All episodes

CJ Cox, COO @ Black Hills Information Security

Apple Podcasts Spotify SoundCloud

Our featured guest this month is CJ Cox, COO of Black Hills Information Security, interviewed by Frank Victory. News from City of Denver, Block, Zvelo, Lares, FusionAuth, RADICL, Ping Identity, Red Canary and a lot more!

We often talk about cybersecurity as a series of technical hurdles, but CJ frames it through Maslow’s Hierarchy of Needs. At the bottom? Paying the mortgage and surviving the 4th-quarter burnout. At the top? Self-actualization. Doing great work with cool people. But here’s the kicker: CJ argues that real security doesn't come from the name on your badge or the company you work for. It comes from your internal capability to learn and adapt.

We’re experimenting with a new, long-form format on the podcast to explore these "human" elements of the industry—the leadership, the culture, and the "why" behind the "how."
Check out the full episode where we discuss:

  • Why BHIS says "No" to multi-million dollar buyouts.

  • The "Borg" effect of corporate acquisitions.

  • Why building a SOC is a three-year slog, not an "easy button."

Come join us on the Colorado = Security Slack channel to meet old and new friends.

Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at info@colorado-security.com

This week’s news:

Upcoming Events:

View our events page for a full list of upcoming events

* Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at carrrladams@gmail.com. Check out his other voice work here.

* Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0

Read the transcript14449 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is the newscast for Monday, March 9th, episode 284.

Thanks for being here and welcome. Since I am doing the intro, that means that likely Robb isn't here, which is correct. We have a special guest co-host with us this week, Chelsea Weiss. Hi, Chelsea. Hello.

Thank you for having me. Yeah, happy to have you here. For those of you that have been listening, you know, we made the announcement last month that Chelsea and Joe are going to take over for us as hosts of the podcast. And this is Chelsea's dry run before we do that. So I'm sure it's going to be great.

You ready for this? Let's do it. All right. Well, good stuff. We do, as always, have some announcements.

So let me go through that real quick. And then we will jump into the news. First, of course, we do have our Slack channel. If you'd love to talk with other people in the Colorado Equal Security ecosystem, join our Slack workspace. We'll invite you in.

You can find the link on the website to join. We also have a mailing list. When in that same form, when you join, check that mailing list box and we'll get you added to the mailing list. We'd also love if you rated and subscribed on your favorite podcast player so that you get this in your feed every month and everyone knows how great the podcast is. And finally, if you want to spread the word and tell a friend about all of the cool things we're doing here at Colorado Equal Security, we would appreciate that as well.

All right, so let's jump into the news. The first story that we have this month is talking about homebuyers in Colorado and that Colorado ranks 28th for family-friendly homebuyers. Chelsea, what do you think about that? As someone who grew up in Colorado and did a brief stint on the East Coast, but growing up in Colorado, and then I have a family here now, it's interesting that Colorado is really not looked at as a family state anymore if you can afford it. So that's kind of one of the bummers.

You know, when I think about Colorado, I think about being outside and being able to do fun activities with my family, with my kids, and in a sustainable fashion. But that's just not where Colorado is going as of right now. So question back to you, you know, as Colorado continues to grow, is it still going to be a family state in the next 2 to 5 years? Yeah, you know, it's hard, right? So they, in the story, they talk about a lot of the things that are positive that came out of this study.

Education, safety, quality of life are all high. But, you know, the big thing that, that drags Colorado down is that affordability. And so as long as things are still really expensive here, then it's going to be hard to move up these rankings. So it was interesting to me that the number 1 state was Minnesota, which I spent a couple summers in Minnesota in college. So Minnesota is great.

But nowhere near as great as Colorado. So I guess, I don't know if there's a way we can figure out the whole affordability thing, then I guess maybe we'll move up that list. Yes, well, we'll have to see. And 2 of the other following ones that I thought were interesting were Nebraska and Kansas. And if you look at the topography of Nebraska and Kansas compared to Colorado, we have a lot more going for us.

Of course, we're biased, but just for the listeners as well, the study scope was on 48 different factors. So yes, affordability is a big piece, education benefits, the strong lifestyle. But there were a lot of different things that went into the factors. So we will have to see how that adjusts over the next couple of years. But with that being said, I'll go ahead and transition into the second article.

Block cuts 61 Colorado jobs in an AI-driven automation push. So essentially they're laying off 61 remote workers here in Colorado, and that's tied to a much larger national workforce reduction based off of what leadership was saying. They're actually expecting to do— to have 40% of work be automated. So more to come there nationally. And no surprise from my perspective, but Jack Dorsey was talking about how he believes in the article most companies are going to have to make a similar workforce change within the next year anyway.

What are your thoughts on that one, Alex? Agree or disagree? Yeah, yeah, I, I think that, uh, you know, we're already seeing it a lot of companies where they, uh, you know, their block has been more straightforward about saying this is because of AI, whether that is true or not. Uh, many companies, you know, we've seen layoffs that, you know, may or may not be related to AI but haven't been quite as straightforward around the reasoning. So it doesn't surprise me a bunch.

Uh, maybe the the amount. 40% is a big, uh, big number. And I think that they had around 10,000 employees at, at Block, which is— of course, the name for Block used to be Square, so people are probably more familiar with Square, the, the payment, uh, technology. Um, but so yeah, so that's 4,000 people. That's a lot of jobs.

Uh, and it's, you know, Square— or excuse me, Block was, you know, not a huge company, but You know, I could see where if larger companies feel like they can get these same efficiencies, we're going to see lots and lots of layoffs based on potentially on efficiency from AI. Yeah. And to take that a step further too, typically I had associated, you know, layoffs related to AI with companies that are not performing as well. But this is a really good example of that not being the case. In the article, they talk about how Block has had such strong revenue growth.

2025, it was $11.5 billion, which is a billion up from 2024. So point there is this is not happening to companies that are not doing strong financially. You know, it's, it's all organizations looking at structurally how are they going to use AI in the organization. And the other piece that fascinated me too was These, these roles that were being laid off include engineering, product sales, risk design, customer operations, things that require a high input of the human element. So not just kind of the low-hanging fruit that AI can, quote, easily take over, but some roles that are legitimately supported by humans.

Yeah, it's going to be interesting. I, I'm sad a little bit for the, the young folks that are coming up, and then all of a sudden all these jobs that are, are going out of the job market. So it's going to be interesting to see, uh, what the, the job market looks like over, uh, the next couple years. Um, one other thing that was noted kind of at the end of this article was that, uh, in February, um, Angie, which is the parent company of Angie's List and a couple other, uh, properties, announced that they were laying off 350 employees to replace them with AI, although they didn't mention whether or not they were here in Denver. So other Denver tie-ins, Colorado tie-ins to this kind of trend.

But, okay, jumping to the 3rd story. This I thought was an interesting one. Although, you know, I guess I'll say a little bit misleading. So this is about Denver they say, turning to artificial intelligence, to AI, to help fix permitting problems that they have with Denver. There's been a long, long road of slow permitting process in Denver that builders and developers have complained about.

And Denver is adopting a system that has AI built into it that will supposedly help speed that process up. What do you think about that, Chelsea? I think this is actually a really good example of where AI makes sense. Like, removing friction in your bureaucratic process is something that aligns with how we should be using it. When we talk— when the article talked about how bad the problem was, once again, 297 days for an approval on average, that's pretty intense.

The article did also talk about how there's other cities that have put this into place, and they were able to cut the review time by 70%. So pretty drastic and almost immediate impact here with this use case. Yeah, I thought that was pretty cool. One of the things they talk about is how a lot of the delay is, is the turn, right? So somebody will submit something, it's got to go to a person, there's going to be a delay before that person can look at it.

Then if there's anything wrong, then they have to send it back to the submitter. Then the submitter has to look again. You know, it's a little bit like doing contracting, right? And with the AI system, now they can have the system review the submission before it actually is fully submitted so that if there are any at least initial problems, the submitter can fix all of those first. And then that initial turn goes away.

So So that is pretty cool. You know, one of the things that I thought was interesting, though, is that, you know, in order to do this, they are implementing a software tool called CivCheck, which they're buying from a vendor. And, you know, the article is touting this as implementing AI, which is probably true. But really, in my mind, they're just buying software to make this better. And so, you know, in one sense, yes, AI can help.

But in the other, it's, you're just buying software that does a good job at doing this thing. So it's one of those cases for me where I feel like, yes, you can kind of tout AI's benefits, but it's also just, hey, you know, smart outsourcing or software procurement processes. Yes, you bring up such a good point that I wish more people honed in on, which is AI does a really good job at removing friction from broken processes, but It doesn't fix the actual process itself. So sending, you know, City of Denver positive vibes that this works out. But I also think it's going to, to your point, uncover some other areas for improvement.

All right, moving on to the 4th article of the day. Denver is set to pause data center developments as mayor joins call for a moratorium. So this one talks about the pause on the new data center construction, which has been a hot topic over the past couple of months so that the city can review how those facilities impact electricity use, water consumption, zoning, energy costs before actually building it. The debate is being driven by a project in Illyria, Swansea, where residents are concerned about the environmental impact of the large facilities. When you think about things like diesel backup generators and the heavy energy demand, that's absolutely something that needs to be considered.

The article does say that this specific moratorium won't stop projects already approved, but it would give the city time to work with the community members, climate experts, and the rest of the industry to have better ideals and create clearer rules for how data centers can actually grow responsibly. Yeah, I think this is a really smart approach. Obviously, you know, we've talked about several articles that have AI involved in them previously. And in order to have AI, we need to have these data centers that are being built for all of the processing power to power that AI and other software. And so, you know, we're going to see more and more data centers being built.

Some of these are going to be in cities, some of them are going to be out in the middle of nowhere. But I think it's important to, to make sure that where these are being built, they make sense, that all of the factors are being taken into account. And of course, you know, because a lot of this stuff is moving really quickly, you know, cities may, or other municipalities may not have their processes and their rules really defined very well because it wasn't a big deal before. So taking that pause, putting a moratorium in place to think about this before moving forward with any projects that aren't already in place probably is a smart thing to do. What do you think, Josie?

I absolutely, I agree with that. And that's the way we treat our critical infrastructure right now. So like when we build highways or airports or anything along those lines that can be considered critical infrastructure, there's a very specific process with checks and balances and connecting with the right folks to make sure that how it's built actually makes sense. So What I would also like to see out of this in the future is perhaps we start treating data centers like critical infrastructure. So they do have those, those healthy planning pieces.

And then the other thing that this brings up that I wish more people were talking about, you know, we have this AI boom happening right now and people have yet to really realize that AI has a physical footprint. There's a colossal amount of infrastructure that needs to be set up to support it. And unfortunately for some cities, that's not realized until the data center starts being built or they're talking about it in their area. So we will definitely have to see where this one goes. Yeah, great point.

I think, you know, for all these big projects, there are always environmental studies and everything else. For something like a data center, probably isn't happening today. So I think that that is a good thing to to think about in a great parallel. All right, moving on to our next story. This is from KDVR in Denver, Fox 31, and talking about a Colorado man who was duped by a deepfake ad and just sort of a general warning about cybersecurity scams and other sort of deepfake scams.

So, Chelsea, what do you think about that? I am— for those of you that know me, I wear a fraud hat at any organization that I step into, and I was fully fascinated by this one because previously people are looking at deepfakes as entertainment, but this is a perfect example of how it's now monetized fraud, and it's a legitimate full marketing campaign built on AI deception, which is messed up. You know, from the gentleman's perspective, but at the same time, as you know, someone that looks at fraud intelligence on a regular basis, super fascinating to see how this has— this is involved. The question that I have perhaps for you, Alex, at what point are YouTube and Facebook going to become responsible for the fraud that's happening inside their paid ads that they actually approve? Yeah, it is interesting and One of the things that was mentioned in the article is that, you know, there aren't supposed to be any deepfake ads on these platforms according to their policies, but clearly it wasn't policed very well.

And also the, the manufacturer, when they were commented, said that as part of their policy, they don't allow deepfake ads as part of, you know, their marketing processes. So either someone's not checking or, you know, some process is broken. Or this is a third-party ad that was, you know, trying to sell these products for the company, something. But obviously not enough checks and balances in place. Um, and, you know, I think that this is just going to become more and more prevalent.

Um, as the— as AI and deepfakes get better, you're going to start seeing all kinds of people selling things that that are not really from being endorsed by those people. I remember a story not too long ago that I think there was— Shaq was in a deepfake ad selling something. And so you're going to see this more and more. So these platforms really do need to step up and figure out how to police this stuff. And of course, like, you know, every sort of fraud, the consumers need to be paying a lot more attention also.

So it's going to be tough out there for a bit. It is. I would buy something from Shaq, so I need to check myself on that. But the other crazy piece about this too was BBB. So Better Business Bureau was, was part of all of this.

And they made a really good point by saying the people that are buying these things are putting unknown substances into their body. So yes, it stinks from a fraud perspective, but also, you know, you don't know what you're consuming, if that's a placebo of some sort, if it's something that you know, could be harmful to you. So with that one, definitely an area for, for improvement because that stuff is getting trickier and trickier for us to be able to detect for sure. All right. Moving on to our 6th article, Building the Future of Defense Tech.

So this one was about SMBs and how they support US defense programs and how those SMBs are increasingly targeted. Many of these smaller companies don't have the budget or the staffing for enterprise-level cyber or a 24/7 SOC. And the problem that this creates across the defense industrial base and critical infrastructure is, you know, essentially a supply chain issue. Alex, were you surprised by this one at all? No.

And this is the first of our sort of security, security articles of the week. And this was from, um, from RADICL. We talked about them last month, maybe the month before, um, regarding their, their recent, uh, Series A raise that they did. And you know that they're, uh, well, one, it's good to see this article to get a little bit more in depth on what it is that they are trying to do over, uh, at RADICL. And, uh, I, I agree with what they are saying here.

Uh, you know, many of these defense industrial base companies are very small, yet handle very important parts of critical infrastructure. So, you know, having a security partner that is geared towards them and can help give them enterprise-level services at an affordable price, I think, is, is a smart move. And hopefully it's something that RADICL can succeed at so that these companies get the protection that they need. Yes, absolutely. Very helpful.

Could potentially be very effective pending the pricing is right, because also the way that I look at this too is the challenge, not just the tools, but the operational capacity. Does the company actually have the capacity to be able to detect and respond effectively? So very exciting opportunity here for sure. All right, next story. This is from a blog post from FusionAuth.

Title is Your Token Proves Who You Are, Not What You Own. And I thought this was a good piece. It goes through a little bit of a case study on DJI and their introduction of their RoMo robot vacuums and how they didn't do a very good job with tokens and implementing the tokens for their robot vacuums, allowing somebody to get way more access than they needed by just taking their legitimate token and poking around. I think the bottom line was that the authentication was good, the authorization was not good. Chelsea, what's your thought on that?

Yeah, this one actually cracked me up. To provide a little bit more about the case study, this guy just wanted to use his PlayStation 5 controller to drive his vacuum, which is like pretty cool. That makes legitimate sense because he didn't like the UI of the app that they had. But like, as you had said, the backend never enforced the resource level authorization. So that token gave him access to 7,000 different devices across 24 different countries.

And, you know, the other, the other hat that I wear is a product security hat. And I can tell you guys, This is like the classic broken level authentication, like OWASP Top 10 API risk problem where platforms check whether the token was valid, but they don't verify if the token owner actually owned the device being queried. So very specific example of that. Yeah, good stuff.

Moving on to our next one, visibility gap. 5 Purple Team Tests Your EDR Is Probably Missing. And so this one talks about 5 different TTPs— techniques, tactics, procedures— that consistently bypass our traditional security controls. And the moral of this article is you have to understand how attackers are abusing your legitimate tools and doing things to blend in to the normal traffic that you see. So Some organizations look at having an EDR and tons of logs as a healthy security control, but it really doesn't mean you're protected.

You have to have healthy detections that are tuned to the actual techniques that attackers are using. Otherwise you have a major visibility gap. Alex, what were your thoughts on this one? Yeah, I agree with you. I enjoyed this post from, from Laris, and I thought that the techniques that they talked about here were, were very interesting.

Talking about some of the things that they see in their purple teaming that are often missed. I think, you know, backing up even a little bit, you know, I think purple teaming is a really important process and something people should be doing. Basically, you know, having your defenders work in conjunction with offensive penetration testers so that as they are attacking When they are successful, you can figure out why they were successful and then, you know, also coordinate with them to put in detections and preventions so that, you know, more immediately those problems can be addressed.

The, you know, some of the things that they were talking about here I think were interesting, and it just made me think a bunch about what it is that may or may not be missed for EDR. And I think we all know that any security control isn't perfect, but just like everything else, you've got to tune your EDR and make sure it is looking at the appropriate things so that you are getting good detections. So good stuff. Yeah. And the article also calls out the difference between passive logging versus active defense.

And that's always a really good conversation and something to understand because the analogy that I like to use or the way that I look to look at it is passive logging is like when you have cameras everywhere, recording everything, but when something bad happens, so that you can go back and actually watch the footage. That's the passive logging. But what you actually want is active defense, which is akin to where you have guards watching those cameras in real time so that those guards can intervene, stop threat, and actually adapt when something happens. So I think, you know, that was also a really good message that folks should, should understand because the industry has spent the last decade optimizing for data collection. These next 10 years are going to be about detection engineering, and this article did a very graceful, nice job of calling that out.

Good stuff. All right, next story. This is a post from Zvelo, and the title is AI Model Drift Is Inevitable. Trust Intelligence Requires Human Supervision. And While I care less about the second half of that specifically, I think it is a super important point that as we develop these models and LLMs from AI, they can't be static, right?

The models themselves, as data changes, the effectiveness of those models are going to change. And we need to make sure that we are looking at the performance of those models and have human intervention to update them, to change them, to give feedback as the models drift from what they were originally intended to do. Chelsea, what do you think? Yeah, this is a really good example, another really good example of why human-supervised AI is needed. Very powerful, but it's not one of those things that you can just set and forget.

The question that, you know, came to my mind reading this one is, when you look at your security platforms that are powered by AI, who is actually validating the intelligence it produces is still accurate?

Yeah, exactly. You got to have somebody in that loop, whether it is you know, something consistently, some sort of, you know, retroactive process, you know, until you have those checks in place, you're assuming that things are going to work, but they may or may not be. Yes, absolutely. That will take us to our last of the day, which we can thank Red Canary for breaking down a supply chain attack leveraging a malicious Google Workspace OAuth app. So this one was about how attackers phished Chrome extension developers into authorizing a malicious Google OAuth app, which essentially granted them control over the Devs Chrome Web Store extensions, leading to the stolen millions of cookies from various users.

What were your thoughts on this one, Alex? Yeah, I think this is another great case study, threat detection case study from Red Canary. They always do a great job of publishing these kind of articles talking about a specific instance in a lot of depth. Obviously, you know, phishing is a bad thing, and then when you add phishing for someone's OAuth credentials, that makes it even worse. And then when those people have a whole bunch of power in those OAuth credentials, then you're headed for a really bad day.

So it was interesting to see how this attack worked and all of the detail that Red Canary put in here that we can all leverage to detect and help stop things that are similar. Yeah, it's, you know, at the end of the day, it wasn't a malware problem. This was a— this was definitely a permission problem. So thank you, Red Canary, for that one. Awesome.

Well, that takes us to the end of the news. Uh, we'll jump over to events. Of course, we always have our full event calendar on the website too, so check that out at colorado-security.com. Uh, we actually just made an update to that event calendar, uh, did some automation to hopefully make those, uh, those events more timely and in a little bit of a different format. So Go check that out.

The first event that we have coming up on March 10th, ISSA Colorado Springs is doing their March chapter meeting. And immediately after that, on March 11th, ISSA Denver has their March chapter meeting. On the 18th of March, we have a new group that we are tracking called IdentiBeer. This is an identity security meetup group. Get together and, and have a beer and talk about identity.

Yep. And on March 18th, Denver OWASP has a meetup for MCP LFI in 60 minutes or your money back. That sounds interesting. On the 19th, ISACA Denver is doing their March chapter meeting and this one is virtual.

And on the 25th of March, we have ISC2's Pikes Peak meeting. And finally, on the 28th, ISACA Denver is starting their spring training classes for, uh, CISA certification. This is an ongoing series of classes, so that first one will be on the 28th, but they will continue for several weeks after that. If you're interested in getting to be a part of those trainings, go check out the ISACA website. They are free as long as you are an ISACA member.

When I got my CISA certification, I went through those and they were great. So you should check it out. All right. That is all we have got. We do have an interview for this month.

Frank Victory sat down with CJ Cox, who's the COO for Black Hills Information Security. Had a great conversation with him, uh, so looking forward to hearing that. And, uh, yeah, that's what we got for this month. Uh, Chelsea, thank you. This was great.

Appreciate you. And, uh, we will talk to everyone next month. Absolutely. Thanks, Alex. Take care, folks.

Paul Beckford, Vice President of IT and Security, FBI Incorporated. Welcome to Colorado Equal Security for Colorado security professionals by Colorado security professionals.

Well, good morning, good afternoon, and good evening. This is the Colorado Equal Security Podcast. My name is Frank, and it is February 2026. In this month's broadcast, we'll be bringing back CJ Cox, Chief Operating Officer of Black Hills Information Security. Now, CJ is known to be a very pragmatic COO.

And he was brought in by the CEO to, quote, do the things that he does not want to do. The first question I'm going to ask him is, in an industry where everyone is obsessed with easy buttons and high growth multipliers, how do you manage the tension of running a lifestyle business that refuses to burn out its people just to satisfy a bottom line. As Chief Operating Officer, and especially at Black Hills Information Security, look, John brought me in because he had worked with me once before, and we were, I guess we were like minds. We were definitely bonded kindred. So I came in as John's friend.

And when I came into the company, I don't know how many people we had, 20, maybe 30 people in the company. And that's not exactly the size company where you need a COO, but he gave me that title. And the reason, I think we talked about this in the other podcast, the reason I have that title is so that customers will talk to me. And so they understand that I have weight within the company because John really did. He said, I brought you in here because I needed somebody to help me keep the plates spinning.

He didn't pull me in because I was a brilliant hacker. He brought me in to just help him to do— I always, my comical way of saying is I do the things John doesn't want to do. Okay. So, among those things that John didn't want to do was talk to people who wanted to buy his company.

John, I probably attended 1 or 2 calls. So, within the first year, I was handling calls with people negotiating to buy the company by myself because they were going to be 30-minute conversations. So here's how the conversation went with John. Company comes in, realize that the— so the multiplier on service companies is, I think, 1.5 to 2. I think in some extreme case you could get 3 times.

So 3 times your revenues. So if you were a $10 million company, you're going to get $15 million, $20 million, $30 million on the outside, something like that. Our offers, we never really got the specific number, although I always prodded them to see like, well, what is the number that we'd get? Because I was just curious back in the day. So typically they— it would be maybe say $8 million they were going to pay, which, okay, $8 million for a very small security company, like that's, that sounds kind of good if you're John Strand, right?

Like $8 million, that's almost FU money, right? That's almost like I never have to work again. I think $8 million would qualify as that. Okay, but a couple things that may be unique to John that aren't common to other people that own or build a company. One is John is totally doing what he loves.

He loves it. He loves teaching security. He loves raising the bar. He And if he didn't have a job, or if he— what would he do? Like, well, he's got a ranch, he could ranch.

He loves to mountain bike, he could mountain bike. He could rock climb, he could ski. But that's not enough for him right now. He has all those things in a balance, right? And he always has.

Um, so the other part would be if he sold to somebody, there would be a non-compete And they're buying Black Hills name and, you know, so they want to— and they want John to stay on board to guide them. So for 5 years, the man who's worked for himself and collected a team has to work for somebody else for 5 years. So that's a lot like purgatory, right? He created his own company because, heck, I like working for me. Um, and then he had the problem of that John pulled in people that were friends or quickly became friends.

He's like, sure, I can sell out, but I need that $8 million. What does the rest of the company get?

Like no one who builds a company and sells it, at least the executive team is always in, right? In on the payoff. And if you're really good, you're like, well, all the employees should benefit. Well, I just don't think there's that level of money at that level that you can give everyone in the company a million bucks and the owner still gets a decent share, right? So to me, it just doesn't work out.

And again, John's just— so then what would he do? Go build another company? Well, he just built the same company again. So the point is, why sell when you're doing the thing you love, you're making the money you want, you're working with the people you want, Other people have higher aspirations, right? Like, well, okay, but let me think here, right?

So in your typical acquisition, right? Because you're talking more from a small company, but let's put, let's shift this a little bit and let's say that we're gonna give you, I'm gonna give you, I'm an investor, I'm gonna give you $50,000 and you are the CEO, right? You know, or, you know, you're made there to find decision maker, right? Why would you not sell for $50 million or $100 million? Right.

And, you know, I think from a context standpoint, right, we need to remove the John factor out here. Okay. And what I mean by that is, you know, the things that you said about John where he'd give everybody a fair share and things like that, that's not the typical mindset. I mean, I've been through, what, 5 acquisitions now? We're about to go through another one.

Um, I know that when they sell the company, they're not giving me— I'm worried about me and my money. So why would you or would you not sell? What would be that rate? You probably would. Okay.

Because you're looking at— so the company's not— if the company's being bought, it's usually not public, so it's private. So whoever holds that, and if it's a sole proprietorship, At $100 million, I think most people would probably sell.

We still today, we might get $100 million if we sold today. And so an owner, you make your decision, like, are you ready to get out and take that money? Tons of people when they're building products, build things, software. Think of the software companies that sell out to Google, Apple, everybody, right? It's constant acquisitions.

Biotech, all those companies, they sell. And I knew companies when I worked in an incubator in Northern Virginia. I knew guys who were on their 3rd company. And I'm assuming they sold it for, you know, in the millions each time, and maybe they got a little bigger each time. That's a wonderful— they seem to enjoy their lives and love what they did, building a different company and doing all those things.

Had a great time doing that. So it's not that it's a wrong decision, but you have to know what you're in the business for. And if you just want to get a double-digit million-dollar payoff, there's absolutely no reason not to sell. Um, well, okay. So in those situations, did they pay their employees $1 million each?

No. Right. Or whatever. I've never heard of that big. I've heard of companies where they sold and people got 6-figure payoffs for sure back in the tech boom.

Yeah, but that's not typical, right? Not typical, but in tech, it kind of, I think it might be more common. I haven't done the research. I would think that it was. I was working for a company called MindShift Technologies that still exists, by the way.

We had angel investor money. So, when they give money, that takes strings. So, we did a lot of things based on the investment group, a bunch of MBAs and that guidance to us, which included at one point downsizing, cutting our staff in half, which happened to include me.

But we were all working under the impression that there was going to be a 6-figure payoff for every single person on that team. We had about a, I don't know, 30 or 40-person team maybe. And of course, the guys that owned it and the guy that was the CFO, the the CEO and the CFO had been in another company before and they were doing this again, they were going to get, you know, multimillion-dollar payoffs. So that was the whole motivation. Now, we were also motivated to deliver great tech services.

And so we had super smart people and we were working insane hours and doing great stuff. But that was the goal then. There's nothing wrong with those goals. You know, People, luckily in America, we set our own goals and what does success look like to us. And I think when you're designing a company at the start, when you start a company, maybe most people are just like, I just want to get by.

I just want to make a good living. But as you get success, that's going to change. And life is dynamic and constant. You're going to have to constantly evaluate. And when the offers come in, because if you're a product company, You could get 3x to 10x or even higher, right?

If you were building some AI thing or some special chip, the sky's the limit. So what will the market bear?

Well, let's go with this one, right? And, you know, we'll deal with, and I'm going to ask this from a point of, with BHIS being a very unique company, right?

Would the effect of BHIS have— the selling of BHIS to some corporate no-name, right— affect the tech community? How would that be affected? Um, I have my own ideas, but let's think. People will be disappointed. You don't get assimilated by the Borg without, without being fundamentally changed.

I worked at Martin Marietta, which was a small defense contractor And we got bought by Lockheed Martin and we called it the Borg. And it did change the company. Lockheed Martin is huge. And I had great experience at Lockheed Martin. They are a great company and a huge company and doing lots of great stuff in different places, but it was a big company.

And so it has the big company bureaucratic feel to it. It's not as agile. It's not as, you know, like one of the BHIS, we consider, call our boutique pen testing firm, right? It's like going to a coffee shop. It's different going to a custom coffee shop than, you know, Starbucks is great.

I love my Starbucks. I go there all the time, but it's a different feel. And so we fill a specific niche. And if we got bought by, let's just say Dell SecureWorks, right? Or Optiv purchased us or somebody, we just become a piece of Optiv like DataSimulate.

But most of these companies, a lot of these companies, I think, are companies that were doing something they wanted to tack on pen testing. And if they tacked on a great name, they'd get themselves a head start and a runway on building more clientele. And so they'd be trying to purchase that. And they may not know the audience like that. All those customers BHIS had may just be completely uninterested in working with us after we're purchased by the Borg Incorporated.

But what about the community portion? I mean, that's the biggest thing. And I think we've had this discussion. You and I have had this discussion. A long time ago about, you know, what you do for the community, right?

I mean, that's, you know, one thing that BHIS is actually bad at, right, is advertising. Okay. And I'm not saying that in a bad manner, right? Because, but, you know, we don't, I don't see a lot of come buy this flashy new pen test because it happens. But yet when I've talked to you in the past, you're like, well, we can't keep up with stuff.

We actually have to turn people down because we can't keep up with the orders. Sometimes when that's— yeah, that happens. We were like, we can't handle you, so we're just gonna say no versus doing a crappy job, right? Yeah.

I'm now going to give a very tough question here for CJ. I'm going to be asking him loyalty to the people versus loyalty to the company. Now that he's at the top of the food chain at BHIS, how does he balance your loyalty to the people with a cold hard reality that the company has to survive the, quote, bad years to keep paying them? As a COO, and that's responsible for the revenue, right? At least I'm assuming that's one of your jobs or part of your job.

All right. Why would you do that? Why wouldn't you make me, if I was one of your pen testers, say, well, Frank, you're going to do a pen test every fricking week for the next, you know, 6 months and work that extra, but don't worry, we're going to give you a $50,000 bonus. So I wish people were purely motivated. I wish, no, I don't.

But if people were purely motivated by money, that'd work great. Heard the story of the goose, right? John and I say that all the time. Let's just kill the damn goose. Look, the— and when we talk about people say, well, what's special Black Billings?

I'm like, look, our secret sauce is our people. And that sounds jive. Every company in the world, yes, we're all made up of people, we get it. But, but because I guess John takes the approach that it's a lifestyle business, he looks at that for his people too. And You just can't, you can burn your people out.

There was a great presentation at Mile High HackinFest on burnout. By Natalie. Yep. Natalie. I saw her at OWASP and I brought her to Mile High and she's fantastic.

Burnout is real. That's the whole approach that one of the things that everyone's captured BHIS's secret sauce, only have your pen testers work on one engagement at a time. They're not working 3 or 4 things. If a customer drops on us, we're dead in the water because we can't just flip over to customer B.

So, but that's designed because that's how John perceived people did their best work. And that was what John was interested in. And luckily in capitalism, sometimes that sells the idea that we're giving people a chance to do their best work. And it shows, it shows up in the product and people come back to us and people tell us all the time, Wow, you find things and you guys are just different and it's better. I don't have a measure on that, but it seems to work.

It doesn't mean that other approaches to business don't work or that other people are doing bad work. It just seems to work for us, the whole thing. So, you could try to kill your testers during the 4th quarter, and our testers do work hard during the 4th quarter. Our compensation for that is we take off from Christmas to New Year's. We just shut down because customers don't want to do a pen test anyway.

So we work real hard in the 4th quarter. We pack real tight. The rest of the year, we try to be reasonable in how we schedule things and to be able to be sustainable. Everyone talks about that sustainability. Well, sustainability on human energy.

Pen testing is clearly a treadmill profession. You see people burn out on it all the time. It's real easy, a lot of pressure. Pen testing is difficult. And so I think you've just got to run a little bit.

And if you're running on the bottom line only, the bottom line is going to have a human cost. And so to me, we just do a smarter cost-benefits analysis, calculate that, and we've been sustainable. So that's when you talk about, you know, growing and the culture and everything, we had to grow. We had to grow because we despise and hate, and we hear the disappointment in the customers who call us, you know, in July and say, yeah, I want to get a pen test in before the end of the year. And we're like, I don't know if someone drops, we'll be able to get you in.

Right. So every year I've been here 10 years, every year until this last year was a rough one. But, you know, we've always been pushing on it and we've grown because we didn't want to say no to customers. So we grew organically. That was one of the things that when people came to buy us, they'd be like, well, what are your growth targets?

I'm like, we don't have any. If the demand is higher than the supply, then we grow. And if the demand is smaller than the supply, then we'll shrink. Like we don't have targets. We go with the damn wind, which is another bizarre thing that business— look, when you're publicly held and people expect a return on investment, you can't do that to them.

You don't have that option. So, yeah, well, that doesn't exist in any other company. No other public company. Yeah. Public companies have to do it that way.

And that's one of the reasons why, when you talk about the reasons, what should someone who owns a cybersecurity business be thinking of is like, do you want to be that kind of business or do you like the kind of business you are now? And what's that worth to you? So it's all, so you actually embrace the values. Though, that you— a lot of people will put that stuff on the walls. You don't actually read them.

Yeah, how we've all read the Jive mission statement: to provide maximum value to our shareholders and our customers. Oh, that's so inspiring.

John's mission is to do, do great things with cool people. That's John's mission statement. In the realm of cybersecurity is unstated, but And people like— well, yeah, and but see, I think in that case people come to you, they— that you don't need to advertise because people already know. I mean, it's— why wouldn't they, right? And plus they know that your stuff works.

A lot of people don't, Frank. We— a lot of people don't. Like, but that is like, we spread it through the things we do. And you were talking about what would the impact— what would the impact be to the community? So that's interesting question.

Black Hills could actually sell off and Wild West HackinFest could go on because Wild West HackinFest has become self-sustaining almost. It sort of gets a buy-in because we use it as a corporate retreat. So we put some money in that gets all the different people there. But Wild West HackinFest in the community, that could continue on the way OWASP does. You know, we still charge enough to have the facility.

We still have the network in the community and collect it in. So the community could go on. What we lose though is sort of our laboratory of pen testing where our pen testers are in the field pushing on the edge and learning things and being able to share them because they'd have to work somewhere to get that pen testing experience to plug that in and our SOC team as well. So, well, that's different though from, I remember the first Wild West I was there and John was determined to lose as much money as he can. I think on that one, he was like laughing about, oh, Oh my God, I didn't lose enough money.

So let me go bring in lunch for everybody. Yeah, I don't know. There's only so much anyone can lose, but like I said, it did really sort of pay for itself. Yeah. So, and you can still do that with the taking people out to lunch thing and all that's worked in and it managed to work out.

Remember, economics is fundamentally a, as Stephen Covey said, a win proposition. You can only do it. You know, and that's why like our training, training's likely to go up. Um, because the costs are just going up and we've got to, you know, we've got to pay enough to, or charge enough to pay the bills and pay the salaries of those good people. Um, but yeah.

From corporate schooling at Northrop Grumman to being let out for recess at Black Hills, CJ Cox has seen every leadership style under the sun. But what happens when a visionary founder can no longer be everywhere at once? CJ explains why empowering champions is the hardest and most necessary pain point of growth. The story isn't completely written. So there's a Greek philosopher out there who says you can't step in the same river twice because rivers are dynamic.

Yeah, now it's in the same exact location. It's between this bank and that, but the river changes. The water molecules, if you want to take it that way, right? Every person you add to a company changes the company. It's a living being.

It's dynamic. And so when you add people in, it changes things. When I got there and we were around 20, 30 people, there were people in the company that were just hard over about, no, we should not grow. We shouldn't— no, because they loved what we had. The fear of losing that, right?

And I glommed onto the idea of that. I knew that because I was the sales guy. So I dealt with the customer's disappointment. And I'm like, but we have to hire 2 more pen testers. We just have to.

All these good friends were saying no to. And so, so I was looking for the solution to how I answer that thing about us not losing what we are and who we are. And I, it's like, corporate cultures existed. I'm like, well, how do we preserve that culture? So, first thing is you identify what it is.

You clarify it, distill it, and present it and share it and go forward with the goal is to keep those things. Now, there's parts of it that are going to change no matter what because, again, think of living creatures. Things change. But you do want to hold on to that which is essential. And you just have to be very purposeful about that.

So what does that mean to someone starting a company or somebody working a company? Well, if you work at a company like I worked at Northrop Grumman, I worked at Lockheed Martin, I worked for SAIC, you have to understand what the company is and what their culture is. And they'll tell you, nobody's shy about that. They'll tell their culture values and all those things, but also what is the lived culture. And you have to learn to adapt.

And if you want to succeed in that organization— and Northrop, I think Northrop was going to be my last company. Company. Um, I was there, and at one point I was pretty unhappy with it. And I had a commanding officer in Iraq who kind of turned me around on, if you're going to be someplace, you got to be happy. And I just flat out made a decision that I was going to be happy, that I understood the limitations and the bounds at what Northrop Grumman is and was.

And they're a great corporation, and I was going to be happy with that. And I was. And then John snatched me out. I feel like he let me out on recess and I never had to go back to school. I still think tons of friends and love Northrop.

And like I said, but you have to realize where you are and what it is and accept that. And if you don't like it, you need to change and you need to go someplace, find a company that's got a culture. And when you're interviewing people, you have to evaluate what is this? Who is this job? What is this like?

What are, what do I see as their values? What do people I talk to, what do I see about their values online? Can I fit in? Can I accept it? Because it's not going to be perfect.

Black Hills isn't. Okay. Well, let's look at it this way then. Let's look at it this way. All right.

It's of course 2026. You have 140 people, right? You started almost 10 years ago. You said something like that, right? Okay, I want you to go back to 2016, or let's say let's do 2017, right?

And talk to CJ in 2017. What would you say to CJ in 2017 about the growth as far as— yeah, don't make any of the mistakes, okay? Just don't make a mistake, okay, CJ? Just don't. Just rule one, don't make a mistake.

Great advice, future CJ. Thank you so much. I really appreciate that. It's ridiculous. Look, I could say, don't do this.

Don't start that. Don't— you can't know. You take risks. Things are harder than you can— you think. All right.

We started a sock. We refused to start a sock forever because we're in the business of making socks look silly and we did it a lot. And we're like, well, we just don't think a SOC can be done right. It's, you know, and we, so we were like, we don't want to be in that business. And then a couple pieces of things popped into place.

John's belief in active countermeasures. And we said, ooh, what if you could actually do the SOC right? What if you could, what if you could be groundbreaking? What if you could make a real difference? Then we're all in on that.

We just didn't want to do something that was kabuki, right? Look, we have a SOC, check the box. Yep, we're monitoring logs, we're monitoring alerts. Great. We thought we could really make it work, and we thought we had an easy button.

And you're a fool in cybersecurity if you think you have an easy button. We've always said all along, which product is the silver bullet? We all know the mantra. There isn't one. We thought we had the secret sauce and we thought we were going to be on easy street and we were dead wrong.

Okay. It's been a slog. It has been hard, but we're, we're making real progress and traction and we're seeing like, yeah, we're on the trajectory, but it's taken 3 long years and a lot of pain and a lot of hard work and a lot of trying some things that failed, quite frankly. And guess what? That's the real world.

That's just the real world. You can't bypass the mistakes and the trials. And I would— growth has been hard and it's been super difficult and it's a different world and you have to structure yourself differently to meet that world. So, as you grow, you hit inflection points where we were super flat organization and we still try to be as flat as possible. But there just comes a point where you've got to change your leadership approach.

John can't be everywhere all the time. And so, and he's always pulled these good people in. He says, you got to let them go champion and then be accountable and kind of run it themselves. So, entrepreneurial growth, that's a real pain point trying to get there, get the people to take that charge and get it and get them to understand really the leeway of their own power and what they're being given. Um, so it's a constant struggle and it's hard.

It's harder than, than we, than I think it should be. And that's just because I want to live in an ideal where I just hit my easy button and everything flows. We have all seen plaques on the wall. Our people are the greatest assets. But how often is it just corporate kabuki?

CJ Cox and I get into the weeds of why hiring smart people isn't a strategy. It's a cliché. We talk about the reality of leadership, choosing between bad options and avoiding that sacrificial lamb project manager, and why your ego is usually the biggest obstacle to solving a problem. But let's say this, let's say this, okay? And this is a very— I'm going to give you a very unlikely situation, right?

Okay. Some company comes to me and says, Frank, you're now the CEO of ABC Company. Right? I come up and I'm going, okay, CJ, right? You have 10 years of experience as a COO.

What do I do? Right? I have no experience as a COO. What would you tell me to do? What kind of— would you give me your secret sauce and say what makes you successful?

Right?

So I think in every job, and this goes for when I was a dishwasher in Evergreen, you have to figure out what is the problem, what is the culture, because solutions are gonna fit in that. And then you have to, your job is to serve.

I think when people go awry, their egos are usually one of the things getting in the way. But if you're looking at how do I serve, what is the problem, what's the best way to solve it? And that you're willing to do whatever it takes within your ethical bounds to solve those problems. And one of the biggest things that makes is talking to other smart people and engaging them, doing a complete analysis. You can't— there's no such thing as a complete analysis.

Doing a good enough analysis that you understand the parameters of the problem and you move it forward. Another big thing that people have is the perfection of the fear of being imperfect, not having the perfect solution. There are no perfect solutions. Get that out of your head. You're not— so many of the problems we face, it's choices between bad options, and your job is to pick the least bad option.

And so that takes a lot of wisdom, a lot of constraint, and you're going to make mistakes doing it. So you've got to keep— you've got to do contingency planning. You've got to pay attention to what are the parameters that tell you whether on track or off track and be able to change. Quickly. In fact, whatever plan you have ought to account for change.

So everything I give you are these broad-seeming platitudes, but quite frankly, from the way I see it, is that it's just the way it is. Doing what I'm doing at Black Hills or doing it at Northrop Grumman are just such completely different jobs because it's the problem set. And doing it at a restaurant, something people like— could you imagine having to step in and manage a restaurant? There's an owner and you have to manage the restaurant. Like, you need to know something about the restaurant business, obviously.

But if you've got smart enough people around, you can just solve problems.

Well, you know, that's always the case. I mean, every company I've been with, right? And I've worked with some really great companies. Every customer that I've been with, they have talked to me about, oh, well, we're just going to hire a bunch of smart people and those smart people will take care of everything.

And I do consider myself a very smart guy. Sure. But I've also seen in these situations where they've ignored that advice. What, you know, are those just words though in that case? Are they just reading something?

They're walking up to a painting or a plaque on the wall that says our people are enablers and we hire the best people.

And then just go to, well, we're just going to do whatever?

So there's— I think people— hiring smart people is always a good choice. It's the best choice. Hire the smartest, most experienced, most capable people you can. That doesn't guarantee success, right?

The value of genius. Well, Genius doesn't equal success, right? One of the things people say is persistence. Can you persist in the problem? The other thing is some problems are unsolvable.

There are people that— my case in point is working at Northrop Grumman and having the sacrificial lamb project manager. That's where they take a perfectly good project manager who's got great experience and they shove them into a project where he's going to fail. The government customer is going to get mad and upset because they are in a no-win situation. And you shove someone in there, they're trying to succeed. They're trying to meet the parameters of success, but it's just not possible.

And so you put somebody in and I saw them do this. They put them in and then they whack them. They fire them. That's, we'll fire him and we'll put somebody else in that place.

Right? Right. That's just the game. So you better understand the whole game of what you're dealing in, what all the customers, all the stakeholders, what all the parameters are in doing things.

And again, Northrop Grumman was, I believe, excellent at delivering on things, but sometimes they were in very bad situations and they just did the very best they could in those situations.

Okay, so is that a strategy, right, from, from a company standpoint? And what I mean by that, right, is that I was talking to one of my good friends. He doesn't live here in Colorado, but he was talking about— he worked for a big major bank, and he said that when they did need to cut and reduce labor One of the things they did was they announced the labor cuts, right, in order to encourage people to leave on their own. All right, is that a strategy?

And how ethical is that? Because is your loyalty to the company or is your loyalty to the people?

So personally I've always been loyal to the people, but my job, and that's one of the pressures on middle management and leadership, they are the bridge and they have both a legal and an ethical obligation to the company and to profitability and loyalty up the chain of what is it we're trying to accomplish. If you're in a downsizing situation, look, you don't think some of the strategy Everyone's going back to the office. That's maybe— is it a strategy to downsize to get people to quit? Is it unethical? No, it's not unethical.

It's not an unreasonable request. There's actually very positive benefits to having everyone in the office. So if it causes some loss, it's meeting your objectives. What are the objectives? The objectives is we're not profitable.

We have too many people. Look, you can see it now. There's unethical ways of doing that. Let's fire all the old people because they're paid a lot.

Being one of the old people now, it's pretty— I'm particularly sensitive to that. You can't do that, right? You can't target people, but you can just have cuts of people at certain cost points. You make value judgments and people lose their jobs. It's not something you're happy about.

It's just something you need to survive for the good of the organization, which is what everyone's there is to serve the organization. You set your own— a lot of your own personal goals and objectives aside, and you put them at the service of the organization. I know in the Marine Corps that's how it was, to the point where you jump on a hand grenade, you rush a hill, you do crazy stuff. It's not because you've lost your mind, but you are very dedicated to what's behind that. In a company, it's a little less so than maybe in the Marine Corps on the battlefield.

Um, but you are there to serve that company. And again, if you don't believe in the company and what they're accomplishing and what their goals and objectives are, it is your moral obligation to get out and find something that fits you so you can be happy. Okay. Well, we're going to build on that. I mean, we're both Marines, right?

We're both Marines and I fully understand that, but I want to build on something and we're going to get into some very touchy subjects here. All right, we're going to get into some very touchy subjects. So coming up, CJ explains why magic words don't work when asking for a million dollars, why every company, even Black Hills, sucks at communication, and the exact moment that he realized that the Marine Corps leadership is actually the gold standard. You don't want to miss the final words from the COO of BHIS. One of my students, this was a couple of years ago, had called me out and said, you know, I was looking at all our instructors' profile for this bootcamp.

And a lot of us don't stay with a company very long. I mean, he said every one of their, every one of our instructors, 2, maybe 3 years into the company, and then they leave. And they said, why is that a trend? Because, you know, the industry that they were coming from, and I don't remember what it was. That's not normal.

And I told them, I said, well, part of it is that, you know, going back to an earlier comment of ours, we are gluttons for punishment. We need a challenge. We need something to change. All right. So we move on.

But a lot of it is because we don't agree with what the security culture is. They're not doing it right. Okay. However, doing it right versus paying your mortgage.

Yes. So this is where I'm putting you into the spot here of that decision.

Do you do what's right or do you pay your mortgage?

Have you heard of Maslow's hierarchy of needs? Yes, absolutely. Where's the— yeah, and I actually, I have a t-shirt with the funny part that says Wi-Fi and battery right underneath it, right? But let's talk about that with the audience. Let's talk about Maslow's for anyone that might not be that familiar with it.

At the bottom is obviously, well, I would say at the bottom is air, right? First you need oxygen, but it's food, water, shelter, living security. So that's the basic getting by physical security needs. And then you want good working conditions. And then you want better work.

Well, at the peak of Maslow's hierarchy is what's called self-actualization, which is basically you've got kind of like what we're aiming for, because I got the right balance. I'm doing the things I want. I'm doing them the right way. I do them the right amount. Everything's wonderful.

I'm achieving my highest purposes. You know, I'm working at the spiritual level now to give to others and to make the world safe for computing. That's the— that's what you've achieved, but you have to satisfy your lower level needs before you can work on the higher level needs.

So to me, when you're in the business of cybersecurity, and God knows I was, so I came in this as an air traffic controller, right? I got into tech from air traffic control. I got a job as a systems engineering and integration guy. I think we talked about this in the last podcast. Um, I was like, how— what can I do that's of value to people?

And I latched on to technology, the computer, because I'd played with the computers a little in the Marine Corps. I kind of liked them, and I latched on. I became a Macintosh specialist, and I leveraged that out until I got into cybersecurity. Your value and your security comes from your capability as a human being, as a technologist, to learn and adapt and grow. That's where your security is.

Your security isn't in a single job. And so you've got to be confident. You've got to work yourself so that you're rolling up your capabilities and you're learning and growing, that you can go do other things so that you're not tied to a place you don't want to be. But you do need to make decisions that make sure that you meet the bottom line. And I would never say you're going to compromise your integrity or anything.

You're not going to steal state secrets in order to pay your mortgage. That's not what we're demanded to do in this society, luckily. But you might have to compromise some of your higher principles and values in order to make it work, and then to, to keep in mind that you want to move someplace better. There's nothing wrong with that. So with your instructor turnover, you got to look at the factors.

There are young people in security that know that the way to make a bigger salary is to change a lot, change companies. It's a strategy. So you're going to lose those people if you're losing them because they don't believe in the mission or they don't like things. The other thing you get is when you get young people in the door is they don't have a lot of experience. Like, you may have a very good company, but they don't really know that.

How do they really know that? They haven't been other places. They haven't been someplace that was truly awful. So that can happen to any company, including Black Hills. Somebody walks in the door, They don't— they didn't know what they had.

And hey, I'm kind of bored. I'd like to move. I'd like to do something else. One of the things we try to do is allow people to— like, if you want to do something else, you've got to be entrepreneurial and figure out a way to do that. So if you've got a cyber idea you'd like to become an expert in, let's talk about it.

Let's see if we can move you in that direction. Not always possible. Like, you can see why someone would come to BHIS, be a super smart person, right, and say You know what, but I'd really like to work at Google. I really like to work at Microsoft. I really like to, you know, that's just what they want.

There's nothing wrong with that. Their higher aspiration, what they'd like to achieve or things they'd like to put on their resume, that's going to cause change. When you're losing people because they're just disgruntled, dissatisfied, they don't like the place. You got to do the analysis and figure out what is that and can we change it? Every culture can improve.

BHIS is not nirvana of culture. We need to be better. We talk about communication. We suck at communication. Everyone sucks at communication.

Like, so you need to be better. But part of that thing is people thinking that you can be at the pinnacle and like, I'm going to go to a company. I did this when I got out of the Marine Corps. I'm going to go to a company. I've been reading In Search of Excellence by Tom Peters.

I was reading that when I was getting ready to get out of the Marine Corps. I'm like, I'm sick of the Corps. I'm going to go someplace where these corporations that know what they have, 3M and Xerox and all these, I'm going to go someplace where they know about about leadership. Like, oh my God, I had no idea. I didn't know how— I was in the Marine Corps.

I didn't know how great the Marine Corps leadership was. It took me years to figure that out. When you're the low level, you're kind of like, you know how much stupid stuff we do and the leaders are all messed up and they just— yeah, that's what you think because you think you know it all. As you get older, you figure out that you don't. Okay.

How are you doing on time right now? Are you okay with time right now? Yeah. Okay. All right.

I have one question for you. It's another loaded question, right? Okay. So we're gonna put you in a situation here, right? I am a, you know, I'm currently serving as a principal security engineer.

So I'm gonna go to CJ. I work for Black Hills. And I have this great idea to build our own SOC, right? I want to build our own SOC, CJ. You've said no a couple times before, right?

Because for, you know, various reasons. Okay.

Now, actually, let me change the situation. I'm gonna go to John to do this. Okay. All right. So I'm gonna ask your advice, CJ.

How do I convince John to do this? What do— what is those magic words? What needs to be in my proposal to convince John to say, yes, I will give you $1 million, Frank, to go build a SOC, right, and create this new function of our company, right? Or we can even shift this, okay, and say Well, I'm going to go build my own company now, right, for managed SOC or whatever, right? How would I convince CJ to be an investor to me?

We can go either way with this, but I think it's along the same lines. What's that secret sauce? Well, you know, the magic word is please. So that's okay. You're looking for magic words.

You just say, please fund me. But okay, well, CJ, can I please have $1 million? No. Well, that wasn't what I was expecting. Magic words don't work, Frank.

You have to go to the Tolkien world to get that. For Black Hills, in our case, to convince investors, you need to pitch a case and you better have research and your ideas better ring true and you'll convince people to invest. It happens every day, all the time. Now the problem is most people you get— so if you wanted to build like the Wright brothers, you want to build an airplane, right? They built the model, then they built one and they flew it, and that's how they got off the ground, pun intended.

Um, but for Black Hills, when we go into stuff, we do it what we call crawl, walk, run. Small experiments. Can you show me? Can you piece these things together and pitch a concept? And at some point we get together enough evidence that we're like, yeah, we'll give a shot.

And it's never just like committing to $1 million. It's like, for us, it was like, can we fund 3 people's salaries? And can we start doing this for, you know, get an operating concept out there, see if we can get a customer in the door and get the customer in the door. You've got like 4 or 5 people working on it. It's like, well, if you want to get any bigger and do any more, we're going to have to get more customers.

You want to hire 2 more people or John says, yeah, I can. I guess we have enough I can afford to front you, like, because we operate at a loss. That happens, but you've got to know what those, you know, those losses have to be manageable. So that has to do with operating revenue, all those things. So again, for us, it was a little more organic.

It's not so planned out, like how much can we afford to lose on that? We don't do any of that big MBA, you know, accountant planning spreadsheets. We just start down the path and see if we can get it off the ground. As we say, building the airplane while you're flying it is a lot of fun. Okay, let me shift that because that's actually not the answer I wanted, right?

Or at least, you know, I was trying to goad you for. We're gonna pull you back to 10 years, to 11 years ago, right? And I'm gonna say we're both at Northrop Grumman. I have— CJ, I have this great idea for a SOC, right? What do I have to do to convince your boss, who happens to be, let's say, the CEO or something like that, to let me have this money?

What do I have to have? What's some of the minimum things? You know, I go and I Google how to build a SOC, and here's my revenue, and you're gonna— you know, what makes you say and not laugh at me and try to take me a little bit seriously? It's all numbers. It's all numbers.

You have to show what the competitors are doing, how your offering is the same, how we're certain that you can deliver what you're saying you can. That's a huge part of it. Like, what's your demonstrated capability? But it would be market numbers and the price point. And what's the data you have that supports that you're going to be able to deliver the service at your price point?

Point. It is all MBA math when you're doing it at that level. You know, to get that, the emotional hook, like how would Apple— how did Apple get off the ground? No one came and gave them a million dollars. They worked out of a garage.

Hewlett-Packard did as well. We were at Palo Alto. I saw a model of the garage where they started. They crawl, walked, run. They had to demonstrate their capability and build it over decades.

Very few things just get a bunch of money thrown. Now, during the tech boom in the '90s, there was some wild money being thrown around, and today maybe on AI occasionally there's some crazy money thrown around for things in different software pieces. It happens in cyber all the time, cyber tools, EDR stuff that gets purchased and done, but you've got to be able to demonstrate a capability that people You got to believe pretty hard to hand out millions of dollars. So how do you convince people? How do you make them confident?

You got to show them evidence. Okay, so confidence, research, market value, math, right? Is there anything else though? I mean, is it just that simple that I can prove the numbers and all of a sudden again CJ is going to give me a million dollars to build this? You've got a compelling problem that you're solving and something is unique about your solution.

Okay. Something that makes it stand out. Can we do anything but, okay, again, I'm gonna put you on the spot here, right? One of the things I heard John say is that we're not building anything unique here. We're not the flashiest tech.

We're not the best, coolest thing. But we do it well and we do it to the service. I mean, obviously BHIS is doing something right with the way that it grows. So again, maybe we're getting into something you don't want to talk about here, right? Secrets, really don't.

So, okay, for us, so people say, what's your secret sauce? And the jive-ass answer is our people. But the answer, and it's one of our sales stories, is Look, technology, it's like medicine, right? Medicine is complex, huge volume of science, all this data and science. But when it gets as complex as it gets in medicine, in cybersecurity, there's an art to it, right?

There's an art in how you put those things together. That's the artistry. It's a little bit intangible. And so we say we hire better artists, and all I can show you is our results. That we have our return customers.

This is how I sell our services in pen testing. In SOC, it's literally our approach is a little bit different. Ours is a little bit different, and I think we do it at a competitive price point, and all that's calculated and figured out. Um, so the angle and how you sell any given thing is based again on your problem set and how— what's your approach and how do you sell it. It's all so unique.

Like every single thing. How can I sell a hamburger? Right? Like McDonald's has been in the hamburger business forever, but Smashburger comes out and, and they're making good money. Well, they're doing it a little bit different.

And, but they're not gonna take McDonald's down, right? They're not. I mean, but that's not the goal. See, that's one of the things people think in winning in business. Conan, I'm gonna crush my enemies and drive them before me.

Somebody winning in business doesn't mean everyone else loses. It means that consumers, you know, consumer spending can increase, and God knows in cybersecurity it certainly has. You're not putting other people out of business. That's not the goal. The goal is to produce an offering that appeals to people at a price point, and that's, again, capitalism is maximally effective at providing lots and lots of different solutions for lots of people And all of those people win.

All the consumers win and the companies win. So you've got to figure out, I mean, that was one of the things out of that book, In Search of Excellence, that you had to glom onto. It said, find a problem that motivates you and that you can come up with a great solution to. That's how you get rich, or that's just how you pay your mortgage. You're solving, as an engineer, you're solving your company's problems.

Frank is the perfect solution to the security engineering problem. He just brings so much. Yeah, he messes up once in a while. That's part of the costs. But the benefit side is such an upside.

And that's what you've got to focus on individually, as a team, and as companies. That's the thing is like, what's our solution? Action and solution-oriented.

Well, that brings us to the end of the podcast. I can't thank CJ enough for sitting down with me today. And I have a huge shout out to the BlackHill Information Security security team for letting us peek behind the curtain of one of the most unique cultures in the industry. We talked about quite a few things, including the soul of the business. While turning down a multi-million dollar buyout isn't just about money, it's about refusing to be assimilated.

The molecular change of growth, understanding why we can't step in the same river twice, and how every new person we bring into his team fundamentally changes the structure of who we are. We hopefully now understand why the easy button is a myth and got some good advice about career security. Again, my name is Frank. I am the host for the interview portion of this podcast. I'm also the president of the Denver OWASP chapter and a university professor.

During the day, I work in risk management at a large ISP And I hope you tune in for our next podcast. Have a great day, have a great life, and hope to see you soon. For appearances, please check out snowfroc.com. That's S-N-O-W-F-R-O-C. That is the Denver and Boulder OWASP chapters in our annual conference coming in April 16th and 17th of 2026. Our keynote is going to be Tanya Janka with She Hacked Purple, very known leader in the world of application security.

I also have some personal appearances coming up with RMISC, BSides Tampa, and of course you can find me here on this podcast. If you need to follow me, I'm on Frank Victory on LinkedIn, and I do have my own website. Professor-Frank.com.

Learn more about the Colorado security scene at Colorado-Security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado equals security. Reach out to Alex and Robb by emailing info@Colorado-Security.com.

Until next time, remember. Remember, Colorado equals security.

Back to all episodes