Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 271 for the, uh, the month of February. It's February 3rd, Alex, happy 8th birthday.
Thanks, Robb. I've always wanted to turn 8. Yeah. So the podcast turns 8 this month. We, we love it.
You know, 271 episodes over 8 years. Yeah, we did weekly for a while. Right. But now we're, now we're cruising pretty consistently with monthly and hopefully we, you know, maybe we'll see 10 years in a couple of years. I'm sure we'll get there.
8 seems like a lot, but obviously things are, you know, moving a little slower now that we're monthly. Hey, while we're remembering what it is like to run a podcast, we have some housekeeping. We do have a Slack channel where we have vibrant conversations, including this week, my favorite, where I said, hey everyone, what's your favorite book recommendation? Because I want more book recommendations. So if you're listening and you're not in there, join, go into the recommendations channel and give me your book recommendation.
How do you join? You go to the website, there's a form you can fill out and we will get you added to the Slack workspace. Really simple. All you have to do is be in Colorado and have an interest in security. The website is colorado-security.com.
That is the website. Thank you, Robb. That's an important piece. Also, while you're there, we do have a mailing list. You can sign up for that as well.
You'll get notes about the show notes for the podcast, maybe a little other note here or there, but that's mostly what you'll get. We'd also love it if you signed up on your favorite podcast player and subscribed and then rated us to tell everybody how great this podcast is. We'd love that. We appreciate it if you want to Also support us financially. We have a Patreon campaign.
You can go to the website to find that. Big thanks to our current patrons. We appreciate you. Keep us going, help fund the podcast and also our picnic in the summers and the other events that we do. We have some, some other sponsors and, you know, mentioning last month we mentioned Armistead joined us.
And as of this month, we have a new one. Zscaler is a new annual sponsor for 2025. So thank you very much to Armistead and Zscaler for supporting our Security Leader efforts. All right. Let's jump over to the news.
Alex, where would you guess before, before having read the articles, where would you have guessed the coldest place in the universe is? Uranus. Wow. That's, that's, that's a good one. I was gonna say Pluto.
Okay, because it's not a planet, but it's really far out there. But no, it's much closer to us. It's actually in Golden. Oh, really? Really?
Where is it, Robb? The School of Mines has built a refrigeration system that gets to within a few thousandth of a degree of absolute zero. That is pretty cool. Um, pretty cold too. It is even— it's even more than cool.
Uh, yeah, so there's, there's, uh, students there as well as, uh, professors working on a project to develop this for, uh, for quantum computing. Yeah. Um, one of the things with quantum computing is the, the warmer that it gets, the more error that is introduced into the quantum computing. So you want to get it as cold as possible to make those, uh, qubits their work. Yeah.
At first when I read it, I, I just figured, oh, they, they just did this because making something close to absolute zero is cool. But, but no, no, it's not cool. It's cold. It's practical. It's very practical.
And, uh, and, uh, I, I, I would suggest they— there's a picture in the, the article that shows what this system looks like, and it looks like a, like a, a case, like a, like a server rack case, like, like a big tall one where you could put additional racks in tight and servers inside of, which makes perfect sense since they're planning to make it be built for quantum computers to go inside. Yeah. And at least once in the article, they call it a refrigerator. Yeah. And so, you know, that's kind of how I think of it.
They also mentioned that this particular one that they've built already has a home. It's going to go off to a company that is inevitably going to use it for quantum computing in Canada. Right. In Canada. Yeah.
But they are also building a bunch of other of these that are going to be used by other folks for quantum computing. And if you want one in your house, it's possible that it will be worth more than your house. They're selling them for about $800,000. And you'll be able to get your, your ice for your drinks very, very cold. Yes.
You might want to let it sit out a little bit before you try and drink that. Might have an issue if you don't. All right. Go ahead. Moving on.
Next article, some exciting travel news. I think we have a particular fondness for travel news on this podcast, even though it's not technology related necessarily. But soon we will have the world's largest airliner that will be landing as part of regular flights at DIA. Yeah, Lufthansa is gonna be bringing— oh, what's it called— the A380 super jumbo jet. Super jumbo.
It's gonna be flying daily between Denver and Munich. And that's a route that I take on, you know, not like all the time, but a regular basis to— and I'm excited to get in the biggest plane. One of the things I love about the bigger planes is the headroom you get. And when you get away from the window, they're significantly taller. Yeah.
And having that extra space makes it feel less, you know, less like a coffin for a, for a 9-hour flight. And not that it will matter to me, but this is also because it's so big. One of those ones where you have your first class and business class on an upper level. So it's not just, you know, separating front to back from the rich people to the cattle class. You get to actually go upstairs and be separated from them.
Yeah, that sounds great. Yeah. One interesting fact that this article mentioned was this. Once it comes flying here, it will not be the first time that one of these superjets has ever been to Denver, but it's the first time it's ever been scheduled to Denver. There was a diversion once previously that had one of these super, super jumbo jets land here.
But this will be the first time that a scheduled flight is in or out of Denver with one of these. And in case you're wondering, it will go in and out of Concourse A, which is of course where they do international flights from. So, and also United. Yeah. All right.
So next we have the update on Boom Supersonic. We've talked about them in the past. They're trying to build supersonic passenger commercial flights, you know, mostly across the oceans. And they had a big breakthrough in the last week or last couple of weeks. Yeah, so they have built their test plane.
This is not the production model. And they were able to, to break the sound barrier using this plane. I think they said they did it 3 times as part of a test flight. So pretty exciting. Yeah.
Not only did they, you know, did they accomplish this, which, you know, maybe seems like a big deal. I didn't realize this is the first ever commercially, you know, non-government funded plane to break through that. Yeah, this is You know, the Concorde that was, you know, the supersonic jet between America and Europe, what, 20 years ago? That was funded by the governments of France and the UK. This is, you know, obviously completely public— private sector.
And they're looking to have— what do they call it? The Overture. The Overture is going to be their plane. And they say that they'll be ready to go fly across the ocean in about 4 years. Yeah.
So not too far off. No. So, uh, continue to make good steps forward. I'm looking forward to that. It'll be pretty cool to be able to fly at supersonic speed sometime in the future.
All right. Lumen Technologies, you know, formerly CenturyLink, you know, combination of— I mean, lots of things, right, that have combined into what is now Lumen over the years. They announced that they have closed their 55-acre suburban campus up in North Denver and moved all of their employees either to remote or into the Denver offices? Yeah. So there were a number of different campuses around the Denver metro area, including one down here by us in Littleton.
And now this one up north that they are— they're closing. They're moving everyone who's going to be in an office into a couple of offices that they have near downtown Denver. Otherwise, people get to work remote. So getting rid of the real estate, making some cash off of it and Uh, hopefully means business operations are better. And so that, that northern Broomfield office that they're closing was the headquarters of Level 3.
Uh, so, you know, I've known a number of people. I think sometime listener, avid listener Mike Benjamin, um, he was a Level 3 employee, and I know we have others there as well. Um, so that office is no more, and I assume some other great companies will move into those spaces. All right, uh, moving on to our next story, which is probably The, uh, the most intriguing story of the, of the month. Uh, this is about a company that's been going through some internal struggles that have now become public.
Yeah, I think we should just throw the word allegedly out here to begin because we don't know anything about anything. Um, if you're going to read one story out of the, the show notes this, this month, this is it. This is the one. Uh, so Denver Post story, there's an MSP called Lucid Point that handles cloud consulting and computing hardware for business clients. Um, they had a couple of partners who founded it.
They, they, uh, uh, they didn't equally own it. Um, and then there's a lot of intrigue between the two. These are former NetApp employees who built this MSP. Um, as you look at basically one of them was forced out by, by the other, allegedly, allegedly was forced out by the other. Um, and the, the one who was forced out somehow remained, maintained access into the environment allegedly and started doing some serious snooping.
Uh, in addition to that, uh, there was— there are now charges by the, uh, the former partner that was ousted that, uh, the, the majority partner was trying to move assets to another company and then, you know, essentially make this company worthless. So the, the minority share that the other partner had would, you know, would basically just go away and then they'd move to this other company. So it's, it's lots of intrigue back and forth. Yeah, I don't think we're doing a great job doing it justice. And people should take the, take the 5 minutes, read the article, pop your popcorn first, and then chat with us on Slack about what you think about this allegedly interesting story.
If you want to hear some more things that are allegedly going to come true— oh, nice segue— we have a predictions article. Last month, we talked about that we hadn't seen any predictions articles. This, I think, is the first and only one that we will have as part of the podcast. In the end-beginning of the year cycle. So this is a Ping Identity blog about predictions for IAM leaders in 2025.
Yeah, so they, they go through, you know, at the high-level category, just ramp through their predictions. Verification through digital credentials will transform traditional authentication. Decentralized identity adoption will continue to gain momentum. Trust is not optional. Not sure that that's a prediction.
Um, AI and verifiable credentials will reshape payments. Deepfakes and AI will drive trust nothing, verify everything. And finally, digital trust will be redefined. Actually, there's one more. Verification will play a critical role in fraud prevention.
Yeah. So I think you and I, as we, we, we talked about this before the show, like, gosh, it sure feels like more like 2 predictions here instead of 6. Yeah, so really, I mean, a lot of this is all revolving around AI and deepfakes and other things like that, but really it's we need more, better verification because we can trust less. And then the second thing is that Ping Identity really feels like distributed digital identity is the future and that it's coming. Yeah, I, you know, they've been talking about digital wallets and the ability to own your own identity for quite a while.
You know, I was there until, what, 2021, and we'd been talking about it for a while before I left. Um, I think that they see this as the future, and I think it's part of the future. Is it really 2025? I, I mean, I personally haven't seen the signs that this is the year that, that it makes significant momentum. Um, but you know, the, the things that were happening with, with AI accelerating things, the, you know, the, the success of cryptocurrencies pushes us in that direction.
And makes it easier so when it's time, it'll go faster. So, you know, maybe, and being ready is never a bad idea. Yeah. Yeah. And we'll see.
Maybe they have it in 2025. Maybe not. That's what predictions are about. All right. Moving on to our next story.
This is a blog from Optiv talking about AI security and governance, how you can build a practical path to protection. Yeah, they do a good job, I think, laying out the 3 key things that you need in order to have a good plan. Acceptable use and data protection guidelines, AI risk management practices, and incident response and reporting. Now, all 3 of those are massive, but it's, it's a good framework to start with. Yeah, I think if you, if you don't have a good AI governance process in place, which includes security and privacy implications, then you should definitely put one in place.
And reading this article is going to give you a head start of areas you should think about. Um, you know, obviously checking with your, uh, your legal counsel and other things like that to make sure you're, you're checking the boxes on, uh, on what, what you're putting in your policies and your governance framework. So that's a nice practical article this week. We have another really practical one from the National Cybersecurity Center down in Colorado Springs. Um, this is— this one is headlined How to Protect Your Child's Data After a Breach.
And as it sounds like, It tells you how to protect your child's data after a breach. Yeah, some very simple steps here. Hopefully it's something that a child of yours will not have to go through. But first, they suggest you understand what was compromised, which obviously that is important. Change any passwords for that child.
Enable 2-factor authentication if it's not already. Freeze your, your child's credit report, which is something you should just do generally anyway. If someone's a minor, they don't need to have access to their credit report. And, uh, finally, uh, just monitor their accounts, uh, through credit agencies. You can usually set this up, um, as the parent through some of the credit monitoring services.
So this is one that I think is worth, uh, you take, take a moment to bookmark this, to share with people who you come across in the future who say, what do I do? This just happened to me. You know, it's a nice resource to be able to hand out. All right, our final story is, uh, is is a blog from Red Canary, one of their, their kind of typical great technical blogs. Um, this one is, is called Tangerine Turkey, and it's about one of their threat actors that they've run across.
Um, they note that they called it Tangerine Turkey because it was discovered in November of 2024, and you know, that's, that's turkey time. Yeah, that is definitely turkey time. Um, I want to know why tangerine. Maybe we're running out of more primary colors, but that That's okay. You can't, you can't keep reusing things and they can't use Red, right?
Red's pretty well taken. That is very true. Uh, in any case, this is a campaign where, uh, the attackers are spreading cryptocurrency miners through VBScript. Uh, so they go into depth here on, uh, how the campaign works and what you should look for and how to mitigate these potential, uh, issues. Yeah.
If you're running a security operations center, if you do your own MDR, uh, this is exactly the kind of content that can help make you successful. Thank you to Red Canary for sharing it. Awesome. All right, uh, that is all of the news that we have. Why don't we move over to our events?
Uh, lots of great events coming up. Um, this coming week, uh, the first Denver version of the Wild West Hacking Fest is happening February 4th through the 7th. Uh, I believe that's at the convention center. If you had to go all the way to South Dakota to attend Wild West Hacking Fest in the past, you're a sucker. Because now it's here.
Those of us who have been just lazily waiting for it to come to us. Exactly. And now I'm hoping that the same thing happens for ShmooCon and all the other ones that I've been, you know, too, too much of a slacker to make my way to. Anyway, obviously joking aside, really cool that, uh, that they have chosen— Black Hills has chosen to bring this into Denver. And I, you know, I know several of the folks from my team are gonna be there and hopefully you guys make it as well.
All right. Oh yeah. Next. Um, the, the 5th. We have an ISSA chapter meeting.
Their privacy special interest group is meeting. The topic is, hey Siri, what should we get out of Apple's $30 or $95 million snooping settlement? All right. On the 12th, ISSA Denver is also doing an event, Cybersecurity Insights from Denver's Top CISOs. So that's their chapter meeting.
Yeah, it's their chapter meeting and it's their, their annual CISO panel that they do on the 18th. Let's Talk Software Security is going to talk about, are security breaches evidence of systemic failures? Also on the 18th, ISSA Colorado Springs is doing their chapter open house. On the 20th, ISACA Denver, it has a joint meeting with IIA. On the 26th, ISSA Denver is doing, uh, an AI and machine learning special interest group, AI Revolution Blueprint: Mastering the Art of Strategy and Governance from Ground Zero Workshop.
Usually we talk about, um, the longest title in our job section. This is the longest title in our event section for sure. I think actually this is being led by Rock Lambros, if I— I think you're right. I think it is Rock, if I'm not, uh, mistaken. All right, last event in February.
ISSA Pikes Peak is doing their chapter meeting on the 26th. We'll talk about March in March. Yes. And hey, you know, usually we do a job section. You know, as we've reached our 8th anniversary, we sat and said, hey, let's think about what, what are we doing on the podcast that's adding value and what maybe isn't.
And, you know, we thought 10 random jobs maybe wasn't adding as much value as we wanted. Yeah. So it's not that we're gonna rethink whether we want to, whether we want to come back with just some especially interesting jobs, or if you guys reach out to us and let us know what you want, maybe we'll listen to that. But for now, we'll, we're thinking about it. I think also when we were doing weekly podcasts, it made more sense to have jobs listed.
Now when we're doing this once a month, Yeah, maybe, maybe not so much. All right. Well, with that, we do have an interview and you already spoke the magic name. Rock Lambros is our interview guest this week. Rock is a longtime member of the community, a personal friend of ours.
He's currently the— he is the— his company is Rock Cyber. He's previous to that ran security at MarkWest Energy and he was over at PayPal or eBay. Uh, I think it was eBay. Yeah, one of those, which I know they, they were one and the same for a while. I don't remember which one for sure, but, but he was over there.
Uh, Rock is a fantastic member of the community, and we're looking forward to hearing him talk to Frank here right now. I'm excited about it. All right, we'll talk to you guys in March. Thanks, Robb.
Hi, this is Dimitri Rouskas, CTO at CR3 Markets Inc. Welcome to Colorado Security, everybody, for Colorado Security Security professionals by Colorado Security Professionals. Well, good morning, good afternoon, and good evening, Colorado Equal Security. My name is Frank. I am the guest host on this wonderful podcast.
It is February 2025, the month of love, and I— it's absolutely appropriate because I love my next guest. Uh, we call him Rock. Rock, how are you today? I'm doing great, Frank, thanks. How you doing?
Oh, outstanding. Uh, in case you have been living under a rock, you know, pun intended, uh, Rock is an icon here in Colorado. He's a co-author of The CISO Evolution: Business Knowledge for Cybersecurity Executives. I have read the book. I loved it as soon as I got it and it was available.
I actually even had it on pre-order. Um, Rock is also a big thing, uh, big on AI governance, right? Um, he thinks it's a natural extension to a cybersecurity background, right? Uh, some of us actually think that he is somewhat of an AI, but we'll discover that here in the— within the next hour. Okay.
And, uh, on a personal note, right, I think that he should be highly admired. He is a kidney transplant survivor, right? So we'll talk about that and everything else in the podcast. Again, Rock, how are you? Doing great.
Thanks. How you doing? Yeah, the month of love.
Yeah, I can't believe January's already over. January's already over. It's already 2025. Wow. Right.
I'm still writing '24 on things when I actually write anymore. Right? You mean like on that paper check, right? As you cash it at the grocery store? All right.
Well, before we get started with the official broadcast, podcast, let's go ahead and give you an icebreaker. Uh, as always, uh, Rock is not aware of the icebreaker I'm going to give him because I'd like to have the most fun that way, right? But let's have actually a little more fun. Rock, if you were a World Wrestling Federation, uh, wrestler, what would your entrance music be? Ace of Spades, Motorhead.
I don't even have to think about that. What? Okay, so you're gonna strut yourself down to Ace of Spades and Motorhead. Why specifically on that one? Well, I grew up in Vegas, right?
So, so there's a, a natural endearment— endearance to me there. And, uh, just the energy of the song. And, and the reason why this came top of mind, because, um, I have a good friend Laz, and we spent a lot of time at Rockies baseball games this summer. And, you know, we would have this conversation of what would your, uh, walk-up music be to the bat. And that's what I came up with after a lot of deliberation, actually.
So that's why that was top of mind. Gotcha, gotcha, man. I haven't talked to Laz in a long time. So, all right, well, uh, let's go ahead and dive into— let's start with that last point, if you're okay with it. Uh, I know that you were having some health issues like what, last year or the year before?
Last couple. Yeah. Yeah. And I was actually unaware. I wanted to respect your privacy.
Didn't want to really ask. But of course, now that you have— we have it on the podcast, a kidney transplant survivor. What was that like? Sucked. I'm not— I'm not— I'm not going to paint this all as rainbows and unicorns or that I always had a positive outlook.
And I kind of want to be clear, right? Like, I didn't make it public on LinkedIn late last year. As like a— because I'm any sort of quote-unquote survivor or anything like that, right? But I do think it's really important that we focus on— we're so like, we're so much— our heads are so much in our everyday lives. We're talking about cyber resilience, operational resilience, and frankly, none of that matters unless we build our human resilience.
And man, I was, you know, I had some pretty thick skin going into the process, and It just, you know, what are the alternatives, right? You're not resilient or you die, right? Or you're resilient or you die, frankly, right? That those were the alternatives. And I think we've lost a lot of that, not to get too philosophical, but frankly, I think we've lost a lot of that since COVID right?
Like, you know, remote, you know, work from home, you know, kind of like disconnect from humans. All that kind of stuff has kind of polished us up maybe a little bit too much. And I'm seeing that in the workplace, right? Like, people are taking things way too personally. Um, we're ghosting people.
We've lost societal norms. Um, it's just, you know, we kind of need to, you know, build up that callus again, I feel like. So you're saying that people are too sensitive, or are you saying that we aren't taking care of our own health? I mean, I think we touched on a couple of different points. Well, first of all, our health, first and foremost.
Guilty as charged, right? I didn't end up needing a transplant overnight. This was a, this was a life's worth of bad life decisions by Rock. Right? So first and foremost, so it's taking that accountability.
Second of all, yeah, we just built, we, you know, we need to build up a thick skin. We've lost the ability to have Uh, civil discourse, right? To be able to agree with, disagree with others. And I say we in the most general sense of the term, right? You just kind of see what's out there on social media and everything.
And, um, and I think that's because we've been hiding behind screens for so long that it's almost become easier to do so. Having said that, I hate return to, return to office policies. I think it's the most asinine thing on the planet. So I think 2 things can be true at once in this, in this regard. Okay.
Well, I think that's, that's actually the big thing now, right? I'm actually in my office right now, and I know that there's a lot of companies that are pushing back that Bank of America has 3 days. A couple other places have 4 days. Yeah. Amazon's a full 5 here in downtown Denver.
Okay, so Amazon's a full 5. And, you know, why, why are you against that? I guess I have been more productive working from home than I have ever been in my entire career. That's because of lack of commute time, right? I'm able to sit down and focus.
I don't have, you know, the only drive-bys I get are from my wife, you know, that sort of stuff. However, I really do miss face-to-face interaction. That's why I try and be active in the community. I try and get out to lunches, right? I get out and see people.
I'm— I fully 100% recognize that I am blessed to be able to be in the role that I'm in, to be able to do so, right? To be able to kind of balance both those worlds. Not everybody's in the same position. But I think if you look across the board at the data that's available, right, people are more productive. You know, they lose a lot of productivity going to and from the office, the stresses of the commute.
Uh, gas mileage, parking, um, you know, that's, that's time that you could be spending at the gym, right? That's time that you could be spending with your family. Um, you know, I, you know, when I was back in my, you know, my, my CISO role, my security leadership role, you know, you're, you're, you're fighting, and I mean fighting in like a tongue-in-cheek type of sense, fighting all day at the office, right? Struggling all day at the office. You have to be quote unquote on all day at the office.
Then you spend an hour in traffic on the way home, and then you get home to your family and you're wiped, right? Like, how much, how much energy do you have to give back to them after the whole day, right? And I don't have kids, right? It's me and my wife, and it was my mom with us for a while too, right? So I, I, I couldn't imagine, right, all those— well, I mean, I, I've had to return to the office And I've taken the approach of I'm gonna make the best of it.
I'm gonna be as positive as I can. Yeah. And, and the place that I work, they, you know, obviously I have to drive there. There's some mileage, but they've made the parking structure very nice. It's very nice building.
And I'm putting my best foot forward, right? I'm putting my best foot forward and I'm saying, look, I'm getting that face-to-face time. It's a lot easier, right, to collaborate with people if instead of over a screen and losing that personal touch, I literally can tap them on the shoulder and say, hey, hello, how are you? Right? Um, and sometimes we got into— and we could talk about stuff that, because of our limited time on screen, we talk about things that we wouldn't talk about.
So for example, we were talking about the Super Bowl weekend with one of my co-workers this morning. So There are some advantages to that. Yeah. But I also know that it's, it's kind of strange. One of my friends works at Microsoft and she was telling me they actually closed the Microsoft office in DTC and set everybody remote.
Right. Oh, really? I didn't know that. Like it's closed now as we speak. I didn't know that.
As far as I know, it's closed now, if, if not soon. But she was telling me, yeah, cuz they're all remote. They are all, they barely spend any time in the office because they're spending time with their customers. What do you think about that? I mean, do you think that is a good culture, bad culture?
Give me some thoughts on that. It is. I don't want to diminish— I guess my, I guess my point is I am very anti-forced remote-to-office policies, right? I, I value the human interaction immensely, right? I'm not saying we can hide behind screens the rest of our lives, but, you know, we're humans.
Right? We have, we have stuff going on outside of the office. Most of us have kids, we have families, we have— I've got a 2-and-a-half-year-old house that acts like a 100-year-old house, right? Like, we have all that stuff that comes up in our lives. And, um, just being able to have the flexibility to be able to handle that and be treated as adults and know that, you know, be held accountable that our work's still getting done, and it could be done without being, you know, kind of looked over by the overlords inside of Office.
And what I see often enough is when I actually do go onto a client site is people are in the office and still joining meetings remotely from their desks. Yeah, right. So it's like, what kind of value are we getting there? Or, you know, I have one client that have a return to office policy, forced return to office policy. Like there's literally one member of the security team in this office.
They're on Zooms all day long. Regardless, with her team across the country. So what difference is it if they're there or home, right? So I think we just have to have some sanity. What's that?
No, I agree with that. I worked for a financial company and that was my— the exact thing that you described. My entire team was in Phoenix. I was here in Denver. What was the difference whether I was in the office or not, right?
But, you know, let's— I mean, I think we can have this debate on forever and ever, um, but as we're talking about this Let's talk, I think, about your specialty. I obviously, I follow you on LinkedIn. I think you're getting a very, very big, uh, lot of reactions, maybe let's put that on LinkedIn, in AI governance and what AI is doing for you, whether it should be allowed inside the building or inside the company at all. What do you think about AI and the different types of AI? Are they changing?
I mean, obviously these, uh, what, large language models, these LLMs, Uh, differ a little bit, but in general, what do you think?
If you— okay, what happened? I'll start with this. What happened when we started rolling out the cloud and we told our companies and our business and our user bases, no, you will not use the cloud? Yeah, I remember that because I remember that when we were doing that with Active Directory, oh, only put one system in the cloud, or You must maintain a physical presence of 30% on-prem because we can't trust the cloud. Yeah.
And what happens? And now we have companies where they have zero presence, they have zero physical presence. And in fact, most companies are trying to get rid of their physical hardware whenever possible. Yeah. But, but what happened in the interim?
People went around your controls and shadow IT sprung up, right? And now we spent years I mean, we have an entire, the whole CASB market grew out of that, right? Grew out of the simple fact that we told people no. We need that technology regardless, but that was effectively what allowed CASB to go to market is get ahold of your shadow IT. 'Cause you have, 'cause it got completely outta control.
And I think that's what's happening with AI. If you tell your user base no, you cannot use it, they will find ways around it and use it. They will load it on their phones, they will load it on their personal devices, and then you have no controls. Over what they're putting into it. They, many of the general user base don't know that the free version of ChatGPT will take everything and train it into the broader model, right?
And, you know, it doesn't matter what you upload to it. It won't, it won't, it won't obfuscate company names for you and won't obfuscate your customer data for you, right? So, you know, I'm very much a proponent of not know but how. So build kind of like those play box environments within your organization, pilot environments within your organization. Say, hey, here's an enclave for you.
Experiment the hell out of here, please. Right? We'll put some controls around it. But here, here's your playground. Please don't go out to the open, to the open models on the internet because we have no control over what data is being leaked out there.
Well, I mean, and of course I think the biggest thing is where, you know, a developer comes in and puts their proprietary code in and say, hey, help me write this, help me fix this. And like anything we upload to anything on the internet, not just to AI, it now becomes their property, right? Yeah. I'm sorry, I'm shaking my head and realizing you just can't see that. Yes.
Or listeners can't see that. Yes. Right. So what are some thoughts? I mean, is that valid reason enough to block all AI?
No, not to block all of it, right? You need to, you need to be able to balance innovation with risk management. Let's face it, right? You know, take our AI hats off, our traditional security hats on. The business always wins.
Period. Dot. End of story. Right? If you're too much in the way, of the business growing, generating revenue, reducing costs, whatever, you know, marketing, sales, operations, whatever that case may be, they'll find their ways around you, right?
They will circumvent you and you will either be extremely burned out as a cybersecurity professional or they will remove you as a roadblock. It's as simple as that. We have seen it throughout the last 25 years. Right? It's as, it's as true as the sky being blue.
And, you know, I truly feel like we're gonna see, we're seeing, we will see the exact same with AI. Well, it's interesting, you know, what popped in my head when you were saying that. I've been in this business, of course, since the '90s and mostly in IT when I started, and then I switched to cybersecurity. And going into cybersecurity, I, it, it was a little hurtful when you said that, but because it was so true. Is that I was the roadblock.
I was the one that said, no, cybersecurity wins. And by the way, I lost, right? Exactly for those same reasons that you told me, you know, they're going to go around you, they're going to remove you as a roadblock, whatever. The business is always going to win. Frank, I think every one of us in this community, in this industry has those scars.
So don't take it too— right? All of us have those scars. Now, well, thank you. That helps me. It makes me feel better.
So I think one of the things that a piece of advice maybe that we can get from you, uh, you know, obviously I have a little bit. How can we work in harmony with the business? Yeah, it's really understanding the business's pain points, right? Understand how your business makes money. It's as fundamental as that, right?
Like, I, I still to this day get on engagements where I try and have the security team explain their business's revenue model to me. And I'm not expecting them to have like a CFO or sales leadership understanding of the revenue model. But what are the basic drivers for your business? What are the basic market drivers for your business? Are you in a high-growth industry?
Are you trying to save costs? Right? Like, what, what are your organizational goals? Right? So now we're going back to, oh, the reason why Matt and I wrote the book that you mentioned.
And it's really, you know, you've got to understand the business context. You can't just operate cybersecurity in a vacuum. You know, I feel like we're beating a dead horse around that. And I think we as a general population community are getting much, much better at that. So take those same principles and apply it to AI.
How can we help the organization implement AI in a relatively safe manner? Right? How are we gonna grease the wheels them to enable innovation.
I, I fully agree with you on that one. I mean, um, and I think that's one of the biggest things that I teach in my classes. For, as you know, I, I'm a teacher as well. Um, I teach in the interview workshop, and I always let them know is that you need to understand the business that you're in, right? No matter what you're supporting, only about, let's say, 10% at a guess whose business is cybersecurity, right?
And outside of that, their main goal, the business's main goal isn't cybersecurity. It's part of them and it's our job to support them. Absolutely. Absolutely. Okay, cool, cool.
So with that, I mean, we've obviously been talking about the AI. What, have you always been in technology? Have you always been doing that? Is this your best job? Is it, Did you get out of high school and say, yes, I want to be a cybersecurity expert?
No. So I've always been drawn to technology, right? I didn't initially know security was going to be my path. Actually, my, my first degree, or my first degree, my first major was aeronautical engineering. I wanted to design fighter jets.
So this also happened to be in the late '90s where President Clinton was in office and It actually turned out pretty well because when I graduated, it was right when he was enacting a series of defense budget cuts. And, um, you know, the dot-com era was starting to take off. So long story short, obviously sometime during my college career, I transitioned from aeronautical engineering into IT. So hindsight being 20, you know, now being 20/20, that was a very Fortuitous move. Um, and then I started off as an Oracle developer DBA.
I, I didn't— I mean, you know, this was late '90s, early 2000s cyber. I was sitting in my office, um, my office— I wasn't fortunate enough to have an office then, a little cubicle, um, when the ILOVEYOU virus hit our, hit our network, right? Um, and it was our CEO, and, you know, everybody laughed. It was just the ILOVEYOU virus. I love you, I love you, I love you.
Um, but you know, that kind of started getting me thinking of, hey, this is— this could be a thing, right? Like viruses aren't just annoying anymore, it's actually causing business disruption. This could be a thing. And then 9/11 hit, and, um, you know, I had the knee-jerk reaction of, oh my God, I should— I should join the military. I want to do something.
I want to— I want to get back at them. And I wasn't in the position to do so. And so I kind of, you know, had the, thankfully, the very fortuitous thought of, hey, this next battle space is going to be this, this thing called the internet. So maybe I should look at that. Maybe I should look into how we protect that.
So I pivoted from database development and administration into data security and then network security and ran a global large-scale security network operations center and kind of grew up through the ranks that way. Started building security programs all the way to, you know, Marcos Energy, building and leading their security program until we got acquired by Marathon Petroleum. Stuck around there for a few years, a couple of years, and then spun off on my own. So when you say, is this the perfect job? No, it's not perfect.
Nothing's perfect. But do I really enjoy the independence and the ability I have to be able to advise many different companies, work on many different projects, see you know, all the ways in which to skin a cat, right, and broaden my horizons. Uh, absolutely, that, that's the part of, of the business that I love. Well, that's awesome, but I do want to take a step back here for a second, okay? You're, you're in college, you're deciding that, hey, what's the best way that I can make this fighter jet fly, right?
And I'm thinking Top Gun, you know, destroying that nuclear facility You know, you are flying the, what, F-18, uh, down the ravine and, you know, taking 2 Miracles, etc. And then all of a sudden I go, well gee, working on a server would be cool. How would you happen to do that? I mean, well, you know, why— what in the world would make you transition from, you know, the Top Gun, I created this jet, to, well, Windows Server, you know? And especially back in the '90s, and I remember Windows Server It was like Novell and NT, right?
NT 3.5. Yeah. No, I, you know, I'll be frank. I've shared this story before. A large part of that is I drank my way out of it in college.
And, you know, realizing that maybe 7:00 AM physics and calculus classes at that stage of my life weren't for me. So kind of reevaluated my life choices and realized if I was going, if I was going to continue down this path, I wasn't gonna end up with a degree. So I could either be working at this video store I was working at the rest of my life. Lo and behold, there would no longer be video stores now, or do something about it. But I still had an interest in technology.
I knew I didn't like programming a whole lot at the time, which is why I didn't go into CS. So, you know, back then the degree was called MIS, Management Information Systems, and naturally fell into that. Okay, so you got a job at a video store, which was what, new back then, right? New back— I mean, this is like the Blockbuster days or whatever, but it was a little local Vegas chain. I mean, it was still VHS and those large LaserDiscs that come out.
DVD hadn't even come out yet, right? So I'm now, I'm now aging myself big time. Well, we both are, because I remember those. But LaserDisc, I mean, okay, so they're just hitting the market.
Did you have to adapt? Did you say, well, this is the coolest thing ever? Or what was your thought when you first saw that LaserDisc?
God, I can barely remember what I had for breakfast yesterday. My first thought when the LaserDisc dropped, we're like, this is cool. Probably, I think this was cool, but these are really big. Like, are these machines, these ginormous machines and their cost practical? And lo and behold, they weren't.
Like, DVD came up and, and cleaned them right out of the market, right? As a result. Okay. So, you know, it's kind of a lesson of adapt or die, right? If you're not innovating, you're dying, which is, you know, a philosophy I hold near and dear today.
Well, you touch on a very good point, though. Not necessarily, but you probably invested some time or Blockbuster or whatever, that local chain invested a lot of money into LaserDisc. And then DVD came in, a new technology came in and essentially destroyed it. What were your thoughts if you were, let's say, the owner of that LaserDisc or that rental company? What would you be thinking?
Or what was he or she thinking? I'll tell you exactly what they did. They sold it. They sold the company and got out, right? They sold it for pennies on the dollar and got out.
Because they saw— because, because there's a weird— I don't know if you remember at the time, there was like a very quick boom, boom, boom move from LaserDisc to DVDs to Netflix, the original Netflix mail, uh, mail-order DVDs coming out, right? So the confluence of all of that together drove— in, in my case, it was Video Time, but the Video Times, Blockbusters, uh, Movies to Go, all those— that, that entire industry Um, to bankruptcy, frankly, right? There's what, one Blockbuster left and it's in Bend, Oregon? Like physical location left and it's in Bend, Oregon? Well, how can we apply that though?
I mean, not so much videos, but how can we apply that ever-evolving technology? How can we protect ourselves? How can we maybe decide— how do you know, right? And, and how do you know that AI is going to survive And now that we have all these different choices from AI, from Copilot to Gemini to ChatGPT, and, uh, lo and behold, what is that, DeepSearch or something like that? Oh no, I know I, I had to, I had to say that one because I knew you were going to react.
Hold that thought, right? But what do you think? I mean, should we go and invest everything, right? Um, and, and we don't have to, you know, we'll talk about maybe AI just because again, I think you were a certified expert at that point, right? Or certifiable, as I know you.
Uncertifiable, right? Yes. Well, what do you think? I mean, would you— if there was an investment opportunity, someone comes up to you, says, I've got this new AI thing, Rock, you absolutely have to go and invest in this, what would your thoughts be? I— full disclosure, I am not an investment advisor.
Do not take anything I say as financial advice or investment advice. Uh, that goes for both of us if you say my bank account, by the way. Same, same. Um, so, you know, I'll kind of start with this. Peter Diamandis, who's a, uh, you know, world-famous Silicon Valley investor, said— I think he said by 2030, that maybe a little after, early 2030s— there will be 2 types of companies that exist: those who have embraced AI and those who no longer exist.
And we could take that corollary back to essentially the start, you know, the, the dot-com boom. Sears, right? Fortune whatever, 100 company, let's say Fortune 50 company at the time. Sears, Roebuck's practically outta business now 'cause they didn't embrace online retail, right? Same with Kmart.
Same with Kodak from the, the photo side, right? It's being able to identify those massive trends. In the market, in the technology, in consumer spending habits, in how we consume information. You know, very few people, I mean, Frank, nobody younger than us is sitting down in front of the TV and watching the local evening news anymore, right? We're all consuming news on our phones and, you know, the 24-hour news cycle, whatever.
So it's being able to understand and adapt to those changes. Now, if I'm looking at, I advise a couple startups and if I'm looking into, you know, who I'm gonna invest my time in, right? I wanna see, are they, I wanna understand, are they creating a new mousetrap or are they building a better mousetrap? And both paths can be viable, right? But if you're creating a better mousetrap, how are you differentiating yourselves from the bigger players that are already more established on the market?
And that could be either a philosophy that could be bridging a gap in which, you know, those who have come before you haven't really addressed. That could come in the form of many things. And, you know, I think we need to apply that to, I mean, if you want to talk about investment decisions, again, I'm not an investment person, but, you know, I bought on the dip earlier this week in the market after DeepSeek came out. Right. No, right, right.
Not, not so much investment, right? Because this isn't a financial podcast, right? But, oh, I think what we wanna talk about is how much of the, which technology, what would make a decision driver for you to embrace such technology? What would make you, is there something, you know, going back to your example that you had before with the video rental store, I'm guessing that they decided to invest in that technology. They invested everything and then like you said, they, went pennies on the dollar, sold it out.
Yeah. Was there any guidance, any learn— anything you could have learned from that going back, looking at that from hindsight, and then possibly applying it to any new technology that we have today? It's identifying and embracing the trends. Um, identifying and embracing the trends, right? Embracing there being the key point.
Uh, I think, I think we in security still have a lot of naysayers. When it comes to AI, I think I still hear a lot of, well, we haven't even figured out our cybersecurity hygiene and our fundamentals, right? And we haven't— we don't even have an incident response plan, and now we're talking about securing AI. Well, I am a firm believer that AI can help you shore up a lot of those foundational gaps quickly, right? And effectively, and without necessarily needing to hire an army of people, because we're seeing that.
We're seeing, you know, there's, there's a lot of discrepancy between, you know, the dreaded ISC², uh, Cybersecurity Professionals in Demand report and reality and what we're seeing in the job market— people being laid off and a glut of talent on the market and all that kind of stuff, right? So we're seeing it. And, um, you know, I think you need to— you know, this is another one of those things like I firmly believe AI is another pivot point in our society like the internet, where if you don't embrace it, you just won't be around. And, you know, people are afraid, oh, AI is going to come and take my job. Well, there were the same concerns with when the cloud came out and, you know, older Windows admins, Unix System V admins, right?
BSD admins, all that kind of stuff. And the reality was they reskilled, they retooled, became really great cloud admins, or they retired, right? Or they changed careers. And, you know, I think we're seeing the same thing. The, the jobs that AI is gonna replace are gonna be the jobs of individuals who didn't embrace AI, in my opinion.
Yeah. Well, you know, and, and let's pivot a little bit here to, I guess, another touchy point. I think the job market is a little rough right now, right? Especially in cybersecurity. And Do you think that is a result of AI, or what do you think the result of that is?
No, I don't think— I don't think AI has impacted the cybersecurity job market yet. I do fear that it's going to make it harder for people to enter the market. Like, you know, what we see today as a traditional Tier 1 SOC analyst way into the industry, right? That's going to change. That's good.
That's going to change what it looks like. But I think, um, we haven't— we haven't been able to demonstrate ROI, right? So think about it because, you know, I know from a CISO perspective especially, there have been a lot of layoffs in the last few years. So let's say by the time you hire a CISO, who's not traditionally not cheap, you hire a team to support them, you get all the tooling and, you know, software licenses and all that in place. Let's say even for a small company, your overall security budget Make the math easy as $2 million, right?
For— that's probably more of a medium-sized company. Let's say it's $2 million. Can you really demonstrate that you're providing $2 million back to the company at least? Right. And that's really hard to do.
I'm not saying like, you know, we're idiots and not able to do so. That is impossible. That is really, really hard to do. And I think, you know, the last few years where budgets have been constrained and the economy hasn't been great and interest has been high and the cost of capital has been high, and the cost of investment has been high.
You know, CFOs and the bean counters have been looking at everything objectively across the organization in that lens. Am I, am I getting a return of the investment that I'm putting into this function, this group, this individual, whatever? And I think we're seeing that. So what would you suggest, though? I mean, I guess, you know, obviously when I give advice and I look at people and of course I think you, me, and all the good people out here in Colorado are trying to always help people, right, that are in, unfortunately, in that situation.
What kind of advice could you give them, the people that are listening to this podcast that have been laid off for no matter reason, whether it's AI, whether it's whatever situation? What advice could you give them?
How do you retool yourself so that way you are differentiated from every other job application that's coming across someone's desk, right? I keep an eye out on LinkedIn. You know, I see, I come across, you know, some of these job postings and I'll click on it and, you know, it's been up for 48 hours and it's got 600 applicants on it, right? So continue to invest in yourselves, continue to invest in skills. It's hard to give someone a roadmap here on the podcast without understanding what they want to do in cyber or what really interests them, right?
Right? But I do know that I think embracing AI is going to future-proof you. What does that look like today? Right? Embrace Python, you know, look into automation, right?
Kind of those building blocks of what we're leveraging AI use for today. In the future, even, you know, 5 years from now, that's probably gonna look completely different with the advent of AI agents and AI agents generating their own code or whatever, right? So it's always trying to to keep that step ahead. But use that downtime to continue to learn, to continue to upskill yourself. You know, I took almost 2 months off after, you know, you mentioned the transplant earlier.
And, you know, I went and dove headfirst into the International Association of Privacy Professionals AI Governance Professional certification. I think that's what you were alluding to earlier. Certifiable. That I would do that while trying to recover. But I was also sitting on my ass not doing anything, uh, had family in town all trying to, you know, be my quote-unquote, uh, nursemaids, right?
Um, going crazy. So that's how I kept my, my brain occupied. Um, but, you know, you got to take it upon yourself. Like, don't blame the market, don't blame— we've seen really terrible recruiters and people getting ghosted, whatever. Grab the, grab the bull by the reins or grab the horse by the reins and upskill yourself, right?
There's Coursera, there's Udemy, there's the MIT OpenCourseWare. There's all sorts of free YouTube, free resources on the internet, right? Go, you know, take, take advantage of this downtime that you have. Survive. I have to say, survive, pay bills, but take advantage of the downtime.
Yeah. And I do have to throw one thing in there since we named some of those courses. Um, you know, and then this is not a plug, they're not paying me for this, anything. TCM Academy. Yeah.
Uh, there's 100 resources out there. Oh my God. Well, he, I, I have to say that I've taken, I've got probably about 6 or 7 of his courses and they are just amazing, right? As to the quality of the work in there. Um, but I do want to add one thing.
I want to kind of go back because of course, you know, I, I have all these random thoughts that are happening when you're talking. Yeah. And you were talking about, you know, how do you value yourself towards the company and things like that? Uh, I was listening to a student and he tells me, well, my roommate, he wants the kind of job where he comes in when he wants, and then when he gets there, he kind of just does whatever he feels like it. Um, you know, I was like, that's some of the attitude.
I like, wait, what? Right. Yeah. And, um, of course that's a silly story. Have you got any silly stories?
Have you ever made any goofy things like that happen? Or have I ever— have I ever, like, seen something like that happen? No, just in general, just something where you made it maybe, you know, I mean, obviously, in that case, I'm laughing about it, right? Oh, yeah, student. But what about, like, you?
I mean, have you ever done anything goofy, forget to do something, or, you know, walked into the wrong meeting or anything like that? Or— oh, God, who hasn't? First of all, I would tell that roommate, Um, start your own business, go into business for yourself, and let me know how that works out for you. That's the only way you'll, you'll have the opportunity to do that. But again, let me know how that works out for you.
Second of all, yeah, man, I mean, I remember a time I had a— I got recently hired on as a security leader at a company, and I had my first meeting with the CFO, uh, and it was first thing in the morning to talk about my security budget for the coming year. And, you know, I walked in the conference room, I was pretty confident, and and my plan, how I was going to, how I was going to present it in the business cases I lined up. And I get there and I realized I never changed my shoes leaving the house, right? I still have my house slippers on and didn't have time to run back home and change my shoes. So I just, I just rolled with it.
I went in, you know, I'm like, oh, maybe they won't notice. They're black. They're not like slip-ons. They're like whole, you know, you know, my whole foot was in them. Uh, but, you know, the CFO, my VP noticed, and we all had a good laugh, and they actually both admitted that they had done the exact same thing at some point in their careers.
But, you know, the lesson learned is, just like in, in life, double-check your game plan, right? Whether that be you presenting the security budget or, you know, that you've got the right shoes on, right? Uh, double-check your game plan before kind of throwing yourself out there. You gotta admit it here though, buddy. They were pink bunny slippers, weren't they?
No.
You know me. Probably a lot of the listeners know me. I am a huge fan of the Christmas story, right? The pink bunny outfit will live in all-time glory, but you'll never catch me dead in one. Well, you know, now I'm gonna be watching you, Rock.
I know we live in the same area, so I'm now gonna be watching. All right, we're coming to the end of this, uh, but we still obviously got a few minutes left. I'm going to give you the hardest question, what I always try to end with here. What do you think the biggest challenge is in security today, and how might you want to address it? Now, not saying solve it, but I'm saying how do we address it?
How do we look it in the eyes? What is that challenge? Yeah, I think, you know, one of the biggest challenges Just the size of the attack surfaces we're dealing with, right? You know, and frankly, AI amplifies that. So add that to the complexity of ensuring both innovation and compliance or risk management.
And, you know, I get a lot of phone calls of, Ron, holy crap, I don't even know where to start, right? And it's, you know, they're just paralyzed, especially with regards to, you know, we're just gonna keep the theme going of AI. And, you know, I think you got to just kind of break out of it and just, just do something, right? Treat it as agile. Fail fast, fail often.
Go figure it out, right? There are a ton of resources. Reach out to your peers, reach out to your networks.
You know, if you trust your vendor relationship, reach out to them when you're experiencing certain challenges. You know, I, you know, I say that from the old school older school compliance days of, do I go with NIST or ISO or SOC 2 or whatever? So I don't care if it's not industry specific, just pick one, roll with it, see if it works for you. And, you know, I do a lot of work in critical infrastructure, right? So there's a lot of convergence of cyber-physical systems.
So the breach isn't necessarily about data. It could threaten safety. And, you know, you've got to take the context of your organization into account. Right? Are you in that environment?
Or are you at a, you know, and I'm not, I'm not bagging on marketing companies, but are you at a martech company? And, you know, most of the data you're dealing with is not sensitive data anyways, right? So it's always taking that environment into context. But I think you just need to take a step back. It kind of comes back to that resilience too, right?
Figure out that you're not going to serve, solve all the world's problems. At one go, take a bite of that elephant, go back to our fundamentals, right? Go back to a risk-based approach of, you know, building your security program and take it one risk at a time. Right. Much easier said than done.
Right. We never work in serial, but you get what I'm meaning, right? You know, no matter how complex the attack surface is today, it's still about, you know, just break it down into the addressable chunks. Uh-oh, Frank, if I still have you, I can't hear you. Okay, well, Rock, thank you for your time.
I appreciate it. Oh, uh, I'm there. My internet connection, uh, hopefully you can hear me now. Uh, thank you for your time. I really do appreciate it.
Again, Rock Lambros, you can find him out on LinkedIn. He is the co-author of The CISO Evolution, uh, with Matt, uh, Sharp, right? Um, and again, thank you for your time. My name is Frank. Uh, I am the VP of the Denver OWASP Foundation.
Of course, I have to throw my little pitch in there. Um, we do have the SnowFROC conference coming up, which I know, Brock, you have a ticket for. Uh, SnowFROC is March 14th, also known as Pi Day. Right? Yes, and we have a wonderful conference coming up.
HD Moore, creator of Metasploit, is going to be our keynote. Tanya Janka, and I don't know if I'm saying your last name correctly, of SheHacksPurple is going to be there. We're also going to have something new this year, a bunch of villages including a lockpicking village. So again, uh, would love to see everyone there. If you're listening to this podcast and you see me running around like crazy at SnowFROC, please though, at least say hi to me.
So Frank will have the pocket protector. Thank you for your time. Yes, Frank will have the pocket protector. He'll be easy to find. Yes, I have to have my pocket protector.
That is my branding though. All right. Well, again, thank you, Rock. I appreciate it. All right.
Thank you, buddy. Learn more about the Colorado security scene at colorado-security.com. Where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.