Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 224, the week of September 13th. Alex, how you doing this weekend?
I'm doing pretty well. How are you, Robb? Doing very well. We, we celebrated the 20th anniversary of September 11th yesterday. Sad day.
And certainly a lot of remembering. You and I are old enough to remember before that and that and after that. Yeah, I have to say I was actually flying yesterday on September 11th. And it was a little weird thinking about it being on a plane. It was a little less crowded than I was expecting.
Yeah, we went out at sort of a weird time. That could have been part of it, but I'd imagine it was a little less crowded than normal. Yeah, I definitely feel like it's, you know, 20 years is a long time. It's hard to believe that that defining moment has been so long. Yeah, for sure.
Well, how was your Vegas trip? It was good. We actually went out there. Columbine High School was playing a football game against a team in in Vegas and we won an away game for Columbine. You know what that is?
Yes, it was an away game. They, they try and do a trip every couple years and this was their trip. So that was fun. They did, did end up winning. The, the other team was pretty good, so I'm, I'm glad we pulled it out.
Congratulations. Thank you. I, I didn't play in case you're wondering, so you don't have to, you know. Did you, did you bribe the refs or anything? I mean, I tried.
Clearly I don't have Vegas money, so. Yeah, it'd be tough to, to do that out there. All right, well, why don't we go ahead and jump into some housekeeping? We have a Slack channel if you guys want to join and be a part of our over 2,000-person-strong community there. If you want to join Slack, go to colorado-security.com and click on the Slack link in there.
While you're there, sign up for our mailing list. You can do that on the website. It will automatically add you to the mailing list. You'll get one email every week— well, mostly one email every week. Sometimes you get zero because, you know, I miss sending out the email for the show notes and things like that, but mostly you'll get an email every week.
Somewhere between 0 and 1 on average. 0.8. All right. We would love it if you would rate us and subscribe on your favorite podcatcher. And while you're at it, why don't you tell any friends that you may have, anyone who you've been thinking about becoming friends with, tell that person to join the community and get to know us.
If you do have Vegas money, we are also running a Patreon campaign. To help support the costs that we have for the show. So you could sign up again, there's a link on the website. And depending on the level that you sign up for, you'll get some free stuff. $10 a month or greater, you'll get mentioned on the show, and you'll get a free t-shirt.
All right, let's jump into news. So each week we break down the show, we talk through news, we, we go through interesting events coming up and any jobs that we find and then finish up with a feature interview. So let's go through some news. Starting off with some non-tech news, Alex. Yeah, so this week 169 new Colorado laws went into effect.
One of them is that unless you opt out on your vehicle registration, you'll pay for a Colorado Parks Pass. Yeah, this was— so this is a Denver Post article, and I didn't feel like they did a great job describing this. I agree that as you register, there's an opt-out ability to not get the pass. But if you don't opt out, if you just do your registration without saying no thank you to that. You'll pay, I think, somewhere between $20 and $80, and they weren't really clear on the number.
And that will give you a pass that will get you into the state parks for free for the year. Yeah, well, it's not for free since you pay for it, but it's no additional cost beyond that registration cost. And then, yeah, I think it's an interesting concept because parks are cool, and I think there are a lot of people in Colorado that use them, but I think The idea here is to spread the cost between more people. Yeah, I know. We actually do go to state parks, you know, I'd say a decent amount.
I'm not sure I go to— I definitely don't go to $80 worth of state parks a year, though. I'm curious, you know, if they get— I think the point of the article was it depends on how many people opt out. Right. Right. If everyone does it, the price is going to be lower.
But if, if everyone opts out, then it's going to be that $80 and maybe not such a good deal. Yeah. It said lawmakers were hoping to get the price down to $20. Per person. So that definitely seems reasonable.
There were, like you said, there were 168 other laws in addition to that one. One that I called out as being interesting is HB 21-1060. Coloradans can compost their bodies as an after-death option. So is it you get one of those, the plastic bins and just roll yourself around for a while until you become dust? Is that— I think you might need to ask someone else to do that for you.
Get an automatic rolling bin. That would be— so there are a lot of other laws if you want to look through them all. But I thought that that one was the most interesting. One of the other ones that technically went into effect was the new Colorado Privacy Act, although it is technically not in enforcement until 2023, I believe. So that's the same thing as the CARB registration one where the law is now in effect, but the— not the enforcement or the The actual implementation doesn't happen until 2023.
All right. Next, we have a, we have a story from 5280 about an innovative solution to Denver's housing woes that's taking place on West Colfax. I thought that this one was a really cool article, Robb. A little off the wall, but, but interesting. So on West Colfax, they are, they're building a new project.
It's a I don't know. It's a condo complex. It's a condo complex. Yes. But there's no condos in it.
Instead, there are essentially like parking spaces and there are parking spaces for tiny homes made out of shipping containers. So this is vertically— they're vertically oriented. So you're not like— it's not like a mobile park home where they're all laid out. They're all above and below one another. Yeah.
And the idea here is to give the possibility of ownership, also some concept of mobility, and also some concept of affordability. So have you seen the movie or read the book Ready Player One? I have. So Ready Player One, the guy, the main character comes from the stacks, right? Stacks of mobile homes.
And all I could think the whole time I read this article was, holy smokes, whoever put this together had read that book and like, yeah, make that happen. Yeah. So it's pretty cool. It's kind of like a co-op. You buy a space.
And then you also buy the shipping container. And then you, you pay for, you know, some sort of monthly costs for your utilities and things like that. But you also have the ability where you could then, if you decide not to be there anymore, you could sell your space and take the shipping container with you. They're, they're planning to build these complexes in multiple places. So you could potentially move to a different place with your, your current house.
Or if you bought someplace else, you could take that shipping container and potentially put it in your backyard or something like that. Yeah. And when they say other places, they're talking other countries. They mentioned Tokyo specifically as a place where this is happening. So they had more than 2,000 people who expressed interest in being a part of this.
By the way, we didn't mention the place is called Stackhouse Denver.
They have applications still open, and there's going to be a random a randomizer. I imagine just like the bouncing balls, bingo balls being pulled out, that they're going to pick the 40 lucky winners who are going to get to buy this thing coming up here later this year. Sounds pretty cool. I would like to see it once it's complete. Yeah, I'll tell you, I struggle with the pricing on this.
The, the things are not very big, but they're 350 square feet. So you're not, you're not getting a lot of space. I don't think I've ever seen a condo for sale that's that small. But the prices here between the buying of the container and buying your spot in the co-op are between $310,000 and $480,000. Yeah.
So to get the, the nice 350-square-foot place with a little bit of a view, you're paying half a million dollars. I just doesn't feel like that's really addressing the affordable housing issue. Yeah, maybe not. In addition, you do get some outside space. You know, there is a balcony that, that's around your, your unit.
So I guess slightly larger than that in terms of usable space. But yeah, I think you're right. It's a very small place. I think it's— yeah, I don't know. But interesting concept.
Well, I think the other thing they say is, the more of these that they do, they're hoping to bring the price down, right? So the shipping container units themselves, I think, are probably more expensive than they will be in the future because they're not at scale yet. Yeah, the shipping containers were the smaller part. It looked like that's about a third of what you're paying and about two-thirds are going to the, the co-op fee. Anyway, I, I think it's a great idea.
I think that, you know, without someone pushing this forward, it would never happen. Right. I do worry that the pricing needs to get figured out for sure. All right. Moving on.
Next story, Palantir. We've talked about several times on the show. You know, they moved here about a year ago. And this story is talking about, you know, catching up with them after being here for a year. Yeah, there is not a lot in this story that made me say, wow, we got to make sure we talk about this.
The main thrust of it is that they've been very quiet since they moved to Colorado. They have not really been engaged with the tech community. You know, the Colorado Technology Association has tried to reach out and they've, you know, they've been quiet and not really trying to bring a lot of attention in. And I think that's part of their point. The article does mention that they have moved headquarters once from somewhere on Blake to the Tabor Center.
Correct. But they mentioned that Tabor Center is probably not their long-term spot either. They're going to find another place where they can grow, and I assume a bigger space for the long run. Yeah, they talk a little bit about some of the controversy around Palantir as well. You know, they have some controversial government contracts using their big data analytics to do what some people think are not good things.
But, you know, talking about that and some of the Palantir folks refuting that and, you know, other things like that in the article. But it's interesting to talk about and they're definitely going to be growing. So. All right. Cool stuff.
Next story. This is, this is a new source for us. We have a story from Infosecurity Magazine. And this headline here is Colorado County Clerk charged with cybercrime. So this was not what I expected when I read the headline.
I was thinking that it was going to be about the, the, the election where the clerk had let, you know, someone else see the, the upgrade process, which compromised the voting machines, right? But that's not what this was. I think it is. I mean, it's related, but not exactly. So it's the same county, same person, sort of.
This is the assistant clerk that was charged. Not the one that is, I think, still on the run with the MyPillow guy. But so, you know, what happened was, after those things sort of went down, the deputy clerk apparently started to do some things that were suspicious, was suspended, and access was revoked to IT systems there. But then a couple days later, she showed up in the office trying to print some documents from, from the clerk's, the head clerk's computer. And this was found out.
And then after that, she was then charged with a cybercrime. And it looks like the article talks about the fact that she got into a secured area at— was it the DMV? Yeah, at the DMV. She got to a secured area and she used the password of the clerk, Tina Peters, right? Correct.
To log in and had her YubiKey, which I don't know if that means that it was handed to her or it was sitting in a machine somewhere. Hard to say for sure. Once she had those, she tried to then print some documents that, who knows what was in the documents, but presumably something that would be damning for somebody. Who knows? Yes.
Not to speculate. It is an interesting story. Very weird stuff that is going on there. I'm sure all related to the shadow government conspiracy that we have going on. So good stuff.
All right, let's stop talking about that because that's disgusting. And let's talk about security news. We have an article this week from Ping Identity. And this is titled The Unbundling of Authentication versus Authorization: What You Need to Know. And I thought this was a really nice introduction to What are the 2 A's there?
Yeah, so, uh, great article. It's much longer than I was expecting it to be. Um, very in-depth talking about what authorization is, what authentication is, and why they're different and, uh, how they can be separate from each other. Yeah, I think if you're in security and all you— and you, you're not really clear on the concepts, this is a really accessible, um, relatively fast read that would describe to you, you know, authentication. It's, it's how you know who someone is.
Authorizations is how you know what they should have access to. And it goes into more detail there. Yeah, I think it's great for someone who is, uh, maybe more junior or, you know, introduction to some concepts. So good article there. All right, uh, next we have a blog post from LogRhythm talking about, uh, the executive order on zero trust and what it means for federal agencies and potentially other people too.
So the executive order does get into a little bit of detail around the requirement around zero trust. I'm— I haven't had a chance to review this, this article in detail, but it does give some nice summary of, of what zero trust means and how do you implement that with, you know, number 1, never trust, always verify. Treat every user, device, application, workload, or data flow as untrustworthy. Number 2, assume breach. Assume the adversary is already present in the environment.
And number 3, Verify explicitly. Access to all resources should be conducted in a secure and consistent manner. Yeah, I think whether you are a proponent of the zero trust buzzword or not, I think it is a good concept that we should be moving towards. And to see the federal government moving towards making their agencies use that is a good thing. And can only hope that as they do, it'll roll down into other areas as well.
Agreed. All right, our next blog is from Thinkst Canary, and this is— it's actually from Thinkst Applied Research. This is a follow-up to our interview with Jacob Torrey from— was that 2 weeks ago? Yeah. This is Jacob's first blog, and he's talking about how to make— use a token, a canary token, to discover bad guys.
Yeah, and it's sort of like an idea of his. He was looking at something and how he thought about the steps that were needed to come up with the ability to, to put a canary token into a MySQL database dump. So a pretty interesting read, very in-depth. This is a technical blog for sure. And so if you want to see his thought process and, and what it is that, that was needed to create that token and the fact that you can now get simple tokens for for tracking MySQL database dumps, take a look.
By the way, it is free. You don't have to pay any money to get these tokens, and there are a lot of other places you can put them. I mean, I just— just having these tripwires throughout your environment gives you a lot of information about who's poking around. So, for sure, stuff. All right, next we have a blog from Virtual Armor talking about the risks of public Wi-Fi and how to protect yourself against them.
Short summary, man in the middle. Man in the middle is the risk. And how to protect yourself, don't connect to public Wi-Fi. That's basically what they said, right? Yeah.
If you have to, use a VPN. Don't go to your financial website. Yep. Seems fair. How do you protect yourself?
Buying unlimited data for your phone and tethering your computer to your phone. That's basically what they said here. Also a solution. That was funny. Yep.
Um, but, uh, another article for folks that are, you know, maybe a little more junior or, uh, you know, mom and dad kind of article for letting them know about public Wi-Fi. Yeah. Uh, so, you know, when we do these articles frequently, one of the main motivations that I have for putting them in the show is that I want to force myself to read it. And this, that's exactly what this is. So this is a blog by Coalfire called Rumors of an Upcoming Major Change to ISO 27002.
Yeah, I think many, most all of us are aware of ISO 27000. It is the information security standard from ISO. And there is a pending update for 27002, which is the control guidance side of ISO 27000. And, you know, apparently there has been a draft of this out that has been circulating. I think you can actually, you may have to buy a copy of the draft, or you have to if, if you're on the board that reviews it or whatever, you know, if you're in, in that, then you could see it as well.
Um, but there's a draft that's out there, and the idea is that it will probably be approved sometime in the near future, and it's going to make some, uh, fairly large changes to ISO 27000. Yeah, they're collapsing the number of domains down from— what was it, 9 today, I think— down to 4. And they're, they're restructuring some of the controls as well and reducing the number But they're only getting rid of one actual control, which is the removal of assets, which kind of makes me wonder how they're dealing with that now. But they didn't address that in the article, so let that go. Just never remove assets, Robb.
That's the answer. I think the key for those of us who have ISO 27001 certified environments, 27002 is the implementation guidance for 27001. You're going to have new guidance for how to do your certification. The expectation being that, you know, you should be preparing your program for whatever these changes look like. For sure.
Also, since ISO 27002 is going to be changing, that means whenever this is approved, shortly thereafter ISO 27001 will also have to get changed to make that, to reflect that change as well. I think this also, you know, it goes along with some of the other standards that have been updated or released recently, you know, with NIST Cybersecurity Framework having, you know, smaller number of high-level categories, you know, identify, protect, detect. I think ISO 27000 just kind of going that same way, collapsing into more human-friendly categories for where the control guidance is. Good stuff. Well, it was one other little, little tidbit I got out of this, which is ISO controls are updated every 5 years.
So there was, I remember 27001:2008, and then there was 2013, and there would've been 2018, but I guess in 2018 they looked at it and said, no, we think we're still good. So that was an interesting tidbit for me. And every ISO control gets that update every 5 years. Yeah. All right.
Well, that is it for news. Jumping over to the events coming up in the next couple of weeks. Start things are starting to pick up. We have a as just as a reminder, we have a calendar of events on the website, colorado-security.com. Go over to our events and you can see what awesome place you can go see people in person or virtually.
First, ACIS is doing a coffee chat with Den on nine fourteen. Oh, at no, it's it's with the airport people. Oh, I see. Because remember, ACIS is the physical security group, so they're doing a chat with the physical security from the airport. Got it.
And that is on the fourteenth. Also starting on the 14th is the big Colorado Springs Cyber Symposium. This is the ISSA Colorado Springs big annual event. This is their 11th annual event, and that'll be the 14th through the 16th. On the 15th, ISSA Denver is doing a Women in Security meeting.
On the 16th, ISACA Denver has their September meeting, which is around— which is Imagine a World Without Passwords. That's one. There's 2 talks. One is that, and the other one is IT fraud investigations. Maybe you wouldn't have to do IT fraud investigations if you had a world without passwords.
Maybe so. Uh, on the 20th, CSA Colorado is doing their September meeting, which is Protecting Ephemeral Workloads. That should be interesting. On the 21st, OWASP Denver and Boulder are together doing a meeting called Cover Your Assets. Uh, ISC² Pikes Peak is doing their September hybrid meeting on the 22nd.
And on the 23rd, SecureSet is doing a virtual event, Intro to Machine Learning for Cybersecurity. All right, those are our events. Let's jump over to jobs. Robb, are there any Red Canary jobs out there? Yeah, I got a few jobs to talk about.
We have a Director of Corporate Security, which would be helping us secure the 350-ish person enterprise that is Red Canary. We also have a couple of Product Security Engineer positions available if you're— if you have a development background and you want to help us secure our products, we'd love that. And the third one, which is not on the website but you can reach out to me about, is an IT support manager position. This will be a manager running our IT support administrative group. The reason this isn't on the website is we got overwhelmed with applicants right off the bat.
But if you, if you know me, I can, uh, I can get you in there. Well, we'd be happy to talk to you. All right, the state of Colorado is looking for a director of cybersecurity investigations. Crocs is hiring a senior manager of IT security. Red Robin is looking for a manager of IT security operations.
CoBank is hiring a security manager for threat management. Tri-State Generation is looking for a cybersecurity engineer. ComputerShare is hiring a security monitoring analyst. And Guild Education is looking for an information security analyst. And that is it for the news this week.
We do have a feature interview though. We had Michelle Wilson was interviewed by Jason Jaques. Michelle Wilson is the CISO at Celebrity Financial. You might know Celebrity Home Loans, but the holding group is Celebrity Financial. Very good.
Looking forward to hearing that. All right. Well, that is it for this week. We'll talk to you guys again next week. Thanks, Robb.
Hi, this is Rich Schliep, the CISO for the Colorado Department of State. This is Colorado Equal Security for Colorado security professionals by Colorado security professionals.
Hello, Colorado Equals Security. I'm Jason Jaques. I was fortunate enough to interview Michelle Wilson, the CISO of Celebrity Financial. Here's the interview. Enjoy.
Hi, Michelle. Thanks for joining me on the podcast today. Thank you, Jason. I'm really thrilled to be here. Hey, so we've got a lot to talk about.
You are a new addition to the CISO community here in Colorado, which is, which is awesome. We'll explore that in a little bit. But before we dive into that, let's talk a little bit about your background. Where are you from? I grew up all over the US.
My dad was in the Army, so moved around a lot. Spent most of my time in kind of Texas, New Mexico, Arizona, Georgia, Florida, Alabama, just stay south. And that's where I lived. What was your favorite place to live growing up? Honestly, it wasn't in the US at all.
It was in Germany. I got to spend 3 years in Berlin, Germany while the wall was still up. It was a really unique experience. Yeah, yeah. Did you learn German?
I did. I was fluent by the time I left. I went to a German-American school, um, so I, I got to, um, really get integrated, uh, in the culture that they've got there. Yeah. Do you still know German or have you lost it?
Not so much. Yeah, I can— I could probably say hello, like, hello. Yeah, yeah. I took 5 years of French growing up in, uh, in school and I don't know anything. So yeah, that tends to happen if you don't use it.
It does. You mentioned you grew up, your father was in the Army, but you joined the Air Force. I did. I went to college for a couple of years and then decided I wanted someone else to pay for college. So I joined the Air Force when I was stationed out in New Mexico.
Good thinking on that, on that front. How did your dad feel about you joining the Air Force? Dad was a little less than thrilled. He really didn't want me to join the services, but he was glad it was the Air Force. He really didn't want me to join the Army, so.
Yeah, and when you joined the Air Force, is that how you got into tech or? It is, it is. When I went to college, I wanted to be an architect. I was going to school for architecture. The Air Force doesn't really need a lot of architects, So, um, they put me in computers, which I found I really, really enjoyed.
I, I had a passion for it, and, yeah, um, they, they, they helped me grow into information security. So yeah, any fun or interesting stories about your time in the Air Force? Oh, fun or interesting, um, or the other direction, not interesting and terrible? No, thankfully I never got shot at. That was of my big goals joining the military was not to get shot at.
Yeah. Um, so I did manage to, to get through the whole thing with— without that experience. Um, I, I spent, I think, 5 months in Saudi Arabia, um, which was very interesting. Living in tents, uh, in the desert is not something I would recommend, but, but it was a really, really unique experience. Um, it was a a joint airbase.
So there were British troops and French troops and Army and Marines and Air Force and all of us kind of in this little 1-mile-square city full of tents. Did you ever get out and explore Saudi Arabia? No, um, we were, we were highly encouraged not to leave the base, so I stayed on base. Yeah, I wondered how that worked. Okay.
Yeah, yeah, they said I could have, but I would have to wear the entire burqa, like they fully covered, find someone with the same last name that could pretend to be my brother, um, to escort me, um, or no father or whatever. Yeah, no, no, it was way too much work. Way too much work. So they had, um, they had vendors come on to the base every once in a while and they'd put together a little, um, you know, like a, uh, fair, I guess. Um, so that was neat.
Know, and they had, had people that would come in and sell things. And yeah, so you got a little bit of the experience without the, uh, burqa. Yeah. So you left the Air Force, uh, before Y2K happened? I did.
What was your Y2K experience like? Were you afraid the world was gonna shut down? Where were you at? I was a little bit afraid. I moved to Denver in, um, November of '99, and I hadn't lined a job up yet.
Um, and because the world was going to end, there were no jobs, right? So my Y2K was probably the most relaxed of any IT person that you will meet. Okay. Um, because I was unemployed. Yeah, that's, that's not a, not a bad way to go, right?
I had to be, I had to be on call for Y2K, and that was not fun. So yeah, all my friends were like, oh, I slept in the data center on the floor, and I'm like I went to a bar. I had fun. Yeah. And so after that, I noticed that you, you were on the vendor side for a while.
You, you've worked, you had a stint at IBM and Coalfire and TW Telecom. What are your thoughts about the vendor side of things and why didn't that stick? Honestly, they were all really fun. I don't, I don't think I had a job that I didn't enjoy. Coalfire was a consulting stint.
So that was, that was really fun getting to go visit all those other properties and get a, get a good understanding of their security programs.
The IBM and, and TW Telecom were more technical, hands-on, but very, still very fun, great people. And I mean, security constantly evolves, right? So just a new place to learn new things. Yeah. So you went from the dark side, the vendor side, to the good side with your next job.
Tell me about that one. So I worked— it was a managed service provider, and I was there for 11 years running the security program, building the team and building the program up. The service provider was very focused on credit union space, so it was very nice to be focused on a single industry. Yeah. And really feeling like you were doing something good, right?
Like I would talk to my team all the time about, hey, my, my mother-in-law banks here, so we're protecting my mother-in-law, not just random people. So it really helps motivate Um, what you're doing when you, when you really think about who it is you're serving, which is important. Yeah, that's very cool. From my perspective, I always kind of consider about 5 years to be, um, almost a lifetime in tech because that's, that's what it feels like. So 11 years, I mean, that's, that's like 2 lifetimes that you were there.
It was. What, uh, what are some things that you learned over that 11 years of time that, uh, that might be interesting to people? You know, one thing I would, I would, I would say is I would ask for things maybe in year 2 or 3, and I'd get told no or shot down. And maybe I'd ask again the next year, um, but I never went back to the well and asked again. And people change, and the environment changes, needs change.
So I'd have other people come into the organization and they'd say something in a meeting like, oh, why aren't we doing this? And I'm like, oh, I asked for that. And my boss would be like, oh, that's a great idea. So don't give up. If you know it's the right direction to take something, just give it a little time.
It may be more of a timing issue, especially when you're there that long. You ask enough times, you kind of get discouraged that they're not going to either fund the technology or move in a direction and give it a few years and they're probably open to it. You just need to bring it back up again. Yeah. And you functionally rose up the ranks to essentially the CISO role.
Did they actually call it a CISO role or was it called something else? No, the title was Director of Information Security, but I reported to the CEO and did the board reports and reported to my customers' boards and things along those lines. So yeah. What are your thoughts on organizations that I guess don't give the proper title to that functional role? It can be a little discouraging for the person holding that role, especially when they know that essentially they are a CISO.
I think a lot of the resistance to it is a lot of companies don't understand what a CISO does, so they don't think they need one. Yeah. And the person doing the job must be doing a good job because otherwise they would really need one. So for those folks that have the title, I would, I would say just keep doing a great job. And either you will land that CISO title at some point, or just take comfort in the fact that you know you are, right?
You know that you're providing that service. Right. And I bring that up because I think there's a lot of people still stuck stuck in titles that quite frankly are less than what they are contributing to various businesses and organizations. So yeah, I was curious, curious your perspective. Yeah, the problem is that as soon as you go to a CISO title, the expectation is going to be different.
Even though you are already doing that, someone's going to go, well, we gave them a bump in title, so we're going to change the nature of what they do. Yeah. Or Or I don't know, I, I didn't push really hard for it myself, um, thinking that it was just going to look like I wanted a nice pay increase, right? Which I wouldn't have minded a nice pay increase. Sure, we all do.
But that wasn't what I was after, right? I was after that, that recognition that that was the role I was filling, right? Right. So what advice would you give to, uh, to others then that are, that are kind of stuck in that, uh, in that deflated title, um, space that, that are deserving of, of a, of a CISO role or a bigger title? Or quite frankly, how do we, we as an industry, I guess, elevate everybody up?
What are your thoughts there? I think a lot of the education needs to be outside of our industry, unfortunately. Um, and we can continue to talk about the different kinds of CISOs. I hear a lot of talk now about that there are different styles of CISO— technical CISOs, advisory CISOs, etc.— and continuing to educate CIOs and CEOs of other organizations, presenting at conferences that aren't necessarily just security-focused so that there's some visibility. The other part is don't give up.
Not every organization Um, they're, they're looking for something specific, and just because you don't fit that particular one doesn't mean you're not going to fit ever. Um, so just keep, keep applying, keep networking, keep meeting people, and, and keep doing a good job at what you're doing. Yeah, that's great advice. So you finally got the role, which, which I'm excited for. So you are CISO at a, at a company called Celebrity Financial.
I had never heard of Celebrity Financial until you went there? Is there— I hadn't either. Okay, fair enough. Is there anything you can, you can tell us about that? It's a relatively new organization and really, really exciting.
It's a holding company. And today we hold Celebrity Home Loans, which is under— I would call it explosive amounts of growth. They've gone from 300 employees to 1,400 in the last year. Just growing leaps and bounds. And the holding company is really looking to— when I asked the CEO, he's looking to compete with Berkshire Hathaway.
So there's a lot of ambition, a lot of drive, which is really exciting. And really want to be financial advisors, financial any, any aspect of your life that has to do with finances, we want to be part of that. So investing, insurance, banking, education services, just understanding how money works, how, how it moves, how to best leverage what you have, how to make more, things along those lines. So there's a lot of work ahead of me. I'm really, really excited about some of the new businesses we're looking to stand up.
Um, and, and kind of build from the ground up. So yeah, yeah, that is exciting for sure. Uh, what you mentioned before, that expectations change a little bit when you do have the title. So what's coming into this, what's surprised you, uh, with this new role or responsibility or title? I don't, I don't know that it was surprise, but, um, I've enjoyed getting to know and understand what's already there.
What skills the team has. I'm not coming in, in a transformative kind of way, which is great, which means I'm not laying people off. Like, I'm just, I'm just getting to know everyone and then understanding the culture to, to be able to build a new team that's, that's strong, works well together, and, and can support this really, really ambitious work that we've got coming. What type of culture do you like in, in the security space for, uh, for organizations to have? Um, willing to learn.
Um, it's really surprising how many cultures are out there are like, no, this is how we do it. Yeah, that's it, right? But everything changes, and in security, the threats and the landscape changed so dramatically in the last 10 years. It's, it's so dramatically different than it was before. So being able to learn and evolve with the changes is, is really important to me.
Final question about your current job. So what's, what's an interesting challenge that you're working on right now that you can, you can share with the podcast listeners? Sure. Um, the way that this organization is structured, they— there's a lot of focus on responsible autonomy. Um, so each of the divisions that get brought in are relatively independent.
So the role of security is to kind of build some of the guardrails so that they can go do business how they see fit for the region or area of the US that they're in. But it does, it does create some really interesting challenges for what's a guardrail versus what's a hindrance to business. So being able to balance that and work with the business to understand how to enable them and how, how to help them understand that we are enabling them has been a lot of fun. I would imagine you get a lot of pushback. It varies widely.
Some are extremely grateful and really on board, glad that they don't have to worry about it, and some are not as much. Yeah, but those are definitely challenges that I'm sure you'll get through. So let's shift gears a little bit. What's your favorite aspect of being in cybersecurity? It'll sound a little clichéd, but I love that it changes.
I love learning new things. I love that there really is no way to be bored. If you're bored, then something else is kind of wrong.
There's no end to do anything, right? I used to get really frustrated because I wanted to win and that's not necessarily the best way to look at it. But I'll win today. Today's good. Yeah, there's no winning a game that lasts forever.
Right? There's no end to the game. Yeah, for sure. What is your least favorite aspect about being in social media? There's no end.
No, I'm kidding.
So least favorite, um, you know, it's a little frustrating sometimes to try and translate some of the problems that we have because they can be very, very technical. It, it's challenging to translate those into business language. I've been very, very fortunate where I'm at today. The, the business leaders are willing to engage in a dialogue if they don't understand. I have worked places before where if, if it was too, too technical, they just wouldn't ask questions and would just get frustrated, right?
So it's, it's just a challenge, though. I mean, I don't— I like, I also like to sleep, which is a challenge in this field. So getting a good night's sleep pretty, pretty great. Yeah, yeah, it can be, that's for sure. I need to learn how to do that though.
So one of the things that I'd like to, uh, to talk to you about is mentoring and diversity. Can we explore those 2 topics a little bit? We can explore. Awesome. What are your thoughts on diversity in, uh, in this industry?
I think we're a lot better than we were 10 years ago, I would easily be the only female at the table very often. And now that's, that's not the case. So I'm glad to see— and not just female, I mean diversity across every aspect that you can think of, of diversity. So I'm glad to see that there's a change there. I think there's a ways to go.
I think one of the challenges there is, is getting in front of students so that they're ready, so that when they are applying for the jobs, you get a diverse set of resumes. I've always gotten frustrated that, you know, I really want to hire somebody that's not just like everybody else on my team already, but I only got resumes that look just like everybody else on my team already. So It's a little bit of a challenge. It's interesting, I, I never— for myself, I, I never put a lot of thought into diversity, uh, until I had a daughter. And, um, that kind of, that kind of changed my own mindset a little bit and, um, and got me realizing, you know, as I attend these conferences and I look around, it's all just a bunch of typically white old dudes that look like me.
And, and one of the things that I think is, is a challenge is you almost need to have role models for that diversity, that incoming influx of, of people to come into it. So, so my daughter specifically, like, I don't know that she'll ever follow in my footsteps in tech. She probably won't because she's super like headstrong and she's got all kinds of ideas of her own, but Like if, if people, if, you know, women or, um, or whatever, they're coming into this industry and they don't have role models to, uh, to look up to and aspire to, you know, how do they, how do they get excited, I guess? Yeah, I, I think that is important. I, I didn't have a role model though, so I don't— I, I didn't get into this field because I saw some strong woman out there and went, oh, I can do that.
I got into it because I started doing the work and I'm like, this is fun and exciting and I can do this. Okay. Um, so I don't— I'm sure there's some element of that. I just wonder if we focus on it a little too much. Maybe we do.
Maybe, maybe I'm a little, maybe a little off from the rest of the society on that one, but, uh, I liked the work. So yeah, yeah, no, you have, I mean, definitely a better perspective than me on this. So how do we get that diversity to, uh, to engage and take interest in the work? I think a lot of it is again going back to kind of the students even in high school or before and showing them the exciting parts of what it is that we do and getting their interests up and then showing them that they can do it. There's a lot of really bright people out there that can do this work.
Um, how getting them to, to understand that it is actually interesting and exciting and, um, a challenge worth pursuing. Yeah, and I don't even know what the, uh, the kids are doing these days, the kind of that younger generation, where they're going. It's, you know, you're one of the YouTube stars. Yeah, I mean, we're, we're of the same general age where, you know, late '90s everybody wanted to be in tech because the dot-com era was occurring, and it's just like, that's how I got into this. It just just pulled me in, and, and the next thing I, I knew, I was in the tech industry.
But like, I, I'm not so sure that younger generation looks, looks at the tech industry the same way. So I don't know, I wonder if we're not doing a good enough job of pulling them in. Yeah, we're not creating enough YouTube, um, influencers or something. Something we need to work on. Influencers, some TikTok Yeah, well, I am trying that, but, uh, oh good, we'll see, we'll see.
Um, so what's, you know, for, for somebody like me specifically, what is something, um, I suppose actionable that you think I could do to actually help with diversity? Because I don't, I don't really interface with a lot of, a lot of that younger generation that's, that's taking these classes. But, you know, what's, what's again something I can do? I don't either. Yeah, I know ISC2 has some really good programs that work with high school students, and there are some— I wish I knew the links for them— some local folks that'll go into high schools and try and explain more about cyber and things along those lines.
I don't know how effective they are. I think honestly one of the biggest things is for For people that are managers all the way through, if you're a hiring manager at all, consider hiring someone that maybe doesn't have all the skills you need. And I, I understand the challenges that come with that, but you get one person on your team that's a strong mentor and then just start bringing in interns and start bringing in people that are in just graduated SecureSet or people that just have an interest. A few of my best employees never worked in cyber before. They were IT sysadmins and they were just curious enough, and, and the level of curiosity that they had made them very successful on the team.
You can teach a lot of, of what cyber needs to be. Focus more on, um, do they have the right attitude and, and the right level of curiosity? And do you have someone on the team that can kind of be their mentor and train them? That's great advice. Yeah, I've always thought aptitude is far more important than experience.
Many, many times. Many times. Um, I've always found the best teams, um, were someone willing to teach and then a lot of people willing to learn. And as they learn, then they become people willing to teach 9 times out of 10. So yeah, that's great stuff.
So, uh, I noticed that you are, um, you're involved with ISSA. Are you involved with, um— first of all, tell me a little bit about that. What's your involvement? How can we, how can we help collectively as a community? Oh my goodness, I would love help.
Um, so I'm on the board for ISSA, the Denver chapter. I am the program director, which means when there is an event and we have a presenter, that means I went and either found them or they approached me about presenting on some topic of interest. I try and keep those pretty mixed up. So I like social topics mixed in with technical topics. I think a lot of people have a lot of interest in social aspects of the world and IT.
So reach out. We have a, we have a form on the chapter's web page that you can fill out if you're interested in presenting. If you're interested in just plain old helping, find me on LinkedIn. I'm like, I could use help. So that would be fantastic.
Very cool. Are there any other organizations you're involved with? ISC² a little bit. Okay. And then EC Council a little bit, but primarily if, if it's free time, it's going to ISSA.
Awesome. And you are on the Colorado Equal Security Slack channel. Definitely, yes. Um, you mentioned LinkedIn. How do you, uh, is there any other ways for people to find or follow you on social media?
Those are the best 2. I, I kind of avoid most of the rest, um, but Slack works, uh, especially if you want a conversation. And then LinkedIn, um, I'm so, so active on LinkedIn. Aren't we all? So yeah, it's, uh, it's the best platform for sure.
So you, uh, You don't have to find me on TikTok. That's okay. I'm just kidding. This has been great, Michelle. I'm glad you joined me.
This has been a lot of fun. I enjoyed hearing about your background and challenges, and the conversation on diversity is always interesting to me nowadays. So again, thank you for joining. I appreciate it. Absolutely.
My pleasure. Thank you. That concludes my interview with Michelle Wilson. Be sure to follow and support Colorado Equals Security on Patreon. This is Jason Jaques saying be safe out there.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.