Link copied
From ethical hacking to ecosystem riskCo-founder and CTO of Black KiteThe supplier became the route to the target

People / Cybersecurity / Field Notes

Candan Bolukbas Found the Back Door Was Someone Else’s Front Door

An ethical hacker kept finding the same weakness outside the fortress. He turned that recurring clue into Black Kite - and a career spent making invisible supplier risk legible.

The useful thing about a fortress is that it tells an intruder where not to waste time. Candan Bolukbas learned this from the inside, while working as an ethical hacker against government and military systems. The central institution might be guarded with expensive care. Its contractors, however, lived in a less orderly neighborhood. Again and again, the softer route toward a hardened target began with a third party. It was not merely a security flaw. It was a flaw in the way organizations pictured themselves.

That recurring clue became the founding idea of NormShield in 2016, later renamed Black Kite. Bolukbas and his team built a platform to identify, assess and continuously monitor cyber risk among vendors and suppliers. The company’s subject is technical, but its premise is almost social: no organization is only itself. It is also the software it buys, the partners it trusts, the services it connects and the contractors whose names may be missing from the grand architecture diagram.

“In the cyber world, there’s no such thing as a ceasefire.”Candan Bolukbas, 2025

The neighborhood around the castle

Bolukbas arrived at that systems view by moving through systems. He studied computer engineering at Middle East Technical University, then earned a master’s degree there in information systems. His early career included software development and a small firm he co-founded, AK Yazilim. He went on to administer networks and security for the Presidency of the Republic of Türkiye, and later managed enterprise security services at BGA Information Security & Consulting. His public record has the enjoyable untidiness of someone who has actually built things: .NET and Python, network design, incident handling, forensics, penetration tests, mobile applications and cybersecurity courses.

One early project, iEndura, handled video from IP cameras across web and mobile devices. Another, SmartPlan, was a university project for organizing course design. Neither sounds much like a modern cyber-risk platform, but both suggest the same appetite for complicated systems with many moving parts. Cameras, networks, curricula, vendors: Bolukbas seems happiest when a messy field can be turned into a map.

His secure-programming repository is a particularly good fossil from this period. It collects familiar application failures - SQL injection, cross-site scripting, broken authentication, insecure object references, request forgery, directory traversal - then places vulnerable implementations beside safer ones. The arrangement matters. It does not stop at “danger.” It shows the mechanism and the repair. Years later, that same instinct appears in Black Kite’s argument against opaque security ratings. A grade without its workings is a verdict; evidence with context is something an engineer can use.

Interview graphic featuring Candan Bolukbas, co-founder and CTO of Black Kite
The engineer as translator: Bolukbas discussed continuous monitoring, financial risk and AI-assisted investigations in a 2026 interview. Photo graphic: HiTechNectar.

A score should show its homework

Third-party risk was long managed with periodic questionnaires. The ritual has a bureaucratic charm: send a form, collect an answer, file the answer, repeat next year. Unfortunately, attackers have declined to organize themselves around the stationery. Credentials leak between assessments. A certificate expires. A vulnerability acquires working exploit code. A software product used by hundreds of companies becomes a common point of failure.

Bolukbas’s alternative is continuous intelligence. External signals can prompt a deeper review when something meaningful changes, rather than forcing every supplier through the same calendar. At Black Kite, that approach brings together technical findings, threat intelligence, standards mapping, ransomware indicators and financial-risk modeling. The ambition is not to replace judgment with a dashboard. It is to give judgment better timing.

The company itself had to cross a translation gap. It began as NormShield, a name that sounded like a useful security appliance and behaved rather less elegantly in conversation. The Black Kite identity arrived as the business widened its reach. In 2021, it announced a $22 million Series B round backed by Volition Capital, Data Point Capital, Glasswing Ventures and Moore Strategic Ventures. Capital is never character, but it changed the scale of the assignment. A founder’s observation from penetration tests now had to support customer teams watching broad, shifting populations of suppliers.

Scale sharpened the original problem. A human analyst can study one vendor with care. An enterprise may depend on thousands, while each of those vendors depends on others. The chain quickly becomes less like a chain than a bowl of noodles. Black Kite’s answer has been to automate collection and correlation while preserving a route back to the evidence. Bolukbas talks about accuracy, transparency, speed and collaboration as linked requirements. Speed without context produces noise. Transparency without scale produces a handsome report that arrives after the incident. Collaboration matters because the rated vendor needs enough access to understand and address a finding, not merely receive a mysterious bad mark.

40M+Company profiles described across the platform
300+Control items evaluated for vendor risk
3×Data-validation passes in the stated process

There is a second translation problem. A security team may understand exposed services or leaked credentials, while a board understands interrupted operations and money. Black Kite maps findings to familiar frameworks such as MITRE and NIST, then uses OpenFAIR modeling to express probable financial loss. This is not a claim that the future can be priced to the penny. It is an effort to let the people who find the danger and the people who fund the response inhabit the same sentence.

The work also produced a patent. Bolukbas is named with Paul Paget and Ferhat Dikbiyik as an inventor of a system for computing ransomware susceptibility, issued by the US Patent and Trademark Office in 2022. The idea fits the larger project: combine observable signals into a measure that helps an organization decide where attention is due. A risk score is useful when it begins a conversation, not when it ends one.

The hacker becomes a host

Black Kite’s growth changed Bolukbas’s role. The person who once searched for the overlooked route now oversees a company’s technical direction and product innovation. He co-leads BK Labs with chief research and intelligence officer Ferhat Dikbiyik. The group mixes threat researchers, data scientists, analysts and engineers, and ranges across ransomware, vulnerabilities, artificial intelligence and supply-chain risk.

That partnership is visible in the technical record as well as the organization chart. Dikbiyik and Bolukbas are co-inventors on the ransomware-susceptibility patent, alongside Black Kite chief executive Paul Paget. It is a small but telling counterpoint to the mythology of the solitary hacker. Modern threat intelligence is ensemble work: one discipline finds the signal, another tests its meaning, another turns it into a reliable product, and a customer finally decides whether to act. The useful hero is usually a well-designed handoff.

The title “CTO” can suggest a safe altitude above the machinery. Bolukbas’s published work keeps descending back into it. He has written about security by design, ransomware susceptibility, data quality, AI in security and the questions required to build an effective security team. He has also taught packet analysis with Wireshark and Tshark, presented on critical-infrastructure protection, and spoken about security operations and incident-response teams. The range is less a credential parade than a refusal to treat technology, people and process as separable species.

Co-founds AK Yazilim during the software-building chapter of his career.

Works in network, security and management roles for Türkiye’s presidency.

Co-founds NormShield, which later takes the Black Kite name.

A ransomware-susceptibility patent naming him as a co-inventor is issued.

Leads product innovation as CTO and co-leads the research work of BK Labs.

His older public work also carries a political current. Bolukbas has described himself as a supporter of privacy, freedom and human rights. In 2014, after Twitter and YouTube were blocked in Turkey and common DNS workarounds were disrupted, he published a technical approach intended for organizations rather than individual users. It is a revealing detail: the problem was both civic and infrastructural, and his answer was to make a system.

Automation, with an address for responsibility

Now the system is learning to investigate. Bolukbas describes artificial intelligence as part of Black Kite’s architecture rather than an ornament attached during the current enthusiasm. Its uses include scanning large volumes of threat data, helping populate assessment frameworks, investigating changes in vendor risk and assembling reports for executives. In his view, the next step is an AI agent that can behave more like an operator: request documentation, validate controls and help coordinate remediation.

It is an audacious prospect in a field where confident automation can turn a small mistake into a large meeting. Bolukbas’s own prescription contains the necessary restraint. AI has to be integrated with the right data and workflows, secured with token-based access, and tuned for a defined use case. The glamour lies with the agent; the hard work remains identity, evidence, permissions and good plumbing. Cybersecurity has always enjoyed dramatic villains. It survives through competent plumbing.

The arc from his early code samples to autonomous investigations is long, but it is not crooked. First expose the flaw. Then explain it. Then connect it to a decision. The scale has expanded from one insecure function to millions of company profiles, yet the editorial demand on the technology remains the same: show your work.

Bolukbas’s enduring subject is therefore not simply third-party risk. It is legibility. The supplier hidden behind the target must become visible. The score must reveal its evidence. The technical finding must acquire business meaning. The automated agent must have an identity and a permitted route. Every black box needs, if not a window, at least a properly labeled door.

A fortress can continue buying taller walls. The more interesting defense begins when someone redraws the map around it.