Colorado = Security Podcast

Colorado = Security Podcast

By Alex Wood & Robb ReckTechnology
Download on the App Store

Colorado = Security Podcast episodes

  • 289 - CEO SpyderSec, Principal Instructor/Course Author - SANS Institute
    Welcome back to Episode 289 of the Colorado Equals Security podcast with Joe McCallister and Chelsea Weiss!
    This month, we are hitting the biggest tech and security headlines impacting the Front Range and beyond:
    Big Tech Moves: Breaking down a massive $100 million federal grant for Broomfield's Quantinuum, Amazon's new 70-acre land grab for an Aurora distribution hub, and a Denver company's long-haul fiber deal with Nvidia.
    Culture & Infrastructure: How a new Denver Oktoberfest is brewing up serious economic ties with Munich, plus a look at Rowan Digital Infrastructure's $4.2 billion data center project in Texas.
    The Cyber Frontlines: We unpack the Rockstar Games compromise, the rising threat of AI "vibe coding" creating a new generation of shadow IT, and why modern security leaders must act as business accelerators instead of just playing gatekeeper. Stick around for our comprehensive rundown of September's local security events, including all the details you need for the upcoming Security Leader Summit Six!
    In this month's wide ranging and candid conversation, Frank sits down with longtime friend and
    cybersecurity leader Serge CEO of SpyderSec to explore the messy, fascinating, and often uncomfortable realities of modern cybersecurity.
    Across multiple segments, they dig into:
    Why pricing in cybersecurity consulting is so chaotic
    How subcontracting layers distort cost and value
    Whether U.S. citizens should ever be allowed to “hack back”
    The ethical responsibility of instructors when teaching offensive tools
    A real world story of shutting down an unethical classroom exercise
    The biggest strategic challenge facing CISOs today — and why authority rarely matches
    accountability
    This episode blends real experience, tough questions, and honest discussion — exactly what
    Colorado = Security listeners expect.
    1 hr 39 min
  • 287 - Tanya Janca - CEO of SheHacksPurple Consulting
    Our featured guest this month is Tanya Janca, CEO of SheHacksPurple Consulting, board member for the Forte Group, and former keynote speaker at the Snow Frog conference, interviewed by Frank Victory. We break down the stark differences between privacy and cybersecurity policy globally, the uncomfortable gap between compliance frameworks and real-world risk, and her personal crusade to institute the world's first secure coding law. Plus, we dive into the major Colorado OIT restructuring, local development updates at DIA, and the latest threat intel and AI insights from Zvelo, Red Canary, Optiv, FusionAuth, and Lares!
    Our featured guest this month is Tanya Janca, widely known across the industry as SheHacksPurple. Tanya is the CEO of SheHacksPurple Consulting, a board member for the Forte Group, a former keynote speaker at the SnowFroc conference, and the best-selling author of Alice and Bob Learn Application Security. With over 25 years of IT and software development experience, Tanya joins Frank Victory for a candid, deep-dive exploration into the intersection of global security policy, developer workflows, and the massive disconnect between checked compliance boxes and truly defensive software engineering.
    Check out the full episode where we discuss:
    The Policy vs. Security Gap: Why international frameworks and high-visibility initiatives like the US SBOM Executive Order often favor visibility and tooling purchases over actual vulnerability remediation and code-level security.
    Shifting Left and Secure Guidelines: Why the industry routinely relies on catching vulnerabilities late via adversary simulation and penetration testing rather than establishing secure requirements, guardrails, and clear guidelines at the design phase.
    The Secure Coding Law Crusade: Tanya details her current petition in the Canadian House of Commons to establish a strict, accountability-driven secure coding law that could set a global baseline for how governments and private enterprises hold software to a true safety standard.
    Come join us on the Colorado = Security Slack channel to meet old and new friends.
    Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at [email protected].
    This Month's News & Resources
    Colorado overhauls state IT office, lays off 173 employees after negative feedback (Colorado Sun)
    Colorado’s fierce two-year fight over AI regulation ends with watered-down law, little fanfare (Colorado Sun)
    Denver ranks among ‘most exciting U.S. cities to drink in right now’ (Westword)
    Denver airport plans pedestrian walkways between concourses (Ground News / DIA)
    Denver-area inflation increases to 5%. Blame energy costs. (Colorado Sun)
    How Lares Thinks About Mythos-Class AI in Offensive Security (Lares)
    The Security Risks of Agent-to-Agent (A2A) Communication (zvelo)
    Red Canary May Threat Intel Highlights (Red Canary)
    Advanced AI Protections for CISOs: A Practical Punch List (Optiv)
    We Surveyed More Than 300 Security Leaders on AI Identity. The Findings Are Counterintuitive (FusionAuth)
    Tanya Janca on LinkedIn
    https://cppcon.org/
    https://www.devsecstation.com/
    https://shehackspurple.ca/
    Secure Coding Guidelines — Tanya’s free, boiled-down 84-item guide referenced in the episode.
    Upcoming Events
    Rocky Mountain Information Security Conference (RMISC) - 6/23-25.
    ISC2 Pikes Peak - 6/24.
    ISSACOS Biergarten - 6/25
    Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at [email protected]. Check out his other voice work here.
    Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0
    1 hr 48 min
  • 285 4:13:26 - Newscast
    News from Impulse Space, Anthropic, Colorado DOT, CU Business School and more - as well as some great research and blogs from Red Canary, Zvelo, and Optiv. Also meet your new hosts Joe and Chelsea!
    Come join us on the Colorado = Security Slack channel to meet old and new friends.
    Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at [email protected]
    Support us on Patreon! Fun swag available - all proceeds will directly support the Colorado = Security infrastructure. Come join us on the new Colorado = Security Slack channel to meet old and new friends.
    This week’s news:
    Name the train: Colorado Front Range rail leaders ask public to vote on finalists
    Broncos push for ambitious stadium timeline, while city leaders weigh neighborhood desires
    Golf-themed coworking expands in Greenwood Village, eyes Cherry Creek
    Space company founded by SpaceX veteran expands to Colorado manufacturing hub
    Colorado business leaders are still negative about the future economy, though less so than last year
    Moving up the Assemblyline: Exposing malicious code in browser extensions
    Continuous Threat Exposure Management (CTEM) – What Is It and Why Do You Need It?
    The Security Intelligence Supply Chain
    Labor market impacts of AI: A new measure and early evidence
    Top 5 Signs Your Identity Program Isn’t Ready for 2026
    Upcoming Events:
    SnowFROC 26
    Denver ISSA - How Quantum Computing will unlock and unleash AI - 4/8
    ISACA Denver - April Chapter Meeting (AGM) - 4/16
    ISC2 Pikes Peak - 4/22
    SANS Rocky Mountain - 4/20
    * Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at [email protected]. Check out his other voice work here.
    * Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0
    47 min
  • 284 - 3:9:26 - CJ Cox, COO @ Black Hills Information Security
    Our featured guest this month is CJ Cox, COO of Black Hills Information Security, interviewed by Frank Victory. News from City of Denver, Block, Zvelo, Lares, FusionAuth, RADICL, Ping Identity, Red Canary and a lot more!
    We often talk about cybersecurity as a series of technical hurdles, but CJ frames it through Maslow’s Hierarchy of Needs. At the bottom? Paying the mortgage and surviving the 4th-quarter burnout. At the top? Self-actualization. Doing great work with cool people. But here’s the kicker: CJ argues that real security doesn't come from the name on your badge or the company you work for. It comes from your internal capability to learn and adapt.
    We’re experimenting with a new, long-form format on the podcast to explore these "human" elements of the industry—the leadership, the culture, and the "why" behind the "how."Check out the full episode where we discuss:
    Why BHIS says "No" to multi-million dollar buyouts.
    The "Borg" effect of corporate acquisitions.
    Why building a SOC is a three-year slog, not an "easy button."
    Come join us on the Colorado = Security Slack channel to meet old and new friends.
    Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at [email protected]
    This week’s news:
    Colorado ranks 28th for family-friendly home buyers in national study
    Block cuts 61 Colorado jobs in AI-driven automation push
    Denver turns to AI to help fix permitting speed, consistency
    Denver set to pause data center development as mayor joins call for moratorium
    Colorado man, cybersecurity experts and BBB warn about AI deepfake scams
    Building the Future of Defense Tech
    Your Token Proves Who You Are, Not What You Own
    The Visibility Gap: 5 Purple Team Tests Your EDR is Probably Missing
    AI Model Drift Is Inevitable. Trusted Intelligence Requires Human Supervision.
    Breaking down a supply chain attack leveraging a malicious Google Workspace OAuth app
    Upcoming Events:
    Check out the full calendar
    ISSA COS - March Chapter Meeting -3/10
    ISSA Denver - March Chapter Meeting - 3/11
    IdentiBeer - 3/18
    Denver OWASP - MCP LFI in 60 minutes (or your money back) - 3/18
    ISACA Denver - March Chapter Meeting (virtual) - 3/19
    ISC2 Pikes Peak - 3/25
    ISACA Denver - CISA Spring Training Classes - 3/28
    View our events page for a full list of upcoming events
    * Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at [email protected]. Check out his other voice work here.
    * Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0
    1 hr 28 min
  • 283 - 2/16 - Cody Cornell, CEO of Swimlane
    Our featured guest this monthCody Cornell, CEO and founder of Swimlane, interviewed by Frank Victory. News from Great American Beer Festival, Lumen, Zvelo, RADICL, Ping Identity, Red Canary and a lot more!
    Welcome back to the Colorado = Security podcast, where today we’re trading the icebreakers of Antarctica for the high-stakes world of global SecOps! Join us as Cody Cornell, the visionary CEO of Swimlane, reveals how he pivoted from the front lines of the Coast Guard to building the future of security automation. It’s time to find out if your organization is a fortress of governance or just a glass house waiting for a stone—let’s dive in!https://www.linkedin.com/in/codycornell/https://swimlane.com/https://www.linkedin.com/in/frank-victory/https://snowfroc.com/
    Come join us on the Colorado = Security Slack channel to meet old and new friends.
    Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at [email protected]
    This week’s news:
    Great American Beer Festival relocates from downtown Denver
    Colorado now has 6 million people, even amid slowing population growth
    Denver-area telecom completes $5.75B cash sale to AT&T
    Louisville tech company nears public offering
    Energy, data center tax break debates set to kick off in the Colorado legislature this week
    Agentic AI Security Exposes the Limits of Zero Trust
    Swimlane Introduces Fleet of AI Agents and Agent-Builder
    RADICL Secures $31M to Accelerate the Future of Autonomous Cyber Defense for SMBs
    What is Zero-Knowledge Biometric Authentication? A Simple Guide for Security Teams
    Go jump in a lake: Measuring the data lake effect on your SIEM | Red Canary
    Upcoming Events:
    Check out the full calendar
    CSA Colorado - Enabling AI: Rules of the Road - 2/17
    ISSA COS - February Trivia Night - 2/19
    ISACA Denver - February Meeting with the IIA - 2/19
    ISC2 Pikes Peak - 2/25
    Denver ISSA - AI/ML Special Interest Group - 2/25
    View our events page for a full list of upcoming events
    * Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at [email protected]. Check out his other voice work here.
    * Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0
    1 hr 24 min
  • 282 - 1/5 - Matt Sharp, Ian O'Neill & Jason Godley at Xactly
    Our featured guests this month are Matt Sharp , Ian O’Neill and Jason Godley at Xactly Corp, interviewed by Frank Victory. News from Inspirato, Optiv, Lares, Ping Identity, Red Canary and a lot more!
    The Security Triad: Turning Risk into Revenue: Step inside the boardroom to see how top-tier leadership turns cybersecurity from a "no" into a "go." In this high-energy conversation, Jason Godley (CFO), Ian O'Neill (Legal Counsel), and Matthew Sharp (CISO) pull back the curtain on the "Security Triad"—the collaborative engine driving Xactly’s massive business transformations. Discover how they’ve shifted security from a perceived bottleneck to a revenue powerhouse with a staggering 80%+ revenue attachment rate on enterprise deals. This is a masterclass in navigating the legal liabilities of Generative AI, mastering the "Speed of Trust," and using a best-in-class security posture to outpace the competition and win in the enterprise market.
    Come join us on the Colorado = Security Slack channel to meet old and new friends.
    Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at [email protected]
    This week’s news:
    Colorado’s First Treehouse Hotel Is Open (and Gorgeous)
    Local travel company acquiesces to $59 million purchase offer
    President Trump signs executive order in bid to block state AI regulations, including Colorado’s
    Colorado courts’ fragmented system for sharing evidence needs statewide fix, task force finds
    2025 Industry Threat Profile
    Audit Success vs Operational Resilience: Understanding the Gap
    What Is Human-in-the-Loop AI and Why It Matters for Identity
    When adversaries bring their own virtual machine for persistence
    Upcoming Events:
    Check out the full calendar
    ISSA COS - January Chapter Meeting - 1/13
    ISSA Denver - CTI Revolution Starts Now: Building a Business-Centric Intelligence Program - 1/14
    ISACA Denver - SheLeadsTech 2026 Climb and Carry (7 CPE) - 1/23
    ISSA COS - January Workshop - 1/24
    ISC2 Pikes Peak - 1/28
    View our events page for a full list of upcoming events
    * Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at [email protected]. Check out his other voice work here.
    * Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0
    1 hr 30 min
  • 281 - 12/8 - Shane Cox, Director Cyber Fusion Center @ MorganFranklin
    Our featured guest this month is Shane Cox, Director Cyber Fusion Center at MorganFranklin Cyber, interviewed by Frank Victory. News from Denver Summit FC, EchoStar, Atom Computing, Quantinuum, Ibotta, Optiv, FusionAuth, Swimlane, Red Canary and a lot more!
    Come join us on the Colorado = Security Slack channel to meet old and new friends.
    Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at [email protected]
    This week’s news:
    Denver Summit FC to debut at Empower Field at Mile high, eyes attendance record
    EchoStar founder Charlie Ergen returns as CEO amid $19.6B SpaceX spectrum deal
    Ibotta celebrates new downtown Denver headquarters
    Two Denver-area tech firms advance in $300M quantum competition
    Cyberattack on CodeRED forces Douglas County Sheriff’s Office to seek new alert network
    Threat Modeling of AI Applications Is Mandatory
    The Authentication Rabbit Hole: What I Learned From Vibe-Coding Auth with AI
    92% Breaches Preventable with AI Automation
    Stay on top of GitHub vulnerabilities with Dependabot Configurator
    Upcoming Events:
    Check out the full calendar
    ISACA Denver - HOLIDAY PARRRTAAAAYYY - 12/11
    Colorado = Security Gives Back - 12/13
    View our events page for a full list of upcoming events
    * Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at [email protected]. Check out his other voice work here.
    * Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0
    1 hr 4 min
  • 280 - 11/3 - Chazz Gifford, VP Information Security @ Intrado
    Our featured guest this month is Chazz Gifford, VP Information Security @ Intrado, interviewed by Frank Victory. News from Palantir, Lumen, the State of Colorado, Red Canary, Optiv, and a lot more!
    Come join us on the Colorado = Security Slack channel to meet old and new friends.
    Sign up for our mailing list on the main site to receive weekly updates - https://www.colorado-security.com/. If you have any questions or comments, or any organizations or events we should highlight, contact Alex and Robb at [email protected]
    This week’s news:
    Checkr, Chevron decisions push downtown vacancy up again in third quarter
    Palantir enters $200M partnership with telco Lumen to offer enterprise AI services
    Colorado plans to fully digitize paper and analog land records, some dating back to the 1860s, by next year
    Police used Flock cameras to accuse a Denver woman of package theft. She had her own evidence
    Governor Polis Proclaims October 2025 as Cybersecurity Awareness Month “Stay Safe Online”
    AWS down: How a single network outage rippled through businesses, institutions and the economy
    Colorado attorney general sues Trump administration over Space Command HQ relocation to Alabama
    Privacy Protections for Children's Online Data
    Navigating the Vast AI Security Tools Landscape
    Commanding attention: How adversaries are abusing AI CLI tools
    Upcoming Events:
    Check out the full calendar
    Denver ISSA - AI: The Good, The Bad, & The Ugly - 11/12
    ASIS - That's a Wrap End of the Year Happy Hour Party - 11/12
    ISC2 Pikes Peak - Chapter Meeting - 11/19
    ISACA Denver - November Chapter Workshop with ISC2 - 11/20
    ISC2 Pikes Peak - Chapter Meeting - 12/5
    ISACA Denver - HOLIDAY PARRRTAAAAYYY - 12/11
    View our events page for a full list of upcoming events
    * Thanks to CJ Adams for our intro and exit! If you need any voiceover work, you can contact him here at [email protected]. Check out his other voice work here.
    * Intro and exit song: "The Language of Blame" by The Agrarians is licensed under CC BY 2.0
    1 hr 38 min

About Colorado = Security Podcast

From the publisher's feed

Podcast by Alex Wood & Robb Reck