Winning DEF CON CTF, Failing at Consulting, and Building an All-Senior Hacker Firm — Erik Cabetas (Include Security)
Erik Cabetas won DEF CON CTF his first year, failed at running a consulting shop, then came back five years later and built Include Security into an all-senior application security firm serving billion-dollar software companies.
Erik Cabetas is the founder and "head hacker herder" of Include Security, an application security firm he's run for nearly 15 years.
His path there was anything but linear. He was a materials engineering major who dropped an entire semester two months before graduation to switch to computer science. He learned to hack from zines and FTP servers before Google existed, after a college roommate put Back Orifice on his machine in 1998. He got his first security job by cold-emailing, at 4am, a guy he'd seen on a documentary that aired at 3am. He won DEFCON CTF in 2003 on a team that was in dead last when he asked to join — and his contribution wasn't the two exploits he wrote, it was reorganizing who on the team did what.
Then he tried to start a company, and it didn't work. He went solo for five quarters, took four clients, hit his revenue target almost exactly to the dollar — and quit anyway, because he'd worked himself into the ground to get there and couldn't see it getting easier.
Five years later he tried again. Include Security launched in January 2011 with three clients already signed.
This is a full start-to-finish conversation. Erik walks through the Ernst & Young Advanced Security Center team that spawned Bishop Fox, Gotham Digital Science, and his own company. Burning out on the road at Fortify Software. Running security, fraud, and trust & safety at The Ladders through the 2008 crash — including being handed the layoffs after HR was laid off. And what it actually took to build a firm that deliberately has no junior hackers on it, in an industry where nearly everyone runs a 70%-junior pyramid.
He's unusually candid about the parts founders normally skip: what his rent was, what number he set for himself, why sales and legal were harder than any technical work he'd ever done, why refusing to use his own network was a mistake, why it took him five years to find one salesperson he trusted, and why the real driver of pen testing demand is B2B contract language rather than compliance.
Some of what we get into:
- Learning security in 1998, and why Erik thinks it's harder now, not easier
- The Honeynet Project forensics challenges, and writing for 2600 at 20
- Getting hired at E&Y off a cold email, and being 22 telling a Fortune 500 you have root
- Why he left a job the moment they promoted him
- Include Security "version zero" — the attempt that failed, and exactly why
- Reading an entire commercial product's source code in a week to survive a customer site
- Cutting seven-figure credit card fraud by 98% with a few hundred lines of T-SQL
- The bad RFP responses that convinced him the industry could be done better
- The all-senior model vs. the pyramid model, and what clients actually notice
- 54 programming languages, and what they found in the largest production Rust app they've assessed
- How paid research time works, and the blog posts that turned into DEF CON talks
- Concrete advice for starting a consulting firm today — including why he lets future competitors subcontract off his company
- Drum & bass, the Spawn soundtrack, and searching Napster by random nouns
Links
- Include Security: https://includesecurity.com
- Include Security research blog: https://blog.includesecurity.com
Books Erik recommends
- Security Engineering — Ross Anderson
- The Ghidra Book — Chris Eagle & Kara Nance
- Never Split the Difference — Chris Voss
- The Trusted Advisor — David Maister