. Because I just, I don't run Exchange, right? And, you know, once you get out of the business of administering your own Exchange server and your own OWA server, like, this is somebody else's problem.

And it's just been interesting to me to see that shift of, you know, moving that critical business process out of my environment. I would have spent the last, whatever it's been, week plus fully immersed in this usually, and now I'm, you know, I'm making myself read the articles so I can stay relevant. It's an interesting process. Yeah, and I think it is an interesting use case in moving to the cloud or not, right? So you have some people that still want to run their own Exchange servers for one reason or another, whether it's more control or flexibility or, you know, just legacy infrastructure, whatever it might be.

And in this case, you know, the Office 365 side, which is essentially, you know, Microsoft running their own Exchange servers, was not affected at all by this. So if you had moved your, your operations to Office 365, you would have been fine. But, you know, running your own Exchange servers, now you got to go through a whole lot of stuff to patch and make sure you weren't compromised and all that kind of thing too. So yeah, it is interesting because this is the second time in the last few months that, you know, that Microsoft has had their software impacted, you know, between this and AD FS through the SolarWinds stuff. Um, while there's— while their SaaS environments were Um, we're kind of— we're safe.

Um, and that's— I think that's, you know, probably, uh, showing us the way the world's going. And that, you know, Microsoft probably does a good job running those things on-prem, but it— but it's an interesting situation for them to be in. Yeah, I mean, and with the scale that they have, I'm sure that they can, uh, make changes and updates, um, you know, faster than any of us. And obviously when they get the, the vulnerability reports, they're going to know it before we are. So, you know, everything on their side is going to be fixed even before the patches come out.

So good stuff. Right, next we have a Ping Identity blog talking about some new offerings that Ping Identity has in the AWS Marketplace. Robb, what's that all about? Yeah, I mean, these are not actually new offerings in and of themselves, they're just new to the AWS Marketplace. Ping has had these customer identity and workforce identity solutions available for quite a while, a couple of years internally, But, you know, the expansion into AWS just opens it, makes it easier for organizations where if that's the way you buy, now Ping is selling it that way.

Pretty cool. Glad that there are Ping offerings in AWS, make it easy and hopefully more adoption. Yeah, I think, you know, becoming more developer-friendly is certainly a key part of being the IDaaS of the future. It is amazing to me how much things have changed I think a lot specifically through AWS where, you know, essentially now your, your developers or whoever else are in charge of buying all of the things. It's just through the AWS Marketplace instead of now through, um, you know, whatever IT team or, um, you know, procurement or however else it was coming before.

Yeah. All right, moving along. We have a blog post this week from LogRhythm, uh, titled What is SIEM and How Does It Work? Uh, you know, obviously LogRhythm knows a little bit about what a SIEM is and how it works, and this article is, is focusing on, uh, really breaking it down into the component elements of what a SIEM is. They say that the legacy SIEM technologies are this combination of log management, security information, and event management, and kind of combining those.

And then they go into what is a next-gen SIEM and how has that evolved past what the legacy SIEMs were. Yeah, and, you know, some of those things talking about using big data and visualization, user and entity behavior analytics, and of course the automation piece, right? So I think just about all of the, the new modern SIEM solutions have some sort of SOAR or automation pieces built into them. So if you didn't know what a SIEM was already, or you wanted to give a good article for someone to understand what they are, this is a pretty good one. Yeah, I think that, you know, we do have a lot of people listening who do things like the SecureSet boot camp and other, other, you know, entry-level folks to security.

This is a really nice way to figure out where a SIEM fits the bill. And I actually have an employee who I'm going to send this to, to get them up to speed on it as well. One thing that the article does not address is what is the correct pronunciation? Is it sim or sem? I hear it both ways.

Yeah, it's sim. That's what I agree to. But you know, with the I and the E, and you know, it just gets confusing. Just like it's GIF. It's not jif.

Get that out of the way. Gift peanut butter. That's smooth. All right, uh, all right, last article for this week. Uh, we have a blog from Conversant this week talking about third-party risk metrics.

I thought this was interesting. Uh, Robb, you found this one, um, a little bit different in that, um, I don't think that they're talking exactly the third-party metrics that we might think about, but, um, I think it, it's pretty close. Yeah, you know, when I read through it, so just You know, for context for people, Convergent, they're not a security compliance. They're really more about like HR compliance, you know, whistleblower, you know, ethical behavior in your organization. And when they talk about compliance from third parties, they're probably thinking about it more from that lens.

But when you read this article, I don't even know that you'd know that. Like the way they talk about risk, it could totally be written about the way we think of risk within security and the practices they have within that business, the transparency, the relationship management, ongoing, uh, review of those relationships. It's just exactly the words that we use internally. And, um, it was kind of cool to see that, that different perspective on the same problem. Yeah, I mean, there were a couple terms in here that, um, maybe you could swap out, or, um, maybe a question or two that you could have, uh, added a couple different words to to make it more, uh, security compliance related.

But, uh, yeah, I mean, I agree overall that the process that they talk about is, you know, pretty similar to the process that we use around monitoring of third parties. And it got me thinking that, you know, there probably are more efficiencies between that, that function that, you know, this, this general compliance function and what we do in GRC than we probably take, take advantage of in most companies. And the better we can do that, you know, they think the, the better integrated security is going to be. So I'm, I'm excited to see what I can take back from this myself. I'm excited to hear about it.

Hey, we're at the end of news. You know, we've, we've done a thing on here in the past where we've talked about people moving and, you know, I'm going to take a moment here and just give the announcement that I gave in the Slack community and you've known for a little bit. You know, I'm going to be moving on from Ping at the early April. Gave my notice a few weeks back and I'm just, you know, just number one, say Ping is amazing and me leaving has no reflection on what a great company that is. And it's just been an amazing 5+ years that I've been there.

I'm ready to take a little bit of a break, look for kind of a sabbatical here over the next few months as my kids get out of school and, you know, figure out whatever comes next after that. But, uh, anyway, I want to let people know since we talk a lot about Ping and I talk a lot about the jobs I'm hiring for on here, so you'll, you'll see me stop talking about those jobs here pretty soon. But, but, um, uh, anyway, just wanted to give everyone some, some news since I— there's probably a few people who listen who are not also in the Slack community. Well, congrats, Robb. Uh, it's been a good run, uh, well-deserved break.

So, so enjoy your time off. And, uh, I guess that also means we're not gonna have to blackball any of the Ping blogs or any of the other things that we talk about in here? No, they— I— we don't have to blackball them for firing me or anything like that. That— and if someone does fire me, they're totally off the show forever after. So let's get that out there in the open.

Now, uh, obviously very amicable leaving. I'm, I'm excited to— I mean, I love the team, I love the people there, and, uh, we'll of course keep talking about the good stuff they're doing at Ping. Yeah, congrats, good run. All right, uh, let's move over to the Slack message of the week. Thanks to Andre Gaeta for sponsoring the Slack Messenger of the Week continually from the beginning and in perpetuity.

You know, he does this out with his own money and he pays for one item out of the Colorado Equal Security store for someone that, that says something on Slack that, that we want to recognize, whether that's witty or insightful or silly or whatever it might be. And the winner this week Uh, is Mike Benjamin. Uh, congratulations, Mike. Um, he posted earlier in the week, uh, since we were talking about the Exchange vulnerability, uh, you know, uh, Mike works for Lumen, and I couldn't tell if this was actually data that came from Lumen or sort of a personal project, but he had a compiled list of all of the compromised Exchange servers that, that they were able to, uh, to figure out that they were compromised based on the traffic patterns. And, uh, was offering if, you know, if you worked at a company to sort of privately talk to him to see if you were on the list or not.

So I thought that was pretty cool. Yeah, it is really cool. You know, obviously, like we said, a massive breach, and it's great to see these kind of free resources making, making everything better for people. So thanks again, Mike, and congratulations. Yeah, good stuff.

All right, let's jump over to upcoming events. Just a reminder, we do have a calendar of events on the website. Come out and see what's going over the next few months. It's, it's pretty well filled out, I'd say, through like the May-ish time frame. So you can, you can schedule your own personal attendance to these things.

Over the next 2 weeks, we have a handful of events. Starting on the 16th, we have 2 events. Number one, ACES, the local physical security group, is doing their Women in Security coffee chat with Tanya Taylor. And also that evening, the Cloud Security Alliance Colorado is doing their March meeting. On the 18th, ISACA Denver is doing their March meeting.

On the 19th, uh, is when you have to have signed up for the Colorado Equal Security March Madness pool. So in the Slack channel, uh, go get a, get a part of that in the fantasy sports channel, uh, and, and get in there and, and maybe you can win. On the 23rd, ACES is doing a young professional happy hour with Kevin, uh, McAnula. On the 24th, ISC2 Pikes Peak down in the Springs, they're doing their March meeting. Also on the 24th, ISSA Denver is doing Don't Let Your Incident Become a Forest Fire.

And I think the last one here is another ACES. So they got 3 events coming up here in the next 2 weeks. This is their legislative committee meeting, and I don't know what you have to do to be able to go to this, but if you are interested in that, I bet if you show up, they'll tell you exactly what the deal is. That's cool. I don't know if that means like legislative, like internal legislative, or like they're meeting to talk about Well, what they need to push forward in terms of lobbying.

Either way, it sounds pretty cool. Good stuff. All right, let's jump over to jobs. Uh, this week we're starting off with, with, uh, kind of a follow-up from last week's story. You know, we talked— was it last week or 2 weeks ago that InteliSecure was purchased by Proofpoint?

Well, InteliSecure/Proofpoint is hiring a Director of SIEM Managed Services for the— oh nice. Uh, AECOM is hiring a Cyber Defense Senior Director. Uh, Bank of America is hiring a cyber threat hunter. Dish Network is hiring a lead wireless security architect. Wow, ties back to the story if you want to help secure their 5G.

Yeah, good stuff. Probably working with Henry Yu over there, who's— who I think is heading up that, that area. Um, Dice— I didn't know Dice had employees here in town, but in Denver they're hiring a cybersecurity engineer. Oh, pretty cool. Uh, T-Tech is looking for an information security engineer.

Cognizant is hiring a senior security specialist. Pearson is looking for an application security engineer. MYR Group is hiring an IT security operations manager. Ooh, and AMP Robotics is hiring a head of information technology. That sounds like a cool job.

Doesn't that sound awesome? Yeah, I was excited when it came— it kind of triggered one of my security search terms. Um, it doesn't— it's not focused on security, but that's part of the job. Um, and obviously AMP Robotics, that'd be, that'd be pretty fun. Yeah, that would be pretty fun doing some cool stuff over there.

All right, well, that is it for news. And we have a— we do have an interview this week. Uh, Jason Jaques sat down with Chris Nickerson. This is our Chris Nickerson Part Deux. You know, I think the last time I talked to him was 2016, so, uh, I'm sure there's been a lot of changes.

I know LARES has grown and evolved a lot over the years, and I'm looking forward to hearing all about that. Well, you know, Robb, if, if you talk to him, then that probably makes it, uh, Part trois, because I talked to him at one of the very first episodes. It was, I don't know, maybe episode ten or something like that. Maybe I didn't even do it then. Maybe it was just you.

Well, and and also, I really hope that this one has some good audio because I think that the the interview with him was the worst audio of any interview we've ever done. Yeah, not not any of his fault. I remember it was it was a bad one. I think it was like a mic on a table, and it was just super ambient noise, right? And and it was in like in a conference room with like brick walls.

And yeah, it was pretty bad. Yeah. Anyway, I'm sure Jason did a better job. Jason always does a better job than us. That's why he's here.

That's true. All right. Well, that's it for this week. Uh, of course, we'll go— we'll listen to the interview and, uh, we'll talk to you again next week. Thanks, Robb.

This is Michael Stephen, Privacy Security Officer for Connect for Health Colorado. Welcome to Colorado Equals Security. For Colorado security professionals by Colorado security professionals. Hello, Colorado Equal Security. This is Jason Jaques.

I had the privilege of interviewing Chris Nickerson for a second appearance on the show. This was a fun conversation, went a little long, but hope you enjoy. Chris, welcome back to the podcast. Thank you for having me. You were episode 27, 3 and a half years ago.

That's been, it's been a long time. Lots has changed. Lots have changed. What I want to start with and what I found interesting about your previous episode was it was a very brave, or maybe brave is not the right word, bold. It was bold of you and Alex to conduct the interview at midcourt of an empty Pepsi Center.

Can you talk? I'm just joking. That's, that's in reference to the, the sound issues. It sounded like you were in an empty Pepsi Center. Where were you guys?

I don't know. I thought we were here in the office. I can't recall. I think we were here in my office, which is the thing behind me. Okay.

Okay. It was a fascinating interview, though. That's why Alex is in security and he's not in audio engineering. Yeah. No, it's, it's come a long way for sure.

I mean, that was, that was early on. You know, early on in this podcast for sure. But yeah, fascinating interview for anyone that wants to go back and listen to it. I thought some of the stories were incredibly funny. My first question to you is, have you uncovered any new Hollywood roles for yourself?

God, no.

I'll try anything twice and I tried those things twice and realized in all accounts, I have no interest in playing those games. So you're, uh, you're out of the Hollywood biz forever? Yeah, you know, um, I, I enjoy my reality. I think, uh, what we get to do for a living is, is, uh, Hollywood enough. Um, I don't really think that the people who are behind the camera or barking the narratives to the viewer, uh, really, really understand what they're, what they're doing or the social implications of showing people certain things and I think it's much better for us to just kind of focus on the work that we do.

Yeah, for sure. So tell me, what has changed in the past 3 and a half years for you?

Oh man, everything. You know, business has been really interesting throughout the last couple of years. You know, it's— I think everyone who is in the security field, whether you're in offense or defense or product or sales or whatever else, has experienced the, you know, insane growth of our profession and the field itself. I think as, as with any growth, you know, you kind of start to figure out what are the things that you like to do, what are the things that you do because you have to do them, and then really kind of what, what your passions are and what are driving you forward. And, you know, we've just been really blessed as a business to always have a very strong kind of purpose and mission-based objective, where unlike I think a lot of other businesses that are, that are controlled by, you know, XYZ PE firm or, you know, leader that needs to buy 40 Ferraris to feel like they're relevant.

You know, we've always worked on the work that we do and contributions to the community and being able to have, you know, customers that are our partners. And I think that that brand message for us has gotten stronger over the last 3 years to the point where it's really great. You know, I feel like every day of work, whether it's playing CEO, whether it's playing engineer, whether it's, you know, playing sales or whatever other role that I get thrown, it's like working with your friends every day. You know, we have customers that challenge us, we challenge them back, and that type of relationship is just so rewarding that we've been able to grow it. We've been able to keep kind of that purpose advantage that we have, but be able to scale it from 3 years ago, I think that we were like 16 engineers and now we're in the 40s and we don't have to lose our way to grow.

And I think that that's been one of those things that as you go through Venture Vulture School or you go through XYZ MBA school, there's this scalability curve where people tend to lose their identity in lieu of making more money. And I think that we've been able to find this really sweet balance of being, you know, viciously dedicated to what we're doing for our customers. And in turn, that's just given us more customers that are viciously dedicated to working with us and being partners. And I mean, if I can commend anything, it's really the fact that we have a team that lives that and breathes it every day, opposed to, you know, people who aren't in the same fortunate sequence that we are, um, where, where they have to do a whole bunch of stuff that they, they may not necessarily agree with, or they may not be, you know, completely in line with, uh, you know. So the blessings, you know, really keep coming.

And, and I think that, you know, as a byproduct of that, we try and give back as much as we can, um, just, just because that symbiotic relationship is something that's— it's so nice. And, and it's grown over the years, you know, and that's— it's, it's really, really a blessing for all of us and for everybody on the team. And for new listeners, your company name is what again? Our company is called LARES. Yeah, there we go.

Which I think it's one of those 5-letter words that's hard to say, likely just because I took 7 years of Latin and it was the first name that popped into my mind. And most of us have not put ourselves through the hell of taking, you know, 7+ years of Latin. So unfortunately, people call us Larrys, they can call us Lorettes. I mean, at the end of the day, it's all tomato, tomato. Yeah.

And in the past 3.5 years, you've expanded. You have more than one location now, right? Yep. We have kind of people in all time zones in the US. We also have employees in the UK, in Belgium, and And we're continuing to move westward with other locations.

So, you know, here, South Carolina and Charlotte, and now working on kind of setting up another home base in Düsseldorf in Germany. Yeah, that's awesome. And I know that the Colorado Equal Security community thinks very highly of your company and obviously in particular you. So it's great stuff. And in leading into this interview number 2, I asked the community for questions and I got a whole lot of them.

So that's definitely— I'm afraid. Yeah. There's going to be some interesting ones. But before we get into that, what are some of your hobbies? How do you avoid burnout?

Lately, it's been more trying to get outside and enjoy the beautiful state that we have. I think throughout all the COVID stuff and even before, I'm a big skier. Um, and, and getting back on that horse after, you know, an injury, I think was one of those things that, you know, we've had to, had to kind of figure out. But now, you know, I'm back to skiing a whole lot. Um, I've got land that we go, and as, as, as, you know, as mundane as it is, it's really nice to go out with an axe and just clear the forest and get down trees and take care of beetle kill and try and do some fire mitigation and the end of the day, you know, you can make a big fire, you can hang out outside and take a look at the mountains, and it's, it's just really nice.

Um, ride my motorcycle whenever I can. I have, you know, some UTVs, so go out, play in the mountains, and, and kind of, you know, instead of taking the hiking path, I can go, you know, 40 miles an hour up the hill, which is pretty fun. Uh, so there's, there's a lot of us that, that get together and go do that stuff. But yeah, I've really just, you know, tried to, to lean in more of, of what outdoors, you know, fun stuff that we can have, and then I think on the other side, I can truly call it a hobby that over the last 3 years, I've been lucky enough to become a principal advisor for a couple different venture capital firms and some investment firms and being able to just kind of give some of the learning lessons that I've had of owning a business for 14 years, being part of various different firms and entities, and then also trying to give people the terrible story of, here's the time where I broke this, destroyed this, failed at this, with hopes that they can learn from some of those lessons and don't have to go through the same hardships. It's been really rewarding as a hobby just to kind of help, whether it's young entrepreneurs or entrepreneurs who've been around forever who need a connection to security or even a connection to just weird new ways of doing business.

So I think between outdoors and that, that's been keeping my dance card pretty full. The first community question is actually what you just stated there, skiing. So you did have an injury that I think most of the community is aware of. What did you do with your time off and did that injury impact, I suppose, your mental health or your thinking? Yeah, it was horrible.

I've never— before that, I had never had surgery on anything. Um, I think even, even in my whole life. I mean, aside from like broken bones and cracked things, uh, my face is— I mean, obviously my face has been beat up plenty. Um, and, and, you know, but, but other than that, you know, I've never really had to undergo major surgery. And, um, to, to give the example, my, my doctor Uh, who was performing the surgery, you know, I was trying to be all like jokes and laughs as I was going through the, uh, you know, big giant CAT scan machine or whatever, or the MRI machine.

And, and I said, hey, did I do a good job? And he just looked at me and he was like, no. And I was like, oh, I was trying to make a joke. Uh, and he goes, he goes, you realize your, your knee is fully detached? And I'm like Nope.

No, I don't. I don't, I don't even understand what that means. And then he walked out, which I thought was even funnier. I mean, it was terrifying for me. And then later on, about 2 hours, 2 hours later, he like brought a group of people in and then pretty much showed them like on a screen that was actually in front of my face.

So like I was behind it like this, and he was showing people the massive amount of damage that I did because I snapped, not tore, Uh, completely dislodged and, and broke my ACL, LCL, MCL, PCL, and then tore my meniscus 2 ways. Oh, and, um, having never gone through anything like that or having had to do physical therapy or anything like that, it was, it was crazy. I mean, like, life was completely turned upside down. I couldn't walk. Um, I wasn't allowed to even touch my foot to the ground for the first 3 months, uh, because of the way that they were repairing my meniscus.

Um, it was, you know, physical therapy twice a day for 2 hours each one of those sessions. And then that, that, that turned into, you know, about 4 to 6 hours of physical therapy a week for 2 years in order for me to get walking again. Wow. Yeah, that's, uh, I didn't realize it took that long. And yeah, and for somebody who's used to, you know, being able to run around and break into buildings and be fairly durable and It was a huge shift.

It was— I mean, I think, you know, to your point, you go through your mental stages of anguish and denial and being angry about it and everything else. And then you see what comes out on the other side. And so, you know, I think part of that takes a huge toll on your relationship with the people that you love because, you know, you have to now, like, rely on somebody for everything from going to the bathroom to taking a shower to— I mean, you're, like, fully reliant on somebody. You turn into an infant. And that's hard for independent people to have that happen.

And then I think, you know, you also got to kind of then balance the whole, well, I'm the CEO of a business and I have, you know, 40 mouths to feed that I have to worry, you know, even more than that when I take into consideration their kids and their families and, you know, their responsibilities. And you kind of have to start setting those priorities so that instead of spending the day feeling sorry for yourself, you're using it to be productive to kind of get back in the game. So For me, I think it was a huge evolution. It didn't happen quickly. I mean, for the first 2 months, I was pretty sad with everything.

And I think that it really took that kind of— whether it was reading that I was doing and trying to study kind of what was happening for me personally, I think I started to have some epiphanies that my responsibilities were much larger than my commitment to walking or even my ability to walk, that my responsibilities were way bigger than that. And that walking was something that got me to my responsibilities, but they didn't leave because I couldn't walk. So I think that a lot of that drove me to just take a different approach both in business and what we were doing, but also I think it gave me some permission to just allow myself to be broken in one way and really some time to heal and focus on that, which that kind of helped me turn the corner. And in turn, I think the business really benefited from it, as weird as it is to say that because I had those priorities, because I had to focus on certain things that I could do versus be mad that I couldn't do things, I think a lot of those shifts in priorities really helped the business grow. And I mean, and from a numbers perspective, you know, we've, we've been growing massively since then.

So I guess, I mean, I guess it was a good thing. Yeah, it's interesting. Knock on wood. Yeah, that you say that because I, as, as you're explaining that, and, and that story is largely new to me, I, I was thinking, I wonder if, if that forced you to trust others more and delegate responsibilities more. And because of that, ultimately, maybe like you just said, maybe it was a good thing in a weird way.

Yeah. I think traditionally I've always ran a very fiscally responsible business and probably much more so than I think most people do, especially as owner-operator types where we started to say, okay, instead of sitting on this in the bank, let's go out and hire people to take take on some of these tasks because I don't— I can't be Super Chris, uh, and my business partner can't be Super Eric. And, um, you know, what we were finding is that, you know, we were doing 3 jobs, we were working 15 hours a day, and, and I just didn't have it in me physically to be able to do that and be able to take care of myself. Um, so I think that like the, the own self-care thing was one of those things that really woke me up because before it was like, ah, I've been doing this forever, I'm fine, I can work 20-hour days till I'm and I'll be totally fine. I think that that was one of those wake-up calls where it was like, no, we gotta bring the right people in so they can keep the ethos of the business and the feeling and the purpose of the business.

