All episodes

Happy New Years Newscast

Apple Podcasts Spotify SoundCloud

2023 is already here? This seems impossible. News from Casa Bonita, CommonSpirit, Red Canary, LogRhythm and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript6573 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 243. Alex, uh, we are in January of 2023.

That, that's a big number for a year, Robb. Um, I— it's hard to believe it is the biggest so far. You know, I think it'll probably stay the biggest until next year. Um, but you know, maybe that's just me. It's, uh, it, it's good to have a new year.

It was nice to have a little time off around the holidays. And yeah, you know, normally it seems like, you know, January starts off kind of slow. People are still getting back from work and, uh, takes a little while for things to kick in. But I don't know about for you, but for me it's been a little bit crazy. Uh, I mean, we're, we're definitely right back into it again.

I, I feel like 2022 just was like the shortest year ever. They, they're, you know, inflation making my money go less far, and, and, uh, apparently there's inflation of years too where they're just— they don't last as long as they used to. Yeah, I know, uh, I know you like eggs, Robb. You eat eggs for breakfast pretty often. And how's that affecting you?

There's a, you know, egg shortage and expensive eggs out there. Alex, you're not wrong. These, uh $10 per dozen eggs. Yeah, I'm just, I'm just stealing them from my neighbors though, so this is, uh, this has been no impact to me. Maybe you should get some chickens.

I should, I should get some chickens. I assume chickens are no more expensive. Now I know there's a number of reasons, but one of the reasons that egg prices have gone up is a lot of avian flu killing off a bunch of birds. Yes, that is one reason. A secondary reason in Colorado is that in January a new law kicked in that you're, uh, you're only allowed to sell cage-free eggs in Colorado.

So it's kind of a double whammy, uh, double whammy impacting our pocketbooks. This is, this is not a story, by the way, folks. We're just, uh, just off the cuff here talking about stuff. But eggs are important. The pratter part of the podcast before we get into the housekeeping.

That's right. Oh, housekeeping. Alex, did you know we have a Slack channel where we, uh, where we have like, I don't know, 74,000 of our closest friends? Uh, we do have a Slack channel and there are lots of people there. Speaking of Slack channels, um, you know, Robb, I started today to do a little maintenance on our Slack workspace.

We, we have proliferated— proliferated, it's a hard word there— the number of channels that we have. And so I started pruning back a few of them and, uh, not the people, but the— but just the channels, trying to get fewer channels to have more, more talk in fewer places. And, uh, I think, well, hopefully it'll be a good thing. Not that we don't like the, the topics of those other channels, but they can be had other places. So good stuff.

I, I appreciate that. And, you know, hopefully that drives even more great conversation. If you do want to join that conversation, go out to colorado-security.com, click on the Join Slack button, and we'll get you in there. And while you're out on the website, why don't you go ahead and sign up for our newsletter? If you do that, you'll get our, our show notes delivered into your inbox every week.

All those great stories that we're about to talk about, all the jobs, all the upcoming events, they're all in the newsletter. You know, if you like this podcast, and you must because you're listening to it, then wherever you got it from, you should probably rate us there, whether that's iTunes or Google Play Store or Spotify or some other place. And while you're at it, why don't you subscribe so it shows up automatically in your podcast player, and then you don't even have to worry about when the next podcast is coming out. It'll just be there and you can, you know, listen to it as it gets there. Also, it'd be great for you to tell somebody about Colorado Equal Security and send them to the website or have them listen to the podcast.

We— the more the merrier. Uh, we, we have, uh, we have a lot of folks in the movement, but we can always have more. You know, the mission here is we're looking to make Colorado the mecca for security here in the U.S. Uh, if anyone— if you know anyone who could be a part of that, whether helping bring more talent here, helping bring more visibility to the community, we'd love it. If you think, man, I've done all those things, is there any more I can do?

Yeah, we would love it if you'd financially help support the show. We have a Patreon campaign that pays all the very expensive hosting and email and I don't know what other things that are always associated with this podcast. If you go out to the website and click on Patreon, you can sign up. Speaking of that, Alex, we actually have a new patron.

Oh, we do? That's very exciting. Did you know that? I did not. Yeah, we have a new patron.

We like to call that out when it happens. Sam Volin is a new patron, a new supporter of the show. He works over at StackHawk. Caw caw! Um, is one of the lovely local security companies.

They're focused on AppSec. Um, yeah, if you want to, if you want to follow him, he's at Untra, or Untra, U-N-T-R-A. Um, you know, go reach out to him. Once again, big thank you to Sam because he sponsored us at that $10 a month level. Not only does he get a shout out on the show, but he also gets some sweet, sweet Colorado Equal Security swag mailed to him.

Who does not like that? All right, that's great stuff. Let's jump into the news, Robb. Uh, first on the list, Netflix has a show called Inside Job, and in one of the episodes they expose all of the truth around the conspiracies, uh, at DIA with Lucifer and aliens living in the basement and everything else. Yeah, you know, I've never, never watched this show.

I had never heard of this show. Looks like it's an adult-oriented, um, uh, cartoon. That, uh, that kind of goes into, uh, different conspiracy theories around the world. And, you know, Denver, which has really kind of embraced our whole conspiracy theory lizard people living under the airport type of, uh, motif, um, they get, they get some, uh, treatment in this last episode. Yeah, uh, when I first read the headline of the article and started reading, I thought, oh well, you know, this must be some reality show where they're, you know, going and exploring the airport or something like that.

But, um, but no, not, not a reality show at all. So, Alex, I know you and I have probably heard some of these facts before, but you know, you got to assume that we have some listeners who are not familiar with the story behind Blue Cipher, that big blue horse outside of DIA. A couple details. Number one, Blue Cipher is actually called Mustang. That's the official name.

Um, it was created by Luis Jimenez and his son. And I think the, the real, um, the real story there is while Lewis was creating Mustang, a part of the statue actually fell on him and killed him. So the, the actual creator of, of Blucifer was killed in his making, which is absolutely the start of many a horror movie. Uh, yes, exactly. That is definitely the start.

Uh, first haunted horse kills its owner and, uh, and begin scene. Um, Yeah, yeah, very crazy stuff there. And, uh, lots of other conspiracy theories, of course, with the airport. Um, did you know, Robb, that on the, the Fly Denver website, they actually have a, uh, a page dedicated to some of those, uh, conspiracy theories as well? I did not know that.

I've been sitting here trying to decide which segue I should use to go from this story to the next one. So why don't I try 2 and you tell me which one's better? All right. Okay. Hey, speaking of adult-oriented cartoons, uh, our favorite creators of South Park, uh, you know, as you're aware, they created Casa been— or excuse me, they didn't create, they purchased Casa Bonita a year or two ago, and we've been waiting anxiously for them to open this thing.

All right, that's, that's number one. Okay, number 2, speaking of crazy attractions in Denver that everyone outside of the area knows about, um, in addition to having a blue horse, we also have a cliff diving restaurant in the middle of Colfax Street, and we have some news about Casa Bonita. Uh, those are both good, Robb. I, I think I like the first one better, so let's go with that. All right, we'll edit out the other one later.

Sounds good. In any case, uh, we've got great news that there is now an official— well, sort of an opening date for Casa Bonita. Not exactly a date, an opening month. So we know about when it's going to open, uh, and that is May. Um, and with the speed that time is going by, Robb, that's going to be here before you know it.

I know, right? We're going to have, um, you know what, that's 4 months from now. We'll have that in about 6 weeks if, uh, if my math is right. Um, you know, I'm really excited to get out to Casa Bonita. I I, I'll admit I did not ever want to go there before it closed because the food is so horrible.

Um, but I'm excited to go see what, what, um, the, the South Park folks are doing over there. And you know, the new chef, Dana Rodriguez, who's, who's reimagining the menu. I'm looking forward to going, and maybe we can make some kind of Colorado Equal Security summer event be, uh, over there. Yeah, I think that would be fun. Um, do some sort of meetup or dinner or something else there.

Um, I would, I'd really enjoy that. Um, yes, I agree that I, I wasn't a huge fan of the food before, but, um, I'm looking forward to the new food. And of course, you know, seeing what the restaurant looks like now after, you know, $83 billion have been put into renovation. Yeah. All right, moving on to our next story.

Uh, if you've ever sent an email to someone who works for the state of Colorado, you're probably aware that their email ends with, um, was it state.us Oh man, call it state.co.us. Yeah, state.co.us. Now they are now looking to make a move to change those email addresses to, um, .gov. Alex, why would they do that? Yeah, so I think there's a couple reasons.

I mean, in general, it seems like it is a, a move by many different government agencies, not just in Colorado, but, you know, sort of across, um, across the country, moving to the .gov domain. One of them is that the .us domain, it's not a controlled domain. So anyone can go out and register a .us domain. So if you wanted to register instead of state.co.us, if you wanted to register co.state.us and do some phishing against people, you could probably do that. Although I'm guessing that one's probably taken already.

And because of that, I think that's a reason that people are moving to .gov, which is a controlled domain. You have to have verification before you can get a .gov domain. Also, there are some restrictions on participation in federal information sharing activities. You need to have a .gov email address to be able to do that. So Colorado officials have been left out of some of those, or at least have a bar to get over before they can participate in some of those activities.

Yeah, I think it's because they have some security controls they can, they can put on that, um, on that domain, on the .gov email suffix. And, and as a result of that, they're more comfortable making, doing sharing over that. Um, what's interesting that to me about this article is they, they say that the Polis administration is asking for $2 million to make this change. And my first thought is, um, well, that's really cheap for, for whatever, trying to change the entire state's email domain. It seems like that would be a very expensive, time-consuming project that if they can do it for $2 million, that seems like a deal.

I would agree with that. Yeah. I mean, with the amount of time that has to go into to make this happen in all of the various places that it needs to happen, that seems like a bargain. Sign me up. Good stuff.

All right. Next, less about email, more about startups. In 2022, Robb, Colorado startups raised $5.7 billion. Was that million? Is that million dollars?

No, that's B, uh, billion with a B. That's a lot of million. Um, and, uh, that is the best we've had in several years. It is not the, the largest we've ever done in Colorado, but it, um, I think it was the second or third largest, but definitely the largest since the pandemic. I, I, I'm gonna do a slight correction.

It— the, the— there was a big outpouring of money into the middle of the country during the pandemic, in 2021 especially. Um, and like, for some reason, you know, historically all the money's gone to the coast, right? Lots of money to Silicon Valley, lots to New York. In 2021, a lot of that went into this middle of the country, including Denver, where we actually in 2021 had $7 billion here in Denver. And it looked like in 2022 there was kind of a— let's go back, going back to the norm where all that money was going back out to the coast again.

And the other middle-of-the-country cities, they all like lost like a lot of it. And really, we're not seeing a big investment in 2022. But Denver, we bucked that trend. And to your point, like, you know, we, we showed up really well in this previous year where, you know, going from 7 only down to 5.4, even though— if you're assuming 5 to 5.7, even though the second half of the year we had a big slowdown, right? Because everyone's worried about the economy.

So we, we really had a strong first part of the year, um, and, and are on trend to, to continue to have a really strong venture capital market here in Denver. Yeah, and in that fourth quarter, uh, only 79 startups snagged deals, um, and they raised $1.4 billion. So based on, uh, that, I think if we would have had a much— excuse me— a better fourth quarter, we probably could have beaten that, uh, that $7 billion from the prior year. Yeah, um, I think it's interesting. This, this article shows all the companies that raise over $100 million.

There's a lot of them. There's more than a dozen companies. A few we've talked about in the past— Crusoe Energy Systems, they, they topped the list with $505 million in, in money raised. This is the company that, that sits out at oil and gas fields, and they take the, the excess burn from, you know, from those fields that's going to be wasted, and they're turning it into computing uh, computational cycles that are being used for crypto mining. And that company is, is valued at, uh, over $1.8 billion now.

Yeah, that seems pretty crazy. Uh, I remember when those guys started, and so to, to see them be a, uh, a unicorn and be over a billion dollars, that's pretty cool. Uh, Velocity Global was second on the list with 400, and they— Velocity, this makes sense, uh, with the remote work trend because Velocity Global helps people, uh, hire workers in various places whether you're, uh, hiring them through Velocity Global or having them help you, you know, set up, you know, an organization in that country to be able to, uh, to hire folks. Yeah, there's— I don't know if we need to go through all these. A couple more interesting ones though.

Um, Dispatch Health, which does like in-home healthcare, valued over— or they took over $300 million last year. Pi Insurance took over $300 million as well. Guild Education, which, you know, we know pretty well, and we had Julie, their, their head of security, on here. They took $265 million, uh, including a big investment from Oprah Winfrey. Yeah, uh, one of the other ones that I thought was interesting, uh, on the list was Meaty Foods, M-E-A-T-I.

I saw that one too. Yeah, um, they raised $150 million, and, you know, they make plant-based protein. So, uh, they make not chicken and not steak. Yeah, it's, it's made from, uh, from a kind of mushroom root. Um, and, and if you looked— I don't know if you looked at that picture in the article of someone cutting a, you know, supposedly chicken cutlet.

It looks like chicken, right? I mean, I, I could be convinced. It does look a little bit like chicken. Also, that picture makes it look like it was the 1960s when they were cutting that chicken. That's true.

That's true. So a lot, a lot of good money raised this year, uh, last year I guess at this point. Looking forward to seeing that continue. And, you know, really it's a you know, it's a virtuous cycle, right? The more money that comes into Denver, the more success we have, the more startups will start here, and the more money will come in, right?

And I love to see that. Love it for the, the opportunities it gives employees, the opportunity it gives investors, and really just what it does to the, to the ecosystem here in Denver. Definitely. All right, uh, I think, you know, this is similar to other stories we've talked about in the past, but, uh, 9News did a, um, they did a profile on a a group of what's a Cyber Patriots team, right? Um, and it's, it's an all-girls group that was competing at Metro State University in Denver, um, and interviewing a couple of the members of that team and talking about how they're, you know, they're looking, you know, into the future for jobs in the security space.

Yeah, um, it was pretty cool to see that, that, uh, they are doing those competitions still and that we're, we're building that next generation of cybersecurity talent. Um, the— of course they had the, the standard statistics, which I don't think have been updated in a number of years, that there are, you know, over 3 million empty cybersecurity jobs and, you know, 700,000— I don't know, something something. Um, anyway, I'm a little tired of those statistics because I, I can't imagine that they are right still. They've got to be either a lot higher or a lot lower by this point. I can't imagine they're exactly the same.

I've heard almost those same numbers for a while. But it's, uh, it's cool to see that Cyber Patriots are still thriving. Yeah, I love to see that. Uh, they, they also show a little bit of inside that Metro State, um, cyber range. If you can, you take a look at a picture of the inside of that.

And, you know, I, I have no idea how that cyber range works, but I think it's just cool that there's a physical place people can go and, you know, feel some inclusion. I think it's just going to make it so much more memorable for those kids to have a chance to go into a university cyber range and learn about protecting and defending and attacking in that kind of environment. Yeah, good stuff. All right. Next, we have a blog from Ballard Spahr, and they're talking about the Colorado revised privacy rules.

So we've talked a little bit about this in the past, that they're, you know, the new Colorado Privacy Act was going to be going into effect and the, the rules that were going to come out from the attorney general's office on how it is that they were going to enforce that would be coming out soon. So those— a revised draft of those rules have come out. It sounds like it's a bit of fine-tuning at this point. Some changes to things like some flexibility around data protection assessments, which I think could be welcome to, you know, some smaller businesses, as well as some changes or clarifications in terms of some definitions around You know, what is a commercial product or service, or some other things like that. Yeah, I think, I think the key here is for those of you who are running or influencing security programs, just make sure you're aware of the, the revisions here, the, the new rules that have been released, and make sure your, your team, your privacy team, your legal team are reviewing those to ensure you guys are up to date with what your requirements are.

All right, next we have some And not so good news over the holidays, or really in December, CommonSpirit Health, which is, you know, one of the biggest healthcare providers, you know, with a— maybe not headquartered here in Colorado, but a really large presence in Colorado, you know, formerly CHI. Also, I think they, they own what, Centura Health, and they have a lot of other kind of tendrils into other health systems. Um, they, they announced, or that they reported, that they were that the ransomware attack that hit them previously exposed the data of, uh, 623 patients— 623,000 patients. More than half a million. Add some zeros there, Robb.

Yeah, you gotta add 3 more zeros. Yeah, I mean, I think on the, the positive side, it sounds like, uh, the, the data that was leaked was not the most sensitive of data. Um, name, address, phone number, date of birth, which is not great, and a unique organizational ID, so sort of a member number or something to that effect. So it doesn't sound like Social Security number was involved, which is good. I mean, I guess you got to look at the bright side of some of this stuff, or hey, you know, your information is probably out there already, so what's the big deal?

Well, I mean, the bright side is you get a year of free credit monitoring, right? Yeah, I'm sure you get some free credit monitoring out there. You could add it to the other 12 that you already have. Yeah, yeah, not, not so great. Yeah, um, and you know, I, I know we know some folks that, uh, that, that work at CommonSpirit.

Hopefully, um, you know, this has helped them. Obviously you don't like to go through this stuff, but hopefully it's, uh, helped them, whether it's through budget or, uh, focus or whatever it might be, to, to make their security program even better going forward. Yeah, and I know they're, they're working awfully hard to protect their customers and their patients and Um, yeah, I appreciate all the work they're doing. All right, uh, next we have a Red Canary blog talking about thwarting account takeovers in Google Workspace. And, uh, Robb, when I, when I first saw this, I thought it was interesting because, um, you know, normally when I think of Red Canary or other MDR providers, I don't think, oh hey, you're going to be monitoring my, uh, my SaaS email environment.

What's that all about? Yeah, it's great. The, the article is you know, something of a way of announcing Red Canary's support for monitoring of malicious behavior in the G Suite environment, which goes along with, you know, pre-existing support Red Canary's had for a while for monitoring of the Microsoft 365 environment. This is just an expansion of— from this fundamental, hey, we, we watch where the hackers are, which it used to be the hackers are on your endpoint, on your laptop, to Hey, hackers are no longer just there. They're also in your, your most important SaaS applications, you know, email being right at the top of that list.

They, hey, they're also in your cloud infrastructure. We gotta make sure that, you know, a company like Red Canary is monitoring that as well. So Red Canary is looking for signs of malicious behavior. You know, think about things like, you know, emails that, that are, are sent to a certain number of executives that have suspicious behaviors or, or forwarding rules that are set up in email or, or sharing that's done in kind of a, a pattern that matches what bad guys do. You know, any of these things can be an indicator that someone has got access to that productivity suite, and that's what Red Canary is looking for, and tying those back to other indicators across the rest of the IT ecosystem and helping with response.

I think that's great. And like, as you mentioned, um, you know, SaaS and, and other, uh, non-endpoint areas are, you know, definitely ripe for, uh, for exploitation these days. Um, the, you know, within the last couple weeks, you know, CircleCI, for example, which is a SaaS CI/CD platform, announced a breach. And, uh, you know, that, that's not something where you would normally think, oh, I need to monitor that, um, because it's a SaaS application. So I think we're going to be moving more and more in those Uh, those directions in the future.

Good stuff. All right, our next story is actually kind of an announcement of an upcoming event from the National Cybersecurity Center down in the Springs. On the 21st of February, they're going to have a capture the flag event at the Broadmoor. It's going to be from 10 AM to 3 PM, and it's, it's really meant to be a way for the community to get together, you know, sharpen some, some of, uh, your technical skills and get to do some networking. So hacking, pen testing, team building, you know, solving some puzzles and, and finding the flags.

Sounds like a pretty fun event. Yeah, it looks like this may also be part of the AFCIA Rocky Mountain Cyberspace Symposium, which I assume was at the Broadmoor as well. So, um, you know, for the adults, maybe you can, uh, hang out at the, the Cyberspace Symposium and the kids can do the capture the flag. So sounds like a lot of fun. Good stuff.

All right, our last story, um, this is from LogRhythm. And, you know, I, I guess it's a little bit interesting that this, uh, came out in January. Usually these sort of things come out at the end of the previous year, but they have some, uh, 2023 cybersecurity predictions. And, uh, this is largely by, uh, the security team at LogRhythm, but also some, uh, some other folks at LogRhythm talking about things that they expect to see in 2023. And, uh, Robb, what's on the list?

Well, so Alex, um, you know, generally the way we prepare for these is we both read all the stories and talk about them. Um, I— what I decided was I was not going to read this, and I'm going to judge whether, as we go through this list, um, I'm— my guess is that all these predictions could have been said last year as well, that, that there's not going to be anything where I'm like, oh man, this is new for this year. Um, I don't know, I haven't read it, and I'm certainly not trying to take a shot at LogRhythms. I'm trying to take a shot at all predictions because they're all the same every year. So Alex, let's start this list, and, uh, why don't you let me know, um, all right, the first one is— the first one: supply chain attacks will continue to be one of the biggest threats to enterprises using open-source software.

Well, I mean, that sounds like exactly what we were saying a year ago, right? Like, yeah. Literally no change at all. Well, and, and not even necessarily open source software, right? Like, you know, SolarWinds was not open source software.

But yeah, all kinds of supply chain attacks. But, uh, but I mean, a year ago today we were cleaning up for Log4j, right? Yeah, yeah, that's true. Like, that's, that's the open source big thing that hit us last year, I think. I think, you know, certainly a continuing theme.

By the way, they're not wrong. Absolutely, those are, those are big threats. But, you know, not a lot of change there. What else we got? All right, uh, number 2.

This one might catch you, Robb. During a time of economic downturn, cyber attacks will flourish. Yeah, you know, kind of, kind of tying in the fact that we are now more confident that there's a downturn. Yeah, I think it's fair to say that that's not one we would have said last year. There was already inflation coming.

Maybe you might have seen it coming, but no, that's— that one's, that one's going to be different. Very one-on-one right now. And I can see if there is economic hardship, then people might turn to, you know, even more nefarious means to make, make a buck. Number 3, ransomware operators will stop encrypting in favor of corrupting files.

Trying to think of why ransomware operators would do that. Yeah, I thought that myself when I read this article. I'm not sure what the what the benefit to them is other than causing chaos. But you're not a ransomware provider if you can't give your files back. I mean, there have been some ransomware providers that, um, you know, are known to, you know, decrypt and either not care to or have the ability to unencrypt their stuff.

Um, and I guess you could call that corrupting even though it's technically encrypted. So I mean That's sort of the same, but still, um, I mean, I don't know. The, the, uh, also they do mention in here double extortion. So I guess if you did steal the data before you, uh, corrupted it, then you can still ransom for deleting the data or giving it back. But I don't know, it seems, uh, I don't know if I agree with that one.

Yeah, that one seems tough. Um, certainly we've, we've seen, I'd say, over the last 2 years this move away from strict ransomware in the traditional sense to this double extortion, you know, where it's you better pay to get it back or you better pay so I don't release it, kind of, right? Double whammy there. Okay, number 4, cybersecurity budget conversations will focus on securing critical business assets. I mean, that sounds, that sounds like, uh, blocking and tackling fundamental right at the, you know, first thing that people should be thinking about.

It's not true because people continue to look at bright and shiny things. But absolutely, this is, you know, what, 20 years now we've been saying that this is what it needs to be. Exactly. Uh, number 5, organizations will reassess and expand end-user awareness training. Uh, so one of the things that they mention here is, uh, MFA fatigue, you know, and, uh, multiple push notifications for MFA and other things like that that may be slightly different than we have educated hated people on in the past.

Um, I mean, I think this is a theme for many years going, right? Where, where, you know, giving that one CBT per year where you're just dumping too much training, it's, it's not effective. People hate it. You're not, you're not getting a lot out of it. Maybe just a compliance checkbox.

Um, you know, reassessing and, and maybe I'd say rather than expanding user training, I would say getting more granular with user training, making sure it's really applicable to their job. That's, that's the thing we've been talking about for years. Yep. Okay. And I, I realize that there's a typo in this article.

So this is also number 5, but it's number 5 too. Organizations will feel pressure of impending security standards. That sounds every, every year for since PCI came out. Yeah. Oh my God.

I actually have to do stuff with my credit card data. Damn it. Okay, number 6, which is actually number 7, competitors within industries will model security strategies of their peers. Yeah, I mean, that's, that's how everyone— this is driven by the board of directors, right? Where the board comes and says, hey, Alex, you know, tell me what your closest competitors are doing for security and make sure that we're, you know, one tick better than them.

Right? Yep. That's, that, I think that's, that's what we see. Okay. And the final one, which is number 7, which is actually number 8: organizations will turn to subscription and managed services to better manage security.

What do you think? Does that, is that new? I, I don't think that's new. Yeah. I, I honestly, I, I don't, I don't, I'm not trying, like I said, I'm not trying to, to dig on LogRhythm.

Like, security just doesn't change that much year to year, right? Like, it's, this is a a battle where we know what we need to do. Uh, we— the battlefield's not changing that much. We need to make sure that we get better and better at executing, and our organizational relationships allow us to be effective internally. Well said, Robb.

All right, that is the news. Uh, let's move over to events. Um, in case you all had forgotten, on the website we do have a calendar of events, so you can go there and check out all of the things that are happening. Not only coming up, but, um, you know, as far out as several months from now. Uh, what do we have first on the list, Robb?

We have 2 events on the 17th of January coming up this week. Um, this Colorado CSA, Cloud Security Alliance chapter, is meeting on, on that day to talk about where you are today in the email maturity model curve. Um, this is a, an interesting conversation. I, I suspect, you know, we, we know some of the folks who are involved here, Mimecast and And Andre Gade has been talking a ton about this, and looks like they have, uh, they have Mimecast out there talking about that in person. Um, also on the 17th, ISSA Colorado Springs is having their January chapter meeting.

On the 19th, ISACA Denver is doing their January chapter meeting, which is virtual. On the 20th, Let's Talk Software Security is doing their AppSec regulation frameworks and compliance meeting. On the 21st, ISSA Colorado Springs is doing one of their mini seminars, their January mini seminar. And while you're down there in the Springs on the 21st, you might as well hang around till the 25th. On the 25th, ISC² Pikes Peak is having their January meeting.

I mean, if you're going to hang around that long, you may as well hang around till the 3rd of February because they're doing the Cybersecurity First Friday in Colorado Springs on the 3rd. All right, that gets us out a month from now. Uh, let's jump over into jobs. Alex, uh, start top of the list here. One of the most important jobs in the state of Colorado, I, I think really there's no question about it, the Secretary of State office, which is, you know, Secretary of State's office is responsible for election integrity throughout the state.

Um, you know, and state elections is really where decisions are made. Um, they're looking to hire a new Chief Information Security Officer. Yeah, uh, that, that is definitely a job that has a lot of responsibility. So something, um, that I think would be very challenging for people if you took a look at that one. And you can— you get to work with a good friend of ours, Rich Sleipe.

Rich has been on the show before, and I think, you know, you get a chance to work with Rich would be, uh, a really good one. You should take it for sure. Uh, Frontier Airlines is looking for a senior manager of IT governance, risk, and compliance. Uh, Denver Health is hiring an IS security analyst 3. IBATA is looking for a senior information security analyst.

DISH Network is hiring a GRC information security business partner. Western Union is looking for a group leader for cybersecurity engineering. Degreed is hiring an information security officer. That's here in Denver. I don't think I know that company.

Spectrum is looking for a director of identity and security. And finally, Sierra Space is hiring a Cybersecurity Analyst 3. Oh, good stuff, Alex. That is the news. And, uh, I got some bad news for us, Alex.

What is it, Robb? Or good news for those listening. We don't have an interview this week, so folks who are planning to spend the next half hour listening to, uh, get to know someone here in the community, uh, number one, you can use that time to go get some exercise or take a shower, you filthy animal. And, uh, and, and we'll, we'll work hard to make sure we have an interview for you next month. I guarantee you, Robb, we will have an interview next month.

Wow, guarantees. Holy smokes. Yep, you get your money back. Whatever you paid for this podcast, you can have it back. All right, well, that is it.

Happy, happy welcome to 2023. Um, this year is going to be fantastic. We're looking forward to meeting with you guys. Anything else before we go? I think that's it.

All right, we'll see you guys. Thanks, Robb.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Colorado equals security.

Back to all episodes