PirOps: What 18th-Century Piracy can Teach Us about SecOps

Aron Eidelman (Google)

BSidesSF 2024 · Day 1

Overview

In his BSidesSF 2024 talk, "PirOps: What 18th-Century Piracy can Teach Us about SecOps," Aron Eidelman draws a compelling and unexpected parallel between the operational practices of 18th-century Atlantic pirates and modern security operations (SecOps) and Site Reliability Engineering (SRE) principles. Eidelman, leveraging his experience at Google working with SRE teams, argues that the unique social and operational structures adopted by pirates during their "Golden Age" offer profound insights into building effective, resilient, and human-centric security teams. The talk demystifies popular pirate myths to reveal a sophisticated, emergent culture focused on collaboration, risk management, and employee well-being, which directly maps to contemporary best practices in technology and security.

Watch on YouTube

Visual summary for PirOps: What 18th-Century Piracy can Teach Us about SecOps by Aron Eidelman
Visual summary for PirOps: What 18th-Century Piracy can Teach Us about SecOps by Aron Eidelman

Key moments

  1. 01:00 18th-century pirates as technically skilled operators of cutting-edge ship technology.
  2. 06:00 Introduction of 'The Articles' as a constitution for shared risk planning and crew support.
  3. 08:00 Mapping pirate culture to Westrum's generative culture model for high-performing teams.
  4. 11:00 Defining 'toil' in the SRE sense: repetitive, manual work that hinders efficiency.
  5. 13:00 Pirate strategy of redundancy (overabundance of crew, short shifts) to reduce toil and improve morale.
  6. 15:00 SRE principle: manual operations are a bug, excess capacity for automation is a feature.
  7. 17:00 Pirate captain's quarters repurposed; analogy to SRE Incident Commander role (leadership as function).
  8. 19:00 Questioning professional management as an anti-pattern, advocating for functional leadership.

PirOps: What 18th-Century Piracy can Teach Us about SecOps

Speakers: Aron Eidelman

Conference: BSidesSF 2024

YouTube: https://www.youtube.com/watch?v=yv3frK6QcOg

Overview

In his BSidesSF 2024 talk, "PirOps: What 18th-Century Piracy can Teach Us about SecOps," Aron Eidelman draws a compelling and unexpected parallel between the operational practices of 18th-century Atlantic pirates and modern security operations (SecOps) and Site Reliability Engineering (SRE) principles. Eidelman, leveraging his experience at Google working with SRE teams, argues that the unique social and operational structures adopted by pirates during their "Golden Age" offer profound insights into building effective, resilient, and human-centric security teams. The talk demystifies popular pirate myths to reveal a sophisticated, emergent culture focused on collaboration, risk management, and employee well-being, which directly maps to contemporary best practices in technology and security.

Eidelman's central thesis is that the voluntary, self-organized nature of pirate crews, driven by a desire to escape the oppressive conditions of merchant and military ships, led to the development of operational models that prefigure many of the principles now championed in SRE and DevOps. By examining pirate culture, their approach to risk, their management of "toil," and their unique leadership structures, the presentation provides a fresh perspective on how security teams can foster a more generative, productive, and sustainable work environment. This talk is particularly relevant for security professionals seeking to move beyond reactive, fear-driven security models towards proactive, collaborative, and psychologically safe operational frameworks.

The talk is not about AI security, as Eidelman humorously notes at the outset, but rather a deep dive into historical sociology applied to modern technical operations. It challenges conventional notions of leadership and organizational structure, advocating for models that prioritize shared fate, autonomy, and continuous improvement. By framing these complex organizational concepts through the engaging lens of pirate history, Eidelman makes abstract SRE and SecOps principles accessible and memorable, offering actionable insights for anyone looking to optimize their team's performance and culture.

Background

▶ Watch: 18th-century pirates as technically skilled operators of cutting-edge ship te... (01:00)

The talk focuses specifically on 18th-century Atlantic Pirates, active roughly between 1690 and 1725, a period often referred to as the Golden Age of piracy. Eidelman emphasizes that these pirates were distinct from other pirate groups throughout history due to their specific time and place, which fostered unique operational practices. This era was characterized by relative peace between major empires like the British and Spanish, yet it saw a significant population of highly skilled sailors. These individuals possessed expertise in operating ships, which Eidelman likens to the "cutting-edge technology" of their time, requiring a small percentage of the population to master.

A crucial aspect of this background is the demystification of popular pirate culture, which is often shaped by movies and video games. Eidelman clarifies several misconceptions:

  • Violence: Pirates primarily used psychological intimidation rather than outright violence to achieve their aims. Figures like Blackbeard were renowned for their intimidating personas, not necessarily for constant bloody battles.
  • Voluntary Participation: Sailors overwhelmingly chose to join pirate crews, often preferring it over merchant or military service due to the promise of freedom and better conditions.
  • Captain's Role: Pirate captains were not owners or members of a higher social class. They were typically "of the crew," integrated members who could be replaced without bloody mutiny if the crew disapproved. The crew, not the captain, owned the ship (with the notable exception of Stede Bonnet).
  • Logging: Pirates did not keep good logs, making historical research challenging but also highlighting their non-bureaucratic nature.

The problem that pirates implicitly solved, and which modern SecOps teams often face, was the oppressive and often pathological work environments of traditional organizations. Merchant and military ships of the era were characterized by a lack of care for the crew, with sick or disabled sailors often abandoned. This environment fostered fear, blame, and a lack of trust, which Eidelman later categorizes as a "pathological culture." Pirates, by contrast, sought to create a new way of operating, one that acknowledged the inherent risks of seafaring but provided a framework for collective support and shared responsibility. Their "Articles" – a kind of ship's constitution – outlined everything from operational procedures to compensation for injuries, demonstrating a proactive approach to risk planning that was absent in other maritime professions. This foundational difference in culture and operational philosophy is what Eidelman explores as a model for modern technical teams.

Key Findings

▶ Watch: Mapping pirate culture to Westrum's generative culture model for high-perform... (08:00)

Aron Eidelman's analysis of 18th-century piracy reveals several key findings that offer profound lessons for modern SecOps and SRE teams:

  • Emergent, Generative Culture: Pirate culture was not mandated but emergent and inspiring. It lacked a formal ideology but drew people in through its promise of freedom and better working conditions. This aligns with the concept of a generative culture (from the Westrum organizational culture model), characterized by high trust, good information flow, and a focus on performance, contrasting sharply with the fear-driven "pathological" or rule-bound "bureaucratic" cultures of merchant and military ships.
  • Shared Fate and Risk Planning: Pirates understood the inherent risks of their profession but, because they voluntarily formed their crews, they collectively acknowledged and planned for these risks. Their "Articles" detailed compensation for injuries and incidents, ensuring a shared fate where failure outside of one's control was met with support, not abandonment. This fostered psychological safety and trust among the crew.
  • Benefits of Generative Culture: Drawing on DORA research (DevOps Research and Assessment), Eidelman highlights that a generative culture, alongside flexibility and effective work distribution, leads not only to increased job satisfaction but also to tangible gains in productivity and the ability to "ship things well."
  • Toil Reduction as a Strategy: Pirates actively reduced toil – repetitive, manual, predictable work – by employing an overabundance of crew and implementing small work shifts. This strategy of building "slack as a feature" ensured that crew members were not overworked, were happier, and were always ready for critical tasks like boarding enemy vessels.
  • Manual Operations as a Bug: The SRE perspective, mirrored by pirate practices, views any manual operation as a bug. The goal is to use excess capacity (the "slack" created by reduced toil) for automation and project work, proactively addressing potential issues rather than constantly reacting.
  • Functional, Not Status-Based, Leadership: Pirate captains were members of the crew, chosen for their expertise, and their "Captain's Quarters" were often repurposed. This model of leadership is functional, not based on status, and is analogous to the Incident Commander role in SRE, where a specialist temporarily leads during an incident and then reintegrates into the team. This approach leads to lower recidivism of incidents.
  • Iterative Approaches to Change: Unlike merchant ships with their rigid, long-term travel plans (akin to a waterfall approach), pirate ships exhibited chaotic, crew-voted trajectories, constantly adapting to find safe ports and opportunities. This reflects an iterative approach to change, emphasizing small, fast failures and continuous adaptation.
  • Resilience and Integration: Despite their parasitic nature, pirates were successful for about 35 years, largely unchallenged by imperial powers initially. They also found ways to positively integrate into local economies, selling goods and maintaining good relations, demonstrating a form of sustainable operation within their ecosystem. Many pirates also successfully reintegrated into society, highlighting the adaptability of their model.

These findings collectively suggest that the operational success and appeal of 18th-century pirates stemmed from their innovative organizational design, which prioritized human factors, proactive risk management, and adaptive leadership – principles that remain highly relevant for modern technical and security teams.

Technical Deep Dive

▶ Watch: Pirate strategy of redundancy (overabundance of crew, short shifts) to reduce... (13:00)

Eidelman's talk delves into several technical and organizational concepts, drawing direct parallels between pirate practices and modern SRE/SecOps methodologies. The core of this deep dive lies in understanding organizational culture, toil reduction, and leadership structures.

Organizational Culture: The Westrum Model

Eidelman introduces the Westrum organizational culture model, which categorizes cultures into three types:

  1. Pathological Culture: Characterized by power orientation, fear, and blame. Information flow is poor, and people tend to hoard information. This is the environment pirates sought to escape on merchant and military ships, where sailors were often abandoned if sick or injured.
  2. Bureaucratic Culture: Defined by rules and silos. Accountability is low, and people often say, "that's not my job." This is common in larger organizations where a lack of a central mission leads to departmental focus over organizational goals.
  3. Generative Culture: Performance-oriented, with high trust, good information flow, and high levels of collaboration. Failure is an opportunity for learning, and support is provided in spite of failure. Pirate ships, with their intimate crews (typically much smaller than 300 people), exemplify this model. The threat is external (e.g., the ship sinking), but internally, there's strong cohesion and shared purpose.

The DORA research (DevOps Research and Assessment) further supports the benefits of a generative culture. Eidelman points out that such a culture, combined with flexibility and effective work distribution, not only boosts job satisfaction but also directly improves productivity, making it easier to "ship things" effectively. This isn't just an ideological preference; it has tangible business outcomes.

Toil Reduction and Redundancy

A significant portion of the deep dive focuses on toil, a key SRE concept. Eidelman clarifies that in SRE, toil is defined as repetitive, manual, predictable work that, while sometimes enjoyable, ultimately hurts an organization due to its inefficiency. It's distinct from overhead (e.g., weekly reports) or genuinely enjoyable manual tasks. The SRE perspective is that manual operations should be viewed as a bug – if you have to do something manually to fix a problem, that indicates a systemic issue that needs automation.

Pirates intuitively practiced toil reduction through redundancy as a strategy:

  • Overabundance of Crew: Unlike merchant ships, which minimized crew size for cost efficiency, pirate ships carried far more crew than necessary for their medium-sized frigates. This was strategic; it aided in psychological intimidation (e.g., "10 of us for every one of you") and ensured ample personnel.
  • Small Work Shifts: With extra people, pirates could implement very short work shifts (e.g., 4 hours compared to 8-10 hours on a merchant vessel). This reduced fatigue, kept morale high, and ensured the crew was always fresh and ready for action, such as boarding an enemy ship.

This "slack as a feature" approach in piracy directly translates to modern SRE. The excess capacity created by reducing toil is not for idleness but for project work focused on automation and proactive problem-solving. Instead of constantly reacting to incidents, teams spend time anticipating risks and building automated solutions, transforming their work from standardized ticket resolution to strategic improvement.

Functional Leadership and Incident Management

Eidelman highlights the unique leadership structure on pirate ships. Captains were not owners but members of the crew. Their "Captain's Quarters" were often repurposed for storage or removed entirely, and captains slept with the rest of the crew in the lower decks. This symbolizes a leadership that is integrated and functional rather than status-driven.

This model finds its modern equivalent in the Incident Commander role within SRE. An Incident Commander is a temporary leadership position, assigned to the person most qualified for a specific incident. Their role is primarily to facilitate communication, coordination, and occasionally decision-making, ensuring efficient information flow between teams. Once the incident subsides, they reintegrate into the crew, returning to their individual contributor role. This contrasts with permanent leadership positions, which can lead to managers becoming out of touch with day-to-day operations or lacking specific expertise for every incident.

Eidelman raises the question: "is professional management an anti-pattern?" While acknowledging the need for professional managers for external stakeholders, HR, and fiduciary responsibilities, he argues that for highly technical teams, entrusting incident leadership to a qualified team member is crucial for career growth, team cohesion, and effective problem-solving. This functional leadership, where a leader steps in only when their specialty is required, has been shown in DORA research to lead to lower recidivism of incidents.

Iterative Approaches to Change

Finally, Eidelman touches upon iterative approaches to change. Merchant ships followed a rigid, pre-planned itinerary, akin to a waterfall approach. Pirate ships, however, had chaotic, crew-voted trajectories, constantly adapting to find safe ports and opportunities. This flexibility and continuous adaptation are hallmarks of agile and iterative development methodologies, emphasizing small, fast failures and learning. For organizations undergoing transformations like DevSecOps or trying to shift security left, Eidelman stresses the importance of managing expectations. Implementing vulnerability scanning, SCA (Software Composition Analysis), or SAST (Static Application Security Testing) abruptly without configuration will lead to high false positives and overburdened teams. Success requires small, iterative steps, accepting initial friction, and earning the trust of leadership for this experimental approach.

Demo / Proof of Concept

▶ Watch: SRE principle: manual operations are a bug, excess capacity for automation is... (15:00)

The talk "PirOps: What 18th-Century Piracy can Teach Us about SecOps" is a conceptual presentation that draws analogies between historical pirate practices and modern technical operations. As such, it does not include a live demonstration or a technical proof of concept of a software tool, system, or security vulnerability. Instead, the "proof of concept" is the historical evidence and the logical mapping of pirate organizational structures and cultural norms to the principles of Site Reliability Engineering and SecOps.

Defensive Implications

▶ Watch: Questioning professional management as an anti-pattern, advocating for functi... (19:00)

The insights gleaned from 18th-century pirate operations offer several actionable defensive implications for modern SecOps teams:

  1. Cultivate a Generative Security Culture: Security leaders should actively foster a generative culture within their teams. This means prioritizing trust, open communication, and psychological safety over fear and blame. When incidents occur, the focus should be on learning and support rather than assigning blame, ensuring that team members feel safe to report issues and experiment with solutions. This directly contributes to better information flow and collaboration, which are critical for effective security.
  2. Prioritize Toil Reduction and Automation: SecOps teams should adopt the SRE principle of viewing manual operations as a bug. Identify repetitive, predictable, and manual security tasks (e.g., routine log analysis, alert triage, vulnerability scanning configuration) and dedicate excess capacity to automation. This frees up security engineers for more strategic project work, such as building new security tools, improving existing systems, or proactively hunting for threats, rather than constantly reacting to incidents.
  3. Embrace Functional Leadership for Incident Response: Implement an Incident Commander model for security incidents. During a critical security event, empower the most qualified technical expert to temporarily lead the response, coordinating efforts and facilitating communication. This ensures that decisions are made by those with the deepest expertise in the specific area of the incident. Once the incident is resolved, this individual should reintegrate into the team, reinforcing that leadership is a function based on expertise, not a permanent status.
  4. Build Redundancy and Slack into Security Operations: Just as pirates maintained an overabundance of crew to reduce individual workload and ensure readiness, SecOps teams should strategically build redundancy and slack into their operations. This might involve cross-training team members, ensuring adequate staffing levels to prevent burnout, and allocating dedicated time for innovation and learning. This "slack" is not idleness but a critical feature that allows teams to absorb unexpected workloads, conduct proactive security research, and develop long-term defensive strategies.
  5. Plan for Risks and Foster Shared Fate: Adopt a proactive approach to risk planning, similar to "The Articles" of pirate ships. Clearly define how the team will respond to various types of security incidents, including support mechanisms for team members who might make mistakes or face burnout. Fostering a sense of shared fate ensures that individuals feel supported, even in the face of failure, which is crucial for maintaining morale and resilience in high-stress security environments.
  6. Manage Expectations for DevSecOps Transformations: When implementing DevSecOps or shifting security left, manage expectations with organizational leadership. Acknowledge that integrating security earlier in the development lifecycle (e.g., with vulnerability scanning, SCA, SAST) will initially generate false positives and require a learning curve for developers and security teams. Emphasize that success will come through iterative approaches, small steps, and continuous refinement, rather than an immediate, friction-free improvement.
  7. Collaborate Beyond the Organization: Recognize that some threats are systemic and cannot be fought by individual organizations alone. Just as merchants eventually enlisted imperial powers to combat piracy, individual companies should advocate for and participate in industry-wide collaborations, information sharing, and engagement with government agencies to address broader cyber threats. This collective defense approach is more effective against sophisticated and widespread attacks.

By applying these pirate-inspired principles, SecOps teams can move towards a more proactive, resilient, and human-centric operational model, ultimately enhancing their defensive capabilities and overall organizational security posture.

Key Takeaways

  • Generative Culture is Key: Adopting a generative culture (high trust, good information flow, performance-oriented) significantly boosts both job satisfaction and productivity in SecOps, mirroring the success of pirate crews.
  • Toil Reduction Drives Efficiency: Treat manual operations as a bug and actively reduce toil through automation. This frees up security professionals for strategic project work and proactive defense, rather than constant reactive firefighting.
  • Functional Leadership for Incidents: Embrace the Incident Commander model, where leadership during security incidents is temporary and based on expertise, not permanent status. This ensures the most qualified person leads and fosters team growth.
  • Build Slack and Redundancy: Strategically incorporate redundancy (e.g., cross-training, adequate staffing) and "slack" into SecOps teams. This allows for proactive work, innovation, and prevents burnout, much like pirates' small work shifts.
  • Shared Fate and Risk Planning: Foster a sense of shared fate and proactively plan for risks and failures, ensuring support for team members. This psychological safety is crucial for effective incident response and continuous improvement.
  • Iterative Approach to Security Transformation: When implementing new security initiatives like DevSecOps, adopt an iterative approach with small, experimental steps. Manage expectations regarding initial friction and false positives, focusing on continuous learning and adaptation.

About the Speaker(s)

Aron Eidelman is a speaker who has experience working at Google, specifically with Site Reliability Engineering (SRE) teams. His background in SRE and his observations of how security teams adopt SRE practices inspired his unique perspective on organizational culture and operational efficiency. He presented his talk, "PirOps: What 18th-Century Piracy can Teach Us about SecOps," at BSidesSF 2024.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk cleverly uses the analogy of 18th-century pirates to illustrate core SRE and SecOps principles, focusing on generative culture, toil reduction, and functional leadership. While not a deep dive into a new exploit or defensive technique, it provides valuable insights into how security teams can be structured and operated more effectively. The historical context makes established concepts fresh and engaging, offering actionable takeaways for improving team dynamics and operational resilience.

Heather Calloway (CISO) — MUST SEE

This talk offers a highly relevant and actionable framework for CISOs and security leaders by drawing compelling parallels between 18th-century pirate governance and modern SecOps principles. It effectively translates abstract organizational theory into practical insights on fostering generative cultures, reducing operational toil, and implementing functional leadership. The speaker provides a clear path for improving security program effectiveness, team resilience, and overall business impact, making it essential viewing for anyone leading a security organization.

→ Top-rated talks at BSidesSF 2024

All talks from BSidesSF 2024