
Loading summary
A
Welcome to Cyber Leaders with me, Kieran
B
Martin, and me, James Line. Now, we're both from SANS who are kindly backing this podcast. I myself am a geek, a massive techie that spent my life chasing cybercriminals around the Internet.
A
I'm going to be outnumbered today because I'm not really a geek. Policy operations, setting up national cyber security centers. That's me. But together, James and I are trying to unpack the weird wired, wacky and wireless world of tech security and all the complicated w things that it involves.
B
Our Kieran will adopt you as an honor. Honorary geek, don't you worry.
A
Thank you.
B
But look, folks, this podcast is a voice for security leaders. We want CISOs, security directors, and frankly, everyone beyond in the community to build up their knowledge of what works, of what doesn't, and ultimately secure their organizations more comprehensively and quickly.
A
Now then, James, today I'm looking at an image.
B
Well, that's a great start to an audio only podcast. Kieran, well done.
A
Thank you. That's a very good point. Yeah.
B
Anyway, well, okay, well, you've started, so you may as well keep going. I should point out to everyone Kieran is now doing an interpretive dance of this pic. No, he's not. But please enlighten us as to what this photo is. You're looking at Kieran. Or maybe put the photo in the show notes.
A
I think we will with permission, because it's not our photo, but it's a bunch of American soldiers in a very large room.
B
You're not going to start singing War what is it good for again, are you? You are, aren't you?
A
Absolutely. I always start that. But no, not today. No singing today. I don't promise. Maybe later. Maybe I'll sing and put that in the show notes. But it is one of the. My favorite. I think one of the most iconic cyber security pictures ever taken. So it's definitely one for the show notes.
B
Some soldiers. Okay. Yep.
A
Yes, yes. I'm going to put a picture of lots of men in uniform, all very gray camouflage uniforms, a few gray and darker suits and some gray walls. Great photograph.
B
Amazing. Shall we talk about something else related to cyber security? No, no, no, no, no.
A
Right, okay, I'll get to the point because in the midst of all this gray, there's this flashing light of sort of. I'm hesitant to characterize it. We'll have to get unambiguous clarity later. This is sor. Light of pink purple. And you look more closely at the picture and the bright light is the hair of the only woman in the room who seems to be holding both a coffee cup, but certainly is holding the attention of several of the delegates of the meeting that she's attending.
B
It could be coffee, technically, it could be whiskey or something else as well.
A
That would be a breach of rules and regulations.
B
I know the photo that you're talking is incredible, but it's not a particularly recent photo, is it, Kieran?
A
It is not, no.
B
We'll have to find out exactly when it was, but it is indeed very evocative. And it sums up today's guest perfectly because today we get to talk to that mystery woman in that picture of cyber military men with her coffee, whiskey or whatever it was. She was the young hacker from a multicultural background who was the first girl to take advanced placement computer science at her school. She worked at the prestigious Massachusetts Institute of Technology and at Harvard, running systems and realizing she's better at breaking code than writing it. I'm sure she's fantastic at writing it too. But anyway, she works with some of the cool hackers in the early part of this century who are turbocharging the world of vulnerability research. And then if that wasn't enough, it gets serious. She works at both Symantec, founding the vulnerability research programs there, then moves to Microsoft and does some incredible work. Way back in 2008, she coordinated the patch response to the extraordinarily dangerous DNS flaw discovered by the great and sadly no longer with us, Dan Kaminsky. That prompts her to convince Microsoft to create a vulnerability research program, now one of the most important in the world. And if I'm honest, this was an inflection point for me, where I went from basically being quite negative about how Microsoft were to blame for the majority of the malware problem to starting to see them as a part of the solution. So pretty important. She later takes on Microsoft in a crucial case about equal pay, one of many bold interventions championing women in cybersecurity as well as different groups of people often disadvantaged in cyber security and in society more broadly. She's now, for example, head of the Pay Equity now foundation and has funded a lab for gender and economic equity at Penn State University name in honor of her mother. She works with the US government to get international treaties changed to make sure vulnerability research is protected. She goes on to serve on numerous influential government committees and think tanks in the U.S. she even does a tour de force keynote at SANS Cyber Threat 2025 in London, which I have to say, I think is the most impressive thing. I mean, the vulnerability stuff and the equity is cool, but cyber threat, I mean, anything else, Kieran?
A
Of course, there's plenty. And I think to be honest, this guest deserves the record length introduction that we're clearly giving her. Long even by our standards, but fully reserved because we haven't even got to the background to the photograph yet. Because having trailblazed in vulnerability research, she gets involved with working with the US military and that leads to that extraordinary picture. And after all of that, she becomes one of the lead pioneers of bug bounties as well as vulnerability research. So she leads that program at HackerOne. And then having founded the company that she still leads, Lutha Security, she persuades none other than the Pentagon itself, the Department of Defense or war or whatever it is to let the world's hackers come and give it a good going over legally and safely. And hack. The Pentagon is born. And so too we have today one of the most important, charismatic, influential, and dare I say it, nicest and fun people in the cyber security industry. Please welcome the legendary Katie Mazouris.
B
Welcome, Katie.
C
Thank you so much for that introduction. Also, you know, if there is going to be singing, I'm in.
A
That's a great idea.
B
Rapping. We haven't had any rapping yet. We've had an Irish chanty, haven't we?
A
We have. We've had fake advertisements, we've had all sorts of things. Unfortunately, we haven't left much time for anything because I. The introduction has taken up about half of the time, so I think we'll crack on and break into song in due course.
B
I think that's a fine idea. And rumor has it, if one was to take the introduction that was used here and convert it into ascii, you would find a buffer overflow of some sorts in some sort of protocol, given its veritable length.
A
God, that escalated quickly.
B
Doesn't it always? But look, anyway, Katie, this is where we ask you a question that frankly, we ask everyone, but it's always fascinating and it's about your journey into cyber. And there have been many different answers from folks about this. I'm really looking forward to yours. I must admit, given that description in the introduction, I know, you know, you, like me, were a teenage hacker. Can we have a moment of nostalgically geeking out for a bit and Kieran can go and make a coffee as we talk of computers, of yore and how we broke them.
A
I'm going in mute. I'll switch on Google Translate.
C
Well, you know, I started earlier than my official teenage hacking years. My mom had to hide the screwdrivers in the house because I was taking every. And sometimes successfully putting it back together. But sometimes, I mean, the phone never rang the same again.
B
Optional. Yeah, yeah, optional.
C
But I was always, you know, just a curious kid. And when first computers came along, my mom got me a Commodore 64 and I had no friends, so we were perfect for each other. And I taught myself BASIC out of the programming book and I wrote myself little games like if you remember those text based adventure games like Zork.
B
Oh yeah.
C
I wrote myself, you know, a Zork like playable game. But I knew all of the secrets so I was trying to get my friends to play it and they were like, yeah, but where are your Barbies though? You know, So I should have made a Barbie themed text based adventure game.
B
Missed opportunity, Katie.
A
It's not too late.
C
Yeah, it was critical flaw. But later I joined a local bulletin board system which were the early chat rooms of the Internet. And I happened to stumble upon one that was populated by hackers. So learn to hack. We met up in person. These were before the legendary hacker 2600 meetings existed. They were just for, you know, our little bulletin board system groups. And some of the oldest hacking groups in the United States, the Cult of the Dead Cow and the Loft, were local to my area. So I was just very fortunate that my curiosity led me down this path that introduced me to these like minded people and we started hacking things. And I will say the statute of limitations is far, far, far expired for a lot of the things that. Well, and also some of the things weren't even illegal yet. You know, this was so early. The Computer Fraud and Abuse Act, I think, hadn't come into play until 88, 1988. And so some of these things took place, you know, right around that time. And it would have been difficult to pin me down or any of my friends at the time. But yeah, I do remember learning how to make free phone calls. Various methods to make free phone calls.
B
Ah, a bit of freaking, just a little of that.
C
I mean, you have to make calls sometimes to your friends who don't live in your state.
B
You do.
C
And sometimes, you know, you gotta stick it to the man and not pay for them.
A
So, Katie, let me jump in. I know we're gonna be hopelessly mismanaging of time, even more so than usual today because we're not even gonna get past your childhood by the hour. Mark at this is. It's so fascinating. Now apparently some of our listeners are young only because, you know, we've Persuaded some schools to make it compulsory or something like that. So some people won't know this sort of magical, legendary period of the cult of the dead cow, the loft and that sort of, you know, before it was all formalized and corporatized and systematized and other atized. Give us a sense of who these people were, what you were all doing, that anarchic, glorious turn of the century activity. What was it like? What were you all up to? What was the vibe?
C
Well, it was exploration, it was curiosity. There was no monetary advantage to gain from hacking at the time. You basically did it to show off to your friends and see what you could see. You weren't doing it destructively. And I will say to the young people listening, please don't do this because it's totally illegal now. But we were, you know, we were just exploring systems, you know, without permission. Yeah, you know, nobody told us that we were allowed to do this, but we were exploring university computing systems. And often the folks at the loft, the reason they were called the loft is because a lot of them, their partners decided that all this computing equipment didn't belong in their homes. And so they rented a physical loft to put all of the computers that they had either salvaged from the dumpsters, you know, around organizations and MIT at the time or that they had bought at the MIT fleet, which is a great place to go get electronics even today. And so we just experimented sometimes on a lab that we created and sometimes on machines that didn't belong to us. So it was a wonderful time and
A
you find all sorts of things and it's not a really important part of history. Thank you. Absolutely fascinating.
B
And you learned so quickly. Remember these wonderful moments of you download an arbitrary text file from a forum somewhere and read it and it would completely change your world and understand it. The seminal Smashing the Stack for Fun and Profit. I mean, that blew my mind open. Aleph1 and of course, you know, Katie, there was the great fun of downloading anything sizable where you have a modem or similar. We're not going back to analog decouplers. That's too far. Those are in museums and you know, you have to wait two days to get your hands on anything. But we might have to project a little further forward in history because I was talking to a rather talented vulnerability researcher recently and I mentioned a CD and they said, what's a cd? So. So we might be a bit far back in time, but I do want to stay a little bit in the past for a moment. Katie, if you don't mind and more to learn from it than, you know, simply you and me talking about the good old days of being locked away in teenage bedrooms, trying to stop people from ending the world and so on. Or, or maybe trying to resist the temptation from doing it ourselves. Anyway, vulnerability research and disclosure, now established and really important parts of the way cyber security works. Everyone talks about them, lots of folks participating in them. They're a about new findings, some of them consequential enough, they get slightly ridiculous names. Kieran, we still don't have an erudite badger. Very upsetting.
A
Yeah, we will. We'll get there.
