Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 279 for the week of October 6th, 2025. This is Alex Wood, and since you're hearing me, that means that Robb is probably off this month, and since he's not here, we do have a guest co-host.
I'd like to welcome Joe McCallister. Uh, Joe, thanks for being here. Hey Alex, thank you so much for having me. I'm really excited to be here. Joe, you've been a, a member of our community for a long time and a volunteer.
Uh, you help with the, the salary survey that we put out every year, which I know is a ton of work, and we appreciate that. Maybe you can tell the audience a little bit about yourself and what it is you do. Thanks. Yeah, I am Joe McCallister, as mentioned. I have been in the security and IT space before that for quite a while now.
I'm originally from Iowa, so all my Midwestern people, hello and how are you? I have a couple of kids. I live down in the South Metro. And most of all, for this especially, I'm excited to do just a little bit and return the favor of how much this community and this this group has done for me over the years. The network, the relationships that I've built here are those for a lifetime.
So I'm just happy and excited to be here. Awesome. Well, thanks, Joe. We appreciate you being here. Robb's a slacker.
He's traveling for work. So glad you could fill in for him. All right. Before we jump into the news, we've got a few announcements. First, We'd love it if you joined our Slack workspace.
If you're not in there already, if you go to the website colorado-security.com, there is a form you can fill out there to request access. While you're doing that, the form is dual use now. You can check the mailing list box and get signed up for our mailing list as well. We'd also love it if you would rate us and subscribe on your favorite podcast player. That means this will get delivered to you every month when it gets released, and the rating will let people know how great of a podcast it is.
And finally, if you're not doing any of that stuff, we'd love you just to tell a friend about Colorado Equal Security and all of the great stuff that we have going on here. And the last announcement, uh, we would like to thank all of our annual sponsors. Uh, this year is the first year we've had, uh, sponsors for Colorado Equal Security, and, and we really appreciate them. Uh, Armis, CrowdStrike, Red Canary, and Zscaler. We couldn't do this without them, and we really appreciate their support.
All right, jumping into the news, uh, the first story that we have is sort of a follow-up to a story that we had last month, uh, I guess sort of a second piece that happened after we talked about the last one. Uh, EchoStar unloaded more of their wireless spectrum, this time to SpaceX for $17 billion. This is following on the heels of, uh, them selling a different piece of spectrum to AT&T for $23 billion. Joe, what do you think about that? Yeah, you know, seeing Elon Musk and SpaceX in the news really isn't, uh, out of the ordinary these days, it seems.
But he's been a bit quiet, so this is really interesting to, to hit the headlines again, um, especially for a Dougco County like this to be in, in the news. I'm really interested to see if it is kind of a power move to, to get into the cell service arena, or if it is aimed at what EchoStar, uh, and Starlink, excuse me, actually received last year, which was $9.1 million federal funds to expand rural internet access in Colorado.
Yeah, so I think, uh, it's pretty interesting. And I think Robb and I actually might have speculated about this, um, last month before this was announced, whether there was going to be another announcement for some additional pieces of their spectrum. But, you know, they're still trying to build out the, the Boost Wireless, uh, network and They were trying to do it themselves, but with these sales, it really is relying on other providers to help give them what exactly they need for, for building out that wireless network. In this case with SpaceX, you know, as part of the deal, they now have access to the direct-to-satellite cell service with SpaceX. So the Boost Mobile customers will be able to use that instead of EchoStar, Dish Network providing that directly themselves.
So just a little bit of a different way to deliver that service, but still trying to get them to the same outcome of being another wireless carrier. Yeah. You know what else might be a little interesting to the audience is going to be like we— AT&T also bought some of this, right? So yeah, they're kind of feeding some, some competition in the market. And I mean, great news for EchoStar.
They're able to pay down more debt. And I think the shares jumped something close to 20% on this news, if I'm not mistaken. Yeah, I think, uh, after the first deal, I think it jumped like 80% or something like that. And then yeah, another, another 15, 20 or something like that after the second deal. So, uh, all those folks that own EchoStar stock, uh, I'm sure they were super happy for this.
Yeah, little old me is hindsight 20/20 over here. But, uh, also of note in the news was CU was ranked number 1 in launching startups for university discoveries, or from information coming from discoveries and intellectual property developed on campus. Uh, this is huge huge. It's really interesting for me to see that CU Boulder is right up there with some of the big dogs that we think of when it comes to developing these startups and putting them out there. Stanford, MIT, even Michigan.
And we are now right up there. I'm really curious what you think, Alex, is driving that surge. What do you kind of see is happening up here? Yeah, I think it's interesting that CU Boulder won. They were number 1 in 2024 by a good bit.
The second university was University of Michigan with only 28, and CU had 35. And they were really close to the all-time record, which was from Stanford in 2022 with 38 startups launched in a year. But, you know, part of the article talks about the processes that they are using to make it easier for these startups to use the intellectual property that's coming out of the research at CU. So, you know, they have sort of a standard licensing model that's called EASE. EASE, which makes it easy for startups to, to license this technology, which obviously is, is one of the pitfalls, right?
Um, that they don't necessarily own it, at least not outright originally. So that, um, you know, this gets them a head start on doing that. And then they've also, uh, the venture partners at CU, they have this Center for Translational Research, and, uh, that helps bridge what they call the valley of death between the early-stage research and getting it commercialized. Which I guess is a big problem, um, from taking that research and how it originally is and getting into the hands of startups for a, a real commercial product. Yeah, clearly they're doing something right.
I mean, 10 years ago it was only 4 to 6 startups a year. So something to be said about making it easier for these things to come out of CU Boulder. And, and kudos to the teams up there for sure. All right, uh, jumping to our next story, uh, this is again as a follow-up. I think we talked about this last month.
Um, you know, the Trump administration announced that they are going to be moving Space Command from Colorado to Alabama. And this Colorado Sun article talks a little bit about, uh, some of the, uh, the losses that we might experience here in Colorado. Um, you know, one of the things that was mentioned was that Colorado may lose up to 30,000 jobs Excuse me, when, uh, when that move happens. But the article, I think, paints a, I guess, rosier picture, a less bleak picture about what might actually happen. Yeah, it looks like from the, the substance there, only about 1,700 employees are based at Space Command, which will be the, the relocation kind of impact in, in the short term, where we don't have to— I don't know if you've heard of this, this concept before, but it is, uh, if an article asks a question in the headline, the answer's typically no.
Uh, so I read these with— it's kind of a grain of salt, right? Um, of course more going there. I think it will. And I'm curious kind of to get your perspective on, uh, what do you think? Do you think this is, is a little bit of symbolism, a little bit of posturing, or is, is this over the long term going to be something we actually see Colorado potentially hurt from a bit more?
Alabama still doesn't make sense to me, but That is— yeah, I think that— I mean, there obviously will be some hurt, but I don't think it's going to be the amount of hurt that was originally projected. So it was that, you know, the Trump administration said that it's going to bring 30,000 jobs to Alabama, which is where that number came from. But obviously with this, um, uh, this research that they're talking about here, it's going to be much less. Um, there's a U.S. rep from Alabama that, that said a number that was more like 4,700 You know, you mentioned that 1,700 from relocation, but then, you know, maybe another additional 3,000 indirect positions that would— that might move to Alabama. So not nearly as big as it was said.
But the Denver Metro Chamber of Commerce estimates that Space Command brings in an annual economic impact of around $1 billion to Colorado. So if Space Command is leaving, then obviously some or all of that $1 billion is going to go with it. Yeah, and they do a good job in this article, I think, of, of alleviating some of that fear. A billion's not nothing, you know. You don't, don't just sneeze at a billion dollars.
However, aerospace brings in about $38 billion, uh, and about 240,000 jobs in the state. So as long as there's not, you know, a tangential or larger impact from, from this kind of move, I think we're, I think we're going to be okay. Yes, right. Yeah, moving on, uh, the next story we have is Guarding Families Against the Latest Online Threats from our friends over at Webroot, uh, Of course, I feel like we're just seeing this more and more. The numbers only go up, don't they, Alex?
Scammers are increasingly targeting parents and exploiting fear about children's online safety. In 2024, losses hit $12 billion— $12.5 billion, rather— up 25% year over year. And seeing some interesting trends, I'd like to kind of get your perspective on the trends, especially in AI voice cloning for fake emergencies. I feel like we've heard more of these stories. I'm seeing more of them in my newsfeed.
How do you kind of parse this as, as a tech leader but also a parent? Yeah. And, you know, this is one of those Webroot blogs. And often when we see the Webroot blog, it's, it's something that's not necessarily aimed at us as security leaders, but is, you know, is a great thing that we can forward on to our family members to help protect them. But, but yeah, I mean, the scams that they're talking about in here Um, obviously are important and things that, uh, that I have heard of.
Um, but, you know, I think with AI, the, the first one that they have on here, the, the family emergency scams, you know, with, with voice cloning and, uh, even video, uh, that can be cloned. If, you know, if you— your kids are, are posting on social media and other things like that, uh, those images and that video can be used to help you know, create deepfakes and, um, you know, potentially, uh, use us, uh, do a scam like this. Um, and, you know, it, it's often hard to detect, especially if you're not, uh, ready for it. And, you know, the, the sense of emergency and all that kind of things. Um, you know, one of the other things that they talk about is social media kidnapping hoaxes.
So, uh, you know, many times there'll be a, uh, an account compromise of someone's social media and And, you know, then they'll use that to post and try and get, you know, a ransom or other things from parents because they're masquerading as one of their kids. Yeah, and they give some good tips here, right? They talk about pause and verify, MFAs, the stuff we're used to. But to your point, even maybe at our organizations where we might want to help our folks in their not just professional lives, being able to tell them, you know, MFA is just as important at home. But I thought it was interesting they mentioned code words.
I don't know, is that anything you've thought about? You know, I mean, it's— I've heard it in a professional sense. I don't know that I've thought about it in a personal sense, but I have heard other security leaders talk about, you know, some of the measures that they've taken for things like, you know, direct deposit fraud and other stuff like that, where, you know, changing the direct deposit info for vendors, right, or other things like that. They have a code word between, you know, executives and, you know, other people that they're— that everyone knows, but they're not, you know, writing down and putting in a procedure somewhere. So, you know, if you get a fake call from the CEO or the CFO saying, hey, I need you to wire this money right now or change these credentials, uh, then they have this, this code word that each of them know, um, which is a bit out of band so that, uh, that, you know, they can detect this stuff.
So I mean, it seems like a good idea for, for home as well in case, uh, anything like that happens. Yeah, yeah, Alex called, but he didn't say Oklahoma. That's right. Oklahoma, Oklahoma. Um, sorry, it's not a musical podcast.
Um, all right, uh, moving on to our next story. This is the, the first of, uh, 2 blog posts we have from Red Canary. One is a little bit later, but, uh, the title here is Node Problem: Tracking Recent npm Package Compromises. So this, this is, uh, talking about some of the, the recent problems that have happened, um, with the, uh, the Node infrastructure for JavaScript and the compromises that have happened where, uh, attackers have been injecting malicious code into these packages that then get put into applications and, you know, result in all kinds of bad things. Yeah, you know, this is just speaking from, you know, anecdotally, this is something we've been dealing with.
And, and whenever, uh, an article like this comes out, uh, bless the folks over at canary, because it is exactly what we need as researchers and as defenders. But it always takes my day for a spin. But it has been something that we've been looking into. And they do a great job over there at giving us options for mitigation and response, and what we really can do, and what might the future look like for these types of attacks. But curious, Alex, This whole supply chain thing, what, what do we do?
Oh yeah, man, it is rough. Um, they do give some, uh, some ideas in here. One of the things that I thought was interesting, and, uh, I'm not an expert on Node or the, the, uh, the Node infrastructure, but, you know, they're talking about the fact that, uh, while you can configure, uh, multi-factor authentication, it's actually, uh, very granular the way that you can configure it. And oftentimes that results in misconfiguration. And so maybe you have MFA enabled, but maybe not for all of the critical things or only some of the critical things that, that you might want to have multifactor on.
For example, you know, you can have MFA for all write actions and for authorization, or you can have things for lesser. So you might have it misconfigured in a way that allows these attackers to still do what they want when they get an account compromised. Absolutely. And they talk a little bit about the tokens in CI/CD just being completely bypassing 2FA and storing them in the environments that might be accessible to malware or an actor or something like that. We think about, you know, they talk about CI/CD pipeline compromise.
Of course, we're worried about that. But some of this other stuff, it's just, it kind of highlights the good old, good hygiene, read the documentation and follow up, right? Yeah, I mean, not just with Node, but with anything, you always see developers storing secrets and tokens and other things as environment variables and other things like that directly in GitHub or whatever your pipeline is. And, you know, boy, that ruins any of the other security controls you've got in place. It's a bad day for sure.
Next up, we've got SaaS risk management in the age of AI. Whoo. So 75% of organizations, our friends over at Zvelo wrote an article saying that 75% had had a SaaS-related incident in the last year. Of course, we would be remiss if we didn't mention that the explosion of AI assistants and LLM-based tools have created a lot of new blind spots. A term I was not so familiar with was NHIs before this year.
And now it is unfortunately part of my everyday vocabulary.
You know, I'm a firm believer, I'm actually very bullish on AI. I've written a few agents and things like that myself. But, you know, what do you think? Do you think we're already in kind of this Wild West, biggest, big old blind spot that we're creating for ourselves? And I'm interested to see how we tie this back into the Red Canary article later.
Yeah. And there obviously, uh, is lots and lots of movement around AI, and, and things are changing every day. Um, and I think that's part of the problem, right? Everything is moving so fast that, you know, uh, you might put a framework in place— and there's actually another article after this that talks a little bit about that as well— but, you know, you might, uh, put a framework in place, and then it's almost immediately, um, you know, not useful anymore because things have changed so fast. One of the things I thought was interesting about this blog was, you know, Zvelo, they do, you know, intelligence basically, and they're talking about how they can provide more enriched intelligence.
But the article is, it's really sort of targeted towards service providers that are providing things like, you know, SaaS security posture management tools and data security posture management. And while as a security leader yourself, you could utilize some of this same intelligence, they're really targeting those providers to get this directly into those tools so that you don't have to use it directly. And it's included in those platforms so that you can help manage your SaaS risk more easily. Yeah, and I tell you, I like the format. It's in like this question-answer.
It's a, it's a great read. Yeah, it was good. Uh, all right, uh, moving on to our next story, uh, talking about cybersecurity capabilities for maturing your TPRM programs. This was a, a blog from Optiv, and this is actually, um, the second part in a 3-part series about third-party risk management. Um, they have some, uh, links to the, the first part here, and I'm not sure if the third part is out yet or not, but you may be able to find that as well.
This is— well, one of the things I didn't like about this article was that they give you a lot of stats, but they don't really give you many solutions. But maybe that's what the third part does for you. But they're talking about governance and compliance requirements for third parties. And, you know, one thing I thought was interesting is that from this data that they have, 94% of these suppliers have an information— a documented information security policy, which is great. But only 19% have dedicated cybersecurity leadership in place.
So, you know, they, they understand that security is important, but they really haven't put their money where their mouth is yet and hired somebody to be in charge of, of that information security program for them. Yeah, it's, it's definitely enlightening to see some of the infographics they have in there. One of my favorites was the IR plan. Where they say 84% of vendors have an IR plan, but then they break it down by industry. And what I thought was, was very fascinating and actually counterintuitive to what I would think was healthcare.
Uh, they have them at only 6%, uh, having an IR plan. And I, I, unless I'm reading the stats wrong, I, I am downright shocked. Yeah, it's, it's very— I don't— I agree with you, but I don't necessarily understand this one exactly. Uh, what I mean, those numbers, one, seem very low, but also, you know, if 84% total, it seems very hard that you'd have, uh, segments of that with, uh, with these very low numbers unless they're leaving out some segments that are at 100% or something like that, right? So yeah, um, this one's a little bit funky, but, you know, still concerning.
You want to make sure that, um, that your vendors have IR plans so if they have issues they can recover. Absolutely. Yeah. Next up, we have Ping Identity bringing an article about NIST standards, SP 863-4, if I'm not messing those numbers up. My goodness, these standards, I tell you.
The framework itself is around digital identity guidelines and breaking it into assurance levels: identity, authenticator, and federation. And what's interesting is I have been kind of along this, I'll call it a fun little journey over the past couple of years about where kind of our perimeter, especially post-COVID and work-from-home increases, how the perimeter has changed. And no longer can I rely on our controls at the network level. And we're starting to look a lot more at the identity and browser. Curious how your thoughts have kind of like changed and if you're seeing more buy-in with executive teams or even just the security leaders in the space that we talk to if zero trust is finally gaining ground or if it is just more that we're kind of, uh, we talk about and then we got to go back to asking for budget.
Yeah, I thought this was interesting in that, you know, one, they're talking about the, the new, uh, identity guidelines, the, the version 4 that they're talking about here. Just, it came out about a month ago, building on the prior versions, which, which were definitely great. But this is, you know, adding more of those assurance levels. Um, but I think to your point, they're, they're really trying to tie it to zero trust, right? If, uh, if you're required to meet certain, um, assurance levels as part of your identity management, uh, it's going to be much harder for you to do that if you're not also using, uh, zero trust philosophies.
Because, uh, if you are, uh, if you're authorizing once and then not coming back to do it again until, say, someone logs in again, then there's no way that you can provide those assurance levels that are required in this standard. So I think I hear more and more people talking about and, you know, adopting zero trust principles. You know, I think with, with anything, it, you know, doing new things costs money. So there is that budget aspect to it. But I think that it does offer such a, a great amount of additional security control that it's something that everybody should be looking to do.
Absolutely. All right, uh, moving on to our last story of the month. Uh, this is that second Red Canary article, uh, talking about redefining incident response in the age of AI. Um, and I think this is actually really interesting. Uh, the, the bottom line is that, uh, Red Canary has an incident response, uh, readiness guide that they just released a new version of.
So that's kind of what they're talking about here. I was expecting this to be talking about how to respond to incidents now that, you know, AI is more prevalent, but they're really talking more about how to make your processes better and streamlined using AI to do things like building plans and documentation and other things like that. And there's also a nice video built into this blog where they're talking about some of that info. Yeah, this is a great article. And I say that because I believe with everything that it's saying.
And I really love that they tie, you know, in AI parlance, they call it the human in the loop. But I think it's also one of those fundamental shifts. I think it's a game changer in incident response, as well as a great tool to use, but never will replace the human expertise, especially at our levels. I'm a firm believer in that. I think it's an accelerator of good process.
And I think AI can also, you know, on the flip side, accelerate poor processes, highlight the real garbage in, garbage out of data cleanliness, and your processes and playbooks and detection architecture at your organization can either be— you can do bad things faster with AI for sure. Right. Yeah. And of course, in this blog, there is a link to that updated readiness guide. So if that's something you're interested check that article out and, and download that as well.
So, all right. Those are the stories for the month. Let's jump over to events. So we, of course, have our full event calendar on the website. Go to colorado-security.com and check out that calendar for all of the latest events.
And we, we now have events, I think, through the end of the year. I don't think we have any 2026 events yet, but I'm sure that those are going to start happening here pretty soon. So first event that we have on the calendar, ISSA Denver is doing their October chapter meeting and they're actually doing this at SecureWorld and they're doing it with an event called How I Got Caught: A Deep Dive into an $800K Fraud. So, Joe, I think that you have some info on that. Yeah, I actually saw this talk live at Rocky Mountain Information Security Conference this past year.
Incredible delivery, speaker, content. I highly recommend checking this one out. And next up, we've got the ISACA Denver October chapter meeting on the 16th of October. And ACES Denver is, which is the physical security group here in town, is doing their ACES Rocky Mountain trade show and networking event on the 21st of October. And our friends at ISSA Pikes Peak will be having their chapter meeting on the 22nd of October.
And finally, CSA is going to be doing their big fall summit on the 29th of October. Check that out. They've actually been offering some discounts here. I'm not sure if those are still available or not, but you may want to check that out soon and not miss those discounts. All right.
That is all of the events. We do have an interview for this month. Frank Victory talked to Greg Foss, who is the manager of threat detection at Datadog. Greg has been on the, the podcast before and is a great member of the community. So I am interested in hearing what he has been up to.
All right, Joe, thank you again for co-hosting for this month. It's been great and we appreciate you being here. Thank you, Alex. Awesome. This has been Colorado Equal Security and we will talk to you next time.
Hello, this is Stanton Meyer, CSO of CoBank. Welcome to Colorado Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Well, good morning, good afternoon, and good evening. This is the Colorado Equals Security podcast. My name is Frank. I am a guest host on this amazing program. Today we have a true expert in cybersecurity, a seasoned professional with over 15 years of experience leading the charge in threat detection and cloud security.
How are you doing today, Greg? Doing well, Frank. Thanks so much for having me. Thank you for being on the show. Well, he's currently heading the threat detection team at Datadog.
He transforms real attacker tactics into reliable detections and practical threat hunting guidance to keep cloud environments safe. Now, hailing from Denver, he's built and mentored top-tier teams in intrusion research, detection, and engineering. His impressive career includes leading the threat hunting at CrowdStrike's Falcon Overwatch, pioneering cloud threat research at Lacework, and serving as a principal researcher at VMware Carbon Black. He's also led security operations at LogRhythm, shaping an offense-informs-defense mindset. A hands-on researcher and speaker, he collaborates closely with his team to investigate cloud adversaries churning complex threats into actionable defenses.
Through research, publications, and industry conferences appearances, he's dedicated to translating headlines into playbooks and empowering security teams everywhere. That sound about right there, Greg? You're too kind, Frank. Thanks so much for the introduction. Well, I always— you're welcome.
And I always like to start this with an icebreaker. Greg does not know what this is going to be yet, so Would you rather be able to talk to animals or speak every human language fluently? Oh man, that's a, that's a tough one because I've been trying to learn French lately and that's, that's very difficult. But I think being able to talk to animals would be, would be very cool. So, so I'd probably go with that.
What would you think you would gain from that? I think, uh, probably lots of random noise and be very confused with a lot of background noise. I'd know what my dog dogs are constantly mad about though. Well, that would be a huge advantage. That's true.
Okay, well, how about this, Greg? Let's— I do want to stop into something that you said in the introduction that we had in your introduction: offense informs defense. Is that different from purple teaming? I think, um, you know, kind of like, like, you know, you and I have been in this space for quite some time, and I mean, even before like blue teaming and red teaming were really like these commonplace things. So when I first got into security, I was mostly doing offensive security, started out with like web application hacking and then got into network attacks and kind of escalated from there.
And I think like, you know, one of the things I've taken with me through my whole career is the fact that like you really have to understand how attacks work, how attackers think, how someone's going to, you know, approach kind of compromising an environment, an asset, things like that in order to be able to build good defenses. So that's And that's why I think like that offense informs defense is very, very much something that's really kind of something I've clung onto my whole career. And it's been like a cornerstone of kind of how I think about problems and how I approach detection engineering here with my team and how we look at threat hunting and those types of things. But yeah, I would say nowadays it is definitely like that purple teaming mindset, like really like let's run through the scenario, let's look at the telemetry that we gather, what can we learn from this? How can we defend against this?
And then how can we do it in a scalable way that's not going to be noisy and inundate us with a ton of stuff we're going to have to, have to look at later? So yeah, I would say like purple teaming very much embodies that. Now, I think conceptually, right, I'm going to put you on the spot here. I think conceptually purple teaming makes sense. But when we start thinking about blue teams, right?
And we start thinking about one of their biggest challenges, or the biggest thing that they have to try to accomplish, is making the business run, right? I'm sure that there are a lot of blue teamers out there that want to make sure— like, we want to set up this defense, we would love to secure this system, and they can't because they have to allow the business to run. I mean, We've both been in this industry for a long time. We have said we can actually make your network 99% secure. It won't function anymore, right?
So how do you cross those hurdles, like, to include the business as part of it? And keep in mind that, let's say, I'm the sales guy or I'm the business people, and we got to make sure that we keep our customers happy. And I'm sure at Datadog, that's something that you have to do.
Yeah, it's a great question because I think it's that, that constant balance that we face because, because, you know, the only way to fully secure any system is to have it turned off and off the network and all those types of things. But at the end of the day, the way I look at it, and I think especially as I've moved into more leadership roles over the years, it's really forced me to think about the business at the core of all these decisions. There are a lot of things where we have to make tradeoffs. With risk, with accepting that risk, with understanding like, you know, okay, this is an acceptable risk. What are all the things that can happen as a result of accepting this risk?
And making sure the business owners understand that, those that will be impacted. You know, sometimes these decisions go out to like the board must be informed of these types of things. So it really depends on like the types of things we're permitting, we're allowing in our businesses. And it comes down to, you know, that delicate balance of like being understanding of the business, of the people trying to run the business and their day-to-day work. 'Cause, you know, they don't see the same type of stuff that folks like you and I do who are in this space day in and day out.
We're looking at attacks all the time. And realistically, you know, I've worked with like a lot of companies that have been impacted by ransomware, for example. Realistically, they could go years without many major issues. They might have like some phishing emails get through here and there, maybe a couple account compromises, but they're able to respond to those in time. But that like first time they have like one big event like that, it's really like a reset button for them, makes them kind of realize how damaging this can be to their business.
Some of them have had to fully rebuild from scratch and those types of things. So I think, you know, it's hard to put that in context for folks who haven't been in those scenarios. So a lot of times, you know, we can make recommendations, we can provide guidance, we can provide information on, you know, what's happening in the space, but ultimately the business owners are going to take that information and then ultimately they choose, you know, whether or not to maybe implement stricter controls or, uh, you know, just allow things to continue as they are. Um, so it can be very frustrating. That's something I think a lot of us in this space have, have dealt with, is knowing, you know, how risky some of these things are, but we have no power to, to truly change them, um, until there's like a, uh, canon event, so to speak.
Well, let me— so I've started, I mean, uh, as you know, I've been lots of hands on keyboards or done a lot of hands on keyboards, but I'm currently working in a job of risk management. And as you know, we have certain tiers. We have things like in risk management, we've got accepting the risk, we've got risk avoidance, right? What do you think? Do you think those are practical ways of approaching risk?
Yeah. So talking about like using a risk register essentially to document, track, quantify, and and uplevel those risks. I think it's a great approach, especially when you can tie it to compliance standards and specific mandates that affect your specific business. So like for us, you know, we're primarily a cloud security company. We also do work with governments and things, so we have to adhere very closely to things like SOC 2 compliance, FedRAMP certification, all these types of things.
So, you know, part of that that takes care of some of this for us, I think, because a lot of this is like, you have to do these types of things in order to continue operating as a business, especially if you want customers in certain spaces. You know, like a lot of SaaS providers also take in healthcare data, so you have to worry about HIPAA and those types of things. And now every company has to worry about GDPR and how we handle data. So I think like using those compliance standards and various controls that come within those to kind of guide your approach are very helpful because they're very tangible things. They're things that the business will understand, the legal team will understand, and you can tie those to what you're identifying in your risk register.
So I think, you know, marrying those 2 up, making sure that they're, they're understandable for folks, you know, outside of our direct positions, I think is very key. So making sure like the business understands why we have to do these things and the cost of not doing them as Well, I think you brought up a good point is that, you know, the business, of course, doesn't always know that something's happening. Right. And, you know, from a security team standpoint, we're kind of in a weird spot because let's say that we do our job 100% correctly. Right.
And you and I know that's not an achievable goal. But let's say that we do that. The business continues on. But then let's go on the opposite end of the scale and let's say that for whatever reason the business doesn't get attacked, doesn't have any issues. Well, the business continues to move on.
How do you say we should build value in that situation? That's, that's a great question because that's something I think a lot of us deal with, uh, on a daily basis. Like, because most companies are going to be in this position where they haven't had, you know, this big event happen, they haven't had a full-on compromise. There's a lot of folks that wonder, you know, why pay for this? Like, security is usually always an overhead cost center, and it's something that is hard to justify oftentimes if there isn't these events.
And I think that's the thing I've always struggled with in my career is like, yeah, the fact these things haven't happened is because we're doing a good job. But it's, you know, that one time something slips through And it's kind of that age-old issue of like the blue team, we have to be right over and over again. We have to understand massive amounts of information, understand the network inside and out, know where our control points are, understand the threat models of how we'd be impacted. An attacker just has to get lucky once, you know, they just have to find someone slipping up one time. Like recently seeing like the MFA fatigue attacks and things, those kind of things terrify me because it's something where you could have the best intentions, you can have a really good mindset about security, you can be aware of these attacks, and your phone's in your pocket sometime and you slip up and accidentally hit approve on one of these pop-ups that comes through.
That kind of thing freaks me out. That's something I've seen with certain customers who've been impacted, certain individuals who've had their personal accounts taken over. And those kind of things like can happen to any of us. And so I kind of, I think I trailed off a little bit here from the original question, but bringing it back around, I think, bringing this back to the business and showing like, here are the investments we're making, here are the things that we've prevented, if it's possible to show that. And I'm not talking about made-up metrics like, oh, we blocked a million attacks at our firewall or things like that, but like, you know, here was this maybe a phishing example, because I really like using use cases and showing like a tangible example that affects people individually, because I think it really highlights not just the impact on the company, but the the personal impact that these attacks can take on people, but show, you know, this thing got through, this person inadvertently shared their password, the attacker was able to get to this point here, but we were able to cut it off at this point.
And here's like what could have happened had they continued. I think those types of stories, when augmented with high-level metrics about overall how, how, you know, your detections are performing, how the usability of your systems are, are functioning, or however you'd kind of want to phrase that, can be very helpful. But I do find, especially when I've talked to executives, those specific stories that affect people within their company and that could ultimately affect, you know, the company itself had they not been halted are very powerful. And so that's kind of something I always try and include in my briefings is like tangible examples of case studies and things like that that we've seen. Well, let's jump back a second here.
Made-up metrics. I mean, you know, let's talk about this because I think that's a very interesting thing. You mentioned what we've blocked, a million attacks on the firewall. Is that really a made-up metric? I think it's like, you know, you could argue either way, but I think there are a bunch of, I'd say, you know, the numbers are real.
You have seen these numbers of attacks. You've probably gotten scanned a bazillion times. So technically it's true, but like realistically, what are you really preventing there? Like I always go back to like phishing email solutions. So a lot of the marketing around those is, oh, we prevent, you know, 99% of the emails from getting through to your inbox and stuff like that.
But the funny thing is like a lot of these are point solutions that sit in between the mail gateway already. So, like, they're taking metrics from something that already was going to be blocked by, like, Microsoft itself or Google itself. And so, those are the kind of things where I would lump them into the category of, like, okay, that's kind of like a sort of fabricated metric. That's kind of why, you know, back to email itself, I really like these newer solutions that are taking an API approach where they're looking at mail in that angle. They're allowing Google to do a lot of the core blocking.
They run their rule set there. Those metrics I trust a little more because it's after that general great filter that all of the major email providers have now. So it's not like sitting in front of that one and then claiming credit for stuff that wouldn't get through anyway. Yeah. Do you think there's a lot of that claiming credit or getting through?
Do you think that there is something like that, or maybe on the opposite end, we don't have the ability to test that. I mean, yeah, not all companies are going to be as mature as, as Datadog, right? I mean, no, totally. Yeah, I agree. Datadog is a security company, right?
I mean, that's their pure focus. Technically observability. Security is one component of what we do. Um, the observability stuff is truly fascinating too, something I hadn't had experience with until coming here. Um, but like, Datadog's a deeply engineering company, like some of the smartest people I've ever met, have the chance to work with here.
And, but security is one kind of component of that. And all of it relates together. And that's kind of how we see it here. It's all part of the whole software ecosystem. So it's kind of an interesting approach here.
And so for us, we're very much a metrics company, very deep into like, how do we measure, you know, about system performance all the way through like security events and things like that. So we have definitely like a significant advantage there, I think, when it comes to how can we show and prove out some of these things where a lot of other companies I've been at, and I'm sure your experience as well, there have been places where we can't prove these things. We don't have the data, we don't have systems that would even give us access into the information we need to gather the data to highlight So it is definitely a challenge. And that's also one of the things I think is fun about this industry, because then that's an opportunity for how do we get creative with how can we find information to help prove our point or prove that we maybe need additional resources, we maybe need some new tooling. So it's like kind of like, you know, looking at hacking in a different way of like, how do I, how do I look at this from I need to show the business this maybe what we need to actually prove value here or show, you know, show the things that maybe we're missing today.
But I mean, you know, Datadog being a technology company, right, or an observability company, how do you actually spin that to, let's say, a company that does finances or human resources? How do you put that in there to people that that's not something that they can relate to. Yeah, and it's a hard, hard problem. I think like, um, that's where those case studies can be very impactful, um, especially people from all walks of life. Um, you know, I can think of like, uh, issues that impact people in HR and payroll and things like that.
I usually try and go to something that maybe would be more familiar to them. Um, like some of the ones I would say like within HR, you know, HR systems are kind of like that central point of your company to have all the information on everyone who works there. They have pay information, sometimes payroll is connected to that. Some of the attacks I've seen that are pretty scary are these ones where an attacker will try and reroute people's paychecks. So able to get into the payroll management system, I won't name any vendors, but there's one incident I worked where someone had, you know, another phishing attack type of situation.
But from there, the attacker got into the payroll system for this employee and it simply updated the routing for their paycheck. Fortunately, it sent an alert to the employee, to HR, so they were aware that this payroll change had happened. And then he went in and saw this, but he had no idea how it had happened until we went back and investigated it. So those types of things like, like, that's maybe one scenario I'd probably bring up when talking to someone in that space. Um, but I think, yeah, you have to make it tangible to them in a way that they'll understand, um, and, and make it, uh, real.
Um, it's easy to say, oh, attacks are happening, you know, blah blah blah, but like that, you know, we, we can't run out there with fear, uncertainty, and doubt. I think being, being honest and showing tangible uh, things, and then looking at things from a real-world angle is, is very important. Yeah, so no FUD, no FUD, right? No, no FUD. Okay, well, Greg, you know, uh, anyone that knows you, and there are a lot of people in this community that do, they know that you're a very smart guy.
Did you always go to school? I mean, did you start from day one, from, you know, first grade, and say, I'm gonna be in computer security, or I'm going to be in technology? What was that like? I mean, did you start or have you always done that? No, I appreciate it.
Well, whoever says that is very kind and I owe them some money. But no, I've always been interested in computers and technology. Like when I was a younger kid, I was really nerdy. I'd be, you know, on the internet back in the earlier days. Like I was one of those AOL kids.
Who I would hop on there, you know, usually every day after school. And, you know, from there it was kind of like the Wild West. Got to really learn quite a bit. And me and my good friend at the time, we would go around and, you know, we started going into like chat rooms and stuff. One of the big ones back then was The Palace.
It was one where you could have like little avatars and things, and it was all like this HTML web interface. With just little people walking around and doing stuff. And the fun thing there, we all of a sudden found out that like, oh, we can actually write like scripts to do things to other people in this application. And you could do stuff or make like a lightning bolt on the screen, or you put someone in the corner, or you take all their avatar stuff away, and they're like this little ball. And it started there, and we started poking around a little too much and got into the punters and all the little script kiddie tools back in the day.
And, um, ultimately got to a point where my friend and I, we were, um, causing so much damage, like, uh, and we didn't even think of it at the time. We were doing stuff with like NetBus and, uh, you know, trying to infect computers just so we could open their CD-ROM drives and things. Um, this was like 6th or 7th grade, I think we were kind of doing this. And, um, it got to the point where, um, we, we had— we'd done too much. I had too many, uh, too many systems calling back to my parents' home network, just directly to my home computer.
I ended up getting banned from AOL. I couldn't touch computers for about a year after that. So it freaked me out for a bit. So at that time was when I shifted. I didn't really do much with technology for like a few years after that.
I got into more sports and stuff and doing other things.
You were banned from— like, was this a legal requirement? Was this like a judge? Yeah, legal, a whole, whole nine yards. Banned for life from AOL. I still can't be an AOL customer, which is kind of funny.
Um, it hasn't really held me back, you know. Well, that's why they collapsed, you know. That's why they collapsed, right? Is because you could not be on AOL anymore, right? Exactly, exactly.
What it is, is funny because at the time that was like everything, but it, uh you know, it did show me other ways to get online when I wanted to kind of after that. And still in the back of my mind is always one of those things. I was always kind of a mischievous kid and ended up getting in a lot of trouble for it at that time. But then I shift to, you know, being mischievous in other ways. But long story short, I, for a long time, you know, I avoided technology and things like that.
And then When I went into college, I originally was going to be a psychologist. Like, I really liked psychology. I liked the topic, and I went in as a psychology major, but I kept computer science as a minor because I still realized I was like good at it, but I didn't know if I wanted to do that for the rest of my life. And it wasn't until about midway through my degree, you know, I was about to— I was getting close to graduating, and my roommate was a computer science major. And he was talking about all of the security stuff and he showed me this show.
It's still a show that it was on for a short period of time on the Discovery Channel called Tiger Team. So Chris Nickerson and Pyro and a bunch of those guys that are very famous, like Colorado security folks, were running this company. And basically, I watched one episode of this and it was when they went and tested a car dealership. The physical security, electronic security, everything. They broke in, stole a car, turned it around and parked it backwards and put like a note in the car.
And I found out like, oh, this is a job? Like people pay you to do like basically heists for a living? And it like blew my mind. And so at that time I was like, oh man, I like, I know what I want to do for a living. Like I want to go do that.
So I took my minor, which was computer science. I made that my major after this point. And at this point, I only had one more psychology course to finish before I would have graduated with that. But because I decided to change my major, I had to extend my college by, by about 2 years, even with doing, doing summer school. But like, at that point, I was set.
I was like, I, I want to do this. So I switched my major. I ended up graduating with both psychology and computer science. And then after that, I actually applied at Lares, the company behind Tiger Team, and the show was off the air by that. I think they had one season and it was cut, but it was still fascinating to me.
I never heard back from them, but I ended up going from there, you know, while I was still in college, kind of working on these extra years for my degree, I started doing web development. For local businesses and things as a way to help pay for college and things. And that ended up paying off really big because after school I was like debating kind of what I wanted to do. I really wanted to do security, but I didn't know if there were opportunities there other than working for Lares and a few of the other small companies that kind of did that thing at the time, but couldn't get in there. So I had a couple places where I was talking to for web development, but then I ended up through a connection getting an interview at the National Renewable Energy lab where they were looking for someone to do web security.
And I was like, well, I've never done this, but I would love to try. And it seemed very similar to like the pen testing, red teaming stuff I was interested in. So I applied, and very fortunately they had a practical as part of the interview. And the practical was this web application where they wanted me to find vulnerabilities and understand how to, you know, explain and exploit a couple like planted sort of vulnerabilities in this app. And I was so lucky that it was the exact same content management system that I was using to do web development while I was in college.
So I knew just enough to like find a couple things and point it out. And so very fortunate to have gotten that start in the industry and really, really appreciative to the team there for giving me that shot kind of as a fresh out of college kid. Uh, to jump, jump right into the security industry. Well, that comes up with a lot more questions. I mean, for one thing, we have had Pyro on the show.
I think it was a year or two ago. Uh, we did have Pyro on the show, a very fascinating, uh, guy, as you know him. Um, and but I really want to go back to your psychology background. Do you think that was a waste of time? No, I honestly think it's been very helpful.
The psychology side of it, and that's part of why I think I often get pushed into management in these roles, because I'm a very empathetic person. I really, really like people. I like understanding them, understanding what motivates them, and then helping them in their careers. And I think the psychology training was very helpful just for not just leading teams, but also on the security side. I think so much of what we do in this space comes down to how people think about things, how we approach problems, and so much of that is just like understanding, you know, what is someone going to do in this situation, you know, how might someone respond, or those types of things.
So no, I think it— I'm very glad that I kind of did this combo of of training back then. Well, it's so funny because, you know, you, you know, I think everyone that knows you knows that you're a nice guy, and, uh, everyone that knows me knows that I'm a bit obnoxious, a bit sarcastic, right? And I was actually talking about you one time, and some guy, random guy, goes, oh well, if I hear, you know, Greg say F you, you know, they're, you know, he's gonna be mad. I'm like, well, wait a minute, if he— that's completely against Greg's personality. I mean, I can't imagine you ever doing that.
Even if I— I think I've actually said sarcastically things to you and you gave me a hug for it, right? So, because the way I like to describe you, Greg, is, you know, back on that Andy Griffith Show, what if Opie grew up and became a cybersecurity expert, right? That's the way I like seeing that. But anyways, anyways, so you studied psychology, computer science, you had some pieces in there, But you also mentioned that you love sports, right? How important is that to have a hobby, a sport, something like that for those of us that are working 50, 60, probably 70 hours a week in this industry?
I think it's, it's very important. That's one of the things where, you know, um, for a long time, especially when I was first in this industry and like, um, coming up to speed on everything, man, I would like spend hours on the computer and just like even after work I would be researching other things and just trying to like up, uplevel my understanding. So I feel it felt like I could be even on the same level as other people in this space, uh, that I looked up to.
And, um, over time, you know, something that caught up with me, like I ended up, um, getting burned out at one point, you know, from just focusing too much on this stuff and At a point in time, I'd put on quite a bit of weight too. I think you knew me, uh, you know, at my chunkier days too. Um, and it was something where, you know, I just didn't realize like how unhealthy I had been getting from just focusing so much on just like this kind of stuff. Um, so having those hobbies, I think, is, is like really critical outside of, outside of this, like what we do day in and day out. Um, so yeah, I got into doing a lot of running, biking, Uh, swimming whenever our neighborhood pool's open in the summer, try and go up there.
Well, I do remember, I— because you had given us— I think it was like your first presentation at my Denver OWASP meetup. And, you know, we've known each other for a while. And then I saw you, I think, at RMISC, uh, and I actually had to do like a triple take on— no, that's not Greg— because you had lost so much weight. You lost quite a bit of weight and And, uh, can you maybe talk about that struggle, or was it trying to get to that point? And how do you keep it up?
I mean, I know we're not really a health show, this is more about, you know, Colorado Social Security, but I think it's a safe assumption that a lot of the listeners are struggling with the same thing, that how do I stay healthy when I like to code? I don't— I want to— I don't want to go outside. Right, maybe. Yeah, yeah, no, it's tough, man. I think, um, you know, that was the thing.
And, and also, you know, uh, that was my first presentation ever, uh, at Denver OWASP. Thank you and, and the Denver OWASP crew for, for giving me that opportunity too. That was— that really opened up a lot of doors down the, the line too. Um, so, but back to, uh, back to the, uh, the health thing. Yeah, it was something where I had, um, just made a realization, you know.
I think it was when I was at Carbon Black and we were in Boston, 'cause we would do these quarterly get-togethers out in Boston. And the big thing I realized there is like, man, we walk like everywhere to do everything. And I was like getting tired 'cause we would like go out to lunch and it'd be like 2 miles away or something. We'd all just walk there and stuff. And I was like, man, I'm like so out of shape.
I didn't like realize until I just, you know, was kind of put in this different environment and stuff. And I don't know, I think that was the big thing that really got me like thinking like, man, I like need to take care of myself. I'm like, I'm not healthy. This isn't good. And so from there I started slowly, you know, just doing more activity and stuff.
I used the fitness trackers, which I think was really good. Like back then I had a Fitbit, so I'd make sure I hit like 10,000 steps a day and stuff like that. And I like listening to podcasts and things and audiobooks and stuff. So I would listen to all these types of things while I'm out, like walking. And then eventually I started running.
Man, that first time when I was trying to run, because I used to be into sports when I was younger, so I figured it wouldn't be that hard to get back into it. But no, it was tough. I ran to like the end of my block and I was winded. But the next day I went out and did it again, ran a little further before I had to stop and just kind of kept at it until, you know, I got to the point where, oh, I can run a mile now without stopping. It was a slow mile, like 12 minutes or something, but still finished it.
And then from there, just kept kind of adding on to it. The tough part was since I did mostly running then, I ended up getting quite a few like little injuries and things because, you know, I had all this extra weight. And so my knee started hurting first. I eventually got plantar fasciitis from running quite a bit. So, over time, balancing that out with different activities, running less, biking a little more, swimming more, doing weights and things too.
But, I think now it's one of those things where I've integrated it into my kind of daily sort of cycle of things where if I skip a day where I don't do some exercise in the morning, I feel kind of off. Off. And so, I think that's better than the other side of that where I could be content just sitting all day or not doing activity. So, I'd say for folks who are struggling with this and stuff, I definitely understand what they're dealing with because it's hard to especially transition over into from especially no activity to doing activity. But the big thing I think is sticking with it and finding what works for you, finding ways to make it enjoyable Like, that's where like the podcasts and things I really like, you know, like I'll probably listen to this one again and mute myself but listen to you while running and stuff.
But I think, you know, just finding what works for you, but don't push yourself too hard and just gradually try and, you know, continue kind of improving over time because it took about a year for me to lose about 100 pounds. Um, but now I'm like, I don't want to go back. Like, well, here's something that's interesting from what you're saying, because just keep trying over and over again, even though you're slow, keep— you know, you still accomplish the goal. Could you apply that to our careers in general, right? I mean, can you apply that type of thought and say, keep trying even though it may take you 3 hours to make a small script at least you accomplished that.
Yeah, exactly. And the next time you do it, it's going to be easier. You're going to be able to build upon what you learned before. It's always hard learning, learning new things. And I think sticking with it is the key, right?
Like, if you ever go see the CTFs going on at conferences, these folks will be there for hours and hours focused on, you know, a specific problem or a subset of problems. And So much of it is like that trial and error and, you know, just, just not giving up. And that's what makes, I would say, successful attackers too. They will persist and continue poking at systems until they get in. So yeah, I think it applies very directly to our careers.
Yeah. Okay. Well, you know, kind of taking all this into account here, let's say that you're walking into a conference, a meetup where you don't happen to know anybody. And you want to start a conversation, what are some things that you might want to start a conversation about? Like, you know, within, of course, our industry.
Yeah, I always like asking people like what they're working on now. You know, like what are the thing— what are the biggest problems they're kind of struggling with? Especially like, so now that I've been in cloud security for some time, often I'm at these conferences where a lot of the folks or like SREs and developers and things. So often have very different problems than say, like when I've talked to someone at DEF CON or Black Hat or something, but I always like just like understanding, you know, like what are they dealing with right now? And especially when it comes to like security things, I would say like in the cloud, one of the things I always like talking to folks about is like how they manage non-human identities.
Because that is becoming one of the things where like everyone here now has like all these other associations to their accounts, to both corporate and their personal accounts and things. I think it's like 80 to 1 or 40 to 1 or something like that of the number of accounts that all of us have that could be accessed in all sorts of different ways. So like figuring out how you handle like identity sprawl and things is one of the things I've been probably talking with people the most about recently, because it's also the main thing that we end up responding to here in terms of like our detections triggering and investigating an event. It often comes down to like one of these non-human identities being leaked or stolen or things like that. That's kind of where I usually start is like, you know, what are you dealing with now?
What's the big hot button issue that you have on your plate? Because I always find like everyone— I learn something new from everyone that I ask this question of. Well, I mean, I think you kind of jumped into the question I always like to save at the end, which is, you know, what is the biggest problem in security today? But let's— so let's revisit that though, since we're on the subject. Non-human identities and identity sprawl.
Can we talk about that for a little bit? Bit.
Definitely, definitely. It's something where, you know, like for us, say, uh, in AWS, you'll have like, uh, access keys, uh, that can be used to access your environment. And oftentimes these are going to be programmatically used in a lot of different places, um, and as a result, they can be leaked, uh, they can be exposed. Um, attackers are very proficient with information stealers now, especially on personal systems.
In fact, a number of the incidents we've seen, I'd say a majority of these are often like folks who have work assets on a personal system that's not protected and they play games on it or download torrents or whatever, and it just allows that system to be a softer target than say maybe going after your personal work asset. So we'll see something like an AWS long-term access key lifted from there, and then we'll start seeing enumeration from another country or something like that in their Amazon account. And oftentimes what the attacker will do too is add a backup identity. So they'll add another AWS access key. You can always have 2 at any given time, and that's so that you can go through and replace where your old keys are when you're upgrading your keys.
And you can switch these out and stuff like that, but an attacker will do this as a means to just maintain access into your Amazon environment. And the smart adversaries usually won't do a whole lot from that point. They'll often watch and wait and maybe start poking around at existing systems, but a lot of the folks we see are these smash-and-grab actors where they will immediately go to spinning up as many GPU instances as you will allow them. Now, so they can start crypto mining on your network. They'll often set up proxies as well, so they'll resell access through your systems to other criminals, uh, you know, called, called proxy jacking.
Um, but it all comes from these access keys that are leaked or mismanaged or stolen. Um, and that's just one scenario, uh, focusing on Amazon. Um, so I think like identity sprawl as a whole, both connecting all of those to an actual person, but then maintaining those and understanding like, you know, what is the blast radius of impact of this getting exposed? What can happen if someone accesses these things is very important and something that I've seen more and more commonly every day here. Yeah, I've actually just this week Uh, a friend of a friend, you know, they were having a problem.
And smart guy, he was an orthopedic surgeon, and his wife clicked on a link, was in a hurry. And I mean, they got everything. They got into his identities, they changing passwords to Gmail, um, their home devices, because of course the smart devices and everything. And, you know, one of the biggest problems is that he told me, well, in my iCloud account I had a list of my username and passwords. And it's like, and, you know, again, he's a smart guy, but he didn't realize he was telling me, well, we got the iPhones and, you know, they were in them, so we physically smashed them.
And then we got Androids and then we physically smashed them. And I'm like, okay, stop smashing your phones because that's not doing anything for you, right? I mean, if they're in your accounts, but they are moving through his network, they are moving literally thousands, if not thousands of dollars and getting into the millions. And I did let him know, it's like, you know, you first off, you gotta start— stop feeling bad. I mean, the way that these attackers are moving through, they're definitely not that smash and grab.
They are— they studied you. These are professionals. And they probably studied you for weeks before they even launched the first attack. You have obviously a lot to go through. So So what would be some recommendations for the people that are listening to this and are probably terrified right now that it could happen to them?
What would you give them as far as what you should do? And, you know, we, you know, let's start with the basics and maybe move into more advanced items. Yeah, yeah, I think it's a, it's a good point, you know, you, you brought up with that scenario. It's, it's all too common. It's terrifying, you know, someone's whole livelihood is like connected to an email nowadays, which, which is terrifying what an adversary can get into.
So I hope your, your friend was able to recover, you know, as best as possible right now. I mean, I literally talked to him on Wednesday, so he is in a lot of pain right now and having to reach out to other people. But, you know, what advice? I mean, I gave him a lot of advice, told him who to talk to, things like that. But what would you give all our listeners right now that know that this is real?
And yeah, yeah, yeah, I think, um, you know, the big thing, especially for like individuals, um, like, like your friend, like, um, implementing some phishing-resistant authentication, um, you know, using, using passkeys, which are very available now in, in all of the major major password management systems, but then also using physical keys. Like, if you have FIDO2 authentication, um, you know, and like using a YubiKey to log into certain things and making sure that like, um, you can do it in a way that's not going to be overly cumbersome to you personally, but like making it so whenever you're setting up a new phone or, or new computer or something, you need that physical kind of token to actually configure it is very important. So, so I think that's like the number one thing I'd say for especially like individuals, you know, just focus on like making sure all your important accounts have multi-factor configured and make sure it's something phishing resistant. Like SMS is something that's been proven that adversaries can gain access and port your phone number over to a different SIM card and gain access to those SMS reset codes in that way. But you can also set a PIN on your account as well.
But the reason I think it's still not an ideal approach is like there's a lot of instances where attackers have just gone into places like a T-Mobile or something and stolen the tablet where they can configure your account. And it's basically free access into just about everything without those preventative controls. PIN codes are pretty simple things that can be figured out. They can be socially engineered from you. So I think those physical phishing-resistant mechanisms are very important.
But then, you know, looking at corporates, really treating identity as like the, like, a monitored control plane, if you will, because you really want to centralize all your logs, bring them all into one location where you can correlate across, you know, the OAuth grants that are being made, who's logging in through Okta, you know, where are they coming from, are there Superman login events that you can detect, kind of all of these things, making sure everything is centralized and tracked in a way that's the security team has visibility into it and they can formulate a response in the event of like they see trends across multiple users who are getting like MFA fatigue attacks or something like that, where they can maybe start putting some proactive controls in place to prevent maybe more users from being impacted by that same type of attack. But I think in general, like, having visibility and making sure everything is connected is critically important. And by connected, I mean just like for us right now, we're implementing OCSF mapping for our SIEM. So basically what that means is the ability to detect something like brute force logging or a session replay attack across not just one source, but like Okta, Slack, Google Workspace, AWS, like being able to see kind of this, like write one rule that will apply across all of these different log sources and then being able to correlate those together and centralize them around the identity. So really focusing on the identity as the center of the entire approach, I'd say, in terms of like how you how you are monitoring these— your networks.
Really take that identity-centric approach. And then biggest thing too is just minimize that blast radius, like segmentate— segmentation, you know, require step-up authentication for certain sensitive actions and things like that. You know, make sure that it's not easy for an attacker to gain access to one thing and then go straight to root access. We'll see that a lot with like these compromised access keys where they just have full admin access, don't even have to elevate permissions. But the more you make an adversary jump through hoops and have to do things like find privileged escalation pathways and things like that, the more bells and whistles they're likely to trip in that process and the more visibility your security team should have.
So making it so there are these challenging kind of components for, for people to do so that they don't just immediately go right from 0 to 100, so to speak. But being in such a connected world, is that practical? I mean, how many times, how many places have I logged on to, right, that says, oh well, log in with Google, right? What would you say in that case? I I mean, even that situation after talking to him was like, how much do I really want to do that?
Or how much do I actually trust a passkey? I mean, can a passkey be lifted off of my system? Right, right. That's the scary thing. So fortunately, passkeys should be tied to assets where you have biometric data that's actually authenticating that you are the person using this.
But, you know, all bets aside, I don't work at a password management company, so I don't know the specifics of how that technology works. But I'd imagine there are ways that— like, I'd say anything's possible with these. If you're able to log in with a passkey on your phone, there's probably some way to replicate that and replay that. I don't know how true that is. It'd be interesting to see if someone from like 1Password or something would do a deep dive on that.
But that is something I always worry about. The simpler it is to like log into these things, I always get concerned. OAuth grants, like when you're looking at Google and what you've logged into with your Google account, it could be like hundreds of apps. And especially if one of these is something malicious that maybe you didn't add yourself, it's hard to distinguish that if you're not regularly reviewing these. And I wouldn't expect regular people people to spend time reviewing those either.
So, so it is a very difficult problem, and I think it's one that, um, you know, I think we as an industry have to continue thinking about, continue discussing, and figuring out, like, how do we, A, continue to make this less of a burden on the users, but also, B, how do we ensure the security, especially not just from, like, outside attackers and things like that, but we have to consider insider threats at these types of companies as well. So how do we have that full kind of coverage and visibility and make sure that we're not making it impossible for people to log into things, but also making it so attackers aren't going to be able to do the same thing? Well, I think that's the biggest challenge we have is, you know, we want to make it secure, but if we make it too secure, users are just going to find a different way around it, right? I mean, the classic, hey, we're just going to put a Post-it on top of my monitor to remember our password, right? Exactly.
And so under the keyboard. Yeah, under the keyboard, you know, because no one's ever going to look underneath the keyboard, right? So, all right, Greg, well, we're coming up on the end of our time here. Um, thank you for joining me. Are there any final thoughts, anything that you want to tell the group in general or anything like that, or maybe how to get a hold of you?
They want to talk to you further? Yeah, for sure. And I really appreciate you having me on, Frank. It's always a pleasure talking to you, and I'm honored to be on the show. Really appreciate you having me on.
I think, you know, if folks want to reach out to me, they can definitely find me on LinkedIn. I will forewarn that I'm terrible about checking my LinkedIn messages, as anyone who's ever reached out to me on there knows. But that is part of like the I think the balance, you know, with working in this industry, not being overly connected. I am one of those people where I have disabled almost all notifications on my phone and stuff. So when I'm not like working and stuff, I try not to be interrupted and things.
I try and actually go out and do, you know, like go running and stuff like that. So apologies if folks do reach out and I don't get back to you in time. But I think that's the thing I'd leave folks with is do you know, take time for yourself. Take, uh, make sure to balance like what you're doing day in and day out because a lot of us have extremely stressful jobs in this space. So make sure to take that personal time and step away and, you know, hit the reset button from time to time.
And, uh, and don't worry about getting back to every single notification that pops up on your phone. Okay, well, again, thank you, Greg. Uh, again, Greg Foss with Datadog. My name is Frank. I think everyone here knows me as part of the Denver OWASP group.
I'm the VP there. We have monthly meetings with meetup.com/denver-owasp.
And we are getting ready. We actually haven't, you know, by the time I think this gets published, we should have the official announcement out of having SnowFROC 2026 set up at the Cable Center with, with with a variance this year of having one day of training. So we're going to have a 2-day conference with the first day doing just pure training. We're going to have our normal stars in there. I think we'll at least— we're going to try to have our normal stars in there, as well as a very memorable conference for 2026.
Uh, we're gonna have it later on this year. It's going to be right towards the end of March, so not in the middle. And there are some reasons for that. We can about. So again, thank you everyone.
Again, this is the Colorado Equal Security Podcast. My name is Frank. Greg, have a great day, and for all our listeners out there, have a great week. I'll see you soon.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.