Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 273. This is for April 7th.
Alex, it doesn't feel like spring has sprung right now. I mean, it's a perfect spring day, Robb. It's cloudy and, you know, a little bit of snow, cold. Like, isn't that what spring's all about? Yeah, we got snow on the ground, a little bit of snow.
We're recording on Friday, so, uh, those listening, maybe by Sunday the weather is perfect. Maybe it is. Um, this is open, but this is a home opener for the Rockies, right? Don't you wish you were sitting outside at Coors Field right now? Yeah, I'm sure everyone there is super happy about it.
Especially the scalpers who probably can't get rid of their tickets. Oh my gosh, yeah. People overpaid for tickets they can't use. Yeah. The one day of the year that the Rockies are popular is today.
Exactly. Oh well. Speaking of popular, did you know that we have a Slack channel where we have so many of our best friends talking in all kinds of different channels? I saw people talking about how to build your own VC SOB practice recently. Folks talking about some recent security news as well.
Lots of good stuff going. If you want to join Slack, go out to colorado-security.com and click the Slack button. While you are there, you can sign up for the mailing list. You'll receive things like notification when there is a new podcast available and the show notes. Uh, you also will have gotten notification of our, uh, 2025 salary survey, which is in process right now.
So you should definitely sign up for that mailing list. We'd also love it if you go to your favorite podcast player and rate and subscribe so people know how good the podcast is and you get it delivered to you every time we have a new episode. Big thanks to our patrons. We do have a Patreon campaign to help pay for the cost of the podcast. We have folks who have been doing this for years.
We salute you. Thanks so much for your support. Speaking of support, we also have some annual sponsors. It's a new thing for us this year. We'd like to thank Armis, CrowdStrike, and Zscaler for their ongoing support of Colorado Equal Security.
Fantastic. Let's jump into news. Alex, I think we talked about this as it was a potential maybe a few months ago, but it is, you know, breaking news. Colorado, specifically Boulder, has landed a prestigious film festival. Yeah.
So Sundance Film Festival will now be held in Boulder, Colorado, starting in 2027. And I think while it's technically Boulder, you know, we mentioned, I think in the previous article that there's a, you know, sort of a film center going in at the Stanley Hotel, you know, towards Estes. And I think that's going to be part of it and all that kind of thing, too. But very exciting news. Obviously, having Sundance come to Boulder will be a boost to the economy and should be a pretty cool thing.
And then, you know, just moving one state to the east. So it's not too, too big a movement for them coming here from Utah, but obviously a big improvement in terms of quality of life. Next up, we have an announcement of a new grocery store chain that is coming to the Denver metro area. You know, I think I've seen the name, but I really don't know anything about this until, until this article. WinCo is the name of the grocery store.
They are an Idaho-based store, apparently very popular. People love WinCo is what I'm learning. Yeah, it sounds like it's a little more bulk-focused, you know, maybe more of like a Costco or a Sam's Club or something like that. But, you know, more kind of in between, more of a grocery store, but also sort of bulk items, but not a membership-based, but not a membership store. One of the interesting factoids in here is that WinCo is owned and operated by its employees.
It is not an investor-owned business. That's pretty neat. They're gonna be putting it up in Thornton, in T-Town, as they call it. Is that what they call it, Robb? They do.
Yeah, I'm excited for this. You know, with the, you know, still, I think, potential that Albertsons and Kroger could merge someday. It's always nice to have more competition. And so looking forward to having a new grocery store chain here. That's good news for the consumer.
That's us. That's us. Speaking of good news for the consumer, did you know you could get 100% recycled flying discs? Did you know that that's a thing? That is very exciting.
The company called— sorry, I just kept wanting to say trash panda. I know. I really want to say it too. Tash Panda. They make frisbees, although I, I, frisbee is, I think, still technically a registered term.
It's like Xerox, right? You can't, you can't say that. Flying discs, flying plastic discs. They make flying plastic discs. You want to play flying disc golf?
Yes. You might buy a Tash Panda flying disc. And apparently, not only do they make recycled, make them from recycled plastic, they are headquartered in Denver, Colorado. They are. And not just— they don't just make them from recycled plastic, 100% recycled plastic.
They have signed a lease on a new facility to expand production. They talk a little bit in here about the origins of the company and sort of the, the manual process that they had to do for their, their founder to do, you know, injection molding with his own, you know, body weight to push the plastic through the molds and things like that. Now they've got a couple new Uh, injection molders. And, uh, they can do, I think they said basically one disc a minute, uh, which, which makes them, uh, recycle, I, I think it's a pound of plastic every 2 and a half minutes or something like that. It's pretty, pretty impressive.
Um, I, I, I do have a, a slight errata. It's actually Trash Panda like we thought. Um, it is a typo in the article we're reading. Oh, okay. Because, because, you know, editor editors have, you know, gone the way of the dodo.
It is Trash Panda and their logo is a little, uh, a little trash panda, a little, You know, uh, thank you AI editors. Thank you for that. So it is neat to know about a new company that's growing 3x in the last year or so. Uh, fantastic stuff. And I know a lot of disc golf folks will be glad to know they can go directly to the factory and see the opening house coming up soon and see how they're made.
Yeah. Uh, moving on, we have some other, uh, local company news. Um, I guess it still is technically local company now. Um, Angie's List, which is now known as Angie, is now being spun off into, um, a, uh, a wholly owned company again instead of being a subsidiary. Uh, several years back, HomeAdvisor and Angie merged and, you know, became part of a, a holding company, and now they're, they're spinning that back out into its own company.
Yeah, they're profitable, they're growing, um, and they are headquartered here in Denver. I love to see local companies make good. We've known some of the folks over I think mostly from the HomeAdvisor side previously, but we've known folks at the Angie company over the years. They do good work and we're looking forward to seeing them keep growing. Yeah, I think, wasn't it HomeAdvisor was based here and Angie's List wasn't?
Yeah. And then obviously now it is based here. But now it's just Angie. Now it's just Angie. And it is a freestanding company that's going to go crush it in the next year.
Speaking of things you can crush, do you remember how we've talked about this for several years, right? Ball Company, Ball Corp, was— had created these aluminum, re— uh, easily 100% recyclable, um, cups for us to use like at stadiums, at Ball Arena and Mile High and all that, to take the place of like basically your red Solo cups, I think. Well, there's some big news coming from Ball about those cups. Yeah, so, uh, similar I think to the Angie story, uh, Ball Corp is spinning out the aluminum cup division into a separate company, which is a joint venture with another company, which has more experience in this particular market. So sort of reading between the lines here and kind of towards the end of the article, it sounds like there's a cash drain on Ball Corp from this aluminum cup business.
And so they felt that it was better to spin this out not have that drain on the, the, uh, the parent company and, and have a separate company to go, go forward and, and build this brand. Joint venture— they're still, you know, they're still an owner of the joint venture and, you know, still behind the success of this thing, but it is pretty different from what they've been doing. It's more consumer-focused. Cool stuff, and I'm excited to see this business continue to thrive. Uh, the, the last sentence in the article, uh, goes to my part about the cash drain.
Chief Financial Officer Henry Yu previously referred to the cups business as a $40 million drag. I thought you were about to say the CFO, upon hearing the news, said, Yahoo! Yeah, I'm sure he did. All right. Moving over our next story.
We love to do follow-ups on companies we've talked about in the past. And that's what this is. We've talked about Crusoe Energy Systems in the past. They are that company that sits in an oil and gas field and takes the exhaust off of burns. To, to turn it into cryptocurrency.
Right. They use that energy to mine cryptocurrency, which is such a cool idea. You know, I, you know, rather than making the Earth a worse place as you mine cryptocurrency, maybe you can make it a neutral place. Yeah. Yeah.
Pretty cool. Things that would have been wasted now can be used to mine cryptocurrency. And so Crusoe, they've had an exit, right? Yeah. So this is another spinout.
So apparently, you know, so they started doing this part of the business, but they have expanded over the past years. And they now also build data centers for, for AI. So obviously that's a big, big thing right now. People need more and more data center space for, for AI workloads. And so they are spinning out and have sold the, the off-gassing part of their business to a, a New York firm that will continue to run that.
And Crusoe will continue to do the AI data center part of their business. So that's going to have 135 Crusoe employees moving over to work for the New York Digital Investment Group. And it sounds like, you know, at least for now, the headquarters stays in Colorado, although, you know, who knows what that looks like in the long term. Yeah, who knows? All right.
Moving into our security stories. The first one we have is a blog from Ping Identity talking about 5 critical insights from the State of Trust Summit. Robb, were you aware of this State of Trust Summit? I was not aware of it. I feel like I should have been aware of it because I'm a big fan of states.
And trust. Yeah, and summits. And summits, that's true. Um, the— this article is actually written, at least the byline is by Andre Duran, the founder and CEO at Ping Identity and a friend of mine. Um, and actually, you know, I don't always love the blogs we go through.
I actually really liked this blog and thought it had a lot of good insights. So he, you know, he went to the summit, which sounds like it was a virtual event, and he captured the 5 key things he found. I want to highlight You know, I think we can go through all 5 at a high level. You know, trust is in crisis and it's getting worse. And I think that this is obvious to all of us as we, as you see the, you know, how close AI-generated content is to unrecognizable from human-generated content at this point.
We're not quite there yet, maybe for video, but man, we're not too far off either. And okay, what does that turn into when you use, you know, phone calls and video calls in order to make big decisions? You know, how do you get there? And that, that trust being in crisis rings true today, and it's going to be even more true in the future. They go into some things like the trust pyramid, how trustworthy are the different parts of our stack.
You know, infrastructure may be a little bit more trustworthy than apps at this point, and identity needs to be the most trustworthy. And I love this graphic, the 3 critical threats to digital trust. And I think that if we don't, you know, if you take nothing else away from it, thinking about, you know, deepfakes, as they threaten us, quantum as it threatens the current state of encryption, and our third-party access risks. The fact that, you know, we can't control what our third parties do. Those are the key 3 things that they believe really challenge trust.
Yeah, I thought it was a good blog as well. I thought that the last piece was interesting, number 5, user experience and trust must go hand in hand. Um, you know, I, I think in the past, you know, we might not have thought of the user's experience really in the relation to trust, but now as, uh, as we trust what gets presented to us less and less, really that user experience does rely so much on trust. And, uh, and some of the things that they mention here, um, progressive profiling, adaptive access, things like that really are going to be important in maintaining that trust as part of a user's experience. And somehow getting trust that we know that that's really Alex while not making it such an arduous thing that you're just not gonna bother using the service, right?
Right. Like, we— that's the progressive profiling. And don't make me fill out a questionnaire all at once when I sign up to your service before I can use it. Over time, learn my profile. And like, it's ways to do these things that, that are less intrusive from a user experience perspective.
Anyway, I thought it was a great post and probably a really interesting conference. Or maybe he just got the best parts and it would have been terrible otherwise. I don't know. A good summary of the The 12 hours of things you'd had to slog through to get those 5 points. Either way, interesting.
We have one more blog post, and this one is around Google's acquisition of Wiz. Well, Wiz is not a Colorado company, and neither is Google. So why do we have this article in here, Alex? Yeah, so this is a Red Canary blog, and Red Canary is a, is a big partner with Wiz. I believe that they're a Wiz customer also.
But, you know, Red Canary does, uh, security monitoring, and now with, uh, more and more, uh, cloud and the need for monitoring cloud, there's, uh, there's an MDR play for there, there for them as well. So I think there's— that's where this is coming from. Yeah, they're talking about the— what things Wiz does a fantastic job of, a visibility perspective, um, and, and what they don't do a great job of, you know, the actual stopping of things and, you know, as they're happening, right? Cutting off attacks in the moment. And, you know, it turns into a little bit of a commercial for Red Canary, but I think they're basically showing how, how a company, a product like WIGS and Red Canary can be complementary.
Most definitely. All right, that is news for us this month, but we do get to now roll over to our calendar of events. A reminder, if you want to go see all of the events coming up over the rest of the year, go to colorado-security.com. Click on that event calendar and see what's coming up. Awesome.
First on the list, uh, April 9th, ISSA Denver is doing an event, Insider Threats: A Hacker's Perspective. On the 6th— or sorry, the 15th, CSA Colorado has their event, Securing the Cloud: Attack Vectors. Uh, I know you really wanted to say the next one, which is on the 16th, and that's Denver OWASP doing the Attacker's Distributed Supercomputer your browser. What? That's my browser.
On the 17th, we have a couple of events. ISACA Denver has their annual general meeting, and the Let's Talk Software Security group is getting together, talk saying, uh, or the topic is, can't we just automate application security? Yeah, can't we? I think we probably can. Maybe we should go and find out.
Uh, and then finally, on the 23rd of April, ISSA Pikes Peak is doing their monthly chapter meeting. Yep. Well, we are, uh, we are done with newscast. We are keeping it short this month. Alex, you did have an interview though.
What do we got coming up? Yeah, uh, I spent some time talking to Nipun Mahajan. Uh, Nipun is the executive vice president for the ISACA Denver chapter and also, uh, is the one of the co-chairs for the Rocky Mountain Information Security Conference this year. So we talked a good bit about RMISC. Speaking of which, I think that early bird pricing for RMISC is about to close.
You better sign up if you haven't already. And maybe by the time you hear this, that's too late. But that, that's all right. You know, you can still sign up anyway. Send them a note and say Alex said you could have— that's right.
Tell them that, that Nipun said you can get early bird a little bit longer because you heard this episode until we'll say Monday the 7th. How about that? All right. That is it for the newscast. Enjoy the interview and we'll talk to you guys in May.
Thanks, Robb.
Hi, this is Jesse Bertoli, CISO of Pinnacle Assurance. Welcome to Colorado Equals Security, for Colorado security professionals by Colorado security professionals.
Welcome to Colorado Equals Security. This is our feature interview and I have a special guest with us this week. We are speaking to Nipun Mahajan. Hey, Nipun, how are you?
I'm doing good, Alex. How are you? I am wonderful. Thanks for taking a little bit of time to talk with us. I think, you know, the biggest reason that we are talking is that you are one of the committee members for the Rocky Mountain Information Security Conference this year, and we're We're going to talk about that for a little bit, but before we get there, I wanted to dive into your background and your journey in security and learn a little bit more about you.
So maybe if you take a minute and introduce yourself and tell us who you are and what you do. Oh, thank you. I'm really excited to be here and share a bit about my journey, not just where I have been, but how each step shaped my thinking as a security professional. Let's start off with how I started off. I joined IBM in 2010, and this was my first major leap in the enterprise tech world.
I was working on a global SAP rollout, helping Fortune 500 companies to manage their SOD and access controls. And post that, I got to work with Deloitte for like 5 years. And like this was getting involved with a lot of IT risk compliance and internal controls things. So after working in Deloitte, I had a change of mind and I thought that, okay, I need to do something different. So I decided to pursue my master's in information systems from Colorado State University.
So I wanted to get more background on cybersecurity, not just SAP security. So CSU really helped me pause and reflect and develop a long-term vision on what I need to be. And this actually led to my current job with the biopharmaceutical manufacturing company that's based in Switzerland. So where I am currently serving as the senior cybersecurity analyst. And Alex, just to, just, just to let you know, Colorado Security was one of the reasons that I got to be in the core SOC team because I reached out to some of the members in Colorado Security and they actually helped me out to get in to start off with more SOC-related work within my current employer.
So that's how I got into core cybersecurity work. So outside of my work, I'm also deeply involved in the community through ISACA Denver chapter. I'm the current Executive Vice President of the chapter. And with that, I also get the responsibility of being the co-chair for the Rocky Mountain Information Security Conference. That's a little bit about myself.
That's awesome. I'm excited to hear that Colorado Equal Security was useful for you and your journey in getting to where you are today. I am curious, you know, how is it that you got into the focus around SAP security to begin with? Were you originally on the financial side and then kind of migrated to SAP and SAP security? Actually not.
So I'm an engineer by background. So I had did my bachelor's in technologies from a reputed college in India. And I got campus placed at IBM where they trained us on SAP security and SAP Basis that's responsible for the infrastructure part. But that's how I got to know about SAP. Awesome.
I know everybody, well, probably everybody knows what SAP is. But maybe if you could give us a little background generally, you know, SAP and what security around SAP really means? So now it's a very good question, Alex. And so one of the things that we need to know about SAP is that it's present everywhere. So even if you're going to Walmart, right, there is an SAP system that's making sure that your product reaches out to you.
What SAP is, it's a major resource and planning tool. So we're talking about the management of finances, procurement, HR, manufacturing, supply chain logistics, and so on. And shutdown in SAP in large enterprise, you're not just disrupting the IT, you're also halting the business. So there will be a lot of things that would happen if an SAP system goes down. Planes might not take off, and drugs might not get manufactured, and the payroll might stop.
So that is the reason it's mission critical. And essentially, there's a need for everyone to also consider SAP cybersecurity and get them involved, get the team involved to look at SAP systems as well. Yeah, and I've had a little bit of experience with security around SAP, and I know that the way that those systems are architected, while, you know, there are some common things that a cybersecurity professional might recognize, SAP is kind of its own beast and trying to secure SAP is a very different specialty than maybe a network security or cloud security sort of job. So what sort of threats are there or what sort of things are you doing or an SAP security person, what are they doing to make sure that SAP is secure. Yeah, I mean, I'll just add here on what you just said, like there's a lot of things involved with SAP and cybersecurity within it.
So the first thing that we need to understand, it's very different from traditional IT security. So it's not just about firewall, it's not just about access. There are a lot of other components that you would have to validate in SAP systems. Now let's talk a little bit about the most significant risks that might be relevant for SAP systems. The very first and most common is the internal threats.
So often organizations focus so much on external threats that they overlook the risk posed by the insiders. Now, as I told, right, there is so much critical data that is present in SAP systems. For example, PAII or And there might be some employee or contractor with access to the sensitive data and whose misuse can cost the company a lot. So another risk that I see is that because there are so many components involved, there is an application layer in SAP, there is an operating system and the database. Often these are overlooked.
And you see that all these, a lot of times, all these systems, SAP systems, are outdated, have outdated patches or configuration, and that leaves them exposed to known vulnerabilities. I don't know how much, Alex, if you are exposed to the current SAP landscape, but there are so many CVEs 9 and above notes that are being released that you will be surprised that companies are not even looking at it right now. And another risk that I see is that there is a lot of unauthorized access. So what eventually happens is that SAP could interact with your different systems. And even if the attacker is able to get into one system, it can potentially get unauthorized access to your SAP systems, and that could lead out.
Leakage of your very critical data. So that's something I think are the most significant risks for SAP system. Yeah, I also know in the past, SAP was a big complex thing that you deployed internally on infrastructure you hosted yourself. Some of the things there were secured in traditional ways just by keeping firewalls closed and that sort of thing. But I know that SAP has also made a big cloud move like many other companies have.
Does that move to the cloud for SAP and them hosting many of the things themselves, does that change what security looks like for SAP as well? Exactly. I mean, you nailed the point here because, I mean, initially SAP systems were not interacting with any other systems. It was just a solar system working and you didn't have so many threat actors involved. So the movement from cloud, from on-prem to cloud, this is called as their S/4HANA RISE offering.
So as things go to RISE, there is something called a shared responsibility model. So wherein SAP is responsible for maintaining the infrastructure, the OS. But at the same time, Alex, there are other things like patch management of your application, or I would say authorizations. This is something that still the companies have to do them. Have to do themselves.
Now, the general understanding that I've seen is that SAP will do everything if you are in cloud. So that is not the case. So the concept of shared responsibility is something that everyone should know about. And even if you are on cloud, it is your responsibility to make sure that the system is protected. And compliant.
Yeah, speaking of compliance, SAP is obviously, you know, does a lot of financial transactions and, you know, manages a lot of the underlying important functions of a business. I'd imagine that there is a pretty big compliance burden for people that are trying to secure SAP systems. Obviously, Sarbanes-Oxley, Maybe PCI, maybe some other compliance. How does the compliance landscape for SAP look? Yeah, I mean, depending on how, what kind of components you are using in SAP for, you talked about a little bit about SOX, right?
So SOX does strict requirements on financial reporting, which means that SAP systems must be auditable to ensure transparency and compliance. So within financial controls. So every year, if you're a US-based company, you will have to go and undergo the SOX audit. There are other things that you need to look into because a lot of companies have presence in Europe, and GDPR does require business to protect the privacy of EU citizens, which means that the personal data is encrypted and only accessible to authorized people. So organizations need to implement the controls and the procedures that align with these regulations.
And SAP has a very specific module that's called Governance Risk and Compliance. It's GRC that helps business automate their compliance management, do regular audits, as well as strongly access control policies and data protection measures. Measures across the board. Yeah, that's good. It strikes me that, you know, being in SAP cybersecurity, it's a little bit niche, and I'd imagine that some of the skills that you have to have are slightly different than a normal cybersecurity professional.
You probably have to understand finance a little bit better than than many security professionals. Are there specific skills that you feel like make you successful in this area? And also, you know, sort of adding on to that, is the reporting structure for an SAP security person normal? Like, are you part of the bigger cybersecurity team, or is that sort of a sub-function that reports to, say, finance or something like that? But that's a really good question when it comes to reporting.
So Alex, what happens is that in a typical SAP landscape, a lot of times SAP cybersecurity is overlooked. And there's the SAP security team actually reports to compliance side of the house. But in my current job at a pharmaceutical company, I report to my CISO. So what my current role is that I am part of the SOC team. So that means if our SAP systems are connected to the SOC and all those events that come up from SAP has to also be reviewed by the IT security team.
So if you consider SAP as a crown jewel, right, you will give that equal weightage in terms of protecting it as well as monitoring it. So that is where the need is to make sure that IT security or your CISO knows about the risk that could come up if the SAP system is not protected well. Now let's talk a little bit about why this skill is a little niche. Because as we said, right, there is so many things involved in SAP. There, let's talk about the database.
So SAP came up with this own database that's called HANA. So it's an in-memory database. But there are a lot of privileges that a normal IT security team will not know about. Similar to that, there is a programming language that's called ABAP that's specifically used for an SAP system. So only if you know about the ABAP language, then you can actually decode if the code that was written in SAP has something malicious or not.
So it could happen that your ABAP code or a report that sits in production might have an SQL injection, and that could compromise the system security. So it's, I would say that definitely it's a very niche skill. And for me, because I had an SAP understanding and I also got my CISSP, this made me actually get into this role where I support the SOC team as well as make sure that SAP system is secure.
That's super interesting.
Is SAP security, is it something where they're looking for more people in this area? You know, obviously you hear a lot about, you know, cloud security, about, you know, application security, about lots of, you know, hot roles that people are trying to hire for. Is there a shortage of people in SAP security since it is so niche? Yes, yes. And I mean, there's so many companies who want to implement good controls when it comes to SAP security and/or cybersecurity, but there aren't that many people.
So, so there are job positions you would see specifically for cybersecurity when it comes to companies nowadays. One thing I would say, Alex, this is something that's SAP cybersecurity or something that came up in the last 5 years. It was not always present. So for that reason, not many people know about it. But now there has been a trend where companies are looking, making sure that they, they have a team member who knows about SAP system within their IT security team.
So it's a good area to look for a job.
Awesome. All right, I think I'm going to switch gears a little bit. I appreciate all of the, the info on SAP security, but I think we're going to shift a little bit and talk about some of your volunteering work. So you mentioned that you are on the board for the ISACA Denver chapter. How is it that you got involved with ISACA?
No, this is a fun story. I'm not sure if you know this. There's a person called Danny Collins, and he was one of our directors when I worked for RSM. And he actually gave us presentations on the volunteer groups that existed in Denver. And he talked about IIA, ISACA, ISSA.
And that very day, I just went ahead and filled up the form to be a volunteer at ISACA. So I think it was 2019. And just filling up the form, right, I got the opportunity of being a volunteer for the academic relations. So after that, I got to be on the board as the academic relations coordinator. So this actually helped me a lot.
So I have built, I have built the academic relations community at ISACA Denver chapter. We're involved with so many colleges across Denver, CSU, UC Denver, UC Boulder, Regis. So we support the professors around Denver, just making sure that they have the right people to act as presenter. Or if there is a cybersecurity club that wants to organize an event, We try to make sure that they have pizza so that students could come and at least have a good time and also get to learn a bit. So that is how I got into the board.
And after 3 years working in the academic relations, I got into the EVP position. And after that, I am serving as the a co-chair for the Rocky Mountain Information Security Conference. That's awesome. As you know, and some people probably know, you know, I volunteered for a long time on the ISSA side and was RMISC co-chair for a number of years. So I appreciate the amount of work that you do as a volunteer for ISACA and a board member, but also working in, in the RMISC and the work that that takes to pull off such a large conference.
We're going to talk a little bit about RMISC. But before we do that, I know that most of the organizations here in town, ISSA, ISACA, run on volunteers, and we need lots of volunteers to help those organizations run. If somebody wanted to volunteer for ISACA, how is it that they would get in contact? With the ISACA Denver chapter? So it's pretty easy actually.
If you go to the ISACA Denver chapter website, there is a Contact Us page and you could reach out to the president or any other person you wanted to talk to. So, and we're pretty good on the responses. And if you want to volunteer, we have a lot of good open positions right now. So feel free to just reach out to us by going to the beach. Awesome.
Well, let's talk about the Rocky Mountain Information Security Conference. It is obviously something near and dear to my heart, and I think the, the best overall conference here in Denver. You know, what are we looking forward to for RMISC this year? When is it? How long is it?
What's happening? Yeah, I mean, RMIC, as you said, is the largest information security event in the Rocky Mountain region. And what makes it special is that it's built by the community and it's for the community. And we focus on practical, real-world content that the security professional can take back and apply immediately. So whether you are in audit, GRC, threat intel, or engineering, Rocky Mountain Conference, Information Security Conference, is the place to go.
So this year, RMIUC25, it's happening from May 28th to 30th of May at the Colorado Convention Centers. And we are really raising the bar. First off, we are incredibly excited to welcome our keynote speaker, Brian Krebs. I'm sure you might have heard about him. So I mean, for anyone in cybersecurity, Krebs is a household name.
His work on Krebs On Security has exposed some of the biggest breaches, cybercrime groups, and flaws in digital systems. I really think that this keynote is going to challenge assumptions, spark discussions, and deliver a rare inside look at how threats are evolving on a global scale.
Yeah, that is super exciting. I know a number of years ago, we RMISC had Brian as a keynote and it was great back then. That was kind of just before he blew up to sort of the global status that he is today. And it'll be interesting to have him back to hear more from him now that he is such a celebrity in our field. What other things are happening at RMISC this year?
Yeah, so there are a couple of new elements we are bringing this year. So one of them is the Authors Alley. So this is a space where published security professionals and thought leaders will be able to do an informal chat and do the book signing. So it's a great opportunity to learn directly from the people who are shaping the way we think about security leadership and innovation. Another thing that we are about to begin this year is called Birds of a Feather.
It's a smaller topic-focused roundtables where attendees can gather based on shared interest or challenges. So whether it's identity management, AI security, or cloud narratives. So these sessions are all about learning, and this will be done during the lunchtime. So you're going to eat and also have those discussions in those roundtables. Oh, that's awesome.
The author piece is pretty interesting. Do you guys already have your roster of authors set, or if someone is an author and they want to be part of that, can they still be part of the author alley? Yes, I mean, we're still open. We have our roster, but we are open to have more people who, if you want to sign up, you can either reach out to the ISSA chair or to me and we can get you connected the right people. Oh, that's great.
Um, so, uh, I know that, uh, that I know, but if someone wanted to attend RMISC, um, where do they get more info? How do they register? All those sorts of things. Yeah, sure. So, so we have a website called, uh, it's www.rmisc.org, and you can just go in there and register as an individual.
We have discounts if you— we have a group discount if 10 members from the same company join us. So that's something to look into if you are a bigger group and want to send a lot, like 10 folks or more, to RMISC. One of the things I am very passionate about is our volunteers that helps run the the conference. And there is this volunteer group called Goon Squad, Alex. And what this Goon Squad does, it helps you organize the rooms where all these lectures happen.
Now, the advantage of this volunteer, or as a goon, is that you got to volunteer a whole day and you get free pass to the conference. So if there is someone who thinks that I can volunteer a day and it's I would be able to get into a conference without any cost. So something to look into. And this is the message that actually we are giving to the students around Colorado. Like, you know, right, there is shortage of money always.
So this is a great way. I would say you get to volunteer as well as network with some of the greatest minds we have across Colorado.
Awesome. Yeah. And, you know, as I said, for ISACA, you know, RMISC runs on volunteers also. So, so yeah, if people are interested, volunteering is a great way to get to RMISC. And I know that there's always a need for people to volunteer.
So anything that we missed talking about RMISC, Nipun? I think we covered a lot. So I just hope people from Colorado will show up and we'll have a good time and Definitely, there are some very good sessions that have been planned for AI. There's some tracks already available, and the speakers list is already available on this website. So as you volunteer, make sure— as you register, make sure that you look at what are the sessions that you would like to go into.
Because just for an example, we were talking in the board meeting yesterday. There was one session for which like 150 people wanted to attend. And those are the things, right? So it helps us to plan better what kind of room availability, what's the size of the room we need to get available for that particular session. So as you register, make sure that you sign on the sessions that you would like to be part of.
Awesome. Alright, any other topics you wanted to cover, Nipun? Oh, I think I'm good. One of the things I wanted to highlight, Alex, is that the ISACA Denver chapter— so I told you I'm working a lot with academic relations. So the ISACA Denver chapter just received the Global Innovation Award for Education in its work for academic relations.
So our board members get to go to Orlando where we get the prize in May. So I'm super excited for that. So I really want to thank all the professors and students for making this happen and look forward to your presence at RMIC. That's wonderful. Congratulations to the ISACA Denver chapter.
You know, as long as I've been around Denver, the ISACA Denver chapter has been, you know, a great community organization and really one of the strongest groups around town. So great to see another recognition of that. So, well, thanks again, Dipun. Appreciate you coming on for the interview. Appreciate all of the background on RMISC and your background.
Also makes me super happy to know that you're a great member of the Colorado Equal Security community and that it's been helpful for you.
I'm sure if folks want to reach out to you to learn more about you or anything that you talked about today, they may want to do that. Is there a best way for people to get a hold of you? Yeah, I mean, LinkedIn is one of the best ways for people to network. So send me a request on LinkedIn and I'll be happy to answer any questions you have. Awesome.
Well, thanks again. Appreciate your time. This has been Colorado Equal Security and we will talk to you next time. Thank you.
Learn more about the Colorado security scene at colorado-security.com where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.