Jen Ellis, a stalwart advocate for security researchers, has made waves in the cybersecurity community with her tireless efforts to reform laws that stifle legitimate research. Her dedication and unyielding spirit have earned her numerous accolades, including a recent honor from the British Crown.
Ellis’s journey as a champion of cybersecurity policy began over a decade ago when her close friend HD Moore faced legal threats from the US Department of Justice (DoJ) for conducting security research through Critical.io. This incident sparked Ellis’s outrage and motivated her to dig into the Computer Fraud and Abuse Act (CFAA), Digital Millennium Copyright Act (DMCA), and other laws that seemed to hinder good-faith research.
“I was incensed,” Ellis says, recalling the moment she realized the scope of the problem. “Legitimate researchers were being threatened by companies, and I knew something had to be done.” This sentiment led her to approach Rapid7’s then-CEO Corey Thomas with a bold proposal: change the law. To her surprise, he encouraged her to pursue this mission, despite her lack of experience in policy work.
Ellis’s determination soon turned into a full-fledged advocacy campaign that would take her to Capitol Hill and forge an unlikely partnership with the DoJ. She testified before Congress, pushing for reforms that would safeguard security researchers from prosecution and promote responsible disclosure practices. Her efforts culminated in significant changes to the way the US government treats legitimate research.
Ellis’s impact extends beyond policy changes; she has also helped raise awareness about the importance of security research and its role in protecting individuals and businesses from cyber threats. Her dedication to this cause is evident in her willingness to engage with both policymakers and the broader cybersecurity community, often using humor to break down complex issues.
This summer, Ellis’s contributions were recognized by the British Crown when she was awarded a Member of the Order of the British Empire (MBE) for her work in shaping cybersecurity policy. Her response to this honor? A lighthearted joke about Americans being required to curtsy whenever they see her.
Ellis’s story serves as a testament to the power of passion and perseverance in driving change. As she continues to advocate for security researchers, her legacy as a champion of cybersecurity policy will undoubtedly endure.
So what can we learn from Ellis’s experience? It highlights the importance of engaging with policymakers and advocating for changes that promote responsible disclosure practices and protect legitimate research. For individuals working in the field, it demonstrates the impact one person can have when driven by a clear sense of purpose and conviction. As you navigate your own cybersecurity career, remember that even small actions can contribute to larger movements and drive meaningful change.
Source: Dark Reading — 2026-07-10