Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 278, September 8th-ish when this gets released. Alex, it's kind of cold outside.
It is a little chilly, Robb. I don't know what's going on. It's almost like it's getting to be fall. Fall has fallen. I think I've said this on the show, you know, how many years is this now?
7 times.
Entirely possible. We do still have a few weeks until fall, I think. But officially it's getting there. But people will not get to listen to another episode until after fall has started. That's right.
So this is your chance. Last official summer episode. Yeah. Uh, and we're, you know, at episode 278, we're doing the, uh, the slow grind towards 300. Slow grind.
We're only 2 years away. In the past, it would have been like, oh, it'll be here tomorrow. Right. We're a little slower now that we're monthly. Yeah.
Speaking of things that are slower, um, we have housekeeping, which is not the fastest part of the episode. Uh, we would love it if you would join us in our Slack channel. We've got vibrant conversations, so many lovely people. Come into Slack and talk to the 2,000+ local folks. You can join Slack by going to the website colorado-security.com and finding the Slack button.
While you're there, you can sign up for our mailing list so you get show notes into your inbox and things like our salary survey and other news, you know, when we get volunteering opportunities, all those good things. If you want to rate and subscribe to this podcast, we would like that as well. Go to your favorite podcast player, probably whatever you're listening to this in right now. Subscribe, uh, give us a 5-star rating, we'd appreciate that. And then tell a friend, let them know all the great things that are happening at Colorado Equal Security and how they should come join us.
Big thank you to our annual sponsors. This year, for the first time ever, we got a little bit of sponsorship for the show. We, we do appreciate Armis, CrowdStrike, Red Canary, and Zscaler who've been with us this year. Thank you for your ongoing support. Indeed.
All right. Let's jump into the news. You know, Robb, another thing that's kind of a slow grind. Elitch Gardens, it's been talked about, about going away for a long time. But maybe that's not going to happen.
It's a little bit like that first incline at the beginning of Twister 3 when it's slowly grinding up that— no, that Twister 3 is the big wooden roller coaster at Elitch's, slowly going up to the top and you know something big is coming. But you don't know how long it's going to take. Well, the news for Elyches has been just like that. But it looks like, you know, the rumors were it's going to get moved somewhere out of the town. It's going to maybe move to a much smaller footprint where it would be more like virtual roller coasters.
But it looks like because of a recent ownership change and Cronkie Sports and Entertainment went from a partial owner to the full owner of Elyches this, this summer, because of that, they might actually be in their current location for years to come. Yeah, the idea was with, with this new River Mile development that Cronkie is putting in, in the area where Elyches is by Ball Arena, kind of down towards the football stadium, that they were going to get rid of the amusement park and put in housing and other things there. But it seems like they're actually putting money into maintaining and upgrading the amusement park now. So I have been a season pass holder for Eilish's several years. I think we went about 5 or 6 years with the kids in that perfect like middle school to mid-high school range.
Really loved it. It's a great deal, I think, for like the price of going a couple times, you can go all summer for free. Really enjoyed it. I didn't enjoy that they weren't ever doing upgrades. So this article talks about the fact that they have now updated.
It was Twister 2, now it's Twister 3. Big upgrade there, big upgrade to Sidewinder, some other stuff coming, and hopefully the park will be better and better every year. Yeah, I mean, and if you're gonna live down there at the new River Mile, you want to be able to just walk to an amusement park, right? So you gotta keep it around. All right, jumping over to our next story.
This is actually pretty big news nationally. President Trump has moved the— what is the headquarters for the Space Command out out of Colorado. I don't know if it's official as of now, but he's made the announcement, right, to move that from Colorado to Alabama. That was a thing that I think he was planning to do his first term, and, and Biden put it— brought it back to Colorado, and now it's going back to Alabama. Yep.
And, you know, Alabama and Colorado were the 2 places that were in the running originally to get the Space Force command. You know, Trump has had a long-running dislike, or I don't know what the right word— disagreement with Colorado. And this article lays out some of those things that, you know, he was not particularly happy with or things that kind of went against him from Colorado. So, so yeah, because of that, and the specific reason he gave is that Colorado does mail-in voting, which he is not a fan of, and because of that, wanted the Space Force somewhere else. Well, that is sad news for our local community.
Good news for the Alabama folks who I do not I believe do not have an Alabama Equals Security program. So, you know why? Why is that? Because Alabama does not equal security. It does not equal security.
All right. Moving on to our next story. We really interesting one. I did a lot of learning as I read this. Xcel Energy has announced recently that they need to invest $22 billion to keep up with the increased energy demand that's going to be coming to Colorado from new data centers.
Over the next 15 years. Yeah, I think the key here though is the potential new demand. You know, Xcel, they currently have, sorry, it's got a pop-up, 6.2 gigawatts of generating capacity in Colorado, but they're expecting a possible 5.8 gigawatts of additional needed capacity from applications that have come in for different data centers. So it actually was even, so that's the, they currently have applications for that 5.8, but there's another like 12 more that they're saying they have applications for right now. But the really risky part here is these are, these are proposed projects, right?
These, these data centers that may be stood up and may have made the capacity, may be used to this level. But if Xcel goes and invests and does all this, and then those things don't come, come true, that the cost of that is actually spread out to you and me. All of the, all of the energy buyers in Colorado will bear that burden if it doesn't have— if it doesn't get used. Yeah. The— since Xcel is a public utility, and they operate in that way, you know, for them to do anything, they have to apply rate cases to the Public Utilities Commission and say, hey, we want to spend this money.
And we're going to pass that along to the consumers in the form of, you know, rate increases and things like that. So, so yeah, so any money that they spend is going to come out of our pockets. But they— well, maybe, right? There's a couple of mitigations that they're talking about putting in place. One of those is, number one, you know, going a little bit more slowly instead of trying to build all this out.
But there are these things called large load tariffs that someone who's planning to build a data center, they would just pay an upfront cost, right? You're gonna, you're gonna, you want this, you're gonna be on the hook for that cost instead of the, the consumers. So there's, that's an option that's certainly not confirmed at this point, but that's something that we're working through. And Xcel, they, they need to move quickly if they're, if Colorado is going to be a data center heaven. Haven.
Haven. Yes. There is also talk in the article about, you know, what sort of data centers do come to Colorado and what the likelihood of these applications actually resulting in real data centers here. And, you know, one of the things they talk about is that, you know, Colorado has a lot of, you know, sort of colocation data centers, but not a lot of hyperscaler data centers, you know, like Amazon or Google or, or those sorts of places. There is one, however, that is being built right now.
And when it's completed, it will be the largest single customer of Excel at 177 megawatts. Well, do we know what company that is? It is— it's being built by OTS Realty Trust. It is a hyperscale data center, but it doesn't say— doesn't say which one at this point. Someone's building it.
They may be building it for somebody. It doesn't say that. Well, very interesting. Yes. We have other technology news from, from our fine state.
EchoStar recently gave up a lot of their wireless spectrum and really kind of gave up their intentions of being the 4th major cell phone carrier in the US. Basically, they sold that spectrum for cash for a couple of different reasons. Yeah. One of the reasons is that they don't have any money and they've got a lot of assets and a lot of debt. They got a lot of debt.
They got a lot of assets that are worth things or had a lot of assets, which is this wireless spectrum. And, you know, they continue to bleed TV customers from the satellite services. So really, they didn't have a whole lot of choice. Well, that was, that was one of the reasons was that, that financial, but then there was also the government, right? The government was coming and saying, hey, you have this spectrum, you are required to use the spectrum that you have, you have to build out more.
And you know, EchoStar's perspective was that they actually were meeting all of their build-out requirements, but the government was still coming at them saying, we want to see more usage here. And to kind of settle that investigation from the government, to settle some of their debt, they sold about $30 billion— was it $30 billion? $20-something billion? I think $23 billion. $23 billion of spectrum to AT&T.
And with this change, they also have signed up to to ride on AT&T's network for much of their, much of the Boost Mobile, um, cell phone access. So they're, they're now gonna be kind of this hybrid carrier. You know, they have some of their own infrastructure and they're also using some of the other, uh, of AT&T specifically. Um, you know, my understanding is this, this will still allow them to make a big play in the cell phone space, but maybe at a different perspective, right? Yeah.
They'll, they'll have to ride on AT&T's network for the most part. You know, maybe they can slowly build out their own network, get more spectrum in the future, and become a bigger, you know, independent carrier at some point. Kind of interestingly, this article mentions that the spectrum they sold is only about a third of the spectrum that they own, which is just mind-boggling, right? You're talking, you know, whatever that is, $70, $80 billion of spectrum that they own. The article mentions that some of the other spectrum they have would be really useful for someone like SpaceX who's looking for it.
You know, different spectrum, different usage. Um, so there might be another $30 billion that they could sell to them. Um, you know, putting them in an even more favorable financial situation. Yeah. Oh, we didn't even mention that.
What was the impact of this for their stock? Their stocks shot up to like 7-year highs. I think it was their highest since 2018 or 2019, 75% increase in stock based on, on this, uh, de-risked their debt. If you had a bond from Dish, it was, it was considered a pretty risky bond before this. Now it's not.
Now it's not. So good for those guys. I think good for people who have a lot of dish stock. All right. Moving on to our next story.
This story is— it's another tech story about Colorado's highest valued public company, which is Palantir. I don't think that I would have even guessed the right company if you said before reading this article, if you said, who is Colorado's highest valued public company? I don't think I would have said Palantir. You could have given me 10 guesses. I probably would have not gotten to Palantir.
Yeah, I might not have thought of it. But not only were we way wrong, but we were way, way wrong because according to this article, there are 58 public companies in Colorado and Palantir is worth more than the other 57 companies combined with their $457 billion or something like that. They are exceptionally valuable as a company. Yeah. In fact, there's a quote in here that says, from an Economist story that ran last week, that said Palantir might be the most overvalued firm of all time.
Yeah, I mean, it looks like they just are going to pass $1 billion in revenue and the number actually is $437 billion in market cap. So they're worth 437 times their annual revenue. That's a big multiple. That's a big multiple. Yeah.
Yeah. I mean, but there's— it makes a lot of sense. We actually have a second story we're going to talk about Palantir later. But they have really had a lot of momentum from the government. The US government has invested a lot of money into Palantir.
Yeah. And, you know, part of this article talks about the controversy that Palantir has and, and other things like that. You know, there have been a lot of protests of Palantir basically from them potentially using big data with the government to do what people consider to be bad things, uh, you know, working, uh, for, for ICE and for some other parts of the government that people are not favorable of. And, uh, so, so this is a company that has controversy too. Yeah, when they, when they first moved to Colorado, it was at least partially because living in the, in Silicon Valley as Palantir was becoming uncomfortable, right?
They were, they had a lot of protests on a regular basis. They had employees who were protesting what they were doing. Colorado is a little bit closer to middle of the road and not quite as activist as the Bay Area. Although, you know, the article we picked for this starts with a picture of a protest outside of their Denver office. So, you know, they haven't completely escaped that.
They do also mention that Palantir has grown in employees as well. They're almost double from what they were in 2020 when they were at 2,400. Now they're almost 4,200. Well, I am glad that Palantir has had some success in Colorado, and I am shocked that they are so much bigger than the rest of our public companies. Yeah.
All right. Next story is a follow-up from one we've talked about a month or two ago around the DaVita incident. This is a story that really dives into what actually happened for DaVita to get breached. And I don't think— I think it's a what could have happened, right? Based on what the— from an outsider's perspective, looking at the DaVita environment, what they know of the incident.
Here's a breakdown of what this might have been. Yeah. And this is— we debated including this story or another one of the recent DaVita stories. Because, you know, they— DaVita did recently disclose the number of people that were affected as part of this breach. Over 1 million.
Yes. And, and we decided to go on this article because it is— it's more in-depth. It's a pretty good investigative piece. They look at open source intelligence and some other things like that. Find potential weaknesses that, that could have been exploited as part of the, the issue here.
Again, this is not an insider that's talking about this. This is external review. But I think it is useful to look at. And, you know, based on what they found, I think that, that there are some things that might have been lacking. Well, and it's good for all of us to look at, at failures anywhere to learn to get better ourselves.
Right. And what happened here? What could have happened here? How can we avoid it ourselves in our own programs? So you know, if you run a program or you're interested in running a program in the future, this might be a good place to learn.
Yeah. Or just curious. All right. Next, we have a second article from Westward. That one about Space Command moving was Westward.
But this is an article about some recent news. Colorado has added AI-generated deepfakes to our revenge porn and child exploitation laws. Yeah. So in the past, if someone would have made a deepfake that would have affected someone that could have been considered child pornography or something like that, a deepfake was not considered as part of the law. Now they have added that so that because of some cases, there was some teens in Aurora that they were extorted because there was deepfakes that were posted to them.
Some of them were legitimate pictures, some of them were altered. And so, so now the law is catching up so that those folks can be prosecuted. Yeah, this, this got really famous, was it a year and a half, 2 years ago when there was a bunch of AI-generated Taylor Swift pictures on the internet and that caught the public's attention. The laws have been trying to catch up ever since then. The nuance of this is, it's interesting.
I think that it maybe doesn't go as far as some folks would like. Like specifically on the child exploitation side, the deepfake has to be recognizable as an actual person, right? If you use deepfake to make a general child, that, that wouldn't qualify. And you can see how not everyone's going to like that, right? That's maybe not protecting in quite that right way.
But, but there's, you know, it's hard, you know, you want to get something, make some progress. And there is progress being made here as a part of this. The revenge porn one is, is kind of similar in that, you know, if you're, if you're using AI to create these images, and then either make blackmail or, you know, or posting things without consent, that's, that's really when folks are going to run afoul with this law. Yeah. And speaking of AI, our next article is talking about what happened in the special session recently, with the Colorado legislature, which was a delay in the implementation date of the Colorado AI Act.
Yeah, Governor Polis called a special session, I think mostly to deal with a budget shortfall. But during that special session, they also addressed this AI Act, which they'd been trying to amend last session and the actual session, and they failed to do. And they said, well, let's just— could we just delay the implementation of it? So would they have another legislative session to work on it. It was supposed to go into effect beginning of February, and now it's pushed out to June.
Is that right? Yeah. Yeah. So they, so after this next session, they'll, it'll go into effect. So there will be a chance for industry to get back together.
And, you know, the tech industry is pushing pretty hard that this is a, it's going to impede the ability for Colorado companies to embrace AI. You know, I think you and I talked about it a couple months ago when this was being debated last time. I'm, I'm like squarely in the middle on this where I think we do need good regulation. We, we don't want people making decisions that impact others' livelihood. You know, are you accepted for a job or a loan?
AI made a decision and we don't know how, and, and we're not gonna tell you it was. That's, that's what this law is meant to address. But at the same time, we can't get in the way of innovation. Otherwise, we're gonna get left behind. Right?
So somehow we need to get both. Yeah. Yeah. And there hasn't been a good compromise yet, which is why, again, we're kicking it down the road. So hopefully they can come to a compromise soon.
Alright. Well, let's jump over to our second I guess this is our 3rd Westward story and our 2nd Palantir story. This one, uh, the headline, uh, When the Government Can See Everything: How Palantir Is Mapping the Nation's Data. If you're going to read like one story from the podcast this week, I personally think this is it. Really interesting details about how Palantir is pulling together different systems and how they're selling that information to government and private sector as well, for people to be able to, to know a lot of things.
Yeah, I think for better or for worse, you know, historically, the, all of the different data that was stored within the US government was pretty siloed. And from one perspective, that, that could be a good thing. You don't want overreach. But from the other perspective, it's hard to use that data to come up with analytics and making things better if you can't you know, map it all together. So they— so Palantir has 2 big platforms.
One's called Foundry. The other is Gotham. Foundry is for private sector companies with global operations, and Gotham is for public sector. It's for police departments and federal agencies and so forth. And I just gotta tell you, when I hear Gotham, I just think of that from The Dark Knight when Bruce Wayne turns every cell phone in the city into a microphone so they can go catch the Joker or whoever it is they're trying— is it the Joker?
Whatever, whoever is it, Bain. I don't remember who he's after at the time. I don't remember either. But, but that's what I think of. And, and it, it is scary.
And, and you, you want to make sure there's good oversight. And I, I don't know if there is or not, but this article goes into a lot of details about how Palantir thinks about this, how governments are using it, and what the use cases might be. Really interesting content. Very, very interesting. And, uh, that is why people think Palantir is worth $400 billion.
All right, uh, last article of the month. Uh, there's been an announcement for change in leadership at Swimlane. Uh, Cody Cornell, one of the founders and original CEO of Swimlane, is now back in the seat as CEO. Super excited. Cody was one of our very first, uh, guests on the podcast.
He, he was a CEO, he moved over being CTO for a while, and, and now he's back as CEO. Cody is a, a visionary and, and really driving the technology element of the company. And as Swimlane has, you know, they've been doing SOAR for quite a while, as long as we've been doing the podcast, and have really embraced AI as the fundamental part of what they do to help companies automate their security operations. I'm excited to see Cody lean into that. You know, as a part of this announcement, they also raised $45 million in additional funding.
So another round for them to continue growth and keep doing the great stuff they're doing. Yeah, they also announced as part of this that, uh, they have hired a new CFO, a new COO, um, and, uh, a new executive chairman of the board. I think they got several folks from Ativo Networks, if I remember right. Yes. Uh, well, they— SentinelOne for a bit, but they came through the Ativo acquisition.
Right, right, right. Well, congratulations, Cody. We're happy for you. Um, congratulations to Swimlane for, for all the success. Awesome.
And that is— that's it for news. Yeah, we, we do have a calendar of events, and a lot, you know, it's fall, people are— kids are back in school, so the, the events are starting up in, in earnest. So we have quite a few things coming. If you want to see the entire calendar of events, go to colorado-security.com and go out to the event calendar. You'll see it all through the rest of the year.
All right, uh, first on September 10th, Denver CSA is doing a study group. Uh, this is the second session, it's virtual, for the CC CCZT certification. That's easy for you to say. I'm assuming that is Cloud Computing Zero Trust certification. I will not comment 'cause I don't know.
Also on the 10th, ISC², or sorry, ISSA Denver has their September chapter meeting. On the 16th, Denver CSA is doing Beyond Patching: Prioritizing Cloud Workload Risk with Exposure Management. The next day on the 17th, Denver OWASP has their meeting. Why You Should Hack Your Own APIs. Oh, on the 18th, ISACA Denver is doing a full-day September chapter meeting.
It is a full day long. Yeah, no joke. Um, what do we got the 25th? Deciphering Human Behavior to Get Security Done. This is a full-day training by our friend Angie Stevens, who's, uh, who's getting together with a smallish group of maybe a dozen folks to to focus on how to make you more effective at your job.
This is a paid training. If anyone wants to get plugged in, we'd love to see you there. Yeah, there is detail on our event calendar and we did skip one on the 24th. ISSA Pikes Peak is doing their chapter meeting. My bad.
That's all right. Let's jump one into October. On the 4th of October, ISACA Denver has their ISACA Community Day. Community Day. I can't say it.
Community Day. I got it. That's a volunteering get-together community community day, and they'd love to see you there. Awesome. Uh, well, that is it for the events, Robb.
I believe we have an interview this month. We do. Jason Hayes, uh, who, who sat down with our, with our good friend Frank Victory. Um, Jason has recently taken over— it's a, uh, whole CSA, right? Cloud Security Alliance.
Um, and, uh, comes talk about the Cloud Security Alliance, what he's done in his career. We get to know him, and he's a great member of the community. Frank said it was a very deep conversation, so I'm excited to hear it. Good stuff. All right.
Well, that is it. We will see you all in October. Thanks, Robb. Hi, this is Kimberly Hahn at NGC. Welcome to Colorado Equal Security for Colorado security professionals by Colorado security professionals.
Well, good morning, good afternoon, and good evening, Colorado Equal Security. My name is Frank. I am a guest host on this totally awesome podcast, and my guest today is Jason Hayes. He is the president of the Cloud Security Alliance, and I think their old logo, at least I think their old logo was, you know, a drinking club with a cloud solution, but I've heard that kind of changed after a while. How are you doing today, Jason?
I'm doing well. Thanks, Frank. It's Friday, so I have no complaints. Awesome. Well, you know, buckle up again.
Um, today we're gonna go through some interesting stuff. We're gonna forget the textbook jargon. We're gonna dive deep with someone who's lived and breathed this world inside and out. All right. Um, we're going to go from electrical engineering at Georgia Tech.
Yeah, he's a Yellow Jacket. To assembling servers in the Wild West of the late '90s tech boom. Our guest today has taken the road less traveled, thinking crashed dot-coms, bleeding-edge data centers glowing with F5 logos, and a baptism by fire into the world of enterprise security. Now he's an executive senior advisor. He's been an engineer, architect, consultant, CIO, CISO, and even a practice co-founder.
He's pretty much seen it all— bare metal servers, music, or sorry, Fortune 500 boardrooms. So we're gonna get ready for some real-world insights, battle-tested strategies, and maybe a few war stories from the career that's been anything out of the ordinary. So welcome, Jason. How are you today? I'm doing well.
It's been a busy time in cybersecurity. We got a lot of fun market factors at play and some regulatory stuff going on these days that we're trying to get out in front of. But Yeah, it's always fun in cybersecurity. I tell people that if you are a lifetime learner and you are passionate about this space, there's really almost no place better to be because the opportunities to learn here are pretty much unsurpassed, I think, by every other industry. But so much so that I would describe them as not opportunities to learn, the necessity to learn.
So it's always fun in cybersecurity. I always love learning, whether it's regulatory or down in the weeds or somewhere in between. But yeah, it's a great, great industry and a great time to be here. Well, I always like to start off with an icebreaker question. Jason has not heard this one yet because, you know, that's of course part of the surprise.
So my question for you is, if you can take any famous person to a team meeting, you know, alive or dead, who would you be? Who would it be and why? Wow, that's an interesting question. Any person to a team meeting? Well, I think if, you know, assuming I get to pick the team here, if it's my— if it's the teams that I work with closely at WWT, I think I would probably go with somebody like a Jocko, somebody who has lived a really interesting life, literally in the trenches.
And has done something that is just completely unrelated in, in at the surface level anyway, to what we do on a daily basis and is able to take, you know, situations seemingly at ease that, that were very stressful situations in combat zones and things like that and, and really convert it into lessons that we can apply in our, in our everyday lives that are hopefully for most of us outside of the combat, combat zone areas. But Yeah, just somebody like that. And I think Jocko's, uh, Jocko's a real good, uh, good, good example of that because, um, you know, for folks that haven't, you know, listened to his podcast or read his books, he will, you know, take you from war zones and really bad, uh, situations, um, and kind of, you know, tell a story that is very Jason Bourne-ish, um, and then back away from that and really abstract things in a way that that brings concepts that might have been heated with lead flying in the air down to ground level that we can, that we can apply to strategy and the way that we do things on a daily basis to, to be more effective. Do you think that kind of combat is helpful with— I mean, we don't do anything physical, at least not in our world. I mean, not, not much.
Do you think that is a good skill? Is that a transferable skill? I think so. I mean, you know, for me at least anyway, in cybersecurity, things are starting to bleed over into physical security as well. But, you know, even stepping aside from that concept, I think we do live in a war zone in cybersecurity.
I think it'd be hard to find somebody in cybersecurity, especially if we're talking somebody on the front lines of like a security operations center, that would argue with the fact that we are very much in a battle zone. Um, you know, we have these, uh, these typhoon attacks now we're dealing with, or even nation-state-backed. But even if you're not dealing with that sort of thing in the industry that you're in, um, you are constantly under attack, right? And those situations are stressful. Uh, there can be very long hours involved.
Uh, there's the need to, uh, you know, prepare before you hit the proverbial battlefield, and there's the need to stay dynamic and, uh, and adjust while you are are in the combat zone, right? So I do think that there are analogies there that apply to our profession. So if you have to remain dynamic, though, can we still rely on playbooks? Can we still rely on our standard, okay, well, we're going to block this IP address? Does that still work?
Or we're going to recognize phishing emails by spelling mistakes?
Well, I think anytime that you're entering into any situation, whether it's a a battle zone or constructing a new piece of furniture in your living room, you got to make sure that you got the right tools there. We are seeing a rapid advancement in our space, as everyone has seen, in tooling that the attackers are using against us, but also in the tooling that is being provided to us to be more defensive and proactive in recognizing those attacks coming in and responding to them. I think the old-school notion of playbooks, like the way that we thought about it as recently as like 3 to 4 years ago, where those playbooks were very static, is something that we've evolved a little bit past, at least in terms of the solutions available in the market. You know, there's a whole lot of, you know, folks in the security space that are in the selling business that are weaving the terminology AI into everything and the term AI has sort of now become a term like the cloud of what does that even mean anymore, right? And a lot of that is driven by these sort of architectural AI things that are not really manifesting real outcomes.
But in the security space, you know, the ability for us to have data centralized from numerous sources and have that data be normalized and even shrunk so that we're not paying massive ingestion fees in our SIEM solutions and other things. And then once all this data is in one place, place, be able to run highly complex analytics around it. You know, we can call that AI, we can call it whatever we want. The bottom line is that our ability to do data science and data analytics based on all this data coming into one source is vastly improved from where it was just a few years ago. But even in the tooling that we're using, you know, a lot of the tooling, for example, in the EDR space, that endpoint detection and response space, are now starting to bleed into things that traditionally would have been thought of as SIEM or SOAR functionality.
And, um, you know, when you get in front of these new solutions, I, uh, look, I, uh, I am far removed from, uh, being hands-on keyboard in a SOC. Um, I was in a SOC back in the '90s before we were calling them SOCs. They were just network operation centers that were doing the security thing. Um, you know, things have changed just so dramatically. I got hands-on keyboard in a capture the flag a few weeks ago event that was being put on by one of the major EDR vendors, and I came in 3rd place.
I had a broken hand at the time, and it was a timed event. I think I could have probably done better than 3rd place had I not had a broken hand at the time. But what I really walked away from that from was not thinking, holy cow, I'm amazing. It was, holy cow, what they've done with the AI in this solution can turn somebody like me that has not been hands on keyboard in a SOC in a long time into an effective security practitioner on the frontline. And so I do think things are happening now that are really evolving our ability to respond to these more modern threats and even these just really more modernized threat actor groups.
I mean, these Typhoon groups are wreaking havoc and they are state-sponsored and they are well-equipped. So it's really good to see that our tooling is up-leveled. Well, actually, let's take a step back here because I want to take a step back. We kind of covered a lot in there. Yeah.
But, you know, you and I have had kind of some similar career paths. We've been in this for at least 20 years, probably approaching 30 years. Right. And you probably remember at one point when virtual machines came out and everybody was resistant to them and now everyone wants them or now it's almost mandatory. And then the cloud came out and everyone was resistant to the cloud.
And you only put 10% of your infrastructure into the cloud because we can't trust the cloud. Now we have full infrastructures in the cloud. And now the new thing is AI. And there are some companies that are resilient to wanting to adapt AI. What are some thoughts on that?
You know, we are, we're seeing a lot of different types of AI adoption. I think to some degree, AI came, kind of came along as a solution looking for a problem. Its ability to solve really interesting problems in a really wide range of interesting problems is, it has been just interesting to watch how things have unfolded. Um, but, you know, we're also seeing some mistakes made there. I mean, you know, just this week Salesforce made, uh, front page news for, you know, launching an agentic AI.
Uh, it actually been launched for a while, but a security flaw in an agentic AI they had launched that exposed, um, confidential information from a number of really big companies. Um, some of the companies that, that I'm partnered with, in fact. So I, I suspect that, that my information was tied up in that. We've got to have a real careful and thoughtful approach to how we're deploying AI. Again, with AI kind of going around and looking for a problem to solve, they have been really focusing on low-hanging fruit, right?
And to make no mistake, there was low-hanging fruit that needed help. If you look at like what's going on in the radiological industry, for example, so I'm stepping away from cybersecurity for a second. What's happening in the radiological industry is a great example of where AI can absolutely thrive. You have an analytical process that needs a lot of different datasets to draw upon, to read imaging and apply it to the situation at hand. But it's, it's a fairly well-known body of knowledge, right?
And so if you think about traditionally what would happen is you would go to the doctor, you would get an MRI order, you would go to the MRI place, that order would go back to an image, an image analysis person who would read that image using the doctor's orders to look at that image. It's not that it wasn't highly accurate when a human read it, it's that it was slow. And furthermore, there was bias involved in it because the, the person reading that image had an order from the doctor saying, I need you to check out this part of the brain or this part of the body or whatever to look for this situation. And it's not to say that they ever confined themselves to that. But if you look at the outcomes coming out of something like RAD AI, it is almost 100% accurate.
The humans were almost there, but it's almost instantaneous. And what's really interesting is just all the examples where, uh, RAD AI has found something that had nothing to do with what the order was coming in on. Like there was a brain image and maybe RAD AI sees, uh, symptoms of early-stage Parkinson's. We are really improving medical outcomes with that type of technology. However, it's also killed off an industry because if you talk to anybody who is a surgical radiologist, like an interventional radiologist, those guys that do really cool things like cut you open on the inside without cutting you open on the outside of your body.
They will tell you that nobody's even going into the radiological analysis industry anymore. You still have radiological techs and you still have the doctors, but in between that space, the industry is being gutted because there's no need for it anymore because of rad AI. Similarly, when AI started looking at security problems, they went after the SOC because we've got major pain points there. There's cost pressure to reduce the pay for the people working in a SOC. There is also a heavy burden for the people that get those jobs in terms of the number of hours that they're working and the amount of stress that they have.
And they're also dealing with datasets coming in from a wide variety of sources that a human cannot possibly keep up with and process in the right amount of time. And so they went after that problem and they solved that problem as well. Now, we're not perfect yet, but we're evolving. Where I think things are really getting interesting in this industry um, of AI being the industry, not necessarily cybersecurity, is just watching them as they kind of go after the next problem they're going to solve. Um, you know, I do think that as AI continues to look for problems to solve and they continue to go after low-hanging fruit, I think we probably will see a little bit of a deceler— deceleration of the amount of money going into AI to solve cybersecurity problems related to AI going into things like, hey, couldn't we, couldn't we actually, uh, displace most of the accounting profession with AI?
Well, the answer is yes. And in fact, the technology has been ready to do that for a while. We just haven't done it. So I do think we are going to see some shifts in investment as AI continues to go look at some of these other pieces of low-hanging fruit that they need to go after. But here's the thing about it, is, and, and can AI solve this problem?
Is that we are going to displace, you know, several, you know, let's say half a million accounts, and we're gonna, uh, lay off, you know, several thousand radiology tests. That causes a problem in our economy because we've now got a lot of people with skill sets, or skill sets that can no longer apply. What are they going to do now? Can AI solve that problem? Well, you know, and what's unique about this problem is it's certainly not the first time in history that a technology of some sort has come along and displaced a lot of workers.
Right. However, historically, most of the time that that's happened, it's been blue collar. AI is going to displace, it already has, and it's going to continue to displace a tremendous amount of white collar jobs, which is different, and it's going to have different impacts.
What I will say about that, though, is, is, is most of that is way, way above my pay grade, right? How to, how to solve the, the larger sort of human impact and societal problem there. We obviously have some, some folks in the, in the political realms that are working on that problem, although that's— it'll be interesting to see if they solve that the right way. They probably won't. Um, there was something that, um, Elon Musk said a few months ago.
I think it was almost a year ago. And, um, now he, uh, he says, um, so many things that I think are so politically charged that when he did say this, which was a really smart thing, that nobody picked up on it. Might not have met the narrative at the time or whatever, but he basically— and I'm not quoting, I'm paraphrasing here— he said that he believes that this debate that we've been having is society around universal basic income is going to come to an end real quick because AI is going to displace so many jobs that this is not even going to be debatable anymore. And I think he may be right. The question is, when does it happen?
Yeah, well, okay, so kind of based on a lot of that here, right, um, we've talked a little bit about these jobs and things like that. I don't know if we really talked about you know, the people that are being laid off, the, you know, half a million people or whatever that are being laid off. But maybe let's shift a little bit and let's talk about the people trying to get into this industry, right? When you and I got into this, what, back in the '90s, there was a lot of opportunity, right? I mean, we were young, we had skill sets, and there weren't enough people to do the job.
So we can almost pick and choose. And there were so many things that needed to be done that we can say, Well, you know what, I don't want to do that job here. I'm going to do this one. And they would pay you anyways because nobody else could do it. They didn't even know what their requirements are.
Now, you know what, 30 years later, their industry is essentially saturated with some people that, oh, I want to be cybersecurity because it's cool, some because, well, it pays so well. What advice would you give to somebody that is either an accountant that got laid off and wants to get into cybersecurity, or the 18-year-old that's getting out of high school right now and said cybersecurity is so cool, and those might be 2 different answers. Yeah, yeah. I mean, my, my general advice, um, especially for early career folks, is, um, is not to get too hung up on this idea that you've got to have this 5 or 10-year plan for your career. Um, actually have a really big distaste for that interview question because, look, I'm a fully grown adult.
I still don't know what I want to do in 10 years. I got some ideas, right? But in my career, I never really tried to, um, to sort of, you know, visualize this path that I needed to be on. Um, really what I focused on was seizing the opportunities that were in front of me. And in the wake of multiple opportunities, I was always deferring to the opportunity that going to allow me a combination of things.
I looked for this combination of the skills that are needed in this I have, and I'm going to be able to come in and add value. However, there's an element of this that offers me a growth opportunity, and holistically all of this aligns with what I'm passionate about. And I just went— I just followed that path. Um, but we talk about early-stage career folks now Look, I'm very direct on this. I don't feel like the people entering the workforce today had the volume of opportunities that we did in the late '90s and even early 2000s.
And that is certainly not to say that we didn't work hard. When the opportunities were presented, you seize the opportunity, carpe diem, as they say. And I just butchered that with a Southern accent, so I apologize. Yeah. So, we just had more opportunity at the time and there was a lot of stuff going on.
I mean, look, I was at Exodus Communications, which at the time was the world's largest data center company in the late '90s. And not everything we did back then was smart, right? I mean, I remember sitting in quarterly meetings for Exodus and we'd be like, oh, we lost $100 million this quarter, and the stock would just go through the roof, right? Because There were so many misunderstandings in the late '90s. Like, the investment community really believed that it didn't— the financials actually didn't matter at the data center company, that if you were the biggest, you were going to be the last company standing, and that everything was going to work out.
And then sometime in like 1999, somebody went, wait a minute, hmm, isn't it actually cheaper at any given time to come along and build the same data center that you already built? And the answer was yes. Now, it's not necessarily true today because now we have AI data centers and that's a whole different thing, but we're talking the late '90s, that was absolutely the case, right? And then the whole market just imploded. Exodus was an amazing place to be at the time, you know, speaking of opportunities.
We were, um, we were doing things in the, in the mid to late '90s that were, you know, things that were pushing the envelope. We were load balancing investment e-commerce sites from coast to coast in the US and even internationally. We would walk onto these data center floors and before the— you know, it was a 300,000 square foot data center in Atlanta that I worked in at the time. We would walk on these data center floors and if you were the first person on there, all the lights were off when you walked on the floor and all you would see around the entire data center was these beautiful red glowing F5 balls just kind of all over the place mixed in with Check Point and Cisco logos. We were, we were doing really cutting-edge stuff and that model just, just tanked.
I mean, we still obviously have colos and data center companies, but the idea that the financials didn't matter just evaporated. But they were different times. There was a lot more opportunity there. And I really do empathize with folks entering the workforce now. The opportunities are there, but you got to be ready for those opportunities when they're there in a specific way and realize what those opportunities are likely to be to align around them.
And that's a large part of the reason that I'm involved with the CSA is just feeling like, look, I've been blessed. And it's certainly, again, not to say that I haven't worked my tail off my entire career, career, but just being blessed by the volume of opportunities that we had when the, when the time came along. And my involvement with the CSA, a large part of that is just wanting to give something back, especially in the wake of just kind of looking around and seeing how the job market has been for the last few years and, and what potentially is coming, and just being able to hopefully have a positive impact on early, early-stage, um, career cybersecurity folks. Well, you know, it's interesting that you say that because That's one of the things I focus on. I mean, for anyone that knows me, I've been teaching for, what, 15 years now, something like that.
And one of the biggest things I press is, why haven't you looked at the job market before you even entered the program? Why are you looking for the job market now? Because you should be aligning yourself with the job market and what the industry trends are before you even start taking courses. Because you cannot, you know, when you and I started, we had a skill set and we can say, here's our skill set, you adapt to us, company. That's not the case anymore.
Now this is that this is what we need. Do you have the skill set? No. Next. Do you have the skill set?
No. Next. And, and we keep going on until they find the right person. So, you know, again, you're coming into this industry Outside of looking at these job things, what would you say? I mean, what would you think in that case?
You know, what, what would you say? Or, you know, we can even take it to you are an accountant and your job has now been replaced by AI, like we said earlier. What would you do? What would you say to that person? They came to you, Jason, and said, I need career advice.
Yeah, I think You know, just applying the AI lens to my response specifically, AI is going to displace a lot of jobs, right? I mean, somebody said a while ago, there was a famous quote like 3 or 4 years ago where somebody had said, AI is not going to take your job. Somebody using AI is going to take your job. Well, I mean, there's some truth to that. There's some stuff about that that we know for sure now is absolutely not true.
AI is taking jobs. In some cases. But when I talk to folks that are like in, you know, still computer science students, for example, at University of Colorado or somewhere else, one of the questions I get from them is, is my job safe? I wanna be in application development, right? That's a very common one.
And my answer is this, you're gonna hear a lot of opinions on whether or not AI is actually doing good things in application development. But you need to be real careful about the sources you're talking to because, like, if you were to go out to Reddit and read in any of these cybersecurity forums out there, you're going to hear 80% plus of the people in there telling you that AI is not doing anything in application development. It's a complete waste of time. Well, like, I only work with Fortune 1000s, and there are some of them that are on the bleeding edge of this, and there are some that are not. And I think what's happening in the enterprise, that Fortune 1000 or similar space, is very different than what is happening in the small to medium business space.
And I think there's a big misunderstanding about what we mean when we say AIDD or AI-driven development. This is not going out to OpenAI and asking it to, hey, write a Python snippet of code for me that does XYZ. That's not what AIDD is. I'm not sure what the word for that is. That's like amateur vibe coding, maybe.
Because that's not even really qualified for vibe coding, I don't think. Yeah. But what AIDD is, is a company making major investments in building out their own LLMs that have their historical good code in it and provide business context and provide all this other information that a generative AI system would need to write code. Protecting that with an MCP server and other technologies that allow your LLMs, when they've exceeded the level of their knowledge, to reach out externally and pull in other trusted data sources and trust but verify things that come in. Because again, we're being selective around where we allow it to go.
That's the truth. You trust that source, but you still have to verify everything coming in. But look, I have a customer that I won't name, but they have a stated goal within the next 3 years to lay off as much as 80% of their development force because their AIDD system is in fact working. They track the stats on their code, they always have historically, on the amount of errors in their code. And what they're seeing out of their homegrown AIDD system is about a 60% reduction in errors in code that need to be remediated off of their human counterparts.
Now, let me follow this up by saying, and this is where my advice goes to in the next generation of cybersecurity workers, is AI is not going to take every job. But the difference is, if you really want to be 100% sure that you're going to have a job as an application developer and doing something really interesting, is you've got to be the application developer that also knows the AIDD system. You know how to architect protect it, you know how to maintain it, you know how to be the prompt engineer that's interacting with this thing. And then, and then yes, sure, there are going to be some types of code that these AIDDs are more prone to error on than others. So then that's your opportunity to have the developers on the tail end of that that can remediate that code.
But we're just not going to need as many developers as we did in the past, which means there's going to be more competition. So if you want to differentiate yourself in this space for the way the winds blowing right now, make sure that you're the AIDD architect and the developer. And I think that same thing applies to accounting. Yeah. Well, here's something interesting that I've heard here, right?
Because we kind of started off the conversation with companies that are being resilient to wanting to allow AI into their— into the company. Like, we don't want any AI because we're too afraid of our code getting out there and being exposed, etc. But you've shifted the conversation from using AI to building your own AI. And that is really almost 2 separate things. I mean, you know, of course, you know, I can understand the concern of wanting to throw your proprietary code into ChatGPT.
But you're saying is, well, instead of using ChatGPT, just build your own LLM and you're making it sound easy. Right. It's not easy. No, no. And that's why I'm like, you're making it sound like, well, you know, just go ahead and sign up and here you go.
And we know that's not true. Yeah. And I think that's why I highlight that is where I would shift myself if I was, if I was like, let's say I was in my senior year of college, I'm wrapping up a computer science degree. I really know how to code. That's where I would, would take this just to go, okay, I need to start layering on some some knowledge around how to operate and run an AIDD, right?
Because these things are not easy to manage. They do require a group of people to manage them. Now, I think if you're talking about, like, let's say a Fortune 500 company that maybe had 300 to 1,000 developers around, the future is not going to be 300 to 1,000 developers, but it's not going to be zero developers either. It's going to be something where you've got to have a team of people that are managing that AIDD. And helping it evolve while also simultaneously having less developers.
And I think those jobs are going to become to a large degree one and the same. There will still be people out there that are just developers, and there will be people out there that are just the folks running the AI system. But I think the real value prop is going to be when you can be the union of both. And again, that concept applies to accounting as well, because look, if you're going to replace your corporate accountants with, with AI, you still got to have somebody that knows accounting and therefore probably is a certified managerial accountant that actually is also the AI expert, right? So I would just encourage people to— and, and this transcends this topic— there's a lot of disruption going on in a lot of different industries.
Look at the thing that is disrupting your industry and don't be afraid of it. Figure out how to make your job more valuable by embracing that disruption. Okay, that's kind of interesting. So we've talked a lot about the stress at work and stress of getting into career and the stress of, well, pretty much everything. How do you relieve your stress?
I mean, how do you— is it important to do that, or do we just stay wound up all the time? No, I think it's absolutely critical. I mean, you know, culture, uh, company culture is, is critical, and, and team culture is critical as well. I think the people that make the best cultural contributions to a team are those folks that are not just all about work, right? Having things that are interesting to us in our outside life makes us more interesting to work with.
It also gives us different perspectives, different opinions. It adds to the team's diversity in a different way than we traditionally talk about diversity. But I have a lot of hobbies. And I think all of them to some degree probably not only helped me de-stress, but also give me different perspectives. I mean, you know, kind of, I've got too many hobbies to talk about, but— Let's name one.
Let's name one of them. Probably your most non-technical one. How about that? Well, paragliding. How about that?
Okay. And just for anyone that doesn't know, why don't we describe what it is? Because there'll probably be a few people here that don't know what it is. Yeah, well, think about a parachute, but make it way bigger and upside down U-shaped. Aerodynamically, a lot of the same principles, but a paraglider can catch thermals and you can stay up in the air in a paraglider for hours versus a parachute.
Unless you're parachuting in some really bad conditions, he's not going to go up, right? So yeah, that's, that's a major difference. And by the way, it turns out this sport is equal parts hiking, reading data to prepare for the flight, and then actually flying. So, um, yeah, I think, um, you know, I'm up to about 43 flights now. I started early last year.
It's been a really interesting sport. I was that kid when you were in elementary school and the teacher asked you what you wanted to be. If you could be any animal, what would you want to be? My answer was always a bird. And, uh, this is about as close as I can realistically get being a bird, I think.
But yeah, I mean, I think anything that you do outside of work that is really requiring a lot of focus and you getting your mind off of work, you know, we have the science that tells us that that actually is good for the way that your process— your brain processes information. There's something called the incubation effect that psychologists talk about. That, that, that explores the benefits of really taking your brain off of the problem you're trying to solve. And the human brain is a very complicated thing. It still continues to process that in the back end.
I mean, I think everybody's had that moment where you forget somebody's name and you're driving down the road 4 hours later and you're manually like, oh, that was Frank. And, um, that's, that's, that's the brain. That's what the human brain does. It works on stuff behind the scenes. We're multi-threaded.
So, well, I think that's a bit different for me. I think a lot of people try to forget who I am. After meeting me. But I think you're right. I mean, getting away from the problem a little bit, taking that walk.
I do a lot with, you know, walking my dog and then all of a sudden it's like, oh, that's how I solve the problem. Right. And but this is also one of those jobs where, well, let me, let me actually rephrase this. Is this one of those jobs that is 9 to 5? Yeah, if you're, if you're real lucky.
I can tell you the reason that I'm not a CISO anymore is that that was a job that even though my office was 15 minutes away from my home in rush hour, that my wife was bringing the kids up to the office to see me on the weekends because they hadn't seen me all week. I was with a healthcare payer and that's a rough industry because the margins are really thin and therefore our team was really small, needed to be about 3 times the size that it was. So I did that for a couple of years and decided to get my work-life balance back and went back into consulting. Funny thing about billing by the hour is that your customers don't tend to want you to work an 80-hour work week, right? So, but yeah, it's, I don't know of anybody in cybersecurity that works unless they're like on a contract basis and doing something real Pacific that really works 40 hours a week, nor do they work, you know, 8 or 9 to 5.
We, again, I mean, you know, if you are in a, in a battle zone, you do not get to just say, hey, the, the bell just rang. It is 5 o'clock. We are off shift. Right? It is just not, unfortunately, how it works.
So, there is a lot of burnout in this profession. And I think things like hobbies are absolutely critical to us maintaining our, our just core sanity. Okay, well, okay, so we've, we've got to have a lot of good hobbies, hopefully something non-technical, right? I mean, you know, would you say that to somebody, to get something non-technical? You know, I think it's probably more important to follow your, your passions and your interests than it is to focus on what it is.
And I mean, I, you know, my hobbies are a great illustration of this. I mean, I, you know, I'm into paragliding, fighting, but I also love playing Warhammer. Um, I'm into golf, but I also enjoy video games, right? I mean, so, you know, I, um, if anything, my problem is I have too many hobbies at this point, which I think is the, uh, the other thing you got to be conscious of when you, when you start getting into your passions. But, um, no, I just think in general, if you're disconnecting from the thing that is stressing you out and the thing that you have just been working on and focusing on, and you just feel like you're, you're, you're getting diminishing returns, or maybe even you've hit a wall, Just disconnecting from that is healthy, you know, and, and look, I mean, gosh, if your, if your passion and your hobby is, is getting in front of a computer and doing AI art, well, that's, that's still technical, but, but it is a disconnect, right?
Yeah, yeah, definitely a good disconnect. Well, you know, since we are kind of disconnected here and we are kind of going in a different direction here, again, in your long career, Have you had any weird kind of moments that made you really think back on them now and said, I would have done better? Are there any strange things?
You know, I've had some weird things happen on engagements.
I'm kind of fortunate, I think, that I've never really been involved in a team that has been stuck in a situation where we, like, you know, messed up something for a customer environment. I was on a team one time, and this was gosh, this had to have been around 2002, where, uh, somebody on our team of 20 people did infect a customer network with a virus, um, and caused a bunch of disruption. But, um, you know, the thing is with, um, with our profession, and especially when you're working with partners, um, a very wise person, uh, once told me that Partnerships are not made based on how things are going when things are great. Partnerships are solidified when something goes bump and how the teams come together between 2 organizations, or maybe even more, to resolve that problem. That's where partnerships are really solidified.
So things do go wrong occasionally. You know, looking back over my career, I think that probably the funniest thing that ever happened, looking back on it, it wasn't funny at the time. I was working for an international healthcare provider.
And we had been on the ground for a few weeks. I was pretty junior in my career. And I got on an elevator coming back from lunch with 2 of my other colleagues. And this older gentleman comes— I say older, he is probably about my age now, but at the time he was older— comes into the elevator and he is pretty casually dressed and he is carrying a bag full of of fried chicken that is clearly for a whole bunch of people. And elevator doors close, and he kind of looks over at us.
He goes, hey guys, I'm Kent. What do you guys do here? And we looked at him, we kind of told him what we were doing. We were working on a disaster recovery business continuity program thing. And then we go, what do you do?
And he kind of looked at us for a second before he responded, and he goes, well, I'm the CEO. And we're like, oh my God, we are such idiots right now. Um, but you know, the thing is, and I think this is a good call out on that, I mean, that wasn't the end of the world or anything, right? He actually got a chuckle out of it. He was a really good guy and he was the CEO at this company for like 20 years and was just kind of known for being a real people person and down to earth.
But, um, you know, I learned a lesson in that. It's like, look, if I'm showing up as a management consultant at a place, uh, I better make sure I know who the executives are that work in that building, right? And I think there's something in that for us. I mean, that, that's an example of something where things didn't go horribly bad. But, you know, we're going to make mistakes in our profession.
Well, let me ask you a question on that. Okay. So you suddenly have a time machine and you can now go back to that moment right before you got into the elevator and talk to yourself. Would you give yourself— what advice would you give yourself back then, or would you say anything? Before I ever got in the elevator, I would have told myself to make sure you know who the executives are that work in that building.
You know, find their face shots. I mean, nowadays it's easy. You can stalk people on LinkedIn all day long. But also read their annual report so that if an executive at that company, in the ultimate case, of course, being the CEO, was to ask you, what do you guys do here? The right answer to that question would have been, well, Kent, on your last annual report, your top 5 priorities were this, this, and this.
We're here solving a problem for you guys, or we're here mitigating risk for you guys that could inhibit your ability to hit 3 of those 5, uh, points that are your priorities for the year. That's the right answer, right? But that's just the level of polish I didn't have as a consultant at that point in my career, right? So do your research, know what you've done. Okay, well, since we're talking about a lot of long days, right?
I mean, I think we've talked about mistakes and things like that. Let's go to a different question here. It's like, when you finish a long day What are some key differences when you get out of work and you feel like your batteries are empty versus when you finish the day and you feel your batteries are still charged? Yeah, you know, that's a pretty easy one for me. Um, and I'll confess to you, so today, you know, my job is a blend of sales and delivery and just adding value at the end of the day.
Um, when I was a consultant, I would finish the day almost every day feeling like my batteries were charged. And, you know, kind of self-actualizing and looking back on this, what I've noticed is that there are 3 things that if I do every day, I will end the day with my batteries fully charged. And those 3 things are really, A, I want to add disruptive value to my customers. Right? The second one is that I want to coach and I want to mentor somebody.
And the third is that I learned something new. So, I moved the bar for my customers, I've moved the bar for somebody else, and I've learned something new and moved the bar for myself. You know, disrupted value to the customers, that first point. What was so amazing about, you know, getting trained up in methodologies around, you know, management consulting and things like that is that You know, a lot of times you would go in and talk to customers and everybody's very happy to talk about their pain points. But a lot of times, and methodologies certainly teach you how to do this when you're kind of early stage, and my first exposure to a formal methodology was with IBM Global Services and got to go through their Global Services Institute and all that.
But a lot of times, the problem that a customer comes to you with is not actually the problem, it's a symptom of the problem. And if you solve the problem they want you to go after, well, that symptom may not be there anymore, but the problem is still there and this— and a new symptom is going to manifest. So a lot of what we would do providing disruptive value, and I still get to do this to this day, is just really working with my customers to really understand the problem and define the problem. And in the course of doing that, quite often you find out that that's actually not the problem at all. That's disruptive value to me.
Um, coaching and mentoring, pretty easy to understand. And then finally, that 3rd bullet point around learning something new every day. Well, I mean, the possibilities for that are endless in our profession. Nobody knows everything in cybersecurity. Uh, if somebody says they do, you should definitely not hire them as a consultant.
Um, but, uh, you know, there's, there's an infinite number of things to learn. And even if you did know everything today, you're not going to know it a week from now. So this industry is just— the rate of change is is, is massive. Okay, okay. Well, interesting, interesting.
Well, since we are kind of talking about problems right now, um, you know, our industry maybe today, would you call that controlled chaos? It's absolutely controlled chaos, especially on the side of the industry I'm on. Um, okay, what is that? What, what would you say? I mean, you know, you— the, the 18-year-old that's coming out of high school thinks controlled chaos is playing a video game, but that's not really controlled chaos.
What would you say is controlled chaos in cybersecurity? Well, I can tell you what it looks like for me, right? So, so I'm in the channel, um, and I don't know that that's a very common term for people that are not in this industry, but if you think about the way that this industry works with people making solutions, whether those are products or services, and getting them out to the customers, Usually that doesn't involve going directly from an OEM or an ISV or a service provider to the customer. It actually usually goes through the channel. And so the channel, really the value that they add is that OEMs and ISVs can't really maintain the same level of customer relationship that the channel can.
The channel can stay very close to the customer and be very independent in terms of the recommendations that are made. So, you know, a lot of times that looks like, you know, defining the problem first, defining what good looks like in a way that can actually be measured so that you can define what the outcome needs to be, and then consulting with the customer to say, well, look, there is a section of the marketplace that solves this problem, and these are the major players in it, and here's the pros and cons between these, and situationally, why we see one solution working better for a customer than another solution. Same concept applies to services as well, although that has a lot more variables to it. But being able to really consult with them and then bring in the OEMs and ISVs. But the chaos for us is that what that essentially means, and I mean, we're, you know, I'm with WWT, we're, you know, for example, Palo Alto's biggest North American partner and many of the other vendors, biggest North American partner, that means we gotta know everybody's solution.
And if you think about what that means, I mean, cybersecurity is not one slice. It's a group of a lot of different things. We've got application security, you got network security. We can start dissecting this stuff into identity security, into data security, into all these other areas. It is a lot to keep up with.
And it is a, you know, within each one of those slices, there's multiple vendors that you're trying to keep up with know that are the market leaders. And then you're also working with venture capital to see where their money's going so that you can, you can place bets on who the disruptors are going to be that probably aren't even household names right now, but they will be in 6 months to a year. Um, that's kind of the controlled chaos on our end. I think, you know, that controlled chaos manifests in a lot of different ways, um, at different sections of this industry. Certainly, I think probably The ultimate example is the folks on the front line of security operations centers.
That is absolutely controlled chaos, as any sort of a battle zone would be. You've got the surface you're trying to protect, both from internal and external foes at this point, which is definitely not— that's not stuff we were talking about really in the late '90s. We were all just focused on creating those castles and moats and defending against the outside. You've got sensors deployed that are trying to give you data to let you know when something goes wrong. Depending on what comes in, you're reacting to it.
But I think there's controlled chaos even at the strategic layers as well. I mean, if you look at the job of an average CISO, they're trying to keep the board happy, they're trying to work with their peers to get alignment on what needs to be done, and they're trying to lead the organization and be that sort of motivational leader to get people coalesced around a vision and executing against that. There's a lot of different types of chaos in this industry, and I do feel like it manifests different, different levels depending on, on the type of role that you're in. Well, okay. Well, kind of, and then kind of just building on that here, what do you think is the greatest challenge that we have in security today and how much you address it?
You know, not saying solve it, but what do you think is the biggest issue?
There are so many to pick from. I think what I would go with And I guess this is probably more top of mind now because it's just come up so many times in the last few weeks with the customers I'm working with, is this idea that there is just too much to do at any given time to do it all. Yeah. And, you know, that resonates with me personally because when I was a CISO, the most stressful time of year for me, believe it or not, was budget season. Okay.
Because Look, if you're approaching your job and you, and you're feeling like this is, this is something you're giving your all to, you obviously want to do a good job on it. Well, budget season is that time where you got to place bets. Um, and those bets are, these are the ways that I think that for every dollar that this budget is giving me to allocate, or this company is giving me to allocate my budget, that I'm using that dollar in the best way to safeguard this organization, its employees, and its data. Um, that's a stressful time of year because you're looking forward, uh, forward a year and placing bets. Now granted, in a healthy organization you have some flexibility to move things around, but that was very stressful for me.
Um, and really, I think the things that made that so difficult, um, is that, um, it was full of, uh, sort of bottom-up analysis of, hey, Let's go to this product owner over here and they own this solution inside of the organization. And what is it that's top of mind for you for this year? And then you go have that conversation with a bunch of other people. And then some of these systems are internal. There's some things that you need to do outside of all that, that are new functionality that you're listing or that you're trying to launch.
How do you take all those things and then somehow put them up against a system that allows you to make objective decisions by getting all of these things that came in that were full of personal opinion and subjective opinions and make this an objective decision. The other thing with budgets that, you know, really concerns me in this industry is we are seeing this cycle where companies have a fairly consistent security posture, and then economics turn, and you get something like a global supply chain disruption or an economic downturn, and the company comes out and says, well, we got to slash budgets, and they go out and they treat cybersecurity like any other line item and go, well, everybody's got to cut 10% on their budget. That is so destructive to our industry because it's a cycle. What happens, and we see it over and over again, is things are consistent, budgets get cut, then a security incident happens, and all of a sudden the board and the other executives are ready to increase that security budget again. And then things stabilize after things get— after that money gets spent.
But then we enter right back into that cycle again, and it's like nobody learned their lessons from the first time. You know, in the security space, the healthiest organizations that I work with, the ones that really are secure and don't have issues year over year, they're doing quite a few things well. But one of them is that they have a high degree of maturity around how they create their budgets and their partnership with the stakeholders in the business and with the board. And I think this is actually an area that AI is actually improving our ability to have good budgeting cycles because we are moving beyond this point where we had a high degree of subjectivity in the process and are really starting to apply risk management concepts that, by the way, have been around for a long time. My dad was a risk manager at an aircraft manufacturer, one of the big ones, and he's had that— he had that job from like 1960-something up until he retired.
These concepts are not new. For some reason, a while ago, the cybersecurity profession decided that the risk management profession— I don't know if maybe the folks that were pioneering this space in cybersecurity just didn't know about them, but they went and tried to reinvent invent the wheel. Well, coming full circle, we're now applying a lot of their concepts to our industry. And AI has come along and said, hey, let me pull all of this data into one place. Simultaneously to that, we've had open quantification frameworks like the FAIR framework come out.
It is now allowing us to say, look, we need to bring in this new solution that essentially just creates a data lake from all these other solutions that we have that have elements risk in them from cybersecurity. And once they're all in one place, let's quantify them. Let's quantify them the same way so it's consistent, so that even if we're off a little bit, at least everything's off in, in the same direction, right? Um, so that we're talking in relative terms. And that helps us get down to this point where we can actually make true risk-based decisions based on quantitative data of risk impacts.
And it is really changing everything. Um, there are a lot of solutions coming up in this space. I was down at Black Hat a few weeks ago. And I was surprised because there's a couple of vendors in the space that I know well and trust. But as I was walking around the floor at Black Hat, I'm like, holy cow, I cannot believe how many new logos have come into this business.
But there's a lot of people in this space now and a lot of good ways to, to advance. But at the end of the day, you know, we can fix this problem. We have the technology to do it in a way that allows us to have good decision support, make really smart decisions. And even communicate to the board better. I mean, this new class of solutions is getting us out of this really dangerous thing that some CISOs were doing where they were showing the board NIST scores.
What a massive mistake. Don't ever show the board a NIST score. The board speaks dollars and cents. Why would you say that? Well, because they're not— you might, if you're lucky, because of new regulations, if we're talking about a publicly held board, you might have one cybersecurity professional on that board.
But the average person on that board, you might be able to coach them up. To understand what a NIST score means, but that's not their native language, right? So now you're asking somebody to sit in a board meeting and make highly informed decisions based on the data you're giving them when you're speaking a language that's not their native language. That's never going to go well. Everybody in that boardroom speaks the language of dollars and cents.
If you can really get all of your cybersecurity risk quantified, which you can, and go to them, it changes everything. The CISO can now go in there and say, hey, We've already agreed that our risk appetite is this much per year. It's $100 million a year is what we've decided, and we're insured for that. But right now, we have $180 million a year of annualized risk based on, of course, not treating every risk as it would necessarily manifest, but looking at the probability that it would manifest and that annualized loss event number. And you can go to them and say, we're at $180 million now.
3 months ago, and I showed you this number last time, we were at $200 million. So we reduced $20 million this quarter, and to do that, I spent $1 million. Furthermore, next quarter, we're planning on dropping from $180 million down to some other number, and here's how we're going to do it. And so now you're speaking their language and making this very relatable. So the benefits here on the way that this stuff is going, moving us to truly risk-based decision-making as it relates to budgeting, and frankly, where you're going to spend the limited amount of chips you have to spend is very, very healthy.
Yeah, well, you know, 2 things. So the first one, I'm laughing a little bit. I know the audience can't see us, but I'm laughing a little bit because I used to prepare reports, you know, some of our vulnerability reports to our board of directors at a huge financial company I was working at. And they were including Qualys IDs in part of that presentation. And I was like, no, no, they're, they're, they're not going to know what Qualys is.
They're not going to certainly know what a QID is. And he goes, well, don't worry, we'll teach them. I'm like, oh no, you won't. You will not be teaching them on that one. But the other part that was going through my head when you're talking about budgetary cuts, for those of us that have worked a lot with those mid-sized to smaller companies, or at least smaller divisions, We're told, okay, we're going to cut your budget, so you're going to have to go find an open source or a FOSS tool to go and solve the solution.
What is your thought to that?
Well, you know, open source can offer a lot of benefits. You obviously have to trust your source. You know, there— I was reading an interesting statistic the other day. On this open source thing. I don't know, I'm going on a little bit of a tangent to your question, but on average, when a company is developing something new, the average is about 90% of that code, the final product, is actually open source code.
You know, and that can save you time in development, it can save you time in operations as well, but then you have to be in the business and making sure that you are looking back at all the different open source repos you used to make sure that you are folding the updates that they publish into that into your code. And the truth is that a lot of these open source repos have known CVEs associated with them. So, you know, you got to be careful anytime you're using open source, but that's not to say don't use open source. Open source is amazing, you know, but There certainly are ways to do this stuff. I mean, even like the FAIR framework itself is a free framework, free model for people to download.
Like, you could look at FAIR and you could write your own algorithms to apply FAIR for risk quantification in your environment, or you go buy a solution, right? Somewhere somebody's already done that. The key thing I think is less in how you do it and being able to move towards something that is That is truly using risk as the key vector to make your decisions objective around where you're going to be steering your investments. Interesting. Okay.
Well, you know, we've been talking for a while. I think we're pretty much burnt up on our time here. So, I want to thank you, Jason, for being on the podcast, taking time out of your busy day. I think this has been a fascinating conversation. I think there are going to be people that are going to want to continue this conversation with you.
How can they continue this conversation with you? I mean, I know CSA has got some events coming up. Yeah, absolutely. So CSA, we have a meetup and our monthly meetups are totally free. It's on Tuesday, September 16th at the Tabor Center in Denver.
If you go out to csacolorado.org, you'll see the events list there and you can RSVP for that. Again, those are totally free, about an hour plus or minus on education. This next meeting, we're going to be covering modern unified risk-based vulnerability management, or as Gartner might call it, exposure management. And then we, in October, we have our fall summit coming up. It's our 7th.
That's a full-day event at DU. That one is not free, but it's very reasonable. Students, it's $80. For anybody who's not a student, it's $100. And we've got really exciting keynotes and speakers lined up.
Just as a teaser for that, Chris Roberts and Kate Keane will be our morning keynote speakers. Chris Roberts is a pretty well-known entity here in Colorado. He was former CISO at Boom Supersonic and just a fascinating guy. Kate Keane, probably a little bit less known in Colorado, but more known internationally. She's on the board of directors and they're sitting CISO of the NTSC.
She actually presents to Congress. She's been speaking to Congress very recently. On CISA 15, and if you're not up to date on that one, I would Google it because that is a fascinating topic that stands to have a pretty negative implication on all of us if Congress allows this to expire. Then for lunch, we've got Greg Foss, who is another well-known entity in Colorado and just an amazing speaker. And then throughout the day, we've got 9 different breakout sessions in addition to those keynotes for folks to attend.
So All that's out on csacolorado.org. If you ever want to contact me, I'm just jason.hayes@csacolorado.org.
It's H-A-Y-E-S. Um, but yeah, always happy to talk. Love, uh, love meeting more people in the cybersecurity community here. And as one of my, um, one of my personal mentors loves to say, iron sharpens iron. Um, the great thing about meeting folks in cybersecurity community, other than just getting to know people and and enjoy, you know, new relationships is just learning from each other. We've all seen different things.
We all have different perspectives. I enjoy sharing what I know. I enjoy being challenged on what I, what I think I know, right? So we can always learn from each other. So iron sharpens iron.
I'm always happy to, to meet up in CSA meetings or elsewhere, grab coffee, whatever. Uh, please feel free to reach out. Well, I mean, I love Chris Roberts. I know who Chris Roberts is. He was a keynote at my SnowFROC a couple years ago.
Greg Foss is a personal friend with me. I fully agree with you. He is an absolutely amazing speaker. So again, that's a great event that's coming up. For those of you that don't know me, my name is Frank.
I am the VP of the Denver OWASP Group. We have a meetup on the 17th of September. So one day after yours, we're going to have a huge announcement at that meetup. We're going to have API Sec University come out. And their leader, their creator, Dan, is flying out specifically for this one.
For anyone that wants to meet me personally, I'm gonna be speaking at BSides Denver, BSides Colorado Springs. And then I'll also be speaking— I was invited to the University of Michigan to speak to at their cybersecurity symposium. So I know that's not exactly next door or anything like that, but I think that's a huge honor for me. So again, thank you for everyone that is listening to this podcast, as I think this has been a great one. So again, thank you, Jason.
Appreciate your time. Yeah, thanks, Frank. Appreciate you. All right. Have a good one.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.