Jen Ellis, a renowned cybersecurity advocate, has been making waves in the industry for over a decade. Her remarkable career is marked by a defining moment that not only shaped her professional path but also earned her recognition from the British government. Ellis was recently awarded the Member of the Order of the British Empire (MBE) honors for her contributions to cybersecurity policy.
The spark that ignited Ellis’ advocacy work came when her close friend, HD Moore, faced legal threats from the US Department of Justice (DoJ) in 2013. Moore, a security researcher and creator of Metasploit, was involved in legitimate research through Critical.io, an initiative that would later become Rapid7’s Project Sonar. The DoJ’s actions against him sparked Ellis’ outrage, as she realized that the legal frameworks were often at odds with good-faith security research.
Ellis’ indignation led her to dig deeper into the Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA), and other laws. She was dismayed by the prosecution of researchers who were trying to expose vulnerabilities and help companies improve their cybersecurity posture. This discovery galvanized her to take action, and she approached Rapid7’s then-CEO, Corey Thomas, with an audacious request: “I want to change the law.”
Thomas’ response was both unexpected and encouraging. He asked Ellis if changing the law was the right thing to do, rather than questioning its feasibility. This conversation marked a turning point for Ellis, who began to devote herself full-time to policy work.
Ellis’ efforts ultimately led her to testify before Congress and form an unlikely partnership with the DoJ. Her tireless advocacy helped shape the US government’s approach to security research, ensuring that researchers are protected from prosecution when conducting legitimate work.
Ellis’ MBE honor is a testament to her dedication and impact on the cybersecurity community. While she downplays her own influence, her work has undoubtedly made a significant difference in the industry. Ellis continues to be an outspoken advocate for security researchers, using humor and wit to cut through the complexities of policy discussions.
So what can we learn from Jen Ellis’ remarkable story? For one, it’s clear that even the smallest spark of outrage or passion can ignite a career-defining mission. It also highlights the importance of advocating for change within the industry. As security professionals, we must be willing to speak up and challenge existing frameworks when they hinder our ability to do good-faith research.
In today’s fast-paced cybersecurity landscape, it’s essential to recognize the value of advocacy work. Ellis’ story serves as a reminder that even those without policy or legal expertise can make a significant impact by dedicating themselves to this cause. As we strive for a more secure online environment, let’s draw inspiration from Ellis’ unwavering commitment to protecting security researchers and promoting positive change within our industry.
Source: Dark Reading — 2026-07-10