Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is our newscast for episode 259. And Alex, we are in February.
This is the week of February 5th, 2024. We've already finished a month. It's crazy how fast the year is going. Um, you know, it was a nice, you know, easy lead-in, and then all of a sudden January was gone. Yeah, it's, uh, and, and, you know, we had this unbelievable weather this last week and then unbelievably quick turn into, uh, 6 inches of snow.
Yeah, it felt like spring for a minute, and now we're back to winter. Yeah, but it's a pretty— honestly, like, it's a pretty warm snow, which, which means you get that big fluffy thick stuff that's not so much fun to shovel, but it's not so bad to be outside in it. Yeah, and you know, it'll probably be gone tomorrow. Yeah, uh, well, good stuff. Jumping into some housekeeping, uh, reminder, we have a Slack channel.
This is the place where you can join 2,500 of your closest friends out in the Colorado Equal Security Slack. In order to join us, go to colorado-security.com and click the Slack button. While you're there, there's— scroll to the bottom and you'll, you'll find a mailing list. Square, you can just join our mailing list and get the show notes into your inbox each week. We'll give you the show notes and occasionally some other news.
I think you'll get some other news here this week as well. Yeah, um, it would be great also if you subscribe to the podcast on whatever you use to listen to podcasts and rate us. Let people know how good the podcast is so we can, you know, move up those ratings charts. I'm sure one of these days we'll hit the top. Um, also tell a friend, let them know about Colorado Equal Security, the podcast, and all the things that we're doing.
I think finally, if you would like to support us financially, we do have a Patreon campaign that's been ongoing for a long time now. We have some folks that help us cover the cost of the podcast hosting and other things like that. And speaking of our Patreon campaign, I believe we actually have a new patron. Yeah, a new patron to call out this week, Travis Heisch from IBM Security. Travis and I have known him for a long time.
He was a sales guy at Ping and he's over at IBM Security now. He's joined as a, as a new supporter of the podcast. Just a big appreciation for Travis and the other folks who, who support us. You know, it's, you know, the podcast doesn't cost a ton of money to run, but it sure is nice to know that there's folks in the community who are willing to support us and, and, uh, and keep it, keep it going. Uh, and occasionally, you know, occasionally we're able to do something fun like the, the summer, um, picnics with, with that money as well.
So big thanks to Travis and the rest of our patrons. You know, one of the other things that we've been trying to do lately, Robb, is organize some volunteer events It is fun, but also meaningful and worthwhile and helpful to those in the community. And we have one of those coming up on the 25th. Yeah, I'm super excited. Big thanks to Ben Fellows and Chris Abbey who have taken the lead on this.
The Colorado Gives— Colorado Equal Security Gives Back has our— was our 4th one, I think. I think this is our 4th one. Yeah, we did the— yeah. Anyway, this is an opportunity to go do a volunteer at a homeless shelter. Uh, through Volunteers of America.
It's going to be on the 25th of this month. In the show notes is a link to a form to fill out. Uh, here's the news: we can only bring 20 people to this event. You know, it's— you know, they, they can't have 100 people running into their shelter. So we would love it if you would join.
Um, please sign up, uh, here as soon as you can so we have a good feel for who's going to be there. Uh, I'm excited to, to, to see the outcome here. Yeah, uh, looking forward to it. I think it'll be a great event. Um, really happy that we're continuing to give back to the community.
All right, what do we got for our first story? Uh, Robb, this is a, a bit of a sad story. Um, this is about a Colorado pastor who was, um, accused of, uh, scheming to defraud some folks with a multi-million dollar, uh, crypto scheme. Oh, Alex, this isn't Pastor Eli Regaldo, is it? Uh, I think, I think that sounds right.
I think that— oh my gosh, Alex, this, this might be my retirement money we're talking about right now. I should have read this article before we started. Uh, well, Robb, uh, now you're gonna hear about it, and I'm sorry to have to break it to you here, but, uh, Pastor Eli, you know, he organized this, uh, this crypto fund as well as a, uh, crypto exchange. And you might say, well, this guy must be pretty technical to, to start his own cryptocurrency and his own crypto exchange. And I think the real answer is no, no, he really wasn't.
And while he felt like this was a good thing, I think it was a bit ill-conceived. And yeah, it turned out that he ended up using some of the money for personal purposes and pretty much the rest of it was lost. Well, it definitely seemed like a good thing to him as he bought his Range Rover, luxury handbags, jewelry, boat rentals, and snowmobile adventures, according to this article here. So, so I mean, obviously there's victims here. The people who trusted him, um, are victims.
I have like no sympathy for this, this guy who, who says, you know, God told him to start a cryptocurrency without knowing what he was doing. And when he got the money in the cryptocurrency, he went and bought a bunch of stuff to have fun versus figuring out how to run a cryptocurrency. So like I said, a lot of— not a lot of sympathy for, for this pastor, but I do have quite a bit of sympathy for those folks who who believed him and probably, you know, put millions of dollars into this fraudulent investment. Yeah, it's a sad thing. And I think we all know that cryptocurrency is a gamble even if it is done correctly, right?
Like, you know, you're not necessarily going to make money off of cryptocurrency even if it's legitimate. So when it's illegitimate, yeah, it makes it even worse. Well, if anyone comes to you and says that they have some really cheap um, shares in the Kingdom Wealth Exchange for the— is it INDX, the index coin? Um, you should probably pass on that. This is not an opportunity that you want to jump on, I do not believe.
Of course, you know, uh, the past is no indication of future results. I don't know what I'm talking about with investments. Don't listen to me. Yeah, we are not financial advisors. This is not legal advice.
Uh, yada yada yada. Yeah. All right, uh, enough with, with that story. Uh, you know, I know, like, was it 2 months ago we're like, man, this show turns into the the DIA podcast way too much. But like, this is a, this is a really interesting story from my perspective.
So we threw this one in here. And as you know, as a couple folks who travel quite a bit through, through the airport, man, the, they've actually, the day has come when the new security is opening. And we're not going to be going through the North security anymore as of this week. Yeah, I believe if you're listening to this podcast, North security should be closed by now. And the new West security gates which are up a level on the west, northwest corner of the airport, are now open.
And this is the one of the big renovations that's been happening at DIA. There are now, I believe, 17 lanes that go through that checkpoint. And it looks pretty cool with all of the newfangled technology that they're using as part of this. Yeah, this is one of those articles that if you're a regular traveler, I recommend you read the article. Because we're gonna just do a quick, you know, summation of it.
But, but there's a lot of good facts in here. First, first of all, there's going to be 3 different sections to the West. So there's West 1, which is kind of your, your typical non-pre-non-status travelers, kind of equivalent to what we used to do on the south side, right? And then there's West 2, which is your priority borders, but with— not with CLEAR. This is people who are, you know, first class or, you know, other things that make you priority.
There's, there's this new reservation system called DenRes that you can, that you can get like a reservation for a time to go through security, and that goes to 2. West 3, that's where people with, with Pre and Clear will want to go. Uh, it looks like it's going to be faster and easier. Like they said that across all 3 of these, you don't have to take liquids and laptops out of your bags anymore. Like, amazing, right?
That's a pretty big enhancement. Um, and there's all kinds of other stuff they're going to be able to Uh, they— it sounds like double the number of people who go through this per hour per lane once this is, uh, once this is up to speed. But even immediately, it's like a, like a 30% increase or something for, for speed per lane. So anyway, pretty cool stuff. I'm excited about this.
Yeah. Um, of course, the south checkpoint is still open. Um, they are working on the east side security, which will be similar to the west side, uh, but that's going to be a few more years still. And until that is done, the South will remain open for, uh, non-pre-check passengers as well. And it sounds like even after they close South, the South may rise again due to the need to have, uh, something close to people who get off the A Line train.
Uh, apparently that the South is where the train comes into, and it makes sense that people don't have to walk all the way to the North to go through security. Um, one other thing just to mention is that through this change, as the North security is closing the bridge security is closed. You can no longer walk through to, to the A gates to go through security, I think, as of now. That's the way I read it. Yeah, I believe so, because, uh, you're going to be coming out of the West security kind of right at the entrance to the, uh, to that bridge.
So I think they had to close that, uh, as part of the new configuration. So yeah, kind of, kind of sad for that, um, for those people that like walking across the, the, uh, the A bridge. But, you know, change is progress. Right? Good stuff.
All right. Jumping into our next story. One of the things that I've enjoyed most about doing this podcast for the last over 7 years now, 7 years this month, Alex, this is it. February. That's, that's the month.
Hey, how about that? How about that? Happy anniversary. Happy anniversary. One of the things I've enjoyed most is getting to really know the tech scene a little bit better.
Like, I've always, well, for quite a while, I've been pretty plugged in with the security scene, but not so much on the rest of the tech scene. And this is, this has been a fun way to learn. So it's fun to call out a couple of, we have a couple articles this week that hit into that. There's a, a local company called Lightship Energy that makes electric RVs. So they are headquartered, kind of dual headquartered in San Francisco and in Boulder, and they just closed a round of funding for $34 million to help use to create their first wave of electric trailers, the Lightship L1.
Yes, uh, it does sound pretty cool. Um, I think it was interesting to me, Robb, that, uh, they call themselves an RV company, but they're making trailers. I don't normally think of, of RVs, um, when I think of trailers. I think of, you know, things that actually you can drive on their own. So I'm— I don't know if I just don't know the definition of an RV or if, uh, you know, maybe there's a nuance here, Alex, that this particular trailer has the ability to propel itself.
I don't think you can drive it itself. But it has, you know, it has really big battery packs and it's solar powered, has a bunch of solar panels on it. Um, so it has the ability when you're driving that you don't actually need to use additional energy from the towing vehicle to drive it. So maybe there's some kind of a rule that if it's propelling itself, it's a vehicle. I don't know the rules either and I'm not willing to look it up, so I'm just gonna go with that.
Uh, maybe some, uh, some fan out there, some listener will be able to, to tell us what the difference is and whether this actually qualifies as an RV or not. But, uh, Sam Masiello is a pretty big RV guy. He might, he might have an opinion us. Doug Williams also, maybe, uh, maybe. Yeah, also, um, so they are using a lot of this money that they raised to, uh, to start up their operations in Broomfield, which is where they're putting the factory to build these.
Uh, pretty cool. I think it's, uh, you know, next wave. I think everyone likes to be outdoors, and having an electric-powered RV, completely electric-powered, um, as you mentioned, that can, that can move itself also, I think is, uh, next generation. Cool to see these being made. Yeah, a couple of things interesting.
Like, I am— I'm not an RV person. I think the idea sounds cool, but I don't know what— I don't want to put it somewhere. And I'm— there's lots of reasons I'm not an RV person, but this is— this is kind of cool. This is tempting. You know, they— these things sleep 2 to 4 people, so they're not huge, um, but they— they're beautiful if you like look at the pictures.
Like, you know, lots of windows, very airy. Um, they can— they can provide off-grid, um, power for multiple days on their own. And they're— I, I know that like RVs can be very expensive. These things are starting $125,000. So certainly not cheap, but I think that's, that's pretty affordable for the, the space that they're playing in.
They're not, they're not coming in crazy high. Yeah, it— I mean, that is— it's not as cheap as you could get a, um, a regular trailer for, but obviously there's a lot more features and functionality to this than a, you know, regular kind of pop-up trailer or something like that. But yeah, pretty cool. Well, good, good stuff. All right, uh, moving on to our next article, another bit of a sad story here.
Um, there was an announcement recently that, uh, the well-known Boulder VC firm Foundry, um, is going to, to sort of cease operations. Um, they've, uh, in 2022, I believe, uh, they started a new fund and they announced that this is going to be their last fund. They're not going to do any additional funds after this. Yeah, I think you're right. It's, it's definitely bittersweet, but it's kind of like getting a cancer, a fatal cancer diagnosis that says, hey, you've only got 10 more years to live.
You're like, Huh, like, how do I, how do I do it? Because they, they say that they're, they're going to go for at least another decade to, to go through this fund. So they— this is not a, hey, we're closing up shop right now. This is not things are going poorly. What they make it really clear that when they started this fund, the intention was not to create a generational VC.
It was a place for the 4 founders to work together and to create something cool. And when the 4 founders were no longer up for doing it anymore, that they would, they would close up shop. And that's exactly what this is announcing. Yeah, but I think to your point, Robb, you know, once you make an investment, you're not done, right? It takes a long time.
So, you know, they're still invested in many companies and there'll be a long time before those companies go public or purchased or, you know, whatever happens to get the finality of their venture funding out of there. And, you know, with this last fund, they're still going to have, you know, a number of companies that they invest in with the money that's still out there. Yeah, so we still have another decade to go, but, you know, as, as just a little bit of a preview, you know, you know, this is a massive thing for Colorado to have had Foundry Group come here. I'd say that they are a— they are the primary reason that Colorado became a, a place for startups and a place for startup funding. They, they really drove that industry.
Um, now at this point, we have an industry that's strong enough that them leaving is not gonna— not, not gonna kill it, but, but it is, it is a big thing. And I'm sure as, as we get closer to them actually shutting their doors, we'll we'll talk more about that and appreciate the difference they've made for Colorado. So Robb, you're saying in 10 years we're still going to be doing this podcast? Um, maybe whoever takes over for us can bring us back on to talk about our, our, our opinions on that particular story. I did, just as a reminder for anyone who hasn't listened to it, I did interview Brad Feld, one of the, one of the founders of Founder Group, and he's— that's a pretty early podcast of ours, uh, and he's just an amazing human.
Yeah. All right. Moving on to the next story. Speaking of startups, we have a Colorado Inno story talking about the 4 Colorado software startups to watch in 2024. Yeah.
Usually when we go through these lists, I'm always looking for any security-focused startups. If there's not security, you know, security adjacent, I'd say none of the 4 software startups on this list are really security-focused, but they're pretty cool. And this is just a reminder that there's cool stuff going on in town that you guys can help out with. I'll highlight one of them. There's a company called Carepool, which is a, uh, kind of an Uber/Lyft type thing, but specifically for helping people get to medical appointments.
So, you know, you can imagine that there are a lot more requirements if you're taking someone who, who can't drive themselves to a, to a doctor's appointment. So, so the, the vetting that they have to go through and making sure that the cars are going to be accessible and, you know, the right fit for the people looking for the rides, that's what Carepool is solving. And they're headquartered here, getting started with Uh, with, with a real mission in place. They— looks like they did about $3 million in revenue a couple years ago, and they doubled their revenue last year. That— so 2022 was $3 million, they doubled last year.
So they're growing. Uh, looks like there might be a real need that they're serving. Yeah, pretty cool. Uh, one that I want to highlight is one called Chamba. Um, I think as people know, there, there's a large immigrant influx into the U.S. and into Denver.
Especially from Mexico and from Venezuela. And it's often hard for those immigrants to find work. And so what Chamba has done is they have set up an app that helps connect them, those folks that are looking for work, with jobs in the hospitality industry, which we know there's been a big shortage in the hospitality industry since COVID and, you know, really hard to get people back into that kind of work. One of the things that Chamba does is, you know, they're essentially the employer of the immigrants and they handle all the paperwork. They handle all the payroll and that sort of thing.
And then those— they match them up with places where there's work that needs to be done. And so I think it's a win-win on both sides. Good stuff. Alright, jumping over to our next story. The— there's some news here that the National Cybersecurity Center which is headquartered just down in Colorado Springs, has joined the Space ISAC.
And, and the space, you know, we, we're familiar with like the FS ISAC and multi-states ISAC. The Space ISAC is a relatively new creation, as you can imagine, uh, helping with intelligence and analysis gathering for the space industry. Well, NCC's already been partnering with them to provide information, and now they are officially part of the ISAC to give cybersecurity intelligence and really to just to help bring some more security knowledge to that industry. Yeah, I'd say this shouldn't be a surprise to anybody. You know, the Space ISAC is hosted out of the NCC down in Colorado Springs.
They've been partnering for a while. So, you know, for the next step for NCC to officially join as part of the Space ISAC makes sense. Pretty cool. All right. Next story.
Jumping into the security-specific stories for this month, we have a blog from Coalfire talking about mastering AI risks. Using the NIST AI Risk Management Framework Core. Alex, I would love you to talk about this one. I'm having a little bit of an issue getting the article, my notes up on the article right now. All right.
I can do that. Basically, you know, with the proliferation of AI, enable— being able to understand the risks associated with that is important. NIST came out with a risk management framework for AI. And it has 4 core components. This should sound familiar with other sort of risk management frameworks, but govern, map, measure, and manage.
And so this is really talking about those 4 components and how you might use them to help think about your risks associated with AI. Also, not surprisingly, Coalfire has a service that can help you to Uh, you know, use this framework if you're not familiar with it. Yeah, it looks like they, they created their own kind of how do you implement this, this framework, um, step-by-step process that they'll, they'll walk you through. So in addition to just using that process, they, they all, they have their own model as well. And, you know, I think that they, the other thing they call out here is that it's, it's really about awareness of this set of risks.
And, you know, it's not like a one-time let's go fix it. It's a, you know, let's make some awareness. Let's make sure that, that people are thinking about these types of risks that AI exposes us to. Exactly. All right.
Our next one, we have a blog post from our friends over at Ping Identity around what is device trust. I think I've seen, I've seen a lot of positive movement on device trust over the last couple of years. It hasn't reached, you know, zero trust or, or some other buzzword status, which is great. But it— I think it's really important if you're not thinking about what device trust means and, and and how you, how you allow access in your environment based on the device, that, that you're probably not really implementing zero trust yet. So I'd say that the Ping blog here, you know, it's not in-depth.
It's— this is certainly not like your, your Red Canary, you know, deep dive here, but it's a nice overview of what is device trust, what are the things you need to think about, and how, how might you want to use this in your environment. Yeah, good stuff. All right. Moving on to our next story. This is a Red Canary blog talking about Kubernetes security.
This is a good technical deep dive into Kubernetes. So if you're not super familiar with Kubernetes, it gives you a good overview of the different parts of Kubernetes and then talks about, you know, sort of the threat models around the possible threats to each of those particular pieces of Kubernetes. Yeah, I think that this— if you've been one of those people who hears people talk about Kubernetes and think, oh my goodness, just stay silent so they don't know you don't know what you're talking about, just read this article and at the end of it you're gonna be like, oh, okay, I understand how those pieces work together, I understand where the security risks might be. You could think that, you know, hey, this is the management plane where I need to be looking for different types of attacks than what I look at over here inside the nodes. Anyway, good article.
As always, we appreciate the folks at Red Canary making us a little bit smarter. Uh, and that was actually our last story, but we do have one other announcement. Uh, the call for papers for BSides Boulder is open. So if you, uh, have an interest in speaking and would like to speak at BSides Boulder, we'll have the link in the show notes and you can check it out and sign up. Yeah, and the— so BSides Boulder will be June 14th, um, and the registration for that is not yet open.
But the CFP is open. So go. I suspect that if you get picked to talk, that you don't have to worry about registering. You can probably just get in. That would make sense.
All right, let's jump over into events. A real quick reminder, we have a calendar of events, and I would say it was getting a little bit lean as you got to the new year, but all of a sudden everyone has flushed out their, their first half schedule. So there's a bunch of events coming here in the next few months. All right. Our first event on February 9th, ISACA Denver is doing a technical training, Alteryx Exploration, a beginner workshop.
So on— sorry, on the 14th, if you, if you want to have your sweetie join you for some security events or you don't have a sweetie and you just want some people to hang out with, there's a couple of things going on. ISSA Denver has their February meetings with their DTC meeting over lunch and their downtown meeting downtown. Um, and then we'll have the— sorry, Downtown Over Dinner. And then also on the 14th, the Let's Talk Software Security group is going to be talking about, are we defending against the biggest threats to software? That'll be, that'll be virtual.
All right. On the 15th, ISACA Denver is doing a February joint chapter meeting with the IIA. On the 20th, CSA Colorado has a CI/CD workload security session with Orca Security. On the 22nd, ISSA Denver's Privacy SIG is meeting. On the 24th, ISSA Colorado Springs has one of their Saturday mini seminars in the morning.
And then of course on the 25th, we already mentioned the Colorado Equal Security Gives Back event. Again, you'll see the, the link to sign up for that both on the, the web for on our event calendar and in the show notes for this podcast. On the 27th, ISSA Colorado Springs has their February meeting, an introduction to zero trust with enterprise Linux. I'm curious about that. Nice.
And finally, ISSA Colorado Springs on the 29th is doing a mentoring mixer and log wars.
We have— so that's the 29th. On the 28th, we also have one from ISC² Pikes Peak. They're doing their February meeting on the 28th. Oh, apologies, I missed one. Yeah, no worries.
All right, jumping over to jobs. Um, I'm hiring a VP of GRC over at Pax8. I'm looking for someone who has run GRC for an enterprise technology company with a global scale. 1Password is looking for a Director of Security Operations. Inspirato is hiring a Director of Cybersecurity Operations.
Sage Hospitality Group is looking for an Information Security Manager. Newmont Mining is hiring a senior operational technology cybersecurity analyst. Uh, U.S. Immigrations and Customs Enforcement is looking for an information technology specialist. Interesting that ICE is hiring a, a security person here in town. It's specifically focused on security.
Yeah. This next one, I was kind of hoping you'd get this next one, Alex, because I don't know how to say this word. I'm gonna go with Clavio. Clavio. That's how I'd say it.
Clavio is hiring a senior security trust and compliance analyst, GRC analyst. It's kind of a long title, but GRC analyst. Datadog is hiring a business continuity and disaster recovery governance analyst. Wow. Salesforce is hiring a security governance risk and compliance lead slash manager on security IEM.
What do you think IEM is? Robb?
Something engineering management. I don't know. I don't know. Identity engineering. Yeah, maybe.
Maybe. Okay. And then finally, Bank of America is hiring a manual ethical hacker. So no tools there. You got to do it all manually.
Yeah. No Google, nothing. We're making that up. We have no idea what they have to do. All right.
Well, that is it for the news, Alex. We do have an interview this week. Thank you very much to Debbi Blyth, who sat down and interviewed Merlin Namuth. We've, you know, you and I have known Merlin for a long time, a longtime friend of the show. Merlin has had a, a rich career from— I met him when he was over at Wells Fargo.
He went over to, to help run security for, uh, Sports Authority before they went bankrupt. And, um, I remember him going over to Red Robin after that and Regroup. And, and I know he's— oh, he has some time at Tenable as well. Yeah. Um, so I'm sure he's had some interesting stories to share with Debbi, and I'm looking forward to hearing them.
Yeah, me too. Should be good. All right, we'll talk to you again soon, next month. Thanks, Robb. This is Artie Wilkowsky, CISO at Dish Network.
Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals. Hello, my name is Debbi Blyth, and I am an executive strategist with CrowdStrike, and I am also the former CISO of the state of Colorado. And I am joined today by Merlin Namuth, who is a local cybersecurity leader here in Colorado. And Merlin and I have known each other for many years, so I thought it would be really fun to interview Merlin today for this Colorado Equals Security podcast that we have actually both enjoyed since its inception. So Merlin, thank you for being here.
I want to hear a little bit about your background and how you got into security. Yeah, thanks, Debbi. I really appreciate you suggesting that we do this. I think this is gonna be a lot of fun. And as Debbi alluded to, that we know, we're pretty sure that we met each other early on, and we think we may know how we, how we met, but I don't know.
I don't think we, we know for sure. So quite interesting. But yeah, so, you know, how I got into, you know, technology. So I am of, I guess, of the vintage. I guess that's what we say when we're old, that I'm of the vintage that most of us got in the field without having a computer science degree.
My undergrad degree is in psychology, and I always had an interest in computers. And after I took my— so my one and only computer class I actually had in college, was basically learning how to use different applications. So this was learning how to use mail on Unix, WordPerfect for DOS, Quattro Pro, and Paradox. It was— yeah. So that's my only formal computer class I've had.
Okay. Well, not that you've dated yourself or anything. No, no, no. And how many people listening to this are probably, you know, having to Google what DOS is? But I'm okay with that.
So after I took that course, I got a work-study job in the campus computer lab. And so it was, you know, just helping people be able to navigate WordPerfect and, you know, things like that, as well as it was— the network was running Novell, I believe it was 311. And so I got to know pconsole. Very well when print jobs were stuck or someone needed a print job canceled. And, and so I, I did that, you know, as a work-study job.
And then I also did that throughout the summer then too. I, I ended up staying. I went to Nebraska Wesleyan University in Lincoln, Nebraska. And I, after my first summer going home, I'm like, yeah, I really want to stay, stay at college with my friends. And so I, I stayed on campus and I worked on campus and during the summer as well.
After I I graduated there, I went to grad school at Washington University in St. Louis. And I, again, keeping with the theme of not getting any technology degrees, I got my first master's degree in social work. And that summer, right before I started, the social work department had gotten wired up for Ethernet. And, you know, everybody, you know, all the professors and, you know, admin people and everything, it was all very new to them. They didn't really know what to do.
I got connected with this, with this lady Her name was Karen, who was assigned to like support everybody in the building. And she had very little experience and understanding with computers. So, so it worked out really well. I ended up working for her as work study and helped the professors. And, and then I also learned a lot more about computing beyond that.
So I worked for the social work department for a year and then I ended up working for the campus NOC. After that. So I learned a lot of, of, you know, local area networking, wide area networking. For those— and Debbi, I'm not sure if you would be familiar with this or not. I don't think we've talked about this before.
There was a mirror. You remember the mirror sites where you could like go download different software and, you know, you'd set it up on your 14.4 or 28.8 modem and you'd like set it up and download all night and then, you know, come back in the morning and see you downloaded, you know, 4 megs of something and So that's how, you know, like some of the games like Duke Nukem back in the day and some of the other ones. So one of the mirror sites was actually hosted by Washington University called WU Archive, WU Archive. And it was a pretty popular site. And I remember just being in awe of like, I actually saw it.
It was like running on a DEC Unix box. But yeah, back in the day. Yeah. The good old days. The good old days.
Yeah. So then after I graduated, um, I ended up, uh, deciding I really liked technology and wanted to make a career of it. So I, um, had had a desire since high school to move to Colorado. Um, I've been skiing since I was like 12 and, um, enjoy the mountains and, and decided I was just going to move to Denver. So, um, after I graduated, I moved here and didn't have a job or anything.
I was just like, I'm just gonna move here. Yeah, that's adventurous. It was adventurous. Yes. And so I ended up getting a job soon after I moved here working for IBM.
That was my first real, you know, job in technology after, after college. And I did phone support for laser printers. So, wow. Yeah. And so we were like in— so working out of the Boulder office, we were the tier 2 support and the tier 1 was out of RTP in North Carolina.
And so if, you know, when things— and there's like a script— if things got to a certain point, then the Tier 1 would hand off to the Tier 2. And so I did different things like, you know, helping customers with like networking issues of getting the printers connected, you know, print driver issues, hardware issues. I even had a toolkit where I'd work with the field. I think they call them customer engineers, CEs, I think. And And they would like have run into some difficulties like taking apart a printer to fix something.
And so I'd pull a printer into my cubicle and I would like get out my tools and I'd step it through with them and take apart printers. So it was, it was, it was quite interesting work. And then after IBM, I went to work for Access Graphics in Boulder. So people who've been in the Denver area for, for some time will definitely know of Access Graphics. There's a lot of people who who had worked there and then, you know, went on to different things in their careers.
And when I was working there, I was doing phone support and it was supporting— so Access Graphics, for those who don't know, back in those days was a huge distributor and they were mostly focused on Sun Microsystems. So I took a lot of Solaris classes and became quite versed. And that's how Debbi and I think we might have met each other was after I'd left there, Access Graphics, I went to work for a reseller and I think I installed some, some Sun Solaris systems for where she was working at the time. Probably so. Yeah, that's what we're thinking.
That's what we're thinking. And, and so we also supported other technologies as well. And they sent me to a Check Point firewall. So this is Check Point Firewall 1 version 4.0 class. Oh my goodness.
Yes. I took that class too, actually.
And I got certified. Yeah. But, uh, yeah, after I took that class, I was like, wow, I really like this. And, and that's really, um, where I, I shifted my career to focus more on security. And, uh, so I owe it to Check Point, um, that I really became interested in it.
What year do you think that was? That would have been 1999. Okay. I took that. Yeah, that was about the year I think that I got interested in it too.
Oh my gosh. And it's like, and when I went to work for, um, you know, reseller, I, I ended up, uh, one of the projects I went on was to do an upgrade. I think it was from 4.0 to 4.1. And it was the only firewall. So there's no HA and it was running a Sun UltraV.
And in the middle of the upgrade, I ran out of disk space. Oh no.
No. So that was, that was quite a tense moment of trying to figure out. Fortunately, the admin who was responsible for that, so he was there, and between the two of us, we were able to figure out how to back it out and to, you know, finish the upgrade. But yeah, and that was actually for a local government agency, so it was going to take down that whole agency. Yeah, this was probably at night though, or something like that, right?
I think we went on a weekend or something like that. But yeah, it was, it was quite tense. And, but I think experiences like that really helps you to, you know, develop a good sense of how to troubleshoot things. And also when things go awry like that, how to back out of changes. Another experience that I had was when I worked for Access Graphics, I, once I became skilled enough, I did, I was on the on-call rotation for weekend support.
And I remember distinctly getting this call from this customer who had— and I remember this so vividly— he had 7 systems, 7 Sun systems. And he said, I had to take all the systems down because we had some upgrades happening to our electrical feed. And now that that's all done, none of my systems will boot. And so So that was like a, oh crap moment. And then I started thinking about it.
And I'd taken like one of the best classes I've ever taken in my career was this troubleshooting class that Sun gave. And I took it at the Broomfield campus. And the first like, I think 2 days was classroom instruction. And the remaining 3 days was the instructor would go around the room and he would break systems and you'd have to figure out what was broken and fix it. And so that class really helped me.
And so when I like I'm like, well, why? What would cause that? And then after thinking about it, I'm like, are you using NFS? He's like, yeah. And I'm like, you probably have what were called hard mounts.
And so it's dependent. So he had cross mounts in there. And so meaning for those who aren't as versed with NFS, hard mount is that the system won't continue booting until it actually is able to mount that remote directory or file. And so oftentimes it's recommended to use soft mounts because the system will keep booting and it'll keep trying to mount that. But he had hard mounts in there.
And so, so once I kind of figured that out after asking some questions, it ended up turning out to be like a fun issue to solve where we booted up a few of the systems in what's called single user mode so we could go in and edit the— what was that called? nfs.conf? Was that the name of the file? That sounds right. Yeah.
Oh man, this is like dating me. Configuration file. Yeah. Yeah. And then just, you know, took out those hard mounts and able to get a few systems up and then the rest of the systems booted up.
So, you know what I find kind of funny about that story is that he upgraded all his systems and then decided to see if they would boot. Like, wouldn't you upgrade one and then boot it up and see if it works good before you upgrade the rest? Well, actually what he did is he had taken them down and it was their electrical feed coming into their data center. It was upgraded. And so, Um, so he had taken all systems down, but I don't think he'd ever been in a situation before where he had all the systems down, them all down, and had to start them all at once.
Okay, that makes sense. Wow. Yeah. Oh, but those were, those were fun days though, for sure. Yeah, I'm sure he was panicking and he was glad he had someone to call.
Yeah, and I'm glad I had, uh, had some knowledge to figure out how to, how to sort through that. Yeah. Oh my gosh. So, um, once you decided like, I really want to pursue career in security What were some of the roles that you— I mean, how did, how did you go about pursuing that?
Yeah, I just, uh, um, targeted like security-specific roles. And, and it was interesting because I remember having like, um, a role at an organization, and I think it was one of my very first roles I had where I was just a pure, you know, I think my title was like security analyst or something like that. And I'm kind of like, what do I do? Because, you know, security back then was much simpler than it is now. And, you know, I joke around that, you know, early in my career it was, you know, antivirus and running FreeSnort and firewall, and that was about it.
And it's so much more complicated. So I'm definitely so thankful for, you know, getting in my career and being of the age that I am that my career really progressed as, as the technology and the capabilities progressed as well. So I knew at some point that I wanted to be a leader, but I felt like to be an effective leader that I really needed to understand the different technical roles in security. And so I just really focused on that. It is interesting though that my first security program I built, I did with a title of senior systems engineer.
So I was responsible for security and the Unix environment, and, and I built a security program. So I learned early on of how difficult it is to even get buy-in for a password policy. Yeah, not, not very uncommon back in the days that you're describing where, you know, there really wasn't such a title as a CISO, or at least it wasn't mainstream. And so you had folks as seniors systems engineer or manager of information security who were leading and building the programs. So not too surprising.
And yeah, not a lot of support back in those days either. Yeah. And it was also— you probably recall this as well— where it's referred to as IT security. Yes, absolutely. And back then it really was.
I mean, it was focused on just the IT systems. It didn't expand to information security. Um, until, until some years later. Very true. Yeah.
And yeah, go ahead. Oh, I was just gonna say, I was, um, curious if you'd tell us a little bit about the work that you did at Lockheed. I can talk about some. Okay. A little bit.
Um, I can say that going through, uh, a polygraph is, is not fun. Um, I, I did, I did have a top secret SCI clearance when I was there and had to go through a poly and, uh, That was, it was pretty nerve-wracking, um, because you're supposed to answer the questions basically without moving because, um, the sensors they have strapped to you like sense any body movement. And so that might indicate that you're lying. And so, and you're trying to get your breathing right. And, uh, and the, the, um, the, the guy conducting the polygraph just told me, he's like, you can shake your head yes or no.
I'm like, okay. Oh my gosh. So, uh, But yeah, it was, um, I had wanted, um, I had targeted Lockheed Martin for, um, a few years. I really wanted to go work there, and I was so happy when I, I ended up, uh, landing a job there. And I had, um, taken a SANS class, uh, the, the GCFA, the forensics class.
And I think I'd also at that point had the, the GCIH, which is the incident handling class. And, uh, Lockheed was looking for, um, someone with some forensics, uh, experience to come work. And initially what I did was to support internal investigations. So this was investigating employees. I can talk about that, that stuff.
I just can't talk about the classified stuff. So, so when I— and I was mostly support, so I was working for a specific business unit, and I was supporting basically one ethics officer with her investigations. And And keep in mind, so I, I, it's just a funny story that, um, she's like old enough to be my mom, so she had kids like my age, and most of those investigations were pornography. And of course, so of course I'm, I'm pulling like, um, you know, evidence office systems, um, and, you know, sending her like these pornographic pictures and everything like that, and she's, and she's cracking jokes about them.
Wow.
So, um, but, but, and then, then one time I, I remember, uh, cracking a joke back at her one, one time saying it's like, it's like, well, I'm just like everybody else. It's like I want to look at pornography at work. So it's like you just have to get a job where it's okay and you don't lose your job.
Yeah, I remember when investigations consisted almost entirely of investigating employees looking at porn. Yes. And when I took that job, I thought it was gonna be like the 20-something-year-olds that were doing that. It's like, oh no, it was like the 40- and 50-year-old people that were doing it. And it was pretty sad that I saw people lose like, you know, 20- and 30-year careers because they were doing that work.
Yeah. Violating policies. Yeah. Yeah. And, you know, and quite frankly, from a technology standpoint, it wasn't that challenging of work.
It wasn't really that interesting doing it. I mean, you know, with every job I learned something. So I definitely learned some, some good skills with that. But eventually, I think it's about 2 years into that job where at the time each business unit had their own CERT and they ended up collapsing that into one corporate level CERT. And so when I became a part of that, then that's when I got into like the really interesting investigations with, with APT.
And, and at the time, It was only— so Lockheed Martin, Boeing, SAIC, all those that do defense stuff is called the Defense Industrial Base. And so at the time, and this was like, I worked there from 2005 to 2010, and during that time, only Defense Industrial Base and 3-letter agencies even knew about APT. Outside of that, nobody in commercial even knew, had even heard the term. And I think it might have been classified at that point even that we couldn't even say anything and became unclassified. A few years later.
And so I could definitely say— I can't, can't say any details of it, but I did do forensics on a system when there was an active intruder on the system. So that was quite interesting. Wow. Yeah.
Yeah. And then— oh, go ahead. Oh, I was just— so one of the reasons that I asked this question is because I was curious to hear about your work on the cyber kill chain model. Yeah, so the team I worked on, the corporate level cert, we developed the Cyber Kill Chain. It was a team effort, so I'm not taking credit for it, like, oh, I did all this or whatever.
And a few people from our team then were the published authors for it, but it was a team effort to develop that. So it was really neat to work on that and then to see how, you know, some— I mean, I come across, you know, even yet still today come across the references for Cyber Kill Chain. Of course. Yeah. I think, you know, the MITRE ATT&CK model, I think is, you know, it's more pertinent today.
But Cyber Kill Chain was, was very pertinent back in those days because there wasn't anything and it really helped people understand, you know, how things move along, you know, from scanning systems to compromise. Well, I think it was super innovative because it was the first time that people really looked at the the full attack and what happens in an attack and realize that if you could detect it sooner and fracture that kill chain, that you could stop the attack. And so it was, it was a way of sort of getting your mind around, is there something I can do to, you know, to stop an attacker, to prevent an attack from being successful? So I think it was super innovative. And that's why I asked the question.
I wanted to hear about it. Yeah, and then also part of that was we had a very extensive threat intelligence program, um, at Lockheed. And so, um, and we had people who were— that's all that they were doing, um, what was threat intelligence. Um, um, and not, not that all, you know, meaning that wasn't, uh, um, you know, a lot of work. Um, it was a lot of work, but that was what they were doing exclusively.
And it's their focus. Yeah, yeah, it was their focus. And we had that down to where we knew at specific times of year that, um, you know, when we would activity from certain threat actors. And so, you know, to your point, we were then able to anticipate that and look for those kind of style of attacks that they are known for and, you know, try to be in front of that. I, you know, I can say we were— I learned a lot.
I mean, I went through many incidents. We had some large ones that took months and months to investigate and Um, I, uh, I got pretty decent with, uh, EnCase. Uh, we had EnCase Enterprise, uh, installed and, uh, um, learned, you know, and I went to a lot of training on that. Um, and it was interesting, again, you know, just, um, you know, given my age and, and when I got into security, just seeing how things have just really progressed. Um, because when I, um, was at Lockheed, they were, um, I went to like a conference and they were talking about like, oh well, you know, we're, we're working on doing some memory forensics, but, you know, there's really no structure to memory.
We're trying to figure that out. And then years later, then there's like tools that can do memory forensics. So it's, it's neat to see the progression of that, how some very smart people have been able to figure some of those things out. Yeah, fascinating.
So I, when I introduced you earlier, I made reference to the fact that you are a security leader in the community. So I'm curious, how did you make the transition from, you know, very technical, very, uh, hands-on and deep into the technical aspect of it to leadership. Tell me about your leadership roles. Yeah, so, um, you know, like I said, I really wanted to get into leadership and I was applying for some leadership roles and, and this is why I was still at Lockheed and I just wasn't really having too much luck. And then, so then what I did, and, and this is a strategy that I recommend to others who are, you know, trying to make that, uh, jump into leadership from, from hands-on technical is I started reviewing job descriptions.
And a common theme that I saw in the job descriptions was project experience. And I'm like, well, I have project experience because one of the projects I actually co-led was to build out the SOC here in Denver for Lockheed Martin. And it was a, I don't know, $3.5 million project back then. And, and so I had a lot of project management experience. And so I actually went and got my PMP, which is also not a very fun exam.
And just like the CISSP, it's very similar to CISSP. And I was so glad to pass it and no longer have to study for that and try to pass it. And so it was like, you know, it's a few months after that I ended up landing my first leadership role. Now, I mean, I wouldn't necessarily say that, you know, just because I had my PMP that that, you know, got me the leadership role. I think it helped.
You know, I, I know there's a debate in our, you know, amongst the security professionals of like, you know, are certifications necessary or not? I think certifications by themselves aren't really that useful, but it's the knowledge that you gain from those certifications. And then having certifications is just a demonstration that you studied a lot to be able to pass the exam too. And then you know, hopefully still retain, uh, um, some, some knowledge from that. Yeah.
Um, so yeah, so I end up, uh, um, getting a program manager role on a government contract, um, and I had 16 direct reports as a brand new manager. Wow, this is your, like, your first manager role and you have 16 direct reports? Yes.
And I also had 4 bosses because I, I, I, I worked for a joint venture company. Um, that was formed by 4 other companies. And every quarter, the CEO of one of those 4 companies was my boss and was, was overseeing this, this contract. And, and of course, you know, them, you know, the 4 of them being CEOs of their own companies, of course they don't agree on everything, you know, that other people want to do. And so I was like caught in the middle with my 16 direct reports.
Oh my gosh. Wow.
So you and I know a lot of the same people, um, and we seem to into a lot of— run in, I should say, a lot of the same circles. Um, so when did you start getting active in like networking?
Yeah, I got active in networking, um, I think it's about 2015, 2016, around there. And by that point, I'd run a few security programs. Um, you know, I've, I've, um, I've actually, over the course of my career, I've led had 5 different security programs, 2 of them with the CISO title. Most of them I've had to either build from scratch or rebuild. And so I have a lot of experience with building up security programs.
And so it was actually, I know a lot of people in the community know Laz, and as Debbi and I do, and he like really encouraged me to start networking. And I'm like, man, I don't need networking.
Yeah, I know. I kind of felt the same way initially too. But it's been great to know so many people because as a security leader, I get into so many different situations where I'm like, man, I don't know what to do. You know, I am not quite sure how to navigate this. And it's so nice that I have a number of people that are quick email, text, phone call, a way to bounce ideas off of.
And then, you know, you're really hosed when all the people I reach out to be like, I don't know what I would do either.
That's a really bad day. That's a really bad day.
But it's really nice because it is a hard job and security keeps changing so rapidly that it's just so hard to know, you know, keep up on all this stuff. And, you know, I think, I think it was SANS, wasn't it, that developed the CISO mind map? Oh yeah, I think you're right. Yeah. And when you look at that, it's like, holy cow, there's a lot, you know, going on in a CISO's brain to try to navigate everything.
And it's very difficult to do. And, you know, some people are really good at some things. Like, I consider myself still pretty good at incident response and leadership. I've taken a lot of training on leadership. And I think also my My, my 2 degrees in social sciences, I think, also helps with that as well.
Whereas, you know, Debbi, I know that, you know, you're strong in calling in National Guard when everything breaks loose at the state. You gotta have friends on speed dial, you know. Yeah.
And so, yeah, so with the networking, you know, I definitely have some, some some, you know, great lifelong friends that I've made in the industry. It's always fun to go to RSA. My— and I've been going to RSA for quite a few years now. And my rule that I have is that I, I won't make any lunch dates, breakfast dates, whatever, with anybody who's local with Denver until my calendar's all filled up with people who are located elsewhere in the US, because that's my only opportunity that I get to see those people in person. And I still, you know, see local people.
Debbi and I have and Rock, you know, we've all gone around and created all sorts of chaos at RSA together. And so that's fun to do. But yeah, it's just neat to like, you know, get together with folks and see them. And, you know, with that networking, that also— and I can't remember who pushed— I feel like somebody pushed me into this because I absolutely hated like public speaking. And, you know, to even do an interview like this, you know, prior to, I don't know, 2016, 2015, I would never even consider doing anything like this.
And, and I feel like somebody pushed me into it, and I don't know who. But it was, it was a great thing to do. My early presentations were rough. You know, I'm not the most eloquent speaker. And, you know, some people are really good at that.
I am not. I, but I do try to make sure that my presentations are very organized. And, you know, some of my presentations are pretty rough, and I'd be pretty embarrassed if I heard any recordings of those. And yeah, I feel like I've— yeah, but it's— I don't know, I think it's— I really enjoy doing it. I end up giving a few presentations a year, get interviewed on podcasts like this, and so it's nice to do that.
One of my best presentations, and it was my very first to be accepted at the RSA conference, was on incident response. And I remember I was working at Sports Authority at the time, and I get this call from the coordinator, you know, one of the main coordinators at RSA, and she's like, she's like, I remember she's saying, she's like, oh, I used to like live in Denver, and it's nice to be able to call a 303 number and And then, you know, she introduced who she was and she's like, yeah, we saw your submission for Instant Response. And instead of it being a 50-minute presentation, would you be interested in doing a learning lab, which was a 2-hour presentation? Oh my gosh. Yeah.
And I was just like, okay, sure. It's like, because I was wanting to get accepted at RSA and RSA is very difficult to get accepted to. And, and so I had given that presentation at RMISC And what's interesting is, is I stumbled across— this is kind of one of those aha moments I had where I was accepted to present at RMISC, and I saw I was the last speaking slot of the day, and I was just like, oh, it's like nobody wants to sit through another PowerPoint presentation at 4 o'clock of RMISC. And back then, there was a one-day conference, and And then the light bulb went on and I'm like, wait, you don't teach incident response by talking to people. You do it by, by doing it.
Yeah, you learn by doing it. And so I turned that presentation into basically a tabletop exercise with the audience. And yeah, so I did RMISC and then, you know, I did that RSA, you know, for the Learning Lab. I asked a good friend of mine that who I worked with at Lockheed Martin together, Bob Huber, who is the CISO at Tenable. I asked him to co-present with me, and so we did that learning lab, and several people attended.
I don't remember, Debbi, if you were able to attend that one or not. I was not. No, no. Yeah, I know there's some people who were there. Laz was there and a few people, and so it was really cool.
So, and that ended up leading Um, to me getting accepted then to give that same presentation at the RSA conference in Singapore, um, which is way cool. Amazing. Yeah, that's great. Um, so, you know, I'm trying to think about, um, we're talking about 25 years approximately that you've been in security. Um, so I would say, you know, what, what are you still passionate about?
Like, what still drives you, uh, to continue doing security? That's kind of a low question. Like, what drives you? That, like, yeah, keep shutting your fingers in the car door. You know, I've been doing it a long time and I just really enjoy it.
I enjoy the challenge.
You know, I like that I always have to keep learning. I do consider myself a lifelong learner. I really enjoy giving presentations. I've been fortunate and blessed that I've been able to present at 5 different RSA conferences and RMISC several times and other conferences. And, and even like this summer, someone reached— or this past summer, someone reached out to me to keynote the FutureCon conference in Denver, which was really cool.
That's the first time I did a keynote. And so I really enjoy that because I feel like over the 25 years, I've learned a lot. I've learned a lot of what not to do. And so, you know, I kind of think of like the demotivator posters. There's like my favorite one.
It's a picture of the sinking ship. Do you know which one I'm talking about? And it says maybe something to the effect of like, maybe the purpose of your life is to serve as a warning to others.
So, yeah, with me out there presenting at conferences and things of things that I've like mistakes I've made, it's like, hopefully that's a a warning to others to, you know, don't make the same mistakes. And I think we can all learn from each other. And, and then also, I really like leadership. I do like leading people. That motivates me.
I was able, in my last company, mentor a young lady who I just identify as having a lot of potential. And I mentored her for a year, and she ended up landing her first management role. And so I was, I was so pleased and so excited for her. And she's an amazing, you know, she's amazing in her job. And someday she's going to have, she's going to be a CISO or a CIO or CTO.
She's just, has that potential. And it's just through mentoring her and helping her to gain confidence in herself that she stepped out and like, yeah, I really want to be a leader. Yeah, that's awesome. And, you know, you, you really are a servant leader. And I I think, got a view into that when one of the presentations that I saw you present on was about Sports Authority closing down and how you really took a lot of time to think about how to prepare your people and how to take care of your people through that.
I think that was a, you know, that was a big event that I think, you know, folks had the privilege of learning from as well because you presented on that at I don't know if it was RMISC or RSA or both. Yeah, I did give that presentation at both. And it was a lot of fun to give that presentation because, oh my gosh, we ran into all sorts of stuff like the IPS technology we had, the maintenance expired on that. So we weren't getting any new signatures for it. And I'm like, oh, and what I was worried about was the opportunistic attackers coming after us, be like, oh, Sports Authority is going out of business.
So you're not paying attention. Attacks going on, you're just like focused on shutting down the company. And so I was concerned about that. And, but we were able to, fortunately before the bankruptcy, we'd actually upgraded the firewalls and Check Point firewalls. And they, the first year include the licensing include all the features.
And so we just turned on IPS on the firewall so that way we got the updated signatures. Yeah, but yeah, it was, it was interesting. I still keep in touch with a number of the people that I worked with at S4 Story because it was a real defining moment in all of our careers. And when that was happening, I was like, wow, how am I going to navigate this? And so I like did some searching and like, has anybody given a presentation on how to keep a company secure that's going out of business?
And I didn't find anything. Yeah. And then I'm like, oh, I need to start taking notes here because I'm the one who needs to give that presentation. Right, right. That's fascinating.
I'm sure that there are a lot of people who were in that situation that wish they'd had some guidance on that. I actually had a few people reach out to me after that presentation and, you know, ask me some questions because they're like, yeah, I think my company's going to start going through that. And so they wanted to you know, pick my brain on, on, on what they need to keep in mind. Yeah. Interesting.
So let's shift gears just a little bit. What's something interesting about you that most people wouldn't know about?
So this was definitely one of my— still one of my top 10 life experiences is many, many years ago. So this was in year 2000. After the world survived Y2K, that my brother-in-law was in the Navy and he retired a few years ago. He was career Navy and he was a nuclear engineer on a Trident submarine. So a Trident submarine is the biggest class of submarines that the US Navy has.
They carry up to, I think it's like 24 nuclear missiles. I mean, these are just massive machines. And so he was able to take me on what's called a Tiger Cruise. And so I got to go on— he was serving on the USS Ohio, which is the flagship. They often refer to that class of submarines as the Ohio class.
And so this is the flagship submarine, the USS Ohio. And I got to go on there for 2 days and 1 night with him on the Tiger Cruise. Wow. It was such a fascinating experience to see, you know, all the technology and And I was able to see everything in the front 1/3 of the— they call it a boat— the front 1/3 of the boat. The rear 2/3 is the nuclear reactor, and we weren't allowed to go there, but we can go everywhere else.
And so it was neat to see what the sonar people do. And they're like, oh yeah, we can identify all these different submarines or whatever just by sound.
Yeah, and they did some different demonstrations for us. The one is called angles and dangles. And so they'll do this like when they're— when they first go underway. And so they'll, you know, once they're in deep water, they'll start at just a few degrees and they'll like ascend and then they'll level off and then they'll descend and they keep working up to— I don't remember how many degrees, but it's quite steep. And really what it is, it's a shakedown.
To see if anything is loose and needs to be tied down before they're, you know, fully underway. That's amazing. Yeah, that's an experience that I think most people have not experienced, will never experience. It was way cool. And one of the stories that they were saying on the submarine was that they would oftentimes have different dignitaries and other people come on board, you know, maybe for a few hours or, you know, not for necessarily a Tiger Cruise like I was on.
And they said a story about Bill Gates was actually on the Ohio one time, because the Ohio was based out of Bangor, Washington. So on the west side of Puget Sound from Seattle is where it was based out of. And they said that they're talking about the computers on board and the Ohio, I think it was commissioned in like 1979 or somewhere around there. And so he was like asking about the computers that control, you know, targeting and firing the missiles, and they had 32K of memory. And they said that Bill Gates was just laughing hysterically over that.
And he was. Oh my gosh.
Um, so I know you love to travel, and I know that you took a really amazing trip, and I want to hear a little bit about that. So, um, what would you say was the favorite trip that you took thus Yeah, so it's something my wife and I really like to do. We've traveled a number of places, and my favorite so far is we went to Nepal, and we went there to trek on that— they call it the EBC, which is Everest Base Camp Trail. And it was amazing to just be in like these you know, surrounded by these huge mounds. So we, we ended up not making it to base camp.
We had some altitude sickness issues, and so we had to turn around. But we made it up to 14,600 feet. And there's a picture of my wife and I where we're standing there at 14,600, and you see these peaks just towering over us behind us, and they're like, you know, well over 20,000 feet. So there's like Lhotse and Emma Dablam, I think, were in the background. And so, yeah, so it was disappointing that we didn't make it to base camp, but we ended up chartering a helicopter when we were there and we were able to fly over base camp and we saw Everest.
We were the— so we went with a trekking company and there were several Sherpa guides that were part of that. And when I showed them the pictures of like how high we were with the helicopter, they're like, oh, you were high. I think they said we were as high as like Camp 3 or 4. So we were pretty high. But it was neat to see Everest in person.
And I highly encourage people who have a desire to, you know, go on a big adventure like that and go hiking to do it. The Nepalese people are amazing. I still keep in touch with 2 of the Sherpa guides that we had on that trip and several people who were were, um, I guess, you know, the tourists, you know, paying, paying people to, to go on the, on the trip. Um, you know, people from like Australia, Canada, US, um, UK, um, that were on that trip. And so it was a very bonding experience to just be able to experience something like that.
But it was just, yeah, it was amazing. That's so cool. Now, one of the things that I remember you telling me about was, um, your wife is a teacher and her students back home were very interested in your journey. So, um, tell us a little bit about How did you keep them informed? Yeah, so we, we buy a Garmin inReach device.
So it's, it's an SOS device. We do a lot of hiking in Colorado. And so we, we take that with us all the time because some of the places we go in Colorado, we might see one other person all day. And, and so what it does is it communicates with satellites and we have to pay like a monthly subscription for that. And Um, you know, like, like in Colorado, like if one of us were to get injured or something like that, you can, uh, basically send text messages through satellite, um, to be able to reach— Garmin has a, has a call center, and so they'll, they'll summon, um, emergency response, um, you know, here in Colorado, search and rescue, SAR, uh, to come rescue you and, and take care of, of you.
And so, so that's one aspect of it, but also another aspect is that you can, um, and we paid for like the, the full-blown like a subscription where we could send unlimited text messages through that with friends and family back home when we're on that trip. And another thing we were able to do is with our subscription is that we have like our own portal with Garmin. And so we were able to update that portal with different messages. And so the substitute who was teaching my wife's classes, she would get on there every day with the students so they could see that they could see where we're at because, you know, it's tracking us because, you know, I had it on all the time. So it's tracking us via GPS.
And so they could see where we're at. And then we were like sending messages of, you know, what we were doing and how the trip was going. So it was just really cool where we're literally on, on the other side, halfway, you know, around the world, because it's about a 12-hour time difference. And the reason why I say about a 12-hour time difference, because India and Nepal, their time is a little bit different than here. So it's, I think that Nepal is like 11 hours and 45 minutes ahead of us or something like that.
It's, it's like a 15-minute difference. It's, it's, it's kind of interesting how that is. But, uh, but to literally be on the other side of the world and have the technology where we can communicate with, with anyone, um, was just amazing. I thought it was super cool because I just thought it was fascinating that you were at Everest. And, um, I was one of those that was sort of following the journey too.
So I just thought your use of technology was awesome to keep people back home sort sort of feel like they were on your journey with you. Yeah, absolutely. It was a lot of fun to do that. Yeah. So, okay, one last topic and then we, we have to close.
But, um, I think something else that's very interesting is the volunteer work that you do. So talk a little bit about that. Yeah, so I currently volunteer with an organization called Team Rubicon. Um, I actually— and Debbi, I don't know if you knew this or not, um, how I actually found out about Team Rubicon. Do you know that story?
No. The co-founder of Team Rubicon actually gave a keynote at RSA a few years ago. Oh my goodness, I did not. Yeah. And so that's how I found out about them.
And so I started volunteering with them a little over a year ago. And so what Team Rubicon is, is it's an organization that was started by veterans. And it was started by this guy, Um, um, Jake Wood, he was the primary person who started it along with a few other people. And they were, um, retired, uh, I think all of them were retired Marines. And, um, when they, they saw like the situation in Haiti like unfolding, this was like when the, the hurricane hit Haiti.
Was it hurricane or earthquake? I can't remember which now. It might have been an earthquake. Um, and, uh, they're like, we gotta go do something. We have, we have all these skills and we can go help people.
And that's how Team Rubicon was, was born. So now it's an organization of, I think, somewhere around 120,000 volunteers. And it's, it is focused on veterans. But they also allow, they call those of us who are not veterans badass civilians. And so that is me.
And, and they're, and what's interesting is they, I'd never thought about this before, but when people join the military, they do that because they want to serve. And then they leave the military, but they still have a desire to serve. And Team Rubicon gives them that outlet to be able to serve. And so the service with Team Rubicon is responding to disasters, mostly. And, you know, they do a few other things too.
But that's, that's the primary mission of the organization. And so I have, I've, you know, since I've been involved with them for just a little over a year, I've been focused a lot on training. I grew up on a farm, in western Nebraska. So I have, you know, some good mechanical type skills like that. And Team Rubicon's like, yeah, we don't care.
You're going to be trained our way, which I can appreciate. I've actually, prior to Team Rubicon, had gone on a few disaster relief trips. I went on a trip— well, actually a couple trips to help after Hurricane Katrina hit. You know, it really hit Mississippi and Louisiana, and I went on a couple trips to help with that. That.
And then for those of you who've been in Colorado for a while, you know, we had the flooding in, in 2013, and I, I got connected with a, a family in Boulder that had mudslide go through their, um, through their property. And so I went and I ran a skid steer and a, and a mini excavator to help clear away all the mud and everything because, wow, you know, I grew up on a farm. It's like I can, I can, you know, still pretty much figure out how to operate any piece of equipment. And so, last summer, I went to Oregon for 10 days with Team Rubicon. We set up a Boy Scout camp up there and it was, they called it a DTC, which is a Disaster Training Camp.
And I've had to learn all these acronyms because they use a lot of military acronyms. And so, I know that FOB is Forward Operating Base, which they set up at every disaster. That's where the command and control staff operate out of. So, so I went there to take training and get certified in heavy equipment. And because of my farm background and experience operating equipment on other disasters, they, they advanced me to Level 1.
And so I was there to get certified on Level 2, so, which I did pass. And so that means I'm an independent operator, so I can go on any disaster with Team Rubicon, and I can operate the— and it's mostly compact track loaders, CTLs. So they're the skid steers with tracks on them is basically what they are. And so I can do anything with hauling it, performing maintenance on it, operating it in a safe manner that Team Rubicon feels comfortable with. So I do that.
And then I also— in Colorado, we have quite extensive chainsaw program. And so I've gone through some chainsaw training and I've been on several fire mitigation projects around Colorado where we go in and we help homeowners where we, you know, remove brush or trees or whatever. And so, I'm still at the beginning level of chainsaw certification. Growing up in Nebraska, we didn't have very many trees, so I don't have a lot of chainsaw experience coming into this. So, I'm still working on that.
But, you know, I just encourage everybody, like, find something that you're passionate about. And, you know, get yourself away from security because, you know, security is a— it's a tough job and it's a stressful job, and it's, it's nice to have another outlet. Yeah, that's, that's very good advice.
Well, Merlin, it's been so fun talking with you. You know, we— our time went by so fast, and I, I could definitely dig into more things, but, um, we are out of time. But thank you so much for being the guest this week, and And thanks again for sharing your time and your wisdom and your thoughts with us. Yeah, thanks, Debbi. It's been a real pleasure.
And thanks, Alex and Robb. Appreciate you allowing people to interview others in the community and help you out. So it's been a lot of fun. Yeah, our conversation with Debbi today. So, right.
Bye all.
Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.