All episodes

Desiree Robinson, Sr Information Security Manager @ Smarsh

Apple Podcasts Spotify SoundCloud

Desiree Robinson, Sr Information Security Manager @ Smarsh, is our feature guest this week and is interviewed by Janelle Hsia and they discuss Bitsbox (https://bitsbox.com). News from Whataburger, Air France, PopSockets, Vizio, Swimlane, Coalfire, Optiv and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript9994 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 207 for the week of April 19th, 2021. Alex, we got some nice snow this weekend.

We did. And if you were listening to this on, on Monday, it may be snowing again. I hear we're not through with the snow quite yet, Robb. I'm ready to be through with the snow, though. It's spring.

Me too. It's time to, time to move on. Weather, get the drift? Let's, let's move into the sun. You know, we do need the moisture.

I won't complain about that. But, but yeah, I'd rather it be rain right now than snow. Right. Well, you know, speaking of rain, it's raining news, Alex. Before, before we jump into that news, let's, let's do some housekeeping.

Housekeeping, we have a Slack channel if you want to join it and talk to almost 2,000 of our closest Colorado friends. I think we have just like 1,890-something people in there. If you want to join that group, go to colorado-security.com and click the Slack link and you can be part of the party. You know, we also have a mailing list. If you go to the website, again, colorado-security.com, there's a form to fill out there.

If you put your, your email in that form, we will add it to our list and you will get one email every week with the show notes. And that will be delivered to you mostly on Sunday, sometimes Monday, and maybe later when I forget. And a few other things we'd love it if you would do: go to your favorite podcast listening app and, and subscribe to get the show in your inbox each week. You can also rate us and put nice comments about us on that place so other folks can find us. And we'd love it if you'd tell a friend, you know, as you— as you're— we're getting back into seeing people in person here soon.

Um, you know, you can be like, you know, there's this amazing podcast with the funniest guy and this other guy too, and, and I'd love it if you'd listen to it. And, and I think if you can help get those recommendations, that would be great to build the community. Yeah, you know, um, Jay Wilson, or, you know, our guest host a couple weeks ago, he is that, that really funny guy. So I, I appreciate you noting that. Um, he sure is.

Uh, and finally, uh, we do have a Patreon campaign. So if you'd like to support the Colorado Equal Security Movement financially you can do that through Patreon. We have a multiple multitude of different options there, uh, depending on what you sign up for. You get things like a t-shirt, a call out on the show, and you can help us by supporting the costs of putting this all together. So we would really appreciate that as well.

All right, all right. So let's take that— we got, we got one more announcement, but it's, uh, it's not exactly, uh, news quite yet. Big announcement, uh, registration for RMISC, the Rocky Mountain Information Security Conference 2021, is finally open, Robb. So everyone should run out right now and get registered. And is there an early bird, uh, reduction of costs that they should take advantage of?

There is. You have, uh, until approximately a month from, uh, from the beginning of RMISC, which is, uh, would be May 8th-ish. So you've got, you know, 3 weeks or so to do your early registration. Much lower cost this year. You have options under $100 depending on, you know, if you're a member of ISSA or student or other things like that.

And, uh, really looking forward to it. It's a good lineup. Oh, awesome. Looking forward to the conference. All right, let's jump into the news.

We have a follow-up from some news you guys talked about while I was, um, sitting on a beach in Mexico. Um, we talked about the fact that Whataburger kind of— we casually heard that they're coming to Colorado. Well, there's a story here that gives some more details about, about their expansion into the state. Yeah. So they made this an official announcement that they will be opening a Colorado training center and their first restaurant in Colorado Springs.

And that training center will be at 5905 Constitution Avenue. Not being super familiar with Colorado Springs, that doesn't mean a whole lot to me, but I think it's sort of on the northeast side of town. And then their first restaurant will be in the InterQuest Marketplace, also on the north side of Colorado Springs. Looking for groundbreaking sometime towards the end of summer 2021. Didn't In-N-Out Burger have a similar strategy where they were going to start off with a distribution center in Colorado Springs?

Yeah, and I think they did, and that the first restaurant was down there. So I'm not sure if it's size of Colorado Springs, maybe it's a little cheaper to put your distribution hub down there or something. I don't know. But yeah, that is an interesting strategy. Yeah, interesting that they both did the same thing.

Yeah, but, uh, you know, since one of our main goals here is to break the, the latest fast food news, um, good to know that Whataburger is going to be coming back to Colorado officially. You know, I, I've poo-pooed, um, In-N-Out Burger as being, you know, it's just a burger. Um, I, I have had a Whataburger, but it's probably been 15 years since I've had one, and I honestly don't remember how good it is. Do you, do you have an opinion on Whataburger? You know, I, I had one a few years ago.

I think there's one in the airport in Dallas, and I had one. Um, I feel like it was a hamburger. Um, I don't remember anything particular about it, but, uh, I know I have talked to some people that say that they like Whataburger better than In-N-Out. So, you know, maybe people are in for a treat. Well, I'm looking forward to giving it a try.

Yeah. Uh, speaking of not fast food, We have some, uh, some airport news here. DIA has landed a new direct flight to Paris from Denver. Yeah, I'm excited about this. You know, any, any new opportunities for us to get directly to other parts of the world are exciting to me.

And this is especially nice because we had a direct flight to Paris that was by Norwegian Air. And, you know, if you remember, um, I think we talked about it on the show, they, they pulled out of, of doing the direct international, international flights really And now we lost that flight, but now Air France is going to be doing a new route directly to Denver. I think it's 2 or 3 times a week. I can't remember which, but I'm excited about that. Yeah, I think competition obviously is good for consumers, and anytime that there are more flights coming out of Denver to places that we might want to go, it's going to lower, lower the prices, maybe bring in other nonstop flights to Paris or, you know, other nearby places.

So, uh, so I'm, I'm pretty happy about that. And I was also sad when Norwegian pulled out. We actually, uh, in summer of 2019, we flew on Norwegian to London, and, uh, it was a good experience and relatively cheap compared to other things. So glad to see we've got more international flights coming back into Denver. Speaking of big things coming to Colorado, uh, there is a new, uh, major network television series that's being shot here in Colorado.

It's, it's It's, uh, by NBCUniversal, and they're shooting this, this, um, drama pilot in between Denver and Durango. They're going between those 2 locations, um, which is kind of interesting to know that they're, you know, if it gets picked up, this, this could be a major show here in our state. Yeah, I think that's pretty cool. One of the things that they talked about in here is how they wanted to, to make it, uh, more realistic and film it in locations that it potentially could have happened in, you know. Uh, you know, in the, the sort of the West kind of area, which I think is why they're doing, uh, the Durango part as well, as opposed to just, you know, shooting it on a soundstage or, you know, somewhere in the, the hills in LA and pretending like it's, uh, in the West.

So I think that's pretty cool. One of the other things that I, I noticed in here is that NBCUniversal is the, the company that is producing it, but it's supposed to be shown on ABC. So I thought that was pretty of weird that NBC is making the show but not putting it on their own network. Yeah, I think you look at it 2 ways. Number one, well, if NBC loves it so much, why aren't they showing it?

But the other way is, number two, there's now 2 major networks who, you know, have a, have a stake in making this successful, and hopefully that means it'll be more likely to be successful. For sure. Yeah, and part of the reason why this, uh, this story came up is because, uh, there are incentives that are being offered to, to NBCUniversal to do the filming here Um, I'm missing the actual number here, but, you know, as, uh, as our normal, you know, the, the Colorado, uh, group that, that does this stuff offers incentives to, uh, to movie and film productions to try and shoot here, as do many other states. So, um, pretty cool. They mentioned a couple other things that are going on, uh, a horror film that, that's being produced by a couple of Colorado natives and as well as a PBS show on music.

So pretty cool. Yeah, so it's the Economic Development Commission that does these offer— that makes these deals, and they're offering $1 million of incentives to film it here. And interestingly enough, they're talking about, you know, as a potential incentive for long-term keeping the filming here, that they would reduce the tax liability for Comcast, which is headquartered here, or not headquartered, but has a whole bunch of employees here. So that's one way that they could, you know, make it, make it sweet for them to stay in the state. Yeah, a couple of quick facts.

The show is about a Native American lawmaker, which makes sense that they might be in Durango and Denver. You know, maybe Durango is where they're from, Denver is where they're, where they're doing the lawmaking. And they do not have a name yet for the show, so we don't know what to call it other than major network television show. I am looking forward to watching major network television show when it comes out on ABC. Should be fun stuff.

Um, speaking of incentives, Robb, we all have an incentive, uh, to make sure that, uh, we push for environmental sustainability, uh, to help our planet. And we're not the only ones that believe that. PopSockets, um, also feels that way, and they are working to make a more environmentally sustainable PopSocket to put on the back of your phone. Yeah, you know, I, I feel like we haven't talked about PopSocket for a few years, and Honestly, the reason I put this in the show notes is because I'm like, hey, just remember everybody, PopSockets is a Denver company. And I don't know how well they're doing.

In the article, they talk about how they were the biggest growing company in 2017, 2018 timeframe. I would guess that in the last 3 years, they're probably not still the biggest growing company, but obviously they're still doing well enough that they can be reinvesting in new products and coming up with new stuff. Yeah, I, I have to say it's been a little while since I've seen someone with a PopSocket on the back of their phone, but, um, that may also be because I don't see people anymore, Robb. Um, could be. So maybe, you know, uh, once we come out of the pandemic, everyone will have PopSockets on the back of their phone, and maybe I just missed it.

But, um, the, the new, uh, PopSocket that they're developing is plant-based as opposed to being more traditional petroleum-based plastic. And, uh, you know, they're aiming to have, uh, well, hopefully all plant-based, but right now the first iteration is 35% plant-based, um, 56% from cornstarch, 52% from canola oil, and, uh, the connector hub is 70% castor beans. Um, not sure I know what a castor bean is, but apparently you can make, uh, organic plastic out of it. Yeah, so there's there's different parts of it, and each of them have different percentages of plant-based stuff. If you look into the article, there's a nice image that shows what their goal is for how they're going to get to being further, a higher percentage being plant-based.

But anyway, for now, I think just the fact that they're prioritizing this means things are going to move in the right direction, and they're pushing the innovation on plant-based plastic-type goods. Yeah. I'll say though, my favorite part of this story is the the photo at the top of the, the CEO of PopSockets in a, a cool pose holding 2 phones with PopSockets on it. Well, I mean, it's important to have, have 2 phones at any given time. So exactly, David Barnett, we salute you.