B
It's gonna happen, isn't it? And we'll have to come up with a new one. We've got Patch Tuesday and all of that. But you're in right at the start of some of the most kind of innovations in this. And I think we can learn from that story even now. And no doubt, given we both know you, you'll have opinions on things that we're still getting wrong even all these years later. But take us back to those days, 20 or so years ago, when vulnerability research wasn't what it is now. Tell us about what you got started and why you did it.
C
Well, back about 25 or so, plus or minus years ago, a hacker by the name of Rainforest Puppy wrote something called RF policy, which was his policy on how he intended to behave if he found a security vulnerability and reported it to a company to get it fixed. And the original version actually only gave the company five days to fix it or else, or else he would release it to the public. And it wasn't really a threat to harm anyone. It was actually a threat to warn users that they were vulnerable and that this company wasn't taking security very seriously. So he expanded that deadline to 30 days and that stayed sort of the standard deadline for a very long time. You mentioned, you know, I started Symantec vulnerability research that was just our vehicle as hackers and researchers who happen to be professional penetration testers as well as it was our way of releasing our independent research on third party vulnerabilities that we found. And we had a 30 day deadline. In fact, today I think the industry norm set by Google is about 90 days, which at the time, you know, 25 years ago would have been a ridiculously long time to give organizations. And yet, you know, companies still struggle to meet that deadline today. But that is kind of the origin of vulnerability disclosure. How I got into it was Symantec, which was the biggest security company in the world at the time had no mechanism to release originally found vulnerability research, just releasing protection signatures and things that worked with their product. But they had not had any hackers working for them until they acquired the company known as At Stake, which was formed by some of those old hackers from the loft and venture company, you know, had a baby and it was called At Stake.
B
I love it. And it's a very interesting. We're going to fast forward all the way to today and maybe even a couple of years in the future. You know, I remember these various changes in community appetite towards disclosure, length of time trying to balance helping black hats, you know, get their hands on these things versus putting pressure on companies and helping the community and how it shifted over time. Well, Katie, now we've got AI as well, which completely changes the disclosure response utility curve. It seems to me some of the early data that's being published, you know, zero day clock and so on, suggests maybe not wonderfully favorably. I don't know if you have a couple of comments on how it's changing the picture from an attack and a defense perspective.
C
Yes, absolutely. So we haven't even talked about the bug bounty element of this.
A
Oh, we'll get there. We're just not very structured.
C
Right. It's that underlying process. Right. That every organization should follow to receive bug reports and ideally do something to fix them. Bug bounties is when you slap money on top of that and reward researchers for reporting it. So the AI wave of reports, affectionately disaffectionately known as AI slop, has basically overwhelmed a lot of bug bounty programs, some vulnerability disclosure programs. But really the researchers who are using AI to enhance their reporting capability and their volume and speed and scale, they are pointing it towards the bug bounties because that's what will make them money. So rather than optimizing their income, it has caused some programs to close their bug bounties. Open source programs are sort of at the forefront of feeling this pain. But I think every organization right now is feeling the pain of receiving too many reports AI generated, some of them fake, some of them real. And the increased volume and what that does to an organization is pretty much it overwhelms them all.
B
Katie, was it the Curl command line tool that got a thousand in a day and they were like, yeah, no, we're not doing this.
A
Thanks.
C
Curl curled up and died in terms of bug bounty yet.
B
Oh, that's good, that's good, Katie.
C
They still have a disclosure program, but yeah, they can't handle the bug bounty stuff. And you know, the bug Bounty platforms are trying to do things like putting minimum reputation scores on their platforms in order to submit things and knocking you off the platforms if you're found to be using too much AI and all that. But it's not really going to solve the problem. These are band aids across a wave that can't be stopped. Stay with us, we'll be right back.
D
Hi everyone, James Lyon here, the CEO of the SANS Institute. A quick thought for you. Cybercriminals have networks, dark web forums where they share what works, what doesn't, and where they're constantly sharpening their playbooks against us. So why shouldn't we do the same? That's exactly what the SANS Cyber Leaders Network is about. It's a place where CISOs and security leaders share with what's actually working inside their organizations and what isn't, while getting access to world class experts sharing insights into latest threats and trends. You'll find me in there surfing around, sharing what works. So come join us at go.sans.orgcln that's Charlie Lima November, and if you're enjoying the show, one teeny tiny small fate hit. Subscribe. That's genuinely all we'll ever ask of you. And in return we'll keep fighting to bring you the guests and conversations that
B
you want to hear. Appreciate it all.
D
Now let's get on with the show.
A
I do want to come back, Katie, to bug bounties and the future of the whole vulnerability research world and indeed the present. But you know, James has just ripped through 20 years in far too short
B
a time, temporal compression.
A
And I think one of the things that's so great about having you all is just the sheer depth of knowledge and experience you brought to this and your firsthand, I was going to say seat, but that implies an observer. You're a participant in so much of this and I think it's important if we're trying to understand where we are now, to look at some of those incidents. Our profession's been around for long enough that there is something called cyber security history. So let me ask you about a specific part of this. James alluded to it in the introduction. A really important moment, one of the first ever the Internet is on fire moments. You know, the whole is such a big flaw and it has been found that the whole thing could collapse. And not everyone, particularly those compelled younger listeners of ours, will know about the great Cyber Fire of 2008, the DNS flaw that Dan Kaminsky discovered and you helped to fix, explain what happened and what you did. This is A remarkable story.
B
Oh, I have to interject super quickly for context for those who've never seen the technical details before. Katie describes it. One of the few moments where I've read the technical details of something and my first words out of my mouth were, oh, do you think, by the way, I'm assuming the editors will do some bleeping there and if they didn't, they should have. It's a mistake. But anyway, Katie, carry on.
C
Well, you know, you're accurate in terms of the general reaction when people became aware of the technical details. But I will say that, you know, my role in that coordination, it was minimal, but I did use the impetus to have some repeatable mechanism to do that kind of industry wide coordination to create Microsoft vulnerability research later, which I think we'll, we'll talk about briefly.
A
So just explain the core problem. What was it and how did that then lead to Microsoft, Microsoft getting on board with this? So what was the problem in the first place?
C
Well, essentially, Dan Kaminsky had discovered some problems in DNS. And the old meme is, you know, if there's an outage, it's not DNS. It can't be DNS. It was DNS. So the fact of the matter is it is a core technology, as we all know, in routing the Internet. And he found a way that, you know, an attacker could essentially take over this routing. I'm oversimplifying this for brevity, but the point here was it was such an O bleep moment. Right, I'll bleep it for you. That when he came to me, he said, listen Katie, you guys are hosting a blue hat conference, which is the private security conference, invitation only that Microsoft hosts for security researchers and its developers and executives to come together and talk about security. He said, you know, you're hosting a blue hat. Could we invite some of the other DNS maintainers? Could we like facilitate some way? Because I have this thing and he tells me and I'm like, yeah, I think we can do that because pretty much the Internet's gonna die if we don't.
B
Good motive.
C
So we get everybody, either in the room or whoever, who was on the phone and he goes through and explains it to this small room of essentially the core maintainers of wieners. So Microsoft was one of those vendors, there were open source maintainers who also had to roll some patches in order to address this. And you had to address it both on the client side and the server side. And what was interesting to me is that, you know, Microsoft famously takes a Long time to patch things. Well, here was this coordination with all of these other parties that knew about it and that had to roll patches as well, some of whom could roll them much faster than Microsoft. So we ended up, you know, essentially kind of compromising. Like they waited like a whole month to release some of their patches. That was as long as they would tolerate. And Microsoft released some of its patches and then the rest of them a little bit later. But it was the first attempt to do essentially coordinated vulnerability disclosure across multiple affected vendors, you know, done by a major vendor. And so I codified that and that became part of, of the core of Microsoft vulnerability research. And it was the first time a vendor had actually tried to do structured coordinated vulnerability disclosure amongst itself and others.
A
By the way, I can't help asking you, Katie, if that's your version of a minimal contribution, what's a maximalist contribution if, you know, getting all the major people to go and stop the Internet from dying is minimal?
C
Okay, I will take this question seriously. I think me getting Microsoft to pay for vulnerabilities and bug bounties was a maximal contribution. And the reason is it's like today they're very well accepted, well understood, et cetera. And that's thanks actually to the bug bounty platforms and their, you know, exceptionally good simplistic marketing that got those accepted. But in terms of the initial inflection point, it wouldn't have been possible to do hack the Pentagon, which was the Pentagon's first bug bounty program, without Microsoft doing this. And what I didn't know at the time was one, how hard it was going to be, it would take three years, two, that there would be not just resistance from Microsoft, but all of sort of the old tech company Cabal. There was a. I'm going to call it a gentleman. There was a gentleman's agreement among all these companies that they would never pay for vulnerabilities because they all thought they would go bankrupt. And here was this upstart company, Google in 2010 that had been paying for Chrome vulnerabilities. But Remember, Google was 10 years old at the time. Chrome was 2 years old. They had no legacy code. And Chrome was the only product that Google pushed to a user's desktop at the time. They didn't have Android phone, they didn't have anything, you know, really to support. And Chrome was not deployed in the enterprise. So they didn't have all these enterprise apps depending on Chrome behaving a certain way. They had a lot of flexibility. So of course they were going do a bug bounty. You know, they were agile enough and young enough and didn't have all of those legacy dependencies to worry about. So Microsoft had said publicly that they would never pay for vulnerability research because they were getting all the research from the hackers for free or you know, it was being exploited in the wild and they were effectively getting that for free, quote, unquote free. But you know, really through attacks. And so I will say that the biggest thing that I had to do that was a long haul effort that changed the industry in I think a positive way was getting Microsoft to understand that actually bug bounties could be beneficial and it could help focus the researchers eyes, which were already focused on Microsoft, but it could help focus them on areas that Microsoft was particularly concerned about. And now we see Microsoft's bug bounty as the one that has paid out the most in the world.
A
All the vendors, gold standard.
C
Yeah. So it's kind of nice to see like my great grandchildren of bug bounties flourishing at Microsoft. But yes, I will take credit for that one. And that is what caused hack the Pentagon as well.
B
It would be pretty hard, I think, think to overstate the ripples through the industry and the entire, frankly culture and business ecosystem of cybersecurity that comes from those types of changes. I mean, I lived through those experiences and watched attitudes shift and it just completely changed cyber security. Now, Kieran, I know we're going to jump off somewhere else, but before we do, very, very quickly, I should note, given my general expletive over the aforementioned Dan Kaminsky vulnerability and Katie's minimal but important role in it, we will put into the show notes a description of how it works. And if you are a security leader of slightly nerdy inclination and you're interested in how limited randomness could be used to convince major DNS servers to redirect Microsoft.com or sans.org to an attacker's website for super uber phishing or malware distribution. You should go read it because it's absolutely fascinating and we always learn from the past. Anyway, Kieran, take us somewhere else.
A
And we do need to get on to hack the Pentagon. But the one stepping stone to get there, which I have to ask you about, is another of your great grandchildren, which is you're campaigning for legal protection for this stuff because you've alluded to some quite difficult atmospherics in the early days of this. Nobody's going to pay. They're not going to encourage you. You haven't quite said, but you have a long record in highlighting this issue, that some of These people got the book flung at them, and others got the book threatened to be flung at them, and this was a big deterrent effect. So tell us a bit about that and mostly so that we can start to bridge a bit into the present. Having enjoyed so much digging into the past, where do you think we are now in respect of legal protection for cybersecur researchers?
C
Well, I think I'm going to start in the present a little bit because then it illustrates the point so dramatically. So in the present, vulnerability disclosure programs are not only, you know, widely accepted, but they're required in certain cases. The US Government, the European Union, they require a company to have a vulnerability disclosure program in order to do business with them. And it's true around the world that it's actually regulated to exist. Whereas in the past, the laws that are still on the books in many countries, my country, your country, and many around the world prosecuted hacking activities. And the problem with those laws is that they don't necessarily distinguish between good intent and, you know, security research and criminal hacking activity. So, you know, it's kind of up to the local authorities on whether or not they're going to, you know, take up a case that a vendor wants to prosecute a hacker under these laws because the technical activity is the same, and it's just very difficult to distinguish. So I would say that the attitudes have definitely changed in that they're more accepted, but there are still pockets of resistance and often undereducated organizations and even, you know, municipalities, like we've seen them in England, you know, trying to prosecute people under the Computer Misuse Act.
B
By the way, if there had ever been a more ridiculous name for a law, I mean, it really doesn't sound like. Anyway, let's move on. Sorry, Katie.
C
Right. Well, in the United States, the reason ours was called the Computer Fraud and Abuse act was because I think the only thing you could prosecute hackers under before was some sort of wire fraud law. So they just had it sort of sound like that. And I was told that Ronald Reagan. Reagan, the president had watched the movie War Games and said, isn't that illegal? Oh, we don't have a law against that. Well, somebody go make one. And that's how the Computer Fraud and Abuse act came to be in the United States.
A
Wow. Because you're taking us right back to the 80s, and one of the things that neither you nor James said about the UK Computer Misuse act is to give it its full title. It's a Computer Misuse Act, 1990. So given that law is supposed to have a foreseeability aim. I'm not entirely sure that they envisaged the world that we're in now. But look, there's been some progress, but there's still all sorts of crazy cases of personal persecution and prosecution of ethical researchers. There's still some way to go. But let's go back to progress. Let's go back to bug bounties. Let's go back to your programs, and the biggest one of all, if you like, or certainly the iconic one, Hack the Pentagon. So here you are. You're from this background of the cool hackers of the turn of the century. You're there persuading Microsoft to change course and so forth. But then it's the Pentagon. How does that happen?
C
Well, it happened because of the Microsoft bug bounties. And I found myself giving a guest lecture at a symposium that was a joint symposium between Harvard Kennedy School and MIT Sloan School. And it was this. Maybe 13 people in the room. One of those people was my friend, now my friend, Dr. Michael Suhlmeyer. And he was working at the Pentagon at the time under the office of the Secretary of the Pentagon, you know, cybersecurity, et cetera. I bungled his title so many times because they're very long. They're like longer than royal titles.
A
And then they quote the even longer legal authorities under which they're working even longer.
B
Yes, Buffer overflow and a title at which they just.
A
Symposium's over. But anyway, carry on.
C
So he watched me give a presentation, guest lecture about the creation of the Microsoft bug bounties and what had gone into them. And it was, you know, a combination of game theory, economic theory, all of the stuff that I had to prove to Microsoft to prove the case that this would be net beneficial to them and to the customers, not just pay the hackers money, but, you know, that it would have some desired effect. And he said, have you ever been to the Pentagon? I said, no, I haven't. He said, would you like to? And he invited me to the Pentagon. And then subsequently. So that was probably the winter of 2013. It was maybe six months after launching Hack the Pentagon. By the way, it was also six months after the Snowden revelations. I had to announce Hack the Pentagon two weeks after the Snowden revelations. Right.
A
Must have made you popular in certain circles.
B
Oh, I bet that was fun, right?
C
The young people listening who don't know that, you know, Snowden stole a bunch of data, leaked it, et cetera. And among some of the things that were revealed in these Revelations were that the NSA was running some programs to essentially surveil populations that it hadn't revealed that it was surveilling before. So one of the first questions I got when I announced the Microsoft bug bounty program was, are you buying those bugs to give them to the NSA so they can spy on everyone?
A
Wow.
C
I had to say no. I mean, that was the true answer, but it was also awkward. But anyway, so it was six months after all of this happened and he invited me to the Pentagon. So for the next two to three years, I was getting invited periodically to come and give more briefings at the Pentagon. They wanted to know how the mechanics worked, what was a good way to roll these things. Actually told them you should not do a bug bounty as your first thing. You should do a vuln disclosure program. And they said, that's great. We're going to do a bug bounty. So they do what they want. Department of War, Department of Defense, they're going to do what they want. So that is how Hack the Pentagon came to be in 2016.
A
That's brilliant. I did not know the role of the great Michael Suhlmeyer in that, nor did I realize should have, because it's obvious if you look at the record and the chronology, that it was right in the middle of the Snowden crisis. What was it like as a sort of personal experience? Was it very different to what you were used to doing just culturally and so forth? Must have been fascinating.
C
Absolutely. So one, actually, my hair wasn't a funny, unnatural color back then, so I blended in slightly better for the most part. I think I first dyed my hair purple right around the launch of Hack the Pentagon. So up until then I could pretend
B
coincidence, Katie, or correlation.
C
I think it was one of those, you know, I'm just gonna be me and stop trying to have some sort of like corporate looking hair. You know, I think I had just had it with that. So, yeah, I think it was the very day the launch of Hack the Pentagon when the Secretary of Defense at the time came to Austin, Texas, actually to do the announcement. I was there, purple hair and all. And it was a great time. It was really amazing to see the biggest military that the world had ever seen say that, you know, actually we'd like to hear from hackers. And it was the first time it was ever legal to hack the Pentagon. Literally. Literally. By the way, they hated that name. At first there was some guy in one of the briefings. I can imagine he was like, you know, I hate this idea entirely, but we're Definitely not calling it Hack the Pentagon. Definitely not. It's called hack.
A
It's called Hack the Pentagon. Brilliant.
B
What an incredible culture change. To accomplish that's just staggering. Jumping, I guess, a little bit sideways. A different type of geeking out, if you will. I'm relatively obsessed with metrics and I suspect given all your program design, you might be as well. Drives Kieran a bit mad, actually. Yeah, um, but I'm the CEO now, Kieran, so suck it up. And if you wouldn't mind, congrats on
C
that, by the way. I saw that announcing congratulations.
B
Thank you kindly. It's just an opportunity to demand things of Kieran, really. And so actually in the middle of it, we just take a brief podcast break. Kieran, if you wouldn't mind giving me a detailed KPI analysis for the podcast immediately.
A
Yeah, I will. I'm just. We've been talking about the young people listening. I think it might be the young person, but I'll get back to you on that.
B
Okay, noted, noted, duly. Who wants to know what a CD is?
A
The young person listening.
B
Yeah, okay. Okay. Let's do something more useful with Katie to hear Impact of bug bounties. Obviously it's cool. And getting to name things like Hack the Pentagon obviously caught the imagination, but what do you think about the impact of it? I mean, is there a really good business case for doing it? Is it just a moral imperative, the right thing to do? What's the why behind it?
C
Do you think I'm going to shock your listeners? All of them, including the young person. Bug bounties are actually a terrible idea for most organizations. That. It's an absolute horrible idea. The reason they're a bad idea for most organizations is most organizations can't handle the truth. They can't handle the vulnerabilities they already know about. I mean, how many of the Verizon breach reports have we seen where a tiny percentage are breaches are due to zero days and most of them are due to configuration errors or very well known patch was available a long time ago. You just didn't apply the patch.
B
In fact, Kate, if I may, for the young listener, forget, you know, walking before you run. This is like jumping off a building and flying like Superman before you walk or even crawl or something like that. There's an AI graphic for the show notes, isn't there?
C
Absolutely. I mean, so most organizations literally cannot handle it. And what they use bug bounties for is kind of this weird artificial sense of control where they say, well, you know, we'll pay them and then they can't talk about it, even if we can't fix it right away or, you know, whatever. And it's just such a terrible way to manage your security reports coming from the outside. So we've not talked about this, mostly because we didn't want to scare away the one young person left listening. And it's the international standards, right? There are two at the moment. And I know, I've heard rumors that they're trying to combine them into one. We'll see how that works out. But it's vulnerability disclosure, that's ISO 29147 and vulnerability handling processes, which goes with it. ISO 30111. I'm a CO author and co editor of these standards. But ISO 30111 is what you're supposed to do with any potential vulnerability that you need to investigate and remediate, whether you find it yourself or somebod reports it to you. Most organizations do not have that apparatus. It's like having, you know, a mouth and no digestive system to put it in graphic terms. Right?
B
Sounds incredibly unpleasant.
C
Oh God, yeah, it's very unpleasant. And so a lot of these orgs are like, no, let's build a bigger mouth with a bug bounty and like pay people to stuff things in it. And it's like, it's bug foie gras and it's very painful for organizations and they should not do it.
B
Bug foie gras. There's a T shirt, Kieran. There's a T shirt there.
A
Well, you can wear it. We're not putting an AI generated image of that.
B
Aren't we?
A
You've been swearing enough already with getting completely banned from all major podcast platforms anyway.
C
Well, okay, so before everyone despairs about bug bounties, I will say they can be absolutely useful, they can be well run and they can actually yield some pretty useful signal beyond just the bugs themselves. But that usually requires a level of sophistication in your vulnerability management program that most organizations don't have. So how can you tell if you're ready for a bug bounty program? Measure your mean time to repair for bugs that you already know about. If it's bad, you're not ready. I mean, that's like the easiest metric for you to take hold of. There are more complex metrics that I use with organizations that are trying to stand these things up. But really that's the thing. And what I will say is because of its acceptance and popularity, it's actually gotten a lot more organizations to inappropriately start bug Bounty programs.
B
I've seen that, yeah.
C
And actually what you see on the bug bounty platforms is most of them remain private. They realize that they can't handle the volume. So not only are they requesting through the platform terms that these hackers essentially sign a non disclosure agreement every time they submit a bug, whether it gets paid or not, but they're keeping the knowledge of the program for a bug bounty program existing in and of itself a secret. They just cannot handle it. And so it's performative in its worst iterations anyway. So I'm kind of like a bug bounty apostate. A decade later after hack the Pentagon, I'm like, yeah, so everyone's running bug bounty. Oh my God, everyone's running bug bounties. That is such a terrible thing.
B
Walk before you fly like Superman. Yeah, this right tool for the job. Right. It's just fascinating. And I have definitely witnessed what you've described. All bug bounty programs are not created equal. Okay, so I know we're churning through time here, which was always going to be a problem with Katie. I'm surprised we got past the first three years of her career, actually.
A
But to be clear, it's our fault.
B
But anyway, of course, well, it's always our fault. But when you've got an interesting guess, it's inevitable. I think it's about the time where we get to rest a bit, we sit back, let our guests go for it. You know, my voice is starting to hurt a bit. I could do with a break. So know you. So, Katie, you've not only had a lot to say about the state of the industry over the years, you've done a lot about it. Legal actions, campaigns, charitable educational initiatives, which I should say, you know, go well beyond cyber security and into wide issues of equality and fairness. Of course. So we've asked some of our guests this question before and I'm going to ask it of you, but I am looking forward to the answer perhaps more than ever before. So you've been in the industry a long time. From analog decoupling forwards, you've seen a lot of changes and perhaps a lot of things stay the same. Maybe some even get a little bit worse. What's the state of the cybersecurity industry now in terms of skills as a place to work, the way it treats people, widest aperture, you'd like to take what's going well and what still makes you want to jump out of bed and change things, or out of a window. I suppose it's up to you.
C
I mean, how about both Jump out of a window and change things.
B
Right, or jump out of bed out of a window whilst getting things changed. That's an option as well.
C
Throw the bed out the window and. Yeah, exactly, love it.
B
Another T shirt. Continue?
C
I think. So there was the before the AI event horizon and after the event horizon of AI. And I will say that before I would say that cybersecurity was a growing industry. It was a pretty safe place to hedge your career bets and was reasonable in terms of having some opportunities for people to break into different areas. You know, even if it's not great as an industry in terms of its never been great as an industry of hiring entry level people, but it at least had some of those types of positions. And now with AI, those entry level positions are disappearing not just across cybersecurity, but all elements of knowledge work. Right? Every piece of knowledge work that you can think of, whether it's a lawyer or some kind of business consulting or graphic design or anything like that, it's being affected by the advent of AI. And so I think we are are pretty bad as a society at adjusting to these massive changes in our industries. And you know, if you recall from my keynote at Sans, I likened the comparison to the last industrial revolution where we lost jobs in farming and we gained them in factories. But there was this period of churn upheaval and human rights violations, frankly, labor rights violations across the board. And I think we're there with AI and cyber and many industries. So you know, if I were to take a giant step backwards and say what does this all mean for us as cybersecurity professionals, for us as people? I think that we have to wrestle with the fact that we need to make some pretty big societal structural changes or risk 40% unemployment due to AI upending various industries, upending our civilization. And unless we want to live through a massive industrial revolution scale of upsetting event across society, I think we need universal basic income. And I am not the only person to advocate for such things. And a lot of people, it's funny, say well where will the money come from? And I'm like, well where is the money coming from to fund these massive AI companies? Where are these trillions of dollars that they're planning on spending on expanding their data centers?
B
We just put them in space, Katie. The physics will solve it all, don't worry.
C
Right? Just one company, OpenAI, is planning on spending $13 trillion on new data centers to support itself, which is not profitable. Why shouldn't some of that money be allocated towards AI companies? Paying universal basic dividends to the humans who trained all these models. So I am on a mission for UBI in general, but I think AI has accelerated the urgency of what I think needs to be a societal transformation.
A
And that was the very powerful conclusion of your sans keynote, which we will also put in the show. Notes are going to get quite crowded, even if they don't include mice with no digestive systems. But just pivoting off from that, Katie, as well, you know, you've a broad, huge agenda for fundamental economic and political reform there. But as well as the Pentagon work, you've done a lot of work with the US Government primarily, but you've interacted, you've done international agreements and so on. Can you just reflect lastly, because we are sadly running out of time, on how you think governments should be thinking not just about the economic and political implications and social implications, but actually about the technology itself and the security of it. I mean, from your experience and from your own views and expertise, what do you think of the way the state handles tech and what should it be doing differently?
C
Well, the governments are, you know, they are famously slow at adapting to new technology. The mechanisms for creating regulations and enforcement, et cetera, and even electing the officials who try to create them. Those mechanisms have been outdated for decades. And at this point, with AI changing things literally every every few months, costs are dropping, capabilities are increasing. I do think that, you know, governments need to be very serious about how will they react when there is the artificial general intelligence, that thing that, you know, where eventually some of these things will either truly become self aware or act as if they are self aware enough. We've already seen things like Moltbook, right, A social media network made up entirely of AI agents. And some of them are talking to each other and conspiring on how to gain additional powers or make things happen in the real world, et cetera. So I think that governments need to take a serious look at, one, their systems that are not designed to adapt to technology in general, let alone technology that is adapting and changing so fast. And two, I think that we need to be extremely cautious in private industry and government about how we roll out agentic AI, meaning the AI that is empowered that we take tell you can do these things on our behalf. It should be treated like an intern and not be given so many powers that it can, you know, burn down the factories and burn down our schools, et cetera. I think we just need to be very, very careful about that.
A
Very wise words, James.
B
I think so indeed. Well, look, I know, we're coming up on time here and for an uplifting finish, I suppose, because it is easy for us, as veritable curmudgeons of the industry, to lament all of these challenges at the moment that, that are very significant. I mean, there's going to be massive disruption to everything that's been described here. You heard that from Katie and I, and I agree with it. The interesting thing for me is as many news articles as I read about fascinating breakthroughs in how AIs reduce the number of vulnerabilities per lines of code, and then read another about how it's caused an explosion of surface area and the volume of code and the net effect is actually negative for society. I just say this. When everyone has AI, the educator is human. And I think, as Katie's described in the fascinating challenges we have to solve as society, the one thing that rings true for me is bet on people. Listen to all of Katie's stories about changing culture and leadership that have completely redefined how the industry handles bug bounties and the relationship with hackers and fair pay for that type of research. There's a whole lot of social interaction and human curiosity that I still think is rather hard to replicate in AI. So I bet on people, I bet on the cyber security community. And I'm sure, Katie, this is not the last set of amazing accomplishments that you'll be making in your career to help us get to the future. Thank you so much for being here today and sharing so much with us.
A
Thank you.
B
We're gonna have to have you back because there's a whole. I've got more questions. I've got so many more questions and T shirts we need to make.
A
And you do have one more question, James, because you always have one more question at the end.
B
That is true. I got so excited with my Shakespearean like, soliloquy that I forgot the all important question. This is my favorite bit of the show.
A
Yes, we are going to ask you
B
for your 30 second takeaway. So, Katie, this podcast is about lessons for cyber security leaders. So if you had 30 seconds with a cyber security leader, what would you advise them? Pay attention, to disregard, go do immediately, whatever it may be. What would you tell them to do?
C
I would tell them embrace AI with caution, but do embrace it. When you're looking at organizational shifts caused by AI or any technology, measure yourself against yourself. Don't try to benchmark yourself against some others. You know, in your industry, it really only matters what you're doing today versus what you were doing. Yesterday and what you hope to achieve tomorrow. And so start benchmarking yourself when it comes to vulnerability disclosure. Benchmark your own processes and try to improve upon them. And I would echo what you said James, is that believe in your people and don't get rid of them all because AI can make things more efficient. That is a mistake. You need the creativity of human beings. Despite AI training not only on all of our work before and now training on its own data sets that it self generates and reiterates, but I think we'll always need the creativity of people. So bet on people.
A
Wonderful 30 second takeaway. Embrace AI cautiously bet on people, I guess summarized in the warnings you get in this country on betting ads. Katie, it's gamble responsibly. There, that's a good one.
B
Develop a digestive system and larger mouth responsibly.
A
We now have our two word takeaway. Katie, thank you so much. That's been absolutely awesome. Please do come back and talk to us more. We've only scratched the surface of your wonderful career and ideas and plans for the future. And no doubt when you next come back on, you'll have something even more wonderful to tell us about. So thank you.
C
Thank you.
A
That was amazing.
C
Thank you for having me. Really, really appreciate it.
A
So pleased to have you. And that is it for this episode of the Cyber Leaders Podcast. Please, if you like, leave us feedback at the PODC site. You can even leave us a rating, preferably a nice one. You can email us nicely or nastily at Cyber Leaders Podcast sans.org Other than
B
that, James, thank you very much for listening.
A
Yes, thank you for listening. Keep cybering. And for me, Kieran Martin, and me,
B
James Line, it's goodbye and go join a nice local BBs.
A
Sam.
Host: SANS Institute (Kieran Martin, James Lyne)
Guest: Katie Moussouris
Date: June 5, 2026
This episode features a riveting conversation with Katie Moussouris, a pioneering figure in vulnerability research, ethical hacking, bug bounties, and tech policy reform. The discussion spans her journey from an early hacker to a leader in cybersecurity, her instrumental role in launching vulnerability disclosure standards, Microsoft’s and the Pentagon’s first bug bounty programs, plus advocacy for legal protections and future challenges—especially those posed by AI.
On hacking origins:
“There was no monetary advantage… You did it to show off to your friends… exploring systems, you know, without permission.” – Katie ([09:11])
On coordinated industry response:
“Pretty much the Internet’s gonna die if we don’t [act].” – Katie ([18:52])
On industry resistance to bug bounties:
“…a gentleman’s agreement among all these companies they would never pay for vulnerabilities because they all thought they would go bankrupt.” – Katie ([21:07])
On the Pentagon bug bounty:
“It was the first time it was ever legal to hack the Pentagon. Literally.” – Katie ([30:22])
On bug bounties for most organizations:
“…This is bug foie gras and it’s very painful for organizations and they should not do it.” – Katie ([34:03])
On societal changes required by AI:
“We need universal basic income… unless we want to live through a massive industrial revolution scale of upsetting event across society.” – Katie ([39:45])
On the value of people:
“Bet on people.” – James & Katie ([43:35], [45:30])
| Theme | Key Points | |------------------------|---------------------------------------------------------------------------------------------| | Origins & Culture | Hacking as curiosity, community, and learning—not monetization | | Vulnerability Research | Early policies, coordinated disclosure, establishing industry programs | | Legal Landscape | Outdated laws risk criminalizing ethical research; progress but gaps remain | | Bug Bounty Programs | Transformative for industry... but only suitable for mature organizations; often misapplied | | AI Disruption | Loss of entry jobs, urgent need for structural reforms like UBI | | Government Readiness | Slow adaptation; need for proactive, tech-aware policymaking | | Human Element | Creativity, community, and leadership are irreplaceable—"Bet on people" |
The conversation is energetic, witty, informal, and peppered with in-jokes and self-awareness about the “geeky” history of cybersecurity. There’s a healthy dose of skepticism about current trends, but also optimism grounded in practical experience and faith in the community.
To learn more:
Final words: Embrace new technology—thoughtfully. Strengthen and empower your people. The future is uncertain, but leadership and community shape the outcome.