All episodes

Douglas Brush, Founder @ Accel Consulting

Apple Podcasts Spotify SoundCloud

Douglast Brush, Founder and Court Appointed Neutral of Accel Consulting is our feature interview this week, interviewed by Frank Victory. News from Xcel Energy, Guild Education, National Cybersecurity Center, Coalfire, Red Canary, Zvelo and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript18326 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 254 for the week of November 6th. Alex, it's remember, remember the 5th of November time.

It is. Do you remember? I remember the movie V for Vendetta, which is one of my very favorite movies. And the, like, the monologue where he just says all the V words. Anyway, really good stuff.

Natalie Portman is the— is one of the stars of that movie. I remember November 5th for different reasons. I have some family members with birthdays on the 5th. So there you go. Yeah.

And what's your mother's maiden name?

Yeah. And I'll just like list out my Social Security number as well. Could you, could you take a picture of some place where I was born and scratch off the thing on the back and send a picture? Yeah, will do. Hey, before we jump into the news, just as a reminder, we have a Slack channel where we'd love to get you guys connected.

Go out to colorado-security.com and click the Slack button to get in. And while you're there, go to the bottom of the screen and join our newsletter where you'll get things such as our, our newsletter each month and also any kind of announcements coming up like, like the recent, uh, well, today the charity event we did. Yeah, it was a great turnout at the charity event. Uh, also please rate us and subscribe on your favorite, uh, podcast player. We'd love for you to do that.

Also tell a friend about Colorado Equal Security, whether it's the podcast or the movement or the Slack workspace or any of the events that we're having. All of that stuff. You mentioned the new promotion. Um, everyone who gets a new subscriber gets one free month of the podcast. Hey, I forgot to tell you that does stack.

That does stack. You can, you know, if you get us 10 new people, you get 10 free months. There's no limit on the amount of free months that you can get. Finally, if you would like to have a not free month, you can join our Patreon campaign and help support the movement financially. We use that money to pay for hosting and, you know, all the other things that go along with Colorado Equal Security and fun things, fund things like, uh, the picnic and other stuff, the charity stuff.

We did charity stuff. Yeah. Although this one was actually taken care of. A big shout out to Voodoo Donuts who supplied some donuts for our, for our volunteers today. And, and we were planning to pay and we didn't have to.

So thanks to that. And big thanks to Ben Fellows and Chris Abbey and Doug Brush who helped put the whole thing together. Yeah. Let's jump into the news. All right.

Hey, we have a story here about a recent bit of research that was done by a real estate company called Zonda. They were looking at what is the average— or sorry, the median home price in different cities around the country. And Alex, what did they find? They found that Colorado has the 4 most expensive housing markets in the US not on a coast, which we don't know exactly what not on a coast means. But, you know, assuming that you're just kind of knocking off whole states, still kind of amazing, right?

The top of the list, no surprise to us, is Boulder. Yep. Going down, we got Denver, Fort Collins, and then This was the shocker to me. The fourth most expensive city in the country that's not on the coast. Greeley.

Greeley. Yeah. Yeah. I thought that that was one of the more affordable places in the state. Yeah.

Part of what they said here was that as places like Denver and Boulder and Fort Collins have gotten more expensive, people have looked for cheaper places. And that sounds like it's been Greeley. Yeah. I would have been less surprised if it said Colorado Springs. Yeah.

It doesn't. It doesn't have that. But, you know, I know. Boulder is known for being an expensive place. I was surprised at exactly how expensive it is, though.

The median home price in Boulder is $833,000, which is more than 2 or about $200,000 more than the second highest at Denver. So call it, you know, a third more expensive than any other city in the country. To me, that was pretty surprising. Yeah. One of the other things that I noted was in 1980, because they also did this, the same investigation for different time periods.

In 1980, no non-coastal market had a median price, median home price above $100,000. Crazy. Yeah. And now we have, you know, $600,000, $700,000, $800,000 median home prices. And they say if, you know, if prices had moved at the same rate as inflation, you know, Boulder should be somewhere in like the $400,000 or $500,000.

Yeah. Yeah. For a $100,000 home back in 1980, the equivalent today would be $390,000. Yeah. So obviously the appreciation in real estate has been very significant.

Not as much as the appreciation in the stock market if you're trying to, to do the math. But really interesting. And it's, I guess, kind of a good news, bad news situation. It's nice to know that a lot of folks want to live where we are. Not a great time to have to buy a house in Colorado.

Yeah. If you're somebody that's been here a long time and has owned a house for a while, then you are on the plus side. If you're somebody that's trying to move to Denver, not so much. You might want to move to Oklahoma. Yes.

All right. Next up, we have a story talking about why Denver is— 10 reasons why Denver is a bastion of geekdom. Yeah, this is a, you know, kind of a fun one. So, Alex, you know, since we've moved from weekly to monthly with the podcast, one of the things I've really appreciated is that we get a whole lot more interesting news each month. And this is— this month is a good example of not having a lot more interesting news.

So, so as an exception, we, you know, I think Westword realized there wasn't a lot going on this month, and they wrote up this story basically basically saying, hey, you know, we got the tech hub for, um, for quantum coming. What other kind of geeky things does Denver have? And, and the answer is apparently we've got a lot of geeky things in Colorado. Yeah, uh, lots of good things on this list. Um, the first thing they talk about is a history of supporting nerd culture, which, you know, I was a little disapp— I'm gonna sidebar here for a second.

I was a little disappointed in the story that they sort of, uh, conflated nerds and geeks and all of the different terms, that they are different things. They are different. And in this case, they're kind of putting them all together as part of the story. But nonetheless, nerds, geeks, dweebs, whoever you are, you're welcome here. Exactly.

Anyway, back in 1999, the very first Star Wars Celebration was held here. Yeah. And they have some nice pictures of that. The second, the kind of evidence that we are a geek city is our, our comic, our con scene. So we all know that Comic-Con has been here for years and now renamed as Fan Expo Con.

There's Genghis Con, there's this Starfest. There's a bunch of different cons that happen here in Denver. Yeah. The, the next thing they looked at was a little bit around jobs and working. Over 5% of Denver work— the Denver workforce is employed in quote gaming.

So that, that seems like a pretty high number. Yeah. And there's an awful lot of tech jobs here as well. Next one they had was around comic books. They called it a Camelot for comic collectors.

We have Mile High Comics, which apparently is the number one comic book store in the country and well known for comic book collectors. And it's just here in Denver on like I-70. Yeah. Also Geeks Who Drink, which if you've ever been in a bar on a weeknight, is you'll possibly run across that. Was started here in Denver and is now nationwide.

So I have done a round or two of Geeks Who Drink. I have as well. I don't think I realized that it started here, but that's pretty cool. I didn't know it either. So then, you know, the next one, it was going to kind of go into our next story around quantum tech.

Why don't we leave that one for now? After that, we have 2 amusement parks. You know, not a lot of cities have 2 amusement parks in them. Obviously, Elitch Gardens and the, what, 100-plus-year-old Lakeside. Although I didn't realize it, but apparently the Cyclone has been closed this last summer.

Yeah. So the oldest original wood roller coaster in Colorado has not been open. Yeah. Also Colorado, of course, the birthplace of South Park. You know, very geeky there.

And the last one, I'm not, I'm not sure exactly how I— 2 more or 2 more. Sorry. The next one was, was about Red Rocks. I'm not sure exactly how that ties into this. They're reaching a bit.

If you're a music geek, And then finally, I do think the last one is legitimate, though, that we have the geekiest governor, Jared Polis. I don't know if you watched his State of the State where he did his yoga— sorry, his Yoda quote and Lord of the Rings references. Like, yeah, he's a pretty good nerd. Yeah, he's hardcore. Yeah, he's one of us.

Yeah, for sure. All right. Anyway, that's, that's kind of the fun story for the month. Jumping forward, you know, as we just alluded to in the last one, this is actually some pretty big news. Colorado has officially been designated as a national tech hub.

And they were doing this in different, different technology areas. Well, we got the Tech Hub designation for quantum technology. Yeah, I know that there was the push to have us designated in a few areas, and this is the one that won out. Yeah. So we had looked at maybe security.

I think that somewhere along the way they kind of dropped off. Colorado stopped pushing for a couple of them. But quantum, you know, as we're looking at quantum computing and what does that next iteration of the computing paradigm look like? They did a good job of advocating for Colorado as a spot to do it. Now, interestingly enough, on this topic, I was listening to the Colorado Sun morning podcast.

It's called the Colorado Sunup. I recommend it if you guys want some local news. Tamara Chuang, a friend of ours, reporter for the Colorado Sun, was on there trying to describe the impact of this. And listening to her try to describe quantum encouraged me not to bother to try. So I will say I cannot describe to you how quantum computers work differently than traditional processing other than to say it's really bad for secrets that are in traditional encryption?

Qubits. That's my contribution. Well, thank you. Is that like the biblical, like, measurement? 2 qubits long, whatever?

Yes. Thank you for that. Anyway, so as you know, so what does this mean being designated a hub? Basically, it means access to funding, right? Like, you're designated this way, the government is putting aside $10 billion initially, $500 million is available.

We don't know exactly what that means or how it's available. But, you know, I assume that's for attracting companies, you know, helping companies in whatever area that it is that you're designated for. But I mean, $10 billion is nothing to sneeze at across all of these tech hubs. And, and one of the things I heard was that the government recognized, you know, Silicon Valley as a hub for technology was great, but having all of our, all of our technical smarts in one place was not so great. Right.

So they were looking to see what can they do to encourage building those similar types of hubs. In different parts around the country. Obviously, Silicon Valley is going to continue to be, you know, a powerhouse in technology. But, you know, as Denver spins up and as, you know, Boston and Charlotte and Seattle spin up as big tech hubs, you know, it adds more, more resiliency to our economy and to our technology. Yeah.

Speaking of tech, our next story is sort of about Xcel Energy, but also sort of about the data center provider QTS. They're building a brand new data center. It says it's C470, but I'm pretty sure they mean E470 and I-70 because it says it's in Aurora. C470 and I-70 don't meet in Aurora for those that, that are trying to keep score here. Anyway, this is going to be a gigantic data center and it's going to end up being one of Xcel's biggest customers for electricity.

Yeah, I found this interesting for a couple of reasons. Number one, I don't think I realized And, you know, Xcel is a private company, but it gets a monopoly in the space because of the oversight it gets from the government and some visibility the government gets. Xcel can't choose to increase its rate. It has to get approval to increase rates. So everything they do around pricing is pretty well researched and, you know, diligenced.

So this story is really about the fact that Xcel wants to give some really steep discounts to this data center to move into town. And as a part of that request to do so, we get a lot of visibility into the fact that this is going to be their biggest customer, you know, surpassing— what's the name of that cement company over there, like at the base of 25 in the mountains? And yes, a couple other— couple of those types of like big manufacturing companies. Yeah, they did say that previously, Evraz— I don't know how to pronounce— Evraz Rocky Mountain Steel in Pueblo was the, the biggest individual customer for Excel. And, and this, the QTS can take over as that with the amount of electricity they're going to be using in this data center.

And this isn't even QTS's largest data center in the country. No, they talk— I don't know QTS, but as, as we— as I read through the article, they are owned by Blackstone and they— it looks to me from like the way they drop hints that they service like the big telcos, the big web properties, you know, your Facebooks and so forth. I'm just guessing from the way this is written. That they're serving those companies and the processing power they need is way more than you get from your traditional data centers that you and I have probably toured multiple times. Yeah, this I believe is going to be QTS's 3rd largest data center.

The biggest one is in Arizona and the 2nd biggest one was, now I lost it, but, oh, in Atlanta, sorry. Yeah. So anyway, so it's going to be a big, a big development out there, kind of on the way to DIA. If you're, if you're coming from Denver, looking forward to seeing the news on that. Good stuff.

All right. We have some update from one of the tech companies. We've talked a lot about Guild Education. They're not called Guild Education anymore. Now they're just called Guild.

But we've talked about them quite a bit in the past. The headline here in this story is Denver area tech unicorn Guild just made a big investment in AI education. So I was expecting to read a story that said they put $50 million into something. Right. It's not exactly what it looks like here.

Yeah. I mean, basically, I think that they're just, they're gonna be offering AI education as part of their programs. Yeah. And, and for those who don't know, what Guild does is they, they, they, they're a benefit that employers can offer to their employees to help them do continuing education kind of while they work. So they partnered with McDonald's and Walmart and some other big companies.

So if you work there and you wanna move in, you know, you're a cashier and you wanna move into IT, Guild has a set of courses that can help you get ready for that. And they just added now a new program around AI and how do you do data science? How do you, how do you utilize AI? So they're going to be upskilling the employees at these different companies to, to be able to do AI. Yeah, it's just sort of a different method than sort of the traditional, you know, tuition assistance where you're sending somebody back to college or to college for something.

You know, it can be smaller bite-sized pieces as a benefit, and also maybe not with the same sort of prerequisites you might need to take a full college degree kind of course. Yep, good stuff. What do we got next? Next, we have a story from the National Cybersecurity Center. They held a training and a kickoff for some Project Pisces stuff.

Yeah, we've talked about Pisces on here before, I think not that long ago. This is the, the open source product tool that is developed with kind of a combination of Metro State and some other organizations. And Richard McNamara, who we actually have on the show next month, is one of the guys running this and is quoted in this article. Alex, what is the, what is the impact here? What is Pisces doing?

Yeah, so, so Metro State has been working with the Pisces program pretty regularly. The NCC got involved and sort of pulled in couple other Colorado Springs area schools to get involved with Pisces as well. So this was kind of the kickoff, I think, and discussion around those schools down in Colorado Springs joining the network and now having more people available to do the free monitoring that Pisces does for government institutions that can't afford it on their own. Yeah, I feel like the model here is, is just so good and something that needs to be replicated you know, 100 times over. Basically, as a part of education, they have created a, a security operations center that can monitor like municipalities and other government or, you know, public sector entities that don't have the funding to do their own SOC and can't afford to outsource.

They have the students as the ones running the SOC. Now, hey, you know, they're not going to be professional yet. They're still learning as they go. But my goodness, it's a lot better than nothing, right? Better than nothing.

And the students get real-world experience. Looking through these tools, looking for bad behavior, trying to combat that behavior, I imagine. And the companies get, you know, free protection. I think it's a really cool model and I'd love to see other, other folks embrace that. Yeah, I know many people complain about students coming out of higher education programs for cybersecurity about not having real-world experience, right?

You've learned all this stuff in books, but you don't really know how to do anything. Uh, the, the people in these programs are getting that real-world experience and they are going to have a leg up on other people because of it. Yeah. And you and I have both brought in folks from other cybersecurity educational, you know, tracks. I would love to have a chance to work with someone from Pisces and kind of see what that experience has been like.

That'd be fantastic. Yeah. All right. Next, we have a blog from Coalfire. Actually, we have a couple in a row that are blogs from Coalfire.

The first one is talking about maximizing the value of threat modeling, which is a super important thing that we can be doing. Yeah. You know, I go back and forth. This is not about the article, just my take on threat modeling. Threat modeling, I go back and forth.

It can be too trendy, just like anything else. It's not any kind of a fix for everything, but my goodness, if you don't know how bad guys might try and misuse your system, you're very unlikely to put controls and detections in the right place. You got to, at least when you're creating or when you get comfortable in a place, do threat modeling, figure out what bad guys might want to do, you know, kind of snapshot point in time that you can go update later to help educate the rest of what you do around your program. Yeah. I mean, even if you're not getting super deep in threat modeling, the concepts of, of what you're talking about, thinking about how bad actors might interact with whatever it is that you're trying to threat model, right?

Like that sort of thinking is helpful in making sure that you have the correct defenses and you've thought about the things that could go wrong. Yeah. To your point, like a guy like, like me or you who, you know, not as technical, not in the code, We can get a lot of value out of understanding like high level what bad guys might do. Whereas I might have an AppSec engineer on my team who's going to like get much more into saying, hey, this is, this is an API in the system and how can this API be misused? Both of those are valuable, but my goodness, if you're not doing either of them, you're probably just blanket applying controls that may or may not be applicable to that system.

Yeah. Anyway, what is this? What is the article? So anyway, the article talks about threat modeling, how to do it. And how to do it well, right?

This is actually a very long blog post and it goes into a lot of detail about threat modeling and the best ways to do threat modeling and the values and things like that. So I don't know that we need to get into all of the details, but I think it's definitely worth a read if you are interested in threat modeling. Well, I wrote my own list of 4 key takeaways. Number 1— You wrote them? Well, I read a list of the 4 key takeaways that was at the top of the article.

Number 1, list and evaluate all assets the system. Okay. Number 2, use threats to derive design requirements. That seems reasonable. Number 3, create independent tests for each threat scenario.

Okay, again, that sounds smart. And finally, implement detections based on the threats and tests. Yeah, I, I might change detections to a different word, like could be preventions, could be preventions, detections, uh, controls, just controls. Yeah, whatever. Fair point.

Good stuff. As you mentioned, we actually had 2 stories from Coalfire this month, which might be the first time we've ever done that. They actually had some other interesting articles this month as well. Yeah, they had a large swath of stories this month. A productive month for Coalfire, right?

Exactly. Which might— maybe that means they're not productive doing real work. I don't know. Anyway, this one is Guardians of the IoT: Strengthening the Security of IoT-Connected Medical Devices in the Healthcare Industry. This article talks about kind of the unique IoT risks that exist for healthcare and what it is you should do as a security leader to try and address those things.

Yeah, Robb, I bet there's 3 key takeaways. What would you say those are, Alex? These are much longer. Yeah, you picked the longer ones to read. I did.

I picked the wrong ones to read. First, that I think basically there's a lot of IoT in healthcare, right? Like every medical device is an IoT device and, you know, you need to make sure that you are protecting and addressing those. Not surprisingly, there are a lot of security challenges around those IoT devices. That's the second thing.

And then, you know, finally, you gotta make sure that you are putting controls around those devices and they may not be the controls directly with those devices, but it could be access control, it could be segmentation, it could be updates, you know, other things like that to make sure that you're reducing the risk of problems with those IoT devices. Yeah, I think that one of the things we hear from our friends in the healthcare industry all the time is, they have this old equipment that still works great. Yeah. But you can't, you know, it's, it's on, you know, NT4 or whatever. Like you just, you just can't do anything to it.

So the ability to, to, to put controls, you know, you know, segmentation controls, detective controls, all things outside of the system itself is, is a big part of success there. Yeah. I mean, if you have a, you know, multi-hundred thousand to millions of dollar device, right, you're, you're not gonna put that on a normal technology refresh like a laptop. It's gonna stay around for a lot longer and you're gonna have to do some, um, interesting and different things to make sure you keep it secure, which is exactly why they are so susceptible to ransomware attacks and, and why we hear these stories in the news about, you know, hospitals being shut down because they, it's so hard for them to secure. I, I do not envy our friends who have to run security at hospitals.

I do not either. Healthcare is hard. Uh, speaking of adversaries, we next have a blog post from Red Canary talking about emulation. Uh, it's a great headline, Validating Detection for Gootloader with Atomic Red Team. Yeah, you know, I don't know anything about Gootloader before reading this article.

Um, I, I do know that the— our friends at Red Canary do a fantastic job of, of identifying threat actors. And, and what I, what I love, and this is another example of, is I didn't know anything about it before reading this article, and now I walked out feeling like, you know, pretty comfortable that I, that I understand what's going on. You know, search engine optimization poisoning compromised websites to get folks to, to, uh, download a malicious, uh, archive. Um, basically, this is a way that they're trying to get in, and what do they do once they're in there? All that's in the blog post.

And if you're interested in also understanding this with, you know, maybe 5 minutes of reading, it's a good read. Yes, this, uh, we usually get a couple different kind of Red Canary, uh, blog posts on the show. This is those, the kind that is the super long, deep technical one, with all the details. So if you want all the details, they are there and you should go check them out. Yeah.

I'll say the kind of thing that's in here is the stuff that your junior SOC should read and learn how to think about adversaries. All right. Final story. We have a blog post from Zillow about cyber insurance, tightening the reins to lower risk. Yeah.

You know, cybersecurity insurance, excuse me, has been a big topic for a decade now, probably. And I'd say over the last 2 or 3 years, we hear these horror stories of, you know, renewals where cyber insurance premiums, you know, triple, right? Quadruple when folks go to do it. You know, this talks about the fact that cyber— that insurance companies are realizing, you know, trying to insure Company A and Company B is not the same thing. I need to understand the risk of what I'm getting into.

And this goes into ways that one can control those costs and be able to get the coverage you need. Yeah. Well, a couple of the interesting things I picked out of here, because I've gone through some of the, the renewal processes that have not been super fun to do. Um, they, they talked about a couple things that I hadn't heard of before. Um, well, actually one that, that I have, one was, you know, sometimes, uh, as part of lowering the risk, the insurance company will require you, require you to use specific security vendors, right?

Like, we know that this vendor is good. We need you to use them for XYZ, whatever product. I have heard of that. You know, more often it's a suite of type— a type of tool. These are the people we approve to do this as opposed to use this one.

But the other one that I had never heard of was they said that they have seen some providers ask to install their own security appliances, not things that are managed by you in your network to make sure that they're managing that you're essentially telling the truth here, you know, a double check on what's going on. And I hadn't heard of that one before. I, I've only heard of it as a theory, not as someone actually requiring it. You know, when, when I this year went through reassessing my auto insurance costs and like every, every insurance provider that I looked at who to save me money is like, oh, well, if you install this device or you let us track you on your phone or whatever, you know, you'll, we'll reduce your premiums. And you know, it's, the really clear trade-off of privacy versus money.

And, you know, I said no thank you. But I can imagine, you know, a corporate decision to make, like, hey, what's actually going to happen if this system's in our environment? You know, what are they going to— I can see that it's actually a compelling question. Yeah, it is. I don't know.

I think it raises some interesting concerns and developments if someone else has a device on your network that is monitoring for security. Well, I've never heard of a third-party compromise impacting an enterprise. So I get that. That's irony for those listening. There's that part.

There's also, you know, the depending on how well the tool is tuned and the effectiveness of the alerts and other things like that, whether they're getting value out of the data that they're getting. I have heard of things like, you know, requiring certain BitSight or other third-party monitoring scores, which also you may say is not worth the money that you would pay for something like that. But we call that the internet mafia. Yes, exactly. Anyway, So it's a, it's a weird, wild, uh, landscape out there.

And, uh, hopefully whatever you do, you can get your premiums down without having to sacrifice things. All right. Well, that is it for stories. Like you mentioned, jumping over to events, um, we have a calendar of events at colorado-security.com and there's, you know, a good number of events coming up here in November. I think everyone's trying to get their stuff in before December and the holidays.

Definitely. All right. Uh, first off, we have a couple on November 8th. The Let's Talk Software Security group is, uh, doing a meetup on what's your biggest security challenge. And also ISSA Denver is doing their November chapter meeting on asset management.

On the 9th, we have 2 events as well. We have the, the most important event of the month, which is yours truly moderating and hosting a debate webinar. So this is not an in-person event. We'd love to have you join us on a webinar where we're gonna— we have 2 different security executives squaring off, debating around the question, will more government regulation help you drive better security? The second event that day is in the evening, and Douglas Brush and Dave Nevada— Douglas, who's our guest here on the interview this month— they're going to be talking about the new SEC reporting rule and the end of cybersecurity as we know it.

Yeah, I believe this is part of the ISSA Denver Privacy SIG, so that's very exciting. Uh, on the 11th, ISSA Colorado Springs is doing their November mini seminar. On the 14th, we have a couple more events. The Cloud Security Alliance of Colorado is doing a security insights event with James Condon. He— James is a great guy from the community, and he's over at Lacework now.

On the 14th, Colorado Springs ISSA has their November chapter meeting. Uh, on the 15th, ISC2 Pikes Peak is doing their November meeting. And on the 16th, we have 2 more as well. There's the ISSA Denver inaugural Veterans Special Interest Group meeting. That's cool that they've created a SIG for, for veterans.

And also on that day, ISSA— or say ISACA Denver is doing an SEC cybersecurity disclosure meeting. So if you go to the one next week and then the one the following week, maybe you'll know everything. Maybe. Since you've been doubling up, Robb, I'll take the last couple. On the 30th, ISSA Colorado Springs is doing a mentoring mixer and Log Wars.

And then the final one actually bleeds over into December. The Colorado Cybersecurity Group is doing their Cyber First Friday event. I believe that's down in Colorado Springs. Yep, you got it. Let's jump over into jobs.

You know, we always look for about 10 of our favorite jobs of the, of the, of the month, starting off with TikTok. If you have been working on your TikTok dances and you're thinking, my goodness, I just need more TikTok in my life, Good news for you here in Denver. They're hiring a converged security technology security specialist. All right. Maximus is looking for a VP of business information— VP business information security officer.

That's— I assume you can go by Gladiator while you're there. Yes. Tanium, which is a name I haven't thought of in a little while. Yeah, it's good to see them hiring. They're hiring a senior cloud cybersecurity engineer.

Sidebar, it's surprising to me that Titanium is still a wholly owned company, that they haven't been bought up by somebody. Seems like somebody that would be purchased anyway. Good point. Advanced Energy is looking for a manager of IT governance, risk, and compliance. So I saw Advanced Energy on the job here, and then I was driving downtown past Union Station and what used to be Antero's building says Advanced Energy.

So I wonder if Antero might be Advanced. This is like totally fact-free speculation right now. But when I— but I saw it twice in a row. Energy companies tend to change their names a lot. So that would not surprise me.

That way they can get away from creditors. I'm making things up right now. Once again, speculation. My speculation would be government regulation. But, you know, same difference.

Western Union is hiring a cybersecurity governance business manager. US Bank, or Us Bank, if you like to pronounce it that way, is looking for a risk framework professional. Datavant is hiring a head of information security governance. Kroll is looking for a Vice President Policy Writer Cyber Risk. MotiveCare is hiring a Senior IT Governance Analyst.

And finally, Meta is looking for a Security Partner for Infrastructure. I wonder the changing of names, you know, Google added Alphabet. Google still goes by Google, but it's owned by Alphabet, right? You know, Facebook going by Meta, and now, you know, Twitter changing their name to X. What is— what's going on there?

What's the trend? Maybe they're trying to get away from creditors or government regulation. Who knows? You can't be a monopoly if you can't— if you don't know my name. Right, exactly.

All right. That is it for the news. As I mentioned, though, we do have a feature interview. Douglas Brush, who is the founder. And I think he's, you know, he's a— oh, shoot— expert witness as well.

Yes. Is Accel, um, Accel Partners, Accel Consulting. Accel Consulting. He's also the, the Chief Visionary Officer. Well, there you go.

Yeah. I mean, he's got vision for sure. Yes. Um, he's, he sits down this month with our, with our very good friend Frank Victory. Um, Alex, anything else before we call it an episode?

Uh, I think that's it. Uh, actually, I do have one thing. Thank you to all the people that came out to the volunteering event today. Uh, we had a great turnout, got a lot of, uh, canned goods and other things collected that we are going to be donating. So thanks to everyone for that.

We'll be doing something else in the future. Yeah, we're looking at one coming up here in the winter for sure. So, you know, be ready to sign up. We want you there. Awesome.

All right. Thanks, everybody. Hi, this is David Stapleton, Chief Information Security Officer with CyberGRX. This is Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Good morning, good afternoon, and good evening, Colorado Equal Security. You've got Frank again for this as a guest host on this podcast. Today my guest is going to be Doug Brush, and I'm gonna have to take a really deep breath before I start introducing all of his job titles because I think he's the only one here that has more jobs than I do. We've got Excel Consulting, He's also a fellow at the Academy of Court-Appointed Neutrals. He's a cybersecurity advisor for Polaris Corporate Risk Management.

And of course, last but certainly not least, he is the founder and host of Cybersecurity Interviews, a podcast, because he had about an extra hour a day, which makes his sleeping hour time from what, about from midnight to about 3 AM every day. So that way he can get all his jobs done. Doug. How are you doing today? I am doing wonderful, Frank.

Thanks for having me. I'm always excited to be, uh, doing stuff with the Colorado Equal Security community and, and Robb Reck, you know, and Alex, Alex Wood, who's an amazing polymath, and he'll tell you that in person. But there, I will definitely cede the throne entitled to them as the best podcast in the Colorado area. I'll take a very humble second. Absolutely.

I would have to agree with you. And as I posted in their in their chat on their Slack channel, I always want to be more like one and less like the other one.

Yeah, it's like when they— when the kid— when the kids ask you, who— which one do you love most? Well, one of you. And then you don't say anything else. Yeah. Oh, that of course is on purpose.

Yeah. All right, so Doug, you have— you're known within the Colorado equal security community as part of You know, well, let's just say you're an icon. How about that? How do you feel about me calling you an icon? I always get very almost embarrassed at times when I hear that.

I've heard legend last week at the Colorado Equal Security Picnic. I like troublemaker. Troublemaker is always good. But no, I've kind of heard I've influenced people. And I think that has been one of the more humbling things.

It's where it's hearing not necessarily for all the maybe dumb things that come out of my mouth when I shoot first and ask questions later. Basically don't ask any questions. I just say whatever comes to my mind. But when people say, hey, you know, you've really said some things that have influenced my career, you've really helped me in different ways. I always find that very rewarding and a lot of reasons I get involved with the community.

I came from a family that was very giving in their various communities, both personally and professionally. So for me, it always was kind of a give-to-get mentality. You know, you kind of put things out there and they usually come back In bigger ways than you can ever imagine. So for me, it's always a big, big thing to contribute and help people as much as possible. And I try to encourage as many people in the community to do that as well.

Oh, okay. Well, that's again, that's very interesting. I myself, I teach at universities while I get paid there. The biggest thing that I think I get out of teaching is getting people started in their careers and again, giving back to the community. For those, of course, that also know me, I've been a board member of the Denver OWASP chapter for about 7, 8 years now.

And same thing, I have received, at least from a monetary standpoint, zero. You, as you know, there's a lot of things that we get. There's a lot of better things we get than just monetary compensation. What do you think those are? What could you put that down to a single word?

Why you should volunteer your time and give back to that community? Well, I think it's hard for one word necessarily, but there's returns on investment of your time. As Warren Buffett said, time's the most valuable thing. He said, I can buy anything in the world, but I can't buy more time. And for any of us is if we can put that time into the communities, but do it with a sense that, hey, what will I get out of this?

As much as I say, hey, I do it for altruism, but smart altruism and smart capitalism. This idea that, hey, what can I do to leverage things? Where's a many to one. And so even recently, what we've been doing with some folks in the community, particularly through Denver ISSA, and working with helping them and some of their special interest groups, particularly around the critical infrastructure, you know, and why is that? Critical infrastructure has come under increased spotlight through the executive orders, CISA, I would say to a certain degree some of the new SEC rulings that overshadow some of the private companies that are publicly traded that also provide public services in the forms of critical infrastructure.

85% of those services in the United States are managed by private companies. So there's a lot of impetus now for the services that we all depend on— roads, schools, hospitals, energy and gas, you know, really everything— to be safe, secure, and, you know, usable in ways that's up— that has the right amount of uptime. So in that effort of trying to work with private and public sector, CISA, ISSA, look, I know in the end of the day it's going to give me opportunity to get in front of a lot of other thought leaders and potential customers. But the idea is to do something that also has meaning in the community that can help strengthen the community and build safety for people in Colorado. So to me, it's like, why wouldn't I do that if I can do all these things at one time?

And I think that's, that's a real approach that more people have to take on this. It's, hey, look, I know you need to do these things for marketing and sales. But what can you do that is less marketing and less sales and more giving back that does allow you to build those connections? End of the day, most people in security leadership roles and executives that support security leaders are gonna buy from people they know and trust. So if you build that trust by showing your knowledge, your domain of expertise within the community, they're more likely to buy from you and they're gonna be more appreciative of what you do.

So I think those types of approaches work much more effectively and efficiently and impactfully in your sales and marketing strategies. And unfortunately, a lot of organizations don't believe it. So we've been working with some folks like Jasmina Filka, who's the chairperson of this group, so she can kind of go back to her company and say, look, you know, you've asked me to work with all these critical infrastructure companies, here's how we did it. And it wasn't a huge spend, but it was time invested on my part to get in front of these people. Let's do this at scale.

So for me too, it's also how do we influence the entire cybersecurity industry to do more of these things? That's getting involved with community, being more active, and less of the spray and pray tactics of, hey, let's send out 6,000, 40,000 emails that we collect at RSA and hope we get a 3% return rate. I think that's not effective and efficient, annoys people, builds a lot of distrust of cybersecurity within individuals, within cybersecurity, outside cybersecurity. If you're doing things where you're kind of rolling up your sleeves, getting to work and helping organizations, okay, then you're showing true leadership skills. And you're building a business that is much more attractive to your customers.

And so for me, that's, that's kind of— there's just— I can't see a downside of getting involved in helping out other people when you can do things that are effective and smart and within your domains of expertise.

How would you get started, though? I should know by now because I do know you at least a little bit to never ask you a question with a one-word answer. I don't think that's— I don't think it's possible. No, I think somebody said one of the recent Colorado things. Is there, is there an switch.

I was like, no. Poor folks like Daniela have to like mute me in conversations at times. He knows how to do it. But yeah, no, it's tough. It's— I, uh, I see.

I think part of it too is I'm more like, I'm already doing it. It's because all my litigation work, I, I work around too many attorneys and I speak the less in the room around attorneys. That should scare everybody that wants to get into legal. Okay, so is that how you got into this Academy of Court-Appointed Neutrals? Yeah, essentially I'd been, I'd started in my cybersecurity career, really, I would say as, as a role, uh, as a testifying expert in forensics and computer forensics and in litigation, uh, in the early 2000s.

At that time, I was doing a lot of network security work and other types of things as, as far as more your, your traditional enterprise networking and support things, whatever they were, everything from the desktop to the enterprise backend. But certainly at that time, we were seeing more and more instances of network intrusions, malware, wireless issues that were still coming up, and we had to do things to kind of protect and secure them. And it really hadn't codified as a separate thing, but it was something I always wanted to do. I go back to my hacker roots as a kid in the '80s and '90s and really always wanting to get into the field, but, you know, lean more, I guess, on the light side of the force at that point, but really always wanting to do more. And really network security was something that I saw as a starting to get into cybersecurity and You know, unfortunately, unfortunately, that's how it happened.

I was, I was doing a lot of work at that time for Merrill Lynch that very quickly disappeared. And when I came back from that, luckily enough, I got a phone call from somebody that needed a computer forensics investigation, which I was looking into and got to do that, testify. And I really found it was exciting to do the intersection of law, technology, how things happen, what's defensible. And that led into a strong passion, I guess you would say, for how we look at the legal aspects of data privacy and data security. And that allowed me to start a company called the Digital Forensic Group, which was doing a lot of expert witness testimony, forensic investigations, and then some remediation and cyber work as well, a little bit of IR.

And eventually that all grew, but I was always having that, that part of the legal side to me, even as my career went through in other areas, as doing proactive stuff from penetration, vulnerability management, acting as a CISO, building out security programs. You know, I always had an, okay, well, how do you know, what are the legal aspects of this? How do we bring legal into this discussion? And I continued to do litigation work, and sure enough, I got a call in 2014 to do some of the special master work under courts in California, the Northern District of California, with some very large data privacy cases involving Google Street View matter. While I can't get into details, you know, some of the stuff's public, a lot of it sealed.

It was a really interesting experience to see how people from the outside think about technology, security, and privacy when resolving disputes in the corporate arena around data privacy. You know, what's accessible? What's there? What's available? And I got to be able to mediate these issues, and that's continued.

I've got to work on a lot of these different cases where people will make claims under the different areas of law, but then have to support it with pieces of evidence that Generally exists in large, complicated computer systems. So answering those questions of, hey, what's there to be supportive evidence? How do we get it? How do we preserve it? How do we do it that's legally defensible?

Manage the cost, meet the court timelines becomes a very, very complicated— well, I shouldn't say complicated. Let's just say it's a very interesting way to take very complicated things down and make it very digestible and usable in a project management area. And so what we're trying to do now with that type of work, because we're seeing more and more data privacy and data breach litigation, is how do we support the judiciary in the various courts at the federal level, as well as state courts deal with the electronic data issues that come into play? Because those will often be called into question of, hey, what type of data existed? Tell us a story about it.

Was there reasonable security controls? What type of data is there? What's the value of the data? So being able to go out and get data from these systems is not as easy as everybody thinks. You're not just Googling an enterprise computer environment.

You have to go through very specific steps of data preservation, collection, and refining the process to take it out to meet all these things. And it's a much more expensive and complicated process if you do it wrong. And that's what we're trying to do is help everybody do this a little bit better, and particularly the judges that are falling under the weight of these types of cases, because more and more— and I guess now you would particularly say with the SEC and other types of regulations, there's just going to be more litigation around data privacy and data breach. And the courts aren't ready for it. You think that we're heading in that direction?

Because I mean, traditionally, from a percentage— and of course, I don't have any numbers, I'm taking a guess here— from a percentage standpoint, I don't think a lot of the crimes that are happening are actually brought to court. Some of it is because we don't know who the adversary is. Maybe they're in a different country, or possibly it's not worth the time and the money because we're not going to gain anything back. Do you think we're going to get back into that era or get into the point where we're bringing actual adversaries to court or other people, who do you think we're going to be bringing to court? Well, so here's, here's the interesting thing.

It's a kind of a delicate area, both in society, ethically and legally and financially. It's often going to be those that, that are quote unquote the victims. The organizations that suffered the data breach will often be the ones that are exposed to litigation lawsuits. So while we not— might not see a lot of criminal action, we're definitely going to see continued litigation action. And, you know, talking about percentages specifically, I asked some of the litigation or some of the data breach coaches.

So these are folks that work under a lot of the cyber policies, the big ones, really all of them that cover most of the data security incidents that we hear about. And I worked for doing probably about 700 of those under different insurance companies, which is a lot. That was just my office in Denver and the team that I ran here. There was— we had just in that company, we had 6 other offices, and there was at least 10 other companies. So at scale, there's a lot of these data security incidents that are happening every day that we never hear about, never make the news.

I don't have to publicly disclose them a lot of times. Sometimes they don't disclose to regulators, but when they do do notification, often they bring on litigation. So plaintiffs will look at class action lawsuits against these organizations and say, well, hold on a second, you know, you were under a duty of care You were supposed to, you know, have reasonable security controls around this data. Why didn't you? And often we're seeing these types of lawsuits filed for hundreds of thousands of impacted individuals that can go anywhere from a couple hundred thousand dollars to several million dollars.

So the data breach litigations are increasing. And when I asked some of the folks in these areas that do the data breach coachwork— so again, these are the ones that come in, help advise the companies on how to go through these things. They might not be in the litigation defense side, which is a clear distinction, but they'll be in the data breach protection side. And they'll say, hey, you know, Doug, it's a great question. 3 years ago we had, you know, maybe 67, this one particular firm.

Last year we had 300. This year we expect 50% in 2023. And for that one data breach coach in their law firm, they do approximately $22,000 2,200, let's say around 2,000 data breach responses a year. So if you think there's 1,000 just in that one law firm, data breach litigations that are going to happen, that is a lot. And that's at scale.

I mean, that's exponential scale. We've never seen anything like that. And more and more that's happening. And I've been watching the different types of class actions being filed about data breach and data privacy, and this is not going to go away. The expectation is greater that these organizations have to maintain some duty of care.

There has to be these types of reasonable security controls. And with that, the organizations are kind of scrambling to figure out what that means. And so luckily there's some new standards coming out around that. But, you know, right now the plaintiffs are being able to bring a lot of these lawsuits and cover them. And then being paid for them, they're being covered by insurance.

But if that insurance runs out, or insurance denies those claims, companies are going to be faced to self-insure and pay for these litigation costs. Whereas a typical breach response and your first-party losses might be $30,000 to $40,000, litigation costs can be in the millions. And so organizations are woefully unprepared for the incident response, litigation, and regulatory aspects of this. And we're going to see more regulatory enforcement that also has litigation. Just because you have a regulatory action from the FTC, the SEC, does not mean plaintiffs can't come after you and vice versa.

So what organizations are not ready for is this level of scrutiny for the data loss. So we're not actually going after the adversaries that are destroying and attacking the data. We're going after the companies that failed to protect our data that we've entrusted to. Is that what you're saying? Yes.

But I would say in the nuance of that is, look, nobody is asking for them to have perfect security. And that's been a failing of cybersecurity for decades. We've said you need to have all these types of security controls, and if you don't, you fail one of them, you're liable. So as soon as you say things like liability and there's a lack of oversight from the governance, from the organization, they're saying, okay, let me explain it to me. If I do— if I spend a quarter million dollars just getting ready for some, you know, framework certification, I go through 3 years of it costing millions of dollars, I get it, but I fail one control.

My liabilities is equals if I do nothing, why would I do anything? We've tried to sell this idea of perfection, this idea that, hey, you know, Doug, you're 47 years old. I want you to look like Hugh Jackman at 60 on the COVID of Men's Health magazine. I want you to be all shredded and jacked. I'm like, dude, I'm never going to look like that.

Why do I want to look like that? I'm looking at you right now. I know our people listen to the podcast, can't see it, but shredded and jacked and everything. But I'm not. I say I've gotten in a lot better shape.

Over the past year. The reason why though is I started focusing on the metrics that mattered. I had to get my blood pressure down. I had very high hypertension. And because I'm a, you know, I have a family, I got worried about my health.

I focused on the health that matters for me. And by proxy, I lost a lot of weight. I lost 35 pounds of fat. I put on about 8 pounds of lean muscle because I was training differently. I wasn't training like I was in my 20s where I was trying to look like my little short jacked friends that go to the gym and had a different body type.

They had a different set of genetics, they had a different set of time in their day. You know, we— I started comparing myself externally instead of measuring the metrics that matter to my personal health. I want to see more of that in cybersecurity. I want to see better dad bod security, meaning that I want people to have achievable goals. I want them to go to the gym 3 days a week, not twice every day.

Doing these small measurable things that matter and measuring the outcomes in ways that actually matter to cyber health is what we need to be doing. Those are the types of reasonable security controls you need to be doing. Focus on what matters, not everything. And this whole idea of, but what if you miss one thing? Who cares anymore?

And that's been driven into management's head for so long by cybersecurity professionals that, oh yeah, but if you miss that one thing, okay, so how much is that going to cost? So what's the ratio of the risk to the cost? And you ask cybersecurity people like, well, that's not our problem. You just need to spend the money. And I get it.

The business doesn't want to talk to cybersecurity people anymore. And particularly after the last year of attrition and held in back of money, the spending is never going to go back there. That's over. Cybersecurity, as we know, is over, and boards and directors are going to seriously consider whether they're going to spend like this anymore, because all they need now are the basics. They need good enough security around the data that matters, that's at risk.

And once you do it from a data governance, it's different. I'm sorry, say it again. I said I think you're going to start a trend right now with the dad bought security. I think that we're going to have to put that— I think you're going to have to put that on your tagline now. I'm going to try.

Yeah. But I think it makes sense because it resonates with people. They're like, oh, okay, we're not going for perfection anymore. It's like, no, we just want you to be better and better health. If right now most organizations, they have blown out knees, they're way overweight, they're, they're, and they're looking at this idea of like, I'm never going to be this idea of perfection, so why would I bother?

And I'm saying, let's bring it down to more achievable results. And I guarantee once people hit those basics, they'll be in better shape and they're going to continue to build on it. But let's start at goals that are achievable. Okay. Well, let's go with— I mean, we've talked about what you're doing now.

How did you get started in the computer industry? I heard about this awesome program called Google, right? Is that what we call this? Yeah, I think I've always been wired like a computer. That's what it— that's the secret.

I'm really a robot sent from the future. That's why I admire you so much, Doug. I think you're— I put you on that pedestal and call you that legend. Thank you. Yeah, I mean, I really got started, I got started in the '80s and '90s breaking computers, breaking VCRs, tearing things apart and getting to really have fun with them safely, which I encourage people to still do.

And although my dad who used the computer for business would not look at it that way, because if you mess up the autoexec.bat file trying to load a sound driver and you probably did the IRQ jumpers and then basically bricked a machine that he needed for work. He was not the type of person you wanted to hear, goddamn it, Douglas, fix this. I was like, okay. And I learned how to fix computers really quick and I learned how to back up at least the autoexec.bat files and remember what jumpers I set because I had to get that computer up and running. But I was always playing with them and it was always something I wanted to do.

And, you know, I get out of high school and I was at the point in high school I was delivering pizzas and trying to figure out what to do with the rest of my life. But I was at the same time I started doing a lot of internships with website designers. They're like, this is like before Netscape, I think it was .4, .6. I mean, it's really early stuff. And at that point, I'm talking about computers in the local security community or local business community with my parents' business.

Say, this idea of this web, think this internet, it's going to change it. You can do all this thing. And people are like, whoa, timeout. We can't even turn our computers on, but we know we need to. It's like giving us better efficiencies.

You know how to fix them? I'm like, yeah, I know how to fix them. That's what I always have to do. They're like, well, We'll pay you for that. I was like, oh.

So that was the start of my business, supporting businesses and individuals fixing computers and really helping out the Poughkeepsie community as a computer guy. And I had the business going and marketing and all this done and it really grew. And that's how I got into the enterprise side was through businesses I supported that then brought me into bigger businesses as a contractor and grow and grow and grow. So it really started there. But, you know, it goes back to like just having that mindset.

We're joking about it before. Podcast, like the Google thing was, you know, kids, I know I sound like the old man yelling at the cloud, but, you know, kids today don't get it. They don't get what it's like, how easy to spin up a VM and be able to do free online training in AWS. In our day, we had to go buy servers from junkyard, whatever it was, and try to rebuild Dell R-Series servers both ways. And gosh, in the snow with, with, yeah, with a Dell R6 server on our back.

And, you know, and, you know, total like SAS arrays on our front. But yeah, no, it's, it was, it was It was challenging, but you figured it out. But, you know, with all that was that thing and you didn't have a lot of— you had to learn how to fight with one hand behind your back. And I was even learning to do all that area, that geographical support, because at that time the internet was not as resilient as it was. This was dial-up and most companies and most people did not have dedicated internet service.

So I couldn't remote in to fix them. I had to get in my car and go to people's places, business to business to business to business. And thankfully, from doing pizza delivery for whatever year or so it was, it was— I got to know the area and my map, like the map in my head better than any, any map book that was out there. So when people would say, hey, we need to be— we need you at this business at this time and this at the other, I already had my geolocation built in my head because I knew every spot and every road and every back road in Poughkeepsie and the Dutchess County area to go from one place to another. So MapQuest really became out of Dougal is what you're saying.

They, yeah, they plugged me into the matrix at night and downloaded my brain. Yeah. So that's, you know, that's one of the things we should do at the next Colorado Equal Security event is we should hold up a survey and say, how many people know what autoexec.bat is or MapQuest or config.sys? We have that. And oh, do you remember what Netscape was?

And only if you answer all the questions correctly can you gain entry into this special room or something like that.

Okay, so you did mention something here just about a minute or so ago. Why, why, how do you feel about clowns? I, I've heard that every time I see you, we should show you a clown because you love them or something like that. Yeah, I love clowns so much. I don't know what my parents, you know, they both passed away, but they still can't figure out the earliest, earliest days of why I'm scared of clowns.

And I just don't like— I know a lot of people don't. I mean, hell, they have Pennywise the Clown as a terrifying creature for a reason. I don't think had to even make him demonic. You can make him happy. Clowns are creepy by nature.

Never liked them. And, you know, my friends being like me, and a lot of them attorneys too, and wiseasses— I had 6 or 5 litigators at my first wedding. So, you know, I tend to surround myself with people that like to, to argue, mess with you, and have fun. They decided one time at our share house in Long Island to— one of them to dress up as a clown and follow me around. Now, to get ready for that, he could have just rented the clown suit, put it on one night, and stalked me from bar to bar messing with me.

He actually went as far as the trouble to learn how to make balloon animals with stupid gloves on, which to this day we don't know why he did that because he never made any balloon animals. And then that freaked me out one night, and of course everybody was on the joke. I didn't think it was particularly funny, and I was freaked out. And finally the next day they kind of told me what's up, what's going on. I was like, guys, Idiots.

And then the next day, somebody's like, well, okay, I'm gonna wear the clown suit out to the bar. I was like, dude, just fine, just get away from me with that stupid thing on. And like an hour in, you know, being in Long Island, and, uh, you know, let's say there's a lot of similarities between Long Island and Jersey Shore, you know, the kinds of meatheads that you get there. 3 meatheads grab my little buddy that's dressed up in a clown suit, throws him over the railing of a bar thinking, okay, where— it's a beach bar, he's gonna land on the fucking sand, right? Well, except for the fact you idiot, you threw him onto the bayside where there was rocks and now he's cut up.

He's got his head. These guys get tackled and arrested. There's a whole— now there's cops, there's an ambulance. My friend's covered in blood in a clown suit and then a neck brace and has to get taken off the island for emergency medical trauma. And I'm like, yeah, I did not like clowns before.

This just made it 1,000 times worse. So yeah, to this day, if you really want to get me, you have to step up above that. It's really then give levels of trauma that I'm still dealing with that involve blood and and, and guidos and, you know, cover clowns. It's so good luck on that one. I actually, I think what I'm going to do now is get a shirt printed up with the word clowns on it and then the circle with a line through it.

Just, just for you, Doug. Just, I do like that for you. Yeah. Just, just no clowns. I know a couple of people that probably agree with me right now.

We should make that a theme at the next Doug event there. I love it. All right. So you moved here, you did. You are not from Colorado.

Tell me something besides Robb and Alex. What are the best things about Colorado? There's so much. Obviously, the Colorado Equal Security Community. You know, and all kidding aside, it's really been the security community has been amazing.

I came from New York, and even when you start dealing with the executive leadership in litigation, legal, the judiciary, CISOs, CIOs, CTOs, CEOs, anybody, anybody that has that level of, say, career advancement, they typically don't live in the New York City proper area. They have to commute. And so trying to get, hey, dinner, drinks, even lunches with them was challenging. So it was very hard to build a community. I was very successful in doing that with NY4Sec.

So it was a New York City for forensics group. We had hundreds of people involved with that, that were local. And we, I had great speakers coming in regularly, but it was, it was a challenge, you know, whereas here it's like, I feel like we did the Colorado Equals Security picnic a couple weeks ago and, you know, that happened on the fly and there was a couple hundred people. That was awesome. It was, it's just so much more accessibility to the community here.

People don't have to rush off and commute 2 hours each way every day. And they don't feel crazy if they have to bring their family to it. And then we did family stuff with, that was just never happening in New York. New York was just so kind of jaded, burnt out, fast-paced, and it was really hard to get to know people. Here it's been much easier.

And I think that overall the community, both personally and professionally, has been incredibly welcome. And for me, I love snowboarding. So being able to go up to the mountains and, you know, in a couple hours or even do a, you know, up at Eldora every Friday, we have the ski and board networking group. So it's a combination of work and play. I actually started that as a joke, just thinking, hey, it's a great way to spend some coffee and maybe a lunch if anybody anybody shows up.

Now there's several hundred people. It's a once-a-week thing. We have 3 other different organizers. Eldora markets it on their website. I'm like, God, I just— this was a joke.

Now it's another job. You know, we're trying. That's all I do is I create new jobs for myself, even when I'm trying not to. But, you know, it's being able to do that. Just, it's— everybody does have a better sense of the work-life balance out here, which I know we all say, but they can also— they really live it.

It's not just saying. And I do love that aspect of being able to be outdoors quite a and still have a great work community. Yeah, that's interesting. I mean, because I'm a Colorado native, yet I don't like snowboarding or skiing. I actually don't like the winter for some weird reason.

I'm a summer guy. I love going up to the mountains in the summer when it's nice. And to me, the hotter the better. Also, you got that too. But that's, that's the beauty.

That's what I really, you know, the summers in New York were often brutal. You know, they were that we had to go out to like 3 hours to go out to the beach just where it wasn't, you know, sweltering heat in the city. The winters, when I first came out here to even evaluate Colorado versus New York, my ex-wife and daughter were out in Boulder and we were hiking 65, 70 degrees in February. New York had just gotten a snowstorm with 7-foot snowbanks. And people are like, why would you want to move out to Colorado?

There's so much snow. I was like, no, there's more snow in New York City. At least in Colorado, we get it in the mountains. And during the summer, it's gorgeous. The lakes, you got so much more.

And I think Colorado, quite frankly, even you go to the mountain towns, are more of a summer place than anything else. Yeah, yeah, absolutely, absolutely. So back to, back to the security part here, right? I'm going to ask a question for you, and I'm going to put a parameter around you. I'm going to say in 1,000 words or less, Doug, and I'm going to try to count this here, what do you think is the greatest security challenge today?

All right. And again, it's easy to remember, 1,000 words or less. I'll see that. This is easy. You just gave me a softball.

I can say in 2 words. Okay. Data governance. Data governance. Okay.

So what do you mean by that? I mean, obviously there's— I have my opinion as to what data governance means. What do you think it is? And do you think things like Sarbanes-Oxley or any of the other regulations help us with that?

Yes. And a little backstory. Okay, so this is going to be the tough with a thousand words things because now I got a backstory. I know half of my things end up sounding like a Quentin Tarantino movie where 4 hours into it you're like, oh, I get it. At the end, these guys already knew each other.

And I know I sometimes I bury the lead. I self-admit that. But about a year ago, I realized I need to take a break. One of the other things that I do, as you know, is a lot of mental health advocacy, both in the community and for other organizations. While I was at Splunk, I helped build out the neurodiversity program with a strong focus on my area.

Under the subset of that was mental health, mental health awareness. I had all the executives on an internal podcast talking about languishing and burnout, and we really did a great job at the different security events such as DEF CON, Wild West Hacking Fest, Blue Team Con, to have safe space villages where people can go in and just chill out rooms. We had people come in and do yoga. We had presentations at DEF CON. Oh my gosh, 2 years ago where, you know, guys like Dimitri McKay who worked for me at Splunk, total, just, I will admit he's slightly better looking than me, but he's shorter.

So he averages out. I talked about his challenges with neurodiversity and mental health that people wouldn't realize because it's not the type of things you see on the outside. And I was going through a lot. I'd gone through 3 deaths last year. So a lot of the early mentors for me in technology and security were my mother.

And this other gentleman, Gavin Singh, who was basically my older brother. His mother is basically taking care of me when I was younger, when my parents were starting their consulting business. And after she got here, her husband passed away and brought these, these kids out of, you know, Guyanese Indians out of South America to live with us. And they all became our extended family. So my mother died in February.

Dolly Singh, the mother, died in May. Gavin died in August. Boom, boom, boom. I lost my 3 biggest mentors. And Gavin was the one that taught me NT 3.51, taught me how to wire IP access units and NetBooey networks.

I mean, and this was, this was a god to me. Everybody passed away last year, and I needed to actually practice what I preach and do some thoughtful introspection about how I was going to live the rest of my life. And again, at that time, my blood pressure was up, I was overweight, I was depressed, and I really had to focus on my mental health. And physical health. It was the same thing to me.

So I did that. And around that time too, I'm stepping back and saying, okay, I left Splunk, good terms, but I was like, what do I really want to do? I really want to make a change. I want to live the next 40 years. And I highly recommend people read this book to help you figure out your next 40 years if you're in your mid to late 40s, called From Strength to Strength.

And it really set my orientation to say, okay, well, what's the problem? I was like, I've been doing this now, security stuff, for so long. 20-something years, and it's like, why am I doing the same problems? Why is it the same problems? Why are we still patching SMBv1 issues?

Why am I responding as an incident responder to SMBv1? Like, these are things that are well known. Out of those 700 data breaches I did, very few were sexy, maybe a handful. And I'm like, what the hell is the problem? Why— this is like the definition of insanity, you know.

I shouldn't probably be saying that as a mental health advocate, but reality is you keep doing the same things over and over again expecting different outcomes. And I sat there and you can't see there. Well, there's some of those manic scribblings on the walls behind me, but I said, okay, what's the problem? There's no duty of care. There's no— nobody ever gets in trouble for a data breach.

And I looked deeper and deeper and I was like, no, that's not true. What about the CEO for Drizzly? I was like, go look at it. FTC gave him a slap on the wrist. It's basically a speeding ticket.

It was a no contest. The CISO for Uber got in trouble, but it was like a lot had to go down for that. I don't think any of the other executives did. There was no material impact to the business when there was a data breach. So nobody protects business.

So an example here, and I call this one out to my university students, and especially for like the Target breach. I mean, I think we both know and everyone here hopefully knows about the Target breach. And they— and I was telling my mom, about how the CEO lost his job, and she's like, oh my God, what's the poor guy gonna do now? But I think, as, as some of the people, if not all the people on this podcast know, he got his golden parachute for it, right? That's not even— I wouldn't even consider that a slap on the wrist.

I mean, not even— no, no. I mean, because I had to explain to my mom, who ever happened— anything about computers at all, or businesses, or anything else. She's the sweetest old lady, but she doesn't know any of this And I said, well, Mom, I'm not sure how he's going to survive on what, the $50 million that they parted him with or whatever that price tag was. And so I think you're right. I mean, I agree with you.

Burnout is one of the issues from a practitioner level and that you definitely cannot sit there and people are not being punished for these breaches. They're not going to jail. They're not suffering anything. And in fact, If I was the Target CEO, I'm pretty sure that I could survive on, on what, that $20 or again, that what, $50 million a year or whatever he received. I know it would be tough to make it work, but that's the thing.

Why do we treat, you know, there was the famous 2016 Economist article that came out and it said, you know, the world's most valuable resource is no longer oil, but data. The data economy demands a new approach to antitrust rules and all this idea that data has this intrinsic value. Does it? Because after 9/11, if you actually understand what happened, the insurance companies made sure that data had no value. And there's a much longer conversation there, but you can literally look up a lot of the work that Doug Laney out of Chicago has done.

But he talks about it. He talks about doing data valuation, but the insurance companies helped spike the ball because these big organizations like the ones I worked for, Merrill Lynch, lost all their data centers. And guess what? They weren't really doing the types of resiliency we plan on now as multiple data centers in multiple states or cities, because the one in the building next door got wiped out too, or the second floor. They lost all their data when they tried to get, you know, a litigation or try to get the coverage for it.

You know, there's various areas of insurance coverages that said no, whether we act or war, and they just said, you know, end of the day, data's not— there's no value to that. And they won. And so people have had this idea that data has no value, but that's BS to me. I mean, we moved past that. We can't continue to wear that.

We are in a data-driven economy. And so there's— right now there's no process to hold officers and directors and officers accountable, liable, and responsible for any of the data loss that relates to money. So one of the largest accounting scandals in history is not like off-balance sheet, you know, finances. It's off-balance sheet data. We treat data Like it's some kind of magical thing that happens and then shows up on a 10-K statement or financial balance sheet, but there's— it has some value.

So if organizations are able to put some value about how it's used and operated, they have to be held accountable when it's stolen, and you got to put the right types of protections around it, and that has to come from governance. And if you look at the new NIST CSF, it's about governance. SEC's rules, governance. They don't want CISOs in the room talking about cybersecurity. They want the board members in there making business decisions about the protection of data.

You're now at a state where data governance is the most important thing. It's the only way we're going to change the situation to stop doing all these things that we've been doing for 20 years that are not working. It needs to end. Now granted, I know there's a ton of vendors out there that are going to be upset that I'm saying this because of how are they going to have have all these very expensive parties at RSA and Black Hat, you know, the drugs and all the sex that come with that might not be able to get expenses anymore in Concorde. They're going to actually have to pay for it out of their own pockets, that they might not have jobs anymore because they're going to be looked at as vendors as how are you having material impact on the business?

How are you protecting data? Why should I trust you, not with the data, but with my money? Data equals money. Until these organizations that sell to other organizations about data protection understand that that's the problem, they're not going to survive. Because that's what the board of directors want to hear, is how are you going to help us protect data and keep us out of trouble?

Because if we have a data breach and we suffer this and we have to report this to financial statements, we can get sued for, you know, derivative lawsuits. We can have plaintiff action. We can have further regulatory action. I can get a Wells notice. You get a Wells notice, you might not be able to get another job.

Going back to that thing about the CEO for Target, those are the types of things things. CEOs, these executives, they do not care about making more money. They just don't want to lose what they have. Threaten that, their behavior is going to change. This is about behavioral economics more than anything else.

You put those in the hot seat that matter, that actually control the money, with fear of losing their money, they will change the way that they manage data and protect it better. And we won't have data laying all over the place. I think that's what's honestly going to change the industry. Yeah. And I think, though, that— and again, some people may hate me for saying this— I think that's very far away.

I And here's the reason. And I've got 2 questions for you that I've been thinking about while you're talking. The first one is going to be, is when we talk about data and regulations, when, like, for example, I was teaching a class at the local college here when Sir Baines Oxley really made it out to the— not Sir Baines Oxley, GDPR made it out here to the US. And they said, And I told them, isn't that great that they're finally doing that? And the answer from the room surprised me because they said, it doesn't.

It's not that great because you know what? My data's already out there. And that's where I kind of came up with this idea, or at least I presented it actually at one of our dinners at the Colorado Equal Security dinners, that this regulation is only going to be effective for the people that are being born today. Because now they have to protect their data, taking into those pieces what the college students told me. The second part I'd like to talk about here is when you mentioned the board directors and they're making those decisions.

Do you think— because I think that's one of the places where cybersecurity professionals struggle, that we want certain things to happen, we know the right thing to do, But the management, the board of directors, VPs, CISOs, CEOs, etc., are making decisions that aren't within the best interest of security. Now, granted, they have to think about the business as a whole, but they also are not doing what's right for security. So which one of those do you think you want to address first? I'll do the latter easily. Okay.

And that's the problem. It's us. It's not them. We need to make this a business problem. Nobody cares about cybersecurity, and I know there's people clutching their pearls and in shock right now, but nobody does.

We're never going to get the board of directors to care about security. Why should they? They care about business. And if I hear another person in this community say, well, it's the job of the CISO to talk about risk to the board— no kidding. Guess what they do all day?

We're like a bunch of little kids that now went into our first year of college, learned about Nietzsche, and are at Thanksgiving dinner talking about existentialism and is God real? And it's like, dude, that's great, that's academic. We deal with risk every day. Welcome to the real world. And the issues are we need to be talking about business and we need to be talking about reasonable risk controls, duty of care.

Nobody cares about security. We need to start at the top, and that's where governance matters. And so when they talk about how they manage risk, all we need to do It's very simple, is align cybersecurity as a function under all the other risk areas of the business. Move the CISO under the CFO, the risk committee, or general counsel. Build an office of a CISO that helps manage the cybersecurity risk separate from the IT and also separate from the data.

So you have the data, which if you think about it, think about a can of beans, right? You have the beans inside that are the data, then you have the can, which is the infrastructure. You need to look at the controls around both of them, but they kind of work together. So how many beans are inside? Well, I need to know, are they the right beans?

Are they quality? Are they poison or whatever it is? So there needs to be some governance around those, but also the controls around the can. Now the expectation is, yes, a certain amount of the cans are going to have failure rates and some of the beans inside are going to be spoiled. Again, dad bod security.

Nobody's saying perfection. All we're saying is put around the reasonable security controls with the beans and make sure the beans inside are protected and separated between the type of assets that they are, because there's not all data is the same. Same. Not all data has the same kind of governance. So just by understanding how you need to protect the stuff that has value to the organization— what is the material impact by losing this, whether it be a compromise of the can or loss of the beans— how does that impact the business?

And so we need to educate ourselves on how that's done. And this has been a fundamental problem. When I spoke on a CISO panel a couple months ago, I said, hey, how many of you here have seen a SIEM- You know, 200 excited hands go up. I said, great, how many of you ever read a 10-K? Maybe 2 hands went up.

I don't even think it was the companies that they worked for 10-K. Cybersecurity people do not understand that we need to align with the business, not the other way around. And that has been my uphill battle now for 2 years. And even this last year when I said we need a Sarbanes-Oxley for cybersecurity, the SEC is eventually going to— I said this a year ago. Everybody said I was completely wrong. I didn't know what I was talking about, but I said there's going to be data governance for real.

There's going to be looking at things for fiduciary responsibility, accounting and transparency of the data and systems, knowledge and literacy of the systems, a standard of care around the systems and data, and separation of duties. Those are the basic components of any kind of governance program, and that is what the SEC just said. They took the CISO out of the equation of requiring the CISO or somebody to be a cybersecurity expert at the board level, and everybody's like, whoa, great, we lost that. I was like, no, no, you're looking at the wrong The board and the directors now are all personally culpable for understanding and knowing how cybersecurity works. So we've actually spread the risk to them, and they're going to focus on it very differently, and it's going to be put in the business terms.

It's going to align the focus and priorities of how they do things and how they execute on their programs. And so instead of like 100 different point solutions, they're going to pick a couple platforms that manage things good enough. And as long as it's legally defensible and somebody can go in and testify on it, say, here are the steps that we took, Look, here's the experts that we brought in that built out our data governance and our cyber resilience programs with duty of care. They're fine. And that's all they're going to care about, but they're going to protect it.

It's like in the '70s when banks were leaving money laying around because it didn't matter. You only had to hold back 10% of any cash deposit you put in, and you can lend on that as much as you can in whatever banking pyramid scheme they have. But the physical assets, the money didn't have value once it passed the teller. People were stealing Until they couldn't insure those losses anymore. Same thing's going to happen in cyber.

Organizations that don't manage their data and don't protect it with reasonable security controls will not get insurance coverage. They will get sued. They will be held liable. That will be reflected on their balance sheets, and when that does, they're going to have to change their behavior. So unfortunately, this is going to be way more than carrot and stick.

It's just going to be a massive kludge that's going to force the behavior change, but it's going to happen because of the money impact. And it's already starting to happen. The SEC is doing this. So this is not data privacy rules that are in effect. Take the word cybersecurity out of that SEC ruling.

It's about governance. The new NIST CSF, it's about governance. We're talking about true top-down approaches to security, not the bottom-up that we've been doing. And I honestly think that's fundamentally going to change businesses over the next couple years because of all the legal liabilities that are now introduced. Once people start suing each other for these things, we're going to have regulation by litigation.

And there's going to be people in the courts that testify on this stuff that happen to be living in Colorado who have been wearing a tank top right now and talking about this. Yes, I'm being a bit of a war dog here. But hey, look, the reality is, is that somebody is going to need to go and explain this in business and cyber terms. I just don't think they can do it. I do agree with you, though, about the business.

I've been touting that. And I think that's why you and I get along so well, is that it is about the business and And I'm going to go off on a bit of a tangent here with that. It also— that business also includes the sales. I mean, if cybersecurity makes it too difficult for the salespeople to sell stuff, then we have no income into the business, and that will detriment the company overall. Well, I mean, companies are going to make better decisions through their supply chains of who they use for their risk management processes.

And that's going to fundamentally change the way vendors are brought on board. And that's everything from the contracting. You know, there's a lot of things under the Universal Common Code, like under UCC, about software being a service and not a product. But there's going to be huge liability standards here. You're not going to have organizations signing with vendors any longer if they feel that, hey, if we have a breach that is material, and we have a shareholder lawsuit, we have a regulator, I'm gonna look down to my downstream, my third-party vendors, say, what the hell happened?

I bought you to help. What type of— what is your software development lifecycle that allowed this type of issue to happen? It's going to really force cybersecurity companies to change the way they contract, design, develop, think about things. And it's gonna have to align with the businesses they serve, not themselves and their ARR and all the things they have to do to boost up their, you know, the shareholders and VCs and the, you know, and the executives. Stock prices.

For once, product companies might actually have to think about the customers, which I know is a new concept for them. Well, that's— you see, it's interesting what you're talking about here because when I was with the company and I— and for— I'll make sure I don't mention the company specifically. I was looking at their budget sheet for a project and I saw a line item that kind of caught my eye. It was almost $1 million and it was reserved for fines because they knew they were not going to be compliant And instead of trying to ruin their timelines to make themselves compliant, they decided the best course of action would be to just go ahead and pay the fines and then build it into the budget now.

Well, I think that's, that's when you have to look at things from, again, this, this kind of duty of care standard. The big thing that came out of the SEC ruling was the materiality. You know, you have to report data security incidents that have material impact on the organization. Now, I would say there's also going to be other aspects of this beyond the data security. And so it's a breach, or a breach of infrastructure can also have that.

So when you start looking at the way that, that aspect of it, that can an action, can a product that I purchase, can a decision we make about a product I purchase and the actions I have have a downstream impact on the business that impacts the stock price. That's going to be the thing that's going to be the kind of way that things are going to be framed is how do we make decisions now from a corporate governance thing that has a duty to the shareholders, you know, that could be seen as gross negligent or liable or any of the other kind of legal standards that get around that where various degrees of culpability go into it. But, you know, You know, it's going to, again, put people in a different type of decision-making about the choices they make when they think there's some real downstream consequences anymore. We're not going to just get a slap on the wrist. We can't just put a fine aside.

Yes, we can pay the fines. Yes, we can pay the legal fees. But if these things actually have material impact to the business and we didn't really think about this properly and we didn't disclose it because it's not part of our governance program, because they have to do this year after year, this is not a point in time You know, they don't just have to attest this once, they have to do this annually. And then if they do something annually and they make an attestation to something that says, hey, you know, we've done the best we can, we really think— and somebody says, well, hold on a second, you totally did not ask the right questions of this vendor, you totally didn't ask those questions of yourself, you didn't look at the data right— there are going to be, you know, there's possibilities again of regulatory action, there's going to be lawsuits, it's going to be a different world when you have regulation by litigation. Okay, so let's go back to the previous— the other part of the question that I had asked you.

Let's say that we get the governance in and we get the, the penalties in and everything today. Let's just say that today, what, September 5th, 2023, everything that Doug wants to— wants falls right into place in perfection. How effective— how many years or decades would it take for everything to be protected. And I'm coming from that from my college students when they were saying my data is already out there. Yeah, and I'll say that there's a couple aspects to that.

One, I, I, you know, I've been doing a little bit of a gloating glory dance since the 26th of July because I said this was happening. And it wasn't that, you know, I wanted to be right. I just saw this coming. And I don't think it was anything that was necessarily a crystal ball. I just stepped back and looked at it more practically in business sense and basics.

I said, well, maybe this is us. Cybersecurity is a problem. We're not thinking about the business. We keep pushing this square peg into a round hole that cybersecurity— and I'm like, no, what just happened is the SEC is going to round off the edges. They're just going to make us the round peg and we're going to go in the round hole.

So we have to start thinking about that. And so I think It's already happening, you know, and I don't think it's something that's going to take decades. If anything, it's going to take months. I mean, the self-reporting and the other aspects of this go into effect in the middle of December, December 18th. And what that means is we do not have to protect everything, and that is a fundamental mind shift within the data protection and cybersecurity community.

They're like, yeah, but what if we miss something? I'm like, who cares? Nobody cares. What I care about are the things that are measurable. And everybody's like, well, you can't manage risk in cybersecurity.

I was like, well, not only— yes, you can, actually. I've trained Doug Hubbard, I got a bunch of people already working on this. Why won't we just use the duty of care reasonable, you know, the DOCRA standard? That's the one that 20 AGs are looking at. That's the way the SEC is going to go.

It is already happening. And the idea of that is we take prioritized risk decisions about about the things that matter, and certain things are not going to get protected. Certain baby turtles are not making it across the highway. Big deal. But we need to move on.

We can't protect everybody and everything. Yes, some of this data is out there, but the expectation is if there is a data breach and litigation or there's data privacy action and there's something that says, hey, this data is out there because it has value— it's not just about the individual's data, it's about how we use it— and somebody else steals it and uses it, and there's other aspects about our intellectual property that are wrapped into individual ownership of data, well, that changes things. What I think will happen over years is that we see greater valuation of the data. Individual records within the database have different values that are tied to us. My crazy idea is that within 4 to 5 years, every individual has a level of data autonomy and ownership that we've never seen.

So yes, it'll be your data, and anybody that uses it will probably have to license it from from you. And so it'll be more of this crazy communistic, you know, uh, capitalistic system, maybe closer to like a Nielsen rating thing where, hey, if you want to use my data, you're gonna have to pay a small fee. And everybody wins in that sense. You know, more— they'll be more likely to protect your rabbit. All we're going to do is, you know, monetize this in a way that, that builds incentives to protect data.

That will allow you to protect what matters, and less data will be laying around. So I starting to see some of this already happen. And I think with things like DACA and assessing things that are legally defensible, because that's what the board cares about, is, hey, if I get sued on this or there's regulatory, how do I protect myself? They don't care about our data necessarily, right? They care about protecting themselves.

So let's start there. We can build out from there, but how do we protect them? How do we give them tools to protect themselves and think about things that are actually effective and reasonable? I'm not saying today, but yeah, we can start putting better business processes around how data is managed. And let's look at things from a business function.

How does, how does data move from customer impression, your first impression, whatever it is, how it's collected, to a balance sheet? What are the business functions? With each function, there's, you know, a swim lane of people, process, technologies. What data lives with this? Who has access to it?

Now we're talking about basics, access controls, RBAC, you know, around things like we're going to use the tools that we have just in more effective and meaningful ways because we're tying it directly to the business function. Functions. And then we can say, hey, we took reasonable steps around each process because this is mission critical, this is business critical, this is a tertiary thing. And we only have to protect what's really necessary to make sure we don't have losses to us or to the individuals that have data get exposed. I think it's going to happen a lot quicker than people realize.

Well, I mean, again, respectfully, I think I'll disagree with you. I mean, you and I think alike. You and I think alike. I mean, one of the questions at the place I had asked is what if we could actually measure what reputational impact we would have in a breach? Now, I know you and I could probably go on that question for about the next hour to 3 hours, but we've been going for almost— I'll give you one more thought.

Okay. I already know people that are working on that formula that are going to bring it to court and testify on it. Awesome. Awesome. Well, we'll definitely want to hear about the results.

And I, we are completely out of time right now. So again, maybe we'll get you back on for another podcast or something along those lines. Thank you for your time, Doug. Again, this is Doug Brush. You can find him on LinkedIn under Douglas Brush.

My name is Frank Victory. I am a board member of the Denver chapter of OWASP. Please come and check us out at meetup.com/denver-owasp.

Again, thank you for your time, Doug, and I will talk to you later. My pleasure. Thanks, everybody. Thank you, Doug. All right.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes