All episodes

5th Anniversary + Drew Labbo

Apple Podcasts Spotify SoundCloud

We can’t believe it’s been five years. It feels like just yesterday that we first sat down and talked with you. To celebrate, we’ve brought back our first guest ever, Drew Labbo. We’ve also got news from Oskar Blues Brewery, Gevo, Inc, UCHealth, Guild Education, ByteBackLaw, Ping Identity and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript14091 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 232 for the week of February 7th, 2022. That is a pretty big number, both 232 and, uh, the fact that it is 2022.

So Alex, yeah, what were you doing 5 years ago today? 5 years, and today being the 6th of February, which it actually isn't right now, but you know what I mean? Uh, I think I was recording a podcast. Can you believe it was our— well, I probably wasn't actually recording it. That's, I think, the day we released it, but yeah.

You know, so, so I guess really what we're trying to say is this is the 5th anniversary of the very first podcast. What, what is a 5th anniversary, Robb? I didn't even look it up. Is, is it, uh, like charcoal or, uh, linen? It's butterscotch.

Butterscotch is for— is the thing. Werther's candies. Oh yeah. Sponsored by Werther's candies. That seems about right.

Anyway, um, 5 years. Can you believe it? 5 years. I can't believe it. I was talking to one of my kids about it today and thinking, holy smokes, this show is like more than a third of his life and like a quarter of my marriage, all wrapped up in the show.

It's a little bit sad sometimes.

No, it's happy. It's very happy. This has been a good thing. It's been fantastic. Yes.

So 232 episodes over the last 5 years. We've learned a couple of things. Maybe we'll talk about it at the end. Or maybe we won't, because that's the kind of thing we learned is how to build suspense. One of the other things that we've learned is that we should check to make sure things are recording so that we're not doing this twice.

This week, we're going to make sure we do this once. Yeah, we're doing good. I see the little, the little thing moving up and down. That makes me feel good. The equalizer bouncing around.

Hey, why don't we jump into a little bit of housekeeping and we'll go from there? Let's do it. You know, Robb, we have a Slack channel. Uh, it's probably the greatest thing about Colorado Equal Security. Uh, lots of great discussion on there.

We've got, you know, over 2,000 of our closest friends that hang out and discuss things. You guys can, uh, come and join if you'd like. Very simple criteria. You got to be, uh, in Colorado-ish and interested in security. And you can find somebody that's already on there to invite you, or you can go to the website and sign up with the form that is there.

While you're on the website, you might as well get on our mailing list. I'll tell you one thing, it's not going to overwhelm your inbox to be on that mailing list. Maybe once a week, once a month, you'll get an email from us with a list of interesting news happening in the area. Maybe occasionally you might get a link saying that there's a salary survey that we're going to be doing or something like that. Very infrequent emails, but I think they're pretty high impact.

It's worth signing up. I agree. You know, also this podcast, it gets pushed out automatically if you sign up for it. You can subscribe on your favorite podcast player. Uh, and while you're there, it would be great if you rated us.

Um, you know, we don't really care about listeners. We, we hope we get some, but if you rate us, maybe some more will show up. Yeah. If we, if we really cared about having more listeners, we would do better. So I think you can tell by the quality of the show that we're really here for the fun.

If we wanted more listeners, we'd just buy them. We do get emails on a regular basis saying that if we, if we just send them some money, they'll get us more listeners. Exactly. Also, we'd love it if you told a friend, let them know how great Colorado Equals Security as a movement is, all the things that are going on, get them involved. That could be the podcast, it could be the Slack workspace, it could be a bunch of stuff.

Yeah. And last but not least, we want to just say a huge shout out, big thank you to our patrons. You know, the show, even though we, we may not put in a lot of effort, it does still cost some money. It does. And, uh, we appreciate those people who are subsidizing this.

Um, you know, there's been some really loyal supporters of the show for almost the entire time we've been doing this. So big thanks to the, the longtime supporters, and big thanks to the recent supporters as well. If you want to sign up and help support the show, go out to colorado-security and click on the Patreon link. All right, with that, let's jump into the news, Robb. An inner drink, energy, energy drink.

Man, it's like we've never done this before. Monster, you may have heard of them. They have bought Colorado's largest craft brewery. So Monster, like the, the cables, like, like audio cables? No, no, no, no.

It looks like for jobs, like something scratched through a piece of metal and made an M in a can. Oh, the drink. The drink. The drink. Okay.

So they bought, they actually bought the, the makers of Dale's Pale Ale. They did, um, which is actually— there's a group called Canarchy Craft Brewery, uh, which Dale's Pale is part of, along with several other breweries including Cigar City from, uh, Tampa, Squatters and Wasatch Brewery of Utah, Deep Ellum of Texas, and Perrin Brewing Company of Michigan. So now they are part of the Monster family. So the, the brewery that made Dale's Pale Ale is called the Oscar Blues Brewery, and it was the largest craft brewery in Colorado. You know, one of my favorite things about reading these articles, if you, if you get all the way to the end, they often throw, throw in a random fact.

I did get to the end this time, and Oscar Blues launched in '97, but it was actually a blues music-focused Cajun restaurant and live. Oh, that's crazy. They were not a brewery. And but the guy who owned it started making his own. So his name was Dale.

Dale, I don't know if you say Ketchum, Ketchum, Ketchum. Um, he started brewing his own stuff there in the restaurant. He's like, man, this is actually going even better than the restaurant. I should start, uh, I should start, uh, selling this. And he did not just go bottle it like most people would do.

He started canning his beer, which was unheard of and has swept the nation since. Yeah, now, uh, canning is the biggest thing in, in craft brewing. Uh, you even go to, uh, some craft breweries and you can get a, a can to go. They'll just can it there right for you. See, I love it.

So anyway, um, now they're owned by Monster and they'll probably have some sweet beer energy drinks coming. I, I can't wait. Yeah, because that's, you know, uppers and downers in the same drink. That's exactly what you need. No recipe for disaster there.

They say not to mix alcohol with some things, but if they mix it for you, it's, it's probably fine, right? Don't try this at home. All right. This is not medical advice. We are— we're going to move on.

Next, next story here is about a Colorado company that is going to be turning cow poop into fuel. Yeah. So this company, they're going to be working in Iowa and they're going to take cow manure and they're going to refine it essentially and capture the methane and turn that into natural gas. I mean, it is sort of natural because it comes out of a cow's butt, but pipeline quality natural gas, pipeline quality. You don't want it, don't want that inferior natural gas.

So, but the good news is, I know what you're thinking to yourself is, okay, but can I still use the manure for fertilizer? Like, I'm sure that's what you were asking. The good news is, yes, you can still use the manure for fertilizer even without the smell. That's crazy. Yeah, I never would have known.

Yeah, I mean, I think that this is interesting. And I'm a little bit torn in reading this, whether— and they give some good reasons in the article about why this is a good thing. But some of it just, it does seem a little bit like greenwashing to me. Right? It's because you're still making natural gas, which is also, you know, you burn it, and it's still a pollutant, as opposed to pulling it out of the ground.

So you're, I mean, you're not putting all the infrastructure in to pull it out of the ground. Isn't the methane already made by the cows? Aren't they just capturing the already created methane? Yeah, it was a little confusing to me anyway. Maybe it's a good thing all in all, but it was also— it raised one of my red flags and said, hey, what are your hairs?

Straight up, my one hair, the one hair on my head that I missed when shaving today. Raised up. All right, let's keep it moving before anyone starts. All right. All right.

Robb, did you know that there are a number of Colorado companies that are starting to adopt 4-day work weeks? So, so I can see why you'd think that from the headline, but the number is 2 as far as I can tell.

Oh, so you actually read the article? There are a number of companies doing this. 2 is a number. 2 is a number. So the headline says Oh shoot.

Why? Here's why Denver tech companies are adopting the four-day workweek trend, and and there are two examples of companies that have done that, and they are both like thirty or fewer employees. Yeah, that they're adopting the trend, and the trend is to think about adopting a four-day workweek. Yeah, there's there. I think there's a survey here, right, to say our company is thinking about it.

And what was interesting to me is, you know, I don't remember the numbers off the top of my head, but the overwhelming number of employees, of course, were interested in this. But the survey showed that an overwhelming number of employers are also interested in this. So you got to wonder who exactly is stopping this. I feel like it's just momentum. You know, people just need to just take a look and go, okay, we're going to do it.

Let's just do it. Do it.

So is there any actual news in this? No, there wasn't really a whole lot in this article. I think just, you know, look into the future. Maybe soon there will be 3 companies that are at a 4-day workweek. And there was one tidbit that the reason that we have the 80 or the 40-hour workweek is the— was it the Fair Labor Act?

Oh, yeah. Early 1900s, 1930 or something like that. And so, you know, it was at that point, it was a protection to make sure that people weren't overworked. But now it's essentially saying it's kind of the opposite way. We're locked into that because it was the We made that protection.

Yeah, and that was for hourly workers too. I will say that we have talked about this company Uncharted numerous times on the show. They're the ones who made the decision to go to the four-day work week and and shared their experience. They're they're mentioned in here again. They're one of the two.

The other one was Signified, Signified, Signified, Signified, probably Signified. And they're They have nearly 35 employees.

Just a direct quote. So a couple of smaller companies have been successful with this. So is it like one of their employees pregnant or something and it's like nearly 35? Maybe someone's starting soon to get them to 35? Maybe.

Could be. Hey, let's keep moving. This one is another update on a kind of a trend that we've seen. Guild Education has partnered with yet another massive employer to help offer education and upskilling as a benefit within it. So in this case, it's actually a local company.

You know, we talked about them partnering with— was it Walmart that we talked about before? Uh, Target could be one of those. They did Target, maybe. I think it was. I know they did Target.

Um, but anyway, this is with UC Health, and this is, uh, them offering these— this service to the 25,000 UC Health employees. Yeah, I, I thought it was pretty cool. And as we've talked about before, Guild Education helps companies offer additional education to their employees as a benefit so that you can, you know, get a degree or get an advanced degree as, you know, as part of a benefit for your employment. One of the cool things that I saw in this article was that UC Health is eliminating some of the requirements in their job postings for having a degree because people will be able to get that degree while once they are hired. Yeah.

And specifically, even for high school diplomas, which you might have thought they wouldn't move, right? They— the— I didn't know this, but Guild Education can help you get your GED. Um, and so now they're able to remove that requirement, they can get it on there. So obviously opening up a whole new workforce. Yeah.

A couple good ways. I think that's awesome. And one other factoid I got from this is that UC Health expects to invest up to $50 million in this program over the next several years. That's a— it's a big number. Um, I believe they also said this is the biggest partnership that Guild has so far locally.

Oh, did I miss that part? Yeah. Oh, biggest local, biggest local one. Yeah. Yeah.

So anyway, pretty cool. Some good stuff. All right. What do we have next? We have a letter from Governor Hickenlooper— sorry, Senator Hickenlooper.

Senator Hickenlooper and Colorado Springs Mayor John Sothers. So this was a sort of a joint message, I guess, from both of them talking about partnership and how Colorado leads in national security. So my, my takeaway here is this is a propaganda piece, but it's propaganda we can get behind. Exactly. Because it's talking about all the good stuff Colorado does for cybersecurity, talks about the governor's council on cybersecurity, talks about NCC, the National Cybersecurity Center.

And I did pull out one, one really surprising to me fact about NCC from last year. This article says that the NCC's Cyber for State Leaders program, where they go and teach state leaders how to, how to protect against cyberattacks, trained more than 1,000 elected leaders across the country last year. That's pretty cool. It's pretty awesome. Yeah.

I mean, I think that is definitely a net positive, trying getting that education out to people that are making the laws in our states. So congrats to them. That seems like really good stuff. Speaking of elected officials doing things, we have an article here that shows that Colorado's Attorney General, or the Attorney General's office at least, has issued data security guidance. And it's really kind of to provide some framework around the consumer— oh, sorry, the Colorado Privacy Act.

Colorado Privacy Act. Yep. You know how I know that, Robb? Last Friday, Michael, I, I spoke on a panel with the, some folks from the Attorney General's Office about the Colorado Privacy Act. So maybe you can speak for them here then.

Shortly, shortly after that, they released this guidance. It's funny, one of the things that they talk about in here is this is guidance for doing reasonable cybersecurity, which is one of the things that is in the private Colorado Privacy Act and some of the other things. And frankly, in a lot of legislation, they want you to do reasonable security. But what is reasonable? But what is reasonable?

And so that's what this publication is. It, it tells you what reasonable reasonable is. And there are some similar— so in the panel discussion that I had, the question for me was, what is reasonable? And I gave some similar answers to this. They were writing it down as you did it.

Not to say that, you know, they took that and then released this right after. I mean, they did release this right after the panel, but I have to believe that they probably already had this made up before that. So most of this seems pretty self-explanatory and pretty obvious for a security professional, you know, developing a written security policy, managing your vendor security, um, having an incident response process. Those are, those are all pretty obvious. I'll tell you the number one one on the list though makes me, makes me scratch my head because I suspect that a lot of mature security programs are not very good at this.

It's, uh, inventorying the types of data collected and establishing a system for how to store and manage that data. That's the hard part, right? It is like really inventorying what you've got. Keep in mind though that this is related to the Colorado Privacy Act, um, which is, you know, very similar to a GDPR or something like that, which, you know, one of the main tenets of that is knowing the data that you have and who you share it with. So it's not surprising to me that that's number one.

It is, it's, it, it is the big difference between privacy and security, I think, right? Like security is, there's still a lot of, um, protect all this stuff, right? I don't even know what it is. Doesn't matter what it is, just protect it. It's like the castle and the, you know, the moat idea, right?

And, and privacy is like, no, no, no, we're We need to know, right? Like specifically what you've got. So it's a really big improvement. Yeah, it is good stuff. And, uh, the Colorado Privacy Act is pretty cool and gonna be enforced here pretty soon.

Speaking of laws, we have another— we had a lot of lawyers this time. Uh, this time we have, we have a, an article from the ByteBack log from David Stauss, um, about how does the CPRA, which is the California— ooh, something privacy, Privacy Rights Act. Update of the CCPA, which was their original Privacy Act. Then they have the Colorado Privacy Act and the Virginia Privacy Act. And they ask me, how do these 3 laws each treat biometrics differently?

And I'll tell you, I actually found this super interesting. Yeah, I think one of the interesting things here is that the Colorado Privacy Act, for example, does not define what biometric data actually is. You can make some inferences from a different Colorado law. But even then, it, it doesn't really necessarily make sense for this. So, you know, one of the conjectures here is that, well, as part of the Colorado Privacy Act, the Attorney General's Office has to do a bit of rulemaking, right?

So the, the law itself is pretty broad, and then the AG's Office can interpret and make rules around it. The hope is that they— one of the things that they do is define things like what biometric data is, although there is no indication at this point that they will do it on that particular point. Yeah, other big points is how, how you need to get consent, for what uses you have to have consent, and what kind of consent counts. There is an idea in here which I don't know if you'd ever read before that I didn't recognize called dark patterns. Yes.

So it's basically the idea that we're gonna make it so painful for you not to accept that you'll just accept it by default. And the Colorado law specifically says that doesn't count as consent if you're, if you're making it so painful to not, not to not accept it, right? You have a giant button that says yes, allow cookies, and one that is a small link underneath it that you can barely see that says no, or anything that's really trying to manipulate you into, into saying yes. Yeah, and, and that's pretty cool. And that, um, dark patterns seems to be a, uh, a trending topic in privacy, so it's cool that it made it into the of the Colorado law.

Yeah. So anyway, good stuff. Appreciate the, the article and the summary from, from David and company over there. Yeah. And David Stauss was also on that panel with me at the AG's office.

I don't know if that was recorded, but there was actually not just our panel, but there were a couple other panels that were really good. So if that is recorded, it would be— so there's actually some good stuff there too. There are us and some good stuff. Yes, exactly. Hey, let's move along.

There is a press release from Ping Identity, who, you know, I'm— I hold pretty near and dear. Ping has launched a new product called PingOne DaVinci. Yeah, and this is a no-code identity orchestration service. I feel like there were— maybe there was an announcement prior about this talking about that they were maybe going to be doing something like this, and now we've got the actual product. But it's sort of, uh, uh, you know, ready-made integration kind of things as opposed to you having to code an integration between something.

Yeah, you, you remember right, last year After I left, they acquired a company called SingularKey, and that company is, is really what they've been integrating for the last, what, like 6, 9 months, whatever it's been, to give them this. And, and it looks like, it looks amazing, the ability for you to drag and drop what your integrations and your, what your, your user workflow will look like, especially from a customer workflow perspective. And I guess from a no-code perspective, drag and drop what it looks like and it'll do the integrations for you on the backend with all your different SaaS apps. And all your, your, your ping identity systems. It looks pretty powerful.

But my real question, Robb, is can you manipulate these in VR? Are you thinking like Minority Report right now? Yeah, that's where you are. Like, I mean, maybe if we, uh, next, next phase in this. You know, it's interesting because, uh, you know, we were just talking about Scott Chasin and how Scott's got, got a job over at, um, at Pax 8.

He said he's now the CTO over at Pax 8. Scott Chasin at ProtectWise, they created the first VR security operations headset. Maybe we can marry these 2 things together. As far as I'm aware, the first and only. I think that might be true.

All right, moving on. We have a letter here written from the CEO at the National Cybersecurity Center at the end of 2021 talking about their year in review and what's coming up for 2022. I will say this was a very informative letter. Um, and by informative, I mean that there were a couple points that he made, and, uh, seems like there was some stuff that happened in, uh, 2021. Yeah, you know, I think that one of the challenges we have, Alex, as we're not, you know, we're on the, what we call it, the private side, and this is, they're really focused on public sector, yeah, impact.

And so we don't see a ton of what they're, what they're doing. Um, I, I do think though that They are, they are making a lot of growth and investment over there, which they didn't for the first couple of years. Right. So it's pretty cool to see the progress that they're making in the areas that they've been focusing on. Yeah.

I mean, and one of the things we already talked about, and that's that there were over 1,300 state and local leaders that were trained in their Cybersecurity for State Leaders program. Other things we didn't talk about, the Space ISAC is managed by NCC, which is pretty cool. I mean, I think by and large, the space sector is, you know, pretty small compared to a lot of other things, but it's an important sector. Yeah. So it's cool that they do have their own ISAC.

They got a K through 12 initiative, the Student Alliance. And we've talked about this one here, the Adult Cyber Education Program, all just helping to work on this cybersecurity workforce shortage problem. Yeah, great stuff. And I'm glad that good things are coming out of the NCC down in the Springs. All right, finally, just a real quick one.

You know, we see these articles about the 40 Under 40, which for some reason I was not picked for again. But why is that, Robb? Huh? It must be some kind of bias in the judging. I think it's bias in the criteria.

Yeah, it might be. But, you know, generally I see these and I'm like, oh, yet another article where I don't know anyone. But this time, We got a member of our community who is, who is recognized as one of the 40 Under 40. Yeah, pretty cool. Glad to see that we have people showing up on these lists whenever they come out.

I always look at these lists to see if there's anyone from any company that I know, and rarely does that actually happen. Do I get to say the name? Jeremy Capel. So Jeremy, who was the director of security operations, I think, for already under already over at Dish and is now recently become the CISO at Everbridge, right? Yes.

So, Jeremy, congratulations. Jeremy, who has the best South African accent in the Denver security community, as far as I'm concerned. Congratulations to you. And we're glad to see you get recognized. That's only because Greg Arnold isn't here anymore, right?

Otherwise, it would be a competition. Right. Fair enough. Yeah. Robb, what I want to know is, what if I identify as under 40?

Um, well, did the people who do the, the, uh, judging identify you as under 40? No, probably not. Hey, uh, that's it for the news. Before we jump over to talk about events, let's just real quickly, uh, give a big shout out to our friend Andre Gaeta, who has been such a great supporter of the show over the last 5 years. You know, we, as we were thinking about what should we do during this show to recognize the 5 years in, it's, it's really about, you know, appreciating him as, as a regular contributor to what we do.

Yeah. And when we started the show, you know, he volunteered to, to essentially to do whatever we wanted to, you know, do giveaways to, you know, incentivize people to listen to the show and other things like that. You know, most recently, we've been doing Slack Message of the Week. I think we've gotten to the point now where we don't need to incentivize people to join the Slack workspace anymore. So we haven't been doing that as well as we're lazy and don't want to pick out a Slack message of the week every time.

But nonetheless, Andre has supported us and he continues to support us and without question and, you know, his own money. You know, this is not his employer sponsoring us. It's him out of his own pocket doing all these things. So great thanks to Andre. Yeah.

Anyone who doesn't know Andre, you should get to know him. He's a great guy. He lives up in Erie and he'd probably go get a, go get a coffee with you if you asked. Maybe even a beer. All right, let's jump over into our events.

We do have an event calendar. I spent way too much time today getting it updated, so there is a lot of stuff going out here for the next first half of the year. But today, let's talk about what's happening in February. Yeah, so ASUS is doing their Women in Security Coffee Chat with Cami Dukes on the 10th of February. On the 11th, the Let's Talk Software Security group is doing a Log4Shell Lessons Learned.

That actually sounds really interesting. I'm going to have to check that one out. On the 15th, we actually have 3 events. CSA Denver is doing their February chapter meeting, The Last Mile Challenge: The Missing Control of the Enterprise. I have no idea what that means.

The web browser. Oh, interesting. I'm just going to go ahead and drop it right now. It's the web browser. Okay, good to know.

Also on the 15th, ISSA Colorado Springs is doing their February meeting. And ACES is also doing a young professional happy hour with Vinnie Winslowitz. On the 16th, we have 2 events. The Denver and Boulder chapters of OWASP are getting together for their February meeting. And also the 16th, DENSEC is getting back together.

It's been a little while since they've met. They're going to be getting together at Improper City at 7 PM. I bet you, you could go to the OWASP meeting, and then you could shoot over there and they'd probably still be there drinking some beers. That's probably true. On the 17th, Denver ISACA is doing their February meeting, Trends and Future Direction in SOD and User Access Management.

Segregation of duties. Yes. No, I thought it was sod, like grass. Oh, yeah. Yeah.

Turf management. On the 19th, ISSA Colorado Springs has their February mini seminar. Those are their Saturday morning, go get a few hours of CPEs in. On the 23rd, Colorado Equals Security Book Club is meeting. They're going to be reviewing This Is How They Tell Me the World Ends.

Pretty, pretty scary stuff. Yes. Also on the 23rd, ISC2 Pikes Peak has their February meeting. And finally, ACES on the 28th is doing Drug Trends in Your Community. Clearly, this is a how-to.

I am curious which drugs are most popular in my community. So maybe I'll Maybe I'll find this out. All right, let's jump over to jobs. Interesting selection of jobs you found this week, Alex, starting off with The Broadmoor, which is looking to hire a security engineer for information systems. Yeah, down there in Colorado Springs.

If you have any questions, happy to help you out on that one. Billtrust is looking for a senior Splunk enterprise security engineer. EchoStar is hiring a security analyst, and I think you mentioned they have like 30 other open positions there. Well, so this is actually EchoStar, not Dish. Sorry.

Excuse me. But Dish does have about 80 bazillion posts out there. So if you need a job, Dish is hiring. Arapahoe County is looking for cyber— a cybersecurity program manager. Slack is hiring a senior software security engineer, triage and incident management.

Torumo BCT is looking for a principal cyber and product security engineer. It's like a fun job. Mandiant is hiring a principal penetration tester on the red team, somewhere focused in the western United States. IBM is looking for a SOC analyst. I put this one because it is near and dear to my heart because my first job in security was a SOC analyst at IBM.

So be careful, you might follow in those footsteps. You might end up like me. Be careful. And then finally, Kaiser Permanente is hiring an undergraduate intern. Yeah, that's pretty cool.

Apply right now. I think we're probably going to see a lot more of those intern opportunities start to pop up. All right, well, that is, that is it for news. Anything you want to say? You know, we're, we're tight.

Oh, we didn't even talk about the interview. We have an interview. We do have news. So let's talk about interview first. Sure.

We sat down with our very first guest. So it wasn't 5 years ago this week. The first week, if you remember, we kind of interviewed each other like, what are we doing here? What's the point of this podcast? I can't remember last week, Robb.

You're expecting me to remember 5 years ago? I remember the first one. And but our first guest, though, was Drew Labbo, who was the CISO for Denver Health. And we said, You know, why don't we get Drew back on to celebrate our 5th anniversary and see how Denver Health's going? Yeah, uh, we didn't find out about Denver Health because Drew is no longer there, strangely, after 5 years.

For like 3 years he's been gone. Yeah, um, but we did talk to him about what he's up to now, and, uh, if you want to hear about that, you're gonna have to stay for a little bit longer and listen to the interview. And then, you know, you know, it's coming to a close on 5 years. I, I think that if you'd asked us in 2017, what we thought about how long this is going to last, we would have said, I don't know, a year, year and a half. You know, now that we're— now that we're 5 years in, I think we can say it's been a pretty good ride.

It has been a pretty good ride. I know it's been educational for me. And, you know, at some points it's been weird when, you know, a random person comes up to you and says, I don't know you, but I really recognize your voice because I listen to you every week. 'Cause I eavesdrop on all of your phone calls. Well, that too.

There's that too. It is interesting and it's fun. You know, I'll tell you, there is, I think maybe in some ways I would have expected like, hey, if we're gonna be around for 5 years, we're gonna grow up to something huge. But, you know, we've chosen to focus on this community and man, I would say that the community 5 years later is stronger, it's more connected than it's ever been before, and really gives us a chance to get to meet a lot of cool people. It sure does.

I think a little bit of that is due to us. Obviously, the community is bigger than us, but I think we've helped play a part in that, and that feels good. Yeah, it's pretty awesome. All right, Alex, looking forward to— I don't know if it'll be another 5 years or another 5 weeks. We'll figure it out, but looking forward to seeing next chapter with you.

Sounds good. Thanks, Robb. All right, let's jump it over to the interview. Hi, this is Chris Ard, CISO with Newmont Corporation. This is Colorado Equals Secure.

For Colorado security professionals by Colorado security professionals.

All right, so this is a special guest interview with a— this is our 5th anniversary guest interview. And Alex, as you and I were talking about this, we thought, you know, it would be fun, let's go back to talk to our very first guest on the show. Yeah, when we did that first interview, we actually, we recorded at my house. It was a— and I think the mics that we had, we use mostly now, but it was a sort of a pre-setup and Recorded in one of my son's bedrooms. I remember we had to move stuff around and put a card table and some chairs in there.

It was good times. But the guest that we had was Drew Labbo. And so Drew Labbo is here. Hey guys, thanks for having me. Drew, excited to be back.

It's awesome. I, I know we've, we've obviously, we've stayed in touch over the years, but, but, you know, you've, you've changed and, uh, what you've been doing. And let's just give a real quick recap for folks who don't want to go 5 years in the past to see to see what's going on. Like, what were you doing 5 years ago and like maybe a couple of things before that? Sure.

So, um, 5 years ago I was the Chief Information Security Officer at Denver Health. I had been running a consulting firm all on the up and up, above board, went through the conflict of interest process since 2014. Before that, I was the Director of Information Security at Children's Hospital Colorado. Before that, I always say, don't laugh, I was a sales engineer for Computer Associates. Sorry, Computer Associates, um, for 6 years.

Lots of travel selling security software. So, um, so yeah, and I've been running my own business full-time since 2017. Does it— did Broadcom buy CA at some point? Is that true? That sounds right.

I don't think they're a real thing anymore. I think they're now— I mean, they're probably still a business unit within, right? I think they're still a brand, right? I don't know that they're a standalone company. Yeah, and it was great working for them at the time.

Yeah, so when we had you on the show, you know, I think you gave some, some of your thoughts about being CISO at Denver Health. And, and, you know, you and I have had lots of conversations over the years about consulting and like the, the pros and cons of it. And I'm super interested to hear today about how you went from, you know, hey, full-time CISO with a little bit of side consulting to being like, hey, it's time to make a decision, and what that transition looked like. And let's just start about talking about the that as you're kind of changing between the two, what that looked like for you. Yeah, so it was a— it was pretty funny.

My, my wife pulled me aside and said, hey, you can either consult or you can work at Denver Health. You're going to pick one. Because I was working 70, 80 hours a week. Money was great, right? Um, and I had to stay on— Denver Health was the number one priority as a CISO.

But so at nights, weekends, I would— or personal time off, I was running my business. It was getting really busy. Not busy enough to jump ship full-time, but when the wife said you're gonna pick one, right, it was kind of that, you know, push comes to shove, do-or-die time. Yeah, so made the plunge. It was really scary, but I had enough business rolling and my website was getting traction with, you know, people finding my website, getting referrals.

So jumped ship, and it was a little bit scary, but I immediately just felt like a weight was lifted off of Not because I didn't like Denver Health, but just be my own boss. No more commute. Work out of the home office, pick who I want to work with. I've actually deferred some clients because it wasn't the right fit. Yeah, I've had a couple of clients that just was a personality conflict and I'll just leave it at that and just said, I'm not— we're not going to work together.

Life's too short. That's pretty rare. Most time I work with anyone that wants to work together. I've had a couple of people that were just combative. Yeah, it's nice to have that.

Like you said, as your own boss, having that flexibility, right? Yes. So we've talked a little bit about where you came from. What's the new business you started and what do you, what do you focus on? So the business is called RMHG, which stands for Rocky Mountain Hippo Guru.

I would say 90% of people love that name, 10% say guru, what is that? What are you, a hippie or something? Like, what does that mean? But you do have a long beard. That's right.

Yeah, I've got the mountain man thing going right now for ski season. Um, but yeah, I focus primarily on consulting around HIPAA security compliance, risk analysis, disaster recovery planning, business impact analysis, really everything in that HIPAA world. It's interesting, I started in healthcare, but I've got so many clients outside of healthcare— power companies, financial services, marketing— just gone way outside of just healthcare. So although that's my core competency, it's really translated into other verticals. So just to be sure I understand that, you are doing non-HIPAA-related things with those other companies, not HIPAA for companies that are not directly healthcare companies?

That's correct. There's a little bit of HIPAA for companies that aren't necessarily healthcare. They provide technology for healthcare, but it's been a pleasant surprise. People will get a referral and they'll say, hey, I'm not in healthcare, but can you help me like with NIST compliance as an example, NIST frameworks? Done some DFARS stuff like NIST 800-171.

You guys probably know, right? That's for organizations that do business with the government or government agencies or military or NASA. They have to follow this framework. Definitely crazy busy in a good way. One mistake I made was trying to take on too much business at once.

Everybody will tell you, I have to have a project done right now or the next week or 2. So I would— or they would say, I can't do business with you, I'm in a hurry. So I would say yes, you know, working 100 hours a week to keep up with it. And I finally— I had— it's funny now, people will say, potential clients will say, uh, I need to start within 2 weeks. And I'll say, well, I can't work with you then, it's 6 weeks out.

And they say, okay, right, right. So it's always, it's always urgent, but yeah, is it really, right? Yeah. But I do appreciate they, they can't sleep at night, they want to get it done and get secure, so Well, I assume as a new full-time business owner too, you're probably like, oh, I need to bring in as much business as I can because I don't know when this is going to dry up. I need to make my money.

So if everyone's coming in and saying, hey, I want to do this now, you're like, okay, let's do all of it. I'm going to take all this in. That's exactly right. And I finally realized that within reason, people can wait. And of course they want— if you're going to say, yes, I can do it now, they'll they'll say, great, let's do it now.

But that was a lesson I learned is don't take on too much. The other thing I've learned is it's feast or famine. And I've talked to other people that own consulting businesses and I'm either too busy or don't have much going on, which is a little weird. And when I get into the doldrums, when there's not those tailwinds to keep me going revenue-wise, I used to get worried and I'd talk to my wife about it like, you know, start saying prayers, I need projects, right? And she said, Drew, you do this all the time.

Once you relax, and it always comes around. So now I just go skiing a lot during— like, if I have a couple weeks with no work, I take advantage of it and don't worry about it. That's awesome. And it always comes back around. Start buying the one-ply toilet paper now.

Exactly right. And the generic beer. That's right. I think it's cheaper just to separate the plies of the two-ply. It's probably true.

Whichever, you know. So, so Drew, I know a lot of folks that kind of debate the idea of going and starting their own business. I've talked to a ton of security leaders who, you know, want to be their own boss. You know, what's the highest highs? What's the best parts of it?

And then I'll ask you later, like, what's the worst parts of it too? So the— my favorite part is the kind of the business development piece. So I have a kind of a— I call it the dog and pony show where I educate people about HIPAA and cybersecurity and why it's important. If they're potentially interested in getting a project. And it's— I don't want to call it sales, but it's taking a warm lead and kind of getting it over the finish line.

And that's my favorite thing to do, is talk to potential new clients, educate them, really speaking their language so they understand why cybersecurity is important. Not just HIPAA security, right, but cybersecurity. Explaining why things— why controls are important is really fun to me. Because I can say HIPAA says to do this, but if I can say here's 10 real-world stories of what happens if you don't do this, right, that I've really seen happen personally, really gets people's attention. Yeah.

The part that I struggle with in particular— I also do some hourly consulting for clients I've already done assessments with, and one thing that's really irking me these days, if you look at third-party risk management, A lot of organizations, especially in healthcare, where they'll kind of outsource that. They'll say, fill out an online security questionnaire, right? And it's not one size fits all, but they want to make it one size fits all. So a lot of my clients are smaller startups and they might have 2 employees and 5 contract developers. Great technology, great vision, but do they need to be SOC 2 compliant as a small company if they don't have their own data center?

Do they need to be HITRUST compliant? So One thing that irks me is I'll have clients with great technology and they're filling out— I'm helping them fill out this security survey and they'll say, for instance, do you have a next-gen firewall with IPS? I'm thinking, in their house?

What are we talking about here? As I'm talking to a security analyst, if I can speak to a human that's a critical thinker that's experienced enough, they'll say, thank you for explaining that. We're going to take that off the table. I've had some junior— no offense to junior security people because we've all been there, So yeah, our requirement is you have to have next-gen firewall with IPS or we can't approve you from a security standpoint. And I have to tell my client, do you want to spend $200,000 to put a next-gen firewall in your house that's not going to protect anything just to check the box?

Or buy a Barracuda, man. Right, exactly. Go get a SonicWall. Exactly. So I think for me that third-party risk management is tough because It's, again, it's not one size fits all.

And you have these really innovative smaller companies that can't, you know, they can't comply with HITRUST because what are they— is someone going to come to their house and assess the physical security of their house, right? Or think about segregation of duties as a control. If you have 2 staff members, right, we're going to hire 10 people so you can implement segregation of duties. So I'll get off the soapbox. That's a great example of one that's just almost impossible at a small company.

Yeah, but I do find if I can speak to someone that's been around in security long enough in that type of situation, if they're managing that third-party risk, if we can really explain we have a small, great technology, but a small company with a limited attack surface, can you make us not jump through all these hoops that aren't necessary? I've actually had more and more I'm seeing, especially big health systems, they'll say these are our requirements. You have to be SOC 2 compliant and you have to be HITRUST compliant or we can't do business with you, and there's no business. My clients just have to say, we can't do this. I had one situation, I'm obviously fired up about this.

They said you have to have a SOC 2 certification. They have their technology hosted in a data center that has a SOC 2 certification and we provided that and they said, no, you also have to have one. Yeah, you know, I talked to them and said, we, we produce one, right, for the attack surface that you should care about. And they just said, nope, you have to go get a SOC 2. So yeah, anyway, little companies have— it's just basically enterprises are pricing them out, right?

Yes. Yeah. Yeah. I mean, and it's a hard problem too. When I was at Kaiser, you know, we had 2 entire departments that their job was to do vendor risk management.

You know, I don't know, it was probably 50 people and contractors like, you know, outsourced to. And I'm sure even then they were doing things like you have to have this and this and this because they needed to cull down the amount of work that they had to do.

It's just one of those problems in general that is not easily solved or not well solved on either side, on the enterprise side or on the small business side or whatever it is. I agree. And when I worked at Children's and Denver Health, I had my hat on that I have to defend the hospital, right, and keep it safe. And I'm eating my words now. I remember saying, maybe you're too small to do business with us, right?

And now when I hear that directed at me and my clients, you know, not me but my clients, I'm thinking, well, I guess it's a little comeuppance because I, you know, I used to say that, right? If you're not, if you're not big enough to get certified in HITRUST, maybe we're not going to do business with you. Well, yeah, now I'm seeing the other side of that, and it's, it's pretty frustrating. It's, it's just so hard. I mean, it's, it's a really intractable, intractable problem where, you know, you want to do vendor risk management at any kind of scale, you just can't spend that much time talking to the vendors, right?

Yep. And on the, on the enterprise side, like, yeah, I'm going to send you a questionnaire and it's going to triage for me, and then we'll, we'll get into some more depth, but Like, if you're not big enough to have a SOC 2, what am I gonna do, like, go fly out to your house and look at your stuff? Like, it's just a really hard problem. It really is. And I think you just nailed it.

It's all about scalability, right? It's— we have our roadblocks. If you can't get past them, we just don't even want to talk to you or look at you, right? Yeah, potential business partner. It's funny, I've, I've seen some executives trump security, which I hate, but I like it for my clients.

But I've had a security team say, one of the executives yelled at us and said, we're going to approve this, so we're approving it, even though we don't want to. In my mind, I know my client's attack surface and it's managed. They worked with me. They've got controls in place, so it's not really taking on a lot of risk, but I also feel bad for a security person trying to do their job saying, yeah, you just got smacked, right? You're going to approve this.

It's a tough problem. Yeah, and like you said, Alex, it's on both sides, right? It's a— there's some tension there. So, so let's get a little bit back to your, your growth as a company. You know, you started as just yourself.

Have you thought about growing? Have you grown at all? What does that look like? So consulting in my space is, is odd. I mentioned it's feast or famine.

Um, I don't have a sales team. I'm not, I'm not actively out doing sales. It's more my website generates leads, referrals, repeat business, which is, which is great. It's kind of a sweet spot. I hired a couple people over the years and it got to where they weren't doing anything because I hit a lull and I finally hit a point where I had to say it.

And when I say hire, I meant it was contract. Yeah. So I had someone on for 6 weeks. Great. We did work for 6 weeks and then there were 6 weeks of nothing.

And he said, hey, I love working with you, but I, I haven't worked in 6 weeks, right? Like, I can't do this. So the— I've tried to scale up and I just keep coming back to I'm at a good spot doing— making a lot more than I ever made working for somebody. Yeah, like double, um, for my last job typically on a good year. So $20 or so?

$25, $25. Um, so it— I'm kind of in a sweet spot where I'm not growing Um, in a good way. I can manage it. I do have contractors I bring in to do niche projects. Yeah, like technical testing or repeatable things, repeatable assessments for hospitals, things like that.

But then when they're not busy working with me, they can do other things, which is nice. Yeah, that's great. I hired an admin for a while that I could keep busy some of the time but not all the time. So I keep coming full circle to I'm a one-man shop with contractors to bring in when I, when I need them. And, and I like that.

I don't like adult babysitting at my age. Um, yeah, I, I brought someone in one time that I just had to manage so much I was almost doing more work than it was worth. Um, on the flip side, I've had more than one potential opportunity to sell out because from the outside looking in, things look pretty good. And then when people look under the covers, like, so it's you, right? It's you and some contractors Um, what would we buy, right?

Yeah. Well, you buy the book of business and the customer base, the customer base and the market presence. Um, and I would like to sell off and ride off to the sunset one of these days. Yeah. But what's there to sell, right?

Yeah, I think, I think generally when— if you want to ride off into the sunset, it has to be after 3 years at the new place, right? Well, that's the other thing, there's the retention element of it. Yeah, there's like that 2, 2 to 3 year commitment. Um, burnout. I don't know if you remember Shark Tank.

There's this term that was coined quite a while ago. It was an acquisition. Acquisition. And they call it like acquire acquisition. Yeah.

It's, it's acquires. I don't know how you say that. Yeah. I thought it was like acquisition, like awkward acquisition. Oh no, I didn't hear that one.

Okay. And it's that a company wants to buy an individual. Like if an individual owns a company and they want, they don't necessarily want the company, they want the individual. Acquire. Maybe that's what it is.

Aqua Hire. Yeah, they're— it's like, well, we got to buy your company to bring you into workforce, right? And I think there's that potential exit one of these days, but I don't want to work for anybody, so, so that's tough, tough sell. Yeah. So, um, yeah, I've had several really good offers to just stop the business and go work somewhere.

Um, and I, I should say conversations. And I keep thinking, do I want to do that again, right? I mean, the steady paycheck's nice, but If I want to go ski on a powder day, I mean, you could build that into whatever the conversation is, right? I like the way you think. Yeah, like, hey, I really like this freedom.

Let me have this freedom. Yep. As long as you started the conversation that way at the beginning, I think it's not too bad. And it was funny, I did— I actually got a pretty decent offer 4 years ago, and I said, yeah, well, if you— if we do this, I'm working at home and I'm gonna make my own hours, and that was a showstopper pretty quick. Which, you know, and I get it, they're gonna offer me healthy 6 figures.

Yeah, my business, like, for me to say, yeah, I'll be available when I want to be, that's tough. Yeah, that's tough. So I keep coming full circle to do my own thing is great. Uh, and you guys have been around a while. At some point you've seen most of what there is to see out there, right?

It's rare to get surprised anymore. Um, to be able to answer technical questions. These days I'm quasi-technical, but I can get in the weeds if I need to. Having that experience is so fun and nice. I remember when I first started consulting or first started in my security career back in 1998, I was scared.

Do you guys remember those days? Not knowing what you don't know. Oh my God. I still don't know what I don't know, but yeah. Similarly, there's so much that Yeah, but at least we kind of know what we don't know, I think, at this point.

But I remember there were people that I would look at and they would have the answers to almost everything, and I would think, wow, how do you get there? And I realized, yeah, it takes 20 years experience, right? Exactly. Plus 24 years, I think, now. But having the answers at your fingertips, and you guys are like that.

I've talked to you around security. It's pretty fun, isn't it? Just to know so much. Yeah, it is, it is nice to not have quite so many surprises, not as many surprises as we used to have. That's a good way to put it.

And, and to your point, the projects I do are pretty repeatable and scalable, so it's kind of built in that I'm not going to see surprises. So I do have to recognize that. Um, I'll share one thing that, that frightens me, and I don't want to be mean to developers, but The fact that they don't know web application security or mobile application security ingrained in them, and I guess if they did, I wouldn't need to be here maybe, so maybe it's a good thing, but it's just terrifying to me that some of these developers that I talk with, brilliant developers, they built brilliant technology and they don't know the first thing about securing a web app, like threat modeling and code development. They generally know what penetration testing is, but not really. Sometimes they think a vulnerability scan is a pen test.

A lot of people have that problem. Right. And then we have web application firewalls. And it's funny, I have a developer saying, we already have a firewall, like a web application firewall, guys. I'm getting a little geeky here, but it just— I'm like, how are you a developer if you literally have no idea about security?

I mean, but they're there to build the thing, right? And make it work. And the whole fundamental problem is it's about use cases and, you know, can I make this thing do this thing? And as soon as it does this thing, you've achieved, right? It compiles and you successfully do whatever feature, and there's no one there to say, well, can, can I, can I use this thing to do that?

Make it not do these things, right? Yep. Misuse cases is a good way to look at it. And I want to be very respectful to developers because a lot of the developers I work with are, you know, a lot more than me and a lot smarter than me. But around security, it's just a little scary to see that lack of knowledge there, but again, that's why we're here, right?

That's why I'm here to consult.

Another funny thing I see, especially around HIPAA compliance, you'll have a visionary with a great idea to build a mobile app or a web app for digital health, and they'll say, I'm gonna do this HIPAA stuff myself.

Like, I'll say, here's what HIPAA looks like, and they'll say, thank you for educating me, I would do it myself. And I say, great. And they call back 6 months later, they haven't done anything, and they want some help. So everyone thinks they're gonna do it themselves, and then it's just, it's just a lot to learn a whole new discipline, right? It's a lot of reading to dive into HIPAA and become, you know, good enough to walk through all those requirements.

It is, and I think reading is one of the most underrated skills in cybersecurity. A lot of people, they don't— maybe they don't like to read. Maybe— I'm working with a client now. I do some vCISO stuff supporting clients, and I've— this one guy, he's a director of security. I won't say where he's at.

I'm not in Colorado, and he He just, he said he hates to read. Like he doesn't even read for fun. And how's this guy gonna read anything, right? How are you gonna get through a 200-page ISO standard or whatever? Yeah, exactly.

So I had a question for you, Drew. You know, looking back to where you were, well, man, when was it we went to lunch when I was at Pulte and you were at Children's and you were like, I think I'm gonna start this consulting. And Alex and I had just started our little side consulting business at the same time. And yep. And, and you were clearly more gung-ho, but, but you hadn't really kicked off yet.

I think it was like at the very beginning. I was very infancy of it. Yeah, like let's say, you know, you get to talk to someone who's at that point. They're like, hey, I think I want to do this thing. And now you're whatever it's been, 7, 8 years later, you know, looking back, what would you tell that, that person?

So you have to have an entrepreneurial spirit, and if you don't have it, it's gonna be really difficult to start your own business. Um, and to me what that looks like is an obsession. And it was funny, God bless my wife as a sounding board. She, she was happy and willing to talk to me about this stuff, but we take the dog for an hour walk and I talk for an hour about, hey, I was thinking I could do this for consulting, or I could offer this service. Yeah, she was a saint.

She supported me and, and, and she was okay with that. But I literally, at the beginning, it was like very passionate about it, and I still am, but it was, uh, it's all I could think about. Yeah. So I think, um, we actually have a friend that was thinking about starting a business, not in cybersecurity, but for, um, those like 360 inventories, personality assessments, and StrengthFinders. And yeah, we went to lunch and she, she said, hey, as a potential new business owner, I want to talk to you.

And I said, are you obsessed? And she said Yes, it's all I think about. In my mind, I thought, you're gonna be fine. Um, if you're not obsessed and you don't— aren't passionate about it, it's just not going to happen. That, that's what it looks like to me anyway.

Yeah, it's interesting, like, comparison, you know, comparing Alex and mine attempt at consulting and yours, right? Like, Alex, do you want to— what's your opinion on this? I was not obsessed. Yeah. Um, and yep, you know, I think wanted to test it out, see, okay, is this something we want to do?

And I, I think the work that we did when we did it was good work. It was good work. I remember working with you guys. But, uh, but it wasn't— I don't think either of us were obsessed with it. And, and so, you know, we were— we basically stopped doing it.

We— and we— but we came into it as, let's try this thing out, see how it goes. And we did. I'll tell you my, my perspective on it. And so similar because we were, we were all running security programs at the time. And, you know, moonlighting these projects.

And I got through it, and my perspective was, you know, it's, it's good. I actually like the work when I'm doing the work. What I didn't— and I actually didn't even mind business development. I just didn't like the context shifting between I'm gonna go work hard to land a deal and then spend, you know, whatever it is, weeks delivering for those people, and then I walk out and I I don't have any— there's no business, right? Like, I did— because I've been delivering, I, I did— I wasn't getting the business.

So do you, you know, time, time sharing between delivery and going— you do new business development? And I just didn't like that. I liked either one, but man, trying to go back and forth and, and really give my all to the thing that I'm already moonlighting to do, that was a really tough challenge for me to do both. Hey, that's, that's really astute, uh, astute comments. Because I do wear all the hats, right?

I do the business development. It's funny, I do some of the admin stuff because it's just so quick, like sending out an invoice. Yeah. Part of me is like, do I really need to be doing this? Should I hire someone to do it?

But I can just knock it out so fast. So I kind of run all the back office stuff as well. It's funny you mentioned that, do you like it or not? I took a month off for Christmas. I just had my project spread out where I took a month off.

And I remember that first day I was going to sit down at my desk, I thought— I was just like, ugh, I don't want to work. I just want to— I don't know if I want to retire yet, but I don't want to do this. But as soon as I got my head back in the game, I was like, I really like this. Yeah. And it was, it was a good confirmation for me that I'm doing the right thing here.

That's crazy. Because I really do enjoy it. And it, it's nice to help people get secure, right? I mean, if you think about it, and help people get to market. Isn't it so cool to get to like This is one thing I loved about our side, our business we did, was you get to know these, these, these business owners, these entrepreneurs.

And most of the people I worked with, they were smaller companies and, you know, just figuring it out. And like, how cool is it to see these great ideas they're creating? And like, I'm a little bit of a part of their success, right? A very little bit, but I get to be a little bit of a part of it. It's pretty cool.

It really is. Yeah. And it— we— I've had some clients that have brought technology to the marketplace and they were able to really get secure, not just check the box, but really got secure. They really took it seriously from a risk management and HIPAA compliance standpoint. And then their products are helping people.

Yeah, it's really neat to see like people with behavioral health issues or addiction issues and their technology platforms are changing their lives. It's really, really neat to see. That's awesome. Definitely fun.

And I think The— I think it's hard for some people too, doing the consulting thing, because they like to see things all the way through. And with, you know, a lot of times you're, you're doing a report for somebody, right? And when it's done, you hand it to them. Maybe you'll see them again sometime when they ask you to come back and reassess. Maybe that's the end of your relationship.

Yep. Uh, I think that part's hard for a lot of people too. You have to have the right personality and the kind of work that you like to do, I think, to be successful as well. For sure. Although, kind of an anecdotal survey of my clients that are dedicated security leaders, working somewhere big enough to be a dedicated security leader of a team, they all say, I really envy you, Drew, because you tell us what to fix and then you get to go home.

Then they have to deal with the nos and the barriers and the resistance. Whereas I, to your point, Alex, I'm just, here you go. And I do hourly support for clients, so I don't abandon them if they want help. I'm still around, but a lot of them will say, thanks for the report, we'll call you if we need you. Others will say, hey, can you join some conference calls to explain to our IT team?

Yeah, I need to implement this. And I do that at an hourly rate. But ultimately, to your point, it's a personality thing. I'm happy that ultimately I don't have to work there and argue with the executives, right? Yeah, I think there's a grass is always greener perspective.

Like, you know, you might, you might occasionally be like, man, I wish I got to be deeper. And some people will look at consultants and go, why is it that you have to pay a bunch of money for a consultant to say the thing I've been saying for years? And, and I think that in both cases, like, there's, there's positives and there's negatives to being in that position. There are. And I will say it's, um, I don't want to call it Jedi mind tricks, but I've been on the other side of this where in previous roles, a security professional is saying, here's what we need to do, and the management team wants to accept risk or they don't want to spend the money or they don't think it's real serious.

Then a consultant would come in and say the same thing and they would agree with them. Well, now I'm the consultant. It's funny, I've had clients say, you literally said the exact same thing I said, but they said yes to you. I guess that's the way it goes, right? It is the way it goes.

Um, which, which can be frustrating, but it is what it is, isn't it? Yeah, it's human nature, right? Like, people, people get used to the voices they hear all the time, and frankly, they, they want that employee to be wrong because they don't want to have to spend more money. And security's hard. They'd rather hear that we can get by with good enough, and then somebody else comes out with a, you know, a long list of degrees or, you know, a nice LinkedIn profile, and they say the same thing, and Now you got to believe them.

Yeah. I mean, I think some of the time too, it's that internal people are generalists. You know, they, they know security, but it's a lot of different parts of security. And, you know, they're maybe not a HIPAA expert or something like that. And then you come in and you are, you're a quote expert.

Right. And so your opinion weighs more to them. Yeah, I think so. And there's also the confidence that you speak with. I think people can see that.

And over my time in my career, when you, talks to them that really knows what they're talking about, they're very convincing. Just, it's even the tone of voice, right? And the, uh, just the look in their eyes. And I like to think I bring that to the table where they're like, well, he— I've heard people say, you really sound like you know what you're talking about. Social engineering, Drew, right there.

Exactly. That's exactly what that is. So, um, so yeah, back to your question, if someone wants to get in consulting, um, what What should they think about?

To try to build new technology and information security and to start a company like that is a whole different ballgame compared to what I do, right? So I'm gonna carve that out. You know, for consulting, obviously you have to know what you're gonna offer. You have to have a vision of how you're gonna articulate what you can offer and the value of it. You have to have the confidence to deliver.

But to me, it's about vision. I talk about my obsession. I could literally see what I wanted to do. I hadn't done it yet, right, when I first started to venture into consulting, but just clear as day, I could see this vision. Here's what it's gonna look like.

And that really got me there. And not necessarily goals, but just the vision. Like, I could literally see it. I'm like, I know exactly what I'm gonna do. And I strove toward that.

And if someone thinks, yeah, I think I might wanna do some cybersecurity consulting and I wanna get into it, but they don't know exactly what that vision looks like, That's tough as well. Yeah, I mean, it might be easier to start off working for somebody else, right? Go get a job at local consultancy, Coalfire or whatever. Yeah, get some, get some reps in the field to figure out what you really like. Yep, for sure.

Don't, don't break any non-competes if you do that, by the way. Well, you know what's funny? I'm glad you just— I'm glad you mentioned that. So I've had multiple people ask me, you know, how did you do this? And yeah, For— I've seen some people completely quit their job and try to consult from scratch.

And ideally you have a good job and you start doing it on the side, but you have to do it the right way, right? So I— when I was at Children's, I immediately went to my boss and said, here's what I'm thinking, here's what I want to do, are you even okay with this? And I was told yes, just go through the proper process. So I just kept it all squeaky clean above board. Yeah.

Um, literally never worked my consulting during business hours. Just, you know, really kept it clean. But that allowed me to just do a couple projects here and there while still getting the paycheck and the benefits, right? So if you can have a job and start something up on the side above board— we want to be really clear about that— then to me, that's the way to do it. Yeah, and I think, I think that's great.

And that's, you know, what we did as well. I think one of the, the problems that I know I saw, probably you too, Robb, It's hard to do the business development side if you have a full-time job that's taking your time during the day, because the people you're doing business development with, they want to meet when your, when your day job is happening, right? So it's like, oh well, I, you know, can I take an hour of vacation in the middle of the day so that I can take this call? Or, you know, how's that gonna work? That makes it hard.

It really does. And for me, I did a lot of had some East Coast potential clients, so I'd be up at 6 AM my time, 8 AM their time, before work. Lunch hours, my wife hated— I would literally take PTO off to do work. To your exact point. And yeah, I remember the first time I said I don't have enough time for a vacation because I've used it all on consulting.

She's like, all right, buddy, yeah, we're done with that. You're gonna pick one, right? And she said, like, if you want to stay a CISO at Denver Health, great. You want to consult, great, but you can't do both. I'm glad she did because I probably would have kept doing that for a long time, longer than I should have.

So glad you did too. Well, hey Drew, we're running shorter on time here. Anything else that we didn't get into yet you'd like to share with the community? So I've been pondering what's coming from a cyber risk standpoint and I'd love to talk to you guys about that real quick. I've been read— you read lots about quantum computing at some point breaking encryption algorithms.

Yeah, kind of geeky stuff, but pretty interesting stuff. Um, well, we always have human behavior that's never going to go away, right, as a risk. Um, just love to brainstorm with you guys real quickly in here, um, what you see coming. For me, the like social media platform risk, like misinformation.

Pretty scary, right? Artificial intelligence, machine learning security.

Yeah, I had a couple of thoughts. I think, you know, thinking about the biggest threats and what they're likely to do, you know, the different threats actors have different motivations. Like the people who are trying to make money on this thing, They've been making a lot of money on ransomware. I don't, you know, ransomware is not going away, but I think more creative ransoms is going to be a thing of the not too distant future where it's not about, I'm encrypting your machines or your volume in your cloud environment. It's more about, I now have control of this very important system of yours and I will cause you downtime And something worse than that, because I have sysadmin type control that I can exhibit in this way.

And I think those types of ransoms will be much harder for people to say, well, I got backups. Like, you, like, it's not what we're talking about now. We're talking about like the fundamental underpinnings of your most important thing are totally owned in a way that you're not gonna be able to get back in any reasonable amount of time. Okay, so how much is that worth to you? I think that's a big risk from the organized crime perspective.

And then I think that the government risks, what we're seeing with SolarWinds and other libraries recently that have been compromised. I think that the third party, the underpinnings that we've for years known, it's some guy who manages as his side project, but it underpins the entire internet. Dependencies are going to become more and more of a risk problem for us. And like, functionally, we as an industry are going to have to solve that because otherwise that's where, that's where nation states are going to attack, go after the weak parts. I can go get access to that open source project and go own, you know, millions of companies.

And the SolarWinds thing, I think our heads are all still spinning from that, right? Embedding a threat into a security update. Yeah. Wow. Yeah.

What do you do about that? Exactly. So yeah, I'm interested to see— I agree with what you guys have said. I, I'm interested to see what happens with the whole, uh, Russia-Ukraine situation that's going on, because, you know, there have been some warnings that have come out that said, hey, you know, if Russia does move forward with, uh, invading Ukraine or doing something like that, you know, be prepared for increased cyber attacks. How, how does the relationship between non-cyber things and, you know, add-on cyber things with that happen as well?

You know, are we going to see more and more bleedover of nation-state activity affecting, you know, day-to-day activities? And then, you know, does it even go beyond that, you know, attacking critical infrastructure and other things like that where all of a sudden, you know, these kinetic things now are happening because of cyber conflict? Yep. Agreed. It's a good thing we're here to help, right?

Yeah. I think that our industry is not going to go anywhere anytime soon. Yeah, job security and security, as they say. One last thing I'll say that's encouraging is working with the— I'm 51, right? So the younger generation, I have just found, and maybe it's a subset, but very bright, very hardworking, fun to work with.

I think the younger generation of security professionals has different expectations about work-life balance. Um, but it's funny, my, my wife has struggled a little bit working with— and I want to be respectful to the younger audience out there— um, she's had a couple of situations where she's seeing younger people she works with being overworked, and they don't know how to speak up and say, hey, this workload is not acceptable. And I, I was like that when I was younger. Um, so she was saying, you know, sometimes it's hard to work with people that are younger. And I— it's not unique to our generation.

I think there's always a generation gap, but For me, I've just found that I really enjoyed working with like the 20 and 30-somethings— smart, energetic, hardworking. Um, it's, it's just really neat to see. It gives me hope. Yeah, that there's good people coming up. That's awesome.

Gotta have hope. Yes. All right. Um, Drew, nothing else you wanted to make sure we got into? I probably bent everyone's ear enough, so I appreciate the opportunity to hang out with you guys and, and talk.

Awesome. Alex, close us out. Well, this has been Colorado Equal Security, and this is our special 5-year anniversary interview. Can you believe that? Can't believe it.

5 years. Didn't expect us to make it 5 years. I'm glad we made it 5 weeks anyway. And to close with a quote from my retired neighbor, life is like a roll of toilet paper. It gets a lot faster at the end.

Oh my gosh.

Awesome. Well, thanks everybody. Appreciate it, Drew. Good talking to you again. And this has been Colorado Equals Security.

We'll talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes