Field Note Compliance describes the plan. Testing reveals the system.Since 2008 Lares has worked where digital, physical and human security meet.Field Note Compliance describes the plan. Testing reveals the system.Since 2008 Lares has worked where digital, physical and human security meet.

Person / Cybersecurity / Field-tested ideas

Eric Smith Built a Career by Asking Security to Prove It

For nearly three decades, the Lares co-founder has treated cybersecurity as a claim that must survive contact with reality. His work helped give penetration testers a shared playbook - and executives a more useful question than “Are we compliant?”

A locked door is a comforting object. It is solid, visible and wonderfully binary. Closed looks secure. Open looks careless. Eric Smith has spent much of his career studying everything that makes the binary misleading: the badge reader beside the door, the software behind the reader, the employee balancing coffee and a laptop, the contractor’s uniform, the assumptions people make when someone appears to belong.

For nearly three decades, Smith has worked across the awkward borders of information security. He has been an engineer, a consultant, a red-team operator, a founder, an executive, an investor and an adviser. Today he is co-founder and Group CEO of Lares, the security consultancy he started with Chris Nickerson in 2008. The job titles have changed. The stubborn question beneath them has not: what happens when a control meets a person who is paid to find its edge?

This is less cinematic than the word “hacker” suggests. Real testing begins with permission, scope and patient observation. It ends with cleanup, evidence and a report someone must be able to act upon. The moment in the middle may involve a clever exploit or a convincing disguise, but the purpose is not applause. It is to replace an organization’s assumption with a measured result.

2008Co-founded Lares with Chris Nickerson
PTESFounding contributor and co-author
3 decadesAcross technical, consulting and executive roles

A common language for an unruly craft

Before Lares, Smith founded Full Protocol and worked as a senior security consultant and analyst at companies in utility, technology and energy. Those environments offered a useful education in consequences. Security was not an isolated technical puzzle. It sat inside operations, budgets, inherited equipment, policies and human habits. A technically accurate finding could still be useless if nobody understood what it changed.

In 2009, Smith joined a group of practitioners who began shaping the Penetration Testing Execution Standard, usually shortened to PTES. The group included consultants, researchers and security leaders from several organizations. Their problem was surprisingly basic: penetration testing lacked a consistent shared vocabulary. Clients might buy work with one expectation while testers arrived with another. Reports could expose vulnerabilities without connecting them to business impact. The craft needed structure without losing the creativity that made it valuable.

PTES organized the work into a sequence that begins before anyone touches a target and continues after the technical action is over. Agree on the rules. Gather intelligence. Model the threats. Analyze weaknesses. Attempt exploitation. Understand what access makes possible. Report the evidence and the consequences. It is a practical arc, and its final verb matters. Security work earns its keep when a decision-maker can see what to do next.

A security control is a promise. The test asks whether the promise holds when conditions stop being polite.The operating idea behind Smith’s work

The badge, the building and the panda

Smith’s public talks show his taste for systems that appear ordinary. At DEF CON 16 in 2008, he spoke about medical identity theft. In 2013, he presented social-engineering material at DerbyCon. A year later, at DEF CON 22 and DerbyCon 4, he explored weaknesses in badge access-control systems in “Advanced Red Teaming: All Your Badges Are Belong To Us.”

Eric Smith onstage during a 2014 presentation about badge access-control vulnerabilities
Onstage in 2014, a badge reader becomes a plot device and a sad panda marks the point where confidence meets firmware.

The talk focused on how flaws in badge technology could lead to facility and system compromise. Live demonstrations made the argument tangible. The important object was not merely the card or reader. It was the chain around them: design decisions, physical routines, social trust and the systems reachable once a boundary failed. Cybersecurity, in this view, does not end at the keyboard. It follows authority wherever authority travels.

Smith’s conference biography from the period carried the kind of mischief common in security circles. It claimed he was born with invisible gills, sent him on retreats in search of unicorns and hidden treasure, and reported that friends and closer enemies called him the “phish whisperer.” The jokes reveal something useful. Adversarial work requires seriousness about consequences, but it benefits from play. A playful mind notices that an everyday object can behave differently from its label.

His interests away from work sound similarly kinetic. Public biographies mention fast modes of transportation, the outdoors, water and technology. Speed may be the hobby, but good red teaming depends on slowness: watching how a place moves, which routines repeat, what people ignore and where a system quietly trusts another system.

Compliance is the floor

Smith’s sharpest public comments concern the gap between validation and reality. In a 2019 discussion of security in complex facilities, he argued that compliance alone could not guarantee security. Connected systems carried identity and operational data, and checking only whether required controls existed left room for attackers. The larger point survives the particulars: documentation can confirm intent; it cannot simulate resistance.

“If these systems aren’t tested beyond the simple validation of compliance, it gives a profound opportunity to cybercriminals.”Eric Smith, 2019

Lares’s approach grew around that distinction. Penetration tests examine technical weaknesses. Red teams combine digital, physical and social routes. Defensive and advisory work helps clients turn the findings into stronger programs. The mix matters because actual organizations are untidy. New cloud services sit beside old equipment. A well-trained employee gets interrupted. A vendor receives temporary access that becomes permanent. The useful test follows the seams rather than honoring the boxes on an organization chart.

In 2020, Smith and Lares red-team manager Tim McGuffin presented patterns drawn from hundreds of the firm’s engagements during the previous year. Repetition converts the entertaining one-off exploit into management information. If the same weakness appears across different organizations, it points to a habit, an incentive or a blind spot. The remedy can then move beyond patching a single machine.

His more recent comments have returned to physical boundaries. Smith has described complex facilities as having “squishy perimeters,” places designed to admit many legitimate people quickly. The phrase is memorable because it refuses the neat rectangle of a network diagram. A real perimeter breathes. It expands for a delivery, softens for urgency and depends on dozens of tiny judgments by people who are trying to do their jobs.

From operator to translator

Smith’s career has gradually widened from conducting the work to creating the conditions for other people to conduct it well. At Lares he moved through partner, senior consultant, CTO and executive leadership roles. He has served as a red-team operator for the Collegiate Cyber Defense Competition and helped organize Security BSides events. In 2024, he joined the IANS faculty, advising security leaders on red teaming, penetration testing, physical assessments, social engineering and vulnerability management.

2008

Co-founds Lares and presents at DEF CON 16.

2009-2011

Helps develop and release the early PTES framework.

2013-2014

Teaches social engineering and badge-system testing on conference stages.

2024

Joins IANS as faculty for practitioner guidance.

2026

Appears in Lares material as Co-Founder and Group CEO.

That progression resembles the path of a good finding. It begins close to the machinery. It gains context. It reaches the people with authority to change the system. The translator’s role is easily underestimated in technical fields, where complexity can become a kind of status. Smith’s public work points in the other direction. A sophisticated test should make the next decision clearer.

There is a founder’s lesson here. Every company is held together by untested beliefs: customers will behave this way, staff will notice that signal, the backup will restore, the partner will call, the process will scale. Writing a policy around the belief may be necessary. It does not turn the belief into evidence. A carefully bounded test can.

The trick is to welcome the result without turning the exercise into blame. Red teams are useful because they produce a controlled encounter with bad news. When the engagement works, the organization receives the news early, from people contractually obliged to explain it and help clean up. That is a rather civilized arrangement with failure.

The proof, then the repair

Security marketing often sells certainty because certainty is easy to package. Smith’s career has been built around a more durable offer: informed choice. Lares’s own description of its purpose is to help clients understand where they stand and build a bridge toward stronger security. A bridge is an honest metaphor. It admits distance. It also implies movement rather than arrival.

The work continues because systems change, attackers adapt and people remain gloriously human. No test creates permanent safety. It can reveal which story an organization is telling itself, where the story departs from reality and what repair deserves attention first. Then the cycle begins again with better questions.

A locked door can still be comforting. Smith’s contribution is to make the comfort conditional. Check the reader. Study the routine. Test the assumptions. Write down what happened in language the business can use. Security becomes less of a declaration and more of a practice - observable, revisable and alive.