All episodes

Doug Hudson, Security Business Executive

Apple Podcasts Spotify SoundCloud

Doug Hudson is our feature interview this week. News from American Ninja Warrior, Vinyl Media Pressing, Ball Aerospace, Techstars, Colorado Public Defender’s Office, Invictus Systems,Todyl, Red Canary, Ping Identity, zvelo and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript12066 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. To the future. Welcome to Colorado Equals Security. This is the newscast for episode 260.

That's 260, Alex. This is for March 2024. For the week of the 11th. Alex, we are, uh, we're, we're recording on a Friday night. Been a long week.

It's good to look forward to the weekend. What do, what do you have to say tonight? We're drinking whiskey. I mean, how can you get any better, Robb? It, it really doesn't get a lot better than that.

We're gonna talk about some security. We, we're gonna talk about some, uh, some ninja. Yes. Obstacle courses. I mean, who doesn't like ninjas?

So that's just a little, little teaser for later on in the, uh, in the episode. But first, You know, I don't know. Do we need to do all this housekeeping? How much of this matters? What should we skip?

Let's skip some of it. Slack channel, mailing list, rate us on podcast players, tell a friend, go to our Patreon and check out the website. And I just say thank you to our patrons. We appreciate you for those who help support the show. Agreed.

You know, it's not even about the money. I mean, it's about the money, but, but, but mostly we appreciate your support that you're, that you're, you're in this with us. Thanks to those, those folks. We appreciate you're willing to step up and show how much you care. We do appreciate that.

Yeah, that's it for that, for housekeeping. Let's talk about the, um, the new America Ninja Warrior Adventure Park that's opening in Denver. Yeah, so there, there is a new, uh, a new indoor adventure park that's opening that is modeled on the American Ninja Warrior courses. They are not nearly as hard. I think they're simplified a bit, uh, because like not all of us can do all those crazy things, but This is a— they're associated with the actual Ninja Warrior brand.

I know there are other similar courses like this around, but this is the, the first in, I think, in the US and— or no, second in the US, first in Colorado, actually associated with the Ninja Warrior brand. Yeah. Like you mentioned, there are some other off-brand obstacle courses. I don't mean to disparage them, but they are garbage compared to the actual branded official American Ninja Warrior. We'll expect our kickbacks, NBC.

Right. Because, and I'm sure NBC is like, God, if there was just a local security podcast that would talk about, talk about our obstacle course, we could finally be successful. But anyway, this is coming at, uh, uh, in Denver on, on Leetsdale. Um, it's, it's a, uh, 37,000 square foot space. And if you, they say that they, the, they're targeting folks, I think they said like ages 8 to 13.

Um, but lots of stuff for For any, any age. They even have like team building events if you and your, if your team wants to go do some falling off of foam things. It looks like a fun opportunity. I'm planning to get my kids over there. They both love American Ninja Warrior.

Awesome. There was one quote in here that I wanted to, to repeat. The 2028 Los Angeles Olympics is replacing equestrian riding with obstacle racing in the modern pentathlon event. So that 2 things there. One, I didn't realize that equestrian was in the modern pentathlon.

I didn't know there was a modern pentathlon, so I couldn't tell you what all the events in modern pentathlon were. And second, that's pretty frickin amazing that we no longer have to ride horses and get to do obstacle courses. Yeah, I think that's fantastic. I am looking forward to, to some Denver, you know, current 16-year-old, right, being ready in 4 years to go, to go win the gold in— where is it? 2028 going to be?

L.A. In L.A. Oh my gosh. Perfect. This is it. Someone from the, the Colorado Ninja Warrior facility will be in the Olympics.

All right. I guarantee it right now. Or your money back. Or your money back. All right.

So generally we only have one fluff story per, per episode, but we got a second fluff one because this was interesting. There is a, a, a new vinyl record printing plant in, in, in Denver. And it not only is it in Denver, it's actually in the heart of RiNo, Why would you put a manufacturing facility in the heart of RiNo? Uh, it's all about quality, Robb. So, uh, this company, uh, is, they, they made a factory there.

They can make, I think like 6 million records a year or something like that. Um, but they're part of like a, uh, boutique, uh, record making and record of the month club. So like, uh, they, you know, an artist might come to them and say, hey, I need to make you know, a limited run of vinyl for whatever, you know, for some single or something like that, and they can press it. But there's also a club that you can join and get records every month pressed from them. But they built this facility and the presses to make the highest quality vinyl records, not, not your regular run-of-the-mill crap.

Well, a couple things. So, so it's called Vinyl Media Pressing. That's the name of the company. And the club you can join is Vinyl Me Please. What What I, what I really enjoyed here is they're looking at it not as, hey, we're gonna do manufacturing off in some warehouse, you know, in the middle of the industrial district.

They're doing it direct— directly next to a, a club where people will be playing and they will, they will make records from those performances at the club. Man, what was the name of it? It was, shoot, lemme figure out the Mission Ballroom. So they're right next to the Mission Ballroom. So if you have a show there, you can make a record from it.

People can take that with them as like the, you know, their, their souvenir of that, their favorite show. They're, they're really changing it from, uh, an industrial, you know, back behind the curtains thing to a, you know, an experiential element. And that's, that's how you create value, right? For sure. There's also going to be a listening room, uh, upstairs in the factory.

And at some point in the not too distant future, they're going to also start offering tours so you could go and see how records are made. And, uh, I, I am looking forward to, to getting down there and taking a look at that. Do it, do a tour, do some listening. Realize that I can't tell the difference between high quality audio and poor quality audio, and that's probably because I'm mostly going deaf as an old man. Exactly.

All right, let's move on to the next story. There is no longer a company in Colorado called Ball Aerospace, Robb. Is that right? There's now a company called Space and Mission Systems, a subsidiary of BAE Systems. Well, you know, we we've talked about this story coming that.

That Ball Corp had sold off the Ball Aerospace company, but we didn't know what that was going to be called. We didn't know exactly what it looked like. Is this going to mean that we're losing the former Ball Aerospace business from Colorado? No. Oh, thank you.

Everyone is staying here. Nothing is changing, or very little is changing. This is, you know, a big move of BAE into the United States. They're, I believe, a British company. They are British.

And there's really not a whole lot of overlap between BAE's legacy businesses and the Ball Aerospace businesses. So a lot of synergies there. And they're gonna, they're gonna leave Ball Aerospace. Now, the new name, Intact— sorry, Space and Mission Systems, you know, rolls off the tongue— Intact here in Colorado. I think that there's 4 locations in Colorado where they have Space and Mission Systems offices now.

Yeah. Well, I mean, I think it's good news that it looks like they will get through this. I'm sure it won't be unscathed altogether. But with mostly the team intact, you know, for our security friends over there, hopefully this doesn't hurt them too much. But, you know, change is inevitable, right?

Speaking of change, Alex, we have a follow-up. Last month, we talked about the the fact that Foundry Group was not going to ever take another fund, although it was going to take them another decade to close. And hot on the heels of that announcement, I'd say that, you know, another announcement that's a little bit less— more upsetting came. What's this one? What's this next one?

Yeah, there have been some mixed feelings about it, but I would say more negative than positive. So Techstars, which was also founded by Brad Feld and some other folks. And obviously this is going back to Foundry Group, which Brad Feld, uh, also founded. They are moving their headquarters out of Colorado to New York City. And they're also, uh, stopping the, uh, Boulder version of Techstars.

Yeah. You know, there, there's all kinds of language in here about how it's, you know, not a big deal because virtual or whatever it is, but you know, it, it's definitely a hit. To the, to the Boulder and Colorado tech scene. Techstars was one of the, one of the jewels in our crown. Yep.

If you will. For sure. And, uh, and they're moving out. I, so that, that, that one bums me out. And this is happening, I think immediately it's happening this year.

It's pretty soon. Yeah. I don't remember exactly the date, but yeah. So that there was a new CEO of Techstars that took over not too long ago. Um, I'm gonna give you a guess where that CEO is located, Robb.

Um, Is it, is it New York? It is New York. What a coincidence. Yeah, I know. So CEO's in New York.

Hey, headquarters is going to go to New York. Um, there's also a former Boulder person who's quoted in this, uh, that's a veteran of Techstars who also happens to live in New York now, who said this is a great move and it's something that they should do. Hey, yeah, big surprise. Um, basically everybody else didn't like it, uh, was sad that they're leaving and You know, I guess it's understandable, but it still is sad. I mean, it just depends on the perspective.

It may be the right thing for Techstars, but if I'm going to be completely candid, Alex, which, you know, I like to be, I don't really care that much about the best thing for Techstars, right? Yeah. I liked Techstars as a partner for Colorado. And as you know, it was— I felt like it was built to help support the Colorado tech ecosystem. And of course, you know, give, give some prestige here.

I think we're going to lose some of that. Yeah. They did note that there are a couple Techstars incubators that are closing, Boulder being one of them, Seattle actually being another one, which is also surprising to me. And I don't know if they mentioned any others, but at least those 2. They did also note that Techstars will still be a headlining sponsor of Boulder Startup Week.

So I don't know, some consolation, I guess. I guess that's something for someone. Yep, exactly. All right, well, we have our next story is a Denver Post story. I think we have 2 Denver Post stories this week, which is— I think we do.

Which is rare. I didn't know they actually did writing anymore. Is that a shot? Most of it is AP stories these days. A little frisky on a Friday night.

But this one is around some trends that the Denver Post columnist found where Colorado, even though we are the 2nd most highly educated state in the union, we are actually one of the most impacted against fraudulent activities, specifically the kind of stuff, you know, the social engineering where folks, you know, text you and try and get you to send them money, but the second most impacted by that? I think from our work in enterprise, I think we can say it doesn't matter how smart you are. Everyone can fall for a phishing scam. Maybe more educated people won't fall for you know, romance scams or other things like that. But who's to say even there?

So I think, I think it's pretty fair to say people are going to try and trick you one way or the other. And it doesn't really matter how educated you are, whether you're going to fall for it or not. The other part is some of this was based on losses. And Colorado has a higher median income than a lot of places. So there's more money to go after.

So it's also not surprising that more money was lost here. Uh, to, to people in Colorado. Yeah. I mean, part of this is how much you're targeted, right? If, if you're going after the, the, the higher income states, you're, you're more likely to be hit.

That, that makes perfect sense. But Alex, you, you mentioned that, you know, even highly educated people might, might fall. Would you fall for a scam? Uh, I don't know. It depends on, uh, what scam do you think you'd— what's in it for me?

What scam do you think you'd be most likely to fall for? Uh, I mean, If, uh, if a distant relative was going to give me some money, I'd be down for that, Robb. Yeah, you know, I, you know, obviously having run security programs for, uh, kind of a long time now, um, I, I, I put a filter on as I see an email, and, and I'm, I'm very unlikely to click an email that I, that I don't have a lot of confidence in. Um, but the other day I got one that it, it wasn't a scam, but after I clicked the link, I'm like, oh my God, it could have been a scam. Yeah.

And, and I'm like, I could have just fallen for a scam. And I was actually quite nervous that I got phished by my own team, but I didn't. I did okay. Um, I do have to say, Robb, I did click on one phishing test phishing email from my own team. Uh, I don't remember what it was.

Once in 2 years, it was on a mobile device, which I think makes it harder. For shame. I know. For shame. For shame.

Yep. Yeah. So some interesting stats in here. They say that in 2023, Colorado residents filed 46,000 fraud reports, having that tallied a loss of $115 million or an average of about $2,500 a person per loss. You know, 46,000 across the state, that, that does seem like a lot.

You know, that's— I don't know what percentage of the state that is, 1%-ish. It's a lot. It's a lot of people. I wonder, you know, they're talking about, you know, how educated the population is and things like that is based on who would fall for things. I wonder if there's any correlation between education and the willingness to report.

Hmm. Interesting. Because we all know that there's a large number of these scams that don't get reported. Right. Are there any variables in there that would cause one population group over another to report more often than another?

So I bet you, so I, I re— I, I'm maybe a year or so into getting into Reddit, maybe a couple years into Reddit. And I recently got into a subreddit called Fish— oh, what's it called? Scambait, something like that. Where basically the whole purpose is people post screenshots of them engaging with spammers. Yeah.

And all you gotta do is spend 5 minutes a week on this subreddit and you'll know all of the scams that exist. And so if, if someone tries to get me with a relationship one, I'm, I'm gonna have some fun. I'm gonna take them for a ride and post it on Reddit. And I'm gonna post it on Reddit. And I actually think that that might be a better training than whatever, like, here's how you identify it.

Just, yeah, just go look at some people having fun with those scammers. Now that's probably true. I look forward to that coming to an awareness campaign soon. All right. Did you know that there was a cyber attack that took down the entire IT system for the Colorado Public Defender's Office?

I did, Robb, even before I read this article. But after reading it, it made me sad. Is this because it impacted one of your cases?

It did not.

Robb, I pay for my own attorneys. Thank you. No public defenders for me. Anyway, no, it is very sad because obviously the public defenders are a service to the community. They, they help the folks that can't afford to have an attorney.

And so when, when they're impacted, it impacts the, the folks that are, that are using them. You know, cases get pushed back and rescheduled. I mean, if someone is waiting for a hearing to be let out of jail, for example, right, they're gonna, they might have to stay in jail longer because this cyberattack happened and the public defender's office can't operate. I mean, I, I don't know for sure, but I imagine that our justice system is not you know, overwhelmed with excess capacity that they can take. Right.

You know, oh, no problem. We'll, we'll just reschedule those cases any old time. Right. Right. Great.

We'll reschedule this. It's gonna be 6 months from now. Thanks. Yeah. See you later.

And, you know, the, the attorneys are obviously super inconvenienced, the, the judges, everyone. Right? It's the, the defendants, of course, above all. Yeah. So, so what do we know here?

Do we know anything about this attack? I don't believe it has been stated what the attack was, but based on What we know, it appears to be a ransomware attack. Many of the systems there were taken offline. I think many precautionarily were taken offline, again, sort of indicating ransomware attack. The, the public defenders and folks in the office were locked out of their computers, they were not able to use them.

It seems like administratively, not because of the attack itself, but Uh, you know, sort of proactively to make sure that no, uh, additional problems happened. But, uh, but yes, very sad. It sounds like things have started to come back online, but I think it's gonna be a long road, uh, just like any sort of, uh, attack like this. So hopefully they get back up soon and we can resume our, our court activities and go on with our lives. Yeah, I certainly appreciate the public defenders.

I, I don't, I don't think it's an easy job. I think it's made all the, all the tougher based on this. They were— they pointed out several times in the article that this did not affect the wider court system, just the public defender's office. Yeah, fair enough. All right, Alex, you know, we, we see these code names for, for projects that the Colorado Economic Stimulus Department, whatever they're called, are working on.

And we often don't know what this, what this project coordinates with. So what we just learned here in this new— this next article So Project Stronghold has recently been named as the actual company. It's called Invictus International Consulting, which is a cybersecurity firm. I mean, Invictus almost sounds like a code name in itself. Yeah, it does.

We should, we should have a Project Invictus here coming up pretty soon. Yeah, which is actually for the Stronghold cybersecurity company. It actually works both ways, doesn't it? So yes, this is a Virginia-based cybersecurity firm. They are moving offices to Colorado and set to bring 130 jobs to Colorado.

Uh, sounds like it's going to be throughout the, the Front Range, some in Colorado Springs, maybe some other places. Mostly they're going to put the headquarters in the Springs, right? And they, they say 65 to 130 people with an approximate salary of $166,000 a year. You know, when I see this range, 66 to 130 over the next 5 to 10 years, you know, you're talking about if a few hires this first year, but it's cool to have a new security company come get headquartered here. They're choosing to be in the Springs, which as I read through this, it really looks like it makes a lot of sense.

They're, they're government focused. There's a DOD emphasis for the services they offer. That's the place for them to be. Yeah, it totally makes sense. Excited to have another company here in town and look forward to seeing the folks from Invictus and, and meeting people and having another cool company in Colorado.

Maybe, maybe we'll get the Invictus folks on the podcast when they get out here. If anyone knows the Invictus folks, yeah, hook us up. Send them our way. All right. Next story.

Another positive story. Another Denver cybersecurity startup has announced a raise, this one being $50 million to double headcount and open new offices internationally. And so the company is Todyl, T-O-D-Y-L. You know, we had John Nealon, the CEO, excuse me, of Total on the podcast. It's been a few years. It has been a few years.

They moved from their headquarters from New York to Colorado. And that's what we talked about right when they got here. We did an interview. Yeah. So I had a chance to meet with John, their CEO, back, back then.

They, I think at the time, were mostly going to market as an MDR for SMBs, specifically through the the managed security provider— managed IT provider, excuse me, the MSP channel. They have really broadened out their offering as a part of this. They're really looking to be that one-stop shop for security services. So yes, they're going to do MDR, but they're also doing Zero Trust Network Access, or SASE. They're also doing endpoint management and identity management, and they're even doing like GRC tool type capabilities.

They're, they're really looking to be for those small companies, you know, all you need from a security provider. That's pretty cool. Um, and, uh, it sounds like they're going to be doing some good stuff. They're going to use this raise to, I believe, double the, the headcount that they have. Uh, they're also looking to expand, uh, multiple offices, uh, more places in the US and potentially overseas as well.

A couple interesting facts. You mentioned doubling. They will be doubling to 150, so there must be about 75 today. Um, one of the nuances that Total has that I don't hear about a lot right now is that they are asking all of their folks to be in the office 5 days a week. So they're, they're kind of doubling down on the in-office culture, which, you know, you and I have worked remote mostly since COVID I, I really miss being with people, you know, 5 days a week's a lot, but, but man, I, I think this would be a really good place to get a lot of support and be surrounded by coworkers.

It could be a good fit for a lot of folks. Yeah, um, seems like they're doing good stuff, good product, and, uh, we'll see how it goes there. Speaking of local MDRs, you may have heard of another MDR company in town called Red Canary. Uh, in this last month, they officially announced that they are— they have MDR support for all 3 of the major cloud providers. They, they obviously, they've been in AWS for a long time, and I think they've been in Azure for a while too, but they now support Google Compute, and they have support for all 3 of those major cloud providers now.

Yeah, they do. They also mentioned some other things that they've got going on in their product set here. They're now bringing in data from CSPM or CNAPP, depending on which acronym you choose to use, services like Wiz and Lacework. Those are 2 that they're supporting.

Also moving into things like Kubernetes and other things like that with their Linux EDR. So more and more stuff that Red Canary can do for you. Yeah, I think, you know, they're— they have— they historically were incredibly strong. They are incredibly strong on endpoint, but they're broadening out that support to, to be more of the, hey, we do great on endpoint, but hey, we could look across your entire IT stack. And it's good stuff to see happening.

And I know you and I both have got a chance to look pretty closely at their stuff, and, and mostly I'm pretty happy with it. Yeah, Red Canary is great. All right, moving on. Uh, we have a blog by Ping Identity talking about MFA and is it enough to stop adversary-in-the-middle attacks. Robb, is it?

Well, the answer is no, but there— I mean, there's a lot of things you can do to fix it, and, you know, believe it or not, Ping helps with those things, right? So it's a shock. I, I think as you look through this, yes, of course there's, there's always a sales pitch, buried in most of these blog posts. But, but I like the fact that they talk through what kind of MFA is, is vulnerable to what kind of attacks, and then what are the defenses you can put in place. Yep.

They also mentioned things like, uh, passwordless, you know, passkeys, other things like that that you can do that could stop attacks like this because there's no password. And, and if you go roll out FIDO2, that is the, I think, the only man-in-the-middle-proof MFA, really. There's other ones that can reduce the risk, but I think FIDO2 or WebAuthn is, is really the way to go. So if you haven't started looking into that yet, it's probably a good idea. Probably should do it.

All right, we've got one more story. Uh, this one is from Svelo, uh, and this is about malicious AI, the rise of the dark LLMs. Yeah, you know, we, we We don't have a ton of Zvilo blogs in the podcast, but this one I thought was actually really interesting. We've talked about the possibility of AI being used by bad guys to attack our environments for quite a while. Well, this blog post actually goes into specific examples, not just of hypothetical things they could do, but here are things that are actually happening and here are the names of the services that people, that attackers are subscribing to to get those things.

Yeah, it's pretty interesting. They have a number that they talk about here and as you mentioned, okay, what is it that this particular GPT or AI service does, how it helps the bad guys, and, you know, what you should be looking out for? Yeah. So, so just a few names. I, I think they're interesting.

There's XXXGPT, which is not pornography. It's, it's just a kind of a Red Hat type of a, type of a GPT that's used for remote access Trojans, cryptors, and malware creation. There's a service called WolfGPT, also used for creating malware and other attacker things. There's WormGPT, which I think the name gives it away, right? For worms.

And then there's Dark Bard, which has got to be the best name on here, right? This is the evil twin of Google's Bard AI. It's defined by its real-time processing of information from the clear web enhancing its adaptability. So since Google just rebranded Bard to Gemini, are they gonna have to rebrand also to Dark Gemini? I can't remember to call it Gemini anyway.

So it's working for me for them to call it Dark Bard. Alright. Alright. No. Interesting blog, though.

Interesting to see the, the evil and illicit applications that people are using LLMs for. Very judgmental. I am judgmental. Hey, before we jump over to events, uh, just wanted to circle up on an event from last month. We talked about the, the Colorado Gives Back event where we were partnering with Volunteers of America for a homeless shelter service.

That did happen at the end of February on the 25th. Huge thanks to Ben Fellows and Chris Abbey who, who really spearheaded this. And then big thanks to the 20-ish volunteers who showed up and, and, and represented the security community there with, with Volunteers of America. I love the fact that we've got a community who wants to get involved. We're planning to continue doing quarterly giveback events.

You know, that'll be— news will be coming up here in a couple months for the next one. We hope you'll be there. We're going to try and be there. We'd love to, love to see y'all giving back. Yeah, and there was a LinkedIn post with some pictures, so if you want to see what people were doing there and Um, you know, go out and like it and make cool comments.

Go for it. Uh, you should be able to find it out there. All right, let's jump over to our calendar of events. We do have a, a calendar out on the website. Alex, as we look through the events here, they're not all in order on our Trello, so this will be fun.

Oh, interesting. Um, somebody, somebody didn't do their job. Oh, that could be, that could be me. Um, but we'll start off on the 13th of March where we have the ISSA Denver chapter, um, having their chapter meeting, which is in the DTC in the afternoon, and then in the evening downtown, we've got Mike Pedrick talking about Better Together: Why Leaders Make Good Privacy Champions. All right, um, I think that I have the next one.

Uh, CSA Colorado is doing their March meeting, A Pentester's Guide to API Security, on 3/19. Well done. The next day on the 20th, ISSA Denver has their Women in Security, uh, meeting, but this one is— this one's awesome. This is a, uh, really a celebration that we should be talking about here anyway. It's a— it's an evening with Gail Corey.

Gail, our long-term friend who just retired, I think it's this week or last week. She's been the last several years the CISO for F5 Networks. She had a long career at Oracle, JB Edwards. Congratulations to Gail. If you can make it out there and hear her talk, I think you'd really appreciate that.

Yeah, Gail is wonderful. You'll have a good time and we'll miss her in the industry. All right. Next, ISACA Denver is doing their March chapter meeting, the Human Factors of Security, Compliance, and Risk Management on the 21st of March. Did I get that one right?

I think you did. All right. On the 27th, we have the ISC² Pikes Peak having their March meeting. On the 27th through the 29th, ISSA Colorado Springs is doing their Cyber Focus Week. Uh, we got 2 more.

On the 28th, the Let's Talk Software Security group is doing Application Security Posture Management: Rebrand or Revolution? Oh yeah, I say revolution, right? Or maybe not. Anyway, uh, and the last one, uh, we have a vendor event here. Red Canary is doing their Red Canary Live event on April 6th.

So if you, uh, you know, we talked about the blog post earlier, if you want to go learn about Red Canary This is at Mile High Stadium, I believe. So check out the link there for more details. And if you come, I will, I will be speaking. If you bring whatever you want me to sign, I may sign it. If it's some kind of contract, I probably won't.

But, but I'll be there. Awesome. Good to know. Hey, let's jump over to jobs. Speaking of, of Pax 8, which is where I work, I'm hiring a couple of security folks over there, looking to hire a senior director of security operations.

For this role, I'm looking for someone who is a Um, experienced operational leader, incident response, um, SecOp operational processes, incident— or I said incident response— threat intelligence. That's the other element. So those are the 3 big things there. Second role within my team is a trust and security program operations program manager. This is someone who's going to help us really keep the department running on, on the rails, help with planning, help with tracking of metrics, make sure we're working well across departments.

Awesome. I was the one that found jobs for, for this podcast. And so we have 2 jobs from Bank of America. I put these both in here, one because it sounds cool and the other one because it sounds horrible. So the first one from Bank of America is Senior Cybercrime Specialist.

That sounds pretty cool. The second one is Information Security Mainframe Security Engineering Team Manager. It's gotta be the longest title of the week. It's gotta be the longest also, like, and the longest lasting role in the industry. This is for the, all of the, uh, the veterans out there who know mainframe security.

Um, this next company, I, I'm guessing it's called Colas. Uh, it's C-O-L-A-S. They are hiring an information security manager. Uh, this is a cool one. NREL is looking for a chief cybersecurity engineer.

Sounds really awesome. You can go help engineer the future. CommonSpirit Health is hiring a cybersecurity senior engineer penetration tester. Pulte Mortgage, a place where both you and I have worked previously, is looking for a manager of information security operations. So if you're looking for a great culture, a great leadership team, Pulte is just a fantastic place to work.

Agreed. Maxar is hiring a cybersecurity vulnerability management analyst. And finally, one close to my heart. Jefferson County is looking for a cybersecurity analyst too. Close to your heart and close to your home.

Exactly. I like it. Well, that is it for the news, Alex. We do have an interview, though. What do we got coming up?

We do. I did an interview this month, believe it or not, with Doug Hudson. Doug is a veteran security person. He's been at many places— Accenture, Coalfire, most recently at Orca Security. He is kind of taking a break right now, but, uh, Doug and I talked about his career and, and what's been going on.

I love it. Well, thank you for talking to Doug. Doug, thanks for joining us. Um, I've known Doug for years and I'm looking forward to hearing— did you guys talk about fishing at all? Uh, we didn't really talk about fishing.

I don't know how you got through a conversation without Doug— with Doug without fish— talk about fishing. That's, that's something special. That is something special. All right, well, that's it. We'll talk to you all soon.

Thanks, thanks for joining us. Thanks, Robb. This is Josh Ryan, network manager for Ultra Petroleum. Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security.

This is Alex Wood, and I am doing our feature interview today. Got a special guest, Doug Hudson. Welcome, Doug. Well, thank you. Glad to be here.

Good to see you. Great to be seen. Always good to catch up with you. Doug, you are a security executive, you know, kind of taking a break right now in between things. Is that how you'd describe your current role?

Yeah, I think that's a really good description. I've been in cyber for 20-plus years now. Yeah, just coming off a stint with Orca Security and trying to chart out what I'm going to do when I grow up. Well, when you figure it out, let me know, because then I'll figure out what I want to do when I grow up.

As you know, we like to center these interviews around the person and try and get to know you and what you do. And I know you've been around Colorado and the Colorado security community for a long time. So how did you start? How did you get into security? Oh, good question.

So I got into security 20-ish years ago. I was running my own telecom company, reselling various services for the providers. I was in the process of building out data center space for an IP space for an old company called MySpace. I also had a client that came to me, a large international automotive parts manufacturer that said they wanted a risk assessment. Well, back in 2001, 2002-ish, a risk assessment was a penetration test.

So as I'm, you know, I was fortunate enough working with MySpace that he gave me a free account. And on the other hand, I watched this pen test firm go through this network and own the network in something like 7 minutes. Yeah, so on one hand, I had what the general public was putting out online for public consumption, which is a nice way to say people were oversharing their information. Yeah. And on the other hand, this— what should have been a large, more secure organization not be secure.

And at that point, I said, dude, I'm out. It took me about 18 to 24 months to sell my business and And I went from there. I got a Master's of Cybersecurity in under 12 months at DU and started a career at Accenture where I spent basically 7 years there in their cybersecurity consulting practice. For those that know Accenture, it's a highly matrixed organization. I'm not going to go through which verticals and horizontals.

And then I left there to go to Coalfire where I started their strategy, privacy, and risk practice and grew that to 15+ consultants and X number of millions of dollars. And then I was given an opportunity to go to Orca Security to really work on building out their partner program as it relates to strategic— or system integrators, rather. And within maybe a week or two, I could spell FedRAMP, and I understood the government space better than the folks there. So I immediately transitioned into the VP of Public Sector, and I built their— both their separate FedRAMP platform as well as their entire public sector organization until January of this year, and have the opportunity to identify new opportunities, we'll just say. Nice.

Yeah, so, well, first I want to dig back a little bit, like Is MySpace still online? Like, does it still exist out there? I haven't checked in a while. Every once in a while it comes up and then, you know, people would go, oh yeah, yeah, I still have my MySpace profile out there. All I can say is out of sight, out of mind, right?

So I have no idea, you know. I mean, you know, obviously Facebook took over for MySpace, right? And, you know, I think the fascinating thing for me without you know, throwing shade, I guess, is probably one way to put it. You still see a lot of people oversharing with Facebook as they do or did with MySpace. So I still think there's that opportunity, if you will, to better educate people on not oversharing all their stuff.

Yeah. Yeah. I'm also curious, you know, you're— so your first real cyber job Your first security job. I've been using the C word a lot more lately and it's, I don't like it, but it's, I'm finally giving in anyway. The, what was with Accenture, which is a huge consulting company.

And then you went to Coalfire, which I think at the time was probably a much smaller consulting company. They're a much bigger consulting company today. I'm just, I'm curious on your, your thoughts about the, the contrast there and, you know, working in consulting in different environments and that sort of thing. So I'll slightly correct you. So while I was doing the master's program at DU, I was helping out some local firms, okay, on their cyber path.

So you hate the C word, right? And what I mean by that is, you know, Chris Roberts locally. So I was helping him at the time build One World Labs. We can peel that onion at some point if you want. But I still love Chris.

Great dude. All that good stuff. So I was doing some of that sort of work to kind of fill in both my time. And, you know, I have a little bit of OCD, so I got to be doing something. The interesting thing about my experience at Accenture was really— well, I'll back up a little bit.

I looked at Accenture, I looked at EY, I looked at Deloitte. I was educated by a partner at EY to do the Accenture thing. The reason he said that is they're some of the smartest people. No offense to EY people, But they're some of the smartest people there and they do the hardest things. So my career at Accenture was pretty, pretty nuanced where I went from, we'll say, breach to breach to breach, and I got tired of working breaches at Accenture.

So I went to the gentleman that ran North American Security and said, I want to do something that's not breachy. So I got signed up to the California Health Care Exchange, which is a different, a different beast, a whole different ballgame. But what I realized working at Accenture are a couple things. There are very, very, very bright people there, and it was a complete eye-opener that I could even be considered to be in that environment. Yeah.

And You know, I don't— you know, I'm pretty humble on some things. To, to be able to accomplish and get some of the accolades that I got at Accenture was remarkable. And I still look back at it like, what? One, why did I ever leave? But that begs your question on how the heck do you end up at Coalfire?

So I had a friend that knew Rick Dakin, and Rick was looking to expand beyond just the compliance business. It was at a time where at Accenture, it was the week after Thanksgiving. This is 2014-ish. And I went to my hotel, which is a Marriott. I don't know if you guys do sponsors or anything like that, but it was a Marriott property.

And when I got to my room, there was a basket in the room with 2 bottles of wine, a really nice box of chocolates, and a whole bunch of like cheese and crackers and crab. Uh, congratulations on your 50th stay for the year. So I hadn't even made it all the way through a year, and I had stayed at a Marriott property 50 times. And I'm not one of those guys that checks in Monday, checks out Monday night, checks in Tuesday, right? Or whatever that is.

I don't play the game. I check in when I check in, and I check out when I check out. So that, that was an eye-opener for me to say what am I doing? You know, my children were young, like I am living out of a suitcase, and honestly there's nothing more depressing than going to your hotel room and having 2 bottles of wine that you can't drink with anybody but yourself. So I had mentioned that to one of my colleagues and he said, hey, you got to meet Rick, you got to meet these guys, they're looking to expand beyond compliance.

When I say Rick, those guys, the Coalfire guys. So I had a very interesting conversation. It was one of the more entertaining conversations I've ever had because I'd never seen somebody so jacked up applesauce about doing this risk strategy thing, right? That at the lunch restaurant that we were talking about this, literally took the cloth napkin, took a pen out, and started drawing out diagrams and what he saw as the organization. So, you know, that gave me a really neat opportunity to both be a practitioner and as well as a builder of a practice.

So, you know, I don't know if that answers your question. If you get more into the specifics of like smart people here, smart people there, that's a different probably onion to peel. Yeah, no, that's a great answer. And I think moving on from that, I'm curious about your time at Coalfire. I mean, I'd love to hear how things went there and interesting tidbits or stories, but also Like, you know, I feel like Coalfire is, um, it's one of the, the Colorado sort of success stories for, for startups, but I think it's also a little bit, um, like undersung, right?

Like, they're— they are, you know, one of the major, uh, compliance and consultant companies that's out there now. Um, it obviously started here, uh, based here, but, uh, you know, you don't hear about them, you know, kind of talked about in the same breath as an Optiv, a Ping Identity, a, you know, other, you know, startups that, that came out of Colorado? So I think to answer that question is kind of an interesting piece, right? So when I joined Coalfire, I want to say, I want to say I was employee like 100 and change, right? 183 comes Right, but it's like 10 years ago now.

Yeah, so I was, I was under— I was employee under 200, and to see it grow and change was really very, very fascinating.

And part of what I was doing helped precipitate some of that change. I'm not gonna say everything, but watching the company grow from being able to sit in Rick's office, or when Rick passed be able to sit with Larry Jones and talk strategy of the business and just how to expand the business to where it's at today, where there's kind of a little bit more layered management. I think was one of the big things is, you know, it was very easy on— in some regards to go do what needed to be done, you know. And then over time, you know, one, as we built the practice, the strategy, privacy, and risk practice, as they added an ISO practice, as they expanded their HIPAA practice— again, more of the compliance piece— I wouldn't say it became more bureaucratic, but there was definitely more bureaucracy involved. So for one, that was probably a really big change as they expanded.

To your broader point of, you know, they're a really big success story here in Colorado, or should be a much bigger success story here in Colorado. That I really agree with. You know, what they've been able to do and how they've been able to kind of transition the market to capture new, uh, I'll call it regulatory compliance stuff, um, and see that trend kind of before it happens has been really cool to watch. And most recently is really on their federal side. You know, as PCI as an example, has become much more commonplace and much more commoditized.

They've been able to pivot and really take advantage of the initiatives surrounding FedRAMP. Now they're pivoting to doing some CMMC stuff. Obviously, I still know people there. Sure. But watching that and just seeing some of that vision that Rick started is still there.

I think what you're seeing now is that next level growth initiative with the new hiring of Tom— if I mess his last name up, I think it's Galicia— and where they're looking to take the business and how they're looking to grow the business is actually really cool. And it'd be nice if more people kind of were aware. Yeah, for sure.

So I think it's interesting that, you know, your first few big roles were basically consulting. Or running consulting practices or things like that. And then most recently you were at Orca, which is a pure product company in a, I would say, very different space than you had been previously. I'm curious why you ended up there and maybe how you ended up there too. So I'll answer the how in one respect.

For a long time in my cyber career, I've been beating the cloud with a giant stick.

People look at the cloud, and even today to a certain degree, and now we've gotten into various SaaS and IaaS and IaC and all this other sort of fun stuff.

The view of a lot of business owners, leaders, security leaders, whatever, is, well, if I just pass this off to the SaaS then they have to worry about all the security, right? It's not really accurate, right? It may be, it may be somewhat true, but there's still stuff that foundationally you need to do from security. So I had a friend that went to Orca to run their sales organization, and in the process of doing that and doing the onboarding and whatever, said, hey, would you look at this? And I looked at the Orca product and it was doing something that nobody else was doing, and it was doing it in a way that was, as I'll put it, legit.

The amount of data they're able to consume, and then the use cases and the perspectives that they're able to provide a practitioner, is even today, it's still, it's still an awesome, unbelievable tool, right? Especially if you're a practitioner, you can get right into your use case very very specifically, very fast. Me as a security wonk looked at that and said, this is a really, really excellent tool. So I said to my buddy, hey, this is good, you should go get the job. He got the job and he says, what's it going to take for you to come over here?

And at the time, I, you know, at the time I was at ColdFire, I was running a practice, things were well. Um, he kind of kept pressing me, and I finally, just to make him shut up, I said, give me an offer I can't refuse. So he gave me an offer I couldn't refuse. There you go. So, you know, that, that precipitated joining.

I joined really to work on— because it's what I understand really well— is the consulting motion and how an Accenture or Deloitte or X or Y will consume a product, use a product, how they build value on it, how they can build practice, you know, practice and offerings around it to be able to support their consulting services delivery. So that's where I was brought into Orca. Within the first week or so, talking to some folks, they were saying, oh, you know, didn't realize you were from Coalfire. We're struggling with this FedRAMP thing. I said, well, I can spell FedRAMP and I know it very well, and here's why you— why an Orca would want to look at FedRAMP, you know.

And they said, okay, can you do this for us? Sure, right? And, you know, the, the rest, they say, is kind of history. Yeah, I'm curious how that went. You know, you went on one side from, I'm assuming, telling people what they should do to do FedRAMP, maybe auditing them on how they are preparing for doing FedRAMP, to then all of a sudden being put in charge of actually doing it and, you know, putting it in place and that kind of stuff.

How is that going from the more consulting side of it to the implementation of what needs to get done for FedRAMP? For me, it was an easy transition. Position because one, I understood the problems that an organization faces when going to FedRAMP.

Take your normal organization that wants to do FedRAMP. The first thing they have to realize is the oh crap moment. The oh crap moment is really, do we do this or not? Then you got to start to unpack that. How much does it cost?

What do we have to invest? What's the business value? For a lot of organizations, the business value is the US federal government because they're the largest employer and blah, blah, blah. We can go down that path, whatever, but there's a ton of available opportunity within that, and especially with the various memorandums, the various initiatives that the federal government is pushing down, that people want a bite of that federal apple. How do you get that?

Well, the federal government is encouraging all the agencies. Agencies to go to the cloud, and they're looking to go meet their partners and etc. in the cloud. Well, they have to do it securely. So one, understanding that ecosystem and understanding that one, it's not just doing business with the federal government.

There's a large commercial component that you have to take into consideration. So kind of understanding that, that play of it's going to take a long time to get federal revenue. Your quicker time to revenue is commercial is big when you're selling it to the executives. Then you take it down and you say, okay, how the heck do I get— for Orca, they're an Israeli company— how do I get an Israeli company into a place where they can successfully get through a FedRAMP audit? Again, that insight is key to understand what are the FedRAMP requirements, how do they work, how do we need to communicate those, how do we build the policies, the procedures, What does the network need to look like?

Those sorts of things that would come naturally from consulting an organization to say, this is how you do it, to be able to coach that within the organization. So it was, for me, it was kind of an easy transition. You know, probably the most difficult piece in that was managing expectations. You know, Orca was on path to get FedRAMP authorized from in under 2 years, which in the FedRAMP environment is just unheard of. And, you know, how does that happen?

Well, one, I think I was a big part of it. I think, 2, understanding how you need to interact both with your auditor, your advisor, how you need to build things, how you need to interact with the FedRAMP PMO, those sorts of things that come naturally from the consulting side just helps when you start to do that and layer in those expectations, and then you flow that down into building the org. How, you know, how do we build marketing? What does that need to look like? Who needs to be involved?

What does a sales organization look like? How are we going to go to market and actually talk to people about Orca's FedRAMP environment? Then you take it, okay, what is the partner ecosystem? How do you develop a partner ecosystem when you know the big boy on the block is Carahsoft? What does that mean to you?

How do you interact with Carahsoft? How do you leverage say the AWS or Azure Marketplace. So bringing all that together again partly was easy, or not as difficult, I should say. It wasn't easy. It's never easy.

Part of that was, was less difficult just because of the consulting mentality of, hey, look, here's a problem. Let's approach it very logically. I've got the experience, whether it be at the technical level or at the operational level to be able to bring those together so that you can manage expectations, you can get the right people in the right places, you can have the right conversations, you can do the right things to set somebody up for success. Sorry for the long-winded answer. That's what we're here for.

Um, no, that's great. And, uh, yeah, I know FedRAMP is no small feat, so, uh, it's amazing that you could get that done so quickly. Thank you. The— you're no longer at Orca. What, what are you doing now, Doug?

What's in your future? Interesting question. So at the— I'll give you the consulting answer. It depends, right? Waiting for somebody to make you an offer you can't refuse?

Is that the— to a certain degree. I've been very fortunate that I've been able to be in places to have the success that I've had. Um, you know, so it's what do I want to do to try and replicate new successes? So, you know, one of the things that I'm looking into, and I'm working with a firm right now to help them raise capital, um, it's in the compliance data space. We can get in if you want to be, you know, pull the string on that, we can.

But it's in the compliance data space, really working with the defense industrial base, and then trying to figure out how to bridge into the commercial space. So that's one of the things that, that I'm pursuing right now and helping build the pitch deck and what is the business going to look like and how are you gonna— when and how are you gonna hire marketing folks and sales folks and, and those sorts of, of things. Uh, the other thing that, that I'm working on right now is, uh, building a, uh, boutique— uh, I'll avoid the cyber word for you. Building a boutique security consultancy really focused on, say, the $150 to $300 million enterprise market, or whatever market you want to, you want to go there. Because me and one of my colleagues really sees that that market is vastly underserved.

It's missed by even a lot of the Coal Fires of the world, but it's missed by the Accentures, Deloites, etc., and they're, they're missed by some of the smaller, more boutiquey guys that are focused on those $1 to $5, $10 million revenue companies. So in that space, there's really a lack of efficient and cost-effective security consultancy providers. It's almost below the levels of a Protiviti or even a Grant Thornton. There's a really big market space there that can use help on the risk side of things as well as the remediation side because either they don't have the staff, they don't have the knowledge, or they don't want to pay a Booz Allen or an EY or whomever the half a million dollars to go do this. They need somebody that can come in very targeted, be able to deliver what they need, for the size of their organization.

So those are the 2 primary things. There's some other things I'm kicking around that could work, they might not, but those are kind of the 2. Other than that, to your point, if somebody comes to me with an offer I can't refuse, I'd love it. I'm also trying to work my way into the board advisory, board, board positions, because I think personally with my experience I'm able to bridge what one of my friends a long time ago said was bridge the suit and the scary. What I mean by that, I can take very technical security CISO-type stuff and turn it into operational language.

What, you have 50,000 vulnerabilities? Why does that matter to an organization? Well, maybe it doesn't, but you need to have the why doesn't it or why does it. A lot of what we see in a lot of boards is a lot of security leaders communicate, well, I took my 50,000 vulnerabilities down to 40,000, right? So I had a 20% reduction in vulnerabilities.

Well, why does that matter to the business? Maybe it does. Maybe, maybe it enables them to go to market with a product faster because you smoothed out. Those are the types of things and messaging that I think that, again, you know, $150 to $300-ish million companies really need that vision in as to how to take one and communicate it into something that's board effective. So that's where I think I can help board stuff, people, whatever.

And do you see that being an actual board position, like being a board member, or advisement to a CISO, or advisement to the board? Maybe directly. So I think there's— to split it, right? I think there's 2 components to it. I think if you look at the boutique consulting piece, I think there's some of that, what I'll kindly call that CISO education thing, right?

Hey, take this technical stuff because the board doesn't care about the technical stuff. They want to know what the business impact is. So I think there's consultancy opportunity there. I think if you asked what I want to do when I grow up, or whatever I said earlier, you know, it's being that board advisor, right? Be able to say, okay, your CISO is telling you that they had a 40% or 20% or whatever the percent reduction is in whatever, or they've improved their risk posture this way.

Being able to help that board member, right, as a board advisor, either ask that next-level question that's going to be meaningful for the business or take that information and say, hey, by the way, this is really good information. It's just not being communicated. This is what they're really saying to you. So I think there's a value there, and that would be ancillary or whatever to the piece. And then obviously on the board piece, you have a lot of finance guys, and they're typically investors in some way, shape, or form.

They've got a equity or they're a stakeholder of the organization, they don't understand IT. If they don't understand IT, they sure as heck don't understand security. Helping being a board to be able to say, okay, great. You want to expand into this market. That's awesome.

If you're going to do that, you're going to have X amount of customers. Those X amount of customers present you Y amount of revenue. That Y amount of revenue could be put potentially at risk. Risk because if you don't have good coding practices, right, or you've thrown everything into the cloud and you just expect Azure to take care of it all for you, right, like being able to ask those next level down questions to those IT and security executives and say, have you thought about this? Are you doing this?

Because at the end of the day, that protects the overall entity and it reduces their risk and their liability should something sad happen. And as we know in this business, it's not— sometimes it happens. It's not a matter of if, it's a matter of when. Yeah, yeah. No, and I think that the advisor sort of idea and role is an interesting one because, you know, there's been more and more guidance lately, whether it's from the SEC or, or others, that like, hey, you, you need to have, um, somebody with security, uh, knowledge and experience on your board.

And, you know, the more I think about that, I think while that may happen in some cases, it's just not realistic because you— it in the sense of having someone actually on the board as a board member, right? Like, oh, well, you know, you should have a, you know, a CISO from another company be on your board. Okay, well, if they're a board member, they've got to do all of the other things that board members too do also, not just the security piece, Right? So they have got to be financially good enough. They've got to be, you know, have all of the breadth of experience to be able to be a legitimate and useful board member as a whole and have cyber or security experience, right?

So that's— and also, you know, it's probably less likely that they're gonna give somebody a board spot just randomly, right? Like those— there's not like an extra board spot out there for somebody to just be added. So having that experience come in through more of an advisory role, more of a, you know, you get hired on to advise those board members and, you know, be present and be the expert, I think is a much better idea than trying to have a full board member with that sort of experience. And I think from a journey perspective, I think you're absolutely right. I think that if I can do what I think I can.

I think you're absolutely right. I think that starting at that board advisor position and helping them interpret a lot of these things that are either scary or not— it's not a line in a spreadsheet as it relates to a financial, or it's not a go-to-market perspective. Perspective and helping them understand what that environment or ecosystem looks like and why it's important to have certain— I'll just use the— I'll use a different C-word— controls in place to be able to do these things. That's not something that is common. And to your point, having a CISO on the board typically means they're invested in the company, which does mean they've got some money.

But then the other question is, you know, are they agnostic? And that's not the right word, but are they able to be able to separate? Truly independent. True, yeah, independence. That's what I was looking for.

Are they really independents where a board advisor does provide that independence? Because they're somewhat compensated, they're not invested in the board, meaning they don't have to go along with everything the board says, and they're not necessarily invested in the company. They're looking to help make sure that there's a right path forward for both the company and the org, which brings me to the SEC piece. Having done a bunch of research on that recently because they've updated all their fund things, we'll just say the boards are now becoming fiduciary responsible for things like breaches, and if there's a breach, when do you have to report, blah, blah, blah, and is it necessarily a— and I'm gonna mess up some of the words— but is it materially impacting to the overall financial performance of the organization and a bunch of that stuff? Trying to disseminate that from a CISO perspective at a company to a board and what that means is extremely challenging, and it sounds like a lot of fear, uncertainty, and doubt.

Oh, if you don't do this, blah, blah, blah, or we have to report this versus versus not, right? Becomes a very nuanced communication path. It also becomes a very interesting way to have the board say, why the hell do I care? Do I really care? Because we're a privately held company.

I am not— I don't adhere to an SEC whatever. Well, you have 50-state breach notes. I mean, there's a bunch of these other things that boards technically don't care about until the proverbial stuff hits the fan. And then they're putting their thumb on the CISO being like, how the hell did you let this happen? Right?

And so you're like, well, as a CISO, you're trying to communicate, I need this to be able to reduce the likelihood. That message isn't getting, getting through. That's where that board advisor piece comes in. And I think if done well, I think those board opportunities will start to open up because you'll get the reputation of hopefully I'm not an idiot and hopefully what I'm doing is putting Putting the board in the best place to help the organization continue to get better because that's their fiduciary responsibility, and working with that CISO and IT team to make sure they're able to communicate in a language that the board and executives can understand. That is the path.

I agree with you, showing up tomorrow and being like, dude, I'm a board member, that's not likely. And further to this point, funny enough, I'm not sure— it's been a little chaotic, right, since, you know, since the January departure from Orca. But I worked with the ISC2 community, and me and a few others are gonna be published, or we've just been published, for one of their— I think it's a badge on how to talk to boards about cyber. So I'm actually gonna be published, or it's already published and I haven't paid attention because I got a little bit of ADD or OCD. Awesome.

We'll have to find the link and put it in the show notes. Cool. Well, yeah, I just gotta find it, really. Awesome. Well, Doug, we're running out of time.

Any other topics you wanted to cover before we break? No, I just really appreciate the opportunity. I mean, this is, this is cool. I think this is technically my 3rd podcast. The other 2 have been around federal stuff.

Yeah. So, um, what is really unique, and again, I'm super, uh, appreciative of the opportunity, um, it's been really hard for me, to be honest with you, right? I don't like talking about myself very much. Yeah. And you extracting that information kind of opens my eyes that, um, I probably am not the idiot I think I am.

So no, thank you, man. We'll let the internet judge that, Doug. Oh crap. Yeah, I just— yeah, nope, I'm gonna— I'm not gonna touch that for a lot of different reasons. But no, thank you.

This is awesome. You're welcome. And thank you. Appreciate you being, uh, on the show. We also appreciate, you know, you've been a big supporter of, uh, Colorado Equal Security, both, you know, when you were at ORCA and prior.

So thank you for that. Um, and, uh, it's been a lovely conversation. Well, awesome. And I'll, I'll add this to the Colorado Equal Security. The, the stuff you guys do for the local regional CISO community and the way that you go about it is outstanding.

Um, having been a consultant and working through with a lot of you folks, both on the consulting side as well as even some of the product side at Orca, you guys have a crappy job, right? You are the policemen of the organization and With Colorado Equal Security, you give folks a sounding board and a safe space to go figure out some of the hardest things, or a shoulder to cry on, and that is so necessary. I, I just, I can't thank you guys for putting the community together and doing the, the proverbial stuff that you guys do. So thank you, and thank you, and thank you. Well, thank you.

Appreciate it. Again, good talking to you. This has been Colorado Equal Security. And we will talk to you next time.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes