All episodes

Kim Decker, Privacy Program Manager at Ping Identity

Apple Podcasts Spotify SoundCloud

Kim Decker, Privacy Program Manager at Ping Identity, interviewed by Janelle Hsia. News from The Last Gameboard, Coalfire, Swimlane, CyberGRX, Webroot and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10541 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 211 for the week of May 17th, 2021. Alex, we were just saying that this is the first time in like 4 years, 210 episodes that we were recording at your house.

I know, um, it's kind of weird. The first episode was recorded, we were just saying, up in, uh, in my younger son's bedroom. We, we put a card table and a couple chairs up there and, and recorded the first episode. And ever since, we've had our studio, sort of in quotes, there at your house. And when we're in person, that's usually where we record.

Yeah, the, uh, we are now in your— what do we call this? The bar shed? Yeah, the woodshed. The woodshed. And we're drinking some alcohol and, and we have some dogs running around.

If there are dogs in the background, um, well, you're welcome. Also, um, you know, coincidentally, my neighbor across the street is blasting reggae music. So if you hear a little reggae music in the background, that, that's why. Yeah, uh, it's, it's probably not loud enough for them, but it's definitely loud enough for us. We can hear it, but you guys probably can't hear it.

All right, well, let's kick off this new episode with some housekeeping, one of our very favorite things to do. We have a Slack channel. If you guys want to join the conversation, go out to our website and click the Slack link. That'll give you a chance to let us know who you are and get you connected with the group. Yeah, we also have a mailing list.

While you're on the website, go to the mailing list form, put in your information, and you will get one email every week with the show notes delivered to your inbox. We would also love it if you would rate us and subscribe on your favorite podcatcher, whether you like Apple Podcasts or Google Play or Spotify or any of the other ones. Yes, go out there, say nice things about us, get it and subscribe so it comes into your inbox every week and we can grow the community here in Colorado. We'd also love it if you told a friend, let them know how great Colorado Equals Security is— the website, the event calendar, the podcast, everything, the Slack channel. Just tell them that they're missing out and they should come join us.

And finally, we do have a Patreon campaign, and I just want to do a big thank you to those who currently support the show financially. You know, for, for, you know, the first 2 or 3 years, Alex, we were paying just about all of the money for this out of pocket, and these, these folks have come along and supported the show, and they're covering most of the cost of what we do, and we really appreciate it. If you want to get on the bandwagon and help support the show financially, go out to our website and click on Patreon and And you can, uh, you can be one of our supporters. And, and if you give— I don't remember what the levels are— $5, you get a shout out on the show, and $10, I think you get a t-shirt. Yep.

And, uh, we'd love to send you one of those t-shirts. That would be great. All right, let's jump into the news, Robb. Uh, question for you: is Denver the most dog-friendly city in the country? Well, you know, Alex, I have the survey results that say it actually is now the new— the most dog-friendly country.

Or city, you know, city, country. I'm sure out in the country, yeah, it is dog friendly too. Um, yeah, so Denver was number 1. This was based on taking some, uh, data from a site called Rover. Uh, apparently it's a, a dog owner's site, and so you can register there that you have a dog.

And looking at that, the new accounts created in Rover, it looks like the most of the people are coming from Denver, so Uh, that means we're number one. Yeah, they also did some Zillow data, and basically people who moved during the pandemic— I think the general population was like 10% of people moved, and in the dog owner population it was much higher. It was like, what, 24% of people had moved over the last year? And a lot of those folks, uh, 62%, had considered moving specifically for their dog. Yeah, that is pretty cool.

I guess, you know, along with, you know, considering what your job is and everything else during the pandemic, you're considering, you know, what your dog's life is too and making sure that they're, they're being accommodated. Good stuff, Alex. There was a— I think you had a favorite stat from this. You want to— yeah, so, uh, my stat was homes with a doghouse sold for 3% more than expected last year. So if you are getting ready to sell your house, um, well, you're gonna get more than you expect in Denver anyway, just because that's how it is right now, but I say, you know, go out and spend a couple bucks on a doghouse and, you know, that 3% of the sales price of your house is going to be more than worth whatever it is you pay for the doghouse.

My guess is that probably not one of those molded plastic doghouses. You might need to spend a little bit of time and put something together, make it look kind of nice, kind of a Snoopy doghouse if you were. Yeah, don't make it out of wood though because lumber is really expensive right now too. Yeah, that 3% might— you might not make enough back to pay up for the wood. Yeah, exactly.

All right, moving forward. Uh, Alex, did you know that— was it yesterday or 2 days ago— Governor Polis made some pretty big changes to our mask requirements here in Colorado? Yeah, um, Robb, I heard COVID is over, we can just go about our business now. I did not hear that. Oh, uh, but I did hear that, uh, they're removing the mask requirements for vaccinated people and the social distancing requiring for, uh, for vaccinated people.

And this is, uh, is interesting, and it has some pretty significant implications for real restaurants and hotels. And there's an article here from the Denver Business Journal talking about those industries really trying to navigate these new requirements. Yeah, so when counties are moving now to the level clear, basically that is removing the restrictions for restaurants, at least for most things at restaurants. So you don't have to have the 6-foot distance between tables anymore. You know, people don't have to wear masks.

And And so I think that that's gonna be a boon for those restaurants, right? Because even when they were open before, being able to space tables accordingly, you know, especially restaurants that are, you know, weirdly shaped or not really made for that kind of thing, you know, you're really limiting the amount of people that you can get in there. So I think that all the restaurants are looking forward to being able to go back to full capacity. Yeah, there's a number of other interesting kind of quotes and facts in this story. The Colorado Restaurant Association president, Sonia Riggs, talked about the fact that the, the industry lost about $3 billion in revenue last year, which is— that's not nothing.

$3 billion. That is a material number. Yeah. And especially when you consider that, you know, most of these, you know, most restaurants are just individual establishments, you know, mom-and-pop type places who certainly can't handle losing a whole year's worth of revenue. They do expect that this is going to help them get back on track.

And those people who made it through, this can make a big difference. But there's another concern that this article gets into, which is even though they're going to be able to reopen again, they may not have the staff to be able to support it. Yeah, there are still federal benefits for people that are unemployed, and they're talking about extending those even further. And so actually, the— what were the 2 groups? There was the Colorado Restaurant Association and the CHLA.

I'm not sure which the CH LA is, but they were, uh, they're crafting a letter to the governor to say, hey, uh, we think if they continue to extend unemployment benefits that you should refuse those benefits, uh, because right now people are still willing to just stay at home and not work and, and keep those benefits. So, uh, they need to, to get people back to work and have the appropriate staff to be able to open up to full capacity. CHLA is the Colorado Hotel and Lodging Association. That makes sense also. I do think that this is a somewhat difficult, it's a thorny topic.

We've had conversations in Slack about this, that hey, if you want more people to show up to work, pay them more. That's a fair point, but the market is not, it's not a real capitalist market when the government is paying this additional unemployment to kind of subsidize not taking a job. So it's an interesting topic. It's interesting to see these local business owners who are saying, let's stop this unemployment so we can get people back in the workforce. And I don't know what the right answer is, but it sounds like a tough challenge to navigate.

One more thing, we aren't completely regulation-free just yet. So for events that are 500 or more people that don't have 80% of those people vaccinated, then you're still under those similar requirements that we had previously— masks, distancing, and that kind of thing too. So if you are a restaurant that is, that is going to have, you know, potentially a large wedding or some other kind of big event, you still have to use some of those guidelines, and this is leading to a little bit of confusion about what's going to happen with those things. It— that's extended through June 1st. Well, if you're going to a Rockies game, if you're going to go to a Red Rocks concert, like, those are, those are venues that would still have these requirements.

Yeah, so not quite out of the woods yet. Uh, all right, next, uh, the Denver gaming startup that we've talked about before, The Last Gameboard, has raised $4 million to bring their, uh, tabletop game board to life. Yeah, I remember us talking about them a year and a half ago maybe, and it was like a Kickstarter where basically you could get in to get this super awesome interactive flexible game board to get on the list for it. I'm a little disappointed to know that, you know, a year and a half later they haven't actually shipped any of them yet, right? But they, but they did just raise a whole bunch of additional money and Um, so that they can actually start shipping and getting those things out to folks.

If you haven't taken the minute to look at what the— what's the name of the company again? The Last Game Board. The Last Game Board. If you haven't looked at how The Last Game Board works, you should just spend the 2 minutes on their website. It is really interesting.

You know, you can play things from as simple as chess, play chess on it, to playing Monopoly, to playing Dungeons and Dragons and all kinds of other games. And it's smart. You'll be able to move your pieces and the board will know that you've moved your pieces. And, and I would imagine, although I don't think I caught this on the article, I would imagine that with the pandemic they've, they've, they're interacting 2 different game boards. So Alex, if you have one and I have one, we could virtually play chess on our game boards.

And that's a pretty cool idea. Yeah, so it's a, it's a 16 by 16, uh, basically LCD, uh, screen that you use for the game board, and it has a, you know, a companion app for for iOS and Android and things like that that you can use to interact with it. Also, they were launched in January of 2019, so it's been a little over 2 years since they first launched. So time goes fast. Yes, it does.

All right, next story. This is a follow-up. I feel like we've talked about this, what, every 4 months for the last— yeah, something like that— 4 years. This is an update on the Front Range passenger rail plan. Um, but you know, the news is starting to, to come a little more serious and coming a lot faster.

Um, so the, the, the proposal for building this, this, uh, what do you call it, like a tax district, taxing district, um, that's really the, the big differentiator here. If you remember from our last conversation, they're proposing we create a taxing district kind of along the 25 corridor where they're going to put the train, and, and as a result, they'll be able to raise the funds to pay to pay for the train. Well, this proposal is called SB 238, zoomed right through the Senate, and the expectation is that they will not have any problem passing the much more democratically controlled House of Representatives. So presumably this is actually going to become a law this session. Yeah, and keep in mind that this just— it does just set up the taxing district.

So basically, when there is a train, you'll have a way to fund it. It doesn't necessarily pay for the building of that train. Some of that is expected to come from federal stimulus money. I imagine some of it could get paid for through that taxing district. You know, once the district is in place, then you could implement a tax to help pay for the building of the train.

But right now it is just that, that taxing district. And this also, for those that didn't hear the last time we talked about this, the proposal is for the train to go all the way from Wyoming to New Mexico. So it's going to be the entire state north to south. So you could, um, you know, essentially go from Cheyenne to— I don't know what's just across the border in New Mexico, you know, Raton, Raton, New Mexico. There you go.

So you can go from Cheyenne to Raton. Yeah, with stops along the way. So that would be pretty cool. That sounds good. I gotta tell you though, and I maybe I said this last time, I don't remember, uh, every time I hear about this, I think of The Simpsons episode with the monorail.

The guy who comes to town, monorail, monorail. Yeah. So, uh, do yourself a favor and watch a YouTube video of The Simpsons monorail. Wasn't it a, was it a play on Oklahoma? Is that what it was?

It was a play on something like that. Yeah. Spoof on something where he brought the monorail anyway. Uh, all right. Uh, next, uh, the speaking of laws, the significantly amended Colorado Privacy Act has also passed out of the Senate.

Senate committee now is going to be heard by a different committee and hopefully keep moving on. The original version of the Colorado Privacy Act kind of got stalled, and I don't think there was a chance for it to actually get passed. So there have been a number of amendments made to it, and now it seems like maybe with the new amendments, people are going to be a little more amenable to getting it passed. Yeah, so interestingly enough, this article from Bite Back Law was written by last week's guest interview, David Stauss. We've had David on the show a couple of times, I think, over the years.

And this, this is interesting. I was— I got to tell you, the way this was written, I'll just read the key point. The Colorado Privacy Act passed unanimously out of committee last week, but not before lawmakers revised many of its pro-consumer provisions to pro-business. Yeah. So like the theme of this article kind of bummed me out.

You know, there's a lot of examples of where previously the initial version said there's a right, they required an opt-in for processing data, and now it's a right to opt out. There's another example of what the definition of data that's gonna be sold, making it more specific and harder to get. Uh, the fact that I can require a company delete my data, but I can— but now the new version, previous version said delete all data about me. The new version says only data that I provided to them. So any data that they, they gathered on their own or they created on their own, presumably would— I would not be able to opt out of or have deleted.

Like those things kind of all, yeah, they're a little bit of a jab. We're going to pass this thing. It's going to be watered down. There was one good piece of news I thought in here, which is that the— there was a requirement that— I'm looking at the article for the details, but I'll do it from memory. There's a requirement in the provision that consumers would be able to do like a browser setting for opting out of cookies and so forth.

And that's a nice thing. Rather than having to like manually click a button, I can do a browser setting where I just do it for all these sites. Yes, I would much rather have that than every site that there is now where it pops up and asks me if I want cookies or not. You know, being able to universally set my browser to my preference and then just have the site accept it would be much nicer. Also, the amended version added a right to cure, which is probably technically pro-business, but I think, I mean, in my mind, I think it's a good thing also.

You know, so if you think someone has violated this law, then the Attorney General will reach out to the business and say, hey, you've got 30 days to fix this problem. Otherwise, then, you know, they can continue on with the other provisions, right? So, yeah, it may actually result in people fixing their security, right? It might actually result in things getting fixed, but it may also just result in the process getting delayed and you having to wait for, you know, your rights to be taken care of. If you think of any of these laws as being like a way to get significant money, you're thinking about it wrong, right?

These laws should be there specifically to make businesses act in good faith and like make things better. So I agree with you that the right to cure is probably a good thing. Instead of you getting $50, they're going to actually fix the problem, right? It should make things better in the long run. Yeah, and it seems to me even with this being watered down a little bit and being more pro-business, it's probably still better than where we are today, which in the end, if that's what passes, I think that's probably a good thing too.

Yeah, good stuff. All right, let's move forward. We have a press release from Coalfire this week. For the first time in their— oh, we get to hear a little bit from Fez. This is Alex's dog saying hello.

For the first time in Coalfire's 18 years in business, they have hired a chief product officer. Yeah, so That is very interesting and congratulations to them. So it is Vineet Seth, or maybe Seth, I don't know how it's pronounced, but he is now the Chief Product Officer. He comes from BitSight. And I think that the most important thing about this article is that we now know that Vineet is a visionary leader and a force multiplier.

Well, if you can hire a force multiplier, You pretty much have to, right? I don't, I don't know how you can pass up on that. We love press release language and making fun of it is one of our favorite things. But I will say that there was an interesting part about this. I would say that the, the unique thing here is if, you know, maybe this news kind of passes over most folks, but Coalfire is a services— is historically a services company.

They mostly focus on like audits, compliance, you know, FedRAMP type stuff. And this is, you know, them building out and kind of doubling down on that product side of things where they do compliance scanning, penetration testing, attack surface management. So they did that, but right. Yeah. So there you go.

So Vineet is, is really kind of going to lead up these product offerings versus the service offerings. And I don't know over time if, you know, if they see that maybe they're maybe right today they're 90/10 and 90% services and 10% 10% products. Well, maybe they want to shift that over to 60/40 over time, and he's going to be there to help do that. Yeah, I mean, I can, I can totally see, you know, the, the products or the services that Coalfire offers, many of them could be productized, and you're delivering it with software as opposed to delivering with people. And theoretically, software is a lot cheaper to deliver than paying people to do it, right?

So if you can, you know, penetration testing is, you know, one of your big things. If you can develop a platform that does some of that in automated manner and more consistently and things like that, and, and, uh, you know, be able to deliver it better, more consistently with fewer people, that seems like a win for Coalfire and for the consumers. Seems like a win to me. Yeah, good stuff. All right, next, um, Swimlane and Elastic have announced a partnership, uh, to deliver an extensible framework for security operations.

Yeah, so we, we know Swimlane is the, uh, I was— it's Colorado-based security orchestration, automation, and response play, the SOAR company. We've had Cody on the show, and, and let's just give a quick shout out, they paid for the Colorado Equal Security stickers that we, that we got when we changed our logo last year. Thank you to Swimlane. But they do some really cool stuff around automation, and they are partnering more closely with Elastic, who is the, you know, Elastic is an open source or The ELK Stack is an open source solution you can use for log management and kind of a build your own SIEM solution, but Elastic builds a whole bunch of stuff on top of it as a company, so it's open source, but then they have their commercial version as well, and the integration between these 2 is probably a really nice way to increase optimization for your security operations. Yeah, and I think some of it, you know, they're gonna help develop metrics and other things that, you know, Swimlane provides as part of their platform that you can use integrate with the data that's coming out of Elastic, you know, automation obviously, and then also, you know, more compliance and audit capabilities.

So I think it sounds like a good thing for both companies. Yeah, you know, this is a press release, so I probably shouldn't be disappointed that there wasn't any details in here, like, yeah, well, specifically what are they doing? Like, what is this orchestration or the integration between these 2 companies look like? There wasn't enough detail here, but as someone who, you I've had a pretty significant ELK deployment in my career, and I would love to understand how, how, how these, these integrations are going to make it easier to get stuff done. Yeah.

So I just looked, we had Cody on as an interview on episode 80, so it's probably worth our time to go back. We need to, we need to tap those guys and get them back on. Yep. All right. So next we have some news from CyberGRX, another press release.

It's a big week for press releases here. Um, CyberGRX is, is the way I look at this. I'll read the headline first and I'll give my summary. So the CyberGRX attack scenario analytics are to provide critical cyber defense insights. I don't know what that means, but what I think is going on here is they have mapped their entire third-party assessment process over to the MITRE ATT&CK framework, and they're, they're starting to give you better insight into Okay, as a— as you look at a vendor or your own company, kind of depending on why you're using CyberGRX's assessment, you can look and map it to it within, within the ATT&CK framework.

Which of these parts of the ATT&CK framework are we strong with? Which are we weak with? Or, or which is this vendor who I'm considering using, what are they weak at? And it helps you figure out what new controls that you could put in place to help mitigate that risk. Yeah, I think that that is pretty cool.

The other thing, not related specifically to this, it just occurred to me, RSA is next week, so I'm sure all these press releases came out this week. That's a great point. Everyone is preparing for RSA next week. Yeah, there's gonna be a bunch of press releases. There will be many more next week, but these are the ones where it's like, we want to get noticed before RSA, so we're going to release it this week and then maybe everybody will talk about it next week.

Um, but, uh, but I think that the MITRE ATT&CK mapping is pretty cool. Um, you know, theoretically you could use that to then say, oh, um, I, I see that this this company, um, you know, is weak in these areas, maybe as part of the contracting process we need to require that they do, you know, XYZ controls to mitigate these things that we know, um, you know, based on these, these attack patterns, that, um, these are the controls to help fix that. Yeah, if you think about where CyberGRX sits in the, in the security program, most companies use them as a part of their own third-party risk management. You know, if you're, if you're looking to buy Picking Identity or Webroot or LogRhythm or Red Canary, you're gonna use the CyberGX platform to see how secure they are. Well, that's great.

Now you can see specifically where on the kill chain they're weak. And then like you said, you'll put some controls in place to mitigate that. I think it's a really nice enhancement for them. All right, last news story. This comes from Webroot, actually Webroot plus Carbonite.

And there's a third company in there somewhere. Uh, maybe OpenText. OpenText. Yeah. Now it's like the parent company is OpenText now.

Yep. Yep. Uh, so this is another NFT explainer. So for those of you who have gotten— haven't gotten enough talk about NFTs, uh, this is another article talking about what they are and, uh, how they work and things like that. So, uh, I don't know that there is anything novel in here, but I think that the definitions and the way that they go about talking about NFTs in here are interesting.

And if you're still having problems grasping what an NFT is or how it exactly works, I think there's some good detail in here. So I threw it in here, number one, because I think we could all use another reminder about NFTs. But number two, because they actually do think about this from a security perspective a little bit, and specifically around NFT theft and what kind of cybercrime has come around that new burgeoning industry. And unsurprisingly, uh, there have already been thefts of, of NFTs that people paid for. And once it's gone, it is gone.

That is the, the new blockchain world we live in. Yeah, yeah. So they, uh, as part of this, they show a tweet from someone and it says, update, looks like I can't get my NFTs back even though fraud has been confirmed and I know exactly where they are. Uh, I can't get them back. Hacker wins.

Secondary market purchaser wins, I lose. So another example of where you need to be very careful and secure your assets, whether they be digital or physical. Yeah, their recommendations are, hey, turn on 2-factor authentication. And, you know, it's just the really basic stuff. But, but, you know, thinking about if they get stolen, it's— it is gone.

Yeah. Well, I mean, you hear periodically about people who have had a crypto wallet with, you know, millions of dollars in Bitcoin. They had one, you know, however many years ago and forgot about it. Now it's worth millions of dollars and they can't find where the wallet is or the password to it or, you know, whatever it might be. And this is— it's a problem that I don't think people thought about going into it.

Yeah. And, you know, something that has to be solved some way going forward if these things are going to continue to exist. All right. Let's zip over to our events. As a reminder, we do have an event calendar on the website.

Diligently each week I look through, look for all of the best security events coming up in Colorado. We add them on the calendar so you can, you don't have to go out to our calendar and you can see all the stuff coming up. And the next 2 weeks we have a couple things coming up on the 18th. So May 18th, first of all, we've got the ISSA Colorado Springs May meeting, and also we have the Cloud Security Alliance May meeting. On the 19th, OWASP is doing their May meeting.

The 20th, we have ISACA Denver getting together for their May meeting. On the 22nd, ISSA Colorado Springs is doing one of their mini seminars. Those are great if you want to get a few hours of CPEs on a Saturday morning. On the 26th, ISC² Pikes Peak has their May meeting. Nice.

That's the last event, isn't it? Yeah, uh, and then we've got Memorial Day, and so there's a little gap there. So it's almost June. That's crazy. All right, with that, let's jump over to jobs.

We've got some great jobs this week. First job post we have is from GHX. Robb, do you know who GHX is? The Global Health Exchange, you mean? Oh, the Global Health Exchange.

They are looking for a VP of Global Cybersecurity. That's, that's a big job. Yeah, global. Red Robin. This is a repeat, but it's still open several months in.

Red Robin is looking to hire a new Director of IT Security. Dish Network is looking for a manager of information security risk management. Risk manager. They're a risk manager. Parenthetically, yes, it's kind of a funny one.

Uh, Xcel Energy is hiring a cybersecurity analyst. Charlotte's Web is looking for an IT security and controls analyst. I believe Charlotte's Web is a marijuana CBD kind of company. If you like to— if you're that kind of person, then maybe this job is for you. There you go.

KPMG is hiring a lead specialist cybersecurity focused on identity and access management. Blackbaud is looking for a cybersecurity governance and customer trust senior analyst. I don't think I knew that Blackbaud had people in Colorado. I didn't either. Universal Studios is hiring a cybersecurity manager.

Invoca is looking for an information security analyst, and that would be working with our friend James Brown. We had James on the show on episode 204 at the end of March. You get to work with James. I think you'd like that. Get down with James Brown.

There you go. And finally, the last one's a little bit different. Western Governors University is hiring for a program mentor focused on cybersecurity. I wonder what that means exactly. I don't know.

I don't know what that means, but it sounds interesting. Yeah, it sounds fun. We could spend the 12 seconds to click the link and look at the job description, but yeah, we didn't. Maybe I'll do that while you talk about what our interview is this week, Robb. Alex, this is an interview that's near and dear to both of us.

We have an interview this week with Kim Decker. So Kim is a career changer. You're going to learn about this in the interview, but Alex and I have a vested interest here. Yeah. Kim was an intern for you at Pulte, right?

She was. Yeah. And then, and then I hired Kim as the security program manager at Ping Identity, even though you said terrible things about her. I did not. I said no such thing.

To be honest, Alex's recommendation. Was the, the reason I hired Kim, and she did a fantastic job doing that. And now she is running the privacy program for Ping, and Janelle Hsia sat with her this week, and we're gonna get to hear all about Kim's career progression and, and what she's thinking. So before we go, I just want to give you guys an update on the program mentor job here. Program mentors have specialized content expertise which they use to coach and guide students through courses and programs.

So it sounds to me Like these are sort of, you know, potentially industry people, like an advisor, like an advisor that can help people through like a cybersecurity. It's a great idea. Western. It's a really good idea. Yeah, that does seem like a good idea.

Cool. All right. Well, that is it for this newscast. Stay tuned for the the interview, and we'll talk to you guys again next week. Thanks, Robb.

Hi, this is Chad Payne, Executive Director of IT Operations for Kraken Sports and Entertainment. Welcome to Colorado Equals Security. For Colorado security professionals by Colorado security professionals. Welcome to Colorado Equal Security. This is Janelle Hsia, and today I am excited to be interviewing Kim Decker, and I hope you enjoy our conversation.

Kim is the privacy program manager at Ping Identity. Hi, Kim. Welcome to the podcast. It's early here on Friday morning, so how's your day starting out? Busy.

I don't know if I'm like everybody else where you get out of bed and say, "Oh, I'll just check my email really quick," and then you completely miss. Breakfast. But yeah, that's what happened this morning. Oh yeah, I know. I've been doing some work with, with companies in Europe, right?

And so they get up early. So I had like 5 emails that they sent at 3 AM. So I totally feel your pain. Work from home, you got to balance the right on and off time. Yep.

Well, tell us a little bit about yourself. I know that, you know, you've had a very varied background. You've owned a couple of companies and have some PhD work in there. So What's— well, tell us the story of Kim. Yeah, well, thank you for having me.

Yeah, my story is pretty varied.

As people who know me will say, I have a tendency to get a little bit bored, so I like to try new things all the time. And I'm particularly addicted to learning, which is interesting because I am— one of, I guess, the rare people today in business who didn't leave high school and go straight to college and get their degree before pursuing their career. I didn't know what I wanted to do, and so I didn't finish college and actually fell into a job in the tech field. In fact, it was in the Macintosh market when the Mac was just really getting launched. And so I have spent most of my career in technology working mainly for software companies, but I've done just about every role for a software company that you could imagine.

I've done everything from managing bookkeeping and accounting. I wrote documentation for several years. I think I've written about 10,000 pages of software manual documentation. I managed marketing and sales teams. I've done product marketing and product management, and then at Ping, I started off in the security team doing security program management and then recently moved into privacy.

So probably of my I don't know how— I can't even count how many years it's been— 30 years in the work world. The most of it has been in the software industry, but back in my late 30s, I did take a hiatus from the business world and went back to school to get my undergraduate degree, which I got in biology. And then I was really enjoying research. I had done a research internship for the summer, so decided to pursue a PhD in molecular biology research and, and really tried to jumpstart a career in research, but it's a really difficult field to be successful in, particularly if you're a, um, middle-aged mother. And, um, because I graduated with my PhD on the same day that my daughter graduated from high school.

Wow. So, um, in that field, they really want you to move around to different universities to do research for very, very little money, and it was really difficult for me to ask my husband to continue to support me financially while I— we traveled around to random places and asked my children to move schools and uproot their lives, so I decided that that really wasn't a realistic career to pursue and kind of came back into the security— I mean, into the software side of things again. And that's sort of how I ended up here at Ping. That's awesome. And I mean, we kind of relate, right?

That whole technology and then that middle-aged mom thing. So I can totally relate to that. But I'm fascinated, that PhD work that you did, So I, you know, I think that is just kudos to you for going back to school to do that, especially while raising a family. Um, and I bet there was a lot of things that you learned in that that you can transition into the business world, right? Um, from the technical and privacy security things that you do now, um, like critical thinking skills and things like that.

Yeah, I think that there's, there's a couple of things that you really have to learn in a PhD program that that I wish people had the opportunity just to learn in everyday life, and one of those is critical thinking, and it's almost a rite of passage. They don't make it easy, but they really force you to think critically about, about things in science because obviously nothing is— there's really no facts per se. It's all, you know, where does the evidence point. The other thing that I think is really interesting about science is you get paid— not a lot of money, but you get paid to sit and think. So you are given and are expected to take opportunities to just sit down and think through problems and, and how to solve them and, and what might be causes of things you're observing.

And That was probably the— I think the real luxury of science is we aren't in business given a lot of opportunity to do that, and a lot of people don't. It's not just having the opportunity, but it's knowing how to do that and having some experience sitting down and just thinking through problems and coming up with innovative ways to solve problems. I think that those are probably the 2 things I really learn most. Well, and project management. Obviously, you're managing your own independent projects.

You better be able to manage projects because they don't teach you that. They just expect you to do it and know how to do it. So that's probably the other skill. Yeah, I think all 3 of— I think all 3 of those skills— project management, learning that critical thinking, and then, you know, kind of being addicted to learning something new— I think those are all 3 things that we need in security and privacy because That is— that's how people are successful. So how did you get started at security?

You mentioned that you were at Ping, but how did you actually start in security? What led you to that field? Well, after I made the decision that science wasn't going to be a realistic career approach for me, I did a number of other things. Like, for example, we built a house and then we bought a historic house, which I did a lot of the renovation work on it. So while I was unemployed but still working quite physically hard at the time, I was trying to decide what my next career move would be and what— and I really wanted to do something that was different and interesting.

And I spent a lot of time thinking about a lot of different ideas from starting a small business like, I don't know, just a home business or even going to cooking school. I thought about a ton of different things. And I kept kind of coming back to wanting to leverage the experiences that I'd had, you know, over the years in technology. And I just doing research on the internet started looking into cybersecurity, which obviously is kind of a gamified field, if you will. There's always intrigue and mystery.

And of course, I was attracted to that, like so many other people, and started looking at how I might be able to get into that field. And I initially thought that I would, with all my experience, not have too much trouble applying for jobs, but It— I just wasn't getting anywhere with what I thought was a pretty comprehensive resume, so I decided I needed to learn a little bit more about the field, but of course I didn't want to go back to college and do a 4-year degree for a couple of reasons. One, I already had plenty of degrees. I didn't need a degree, and I wasn't a spring chicken. I didn't want to spend 4 years of the short remaining amount of my work life that's left you know, studying things I didn't necessarily need to learn about.

So I came across SecureSet. I looked at quite a few different cybersecurity boot camps out there, but came across SecureSet, which is here locally in Denver, and I decided to give that a shot because it was a kind of an intensive 6-month program where you could learn, you know, a lot of technical things about security in the field, as well as things related to compliance as well and privacy, and I think that the real benefit that their program offered was help finding a role within the local community, so, you know, I mean, people have mixed opinions of boot camps in general, right? They're not— I know what I paid for tuition there, and I can extrapolate mathematically the number of people in my class, how much money they have to pay their instructors, and, you know, it wasn't difficult for me to figure out that a lot of the instructors there were not there because they were being paid highly. They were giving back to their community. It isn't necessarily that you you're getting world-class education in a boot camp situation.

But I think what the skill that I have is I know how to teach myself and fill in the gaps. So I don't expect a program to do all of the work to get me the knowledge that I need. And so for me, SecureSet was, was a great, a great way for me to try to understand what I needed to learn and, and have that dedicated 6 months of full-time effort into getting the knowledge I needed and working with around people who had the same desire, and then, you know, getting that help to, to find a role within the security community. So it was a really, a really good experience for me. Well, and I, and I appreciate you saying that, and a shout-out, we do actually have quite a few SecureSet teachers that listen to the podcast.

So thank you so much for that, because it is a huge shout out. And the teachers that I know that teach at SecureSet, they do it because they have a passion for it. And so I appreciate you saying that. And so what was it like, you know, we've already said kind of middle-aged mom, what's it like going back to that sort of environment, that learning environment? And again, security is mainly a boys club.

What, what was that like? Um, I found it a really, really wonderful experience. Um, I enjoyed being there every day. It, it's funny because when you're in like high school, you know, you're, you're there to learn, but you have all your friends and you have that experience where you're— that social experience where you bond with people over a long period of time. Well, I mean, it's been a long time for me.

I've kind of forgotten what that is like. And unexpectedly, that experience replicated that friend-building experience from when I was a child. And I ended up coming out of there with a pretty strong handful of really, really close friends that got to know really, really well. And that was just— it was just— it made going in there a pleasure every day. I just— I looked forward to getting in the car.

And I had to drive downtown. I lived in Castle Rock, so it was quite a commute. But boy, it was, it was a really great experience for me and learned, learned things about myself that I didn't know. Really, really enjoyed the cryptography module that we— modules that we learned, and, and I guess maybe that appealed to my scientific side. Really, really learned a lot from the GRC side, which was taught by Mohammed.

Yeah, he's awesome. He is awesome. And, and then a lot of the web, the web-based kind of vulnerabilities and building secure web-based apps that Serge taught, which was also awesome. I mean, it was It was a really great experience all around, and it really does help to have an opportunity to be immersed in something because that's really what it is. You're there, you know, 5 days a week, all day long, and you really get that opportunity to immerse yourself in, in a topic, which I think is a great way to learn.

That's awesome. Well, you're at Ping Identity now, so tell us a little bit about Ping. You know, and I know that you— Robb has left Ping Identity, but you, I think, worked for him. So what's Ping Identity like? And, you know, yep, we're all very sad right now because Robb left and we don't know what's going to become of us.

But, um, we have a really great, uh, security team that Robb largely built at Ping. Uh, it's made up of 4 teams, if you will. There's the GRC team that obviously handles compliance, and the privacy program that I manage is a part of that, and we also have incident response, and the one thing that I think is really neat about this team that I don't think is done in a lot of different organizations is that we have a sales support group within our team. Of individuals who, amongst their other duties, they actually answer specific security-related questions that come up from our prospects and customers. As you can imagine, enterprise customers really take a deep dive into the security of any software organization that they're going to engage with, and so they're always asking all of these quite detailed questions about what we're doing and what our policies are and what our certifications are, and So we have a number of individuals that work incredibly hard to answer those questions.

And even though they're not salespeople, you know, they still recognize the criticality of getting these questions answered in a fast period of time and being really, really responsive because obviously that has an impact on our ability to get those sales is that response time. So, that's the team I'm part of right now, which is a great team. We also have a pretty large product security team, and the individuals there focus on making sure that our products are developed from the ground up in a secure manner, and they work directly with the different product teams, so they're kind of embedded, and they also work at getting security champions from the development team to engage in those security activities as well. Well. So that's a really great team full of some strong technical individuals.

Then we have an infrastructure security team that really manages the monitoring of our environments and, you know, events, security events that pop up here and there, and working with the incident response team if, if and when there was something of concern that were to happen. And then lastly, we have a security architecture team that is composed of a couple individuals who are very, very knowledgeable and focused on evaluating architectures of products, approaches, you know, technical approaches to solutions we need to implement, or new technology that we want to take on and make sure that the appropriate security controls are in place and that things are designed in an architecturally secure way. So It's a, it's a really great department with really great culture. And yeah, I've been there about a little over 3 years now, I think. I'm at that point where I'm starting to lose track of time.

And yeah, I've loved every minute of it. And it is really sad to see Robb move on, but it happens. It does. And he said it was time. So Yeah, well, thanks for explaining the security breakdown at Ping because I think, you know, that knowing how it's broken down and it sounds like each department has its focus, right?

Its own focus and kind of it highlights as well how security, you know, it's not just one hat that people wear and the fact that you have specialists in these different areas. But kind of diving into the privacy piece since that's what you run is the privacy program. So what would you say are the current privacy concerns or trends that the identity industry is thinking about?

Oh, wasn't— I went through that question in advance. Well, because you mentioned the security-related questionnaires that are in the sales support teams, right? And I mean, all of us answer those questionnaires. I think that's like the bane of some of our existence. And so kind of like, I'm just curious, like, what are, you know, Are there any new things, trending things that people are concerned about from an identity perspective?

Because that's really pings, you know, that they, they authenticate and make sure that people are who they say they are. Right. Um, I, I think, I think this is probably true for our, our organization, but also for other organizations as well. But supply chain issues are obviously, um, of really major concern. You know, most of the questionnaires that we receive and send out to people or to new vendors and our customers send to us really are focused on security.

And they still do, but you can really see that they are evolving to address privacy issues and supply chain issues as well. And obviously, we're not only seeing that coming in, but we are also doing that ourselves. And that for me has been a little bit surprising as how much workflow there is that I need to manage and the need, you know, I sort of, I knew that would be something I would have to deal with, but I kind of thought it would take, you know, over the course of the first year I would find a way to make it more efficient and automate it, but it's become rather overwhelming really quickly and we need to find a way to be able to handle that faster. And I'm sure other organizations are facing, facing the same, the same thing. And then understanding, understanding what, what questions do you ask that are going to get you an answer that makes you feel more comfortable, because so much of this is based on trust.

You can ask as many questions as you want, but ultimately you have to get to a point where you can trust that vendor. And, uh, and that's, that's really challenging, really challenging. So I 100% agree, and I do think that it is all about trust. And you move from the security program to the privacy program, and so how old is the privacy program at Ping? Um, it was started, um, actually I think a little bit before I joined Ping is when they launched the privacy program, so that would have been back, I think, 2018.

We just haven't had— it's sort of been a side project, if you will, that other— the people with other full-time roles were bootstrapping. And it's— so it's really just been in the last year that we've been able to dedicate resources to it. So yeah, so it has been around. It's just been growing maybe slower than we would have liked simply because of resources. Yeah, and it didn't help, right?

And I think that's what we see traditionally, is that it starts in security and it's somebody's part-time job and then transitions to full-time. Do you guys follow a framework, um, your privacy program? Is there a particular framework that you've adopted? Um, yeah, and we, we're still working on building this out, but, um, the NIST framework is is an easy one to at least jumpstart. I am— and we're all— we also are a pretty heavy ISO-certified shop, so the ISO 27701, I think it is, also has some really strong characteristics as a framework.

But I think it's really easy to start with the NIST framework and kind of build from there. So that's the way I'm— that's the way I'm kind of starting. Okay, and you mentioned that workflow, and are you talking about like the data workflow of how like from the collection through the processing and sharing and deletion, like the life cycle of data when you said workflow? Well, when I was— both of those things are relevant to us and they're both obviously projects I'm working on, but when I was talking about assessments, I'm thinking more along the lines of, you know, there's a workflow for, okay, when do you ask privacy questions of a vendor, for example? What questions do you ask them?

How do you deliver those questions? How do you assess those questions? Who needs to look at them? What do you do with the answers? Is there, you know, a certain person that needs to say, hey, look, this looks okay, these risks are manageable?

Or there's a whole workflow to that, um, that has to be defined and managed because it could easily take up a ridiculous amount of your time. But then also on the data lifecycle side of things, there, there's a lot of, uh, workflow issues there to deal with that we're also tackling. Yeah. Um, is there any specific identity challenges? Like, I know that some of the articles I've been reading You know, it's about, you know, knowing who you say you are and how to, you know, from a privacy perspective, sometimes we collect more data than we need because we just want to make sure that they are who they say they are.

Is Ping helping with that challenge? Yeah, there's, there's definitely challenges related to the field that we're in and what we want to do because you do have to balance that Are you collecting more than you need? But a lot of the direction that the identity field is moving towards, right, is passwordless, for example, and finding ways to make authentication more seamless and less painful to the users. And in order to do that, you want to be able to leverage machine learning and other types of technologies, and in order to do that, you have to have a baseline of data, and of course that tends to be private data, so you're constantly trying to balance this need to collect information so that you can— your systems can grow and make smart decisions without violating people's privacy, and that is That's definitely a challenge. And then with machine learning and any of these algorithms, we always throw in that bias component, right?

So making sure that we don't bias the algorithm. So, um, yeah, well, I'm glad that, you know, it sounds like Ping is definitely tackling some of those challenges. Yeah, we encounter them every day. Do you ever get pushback where you say, you know what, I think we're collecting too much information?

Yeah, there's definitely, I guess, a push and pull even within the organization because it's an educational process for everybody, right? You know, you might have a development team who's trying— who has this amazing idea that they want to move forward with, and you know that it's the future of your organization. And then, of course, you know, as is true with the security team, the privacy team as well becomes a little bit of the no team, the hey, but you know, there's these challenges here. And but then I think it forces everybody to think creatively because whether it was when I was in security or in privacy, I don't want to say no. I want us to work together to find a creative solution.

I mean, that's, that's how advances in technology have always happened. But there, there are always going to be these balances of respecting people's privacy, and, and I always try to think of it from the perspective of treat other people's privacy as you would expect your own privacy to be treated, yet really isn't. But that's another story. Yeah. But yeah, I try to think of that in my work, that, you know, I'm trying to think about being respectful of other people's privacy and the recommendations that I make and— well, and I think about things to kind of go full circle what you were saying, you know, the fact that from a research perspective you were allowed time to sit and think through those problems.

I think that is probably a huge skill that you bring to Ping because you have that critical thinking to be able to look at like all that data because like in privacy and security, as you mentioned in research, we don't have the answers, right? Like, there's so much gray area. It could be— I always say it depends. Like, let's talk through that. And do you do the same thing?

Yeah, definitely. I really love solving problems. So it almost is disappointing to me when there aren't problems to solve. But yeah, I think that's definitely something that we have to do a lot in the security team here at Ping. Yeah, there's always a problem to be addressed.

Well, um, as we wrap up the interview today, I always talk about giving back to the community, um, and I like to, to see how Ping and/or yourself are, are giving back to the community. Do you have any, um, organizations or things that you support?

Um, I tend to, um, I guess, try to give back to the community by participating with some of the different security organizations and now privacy. I'm a member of ISSA and ISACA as well as IAPP, and I like to try to provide opportunities where I can speak about things that I'm knowledgeable about. I've also— I also, while I was at SecureSet, wrote some articles about that experience to try to help people who are looking at SecureSet and trying to make a decision as to whether it was the right educational approach, approach for them. And, and so yeah, I try to speak, try to do some speaking engagements locally and, and be engaged in those, those different local organizations, which is obviously a great way for networking. It's not like it's a one-way street, but I try to give back in that way if I can.

That's awesome. And are you also part of OWASP? I'm not a member, but I have spoken at a local OWASP meeting, the Denver OWASP meeting, and then also at the annual SnowFROC meeting as well. I love SnowFROC, so I thought I saw you speaking there. So as we're— as I mentioned, we're wrapping up.

Is there anything else you'd like to talk about or anything else you'd like to tell the audience? Not that I can think of. So where can people find you? I'm on LinkedIn and I'm obviously at Ping, so that's probably the easiest way to find me is through LinkedIn. Kimberly Decker, I think, is my, my handle on LinkedIn.

Yeah. Awesome. Well, Kim, it's really been a pleasure talking with you, and I've learned a lot. So thank you so much for your time. Well, thank you for having me.

Yeah, it's been fun. This is the end of our interview. So until next time, thanks everybody for listening. Bye-bye.

Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes