All episodes

Jacob Rubin, CSO at Curana Health

Apple Podcasts Spotify SoundCloud

Jacob Rubin, CSO at Curana Health is our feature interview this week, interviewed by Frank Victory. News from Buc-ee’s, Dish Network, Maxar, Red Canary, Optiv and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12922 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 269. This is December, Alex.

Can you believe it? It's hard to believe. Just had Thanksgiving, which was nice. A little break. But yeah, we're already at the end of the year, Robb.

It just goes so fast. Time keeps on slipping. Slipping, slipping. Into the future. Speaking of into the future, did you know that in the future there will be more people in our Slack community?

I sure hope so. Especially if the people listening join. Are we doing like predictions for 2025 now? Predictions for 2025. There will be more people on January 25th.

Or January 1st, 2026, than there were start of next year? I don't know. Maybe not according to one of the articles that we're going to read. We'll see. But, you know, that, that does remind me when you say that usually this time of year we have somebody that's given a prognostication article.

I don't think I've seen any yet. I saw one and I ignored it like I always do. But I do appreciate that people, you know, generate content this year. Like you said, we haven't seen as much. I bet it'll be coming out in the next few weeks.

Yeah, we'll talk about it in January. We'll have 10 of them in the news for January. That's a next year problem, Robb. Speaking of other things to talk about, if you want to join the Slack community, why don't you go out to colorado-security.com and click the Join Slack button, and while you're there, we'd love it if you would join our mailing list so you can get the news into your inbox each month. The news and maybe occasionally an announcement like a charity event that we do or the picnic in the summer.

That's what we use it for. Yeah, and you're listening to this somewhere. If you're hearing us, it's probably probably a podcast player or maybe YouTube or some other music app. I would appreciate it if the ability is there to click subscribe and like and rate us. That way everybody else knows how awesome we are and maybe they'll join us as well.

Also, you know, just reach out, tell friends, other people you know in the local security community to come check out Colorado Equal Security. And if you'd like to, we do still have our Patreon campaign going on to help support the show and all of the things around it. We love when we get new folks there because we get to call them out on the show. And speaking of that, Alex, did you know we have a new patron this month? It's like I teed that up.

Jose Castilleja has joined us as a patron. Jose, we appreciate you very much. Thank you for supporting the show and being a regular listener. Awesome. We love it.

All right, let's jump into the news first. I think everybody has heard about the fact that Buc-ee's opened in Colorado up north kind of by Loveland and right across from Johnson's Corner. And there may be a second location here in the future. Yeah, super exciting. When I first read it, I was even more excited because it said Buc-ee's is coming to County Line in '25.

There is a County Line Road right by Park Meadows, very close to my house. This is not the county line that they're talking about. This is probably El Paso County down by Colorado Springs. Yeah, it's the, it's the border of El Paso and Douglas County. Near Palmer Lake, Palmer Divide area.

Anyway, they're proposing a second Buc-ee's in Colorado. The first one is incredibly successful, bringing a lot of people. This, the second one would probably also bring a lot of traffic into that area. It'll be interesting to see if the public, public outcry is, is so loud against it that they end up shutting it down or not. But I hope it does come.

Well, I think that the construction on I-25 between the south of Denver and the north of Colorado Springs is finally just about done. So maybe, you know, there'll be a little bit of room for people to actually get to that Buc-ee's for a bit before it fills up again and they have to make the highway wider. I mean, it would be nice if, if it gave you a place to stop when the traffic's bad. That's true. You won't mind the drive as much if you get to stop and enjoy— have a barbecue sandwich and 3-meat sandwich.

Yeah. A Buc-ee's nuggets. Is that what they call those little things? Yeah, the beaver nuggets. Beaver nuggets.

Thank you. Yeah. Anyway, it'll be nice when that's open. No timeframe for that. I think just talking about it at this point.

So, Alex, I think it's fair to say we as Colorado longtime people in Colorado here, we know that Colorado's population is just growing out of control. So many people moving to the state. And really, it's filled up much faster than anyone could have expected. Yes. Unless you were Colorado's state demographer, Elizabeth Garner.

Who has predicted what growth is gonna be like in Colorado for the past 20 years and more or less has been correct. But what does she have to think about the growth? Does she say that we're growing faster than expected? No, no, actually a little bit less. The opposite.

Yeah. Yeah, we're, she said about 5 years behind the projected growth. And really what it sounds like is even though it feels like, you know, we're continuing to grow, traffic's certainly getting worse, we've grown significantly more slowly than anticipated. And this has driven in large part to the fact that we have the 6th lowest fertility rate of any state. Yeah.

So a couple of things. There's that less kids are being born in Colorado. So that part of the population is not growing as much. But also migrations have slowed down a bit. So in previous years would have been 50,000 to 60,000 people migrating into Colorado.

Now it's more like 20,000. And I want to be clear, fertility rate doesn't mean that you're impotent. It means, it means the percentage of people or the number of children who are born to the number of folks who are there. I mean, it could mean that you're impotent. It could, but it doesn't necessarily.

That definitely contributes to it, Robb. Does it though? I don't know. Are we less potent than we used to be? But, you know, I think it's microplastics.

There's this really interesting correlation between— I guess it's a reversely proportional correlation between income and, you know, wealth and number of kids that are created, right? And as our society becomes more wealthy and, you know, incomes are going up, the birth rate's going down, you know. And that means that in order for us to as a society stay neutral in terms of population, you got to have more immigration. That is true. That is true.

They talk in the article that, you know, this could have some negative effects on the economy, less people here to fill jobs, you know, other sorts of things like that. So we'll have to see how it pans out. But I have a feeling we'll be okay. All right. This next story, I don't think we don't often cover a lot of real estate stories.

But this one was interesting to me, because it's around the old T-Tech office, which I think might Maybe it was like an MCI or AT&T office before that. It's this beautiful— what is it? Is it pentagram or is it a— I think it's round. I think it's like a donut. Well, it's definitely a donut.

There's a courtyard in the middle and you can walk all the way around it. And if you've ever been in there, they have like the degrees all laid out on the ground. So you can say, I'll see you at, you know, 132 degrees at the conference room there or whatever it is. And it is a gorgeous office. And when we were doing ISSA, you know, Sam Masiello was the CISO there and let us do some meetings in the office.

Really cool facility. Unfortunately, the news here is that office has been purchased and is going to be demolished. They had some serious foundational problems. They actually couldn't even go back in there. Yeah.

So, so really, CommonSpirit Health has purchased that facility not for the building, just for the land. Yeah, so they purchased the land, they purchased a plot of land next door to it that was owned by Shea Homes. And they're going to make a medical campus there. So presumably, there'll be a hospital and some other medical buildings there at some point in the future. That office building needs to obviously get demolished first before they can do anything.

And hopefully they figure out whatever the issues were with, with the ground there so that the hospital doesn't sink in the future. Yeah, I'm— I suspect that it will be just fine. But it is A pretty good location for a big facility if you're going to try and serve, you know, South Aurora, Parker, Castle Rock. Yeah, there's a lot of good folks there and a lot of aging and growing population on that part of town. Yeah.

So keeping in the area, talking about the south side of the tech center, big negative news that the deal between Dish Network and— or I guess technically between EchoStar and DirecTV to sell Dish Network to DirecTV has fallen through. Yeah, we were gonna have a combined Dish Network, DirecTV, and now it doesn't look like that's gonna happen. Yeah, you know, the article has some interesting details. The sale of Dish Network to DirecTV was gonna cost DirecTV $1, but with the purchase, they were going to have to take on something like $6 billion in debt. Yep.

And that, in order for that deal to be approved, the people who held the debt on EchoStar had to approve basically giving up about $1.5 billion of the debt that they were owed. And, you know, under the assumption that this is gonna get them paid back, you know, better than they would if they don't make the deal. And the folks declined it. The voters said, no, we're not gonna approve that. So the deal collapsed and Dish Network, at least for now, will stay with EchoStar.

Yeah, we were talking before the show, Robb. I think, you know, both of us are interested to see what happens to Dish Network now. It doesn't seem like there's a whole lot of apparent options for next steps. You know, maybe there could be a different deal that comes up again with DirecTV that's more, more favorable, that would allow this deal to go through. But like for right now, it's just kind of in limbo.

And I think that they did— it's not in this story— I think that they did end up restructuring some of the debt at Dish Network, uh, cuz there was some of that was imminent, like part, that was part of the reason for the sale. So I think that they're not, you know, gonna be insolvent in the immediate future or anything like that. But, uh, but very interesting. Yeah. But it, it just puts a, an anchor on the, what they're hoping to be a fast-growing mobile business, you know, having, having to service this debt for the, the legacy, um, satellite TV business.

You know, it's, it's a shrinking market. You know, fewer and fewer people are paying for monthly TV subscriptions. And, but, but it's a big— but it's a lot of money. It's 8 million users, right? So they, they have a lot of revenue.

If they can figure out a way to monetize that, may start moving them over to, to streaming services, maybe there'll be some, some positive news there. But we're curious to see how it goes. Yeah. And if you thought that the interest on your mortgage was bad, try paying the interest on $8 billion in debt. I don't want to do that.

All right. Moving on. Our next story. This is a recurring one that we seem to talk about every year. 10 Colorado businesses made Deloitte's 500 fastest growing tech companies.

Yeah. You know, I don't, I don't know all of these. We definitely know some, right? Pi Insurance, we've talked about on the show a number of times. Pax8, never heard of them.

Pax8, I've heard of them a couple of times. There's a, there's one called Prove, which is I'd never heard of, which is for helping women track their, their biology. And the last one on here, I, called Quantum Metric. I read it and I read it again and I said, I think that these people are doing marketing snooping to find out what users are doing on the internet to sell. So they're the— and I don't know, like allegedly or whatever words I need to do to not get in trouble here.

It looks to me like really what they do is they have technology that shows what people are doing on the web and they probably sell that to vendors who want to target those people. So they're the new DoubleClick or, you know, those other tracking kind of sites. Um, they, they capture customer behavior and technical issues and prioritize product decisions based on real-time data. Ah, yeah. Okay.

Uh, there is one security company on the list, FusionAuth, uh, which was at 283 out of 500 and had 409% growth. Uh, it's designed for developers. They do things like MFA authorization registration for online security. All right. Next, we have a story, really another piece of bad news.

I don't think I really realized we had kind of a theme of bad news this month, but there's more coming. This is a story about Maxar, the, the somewhat US or Colorado headquartered space company. They're still headquartered here. Aren't they mixed here in Canada? I think they're still technically headquartered in Colorado.

They're, they're owned by PE now. So, you know, who knows what that means for the future? Well, formerly DigitalGlobe, now Maxar. They, they had a breach. Uh, and this breach gave some attackers who had an IP address in Hong Kong access to customer— excuse me, employee information.

So a little bit different, not quite as big a public story. Um, but if you're an employee of Maxar, you know, not the best of news. Yeah. Um, sort of reading between the lines here, you know, my guess is that whatever solution that they use for HRIS was misconfigured or had wrong access or something similar to that. And attackers got in and got employee, uh, information, but Again, that is sort of speculation on my point, on my part.

Uh, sucks for the employees because they did lose things like Social Security numbers. Just change it. Just, just change it. I mean, everyone's Social Security number is on the internet now anyway, so what's the big deal? Uh, all right, let's move over to a— we have a blog post from Red Canary.

Uh, you know, this is, this is one where they actually dive into some real nice technical information, but they do it through a fun lens to, to commemorate Ryan Gosling's birthday, which I know we all celebrated when it happened. I did. They did a blog post going through the biggest attacks or attack threat actors of the year from the perspective of, of Ken from his role in the Barbie movie. Yeah. So they talk about a few of the different threat actors in here and then they also use some of the other, the Barbies and their lens as well.

STEM Barbie and Bookworm Barbie. Um, and you know, so they talk about a bunch of the different threat actors. And of course at the end they give some advice on things that you should do to help prevent these specific threat actors in the, uh, the guise of Lifeguard Ken. If you're looking for a nice list of the biggest attack actors of the, of the year with a little bit of fun reading, I take— I recommend taking a look. All right.

Uh, next story. This is one that we've talked about previously, but some additional information here. The Colorado DAs are investigating the password leak that happened just before the election by the Secretary of State's office. Of course, recapping that, there was a spreadsheet that had a, I'll say, unintended tab available to the public that had passwords for voting machines. There has been an affidavit filed, which then requires that the Colorado AG to do an investigation.

The Secretary of State's office has also engaged an outside law firm to do their own independent investigation. So looking into what happened here, and I think when we, we said it when the story originally broke, you know, you need to have physical access to use these passwords, you need to have 2 passwords to make any changes. This is only one of those passwords. So I think, you know, limit on the risk here. But it'll be interesting to see what comes from all these independent investigations.

You know, if you put yourself in the shoes of this team, this is, it sucks, right? It sucks that this happened, but man, how hard would this be to find? Like an employee put passwords in and then hid the tab in the Excel document. Yeah. Um, they left the company.

Somebody else came across that spreadsheet and said, oh, this is the stuff we have to share. And put it on the website, you know? Yeah. Could, could you have checked to see if there were hidden tabs? Of course.

And yes, they should have. Well, you know, consistently, is that going to happen? And it's just a hard thing to look for. It's hard to know. You can always be better.

I'm sure that we could come up with tons of ways that could have prevented this from happening. But it does seem like a somewhat innocent mistake. Glad that it was found. And glad that, that we believe that the actual fallout from this is small. And, and then the Secretary of State herself, who, you know, I have no political opinions about her.

But like, was she supposed to stop that from happening? Right. And she's just getting reamed everywhere, right? Like, it's, it's a really tough situation. The, the, you know, the Libertarian Party asking for every ballot in the state to be voted by, counted by hand.

And the Republicans said she should resign immediately. Like, yeah, it's political. It's ugly. Hopefully this goes away soon and we can get back to actually making things better. Yeah.

All right. We, our last story for the month, we have a, a blog post by Optiv, 6 Tips for a Successful Security Vendor Consolidation. That's the word, consolidation. And I think that we all see, you know, this pressure to, you know, save money, fewer vendors versus do you want, you know, best of breed, pure play? And it goes back and forth at all times.

Well, they have some tips when you are looking to consolidate. Here's what you should do. Yeah, and I think some of it is not even pure play versus platform. But, you know, sometimes you have a couple sort of, uh, pure play kind of vendors, but even with that, like, their features overlap. So maybe you can get rid of one and, and use— or yeah, instead of 2 vendors, you have one that do the same things.

Um, and the— there's nothing amazing here. It's pretty obvious what they're, what they're telling you to do, but it, it's a good thought. Nice checklist. So let's go through the 6 steps real quick. Evaluate your spend categories to identify vendor overlap.

Get an outside perspective on your vendor's capabilities, map your vendor capabilities to find where you can safely cut, assess your vendor's abilities to be long-term partners, consider what your vendors offer beyond technology, and weigh your consolidated list of vendors against other risks. Yeah, I mean, really, this should be part of your overall vendor governance process anyway, not just security vendors, but any sort of vendors. So yeah, good advice there. All right. Let's jump over to calendar of events.

If you are not constantly on colorado-security.com on our event calendar hitting refresh, you're missing out. We want you there daily because it gets updated once a month. So we want you there daily. Really? That's not fair.

It does get updated slightly more often if people send us events to add to the calendar. I would not do it daily, but you should occasionally check out what's going on because there are a lot of events in this, in the place, and they're all on the calendar. At least once a month it is daily.

It's daily periodically. All right. Speaking of events, on December 10th, the Tech Yeet Holiday Meetup Extravaganza is happening. Yeah, I think I'm planning to go to that. So if you go, I will probably see you there.

On the 11th, Onspring is putting on their Denver GRC Summit. On the 12th, the Colorado ISSA chapter has their members-only holiday party, which I believe means you have to wear a members-only jacket. Isn't that— that's what this is, right? Yes, that's what it means. Dress up like you're in the '80s and go to the party.

Allegedly. Allegedly.

On the 13th, ISC2 Pikes Peak is doing their December meeting. On the 19th, Denver ISACA and Denver ISC2— excuse me, ISC2 is doing a joint meeting, which is awesome. ISC2 kind of coming back from the dead. Yeah. Shout out to Ram Romanos, who's helping the ISC2 chapter in Denver.

Uh, also on the 19th, the Let's Talk Software Security group is doing Is Your AppSec Strategy Increasing Cognitive Load of Developers? Well, that's a lot of words. A lot of words. Well, in case we have a New Year's hangover and we don't have the show out by then, I figured we should talk about the January 9th event. On January 9th, ISACA Denver is doing a January chapter meeting, but it's going to be online.

You gotta— yeah, don't, don't go driving anywhere because they won't be there. Sounds good. I'm gonna actually even look farther into the future. What are you doing? A couple things.

One, because this is the first time this is happening. Wild West Hacking Fest, Black Hills Security has put this on in South Dakota for a long time. They're doing the first version of that here in Colorado, the Mile High version, the 4th through the 7th of February. And then, of course, not too far in the future is Rocky Mountain Information Security Conference as well. And I wanted to bring that up because the call for papers is open.

Oh, that's fantastic. Yeah. So, well, since we're talking about future events on Pi Day, Pi Day, which is March 14th, we have Snowfrock. And, and I don't know for sure, but I have heard that at 1:59 on 3/14, they will be serving pie. So if that's not true, tell them that Robb said he's very disappointed.

Yes, you should all go bring your own pie just in case. And if they don't give you some of theirs, complain. Or maybe like one of those Hostess pies. Those are good too. Hand pies.

Everybody loves a hand pie. All right, let's jump over to jobs. Alex's first job, I, I actually thought this was your job. So help me out. What is this Uplight VP of Information Security?

Yeah, you know, Robb, Uplight is hiring for a VP of Information Security. That was my job. I don't have that job anymore. Decided to step away from Uplight. I am sticking around there for a little bit, helping them fill a new person into this role.

Be there for a couple of months and hopefully do some transition with the new person. But I'm no longer a full-time employee. If you have interest in that job, please reach out to me. All right. Well, we also have a VP of Security and Privacy at Luxo, which does— I've actually looked at this before.

It's a recruiting platform for helping recruiters find candidates. Interesting. Bank of America is hiring a Business Information Security Officer, BISO Engagement Senior Lead. Fastly is hiring a Technology Compliance Lead. Kroll is looking for an Associate Managing Director of Cyber Risk.

In what I believe is the longest title of the month, S&P Global is hiring a Head of Corporate Platforms Technology, SOX and Controls Management. That sounds horrible. The Trade Desk is looking for a Senior Data Privacy Director. LaSalle Networks is hiring a Director of IT and Security. Optiv is looking for a Cybersecurity Architect.

Sumo Logic is hiring a Senior Security Compliance Analyst. And finally, Rapid7 is looking for a senior security solutions engineer for SLED. Well, that is it. Happy holidays to folks. Before you leave, you should probably listen to the interview that's coming.

Yeah, we've got, uh, Jacob Rubin, who is CISO at Curana Health. Uh, Jacob started there recently. He came from consulting, was in the, the CISO chair before that, so it'll be interesting to hear his transition to consulting and back to Uh, running a program. Yeah, I, I knew Jacob. He— ProBuild, he was the CISO at ProBuild, and then he went over to Cognizant and then Red Robin.

Lots of great stuff around town. And, um, Dr. Jacob. Dr. Jacob Rubin. Yes, good stuff. All right, Alex, well, happy holidays.

You as well. We'll see you next year. Thanks for having me. Hi, this is Cole Metzner, VP of Information Security and Infrastructure at Initiv. Welcome to Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Good morning, good afternoon, and good evening, Colorado Equal Security Cloud. My name is Frank. I am a guest host here on this absolutely awesome podcast, and today I have with me is Jacob Rubin. Jacob is a seasoned security leader with 20 years of experience with various industries— technology, manufacturing, hospitality, healthcare, and even consulting here, right? He's been a CISO and executive advisor at EVOTEK and has recently taken a new position here.

So welcome, Jacob. How are you today? Thanks, Frank. I'm pretty exceptional today. How are you, sir?

Oh, I am absolutely outstanding. Before we actually get into the podcast, I've got an icebreaker question for you here. All right. And by the way, just so the audience knows, they— I have not prepped up Jacob for this, so he's going to hear it for the first time right now. Dangerous.

What 3 things would you do if you were invisible? Oh, um, I think the first thing would be take a nap, uh, because that means my office, my kids, the wife, nobody's bugging me. Uh, okay, uh, boring. Um, hey, the importance of a nap as a father of 2 young kids and a budding executive, you never underestimate the power of a good nap. All right, man, I tell you, I'd probably find my way onto an airbase and commandeer a jet.

My, uh, one of my bucket list items is to take some flights in a fighter jet. Okay, so national crime. Gotcha. We'll let the FBI know. Yes, felonious theft.

That's right. Um, it's something a little less seeding here. Boy. Um, Hmm, you know, I think, uh, I think I would try to find maybe another crime here. I think I would try to find my way into, um, maybe, maybe NORAD or some of those other restricted facilities.

You know, there's just that constant wonder of, of what's behind all those big metal doors that's so important. And, you know, now I'm just curious. So I think— okay, so yeah, taking a nap and then going ahead and breaking into the secure facility for a crime that would probably get you into supermax. Yeah. Am I crazy here?

Are those on 2 different ends of the spectrum? I don't know. Both. They seem equally important to me. But if I got to end up in supermax, at least it's in Florence.

I don't— at least I don't have to leave the state of Colorado for that, you know? Oh, yeah. Well, yeah. Always think of the positive parts there. Silver lining.

You know, you're, you're, you're only in jail and get 1 hour of daylight a time, but hey, we're still in Colorado. Uh, yeah, there's, there's that good points in there. So, um, great positive outlook. All right, well, that's some fun stories to tell at least. Yeah, well, uh, fun if you're allowed to publish them.

Uh, you do realize you don't have a whole lot of rights outside of that. All right, so in your career you have a couple of different things here. You started off, or you have been an internal CISO, right? For what I think a hospitality business. And then you moved into consulting and then you moved into another internal CSO position.

Is that correct? Does that sound right? Yeah. So, I mean, throughout my career, I've, I have flip-flopped between internal corporate roles and consulting roles. You know, hot out of college, my first gig was in consulting and I cut my teeth in IT infrastructure.

So, you know, I was part of a regional managed services provider that provided IT consulting and then went to an internal role with Fidelity, then went to IBM, then back to Fidelity and then, you know, into that hospitality role with Red Robin and into Cognizant, which was something of a foot in each camp, you know, Cognizant being the big IT services provider that they are. But I was on what would arguably be their internal security team. That said, still had significant involvement with, you know, Cognizant's client base. It's not uncommon for, you know, multi-billion dollar fortune class organizations, their client bases to want to understand how that consulting firm is kind of, you know, drinking their own champagne when it comes to providing security services. And whether or not that company holds itself to the same standards.

But so that was an interesting role in and of itself. And then, you know, movement to EVOTEK was more about finding a good partner organization for the next role in my career and less about, you know, hey, wanting to get back to pure consulting or pure corporate.

And then, you know, there was kind of this, this too good to pass up opportunity that I have now where I I just kind of organically moved back into the corporate world. And, you know, there's probably a therapist or a doctor out there that's wanting to diagnose me with something, getting me to go back and flipping back and forth between these and that I can't focus on one thing. But I'll say, you know, the differences between a consulting gig and corporate gigs, both sides fascinate me. You know, in the corporate side, you own that program and there's something to be said about seeing the fruits of your labor and, you know, watching those programs really go from this nascent soup of, you know, broken processes into something that is truly providing some, you know, risk mitigation and some value back to the business. And again, there's something with seeing that manifest itself.

But, you know, I also find some pretty significant fun, for want of a better term, some value in the variety that comes with, excuse me, that comes with consulting, you know, in any of the consulting organizations I've been in, you know, the clients are varied. It's everything from digital engineering to healthcare to manufacturing to marketing to something else. Well, as somebody that's known you for several years, I definitely have a lot of questions about your psychology or questions about lots and lots of questions. But before we get into that, When you are looking for a new job, what are you looking for? When you search, do you just look for a paycheck and say, okay, well, Company A is going to pay us way more money, or consultant is going to pay us more money?

Or are you— what else could you be possibly looking for? You know, it's, it's never any one thing. You know, the expression, I'm here for the income, not the outcome, of course comes to mind. You know, you ever think of that high school counselor that always asks you, oh, if you were infinitely rich, what would you do? I always thought those questions were bogus because nobody ever says janitor.

But, you know, of course the financial piece is part of it, the benefits piece, because I have a family and, you know, I enjoy eating food, you know, so being able to pay for that's nice. But I will say, you know, outside of a paycheck, which can get old inside of a couple of months, I'm typically, you know, I used the term earlier, a partner, looking for a partner in who I'm going to work for or something that can give me more than just I show up and earn revenue for you and in exchange I get a check. That partnership is typically something that has good respect for work-life balance. You know, my family goes a long way to respect when I'm at work, I'm typically at work, you know, and unless somebody's, you know, bleeding or the house is burning, they kind of leave me alone. I work from home for the record.

So, you know, they're pretty respectful of that boundary and vice versa. I look for companies that, you know, respect that I'm a father of 2 young children and You know, I have my own pursuits outside of just being a practitioner. And I have been lucky in my career, I think, to find employers that are very much leaning in that direction. It's not by accident, of course, but lucky that they hold true to the things that they typically say during an interview process. And, you know, another function there is I'm typically always learning something new in the roles that I take.

And if you look back at my CV, you notice I try not to take roles in repeat industries. In fact, I think this role that I'm in now is the first time where I've actually repeated in an industry, which is healthcare at the moment. But this offered some other perks outside of that. But it's always, you know, okay, we've done security. Can I do it in, you know, entertainment?

Can I do it in manufacturing? Can I do it in healthcare? It's different nuances that give me good learning opportunities, which is part of me finding that key thing that I look for in that partnership is am I going to learn something out of this and vice versa? What would you find though? I'm sorry.

What would you find? Let's say between, let's say all the industries that you've worked in, what's a commonality between them? What's something that's, I mean, and don't just say security, right? We all know that's why we're here, right? So what would be the one thing that would be consistent And then possibly even the one thing that might be different and make each industry unique.

And there's one factor that I think juxtaposes between all of those things, between what's the same and what's different. And what's the same in the industry from industry to industry is our, our industry, cybersecurity, seems to have a less than desirable mix of, oh, I just do security type practitioners and individuals that aren't business-minded enough that, you know, they pursue security for the sake of that's the way it's supposed to be done. And I find that many of our cohorts, our peers might struggle with doing things in a less than ideological way. And, and that's really what businesses are looking for is, look, we don't want the checkbox security piece. We want security that is built to our business and to our risk tolerance.

And that's only ever accomplished by truly understanding the business that you're gonna go work for. So that's what's the same from company to company. And even when I step into consulting and I start to work with clients, that's always what they're looking for is something that's built to them and that isn't just going off of the CSF standards or you know, the regulatory obligations, but that's something that is practical and contextualized to them. But then you look at— Well, you have to be flexible, right? I mean, you have to be flexible.

You have to be reasonable, for goodness sake. Reasonable. Okay. I think we don't even approach flexible so much as, you know, we're sometimes missing the mark on reasonable. Okay.

If I could give advice to anybody in our industry, it would be to be that reasonable business side CISO. You know, I've been working on some content in the background, Frank, not to digress from your question too far, but Talking about, you know, the role of the CISO is dead. And that's, you know, that's some of that flair that comes with, you know, you go to a conference about security and you say that the chief role in that industry is dead. What I'm really getting at is saying the olden days CISO, and if you think about what that looks like, is what's dead. And instead, you know, modern CISOs should be better representing something closer to a CRO or a COO or a CTO.

Being technology officer, not, or trust officer, frankly, something like what Robb was doing.

Well, okay, could you explain that? Because you just made half the audience listening to this podcast panic a little bit here with that statement. It's, again, it's not that our chief and our function and analogy is supposedly dead. Rather, the old way, if you will, the legacy way of doing things is what needs to be deprecated and you know, as security has become more front and center in our industry and in our businesses, it's getting more at the board, it's being absorbed more at the C-suite, and we need to go away from just being department leaders now to being business leaders. And that's kind of that transformation that I'm getting at there.

But, you know, what you asked me also, what's not the same from company to company? And in fact, it is the end game of what a security program, as I make air quotes on an audio podcast, but of what the endgame of a security program is. It is very different for every company that you're in. And anybody that's held, you know, senior leadership roles at various companies knows what I'm getting at here. And that is the security program is typically driven by the inherent risk tolerance of a given organization.

I'll give you a really good example. You know, working in my time at IBM for the US Federal Data Center, almost no risk tolerance. They wanted everything to be buttoned down, locked down. Everything had, for want of a better term, red tape associated with it. There was zero room for any type of risk acceptance in that space.

And it's, you know, you're dealing with a FedRAMP-certified data center and, you know, you're hosting 3-letter agencies in this private cloud that IBM has built. Specifically for the US federal government. So there's no room for risk there. They just have no tolerance for that. To the organization that I'm at now, you know, we're basically a $2 billion a year startup.

You know, we have tripled in size in the last 18 months and we're looking to double in size again in the next 2 years. So, you know, you can only do that so many times before that becomes really formidable to accomplish. Sure, going from you know, 500 to 1,000 employees, not so hard, maybe even 1,000 to 2,000, but 2,000 to 4,000, 4,000 to 8,000, it really starts to get difficult to double those things. And the risk tolerance that's necessary to accomplish that and to facilitate a business in doing that is very different than what was seen at the federal data center. So, you know, I find myself, and maybe this is why consulting comes naturally to me, but having to become almost a chameleon security leader In that I tailor the programs and the governance and oversight and the, the goals of my programs to match that business risk tolerance.

This organization, very willing to take some risk, you know, outside of regulatory obligations, they're, they're very open to taking on risk. They would much rather have speed to market than everything 100% vetted, absolutely pen tested. If we get a defaced website, Great, let's clean it up, move on. You know, not to the degree of negligence of, you know, perhaps having healthcare data breached, of course not. But, you know, they're much more interested in market share and enhancement and market innovation and leadership than they are making sure that everything is buttoned up, you know, eyes are crossed.

Oh yeah, pick your idiom. Yeah, well, I mean, I definitely understand that we— there are times, and I've been with, of course, several organizations as well, where They want to do— have everything buttoned up, and it takes so long that it's like our opportunity is now gone. We are going to the market way too late. We are not getting enough feedback. And honestly, you know, you may hate me for this or you may agree with me on this, we can never get this perfect, especially because we won't have all the factors and we won't have all the feedback.

You know, a lot of times if we are to put this at 100%, we aren't gonna have the feedback necessary, the data necessary. We're building it in a vacuum. Yeah, you're absolutely right. And, you know, that varies from org to org, you know. So at the core of your question of what's different, it's in fact that risk tolerance and tailoring a program to that business.

And, you know, a lot of leaders in our business, in our industry are are old hands, you know, we've, I mentioned earlier, I cut my teeth in infrastructure and a lot of us are former engineers or architects or, you know, who have kind of come up through the ranks.

And we're not awesome at talking to people, you know, a lot of us are social introverts or we didn't develop organically those business communication skills. And that can sometimes handicap, you know, us as executives and If we're working on any one thing, I think as an industry, particularly the leadership in this industry, it needs to be those business communication skills because we're never gonna get to a point where we're taken seriously at the executive table or in a boardroom as business leadership until we're able to speak that language with the business. We're able to understand what they're trying to accomplish and then turn around and then do the old school CISO thing. How do I take those business obligations, translate them into technical thingies, and then go out with my architects, engineers, and my partners over in the IT team to actually make it work? Okay.

Nowadays, that's one of the most critical skills we could develop is the ability to communicate effectively with the business and translate those things into operational execution. Okay. So since we're talking about this here, you've got a brand new person coming in into this industry. How would you advise them? I mean, and, and they're coming in with no real knowledge of what anything we just talked about here.

They came in and said, I want to get into this thing called cybersecurity, and I'll, I'll do the same thing that you did. I'll do the air quotes even though we're just doing an audio podcast here. How would you advise them? You know, it's, um, that's a pretty broad question for, uh, for a pretty broad industry. Um, I, I spent a good amount of my time you know, coaching folks that are coming in new to our industry.

I think if, you know, many of our peers that have been here for 5, 7, 10 years, they've got enough contacts to get out and find some peer coaching and stuff. But I remember when I was first trying to get into security, you know, make that shift from IT into security, I really struggled to find, you know, a good coach or a good mentor. I have since found them, but it was hard. So I try to make myself available to those newbies. And, you know, Frank, to answer your question, it's, it's, you know, their first question when they ask me is, what do I do?

And I, and my immediate response is, well, what within cybersecurity do you want to get at? You know, there's everything from AppSec to, you know, to infrastructure security to physical security. And, you know, it's like saying, hey, I want to you know, I wanna go into the healthcare industry. Okay, well, do you wanna be a neurologist? Do you wanna be a chiropractor?

Do you wanna be GI or, you know, general peds or what? So, you know, I try to feel out a little bit what they're trying to accomplish. But something that's consistent between all of these, all of these folks that I tend to coach is, well, I will customize some of the coaching that I give them to the part of our industry that they wanna get into. I consistently tell them that their ability to get out and network, establish relationships. You know that old adage of it's not what you know, it's who you know?

Frankly, it's a little bit of both. You know, I'm blessed enough that, you know, many, all but one in fact, of the jobs that I've ever had, I have had somebody somewhere that I knew or, you know, it wasn't necessarily some, you know, a poor version of nepotism or anything, but I always had an in Um, and I think unfortunately that has something to do with it. Uh, fortunately, unfortunately, you know, you take the evil that you know over the one that you don't. So, um, yeah, and I think that's where a lot of us think— sorry, I said I think that's where you and I have a lot of similarities. I mean, when I, you know, obviously as a, uh, you know, instructor for a lot of the universities and local colleges, um, when people ask me that, I try to do a little bit different.

I try to build on what they already know. Um, you know, whether or not they, you know, what did you do if you're right out of high school? What did you like in high school? Because the one thing that I think you absolutely have to have in a cybersecurity career is passion for it. Yeah.

Um, constantly changing, you know? Yeah. But I mean, you can't just get into this. I, I always tell people, if you're trying to get into cybersecurity because of the money, you're in it for the wrong reason. Yeah.

Yeah, that check, as I noted earlier, that check gets old. You have to really enjoy the critical thinking, and this is the same feedback I give to the folks that I coach. You have to enjoy the critical thinking. You have to be a lifelong learner. This isn't GAAP accounting.

You don't learn this and then do the same thing for 20 years. You know, if you're 6 months out of the industry, you've got weeks of prep and review to get back to current. If you're a year or 2 years out of this industry, you might be very close to starting over. Granted, the OSI model hasn't changed in 20 years, but, you know, modern tech evolution comes and goes in probably 2-year waves if you look back historically. So, you know, you're out for 2 years, you might as well just start at the bottom of, you know, emerging tech and go up from there.

But it's that critical thinking, it's the constant learning, people skills, is becoming just as important in cybersecurity, uh, as anything else. And, and you know me well enough to know, you know, my, my post-grad education is all based around human security and psychology and things of that nature. We've always said, Frank, in our industry, you know, the, the users are the biggest factor in our cybersecurity programs, and it's generally not wrong. You know, breaches come in as a result of human error. Um, you know, so the ability to get out and talk to people and understand the way that they think to relate to them in, in the context of, you know, championing your programs out amongst your companies and such.

There's a lot of value to that ability to just get out and talk to people, which can be frankly a lot more difficult in, in our modern society. You know, a lot of us work from home, or it's a lot of Zoom meetings or something. So it's even a bit of a different skill now than it was pre-COVID, right? I mean, COVID kind of normalized work from home. And granted, you and I have bounced off of each other in career roles since, I don't know, 2015 or something.

But, you know, I've worked from home since 2010, 2009. And it was, it was always a little weird sometimes to, to be working remotely and to still establish those ties. And it takes active effort to build those relationships within the business. And, you know, the first thing I do when I start a new role, I'll spend a week just getting out and talking with people, meeting people, sit and listen and understand, you know, what are you struggling with? Not necessarily with IT or with security, just what are they struggling with day to day?

Because you'd be— I mean, we all know IT and security touches every part of the business. So if they tell, you know, my current role, I had someone tell me, oh, you know, we're really struggling, you know, just, just trying to get our doctors to, to do consistent things across all of their practices. You know, I've got a group of doctors over here that's doing one thing and another one over there that's trying to accomplish the same goal, but they're going about it totally different, and it's really expensive for me as a result. I pay extra money on tech and things like that. And, you know, I might hear a business problem there on the face of it, but what's really behind that is a lack of technology strategy, IT communications, business communications, change management, you know, those types of things that can really inform in an effective way.

And IT has arms into all of those things. So does, you know, a good security program seen as an innovation office. You know, not a, not a bolt-on. But I mean, if you think about it though, and kind of going back, those 2 doctors may try to accomplish the same thing, but because of their unique backgrounds, yeah, they might have to do something different, or you may have to do something different from them. Yeah.

And getting out and talking with them, man, I, I learn new stuff every day about working within med field. You know, we, I spent what, 5 years working in Cognizant and Cognizant Healthcare and You know, even in my time here since I've joined Kirona Health, you know, getting out into the field and learning how these doctors deliver and such gives me great insight and the challenges they face every day. So, you know, again, always learning, understanding the business better is gonna help me provide a better program to them that frankly just isn't a pain in the butt. You know, they're gonna take— human psychology is gonna take the path of least resistance and they're gonna take the path that has something in it for them. And if we don't have, you look at sidewalks on universities, Cambridge did a study on this, you see these paths through lawns that are just trotted down because people will take the shortest path to somewhere.

We'll just put a sidewalk in where everybody's trodden the grass down. And at least then, you know, if we extend the metaphor back to the business, at least then it's a governed enterprise-sponsored solution. You've got controls around it, you've got the ability to monitor it, you've got the ability to just support it. Provide contract liability protection around it, those types of things. So instead of trying to force people to use something, understand what they're doing and why they're doing it that way, and then find an enterprise solution, be that innovation office that, you know, understands what they're trying to accomplish, and then find a safe, governed, and sponsored way for them to do the thing that they're already doing, just with less risk.

And you'll find the adoption is much easier. And in fact, they I found that people now proactively engage my security teams or even our IT shared services team to say, look, we don't know how to get there. We just know we want to do this thing. Can you guys find an efficient and risk-averse way for us to do that? And it's really a blessing to, to be engaged as an innovation office and not have to, you know, constantly be chasing people's products to bolt security or IT efficiencies or something else on top of that.

Okay, well, you know, we've been very serious and talking a lot about the businesses, but, you know, let's talk about the outside life because one thing we repeated in this podcast over and over again is that you've got to have something non-technical, something to get yourself away from that computer. Yeah, tell me about it. I happen to know, since we've known each other for a while, that you're a bit of an adrenaline junkie, right? Um, yeah, yeah. I remember you— I— we had a conversation.

You wanted to go jump on a space shuttle at one point, uh, jumping out of airplanes, which completely confuses me because it's a perfectly good airplane. Uh, what would you do though? I mean, what— how would you talk about that, or what's your biggest passion in that area? Um, you know, in that— in that thrill-seeking space, um, you know, I, I drive fast cars. That, that's always fun.

I, uh, I pursue these things less as I have 2 around kids. And now, you know, I find my passion in being terrified about my kids doing things. But, you know, pre-kid, you would see me, right, jumping out of airplanes. Skydiving was a hobby of mine. I would head down to— what kind of cars though?

I would head down to Bandimere and race on the track. And, okay, you know, my— right before I had kids, you know, I was a Corvette guy. And, you know, that never ends well for speeding tickets. And now I, you know, I drive a Model X and You know, those are sub-3 seconds, 0 to 60. And, you know, now I just— now the kids fit in the back seat and we make it to 60 in 2.5.

And, you know, the kids yell at me every time I spill their chocolate milk on the back window. Every time, you know, you have to warn the kids, you know, hey, hey, kiddos, are you ready for some speed? Yes. And then, you know, you got it and you got to hang on tight, right? Well, you know, one of the things that I made a purchase of that you don't know of, I traded my minivan in since my kids are older.

Yeah. And one of the things I purchased was a 1997 Mitsubishi Eclipse right out of the Fast and Furious movie, manual transmission. I have to tell you, one of the funnest cars to drive. That was, that was one of my focus cars in my undergrad and in college, man, was, was that or a, one of those Mitsubishi GT-2000s, man. So yeah, you know, fast cars are right up there for me.

Um, you know, I do tactical defense training to provide security services to, to my churches and local congregations. Uh, you know, so, so anytime you're running around through a shoot house with some munition, you know, that's always a huge, uh, adrenaline dump to do those types of things. And, um, okay, I, I am getting on in my years, Frank. I, uh, I got a photo shoot at one point, uh, when I took this role Because they like to paste your face all over the internet when you take these things. And the, this photographer that was taking our pictures out in DC, he asked me if, if I wanted the gray hair that's, that's coming through now to be Photoshopped out.

And I didn't know if that was a kindness or an insult, but I said, no thanks. Au naturel. But so as I get older now, you know, and my kids are, are growing, you know, I got a 7-year-old and a 2-year-old now, just about. You know, I spend my time now building Lego is a big fascination of theirs. It's part of that STEM piece.

You know, I'm an engineer by trade. So, you know, I build things and that's, that's kind of zero brain activity for me. So as I get older and more tired, I just look for something that gets me away from the rush and the stress of work is this kind of zero brain activity to just follow the instructions and do the thing. And I use it to spend time with my kids who have a really good time with it. You know, the funny thing about our job, Frank, is, you know, if you ever get those error messages when you're, you're doing something, it says, oh, an error occurred, please contact your system administrator.

And you're going, I am the system administrator and I have no idea what's going on. Well, we spend our lives just figuring it out, Frank. Like, there's no instruction manual for security and there's no instruction manual for getting a program right for a business, you know, to a degree, you know, we've got these core concepts and frameworks, sure. But man, 50% of what we do is art. You know, we're kind of figuring it out as we go.

And anybody who says they're not, they're probably lying to you. Well, that's why I always like to say is that, you know, it's more of an art than a science. Yeah. But we can use the science to drive the art. Yeah.

Yeah. I mean, that old adage, does life imitate art or does art imitate life? Nobody ever knows. Once, but— oh, I, I know that one. The answer is yes and yes.

Yeah, yeah. Um, so, you know, there's— I do that all day long. So the— I think the, the brain relaxation that I get out of just having a freaking manual for, for how to build the, the latest Lego set just tells my brain, you don't have to think about anything critically, just follow the steps, dummy, and, and you'll get to this nice pretty thing at the end and you know, that, that's calming for me. But more than anything, um, it's quality time with my kids. And, you know, I, I don't know what they're gonna grow up to be.

It's, it's one of the biggest fun things about being a parent is, um, you know, trying to figure out what your kids are going to be when they grow up. And my kid, my eldest, uh, she has such an affinity for, for engineering and mathematics, but she tells me every day for years now she wants to be an artist when she grows up. And I'm like, man, how are you gonna you know, being the adult, I go, how are you gonna marry what, you know, what you wanna do with what you're naturally good at? And, you know, I'm sure she'll figure it out. Maybe she'll be an architect someday or something.

But that, that for me is my time away from work. And, you know, my wife and I, we waited 15 years. We were married, we got married before we could even drink. But, you know, we were married for like 15 years before we had kids. And, you know, the intent was that You know, you've done the corporate ladder thing, you've done the education thing.

And now, you know, if my daughters come to me and say, hey, can you, can you be our soccer coach? Or can you learn that? I kid you not. Can you learn this ballet dance with me? I'm 2 feet in with that.

So, Frank, you know me, 6'1, 200 to 250 pounds, and I'm rocking a tutu. No, you know, it's— yeah, I will hands down learn a dance routine for my daughter's Christmas ballet. Thing, which is funny enough is this weekend. Uh, so looking forward to that. But, um, you know, no, that's where you and I have a lot of similarities, right?

I mean, uh, we waited 8 years and, you know, at one point, uh, I had all the Disney princesses memorized, or at least a cheat sheet on my phone.

Yeah, well, you know, it's— it was important to them, so it's got to be important to you. Absolutely. And, you know, it never goes the other way, Frank, because I'm pretty sure we've been, we've been doing this for what, 20-something years? And I don't know about your wife, but my wife still can't correctly tell people what I do for a living. So, you know, anytime my wife goes out and she's just, oh, he does computer security, and that's about as accurate as it gets, which is, which is not wrong.

But, you know, any, anytime there's a follow-on question by somebody who's interested in that space, it all falls apart, Frank. Yeah. So, you know, while I have to know all the Disney princesses, my daughter does not yet know all of the, all the ports from 0 to 1024. And I'll get on it, man. You got it.

No, no, it's a parenting goal of mine. Teach her all the common game ports. You know, it's funny though. My wife originally started out as a very non-nerd, like you said, but now she's— I've converted her. I've converted her into nerdism.

Yeah, I mean, she, she knows quite a bit about systems, uh, she knows Star Trek. She actually loves Star Trek now. Really? And yeah, it is just like, wow, you know, it's— it took me, you know, 30 years to do this, but I, I got there. So persistence is king, right?

I think my, my wife won that war. Um, okay, you know, I I was never— I never saw myself as, as a, as a functional father, I think. And, you know, I will— Frank, you've known me long enough to know me before I had kids. And I mean, for anybody that's listening that's known me longer than 10 years, you knew me before I had kids. And I was a very different person.

And now I'm arguably slower. I'm, I'm a bit more emotionally mature. I'm a bit more conscientious of— Well, wait, hang on, hang on, hang on, hang on. Emotionally mature? No, wait, hang on.

It's better now. I didn't say I am emotionally mature. Okay. No, I thought you said that. You said that you were emotionally mature and it's like, come on, man.

If I'm not emotionally mature, I know you are not. So the wife, the wife turned me into a better person, which I think is what we're all kind of hoping for is our partners turn us into better people. Yes. I agree with you on that part, especially with my wife. I, I still have the goal to get my wife to learn all of the, the primary Batman characters and, and villains.

And, you know, I'm— I, I didn't even get it one a year, man. So I think she knows who Batman is. Maybe there is a 6-foot statue of Batman in my basement, um, so I think she's at least figured that one out. But that's, that's as far as I've gotten in 20 years. So is it ever gonna make it upstairs though?

Uh, no, but I have gotten Lego to make it upstairs, so You know, that's, that's now seen as appropriate decor, and I didn't think— well, did you do it when she wasn't home and then made it into a way that it would be too hard to remove? Uh, yeah, it's, it's, uh, in fairness, I, I, I built things. My wife is a giant book nerd, and I love her every day for it. Um, so in fairness, the, the models that are upstairs are of the books that she finds most interesting. So I think that was, you know, marriage is about compromise.

And that's probably where, where we landed with that is if I'm allowed to have plastic toys upstairs, they're at least things that interest my wife, you know? Okay. Well, you know, we are coming close to the end of our time, so I'm going to give you probably one of the most difficult questions for the podcast. But I always like to end our podcast with this one. Sure.

Okay. So what do you think is the biggest challenge that we have for security today? Now, I'm not necessarily saying solve it. What I'm saying is, what is the challenge and possibly some ways to do it? And just to make sure that we change the conversation, you can't call back on the previous stuff.

Sure. I think we have a distinct lack of anxiety medication. I also think, you know, I think our industry, and you might call me a pessimist for this, but You know, what is, what is a pessimist other than an optimist with a dose of reality? Um, I, I think our industry, too many people have this notion that, that, you know, if what you can calculate what we're doing as, as a war, so to speak, um, you know, the good guys, the white hats, the bad guys, the black hats, and then everything in between. Um, we seem to, to have too many people expecting that we're effectively holding back the black hats or the bad guys or the threat actors.

And, you know, anybody that does this long enough knows, you know, we have to be right 100% of the time or effective 100% of the time. And they only have to be effective once. And it's a problem. So I think we as an industry have a perception that we are doing well. And I don't personally think that, that we are even close to defending ourselves well.

You know, breaches happen every day. New product is published every day with vulnerabilities. We're just, we're not, and capitalism, I think, is not conducive with this, especially US economy is not conducive with ensuring that everything is buttoned up before it goes to market, which, you know, would go a long way to this. So You know, we, we tend to think that we're doing better than I think we really are. And as a result of it, you know, our industry might be a little bit more relaxed about cybersecurity programs, or particularly their ability to invest in simple incident response.

You know, I, I don't think that there's enough focus put on the fact that we just accept, you know, everybody says, oh, you know, it's when you get breached, not if, but I'm of the mindset of how many times are you going to be breached and, you know, how do you respond effectively to that? Stop trying to not be breached and instead try to respond very effectively and very quickly when you are breached and you're breached multiple times, right? Because you can be breached without even knowing it for, you know, what's the average now, 102 days or something like that. But once you find out, you know, Are you, are you taking 3 months to recover from that? 2 years?

And some of our past employers, you know, they're still dealing with that. Or, or is this something that, you know, you have locked down and buttoned up enough that you can, you can recognize that you're breached, you can respond to it, you can get things under control, and you can get back online in less than a month? I think is a great metric to start with. And, you know, maybe that becomes even faster and faster as you get better and better. And that to me is the true measure of a cybersecurity program, not how well you can stop breaches, because again, nobody's gonna bat 1,000.

Nobody's effective 100% of the time. A true measure of a cybersecurity program is how quickly you can get a business back online, which effectively means how well are you minimizing impact to your business. And that's the real value that a cybersecurity program should be providing to their businesses. You know, minimizing disruption. And cybersecurity is, you know, security breaches are just one form of disruption right next to supply chain disruptions and availability disruptions and staffing disruptions.

Risk is risk is risk to a business. They don't care that it's security risk or manufacturing risk or supply chain risk. We're all just trying to develop consistent and stable operations so the business can maximize revenue. Um, so, well, that's what I'm after, you know. Well, that's where I like to teach my students.

So, and one of the biggest challenges in going into this industry, right, is that if in some very unlikely case that we don't ever get breached or attacked, business goes on as normal. Yeah. But if in some weird way that we are able to do 100% of our job and do our job 100, you know, bat that 1,000, right, or bat that 100 here, yourself lucky. Right? Well, the business goes on as normal.

So what's the difference? I mean, the business, you know, if we do our job perfectly, the business goes on as normal. If we, you know, don't get attacked, the business goes on as normal. So how do we show our value? And that's, I mean, you're the power company, right?

Nobody remembers that the power company's there until the lights don't come on. And then it's not a problem until it's a problem. So, you know, lights are off for 3 months. Everybody's mad because the milk spoiled and, you know, we can't function in our household, we can't function in our business. Lights are off for 15 minutes, no big whoop, we move right on.

We go, yep, I'm gonna keep paying my power bill, I'm gonna keep investing in my cyber program because yeah, we had a cyber incident, but they had me back online in no time relatively, you know, and that's, that to me again is the true measure of a successful cybersecurity program is how well are you enabling your business to provide consistent stable and profitable services to whatever industry model they're pursuing, is it consumer-facing or otherwise. Awesome. Well, Jacob, thank you for your time. I mean, we are right at about 45 minutes here. So again, thank you for your time, really, especially talking about things like going from an internal CISO, you know, to consulting.

I think that you gave some people a lot of insights with that. Um, being able to talk about, you know, mentoring that next generation of folks. And I would love to do is encourage everyone listening to this podcast, if you are very experienced, be a mentor for somebody. Be a mentor and find some people, some people that are getting into this industry. Help them out.

See what you can do. Put that foot forward. Reach out to them. Uh, because we all know how hard it is to succeed in the success in this industry, right? So, and I would be remiss here if, if I didn't close with saying, um, you know, it's important to recognize the difference between coaching someone and mentoring someone.

And, you know, one of my old mentors, Matt Shufeld, uh, is the one who educated me on the difference of these things. So, uh, before you pursue that journey and before you use those terms with with, you know, these up-and-coming generations. Understand what you want to accomplish and how much of your time you want to put into that. And just set expectations with those new industry entrants as to what you're putting into it. And also, you know, what you expect them to put into it.

It's a mutual two-way street. So they are our retirement plan someday. And, you know, we can't do this alone. We can't do this on an island. We need multiple generations of practitioners to make this work.

And, uh, you know, I don't want to be doing this until I'm 70, so I, uh, I would— yeah, well, get out and find someone new to pick up the gauntlet, pick up the mantle from us so that we can keep moving on. Well, I think that's the most of our audience, but I think you and me particularly, we're never going to retire. Uh, we're probably gonna die before we retire. So I think, I think if I truly retired, my wife would probably run me out of the house for lack of leaving her alone. So I think I'm always gonna have to find something to do, even if I You know, I just fall back on, on coaching or mentoring or, you know, doing something else.

Awesome. Well, again, thank you for your time, Jacob. I really do appreciate it. Again, my name is Frank. I am— well, along with a lot of other things, right, I am the VP of the Denver OWASP Group.

We do have the SnowFROC conference coming up in March. It's actually going to be Pi Day. We have speaking engagements available on snowfrog.com, which I am going to voluntold Mr. Rubin here to submit for that. And he's going to speak at my conference. Notice that I don't give him a choice in this case.

Right. So he's going to come to my conference. He's going to do that. He's also going to encourage a lot of the people that he works with to also submit papers. And, you know, we're going to get Mr. Sheffield to sponsor my conference this year as well.

Right. So those are the goals that I'm leaving you with. If not, this podcast will not be published. And, uh, we'll change your words, turn you into AI, and put a bunch of fake stuff up there for you. So that's your only choice there, Jacob.

I appreciate it, Frank. Thanks. All right, thank you. Have a good one, Frank. You too.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes