Taylor Banks
Since 1997 I've watched real security work go unproven and real talent go unseen. If you're a security leader, that's an incident response plan nobody has ever practiced. If you're good at your job, it's months of applications and no callbacks.
Who I am
I've worked through pentesting, technical training, DFIR, sales engineering, sales leadership, ransomware negotiation, and executive advisory, roughly in that order.
I founded DC404 in 2003 and it grew into one of the longest-running grassroots hacker meetups in the world. It still meets. In 2005 I built Anonym.OS with my crew at kaos.theory, which put anonymous browsing one reboot away. It did 190,000 downloads in thirty-six hours and held the front page of Wired for twelve weeks.
I helped run DEF CON's ~200-person safety operations team since 2014, and retired as Ops Chief after DEF CON 33.
I've negotiated with ransomware threat actors on behalf of Fortune 500 giants, critical-infrastructure providers, single-office law firms, and one-person IT teams that never expected to be on a target list. It taught me that even the most technical crisis you can imagine is a people problem.
I'm also a volunteer firefighter, EMT, and search and rescue responder in southwest Colorado. That turns out to be relevant more often than you'd think.
What I'm working on
Ransomware Resilience Advisory
Ninety-nine percent of organizations have a formal incident response plan. Seventy-three percent of security leaders still say they would not be ready to execute under pressure if it happened tomorrow, and ninety percent expect coordination to break down when it does.1
What sits between those numbers is the first few hours, when security, legal and communications have to decide together, on one clock, on incomplete information. That runs on trust the team either built beforehand or didn't, and no document supplies it.
I've worked that hour from both sides. I've sat on ransomware calls where the technical answer was known within the hour and the decision still took two days. I also run emergency calls as a volunteer firefighter and EMT, where the same failure looks like four agencies on scene and nobody saying who has command.
Security Career Advisory
A friend of mine sent six hundred applications last year, made six final rounds, and walked away with nothing. He's good at his job. Across fifty-four million applications, about thirty-five percent of candidates get past a first screen. Referred candidates get past it fifty-two percent of the time, and a referral from someone in the same job function converts better than one from outside it.2
The first screen is where good people disappear, and applying harder is the worst available answer to it. Six hundred applications is six hundred attempts at the one stage least equipped to see him. Most of my work here is making real experience easy to see from the outside, and getting it in front of the people who can vouch for it.
Speaking
I keynoted Driving IT 2025 in Copenhagen for IDA, the Danish Society of Engineers, on why the security-versus-privacy tradeoff is a false frame. Booking 2027 now. Talks and topics →
1 Sygnia 2026 CISO Survey, 600+ senior security decision makers, April 2026.
2 Ashby 2026 Talent Trends Report, 54M applications and 93K jobs, January 2021 to March 2026.
Reach me
I read everything and I reply.