Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Hello and welcome. Oh God, I instantly punched my microphone, Chelsea. I didn't hear that.
Good. What a better way to start. All right, welcome to episode 285 of the Colorado Equals Security Podcast. My name is Joe McCallister, and I may sound new, I may sound familiar to some of you, but, uh, we have sufficiently procured the podcast from Alex and Robb. I say that, but actually it was a graceful handover.
We thank Alex and Robb for their years, 9 full years of incredible programming and work on this podcast, uh, but we are happy to also usher in the new era, myself being Joe McCallister and I am a security professional that's been in the Colorado area for a number of years. I started out on the IT help desk, moved up to a road warrior providing end-user services, and then had a good friend of mine here in the Colorado security community say, you should do security, you're already doing it. And thanks to that guy, who knows who he is in the chats, I got my CISM. I worked at an MSP for a long time, did some consulting work, and now do enterprise cybersecurity and just took over some application security, basically the whole stack. So I am sufficiently what I'd like to call experienced and also like to admit I don't know nearly enough, but I am more excited to introduce and hear a little bit more about my co-host Chelsea Weiss.
Thank you, Joe, very much. Everyone, hello, nice to see and hear all of you again. As Joe mentioned earlier, let us do give a round of applause to both Alex and Robb for the phenomenal legacy that they have built with this podcast. And thank you for handing it over and trusting it with us. So to build a little bit more about who on earth am I, I grew up here in Colorado, also a security professional, spent some time in the New England area.
Go Boston teams! But I've been back since 2015. I've really spent my entire career working across product security, fraud, and intelligence. Typically, we see those domains treated as separate disciplines, but they're really just the same way of looking— excuse me, they're really just different ways of seeing the same problem: how systems get abused. And when you connect the dots of product security, fraud, and intelligence, you can see risks earlier.
So at the end of the day, or to put it more simply, I am Chelsea Weiss, and I like making fraudsters and threat actors have bad days. Looking forward to what we learn and grow together. Back to you, Joe. I love it, but I did not realize that in our episode 0 together we were immediately going to have an issue because I am a New York Yankees fan. Oh shoot.
Yes, we'll have to take that out back. Yeah, I was gonna say we've had a good run. All right, thanks everybody. Podcast. Yeah, nice knowing you.
Oh goodness. All right, well, I guess we will have to, uh, see past our differences there. Um, Just quick housekeeping notes. Remember to visit colorado-security.com to do multiple things, including join the vibrant Slack community, join the mailing list, as well as head over to your favorite podcast subscription platforms, be that Spotify, be that Apple Podcasts. Rate, subscribe, like it, tell a friend.
Make sure that you are spreading the good word of what this podcast is. And while we're speaking about that, let's make sure we're crystal clear about what is changing, which is not a whole lot except the names and the, the voices on the, the show. Chelsea and I are committed to continuing the mission, which is highlighting Colorado security professionals and the landscape of Colorado and how that relates to the cybersecurity profession, uh, across our great state, and what kind of national news might have local consequences, repercussions, or Um, I don't know if Chelsea, you have any other color you want to add there, but feel free. No, once again, yeah, the only things I would add is this is a great opportunity for us to continue to learn and grow together as a Colorado community. It's small and it is very well interconnected.
And thanks again to Alex and Robb for helping it, helping it stay that way. And we want to continue growing that. Absolutely. Well, with that, let's dive right into the news for this, your April show. Absolutely.
We will start off with our first article of the day, Name the Train. Colorado Front Range rail leaders are asking the public to vote on finalist names. So we have a Front Range passenger rail project that's going to connect different cities from Front Range, from Fort Collins to Trinidad, and the exciting part is we the public are being asked to help name that train. There's 4 finalist options. First one, Colorado Connector, AKA CoCo.
Second, Colorado Ranger. Third, RangeLink. And fourth, FRED, Front Range Express Destinations. Joe, what's the front runner for you? Uh, clearly it's FRED.
I really like CoCo. Don't get me wrong. Uh, however, there's something about getting on the Fred, uh, that just sounds right. It feels like home. You know when you walk in a house, if you've toured a home to buy a house or, or a venue for anything, and you just say, yeah, this is it?
Uh, as soon as I saw Fred, I got that feeling. How about you? I also do like Fred. I like Fred and I like Colorado Ranger. I think that's pretty strong.
So we will see. I will be happy campers with any of those. And I'm, I'm excited. Like, I don't know if, if you and, you know, our folks listening have had the opportunity continue to explore in those specific types of areas, but the Front Range cities are absolutely beautiful. Fort Collins, absolutely love.
So this is an exciting opportunity for those cities to get anywhere between $1.5 million and $4 million annually for local development tied to the rail. So exciting opportunity for there. Of course, You know, there's going to be a 0.5% sales potential sales increase tax to fund the project, but we will see how that goes.
Absolutely awesome. Well, with that, let's move on to our next story, which is the, uh, a bit of an update around the Broncos' new stadium, or maybe new Reno Stadium. Who knows? There seems to be quite a bit of movement, discussion, uh, and a real area of passion for a lot of the fans here in Denver as well as the, the entire state of Colorado. Um, I don't know if you have had the, the chance to look over kind of the full drama behind this, but the story itself is, uh, highlights a couple of key things.
Uh, they're looking at a retractable roof stadium. Uh, they're looking at the Burnham Yard area, but I've also heard some interesting concepts about, uh, further east out near the airport. And there is a lot of— of course, this becomes a kind of political discussion around local, uh, city councils, mayors, and different, uh, folks vying for or potentially discussing, uh, the challenges that come with, uh, building a new stadium. Now, when I saw the plans, uh, for Burnham Yard at first and hearing a lot, a lot more about making it, uh, less parking Uh, just blacktop and a lot more walkable, a lot more entertaining, uh, venue. I was actually extremely interested, um, in what that means for the community, especially in, in the areas that we're talking about here.
Um, I think my first question for you, Chelsea, is do we need a retractable roof? Do we need a dome? I am in favor of that only because it brings so many different opportunities for different types of, of playing, different types of people being able to attend. I am— I have small children and I'd like to be able to take them to games when it's not absolutely freezing outside, even though that is a phenomenal Colorado pastime. I would love the opportunity to be able to have a new and modernized stadium to be able to watch that, and the retractable roof is key.
But at the end of the day, Joe, I will just be a happy camper if they continue to allow Billy's Hot Dogs and Billy's Sausages to be in the stadium. So as long as they have something that will, that will satiate my palate from sausages, I'd absolutely love that. The other piece though that I loved about this article, and when you think about it, like, this is, this is really similar to what the LA Rams did with SoFi Stadium. So like rather than doing a traditional stadium build, they were very smart with how they approached it from a real estate and ecosystem strategy. Like, it's, it's not just a sports investment.
They're also looking to have an entertainment district and build neighborhoods here. Like, that's the Burnham Yard. Like, that's 150 acres in a major city. So kudos to them. I'm excited to see where this goes.
Agreed, and same here. I think Uh, for, for my 2 cents, the, the retractable roof is an interesting concept because it does lend itself to year-round activities. It doesn't matter what the weather is doing. And so not, you know, we're talking football, but just in a couple of weeks we've got, uh, Inter Miami coming with Messi. Uh, we could have some more interesting things happening if we have a winter, uh, and actually get snow.
Uh, it seems like this past year it didn't matter if we had a retractable roof or not. You could still go out in the 70-degree February day and, and enjoy things. But I don't think we can count on that going forward. The other interesting thing is going to always be, especially with these new stadiums, the contention around the financing. I know that's kind of discussed in the article itself, and, uh, there's, uh, not much public appetite for the taxpayer-funded stadiums, which, uh, I find myself on the side of as well, especially with the ownership group that we have being one of the, the wealthiest in, in the league.
Uh, I would love to see kind of a creative solution there as opposed to our taxes going up yet again. Yes, you and me both. We will have to see how that plays out, and we'll use that as a transition opportunity to number 3. So along the same sports theme, 3rd article of the day today talks about a golf-themed coworking called Clubhouse Work and Golf is expanding in Greenwood Village, and they're eyeing Cherry Creek Clubhouse for work and golf. So essentially, this is a coworking community built around Golf.
So, um, I don't know if some of you guys have experienced this, but it's big beautiful offices and they have awesome golf simulators. This place has blown up in a healthy way and they've hit full capacity over the past year. They're looking to add 30 more private offices in DTC plus some more golf simulators and meeting rooms. And then in addition to that, they're looking at the, the larger location going to the, the Cherry Creek area, and that one will be about 23 square feet and probably be about another 65 offices. Joe, tell me, if you were working there all day, every day, how productive would you be?
Not. Not is the answer. It's funny because I'm not necessarily— I don't consider myself a golfer. I have, of course, as I kind of climbed the ladder, I find myself getting more invitations and more of those vendor invites saying, I'll send you a putter if you take 15 minutes to talk to me, uh, and have to tell those folks it's, it's not necessarily my bag. However, I've had some great times, uh, at, you know, Topgolf and, and even at, at some, some clubs just getting a bite to eat.
So it is, it's very interesting. I think this entire space is very interesting of, uh, what do they call it, like a lifestyle co-working, uh, space that's not just, you know, beautifully appointed. Uh, we do have some incredible co-working spaces, uh, in, in Denver and in Colorado at large. If you've been down to the Milk Market, there's a beautiful one down there as well. But it also kind of interested me, this story in general, just because having a kind of hybrid arrangement, I get to go to a beautiful office 3 days a week with my current employer.
But if I were working from home, I know I would want some sort of interaction, some sort of social space to even just be in the presence of other people, even if I'm not necessarily, you know, doing 9 holes with them over lunch. Um, but so the day pass option that they kind of chat about in the story at $75 a day wouldn't be— you know, adds up quickly. And also, uh, kind of for my mental health of being what I like to put myself as, right in the middle of that extrovert-introvert. I have a social battery that drains fairly quickly, but I do love being around and with people. So for $75 a day, uh, I could probably satiate that need.
Yes, absolutely. I would say my productivity levels would be healthy, but also I don't know if you want me in competitive scenarios around customers and clients. There's a reason I'm not the most successful when it comes to sales. So I, um, probably wouldn't do that because I just like to beat people at the end of the day. But going back to what you said earlier, kind of about, about it like being lifestyle-driven.
I do agree with that statement, and I like the shift in coworking demand in regards to it being experience-driven spaces versus desks. And this is an example of a very healthy client-facing environment rather than like, you know, people that just work internally on a regular basis. So, you know, probably not the best for me all day, every day, but absolutely something that I would love to experience to just build rapport with the people that I work with with and/or give them an opportunity to kind of, you know, get our stresses out in a healthy manner. Absolutely. I hear you on that one.
All right. Well, in some other interesting moves— or excuse me, moves and news. This is a bit of a pivot. So bear with me as my segue is not going to be as artful as Chelsea's. But we're going to talk a little bit about a new space company, New Earth Space.
Company here in Colorado founded by some SpaceX, uh, propulsion engineers named Tom, uh, I'll say Mueller, but I'm hoping to get corrected so we can get that right. But, uh, Impulse Space, um, is blowing up in the best of ways when we're talking about rockets— good ways. We're talking hockey stick, uh, growth, not, um, fire. But in, um, In March here, Impulse just opened a new facility, 20,000 square feet. They're doubling their workforce, uh, and perhaps one of the biggest pieces of news, uh, for this company is being selected as a key player in the Golden Dome missile defense shield, uh, initiative that has come down from the government, uh, as well as a few other projects that are going forward— the Mars lander, Project Helios, and so forth.
So some really exciting stuff coming out of the space sector in Colorado. And I think we— Aerospace Alley is the name referred to in the story. This on top of just a quick also call out for a big conference that happens in April that I wasn't terribly aware of because it's not my industry, but the Space Symposium happening in Colorado Springs in April. I know a couple of friends are heading down to. I'm very excited for.
And I know, Chelsea, you've got a kind of soft soft spot for, um, space and defense. So I'd love to just kind of get your, your feelings about this stuff. Yeah, we are, um, I don't remember what the term was you just said it, Aerospace Alley or something like that, but Colorado really is an aerospace manufacturing hub. So I'm super excited about this opportunity of Impulse Space building further out here, um, because we have such really great healthy talent. And what Impulse does specifically is their focus is on like space mobility, so moving the payload after launch.
And this is actually one of those like growing, very high-value niche spaces in, in space economy. And, um, what we're seeing, because this is an area that is expanding in, in multiple different veins, a lot of companies are shifting from, you know, launch, which is what we typically think about when we think about aerospace and defense satellites, to what happens after orbit. And, you know, this is kind of what Impulse does, and this is where you're seeing a lot of new money and innovation growing, which is why, you know, Impulse, as you said, you know, it's led by Tom Mueller. He's one of SpaceX's first employees. They are very well funded, like $300 million on their Series C. So they're, they're in their scaling phase, and I'm excited to see how this continues to grow for us.
Absolutely. And I'll do a real-time correction as I, uh, was reading through the rest of the story there, that Impulse is actually headquartered in Redondo Beach, but their facility, that 20,000-square-foot facility, is located up in Louisville. Yes, absolutely. Well, thank you, Joe. Moving on to number 5 of the day.
Colorado business leaders are still negative about the future economy, though less so than last year. So if we— moral of the story, if we look at Business Confidence Index, it was at 41.9 for this past year, which is below the neutral 50. Slightly positive. You know, it's an additional 10 points versus last year. So us leaders are getting used to operating in uncertainty, and this is what our new baseline looks like.
The article talks about the top concerns are really, you know, geopolitical instability. So war, tariffs, federal changes, the soft signals of the economy, slow— slowing US growth rate, shrinking labor force. Of course, there was a big section talking about AI and the workforce shift being a big theme. 40% of leaders in this article are saying that AI is already actively transforming jobs. No surprise there.
And then 69%, in addition to that, are reporting productivity gains from AI. I am— my big takeaway from this article was, you know, companies are now focusing more on efficiency rather than hiring. So what used to be, you know, a conversation on how are we growing in regards to hiring. It's now how is our productivity growth happening. So it's, it's less negative, but it doesn't necessarily mean healthy.
It just means we're adjusting. Do you align with any of this, Joe? I— this is a super interesting article because I've been spending a lot of time thinking about how to think about things differently. I think that's always, you know, a healthy thing to do in the security space and tech and, and so forth. But this type of, this report or this, excuse me, article in particular focuses on how many disruptions are happening all at once.
We've got, and some of them are downstream, right? The AI disruption is a huge part of this article, and that's kind of where I found the most interesting and things that I kind of identified with and echo in some of my discussions with my teams and other leaders about thinking about things differently. And Richard, I'm going to say I am terrible with names, so I'm sorry, Mr. Wobkind, who's the Associate Dean for Business and Government Relations at CU Boulder. And he kind of mentions that we think about the economy in a different manner. Maybe it's not just GDP or employment growth, which is the indicators we've typically looked at.
Instead, as you said, Chelsea, we're We're looking at productivity gains. We're looking at, can we do— can we execute on a phrase that unfortunately us security professionals are very used to hearing, doing a lot more with a lot less? And what does that mean for the future of the industries that we operate in? And there's a whole bunch of interesting things happening with AI. You know, if there's a quote earlier in the article about if we were just talking about, say, a war with with Iran or another sort of international geopolitical destabilization event, it might be more drastic.
Could we see a larger dip? But we are seeing that also juxtaposed with, you know, if I wanted to go buy RAM for my gaming computer, it is 3 times, 2 or 3 times the cost it was a couple years ago. So there's a whole bunch that's just really interesting about the times. Being a millennial and hearing unprecedented times yet again is, Sigh-worthy and also just kind of the, the, the present. No surprise.
Yeah, yes, exactly. No surprise. Well, I think, Joe, it's time for our security articles of the day. I agree. And the, the stuff that we get to cover from the Red Canary blog, can I just say, like, I'm sure, uh, I've heard Alex and Robb sing the praises of this blog, but yet again, the Red Canary Threat Detection Blog and Trey Wilkins over there put out an incredible article called Moving Up the Assembly Line: Exposing Malicious Code in Browser Extensions.
And it goes into some incredible detail, as always, that starts fairly high level and really gets down to how you can get a little bit more granular and identify script modifications, checking out signatures and domain comparisons. It's, it's something for the tech heads out there.
The, the biggest thing I took away is actually in the closing thoughts where Trey says high-fidelity detection of potentially malicious browser extension updates is a practical reality. And that actually made me feel great compared to where I've felt the past couple of weeks with all of the npm news, all of Team PCP out there, the trivia stuff. Chill Kelsey, how are you doing? I know I'm talking about an article in particular, but how, how kind of is your brain space when we talk about the nature of these threats and detecting these threats in the wild? Yeah, this is one of those ones where it's, it's typically an afterthought.
So when we as security professionals think about our attack surfaces, Normally browser extensions are one that does not come to top of mind. And so I would really simplify that by saying like browser extensions are a massive undermonitored attack surface. But for those of us organizations that are, are much larger, you can have thousands installed and all thousands of those browser extensions have auto-update capabilities and very broad permissions. And going back to something that you said, Joe, like there have been a lot of real-world recent compromises that show this is an active supply chain vector that we need to be thinking about when we talk about, you know, what is our risk to our business. One of the core problems in this article, but also in how we look at, you know, vulnerability management and our ATT&CK services, a lot of the conversations the industry has been talking around is runtime telemetry.
This ATT&CK surface, Joe, is a really good example of where that does not apply because if you're looking at runtime telemetry, that's too late. If you're looking at public reporting for this ATT&CK surface for browser extensions, that's way, way too late. So, you know, here this article, Trey's talking about using Assemblyline, which is this, you know, open source solution to be able to compare the diff. So comparing old versus new extension versions and, you know, providing any real-world validation on what could be a problem to you. So it's funny, after reading this one, I kind of had to think in my head, how on earth do we tackle this?
Luckily, we do have a solution. It's not assembly line, but, you know, it's not something that I think about all day, every day. Agreed. And I think what really struck me as well is the— when I read things like the red flags in an update that Trey calls out, which are things like permission changes, network domain, changes, uh, increased entropy. It, it reminds me of the days when I was doing threat hunting, when I was doing incident response on the, on the front lines, of the, the problems that I think a lot of us are solving are not so different than 5, 10, 15 years ago.
There are new— there are absolutely new threats, there are absolutely new vectors, uh, but we're looking for similar behaviors, we're looking for similar things. It's just a matter of how thin is our peanut butter spread right now?
That's a good phrase. I'm going to start using that. You're welcome. No trademark on that one yet. Yes.
All right. Transitioning again to our 7th article of the day, which is— I'm very excited to talk about because this is something that I've spent the past year and a half doing. But this one is dedicated to continuous threat exposure management. What is it and why do you need it? So for those of you not familiar with continuous threat exposure management, which, you know, the acronym which we have many of here in the community is CTEM, and CTEM is something that shifts your vulnerability management strategy from reactive to being continuous and very attacker-focused risk reduction.
It does a really great job of connecting what exists what exposed, what matters, and what actually gets fixed. For like most of us, that matters because our typical company's attack surfaces have been exploding just with all the various vectors that we've been talking about in this podcast and what, what Alex and Robb have talked about in previous podcasts. But a lot of us also have a ridiculous amount of tools with no single source of truth, and our traditional vulnerability management programs are very noisy. And they're not aligned to real attack paths. So in this article, and I'll just give you guys a high level, it really talks about the 5 steps in order to get a healthy continuous threat exposure management program.
The first one, you know, scoping— what do we actually own and what are we exposing? Second one, discovery— so what is actually wrong? Third one, very important, prioritization— does it actually matter? Fourth Validation. Is this real and is it actually safe for us to fix?
And then the 5th one, mobility. Can we actually fix it? How do you guys solve vulnerability management, Joe, at your current place or in the past? And does that align with CTEM? Are you guys going through an evolution journey now?
The answer to the question of how we solve vulnerability management is essentially by doing our best. It's— we, we try. It is one of those, I think, those terms that whenever you start to talk about it, it becomes this giant gray cloud in people's heads. And I love what Jared here at Optiv has put together because I am a framework and lifecycle type of person, very similar. He's putting terms to what, similar terms to the way that we've talked about lifecycles as well.
We talk about the prerequisites and the dependencies, right? Like, what do we have? What are we responsible for? How are we going to actually go get things done is also a very valid question to think about. And I also think about the alternatives to what Jared's talking about here, which is intelligence-driven management of the solution.
And what is the alternative, right? It's compliance checkbox. It's potentially reactive, and I think that's where a lot of us come from, is we figure out, oh, there's too many things, it's popping off like crazy, I'm just gonna have to figure this out. But you can't get ahead of it unless you dedicate the time and have resources like this to put to paper the concepts that are in your head. I need to figure out what I have.
You did a great job of defining those 5 steps in the cycle of CTEM that are the questions that people are asking. What do I have? How do I find it? What's important? What matters?
And this is what's extremely useful. And this graphic being up top is so great, I may have to steal it for a deck or 2 here. Yeah, and I expect that visual to be going around with multiple organizations because the other piece CTEM is really just vulnerability management 2.0, and you called it out directly. We should have been doing this threat-informed, understanding what the actual threats are in advance. The power of having a threat-informed program, not just from a vulnerability management perspective, but from everything else we do, is really powerful.
And this is a soapbox that I'd love to stand on another time because today is not that day. But in short, Shift left. When we look at product security and vulnerability management and application security, like shift left was great for a time, but it wasn't meant— it wasn't meant to grow in the way that it did. So high level, one of the outcomes of shift left was it brought in a crap ton of scanners. And it's healthy because we no longer have a visibility problem.
But what CTMS helps solve is the decision problem, because we have all those scanners that gives us all of those vulnerabilities. But now it's a matter of What do we actually fix? So I will, you know, punctuate this article only by saying the health of having a CTEM or vulnerability management 2.0 program, it needs to drive remediation just like, you know, a healthy threat intelligence program needs to have actionable outcome. With CTEM, if you don't have a fix, then it's a failure. Take that out.
Just put that out as the soundbite. That was beautiful. Thank you. And with that, we'll go on to our next story from Zvelo. I will always probably struggle with that one as well.
I'm pretty sure there's only one way to say it unless we're using accents on the E, but I doubt that. This article from Zvelo is about the security intelligence supply chain advancing toward AI application. Risk intelligence. And I like this because again, I've been spending what I'd like to think is far more time than is necessary, but it is one of those new threats we talked about, new vectors that I think everybody has to kind of consider. And with that comes some new lines of thinking as we get more AI-enabled SaaS applications, which spoiler alert is just about every single one.
They introduced an interesting an execution layer to what is the supply chain of software. And that execution layer is where those agents get to go out and perform actions. They're doing things, and those agents can operate with, you know, delegated privileges. That's one of my favorite things to go look for is, are those privileges greater than what the user typically has? Are we getting privilege escalation as a service with some of these?
And what Zavelo as an organization in their blog here is trying to get across is that the security intelligence supply chain for SaaS needs to be considered not just an end product. We can't just go out there and say that the Workdays, the ServiceNows, the Monday.coms are just the end product. We need to consider an entire lifecycle and consider what that means for managing those risks. Again, we mentioned a few of the supply chain compromises and campaigns happening today, and Svelo calling out what at the new challenges that us as leaders and professionals are faced with in what is this brave new world of execution paths for AI risk. Chelsea, how are you thinking about this Wild West of this frontier that we're in?
Great question. Haven't really nailed that down. And if anyone has any solutions directly in regards to this evolving navigating waters, do let me know. But at the end of the day, I took this as, you know, we were securing identities, and now we need to secure behavior. And a lot of us talk about how AI is introducing a lot more risk.
Well, of course it is, but it's also changing how risk is created and then propagated. So that's kind of the key piece that I've been tying back to, is not only looking at that from a threat surface perspective, but looking at how it further propagates. That has been kind of a favorite word that I have been using with my team when we talk about what our AI does for us. And, you know, punctuating what you had said earlier, Joe, like takeaway, security tools need to understand what your app can do. The capability-based security is going to be our new baseline moving forward.
100%. I think what's, what's interesting is that conversation between identity and behavior. I've been, you know, I went to RSA a couple weeks ago, and I think the, the interesting conversations I kept having were we And with these AI execution layers and processes that they're able to go just do, a lot of things are starting to look a lot more like insider risk instead of a malicious actor, a sophisticated attack that follows the ATT&CK frameworks, right? We're now looking at like, wait, why is this person doing this thing that they shouldn't necessarily be doing? Or how did they get permissions to that?
And so we have to change what our brains and what our systems therefore are also keying in on for signals. It's— it is. I think for me what helps is the bourbon. The bourbon. Absolutely.
Yes. Especially early in the morning. Do not follow my advice. Quickly moving on to the 9th article of the day. This one was from Anthropic.
Labor Market Impacts of AI: A New Measure and Early Evidence. So this one was a beast of a report. Highly recommend it for folks that enjoy going through reports. They did a really good job of data visualization and helping share a little bit more information about the specific scope that they looked at and what that means. But the biggest callouts of this report were essentially a new metric has been introduced, and it's called observed exposure, which is essentially what AI can do versus what it's actually doing at work because the reality check for a lot of us is that AI is way below its theoretical capability that it has today.
There are, of course, you know, jobs with higher AI exposure and they're projected to grow slightly slower but not disappear completely. Interestingly enough, this report did say that there's no real increase in unemployment tied to AI yet. I'm not 100% in line with that. And Joe, I want to get your take on that in a second. But some of the key indicators and early signals that it did talk about were how, you know, younger workers are getting hired less into AI-exposed roles.
And most of those exposed roles are actually, you know, the white-collar, high-paid, more educated roles, not the blue-collar roles like most people expected. Biggest takeaway, you know, that I have from this report from Anthropic is the AI impact is gradual. It's not a shock event. Don't necessarily agree with that. Joe, tell me your thoughts.
I, I'm right there with you. I don't agree that it's not a shock event. I think we're seeing the shock, especially with some news. I mean, there's probably some delta between what is attributed to AI, uh, Oracle's layoffs, right? It's 30,000 jobs cut and Part of it has got to be from something else but be attributed.
So I think there's always the attribution problem in security, in what is my industry, advertising. Attribution is always hard, no matter what. It is just a hard concept to really understand. However, I disagree that there has been little to no impact so far. What I actually really enjoyed about this, I'm a, you know, I'm, I'm a crayon drawing kind, kind of person.
And so the figures were super interesting to me. I really tore apart the theoretical capability and observed usage by occupational category figure, Figure 2 in the article. If you get a chance to go check that out, it has observed coverage of AI, essentially occupations, and then theoretical coverage. And what is most fascinating to me is The acceleration in certain— it's a spider chart, right? So it kind of goes out from the center.
The acceleration in computer and math and business and finance of the current observed and where the limit of that is, which is essentially almost 90% of those occupations can be covered according to this graph. Management's also up there, which I think some of us may know, but I'm also interested in some of the other things that are at near zero today but have a high high-capability kind of theoretical coverage. So like architecture and engineering at 85-ish percent. I don't know that I see it today. Again, that it is still a fairly nascent technology.
We're still in the early days, but it is an interesting kind of— and social services being around 50%, very, very interesting. However, if you are in transportation or grounds maintenance is the most safe of the occupations on the graph. So if anything, we've got backups, Chelsea. We do have backups. I need to get a couple more degrees in order to be able to support that long term.
But, um, I, I want to see how this grows over the next 3 months. Like, once again, when this report came out, I, I think we can all agree it may not be 100% accurate based off of what, you know, the pressure that we're all feeling and/or, you know, As you had mentioned Oracle and the 30,000 layoffs directly related to AI earlier, we'll have to kind of see how this one expands and I'll leave it at that. Agreed. Yep, it will be an interesting future. Quickly on to our last story of the day, which is from the Optiv blog and is an article about the top 5 signs your identity program isn't ready for 2026.
We can run through these really quickly because I think Just speaking selfishly, I am looking at these and saying, oh, oh, oh, oh, okay. So we talked a little bit about some of the numbers, but I'll run through them really quickly. Your identity ecosystem has outgrown your governance model. Manual provisioning and access workflows remain the norm. Lack of clearly defined roles, ownership, and executive alignment.
Audit findings are recurring or getting worse. You can't keep pace with non-human identities is number 5. And I keyed in on that last one that has been something I saw on the floor quite a bit at RSA is identity identifying those identities and kind of like I hinted at earlier, the being able to tag what is insider risk versus what's this identity doing. And there's a whole bunch of stuff. And I, as a leader, feel somewhat lost in the realm of NHIs these days, but I don't know how you're kind of feeling about this checklist.
My prediction is that most of us listening to or in this industry, listening to this show or in this industry here in Colorado can probably say, see themselves in one or two of these. Yeah, I, I can absolutely agree with and align on the fact that most of our environments are an absolute mess of both human and non-human identities across a bunch of disconnected systems with less than a clean source of truth. And this one like really had me thinking, like, it's interesting to see how the identity industry has changed, and there's There's— I've worked at a myriad of different companies in the past 10 years, and each of them have treated identities differently. Some were really healthy and they treated them like critical infrastructure, and there were other organizations that I worked for that they treated identities just like another control function. And the latter, those are the orgs that are going to get their behinds burned in 2026 if they continue to treat identity and access management as back-office administration.
100%, totally agree. A few, a couple years ago, I think maybe one or two, I heard, you know, identity and browser, that's where you really need to spend your energy. And I'm seeing those trends come to fruition here. Absolutely. Well, I believe, Joe, that handles it for our interesting Colorado news of the day and our Colorado security-related news.
Of the day.
That does it, which takes us to the events calendar. Uh, Alex and Robb made some great updates to the events calendar on the Colorado Security website. So if you go to colorado-security/security-events, if you can remember all of that, but you could also just go to colorado-security, find it in the little hamburger menu off to the left. It will be updated as new events come out. But for now, let's run through a couple of the events of note for April, starting with Denver ISSA, which is hosting on the 8th an event titled How Quantum Computing Will Unlock and Unleash AI.
And on April 16th, there is the April chapter meeting for ISACA Denver.
Awkward silence because I also want to show that on April 16th, we— I'm looking at the calendar myself because I had failed to add in some of the events around SnowFROC, which is happening this month, one of them being some workshops on Thursday, April 16th from 9 in the morning to noon. Great conference, hoping to be there myself, but good to check out. Next in our list is also the ISC2 Pikes Peak meeting on April 22nd. And then on good old 4/20, we have SANS Rocky Mountain meeting. Yep, it looks like that one actually goes through the week.
And ISACA has been putting on their spring CISA training classes. Those are ongoing. Contact your, your chapter representatives for more information. And with that, one more reminder to check out the Slack channel, which is accessible through the Colorado Dash Security website, coloradodashsecurity.com. Ask to join the Slack channel, bring your friends along if they're in the Colorado security community, join the mailing list, rate and subscribe the podcast with your wonderful new hosts, uh, and tell a friend about our show.
I would just like to say once again, we thank Robb, we thank Alex for the incredible, incredible efforts and value they've brought to this community over the years, hoping that we can carry that torch forward for them. But Chelsea, do you have any parting words? The only parting words that I have for us folks is go crush your day and make it a productive and happy one. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.