Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 276 for July 7th. Alex, happy America's birthday.
Yeah, you know, this is 276, kind of like 1776. So similar. Almost exactly the same. Very similar. Happy after July 4th.
Did you see— I don't know if you're, if you're paying attention to my Facebook posts, but I posted a Facebook, which I do not ever do because someone actually— my little nephew is in town and he, he shared the Washington's Dream SNL skit. Have you seen this before? I have. I haven't. I'd never seen it before.
It's Nate Burgazzi, right? Yeah, exactly. Yeah, it's hilarious. Yeah. You know, why, why do we need independence from Britain?
So we can have our own weights and measures in the United States. And it goes into the insanity of the differences between our weights and measures versus, versus the rest of the world. It's a good one. Yeah. Well, anyway, it's hot.
There's fireworks blowing off all around us, all kinds of good long weekend stuff. I hope everyone has all of their, their fingers still. That would be a positive outcome for Fourth of July. As many as you came into the weekend with. That's right.
Yeah. All right. Well, let's, let's jump over to some housekeeping. We do have a Slack channel. Are you aware of this?
I am aware we have more than one person in there. There's good discussions that happen. If you're not in there, we'd love to have you join us. We join the Slack channel by going out to colorado-security.com and saying join the community. While you're there, you can join Slack and get on our mailing list with all with one little form fill.
Yeah. We'd also love it if you rated and subscribed to the podcast on your favorite podcast player, as well as telling a friend, letting them know how great Colorado Equals Security is and all the wonderful things that we're doing as part of this. Speaking of great people and things, we have some great annual sponsors to thank. You know, we, as a part of running this community, we've, we've had 4 companies step up to, to support us. And we want to do a huge thank you to Armis, CrowdStrike, Red Canary, and Zscaler.
Yes. Thanks all. Also, a little later this summer, we are— breaking news, breaking news— we are doing our annual summer picnic. August 23rd. It's going to be at Berkeley Lake Park in Denver, um, 11:30-ish.
We're excited to have a whole bunch of people there. Um, we've got a, a great sponsor this year. Alchemy Security is sponsoring that picnic for us. They've always been a great local community supporter. And we also have a— basically every other security organization in the metro area is co-hosting with us.
Uh, I'm gonna miss some of them, but CSA, OWASP, ISSA, ISACA, uh, Denver Cloud Security Meetup, YSYS, Cyversity. Um, uh, who did, who did I miss? Did you say, did you say DENSEC? I didn't say DENSEC. ISC².
ISC² Denver. Um, Cloud Security Alliance, if I missed them. LIFT. Is it Popsicle? Popsicle is going to be there anyway.
Uh, all these different groups are gonna be there. You can come, um, hang out, have a, a food and a drink and learn about these groups and network with people. It's gonna be fun. Say hi. We're gonna be at the park.
It, it's free. Bring your family, bring your dog. Have a good time. Yeah. Go to the event calendar on the website.
Uh, go to the RSVP link just so we know how many people are coming. All right, let's jump into the real news. You know, I know everyone has been waiting anxiously for the last month cuz we, we kind of left a cliffhanger last month, didn't we? We did. There's going to be a new statue and it's going to be named.
Yeah, it's a, it's a rhinoceros in RiNo. And there was a competition to name the rhino. I'm sure it was very difficult to choose this name, but the name is— it's Ringo. R-H-I-N-G-O. Ringo or Ringo.
We don't, we don't know for sure since we don't get to hear it. We just read it. R-H-I-N-G-O. R-H-I-N-G-O. Ringo was his name-o.
Well done. So this obviously is a little play on the name RiNo. While Ringo was officially chosen, there were a few other finalists, some interesting ones. We had Ryan Osiris. We had Darryl.
I don't know why Darryl's interesting. Why not? And we had Gentry, which is short for gentrification. Yes. Which is— I'm glad they didn't go with that.
Maybe a little tongue-in-cheek there. Yeah, that would have been a little bit harsh. And Anyway, we can go see Ringo as it's completed in RiNo, and I'm excited to have the newest large animal statue in Denver. Yeah, maybe someone should go take a picture next to Ringo and post it in the Slack channel. You could be famous.
You could be famous. Speaking of animals around the Denver area that needed to get a name, holy smokes, we've got a theme here. There is a brand new dinosaur that was discovered here in our own backyard. Yeah. So this is a pint-sized dinosaur that was discovered actually out in Moffett County.
It was discovered a few years ago. It was originally named one thing because they thought Nanosaurus— they thought it was a Nanosaurus. Yep. And then some archaeologists said, yeah, I don't think that's a Nanosaurus. Let's figure out what it is.
And they decided it wasn't. So new thing, got to make a new name. Interestingly enough, they decided that Nanosaurus shouldn't be a thing at all because apparently it wasn't its own dinosaur. So they kind of struck down the whole category of Nanosaurus. And they've created, I think, several subcategories instead.
This particular one is the Enigma Cursor, which is which means you know mystery runner. Enigma Cursor, and then what's the last name? It's it's a person's name. Molly Molly somebody. I'm looking who was nice enough to to pay some money to help these archaeologists do this work.
It's the the Enigma Cursor Molly Borth Wiki. Yeah. So thanks, Molly Borthwick. So we, we have this new dinosaur name. Yeah.
So apparently what we've, what we've learned is that there is a new dinosaur identified and named every week. This is not, this is not a super rare thing, but it is, you know, rare that in our own backyard we find some new fossils and it turns into a dinosaur. And, and now Molly's famous. Yeah. And in case you wanted to know how big this dinosaur is, it's about the size of a wallaby because, because all Americans know how big a wallaby is.
As we were doing some additional research for this, we're like, oh, how big is it? And I found a Smithsonian article that said it's about the same size as a wallaby. You know, if we were in Australia, we'd be like, oh yeah, size is great. So then I had to go look up how big a wallaby is. A wallaby is about 18 inches from nose to tail.
All right. Yeah. And it is also possible that this was not a full-grown dinosaur as well. So maybe— how could they know that, Alex? Who knows?
I'm not an archaeologist, Rob. Well, like the little top of the bones, like seal in after it finishes growing and these bones hadn't all sealed in. That's the non-scientific definition of why. Anyway, that's— you've stretched my science knowledge as far as it goes. Let's move on.
You know, speaking of old things, if you wanted to go somewhere to see other old things, some ruins even, Denver now has a nonstop direct flight to Rome. That's fantastic. We went to Italy a few years ago and it was not direct, and I really would have loved it to have been direct because it sucks to to miss your flight on your way through Germany. Yeah. Thanks, Frankfurt Airport.
So now United Airlines has a nonstop direct flight to Rome. It operates in the summer, I believe May to September or something to that effect. And I think this is the only nonstop flight from DIA to Italy. Yeah, they did mention if it goes well, if there's enough demand, they'll keep it year round. So, you know, I want you all to start booking your flights for the fall and winter so that whenever I want to go back to Italy, we can get there directly.
Yeah, and actually the article is pretty good too. This is a little bit of a travel blog. It looks like it was, you know, a bit of a paid promotion from, from United, but the person who wrote it spent a bunch of time talking about all the things that they did in Italy. So read that and apparently inspiration. I don't know how many single traveling women are listening to our podcast, but if you are a woman who likes to travel by herself, apparently Italy is the place for you.
This is what our— the blog writer suggested that, yeah, and that women traveling alone is actually the single biggest growing traveler group. So get out there, get to Italy, have a good time, find some pasta, see some relics. Yeah. While you're traveling on that plane to Italy, you might have a, you know, a battery or something to that effect to keep your electronics charged while you're there. And when that battery is all spent, you want to get rid of it.
You know, Rob, what is it you do with it? What, what I do with it or what I should do with it? Well, maybe those are the same. Maybe they're not. What I should do with it is keep it in a box in my house forever, making sure the box never catches on fire because I can't put it in my trash because it might cause a fire somewhere else.
We have not had a good system for disposing of batteries in Colorado, but that is about to change. Yeah, there was a law that came into effect in Colorado that says that there needs to be a way to get rid of batteries. And it has to be— I don't have that. It's like 15 minutes between 15 miles, 15 miles of 95% of the population or something. So by October of 2028, that there will be coverage, at least one drop-off for small batteries within 15 miles of 95% of Colorado residents.
So that's, that's going to mean that we're going to have a place to take batteries. And this means like the little batteries from your watch, the big the, the D batteries, the big like rechargeable lawnmower batteries, all these batteries are gonna have a place to go where they can not only not damage the environment, but maybe be reused. 'Cause there's a lot of valuable materials in at least some of these batteries. Yeah. And by 2029, there must be at least 15 permanent collection sites for medium format batteries, which are those, you know, power tool batteries and e-bike batteries, things like that.
So it's, it's nice to have these things coming. There's a little bit of controversy here, right? There is a for-profit company. What's it called? Redwood.
Redwood Materials. Redwood Materials. Yeah. Who, who are like a, a for-profit battery recycling company who are, you know, they're opposed to this because the government's basically going to create a, a public option that steps on their business model. But what the government's response is, is, well, that's true, but Redwood Materials is only taking the very valuable lithium batteries.
Yeah. That that are, you know, that are maybe worth the money to tear apart. And they want to build a system that, that takes all of the batteries, including those where there's not a good ROI to recycle because they don't want those things in landfills and they don't want to, you know, they want to, they want to harvest that value. And by lumping them all together, it becomes a, a break-even or a profitable endeavor versus, you know, just throwing away the rest of them. So it's an interesting conversation, capitalism versus whatever the other option is, communism, I guess, you know, which is the right fit for Colorado for this particular question.
Good stuff. All right. Next, we have an article. It is an interview with Brad Feld, who is a, as we know, a VC out of Boulder, you know, helped start the startup scene here in Colorado, founded Techstars, and has done lots of other stuff. And it's him talking about his give-first philosophy.
Yeah, Brad has been— he's really been out of the public eye for the last couple years. If Those who remember, he was quite active in Colorado, um, talking at Denver Startup Week on a regular basis. We had him on the podcast the first year. Uh, Brad has been a character and a, and a really important driver and leader of Colorado's VC, but really technology industry for a long time. The last couple of years, he has intentionally got out of the public eye.
Um, you know, he, he, he's very public talking about there's some mental health challenges and spending time with his family being a priority. Um, and he's coming back into the public eye a little bit, and, and this book is, is part of how he's doing that. Um, so Give First, the, the idea is, hey, you know, you don't, you don't go invest in a community and building a venture capital community or technology community with a really clear, like, this is how this turns into money for me, right? Right. And that's not to say that it's a completely, um, you know, selfless act.
There's an expectation that you're building something that eventually will, will become a viable thing. But, but he says you can't come in with that identity as that is the reason, right? Because it's just not going to work. You have to first kind of give selflessly, build this thing up, and then once you're there, you can kind of figure it out. And I'd say that that reflects what you and I have done over the last decade, right?
Decade plus building this thing. I get you don't know what this is going to turn into, but, but there's opportunities as you get to build a cool thing. And, and I love the way he talks about it. And I love that philosophy that you, you do, you do it because you care about it. You do it because you want to build a cool thing.
And then somewhere along the way, maybe that turns into something that, that is profitable. Yes. Uh, you know, people are going to come because there's a good thing, you know, in the end something good is gonna happen. But, uh, but yeah, if you go into it expecting a certain output, then it, it's, it's not gonna be genuine and it's not gonna be successful. And he talks about this spectrum, uh, between, you know, givers, traders in the middle, and then takers on the other end.
Yeah. You know, the two ends, the givers and takers and the traders in the middle. And he, he mentions that, you know, in the short term, yeah, the takers will do, do well for themselves. And in the very long term, it's the givers who do the best. And, and I— it's a really interesting concept.
I'd never, I'd never heard it written that way or heard it described that way. And I'm interested in learning more about it. So maybe I'll read that book. We'll see. Yeah.
The other thing he talks about is mentorship and how he approaches mentoring relationships. You know, the way that you can be best as a mentor and a mentee. So some, some good stuff in there. Check it out. Read the book.
Do all that good stuff. Yeah, good stuff. All right. Speaking of building a tech community here in Colorado, this next article, it's a Colorado Sun article. Headline, Colorado's post-COVID tech startup scene looks a lot like it did 20 years ago.
This is written by our friend Tamara Chuang, and she's talking about the return to in-person events. Yeah. So apparently the startup community is coming back. There's lots of meetup groups, CEO dinners, founder events, other things like that, that, that really make it feel like it did, you know, 10 years ago, plus 20 years ago. And it seems interesting.
I'm waiting to see what comes out of this. Like, you know, I'd love to see a more vibrant startup community here that I felt like we had a bit ago. But maybe this is the start of that. I think she starts off with a pretty cool story. A serial entrepreneur, Danny Newman, was talking at a CEO, an entrepreneurial group recently.
And he decided as his talk, he was going to have the entire group crowdsource a company while they're doing it. And it was, they're going to crowdsource an idea, develop a sellable product, market, create a marketing campaign and go live with the company all before dessert. Like, you know, over the course of an hour, a really interesting idea. And it was, to emphasize what AI tools can do for you and this idea of vibe coding, which, you know, if you don't know vibe coding, it means you're not actually writing code. You're kind of feeding it into these new AI tools to, to have your, your new things turn, your, your ideas turned into a product.
So the idea that they ended up coming up with over dinner was a, what they call it, an Uber for dog poop pickup, right? You want dog poop pickup at your house, use this tool. Called it the, the Turbinator. Is that what they named it? Yeah, the Turbinator.
I missed that. I guess they went live. I have not tried to— I do have a dog. I do have poop in my backyard sometimes. So maybe, maybe I should do this.
It seems like you could create the app and the company and the marketing campaign, but you still actually need people to go get the turds. So maybe it's not quite fully baked in Before Dessert. I don't know. But it's live. It's live.
You could make an appointment and then they're going to have to find somebody to come get your turds. Why don't, why don't you start talking about the next story and I'll see, I'll see if this thing's live yet. Yeah. Uh, all right, uh, moving on, uh, getting into our security stories. Uh, first one, Swimlane put out a press release that they have raised an additional $45 million, uh, for their next round of funding.
Um, exciting for them. Glad to hear Swimlane is still doing well and still, uh, moving forward. They are going to be using this $45 million to do global channel expansion and product innovation. So Um, SOAR, I guess, is, uh, still alive and well in Colorado. And, uh, they are now also focusing on agentic AI SecOps.
So beautiful stuff there. It's nice to hear, you know, Swimlane, one of the, one of the folks who was around when we started this thing up in 2017, um, still growing, still, still, you know, expanding their reach. They, they have a really nice, uh, set of customers, especially in the, in the upper end. Yeah. Um, I, I know that SOAR is changing and, and getting combined and moving around.
And of course, AI is really changing the way we think about it. Um, I, I am excited to see Swimlane, you know, adapt into this new world and hopefully be a leader there as well. Uh, so Rob, in, in the office here at your house where we're recording, there's a window out to your backyard. When I'm at— when am I going to see someone walk through the gate to come pick up your, your poo? Well, I do see a website for Turbinators, but I did not find an app on my phone.
So maybe— I imagine getting published in the App Store takes a little bit longer than it does to have a website built. So Okay, maybe my guess is they're not probably quite there yet. Yeah. Anyway, moving on to our next story. You keep working on getting your, uh, your dog poop picked up.
I'll keep talking about the news. Uh, the next blog we have is from Laris, uh, talking about, uh, stop overscoping, start pressure testing. So this is talking about how it is that you should run your, your pen tests, um, really talking about how many pen tests are scoped to a specific thing. Hey, I'm going to test you know, this application or these set of IP addresses or something like that versus, you know, testing, pressure testing, you know, your defenses in general, like, hey, this is the goal I want you to achieve, you need to get domain admin in our primary domain or something like that. And really leaving the testing more open how an attacker would actually do it as opposed to the limited scoping that is there.
Um, they talk about the, uh, Pen Test Execution Standard and, uh, how that works and, you know, how that is built to do, to do tests more like this. And, you know, obviously their opinion is you should do less scoping in your pen testing and, and more about outcomes as opposed to defining a tight scope. Yeah, you know, I, I would argue that what I think they're saying is, is getting away from the restrictions that folks will often put on pen testers. Hey, you can go after these systems, but leave these alone because these are delicate. Or, you know, you can do phishing, but make sure you don't do anything that includes an executive's name because we don't want to make anybody mad.
Or I think those, that those areas where security people, maybe we don't feel comfortable or empowered in our company to, to do our job full well is, is kind of cutting the legs out of the pen test and, and restricting a lot of the value. You know, there is, there is a, who I remember having a pen tester, was it, was it Nickerson? He's like, He's like, oh, you full scope pen test? All right, does that mean I can go kidnap the daughter of your CEO? Right?
Like, okay, maybe not that. Like, okay, there's gonna be a line somewhere. Right. And figuring out where that line is, what's appropriate and what's not, is always interesting. But if you're limiting too much, you're just not getting the value out of those professionals.
Yeah, for sure. All right, moving on to our next article. This is a press release from Red Canary talking about their expansion into AI agents and how those agents are, helping with security operations. Yeah. You know, there's this— the press release is interesting.
I actually found it more interesting though, to read through the link in here that where they actually on their, the corporate website for Red Canary, they go through all of the different agents that they've created. And then there was something like 20 different agents. And when I, as I see it, it's, they're relatively atomic, right? Of course they think about things atomically. It makes perfect sense.
They've created an agent specifically for take ingesting the alerts and information from SentinelOne and ingesting the information from Okta. You know, they have different things for that. And then they have one that's there to add context from threat intelligence into the alert. And then they'll have an agent that's there to, you know, I don't know, like I said, there's about 20 different agents. I think that the way that they're thinking about it and creating these really discrete tasks for agents to accomplish allows them to measure the success of agents much more than you could if it was, just this broad thing, go take the place of a SOC analyst.
It's really task-specific, and I thought that was interesting. These are all internally focused, it looks like to me. Like, it— from as a customer, it's kind of hidden behind your portal, behind your CSM. There's— the work is happening behind there, but it should be making things faster, more effective, you know, more complete, higher— higher true/false— or lower false positive. Yeah.
Yeah. You know what I mean? Yes. Good stuff. All right, and then moving on to our last story of the month.
I really wanted to say week, but it's the month. This is a Ping Identity blog post talking about understanding separation of duties in cybersecurity. You know, tried and true concept, but one that, you know, you don't necessarily hear a lot about these days. Yeah, I think it sits really clearly on the line between security controls and financial controls. You know, if You need it for both.
Of course, it's a security control to help with financial outcomes, but there's other outcomes there as well. I think the majority of insider threat will be identified by or prevented by good segregation of duties. The ability for us to, you know, to stop things like poor payments that are going, you know, being wire fraud, right? When somebody takes over a vendor's email and sends a change your bank information Having 2 people make sure, hey, did you really go through the process to ensure that this is a legitimate change? Those types of things go a long way.
And as a security team, understanding what those look like, where those need to go, what the value is, I think it's important. And it's a nice kind of primer on that topic. Yeah. And it's actually a decently long blog talking about the different ways that you can implement segregation of duties and the things that it can prevent. So, You know, definitely something to check out.
Got a little bit duplicative talking about the values, but I think that they're right and I appreciate them keeping to put this educational content out there. All right, to events? To events. That was our news. Let's jump over to events.
Well, we have a calendar of events. We do. So if people don't want to listen to us, they can just go read it at colorado-security.com. Go to the events calendar and see what's coming up. But if you do want us to read it, that's what we're here to do.
The first event we have, ISSA Colorado Springs, is doing their July meeting on July 15th. On the 19th, ISSA Colorado Springs has their July mini seminar. That is their, their Saturday morning, like, deeper dive educational content. On the 23rd, we have 2 events. The Let's Talk Software Security group is doing, is cybersecurity training necessary in the age of AI?
Yes.
Okay, uh, you don't have to go to that one then. Rob already answered. And then, uh, ISSA Pikes Peak, I'm gonna guess that's ISC² Pikes Peak, is doing their chapter meeting on the 23rd as well. And then on the 31st, we have the Northside Cyber Meeting, which is a little less formal group getting together, and you can hopefully get connected there and go hang out with some folks. Yeah, good stuff.
All right, well, that is it for our, for our news this, this month. We do have an interview. We do. Thanks to Frank Victory for sitting down with Rob Lee. Rob is an illuminati.
Is that a good word for him? Sure, he's an illuminati. Is that a polymath? I don't know. That might be a little bit too big.
But Rob is fantastic, a longtime contributor to the industry. He's the Chief Research and Chief AI Officer over at the SANS Institute and has helped create so much of the great content that exists out in the industry. We're excited to hear what Rob has to say. I am definitely excited. Should be good.
All right. Well, that is it for July. We'll talk to you all in August. Thanks, Rob. Hi, this is John Everson, Chief Security Officer at TTEC.
Welcome to Colorado Equal Security for Colorado security professionals by Colorado security professionals.
Well, good morning, good afternoon, and good evening, state of Colorado. This is the Colorado Equal Security podcast. My name is Frank, and it is July 2025. It's actually July 3rd, 2025, the day before Independence Day. And my guest today is a very special guest.
This is Rob Lee of the SANS Institute, and he's also known as the godfather of DFIR. Rob, how are you doing today? Doing great. How are you? It's good to see you.
It's good to see you again. I'm doing outstanding. Rob was my keynote speaker in what, 2023, right, for my SnowFROC Conference, my Denver, uh, OWA SnowFROC Conference. I think it was '24, but, uh, it was just last year. It was— he had years this year, but it's '24.
I'm trying not to age myself anymore than you actually need to age me. So, well, I'm trying to figure out what year it is, uh, much less, you know, what month and everything like that. It's because it seems to have flown by, right? Uh, but Rob is known as the godfather of DFIR, uh, CISOs, CTOs. He talks to— talks a lot about AI, right?
And with over 20 years of cybersecurity and AI initiatives, right, he's a founding officer. He's worked for Mandiant, wrote the M-Trends, or wrote the groundbreaking Mandiant M-Trends. Lots and lots of credentials. I actually first met Rob probably about 10 years ago at his, I think it was at the 508 class at SANS, and learned a lot about him, mostly though through the recordings, right? I think that we actually had a different instructor.
He dropped in for a minute, but we had a different instructor, Alyssa. She was completely awesome. And just what an absolutely wonderful course. So again, welcome, Rob. Uh, I do have a question for you to start off with.
You're known as the Godfather of DFIR. Is that because you're wisdom-filled, you're philosophical, or, or is it more kind of like this here? And hopefully we can hear the sound bite. I'm gonna make them an offer again. Is it that kind of thing right there?
You know, you can make that offer, and if so, what kind of offer can I not refuse from you? Oh, uh, so wait, which question are we answering?
Well, what kind of godfather are you? Are, are you the full of wisdom, or are you the one that's gonna make me an offer I can't refuse and possibly make sure that, you know, if I do refuse, I'll be sleeping with fishes? Um, yeah, it's definitely the latter. So, uh, I don't know. It's like someone said to you, you're full of wisdom.
And I'm like, oh, I immediately reject that one. You know, and so it's got to be the second one. You know, offers you can't refuse. I'm like, well, I don't know. It's less than the first one.
So it's like if I have to choose the least of the two, I'll choose the number two. But well, in that case, make— I just want to note that I gave you all positive remarks on the review for the class as well as everything else. Everything was absolutely positive. I like my shoes being made out of, you know, regular shoe material and not out of concrete. So, all right.
So I would— I will say that the moniker came from the other Robert Lee during a— it was like the 10th year of the DFIR Summit. And they— he just said something about Rob Lee is the, you know, godfather of digital forensics. I'm like, oh, that's I guess it stuck and people just started calling me that at this point. So, um, why do you keep it? In that case, why would you keep it or why not?
I mean, I, I like it. I, I, I like the idea, but what— oh, they— I'm told I have to. Oh, you're told you have to? Okay. I'm not given— I'm given no choice.
Uh, you know, uh, yeah, it's, uh, I don't know, it's— the moniker is kind of stuck at this point and it, uh It's fun. It really is. Again, I really like it. I think it makes you stand out. And of course, with your absolutely incredible credentials, I think it's a fitting one, right?
It's especially— I think it's like, what is it, the— in the fighter pilots, they're given a nickname and they don't get to choose what that nickname is. It's given to you. Well, again, I think it stuck with you. Yeah, well, in Top Gun: Maverick, I like the guy's name. It was just Bob.
Like, that's— I was like, that's the best handle ever right there, Bob. Yeah. So can we call you just Rob at times, or? Yes. No, please.
Well, here's one thing about it. On your profile, you've been with the SANS Institute for 25 years, and I think that is incredible for any career field. But specifically in a career field like cybersecurity, where we do have a tendency to only stay with companies for, what, 3 to 5 years? What makes you want to keep staying with SANS, or what advice can you give to somebody that's listening to this podcast? Should they stay?
Should they go? Well, that's a great question. Well, officially, I've only been with SANS in a full-time role for about 4 years. Um, I was a contractor, you know, instructor, uh, since 20— uh, 2000. Um, and, uh, yeah, 25 years is a long time.
You sit there and think about that now. Um, but, you know, the thing about, uh, why I enjoy SANS so much is, you know, is it goes back to being— when you— and maybe it's just like overthink these things, but when I was doing a lot of the initial talks at SANS. I've really felt that a lot of the greatest impact I was having was through instructing others and sharing my experiences, what I learned in the Air Force Office of Special Investigations, my time working Title 10, Title 50 work. I mean, all these other little things that I've done is by training others to be able to handle really difficult problems. And that really, um, was the real— was the one way that I felt was able to help bolster, you know, overall cybersecurity and the defense of folks that are out there.
And plus, it was fun, you know. Everyone was all— we're all in it together. We're all learning. Um, it's not like I was, you know, some expert. It was just the way I was thinking of it.
It's like I'm showing— sharing what I learned, you know, and tinkered with yesterday. And so the SANS Institute, you know, all of the instructors are these practitioner instructors that have basically really have enjoyed sharing what they do, how they do it with the overall community. And, you know, SANS gives them the platform, you know, to be able to do that. And considering it's worldwide, you know, we do training everywhere. We have a massive mission program that's out there that does a lot of free training.
Content. Overall, the organization is really dedicated to furthering cybersecurity, cybersecurity workforce, and a lot of very similar efforts. I could go on and on about why I love SANS, but it really comes down to just, it has given me the greatest ability to create impact in the community through the different mechanisms SANS exists in. Do you think that's important? Like, how important is it to you that you create that impact?
Is that something where, okay, well, I always have to create that impact, or I'm good with taking a step back? Well, it's a little bit of both. You know, you want others— I mean, it's not really about me at all. And, you know, that's one of the reasons I don't like the monikers, because it, you know, it sounds very self-centered.
Into what I was doing. But it's like, you know, what I do ends up making a difference, or, you know, someone, you know, hey, this is kind of cool, this is pretty amazing, and it helped me out, then that's great. Um, and that's kind of, you know, what it, what it really boils down to is that I continually like doing things that have broad impact in general, and I don't think that's really ever going to change, you know. Um, I've never, you know, even if I'm not doing cybersecurity, I'd probably be doing something in the community, you know, helping, you know, with my kids at school, you know. It's like, you know, you have multiple ways to create impact that's out there.
Um, SANS just is a capability that, you know, draws in a fantastic amount of, you know, professionals that are able to dedicate themselves to saying, hey, I really want to make this, you know, a career, and you're really helping them out. Okay. So when you're helping people out, and how did you think that helps? Like, you know, what drives you to do that from your career standpoint? Do you think you get any benefit?
Like, if you were, you know, I took your class, And, you know, along with, of course, what, thousands of other people. How do you feel when we take your work and we're showing your work out there, or possibly, you know, in some ways improving on your work or reteaching your work and saying, you know, this was great material, here's how I can make it better?
Well, I mean, the thing about trying to talk about a topic, it forces you to learn a topic. Even if you say, hey, listen, I've just learned this, but I'm going to try and work my way through it with you, it forces you to walk through the logical leaps that someone else may end up missing, or, you know, miss in general, or, you know, helps hone your own knowledge. There's a lot of the things that in the process of, you know, me just learning. And, you know, it even goes through today in which, you know, a lot of my learning is now focused on AI. And I really feel— I actually know I'm not the best at it, but again, I'm dedicated to learning and tinkering with it on a daily basis.
And through trying to talk to others about things like AI and then, you know, digital forensics and, you know, these broad topic terms, that level of knowledge that you are trying to accumulate ends up having more of a razor-edge focus. And as a result of you putting yourself out there a little bit more and trying to say, hey, I'm gonna try and teach someone else what I think I know, or I've just learned about something— and just because you teach someone, it doesn't mean you're declarative the expert either. It is meaning that you're trying to share an experience of something you just went through. And that's, again, you know, teaching comes in a lot of different forms. And that's the thing that I really want everyone to kind of recognize is that even if you're brand new and you've just been doing this for a year, you could still be educating not only those who are coming up behind you, but those who've been here for a while.
The new techniques that you've used in your learning maybe something that your boss and your other technical team members have never seen. So, you know, take that to your advantage and say, hey, look, don't assume everyone knows everything and you're just the one who's playing catch-up. You may have touched on something that no one else has seen. So you constantly can become better by educating. And I say, you know, and we're just— stop thinking of it as a formal thing, education.
Think of it as just go talk about what you're doing to others and share. And those principles will then get people to lean in and saying, well, what did you do? How did you do that? Did you consider this? And now there's bilateral sharing and education.
And that's one of the things that, you know, I really encourage everyone out there to, you know, truly think about is that, you know, the more that you share, the better the community is going to be and the better that you are going to be because you're going to force yourself to say, if I'm talking about a thing, I should know about a thing a little bit, you know. And again, even if you say, I don't know what I'm talking about, but as soon as you start walking through your brain to discuss it, it'll make it more of a permanent memory and create the calluses in what that thing is that you're trying to do. It'll help you, you know, become an expert at it. Do you think then— and what I'm hearing you say is that we must always stay within community events— that do you encourage everybody to be in community events, and especially when we're talking about people that by nature that are in this industry introverts? Well, I don't know, I always push back on, you know, what is an introvert versus, uh, extrovert.
Introverts still love people, um, they still, you know, like the connections. They just recharge in a little bit more solitary state where extroverts will probably go to a coffee shop and meet a friend. Um, it is— I always push back on, you know, those definitions a little bit. It's like the community is very friendly. It is one of the most welcoming communities I've ever seen in my life.
Um, and I think that part of the reason is, is that it is such a fantastic and challenging beast of a thing to try and wrestle with a science and knowledge base that is changing year over year. So I think to that extent, unlike other communities, and you know where you might say, hey, we have a running community, we have a— the medical community, you might go to an event in 2010 and an event in 2020, it's basically the same thing. We're talking about running And of course the runners out there is like, Rob, you're an idiot, no idea what you're talking about. But if you go to an OWASP event in 2015 and you went to one now, the thing that is only the same that is being talked about is the people potentially. The topics I guarantee have significantly changed.
And I think because of that, when you talk about the community and the introverts, extroverts, and why they're so welcoming is like, we all kind of know we're in this together. And if we don't go to these community events, you know, whether it's a SANS Summit, you know, OWASP get-togethers, your own local groups and team members, all kind of like, you know, what have you heard the past week? What's this latest thing that's coming out? I think that's what makes the cybersecurity community extremely special is that we know no matter if we disappear for 5 years and come back, it is not just talking about running and, you know, what is the fastest time you could do a 5K in. Everything you're currently talking about is almost like you're showing up to the same event, and the only thing that's the same is, hey, we, we have muscles in our, our hearts in here.
Uh, everything else is like, I guess today we're going sailing and tomorrow we might be playing golf, uh, but no one's ever seen golf before, so we better learn how to play the sport before we go out on the on the field tomorrow. And I think that, that's a good analogy. I should actually, like, write that one down.
That is how I feel the cybersecurity community faces problems, is through that. And, you know, sure, we're all shy. Everyone's shy. I don't see that as unique to cybersecurity. That's everything.
Okay, well, I got 2 things that I'm coming out of that. The first one is let's talk about the topic. So I think a couple of years ago, Ransomware was a big thing, right? It was a big hot topic. And of course, we had Bitcoin and things like that before.
But now, and what you mentioned earlier, it's AI, right? And I do see in your profile, of course, you partner with, of course, the OWASP AI Exchange along with the SANS Institute. What are probably some of the biggest concerns about AI? And what are some of the biggest benefits?
You're going to have me take over this podcast. Well, that is the entire point, right? The entire point is they want to hear you. They're probably tired of me talking. Oh, good Lord.
You could go down this path multiple different ways. Let's just, you know, sort of— I'm very optimistic about AI. I think, you know, from a cyber— and I'll just stick to cybersecurity in general. AI is extremely transformative. It is going to change everyone.
You know, everyone's using the internet, has phones connected to the internet. Everyone uses email, browser. It is now part of every single human being that is, you know, tied to electricity somewhere out there. And even then, you know, with Starlink, it's even expanding even faster now. AI is going to be the same.
You will not remember a time from this point forward that, you know, you will not be working or copiling with or having AI assistance or, you know, anything out there that's helping you out. Like, if, you know, 2, 3 years ago, we might have had a, you know, that was probably the last instance where we probably say, hey, we were trying to do our jobs without it. And for cybersecurity in particular, Uh, and I'll just say, let's assume the threats don't progress. It just— threats are threats. Um, you know, the thing that's— it's going to be able to be able to be utilized in cybersecurity is the reasoning capability and decision-making capability.
You know, everyone is saying it's going to replace our jobs, and I'm like, I really push back on that because I think we're still in a situation in cybersecurity that we can't examine every single packet. You know, we don't have the capability. Where are we going to put it? You know, do we have the analysis tools to be able to look at that? Do we have enough capacity to be able to inspect, you know, more alerts that are coming through?
So when we end up saying, what would an AI-powered cybersecurity human being look like, is they start to be able to aggregate more and more of the ability to move faster and do more, be able to block more things with a single human in conjunction with— and I'll use the term agent swarms— to be able to utilize multiple different capabilities inside a network orchestrated by that one human that is essentially going to allow for cyber defense to scale in ways that we've never been able to see before. So I get really excited about it because, you know, I always go back to, hey, someone asks you the same thing, it's like, hey, your job is to keep the lights on, right? I'm like, yes, except we all know no one in the, you know, water industry, uh, really can afford, you know, some of the best cybersecurity analysts that are out there. In fact, they struggle. But what if you put an agent swarm inside that network for defenders and suddenly you're able to say, hey, we have 1 or 2 people that are able to manage a network of agents that are helping defend this critical infrastructure node from an attack.
To me, that creates more safety capability and makes my kids safe, your family safe. And to that end, you know, we have a lot of industries out there that can't afford the bright and shiny buttons, but AI, I think, is a great leveler. Well, let me ask you a question. Real quick, let me interrupt and ask you a question kind of based on what you were saying here on taking over jobs. And I'm going to touch on a controversial subject here.
No, please. I think it was probably what, probably a few months ago, CrowdStrike, there was a RIF and there was some rumor there that the RIF was caused by AI, that they didn't need as many people. And of course, you know, this is really trying to address your comment here where it says, well, AI is taking over our jobs. If that rumor is correct, then AI is taking over our jobs, uh, because of the reason that you just said, where now 2 people that are AI enhanced are now being able to take over for 3 or 5, maybe even 3 or 5 people. Yeah.
So what are your thoughts in that case if someone was to come with you in that situation? Well, this is going to be the, I mean, the shark attacks of the summer right now. And it's going to be probably carrying over for the next few years. Uh, there'll undoubtedly be companies that are going to try and, uh, cull their workforce saying, hey, we could have this done by agents now, instead of realizing that part of the thing that enables agents to be really programmed well is people who know your organization extremely well and know what their jobs are extremely well, or how your organization goes about doing those kinds of jobs extremely well. Where I think the greatest impact will be, uh, from a job perspective is that you'll see companies do more with the same, meaning that if they're doing it right, they would not really need to be cutting the workforce.
And, you know, you have workforce cutting things regardless, you know, whether it's AI or not, but let's just keep it to AI. If everything is fine and all of a sudden AI enters a technology stack that we currently have, you might be able to say, hey, listen, we don't need as many farmers with spoons, we need more tractors, but we could have more fields plowed if we have all those farmers trained on the tractor. And, you know, it creates scalability. But in the modern workforce today, the thing that has been driving more than anything else, I would say, growth is the data and information that is sitting in, you know, what is running around a lot of the individuals in your organization, if each one of those individuals figures out a way to potentially code a part of their job, you know, it's going to be taken over by an agent. Um, I use the term agent, you know, something that's able to reason that, hey, this eats up a lot of your time per day, you don't have to worry about this near as much.
Um, and so with that in mind, you're going to be able to potentially have an individual start to focus more on the creative aspects of their job, saying, I'm going to focus on the hard problems while the small problems I'm going to have my agents go and start handling those. And because you know your job better than anyone else, you're able to potentially create that benefit for your own organization. So, okay, so, so here's a question then, especially on the agents and knowing the jobs here. You know, I'll take a quick step back. And when we look at using things like Microsoft Word, we know that when we spell something wrong, it gives us a red squeaky line.
We, you know, we right-click it or we click it, we get the correct spelling of it. And that has had a bit of a psychological effect, at least when I was studying and getting my certification for becoming an instructor, that in some ways we have become dependent on spellcheck, we have in some ways become dumber, right? In that instance, do you think that AI is going to cause us that same type of trend, that we're going to basically not know how to do our job with AI? Do you become, quote, stupider, right?
Because of AI? Oh, the great debate right now. And it's much— this debate is amazing to have, by the way, when you're having a cocktail at the same time, because then the debate could turn into which creates the worst brain rot, the AI I'm using or the alcohol I'm drinking.
So it's a, it's a, it's the new debate that I always challenge everyone to. Let's meet at a bar and talk about this while we're rotting our brains with alcohol. We're going to rot our brains with ChatGPT. So now here's every technology that's out there. You know, We could sit there and look at modern food processing.
You know, we have, by and large, have more abundancy than ever before in every grocery store you ever walk into.
I kind of laugh at things. You know, Frank, you probably remember hearing these things. Strawberries are in season or not. When's the last time you went to a grocery store in the United States that you couldn't find strawberries? Right.
Yeah. You know, so there's this aspect to it that, you know, because of the new technologies that are out there and, you know, modern shipping and all these other things, we end up having the ability to have this, you know, massive abundant capability and capacity that's sitting in our grocery stores. Ironically, though, if you also go back to the 1930s, 1940s, what it was, the average height, weight, and, you know, scalability of a human being at that point, What has happened since? You know, so every time you potentially introduce a new technology, there are going to be clear benefits. And the clear benefits are we have abundance.
We have— and of course, you know, it's like, hey, that's part of the problem. It's like, yeah, notably. But we don't have near as much of, you know, starvation as a human societal issue like we used to in the past. We have so much abundance of food and capabilities of people's choices, but then the processing and being able to do the mass you know, production have created its own issues. And the reason I mentioned that is because it's a very clear— you could write a study on it as to the technology changes in food production, what was the result on, you know, human health and everything else.
Some cases we're much healthier, in other cases we're not because we're, you know, a lot of people carry weight. And I say this, you know, because I've lost a lot of weight in my life too. AI as a technology is going to do the same thing regardless whether or not you just sit there. And it's the same thing with TikTok, social media. You know, has this helped connections, not helped connections?
Is AI going to make it easier to cheat and not think? Yes. But equally so, the way I'm using AI is to force myself to learn. I will say, I've never done this thing before. Um, I'm stuck.
I now have a thing, even like I'm doing plumbing. I will take a picture of the thing and I'll send it to ChatGPT. And I said, here's what's going on. I think I'm doing this right. What am I doing wrong?
And even in a plumbing thing, I never would have touched this before. Now with AI, I'm at least trying to do basic things just by sending it pictures. Okay, now what? And it says, here's the next thing you do. Take a picture.
Okay, here's now what you're doing. And again, even on your own computer screen, people, that's the one they, you know, if you get an error, say I was doing this task, here's the error I got. What do I, what am I supposed to do? You know, remember we used to use Google search and we copy and paste in what we think the error message is. This is like the new game changer.
You're still going to be able to troubleshoot, problem solve, learn. And then if you take that additional step in ChatGPT and say, why did, why did I get a 0? What did I do wrong? What was my thinking? And it'll actually coach you a little bit.
So you're going to have your own little personal— if you do it right, your own personal coach guiding you to learn, creating more creativity, figure out new ways to do more problems. So make sure that we're using— well, so make sure that we're using AI as more of that, and you probably remember this, bionics versus a crutch.
We could say that, but we all know everyone's gonna be using it both. Spell check has made writing improve, I'll admit, but even my kids aren't even taught cursive anymore in schools. Okay. So it doesn't mean that technology changing was once good or bad. I will definitively say AI is going to have a lot of negative impacts on your, you know, just to that point you're saying, yes, that is true what you're saying.
It is going to create laziness. Do it for me. I don't want to think. I don't want to create. Well, if you're thinking like that, your job is likely going to be replaced, tying back to the previous question.
If you're using it to learn, create, challenge, move ahead, accelerate, scale, you're going to be using AI in ways that no one else is going to be able to keep up, and you're going to become a superhuman and doing things that, you know, you're going to say, I never would have attempted this on my, you know, by myself without AI little, you know, copilot along the way. And I'll just tell you a quick story on this. It's like my kids are like, AI is bad, you know, it's going to be used for cheating. And I showed them how to use it to write a song. And I said, no one would ever be able to say, like, you know, you just dump your feelings out, you know, just tell— write it down, dump it out, then take a picture of it and say, I'd like to create lyrics, you know, that really, you know, kind of sound like my favorite artist or something like that, and take the lyrics and, you know, create a song out of it.
These things allow a human being who don't have the ability to pay for a lyricist or to pay for someone to write the music for you. And again, you don't— you think all those superstars out there are doing it all themselves? They're not. Maybe they did a few, but they now have people helping them, just like AI is going to be helping you. You now can express your ways— yourself in ways you've never thought of before.
It's really cool if you think of it in a creative way, not in a life-cheating way. That's, I think, very good advice. And I think it's going to be a constant battle, right? Like you said, it's not going to be something where Oh, I'm going to always use it in a creative way all the time. I think it's going to be each decision that we make and that we have to force ourselves to consciously again make sure that we're using it as that bionics, as that enhancement versus that crutch.
Um, I'd like to kind of take a step back to something that you said way a bit earlier about going to coffee shops and our introverts. And really talking about things like, okay, we, we all are very passionate to be in this industry. We do have to have that passion in there. We like to work extra. We probably do stuff after the fact, right?
But, but how do we avoid things like burnout? Because I think burnout is a real thing. How would you address that? I mean, what would you say? Um, well, I think burnout— and well, here's the thing, I think we're trained societally to not allow the human soul and entity— and this is not even part of it— it's like to have natural breaks in our lives where they should take place.
It is you have to move on to the next thing. You're wasting your time. This time waster mindset. But if you're— go back and talk to your younger self is maybe take a year or two after college and just, okay, I got this thing. Let me go explore a little bit.
Or take a little bit more time when your kids are young. I'll take a year off. I'll go do something with them I've never done before. We're always waiting for us to be at the right time. And I think burnout is just a natural condition that occurs as a result of not prioritizing your own boundaries from professional, family, all these things to be able to say, you can get burnout on your family, you just can't quit your family.
So, you know, there's these everywhere you're going to be running into burnout. The question is, are you creating your own boundaries enough to do that? So I coach a lot of folks out there and they say, I just feel like I've reached burnout. I said, dude, just take 3 months off. Go— how long you been there?
It's like, just ask them. Instead of quitting, which I feel like I have to do and then I'll have to immediately go get another job, I said, can I just take a sabbatical for 3 months? And just see what they say. They'll probably say yes, we'd rather not lose you. But no one asks these questions.
No one. How many people have ever got, I would like to take a 3-month sabbatical. I've been here 15 years. I would, you know, uh, I think employers would be like more open to this. And I do think in life, those life beats also should be there that, hey, you know, it is totally okay and not weird to take 6 months between job A and job B and just say, I don't know what I'm going to do, but I'm going to go on a cruise for a little bit.
Um, you know, but again, it's my advice to a lot of folks out there is like burnout is going to occur no matter where you're at. Is the lot— the reason why you have burnout is because you're not creating successful boundaries between profession, your family, and everything else. You need to shut the laptop, you need to read the book, you need to go out and take walks, spend time with your kids, not spend time with your kids, go watch movies, create boundaries. And it's a boundary issue. Well, okay, so I happen to know that, uh, Robb Reck and, you know, half of the actual official Colorado Equal Security podcast or the group here took a few months between jobs for the same reason, and exactly like you said, um, what— and I, I don't disagree with you, but I think financially that's not practical for a lot of us to take 3 months off.
Um, so— oh no, I didn't say— I didn't say quit work. I said ask your employer if you've been there for a long time especially. They may say yes, go take 3 months. And they will just give you the time because you've been there. And I've, I've seen this happen before.
We just have not really pushed that lever enough to be able to do that. You may just say, hey, I've put in some good time here. Um, I feel like I'm given a choice. I have to do A or B. But again, you know, I think people look at things as very black or white in terms of not looking for the middle ground.
Um, and what I always say with that is like, you know, always take those beats when you can, especially after about 10, 15 years. But the reason why we're consistently feeling burnout on a week-in, week-out basis is that you feel like, hey, I have to go work on the weekends. I have to work until 9:00 PM. And I'm not saying don't, you have to be the get shit done person. But at the same time, this is where I think AI will really help you out and maintain focus is create those beats, figure out ways to, you know, get more time back.
But then once you get that time back, create the boundary again. It says, I'm going to take this for myself. And usually every single time I've heard of burnout, it is related to you just have let the thing overtake you and not create enough boundaries to establish yourself outside of the profession, your family, or anything else. Cybersecurity is awful because you're on beck and call all times during the day. There's not enough of us.
You know, it's very stressful, but at the same time you have to figure out a way to shut the laptop and, hey, I'm gonna go cook dinner for myself and I'm gonna sip coffee in the morning. Um, I, I mean, Craig, I'll do one last thing here. It's like, I, I've— it took me a podcast, like years of podcasting, of not doing them, listening to them. Uh, but one of the biggest ones, biggest piece of advice that I try to adhere to, especially in the morning, is I don't reach out to my phone until about an hour, an hour and a half after I've been up. I've done my workout, I do a cold plunge, um, and I meditate a little bit, you know, like I read, you know, that I'm violently protective of that time now.
Um, but someone who reaches for that phone, you'll be pulled in because if, you know, someone in Asia wrote you an email, Europe wrote you an email, they're already online. Um, and you immediately go to work. So even if you wake up at 5, you have no freedom. So you have to figure out a way to create— um, don't reach out for your phone in the morning. Give yourself an hour.
Start with 30 minutes though. Don't reach out to your phone for 30 minutes, and then, you know, see if you could increase it from there. That will help reduce the fatigue that I think is created by burnout. Well, let's kind of shift a little bit here. Um, not really shift, but kind of build on that, because you mentioned, of course, Asia and other countries.
Of course, SANS is a global organization. You know, let's touch on a very specific subject here. Do you think that the American culture where we're always going and we get 2 weeks off at a company versus a lot of other countries where they get a 30-day vacation and that's pretty standard, what are your feelings on that? Great question. It has less to do about the United States versus other countries.
You know, and some of those, you know, I know are written into law and so forth. Uh, you know, you have companies here in the United States that kind of give, you know, more free time to research and development on Fridays than you have other— you know, it, it is all about culture when it comes down to what is the kind of culture you want, uh, to potentially have. Um, you know, the other side of that, you know, training company, like I always tell those trying to get cybersecurity jobs, I said, you know, and I tell a lot of in the HR community this too. I said, training should be as guaranteed for at least cybersecurity folks, maybe anyone in IT, as much as vacation is. You go get hired, you get your 1-year annual training, whatever it is, you know, they need to treat it like it is a thing as important as vacation or an HR benefit.
Um, and just, you know, you have to pay for vacation, you have to pay for healthcare, you have to pay for training. Now I know that's very self-serving for me to say because I work in a training organization that, you know, hey, we train people. But I think in our world, we end up having to make a choice. Do we use vacation to go do our training? But then I take it away from my family, but I know how valuable training is, so I'm going to take my vacation and go to Black Hat.
These kind of things could be solved because in our world, Frank, you and I know how important training is, and it doesn't matter if you go to Black Hat or any of these other things. You need a week at least of time and you can't really— I'm not a big fan of like every training on top of that, which is like, hey, I'll do online stuff, cool. But I do believe in going and doing the community bonding thing and going out there, hanging out in a conference or training class is helpful. But going back to that, your core question in there is that's one of the aspects of— I've not seen any country on the planet nail that one yet. But I think it needs to be done culturally in the IT fields.
Um, especially cybersecurity. But what about vacation and other, um, uh, when you end up talking to other different, you know, folks in different countries? Listen, you know, I fully get that, you know, but at the same time over there, that is, you know, I'm not going to even dive into is there a system that's better than the others. It's like, are you in the culture? Are you in the career field that allows for that?
I was in the military. I really, you know, even though I had vacation, you, you and I both know that That's nice. You're now needed over here. And that's— is the military, you choose to go be in the military. You choose to be a firefighter or a policeman.
You choose— or policewoman. These are career choices that you make. And of course, not everyone has those choices. But to a certain extent too, there's agency when it comes to the culture you potentially want to be in. And I know a lot of people said, I don't want to join the military because I don't want to have to, you know, I'd like to have some agency over my life where in the military I don't have as much.
So I think the nutshell comes into it's a cultural thing. And I think it's more important for us in the cybersecurity community to, you know, draw lines around the thing I think is really going to give us life, which is, I believe, continual education and ability to tackle those things without impacting our normal day jobs. Now, you, you mentioned the military. Of course, uh, you were in the military, so was I. And then of course you have been in the career field for a long time here.
Did you always plan— was this part of your plan? If we go back to, let's say, your high school self, your middle school self, did you say, I want to be in cybersecurity? And, you know, based on, uh, both our ages here, that probably wasn't even a thought to a lot of people back then, but Have you always worked in cybersecurity? Have you ever had any weird jobs or anything like that?
Yes. No. So I went to the Air Force Academy and studied astronautical engineering, and I wasn't able to go into that career field because of my color vision.
Really thought my life was over and then ended up being the best thing ever because I got pulled into an experimental unit at that point, the 609th Information Warfare Squadron. And I kind of applied for it-ish, meaning that when I heard about the unit, I intentionally went and sought the commander who's going to be visiting the Air Force Academy. And I was taking computer science courses and security behind the scenes. And I was a closet hacker at that point. I just thought it was fascinating.
And so I went and wanted to do this thing. And then, you know, I got assigned down there. And so, yeah, I was basically in the military. Like, that was kind of part of the plan. But I was— because of Star Trek, I wanted to go do space stuff, but ended up taking a detour into cybersecurity in the mid-'90s.
So wait a minute. Hang on. Let's back up a second here. Astrological engineering? Astronautical.
Astronautical engineering. Did I say astrological? Possibly. I, I may have just read it down wrong. Uh, I can't read my own.
I like astrological too, just so you know. Okay. All right. But, but what, what is that exactly? Um, you— there's a heavy thing down here that you need to put heavy thing up there.
Okay. Okay. And that's basically what it is, is like, how do you do that? And how did not being able to see, like you said, some color issues with red-green? Yes, you can't.
It's the same reason I got knocked out of pilot training is red-green color vision. Yeah. Yeah. So, okay. Wow.
That's kind of an interesting thing because we've had, of course, other people in the military crashing planes and other things like that. But if you could overcome that, let's say for whatever reason, let's say that AI now allows you to correct that problem or not be an issue, would you leave what you're doing now and possibly go back to that career field? Um, well, okay. There's, there's always this, uh, uh, I would say there's always the aspect of, um, you're fascinated by the things you fell in love with always. And I'll always just be completely enamored by like SpaceX and Virgin Galactic and, you know, all the space stuff that's out there.
I love it, love it, love it, love it. Um, would I switch over and, you know, do it? Uh, no, you know, because like you, once you have your career and you kind of have yourself set, um, you know, if I go do stuff like that, it would be like some sort of like, hey, go be a part of it, you know. You know, maybe the space, you know, we'll have space travel in 30 years. I have no idea where things are going.
But the bottom line is that, you know, I've always loved it and it's always in my heart. And it's, you know, it's kind of like it's always going to be there for me. Okay. Well, we are coming close to the end of time here, so I'm going to give you the hardest question or possibly the easiest question to end up with. Right.
So it's my favorite color is blue. Yeah. Blue. Blue. And then, and then 42, right?
Yes. Okay. What is the greatest challenge to security today, and how might you address it? Now, I'm not saying that you have to solve it, but how would you do it? And of course, we've talked about things like AI and we've talked about some other things.
Is that going to be the greatest challenge today? And would you continue that? Or if you had full control, if you said, You know, no matter what I say, AI is going to go this way. Would you continue or would you say something else?
Okay. I'm— rephrase the question. Okay. So the greatest challenge today, would I say it's AI or would I say it's something else? Yeah.
Or what is the biggest challenge to security today? Is it AI? Is it education? Is it training? Is it burnout?
What do you think is the biggest problem that we have today?
I'm not, you know, and here's the hard, you know, hard part because I could sit there and go down each one of these topics in and of itself. I think by and large for our careers in cybersecurity and where things are today and where things are going. I would, I never really want to point at a tech stack because every single time there's a new tech stack, someone, we end up solving it to an extent. I definitively think that our society is becoming more and more dependent specifically on these connected technologies and the risks of that connection and that connectivity. To everyday life continue to rise.
And therefore, I think cybersecurity as a definitive and needed profession of problem solvers is needed now more than ever, especially since we're facing a massive transformative technology stack that's in front of us. When I think about In particular, there's this general feeling that, you know, a lot of these things have been solved. I don't need to grow the team, you know, this kind of mentality. I actually, you know, really encourage a lot of leaders out there to think about at some point you also didn't need a financial officer. You kind of just counted the cash on a daily basis and what you went home with was what you went home with.
When did that first CFO, like, come into existence as a part of the job? And as you know, other than you were doing it yourself, I think the formality of the cybersecurity career and getting the CISOs being seen as a key member of the executive-level boards and organizations that are out there has been significant. But I still feel that every part of society, whether you're Safeway, you know, grocery stores, financial, all of these different organizations need to realize that if they're compromised, it is going to impact people's lives significantly more now than it even was 20 years ago. So I get excited. What is the problem today is that we continually think that the problem is kind of solved and we just hire about 10 people and we're good.
But the— I think the bottom line is I think the problems are going to continue to grow, and we're going to need to still encourage a lot of smart people entering the field. And I believe that cybersecurity and security in general is going to be more and more important to every organization, including your own personal families, um, from now. And we'll look back at this and say, wow, you know, Frank, you were there at the beginning still. You're part of that initial, like, you know, 10-year group that jumped into that, you know, what was it like? It's going to have that feeling, you know, it's because of how important these technologies are to life sustainment from here forward.
So it's a good career to be in, and I really want to encourage a lot of folks out there who are saying, hey, what should I do when I grow up? Cybersecurity, it's an important job. In many cases, I think it is The most important job, you know, next to like critical life-saving hospital firemen, da da da. It's the next rung down. You know, well, military's up there too.
You know, military, you know, life-saving, and you could go down the hierarchy there. But I cannot see any other job where someone in their civilian life can say, I came home from work today and I saved lives. You could do that at a financial firm. You could do that at a cloud service provider. You could do that at a power company.
I'm not sure any other career that you're just working there in general, you're gonna be able to say I am that significant, you know, to potentially, you know, really disastrous level events. Cybersecurity does that, and it should make people really excited to feel they're a part of it. And burnout's real, but your job's important. And I said this in the presentation, you know, I gave it SnowFROC. I said your job's important, but, you know, your job saves lives.
And it's always good to remember that. And like, you know, if you weren't there, who would be? Right. Okay. Well, I'm going to give you some just open mic time, just some general stuff.
No questions. Is there anything that you would want to address our larger audience here? Any, anything else? Any final thoughts?
I'm excited and very optimistic about AI's capabilities, capacities. And the only reason I say that is for my own personal learning, is that if you look at AI with, you know, as my kids say, sus, if you're looking at it with sus, you know, and you're really not sure about it, you know, I just encourage you to start playing with it. I'm not saying you're going to fall in love with it and it's going to be your next, you know, epiphany, but rejecting a technology has never worked for any generation or any career field. I've yet to see it. Please point it out to me.
You know, someone will say, well, what about, you know, Pennsylvania? We have these people, you know, did very well during COVID Okay, yes, fair point. But at the same time, you know, in general, this new technology is not going anywhere. So the best thing you could do is learn how to adopt it and learn how you could use it. There's downsides to it.
And there's upsides. And for those who are in the cusp one, you definitely need to be the voice of how do we not let this thing do the brain rot, you know? And the other side will say, look at all the cool things I could do with it. That meeting the middle, I don't believe we need to be in the late 2000s figuring out that, hey, the, our entire food processing thing has actually caused the obesity epidemic for the past 50 years. Yeah, we could probably look at science around that and there's some truth to that.
Uh, but, you know, it also— you have to look at the other side too. It's like, hey, you know, we've solved some of these major technological issues. We just need to go into these new technologies with more eyes wide open. And instead of learning that later on, hey, this building material, this thing that we thought was amazing, asbestos, actually is really bad. We need to take a look at this stuff now with, you know, jaded eyes and also with suspect eyes.
Before it gets too far ahead of us. And that's where, you know, I go back to cybersecurity. We need you to look at how it's going to help you and become, you know, the best defender out there, how the attackers are going to be leveraging this to become, again, the best defender out there. And then we also need to look at it societally. Hey, if you're advising people from a security and privacy mindset, where could this technology run amok?
And, you know, be that individual that is able to balance sensationalism in reality and be that steady hand in the middle. And that's where I lean on a lot of folks in our career field. It's like, because we're not out there, you know, most of us are non-sensationalized, you know, we don't get very emotional. We're the ones who are turned to. It's like, what do you think, Frank?
And when someone asks you that question, you're like, glad you asked. And here's my— you're always going to give a balanced perspective. I don't even need to know. You know, there's very few people in our community go like one way or another. You're just like, well, I work in a cybersecurity thing.
Here's my view on this. And that's one of the great things about our community in general is that, you know, we always approach things in a very balanced way. Awesome. Well, Rob, thank you so much for your time. I know you're always incredibly busy.
We'll put a link to Rob's LinkedIn profile up into the podcast notes. Of course, if you want, I think the SANS community, you can always visit sans.org. I'm sure Kate would love that. See about some of these local events that are out there, see and be part of the community. We do have a couple of community events coming in.
My OWASP meeting, we're going to have one on July 16th. We're going to be back at Dave Buster's, and it'll be a great talk. We're shifting it a little bit. Vince and I are working with them. We also have a Colorado Equal Security picnic coming up on August 23rd, and this one's going to be a little bit different than the rest of them because we're going to bring in about 10 different nonprofit organizations— ISACA, CSA— to help us with this picnic.
But it's not going to be a learning opportunity in the sense of a presentation. It's going to be, hey, come and have fun, learn how to play some games, some volleyball, And really just have some fun discussions. So that'll be coming again up on August 23rd. Please check out the Colorado Dash Security website for all these events. So again, thank you for your time, Rob.
I really do appreciate it. My name is Frank. I am the VP of the Denver OWASP chapter, and I hope to see you in future events. No, I love it. Thank you for having me.
Thank you, Rob.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Rob by emailing info@colorado-security.com.
Until next time, remember, Colorado equals Security.