We do. All right, uh, next story here, uh, we have another, another store company that's coming to Denver, and this is, uh, this is one that, you know, I, I actually didn't even know they had a big presence in the West. Um, Visio, they're the, uh, the television manufacturer, they're looking to bring a whole bunch of jobs here to Colorado. Yeah, um, not only did I not know that they were based in the West, uh, I just assumed that they were a, you know, South Korean or, uh, some other, uh, Asian country-based company. Um, but, you know, Vizio is based in Irvine, California, and, uh, like many companies, they've, uh, decided to, to put offices sort of around the country and Denver is one place where they, they've decided they want to put some people, and so they're, they're putting an office here right now.

They have a small team, but, uh, going to be growing that, and at some point are going to have an actual physical office here. Yeah, I'm looking forward to, to seeing, you know, yet another big, uh, company that we appreciate having a big presence in Denver. I think it just adds credibility to what we do in Colorado. Yeah, and, you know, we think of them for, for televisions, but obviously to go along with the television, you have to do a lot of software. Um, and so, you know, there's a lot of security that comes along with that kind of software.

So maybe there'll be some opportunities there. I did happen to look at their, uh, their website to see what kind of jobs that they had open in Colorado, and there were a lot of, you know, software engineering kind of jobs. Um, didn't see any security jobs. So, uh, maybe we can push them to, to up their game in security and hire some security folks out here too. Maybe we need to, to create a, a viral TikTok video talking about how security in Colorado is what they should be doing.

Yes, I, I think that that would, uh, would go over well. Jason Jaques, let's get on that. Jason, could you please create that viral TikTok video for us? Thank you. All right, uh, jumping into the security news, um, this is a, a follow-up to a story that I think we've talked about at least once, maybe twice, um, that it is— it's ever-evolving.

Um, it was announced that Uh, that hackers are trying to extort the University of Colorado, um, you know, in sort of a ransomware sense, uh, not to release data that they got through, uh, the Aselion hack from a few months back. Of course, the University of Colorado was affected by that. There was a vulnerability in Aselion products that allowed attackers to get in and pull data out of the, uh, the Aselion file transfer, uh, application hardware, whatever it might be. And, and so this is just following up on that and letting us know that, that this is sort of still ongoing with, with CU. The hackers are— have been slowly leaking some data, trying to, to pressure CU to pay the ransom.

Yeah, I mean, it is a— it is really a bummer that the attackers are going after public organizations like this. I am glad to hear— I personally am glad to hear that they're not planning to pay the ransom. I just think it only makes things worse for everyone in the long run if they do. Yeah, one thing that, that made me chuckle, and I think it's just the, the words that they have here, that, you know, the first paragraph of the, the story says that, that hackers are trying to extort them, and the more than 310,000 files is what they got, but it included student data, medical information, and several Social Security numbers. Know, just, you know, one or two.

Several. Several. Yeah. All right, uh, moving over, next story we have an update from Swimlane, uh, the local, uh, SOAR company here in Colorado. Um, they, they are expanding, or they have expanded into APAC, um, with 500% year-over-year growth in the region.

Yeah, um, congrats to them. I'm glad to see that they are growing. Um, I'm not sure how much the 500% actually means at this point. If you have basically no market one year and then you have a great market the next year, you're probably going to have some pretty good growth. Otherwise, you're not being successful at all.

But they mentioned the addition of 11 new customers, which is great, and they're getting ready to start a professional services organization in APAC as well to help support all the customers that they have out there. Yeah, that's fantastic. One thing that was interesting to me in this article is there's a quote in here from Vaikut Shah, maybe, who's a director of security practices for Lumen Technology in APAC, Asia-Pacific area. And I was really surprised that— I mean, this, I assume this is the same Lumen that was CenturyLink. I was interested to see that, you know, publicly they're talking about a partnership that they have with Swimlane.

I would have put that at the headline here if it was me. If, you know, if Lumen is using Swimlane throughout their managed security services. Practices, that'd be— that's a pretty big company. Yeah. I mean, the other surprising part to me about that is, um, I guess when I think about it, it doesn't surprise me that Lumen is a global company, but, you know, I think of them as a more, you know, US-based telecom carrier.

So I guess it hadn't really occurred to me that they have, uh, they have pieces in other places, including APAC as well. Yeah, really interesting stuff. Anyway, and Lumen's another Colorado connection, obviously. A lot of A lot and a lot, a lot of those employees here in town. Yeah, the, uh, obviously the Broomfield campus for, uh, for Lumen and, uh, Swimlane are not very far from each other.

So makes a lot of sense. Uh, all right, we next we have a blog from Coalfire talking about how to ramp up for StateRAMP and what it is that you need to know. Um, I guess first, Robb, what is StateRAMP? You know, so what I think you have to first start by saying, what is FedRAMP? So FedRAMP is a federal a federal program that allows different federal agencies to use the same information from cloud security providers in order to say, okay, well, this is kind of approved.

It meets all of the FISMA requirements. There's a centralized process for keeping documentation, and people can reuse other agencies' research into that vendor. So then there's a whole like FedRAMP marketplace to say these are the vendors that have already received an authorization— authorization to operate, makes it a lot easier for agencies to see that. Well, State-RAMP is the idea that, you know, they looked at FedRAMP and said, that's great, but, you know, we're not federal agencies. We don't have access to the same market, so let's create our own and call it State-RAMP, so different states have the ability to get that same leverage of, you know, vendors say do it once, and other states can use that research.

Yeah, this seems to me like something that, could have just as easily been solved by the federal government giving access to the states to the, the FedRAMP information. Um, but, um, you know, that, that's a political decision, and, uh, for whatever reason that didn't happen. So, uh, glad to see that something is kicking off for the states as well. I think this will probably be a little bit of a burden on folks that want to be both FedRAMP and StateRAMP compliant, but, um, it does look like, based on the sort of Q&A in this article, that You know, if you already were FedRAMP compliant, mostly you can just take the information that you had there, port it over to the FedRAMP portals and do a couple things— excuse me, from FedRAMP to StateRAMP and be compliant with StateRAMP. Yeah, I had the same thoughts you did as I read it.

I'm like, why can't they just use FedRAMP? And at the end of the day, I think it does come down to the fact that, you know, the state of Colorado can't call up the JAB, the Joint Approval Board for FedRAMP, and say, hey, give me the information on Ping Identity. Right? They just can't do that. So the fact that they don't have that access within FedRAMP means they had to create their own.

I agree with you, it'd be nice if there was a way to centralize it in one place, but at least they're going to use the same requirements, and if you got through FedRAMP, you should be able to very easily get through StateRAMP and just, you know, spend the— it looks like it's $12,500 to get registered with StateRAMP in addition to FedRAMP. Yeah, a little bit more regulatory burden on those that want to comply with both. But yeah, doesn't seem like too much. So hopefully it'll work out for the states. And if you want more information on State-RAMP, there's some in that article.

All right. Oh, I guess we should mention in that same article, Coalfire is an approved 3PAO, third-party assessment organization, for State-RAMP. So, you know, they're also a FedRAMP 3PAO. So they'll be able to help you with your State-RAMP too. That makes a lot of sense.

I'm glad that they're doing that too. Good times. All right. Last news article here. Optiv has a blog this week, and this is one of those situations where we have a national story and we're able to find a local company that's talking about it so we can talk about a national story.

They're talking about the Improving the Digital Identity Act of 2020, which is— what's the name of that bill? H.R. 8215. Yep. This is a bill that really goes into the creation of a single federal identifier per person to take the place of this ad hoc system we've had where people basically use Social Security numbers, um, for a purpose they're not intended for.

Um, and this is like, okay, let's actually create a digital ID for all of our citizens. Yeah. Um, and there's some, some interesting stuff in here. I'm not— before reading this, I actually wasn't super familiar with the Improving the Digital Identity Act of 2020. Um, but, you know, they're talking about what the goals are of the bill.

Uh, and, uh, you know, basically it's, uh, It's to come up with, uh, you know, what we would want to do for, uh, for replacing Social Security numbers, the requirements, uh, how it would be enacted, and things like that. So I think, you know, this is also very, you know, preliminary. It's not that, uh, once this passes, all of a sudden we're going to have a new digital identifier, but I think it'll be the start, and hopefully people will be able to, to put input into that and make it better than what we have currently with Social Security numbers. Yeah, and I think the biggest problem with Social Security numbers is not their identifier. Like, you know, it is a unique identifier and that works just fine.

The problem is that we've used it as some kind of a secret, right? You know, if using— if knowing the unique identifier is also the secret, well, everything gets thrown out, you know, into a bad situation. And that's why, you know, having Social Security leaked in breaches becomes a problem because we've done it wrong. And this is— this implementation, you know, will separate the identifier from the secret. And that should, you know, knock on wood, that should do away with that being, you know, a fundamental problem with a breach where, hey, we just got your identifier and now we can go file your Social Security tax or file your income taxes or, or go, you know, apply for a credit card or whatever other things you can do with Social Security number.

Yeah. I mean, who, who knows what's going to happen with this? You know, from my perspective, Social Security number is essentially your username and your password. If instead of creating new usernames, which is what this bill potentially wants to do, as well as some sort of authentication method, if we instead just make Social Security numbers your username and then have some authentication method that goes along with it, I think you come to the same place as well. So it'll be interesting because they're do bring up the fact that there will be some impact if we come up with a new universal ID number.

Basically, every government system and healthcare and other things like that are built around the fact that your Social Security number needs to be in there to identify you. If all of a sudden you have a different number, different format of number, whatever it is, there's going to have to be work in those systems to be able to support that. I would think it would be an easier adoption if you— everyone keeps their Social Security number, but then, you know, you add something else where it's going to be, uh, authenticated in a different way. All right, good stuff. Uh, that's it for the news.

Jumping over to the Slack message of the week, I'll start off with a big thank you to Andre Gaeta. Andre's been paying for this out of pocket for more than, more than 2 years, 3, 4 years, something like that. Thank you, Andre, for what you do keeping the community going. We appreciate it. Yeah, and, uh, this week the winner of the Slack Message of the Week is Terry Bradley for posting an article on, uh, the FBI hacking Exchange servers, uh, to be able to remove the web shells that were put in there by attackers.

Yeah, and this started a good conversation. You know, this is another situation where, you know, someone gives us the opportunity to have a conversation we should be having. Um, so thank you, Terry, for, um, uh, for being the guy to just share that news first. You'll get one item from the Colorado Equal Security store up to $25 in value. Uh, you can use that to, to, to make sure you're sporting your Colorado security look anywhere you go, you know, in this post-pandemic world that's coming.

