Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 272 for the great month of March. Alex?
March. March. You know, Robb, earlier today I was watching some of the behind-the-scenes documentary on Saturday Night Live. Okay, the 50th anniversary. It wasn't the 50th anniversary show.
They also have a documentary about Saturday Night Live. And one of the things that they said that I was just reminded of was like 5 seconds before they go on, like one of the offstage people like says 5 seconds, but like in a really funny way so that the audience starts laughing. And, you know, a lot of times you hear the start of Saturday Night Live, they do the cold open, but like the audience is laughing as they come in. They're already laughing. And that's why they do it.
And so I was thinking of that, 'cause both you and I were kind of joking around before this, and we were kind of laughing coming into the show. Jokes that were inappropriate for this podcast. Exactly. Podcast office, or audience rather. Speaking of inappropriate for the audience, we have a Slack channel that people are welcome to come to.
There will often be jokes, mostly work appropriate. We'd love to have you join us in Slack. You can go out to colorado-security.com to join there. While you're on the website, please go to the bottom page and join our mailing list. That's how you get the news right in your inbox every month.
Uh, it would be also wonderful if you subscribe for the podcast on your favorite podcast listening service, whether that's YouTube or Spotify or Apple Podcasts or whatever it is, and rate us there. Make sure people know how good the podcast is. It'd be also wonderful if you told a friend about Colorado Equal Security and all the fun stuff going on. And if you'd like to support us financially, we do have a Patreon campaign that has been ongoing. Thanks to all of our patrons.
But we use that money to do fun things like host the podcast and throw a picnic. And we really do appreciate you patrons. Thanks for your support. I also want to say thanks to our annual sponsors who support our security community, security leaders community here in Colorado. We have Armis, Zscaler, and CrowdStrike as our annual sponsors.
Thanks to all 3 of you for doing that. Yeah, that's great. Why don't we jump into the news? Awesome. First, in the long history of the podcast, we'd like to talk about the airport and things going on at the airport.
And I'm sure we've had many stories about the construction going on at the airport. But this one is, is one of the ones that maybe we can see the end of the light at the end of the tunnel. Yeah, the, the traveler-facing construction has a deadline. They say that this should be done by the end of 2027. So less than 2 years from now.
And they showed that this article is worth clicking into and taking a look at the drawing. It shows a model of what the— oh, the new Jefferson Terminal, but I can't remember what they call that big— it's the Great Hall. The Great Hall, what that's gonna look like. You know, where the security used to be is gonna be restaurants. There's gonna be a live music venue there.
There's gonna be big boards to see your RTD scheduling. Honestly, it looks pretty cool. I'm excited about it. It does look pretty cool to me. I think this is, you know, kind of what they were hoping for the airport originally, before they had to, you know, put in all these security gates in the middle of the Great Hall there.
Yeah, it's gonna, it's gonna be neat. They mentioned that while this will be the end of the customer, the traveler-facing construction, at least for quite a while, that there will be ongoing construction basically forever, right? Because they say they anticipate in 2040, they're going to surpass 120 million travelers. Apparently, that's going to require a lot of behind-the-scenes construction and changes to the systems to make it work. But I guess it'll mostly be seamless to those of us who travel through there.
All right, moving on. Our next, actually 2 stories, are about our favorite topic, AI, but also startups here in Colorado that are using AI for medical purposes. Yeah, you know, I knew that there's been lots of AI companies built, and of course, it makes a ton of sense that medical would be a place that you would focus since not only is it very valuable to humanity to do it, but it's also a lot of money. If you can get more efficient with how doctors work, you can really improve quite a few things. This talks about a couple of companies here in Colorado that are doing just that, that sell to doctors' offices and help automate and really make more efficient a variety of different processes.
The first of those is a company called Cleexa. They raised $2.8 million, and the company uses artificial intelligence to help healthcare providers streamline diagnostic data and patient care information. The second one that we've got here is Affinion, Affinion Health, and they do something very similar. So they use artificial intelligence to streamline healthcare workers' administrative tasks. And it looks like, really, like I said, they're both very similar.
Affinion raised $5 million to go toward product development and expansion, and they're focusing on helping automating the tedious tasks, reducing the amount of email that doctors go through They say they can reduce about 5 hours a week per work for a physician. So if you, you know, you got a practice with 20 doctors, you all of a sudden get one free doctor out of this thing. Yep. And I look forward to the day in the not too distant future when Clio acquires Affinion or Affinion acquires Clio. Yeah.
Hopefully they're both wildly successful and, you know, Denver becomes the hub of AI healthcare technology. Next, we have an article from Webroot. We don't get a ton from Webroot, but this is, this is one that's probably not focused for us as security professionals, but more focused for us to share with our loved ones who might not be quite so security savvy. Yeah, so this is talking about how to protect your digital life and 4 ways to address some of the common vulnerabilities you have in your digital life. So talking about protecting yourself from viruses, protecting your privacy online, safeguarding your private information and identity, as well as how to uh, you know, protect and back up the data that you have that is stored online.
Their list of 4, they forgot to put a 4 on the last one. Yeah, it took me a minute. You did a good job getting right to it though. Yeah, it took me a minute. I was like, there's 3 things here even though you said there's 4.
But there was 4, there was 4. So anyway, Webroot, uh, giving resources that we can share with our loved ones, and, and I appreciate that. All right, uh, our next story comes from Virtual Armor. We don't get a whole lot of stories from Virtual Armor, so this exciting for that. This is talking about cybersecurity challenges in the age of remote work.
Yeah, they— I, we were kind of joking ahead of time talking about this article. It feels like somebody went to a whiteboard and just started dumping all of their thoughts about things to think about in a remote work environment from a security perspective. You know, shadow IT is on their list, endpoint security risks, remote work fatigue. Yeah. A lot of stuff that I'm not sure exactly makes a ton of sense.
There's not a lot of guidance here, right? It's just things to think about if you run a security program and you have remote work. Yeah. So yeah, exactly right. So, you know, if you want a list of risks, this is your list.
The evolution of regulations for remote work. That's one of the topics. Yeah. You better keep on top of that if you run this program. You better pay attention to regulations.
It's a good idea. Yeah. Don't get arrested. Next, we have a blog post here from Ping Identity. Did I skip something or is that it?
Nope. Right, right. Good. Ping is starting— has started a series of blog posts about myths having to do with financial fraud. And this is myth number 1 that suggests that financial fraud starts with— at the moment of loss, at the moment of financial loss.
Yeah. So, so when, say, your credentials are compromised or something like that, immediately, that's when fraud happens. And in their eyes, that's a myth. It usually happens earlier, right? We're saying that this happened when a credential was initially compromised or exposed.
Is that the focus here? Yeah, and then they go into where fraud actually starts. So things like new account fraud, account takeovers, you know, and then they also talk about how identity crimes, you know, lead into other kinds of fraud. So it's not just identity crime that is the be-all end-all. You know, kind of gateway you get to other stuff as well.
And then they do get into why traditional approaches fall short. And lo and behold, Ping Identity has a solution that can help you with this if your traditional resources are not working. Indeed. All right. Last story of the month.
We have one of those technical blogs from Red Canary. This is a good one talking about CopyObjection. And this is the subtitle here is Fending Off Ransomware in AWS. Sounds like a great idea. How do you do that?
Yes. So if you want to know how to do it, you have to read the blog. But this is one of the ones where they go into sort of deep about talking about S3 buckets being targeted and some details about what to look for, obviously how to automate the response to that. I think it's primarily around detecting ransomware as it starts to get kicked off somewhere and then being able to quickly in an automated fashion respond to it. Yep.
Yeah. Good stuff. Obviously, if you're running an AWS environment, the last thing you want to do is, is have this happen. I mean, in AWS, not— it's even worse than in other environments in some ways, because not only do they encrypt your data, they also run up a lot of money along the way with, with overutilizing these resources. All right.
Those are the news stories. Why don't we jump over and talk about the events coming up? We do have an event calendar if you want to go take a look at all of the things happening throughout the year. And in fact, a lot of our local groups have filled out their own calendars, and that's how we fill out ours. We go out to theirs and move stuff over.
So there's a lot of events actually in the calendar right now, but starting in March, we have our first event on the 7th. The NCC, the National Cybersecurity Group, is doing their NICE Local Stakeholders Engagement event. What's NICE? So NICE is basically the job taxonomy that CISA came out with for cybersecurity jobs. So if you care about employment and other things like that, you want to get involved in that, that's what this event is about.
Uh, our second event, which is also on the 7th going through the 8th, is the 2025 Rocky Mountain Collegiate Cyber Defense Competition. Uh, I know at one point they were looking for volunteers. They may still be looking for volunteers to, to help with that. And if you're interested, I'm, I'm sure you can find info on the, uh, RMCCDC site. I've been to that event in the past.
It's really neat to watch these, these teams competing. Um, if you, if you haven't been to one, I, I recommend swinging by to take a look. Also in March, on the 12th, we have the Denver ISSA March chapter meeting. On the 20th, ISACA Denver is doing their March meeting online only. And depending on when you go to try and sign up for that, it may or may not be a circular click-through to try and sign up for it.
I'm sure that it'll get fixed at some point. But as of this recording, you can't quite sign up yet. On the 26th, ISSA Pikes Peak down in the Springs. They're having their chapter meeting. And the last event of this month, SANS is doing an AI cybersecurity summit from the 31st all the way through April 7th.
And then there's, there's the summit part and there's trainings all throughout. Yeah, that's part of that, that week there. Yep. We do have some jobs this week and start one more thing before we get to jobs. Oh yeah, you're right.
We did want to also highlight the Rocky Mountain Information Security Conference, which is coming up in the not too distant future. I think that early bird registration is ending soon or maybe has already ended, but that's happening May 28th through 30th. So definitely check out the RMISC website. Yeah, if you are a practitioner in the area, I think RMISC is about as good as it gets in terms of getting out, networking, education. It is a world-class event here right in our backyard.
Jump— let's— now we can jump over to jobs. We did get one specifically requested by the hiring manager. Prologis is hiring an energy security architect that would be working for our friend Tyler Warren over there, and it looks like a pretty fun job. Nice. Uh, Bank of America is looking for a business information security officer engagement senior lead.
EisnerAmper is hiring a director of national security advisory cybersecurity. This looks like a, like a consulting type advisory role. Optiv is looking for a senior consultant in DLP and data security. Charles Schwab is hiring a senior technology risk manager on identity access authentication risk management. That's a mouthful.
Klaviyo is looking for a lead security risk analyst. Fastly is hiring a technology compliance lead. Datadog is looking for an information security analyst 2 for commercial audit. And finally, Sage Hospitality Group is hiring a director of information security, going to be running the program over there. Very nice.
Well, that is it for the news this week. Alex, do we have an interview? Good question, Robb. We might. We're recording this news section a little bit earlier than we normally record in the month.
And we have plans to have an interview for this podcast. But there's not one done as we speak. If the, if the headline of this podcast has a person's name on it, you should be hearing from that person very soon. Otherwise, you won't hear an interview this month, and you'll hear from us next month. That's it.
Well, we will talk to you guys in April. Have a great month. Thanks, Robb. Hi, this is Jason Hamilton, Deputy CISO at Movement Mortgage. Welcome to Colorado Equal Security for Colorado security professionals by Colorado security professionals.
Well, good morning, good afternoon, and good evening. Welcome to the State Colorado Equal Security Podcast. My name is Frank. And today I have the pleasure of having CW Walker in here. CW, how are you today?
I'm doing pretty good, Frank. How you doing? Good, good. Outstanding, actually. CW is in technical strategy— yeah, strategies and solutions here.
And he is currently working for SpyCloud, has been for the last 5 years, works in product strategy. Research and development, and has a very, very, you know, varied, varied— that's, that's super varied, by the way, right? Quadruple varied, uh, background here. Okay. All right.
Uh, okay. So CW, uh, again, how are you doing? We were just talking right before the podcast. I do have an icebreaker question for you to kick it, kick it off though. Yeah, what you got?
Right. Okay. So, uh, you know, in pure honesty, CW has not heard this question yet. Uh, so we're gonna have a little fun here.
In my background, I know everyone here is just listening to this in audio, but in my background, I have a lot of Dungeons and Dragons stuff. And we are talking about Dungeons and Dragons. What character type or what character class would you be, CW? So I am running a current campaign right now and actually playing a Paladin, and this is an Oath of Vengeance Paladin. So someone that has strong feelings about justice and making bad guys' lives hard.
So it's, it's fun to be able to win and get to see those wins happen in real time in Dungeons and Dragons where we don't always get that in security. Well, I guess that brings up some questions here. For an oath of justice, why don't we get that in cybersecurity? I think actually that we probably get it a little bit more than we realize. But the challenge is a lot of us in blue teams and as defenders, we are sort of constantly under the gun to make sure bad things don't happen, or if something bad happens, to be able to bounce back from it as quickly as possible, right?
And so we don't really get as much of a chance to see or to think about adversaries beyond the way that they're trying to interact with our organization.
But something that is not on my LinkedIn is actually that I started my career at the Federal Bureau of Investigation. And we got to do things that made bad guys' lives hard all the time over there. And that's really satisfying. So I think that there's a lot of really good work being done in government sort of in that vein, but we don't get to hear about it and see it, I think, as, as often as it's actually happening. Yeah.
Okay, so first off, that explains the black van sitting outside my house right now. Uh, should I bring them food and beverage? I mean, I, I think the world of them, so I should maybe bring them food and beverage, knock on the door a little bit. Yeah, as long as the food and beverage is under $15. Otherwise, you know, we have to have a conversation, uh, about, uh, undue gift giving.
Okay, so, so if I give them something for, let's say, 1501, they can't surveil me anymore, right? You're gonna have to report that, you know. Yeah, we're gonna have to report that. Okay. All right.
I'll be right back. No. All right. Okay. So, uh, you've been in cybersecurity your entire career, right?
How does that feel? I mean, like, where did you start off at? So I, uh, you know, going back, I guess, to ancient history, I studied political science for my undergrad, and then I went to grad school in DC to study intelligence. Really thought that I wanted to get into the intelligence and sort of the operational intelligence space. And when I was at grad school, I attended a seminar about cybersecurity, and I, up until that point, didn't even know it existed.
As something that someone could do and actually get paid to do. And so that was a little bit of an eye-opener for me. I ended up getting into the FBI and working on some really, really boring paperwork before going back and being a cyber threat analyst. But that's really kind of what kicked it off. My first semester of grad school, going to a seminar about— I think it was cyber statecraft.
And then every research paper and every element of my studies that I could use to focus on cybersecurity from then on out, I was all in. That's really what, what got me started sort of in the industry, which I didn't even know existed before then. Okay. Well, that's interesting. I think you and I have some, well, similar background pieces, mostly because if we think about this with the You know, I didn't intend to get into cybersecurity either.
Right? Yeah. I started off actually trying to become an attorney. I had some interesting things with being sponsored by a state senator, trying to get into cybersecurity. Ended up joining the Marine Corps instead.
And then tried to do back, going back into my Marine Corps studies or going back to my attorney studies. My computer broke. When I found out how much they were trying to charge me, I was like, I'll figure this out myself. Right. And so it started.
But I think you have an interesting thing. Would there be a relationship between political science and cybersecurity? Did you get some skills from that? Oh, yeah, absolutely. No question.
I think the 2 things that really set me up for success studying political science and international relations were, one, I learned how to write and write quickly and write well, which helps a lot in security because so much of what we do requires us to communicate with other teams that are probably not technical. And so being able to communicate that in the written word, I think, is really important. And then the second piece really helped earlier on in my career when I was looking at nation-state adversaries. And trying to understand, um, things that we believed that they were looking at, or that we knew that they were trying to find out about on the intelligence side, and, uh, understanding the way that states operate and an intelligence apparatus operates so that we can manipulate their, uh, perception of reality, right? And I think that if I didn't have studies in international relations and I didn't understand some of the history behind the intelligence organizations that we were squaring off against, it would have been a lot harder to especially step out of biases, right?
Okay, so do you think that nation-state adversaries— do you think that they're after us for what reason? Is it for our state secrets? Is it to really just destroy us because they hate us? What would be their motivation? So it's a little bit of an odd space.
Uh, I think destruction is not really on anyone's mind because we're so intertwined economically. Less so with Russia, right? Um, and, uh, and with North Korea and, and Iran. But when we're looking at like China, um, I think that, uh, the The more interesting space there is control and influence, and then also sort of state secrets. But China is interesting because they're a state that is interested in collecting sort of all of everything and using it to help their growth, wherever that may be.
Back in the ancient days in grad school, we had exchange students from China. That would go into the library and would burn out printers copying entire textbooks page by page so that they could ship the textbooks back to China, which, you know, is, is a little different than the way that we operate. So whether it's economic espionage, so that touches our private sector industries in a really big way, trade secrets, that kind of thing. At the state level, understanding the way that we operate and trying to be able to influence that, especially in the East, and understanding our capabilities. So one, they can copy them if they can, or two, they can protect themselves against the methods that we're developing and try and influence our perception of reality.
Okay, so I'm going to go on a controversial subject here. We're going to try to keep the actual politics out of the politics politics out of this, right? But how do you feel about that TikTok ban? Did you think— because that was the driver behind it, right? Was, oh well, China's collecting our information.
And I was thinking about this, my own personal thought about it was you know, watching TikTok, like, wow, this would be worthless information though. I mean, being someone that's addicted to TikTok, I sometimes think, wow, there are a lot of idiots on this thing, uh, and I keep watching it though. What is China going to gain, or how could they influence us through TikTok? So TikTok is interesting, um, and I think there's 2 elements of it. I think that politically it was Oh, there's a huge risk of us having stuff stolen, our information stolen from TikTok.
And that's sort of what was going around Congress, right? And I don't— for me, that's actually not even the biggest piece. For me, the more interesting piece is the fact that over 40% of US adults say that their primary source of news is social media. And TikTok has, uh, 135 million monthly active users, and that is a very large number of folks that could potentially vote. So if your primary source of news is a source that is inherently controlled by a foreign adversary, even if it's just algorithmically deciding what you see or what you don't see, Uh, that I think is incredibly powerful as far as like information manipulation.
Um, but I think the risk of us getting information stolen from TikTok, wildly overblown. But having our entire country consciousness, uh, manipulated, much, much, much, uh, shorter leap, I think, to that kind of operation. Wow. Uh, I have some opinions in that, right? A couple of different opinions.
First off is You know, when we think about our influence, I think that we are way too easily influenced. And when you think about our media, what people actually believe in and things like that, I though again, I'm I am very addicted to TikTok. I was hurt just like everyone else when when that went away. But again, the news. I mean, I I listened to some of the news on there, and of course, maybe it's just.
What I feed on, but I listen to The Daily Show, right? I listen to, uh, oh look, Disneyland has been flooded, and we— it's like, it's fake news. How did that influence— how could China turn that into it, into something they could use? Um, I think that it's, it's less about what people are seeing and more about what they're not seeing, right? So if you're not seeing news that might push you to think or act a certain way, um, then it's going to change your perception.
And, you know, this I think is most apparent when we're looking at China specifically. How does the US view China? If China controls the algorithms in TikTok, if there is anything that could potentially be critical of China, then that's just really not going to have much of a shelf life on TikTok, right? And so it's multifaceted, but Let's— one of my friends, I wonder if I can find the post. But Marcus Hutchins, who's sort of a bit of a celebrity in cybersecurity circles for the WannaCry stuff, he had an interesting take on TikTok when it came to cybersecurity professionals.
He said something along the lines of, it's really interesting that people who build their personality and their career on living in dangerous spaces and challenging operating environments not wanting to be on TikTok. If you're that worried about TikTok, you would think that cybersecurity professionals would be the most comfortable there if it's as dangerous as they say. So I think that the security concerns, you know, from, from a theft perspective are a little overblown, but just the number of people on TikTok and the way the algorithms can be tuned. That's, I think, what's probably most fascinating. I will also say, though, that from a media consumption standpoint, Frank, you're probably in sort of the top echelon of people who are getting sources from all kinds of different places just for the very nature of what you do.
The conversation we're having, Right. Well, I think it's— and again, I know there are going to be people that know me that listen to this. And after they hear about the TikTok and how addicted I am, they're going to think, well, a lot less of me. Right. But I do want to get back to something that you mentioned here.
Marcus Hutchinson. I know the name. He was on Twitter, right? He was on— he was very big on Twitter. Yeah.
And especially with the WannaCry. So if he is actually a friend of yours, right. First thing I would have to say is thank you to him because of what he found on WannaCry. I was one of the many, many, many people that were affected by WannaCry. We were working and trying to figure out how to block this thing.
We saw his post and it's like, why not? Because it was like blocking 4 URLs, I believe, right? Yeah. And it's like, well, what have we got to lose? We've got nothing to lose at this point.
So we blocked those things. It stopped. And again, big giant thanks to him. But then, of course, something controversial happened to him. Oh, man.
Yeah. Yeah, that, that dude has had a wild ride. And, you know, he obviously was arrested when he was coming to conferences here in the United States. And that I think was kind of tough. And then it didn't help that, uh, the underground, um, was sort of all frothed up around, uh, you know, his legal situation, uh, and, uh, there's all kinds of interesting things related to that that I won't get in here.
There's an excellent Wired article for folks that aren't familiar with, uh, Marcus Hutchins' story. Um, I would definitely check out, uh, that Wired article. But, uh, we've got, um, some other friends in law enforcement, uh, and someone, uh, you know, joked that, uh, one of the law enforcement folks should just, uh, walk up to Marcus one day and say, hey, you know, we need to take you in. And, uh, he thanked them profusely after the fact for not doing that because I think that's pretty stressful for a young dude. No one likes getting arrested.
Right, right. Well, again, I, I looked at some of his stuff. I follow him on Twitter. And actually, I think he did some courses out there and I went through those. I'm like, wow, those things are absolutely amazing.
But speaking of friends, let's switch a little bit here. Speaking of friends, what do you do to maintain your friendships? I mean, are friends important in cybersecurity? And how do you maintain them with the fact that everything we work on is classified? I mean, we can't talk about it.
I'm gonna assume with the— especially with the black van outside of my house right now, that you can't talk about certain things. Yeah. And by the way, can we get them a different color van? Like, can we do something like that? Maybe do like pink with roses?
No, that's too expensive for government budgets. Oh, is it? Okay. Yeah. So I don't think we're gonna move away from that.
Okay. But are friendships important and real friendships? Do you, do you talk about other things in cybersecurity or are all your friends in cybersecurity? Yeah, this is a good question too. I would say that most of my friends are in cybersecurity.
And part of it is because, you know, We like the same things. We're into the same kinds of technology. But, you know, speaking about things that are classified or that we don't talk about, I think the other side of the coin there is sometimes normal people just don't want to talk about it. They find it intensely boring, right? So even if we could talk about some of the things that maybe we otherwise wouldn't, you know, my wife early on in my career.
I was like, oh, you know, I'm working on like some secret stuff. Does it ever bother you that I can't talk about it at home? And she was like, if it's anything like what you researched at school, then no, I'm glad you can't talk about it because it's so boring. I'd rather talk about something else.
Your wife and my wife have a lot in common, at least that part in common. She hates it when I listen to my podcast. Yep. And listening to all these classes, she's like, go put on your headphones. Right?
Let me listen to something interesting. Relationships, I think, are critical. So security is and can be a fairly stressful career. Right? And so having people that you can sort of blow off steam with and that just understand some of the stuff that you're working on, or even if they don't understand, They've been in something similar before, right?
The challenges were sort of spread out as a community. As much impact as cybersecurity has, it's still relatively small, right? So the ways that I kind of try and keep those relationships alive are twofold. One is I enjoy playing video games with my friends online. And most of the time, we're just getting on and we're catching up about wild things that happened during our week and talking about new stuff that we found while we connect sort of in a virtual space where we're not able to do that physically.
And the second is at conferences. And I love seeing my current friends at conferences, but I also had someone who I think is one of the more connected people in security that I know, uh, a guy by the name of James Shank. He said, for every conference that you go to, try instead of meeting as many people as you can, try just building, um, one or two really solid relationships instead of getting, trying to learn 100 people's names, get to know 2 people really well. And connect with them outside of the conference. And that's made a huge difference in sort of my social network, my support network.
And a lot of us are relatively introverted in security. We don't have to talk to each other once a week or once a month or once a quarter. If we see each other once a year at a conference, but we built a connection at that conference, Sometimes that's as much as any of us need. But having those friendships, I think, is super, super, super important for managing stress and feeling like you're, you're doing something fulfilling with the team, right? Well, I definitely agree with you.
This is such a small community. We see each other again. At my current day job, I work with 2 people I worked with in the past, one from 15 years ago and one, believe it or not, from 25 years ago. Well, right. Industry.
Yeah. He's now a director. I enjoy talking to him. We try to go back, it's like, wow, we were working together in 2000. So I mean, even with my simple brain, I can figure out that that's 25 years ago that I met him.
Uh, and so it's just like, wow, that's such a small community. And I think that's some pretty good advice that you have, right? One or two. We talk to everybody. We have a tendency to talk to everybody.
Anyone that knows me at conferences know that I actually talk to probably about 50 to 70 people per conference. But that's who I am. But I like your idea. I think there are going to be some people listening to this podcast that are going to walk away saying, well, maybe we'll try the next conference. Dude, you're so right.
And Along those same lines, you know, I had someone on an email thread this week with a different cybersecurity company and he was just CC'd and I was like, wait a second, I know that guy. And I reached out and he was like, oh dude, I didn't even know you. He's a previous work colleague and totally unrelated to our relationship at all. We just ended up being on the same email thread And we worked together like 6 or 7 years ago. It's crazy how small the space is.
Wow. Well, thinking about getting into this space here, I think you and I have some, again, a lot of common backgrounds. I currently teach for CU Boulder in their cybersecurity program, all entry-level stuff. Cool. I try to get people into this industry.
I've been doing that. I have more than 20 people that I have mentored to get into this industry, right? What advice, like, if you're in, well, political science, or let's even go maybe a little bit outside of that, maybe you're waiting tables at a restaurant, how would you say to get into— what would be the best path to get into cybersecurity? Oh man, yeah. So I think one of the things that's beautiful about cybersecurity is it's still one of the relatively few, um, white-collar tech jobs that you don't necessarily have to have formal education to succeed.
If you do have an education, it will make a difference, right? If you're studying, um, you know, uh, at, uh, the university level, or if you're going for some specific certifications that are more practical, That I think is legitimately useful. But at the end of the day, there's still a ton of work that needs to be done. And cybersecurity hiring managers will not turn up their noses at someone who doesn't have a super shiny degree from a great university if they can speak the language, they understand the technology, and they can do the job. So What I recommend, and I love that you've mentored that many folks getting into security, that's incredible.
We need more good people in security.
The way that I recommend folks get into security is to look at very broadly the security industry as a whole. And you can do this by looking at like the Momentum Cyberscape. Every year they come out with like this massive PDF that says these are all the subindustries in security and the companies in those industries. Pick 2 or 3 of those subindustries that sound interesting. Don't spend more than like 5 seconds on this.
If you think, oh, threat intelligence, that sounds kind of cool, set that aside. Oh, authentication or virtualization. Hmm. Interesting. Grab a couple of those subindustries.
Look at the companies in those sub-industries, read their white papers, read their blogs, get to understand the language of that sub-industry and security. And then go to local meetups if you can. If you can't, connect with someone on LinkedIn that sounds like they're doing something related to what you've read in those white papers and just say, what's a day in your life look like? Security is an industry that is built for better or worse on relationships. But we're also, some of us, I think like you and I are relatively extroverted, but not all of us are, right?
And so there's a lot of trust that goes into getting a job into cybersecurity, which is why there are so many companies that offer really, really lucrative referral bonuses. They want to bring people in that someone in the company already knows. And our job is to understand what makes us excited, what gets us up in the morning, what we're passionate about on the technology side, and then start getting to know some people in that space and not be necessarily looking for a job, but looking to build relationships. It doesn't have to be something that you, you know, go to all of their, you know, baby baptisms or whatever, but start making some friends, understand what that life looks like, and understanding the language gets you a massive, massive head start in interview process because we're all about trust. We're trying to understand a risky environment, having someone that is speaking a language that we understand.
And that understands our language is huge. And you get that by relationships and by reading everything that you can about that space from companies that are in it. Okay. So I've heard a couple of things in that. First off, it's not always what you know, but who you know, right?
But I think the other thing and the biggest thing that you emphasize, and I fully agree with you on this, is having that passion, having a good attitude about this. Uh, you know, because the one thing that I cannot teach— I can teach you the basics, I can teach you how the interview process is going to go, I can teach you about certain things— I cannot teach you about attitude. I was talking to Asuna a while ago, and one of the things that they said to me was, well, I'm a procrastinator. Guess what? I can't fix that.
That is something I cannot help you with, is wanting to study, wanting to do this. You should be doing this because you want to do this. And if you don't want to do this, if this doesn't get you up in the morning, kind of what you just said, yeah, maybe this isn't the right industry for you. That's a good point. I, I think there's something to that.
When someone says to me, I'm a procrastinator, I say, me too. Are you a selective procrastinator? Because it may not be a surprise to folks listening to this, but I think that neurodivergence in cybersecurity is vastly overrepresented versus the general population. So we've got a lot of us with ADHD, a lot of us on the autism spectrum. And when there is something that is really interesting to us, sometimes it's an itch you can't scratch.
You know what I mean? And so I'm a procrastinator too. I struggle filling out any kind of paperwork, but I can go, you know, 32 hours without sleeping if I find a technical problem that I just have to answer the question to, right? Which probably not healthy, but hey, sometimes that's just how our brains work. And I think that that's okay.
I think that's okay. You can train the interview process like you said. You can train people on security concepts, but you can't train people to be interested and you can't train people to be curious. So if you're curious and you find something that is just like, why does that work that way? That's so weird.
I need to understand that. Then you should be in cybersecurity. That is going to be a field that is going to interest you for a long time. Because there's always something new to learn. Yeah, especially with, like you said in the beginning of this section, how many different disciplines, how many different areas of cybersecurity there are from what threat intelligence to digital forensics to actually what you do with product strategy and technical strategy.
Yeah. Yeah, absolutely. We've got marketing. We've got sales. We've got Anything that would be the same in a very large enterprise for any other kind of business function, we need those kinds of people in cybersecurity too.
We have artists and designers that are working in cybersecurity, and to be able to visualize something and put it on a page in a way that people understand, you need to understand some cybersecurity concepts. Otherwise, it's going to look like nonsense. To be able to have conversations like we're having, Um, you need to be able to understand people, human beings, right? Um, so a psychology background can be really useful. Um, there is— hang on, hang on, human beings?
Come on, talking to a person? Oh, wait a minute here, hold on here, hold on. We've gone too far. We've gone too far calling me human, man. There are going to be people that are going to listen to this and say, you called Frank human?
You are a liar, CW, right? And he's probably just a bot and on TikTok. We know, we know the truth. Exactly.
But you're right, it takes all kinds. You're right. Yeah. Okay, so we've drawn those parallels from different industries, different places. Um, how would you meet those?
I mean, you, you talked here about attending conferences or walking up to people in conferences. Of course, That's one way to do it. Not always that convenient. I mean, we have people that live in remote areas of Colorado here, um, possibly, you know, this podcast goes out to, of course, to people across the nation, even maybe internationally. Maybe it's not easy for them to reach out because they are introverts.
They like to live in the middle of nowhere where they don't have to deal with people. What are some techniques they could use? So I would say, uh, there are a lot of groups, even online groups, Discord servers, uh, that talk about specific, um, challenges in cybersecurity that are full of a lot of people that either can't go somewhere or don't want to and are way more comfortable just interacting with people online. So I would say, um, when you find sort of that niche in security or it doesn't even have to be a very small niche. When you find a group online that follows a similar interest, get involved, you know, and getting involved doesn't necessarily mean, oh, like writing some open source code for this new malware reverse engineering program.
And if you can do that, sure, do that. That sounds awesome. But there are multiple trust groups that I'm part of where I would say 95% of what we talk about is just nonsense. It's memes. And the 5% of stuff that's really hardcore security related is important, but we're just building relationships, right?
We're talking about how we smoke meat, why one mustard is better than another. Sometimes the arguments are silly and ridiculous and pedantic, but some of those are my best friends now and I see them once a year, right? It doesn't have to be in person, but get involved. And getting involved sometimes just means being involved. It doesn't mean being the, the most consistent or important contributor to a project, right?
Well, it's funny that you mentioned that because one of the people that I follow on Twitter all the time, he talks about working out a lot. He talks about honestly cooking and smoking meat all the time. And yeah, That is actually a passion for a lot of cybersecurity people, is that non-technical piece in there, right? That being said, how important are hobbies for cybersecurity people, the people that are already practitioners? I think that hobbies are super important for 2 reasons.
One, it may be a totally non-technical, unrelated hobby. Smoking meats is a great example. I think there are a lot of us that really get passionate about smoking meat in security. It's an odd thing, but it's absolutely true. But there are a lot of hobbies too that I think are interesting from a technical standpoint.
One of the things earlier in my career was I had a manager encourage me to get into home automation with some self-hosting stuff. And that sort of kicked off a multi-year learning project where I was learning the ins and outs of a home automation project. It taught me how to write some of my own first custom scripts. Remember my background, mostly non-technical. I was an intelligence analyst that focused on cybersecurity challenges, right?
And so I think that some of our hobbies can serve 2 functions. They can get us out of the cybersecurity headspace where we can just relax and be creative, do something that's not security related. Which all of us need a break every once in a while, right? But sometimes those hobbies can lead us in a different direction technically and help us level up our skills with, you know, home labs and servers and like me, home automation. Those things I think are really important.
They also connect us to other people too that may or may not be in security, but relationships are what make life interesting. Okay. Well, well, speaking of relationships, what about family? I mean, I think a lot of us have kids, right? And how do you balance that?
And here's a hard question for you. Do you try to get your kids into cybersecurity?
I'm putting you on the spot here right now. Yeah.
I, I hope that my kids get into cybersecurity, but ultimately I want them to do something that makes them as happy and energized as cybersecurity makes me. I hope it's cybersecurity because then we'll have more to talk about. But if it's not, that's okay too. But balancing kind of that family and work life, I think that it takes a lot of discipline and At least for me, sometimes I have a challenge saying no. I got into cybersecurity because I want to make a difference and I want to do good things.
I want to protect people or make bad guys' lives hard. If I can do both, then that's even better. But there are more bad guys working more hours than I could ever hope to, you know, if I wanted to do that every hour of every day, I could. And so I think that for me, over the past couple of years, I've found as my kids are getting a little bit older, I was still in elementary school, but for me, it's making sure that I have a very defined time that I'm going to stop working in the day and that I am going to be interacting with my family and my spouse. I think, you know, the kids are one thing, but being on the same page as your spouse is a critical component of that too.
So my wife, she takes care of the morning routine because I am not a morning person. I hate it. And it's better for everyone if I'm not the one trying to get people out the door. But by the end of the day, she's pretty tired. And so I am, you know, from 4:30 to 7:30, uh, I am the point man with kids.
I'm doing the nighttime routine, I'm doing brushing teeth and reading. Um, we're halfway through The, uh, uh, The Two Towers, The Lord of the Rings. They're very passionate about fantasy right now, which is great. So setting aside some time, and like literally I've got it in my calendar, no one can book anything from that time. Bad guys can still do stuff.
There's an emergency, text me or call me. But if I don't set aside that time, work can just eat it all up. And so I put it in my calendar. That's what I have to do. Okay.
Well, we learned though that, okay, so you're not gonna banish your kids later for not learning cybersecurity, although that would be the preference. Are we sure on that piece that we're not gonna banish them later? You know, I'm still, I'm still, I'm still working through it. You know, I'm still working through it. We'll see.
Well, I mean, I have 2 daughters myself. Uh, one of them has already said wants nothing to do with it, doesn't want to learn about it. One originally had it but changed her mind later and, you know, may pick it up again. Who knows? Uh, but I definitely agree with you.
Um, I want to switch topics real quick to the probably the the last question that I always ask everybody on this podcast here. What is the greatest challenge in security today and how might you address it? Now, we're not, of course, looking for you to solve it, but I want you to call it out.
All right. It's my turn, probably for a little bit of a controversial take here. Now, I think that the biggest problem in security today is security professionals who do not understand the business case for security. We want to make things secure. We want to protect all the users.
We want to protect all the systems. And I think if most of us had our way, we would do that to the nth degree and everything would be so secure that no business would ever actually truly be able to function. We'd get rid of all of the human beings. There'd be no users. And so we'd have no user problems.
Right? I think that one of the biggest challenges in cybersecurity today is that we are really comfortable being, I think, anxious or maybe a little bit frustrated that an organization doesn't want to take security as seriously as we want them to. And we are not spending enough time understanding that that is often a conscious decision from a business that balances the benefit and the risk to the business. And I think that as cybersecurity professionals, if, if we want the industry to get better and we want the, the field to grow and be even, I think, more respected at the business level, then we need to start being able to talk to business cases. And the former CISO, I think, of Levi Strauss said on LinkedIn, this is a long time ago, that he would always ask cybersecurity salespeople, how does your software help me sell more jeans?
And he said all of the cybersecurity sales folks except for a select few would just choke on that because they couldn't even articulate it for him. And that's what— those are the conversations that he had to have with his leadership. How is what you're doing going to help us sell more jeans? If we as security professionals got to a point where we're comfortable asking that and describing the value to the business instead of just the cost, we would be in a much better place with budgets, with initiatives, And I think that we'd get more executive buy-in for the things that we do want to do if we can describe it in the business value that executives understand. And of course, how that compares to other areas of the business, not just selling more jeans, but how many ways that we have to talk to, like, what if communications was disrupted between our business units?
What if you couldn't talk to manufacturing? What if you got the wrong data sent to manufacturing? Right, exactly. Yeah. What about our suppliers?
How do we interact with those folks? How do we justify what we want to do to protect them with our leadership as well? Yeah, it's complex. I think the better we get at that, the better we'll be as an industry. Do you think, because I know supply chain security has been on the uprise or some thoughts about it on the uprise in the last few years, how would you have to sell that to somebody down the line?
What if they're not providing a technical service? Let's say that you have a business that makes jeans, right? Sure. Your supplier, right? You have a supplier that gives you, for example, denim.
How do you make them understand the need for cybersecurity, or is there a need for them to understand cybersecurity? I think it depends on the business. There is a need at a certain level. I was talking, this is like just after we started traveling again after COVID. So maybe 20, like end of 2021, beginning of 2022, something like that.
I was talking to a large company that makes internet products, routers and things like that. And they said that they had over 150,000 suppliers and some of those suppliers for pieces going into this hardware product they make, you know, maybe it's a rivet or something like that. They had 3 employees and they were using personal Gmail accounts. How do you secure that rivet maker so that you can get your product out to market, right? And some of it just ends up being technical controls.
We as a business need to understand the security of our suppliers. If our suppliers are too small or don't have the security, in some cases, we're going to provide it to them as effectively a managed service provider. Not every company is going to be able to do that. These guys are obviously huge. But that's the way that I think that we need to be thinking about it is Beyond the technical controls, what are things that we can be doing to make it easier for our supply chain to be more secure?
And how do we prioritize that? Can we look at technical sources that help us understand our supply chain? And then we can prioritize those that have the potential business impact that if something bad were to happen would have the biggest impact for us, right? Rivets, we might be able to source that somewhere else. But a special wafer silicon, maybe they're small, but we're not getting that many other places.
We need to take a special way that we operationalize security with that supplier. Wow. Well, you know, I think we could be talking probably for the next 2, 3 hours about this, and I would love to, but we are actually coming to the end of the time here. Robb and Alex always limit me to you know, just under an hour or something like that. And I think we're right there.
Any final thoughts? Any final comments?
I will say as a final comment that I am looking forward to running into you at a conference here, hopefully sometime soon, and getting to meet face to face. And I hope that for folks listening to this, If you end up being at a cybersecurity conference, check and see if I'm there. I'll usually post on my LinkedIn when I'm at a conference somewhere. I'd love to meet up with folks. And let's try and make the world a little bit of a better and safer place for our families and our friends together.
Okay. Well, you can find CW on LinkedIn. He's under CW Walker. Of course, you did mention conference. We have Denver's premier cybersecurity conference, the best conference ever coming up, SnowFROC.
I, yes, I am biased, but that is going to be on March 14th, 2025. Our theme is going to be Don't Let Hackers Get a Piece of Your Pie, since it is, of course, going to be Pi Day. And I hope to really see you in person there, CW, along with— I think we have almost 300 people registered so far. We only have about another, what, 75, 80 tickets available. So again, yeah, yeah, I hope I'm able to have everybody listen to this podcast at that conference.
Fantastic. Yeah. Well, again, thank you again, CW. My name is Frank. I am with the Denver OWASP Group.
Please check us out again at SnowFROC. That's SnowFROC. Uh, you can also find us at the Denver OWASP Group, both on LinkedIn. And again, hope to see you in person. So thank you again, CW.
It's my pleasure. Thanks, Frank. All right.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about the Colorado Security Association. More about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.