Still Cyber Podcast Ep 03 – Is Government–Industry Cybersecurity Collaboration Breaking Down?
On this episode of Still Cyber, Mitch Ashley and Alan Shimel are joined by cybersecurity veteran Kate Scarcella to examine how political shifts, leadership changes, and budget pressures are reshaping the government–industry partnerships that underpin national cyber resilience.
Transcript
Hey everyone, I'm Alan Shimel. And I am Mitch Ashley. And you're listening to Still Cyber.
Cyber After all these years, baby. Yeah, baby. Still cyber.
Yep. Still cyber. Mitch, it's good to have you back on here.
Well, I'm glad to be on here with you. Um, always, you know, I'm having fun doing this one. It is.
Well, we always had fun doing these, Mitch. We did. I think we, we laughed as much as we talked Yes.
Back in the day. Maybe. Still do.
Yeah, we do. We do. We're gonna have to do one live in RSA Yo, but Stone Cold Sober this year, please.
Stone cold. Okay. Well, I don't know about that, but we'll see.
Alright, well, I don't drink, so I don't have a choice, but anyway. Hey, we are really happy to have a guest on, uh, this episode. I want to introduce you to our friend Kate Scar.
Uh, Kate brings over 20 years of experience in cybersecurity and critical infrastructure protection. I'm not reading my bio or your bio, Kate, tell the people who you are. Yeah.
So I have, I've been doing this for it seems like just more than, uh, just decades, man. I was one of the people who went to Radio Shack, so there you go. Um, but, yes, Yes.
Uh, but yes, I, um, Hey, look, I, I love cybersecurity and it has definitely been a passion of mine since, uh, since identity management, since vulnerability management. It's, you know, and I could just keep going, uh, with this, on this role. But, you know, more importantly, I think in this discussion for me and why I am so excited is, of course, today is about critical infrastructure.
Mm-hmm. As I was telling you earlier, I actually got my master's thesis in securing the North America grid, the electrical grid. So I love, um, this discussion.
I love where the Internet of things and the industrial Internet of things and everything that encompasses including, uh, what it means for our government. So you're the person that's gonna solve that. I, and you've been here all the time.
Just right under, you know, right under her finger. Right under our foot. Hiding in plain sight.
I'll tell you. Yes, yes. You know, I, I will say that.
I, um, my thing is I don't wanna retire until this is solved, so, oh. You know, Be careful what claims you. I know.
Be careful why, I was just gonna say, careful what you wish for, though. You're a lot younger than us. But, um, anyway, guys, today's, today's episode grows out of an announcement Last week, something I wrote about, um, the RSAC folks, the people behind RSA conference or SAC conference announced that none other than Jen Easterly was gonna be their new CEO.
Fantastic. And I, I applaud it. I thought it was a bold move.
Um, you could go read my article if you want the background, but, you know, Jen Easterly is truly a leader of the, of a, of this community. Truly someone who has the chops, the experience, the talent, the skill and the gumption and the relationship. The lead Yeah.
And the relationships to lead. Yeah. Yeah.
You know, she West Point grad, 20 years in the, in the Army. She was then the director of Csar after our Frank Chris Krebs left, um, with the new administration, along with many of the, of the rest of the leadership there. She, she was moved out of Csar as Cesar's budget was, was cut.
And then her chairpersonship at West Point was taken out from under her by the administration. I'm not here to make this a political discussion. What I am here, though, is to talk about what's happened to CSA under this current administration.
And, you know, one of the great things about CSA was part of the charter was working with private industry mm-hmm. Forming that public private partnership. Yeah.
To protect critical infrastructure, because it's too critical. No pun. It's too critical, right.
To go it alone. No one private company probably has the resources to stand up to some of these nation states. The government itself doesn't have the reach or wherewithal sometimes to do it.
I really feel like we're making a grave mistake by not encouraging this public-private, in, uh, you know, partnership towards protecting our infrastructure. Mitch, I know you feel the same way. It, it, um, yeah, there's kind of a hollowing out is, is what is the hard part to accept about it.
Um, 'cause so many good people left and, you know, the, the mission has, I dunno if I'd say subtly changed, um, but it, it, it, I I have less confidence in it than I did at one point. Not to say we can't return and, and build that back as well. But I think we have to look at it as, okay, that's happened.
Now what do we do? Right? What do we do to help these people succeed?
And how can we help influence? And maybe Jen can do some great things. I know she will as part of RSAC that might be part of it.
But, you know, the security's a community. It's Yeah. And I know you all agree about with me on that.
Yeah, it is. So, so, Kate, your, as you mentioned, your master's, you know, your graduate work is in critical infrastructure, specifically around the electric grid. And that's a perfect example of a private public, uh, right.
Partnership. Right. You have private utilities, private electric companies.
And not only that, you know, it's like the car business. It's not just gm. It's all the third party suppliers.
There's a ton of third party suppliers and supply chain and everything else that goes into the electric grid that we all rely on. And it's kind of take for granted, can, can it survive without a government private partnership? Is it mandatory?
Are we all less because of it? I think at the end of the day that we're, we're less because of it for a lot of different reasons. I mean, first, when you look at, you know, and I know that people in business push back against, um, regulatory bodies.
You know, I understand that sometimes regulation seems that it, it just becomes very, um, heavy handed and difficult to manage. It's unfortunate that we need regulation in order to have people to do the right thing. But for example, the North American Electric Reliability Corporation, nerc, um, you know, they came out really providing guidelines for, for interconnectivity of the grid.
And it, it helps, it helps for all of us, for, for this United States to have governing bodies to help us, you know, distribute, um, energy and to be safe about it. And that's the key word, right? Is, is safe.
Um, we want it to be safe for us to use. And let's not forget, I mean, in order for the lights to maintain, you know, we've all seen what happened in Texas when there was an ice storm. Um, and we've all seen what, you know, even let's not forget nuclear regulation.
It's all part of the NERC as well, N rrc. Um, it's so important to have the collaboration. And, you know, one of the things that I saw out in the field, um, with, um, working with field engineers, uh, in, with the electric company, people care.
People actually care. They want to do things safe. And, you know, by providing guidelines, it helps people not to be like, like just shooting in the dark.
Like, okay, what are we working for? What are we working towards? It really does provide us this structure, this framework, in order to, to, to be safe for all of us, you know?
Absolutely. Y you know, Mitch, I remember 2005, 2006 going with you to some of these ner and ferc Ner ferc, remember NER and FERC Ner and the Ner and FERC meetings And, and not conventions, but conferences. I'm Sorry.
Sorry. Those were the days, you know, it sounds like ney, right? He was ferc.
I was nerc. But, but anyway. Oh my gosh.
But anyway, we used to go to NERC and FERC meetings, Mitch and I, and we, and we'd listen in and, and you know, and I, I remember that that's when it first dawned on me, my God, we're this close away to a disaster. Yeah. Right?
Yeah. Right. Uh, uh, it, it didn't take much.
And this security stuff that we're talking about, 'cause we didn't call it cyber that we called it security stuff. InfoSec, this InfoSec stuff we're talking about is all that standing between us and disaster. And, and I was so grateful that we had NERC and FERC all getting aside mm-hmm.
This, this framework of cooperation between public utility, private companies, the government. And they were constantly saying, Hey, what's best practices? What could we do?
How do we keep it better? How do we secure it? And I, and I, I think that was a great model.
Um, I was even happier when CA first came on. I remember at the first RSA where CSO was involved, the RSA conferences. And it was such a fresh breath of fresh air that it wasn't just the government saying, look, I just gotta worry about an MCI or, you know, some government network that I'm, I'm worried, I'm worried about, no, we're gonna worry about public and private networks.
We're gonna work with you. And we're not just going to sit up hide. Like in God giving the 10 Commandments to Moses or something.
We're, it, it was truly a partnership where we're gonna collaborate and work together. And if we hear something through the CIA or the NSA or some of our National Intelligence services that's germane to you, we're gonna bring you in on that to make sure you're, you're hardened and protected. And, you know, we're, we're not gonna have a digital nine 11.
How's that sound? No, that's heavy. Boom.
Yeah. In fact, that's what, um, my thesis paper was. It was called the a pearl, a Digital Pearl Harbor attack.
Really? Yeah. Okay.
There you go. Yeah. And, and, you know, with critical infrastructure, one of the things that I make a poor joke about that I'm still in this industry and not a comedian somewhere, is that, um, when I did my, my thesis, it was on this, um, it was about critical infrastructure being taken down.
It was the, it was a diehard, I love diehard. And, um, it's live free. Your die hard.
It's a Christmas move. Me. Thank you.
Thank you for Yes. But the idea that if we take down our critical infrastructure, um, you know, in that movie that they did well, is that they took the attention and went over to the financial industry, right. And started to take from the financial, and that was this whole idea about how our grid actually, you know, you take down our grid and how much is impacted, um, and why we need government, um, collaboration is so, it, it, it's imperative to keep us safe.
So I connected back to, uh, I'll bet you cited him in your, in your research, in your, in your thesis. Uh, Richard Clark, do you remember when he came to speak at, uh, RSAC? That was Sure.
That was a huge deal. Just having someone who was, you know, US National Security Official was from multiple presidents, from multiple president going back Richard Clark, 2001, if I remember when that was. Somewhere around there.
Close to that is when he started. But he was the first national speaker I know of that was talking about critical infrastructure. Yeah.
Um, you know, that was back in the days of, we did kind of experience our own version of that. 'cause Code Red and I Love You Virus would take down every business. Right.
Uh, that ran email, I mean, really had things out there that did impact everybody. And you could, you could feel that. Yeah.
And Seql slammer, I mean, you know, I remember Yeah. What I was doing, you know, when Seql slammer hit, I remember You guys are old. I don't remember any of that.
Yeah. We'll sit on the front porch and, and, uh, take it back. Yeah.
Yeah. Have lemonade iced tea. Right.
Marles and Jane. But, but, but here's the thing. Over the course of the last 25 years, all kidding aside, we have seen this public private partnership grow, not contract.
We've seen it blossom. We've seen it be rich, right? Mitre mm-hmm.
Which is kind of quasi-governmental in their relationship with private industry. Uh, NIST does a great job of working with, with private security, with the security vendor community, um, the FBI, right? The FBI, I mean, look at, uh, remember our friend Tony from NSA, Mitch, I forget Tony.
Oh, yeah. His, the last name he ran, he ran the red teams at NSA. Yep.
Uh, he's Tony Sanger, I believe his last name. I think it's a, that sounds right. Yep.
Um, Tony Sanger. So, you know, there's a rich history of not only the public-private partnership between government and, and industry, but between government InfoSec resources and private InfoSec resources. And in them meeting at conferences like RSA conference, like Black Hat and DEF Con, right.
In regard, remember meetings most all that. Yeah. No, but you go to DEF Con and the feds were there, right.
They were recruiting there, right? Mm-hmm. Um, this was, I think, part of, you know, you know, what they say about security, nothing happens.
And it means you did your job. This was part of why maybe some things didn't happen. Yeah.
Right. Is that part of it? Let me ask you both a question, and I'm, I'm gonna take a very simplistic approach to this.
I realize this, but I think one of the big things that led to the 17% cut, or whatever it was in the CISA budget, is because there were, they were addressing election security and things like that, which, you know, is, is a political hot potato. Um, now that, that's kind of out of their mission, at least made by the Trump administration, do you think CSA can get back to, 'cause they're supposed, they're supposed to protect the federal networks and infrastructure. Do you think we can get back there now that, that sort of, we've laid aside the election security issue from Cissy Charter?
Kate, do you wanna go first? You know, honestly, it's a, a great question. And honestly, though, I, I don't think so.
I, I think, um, if people don't understand the value that the industry brings, um, then I, I don't think that they're going to invest in it overall. I, I don't, and I think that there's a lot of people who don't understand what cybersecurity is or, or what we do. And so I think it's sort of like a, that's what I think.
Anyway, we're not wrong on this. So, Mitch, I'm, I'm, I'm surprised to hear it was only 17%. I think there might have been 17%, but then there was other money that was shifted from CSA to ice.
Yeah, yeah. I'm sure that was, it was like a thousand people was the cut. But that may have been just part, that was just the head count.
Yeah. But budget over and above head count, a lot of their budget went over to ice, all under the DHS kind of umbrella. I was just remember.
But, but, but here's the thing. It, it's not just the amount of money that was taken out. It is the heads.
You lost some really good people, like a Jen Easterly, like our friend Alan Friedman, the kind of father, the father of SBOs. Yeah. Yeah.
Right. I, I'm friends with Alan on Facebook. I still stay in touch, but man, it's hard to replace those kinds of people.
And at the same time, as you mentioned, I think the mission's changed. The mission is no longer necessarily to work with private industry to protect all of critical infrastructure. It's to protect specifically government networks, maybe.
And can they do that? Perhaps apps, You know? But as, as we said in the beginning, we're all worse off for it.
We're all worse off for it. Government networks don't exist in a vacuum. Yeah.
You know, the one thing I, I think though, about our community, the cybersecurity community, is that you have a lot of people who care. And I think that this caring and, you know, I think it, it will actually take us to a different place that we want to, as you know, wanting to secure people, that you're gonna see some pretty cool things, I think stand up at the end of the day, because I think the people want it. I think we actually care.
And I think because we care, you're gonna see some, some pretty cool things that will be stood up because of, of this pushback. That kind of brings up the second part where I wanted to go. Unless, Mitch, you, did you have something?
No, go ahead. Yeah, I'm just thinking here. You know, shortly after I, um, wrote my article and we spoke about it, uh, there were reports out of the government as a, as a result of Jen being appointed the CEO over at RSA, the government was contemplating pulling all resources.
They weren't gonna let any of the agencies or even the individual employees attend RSA, they were, because of Jen being there, they were gonna basically pull out A-R-S-A-R-S-A conference. Excuse me. And well, you talk about cutting off your nose, spite your face.
Yeah. Right. Who, who wins there?
No one wins. You. You just losing all around and, you know, nature rapports a vacuum, right?
And so, in the vacuum of the government pulling out of working across industries to, to protect our infrastructure, our critical infrastructure, who takes their place? Well, it's a big hole to fill. It's a big gravity sink, right?
That's outta there. But, you know, you would hope maybe an organization like RSAC that is trying to move beyond just being a, a once a year conference, but to truly be the world cyber community, maybe they can help forge these kinds of partnerships, these kinds of relationships that we're gonna need. I mean, the threat as, as I'm sure you're aware, Mitch, and certainly you are, Kate, the threat to our critical infrastructure hasn't lessened No, no.
You think is greater. Yeah. It, it really is.
Because, you know, something that we don't talk about is the internet of things and mm-hmm. You know, cameras and cameras are in critical infrastructure everywhere. So that, that's like one huge pathway.
All the, um, systems, uh, IOT systems, uh, entryways, uh, badge access controls, again, all systems that are, that are built on free realtime operating systems on free R toss. And I, and as I would walk into, uh, you know, to a place, I mean, as I looked around, I'm like, you know, there's no, there is, there is no agent on these IOT systems. And of course, the IIOT systems don't have agents, you know, the industrial internet because they're too darn old.
So, and then there, there are 40 billion devices out there, folks that are just, you know, hello, wild, wild west. Here we are. And yeah.
With no visibility. So, you know, we're, you know, ro You know, I'm reminded Mitch, remember going after we, Mitch and I used to spend about a week, a month, every month we spend one week up in Chantilly, Virginia and be all around the, the, you know, the beltway area Court, Marriott, the court. Yeah.
For now. That was our home away from home. Um, and we had a good friend, Stu Mitchell.
Stu must be retired. Retired now he's retired up there. Yeah, he's retired.
I've talked to him. Yeah. Yeah.
Stu was like a deputy Seesaw, maybe the CSO at the Department of Interior. Mm-hmm. And Kate, Mitch and I would go up there and meet with Stu, and it was great.
He would arrange, we would get like VIP tours of the Lincoln Memorial and Oh, nice. And Mitch and I would always go to the Smithsonian and, you know, we were like two little kids in a fricking pond. But, um, it was interesting, even back then, this is like 2004, 2005, even back then, you know, talking to the US Geological survey people, now they've got sensors on the top of the mountains.
Yeah. Weather, earthquake, you know, all kinds of sensors. I'm sure there's probably early warning stuff put in there too.
They've got sensors on the bottom of the sea also for earthquakes and waves sub also, again, probably submarine sensors. Mm-hmm. And you would talk to them about, Hey, what are you doing to secure all these senses?
What do you mean We're scientists? We're scientists. We don't secure these things.
We want 'em to be open. We don't wanna lock 'em down. Right.
And we had to like really make a case for why they had to build security, even JPL going out and was in New Mexico or Albuquerque, I can't remember where. No, not JPL That was wasn't Los Alamos, it was White Sands. White Sands.
That's what it was. Yeah. That's Department of Energy.
Yeah. Yeah. You know, talking to the scientists.
Yeah. They, they didn't see the need because they thought that the only people who would ever be interested in those kinds of devices, Kate, were other scientists. Right.
It never occurred to them. Yeah. You know, my what an innocent naive time that was, huh.
Compared to now. I honestly, and, and it's, um, it's, it's not much difference with these iot devices. You know, think about, you know, even, um, cameras that we have, um, for security, whether it's in the, you know, the subway systems or even the, the lights, um, you know, they're all actually connected now.
Yeah. It is so interconnected more than ever. Oh, absolute.
So it's, you know, if you watch like the Mission Impossible movies or some of these movies where the hacker Yeah. Breaks into the traffic light system and the camera system and there you go. It can change all the lights, green or red, so you can go and, and get away.
You know, it, it is all, but, you know, let me bring it back though. How do we, how do we fill the vacuum? Or maybe we just don't, lemme throw out idea.
It, it's very, it's highly impractical. It's not the right idea, but just kinda sharing experience. One, one of the things I learned along the way of kind of budgeting software for IT projects or whatever things I was in charge of is in big companies, I learned the lesson of, well, the, the, uh, the, the favored program of whatever we're supposed to be doing over the next nine months will shift in nine months.
So whatever it is, it's gonna keep changing. And this, this, right now, it's, let's secure this. Right.
Next month, it's, let's go do that. So I would always tailor my budget presentation to how my things helped us accomplish whatever the mission of the day was. And people would always be like, how do you have all that capital?
How do you have all that budget? I'm like, it's all how you position it. So maybe that's what we do today, as is, again, simplistic.
But if the watch word of the day is what public private means is really enrichment in hiring, uh, private companies to do these things instead of government agencies. How do we help make that happen in a way that maybe minimizes corruption tilting up one mills there? But maybe that is the answer.
And I know that may not feel good as a security community doing it for the better good through, uh, government pub, public, private, but maybe that's the model we have to transition to something like that where we really have to make that happen. Well, I don't know what it looks like, but I don't think we're going back to the way it was. Even if a new administration came in and said, yeah, we're gonna go back and do that.
You're, you're talking a decade at least before we even kind of got back to where we were. Kate, let me ask you a question. You did your, your thesis in, uh, graduate work on this way back in 2006, you mentioned, right?
Right. Here we are 20 years later. Are you frustrated, surprised, dejected, uh, with the progress we've made since then?
Or you think it's kind of about what you thought Rita would be? Frankly, I, I am, I, I am, as I've said before on our shows, a Pollyanna unfortunately. But in this instance, I, I am dejected.
Um, I, I mean, it's, it's a lot and, and it's Groundhog's Day for me. Um, I always feel like we're still chasing, um, we're still chasing the threat. We're never getting ahead of the threat.
And I don't understand when we've had some phenomenal minds. Um, when we, we, we all, we understand the problem. And this is where I, I get a little bit bummed out because, you know, I, I don't know whether it's when, and to Mitch, your point about, you know, money, sometimes we, i, I think products, you know, so with vendors, I mean, and I worked with vendors.
I mean, IBM for, you know, over 20 years, et cetera, McAfee, um, and sometimes, you know, it's based on, you know, sales kickoff meetings. You know, what are, you know, what are, you know, what's, the company has to prove a profit and everything else. And so the, so the, so the vendors are talking and trying to sell the products.
But at the end of the day, um, and I was an architect, so I would, you know, bring in, and, and I, and I didn't, I, I was agnostic, um, as far as products were concerned. And, um, but it always seemed that at the end of the day, you know, it's like we have this phenomenal product and we're gonna, you know, crush this CVE, well, now we have 40,000 plus, you know, CDs. And you, I, and I walked into, you know, how many companies that had over 120 different security, cybersecurity products, 80 different vendors.
And I'm like, okay, this is a vulnerability within itself. You know, you have so many different vendors and so many different products. So, um, so I think we have to switch.
Um, and Mitch, you know, I, I do, I, I like the way the thinking is because I don't, I think that this gives us actually an opportunity within the cybersecurity community to look at things seriously. We need to look at this problem differently. And, um, we, we really do.
And, and we have to seriously understand, 'cause look, we have to crush disinformation. We have to, you know, look at large language models, we have to look, um, at, at doing, um, you know, the, the AI and the coding, um, differently. Because if we humanly look at this, we're not, not going to, we're not going to win.
So we have to look at LLMs and we have to look at how are we going to address this to address these threats for real? And not just singular threats. I mean, big threats like disinformation as an example, Don't disagree.
Yeah. I, I'll just chime in one, we could do a whole podcast about this, but I think we have already surpassed, but certainly we'll reach a, a, uh, a velocity stage where what is happening, whether it's the amount of change, whether it's the tax surface where there's all the events that are happening are far beyond the, the model of report and human take action. We have to get to a place where, oh, I, I think we passed that Rubicon a while ago.
We have to get to a place where we can trust technology to take action for us. Whether that's AI or something, you know, even current generation. And, and otherwise, it's, it's just there's not enough people on the planet to respond to every CVE vulnerability that gets reported, or every incident that happens.
So that, that to me is we, we have to invest in that. That's where I think the next big, big, big, big innovation in security is that hump we have to get over. Otherwise, it's, it's not gonna get solved.
But that, but that's also the kind of mission where it's good to have the breadth and width of the government trying to solve that with you because it's, it's really, it's a big mission. Maybe almost too big for any one vendor or one company, or even industry state, nation state is, well, no company is prepared to really Well, and, and there's the flip side to this, which is this whole sovereignty, digital sovereignty thing, right? Where whole nother, you're not, you know, used to be able to, so one of them, besides dealing with private individuals, would deal with their counterparts in Europe.
And you know, we in the west, in Pacific, our allies, well, we don't have a lot of allies these days. No. Wherever they may be.
Well, north, North Korea might help us. Who knows? He's friends with them, Greenland.
But, uh, we count on your green one. It's just, it's just a block of ice. Anyway, um, we're not gonna go there though.
We're not going there. Please. But let me, let me, let me wrap this up in a dignified way, Mitchell.
Thank you. I certainly can't do it. I appreciate you in Kate.
Dick that up. You Jack, you dragged us down there on that one. But, but the national sovereignty issue is a another example of us breaking down partnerships instead of working together to solve a global cyber problem, which is critical infrastructure safety.
Yeah. And, and I'd like to just add that I talk a lot about frameworks. At the end of the day, a framework is so important.
It gives us a vision. And I think if we can invest in a framework and one that we can agree on, I think we can then start to build the components around it that can actually give us this vision that we need for the cybersecurity that we need for today. Not even for tomorrow.
We need it right now. I just wanna Absolutely. One thing, and, and Kate, I mean, listen, with every bit of sincerity, you are one of the clearest voices in cybersecurity right now.
We need to elevate you and what you're, you're talking about, and yes, you're on Textron Gang with us, you're on Security Boulevard, but I hope you can take an even greater role, whatever that is in. Oh, she's also the chair of the CD Foundation Cybersecurity special Interest group. There you go.
I mean, the more we can elevate you and, and folks like you, because you are such a clear communicator, you know, you don't get lost in the gobbledygook of security. Like, it's so easy, easy to do, and you, you really get to the heart of things. So thank you so much for what you do, and we hope, well, That's very kind of you and I really appreciated thank being a part of this f and nerc.
I hope to be back f and Ner Ernie Mitch, take us. So, well, I don't know what f fricking ner stand for anymore, but whatever it was, we used great thing back then and we'll have the future version of it. So thank God we have, we have leaders like Kate that, that are helping make progress.
And Jen Easterly, good luck to her and RSAC. Yeah, I'm looking forward to, Hey, hey, you know what? Step out, uh, connect with us 'cause we're gonna be recording an episode at RSAC and we'd love to sure have you on and talk with you.
We are having guests like Kate, uh, come on. And, uh, we'd love to have you. com or myself, m Ashley at Secure.
I thought you almost gonna say still secure for a second, Mitch. I almost did. Almost did.
Yeah. com and, uh, we'd love to chat with you and thank you for listening. And hey, hit that follow, hit that like button, you know, aren't we supposed to say that?
Hit the like button. Yeah, hit the like button or subscribe or whatever button you see over there. I don't know.
But for now, this, this is gonna wrap up this episode, episode of Still Cyber. After all these years, I'm Alan Shimo. I'm Mitch Ashley.
We'll see you next time.
