Key takeaways from the conversation
Engagement is a hacker superpower too.
Asked what his “hacker superpower” is, Tom didn’t point to a technical skill. He pointed to people. He described himself as a kind of digital evangelist, someone who takes what he learns from the community and pushes it back down to the people he’s trying to protect, whether that’s at a conference or in a classroom. For him, the goal has never changed: keep people, and the systems they rely on, safe.
The “Fed at DEF CON” stereotype doesn’t hold up.
Tom talked candidly about the assumptions people make about government cybersecurity professionals, and the assumptions he had going in himself. What he found inside his own workplace surprised him: hacker flags, personal touches at every desk, the equal curiosity and community ethos found anywhere else in the industry. His point was simple. Whether you’re red team, blue team, government, or private sector, the end goal is the same: make people and organizations more secure.
AI will help some people and hurt others, and the real risk isn’t the model.
On AI’s impact on cybersecurity, Tom’s view was measured rather than alarmist. He uses AI daily, mostly to get to source material faster than a traditional search would. But he was clear that AI shouldn’t be viewed as a replacement for people; it’s a tool to enhance what security professionals already do. His bigger concern wasn’t the technology itself, but the lack of guardrails around the companies building it, and the absence of any shared agreement on the ethics involved.
Cyber education needs to start a lot earlier.
One of the strongest points in the conversation was Tom’s case for pushing cybersecurity education down to elementary school. Kids are handed powerful, connected devices well before they understand concepts like privacy or data exposure. Tom compared it to driver’s education: society eventually recognized that handing someone a powerful piece of machinery without training was a real-world risk, beyond just an inconvenience, and built education around it. He argues cybersecurity needs the same shift, treating digital competence as a core life skill rather than an afterthought.
Employees are part of the security team, not just a risk to manage.
Tom pushed back on how the industry often treats employees purely as a liability. His argument: organizations rarely make clear that using company equipment securely, whether that’s a laptop, an email account, or a delivery van, is part of the job itself. When an employee repeatedly falls for phishing, there are rarely real consequences, even when a breach can cost hundreds of millions. He argued security teams need to bring employees into the conversation, not just dictate policy.
Convenience is quietly winning the fight against security.
Tom was refreshingly honest about where the industry gets it wrong. Security teams often lock things down without considering how people actually need to work, then wonder why employees look for workarounds. He believes security and convenience don’t have to be at odds, but getting the balance right needs collaboration instead of top-down mandates. He described his own habits around personal tech he uses despite knowing the tradeoffs.
The community is what keeps people in this career for the long haul.
Tom’s own path into the DEF CON community started later than most, at DEF CON 30. Since then he’s started his own DEF CON group at work, describing it as a way to give federal employees and government workers from any country a place to connect with people who share their curiosity, even when their day jobs don’t allow them to talk openly about what they do. As he put it, that kind of space helps close a gap that can otherwise result in isolation. Peering ahead to retirement, his focus is already shifting from what he’s taken from the community to what he wants to keep giving back.
Watch the full conversation.
The full 30-minute conversation is available now on the CovertSwarm YouTube channel, as part of our
Swarm Spotlight playlist.
Thomas Cox is participating in a personal capacity. The views expressed are his own and do not represent the views of, or constitute an endorsement by, the U.S. Government or any Federal agency.