That's right. Uh, we— everybody's got to be fashion forward now that we're going to be seeing people again. Absolutely. All right, let's jump over to events. Uh, we have a good deal of events coming up in the, the next 2 weeks, uh, starting with ISSA Colorado Springs doing their April meeting on April 20th?

Well, April 20th is going to be a big week— or a big day, excuse me. We have a few more things going on that same day. We've got ACES doing a case study of workforce inclusion. This is presented from DEN, DEN being the new acronym for DIA, the airport. There's an employee from Denver International Airport who's going to be there talking about how they do inclusion there.

Nice. Uh, also on the 20th, CSA is doing their April meeting. ISSA Colorado Springs has their Cyber Focus Days. It starts on the 20th and it goes through the 22nd. On the 21st, OWASP is doing their April meeting, and that's a combined meeting, as all of them have been, between OWASP Denver and Boulder.

It's been combined since COVID started. Um, on the 21st, uh, ISSA Denver starts their April General Meeting, and it is interesting. It's actually a 3-day meeting where there you have, over the course of a few days, the opportunity to get a whole bunch of CPEs. So a good one to join. Good stuff.

On the 27th, ACES is doing a young professional happy hour with Tony York. Also on the 27th, if you're— if you don't want to be a young professional, you just want to be a degenerate, there is a Colorado Equal Security poker night, and you can go play poker with Jason Jaques. And I think I'm going to be there like that on the 27th, so maybe you can take some of my money. Nice. And then finally, on the 28th, ISC² Pikes Peak is doing their April meeting.

All right, good stuff. Let's jump over to jobs. We have some great jobs this week. Um, University of Colorado Colorado Springs is hiring a Director of IT Security and Compliance and Information Security Officer. Yeah, that sounds like a cool job.

Arrow is looking for an Identity and Access Management Audit Assurance Analyst. Uh, you'd be working for, uh, Rishi Singh down there at Arrow. With a callback to earlier in the show, Lumen is looking to hire a Splunk Enterprise Security Architect. Nice. Uh, Zayo is looking for a Cybersecurity Analyst 3.

Swimlane is hiring a Professional Services Engineer Consultant. Yeah, this is not supporting their, uh, their APAC, uh, professional services apparently. Centura Health is looking for a security engineer. Terumo BCT is hiring a product security analyst. RTD is looking for a manager of cybersecurity operations.

I assume you get to work directly for Tim Coogan, which I think would be a pretty awesome opportunity. Tim's a good guy. Yeah. Uh, next, the Colorado Judicial Branch is hiring a lead security architect. And finally, Paladina Health is looking for a manager of IT security, and this job can be remote.

Good stuff. All right. Well, that takes us to the end of the news. We do have an interview this week. Desiree Robinson, who is the senior information security manager for Smarsh, is on the show.

And she was interviewed by Janelle Hsia. We've known Desiree for quite a while. She was the CISO for NREL and moved over to Survey Gizmo, which is now— oh, man— Alchemer. Alchemer. Alchemer.

Yes. So Desiree is, you know, kind of a 3-time security leader here in Colorado. And I'm excited to hear what she's up to there at Smarsh. Nice. I am looking forward to it as well.

All right, well, that's it for this week. We'll look forward to talking to you guys again next week. Thanks, Robb. Hello, this is Stanton Meyer, CSO of CoBank. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.

Welcome to Colorado Equals Security. This is Janelle Hsia. Today I'm excited to interview Desiree Robinson. Desiree is a senior information security manager at Smarsh, so I hope you enjoy our conversation. Hi Desiree, welcome to the podcast.

Hi, thanks for having me. Yeah, absolutely. Are you as excited about spring and the warm weather as I am? I'm so tired of being cold. Yeah, I, I'm actually— I feel like the winter was late to start but late to go away, so I'm very excited for the warm weather.

Yeah, no, I love spring and my, my trees are almost budding. They're like, I think, 1 or 2 more days of warm weather and we'll have buds. So then hopefully we won't have more cold and snow to kill them again.

Yeah. Well, tell us a little bit about yourself. Okay. You mentioned my name is Desiree Robinson. I was raised in the panhandle of North Idaho, Coeur d'Alene, Idaho, small little resort town.

It used to be farming town, mining town. So growing up in that remote area, I had a really liberal education. We were never— I never experienced anything other than if I want to do something, well, I had 2 arms, 2 legs, go do it. And it was just a really great environment to grow up in, especially with the group that I grew up with. We're all Mount St. Helens babies, so we were born 9, 10 months after Mount St. Helens happened.

So it's just a very core group of kids that grew up together and challenging each other, and it didn't matter boy or girl, disability, non-disability, race, nothing. It just— we all grew up together really close, and I think that actually shaped how I viewed life. You know, work hard, work for what you want, and I have 2 arms and 2 legs. So with that in mind, my parents were small business owners and let us know, each of the kids, that if we wanted an education, which they totally supported, We'd have to go find a way to pay for it ourselves. And so I took the long route of working for employers that paid for my education along the way.

During that time, I married someone who was in the military. We were in the Navy family, and we traveled all over the West Coast. And during one of those stations, I just happened to meet the right people at the right time. Get introduced into information security. Uh, and I think it was called information assurance back then.

So it was for the government, started off as a contractor, worked my way up to be, um, going from California weapons testing station there, um, moved to the Naval Sea Systems Command in, in DC and running a team there. And again, I started off as a contractor but worked my way up to a government leader for the team. I ran the research, development, testing, and engineering program for all of Naval Sea Systems Command. And then I worked for the Navy IG, so the Inspector General, going around to these sites and auditing their programs. So it's just very eye-opening coming from remote Idaho, living up and down the West Coast in these tiny little Navy towns, to going to the, you know, Washington, DC, to me the headquarters of the world.

And, you know, dealing with big real-world programs and lots of money and lots of responsibility that comes with that. And it was eye-opening to me. And again, it got to the point where, you know, put even bigger glasses on and see what else is available to me. And again, it was the, you have 2 hands, you have 2 feet, go get it. And so I decided what I wanted to do, and that was management in the the tech world.

So I went back to school and I got my degrees. And then during that time, the Navy Yard shooting happened, and that had a huge impact on my office. So there was a minute where I had to decide what I want to do with my life and for my family. So that's where we settled in Colorado. And I worked for University of Colorado for a couple years there.

And while there, I got my master's degree in engineering management and then decided to leave higher ed and do private industry for the energy industry for a little bit and went back to government and then tried to be a CISO there for about 15 months. And I'll be honest, I missed the work. And so it was another eye-opening situation and decided that what was best for me was, out of all my experience, private industry. So I went back that way and changing titles, changing Maybe the day-to-day, but overall it's been management of teams and leading governance, risk, and compliance programs. And that's where I'm at today.

That's awesome. Yeah. And so I worked for the federal government for a while too. And so when you said that you made a decision, because I know you were at NREL for a while, did you miss working for the federal government and that, and that's why you went back to NREL and then you decided that you didn't like that and you left again? Like, what, how do you know?

Because I know, like, some people love working for the federal government or government in general. And then for some people, it's just like not their cup of tea. Yeah. So when I started in California, and even in DC, I loved it. I loved who I worked with.

I loved who I worked for. I loved what I was doing. And then in DC, I got to see how it impacted the, you know, the warfighter and our military members. And it had a big impact on me of you know, the value of work that I provided helped. Um, but with the government, sometimes things are way too slow, uh, and sometimes they're detrimental.

I remember auditing a program where they had, um, software in place that was better than what was allowed, and we had to make them strip it. So it was a waste of money, a waste of time, and it was less secure, but it was all because of that red tape. And I just remember feeling icky, like that was icky. Then when I came to Colorado with government again at NREL, that was more of a decision of the side of the government that was not presented to me before. So before I led the team, I led the work.

I was still hands-on. At NREL, it was more of a It— I don't know how to explain it other than there was real laziness. And again, too slow. I spent more time creating project date documentation than I did actually performing the work. And so again, it was just that it's too slow, it feels icky.

People aren't willing to do what's necessary to do it. And again, I'm not I'm not saying it's the government, just the people that are in that mentality. There's always a few. And I just decided if that's what a CISO looked like in the government, I wasn't— I didn't belong there. Yeah, no, that makes sense.

And I think going back to your philosophy, you know, of like 2 hands and 2 feet, and just you seem like the get-'er-done kind of girl, right? Yeah. And I've been explained that it's either I'm a breath of fresh air or the bull in the china shop. Because I do come in there and I want to get stuff done. Like, I'm not, I'm not there to ask you how your day is for the first 20 minutes of a 30-minute meeting.

I'm there of like, hey, it's nice to see you. What can we do today to get something accomplished? And that, and that doesn't always sit well with government. No. And that doesn't sit well with a lot of people either.

And I, and kind of to transition, so military and cybersecurity, you were probably one of the few women, right? Those are really both heavily male-dominated areas. And, and to be that, like, just let's, you know, no chitchat and just get it done. How was that perceived by your, your colleagues? Yeah, luckily in California, I started with 4 other females.

So no male was in the group. Very rare. But in that situation, they recruited from within. Nobody wants to live in China Lake, the deserts of California. So they recruited from the town.

So I was lucky there. However, anywhere else I've been, that's not been the case. So in DC, we were probably a team of government— gosh, more than a dozen, but I can count on 3 or 4 women, including myself, in that group. And I would say for my direct colleagues, they were either familiar with me already or got to used to my style quickly. It was the contractors that we worked with, or the other government workers in different departments or areas that we would only work with maybe once a month or a check-in.

And I had developed a reputation of I'm the hardest person to get anything approved, I ask too many questions, I, I expect too much. However, The result of that became any— let me back up a little bit. There are 3 ways to get packed. There's operational, RDT&E, and then what they called PIT. And I didn't do operational, and I did do RDT&E, and I helped with PIT.

Anything that came through my office that we approved and moved on to big Navy got approved first shot. No one, no other department could say that. So there was a reason why it was hard. And, you know, because that puts my name on it too, and I'm a part of it, and I'm responsible for it. So of course I'm going to want it to the best it can be.

And it did ruffle some feathers along the way, but I would say having been there for a few years, it became an appreciation where the other teams did rely on our packages, our templates, our work to get their other work done. Yeah, no, absolutely. And I think that, you know, that's what you hope for, right, is that, you know, your templates and your documents will be used by somebody else. I always say that too, like, steal my stuff if you think it's that good. That's great.

So, and last year you were featured as an inspirational woman in STEM and technology. So how did that come about? Yeah, so at the time I was working for a company called Survey Gizmo, is now Alchemer. And they're, they had a great VP of, or I think he was the chief of marketing. And he and I just got to talking and we just— our philosophies in life were same about work and people and management.

And it was through him that he actually nominated me for, um, the Denver's 40 Under 40. And I didn't make it. I obviously was a nomination, didn't move further. But it was through that and my participation of that program that Authority Magazine had reached out and wanted to do an article.

Yeah, that's pretty cool. So now you're with Smarsh. Sorry. Yes. So tell us a little bit about Smarsh.

Yeah, so Smarsh is— so the best way I explain it is banks, credit card companies, anything in the world or any company in the world that has data archiving and/or capture requirements, they would want to use Smarsh. I believe the number one in our industry. I mean, we outscore everybody. We're always in the top quadrant. Um, uh, we have very— I want to say this is horrible.

Um, I can't say it, but we have so many products. What's great about each and one of those products, it's either capture or an archive or an AI of research, like search in other capabilities. We have all these options, but what's great is that each and every team on Smarsh or at Smarsh in each of those products, they are so knowledgeable about what they do and how they do it and how it could help you. So I don't know if I want to say that we only sell capture and archiving products, but we sell, I would say, top quality service and top security in those services, because that's been my experience on the other side. It's just how much we love and take care of our customers and provide that level of security and assurance for them.

That's awesome. And then what do you— what's your job there? What's your responsibilities? Yeah, so I was hired to be a senior information security manager, so kind of like a team lead at the time. I was probably there 3 months before they moved me up to the people manager of the whole team.

So I was a direct— I was the only direct report to the CISO and VP of InfoSec. He has since moved on to a different opportunity. So right now I'm running the team. And so I do all of the responsibilities of our internally, the security assessments, questionnaires, vendor management, GRC, all the audits. We have our own information security office, channel, Slack and Teams.

We have newsletters that go out. We have the phishing campaigns that we run our group through. We have, gosh, security awareness training. We're part of the onboarding process, and we're there to help wherever we can and with whoever we can. We, we help really every single team, and they help us.

Spread security across the organization. Yeah, and it sounds like, you know, from your history is that once you get into a position, they see how valuable you are and you, you know, you're kind of always given that additional responsibility. And I think that goes back to your work philosophy, right? And that philosophy. And I also, when I read that interview, you had mentioned that you're both a business partner, not just that data cop, right?

And so, you know, I think that goes into your philosophy as well. So tell me more about that. Yeah, it probably started off in when I first got into information security, and in government you are seen as a data cop. You're yes or no, it's black or white, and within government you do have some of that black or white legalese around that protects information security and how it applies to everything. However, in the real world, out in the business world, you know, security isn't always the first priority, or it's a priority but not the risk maybe not outweighs the, the, the issue at hand.

So, you know, sometimes you do have to take that backseat.

So leaving government was a bit of an eye-opener in that reality, you know, because again, black or white. However, I just found myself more at home in that situation of working with others. And that icky feeling I had on the government of black and white, whether it was good or bad, that went away. And yeah, some things don't always get to be the way we want them, but at least I got a voice at the, at the table, a seat at the table. My voice was heard.

We presented all the risks and then people made decisions based on that, and I was a partner all along the way. And if anything, that's what security to me is all about, is presenting it and then weighing the best option. You know, and I would say up until the last couple years, InfoSec was still very much seen as that data cop or that no or that black or white. But the more and more I interview people or get interviewed myself, or I participate in a forum in some way, it really has changed to where we're enablers, we're business enablers, we're your partner. Let's help get you the right, the right path or the right direction.

Yeah, and so I think this leads into what my next question is. What's the best advice you can give to people who are building that security program?

There's so many first steps, but my first step would be, obviously, it'd be the risk analysis of what exists and what needs to happen. But then on that plan of what needs to happen, really get to know who your business partners are across the organization and then reach out to even more people. Because, you know, marketing has been a huge partner to InfoSec because they're the ones who make our reading material and our policies and our public-facing things readable. You know, they are our voice to our audience, and that's not what people think of when they think of InfoSec and a business partner. Another is finance and HR.

They're going to help you get the right people and pay for them because their value in our market is like there's not enough people and too much competition for jobs. So, you know, we want to be able to get the right people and then pay them what they deserve. And so those are partners that, again, people don't think about in InfoSec. But then also, you know, when you're building those relationships, with your product and development and your security engineering, you know, they, they have priorities that may conflict with yours, but it doesn't mean that they're not on the same page or have the same path or don't want to do the right thing. It's just, it may just look different, and it's okay to go a different way as long as you end up there.

So that would be my advice. It sounds like, yeah, it's kind of like integrating security into the whole business. Yes. And, and in your everyday life, like if you're doing it all day at work and it's subconscious after a while, then you're going to, you know, take it home with you. And it's just great business practices when, you know, your kid won't give you something.

Like if you ask— I ask my kid all the time, like, hey, can you tell me your passcode of this so I can check your homework? And he's like, I need to— I need you to prove this is you, you know. So it's— they're good habits for work and then home as well. Yeah, no, absolutely. I love it when employers use that as an opportunity to train their employees at home and then like even offer the training to the employees' families and things because it is, it's educating the entire ecosystem.

So yeah, well, talking about family, you know, I know family is really important to you. So what do you do for like self-care and downtime and take care of your family? Yeah. So for the last 10 years, it's just been my son and I. His father passed away of cancer.

And so we made a pact to each other that we were going to live our best lives and we were going to do it together and we were each other's partner in that. And, you know, he was only 9 at the time. So, you know, he's changed a little bit as a teenager about to graduate high school. But we, we travel, we love to travel. That was one thing that, you know, we're only here on this earth for, you know, whatever destined period of time that consists of.

And so we just, um, we make lists of everywhere we want to go and we pick a time and we just go. And sometimes we get the ticket and head out before we make any plans. And to us, um, that's probably the best because it's whatever adventure awaits. And life is an adventure. Go enjoy it.

Another thing that we do is, or we like to do, is we'll find a TV program or a movie that we're really into. And sometimes we just don't have the time to sit down and watch it together. So, one of us does it, but we have to promise to tell the other person. So, we still, I don't want to say we watch TV together, but we'll participate in the watching. So, somehow and we'll tell each other.

So storytelling and communications. And to be quite honest, I almost skipped the TV watching just so I could hear him talk about it. Get that time with him. Yeah, I know. My son's 20 and my daughter's going to be 19 next week or 18 next week.

So yeah, that end of childhood, beginning of adulthood is so difficult for moms to manage. And then you were a single mom for— or you still are a single mom, right? So yeah, that's, that's in addition to everything else on your plate, that, you know, that's a lot. Yeah. And, and I think that, I mean, when you're facing a situation where you have limited time or resources or funds to pay what you need, it was again a choice of what kind of life did I want to provide for my child and what kind of life did I want to live after or besides him, you know?

Um, and it was, I wanted to give him a permanent home. Um, so no more moving. And then I wanted to give him, um, culture and experience. And so again, that's why we travel. And, um, and so I did whatever I could.

I went back to school, I got my master's so that I can move up the chain, um, or the career ladder and get in these positions that one, I wanted to do for myself. And that took some trial and error, you know, moving up and moving down and moving across sometimes. And then also, you know, have the ability to pay for these experiences and provide him everything he needs. My parents are very similar. It's, what can— what do you need?

I gotcha. Let's work on what you want. Let's help you get there and experience those things. So I wanted to do the same for my son. And I really like that when you say like, I'm here for you, I got you, but what do you need?

I think that's, that's awesome. And the other thing that I usually ask people is about giving back to the community. And so are there things that you and your son do to give back to the community? Yeah, so 10 years ago when his father passed away, we got involved in a program called Tragedy Assistance Program for Survivors. And then again, when the Navy Yard shooting happened, that program actually became very involved with, with our group specifically, my work group, and they had always been really good to us, you know, through my son or through our involvement or their support of us.

And so we've spent the next 10 years trying to support them. We've run their marathons, we've collected money, we've participated in their forums, and we have connected others in a similar situation to the program as well because they have such great resources and other programs and whatnot that are related to them. And it's just, I would say it's very, it's almost like a family member. We're so integrated with that program. They've been good to us that we wanted to That's awesome.

Well, as we're wrapping up our time here today, is there anything we didn't talk about that you wanted to talk about or mention? Um, sure. Uh, it's just more of an idea of like women, we talked about, you know, not enough women are in this career or this area of expertise. And, you know, it's always been a focus of mine of either getting involved with programs that look back at high schoolers or starting in junior high. And we've decided, some friends and I have decided, that it just isn't early enough.

Like, there's too many studies where this separation of that's not a girl's job, or you shouldn't like math, or you're not good at math or science or anything, it starts almost in kindergarten, right? And so we've started looking around and there's several companies, but one in particular that's very close to here where I'm at in Colorado. They're up in Boulder called BitsBox. And they are a program that— or a company that provides coding kits to children. And they're— I understand they're really— they're working right now with the Girl Scouts of America, and they send these kids a box in the mail, and they learn how to code.

And so friends and I are starting to buy them and send them to our nieces and our friends' daughters and as gifts, because who doesn't— what kid doesn't want something in the mail, but then also get introduced to how to code and build something? I mean, it's like a technical, technical Lego set. It's just so fun and exciting. And so we just wanted to do something ourselves. And so yeah, just wanted to bring that up of, you know, there's more, more to come, more More Girls to Grow.

Absolutely. Oh, I absolutely love that. And I need one. I've got a couple nieces that I will absolutely send that to. Great.

I'll send you their information. Yeah. And I'll actually— so if you send it, we'll have Alex put it in the show notes so that they can get even more. Great. Awesome.

Yeah, no, that's great. And then how can people find you? So I'm either on LinkedIn or Gosh, I'm never on any of the other things, but I'm in— I'm involved in the Colorado Equal Security, the CISO dinners. I'm a member of the group, the Slack channel. And then reach out to me on LinkedIn.

Say hello. Awesome. Well, Desiree, it has been a pleasure talking with you. Thank you so much for your time. Yeah, thank you.

I appreciate you inviting me. Yeah, absolutely. Well, with that, that's the end of our interview. So until next time to everybody, thanks so much for listening. Hi.

Hi. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security. Security.

Back to all episodes