And then I think that expansion brought, you know, great new ideas to the team. It brought excellent people to kind of come on and build their version of the vision. And I think that as we've continued to grow, embracing that spirit of bringing new people on that really have a contribution to the vision was something that was really started out of necessity. That makes sense. I have to credit Douglas Brush for prompting me to ask about the skiing thing.

I think that's a lot of interesting perspective and wisdom there that you just shared. He does have one other question. Well, he had a slew of questions, but I'm going to read this question verbatim. I'm not sure what it means. Maybe there's something there that you'll understand.

Why did you decide to hang your own shingle?

So I guess I interpret that as, you know, why did I decide to start my own company? Okay. I didn't know if that was something that you used to talk about in like speeches or something. No, no, not really. But I think it's worth discussing.

At the end of the day, once you've kind of explored different things in what drives you, I think some people are great corporate leaders, some people are entrepreneurs, some people like studies, some people like things fast, some people like things chaotic, I guess I'm— I mean, probably more than anything, I was stupid in the fact that I started my business in the worst possible time in my entire life when everything was in the air and the economy was completely in the toilet. And so starting a security business that focuses on offense in 2008 when the market's completely destroyed and most people don't even know what offense is, Yeah, I mean, I don't know, maybe I drank too much that day, but I think really what the thing was with me and the conversation that I had with my partner, Eric Smith, when we started it was, you can probably see my history in the community of being pretty vocal about things not being done right and the kind of vulture culture that happens around security, where people are just trying to make money and they're just trying to put up the new product that does the thing so that they can cash out and go back to their cush venture life without really giving a shit about anyone or what they do or how they do it. And I had really hit a point in my career where my career started really, really early in comparison to most people. By the time I was in my early 20s, I ran, you know, the entire corporate compliance and security team at Sprint. You know, so I was well on in my career in security and then moving from where I was at in Sprint, whether it was first doing architecture engineering and then kind of, you know, bridging the gap between actual security and compliance management and then moving and going like, oh, I want to see what the world looks like from the KPMG perspective, uh, which, I mean, that was absolutely stupid for me to do, but it was a great learning lesson, right?

It's like falling down the stairs. You just, you know how bad it hurts to fall on the stairs. But, um, but, you know, then being exposed to that market of, okay, I ran security at a carrier, now I'm helping build a practice in one of the largest possible firms to build this market in and explore the market. Then went to, uh, alternative technology, which became Arrow Electronics. So learned distribution channels.

So, so I got to see security from all these different angles, and my conclusion was the same, is that none of them were actually out there to help the customer at all. Like, none of them were. They were all there to make money, you know, with the exception of Sprint that was just trying to protect their money. Um, and, and really kind of took the stand of I don't care if it's inconvenient. I don't care if I have to go out and, you know, yell and bark at every single conference to say that there's a way for us to have respect and dignity in the field.

Um, but it was a field that needed to get started. It needed exposure, and, and people around the world needed it. And, and I said, all right, well, I'm just gonna take it on. And there's, you know, so we just sort of jumped in with both feet and said Here's who we are, here's what we do, and someday you're going to need it. It might not be today because you don't know that.

And 14 years later, the bet paid off. Yeah, that's awesome. Well said. All right, next question for you. You're one of the founders of BSides.

Someone in the community, and I'm going to withhold some names here, but somebody in the community wonders if someone gets too much credit for starting BSides and perhaps you don't get enough credit. Now, Now, before you answer that, what I'm curious about, and I think some of the listeners, tell us what BSides is and actually how it started, because I don't know any of these stories. Yeah. So the question is kind of perfect based on the genesis of where BSides came from in a couple different ways.

Black Hat, DEF CON, et cetera, right? It's hallway con, it's party con, it's a place that I can charge off my $5,000 expense to go hang out with a bunch of people in Vegas, slash my company thinks I'm doing a security conference thing. I mean, that's really where most of those things exist, right? And as a speaker, you get invited to those things and the kind of social contract trade that you get is, Well, it's going to give you exposure and you're going to— your brand, right? Like me as a person, my brand gets extra credit.

And in trade, they get to keep all the money. So they sell tickets for people to come see me and I'm supposed to thank them for them giving me exposure for the people who paid to come see me. Kind of a weird thing if you think about it, right? Um, there's something, there's something real shady about all that, uh, especially when you get to the RSAs and to the, to the Black Hat. You know, you're paying tens of thousands of dollars with training and all this other stuff.

Oh yeah. And most of the people that go there, they're not getting paid a damn thing. And you're going there to see those people. You're going there for their talks. You're not going there because, because you're getting something from Black Hat.

You're getting something from that researcher or that person who's on stage. And what we started to see is that the marketing of it, especially once Black Hat got sold and became the marketing event, like the IDC-owned whatever conglomerate thing, and RSA became COMDEX, Black Hat became RSA, and there's this big gap. And the thing that we always longed for were the days of community, was the times that we all used to get together in hotel rooms and just hang out and talk. And it wasn't like there was a schedule. It was like you were around a whole bunch of really smart people.

And if you asked them a question, they would give you a really, really, really in-depth answer because that was stuff that they were super into. And then, you know, 25 minutes later when there's 30 people huddled around this one person, like going off, writing all over the whiteboard, like making random things on the fly, everybody pulling their machines out, Like, that was, that was this beautiful way that we used to share information where it didn't have this, like, evil Don Draper marketing machine over it. It was like, it was real, it was authentic. And one of the other things you started to see is that Black Hat and some of these other conferences started to pick up these tangential talks that they knew for sure would get gag orders because it was this beautiful, easy publicity layout. Up, right?

Like, oh, somebody's talk's getting censored. Well, that means that we must have the craziest content ever because even the lawyers can't even let us give this talk. And we were like, that's the worst, most blatant, egregious, bad marketing. And it hurts our community, it hurts our industry, it hurts the people. It's horrible and it's really slimy and it takes advantage of everyone.

Everyone. The consumer, the person on the stage, the only person that benefits is the people who get the money at the end. So we said, all right, this is dumb. We need to just have house parties again. And if your talk gets banned, cool, come have it at the house.

And if their lawyers want to come over, I'll tell them it's a private event and they can sue me for not coming to my private event. Guess what? They can't. Um, so, you know, we said, all right, this is a refuge just like it used to You know, it's, it's a, it's a, you know, what happens here stays here. Um, and, and it's a free place to share information.

And, and those places started to become less and less and less. So we said, all right, well, we're gonna do it. And when we do it, we're gonna do it right next door to all these big money-making evil corp conferences. And any one of the speakers that wants to come over to give a better version of their talk that they can't say on stage because maybe it's a language thing, maybe it's a of professionalism, maybe it's this, maybe their employer's gonna freak out or whatever else. Cool, come do it in the cone of silence.

It's a house party that you happen to have a microphone. And so there were some talks that were starting to get squashed. There were also some talks that didn't fit the panel's narrative. Now, the panel that exists at most conferences is there for a couple reasons. One, to like vet the kind of bullshit and like the bad technical content, good technical content.

And the other is totally for marketing. Right? Like, oh, this is going to sell more seats. Oh, this one is more important to like me as the panel. Um, it doesn't take into account how cool some of these topics are that are just not cool to other people because the people on the panel either don't understand it or it's not going to put butts in seats.

So we're like, well, well, that's silly. There's— that's not why research should be muted. I mean, like, you know, you look at, look at the, the first one that we had and, and the, and the panel that we did Um, was the first women in security panel. Why? Well, other conferences weren't doing that, and it wasn't because of anything, you know, it wasn't because— I, I hope not.

I mean, I hope it wasn't because those conferences were biased, but I think it was like, oh, they just don't think it's going to put people's butts in seats. And we were like, this is an important topic. I don't give a shit if one person goes or if everyone goes. It's an important topic. And, um, and, and we, we took the approach of important topic, interesting research, and privacy are going to be the way that we go with it.

And lo and behold, the conference fires up and we get buses running back and forth. We get some great sponsors that go, hey, we'll give you some money. This is a fun idea and it's disruptive to the market because we're not asking for money, We're just asking for time and attention. And it's amazing what, you know, a couple people with, you know, a grill that could fit 60 hamburgers on it and a chest full of beers and sodas and other stuff can do. And so we brought back that old school house party and really that's where it started.

And then it was also about being able to show people that possible. I think a lot of things in this world don't happen because people believe that they're impossible or believe that the bar's too high. And when you can set something like that, you can show them, here's how we did it, here's what we did and how we did, and it's completely open. And you can tell the people that actually contributed to starting BSides versus the people who may claim it, Because the true spirit of BSides is that there is no owner. It's a possibility.

It's a thought. It's, it's, it's a way to show people that you, anyone, can do it anywhere, and that we don't have to be beholden to the marketing machine. We don't have to be beholden to the security industry. We don't have to be beholden to the dollar. If you can grab 5 people and you, you go to a dumpster and you throw a log in it and you, you yell happy 2020 and you talk, you start talking, bam, you just had a B-side.

Yeah. And, and I think, I think you can, you can really easily distinct, um, where B-sides is, is, you know, like, like every other thing in, in this industry, uh, starts to get polluted once marketing, money, all of those things, and people start getting an inflated ego about that The movement is really about creating opportunity and breaking down the barriers and the walls for people that don't believe that they could do something, to prove to them that any idea is a good idea. You just have to try it. That's well put.

Let's kind of change gear. You know what? Actually, as a follow-on question to that, this probably fits perfectly. So what events are your favorites? To speak at, if any?

And, um, and what's possibly the most offensive thing you've ever said on stage that got you in trouble? Oh, I mean, I've— every one of the offensive things that you can say on stage, I've said on stage. Um, I think, I think if I'm ever gonna be a trailblazer in anything, it's probably saying fuck in a conference. Um, okay. And then people being like, yeah, he gets it.

But Um, but, but no, I mean, seriously, uh, I, I think that, uh, I, I'm a real big fan of, of small events. I'm a fan of intimacy. I'm a fan of collaboration. Uh, the, the idea, you know, one of those other kind of B-sidesy things, right, was, uh, was really— and I can, I can say that more of this has happened uh, than, you know, predating B-Sides. When you look at, uh, how Finaleat and FX and their team used to throw pH Neutral, uh, in Berlin, and, uh, one of the things that they, you know, really, really highly encouraged, which I've always, I've always held dear to my heart, and I love those guys and girls and, you know, robots and whatever everyone else is called right now, But those people have, have always embraced this culture of, you know, you can say anything at any time without judgment, but if you say something that may not be true, be prepared to be challenged.

And I think that that culture is something that a lot of people aren't, aren't capable of right now. They're not capable of respectfully being challenged. Everyone wants to to have this like, oh my God, how did you say that? Or how could you say this? Without just saying, look, throw all that away.

We're in a tech, like super technical field. And if this was a, you know, if you were Einstein and you were on stage and you put a formula down, expect people to challenge your math and then prove it. And if you can't prove it, don't be mad and walk away. Now collaborate with the person and be able to develop and bring new ideas. To the table.

And I think that, like, that sense, when that sense exists as a core of what a conference is going to do, when the speaker is encouraging the audience to interrupt them and encouraging a conversation, that's worth going to. If I want to sit and listen to somebody in a hard seat and eat conference chicken, I'll do that shit at home. Yeah. So do you ever participate or speak at kind of the mainstream, I guess, corporate events anymore? Or is that like well in your past?

I kind of stopped with the exception of a few of those events that are maybe on the bridge or edge of corporate things that I have friends that I'm trying to support. I mean, most of the time, any of my interaction with those things are really around me trying to support other people in the community who are taking on the challenge of like, hey, I'm blowing the conference up and we're gonna go do the big corporate thing, like, would you help? And a lot of times I try and balance my, you know, my efforts on that for how responsible they're gonna be with the audience that they have, how they're gonna treat their speakers that are really generating that revenue for them, and then what's their mission? You know, is their mission just to go make money? And if it is, Like, I don't need to be part of that.

Like, there's plenty of people in the industry who can get some personal brand and credit out of those things. But I'm now to the point where I'd rather be out of the way so that those people who need that brand credit as part of their career can have access to it. And I'm not in that seat that they need to be in that they could be benefiting from, or as a staunch, you know, adversary and an opponent to people doing things in a way that's just not ethical. Yeah. Great answer.

Next question. Prediction for the next 5 years. What's going to impact us the most, the industry the most? What are some trends you see developing? What are your thoughts?

Man, what's going to impact us for the next 5 years? I feel like what's going to impact us for the next 5 years is the thing that has impacted humankind since its inception, which is stepping on our own feet. We suck at getting out of our own way. We constantly develop things that are completely not needed and sell them to ourselves as a way to falsify our progress. And I think that the continual thought of security being an empirical and being one of those on-off, secure, not secure, is the biggest problem that we have.

And I think that that's going to self-perpetuate. I think that the more stuff that we come out with, instead of going the path of understanding that security is a point in time, it's dynamic, it is a measurement, and it's not a 1, 2, 3, 4, 5, it's a pressure gauge that every single day it moves and you have ranges and variances of tolerance.

I think we're continuing to build machines and build automation and build security products with the wrong end goal in mind. That end goal being, I'm going to be a 5, instead of, well, this is my range of tolerance for the pressure gauge and I need to be somewhere in there, but all of the things that I have in a security program are there to give me the telemetry to make sure that my gauge is right. Not the— my— so my, my job is performance engineering. My job is making sure that the gauge is getting the information that it needs to be real time, to be real, to be accurate, versus us continuing to cheat and play the like, oh, I could game any— like, I can get any compliance certification you want. Why?

Because I can game any auditor. And, and then they're like, yay, pat yourself on the back. And then they're like, shit, we're in the New York Times again for getting owned. And they're like, whatever, the stock's gonna go down for 3, maybe 4 weeks, and then we're gonna go back up to exactly where we were. So like, we could probably make money shorting stock.

Hooray, let's go back to capitalism. Like, I, I think, I think the, you know, we're going to continue to see that. I think we're going to continue to see, um, you know, the, the, the most pertinent phrase I think in our industry is, is that, uh, The only thing that a smarter mousetrap does is breed smarter mice. That's it. Okay, we can distill— we can sell our entire profession down into that one profound, very famous statement, is we will continue to build smarter mousetraps and we will continue to have smarter mice.

That's a, that's a good way to put it. Do certifications matter for, uh, hiring offensive analysts?

Anyone who's read my job postings, which I try and be funny in, but at the same time, I take a level of seriousness with the outward smack talking that I do in them, is that if a certification is a requirement, someone coming to me and saying, Well, that's ridiculous because the certification doesn't prove that you're good at anything. I always rebut them with, okay, well, but if your job was to hack into something and that was the job description, and then you just came up to me and said, well, hacking into it's really not going to do anything. I'll be like, well, then you just can't take basic instruction. And if the certification's so easy, then go get it and shut up.

But people love to have this fight about the utility of certification. When I think the same thing with certification as I do degrees, the higher level degree, the more I can show that you have some type of history of being able to go into a body of knowledge, absorb a certain degree of that body of knowledge, and then prove that whether the test is good or not, that you can say that, you know, you've learned something about it. Now, a certification may be a very short path to that. A PhD could be a very long path to that, but it does show that you can achieve a goal, right? So I'm not gonna say that getting an OSCP or OSCE or NET whatever, or I don't know, whatever Security+ thing of the day, I'm not going to say that makes you a great hacker, but it does prove that you said that you could get a certification and then did it, right?

Um, and those are people that you need. You need people who can set a target, set a goal, and achieve that goal. Now, that could happen from the PhD level, or it can happen from the cert level. Uh, do I think that there is utility in that from a hiring standpoint? Sometimes, uh, you know, I will— I will look at someone with no certifications as well as someone with every certification.

Yes. Um, personally, uh, I'll probably look at the person and I evaluate like how many do they have. If there's someone who just like collects certifications, I'll be like, oh well, you've probably spent all of your time in the lab and never done it for real. So maybe it starts to hurt you at some point. There's other people that, you know, have no certifications and are really, really good.

Um, I, I think, I think that goes all the way across the board. At the end of the day, it's about can you do what you say you can do, right? And, um, I, I don't believe that certifications or college degrees, which is just another certification, I don't think any of those prove concretely that you can do the thing that you say that you can do. Um, I think that they, you know, can show you various different degrees of discipline and whether that person can follow long-term programs, short-term programs, whether they can, you know, achieve tests or pass certain things or, you know, solve puzzles, whatever that is. Um, I don't, I don't personally believe that it is a fundamental requirement, uh, but at the same time, I I would challenge absolutely anyone who says, well, you know, I'm not qualified for this job because I don't have a CISSP or an OSCP.

And then, well, that company is just dumb because I can do all of that stuff. No, I would say that the person making that statement is fairly ignorant because they weren't able to just go complete the task that they needed to get to the next stage. Because sometimes you have to do stuff in life that, that you may not find convenient in order to get to a place that you really, really truly enjoy. So I think, I think that the, the debate in that is not productive for work, whether it is good, whether it isn't good. I don't think that that's a productive thing for the industry.

I think what we need to figure out as an industry is how do we adequately measure somebody's skill to do something and actually have them execute it with those people. So, you know, if we were a blacksmithing guild, I could say, make me a kukri, and then I could play the Forged in Fire thing and I could try and chop it. And when the knife blows up, I'll be like, we suck at making knives, you know, like, and I think that we need more of that. We need to take a look at our trade a little bit more from the workers' perspective and start to have a few more mechanisms that exist, whether it's trade journeyman-type programs, whether it's following more of those. How do we take it out of the lab and put it into the field?

The people that want to go that path, whether they're certified, whether they're not certified, whether they have PhDs, whether they don't, the people who understand that this is, this is a trade. It's not, it's not a, you're going to get an education, you walk into the industry, you get $100 grand because everybody needs a pen tester, and then you suck at everything because you're script kiddie. Um, I think, I think the people who really want to work that, that trade angle and learn those things over time, uh, you know, that's, that's the most valuable resume that sits on my desk. Yeah, well said, and I totally agree. If you could do it all over again career-wise, what would you do different?

Man, so I don't know. I've— I have so many bruises and I've taken so many lumps and I've had so many, you know, look back on them, bad things happen. Um, but at the same time, I'm so appreciative of where I am in life right now that I feel like the butterfly effect would happen if I changed anything at all. Uh, I wouldn't— I wouldn't be in the state that I'm in today. Yeah.

And so So I just don't wish to tamper with my past. What I would do, I think, is expose more people to knowledge that I've gained and share those things more fearlessly. And I think that as part of a business, when you're a business owner, there's things that you can and you can't do. And, um, you know, not, not to be blaming of society, uh, but in a, but in a breath, I think I do a little bit that, that I would really, really love to share my failures openly, um, so that other people could learn from them. Uh, but when you're accountable for, you know, 10, 20, 30, 40, 50 mouths to feed There's certain things that you just can't say out loud because if they're misconstrued or if the culture of the community that you're in can't take those things for just face value and wants to attach some meaning to it that may not exist, I'm affecting multiple lives.

And I think that if there was a way for me to share the experiences that I had without judgment and being able to just say, hey, look, we're just putting it out there, that good, wrong, right, whatever you want to make about me, if it didn't affect all of those other lives, I think fearless sharing of failures is something that I would look at as a larger contribution to the world around me that I truly wish that Uh, there is a safe way to do that without, uh, the amount of venom that comes back from the, uh, from the hobbyists that exists, uh, purely just to make people's lives shitty. Yeah, I love it. Yeah, that's great. Um, but yeah, it's really where I would go. I, I— all the other stuff, I mean, obviously, like, starting a business is really hard.

Like, like, I think, I think now, you know, I look at those things and I'm like, oh, I could have taken money and I could have done this and I could have have, you know, had a board and then the board could have pumped it up and could have done those things. And like, that would have been awesome. I would have had far— I mean, I probably wouldn't have been on my third marriage, but like, I love Amanda, so I kind of am glad that I am, you know? Like, um, but, but, but all those lessons that I had to learn the hard way, um, I don't know if I would trade that experience for anything. But at the same time, I think if I was to, you know, go at it in a route that, that had me bleed less, um, or I didn't, didn't have to die on the field all the time, I think I would have done things a lot smarter, um, instead of having to, you know, work harder to succeed.

Uh, but, but that's hindsight, and, and you, you only learn that later on. I think, you know, my changes now are like, how do I take those things that I could have done smarter before and implement them tomorrow is my goal. Yeah. No, that's great stuff. So the Colorado Equal Security Slack channel is now over 1,800 people.

So it's grown a lot. Crazy. Yeah. Do you have any final thoughts for the community? Just stay a community.

Treat people— I mean, play the Bambi game, treat people the way you want to be treated. You know, try and, try and see if you can be open and be honest with people and create safe spaces that don't immediately work towards judgment and allow yourself to learn from people's failures and, and from people's successes. And I think at the end of the day, if we all were a little bit more like dogs and we got excited to see each other and we were there to help and we were there to play more, and not just take everything as the most serious thing in the world, I think we'd all be better off. And the fact that this community has grown so much, once you get to these critical mass sizes, it's really a time to reflect, to make sure that you're not becoming the machine that you didn't want to be. And it's really easy for us all to go there.

It's really easy for us to, you know, take sponsorship or do certain things that seem like the right thing to do at the moment, uh, when, when in turn I think that you need to foster culture and creativity, uh, and, and camaraderie, uh, and, and really truly be a force instead of being forced to do something. Uh, so I, I'd really I hope that everyone in this community has the ability to say, look, we're all on the same team, and actually allow them to be on your team. Let people drop the ball, let people screw up, let people do things that are wrong, and be able to have a conversation openly about better ways to do it instead of just immediately criticizing people. You know, let's, let's do a little bit more education and a little bit less adjudication. Yeah, that's excellent.

So you are on the Slack channel, but how do people find and follow you on social media?

@Indie303 is my Twitter handle. If you type Chris Nickerson into Google, I'm sure there's like a million different ways to get ahold of me. You can hit me up at my LARES address, which is just cnickerson@lares. I don't know. My phone number's all over the internet.

You can call, text, carrier pigeon, smoke signal. You seem to respond to Twitter DMs. I'm down. I mean, however, I roll the roulette wheel of like, I have 5 minutes for free. Let's just randomly swipe through stuff and see what I can do.

Yeah. No, that's great. That's great. Well, this has been a ton of fun, Chris. I'm glad you joined me today.

Absolutely. And I think the community's going to love this interview. Right on. Well, thank you so much for having me. I really, really appreciate it.

That concludes my interview with Chris Nickerson. Be sure to follow and support Colorado Equals Security on Patreon. This is Jason Jaques saying be safe out there.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex. Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes