Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode— what are we at? 263, Alex.
263. How about that for an audible, Robb? Didn't even remember the number. Oh, what But fortunately, I did some pre-work and I wrote it on the top of the screen here. That's good.
Good job. Yeah. Way to be prepared. It's for June 10th. We're well into the summer break now.
Not the literal season of summer, but it feels like summer. It's warm enough. It's been warm. I guess you were out of town. I was out of town.
You got back and it's going to be a little bit cooler for a few days. So good for that. It was. But my house was I mean, I got back on Friday night. It was very hot.
It was like 95, I think. Yeah. You got back for the hottest day, but that's, uh, that's all you had to worry about. Well, but you know, beautiful, beautiful summer, ready to get going now, now that we're back from our vacation. Um, Alex, should we jump into some housekeeping?
What do you think? Let's do it. Uh, Robb, do you know we have a Slack workspace? We've got a bunch of people in there always talking, lots of good conversations. If you're not there, you should get there.
Go to the website, colorado-security.com, fill out the form, we'll get you added. While you're there on the website, join it, sign up for our mailing list. That'll get you the weekly show notes and occasional other news like our volunteer events. And I don't know, you know, once, once every few months we come up with another thing to share out with the list. We'd love it if you would rate us and subscribe on your favorite podcatcher.
Maybe while you're at it, tell a friend, tell someone who you work with, the Colorado Equal Security Podcast is amazing. And they should be listening. Yeah, spread the word, let 'em know. Also, if you'd like to support us financially, we do have a Patreon campaign. It helps pay the bills, hosting, you know, doing things like a summer picnic and other stuff like that, which, as I say that, we should probably figure out when— We should probably figure that out.
When we're gonna do our summer picnic, Robb, since we just said it's summer now. Also, you can find information about that on the website, colorado-security.com. And let's jump into the news. The first article is a, is a big headline for what I'd say is not that big a story. But Denver is named the best U.S. city for foodies.
Can you believe that? Yeah, I think like many of these stories we end up putting in here, this one's BS. But, but, you know, somebody came up with some formula for deciding it and the numbers for Denver worked out. So don't be dismissive. It's not just somebody.
This is one of the most respected websites out there. It's the Cookie Rookie website. Cooking, you know, that, that super respected. I heard they won a Pulitzer last year. As, as we are being a little bit sarcastic, it's, it's actually kind of fun though.
They, you know, they, they show the equation that they use to determine that Denver is the best for foodies. And there's some legitimacy to the, to the format they use, right? Yeah. And you know, to be fair, the, it's not saying that we have the best restaurants or it's the best town for food or anything like that. It's, you know, it's kind of, Prices are reasonable for good food and there's not, not too much problem getting that food essentially is what I got from the— Yeah, the prices are reasonable.
There's a lot of high-quality fine dining, but, but like you said, not, not too expensive. And there's— they include social media as part of it. So there are, you know, a lot of Instagram posts about food here, which doesn't— I guess if you're a foodie, that's important to you, right? I don't want to yuck your yum, as my friends Josh and Chuck say. Don't want to yuck your yum, that's for sure.
But yeah, no matter how good it looks on Instagram, it still doesn't change what it tastes like. You know, what I've realized is I really like food, but I'm definitely not a foodie. Like, I really like food that is good, not food that looks fancy or is hard to get or is popular, really. Yeah. Yeah, I'm mostly in that camp.
I'm probably a little more of a foodie than you, but I also don't post pictures of my food. So can't be that far down the road. All right. Moving to our next story. We have a blog from Husch Blackwell.
This is, this is actually real news, right? Colorado passed our first-in-nation artificial intelligence bill and it's been signed by the governor. The rest of what we're going to talk about today, not real news. This one, this one, real news. Yeah.
So, I mean, this is big news. The, this bill was passed and the governor, since this blog has signed it, And it is the first bill in the US to really regulate and help prevent bias in generative AI algorithms. And one of the only drawbacks to that, I think, is that it doesn't go into effect until, I think, 2026. Right. February 26th.
So who knows, maybe even generative AI may not even be around in 2026. I think that's very likely. Or people may not be around in 2026. That's much more likely. The revision to this may be written by AI by then.
That's right. But the— I thought there's a lot of interesting stuff in here. This— the framework that we used in Colorado was actually created by a multi-state working group that was led by a senator from Connecticut. And the same format was put together for a proposal in Connecticut that ultimately did not get signed by their governor. But this basically is a, you know, were trying to like just have a multi-state approach to how should AI be considered.
They looked at AI not just from, well, from 2 different perspectives, from the perspective of those who create AI decision-making systems. And you could think of that like a vendor who sells AI stuff, I think, or someone who does it internally. And then there's the other side, which is the deployers of it. So, you know, as a company that maybe uses AI for part of your decision-making process on mortgages or your, what your rental decisions, whether you're going to allow a renter to sign a lease with you. If you're deploying AI, you also have requirements as a part of this regulation, this new law.
Yeah. I thought that the, the multi-state approach was really interesting. And I sort of, as an aside, I wonder if that happens more often and I just don't know it, but that seems like it's a really good approach for things. It's really cool. If they don't, maybe we should do this more often.
Problem is like you can see what happened here is, like, you know, the 2, 2 different states proposed— had the same laws, and one got in, one did not. Yeah. So it, it's not gonna solve the problem anyway. Yeah. Some additional things in here.
The bill does not contain a private right of action. So essentially, you cannot sue people for this. Only the attorney general can bring suits if someone misuses generative AI according to this bill. And the, the 3rd thing, there was part of it that that talked about overall artificial intelligence, general artificial intelligence, or, you know, general purpose. Sorry, not, not general.
We don't, we don't have that yet. General purpose. And that was removed from the bill before it went through. I do think it's worth reading if you definitely, if you are creating AI systems in your work. But if you are, if you're deploying, it's worth reading as well.
They do have a nice, what, like 5 bullets for what you have to do as a deployer. You have to have a risk management program that that looks at the risk of deploying your AI. You have to have an impact assessment, understanding the impact if that thing is misused. You have to have notifications to customers talking about the fact that you do this. You basically have to make it public that you're using AI and how it's— how decisions are being made and how you are avoiding the risks to it.
You have to have the right for an appeal. So if your AI leads to a denial decision, there needs to be a way for consumers to appeal that decision. And finally, you have to have disclosures on your website, basically write it all up there so it's publicly available. Yeah, I wonder if this will just, you know, get put in with a privacy policy or something like that in the future. Seems like it should.
It's all part of— this all actually gets rolled into Colorado's Consumer Protection Act. Yeah. Which the— what's our CCPA? CPA, the Colorado Privacy Act. The Privacy Act is one of the articles within that act.
So this is going to just be another part of the The Colorado, whatever, that thing. I already said it once. All right, moving on to our next story. A Denver area community college is the first to join the Space Force to help teach aerospace workers. I feel like Arapahoe Community College has done a bunch of cool stuff and really leaning into technology and industries that maybe you wouldn't think that community colleges place to go.
You know, I don't know, like growing up I would think community college is a good place to become an accountant. I know like dental hygienists go through it sometimes. There's, there's a few like kind of really specific industries and it's interesting to see them broadening into a much wider set than I would have thought of. Yeah, I think, you know, some of it is the push for, uh, getting people into the workforce as opposed to people going to 4-year colleges. And so, you know, many community colleges are jumping on that bandwagon.
I think beyond that You know, this is not something that in my head I would have thought, oh, we need a, you know, specific training program for people who are going to be working in aerospace with the Space Force. But apparently we do. Yeah. So Arapahoe Community College hired former Air Force Colonel Tom Coakley to be the school's academic dean and head of the Aerospace Institute that they've created. Really, I love the way he talks about this.
He's, he's not just saying, hey, we want to have classes that teach you about aerospace. He's saying we want to teach everyone in the different programs about aerospace and, and what things like orbital paths look like so that as they're, you know, as they're looking to whatever profession they're going to go to, they can just be more well-informed about this. And it makes— it sounds like security in some ways, right? Like you just want to know the context that you're working in. Well, and some of the things that they're trying to put this into are areas like data analysis, cybersecurity, spacecraft operations, and other non-engineering jobs that are expected to be key in the space industry.
They do mention that the average pay for an aerospace job is 30% more than the average STEM job, which really surprised me. Like, yeah, STEM jobs are pretty well paid as they are. This is 30% higher. Um, pretty cool stuff if, you know, they're, they're looking not only to get people into a needed industry, which has a lot of organizations in Colorado, but one that pays pretty well. Yeah.
One last fact here. The Space Force estimates that 60% of the workforce connected to Space Command in Colorado Springs will be civilian. So there's going to be a lot of jobs for, for people working with the Space Force. I love it. They— I'll mention one thing before we move on to— they got to be the last.
They, they, they mentioned the EPIC Center in Littleton Public Schools. It's actually— my kids go to Littleton Public Schools. There's actually like this separate building that is specifically created for STEM industry So my kids can go take classes during the school day in like four different programs. One of them is cybersecurity, but one of them is aerospace as well. And that's that's a you know part of supporting this this really rich aerospace industry we have here in town.
Pretty good stuff. All right, let's jump over into the next. So this is I think this is like yin and yang here, right? We just talked about the fact that there is a lot of need for aerospace. Now this next article.
Is around the need to find people to do quantum jobs, quantum computing. Yeah. I'd say this is more like yin and yang. It's, it's basically the same thing for different industries. Right?
So it's, it's job shortages. You need somewhat specialized people for these, these industries. And community colleges are helping step up to, to train people for those. Well, we got the, the Center of Excellence for, for quantum computing right here in Colorado. Yep.
As, as I looked at this article, I'll tell you, I, of course, the need is the same. There's an industry that needs a lot of people. But this didn't seem nearly as appealing to me the way they wrote this article. Well, they need a lot of, it sounds like, mechanics and techs and repair people. And it's much more, more hands-on type of, type of jobs.
Again, which you know there's not necessarily a lot of people of that ilk are aging out of the workforce, so we don't necessarily have those skills around anymore. But yeah, it's not not nearly as exciting as you know orbital paths and other things like that. But really, candidly, what I thought I read through this article in subtext was we don't want to pay these people very much. That's what I that's what I thought I read, and and I did take a moment to there's there's a specific company mentioned in here. It's Vessent.
I think you'd say it. Their CEO is talking about how. They've had a pretty easy time hiring PhD scientists, but hiring the engineers has been challenging. And when I looked at their website, they didn't actually have the hands-on techs job postings on there, but they did have other postings and they were all not what I would have expected in terms of pay. So I'm imagining that these hands-on techs are not super well-paid positions.
I guess it's not surprising, you know, aerospace and that sort of industry, there's a lot of money there. Right? Whether it's government money or other money, you know, quantum, while, you know, there is government funding to help increase this, you know, it's a, it's an early industry, right? Like, you're not going to go out and buy a quantum computer today, Robb. So it's not like there's a big market for this stuff right now.
It's still pretty early. So I imagine that they're pretty tight, trying to stretch every dollar on their dollars. And yeah, and some probably not paying as well because of that. Yeah. Well, we have a follow-up.
I believe that a couple months ago, we talked about a layoff at Guild Education. That was, I think it was 12% of their workforce at that point. A significant, significantly larger layoff just occurred in the last month here. So they talk about having laid off a quarter of their employees. They didn't say the specific number, but based on estimates, it looks like about 300 of their 1,200 employees were probably impacted.
Yeah, that's a big number. And it's a little bit sad, but also, I suppose, not surprising. You know, this is the kind of stuff that seems to be going around a lot right now. Everyone is still belt tightening. I think people thought, you know, sort of second half of last year, early this year, that we were going through all of this stuff and maybe we were through it.
But it appears that we're still, we're still belt tightening and people are still optimizing their workforce. Yeah. And I know that these, all these euphemisms, just, they kind of blend in and just sound like corporate speak. I'll just give you my take on what this probably means. It probably means that Guild got a really high multiple on their last fundraise that said that they were worth, you know, many billions of dollars.
The multiples for companies like Guild and just about every other private company have gone way down. And so in order for them to justify, how do we use this money we've raised in the past? And are we gonna have to raise money again in the future? 'Cause we're not profitable yet. They just have these choices to make, right?
They're never gonna be able to raise money at that same multiple. They're not growing fast enough to grow into a bigger multiple. Or a bigger number. So they have to make a decision. Do we, do we lay people off, or do we, do we go make— take a really bad fundraise that, you know, kills everyone's share or option value?
You know, it sucks, right? It, it doesn't mean that Guild is not doing well. It, it really doesn't. It, it— they could be. I don't know if they are or not.
They could be doing fantastic. But these kind of layoffs, they, they just really mean that the macroeconomic conditions have changed, and they don't want to go raise money with, uh, with their current spend. Yeah. And, and I think, uh, I think in these, these economic conditions, you know, there probably is a slowdown on companies, uh, spending on the, you know, the workforce training, uh, piece that, that Guild does. Uh, when times are good, it, it's easy to give sort of, you know, additional extra benefits to your employees, but when they're not, maybe you cut back on that stuff, even if it's not completely.
Uh, you probably, you know, limit the amount of, uh, of spend you're gonna have with a company like Guild. So, you know, that growth that you mentioned probably isn't, uh, quite as steep as it was previously. Yeah. All right. Well, let's jump over to security news.
You know, we love to, to talk about local security companies each month, and this month we have a new security company we can talk about. That's awesome because we're gonna have a story later where we're gonna have one less security company. So sort of, yeah, we're gonna have one less. Um, Anyway, so Catalyst, which is co-founded by Dustin Lair and Stanley Harris. Dustin is a friend of ours.
We've known Dustin for a long time. They've just come out of stealth with a company that is helping for you to create security champions programs and increase your security through essentially, you know, encouraging and gamifying behavior of your employees. Yeah, you know, Dustin has run AppSec. He's actually been a developer and run AppSec for Staples and Five Tran, and I believe another company in there too. Um, he's done a fantastic job really building a brand around what does it look like to build a community around security within your business.
And they've, you know, now got a company that the whole purpose of which is to help security teams build that community, right? It's gamifying and, and making it really discrete steps to go from developers who maybe don't care to developers who do care. It's pretty cool stuff. It is pretty cool stuff. Uh, we talked to Dustin and Stanley, you know, early on in their journey prior to them coming outta stealth.
And, um, it seems like it's a, it's a cool concept and pretty excited for them. Uh, this actually came out, this article came out right before, uh, RSA and I saw both of them there and they given some talks and things like that. So it was good times. Good stuff. And just as a reminder, we did have Dustin on the show about 6 months ago.
If anyone wants to listen to, to him share his story, uh, you can take a look. A look at that in episode 242. All right, next story. This is what I was alluding to. We're— an announcement here.
LogRhythm and Exabeam announced their intent to merge. And I won't read you the marketing speak of everything else in the headline. But, you know, 2 SIEM companies coming together as one. Yeah, you know, Exabeam started as this UEBA thing, right? User an entity behavior analytics, looking for suspicious activity by your users.
Along the way, they pivoted into being a real SIEM company. I'd say that neither Exabeam nor LogRhythm, although more LogRhythm, has really had a big mind share in the SIEM market. Yeah, man, it feels like it's been Splunk and folks like Sumo. Yeah, the— these, uh, I don't even think Splunk's newer at this point. They just, they just have this, this grasp of the market that it's It's really hard for other folks to compete well, I think.
So it's interesting to see what, what does it mean when you put 2 of the not winners together in this situation? How do you deal with that? Yeah. I also think, um, you know, my reading between the lines is, uh, you know, Logarithm I think has been struggling a bit. You know, they are, they were one of what I'd say sort of the original sim companies.
You know, they've been around an awfully long time. Yeah. Um, back when, you know, sim was a new thing, they were, they were one of the players. And I think, you know, they were a little late to the game in, you know, cloud-hosted SIEM and cloud-native SIEM and all those sorts of things, which Sumo and, you know, other folks like that really, you know, came on strong in. So, you know, it doesn't surprise me that they needed to get together with somebody else to help move the journey forward.
So presumably there'll be some kind of a collapsing of the products into one. Obviously a great customer base on the LogRhythm side with historically happy customers. It'll be interesting to see if they can get those folks to move to, to the cloud. Anyway, interesting story. We don't yet know what is the new company going to look like?
Where are they going to be headquartered? What's it going to be called? I don't think any of that's been announced, right? Nope. Yeah.
So, so looking forward to hearing about that. Hopefully there will still be a big presence in Boulder either way. Yeah. All right. Next article.
You know, Robb, for this article, I just have one question for you. What is liveness detection? Well, if you want to read about 3,000 words, you can, you can learn that really quickly in this blog post. Actually, this is, this is a pretty good blog post. It is.
I, you know, we're used to these kind of blog posts that go into a lot of detail with our Red Canary friends. This Ping one, honestly, I was really impressed. Liveness detection is the ability to, when you're doing biometric authentication of a person, how do I know that it's really the person alive versus a picture of their face or, you know, a copy of their fingerprint or whatever it is. Um, this goes into describing that pretty simple concept, like I said, in a lot of words that go into a lot of detail. Why would you need to use this?
What are the, what are the attacks bad guys might use to overcome your liveness detection? A lot of good detail. Yeah. And, and of course, when I think about this, I think of CAPTCHA or other puzzles like that to determine that you're a human. But they talk about many other methods that you could use, uh, or that are used here as well.
Like 3D depth sensing. Exactly. That's totally right. Texture analysis. Right.
All kinds of stuff. All kinds of stuff. So if you want to know more about liveness detection, check out that article. Good stuff. Final article of the month.
We actually do have a blog from Red Canary, but this is a blog describing a new tool that they've created. So it's the, it's a tool they created about how to evaluate what EDR solution is right for you and your company. And this, this blog post just goes into describing what this new tool is. Yeah, pretty cool. Um, I think, well, you know, EDR is, is still at the heart of Red Canary.
You know, they do, um, you know, detection response on many other things besides just EDR data these days. But, uh, you know, EDR is important for them. So having their customers pick the right one is super important. So this, it doesn't surprise me that they would come out with a tool like this. Yeah, they, they do talk about the 5 things that you're going to want to look at when you're choosing your EDR are visibility, alerting, prevention, reporting, and response.
Those are the 5 categories. If you get the tool, you can get a lot more nuanced than that. Sweet. All right. That is the news.
Why don't we move on and talk a little bit about some upcoming events? All right. As a reminder, we do have a calendar of events on the website with stuff going up to the end of the year. Uh, go ahead and get out there and take a look. But this coming week, it's a big week here in Denver.
It is. Yeah. Hopefully you're listening to this on Sunday or Monday and, uh, you still have time to get to RMISC on— what is it— Tuesday the 11th through, uh, Thursday the 13th. Yeah, it's the big conference of the year. I'm looking forward to seeing many of my friends.
I think I'll only be there for one of the days, um, but it should be a good event. It's always a great event. Some good speakers this year. Looking forward to joining folks out there. On Friday, we have BSides Boulder.
This is a, you know, a fantastic event that if you're— if you maybe don't want quite so many people, if you want to— if you want to be able to wear more casual clothes, you can wear whatever you want to RMIC too. But, you know, it's a more laid-back feel at BSides. This might be the right event for you. On June 20th, the Let's Talk Software Security group, which is also led by Dustin Laird, is doing a meetup, Quality Test Security Outcomes: Are We There Yet? On the 25th, CSA Colorado is doing their June meeting.
The topic is Modern AI Threats and Challenges. And on the 26th, ISC² Pikes Peak is doing their June meeting. And that is it for our news. Let's jump over to jobs. I have a job that we're hiring at Pax8, looking to hire an IAM architect.
That's on my team. And we'd be happy to talk with any folks who are the right fit for that. Maybe on Slack. Bank of America is looking for an Azure Senior Cloud Security Engineer. The State of Colorado is hiring a Senior Security Administrator in Audit.
CoBank is looking for a Director of Internal Controls and Operational Risk IT. Well, that's interesting. Yeah. Maxar is hiring a Senior Information Security Specialist. Gates Corp is looking for a Cybersecurity and DLP Specialist.
Quizlet, not Quiznos, Quizlet is hiring a staff cloud security engineer. Flexential is looking for a manager of security architecture. And finally, Western Union is hiring an information security engineer. All right. Alex, do we have an interview this week?
We do. We have an interview this month. I talked to Guy Sereff. Guy is a partner at Michael Best. He's a privacy and security attorney.
We had a nice conversation. Uh, Guy and I are in a whiskey club together, so we talked about privacy and security and a little bit about whiskey. I love it. All right, well, that's it. We'll look forward to seeing you all in July.
Thanks, Robb.
Hello, this is Stanton Meyer, CSO of Covant. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equal Security. This is our feature interview, and today I have a special guest, Guy Sereff. Guy is a partner for privacy and security with Michael Best. Welcome, Guy. Thank you, Alex.
Good to see you or hear you for the people that are listening.
Interested to get to talk to you today. You know, while we know each other, I don't know that I know a lot of in-depth things about you and your history and your background. So I'm cool and excited to hear about that. Yeah, definitely. So I've been practicing for 14, 15 years, all in Colorado.
Came out of law school at the wrong time for lawyers, right? The time when nobody could get a job and but got lucky and found a job with a mortgage services company that was doing HAMP and HARP loan modifications back for, you know, 2010s timeframe. Stayed there for a few years and then moved over to Level 3 Communications, which those in Colorado probably remember them before they were acquired by CenturyLink. And that was the post where, you know, after CenturyLink acquired Level 3, continued working for them for a little while, really building out the GDPR compliance program for the combined company. All of that was building on, you know, privacy and security work that I'd been doing since early on.
So, you know, shifted from Graham Leach Blyley and HIPAA now to GDPR. And then a little bit after the the acquisition completed, went outside, went and joined a Denver firm in their privacy group. I was there for a little bit of time, but then joined a much larger team at Michael Best. We're now, our team, we've got myself as well as 3 other associates in Denver and then 4 other attorneys spread out throughout the country where we really focus on all aspects of security and privacy compliance, risk mitigation laws, and been there for just coming up on 4 years. And, you know, work with companies both domestic and international.
And it's been fun, you know, not to, you know, obviously just watching the laws change, but also seeing how companies have matured and grown, especially those in Colorado, of, you know, addressing our particular, you know, particular legal issues that come up now that we've got the Colorado Privacy Act, just have the new Colorado AI law, and then also the pressures that come from other states and federal requirements as well. Well, that's awesome. There's a lot of stuff to dig into there. Oh yeah. I am gonna go back in time a little bit though.
You mentioned at Level 3 and CenturyLink building out the GDPR practice there. What is it that— I'm sure that was some of it, but what is it that really got you into focusing on security and privacy as part of your practice? Because, you know, that I think probably when you started that, that was a much smaller practice area in general for lawyers altogether? Oh yeah, it was. There's, you know, there's kind of 2 classes of privacy and security lawyers at this point.
There's those of us that now, you know, gray hair, losing a lot of our hair, right? We've been doing it since before it was cool, before there were really laws out there or they were very focused laws. And so the way I got into privacy and cybersecurity Funny enough, it was actually pre-Level 3, working for that mortgage services company. We had a question come up about our red flags policy and how we were complying with the Gramm-Leach-Bliley security requirements. And that was a legal team of 3.
And I was the one that got along with the IT folks, right? That's, you know, that's kind of always been, you know, my, you know, outside of work, right? That's always been my cohort. And I was the one that got along with the IT folks. I was the one that understood what they were saying.
And so my boss, the GC for that company, said, all right, you're gonna go learn privacy law. And so that's where I really started in on privacy and security. And then that same company a year or so later went self-insured. So we had to become compliant with HIPAA. I had to go learn HIPAA and, right?
So it really, my role started to shift from pure legal to being more of an ally on the legal side with the technology groups so that we weren't just looking at, well, what does XYZ law say? Because it doesn't, but more what are contractual obligations we have? What is the risk mitigation that we can do? And so that's really where all that started and that continued on, right? Level 3, CenturyLink was working with the CTO's office and the CISO's office probably more than any other group.
And it was really, let's design a strategy that mitigates risk. And I've continued that along in private practice now. You know, my statement to clients is, look, I'll tell you what the law says, but ultimately what I want to drive at are going to be pragmatic, practical solutions that can keep you operational, while managing both compliance obligations, but really bigger, you know, mitigating risk at an acceptable level. Yeah, no, that makes sense. I think it sounds like for a little while there, you were essentially functioning as the, you know, as a privacy officer, even though that was not a term back then.
I think as things have evolved now, we've got more and more of that type of practice, that type of position. And it seems like more than not, you know, inside counsel does fill that role. Is that what you see? Yeah, I see it a lot. It really goes one of two ways.
It's either inside counsel is serving that chief privacy officer or data protection officer role. Or it lives in the IT operations side, right? And both of those approaches can work and do work as long as they're designed the right way, right? Because if it's all— if legal is the one that is sitting as the CPO, DPO, great, but make sure that you're, you know, we talk with folks who are like, make sure that you're bringing in the IT folks because, and it's not just the IT folks, right? It's operations as well, right?
Data lives everywhere, data gets generated everywhere. So it's got to be accounted for and protected everywhere it goes. Well, if we, anytime you isolate, right, there is the, you're gonna start missing things. And so really, I think it typically breaks down organizations that have a higher obligation for compliance with specific laws, specific frameworks typically are gonna park their CPO in the legal department. Those that are maybe less regulated or there is a competing, there's a, you know, there's a complex architecture for the data, you know, distributed networks, really, then it starts making sense.
Let's park it in IT so that, or sometimes it doesn't necessarily make sense to park it in security just because they work together, but they can be at odds at times. But parking it where it's gonna have the best value as far as on the IT side. All right, we need to make sure that operationally data can still move. We know where everything is. That's when CPO sits in the IT side and the legal serves as a, you know, as a here's your guide, here are your compliance obligations, make sure that you're addressing X, Y, and Z. Yeah, no, that makes sense.
Going back into your history again, you know, you were internal for several jobs there and then you decided to go outside to be outside counsel.
What really made you make that switch? Was it just looking for, uh, you know, broader practice areas, uh, making more money? Like, what, what was the, uh, uh, the, the goal here in, in, uh, branching out and going outside? Yeah, there, there, there were a couple driving factors. Um, so one, I was at CenturyLink and I was looking at, uh, all of the folks in the org chart above me and one consistent item on their resume was outside counsel experience, right?
And so, you know, this was back, I had more hair, less gray then. And so I was like, all right, well, if I ever want to take that next step in an in-house department, I've got to get some outside counsel experience. So that was part of it. The other side of it was it was a logical transition point, right? We had just come off of building out the compliance program.
We were going to be largely operational. This is also before all of the state privacy laws had started to erupt. I mean, we knew California was coming, but it was still kind of all in flux. And I was really looking at, all right, I need that opportunity to continue to build programs. I prefer the program building side.
And if I've already built one in-house, right, I'm just gonna be maintaining it. By going outside, now I get to work with different clients across different industries, which means that have different risk tolerances, different issues to solve for. And it's the joy of solving the puzzle. But if you keep pulling the same puzzle out of the box, all you do is just solve it faster. And so that's really where it's gone.
And then the move ultimately now where I'm at Michael Best, a very diverse base of clients, which means that we hit every— we've got clients that hit every single one of the different compliance structures and different laws that they've got to comply with, including those that are— they operate in a way that doesn't subject them to compliance with any of the legal requirements, but they still have to operate within certain bounds created by those because that's their, that's the expectation of the industry that they're in. And so lots of, lots of really fun, you know, head scratchers that we spend our day solving. Yeah. Well, now that you've done it for a bit, you've had this outside counsel experience, do you now go, oh, maybe I should go back and be a general counsel somewhere, you know, be a chief privacy officer, be you know, something internal somewhere to run these programs for a company? I haven't reached that point yet because I still enjoy the different clients, working with different folks.
I could see going in-house. I don't think I'm quite— GC might make sense, but it would have to be for a particular type of company, right? It's gonna be a tech or data-driven company. But where I am seeing, and, you know, and this may be something down the road, is I'm seeing more folks kind of my ilk, right? The technology lawyers that are, you know, probably more technologist than lawyer at this point, really moving into CISO, CIO offices because it's turning into— these are the— this is strategy.
Right? This is the— this turns into long-term strategy, comes into long-term risk mitigation. That's what we're trained to do as lawyers. And so there's a possibility that I'll find myself in-house again one day. But, you know, I would say it's probably later rather than sooner.
Yeah. And I hadn't really thought about it, but that is a good point. I do know a few CISO colleagues who are also attorneys. So I can see that happening. You know, the CISO role, as you know, is changing over time and becomes more and more of a risk officer type position focused on a certain piece of risk.
And so understanding risk and being able to manage risk is a super important skill to have there. So, oh yeah. Well, and not to mention, you know, certain 3-letter agencies, you know, are toying with the idea that CISOs can be personally responsible, right? There's— we're, you know, as attorneys, we're all Type A crazy types that, you know, yeah, we'll take that risk on. And so, I mean, I think we're gonna— honestly, I think we're gonna see more and more of that.
There's been an uptick, you know, kind of looking at, you know, what are— in law school, they always tell you, oh, well, you know, get the law degree and there's so many other jobs you can do, you know, so many other things that are available. I still haven't really come across too many of them. But looking at the kind of, you know, data as far as lawyers that transition into a non-legal role, security and information operations keep on ticking up the list as far as the most common landing spots. No, that's really interesting. Yeah, it's— I played soccer in college.
And my, my college coach, his advice to every one of his, uh, graduating seniors was go to law school. Um, you know, this was also a college where many people went on to graduate degrees anyway, but, you know, his contention was, um, you know, in order to be successful, knowing the law is really important. So even if you don't go to be a practicing attorney, Uh, going to law school and understanding that that stuff is, uh, is super important. So I did not follow his advice, but, um, you know, he held the same opinion that you do. So anyway, um, all right, uh, moving on to another topic.
So, you know, since you, uh, have many clients, you see lots of different things. Um, what are, uh, what are some of the things that, that you see that, uh, that people are either are not doing right or should be doing better. And maybe also we should preface this with our standard lawyerese of Guy is a lawyer. He's not speaking in the context of a lawyer. He's not giving legal advice.
This is only his opinion. So nobody come back and try and say we gave you legal advice. Yeah, you've been around me too long. Yeah, that was perfect. No, the things that I see and I really addressing one of the, I think one of the biggest misconceptions that I run into time and time again is not fully appreciating the scope of the legislations that's coming out, right?
Yes, 10 years ago, You could, you know, solve privacy, you know, specifically privacy issues. Well, we'll slap up a privacy policy and we're good to go. That's— yes, privacy policies are required under, you know, Colorado Privacy Act, CCPA, GDPR. That's the tip of the iceberg of what these laws really actually apply to. They're more backend laws.
It is, and it— I won't go into all the nuance of it, but, you know, to give a nice high level, it's forced data governance is really what these laws are turning into, right? We're, you know, and that's tough. We haven't, you know, different companies, different clients, they have all approached data governance in their own way. For, you know, they haven't, decades and decades, or they haven't. You said it first, not me, but they haven't.
But now to have to shift and say, all right, you can't necessarily do it your own way anymore, and you've got to fall within these buckets, or at least make sure that you're addressing all these things that you may not have thought about, or, you know, were never really, you know, in scope, that, that's where I see so many companies hit that struggle point of, what do you mean I have to, do I really have to map out every place where I have data? Yeah. Well, but are there exceptions to the law? Sure. But those exceptions may apply to one thing, You know, so a data map, I actually just had this conversation yesterday with somebody.
GDPR gives a, has a small business exception for creating your records of processing activities. Okay, great. That exception is way more narrow than you think. I know everybody stops reading if you've seen it. Apologies for the repetition.
But what that exception is, is, hey, if you have less than 250 employees, you don't have to create a ROPA unless your processing of data falls within one of these 3 buckets. Everybody stops reading before that unless starts and says, oh, we're under 250, we don't have to create a ROPA. Even if you don't have to create that ROPA or data map or whatever term it goes by, That exception doesn't say, oh, you don't have to have documented security, you don't have to respond to data subject requests, you don't have to manage cross-border data transfers. All of that data is in the ROPA, it's in the data map. And so there it's one of those we really are working and I think we'll get there and we get, you know, more and more buy-in year after year.
Of understanding just because there isn't a requirement to do it, or just because there's an exception, this is not necessarily an area where you look for every loophole, you look for every exception, because those exceptions are very specific and they, they wind up— if you don't do one, then you're going to fall down on another, you know, on your ability to comply with another requirement. The data subject request is the biggest one that I see. It's, well, we didn't do it, you know, we don't have a data map, we don't have a ROPA, we got somebody that asked for all their data to be deleted. Okay, how are you going to find that data, right? Where is everything?
Or on the security side, right? We have a, you know, we've got a security incident. Okay, how are you going to be able to quickly figure out what's been compromised if you don't know where anything is? Right? So a lot of this is, you know, this is that classic, an ounce of prevention is worth a pound of cure.
It's probably an ounce of, you know, I would say here it's probably an ounce of prevention is about 10 pounds worth of cure because the, and you gotta, you gotta do it every time the situation comes up, right? So there are really moving past the We just have to have a privacy policy and getting more into the, what are the requirements? What are, you know, what's applicable, what's not, and what is a, just because we don't have to do it, we still should do it because here's the upside. And that gets into the other, the other, you know, one of the other biggest, big issues that I, that I see is there's not necessarily always a solid level of understanding across the entire strata of an organization, right?
Legal, IT, we're cost centers, right? We don't, you know, we, yes, we're a necessary evil, but we're a cost center. And so really in that, you know, and a lot of times that is, that's a mindset that comes from the C-suite. Where those of us in the legal and the IT space can really serve ourselves is, no, no, we're not just saying that we're going to do this because, you know, hey, we're going to do this thing we're not required to do and it's going to cost, you know, a good chunk of our annual budget, but we need to do it anyways. Really being able to say to the C-suite, to the other stakeholders, We know we're not required to do this, but if we do it, here's the benefit to the organization as a whole.
That's where the buy-in starts, and that's where you really start to— where I typically see organizations start to embrace that culture, and it allows for further operation because that's the other part of this. And the other part of, you know, one of the other parts of my practice is All right, once we get compliance done, now we can start talking about how we can leverage the data that we have for research purposes, for carrying out other development initiatives. But we can't do that stuff until we get all the compliance pieces in place, because now we know what we're operating from. Yeah, I think the other part there that I would say is, you know, sales enablement too, right? Like, I think if you have good data privacy practices, if you, if you can prove these things, it makes your, whatever it is that you're selling, it makes your salespeople able to sell it more easily and faster.
And it makes your, your customers more likely to buy from you because they can trust you. Oh, no question about it. And funny you bring that up. I'm in the middle of that with a client right now who's looking to acquire some tech for A/B site testing. And some of the language and some of the, you know, the technical docs as well as the agreements left us with some pretty big questions of Wait a second, we're not entirely sure that the vendor had what they needed or really fully content, you know, comprehended what the legal requirements are.
And so we went, we've gone back and forth the last week, week and a half over, well, but what does this do? What does this do? What does this do? To where I'm thinking, I'm like, look, if you would have just had a technical, you know, a support article, a technical article that addresses these issues without trying to dodge Because that's the other thing that I see is the dodging that opens questions. I know why you do it.
Hell, I talk to clients all the time about what do we say publicly versus what do we have, you know, right? Because everything that we, everything we publish, you know, everything that gets out there, that's a risk point. But And that's gonna be, I think we're gonna watch and see, you know, a development in the industry and just kind of in general over the next 5 to 10 years of learning how to say, yes, this is, we've addressed, we know what the requirements are, privacy and security, here's how we've addressed it and here's how we have worked it into sales enablement. Here's how we've worked it into onboarding. That's another pain point is because once you're, all right, great, you sold it.
But once we then get into onboarding and configuration, that creates a whole new set of, you know, issues. And as part of that whole sales enablement process, the one thing that I will, you know, as somebody that has to deal with this on both sides that I beg of everybody, The vendor risk assessments, it's time for those to get streamlined. And really, frankly, vendors, and you're gonna have to have this in certain circumstances, right? If you're gonna be a company that's gonna be, you know, subject to CMMC, or so that's for the DOD, you know, prime and subs, DOD's new security requirements. Or you're subject to the SEC's Regulation S-P, you now have to have an information security program, by the way, and you have to have an incident response plan.
All of those, right, we should be taking that, creating, you know, vendors should be creating their own, you know, here's our, you know, here's our control matrix, right? Here's what we're doing. Do it in a way that you're not giving away all the information. Nothing worse than handing over all of your detailed security policies and procedures that say, hey, here's how to beat me. But really opening that up so that instead of vendors having to spend time to respond to these risk assessment questionnaires that frankly, I see it happen every year, a new tab gets added to the Excel sheet That's asked, it has about 75 to 80% overlap of all the questions that were already in the sheet.
It's just things just keep getting, you know, they're not getting streamlined, but really working towards a sales process cycle where vendors are expected to provide their risk matrix, right? What is that? What do their controls look like? As opposed to having to spend time to answer as part of every RFP the same vendor risk questionnaire. Well, same in that it has all the same questions, but it's formatted differently.
And it's, you know, well, they ask this question slightly different. And there's just so much time that is spent and wasted filling those things out where standardized responses, I pray that that is the, that that's the future. And I think with all of the you know, now that security is kind of catching up to privacy from a legal standpoint, I'd say security from a, you know, laws on the books perspective, security is about where privacy was 5 years ago. And we're gonna see, I mean, we're already seeing it with the agencies, but I think we're gonna continue to see very much like privacy started to get some laws in place, We're gonna see the same thing happen for security. And so you'll have all these, you know, legal, specific legal obligations coming for security, just like you do for privacy, probably within the next— it's probably not even 5 years.
You know, we're already seeing it, you know, for particular agencies, particular industries. I think we're gonna see it at a federal level within the next— it'll depend how November goes. Probably 2 to 4 years. Yeah, one of the things that, uh, I always say is that, well, I mean, generally, I, you know, as a CISO myself, I like to treat my, my CISO peers nicely. And, uh, you know, that, that's always a good, good thing.
But one of the areas where we hurt each other the most is vendor and third-party risk management, um, because, uh, you know, I think we are we're in control of our own destiny, yet we, we let it get away from ourselves and, uh, inflict that pain on everybody else. I don't know if it's because we know that it's getting inflicted on us too, and, uh, and, and we want to, uh, to reciprocate because we feel like that's the way it should be done. But, uh, yeah, I definitely advocate for, uh, I mean, you have to manage your risk, right? Like, you have to be able to, to understand that the third-party risk landscape, but we've got to be able to do it in a way where we're not inflicting so much pain on each other. So yeah, yeah, no, yeah, I mean, and, and that, that too, I, you know, one of those areas, and I, I do see that kind of CISOs inflicting pain on each other of, you know, not right-sizing the requirements for who it is that, you know, who the vendor is and what they do.
Right? Not everybody needs to be ISO 27001 certified. They just don't. In fact, a huge chunk don't. So that doesn't need to happen.
And also too, and this is where the lawyers don't help, but I'll be the first one to admit this. But the terminology that we use, I do think also causes some issues. Right? So certification versus an audit report, 2 very different things. But I, you know, probably 30% of every agreement that I look at where it talks about SOC 2, SOC 2 certified.
SOC 2 is not a certification. But the reason why I bring that up and where I'm saying now the lawyers are causing problems and there's this conflict And if you've ever wondered why did the lawyer say, you know, strike certification from SOC 2, the reason is that because that's not accurate, right? If you say SOC 2 certified, we've now created basically an impossibility in the contract that in some jurisdictions, that entire provision could be thrown out because it's impossible. So that's where to making sure that, you know, we all kind of understand what is the— words matter, and really making sure that those— the way that we characterize stuff and the requirements that we impose are really tailored to what is the vendor doing, you know, what's the sensitivity of the data, and what is it— what's the reasonable expectation? Right.
If somebody has gone through a SOC 2 Type 2 and they don't have a bunch of, you know, and the report doesn't list exceptions that say, wow, this is Swiss cheese, that in most circumstances that, that, that's likely going to be sufficient. You still want to take a look and, you know, make sure you know what controls they were being assessed against. Because if, if I only had the control that says, Password isn't password. All right, sure. I'm going to pass my SOC 2 Type 2.
You know, I'm going to get a glowing report, but I don't have controls. So I think really all of us working together. And if you look at that, privacy is one thing, but security, if you look, it is that that's really the approach that's coming out of the federal rules, right? It's, hey, we all need to collaborate together. We all need to, you know, this is especially on the DOD side.
Right? This is declared, this is a national security issue, and that's everybody's job, right? So, and I think if we start to approach security with that, hey, we're looking to collaborate and not, you know, dictate you have to use this, you know, particular standard, even though, you know, you're a cloud-based service provider that doesn't provide bespoke services, we're going to make life easier and we're going to have a better understanding of the security of our data and hopefully not be caught with, what do you mean you had that vulnerability? You should have known about that. Yeah.
Awesome. This has been a good discussion, Guy. I appreciate your, your thoughts and insight. I do want to take a little bit of a turn as we're getting closer to the end here. And this is where some people might tune out, but other people might perk up.
I'd like to turn this to the Colorado Equal Security Whiskey Hour instead of, instead of talking about security and privacy. Guy, I, I might come to understand that you're a bit of a whiskey file. Maybe, maybe, you know, have sampled. Oh, I lost count a long time ago. Probably at least sampled say 600, 700 different whiskeys, bourbon, rye, Scotch, Irish, kind of across the board.
It's fun. I really like it. Well, there's definitely some, there's some sort of just direct draw of tech and security people to whiskey. So there's always, it's, there's always good community. But, you know, the stories behind it, the the, the, all the discussion.
And, you know, for, I, I think also too, for me, one of the, you know, one of the most fun parts about it is all the technological advancements we've made, all the, you know, high-tech stuff. That's still a, you know, we're still following the same processes from 300, 400 years ago, right? And so there's, there, there's something to be said about just sitting down and, you know, kind of It, it, it, if you, if you're like me, it makes you sit down and appreciate it and, and really just, you know, take it in, slow life down for a couple minutes, you know, have a good conversation with, with, with some good folks. Whiskey's a, you know, whiskey's a good way of doing that. Yeah, I, I think some of the reason that the security folks are drawn to it too is that You know, we're really just all alcoholics and we, you know, we need a reason to justify why we're drinking anyway.
Again, your words, not mine. So in a, in a practical perspective for some of the folks listening, because I know you're going to have some, some good insight here. If somebody wanted a, a really good, inexpensive bottle of whiskey, what would they— what should they look for? What may be some options? And They want something that's, you know, maybe a little more spendy and, you know, special occasion or, you know, splurge on kind of thing.
All right. So we'll, you know, there's, there, the, in whiskey, there is, there's 2 categories. There's the stuff you can get and then there's the stuff that, yeah, no, no chance of getting, right? And if you ever do get the opportunity and it's not, you know, crazy overpriced, jump on it. In that category, and I, yeah, I think you, I think you tried a little bit of this.
My, my ultimate, you know, I, I'll probably never see this bottle ever again, but my, my absolute top is Van Winkle Rye. Most folks have probably heard of Pappy Van Winkle. Well, that's all bourbon. It's fine. Frankly, my favorite's probably the the 15-year.
I think the 23-year is, you know, way overrated. But the Van Winkle Rye, that's my ultimate. If I ever see that bottle again, I'll buy it. As far as for everyday drinkers, it really depends on what, what you like. If you like, you know, kind of vanilla and dessert and, you know, a little bit sweeter, You're looking at the bourbon side.
The bottle that, you know, got me, got me hooked and, and pulled into this. It's a little bit pricier than it used to be, but it's still, you know, right in that, you know, $35, $40 price point. Russell's Reserve 10-year. It, that's a great everyday. You can find it all the time.
And it, it just, it, it's got a nice depth of flavor. It's, you know, You don't, you know, feel like you can only pull this out for a, for a special occasion. But that one's, that, that one's solid. Ryes, I jump all over the place. So ryes are a little spicier.
They've, you know, you'll, you'll get some more depending on who it is, but a lot of times you'll get some more earth tones to it. But oh gosh, I mean, ryes, I'll go for, well, Russell's Reserve again does make a rye. They're just pretty good. High West makes some really good ryes. They're out of, they're out of Salt Lake.
But really it's, you know, it, it, there are so many options at $35, $40 price range. Rye's gonna be a little more expensive, just it's more expensive to grow. But funny enough, right? I, I, I think a lot of ryes that are produced outside of Kentucky are really solid. Now, if we're talking special occasion and not the Van Winkle, if you can find it and it shows up every once in a while on the rye side, Michter's 10, Michter's 10-Year Rye.
That is a, that is solid. It's, it's actually my wife Kate. It's, it's her favorite. And, you know, she, she, she grumbles a little anytime I open it. But that one's a really good one.
And then on the bourbon side, really anything, anything from Booker's. So they do, they do limited release batches 3 to 4 times a year.
They, they, they, they are available, but not for very long. But if you can get your hands on one of those, you know, funny enough, it's a, you know, it's a product from Jim Beam, but it's really good Jim Beam. And yeah, I, I would say, yeah, as far as my, you know, special occasion open bourbon, Booker's is gonna always— and frankly, that's what I order most of the time if I'm out at a, at a bar and they have Booker's. That's what I'm gonna order. Um, though I am in Tennessee at the moment, uh, went out someplace, they had a Blanton's Straight from the Barrel, not the regular Blanton's that, you know, used to be $60 and now is $90.
And yeah, Maybe you can get it, maybe you can't. It's okay. I, I, I, and come at me. It's okay. Straight from the barrel is completely different.
It's so super good. And if you can find a good price per pour, it's one that I always, I will always highly recommend somebody try when they're out and they see it on a, see it on a whiskey list. Cool. Those are some great recommendations. Appreciate it.
I try. Well, we are just about out of time. Anything else you wanted to cover before we get out of here? No, I think this is great. Thanks a lot.
Thanks again for having me. And when I get back to Colorado, we'll have to have a couple pours together. Sounds good. Thanks, Guy. Thanks, Alex.
This has been Colorado Equal Security, and we will talk to you next time. Learn more about the Colorado security scene. At colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.