All episodes

Newscast

Apple Podcasts Spotify SoundCloud

News from Lightning eMotors, Twilio, Randori, StackHawk, Red Canary, Coalfire and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript4205 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 236. This is for the week of June 13th.

Alex, happy summer. The summer weather has come. It most certainly has. Robb, I was out driving today. My car said 102 degrees.

That sounds like summer to me. That sounds miserable to me. Yeah. Was it? But inside your car was, was cool.

I assume you kept it, kept the AC going. Yes. It was still not super cool. We were driving one of our older cars where the AC is not the best. But yes, we weren't sweating, but we weren't super comfortable either.

Yeah. 100 degrees. It's a little bit of work to keep the temperature there. I will say I'm a bit of a Scrooge when it comes to the thermostat in my house. And this week it did force me to turn my air conditioning on finally.

So yeah. So I also, a similar, I don't love to keep it on all the time. I did turn it on one night this week and then today, even like this morning, I'm like, it's gonna get hot today. Let's just get ahead of it. And enough of the silly weather talk.

I guess we can move on to something else. So Housekeeping, maybe? Housekeeping. We have some housekeeping to do. Robb, did you know we have a Slack channel?

Uh, I did know we have a Slack channel. I use it on the regular. As do I, uh, as well as several thousand folks that are in there. Uh, it's a great place for conversation. Check out the website colorado-security.com and you can request access there.

Uh, we also have a mailing list that you can sign up for on the website. You will get, uh, now one email a month with the show notes after we do this. That is all. Nothing else. We'd love it if you would tell a friend about the Colorado Equal Security Movement.

Obviously, we'd, uh, we want to grow and we want to make sure that the folks in Colorado know what's going on here and we can really just build as good a community here in town as possible. So tell a friend. And if you want to help support the show, we would love it if you'd look, consider signing up for our Patreon campaign. And a huge thank you to the current patrons we have who help pay for all of the expenses of what we do. Yeah, it's great.

We love them. And thank you very much. Okay, let's jump into the news. Robb, 7 Colorado sites make the list of the 150 best things to do in the US this summer. Yeah, this is pretty cool stuff.

In fact, there was a couple that made the top 10 in the top things to do in the US, including the Million Dollar Highway, which is a highway located between Ouray and Silverton, made second place on the list for its amazing scenery, historic stops, relaxing hot springs. Now that's the one that has like the crazy, like it's kind of scary road, right? Yeah, I think so. And they, I think they call it that because it costs so much to make way back in the day. A million-dollar road.

Can't imagine a road costing that much. It's, it's insane that you could spend a million dollars to build a road. Yeah. The other on the list, which sadly has already passed, is the, the Five Points Jazz Festival, which happened last weekend on June 4th. They have it at 6th place given the festival's host's generous Five Points Jazz Activation Grant program.

So very exciting there. So hopefully some of you out there got out to the Jazz Fest in Five Points. So those 2 made the top 10 on the list. But there is another one. I don't know what this is, and a whole bunch of other ones that made the list other places.

So Denver's Meow Wolf, Pagosa Springs, Leadville, the 5430 Rooftop Great Sand Dunes National Park, Red Rocks Amphitheater, the Rocky Mountain Arsenal, the Mount Evans Scenic Byway, Estes Park, Mesa Verde National Park. And coming in at 136 on the list is The Source Hotel in Denver. Yeah, that one surprised me a bit. I was also a little surprised by the Rocky Mountain Arsenal. I know it's a wildlife area now as opposed to an actual arsenal, But anyway, good stuff.

Have some stuff to check out. Some other news here in the state. Governor Polis signed into law the law that would make daylight saving year-round here in Colorado if a couple of other caveats happen. Yes. So I think, you know, we've been in general hearing about the movement of people trying to eliminate the time change.

And there are a number of states now that have passed laws that say, they will go either on standard time or daylight savings time. But they all usually have caveats, like there have to be a certain amount of other states that do it, or there has to be federal legislation enacted or other things like that. For our particular law in Colorado, we say that there have to be, I believe, 4 other states that go to full daylight savings time all year round for us to also join in and do that. So 4 other states in the Mountain Time Zone? Correct.

So it's actually a relatively small number of states. I think it was like 8 or 9. There's already 3 who have signed this type of a compact. So they need one more. And then they also need the federal government to pass their kind of approval of this type of a move.

So the Senate's already passed it, it's sitting there in the House waiting to be passed. So, you know, it's possible this could happen soonish. If the federal government passes theirs, I think it would go relatively quickly. Yeah, I think it's— I think they said New Mexico and Idaho were 2 that could do it, and or Arizona, which is already on full-year Standard Time, could decide to go to full-year Daylight Savings Time, and then that would push us over the edge too. All right, good stuff.

Yeah, I look forward to the day when there are no more time changes. Colorado electric vehicle maker Lightning eMotors is partnering to offer autonomous passenger vans. Yeah, so this is pretty interesting. What Lightning does is they actually renovate, they don't, it looks to me like they don't actually start from scratch. They buy chassis for vehicles from other auto manufacturers and turn those into electric vehicles.

Well, they're now gonna be working with this other company. Is it Perrone? Perrone? Yeah. Call it Perrone Robotics.

That Perrone actually goes and retrofits other vehicles to become autonomous. They're not making their own. So the 2 of them combined can basically make a vehicle both electric and autonomous. And the intention here is that these would be used for like shuttles around a campus. You know, you could imagine at a campus, or excuse me, like a college campus or an airport or something, um, that there'd be a lot of value to that.

Yeah, um, it's pretty cool. Uh, Lightning eMotors reminds me a little bit of like a conversion van company, right? You know, you're taking something that already exists and, uh, making it better, in this case making it electric. And, uh, I think it's pretty cool to see this happen, and I look forward to being on, on driverless passenger vans sometime in the future. In the article, it did say, however, that for many of the instances, Prony recommends that they— you still have an employee in the van for instances where you get stuck.

Essentially, it definitely seems like it's limited right now. If having to have a person in there to jump in to drive takes away the vast majority of the value in my mind. Yeah. The example they gave is you know, they had a demo and there was a car, a van parked in the traffic lane, like you might imagine on a road where someone just pulls over to, I'm gonna go quickly inside the store and like double park there. When the autonomous vehicle came in behind it, it just stopped, right?

It wasn't going to go veer into the wrong side of the road to get around this thing, which a human would probably do. Yeah. All right, moving on. Twilio, which if you remember acquired SendGrid several years ago, Twilio is, going to be shedding some of their downtown office space as the company goes primarily remote. So this is in that 1801 California building, which was the old SendGrid headquarters.

They're getting rid of one of their— I think it's 2 floors. Yeah. So they're subleasing some of the space in there. I don't know if it said in the article who they were subleasing it to. But, you know, they've decided that they are going to be a remote-first company.

And so they'll still have space where, you know, in the office, you can go in and have meetings, customer visits, social events, things like that. But for the most part, people are going to be working remote. They decided to do this after doing a survey of their employees, and they found that 99% of workers didn't want to return to the office on a full-time basis. 99%. That's, that's a lot.

That's a pretty high percentage. A couple other stats in here I found interesting. They have 8,000 employees in the company worldwide, and about 650 of those are here in Denver. And I bet you most of those are SendGrid, ex-SendGrid types. Probably.

I think one of the other interesting things for me was that 72% of Twilio's workforce has been hired after COVID started. Yeah, crazy, the last 2 years. So almost none of them have even been into a Twilio office. Yeah, yeah, that's just nuts. And I imagine, you know, part of that's growth and part of that's the Great Resignation where they've been backfilling folks who've moved on, but 72% of their company in the last 2 years, just crazy.

Next, we have an article in the Colorado Sun by our favorite technology reporter, Tamara Chuang, talking about the cybersecurity professional shortage in Colorado and how things have been going. Yeah, you know, I'd say that this is— that's what the headline of this is. It feels to me like the article was actually not really about that. Yeah, it's really not, right? It was really just about the training here.

Oh, shoot. At Metro State. Yeah, Metro State's training program, which actually looks really cool. And I, you know, I didn't know as much about it before reading this. So it was, it was cool, but it's more like a commercial for Metro State's program.

Yes. Um, and as part of this, they interview Richard McNamara, who I am still planning to interview for the podcast, but still haven't gotten around to doing. Is that the interview we have this month? It is not the interview we have this month. Um, I actually, um, I have, uh, met him and I've been to their, uh, on their campus and seen their, uh, their security operations center there.

It, it is a pretty cool operation, but basically what they're talking about in here is the programs that are offered at Metro State, as well as, you know, some other places around Colorado and the designation that Metro State now has as an NSA Center of Excellence or whatever, the Training Center of Excellence. I forget what they call the actual acronym. But really, you know, they're talking here about where training and things like that stand in Colorado and the still lack of entry-level jobs for people that are coming out that want to get into cybersecurity and some of the things that are happening to help them get past that. Yeah, there's a couple of interesting— there's— you guys should take a look at the article. It's actually pretty long, but it does get into some interesting stats.

One interesting stat, they say this article says there are 29,000 total employed cybersecurity folks here in Colorado, 29,000. And that's a big number. It's probably bigger than I would have guessed. I think it's bigger than we've talked about in the past. But then the crazy thing is that they say there are 26,000 total open cybersecurity jobs.

Is that, is that possible that like almost like there's almost as many open jobs as there are filled jobs right now? I mean, that's nuts. That is nuts. I guess it's entirely possible. It depends on, I think it's one of those things where, you know, what counts as a security job too, right?

So, so I mean, if we all just took a second job, We could, we could, we could nip this thing in the bud. Problem solved. Uh, you know, but one of the things they do talk about in here also is the, uh, Activate Work, uh, apprenticeship program to try and get people that are potentially moving careers into, uh, security jobs, even if they don't have experience doing that. And, um, you know, I, I think that is still a big problem. You know, we're, we're training more and more people, but there are, a lot— the skills that we want aren't necessarily the entry-level folks.

There's a lot of, uh, a lot of positions out there that require more than, you know, essentially taking a boot camp to be able to get the job. Um, that was sort of highlighted by me in, uh, to me by some recent job posts that I had out where I got about 10 times as many people for an entry-level job versus an experienced person job. Yeah, it's definitely It is hard to find those experienced folks right now, and we got to make room to bring in the next generation for sure. So love it. All right.

Moving over to more security-focused news. We have a story this week where local security startup Randori has been acquired by a former employer of yours, right? Yeah. IBM has purchased Randori, and Randori is sort of a half, half Colorado company. They're half Colorado, half Boston, I believe.

But still, They're, uh, they are now part of the IBM family. They're a tech service management slash continuous testing company. And, um, as IBM moves some of their business more and more towards security and, you know, services and technology as opposed to computers, this, uh, this seems like a good fit for them. And hopefully it was a good exit for the Randori folks and they can continue to, uh, push their stuff forward under the IBM umbrella. Yeah.

Looking forward to hearing what's next for, you know, we have a couple of friends over there. Moose and Aaron Fosdick are both, you know, employees at Randori. And I'm curious what that's going to look like for them and, and what the next iteration of their mission is going to be. Awesome. And congrats.

All right. Next, the National Cybersecurity Center participated in a ribbon cutting at UCCS for the new cybersecurity building, which is now housing the newly formed Space ISAC. So the National Cybersecurity Center, one of the things that they do is that they run the Space ISAC. And, and there's now an official place for that in conjunction with UCCS. So some more stuff happening down there.

I think this is going to go toward them just creating more and more talent, right, to funnel into both the support for, you know, the Space ISAC and, and the industry around there, but also private companies that are, that are just in the Colorado Springs area. And more broadly, you know, obviously, they're They're working hard to find more and more ways to, to bring a focus of talent and, and needs into the Springs. And that's great stuff. Yep. Good for them.

All right. Uh, next, another local security company news. Uh, Stackhawk, uh, secured a $20.7 million Series B funding round. Uh, so congratulations to them. Yeah, this is— this brings up their total raises to about $35 million.

Um, they, they raised from— excuse me— Sapphire Ventures and is it Custon— Custon Noah? Sure. Probably Custon Noah, um, with Foundry Group. Those look like those are the lead investors for this. Nice.

Um, yeah, and, uh, there's not much detail in the article here, but the— they do say that Stackhawk will use this raise to accelerate product development and continue rapid growth. Um, hiring developers and salespeople. That'd be my guess. Yes, that's what it sounds like. That's what most salespeople— or excuse me, security companies, when they raise money, that's what they usually do.

Uh, salespeople, marketers, and developers. All right, speaking of local security companies, Red Canary, who I am pretty fond of, recently was recognized by Microsoft as a Security Trailblazer, winning an award this last week. So what does that actually mean, Robb? Um, well, the Basically, Microsoft looks at their partner ecosystem, and, you know, obviously, you know, we're— you and I think a lot about the security side, but Microsoft does a ton of stuff outside of security. So in their entire security— or excuse me, partner ecosystem, they're looking for partners in different areas who are helping drive things forward.

And so you'll get the one around like office productivity and digital transformation or whatever, but in the security space, they're looking for who's their security partner that's helping their customers, joint customers, of Microsoft and that partner, um, really drive their security program forward. And they saw, you know, Red Canary as one of the 2 finalists and then ended up being the winner to, to help Microsoft customers best improve their security. Who was the other finalist, Robb? You know, I don't remember off the top of my head. I was going to tell them to suck it, but that's, uh, you know, we won't do that.

Whoever you are. Yeah. Um, no, but that's awesome. Congratulations to Red Canary. And, uh, it just goes to show Uh, one, how far the Microsoft Defender product line has come that an MDR provider can use that to such great effect and, uh, and how great Red Canary is at doing that.

Yeah. I will say Microsoft has come a long way in terms of where they were a few years ago as more of a checkbox to doing much better for many of their security tools. Yep. Awesome. Uh, next we have a blog by Coalfire talking about a FedRAMP and the new supply chain security requirements that are in FedRAMP now?

Yeah, I'll tell you, there's some bullets at the top, and I feel like it's maybe a little misleading. On the one side, it's, hey, this is nothing new, you've had to do this in the past, right? The other side is, here's a whole bunch more focus, you need to get more serious about your third-party risk management. And so I'd almost just toss the whole, this is nothing new, and say it may have been required somewhere in the past, but FedRAMP is making it much more explicit now to say if you want to be a FedRAMP-compliant organization, you need to have a really well-understood mapping of the risks of your third parties and a really nice inventory of those third parties, along with a plan for how you work through the risk there. Yeah.

And to me, this is not even an article about FedRAMP. It's more about the Rev 5 updates to NIST 800-53. Good point. Which has these new supply chain security requirements in it, which then roll down to FedRAMP through DFARS and all that kind of stuff. So, so yeah, there's, I think, 12 Uh, 12 new requirements in 853 Rev 5 around supply chain security.

And so that's really what they're talking about here. Make sure you're doing those if you need to be FedRAMP compliant or 853 compliant in any way. Yep. Good stuff. Um, obviously if you, if you want to do business with any of those companies that need to be there, you probably need to get good at this as well because they, they, those, those expectations are going to roll down.

Yep. All right. Finally, uh, not an article, but maybe like a piece of news. The call for papers for the Cloud Security Alliance's Colorado Fall Summit. Um, the Fall Summit happens in October, but the call for papers is open today.

So if you've been thinking, man, I'd love to talk locally, I'd love to get together in person, this looks like a great opportunity. Awesome. Yeah, I'm looking forward to seeing that. We're also, uh, very soon here we should have registration open for the Rocky Mountain Information Security Conference, which is in September. So, um, we've got a lot of good stuff coming up.

All right, that's it for news. Let's jump over to events. Um, you know, as a reminder, we, we have a calendar of events on the website. We keep it up to date. You can go, go poke out what's going on there.

I got to add out several months worth of stuff as I was getting ready for the podcast this month. So take a look and see what's coming up. What, what do we have the next month, Alex? Uh, coming up, uh, on June 17th, we have the Let's Talk Software Security group, uh, talking about are bug bounty programs worth it? Well, I mean, it seems like a relatively simple yes or no question.

Why do they need to have a meeting about this? Well, it's a reason to drink beer, right? It's a reason to debate yes or no, right? Yes. No.

Drink beer. Yeah, drink beer. I think they're mostly virtual, so you'll be drinking alone. Virtually. On the 21st, the Cloud Security Alliance of Colorado has their June meeting.

On the 22nd, ISC² Pikes Peak is doing their June meeting. On the 24th, DC303 is getting together. That's usually a fun time to get together. Go make sure you sign up on their meetup page so you get any news about that before you show up. Awesome.

And that is all of the events for June. So let's jump over to jobs. Uh, Robb, I have one job that is open. I'm looking for a cloud security engineer to come join our team at Uplight. Did you close your entry-level position?

Uh, it's still technically open. Uh, if you want to apply, you can. However, I probably won't even get to you. There are so many people that have applied for that job that, um, at this point it would be rough to get, to get screened in. Awesome.

Awesome. Next, Spectrum is hiring a Director of Risk and Threat Management. Granicus is looking for a Senior Director of Governance, Risk, and Compliance. The Gates Corporation is hiring a Senior Manager of Cybersecurity Operations. Western Union is looking for an Information Security Engineer in Risk Assessment.

I was hoping I'd get this job. The United Launch Alliance is hiring a Chief Information Security Officer, Leader 6. Yes. I did the leader 6 thing. I, I, that's the part that I'm just kind of scratching my head.

I, I think that's probably like, you know, the government jobs where it's like information security, right? Engineer 5, right? Yeah. You know, to be a leader, you're gonna be at level 6. Yeah.

Square is looking for an embedded security engineer. That sounded cool. Kaiser Permanente is hiring a principal IT engineer on infrastructure security. UCAR, which is the University Corporation for Academic Research, is hiring a cybersecurity risk and compliance analyst. And finally, CoBank is hiring an information technology security architect.

Awesome. That sounds like fun. Well, that is it. And unfortunately, that is it because we don't have a feature interview to ship it off to this week. We do not.

Both Robb and I are slacking and Frank must be on vacation. Yeah, we're all slacking and enjoying the beautiful weather and hopefully we'll get one for you guys next month in July. Sounds good. Thanks for having everyone. Have a good one.

Learn more about the Colorado security scene at colorado-security.com. Security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes