Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for episode 277 for August. Alex, August, can you believe it?
Man, this summer has really flown by. It's hard. Well, in one sense, it's already over. My wife, who's in education, is going back to work already. So, oh my gosh.
So summer's technically over in one sense, but yeah, it's really going fast. Well, it's not over until the Colorado Equal Security Summer Picnic has happened. That's true. So it's not over yet. But before we jump into that, do we have some housekeeping?
We do. As some of you may know, we have a Slack channel. If you're not in the Slack workspace, we'd love for you to join. Uh, go to the website. There is a signup form there.
You can sign up for the, uh, for Slack as well as the mailing list in one single click. Um, and then we'll get you all going. We'd love it if, you know, while you're listening, while you're thinking of it right now, go do a quick, uh, rate us on your favorite podcast player, subscribe, tell a friend, help us get more folks into the community. We love to grow the security community here. Yep.
Speaking about the picnic, we do have our summer picnic coming up August 23rd. We'd love to have you there. If you haven't registered already, go check out our event calendar. There is a link there where you can register. You know, you can also just show up, but we really want to know how many people are going to be there so we can get the right amount of food and drinks and that sort of thing.
Please let us know so we buy food for you. Exactly. Before we jump into the news, we just want to do a big thank you to our annual sponsors. New thing we've done this year. These groups are helping keep Colorado security going.
So thank you to Armis, to CrowdStrike, Red Canary, and Zscaler. Very good, good stuff. All right, so much for stories. Yeah, let's jump in. Uh, so Robb, I think we may have teased this before, but, uh, it is actually here now.
Colorado is getting a new area code and it's about ready to roll out. Yeah, it's good stuff. It's, uh, coming out on the Western Slope, right? Um, the, the folks, the folks who are in 970 today are gonna potentially get 748 as their area code instead. Yeah, it sounds like sometime in 2026 they will run out of new 970 numbers, so they'll definitely have to start doing it by then.
But I think, you know, as we've seen, uh, when 720 rolled out with 303, you know, it's kind of both for a little while and then eventually, uh, no more 303s. So you, you know, you get 720s. So, I mean, honestly, the, the big, uh, mic drop for me in this story was not about the new, uh, the new 748. It was about the fact that there actually is a third in the 303. We know 303, we know 720, but I didn't know or remember that we also have 983, which is the same Denver area area code.
Did you know this? You know, um, it's funny. They say that as part of the article, that the last time we got a new area code was 983. But in some of the other parts of the article, they don't talk about it. And I have never ever heard of anyone with a 983 number.
So I don't know if that like was a false start. And they started to roll it out and then they didn't. And that's not talked about in the article or exactly what happened. Or maybe it really is. But, but if someone has a 983 number, I'd love to hear about it.
Yeah, it It looks like, you know, there are a number of other stories that also say 983 is a Denver overlay with 303 and 720, but I've never seen it. If you have it, let us know. We're curious. Anyway, that's the big news on the Western Slope. That is big news on the Front Range.
Nederland is going to buy Eldora Mountain Resort and will have a municipality-owned ski resort. The city of Nederland is is paying it. They estimate somewhere between $100 and $200 million to buy Eldora that will be paid by bonds that they plan to pay back using like on-mountain, you know, lift tickets, lift tickets, yeah, parking and all that stuff. Kind of interesting thing. This is to me, you know, they mentioned a couple other cities that own ski slopes here, but this is the biggest one that I've heard of.
The rest that they mentioned, I'd never heard of the slopes. And this Eldora is a, a good-sized one that's local folks, folks like quite a bit. Yeah, well, I think technically Denver owns Winter Park. I think they owned— I don't think they do anymore. Is that wrong?
I feel like they maybe still own it, but like basically have nothing to do with it. I don't know, maybe I'm wrong there. At the very least, they used to own it. But yeah, I found this interesting because when there was first talk of Eldora Mountain being sold, like someone, I think, sort of offhandedly said, well, maybe Netherland should buy it. And then someone in the leadership at Netherland was— or yeah, in Netherland was like, oh yeah, maybe we should buy it.
And then here we go. They are buying it. It's pretty cool. They're looking to annex the slope as well. It's not actually officially in Netherland.
It's just near Netherland. So they're trying to annex the property, which would allow them to have a little bit more control over the area. Pretty cool idea. I personally think You know, if you can have a thing like this owned by, by your city, it's just a good thing for the city and maybe, maybe a little bit bad for the capitalism. But I think generally a nice thing.
I think with the way that prices have gone for, for Lyft tickets, it's probably good to have this community and municipality owned. All right. Well, our next story is— I think we talked about this trend recently around the Denver housing market. The housing market inventory has hit its highest level in 14 years. Yeah.
In June, because we're doing a little bit of a look back here, there were 14,000-some-odd properties that were available. And that, as you said, is a high for a number of years. There's lots of other stats that we have here as part of this article. The The pending sales also are down, which is weird considering that there is more inventory. But it's— it is a great time, it seems, if you are buying a house.
Best time in a while to actually do that. Well, maybe because the prices have not gone down, right? Like consistently prices have been going up. And so you think, well, how can you say there's more inventory, prices are going up? But sales have been going down.
Well, what's happening is time on market has been going up. People, the sellers, have been unwilling to compromise on their price. So they're seeing their houses sit on the market for quite a bit longer. So in some ways it's good, meaning there's more inventory to choose from, but you're not getting much of a discount right now. Yeah.
One of the other things that I noticed as part of this article is not related to house sales directly, but— and we've talked a little bit about this, I think, in the past— is that migration trends in Colorado, there are actually more people leaving Colorado than coming to Colorado, which I, you know, I don't mind at all.
But nearly 11 people are leaving for every 10 that are arriving. So was that like a 9%? Yeah. But considering where we were for most of our time here in Colorado, that's significantly different. You know, we were definitely a net, you know, incoming people here.
You know, maybe traffic goes down, maybe it's a little easier to buy places, maybe there's some positives here. Or at least it doesn't get any worse, right? Like, if it stays the same, that's better than it getting worse. Yeah. So, all right, let's move on to the next one.
An announcement here about a new driver-owned rideshare app that's, you know, competing with Uber and Lyft. That gives you the, the same benefits, but more of that money goes to the drivers. So it's called Coop, C-O-O-P. And if you wanna find it on your app store, just type in Coop Rideshare. I have installed it and set it up. I have not done a ride in it yet, but I was, you know, curious, how's this gonna compare in terms of pricing?
I was sitting, uh, near my home and I, I asked for what would a cost of a ride to the airport cost? And, and then I went over to Uber and I went over to Lyft and compared, and it was about a buck or two less. No, not a lot less, but, you know, a little bit less. I thought maybe it would be more because more money is going to the drivers. But the great thing about what Co-op's doing is they have a flat— I think it's 20%.
It is. I know it's 20% fee that goes to the, to the system. Right. And then the rest of the 80% of your ride goes to the driver and it's all really transparent and it's owned by the drivers themselves. I think it's a really cool system.
Yeah. When they originally started this, this is the second time this has been launched. They launched with a different technology platform, which which didn't go very well. It apparently didn't meet the needs of the co-op, but they've now partnered with a company called, I don't know if it's Tata or Tada, out of Singapore. They're a rideshare company, and so they're basically white labeling the platform for the co-op here in Colorado.
First one of that software platform in the US. Pretty cool. I'm excited to see if it turns out to be great. It looks like they don't have a lot of drivers yet. Yeah.
Although I found drivers when I looked today. Um, but you know, they, they estimate they're gonna, you know, they're gonna have somewhere in the 10,000 driver range, or 8,000 to 10,000 here by the end of the year. Um, so when they hit that, it's gonna be pretty competitive. Good stuff. All right, uh, moving on to our next article.
Uh, this is, uh, a semi-security related, uh, topic. Uh, this is a story about, uh, weird and shady QR codes that are showing up on Denver parking meters. Yeah, folks, It looks like some bad guys went around with stickers that had authentic-looking QR codes for you to pay your parking at these different parking meters on South Broadway and some other places around downtown. And, you know, the link that you went to took you to a place where you could put your credit card information and you could pay. And lo and behold, you were being scammed.
Yes.
It doesn't seem like they offer many solutions as part of this. The city is looking into it. It's being turned over to the police. They did mention that they would never legitimately send you to a website to, to pay your, your tolls or parking meter there. They would just send you to a, to the App Store to download the app.
Yeah, I, and that sounds like I get when I read it. I'm like, oh man, like, that's, it's an awfully small difference that they're saying. And the other problem is, okay, they don't send me to a website, but there are plenty of other places that do. Like parking over at Landmark— not Landmark though, the Broadway Station area— like that takes me to a website to pay, and I've done it numerous times. I think it works.
And like these things, it's hard to keep track which are which. I, you know, the advice that the columnist or the author of the story gives is Uh, you should just try to pay with a credit card. Like, okay, unless there's a skimmer, right? Right. Different technologies, but man, it's, it's awfully tough.
Yeah, for sure. So just don't let anyone who doesn't, who can't tell what a good URL is, use their phone. Yes. There were definitely clues that they mentioned that if you, uh, went with these bad QR codes, you could pick out that this was phishing, but you gotta pay attention. Yeah.
All right. Um, Next story we have from the Colorado Sun this month. It's actually not from Tamara Chuang. This is Kate Reuter. It's about Colorado passing a privacy law specifically protecting brain data.
And I found this honestly a pretty, pretty interesting article. I didn't know anything about this trend, and apparently it's a significant trend from all around the country. Yeah, I didn't know either. And I thought it was interesting as well and not something that I had really thought about exactly, you know, brain data thought about. Um, hey, uh, but, but yeah, I mean, I guess my assumption would have been that this would have been caught up in, uh, you know, biometric or other data that privacy laws already had, but apparently it wasn't.
So the, the kind of concept here is wearables. I think they specifically mentioned headphones and, and earbuds Um, that are capturing information about you to, to learn like how you're sleeping and, um, like, you know, your, your, your mood and a bunch of other stuff, uploading that data to the cloud and trying to use that to start getting, you know, trending and what can we tell about what's going on. And then they, they kind of take this jump from those, those consumable wearables to some actual research that scientists are doing where they're able to put a bunch of, you know, significantly more technology, you know, the little— what do you call those things you put on? Electrodes. Electrodes.
Yeah, thanks. Electrodes on people in order to see what they're thinking. And like, they had an experiment where they were able to play back the song that someone was listening to based on what parts of the brain fired up. So you start to expand that. You're like, oh, this is like reading minds.
And like, you know, you're able to start seeing a lot more detail than than maybe you'd expect from this type of monitoring. And then, you know, when somebody hears that, they go, oh my gosh, and these people are taking it from folks as consumers. And maybe the data they take today is useless because they don't know how to use it, but that same data will be very valuable when they get smarter at how to use it in the future. So it's an interesting conversation that these advocate groups are going after, and they have a lot of support from the different politicians. In case you were wondering, the song is Pink Floyd, Another Brick in the Wall, which is what they totally recreated.
But yeah, it's interesting. Glad that this is— there's gonna be privacy rights for that kind of data. Good stuff. All right, moving on. The next topic for us, this is from a Husch Blackwell blog, sort of a summary of the Trump administration's AI action plan and the new executive orders related to that.
Yeah. So there is a new strategy that's been released by the Trump administration. They called it Winning the Race. He backed this strategy with 3 different major executive orders. That's a pretty big pivot away from regulation and trying to really accelerate our innovation around AI.
So the focus is on having fewer regulations by the states, fewer, fewer federal regulations, and really trying to let, let the technology companies drive this. Yeah. Also giving investment in various places to help move this along, including both technology and adoption of, you know, potential new models and other things like that. I guess you know, this shouldn't really come as a surprise for, you know, how the current administration is operating, looking for less regulation, moving faster on things. They, they do also talk about some potential drawbacks to this approach, and also some potential conflicts with other executive orders and, you know, other strategies that have already been put in place.
So, so I think it's a little bit of a mixed bag. I think trying to move this forward is a good thing, maybe not in the way that it is trying to be moved forward. And, you know, as, you know, running security within your organization, you know, we're still meant to be the guardrails that allow our companies to invest in technology safely. So we need to be thoughtful, like, yeah, I know we want to regulate later, but within our own organizations, what's the data that we're really concerned about? What's the What's— what are— where could the real harm be?
Are there decisions that are being made that we need to be a little bit more careful of? I think that that's the place where we can step in and, and, and be thoughtful about the things. Maybe there's no regulation requiring it, but, but we want to be the ones to, to make sure we're doing things in a thoughtful, safe way in our companies. Yeah, I will say, uh, this article is, uh, there's a lot of meat to it. It's pretty in-depth.
So if you want to, to dig in deep on, uh, these executive orders in the action plan, it's a good one to read. Speaking of meaty content, we have a blog here from Red Canary who always deliver the goods. This one is around MCP, understanding the threat landscape for AI workflows. And I think as always, they start off with a nice high-level, what is MCP? Where does it fit?
They use, you know, I've heard people talk about it as the API layer, but they're talking about it as like, what they call it, USB-C port for your AI applications. Yeah. Kind of the general connection between your applications. And they talk about how it sits in the middle, and then they start getting into the security implications of MCP. Yeah, and there's actually a little bit of a case study embedded near the end of this.
The author deployed their own MCP server to do some things and talked about the lack of security and some, potential misuse cases as well. So, good detail and good article. All right, moving on. We have another article here from Optiv this month around cybersecurity leadership in 2025, the strategic role of CISOs in an AI-driven era. How has the AI-driven era changed the CISO's job, Alex?
Yeah, I think we left this blog post in the list this month. Because I didn't think this was a particularly good article. We don't always say that, but they have basically 3 points that they're talking about here. The first one, which goes to the title, that CISOs are now responsible for AI integration and oversight. That is new.
There wasn't this amount of excitement and oversight needed in terms of AI previously. New responsibility and a bit different than some of the other responsibilities that CISOs may have had in the past. It's like, what was it, a decade plus ago when we had to figure out how to adapt to the cloud? Now we have this new one. It's a new challenge for sure.
The second point, what's the second point? I think the other 2 points are kind of baloney. They're clearly things that have existed already, and I'm not sure how they relate to the evolving role from AI anyway. But The second one is incident response leadership. I mean, that's a key pillar of what security leaders and security teams have done forever.
So I don't know how that's new. That's probably how the first security team was created, incident response. Right. And I mean, I guess you could say that that is evolving, but yes, everything is always evolving. Right.
And then the third one is talent development. Again, like anyone in any leadership position is responsible for talent development in their teams and their organization. That's always been there also. Again, that could be evolving, but yeah, so, so is everything. Well, things are always changing.
People are always looking to get clicks and talking about CISOs is a way to do it. We talked about it, so they win. They win. Congratulations to them. All right.
We have one more story. We do have one more story. This is from Svelo, and the title is Addressing Legacy Phishing Detection Failure. And really, this is a blog post talking about, you know, how phishing trends have changed and the ways that you now have to try and detect these new types of phishing attacks. And so, I think if you really want to see some of that change, you can read the article and hear a little bit about it.
Yeah, obviously, you know, they do offer services around detecting phishing, but I think just seeing how they're seeing trends change and maybe our assumptions from past years that that phishing would be, you know, written with grammatical mistakes and really not customized for the organization is going away as AI makes it easier to be better at language, better at customization. So it's an interesting article if you just want to know more about how phishing has changed. Awesome. All right. That is it for stories.
We, we have events coming up. As a reminder, we have a calendar of events out at Colorado-Security. You can go see what's happening over the next several months. And today we're going to talk about the things happening through August. The first one of those, ISSA Denver, is doing their August chapter meeting on the 13th.
We've already mentioned it earlier, but as a reminder, on the 23rd we have the Colorado Equal Security Picnic where we're co-hosting with a whole bunch of other organizations we're excited to join with. We hope you'll join us out there at the park on Saturday. And then we have 2 events on the 27th. ISSA Pikes Peak is doing their chapter meeting. And ISSA Denver is doing another.
This is one of their special interest groups on AI and ML. This is talking about agentic AI. And we'll go one one meeting into September since we I don't know if we're going to be recording before September third. ISSA Denver ISSA Denver has the Women in Cyber Special Interest Group doing a meeting from crisis response to boardroom becoming a CISO. The unconventional way.
And that's with Nikki Rosenkranz from Arapahoe County. Oh, cool. Yeah. Awesome. That is good stuff.
All right. Well, that is it for events, Alex. We do have an interview. You sat down with Josh Peltz and you want— you want to give any teasers or should we just jump into it? Yeah.
Josh Peltz is VP of the West for Zero Networks, but he has got a very interesting and colorful past. Part of that. He's been on Oprah. That's pretty good. It's for a reason that, like, he might not have chosen.
But, you know, he was on Flight 1549, which is the, the Captain Sully flight that was diverted and landed in the Hudson River. Awesome. Yeah. So we talk about that. We talk about a bunch of other stuff.
It's a good listen. So people, you should, you should pause, go watch the Sully movie with Tom Hanks. Exactly. Come back and then listen to the interview. And then you should also— I didn't talk about this with with Josh, but you should try and pick out which passenger in the, uh, in the movie is him.
I don't know if there really is one or not, but I'm just picking up. Now I need to go watch the movie again. All right. Awesome. Well, that's it.
Um, we appreciate it, Alex. We'll, we'll get back to this whole lovely community in September, but for now, I guess we're good. Thanks, Robb.
This is Joseph Nahar. I'm a CISO at Woodward. Welcome to Colorado Equals Security for Colorado security professionals by Colorado security professionals. Welcome to Colorado Equals Security. This is our feature interview, and I have a very special guest with us for this month, Josh Peltz of Zero Networks.
Welcome, Josh. Hey, Alex. Thanks again for having me on. Yeah, happy to have you. Josh, you know, we met, I don't know, a year ago, probably something like that.
You had, uh, you were a fairly new member of the Colorado community, and we had coffee and, and had a good time. And, uh, we've had several discussions, uh, since. And, you know, through that, I've, I've found that you have a very interesting story, and I thought it would be something that, uh, that we'd love to talk about here on the podcast. But I think maybe to start, why don't you, uh, tell the audience a little bit about yourself and Uh, you know, what you've done over your career, how you got started, and how you got to where you are today. Yeah, happy to.
Um, coming in loud and clear, by the way? You can hear me? You sound great. Okay, I'm using my podcast voice. Is that also okay, or should I just talk normally?
Yeah, uh, it sounds very podcasty. Okay, good. Um, so nice to meet everyone. Josh Feltz. I am new to Colorado.
I've been here now about 2 years. We did meet about a year plus ago, uh, for that coffee and then conversation since. I am originally from the East Coast. I've been about a decade or so in cyber at a few really cool startups. Notably, I was at Duo Security for 4 years, 3 years under our own flag, 1 as we were acquired within Cisco.
So that was a meteoric rise and ride. And now I'm at Zero Networks trying to solve really cool problems around micro-segmentation, holistic segmentation, saving organizations with preventive technologies from the risk of breach and containing those risks. So lots of fun and a lot of background in cyber. Josh, I did notice that you were at Cisco prior to being at Duo. So you just couldn't stay away?
Is that how that worked? It is a great company. So yes, I was acquired actually when they were really moving into their cloud space. It was called Intercloud, which was the strategy that they were unfolding. And I was at a data integration technology back then called Composite Software.
So we had 2 successful acquisitions in Cisco. Honestly, they handled those so well and create such a home for these organizations and for the technologies. So yes, I've been there twice so far.
Well, that's great. I know a lot of times, you know, after the initial acquisition, things don't necessarily go well. So I'm glad to hear that that was a successful transition. And, you know, I know Duo is still great technology and a great player in cybersecurity. So I am curious, was there something in particular that led you to work at cybersecurity startups?
Because I know you had some time before your first one where it was, you know, other types of software startups. Startups. Was there something specific that drew you to security? Well, the honest answer is relationships. The former CFO of Composite was very good friends with the COO of Duo, Zach Erlacher.
And through Zach, I met Jim Sibb and Jason Stutt and Doug Song and Jono and a variety of other people. Paul DiMarzo, the CFO over there, and Ash Tavada, who's now at GrayNoise. And so I had an opportunity to meet the executive team and senior leadership team and a lot the practitioners and realized after talking to my 7-year-old son when I returned from one of the trips, I told him a little bit about Duo. I told him what security was. And remember, he's 7.
And he said, Dad, you're one of the Justice League. You're like an Avenger. And if you have any children or have children in your life, you know, you feel like you won the Adult Olympics, the Dad Olympics, when you hear a comment like that. And I realized I could do well for my family. While doing really good for the world by being in cybersecurity very differently than I had ever felt before with other software solutions or product solutions.
So I jumped in with both feet. I was welcomed by the Duo team, and I haven't really looked back. It's been a great ride being in cyber, trying to make a difference. That's awesome. Yeah, you know, I've— I can't remember a specific, you know, sort of superhero moment like that with my kids, but it was definitely a driver for me when I was early on in the industry too, is You know, this was really cool, fun stuff, but it's also, you know, a way to do good for the world.
So, you know, I appreciate that part of it also. And the problems never go away. In fact, they just get more cool or cooler, I guess, and more unique and harder to solve. And so, you know, with all the new attacks and attackers, it is constantly changing and always challenging. Um, that is very true.
And, uh, you know, I, I buried the, uh, the lead here a little bit on purpose, but, um, you know, as cool as cybersecurity is, you know, there is something even cooler than that, uh, and more fascinating than that about you. And that is that you were one of the passengers on Flight 1549, which, uh, Captain Sully Sullenberger landed in the Hudson River. Um, I want to tell us a little bit about that. Yeah, it's, uh, it was a very long time ago, very short flight, but it's still relevant today. A lot of fun.
Shortest flight you've ever been on? Yeah, I think this podcast would be longer. It was, uh, yeah, it was about a 6-minute flight in total. Um, for those that are not familiar with it, I was on the flight that went into the Hudson River. Um, it was January timeframe, January 15th to be specific, in New York City.
And I was returning home to Charlotte after a business trip. I got on the flight. Nothing, nothing specifically interesting about that day other than looking forward to getting home to the family. Got to about 2,800 feet in the air and the flight hit a flock of geese, Canadian geese. Now, if you lose one engine, you can typically resume flight operations and get back to a safe landing.
But we lost both engines. As they were simultaneously struck. So you quite literally— and I can go through the whole story or just a summary right now if you'd like. Keep going. Yeah, it's interesting stuff.
So we lost engine, engines on both sides. You heard the actual engine wind down and we continued our forward momentum. So we got to about 3,100 feet, I believe. The pilot was able to bank to the left. And then resumed his dive in order to create enough speed so he could try and safely get back to some semblance of safety.
He determined very quickly that he had no other options but to put it into the Hudson River. On the flight, I was actually able to help a number of people during the actual water landing itself. I was on the emergency exit door, so I actually got to open up the the actual side door on the right-hand side of the plane, got a number of people to safety. And with the help of other passengers, we actually saved a 9-month-old baby who's now 16, which is amazing to me. But incredible day, incredible human spirit, collaboration.
The whole city came to our aid, it felt like. And yeah, pretty incredible. I remember very shortly after, I was at a business event. And someone walked up to me very excited and very positive and said, what a gift. Exciting thing for you to go through.
And at first I was a little offended because I think I still had a lot of— well, I know I had PTSD, but I'm sure as time went on, I realized that person was absolutely right. And I've had the opportunity to digest it all and to assimilate it into my life and share lessons from it. And so that's what I did at the Rocky Mountain Information Security Conference that you were part of and, and Jeannie O'Kane and a number of other people invited me to speak at. And Now, I'm tethering the story together, comparing Flight 1549 and what we went through with the cybersecurity breach, and it's been a really fun conversation. I've spoken privately with a number of CISOs and their teams, and I'm speaking publicly not only at RMISC but also at ISSA International in September.
I'm going down to Dallas, and I'm outlining the similarities between the 2 events. And on the surface, no pun intended, surface, but On the surface of that, you wouldn't expect them to be very similar, but they both have preparation and training. They both have incident response. They both have business continuity, disaster recovery. They both have aftermath investigations and actions.
And so I've drawn those parallels and it's been a lot of fun. It's very engaging conversation. It opens up a lot of eyes typically for teams, and it's a fun story to share. So yeah, that's a My 15 minutes of fame. Yeah, I mean, it seems like maybe even more than 15 minutes.
But, and I do want to dig in more to the parallels part. But I did want to ask you one other question about the flight itself, just for my own curiosity. I'm curious what it was like for you once you realized what was happening. Was there panic? Was there calm?
What, what, uh, how did your, you and your, uh, body and personality react to that? Yeah. Um, I typically, including this podcast, go to humor when I'm uncomfortable. Yeah. Uh, I'm also, uh, in consultative sales, so I'm not used to talking about myself.
I'm more interested in talking about other people and their questions and problems, but, but I'll give it a try. Too bad this podcast is about you. So the, the initial thing was humor. I remember when the engines blew up or were struck, I made an offhand comment to someone that I had met earlier in the airport, and I said, that's not a noise you want to hear on an airplane. And it turns out I was absolutely right.
After the initial scream that everybody had after hearing the explosions, it got dead quiet and everyone was trying to assimilate very rapidly what was happening. As we started to lose forward momentum and we paused in midair, almost like one of those old Wile E. Coyote or Road Runner cartoons, if I'm not dating myself. But, but everything kind of froze as we started to bank to the left. And then, and then it was a pretty dark time, to be honest. I started to think about what could happen.
And I actually said goodbye to my family mentally and emotionally, which is a pretty hard thing to admit. From that, I realized we hadn't crashed yet, and I sat in the emergency aisle for a reason. I wish I could say I paid adept attention to what the flight attendants were going through in the pre-boarding instructions, but I'd sat there enough that I thought I had it locked down, and now it's time to actually do something about my seat and my responsibility. So I reached into the seatback cover and pulled out that little pamphlet, the, the, uh, the the trifold that you have in your seat when you sit in the emergency exit aisle. And I started reading the instructions because I was quite literally on the door and I had to figure out how to open up that door and help people get to safety.
So I remember thinking, I sat here, I have a job to do, I need to act because you have this complete loss of control. And when you're not actually involved in flying the plane or driving the bus or taking care of the situation, And giving myself something to do and trying to help in some minor way felt like at first it was the right thing to do. And secondly, it gave me something to act upon. So I read the instructions, memorized those as best I could. The second thing I did is I noticed the person sitting 2 seats away from me because we're on the actual pass— on the exit door, couldn't see out that little porthole, Alex.
So if you remember on a flight, you've got the larger windows in the typical seat rows, but on the actual door, there's a tiny little porthole. And so sure, she was absolutely terrified. And white-knuckle doesn't begin to describe it. So I started giving her a sense of exactly where we were in our experience and told her we had just crossed over the George Washington Bridge by about 600 feet, you felt like you could reach out and touch it.
And so I started, as we started our glide descent, Yeah, I know a lot of data points, so I'm happy to share those. We accelerated to about 240 miles an hour. We hit the water at 177 miles an hour. The air temp outside was about 20 degrees and the water temp was about 40 degrees. And so people always ask, like, what was the situation like?
So I typically share those numbers. But back to the woman Jenny that I had met, she had no inclination of exactly where we were. We just heard the klaxons and the sirens and the alarms. Going off because as you get too low in the— in the embankment, I guess, is the wrong word, but in the experience, all these different alarms start going off and the flight attendants were trying to help and there's smoke inside the cabin from the engines. And it's a really confusing, terrifying time.
And so I did my best to assuage some of the stress that Jenny and others around me were going through. And so I started basically a countdown. So, okay, now we're at about 300 feet. Now we're about 15 seconds away. You can't read a trifold that has no words on it because your brain won't work, but you could do advanced calculus on the fly and figure out your angle of declination and the speed, kind of triangulate where you are with the sun and the bank.
And so I was able to kind of get really close to within a second of exactly when we were going to hit the water. So Jenny told me later, That was a godsend for her. And so I'm happy I made a difference for her.
Yeah, I'm, I'm sure you did. And I think that goes to, to some of that talk about preparation, right? The, you know, I think everybody, everybody ignores the flight attendants when they say you might have to do something later. But like in the time that you're talking about, you did as much preparation as, as you possibly could to be, to be ready for the situation as it unfolded after. And I think that, that, I think that is a really good parallel to, to cybersecurity incidents, although, you know, most cybersecurity incidents aren't life and death, but they are, they are chaotic.
And there is a lot going on. And the more that you prepare for them, the better that you can run through them. So, you know, I don't know what else you wanted to talk about in relationship to that, those parallels. Yeah, I think you're absolutely right. Tabletops or simulations, training, phishing campaigns, all those things go into play on the cyber side.
On our side, it's air traffic control or the crew or the first responders. You know, they're the professionals that actually have to contend with this. And I think the similarity exists where you have the business users on the cyber side that might not be taking it as seriously or might be thinking this is a pedantic exercise or something getting in the way of them actually going about their day. Just human nature. Some of them understand the gravity of it and adopt it very willingly, and others probably are more pulled into cyber exercises.
I think the same thing on flights. You get everyone from the people that pore over the trifold and really understand all the all the roles that they have to play, and then other people to sit there for the legroom, and I was somewhere in between. But thankfully, the air traffic control and the crew and the first responders and the pilot and the copilot all had the advanced preparation and the training in order to get us through that day. Captain Sully has a really cool quote that I'm not going to do justice, but he says something to the nature of, for 42 years, he was making small regular deposits in the bank of experience and training. And on that day, he made a really large withdrawal.
Yeah, I think, I think that, you know, developing and implementing plans, whether it's an IR plan or a flight plan, and then conducting the right training and tabletops to simulate attacks and protect systems and protect passengers is, is a really cool similarity or a cool parallel.
Yeah. And I think also along with, with cybersecurity incidents, you often have folks that, that even if they do know the plan, they don't necessarily follow the plan. And you know how it is that you have to deal with those things. I think from a different conversation that we've had around this topic, I, I think I remember you mentioning some folks that didn't necessarily follow the plan and tried to to swim away from the plane, which is probably a bad idea. Different parts of the, yeah, different parts of the plane took different actions.
I heard about some people trying to pull the exit door in as an example. That doesn't bode well because it blocks the egress. Other people, like you said, jump off the wing once we exited the plane and swim for shore. Well, in 40-degree weather, you probably have 30 to 45 seconds, especially if you submerge your head. Before your muscles contract where you can't actually swim a stroke or you're completely discombobulated or maybe worse.
So, yes, a lot of people just took action. Unfortunately, it wasn't the right action because we all didn't have the right training to contend with the disaster we faced.
Yeah. One of the other parallels that comes to my mind is sort of the after-action and, you know, looking back on, in this case, accident, but in cyber, you know, incident, and trying to figure out, you know, what happened, did the right things go on. And, you know, of course, in aviation, there is a much more rigorous process that they have in relation to this— excuse me, relationship to this with the NTSB and investigations and things like that. Um, and, uh, you know, of course we know exactly what happened in that because, um, you know, Tom Hanks was, uh, great enough to, to lay it all out for us in the, the, uh, the movie that followed this. Um, but, uh, you know, I think that there's also, uh, there's great parallels there.
And I think it's something that, uh, that cybersecurity can learn from to be even better and more formal about these, uh, after-actions and reviews of of what happened and how you can be better. Yeah, 100%. So, so in my scenario, we had the NTSB, National Transportation Safety Board, that conducted thorough investigations afterwards, looking for cause. And in the movie, just like in real life, Captain Sully and co-pilot Skiles were grilled about whether or not they acted fast enough, whether or not they had the requisite training. And then after the investigations are concluded, then the NTSB recommends safety improvements or better engine designs or safety protocols or, or different training programs that they can implement to, to obviate risk.
I don't know how you plan for dual engine failures because of Canadian geese over one of the most populated metropolitan areas on the planet. But, but there are smarter people that figure those things out. In a cyber event, you have the exact same thing, right? You have different governing bodies. You and I talked about that in the past.
You have to identify the vulnerabilities and the attack methods, and then you have to recommend measures and prevent future concerns, right? Sorry. And I think, you know, learning from all those failures, if you can call them those, or the lessons learned, helps strengthen defenses. I've typically been on the preventative side of cyber. I mentioned Duo, I mentioned Zero Networks.
I think protecting the organization, trying to mitigate lateral movement, movement into the enterprise, our firewall partners, anyone that's actually focused on not just the detection side of the house, but also the preventative side, I think a good partnership can help strengthen that. And depending on someone, Thomas Maldonado, the CISO of the NFL, Had a great quote, which I'm sure has been quoted from other people, which is never let a good breach go to waste. I think all these lessons learned from these examples and exercises, you know, just help strengthen defenses and keeps us all safer. So these post-incident analyses are really important. Yeah, I think, you know, most often when people use the don't let a breach go to waste, quote, they're, you know, they're advocating for, for more money for their security program, so that they can, you know, potentially get other controls in place.
And I think sort of subconsciously, you know, in their mind, help, you know, right the wrongs that have been done to their, their security program by not being funded appropriately. But in my mind, what we're talking about is, is a super important part of that, too, which is Uh, don't let the breach go to waste by not seeing what really went wrong and how you could be better about, uh, preventing it, um, or responding better to it in the future. Well, you know, uh, so there's 2 sides of that. It's one for your own, uh, program, but also paying it forward. Uh, and that's something I love talking about in this session is learning the lessons from Naming some notable people, Joe Sullivan and Tim Brown and Steve Martin over at Change Healthcare.
I was at MYs in Denver about a year and a half ago and got to hear Steve speak about the lessons he had from Change Healthcare post-breach or even during the breach exercise. And that honesty and transparency are so vital because every crisis is a lesson, whether it happened to your shop or someone else's. And I know that you have a very strong community here within Colorado Equal Security that do share those lessons, either in the private Slack channels or in your events or in your tabletop exercises that you perform with your community. I think we can all keep each other stronger by paying it forward and sharing those lessons. Yeah, I think that's great.
On that topic, one other thing that I know that you've been doing to to try and help pay it forward is you were one of the folks that started a chapter of Cyversity here in town. So I don't know if you want to talk a little bit about what Cyversity is and what, what the goal is and what's going on here in Colorado. Yeah, happy to. So Cyversity is a program that I happened to come into contact with. It is short for cyber diversity.
I have a very good friend of my family's, a young man that lives in Charlotte, North Carolina, and he is specifically in West Charlotte. It has a 500% higher crime rate than any other part of the city and one of the highest in North Carolina state. And he was in a situation where he couldn't leave the house even during the day without some precautions because it was such a dangerous neighborhood that he lived in. What he did within his 4 walls is taught himself IT networking and how to build better hardware systems, specifically to play better video games because he's a teenager. But he had a good design behind that.
The logic was he wanted to build faster systems so he could play better games and buy groceries for his family by streaming his results. And I learned about this young man. I learned about his story. He was struggling finding a job as a young Black male in Charlotte, specifically from this neighborhood. It was very hard for people to trust him regardless of his, his own personal journey and education because he didn't have formalized certifications and formalized training.
We, we meaning some of his other friends and mentors and myself, reached out to the cyber community explaining his story and asking who potentially could help. And that's how I met Cyversity. I had a great opportunity to, to talk to people like Larry Whiteside and, and, uh, and, and Julian and, uh, and Devin Bryan specifically about this young man and about some of the struggles. You would think with their, with their roles and their program and their mission, they would be looking more at, uh, scaling solutions, but every individual counts, and every single person within their team and, and them specifically reached out to me and said, how can we help? And, and I was so impressed with that level of support and care and compassion.
I learned more about Cyversity itself. It is, in a nutshell, and I should have started with this, it is an organization that focuses on helping people grow personally and professionally within their careers in cyber. Whether that are— that could be young Black males in Charlotte, that could be women in technology, that could be veterans, both military and police, that could be people from underserved communities all over. These are people that are looking for a new chapter, an additional chance, and looking for entry-level opportunities or to make career transitions later in life. I talked to a woman that was a chef, a professional chef that really wanted to get into the cybersecurity career track and how does she actually make that transition.
So Cyversity tries to focus on education programs and training wherever we can. I was so impressed with the organization that I learned more about the fact that they didn't have something in Denver. Some amazing people, Erica Mancilla and Geneva, who I know you know, Damaris. Geneva is our president, and Erica is effectively the wind beneath our wings, and a number of other individuals, probably 20+ people now in the organization. It's a newer chapter.
I think we're lucky number 13 in Cyversity's org, but we are focused on helping people, meeting them where they are, and giving them the skills and education they need to jump into cyber.
That's awesome. And I really love that mission of trying to get those that, that are underserved the opportunities that, that they might not normally be able to, to get easily. What are, what are some of the things that, that Cyversity does locally? You mentioned trainings. Is this sort of a chapter-type organization where you have, you know, sort of normal monthly meetings or things like that?
And, you know, Trainings, education services, what sort of things are being offered by the local chapter? All of the above. Thanks, Alex. Mentorship, you know, connecting people with people, much like, you know, Devin and Larry and folks that actually reach out to my friend.
Training and skills development, apprenticeships and internships, different career resources, just looking to make an impact at the individual level. But there have been a number of really amazing organizations, large corporations, small companies that have leaned in to be training partners, provide spaces for training, as well as different programs, internships, you know, helping to bridge the skills gap wherever they can. So that, that's essentially what we've been doing at a localized level. We do do events. You'd be hard-pressed to find a local conference where we're not supporting the broader community and really trying to expose the mission behind Cyversity to other people.
So shameless plug, if folks are listening to the podcast and do have programs where they want to find entry-level interns or entry-level professionals in cyber, or want to help support getting more people as we try and bridge the mounting talent gap outside AI bots. They're fantastic, but we still need people. So helping people actually jump into the cyber ranks, we do have sponsorship programs where people can lean in as we are a nonprofit and we are dedicated to doing so. So that's awesome. Yeah, professional memberships and student and veteran memberships as well.
Also, As you and many of the listeners know, we have the Colorado Equal Security Summer Picnic coming up on the 23rd of August. And this year we're doing a little different with a bunch of different co-hosts of different organizations from around town. And Cyversity is one of the organizations that's going to be there with us. So if you do want to learn about Cyversity in person, show up to the picnic. I know Geneva will be there and maybe you will be there too, Josh.
Yep. Yeah, I am gluten-free, so I got to probably eat ahead of time. But, but I'm going to be there. Excited to support everyone. If you want to learn more about Cyversity ahead of time, it's cybersity, which is cybersity.org.
Or you can just DM me on LinkedIn. Happy to help people find their way. That's awesome. Uh, we'll make sure to put a link in the, the show notes as well for, uh, for people to find their way there. Um, all right, I— we've covered a bunch of topics here, uh, lots of interesting stuff.
Um, was there anything else as we're getting close to time that we wanted to cover, Josh? Uh, this will probably air after Black Hat, so thank you for everyone that came by the Zero Networks booth to meet me. I really appreciate that. Uh, in all seriousness, I'm really excited about Black Hat. It was my first Black Hat ever that I got to attend last year, and it was my first— oh nice, it was my first week at work at Zero.
No, that was quite an experience, you know, 30+ people strong. It was a lot of fun. This year we've got probably doubled the size of the team because we've grown dramatically. It's, it's a, it's a fun atmosphere. We're going to be right next to the Wiz booth and the Microsoft booth, so pretty easy to find.
But, but I hope you're gonna be out there, Alex, and some other friends. I, you know, again, this airs afterwards, but I'm looking forward to that show. It's, it's, you know, RSA and Black Hat and some of the larger conferences are fantastic to connect with people. I know CISOs in your position get inundated with outreach. That's not our intent or my intent.
I authentically like to reach out to people, learn from them, and understand what they're experiencing. And that was kind of the notion behind what we did with Zero. Our founder was so tired of seeing his friends get breached and, and the experiences, like I mentioned, with Steve Martin and Tim Brown, Joe Sullivan, CISOs in general go through, the experiences that I reference in my session about cyber breaches and how they parallel the flight situation that I went through. It's terrible. And the trauma and the PTSD that everyone goes through, that's why I think I focus on preventative in the in the work that I've done for the most part.
And if anyone's interested in having those conversations, even outside Black Hat, I'm happy to do so. Awesome. That's great to hear. And I'm sure if someone does have a conversation with you, it'll be a great conversation because I know the ones that I've had have always been fun. So reach out.
I'll tell you how I got 2 hugs from Oprah, which is part of my tagline on LinkedIn. That is— there you go. We didn't even get to that part of it as part of the That's right, the podcast. So, uh, that'll be the teaser for people to have to come talk to you later. There you go.
That's right. Awesome. Well, uh, Josh, this has been a ton of fun. Uh, I appreciate you coming by. Thanks for being a guest on the podcast.
Um, and, uh, this has been Colorado Equal Security, and we will talk to you next time. Learn more about the Colorado security scene at coloradosecurity.org. Colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.