Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 213 for the week of June 7th. Uh, as you may notice, this is Alex, and since I am doing the intro, Robb is not here this week.
I have Brian Beyer again as a guest co-host. Welcome, Brian. Awesome. Thank you for having me. Glad you could be here.
How are things going? Things are going well. It's been a busy year leading up into the summer. Excited to kick off summer activities with the family, and we're getting about a month away from the Denver office for Red Canary opening. So lots going into that.
I think we've talked about that on the show before with, you know, you guys moving into the, the new, uh, what is it, McGregor buildings? McGregor Square, uh, right across from Coors Field. So I, I do have a question for you about that. As part of the lease, do they give you free season tickets to the Rockies since it's actually— it's owned by the same people that own the Rockies? It actually is owned by the Rockies, and it's been really fun.
Of all the buildings we've gotten to work with in the past, like, we are actually working with the Rockies for some of the design decisions and Of all things we learned, the Rockies actually have a relationship with Cambria, who makes all of like the faux marble type things and like the fancy stone. And so there are pieces of the new office that have Rockies Cambria in them. And so there's been some fun things of working with a team like that. Okay, I'm gonna dig in more on this. So, so by Rockies Cambria, is that like a certain color?
Like they have a Rockies colored or it's just like— it's not a specific color. It's a specific relationship with the Rockies. Okay, so just a relationship. It's not like you know, so far that there is a specific, you know, faux stone that they made. There's not a stone that is purple, purple and gray.
And well, I haven't seen it in person. There's definitely gray in it, so we'll see if there's some purple. But they, they've been awesome to work with, and we've had a couple small get-togethers already in the Rally Hotel that's down there that's gonna have the Hall of Fame down on the first and second floor, and they have just done an awesome job. Nice. Uh, one of the other things that I I said this to Keith, um, who's, you know, one of the other co-founders.
Um, you know, there's that giant TV screen that's down by the, you know, the base of the building. I, I— you guys have to work out a deal where like all of the webcasts that you guys do or whatever are, are displayed on that giant screen in the courtyard there. So it turns out, so we looked into this because for Beast Mode we were wondering, can we just hold it in that area? And you can have events there as long as they're fully open to the public. So we won't be able to have like a company event like Beast Mode there, but we will totally be able to see if like you and Robb want to come out there and do a live podcast recording, like in front of everyone in the pavilion.
We can definitely do it. That would be cool, but scary. Exactly. That'd be— there haven't been a lot of live recordings, have there? Uh, no, not a lot.
We've done it a few times, you know, RMISC, we did it, uh, Uh, oh, a secure world one time. Yeah, but yeah, that might be a fun thing to do. That'll be a fun one. Maybe on a game day as well too. Oh man, you got a span of thousands, like actual, like non-security people that are like, exactly, what the hell are these 2 guys talking about?
Why, why do they have the stage? Exactly. What is wrong with them? That would be a good time. All right, uh, enough of the digressions.
Let's, uh, get through some announcements. Uh, in case you hadn't noticed, we have a Slack channel. Uh, if you guys want to join the Slack channel, go out to the website. There are instructions there on, on how to join. Uh, we also have a mailing list.
Again, if you go to the website colorado-security.com, you can sign up for that. You will get one email a week from us with the show notes. We'd also love it if you went to your favorite podcast player and rated us and subscribed so everyone knows how great the podcast is and how— and you'll get this in your podcast player automatically every week. Also, uh, let people know how great Colorado Equal Security is and how they can join in with us. And finally, if you want to contribute financially, we do have a Patreon campaign that goes to covering the costs that Robb and I have for doing all the Colorado Equal Security things.
So we would love it if you would join that, and thanks to all of our current patrons. Uh, all right, uh, let's jump into the news first. Brian, did you know that the Denver metro area is getting a new area code next spring? I did see that. It really made me wonder, how often does this happen?
I sort of thought we had already given all the area codes out. Yeah, you would think that that had happened, right? But I guess at some point maybe they do run out of area codes, and then we have to move to 4-digit area codes or something like that. Area code v6. It's going to be a disaster.
So there's going to be area code translation and other things like that so that you don't actually— anyway. So as you all know, for the Denver metro area, there's the 303 and the 720 area codes. 720 came in— where is it— in 1998. So this was an overlay. Previously, 303 had covered all of Colorado, and over time they had chopped it up and added 719 and then 970.
But now I guess we are running out of numbers again, so we have to add another overlay, as they call it, on the same area. So we will now have the 983 area code. And according to this article, it says that's supposed to last us 25 more years. How are area codes still relevant? Like, do you, do you have a— like, what's your area code?
Uh, so I'm a 303. Okay. Uh, my wife is a 720. Or a Google Voice 303? No, no, it's, it's real.
Okay, it is real. I was lucky that 720 was in existence when I got the— my cell phone number, uh, you know, back in the early 2000s. Yeah. Uh, but just happened on a 303 number because I still have my Indiana area code. Yeah, from when I was at Purdue, and they just seem much more irrelevant these days.
Yeah, it is surprising. Um, I guess I don't understand the point at this point either. Um, maybe at some point we will just go to, you know, 10 random digits and that, that's your phone number. Um, because it used to be, you know, there was area code and then there was I forget what they call the middle 3 numbers, exchange or something like that, right? But like those were like for neighborhoods and things like that.
So you knew if, um, like in my neighborhood 979 was a, uh, an exchange, right? So around here, so you know if it's a 303-979 number, like this, the business around here actually got that, you know, sometime long time ago. I see. Um, but yeah, I mean really I don't think it makes much sense anymore. So right now the biggest benefit is if I get a phone number from a 765 number, it's definitely spam.
No one I know in Indiana discalling me from there. That is true. All right, uh, next story. United Airlines buys 15 supersonic planes from a Colorado-based jet startup, which is awesome to see that they're headed toward— I think it was 2029 that they plan to be in service. But that would be really cool if that happens, because for me it was always a dream to get to fly on the Concorde at some point.
So when they retired that, that was always a big bummer. So really neat to see United buying into that future and then that they're coming from Colorado. Yeah, so we've talked about Boom Supersonic, which is the, the company that's building the plane, several times on the show. We also maybe threw a Boom article a few weeks ago. I don't know if you know, but it was like $15,000 round trip to fly on the Concorde, which was like $20-something in today's money, which is just insane that you would pay that for, you know, a round trip ticket.
But anyway, so it is cool to see that Boom is making progress and that they're actually selling jets even though they don't have any jets to sell. I guess jet futures at this point. But yes, the Overture, which is the jet that they're working on, is supposed to be into service in 2029. Hopefully that is actually the case. And again, I think we've talked about this before, but, you know, it's going to possibly cut some of these long-distance flights in half.
So instead of 7 hours from New York to London, it would be 3.5. Yeah, that means London is a day trip now. Yeah, I mean, long, long day trip, but yes, day trip. So you could get up early, uh, or I guess fly overnight still, probably just because of the time zone differences. But, uh, but yeah, that would be pretty cool.
Uh, I'm very excited also that it's, uh, coming here in Colorado and I'm hopeful that maybe they, they do some things where you could, you know, maybe go have the jets on display or something around here and go check them out. Yeah, anyway, I'd like to see that. All right, moving on. Next, another big story. This is a little bit old.
We're combining news from the past 2 weeks since we didn't have a podcast last week. But Colorado-based JBS, which is one of the biggest meatpackers in the world, was taken offline from a ransomware attack, and I believe they are now 100% back online. But, you know, the shutdown affected some plants, including the one in Greeley where they have 2,900 workers. Looking at some of the details, you know, this is being attributed to the REvil group, which is, you know, one of the groups that has been, you know, extremely prevalent and making lots of money doing ransomware. It also looks like the reason for the shutdown was maybe not because of their systems being offline, but, you know, them being more cautious and basically taking everything offline to make sure that the systems that were compromised didn't continue to spread.
I don't know if you have any more information on that, Brian, or not. I don't, but if that's what they were doing, that's a smart move to prevent it from hitting everything. Yeah. And I think that this is, you know, just going along the lines of the other things that we've seen lately with, you know, the Colonial Pipeline and lots of other different businesses that are getting hit by ransomware and things that we are starting to see, you know, affect our day-to-day lives because of ransomware. So it is that time.
Some of the coverage I've seen that's been interesting and sometimes frustrating is that people people are talking about this and Colonial Pipeline like they're a wake-up call for the industry. And I think we've had wake-up calls like this has happened for the last decade. Maybe it hasn't always been ransomware, but every single business needs to know you have to be prepared for this and they have to spend the time and money in order to go do that or else they're going to have very bad things happening to them. Yeah. One of the things that is not known yet, as far as I'm aware, is whether or not JBS paid a ransom.
Um, I think it'll probably be another week or two before we, we start to hear stuff like that, right? Uh, you know, the Colonial Pipeline attack, which was a couple weeks prior to this, you know, now that the details are starting to trickle out about what was happening there, so maybe we'll hear the same about JBS. Um, but, you know, based on their, their PR, it sounds like they were able to handle this okay, right? Which is good. Congrats to them on being able to handle it and recover.
I think they were only offline for 3 or 2 or 3, 4 days. Absolutely. This article is actually in the Colorado Sun, and it's a very detailed article, although I guess it, it does come from the AP. But it's, you know, they talk about the fact that meat processing, meatpacking, they can afford to have a delay of a couple days, right? They can make up the difference with extra shifts and things like that.
But if you start getting to like a week or a couple weeks of, uh, not being able to do meat processing, then you're going to see some significant impacts, uh, in the grocery store and prices and, uh, you know, other things like that. So, uh, obviously very serious, and we hope that stuff like this doesn't happen, uh, specifically to JBS but to other critical infrastructure, uh, players again. Yeah, absolutely, definitely. Things like this are not novel anymore. People need to spend the time and be prepared.
For sure. All right. Following that, Datadog, who's based out of New York, has selected Denver as their second primary location, and they're going to be bringing 400 high-paying tech jobs to Denver. That's exciting to see. Datadog has been a great SaaS company and grown really well, and it'll be awesome to have their need for more great tech people in the area and hopefully attract some talent from New York and the Bay Area here.
Yeah, I think it's, you know, it's another one of, uh, of the line of many companies that are starting to move, uh, you know, second headquarters or, you know, big presences here to Colorado. Uh, this one was, you know, based on some incentive that the economic development group gave to them. Pretty cool that, I mean, 400, that's a pretty big number. So glad to see that that's coming. They also talk about a couple other ones that were happening here.
The other thing, you know, we go over these stories a lot. Usually, you know, the Economic Development Commission says they're giving money to some project codename, and then later, like when it comes to fruition, like you hear what that was. So back in— what was it— back in November, they'd announced that they were giving, uh, $5.4 million in incentive credits to Project Rover. Ah, so that was DataDog. Makes sense.
Um, yeah, and, uh, the article goes in and talks about a few other companies that, uh, that were getting incentives. Uh, Crusoe Energy, which I think we've talked about before, which is an interesting one. They take the off-gassing from oil and gas production, use it to run electric turbines, and those turbines power mobile data centers which largely do crypto mining.
All right. So, so you're taking the things that would be wasted and polluted in the environment, using them to mine cryptocurrency. Theoretically, one of the greatest wastes and polluters of the environment in terms of compute, right? Theoretically, you could do other things with it too. But I think that that's their— that was their first use case.
So, uh, anyway, pretty cool. Uh, glad to see that Datadog is coming and, uh, hopefully we, uh, we hear more from them. We'll keep our eyes open for, uh, job posts. Uh, next, uh, Guild Education has announced that they are, uh, doing a Series E raise of $150 million. Uh, and with that, they're planning to double their engineering team.
So, uh, congrats to them. I mean, I guess now, you know, being on Series E, um, they're getting close to the end. They're gonna, I would imagine, have to go public here pretty soon. But I feel like this has been like a really fast rise for them. Um, it does say that they were founded in, in 2015, but I feel like it's, you know, mostly newer than that that they've had any kind of success.
But, uh, for those that don't know, Guild is an education company, so they work with, uh, with other large companies to to give education essentially as a benefit to their employees. You know, like McDonald's, for example, if you wanted to make sure that your workers had a chance at higher education so they could maybe go on to do some other things. And, uh, it's pretty cool. Guild's been growing, uh, with this Series E. It puts their valuation at approximately $3.75 billion. So pretty cool for them.
Yeah, that is awesome. And With the next 2, kind of 2 interesting related articles. One was that nearly 200 companies with Colorado customers reported data breaches in the past 16 months. And then we had a highly amended, yet again, Colorado Privacy Act passing through the Senate. And kind of interesting to watch how privacy is a big focus of time inside the state legislature.
Trying to figure out if Colorado is going to be the third after, I think, California and, what is it, Virginia, who had the big data privacy laws. Are we going to be the third? And watching a bill that had some deep provisions in it, then had a bunch of them pulled out, now they're back again. Interesting to see where that one ends up. Yeah, I think this first article was actually really interesting to me.
This was by Tamara Chuang in the Colorado Sun. It talks about all those 200 reported data breaches. And it really, so this is related to the Colorado Data Security Law that passed a few years ago. And as part of that, you have to notify the state AG when there's a data breach. The interesting thing in here is that it really highlights the patchwork of data security laws.
They, they give a number of different examples where a company has announced a data breach of, you know, X number of records, and then the, the AG here gets notified of an extremely small amount of records that are a subset of that. Um, or, uh, you know, maybe they, they announce, uh, something but don't notify the AG's office, or other things like that. So, uh, really interesting to see how this is actually working. I mean, I think it's great that we have the data security laws, but it doesn't seem like they're being uniformly followed by people. And, you know, when they're not, there's, there's just not resources by the AG's office to really follow up and, and make sure that people are doing what they need to do or prosecute if they're not.
Yeah, yeah. I think there's a big— there's the big so what question throughout all of these, right? Of when the AG gets it, so what? Like, what do we expect them to do? What does the state expect them to do?
And then like a fascinating statistic I saw was, I think it was when they were talking about the first versions of the bill going through the Senate right now, they were saying that the cost for state agencies to comply alone was something like $2.5 billion, right? And so you have to sit there and ask, is that what you want $2.5 billion of state money being spent for? And what is the so what, right? It's going to be very interesting. Yeah, I mean, and on that privacy law side, it one is going to be interesting to see if they actually get it, get it passed.
They have until June 12th. So basically another week. That's when the, the legislature session comes to an end. But yeah, you know, as you were mentioning earlier, there was a much stricter version of the bill and then it got amended. To be much weaker, and then it got amended again to be, I think, almost as strict as it was originally.
And, you know, the article, which is from the Biteback blog, Husch Blackwell and David Stauss, you know, talking about how originally it was opt-in and then they changed it to opt-out, and now it is back to opt-in for— but for sensitive data, not for regular data. Um, and you know, this is a— it's a great blog talking about all the different things that were changed. Um, also, one of the other things that came in the last one was they had put in a right to cure. So basically, instead of you just being at fault for it happening, you had a chance to fix things, right? Well, now they have changed it a little bit.
There is still a right to cure, but that right to cure sunsets January 1st, 2025. So You get a couple years of a right to cure, and then I guess they assume at that point you better know how to do this, because then if you screw up, there's no right to cure anymore. So I don't know, it's going to be interesting. I mean, I would be happy to see it pass, but I think when it does pass, it's going to be a pretty big— or if it does pass, it's going to be a pretty big lift for Colorado businesses to make sure that they can comply with that. Well, I mean, but it won't be just Colorado businesses, right?
It'll likely be EU-style jurisdiction of if you have data about any Colorado citizen. Yeah, I mean, yes. Thinking about it is if you're one of those companies that, that is not in Colorado, you probably are already having to do these things for either GDPR or CCPA or something else. So I think it probably will affect Colorado companies disproportionately because those that just deal with Colorado consumers probably haven't had to deal with those other ones. That's definitely true.
All right, next, some acquisition news. Last week, Coalfire announced that they were acquiring Denim Group. So Denim Group is a big AppSec shop. They do a lot of consulting. John Dixon is one of the principals down there.
And we know John very well. He's a good guy. And they've grown a lot over the year and are really a leader in that space. They also have the ThreadFix platform, which helps people do AppSec in applications and fix vulnerabilities. So they were acquired by Coalfire to help shore up Coalfire's offerings in this area.
So I think it's a win-win. Coalfire gets to get better here. Denham Group gets an exit and gets to be part of a bigger organization. Yeah, absolutely great. Similar, but on the acquisition of great talent side, Swimlane, who is our local security operations orchestration and response.
There you go. I will always get the O and the A wrong on those. Great SOAR company locally. They introduced 3 new appointments to their leadership team: a new Chief Marketing Officer, Chief Financial Officer, and SVP of Customer Experience. So all of them coming from great backgrounds.
Really excited to see a great Colorado company adding more to their leadership team. Yeah, I actually have an interview scheduled with Cody this week to re-interview him for the podcast, so I'm definitely going to ask him about these new leadership additions. So that should be good. Next, we have a blog from Laras talking about something they have released called Sysmon Config Pusher, which looks really cool. And Brian, I'm sure that you have some insight onto this in the sense that I'd imagine you guys deal with Sysmon fairly often at Red Canary.
But the blog talks about the fact that Sysmon is a great free tool within Windows to to do monitoring if maybe you can't afford EDR or, you know, just as a supplement. But oftentimes it's hard to make sure you're getting the config correct for Sysmon across all your systems. And so Larez has introduced this Sysmon Config Pusher to make it easier to do that. Yeah, it is one huge kudos to the team for following my favorite process for naming products, which is literally name it what it does. Like awesome to see.
One of the biggest challenges you always have with Sysmon is how do I actually get systems to follow the group policy that tells them what to collect and in what cases? And now to have a tool like this that you can use that to orchestrate it across all your systems is great. I mean, Sysmon is a great way to get started if you don't have full EDR. Definitely a useful tool to help get that rolled out and deployed. Nice.
Following that, we had an article on ThreatPost about Biden's cybersecurity executive order having all of the wrong issues and focusing on the wrong things. That was actually written by David Wolpoff, also known as Moose, over at Randori, and really focused on one interesting part of it that I thought, which was the push of organizations to move very quickly from on-premise to cloud. And talking about how if you go do that very quickly without having a good plan, you're going to make mistakes, and mistakes are going to create opportunities for adversaries. And he is totally right. As good as some of those moves to the cloud can be, they also can be very, very damaging if you do it wrong.
Yeah, and I think it's a great point. I think in the long run, a move to the cloud could be extremely beneficial for for government customers, you know, because they're not going to have to deal with a lot of the things that hold government back. You know, slow-moving infrastructure, not enough budget, things like that. You know, if you're in the cloud, stuff is going to be updated for you, managed for you, those kinds of things. But, you know, one of the benefits that you have of an on-premise solution is, you know, you probably have really big walls around your stuff, right?
It's not going to be open to the internet. Of course, the drawback to that is when you get around the wall, you know, then you have access to all the stuff on the inside. But yeah, I mean, if you make a push to the cloud and you don't really think about what it is that you need to do to secure it without those walls anymore because you're in some more public environment, then yeah, it can lead to bad things. And we don't want to compound a bad situation by making it worse. Exactly.
So interesting perspective there from Moose. Moving on to the next article, more talk from the government. So this is another article from Laras. This is actually, actually by Andrew Hay over at Laras. And he is talking about how the White House ransomware memo, which came out this past week, what it got wrong.
And really the, the, the net there is that You know, one of the pieces of advice in that, that memo that came out, and this was actually from, from DHS, from Ann Newberg. And basically it said, hey, you should, you should get some advanced tooling, which was not the only advice that was in there. But I think that his point was maybe let's think about doing some other things before we get to thinking about advanced tooling. Which is, I think, sound advice. You know, there were some good things that were in that ransomware memo.
Basically 5 things that you should do: back up your data— that seems like a good idea. Again, this is all related to ransomware. Update and patch. Test your IR plan. Check your team's work, aka penetration testing.
And segment your networks. So I think all of those things are great to help prevent ransomware and things that people should be doing. So I think if you focus on that, and not necessarily the tooling part, I think you will be in good shape. I think altogether, you know, especially having spent a bunch of time with different government agencies, this was probably the most concise and well-written 2-page memo I've seen from the government. Like, if you can get a copy of it and send it around, you know, or a link to it with the show notes, it's actually difficult to find, but when you look at it, it is something every organization should follow.
Like, it had really good advice in it. Yeah. From the stuff that I have seen from Anne Newberg, she seems to be sharp and does good stuff. Yeah. So next, we actually had a blog from Red Canary that I see you conveniently timed so I would end up having to speak about this one, talking about what is normal in System32 binaries.
One of the things that was fun about this is we actually had one of our Red Canary detection engineers and we paired up with Mike Haag, who is a former former Canary who's now on the Splunk threat research team, and they wanted to educate everyone around what do System32 binaries actually load in their dynamic link libraries so you can identify if someone is doing search order hijacking, which is where you sneak in your copy of a library before a similarly named proper one so that it runs your malicious code instead of the proper code. This is another one of your guys' great, very long, detailed blog posts. I don't know that we're going to get into the details here, but I think you just gave a very good summary there, Brian. I did my best. So I would say take a look at this.
You know, while it is something that I've heard of before, I hadn't really dug into it too deeply. So it was good to see. And if you are someone that is very technical, lots of good stuff in here on how to prevent this stuff, how to detect it, how to prevent it. So another good blog post by you guys. So last news story, another Biteback Law blog here from David Stauss.
This one is sort of hot off the presses. This was Friday, I believe. The European Commission has announced that they've adopted their new standard contractual clauses. So basically, you know, one of the ways that you can do data transfer— transfers and feel confident that you won't get into trouble from, uh, from GDPR is to use standard contractual clauses. Basically, these are the things you need to put in your contracts to say we are doing these things to make sure that the data is protected and kept private.
Um, because of, uh, some of the, the previous, uh, court rulings and other things, the, the previous versions of, uh, standard contractual clauses were no longer valid. So now they have to put out new ones. Um, some good analysis of this here, at least at the high level, considering it just came out on, on the 4th. Um, but you know, there's definitely gonna be some work to do for people to have to go back to their contracts, put in new standard contractual clauses. One thing that David notes in the blog post is that, uh, a footnote found in Section 3, Clause 14 basically says— um, I'm going to summarize it and say you basically can't just put these clauses in your contract and expect to be safe if there's reason to believe that they can't be enforced legitimately, right?
So, you know, one of the things was European countries were wary of putting their data in the US because the government can go and seize that data. And so basically it's saying, you know, if you say something in one of these clauses, but we know that the data is hosted in the US, for example, and we know that that can't be upheld because of the way that it is, the laws are in the US, then maybe we're not going to consider this valid. So it's going to be interesting to see how these actually get implemented or if you're going to have to put in other clauses in addition to the standard contractual clauses to make sure that you don't run afoul of European data commissions or other things like that. Anyway, but it's sort of big news on the privacy front. Yeah, it'll be interesting to see, does this over the next 18 months that people have to comply with it, does it trigger GDPR 2 all over again?
Where everyone had, you know, they had built on the foundation of the contractual clauses and now they change. Yeah, exactly. All right, so that is our news. Again, we had a longer newscast this week because of 2 weeks' worth of news and there was lots of great news in there. We're going to jump over to events.
We've got a few events coming up. First, starting on the 7th, NCC is doing their Cyber Patriot camps for kids. Um, so, uh, if you're hearing this, it's probably already started, but you may still be able to get your kids in there. Uh, go check out the NCC website for more information on that. And next week we have RMISC, which I'm sure you have tons of great details for.
Yeah, so tell us more. Coming up, um, Tuesday to Thursday, Tuesday to Thursday, 8th through the 10th, is RMISC. Uh, there is still time to register. Um, if you guys need a discount code, please, uh, hit me up in Slack. I've got some of those, but it's It's going to be great.
We're doing 3 half days. However, since this is virtual, if you can't make it to any of the sessions, they are all recorded so you can come back and see them. If you are someone that needs CPEs, you have the ability to get over 90 CPEs if you watch all of the different presentations for RMISC. So really excited. I am doing the CISO panel as the keynote on Thursday morning.
I am moderating that, so that should be fun. Go check out rmisc.org. That's great. Yeah. Exciting to have that happening this year.
It is. I'm excited. I'm looking forward to being back in person next year. Next, we have the AppSec group that Dustin Lair is running talking about what is threat modeling and why should I care on June 11th. And then we have on the 17th, ACISS is having an event focused on propaganda and extremism today.
That should really be interesting. You know, ACISS is the physical security group, but, you know, propaganda and extremism is something obviously that affects all of us, not just physical security, but also in the cybers. So I'll be interested to see what that one looks like. Yeah, that's also online, and it's from their Counterterrorism Education Learning Lab. Wow, which is a neat group.
That sounds cool. That does. All right, let's jump over to jobs. We've got some good jobs this week. First, Platform.sh is looking for a security engineer, and this can be remote.
SpecTrust is looking for a senior DevSecOps engineer. RxReview is looking for a senior DevSecOps engineer. The Trade Desk is looking for an information security engineer. OpenText, which I assume in this context is Webroot, is looking for a Senior Research Engineer for Network Security 1. The Department of Energy is looking for an Information Technology Auditor, and they specified they're looking for a recent graduate.
Yeah, so this looks like an entry-level one. Good stuff there. PayPal is looking for a Senior Product Security Engineer. Jeffco Public Schools is looking for a Senior Information Security Analyst. Both Brian and I are very excited about that.
Since we both live in Jeffco. Oracle is looking for a development security manager. And Ball Aerospace is looking for a senior architect at the senior level. Nice. All right.
So that is it for the jobs. And then that is it for the newscast. Brian, this week we do have a feature interview as well. Janelle interviewed Teressa Gehrke, who is the founder of PopCykol, spelled P-O-P-C-Y-K-O-L. And now that I say that, I am going to have to look up what it stands for because it is Protecting Our Precious Curious Kids Online. So this is a child internet safety organization.
So I'm interested to hear more about PopCykol as part of the interview. That's awesome. That's going to be great to learn more about. Definitely important. For sure.
Well, Brian, thanks again. Appreciate you filling in. Robb is going to be back next week from his travels around the US, and we will talk to you then. Looking forward to it. Thanks for having me.
Thank you. Talk to you next week.
Hi, this is Vincent Grimard, CSO at Nelnet. Welcome to Colorado Equals Security, for Colorado security professionals by security professionals.
Hi everyone, welcome to Colorado Equal Security. This is Janelle Hsia. Joining me today is Teressa Gehrke. I hope you enjoy our conversation. Teressa is the founder of PopCykol.
Teressa, welcome to the podcast and thank you for taking the time to talk with me and share your insights today. Thank you, Janelle. It's a pleasure to be here. Well, tell us a little bit about yourself. Sure.
I'm Teressa Gehrke. I'm the founder of PopCykol, which stands for Protecting Our Precious Curious Kids Online. It's a cyber security awareness company for kids. I earned a Bachelor of Arts degree from the University of Denver in art history and anthropology. I have a master's degree in anthropology and international development from Colorado State University, which gives me a unique perspective into the human experience and culture.
And I also studied network security at Arapahoe Community College. I've been working in security engineering since 2014. Consulting as a technical writer, project manager, and customer experience consultant. And kind of the cherry on top of that is I'm also an award-winning singer-songwriter of kids' music, and I love the idea of bringing my passion for music and art to PopCykol. Wow, that is a very stellar resume, and I'm so again excited for the interview.
So why did you decide to get into cybersecurity, and was it hard to get into cybersecurity? So I got into cybersecurity through technical writing. I had taken a position at the National Wildlife Research Center as a work study during graduate school, and I had these interviews on the same day. One was for like a librarian and doing graphic work, and then the other was for a research assistant. And when I interviewed for the librarian position, I knew I was going to have to look at snakes slides of snakes.
And that was very unappealing to me, because I'm pretty scared. And so I ended up taking the research position in the economic department, and just found that I was really good at kind of this technical writing and research report writing. And that's how I got into technical writing. And then I took other consulting roles in different industries, biotech, security engineering, and that's kind of how I got into cybersecurity. And so you obviously enjoyed that piece of it because you went back to get an associate's in it.
So what was it like to go back to get your associate's? I actually don't have an associate's. I'm sorry, I took all of the core, like the primary coursework in computer networking and network security, and just didn't need all the gen ed stuff. But I really liked it. I was surprised I got a 4.0 in my degree because occasionally that would happen when my semester grades were really good in college and graduate school.
But I worked my tail off for, for those grades. But I really liked it. Awesome. So this diverse background of music, anthropology, cybersecurity, and then you didn't mention your blog, which I love the name of, Dark Shiny Unicorn Cyber Blogger. And you're a podcaster.
So that's a lot of experience that you bring to the table. So how are you using all of these skills together for PopCykol? Sure, I feel like every little thing was an incremental step towards getting to PopCykol. And so last summer I worked for a mobile security company as a cybersecurity writer. It was like a 3-month internship, but I was learning about and researching mobile security threats and Internet of Things threats, as well as legislation and compliance.
And I kept— I found myself wondering why the threat actors do what they do. And I was able to fall on my anthropology background, thinking about human behavior, thought processes, and culture. And then I came up with this idea for the Dark Shiny Unicorn cyber blog, where I could really highlight my passion and interest in anthropology and connect that to cybersecurity.
So those 2 disciplines working together, they give you that unique perspective. So how does that translate into PopCykol? Because is PopCykol— who's your audience for PopCykol? Is it schools, parents, kids, or all of the above? Kind of all of the above, but definitely directed towards the littles, tweens, and teens, and of course parents.
Okay, and I don't think I asked you, but why did you start PopCykol? Ah, I started PopCykol because of my son. He's in elementary school, he's a 4th grader, and he's just very clever and a little bit sneaky. And he found ways to work around and bypass his school security and the monitoring app. He also figured out how to hack his phone by seeing me enter the code to his cell phone in the reflection of a window.
And so he knew 3 out of the 4 numbers of the PIN, and he deduced from that what the last number was, was able to open up his phone and download apps that I would not have approved of, and figured out how to do stuff on his school computer that I also would not approve of. And so I was kind of sitting in my mom's room and I was just like, we need to figure out a way to protect him. 'Cause I thought I was doing a pretty good job, you know, working in cybersecurity and I'm checking his things and I've got the app and sure enough, he was just very clever. And so I came up with this idea for PopCykol. That's awesome.
And I know that you're just at the beginning of the adventure. Did you have some help getting started?
Well, kind of just, you know, brainstorming with my mom. And obviously, I was influenced by my son. But so far, it's kind of been started by me. And I have reached out to a designer and animator who worked on a kids music video of mine. I, as I mentioned, I'm a singer-songwriter of kids music.
And I go by the persona or stage name Teressa G and the Monkeys. And I put out a kids album in 2019 called Hippity Hop Pop. And one of the songs from the album called Tub Soup, I created into a kids music video. And it was submitted to a number of film festivals where it won— has won a number of awards and received a number of nominations. And so one of the animators who worked on Tub Soup is now my designer.
Awesome. And so the goal of the website and kind of how is the content organized? Like I've a couple videos and I want to ask you specifically about those, but is that kind of your thought process from an awareness, you know, of how you're going to do awareness for the kids? Yeah, so ultimately I, I have 5 scripts that I've developed and they will reach different demographics, um, but they will be animated. So I have these penguin ambassadors, there's 3 of them, there's Spicy, Savvy and Sweets, and they're going to be the storytellers of our cybersecurity lessons.
And so they will kind of run the gamut of stories for the littles to understand. And so there'll be 1, maybe at most 2-minute videos, and then we'll hit some of the more deeper, more difficult topics of cybersecurity, like cyberstalking and bullying, as well as you know, things like revenge porn or human trafficking. Wow, those are really deep topics. So how are you going to bring those across in a child-friendly way? Well, I have a child, so that's helpful.
And, you know, I think being around the kids' music and kind of having that, that knowledge of the audience is helpful. And also being an anthropologist and knowing about culture and human behavior, I, I think that really helps me be able to reach that audience as well. Yeah, and I do think that it needs a delicate touch with those topics, right? And I completely agree as a mother myself that they're really important topics to talk about with our kids. So, you know, I'm really glad that you're doing this and going to be providing this content.
And I was on your website, and so I see that you have something called a taste tester. Do you want to tell us what a taste tester is? So a taste tester is essentially someone who wants to help me be a volunteer, or help me— will be a volunteer for me and kind of be a part of the focus group. So I want to be able to have that one-on-one interaction with people. When I'm presenting new content and media to my demographic.
And so I have a couple of people that I've reached out to, I've talked to a high schooler, and she gave me some really interesting insight into some of the things that she faces. And I've asked her to be a taste tester and bring on some of her friends as well. And so just, you know, I would like to have a focus group for the littles, the tweens, and the teens. I love that. I think that's just a really great example of how, like, when I saw that, I was intrigued to read more about it, right?
And so I think that's just an example of that, that, that how you can convey that to express interest or get people interested. So how big do you think this will get? Do you want to be local, national, or to have a global presence? Well, I definitely want to have a global presence. And actually, the day that I shared out PopCykol on LinkedIn, I had a woman in Africa reach out to me expressing an interest in patterning my model.
And I'm like, well, I'm literally just starting. So there's not a whole lot yet to model. However, you know, in talking with my attorney, he said that there's a way for me to license my media. And I can do that in a way where I can create like a package, a content package, where I could provide maybe like the logo or some— the template to the video. I have obviously scripts and voiceovers and background music.
So that might be a way for me to reach out globally. And of course, you know, the idea of going big is very appealing to me. I would love to have a Super Bowl halftime commercial for popsicles. So that's That's the big I want to go. Dream big.
Think big. I love it. That's awesome. Well, you mentioned your son Sneaky. So are you concerned about putting him on the videos or having using his examples?
In some ways, yes. You know, I've always been very protective of my son because I fostered him for a number of years, for 2 years, and then I adopted him in 2018. So I'm very aware of his presence on However, I also knew that I really needed some buy-in. You know, if I created a video or a blog kind of based on the Dark Shiny Unicorn, which is obviously catered to cybersecurity professionals or what I would call cyber curious, then it wouldn't go over as well because I'm kind of innately kind of serious professional individual. I'm kind of introverted as well, and he's very outgoing.
So when we do a video together, it's— we've got this kind of fun interaction and we kind of play off each other. And he, he's funny. I like doing it with him. So he brings kind of the levity to the videos that I really enjoy. Yeah, I have to say, you, you have awesome chemistry and he is so darn cute.
And a couple of them too were you guys messed up the song or whatever and then just did it again. And I love how those bloopers are there and it's just real, and I think that'll relate to the kids. I certainly hope so. You know, I'll have the live videos, but I'm really also looking forward to having the animated videos, and I'll be doing the voiceovers for those as well as having my record producer helping me out with the voiceovers. But I, I love the idea of having kind of you know, this interpersonal connection with my son that we can share out.
And then also having kind of more of the standard, like, here's how you can understand password strength or netiquette or cyberbullying and kind of take the human element out of it so that the message is still very clear and concise. Yeah. And this is perfect because I want to segue to one of the videos that I watched on your YouTube channel. So I did watch the Google Classroom video that you recently posted, and it was about kids using Google Drive, Google Classroom, and these untitled forms at school. And I know that our schools are trying to keep our kids safe, but Sneaky found a way around this.
So can you tell me more about that? Yes, I can. And I, and I got an email from the school today, so there's always, you know, New development. Oh, breaking news. I've never done that before.
Yeah, yeah. So, um, so we use a— the school district and parents can use a monitoring app to monitor behavior online. And so, um, what has— what he has figured out is he can be in Google Classroom and he can create an untitled form and embed videos that are inappropriate into the form and email it to himself or, or to another, and then he can accept that form when it comes in as an email and watch the video and kind of bypass the monitoring app, or he can make a presentation and he can go to Insert, Video, do a search find the video he wants and then select it and then watch the video from the presentation. So it's very clever. And I actually took a video yesterday.
This is so breaking news. I took a video of how he does it and then what we see in the app. And it does not show that he's done a search for the thing that is inappropriate. It's not sexual in nature. He's like 10.
Right. But it's, you know, videos Granny videos or Baldi videos that I would never condone. I don't know how he even learned about it. I'm sure it was through the chat. Um, and so you can see in the, in the monitoring app that there's nothing happening.
It, it just looks like he's in Google Classroom. So, uh, today I got an email from IT tech support. They are reaching out to the monitoring app the vendor as well as Google to say, you know, this is what's happening. And I made the video so they can actually see what the interaction looks like online. And so he's just— yeah, he's clever popsicle.
He's sneaky popsicle. Yeah, I love that. And I have to say, my kids are older, right? I've got a graduate from high school and one in college right now. And I think that this is what to me is so awesome about what you're doing is Like, I wish my kid— I would have had this sort of like monitoring for my kids because they probably had ways around all of this.
And we just didn't have the tools or, you know, the— we didn't do anything about it. And so how— so is this kind of your model where you, you know, when you find these things, you have an avenue to reach out to the school and kind of affect change? Well, I do now, you know, and, and our school district has been incredibly helpful, you know, because there were some issues around cyberbullying in the fall. And, you know, I, I do random checks of his chat and they have adjusted some of the chat room settings. It's not perfect, but I know it's going to get better because there's, you know, parents like me who are out there just like This is wild territory, right?
You know, with remote learning, and I wouldn't have expected us to go through a pandemic like this and have my son have a full year of remote learning, but here we are. And so there are just these unexpected dangers for kids of all ages and adults, as we've seen. Yeah, and I think that, you know, I always try and find the bright side of things, so maybe one of the upsides of the pandemic is, you know, sneaky being home and being online learning so you could start PopCykol so we could be better informed all the way around. What do you think of that? Absolutely.
And I think what's really nice about PopCykol is that the message is going to be short and sweet and clear and correct. And if I don't know something, and I— and certainly I don't know everything there is to know about cybersecurity, and I would never claim to, But my cybersecurity, my cybersecurity community is amazing, and I shared this the other day. I am so lucky to be part of this tribe where I can reach out to anybody and say, can someone tell me about this or explain this or provide a reference or resource material for me because I'm, you know, I'm really curious, but I don't, I don't know what this thing is. And so anytime I've ever done that, there's always been someone there to help me. That's awesome.
Is there, uh, you mentioned that you had recently posted this about the community. Is there, you know, being relatively new to the community, is there something that you really enjoy about it besides just like the camaraderie and the, the, um, you know, like what's, you know, coming new to the community Are there other things that you appreciate about it?
Yeah, I mean, I, I have people that I— that are friends now, um, who are— that I've just met through different organizations, um, especially women. And but there's these great male allies as well. And, um, I, I just really appreciate that. Uh, and I'm trying to think what else. You know, just as I am developing and sharing popsicle, I have gotten a very positive and encouraging response.
Like, I'm messaging my followers on Twitter and messaging people on, on Instagram and sharing this with people, and people have said, this is great, this is really needed, this is a great cause. People believe in the mission of it, and that feels very validating. So I'm honored for that encouragement. And, you know, as I'm sharing this more and more with people, people want to support it financially as well, which is great because not quite there yet, but that's ultimately the goal to get PopCykol videos and more content out there to the kids. And I actually did want to ask you about that, whether you were ready for investment.
Um, or fundraising? Um, so you kind of answered that a little bit, but from a direct question perspective, is there anything people can do to help financially?
Oh, always, always. And, um, I'm planning to do an I Fund Women campaign, but I'm not quite there yet. Um, I really— I'm literally just trying to get the word out and individualize the messaging to people and say, hey, I'm here, I'm new, please support PopCykol by following. And, and at some point, then there will be another follow-up message saying, would you like to fund PopCykol and give? Because it requires a lot of extra time and effort.
So it requires me to go to the recording studio and work with a record producer. I've put out a number of albums and And so I have a great working relationship with the studio. And then I have my animator and designer. And at some point I'd like to hire someone to do some of the voiceovers because my, my voice tends to work for about 30 minutes and then it's done. So I've done voiceovers in the past, but I know where my limit is.
Awesome. So it sounds like it's stay tuned for more information on funding. Absolutely. Cool. So, and as a busy mom and as a businesswoman now, what do you do for self-care?
Well, I'm pretty introverted and I need a lot of downtime, quiet time for myself. My son is very outgoing and, and he's also not just clever, he's very inquisitive. And from the day that I got him, he's always asking questions. And I love that he's curious. But it can also be pretty exhausting because I don't know everything he's asking me about the moon or the Titanic or the weather or sharks.
And so I, I need a break. I'm also taking care of an aging mother who has health issues and an aging dog who's now 13. He's really been struggling. And so I need to take a walk. I love to go stand-up paddleboarding, and sometimes I take my son with me, but other times I just need to be on the paddleboard, soak up the sun, and ride the waves.
I love that. I love the sun and the water as well. So I usually talk to people about giving back to the community. As you mentioned, like, the cyber community, especially here in Colorado, is so encouraging. And there is such an awesome community.
And I think PopCykol is a huge way for you to give back. But are there other ways that you give back to your community?
Sure. At the beginning of the pandemic, I offered my writing and editing services to help others with their resumes. And I did that for free. And so I There were people who really thought that was very helpful, and I still offer that. I actually did a resume yesterday for, for someone that I'm considering bringing on to the company, and I just— she's newly graduated from college, and I'm like, this is a decent resume, but I know it can be better.
So I offered that, you know, just as a help to her. I also like to give back to organizations that I really care about, and those are around rescuing animals. So I like to give to Hope for Paws and the Wildlife Animal Sanctuary. The Wildlife Animal Sanctuary is one of my favorites. And if we're— I think we're connected on LinkedIn and you'll see me post a lot of stuff from them.
I just absolutely love their animals too. Excellent. Yep. So we're about out of time. Is there anything we haven't talked about yet that you want to tell the Colorado Eagles community listeners?
Connect with me, connect with PopCykol. I have all the social media and subscribe to the YouTube channel. Obviously, at some point down the road, hopefully later this year, I'll have the crowdfunding campaign going and I would love support for that. Like I said, I have 5 scripts that are ready to go and be developed into 1 to 2 minute videos for kids and they're around Password strength, cyberbullying, netiquette, catfishing, and another one I can't remember. And so, you know, they're, they're ready to go.
I just, I need to be able to go back into the studio and record background music and the voiceovers and connect with my designer about kind of the vision that I have for popsicle videos. And so I would love that financial support for the creation of those. Down the road. Awesome. And I can tell, I mean, every time you speak of it, you just have so much passion in your voice.
It's so great. You know, this is the first time in, in my life, in my career, where I have felt like everything has come together in the most perfect way. I don't think that somebody else could do PopCykol the way that I have envisioned it, where I can bring in my kids' music and the video that's really fun and inviting and talk about human behavior and experience as well as the cybersecurity piece the way I can. I think you said it perfectly, and I think that's a great way to end it. So, Teressa, it truly has been a pleasure talking with you.
I want to thank you so much again for your time, and I'm super excited to continue to support you in any way that I possibly I appreciate that so much. Thank you, Janelle. You bet. So this is the end of our interview, everyone. Until next time, thanks everyone for listening.
Bye-bye.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Safe. Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.