All episodes

Mike Kalac, CISO @ Paymentus

Apple Podcasts Spotify SoundCloud

Mike Kalac, CISO at Paymentus is our guest this week, interviewed by Jason Jaques. News from Pit Liquor, Boom Supersonic, Ball Corp, LogRhythm, Swimlane, Red Canary and a lot more!

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript11078 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 212 for the week of May 24th. Uh, Alex, we are once again in your shed.

And right now the dogs are peacefully laying at our feet. Yeah. You know, fingers crossed that they will not make an appearance in this episode. We're starting a trend here, Robb. Both recording in the shed and with, you know, having dogs present.

So hopefully things go well. I mean, the most important thing is they will keep the mass of fans from pressing in around us as we record. Because it's very disruptive when everyone's screaming, oh, I want your autograph! The whole time. You know, also the, you know, the throng of wild animals.

It'll keep, you know, all the bears and coyotes and everything away. Yeah, safety from it, from all the crazies. Exactly. Hey, speaking of crazies, we have a Slack channel where we have roughly 1,900 people that are really the kind of the core of what we've built here with this community, this Colorado Equal Security community. If you're not a part of it, I highly recommend you join in and, uh, you go out to our website to figure out how to join.

We'd love to have you be a part of the group. We also have a mailing list, which is a much smaller subset of the core of the people that we've built for Colorado Equal Security, but a loyal following nonetheless. People who like to get the show notes delivered to them every week in their email. If you want to be part of that, go to the website and add your email, and we will send you one email every week. Yeah, if you— so that if you've heard the concept of 100 true fans, Like all it takes for a movement to be really successful is 100 true fans.

Well, if you're one of the 100 true fans of Colorado Equal Security, you might be interested in knowing that we have a Patreon campaign where you could financially support the show and, and help us keep moving. I was thinking about like what I am a true fan of. I— there's a few bands that I really like, and one of the bands who I really enjoy is Blues Traveler, and they, they recently re-released 3 of their biggest hits from like, what, man, 30 years ago? The, you know, like Hook and Runaround, these ones from Forever Gone, their 4 album. They re-released them as like a 2.0 version, right?

And I'm like, oh, I will buy them. They are the same thing as the original, like very slightly different. But I'm like, well, I haven't paid for this song in 30 years. I might as well give them another few dollars. And there you go.

That's one thing I'm a true fan of. That's nice, Robb. Good to know. Are you also part of the Blues Traveler Patreon campaign? I am, by which I mean I pay to go to their shows whenever they're in town.

Yeah, that's fair. Yeah. All right. Well, those are some good announcements. One last announcement.

We've— we're a couple weeks out now from the Rocky Mountain Information Security Conference. So if you haven't signed up, it would be awesome if you did that. Go to rmisc.org to see all of the details and to register there. We've got some great content. We've got several wonderful keynotes, including a Colorado CISO panel that you are not a part of, Robb, for the first time in several years.

I'm also not a CISO. You're also not a CISO. Part of the reason you're not part of the panel. And, you know, we've got 3 days of content. It's going to be wonderful.

If you are still hesitating to sign up because you think, oh, maybe I can't afford to sign up, Uh, you know, why don't you jump on the Slack channel and, and hit me a message? I bet I could get you a discount code. Awesome. Uh, all right, let's jump into the news. This next one, this, this article made it as much because of the origin story for this as anything else.

Um, so nearly 2 years ago, uh, Erica— is it Fuchs maybe? Um, she was working through every brand of natural deodorant on the market and none of them were working. So at Erica Fuchs stank. This is, this is what I get. Her husband pleaded with her to keep trying and not go back to real deodorant.

This is such a strange story. Yeah, well, you know, when I read this, I thought, well, of course when you're using natural deodorant it doesn't work because it's natural deodorant, right? That's sort of like using, you know, natural toothpaste or, you know, anything else that, you know, says natural in it that know, probably doesn't work to the way that we would expect it to work. So, um, she, she got so frustrated she just slapped some hand sanitizer on her armpits, and apparently that worked. Have you ever been so frustrated that you slapped hand sanitizer on your armpits?

Every day, Robb. Every day. Uh, I, I thought we were going to include this story because of the name of the company, uh, the name of the product. It's called Pit Liquor.

Of course, you know, there's a play on words there. This is liquor like a liquor you would drink, you know, coming from the alcohol in the hand sanitizer. It is spelled like the liquor you would drink, but it's a little, it's a little questionable, a little double entendre there. Just so you know, you should not lick someone's pits in case you want them to stop stinking. If, uh, so if they are using whiskey as their, as their deodorant, maybe you should.

Yeah, maybe you should. Okay, so anyway, this new— this is a Colorado-based— obviously we're talking about. It's a Colorado-based company that is using some of the edible ingredients from whiskey to, uh, whiskey and vodka, um, to make natural deodorant. Yeah, so I, I would imagine that one of the main ingredients is alcohol to help kill whatever germs there are in your pits. Um, but they now have a line of several different flavors including whiskey vanilla and coconut rum with lime.

Yeah, they're— and they've, they've been doing this since, uh, well, they started on, uh, Kickstarter back in 2017, and they had $20,000 immediately from like 500 backers. And since then, they— during COVID they actually made a little bit of a pivot, you know, just like everyone at the beginning of COVID you know, we can't sell anything, but there's a big need for hand sanitizer. They pivoted to that. But interestingly, they never sold hand sanitizer. They were just giving it away from their website.

And, you know, it looks like that turned into a lot of new customers for them. Yeah, great marketing. And, you know, their hope was that If they gave this away, then, you know, some of the people that they gave it away to would also buy their natural deodorant, and it seems to be working. Another interesting fact on here, they started using the crowdfunding website WeFunder last year, and they, they used that— they actually closed their round here this spring, and they gathered $550,000 from 660 investors to really fund the business and grow it. And they're actually growing pretty well right now.

