Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is our newscast for episode 268 for November, the, the week of November 4th. Alex, it's November, it's getting cold too.
Yeah, we just had Halloween. Robb, do you have a good Halloween? Lots of tricks. How'd you get Halloween? We, we ran out of candy for the first time in— oh wow, a very long time.
Yeah, that's nice. I think part of it was because I held a bowl out to like 3 2-year-olds, and I think that they just grabbed like 8 things each. I'm not sure that we had that many trick-or-treaters, but I had a hard time taking the candy back from the 2-year-olds. All right, uh, I, I could see that. It's probably not the, the best move to take candy from babies.
Yeah, I think there's, there's a saying about that. How was your, how was your Halloween? It was good. We actually, we did adult things this year and actually we weren't even home to hand out candy. So kids had to skip our house.
So you had to clean eggs off of your house? We did. We did. Yes. Still working on that.
Yeah. Well, getting into the housekeeping, we have a Slack channel. You know, we'd love it if you'd come join us out there with about 2,600 of the best and brightest security people in Colorado. You can join Slack by going to colorado-security.com. While you're there, you might as well jump to the bottom the page and sign up for our mailing list.
Then you can get all of the news in your inbox that you need to know. We'd love for you to subscribe to the podcast, and when you do, rate it, of course, a 5-star or whatever the appropriate highest rating is. And then, you know, once you've subscribed, it'll come to your reader— reader— listener whenever, whenever we publish a new episode. We'd also love it if you told a friend about Colorado Equal Security and all the great things happening here. And if you'd like to support the podcast and other things financially, we do have a Patreon campaign that you can subscribe to and help us cover costs of hosting and other things like that.
Big thank you to our current patrons. We appreciate you very much. Keep us going. Keep us— keep the, the energy in the website so it can continue delivering and pumping out the hits. Right.
Good stuff. All right, let's jump over to the news. We start with a little bit of city planning news, Alex, that looks like there's a new plan for the Ball Arena area. Yeah, so the area kind of by Ball Arena and Eilich's and that sort of area has been rezoned. And the plan is to put, you know, a number of mixed-use things in there, some taller buildings for hotels and offices and an entertainment district.
It's going to be great. Yeah. And the, the president of the, the association doing this said they're going to have a second downtown. And I think it's too close to downtown to be a second downtown, right? It's just kind of stretching downtown a little bit.
I feel like it's kind of going to be like Florida, like a, you know, a little thing sticking off the side, a little peninsula of downtown. Exactly. Um, they, they did mention in this article that they got a exception to a— what do they call it— view plane. Yeah, basically, they— there is a rule that you can't have any buildings above 95 feet that would get in the way of a view from, from downtown Denver of the mountains, which is nice. But apparently, that rule didn't stop the state of Colorado from building some buildings that already got in that, in that view.
So when the city was looking at this proposal, they're like, well, the view's kind of gone anyway. Right. So let's make it worse. And so they approved it. They got an exception.
They can build buildings over 95 feet. Yeah. And so there will be a lot of building going on there. I think the— well, they said groundbreaking could start as early as next year. It'll be done soon, huh?
But the entire plan could take 30 years to complete. So it'll be a little while. Well, okay. I guess my grandchildren may move in there when they're ready to. One of the other things that was part of this was the agreement by Cronky Sports to keep the Avs and the Nuggets here for basically for another 30 years.
Well, great news, right? Great news. So Nuggets fans. Yeah, good stuff. All right.
Next story. A Denver startup was on Shark Tank and they signed a deal for expansion with the Raising Cane's CEO. So Rig Strip, I believe, is the name of the company. I mean, for somebody that makes chicken strips, that should be a perfect name. Not a bad fit.
Basically, what they do is they create little, like, plastic pieces that will help you mount your skis, snowboards, your firearms, your fishing tackle to your car, and will keep both your, your gear and your car from getting scratched up and damaged in the process. Yeah, simple little pieces, but apparently effective. I think that they said last year they had like $3 million in revenue or something like that. Great. Yeah.
For selling little pieces of plastic, that seems pretty good. They went on to Shark Tank with the intention of trying to get $300,000 for a 7.5% stake in the company. They ended up making a deal, as you said, with the Raising Cane's CEO for $300,000, but it was for 15% of the company. So I guess that values the company somewhere in the ballpark of, what, a little bit less than $2 million. So my mathing, my mathing in the moment was a little tough, but it's not terrible.
And, and, you know, good for those guys to, to get this investment infusion of money to go grow and hopefully take over the world. Yeah, it sounds like they're gonna use it to buy inventory for the upcoming season and then use some of the money to help get some new products. Speaking of small little Colorado startups, we have news from one of our other startups in Colorado, the potential acquisition of DISH Network by competitor and other satellite TV series or system, DirecTV? Yeah. So this is something that has been on again, off again for a long time.
I think there was many years ago, there was the attempt to either for DirecTV to either buy DISH or merge or whichever it was at the time. And at that time, regular regulators said, no, that would be anti-competitive. Back when we needed multiple satellite TV services to have competition. But now with streaming services and all of the other ways that people can watch content, they don't think it's going to be anti-competitive anymore. So they're going for it.
It sounds like the number of subscribers for the traditional TV systems like these continue to go down, which means that as you mentioned, that there is a lot of other competition. Obviously, we all know Netflix and Hulu and Prime and, you know, all these different systems. But I think that there's still a pretty big place for players like this. And it'll be interesting to see what is— what does this new system look like when they're joined together? I do want to be clear, EchoStar and Dish, you know, they merged— was that last year, right?
Yeah. And when they merged, they came— they initially were going to go under the name Dish. They ended up for maybe a mistake having to go under the name EchoStar. And this was not the entire Dish EchoStar company that's going to be going to DirecTV, right? This is just the Dish Network's kind of satellite TV business that would be moving over, not the, the new 5G cell phone business and not the Hughes satellite systems that, you know, do the enterprise work that they do.
So it is a portion of this big company here in town. But I would say probably not the— not even the majority of that business at this point. Yeah, it's definitely the most public-facing part of it, at least today. But, but yeah, I would agree there's a lot more things that are going to not be part of this and stay in Colorado. Yeah, well, hopefully that goes really well for that business and gives the, the EchoStar folks the financial, you know, the capital they need to be successful with that cell phone business, which I know is very expensive.
Robb, speaking of business finances and capital, Our next story is all about business finances, but not quite in such a good way. It's a juicy one. It is a juicy one. There's a story— fluid, juicy. Oh, yeah.
You guys don't get the joke yet, but you will. This article is about Fluid Truck, who we've talked about on the show before. They're a company that, that will do short-term rentals or even longer-term rentals of vans and trucks and things like that. I think, you know, for delivery services, Amazon, Amazon. And there's a lawsuit that has been filed alleging that the, the founders have hatched a scheme to defraud investors of $11 million.
Yeah, I feel like we need to use the word allegedly multiple times during this segment to keep ourselves out of trouble. I don't know much about their business model, but I learned by reading this article that it sounds like allegedly that, that Fluid Truck would allow, you know, us to invest by buying a bunch of trucks that they would specifically be responsible for renting out to their users. Um, Fluid Truck would do the maintenance on the truck. When the truck has reached its useful end, they would sell it. And then me as the investor, I would get the profit of that sale, you know, minus the cost of maintenance.
And I imagine there's probably some management fee, but I don't know. So that's the idea. And they, they And then what this article talks about, one of the people who made the lawsuit was quoted in here, talks about how he'd invested, I think he said 47 trucks. And over the course of the year, they sold a bunch, but he never got his money out. And then eventually he got a letter from the CEO saying, hey, it looks like we do not have the financial wherewithal right now to be able to make these, you know, these payments that we owe.
We're working on it. And that's where the lawsuit came from. Yeah. And it also sounds like maybe there were some backroom conversations and this person who filed the lawsuit maybe got some information that was contradictory and other things allegedly that he, you know, Fluid Truck would be filing bankruptcy in order to not have to pay these investors back. And lots and lots of accusations here.
So hopefully this is all misunderstanding and things are being done in good faith and that they are just running into some temporary financial problems. But I guess time will tell. Yeah, really, you know, like we mentioned, we've talked about them on the show a number of times in the past. Sad to hear things maybe aren't going so well now. That said, let's jump on to our next story, which is a little bit better news.
Yeah, another continuing story we've talked about on here has been Techstars over the years. And just earlier this year, when Techstars announced they would be closing their Boulder accelerator, it sounds like maybe there's a change to that news. Yeah. So this article is talking about the, the new Techstars CEO kind of reversing course and saying that they're going to reopen a new accelerator in Boulder for Techstars. There's not a whole lot of details in the article.
They do say it's going to be more community-focused. It sounds like maybe previously that the Boulder accelerator had been, you know, just one of their accelerators and had companies from multiple places. But really, the idea going forward would be this would be a local Colorado-focused accelerator. Yeah. Obviously, it's good news that, that they are kind of doing an about-face, and they're going to be creating a new thing in Colorado specifically to keep the Techstars presence here going.
Looking forward to hearing what it is. We'll give you an update when we know. Yeah. Next story, some not as good news, but maybe not a cause for giant alarm. You all may have heard already, but It was announced this week that the Colorado Secretary of State's office accidentally shared some of the passwords for voting machines in Colorado on their website.
There was a spreadsheet that was shared that shouldn't have been given access to that had some of those passwords in it. Specifically, I think it was the BIOS passwords for the, for the voting machines. Obviously, not a good thing, an embarrassment. I'm sure that, you know, They're looking into what happened to make sure it doesn't happen in the future. I will say that it has been jumped on, you know, as a way for some folks to talk about how Colorado's elections are not secure.
Obviously, whenever one security control is defeated, you have to look at the others. In this particular case, it seems relatively low risk. In order to take advantage of this, you would've had to have physical access to the voting machines. You would've had to be able to, you know, in some way, write new code. To update the BIOS, to, to, to make the machine operate in a different way.
And then remember, the machines, what they do is they actually print out your ballot after you voted, right? So you have the ability to look at what is in front of you. So if, if you looked to see, hey, I voted for that person and the other ones checked, you know, it would have been relatively clear that that's what occurred. So interesting. I mean, obviously something that, that they will improve on.
Sounds relatively low risk to me as not not all the way in the weeds on what's going on here. Yeah, it is a political time of year. And there have been many politicized comments around this. I agree with you, Robb. It seems like, well, maybe it could have been handled better.
It doesn't seem like it's a super high risk. So, okay, well, speaking of not the best news from Colorado, we have a ransomware event that attacked one of our healthcare systems and That's in Southwest Colorado, right? Access Health Systems announced earlier this month that they had experienced a cyber incident. And it looks like it infected or impacted— excuse me, what was it, about 80,000? Right.
Good number of people. And subsequently, the ransomware actors did take responsibility for it. They were asking for, I think, $1.6 million in a ransom. Uh, and then they ended up posting some of the, the victims' information online, which is no fun either. And seeing that they, they actually asked for was 25 Bitcoin, which was the $1.6 million in ransom, which made me look into, man, how much are Bitcoin right now?
It's almost $60,000 for Bitcoin. And we could have bought it for how much back in? Uh, it's just for nothing, Robb. Terrible. For nothing.
So this is really the lesson I got from this is you should buy any cryptocurrency when it's cheap because that's a really good use of my money. Exactly. Uh, that's sarcasm. Please don't take that as financial advice. You're not a financial advisor or a lawyer or a doctor.
Read the fine print, people. All right. Moving on to our next article, jumping into, uh, security blog stories. This is a blog post from Red Canary, uh, talking about the understanding and observing Azure OpenAI abuse. Specifically, they go through how does Azure's OpenAI work, and then gosh, what would it look like to misuse it?
What can you do to monitor for misuse in that? Honestly, if you are a, uh, a security operations team at a Microsoft company, it's gonna be must-read type content right here. This is either in your organization already without you knowing it, or it's likely coming And here's how you get ready. Yeah, this was a really great post. I would agree.
And everyone should read it, even if you're not using the Microsoft side, just to think about ways that you could look into generative AI abuse. Good stuff. All right. We have our next story. This is actually by Ping Identity.
Why siloed IAM is a burden on IT resources and security. I think the short version, Alex, is if you do federation, you only have to manage it in one place. You get a common experience everywhere throughout the organization. Yeah. You know, that whole single sign-on thing, Robb, it's pretty cool.
You might be wondering why we picked a blog post from, you know, 2010 to talk about on the show today. But, you know, Ping Identity just doubling down on things that they do well. There are still companies out there that haven't embraced single sign-on, and there are still a number of companies that charge the single sign-on tax. So we should shame those companies when we see them. For shame.
For shame. Shame. Okay. What's our last story? Last story.
We have an announcement from the NCC down in Colorado Springs. They are going to be having some training. This is part of their adult education series. So, you know, I would think aimed towards people that are career changers and want to get into IT or security. They are offering some training classes for both Network+ and Security+.
These are— I'm gonna find the dates again. It's in January through February, right? Okay. Yeah. So January, February, Mondays and Wednesdays, These are virtual, so you don't have to be in the Springs to take them.
But they are— I was going to say it says Zoom or Microsoft Teams. I was going to say, you know, if it's on Teams, it might be painful. But hey, it's not so bad. I'm getting used to it. But yeah.
So if you want to— if you are an adult or know an adult that wants to be a career changer and learn more about these things, sounds like a good opportunity. All right. All right. Moving over to our event calendar. As a reminder, you can go out and see events going up really all the way through April right now on the calendar.
We'd love to have you take a look at that. But we'd love to remind you what's happening this month. Alex, what do we got? On November 12th, ISSA Colorado Springs is having their November meeting. The 13th is the day of the month with the most meetings for sure.
We have 4. ISC2 Pikes Peak is having their November meeting down in the Springs. Denver ISSA is having their monthly meeting, doing more with DSPM. The Let's Talk Software Security group is getting together to talk about, um, are automated testing tools truly reducing risks? And finally, the— is it WISIS?
Is that how you say this? Uh, Women in Cybersecurity Colorado is having their 2nd annual CyberCon that day. Nice. So if you go to all of those events on the 13th and, you know, you're having a little withdrawal, on the 14th there is one event The not-so-secret secret speakeasy cyber event. That's all the— that was the one in Fort Collins, right?
No, this is Fort Morgan. Fort Lupton, I think. Fort Lupton. So those forts. So if you went to these events on Wednesday and Thursday, you would get to drive all the way from the Springs all the way up north.
You cover a huge amount of the Front Range. That's true. All right. Moving forward on Saturday the 16th, the ISSA Colorado Springs chapter is doing their November mini seminar. On the 19th, CSA Colorado is doing an event, Modernizing Big Data to Help Secure Your Cloud.
The 20th, Denver ISSA has their Women in Security special interest group, and it's, uh, Andy Hill talking about Back to Basics. Oh, nice. And then the last event for November, ISACA Denver is doing their November meeting on the 21st, and that is online. Uh, well, that is the end of November. I wanted to go one event into December and talk about the joint ISSA and ISACA holiday party.
That will be, uh, December 4th, and that's always a super fun event. I hope— I encourage everyone who's in town to make it over there and, and have a party with some security nerds. Awesome. Should be great. All right, should we talk about some jobs?
We should look at the first one on there. It's a big one. It's a big one. CommonSpirit Health is looking for an, uh, SVP Chief Information Security Officer. Yeah, that's a, that's a big role for a huge organization.
Big national health system. Um, Inver— Inver— Invenergy? Invenergy, thank you, is hiring a director of cybersecurity programs. Boston Consulting Group is looking for a senior consultant in cybersecurity-platinon— platinion— platinion. Yeah.
Uh, H&R Block is hiring a director of security engineering. Oh, interesting. I-Trade Network is looking for a Director of Information and Security. Baker Hostetler is hiring an Associate focused on Digital Risk Advisory and Cybersecurity. Visa is looking for a Global Safety and Security Senior Manager Engineer, Physical Security Technology.
A lot of stuff. Yeah, that is the longest title of the month. Bank of America is hiring a Senior Information Security Officer. Securitas Security Services is looking for a cybersecurity awareness analyst. That's interesting.
They're like a physical security, you know, guns and guards kind of place. Interesting, right? Yeah. And finally, Plant Moran is hiring a cybersecurity compliance senior consultant. All right.
Good stuff. Well, that is it for the news this month. We do have an interview. Alex, what do we got this month? Yeah, for this month, I talked to Dave Farrow, who is in charge of security at Red Canary.
Um, I'm going to say it was an interesting conversation, but we're going a little out of order this month, Robb, and I haven't actually interviewed Dave yet. So I'm guaranteeing it's going to be interesting. But, um, it, you know, I'm going to have to live up to that guarantee. So Dave took over the security program from me. So feel free to ask him like, what's the worst thing you inherited?
Right. Or, you know, something, something like that. How big of a mess was the security program here when you arrived? On a scale of 1 to 10, how terrible was Robb at his job? Exactly.
I will make sure to ask him that. Well, awesome. Thank you for that. And we'll look forward to talking to everyone in December. Thanks, Robb.
Hi, this is Chris McLaughlin, CISO with Johns Manville. This is Colorado Equals Security for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is our interview, and I have got a very special guest with me today. I'd like to welcome Dave Ferro, CISO at Red Canary.
Welcome, Dave. Thanks, Alex. Great to be here. Love what you and Robb have been building here. Thanks for having me on.
Awesome. Well, it's good to have you. You know, it's honestly surprising to me that we haven't had you on the show before because, you know, since you've been here, you've been a great supporter of us, you know, helping us plan our picnics every year and stuff like that. So it's about time we got you on the podcast. Well, thank you.
I wasn't keeping track, but I am glad. But now I've corrected the wrong.
Well, I'm excited to hear more about you, Dave, and learn more about stuff that I didn't know about you. But maybe real quick, you can just give an intro of yourself and what you do and where you're at these days. Yeah. Well, so Dave Ferro, VP CISO at Red Canary. Been there for a little over 2 years now.
Grateful both that Robb brought me in there and for the introduction to the Colorado cybersecurity community that came through that. So very, very grateful for both of those connections. I've been in cybersecurity for, well, since about 2012. I came into that, that role. After about a 23-year run in product development and engineering leadership.
Nice. And so I come up from the developer side of the house, and in my role at, at Rigeneria, I'm also responsible for our corporate IT as well as our business information systems, which is moving me a little bit closer back to my builder roots, and which makes me very happy. That's great. I'm gonna dig into that in a minute, but Before we get there, as we were planning for this, I like to prepare as little as possible for these interviews. And, you know, you obviously were a little bit nervous coming in blind to an interview, but you let me know that you've had some experience with those sorts of blind interviews in the past.
So, you know, maybe you want to expand on that a little bit. Yeah. Yeah. So in my early college days, I had a friend asked me to join him on a trip down to Los Angeles for moral support. He had apparently been roped into trying out for The Dating Game, and I said, sure, I'll go down for moral support.
Long story short, he never tried out, and I ended up actually on The Dating Game. And I think a lot of people wonder whether those things are scripted or not. I will tell you that, uh, the intro, the, the witty repartee between you and the whoever's hosting it is relatively scripted. But the questions you've got to field from the, the gal on the other side of the wall searching for a date come completely out of left field. So yeah, you have to improvise on the spot.
It was great preparation for the role that I'm in now because I find myself having to answer awkward questions in a diplomatic way. But yeah, I ended up I ended up, I think, being the least threatening of the 3 bachelors and ended up winning a trip to Costa Rica. That's awesome. So did you win a trip to Costa Rica with the young lady that you were talking to? I did.
I did with the young lady and a chaperone. They were very sure that everyone was safe. It was kind of interesting because the gal, the bachelorette Wendy, and I both spoke a passable amount of Spanish. And, uh, and, and the chaperone spoke not a lick of Spanish. It was totally useless.
Um, so did you and Wendy date at all? No, no. Like I said, I think if you ever managed to get a hold of that, uh, that video, um, the other 2 guys were, were super, super creepy. I think I was the best of the choices. And, and we, we talked a little bit outside of that and discovered pretty quickly that we had Uh, an inadequate amount in common for us to, uh, to do anything other than just enjoy a weekend, uh, visiting Costa Rica.
And, and did you manage to stay in contact at all, or that was it? No, I haven't spoken to her again. Nope. Yeah, no. And it's funny because, uh, my wife claims I didn't tell her about this until after we were married, and she really, really thought twice if she had known about it before that.
Uh, I don't— you know, who doesn't like a, you know, a spontaneous kind of guy, right? Like, you know, right? That's right. Awesome. I'm sure that was a lot of fun.
I've never been on a game show and I think it would make me far too nervous. But I don't know, I suppose I could survive if I needed to. Like I said, there are a lot of parallels between that experience and much of my professional life where you find yourself in a situation where you know you're going to be asked a question, you're going to have to think quickly on your feet.
I've experienced that same sense of sort of nervous apprehension on a lot of occasions since then. Yeah. But yeah, you go in there thinking, oh no, I mean, the light's on, camera's pointing at me, I have to start talking. And you just think, well, I wonder what's gonna come out. Uh, well, now we're gonna find out.
So, uh, going back to, uh, to you and your roots, you know, you, you said you started out in, uh, in product development and, uh, making things? Did— was that something— did you go to school for computer science or computer engineering or anything like that? I, I did. I actually started out going to school in speech communication, and I got a quarter, one quarter into that at Cal Poly San Luis Obispo and said, man, this is not nearly, uh, concrete enough, not nearly enough math. So I, I rebooted, uh, and went back and, and I actually ended up majoring in electrical engineering and computer science.
Oh, okay. I chose electrical engineering because— and computer science because, you know, after a couple years of, of, uh, physics at junior college, the part that made least sense to me was electricity. And I thought, if I'm gonna spend a couple more years in school, I'd like to actually learn something that doesn't already make sense. And so I just sort of fell into electrical engineering and the school that I went to had a very strong vibe that said, if you're in computer science or if you're in software, you're there because you can't succeed at making hardware, right? There was a real, what's the word I'm looking for, snobbery around it.
The ETS students thought, oh, you CS students are there because you can't make hardware. I, right out of college, I got hired to write software for TRW down in LA. And when I got the offer, I thought, I don't think I can afford to turn down someone paying me to learn something.
And so I'll try it out, even though there was a big snobbery around writing the software. I said, I'll give it a try. And I did that for a year. And then I said, look, I'm gonna, I'd like to try hardware. And it was the worst year of my life.
I, I just, my nose was buried in parts catalogs. I was building basically I/O circuitry around a custom ASIC that was doing frequency interpolation. And God, it was boring. And I found myself really leaning into the circuit analyzers that they had, the circuit analyzing software they had, and building software models and ended up building a software oscilloscope to test out this design of this ASIC. And I just fell in love with software development.
So after that year with hardware, I moved back to software and never looked back. Realized discovery was stupid. So as part of the CS portion of your college, it doesn't sound like you actually learned software development. You know, you probably learned algorithms and other things like that, but not like— Not even really that. No.
So I had a couple of programming classes and I jammed those into some summer, summer classes. So I had a, you know, God forbid, Cal, I went to school at UC Berkeley. Cal's idea of intro software was to start you with Lisp. And so I had a summer of dreaming recursively, which was awful. And so really the CS portion of it was focused on computer hardware architecture.
Oh, okay. Everyone's sort of big senior project, CS 152. Well, you know, my wife, we met there. Her year she had to build a PDP-9 or PDP-11. And I ended up having to build and design a Microsoft 68000, or sorry, a Motorola 68000.
Right. So the computer science part really had to do with like the guts of how a computer is put together. And even then, a lot of that was sort of microcode-based. This was before, you know, there were readily available systems for doing circuit emulation, right? So a lot of it was paper design, but I didn't, you know, when I rolled onto the floor my first day at TRW, I'm embarrassed to say that I looked at the machine and I'm like, I'm not even sure quite how to log in.
That's how much I didn't understand programming. So I am super grateful that TRW's perspective on this was we want trained engineers and the fewer bad habits they have for us to break, the better. Right. And so they dropped me into a group there. There's some, some guys that I still periodically talk to that were mentors that had a profound influence on, on my development.
Uh, and I was super, super grateful. It was actually that group that brought me here to Denver. Um, after 2 years in LA with that group, most of that group picked up and moved out here to, uh, the TRW facility over on Centernack Parkway, supporting the, the, the base over there. Um, and we followed in '91. And so I was here from, from '91, uh, and then took a brief hiatus in the middle to raise my kids back in California.
Brief being 20 years. So, so you spent a long time building software.
What happened? Why, why did you decide that that was no longer exciting for you and moved into the crazy world of security? So, so I didn't, I didn't intend to. There's been sort of a theme in my professional life, and it really informs the way that I think about the security field. We'll maybe touch on that a little bit.
Um, but, um, I have done a whole bunch of things that I swore I would never do. I swore I would never be in software. I swore I would never have more than 2 kids. I swore I would never move back to California. All these things I swore I wouldn't do, and then life would intervene, right?
Uh, and so what, what happened for me was that, um, One of those things, we moved back to California in the end of 2001 to raise our kids because we, we had a lot of them and we needed support from family. And when I was there, I ran into a guy at a Cub Scout event. It was hosted at his, his house, and he was the founder of a company called Yosemite Technologies. They were the makers of a tool called Tapeware. For anyone that's been around long enough to remember that, Tapeware was giving backup exec a run for its money in the late '90s before we tripped, tripped and fell.
And we were, we were complaining to each other because we both were in a position where we were doing both the architecture work for our projects as well as the engineering management work. And we realized that we couldn't further the architecture as well as align the engineering teams with that architecture. We couldn't do both, right? You could do one or the other. And if you focus too much on the architecture, the team would keep moving down the field out of alignment and it would sort of end up vandalizing the architecture.
And if you, if you kept everyone sort of in line, you didn't actually do the innovation, right? And so as we were moaning about this to each other, he's like, why don't you just come run our engineering team? And so that's how I got involved with Yosemite Technologies. Um, and 4 years into that, uh, we were sold to Barracuda Networks. And so for the next 5 years, 4 years, I was responsible for overseeing sort of the, the long tail of the software business.
Barracuda bought that business to embed the agent technology into their cloud backup system. So half my team went to build the agent into their cloud backup product. I oversaw the rest of the life of the software product, which was a really interesting opportunity because I actually ended up owning the sales team there as well. So I got an idea of how, how much there is to learn there and how I don't want to do that. And I end of life the product there, a couple of products in that process.
But as that was winding down, I was looking around for a place to contribute to earn my paycheck. And so I joined the, I was made an email security gateway product manager. They made me a product manager, but I was effectively the engineering manager. They just didn't want to break that news to the lead engineer who was one of the founders, founding engineers. Got it.
And in that process, I was looking for ways to get him focused on the product. Like, what could I take off your plate that is distracting you. One of those things was, uh, an internal bug bounty program. So somebody else in the company had created this external bug bounty program when it was sort of just an emerging, emerging space, right? We were like one of the first to announce a public bug bounty program.
And I took that on. I said, hey, Dennis, I'll take this off your plate. I'll handle paying the researchers. I'll handle correspondence with them. And it turns out that when you start paying researchers and you start corresponding with them, they come out of the woodwork.
Oh yeah. And so that, that in October of 2012, the floodgates opened. And that's when Barracuda realized, hey, we need, we need to centralize the security function. And what happened is over time, like Barracuda was a, I would call it a loose federation of states, a lot of independent product organizations operating independently. And there hadn't been a real need for what I would call a federal security function.
But it was becoming clear that we needed one. And so that bug bounty program was the first step in— the next step was like, hey, let's get out ahead of our application security so we don't just write a blank check to the internet. And as we pivoted into the cloud, that moved into all of the infrastructure security that you're thinking, you know, you expect. And so the program built from there. So I oversaw that for about 10 years, but I really did back into that.
Because it was clear that somebody needed to do the job. Nobody wanted to do it, and I wanted to add value. And, and I've been blessed with being able to find something that I like and I'm interested in, in almost any subject. And so if you had asked me before I started if I wanted to be in security, my answer would have been, I wouldn't say it that way. I would say I'm very anxious to not be in security.
And after I got into it for a bit, I'm like, this is absolutely fascinating. It became— has been a passion for me. That's great. And so you were— I'm guessing you were at Barracuda 10-ish years, that in that general area. So if you count the time that I was at Yosemite, sort of my entire duration between those 2 companies, it was 18 and a half years.
Okay. And then, you know, at some point you decided you'd had enough and you moved on from there. And you went from there to Red Canary. That was the next step. There was a, there was a brief lull in between, right?
So, so I, and I think, I think everybody runs into this at some point. At a certain point, you sort of fought your war, right? And you've, you've, you've got a certain set of entrenched battles that if you haven't won them by 18 and a half years, they're not going to be won at your hands. And it became clear that it was time for me to move on. And I was just sort of tired of fighting those things.
So I started the process of stepping out of that role and I took a year to get out of that role. I was very deliberate about my succession planning, right? I had a close peer. I didn't, you know, I owned all of information security, but I didn't own GRC. I had a close peer in the VP of GRC.
We were kind of joined at the hip. And so I made the recommendation that they form officially a CISO role there and give my role to, to Riaz and have him keep GOC. And it, it took about a year to convince them, A, to do that, and, and B, for him to feel like he was really ready for that. Got it. And so I worked halftime during that time, and during that time I did some side projects.
I was the, the virtual CISO for, um, or fractional CISO for VESA, an identity visibility product. And I spent a good year with them building out their program and getting them through a couple of certifications. Uh, and then, you know, and then I'm— in that time, I moved back to Colorado without a real concrete plan. And so I really just fell into the Red Canary role. You know, when Robb, uh, when Robb mentioned in a, I think, a a CISO Slack community that we're in, that he was looking for a CISO.
I couldn't believe my eyes, right? I was very invested in Barracuda's mission. Barracuda's mission was to secure our customers' journey. And I thought, I'm leaving this. Am I gonna find something else where I feel as connected with the mission?
And I was a Red Canary customer at Barracuda, and I can attest that They were the only security vendor I didn't hate. Right. The hackers at Red Canary say that, that that's what their customers say. But without asking me if I said that, that's exactly what I said. And so when I saw there was an opportunity to join that team, you know, like that, that idea had been planted years before.
And I saw that and I just, I hit him up directly in Slack. I didn't quite come out and say, please don't talk to anybody else, but that's what I wanted to say. Right. And so I really felt like it was just, like the universe lining up. And I got super excited about it.
It was a long process. And I'm still very, very glad to have had that opportunity. That's awesome. Going back to, you know, your previous point about not wanting to fight the battles anymore. I feel the same way in the sense that it comes to a certain point and it's not the particular battles.
It's not the topics you're fighting over. Um, I— there just comes a point where, uh, people need to hear it from a different voice, you know? Exactly. I think, I think that happens sometimes when you bring in external consultants, right? Like, you, you know, you bring in, uh, you know, a Big Four or, uh, some other somebody to, you know, do an assessment of your program, and they, they do that and they, uh, they present some findings and they're all of the things that you already knew were wrong that you've been telling people about.
And then whoever it gets presented to is like, whoa, there's so much stuff that we need to do. We should do something about this. And you're like, yes, I've been telling you that this is what, uh, what we should be doing anyway. Uh, or, you know, generally anyway. And right.
So, so sometimes, uh, even that part is, is not enough anymore. And it's just like, okay, you've got to hear this from somebody else. I've done everything I can do here. I need to move on. Yeah.
Well, I think there are, there are a couple of things at work there. One is, is that, that old adage that, that no prophet is accepted in his own land, right? But like when you spend 18 and a half years with a group of people, uh, and, and especially, you know, I can't, I can't tell you how grateful I am that Barracuda gave me the latitude to grow as a leader in a new space that I didn't know. Um, and, and over that time, like you're gonna make mistakes, right? It's just, it's kind of like that time in kindergarten when you picked your nose and like, if you're in the same school from kindergarten through 12th grade, you may never in some people's minds ditch that idea that you're that kid who picks his nose.
Right. And so even if you mature as a leader and it's about you change your perspective, it's really hard for people to look past the outrageous claims that you made about risk when you were first starting. Right? And so, so you are also right that at some point, you know, they need to hear it from somebody else. And, and there is a time when you just say, hey, I'm gonna, I'm gonna step aside.
And like, one of the guys that was in the organization that followed behind me was very, very effective at getting funding for a major control that, that we needed that I just, I honestly, I didn't bother asking for because I was so beaten down about getting budget. Yeah. And so that new blood is really valuable for an organization. Yeah, I totally agree. All right.
So you went from Barracuda with a small stop at Vasa and then to Red Canary. All 3 of those are security companies. Is that a conscious choice in your mind? You know, you mentioned the mission as part of, you know, going from Barracuda all the way to Red Canary, but like, was security specifically making sure you were securing people's journeys, not just your companies? Was that part of what you wanted to do?
So not when we moved to Barracuda, right? And full transparency, Barracuda saved us, right? Yosemite was, was on its last legs and we, I was happy for someone to just keep paying my paycheck. Right. Uh, and so, so the, the attachment to the mission came over time as I understood Barracuda's larger picture.
Uh, from there, you know, when I think about other places where I would like to contribute, um, yeah, it was very conscious to stay in, in security. Nice. Yeah, I think adding on to that, do you feel like, you know, as the security leader at a security company, do you feel more pressure? Do you feel like there's a higher bar for what you do than somebody else who, you know, maybe the— obviously everything is important, right? But, you know, I think especially for us as security professionals, you know, we depend on lots of vendors.
Do you feel like you have a higher responsibility than someone else might?
So yes and no. I mean, I think we should all take our security as seriously as we do at Red Canary. I think that's I think that's the culture that, that, you know, the SEC is trying to drive. I think it's a culture that we, we ought to be driving towards. Like, we just live in a dangerous world.
Um, so do I feel like there's more pressure? In some ways, yes. But the, the other side of that is that doing security in a security company is actually significantly easier. And it's significantly easier because our leadership knows exactly the fight we're in and they understand what's involved. And so there's a lot less trying to translate the, some of the, the thornier nuances of risk that we've got and why it's a risk to our business than in, in a, in a company that's, that's less, less of a security company.
So, like, yeah, the bar is higher, but, but the bar to get the support that you need, that both the budgetary and the cultural support is way lower, and that really offsets it. And I will take higher scrutiny over a greater ability to get things accomplished every day of the week. Yeah, I'd also imagine— or excuse me, imagine— can't find my words. That, you know, being at a security company as well, you have a lot of security-minded people in the company. So, you know, it may be, uh, it may be easier to— for them to accept some of the things that you want to do as, as users, as members of the, the company, as opposed to, uh, you know, some company that, you know, you have a lot of, I don't know, customer service people or, you know, other non-security-related people.
So I'd imagine that's an easier part of it as well. So that's a— that's true. It's a double-edged sword, though. There's always going to be that set of people that, that say my operational security is way more effective than the controls you've got deployed, and you should just trust me to do that. And you're like, okay, I get it.
That may actually be right. And, and let's explore that. Maybe, maybe the right answer is for us to write into our policies that we get audited on. We have these controls in place except for these people that we trust, and we think you should trust too, because their operational security is better than ours. Right?
Because short of that, if we let you out of this, we're actually kind of lying to our customers. Right? Right. And so those conversations are hard to have because especially with deeply technical folks that are especially that are really, really frontline operators, They're like, that feels— their response is, that feels like a you problem and not a me problem. Right?
I'm concerned about, like, objective better security in this instance. And you're like, wait a minute, we've got to play as a team. Right? We need to look at this collectively. And so those are hard conversations to get across.
And frequently those people, because of their skill set, have a lot of influence in the company. And there's a fair amount of effort that goes into finding solutions that are going to be palatable for them and for the business. And that makes sense. I'd imagine if, if their operational security is really that good, that you might be able to adopt some of their practices into your practices to make yourself better. But my guess is it's probably more a personal preference than an actual better practice.
So, so yeah, I think that's the case. They're also not factoring in the fact that some of that better practice involves personal skill that is not necessarily repeatable. That's true. And so if you can't transfer that personal skill over, right, like, I'm gonna go out on a limb here and say that I would be completely fine running my daily driver Mac with absolutely no security controls on it and doing it 100% safely, provided I never touch the internet. Right?
But, but that's not really an achievable goal. Right? And so you can make claims and, and, you know, I'm thinking of a particular guy in, that I know that who, who takes great pains in, in his OPSEC and, and operates with quite a bit fewer protect— quite a lot of fewer protections than an average corporate desktop would on his daily driver and has had no problems. But it's, it's just not— it's not something to build your program around because it's not repeatable for sure. So I, as you know, I in my day job am a Red Canary customer.
I've always been a fan of Red Canary. I think that, you know, you're also in an interesting position in that, you know, being internal at Red Canary, I assume you were also a Red Canary customer. Absolutely. But how much, because of that unique position, how much do you feed back into the product organization at Red Canary since obviously you have, you know, some direct lines there and, you know, you are using the product every day as a customer as well? Yeah, the answer is as much as I can.
The way that we've designed this, and I have a very strong feeling about the importance of this, is that we engage the Red Canary organization as a customer would. I'm very interested in understanding how our feedback gets through and get— we look to be treated like a customer. We'd like to give our feedback as a customer because I want to know and I want to be able to advocate for people like you if that process isn't working, right? So I see our position as a way to provide some kind of QA for our customer success process and for our account management process because, you know, it's great to have an inside line, but if our customers can't provide that feedback, then we're missing out on valuable input. Yeah.
Are you giving new product recommendations as well? Like, you know, I, you know, hey, we're trying to do this thing and we can't do this thing. It'd be really great if we could, if we internally could use our own tools to do this thing instead of me having to go buy somebody else's tool or something like that. Yep. Yep.
And I'm not saying that process works flawlessly. That's the intention is like we're working through some of these things. But Like, one of the questions we've got is, like, of the things that we do have to write in Splunk for our environment, we always ask, should I have to do this? Or should this be something that Red Canary watches for? There are always going to be environment-specific things in every customer's environment that, like, we just don't— Red Canary doesn't have the context to know what to search for.
But We always ask the question, should we have to look for this, or should Red Canary find it? If they're not finding it, we give that feedback. Yeah, no, that's great. Um, right, I think we're, uh, we're getting close to, uh, to our allotted time. Um, any topics that we have not talked about that, uh, you wanted to bring up or, or discuss?
Yeah, I want to circle back to, uh, You know, when I, when I said I, my career has been, I've done a lot of things I didn't want to do. Yeah. That informs sort of my philosophy around security. I think one of the things that, that is really helpful for me in thinking about security, if you're going into the security world, especially in security leadership, it's a thoroughly thankless job. I think I said at the first CISO Summit that you guys did, which was a wonderful event, by the way.
That I don't know why anybody would want to be a CISO. It's a terrible job, right? And I say that as a father of 5. It is a terrible job in the way that being a parent is a terrible job. It's very, very similar.
We do a lot of things to protect our family that people are not happy that we're doing. They don't thank us for, they're not glad we're doing it. They resent it, right? There's this There's this difference in our role. It's not the glory role of the revenue generating side of the house or the product generating side of the house.
The way I like to think of it is that there's just sort of 2 models. It's either a parenting role or it's a federal governance function. And if we think about it that way and, and make peace with the fact that people aren't going to be happy about it until they realize what they've been saved from. All right, that's the best way that I found to maintain my morale and my team's morale through this, is to recognize like this is a really, really super important job. It's okay that nobody thanks us.
They're not going to thank us, right? Our job is to make an environment where the rest of the organization can be successful and, and get the accolades and the trophies. And, you know, we can, we can take joy in the success of the organization because of the work that we've put in. But if you're not cut out for that, I would encourage you to stay away from security because it's a super thankless job. Yeah, I, um, I want to dig in on that a little bit, uh, before we end the— you know, uh, neither you nor I are spring chickens.
Um, we're not going to be doing this forever. Uh, between the, the thankless nature of running a security program and, you know, other things that are happening, you know, potential personal liability for, for CISOs, you know, based on SEC actions and other things like that. What do you see for the, the future of this role? Do you, do you see that there's enough talent pipeline out there that people are going to still want to come in and be CISOs? I think I think we're almost at, like, you know, a, a pivotal point on, on what happens for, for the future of our roles.
It's a good question. I don't know if I, if I see broadly enough to know what that pipeline looks like, but one of my motivations for bringing this up was really to make an appeal to folks to whom sort of that parenting role resonates. Right? When I, when I came into this role, my youngest kid had just left the house, and I thought, like, for 20 years I've known what I was supposed to do every day, like, and now they don't need me in that role. What, what should I do next?
And ultimately, I feel a calling to, to being a father, right? And if you have, if you sense that, that, that sense of service, right, this is a great role. I believe that we can manage that personal liability for ourselves. Right? But I think, I think when I first started down the road towards security leadership, I had a different perspective of what it would mean to be a CISO.
Right? And now that I'm, I'm here, I think I'm lucky that it aligns with my, what I feel my calling is. But I also feel like, hey, we should, we should speak up about that because it's not a glorious position. But just like being a parent isn't a thank— is a thankless position, when your kids are grown and they're out being successful and you can look and say, I had an input to that, it's such a fulfilling thing to have built, right? That I think, you know, I really feel like appealing to the right folks, we are going to pull the right folks in.
But I think we need to clarify really what that function means, right? And, and I joke when people say, oh, hey, we're going to have a kid, I say, life as you know it is over. And then I laugh, right? Because I know that on the other side of that is a life that's wonderful, wonderfully different and better, right? And it's the same thing if you're going into this type of leadership.
It's probably not what you expect, but there is, there is great value to the community, and to the business and to yourself in doing it. And if you go with your eyes, eyes open, it can be a wonderful, wonderful career in spite of me saying it's a terrible job. I think that is a great perspective, Dave, and I think that is a perfect place to end. Thank you for being part of this. Thank you for what you do, not only for Red Canary, but also for the Colorado equal security ecosystem.
We appreciate you having— being a member of it. And appreciate your time today. Thanks, Alex. Thanks for having me on. And again, really, really love the community that you and Robb have built and looking forward to being part of it for, for a long time to come.
Thanks for having me. Awesome. Thank you. This has been Colorado Equal Security, and we will talk to you next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security.
Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.