All episodes

Chazz Gifford, VP Information Security @ Intrado

Apple Podcasts Spotify SoundCloud

Our featured guest this month is Chazz Gifford, VP Information Security @ Intrado, interviewed by Frank Victory. News from Palantir, Lumen, the State of Colorado, Red Canary, Optiv, and a lot more!

Come join us on the Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript15469 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 280 for November. If you're listening to this, it is sometime after November 3rd when the episode came out.

And this is Alex Wood. Happy to have you here. We have once again a guest co-host with us. I'd like to welcome back Joe McCallister. Welcome back, Joe.

Hey, thanks so much for having me. How have things been since, you know, the last time people talked to you a month ago? Oh, you know, everything's moving too fast and not fast enough at the same time. But a lot of, a lot of stuff happening. I'm excited to get into it.

And, uh, and we are actually recording this on Halloween, so happy Halloween everybody. Uh, Joe, you guys have big plans for Halloween? Oh yeah, I got the 2 small kids, so we have 2 different Halloween parties, not to mention our neighborhood trick-or-treating. What about you? Very nice.

Uh, my kids are both grown and out of the house now, so, uh, we have decided to boycott Halloween. Um, we, we are going out to dinner with, uh, another couple friends of ours, and, uh, we're gonna stay away from the house until we think trick-or-treaters are gone and then we'll come back. So respect it. Someday we'll have grandkids and then we'll pick up Halloween again. But for now, we're doing adult things.

Anyway, let's get our announcements out of the way and then we'll get into the news. So first, as you all know, we have a Slack workspace. If you're not in there, you should be in there. We've got a couple thousand folks having great conversations. If you'd like to join that or join our mailing list, head over to the website, Colorado colorado-security.com and sign up there.

We'll get you added. Uh, we'd also love it if you would rate and subscribe to the podcast in your favorite podcast player. That way we know how well we're doing, as well as this getting delivered directly to your podcast player every month. And finally, uh, if you're not gonna do anything else, just tell somebody else about Colorado Equal Security, get them involved in the community. We love to have more folks in Colorado, uh, involved in our efforts.

And then finally, let's thank our annual sponsors for 2025. Almost done with 2025. Those sponsors are Armis, CrowdStrike, Red Canary, and Zscaler. Thanks to them for their support of Colorado Equal Security. All right, let's jump into the news.

The first story we have, it's a little bit of a downer, but it's talking about vacancy rates in businesses and real estate in downtown Denver. Joe, what did you take from this one? You know, I kind of tried to take the optimist approach. I see some things in here, but they're kind of scary stats we got to start with, right? Denver's vacancy downtown is roughly 37.7% according to the article.

And I think they had a kind of backup stat that is true unused and unfilled spaces around 34%, creeping up towards 40%, which just kind of looking at the lay of the land, I'm no real estate expert, but when I was kind of researching and reading about that, 40% was kind of a tipping point to kind of scary zones of, of, um, of vacancies down there. And it'd be the, the optimist— I, I tried to look for the silver lining here— is really about what can be done with the space with that type of a vacancy. And it made me think about just watching Denver 7 this week, and they were talking about how Wynkoop Street is trying out a pedestrian-only zone between, uh, you know, right out front of Union Station. Uh, so I think there's some interesting upside, uh, but it's definitely concerning. I, I myself have noticed, you know, some— a little bit of a ghost town, not to get too spooky on Halloween, a little bit of a ghost town feel in some of those sectors downtown.

Yeah, it is kind of sad. I would really love downtown to come back to life. Um, you know, I've had several jobs where I had offices downtown pre-pandemic, and, you know, it was great during the day just having so many people together, the energy, and you know, restaurants and all that sort of stuff down there. And it really is, uh, not the greatest right now. I did think it was interesting also how they, they sort of divide things up.

You know, when they say downtown Denver, they mean, um, you know, sort of 16th Street Mall adjacent and, you know, over by Union Station and a little bit towards uptown. But they don't include things, um, like RiNo or other areas that are just a little bit farther outside of what they consider downtown Denver. So Uh, thinking again about the optimist, I'm hoping that the numbers in some of those other areas are a little bit better, even though they don't talk about them specifically here. They did talk about a couple of, uh, of key companies that had left downtown, but, um, one or two of them had actually moved to Rhino. So it's not like they're, you know, leaving Denver completely.

They're just relocating to a different part of town. Now, that doesn't help downtown directly, but I think that's a slightly better story than what maybe the numbers present. Oh yeah, absolutely. And that's a great point 'cause I think RiNo, if you've gone through the neighborhood, you see it kind of has that bustling. It doesn't quite have the lunchtime rush that you used to see in uptown, you know, everybody walking out of the buildings at the same times, that kind of feeling.

But you definitely get the feel that there's stuff going on in RiNo. It's just down the street from kind of where I work. So it is definitely feeling like it's up and, I wouldn't say up and coming, It is here, but it's also kind of developing. It's interesting that they also talked about how some companies are downsizing in their space, Checker being one of them, quite drastically. And I think some of that they attribute a little bit to maybe redefining how we work, which is still interesting to think about, you know, 5 years on from that which shook the world.

And yeah, it's kind of a brave new one, isn't it? The, the pandemic that shall not be named. Exactly, exactly. All right, well, on to story number 2. We've got, uh, some big business dealings from 2 Colorado companies.

Uh, Palantir and Lumen have struck a partnership, a multi-year deal between Palantir and Lumen, where Lumen will be leveraging, uh, Palantir software, uh, namely the Foundry and the AIP, which kind of go hand in hand. I, I actually found myself doing a little bit more research about what the heck that means. And what those, those kind of pieces of the puzzle— and when we talk about enterprise software— do. And they kind of promise this on-ramp to figure out your data is the best way I can distill it down to a single sentence. But really interesting to see what these 2 are doing.

And we'll get to another story featuring Palantir here in a little bit. But kind of curious about how you're viewing this, especially with Palantir being in the news, Lumen as a, as a telecom provider, kind of how those 2 worlds get together and meet? Yeah, I think there were a couple of things that stuck out to me. One, you know, they're striking this deal partially because Lumen is trying to pivot a little bit from, you know, being directly a network services kind of company, telecom company, to, you know, providing more sort of enterprise computing services along with those, those networking pieces, you know, edge computing and, you know, other things like that. And this Palantir platform is supposedly gonna help them do that.

The other part that I thought was interesting was, you know, it was sort of a third party that said this, but Lumen had said that they achieved $350 million in cost reductions in 2025 and that this deal was a material contributor. We don't know exactly how much to those cost savings, but the interesting thing that I saw as part of that also was that Lumen has committed to reducing expenses by $1 billion by 2027. So obviously things like, like AI can help. But I think we should probably be on the lookout for other cost-cutting expenses from Lumen. Hopefully that doesn't mean people in the future to get to that $1 billion mark.

You read my mind. It's right where my, my brain went when you said cost cutting. $1 billion with a B is a— it's a big number. $1 billion.

All right, let's jump to the, the next story. This is an interesting one by our favorite tech reporter, Tamara Chuang, over at the Colorado Sun, talking about how Colorado is digitizing all of its paper and analog land records going back to the 1860s. And this is supposed to be done by next year, which is pretty cool. Part of the story focuses on Littleton in Arapahoe County. Where they are just finishing up some of this work.

But a lot of this has been made possible by some grants that the state is giving out. For a number of years now, there has been a $2 fee associated with every sort of land filing, and that goes back to the state that can be then issued as these grants to help different counties go through and digitize all of their records so that they are kept for eternity and that we can see them online. What do you think about that, Joe? I, you know, I think it's such a huge win just to be preserving things in this way. You know, I can probably reserve my, uh, tinfoil hat cyber skepticism for, oh gosh, now everything's also in the cyber domain and we, we should question what defenses are around that type of thing.

But I think it's just downright cool that we, you know, the, the numbers from the article, 3.5 million documents, 6.5 million images have already been scanned. Uh, and I, I mentioned to you before we started recording that, you know, part of my maybe optimistic assumption again getting in the way here was I thought we kind of did this work. I was hoping that it was kind of already up there. So I'm of course glad to see that it is being done. But seeing also how they are performing the logistical work of getting these digitized made it all the more clear in my mind why it's not done by 2025.

Yeah. It is interesting. Some of these are, you know, sort of individual pages in ledger books and, you know, other things like that. Right. So it's paying for a person's time to pull out a book and go to a page and scan that, make sure the image came through, all those sorts of things, and then go to the next page.

And when you've got hundreds and hundreds of different ledger books and other things like that, it takes time. So I think this is a good forward-looking idea to get all this stuff done. And I'm glad that we're close to the finish line. Absolutely. Yeah.

Uh, well, on to our next story. Uh, as promised, Palantir, uh, makers of the flock cameras, are in the news. This one's a little different, uh, and I mentioned my word I used before we started recording was this one's a little thornier. Uh, police had used flock cameras to accuse a Denver— they say Denver, it's Beaumar, we know better— uh, woman of package theft, but she proved her own innocence with evidence that she had. So with the, the proliferation of this technology, I've seen it in a lot of towns.

And even Denver is in the news this very week. Mayor Mike Johnston wants to get these in place as soon as possible, it sounds like, and is really, really lobbying for them with the people of Denver. But as, as most of us in technology know, they can make mistakes. I'm really curious to hear your, your take on this one. Yeah, I thought it was interesting.

Um, for those that don't know, uh, Beaumar is a very small, uh, town that is wedged between Denver and Lakewood and Littleton, and it basically has, uh, 2 entrances and exits, you know, one on sort of each side of the community. So, uh, easy choke points. And they— the community has put up flock cameras at each of those choke points. So that they know when people are entering and exiting the neighborhood. And I think while I do have reservations about the, the mass surveillance and, and flock cameras in general, in this particular case, I think it was just sloppy work.

Right. So no matter how good or bad tools are, they're only as effective as how you use the data that comes out of them. Right. So this woman was accused of stealing a package off someone's porch. But really the only evidence that they had was that she entered and then exited the neighborhood around the same time that the package was stolen.

So, you know, that, that seems pretty circumstantial. And she was able to go back through a bunch of different means and, you know, prove her innocence. Some of it, you know, GPS on, on her Rivian, some of it on some video footage of the place where she was actually going as she went through Beaumar. But, you know, the, the real problem here is that, you know, she got accused with basically very little evidence and it was up to her to prove her innocence. And it took her a whole bunch of time and effort and money and also, you know, caused her a lot of emotional distress.

So, so no good there. Yeah, I think it's one of those cases of if we've all been If any of us have been kind of watchers on the wall of the alerts that come through, it is the most high-profile case of a— that I can think of in, in recent memory, or at least locality here in Colorado, of a false positive going the wrong way, right? Yeah. Jumping to conclusions in those investigations, never good. For sure.

Spend a little more time, get the details. Anyway, jump into our next story. We are— today is the last day of October. When you're listening to this, it's going to be November. And of course, everyone knows that October is Cybersecurity Awareness Month.

So at the beginning of the month, Governor Polis made a proclamation that he wanted everyone to stay safe online. And so this is an article just talking about that proclamation. In there, there is a quote from everybody's favorite chief information security officer, the the CISO for the state of Colorado, Jill Frazier. And she says, just like physical security entails shutting and locking doors, cybersecurity requires us as individuals to take basic actions to protect ourselves online from online threats. So, uh, not a whole bunch of, uh, deep information in this article, but, uh, again, good thing that, that we are being safe online and that, uh, Colorado is, uh, proclaiming October to to be Cybersecurity Awareness Month.

Absolutely. I completely agree. I think, you know, we talk about in the enterprise world, top-down kind of priority setting, and it's good to see from the top-down leadership at the state level, they're making these things important. They mentioned things like unique passwords, passphrases, multifactor authentication, and just staying vigilant against phishing, which, you know, for better or worse, has been the number one culprit and doesn't seem like it's going anywhere. For sure.

All right, let's talk about the big one. Uh, if you were trying to live your life, uh, this past couple of weeks, you probably noticed that AWS suffered a major outage. Uh, I know for myself it affected me trying to get a car wash, which was a minor inconvenience, but I, I survived. I'm still here. The car did get washed eventually.

Uh, but there was widespread service disruption. Probably don't need to tell this audience that it was a pretty big, pretty big event. And for me, Alex, I kind of wanted to talk about the centralization of a lot of services, right? Even down to OpenAI. And you watch downdetector.com's main page and you just see spikes everywhere.

And we kind of think about centralization of services and where we're all relying on things. We thought the cloud was was the answer. And now we're kind of stuck here, um, contemplating. And then Azure suffers a, an, a similar but different incident a few days later. Uh, I just kind of want to get your thoughts, feelings, frustrations on the, the whole thing.

Yeah. Um, and, uh, people may be wondering, um, you know, is this actually Colorado news? And so we're, we're talking about an article here that came from CU, um, But yeah, I mean, to your point, Joe, the, you know, we wanted everything in the cloud because, uh, it, it is, can make things more scalable. It can make things, um, you know, easier to keep online, but you actually do have to architect your solutions so that they do that. And, you know, because AWS East is, uh, is so old and one of the first AWS regions, Like it seems like everyone bases their services there.

And so oftentimes they don't have the, the correct failover or other things so that when there is a problem with AWS East, things still work. And so every time something there screws up, it seems like the whole internet goes down. And if people aren't aware, the reason why this happened was DNS, because it's always DNS. You know, not any sort of security issue, not any kind of hacking or anything like that. You know, just a configuration problem.

One of the things that I thought was interesting was, we'll say coincidentally, shortly before this happened, AWS made an announcement that they had replaced about 40% of their SRE staff with AI. I mean, coincidence? I don't know. Yikes. Yeah, the, the timing is— the optics, as they say in the political sphere, not, not great.

Um, and, and Levi R. Perrigo up at CU Boulder, the, the co-director of the professional master's program in network engineering, was, was featured in this article from CU Boulder and kind of lays it out very bluntly to say these things do happen, for better or worse, and there, there is risk to it happening again. And unfortunately, it is essentially a fact of life today, especially as many things are as reliant on, on that infrastructure. We just kind of have to hope that our, our backups are good and life can go on. Obviously it did and, and they— it will happen again. So testing, validation, documentation when automation is involved, Mr. Perrigo says, is vital.

And I'm right there with him. Awesome. Let's jump to our next story. This is a story that came out a couple of days ago talking about how Colorado Attorney General Phil Weiser and the state of Colorado are suing the Trump administration over the relocation of Space Command from Colorado Springs to Alabama. And we have talked about this story, or at least the relocation part, several times in past months.

And I wanted to put this article in because I think it's interesting, the reasoning behind why Colorado is suing the Trump administration. And that's basically that the— it was stated by them that the big reason that they are moving Space Command from, from Colorado to Alabama is that they did not like the way that Colorado does its elections, which is paper ballots. And, you know, part of Colorado's Constitution and the way that elections are set up is that each state should have the right to do however they want to do their elections. And so, uh, we feel like this is retaliatory. Your thoughts, Joe?

Yeah, I think I, you know, this one's not over, uh, and I don't think we're gonna hear the end of it. I just, I believe even this week there was some, some stuff coming from the president that said, uh, along the lines of, uh, no mail-in ballots, in-person voting only, no absentee, and that type of thing. So he clearly hasn't changed his position on what he believes he can, he can do and, and, and how to exercise that power. I think that it's a, uh, very smart way to position the suit. Again, not— I'm not a— just like I'm not a real estate professional, I'm not a lawyer either.

However, um, I do, uh, like, uh, Phil Weiser. I think he is, is positioning this correctly as far as I can tell, and, and intelligently. And I think, you know, retaliate— retaliation at this level is not, um, not good. It's not benefiting anybody. And I think that we, we even talked about this just last month, but the, the actual impact to the job numbers was a little, uh, foggier in the news initially, but it's, uh, it'll be interesting to see, you know, what happens when, uh, the next administration comes in, whoever that may be.

Do they continue this? Do they drop it? And what— poor Space Force caught in the middle, you know, like a child of divorce here. What are they gonna— yeah, how do they continue and how do they, uh, keep their mission primary? Yeah, and the goal, short-term goal of the suit is an injunction to stop the move.

So Maybe if nothing else, it will delay the process of moving from, from here to Alabama until a potential next administration, and then we can see what happens then. So I guess we'll just have to see what the courts say. Yeah, yeah, should be interesting. Well, on to our next one. This one is straight from the Colorado General Assembly.

This is actually more of a kind of heads up. I hope you're ready for it already. If you're not, might want to go back and check with your legal teams, but the, uh, privacy protections for children's online data, uh, effective October 1st, this act amends the Colorado Privacy Act, which this, uh, enhancement essentially centers around the privacy of children in Colorado. Uh, the big tenet here is going to be things like targeted advertisement, uh, cannot be performed, or, or selling a minor's personal data cannot essentially take place, which, uh, being in that industry currently, it is a little bit of a Wild West and it is something that we see these, you know, 50 different legislations for 50 different states. And I know my privacy team has been very, very busy considering how we're going to work on these things.

But there's other things to include, precise geolocation, and it's good to see. And this is kind of the angle I want to understand from your perspective, Alex, is how do you feel about one multiple privacy acts. You know, there's a Colorado, there's an Oregon, there's a Nevada. Uh, 50 for 50 here, we're shooting for the full gambit. But also, how do you think Colorado is doing on this proposal here, these protections?

Yeah, I think that, uh, that this clarification, first of all, is great. I believe that there was, uh, some language in the Colorado Privacy Act about, uh, data from children, but, uh, you know, getting more specific and providing these, uh, specific guardrails that have to be in place for children's data, I think is welcomed in my mind. But to your question, yeah, I mean, it makes it really hard to run a privacy program when you've got all of these different regulations that are based on every state. Granted, many of them are pretty similar. So I think if you get to the high watermark to meet whichever is the most strict, you're generally going to meet all of them.

Uh, with, you know, a little bit differences here and there. Um, but I, I think with a lot of things, it would be great if we had a federal statute for this as opposed to all of the different state ones. Uh, but as we have seen with, uh, with data breach and cybersecurity protections, uh, that came before this, where we have 50 different states with 50 different, um, regimes for this, pretty unlikely that the, the federal government is going to actually get their act together and put something in place. So, I won't hold my breath. Yeah, you make a great point.

I remember working back with a global retailer and they always used to say, you know, if we can, if we can hit California's bar, we're probably going to be good everywhere else. I don't know if that still holds true as them being the most strict, but it's a great point to try to find the highest bar, clear that, and you're probably going to be able to cross-map it down without any issues. Yeah. Yeah. I mean, we can always hope for a national standard, but, but yeah, like I said, I don't— not gonna hold my breath.

Maybe it comes someday, but for now we got to deal with what we got. So, uh, moving on, we've got a blog from Optiv talking about navigating the vast AI security tools landscape. And, uh, this was— I thought was an interesting article. Um, you know, it's talking a little bit about— and this is mostly about AI security tools, um, and so all of the different tools that are helping us either by using AI for security or for managing, uh, AI as part of a security program. But, um, there's lots, and we are in a boom right now.

And every day it seems like there's another tool that's coming out that either is, uh, strictly AI or is using AI as part of making their, their product and service better. So, so what is it that you do about that? And, you know, one of the problems they lay out here is what they call the bread aisle effect. Um, you know, so many tools, it, it makes it hard to make a decision when you, you see all of these different options that you have. And, uh, what they say instead is, okay, why don't you start off with, uh, use cases and use use cases to, to be the basis for tools that you look for, as opposed to just looking at overall AI security tools?

What's your thoughts, Joe? Yeah, I think they also, you know, I'm going to steal what is the easy call out, their bolded sentence here that says awards often recognize innovation, not integration, uh, and that it essentially can look great on the paper or, or through a POC even, or through the demo, of course, when as long as the demo gods smiling. It might look awesome, and then it also might mishandle regulated data or create more noise, or who knows, could take a year of really tuning and enhancing the product itself to make it worthwhile for your teams. You have to think about quite a bit of your use case to understand the up and downstream effects of what you're bringing in. Should be, you know, I think AI kind of does this thing where it highlights the preexisting conditions of your organization.

Like if you already have a problem at the foundational level, it's going to be exacerbated by an AI tool the same way that automation, you know, bad, bad process in equals bad process out. And I think that's— that holds true for the AI revolution we're in the midst of here. Yeah. Yeah. I thought it was interesting, as you know, from Optiv, as someone who sells security tools, They had a great line near the end that says, start with the problem and understand the process, then pick the right tool, not the loudest one.

So I think that's good advice for anything, not just AI tools. Absolutely. And on to our final story, uh, this month from the Red Canary blog. We have, uh, Commanding Attention: How Adversaries Are Abusing AI CLI Tools, which, uh, Right in line with what we were just talking about, uh, right? I think what's interesting about this, and always interesting about Red Canary, is as we learn about a new technology, as we see it kind of proliferate through organizations, enterprises, we get the demos, your COO gets excited and you're asked to implement it, uh, or MCPs are the new hot thing at your organization, it is also hot for the adversaries and the attackers.

And so what Red Canary is essentially laid out here is as these things become more popular, they will not only become popular with the, your engineering core and your, your build functions, but also the folks looking to exploit and get in there. So they've got some great detection logic and everything down to specific tools. They're calling out Gemini CLI, Claude Code, and then also some testing that you can run through. But once again, Red Canary just coming through with great technical lingo to, to look through and have your analysts or your detection engineers implement in the real world here. Yeah, I think that this is a— it's a great blog.

And, you know, we're at the point now where it's not really whether people are using AI tools or not. It's now, okay, trying to determine which ones people are using and how it is that we can help protect them. And, and so I think that this is really some, some good info that, that people can use to help with that. One of the things they talk about in here is MCP security, which I know is a big concern for a lot of people right now. MCP is kind of the Wild West-ish piece of AI at the moment and pulling in data from all kinds of places.

So I thought that that was really interesting as well. Yeah. Yeah. And oh, go ahead. No, go ahead.

I was just going to say Zscaler being, you know, the parent company of Red Canary now also does have some stuff to to kind of help you along the way. So they've got, of course, their links out to their GenAI security. But I feel like even in the last week I've gotten 4 or 5 different emails about come check out our, our new stuff. I know CrowdStrike's bringing stuff in. So as we see more of the exploitation and, and development of the adversaries, we'll also see it on the, on the, on the blue side.

So still not, not all doom and gloom here. Nice. All right, uh, that is our news. Let's jump over and talk about our events. Of course, we do have our event calendar on the website.

This is the consolidated location for all the, the things happening in the security ecosystem in Colorado. So go take a look at that, colorado-security.com. And, uh, the first event that we have is at Denver ISSA. They have a chapter meeting, AI: The Good, the Bad, and the Ugly. On the 12th of November.

And also happening on the 12th of November is the ASIS— that's A-S-I-S— That's a Wrap end of the year happy hour party. Very nice. On the 19th, ISSA Pikes Peak is doing a chapter meeting down in the Springs. And on the 20th, ISACA Denver is having their November chapter workshop with ISC2, uh, offering 4 CPEs on that one. Very nice.

On— we're gonna jump into December a little bit because we got a couple December events in the, uh, early in the month. Uh, on December 5th, ISC2 Pikes Peak is doing a chapter meeting, and of course we have the ISACA Denver holiday party on December 11th. I, I would be remiss if I didn't let Alex, you chime in a little bit because that is— is— it's the big one. Yeah, and this is, I think, ISACA and ISSA and maybe even a couple of the other groups. You know, for a long time, ISSA and ISACA did a joint holiday party.

And they, I think they've expanded that a little bit, maybe bringing in some other groups, but always a good event. December 11th. So check that one out. All right. That is everything we've got for this month.

We do have a feature interview this month. Frank sat down with Chazz Gifford from Intrado, and they talked about a number of things, and really interested to hear that interview. So that's coming up next. Thanks again, Joe. Appreciate you being here, and we'll talk to you next month.

Thank you.

Hi, this is Matt Morton, CISO over at Ball Corporation. Welcome to Colorado Equal Security for Colorado Security professionals by Colorado Security professionals.

Good morning, good afternoon, and good evening. This is the Colorado Equal Security Podcast. My name is Frank, and my guest today is Charles "Chazz" Gifford, right? And you—I understand you prefer Chazz over Charles, right? Yeah, for the most part, correct.

Okay. Thank you for having me. Thank you. Well, everyone, welcome back to the show. We're about to dive into the minds of people who don't just observe change, they engineer it.

Our guest today is a visionary leader who understands that technology isn't a tool, it's a blueprint for tomorrow's business strategy. He has spent his career at the intersection of complex operational challenges and global business transformation, leading high-stakes teams through periods of massive growth and disruption. He's a specialized— he's a specialist in simplifying chaos, whether that means architecting enterprises and solutions for world's largest brands, driving digital excellence, or building resilient operational models from the ground up. If you want to know how global organizations truly move the needle in innovation, leadership, and scalable technology infrastructure, you've come to the right place. So again, welcome, Tras.

How are you today? I am doing well. It's fall, the colors are great, and it's budget season, which we all are aware of, but fall is still one of my favorite times of year here here in Colorado. Well, which one do you feel, uh, I guess either better or worse about, the colors or the budget? Um, I feel better about the colors, worse about the budget.

All right, I think that is the, uh, the standard answer that we want everyone to hear. Okay, uh, before we actually get started, I always like to start off with a fun icebreaker question here, and for you, the one I have is If you had a time machine, what event would you want to witness and why?

Oh, that is a really great question. I have never been asked that question. I have had many icebreakers, but I have never been asked the time machine question. So for me personally, I think if I had the ability to use a time machine, I would like to go back and see when the Declaration of Independence was signed by, um, by our forefathers, only because I happen to love the United States. I love the freedom, and it would be awesome to really get their perspective.

I mean, if you think about where we've come as a country, and then you think about, like, I mean, all of these forward things that have happened since then You know, automobiles, air travel, space travel, satellites— like, none of those things were even a hint in their lives. That's what I would do. I would, I would go back and, and, and learn a little bit from our forefathers about how they framed the Constitution and, and the things that they brought that allow us to operate today in this great country. Well, if you put your mind— and let's say General George Washington and you put yourself in there, what do you think they would say then in that case?

I think that they would say a lot about— not a lot about what freedom is for every single person. And, um, you know, I would love to, to really hear. I don't know what they would say about, you know, the founding and, and if they looked at what we have today in terms of, you know, where we're at as a country. But it would be awesome for me to listen to, you know, what framed their mind, like what brought them there. Because I don't know what they would say to, you know, I mean, we obviously know the, the story with the Mayflower, and we obviously all have that history about, you know, forming this country.

But understanding what, what was in their minds and what not just George Washington but all the framers of the Declaration had as their mindset. Because, I mean, they were visionary leaders in their time. And, you know, that's what leadership is sometimes, you know, putting together your bold vision and learning that. So I think they would talk a lot about the freedom and a lot about, you know, the breaking off of monarchies and things like that. But I would really— I really don't know what they would say otherwise, you know, and that's what's interested me.

Okay, well, you know, I think something that maybe some people know about you or not is that you are the author of The CISO Evolution, right? Business knowledge for executive cybersecurity executives. I actually own a copy of this, um, and from talking about visions and talking about that book, what do you think is our greatest innovation in, let's say, the last decade? Whether it's AI, whether it's a lot of the automation, whether or not— and, and we don't actually have to stick with, with, uh, computer technology or technology at all. What do you think is going to be our greatest thing, and what do you think started that vision?

That is an excellent question. You know, Um, I think for me the greatest, most impactful aspect that I see today is quantum computing. Okay, quantum computing, really? Okay, and why is that? I mean, you know, I think a lot of us know that from, of course, uh, the Marvel movies and Ant-Man, but that's not real truth, right?

Yeah, exactly. Uh, you know, early on when I was super young in my teenage years, when I was, you know, working with x86 type of computers and, and things of that nature, um, and building those and, and understanding the register, you know, my favorite— my, my 2 daughters will say this— my favorite saying about the world is it runs on zeros and ones. And, and in the quantum realm, you run on qubits, which those qubits can be 0 and 1 at the same time. So while it's slowly gaining steam right now, eventually we will have systems that will be able to do calculations that would take hundreds of years in seconds, even with today's modern computing. And they're probably going to wind up powering a lot of these large-scale AI models we see today and use today because that's the next evolution.

And so while AI is kind of a big deal, you know, AI has been around for a long time. Like we've been using machine learning since, I don't know, since, you know, the early 2000s with respect to user behavior analytics. Like, you know, those type of things have always been been with us in the cyber field. So AI isn't this like new frontier for me. It's the, it's the evolution of our compute environment and what quantum is going to bring to us, which we wouldn't have available today.

And that's why I feel that way. Okay. Well, I do have to correct myself, I guess. I made a slight mistake. I mean, I think you've read the book, but I don't think you said you were the author of the book, right?

I think Rock and Matthew were actually the author of that book. So we'll have to apologize to our listening audience here, uh, but I'm sure you're familiar with that book. Oh yes, I have. I've read that book and, and, and I've really enjoyed it. I think, you know, part of leadership is learning from other people that have gone through similar aspects.

And so, you know, reading is super important, and I love that book. Not trying to plug the book here on Colorado Equal Security, but just as me personally, I really enjoyed that book. Well, both of those guys are at least, uh, are part of our group, so I think that's okay. And, uh, they think they give away a lot of that knowledge. Um, but going back to that visionary in the quantum, is quantum the thing that drove AI, or was there something else in there?

When you say drive AI I'm not sure. Do you mean like the AI explosion that we see now where you can't have a conversation without someone talking about AI and cyber, or are you thinking on different terms? I think, I think when we were talking about is mostly in the last, what, 2, 3 years, maybe even less than that, we all of a sudden, and we started off with like what, uh, ChatGPT, and then Gemini. And now I don't think we can count how many AIs, or we, we could probably have AI count how many AIs there are these days. Uh, but all of a sudden, what was the reason for that explosion?

Was it the quantum computing? Was it the new, uh, ARM processors? Was it just, it was just going to bound to happen? So my perception, and, and this is just my view, is that the cost of computing has, has come down and actually is ubiquitous now. And that's what drove this revolution because AI is so compute heavy.

So, you know, and I mean, you and I have been living through Moore's Law for our entire careers. And, and now, like, for example, when I was building systems in the late '90s, you know, with 8 x86 processors for my friends and family, like those, the cost of building one of those was like $2,000. Like an Apple IIe was going to run you about $2,000. Now you can walk into any electronics store and buy a laptop for, you know, $200 to $400 that is going to do it. That's how ubiquitous.

But I think that that is what drove AI because we have this, all this compute power that we never had 10 years ago, and it's been able to release unharnessed AI in that environment. Okay. And its effect on society, AI and society in general, what do you think about that? Oh, I mean, that's— I mean, we— you just mentioned— well, you just mentioned we— you can't have a conversation without saying AI, so let's, let's just handle that element in the room there, right? Yeah.

So yeah, I— my personal opinion is AI is going to advance civilization, but it's going to come at a cost. And that cost is going to be jobs in, in, in the world, not just the, not just the United States, but the world, because AI can do a lot of manual things for us and they can make us better. And we can do more. You know, a lot of code is being written by AI. So, you know, entry-level software developers, those are some of like the things that I'm concerned about is there's going to be a negative reaction, which is going to fuel a public negative opinion of AI.

And then I see it as a wonderful tool that that we can use to become even better cyber practitioners. And what I mean by that is leveraging AI across our security stacks and across our environments to ensure that we are keeping up with how the bad actors are leveraging AI. And so I'm kind of one of those people that loves AI, is very fascinated by it, but I also have this deep-rooted concern that I feel is once we cross this threshold where we start to see AI in businesses, like the normal business day, you know, whether that's at a McDonald's or at some other fast food joint or wherever, it's going to have a, a negative public opinion because it's gonna— it, it will eventually drive jobs and take over some of the jobs in our world, and that's going to be tough for us to swallow. Well, okay, so let's tackle that 800 pound gorilla that's in the room right now. And, you know, what, we, we don't want to get into the politics of this.

However, I'm sure you and a lot of our listeners have heard Facebook laid off, what, 600 or 800 people from their AI division. Was that shocking? I mean, to you? And what could possibly be their motivation for it? Did their own Can creation get them out of the job?

I tend to think, and maybe I'm a little more cautious around my theories, you know, with Meta and with those layoffs around AI. But if you take a step back and you extrapolate, hey, you build your first AI, it's maybe on a scale of 1 to 10, a 4, and then you train it, train it, you release your second one, it's now a 5, and it learned from the first model. And then your third one, third one's a 7 because it's learned from the first 2 models and it knew how to go from 5 to 7. And that increasing cycle means that the AI is learning and adaptive and becoming almost, um, you know, more than just model processing and language, but actually human type of learning is now intrinsic to it. And so to answer your question, yes, I think probably at some point some of the AI got to a point where it didn't necessarily need as many people overlooking it.

Okay, well, let's, let's Uh, let's not get so serious here, but, but, uh, let's think of what The Matrix and the Terminator movies, right?

That is the basis for human destruction. Yeah. I mean, do you think that we're down that path?

Do I think we're down that path? No. Going down that path? I, I do think we're, we're looking down that path. Yes.

And the reason I say that is, is only because Now, I'm not one of those gigantic conspiracy theorists, and I love to think about this type of stuff, but at the end of the day, when you start developing these AIs and eventually they start running more autonomous things in our environment, how can it not lead to that? Because, you know, we're programming it. If, if we as the engineers don't program it with the proper parameters, it could, it could literally, you know, cause mistakes. Now, I don't think it's going to get to the point of, you know, what we've seen in The Matrix and in all of those, those movies, which I happen to like watching. But, you know, is there, is there a path to get there?

Sure. Do we— are we ever going to see it? I don't— I think a lot of the guardrails and a lot of the ethics around the safety teams of AI would have to fail for us. To get there. So like, what is it, uh, the 3 laws of robotics that— oh yeah, yeah, right, you know, never harm a human.

Yeah, yeah, yeah.

Have you ever let— you know, don't allow yourself to become harmed unless a human, etc. Yeah, uh, but what about, you know, you're talking about the goodness of people, right? You're talking about the engineers, us, and probably a lot of the people that listen to this podcast Oh, but AI of course is being used in evil purposes as well, and in that case they don't have those guardrails.

This is true, and that's what's very concerning, and that's why I think, you know, as practitioners, um, you know, we have to adopt the use of AI because our, our attackers are using it today. I mean, you can go on the dark web and buy a hacked version of any of the large AI LLMs that are out there in the industry, and you can rent it to create phishing campaigns. You know, they basically have removed all the ethical boundaries, and that's only going to grow. And so the access to more compute means we have to then you know, continue upping our game. Okay, well, what would you suggest?

Like, if you have put yourself back into your school— I mean, I think you and I started at the same time working on— I actually started on 486s, not, you know, a little bit on 386s before 486s. But looking back and trying to go through that timeline, would you have a different opinion knowing where the end of the evolution is?

And I guess, you know, as it stands right now with the AI, right? If you knew where— if, if you could go back in time right now and talk to your 20-year-old self, what would you say? Oh, I would say, self, you need to focus more on the nuts and bolts in the plumbing of the, of the networking that builds everything together than the application side. Okay. And I would say that I would need to prepare for, you know, IPv6.

I mean, I grew up in IPv4 land, you know, lots of, lots of those protocols, the OSI model, and just know that I would also prepare myself that Moore's Law is going to continue. Like, when I was young, I, I couldn't have imagined the compute power we have now in the palm of our hand. Like, that was never— and, and I'm gonna date myself here, but, you know, my first real job out of college, I had a 2-way pager and I thought I was the bomb. Like, that was so cool. You were the bomb back then.

They were, you know. I had a car phone. You know, one of those big things you'd lug around, plug in the cigarette lighter, and then I had my 2-way, you know, to, to get in touch. And I thought, oh man, this is awesome. But I would prepare myself for a world that is more digital than I could have ever anticipated.

Okay, and I do want to get back to that comment, but I actually want to get back— I'm going to put you in position here, right? In the fact that now let's have you take— go all the way back to the founding fathers knowing of course what you know now, let's say that you can, in, in whatever some kind of miraculous way, you could now advise them and they're all ears to you.

Wow, that's, that's a lot, man. That is, that is— we may spend the next hour talking about that. Seriously, there's a lot to unpack there. You know, if, if I was advising the founding fathers Wow. I would have to say I would think about, and I would advise them on understanding just how much technology can further our world, as well as technological— technology type of guardrails.

Like, those are the 2 things I think of right off the top of my head. I'm sure I'll think of more as we go through this conversation, because that's a pretty heavy pretty heavy, you know, heavy thing. Oh, absolutely. And, and maybe we need to change this to the Colorado Equal Security Thinking Podcast, right? Or yeah, we'll have to add that to the name.

Okay, well, let's, let's go actually go back to that pager and the cell phone and when you thought you were the bomb. Or I think you actually— I'm going to say is that we still think you're the bomb here, but Was that your first job? Did you come in, did you get out of high school, out of college and say, I'm going to be a cybersecurity expert? And as a lot of our peers know, nobody really knew that cybersecurity existed back then. However, let's kind of just pretend a little bit.

Is that where you were going to go? I'm going to do computers for the rest of my life? No, actually, it's kind of interesting how it transpired in my lifetime on my journey. Because I started college, and when I started my undergrad, I wanted to go in law enforcement, and I thought for sure I was going to be a police officer. I thought for sure I was going to work in, in, in my city I grew up in, which I actually did my summer job with the police department there as a bike patrol officer during the summers, ride around and write tickets and things like that.

And I always did the technical thing on the side, and I always built computers. And I wound up, um, building a, a computer for a family friend, and they ran the local aerospace office, which was right across the street, and said, hey, we need someone to come and help with IT. And I was like, oh, okay, I'll do that. And so my senior year, I started part-time there, and then I was blessed with being hired right out of school. So my first job, I managed a VAX system for those people that know the old computing.

And I finished a thick coax tin base T network. I mean, finished building the BNC connectors to build that out for this office space. And that was like my first job right out of college. And so it was a blessing. But that is what led me into cyber, actually.

Okay. So, you know, and I do also have your LinkedIn profile here. Was that with Ball Aerospace? Yeah, that was with Ball Aerospace initially, back in actually Ohio, of all places. Okay.

Well, okay. I'm now going to, you know, because I'm really putting you in a position here and I maybe put a little bit more.

You've been with— you were with Ball Aerospace for like 19 years, and then you did another 2 years with Ball as well. And one of the things that we talk about in cybersecurity is maybe getting into that stagnant area, right, where ideally some of us like to stay about 3 to 5 years and then we move on to a different company so that we can continue learning. And at least in our industry, it's actually very rare to stay in a company for 10 or, you know, in your case, 20 years. What do you think your thoughts are about that as far as, you know, both from someone that's lived it and then maybe even later on turning it around and hiring somebody that's been with the same company for 20 years?

Yeah. So firstly, I would say that, um, you know, during those 20 years, I was blessed with significant opportunity of changes. So like, for example, when I first was hired, I was at a remote office, managed the remote perspective, you know, only things in that, in that office. So you can think of it that way. And then I was given the opportunity to move up and join the enterprise at the headquarters.

So they moved me out to Boulder, which is where I have been since then. And so I share that as just an example So that's an example of while I've been with the same company, it wasn't the same job. So for example, I went from managing a little local office to help managing the domain infrastructure, running the email system, you know, dealing with things on the enterprise level as opposed to that. And to drill down further into your question, part of the reason why I transferred from Ball Aerospace to Ball Corporate is I was doing a lot of classified work and I couldn't talk about what I was doing, and that was really hard for me. And so I was ready for a change.

I had, I had actually gotten to that stagnation that we talk about openly now. We didn't talk about it openly back then, but we do now, which is great because that's you know, that means we're advancing. And I personally, um, I went from, you know, the aerospace DOD to a global, you know, 30,000-person organization all over the world. And, and I was leading, you know, security operations across the globe. And that was really an awesome transition.

And so As I grew up with Ball Aerospace, I learned a lot of that. And, you know, I was given opportunities. I don't necessarily— I don't think that I did myself any favors staying with the company as long as I did. When I look back at my career now, I guess one of the things I would tell my younger self is move, move. And, you know, once you reached a position where, where you've— where you feel a little bit stagnant, don't stay there.

Like, you know, I saw my father, who, who worked his whole life for the government, do a job. You know, he went on base every day and came home, and, you know, that was it. So it was, it was used to me. But now the world's different, and, and I tend to want to see those changes because what I will tell you is You know, I went from, you know, Ball Aerospace to Ball Corporate to Charles Schwab to United Launch Alliance to Intrado. In every one of those changes, I learned and I grew as a leader, and it set me up for more success.

And that growth is what's important to me when I hire somebody. So when I look at, okay, you know, if a person's been with the company for, for 15 years, that's okay to me provided they, they have the growth, you know. And that, that growth and understanding and maturing is what I'm looking for. Does that make sense? Okay.

Oh yeah, yeah, absolutely. I mean, and I think that's one of the things. So, uh, one of the things that I'm going out next week is I'm actually flying out to the University of Michigan to talk to the university students about getting a career in cybersecurity. And I do talk about that growth. I talk about being hungry.

And honestly, I want to talk about some realities. And I'm saying, if you are not hungry for this job, it may not be the right job for you. And I'd like to get your opinions on that. Am I— and, and I want you to be very honest with me. Am I right?

Am I wrong? Wrong in saying that, hey, Mr. Student, if you're expecting to come into this job and do the same job for the next 20 years, this is the wrong career field for you. I think you're absolutely on, on point with, with that statement. And, and the reason why— and this is, this is, gets back to my philosophy, like with leadership, you're always growing, you're always learning to be, how to become a better leader. You find a mentor, you listen to that mentor, And you grow as a leader.

And the same thing is like technical. Like, I'm— I can't see someone that does penetration testing for 10 years. Like, okay, what else have they done then? You know, like, I want someone that's well-rounded in cyber. You may be a great pen tester, but you also have to look at at the defensive side as well.

And if you're doing the same job for 10 years and it doesn't change, then you're stagnant. And the hunger that you talk about, what I, what I appreciate about that is that's the hunger to learn. And that's the thing, our, our industry evolves, and it, and it's evolving faster than I ever anticipated it And so if you don't have that hunger, you're not out there learning, you're not out there going to conferences, you're not out there talking to people, you're not out there growing your skills. I mean, a decade ago, no one knew of containers. Now, now we have infrastructure as a code, we have containers, and you better understand how to protect those things, you know, or you're going to wind up on the news, you know, in And that hunger is what drives you to learn that.

Okay. So when we start talking about that hunger, right, or how do we quench that hunger? Is it, you know, cuz we have people of course that may stay in the job for 3 to 5 years. There are some people that almost every year they get a new job. Is that looked upon like if you are looking at resumes without knowing personalities, not knowing anything else, would that affect your decision to bring that person in?

Or maybe not even a resume, maybe in just a casual conversation.

I would have to say it depends because you want to find that balance, right? Like someone that moves year from year from year from year, it depends on what they're jumping to and what they're leaving behind. Like, you know, when I first started in IT and cyber, like you mentioned, there was no, there was no, oh, this is a cybersecurity position. It was like, you're gonna do, you're gonna run the cybersecurity services, you're gonna do IDS, and you're gonna be part of IT. And that's just how it was.

And now that's different. But I personally would want to understand what's driving because it also takes time to get orientated into a company. And if you're moving every year, you're not necessarily getting the full understanding of the company, you know. And you, you may have grown and understood it enough and said, oh, I don't like this, I want to move, and have very good valid reasons to do that. But if you're doing that over and over and over, on year increments, then it looks like, okay, I can only count on you for a year.

So I may— if I hire that person, I may not necessarily put a lot into that person's growth and, and think of that as a long-term team member. Okay, well, speaking about team members, right, and talking about team members, how important is it that you get along with your co-workers and your immediate team And maybe even teams that are related to you or related to your organization.

I think it's one of the most important aspects, and that's why I smile, Frank, because it's like soft skills are so important in today's breakneck speed type of environment. I mean, just look at the last couple of weeks that we've gone through significant vendor you know, vendor challenges, which most likely people listening have some form or, or fashion of understanding of. And when you see that, like, it— I just, you know, if you cannot build the relationships— and this is especially important with CISOs— and being able to speak to the board and being able to, to talk and be professional with the senior leadership team, you're not going to be successful. If you can't do those things, you're just not going to be successful. Well, you know, and again, and I'm not trying to sell my talk or anything like that, but I actually put that into my talk with these things is how important soft skills are.

Right? And be able to talk to people, which is a challenge, I think, because people don't become developers or choose that developer phase because they're outgoing people, right? I mean, there are some, of course, we always know that there are variances. But when you see a developer that doesn't have any social skills or a networking person or anything like that, how could we help them out? How can we, you know, how important are those soft skills?

So I think one of the things that I've always tried to do is with those individuals, I've tried to mentor them and, and, and show them over time how much more effective they can be when they have those soft skills. And that's critical to us. I mean, you know, in the late '90s, you know, IT was that shop that was in the basement. You know, IT was the people in the closet that make things work, you know? And that's how it was looked at.

I mean, my first job, even though it was at an aerospace company, I was in this tiny little office and the PBXs were like above me, you know? It's like we had 110 blocks behind you that you'd punch down, you know, when people moved. And yeah, it was, it was good fun, but I say that kind of jokingly, but also kind of seriously. Like, you know, just like accounting, just like any other profession, cybersecurity is now a true profession. And if you're going to be a practitioner, soft skills are critical.

Doesn't mean you're still not going to be able to find a job if you don't have soft skills. You're just not going to be as effective as you could be at change. And at bringing stuff out to the world. OK. So is that important then to have that ability to drive change?

I mean, that kind of goes on our growth thing, right? Yeah. In leadership, yes. And in an individual contributor, I think you can, you can push on that a little bit with them and grow that for them. And, you know, and this gets back to what, what does the person want out of their role?

Like, you know, is the developer just wanting to develop? They love writing code. That's just what they want to do. Nothing more, nothing less. And there's going to be, there's going to be room for that, right?

Those people will eventually, you know, be monitoring, you know, agentic type of coders and making sure they're not, you know, going in the direction that they're not supposed to. Okay. Well, you know, so are you saying though that we got to get out there, right? And, you know, if you're the coder, would you suggest being in front of the keyboard 10 days a week? Should that be your hobby or should you have a non-technical hobby?

My recommendation is to have a non-technical hobby because balance in life is— it's important to me, and I think balance is also important to our profession. And, you know, whatever hobby that is, you know, outside of it, as long as it's not something technical or in front of a screen, I think it's perfect. And that's my personal opinion, because a well-balanced person is gonna give you more and it's gonna put more into it. It's like we all know if we get like 2 hours of sleep, we're not gonna be the sharpest tack that next day. Okay.

And it's the same thing with balance. Well, do you think that would affect, again, uh, you know, we're talking about performance and hiring, would that, I mean, cuz you know, as you probably know, we're not really allowed to ask those questions anymore in interviews, right? We can't really ask you about your outside life. Life. Yeah.

Do you think that hurts us though in, in hiring? Yeah. Yeah. I mean, I, I personally, um, I personally think it, it hurts us because I think we need to, we need to understand the person. I mean, when you're talking about these jobs that are like, for example, you know, cybersecurity is has gotten elevated to the point where the board pays attention to it.

And if the board is paying attention to it, it has an impact on business. And if it has an impact on business, we have to bring that professional self to that. And having balance means that your mind is refreshed. It means that when you get up every day You're excited about what you do, and you're also excited for the things outside of what you do. And, and that balance makes you great at what you're doing.

You know, it's really interesting because, you know, we both worked at Schwab, and when I was there, I took a hiring class, and one of the people— not the instructor, but one of the people— came up and said, you know, we can usually figure out whether someone can do the job or not within the first 10, maybe 15 minutes. The rest of the 45 minutes is, can we get along with you for 8 hours a day, you know, the 40 hours a week? What are some thoughts on that statement?

I think that statement is, is probably pretty accurate. Um, okay, you know, I can get the general sense of whether whether an applicant that I'm interviewing can execute or not rather quickly.

And, and because we're limited now in, in the questions that we can ask, it's more about ensuring that the soft skills and the integration into the team is, is going to work. And sometimes I've, I've hired people that have maybe been a little lower on the skills and a little higher on the soft skills and grew their technical skills because those are easy in my opinion. It's harder to grow the soft skills. Okay, so in other words, we can teach the technical piece but we can't teach things like attitude. Yeah, in coming in every day and, and And, you know, I mean, if you have, if you have a boss that you say hello to every day and they're like, this day sucks, you're gonna be like, well, why does it suck?

Like, why is your life so bad that every day sucks for years and years? You're not happy, you know? Well, you know, it's, it's, it's funny because I worked from home for about 6 years and the current job I'm in, uh, requires me to be in the office. And I've taken the attitude of being the most positive person. I mean, I could walk in and I could say it sucks every day that, um, I could be remote, blah blah blah.

That's not going to be an option in my current job. So instead, I walk into the lobby, I say hello to the security guards as loud as I can, and every morning one of the monikers that everyone expects from me now is I say, good morning, beautiful people, right? And I try to be the most positive person out there. Just for that reason that you're talking about, to try to get people to talk, to try to get people to smile a little bit. And honestly, let's just enjoy what we have.

Yeah, because it's a blessing in my opinion. I, I like that a lot. Okay, cool, cool. Well, we've talked a lot about people, we've talked a lot about, you know, a lot of jobs What would you say though is the most important thing that you're— or the most thing that you're passionate about?

I think my passion runs deep with protecting people. Okay. Like, I've had this innate aspect of, of fairness and protection in my life from the time that I can first remember. And so I— that's what's naturally like— I mean, I was going into law enforcement, and you can kind of make the argument that I'm, I'm, you know, I'm a protector, just a different type of protection, uh, for, you know, people. Okay.

What drives that though for you? Like, again, why, why is that so passionate for you? Is it because of the way you feel with, hey, I'm going to— I want to be a protector, or is it more of possibly, you know, I've been vulnerable at times?

So both. It stems from both. But early on, um, in my life, I, I faced a lot of adversity. Uh, you know, I lost my best friend when I was in 6th grade. I lost my mom when I was a sophomore in high school, and those 2 things had profound effects on me in terms of vulnerability.

And what it taught me is being self-reliant. And, and obviously, um, I have, you know, I had a good father who's unfortunately passed away, um, and I have an older sister, and we had to get through those things together. And that fairness, like, I felt like it wasn't fair to me. And so being vulnerable, um, from that perspective was a huge, huge part of that. And then, you know, my belief system is, you know, I believe we should protect people, especially, you know, the orphans and the widows.

And, you know, protecting people is, is part of my belief system, so therefore it fuels that passion. And so, and I've just extended that to protecting as many people as I can. Okay, what about though, right, and, and I know this is also an issue about the people that either maybe don't want to be protected or put themselves in danger, either through, you know, the physical area of walking into a bad place or, you know, clicking on those phishing emails, or wanting to say, you know what, I don't believe that there are really hackers out there. Yes, there are some people like that. Yes, sadly.

Uh, but what I would say to that is, you know, I learned a long time ago you can lead a horse to water but you can't make it drink. And then there are sometimes you could do the best you can can, and the best you can is what you need to do, and everything else will fall into place. So those people that don't want help, I, I wish that they would want protection, but if they choose not to, that is their own volition, and I cannot change that. I can only make sure I do my best. And so it's sad.

I think that, you know, I know, like you said, people are very argumentative these days, and, and instead of finding common ground, which is what I think we should do, we don't. And that's, that's, that's, that's sad for me, just being honest. Okay. Um, would you do anything to try to help them change their attitude, or can you change their attitude?

I don't think, I don't think you could change their attitude. They have to, they have to come to that change on their own. But you can assist with that, and you can assist by, you know, by demonstrating, uh, a great attitude. Just like when you walk into the office every day, you're boisterous, you're hello, you're like, let's talk, let's, you know, let's appreciate And just that simple act is an example, I think, of how you can potentially influence them. But they're going to have to want to change in order to change.

And so that's, that's how I think from that perspective. Okay, well, before we get into my final question— I always ask the same final question— have you given any more thought, or has any more thoughts popped into your head about what you would tell the founding fathers about the path of the country today?

Yes. Okay. I would, I would tell the founding fathers a couple of things and let them make the decision on those things. Um, one being career aspect of politicians. Uh, you know, I, I think there should be be— and this again is my personal view, you asked the question, I'm going to respond— I think there should be term limits.

So I would ask them to think about that for the people that write our laws and govern. And then I would talk a little bit about, you know, how divided people can get and, and maybe how we help that from not happening. I don't even know if that's possible. I'm just saying that would be, you know, as we have talked through in this application, in, in these questions and stuff. That's what's popped into my head additionally.

Yeah, well, I mean, I think that whole division part, right, is something that not only exists in politics, but— or at least politics within companies as well, right? I mean, you have those divisions, those supporters, and you do have to, of course, convince them, right? Um, okay, would you give that same advice to, again, your 20-year-old yourself? No, only because I'm not in a position to make some of those changes where the 4 founding fathers were. You know, they, they were— they're in that position.

And, you know, the, the, the way my career has gone and the way that my life has gone, um, you know, I don't think that it, it would apply there. Um, I still would tell my younger self, always listen more. To, in order to learn. That's what I would, okay, would say. Well, you know, of course I've been asking a lot of deep questions.

I noticed the pause before that one. You really had to think about that one. And, um, I, I do try to get into these, into these podcasts, right? Because we want to know about the person, we want to know about the brain. I think there are people here that are either CISOs themselves or want to be CISOs or want to get into that leadership, and we want to get into your brains and understand your journey, right?

And okay, well, I do have the same final question for everybody, which is what is the greatest challenges for security today and how much you address it? Now, we're not looking at trying to solve it, but we're just looking at how do we get in front of it, or is it possibly too late? It's, it's interesting that you asked that question because it's very similar to a question that I got at, at the Summit 4 that we just had, that Colorado Equal Security just had, um, down in, in Denver. And, and I, I had— I was teaching, or I'm not teaching, pardon me, I was speaking on using a certain method to measure um, security effectiveness. And one of— after, after it was done, I got asked, what do you think is the biggest risk today?

Which is very similar to your question. And I always like those questions because it makes you think and reflect on, okay, what is the biggest challenge? And, and I've thought about this for a long time over the years and it still rings true to me. The biggest challenge is the people, because we have to secure the human. And that is, that is the most challenging aspect, because no matter how much awareness training, no matter how much you put into your GRC function and we're still seeing companies get owned by phishing.

Like, and I mean, even, even all the reports, if you look at like, you know, the, the massive reports that come out, I'm not going to name any, but we all read them. Um, you could still see the statistic is staggering. You know, you still have some inside threat, you still have, you know, you still have some misconfigurations. But that entry point, human, and I'm not sure I know the answer of how— I mean, I know how to be effective in certain situations, but securing the human 100% of the time, that's tough. Yeah, well, I mean, I think that also goes back to what we were just talking about a little bit ago about people not wanting to help themselves because the people that work in our business are obviously, you know what, let's say just at a number, 90% of the businesses out there aren't cybersecurity focused, right?

They don't offer a product of cybersecurity. They have a business to go to and they want to accomplish those goals, and they see cybersecurity as a roadblock. If I was one of those people, right, and I'm not obviously, but if I was one of those people right? How would you address that with me? So, and this has been one of the age-old challenges that all security leadership has had, whether the board has been disengaged, whether the senior leadership team has been disengaged, whether the company, you know, hires, you know, one security person to cover, you know, the world, whatever you want to throw out there.

This challenge has always been put, you know, I, I'll be very honest in my career, I have been called this term pond sucking scum of revenue. Okay. Right. And so there's someone that says you're a blocker. They're not using that term, but they're, they're, they're, they told me exactly what they felt about my position and what I was trying to accomplish.

And it was clearly not aligned with their business goals. Okay. And now that I, now that I was thinking back in the moment, it was actually profit was used in there. You were, you were profit, you know, pond-sucking scum. That's exactly those, those were the terms.

But, um, getting back to the seriousness, how I have traditionally approached those, those people that have seen security as a impediment, to understand their view and then to slant my conversation with them according to their view. Now, sometimes they won't come around, sometimes they'll move on, and then sometimes they will come around. And part of that is, you know, every— we, we hear this all the time. Well, you got to make, you know, you got to make security, you know, an enabler.

Mm-hmm. But that's very ambiguous. What does that really mean? And, and so one of the things that I've always done has been taking it upon myself to really understand the business And how business decisions are made so that— and that's the listening part to that person. And I would, I would show through historical activity how cybersecurity can be a partner to enable that person's business decisions, whether that be from the fact of, hey, you're trying to go launch this widget in a market.

And by the way, when you launch that widget, guess what happens when you're on the front page for a cyber event that shuts everything down? I mean, you know, like, so think about that for me and then come back. Let's talk about what that would look like from your view. And when you start working at that level, you get the person that views security as an impediment to understand that, oh wait, it's not necessarily impediment, it's something that we need to do as part of just our business processing. And if we don't do it, here's the risk.

And you allow them to make that, that decision on risk. And sometimes they'll accept the risk, and sometimes they'll say, no, we want to go do something about it. And you have to be prepared as a practitioner that the business isn't always going to align with your view of risk. And that they may choose not to do something. And that's okay.

If you've presented them with all the evidence of why not, then they make that call. You know, CFO controls the budget. And if the CFO says no to this and pushes it out, that's, that's okay. But it will have an impact at some point. Well, I love how you tied the, you know, the slanting of the soft skill, you know, back to your soft skills.

Uh, but I do want to kind of go back to something here, and talking about is understanding that business, right? I mean, we as cybersecurity people love to think about all these attacks and all these potential things that have— and of course, you know, especially in the last few years, we've been told stop doing FUD, right? Stop pushing that fear, uncertainty, and doubt. Uh, try to be a business enabler. Right?

Um, how important is it that you understand the business, right? And does the business come first before security? So my view in leadership, it is a, it is a cornerstone of how you lead, is to understand your business. I believe that if you don't understand your business, you're not going to be effective at your role as a leader, whether that's a CISO, director, manager, whatever. If you don't know your business, you're not going to, you're not going to be successful.

So I think it's paramount. And, and part of that is my experience. Part of that has been several mentors that have showed me how to understand risk at at the board and at the, the C-level throughout my career so far. Um, and then secondarily to your question of, you know, the, the second part, that, that's hard. Could you, could you repeat the second part?

Um, well, does the business outweigh security? Yeah, does the business outweigh security or does the business come first? Yeah, does the business come first? And so I think in the— I think in, in our today's world, yes, the business comes first. Is that right or wrong?

I think we can debate that. Like, okay. And, and I think that you have to partner with the business in order to affect the change that you want to affect, because it does come first. The dollar is what it's about. You know, and if it's a publicly traded company, you know, the shareholders that own the shares are what it's about.

If it is a private equity-owned company, the PE makes, you know, they make those decisions on risk. So that's where the business comes first because they're going to decide the risk tolerance and you're going to execute all the things associated with that risk. Okay, well, we're technically over time, but I, I'm gonna hate myself if I don't ask this last question for you. Going back to something that you said earlier, and I guess at the summit, how do you measure effectiveness? But I mean, there is that book, right, How to Measure Anything.

I think there's actually a cybersecurity version of it as well. But you know, that's something that's very hard. I mean, how do you measure how effective we are in cybersecurity? Yeah, well, I'm glad you asked that question because I, I think it's an important one. And, you know, early on in my career, I had a, a good colleague, a good friend, um, his name is Matt, and he showed me a model from Carnegie Mellon called CMMI, and I have tailored that to cyber-specific activities, and it has given me the ability to speak quickly and crisply to the SLT and to the boards using that methodology.

So I'm a big proponent of that. You have to be able to measure your effectiveness. And the CMMI model does a great job because, you know, it's got the different levels based on execution. And so as a leader, you can literally display a chart that shows where you think the company is and where you think we need to go. And then if you want to even take it a step further, you can get an external rating service that all gets used, all gets tossed around at the board level.

You know, we've all seen the different vendors that do it, and you can see how those align. And over time, if you, if you have a methodical, pragmatic approach, you'll be able to measure. And so that's why I use the CMMI. It's, it's something that I have ingrained in all the programs wherever I go. Okay, cool.

Well, we are actually over time, right? So let's talk any future appearances. I know, I'm assuming that you'll probably be at Summit 5, right? The Colorado Equal Series Summit 5. Anything else coming on or with you?

Um, not, not the rest of this year. Um, I've, I've been doing a lot of, uh, doing a lot of talks. I have, I have one more, um, talk called Share, Solve, and Evolve, um, through the company I work for, and that's a, that's a discussion based with all of our customers, uh, on how we can, how we can approach cybersecurity. So I'm doing that because it's Cybersecurity Awareness Month and And then I get to, to take a break. I'm, I'm submitting papers and, and submitting opportunities to talk.

You know, 2026, there looks to be some conferences outside Colorado Equal Security that I'll be at, and then some of the conferences I know I'll be speaking at with respect to public safety. So I'm excited about those next year, and that's, that's what the future holds in terms of, of what I see in, in terms of engagement. Okay, so, uh, and of course if they want to see what's going on, they can find you out on LinkedIn, right? LinkedIn. Yep.

Okay, well, again, thank you for your time. Uh, I personally, I think by the time this gets published, I'll be finished with my talk, or I'll have a talk at BSides Colorado. I have one called Reframing the Pyramid of Pain, right, for my Defender's Edition, and really talking about the pain we feel as defenders and has actually nothing to do with about attackers. They're trying to get our tools to work, trying to get the money, trying to get a budget. A lot of the things that we just talked about here.

Um, again, I also have that talk coming up, training that next generation of cybersecurity professionals at the University of Michigan. So I'm flying up there again. Uh, that talk should be done by the time this gets aired. Uh, and then of course, Denver OWASP, we're trying to spin up SnowFROC talk and trying to come up with a lot of hurdles, and we're having a lot of hurdles with getting that going. So, all right, well, again, thank you for your time, uh, Chazz.

I really do appreciate it. Um, have a great day, and hopefully I'll see you at either one of your talks or somewhere else. Thanks, Frank. Thank you for having me on. I've, I've appreciated the time and appreciate Colorado Equals Security.

So have a great day. Thank you. You too.

Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.

Until next time, remember, Colorado equals security. Security.

Back to all episodes