Yeah, I didn't look into WeFunder specifically, but I believe that's one of the platforms where you can actually do crowdfunding, crowd equity funding, right? You know, so the people that are investing are actually getting a part of the company as opposed to a Kickstarter or a GoFundMe or something like that where you're just getting a product. Yeah, those people probably actually own part of the company. Yeah, it's pretty awesome. So they're now up to a team of 16 employees and they're growing really well.

It sounds like, you know, they may end up using WeFunder again in the future. They had such a positive experience. I think this is going to be a fun local company to get to, to get to see grow. Yeah, um, so if you want to try natural deodorant too, you should, you should check out Pit Licker. And if you want natural deodorant but you don't have the time to wait, just grab some hand sanitizer.

Hey, this is not medical advice. It's probably a really bad idea. We're not doctors. Uh, we do not play one on TV. Uh, all right, moving on.

Uh, next, Red Rocks concerts are going to return to full capacity starting on June 21st, Robb. So this is, this is awesome in that if you wanted to go to a show and you couldn't get tickets, maybe now you can. Yeah. It's not as awesome because I was looking forward to my 4th of July Blues Traveler concert being totally empty as I sat in my lovely seats. But, you know, I am excited to get to have more shows and more options.

So pretty cool stuff. Do you know what the capacity of Red Rocks is when it's at full capacity? You know, I do, Robb, because I've read this article. It's 9,545 people. And they were limited, I think, down to like 20% or something like that previously.

Yeah, it was, uh, 2,000-ish, maybe even a little, 1,500, something like that. Yeah, pretty small. So very big difference. And obviously that, that will open up a whole lot more tickets. And if you're looking to get to a show, you know, this is probably a good time to look.

Yeah, I mean, and there have been just generally more shows trickling out on the Red Rocks, uh, schedule. So I think you should keep an eye out for that as well. Uh, obviously now I think there's gonna be more potential for bigger shows because I think some people probably wouldn't want to come if it was only going to be 25%. So hopefully we'll have a full, full show for, uh, for Red Rocks this year. I actually, I bought tickets to a Red Rocks concert for later this year as well.

Which show are you going to? I'm going to go see, uh, the Wu-Tang Clan with, uh, playing with the Colorado Symphony Orchestra. That sounds like a lot of fun. Yeah, should be fun. Those are different, different styles.

Yes, for sure. Yeah, should be fun. Should be fun. Trying to think of what, um, uh, what one of the stand-up comics talks about Wu-Tang Clan as the, uh, the kung fu rappers, something like that. I think it's a pretty funny way to summarize them.

All right, moving along. We have an article of an official name change of a Colorado— or excuse me, Denver neighborhood. Um, so long Stapleton. And what is that? What's the new name?

The new name is called Central Park, which I think maybe they could have spent a little bit longer trying to come up with the name, but I guess it is sort of central and there's a lot of parks there. So I guess from that perspective it makes sense. And you know, there's— this has been a multi-year thing where, you know, that I don't know if we've just recently realized that the 100-plus-year-ago mayor of Denver, Stapleton, was a Klan member, or it's been known but it's just become a bigger deal. I don't know which, but you know, he his name being associated with just about anything these days is getting a lot of pushback because of that. Um, I think he might have even been a Klan leader, not just a member.

Yeah. Um, and, you know, this is kind of the culmination of that neighborhood saying that they did not want to be associated with that name and that, that history. Um, and so, you know, really cool to know that, you know, the, the city council said we're going to approve a change. The, the citizens got to vote on what the change was going to be. And I now I need to click to remember what was the losing It was, uh, Skyview or Skyline or something like that.

Skyview sounds right. Neither of those names are particularly inspiring. However, uh, Skyview— I have a feeling that neither Skyview nor Central Park will ever be in the Ku Klux Klan, so, um, you're pretty safe in, in that regard in terms of ever having to rename because, uh, you know, not named after a person. And fortunately, the Stapleton Airport is long since been gone. So there's, there's not much more that has to be changed.

Yeah, so, uh, just make sure when you, you talk about, uh, that area now, it is no longer Stapleton. It's now Central Park. All right, uh, next, Boom Supersonic, which we've talked about, um, several times on the podcast. They're making a, a new supersonic jetliner. Um, there was an interview here with, I believe, their CEO Talking about how their goal is to make this travel available to everyone for as little as $100 per flight.

Yeah. So this story caught my eye, not in one of our local Colorado resources, but this was a front page story on CNN's website. And basically the idea here is this is going to not only take over where the Concorde ended as supersonic travel to Europe, but they're saying there's no reason that this can't go everywhere in the world. And they can't do it for a very low cost, which the very low cost is what blows my mind. Yeah, I'm not sure if they already have a contract in the works with Southwest or something like that, that they're trying to do these for $100.

But I mean, that would be pretty cool to be able to fly from, you know, New York to London in a couple hours for $100. Yeah, and part of the article shows that, you know, first we set the goal, then we work backwards. They set the goal of being able to do these travel everywhere in the world for these low costs. But then, okay, well, now that we know that's the goal, how do we work backwards from that? So, right, the goal is that you can get anywhere in the world for $100.

And you mentioned that, you know, maybe they have a deal with some companies already. They don't specifically say which airlines they have deals with, but they have pre-sold a whole bunch of these jets already. Yeah. And just as a sidebar, they do talk a little bit about the Concorde in here. And I, I knew it was expensive to fly on the Concorde, but I don't think I realized how expensive it was.

Um, back in the '90s when the, the Concorde was flying, it cost around $12,000 in '90s dollars, which would be about $20,000 for a round trip today. Yeah, which is pretty crazy. Yeah, and I, I don't know. Yeah, obviously it just— you limit it to a very small group of people, and for sure, and that group of people probably really appreciated it. One other thing that they talk about here is that airports also like the new Boom planes because they are going to be smaller.

The, you know, you have these jumbo-sized planes, the widebodies like the 777 and the Airbus A380, which it's harder to get gates for. There's less gates that fit those. But the plan for the, the Boom jet will be that it's gonna be the same size as like a 737, so you could park it basically at any, any gate anywhere at any airport. Yeah, pretty awesome stuff. All right, going from supersonic travel to a little slightly slower travel, we have news from the iconic Pikes Peak Cog Railway.

So there has been for what, well over 100 years, right, a train that climbs— since 1891, a train that climbs the side of Pikes Peak up to the, up to the summit And it's been closed since October of 2017, so almost 4 years, 3 and a half years, and it just reopened after $100 million of repairs. Yeah, so I think that— I mean, the number $100 million, I think it tells a little bit, but when they say repairs, they basically rebuilt the track the entire way from scratch, also bought all brand new engines and cars. So this is essentially a brand new train just running the same path that it did before.

It was a lot of work, as you might imagine. I think also, you know, some of it had to be done by hand because there were areas that they couldn't get machinery in there to, to help rebuild the track. So I think, again, hard work. That's one of the reasons why it took so long as well. So this is somehow associated with, with Anschutz, right?

Talk to me about that. Yeah. So this is under the Broadmoor portfolio of properties down there in Colorado Springs. And so, uh, yeah, the Anschutz, uh, company put in some money to have this done. And there's also going to be a new visitor center at the top of Pikes Peak.

Um, I don't know if folks have been to the top of Pikes Peak in the past, but that visitor center was nothing to write home about. Uh, so rebuilding that, and that's going to be open, uh, in June. So the visitor center is not yet open, but the railway is open, right? Correct. Yeah, good stuff.

Yeah, pretty cool. Everybody go check it out. We should take a look. All right. What do we have next?

Oh, this is a good story. So I think we've talked about this as well. Ball Corp, they have their new aluminum Solo cups, I guess you can call them. They're now silver instead of red, but made of aluminum instead of plastic. They started selling these at various places, including CU Games and the new Ball Arena.

But now they are available in all 50 states at major retailers. Yeah, so Kroger, Target, Albertsons, CVS. But most relevant to someone like me, it's on Amazon. And I, and I was— I quickly went over to Amazon to see, well, what does this thing cost? And you could buy a package of, of 30 of these cups for $10.

So I mean, considering the fact that they are metal and you can reuse them, and then they are, you know, the big selling point of them is they're 100% recyclable, right? You— there's no waste as you recycle these. That's the big selling point. But, but the, the idea that, that you can go get them for relatively cheap, they look pretty cool. I'm definitely looking to try some of these guys.

Yeah, I have tried them at sporting events previously. I haven't bought any for the house, but, you know, they seem to work just like any other cup. I do like the recyclability. I think, you know, with plastic, obviously you can't recycle all of it, and And, you know, it degrades over time, so you only get some of it back. With aluminum, you can basically reuse the entire piece of aluminum from the cup.

And, uh, they— Ball says that, you know, if you recycle one of those, it can be back in your hand as something new within 60 days. Does, uh, does it have the satisfying smash of like a can when you, when you, when you crumple it? It does, it does. So I like that. Yeah, good stuff.

All right, uh, moving over to our next story. We're now coming into the side of things. This is an interesting story in the Denver Post. Headline is Cybersecurity Analysts: A Pressing Need for Front Range Growing High-Tech Industry. And this is, this is really some interesting facts from Denver Post around how many jobs and how many job openings there are for security in Colorado.

Yeah, and part of the article talks about a new boot camp that is opening in the area, which it's seems a little promotion-y there, but, you know, I guess that's kind of what got this story going. You know, when this academy looked at Colorado, they saw, hey, there's a whole bunch of unfilled jobs, maybe we can help train people for those jobs. They say 30,000, you know, who knows what that number actually means, but obviously we all know that there's a lot of cybersecurity jobs open in Colorado and definitely the need for people to fill them. Yeah, I will say that this article seemed like it was written by someone who doesn't understand the industry, in that they say, uh, there are 30,000 cybersecurity and coding jobs. They just lump those 2 things together, right, as though, as though maybe the same skill set works for both.

But they do break it down. They say there's 17,271 cybersecurity jobs open in Colorado and 13,000 coding jobs. That also blows my mind, that there's more security open recs than there are coding recs? Is that possible? I don't know.

That does seem sort of weird. It seems upside down to me. Yeah. But then they say that there are, just from the security perspective, I think they were saying that there were 72,000 jobs in the area, which seems awfully high as well. Yeah.

But I mean, I think the bottom line here is there's lots of opportunity. We need people. We need people trained, and hopefully whether this boot camp does it or somebody else, we can help move in that direction. Yeah, I think the more training we have, the better. Next, we have a new release from LogRhythm and Zscaler, who are partnering on a new web application website access control partnership.

Alex, what are they doing? Yeah, so it's sort of a 2-way integration, basically. You can pull the Zscaler data into LogRhythm. And then, you know, based on some analytics and alerting, you know, say you pull the website that someone accessed from Zscaler, you know, LogRhythm can run analytics against it. Is this a bad thing?

Is this a good thing? Is it against policy? You know, something like that. And then, you know, you can make a decision to push a rule back to Zscaler and say, okay, we've decided you shouldn't be accessing this website, we're gonna put this to the block list and, and have that happen automatically. So that's pretty cool.

Yeah, clearly high value, and you want your SIEM to, to have integrations with all of your other security tools. So I think that's a good one. And, and you're kind of pushing a little bit into automation, which I think leads us to our next— yeah, speaking of automation, we've got a blog post from Swimlane talking about why you need a true SOAR, not just security operations. And so this was written by Cody Cornell, who is the founder and Chief Strategy Officer. Cody moved over from CEO into this strategy role, what, like maybe 18 months ago or something?

Um, and what I really like about it is, you know, he talks about generally how we think of a SOAR from an improve your security operations perspective, but this article dives into how do you use these— this automation to actually improve your business outcomes, and, and what is it that you're trying to to accomplish with your security practice that, that maybe a SOAR can help you do. Um, so, you know, they go into things like the ability to better support your remote, your remote workforce, um, the ability to make, uh, to help support this hybrid environment that we're going to have where a lot of people are remote and in the office. And, and the better you have repeatable processes that are supported by technology, the better those folks who are not just across the cube from you are going to be able to integrate with processes and really support the new way we're going to be working into the future. Yeah, and I think also you having a single sort of centralized place where you're, you're working on this stuff as opposed to, uh, you know, multiple products and consoles and things like that. If everyone's working out of the, the centralized store, then you can, you know, much be much more streamlined and, and, uh, better operationally.

Yeah, there's definitely a spectrum, you know, between how how process-oriented can we be to get maximized efficiency and maximize scalability? And then how free can we be to be innovative and move us in new directions as an organization? And I always, as a security guy, I'm always on the side of process and repeatability. And I think that's the part that SOAR really supports as your organization is maturing. For sure.

All right, let's move on to our last article. This is a blog post from Red Canary. This is one of their detection and response engineer posts talking about tales from decrypt, differentiating between ransomware and ransomware decryptors. Yeah, until you said that out loud, I did not catch the tales from the crypt type of a reference. Yeah, so this one's— I love this.

You know, it's going through the process of what do we see on the system? And then as the kind of detective on the other end, this detective, detection engineer has to decide, is this potentially bad? And, you know, he sees what appears to be someone deleting all these restoremyfiles.txt files and, and going through— I'm sorry, there was a couple other things that they saw at the same time, but basically it looked like it could be the behavior of a decryption tool, like maybe if you paid a ransomware ransomware for the decryption tool. But at the same time, you say, well, what if this— what if they're just, you know, hiding as a decryption tool instead of actually doing it? So yeah, how can you know the difference?

To think through that process, what does the difference look like? Yeah, what does a legitimate tool— I guess legitimate, maybe an actual tool that's doing this thing— what does it look like versus what does something that's doing bad look like? Yeah. And maybe, you know, even if it is something that you want to be a decryptor, how do you know that it's not doing bad things as well? Yeah, that was an interesting point that, you know, that one of the behaviors they saw in this tool was that it was doing a port scan, which was probably looking for SMB shares, which could be because we're looking for things to decrypt, or it could be we're looking for ways to get persistence in this environment, right?

Yeah. So, you know, even I would say Even if you know that you're paying for a decryptor, it's probably worthwhile to have, you know, to have forensics on that process anyway, because how do you know the bad guys aren't going and doing something else in your environment with the tool they just gave you? They're obviously good at building bad guy things, right? So great, good article. I think, you know, a lot of technical info that's worth going through in there.

Yeah, check it out. So, all right, that is the news. Why don't we jump over to the Slack message of the week? Thanks to Andre Gaeta for supporting this endeavor that we have, promoting our Slack channel in the Colorado Equal Security. We pick one winner every week who has posted something on Slack that we think is interesting or worthwhile, and Andre provides them with the opportunity to get one thing out of the Colorado Equal Security store.

So this week, our winner is Michael Stephen. Congratulations, Michael. Uh, Michael works for Connect for Health Colorado, but he was posting about the fact that, um, the Biden administration, because of COVID has reopened the healthcare exchange for a short time period. Uh, so if you want to enroll in low-cost affordable healthcare, uh, that the Colorado Healthcare Exchange is open right now, uh, for you to do that. It's strange, right?

Like, normally it's once a year open enrollment. Correct. Due to the the kind of strange world we're living in right now with high unemployment and the pandemic, they've, they've made the option to open it a second time during the year. I think that's pretty cool. Yeah, nice to know.

I'm glad we can amplify that message. Yeah, and thanks to Michael for posting that. Yeah, awesome. So we do have an announcement for next week, and we'll post this in Slack as well. But we decided next week we want to do something a little bit different versus the normal Slack message of the week.

We want you guys to nominate someone to be recognized. We want you to nominate someone who, as a community member, uses their time and skills to improve the Colorado security community. And we'll, assuming we get some good feedback, we'll pick one member or one person from that list of nominees to be rewarded and get an item from the store. And hopefully, you know, to tell the story of what cool stuff they're doing. Yeah, basically, you know, Robb and I are tired of picking out the messages ourselves, and we want someone else to tell us people that are doing good stuff.

And we want to reward the behavior that we want to see in the world, right? Exactly. All right, uh, let's jump over to upcoming events. As a reminder, we have a, uh, we have a calendar of events on the website with things going out quite a bit into the future. But over the next 2 weeks, there's really only 2 events.

I think Memorial Day is kind of putting the kibosh on, uh, sure, on lots of stuff going on. Yeah, uh, so first, ISC2 Pikes Peak is doing their May meeting on May 26th, and on the 5th of June, ISSA Colorado Springs is starting their CISSP training. This is session 1 of 6, and I just cannot strongly enough recommend if you're looking to get your CISSP, look into this training. They have great, great quality instructors, and it's really affordable. Even if you're not a member of the chapter, it's affordable.

I think if you join the chapter, it's even better. And I assume, I don't know, but I assume you can do virtual at this point. But take a look at it. I've had some folks who worked for me in the past attend their different trainings for Security+ and CISSP, and I've only had positive feedback. Yeah, and it is more than 2 weeks out, but we noted it earlier, Rocky Mountain Information Security Conference is coming up June 8th through 10th.

So again, take a peek and register for that if you're interested. All right, let's jump over to jobs. You know, each week we try and identify 10 interesting jobs in the area. 10 of the— what do we say— 17,000 open security jobs in Colorado. Next week, Robb, all 17,000.

So we'll do 10 now and we'll do the rest of them next week. Um, so starting off, we have the, uh, the Gates Corporation CISO. So this was Sam Masiello's job. Sam recently posted on LinkedIn that he's moving on to, uh, uh, to, to run security and technology for a law firm. Um, but, uh, now his backfill at Gates is open, and if you're interested in that, I think I think this is a great job for one of the biggest and best-known Colorado companies.

Western Union is looking for a cybersecurity senior engineer for application defense. Sorry, that was a mouthful. Yeah, sure was. Zoom is hiring a security investigator. You get to investigate security.

Ooh. Guild Education is looking for a senior information security analyst. Agon is looking to hire a senior global security operations center analyst. So Aegon, if you don't recognize that name, they are the parent company for Transamerica, a bunch of other insurance companies too. NREL is looking for a chief cybersecurity engineer.

Yeah, there was a number of postings from NREL, but that one seemed especially interesting. I don't know what a chief cybersecurity engineer does, but it sounds important. Bisto is hiring a senior information security analyst. Visa is looking for a senior cybersecurity engineer. T-Tech is hiring an information security engineer.

And finally, Presidio is looking for an engineer in cyber cloud security. All right, well, that takes us to the end of the news section. We do have an interview this week, Mike Kalac, formerly the CISO from Western Union. And I think— I haven't listened to the interview yet, but I think that in the interview he doesn't mention having a job, but he does now have a job. He's now the CISO for Paymentus, and who I'm definitely looking forward to learning about more about Paymentus.

Yeah. Anyway, he's our feature interview. Mike's just a great guy with, you know, many years at First Data and then Western Union. Looking forward to hearing this background interview. Should be good.

Looking forward to it. All right. Well, that is it for this week. We'll talk to you guys again next week. Thanks for all.

Hi, this is Chris Martinez, CISO at Digital Globe. Welcome to Colorado Equals. Security for Colorado security professionals by Colorado security professionals.

Hello, Colorado Equals Security. I'm Jason Jaques. I had the privilege of interviewing a well-known and longstanding member of the security community here in Colorado, Mike Kalach. Here's the interview. Enjoy.

Hi, Mike. Thanks for joining me on the podcast today. Thanks for having me. Hey, there's a lot of different areas that we can get into, and I've got a lot of questions for you. But let's actually start, um, let's start with your background.

I'm curious where you're from. Yeah, I grew up in a small town in northeast Pennsylvania, sort of that Wilkes-Barre, Scranton area, uh, where, you know, Scranton became famous through The Office, right? Um, but yeah, a small town there. Um, one of 4. I have 2 older sisters and a younger brother.

Okay. Yeah, I was the first one to sort of venture out, uh, when I went, when, uh, went away to college. Yeah, they're still there in the area. So growing up from there, did your family work for a paper selling company? No, no, they didn't.

My, uh, my dad was, uh, he, he was a sort of an inventor, or, uh, he started out as a draftsman. And, uh, actually when I went away to college He, uh, ended up starting his own company. He was always in the, uh, special design machine business. Okay. Um, and, uh, he actually started his own, uh, special machinery shop, uh, which, which got quite big.

Uh, I think at one time he was running a couple shifts of about 200 employees. So— oh wow, it's a nice, nice business he built. Yeah, yeah. Is that business still going today? It is, it is.

His partner and his partner's son, I believe, took it over and it's still going today. Okay, you never thought about getting into the family business? You know, that's a great question. Um, I think if the timing was a little bit different, maybe things would have changed, but I was sort of on my way into college and just wanting to get out of the small town and see what else was out there. And yeah, and, uh, you know, it sort of took off when I was already on my way out.

So yeah, okay, so you left Scranton And you went to college. Where'd you go to college again? So actually, I, I finished a 2-year degree at a branch campus at Penn State in an engineering program. Okay. And that's when I sat back and I was, I was really wanting to finish a 4-year degree.

Um, and a professor there at Penn State, uh, the branch campus in Wilkes-Barre, um, actually suggested that he knew a guy that was starting at the time, believe it or not, a telecom program at Texas A&M. Wow. So a friend of mine who was with me at Penn State, who graduated high school with me, he and I went down to A&M. And, uh, you know, there's a funny backstory to that. We flew People's Airline, if anybody remembers People's.

I do not. You actually took your payments on the plane. Wow. No kidding. So it was $99 round trip.

I'll never forget it. And you paid Like, and like back then you were paying in cash. This was probably 1987-ish. Yeah. And, uh, so, uh, went down to A&M, loved the campus, um, and ended up, uh, going there for the next 3 years and finishing my 4-year degree in, uh, engineering.

I, I'm still fixated on this idea of paying on the plane. So what happens if you don't pay? Yeah. Do they kick you off mid-flight? Sort of hold you ransom.

Yeah. I, I don't know. But yeah, it was like the flight attendant would have like a cart with, um, a box and cash. Yeah, yeah, I vaguely remember it, but I, I do remember paying on, on the plane. You know, the funny thing is— I shouldn't say funny, um, like because of, of 9/11, you know, being now— I mean, that was, that's 20 years ago, right?

It's It's funny to think back at like how, you know, I suppose how long ago that was, but the world was so different relative to airports. Like you could just walk straight up to the gate and do whatever you wanted to do. So that business model made sense. I remember, you know, even flying when I was younger or flying back to college at the time, where your family or your parents would come and sit at the gate with you. Yeah, hang out until you took off.

And now that's non-existent, right? Yeah, that's a world that a whole generation of 20-year-olds and younger will never know. Never know. Yeah, it's kind of sad, but, uh, yeah, it's the way the world is. Well, some good things came out of that.

They don't allow you to smoke on the plane anymore. Yeah, in the last 10 rows. Yeah, that was a little weird. Yep, yep. Yeah.

Okay, so you went to College Station and you're, you're now an Aggie, right? Are you a football fan? Because that's a big football— Yeah, absolutely. Um, I, I tend to follow, uh, A&M football a little bit more than even Penn State because I had that sort of that real campus experience there. Um, so it's been a— it's been interesting to see what that's turned into with them moving into the SEC.

And yeah, it's really grown the program immensely, but I still like those days over Thanksgiving when we would play UT and— yeah, that was— those days are gone and it's unfortunate. Yeah, those were, those were really big games. Um, a lot of excitement in the crowds. Okay, so you went to school there at A&M and then, um, you got your degree and Then where, where did your travels take you? Yeah, A&M did a great job of, uh, you know, bringing companies in.

So, um, back then, and this was like 1989, uh, there was a lot of activity around, even in Texas, you know, Texas Instruments was recruiting big, uh, believe it or not, JCPenney. I remember a lot of people going there, um, some other, you know, larger companies, but Uh, you know, I interviewed with, uh, Hewlett-Packard at the time, HP, and, uh, it was, uh, for a position out in California. It wasn't in Palo Alto, it was in San Jose, um, and it was a, uh, a telecom, uh, program, uh, that they had. They had a very large, uh, telco private network, uh, internationally even. So, uh, I actually got on with them right after graduation and moved to California, moved to the Bay Area.

Wow. So your first actual job in tech was right out of college, going straight to what ultimately became Silicon Valley, although probably at the time it was kind of the, the early beginnings of that. It was, it was still not the greatest place to start your career. No, sort of. It was the beginning of the haves and have-nots.

Let's just get right in the Bay Area. So it was, it was a difficult difficult run, but it was, uh, it was fun. Um, I actually, uh, had a friend of mine who, uh, was just graduated also that I went to high school with that was looking to do something, and he moved out there with me. So we kind of moved in out there together and, you know, got the apartment and, yeah, started my career there. Yeah.

How long were you out there working for HP? Working? So HP, HP, uh, was about It was only a year, you know, it was one of those things where, and I'm sure a lot of people have experienced this, when you come out of college, you sort of want to change the world quickly. Yeah. And you find out that an organization that's been around for a long, long time, that was, you know, sort of 50,000 employees, that you were just a number.

So I ended up following a, a friend of mine who I was working with at HP that went over to a voicemail manufacturer called Octel. Oh yeah, yeah, yeah. But Olson and Cohen was the OC in Octel. Okay. And they were building voicemail at the time.

This was a little bit of a pre-email and when we were leaving voicemails for everyone. Yeah. And they were big into, you know, enterprise voicemail, but also, uh, building a lot for the Bell companies at the time. So a lot of the, a lot of the Bell companies that you had your voicemail with at home was an Octel behind the scenes. Yeah.

And Octel, if I remember right, they were either acquired by Nortel or Avaya. Uh, it was Avaya. Okay. Yeah. Okay.

It was Avaya at the time, and then which, which ultimately turned into Lucent. Yeah, yeah, okay, interesting. So then, yeah, you really did start on kind of the telco side. Yeah. Or the, I guess the, I don't know, telephony side.

Yeah, Octel was actually, was one little step out of my standard, what I did a lot of, where I did a lot of QA engineering Both on the software and the hardware side, which was kind of fun. Yeah. And then from Octel, where, where was the next stop? Yeah, this was an interesting step. So this was the step that actually got me to Denver.

I was in probably my 4th year in the Bay Area, 4 and a half years or so. Yeah. And out of the blue, I get a call from my manager who hired me at HP, who I had lost track with for a year or so, maybe even more than 2 plus. And he said that he has this opportunity. He had been, he had moved to Denver and he had this opportunity with McCaw Cellular One.

Okay, which I didn't know much about the, you know, the mobile cellular business at the time, but I was just about ready to get out of the Bay Area. It was kind of, uh, like I said earlier, it was weighing on me a little bit where, uh, it was hard to, hard to start your career there. Yeah, so I, I jumped on a plane, went out to, uh, Denver for the first time ever, never been there, and, uh Had a great, uh, time. And, uh, and, uh, I knew him for a while when I worked with him at HP and, uh, and accepted that role and then moved to Denver in, uh, in '93. Wow.

And you've, uh, never looked back? Have you been here the whole time? Have been here the whole time, 3 kids later. You are definitely a native. I've been here 20 years, I claim I'm a native.

So you've been here longer, so you can say you're a native. Yeah, I saw Coors Field being built when I got here. I saw the whole Park Meadows area being built out. Yeah, a lot. It's changed a lot.

Right, right. Yeah. So how did you— all for the good. Yeah. Yeah.

How did you get into security specifically? Like, where was that pivot? Yeah, where did that sort of jump into? So You know, I spent a couple years at Macaw. Macaw ultimately got bought by AT&T.

Okay. I, I really didn't want to go back into, um, with AT&T or stay with AT&T or back into that big, um, company. And but at the time I started looking and found First Data. Okay. Went over to First Data in, um, in '95, late '95, and started there running a lot of their telecom program, some infrastructure, took on network engineering after a while.

But when I first started in '95, probably about '96 or so is when First Data bought a company called FFM&C, First Financial Management Corp. And there was 3 companies under there, and one of them was Western Union. It was really the target at the time. I didn't know much about Western Union other than sort of what they did, right? Money transfer while I was at First Data, but we owned them for nearly 10 years. And then in 2006, when I was running a pretty sizable network engineering group at First Data, some of the telecom still, I built a lot of the call centers, some of the infrastructure stuff there.

First Data decided to spin Western Union off as its own company, actually its own company again, because they were one of the first, I think, 10 or so, or 40 on the Dow. They were one of the first ones ever. So they became their company again. I was— it was an interesting story here. I was, in my mind, I was staying with First Data.

I had a great Great job there, great people. But I actually had a friend of mine come into town and I went to a Rockies game with him. And sure enough, I sat one row behind one of the executive vice presidents of Western Union. Yeah. And we got to talking and she said, well, what are you doing?

And I said, well, I'm staying with First Data, I've got this running this network engineering group. And she said, well, why don't you come talk to me tomorrow? Um, I, I think I'd like you to come over to Western Union. So it's those kinds of things that you just can't make up, right? Right.

Um, that just happened, sort of fate, right? Yep. So I, I did that, um, and I met with her the next day, and, uh, sure enough, uh, she had this position of their Chief Information Security Officer that they needed to fill. And, you know, now this is sort of the end of 2006, right? So you can imagine back in 2006 that, that role was not as— no, there weren't many.

It wasn't very defined, right? We were still doing rack F on a mainframe as security, right? Yeah. Um, but I knew that I, I knew some of the people that were moving over there. I knew that sort of my background, my leadership, uh, what I was doing in the network space, I knew I could carry that over and take this on.

Yeah. Uh, so, uh, that's when I accepted that role as their first CISO, um, for Western Union. So it was, it was a great opportunity.

I had no idea what it would turn into at that time. I had no, absolutely no clue. And it, back in that timeframe, it kind of seems like, at least to me, that that really was the early days of, you know, that role, the CISO role. Who did you have to look towards or talk with that had similar roles that you could learn from, or were you just kind of inventing the role as you went along? Yeah, I guess a little bit of both, right?

Um, I, I remember taking on that role and thinking to myself, okay, I need to build an entire new network of people. Yeah, around me just to get my head wrapped around what are the important things, right? Um, when I came over which this is sort of a lot of times happens with big spinoffs or sort of divestitures, right, is that the mother company, the mothership, sort of keeps a lot of the— say, a lot of the people, right? So we were— when Western Union was there under the First Data umbrella, they were using all the shared services of First Data, right? So when I came over and took that role on, I was given— I had 4 people, which one of them left almost instantaneously after.

Uh, so I was— I had 3 people to run a global security program, right? Yeah. So, uh, what I did was I really just focused on finding great people that had experience in specific areas that I really wanted to move forward with, right? So I needed somebody to run or to figure out what we needed to do from a security operations center, right? So yeah, monitoring, logging, and, and, you know, at that point in time it was just find people that, you know, even engaging with MSSPs and stuff just to get the program started, right?

And it was very global too, so I was hiring outside of the US and finding people there and and just bringing them on board. So it was more of building people around me than it was sort of me coming up to speed as fast on it. I think that was okay. I, I, I, I learned more from the people that are with me and the feedback that they're giving me than at that time than setting the direction, right? The direction was set from what I was hearing from the people that I was bringing on.

Yeah, that makes sense. How, how did you go about finding the right people? Yeah, well, back then it was a little bit easier, right? But, um, well, I, I don't know if it was that much easier because, because the, the, the skill set really wasn't there yet. Yeah.

So what I relied on was a little bit more from skill sets in network engineering, skill sets in, you know, Microsoft and infrastructure backgrounds that knew somewhat around the security side, right? Yeah. And really, at that time, it was all about operational, you know, it wasn't this sort of risk management, governance, policy, right? We were taking paper-signed requests for access, right? So none of this was automated at the time.

So it was really sort of just running it from an operational perspective and making sure that we were covering what we needed to cover. Yeah, yeah. And then you built that. So it started as like 3 people, like you were mentioning, and you, you ended up building a pretty large, significant team. I think you told me in the past, although I don't remember how big it was.

What was kind of the biggest it got to at one point? Yeah, the largest the team got was probably somewhere in the 130 range. Okay. That probably— yeah, we never really truly brought 100% of the SOC in-house. We kind of went through cycles there where we had MSSP, then we did some StaffAug, but yeah, the 130 was global 24/7.

So I'm curious your opinion on this. I've wondered sometimes what really is more difficult for large organizations or small organizations. So large organizations have a much bigger attack surface and more people, but more resources and again, more people to, you know, help with mitigating risk and security in general. Smaller organizations don't have that, less people, smaller attack surface. Like what really is more difficult from your standpoint?

Yeah, I would sort of argue that maybe some of these smaller companies that I see now, the attack surfaces maybe not that small. Yeah, you look at some of these online trading platforms, um, you know, take Robinhood for example, right? Um, that attack surface must be large, right? Um, you know, I, I managed an online platform including a mobile app that moved— could take a credit card an online credit card and turn it into cash anywhere in the world in minutes. So that attack surface was huge.

But I would say that in some cases, I think it more is about the sort of the business you're in, and that equates more to the attack surface than what the size of the company is, I guess. Yeah, that's definitely fair. What are some lessons learned, possibly the hard way? Because I don't know about you, but I learned a lot of lessons from failure. I learned what not to do.

What are some lessons learned that you experienced in your, you know, your time as CISO that you think back and you're like, I would ever do that again, but glad I learned that. Yeah, that's a, that's a great question. Um, you know, one that comes to mind is trying to build out certain things that, um, maybe you— let me put it a different way, I guess— building out things that probably weren't that valuable to the company. Right? So trying to build out a full 7 by 24, 365 security operations center within an organization like that really maybe doesn't make sense for the company as a whole.

When there's other organizations that are good at that, go use those type of services, right? Because trying to keep those people on board, trying to keep their skill sets up and keep them motivated and not burned out was difficult, right? Um, I would say another lesson learned was, uh, try not to, uh, sort of what I say is get wrapped around the axle, uh, too quickly on what you're seeing from an attack surface, right? Um, it, it almost got to a point where, you know, I, I had the realization that, look, this is, this is going to be constant, that this is not going to stop, but you're doing everything you can to sort of control it. Because in my mind, so sort of my engineering background would kick in and say, okay, this is sort of a— this is a 1 or a 0, right?

It's, it's, it's, it's, it's an on or off, and I've got to stop it. But in, in, in the space that I was in, there's— there was no stopping it. It was more controlling it. So you had to be comfortable with just this controlled environment versus completely stopping it. So that was a learning experience that you have over time.

Because when I first started, I was like, oh my God, I gotta stop all this. Yeah. What's some of the, uh, the fun things about being a CISO in the early days that you really enjoyed that, uh, made you realize, I like this job, this is for me? Yeah, I, I think, um, that was definitely what drove me, uh, sort of into the office every day and what excited me was was that challenge of how much control I could put around that, right? How much, how much could I bring together?

But, you know, also a lot of it was just, again, going back to building that group up. That really, uh, really excited me throughout my, you know, years there, was just building out the skill sets and watching sort of this whole area of cybersecurity or security change over time where, you know, like I said, it started very operationally in the beginning, but then knew that years into it, I need to start building out a governance, a risk, a compliance group, right? I can remember sitting there a year into, um, uh, into my role when I moved over into that CISO role And thinking, who has this PCI compliance and who's running this? Is the compliance group doing that? And just grabbing that and running with it, right?

So it was interesting in bringing people on that knew more about that, but really building that team out was something I really truly enjoyed. Yeah, very cool. So you have since left Western Union and now you are— can you talk about what you're what you're going to be doing? Or I know you're doing vCISO. Yeah, I'm looking into some of that.

I'm doing some of that virtual CISO work. Yeah. You know, I'm trying to— I'm sort of taking some time to work through in my mind, you know, what's next. It's interesting from a virtual CISO perspective, it's a little bit more on the consulting side, I would say. And, and I, I'm sort of working through that right now to make sure that that's for me.

Yeah, I mean, that's a big difference. It's, it's a totally different— you would think it would be almost the same, um, from being in that CISO seat, but it's, it's, it's, it definitely is, uh, sort of a 180 from, from where I was. So just making sure that that's what I want to do. Um, you know, I, I think I go back to building teams. I would love to find something right now that would let me build something again from scratch.

Yeah. And a lot of those lessons learned would come into play on that one too. You know, and understanding what sort of vertical I want to play in also. You know, I've been in financial services for a long time with First Data and Western Union. So, uh, we'll see what's next.

I'm really excited. I— the one thing that, uh, I definitely sort of set my mind to was to stay in the Denver market, which has been just the, the community here. And, and not, not only just the CISO community, but also sort of the entire IT community. It's been unbelievable. When I first started reaching out to some of my connections and, and those connections made me more connections, right, as, as you get through this process, and it was unbelievable how open this IT community is in Colorado.

I don't think you'd ever get this in sort of a New York City or San Francisco or some other places. But just willing to help. I mean, people I would just meet on a call for the first time ever, and we'd have such a great discussion just around technology and where it's going and what I wanted to do and just so helpful. It's a really great community here in Colorado. Yeah, for sure.

That's, that's one of the things that I like best about, uh, about us here in our isolated pocket of Colorado. Yeah, it, it is a small community, yet it's big too. It's, it's, it's a weird kind of dynamic. Yeah, absolutely. Um, what I've learned over the last couple months is there is a lot going on in, in this, uh, in, in IT in Colorado, uh, which is wonderful.

Uh, I wish it actually got a little bit more notoriety, uh, even within Colorado or nationally. Yeah, because there are some fantastic companies, uh, small, medium, and large that are happening here in Colorado, uh, that are doing some incredible things. Uh, but I, I don't think the publicity or the notoriety is there just yet. Yeah, but when you start digging in and start sort of looking around and meeting other people and seeing what they're doing. It's an incredible community.

Yeah. Yeah. So nothing has ever attracted you to go back to California or Texas or even Pennsylvania? You've stayed here in Colorado? Yeah.

What, what have— what are some of the hobbies that you've picked up living here? Yeah, I, I've told a couple people just recently that I've been here for, you know, over 20-some years now, and, and I think I skied once. Yeah. Uh, so I, I've been a, I've been a golf nut for a long, long time. So, uh, that's my, that's my getaway.

Yeah, I'm trying to spin that up for the Colorado Equal Security community. There's a golf channel in Slack, so there we go. Feel free to join anytime. I'm in. What are some final thoughts you might have for the community?

And again, you come from a very interesting— you have a very interesting perspective, I should say, in that you have built one of the largest really security groups here in Colorado.

Is like a lot of people within the community are looking for advice that might be in a similar role as you were. You know, what, I guess, what things can you share to the community? What advice might you give? Do you have any final thoughts for the community as a whole?

Yeah, I guess what comes to mind is, you know, if you're looking, if you're on that fence line of looking to get into, you know, this CISO role. And again, we go back to our discussions around, you know, what industry it might be in, or how big it might be, or how small it might be. I would say, this is probably not the first person ever saying this, but don't try to solve everything with technology. Yeah. You know, there's, there's, there's sort of people behind this.

There's process and policy behind this.

You really have to sort of think about it in that risk-based approach and really truly understand what's that risk appetite of the company. And don't try to put a box with flashing lights in front of everything to solve what we're up against. That's great advice. There's definitely some great technology out there, don't get me wrong, and some of it has to be there. Um, but I think sometimes, uh, how do they say, uh, if technology, you know, was a nail, everything is a hammer or something like that, right?

I probably got that completely backwards, but you know what I mean? Like, uh, don't continually look to technology to solve all the problems. Yeah, there's, there's a, a person in a process and a procedure behind a lot of this that really needs to be tweaked and, and looked at what's going on behind the scenes. Yeah, yeah, I like that analogy because, um, I like to tell people I've got 500 tools in my tool belt, so they're, they're not just a hammer, right? You can't go after everything with a hammer.

Everything's on a nail, right? Yeah, yeah, yeah. So that's, that's Definitely fantastic advice. How do people find and follow you on social media?

I'm not a big social media guy. I'm out there on LinkedIn. You can find me there for sure. Yeah, that's, that's not a problem. And, but you'll see me around.

Yep. Things like this and, and other, other events. So I hope to, hope to run into a lot of people soon. That, yeah, now that we could sort of start seeing each other face to face and shaking hands now that the world feels like it's opening up again. So yeah, yeah, we could only hope.

Yep, that's the direction. Well, this has been great, Mike. I'm, I'm glad you got, um, the, uh— I'm glad we finally did this, actually, since this was on our calendar for over a year. I know, it's been a long time. We, we were supposed to do this interview right as the world closed about a year ago, and, um, We finally made it happen.

Yeah, I, I appreciate, uh, you doing this. I think it was great. I, I'm glad you didn't sort of quiz me on, you know, cryptocurrency or, uh, something. I came really close actually to asking you your thoughts on, on crypto coins and whatnot, but I held that back. Yeah, you were kind.

Yeah, yeah, that's funny. Well, again, thanks a lot, Mike. And, um, yeah, anytime if you need any help from the community, feel free to Reach out. We're we're around, always happy to help, and and you know we'll we'll see you around. Thanks, Jason.

I appreciate it. That concludes my interview with Mike Kalak. Be sure to follow and support Colorado Equal Security on Patreon. This is Jason Jaques saying be safe out there.

Learn more about the Colorado security scene at colorado-security.com, where you can see information. About local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes