Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 262. We're into May, May 6th.
Alex, uh, I don't know. It's May. It's May. The the weather's nice. Things are blooming.
My nose is running. My eyes are watery. School's gonna end here. School's almost out. Yeah, I've got a kid that's about to graduate.
Unbelievable. Kind of crazy. Unbelievable. Time ticks by. Time keeps ticking, ticking, ticking.
This is the the sound of your life. The future ticking away right now. Ah, on a a better note, we have a Slack channel. We'd love you guys to join. Yeah.
2,500 people. Feels like this week was super active in there. A lot of chatting. There was a lot of chatting. Yeah.
I feel like a lot. Of people, a lot of new members, a lot of people asking for access. So that's cool. Good stuff. Uh, well, you know, if you want to join Slack, if you're not already there, which you're probably already there, but in case you don't know, go to colorado-security.com, click the Slack link, we'll get you joined in there.
And while you're on the website, go down to the bottom of the page and join our mailing list and you'll get some news in your inbox. You know, also, if you're in the Slack workspace, you will notice now that there are no dashes. Yeah, all underscores, only underscores. Uh, we We, we had a, you know, a minor complaint that, uh, our channel names were not consistent. Some of them had dashes, some of them underscores.
So I fixed it. We had some OCD people, uh, keeping an eye on things for us. I appreciate that. Yeah. Uh, also, you know, we'd love for you to, uh, rate the podcast on whatever your favorite podcast player is and subscribe so that you automatically download the episode.
Whether you listen or not is, is irrelevant. You know, we get, we get credit for the download, nothing else. If, if you listener Listen or not, we don't care. It's punchy. We're Friday.
Tell a friend and come support us financially. We got a Patreon. Speaking of patrons, we have a new supporter this month. We do. Thank you very much to Andy Wing.
Andy is the director of IT at Uplight, works with me, and apparently thinks we do something valuable here. So he thought he would support us financially. Did you— did you twist his arm? You say? I did not.
I was surprised. I was surprised by this. Well, thank you, Andy. Yeah, thanks, Andy. I appreciate, I appreciate even if Alex doesn't, I appreciate you.
Hey, let's jump over to the news. We, we start off with some heavy hitting news here. Denver has won, I mean, the most prestigious award I can think of. Yeah, number one city for pizza. And you're gonna go like, WTF, right?
Like, Denver's not a pizza town. So what's going on here, Robb? Well, Denver is a pizza town. Apparently, we have a high percentage of, of pizzas and They they did not only like the number of pizza places, but highly rated pizza places, and they also looked at like the the price for a for a pizza and kind of adding all those things together, jumble it together. Denver is the number one place.
We we beat New York. We beat Chicago. We beat Detroit. We beat Austin, Texas. Of course.
Number one. Number one in the world. I mean, I don't even think they have pizza in Austin. Oh yeah, you don't don't even don't even talk about Austin anymore. So yeah, so people are a little upset if you're if they're not in Denver about this because they're like, what the heck?
Denver doesn't even have its own style of pizza. So, yeah. And they, they talk actually about a couple of other pizza restaurants that are gonna be opening of different kinds. Yeah. So the actual thrust of the article was about these 2 new pizza places, one called Rolling Pin Pizza on East Colfax.
And the other one is, what's it called? Iccia Pizza, which is on the 16th Street Mall. Iccia Pizza is doing Roman-style pizza, which is, it looks kind of like a flatbread sorta. I was looking it up, like square pizza pieces. Apparently this is really cool.
Almost like a focaccia. Focaccia pizza. Yeah, focaccia. It's, it's on the 16th Street Mall between Blake and Market. Um, so kind of the west side, or maybe that's the north side of the mall, however you think of directions.
Um, and then the other one, the other one at Colfax does, uh, other kind of pizza. They were talking about like Midwestern pub-style pizza, which is sort of crackery crust. Okay. Um, which, you know, is apparently an, an actual style of pizza. You know, for my money, Papa Murphy's pizza, take and bake.
Man, if if people were mad about Denver being number one pizza, they're gonna be even more mad about you saying Papa Murphy's is good pizza. So anyway, good times, good times. What else we got here? More more restaurant news. Apparently is Colorado equals restaurants.
This is sad today though. It is sad. There, there was an announcement recently that the Brown Palace is closing their marquee fine dining restaurant, the Palace Arms. 74 years. 74 years.
74 years of very expensive food that I've never once had. And I don't think I've ever eaten at the Palace Arms either. And if just in case, you know, it's not too late for us, but it is too late for the listeners. The last dining service will be Saturday, May 4th. So tomorrow will have been by the time we record the release this.
Too bad for you, but you and I could go eat there tomorrow night. Maybe we should. Yeah, maybe so. You know, throw a little change around. You know, see what's going on.
It's gonna cost hundreds of dollars. Yes. So you know, their times are changing. Fine dining is not as popular of a thing anymore. One thing I noticed in this article they talked about it was it was until I think they said 2004.
That, that you still had to wear a suit and tie to, to go to, to dinner there. Obviously, that's not the case anywhere in Denver or Colorado anymore. So I think, you know, they're just not getting the traffic for fine dining anymore. So it didn't just justify having the, the restaurant open. So they do say this isn't a permanent decision.
It's just for now and maybe they'll come back. But, you know, no promises. Yeah. They also mentioned that, you know, there is a cigar bar Um, at the, uh, the Brown Palace, which is one of the last cigar bars in town. And so they may expand that and do some other things.
Yeah. And the other restaurants at the Brown Palace are still open, just not the Palace Arms. Awesome. Well, we just, we do have a follow-up from last month. Uh, honestly, this came much faster than I thought.
We talked about Ibotta was gonna go public sometime. They went public like really right after, uh, our last podcast. Um, they, they had a successful looking IPO. Yeah, I think it had a good initial pop. I haven't looked recently.
I think that the stock was down a bit from sort of the initial high, which is to be expected, right? Like it goes up a bit. You know, the, the people that are eligible to sell some of their shares immediately sell their shares and it goes back down. And so, I mean, I think it's a positive thing for them. I think that they, they hit above where they wanted to be and good, good IPO.
Most of this article actually kind of just retells the history of Ibotta. If you're interested in knowing where they came from, kind of how they evolved into this B2B versus the B2C that they used to be, it's worth it. It's worth a read. But we talked about it last month, so I won't go into it too much. Yeah, I mean, I do think it was actually— it was a very interesting article.
And this is a Colorado Sun article, so it's long, long and very detailed. So if you want that, go take a look. Next, we have an article about the The health of downtown Denver. The headline is Downtown Vitality Index: How Downtown Denver's Comeback Compares. And, you know, I clicked it.
I'm thinking, ooh, we're going to— how's our comeback looking? The answer is not looking good. We're not really coming back. Yeah. They compared 44 metro areas to see how well they have, you know, come back from before the pandemic.
And of those 44, we were 41st. Yeah, that's not good. Yeah. So not good. I guess the bright side is It's like tech hub San Francisco is 44, right?
Like they're the ones who's come back the least. And I'm looking at this list, Portland and Pittsburgh. Those are the 3 that are on the other side of us. Portland and San Francisco go together. You don't really think of Pittsburgh.
I would have guessed Pittsburgh on that part of the list. But anyway, yeah, not good for Denver. They looked at a bunch of different metrics, things like downtown office space, downtown office space occupancy, cell phone usage downtown, which I thought was an interesting dynamic. Like how many people are actually downtown during the day? Hotel occupancy.
Yeah. They, there was a couple other things, work from home percentage. Uh, they, they looked at all these things that we have a, a very high work from home percentage in Denver. You know, these are, these are things that I think as people who live here, we would say, you know, it's great. But what it really means is that downtown is just not as vibrant as it was before the pandemic.
Yeah. I mean, and I think if anyone has gone downtown, you would agree it's not as vibrant as it was before the pandemic. Yeah. I, I hope that downtown comes back because it was a great place to be before. So hopefully again soon.
You know, it didn't occur to me till like right now, but we're about to talk about a third kind of downer story. Yeah. So we have, we have closing the Brown Palace, we have the downtown Denver vitality problem, and now it's headline is, is, oh man, where'd the headline go? Boulder's— has Boulder lost its luster as a tech hub? Has Boulder lost its luster?
Yeah. So the answer is, uh, you know, kinda, right? That's the short summary here. Yeah. I mean, I think part of it is, uh, things have changed, right?
So that they're, uh, this again is an article that goes into a good bit of history talking about how, uh, Boulder started as a tech hub with, with Foundry Group and Techstars and, you know, other things like that. And, and really how it, it grew into being a place where It was super friendly for startups. There were, you know, a lot of new companies that were happening there. And, you know, now— well, and that part of that was like the rest of the metro area wasn't like that. Right.
So it made it really, really good for Boulder to be that way. People were kind of concentrated there. And now there's lots of areas like that around the metro area, you know, Denver and even Fort Collins and some other places. Right. So it's, it's not as, as necessary to be, um, concentrated in Boulder.
And so, yeah, I mean, maybe it's a little bit less of luster, but it seems like that there's still stuff going on. Yeah, it, I, I feel like it's, it's a little unfair. It's not necessarily that Boulder is doing less. I actually think it has more startups and has more tech industry than ever before, but like the, the, the surrounding area and really the whole country has kind of come up to be closer, right? So, you know, Denver has a very vibrant startup community now, which it didn't in the early 2000s.
And, and of course, you know, other areas in the country, we've just seen the spread going more places. So the article does talk about that there are more startups than there's ever been in the past, but there's less of a startup feel, if that makes sense. Yeah. I think also, you know, there was a big influx of large tech companies putting people in Boulder. And, you know, with COVID some of those have fizzled out, you know, Twitter lost their lease essentially on their space there.
And, you know, many people are working remotely. It's not exactly the same as it was before. So, I mean, I think that some of that has led to it also. And then one other thing they mentioned in the article is that there were fewer sort of verticals that these startups were in previously. And now there's a lot of other Uh, startups that are happening there in various different areas.
Uh, you know, I mean, like, you know, Uplight where I work is in sort of in clean tech and things like that. And so it's, it's a little more siloed than it used to be instead of like one big tech community. There's lots of littler tech communities. It's interesting. Um, so I do think, I do think one of the points it makes is, is where tech communities happen is where you have the combination of industry and education.
And Boulder was great for that with CU and like big companies like IBM that had big presences there. And, um, that's still true. But you can look to other places like Colorado Springs, or you're gonna see similar type things developing over time. Yeah. On that point, too, they did mention that, you know, IBM used to employ thousands of people at their office there in Boulder.
And I mean, it's, it's basically a data center and, you know, a manufacturing hub now. It's not really an office space anymore. So you have far fewer of those kind of people. Anyway. All right.
Moving on to our next story. This one is exciting for you, Robb. Uh, there's a fast-growing Denver tech company that has just announced a new CEO to replace one of their founders. Yeah, so Pax8, where I'm employed, um, we, we named a new CEO this week. Scott Chasin is, uh, is our new CEO.
He was the CTO. Scott's my boss, and I'm super excited for him to, to move into that new role. We actually had Scott on the show back in 2017. Oh yeah, a long time ago. Yeah, he was the— at the time, he was the, the founder and CEO for ProtectWise.
Denver security company. And now he's, now he's taken over Pax8, which is not a security company, but it's a technology company that sells a bunch of different stuff, including security. So there's, he definitely has strong, well-informed perspectives about security. I'm super excited about it. And, you know, for those who don't know, Pax8's about, about 1,700 employees here in town and growing very quickly.
And, uh, we, we don't probably sell to you, but probably that whoever you are, we probably don't sell to you. We specifically target MSPs, like small outsourced IT companies, but it's a cool company. Glad to be there. Awesome. Next story in another sort of downer of a story.
This is kind of a downer story month. There's a new FBI report out. This is sort of, you know, their annual report, but talking about how Coloradans lost, uh, were scammed out of $187 and change million in 2023. Yeah, you know, I don't know, that doesn't seem like a lot to me if I'm being really honest. $187 million for, for the size of population we have.
It does say 7th in the nation per capita. Okay, that's maybe— that's a lot. I don't know. I mean, 7 out of 50, it's a few, you know, it's $100 a person or You know, less. I don't know.
I haven't done the math to figure this out really. But, you know, anyway, regardless, nothing is good to have stolen from our people. They specifically talk about the scams that impacted Colorado the most. Number one was investment fraud. And I kind of wonder if that goes back to that.
Remember that we had the cryptocurrency scam here? Oh, yeah. I wonder if that, like, falls into that. Probably. Second was business email compromise, you know, right in our wheelhouse as security people.
And the last one is tech support schemes. If you know, that's at $23 million. So the biggest one was $60 million, business email compromise at $57 million, and then tech support schemes at $23 million. Wow. Yeah.
They also mentioned that altogether it was 11, just about 11,500 people across the state reported being victimized. So, so, you know, talk to your family, give them some tips about how to keep safe because this, this is happening. I will say, you know, not, not that long ago, I reached out to my mom and some other family members and said, Hey, these are the things you should be thinking about. The people that want you to renew your antivirus or that are saying your Windows is expired are not actually nice people. Just trust no one.
Just trust no one. Hey, let's jump over to our next story. We have a blog post from Red Canary. I really liked, I liked the topic here. It's manage your SOC, your security operations center, like a product.
Yeah. Having that product manager perspective to running your SOC. I love the concept and, you know, getting into the details of how they think of it. They're, they're, you know, you want to think about a delivery that's coming out of it and, and really what, what are the features of your product that matter to you? And they, they talk specifically about the importance of threat intelligence, kind of as your product manager, your threat intelligence helps you determine what to invest in next.
Hey, if I know what the threats who are targeting me are going to be doing, I can think about what my SOC needs to be good at. I really love this idea and this, like, I think of it as a like a dynamic, you know, ever-changing approach to running a SOC. Yeah, I mean, similar, they also talk about, uh, you know, prioritizing how your, uh, your work basically on risk assessment, you know, so using that threat intelligence to figure out what the biggest risks are and then trying to plug those holes. Um, and I think this is a good one too, and this is always a problem with security operations and SIEM and things like that. Saying no is just as important as saying yes.
Yeah. Right. Like, I think that basically every SIEM I've ever used, like, it's the, the operating model has been, all right, let's put our data sources in there and then turn on every rule we can turn on so we can find everything. And then, uh, you're inundated with a whole bunch of false positives. And then you have a SIEM that you're not happy with.
Right, exactly. Yeah. So learn to say no. Awesome. Love it.
Um, next we have a blog from Optiv, and this is the Rising Role of the BSO. I will say, you know, mostly I do think that I've seen more of the BISO popping up over the last year or two. They suggest that it's a new role in this article, and it's definitely not a new role. It's decades old, but it's coming about and becoming more popular these days. Yeah, and, you know, I think if you're not familiar with what a BISO is, it's sort of like a, you know, a divisional CISO or something similar to that.
You know, somebody that is responsible for similar things to, to a chief information security officer, but for a segment, uh, of your company or, you know, geography or something like that. Yeah. The way I think of it is that a BISO is, it's really a relationship play where you want to have a closer relationship with one part of the business than you can get at this like corporate side. Right. So you, you go say, you know, I'm going to have a person who's responsible for knowing this business segment.
This business unit, this department, whatever, this function. Um, and this person is kind of their champion, their, their go-between, and then have them feeling some ownership. And, and frankly, that, that BSO feeling ownership for their business unit means you're just going to get a better level of care, I think. For sure. Yeah.
And it's probably not something you're going to see if you're in a smaller organization. There's just not, um, enough size, uh, to need something like that. But I mean, I think even moderately sized, uh, organizations can drive value from having this type of role. Yeah, we're not huge at Pax8, but we do have a BISO, and it's based on region for us, where we have these, these regional businesses. And if, you know, if we're trying to support our APAC, you know, out of Australia, if we're trying to support that from Denver, it's just really hard.
You know, how do you— how much time do we have to overlap each day? How do we know about things changing in their region? What's really difficult? So we put a person in region to, to stay on top of it, and they can, they can do important security work while they're there, but they can also build those relationships and make sure everyone's aware of what's going on. Yeah, definitely.
All right. Last story for the month. This is from Zvelo. Deepfakes, escalating threats and countermeasures. Really talking about the rise of, you know, AI and deepfakes and what it means to us.
Yeah, they, you know, they go through some strategies for detecting and mitigating deepfakes. Deepfake risks, you know, using AI-driven systems to detect it, doing some training, having incident response plans in place. Just, you know, honestly, if you haven't given any thought yet to how you need to respond to deepfakes in your organization, this is just a nice primer that you can go through and maybe take some action today to get ready. Yeah. You want to be aware so that you don't get a call to somebody that is deepfaking your CEO telling them to transfer money where you shouldn't transfer it to.
Yeah, if ever, and then if your company doesn't know that deepfakes are possible, then when, when they hear your CEO's voice, right, it's, it's really convincing. Yep. It's really convincing for sure. All right. Moving over to events.
As a reminder, we have a calendar of events on the website. Go out there and see things coming up through actually through the end of the year. Now I got, we got stuff quite a ways out there, but what's coming up in May? We got a couple of events happening on the 8th. First, ISC² Denver.
Uh, is doing an event navigating the cyber landscape in operational technology challenges, threats, and solutions. That's on the 8th. Also on the 8th, ISSA Denver is doing a real world, the real world hunting cloud security threats, both DTC and downtown. That's just their normal monthly meeting. On the 14th, Let's Talk Software Security has a security champions.
What can keep them from being successful conversation? And then do they also have an event on the 15th talking about security champions? Probably not. One of those is probably wrong. One of those is wrong.
But either the 14th or the 15th, Talk Software Security is going to have an event. We should figure that out. Uh, on the 21st, we got a couple of events. CSA Colorado is doing an AWS hands-on identity and access management immersion workshop. This looks really cool, by the way.
That does sound cool. I was taking a look at that. Also on the 21st, ISSA Denver has an AI and ML special interest group inaugural roundtable event. That sounds fancy. Uh, also a couple events on the 22nd.
ISSA Denver is doing a Denver chapter and Gigamon Superfly Golf event. So this is a social event. And then ISC2 Pikes Peak is doing their May meeting. And then we're going a little bit further out just to mention what's coming up. Um, June 11th through 13th, it is the premier conference in the whole region, the whole Rocky Mountain region.
Rocky Mountain Information Security Conference is coming. Yeah, the 11th through the 13th. Sign up. If you're listening to this, you've already missed the early bird, but you can still get a good deal. And also the day, the 14th following RMISC, like any good big conference, there is a B-Sides that follows the conference in Boulder.
I love that they got that. They got it back with the timing again. Yeah. All right. Jump.
Let's jump over to jobs. I will start because I got 2 here. PacState, we are hiring a senior cybersecurity operations engineer. That's someone who, who's going to help us really run operations within our SOC. And this person needs to have quite a bit of cloud experience.
That's the, that's the number one skill for this. The second job I'm hiring is an IAM engineer, looking for someone who has some good Entra ID experience. All right. Good stuff. Bank of America is looking for a senior information security officer.
That sort of strikes me as a BISO-type role. I was kind of hoping you'd get this one. This company is called Clavio, maybe Clavio, Clavio, Clavio, Clavio. They're hiring a senior manager of security risk and reviews. Sweet.
Trimble is looking for an IT risk and control manager. This one's interesting. Amazon Games is hiring a senior security risk specialist focused on games, media, and entertainment. Wow. I didn't know there was a thing called Amazon Games.
I guess I do now. Here in town. Here in town. Cool. GoGo Business Aviation is looking for a senior cybersecurity analyst.
Juniper Square is hiring a GRC security specialist. U.S. Bank is looking for an IS governance risk and control specialist. NREL, the National Renewable Energy Lab, is hiring a chief cybersecurity engineer. And finally, Synopsys is looking for a Senior Staff Cybersecurity Engineer. All right, well, that is it for the news.
We have an interview this month, and it's with the, uh, 2024 CTA APEX Awards CISO of the Year, Randall Frietzsche. Randall is, uh, the CISO over at Denver Health, and I think it's been like 7 years or something like that. It's been a while now. Yeah, he's been doing it. We've known him obviously much longer than that, but he's been doing Denver Health for quite a while.
Congrats to Randall for that. And He sat down with Frank and went through kind of how he thinks about leading. Excited to hear it. All right, well everyone have a fantastic month and we'll talk to you in June. Thanks, Robb.
This is Larissa Thomas, CISO at Knox Health. Welcome to Colorado Equal Security, for Colorado security professionals by Colorado security professionals. Good morning, good afternoon, and good evening, Colorado. My name is Frank, and this is the Colorado Equal Security Podcast. I have today with me Randall Fritsche, or Fritsche, and I know I just said that wrong, but that's why he actually prefers to be called Fritz.
He is the CISO of Denver Health. He's been in cyber for 25 years, 7 years as a CISO, 6 years as an R ISO. He just won the CISO of the Year. He's a CISSP. He's got a master's degree.
He teaches for Harvard. He's been inducted to the ISA Hall of Fame, graduated from the FBI CISO Academy, right? And it's the 3rd time on his podcast. So one of the things I can say is that any one of those outqualifies me in the world of cybersecurity, even though I've been in this for a very, very long time. Randall, how are you, sir?
I'm good, sir. You can call me Fritz. Fritz? Oh, sorry. Bad habit, bad habit.
Uh, or I guess good habit from my Marine Corps days. So I'll probably do that a couple of times though.
All right. So you are the CISO of Denver Health. How is that going for you? Going really well. A big part of cyber is making sure you have the support of your organization and Denver Health really cares about it.
They really care about protecting both the data and the safety of our patients and our employees. And so they do invest in cybersecurity. And we have benefited from that support in ways that allow us to be very good at cybersecurity. Certainly, you know, nobody's perfect, but we do a pretty good job. Okay.
I just got a new team. In the past year, we've completely replaced the team. I have, um, a Marine. Mhm. I have former Army and former law enforcement officer, and then I have another former law enforcement officer, and then I have me.
I'm a former law enforcement officer as well. So we have 3 cops and 2 soldiers, okay, on the team. And so You know, those guys really know how to protect and serve. They have that mindset and that heart. And they, they know how to respond to situations which are bad.
They know how to respond calmly and, and problem solve. They know how to communicate well and just all assets that in cyber we really need. Uh, and so these guys are really fantastic. Well, do you think that helps to have a background in either law enforcement or military? I mean, I, I have to admit that I am very, very biased, being a Marine.
But do you think that really helps? Because at least when I got started 20+ years ago in, you know, just in IT, there really wasn't anything in security. At least, you know, it wasn't nearly anything like we have today. So do I know response times? Absolutely.
Do I know how to protect? Yes. But the skill set that I learned in the Marine Corps was not the skill set that I don't use any of those skills, or at least those hard skills that I use. How do you think that applies? What advantages do you have with being law enforcement and/or military?
Yeah, well, I think it's, I think it's a set of skills that are, that are relative to our profession. And I think that that allows them to be able to, you know, they, they're used to responding to bad situations, rolling up on scene. And in the military, you know, they're used to being shot at. And, you know, cyber is a little bit less dangerous, but they bring those skills that your average cyber person may not have. And they may not have it embedded in them the way that we do when we come out of law enforcement and the military.
So while it's not a requirement, certainly It's, it's a good thing to have, especially when you know what hits the fan and you got these guys on the call with you and, you know, they're going to handle business. Okay. What about the people that don't have that type of background? Is all hope lost and they can't do anything else? Or what could they do?
Well, I think they get that experience through dealing with incidents, right? They learn how to do that. You know, in a normal shop, you've got all the IT people who are sort of scrambling and maybe even panicking. And then the cyber team rolls in, you know, we do this all day, every day, right? It's just, it's just another scenario for us to deal with.
And so, yeah, through experience and dealing with cyber incidents, they definitely get that. They get used to it, becomes second nature, and they're not panicking anymore. But it is a very scary situation when you're in that. Uh, and so, yeah, it's just through experience. What if you don't have experience though?
What if this is your first role? Or maybe you always have— you always— we always have those situations where we haven't dealt with it before. I mean, as you already know, we can't really be prepared for every single incident. Right, right. How do we deal with that?
What would be your advice? Well, you have to, you have to have some experienced people who can help train those new folks, right? You know, they're not, they're not doing it by themselves, hopefully. And so they learn from, they learn from their peers and their colleagues. And they observe, you know, we teach them what they need to know.
And over time, we give them more responsibility. And they continue to live up to that and continue, um, being able to handle that until they can handle it just like the rest of us. Okay, so you do have an access— you do have a background in law enforcement. Was that with the regular police? Was that with the cyber police?
Was that SWAT teams? Uh, what, what was that experience like? I was a regular deputy sheriff. Uh, cyber, we did not have computers back then. This is like in the '40s.
Just kidding. But no, we didn't have computers. You know, the internet wasn't publicly available yet. And so, yeah, I was just a generic deputy sheriff. I do have a SWAT guy on my team.
Um, he was also a hostage negotiator. And so those are really, it's really funny to see how that kind of overlaps into cyber. Okay, well, first off, I think it's funny how you say, quote, regular, and I know I'm using those air quotes. It's like regular, like that's normal or something like that, right? Yeah, that sounds really, really weird.
I mean, it's like, I, I, because I have to tell you one thing, I have the ultimate respect for the law and for people that put themselves on the line to defend against, well, people that take advantage of us. But they get it from both sides because law enforcement, nobody likes getting pulled over, including myself. Right? Am I mad about it? Absolutely.
Do I think, you know, blah, blah, blah, police officer? Absolutely. But they are here in the, they are here to protect us possibly from ourselves. Taking that statement, how does that get into cyber and relate to cyber? Well, we're all dealing with the bad guys, right?
Like, I call them sheepdogs. So the military, law enforcement, and even cyber professionals, you know, we have our sheep. And, you know, they're not necessarily experts in cybersecurity, or, you know, hey, I got an email, I don't know if it's phishing or not. And so we have the wolf that's trying to attack the sheep. And the sheepdog sits in the middle and Part of its job is to protect the sheep from the wolf.
And we do, that's what a military, the soldiers are standing between the bad, the enemy, the, in war to protect the country, the law enforcement, we're standing between the innocent and the bad guys to protect them. And in cyber, we're standing between the criminals and our organization, our customers, our patients, and our employees. Uh, so we are all doing the same thing. It's just we don't carry weapons, you know, and get shot at. We're, we're all doing the same thing.
It's just a different type of protectee, a different type of method and tactics and so forth. Still a sheepdog. Well, do you ever feel like you're protecting them from themselves? Absolutely. Yeah.
Yeah. Yeah. Maybe against their will. So, I mean, yeah, sometimes, right? It, you know, they don't always like what the controls we put in place, but it's really, I think I try to train all my guys to be future CISOs.
And I tell them, you're running a business, you're trying to run a business, you're trying to make it secure, but you still have to run the business. And so the safest thing would be to unplug from the internet and have everybody shut their computer off. But we have to run the business and we have to use technology to do it. And so we have to be able to find those balance between making it secure and having the business be able to do their job. And sometimes that's compensating controls.
So I can't do this thing that we require, but I can do these 2 other things to make it really hard to, to exploit the problem that I have in the first, first degree. So my compensating controls can can make it harder to get to that. Certainly not impossible, but, you know, nothing in security is perfect. Yeah. Well, have you ever had any of those challenges that just turned out to be a big laugh?
I mean, have you ever come in and it's like either it was a wrong control, it was a business that didn't make sense, or what else could it be? Could there be something along those lines? You're talking in terms of incidents that may happen? Incidents, maybe. You know, we're getting very serious here, so I'm trying to think of some funny stories, maybe from your past.
Do you ever, like in the SWAT team, jump out and be in the wrong address or anything like that? Well, I was never on the SWAT team, but okay. Yeah, I have a ton of law enforcement stories, but you know, relative to cyber. You know, it's always they, they're trying to do something and they don't know how to do it and they assume it's a cyber problem and they call me up, right? And it's like the old days, you know, I had a boss one time that said, called me up and said, my Yahoo is down and I want you to fix it right now.
And I said, yes, sir. Right. And I just went back to work and about every 15 minutes I checked it. And as soon as Yahoo came back up, I called him and I go, I fixed it. And he goes, you're awesome.
You know, like, why argue about it? Right? Like, you know, if I tried to educate him, he would have just argued with me. So I, you know, I just said, okay, I'll fix it. And I fixed it.
So by waiting until it came up. So yeah, it's just, you know, we have to understand we're dealing with people who, you know, we're, we run in cyber circles and we all know what we're talking about and we have to realize that The folks that we support and protect, they don't know what cyber is. They don't understand it. You know, they might understand antivirus and what a phishing email is, but they don't understand actually under the hood what we're talking about. And so we, we have to assume that they're going to always do the dumb thing and, and the wrong thing.
And so we have to build our controls and we have to do our education and training to make sure we give them the tools they need to be safe as much as we can. So from what you described, and just taking part from one of the things that you just, you told me, do you think that the hostage negotiator on your team helped you with that? Or was that a skill that you've already had? Well, I don't think, I don't think he's negotiating for any hostages. I think it's the communication skills and the persuasion That he has just learned and he's learned how he was trained.
And he also through experience honed that training. And it's just, you know, he could, he could email or pick up the phone and call the CEO and I'd be completely comfortable with it. He's, you know, very, very good communicator and, you know, he understands people's issues, right? Like the, the hostage taker has their needs, right? That they've done it for some reason.
And so acknowledge that they have a need, acknowledge they have an issue, because that then helps them be on your side. And then with that, you can be very persuasive and you can get to the bottom of it and solve the problem. And I think that he's just a master at that because of his training and experience. Well, I think that's the hard part. That we have in cyber is, and you mentioned this, is being able to protect.
We could protect everything, right? The business wouldn't function anymore. We could unplug everything. I remember I actually had a conversation. I was doing web application penetration testing, and the vice president comes along and he says, I want my application 100% secure.
I said, great, take it off the internet. He looked at me like I had a third eye. And I looked at him and the very few times that the filter between my brain and my mouth worked, because I wanted to say, well, you look stupid, right? Because like you said, they're trying to run a business. They keep trying to run that business.
They keep trying to get it going. And making the business run doesn't necessarily mean that it's going to be secure. If you have that overarching need, if you have that CEO or, you know, that senior vice president or something that says, I don't care what it takes, I need this thing working, and I don't care if we have to back down on security, what is your answer to that? Well, I think that That question goes directly into my sort of root psychology and, and, and in being a CISO and that, and really any cyber professional, and that is building relationships. And you build relationships by gaining trust and you gain trust partly by demonstrating your competence.
And so they know that I know what I'm doing. They trust me. And they're, they're more likely to take my advice. And so if the CEO says, I want to rip out all our firewalls, I'm going to say, here's the issue with that, here's what will happen. And it's just going to be a bad thing.
And hopefully, because she has my trust, and she knows I know what I'm talking about, that she will take my advice and back, back away from that stance. You know, that's a That's an extreme example, but, you know, that's, that's what really it takes. And it, I see it every single day, almost every single hour of the day where somehow those relationships that I've built across the organization just kind of lubricate the process, right? I mean, I get on there with anybody, almost anybody in the organization. Hey, it's Fritz.
How's it going? Hey Fritz. Hey, I'm here to help you today. What, what's going on? And that relationship that I have is just like gold.
It's just a golden ticket, right? It's so critical to build those skills. Professional branding, I think, is really important. You gotta have a brand, right? It's like Nike, like they have a brand and then they got Michael Jordan.
So when you see the Nike swoosh, you know, what do you think? Right? Do you think bad shoes or do you think really good quality shoes? That's branding. So what is your professional brand?
What is it that when they see that brand, they think of you? What do they think in their mind? Because if you don't put, establish that for them, they're gonna establish it for themselves and it's never gonna be accurate to what you, what you would like it to be. So you gotta establish that professional brand with them. And I personally use the thin blue line because I'm former law enforcement and I use the sheepdog And because they know that when we roll up, we're going to take care of business and that makes them feel better.
And then it helps, helps them to support us. So if you don't have a law enforcement background, how would you have people like right now with me, you know, and let's forget it right now about my military experience. Let's say I come to you and I say, hey, Fritz. I need a brand. How would you start this conversation with me?
Well, so what do you have that not everybody else has or could go get in 6 months? Right? Right. You have the Marine Corps, so you don't have to, you know, it's not, it's not the Marine Corps that kicks down the door and throws a hand grenade, right? It's the Marine that communicates very well, impeccable character, impeccable loyalty and commitment, right?
Those are values that you have that not everybody has, especially if they haven't been in the Marine Corps. And so that's what, that's the kind of thing you have to grab onto and then sort of build a brand around and, and be able to say, you know, yeah, I was in the Marine Corps and through that I've learned to, you know, maintain my military bearing. I've learned to maintain my level of professionalism. I've learned to be a constant learner and reader. I've learned, you know, through my leadership, I've learned all these things.
And that's the value that you're going to bring because you are who you are and you've done what you've done versus the next guy or girl who may not have that same thing. So that's really what I'm talking about with a professional brand. Well, I mean, that's one of the things that I always push is value and impact. And being able to constantly push that way. We make a lot of statements in cyber where, well, we have this thing coming in or this thing could possibly come in, but it doesn't have any value.
It doesn't have any impact to the organization. So I think that would be my brand along, of course, with what you said in the Marine, about the Marine Corps part. Yeah. What about if you met somebody on the street? Oh, I don't want to discourage anybody from You know, hey, I was never a cop, never soldier.
Maybe I should go into cyber. That's completely wrong. You absolutely should. We need all the best people we can. Character is critical.
Integrity is your currency, right? Nobody's going to trust you if you don't have integrity. That's really it. And then, you know, I've seen people from sales, pure sales come into cyber. I've seen people from manufacturing come into cyber and they're fantastic because they have a set of skills that are unique and they bring those to bear to add value and impact, right?
And so, yeah, anybody that wants to be in cyber should pursue it. I just think that they need to pursue it with the realistic and not false expectations, right? You can't come in and be a technical cyber person just off the street. You have to understand the underlying technology and you can't get that in cyber. You have to get that through racking and stacking and building servers through setting up you know, IP networks and switches and routers and building desktops, breaking open a box and replacing a CPU, whatever.
You got to understand how that technology works really before you can. Now, that's not all cyber. There's a risk and compliance aspect of cyber. And I've seen lawyers come into cyber and do more GRC stuff. I've seen a lot of folks who don't understand technology hardly at all, but they're able to sort of be like an auditor because they can They can really bring the skills, detail-oriented type skills to sort of go through an audit, understanding the audit protocol or the compliance regime or whatever, and be very effective that way.
It's just, we have to make sure that we're always setting those expectations. You're not going to come in and be a pen tester just because you got an associate's degree in cyber, right? It's just not realistic. And the universities that push this should be ashamed of themselves because they're taking their money and they're setting their expectations. And then they go out in the job market and they're just so frustrated.
I see it all day, every day on LinkedIn. All these people are like, I can't get in. I've got 100 resumes and I haven't got one interview. And, and well, that's why, right? You're applying for a senior cyber engineer and, you know, you, you know, you haven't even worked in IT before.
And so it's just those expectations. It's, it's definitely doable. We've all done it, right? And we just need to make sure, and that's all, that's also for people who are in cyber already, which is most of the listening audience. And that is, yeah, you got to just keep on working at it, put in the hard work, invest in yourself, you know, go out and get that next certification or go out and get that next degree because it will help you.
It's not, it's not the only thing, right? And it's not guaranteed. But if you're not investing in yourself and you're not putting in the hard work, you're, you're going to be stagnant. And really, really understand where you want to go. And then I build a ladder, right?
I have a diagram, I build a ladder and I can put on the bottom rung what I can do today. And then on the next rung is what can I do tomorrow or next week or next month? And I keep on adding to that and I have my goal at the, as the very top rung. And so if I keep taking these steps and knocking down these things, eventually I'm going to be at the top of that ladder and I'm going to be at my goal. And that is really important methodology that I have used personally to be successful.
And, you know, anybody, anybody out there can do that. Okay. So what I heard though is the really the biggest thing is that commitment, right? I mean, I do teach at the universities and one of the biggest things that I tell them is that this is an investment in yourself. It is a time commitment and an investment in yourself and I think that's true for if you're not in the university.
Why are you doing these labs? Why are you taking this SANS class? What are you pulling out of it? Are you really committing to it? Are you spending your time going through the labs and then at, on Friday night going out and partying?
Or are you spending your time going through the labs and then on Friday night reviewing the labs, maybe trying to break the lab a little bit, do it a little bit different. Because, you know, the nice part about doing the labs is that you can break them and typically reset the lab and go, well, I learned from the failure part. I learned from the broken part. Yeah, absolutely. Yeah.
Yeah. I do love your— again, I love your ladder analogy that you can't go from basically zero to being the CISO until you get that experience in. I'll tell you that I share this with my team as well. And so I did that when I was relatively new in cybersecurity. You know, I'm looking out there, what, what can I, what can I accomplish?
And, you know, I keep seeing the chief information security officer, that seems to be the top. And so I'm like, yeah, I could do that. Right, right. I've been in, I've been in it 2 years and yeah, I could be a CISO. But so yeah, I figured out, I started reading job descriptions for CISOs and I figured out what all the things they're looking for.
15 years experience. Experience, master's, bachelor's degree, master's degree preferred, CISSP, you know, like leading a team of at least 10 people or whatever. All these things that I kept seeing consistently in every CISO job description. And so I started adding those to my ladder, and I started with the ones that I could do first, and then I started— I lined them with the ones that had dependencies, right? I'm not going to get a master's until I have a bachelor's, and so I got bachelor's first and then master's.
And so I put those all on my list, and now I have a roadmap. Now I know I'm going to do it. And so I, I knock out the first rung and take a shot at the second rung and so forth. And so at the top of that diagram where it has CISO, I had a diagram of a door and on the door it said Chief Information Security Officer. And that was in my actual ladder diagram.
And so I got hired. So I was a RISO, Regional Information Security Officer. We had a CISO. But we're sort of the regional CISO, right? It's, it's not the CISO, but it's similar in your, in your area, your business unit or your geographical region.
But it wasn't the CISO yet. And so I got hired at Denver Health as the CISO. First day, showed up at the building, went upstairs, got my key out, walked up to my office door, and on the office door it said Chief Information Security Officer. And I opened the door and walked through and I saw that diagram in my head. I've just walked on the last rung.
I just walked through the door on the last rung of my diagram. And that was pretty cool.
Okay. Well, I mean, kind of on that line and to go back to something that you said earlier about building relationships, it took you a while to build trust with your What is it? I think you said your CEO, right? Yeah. Well, all the leadership and not even leadership.
I mean, individuals, right? Okay. Just when you've been there for 7 years, you tend to get to know a lot of people. And so, yeah, definitely. I meet with all new executives when they get hired and then I recur that, you know, as often as I can.
Generally it's 6 months, 9 months. And I'll just touch base with them again. And, and I want to understand, what are your issues? What are your needs? What do you need?
What, how can I help you? Here's what security does at our organization. And then they'll have questions. Well, my last organization, we did XYZ. And, you know, and so I listen to them, make sure they understand I'm there for them to help them and make sure they understand that my goal is to run the business.
Um, but do it securely. And so that I'm, you know, very flexible and work with them however I can to make sure that we get— we make sure their business can run. And they appreciate that. And they call me and I tell them, you can call me anytime. Here's my cell phone.
Call me at 10 o'clock at night if you need to. Um, just open up those channels, communications, show support for their business. And, and the other very important thing is Find out where the company makes their money. What's the top 10 revenue-generating areas of this business? Because that's where I really need to spend my resources at, right?
Where am I making that money? And make sure you're relaying that to those leaders so that they understand that you're, you're not just an IT person, you are a business leader, and you understand the business and business is to serve our customers or our patients and make money. And so that we can continue to serve our mission as a nonprofit, right? We don't make any profit. We invest it back into the business.
And so it's very vital that we continue to have revenue so that we can continue our mission. We've been in business for 164 years. Denver Health was, it was called Denver General. It, yeah. 1860, we started the hospital.
We were there when ambulances were horse-drawn carriages. And so yeah, we've been 164 years. Is it 164 or 124? I think it's 164. I'm— I don't teach math, so, but yeah, we've been there forever and we want to— I bet you could tell me if you were subnetting it though.
Right now, I do have a question, and it's funny because I do tell my students this, is that when we go to apply for a job, 90% of the companies out there don't offer security as a business. So you should spend some time running the business or at least learning how they make money. So thank you for the confirmation on that. I do have a question though, is You've talked about day one a little bit. Could you describe that a little bit more?
Let's say that it's, you know, you've been there for 7 years. Let's go back 7 years to the first day. Did you walk in as the CISO? Yes. Okay.
Did you have previous experience as a CISO? As a CISO? So I was a RISO for Catholic Health Initiatives. Okay. Yeah, we reported to CISO, but We were not— we're not the CISO, but the CISO of our region, right?
We're based up regionally. Um, and so, yeah, as a RISO, I was, I was in charge of the cyber for my region. Okay. Well, I want to try to put you in a situation here of, let's say you didn't have that leadership experience, right? And you're walking into a brand new organization.
How would you build trust? I mean, you talk about that earlier about how important it is, and I absolutely agree with you. How would you build trust? Because at this point, you don't really have a branding, at least not within the company.
What advice would you give to some of our listeners today?
Well, I don't think I would have got the job if I didn't have the experience, but But, you know, even when I first started at CHI, you know, it's the same thing. It's really understand who the players are, understand what the business is, what's the business do, and what's the primary mission of the organization, and really try to align that to your cyber program in terms of risk management, in terms of putting controls, spending, spending money smartly so that you're not protecting You're not spending the exact same amount for every single thing in your network, that you're spending money wisely around risk and try to understand who the players are. Use your boss to start making introductions. I had been at Denver Health for 2 months before I had to present to the board. And so they, at the time I had the EC Council Certified ethical hacker.
And the president of the board or the chair of the board said, I see you have ethical hacker certification. Isn't that an oxymoron? I said, yeah, it actually is. And then I went right into the sheepdog branding thing, right? So I'm, I'm building those relationships and branding right off the start.
And, you know, it's getting to know those people, start setting up meetings with those people. And it's not easy, right? Okay, they have, they have admins, right? Who's your admin, right? I don't know.
I don't know who to call to try to get on your calendar. But yeah, you've worked through it, you solve for that problem, and you continue on meeting with those folks, introducing yourself. And in the interim, you're trying to learn as much as you can about the infrastructure, where the data is at, what value is the data, what sensitivity is the data, where is it living, what's connected to what. You know, who do we have site-to-site VPN tunnels with and why? And do we have that documented, inventoried, right?
Just all the things you got to learn. I was fortunate enough that we do a third-party risk assessment every year, and about 2 months after I started, we went through that, which is a week-long exercise where they really ask us all the questions they need to ask. And so I was able to learn quickly what we're doing in all the different areas. And so that education is really— you've got to be educated on the business, got to be educated on the technology. And then, you know, you don't come in immediately and start dictating policy, right?
You got to learn it first. Then after you've learned it for a while, you say, hey, I see that we're doing XYZ this way. Have we ever tried to do it this way instead? And so slowly you're trying to learn and then you're trying to bring your experience into bear to try to help move that program along. Cool.
Cool. Well, that, that's, that's good advice. Do you have any advice though? Because we, we have been talking, of course, at that leadership level. Do you have any advice for either the entry level or the more hands-on type people that don't want to be in leadership?
Right, absolutely. Yeah, I mean, I— that was me for a long time, right? I wanted to be in the basement with the lights out, and I, I didn't want anybody to call my phone. And that's normal for IT people who tend to be introverted. And I have to say, I'm introvert.
And the definition of introvert versus extrovert is the extrovert, it gets energy from being around other people, talking to people. An introvert, it sucks the life out of them to have to talk to people and, you know, be in a room with a bunch of people and talk and be bubbly. And it's exhausting. So I'm an introvert. I don't like it, but it's a learned skill.
So you can learn to be an extrovert and you have to learn at some level to be somewhat extroverted. If you're gonna be in a leadership position, you have to be able to sit and talk to people. You have to be able to present to a, present to people. And so yeah, definitely try to get out of the habit of just wanting to be in the basement forever. Well, unless you just wanna be in the, in the tech forever.
But even then, you got to be a— you got to be a good communicator. So learn your communication skills. Try to be precise in your communications because as cyber people, we tend to— we're talking to a director or an executive and we're saying, well, your IP address doesn't match in DNS and we're going to need to get your MAC address. And they don't know what you're talking about, right? They don't know what the hell you're I mean, we get— we gotta understand, back to what I said before, they don't understand cyber or technology, and it's not their job to understand it.
It's our job to translate it for them. And so in my Harvard class, we give presentations back. The students give presentations back on a complex scenario, and I'm the role play of the CEO. And they'll come back with this, oh, it's a DDoS with a We have a DNS inject and we have a— and I stop them and I'm like, I'm the CEO. I don't know what the hell a DDoS is.
What's a DNS mean? I don't know. And I correct them until they get the point that you've got to translate that technology jargon up. Right. And that's a critical skill no matter what level the organization that you're at.
Definitely understanding customer service. And this is not the Department of No anymore. Right? Because you think when we're— when we first get started, we think it's an absolute. Security is an absolute, and it's absolutely not an absolute.
It's, it's a depends. It depends on the context. And security context is king. If I get an alert from one of my tools, I have no idea what it is. I've got to go out and I've got to figure out the context around it before I can even begin And that context is so key.
And so we've got to be meticulous, we've got to be precise in our communications, we've got to be precise in what we're doing in our job. You know, if we're making a change to a config or something like that, we have to go do that research. You spend 80% of your time doing the research and documenting the details, and then when you go into a change, you spend 20 minutes 20% doing the change. At that point, you're executing the plan. You don't go into it, you don't go into the change window then trying to figure it out.
You've got to have done all that research. And so, you know, excellence. I preach about excellence. You know, we're in cyber. We have to hold ourselves to a higher level from both from a, from a work ethic, from an integrity standpoint, and also from a just execution of our job because we can really screw things up and we can really cause bad things to happen if we're not careful.
So that sounds like a good branding tip is to, is to always have that. Yeah. And you lead with that in an interview. You try to show those things that you can bring. And if you're communicating really well, if your writing is good.
Yeah. Communicate verbal communication. Yeah, if all that's good, you know, you're— you probably look better than 80% of the other people who are applying for the same job. Excellent. So what do you think?
I mean, we're running a little bit short on time here. What do you think is the greatest challenge in security today, and how might you address it? Keep in mind that I'm not asking you to solve it. I just want to see if we can identify, at least to you, what's the biggest challenge? Well, that I could probably talk for an hour about that.
But from a technology standpoint, ransomware is the symptom of the problem. The real problem is our lack of ability to spot the kill chain, to have the tools, to have the trained people to be able to see these things as they're happening. Because if they're, if they're already executing ransomware, it's too late. They've been in your systems for, for a long time at that point to build an infrastructure to be able to hit you quickly with ransomware. And so it's that simple.
The problem is really still not having the, the budget that we need, not having the people who are trained well enough or have enough experience yet to be able to utilize our stuff and go in and detect on those things. The detect is the most important part of it, right? You, you've got to see it coming in. And if you see it coming in, then you have a chance. If they can get in your system and do support Trojans and they're moving laterally, they're escalating privileges, they're gaining persistence.
At that point, you're just— it's the game is over, right? They already own you and they can do whatever they want to do. And now you're just in, you're just in response mode, right? You're in reactive mode. And so That's really, really important, I think, from a challenge.
Preparation and detection, really knowing your environment, knowing what the business does is really going to help you. What should and possibly should not be there. Yeah. Do you think that it is that dry? Is that black and white?
Oh, absolutely. I mean, it doesn't matter what I'm protecting, right? It's just the same thing as if I'm protecting my home. Right? I've got to be able to detect these things.
If somebody's trying to break in my house and I don't know about it, they're going to be in my house and that's too late. I don't want them in my house. I have to be able to detect and then block it. I don't want them in my house where you have kids and everything else. I got to keep them at the perimeter, keep them out.
And if I can't detect on that, then I'm just out of luck. Okay, cool. Well, Fritz, I want to thank you for your time. Again, this was Randall Frietzsche. So that's Randall, F-R-I-E-T-Z-S-C-H-E. You can find him out on LinkedIn, connect with him on LinkedIn.
He's also, of course, in the Colorado Equal Security Channel. Great guy. I've actually had several dinners with you, Randall. Always had a fun time with you. But again, thank you for your time.
My name is Frank. For those of you that don't know who I am, along with the podcast, I help run the Denver OWASP chapter. We have a meeting coming up next week, April 17th. So Randall, I hope I see you there, or Fritz, I hope I see you there. It's going to be a great meeting with the CEO of DeepFactor.
But otherwise, uh, I'm sure I'll see you in other circles. And I want to Thank you for taking the time and the opportunity to speak here. I also want to thank you so much for your service to our country and to our profession. And sir, I would like to say the same thing to you with the law enforcement. Again, it, it's got to be a great thing or a very hard thing, I would say, to protect people that may not want to be protected or not recognize that they need protection for certain things.
Again, thank you so much. I appreciate your time. I know we have a hard stop soon, so I hope to see you, see and talk to you in the future. Have a nice day, sir. Thank you.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.