Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 253 for the week of, uh, I guess it's the month of October. Month of October going out October 9th.
Alex, is it fall? It is fall. Happy fall. I mean, it feels kind of chilly outside the last few days, so it must be fall. My outside plants are dying.
That is usually an indication. I think it did dip below 32. This— we're recording on Saturday. I think it did dip below 32 overnight last night. Yeah, I didn't see any frost personally, but that doesn't mean it didn't, didn't frost.
So the trees are turning. Yeah. You know, a lot of folks are out leaf peeping. I am, I am not this year so far. But you're not a peeper?
I, well, I wouldn't say that, but I haven't done it yet this year. Last year we went and, and, you know, there's still time. Once a peeper, always a peeper. There you go. Once you've, once you've enjoyed, um, getting out to, to see nature in all its beauty, um, it's, it's hard to stop.
It, it sure is. It sure is. And hopefully everyone's getting a chance to get out on their own, uh, before it gets too chilly. Uh, for sure. All right.
Hey, we have some housekeeping type activities. Uh, we love to remind everyone that there's not only this wonderful award-winning podcast, we also have a Slack community. And we've got 2,500 of our closest friends out there in Slack where you can discuss things all the way on the gamut from the newest ATT&CK techniques that are out there to where the best coffee is in the Denver area. If you want to join Slack, go out to colorado-security.com and click on the Slack link, and that'll get your request over to us. We'll get you joined.
We also have a mailing list. You can sign up for that while you are on the website. You will get the show notes sent to you. We've actually been, you know, trying to think if there's other things that we should be doing to, you know, enrich the people that are on that mailing list other than the show notes once a month. There's occasionally some other things, but, you know, maybe we'll do something in the future.
Who knows? So to enrich them, are you thinking some kind of lottery? Some kind of— I was thinking of pyramid schemes, sweepstakes, MLM. I have an opportunity that will change your life. And by them, I meant me.
Also, If you're listening to this, you're probably doing it in some kind of podcast player. Please subscribe to this so you get it downloaded automatically and rate us. Give us hopefully a good rating so we move up the charts. Yeah. If you've heard this every time we talk, this is your time.
Go, go do the rating and give us a review. That's good stuff. We would also love it if you would tell your friends and your enemies, whoever, whoever it is, you know, that might listen to security stuff, let them know about the podcast. Let them know about the community. We'd love to grow this.
You know, the mission here is to, to help the Colorado security community to become uber connected, and you can be a big part of that. So please do. Finally, if you'd like to support Colorado Equal Security financially, we do have a Patreon campaign. You can be a patron of us. If you sign up for at least $10 a month, you'll get a cool gift from us and a shout out on the show and other good stuff like that.
So we use that Patreon money to support the costs we have for Colorado Equal Security and do fun events like the picnic we had this summer. Yeah, good stuff. We do appreciate our current patrons very much. Thanks to those folks who are helping keep things going. You know, not only financially, but the support we get from you.
Just knowing that you care, it means a lot to us. So thanks a lot for those who do that. All right, let's jump into the news. Some international news happening here in Colorado, Robb. Colorado's first Michelin star restaurants were announced.
Yeah, I think another way to say this is, you know, a tire company is going to tell you where to eat. Yes. Yeah, it is. It is amazing to me that somehow the Michelin company became the premier place to find the best food in the world. And apparently Denver is now a region that will be reviewed by the Michelin Guide.
I guess the Denver Tourism Office, something like that, paid some money to get Michelin to come take a look out here. And there's 5 restaurants that are going to make the cut. Yeah. And Michelin is looking at Denver County, Boulder County, and Aspen, I believe, are the 3 areas. I know leading up to this, there was a little bit of kerfuffle because there are some good restaurants in Denver that aren't technically in Denver County, so they couldn't be counted.
I gotta tell you, you know, there's like a running joke that like, you know, the more expensive the food, the the the less food it looks like you get. I'll just say the pictures in this article, like absolutely are right right in line with that with that meme. Yeah. So there are five restaurants that received a Michelin star. I think all of them were were a single star.
Becken, Bosque. Bruto, Frasca, and the Wolf's Tailor. Um, and obviously, like I said, take a look at the link in the, in the show notes. You can see the food that you get from these places, and it is very— the presentation is a big part of it. I'm— I believe for Michelin that that's a big thing they care about, and obviously, uh, taken very seriously by these restaurants as well.
I have eaten at Frasca. It's very good. Um, I know people that have eaten at the Wolf's Tailor. They said it's very good also. So yeah, well, it's, uh, it's cool to know that, you know, now, now we have some rating and we're kind of on the stage a little bit, right?
Yeah. Good stuff. All right, moving on to our next story. Speaking of cool local stuff, there is a competition for the coolest thing made in Colorado, and there were 10 companies selected, and this article goes through what those 10 items are. Yeah, so it's a wide range of things, and, you know, Robb, we were talking about earlier, I'm not sure exactly how you compare these things together, but hey, but they're all cool.
Like, Wad-free bedsheets, like who wants their sheets all watered up? And an ejection seat for a spacecraft, right? Right. So pretty wide variety of stuff. But Alex, you know, you and I each took a moment to figure out what we think was the coolest thing on the list.
You know, I chose Lockheed Martin's— let me get the right wording here— Lockheed Martin's OSIRIS-REx spacecraft made here in Colorado. It's hard to beat a Lockheed spacecraft being built here as the coolest thing. What did you find to be the coolest thing? Yeah, I'm taking a little bit of a different tack to this, Robb. The one that I'm picking is the DNA Vibes Jazz Band.
And I'm picking this because it's also— I'll say it's interesting. The— I'll read some of the thing here. It's a wearable device that helps prevent injury and accelerates a user's recovery using a patent-pending regenerative process that stimulates DNA expression. It— from the picture, it looks sort of like a reddish disco bally earring. I think it's a pad behind her neck right there.
Maybe. But that's what I think. But it doesn't look like from the picture, like it could be like something hanging from— anyway, look, it does in the picture look like an earring. But I do think it's a pad behind her neck, coming near her ear. Anyway, this sounds a little woo woo.
And Maybe there's some science behind it, maybe there's not, but, uh, yeah, I mean, I think much like many of the security tools that we invest in in our programs, one needs to, to do a little bit of analysis to determine if it, if it's effective. Well, if, uh, if DNA Vibe wants to, uh, to give us a trial unit for us to, to test out and, and do a POC with, we'll be happy to, and then we can tell people whether it works or not. And we can use all 5 kinds of light that it generates. Exactly. To, to help with both recovery and, uh, and not getting injured in the first place.
Exactly. All right. Moving on to the next story. This is a recent one. This just happened this week.
There was some renderings that were released from the airport as part of their next version of their planning process. This is, you know, they have like a 30-year plan continually. And this is talking about what they're going to be doing in years from now. And the enhancements that they're going to do to the terminal, more concourses, other things like this. It looks interesting and I'll be happy to see it.
Yeah. So specifically, the thing that stood out to me here is by the year 2045, they are planning for more than 120 million passengers. And one of the things that they're looking to do is to make walkable concourses from the main terminal. You know, you know, the place where you have baggage claim and generally right now you maybe you get your ticket, then you go get on a train somewhere else. They're talking about adding you know, connected to that terminal, they're going to add on concourses with gates, another, another 100 gates or so it looks like that folks can get to.
I was hoping when I first saw this that they were going to make it possible to walk to the existing concourses because it drives me crazy that I can walk to A, but it doesn't matter how much time I have, I can't walk to B and I can't walk to C. So you're kind of at the, at the mercy of the train anyway. But cool stuff. And the rendering shows what that's going to look like. Yeah, it looks like they're going to be building some stuff off of the main terminal, which is cool. And as you said, you know, at this point, I would just love it if they would fix the current airport, right?
You know, I know the current 10-year project they're in the middle of feels like we are a long way from the end. I know they are planning for the future, and you need to do that. But please just fix security for now. Yeah. Well, we have an update from a company we've talked about on here, I think a number of times, formerly known as Digital Globe, now Maxar.
Digital Globe was acquired and merged in with Maxar, one of the larger tech employers here in Colorado. Maxar, just this, in this last week or last month at least, has been broken up into 2 separate businesses. And they, it looks like one of those is relocating out to California as the headquarters and the other one staying in Denver with a new interim CEO who's the same as the old CEO, which is a little bit weird. Some big news from a local company. Yeah.
So the, there's going to be 2, they call them in here business units. Because they'll still both be part of the bigger Maxar Corporation, I guess. But one of them will be Maxar Space Infrastructure. And that will be the one that is led from California by a new CEO, Chris Johnson. And then Maxar Intelligence, which will be led by Dan Jablonski, who will be interim CEO, but he is the current CEO of Maxar.
Yeah, really, it's clearly some, some big changes going on over there. This has impacted some employees who've already been laid off. Um, you know, and it's interesting because usually I think, you know, layoffs happen when you combine companies and you find synergies. In this case, um, there was layoffs even though they were, uh, collap— or dividing into 2 separate business units. Um, you know, I don't— we don't know how big the implications are going to be.
Maxar didn't want to comment on how many layoffs were made. Um, but, you know, there's— there is news going on there, and if you know folks over there, maybe reach out to them and make sure things are going okay. Yeah, it can't be that big, otherwise they would have had to tell the state, and then we would have known approximately how many. So I'm guessing it's small. Also, it was sort of implied but not said.
I'm assuming that the, the Maxar intelligence business is staying headquartered in Colorado. Yeah, they didn't say that it was doing that. But they didn't say it was moving either. And I think fair point that that headquarters, the one up there at 120th, 120th and Pecos, I think it is, That's been there for a long time, and presumably it stays there. But you know that maybe there's more news coming.
All right, next we have an article talking about top universities for startup founders. This is a list that came out recently, and CU is on that list at number 39. Yeah, this is a story from the Colorado Inno, which we've talked. About these guys a couple— we had stories from this publication a couple times in the past. But it's interesting to see, you know, that CU is, you know, it's on the map for universities.
As you mentioned, you know, it's not in the top 25 even. You know, you start off the list with the ones you might expect, you know, Stanford's number 1, Cal Berkeley, Harvard, University of Pennsylvania. Those are the ones at the top of that list. But it's nice to see that, you know, the the work that's been done up in that Boulder area with getting venture capital funding, getting, you know, more support for start— for entrepreneurs and for startups, it's made some progress. And now CU is starting to generate some of that same, some of that buzz.
Yeah, I don't have the CU numbers in front of me, but the Stanford ones were pretty amazing. They list both the founder count and the amount of capital raised by those founders. 1,435 founders from Stanford for $73.5 billion in, uh, money raised. That's a lot of money. You know, I, this article doesn't get into it, but I would love to see, you know, for every dollar you give to a founder at the different schools, how much you get back from that.
Like, right. What's the ROI on that $14 or $73 billion? Right. Because if it's, because if, you know, I, you assume that Stanford's getting all this money because they're the ones who, who produce the best companies. But it, it wouldn't surprise me if there's this halo effect that, you know, because we had some great people come outta Stanford, way too many people are getting funded outta Stanford and companies or, uh, universities like CU lower on the list have a harder time getting funding.
So they're, they're, you know, only funding better companies. I don't, I'm just making hypotheses with no data at all. I would love to see that data if someone does that analysis. Uh, okay. This is interesting.
I, I, so I dug into the list a little bit. You can go to the, Uh, the link there that has the list. Um, I looked at CU, 381 founders out of CU, which is, I think is a good number. Uh, top 5 by capital raised. And these are the companies that they founded.
Yeah. Number 5, Silence with $327 million. Silence is a CU company. Wow. Yeah.
See, this is the kind of deep investigative journalism that I expect from you, Alex. I, I don't really, uh, recognize any of the other ones, but obviously Silence. Silence. Huh. Yeah.
And so I think you mean BlackBerry at this point. Well, actually, well, I also heard this week that they're spinning off their security unit into a separate company, CU, or excuse me, security and IoT stuff. So they can focus on handsets. Exactly. From the '90s.
Exactly. I love my BlackBerry. I have nothing but positive things to say about them. Hey, next we have another story. This one's coming from Denver— Denver.com.
Was it Denver7? Denver7.com. And this is around Metro State University's cybersecurity program. We've talked about it in the past, but Metro State is getting to expand their cybersecurity program with the help of a brand new grant. Yeah, this grant for $500,000 is coming from the Colorado Attorney General.
And I'm not— I don't know if that is from the Attorney General personally or the Attorney General's office. I'm— anyway, I'm assuming the office, but Anyway, probably from the office. Yeah. Anyway, this $500,000 is going towards them training a bunch of new security analysts. Yeah, I think this is a really neat thing.
I, I know we talked in the past about how they have this program. I don't know that I understood before that they are actively not only training people, but they are delivering services that are being used currently by through this thing called Project Pisces. Yeah. Was it 11 different organizations, the different customers that are, that are helping protect, I think it was 450,000 Coloradans through this, this service that they're doing at the school. So people are coming in, not only are they learning some tools, they're actually delivering SOC services as a part of their education.
It is a really cool program. I have talked to Richard McNamee, who's the head of this program before, and we were actually trying to get him to be an interview on the show and we just got to figure out the timing for that. Um, but yeah, they, they have a cool security operations center and that the Project Pisces, you know, if you're a, uh, small, uh, understaffed, underfunded municipality, uh, you can sign up with Project Pisces and have, have them monitor your, your security infrastructure for you. Yeah. Um, I think largely for free.
Yeah. It's such a cool thing. And, and the fact that you're now gonna be graduating people who not only have hypothetically learned how to do stuff, but have worked in a SOC, you know, dealing with real incidents, you know, working with real customers, it's only gonna make them more employable. It's only gonna help try and fill that, that large gap for, for hiring. Yeah, so the plan here is, uh, the grant goes for 2 years, and they're trying to train 85 analysts in the first year and an additional 100, uh, by June of 2024.
So pretty cool. I don't know if that means like full ride or some money towards your school. Anyway, doesn't really say, but, uh, cool stuff. Good stuff. All right, let's move over.
We have a blog this week from, uh, from Ping Identity about MFA bombing. Um, and, and it's not a phrase that I have used. I didn't know that that was the word for this idea of overwhelming people with MFA requests in hopes that some number of them will approve it. You know, the idea of MFA is that, you know, hey, if I, if I figure out your password, I still won't be able to get in because of that second factor. But if, if I figure out the password for everyone in a company and I authenticate as everyone over some amount of time, some number of those people are likely to approve the MFA if it's a push.
Automatically. And this is talking about what does that, that kind of alert fatigue look like? Um, what can you do about it? And, and, and really like, uh, how security folks should think about this. Yeah.
And so some of the things they say that you can do about it, one, uh, limiting the number of MFA prompts during a specific timeframe makes sense. Uh, lever— leveraging push notifications with the number selection. People have probably seen that where, um, instead of just saying, do you approve or not? Like it sends you a number. And you have to, on your end, input the number.
Obviously, these are sort of blind attacks. So if, um, if the attacker can't communicate with you, then they can't get you to put the number in, uh, using risk-based authentication. So, um, obviously that makes it easier if you are really the person trying to authenticate and harder if you are not the person. And of course, going passwordless with FIDO2 options, you know, uh, hardware tokens and things like that. Yeah, I was, I think that those are all, those are all good suggestions to help to decrease the risk of this type of an attack.
But I was surprised that one of the things that we did a lot when I was at Ping isn't on this list, which is recommend that the first time someone signs in from a new browser, that you can't use push notifications. For that one authentication, you have to use a one-time password, which like just completely eliminates the idea that I'm getting a push that I'm gonna approve, 'cause you're never, well, you're almost never going to be trying to attack from my browser. You're attacking from some system somewhere else. So that's another thing you can look at doing as well. I mean, one other possibility there, obviously, too, is just eliminating those push notifications, right?
Like there are so many options that you have now. Um, that particular one, I mean, you could just get rid of that and then this attack goes away. Yeah. Good stuff. All right.
Let's move over to our next blog. This one's from LogRhythm. We haven't talked about LogRhythm in a little while. Um, they have a, a service called an, um, Analytic Copilot, which is basically a combination of using their technology and a human on the LogRhythm side to help you get analytics set up in your SIEM. Yeah.
And this is not an AI service. I know everyone that's doing GenAI services these days are calling it Copilot. This is not that. Basically, you know, you have someone that you can call on and assist you in creating new use cases and tuning the ones that you have. So that's pretty cool.
So this blog post is talking about 6 use cases that they have used during Copilot or 6 of the most popular use cases that they've used with their customers. Uh, one of them, which I think is, uh, very useful, is monitoring for disabling Windows event logging, right? If someone's turning off event logging, yeah, you really wanna know about that. Yeah. They have 6 on here.
I don't know if we're gonna go through all of them, but, and I'll mention another one that I found interesting is they also can detect MFA fatigue with what, what they're calling MFA bombing. They call MFA fatigue here. Right. Um, uh, they have the ability to detect, you know, if there are a bunch of MFA requests that end up getting denied and followed by one that's accepted. That looks suspicious to them and can be, um, could be an opportunity for the, the SOC to get involved.
Yep. Uh, another one that they have on here that I thought was cool is travel lists on admin accounts. Um, basically, uh, it looks like for the BlackCat group, who was the one that, uh, ransomed the, uh, the casino groups in Las Vegas, they leveraged admins that were out of the office, um, to, uh, to get password resets and other things like that, right? So you can monitor. If you know when people are gonna be out of the office, you can monitor for that and, and check on when bad things are happening.
Yeah. I, I think the point of this blog in my mind is to show that, you know, you, you can't just turn any technology like a SIEM on and like just watch it go. Right. You know, it takes work, takes, takes tuning in your environment and using a service like this probably makes sense to get the most out of your investment. All right.
Next, we have a blog from Coalfire, and this is a rundown of the OWASP Top 10 for large language model applications. Yeah. Speaking of GenAI. I feel like this is, uh, kind of a, a backdoor way to talk about a non-Colorado thing because I find this really interesting to talk about the OWASP Top 10 LLM list. You know, we, we've had the OWASP Top 10 Web Application Vulnerabilities and the API list for a while, and this is a new one.
And, and I'm excited to get to, to see, Alex, any favorites from the top 10 list here? Um, I don't know about favorite, but I think the one that, that people probably know the most and is, um, is pretty, common these days is prompt injection. That's number one. So putting things into prompts to either to get the model to do things you— it shouldn't do, or, you know, potentially do things that, you know, the user doesn't want to do, but you're injecting things with them. Yeah, there's some overlap here between, you know, normal, you know, sanitizing, you know, inputs, right?
That's the thing you're going to see any on any of these types of lists. But there's a lot of stuff that's that's quite unique to, to an LLM, you know, model theft, the denial of service, the, you know, poisoning your, your learning data, you know, interesting stuff that I, you know, I think that maybe I could have come up with some of these, but I love the fact that I have a validated list from a, from a trusted source here. Good stuff. For sure. Yeah.
Good stuff. All right. Last article. This is a Red Canary blog talking about the new SEC guidance and what it is that's required of us if you're a public company. Company.
Yeah, so Red Canary is known for having like these really great in-depth technical blog posts that'll show you all the details of an attack. That's not what this is. This is a blog post by a friend of mine, Matt Spahn, the general counsel over at Red Canary, talking about what do companies, public companies, need to do based on the new SEC guidance. And, you know, I, I don't know that there's anything new for us on this list, but he does a good job summarizing what companies should be thinking about. Yeah, so if you are in a public company or if this just interests you, I think it's, it's a good way to get a good summary of that and see what it is that is expected from organizations around cybersecurity from the SEC.
Good stuff. All right, that is it for our news. Let's jump over to our calendar of events. As a reminder, we do have an event calendar on colorado-security.com. Go see all this stuff coming up through the end of the year.
Quite a few things coming up. But Alex, what do we have here in October? First on the list, on the 11th, ISSA Denver is doing their October chapter meetings. On the 17th, the Let's Talk Software Security group is talking about, is threat modeling scalable? We actually have a couple things listed for ISACA Denver on the 19th.
It's the same thing twice here. Oh, okay. This is their October chapter meeting, fraud lessons from a reinvention architect and mindset coach. Interesting. Yeah.
I think it's actually 2 separate things. So there's, there's the mindset coach, and then there's the, the lessons learned. Got it. Yeah. On the 25th, we have ISC2 Pikes Peak doing their October meeting down in the Springs.
Also on the 25th, CSA Colorado Fall Summit. This is on AI. So if, if that's an interest to you, you should sign up for that. Yeah. Especially where, you know, our special guest today is the CSA president, Darren Weiner is going to be talking on our interview today.
Um, yeah, he's going to tell a little bit about that conference. I think this is a great event for you guys to go to if you're looking for a fall event. This is probably it. Uh, very inexpensive. And I think that there's still some discount codes out there.
And if you, if you go and you want to do something fun after the event, you should swing over to ISSA Denver's Women and Whiskey event. This is done by their Women in Security group. Um, and you get to have some whiskey and hang out with some great gals. Jumping a little bit into November, ISACA Denver is doing their Dark Web Investigations workshop on the 3rd. All right, good stuff.
Let's jump over to jobs. You know, we love to highlight a variety of jobs on the show, starting with some more senior level stuff and ending generally with more entry level. First job here on the list is by a company called Greenlight, and they are hiring their VP of Security here in Denver. Sounds good. Thrivent is looking for a Director of Information Security.
BDO is hiring a Director of Privacy and Data Protection. Gensler is looking for a Security Administrator, Senior. Western Union is hiring an Information Security Architect. Bank of America is looking for a Vulnerability Identification Senior Analyst. Gogo Business Aviation.
I actually got to meet with their Head of Security this week, Anita Edmonds. Oh, cool. Anita is looking to hire a Senior Cybersecurity Analyst. Honeywell is looking for an IT security engineering manager. I don't know, is that Justin Cohen's position?
Is that part of Honeywell? I don't know if it's his part of Honeywell or not. Justin's a great part of the community. If you don't know him, you know, maybe he's a good guy to ask about this position if you do know him. Um, CoBank is hiring a senior cloud security analyst working with Stanton over there, a friend of ours.
And finally, Plant Moran is looking for a cybersecurity consultant entry level. Good stuff. And that's a 2024 job. So they're looking— I think they're looking for someone who's graduating. Yeah.
Kind of thing to start with them after graduation. It's crazy. I was— I happened across a post on LinkedIn. There are companies that already have their 2024 summer internships listed. Yeah, it starts.
Those are companies that we call well-prepared, Alex. Yes. Many kids have already applied for college as well. Kids who we consider well-prepared at this point. All right.
That is it for the news. But like I mentioned, we do have a feature interview. Alex, what are we doing for the feature interview? Yeah, this is the CSA president. We have Frank, who is our guest interviewer.
Interviewer? Yes, doing another interview for us and looking forward to hearing about the CSA and the conference they have coming up and all that stuff. You know, we should just do a quick shout out to Ben Fellows and Chris Abbey, who are helping organize a Colorado Equal Security Gives Back event. We're, you know, we did We've done 2 so far this year and they're looking to schedule a 3rd one. I don't, we don't have enough details yet to, to, to post on the website, but they are working on getting, uh, some support for the Denver Rescue Mission and kind of a gift slash coat drive put together.
So details will be out on Slack. We'll also put it in the newsletter when we know. Um, but thanks to those guys for organizing that. Yeah, I think we should give a, um, a thanks to Frank also, Frank Victory, who's been doing all of our interviews lately. So yeah.
Thank you. Thank you, Frank, as well. Yep. All right, let's, let's go listen to Darren. Have a great month.
Thanks, Robb. Hello, this is Stanton Meyer, CSO of CoBank. Welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Good morning, good afternoon, and good evening, Colorado. My name is Frank. This is the Colorado Equals Security interview. Today I have a guest, Darren Werner. He is— say it's Weiner, actually.
It's Weiner. Okay. I should, I should figure that out before the podcast. This is my second time now. So it's Darren Weiner.
He is the Chief Cloud Officer of CloudButton LLC. And he's also the president of the Cloud Security Alliance, the Colorado chapter. And what is that slogan? We are a drinking club that talks about cloud. Drinking club with a security problem.
With a security problem. We haven't been promoting that tagline lately, but yes, that is— we are known for that. The original tagline. Well, before we get into the actual interview, I do have a question for you, an icebreaker question for you. Okay.
A mothership lands on Earth and they, they start talking to you, they start waving you inside. Do you go with them?
Oh boy. Um, at this stage in my life, my kids are grown, just about both out of the house. Yeah, yeah, I would. Yeah, absolutely. You only live once, you know.
That, that opportunity might not come by again. So, which might not end well, but be an adventure. All right. All right. Yeah.
So would you tell anyone or would you just go? Depends if they gave me any time or not. Yeah, I might throw a quick text out to my wife saying, sorry, honey, love you. But, you know, once in a lifetime right here. Yeah, yeah, yeah.
At least because I know that if the positions were reversed and it was my wife, she would just be gone. She'd be like, see you later.
Done your job. Go. Yeah, yeah, yeah. Dinner's in the fridge for the next week. And after that, you're on your own, buddy.
All right. So again, you are the Chief Cloud Officer of CloudButton and you have a very interesting background. You are a, you're not a Colorado native, but you do of course live in Golden right now. Is it? Is it Golden?
I do live in Golden. Yep. Yep. And what made you end up there? Where'd you start off in your career?
Yeah. I mean, my career is, there's a Harry Chapin song that goes, no straight lines make up my life. All my roads have bends. And, and that definitely applies to me. And, you know, I didn't— I, I actually was a computer geek back in high school.
I was— had my own BBS, so that dates me a little bit, along with did a little freaking as well back in the day. And then I sort of put computers aside, and I was, I was pre-med in college. I was studying biopsychology, which is really a pre-med major, and I was thinking about going to med school, but sort of life made other plans. I was actually for a number of years after college, I was actually doing bodywork, and I came out to Boulder for the summer to go to a workshop, just a bodywork workshop. And I discovered rock climbing, and I just— I fell in love with the mountains.
And I, I was planning on spending a couple months going to a class. I ended up spending all that money on climbing gear and never left, uh, Colorado. That was in 1993, so I've been out here since then. Okay, so I am Yeah, at some point I needed to get a real job and I started working in the outdoor industry, gear and clothing, working for rep agencies for high-end clothing, things like Marmot, K2, those sorts of companies. And this was, you know, back right around when the dot-com era was starting and the company itself was still, this was all old school ordering process.
Think about companies that need to order, you know, twice a year they need to order all the gear and clothing and things like that, all the shops. And I started bringing up a lot of my old computer skills. I started writing VBA code with Excel and Access. To try to operationalize it, create electronic order forms out of these very sort of standard order forms. And I started just spending more time getting into some of that development.
And that was right when the dot-com boom was taking off. And there was a company that was— this was even before rei.com was a thing, trying to get online gear and clothing. And I started working in databases. I started working, helping out with the database side of that. And that just got me on the tech bandwagon.
And from there, from data, I moved into DBA work, database administrator. And then from there I moved into IT, managing IT, everything from the help desk, desktop support to small data centers in offices, you know, again, way back when, right? I became, was the manager, IT manager and IT director for a number of different organizations. And then once I discovered cloud, right, when cloud came about, the light bulb came on. I realized this is absolutely the future of what I'm doing.
And so Pretty much went all in into AWS cloud about 13 years ago or so. And from there, obviously it's, you know, all the things associated with working within cloud infrastructure. So all the security components, all the disaster recovery, managing cost, managing infrastructure as code, all those things just came with the job. And so I just continued to move in that direction. And then I decided to start my own consulting company about 4 years ago, it'll be 4 years this November.
Where I take that, thank you. I take that sort of 26 years of IT experience, 13 years of cloud experience into every engagement. So I do what I call a deep engagement model where, you know, the cloud is a very confusing place for companies to work and I try to help make sense of that, right? Bring in all my skills into it. So wherever I can add value within these organizations, I do.
Okay. Well, before we get into that portion, let's take a step back because I heard something. Biopsychology. What in the world is that? For the people that may not know what that is, and that would include me, what is biopsychology?
Yeah, it's basically the study of brain and behavior. So it's the biological basis of behavior. So for instance, when I was an undergraduate, I was doing research into the dopamine hypothesis of schizophrenia. So looking at, you know, how those neurotransmitters impact the behavior and progression of schizophrenia. So it really is very much a neuroscience-based degree with, you know, just bridging that gap with psychology as well.
Okay. So do you use that today? I mean, could, could you find uses today, like maybe managing an IT team? I mean, hopefully you're not managing anyone that has a serious disease, but— Right. I mean, certainly when it comes to what I do in my day-to-day, I really feel that the biggest challenge is, you know, when you talk about challenges within technology of people, process, and technology.
I think people is always going to be the biggest challenge. And so certainly when it comes to the psychology aspect of it and building relationships, I'm always thinking about how can I do a better job working with people and managing relationships to be more effective at what I do and to help people be more effective at what they do. So I can't say necessarily that the degree directly helps me. However, the reason why I went into that area of study in college is because of my interest in people, in psychology and relationships. Okay, well, I'm going to ask a question of you, and it, it may upset some of the people in the audience, possibly even you, but I, I don't think so.
Do you think that it's different managing people and technology versus maybe your first job of managing in the outdoors? Like your outdoor equipment field?
Yes. Okay. I think that, you know, technology companies are— there's culture is such a challenging aspect of working for companies, especially in startups where you have all these different sort of subcultures that exist in organizations and larger, large organizations have their sort of more of a siloed approach to things where there's also those, there are sets of cultures as well. And so that's just, it can be incredibly challenging. You have people that are dedicated to certain fields of study within technology and getting them to think differently or work with other teams that have different perspectives can be, you know, a real challenge.
When you look at, for example, think about IT versus cloud teams right now. I have always considered cloud to be an evolution of IT, but that actually isn't the case in a lot of organizations. There's still the IT teams and then there's the cloud teams, and they don't necessarily speak the same language. And then when you talk about security teams, security teams that historically aren't necessarily as focused on business value, for example, they're really focused on protecting the organization, but not so much on really what's happening at the customer side and try to get them to interact with, say, development engineering teams. Which have a very different perspective in terms of what, what their focus is and where they're trying to drive value.
It's, it's just a challenging environment, a lot of strong opinions. In something like, you know, just to use that example of the outdoor industry, I mean, everyone had a common passion for the outdoors, and that always— it was a very, very open culture, really fun, and everyone was in it for, for just, hey, how do we, how do we get out and play more, right? Technology is a little bit of a different, different beast. Okay. So you've got your IT teams trying to just what, make things work.
You've got your cloud teams that have a completely different era. I mean, I think for most of us that are listening to the podcast, we've had a lot of experience with the security. We've had a lot of experience with the IT, but I'll have to be honest with you. This is the first time I've heard anyone say that the cloud was different, at least the support teams for them. How is it different?
So certainly in some, in a lot of organizations, the IT teams transition into cloud teams. But when you look at organizations that are still managing significant on-premise data center environments, so you have a hybrid sort of setup, those teams are still very, very different and they operate completely, really in completely different spheres. And there's You know, I've always said I know what it's like to go from IT to cloud, right? I did it myself and I remember the fear. I remember working, I was in IT for over a dozen years and cloud came along.
And as I said earlier, the light bulb went off and I remember that feeling of being terrified of like, wait a second, I have all this stuff that I need to learn and move to. Now I was excited about it, But it was also incredibly intimidating. And I see a lot of IT teams that still avoid moving in that direction, or they sort of move in baby steps because it's really challenging. And it could be where they're at in their career in terms of later on in their career, and they don't want to learn new things. Or it could be that they're just really comfortable and really adept and skilled at, you know, in the particular domain area, areas of domain expertise where they're working.
But every organization, every culture again is really different. And there's still a lot of— and resistance is not necessarily the right word, just a lot of intimidation and a lot of, hey, I'm really comfortable here and I don't want to necessarily move in that direction. At the same time, I actually ran into someone last night at the gym who was working in HPC at— used to work at NREL and he worked at NREL HPC and he completely transitioned into cloud and he absolutely loves doing what he's doing. So it just really does depend on the individuals and how the organizations are structured in terms of really facilitating those types of career transitions. Well, I have to disagree though with you a little bit because I think there is a resistance sometimes to go to the cloud.
And I think you nailed it though with the fear, the avoidance, possibly learning a new skill. But what about control? I mean, when we have stuff on-prem inside in our own infrastructure, We have, for the most part, absolute control of everything. How do you turn over that control to AWS?
I, you know, getting into the discussion around, you know, remember early days of cloud, right? Cloud was, they were marketing themselves as it's more secure. And of course, the on-premise was saying there's no way it's gonna be more secure. And of course, the answer lies somewhere in the middle because it doesn't matter physically where most of these systems reside anymore because all these systems have some sort of numerous public access points, right? So I'm not going to necessarily, necessarily have that discussion.
But the, the resistance with regards to on-premise and saying this is more secure, that, that does exist, absolutely. And I could think of a number of places that where I worked where that was, that was a challenge. Over time, that resistance has broken down, right? You saw it much more so early on when cloud was first being adopted, and now you're seeing much more hybrid solutions being accepted and then managing, you know, whether it's the toolsets that they're working with, the configuration management frameworks, you know, whatever it is to try to manage across those hybrid environments, a lot more of that is happening to sort of make people feel at ease that, hey, the way we're managing on-premise is actually similar or identical to they were managing it on cloud. So I think that those walls are breaking down, you know, for the most part.
It doesn't mean that there are some organizations that are gonna be— they're still gonna be hugely resistant to that. That's gonna depend on leadership and culture, right? I don't think there's any objective facts that are gonna say this is more secure versus that on-premise is more secure than cloud. It's really gonna be a matter of subject matter expertise. It's going to be a matter of leadership.
It's going to be a matter of how you develop those policies, how you develop those procedures to create secure environments. Okay. So as a chief cloud officer, right? And of course, the president of CSA Colorado, you're in a leadership position. You are trying to get your people and convince your people to move over to the cloud.
And there is some resistance there. Right? And of course, you have your positioning and everything else. What advice would you say? What would say, no, we have to do this without, of course, you know, throwing that hammer down.
You want to do it from a more convincing standpoint. So I don't necessarily spend a lot of time trying to convince organizations of why they should move to cloud just in terms of the role and what I do. First of all, most of my clients are SMBs, small, medium-sized businesses, often startups. Technology-enabled sort of companies that have their own development shops and those sorts of things. Most of them, all of them have some amount, if not entirely, a cloud presence.
So I typically work with those teams that are either moving to cloud or already in the cloud and just facilitating, you know, just making that work, you know, more better, right? In terms of organizations that I work with that are hybrid, Often what you see is very separate teams. So you see that cloud centers of excellence in large organizations that are created, and those are often very independent from the on-premise IT team. So a lot of times the hybrid approach is often very separate teams, and they actually don't necessarily play well together, or there's just a sort of a clear line there. Again, going back to the silos that exist in a lot of larger organizations.
So I don't spend a lot of time. I, you know, when I worked at NREL, one of that was one of the biggest challenges was actually trying to work with the IT teams to get approval for certain cloud projects. And it was challenging. I'm not gonna lie. It was a real challenge to sort of figure out how to convince them that we're gonna do this right in the cloud.
Okay. Okay, so now you're the— you are the president of CSA in Colorado chapter, but I heard something about you almost resigned from the board. So not many people know this, so some people might listen. So we— so the— I was— I've been a volunteer with CSA Colorado for a number of years on the board. And but see, so CSA Colorado is entirely volunteer-driven.
It's a nonprofit. We do— we just are— our goal is to try to enhance in-person educational and networking opportunities for Colorado cybersecurity professionals. And there's a, it's a huge labor of love for everyone that's on the board, for everyone that volunteers for it. So it's a lot of work. I'm not gonna lie.
It's like my second, second job, but the, the one that I don't get paid for. And, and so last year, and we've been doing this annual summit or conference, which I'll, I'll talk, we'll maybe talk about at the end. And last year we did a conference on security compliance and privacy. And, you know, it's a one-day conference in Colorado. We had a number of speakers, a whole bunch of different sessions, a panel, you know, a lot of vendor sponsors, tremendous amount of work to put it together.
And it just, it almost broke me. I mean, it was just so much work and I was literally like, you know, at the end of it when we got through it and it was a successful conference and it went well, but I was just burnt out. I mean, it was just hard. It was a lot of work. It's a lot of herding of cats when you're dealing with with a board that's again all volunteer and they have their jobs and their lives and everything else.
And I had the resignation letter all written out, you know, I was like, I was up after the conference, I was like, I'm done, like I'm done. And then Tyler Warren, who was the president at the time, came to me and said, you know, he wanted me to, to, to be president, the next president. He was going to sort of put his vote in for me. And so I sort of reflect on, I'm like, okay, you know what, it's, yeah, it's a lot of work, but it's also very rewarding. And if I was at the helm and I said there were the things that I might want to do a little bit differently and sort of, you know, really what's important to me in terms of what I want to do for the community, I thought, well, you know what, maybe that's the path to go.
And so resignation letter is still somewhere in Google Drive, but I took over as president last December and it's been great. It's been, it's a tremendous amount of work. It definitely is something that I, I have to, I have to remind myself it's not my day job because of how much time I spend on it, especially planning for this conference. But it is so rewarding and it's great. You know, our focus on in-person networking and educational opportunities to me is what, where we're trying to distinguish ourselves.
It's not that other organizations like OWASP Denver doesn't do that as well, but we've been trying to really focus on that and less on, for instance, what Colorado Equus Security does with Slack channel. People say, hey, why don't you have a Slack channel? Well, I know how much work it is to add a digital element to what we're trying to do. I'm gonna let Colorado Security do that great job and we're gonna try to enhance that in-person, those in-person pieces. And to me, the networking is so important, the in-person networking, right?
I mean, even before COVID right? But since COVID it's even more of a challenge in terms of, you know, getting people to really have that one-on-one interface, right? The water cooler is dead, right? We don't have that water cooler conversation and just that flyby sort of conversation that existed in offices where we could just talk about a problem or talk about a particular situation that, that was, is going on, whether it's in security or IT or whatever else. All that is diluted now, right, with, with, with all the, the digital stuff that we're doing.
I'm trying to do what I can with the Cloud Security Alliance Colorado to sort of really bring back some of that really in-person networking pieces where I can. And by the way, from a career perspective, when you talk to the HR people in cybersecurity, Right? They talk about how the HR funnel is, is broken. You, you can't throw your resume in with 4,000 other resumes. It gets funneled through AI machine learning algorithms to a handful of, of resumes that humans finally see.
Like, that doesn't work, right? What does work is that networking. And so we're trying to do everything we can to enhance that. Well, some people know this already about me, but I teach a lot of university classes and I kind of tell them the same thing. That it's not just what you know, it's who you know in this industry.
And of course, listening to this podcast, going to the Slack channel for Colorado Equal Security, CSA, OWASP, etc. I know it takes a lot of time to— personally, I know this, that it takes a lot of time to put yourselves into a nonprofit. But I think that you also have some time to walk your dog at times, and you've come up with a new way of doing that. Well, so this is an old, old story. So I mentioned that when I first came out to Colorado, I was basically just, I was basically climbing full-time.
That was my, that was my job. I was just a climbing bum, which doesn't really pay the bills. And at some point I was, but what was paying the bills, I was actually dog sitting. I was doing dog sitting for friends. And one day I was a climber, so I had the, you know, carabiners are, right?
That's what, that's what you attach your, your, your ropes to, carabiners, little clips. And I was walking these 2 dogs and I sort of attached their leashes to, again, dating myself, to the fanny pack I was wearing with this carabiner so I could have my hands free. I'm like, huh? And I had a lot of time on my hands because I really didn't have much by way of a job. And I had a, my roommate at the time had a sewing machine.
And so, I ended up building this belt that goes around your waist that had shock absorption built into it. And you could, with a little quick release buckle, you could attach any leash to it. And I called it the Hands Away Leash Belt and I, and it was the new way to walk your dog. That's what I was, how I was advertising it. And I, I went around to all the trade shows around the US and was selling this product for, for a couple years along with a couple of other little ancillary products.
And yeah, that was my random sort of career move, but I didn't really know how to run a business. I had no idea what I was doing. I was just looking for ways to support my climbing habit. And lasted a couple years. It's still a great idea.
It, it was, it was, it's still a great little product. It was a patent pending, but I never actually went through with the patent because I just decided to actually get a real job instead. But the new way to walk your dog, that's what it was. I like the way that you put it. It's a climbing habit, like it's an addiction.
Here's something though. So you're walking your dog or you're addicted to climbing, but somehow in the Flatirons you ended up naked. So have you seen Free Solo? Uh, I have not actually. Okay, so that's the story about Alex Honnold, really famous climber, and he climbs El Capitan solo, which is an amazing feat.
And people who don't climb look at it and go, that's like, that's insane, that's nuts, right? But in his world, that's all he does, right? And, and so when you look at it from a risk perspective, people look at it externally and they say there's a huge amount of risk that he's taking, but in his world it all makes sense, right? His risk threshold is very different than sort of your average person. When I was climbing full-time, things that, you know, look crazy sort of made sense.
It was just part of my world. And so the Flatirons up in Boulder are these known to be these very— you can obviously see them when you drive into Boulder, the Flatirons. And they're, they're these slabs. They're not very hard to climb, but they're very long, so 800 feet high, that sort of thing. Um, and I just— it was my backyard.
It was a place that I'd go, and I was just— I was climbing all the time. And so you just kind of like make it interesting. And so, you know, one year I, I had my holiday card one year, and this— so this is before, you know, phones, right? So I took one of my cameras up there and I made a very tastefully done holiday card where I had to like position the camera on the slab so that it was like horizontal, and then I had to like set it on the timer and sort of scoot over and, and strike a pose wearing no clothes, just my chalk bag and my climbing shoes, and then get back. And of course it wasn't for a few weeks until I knew that if it came out or not, but it was on my holiday card one year.
And you know, I did that a few times. Again, it just kind of made sense. It was just kind of a fun thing to do. I'd never considered it risky because again, that was my world at the time. Okay, okay.
But you really do love the outdoors and One of the things about it, I think, as I look through your profile and everything, the land of no service, right? I mean, we're attached to our phone these days and especially again in cybersecurity, we have our phones and trying to navigate with our phones sometimes we become dysfunctional. Some people do. I mean, I carry actually, believe it or not, I carry 3 phones with me at all times. So, so let me ask you this.
Ask. Okay. When do your most creative ideas come to you? When do your deepest thoughts come to you? My deepest thoughts?
Oh, I think you and I have at least some kind of alignment. It comes when I'm walking my dog and, uh, doing anything else. I'm just enjoying the walk and seeing what interests her with all the sniffing and everything else, you know. And they say, you know, Einstein came up with a lot of his ideas on his bicycle, right? I mean, when we're just— when we're free, right?
When we let our minds go. And, and so I recognize that. I'm obviously, I'm quite the digital native. And yet at the same time, I recognize that, you know, this technology is not who we are. And so for me, I just love getting away from it when I can.
And because it is where I explore my creativity and my limits and do a lot of my deepest thinking. I mean, to prepare for this podcast, I went on a walk this morning, you know, and wrote down some ideas without the distraction of a phone and And the constant, you know, just, just the distractions of, of all our notifications. And so for me, yeah, when I go, I don't— I like to go camping, I like to go backpacking, I like to be out, out in the wilds. And I really do like— my favorite place is no service, whether it's out in Utah, whether next week actually, although this— I don't know when this podcast is airing, but I'm actually headed out for a multi-day backpacking trip out to the Lost Creek Wilderness. And the favorite part about that is my phone's not going to work out there.
And I'm really, really psyched about that. That actually sounds very, very nice. Well, this is the Colorado Equal Security Podcast. And so let's talk about some security issues here. What do you think is today's greatest challenge?
Now, I'm not saying solve it. We do need to address it. But what do you think is the biggest, largest security challenge? What is top of mind? So there's obviously a lot, right?
And I could bring up things like ransomware, API security, those sorts of things. But I'm gonna sort of go back to some of the theme of what we've been talking about up till now and talk about sort of the people and process side of it. So it's very easy to talk about all these security tools and processes that need to be in place. But at the end of the day, I spend a lot of time with my hands on the keyboard. I spend a lot of time with companies that are trying to drive business value.
And the practical management of a security program that really is, is doing a good job of improving security posture over time is just really hard. It's hard to do it on the ground. We could talk about, oh, you got to patch your stuff. Yeah, patching is, is hard. As much as there's all these great tools out there, when you try to intersect that with business value and maintenance windows and all the things that businesses need these days.
It's just like, practically speaking, it can be really hard to do even with immutable infrastructures. It's hard to do because you have to make sure you're running it through your pipelines and through your lower environments before it gets tested and through the upper environments. Shifting left is fantastic. All the toolsets that are coming out right now to make it easier to shift left is great. But at the same time, It's just hard to make that transition and to do it consistently.
Well, I think a lot of the tools that are coming up in that space, I think a lot of the vendors are doing a fantastic job there. Even a WAF, right? A web application firewall, right? Very easy to put in place. Tuning it's really hard to a point where you're not impacting your valid customer traffic, right?
And some people say, well, WAFs don't matter anymore. Everything matters. All these layers, all these layers of the security onion. Matter, even if certain things might be more important now than, you know, and other things are less important. And identity access management, still hard, right?
We still haven't— it's just getting more and more challenging over time. And when you start working with more mature organizations that have been working in cloud, for instance, for a long time, shutting down things like, you know, IAM, you know, excessive privileges and those sorts of things, the risk introducing that you're introducing to organizations when you want to sort of tighten things up. It's just hard. It just— all of it is hard. And so I think when it comes to it, what I see a lot and what I deal with a lot, again, with my hands on the keyboard, is we want to improve security posture.
We want to make incremental improvements to the environments. And we just have to recognize that it's going to be small steps. Make sure that we have our goals in mind. You know, the things that we're trying to achieve by way of compliance or by way of controls. But just recognize that it's going to take a while to get there and it's never, it's never ending.
Okay. So here's— is that what you would call shifting left? I mean, it's a buzzword these days. At least I see this as a buzzword, is shifting left. What would you define shifting left to be?
I mean, shifting left means a lot of things, right? Fundamentally, it's really about creating that security awareness at, you know, at the beginning of, say, software development lifecycles, right? Again, in a lot of the startups that I work at, that's where this comes into play a lot. So there's other sort of other, a lot of other areas of the organization where shifting left applies as well. But let's just take software development lifecycle, for example.
So are you bolting on security at the end, right? Where you're saying, okay, we built this application. Now let's test it and see if it's secure. Let's throw a pen test at it or let's, you know, run Burp Suite or whatever, you know, whatever it is. Instead, well, there's these great tools that exist now that you can integrate into pipelines for things like static code analysis, you know, SAST testing, DAST testing, those sorts of things that we could be integrating early on in the process, early on in our pipelines.
We could even prevent, you know, pipelines from continuing if certain things are detected, secrets in code and those sorts of things. So let's start applying that. Let's start applying things like secure code reviews as part of that process as well. So you're getting more interaction and more discussions between different aspects of the development teams, security teams talking to each other earlier in the process to really look for those, asking it from a perspective of security, not just is this good code, but is it secure code? Is it secure infrastructure?
Those sorts of things. Are you applying standard best practices early on in these processes? So it's It's a lot of it really is again that people and process combined with the technology combined with some of the technology that's out there. But shifting that mindset to saying, hey, security is important. We're not just going to bolt it on.
We're going to be having those conversations earlier in the process as the, and not just earlier, but throughout the lifecycle, product development lifecycle as well as software development lifecycles. And that just becomes part of what we do and how we do it. Hey, that's, that's again, that's very interesting because I agree with you. It's a, it's a buzzword. It's floating around.
It could mean different things to different people. But it sounds like really it's something that all the security professionals on this podcast, listening to this podcast really want is let's start building security into the products before we even start. Stop having it as an afterthought. So because I bridge the gap between sort of the security world and development world, the DevOps world and the sort of leadership level, I see when you talk to security professionals, they're like shifting left makes sense. We just have to do it, right?
And they're not wrong. But when you talk about what businesses are trying to do in terms of driving business value and get products to market in highly competitive environments, you understand why it's hard to shift left and why it's hard to, you know, to slow things down, to put these processes in place and to manage these processes and these pipelines over time. So I understand the tension that exists and the way my just general approach is always sort of middle of the road, which is like, let's talk about incremental improvements to get to a better place. To me, that is, I see that making a difference. The biggest challenge is keeping that pressure on, right?
Don't let inertia sort of slow it down. You have to constantly be really looking at how we're okay, we're making improvements. Now, what's better than that? What's better than that? And we need to constantly have that conversation to sort of really align those, that security mindset and that business value.
I think you're definitely saying the things that the security professionals listening to this podcast definitely want to hear, right? Is that, that incremental side, getting to that goal, keeping up that momentum. If we started talking about that, I'm pretty sure we'll go on for about the next 3 to 5 days nonstop. And I do have to actually come up to an end of this podcast. I do want to thank you though for your time.
We do have a couple of events coming up here. Uh, next week, next Friday, September 8th, 2023, BSides Denver is coming in. Okay, there are some interesting talks, including one called Going Undercover in the Underground, MITRE Mayhem, and then The Tragedy of Commons, and it's all about phishing. We also have another conference coming up, the CSA conference on October 25th. You want to mention that a little bit, Aaron?
Can we talk about that for the next 3 or 5 days? Because that's what I spend my time doing. I'm pretty sure Robb and Alex will get upset with me, but I'm looking forward to seeing you there, Frank. So October 25th, October 25th at the Cable Center in Denver. You can find out more about it by going to csacolorado.org.
So this is going to be a pretty unique conference. So this is the 6th annual conference that CSA Colorado has done, and it's going to— the entire content all day is going to be talking about the intersection of AI and cybersecurity. So all day, every day, all day that we're gonna be, this is what the conversation is gonna be. This is what all the, you know, in between the sessions is what people are gonna be talking about. It's a curated group of speakers that are all handpicked because they have a level of expertise in this intersection.
And obviously it's pretty important in terms of timing. We came up with this idea in Q1 of 2023, right when ChatGPT 4.0 was hitting, you know, as hard as it did. And we suspected and hoped that the conversation would just even be that more important in the fall when we're having this conference. And we're not wrong. And it's going to be a great conference along with the speakers and of course the networking, because the networking obviously is really important to me and some great sponsor vendor sponsors that are going to be there.
We're doing a couple of really interesting things as well that are, that are pretty unique. One, we're going to have a couple of kiosks set up and those kiosks are going to allow people to explore prompt engineering with ChatGPT. So you hear a lot about this. With this kiosk, this UI is gonna really help you understand what that means. We're also gonna be doing a panel discussion, except all the panelists are gonna be ChatGPT roles.
So we're gonna have a Russian nation-state hacker role. We're gonna have a CISO of a large financial organization and then a third role as well. And these, this session is gonna be, they're gonna be interacting with the audience. In voice. So this is going to be a very futuristic sort of approach to how we're going to be interacting with these AI models in the very near future.
It's going to be really exciting. It's— you'll be pretty amazed at how deep you can go if you role-play ChatGPT correctly. Well, that's— again, I, I think that's going to be awesome because I remember your talk at our SnowFROC conference. It was all about Alexa, right? You had something about Alexa with us.
I was using Alexa to, to basically deploy Well-Architected Framework, so secure infrastructures in AWS. And it was an interactive discussion I've done several times where Alexa was actually doing everything for me, which included creating infrastructure, securing the infrastructure, attacking the infrastructure, remediating security issues, and then destroying the infrastructure as well over the course of the session. It's a lot of fun. Okay, well, that again, I think that anyone that's interested in AI should come to your conference, whether they're interested in cloud or not. And any— I think that AI is going to be both a benefit and a detriment to IT security, probably pretty soon, if not already.
Yeah, challenging discussions around that. And that's a lot of what's going to be talking about— talked about in in these sessions. I've been telling the speakers very briefly, I've been telling the speakers that if the people attending their sessions are a little more scared after the session when they went than when they went in, they've done their job right. Okay. Well, I want to thank you for your time.
I appreciate especially coming in on a weekend and talking to me and doing this podcast on a weekend. My name is Frank. I am on the board for the Denver OWASP chapter. We are planning our annual SnowFROC conference for 2024. It'll happen sometime in March.
If there are any volunteers, anyone that wants to help out with this conference, we're going to start off with our call for sponsors. Please contact me through the OWASP Slack channel or my email. My contact information is everywhere. Again, thank you, Darren, for your time. I appreciate it.
Darren, again, is the Chief Cloud Officer of Cloud Button. He is the president of the CSA Colorado chapter and an all-around nice guy. So thank you again, Darren. Thanks, Mike. It was really an honor.
I really appreciate it. Appreciate it.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.