# Eric Smith

> Eric M. Smith is the co-founder and Group CEO of Lares, a cybersecurity consulting firm built around adversarial testing. Across nearly three decades in information security, he has worked as an engineer, consultant, operator and executive; founded Full Protocol; helped write the Penetration Testing Execution Standard; taught at security conferences; operated on Collegiate Cyber Defense Competition red teams; and joined the IANS faculty. His recurring idea is practical: compliance can establish a baseline, but only realistic testing reveals whether controls work when someone actively tries to get around them.

- **Role:** Co-Founder and Group CEO at Lares
- **Organizations:** Lares, Full Protocol, IANS Research, Penetration Testing Execution Standard, Security BSides, Collegiate Cyber Defense Competition
- **Education:** Bachelor of Science in Information Security Systems
- **Known for:** Co-founded Lares in 2008., Co-authored the Penetration Testing Execution Standard with a practitioner group that began the work in 2009., Founded Full Protocol before Lares.

## Career timeline

- **Before 2008** — Founded Full Protocol and worked as a senior security consultant and analyst for utility, technology and energy companies.
- **2008** — Co-founded Lares with Chris Nickerson; presented on medical identity theft at DEF CON 16.
- **2009** — Joined the practitioner group that began developing the Penetration Testing Execution Standard.
- **2011** — Named among the contributors when the PTES alpha was released.
- **2013** — Presented social-engineering material at DerbyCon 3.0.
- **2014** — Presented “Advanced Red Teaming: All Your Badges Are Belong To Us” at DEF CON 22 and DerbyCon 4.
- **2019** — Publicly argued that compliance alone cannot guarantee security and that connected systems require testing beyond validation.
- **2020** — Presented Lares findings from hundreds of 2019 penetration-test engagements in a webinar with Tim McGuffin.
- **2024** — Joined the IANS faculty, advising clients on red teaming, penetration testing, physical assessments, social engineering and vulnerability management.
- **2025** — Commented publicly on physical-security testing and the porous boundaries of complex facilities.
- **2026** — Identified as Lares Co-Founder and Group CEO in the company’s adversarial-integration methodology guide.

## Achievements

- Co-founded Lares in 2008.
- Co-authored the Penetration Testing Execution Standard with a practitioner group that began the work in 2009.
- Founded Full Protocol before Lares.
- Presented and taught at DEF CON, Security BSides, DerbyCon, HackCon, Infosec World, ShakaCon, DakotaCon and other conferences.
- Served as a red-team operator for the Collegiate Cyber Defense Competition.
- Co-founded and organized multiple Security BSides conferences.
- Joined the IANS faculty in 2024.
- Maintains CISSP and CISA certifications according to Lares and IANS biographies.

## Latest updates

- **2026-03** — A Lares methodology guide identified Smith as Co-Founder and Group CEO.
- **2025-08** — Lares published Smith’s comments on physical-security failures and the limits of documentation without practical testing.
- **2024-11** — IANS listed Smith as a faculty member focused on red teaming, penetration testing, physical assessments, social engineering, and vulnerability management.

## Links

- Website: https://www.lares.com/
- LinkedIn: https://www.linkedin.com/in/infosecconsulting/
- Twitter/X: https://x.com/infosecmafia
- YouTube: https://www.youtube.com/watch?v=EEGxifOAk48

---

Profile page: https://yespress.io/eric-smith
Published by YesPress — https://yespress.io
Last updated: 2026-08-26
