Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 281. Alex, it's December, December 8th.
Holy smokes. I know. Almost the end of the year. Also, it feels like we haven't done this in a little while, Robb. Well, you and I haven't, right?
Yeah. You had with, I think with Joe, 2 months in a row. I know. Thanks to Joe for scheduling conflicts and it's just, it was a little different, but now here we're back together. Beginning of November, I was on a beach in Mexico.
Hard to beat. It is hard to beat. Not the place where you want to record this podcast. I did not want to record this podcast. You're right.
Um, but I am excited to record this podcast with you today. It doesn't get better. Uh, speaking of doesn't get better, we have a Slack community that could not be better. That is true. We've got a bunch of folks in there.
You should come join us. We also have a mailing list. Uh, get on that and you get show notes from this as well as some other announcements. You can get both of those at colorado-security.com and get signed up for both of those things. It would be great if you went to your favorite podcast player and rated and subscribed to this podcast so that, uh, we have good ratings and look good and that you get this every month.
Uh, we, we, uh, we appreciate you. Tell a friend about us if you like the podcast. We'd love to have more folks in the community. And speaking of folks we appreciate, we do have some annual sponsors to shout out. This is, uh, the end of the annual sponsorship for Armis.
Thank you so much for sponsoring us through 2025. You've been great. Uh, we also have shoutouts for CrowdStrike, Red Canary, and Zscaler who have, have continued to support the podcast. Wonderful stuff. We appreciate all of them.
All right, let's jump into the news. Uh, first story we have is about the, uh, newly formed women's professional soccer team Denver Summit FC. And Robb, big news about where they're going to play their first game. They're gonna— they're looking— they're hoping to set the league record for the most attendance, the greatest attendance at a game, by having their game at Mile High Stadium, the home of the Broncos. They're, they're looking— I think Their league record was like 40-something thousand.
Yeah, biggest game previously. They're looking to get 70,000-ish. Well, that's what they hope, sell it out, right? The game is in April, but it's been announced. I believe it is on March 28th.
That's really close. Very, very close to April. If you start just about April game in April, you'll be disappointed with me. So yeah, thank you for fixing it right away. I believe tickets are on sale now if you wanted to go get a ticket for that game.
And be one of those folks that hopefully helps them break the record. They, they are going to have a beautiful new stadium built in like the railroad area in South Denver. But, but it's going to take a couple of years. So for the next couple of years, they're going to have a temporary new stadium built here down near me in Centennial. Yeah, I think it's in partnership with Cherry Creek Schools, maybe using some of their facilities.
And they say that The temporary stadium won't be done by the beginning of the season, but they have some contingencies in case they need to use them other places around town. They could play things like that. Awesome. All right. Jumping over to our next story.
A Colorado legend is back at the helm of EchoStar/Dish. Charlie Ergen, the founder, and I think he's been the chairman of the board forever, has stepped back in to run the helm of the company. You know, they they ended up doing an incremental sell of of their bandwidth. You know, they sold more now to to SpaceX, and as a part of them getting like twenty billion dollars from that, they decided they want to spin up a separate entity within the company to go figure out how to invest that money. And that's where the old CEO is going, right?
Yeah. So Hamid Akhavan, who was EchoStar CEO and president since 2022. Is going to lead that new division called EchoStar Capital. Nice, I suppose, to step into a job where they give you almost $20 billion to go invest it somewhere. Expectations are probably high, though.
Expectations are probably high, but it seems like an okay gig. But so, yeah, he's going to run that. Charlie's going to step back in and be CEO of the big company. And, you know, hopefully things go well. Good for those folks.
Our next story, a company we've talked about quite a bit, Ibotta, you know, You know, they IPO'd, was it 2 years ago now? They have— That long? Wow. It feels, time goes fast. Yeah.
They have moved into a new headquarters and they stayed downtown. I think trying to shake the pattern where, you know, you've seen companies leave downtown. They're sticking around and they moved into a new place with a 10-year lease. Yeah, Brian Leach, who is one of the founders and CEO of Ibotta, is a big proponent of downtown Denver. And so he wanted to keep the headquarters there.
In the article, he calls out the fact that Palantir just recently moved their headquarters from downtown Denver to Cherry Creek, which, you know, in his mind was not something that was the best. So, you know, they're doubling down and got, they have 3 floors now in this new building in downtown Denver, right off 16th Street. Do you see, he says, Palantir, who's just a little bit bigger than us. I think they're kind of a lot bigger. Yeah, I guess it's subjective.
It's, it's subjective. Yeah, they are a multiple bigger. They are just, they're just, it depends what that multiple is. Um, all right, well, speaking of, uh, speaking of news, we have a story about 2 Denver tech companies who have advanced toward a potential $300 million prize in the quantum computing world. Robb, that this is great news for those 2 companies, but I would like you to tell me after reading this story What is it that these 2 quantum companies do?
It's almost like this was written by— well, so the 2 companies, Atom Computing and Quantinium— Quantinium? Quantinium. Quantinium. Quantinium. They're both— they both have big presences here in town.
I think Quantinium is headquartered here. Atom is, I think, officially headquartered elsewhere, but has most of their employees here. They are competing for a federal program that will have up to $300 million for the winner. And what do they do? Well, they're building quantum computing.
And somehow this I don't get. Like, by 2033, they want to see like a production commercial quantum computer out. That's what the federal government wants. That's what this whole program is about. And Adam, you know, there's a lot of quotes from Adam Computing in this thing where they're saying, well, we are the first ones to have created a logical qubit, right?
I get the word right. Logical qubit. Yeah. So they're, they're way ahead of the others. But I don't understand, like, they're, it sounds like they're saying that they have computers that run, but, but what are you doing?
What, what would you say you actually do here? They do have computing though. They're actually running things now, but it's not quantum yet, or it's half. I don't understand. I, I don't know if they just wrote this story strictly on the money side and the, the people writing it didn't, don't know the tech, so they didn't talk about it anyway.
So this is all part of a DARPA competition and it's in multiple stages. I think they're currently in the B stage, where it's undisclosed, but they could have gotten up to $15 million in funding as part of this B stage. And then they're— they can get up to $300 million in funding for the C stage, which is what they're competing for now. So glad to see these companies succeeding at whatever it is that they do. And we love to have them here in Colorado.
You know, I, I'm hopeful that by the time quantum computing takes over, that I can have retired because it's going to break everything. And I don't really understand it. We're not in one state or the other. We're in every state. All the states.
What now? Yeah. My brain doesn't quite— I don't think I have a quantum brain. That's why maybe my problem. That could be it.
All right. Moving on to our next story. This is about a cyberattack that happened in Douglas County. The sort of— no, I don't think it happened in Douglas County. Happened to Douglas County through a vendor.
Yeah. Yeah. Yeah. So the Douglas County Sheriff's Office, is looking to move away from a provider called Code Red, uh, based on a, uh, cyber incident and breach that they had. Uh, this Code Red service is the thing that will call you at your house and say, hey, there's an emergency, you need to do XYZ.
And, and so Code Red got— they had a security incident of some kind that leaked the consumers of their customers, and Douglas County as a customer had their consumers impacted and said, hey, well, we're outta here then. We're, We're leaving. The article, like, I mean, it's sad. It sucks that they said, well, if, if there's an emergency, we will go knock on doors door to door. Like, holy smokes.
Like, that's the, that's the other option, right? Back, back when we, when we were young, they could have just called people on the phone. Back in my day. But now that doesn't work. But they did say that they are, there are other vendors in this space and they are looking at other vendors.
It was a little interesting to me. They mentioned that You know, they're recommending that the citizens of Douglas County, you know, check their, their credit reports and other things like that because of this breach, which makes me— I mean, maybe that's a little bit over the top, but it's like, what kind of information does this, this place really have? Like, probably your, your name, your address, and your phone number, right? Right. That would have been in the White Pages back when we were that age.
Yeah. Anyway, I mean, I guess it's not bad advice, but it never hurts to check your credit. Yeah. All right. We next, let's jump over to our security vendors.
We had some blog posts this month. Optiv has a blog post around threat modeling of AI applications and how it is mandatory. I don't think it's actually mandatory, but it should be mandatory. I mean, he wants it to be mandatory. He wants it to be mandatory.
Yes. Strong language here. Be mandatory. Yeah. Go ahead.
But yeah. You know, in the past there have been different frameworks for threat modeling that you would use for traditional applications like STRIDE or PASTA. And this is talking about a new framework called MAESTRO, which is now being developed for AI applications. MAESTRO, which stands for Multi-Agent Environment Security Threat Risk and Outcome. I mean, they made it work.
They did make it work. They made it fit. They made it work. It's a good name, MAESTRO. So this is basically, you know, if STRIDE doesn't work so well with AI, they're saying, Here's the model that's going to work much better.
Yeah, it's the same concepts. You know, you're looking at the possible threats and bad things that could happen to an AI application. And, you know, you're trying to figure out what it is you need to do to prevent those. Take a look at that and maybe you'll learn something interesting about how to threat model AI. Cool.
Up next, we have a blog post from FusionAuth. You know, we've been following the FusionAuth blog a little bit more recently. This blog post is about the authentication rabbit hole, what I learned from vibe coding auth with AI. So the author, Cheryl Hung, decided to see what she could do. I assume that's a she, to vibe code the authentication into an application.
And it looks like her experience was, hey, it would code exactly what I said, but it's awfully hard to say the right things for authentication. That's the general gist. Yeah. And, you know, Cheryl is smart and knows a lot in auth. And so through this process, had to ask for more and more things because knew they knew about those things.
But if you are someone that is not aware of all of those, those auth requirements, you might not know to ask for them and your application is going to be more vulnerable and potentially not as functional. I think if I, if I were to pick like the, the 2 general rules for when you do not build your own thing, it's cryptography and authentication, right? Like, you should use a different tool for that. You should not use vibe coding to solve those problems. Yeah.
My take. All right. Speaking of not using vibe coding, Swimlane had a survey that had nothing to do with that. They did a survey of about 500 IT or security professionals throughout the US and the UK asking a variety of stuff. The headline here is that the report reveals that 92% of breached organizations admit that stronger cyber hygiene could have prevented the incident that hit them.
Robb, I am shocked. Shocked, I say. Um, yes, I think, uh, this is a, an interesting survey. Um, I appreciate that, that Swimlane did it. Um, again, it's, it's great to point out that hygiene is important, but this is nothing new, right?
Like, this is the— it's the same old story. We got to still focus on the basics. No one focuses on the basics. We do, uh, shiny fancy things, and, and breaches happen because we didn't do the basics. You know, so some other kind of basics from this, uh, 52% of organizations say that their greatest weakness is human, uh, human— the human element.
Uh, 2/3— this one's interesting— 2/3 say that they audit user access privileges quarterly. Or less often, which made me say to you, are you saying that there's a third of companies that audit more than quarterly? I don't know. Maybe that doesn't mean audit quite in the way I think of. Yeah.
And, you know, one of the things that I always have an issue with is studies that are just surveys of people. While people's opinions are important, they are just opinions. And gathering a bunch of opinions doesn't make it necessarily fact. Just like us, we have opinions. Nobody cares.
Exactly. I get it. All right. We have one more blog post. Love this one.
This is a Red Canary one from Matt McKinley, a friend for quite a while. Matt's created a new tool. Yeah. So Red Canary, as part of their operations, uses GitHub. And as part of that, uses Dependabot.
And he created a tool called Dependabot Configurator because while Dependabot is a good tool, it can cause a lot of issues, false positives, other things like that if it's not configured correctly. So Matt wanted to make this tool to help you configure Dependabot at scale. So if you are looking for a tool to help you review your third-party dependencies and not overwhelm your team, maybe take a look at Dependabot Configurator and see if it's a good fit for you. If you're in GitHub, right? You gotta be in GitHub.
This was always one of my favorite things about Red Canary is building tools and releasing them to the public, right? So it's, hey, we, we saw a problem, we solved it for ourself. Now everybody else can go solve it easily for them, uh, themselves as well for free. This is an open source tool. And those who don't know, Matt McKinley is not like some, you know, engineer who's working on the product or, or like a customer facing.
He's a security engineer on the security team solving the problem internally. And they, and the company said, hey, let's, let's turn this external. So, So really cool stuff. Good stuff. All right, jumping over, we have next is our events.
We have a calendar of events out at— where is that? Colorado-security, right? Colorado-security.com. You can see I spent some time yesterday going through and finding all the events for the next 6 months, and there's quite a few posted. So you can go see what's coming up.
But in December, we only have 2 events. Yeah. So the first of those next Wednesday, the ISACA and ISSA chapters are doing their annual holiday party. This is a big party. They've got a lot of other groups along with them doing the party and you should go check it out.
And then on the 13th is the Colorado Equal Security Gives Back volunteer event. And we really appreciate Danica and Ben who have been putting this together. I think we're going to be meeting back at the Red Canary office. We are to have everyone drop off the things we're giving away. We would love to have you donate some stuff to help the needy.
There is information on the website. Go check it out if you want to participate in that, if you're not doing that already. All right, our final bit for this. We do have an interview. We do.
Thank you very much to Frank Victory, who sat down with Shane Cox, our friend, uh, who, who, man, he's been in the community for a long time, moved around between, you know, the, the enterprise side, uh, over to the vendor side, back to enterprise. Now he's, now he's working for a company called MorganFranklin and, uh, running their security practice. Excited to hear how that conversation went. Shane has also been a good friend and volunteered for a number of, uh, different Colorado Equal Security things. So we appreciate him for that.
All right. Well, that is, that is it for us this year. Happy 2025 and look forward to 2026 with everyone in a month. Thanks, Robb. Hi, this is Maurice Olson, Director of Information Security and Compliance at EucabyteDB.
Welcome to Colorado Equal Security for Colorado security professionals by Colorado security professionals. Good morning. Good afternoon and good evening, state of Colorado. This is the Colorado Equal Security podcast. My name is Frank, and my guest today is Shane Cox.
Shane, how are you today? I'm doing great. I'm doing great. How are you? I'm doing outstanding.
All right. So they say that complexity is the enemy of security. And our guest today is a man who cuts through the noise, whether he's analyzing the latest threat vectors or architecting resilient systems. Shane Cox, better known as the Shane-O-Matic, operates at the intersections of critical systems and real-world defense. He's ready to put his expertise to the test against the 16 sectors.
So again, welcome Shane. Um, Shane, I always like to start off with an icebreaker. And, you know, to the audience, Shane has not heard this. He has no idea what this question is going to be. But I always like to start with a really, really silly one.
So from a cartoon world, what character would you want to spend the most time with and why? Oh, what a great question. What a great question. I would probably say Professor X from X-Men. X-Men?
OK. You know, just, I enjoy the character. I enjoy the history of that character and kind of the, and this is the cerebral nature in which that character approaches problems and then also combines a little bit of that emotional intelligence element. To help folks work through things. And I think that that's a, that would be someone that would be interesting to spend time with, I think. Would you want him inside your head, though?
Absolutely. I would hope. Absolutely. I would, it would be almost like therapy, right? Where you kind of see what's going on, see where maybe there are some walls built up, see where things could be broken down and into, you know, smaller chunks and maybe addressed a bit better, you know, inside my mind or, or Or help me, you know, better build a memory palace.
Any number of those things I think might be interesting. Well, then let's flip that around. What about, would you want that power to be able to see into other people's minds? Oh, no, thank you. I think that— no, thank you.
Yeah, I think I'm good. I enjoy learning about folks and I enjoy building relationships and You know, I wouldn't need to do that if I could be in people's minds. I think that that would kind of defeat the purpose of the whole relationship piece. So it wouldn't be scary though to have, let's say, it wouldn't be scary, right, to be able to see what people are thinking though? Like, it would be scary.
I think, I think it would be scary. That's why I don't want, want that superpower. Okay. All right. And then again, I think that is a Fair enough point.
Okay, so right now, Shane, you are working at Morgan Chase, right? Or MorganFranklin. Sorry, Morgan— wow, where am I getting that from? That was completely off. I'm like, that's not even a thing, is it?
Okay, so MorganFranklin, uh, we actually reconnected. Shane and I used to work together a number of years ago, um, and What is your role like today? I mean, is it, you know, you're working through this. What is it like to work in a SOC? And I think that's been your history for quite a few number of years, right?
I mean, for a long time now. Yeah, I've been building and managing and optimizing SOCs and SOC programs for a couple of decades. And I love it. I enjoy it. My role today, I'm part of an exceptional organization and I'm building We have a SOC, we have a number of SOC services and intel, threat hunting, adversary simulation, et cetera, et cetera, that go on top of multiple layers of 24/7/365 detection and response services.
But what's really interesting about that is going through this journey in this organization with such incredibly talented people of high integrity. Like, I don't know that I've ever loved working in an organization as much as I love working within this organization and with within that team. The people I work alongside are just tremendous, top, top of the food chain, salt of the earth human beings. Okay. And so it's, it's important to you to have those people that maybe want to do beyond check-the-box security, right?
That's right. Yeah. Okay. Okay. Now, how did you fall into, you know, now SOC services?
Obviously, I think it can— it's a good starting point. As I tell my students, there's always a good starting point because You know, it's, it's, it's entry level, sometimes a little bit of a high turnover because, you know, people get in there, they get their foot in the door, and then they hopefully get promoted and they move on and they, they get that experience moving on. But I said the bad part about it is you are also exposed to pretty much everything negative into the company because You know, the SOC doesn't really see that, hey, great, this business services worked awesome. They only see, well, only when there's an issue against it. How would you respond to that?
How would you respond to that comment right there? You know, I would say that that's true, that a lot of what a SOC does is take a look at information that could be potentially malicious, perform some sort of analysis and decisioning, and actions to either determine that it's a false positive, which sometimes also can result in a corrective action, or if it's a true positive where, you know, other types of actions and mitigation, containment, et cetera, might be appropriate. In addition to that though, a lot of the work that the SOC does along with services such as adversary simulation and threat hunting is to actually prove or disprove an organization's, you know, exposure or vulnerability to certain types of TTPs and IOCs. And so I think not only does the SOC see some of those bad things, but the information that comes into the SOC and the partnership between the SOC and other areas of the organization, including other service areas, helps to verify and validate the company's posture against certain types of attacks, etc. So I think it's really kind of a double-edged sword in the SOC.
Yeah, but let's say, you know, and I'm going to put you in a situation here, hopefully not too uncomfortable. Sure. No, no, no. But let's say that the company's doing outstanding, right? And, and it's doing a great, great job.
It's got, you know, 100 businesses that are running great, but the SOC doesn't see that. Right? The stock doesn't see the successes of the company. How would you address it? Let's say that I'm one of your analysts, and for the last, you know, 6 months, year, whatever, all I'm doing is seeing everything that's bad.
I'm getting a little depressed, right? Because I don't see anything else. How would you address it? Have we sat down on a one-to-one? How would you address that?
That, that's a good question, because I don't believe that that would happen in Most organizations, certainly not in my organization, even though we have multiple clients we're providing services for and in a way have multiple SOCs, et cetera, I would say that that's a leadership and organizational type of function where really great communication about here are the wins from an organizational perspective, here are the things that we're building, here are the things that we're doing from an employee engagement standpoint, et cetera, et cetera. So really solid and regular communication on what's happening within the organization How we're pivoting, where we're finding success, and the things we're doing to take care of our folks and provide growth opportunities are all things that should come down from the greater organization and through leadership of the SOC. And so that's a conversation I typically wouldn't have with an analyst as far as I'm only seeing negative things. The other thing that I hear mostly from whether it's L1, L2, L3, IR, etc. Most folks, unless they decide to pivot into another career path, they love the idea of stopping the bad guy.
They love the idea of being able to do something meaningful and protect the organization through detailed analysis, being, you know, even thought leadership and, and, you know, thinking outside the box, um, and getting creative. And so I think that, uh, I don't really hear that from SOC analysts as far as they're just seeing the negative. I think it's more There's a pursuit of additional knowledge, a pursuit of additional ways to, like lenses to see problems through, because the adversaries are getting very, very creative and continue to, right? And I think that's something we talked about previously as far as that race condition between, you know, the SOC or, you know, whether it's from an infrastructure and engineering perspective or a process and procedure, GRC, etc. We're all trying to do things to protect our organizations.
We're moving at a certain speed, adversaries are moving and changing at a certain speed. And so I think that the SOC is part of that mechanism and they see the value in what they're doing in protecting the business. So for all the SOC managers, all the people that are in your position right now that are managing those SOCs, that would be the advice you would give to them is make sure that they're feeding that positive part of what the company is doing. But I think you also said a very important thing here with making sure that you're stopping those bad guys and showing that success rate. How would you roll that up to your upper management?
I mean, you know, if we say, okay, well, we stopped a bad guy, and they may say, oh great, right? What does that actually mean to me? How would that advice be, or maybe to your clients, right? Since you deal with multiple clients here. No, absolutely.
It's a great question. And, um, it's something that happens regularly. Typically what this looks like is we will find something that's not part of the basic blocking and tackling. Like there's things that are coming in, there's phishing emails, there's people clicking on links and resetting of credentials. And those are all kind of the basic blocking and tackling things that happen every day.
But sometimes through our analysis, we'll actually find systems that are almost like shadow IT, that the business or people who should be the owners of those systems don't even know that they're there. They have applications exposed to the internet with, you know, high-severity vulnerabilities. And these are like unknown types of things. And so we'll take that information and provide it to them along with a recommended course of action. And when that happens, clients regularly will come back and say, thank you so much for going beyond what is expected from the delivery of the services that we're partnering with you on.
Thank you for just being a great partner, right? And so that's typically that comes from the clients. And then when we, when we get that information from the clients, which is pretty regularly, that praise for our analysts and IR folks, that information gets shared throughout our organization. So we have something within our organization, a place where we provide kudos that everyone has access to and everyone's monitoring. And so throughout the organization, when those types of things happen, we give them credit.
We, you know, make that visible throughout the organization and, you know, help drive that confidence. So you, you combat the negativity by making sure that we get those kudos, those wins, those things that say, hey, you actually accomplished something in this case. Yeah, and something exceptional, something beyond just the basic blocking and tackling that most folks view as SOC services. And I think that's something different about, you know, the team here at MorganFranklin Cyber is that We're a value-based organization, and the value is based on what the need is and what the goals are and the outcomes are that the client is looking to achieve. And so if we can help them do that, even through unknown types of things, giving them visibility to things they didn't previously have visibility to, as the example I just mentioned, that's what we're all about.
That's that great partnership. Okay. Well, I mean, I do want to get back to something else that you said about the race conditions, but let's, let's hold off on that for right now. You've been doing this for decades. When you were, let's say, in high school or middle school, is that what you said?
Is that, say, you know what, I want to manage a SOC when I get up, when I grow up, I want to go out there and be this most exciting person. Is that where you go and started from? Well, this, this is dating myself a little bit, but personal computing wasn't really an affordable thing or really a thing at all when I was in high school. And So no, I actually thought growing up from 5th grade, I thought I was going to be a marine biologist until I got into my junior year of high school. And I really started digging into what does that mean?
And what does that path look like? And what are those opportunities? And I started talking to folks and realized that it's a, it's a very large population of folks vying for a very small number of roles. And, and so I, that just didn't seem like a great way to start. And so I decided to, to pivot into a few other things.
And yeah, and ultimately ended up, you know, through— it's interesting, I ended up working for a company called Kenetech Wind Power. I don't even know if they're still there or if they've been absorbed by another organization, but they were a wind turbine company. And so I worked for Kenetech Wind Power doing maintenance on the wind turbines and the down towers that had electronics and control systems and things like that. And that was really my first real exposure to technology. And I was just captivated.
I was done. And when that happened, I decided, okay, I'm going back to school and I need to learn more about this. It's so compelling and interesting. And that just led me through my journey of, you know, starting out. My first role was a LAN administrator, phone systems and wall fields, token ring, DECnet, AS/400s, Novell.
I was a Novell CNE way back in the day, right? And then what happened was I got into engineering and systems engineering and then security engineering. And then I was just so hungry that I just wanted to learn. I wanted to grow. And that's just been my journey.
And here I am, you know, leading an amazing team of professionals. But you went from wind power, right? And turbines, something obviously very, very physical. Yeah. Plus infrastructure related to SOC services that, I mean, you know, at a very high level, obviously there's some relationships there, but for probably everyone listening to this podcast, they're like, wait a minute, that's a bit of a stretch.
I mean, that's kind of almost 2 opposite ends of the spectrum. Yeah. No, it just got me interested in tech and got me back in school learning. And, and as I did that, that's when I started, I was really interested in networking. I was really interested in systems administration.
And then that just then is about, is when security was starting to take shape. If you remember back in the day, it wasn't even called, there wasn't IT security, there wasn't cyber. Sometimes they would be called tiger teams, but really what it was, was the principal level senior engineers that were the security folks, right? As that kind of initially involved. And so that's the space that I was in through system administration and networking.
And then I just, and then I realized I've had some great mentors. You know, if there's one thing that I would wanna say to the audience here is how important mentorship is. I have had a number of really, really talented and thoughtful leaders who mentored me and coached me and helped me see the value that I could bring and the paths that I could take to bring that value and to continue to learn and grow and, and build my career while building relationships and, and providing value to organizations. And so it's super, super important. Wow.
So, you know, of course, we have a lot of parallels within our brains. I grew up with— I didn't— I never dealt with DECNET, but I did a deal with Token Ring. I did deal with some of the first Ethernet, etc. Uh, so going— growing up with a lot of parallels. But I really want to focus on this last thing that you just said about the mentors.
I mean, I have a mentor, right? My mentor, uh, and I'll call him out here, his name's Andy Lewis. He's absolutely fabulous and fantastic person. He has guided me through my journey for the probably the last, oh, say 20 years, and really has given me advice not just on the positive but even as in smacking me in the face and saying, no, don't do that. You can't do that.
Right. How would— does somebody go around getting such a great person? I mean, I kind of fell into it a little bit with, you know, I guess maybe a happenstance meeting. But if you were actively looking for a mentor, for everyone that's out here, what would you do? That is a great question.
And the first thing that I would say is If you're employed and you have an organization, I would ask, ask your leaders, ask your HR folks, do we have a mentorship program within the organization? I think that's a really great place to start. There's always already some commonality there and a way to make an easy connection. Another way is going to user groups, local security conferences, things like that, and networking, meeting people, and then asking, just asking folks, Do you, do you mentor? And is that something that you do or that you have room for?
And I think that folks would be surprised at how often they would hear yes. Yes, I do that. Yes, I'm interested in it. And I would love to speak with you more about that type of thing. I find that I get a lot of mentorship opportunities for mentees through internship programs that I'm involved in.
And so that's another great way as part of an internship program, you know, what's the next step? Oh, is there, is there someone who would be willing to mentor me and help me continue on with my, my career. Um, so those are some of the high-level recommendations that, that I would make, but it's really all about networking, putting yourself out there, asking the question, being vulnerable. And, um, you know, more often than not, you're going to hear a yes. Yeah, well, that's where I think this is a great community.
And one of the things that, again, that I, I push over and over again is that the cybersecurity community is very, very giving. It is also very self-motivated. Yes. But it is also very giving, right? And you've got to go and put in the time.
If a mentor asks you to do something, they're not gonna follow up with you and they're not gonna tell you, okay, you know, it should really be your thing to come back forward. When do you stop being a mentor or having a mentor and then becoming a ment— or stop being a mentee and then become a mentor? Is there a threshold? Can you run those in parallel? What are your thoughts about that?
My encouragement would be, I think everyone to some degree, whether it's within a hobby or some other outside-of-work pursuit, or whether it's within the business, there's always someone, there's typically someone, unless you're at the very beginning of your career, that you have more insight, more knowledge, a broader view of things where you could share that with them. And so I would say, for most folks, it's both. Could benefit from both at the same time, being a mentor and being a mentee. I am both. I hope that I'm both for a very, very long time.
And I would encourage others to do the same. Yep. Yep. Well, I mean, I kind of in the same way. I mean, I do still have a mentor.
I still talk to Andy on a normal basis. Again, after 20 years of doing this, I wonder if he's ever going to get tired of me. Great. Uh, I don't actually have a whole lot of mentees, but that's because of my schedule and running OWASP and all this podcast and everything else. So, right.
Um, it's a great thing, but would you encourage other people in your position, whether they're a director, whether they're a VP, or even just a manager, would you go and say, be active to be a mentor? Yes.
I would say that mentors, from my vantage point, get just as much out of those conversations as do the mentees. There's a lot of mutual learning that happens. There's a lot of mutual help and assistance that happens as far as walking through and talking through certain ideas, certain options, in making introductions to folks, etc., etc. It's extremely fulfilling. And I mean, these folks typically become friends and you stay, even if you know, they grow and they decide even to pivot into another mentor because they're going in a different direction perhaps, and they're looking for a different style of mentorship or a type of mentorship.
You maintain those connections, you maintain those relationships, and I think that's what it's all about. Yeah. Well, that's great. I mean, again, I don't do a lot of— actually, I have been a mentor for a young lady here at my job for probably the last year, and she's actually at that point. Where she's learned quite a bit from me.
At least I hope she's learned quite a bit from me, and she's moved on to some, some other folks. And I think that's actually excellent. I love to see that progress moving on. Um, now we work a lot, right? We— this is not your typical 9 to 5, 5 days a week type of job or career field at all.
How do you deal with You know, do you do this 24/7/365? Do you look at threat actors all the time or you do other things? Yes. Like any hobbies? Okay.
All right. Yes. So, so you're right. And I appreciate you calling that out. I think a lot of folks in this industry would appreciate you calling that out, that, that it is not unlike some other professions, but certainly not like all professions where when you're needed is when you're needed.
And you show up when you need to show up, right? You show up for your team, you show up for your business, you show up for yourself. And so, that can create challenges. And so, I think being very structured in what your day looks like, there's only so many minutes in a day and some of that is going to be sleep. And so, what is it that you're looking to accomplish in any given day?
And then, how do you break those into components that can be moved? So, when something unexpected happens, there are certain— it's almost modular where you can kind of move things around on certain days and make sure that you're taking care of all those big boulders things, whether it's for your business or for your family. And then, you know, you're fitting everything else in the, you know, the best that you can. And part of that, part of those things that you need to fit in, it's a really great callout, is something personal, something— it could be reading, it could be music, but something outside of work is really, really key to— it gives fresh perspectives, helps you meet new people in some elements. It could be good for your mental and physical health.
It gives you opportunities to create new metaphors and new ways of storytelling as you learn things through the journey of certain hobbies and activities. And so I just think that enriching your life with additional people and hobbies and things like that is really, really positive and is reflective in how people perform. Folks that have hobbies, in my experience, typically tend to have higher job satisfaction. They have better, I'm going to say, work-life balance with air quotes here because they're finding a way to fit these personal things in that allow for additional personal enjoyment, and they're not just working all the time. So can I ask you, what are some of the things that you like to do?
Sure. You know, I moved to Colorado about 12 years ago, and When I first came here, I, of course, got into hiking and we love the outdoors. So we do a lot of camping and all those types of things. And then I got into mountain biking for several years and I did that. And then I recently, most recently, I still do that a little bit, just not as much as I have previously.
But now I've gotten into rucking, which, as you know, is carrying a backpack or a plated vest with additional weight. And then you go basically go on hikes and enjoy the outdoors and things. And it's absolutely fantastic. I absolutely love it. But what I probably get the most satisfaction from and where I spend most of my time and find the most value is actually cooking, believe it or not.
The creativity and the problem-solving sometimes, especially I do a lot of outdoor cooking, a lot of smoking and grilling and tabletop type things. And I typically do it for, you know, neighbors and family and things like that, not just myself. So, the whole act of being creative And also that kind of servant leadership, that kind of servant personality style is my style. And so being able to create something for someone, serve it to them, part, you know, talk with them about it, etc., is just something that's deeply fulfilling for me. And then I bring, I kind of bring that with me to work in that sense of for my clients, it's kind of the same thing.
I want to do something meaningful for them. I want to partner with them and talk with them and, and, uh, um, you know, have that relationship. Okay. Well, I want to get back to that, the cooking part here in a second. But the, the rooking part, of course, is, is rather interesting because I have to tell you, after my time in the Marine Corps, I never want to do that again.
I mean, I'm, I'm, you know, I, I, of course, I'm a very strong believer in once a Marine, always a Marine. But to put on a pack again and wanting to go run across, I'm like, no thank you. Uh, You know, I, I, I actually had some folks when I worked at a different company wanting me to do, what is it, the, uh, Running Man or like this mud thing and running through. I was like, I was watching the videos. I was like, okay, so you're, except for, with the exception of jumping through fire, I did all this.
We jumped off of cliffs. We did it except that we were in full boots and utes, right? Yeah. We were all in full, we, I was like, nope, don't wanna ever do that one again. But anyways.
Um, getting into the cooking part, right? You said cooking for your neighbors, so not just for yourself. That would help build that relationship outside. Now we're out there cooking. Let's say I happen to be your neighbor.
I said, hey Shane, that smells great. And you know, you invite me over, you give me some food. You talk about cybersecurity in that case? Not typically, actually, because what I want to do is I want to talk about the interests of others. So I typically don't bring my interests in unless there's an alignment.
So I wouldn't start with something like that. But if there was— we were talking about current events as an example, and someone said, hey, I wonder about this, and I had something to offer, I would certainly lean in and offer, you know, what I know and what I would recommend as far as it was appropriate for that conversation. But no, I actually enjoy talking about outside of work, lots of other things other than work, you know, talking about relationships and their hobbies and their families and and things like that. Do you ever bring— I mean, like, any funny stories? Anything, you know, well, you know, I burned up a crisp or thing or anything like that?
No? Any— anything funny? Or, um, specifically for cooking? No, just in general. I mean, if we were sitting in your backyard having a drink, eating some great food, what would you— how would you start that conversation?
Or No, that's really 2 separate things. I think the conversation would probably start with, you know, how are you doing? And can I offer you some sort of beverage? And, you know, et cetera, et cetera. But if someone asks me, like, for a funny story, one of the stories that I like to tell, and I won't name the organization, but it's one of the many healthcare organizations that I've worked for in the past.
As you know, I was on the client side, the buyer side for a long time before I transitioned into managed services. And there was a large healthcare organization that I was working for. And this is back in the Novell days, right? GroupWise email and all those types of things. And the data centers weren't, didn't have racks.
In most organizations, they were just these huge metal shelves. There would be like 3 or 4 layers and there'd be, you know, physical tower servers across the top, you know, all the way down. And so I was, I was doing some upgrades. And I was working at night, I was working that night, you know, doing the upgrades after hours. And these Compaq, old school Compaq physical servers, they had a power switch on the very bottom.
And so what I would do, I had like, you know, 8 or 10 servers that I was doing and I would type in a command to get that part of the update running. I'd move to the next one, move to the next one, move to the next one. And then I would push off the wall and my chair would slide all the way down across the raised floor. To the first one. Well, in one of those elements, I dragged my foot and turned off over half of the servers with my foot while they were in the middle of updating as I swung by because they were on the floor.
And so, of course, you know, a Benz from a, you know, Novell parlance. And so rebuilding all of those servers from backup and everything. And so I worked a solid 36 hours from from the start of that previous day through the next day until I had everything back up and running. But it was pretty funny and I had to laugh at myself as I realized what I did and turned all those servers off mid-update. But that's one of the funniest stories I like to tell.
So we can terrify you now by having wheels on chairs in a data center. Absolutely. Absolutely. We can terrify you. And physical boxes on the floor, right?
And physical boxes on the floor. I mean, I don't think you could still top buying where I turned off the Bank of Denver at 5 o'clock on a Friday. So yeah, I turned off all 3 branches early in my career by pulling a server off. And yeah, that— by the way, I was asked never to come back and work on them again. I wonder why, right?
That's how we— I mean, that's how we learn. That's how we grow, you know. Yep. Yep. And I think that for anyone that's made those type of mistakes, you can't let it defeat you.
You can't. You, you've gotta get back up. And I think that's part of why being in this industry is always getting back up and giving, you know, maybe being a mentor to people. You're gonna make mistakes. Things are going to happen.
Things are going to blow up. How would you respond to that? Like, you know, Put yourself now, let's say that I'm now the person that turned off all those servers. You are my boss. What would you say in that case, you know, to me?
Sure. So if this was like my first notification and you're working through it, my first, my first question would be, what help do you need? What can I do to help you? Because the, the, what we need to do is just focus on resolution of the issue. Like whatever was happening in a very, as positive a manner as we possibly can.
So what help do you need? Who can we bring in? You know, et cetera, et cetera. So that's really my first question. When you're in the thick of it, it's all about the team.
It's all about solving whatever challenge is in front of you first. And then I think after that, the question is, do we understand what happened?
Do we understand how to prevent it in the future? And how do we put things in place to make sure that we train and educate others to make sure that they don't make the same mistake? And then we just move on. We just move on to the next thing. So I would say have a short memory, you know, for those that, you know, love sports, that's a very common thing that you hear.
You're on the field and you make a mistake and, you know, have a short memory, get back on the field, get back in, you know, play your position and do what you do. And so that's, That's my style, and it's been pretty effective. I, I don't think that chastising or finger-pointing or in any way being negative, because we're human beings and things are going to happen. And I think what makes a difference is how we come together to solve that problem and build each other up rather than tear each other down. OK, so go ahead and start off with the positive part.
The, the issue part should come later. Let's, let's fix the problems first. Mm-hmm. Okay. Well, okay, then let's get into some other things here.
Let's take a little bit of a sharp turn here. You know, you're trying to do some constant improvement here, and I understand that you went to an artificial intelligence type of thing, or why don't you tell me about that? Sure. I, I did the MIT AI for Business Strategy course. Okay.
And it was great. I did that just this summer. And it was really fantastic and not from a nuts and bolts, hands-on keyboard architecture and engineering of LLMs and SLMs and things like that. It was more, how do you take the potential of AI and evaluate use cases within your organization and determine what is a good use case and what isn't a good use case? And then how do you pursue that?
And when do you say, we now realize actually it wasn't as good of a use case as we thought? Et cetera, et cetera. And what are the types of data and metrics and outcomes and things that you can either declare and/or measure over time to be successful in the implementation of AI? And that's really not specific to cybersecurity. That's really any business use case.
So it was a fascinating— I love being around folks that know things that I don't. And so I'm a lifetime learner. And so this was a really great opportunity to meet and hear from folks that have experience. You know, AI has been around for a long time. There are companies that have been doing significant AI work in the supply chain space since 2017.
I had no idea. And there were a lot of lessons learned through those exercises, through those companies that led to what like companies like OpenAI and Anthropic and others are doing now. We're kind of on the backs of the lessons learned from some of those other organizations. And so just kind of learning about some of that history and how it applies and how some of those things apply to business and how to make good decisions on, you know, selection, governance, implementation, monitoring, and management of AI models and use cases is something that was really terrific. Well, that's great.
I mean, and I have to tell you, I definitely know that AI has been around for a long time. Uh, I used to work for a company called Inflow, and one of the, uh, one of the directors there, he was actually a doctor, was actually working on the very beginnings of AI. He was trying to tell me how, you know, do you get recognized— a computer to recognize that a dog's a dog, right? And then the different variations. And that was actually back though in 1999 was when he was starting that.
Um, and he's still around, I believe. Uh, he's absolutely amazing. Uh, wish I could remember his name. I know his first name was Yusuf. I can't remember his last name though, but if he hears this, he'll probably ping me, or hopefully he'll ping me.
Okay, so, uh, we've got, you know, we're coming kind of short on our time here, but let's talk before we go to my final question here. Let's talk about AI and its effects on society these days. Um, and Or I guess maybe the effects of specifically our industry. What do you think? I mean, is AI going to take over the world?
I mean, is it, you know, because this is pretty much the conversation I have at every conference I get. What is AI going to do to us? And since you are obviously now an expert in it, right? Well, no, no, I would not say I'm an expert. What I would say, though, is that I'm a bit better educated about what it is and how it can be applied and where it should be applied first as a priority.
But, you know, you're right. There's a lot of conversation going on about what does AI mean? What does it look like, et cetera? And, you know, I would say that most of us agree that we're moving a little fast. You know, a lot of folks are worried that they're gonna be, you know, the last to the party and that, you know, their competitors or or what have you are going to, you know, realize the benefits of AI before they do and et cetera.
So everybody kind of wants to not be left behind, right? And which is understandable, right? With any type of major innovation, you know, everyone wants to capitalize on it. If you can find a way to decrease cost, increase shareholder value, or, you know, EBITDA or whatever it might be, everyone's looking to do that. The challenge, I think, is that we're moving too fast.
We're just now, I think, starting to really understand the types of governance and management and monitoring and types of things that we should test and verify. I mean, forget about hallucinations and just, and it doesn't have to be an adversary. It could just be someone, you know, using a chatbot within some business that then somehow gets access to information that they shouldn't have unintentionally or intentionally. And I think that there's, there's so many scenarios where that could play out. And we're just now learning how to accommodate for that and how to safely build, map, test, validate these models, especially when we're dealing with, you know, you know, high, high areas of sensitive information.
I think One of the more interesting conversations that I've been having lately is how AI can help in the OT environments, given that they're often segmented off from everything else in the organization. They don't have internet access. They have their own, you know, identity and access management solutions. They have their own processes.
And oftentimes, you know, physical access is required to do a lot of things. And, you know, how do you apply AI there? How do you safely do that and allow for that to happen? Do you have to build your own models and have them within that segmented environment? Is there a way to do it safely where it can be outside of that environment?
Cloud becomes a huge concern with those environments, you know, being so segmented. So I think those are really interesting conversations that I'm having with folks that know far more about OT than I do that are talking about, the possibilities and the risks. And again, it's unique because those aren't internet-connected systems, right? So, so yeah, you know, I don't think it's going to take over the world. I do think that it is going to continue being an amazing tool for human beings to use to complement what they currently do, as well as realize successes that we couldn't do without it, right, in the future.
And so I think I'm really excited to see what the future holds. And I think we're just starting this journey and it's going to be a fun one. Awesome. Well, of course, as we know, though, also AI gets it wrong. Shane and I was actually talking before the recording and it said that he had a criminology degree.
And I approached Shane, I'm like, you have a criminology degree? And I'm like, no, I don't. Oh, no. All right. We are again coming close to the end of the time here.
So I always have the same question. You know, what is the greatest challenge for security today and how you might address it? Now, we're not saying solve it. We're just saying, how do we address it? And we had talked a little bit earlier about race conditions.
Do you want to kind of build on that? Sure. So this is my, my lens, my, my viewpoint. And there's a lot of accurate viewpoints out there. For, for mine, I think the main challenge is the same challenge we've had for a very, very long time, which is this race condition between how we manage our organizations, how we measure our third parties, how we secure systems, etc., etc.
That race condition of defenses and management, safe management of data and systems, and the adversaries who are trying to get access, you know, to that data and maybe compromise those systems, etc. And so there's this race condition of And it's happening with AI right now where the adversaries are using AI and, you know, we've all seen phishing emails were very, very good very quickly once generative AI was available. And so I think there's this race condition and the challenge with that race condition is it's costly. And so I think our challenge is how do we figure out how to provide an effective, strategy and solutions to address that race condition that organizations can afford, right? And, you know, not every organization's risk is the same.
Not every organization's, you know, attack surface is the same. And so it can't be a black box that everything has to fit into. And I think that through certain partnerships and models that come from some of the security product companies and things like that. I think that there are a lot of companies that are doing a pretty good job, but those are usually companies that are pretty large and have the budget to try out some things, have teams or partners that can help them solve those problems. But we haven't necessarily done it through large enterprise all the way down through small and medium business.
And so, I think that there's an opportunity to find a way to help all organizations get to where they need to be At a cost that they can actually afford, that's reasonable and they can afford. Yeah, well, I mean, as you were talking through that, that was the first thing that popped into my head when the race condition is how do we afford this? And right, always goes back to budget, not just within cybersecurity, but within everything that we do, of course. Yeah. Okay.
Yeah. And I do think that AI in time will help us with that, right? The challenge is that the adversaries also have it. And we'll continue to have it. And so, but I do think that the speed and accuracy at which we're able to make decisions and take corrective action is going to continue to decrease.
That time will decrease. And so AI, I think, is going to help us with that in a number of areas. But the problem still doesn't go away. You know, right now, no one can tell me that I've asked and I can't project what AI will cost If you, whether you build it yourself, you know, the power consumption, all of the things, the infrastructure, whether you do it yourself or whether you're providing it as a service to clients, what is that gonna cost in 5 years? Is it gonna be cost-effective?
Is the cost gonna go down or is it gonna go up? And, you know, how does that affect this equation where we're trying to find a way to solve this problem at a reasonable cost with high value to the clients? Well, of course, um, you know, I think there are other people outside of the Colorado area that are listening to this podcast, but they had talked about that this morning on the news, that they're building an AI-specific data center. And I forgot where, somewhere in the Denver area. And of course, the neighbors are going to have issues with it because of the power consumption, the water consumption too, to cool down these systems.
But then they're going to say, well, it's going to bring a bunch of jobs in, right? And, and that's the immediate, uh, benefit from it. But what's the 5-year benefit of that? What's the 10-year benefit of that? And I agree with you, nobody really quite knows yet what's going to happen.
Yeah, it's interesting though. There's— I heard something that was so insightful as part of that MIT course that we mentioned earlier. And it was, it's easy to predict the future. It's not easy to predict when something will occur in the future. And so we know the things that are going to happen with AI.
We know the things that are gonna happen with robotics. We know the things that will happen even sociologically. We can understand how we're evolving and how things are transitioning, but we don't know when there's gonna be something that accelerates that or decelerates it. And so it's kind of a waiting game. And so I just thought that was really, really insightful.
And like, that's why it's gonna be a fun journey, especially with AI. Awesome. Well, I think that was a great final thought. For our audience, I want to say thank you for your time. If they wanted to connect to you, what's the best way to do that?
Through LinkedIn? The best way to connect to me is on LinkedIn. Yes. Hit me up on LinkedIn, Shane Cox at MorganFranklin Cyber. And, you know, I would also say that if you are especially someone who's breaking into the field and you're looking for someone to talk to, you're looking for someone to kind of help guide you, maybe make an introduction, please reach out to me.
I am happy to help. Awesome, awesome. Well, again, my name is Frank. I am Frank Victory out on LinkedIn. I also, of course, run the— or help run the Denver OWASP Foundation along, and the Denver and Boulder OWASP Foundations are going to partner together for probably what's the 4th or 5th time now to run SnowFROC.
So snowfroc.com, and that's snowfroc.com. We're gonna have a conference up there. Our call for training is now open, and we will have our call papers open by the time this podcast is published. Uh, again, thank you so much for— Shane, for everything. And my pleasure.
I hope to talk to you in the future. We certainly will. You have a great day. Have a great day, everyone. Thank you.
Thank you, everyone.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.