I'm a cyber policy researcher and convener working on community cyber defense and offensive cyber policy.
I study how AI is shifting the offense–defense balance in cyberspace, how offensive operations and the tools market should be governed, and how the public interest institutions least able to defend themselves might be defended anyway.
I'm a Senior Fellow of Public Interest Cybersecurity at UC Berkeley's Center for Long-Term Cybersecurity (CLTC), where I work on how community organizations and states defend themselves from cyberattacks. My recent research maps volunteer and whole-of-state cyber defense programs across the country, models both their workforce development and financial return on investments, and asks what it would take to scale them. I lead CLTC's work with the Cyber Resilience Corps, and I've advised on the design of a national platform for cyber volunteering.
Currently, my research focus identifies previously untested and unmapped pathways for existing cyber volunteer programs to serve as surge capacity during a national cyber crisis. Deploying these programs requires navigating a complex web of state, local, and federal authorities that determine who can mobilize volunteers and what work they are permitted to do. Beyond legal authority, these programs need operational frameworks that allow them to scale quickly, procedures and best practices that guide their actions once activated, and a playbook for how they will communicate, coordinate, and delegate with one another when a crisis occurs.
The organizations at the center of my research – hospitals, school districts, municipalities, small electric and water utilities, and nonprofits – face the same threat actors as the Fortune 500 with none of the budget. Most of my fieldwork is with the people and policymakers trying to close that gap.
I'm the founding Head of Policy at DistrictCon, a hacker conference in Washington, D.C., where I've been part of the all-volunteer organizing team since it was created in 2024. I run the policy track and convene closed-door roundtables bringing senior government officials together with practitioners and industry policy decision makers. Recent sessions have covered the future of AI security policy, cyber campaigning below the threshold of armed conflict, accountability in the commercial offensive cyber tools market, and the role of non-state actors in cyber conflict. I'm also a member of the DistrictCon Call For Papers (CFP) Review Board.
My offensive interests are in AI security policy, cyber harms, evolving cyber statecraft theories, whether continuous engagement holds up as a strategic logic when the cost of operating falls, how states decide in a crisis without confident attribution, and what accountability could look like for an industry that sells intrusion capability.
I was a tech policy associate at a San Francisco tech policy consulting firm and at the Atlantic Council's Cyber Statecraft Initiative, where I worked on global cyber capacity building initiatives. I earned my degree in Philosophy (morality, politics, and law) from Arizona State University.
I've moderated 30+ roundtables and panels and presented my research at leading security conferences, industry forums, and policy gatherings, including DEF CON Policy, the National Conference of State Legislatures (NCSL), the National Governors Association (NGA), BSides Las Vegas, BSides Seattle, and the Center for Cyber Safety and Education.
LinkedInThis is a personal website. The views expressed here are my own and do not represent the views of my employer or any other organization.