Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 256 for the week of December 4th. Alex, this is it.
This is the, this is the last month of the year. It is. It's hard to believe we're already in December. We're, we're into the holidays now, I guess. I guess.
Yeah. I mean, we're past Thanksgiving, so no one can complain about Christmas music anymore. Now it's that time. So I was in— I don't think I told you this. I was in, I was in Florida for Thanksgiving.
I did tell you that. But, you know, we flew out like the, the Sunday before and the airports were all like normal. And then we flew, we flew home on Friday. So like the day after Thanksgiving, it was just Christmas music all throughout the Fort Lauderdale Airport, all throughout DIA, just back-to-back Christmas music the whole time. I'm not a big fan of Christmas music in November.
Not a big fan of Christmas music in like early December either. Yeah, it's a little too much for me. Yeah, it's gonna get old pretty fast. You know, I don't mind Christmas music for a little bit, but I only need to hear every Christmas song once. Yeah, some a couple times.
That's it. Yeah, that's about right. Yeah, but we will get a lot of Paula Abdul coming up. All right. What do we got here?
We got— let's talk about our housekeeping. We've got the Slack channel if people want to join us in Slack. We got a great bunch of great conversations going on in there. If you want to join Slack with the Colorado Equal Security community, go out to colorado-security.com and hit the Slack button there. While you're there, you can join our mailing list.
You will get the show notes for this podcast sent to your email and maybe a couple other emails every now and then on various subjects, but mostly just once a month. An email with the show notes. We'd love it if you would rate us and subscribe on your favorite podcatcher. While you're at it, why don't you tell a friend? This is a good way for you to help us find new listeners.
We'd love to have, you know, everyone who's interested in Colorado security and here in the area be a part of the community. And, you know, it is the holiday season. It's, you know, a time for giving. And if you want to support us financially, we do have a Patreon campaign. It helps us pay the bills here at Colorado Equal Security for all the things that we do.
Any money that we have that doesn't go towards, you know, hosting fees and other stuff like that, we use for fun things like our annual picnic and, you know, other events like that that we do. Yeah. And speaking of good stuff, people giving back, this last month we had our Colorado Equal Security Gives Back drive. Really a lot of work put into that by Ben Fellows and Chris Abbey. I think Douglas Brush helped out with that.
A big drive for the Denver Rescue Mission, right? It was mostly food, but some other giveaways as well, clothes and other things like that. We had like almost 2 pallets worth of stuff, a ton of stuff. And a big thanks to the Red Canary folks who let us use their office to make it happen. I don't know if you probably heard, not everyone else probably heard, they, they'd gone to Voodoo Donuts to buy some, some donuts for us, for the, for the volunteers.
And Voodoo Donuts heard it was what we were doing and they gave it to us for free. Yeah, that was pretty cool. Pretty nice stuff. Shout out to Voodoo Donuts. Anyway, really cool stuff.
Thanks to those folks for doing it. This is That was our, what, our 3rd volunteering event so far? Yeah. You know, I would say that the turnout has been great. We really appreciate you for supporting that.
I hope that we keep, keep it going. Ben, thanks for all your work. Awesome. Let's jump into the news first. I'm going to call this a welcome story.
The migration to Colorado is on the decline. But this story is also talking about where people are moving from. Yeah. I mean, I would say it's not just that migration is on the decline. It's, it's that we have, we have a net loss of folks due to immigration or migration.
Right. The, the net total of people was like -9,000. Yep. Versus, you know, I think as long as I've known, Colorado has continually gained every year. Yeah.
So I think those of us that have been here a while, whether, whether we're natives or transplants, you know, shake our fists at all of the people that come after us. So, it's glad on, on my part anyway, to see a couple fewer. Burn, burn the, burn the bridge behind you. Right, exactly. This, but this is a little bit later or older news.
This is between '21 and '22. So we don't have the '23 numbers yet. Yeah. It's based on the '22 census. Yeah.
So, but looking, looking forward, interesting facts in here. You know, there are a lot of folks still coming here from California and coming here from Texas that we're, we are net positive in terms of more people coming here from California and Texas both than vice versa. But we're losing a lot of folks to Florida. That's probably the biggest place people are moving to, which I totally get. I get tired of the snow sometimes too, Florida people.
Yeah. The top 5 for people leaving Colorado, 1 was actually Texas, 2 was Florida, 3 was California, 4 was Arizona, and 5 was Washington. But of those 5, Florida and Arizona and Arizona and Washington, that's the ones that have taken more than they've given. Got it. Yeah.
Anyway, interesting facts. And it's always, it's always fun to get to learn some of that random stuff. All right. Next story for people that, that want a new job but don't want to migrate out of Colorado. Remote work is on a slight decline in Colorado and nationally.
Yeah, these are interesting numbers. You know, they're talking about like the overall work from home numbers in different parts of the state. And what was it like 24% overall for the state? I'm having a hard time getting the story open right now, but the numbers were Yeah. Even at the peak, even at like the biggest counties, like, like Boulder County and Douglas County, those were the 2.
Yeah. They were in the 30s. And, you know, I just, in our industry, I think of the number as being significantly higher. Yeah. Now I don't, you know, teachers obviously and, you know, retail and, and basically most services are gonna be in person and don't get to do that.
But I'm still surprised that 30 is kind of the, the peak for where this stuff's getting to. Yeah, I also— I mean, I don't know what the exact questions were, right? Like, what is work from home? What percentage? Right.
Right. You have to be 100% work from home to be work from home or 4 days a week, 5, you know, 3 days a week. I don't know. I think that's probably part of it, too. It's also not surprising to me that Boulder and Douglas counties, which are, you know, predominantly wealthier counties, are the ones that have the higher work from home numbers as well.
Yeah, there was one other interesting element I thought in this story, which was talking about the difference between women and men in their work from home. And across the state, women had a higher percentage of working from home where it was like about 23% of women and 20% of men. But different counties had different breakdowns. Douglas County had, had more women working remote than men. But, but Boulder County was the opposite with 34% of men and 30% of women.
So it's just interesting to me that— I don't know, is it— what in the world causes that, right? Like the different cities to have different breakdowns, industry prevalence, right? I just, I don't know. Well, and I think another interesting thing too is that nationwide, the, the, the number was 15% of people that work from home. And that, you know, overall seems really low to me.
I guess in my bubble, it seems like also it would be way higher than that nationally. One, I guess there is one other interesting element about this story was kind of what the pre-COVID to current shift looks like. And it was, it was something like going from 9% to this 20, you know, low 20s that, that we've seen, you know, kind of a lasting jump. So more than doubling the work from home numbers, right, from call it 1 in 10 to 2 in 10, which, you know, still pretty low numbers, but a significant impact. And I would imagine if you did a survey of our community, I, I think the numbers would be, you know, maybe even north of 50%.
It would, it would be a very significant minority or a majority of people. Yeah, definitely. All right. So our next story is, I, I actually heard about this like 4 different places. So we get to talk about it a few weeks later.
For some very short amount of time, the fastest internet in the world is not in some data center for, for Facebook. It's, it's actually in the Colorado Convention Center. Yeah. Yeah. Yeah.
So we had a conference here, the SC23 Supercomputing Conference, and at the conference they had temporary internet service, which was 6.71 terabits, which is a little faster than my home internet. So when a modem connects at that speed, what does the beeping and buzzing sound like, Alex? I don't even think you can hear it. The pitch is so high and so fast. It's not only dogs can hear it.
I mean, you must. I just vividly remember listening to the modem and knowing based on how long it goes, the longer it goes, the slower it's getting, right? Yeah. And, and you hear it, you're like, oh man, it didn't connect right there. Now I just, I just dropped down to 33 kilobits.
This is a little bit faster than that though. It is a little bit faster than that. It was interesting, this, the supercomputing conference, they don't always come to Denver, but they seem to come here a good bit. Um, and one of the things that they talk about is that, uh, they have to have plenty of time in advance because they build out their own, uh, network operations center. They build out all of the, uh, fiber optic lines.
They do all of this stuff in the convention center and build it out before the conference so that during the conference, the vendors and everybody else has super, super high-speed access to all of these gigantic, uh, you know, data-intensive applications that they're using. One of them they were talking about was, uh, you know, getting high, super high-res images from a, uh, I believe a telescope in Chile, I think. Right. And so you need this, all of this bandwidth to be able to, uh, to do those things at the conference. I always find it fun when they try and put big numbers like this, 6.71 terabits, they try and put it into some kind of perspective for us.
So the, the perspective they give us here is that that's 250,000 times as fast as an average US household internet connection. Which means absolutely nothing to me, right? Like, like, okay, so that— does that mean that I can download a movie like before I click the go button? Like, right, I don't really know even what you get when you go past a certain speed. Anyway, pretty cool stuff.
I mean, Denver's the internet hub— what was the internet hub for just a brief moment. One of the other cool things about it too is that most of that bandwidth and the equipment for it was donated for the conference from various internet providers like CenturyLink and other people like that. Zayo, other people like that. Yeah. Well, good stuff.
Oh, man. All right. Next, this is not a super exciting story, kind of an unwelcome story. But— and I kind of mashed a few stories together here. We actually have had some, some rounds of notable rounds of layoffs here in the metro area over the past month.
Dish, which I think is kind of have multiple waves of it. Ping and Broadcom, they all have announced various layoffs for various different reasons. I mean, I would actually say they all have pretty similar reasons, right? Like Dish and EchoStar merging together caused, you know, you know, quite a bit of efficiency gain. And then Ping and FortiRock merged together, that caused efficiency gain.
And then, and I don't know for sure, but Broadcom acquiring What did they just acquire? VMware. VMware. Obviously another opportunity for efficiency gains. So, you know, there have been a lot of layoffs, maybe not always related to that, but all 3 of those have the common problem is that— and I'd say another reason that those are common is that the stock market prices in general have— the valuations for companies have gone way down.
And when valuations go way down, it means that people who have a bunch of money sitting in the bank think, oh, I can buy it now and later I can respin it out and make more money, right? They're trying to play arbitrage. And I think that that's what happened here for all 3 of these. You know, Charlie Ergen doing kind of his own game with, with Dish and EchoStar. But, you know, certainly for Thoma Bravo buying Ping and ForgeRock, they see the chance to, to, to make a lot more money by buying them and combining them.
So the pricing, stock market going down, it just has these effects. Yep, that is for sure. One of the things I learned in this article too, actually not because of this article, in this article, but because of this article is that there's maybe a little bit of life for Carbon Black. You know, they were owned by VMware and read that now that they have been acquired by Broadcom, they are being split off from VMware and they're back to being their own business unit in Broadcom. So maybe we'll actually see something from Carbon Black again.
I have heard that maybe they're going to get spun out all the way separate from that. It'll be interesting to see what happens. It would be nice to see Carbon Black start to invest like, yeah, you know, they were the, they were the best EDR for a long time and they still have a fantastic product. It's just they haven't been investing in the same way. Yep.
All right. We have a, we have kind of an update from one of the stealthy tech companies here in town, RADICL, which is Chris Peterson's new company. Chris was one of the co-founders of LogRhythm. Every time I read a RADICL story, I get really patriotic. There's always American flags waving.
It's all about like protecting the country. I'm going to salute this story. You go for it. So the— what the story says is that RADICL just finished raising $9 million of new funding to help them go protect the critical infrastructure. Yeah.
So this is, you know, Chris Peterson's company, who was one of the former LogRhythm folks. And, uh, they're trying to make a, a new platform to help small and medium-sized businesses, especially in the defense sector, uh, or defense industrial base. Um, so they're, you know, doing various things, sort of a combined platform, it sounds like, of various different cybersecurity services for, for that type of company. And, uh, now I've got— they previously raised, uh, $3 million, and they added another $9 million to that. So the $12 million total round Um, so yeah, good for them.
Sounds like they're on their way. Yeah, they, they're, they're kind of another MDR type offering. I think it's MDR plus a few other things. You know, we also have Red Canary in town that does that and, um, Total, which, which does it mostly for MSPs. So interesting that, you know, we're kind of becoming a hub with a number of, uh, MDR type companies.
That is pretty cool. All right. Uh, oh wait, is that the right story that I just clicked on? Well, next is Jeffco Schools. Yes, I was in the wrong column.
It's bad news. Uh, it's bad news. Yeah. Jeffco Schools had they had a ransomware attack. Hackers, they, they were able to get into Jeffco's school systems, demanded money, and actually like sent out emails to parents and really kind of an ugly story here.
Yeah. My kids have attended Jeffco schools. My wife has previously worked in Jeffco schools. We did not get a ransom note sent to us. But we have, you know, seen the communications that came from the school district.
So Sounds like some data being lost of students and potentially employees and others. Yeah, no fun. The story has a good bit of detail. A couple of interesting things to me. You know, when I hear about ransom stories, generally I feel like the numbers are pretty good size for what they're asking for.
Yeah. So the initial ask here, they were asking for $15,000.
Right. Not $15,000 million. Right. Just $15,000. And then, and then later when Jeffco didn't pay, They, they dropped their ask to $2,000.
And, you know, I'm, I'm not a fan of paying the ransom, but like, when you're at, when you're at $2,000, like, yeah, you might just do it. Yeah. That number is low enough that you kind of getting off pretty free if it works. Yeah. I mean, I know, uh, schools are, are tight on budget, but, um, you know, I think they could still probably afford $2,000.
Um, I mean, whether you wanted to pay or not, we're not suggesting that they should pay, but man, it, it, the price gets low enough. And all of a sudden, you're like, well, if there's a 10% chance that this stops them from leaking that data, right? It's, it's worth it. Yeah, it was interesting for one weekend during the triage and try to recover from this, they had taken down all of the, the systems at Jeffco. And so, you know, neither teachers nor students were able to do any of their, their assignments over the weekend because You know, you, you give all the assignments out on online now.
So kids didn't know what they had to do or Google Classroom type stuff. Yeah. Yeah. So there, this, the article itself has a bunch of quotes from impacted people. It's, it's a, it's a messy, sad story.
There's no winners in this situation. It sucks. Yeah. Uh, and a friend of mine and, uh, local cybersecurity lawyer, lawyer Deb Howitt was also quoted in the article, um, talking about the, the potential, uh, Badness of using student birthdays as the default password. I remember that quote.
Yeah. Yeah. Maybe, maybe don't do that. Yeah. Maybe don't do that.
I get the ease of use, but maybe don't do that. Yeah. Maybe don't do that. All right. Well, our next story, it's actually a blog from Coalfire.
And this is around a push from the federal government around the responsible use of AI technologies. I wasn't aware of this. It's kind of a proposed law here, right? Right. Yeah.
So there was an executive order some time ago about AI. And this is the, the proposed follow-on law for it. The, you know, all around the safe and responsible use of AI. The executive order, I think, you know, talks about how a little bit things should be used within the government. And then I think that the, the law, should it pass, is going to add a little bit onto that.
And, you know, this is all sort of federally focused. But I think, as we know, so many systems are interconnected with the federal government that, you know, it will sort of trickle down to other places. Yeah. So if you're, if you're thinking about AI in your environment, which I imagine most of us are, this is worth a read just to see where potential regulatory pressure may be pushing us. Um, it's a good write-up from our, from our friends at ColdFire.
Yeah, good stuff. Uh, all right, uh, next, uh, speaking of AI, we have a Zvelo article here talking about the role of AI in social engineering. Um, this was actually a more in-depth article than I expected it to be. Um, and they, they talk a little bit about some of the, you know, some of the obvious ways that AI could be used to do social engineering. Uh, but there's also a couple of things in there that I thought were kind of interesting.
Um, you know, maybe different than what you might normally think. Yeah. So this is super interesting to me because just last night I was talking to someone who was telling me about a new company that the whole idea of this company is AI that goes out and finds potential customers and kind of stalks them across all of their public, you know, this is what they put on LinkedIn. This is what they put on Reddit. To help figure out who would be a likely person to buy your technology.
And it will like initiate initial contact with them about, about the idea and have like a couple back and forths to start getting them interested. And then you, then you can hand it off to a sales rep. And this is totally like the SDR motion, right? This is what, what vendors do. And as he, as this person was telling me about it, I'm like, oh yeah, I can see like, no offense to SDRs, but like, like they're not super effective. If you can scale this this way, like, holy smokes, way better.
And then I read this today and I'm like, This is exactly the same thing, right? Except instead of selling, it's to learn how to hack people. And it's like, it's exactly the same technologies they describe here for sure. And, you know, they talk about some of the ways that AI can be used in social engineering. They talk about using it for that data analysis and targeting that you're talking about, automated target profiling, efficient information gathering, personalization for deception.
Like, Learn more about the person. So, you know, like, they don't, they don't use UPS, they use FedEx. So you're going to send the FedEx fake email, right? One of the things that I thought was the most interesting, one of the points they raised was simulating insider knowledge. And as I thought about that, you know, obviously, if you don't have insider knowledge, but you gather all this other information, and you can then kind of guess what insider knowledge might be like, But also, like, you know, generative AI technologies are good at bluffing, essentially.
Right? Like, so I can see where it's like, hey, you know, tell me what you think this should be. Yeah. And it might just go off on a tangent. Yeah.
But, but it's gonna be super confident. A believable thing. Super confident, believable thing. Yeah. Whether it's real or not.
Like, you know, the AI sees that you and I posted a picture of us at a bowling alley last night. Right. And it, and then in the note, it's like, hey, hey, Robb, this is Alex. Good job bowling last night. I, you know, can't believe you, you, you, you broke 100.
Right? You know, I'm like, oh, God. He's right. I broke 100 finally. Right?
You know, and, and I saw it becomes believable. Right? Like, I, I can imagine, like, Robb, is it believable that you broke 100? It's believable to me that the AI could think it. The— but it's the scale that it can do it at.
Right? Instead of having to be a person who spends hours and hours doing this research, it can, it can monitor everything and have, you know, a million hooks in the, in the, in the water at any given moment. Anyway, and actually a very interesting article. So that, that's one I would recommend reading. Good job to our friends at Zillow.
Next, we have an article from Gregory Swicek at which Cyber Advisor blog? Ballard Spar. Yeah. Sorry. At Ballard Spar.
And talking about, I thought this was really interesting too, about Colorado pushing out the options for universal opt-out mechanisms for their— the Colorado Privacy Act. Yeah. So the Colorado Privacy Act had required that universal opt-out be enacted. Right. And so now this department, the Department of Law, has published a short list of potential opt-out mechanisms you could use.
These are like for review right now and comments. So the 3 options are an opt-out code, global privacy control, and an opt-out machine. And I didn't know what any of those 3 things were. So you have to read in the article. The opt-out code is basically something you put in your browser to— so that as you, as you browse through web pages, it will— it's like a cookie that lets them know you can't be tracked.
Or is that the global privacy control? I think that might be the global privacy control. I don't remember. Confused. But one of the things that I think is cool about this in general is that You know, sort of in, in prior generations of laws, whether it's privacy or security, um, you know, it would say, hey, you have to do this, you know, potentially really hard thing, but with no mechanism for how to actually do it.
So to see the, the follow-on from the Colorado Privacy Act saying, hey, you're gonna have to do this really hard thing that doesn't exist today, which is universal opt-out, to come back and say, hey, well, and here are the actual options for how you're gonna do it. Yeah. I think that's pretty neat. Um, I, since we don't do errata because it's too much work, I'll just, I'll correct myself now. The opt-out code is around, um, across IoT devices.
That's how you monitor across IoT. It was the GPC, the Global Privacy Control is the, the do not track signal on website browsing. Good stuff. Good stuff. All right.
So that, so that, that'll be interesting as it, it's not finalized yet. Right. But we'll hopefully we'll follow up when that happens. All right, finally we have a blog post from LogRhythm around detecting domain name abuse, kind of walking into, walking through like what does domain name abuse look like? Yeah, and this has an article and a video as well, a little more detail in the video, but you know, talking about, you know, why it is that you would want to monitor domain name traffic, how it is that you can do that, and I mean, not surprisingly, how you could do that in LogRhythm.
Yeah, but I, I, what I actually really liked about the blog post was that they leaned into using an open source tool that I hadn't heard of called DNS Twist, which it's actually really cool. You, you enter your domain name as a seed and it will generate a list of potential phishing domains. So, you know, replacing, I'm imagining replacing L's with 1's and, and so forth to look for whatever somebody might stand up as a potential as a potential phishing site for you, and it will monitor for any new register— registrations of that. And it'll also do a test, uh, of your MX record to see if it could be misused or inappropriately intercepted. Yeah, pretty cool.
It's good stuff. All right, that is it for news. Oh, actually, I have a little personal news, Alex. Um, I will let our listeners know I've started a new job as of this week. Um, I am— I'm now the chief Trust and Security Officer for another technology company here in Colorado called Pax8, headquartered in the Tech Center.
I'm excited to, to kind of get started again. About 6 months off of, of working and ready, ready to start again. So you'll hear in the job section, I'm going to talk about one of the jobs I'm hiring for and looking forward to, to getting right back at it. Congrats, Robb. Welcome back to the world of the working.
Grinding. Back to the grind. Love it. All right, let's jump over into events. Let's, as a reminder, we do have a calendar of events on the website.
You know, this time of year it kind of slows down. Uh, you know, I think most organizations kind of think in a year, in, in a calendar year themselves. So we don't have a ton coming up after December, but there are quite a few months or quite a few events this month for sure. Uh, starting off, ISC2 Pikes Peak is doing their December meeting and holiday lunch on the 8th of December. And then the biggest day of the month is the 12th.
We have biggest day of the year apparently. Yeah, maybe so. 3 big events. CSA Colorado and the Lyft Group are doing a holiday party on the 12th, along with the annual, always fantastic joint ISSA and ISACA event that's at the Botanical Gardens this year. And then the 3rd event, the ACES, the Physical Security Group, they're doing their holiday happy hour and board nominations as well.
Robb, I put all these in earlier, and I think looking at the timing, you could probably technically get to all 3 events if you wanted to. Each of these? Not for all of them. Okay. But you can attend a little bit of each.
You can make an appearance at all 3 of those events if you wanted to. It would be a lot of driving and not as much time at the parties, but you could do it. If you do that on Tuesday the 12th, send us a picture of you at all 3, some evidence, and we'll put it up on LinkedIn and give you a shout out. Yeah. We'll send you something cool too.
There you go. All right. On the 14th, the Let's Talk Software Security group is doing their monthly meetup. Are industry security controls relevant? And that is it for events this month.
Uh, after that, everyone figures that you're done for the year. That's right. Last couple weeks of the year, take some time off, no events. All right, let's jump over to jobs. Um, I, I was, I was surprised there are a ton of security leader jobs this month.
I wasn't looking for that as I was collecting jobs, but man, I— that's really all I found. But anyway, the first one, the, the best one, the most important job on the list is at Pax8. We're hiring a director of GRC to help to help build out and maintain a GRC function for a very quickly growing technology company. Reach out to me if you're interested and just apply online as well. Spectrum is looking for a VP of Information Security Engineering.
Vertafore is hiring a VP of Cybersecurity. Zoll is looking for a Director of Information Security and Cyber Risk. Connect for Health Colorado is hiring a Director of Cybersecurity. Just occurred to me that all 3 of those jobs are based on our friends having left them. Yeah.
To go to somewhere else. Yeah. If anybody's interested in any of those jobs, we know the people that were in them before. So, you know, we can make some connections if you want. That's funny.
Cloudflare is hiring a director for cybersecurity and IT audit. Darktrace is hiring a cybersecurity technologist. The City and County of Denver is hiring a senior manager of airport security at DIA. Sovereign is hiring a privacy ops engineer. That's with our friend Melissa Cooper.
And Denver Water is looking for an IT security architect. And that's with Tung Nguyen over at Denver Water. A lot of, a lot of great opportunities this month. Well, that is it for the news, but we have a feature interview. We've been talking about getting him on the podcast for a long time.
It's been a long time. More than months. Yeah, it's probably a couple of years. Yeah, we finally have Richard Mac Namee on the podcast. Yeah, I actually, I'm, I didn't do the interview, but I originally met with Richard probably over 2 years ago now.
He is the director of the cybersecurity programs at Metro State and runs the cybersecurity operations program there where they're doing Pisces, which we've talked about several times on the show. And our friend Frank talks to him. And Robb, you've got some notes about what they're talking about. Yeah, I mean, they definitely talk about MSU and Pisces. They also talk about like what it looks like to train the next generation of cybersecurity professionals and Her Majesty's Secret Service.
That'll be interesting. Yes. Richard is a Brit, so you get to hear about some of that, some of his military service. All right. Well, that is it.
Happy holidays to all of our friends out there. We will not talk to you again in 2023, but we're excited to see you in 2024. Happy holidays, everybody. Enjoy yourself. Have a happy New Year, and we'll talk to you in 2024.
See you soon. Thanks, Robb. This is Robert Wood, VP of Security at Alps Fund Services. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals.
Well, good morning, good afternoon, and good evening, state of Colorado. This is the Colorado Equals Security podcast. My name is Frank. And today I have a very unique host. I think I'm gonna try very hard to make sure I say his name correctly.
Richard Mac Namee, is that correct? Mac Namee. He just told me this right before the podcast, and I am still going— I am still getting it wrong here. One more time, Richard. It's Richard Mac Namee.
Mac Namee. Okay. All right, that one I might actually get this at one point. So Richard, right, is currently working at Metropolitan State University. He was— he does own his own tech company providing intelligence and risk advisory services, right?
At the start of pandemic, that's of course when he started working at the university, and before that He worked for His Majesty's Secret Service, MI5. So I think the top question from that piece right there is, how do you feel about 007, as also known as James Bond? Welcome, Richard, to the show, by the way.
Well, I have to say, it depends which flavor of 007. There are those who are the diehard Sean Connerys, there are those that have moved on to the Daniel Craigs. As characters, they're all equally entertaining. But what I will say is that in real life, the people who fulfill those roles don't necessarily have the same persona. Okay.
Yeah, I mean, they're probably— and how do you mean by that, not, not having the same persona? Well, I mean, the more they obviously have very charismatic and very outward personalities, um, that obviously plays to the fact they're in a film. But those that actually do the real work in that particular field tend not to be quite so visible. I've actually heard that before. Uh, somebody had written— supposedly he had worked for the CIA— was talking about the TV show Alias where Jennifer Garner plays a CIA agent, and he says, well, 4 reasons why Jennifer Garner will never make it: she's too pretty, she's too noticeable, she fails too often.
It's like, well, yeah, that's why we watch the show. I mean, we watch these shows, we watch these films, because if it is as you described, we'll be sitting there basically watching nothing. I mean, we would watch an office building or something along those lines and nothing would happen. And that's exactly what you like, right? Yeah, it is that you'd be watching a very dry sort of office space with not a lot going on.
To be frank. And there's only one way to obviously make that look, you know, more sensational. That's to have the Sean Connerys and the Daniel Craigs of the world do it for you. Does that also mean that you don't have any of that cool gadgetry like they have made by Q, uh, being able to sit there and hide some, you know, a pen that has poison in it or something like that? Well, that, funnily enough, the technology that we were um, issued was bespoke and was customized.
And I'm probably not permitted to disclose the name of where it was manufactured, but it was all done in-house. And I would say the individuals that did that were probably more charismatic than the actual people that deployed onto the ground. They were wildly intelligent, extremely eccentric, very entertaining. But one thing I learned was to make sure that when you gave them technical parameters, you were very strict about what you actually wanted them to produce. Because they had very little understanding of the actual operational deployment.
So frequently when we went to go and take delivery of a piece of equipment, it was probably 3 times the size of what it needed to be. But their argument was, well, it does it technically, so that should suffice. But very charismatic people. Okay, so charismatic people, but it didn't do what you needed it to do. And of course, this is a device, a weapon, however you want to call it, that essentially would make, could ensure the success or failure of your mission.
How would you approach that to them? Do you come back and slam your fist on the table and say, get this right? Or, you know, no, no, I found that with technical people, they do. I mean, the actual R&D, the designers and the fabrication staff who were absolutely brilliant at what they did, they took huge personal pride in their work. And the worst thing you could possibly do was slam the table.
It was, it was to really lean on your emotional intelligence and your ability to communicate with a very diverse and very talented workforce, but make sure that they felt they were part of the team and you were just trying to refine what they've done. I mean, a good example would be in the very first, if you recall, everybody used to have a car alarm and certainly in the UK and in Europe, you had to have a car alarm fitted. In order for your insurance to actually be effectively enforced. And the first sort of generation of car alarms, the defeats that were used to actually get through those were pretty straightforward. But when you ask them to design a way of sniffing a code, what you did not need was an 80-liter backpack that they produced, which you'd have to carry through the middle of a car park.
You know, in certain cities, you're about the only person carrying an 80-liter backpack through a car park. So the technology, to my earlier point, worked, but the operational understanding in terms of the environment was sorely lacking. So you had to find a very creative, a very constructive way of guiding them through the operational environment so they understood, you know, how it had to blend in with the background. Gotcha. Now, does that experience explain what you're doing now?
And my understanding is that you're training some Tier 1 SOC interns. You're actually at the Cybersecurity Center in Colorado Springs? Yes, today I am. Yeah, we, we've built a program, um, which we, we actually run from MSU Denver in, in the center, but we actually deployed down here to train 47 Tier 1 analysts from UCCS and from Pikes Peak State College. So yes, I think a lot of those skills that I acquired in earlier years have direct application to what I'm actually doing today.
Okay. And can you tell me more about this program that you're working on? I mean, is this a— is this something where you can tell me about it and then I can publish it? Or is this something you can tell me about it and then the next thing I know, all trace of me is gone from the internet? No, no, not at all.
Not the latter. Um, okay, okay. The short version is it's called Pisces. P-I-S-C-E-S. And this came out initially from the state of Washington. And if you and your listeners consider the, the rural expanse of the United States, you know, we've got thousands of small counties and municipalities and cities that actually have no real security budget of any description.
And if you then consider, um, the, the idea that we're trying to now, you know, develop a talented workforce to provide these types of services. What Pisces did was say, well, look, why don't we do this? Why don't we go to those smaller entities? For want of a better expression, let's put a collector on a network, take the data, push it to a stack, and let's find a university that can analyze that data. And the win-win being those smaller counties and municipalities get free monitoring, and the university students that are doing their various cybersecurity degrees at various organizations, entities have the opportunity to gain this much-needed hands-on experiential experience that they all need to put on their resume.
You know, a 4-year degree is going to only get you so far. You then need, you know, as we all know, industry certifications is one, but also some experience. And what this, this does is allow the students to gain that much-needed experience. Well, that's kind of interesting because they're— so what you're saying is that they're analyzing real data. Correct.
And I guess, you know, because what some people know about me is I am an educator. I do teach for a couple of different universities. And some of the things, some of the conflicts are, I guess it goes back and forth in my head, is that when we do our labs, we of course know what the results are going to be. You type this, this is the results, etc. But in the situation you just gave, you don't know what the results are.
Correct. So what we're trying to achieve here is, or what we've already achieved is the— and let me back up a little bit to understand how we funded this— is that if you recall, the state of Colorado incurred— sorry, was impacted by a fairly serious breach. The Attorney General's Office received a settlement. And what I did was went to the Attorney General's Office and said, look, now you've got this settlement. Why don't we think of a way of shoring up the state's security and posturing by, you know, developing the next workforce and thinking about how we equip them with real-world hands-on experience?
And that's where Pisces came from. We're all under NDA, so I'm not at liberty to share the names, but we currently have 12 customers. 6 of them are school districts, 4 are counties. One is an emergency response service or agency, and the final one is a city. And that's within a period of 12 months.
So they're onboarded as customers. And by the end of today, we'll have 95 analysts that are analyzing that data. They are there. And if they find and identify anything, that's escalated to a Tier 2, which are our team leaders, of which we have 4, and they will in turn escalate to Tier 3. And that will then go into the National Cybersecurity, where I'm sat today.
And they will be responsible for informing the customer. So the only feedback we really get is when we get something that's escalated, actioned, that comes back down through the NCC, and the student then actually gets a, you know, a pat on the back. Congratulations. Thank you very much. So you're getting positive feedback from a, you know, in a real-world scenario, which is incredibly helpful.
Okay, well, that's Interesting. I mean, because, and I think that it's great that they're working with real data, but if they've never seen any of this data before, let's say a malware attack, a phishing attack, take your pick. What do you think will really be helpful for them? I mean, what, or what would happen if they missed something and they failed to escalate it up? Well, we, by virtue of the way we've, we've, we put them in teams so that you've never really got just one set of eyes.
Looking at a problem. You know, there's, there's 4. I think I've— some of the previous information I've shared with you is that whilst we exist in a very technical world, this comes down to humans. And what we've identified is that a single analyst sat looking at a GUI or, you know, a screen for 8 hours is probably not a very effective way of solving this problem. What we found is you team them so that there's a better chance of that a mistake or that issue you mentioned not being missed by virtue of there being numbers being applied to it, which we can do because we're dealing with students and we've got, you know, no shortage of students.
And what about motivation? How do you find them? Do you find that they are motivated? Well, we did initially when we ran the pilot, we did not really market it as such. We wanted to find out, you know, at grassroots level, one, What was the, what would be the training burden on our side?
Because before we dipped our toe into this, we wanted to understand the commitment we were going to make. But then when we finally secured the Attorney General funding earlier this year, I was able to reach out to students and say, look, do something that's actually bigger than just you. You know, your work is actually contributing to the safety of the residents of the state of Colorado. And believe it or not, even today, despite the very negative things we've seen social media and worse, you know, that's going on, there is, there is a sense of wanting to belong and wanting to, to serve. And we found that actually that's a very attractive aspect to this, you know, no shortage of students wanting to turn up, wanting to do the work for the benefit of the state and for doing something, you know, bigger than just themselves.
We found it to be quite appealing. Do you think that stresses them out a bit though, being responsible for, as you said, Colorado? I don't think— we haven't reached that point yet where we've identified them being stressed because we've got a very robust group of team leaders that can identify, you know, they're very experienced. They've got commercial security operations center experience over many years. So they can identify very quickly that, okay, this person's probably not handling this particularly well.
So we, but we've not yet reached a situation we've got stressed out students. We try and actually, actually we try and make it fun and enjoyable and that we found that team component really does help address that as well. Okay, so try to address the burnout situation before the actual burnout happens. Correct. Yeah.
Okay. Well, we're talking about training people, and one of the things I see in your profile is that you like to find ways to improve human performance. Uh, you yourself is a, what, elite professional triathlete? Can you tell me a little bit more about that?
Well, yeah, I found— so during my service, you know, I was being operationally deployed 280, 300 days you know, in a year. And what I found was that you need, you need an outlet. You need to be able to remove yourself from the operational environment and almost normalize a bit like a diver coming up, you know, you know, in order to avoid the bends, you know, we know we've got to go in a very staged approach. So I, I was at great pains to find a way where I could just Disappear off, you know, into a, to go swimming or ride a bike and, or go and run. And it was for the benefit of me, you know, I wasn't doing it for somebody else.
For once I was doing it for me. And I just found that having that outlet allowed me then to step back into my operational role, rejuvenated, refreshed, and, you know, my thought processes and who, you know, who I was and how I was feeling physically, psychologically, emotionally, and spiritually. You can get a lot of that out in the hills on a bike. You come back in and your contribution is rejuvenated and fresh. What I've seen in my time in the tech space and particularly in things like incident response and crisis management is immense burnout because people don't take a break and they don't take a break to look after themselves.
You know, they're sat behind or sat in windowless rooms behind a computer for 14 hours a day and not realizing, you know, there is a time to get outside, get some photon on the eyeballs, get some fresh air, think about, you know, your diet and what you're eating. And we're trying to introduce those types of— not to turn everybody into an elite athlete, obviously, but to actually give them the skills not just to be able to operate in a complex technical response mode, but also be able to look after themselves because From my experience, major breaches, they're endurance events. They're not sprints. You know, they're not, they're not over in a Usain Bolt 9-point-whatever for 8 seconds. You know, these, these are, these are going on for weeks, if not months.
In fact, one we're dealing with at the moment has gone on since April of this year. So it's how you actually improve someone's ability to perform as a human day after day after day. Without them burning out. So we're very early on in the process trying to educate them not just with those hard technical skills, but those survival skills in how to look after themselves so they can perform on a repeatable basis. Well, I think that's actually excellent advice.
I'm assuming that some people here on this podcast already know about this, but I always try to say for the hardcore professionals, you have to have something that is not technological as a hobby to just not look at code, not look at tech. Bike riding, I do the bike riding part myself and I go to the gym when it's too cold up here, you know, here in Colorado. So I think that is actually excellent advice. Yeah, I've seen it with my, I've just recently hired my, an associate director to run the training and operations. Very talented young man.
I'll spare, I won't, well, I'll spare him a blush by not mentioning his name. But one thing that I pretty much insisted on is him having, you know, the ability to disappear and go and fish, take out a fly rod, go and stand on a river, get cold, get frustrated, but actually do nothing remotely connected to technology. And I think that is moving forward, that is a critical part, certainly in, I think, our sector, to make sure people understand, you know, you do need that outlet which is non-tech related. And we're pretty hard on it actually. And I'm proud of that.
Excellent. Well, that again, I think that is just some excellent advice to give people. You just said you had mentioned something that you had said that you just introduced and hired a new person. How would you start? Like when you start meeting people in this, whether they're a student, another person in the community, you know, maybe your interviewer or podcast, do you just always say hello or is there a great way to start a conversation?
What is your favorite thing to do? Um, I, so coming from Europe, we, I grew up where, you know, you, you genuinely shake, even though you know them, you'll shake somebody's hand and it's always good morning, good afternoon, good evening. There is always some form of salutation and some sort of greeting. You know, I've raised manners maketh the man. And I have to say today, maybe it's just the speed of society and some people's use of technology.
A lot of those, dare I say, some would call almost antiquated approaches actually do still matter. Having somebody that can lift their head from a mobile screen and take the time to say good morning or hello and you know, just be polite. That goes a long way. And the reason we, again, we focus on that a lot in our particular program is that when I initially was hired by the president of the university to come out, I was living up in the mountains, uh, and come down and build this, the Cyber Center at Denver, in at MSU Denver. One of the things that we did was, apart from introducing the hard technology, was to work on what initially was called soft skills.
I actually call them essential skills. So we make them come out of a simulated range environment where their network's being attacked and take fingers off a keyboard and then walk across, we call it the 10-foot walk into the bullpen in the center. And then I'll play the role of a chief operating officer of a company with no technical background. That's the role I play. And they've now got to communicate with me in English, not tech.
And explain to me what's happening to my company. And I've just found that if we can work on those, those softer communication skills, understanding the importance of introducing yourself or just the simple thing of saying hello or good morning, you know, that starts to break the ice a little bit and allow those very talented techies who sit with fingers on keyboards all day long to understand if you wanna progress, there comes a point you've gotta communicate and calibrate your language. So we do a lot of, and I focus on that. The associate director does more of the hard technical. I focus on that soft stroke essential skills.
So yeah, so because of course you can't go up to a non-technical person and start talking about, well, this vulnerability is going to affect this process, etc., right? I mean, is that what you mean by that 10-foot essential walk? Yeah, it is. It's when they We appoint team leaders. So it's not just about learning, you know, what the tools are doing in the environment.
It's actually an understanding, okay, you are now beyond that and we're making you a team leader. You need to scoop up and collect all that data that your team is seeing, what they're seeing, and actually put that into a 5 W's, you know, who, what, when, where, why, and be able to express to a non-technical person what is happening. And that they, they get 10 feet of walking space to start making that adjustment. Initially, a lot of them find it incredibly hard. It's not— it's meant to be hard.
It's meant to be a learning process. Um, but as you, as you do more of it, and typically our, our students, they're going to get attacked 8 times in 15 weeks, you know, by the time you get to number 4 or number 5, they've got it. You can almost see the cogs turning. And McNamara's just asked me to come and brief him, and you could see the the pain on their face has suddenly changed into, okay, I've got this. I now know what he wants and he doesn't wanna hear a single acronym and he doesn't want any technical jargon.
He wants to know how this is impacting my business. And I have to say, the employers we've had in there looking at potential candidates, they really like that flavor that we've added to it because it's a skill that if they don't arrive with it, they're gonna have to train them in. You know, when they first enter the workforce. So do you think that would be a good thing to integrate into all training programs? Is that soft skills?
I do. Yeah, I really do. Particularly I've seen, well, I refer to them as digital natives and digital immigrants. And we have got generations today that have grown up in a world where everybody, including themselves, has had a cell phone from day one. But we still have those that are still learning about the technology.
So the ability to gauge an audience and calibrate your language is an essential skill for survival in the business world. Let's face it, you know, anything in cybersecurity is supporting a business mission. So you've got to really understand how that you fit into that mission, but how to convey in their language as a, you know, the senior leadership, the issues that you've identified and how it's hitting their mission and their business. Yeah, I would, I'd strongly encourage them. Cool.
Well, you know, we've been talking about some of these things with how about the training and I think we can all see that you have a lot of experience here. When you sit there and we talk about these war stories and I'm reading through your profile, I see that you say you're a Quiet Professional, but it's capitalized like it's a proper name. So I'm kind of wondering about that. Yeah, so the word, the word, or the words Quiet Professionals comes from really more not so much the, the Cold War, but the generation that then followed, in that we grew up in a world where we were conducting, for example, covert operations against the Provisional IRA in Northern Ireland. And anybody who reads any history about Northern Ireland will also know it was referred to as the Dirty War.
And there was a lot of work that we were involved in that none of us, for our own personal safety, would want to be associated with in terms of a headline. So we conducted the work in the interests of national security for the benefit of our country. And not for the winning of a headline for our own personal benefit. So that notion of quiet professionals has sort of permeated throughout my entire professional career. I came, I still come from the era that served in various parts of the world we are not even permitted to discuss.
And I vowed I'd never write the book. And I have been offered, you know, money to write books, but it goes against the very grain of service. I'm actually a member of a fabulous club in London in Herbert Crescent. It's the Special Forces Club. It's a beautiful building that was bought and it was dedicated, it really stems from what was called the Special Operations Executive, the SOE, which is the UK counterpart to the US's OSS.
And when you go into the club, when I first went there many years ago, there's a little restaurant or a dining area. And there was this very elderly lady sat in the corner from France, and she had been part of the Resistance. And if you didn't know otherwise, there was this frail, very well-dressed French lady sat there having breakfast. If you saw her walking along the street, you would have no idea what she had done. But by virtue of the fact she was sat in that dining room in that club was a very powerful testimony to the, to what she'd actually done during the war.
And that's, that's the world we come from. And I'm very proud of the fact we don't find it necessary to write books about it. It's almost like winning the Olympic gold medal, but not being able to tell anybody you've won it. That's the way it should be. So that kind of goes back and circles back to your statement about the 007 thing and how you would never, probably sounds like you would never even pick her out of a crowd.
You see her walking down the street. Is that? Yeah. Absolutely. Yeah.
Yeah. Yeah, very much so. Okay. Well, before you got into the military, right, you did a gap year at what, the forex markets? What is that?
Right. So I, I was actually very lucky in that I, I actually managed to get through my, what we call secondary education. I was at a private school in London. I actually got through it very early. And it's not quite as popular over here, but in Europe they still do today.
We take a gap year, you know, before you decide where you want to go. And I knew very early on, I was very, very lucky in that I knew I wanted to be a soldier. So I knew I was going to go to Sandhurst and I couldn't go because I was too young. So I had my gap year and I had no idea what I was going to go and do. And I decided, well, I speak a little bit of French.
Why don't I do something involving maybe banking, international payments? You know, I don't know why I decided that particular avenue, but Forex stands for foreign exchange. So I spent a year working at Lloyd's on the foreign exchange where they were trading currencies. And interestingly, I don't even think— I'm casting my memory back now as we're going back pretty early on, mid-'80s. Yeah, computers might have been something in there, but we would actually hold a position in a market with a pad of paper that was probably about 36 inches wide and, you know, 24 inches in terms of diameter.
And we'd be holding a position with a, with a pad and a pencil in the markets. And I was, I was basically what they called a position clerk. So the traders were trading currency, and I was on US dollars and sterling. And I was the one that had to sort of work out how many dollars we had and how many dollars we sold. So fascinating experience.
Well, I do have a question. You mentioned Sandhurst. What is that? So think of Sandhurst as being the, it's the good point. Well, here it's West Point.
In the UK, it's Sandhurst. It's the Royal Military Academy, Sandhurst. Okay. Okay. So you chose that versus, let's say, flipping burgers or something.
I don't know if you really wanted that one, right?
Well, yeah, exactly. I, for some reason— well, actually, you know what, I think McDonald's had just arrived in the, in the UK at that point, which is where I was. So I'm not even sure flipping— actually, flipping burgers would have been a place called Wimpy. And I have to say, they were, they were not good places to go. Guaranteed food poisoning at a Wimpy.
So McDonald's was very welcome. So, so Wimpy as in the, the Popeye character? Yeah, W-I-M-P-Y, Wimpy. All right. So what did you think of the McDonald's over there compared to, I mean, I think you might have a unique perspective.
How does McDonald's compare from the United States to, you know, Europe? Oh, when McDonald's first arrived, it was a sensation. I mean, it really was because up until then it was Wimpy Bars. Which were notoriously bad. And when McDonald's arrived, it was clean.
It had that sort of clearly an American touch to it. And there's always been a fascination with the United States. So no, it was a huge success, particularly milkshakes. That I do remember. Particularly what again?
I'm sorry. Milkshakes. Oh, milkshakes. Gotcha. Gotcha.
Okay. All right. Well, this is the Colorado Equal Security Podcast. So let's address a security issue. Yeah.
What do you think is the greatest security challenge today? Now, we're not saying that you have to solve it, but what do you think is the biggest problem?
Talent and people. Okay. So when we, when I look at the landscape of all the pipelines of talent that we have today, One area which is really struggling to recruit is the government side. So federal and state government. And the reason for that is, let's face it, that their rates of pay are nowhere as attractive as the private sector.
And if we take a— if the question is put to you, okay, what's the priority here in terms of private sector, public sector? I'd argue that they're actually— they're equal in that, you know, we clearly— there's a huge amount of infrastructure that sits within the ownership of the private sector that the government side doesn't have ownership of, but it needs it to actually function the way it should. So one of the challenges is staffing in both of those areas, but also the collaboration that should exist between the two. And I know there have been great strides made to try and improve that, but You know, it's when you get to the point where we, we get ourselves wrapped up in security clearances in the government. And, you know, there's frequently occasions where the government will turn and say, well, we can tell you this, but we can't tell you this.
You know, there needs to be some way of improving that and just having almost like a, a Post-it note with a one-day clearance that says you're cleared. Now this is what we're going to tell you. This is what we've identified, go away and solve the problem. So it's like the first one is talent into those 2 respective areas, identifying it and recruiting it. And then the other is retention of that.
I can think of several examples where I've had some very, very talented people that have come through the other programs that I was running at another university some years ago and They decided they were going to dip into the private sector. They paid them extremely well, and, you know, they went off and maybe experimented with some various forms of substances around the world. They then decide that actually I'd like to go and do something for the government, and all of a sudden we've got the drug policy issues to consider. Plus they sort of— they've lived in a, you know, with an income of X, and they're going to be asked to take a drop of X, you know, minus 20, 30%. In order to serve.
So it, to me, although it's a hugely technical field, the problem comes down to people and finding the right people, recruiting them, retaining them, and paying them properly. That, that's where I think the problem is. So for our folks that work for the government or any of those type of agencies, what advice would you give them to try to retain those people? Let's say that I'm working for you, you're— and this is the government, or even your, your students that you're training now. Is that part of your lesson plan?
How were you training them? How are you convincing them? Well, I, having come from a world of where I dedicated, you know, decades of service, I've often asked myself, well, okay, what— why did I make the sacrifices I made, you know, for the— for what I was doing? And it was It goes back to one of my earlier comments. It was a sense of contributing to a much broader mission and doing something, you know, not just for yourself, but for the benefit of others.
I, some may say this is a hackneyed phrase, but when I was at the Bush School of Government, you know, the byline was service is a noble calling. You know, there is still immense value in doing something for others. And To a certain extent, you know, if you've got people who are serving in government who are questioning, well, you know, I still can't, maybe I've gotta think about putting money into the school fund to get my kids through college. And if I jump ship now, I could earn another $30,000, $40,000, $50,000 and it would solve the problem. Yeah, maybe.
But I would say that when you do that, think carefully because the corporate world is a very different animal. And yes, okay, they do very meaningful work and I'm, I'm actually in the private sector. So, you know, I can see the benefits of it, but don't lose sight of being part of something where you're actually doing real work that could potentially, you know, arguably save lives. That's not a corny hackneyed phrase. It's, you know, if you're doing work that's of value to the government, you're benefiting the citizens of this country.
And then on the private side of it, You know, don't necessarily be lured in just by the dollar amount. You've got my sound, my real advice that sort of backs this up is you've got to be passionate about what you do and don't follow the dollars because there's nothing worse than being stuck in a job where the money may be great, but actually you don't really enjoy what you do. And sometimes you can do things that don't necessarily pay as much, but you know what, you're surrounded by great people, you're doing a fabulous job, um, and you know, you're in a great environment. So don't be lured away by money. That's, that's my advice.
Well, I, I definitely believe in that. My current job, I took a pay cut, and, but I'm much happier at where I'm at. Uh, yeah, my stress level is about half of where it was before in my previous job. So absolutely, I understand that. Uh, I also understand doing things with honor.
One of the things I probably, we probably haven't discussed, but a lot of people that know me is that I am a U.S. Marine. And why did we do this? Why did I join the Marine Corps when I actually had an opportunity to go to law school? Yeah, to serve my country, right? Yeah.
So I, I, I absolutely understand that. I also understand what you're trying to do, and I very, very firmly believe in what you said about the money part. Right. Yeah. I tell people that are trying to get into this industry and the first thing they ask me is, what does it pay?
Or these guys make so much money. And I'm just like, if that is your first question, this is not the career field for you. Right. I agree with that. I agree with that 100%.
Um, unfortunately, I, I see a lot of it today in terms of, you know, I won't call them young kids because they'd probably, they'd hate me telling them that. But I do, you know, I see them that way because I have children of their age and they are walking through the door on the basis that I understand this is, you know, probably one of the, the most highly paid professions that I could get into. And to your point, that is the wrong reason to do it because the hours are demanding and you've got to enjoy some of the inconvenience. Because let's face it, an incident never happens between 9 and 5. It's 3 o'clock on a Sunday morning.
You've gotta be ready to step up at short notice and that doesn't fit in If all your motivation was, you know, the paycheck at the end of every month. Well, I think it's also that love for what you do and the understanding because if you walk away and you shut down and you don't even talk about technology afterwards because I actually like to believe that this is not a job. This is actually not even a career. This is almost a way of life. Yeah, I agree.
Yeah. I mean, and I mean, we dealt with an incident earlier this, the one I referenced earlier that started in April and it's still ongoing. I actually treat, um, when we go into a major incident, which is a breach, the B word, you know, I treat it the same way we do the 5 stages of grief. And when I sat down with the partners, it was a local company. Again, you know, under NDAs, I'm not gonna disclose the name.
Local company, 3 partners. One was brand new. One arguably is almost terminally ill. And the third was trying to retire. And you realize their life, their business because of the scale of this, that business was about to just explode. And our work and what we did was really save the livelihood of one, you know, the 3 partners, but also the 28 staff, small company.
But that's 28 people who still have a job that can still pay rent and put food on the table. And you know, the motivation to do that in my mind is to actually ensure that you have people that want to serve others and actually be a benefit to others and are not even worried about what the bill is at the end and how much they're getting paid. So it's a different beast. It is a lifestyle because none of that was done at, you know, from 9 to 5. It was all done on a Sunday afternoon at 4 o'clock, hugely inconvenient, but actually it goes with the territory.
Yep. Well, Richard, that is all the time we have today. I want to thank you so much for your time. Definitely, we will put your LinkedIn profile in the show notes. Check out MSU, right?
Metropolitan State University. It's a university that I have great respect for. In fact, one of my close friends is a dean over there in the nursing section, but is a dean over there. She speaks very, very highly of the organization. Uh, so again, thank you for your time.
My name is Frank. For those of you that don't happen to know me, I am a board member of the Denver OWASP Group. We just had a great conference or great meetup at Dave Buster's. You can find us at meetup.com/devera-owasp.
And we have just announced our annual SnowFROC Conference that we're going to have at the DU Cable Center. It looks like we're going to target March 7th for that. We'll have great speakers, great conference. And Richard, I would like to personally invite you to be there, maybe with your staff to help us out. Absolutely.
Consider it done. Awesome. Well, you know, I'm gonna hold you to that because it's on the recording now there, Richard, right? All right. I get it.
Understood. All right. Well, again, thank you for your time. I really do appreciate it. And I hope to see you soon.
Thank you very much, Frank. It was a pleasure. All right, pleasure.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.