Yvette Florez, CISO of a Colorado State Government Agency
Managing statewide crises and driving legislative change, from the SamSam ransomware response to the Joint Technology Committee. Interviewed by Frank Victory.
Our featured guest this month is Yvette Florez, Information Systems Security Manager at the City of Lakewood and former Director of Identity & Access Management for the Colorado OIT, interviewed by Frank Victory (President of Denver OWASP and Conference Chair for SnowFROC).
We often talk about the operational side of cybersecurity, but Yvette brings a unique perspective on managing statewide crises and driving legislative change. She takes us back to her time with the Colorado Governor's Office of Information Technology (OIT), detailing the intense response to the SamSam ransomware attacks that took down CDOT. Yvette also shares the behind-the-scenes work of representing OIT before the Joint Technology Committee (JTC) in 2018, where she played a key role in securing crucial funding for state identity initiatives. Finally, we explore unique workforce solutions, like the Department of Corrections (DOC) programs that utilize offenders for tier I Help Desk calls.
In this episode
- The SamSam response. The state's battle against the SamSam ransomware attacks on CDOT and the resulting federal indictments.
- Funding state identity work. Navigating the Joint Technology Committee to secure legislative support and funding for critical state identity initiatives.
- Unconventional workforce development. Using Department of Corrections offenders for tier I Help Desk calls via the CCI program.
This month in Colorado security
The news & resources segment.
- Software company expands into downtown Denver Denver Business Journal
- U.S. military terminates Aurora-based GPS technology contract after $6.27B spent Denver Business Journal
- Ibotta extends Nuggets jersey sponsorship Denver Business Journal
- Aerospace company chooses Northern Colorado city for manufacturing site Denver Business Journal
- Elon Musk's xAI sues Colorado over artificial intelligence law Denver Business Journal
- Why AI application signals should drive enforcement decisions zvelo
- The governed agentic future of security Optiv
- How AI can streamline your security testing Red Canary
From the guest
- Yvette Florez on LinkedIn
- Frank Victory on LinkedIn
- Professor Frank
- Frank Victory on GitHub
- Professor Frank on YouTube
- How SamSam ransomware took down CDOT, and how the state fought back twice (Colorado Sun)
- CDOT hacking indictment (Colorado Sun)
- CDOC Colorado Correctional Industries (CCI) program
Read the transcript
Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now, here are your hosts, Robb Reck and Alex Wood.
All right, welcome to episode 286 of the Colorado Equals Security Podcast. It is a beautiful day in sunny Colorado. I am Chelsea Weiss and I am here with my co-host, Joe McCallister. Hey, Joe. Hey, Chelsea.
How's it going? Not too bad. Thank you for asking. Of course. And I agree, it couldn't be prettier.
We're in the middle of the, the May heat wave and probably getting some storms almost every afternoon. I could do an evergreen forecast that is nice and toasty, nice and sunny, a little bit of rain, and then it's sunny again. But welcome to all our listeners out there. We encourage you to join us over on our Slack community at colorado-security.com. There's information on how to join the Slack community as well as the events calendar we'll cover at the end of the show.
And you can also access, of course, all the shows there or on your favorite podcasting app of choice, Apple Podcasts, Spotify. If there's any fun Overcast people out there that like to be a little different, go for the gold. But let's kick right into our first story, if you don't mind, Chelsea.
We— if you would quit holding me up, quit holding me back, we'll get into a couple of big stories in the business world over the past month or so in Denver. One of them being that a big software company called Latera opened a downtown Denver office to help them in their mission of developing legal software and AI-aided legal software. It's really interesting because I think we're seeing, uh, I don't know if you're seeing this or feel this as well, but I kind of feel some tide shifts, a little bit more walking on eggshells around AI. But I am interested to see these, these companies, uh, like Latera opening up. They're down off of WeWatto, so they are right down in the, in the thick of things.
Um, Chelsea, any thoughts on what you're seeing in terms of AI-aided companies? Coming into the area or anything that was interesting in this story for you? Yeah, from my perspective, and as we kind of talked in the last podcast, when I think about Denver, I definitely think of us as an aerospace and manufacturing hub. And definitely over the past 5 to 10 years, we are continuing transition to a real serious tech hub and now a serious AI hub. So I am a big fan.
And this one, is also interesting because I know a lot of the companies that are looking to expand their hubs, Denver's having some vacancy issues anyway, but it's nice to see that companies are still investing in downtown and betting on in-person collaboration here in our beautiful sunny state. Absolutely. I really enjoyed part of the article that talks a little bit about the revitalization efforts downtown and Greg Ingino, I'm going to say, I hope I got that right, Greg, the CTO of Latera, who is a Denver resident and has been here for a while, made a couple comments that just about the perception that we haven't addressed crime and the perception that we haven't addressed cleanliness kind of travels quickly, but I think has come a long way and shows that these investments are companies being bought into the revitalization and the, you know, the kind of cleanup of the area and even just the reputation down there. Already mentioned specifically, um, what will always be in my mind the 16th Street Mall, uh, being completed. Oh yeah.
All right, Joe, I will transition us to the next one. Number 2, US military terminates Aurora-based GPS technology contract after spending $6.27 billion. So digging into this one a little bit more, it's, um, Space Force had a program called GPS OCX. It expanded over 15 years and once again was super expensive, $6.27 billion. The whole purpose of this system, it was, it was developed out of Raytheon/RTX, and it was supposed to modernize the military GPS ground control infrastructure.
But, um, instead the testing uncovered some pretty major system-wide failures that were serious enough where Space Force essentially said, we're not going to deploy this because it could actually put military and civilian capabilities at risk. You guys know me, I love the aerospace and defense community. And this was an interesting one for me because, you know, GPS isn't just maps on our phone. It is truly the underpinning of our financial system, aviation, military ops, telecom timing, critical infrastructure. So when modernization of something this foundational fails, it becomes a big issue.
What were some of your takeaways for this one, Joe? This one not being as close to military, space, any kind of that realm in my professional career has me really interested in this story because I feel like I kind of went down the rabbit hole a little bit here. But it is also kind of one of those tales as old as time where cost overruns kind of really doomed this one and continued to kind of be the final nail in the coffin when they looked back and said, we can't justify putting more into this, uh, as opposed to just stopping the bleeding now. If I'm not mistaken, this was actually first created, uh, in 2010 before the Space Force was even a thing. So for it to continue to run now, uh, 5 years ago the estimates had the project at about $3.7 billion.
So jumping, you know, almost doubling in a couple of years, uh, in, in 5 years is pretty substantial. And for it to still be having some issues, I think it kind of benefits if it's all parties to just say, you know what, we tried, this isn't the solution, we're gonna continue moving forward. Uh, puts the, the, you know, the companies, um, in, in this project kind of in a, in a weird spot. But I think it's better than trying to keep this thing limping along for the next— or like you said, rushing it out while it is having these issues would be potentially the worst-case scenario. Yeah, this was a good example of you know, complexity killing something.
When you have a big mega project and it gets so big and interconnected and delayed, it really collapses under its own weight. So let us all learn something valuable from this one. That is right. Well, thanks, Chelsea. We're going to move on to the next one, which is a bit of our hometown heroes, uh, both in the business realm and in the sporting realm.
Ibotta has extended their Nuggets jersey sponsorship, which is the biggest news of the month for me for sure, just because I recognize the logo. If you don't know the company. You'll know it from the jerseys running up and down the court. Not so much anymore now that we're recording this as of May 15th. Unfortunately, our boys didn't make it much further in their Finals pursuit this year.
But it is always encouraging to see a local company investing back in the community and the sports that keep this town, in my opinion, a sports town. Go Avs, go! But Chelsea, just wondering what your thoughts are about this, how you feel about general sponsorships And if you are a Nuggets fan or if you are an absolute traitor. Not a traitor. I do enjoy the Nuggets.
I just love watching professional athletes. You know, they're really good at what they do. Watching people do what they're really good at and the state of flow that they get in is super exciting to watch. So big fan of that. I actually used to work for Arrow Electronics and they do a lot of really good sponsorships and it's a good way to get your company's brand out there.
I mean, for Ibotta, a lot of us know them as historically like cash back on everyday purchases type of company, but they have done a really good job of kind of reinventing themselves as a major platform for digital promotions, marketing platforms, and a lot more. So kudos to Ibotta and kudos to Denver. This is another really good example of a big tech company investing in Denver long-term. Absolutely. And just to tie it back to the first story that we had about local businesses investing in the community, same deal for Ibotta investing opening a new office, I believe, just last November.
Uh, moving offices, I should say, but putting a little bit more into the community. So thanks to everyone involved there. That's awesome to see. Mm-hmm. 4th article of the afternoon: Aerospace company chooses Northern Colorado city for manufacturing site.
This one is a new Danish aerospace company called Multicut, and it's going to open in Loveland. They're going to hire about 82 people. And the article also talks about the annual wage of those folks will be about $71K. And, well, you know, no surprise here. Big fan of this one as we in Colorado continue to solidify ourselves as a real serious aerospace and defense hub.
You know, not just RTX and not just Lockheed, but specializing in international suppliers supporting the entire aerospace and defense ecosystem. Yeah, and what I think is interesting is that it is such a multifaceted strategy. You know, I'm pretty out of the loop on how we attract businesses like this, but seems pretty cut and dried on this one. There was a, a great tax, uh, benefit that was extended to, uh, Multicut, the company in question here, uh, from the Colorado Economic Development Commission, uh, up to $1 million over 8 years if the job— or if the company, excuse me, meets job creation and salary mandates such as you mentioned, paying at least— or excuse me, an average— geez, messing up twice in one sentence. That's always good.
Paying an average annual wage of $71,800 for its 82 employees. I think it's also notable to, to kind of put things in the right perspective of where this company is going to be and their proximity kind of to other in the space and defense arenas is, is gonna work out pretty well. And this was all announced at the Space Symposium down in the Springs just, uh, just a couple of short weeks ago, I believe. Did you get a chance to check that out at all, Chelsea? No, not this year.
I was at a different event called Safeguard that focuses on risk compliance and cyber and AI, so kind of had to trade one for the other. But my— I did read a lot of interesting takeaways. You want to tell us A little bit about Elon Musk, Joe? Yeah, maybe. I don't know.
You know, it's— he tends to find himself in the news cycle more often than not. But this is actually kind of an evolving story. And this is because we, we have been a little bit later putting this episode up. We've actually benefited from that. And as it pertains to what we're going to talk about here, but the original headline we wanted to talk about was Elon Musk's XAI lawsuit against Colorado over our AI law that we are putting through, that the governance is out there and the proposals are up.
X is— XAI, excuse me, because now there are multiple Xs— is arguing that the law infringes upon XAI's First Amendment rights. As we were looking and kind of reviewing the story, we also see that as of just the other day, Governor Polis did sign the bill into law, but did scale a few of the protections back, most notably the mandates for an annual impact assessment and disclosure requirements for certain AI decisions on Colorado residents. So really what happens and what the kind of meat of the changes is that the— an AI system can still make decisions based on a resident but does not have to disclose how it arrived at those deterministic kind of ends. However, it does not change anything that Elon was originally— Elon and his company were suing the state of Colorado for. Big ball of wax here.
Lots of threads. Where do you want to start, Chelsea? What are you thinking? The biggest question that comes to mind for me is who gets to define what fairness means? Who gets to define what bias is and what acceptable AI behavior is?
Is it going to be our government? Is it going to be the company? Or in this case, eventually the court? It's a question that we all need to be prepared to answer because, you know, my methodology is if you don't decide, someone's going to— someone else is going to do it for you. Yeah.
Yeah. And Brittany Morris Saunders, president and CEO of the Colorado Technology Association, just kind of added a couple of updates and congratulatory messages that the— and supportive messages that will kind of aid in SB 189. That's the, you know, the government name for the bill that's going in. But she had said that it turns years of policy work into a path forward for Colorado. And I do have to say, it's nice to see the machine of government working here to see something in place as opposed to the hand-wringing and the back and forth.
And at the end of the day, we either get something that is effectively neutered or something that we are all kind of wishing wasn't in place or nothing at all. So it's good to see this stuff. I think I fundamentally don't think that the First Amendment rights of a an AI company or something to really be battling too much over. I'll be really interested to follow this and see where kind of the courts end up deciding on how xAI's claims are either upheld or wholly rejected. I think it'll be not the last time we see some interesting legislation and interesting court cases based on AI in the very near future.
Yeah, a.k.a. more to come on that saga next podcast episode. And with that, we'll move into the 6th article of the day, Why AI Application Signals Should Drive Enforcement Decisions. And this one comes to us from Zvelo. And the moral of the story on this one is that AI security needs to evolve to capability-aware enforcement, which is really just a fancy way to say the security tool needs to understand what the AI app actually does.
Does it generate content? Does it execute actions? Does it integrate with third parties? And from there, adjust enforcement of these decisions accordingly. Kudos to this article.
It broke things down into 4 different signal types, which as a practitioner is very helpful and easily digestible. The first one is capability. So once again, understanding what the app can actually do. Summarize, generate, transform data, etc. Second one is authority.
What access or write permissions does it have? Third one, integration reach. What downstream systems or APIs is it touching? And then the last one is execution behavior. So whether it operates autonomously or continuously.
Well done, Svelo, on summarizing all of those. From my perspective, this was really just a reminder for all of us that some companies are still focusing on AI usage, which is important. But this article is a good reminder that we have to look at our entire enforcement stack and how that behavior changes based on the context of the AI. What did you think on this one, Joe? You know, this is one of those articles that I applaud the the article in, in totality.
And also it is equal parts fascinating, in-depth, but also high level enough that it made me kind of consider things in a different perspective than I had previously. The 4 signal types in particular being like, oh, I, I know exactly what they're talking about and they just put a word to the thing I'm trying to say is, you know, when I'm struggling to do words good, I appreciate folks like Cervello putting out these types of things to help make it real for myself and my executives. Right? Because these are questions that come up and how are we addressing them? How can we extend our existing IT controls to AI today?
Is that actually possible? Are we talking about a brave new world, a new frontier, if you will, of the controls that we can implement for these types of actions? And everything's happening faster.
No surprise there.
All right. Well, let's head over to our next article, which comes from the folks at Optiv. And this one's called The Autonomous Security Enterprise: Balancing Innovation, Compliance, and Trust, which I will say headline alone is bang on because it is something that I'm struggling with. I think a lot of business leaders are, are really struggling with today being able to keep things in line and also be on the bleeding edge, right? The— you know what, Chelsea, I don't like this article.
Yeah, well, let me— I also don't like this article only because, you know how there's 2 things that I'm continually reading from news articles and I'm continually reading from LinkedIn? It's AI governance and the most latest software supply chain attack. And this one just made me smile because it really strikes a drum to the beat of 2026 is the year of AI governance. And then of course all the software supply chain vulnerabilities that we have. But Palo Alto, this article called out Palo Alto specifically and how they are pushing plat— I have a hard time saying this word— platformization.
Platformization. Anyway, consolidating all of their stuff, cloud, SOC, AI, identity, network security, all-into-one ecosystem. So when we talk about autonomous security, you know, surprise, autonomous security is here. Agents can investigate threats, isolate systems, revoke your access, respond faster than humans. I'm still waiting, Joe, for it to do my laundry.
Me too. I say that as I have things in the dryer so long they're no longer— they got to be run through again just because they've got the wrinkles. Unfortunately, it is interesting because I've even had some conversations with my technology partners in my organization about, do we need to consider a platform play or are we good with point solutions and where is the line? I know that's not necessarily the bent of this article, but I think as technologists, like, it's definitely one of those, do you use the saber that cuts wide across a bunch of solutions and maybe doesn't do all of them, you know, might not be an A+ in all, but probably is in a few. There's a reason it's as big as it is.
Or do you go the point solution, the spear that is able to surgically get in there, or the scalpel if you will, that can get in there and do one job very, very well, but also might get swallowed up in a couple of years by one of the platform players. Just the general landscape is very wild in technology, but I think that's why a lot of us still like it. Yeah. And the last thought I'll leave everyone with on this one is, you know, what are— for those of us in highly regulated industries, our regulators are going to want to know who authorized the action, what evidence exists, whether AI actions actually followed up on the policy. So that just trying to make it easier to be able to answer that question for our regulators is also going to play in this.
So kind of similar to what I said earlier, this is evolving and this one saga will continue. So that being said, I will transition this to our last article of the day. Brought to us by Red Canary. How AI can streamline your security testing. This one talks about how Autonic Red Team released an MCP server that lets AI assistants execute security testing workflows using natural language, which is super exciting, easily digestible.
As a product security professional and an offensive security professional, highly attracted to this one. Rather than me and my teams having to manually build attack simulations, it's gonna be so nice to be able to ask AI just to map the threat intel to the MITRE ATT&CK techniques and then validate the detections automatically. You know, key takeaway, this is a good use of AI helping our teams be more efficient. Security or offensive security teams can validate those detections and build adversary emulations in minutes instead of ours. Hallelujah.
Joe, how do you feel about this one? I think you hit every great piece of it. There's a couple of things that it does say single pane of glass, personal ick, but that's okay. I can get over it because I do like the way that they break down using your different MCPs and you like orchestrating, truly orchestrating between your different tools that you have. When I think about what this article is really going after and what the struggles of me as a security practitioner and leader of a team are, It's about buying ourselves more time.
And when we have things that can cut down on the time to effectiveness, like these automations, these orchestrations, or AI aiding us in doing those menial and tedious tasks much quicker, that's where the nuggets are. That's where we become operators as opposed to just trying to figure out what the next kind of fire we're going to fight is. This allows us to be available and actually start thinking about trends and themes and more important big kind of monumental changes to affect our different organizations' postures and things like that. So this is huge. I'm really excited.
I candidly put this in our Slack channel today and said, all right, what do we need to do to get this in the process? What are we thinking? How excited is everybody? And the team responded to it pretty well. So I'm very excited about this.
Heck yeah. Well, we will end the news section, the newscast, With that positive news, enjoy that, my Colorado sunshines. And Joe, I will turn it over to you for our events, please. Absolutely. Before I do get to the events, I do want a quick plug for the security— the Colorado Equal Security Salary Survey is live right now.
I would imagine it will be running through the next time we record and publish, but go ahead and jump into the Slack channel, grab the link, or email the Colorado Security channel, or excuse me, email address, and we can get you included in that. It is for security professionals located in Colorado exclusively, just to keep our data as clean as possible. But that's something that I've run for the past couple of years and been very happy with the output. Always taking feedback as well. So hop in the Slack and let me know what is great and what is not so great.
But let's get to the events for the remainder of May here, starting off with the 20th, which is a Wednesday, where DenverSec will have their monthly meetup. You can check them out at denversec.org for more details. And also the very next day, we have Identibeer Denver at 4 PM on Thursday, May 21st. You can check them out at meetup.com/identibeer.
Think identities, but beer instead of ease. They're also a group on LinkedIn you can join. So if you'd like more information, check it out there. The following week on May 27th, we have the ISC2 Pikes Peak May chapter meeting, as well as Denver ISSA Privacy and Regulation Special Interest Group is meeting up that evening. And on Saturday, the 30th of May, there is an ISSA-sponsored Colorado Springs Chapter Security+ Review Session 4 from 8 to 5.
We— I'm also going to pop over into June and just see if we've got anything, just in the off chance that we don't get our episode out at the first week. But on June 11th, there's the Northside Cyber Quarterly Meetup from 4:30 to 6:30 PM.
On Wednesday the 17th, DenverSec Monthly Meetup again, 6 PM to 8 PM. And RMISC is happening June 23rd from 8 a.m. to 5 p.m. on June 25th. So the middle of the week, check that conference out. I know I will be there. Chelsea, you planning on hitting that one up this year?
I will be there and I will be speaking on Wednesday, talking a little bit about exposure management, vulnerability management, secure by design. Western Union's experience with that, and I'm super excited. And for the local folks, this is— this ARMSK has gotten big over the past couple of years, so we have a lot of really good people there, a lot of really good speakers. This is one that I would definitely recommend attending if you can swing it, and invite your friends. Absolutely.
It's always a great time. It's one of my favorite events. If nothing else, the talks are fantastic and LobbyCon is a great time. I will be sure to check your talk out, Chelsea, and I'll warm up my tomato throwing arm just for you in case you say something I disagree with. That's all the events for May and into June.
Reminder to hit up the Slack channel. colorado-security.com is where you can find all of this information. The events, the Slack channel, the application for special interest groups and other things like that are all available there. In the meantime, submit a review. Let us know what you like about the show.
Subscribe on your favorite podcast. Tell a friend and get the chance to maybe chat with us live in person in June. Chelsea, thank you so much for joining this, the 286th episode of the Colorado Equal Security Podcast. Amen to that. Everyone go and enjoy your day.
Hi, this is Jason Hamilton, Deputy CISO at Movement Mortgage. Welcome to Colorado Equal Security, for Colorado security professionals by Colorado security professionals.
Well, good morning, good afternoon, and good evening. This is the Colorado Equal Security podcast. My name is Frank, and today I have Yvette Florez is on, and she is the CISO for a state government agency, and she's new to the podcast. I don't believe that you've been on before, so welcome, Yvette. How are you today?
Thank you, Frank. It is so good to be here. I am doing excellent. Well, we've been through your, your LinkedIn profile. I believe that you are a CISO with a state-funded agency, and you've been in the public sector for many, many years, uh, well over 25, I believe.
All right, you are right, over 25 in the public sector. My current role, uh, I did leave the CISO role in December, so I do have a new role at a new organization, not in the CISO role but still in the— still in security. Okay, well, before we start off with the seriousness, or I guess the actual podcast, I always like to ask an icebreaker question. And I don't prep you for this on purpose. Your icebreaker question for today is, if you had a time machine, would you go forward in the future or would you go back in time?
I would go back in time. And why?
Oh, it's just so nostalgic and fun. The clothes, the, the music. I'm so big on music. What's that? Is there a specific time period that you would go for?
I, I don't know. I did enjoy '70s. I enjoyed the '80s, but maybe even going back to '50s or '60s, maybe. Okay. Yeah.
One of the things that I found fascinating about the public sector in cybersecurity is that the challenges are not just technical. They're organizational, political, and sometimes even even legislative. In the private sector, companies can often pivot quickly. Government does not always have that luxury. I wanted to spend some time talking about what it's like to actually build and lead cybersecurity programs in that environment.
Multi-year planning cycles, budget approvals, statewide coordination, and trying to future-proof technology in an industry that changes every 6 months. Also, also, let's just get, uh, just kind of loosen up the crowd a little bit. You're currently in a C-suite, or sorry, in a leadership, you are still in a leadership role for a state agency.
And you've never worked for a corporate environment before. You think, I mean, that makes you unique maybe, or what kind of unique perspective could you say about that? I mean, being in the public sector?
So being in the public sector, some challenges or what's unique is the stringent budget that we have, even thinking 5 to 10 years down the road for that budget ask, which can be difficult because how can you predict what the next 5 to 10 years is going to look like. You do have to be very strategic in the government space. And yeah, knowing what work is going to look like, what positions are going to look like, what resources you're going to need, how quick technology is changing. And yeah, that transformation and, and budgeting for those things. Well, what would make that different?
I have had a— probably most of my career has been in the corporate sector. And having budget limitations is nothing new. Is there something, do you think, that's unique with working for state-funded, or is it just in alignment? Is it that time period, that 5 to 10 years, that's different? I haven't worked for corporate.
I'm not going to be able to speak to that, but I can tell you what it looks like in government, and I can give an example from my experience. As I led the Identity and Access Management program for the entire state of Colorado. So that is the 17 executive branch agencies, and then also providing those services to the 64 counties that we have across the state. One of my initiatives— this was just one of them— it was kicked off in 2014, and a full live implementation of our identity governance administration privileged access management, data and access governance with those technologies. Again, it took from 2014 to 2019— I might have said 2017, I misspoke— 2019 to go live with that.
And it was a very phased approach, one, because the funding for the technology, funding for those resources to be able to come in and help implement and then also support. So I had to do budget requests many, many years out. So every 3 years asking for budget and, and hoping that that budget from the State Budget and Planning Committee would approve this. So this does need to go through legislature to even get the funding approved to do new technology, bring in resources. And I don't know how corporate would operate that way.
We're also for state, our fiscal, fiscal year runs July 1st through June 30th. So you really also need to be strategic with planning for what you are going to ask for that next year that is 3 years out. Um, I don't know what corporate would look like. I can tell you with an organization that I'm with today, it does not appear that stringent. Top-of-the-line technology, and we know that if that money needs to be spent and it makes sense for tech on that technology, we're going to do it.
Just much more stringent for, for the state. With that said, anything that I asked for, I also would go back to the Joint Technology Committee to explain that return on investment. So you're really proving that that money that was spent was well spent. Well, here's something I think, especially coming from a corporate environment here, roughly a 5-year implementation plan for this. Do you think, one, that it caused you issues or possibly security gaps by taking that long, right?
If, yeah, I know you said a phased approach, but I think the other part and the second part of this question is that if we took 5 years to do anything in the corporate world, everything's changed since then. Like project managers and heck, the company could have been sold twice in 5 years. Let's start off with that first question. Did it cause problems? Was the technology an issue?
Was the company that you were implementing the IAM and PAM solutions with, did they change at all? Absolutely. Oh yeah, absolutely. So you're right. People come on and roll off of the project.
So project managers changed, staff changed, vendor partners changed throughout that, those years. But also because the way the project— and I'll talk about just for IDA itself, the Identity Governance Administration portion— that was ran as waterfall project. So yes, by the time you're doing your requirements, you're doing the design, you're considering what those compliance— the compliance looks like, the, the regulations, things do change. So now as you developed and designed the program to act in a way, and 2 years later, does that stuff even still apply? Did that compliance change?
Did that process change? And so it was, it, it was very challenging. Now, could we do something? Could we have done it differently? I don't know.
Not for IGA and for doing it for the entire state in those 64 counties, because you could not do a big bang. It's not a flattened network. It was a very complex environment. I don't know if we could have done anything different. I will share, um, that there are risks out there, and we did have to act more quickly in some areas like multi-factor authentication.
As regular listeners of this podcast already know, one of the hardest parts of cybersecurity is convincing people to take security seriously. Seriously before something bad happens. Security controls like multifactor authentication often feel inconvenient, expensive, or unnecessary until a real-world incident suddenly changes the conversation. In this next segment, we'll talk about the impact of the CDOT ransomware attack and how incidents like that can fundamentally shift both organizational cultures and security security priorities. What happens when critical infrastructure systems are targeted?
How close can these events come to affecting public safety? And why do major incidents often become the catalyst for funding, staffing, and long-overdue security improvements?
So in— I think that was 2017— I was a part of the major— I think we can say this, Frank— the CDOT ransomware attack that happened. So many of our agencies, they then— this became a verb. I don't want to be CDOTed. So they didn't want ransomware to happen. And even pushing MFA years earlier, did the user even want that type of experience?
But as you explain, why are we implementing multifactor authentication and how it's more secure for you to protect your identity and the, the data. At that time, once one agency got hit with that ransomware, then the culture changed. The, the users were like, yes, sign me up, put us on. So it made a difference. Um, but was, was it risky at that point when there was not MFA for them?
So it was a balance. Well, this brings up actually more questions here. A lot of, I think, really good questions from what I am thinking so. But let's start off, I think, with the one that's burning on everyone's minds here. Obviously CDOT, and I'm assuming the Colorado Department of Transportation, right, responsible for at the very least we know roads and snow blowing, etc., even though we didn't have much of a winter this year.
However, however, it's something that I take for granted. I get up on the road or I get up and go to the mountains and don't think about what could happen from that ransomware. What kind of impact happened or could have happened from there? Could there have been road closures? Could there have been?
Yes, there definitely could have been. If you take worst-case scenario, the signage, you're getting on the highway, look at the signs that are saying these, this part of the road is closed down. There's an accident, merge right. There's an Amber Alert. Those things, yeah, could be down, could, could have gone away.
What about when you're on-ramp to the highway and then you're getting the red signal to stop and hold on and let traffic continue? Then you get your green signal so that you can then enter onto that highway. Now, if those were not operational and/or more maliciously somebody's messing with those and causing accidents, absolutely those things could have been detrimental. But those things were not impacted. So yes.
Well, definitely. I mean, when we start running into, well, let's say every single light in the city turned green. That's, that's been placed in the series of pretty much any number of TV shows and natural disasters. Exactly. And again, we, we take this for granted.
So I guess first job, or I guess the first thing is to be congratulatory to the response, whatever the response team was, I guess the CCERT team that prevented this from happening. And then on your other piece then, right? Did that give CCERT more power to implement MFA? Into another series to the other departments. It definitely did.
And yeah, there were a— we walked away from there, I'll say similarly to an audit. So when you're audited and you have a finding and maybe it's not just a process improvement, but it's a piece of technology that you need to be— that needs to be brought in.
That audit finding can help you get that funding, that budget request. The same thing happened with the CDOT incident. We did come out of there with what would it look like, what would it take for this not to happen again to CDOT and/or any of our other agencies. And so with that ask, we were able to bring in solutions work with partners, and even staff up our teams. So let me spin something that is normal in the corporate world.
Is let's say there is a security incident, data's compromised, users, etc. Take your pick, any number of those things. Usually what happens is that there's an immediate funding. Hey, security, here you go. Here is half a million dollars to solve this issue, etc.
And the security team says, great, we had an incident. We're now going to buy this technology. We still have to meet with the vendors. We're certainly starting off with the bake-offs, et cetera. And then 30 days later, that budget gets cut in half because it's kind of lost its power.
It's kind of lost that issue. And then maybe in 60 days, that budget, the remaining budget is also cut in half from half a million dollars. We're now at $125,000, which in security sometimes is, well, pretty much nothing. Would you say that's the same type of issue in a state government agency? Would you run into that type of issue?
No. No, I'll tell you, we did not run into that type of issue. I would see that happen if there was a department, a division, an agency who made that, made a budget request, and this could be outside of incident response, and that budget was approved. Here's the funding, go do what you say you were going to do. And if you sat on it and did not do what was in that budget request, then it sounds like it wasn't that important, you don't need it, and then that money is going to be reappropriated to something more, to another need.
So kind of though, on a similar standpoint, I mean, we don't use that budget right away, or obviously with all companies. And it sounds like, of course, with the government, budget's limited no matter where you go, no matter what you do. And it sounds like, again, same type of stuff, but let's kind of go in some other direction a little bit from what you said earlier about having to talk to state legislators. And when we start talking to them, though, when I start thinking about having to present to a CISO, having to present to executives, etc., we've got to change our language. We can't go in there and say this hacker tried to exploit a CVE or Qualys ID or something like that and tell them, oh, well, that, that VP, that non-technical CISO or etc., whoever we're presenting to is going to go, we have no idea what you're talking about and we honestly don't care.
There. I'm imagining though that you would have similar, if not even stronger, challenges with state legislature.
And I did not find that. Okay. Um, and, and it is out there. It is recorded for the community listening. Colorado Equal Security— there is a recording of me and our CISO at that time Debbi Blyth.
We are talking about the incident. We are talking about our ask that we had for budget needs and the technology that we were going to implement, and then that return on that investment and where we were. So kind of going back, Frank, to even what you were saying, so if you don't spend it, you lose it. We're also held accountable to what we are asking for. So here's this dollar amount that we're asking for.
Here's the technology. Here's the resources, here's the time frame that it's going to take to get this done. And then you are held— we are held accountable for that. So even that reporting, those milestones, and, and so on. So that's what you— somebody would hear that is live out there.
It is recorded. Again, it is that accountability. Um, I know Debbi and she's an amazing person. She, she really is. I think the world— I think the world of her.
Give her a hug whenever I see her and things like that. So as we discussed, as we discussed, you talk to— you tell them in terms that it's meaningful to them. It's not the tech talk, like you said, not these CVEs, not the threat, not the attacker, not how they're coming in and what they're doing, but worst-case scenario, like you said. So if CDOT, if the lights were impacted, what does that look like? That's life.
That's life and safety. Um, we had a very good, um, exercise initiative project, whatever term we want to call it, at the city. And what we did across 11 departments, and this does include the police department, we talked to them about their crown jewels. So even to them, well, what is a crown jewel to me? So instead of, again, talking tech talk, we went in and talked to them about what is, what is the mission?
What is the mission that your department provides? What is your mission? What is the services that you provide the community? So when you use technology to provide those services, what are those tasks and functions that you're using for that technology to provide that service? If you could not use that technology to provide that service, is that reputational?
Is it— are you going to be fined? Is it operational? How long can you do without that technology to provide the service for the mission that you provide? And so when you talk to them like that and have them really step into the shoes like, oh geez, well, if this technology or this data gets out, how bad could it be? And then they really start to, to understand the importance of protecting that data, not sharing that data publicly, or using strong passwords to protect and the need for MFA, etc.
So talking to them about, yeah, what's in it for them has been helpful. Well, how about this? Um, one of the things that we're told to always avoid is FUD, that fear, uncertainty, and doubt acronym. That— does that translate to a state agency? From what you were just saying, what could you do that, that almost falls underneath that FUD?
That, that FUD concept. And how does that apply, or does that apply? Does that make any— I don't know if I'm making any sense or not by asking. No, you are making sense. But I would flip that and I'd say it's not about that fear.
It's more about empowering and educating. That's what I, I'm empowering you, uh, to be cyber secure. I'm educating you and how to do that. And these are the right— the reasons why we want to do that. That's how I would spin it.
It's not about fear. We also— nobody wants to be in the paper for the wrong reasons. And so they're going to be your partner to ensure that that does not happen. And we're all going to do our part for that. That's what I truly believe.
One of the biggest challenges in cybersecurity is not always the technology. It's the coordination. Security programs rarely succeed because of a single team, tool, or department. They succeed when multiple groups with different priorities, responsibilities, and perspectives learn how to work towards a shared outcome. In this next section, we'll explore the human side of security governance.
How do you build cooperation across departments that may all view risk, compliance, and ownership differently, from PCI DSS responsibilities to operational accountability. We'll discuss realignment of aligning IT, finance, operations, and vendor partners around a common security objective. We will dive into the limits of process-driven solutions, why compliance is ultimately a shared responsibility, and how communication and relationship building often matter just as much as technical controls when trying to create an effective cybersecurity program. Okay, let's talk about a different challenge here, right? Because you talked about 11 different agencies and 11 departments at the city.
Yep. Yeah, 11 different ones at the city. Let's talk though about cooperation here, because one of the things that when I was running team. I used to talk about how the difficulties of getting everyone to agree, and one of the examples I gave them was if you call 10 people, or maybe in this case 11 people, into a meeting room and told them all to go draw a picture of a dog, you're going to get 11 to maybe even 15 different variations of that dog. I mean, they would have, of course, the, the common elements, the 4 legs, the tails, etc.
But you would get 11 different interpretations of that. And how do you get those people to agree on one solution? I don't know if you can get everyone to agree on one solution, but what you can do is get that 80/20. Uh, I did this, and we'll even— maybe we won't even— I'll give another example instead of the IGA solution. That was rolled out to the 17 executive branch agencies across the state and the counties.
I'll talk about— let's talk about PCI DSS. So here's not 10 people, could be 10 people, but here's 3 different departments. So the recreation, the finance team, and the IT team. And let's also put in our vendor partners in there. So let's talk about 4 of those teams.
So how do you get someone to own their part in PCI DSS compliance. The rec centers may say this is an IT thing, we're using technology, we're using systems to do this, you protect it. When no, the rec centers, you are providing that service to the community and you're taking those credit cards for a service that you provide at the rec So you have a responsibility. The finance team, you also have a responsibility as finance team for the city, and so does IT, ensure— to ensure we're changing default credentials, we have a firewall in place, etc. So this is a partnership.
And then we also have our vendor partners who may be handling those point-of-sale systems. So how do you then bring this information to get everyone to agree that we all have a part of PCI DSS compliance? What I did there is broke that down and for an understanding of where each person or each department had a role in the compliance, because if we're not compliant together, then what happens to the city, which then equals the community, when we can't take payments? Or we're fined. And it is then our reputation.
Again, explaining it to them, how they can help, how they're a part, how they have a responsibility. And then, yeah, we're in this together. Okay, well, I guess the quote obvious solution to this is, well, let's— we'll just put together a RACI matrix and solve everything with that. I think that while at the surface it's easy to say you're responsible and we all want to be a community and we all got to serve this together, each department is going to have their own goals. The finance people, of course, they want to be protected, but their primary piece is, can we run transaction?
The people at the rec center are probably saying, well, I don't care anything. I mean, I swipe a credit card and it's some kind of super magic that happens, and they don't care. They'll probably walk away from their workstations. They care about is Well, I'm in the recreational piece. My job is to check out basketballs and have people come into the swimming pool, not about what happens after this magic ends.
How do you solve that issue? We're talking— there's not a hardcore solution. I mean, if there was, we'd all be rich and we'd all have everything secure. So it's more about more art than science, I think, in this case. Yeah, I would— yes, art and science.
My answer there It's that relationship building. So building those relationships, establishing the trust. It's not sending an email. It's not sending that racy matrix. It really is that conversation.
Really? Yeah. Having conversation, getting together in person, via Zoom, via Teams, whatever that looks like. But what it's— I can say what it's not. It's not an email.
It's not a playbook. It's not a matrix. It is— it's the relationship and establishing that trust. Oh, so you mean treating people like people? Yeah.
Understanding. Wow. Wow. Okay. What a concept.
I know. I know. I think that tomorrow you and I are going to be rich. Absolutely. Because it was that easy.
It was that easy. Okay.
Cybersecurity is usually portrayed as a world of tools, technologies, hacking, and nonstop problem solving. But behind all of that are people, and the experience people have in this industry can shape not only their careers but the future of cybersecurity itself. In this next section, we'll shift gears a bit and have a very real conversation conversation about what it's like being a woman in a field that's still heavily male-dominated. We'll talk about mentorship, confidence, finding your voice, and why having allies and supportive communities matter more than people sometimes realize. This is a conversation about persistence, about showing up, speaking up, and pushing through the moments where imposter syndrome tries to convince you that you don't belong.
Whether you're a student early in your career or someone that's trying to help make this industry more welcoming and inclusive, there's a lot of insight here, not just about cybersecurity careers but about people, growth, and community. Let's take a shift here, and I'm going to go someplace that I know I didn't cover with you before, so it might be a shock. This is right, and I think hands down a male-dominated industry. What do you think? I personally would like to think that gender no longer plays a role in anything within cybersecurity, that we respect no matter what gender you are, no matter what alignment, anything like that.
We treat people equally. But I'm also coming from that, from the heterosexual male standpoint.
What— and, and I want to do is give you the opportunity to either debunk everything I've just said or to give us their opinion. Or more importantly, for the younger audience, maybe the one— the young ladies that are getting at a high— at a— we're in college right now, what would you like to say to them?
Okay, I— and I totally agree with what you said, it is male dominant. It was 17 years ago, probably, when I— and I'll do these air quotes here— really stepped into security. Security has always been a part of my career. It maybe just looked different or was called something different, but really, over the past 25-plus years, security was a part of it. But we'll just say 17 years ago, as I started attending security events, whether that— yeah, events, conferences, um, luncheons, dinners, whatever that looked like.
It, it was me. I'm like one woman to many, many men. It could be 100 men, 75 men. It could be intimate dinners and I'm one of— there's 15, so I'm, I'm the only woman in there, so 14 other men. It still does look like that.
Maybe now at larger conferences, events, maybe It's— oh geez, I'm go— I still would say less than 10%. I'm sure there's a, a, a number out there, a metric out there, but it's, it's very low. What I would tell somebody, a female new coming into this, is you belong. Don't quit. Don't give up.
Um, bring somebody along with you. Um, call me, I will support you. But I am a co-founder of LIFT, Empowered by Women in Security, and it's not just women in security, it's technology, um, too. And what we want to do is bring others along with us. When we lift one, we all rise, and I, I stand strongly beside that.
That is my passion. Also, yeah, find a mentor. And this could be woman or man, um, in the workplace. I would also say get that ally, that male ally. Um, we love it when you support us.
I love it when men support us at work, in our community. And yes, and I know I'm diving into some very sensitive subjects, but really going down to is Do you ever feel like your opinion is not valued because you're a woman? And I have the answer I'm hoping for, but I think as we talked before we started recording here, I'd like you to tell me the truth. Yeah, I don't think it would be my opinion would not be valued because I'm a woman, because I think that could happen even from another female to me.
Another word of advice, speak up. Your opinion does matter. And again, that is that, that don't quit and that you do belong. So that's even being verbal, being present, being there. You do matter.
Challenge yourself. Speak up. I still do that today. How many years have I been in my career? That is what the imposter syndrome So you challenge yourself, talk to a friend, get a mentor, get that ally.
I, I don't think no matter how many years you're in this, I can't say that it's going to go away. I can't say that. Well, I mean, I have to tell you, you know, because I taught college for what I'm— I actually just finished a 6-year stint with multiple universities. And one of the questions I had, I had plenty of women inside my class, some of them very, very sharp, extremely sharp. In fact, actually, I believe that some of the students that I had, some of the sharpest students, especially in my last semester, her name was Dani.
She was sharp. I mean, it was very, very obvious she studied and everything else. And she had asked me the same kind of question. And I told her one of the best hackers that I've actually known in the world She was on my security team. She was amazingly brilliant, and it was a she.
And I mean, in that case, I don't think anybody saw the difference between male or female because of her skill set. I mean, the only thing I had was, well, okay, stop hacking my phones and everything else because— but that has nothing to do with male or female. Just, you're making people angry with that. I mean, just because you can. But I can imagine And, and I, I believe in that case it was completely— gender didn't have anything to do with it.
I would agree with that. There's a question that almost everyone entering cybersecurity eventually asks: what matters most? Is it degrees, certifications, or experience? And depending on who you ask, you'll probably get a different answer every time. In this next session, we'll get about education career paths and what actually helps people break into cybersecurity and grow in the industry.
From community college classrooms to certifications, on-the-job learning, and hiring realities, this conversation challenges some of the most traditional assumptions people have about building a successful security career. We'll also talk about something that doesn't get discussed enough: the gap between academic learning and real-world operational skill. Because at the end of the day, employers aren't just hiring resumes. They are hiring problem solvers, communicators, and people who can demonstrate practical capability when it matters. Whether you're a student, a career changer, or someone trying to figure out the right path into cybersecurity, this section offers us a very honest look at what hiring managers and practitioners are actually looking for.
Well, first off, I guess maybe to make you feel better, I feel like I'm much older than you because I actually was using a lot of those floppy disks to run programs. I was actually working a lot on that. I'd like to tell some of my students I was around before DHCP was a thing. However, however, I wrote down a few things here that I think we should talk about. Probably going to give us back past our allotted time, so hopefully that's okay.
But first off, let's talk about college, right?
I'm going to admit something to the general audience here. I don't have a degree. I taught for the community colleges out in Colorado. I got my teacher certification. I've worked for several companies.
I've taught at the university level, but I don't have a degree, mostly because when I tried to go to school, one, it was too expensive, but two, none of this was reality. Everything was so brand new that by the time the books came out, it wasn't accurate anymore. I knew more than the instructor, and I'm not trying to be arrogant or anything. It's just I worked in the industry already. So let's say that someone is in school right now because they've got to find some way of learning, what's going to be the most important?
Is it going to be a certification? Is it going to be a degree? And I have my pre-canned answer here, but I'd like you to answer this first. Sure. Since we are being very transparent and you shared with me, I too will share my degree.
I have an associate's degree. That's how far I went. Uh, I did get a scholarship for first-generation scholarship. Again, remember, my parents didn't go to college. So I would have went on for that 4-year degree, but life happens.
And then here comes baby number 3. So halfway through trying to get that degree, I'm now like, nope, no more schooling because I'm taking care of— now we're a, what, a family of 5? So husband, wife, 3 kiddos, teaching. I'm— so that means working. And then also going to school, but I, I needed, I needed something more.
So stopped going to school, um, still taught, but that was more of part-time and then full-time job during the day. So I have an associate's degree. I do have certifications though, so I'm a continuous learner, strongly believe in that. Those that are seeking a degree go for it, do it if you can. Yay.
Um, if you can't, that's okay too, because Frank, both you and I here on this podcast, we don't have those degrees, but we have certifications behind us. We also have that work experience. So for me, as I have done the, the job search, it is degree and/or years of experience to, to be equivalent. So always looking for that because I have those years, I have on-the-job training and that knowledge. But that continuous learner, I have to, I have to do that for me personally.
But of course it benefits as well as your job seeking. So I believe in certifications. Okay. Well, I guess my, my answer, and this is part of my talk. So along with working full-time and running the OWASP chapter and SnowFROC, etc., which of course just finished up, up, I teach and I also give talks.
And in one of my talks, I have kind of a shocking subject here. It's called the 4 Realities of Getting Hired Within Cybersecurity. And I know that when I go fly down to BSides Tampa in about a month, I'm probably going to make some people angry because I don't sugarcoat stuff. And one of the things that I talk about is when we talk— talking about certifications and degrees, is what do you lead with when you walk into an interview? Are you coming in there and saying, well, I have a degree in cybersecurity, or is it these are the skills that I'm bringing to the table?
And I think both of us can agree that it's going to be a situation where it's the latter. Nobody cares that you have a degree in cybersecurity, or you— doesn't— nobody cares that you have a certification in digital forensics. What they care about is what benefit are you bringing to me? Is it going to be those hands-on keyboard skills that knows how to run Nmap and more importantly, the results of it, right? And how to interpret those.
Or is it, well, I have a degree so I can do this, right? Yeah, you, you are exactly right. And I've been in the hiring phase since December So doing lots of hiring at the organization that I'm with right now. And I'll be honest with you, as I'm looking through those resumes and applications, I'm diving deep into their experience. What, what have you accomplished?
And yes, I, I take a peek at their education and their certifications, but to me it's more about, yeah, what have you done? What can you done? What is that going to look like when you're here in our organization? That's what I'm looking for. Yeah, well, and one of the things I tell them is that if you list on your resume that you took a course, that you took a boot camp, you took this, that's completely worthless to us.
What was more important to us is you took this course and this is what I learned, and be very, very specific. Show me the skill that you came out with. I took a course in digital forensics. What, there are probably 100 different digital forensics courses out there. There.
What are you bringing to the table? Even if, let's say, for some weird reason there was one, only one digital forensics course, and we obviously know that's not true, doesn't matter. If you have 100 people that have taken a 10-week course in it, not all of them are going to be able to come down and say, well, here is your 3 LSASS processes, or here's this. This is where you have to be very, very specific Again, show me the benefit that you're bringing to me. Right.
That benefit and capability. So I want to share, and I know you had mentioned we might be out of time. We'll see if this, this, if we have a few minutes for this. I have a success story. So it is capabilities alignment.
I don't know what other word we want to use, but I've also hired Um, 2 people, they're still with the state. They have continued to progress in their career. Before I even hired them on the identity and access management team, they weren't in tech. Um, so they didn't have— well, one did have a degree, but it was like a gym teacher type. So that has nothing to do with tech or cyber.
And the other, I think some college college, um, but, but again, nothing that— no degrees. One was working in retail for a phone company, so mobile. And I, and I know what I needed. I needed somebody to come in here, to come in and do some provisioning, do account auditing. So I, through conversation, said, okay, you inventory at your job.
Yep. You provide customer service at your job. Yep. Okay, you configure and provision those cell phones. Yep.
So as those transferable skills— I need customer service, I needed somebody to inventory, audit, audit our accounts, provision access. Will you provision a phone? You configure a phone. I'm going to teach you how to provision and grant access. So it was those transferable skills came in as providing access management, so provisioning, but then through audit and then through governance and lead worker, etc.
And another one worked at a warehouse, and I taught him— I needed you to come in, and this was a contract position. Both of those ended up work contracts, but they're now state employees. Taught him to do provisioning. He now runs the authentication, so account provision, a warehouseman to account provisioning to running authentication. Um, yeah, so transferable skills.
So again, not about the degree, not about the certification, but what can you do? And, and again, I think that you and I are very aligned with some of this stuff, mostly because another young lady, different young lady that I had in my class, one of the things that she had mentioned was, well, my current job has nothing to do with cybersecurity, there's nothing transferable. And I asked her what she did, and she says, well, I'm a bartender. Bartender. And I said, well, I don't think that's true at all.
I mean, but on your resume, you're not going to list, well, I serve drinks. Nobody cares. That's not relevant. But what you are going to be is, as a bartender at the same place for 10 years, can you read people? Like, I walk up, what could you tell about me, right?
And she's like, well, this and this. And my— she had me kind of walk up and things like that. Yeah. And I said, you're right on. So now that is the skill that you need to bring to the table— not serving drinks, but that psychology that, hey, I can read what this person is doing.
I can tell by the way they walk, by the way they react, by their facial expressions, and I know how to adjust to that personality. And they go, that is a skill that you need to bring. That is the value that you are adding to my Absolutely, yes.
In this next section, we'll shift into one of the most fascinating parts of cybersecurity: criminal psychology. What motivates cybercriminals? How do security professionals learn to think like attackers without becoming one? And are today's threat actors really that different from traditional organized crime groups. This conversation goes beyond the technical side of security into the mindset of people behind the keyboard.
We'll talk about motivation, behavior prediction, and the constant challenge of trying to stay one step ahead of attackers in a world where threats never stop evolving. Honestly, this is one of the topics that could probably turn into an entire podcast series by itself. Well, if we've got a few more minutes here. I've got 2 more things, and maybe to spin off of this a little bit, you talked a little bit, or we talked a little bit ago about criminal psychology. How does that play into this cybersecurity role?
And then this may be something where we go for the next 3 hours. Yeah. Well, yeah. Oh my gosh. Those, the threat actors, these are criminals.
So how do we think like a criminal? How do we stay ahead of that next attack? How do we predict what that is going to be? Where is it going to happen within our network, our cloud environment, our identities?
But does it work to get into that mind of us? But is that criminal, that type of criminal, a cybersecurity criminal, the same as your traditional Sopranos-type mobster? No, no. Uh, I don't know, maybe that if we're talking about Sopranos mob type, look at the, the network of the cyber, cyber criminals. Look how far and wide and deep, um, and secretive that they are.
I don't know, then maybe there are some similarities there. Yeah. Yeah. I mean, again, we could probably talk about this and start a conversation. In fact, we could probably do an entire podcast, right, on this subject within itself, talking about what motivates those.
But we are running on, on time here. So let's kind of go to a related side of that. And you talked about teaching at the Department of Corrections. Put somebody that has been arrested and convicted in jail. Work in cybersecurity?
And if so, are there limitations?
Should they— could they work in cyber? Yes, why not? Are there limitations? Unfortunately, yes. Um, yeah, I don't know what that looks like really as far as like now on your application, have you been convicted Of a felony, are we still looking at that and saying, "Nope, we don't want you." But why?
Why not? Right. To me, yeah. Why not? Well, well, I mean, like I was talking to I think somebody over at like Jiffy Lube, like the manager at Jiffy Lube, and he goes, "What?
Half my staff are ex-convicts, some of the best workers that I've ever met." I applaud that. Absolutely applaud that. And I've actually talked to and worked with people that have been convicted of a felony, right? And maybe they are barred from certain areas, like they'll never get a secret clearance or anything like that. They may never get that kind of stuff, but there are plenty of jobs within cybersecurity where that is not required.
I mean, yes, they, they may be monitored, et cetera, things like that. Also depends on the nature of the crime. And, and what they were convicted of. But, right, is there hope? And I'm hoping that, that there is that case, that each person judges.
Yeah, absolutely. I hope so too. Okay, in this final section, we talked about the growing challenge of speed in cybersecurity— how quickly attacks evolve, how fast defenders are expected to respond respond, and how pressure organizations feel to continuously adapt, train, and scale. We'll also explore the human side of that speed— burnout, mental health, mentorship, and the need to invest in people just as much as technology.
Well, we are at the end of the time, but I always ask— like to ask the biggest question, and I do this at the very end of every podcast here. What is the biggest challenge within cybersecurity today? And I'm not asking you to solve it, but just can we identify it and maybe go with some paths forward?
The biggest challenge I'm going to say is speed. And what do I mean by that? So the threats that are out there— so the threats that are out there— AI, of course AI was going to come up, but even so, threats, protecting yourself that incident response, the training your staff to be able to act as quickly for that incident response, um, the speed. So resources— how quickly can you even staff up your team? Can you get these resources in?
Um, when you have these resources in, because of the speed of things, the demand— does burnout come play a part of that? So what about the mental health, really protecting our employees, our number one assets. And those resources, again, upskilling because, because of AI and how quickly the speed technology changes. Always, hence why I'm a continuous learner, really. Yeah, upskilling, being that forward thinker.
So again, if I summed it up, it's speed. Speed. All right. Well, I, again, I think that we could go on for another hour and maybe we have you back on again to talk about things like that, criminal psychology, to talk about speed, how to do things better. And I know that one of the things we wanted to talk about but didn't get to was things like mentorship.
And again, I think ultimately important, but absolutely. Um, again, I think we've got to cut this at least to— I always tell Robb and, and Alex that we'll keep this to an hour. And I think in the last 3 podcasts, I've gone way over, right? Right. So, but I think this one will go over as well.
However, however, I think that I can't go to an hour and a half or 2 hours as much as we'd like to. So we'd love to have you back on at a later date if that's okay. Absolutely. I had a great time with you today, Frank. Oh, and I as well.
All right. Well, hey, thank you everyone that's listening. Keep logging in. So what's that phrase? Like and subscribe.
And hopefully we'll see you at what, RMISC and those other type of cybersecurity conferences. If you see Yvette or myself, and we can be found up on LinkedIn and we'll provide the links in the show notes, definitely stop by, say hi, let us know some feedback on this podcast. Good, bad, or indifferent. Yes. All right.
Thank you, Yvette, so much. Thank you.
Learn more about the Colorado Security seen at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado Equals Security.