Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 241 for the week of, uh, November 7th. Alex, we're remote.
Um, you know, we haven't done this in a while, have we? I know, it's, uh, Back to the Future kind of stuff. Um, you know, you were feeling a little bit under the weather, so we thought, you know, play it safe and do it remote. Yeah, in this world where everyone can work from wherever, we're, we're doing our best to be flexible. That's right, we can podcast from wherever too.
Yeah, we got a good snow this last week, so we're— maybe we're officially getting into the cold part of the year. Yeah, I mean, and we're in November now, so it's, uh, you know, deep, deep into fall. And, uh, oh, you know, big news for, um— well, it would have been passed by the time that people listen to this, but, uh, you know, it's time change, fall back. So don't forget, if, uh, if it's Monday and you're listening to this and you still haven't changed your clock, you better do that. Yeah, you're, you're early for work if you did, so good.
Yeah, so congrats. Um, but that really means it's fall. It does mean it's fall. Speaking of fall, um, we hope you will fall into our Slack channel where we've got 2,500 or so of our closest security friends in Colorado if you want to join the conversation there in Slack. Go over to colorado-security.com and click the Join Slack button.
Give us 4 interesting facts about yourself and you're in. Uh, we hope you don't fall off of our mailing list. Um, go to the website as well, uh, sign up there, put your email in. You'll get the show notes in the mail and maybe occasionally some other things like, uh, you know, notification of when we do our next picnic and that sort of thing. We'd also love it, um, if you went to whichever podcast player that you use and rated us and, and subscribed so that you get that episode to fall into the, the inbox of your, your player every week.
And when you do rate us, make sure you give us a high number. Alex's ego has been falling recently, and this is the only way I can think of to perk him up. I appreciate that, Robb. While you're at it, uh, tell a friend about the show. Let's get some more folks plugged in.
And, and if you would, uh, not mind, we would love to have you supporting the show as a patron. Um, you know, you can help financially defray the cost of the show. Go out to the website and click on the Patreon and That's the way to do it. Awesome. Uh, I think that's our announcements, so let's go ahead and jump into the news.
Uh, first, uh, you know, there are some corporations in Colorado, Robb. They're, uh, they're caring about the environment, and they're doing that by investing in saving Colorado's bees. Yeah, this was an interesting story. A whole bunch of local companies here, IBM and Google at the top of the article, but they also mention Um, Sterling Bay Gates Corp, which we know really well, Colorado Public Radio, UMB Bank, and the University of Denver. They're, they're all working, um, with a, a company called Free Range Beehives, which it does a, uh, a corporate beekeeping, um, service.
And they'll go out to these different companies and, and help them keep beehives in their facilities. This is nuts. It, it is, uh, it is nuts. But without them, we wouldn't have any nuts because as you know, uh, bees are, you know, one of the biggest pollinators that we have out there, and we've been losing bees at an enormously large rate. Uh, so, you know, they're trying to make sure that we keep some of those bees around by, by having more hives.
And I think this is a really cool initiative. Um, I would say, you know, go reach out to your company if, uh, if you don't see yours on the list here and, and have them talk to Free Range Beehives, see if you can get some beehives at, uh, at your company as well. Uh, they, they have a representative here, um, one of the co-founders, John Russell, from free-range beehives. He says that they work with about 15 clients in the area, taking care of about 70 hives around here. And they around— when they reach their peak, the hives host between 50,000 and 60,000 bees each.
Wow, that's a lot of bees. Anyway, that's good stuff. And speaking of beeswax— no, this joke's not going to be good. Let's just keep moving. Pretend I didn't say that.
All right, so does that mean we're moving on the, uh, the, the next article. Uh, yeah, we have— yeah, we're just gonna pretend that joke didn't happen. We'll edit it out in the final cut. Um, and we're back. Uh, Macy's, um, I, I don't know if you've heard this, but the Macy's in Colorado is going to have my favorite childhood toy store, um, coming back to them across the country, but here in Colorado as well.
Uh, is it KB Toys? Was that your— it is not KB Toys. I'm a Toys R Us kid, Alex. Uh, so that was your second favorite toy store. Um, it wasn't anywhere near my house growing up.
Yeah, well, it wasn't very good either. Toys R Us was always better. Um, so, uh, yeah, as you mentioned, the, the Toys R Us brand is coming back and it's going to open, uh, within some, some Macy's locations, including here in Colorado. Um, you know, I've seen this happen not just with, uh, with Toys R Us but with some other brands, you know, sort of, uh, mini stores within stores. I mean, I think it's a pretty cool idea if you want to You know, sort of brand your toy section with a, a well-known brand.
It seems to make sense. Yeah, this is— this actually has already happened. It started in the middle of October, uh, and it's at 9 Macy's stores here in Colorado, um, near me. There's Park Meadows, um, the Cherry Creek Mall, and it looks like, you know, there's quite a few places where you can go see Toys R Us. And maybe Geoffrey the Giraffe will be there.
I don't know the answer to that, but, uh, either way, you'll get a little bit of nostalgia if you show up. I guarantee a full life-size Geoffrey the Giraffe will be there. Wow. Or your money back for subscribing to the podcast. That's right.
Or I will give you this podcast for free.
All right. Yeah, I mean, I'm glad to see Toys R Us is back. But speaking of things that are new but not back, there are 11 tech products that are going to be tested in various Colorado cities to help those cities operate better. Yeah, it's an article from the Denver Business Journal here, and, and I can imagine that they, they came across a couple of these stories and they go, you know, it would be interesting, why don't we just put all these together into one big story to talk about how Colorado cities are embracing new technology? And that's just what they did with 11 different stories of, of cities who are partnering with tech countries from around the world to bring, you know, some kind of new technology into their area.
Well, Robb, it did have, uh, something to do with the Connected Colorado Challenge, which is an annual competition hosted by Colorado Smart Cities Alliance to pair the cities with different technology companies to help them move technology forward in those cities. And there were 87 applications to that challenge. And of those, there were 39 finalists and 11 winners picked. And there— I think there was 4 or 5 different cities that are partnering with these 11 different winners. Some interesting things that they're doing.
And, uh, also one of them, uh, is, uh, in your town, Robin. Centennial. I, I noticed the, uh, the Centennial, they're gonna be partnering with a Finnish company. I'm not sure how to say this. Is it Viasala?
Um, and it's basically, it's a, uh, a company that has developed a system for monitoring and warning for extreme weather. So if there's extreme weather, they're gonna notify. I don't know any more than that. Um, but I guess now I'm going to know if extreme weather's coming my way. Yeah, that's pretty cool.
Uh, there are some others that are, uh, working on communications, sort of like emergency communications, um, city planning, uh, mapping. Another one in my— actually, that also my area, it's not Centennial, but it's Arapahoe Libraries, which is where I live. Um, they're partnering with a company called The Routing Company to provide on-demand vehicle routing to get people to and from the libraries. I don't know exactly how that works, but it sounds pretty cool. Yeah, it's sort of like a, uh, an Uber for books.
Pretty cool. Uh, so yeah, some interesting technologies here. I'm interested to see if, uh, how well they work and if they help those cities make their technology better. All right, speaking of new technologies, uh, we've talked about Thaddeus Batt on the show I feel like quite a few times. He is the— what do they call him— like the, the blockchain czar for the state of Colorado.
I believe he is our blockchain architect. Our blockchain architect, which is, you know, I think czar is, you know, is better from a— for sure, it should be the czar perspective. Um, but Thaddeus, they have a profile on Thaddeus in the Denver Business Journal this week. I'm really talking about misconceptions around blockchains, um, what his job there was. And as he actually came in right before COVID struck, um, and got distracted away from working on that to work on like, uh, notification alerting for exposure to COVID.
But he really, in this article, talks about what is the blockchain good for. Um, it's really good for publicly, you know, visible audit logging, so you, so you get to know what's going on there and, and you can trust it. Um, he talks about ways that the state of Colorado might be able to use blockchain going forward. Uh, should I sing the song? I think you should sing a song.
Yes. Blockchain, huh, what is it good for? Uh, that's your cue, Robb. It's, uh, it's good for, um, helping with supply chain for things like, uh, like livestock. Apparently, uh, Governor Polis was talking about how, um, blockchain could be used for the state— the state's livestock branding system.
Um, and, and Thaddeus Batt was talking about other places it could be used, like water rights. Um, I, I do, you know, here, there's the one side, you know, you know, I'm skeptical about blockchain just like you are. What? Um, however, you know, if you don't incentivize trying to find uses for it, you know, you're probably not going to find it. And they're just trying to make sure that if there are good places, we're gonna, we're gonna identify them and we're gonna use it for that.
Yeah, and I agree. And, um, I'm not opposed to people trying to find, uh, things that blockchain is uniquely good at that other things are not good at. However, I still don't think those things have really been found. Just about anything you can do with blockchain, you can do with some other technologies too. You want to use blockchain sitting on my laptop?
Great. Um, you know, a piece of paper, uh, you know, lots of different things. Um, but anyway, um, you know, things don't ever move forward if you don't make the effort to push them forward. So, uh, not a, not a bad thing to have someone trying to, to find out good uses for blockchain. Awesome.
All right, uh, next, uh, a big announcement for Lakewood, Colorado. Uh, Google Fiber is coming to town and Lakewood is going to be the first place in Colorado where they have it. Wasn't it like— I swear it was like 5 years ago that they said they're coming to Colorado and they still haven't gotten to any towns here yet? Yeah, I think, um, I think it was like 2019 maybe, so maybe not quite 5 years. Um, but to be fair to Google Fiber, I don't think that they've gone anywhere since then.
I think they kind of put Google Fiber on hold there for a little bit. I think that's being fair to them, pointing out that they've done nothing.
Maybe, maybe not the best words, but yes. Um, but it's not just Colorado. They haven't done anything anywhere. Um, that's much better than— yeah. Uh, so, and I think honestly, I think this is a nothing story anyway.
Um, it— Google Fiber was super cool 10 years ago when no one had, uh, gigabit internet to their house. But now that all of the major providers, whether it's through Fiber or other things, are offering Um, you know, gigabit speeds to your house. I'm kind of like, yeah, okay, another provider. I, I'm all for competition, but, uh, this does not have the splash that it once did. That, that's— I agree with you.
However, Google is going to outspeed everybody else. They're going to be offering 5 gig and 8 gig speeds. Um, that, that's, you know, I've never seen that offered to a house. Yes. Um, and that will be wonderful when we're all streaming 8K to our house.
Um, but, but I think until then, um, I think most everybody is fine with a gig or less. Um, again, good thing to push things forward. It'll be nice to have the other providers follow along and, and up their speeds as well. Competition is great. But, um, I think for me, this is still a little bit of a yawn of an announcement.
All right, next story here reminds us that going to a monthly cadence means some of the stories are really old when we talk about them. On, uh, what would it have been, October 6th? There was a, there was a cyber attack that, that hit, um, the Colorado State's website and, and took us down. Um, Alex, you and I actually talked about it the day it happened, I think. Um, and it's been a month since then.
So what do we know? What do we learn in that next month? Yeah, so, uh, the, the Colorado State website, which actually is not run by the state, it's run by a third party, um, and doesn't actually have any of the state services on that site, it's just sort of a a front page that, that they have, uh, was taken down, uh, denial of service sort of attack. Um, it was not just Colorado. There were several states, I think, that were hit at the same time by a, um, a Russian hacktivist group called Killnet.
I think that, you know, some backlash from the Russia-Ukraine situation, uh, they were looking for, uh, ways to strike back at the U.S. And, um, yes, they, they made a little noise by taking down some state websites, but I think ultimately it didn't really cause any harm to anything other than those things being offline. A couple days later, maybe a week later, I think the DIA website also was taken offline from the same group, as well as a few other airline— or excuse me, airport websites. But again, I don't know that it really affected much other than the front page of those particular sites being taken down. Yeah, not— it seems like not a lot there, kind of a nothing burger in terms of impact here. The services were still up even when the main website was down.
You just had to go directly to those services. Um, hopefully, you know, it teaches us how to be more resilient in that area, and, you know, if next time it comes along, you know, we won't be impacted. Uh, it, it is a benefit for us that all of the state services are run independently on their own sites, on their own infrastructure, and that, uh, that makes it a little bit harder to take them all down. Uh, I'm sure that's what they were thinking when they did it that way. I'm sure that's it.
All right, let's move into our next story. We have a press release from Ping Identity, or more like a blog post, I guess, summarizing the fact that Ping has been named a leader in the KuppingerCole CIAM, or Customer Identity Compass, for 3 consecutive years. Yeah, that is awesome for Ping. You know, customer identity, as you know, Robb, is one of their bread and butter items. So good to see that they are being recognized for their leadership in this area.
Yeah, it's interesting, you know, looking at the If you, if you click on the link, you can see the, the compass and see where all the companies are, are ranked. You know, Ping's right near the top, FortiRock's right there, uh, just above them. Um, so the first few companies are the ones you'd expect, you know, Okta's on there, Microsoft's on there, IBM. Um, then you get onto this, this like left part of the list, and it's, I don't know, like a dozen companies I've never heard of. Uh, and I've never heard of it even being pretty close to identity, so it's, it's obviously a, a growing part of the industry and lots of new companies and hopefully adding lots of new capabilities.
So congrats to Ping, and hopefully they keep up the good work. Next, we have a blog post by Red Canary. This is talking about a taxonomy of computer worms, and this is part of their threat detection blog and really gives some, some in-depth history and detail about computer worms, what they are, The types of worms categories, as well as, of course, because Red Canary is all about detection, about how it is that you can detect some of these types of worms. Top 5 things you can do to stay ahead of worms. I love that.
Yeah. All right. Oh, sorry. Go ahead, Alex. I was just gonna say, you know, pour salt on them.
Yeah, I think that's slugs. I don't know if that works for worms. Maybe, you know, from experience it does. I don't know. Who knows?
Moving on to our last story, we have a blog post from Coalfire. And this— I, we picked this one because, you know, honestly, I kind of forgot that there is a new revision of ISO 27001 coming. So this is an FAQ that kind of walks us through what the 2022 version of that certification is going to look like. Yeah, it's kind of funny, the— because obviously there's, you know, 27001 and 27002, which, you know, kind of go hand in hand. You know, one is the standard standard and one is the, the control language.
Um, and the 20002 was— the updated version was released in like February or something like that, and then it took them something like, you know, 6 or 7 or 8 months to release 27001, but it's here now. And I think, uh, the— there are a lot of changes but also not many changes. I think on the controls themselves, there weren't a whole lot of, uh, changes in them. There are definitely a few, but more it was about the organization and categorization of those controls to make it look a little bit more like the, the NIST Cybersecurity Framework, which I think more of the frameworks are sort of looking at the, the way that you use the controls as opposed to, you know, sort of the families of control that you used to look at. So if you are a company who either uses ISO 27001 in your own environment or maybe just about everybody else, you use vendors who use ISO certifications.
It'd be useful for you to just take a read through this blog, understand the differences, what's it going to look different on certifications in the future, what expectations are going to change, uh, make sure you're, you're up to speed with how the industry is evolving. Yeah, it's good stuff. And, uh, also, yeah, if you have to get certified, how soon it is that you have to be certified on the new version versus the old version. Yeah, good stuff. All right.
Let's jump over into events. Uh, we do have a calendar of events, and, and I spent way more time than I would have guessed over the weekend looking at all the new events that are posted out there. There's quite a few, um, events coming up here in November, December, but then also going into the new year. We've seen a bunch of stuff posted now, so go take a peek at that. But you know what we want to talk about here is the events coming up in the next month.
So Alex, what do we got coming up? Uh, first on November 9th, ISSA Denver is doing their November chapter meeting. On the 12th, we have the Colorado Springs ISSA doing their mini seminar. That's that Saturday morning event. You can get a couple hours CPEs.
On November 15th, we have 3— count that, 3 meetings. Colorado Springs ISSA is doing their November chapter meeting, uh, ISSA Denver is doing a Bank of America networking event, and CSA Colorado is also doing their November meeting. On the 16th of November, the ISC2 Pikes Peak has an event down there in Colorado Springs. And, uh, the last event that we have for November, uh, ISACA Denver on the 17th is doing 5 Reasons You're Thinking About Breaking Up with Your Service Provider. This is a virtual meeting.
Uh, that'll be interesting to hear. Uh, I'll go a little bit further into the future and just mention on the 13th of December will be the big holiday— what do they call it— holiday happy hour or party Um, the, the co-hosted by ISSA and ISACA of Denver. They usually get together and have a really fun time, some good learning, but mostly great networking as well. So that'll be on the 13th, and registration is not up yet, but you can mark it on your calendar. Good times, looking forward to that one.
All right, let's jump over to jobs. Alex, what do we got for jobs first? Yeah, uh, first one, uh, I am hiring. Uh, Uplight is looking for a product security engineer. This job was just posted, uh, so if you wanna, uh, if you're interested in that, get on it right away.
Uh, we are looking for for somebody to help us secure the, the products that we make, uh, AppSec sort of things, um, you know, helping us in that area and really trying to, uh, to help move that area forward as part of, uh, part of my crew. Ball Aerospace is looking to hire a deputy CISO. Uh, Sovereign is looking for a privacy system engineer. CommonSpirit Health is hiring an IT cybersecurity engineer. That might be a good place to be right now since they're recovering from a security breach.
I bet there's going to be a couple dollars flowing in that security program. RTD is looking for an analyst for information system risk. First Bank is hiring an information security analyst, application security. Visa is looking for a cybersecurity attorney director. That sounds like an interesting job.
I kind of wonder what that person is doing. I don't know, but it's pretty cool. I know. I assume it reports to the CISO with that title, or maybe it's under general counsel and they just like, they focus on the security part of things. Anyway, I'm interested in knowing what that is.
Yep. Uh, and the next one is, I think, our longest title of the, of the month. Uh, Charles Schwab is hiring a Senior Manager Technology Risk Management Senior. That is a very long title. Uh, twice senior, twice, uh, double senior.
Red Robin is looking for a, uh, VP and Chief Information Security Officer. Uh, that job's been open for a little bit. So I think that maybe they're struggling to find somebody for that one. I think you're right. Last one here is University of Colorado is hiring a security analyst.
If you want to work at higher education, that could be the spot for you. That is— I think that's it for our news. But we do have an interview, right? Tell us about the interview. We do.
I was lucky enough to interview Derek Booth, who is a special agent with the U.S. Secret Service. Uh, we talked about what it is that he does and some of the things in Colorado that he helps organize and how the Secret Service interacts with cybercrime and how you might want to talk to them. It was pretty interesting. I am looking forward to learning more about it. The Secret Service, I know that they do a lot of cybercrime, but I don't really know where they start, where the FBI ends.
So I'm looking forward to it. You know why? No, I— why is that a secret? That makes a lot of sense. Yeah, a lot of sense.
Indeed. Walked right into that one, didn't I? Yep. All right. Well, that's— I think that's it for us this, this month.
We'll look forward to talking to everyone again in December. Thanks, Robb. Hi, this is Chris McLaughlin, CISO with Johns Manville. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security.
This is our feature interview for the podcast this week. I have a special guest, Special Agent Derek Booth. Welcome, Derek. Thank you very much. I appreciate it.
How's it going? Good to see you. It's going great. Life is good. Halloween was great.
Broncos won this week, so yeah, can't complain. You can't complain about that. So what— I called you Special Agent, but what is your official full title? So I am the Assistant to the Special Agent in Charge in the Denver Field Office. For the US Secret Service.
I'm also the coordinator for the Mountain West Cyber Fraud Task Force. So those are my official titles. That's a lot of title right there. That's a lot, a lot of acronyms. Before we get into talking about that a little bit more, let's talk about you a little bit, get to know you a little bit.
As we were talking before this, it sounds like you are part of the craze that is sweeping the nation Um, I've heard that you're a decent pickleball player. So I pretend to be, or I try to be. Um, I played in a few tournaments this last year and this year, uh, worked out— my partner and I have worked our way up to, uh, they, they rank you in pickleball just like in tennis. And right now I think we're officially a 4.0 tennis or pickleball players. What's the highest?
What, 5? 5 is my understanding. That's professional. So those those are the pros out there. So you're sort of a semi-pro pickleballer?
I, I'm not even sure if I'd go semi-pro, but maybe just semi-pro wannabe. Aspiring pro pickleballer. That's, that's perfect. That's perfect. But yes, I agree, it is.
It's the fastest sport, or the fastest growing sport in America, or in the world. And I got a whole— I got part of this about 3 years ago with my partner. He's the one that introduced me, he and his wife, and just kind of casually. And then we just started working our way up, and we started playing more. When COVID hit is when it really got crazy.
We had a group of guys that would meet 3 or 4 times a week because we— most of these guys would work from home, so they needed an out, an escape. And so we would meet at 6 o'clock in the morning, play 3, 2 or 3 hours, and then we just started playing some tournaments and having some fun. Yeah. And it's a great sport. It's a great way to meet people.
Uh, it's just, it's just, it's a lot of fun. It's crazy. Yeah. I mean, I, I see courts popping up everywhere. Um, you know, well, obviously there's the stuff, you know, around here with the, you know, guys painting over, painting over tennis courts and getting in trouble and things like that.
But like, I, you know, I see sort of official pickleball courts now popping up everywhere. It's crazy, uh, how big it's getting. Yeah, it is. It's getting crazy. Yeah, I've played a few times.
I'm definitely not a, a 4.0, but, uh, it's fun. There's one not far from my house. My wife and I have decided we're gonna try and play it a little bit more. Nice. Yeah, anyway, good times.
That's awesome. So, so tell me a little bit about yourself. Where are you from? You know, how'd you get here to Colorado? So that's a great question.
I'm originally from St. George, Utah. I grew up there, went to college in St. George. I went to— back then it was Dixie Junior College. And Dixie State is that what it is now? Well, they actually just changed the name to Utah Tech University literally just this last year.
But yeah, I went from Dixie College to Dixie State, now Utah Tech, and then I went up the road to Southern Utah University in Cedar City, Utah. I received a bachelor's degree in accounting, and then I went back and got a master's in accounting because at that time the FBI was recruiting accountants and lawyers. So I met an FBI agent, and he's the one that got me interested in becoming a federal agent, and he strongly suggested I take either accounting or law. And so I studied accounting, and that's what got me my degree and got me rolling. I left Utah back in 1997, went back to Stamford, Connecticut, got an accounting job back there, and then I was hired by the Secret Service in our New York field office.
So that's how, that's how I started with the federal agency or federal government. I worked in our New York field office for literally 7 months. Technically 7 months, which 6 of those 7 months is training. Okay. But on the books, I'm 7 months in New York, and I wear that with a badge of honor.
And then, and what happened was I lived up in Connecticut near— I lived in Norwalk, Connecticut at the time. My wife was teaching school, and we had an opening in our New Haven, Connecticut office, which is a sister office under New York. And I turned around and went to New Haven for my first 3 years of the job. And then George W. Bush was elected president in 2000, and one of his 2 daughters was going to school at Yale University in New Haven, Connecticut. And so I jumped on her detail for a couple years full— as a full-time assignment.
So you just partied at college for 2 years? Totally. That's exactly— we actually took her to Cancun for a couple spring breaks and all kinds of shenanigans going on down there. And I can't really say too much more about that one, but yeah, that's exactly— we we would take her to class. And so our job was to make sure she doesn't get hurt or kidnapped while she went to Yale University.
Did you get an honorary degree from Yale? I did not. I wish. I mean, looking back, that really would have helped me out now. But it was a great life.
It was a great experience. I love Connecticut, loved living there. My wife actually wants to go back there. She talks about it all the time. And but yeah, I did.
So I finished up my protection time with with Barbara Bush. And but I was assigned— so the way we work is we're assigned to the Presidential Protective Division. PPD is the acronym. And those 2 years in New Haven were technically part of that division. And so then my, my assignment continues after she graduated college.
And so I transferred to Washington, D.C., and I protected Mom and Dad, President Bush and Mrs. Bush, for about 3 years. And then in 2007, I moved here to Denver. The reason I came to Denver was I was this— what we call the site agent at the— what is now the Ball Arena, which was then was the Pepsi Center— for the Democratic National Convention in 2008. So that was— that's what got me here. I spent that first year preparing for the DNC for 2008.
In the meantime, we had a lot of candidates and a lot of protection here. I ran the first visit of Barack Obama at the time, John McCain, during the 2008 campaign. And so that's what got me here. And then once I was here, the DNC finished, I just stayed here in Denver. And I needed to do something.
I needed to do something with my life. So in 2011, 2012, my supervisors came to me and asked that we start a cyber fraud task force. And actually, back then it was, it was the Electronic Crimes Task Force. And what that is, is to help, you know, build up our defense and build up our response to electronics, computers, cell phones, you name it, and especially to help state and local police departments. And so I went to computer forensic school in 2012, and that just, that's just, just built.
So for the last 10 years I've just had my head down trying to get as proficient as I can in computers, cell phones, skimmers. And then that has, that has evolved into more network, network intrusion, ransomware, business email compromise, anything that now businesses are being attacked with. And so that's, that's where I am. And then a few years— sorry, going back a couple of years ago, I was promoted as the coordinator And so that's what I do now. Awesome.
So I think stepping back just a little bit, the— what are the, what are the full responsibilities of the Secret Service? Because obviously there's, there's presidential protection. I think people understand that pretty well, but people might not understand what all of the different directives and responsibilities that the Secret Service has. Yeah, totally. So the Secret Service has a dual mission.
So it's to protect the people, whether it's the president, and we have a list of those that we protect, and that's the president, the vice president, former presidents, and their family members. And that changes a little bit whether you're in office or out of office. And then also heads of state and foreign presidents when they're on U.S. soil. So that's— some people argue which mission is more important. That's probably our primary mission, but our secondary, our dual mission, is investigation.
So Secret Service, we started in 1865 after the Civil War investigating counterfeiters because a huge chunk of the currency that was in circulation after the Civil War ended was Confederate money. So Abraham Lincoln, ironically, the unofficial beginning of the Secret Service was April 14th, the same day he's assassinated. And which is really weird, such a weird date. So the Treasury Secretary started the Secret Service in July, on July 5th, 1865, as an investigative arm of the U.S. government to fight counterfeit money. And that has, that has just slowly evolved over the years where, you know, our protection assignment now changed in 1901 when William McKinley was assassinated.
That was the beginning of the Secret Service protecting the president full-time. And then that has evolved. So the protection mission has evolved as well as the investigative mission has evolved. And I tell people, you know, our investigative mission has evolved from counterfeit money to cybercrime because the world has evolved. And that's where the money is, right?
That's where, that's where the bad guys and the, and the bad players are going. They, instead of, instead of printing counterfeit money or robbing a bank, they're gonna, hey, I'm gonna send ransomware or malware to your computer system and capture all the credit card numbers that are on your system, and they can, they can translate that into, into cash. And so that's, that's how we've evolved. The electronic crimes aspect really changed in 1995 in New York City. So the New York Police Department and then the Secret Service, the New York field office, started the first electronic crimes task force, and it worked so well that come come to 9/11 in 2001, the US government realized that, hey, we need— we've got problems with especially foreign players, terrorists, Al-Qaeda, those kind of players.
We need some help on the electronic crime side. So that has evolved from one task force in New York City to, I think we're up to 50 around the world. That includes London and Rome. And there might be other foreign ones out there, But, and then there's not one in every state, but there's, there's 50 of them out there around, around the country. And our job is just to support whoever needs help, whether that's our state and local partners, especially police departments, state patrol, state police, whoever that may be.
And then also our private partners. We have a lot of private businesses out there that we can talk to, we can help train, we can provide guidance, we can provide intelligence. Hey, these are the things that we're seeing, and we kick that out weekly with emails. And then we try to have quarterly meetings and have like some kind of training seminar for them and for us, for all of our partners to just go, hey, this is what's going on. This is the new strand of ransomware.
These are the malware hits that people are going through, as well as the forensic side of it, again, with those state and local partners. Partners. So yeah. Nice. Yeah, I'm curious because I know that there are different pieces of this puzzle that different areas of law enforcement deal with.
Obviously you guys have some, you know, the FBI does some things with electronic crimes. You've got CISA with more like directives and, you know, assistance from that way and and some testing and things like that. How do all the different groups sort of play together and what are kind of the differing responsibilities that people have? They definitely overlap. Our mission, as well as the FBI, as well as Homeland Security Investigations, who used to be the U.S. Customs, a lot of our crime, a lot of our investigations overlap.
So one, we just try to work with each other and just try to help each other out. Hey, who has what? And then, and then, and then also at the same time stay out of each other's way. You know, the last thing we want to do is ruin an investigation for anybody because we stepped on somebody's toes or we tipped, you know, tipped the card on somebody. Hey, we're looking at this guy and now they know that he's being looked at.
He's going to run the other way. And we just messed up either an FBI investigation or HSI or DEA or ATF, any of those other federal agencies. We— so we just try to— we try to just answer the phone. If somebody calls looking for help, we're there as well as like, yeah, CISA, those guys, those guys are some of the experts out there when it comes to computer defense and network intrusion defense. So we rely on them a lot.
I'm actually speaking in a seminar next week with, with, with them and the FBI. And so a lot of our, a lot of our responsibility does overlap. And I tell people, hey, you know, who should you call? I say call who you're comfortable with. Call, you know, the guys you have a relationship with them, call them, and we're gonna help.
A lot of the stuff is gonna flow over, or, you know, say the FBI gets a case and they run with it, that's great. As long as it gets solved, I don't care. I'm not, you know, we're not territorial. Like, hey, if you've got it, you run with it. And vice versa.
At the same time, there's things that we get, we get the call, and sometimes it does overlap and they do want a piece of that, and it does help. It helps on an investigation they've already got running. So we'll help them out. As far as responsibilities, those overlap to everybody. You know, HSI, I mentioned HSI.
They do things that we don't really look at online. They look at a lot of counterfeit products and services and things like that. They also dive a lot more in like the child pornography and the sexual, sex assault stuff with kids. We do, we, you know, we touch a little bit on that, but they They're kind of the primary agency with that. The FBI, I mean, the FBI does a wide variety of things from murder and extortion to white-collar crime to counterterrorism.
But everything that we're talking about, every crime out there touches an electronic. So it's impossible for one agency to be solely responsible for the electronics. So that's what we're just trying to be. We're trying to be a team player and say, hey, where can we help? And this is how we've been going.
Well, I mean, in 10 years, if you ask me this question, might be different. Hey, we're gonna, we're gonna evolve into, you know, maybe we're the primary agency in ransomware or cryptocurrency. Um, those things, those things are evolving. Like, like crypto is a perfect example. That, that's just, that's exploding.
And all of us kind of have a piece of that. There's not one agency that is the guru or the, the subject matter expert in crypto. There's, there's a lot of us that are trying to get our hands and our minds wrapped around this and how can we help the general public and help our partners and help solve those crimes. Speaking of ransomware and crypto theft and things like that, the crypto stuff is crazy, but I saw a number, it's like $1 billion in crypto or something has been stolen this year or something crazy like that. What are the trends that you guys are seeing?
What are people calling you or what are you guys investigating? I think probably our biggest one right now are— it's the old investment scam. It's, you know, dad's sitting at home and he gets a phone call or gets an email or he gets a text message saying, hey, invest, you know, invest, give me $1,000 worth of crypto and I'll return it, you know, I'll return tenfold or fivefold. And so, you know, dad invests in some crypto. And then he tries to collect his crypto, and bad guys disappear.
You know, and either they stop answering calls, and they take the crypto, and they exchange it, they move it from one wallet to another, and now dad's, you know, now he's hosed, and he realizes that, hey, I'm now a victim. So we get, that's probably our number one. Just, you know, local citizen, hey, I invested some money with this person, and they took it and ran with it. And I don't understand crypto enough to go trace it. How do I— what do I do now as a victim?
Now, I'm calling the local police department, and they kind of throw their hands up and be like, we don't know what to do with it. So they end up calling us. And so we're trying to put the pieces together for that. That's number one. The other with crypto for sure would be just bad actors in you name it, fill in the blank with either wire fraud, bank fraud, bank robbery.
I mean, no matter how the bad guy gets the money, they're going to convert that into crypto very quickly because they, one, they think it's anonymous completely, which it's not sometimes. And then they'll convert that and then they can move it. I mean, they can move that all over the world in seconds. And so that's why, that's why there's such a great, it's such a great asset for a bad guy. And why it's such a challenge for us.
So yeah, I've been in some jobs in the past where we did a lot of wire transfers and things like that and had to deal with those things. I know it used to be that sort of the general guidance was if you have somebody that makes a bad wire transfer, you've got about 72 hours before you can claw that back. Is that still the case? Yes, it is. So we call it the kill chain.
So If you call me as the victim and say, hey, I wired this money, I fell for one of these scams, whether it's a business email compromise or I just got duped, a romance scam, you know, we call it elderly scam, the scam on the older, older people, whatever it is, whatever money I sent, if you can, if you could call us within 72 hours through our, through our partners at FinCEN and the banks, we can, we can shut those down. The problem is most people don't call within 72 hours. Either they're scared, they're embarrassed, they don't realize it. Or you know, that 72 hours has passed. It's not a hard— That's not a hard set because I've heard stories and I've seen where if we get the notification even after that 72 hours, sometimes it is possible depending on what bank it went to, what country that bank is sitting.
And then the relationship between that bank and law enforcement. So the 72 hours is kind of our— that's our guideline to get that money back. Absolutely. Yeah. Yeah, I mean, it's crazy how fast that stuff moves.
It's, it's sad how many people fall for that and how common it is. And I feel bad, especially, you know, for like a network security guy for a company. A lot of that lands on him even though he's not the one that transferred the money, right? You know, I don't want to point a finger at anybody, but whoever's responsible for that account, say account manager, wires the money because they fell for it. Now they're embarrassed.
They feel bad. They call that network security guy. He feels bad. They think they're going to lose their job, which I really hope that doesn't happen because it's a mistake, right? They fell for the scam, but that's reality of life.
That's why that 72 hours is so critical. If they can just figure that out, within this 72 hours and get word to us or whoever it is, FBI or again, HSI, whoever it is, we can shut that down and hopefully get that money back. Yeah. Yeah, it's scary. So we've been talking a bit about you.
I know you have a team of folks that are here. What does your whole team do? What are the other functions, responsibilities, services that you guys have as part of the office here? So right here on my team alone, I've got, I've got 8 players if I can't— if I do my math right here. I've got a couple computer forensic guys, and so what they do is, you know, local police brings a computer, cell phones, a skimmer, whatever you can— whatever it is, whatever electronic device, they can dive into that device and they can basically dump— we call it dumping it.
They can suck out all the information and put it in a nice neat format and put that together in a nice report. So hands that to the detective, the district attorney, whoever it is, so they can find evidence and then take that to court and prosecute the bad guy. I mean, that's literally what at the end of the day what we're trying to do. So those guys, they concentrate on the forensic side of it. I've also got a couple network intrusion guys that they go out and they respond to, hey, mom-and-pop shop or this business has been hit with business email compromise.
A ransomware or just a network intrusion where the bad guy uploaded some bad malware through some other means, they'll respond. They can dump the memory, dump an image of that computer system, that server, and then they can go back, bring that to the guys in the lab and dissect it and try to find the trail, try to find the IP addresses, try to find URLs, try to find emails, try to find pieces of evidence to find the bad guy. Uh, on top of that, I got a couple agents that all they, they, they focus on EIDL fraud. So we have a little— I'm in a really unusual spot because EIDL is Economic Injury Disaster Loans. That's the SBA, Small Business Administration, uh, relief funds that went out because of COVID right?
So right now SBA is saying $320 billion was issued in EIDL loans, and these are for— these are business owners that can apply apply for these loans and these, this relief funds because of COVID Well, SBA kicked out $320 billion. They estimate now that $80 billion of that is fraudulent. So about a quarter, yeah, we're talking about a quarter of that is fraudulent. So we've got, got 3 agents doing that full-time helping. And we're actually, that's a whole separate task force that we work with the US attorneys here in Colorado and the FBI, IRS, Treasury, HSI, I'm trying to think, I'm probably missing a couple of those partners in there.
That's what those guys are doing, they're tracing that. So yeah, we've got a great, we've got a wide variety of agents and personnel, and they bring a lot of talent. Everybody's got a little niche of something, and so that's what we try to do. Again, we have this task force where we try to rely on each other. We kind of do that here in the office as well.
Hey, I know this guy or girl has this expertise, I'm gonna I'm gonna abuse them. I'm gonna go to them and ask them the questions when it comes to, you know, whatever, whatever we're dealing with. So yeah, and speaking of that, you know, tell me a little bit more about, about the task force. You know, what it, what it does, who's a part of it, you know, how people can get involved with it, that kind of thing. So we started it, we started more as a law enforcement task force on the forensic side because back in 2012 we were getting hit with computer fraud.
Desktops and laptops were our biggest customers. And so our tasks were started more, hey, how do I help the police and how do we get this going? So our biggest partners back then were Arapahoe County Sheriff's Office, Douglas County Sheriff's Office, Aurora Police Department, Greenwood Village Police Department, the Denver DA's office. Those were kind of our core our core group. We've now expanded from about 5 to 10 partners to— I think we're up to 250 total, total partners.
Within that is about 80 law enforcement partners. So my math, about 170, 170 that are private partners. On the law enforcement side, we've expanded. So we've got— we tried and we tried geographically, like, okay, Colorado is a big state, Wyoming is a big state, and geographically that's just hard for detectives to transfer evidence and to get things, you know, to each other that need to go across, you know, miles and mountains. So we cover, you know, we've got partners in Durango, La Plata County, Durango Police Department, Montezuma County, which is in Cortez, Mesa County and Grand Junction Police Department, also Routt County, which is up by Steamboat area, and then we've got partners in Casper Casper and Cheyenne, Wyoming, and then basically all down the I-25 corridor, starting up in Fort Collins and Greeley.
The Boulder County lab is a fantastic lab, has a lot of resources. Those guys and girls serve Boulder County, Boulder PD, Longmont, the Boulder DA's office, and then down through Denver. Again, I mentioned Greenwich Village, Aurora Police Department, Arapahoe County, Douglas County, Castle Rock, and then going all the way down to— we go as far south as Pueblo County, and, and I don't forget El Paso County, Colorado Springs as well. So, so we've got a lot of these partners that they need help from us with some tools that we have that can help with cell phones and computers that they might not have the resources to pay for. Their departments are either small or they just don't have that— they don't have the money for certain things that can help with, with the forensic side.
So that's kind of— that's how we got— that's how we got started. That was our bread and butter. That has now evolved into, like we was talking earlier, the network intrusion aspect is so big now. And a lot of these private partners out there have a lot of good intelligence that they can share with us and we can share with each other. But then also they just want to be kept in the know, like, hey, what are you guys seeing as a US government?
What are the locals seeing? And then also we can, it's just a shared, you know, it's a team game. We can help them while they help us. They can share intelligence and education with us, and then we can share that with others, and especially the law enforcement side of it. Hey, private partner brings, hey, this is what I'm getting hit with.
You know, in seconds I can launch that out to 250 people. Hey, this is what these guys got hit with. You might want to just keep your eyes out, keep your eyes open. As well as, hey, these are the, these are the new trends that we're seeing, and this is, this is, this is what's— this is what's hitting us. How can we help each other fight that?
So, so that's where we are. So right now we're about, about 250 strong, and it's growing every day. I mean, I get phone calls and emails weekly. I got, I got 3 emails last week from different agencies. One was a government agency.
And we also— we don't forget our federal partners as well. The FBI also has— they have their InfraGard, which is very similar. And they, they go more kind of grand, bigger, kind of bigger picture as far as companies. They deal a lot with the Fortune 500 companies more. So I would say we focus more on kind of the smaller intermediate mom-and-pop shop.
We don't, we don't want anybody left behind kind of thing. And so that's, that's where we kind of spend most of our time. So, so if someone wants to get involved, maybe they're a government agency or maybe some sort of private partner, if they want to get involved with the task force, How do they go about doing that and what are they gonna get as part of that? So they can, they can either email me or they can email the task force email address. It's mwCFTF@usss.dhs.gov.
That stands for Mountain West Cyber Fraud Task Force at ussecretservice.departmentofhomelandsecurity.gov.
I can't believe I just spelled that acronym, but no. So what they do is they can just email me and I'll include them on some email lists. And part of that will be weekly emails from some of our partners like Verizon or Trend Micro or PassiveTotal, those guys. We get weekly emails that I can launch that out and just say, hey, this is— these are some trends, or these are some attacks that have happened all over the world, as well as those quarterly task force meetings we try to hold and And like we're going to— we've got one up in 2 weeks that we're going to get together and have some gurus and experts on cryptocurrency come talk to us. TRM Labs is one of our partners and they're going to come talk to us, a couple of their personnel, and just kind of teach us.
Like we were talking about, crypto is such a challenge. They're going to get— we'll get together for a couple hours, have them instruct us, give us some training, and then also we can socialize. Hey, you know, we'll get together. Meet afterwards somewhere, get a refreshment, and they can get to know some of these network security guys as well as the law enforcement side and build that social as well as business network just to help each other. Those are the biggest things, as well as, hey, if you need help, you've got a lot of companies, they put together now an incident response plan for their cyber side and cybersecurity.
So a lot of them will call and ask, hey, who should I call if I do get an attack? And the best thing about that is we can give them a face and a name and an email and a phone number to, hey, if you get attacked, I got to, you know, here's who to call. I got it. I actually received a response or a text on Sunday night as I'm sitting there watching the NFL game from a gentleman I met 6 months ago at a seminar. And this guy's company in Arkansas was hit, and he had a— one of the smaller companies was hit with a— it was a business email compromise, and he's just like, hey, what do I do and who do I contact?
Well, within seconds I can do, hey, here's a Secret Service agent in Little Rock, Arkansas, and that agent responded immediately, oh, I've got task force partners in that area. I can hit them up. And so it gives a quick response for those moments that you really need it. I mean, a lot, a lot of those responses aren't like, oh my gosh, we got to have this in seconds. But it's under the 72-hour is what we're trying to narrow that down.
So those are the biggest things that those partners can expect. Yeah, that's awesome. So you mentioned the quarterly meetings that you guys have. Are those normally, you know, in the same place? Do you move it around?
We, yeah, we move it around. We had our last one, we had downstairs right here in this building. We're in the tech center. Our next one will be, it's gonna stay in the tech center, just different building. We try to do move it around for the, just for the convenience for our partners.
We're gonna have a meeting. We're actually in the process of doing a virtual meeting in probably February-ish. We're still putting that one together. And then we've already got a location for our May meeting that'll be downtown, the near downtown Denver area, near Mile High. Stadium.
And so yeah, we do, we try to move that around a little bit just to help our partners. The majority of the partners are, you know, right here in the Denver proper area. So we don't want to go too far just because we don't want to, we don't want to get out of— get too crazy with that. But yeah, yeah, that makes sense. Yeah.
We're getting close to time here. So I think I have a couple more questions for you. The first, maybe just something in general uh, advice or other things that you would want to leave the listeners with, something they could do, or I don't know, whatever advice that you have, uh, sort of coming out of this that, uh, that might be useful for them? You know, I, I always fall back, and I get asked that question a lot, and my— I fall back to my— I hear my own, my own father's voice, and pretty much everything is education, education, education, right? And I, I try to tell, um, you know, especially private private business owners that get hit with an attack or things, educate yourself.
Like, get yourself up to speed because a lot of, especially these older, older crowd, they seem to be intimidated by, you know, technology. And I just say, hey, just try to educate yourself. You've got, you've got young kids around, whether they're your kids or your employees, you know, especially these college kids, dude. These, these are the experts when it comes to technology and they're, they're 20 years old. And so I, I always strong.
I suggest, hey, you take advantage of who's in your business. You know, you might have a network security problem and the kid at your cash register might be the smartest kid when it comes to a network security issue. Use it, use them, you know, talk to them, get to know what they know, and then educate ourselves. Like, I'm constantly reading and I never feel comfortable. I'm always on edge, like, I need to know more, I need to know more.
And I think that's a good thing. It can turn into a bad thing, but I think that's a good thing to just educate ourselves on, hey, what are the trends out there? We hear a lot about ransomware. What does that even mean? We hear a lot of business email compromise.
Those are the terms we're hearing a lot. Cryptocurrency. What do those mean in today's world and how does that apply to my business? And how can I get involved in this and how can I get better at it? You know, these detectives and the law enforcement world that we deal with, these guys and girls are overrun with this.
Some of these guys and girls are really good at just, you know, they'll spend 3 or 4 hours a night, you know, on their own time, you know, after they put the kids to bed, they'll go just study and they'll pull up a, they'll make virtual machines on their own computer and test things. I find, one, I'm inspired by it 'cause I'm like, that's awesome, the fact that they're doing, they're taking the time out to do that. And it just tells me, dude, I need to quit, you know, not doing that. I need to spend more time, you know, learning for myself. These things that we're seeing.
Because again, you know, back in the, you know, back in the day, it was counterfeit money and credit cards and bank fraud. That was pretty easy to get your head wrapped around. The crimes that are out there today are pretty complex and pretty sophisticated. And but it's up to us as law enforcement and network security guys and girls to kind of get our heads and figure out, hey, these are the new trends. This is what bad guys doing.
How can we help each other? And then on top of that, educate the person behind you. You know, somebody educates me, I should help somebody behind me. You know, either the junior agent or the junior detective or the junior patrol officer, whoever it is, or the, you know, somebody in my company who— my new hire— I should educate them. Hey, this is what I know, you know, and then help them.
So it's almost like— I think I've said this before— somebody's helping me up the chain, I need to help them up the chain. So that's my mentality, and I think that's probably the most, I don't know, beneficial thing any of us can do. That's awesome. All right, last question. And, and for everybody, like, dude, I, I didn't prep you for this.
Okay. But I imagine with all of the things that you've been through, you probably have some good stories. Is there one story that you can tell us that's okay for on the air that, that people might find interesting or, or unique? You know what, I will tell you this story. I said, I told this story the other day and somebody, they, the people responded so well to it.
I was like, wow, I didn't expect that story to be that interesting. But gas pump skimming is a big issue right now. Yeah. And it's a device you put inside the gas pump and it captures, it captures credit card numbers. We're getting, we're getting hit pretty hard and it goes, it goes in spurts.
We'll get hit really hard and then it'll disappear. And I think these, we have groups, especially coming up out of Miami and Los Angeles, criminalists that are putting gas pump skimmers in the area. We had a case, and it's still ongoing, so I can't say too much. We had a case where an individual was identified through a family member because this family member wasn't treating this person very well. So the victim of this mistreatment was at a local business, and the FBI raided that business.
And I'm not going to tell you why they raided that business, but the FBI was serving a search warrant at that business. And this person, this victim, responded to an FBI agent and said, hey, I know who's doing this. Are you interested? Well, that FBI agent's like, not really. I really don't care about that right now because I'm concentrating on this crime.
Right. Right. But that FBI agent called our office and we called that person who was the victim and talked to, talked to that person. And that person gave us in great detail, great information that, that that turned— evolved into multiple search warrants, multiple arrest warrants, and all kinds of greatness on our side. You know, the great stuff we like to see, you know, bad guys in handcuffs.
And it was simply because that person, that victim, literally was sitting there and she, you know, that person sitting there like, hmm, this is an FBI agent. I wonder if he'd be interested in this crime. And it turned out to be fantastic. And again, that case is still going. And that victim, that, that person gave up great information that led to, to these other, to these other great crimes being solved.
So I, I would give you more detail on that, but I'm afraid because it's still ongoing right now. Oh, wait till it hits the news. Yeah, that's totally cool. So that's probably my biggest investigative, investigative story. So, and I wish I had a great protection assignment or a great protective story.
People ask me all the time, especially my kids, like, Dad, did you ever hang on the bottom of a helicopter? Or did you ever have to, you know, abort a mission or call, hey, call off the airstrike? Or— no, I didn't. I guess life was really good during those years because we never really had any craziness or madness. You know, that's probably the way you want it.
If you don't have a crazy protective story, that's probably a good thing. That's exactly— my wife, my wife totally says that. So yeah, absolutely. Awesome. Well, Derek, thank you very much.
I appreciate your time. This has been great. Uh, this has been Colorado Equals Security, and we will talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.