DEF CON Unplugged: Cocktails & Cyber with Jeff & Jen
Jen Easterly, Jeff Moss
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
This DEF CON Unplugged session, titled "Cocktails & Cyber," offered a unique glimpse into the evolving relationship between the U.S. government's lead civilian cybersecurity agency and the broader hacker community. Featuring Jen Easterly, the Director of the Cybersecurity and Infrastructure Security Agency (CISA), and Jeff Moss, the renowned founder of DEF CON and Black Hat, the talk transcended traditional conference presentations by adopting an informal, conversational format. The core of the discussion revolved around the critical importance of building trusted partnerships and fostering genuine community engagement as foundational elements of national cybersecurity strategy.

Key moments
- 0:00 Introduction and Cocktails & Cyber format
- 2:00 Jen Easterly on Defcon: favorite con of the year
- 2:20 Jeff's advice for Sissa Director: be part of community
- 2:35 Sissa's mission: catalyzing trusted partnerships, not intel
- 3:00 Building trust: people trust people, not institutions
DEF CON Unplugged: Cocktails & Cyber with Jeff & Jen
Speakers: Jen Easterly, Director, CISA; Jeff Moss, Founder, DEF CON
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=QCoRhK7u9qw
Overview
This DEF CON Unplugged session, titled "Cocktails & Cyber," offered a unique glimpse into the evolving relationship between the U.S. government's lead civilian cybersecurity agency and the broader hacker community. Featuring Jen Easterly, the Director of the Cybersecurity and Infrastructure Security Agency (CISA), and Jeff Moss, the renowned founder of DEF CON and Black Hat, the talk transcended traditional conference presentations by adopting an informal, conversational format. The core of the discussion revolved around the critical importance of building trusted partnerships and fostering genuine community engagement as foundational elements of national cybersecurity strategy.
The session served as a powerful demonstration of CISA's commitment to a collaborative defense model, emphasizing that effective cybersecurity cannot be achieved in isolation. Director Easterly articulated CISA's distinct role—not as an intelligence, law enforcement, or regulatory body—but as a partner dedicated to supporting and serving the American people through collective action. The presence of a high-ranking government official like Director Easterly at DEF CON, engaging openly with the community, underscores a significant paradigm shift in how government agencies approach cybersecurity, moving from a posture of separation to one of active collaboration and mutual trust.
The conversation highlighted the strategic imperative of human-centric relationships in a field often dominated by technological discussions. Jeff Moss's advice to Director Easterly—to "be a part of the community"—emerged as a central theme, illustrating the profound impact of personal engagement in bridging divides and catalyzing cooperation across diverse stakeholders, including industry, researchers, federal, state, local governments, and election officials. This approach is deemed crucial for building resilience against an increasingly sophisticated and pervasive threat landscape.
Background
▶ Watch: Introduction and Cocktails & Cyber format (0:00)
The cybersecurity landscape has historically been characterized by a complex and often strained relationship between government entities and the independent hacker and security research communities. For decades, a significant trust deficit existed, stemming from differing objectives, operational methodologies, and sometimes adversarial interactions. Government agencies, particularly those involved in national security and law enforcement, often operated under strict secrecy, perceiving external researchers with skepticism, while the hacker community frequently viewed government with distrust, fearing surveillance or legal repercussions for vulnerability research.
This dynamic began to shift as the scale and sophistication of cyber threats escalated, making it clear that no single entity—government or private—could adequately defend against the global challenges posed by nation-state actors, organized crime, and sophisticated persistent threats. The realization that cybersecurity is a collective defense problem necessitated a re-evaluation of engagement strategies. The creation of CISA in 2018 under the Department of Homeland Security marked a pivotal moment, establishing a civilian agency specifically tasked with improving the nation's cybersecurity and critical infrastructure resilience, distinct from intelligence or law enforcement mandates.
CISA's mandate, to secure the nation's critical infrastructure from cyber and physical threats, inherently requires broad collaboration. Critical infrastructure, encompassing sectors like energy, water, healthcare, and finance, is largely owned and operated by the private sector. This necessitates a model where government acts as an enabler and partner, rather than solely an enforcer or intelligence gatherer. Events like DEF CON, founded by Jeff Moss, have long served as crucial forums for the independent security research community, bringing together diverse talents and perspectives. Moss himself has played a unique role in bridging these worlds, serving on government advisory bodies and advocating for greater dialogue between hackers and policymakers.
The problem that CISA, under Director Easterly's leadership, seeks to address is the inherent fragility of a fragmented defense. Without coordinated effort, shared intelligence, and a common understanding of threats and vulnerabilities, the aggregate security posture of the nation remains weak. The challenge lies not just in technical solutions but in overcoming the human and organizational barriers that prevent effective collaboration. Director Easterly’s approach, as articulated in this talk, directly confronts this historical context by advocating for a strategy built on transparency, empathy, and direct personal engagement, seeking to transform historical distrust into a foundation for proactive, collective security.
Key Findings
▶ Watch: Jen Easterly on Defcon: favorite con of the year (2:00)
The central "findings" of this session are not technical exploits or vulnerability disclosures, but rather profound strategic insights into effective cybersecurity governance and partnership. Director Jen Easterly succinctly articulated CISA's core operational philosophy, which represents a significant departure from traditional government engagement models. The primary insights include:
- CISA's Unique Role and Mandate: Director Easterly clarified that CISA is "not an intel agency, we're not a law enforcement agency, we're not a regulator." This explicit statement is a critical finding, as it directly addresses historical misconceptions and anxieties within the security community about government involvement. By defining what CISA is not, Easterly effectively delineates its role as a supportive, collaborative, and non-punitive partner, primarily focused on national cyber defense and resilience.
- The Imperative of Trusted Partnerships: The success of CISA's mission is "predicated on our ability to catalyze trusted partnerships." This emphasizes that CISA's effectiveness hinges entirely on its capacity to build and maintain strong relationships across a broad spectrum of stakeholders. These partners include "industry, with the research community, with the hacker community, across federal government, with the state and local community, with election officials." This holistic view of partnership acknowledges the interconnectedness of the cybersecurity ecosystem and the necessity of engaging all relevant parties.
- Human-Centric Trust Building: Perhaps the most salient finding is the principle that "people don't trust institutions, they trust people." This insight, which Director Easterly attributes to Jeff Moss's advice, underpins her entire engagement strategy. It highlights the recognition that genuine collaboration requires direct, personal interaction and relationship building, rather than relying solely on formal institutional channels. Her consistent presence at DEF CON and similar forums is a direct manifestation of this philosophy, demonstrating a commitment to human connection over bureaucratic distance.
- Community Engagement as a Cornerstone: Jeff Moss's foundational advice to "be a part of the community" served as a guiding principle for Director Easterly. This elevates community engagement from a peripheral activity to a core strategic imperative for CISA. It implies active participation, listening, learning, and contributing to the broader cybersecurity ecosystem, rather than merely dictating or observing from a distance. This involves understanding the community's perspectives, challenges, and innovations to better integrate them into national defense efforts.
These findings collectively illustrate a deliberate and strategic effort by CISA to redefine its relationship with the cybersecurity community. By clearly articulating its non-enforcement role, prioritizing trusted, human-centric partnerships, and embedding itself within the community, CISA aims to foster an environment of open communication and collective action essential for robust national cybersecurity.
Technical Deep Dive
▶ Watch: Jeff's advice for Sissa Director: be part of community (2:20)
While the "Cocktails & Cyber" session itself did not delve into specific technical vulnerabilities, code examples, or protocol analyses, the foundational philosophy articulated by Director Easterly has profound implications for the technical aspects of cybersecurity defense. The emphasis on "trusted partnerships" and direct engagement with the "hacker community" directly impacts how technical security challenges are identified, communicated, and mitigated across the nation.
Firstly, CISA's partnership model significantly enhances vulnerability disclosure and remediation. For a government agency not acting as law enforcement or a regulator, the trust built with the hacker and research community is paramount for receiving timely and actionable intelligence about newly discovered vulnerabilities. Researchers are often hesitant to disclose zero-day exploits or critical weaknesses to government entities if they fear legal repercussions or a lack of understanding. By fostering trust, CISA aims to become a preferred channel for responsible disclosure, enabling faster analysis, coordinated patching efforts, and the issuance of crucial alerts like CISA Alerts or Known Exploited Vulnerabilities (KEV) Catalog updates. This direct pipeline of information from the discoverers to the agency responsible for national defense is a critical technical advantage, allowing for proactive defense rather than reactive scrambling.
Secondly, the strategy of "by with and through partners" is vital for threat intelligence sharing. Technical threat intelligence—such as Indicators of Compromise (IOCs), Tactics, Techniques, and Procedures (TTPs), malware signatures, and attacker infrastructure details—is most effective when shared broadly and rapidly. CISA acts as a central hub for aggregating and disseminating this intelligence. Trusted relationships with industry and other government bodies facilitate bilateral and multilateral sharing of sensitive threat data, enriching the collective understanding of the adversary landscape. This enables organizations to implement technical controls, update intrusion detection systems, configure firewalls, and deploy endpoint detection and response (EDR) solutions more effectively based on real-time, actionable intelligence. Without trust, such sensitive information would remain siloed, diminishing its defensive value.
Furthermore, CISA's engagement with the research and hacker community directly influences the development and adoption of secure by design principles and cyber hygiene best practices. Discussions at forums like DEF CON often highlight emerging attack vectors, novel exploitation techniques, and systemic weaknesses in common software and hardware. By being "a part of the community," CISA gains early insight into these trends, which can then be translated into guidance for critical infrastructure operators and federal agencies. This proactive understanding helps shape technical recommendations for secure software development lifecycles (SSDLC), robust authentication mechanisms (e.g., multi-factor authentication - MFA), network segmentation, and data encryption standards. For example, CISA's focus on foundational cyber hygiene is directly informed by the prevalence of basic vulnerabilities exploited by adversaries, which are often discussed and demonstrated within the hacker community.
Finally, the collaborative approach extends to improving supply chain security. Modern technical systems rely on complex global supply chains, introducing numerous potential points of compromise. By partnering with industry, CISA can work towards establishing common technical standards, conducting joint assessments, and sharing information about supply chain risks and vulnerabilities. This collaboration helps in developing technical frameworks for validating software integrity, implementing Software Bill of Materials (SBOM), and enhancing the security of critical components, ultimately strengthening the technical resilience of the entire ecosystem against sophisticated supply chain attacks.
In essence, while the talk was not technically prescriptive, its message about trust and partnership forms the bedrock upon which effective technical cybersecurity operations are built. It enables the flow of critical information, accelerates vulnerability response, informs defensive strategies, and fosters a more secure technological landscape through collective intelligence and action.
Demo / Proof of Concept
▶ Watch: Sissa's mission: catalyzing trusted partnerships, not intel (2:35)
This particular DEF CON Unplugged session, "Cocktails & Cyber," did not feature any traditional technical demonstration or proof of concept in the sense of showcasing exploits, new tools, or architectural diagrams. The format was explicitly designed as an informal, conversational gathering, as implied by the title and the speakers' opening remarks about mixing drinks and having a discussion.
Instead of a technical demonstration, the session itself served as a proof of concept for Director Easterly's stated philosophy of building "trusted partnerships" through direct, personal engagement. The act of the CISA Director participating in a relaxed, open dialogue at DEF CON, a conference historically known for its independent and sometimes critical stance towards government, directly embodied the principle that "people don't trust institutions, they trust people." Her presence, willingness to engage, and explicit articulation of CISA's non-regulatory, non-law enforcement role demonstrated her commitment to bridging the gap between government and the hacker community. This informal setting, therefore, acted as a living illustration of the very collaborative approach CISA advocates for, proving that genuine interaction can foster the trust necessary for collective cybersecurity efforts.
Defensive Implications
▶ Watch: Building trust: people trust people, not institutions (3:00)
The conversational insights shared by Director Jen Easterly and Jeff Moss, particularly CISA's philosophy of "trusted partnerships" and community engagement, carry significant and actionable defensive implications for organizations across all sectors, not just federal agencies. These implications shift the focus from purely technical controls to a more holistic, collaborative security posture.
- Embrace Collective Defense: The most critical implication is the necessity of adopting a collective defense mindset. No single organization, regardless of size or resources, can independently defend against the full spectrum of modern cyber threats. Defenders must actively seek out and participate in information-sharing initiatives. This means joining Information Sharing and Analysis Centers (ISACs), engaging with CISA's programs (like the Joint Cyber Defense Collaborative - JCDC), and contributing to threat intelligence platforms. By sharing threat indicators, attack methodologies, and defensive strategies, all participants benefit from a broader, more timely understanding of the adversary landscape.
- Proactive Vulnerability Management and Disclosure: Organizations should cultivate a more open and proactive approach to vulnerability management. This includes establishing clear and accessible vulnerability disclosure programs (VDPs), encouraging ethical hackers to report findings, and engaging with the security research community. CISA's model suggests that fostering trust with researchers leads to earlier detection and remediation of weaknesses, preventing potential exploitation. Rather than viewing external researchers as a threat, defenders should see them as valuable, crowd-sourced assets in identifying critical security flaws.
- Build Internal and External Trust: The principle that "people don't trust institutions, they trust people" is vital internally and externally. Within organizations, security teams must build trust with development, operations, and leadership to ensure security is integrated from design to deployment. Externally, establishing personal relationships with peers in other companies, government agencies like CISA, and the broader security community facilitates candid discussions and robust collaboration during incidents or when sharing sensitive information. This human element is crucial for effective incident response and crisis management.
- Understand CISA's Role as a Partner: Defenders need to clearly understand CISA's non-regulatory, non-law enforcement role. This understanding should encourage organizations, especially those operating critical infrastructure, to engage with CISA without fear of punitive action. CISA aims to provide assistance, guidance, and threat intelligence. Organizations should leverage CISA's resources, such as its Cybersecurity Advisories, Capacity Enhancements, and Incident Response Services, as a trusted partner in improving their security posture.
- Prioritize Cyber Hygiene and Foundational Security: While not explicitly technical in the talk, the emphasis on CISA's supportive role inherently points to its efforts in promoting fundamental cyber hygiene. Defenders should continuously reinforce basic security practices: strong multi-factor authentication (MFA), regular patching, robust endpoint protection, network segmentation, and incident response planning. These foundational elements are often overlooked but are consistently highlighted by CISA as critical for defending against common attack vectors.
- Engage with the Broader Cybersecurity Community: Active participation in cybersecurity conferences, forums, and working groups allows defenders to stay abreast of emerging threats, learn best practices, and contribute to the collective knowledge base. It also helps in identifying potential partners for future collaborations. The hacker community, in particular, offers unique perspectives and innovative solutions that can enhance traditional defensive strategies.
By internalizing and acting upon these defensive implications, organizations can move beyond a reactive, siloed approach to cybersecurity and contribute to a stronger, more resilient collective defense ecosystem, aligning with CISA's vision for national security.
Key Takeaways
- Community Engagement is Paramount: CISA's strategy under Director Jen Easterly prioritizes direct engagement with the cybersecurity community, including hackers and researchers, as a cornerstone of national defense.
- Trust is Personal, Not Institutional: Effective partnerships are built on personal relationships and trust between individuals, rather than solely through formal institutional channels.
- CISA's Role is Collaborative, Not Coercive: CISA explicitly defines itself as a partner, not an intelligence agency, law enforcement body, or regulator, aiming to foster an environment of open communication and support.
- Collective Defense is Essential: No single entity can secure the nation's critical infrastructure; success depends on catalyzing trusted partnerships across industry, government, and the research community.
- Proactive Engagement Bridges Divides: High-level government presence at events like DEF CON demonstrates a commitment to transparency and helps bridge historical trust deficits between government and the hacker community.
- Human-Centric Strategy Drives Technical Outcomes: While the talk wasn't technical, the philosophy of trust and collaboration directly enables better vulnerability disclosure, threat intelligence sharing, and the adoption of secure technical practices.
About the Speaker(s)
Jen Easterly is the Director of the Cybersecurity and Infrastructure Security Agency (CISA), the U.S. government's lead civilian agency for cybersecurity and critical infrastructure protection. As highlighted in the talk, she is a multiple-time veteran of DEF CON, considering it her favorite conference of the year. Her approach to leading CISA is deeply influenced by the philosophy of building "trusted partnerships" through direct, personal engagement with the cybersecurity community. She emphasizes CISA's role as a supportive partner rather than an intelligence, law enforcement, or regulatory body, dedicated to helping secure the American people.
Jeff Moss, famously known as "Dark Tangent," is the founder of the highly influential DEF CON and Black Hat security conferences. He holds a unique position bridging the independent hacker community and government cybersecurity circles, serving on various advisory councils, including one for CISA. His advice to Jen Easterly—to "be a part of the community"—was a pivotal point in the discussion, underscoring his belief in the power of direct engagement and community involvement for effective cybersecurity. Moss's role has been instrumental in fostering dialogue and collaboration between diverse stakeholders in the cybersecurity world.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This session, while devoid of technical exploits, delivered critical strategic signal from the highest levels of CISA. Director Easterly's direct articulation of CISA's non-regulatory, non-law enforcement role, coupled with Jeff Moss's foundational advice on human-centric trust, represents a significant, actionable shift in government-community engagement. It's a masterclass in strategic communication, providing clarity and a roadmap for collective defense that every security professional needs to understand.
Heather Calloway (CISO) — STRONG ACCEPT
This session with Director Easterly and Jeff Moss offers a clear and unsentimental look at the imperative of trusted partnerships for national cybersecurity. It effectively articulates CISA's role as a collaborative partner, not an enforcer, a crucial distinction for fostering genuine engagement. The emphasis on human-centric trust and community involvement provides actionable strategic guidance for CISOs seeking to build more resilient programs through collective defense, translating high-level policy into practical, real-world implications for risk reduction and operational effectiveness.