All episodes

CJ Cox, COO at Black Hills Information Security

Apple Podcasts Spotify SoundCloud

CJ Cox, Chief Operating Officer at Black Hills Information Security is our feature interview this week, interviewed by Frank Victory. News from Sundance Film, Valhallan, Red Canary, Optiv and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

This Week and Next:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript13000 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 267. This is for October.

Alex, we're doing a little bit different. We are, we are releasing on October 1st, which is a Tuesday. Yeah. I think this may be the first time ever we have not released on a Sunday. Maybe once or twice we screwed something up and released on a Monday instead of a Sunday.

I seem to recall, oops, I didn't hit publish. Right. And it go out on a Monday, but never a Tuesday. Never a Tuesday. We have a little bit of travel coming up, a little bit of conflict so that we thought we wanted to get it out in October.

So there you go. This is the October episode. We're technically recording it in September. But you're, but you are listening to it in October. Yeah.

So enjoy. And we just realized we are a third of the way to that illustrious episode number 800. Right. When we're both 150 years old, we will hit episode 800. Yeah.

If, if we're still going at that point, somebody please end it. Something went wrong on the retirement plan and, and we're still around. We must have some great sponsors by then. Or maybe it'll be AI Robb and Alex. Oh my gosh.

By then it could go forever. It could, could go forever. It's like James Earl Jones has passed away, but the voice of Darth Vader will live on. Right. Yeah.

Speaking of things that will live on, we have a Slack channel. The Slack channel is alive and well with about 2,600 members in it. We'd love to have you join. If you're not in there, go out to colorado-security.com, click on the Slack button, get signed up. While you're there, you might as well scroll to the bottom of colorado-security.com and join our mailing list, and you can be privy to all of the inner machinations of Alex's mind.

Exactly. Also, we would love for you to rate us and subscribe on your favorite podcast apparatus, whether that's YouTube or Spotify or any other listening service or subscription.

Please rate us 5 stars if you think we're good. If not, rate us 5 stars. Please tell us. That'll teach us. Exactly.

Tell a friend about Colorado Equal Security, all the great stuff that's going on. And if you want to contribute financially, we do have a Patreon campaign that we use the money to support things like hosting fees and our annual picnic. And we just want to do a shout out to our current patrons. We love you, appreciate you. Thank you so much for keeping us going.

We got it. We got, you know, 15, 20 people like consistently fund the show. And we really do appreciate you all. All right. Let's jump into the news.

Some film news, Robb. Yeah, it's a slow tech month, Alex. Boulder has been selected as a finalist, one of 3 finalists for the Sundance Film Festival in 2027. Yeah. So apparently the Sundance has happened since its inception in Park City, Utah, with a little bleed over into, into Salt Lake City because it's gotten, it's gotten much bigger.

But I guess the local business owners are not so happy. You know, Park City is a ski town and these things are happening during the height of ski season and it gets in the way of their ability to continue serving their customers. So, so other cities are taking a look at making bids to have the Sundance Film Festival move there. Yeah. And for context, Sundance is a 10-day festival that can bring as many as 50,000 visitors.

So I could see where a small ski town that is not expecting an extra 50,000 visitors could have a problem with that. So the finalists to have the Sundance Film Festival move in there— start, by the way, this is starting in 2027. This is not like right around the corner, a few years off. But the 3 finalists are, like we mentioned, it's Boulder, right? Boulder is one.

Cincinnati, Cincinnati, Ohio. And the third one is Park City and Salt Lake City. So I'm not sure why they're bidding if they're, if they're the reason it's not going to be there in the future. But we'll figure it out, I guess. I don't know, maybe they're doing this as a way to show what it would look like in the future if they stay.

There's, there's a lot of news in this article about, hey, you know, we've talked in the past about, you know, the Stanley Hotel, they're planning to build a film school slash museum up there. And there's incentives to try and get more movies made in Colorado. And I sat with this article for a minute today. And I thought, do we really care if movies are made here? Do I care?

Like, I love to win. And it's fun. It's fun to win things. But is it really a good thing for us if we spend millions of dollars to have movies made here? I think that there is some economic impact, you know, they do spend money while they're here.

So I think net-net, There probably is a positive economic impact, but I mean, I don't really care. I think we should probably do a little bit more incentivizing to get like tech things brought here. Yeah. This is an allusion to the future versus having the film things brought here. That's fair.

Speaking of national or global things that are showing up in Denver, did you know that there is a new Michelin-rated restaurant here in Denver? I do know that they released the this year's rate or Michelin star restaurants for the Denver Boulder area, and there is one additional Michelin star restaurant that is now on the list. That is Alma Fonda Fina, which is a high-end Mexican restaurant which opened less than a year ago. So it's pretty amazing that they got a Michelin star after less than a year. Yeah, this is the second year that Denver has has.

I think paid the money to have the Michelin reviewers come out to town and, and look at our restaurants and figure out which ones should fit. We now have 5. It's now 6 across the whole state, right? 5 in the Denver metro area, 1 in Colorado Springs, 1 in Vail. So it is now 4 in Denver, 1 in Aspen, and 1 in Boulder.

Gotcha. There's not, there's not one in Springs. There's not. Yeah, sometimes I make things up. It's all right.

Yeah. Anyway, it's exciting to see, you know, this kind of world-class food here. In addition to having the stars, they also do recommends. They recommend a series, a much larger list of restaurants. And I've been to a couple of those.

I've never been to any of the Michelin-starred restaurants, but I've been to some of the recommended ones. Garden Grace was on the list. I remember that. Yeah. My wife and I about a month ago went to one of them, the Wolf's Tailor, which is one of the 1-star Michelin restaurants.

It was pretty darn good. A little spendy, but pretty darn good. So glad to see that they are still on the list after going there. Good stuff. All right.

Our next story, we have news from a really a whole new sport is moving to town. I remember when I moved to Denver and maybe when you did too, people talked about Denver as being one of the very few cities that had all 5 professional sport leagues here, right? NFL, MLB, NHL, NBA, and MLS, the soccer league. Well, we are now also going to have several esports training facilities coming to town. This sounds like a brand new thing for Denver.

Yeah, I think that there's been a little bit here, but there's a new franchise opening up in Colorado. It is— Valhalla. Valhalla. I think that's how you say it, Valhalla. And they're opening, I think, 4 or 5 locations locations, or at least they've identified 4 or 5 locations where they would like to be, not necessarily that they're opening in all of those.

But the first one was open in Broomfield on August 24th, and the governor was there to help unveil. But this is a training center where they have multiple computers and gaming systems where kids can get access to different games. They have coaches that can help them. Uh, I don't know. Can't imagine that I would ever have said that there's gonna be people coaching kids on how to play video games, but there are.

Yeah. Uh, and so that, that's kind of what they're about. So, you know, the, the, at first thought it seems a little, little strange. Um, I, I do love that in, they talk about in their curriculum, they, they are making sure to ingest other or include other things other than just video games. They've got talking about the importance of stretching and how to build an online personality that's safe and, Um, uh, a lot of, a lot of things that are not just about being great at video games.

Of course, I'm sure being great at video games is at the top of the list. Yeah. Um, one of the other things that they talk about here is, uh, some other of the, the places that have existed prior to this. There's one called Localhost, which is in Lakewood, which has a 15,000 square foot esports facility that's been around for a little bit. Um, so it's, it's been here, it's getting bigger.

Uh, one of the other things I noted in here was at the bottom they talk about, uh, Cronkite Sports, you know, which, uh, the Cronkites own the Avalanche and Nuggets and things like that. Um, and a couple years ago they actually founded an esports division and, uh, bought a couple prominent esports teams, but it seems like maybe that's not going so well for them. And, uh, well, it's folded. It's folding or folded. The, the, the other thing I call pulled out of this article I thought was interesting is it mentions that over 100 local high schools have esports either clubs or teams.

That's a lot of high schools. And all of the local major universities here also have esports teams. Pretty cool. Good stuff. All right.

Next, 5 small businesses in Colorado rank among the U.S. Chamber of Commerce's top 100 businesses, 4 of them from Denver. They talk about the criteria used for this is 10 criteria: innovative growth, commitment to community, micro-business leaders, adaptability, customer service, global reach, digital innovation, legacy disruptors, and positive employee culture. Again, Robb, slow month for news.

So what are the 5? What are the 5 Colorado companies that made this? They are one is Woof. They make dog care products. Repurposed.

Talked about Wolf before. That sounds familiar. Repurposed materials. I think that that is pretty self-explanatory. Holladayley Brewing Company.

They make gluten-free beer. They are the only woman-owned and gluten-free brewery in the US. How about that? Here in Colorado. Yeah.

In Golden. The Cavern Men's Barber Lounge in Colorado Springs. What do they do there? I bet they cut hair. They— I think that they pair haircuts, beard detailing, and facials with a relaxing atmosphere and complimentary wine or beer.

How about that? Also, Vladenchonk Ciders and Coffee. Interesting that 3 of the 5 Colorado businesses have something to do with booze. Yeah, that's, that's pretty good. I think there's a theme there.

Too bad they're not giving any booze to the dogs. Not that we know of. All right, uh, moving on, uh, back to another theme that we've talked about a lot recently. Uh, there is a Colorado Sun article about Colorado's multi-million dollar investment, uh, in quantum and the 70-acre campus in Arvada that is taking shape because of it. Yeah, you know, we've— we have talked about this a lot, but I feel like I learned as much new stuff here as I have in several previous articles.

There's a lot of cool stuff. Kind of the headline piece for me was that the Colorado School of Mines has bought an old oil and gas facility. And they are— they paid for this facility for it to be used by the Quantum Tech Hub as like a campus where people can build clean rooms to allow them to start actually doing work on quantum computing in a shared facility so that all these smart small startups don't have to go create their own campus. Yeah, one of the, the quotes that I saw, uh, which kind of resonated with me, and, uh, it was that, you know, why this matters is that, you know, the Quantum Commons, which is what they're calling it, it's not 70 acres, just 70 acres. It's our Bell Labs, it's our Stanford Research Park, it's our Apollo program, right?

So it's, it's really a place where they're hoping magical things are going to happen. This is, this is where they expect the physical confluence of different companies, different, you know, brilliant people is going to turn into the commercial impact that's going to make a difference for Colorado. And of course, for the School of Mines, a chance for their students to be, you know, early on access to these types of materials. You know, really, really cool stuff. I'm excited to see where this goes.

Indeed. All right. Moving on to the security section of the podcast. Yeah, we've got, we've got a blog post here by Keith McCammon, the Chief Security Officer at Red Canary, the CrowdStrike Outage Detection and Defense in Depth. Yeah.

So again, this is talking a little bit about incident response and incident response plans. I think, you know, kind of jumping off of the CrowdStrike outage that we had a couple months ago, Um, you know, really thinking about, you know, how you need to be ready for incidents like this, whether they are security incidents or whether they're operational incidents. Yeah, I think that one of the things that he called out, Keith calls out in this blog post, is that Microsoft has called a summit, the Windows Endpoint Security Ecosystem Summit, scheduled, um, actually here, here this month, and, and bringing these folks together to figure out how do we avoid these things in the future? How do we get better at supply chain and think through the impact of changes on one another, uh, in this ecosystem. Yeah, hopefully they figure something out, um, because one of the reasons that this happened on Windows computers is that they— these antivirus makers have probably more access to the kernel than they actually need to.

Uh, so hopefully they can have some discussions there and back some of that out but still provide what's needed. Yeah, you know, you don't want to become a closed system where, you know, we where mistakes are hidden behind some kind of a wall of confusion. We want to make sure we— people that can work together. I think there's a tough line here, and I'm looking forward to seeing that. The other part of the article, which I think you alluded to, is what do we do about it in our own programs as a result?

And he talks about the readiness programs you can go through and the different kinds of tests that different companies can do to test different components of their program. I think that not a lot of us were, were able to test what if a, what if a bad antivirus definition goes out that, you know, that bricks all of my, all my machines. Um, but it's, you know, it's a, it's a real threat, right? And coming through with this list of threats and figuring out which ones are worth testing is, was one of the challenges of any resilience program for sure. Okay, uh, next we have an Optiv blog talking about how AI is increasing efficiency in cybersecurity.

Yeah, the headline on this looked good.

When you dive in here, there's really not a lot of depth, right? We will give you all of the depth of this article as we go through the different topics. AI can be used to automate the mundane, to connect the dots, for autonomous threat prevention, for reducing fatigue, The human element, which is basically saying, hey, it's helping to expand what humans can do by making them more efficient, and it is the future of cybersecurity. For all of these, I would have really loved if the blog post would've talked about specifics, like, all right, well, you say it's helping for autonomous threat prevention, show me where. How do I use that?

Give me a case study. Or, you know, optivis a VAR, like, which of your partners, which of your vendors that you sell are the ones that are doing this the best? So there's, there's nothing like that in here. There's a couple small paragraphs for each one of these, um, which has a slight amount of detail but not the amount that you might want. Yeah, but like we said, not a lot of news this month, so you get that.

And you also get a second Optiv blog post, which I did think was better than the first one. Uh, this is about, uh, 5 budget-friendly OT networking improvements for small manufacturers. And not a lot of content that we go through is, is created for the OT space, especially for you know, not the big large enterprises. What is it you can do to actually make a difference in your small OT environments? Um, 5, you know, 5 categories they go through, starting with asset inventory, where they're talking about, you know, what you should do for that.

Network segmentation. The third, third category, or third category, is password management. Software awareness train— excuse me, security awareness training. And then number 5 is incident response and recovery. Uh, all, you know, sort of base level things, but Also still very important.

Yeah, and he goes into details that are more specific to an OT environment for each of those. All right, the final article we have is more of an announcement, uh, in, uh, from the National Cybersecurity Center down in Colorado Springs talking about the University of Colorado Colorado Springs Cyber Service Day. Uh, this is an event where a number of undergrads from UCCS, as well as some industry volunteers are going to get together and help folks who are less technologically savvy to be more technologically savvy. Yeah, I would say this isn't so much an announcement as a call to arms. This, this event is looking for, I think they said about 30 industry veterans.

So folks who are listening to this podcast, you could be the person to help with this. To come alongside a bunch of undergrads from University of Colorado Colorado Springs to help the elderly and the folks who really are maybe a little bit more vulnerable to cyberattacks, to help them be more aware of those attacks, set up their own infrastructure in a more secure way, all kinds of good stuff. I do have to note also that they said that this is targeted at older adults and they they targeted, or they noted that older adults are those 55 and older. So that makes me feel real bad, Robb, that I'm getting close to being an older adult. What's the other option?

Just not getting older? Dying? Yeah. Yeah. No, no, no thanks.

I don't want that either. So if you are someone who wants to help give back to the community, go sign up. There's a link in the show notes. If you have a family member who is over 55 and you think, might be someone who would fall for one of the scams. And frankly, just about any adult is vulnerable to those.

Maybe you can get them signed up to join this event. You know, I'm going to sidebar a little on this, Robb. So speaking of older adults, as our generation is getting older, you know, we were one of the first generations that had ubiquitous technology as part of our, our youth. Right. We had most everyone has Nintendos.

Well, yes, gaming, but also probably a computer, some sort of computer, whether it's an 8086 or Commodore 64 or whatever, right? Like, we've been exposed to technology for a long time. Does this— is this a problem that falls off for older adults as our generation becomes older adults? It's an interesting question. I'm not sure that this is really a technology problem.

It feels to me like this is a people problem. And you know, if, if you guys are familiar with pig butchering scams, that's where they, you know, they create relationships, seem to be genuine relationships to the, to the victim, uh, with the long, long play, right? Months of building a relationship, getting to know each other. Eventually, oh yeah, I do investing in Bitcoin, I can help you do investing in Bitcoin. And, and then they go to, to steal all their money, um, through these scams.

I don't know that it's technology. I think it's accessibility for people who are vulnerable now that technology enables them to connect in a way that they, that they couldn't have when they were sitting on their lawn chair and the attackers were on the other side of the world. Yeah. I don't know. So you're saying it's going to be worse for our generation, but the protections could come too, right?

Yeah. Who knows? Anyway, food for thought. You're making me sad. Yeah.

But all right. Speaking of making me sad, there's a lot of events happening in October and you can see them all on the event calendar. That's not sad. And this makes me sad because I won't be able to get to all of them. That's true.

Yeah, there's gonna be too many events for me to attend. Yeah, okay. Well, what events are they, Robb, that you won't be able to go to? Well, on the 10th of October, there's a couple of good events, right? Starting— well, I think we have one on here, starting with the Secure World Denver Conference.

That's one of the, one of the better conferences. I will say it claims to be the premier conference in Denver, but we all know that's RMISC, right? Everybody. But it's like, what's the second? What's Second to Premier, like secondary.

This is the secondary conference. Yeah, I'd say that's probably true. Yeah, it's a great conference. If you guys can get out there, usually at the Cable Center. I assume it's the Cable Center again this year.

Yeah. Yes, I should know that. I'm on the advisory board. So on the 15th of October, we have 3 events. Very, very busy.

I have to say Colorado Springs is doing their October meeting. The Let's Talk Software Security group is doing one of their meetups. Is pursuing Change Essential in AppSec, and CSA Colorado is doing their October meeting addressing material risks. On the 17th, there's a couple more events happening. First, there's a webinar, Cisco SCORE: Building a Strong Cybersecurity Foundation.

And also that same day, the ISACA Denver chapter is having their monthly meeting, which— but this is going to be interesting— only online. They're not doing in person for October. Interesting. The topic is auditing with AI. That sounds pretty good, right?

And it says demos. I wonder if they're doing it online just to make the demos easier. Yeah, could be. All right. On the 19th, ISSA Colorado Springs is doing their October mini seminar.

And finally, down in the Springs again on the 23rd, ISC2 Pikes Peak is doing their October meeting. All right. This is jobs. We can talk about jobs. All right.

First off, Invenergy, I think that is correct, is doing a— or is doing— is hiring for a director of cybersecurity programs. Twilio is hiring a director of cybersecurity, or excuse me, a director cybersecurity counsel. This is a lawyer. They're looking for a lawyer. Sweet.

S&P Global is looking for a head of security architecture and engineering. Moody's Bank is hiring a VP of cybersecurity engineering. Parenthetically, it's Cyber Investigations Manager. Oh, that sounds interesting. The Trade Desk is looking for a Senior Manager, Global Security and Resilience.

I think I get the longest job this week. Bank of America is hiring a Cloud Security Controls Deployment Specialist, Global Information Security. Protiviti is looking for a Privacy Management Senior Consultant. Zoll is hiring an information security architect. Red Canary is looking for a senior threat hunter.

And finally, Xcel Energy is hiring a senior regulatory security consultant. All right, good stuff. Well, we do have an interview this week. We have, uh, we have the COO of Black Hills Information Security, CJ Cox, sat down with Frank Victory So I haven't had a chance to listen. I don't know CJ.

I'm excited to get to know. Do you know CJ? I have met CJ. It's been a while, but I have met him. He's an energetic fellow, so I'm sure this will be a good interview.

Good stuff. Well, well, thank you everyone for listening, and Alex, thanks for your time. Thanks, Robb. Hi, this is Rich Schleip, the CISO for the Colorado Department of State. This is Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Good morning, good afternoon, and good evening, State of Colorado, or the Colorado Equal Security Podcast. My name is Frank. Welcome to this podcast. We have a very special guest today, and his name is CJ Cox with Black Hills Information Security. He is the COO, right?

Yes, sir. And he's a wonderful friend. I've known CJ for at least a few years now. He may not want to admit that in public, but Who knows? So CJ has a very long background here.

He's been around in cybersecurity, but he's done a lot more than that. So we're going to learn a lot more about him in the next, in this next, what, 45 minutes or so. So CJ, how are you doing? I'm doing great. It's a beautiful Friday in Colorado, isn't it?

It is actually a beautiful Friday. It's finally not so crazy hot. They said it's going to get up to 90, but that just doesn't feel that hot now. Not with the weather we've been having though, man. I mean, it's been, uh, like crazy dry heat.

And I just came back from Atlanta about a month ago, and, uh, it's amazing how much living in Colorado— if you, you have such a hard time in, you know, humid states. Yes, yes. Uh, we got one of our guys just moved down to Louisiana. I pity the fool. Pity the fool.

Okay, so I guess our first question is gonna be how many people of our audience actually recognize that statement? Oh yeah, I've got a guy, a young guy on our SOC team that I'm always just giving him hell because I, I just a constant movie quote dropper. So is John, and, uh, he never has a clue where the movie came from. Like Caddyshack? What?

I actually saw a keychain with the Caddyshack, uh, uh, what, gopher on it dancing around and instantly recognized it because it was at a golf club. But anyways, uh, so CJ, how long have you been the COO, or how long have you been with Black Hills? Amazingly, it's up to 8 years. Um, years. Okay.

I think you and I met about 5 years ago when you were having John in. Uh, he was in Denver and we came to an OWASP, I think. Yeah. Yeah. Well, you know, John, of course, is a totally awesome guy.

He did our keynote. He did our meeting with us and everything else.

So, you know, again, I think everybody loves John, right? I mean, when I talk about Black Hills Information Security in my classes, I say, well, look up the definition of good people and you're going to find John's picture in there, right? Amen, brother. That's, that's kind of an interesting story, even like, While I'm there, I mean, you introduced my title as Chief Operating Officer, and that's kind of a funny story by itself. Okay.

When John was hiring me, he said, what I need, CJ, is someone to help me keep the plates spinning. Okay. And I was not a hacker dude. John and I worked together at Northrop Grumman. I'm kind of the opposite.

If I was, I was a Unix sysadmin for a while. I would call myself a Sage Guild Level 1. I mean, I'm, I can barely script. And so I'm like, why the hell, John, are you hiring me? He's like, and the answer is, the short answer is he needs somebody to do all the things that he doesn't do.

He knew me, he trusted me, he knew my soft skills. And he was just like, so I'm going to call you COO just so, you know, you have the creds that you can talk to anybody on my behalf. But my job is just to help John. And it— that's a— I love it. I love that role.

So kind of interesting that you mentioned that here, soft skills. How important is that? I mean, we obviously have to be very, very technical in this field, sometimes getting down to these nith degrees. And when we're talking to other technicians, we may laugh about certain things. We may get down to some little codes.

Uh, I remember talking to one of my friends because they wrote something and they missed a bracket. And it was just massively offensive to me, but nobody else would realize that, right? I mean, I would show my wife and she was like, so what? What? Right?

But, you know, going to the other side of that, right? How do we talk to non-technical people or how busy, what kind of challenges do we have? Well, obviously they're huge. I mean, So we're talking about my, my skill sets and which, which is more important, hard skills or soft skills. And like every engineering or security question is, it depends, right?

There's a mix of skills and there's place in the business and the industry for all sorts of those mixes. My path was largely dictated by the opportunities that came up.

I started off as a help desk person doing Macintosh, which I was not a Macintosh specialist. I was at the Environmental Protection Agency. They were only about 10% Mac. They didn't have anybody. And I walked in that door.

I had been, I'd been making graphics on a Mac workstation. That's it. That's how I got hired. And I grabbed, there was a thing called the Macintosh Book Club back in the day. I bought 3 of them that were the size of phone books and I spent all my time looking in the index to answer help desk calls.

And I became an expert. And that was all great, although Mac isn't like the highest demand for that. So I, I got an opportunity to switch over and manage a bunch of Unix weenies. And when they interviewed me, they said, what do you know about Unix? And me being the painfully honest person I am said, I think I can spell it.

And man, did I resist it, but I learned it. I learned to love it. And that's where I went down the path of being a Unix sysadmin. Never got good at it because I was in an environment where I was all by myself. I had no one to help me.

Again, I was trying to do the Macintosh thing, use the man pages, look stuff up, buy O'Reilly books. I was never very good at it, but I also had a foot in the leadership side. And I had enough tech skills. And I spoke enough management because I really started in management, a lieutenant in the Marine Corps, air command and control, all that stuff. And, uh, I could do the translation.

I had enough tech to understand it, but not enough tech. Like I said, I can't script my way out of a paper bag. You're probably, what is, what is the scripting language that we use all the indentation? Pre-Python? JavaScript.

Yeah. Java, a whole bunch of those, right? Like I just, I don't know that stuff, but I am cognizant of, I know what I don't know. But man, is it important to bridge the gap and talk to various angles of the business and things like that. So there's been a place for my combination of skills.

So, well, here's, I want to go back because there was an interesting thing you said. You said you're by yourself. So you obviously work at Black Hills Information Security, known for a lot of expertise, right? I mean, when And not just expertise within the company, but expertise within the community. Yes.

However, however, there are quite a few people in the audience listening right now that do not have that type of support within their own company, right? Uh, they are that lone person inside there. What advice would you give them right now? Um, you know, hey, you're either by yourself or You have a very small staff. It's a very recognized theme because they, you know, they may work for a law office, a medical office, et cetera.

I'd say that's the majority of the world. Um, you know, I came out of the defense industry. I worked for SAIC, Northrop Grumman, Lockheed Martin. Um, now when I was a sysadmin, even though I was at SAIC, I was just all alone. I was on an island.

What you have to do is you have to network. So you have to find other experts that you can rely on. We're happy for you to network into Black Hills Information Security. Go to OWASP meetings. No one is ever going to be an expert on everything around here.

We all know anyone that's in the business knows, like, yeah, I'm a Unix whiz. I don't know crap about Windows, or I don't know crap about Amazon Cloud. Well, when you're in this small business, you are You have many hats. Most of the guys in charge of IT, when it's 1 or 2 or 3 person shop, they also have to put on the security hat. And quite frankly, that's a specialization.

That's, we know that's all there, and there's multiple branches. How do you, how can I be an expert? You can't. You just can't. You have to find resources you like, and that's podcasts.

That's newsletters. That's books. It's experts that you tap into, um, to diversify your view on things. You have to find people you trust because there's people you won't trust. So it's networking.

Well, here's the thing about it is that one, of course, there's always a time factor where you have way too much going on, especially if you have to wear, you know, like you said, multiple hats. Yep. How do you find the time? And then let's say you want to go to the Black Hills Conference or the OWASP No Fraud Conference, and there's a fee involved. If I was your boss, right, and you were the island in here, how would you convince me that this is important considering the fact that I had no clue as to what this whole cybersecurity stuff was?

So how, how bosses speak, which is one of those soft skills, is, is what's important to your boss. We've always talked about the guy who's slaving away. He's got a limited budget and his— they've got old firewalls that are almost out of maintenance. He wants new firewalls and the boss is like, we just can't afford it. And so that, that person will come to me and say, well, I'm, you know what, I've, I've got, I've got an image.

I'm going to download it. I got some old hardware I cobbled together. I'm going to come on the weekend. I'm going to do all this stuff. And it's like, dude, why are you killing yourself?

You know, you make the case to your boss, we need new firewalls. If we don't get new firewalls, the likelihood of our getting hacked is going up significantly, the amount of time it takes to support it. How do you speak your boss's language? And how you speak your boss's language is dollars or risk. So you've got to know what buttons, what's his big thing, and you've got to paint him a picture and don't try to, don't try to propagandize him, don't try to oversell it.

Give him the costs and benefits. Give him multiple courses of action and tell him the relative merits of those things and let him make a decision. He'll ask you, well, which one do you prefer? Well, I prefer the $6 million firewalls. Well, you know, you've got to understand, we got to understand, we all know security doesn't wag the dog.

We're there to support the business. When you understand that and you just try to plug it in, the other thing is When the boss makes a decision and you've presented your case, you got to let it go. You know, if you're not going to sit there and work all weekend to stand up new firewalls, you tell your boss, if we don't do this, we're increasing likelihood of getting— or we're going to get an outage because of lack of support or any of these things. And you as the security person, you've got to be willing to accept that consequence because it's a consequence of a business decision that your boss has made and he owns it. You just salute, say, aye, aye, sir, and, and try to do the best you can with what those resources he gives you.

Okay. Well, in that scenario, right, you are working already probably 10 hours a day. You're putting in 50+ hours a week. And now with what you just said, coming in on the weekend, either that or it fails. How do you decide?

I mean, at a certain point, you're going to get tired of having to come in on the weekend. You're gonna give up some of the most important things in your life, which is maybe like your hobbies, give up some mental health things, right? Fitness. Yeah, fitness. So what would you suggest, or is there a right answer?

I mean, I don't think there's a right answer. How would you give our audience some guidance that might be in those situations? I had a great guy I worked with at Northrop Grumman named Mike Aletto. And it was a little hard stance. He didn't mean 8 hours, but if you can't get it done in 8 or 9 hours, it's really not that important.

If you're being diligent and you're pursuing the most important things, you do that. The other thing is, like I said, you present your boss, um, here's the, here's the things that are going on. If he's, if you've informed him properly, among those things is the firewalls might just fail and shut off. They're past maintenance. You've informed him of that.

Let it happen. You told him, he knows it. I always had this thing called the Pearl Harbor file. Another Northrop Grumman guy, Old Navy chief, told me, you know, that's that you better have the logbook entry that said you told them that there, there was targets flying in from the northeast, that you reported those and it got ignored, right? You got an email.

Not only did I talk to you, but I said, hey boss, I summarized this stuff. Here's some bullet points. Like, that's that whole risk. You've got probably, hopefully you've got a risk registry. I'm huge on the risk management matrix.

That's where you inform management what your risks are, what you've rated them, what the things are you could do that would change those, the costs of those things. And then the business makes decisions. And when one of those gets realized, I told you so. I mean, nobody likes I told you so, but in business, you've got to cover your bases. You have to have been clear in your communication, your summary.

That's your obligation as the professional and as the expert. Is to inform the generalist. Okay, cool. Well, I mean, I think everyone's kind of dealt with this, and like I said, I don't think there's really a right or wrong answer. There's guidance, but there's too many variables to consider, right?

But I do want to go back to— because you mentioned the military a couple times. Of course, you're a veteran, a Marine Corps veteran. So am I, right? What did you do in the military? My first job was to crash airplanes into each other.

Wait a minute, hang on. Crash airplanes? Well, you've seen Top Gun, right, Frank? Yeah, of course. Well, you know, 1 to about maybe 30 times only, but yeah, you know, I— and, and I've heard of jobs where it's things like, okay, well, I gotta bend the metal to make sure the planes fly, or I got to figure out a better way to land it.

This almost sounds like you're playing a video game, dude. Oh, it's totally a video game. Uh, we had a simulator. It was really a video game in training. Okay.

But so part of air command and control, which was my MOS specialty, military occupational specialty, um, it's those ground control interceptors. And they didn't show them too much. They showed them a little bit in the ship. It was all dark and there was a guy looking at the radar scope. So my job is to get the, the fighter jets onto the bogeys.

Onto the bad guys. And, and the reason you do that— so electronic warfare stuff— is you don't want the pilot to turn on his radar until the last second. So you got the E-2 up in the sky radar, and we have our ground-based radars. And so I'm telling the pilots how to turn and juke and vector to get behind the guy, and then he can turn on his radar and alert the other man that he's there. So yeah, crashing people into each other, that was my job.

That's the funny way we say it anyway. Why wouldn't they wonder how come you don't want to turn on your radar until the last minute? What's the significance of that? They got sensors they can detect. They know what quarter radar.

So you don't want the enemy to know you're there. Okay. So they, you don't want to turn on the radar to let the enemy know you're there. Would you actually apply that though to cybersecurity maybe or to management or to anything else? I mean, did you take a lesson from that maybe or is it Yeah.

Uh, I'm, I'm, I'm one of the members of the bad analogy fan club. So yeah, military, everything you do in life. I work, I wash dishes, man, that applies to this. Okay. Um, but, but stealth.

Yeah. Um, John wrote the book on, uh, active defense, right? Right. And deception is a huge part of that. Um, because when you deceive the enemy in your network, You can get them to cross it.

It's like putting in a fake admin account and the password is password01. Anyone ever logs into that, it pushes up the red flares like somebody's in the network. No one would accidentally log into this account. So deception, huge part of this. Setting up honeypots, that's deception.

Yeah, it's— and this is, look, cyber is war. This is a war on— in the electronic sphere. And the military's adopted it. And, and so remember, offense informs defense, defense informs offense. The whole way the evolution of weapons and tools in cyber work is that when one thing gets fixed, they go look for another one.

So yeah, it, it all applies. But, but I mean, and, and I definitely agree with you. I have John's book. I think it's wonderful. But yours is soft skills.

Could you use deception in your soft skills and more of not so much a social engineering? Because we know that's, that's obvious. I'm putting you on the spot here, of course, right? But are there any advice for, or could we use that deception maybe when negotiating with your boss? Like going back to the previous scenario, or is that something that you say, no, let's not go there at all?

I don't go there. You don't go there. Deception is for the enemy. Sun Tzu, The Art of War. Um, I am a cards-on-the-table guy.

Okay. You can tell when I talk about just tell the boss the cost benefits, don't try to sugarcoat it. Tell people the truth. I don't like manipulating people. I don't.

I did sit— one of my first jobs with John was doing all the sales. Now I do none of the sales, but we were never, never in the sales realm of trying to, we'd always tell people, oh, you don't need a red team. You just need an external pen test, you know, a difference of like $50,000, $60,000 in cost. Like, well, CJ, you're the sales guy. Why would you ever do that?

I'm like, because I'm not just here to sell you stuff. I'm here to solve problems. And, and I, and we take, so it's social engineering. The other thing is social engineering. Long-term approach.

I'm looking for a good relationship with you. The way you get to that is with truth. If the truth's not on your side, then accept your outcomes. No, I am a— I am a be truthful with your friends and allies. Deceive the hell out of the hackers.

I don't care. Right. Right. Okay. So that's, that's, I think, some important advice, right, is just put it out on the table.

Some people are always very cautious about that because they're afraid that it might be turned against them. Sure. Yeah. A good scenario for that, Frank, is should you tell your boss you're looking for another job? Okay.

Right. I've been here 5 years, boss. You know, I've climbed the chain. We've talked about raises. I can't get one.

I also want to work in a different realm. Should you just go be honest with that guy and just tell him, hey, I need, you know, I need to move laterally. I need to move from, uh, from desktop into, to, uh, network support or into server support, right? But you can't get it in your current environment. So how honest should you be with your boss?

Well, what kind of a culture do you have? Have you watched other people be walked out the door? Well, if you're going to say that you're looking to go somewhere else, here's your 2 weeks notice. Okay, well, I guess you can't be upfront and honest in an environment that doesn't support that. Um, so, you know, your thing, it depends.

Well, you got to determine your own thing. Like I said, I don't like to lie. Um, I don't have to share the whole truth about things that are maybe personal or things that are going to get me punished. Um, so like getting fired for, for something that's like, like, hey boss, I blew up the server farm. Well, you're fired.

I'm gonna hide that I blew up the server farm. No, no, that's not where we go with that. Yeah, right. Well, I mean, I, I've actually been in that situation where I have asked, you know, should I look for another job? And I was lucky enough in one situation where You know, he was very understanding about that, tried to find something.

I mean, I've been in the same role for several years and wanted to move on. I've actually helped one of my employees, very loyal employee, and helped him find another job because I couldn't do anything else for him. The best thing though is that when my server farm did blow up about 2 months after he left, he spent a good 6 hours on the call with my new guy. Working with that person because of his empirical knowledge on how to fix it. And I said, let me, you know, send me a bill, I'll pay for it.

He's like, nope, nope, you, you helped me out, now this is my return. So I think it— what goes out, what goes around comes around, right? That, that is, that is the use case, Frank, for why it's— why you're a good person and why, why you deal above board. And that, that urge to help people, you're investing My relationship with so many of my employees from the past is ongoing. I help them, they help me.

You know, when you invest in those other people, it pays a very serious long-term dividend and not being honed in on the short side, like knowing that your employee does need to diversify, they may need to work in another environment. I've supported that. The other thing is when they're upfront with me, we can manage that on/off ramp. What timeframe are we looking at? What is it like?

I can start looking for another person. You can help me interview. You know, manage that thing. When you look at things as short-term and maybe just a single fixed pie, that's not how it is. You got to get creative around here.

You got to be out to serve all the stakeholders, your employees, your customers, your bosses, the teams you work with. You know, if you're in the service orientation, that good one, people see that. They understand that you buy yourself a tremendous amount of influence and goodwill Uh, when you, when you live like that. That's great. No, I think that's good advice, and I think that proves again that we have a lot of good people in this industry, right?

A lot of good-hearted people that are willing to do a lot of things to help other people because, you know, they were lost souls. And, you know, I think both of us came up from that, right? You— oh my gosh, right? I mean You didn't have a plan for this. I was originally going to school and trying to learn to be an attorney, right?

Yeah. Yeah. How would you like me defending you, right? I think that's the hand of providence, Frank, that you're not an attorney, but okay. But if that wasn't your plan to be in cybersecurity, and I think that's true for a lot of older people in this industry because it didn't really exist when we were trying to go to school.

I mean, What was the school? And oh well, here's a server. We didn't really have anything. The technology at that point was further advanced than our education. Yeah, well, do you want me to start at college, Frank, or do you want to get forward to getting out of the military?

Oh well, you know, I think you have something interesting. I mean, in college, did you go to school for cybersecurity or Well, I guess not. That didn't really exist back then. Computer, uh, what was it? Computer science.

That was about it. Okay. Yeah. Um, I was, I was there to be a veterinarian. I changed my major about 7 times, decided I was just, uh, what did my credits fit into?

I got a degree in physical science. People look at me and say, you look like a physical science major. What they mean is I look like a physical education major at the time, I guess. Okay. No.

So I did, computer science was new. Um, there was a guy in my fraternity house who was majoring in it and he had the, uh, the green screen and a modem that was, you put a, we don't even have phones like this, but it was set in a cup. That was the modem. Um, everyone else had to go to the, wait in line at, to get a mainframe terminal to do their Fortran. I went to a counselor, hey, how do I learn this computer stuff?

You know, how, When I push X on a keyboard, how come it appears on the screen? You know, how does that work? That's what I want to know. And they told me, well, the first place you start is Fortran. All right, Fortran it is.

So I walk in there, tell me I need to change my password, right? I wait in line for over an hour to get a terminal. Sit down at the terminal. They give you a piece of paper. Your username is Cox CJ.

Your password is password01. I sit down, password01. Fail. Huh, did I, did I mistype? I stop, I slow down, I look at every keystroke.

Password 01. No, no, no. I think their, their policy was 5 times lockout. So now I go wait 15 or 20 minutes in line to talk to the TA just so he can reset that. Go back, rinse, add, repeat a couple of times.

Then I had to go, then my time was up. So I had to wait another hour. He finally comes to the terminal to watch me. Password 01. CJ, when you typed password 01, you typed Shift+O, lowercase l. That's not 01.

I go, oh, well, you know, I've grown up my high school and everything. I typed all my papers on an Underwood typewriter and there's no 01 because it saves space on the keyboard. So you use capital O and capital and small l for the 1. He's like, CJ, this isn't a typewriter.

Not a typewriter. Okay. So that was lesson number 1 for you, right? Lesson 1. I got a D in Fortran.

Okay. And I, I went screaming out of the building. That's it. I'm done. I'm done with computers.

Just not a good fit. So fast forward to the military and I was a legal officer and they had a computer that was a little more user-friendly. I was able to manage it after my Fortran experience. And I fell in love with the computer, man, because I didn't have to type charge sheets up over and over. I just changed the name.

Okay. So, uh, I got good at that and, uh, used computers then kind of the rest of my career everywhere I went as I wandered about after the military. No one was hiring anyone to crash planes together, and I didn't want to be an air traffic controller. And, uh, that's not a good mix though. So that's, that's good, right?

My instincts would have been all wrong. Yeah. Okay. Yeah. Okay.

So I'm glad you didn't go that way. But I, I, I did fall in love with the computer and the utilities of the computer. So, and, and working live with it, I developed that. And one point, because I had a boss like you've been to your employees, when we lost a contract and he wanted to place me, um, he said, hey, there's this opening at the EPA help desk. Are you interested?

I'm like, I'm interested in staying employed. And yeah, I like the computer. And And so that's how I worked my way into it. And then interestingly from that, so I worked help desk, I worked not network operations center, um, managed tech people. Um, but fast forward, I was as a reservist, I was, uh, working for a guy and my job was to change the passwords every weekend because the reservists would forget they had 3 different systems and they couldn't remember.

So my job, my big signals intelligence job was changing people's passwords every Saturday morning. But, um, the guy there, he's like, hey, you got some tech background experience, but we got this thing, the cybersecurity thing coming out. We need something called a CISSP. Would you be interested in that? And I'm like, yeah, that, that sounds cool.

And, uh, so I studied, he hired me at SAIC, got, I got my CISSP after a year of study. And so that's how I broke into cyber. But dude, I wandered across the plains in a panic mode. For what am I going to do to be valuable to people? And again, opportunities and networking is what led to every single shift and change that I made wandering through that, that pathway.

So would you give that as advice to people? I mean, obviously now we have a lot of different cybersecurity classes. Black Hills obviously offers some classes at unheard of prices. And when I say unheard of, right, I am talking about— I believe John makes it a goal to lose money on his classes, right? But to give back to the community.

I mean, that is the entire attitude. Uh, but let's say that I've either coming into this industry from college, another career field, etc., or maybe I've been in this job and something like that. What would you offer as advice? I come to you, CJ. I said, look, I know you're the COO of Black Hills Security, a well-renowned, uh, renowned, right, uh, company about cybersecurity.

I am a career changer. I am a veterinarian. I don't know what to do. What advice would you give me as far as breaking into the industry? Well, you take whatever you can get.

Okay. I've advised college kids to, well, intern, right? Move around, go see some things. One of the things that's important to learn in life is not what you— it is important to learn what you want to do. It's also important to learn what you don't want to do.

Like if you hate Unix, which I did initially, you know, don't do Unix. Go to— there's so many options, but you need to explore. You need to take the opportunity that's available to you. I started on help desk. I think it's great.

When I talk to college kids today, I tell them, hey, if you can get a job, or people with nothing, I'm like, try to get a job at Best Buy. Okay, go get a job at Best Buy. Help people buy computers. Like, and, and if you can help them buy computers, you're going to start learning what's memory, what's screen, what's pixels, what's What's hard drive? What's this?

What's that? You get, you start laying down a base of knowledge. Be really good at what you do. Master that stuff, throw yourself into it and learn it. If you don't like it, still be good at it and look for the next opportunity.

Hey, maybe I can move over here to the geek squad. I've learned enough. I hobbied, I've read books, I've taken some classes, leverage it. And you gotta, it's like, it's like hacking, right? Move laterally and escalate your privileges.

So funny. It's funny that you mentioned that because I've actually given pretty much the exact same advice to students the entire— I mean, all the way down to the Best Buy and the Geek Squad. Yep. And I think though that where you've added a little bit more, emphasized a little bit more, is be good at it and commit to it, right? Yep.

Good, bad, or indifferent, you need to commit in this industry. Yeah, I did that as the dishwasher, right? Dishwasher. Okay. Dishwasher.

I washed dishes at a very nice restaurant up in Evergreen, Colorado called My Friends. Had deluxe gourmet chefs cooking great stuff. And most dishwashers that aren't in high school are alcoholics. Okay. Back in the day anyway, right?

Well, so are a lot of cybersecurity people, but yeah, but that's, well, heavy drinking is not alcoholism, Frank. Okay. All right. I did a great job as a dishwasher. And so I didn't just wash dishes.

I was a prep cook. They also made me work doubles on brunch weekends when people would call in. But so being good at your job, it gets you the admiration and loyalty of your boss and they'll help you. In the tech field, when you're really good at it and you've, you've ingratiated yourself, you're a great employee. People can't help but notice that.

And people want to help and reward that goodness. Um, like I said, dishwashing ain't great. You got to embrace the zen of dishwashing. Um, help desk wasn't great. A lot of the starter jobs, I mean, at least kids coming out of college, you think you're going to be CSO or CEO of a company.

I majored in business. Well, what do you plan on doing? Oh, I'm going to run a company. No, you're not. You, you, you gotta, you gotta jump in and you gotta do things.

And like I said, excellence is its own reward. When you master the one topic, It'll apply to another topic, how you learned it, that energy, the whole method of how you do it. You will grow and growth, growth will find opportunities. And look, it's so great. I'm 61 years old, Frank, and, and I've arrived at the job that's my dream.

And people can look at it as like, God, I'd like to do that. I'm like, yeah, let me tell you, it didn't look— looking forward compared to looking back. You know, oh my God, I had no clue where I was going. I was panicked. I was scared.

I was afraid of being unemployed. Everyone knew more than me technically. Those things, you gotta use those things as drivers to just make yourself better and find your niche. You gotta keep your own confidence and you gotta work hard and believe that it's gonna pay off. It won't.

There will be people that are gonna mistreat you. There's people that are gonna shaft you. You're not gonna get offered jobs. You can't let the bastards get you down. What's Edison?

He goes, the only way you lose is if you quit. Persistence. It's not even brilliance that pays off. It's persistence. Cool.

Keep trying over and over again. Get ready. I mean, one of the things that I used to tell, I tell a lot of my students and tell a lot of my mentees is be okay with failure, right? Yes. Yes.

But the question is, is that what do you do after that failure? Yes, you don't get the job, you don't pass an exam. I think that it's perfectly acceptable to walk over to your sofa, do a face plant, feel sorry for yourself for the rest of the day. Absolutely. The most important part is the next day you better get your ass out of that, off of that couch, and you better make yourself better, right?

You've got to do that problem analysis, which is what you do as a tech person. It failed. Why? Like, why did— look, failing the CISSP, at least back in my day, was kind of the majority experience. Like, that didn't happen to me, but for people that did, and what the natural question is, well, which, which, which domain did I fail at?

I gotta, I gotta double down. I gotta go in there. I gotta master that one. Why are you failing? And, and always looking at what you can do, not what something else did, the situation, the economy, some dumb boss somewhere.

Um, you know, you can't control other people. You can't control your— a lot of, a lot of factors in your environment. You can only control your own effort and your own attitude. And it, I know in the moment, the darkness, everyone will go through grief and that process of grieving, but you got to move past that and, and, and prevail. You will prevail.

Awesome. Awesome. Well, you know, we've been talking about work. Uh, mostly for this podcast. What about outside of work?

I mean, you know, assuming that you're not going to give up your weekends, what would you suggest though? I mean, what's probably the most important thing for people getting into this industry or the people that have been in this industry for a long time, either one? What do you think is important?

Well, finding work that, that, that is gratifying, finding work that's like a hobby. Um, that will make you not resent working 50 or 55 hours. I kind of tell my people, look, if you're working from home, 45 hours is nothing. I don't commute. Um, there's some balance and it varies for people.

We've got guys at Black Hills Information Security that I swear they must put in 60 or 70 hours. Um, they're producing tools and things like that, and they do that on their own time. Um, if they're getting burned out and exhausted and frazzled And they're demoralized, that's not good. But for some people, that, that building a tool, that's the hobby. They'd rather do that than game.

Um, if, if it's actually recharging your batteries to do that, that's, that's good. I, I want people, I think people should be balanced. You need a balanced life. You need your physical health. So you should do some fitness.

Don't just be sitting there getting your suntan by, uh, the blue glow from the screen. You've got family, you've got friends. Diversity is going to make you better. And there's things to be learned from, from those other activities. I think it's going to make you long-term a better balance.

There will be times in your career when you do have to work. You might— you're on a proposal. If you go to war, if you're in a law firm and you're trying to make partner, you know, hopefully that doesn't take 15 years of your life. Yet, is it worth it? Um, but there will be times when your life will be a little out of balance.

It's up to you and your network to help you maintain that balance and stay healthy, because that healthiness is also effective, I think, at your job. Okay, cool. So what are you most passionate about in this industry though? I mean, I think we've kind of heard that already, but could you define that for me? Like, can you just As a very plain question, what is the most biggest thing?

Oh, so much. And it, again, it varies on the day maybe, but I think the big thing that we're facing, and I see it, I just saw the government hire, it's a lack of people. Okay. Um, and so the training side of that, but the sharing in the network, like how do we share more effectively? How do we teach more effectively?

How do each one teach one? The mentorship that you're talking about, Frank, that you do, and I, we all try to do, I think paying it forward, that's helping to grow the field, encouraging people to get in. Um, you do a lot of work at OWASP, Frank. Like, why do you do all that? Like, you're out there sharing because that the knowledge and understanding is rare.

And so easy. And so it's a point of leverage. How do you make the impact? Um, I say growing, getting people into it, sharing the knowledge, whether that's for teaching a course, mentoring, whatever it is. We need more people doing this, more people understanding it.

So I'd say that's one of the biggest ones for me. Yeah. Oh my, it was a little shocking and, and arrival. One of our previous guests and a good friend of mine, Dustin Lehr, he had actually asked me one time, why do you— how much do you get paid for running OWASP? And I was like, well, let's see, uh, I— it's actually a 7-figure salary, right?

Um, the problem though is that those 7 figures are be— are after the decimal point, right? Um, it's all right around $250,000, but that's because the last time I was at Dave Buster's, I found a quarter on the floor, right? Nice. Um, however, he asked me why I do this, and I've been doing it since about 2010. So, you know, we're running on what, 14, 15 years now?

What are your paybacks? What are your payoffs? And I was like, you know, there's a lot of payoffs, but none of it is monetary, right? But I get— do get a lot of rewards from doing that, um, you know, doing this podcast, right? Robb and Alex aren't going to pay me a dime for this, but that's okay, right?

They do a lot of stuff for the community that, you know, people are not paying for, but it is giving back to the community, and that right there is a payback. Well, so here's a tangible thing. One, Frank, you've— what is it? What, how, what was the guy, uh, was it Malcolm Gladwell? Takes 10,000 hours to become an expert.

Something. Yeah, I'm not sure if he said it, but I've heard the phrase before. Somebody like that, right? The, the time you've invested in all that has made you an expert. I mean, you're an expert.

So, and not only are you an expert, you're recognized. Like, if you got fired tomorrow because— not because you screwed up the server farm, Frank, but your company went under, something happened. You wouldn't be unemployed for a month. You know too many people. Those people may not be able to hire you, but they know people who know people.

So if you're just social engineering, Frank, you've just made yourself, you know, so hireable that, but that 10,000 hours to do that. Well, God bless, you know, but, but seriously, you, you, you can't put in that much time and not benefit. Yes. Yes, you didn't, you don't have 6 figures sitting in the bank from it, but you've benefited. It's changed who you are and how you do things and what you know and how you relate.

It's a huge impactor. Yeah. Okay. Well, we've got, we're starting to come to the end here. So I'm going to give you the final question that I ask everybody here, which is, what is the greatest challenge for security today and how might you address it?

Now, I'm not asking you to solve it. I'm just asking is how are you going to approach it?

The greatest issue from, for God's sakes, I'd say patching. Okay. But just, it doesn't have to be technical, right? I mean, what would you say is the biggest problem? You, you know, John comes to you and says, and says, CJ, solve the world's problem.

Solve my cybersecurity problem. But he doesn't tell you what the problem is. He wants you, and when you ask him, well, which problem you want to solve? It's like, CJ, you're the expert. You go figure it out what the problem is, and then I want you to go solve it.

Hmm. Man, you throw some hard balls toward the end of the program, man. Um, it is awareness and knowledge. And I say that because everything I read in the paper is ransomware, ransomware, ransomware. I just got a notice the other day.

I think an insurance company I'm at. I, luckily, you know, I get, I get some security monitoring of my accounts and stuff, which is great.

Someone there at that company made some very bad decisions. And my guess is it's not the tech guy in charge of implementing 2-factor authentication or patching. They've made arguments, but I think they've maybe made them ineffectively that the bosses didn't grasp the risk.

Most companies, like I said, where there's not specialists, look, there's so much, so much is required, you think.

But the clear awareness of what's the priorities, like, we'll tell you, increase your password policy, make it longer. Get the 2FA in place and patch up. Okay. Patching is wildly difficult. It's a simple thing, but not easy.

So patching is just— I don't know what to tell people. If you're leaving stuff unpatched, all the awareness and sometimes even 2-factor authentication is not going to stop people. But I think it is— it's the knowledge and awareness. And part of it is having the knowledge to know what that is. In the places where you need it, but also the ability of the specialists again to communicate it so that the bosses understand it and can then make good decisions around it.

Cool. All right. Well, let's talk just a little bit here and I'll give the audience a fair warning. We're going to do a little promo stuff here, right? You do have a conference coming up in what, Black Hills, right?

Or inside in South Dakota. And so you want to tell us just a little bit about that? Oh, that's been going on I don't know how many years now. You've been at almost every one of them. Um, we love that thing.

Unfortunately, it's sold out. Okay. Uh, but let not your hearts be weary because we have another one coming out, and I'm having to look it up, Frank. I'm so unprepared for this part. Well, I actually happen to know this one.

You're going to have it here in the Mile High City in February. Ding, ding, ding, ding. That's the one, Frank. Yeah, you know, you know, the, the, the city and the state that you actually live in. Yes, that happened here this time.

So we are so excited to bring this. We have maxed out Deadwood, South Dakota. Um, you can't get a hotel room there the week we're there. It's like it might as well be Bike Week. Okay.

And, uh, um, We love it, and that's a special place. That's John's home. We all love it. We love the ambiance. But we are looking— I've been to a couple conferences here in Denver.

I'm amazed at the amount of turnout. And so we think it's just, you know, if we get— if we match what's at Deadwood, that'll be successful. But we've got room for a lot more. We look at Colorado as a central place in the nation. People can get here not just from Utah, Wyoming, New Mexico, Um, you know, and there's plenty that goes on on the West Coast, but it's just a great opportunity.

People can get here in one hop usually. Um, and it's great. I love Denver. I love downtown, and we're going to be right downtown. Um, it's going to be fun.

We're going to try to get the same kind of feel. You know, it'll be a different vibe, a little different, but you'll get the same caring heart. You'll get the same great people. I'm pretty sure Frank will be there, so that, that kind of gives you a sense of the caliber of the person that we'll let in the door. So, uh, we're excited.

You'll let anybody in the door then? That's what you're saying? All right. All right. So if they want to learn more, of course, Black Hills Information Security, they also can go to what, Wild West Hackin' Fest?

Yes. Right. So, CJ, thank you for your time. I really do appreciate it. Again, for those of you that may not know me, my name is Frank.

I am the VP of Denver OWASP. We just had a meetup the other night with about, what, 80 people attending from Jason Haddix. We are spinning up and getting ready for our SnowFROC conference. And we can't give any details yet. We're still— it is going to be in March.

The only thing is, if you happen to go to snowfrog.com in the next week or so, we'll have a few clues about it, right? We'll have a little bit of a scavenger hunt. Anyways, again, thank you for your time, CJ. I really do appreciate it. My pleasure.

Keep up the good work, Frank. Thank you.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security.

Back to all episodes