/https://img.transistorcdn.com/PIJ_q8YldTCT31T7jHnxHRqUzGjdO0-hoEOcvxXsKvc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82Yjc5/YWM4ZTdmYmY0ZjFk/MjVmZDRkOTU4ZTZk/MzYwMC5wbmc.jpg)
Hackers to Founders
Chris Magistrado
Winning DEF CON CTF, Failing at Consulting, and Building an All-Senior Hacker Firm — Erik Cabetas (Include Security)
SEP 3, 2026124 MIN
/https://img.transistorcdn.com/gNH0zm8jmbppdlWBg3GX35MAg47_p9PDV0Xi0QGT2rQ/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YTU5/ZThkN2NmZWYxNmQx/NmNmZGNhNTY4ZGYz/Njg2OC5wbmc.jpg)
Description
Erik Cabetas won DEF CON CTF his first year, failed at running a consulting shop, then came back five years later and built Include Security into an all-senior application security firm serving billion-dollar software companies.
Erik Cabetas is the founder and "head hacker herder" of Include Security, an application security firm he's run for nearly 15 years.
His path there was anything but linear. He was a materials engineering major who dropped an entire semester two months before graduation to switch to computer science. He learned to hack from zines and FTP servers before Google existed, after a college roommate put Back Orifice on his machine in 1998. He got his first security job by cold-emailing, at 4am, a guy he'd seen on a documentary that aired at 3am. He won DEFCON CTF in 2003 on a team that was in dead last when he asked to join — and his contribution wasn't the two exploits he wrote, it was reorganizing who on the team did what.
Then he tried to start a company, and it didn't work. He went solo for five quarters, took four clients, hit his revenue target almost exactly to the dollar — and quit anyway, because he'd worked himself into the ground to get there and couldn't see it getting easier.
Five years later he tried again. Include Security launched in January 2011 with three clients already signed.
This is a full start-to-finish conversation. Erik walks through the Ernst & Young Advanced Security Center team that spawned Bishop Fox, Gotham Digital Science, and his own company. Burning out on the road at Fortify Software. Running security, fraud, and trust & safety at The Ladders through the 2008 crash — including being handed the layoffs after HR was laid off. And what it actually took to build a firm that deliberately has no junior hackers on it, in an industry where nearly everyone runs a 70%-junior pyramid.
He's unusually candid about the parts founders normally skip: what his rent was, what number he set for himself, why sales and legal were harder than any technical work he'd ever done, why refusing to use his own network was a mistake, why it took him five years to find one salesperson he trusted, and why the real driver of pen testing demand is B2B contract language rather than compliance.
Some of what we get into:
Learning security in 1998, and why Erik thinks it's harder now, not easier
The Honeynet Project forensics challenges, and writing for 2600 at 20
Getting hired at E&Y off a cold email, and being 22 telling a Fortune 500 you have root
Why he left a job the moment they promoted him
Include Security "version zero" — the attempt that failed, and exactly why
Reading an entire commercial product's source code in a week to survive a customer site
Cutting seven-figure credit card fraud by 98% with a few hundred lines of T-SQL
The bad RFP responses that convinced him the industry could be done better
The all-senior model vs. the pyramid model, and what clients actually notice
54 programming languages, and what they found in the largest production Rust app they've assessed
How paid research time works, and the blog posts that turned into DEF CON talks
Concrete advice for starting a consulting firm today — including why he lets future competitors subcontract off his company
Drum & bass, the Spawn soundtrack, and searching Napster by random nouns
Links
Include Security: https://includesecurity.com
Include Security research blog: https://blog.includesecurity.com
Books Erik recommends
Security Engineering — Ross Anderson
The Ghidra Book — Chris Eagle & Kara Nance
Never Split the Difference — Chris Voss
The Trusted Advisor — David Maister

