All episodes

Richard Staynings, Chief Security Strategist at Cylera

Apple Podcasts Spotify SoundCloud

Richard Staynings, Chief Security Strategist at Cylera is our feature interview this week, interviewed by Frank Victory. News from NWSL, Red Rocks, Spekit, Fluid Trucks, Lumen, Red Canary, Swimlane and a lot more.

Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Job Openings:

Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript10595 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 207. Alex, it's January of 2025.

It sure is. Holy smokes. I read the other day that we are now as close to 2050 as we are to 2000. That can't be possible. Isn't that crazy?

Check your math. Yeah.

That is really hard to believe. I mean, the year 2000 was just the other day. Yeah. I'm still worried about Y2K. One of these days you're going to come home, dates aren't going to work, everything's going to be shut down.

Yeah. It's coming. Well, happy New Year. Happy New Year. Happy holidays.

Hope everybody got some rest, you know, relaxing, you know, coming to 2025 strong. I got to tell you, the, the way the holidays hit on the calendar this year was really great. Yes. It's like Christmas Eve, Christmas, Christmas Eve being a Tuesday. Everyone, you know, it's like, yeah, the Monday kind of blew the Monday off.

Right. New Year's Day being a Wednesday, you know, you got the second and third. Yeah, you kind of blow that off. Everybody comes in, checks their email. That's about it.

It was about 2 weeks off of just— and it's not just like taking PTO. You can take PTO anytime, but nobody generating work while you're on PTO. That's, that's magic. I've gotten very few emails in my inbox the last 2 weeks. That's magic.

Yeah. All right. Well, we are, we are ready to talk about the podcast. We sure are. What do we got?

What's our housekeeping? What do we do here? You know, we have a Slack channel, Robb. Several thousand of your closest friends are hanging out there. Come join the Slack channel as well.

We'd love to have you join the conversation. Go to the website, colorado-security.com. Fill out the form. We'll add you to the website. While you're out there, once you go ahead and join our mailing list, you'll get the show notes into your inbox.

Occasionally talk about volunteering opportunities, other good stuff happening in the community. And we'd also love it if you would rate and review the podcast on your favorite podcatcher. Say nice things about us, and maybe more folks will come join the community, which we would love to grow. Yeah, reach out. Tell friends.

Tell your neighbor. Tell your doctor. Uh, you know, tell anybody in Colorado about all the great stuff we're doing here. And finally, if you want to support us financially, we do have a Patreon campaign going to help pay for things like hosting and the picnic that we do every year and other things like that. And we love to see that financial support.

Uh, and thanks to all our Patreon supporters. Yeah, we appreciate you guys, especially around the holidays. Thank you. Uh, you know, one thing we don't talk about a ton on the show is that in addition to, you know, what we do with the broader community, you know, you and I also run a local security community leaders Security Leaders Group. Uh, we get together for dinners, we do a couple of summits per year, uh, and, and we just as of, as of last month or so have had a sponsor come to join us to support that community throughout the rest, through all of 2025.

And we just wanna give a shout out to, to our sponsor Armis. Thank you for, for doing this. We, we appreciate it. Looking forward to working with you this year. Yeah.

And, uh, if you are a security leader that's out there that's listening to this, someone that runs an internal security program at your organization and you're not part of our Security Leader Group, Reach out. There are— you can go to the website and find a signup form there as well. We'd love to have you join that part of the community. Awesome. Let's jump over into the news for this month, starting for breaking news.

Alex, we were recording on Friday and right before we recorded, this news broke. Denver is going to become a major athletic city here coming up soon. 2026, I think it is. Yeah, it's very hard for us to find real breaking news to get on the show, but we happen to do it this month. Denver has been awarded a national Women's Soccer League franchise.

So we will now have a professional women's soccer team in Denver. What do you think? What are they gonna call them? What's the Denver Kickers? Denver Soccer People?

Yes. Denver Rockies? The Denver— I don't know. I'm, I'm out of things that— names that aren't sexist, Robb, and I'm not gonna say any of those. Well done.

So anyway, that's, that's coming. A bunch of local investors and kind of chipped in to make this happen, to over $100 million in fees to get this going. But it looks like it's official. We're excited to have a new sport team to root for and be disappointed by based on how the rest of our sporting teams do here in town. Although I shouldn't say that.

The Nuggets just won the championship. Yeah. Uh, Avs not too long ago either. Um, but the, it is noted in the story that the controlling owner for the team will be Robert Cohen, who is the CEO of IMA Financial, which is a, you know, big financial group here in town. And then, you know, a list of other folks that are investing as well, other local technology leaders and things like that.

So pretty cool ownership group and excited to have the, the new women's soccer franchise in town, whatever it might be called. Good stuff. Let's move over to our next story. Looking back at 2024, it turns out that Red Rocks was the 2nd most attended venue in all of North America and the number one outside venue in the country. Exactly.

Yes. The biggest amphitheater for attendance in the country, which is pretty cool. I mean, I know that there's a ton of concerts at Red Rocks, but it didn't really occur to me that maybe it's the most attended. So it's, it's great to hear that, which is crazy because we don't have wet all-year weather. Right.

I would think that a place, you know, Vegas, L.A., you know, Florida would be able to use it all year round. But, but apparently we do better than any of those places. The only American venue that was ahead of us was Madison Square Garden. So obviously a big internal arena that must be busy all, all, all day, all year round. Uh, they had 1.7 million attendees last year.

That includes concert venues, but also folks who do things like Yoga on the Rocks, which I didn't expect to be part of that. Yeah. They basically every day from April to November, uh, Red Rocks is booked with something. There's a few nights when there's not, but almost every day it's booked. Um, Also, Red Rocks was the number 4 in the world in terms of, of attendance.

The other ones that beat it, we already mentioned Madison Square Garden, but also London's O2 Arena and Mexico City's Auditorio Nacional. I feel like I need to go to those places now. Yeah, maybe we should go compare that. I bet you that they're nowhere near as good as Red Rocks. I mean, Red Rocks isn't great because it has a lot of people go through it.

A lot of people go there because it's great. Right. Exactly. All right. Why don't we move along next?

Talking about a topic we've brought up in the past, but revisiting a little bit. There's some testing that's, that's going on down in Pueblo, talking about Hyperloops, which is not something you hear too much about anymore. But there is now a test track being built in Pueblo for a potential Hyperloop. I think that my favorite part about this is that I could get from Pueblo to Denver in 11 minutes. And if you've ever been to Pueblo, you know, getting to Denver quickly is a high priority.

And if you've ever been to Pueblo, you know, getting out of Pueblo quickly is something that you wanna do. Right. That's exactly right. So I am, I mean, I would love to see Colorado and of course the whole country really lean into rapid transit. Having got to travel through Europe on trains, I love it.

I think it'd be a big improvement here. Hopefully we can see something like that get started here in Colorado. Yeah. So the company is SwissPod Technologies. And they're working to complete a 1-mile full-scale Hyperloop test track down in Pueblo on the former Pueblo Army Depot grounds, which is a place that's now being turned into sort of a research and development site in general.

So this is one of the, the companies that's there. It was interesting to read in here. One of the cool things about this particular company is that they've sort of abstracted all of the technology related to Hyperloop from the track and put it all into the individual pods, which makes it much more cost effective. Excuse me, cost-effective to, uh, to make these, uh, Hyperloops. I, I mean, I, I was encouraged to know that they're actually building the track, which means maybe there's some money that might want an ROI.

Hopefully it's not all grant money that, you know, doesn't need to see a return. We— I'd love it if, you know, they're doing this because it's going to turn into something and we can actually get on one of these one of these days. Yeah, that'd be pretty cool. All right, next we have a story about a local tech company making an acquisition and, and, you know, Candidly, I picked this story because I didn't know the company, the local tech company, and thought this would be a chance for us to learn a little bit about them. So the company is called Spekit, S-P-E-K-I-T, and they do insights for sales.

Basically, you're a salesperson, you want to have more visibility to your pipeline, to your opportunities. That's what they offer. And they made an acquisition recently. Yeah, they purchased a company called Sequence. Letter C, Qents, very clever there, which is an AI company, sort of AI search and other things like that.

And they bought them to help bolster the AI capabilities in Spekit. They, they want to be a bigger AI company. And they thought the best way to do that was to purchase another company and integrate it. So they're going to use the Sequence folks to run that element of Spekit. This will give them you know, faster, hopefully more accurate insights into the sales opportunities.

I learned a little bit more about Spekit. They are Denver headquartered. They moved here a few years ago. They have just under 100 employees here in town. I don't know if they have any security folks.

If not, might be a good place for you guys to reach out if you're looking for a new hot startup to get hooked up to. There you go. All right, our next story. This is potentially the culmination of several stories that we've had in the past. We've talked a bunch about Fluid Truck.

Some of those stories good, some of them not quite as good. The most recent one that they were filing for bankruptcy and there's a plan to buy the assets that they had out of bankruptcy and then a lawsuit potentially to stop that. So that lawsuit has now— or the sale has come to pass. So I think the lawsuit has also passed. It seems like now there will— I don't know if they're going to keep the Fluid Truck name, but that they have been sold to King Bee Rentals.

King Bee Rentals. So King Bee Rentals is buying Fluid Truck. And like you mentioned, I think our last update was that the sale was blocked due to this lawsuit. And now the lawsuit has gone away. It's unblocked.

The bankruptcy judge said, no, this looks like a good sale to us. I think unless there's another dramatic turn, this will be the end of our discussing Fluid Truck on the show, which is very sad. They, you know, have been on all the fastest growing lists and other things like that. So meteoric rise and as big of a fall? Well, it is no— it is no longer 2024.

So this is now a warning for you that's already come to pass instead of a warning for the future. There is a new law in effect. You— if you have your— excuse me, your cell phone in your hand while you drive, you can get a ticket, a 2-point ticket with a $75 fine, even if all you're doing is holding your phone. Uh, you, you can get a ticket if you're holding it while you drive. If the car is in drive, you can't be holding your phone.

Yeah. So that, that includes if you are stopped at a stoplight, if you are in traffic and not moving, uh, if the phone is wedged between your face and your shoulder, all of that is considered, uh, you know, using your phone and subject to a ticket. Yeah. This, this, um, this is a tangent. This reminds me of one of the most infuriating DUI things out there.

I've never got a DUI. I don't drink and drive. Um, but apparently if you get in your car to like sleep off being drunk, you can get a DUI for sitting in your car without the car even on. Yeah. Like, there's gotta be a better definition of things in my mind if that counts as a DUI.

And, and if you're— yeah, I, now I worry if you use your phone in your car before you start driving, Is there potential that the cops say, well, he could have turned the car on with the phone in his hand? Yeah, that, that is mentioned in here. And I don't know if this is discretion or, or what the actual, um, text of the provision is, but they do mention that, um, as part of this, you know, if, if you are seen, uh, driving recklessly or dangerously and you're, you have your phone in your hand, that's when they can pull you over. So I, I, I'm not sure if it's, um, 100% like Oh, I saw them holding their phone. I'm going to pull them over.

I think you may have to have given some other cause as well. Right. So sometimes they talk about like a primary cause for a ticket or pullover. All right. Moving on to our next story.

We have a story by Ballard Spahr talking to us about another law that just went into effect, the Colorado Privacy Act, and some amendments that came to that. Yeah. So there were a few things in amendments that have now been added to the law. The first is sort of a clarification on some definitions. What is a child and some other responsibilities around privacy data for children?

The second is a bunch of clarifications around biometric data. What is required for notification and other things like that? Some cars out for employees and employers and biometric data notification. And then the final part is a new piece of the uh, the law, which relates to the Attorney General's Office being able to, to generate opinions and other things like that related to the law that can, uh, you know, color, you know, how the law is interpreted and how they see that it will be enforced. Yes.

So I mean, this seems like something that's absolutely a must-read for anyone who's practicing privacy in Colorado, and probably for most of us who are, who are in security leadership roles, understanding what do these edits look like? What do these amendments look like? What should we be thinking about when we think about privacy here in our state? Yeah, it doesn't seem like major changes, but definitely want to know them for clarifications. All right.

Our next story is, it's a kind of a hitting home on a big national or even global story. Uh, we're over the last couple of weeks, we've had the government come out. Was it CISA or? FBI, I think it was the FBI, came out and let us know that there had been China— Chinese breaches of numerous major telcos, um, and that, you know, for some amount of time you should, you know, use encrypted communications, you know, end-to-end encrypted communications for any sensitive conversations. Well, this hits home because Lumen is headquartered here in Denver, and Lumen apparently is one of those who was impacted by this breach.

Yeah. And this article talks about the fact that Lumen has confirmed that, that they have removed any evidence that they have seen of Salt Typhoon being in their network. So they feel that they are now secure from these types of attacks from Salt Typhoon specifically. Not to say that you shouldn't stop using end-to-end encrypted communications, but, you know, potentially the immediate threat that was brought up around Salt Lake Foon is maybe minimized now. And Lumen does say that there is no evidence that customer data was accessed.

I don't know what that means. You know, there could be no evidence of a lot of things that have happened. I don't know in this case if it did or did not happen or whether they're suggesting it didn't. But hopefully all is well over there at Lumen. Is that sort of like the old, when did you stop beating your wife, Robb?

That joke? Yes, exactly like that. All right. Moving on. We have a blog from Red Canary talking about a Defender's Guide to Identity Attacks.

Yeah, this one's not one of their more technical blogs. This one kind of just goes through at a high level what, what kind of attacks you might think about for identity and what you might want to do about them. Like I said, at a high level, you know, identity attacks focusing on authentication vulnerabilities, stolen credentials, um, obviously things like taking someone's MFA is going to be part of that. Um, they talk about some of the techniques: phishing, credential theft, credential stuffing, session hijacking, account takeovers, privilege escalation, insider access, um, all kinds of different types of attacks. And then they do go into the, the kind of controls or the protections you might want to have in place there, um, using unique passwords.

Although I'd say, you know, you of course use unique passwords, but you got to partner that with MFA, which is what they say next: enable MFA. Be wary of phishing attempts. Of course, we all should be thinking about it, but remember that they can be really good. They can trick just about anyone. Secure your session tokens, limit privileges, so, you know, implement least privilege everywhere, and monitor for suspicious behavior.

Yeah, also along with this blog, there is a video, a YouTube video attached to it that goes into depth on, uh, on some of these things. So if you want to hear a little bit more in depth, check that one out as well. All right, our final story of the week is a, it's a press release from, from our friends at Swimlane. Um, they, you know, they've had a great run and we've been with them the whole time. Um, it's been fantastic to watch those guys develop so well.

Um, this is just a mention that they won an award on the Best in Business list. Um, that said, um, it looks like things are going pretty well for Swimlane. Yeah. Uh, not a lot of details on what the criteria are to be on the Best in Business list, but congrats, you're on the list. Yeah.

And of course we just wanted an excuse to talk about our friends there. Exactly. All right, uh, those are the news stories we have for this month. Let's jump over, we'll talk a little bit about some of the upcoming events, and then after that we'll jump into some jobs. All right, coming up on the 9th, ISACA Denver has their January chapter meeting, but this is online.

Do not drive somewhere because they will not be there. Well, you could drive, but then you'll just have to get online and— yeah, you could drive to wherever you want to use your computer. Exactly. Uh, on the 16th, the Let's Talk Software Security group is doing their monthly event, Is Software Security a CISO Priority? On the 21st, CSA Colorado is talking about Building Security Automation That Works: From Alert Overload to Streamlined Response.

All right. On the 22nd, ISSA Pikes Peak is doing their monthly chapter meeting. On the 24th, I just scrolled right past it. ISACA Denver is doing their She Leads Tech event. All right.

And then finally, it's a little bit outside of January, but I wanted to talk about it anyway. Wild West Hackin' Fest is doing their first Denver edition on February 4th through 7th. So check that out. Going to be a big conference here in Denver. All right.

Let's jump over to jobs. Altura Mountain Company is hiring an IT security architect. PatientNow is looking for a cybersecurity engineer. NBCUniversal is hiring a Director of Infrastructure Security Services. Spectrum is looking for a Security Engineer III.

Scout Clean Energy— Scout Clean Energy is hiring a Senior Manager of Cybersecurity and Technology. S&P Global is looking for a Business Information Security Officer for their Enterprise Data Organization. So yours just barely loses out to mine for longest of the month. Bank of America is hiring a cybersecurity product manager focused on third-party cyber assurance. Now we're coming into the fun section.

York Space Systems is looking for a cybersecurity systems engineer. General Atomics is hiring a space cybersecurity architect. General Atomics is a company that supports nuclear energy and nuclear reactors that That's why I thought that was pretty cool. How is there not more nuclear energy going on here? I don't— maybe there's a— maybe General Atomics is bringing it back.

Maybe we should talk to those guys. Yeah. And finally, NREL is looking for a cybersecurity engineer. Awesome. Well, that's it for news.

Our first episode of 2025 does include an interview though. So awesome. We get to sit and listen to Richard Staynings, who sat down with our very own Frank Victory, and we get to know Richard a little bit better and, and get some, get some of his knowledge dropped on us. Looking forward to it. All right.

Well, that is it for January. We'll talk to you next month. Thanks, Robb. Hi, this is David Bratton, VP of Congruence. Welcome to Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Good morning. Good afternoon and good evening, Colorado Equal Security. Welcome to this wonderful podcast. Welcome to 2025. This is the Year of the Snake, also known as the Year of AI, possibly of space exploration and sustainable technology.

My guest today is Richard Staining. He is a renowned thought leader, an author, a public speaker, and an advocate for cybersecurity specifically focused on healthcare and life sciences. He's currently the chief security strategist of Cylera. Right? A pioneer of medical devices and IoT security, author of Cyber Thoughts, healthcare industry blog, right?

He teaches postgraduate at the University of Denver, right? And as you can tell, he doesn't have enough to do, so he wants to jump onto a podcast with me. Welcome, Richard. Before we get started with anything though, and let you really talk to you and get going with this podcast. So I'm going to do an icebreaker here, and Richard has not heard this question yet.

So, uh, Richard, I'm going to put you on the spot here. If you could be a character in any movie, what character and what movie would that be? Oh, I don't know. That's a— it's an interesting question to kick off a new year, but, uh, I'm a big fan of, uh, of some of Harrison Ford's movies, so would probably be one of his, I would imagine. So Whether that's, you know, futuristic Blade Runner-esque type, you know, sci-fi thing or something a little bit more down to earth, knocking out the bad guys single-handedly.

So those are the types of, types of movies I would, if I were to be in, I would, I would want to play. Let's see. So would that be— are you good with a whip? How about that one with the Raiders of the Lost Ark? Well, I could be.

I'd have to— I'd certainly have to practice my whipping skills. Okay. Got to practice your whumping skills. Okay. Well, how are you doing today, Richard?

It's, it's, it's great to be here. Thank you very much, Frank, for inviting me to Colorado Security. And it's an honor to be here and share a few thoughts with, with your listeners. Awesome. Awesome.

So we're obviously going into 2025 and we know one thing, though, by the way, and I notice is that you do live in Colorado. Or technically, I think you buy the taxes you pay. But I think anyone that knows you really knows that you live about 30,000 feet up in the air, right? As I think we've been trying to get this podcast set up for a couple of months, but I can't even count how many countries you've been in the last 2, 3 months. It's, it's pretty prolific anyway, and it really interrupts my skiing, my skiing skills, particularly at the beginning of the season.

But yeah, I tend to live at 38,000 feet. When people ask my wife where I am, she says, I have no idea. Contact United Airlines. They'll know. United Airlines knows where you are.

So she doesn't really know anymore or doesn't care or should we even make that delineation? I think she's gone past caring actually, as long as I come home at the weekend or as long as I take her with me to some of the more exotic locations that I find myself in. I know that feeling when I used to travel a lot. Uh, my wife has gone to, let's say, Washington, DC with me, Dublin, etc. She decided not to go with me to, I think, um, Iowa or a couple of places out there.

That's understandable. Yeah, it's just like, you want to go? She's like, no. But, uh, she's gone to some of those most interesting places for me. Yeah, yeah.

Uh, I just got back from a trip, uh, with my wife, um, to Malaysia actually and Singapore. So we tacked on a few days and did some fun stuff there, and she was, uh, very eager to come along on that particular trip. Was that business or pleasure? Well, it was a bit of both actually. So I had a business meeting in Singapore, and, uh, I tacked on, um, some meetings, uh, in, uh, in Kuala Lumpur and Penang, and, uh, then, uh, 3 or 4 days on the island of Langkawi.

And if you've If folks have not been there, it's absolutely beautiful. So well worth a trip off the beaten path. When you travel that much and when you're dealing with countries, foreign countries like that, what's your biggest challenge?

Trying to fit in meetings back in the US when you're, you know, 12 or 14 hours time difference away from the US. It leads to some, you know, 3 AM, 4 AM calls, which can be a little bit disruptive if you've got a full day of meetings or full day of activities in the time zone in which you find yourself. So Cylera does a lot of work in the Gulf, and that is, you know, diametrically opposed from a time zone perspective to Colorado. So that can lead to some tougher challenges. You know, I also spend a lot of time in the UK and Europe, and, you know, that 7-hour time or 8-hour time difference can be a lot more manageable, you know, particularly if you don't mind, you know, losing some of your evening times to join calls back in the US.

But that's probably the biggest challenge other than, you know, perhaps the jet lag. And I seem to be immune to it compared to most people, but I know a lot of people suffer with that.

Well, obviously you have an accent, right? So you didn't grow up here. At least I'm assuming you didn't grow up here. But what about like local cultural differences?

Are there anything interesting, any advice that you'd give to our listeners if I was to, let's say, follow you along on one of your trips? Understand the culture in which you're immersing yourself, the language, the nuances. Plainly, you can do things in the United States which are fully acceptable in business meetings, for example, which are not acceptable in East Asia or the Middle East, right? Understand the environment in which you're in or try to make an effort to understand it. You'll eventually pick it up.

I travel so much, it's kind of second nature to me now. But, you know, just a simple act of offering someone a business card is a very different prospect if you happen to be in Japan compared to, you know, Colorado where you may just pull one out and throw one at someone, right? In a very blasé manner. It's a very formal process in Korea or Japan or even China in many cases, right? So what makes it different in that case?

Just the way that you represent yourself, you present your business card as if you are going up, you know, in front of, you know, a very important person regardless of their rank and their position within the organization. But it is an act of representation an introduction, very formalized compared to our very informal manner of offering a business card to someone and say, hey, give me a call sometime, we'll go out for beers, right? It's just wholly different. And, you know, obviously other cultures like the Gulf are significantly different as well. The way that you greet someone, that you welcome someone, the way that you talk to someone, right?

There's a lot more foreplay involved in negotiations, shall we say, or business discussions in other regions than there are in the US. And that takes a little bit of learning for many people that, you know, perhaps haven't traveled quite so much as myself. I grew up in the UK, did my first couple of degrees there and, you know, moved to Australia and Asia and spent many years living in China, Hong Kong, Japan, Malaysia, Singapore, you name it, right? I've lived in 30 different countries over the course of my career. And I guess that's why, you know, traveling comes second nature to me.

Well, when you— so from some of those advices, let's say from the business cards, what kind of advice, what could you possibly bring back to our folks here in Colorado Maybe a good thing. Like, what would— what could you advise? Maybe just to say we should maybe start this in Colorado and bring this type of culture into Colorado. One thing I particularly like when I'm working in Europe is the punctuality of meetings, right? In Germany and Switzerland and Austria, if you don't show up to a meeting 5 minutes early, you're considered late, right?

And that is unacceptable. It's verboten. You know, it's not allowed, not permitted. And I think we could do a lot better about being punctual to meetings. I know a lot of my business colleagues tend to book their meetings back to back and as a result, sometimes show up to my meetings 5 or 10 minutes late because they're, you know, their meeting went on a little bit longer than anticipated or they weren't watching the clock.

And that can be extremely disruptive. So I think, you know, other cultures wouldn't accept that. So why should we accept that in the United States? You know, it's different if you say, look, I'm going to meet you at the pub or a bar, you know, between 4 and 5 and, and you show up at 10 to 5, right? That's a different kind of faux pas, shall we say, rather than, you know, not showing up to a business meeting on time.

Yeah. Oh, you know, I've noticed that. I mean, being military or prior military myself, I was always, you've got to be 15 minutes early to a meeting. That's 15 minutes is on time. But I've noticed that folks that do not have that, it's like, well, we got to be there in 5 minutes.

Well, we've got a whole 5 minutes to be there. We don't want to be early. Right. How would you address that? I think it comes down to a learning experience, really.

And I think if you are the leader of people, as I've been for much of my career, then you need to instill those values in your people, right? You need to tell them, look, this is the culture, this is the behavior I expect from you as a member of my team or as my organization or my company or my division or whatever. You know, this is how I like to run meetings. I don't find it acceptable for you to, you know, act in a way that's contrary to that. And I think it's down to all of us as leaders kind of make sure that our people are following in our footsteps and, you know, and are adhering to the same, you know, business ethics, security, you name it, standards that we, you know, we expect and we instill upon our people and our customers.

Okay. Well, I'm gonna put you on the spot here. Let's say that you were teaching me that and I came back and I said, no, I don't agree with you. I think that being 2 minutes early or even just right at that minute is on time. How would you address that?

I, I've, my, you know, when I've had to do this in the past, I've had to, you know, suggest, suggest to people that perhaps they're in the wrong organization or the wrong unit, right? Or how long do they intend to stay here? You know, those sorts of things. I mean, obviously, you need some level of upward respect in, you know, in an organization, but conversely, you also need downward respect, right? So, I'm not a stickler for rules and regulations for the sake of it, you know, like the military would be, for example.

I'm open to suggestions. And in the course of my cybersecurity career, I've had some brilliant suggestions from people that are many levels down in the organization that they've been able to perhaps think in a less colored way with less preconceptions about how to deal with a security incident or a data breach or someone that is breaking the rules as far as, you know, security policy goes. Does any of that change depending on what country you're in? I think it does, you know, to some degree, but I think it depends on who you're dealing with, right? So if you are dealing with a sheikh or a sultan, or someone of that level in the Gulf, then, you know, your options are limited if that person happens to report into your organization.

In actuality, you know, there would be a dotted line at best anyway. But plainly, you have to understand the cultural nuances of the environment in which you're in. Okay. So do you think that growing up, I mean, you, you've grown up in cybersecurity. Have you always grown up in cybersecurity?

Is that how you learned this, or did you start somewhere else? So I started, you know, academically in a, in a humanities social science space. My first couple of degrees were in that space, and I made the transition naturally over to what became information security long before we called it cybersecurity through, through the side, through consulting, through IT infrastructure, and through a whole load of process procedures, standards development type work. My degrees in cybersecurity came much later in my career, you know, as I consolidated my position in there. And I think I'm not unique in my generation.

In that most of us that came into cybersecurity did so from some roundabout way. We came in from application development, you know, and became, you know, embossed in secure application development methodology or, you know, code string testing, etc., right? They came in from IT infrastructure, from firewall management, router management, and a whole heap of other skills in that space, all came in from a policy and compliance perspective, from doing audits and other aspects that had a security component to them and have tended to focus on the cyberspace for various reasons, most of which we're extremely grateful to because we are 3 million people short in the cybersecurity profession, as you, as you well know. So absolutely, we need all the help we can get. Well, you know, I think it's interesting.

Do you think that your humanities, your Bachelor of Arts degree has helped you though in any way? I think it has. I mean, my undergrad was in government and public policy, and I think there is a geopolitical nature, an increasing geopolitical nature to cybersecurity, particularly when we look at threat actors, you know, today compared to 5 years ago or 10 years ago. Right. I mean, China's been at the intellectual property theft game since the APT-1 report, you know, back in 2004.

Right. But, you know, the Russian actors or the collaboration between the Russian crime syndicates and the Kremlin is a more recent development. Right. That has not fully been proven but is considered to, you know, to exist to some degree, shape or form. And I think understanding how government works, understanding how public policy works, understanding how to use things like, you know, the Budapest Convention, right, the Tallinn Agreement, the new UN Convention on Cybercrime, and how these are going to impact our ability as cybersecurity professionals to secure our organization.

And then I think there's a second dynamic there, which is really about collaboration. With the forces of government, right, about intelligence sharing, threat sharing, the sort of stuff that Interpol shares with many of us today and that we share amongst our peers at ISACA and ISAR and OWASP and other cybersecurity meetings, you know, around Colorado. But I think there is an increased need for government to assist us to defend our organizations against what are essentially nation-state hackers or nation-state-sponsored criminal actors. You know, it's no longer a case of hacktivists and script kiddies trying to break our defenses and prove a point, right? It's out-and-out crime syndicates that are highly organized, highly professional, and highly structured in their attempts to extort money from us, to steal intellectual property, to steal nonpublic information, and then to extort us into paying some level of ransom in order to not have our data published on the World Wide Web.

And sometimes that works. Most of the time it doesn't. So you haven't, like, felt the need to maybe belt out Shakespeare in any of these meetings or anything like that? Yeah, I'm not sure that people would really understand the nuances of Shakespeare, but I'm not necessarily— I'm not sure I do, quite frankly. But, but, you know, it's funny that you named for those career fields coming into cybersecurity.

I mean, I've had students and I've mentored people coming in from one. I think one came in, he was a zoologist. I have had another good friend that was a geologist, and probably one of the best pen testers out there used to be a Honda service advisor. Works on cars, enjoys working on cars, but he is a dang good pen tester.

Do you think, though, that a degree in cybersecurity or degree anywhere is necessary for this industry? So I think the jury's out on this, right? I mean, we've always looked at cybersecurity as being a profession, right? And by profession, we mean a graduate job, right? Someone that has proven themselves academically.

They can write reports, they can digest and assimilate and synthesize information in a way that allows others to understand what they've discovered and can report findings up the food chain to the ultimate arbiters of risk, which are the CEO and the board of an organization, right? You can't necessarily write threat reports unless you've got writing capabilities. And, you know, the way to accomplish that is really with a degree. I suppose I'm going to put my academic hat on here as a, you know, as a member of the teaching faculty at DU and say, yeah, absolutely. You know, everyone should really have a degree and ideally a master's degree if you want to get to the top of the pile and become a CISO, you know, or a senior director in a security role.

But I think there are a lot of very, very capable people that don't have academic degrees, right? Some of the brightest people I've worked with in my career dropped out of university, you know, when they got their girlfriend pregnant in the freshman year or ran out of money in their sophomore year, right? Or just got bored. One guy was absolutely bored to death with his university degree and he got a job in IT working on the service desk and, you know, eventually made himself, made his way over to cybersecurity and was working alongside me. And I discovered fairly quickly that he was as bright as they came and suggested he go off and get some certs, right, to prove that, you know, his worth in the cybersecurity space because he was looking at maybe changing jobs and he just went through you know, the Certified Ethical Hacker and God knows how many other certs on a fantastic basis, right?

Excuse me. He would, he would, we would go on a trip to a hospital at the other end of the state and he would load up the trunk of my car with, you know, manuals and he would sit up and he would read those manuals and then he'd come back and he'd take a test and, you know, he'd score in the 95th or higher percentile. Of every test that he took. So I suggested to him, oh, you might as well go back and get your degree, right? Because, you know, you're halfway there anyway before your credits expire.

And he started, he found an online degree that he could do in the evenings and weekends, went back and got his, was working on his bachelor's degree, then signed up for a master's degree program at the same time. How he got in, I don't know. Obviously, you know, different university policies at different locations. But did that and did an MBA at the same time he was doing his master's in cybersecurity and computer science. So I think it's not just a question of you proving yourself to get a foot in the door, but I think it comes down to aptitude.

And I would much rather have someone on my team that had the right attitude towards cybersecurity, a willingness, a dedication, and the aptitude to understand, you know, what cybersecurity is about and what things mean. When you see something come across your screen, you see a threat alert, you see a SIEM alert, right? You see something else, some other instrument playing out in front of you that raises your alarms.

I think that's interesting because, of course, I am, I'm a teacher too. I, you know, I'm currently teaching a couple of courses at more entry level for CU Boulder. And no, I get asked about, of course, the degrees and the certifications all the time. Of course, I give them the politically correct and totally worthless answer of it depends. But, you know, part of it is you've got to apply yourself.

I think we can all agree that you've got to apply yourself. You got to have that piece. You know, because the one thing we can't teach is aptitude or as I like to say attitude, right? We cannot teach you that willingness to go after and as the example you just gave us. Exactly.

You've got to have an inquisitive mind and your mind has to be able to draw the lines between dots and draw conclusions, right? Or possible conclusions and then investigate that. This is not a a simple job of, you know, making widgets, right? It's not a 9-to-5 job, right? Or even a shift job of making lattes, you know, at your local coffee house, right?

This is a very different type of job and it requires a different kind of dedication perhaps than many other IT roles, for example, right? You know, of coding or, you know, writing applications or managing the IT systems of an organization, you can to a large degree in IT switch off at 5 o'clock and go home. In cybersecurity, you know as well as I do that there are times when you can't do that, i.e., there's something happening that requires that you miss dinner and you work till 2 a.m. in the morning in order to investigate an incident or to write a report or to you know, update something that's required. And that's not for everyone, unfortunately, right? There are a lot of people out there that want to do their 9 to 5.

Yeah. Well, you know, what's interesting is that, you know, some people say, of course, and kind of, I think along the lines of what you were talking about, you know, this isn't a job, this is a career. But for at least a lot of us and including myself, this is more like a way of life. I mean, this is not only my career, this is also my hobby. When I'm not at work, I go and I tinker around.

I like to mess around. I'd like to see these new brute force tools and, uh, you know, the new Kali and, ooh, let's look at this vulnerability and can we exploit it and can we code against it and can we detect it? And we do that because it's fun to do, you know, or, you know, it was interesting. My wife told me we had to go to Costco and I said, we're going to leave about half an hour. So I went downstairs.

I went to go work on a couple of laptops. Next thing I know, it's like 3 hours later. I come back and she's like, oh, you know, I thought we were gonna go to Costco. She's like, I left and I came back already. I came downstairs, you look like you were having such a good time, I just left you there.

I was just enjoying myself so much. Yeah, my wife's the same. So, uh, yeah, and it's not just Costco I miss occasionally, right? So if I'm ordering something, it's, uh, it's sometimes much bigger things like family dinners and what have you. I do have a kind of a question that's been building up and something that you mentioned earlier, especially since we're kind of talking about younger audiences here, younger people.

You said something about downward respect. What do you mean by that? I think as a leader, as a boss, as someone in charge of a group of individuals, you need to respect those people who work for you in the same way or in a similar way, but not identical way, in the way that they, you expect respect from them, right? Now, you know, as a former military that you had tremendous respect for your officers, your leaders, right? And, you know, that it went both ways, right?

If the men didn't respect the officer, their ability to lead the men was severely impeded, right? So I think you need to instill respect in your people, and that comes through by listening to them. It comes through by attempting to understand their concerns, complaints, and everything else that perhaps you don't necessarily agree with, but you can understand where they're coming from and working with individuals to overcome hurdles that prevent them from operating at 100%, doing their best. Okay. So you, how would you handle, I mean, like, could you give me an example of one of those hurdles?

You know, obviously we're on a recorded podcast here. We don't want to give any personal information away, but what would be maybe a hurdle and how would you solve that? So in one of my roles, I had one of my incident responders who was, who preferred to document everything after the fact rather than take notes or documentation during handling with an incident. And, you know, you know as well as I do, some of these incidents can go on for days, right? And when you're tired, you tend to forget things.

And over the course of you know, a really complex incident, assumptions that you make at the beginning or during the early part of an incident tend to be overwritten by new assumptions, by new paradigms, through, you know, a new conceptual lens that you develop based upon the evidence that you gather as part of that investigation. And I had one individual, as I said, that didn't like to document everything. And, you know, he had good cause for it because he was a very good incident responder. But, you know, it used to drive me insane that he couldn't remember, you know, certain things at the beginning. So I ended up actually pairing him with a much junior person that could just document things because this guy just wasn't focused on it.

And together, they, you know, they were a very powerful team. So I think you need to adjust your mindset and look at practical ways of overcoming obstacles as a leader.

Okay, that's, that's actually great advice. That's great advice. Um, talking about incidents here, you know, what do you think is our greatest security challenge today? Now, I'm not trying to solve it, and also keep in mind that we only have a very limited time, and, you know, I'm sure that you and I would— could have a fascinating conversation over the next couple weeks, but If you were to choose, let's say, one thing, what would that be? And it doesn't have to be an APT.

It doesn't have to be a specific attack, just a challenge in general. Yeah. How long do we have?

I'll limit you to about 3 and a half minutes. How about that? Or, you know, just kidding. I would say from where I stand today, I'm not involved in day-to-day security operations as I once was. Right.

I'm not involved in the same way that I was leading a security team. I'm more involved at a strategy and policy and thought leadership role across cybersecurity and particularly focused on critical infrastructure and in particular healthcare. Right. I've dedicated a lot of my career to protecting hospitals, payers, providers, pharmaceuticals, life sciences. Organizations from rising cyberattacks, right?

And different types of attacks, obviously, you know, ransom and extortion in the delivery space, intellectual property theft and commercial trade secret theft in, you know, in the pharma space, right? It's kind of the threats run the gamut. I would say the biggest, my biggest concern today is the fact that, you know, cybercrime is rising at an exponential rate. Groups are becoming increasingly emboldened. Perpetrator groups are becoming increasingly emboldened in terms of their, their frequency, magnitude, depth of attacks and who they, you know, who they attack.

There seems to be no ethical restraint around, you know, launching a cyberattack against a pediatric hospital. For example, right? Which is apparent, right? I mean, no one's— you know, little babies are no one's enemy, right? And should be afforded all of the protection.

But this is, this is who we're up against, right? And I think a lot of that comes down to the nature of our cyber adversaries. The fact that this is an extremely lucrative industry for criminals because we as defenders haven't figured out how to build resiliency into our systems and how to respond and recover from a cyberattack in an expeditious manner. And as a result, we're paying ransoms, which is fueling the ransomware industry. Right.

53% of— if I can disagree with you for just one second, though, here, I think that we could build those in. But then, of course, the business wouldn't function anymore. And I think that's one of our biggest challenges, right, is we always like to say we can make this system 99% secure, right? I was talking to a VP one time, and he says, I want my application 100% secure. I said, great, take it off the internet.

And he looked at me like I had a third eye. And I, one time, the one time where, you know, the filter between my brain and my mouth worked, because I looked at him and was like, Yeah, you're stupid. So how would you react to that? I mean, how would you— when we say we want to make them secure and everything else, but we have to keep that balance opened up. And I think that's one of our greatest challenges.

Or you disagree with me and feel free to disagree with me. No, I think we need to, we need to strike a balance between security and function, functionality. Right. And if you look at the healthcare space, We have turned what was a fortress citadel, right, of firewalled, isolated hospital networks. And those— that citadel is now, you know, all the walls have crumbled down, all the drawbridges have been lowered, the moats have been drained, the alligators have been removed.

And, you know, the firewalls look like Swiss cheese. And we've done that to facilitate enhancements in the healthcare industry with portalization of medical information. So instead of you having to call someone to make an appointment, you can go online and you can read your results online. Your insurance can access your data without having to go through you, right? You can access your medical records from a mobile application on your iPhone or your Android, right?

And your, your your level of physical activity is recorded by your Apple Watch and pushed to your iPhone and then sent up to the cloud where it can be connected to your personal health record in some medical institutions. Australia has connected their consumer medical data to My Health Record, which is the national health record in Australia. We haven't quite got don't even have a national health record in the United States, but we have— some hospitals have facilitated some of that. Most haven't yet, right? So it's a continuum.

There are definite advantages to exposing data and using data and storing large amounts of data. We have massive data lakes in healthcare, the largest of any industry, right? We create more data in the healthcare space than the next 3 industries added together. And that data is very, very useful for training artificial intelligence algorithms, you know, around, you know, radiological medicine, around machine learning algorithms that are used for clinical decision support. And it will be a major driver in the advance of precision or personalized medicine, right?

So we have one pill that is targeted for us. And instead of having to take a course of 30 antibiotics that are broad spectrum, we have 1 or 2 magic pills that basically cure our particular medical ailment. We're not at that level right now unless you happen to be a multibillionaire that can afford that level of investment in your healthcare, your personal healthcare. But that's all coming. These all present risks.

But I think at the same time, we need to understand the level of risk or senior executives need to understand the level of risk that a business faces. Some of these risks are existential, right? If, excuse me, you might have cut that out.

If that risk becomes too great, then a business could go under. And we've seen this, right? We've seen a whole load of mom-and-pop joints that have gone over. In the healthcare space, we've seen a whole load of doctors and dentists that have been hit with a cyberattack. They haven't been able to afford the fines or the restitution of their data, and they've gone out of business.

They've shut up shop. These are people who, you know, trained for 10 years to be a general practitioner, a primary care physician, or a dentist, and are now saying, look, this is a very different industry to the one I trained in 20, 30 years ago. This is not what I signed up for. Or they alternatively weren't aware of the risks because cybersecurity is gobbledygook to them, right? They speak a medical dictionary, not a cyber dictionary like you or I would.

And, you know, as a result, you know, weren't able to put in place the appropriate security controls in order to protect their businesses or the secure— the appropriate resiliency for their business to withstand this sort of attack. And I think that comes down to us as cybersecurity practitioners being able to translate deeply technical cyber risks into language that other business leaders, that laymen, as it were, might not be able to fully comprehend the significance of what we're saying and understand. Okay. I mean, with all your experience and everything, you mentioned a pill to solve, you know, of course, multiple diseases, things like that. Are you going to create a pill to solve all our issues within cybersecurity?

Is that within your docket? Yeah, I'm gonna do that. You're probably more qualified. Yeah, I think right before I retire, I'm gonna do that. And then I'm gonna buy myself an island somewhere, you know, and disappear off into the sunset as a gazillionaire.

Yeah, if I could do that today, I certainly would. But, you know, an island or a space station, which one? Well, as long as it's not next door to Elon Musk, it's fine by my book. So awesome. Awesome.

So Do you think you'll eventually retire?

I don't know. I doubt it, right? I'd like to keep going for as long as I possibly can. I'm quite a few years away from retirement. I've been in the space for 30 years, but I don't see myself retiring anytime soon.

I enjoy the challenge of what I do. I live for cybersecurity. I don't live for the golf course. And how many rounds of golf can you play a week, right? You know, this there's only so much before you start banging your head against the, you know, the clubhouse wall, I think.

So I foresee— I see you have experience in that area. Yeah, that's my golf game. That's nothing to do with the frustration of not having anything else to occupy my mind. But I'd like— I like giving back. I greatly enjoy teaching.

As I say, I teach the master's program at DU and, you know, I every quarter I have, you know, some very, very good students. And if I can get all of those students to leave with more knowledge than they came in with and a greater awareness of understanding when, you know, they go back to work, then, you know, that's a good thing. I think all of us owe it to ourselves really to pass on through our legacy, through our writing, through, you know, anything that's recorded, that we've recorded over the years, including Colorado Security Podcast, which hopefully will be in the Library of Congress at some point. You know, you know, those jewels of information can be shared with future generations. Awesome.

Awesome. Well, we're coming upon the end of our time. Some final thoughts.

I would say for, you know, as a message to those who are perhaps considering a career in cybersecurity, yeah, stay, stay with it, stay with the program, right? Get with the program, stay with it, build persistence, shall we say. It's— there's a lot to absorb if you want to get into this space. You don't have to learn everything in one day. You know, you build data, you build information, you build understanding incrementally.

There are a lot of open positions in cybersecurity, as I alluded to the beginning of the podcast, 3 million positions right now estimated to be open globally in the cybersecurity space. So, you know, if you're considering your future options, then there's definitely space here and you'll have a job for life. And it will be exciting too. No one ever said working in cyber was dull or boring, that's for sure. Absolutely.

Well, thank you, Richard. You can read more about Richard, watch some of his videos and his blog at cyberthoughts.org. He's got a lot of publications. Richard likes to present here locally in Colorado for ISSA, ISACA, HIMSS, and of course OWASP or Denver OWASP. Remember that we do have the SnowFROC Conference coming up on March 14th, uh, also known as Pi Day, right?

And I hope to see Richard there at the conference. Hopefully he's in the country presenting, hopefully again presenting for us in that area. Uh, well, again, thank you, Richard, uh, for everything. Uh, my name is Frank. I am a guest host here on this wonderful podcast.

I am also the VP of the Deborah Owatz Group. Hopefully we'll get to see you at some of our meetings either at snowfrog.com or meetup.com/deborah-owask.

Again, thank you, Richard, for your time. I appreciate it. Thank you.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado Equals Security.

Back to all episodes