Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 242 for the week of December 5th, 2022. Alex, this is our last podcast of the year.
Wow, that's crazy, Robb. I didn't even think about that until you just mentioned it right now. Yeah, I like to drop things on you like that. It is crazy though, right? I mean, like another year over and deeper in debt.
Isn't that how the saying goes? Something like that. This, this year seemed to go really fast. I don't know about you, but it doesn't seem like it should be the end of the year already. It sure doesn't.
I'm not ready for Christmas. I'm not ready for New Year's. I am ready for a vacation that I have right after New Year's, right at New Year's. I mean, aren't we always ready for a vacation, Robb? I am always ready for it.
I just got back from a vacation. I'm ready for my next vacation. I'm planning my next 2 vacations after that. Man, you're on top of it. Vacations, it's kind of my thing.
It's kind of my thing. What do you like to do? I like to not be here. I like to be anywhere but here. I like to not work and I like to not be here.
Yeah. Can I be somewhere else, please? Yeah. Someplace I'd never been. For Thanksgiving, we We went to Clearwater Beach, Florida, near Tampa.
Just a place we'd never been. And, you know, nicer weather right on the beach. You know, kind of like a walkable touristy area. It was really fun. What did you guys do?
Sounds awesome. We were here. We had family come into town. So sounds less awesome. It was— it was not the beach, that's for sure.
But we had a good time catching up with family and hanging out and eating too much and all that stuff. So the holidays are for, right? Exactly. Speaking of the holidays, let's talk about our podcast. Smooth segues.
Yeah, so we got, uh, we've got a few things to talk about here and then we can jump into the news. Um, Robb, do you know we have a Slack channel? I did. I've been using it quite a bit lately actually. It's been nice.
We got 2,400 or so of our favorite friends out there. Yeah, something like that. Lots of good chatter going on in there. You should check it out if you're not in there already. Uh, we also have a mailing list.
Uh, both the mailing list and the Slack workspace you can sign up for on our website, colorado-security.com. Submit a form, we'll get you added to either of those or both of them. Yeah, while you're there, uh, go take a look at the rest of the pages. We got a lot of stuff on the website, uh, we— that we update on a regular basis. I'd say the calendar of events is super popular.
We also have a list of local security companies and security associations. You want to get plugged in with people in the area, you know, go, go read about OWASP or CSA or ISSA or ISACA. And, you know, we have a bunch of groups out there you can get to know. Yeah. Also, we would love it if you rated us on your favorite podcast player, or, and subscribe while you're there, get the podcast delivered directly to that.
So you don't even have to think about it. Just have it in your feed and listen to it as soon as it shows up. If there's, if you're thinking to yourself, you know, I'd love to give Alex and Robb a Christmas gift this year. What should I give them? There's 2 things you could give us.
Number one, you could tell a friend about the podcast, let them know that this is, this is a community that's worth getting engaged with and you know, give us the gift of a new friend to know and them the gift of knowing Colorado equals security. Or number 2, you could just give us your money. We have a Patreon campaign if you want to help support the show. All that money goes back into the community. You know, last year we did a picnic with, with some of that money, but most of the money goes to, to hosting fees and kind of what it takes to keep the show running.
Yeah, good stuff. All right. That's all the announcements we have. Let's jump into the news, Robb. There are some famous people that are going to be hanging out in Colorado.
And what is it that they're going to be doing? I think they're going to be turning Colorado into Hollywood somewhat east. Yeah. Apparently we're going to be getting a couple of big budget TV shows and big budget movies that are going to be here in town. Yeah.
Anthony Mackie, who is Falcon in the Marvel Cinematic Universe, for those of you that watch that, is is in the midst of filming a movie here. It's called Elevation, I think. Elevation. Yep. It's going to be the biggest movie to come to Colorado since The Hateful Eight almost 8 years ago.
Oh, wow. Yeah. Yeah. Also, HGTV is filming their reality show Rock the Block in Berthoud, where they get HGTV celebrities to, to fix up some houses and some, you know, I suppose afterwards they'll probably be for sale if you want to live in Berthoud. Couple other things coming in.
There's another movie that's going to be here called Making Tracks, which is about an LGBT bar in Denver, one of the oldest LGBT bars in the country, I think I saw. And there's a TV show from the History Channel. Apparently, it's a spinoff from Pawn Stars. It's called Pawn Stars: Do America, and it's going to be the Denver Gold Rush. There you go.
There you go. There's even more though. There's also High Science, which is a reality show that's made by the same folks who did Pawn Stars and Duck Dynasty, all about the cannabis industry here in Colorado. Yeah, very exciting. We're going to be famous.
We're talking about this because this article is highlighting the fact that the Movie and Film Commission here in Colorado is giving tax incentives for folks to come here and do that filming. So it's giving them a little incentive and then them coming here and spending a bunch of money. It's helping us compete with New Mexico and Utah, which apparently have had a lot of things in their areas. Yeah, I have seen articles in the past that people have said, we don't offer enough incentives, so no one comes here and films. All right.
Well, I get to read the best headline of the week. You do. Dutch asteroid mining company is going to relocate their headquarters to Colorado. I'm looking forward to this. So the name of the company is Carmen Plus.
That's the, like, the plus sign. Yeah, not the word. And what they do is they do near near-Earth asteroid mining to find abundant sustainable energy and resources. Interestingly enough, they're not starting with like heavy metals and those really rare metals. They're starting to mine for water, because apparently that's the most important thing for propulsion in space, which will allow us to go further and further.
Yeah, it also mentions that some of the tailings that they are going to be getting from their mining, they're going to be using to hopefully build solar panels, which also are important in space sustainability, right? Some facts here. This company is moving their headquarters to Colorado. We beat out the UK and Luxembourg. There's only 8 employees now, but they intend to be up to about 150 in the next couple of years.
And this article also dropped the fact that Colorado's aerospace industry is second only to California. Yeah, I think— I mean, this is actually a pretty cool article, other than the fact that we're talking about asteroid mining. Because many times when we talk about people moving here, it's a second headquarters or their, you know, US base of operations. This company is, you know, like picking up completely and moving to Colorado, which I think is pretty cool, including the employees there. They're moving their folks here.
I think also, to be fair, I didn't see anything in here that said that this company has actually done any asteroid mining yet. So I'm not sure how far along they are in their journey, but it still is a pretty cool concept. Well, vaporware here, right? But, but we're all, we're all buying the futures. Yeah, exactly.
Okay, our next article is, is talking about the new cohort that's part of Techstars Workforce Development Accelerator and the folks that are participating in that. So Techstars is a big tech accelerator headquartered in Boulder. A lot of great companies have come through there over the years. Techstars is associated with the Foundry Group, which is like the big VC headquartered in Boulder, and really kind of the thing that brought VC to Denver. So whenever they have a new cohort, it's great to take a look at those companies and expect that you're going to hear a couple of these things become household names.
Yeah. And so there are a few that are part of this cohort. It's actually a virtual cohort. So not all of the companies have to be here, but a number of them are from Colorado. The first of those is Gritly, which is a skills-based hiring and training platform that helps companies build pipelines of technical talent.
LivedX, or is it LivedX? I think it's LivedX, an online platform that allows learners to build portfolios portfolios of microcredentials to capture and share lived experiences and soft skills. That's a Denver-based company. Yeah. Recruiting Innovation, which is also a Denver-based company, surprisingly is a recruiter training platform that helps companies develop and upskill sophisticated talent teams.
And they also have a nonprofit section. We had a couple of nonprofits, one of which is from Denver. And this is— sorry, it's Access Mode. A nonprofit working to cultivate venture-ready tech companies founded by exceptional entrepreneurs of color. Yeah, that's pretty cool.
Yeah, I had a favorite as I was looking through this list. My favorite's not a Denver one. It's actually called Spatial Guide from Delaware City, Delaware. They harness the power of augmented reality to create service manuals, training experiences, and safety. I just love the idea.
You go put on an Oculus and you can go walk around the machinery that you're going to fix, or, you know, The experiences that you just can't get normally without big expenses and a lot of inconvenience, you get to do that virtually. Yeah. I'd like to see the warnings that are in that, like big Xs, like don't go this way, don't touch this thing. Explosion. Yeah.
I mean, but that's, this is the way you can actually touch it and see how you die. Right. Right. That's the good part. Like what happens if I touch the X?
Oh, look at that. I killed everyone. Yeah. Don't do that. All right.
Next story. This is a story I think that's going to shock everyone, Robb. Tech workers in this survey are rejecting returning to the office, a survey finds. Yeah. So there is one shock to me in this article, which is— and maybe I knew this before, but it's an article written by Dice, as in Dice.com.
Dice is headquartered like a mile from here. They're right by Fiddler's Green. Maybe I knew that and I just forgot. I am getting old. But, you know, I think Dice is a big national company there.
They're a Denver company. Yeah, I guess I didn't realize that their headquarters was here, but I have seen job postings for them over the years. So I guess it's not that surprising to me. I think the article obviously just lays out stuff that we— a lot of stuff that we already know. There is more management wants people to come back to the office.
More, more workers don't, especially tech workers, don't want to go back to the office. When they talk about like what incentives would make you want to go back, you know, all the tech workers said, pay me more money. Right. I think it's going to be interesting to figure out over the next couple of years what's the right balance. You know, it's clearly, you know, not 5 days a week in the office is probably not going to happen everywhere.
But I think, you know, never going to the office probably isn't ideal either. So there's probably some hybrid that ends up working. Yeah. The, the, the stat that stood out to me, which was, you know, in giant opposition here, is that 70% of employers intend to bring workers back into the office at least a few days a week, whereas 60% of tech employees say they preferred to work at home full time. So that those numbers don't add up.
Yeah, I am curious though. As of today, it's still quite a bit of a job seekers market, right? Right. So companies who are looking for an edge in getting great talent, you know, can certainly look to that. You know, if that balances out, I think maybe we see some kind of a hybrid come into place.
Otherwise, it does seem unlikely that people can effectively get sent back to work because they'll all just quit and go to the other companies. Right. Yeah. I mean, I think also with all of these surveys, the questions are always— they never line up exactly right. Right.
Like with that specific question, it was 70% of companies want people to be in the office a few days a week versus 60% of tech workers prefer to be at home. Right. Well, okay, I would prefer to be at home, but if you say you would like me to come into the office a couple of days a week, that's fine with me too, even though I prefer being at home. Yeah. Yeah, and of course, you know, what's— is it a deal breaker on either side?
Something we're gonna just figure out over time. All right, we have one of these lists that we talk about, I think once or twice a year we get these lists, right? This one is Deloitte's list of fastest growing tech businesses. They had a top 500, and 17 companies on this list are here in Colorado. Yeah, good stuff there.
The— one of the things that I noticed here was that The, the number 1 on the list, which is not a Colorado company, their growth was 125,000%. Yeah, that's a lot of growth. And, you know, I can't remember now. I don't have it in front of me. But the whole list had Moderna near the top.
And, you know, Moderna, like, you know, we know— we obviously know them as having created one of the big vaccines during COVID But like, they were a tiny company before COVID and they now became, you know, multiple billion dollar valuation all through their quick research and coming to market with that vaccine. Interesting stuff. Yep. So the number 1 company on the list for Colorado was the number 9 overall, which is Fluid Truck. We've talked about them a handful.
We have talked about them almost 10,000% growth. Yeah. Some others I actually don't recognize. Harvest Hosts, I don't recognize. Arrive Health, I don't think I know them.
Pi Insurance, I know we've talked about before. What about Maxwell? I don't know Maxwell.
A2 Biopharma, don't know them either. Pax8 at 131 with just over 1,000%. Yeah, we know them. They've been a great tech company here in town. Forge Nano, I think I've heard of them.
Then we get to our first security company, CyberGRX, at number 220 on the list overall. They've grown at almost 700%. Yeah. And then the other security company on the list, Swimlane, at number 355 with almost 400% growth. Yeah.
Good stuff. Yeah. Good times. All right. Moving on.
What do we got next? I got it. This is actually from Red Canary. This is a story in Dark Reading. Um, which kind of had a weird headline, to be honest with you.
Um, I, the, I think the real story here is that there's— MITRE has created a, um, a methodology for testing, uh, managed service providers like, like Red Canary and other, you know, MDR providers to see what do they detect when an attacker's in their environment. Basically, they say, we're going to do an engagement with you. You let us know when you see bad stuff and we'll see what things you find. Yeah. Really considering the fact that, you know, it, it's been so subjective as you look at service providers to say, all right, are they better than them or, or not?
Uh, this is a really fun way for, for us to get to, to kind of show off what we do and, and see how it stacks up against other providers. Yeah. And I mean, I think it's cool the way that they do it too, because of course, you know, MITRE ATT&CK categorizes the way that, uh, that attackers work, right? The different, uh, tactics and, and, uh, techniques. And so they can then go and look at those different categories and sort of replay back based on a particular type of attacker, those things, and then see how the managed service providers respond to it as opposed to, you know, I think in the past if you might do this, you know, you might hire a pen tester and then it's really you're detecting that particular pen tester.
You're not protect, you know, you're not detecting an actual adversary and there wasn't a great way to categorize it and things like that. So I think this is much better. And the way you should just take a look at the report reports here. Um, either they— MITRE does not show a winner. What they do is they show at different stages of the attack chain, you know, who detected things.
And, um, you know, I, I'd actually say all of the competitors did really well, um, detecting things at each stage of the attack chain, meaning, you know, if you're going to try and get into the environment, are they going to see you? If you're going to try and escalate privileges, do they detect that? And all that good stuff. Anyway, overall, it's really a good step for the industry, I think, and it'll make sure that people are and actually doing the stuff they claim to do. Yeah, that's good stuff.
All right, our next article is from Swimlane. This is actually sort of a follow-up to that Deloitte article from earlier talking about Swimlane and, you know, their position on the Deloitte Technology Fast 500. And, you know, they were, as part of this article stated, that they are in the top 25 of cybersecurity companies in total out of those 500. Um, and I think there's some other really interesting stuff in this article. They, they went on to expand and talk about notable achievements for the company.
Um, they've had, they, they grew, uh, or they, they raised $70 million in funding in the last year and they've expanded globally. They, they went from, you know, mostly North American to adding in Middle East, um, Turkey and Africa with a new regional VP out in there. Yeah. They also released a new, uh, automation platform, which they call Turbine. Which really expands their low-code automation capabilities as part of their SOAR.
Yeah, they, they have— they hired a new SVP and CTO, um, and they, they also got their SOC 2 Type 2 certification. Yeah, good stuff to them. All right, moving on with our next story. Um, this is a, a blog— it's actually a webinar, a recording from a webinar that LogRhythm had done about a deep dive onto multi-factor authentication. Um, like, I don't know what you call it, spamming basically.
You know, one of the attack types we've seen, and especially when I was at Ping, I was thinking about this a lot, is that attackers, you know, yes, they, they get, they get a password, but they can't pass your MFA because of course without your device they can't do it. So instead of, you know, trying to weasel their way through it, they'll just overwhelm you with, with MFA attempts. Or requests. So at some point, you know, some percentage of users will accept it, right? So if you're, if you're setting your MFA to just always send like that blank push notification that someone can say yes or no to, well, eventually someone's going to say yes.
And whether that's 1% or, or more like 20%, to be honest with you, um, you're going to be, you're going to be hit. So this goes into some ways you can mitigate that. And frankly, it is mitigatable and you can actually eliminate this as a risk. Yeah. And, you know, I will say I've I may or may not have been at previous companies involved in incidents where this happened and, you know, people in the middle of the night were getting their push notifications and they just want them to stop because they're sleeping.
And so they would agree to them and then bad things would happen. So definitely a way that bad things can happen and, you know, you wanna think about how to prevent those things from happening. All right, moving on. We have a blog post from Layers this week. Lair's Local Application Security Company, and Andrew Hay over there wrote a blog around how to choose the right application security assessment company.
How do you do it, Alex? Yeah, so they laid out a few criteria that they thought you should look at, things like history of the company and size, areas of expertise that they have for their testers, reputation, and of course, you know, what many people care about, which is price. And, you know, although the lowest price isn't always good, pricing is, uh, obviously something you want to think about. Yeah. I mean, lowest price might mean that you're, you're getting a Metasploit run-up against your environment.
Um, highest price might mean that they've scoped it too big and, you know, you want to make sure you're, you're, you're getting what you paid for. All right. We got one more thing, right? One more bit of news. Yeah.
This is definitely some good news. Um, our friend of the podcast, uh, Joe McComb, who is the CISO for Holland and Hart, was named a 2022 Top Global CISO by Cyber Defense Magazine. Yeah, congratulations to Joe. Good friend. We're excited for him to, to have a little bit of success there.
And we will look forward to seeing Joe as he celebrates and jaunts around town. Excited. You know, I will never poo-poo someone for having excess, Robb. You know, nothing wrong with a little excess. I'm very excited.
My dog is outside the door, very excited to see Alex. So We're gonna, we're gonna pause and we're gonna come back and talk about whatever's next. All right, now that, uh, the dog is happy and we've done all the petting that needs to be petted, and we can move on. Um, that was the end of the news. Let's talk about events.
Uh, of course, we always talk about the next month's worth of events. We've got a few here coming up in December. If you'd like to see all of them, you can go to the website. We do have a calendar of events there. So again, colorado-security.com/events.
To check those out. All right, first on the 9th of December, ISC² Pikes Peak has their annual chapter meeting. On the 13th, ISSA and ISACA are doing their annual holiday party, which is always a blast. Yeah, it's a big event and it's at one of those museums downtown this year. Plenty of space.
Yeah, plenty of space. Finally, on the 16th, the group Let's Talk Software Security is talking about practicing security within the company culture. Cool. That's the last of the events for this year. After that, you're, you're gonna have to be on your own.
Oh, makes me sad. Speaking of on your own, if you're on your own looking for a job right now, uh, it looks like there might be an opportunity at Uplight. Yeah, uh, Robb, we are looking for a product security engineer. Uh, so if you are, uh, good with AppSec and helping to secure applications, I'd love for you to take a look at that job post or reach out to me. We, we've been talking to some folks but haven't made a decision on anybody yet.
So if you think that that is something you'd be interested, feel free to reach out. Next, there's a, there's a CISO position for Weld County. I think you got to be up like Fort Collins for that job or Greeley. Greeley, that general area up there. So if you're in the north part of the state or you're willing to go there, this might be the role for you.
Vertafore is looking for a VP of Information Security, which is functionally their CISO. CommonSpirit Health is hiring a director of IT cybersecurity. Kaiser Permanente is looking for a senior director of cyber risk defense. I wonder if that's interesting. I wonder if that's running their SOC, I assume.
I believe so. It's probably, yeah. Katie used to have the job. Yes, I think that's the job. Interesting.
Western Union is hiring a senior information security analyst. Denver Health is looking for an IS analyst Security 3. If you're a Security 2 or Security 4, don't bother. That's right. It's not for you.
That's a joke. You should apply. Dish Networks is hiring a GRC information security business partner. Flexential is looking for a compliance specialist. And finally, the FBI is looking for you.
They need a special agent with a cybersecurity and technology background. Nice. I think you just need to be awesome and wear sunglasses well. Then that might be the role for you. Dark suit, all that sort of thing.
Yeah. All right. That is it for the news. We, of course, have an interview this month. Of course.
Our good friend Frank Victory sat down with Dustin Lehr. Dustin is the Senior Director of Platform Security for Fivetran. We've known him from his Staples days. Great AppSec guy. He actually runs that group we talked about, Let's Talk Software Security.
Indeed. So I'm sure, I don't know, I assume they're going to talk about that on the interview. I'm looking forward to find out. I think that that would probably be what they're talking about. All right.
Well, for everyone, this is it for our signing off for the year. Have a happy holidays. Your, your Kwanzaa, Hanukkah, Christmas. Did I miss anything? New Year's is coming.
New Year's, probably something else. But all of the stuff, be happy. Maybe get up skiing or something, you know, enjoy yourself, take a little break, recharge, get ready for 2023. What's the— I mean, what's the day when you have the longest night, the shortest day of the year? Vernal Equinox?
No, that's the other one. Solstice. Solstice, yes. Winter solstice is coming up. Yes.
Yeah, that's worth celebrating. Sure it is. All right. You know, dance around the maypole like pagans or something. There you go.
Nothing wrong with that. Yeah. All right, well, that's it. We'll talk to you guys next year. Thanks, Robb.
Hi, this is Mary Haynes, VP of Network Security at Charter Communications. Welcome to Colorado Eco Security, for Colorado security professionals by Colorado security professionals.
Well, good morning, good afternoon, and good evening, Colorado Equal Security listeners. My name is Frank. I am a guest host on this podcast. My guest today is Dustin Lehr, who has spent 13 years as a software engineer before becoming director or senior director at Five Trad. He works as a consultant building security culture, security champions programs, and has embedded security habits into his daily work.
Welcome, Dustin. How are you today, sir? Doing great. Thank you very much for having me. Thank you.
So I understand you are a senior director at Fivetran. Can you tell us a little bit about that? Yeah, absolutely. So Fivetran is a company that specializes in ETL, or what we like to call ELT. It's essentially moving your data from source to destination, such as a data lake.
Or data warehouse, uh, Snowflake, BigQuery, Redshift, you know them. A lot of people are, you know, data-driven. A lot of companies are data-driven and have a heavy analytics piece to what they do. And we essentially help get your data in the right place so you can run those analytics and, and ultimately make those decisions. Awesome.
Awesome. Talking about older technology and older items, You've been around for quite some time. I mean, this is not— you're not new to this business, right? Yeah. Yep.
I mean, I did study computer science back in school at CSU. I've had several development-focused software engineering jobs and roles along the way. Like you mentioned, you know, it was over a decade that I spent as a software engineer. A lot of industries, retail. I worked in the DOD for a little while.
I worked on video games and then more recently started to work at Staples as a data analytics software engineer. And then shifted into kind of more of a, you know, architect role, application architect role. And from there it was kind of a natural move into the security industry because As an architect, you're always thinking, you know, about things beyond just making it work, right? You want it to be maintainable. You want to focus on quality and security is always kind of a big focus on your mind as well.
So I shifted into a security architect at Staples and then eventually was given the opportunity to lead the team. I did that for about 3 years and then about a year and almost a half ago, I went to Fivetran to essentially build an application security function there from scratch. So. That's, that's my background in, in very short form. Well, here's one interesting thing that you just told me.
We, we obviously are here in Colorado. This is the Colorado Equal Security Podcast. You went to CSU. Have you always lived in Colorado? I actually have, yeah.
I was, I was born in Englewood. I grew up in Castle Rock. Okay. And yeah, made my way up north to Fort Collins for school, and then I've always lived you know, kind of in the Denver suburbs ever since. So I love to ski.
I would— I can't see myself ever leaving the state because of everything it has to offer, right? Skiing, the hiking, the outdoors, the camping. We all know it. Being here in Colorado, I've never went anywhere else and thought, hey, I want to live here instead. It's always been Colorado.
So, wow, great state. That's interesting. I, I do love the state. I grew up here as well, although interesting enough, I don't ski. I haven't really skied at all, and, uh, I think that's kind of sad.
I was like one of those things where I'd eventually get around to it, and being that I'm old and decrepit now, I'm no longer. So, you know, it's never too late to start. Yeah. Yeah, it is much easier. I, I started at 6 years old and I've trained all 3 of my kids to ski at this point.
My 15-year-old, I started at 3 years old. My, and both my 6-year-old and 3-year-old have been up skiing a few times at this point. So, wow. So where's your favorite place to ski? We typically go to Eldora and probably my favorite place though is still, is still Keystone.
I do enjoy Keystone and Brecken, kind of that that whole area in general. Okay, I, I do like Breckenridge. I think that's awesome. So cool. Well, you like skiing, you love Fort Collins, or you, you lived in Fort Collins, or at least was going to college there, and you're currently of course living in the, in Colorado area.
What was it like to create a new video game from scratch? I, I saw, I thought I saw something about creating video games I mean, you have DOD experience, you have retail experience, but video games for some reason sounds very fun. Is it as fun as it sounds? Oh, there's a lot behind this story. You know, to, to kick it off, I would say, you know, always been a gamer since, since I was a kid and always wanted to know how they worked and how they ticked.
And I always aspired when I was studying software to be a video game programmer. And what I would do is, is during my, you know, kind of day jobs, I was working on video games on the side in order to demonstrate my abilities to crack into the industry. Eventually did get that shot and worked for Sony for a couple of years, which You know, I think the video game industry is— it's highly competitive, especially when it comes to the software side. And they— it's not a— it's not an industry that pays all that well, and there's deadlines to meet. It's very much in line with the rest of the entertainment industry, right?
There's projects that come up, projects that are canceled, very fast-paced. And eventually I decided It wasn't for me. So even after all that hard work on the side and cracking into the industry, just decided it wasn't actually where I wanted to end up. And I had to go figure that out. There was no way for me to ever know that without actually trying.
So it was, it was a, it was a good experience that I'm glad I had, but I'm also just as glad to have left it. So you spent a lot of time saying, I wanna be a video game designer, wanted to really get into video games, get into the entertainment industry. And then realize it's not as entertaining as the entertainment industry. And to some extent, it comes down to just, just hard work. And some of my logic here was I could do this hard work elsewhere for better pay and have people around me that I enjoy.
And it's just, yeah, it was one of those life lessons. You know, you think you want something, especially as a younger person, you get there, you try it out, and you, you decide it's, it's not for you and you move on. Okay, so let me put you— give you a situation here. You're obviously older now, and if you had the ability to talk to yourself back in what, your teens, about this, is there any advice that you would give yourself 20 years ago if you could go back in time? There's so much advice I would give myself.
Yeah, specifically about the video game or about creating the video games. Is there something in there that says, hey, I really either do this, don't do this, change this, something along those lines?
I, I would say, you know, take, take the time to really understand yourself and what you actually want, right? Is it the development of games or is it just creating something of value? Is it playing the games or is it actually creating the games that you're interested in? You know what I mean? Like, be real with yourself, be truthful with yourself.
And I think that's— it's a lifelong lesson for all of us to learn how to do that. You know, to really get to know ourselves and build character and just spend the time and the effort to understand what you want. Yeah, I'm also picturing my reaction as a teenager to that, and my reaction as a teenager to that would be like, yeah, whatever, I don't buy it, I'm just gonna do it anyway. So I think that's I, I think it also, it takes years to train yourself to, to listen as well, you know, even to your future self. I, I think though that, and just from what I've heard, being real and being passionate, I guess a little bit about you, one, that's almost advice that you can not only give to your younger self but anyone coming to the industry, maybe anyone that's just got into the industry, been here for a few years, or Honestly, maybe as a reminder for some of us that have been very seasoned, right?
Yeah. And this is a theme that I talk to my, my team often about and also to anybody looking to break into cybersecurity. And that's start with what you want. Like, really think about what your— where your interests are and focus on that. Because I think when you find what that thing is that you're very passionate about, Your career just takes off.
And that was my experience in joining security. I love software and I loved building software. I love the problems. I loved, you know, bringing creative solutions and new ideas and new innovative ideas to the problems. But it wasn't until I found cybersecurity that I felt home.
I felt like, oh, this is what my whole career was building up to. And I'm just extremely grateful for that. So I think anything that folks can do to find that sooner is only going to serve them better. Hmm. Well, that's interesting because, as, as you know, I teach a lot at the university level and we're taking a lot of inexperienced folks, trying to get them into cybersecurity.
A lot of them, it's a jump. They haven't even been in IT. Who are trying to bring them up to that security level, when they ask me, well, what kind of job should I look for? Or what kind of jobs— more importantly, what they'll ask me is, what kind of job should I accept? And my thought behind that, at least from that beginner's level, is accept anything.
Get your foot in the door. Try what you want. Because honestly, at this point, you don't know yet what you want. Give me some thoughts about that, either positive, negative, feel free. It's a really good point.
I think there's a balance there because I think if you sit back and say, well, I only want to do a very specific thing, well, that there may, you know, you got to eat and there may not be a job out there that fits your profile perfectly. Is it really something that you want to do and that you can see yourself doing in the future? Even as a, even as a young person, I do think you have— young in your career, by the way, not necessarily age, because it's never too late to start. Like we talked about, I think you can to some degree determine that as well. So it's hard though.
And like you said, sometimes you don't know and you just have to go try stuff. And I think being active and going out there and part of the search is actually trying stuff and experimenting and saying, Well, I'm going to do this and I'm going to see if I like it. I think that's perfectly fine. Do that for a year or two. Become a stock analyst for a year or two.
See what you like and go from there. Well, I think that's an important part of what you said is try it for at least a year. As much as you may like or hate something, try it for at least a year and give it a point to keep going. Yep, I agree with that. Because the other thing too that, that could emerge from a role like that is that you're— and I would, I would highly encourage folks to bring their own self to that role, right?
Like, if you're going to become a SOC analyst for a year, it doesn't mean you need to emulate what all the other SOC analysts are doing. You know, learn the craft, learn the business, learn what's valuable, what the goals should be, what you're supposed to be aiming for and accomplishing. But bring your own flavor and nurture and unique background and skill set as well, because I think that is what the cybersecurity industry needs is different, more innovative and thoughtful approaches to what we do. This is not a solved thing. This industry is not solved.
There are plenty of major issues that we deal with all the time. And frankly, we could use new approaches. You know, and different backgrounds. And, and that's what I would encourage people to think about. Like, don't feel like, well, I don't have the perfect background.
I can't get into cybersecurity because I'm not the archetype, you know, technical person. Well, I mean, try anyway. Like, if you're, especially if you're enamored with the industry, bring that unique background, whatever it is. It could be education. It could be Marketing.
Maybe you're a marketing person or a salesperson or something, and you're thinking of getting into it. I'll tell you what, from a cybersecurity awareness perspective and stuff, we could use better marketing. We could use better sales talent across the industry to sell these ideas. You know, how do you sell the idea of cybersecurity to senior leadership? That's a talent that a technical person may not be able to bring as well as a salesperson.
You know, so don't discount your background. Give it a shot. Oh, that's cool. So everybody has something to offer is really what I'm hearing. Absolutely.
Yes. Depending on your background. So in your background, you have some other skills that are not related to cybersecurity, something like guitars or music? Yes. I've been playing guitar since high school.
I actually do find that a lot of technical folks are musicians themselves as well. Don't hesitate to ask the question because I think people will emerge that you didn't even think, oh, I didn't know this hardcore software engineer was a creative musician as well. But I think it's more common than you think. So for me, it always brought balance and it always brought kind of the creative side to my life. I was part of several original song-focused bands.
We wrote our own music, we composed it, we got out there and played in various venues across Denver. It was a blast. It's been a few years since, since I was in my last band, but I also took a lot of lessons from that, especially when it comes to leadership. Frankly, you know, things like how do you bring together a group of 4 very passionate folks and somehow create music that you can all, that you all play and, and are passionate about. You know, like that, that's a major challenge.
Everybody brings their own opinions and unique voice and all of that in the creative process. And yeah, I just, I learned a ton from a leadership standpoint. I'm going to put you on the spot here. Okay. Compare leading a band to leading a cybersecurity team?
Is there similarities? Maybe the differences? Are there anything that you can compare? Oh yeah, there's a ton. Okay.
Kind of, kind of like what I was just saying, where everybody brings their own unique thoughts, ideas, opinions. Same thing with a cybersecurity team, right? Everybody's got their own unique approach and all that. How do you, you know, align everybody to march in the same direction? I think so.
One of the biggest kind of metaphors that I usually use from the band days is that your music is going to sound slightly different based on who's in the band. So let me, as an example, right? So, you know, we would have a drummer, they would play the drum part of a specific song in a certain way with their own style. Great. They move on, you get a new drummer.
What's going to happen? Are they going to play the song the exact same way? No way. And you wouldn't want them to either, because you want them to bring their own unique touch to it. Maybe they would even improve the song.
So it's the same thing with composing teams. Your whole team dynamic changes when you have new people join. Right? So you have to account for that and you have to say, okay, you know, my team now specializes in this slightly other area that, you know, maybe we didn't have a strong skill set in before because of our new addition of a teammate. So there's a lot of, you know, kind of flexibility.
And the other thing that I would say is that people are— people should be allowed to play their song, you know, the song in the way that they want to. Like, they're the expert in their instrument, right? I play guitar. I'm going to play guitar in the way that I think sounds appropriate for the song, but I can't tell the drummer how exactly to play the drums because I'm not a drummer. He has to come with his own unique style and skill set.
And it's the exact same thing with, with cybersecurity teams. And so the team dynamic changes depending on, of course, the members. In both situations. Yeah, absolutely. And, and to find those skills, like on a cybersecurity team, find those skills and interests even that are unique to each individual member of your, of your team.
And, you know, figure out a way to inspire that to come out so that you can ultimately have them be as productive as possible. Right? Like, for you to dictate, hey, I want you to play the drums in this very specific way, destroys all their creative power and freedom at that point, right? But if you say, hey, I want you to play it your way— I can't drum, you tell me how to drum, you know, or don't tell me how to drum, but you, you know, you play the drums in a way that is going to enhance the sound of the song It's the same thing with cybersecurity, right? You bring your unique skill set and do it in a way that's going to enhance our team and do it right, do it your way.
So that's good. I mean, bringing out that creativity, bringing that individually, everybody has something to bring to the table, and I think that's awesome. I have a kind of a question. I was reading through some of the notes and I heard something about drop your nose and getting yourself— is it, did you give yourself a nosebleed or Yeah, this is an old, old story. So this is, this was back in the day when I joined my very first conference.
You get into the tech industry and you get sent to trainings, you go to conferences, you kind of get out there and socialize and build connections and all that. So I went to a conference and it was, it was in DECA. I'm just remembering this right now. This was like a front end. Display engine that I was learning about.
It had a whole backend component. It was, it was really cool. And I went to their conference and they had one of those social events, right? Where, you know, hey, there's a bar, there's drinks and, you know, you mingle and you just kind of get to know your peers and all that. And more experienced people and trying to talk to them.
And my drink had one of the little red straws, you know, in my, in my Jack and Coke at the time. I went to take a drink, but I forgot the straw was there. So I literally went in and the straw went up my nose and like smacked into my nose enough for my nose to start bleeding. And I had to excuse myself and say, I'm sorry. And it just like leave in complete embarrassment.
So yeah, so I definitely learned to manage the straw in my drinks, you know, going forward. So yeah, that's, that's the story. So you, so have you, you learned how to manage the straw? Maybe, uh, we can even bring that into managing little stray components in your life or in your work life as well, right? Sure.
Detail-oriented, right? Detail-oriented. And be, and be conscious of your surroundings, just kind of work life in general, especially when it comes to cybersecurity, right? Like trying to put together the bigger picture. Why are we pursuing this strategically and what is the impact and, and, and all of that, you know?
So yeah, so I think that— I think we extrapolated further lessons from the straw experience there, but I think they're relevant.
Well, let's see, you've been a— you've played guitar, you toured. What other odd jobs have you had?
Yeah, so, um, I will say some of the best jobs that I've had were in high school where I basically didn't have to do anything at all. Um, I remember working for a driving range that nobody ever went to, so I would basically just hit, hit golf balls all day, right? Which was awesome. And then I even worked— you got paid to hit golf balls? I got paid to hit golf balls.
And, you know, people would show up every once in a while and I'd be like, okay, here's your bucket. And then they would hit and I would just hit next to them. It was just a blast. I mean, we had to clean the golf balls and pick them all up and do all that stuff as well. But for the most part, it was a lot of just messing around.
Um, and then, uh, I had a similar job at a batting cage that nobody ever went to. You know, so I would just literally hit, hit balls all day. Again, hit baseballs, right? All day from the batting cage machines. Um, even to the point where I actually taught myself how to bat left-handed because I spent so many hours batting right-handed.
I got, I got bored. I was on the fastest, um, machine and I'm like, let's see if I can work my way up to the fastest machine again, batting left-handed this time. And, and went all through that anyway. Um, so that all is to say, those were some nice solid jobs, and they definitely did not prepare me for the real world whatsoever, but they were still some— they were decent as a high schooler. Hitting balls and learning how to hit the fastest ball and then giving yourself a challenge by not using essentially your, your dominant hand— none of that has helped you build a security champions program though?
Uh, because that's one of the things that you have been working on is getting a good security champions program, and it's not easy. Definitely not easy. Yeah, I like how you, how you, uh, did your segue there. I think, um, I think for me it's always been about the challenge, you know, like you don't go into college and, and study computer science unless you want a challenge. And you don't try to build or change culture through security champion programs without embracing that challenge.
It's very challenging. You know, you're trying to win hearts and minds. You're trying to change the way that people work and their habits. And people are very hard to change in general, you know, like, so anyway, so I do like to bring unique ideas and new approaches to building security champion programs that include you know, motivational pieces, gamification, to really be innovative here. I think the industry, there's still a lot of potential here to understand, you know, how we can influence behavior.
And frankly, we need help from, from everybody. You know, you can't have a small security team running around doing everything for everyone. It's not like you can manually review all the phishing attempts from everybody, you know, that drops in people's inboxes. So You have to train people and you have to incentivize them to make the right decisions themselves. And that's where I think cybersecurity should focus to kind of put, put more effort into.
You know, I definitely see a lot of, hey, we'll, we'll do this for you, or how do we automate this away in the conversation? I hear a lot of things that I know we've all heard about people are the biggest opportunity, but I don't see a lot of active efforts to, to really fully realize people's potential to help our organizations. So that, that has become very much a passion area for me and my career in general. Well, I mean, I think you have a unique part, at least in one of the biggest areas, to build a security program because you have been a programmer, you have been a software engineer. And software engineers, as some of us know, or at least some of them are, they live on that SDLC.
That's a very tight schedule. We want to live— we got to stick really, really close to that SDLC. How do you sit there and create a security champions program from folks that are in a very tight schedule and try to add a new program? How do you motivate them? Because I don't think skills are really an issue with software developers.
I mean, they know if you teach them what to do, they can probably do it. Uh, to become a software engineer, you have to put a lot of work into code and things. And honestly, in some ways, security is just a different type of code or writing the code in a different way. But how do you motivate them to want to do a better job?
Yeah, so I think there's a lot of different techniques. I think one of the things I would say to not try to do at first is to try to change everybody. I think there's an element here where you have to find your allies, is what I like to say, across the organization. It's the people who have a tendency or a proclivity to, to toward quality, and they care about not just delivering, they care about doing it right. And when you start the security conversation with them, they're intrigued, their eyes light up, and they're like, whoa, this is a whole new dimension.
Those are your champions. Those are your first— that's your first cohort that you should work with closely. And then what happens there, it's the theory of diffusion of innovation, right? Where, as you know, as you do work more closely with those people, the word starts to spread, right? And other people get inspired by what those people are doing, all the way to when you reach the laggards who at first you might have talked about security and they're like, we don't have time for that, we're not interested.
Now what you've done is you've started a movement across your organization that will eventually reach people. So, so I think that, I think that's important, but I also think to some degree you can appeal to people's extrinsic motivations versus their intrinsic, right? So what I was talking about in terms of finding your allies and the innovative folks, they're, they're more intrinsically attracted to this idea of security, but there could be other extrinsic factors that you can appeal to for the masses at a, at an organization. Including things like recognition. Maybe people want to be seen as the technical expert in their area.
If you can give them a reason why security will help them along that path, they're going to have to pick up security along the way, even, even if that's not their primary goal, right? So, and that's kind of where the gamification elements come in. Like if you can recognize, hey, this is a SME, this is an expert in this area, and reward them accordingly, then that could have a major impact on their motivation ultimately. So yeah, there's a lot of different techniques out there. Gamification is an absolutely fascinating field, and I think it has a strong place in cybersecurity in general.
Why are people going to be looking out for phishing emails? Is it because they recognize all of the impacts of not doing so that we on the security team know? No, but they do understand that if they're the top person who reports phishing emails that month, that they get some kind of reward. Maybe even they have to take less training than other people on phishing emails. That's tangible stuff that I think people latch onto, even if they don't understand exactly why it's important.
So there's a lot that we can do, I think, to give people that path. Because eventually, if they are somebody who gets recognized as doing the right thing when it, when it comes to security, then I think eventually they will start to understand the why. Why is this important? You know, you've piqued their interest at that point. And I think, I think that can lead them down a very positive path to learn more.
That's great. Uh, and I like that you were showing more than just monetary value. I mean, budgets are tight as always, and that nothing has changed in there. You don't always have to give them a monetary— I mean, money's always nice, prizes, but you also gave them a point of saying, hey, you're this me in this area, you're the subject matter expert that you can teach and really be at that top of the chain. And I think that's a great, awesome way to motivate people.
Yeah, we had a— so we have a belt leveling system at Five Tran, follows karate belts, you know, white, yellow, all the way up through black belt. And you essentially, based on your actions, you earn those different levels, right? So I have a, I have a really interesting story that I want to share, and that's one of our security champions. They were taking classes and they were learning about cybersecurity outside of their day job. They're actually a sales engineer, not a, not a developer, still technical, of course, but essentially because of all that extra coursework, they learned a ton and they moved up the ladder very quickly, all the way up to black belt within a few months.
And when they did that and they became a black belt, what we did is we shared that information with Everybody that we could. Hey, this person goes above and beyond. She went outside, she took classes, she did all this stuff, and she earned this highest level as a security champion. What happened was that inspired her as well. So she got recognition from her manager, from our senior leadership, et cetera.
She got inspired to then start a security club, essentially at Fivetran. Where other folks have joined. They meet weekly, they talk about security topics, they write summaries of articles that they read. They're very active when it comes to security now, all because all we did is we recognized this person's effort. And, and the thing that fascinates me that I love about this is that you can't dictate this type of action.
You can't tell somebody, hey, I need you to start a security group. Well, I'm not going to pay you anything extra. It's going to take a bunch of your time, but just go do it. You can't do that. You have to inspire somebody to take that on themselves.
And that's what this program did. And that to me is a major win. Awesome. Well, let's finish up. Uh, let's— this is of course the Colorado Equal Security Podcast.
Let's finish this up with what do you think is the greatest security challenge today? Now, not necessarily solving it, but let's address what do you think is going to be the biggest security challenge? Yeah, I mean, we talked a lot about the biggest opportunity being people. I think the biggest challenge around understanding our environment, specifically around inventory. Asset inventory.
Any security leadership walks into an environment, the first thing they need to know is where's our risk, right? And, and before they even ask them that question, they need to know what's out there. What do we do? What are our systems? How are they deployed?
What's our code base look like, right? All that stuff. But what I don't see in the industry as a whole— and this isn't even just on the cybersecurity industry, it's kind of in the tech industry as a whole— We don't have a good handle on that. You know, I think, I think that we spend a lot of time getting solutions out the door. We don't necessarily spend the time to track all of our deployments, everything that's out there in a way that we can then query, ask good questions about it, add additional information about it, things like a risk score for every asset, you know, that kind of stuff.
So I just think there's a lot of untapped potential. Around that. I've spent a lot of time actually building custom inventory systems that provided a lot of value. Think Log4j for a minute. Imagine being able to type into a system, just show me all the places where Log4j exists and tell me all the teams that support those systems so I can go have a chat with them.
We had that system in my, in my past that built systems like that. The other thing too that I'd like to say without plugging too hard is that That's where Fivetran can also help because it helps you build that data lake that could become your inventory system, right? If you can find a way using products like Fivetran to find the data in your environment, pull it into that data lake, now you can start to ask and answer those, those very interesting questions about your environment. So, and we are, we are building a system like that within Fivetran and it's become very helpful. At this point.
Well, you definitely hit on one of my biggest pet peeves, which is asset management and being more on the infrastructure side, I think, of hardware. But you bring up a really great point. Where's your data at? Where are those parts? Where are those pieces where your data is at?
Do you know where your data is at? Is it at risk? Because how can you protect something that you don't know about? Yeah, I think another big piece here is ownership. Even on the hardware side, there's a problem with the system.
What team actually maintains this system? Can you quickly look that up in your organization or not? From what I've seen, that's, that's not a SQL query in most companies. It's, it's, you know, it's a series of meetings and questions to try to figure it out. Yeah, and that's very slow and inefficient, and we need to do better.
Yeah, well, what I've found, and I think you've said this in the other part, is when you're looking at assets— and we all have this, unfortunately, we all have those assets that are out there that nobody seems to know about— can you identify at least who was the last person to log on, or grab the last 10 logons and see who those last 10 people are. Yeah. And that will help you get, at least hopefully, into who maintains it. 100%. And to do that successfully, you also need to understand your org structure because, okay, that's nice that this random person whose name you don't recognize actually maintains this, but how can you trace that into, okay, who's their manager?
Who's their team? Who should I actually reach out to about this? You know, you can reach out to them of course too, but like a lot of what makes you effective as a security team is understanding your organization and who, who to contact for what. Right. So I think that's an important piece that, that we don't account for enough, you know?
And the other thing that you brought up that I think is important on the software side is like, who made this last commit? Who? Most likely owns this code base or this repository can be determined by who's actually committing code to it. You know, so if you can take that information and trace it to the right team or manager, now you know who to go to to take action. That's great.
Well, we're running out of time. Is there any last parts that you'd like to give to the Colorado Equal Security Podcast? Any, any last opening thoughts, whether it's security-related, whether it's personality-related? Related. Anything else?
Yeah, I, I would say this, this is something that I've had a lot of conversations with folks there and get involved. I would say as a message in general to folks, I think it's really easy, especially with, you know, COVID and some of the isolation that we've had to deal with, to just get, you know, get kind of stuck and, and just focus heads down on the technical problems or for the work itself, but I think a big piece of what makes somebody successful is their ability to communicate, to create connections, to have an influence over the industry by getting out there, you know, and talking to people and going to meetups and going to dinners and that sort of stuff. So I would just highly encourage anybody, even if you're just breaking in, You know, to get out there, put your name out there. One other thing in line with this, I would say as well, especially if you're just getting into cybersecurity, is reach out to other cybersecurity people. Just send them a note.
Not everyone's going to respond, sure, but there are people who very much will, and they're going to remember you. I get reached out to by folks all the time, you know, hey, I'm confused where to go with my career in cybersecurity. Do you have 15 minutes to chat? Absolutely, I do. And I think you're going to find a lot of experienced leaders who will make the time to help other people.
You know, somebody helped them once, and, you know, there's a desire, I think, to reciprocate and to give back. Well, that's great, and, and a great closing note, because I know you do that. You do a lot of mentorships. I saw some of your meetup groups and your podcast. I do the same thing.
I give interview workshops. I mentor quite literally over 100 students every year and help them out trying to get their careers going. I do want to thank you for your time. Again, you are Dustin Lehr, Senior Director of Platform Security at Fivetran. You also build a lot of security champions programs.
And again, I want to thank you for your time. I appreciate you taking— sitting there talking and speaking to the Colorado Equal Security folks. My name is Frank. I am a guest host again on the Colorado Equal Security. Remember that we do have a Slack channel.
Join our Slack channel. Get out there, reach out to folks. There are plenty of people that will help you, whether you're experienced, whether you're new to the industry. I am also with the Denver OWASP Group. So remember the meetup.com/denver-owasp.
We do have our upcoming SnowFROC conference in March 2023. So check out snowfrog.com. And again, thank you for your time. Dustin, I will talk to you later, sir. Thanks a lot, Frank.
It was great to chat. Thanks for having me. Thanks, Dustin. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
At colorado-security.com.
Until next time, remember, Colorado equals security.