
Long-form profiles of red teamers, CISOs, threat hunters, and incident responders. No vendor content. No recycled compliance lists.
I found the vulnerability on a Tuesday night. By Thursday, the patch was live and I'd paid off my student loans.
Jordan Mercer doesn't have a degree. What he has is a 32-page report that brought a Fortune 100 company's authentication system to its knees, a HackerOne leaderboard position in the top twelve globally, and a bank account that most senior engineers would envy. We met over video call — he was eating cereal at 11pm, unbothered.
The conversation that followed lasted four hours. He talked about his methodology the way a chess grandmaster talks about opening theory: not as steps to follow but as a language to think in. 'Most people look for what's broken,' he said. 'I look for what was never meant to be tested.'
You develop a sixth sense. Not for code — for the pattern of behavior before the code ever runs.
Renata spent eleven years inside Fort Meade before she left to build a threat intelligence consultancy that now advises three central banks and a sovereign wealth fund. She speaks in careful sentences, the kind shaped by years of briefing rooms where imprecision has consequences. Her hands move when she talks about attribution.
'The hardest thing to teach is restraint,' she told me. 'Every analyst wants to name the actor immediately. But naming too early is how you get the response wrong.' She paused and looked past the camera for a moment. 'We got it wrong twice. Both times we were too fast.'
The breach doesn't announce itself. It waits to be noticed — sometimes for months. Sometimes for years.
The surgeon asked me if he should stop. I told him to keep going. I had forty-seven minutes to contain it.
On the morning of March 14th, 2023, Lakefront Regional Medical Center's imaging systems began returning corrupted outputs. In Operating Room 3, a cardiac surgeon named Dr. Priya Nair was twelve minutes into a procedure. Kwame Asante, standing in the SOC two floors below, made the call that would define his career.
'People ask me if I was scared,' he said, sitting across from me in a conference room that still had the smell of a room used for difficult conversations. 'I wasn't scared. I was very, very focused. There's a difference.' He stopped the ransomware propagation in forty-seven minutes. The patient was discharged four days later. Kwame filed his incident report at 3am.
From nineteen-year-old bug hunters to three-star-general-level CISOs. Cipher profiles the full spectrum of practitioners who keep the internet from collapsing.











Each issue is a single long-form profile. No roundups, no sponsored sections, no five-point frameworks. Just one person, one story, told properly.
4,800 security practitioners already read Cipher. The next issue drops this Sunday.