Series Three In progress

Security Professionals

The third set, and the largest. Cryptographers, firewall builders, incident responders, tool authors and the security chiefs who had to answer for the breach — 50 cards for the people who spent their careers holding the line rather than crossing it.

Every portrait here is painted from a real, identified photograph of the person, and the photographer is credited on the card. 0 of the 50 have no freely-licensed photograph we could find, so those cards carry no face rather than an invented one. If you can point us at a properly licensed photo of someone, that is the single most useful thing you can contribute.

Roster drafted50/50
Cards locked50/50
Portraits from a verified photo50/50
The working roster

50 names, ordered by set number

Open the scouting report for the sources behind each claim, or go to a card's own page. Nothing here is final until the set is frozen — argue with any of it on GitHub.

001Iconic
Whitfield Diffie card front
Whitfield DiffieCo-Author of Public-Key CryptographyDiffie–Hellman key exchange, and the end of the shared-secret era
CryptographyKey exchangePolicy
USA1976–present98

With Martin Hellman, published “New Directions in Cryptography” in 1976 and showed that two parties who had never met could agree on a secret over a wire anyone could read. It broke a problem the field had considered permanent, and every TLS handshake since is a descendant. Shared the 2015 Turing Award for it, and spent decades afterwards arguing the civil-liberties side of the crypto policy fights.

Locked inCard page
002Iconic
Martin Hellman card front
Martin HellmanCo-Author of Public-Key CryptographyDiffie–Hellman, and the fight to keep crypto research public
CryptographyKey exchangeAcademic freedom
USA1976–present97

Co-author of the 1976 paper and Stanford professor who then refused to let the NSA classify academic cryptography out of existence, publishing and teaching through explicit pressure to stop. Also co-authored the early analysis of DES key length that argued, correctly and years early, that 56 bits was not enough. Shared the 2015 Turing Award with Diffie.

Locked inCard page
003Iconic
Ron Rivest card front
Ron RivestThe R in RSARSA, MD5, RC4 and a career of primitives everyone uses
Public-key cryptographyHash functionsElection security
USA1977–present97

Co-invented the RSA cryptosystem at MIT in 1977 with Shamir and Adleman, turning public-key cryptography from a proposal into something you could ship. Went on to design MD2, MD4, MD5, RC4, RC5 and RC6, co-author the standard algorithms textbook, and spend his later career on verifiable election systems. Turing Award, 2002.

Locked inCard page
004Legendary
Adi Shamir card front
Adi ShamirThe S in RSARSA, secret sharing, and differential cryptanalysis
CryptanalysisPublic-key cryptographySecret sharing
Israel1977–present96

Co-invented RSA, then invented Shamir secret sharing, then co-developed differential cryptanalysis with Eli Biham — the technique that turned out to be the one the DES designers had quietly hardened against seventeen years earlier. Also a co-author of the cube attack and a long line of side-channel work. Turing Award, 2002.

Locked inCard page
005Epic
Leonard Adleman card front
Leonard AdlemanThe A in RSARSA, and naming the computer virus
Public-key cryptographyComplexity theoryDNA computing
USA1977–present92

The third name on the RSA paper, whose role was to keep breaking the schemes Rivest and Shamir proposed until one survived. Later coined the term “computer virus” for Fred Cohen’s 1983 experiments, and founded DNA computing with a molecular solution to the Hamiltonian path problem. Turing Award, 2002.

Locked inCard page
006Iconic
Phil Zimmermann card front
Phil ZimmermannAuthor of PGPPutting strong crypto in ordinary hands, and getting investigated for it
Email encryptionCrypto policySecure voice
USA1991–present96

Released Pretty Good Privacy as free software in 1991, and it escaped onto the internet worldwide. The US government opened a three-year criminal investigation into him for munitions export, dropped it in 1996 without charges, and the crypto-export regime never recovered. He later co-founded Silent Circle and worked on ZRTP for encrypted voice.

Locked inCard page
007Iconic
Bruce Schneier card front
Bruce SchneierThe Field’s Public ConscienceApplied Cryptography, Blowfish, and “security theatre”
CryptographySecurity economicsPublic policy
USA1994–present95

Wrote Applied Cryptography in 1994, the book that taught a generation of engineers how ciphers actually work, then designed Blowfish and co-designed Twofish. Spent the two decades after arguing the harder point: that security is a systems and incentives problem, not a maths problem. Coined “security theatre”, has written the Crypto-Gram newsletter since 1998, and helped report on the Snowden documents.

Locked inCard page
008Legendary
Paul Kocher card front
Paul KocherThe Side-Channel PioneerTiming attacks, differential power analysis, and Spectre
Side channelsHardware securityTLS
USA1995–present94

Published the timing-attack paper in 1996 and differential power analysis in 1999, establishing that a correct implementation of a correct algorithm can still leak its key through how long it takes or how much current it draws. Co-authored the SSL 3.0 specification, founded Cryptography Research, and in 2018 was one of the co-discoverers of Spectre.

Locked inCard page
009Iconic
Dorothy E. Denning card front
Dorothy E. DenningFounder of Intrusion DetectionThe 1987 intrusion-detection model every SIEM still runs on
Intrusion detectionInformation warfareCrypto policy
USA1975–present94

Published “An Intrusion-Detection Model” in 1987, the paper that framed detection as statistical deviation from a profile of normal behaviour and gave the entire monitoring industry its foundation. Also wrote Cryptography and Data Security, worked on database security and lattice-based information flow, and was one of the few academics engaging seriously with both sides of the Clipper chip debate.

Locked inCard page
010Legendary
Gene Spafford card front
Gene SpaffordSpafThe Academy’s AnchorThe Morris worm analysis, Practical UNIX Security, and CERIAS
Systems securityForensicsSecurity education
USA1988–present92

Produced one of the first detailed technical analyses of the 1988 Morris worm while the internet was still smoking, co-wrote Practical UNIX and Internet Security with Simson Garfinkel, co-created Tripwire, and founded Purdue’s COAST lab and then CERIAS — for years the largest academic security centre in the US. Has advised more federal panels than most people have attended.

Locked inCard page
011Iconic
Ross Anderson card front
Ross AndersonAuthor of Security EngineeringThe textbook, and the economics of why security fails
Security engineeringSecurity economicsBanking systems
UK1991–202494

Cambridge professor who wrote Security Engineering, the closest thing the field has to a canonical text, and gave away earlier editions free online. Founded the security-economics research programme with the observation that systems fail because the people who could fix them are not the people who bear the loss. Spent years demonstrating that bank chip-and-PIN systems were weaker than the banks told courts they were. Died in 2024.

Locked inCard page
012Legendary
Matt Blaze card front
Matt BlazeThe Clipper Chip BreakerKilling key escrow, then auditing the voting machines
CryptographyElection securityPhysical security
USA1994–present92

Found the protocol flaw in the NSA’s Clipper chip escrow scheme in 1994 and published it, which did more to end mandated key escrow than any amount of lobbying. Later led state-commissioned source reviews of US voting systems, published work on the vulnerabilities of master-keyed physical locks and wiretap systems, and became a law-school professor arguing the same points to a different audience.

Locked inCard page
013Legendary
Radia Perlman card front
Radia PerlmanArchitect of Resilient NetworksSpanning tree, and routing that survives a malicious node
Network protocolsPKISecure deletion
USA1985–present91

Invented the spanning-tree protocol that made large bridged Ethernets possible, and did the early work on routing protocols designed to keep functioning when a participating node is actively hostile rather than merely broken. Co-wrote Network Security: Private Communication in a Public World, and designed the “ephemerizer” approach to making data reliably expire.

Locked inCard page
014Legendary
Steven M. Bellovin card front
Steven M. BellovinThe Protocol ScepticSecurity Problems in the TCP/IP Protocol Suite, and the firewall book
Network securityProtocol designPolicy
USA1989–present91

Wrote the 1989 paper cataloguing the security problems in TCP/IP — sequence-number prediction, source routing, DNS spoofing — years before anyone was exploiting them at scale. Co-authored Firewalls and Internet Security with Cheswick, co-invented encrypted key exchange, was a Usenet co-creator, and served as chief technologist at the FTC and on the Privacy and Civil Liberties Oversight Board.

Locked inCard page
015Epic
William Cheswick card front
William CheswickChesThe First Firewall BookFirewalls and Internet Security, and “An Evening with Berferd”
FirewallsHoneypotsInternet mapping
USA1990–present88

Co-wrote the 1994 book that taught the industry what a firewall was and how to reason about a perimeter. “An Evening with Berferd” documented him feeding a live intruder a fake environment for months and writing down everything, which is the honeypot genre’s founding text. Later ran the Internet Mapping Project at Bell Labs.

Locked inCard page
016Legendary
Marcus J. Ranum card front
Marcus J. RanumBuilder of the First Commercial FirewallDEC SEAL, the TIS toolkit, and thirty years of contrarianism
FirewallsProxiesLogging
USA1990–present89

Built DEC SEAL, generally credited as the first commercial firewall product, then the TIS Firewall Toolkit and Gauntlet — the code most early internet perimeters were actually made of. Ran whitehouse.gov’s first email server. Has spent the decades since publicly arguing that most of what the industry sells does not work, which has aged better than the products did.

Locked inCard page
017Legendary
Wietse Venema card front
Wietse VenemaAuthor of TCP Wrapper and PostfixDefensive software that a generation of admins just ran
Host securityMail securityForensics
Netherlands1990–present90

Wrote TCP Wrapper, which for years was the access control on a very large share of Unix hosts on the internet, and Postfix, a mail server written from the start around privilege separation. Co-wrote SATAN with Dan Farmer and later the Coroner’s Toolkit and Forensic Discovery, giving incident responders their first real open tooling.

Locked inCard page
018Epic
Dan Farmer card front
Dan FarmerAuthor of COPS and SATANPublishing the scanner, and getting fired for it
Vulnerability scanningForensicsHost auditing
USA1990–present87

Wrote COPS as a student, then in 1995 released SATAN with Wietse Venema — a scanner that audited a network the way an attacker would, published openly so defenders could run it first. The press predicted the end of the internet; SGI fired him over it; the security scanner became a permanent product category. Later co-wrote Forensic Discovery.

Locked inCard page
019Iconic
Gordon Lyon card front
Gordon LyonFyodorAuthor of NmapThe scanner that is on every security laptop on earth
Network scanningOS fingerprintingOpen source
USA1997–present93

Released Nmap in Phrack in 1997 and has maintained it ever since, adding OS fingerprinting, service detection and the NSE scripting engine. Runs seclists.org, hosting the Bugtraq and Full Disclosure archives that are the field’s institutional memory, and fought MPAA and studio takedown attempts over the tool. Nmap is the first command most defenders learn.

Locked inCard page
020Epic
Martin Roesch card front
Martin RoeschAuthor of SnortOpen-source intrusion detection, and the rule format everyone copied
Intrusion detectionPacket analysisOpen source
USA1998–present89

Wrote Snort in 1998 as a lightweight packet sniffer, and it became the intrusion detection system that put IDS within reach of organisations that could never have bought one. Founded Sourcefire around it, which Cisco acquired in 2013. The Snort rule syntax outlived the product and is still how a large part of the industry writes network detections.

Locked inCard page
021Epic
Gerald Combs card front
Gerald CombsAuthor of WiresharkMaking packet analysis free, and keeping it free
Packet analysisProtocol dissectionOpen source
USA1998–present88

Started Ethereal in 1998 because commercial protocol analysers cost more than his employer would spend, renamed it Wireshark in 2006 after a trademark problem, and has shepherded it ever since through thousands of contributed protocol dissectors. It is the default answer to “what is actually on the wire” for network engineers and incident responders alike.

Locked inCard page
022Epic
Renaud Deraison card front
Renaud DeraisonAuthor of NessusThe vulnerability scanner that defined the category
Vulnerability managementScanningProduct security
France / USA1998–present87

Released Nessus in 1998 as a free scanner with its own plugin language, at a point when the alternative was an expensive appliance. Co-founded Tenable Network Security around it in 2002 and took the product closed-source in 2005, a decision the community argued about for years. Vulnerability management as a routine operational practice largely grew out of that codebase.

Locked inCard page
023Legendary
Paul Vixie card front
Paul VixieKeeper of the DNSBIND, DNS RPZ, and the anti-abuse infrastructure nobody sees
DNSAnti-abuseInternet infrastructure
USA1988–present90

Maintained BIND for years and wrote or co-wrote a long run of DNS RFCs, then built the response-policy zone mechanism that lets defenders block malicious domains at the resolver. Founded the first anti-spam DNSBL, ran the Internet Software Consortium, operates F-root, and co-founded Farsight Security around passive DNS. Internet Hall of Fame, 2014.

Locked inCard page
024Epic
Niels Provos card front
Niels ProvosHoneypots and Safe Browsinghoneyd, bcrypt, and warning a billion browsers
HoneypotsPassword hashingWeb malware
Germany / USA1999–present88

Wrote honeyd, co-designed the bcrypt password hash with David Mazières, and created systrace and privilege separation work in OpenSSH. At Google he led the Safe Browsing malware research that put interstitial warnings in front of drive-by download sites, and co-authored the papers that measured how large that problem actually was.

Locked inCard page
025Legendary
Jeremiah Grossman card front
Jeremiah GrossmanThe Web Application Security AuthorityXSS Attacks, WhiteHat Security, and making web appsec a discipline
Web application securityCross-site scriptingVulnerability data
USA1999–present90

Was an information security officer at Yahoo before founding WhiteHat Security in 2001, where continuous scanning of thousands of production sites produced the first credible public statistics on how long real web vulnerabilities actually stay open. Co-founded the Web Application Security Consortium, and co-authored XSS Attacks: Cross Site Scripting Exploits and Defense in 2007 — the book that turned cross-site scripting from a curiosity into a class of bug developers were expected to know.

Locked inCard page
026Epic
Robert Hansen card front
Robert HansenRSnakeThe XSS Cheat Sheetha.ckers.org, Slowloris, and browser attack surface
Cross-site scriptingBrowser securityDenial of service
USA2005–present85

Ran ha.ckers.org and published the XSS cheat sheet, which for years was the reference list of filter-evasion payloads that every web application firewall was tested against. Co-authored XSS Attacks with Grossman, released Slowloris to demonstrate that a single machine could hold a web server’s connections open indefinitely, and co-wrote Detecting Malice on behavioural detection.

Locked inCard page
027Epic
Mark Curphey card front
Mark CurpheyFounder of OWASPStarting the open project that appsec organised itself around
Application securityOpen standardsSupply chain
UK / USA2001–present87

Started the Open Web Application Security Project in September 2001 as a mailing list and a few documents, and it became the vendor-neutral body that produced the Top Ten, the ASVS, ZAP and the testing guides that appsec teams still work from. Later founded SourceClear on software composition analysis and has kept publicly pushing OWASP to stay relevant to modern supply-chain risk.

Locked inCard page
028Epic
Jeff Williams card front
Jeff WilliamsAuthor of the First OWASP Top TenThe list every compliance regime ended up pointing at
Application securityRuntime protectionStandards
USA2002–present86

Wrote the first OWASP Top Ten and served as the volunteer chair of OWASP from 2003 to 2011, the years in which it went from a mailing list to the reference that PCI DSS and a long line of other standards cite by name. Co-founded Aspect Security and then Contrast Security, arguing for instrumentation inside the running application rather than scanning it from outside.

Locked inCard page
029Epic
Gary McGraw card front
Gary McGrawBuilding Security InSoftware security as a discipline, and BSIMM
Software securitySecure designMeasurement
USA1997–present86

Wrote Building Secure Software, Exploiting Software and Software Security, making the case that you cannot test defects out of a system you designed insecurely. Co-created BSIMM, which measures what security programmes actually do rather than what a standard says they should, and has run a long-standing interview series documenting the field’s own history.

Locked inCard page
030Epic
Michael Howard card front
Michael HowardAuthor of Writing Secure CodeThe book and the process behind Microsoft’s security turnaround
Secure developmentSDLThreat modelling
New Zealand / USA2001–present87

Co-wrote Writing Secure Code, which Bill Gates ordered Windows engineers to read during the 2002 Trustworthy Computing halt, and helped build the Security Development Lifecycle that came out of it — threat modelling, banned APIs, fuzzing and a final security review before ship. The SDL became the template most large software organisations copied.

Locked inCard page
031Epic
Adam Shostack card front
Adam ShostackThe Threat Modelling CanonThreat Modeling: Designing for Security, and STRIDE in practice
Threat modellingPrivacySecurity design
USA / Canada2003–present85

Drove threat modelling into shippable practice at Microsoft, including the Elevation of Privilege card game that got non-security engineers doing it voluntarily, then wrote Threat Modeling: Designing for Security and later Threats: What Every Engineer Should Learn. Served on the CVE editorial board and co-wrote The New School of Information Security on learning from breach data.

Locked inCard page
032Epic
Ivan Ristić card front
Ivan RistićAuthor of ModSecurity and SSL LabsGrading the internet’s TLS, one hostname at a time
TLSWeb application firewallsMeasurement
Croatia / UK2002–present86

Wrote ModSecurity, the open-source web application firewall that became the reference implementation and the base of the OWASP Core Rule Set. Then built SSL Labs, whose A-to-F grade for a server’s TLS configuration turned an obscure ops detail into something executives asked about, and wrote Bulletproof TLS and PKI as the manual for fixing the grade.

Locked inCard page
033Rare
Mark Dowd card front
Mark DowdThe Art of Software Security AssessmentThe code-audit bible, and the Sendmail and Flash bugs behind it
Code auditingMemory corruptionExploit mitigation
Australia2002–present84

Co-wrote The Art of Software Security Assessment with John McDonald and Justin Schuh, still the most thorough published treatment of how to find memory-safety and logic flaws by reading code. Found deep bugs in Sendmail, OpenSSH and Flash while at ISS X-Force and IBM, and founded Azimuth Security. His work is why a generation of auditors know what to look for in a parser.

Locked inCard page
034Epic
Thomas Dullien card front
Thomas DullienHalvar FlakeThe Binary Diffing PioneerBinDiff, and the theory of weird machines
Reverse engineeringPatch analysisExploit theory
Germany2000–present85

Built the graph-based binary diffing that made it routine to extract the vulnerability out of a vendor patch, founded zynamics around BinDiff and VxClass, and sold it to Google in 2011. Later worked in Project Zero and wrote the “weird machines” framing that treats exploitation as programming an unintended state machine inside the target.

Locked inCard page
035Rare
Alex Sotirov card front
Alex SotirovThe Rogue CA DemonstrationMD5 collisions against a real certificate authority
PKIExploit mitigationBrowser security
Bulgaria / USA2007–present83

Co-authored “Bypassing Browser Memory Protections”, the 2008 paper that showed how attackers were routing around DEP and ASLR, then at 25C3 the same year demonstrated a working rogue certificate authority built on MD5 collisions — which pushed the CA industry off MD5 for good. Co-founded Trail of Bits.

Locked inCard page
036Rare
Thomas Ptacek card front
Thomas PtacekThe IDS Evasion PaperInsertion, Evasion and Denial of Service, and Matasano
Intrusion detectionCryptographic reviewAppsec consulting
USA1998–present82

Co-wrote the 1998 paper with Timothy Newsham showing that a network IDS which reassembles traffic differently from the host it protects can be walked straight past — the work that forced every vendor to rethink normalisation. Co-founded Matasano and later Latacora, and wrote the Cryptopals challenges that taught a generation how crypto actually breaks.

Locked inCard page
037Epic
Matthew D. Green card front
Matthew D. GreenThe Cryptography AuditorTrueCrypt audit, and explaining broken crypto in public
Applied cryptographyProtocol analysisPublic explanation
USA2010–present86

Johns Hopkins cryptographer who co-led the Open Crypto Audit Project’s review of TrueCrypt, contributed to the analysis of Dual_EC_DRBG and the RSA BSAFE backdoor, and worked on the attacks behind Logjam and DROWN. His blog is the standard place the rest of the industry goes to find out how badly a new crypto story is being reported.

Locked inCard page
038Epic
J. Alex Halderman card front
J. Alex HaldermanThe Voting Machine AuditorCold boot attacks, election security, and Let’s Encrypt
Election securityMeasurementPKI
USA2008–present87

Co-authored the cold boot attack paper showing DRAM retains keys after power off, then spent a career demonstrating — in court and in front of legislatures — that deployed voting machines could be reprogrammed. Co-founded the Internet Security Research Group behind Let’s Encrypt, and co-authored the ZMap internet-wide scanner and the Logjam and FREAK results.

Locked inCard page
039Epic
Nadia Heninger card front
Nadia HeningerThe Key-Entropy AuditorMining Your Ps and Qs, Logjam, and measuring real deployed crypto
CryptanalysisInternet measurementKey generation
USA2012–present85

Co-authored “Mining Your Ps and Qs”, which scanned the whole IPv4 internet and found that a meaningful share of TLS and SSH keys shared factors because embedded devices generated them without entropy — and then factored them. Followed it with Logjam, DROWN and FREAK, a body of work whose method is: measure what is actually deployed, then break the weak part.

Locked inCard page
040Rare
Troy Hunt card front
Troy HuntKeeper of Have I Been PwnedTurning breach data into a public service
Breach dataPassword securityPublic awareness
Australia2013–present84

Built Have I Been Pwned in 2013 as a way for ordinary people to find out whether their account was in a dump, and it became infrastructure: browsers, password managers and the NIST-endorsed practice of checking passwords against known-breached lists all query it, using a k-anonymity scheme that never sends the password. Runs it as a public good rather than a product.

Locked inCard page
041Legendary
Window Snyder card front
Window SnyderThe Serial Security ChiefWindows XP SP2, Firefox, Apple, Intel, and Threat Modeling
Product securityThreat modellingDevice security
USA2002–present89

Was security lead and signoff for Windows XP Service Pack 2 and Windows Server 2003, co-wrote the Threat Modeling book that came out of that era, then ran security at Mozilla for Firefox, at Apple on privacy and security strategy, at Fastly and Square, and became Intel’s first chief software security officer. Founded Thistle Technologies in 2020 to bring update infrastructure to embedded devices.

Locked inCard page
042Rare
Heather Adkins card front
Heather AdkinsGoogle’s Founding DefenderTwenty-plus years of Google security, and Operation Aurora
Incident responseEnterprise defenceReliability
USA2002–present85

A founding member of Google’s security team who built and ran its incident response function, including the response to the 2009 Operation Aurora intrusion that Google chose to disclose publicly — a decision that reset industry norms on breach transparency. Co-authored Building Secure and Reliable Systems, and has served on US federal cybersecurity advisory bodies.

Locked inCard page
043Rare
Parisa Tabriz card front
Parisa TabrizGoogle’s Security PrincessChrome security, and the campaign that made HTTPS the default
Browser securityHTTPS adoptionSecurity engineering
USA2007–present86

Joined Google as a penetration tester, printed “Security Princess” on her business card, and rose to run Chrome. Led the multi-year project to mark plain HTTP as “Not secure” in the world’s most-used browser, which more than anything else moved the web to encryption by default, and pushed Project Zero’s 90-day disclosure deadline as an industry-wide forcing function.

Locked inCard page
044Rare
Alex Stamos card front
Alex StamosThe CSO Who Resigned Over ItYahoo, Facebook, and saying the uncomfortable thing in public
Enterprise securityPlatform abuseDisinformation
USA2004–present85

Was CISO at Yahoo, where he objected to a government email-scanning programme, then CSO at Facebook through the investigation into foreign influence operations, leaving in 2018 over how much the company would disclose. Publicly challenged the NSA director on encryption backdoors, founded the Stanford Internet Observatory, and co-founded iSEC Partners and later Krebs Stamos Group.

Locked inCard page
045Legendary
Dan Geer card front
Dan GeerThe Field’s Dissenting EconomistCyberInsecurity: The Cost of Monopoly, and getting fired for it
Security economicsRisk managementPolicy
USA1998–present88

Co-authored the 2003 CCIA report arguing that monoculture in operating systems was itself a national security risk, and was fired by @stake, then a Microsoft consultancy, the day it was published. Went on to serve as chief information security officer of In-Q-Tel and to give a run of Black Hat and USENIX keynotes that are still the most quoted long-form arguments about security policy the field has produced.

Locked inCard page
046Legendary
Kevin Mandia card front
Kevin MandiaThe Incident Response IndustryMandiant, and the APT1 report that named the unit
Incident responseThreat attributionForensics
USA2004–present88

Founded Mandiant in 2004 and built breach response into a business that governments and Fortune 100 boards call at 2am. In 2013 the company published APT1, a report attributing years of intrusions to a specific People’s Liberation Army unit with building photographs and operator handles — the moment public, named attribution became something private companies did.

Locked inCard page
047Legendary
Mikko Hyppönen card front
Mikko HyppönenThe Malware HistorianThree decades at F-Secure, and finding the authors of Brain
Malware analysisThreat researchPublic communication
Finland1991–present87

Has been analysing malware at F-Secure since 1991, through the DOS virus era, Sasser and Blaster, Stuxnet and modern ransomware. Tracked down and interviewed the Pakistani brothers who wrote Brain, the first PC virus, twenty years after the fact. Formulated Hyppönen’s law — if it is smart, it is vulnerable — and is the researcher most often trusted to explain a live incident to the public.

Locked inCard page
048Rare
Robert M. Lee card front
Robert M. LeeThe Industrial Control DefenderDragos, and the analysis of the Ukraine grid attacks
ICS/OT securityThreat intelligenceIncident response
USA2013–present83

A former US Air Force cyber warfare officer who co-authored the analysis of the 2015 Ukrainian power grid attack and the later CRASHOVERRIDE and TRISIS malware, then founded Dragos to do industrial control system defence as a specialism rather than an IT afterthought. Co-wrote the SANS ICS courses that most OT defenders come through.

Locked inCard page
049Rare
Lesley Carhart card front
Lesley Carharthacks4pancakesThe Industrial Incident ResponderOT forensics, and teaching the field how to get into the field
Digital forensicsICS/OT securityMentorship
USA2010–present81

Led incident response at Motorola Solutions and then at Dragos, running investigations inside live industrial networks where you cannot simply reimage the plant. Writes long-running public guidance on breaking into and surviving the profession, founded PancakesCon, and holds the SANS Lifetime Achievement Award for that work as much as the casework.

Locked inCard page
050Rare
Katie Nickels card front
Katie NickelsThe ATT&CK TranslatorMITRE ATT&CK threat intelligence, and making CTI actionable
Threat intelligenceDetection engineeringATT&CK
USA2015–present82

Was the threat intelligence lead for MITRE ATT&CK during the years it became the shared vocabulary defenders use to describe adversary behaviour, then went to Red Canary as director of intelligence. Teaches the SANS cyber threat intelligence course and spends most of her public work on the unglamorous question of how an intelligence report turns into a detection someone actually deploys.

Locked inCard page
Selection

What earns a card

Documented

It has to be on the record

Every card cites the paper, the book, the source tree or the report behind the claim. If we cannot link it, it does not go on the card.

Load-bearing

Somebody still depends on it

A protocol, a tool, a process or a body of research that defenders are using today. A long job title is not a qualification for this set.

Distinct

Nobody appears twice

Series Two documents the people who broke things. This one documents the people whose job was to hold. A name in Hacking Legends cannot also be here.

Real faces

No invented likenesses

A portrait is painted from an identified photograph of that person, credited to the photographer. Where no properly licensed photo exists, the card carries no face. An earlier version of this set generated faces from text alone; those were fabrications and they were withdrawn.

Who are we missing?

Fifty slots is not many for a field this old, and the cuts were painful. Nominate a defender, challenge a stat line, or rewrite a scouting report — every card starts as a pull request.