All episodes

Dr. Erik Huffman, Director of IT at BombBomb

Apple Podcasts Spotify SoundCloud

Dr. Erik Huffman, Director of IT at BombBomb is our feature interview this week, interviewed by Frank Victory. Check our Erik’s Ted Talk here. News from ACI Learning, VF Corp, Red Canary, Ping Identity, Optiv, Secure64 and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13796 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 258. Happy New Year!

Happy New Year! January 8th, 2024. Um, we're already a week into the new year though. Yeah. Uh, Robb, that was probably too loud looking at my, uh, my levels there and the thing, but we are in a new year.

We're in a new year. Thanks for calming down. Yeah. People probably turned their volumes all the way down now. Anyway, I blew out everyone's speakers.

My bad. But you know, you only have 51 more of these weeks before you get to say it's a new year again. That's true. We're, uh, we're, we're already almost there. Yeah.

Hey, um, we have, we have, uh, so much interesting news to go through this week. We do. But before we get into the news and the interview, we have a little bit of housekeeping. We like to talk about the fact that we have a Slack channel, and in that Slack channel are 2,500 of my very favorite people. If you're not in the Slack channel and you're not my wife, you're not that great.

So get in there and you can be great like the other people in the Slack channel. To get in there, go out to colorado-security.com and click the Slack, join Slack button, and you can see us there. There's also a place on the website to join our mailing list that gets the show notes and a few other communications. Sent to it. So do that as well while you're signing up for Slack.

Also, it would be great if you could rate us and subscribe on your favorite podcatchers so that you get this every month when it comes out. And, you know, we get, you know, marginally meaningless metrics of, you know, who downloaded and who listened. Speaking of great people, you know, if you want to join the ranks of great people, you could join our Patreon campaign. We actually every month get just a little bit of money from a group of folks who help us keep running. And, and, you know, those— just a huge shout out to those people who do that.

Um, they, they pay the, the hosting fees and the website fees and for all the hookers and blow that we go through as we record these podcasts. Um, it, it is important to us, and, and none of that money is used for anything other than improving the Colorado security community. Um, and hookers and blow are clearly, clearly improving the community. No, no one listens to this part of the podcast. They just get back to the news.

Anyway, speaking of the news, Alex, there is new news coming from DIA. I feel like this is almost like the DIA podcast sometimes. I know we do end up having a lot of news about DIA. But this is new news. This is new news.

DIA has received or is beginning to receive new cars to update the passenger trains from the main terminal to the departure terminals. So, you know, I go through the airport quite a bit, I'd say. I'm an experienced traveler. And one of the things that I never complain about at DIA is the trains being old. I didn't— I never thought about that, but they are like almost 30 years old.

Yeah, it's pretty crazy. These are sort of the original trains that they had. And so now it's— they're at the end of their life and time to replace some of them. And the good news is the new trains they're getting are more efficient and they will allow them to try to carry more people. So you're going to be able to— they gave a number, but they didn't give a percentage of increase of people.

So it didn't mean anything to me. Uh, but they're gonna be able to run 8 trains for every 7 that were previously run, get a lot more folks through. Um, hopefully it'll help deal with the ever-increasing crowds at the Denver Airport. Yeah, I think these new train cars are slightly faster, which allows, uh, more trains per hour, hence more people per hour. Uh, it, it says they're gonna be able to do 850, uh, people to the gate per hour.

Additional, additional, additional. Yes. Yeah. Uh, which is good. And, uh, yeah, I mean, I think that there are times today when you, you know, you get to the train one way or the other and it's fairly crowded.

Yeah. Um, especially coming back, uh, from, from your gate if you've arrived. So I think that, I think that I have, like, on the way from security, I have got to the gate, to the train and not gotten in because there was too many. I think it's happened once. It's very seldom, but a couple times.

Yeah. So if this can make that go away, that'd be fantastic. Yeah. So excited to see that. I think I have at least one trip every month for the first few months of the year.

So I'll be excited to see if I end up on a new train car. You won't. It looks like they're not going to have these out until, until like just about summertime. So they— by the summer rush, they said that they'll be, they'll be in service. But speaking of in service, the, the government has named that Colorado will be one of the 2 tech hubs to service the United States.

For tech hubs for quantum, for quantum, yes, for quantum technologies. And we've talked a little bit about this before. But this article is talking about a little bit more around what does that mean, right? Like, we've been named a quantum tech hub, along with Illinois. And, and what does that mean?

And really, it's, it's access to funding. Yeah. So what's interesting is, while both Colorado and Chicagoland area are the quantum tech hubs, they're not really the same. The focus for the Colorado Quantum Tech Hub is really all about the commercial viability of quantum computing, more about how do we find practical applications, right? Whereas the Chicagoland area is focused more on the cutting-edge tech part of it and really trying to be diving deep into what the capabilities are from a tech perspective.

I think it's interesting that they have those different lenses on it. They will, I'm sure, will be competing with each other though as they look to get this funding, because of the 30-ish tech hubs that were named, only 5 to 10 are going to be able to get that juicy, juicy federal funding. Yeah. Some interesting facts, Robb. Did you know that Colorado is home to 4 Nobel Prize-winning scientists for their quantum research?

I did know that. Yeah. Because I read the article. Yeah. But I didn't know it before reading the article.

I— and I didn't even know that there were 4 Nobel Prize-winning quantum scientists before I read this. That kind of surprised me. I also was surprised that Chicago has a— what do they call it, like a quantum accelerator or something? They're home to the first quantum accelerator in the country, which I don't even know what that means. It's like, it's like SLAC, the Stanford Linear Accelerator, except it's a quantum— like, I don't know.

I don't know either. I thought this was computing, so I don't know why you're accelerating things other than making things faster with more qubits. Yeah, maybe, maybe accelerator isn't as big as I'm thinking. We're— I think we're beyond our— we should probably stop talking about this. We should move on to something else anyway.

Next story. Here's a story about an acquisition. There is a Denver cybersecurity company that acquired a Baltimore edtech firm. So, I mean, we, you and I know the Denver cybersecurity company landscape fairly well. I'd say, I'd say we're probably up in the top 0.001% of people with knowledge of the Denver, Colorado security landscape.

Yeah. Never heard of this company. Me either. Yeah. It was ACI Learning.

Uh, they, they do training. They actually have an office a mile or 2 away from my house, um, at Arapahoe and 25. Um, it looks like what they do is they, they do some specialized trainings to help people, uh, you know, get learned up on security. Yeah. Um, this was a curious one, I think partially because both of us, uh, had never heard of ACI Learning.

Uh, but, you know, when we investigated further, you know, looking at the leadership team for ACI Learning that none of them were really here in Colorado, which is surprising for a Colorado-based security company. So yeah, they, you know, they obviously have a presence here that with those couple of— they have also had an office in the Springs. And the company they acquired was— oh man, what was it called again? I forget. But they were based out of Maryland.

Yeah, they acquired that other company that I am embarrassed I can't remember the name of— InfoSec Learning. And InfoSec Learning sounded like a pretty interesting one too. They had these like 1-hour kind of quicker trainings that would correspond with other more formal education. And the fact that they're combining these companies seems like a pretty good fit for— honestly, what I'm thinking as I read this is maybe I can find a less expensive way to get quality training than SANS. There you go.

That's what I thought. Yes. Uh, okay, moving on. Uh, next story. Uh, VF Corp, which moved its headquarters to Colorado, uh, several years ago, sadly was hit by a cyber attack which limited its ability to fulfill orders.

I mean, there's not a ton of information in here. It sounds like a fairly standard ransomware-type attack where they saw bad guys in the environment, they started encrypting stuff, it took down systems. Good news for VF Corp was that their stores were still able to run. Bad news is they're not able to fulfill orders, at least they weren't when this was written. I'm actually not sure.

This was, I think, 19th of December, so it's a few weeks ago. Hopefully by now they've got this figured out, huh? Yeah. But, you know, local company, you know, it seems like every month we have a couple of local company breaches that we could talk about. This one's maybe interesting because it's a big name that we talked about when they moved to town.

But generally, it just happens so much that we let it go. Yeah, it's, it's also one where since it's been several weeks ago, I would expect soon a follow-up article with more details on, on what happened based on further information from the company. All right. Next, we have— we're kind of getting into this, you know, New Year review type stuff. Red Canary did a blog post with their best of 2023, and this is their best blogs, their best webinars, their best research.

Alex, I thought it would be fun for us to both go through this and, and pick our favorite item from 2023 from Red Canary. Did you have something? I think that would be great. But, you know, Robb, since I'm so generous, I'll let you go first and you can choose the first one. You know, out of all of the things that are in here, I thought that the— this collaboration they did with Black Hills Information Security was really fun.

So Red Canary and Black Hills together released a custom expansion pack for the well-known Backdoors and Breaches role-playing game. And this custom expansion pack, they actually played a game, Black Hills and Red Canary together, and they recorded it. And you can watch a video of Backdoors and Breaches with some of our friends from the very tech nerdy companies. That's pretty cool. I think that is an interesting pick considering earlier this week, we were talking about whether we would actually include a Black Hills InfoSec article in the show this week, which talked about their implementation of some Atomic Red Team things.

And we did not. And we did include them anyway though. So they made their way in no matter what. You're welcome, John. Yeah.

The one that I'm going to choose is in their best new blogs section. And this is the one talking about introducing the Red Canary Mac monitor. Oh yeah. Mac monitor was something that was announced this year and it's sort of a, a first-in-class, best-in-class tool to do, you know, in-depth monitoring on the Mac. You know, this is stuff that has been around for a while on Windows, the Windows side, but there really haven't been tools like this on the Mac side.

So cool to see that Red Canary has those tools and for free, for free. Glad that they're out there and everybody can use them and enjoy them. I looked through all the blogs, but I was mostly looking to see if they had anything by me in there and they didn't. So I did not pick those. Wah wah.

Speaking of end of year things and places that I have worked in the past, Ping Identity had a, had a, what, you know, every year what you expect to see there, 2024 predictions. And as you can imagine, they predicted identity was going to die in 2024. Really? Isn't that? Wow.

No, no. I think instead they predicted that identity is paramount to securing our new distributed world. That's crazy. I think Andre Durand, the CEO and founder, started talking about how that identity as the new perimeter was going to become more of a, more of a real thing for enterprises. There's also some talking here about passwordless and passwordless authentication, which I think is continuing to take off.

John Canova, a friend of mine, is the CIO over there. He posted around the continual improvement that artificial intelligence is going to have among business leaders internally. You know, he's the internal CIO there. I think he's focused on how he can get leverage from that. Yeah.

Alex Riles, do you know Alex? That's Alex Riles, is talking about decentralized identity and new innovations in that area. And I do tend to hear more and more about decentralized identity. I don't know if this is the year for decentralized identity, but I'm sure we will continue to hear about it. This the year for Linux on the desktop?

I thought that was, uh, 1998. Um, Alex Laurie, uh, the SVP of Global Engineering, talked about that deepfake technologies are going to penetrate every level of society, which will be interesting if that's the case. Uh, every level is a lot of levels. Yeah, yeah. And there, there is one more, but it's again a little bit of a talk about passwordless.

So, uh, I think we've covered all of the themes. Good stuff from Red Canary. It's always fun to look at. Ping, different company you worked at. Well, good stuff for both.

A red security company in town that I was fortunate enough to work at. Robb, you have a type. I have a type. There you go. All right, moving on.

We also have an Optiv blog here talking about one year later managing security in the age of ChatGPT. Hard to believe that it's essentially been a year already since ChatGPT has come out and been the rage. I think that that realization was what made me be like, yeah, we should have this story in here. And it starts off good. It gets kind of long by the end.

I had a hard time making my way through the whole thing. But I, I think the, the point being, hey, ChatGPT is here to stay, and this blog gets into some really important points about what you should think about for your own company. It, it does take a little bit of a left turn and starts to talk about APIs and API security, which is related sort of, but certainly part of taking advantage of it is understanding how the APIs work. All that to say, you got to be thinking about how you guys secure APIs and you got to be thinking about how you secure generative AI. Optiv's right.

Thank you for writing this blog post, Optiv. Well done. Well done. All right, moving on. All right.

We have one more news story here. Our friends at Secure64, the local DNS security company, they, they have a press release and they're talking about, I don't think it's necessarily a new capability there. I think they're just giving some more information around how they do AI and machine learning or how they use AI and machine learning to look at your DNS requests. And I actually learned, this is a press release that taught me something. I don't know if that's ever happened.

Wow, that— congratulations. What did you learn, Robb? Um, so, so the way— I mean, this part I think we, we both know that, you know, a, a DNS request is, is generally going to be unfiltered, um, go leaving your network because that's the only way you can find websites. Um, the— but that traffic DNS can include, um, other information. You know, it's going to be a slow way.

It's not, not going to be nearly as good as using a TCP connection, but you can actually exfiltrate data through it through DNS, and that generally most security tools wouldn't look for it at all. Most network security tools, hey, it's, it's, it's going to be DNS, we're not going to inspect it. And they're not looking for any kind of embedded data. They're not looking for malformed DNS, generally speaking. Well, what these guys are doing is not only looking at those, but they're running all of those, all those DNS requests through their system to look for potential patterns that might indicate any of these malicious things, you know, the, the inclusion of sensitive information, the exfiltration of data, whatever those things might be.

Yeah, pretty cool. I also appreciate the fact that because AI is cool, even if they've been doing this for a long time, they can now put out a press release and say that they're doing this and people will pay more attention because now AI is cool. AI is very cool. Yeah. All right.

That is it for news. Let's jump over into our events. We have a fairly busy January coming up here. I'm starting up this, this next week on the 10th. ISSA Denver is doing their, their January chapter meetings, uh, both in the DTC and downtown on Wednesday the 10th.

The topic is Navigating Trust: AI's Impact on Media Integrity. That sounds really interesting. That does sound like an interesting topic. I might have to go find my way over there for sure. Uh, on the 16th, the Let's Talk Software Security group is doing a meetup talking about What do our AppSec terms even mean?

Also on the 16th, the CSA Colorado chapter has their, their January meeting, Unlock Your Future in Cybersecurity: A Roadmap to Success. On the 17th, OWASP Denver is doing a chapter meeting, Threat Modeling the AI Pipeline. Seems like a trend here. I know, I like it. On the 18th, ISACA Denver has their January meeting, Managing Regulatory and Compliance Risks.

From AI-driven digital technologies. Still following the theme. Can we keep this going? We could. ISC² Pikes Peak is doing their January meeting on the 24th.

I don't have a topic here, but it's possible that they're talking about it. These guys don't let us know in advance, so we don't know. You should assume it is, though. The 26th ISACA Denver has the She Leads Tech Uplift Lunch. I think this is their, their women in tech group.

Sweet. That is all of the events that we have for this month. All right, let's jump over to jobs. Jump into jobs, Robb. I think there's probably one you want to talk about.

Yeah, um, at Pax8, I am hiring a platform security engineer. This is application security, uh, product security. I'm looking for folks who have, you know, some, some good, uh, software development skills, maybe some pipeline, uh, maybe infrastructure cloud security, but really looking for someone who understands engineering, uh, for that role. If you want to reach out to me on Slack, I'm happy to talk with you. Checker is looking for a VP of corporate engineering and security.

In case you're wondering, there's no second E. And this looks— I mean, it's— it doesn't say it, but it kind of looks like a CIO role. Yeah. We look at it. You have responsibility for security, but lots of other stuff too. Yeah.

Dan— is it Dannon? Danone? Danone? Danone? I mean, I've eaten their yogurt, but I've never said their name.

So the people who make those dairy products are hiring a head of cybersecurity, and it's here in Colorado. Pretty cool. Western Union is looking for a Director of Cybersecurity Architecture. Metro State is hiring a Cybersecurity Affiliate Instructor. Uh, Gensler is looking for a Security Administrator Senior.

Medtronic is hiring a Senior Director of Cybersecurity. Charles Schwab is looking for a Senior Specialist Technology Risk Management. Gusto is hiring a Privacy Program Director. This is a lawyer. You got to have a JD for this one.

It's a pretty high-paid job too. So if you're a lawyer looking for a privacy gig, take a look at this. All right. And Epic is looking for a security engineer. Is that the medical software?

And they're like in Lakewood or Golden or something over there on the west side of town. I did not know that. And it's an in-office position. Pretty cool. All right.

Well, that is the news for us. We have an interview this month with Dr. Erik Huffman. Dr. Huffman met with Frank, who does so many of these great interviews for us. And I'm looking forward to figuring out what is going on with this man who is— I mean, he looks like an internet sensation to me. He does.

He's got a lot of responsibilities and some pretty cool stuff. He's done a couple of TED Talks and some other things like that. So from what I understand, he did those TED Talks to try and build the resume to get on our podcast. That's, that's what I, that's what I hear. I mean, that's usually the way it works, you know, do a couple of TED Talks and then we're willing to talk to you.

Yeah. All right. Well, Alex, that's it. We'll see you again. You know, next time I see you, we'll be more than a 12th of the way through the year.

Wow. Wow. That's pretty crazy. All right. Happy January, everybody.

Thanks, Robb. Hi, this is Chris McLaughlin, CISO with Johns Manville. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals. Well, good morning, good afternoon, and good evening, state of Colorado. This is the Colorado Equals Security podcast.

Today, my very special guest is Dr. Erik J. Huffman. He is a director of BombBomb, a founder of what we call— what he likes to call handshake leadership— is also an adjunct professor, and when in his free time, apparently does a podcast himself. And I'm gonna go ahead and put together— I'm going to ask the question that everybody I know wants to ask you What's up, Doc?

Not much, man. Hey, just, just loving and living life. I appreciate the opportunity. It's a blessing. Yeah, I, I have to tell you, I first met you a couple weeks ago at B-Sides Colorado Springs, and it was a quiet venue, but you stood out.

You were like, wow, you know, here we are in the Cybersecurity Center in Colorado Springs, right? The, the Cybersecurity Center. And I was like, wow, I gotta meet this guy. He seems fascinating. And I was 30 feet away from you, right?

So I, I'm really looking forward. And we started talking. You were doing something for the Girl Scouts of America, or you just did something, right? Yes, sir. I was very blessed enough to help construct the Girl Scout cybersecurity badges that they're currently handing out that they're doing.

So very fortunate to be a part of a discussion like that and to help run classes to get more girls in tech, which in turn is going to get more women in tech. So it was a fantastic opportunity to have. Okay. What if it's okay? And I don't know if you're allowed to discuss this.

What would you want to teach someone? What would you get to get more women into cybersecurity? And what kind of positive effects do you think that's going to have in our industry overall? Man, it's going to have so many positive, like the positive effects is hard to quantify because we need more diversity in tech. We need more diversity in STEM in general.

And to bring in a girl or a woman's perspective is definitely going to help us out. As we know, tech is a male-dominated industry. And we've tried. And if you look at security in general, we tried and we suck at it. Look at where we are right now.

We can use more women in tech, use more women in STEM, and to be able to start with the Girl Scouts, man, it's fascinating. Because if you watch the trend of, of tech through grade school, it's like 50/50. You may have more girls than boys. Then in junior high, it's about 50/50, or you may have more girls than boys. But when they hit high school, you start to think like, where'd all the dudes— where'd all the girls go?

Why is it just all dudes in here? Because there's something systemically that we're doing unconsciously or consciously to push women or girls away. And so with these Girl Scouts, oh my gosh, they're fantastic. And to be able to give them a badge, something the equivalent of a certification to show, hey, you're really good at this, you should stick with this, is hopefully going to stop that trend for the small impact that we have within our Girl Scouts. Like, hey, you have a badge in cyber, and you're good at cyber, maybe you should stick with cyber when you go into high school or stick with cyber when you go to college.

Uh, 'cause what we found is that if you're able to embrace STEM in high school or in junior high, you're more likely to have a STEM job. So, and we're in that position right now. The, the impacts of getting more girls in tech, get more women in tech is just going to make us stronger and better for it. Because if you think of security, man, back growing up, the best person for security in my life was my mama. You know, my mama always kept me safe.

And so, hey, if we can bring more women in STEM and they bring that, they bring that mentality to it. We've trusted them our entire lives. A lot of us have been secure. Why not with, why not with your digital security? Why not online?

I'm confident they'll do just as good, if not a better job than us dudes are doing right now. Be maybe a little bit more passionate. Is that what you're saying? Or, well, more passionate, just a different perspective. Just, it may be better, maybe worse, maybe this, maybe the same, but man, we, we can use, if we're in this industry, we're pleading for more people to deny women.

That's, that's terrible. That, that's terrible. We need to embrace them and create avenues to get more women in tech. The way that I'm choosing to do it now is to get more girls in tech. Which in turn is going to get more women in tech, but the door needs to be open.

There needs to be no gatekeeping. The notion of breaking into cyber, that needs to stop. You shouldn't have to break into cyber. We can use your perspective because cyber is not really an industry. It's a trade, man.

You can be in automotive, work in cyber. You can be in healthcare, work in cyber. You could be in the dental industry and work in cyber. It's a trade. It's not, it's not an industry.

And so every perspective is unique and every perspective is needed because to do cyber in the automotive industry. That's a perspective I don't have, and we need someone to do that though, because we're gonna have self-driving vehicles. If those things ain't secure, man, it's going to get real ugly real quickly. And so we need to embrace these other, other perspectives and know that women and girls to become women, they could bring those perspectives that we absolutely need, whether it's mental health, because we need to be cyber mental health, whether it's retail. We need cyber in retail.

We need to stop this gatekeeping if that's going on and embrace unique perspectives and different perspectives. Well, that's interesting because that's the same type of advice that I give to my university students, male or female, is if you're trying to be a career changer, try to do that cybersecurity in the industry that you're already in. And I give this great example. I went to go do a service call at an architecture firm and really try and understand what was happening here. But to me, the system was just a system.

It didn't have anything. I didn't like, well, it does this, it does this program. Well, great, so what? But if so, if you're already in this industry and you understand, in that case, architecture, you know what that program is, you understand what full importance and the impact of it is. Maybe why the performance is so important.

Maybe what the results should be. Because I can type in any number and say, well, it piped something out. I don't know exactly whether that was correct or not. So, uh, that's, that's great advice. But back to the Girl Scouts, you know, you and I again have had some similar experiences.

If you're trying to give a Girl Scout a reason. I mean, I don't know much about the Girl Scouts, but when you are trying to give them a reason, it's like, you should get this cybersecurity badge. What would motivate them? Why would you say— what would— what is their benefit from getting that? Because they're growing up in the environment.

So like Girl Scouts, the youngest ones, some of the youngest ones, like the Daisies, they're growing up in that environment. So they understand what it means to be digital already. They understand whether they're playing online video games, whether they're in social media or something like that. They understand the environment to say, hey, they, well, they don't get it. Well, they, they do get it to a portion because they're living with it.

Some of them have laptops when they're going to school already. And so to say, hey, do you want to learn the security side of it? Do you want to learn the offensive or the defensive side of it? I have yet, yet to hear a no, like I do not want to do that. A lot of them just, yeah, I would love to learn about it.

Some of them learn it and get it very quickly. Some of them takes a little bit of time, but teaching in a university as well, I promise you when it came down to encryption, they learned that faster than all my university students. Like the, you know, the abstract thinking was just absolutely fantastic. I, something real simple, like, hey, if A equals B, B equals C, C equals D, what does this spell? They'll be like, hey, that spells your name.

Hey, I spelled my mom's name. I spelled my name. And so, you know, they get the very basics very quickly. And they also, they understand the environment. They, they're, they're native to it.

Everything they've done to this part has been digital. And thankfully, but unthankfully to like COVID, online learning is a thing. So their education at one point was online. Their environments that they live in is online where they communicate with their friends. Is online.

And so they get, they get it. And so I have not yet to hear a girl say, no, I don't want to learn that at all. I've heard, hey, I don't want to do this for my career, which is totally fine. But to learn it, man, I like, I think cyber is like, it's a good tasting food to me. And so if you taste something really good, you just want your friends to taste it as well.

I'm like, hey, try this, at least try it before you say no. Before you say no, at least try it. But no, none of the Girl Scouts said no. They all said yes. They receive their badges and then they may go on with something else in their career, or they may choose to embark on cyber for, for their career.

Well, that's interesting. You talk about the, the cryptography portion at the BSides Denver, right afterwards at the afterparty event. I was sitting with what I like to call a young lady. She wasn't a young lady, right? I mean, I'm just an old man, but she was a cryptographer.

And as I talked with her for a little bit, I'm like, you know, I think I'm, I don't think of myself as dumb. But after I talked for a while, I was like, wow, this, this woman, she is highly intelligent. Like, just being able to figure stuff out. I mean, I'm trying to figure stuff out. I'm trying to count.

I'm still using my fingers at times, right? So it's amazing how well they are. I mean, one of my university students, a female student, asked me about their success rates and things like that. I think one thing in our industry, especially all now being a lot remote, it's a lot of gender-neutral stuff. I mean, I don't think anybody— I like to think that in our industry specifically, we've broken down that barrier between males and females because I will have to tell you, I used to run an offensive security team and the best hacker that I had was female.

And to the point where I'm like, okay, loved what you did, loved everything that you did. But, you know, she ended up, believe it or not, hacking in from the outside of our web application from an outside source and changing my password. Right. Nice. And I said, great job.

Great job. But could you not do that 5 minutes before my board meeting? Right. I'm about to go in front of the board of directors here. And you kind of choked me off a little bit.

So there are trade-offs. Yeah, because man, computers, they don't, they don't, they don't care about your age, race, gender. They just care about results. And if you could produce the results or not, that's what's, um, that's what's going to happen. I think we've done a pretty good job in cyber embracing diversity.

Because if you remember way, way back in the day, man, your primary and secondary drives were called masters and slave drives. I'm glad, I'm glad we got past that, you know. So now we're, now we're primary, secondary. And so the tech industry, man, we're, we're making some progress, which is something to be celebrated. But yeah, with the Girl Scouts, I encourage every— if you're a cyber professional listening to the podcast, you know, find a way to give back.

If you can give back to, to some kids, because at some point, man, I, I would love to retire. You know, I would love to retire and And, and just hang back and chill. And being able to embrace these kids and help them find their path into the industry so they don't have to break into the industry, it would, it's just doing us good because cyber or security, information security is a trade. It's not an industry. It is a trade and it is in every single industry.

You can do higher education security, healthcare security, automotive security. All these things, it's a trade. So regardless of where you came from, regardless of what you've done in the past, man, we need it. We, we absolutely, we absolutely need it because the days of this is old school is gone away. Like, man, you got a smart thermostat, smart doorbell, smart shoelaces, smart spaghetti, you know, everything's becoming smart these days.

And so all that stuff needs to be secured because We can't stop it. Like you and I, we can sit on this podcast, Frank and Erik talking like, hey, we need to stop all that. It's going to, it's going to change nothing. And so we need to embrace it and we need to invite people in with unique backgrounds to say, hey, I don't understand retail the way you understand retail. So you're better suited to secure that than I am.

Because what we, what we have in cyber, people don't understand the business cases. They receive a degree, they receive a certification. And they base everything based off the textbook without the context of the business. If you have the prior experience, if you used to be a nurse, do healthcare cyber because you understand the context of the business much more so than if they hired me. I'm just going to try to lock everything down and you're like, hey, this needs to be locked down, but this needs to be protected, not quite locked down because of this need of the hospital.

Man, we need to, we need everyone to understand the business context first. And then let's start, let's start securing this thing up. If not, we're just gonna try to cyber everything together without any business context, which is a terrible plan. If your security plan incorporates at all slowing down business, it's a bad security plan. Like, so we need those different perspectives entirely.

Well, I do have a comment on that, but about the whole industry. But before I get to that comment, I actually want to go take a couple steps back about what you said about wanting to retire. My comment that was running in my head when you said that is, liar, liar, pants on fire, because I don't think people like you or me will ever actually retire, right? We can't stop what we're doing. We have too much of a passion, too much of a love for it.

But that's true. Going forward with that conversation, right, going forward with that conversation about the industry, I think you hit the nail on the head. It's not learning about the industry, it's understanding about what the business industry is. We always talk about how, well, we can take a server and we can secure it up to 99%. We have to pull out all the drives and encase it in concrete and bury it in the ocean.

So it would become completely nonfunctional, but it would be at least, you know, 99% secure because as security professionals, we'll never say 100%. Yeah. Yeah. But I think that's great advice because some of the people that have never worked in tech and they're so nervous about this, they do understand the business overall, right? What are their goals?

I had a student that was in the concrete business and talked about how he just can't do it anymore. It's obviously a very physically demanding job. It's like, well, what about the tech in it, right? What about the programs that you need? I don't understand what that program is.

And he started talking about, oh yeah, we use a software program that does this, this, and this. And then last I heard from him, he was well on his way to helping develop that program and then secure it as well. Oh, that's fantastic because, man, I'm very blessed enough to, to work and speak a lot in Wyoming. Huge shout out to Laura Baker and Cyber Wyoming. They're doing fantastic work there.

But if you think of like agriculture and the tech in agriculture and farming, oh my gosh, like it's, it's unique and it's amazing the, the work that's going on there where if you have If you have a farm or if you have cattle and, or if you, if you're, if you have like plows, like modern plows and things like that, that the tech in that is absolutely amazing and fantastic. And we need individuals that are passionate about that particular industry, or we need individuals that have worked in that industry to jump in and be on the security or on the tech side of that particular industry. And those that are listening thinking like, hey, I don't, I don't know as much as this person or this person or this person about the tech side. That's maybe true and that's fine and good. But myself, I don't know anything about agriculture.

That's not a, that's nothing that I've done. So I would submit that that person passionate about that industry is probably better suited to secure it than I. Because I can do a better, I can do a decent job, you know, locking down networks and things, but I might slow down. They might fire me because they like, hey, you're slowing down production to a crawl because you don't understand what we're doing. If you think of like job postings these days, a lot of times they want you to have worked in industry or something like that because they want you to understand the business context, like CEOs, CTOs, COOs, individuals like that.

And it's, we could say it's, it's about the bottom dollar. Yes. To, to a degree, because businesses have to make money, but they want to be secure as well. But they're not going to be secure if it means like, hey, Erik came in and said, unplug everything. We're a healthcare organization.

We're no longer going to do e-prescriptions or anything like that. We're taking it all and we're writing it down because we're going to be secure. We're going to go from filling 10,000 prescriptions a day to 100. They're never going to do that. So like, they— those industries, I like that you bring that up because those particular industries, man, they need passion about those industries.

They need people that have worked in those industries. Sometimes it's harder to find individuals than that. If you're— if you grew up on a farm and you love tech, dude, do it, because it's hard to find people that want to— that want to do things like that. If you are a nurse, like, do it. Man, because it's hard to find individuals with the passion that align with the passion in the tech side like that, man.

So I think those people with those unique backgrounds, if you were a lawyer and you want to get into tech, I don't know if there's a check big enough for you, you know, because as you move industries, man, it's, it's fantastic because I'm— sounds like Frank, sounds like you and I, we're unique in that we just love security. As the trade, like the peer, as the trade, we just love security. Well, here's a question for you and something that you mentioned going back a little about the agriculture part, right? I think that's a smaller part of one of our security issues these days, which is supply chain security. Yes, sir.

I think it's been there for a long time and it's been a concern for a long time. I don't think that it really came to light about how big this could be until the pandemic. What do you think about supply chain security? How do you think that we as an industry, whatever industry you're in, should we start thinking about supply chains? And, you know, how much of a concern if I get my supplies for like key fobs or if I get my supplies for my farming equipment, what right do I have as a grocer, right?

Let's say I work for King Soopers. What right do I have to go back to the farmer and say, what is your supply chain security? Man, that is a unique and that is a fantastic thought. That's a unique and fantastic thought. Supply chain security is— it's hard to think of something more critical, more important than supply chain security.

I'm sure there's something off top of, uh, that can come up like healthcare, things like that, but supply chain security will rival important importance, darn near anything else. Because when you start, when you think about it from the grocer standpoint, if the grocer wants to talk to the farmer about their security, man, I, I don't know if now's the time to ask that particular question, because we need people to secure that because is the farm secure? That is probably if the answer is no, do you, does King Soopers or does Walmart move on from them? And how many other farms can they move to before everything's monopolized to these 5 farms because these other farms haven't quite caught up to that? We need it.

Yes, I would say yes, we absolutely need it. And I think those questions should be asked. Is now the time to ask those questions? I think we need to start getting the security in there, and then we start asking those questions because the pandemic really opened our eyes. You were right, because we found out whose job's essential and whose job's not.

A lot of people making a lot of money, you weren't really essential back then because, hey, we need to eat. Bottom line, we need to eat. We need that farm, and we need that farm to be secure. Yes. But if King Soopers, Walmart, Kroger, Wegmans, all of them, if they asked about the security of that farm, if they said it's not up to their standard and they move on, then the amount of food we would have, would be significantly less because we're taking food from less farms.

Because, hey, these other farms, you're not secure enough for us. You're not secure enough for us. Next thing you know, potatoes are like $10, about that right now.

Food, because we're, as a consumer, as a citizen, I would love— sorry, I'll back up. As a lover of the trade, yes, we need to ask that. We need to ask that, and I want to see farms drilled for those questions. As a citizen of the United States and of the world, I don't know if now's the time to ask that question because knowing the trade, loving the trade, I think the answer is going to be no. They're going to be like, nah, we're not going to meet your standards.

And then if they moved on from 1, 5, 10, 20 different farms, What is that going to do to our food supply chain? Because the demand's going to be high, people are going to be hungry, but the supply that we're going to be— the amount of farms that we're going to get food from is going to shrink significantly because I think the answer is going to be no. So yeah, it's, it's both sides of the coin. We can say, well, we won't do business with you because of the fact that you're not secure, but if we don't do business with you with you, we're hurting ourselves as well. Yes, sir.

100%. 100%. Because the secure farms, man, price might go up. You know, I would say price should go up. You know, good business practice.

Hey, you got this. You got your secured tomatoes, you know. Well, why would— why would I— well, you know, as a consumer, not that I'm a big fan of tomatoes or anything like that. Me neither. I hate them, to be honest.

Me too. But what— how would you react to that? Like, okay, well, I'm now paying $10. I don't even know how much tomatoes cost, but I pay $10 now for tomato, but it's a— it was produced in a cybersecurity, cyber-aware facility. Does that tomato taste any different than the one that has zero security in it?

No. Okay. No, no. As a, as a, I, I don't think at that point consumers don't, don't care. Um, and should they?

Depends how hungry you are. Like, I, I'd be like, if you're hungry, I don't care. I think you just should eat. There's a, there's a point where I don't, like, if you're very, very, very hungry, screw security, eat.

Let's get you some food. But as a consumer, if you're wealthy, if you're doing well off, then man, it'll help your data, to be honest. Like, hey, if King Soopers get hacked by a third party and that third party happens to be a farm and somehow that farm, they end up passing data back and forth and wham bam data breach, you know, it'll, it'll protect your data potentially. But at the end of the day, man, just eat. That's, that's it, man, woman, child.

If you're, if you're hungry enough, screw security.

Well, I mean, isn't that what we learned from the Target breach though? Is that our vendors and, and how they came in and things like that? Um, yes, sir. So thinking of talking about all these different industries here, I see that you used to work at We're going to bring back some of the classic stores there. Ultimate Electronics, Circuit City, right?

Yeah. Always been in tech, huh? Yeah, I, I always been in tech. The only time I was not in tech was my first job where I worked at Taco Bell. Shout out to Taco Bell for hiring, uh, uh, not so safe or secure version of Erik.

I'll take a shout out. To Taco Bell for taking a chance on me. But yeah, I, I worked at Ultimate Electronics, man, way back in the day when I was in college. I, I loved it. I was always in tech.

It's either selling tech to, to consumers because my dad, he worked, he worked in tech my entire life. He was, he was a chemical engineer in the Army and then he moved to, to be a civilian software engineer for the Air Force. And so I looked up to him. I aspired to be like him. I got to see how we moved from a very small house to a pretty decently sized house, watched him get his master's degree and watched our family begin to flourish.

And so I'm like, hey, let me, let me jump on this gravy train. And so I, I loved computers. And so when you love computers, Ultimate Electronics was a good place to be. I loved home audio, home video. Cameras.

I love the tech inside all those. So yeah, it was the place to be. I loved it. Yeah, I think all the stores, they're all going away. I mean, there's what, Best Buy and Micro Center now, right?

I mean, at least for the physical stores. Yeah, yeah, that's it. Best— man, Jeff Bezos took all them things out. You got that. And, uh, yeah, Best Buy, Micro Center.

I think Micro Center, well, You can build a computer at Best Buy. Yeah, but I have to throw a shout out to the people out at Micro Center. I mean, they are old. I mean, if I have to buy something in person, that's where I'm gonna go. They're great customer service, knowledgeable people.

I know. So the people at the DT store, again, got to give them a shout out. They're just totally awesome. Definitely. Yeah.

Yeah. I Love, man. That's, that is like my Christmas shop. You just to go, go into Micro Center. I am a dangerous, dangerous person to my budget whenever I step into Micro Center.

Oh, cool. Well, hey, let's move on to possibly a bit of a touchy subject here. Something that you mentioned earlier, right? You mentioned about diversity, right? And how like in the original computers and, you know, you and I have had a long career.

I remember the whole master slave with the drives before. I do work for a university right now, or at least I do some work for a university. And we talk about, you know, one of the things that we had to change in all our material, and I definitely agree with this, is, you know, whitelist and blacklist, right? We're now calling them allow list and block list. But there are some terminologies that we're not going to change.

So for example, black hat, white hat, that was one of those controversial issues. What are your thoughts on that? Well, I think there's, there's a little progress to be made, but I think is now the time for some of those conversations. We have, we have bigger issues than to worry about white hat and black hat, in my personal opinion. And I'm huge.

Huge into DEI. It's a, it's a passion of mine. Um, and so I would rather see more women in tech. I'd rather see more minorities in tech, um, than to worry about white hat and black hat. I think there's that.

Is it offensive? I don't, I particularly, me, I don't find it, uh, offensive, but if someone does and it's worth a conversation, I think it might be worth the conversation, but I think there's bigger conversations to have. Uh, at this moment in time where if you look at a gender gap or if you look at how, uh, what it takes for a minority to break in, what it takes for different backgrounds to break in, into tech. Because I've sat in seats where I was making less, if not barely a little bit more than the people reporting to me, where you just feel like, man, this doesn't, this, this doesn't feel right. Um, and I, I am big into making sure everyone's treated equally, everyone's treated fairly.

Um, I think there's bigger conversations for us to have, and I think— but I think there might be a conversation there. But to me right now, that's not offensive. To me right now, I want to see more. I want to see more women. I need to see more minorities at the executive level, um, because Sometimes.

Regardless, I mean, I like to think that our industry particularly, and with my last podcast, I just talked about this a little bit, not as much as we are now, but I like to think that we have, I wouldn't say blinders, but more acceptance because honestly, I don't think that we see those in cybersecurity. We don't see race. We don't see gender as much. Uh, in this industry, because we know that there are some really great technological people, uh, technological people that can just do wonders, and you have no idea what their gender is, whether it's even a him or a her. Yeah, yeah, I, I, I agree.

There's a, there's a saying that goes on if that the person that hacked you and stole all your company's data, they didn't have a CISSP. They probably, they probably did not take the CISSP exam to learn how to do, to execute whatever data breach they need to execute, or they don't have their OSCP or OSCE. They are a certified ethical hacker, uh, certifications in order to execute those, uh, attacks. Yeah, I think there's, I think there's room to be, room to be made. But I agree that tech, a lot of times we don't see the color in that regard.

But I think we are victimized sometimes with, with that same notion with people that do, because some people say, hey, I don't see color, I don't see race, I don't see age or things like that. That means you're missing beauty, in my, in my opinion, you're missing beauty. Like, man, there's, there's beauty in in being a female. There's beauty in being African American. There's beauty in being Asian.

There's beauty in being Hawaiian. All these different races out there, see that and, and recognize that and understand that there's beauty in that. Not that it's like, hey, this person is Asian, so you see color and you treat them differently or whatever. No, it's not that. It's like, man, they have a unique perspective, unique background.

Tap into that, tap into that. That's where diversity lies. That's where inclusion brings in. That's what inclusion is. Bring them in as a person in their entirety.

Embrace a different style of thinking because the people that don't, where we don't, as you go up in the organizational chart, you begin to see less and less diversity. Because sometimes, not everyone, sometimes those, those are, those are individuals that want people to agree with him or her, like yes men and yes women. And that's where it begins to— the frustration lies in your director or in your VP is just like, hey, I can't get into these rooms to help these decisions that are being made that's cast down on me, that is in turn cast down on the entire team. That's entirely frustrated because the IT team or the security team no longer, or they don't understand the business objectives.

I'm laughing at your comment here because I had one of my students ask me, they were checking out some people's profiles on LinkedIn and it's in several, apparently several different people. And they said, how come in careers and cybersecurity careers, They usually go, what, 3 to 5 years maybe at a company, something like that. They're usually pretty short. You don't see people staying with a company for 10, 20 years. And I think you kind of just hit that nail on the head is because usually as cybersecurity, we have maybe a little bit more of an ethical background and we're not good at being that Yes person.

Yeah, I— yeah, that is, that is entirely it. But we're uniquely wired to push the boundary. We're uniquely wired to question things. Because in order for you to succeed, or be great at this job, you got to understand that things innately are not designed to be broken, but they're designed flawed. And so you're pushing, you're analyzing the flaws and you're pushing the boundaries of some things.

And so to simply just say yes, yes, yes, that's not really in us. You're going to say yes, but, or have you thought about this? Or no, but have you thought about this? And that might get you kicked out some rooms. It might get you silenced in some rooms.

And it's unfortunate that it's that way. And I've seen that as well. And shout out to your student that said that because that's that's very, very observant when you get into an industry like this, that sometimes you stay and you love it, or sometimes you stay and you love it until you hate it, and then you move somewhere else. And then you stay until you hate it, and then you move somewhere else. Um, we need, we need a lot of work at the, at the top with executives being able to be pushed, uh, be able to be challenged In some ways, which may slow down some business practices, which may slow down some business processes, but it's, but it's needed.

Someone needs to say, hey, chill, stop. Like, let's think about this. Let's think about this. And some executives, it's just, yeah, do they want to get it out? Oh yeah.

Yeah. No, no, I fully understand. I mean, I was actually working as a web application pen tester. I was talking to a vice president for the first time. And he comes over and he tells me, I want my website 100% secure.

Well, well, I looked at him and I said, no problem, take it off the internet. And he looked at me like I had a third eyeball right in the middle of my forehead. And like, you're just crazy, Frank. And it was one of the very, very few times that the filter between my brain and my mouth actually worked. And I didn't say what I wanted to say to him.

And I said, well, because that's— if you think that's crazy, I think that that's the right amount of crazy where I really wanted to say a number of other things to him. Yeah, because, man, the— and I say this in a lot of my talks whenever I give any presentations is that security doesn't exist. So we need to stop saying, hey, we need to be secure. Secure doesn't exist. We're just living within acceptable levels of insecurity.

How much insecurity are you willing to take? That's it. So imagine we know no website, if you're a pub, if you have a public-facing website, something can happen. You know, at some point in time, something can happen. So think about Amazon.

Amazon, they're entirely, their entire business model is online. And so they're innately taking a risk by being public-facing online. But what is the business case of that? And so the level of insecurity they're willing to take is, we're one of the most profitable organizations on the planet. So yes, we're going to take this level of insecurity of allowing people to post their own stuff onto our website to be sold on our website where the business case is just, if there's a data breach at some point in time, like, hey, there's a data breach once every 10 years, because you really focused on security once every 10 years, something along the lines of that, worth it.

Totally, like totally, totally worth it. And so we need to stop thinking that, hey, we need to be secure. We need to be secure. Is this secure? It doesn't exist unless it's offline.

Even if it's offline on a piece of paper, It's probably not as secure as you think it is. Security doesn't exist, but is it at an acceptable level of insecurity? That's how we need to talk about security. Is it at an acceptable level of insecurity? Know that it's not secure, but is the insecurity level acceptable?

Yes or no? If it's yes, cool, move on. If it's no, do something about it, but don't act like because it's yes, It's secure. It's, it's, you're not doing it justice. It's not a, it's not a 50/50 question.

It's not a, and well, like to say, maybe a black and white type of answer, right? It's, it's just shades of gray. Absolutely. Exactly. Because it, because it's secure today, you know, a CVE comes out, it's not secure tomorrow.

Hey, just assume it's insecure. Is that, is it? Insecure at an acceptable level. That's, I think that's how we need to think about security. A lot of people do a fantastic job of that.

Some people, you know, coming fresh out of school or, uh, with a different perspective of security, of technology, of cyber, uh, they think, hey, it's secure. Like, assume it's, assume it's not, assume it's not, it's just insecure enough. And then we've been talking We've been talking about security and we've been talking about security for a while. Let's switch a little bit here. What do you do in your spare time when you're not working and you're not thinking about security and you're not thinking about your next presentation, which is probably what, 90% of the time, right?

90% of your day. What do you do to relax? What do you do to have fun? Or do you have any fun? I have no fun.

No, no, I I, I can tell you're a very boring person. That's why I chose you. You know, people, people probably fall asleep during your presentations, right? All the time. Yeah, yeah.

I, I don't believe that because at the CSA conference I tried to get in your room and I couldn't even open the door, right? Your room was so packed. I was like, great, people are blocking the door trying to get in and listen to you. So I know you're not boring. I appreciate that.

Yeah, that was, that was definitely a blessing and that was a fantastic venue. Fantastic conference, by the way. Yes, absolutely. Thank you to Darren and Paul Beckford and the entire team that put that together. Yeah, it was, it was great.

Every, all the speakers crushed it. I was blessed enough to be one of them. But regarding hobbies, uh, I'm a nerd. I'm a video gamer. And so I, every Wednesday, my best friend and I, we play either like Call of Duty or we'll play Mario Kart or we'll play Mario Party, something along the lines of that, just to relax and just be, be kids.

Because despite all this gray hair, I'm still a kid at heart. And so we just sit down, we'll play some, play some video games and just yell at the screen and just laugh and have fun because that's To me, that's, that's relaxing. That's relaxing, just spending time with some of my friends. And every Wednesday we eat Chick-fil-A and then we go play video games. And so passions of mine is just going to either a restaurant that I love like Chick-fil-A or go to a brand new restaurant that I never heard of, some mom-and-pop shop, uh, someplace where someone's grandma is cooking, because that's where I want to be.

I want to try every family recipe on the planet. And then, you know, play some video games. I love it. Oh, well, so you're a foodie. Oh my gosh, if there's anyone that's getting ready to host a conference, if you're in a good spot with some good food, the answer is yes.

Let's, let's go. Let's make it happen. Well, the next time you're up in the Denver area, you need to go to a restaurant, a Filipino restaurant called Manila Bay. It's right at 225 and Mississippi, and I will have to tell you that It is the most authentic Filipino food that I've ever sensed. I like to say is that they're not really cooks back there.

It's somebody's grandpa that is back cooking. It is just— I, I, I, I went to go eat there. It is a little pricey, but I want to go eat there and I'm like, oh my God, this, this is what I grew up on, right? Oh my gosh, I'm doing that. I need you to bleep that out because I don't need everybody going there because I want to go there.

I need, I need Yeah, so send me that, like, all serious, send me that. I will, I will be there. We will throw it in the show notes for everyone that didn't happen to catch that, along with like your profile and everything else. Yes, please, please do, because man, that, that is, uh, that, that's what I'm— to find things just to relax and just, man, it's time with friends, it's time with family, it's good food. That, that's my That's my, that's my jam.

That, and obviously I'm a serious video game nerd, and so sitting down playing a video game, eating some good food, some good jokes, that's what it, that's what it's about for me for sure. Yeah. Oh, I know the feeling. Although I, I did pick up the new Super Mario. They came up with a new Super Mario, Super Mario Wonder.

Yeah. Yep. I can't play it though. I can't play it yet because I'm still teaching right now. It's like If I open up this box, they are not going to get their lesson plan, right?

I mean, just let's just— doesn't matter. Forget them.

Okay, so I'm gonna list in your description Erik, Dr. Erik Huffman. Bad for my— oh man, no, that's, that's good though. Yeah, Super Mario Wonder. One of my friends that I just went and had lunch with today They got— unfortunately, they had COVID last week, and they said they just played that game from start to finish, locked in the house, start to finish. Said it was a classic.

So yeah, that, that's a good one. That's a good one. You're in for something when you open that up. Go ahead, cut that week short. That, that week is done.

You're gonna be playing Super Mario the entire week. Awesome. All right, we've been going for a while. We've talked about a couple of different issues. We talked about Diversity.

We've talked about Girl Scouts and teaching the Girl Scouts. We've talked about, you know, your previous jobs. Let's get back to the actual security. Outside of what we've talked about, and this may challenge you a little bit here, what do you think is the greatest security problem we have right now? I always end with this question.

What is the greatest problem we have? Maybe not a solve, not trying to solve it, but what do you think is hindering security today? Not hindering, but I think we, we don't, we ignore the human element in cyber a lot, especially as tech nerds. Um, we try to patch human behavior all the time. Like, that's why spam filters exist, because it's trying to take phishing and say, let's put all, all the bad things, all the advertisements and whatever, let's put that, let's put that in spam.

Um, we've been trying so long to patch human behavior. And I think it's time for us just to focus on the digital environment. That's where my postdoctorate research is in. We need to focus on the human. Let's focus on the person and biologically what, what makes us more vulnerable online and not.

Because that, according to Verizon, 74% of data breaches last year included the human element. And so we need to start focusing on the 74% just as much as we focus on, you know, the crazy nerds in their mom's basement sipping Mountain Dew with Cheeto dust on the keyboard. We need to focus on that too, because that person is going to crack the crap out of us. But also we need to focus on us. We need to focus on the human, not just the users.

Because what I found is that us cyber professionals, we're just as susceptible to digital social engineering as much as anybody, because we're all people and we really need to take time to, to look at us. I think that is, that is the final frontier. Because if we can take that— is that what your TED Talk's on? Because I'm looking on your profile and I see the TEDx Colorado Springs and then your featured link Human Hacking: The Psychology Behind Cybersecurity. Yes, sir.

Yes, sir. That's what, that's what the, the TED Talk's about. You know, I share 3 stories and then I get into a little bit of research. And so, yeah, that, that is, I think that's the, the final frontier. Because if we could take that 74% and cut it down to even like 60% or 50% or 40%, the, the entire economics of hacking change.

Because right now you can— the hacking is making more money than illegal drug trade. And so if we begin to switch the economics of that, it won't be as profitable. So hopefully less people engage in it. But because we, we on this industry, we said stupid users so much, like stupid users, stupid That our users begin to hate us. There's this, imagine if the cyber professionals, imagine if everybody's like stupid security person, stupid security person.

We would, we'd feel some kind of way about them. But we said stupid user so many times that we draw this line in between the security professionals and the users. And we need to, we need to stop doing that because we heard the note, the saying, it's not a matter of if, but when. There's a cyberattack. People have said that.

I've said that before. But psychologically, that's a Pygmalion effect. The Pygmalion effect is self-fulfilling prophecy. And so if it's not a matter of if but when, imagine there's a data breach the next day. And we've been saying that time and time again, why would the user care?

We said that is going to happen. Who cares? They clicked on a link, so it happened. And so we need to take that onus off. And so I'm not saying embrace the users and care for them, whatever.

Let's put the onus on them as well and say, hey, as a human, you are the difference between success and data breach. And we don't have to have a data breach if you begin to do your part and understand how we are, how we act psychologically in, or in this particular environment. Then I think we'll be able to see success because right now we said stupid user and we put on the security jersey But we know that it's a team sport and you have more users than you have security personnel. And so we, we have a lot of work. I mean, a lot of work on the humanistic side, on the human element of security.

There is a ton. There's a ton of work to be done there. Yeah. Yeah. I, I, I, although I have to disagree with you, I think they're already saying stupid security person.

I think so too. Yeah, but I think that's where— that's one of our biggest hurdles is how do we bridge those gaps. And I think we've been talking about that, is to really try to build an understanding and, and understand that their job is just as important to them as our job is to us. All right. Yes, yes.

Yeah, they, they have to understand that portion. So definitely, because man, in this environment— apologize. Because in this environment, like, if you think about online, much like you think about a forest or a desert, uh, those particular environments, this is something that we're not built for. And this is something that wasn't built for us. We, we created this.

And just because you're online, you're still human. And the advantage is on the attacker every single time. So think about when you read a book, or when you read a text message, or when you read an email. The default voice you read in is your own. And so the attacker is sending you a message, and you're reading in a friendly voice.

You're not— you don't read in like some deep, dark voice or anything like that because it's coming from a stranger. The default voice is your own, which is a friendly tone. In your mind, your voice is— your voice is a friendly tone. And so the attacker is making you say whatever you want— they want you to say. You're going to internalize that information as such.

That is a biological function. That's all of us. Every single one of us— man, woman, child, white, Asian, Filipino— all of us do that. That is a human function. And for us to ignore that that doesn't happen and that the attacker innately has an upper hand In this environment, we're not give— we're not treating the environment with enough respect.

And we're putting, say, hey, stupid user or stupid security person without understanding that we're operating in an environment where your biological functions, like your limbic system in your brain, that fight or flight, it doesn't engage in the same way. Like it keeps you safe when you're in a forest or when you're on the street walking, when you're like, hey, that person looks sketchy. That person looks scary. You don't look at, oh my God, that username is horrifying. No one says that, you know, you, you, but you're seeing the username, but you don't look at the person much like you would someone walking down the street, you know, waving a gun or just acting totally irrational.

When you see that biologically, you have some safety mechanisms built within you that's going to get you away. That's going to get you more towards safety or what you think at that time would be safety. We're treating this environment as if it's that environment, as if we can see the per— we can't see the person. You can't hear the person. They have the upper hand.

And so when, as we're continuing to embark on this digital journey, I think there is a ton of work on the human side, on the psychological side of cyber that helps sway that 74%. Not that it's ever going to be zero. Because we're all not going to make the correct decisions, but we're going to impact that enough where, where you need to treat this digital environment as if it's a new city. When you go to a brand new city, and if you're— if you have your laptop bag or if you have a purse on you, you might clutch that purse in a crowded room a little tighter. You might pat your pockets to make sure, hey, your wallet and your phone and your keys are still in your pocket more than you typically would because you want to keep yourself safe.

However, online we treat, hey, we're just out here. We're just out here winging it. But it's a new city. It's a, it's an entirely new environment in which we're not built for. So your biological safety mechanisms, dude, you're not ducking under your screen from spam.

You're not doing that. Like they're, they're not, they're not there. They're not there. They don't operate in the same way. But however, when you're attacked, you do go through what's called amygdala hijacking.

You do panic. You see your name of your boss, you begin to panic. You see a name of a bill collector, you begin to panic. And so those mechanisms still work, but your safety mechanisms of stranger danger, it doesn't, it doesn't happen because you don't see a face. If attackers were attacking us, looking at the mind like, hey, Give me your Social Security number, kid.

Like, okay, you're, you're not going to do that. They're going to send you a fake Amazon invoice in which you're used to seeing. You're going to read that in your own voice and you might click on it because it makes sense to come at that particular moment in time. We got— sorry for the ramble, but no, no, no, no, that was amazingly insightful. I mean, I, I think you put into words things that I've been trying to convey for a while.

And honestly, I failed at it. So you put it into words. I think I'm gonna actually have to steal a lot of that. But I, we are actually out of time. As I said, I knew this was going to go long.

It was going to be very hard to keep within an hour. It's all good. I apologize. It's my fault. Don't worry.

Don't worry. I'll blame you. I know, cause it's easier that way. Right. Yeah.

What is that we just said? Stupid security guy, man. Yeah. Yeah, I'll tell you, man, you put a microphone in front of a security guy and they are just going to rant.

Awesome. Well, definitely we'll put your LinkedIn profile in the show notes, but it is Dr. Erik J. Huffman, upped on LinkedIn, Human Hacking. I mean, I'm definitely going to watch that TED Talk of yours. Thank you for your time. I def— I really appreciate it.

Um, no problem. For those of you that don't happen to know me, I am Frank Victory. I am on the board of the Denver OWASP chapter. We have just announced the SnowFROC 2024 conference, and I am going to voluntold Dr. Huffman here to come and speak at my conference. So you'll be able to see him.

He doesn't know that he's already been volunteered yet. He's just finding out now for the first time. I appreciate that. All right, well, again, thank you. Check us out.

We'll put in our show notes the OWASP Foundation. We'll put his LinkedIn. Check out— what is it called— Handshake Leadership. We weren't able to get into that, but I think it's a fascinating name and, and what you can learn from this. So, all right, well, have a good day, sir.

Hey, you as well. All right, take care. Bye. Take care. Bye now.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes