Lesley Carhart isn’t just a pioneer in cybersecurity — she’s a storyteller, mentor, and relentless advocate for the people behind the tech.
From a childhood spent on a farm outside Chicago, where a single early PC opened the door to programming at age eight, to two decades of service in the U.S. Air Force Reserves, Carhart has built a career defined by persistence, curiosity, and a refusal to give up when doors were closed to her.
She’s now globally recognised for her work in OT and ICS cybersecurity, a SANS instructor, a DEF CON “Hacker of the Year,” and a mentor to countless up-and-coming security professionals.
But what makes Carhart stand out isn’t just her technical skill — it’s her empathy, her love of teaching, and her passion for helping others navigate an industry that doesn’t always make it easy to belong.
In this Close-Up, we talk about how a dot-com crash redirected her life into the Air Force, what aviation taught her about process and safety, why she worries the next generation is losing critical knowledge in the age of AI, and why community recognition matters more to her than any technical accolade.
Where did you grow up, and what did you want to do when you were young?
I grew up in Chicago. I grew up on a farm, and we didn’t have a lot of money. When I was about seven or eight, my dad bought an early PC to handle farm inventory. This was in the ’80s, and we didn’t have television or much else, we couldn’t afford it. My choices were to learn farming or to learn how to use the computer. Long story short, I’m not a farmer today, though I have the utmost respect for farmers.
I started programming when I was around eight, and by 15 I had my first job as a programmer, which I thought was amazing. But then the dot-com bubble burst, and I had no choice but to enlist in the Air Force.
What was your role in the Air Force?
I got to fix aircraft computers and avionics systems, which became my first degree. But my real passion was always computers. I knew early on, even back in the ’90s, that I wanted to go into computer forensics. I was reading magazines and white papers about it when the field was still very new.
You spent 20 years in the Air Force Reserves — what’s the biggest lesson from that experience that you still carry into your work in cybersecurity today?
The military taught me a few key incident response skills. The first was managing high-pressure, crisis situations and making rapid decisions based on risk evaluation. The second was adaptability, being able to travel anywhere, often to very remote or isolated places, to handle on-site incident response. Finally, I learned to think about the real-life physical, human, and ethical impact of my decisions, and the decisions I advise on every day, instead of just approaching cybersecurity from a purely academic perspective.
You knew early on you wanted to do computer forensics. How did you finally break into the field?
I called every computer forensics professional I could find in the Midwest, asking if I could at least talk to them on the phone about how to break into the field. Nobody ever returned my calls.
Eventually, I landed a job as a security analyst. I met the right people and worked my way in from network engineering. I’ve been doing this ever since—almost 20 years now. My background in telecommunications, network engineering, and avionics gave me experience with electronics and complex systems, which set me apart from the traditional “computer hacking” path. That’s how I ended up in operational technology and ICS so early, because I came from a non-traditional background rooted in electronics rather than just cybersecurity degrees.
What did you learn in the military that you carried forward?
The military gave me process knowledge. You have to be good at crisis management—responding under pressure to very difficult situations—and you also need to understand how things actually work.
Working on aircraft taught me that if you drop a single screw, the plane won’t fly. One missing tool, one misconfigured part; any of those things can compromise safety. That’s why aviation is so safe: it’s highly regulated, structured, and safety-driven.
That experience made me want to understand how everything around me works: how systems are built, how they fail, and how failures are prevented. In industrial systems, it’s not just about hacking into a train’s computer. The real question is: what prevents the train from doing something dangerous if that computer fails? Because computers do fail.
All industrial processes are designed with safety in mind, shaped by disasters like Bhopal and others. Over time, technology has become safer and more resilient because devices fail and humans make mistakes. If you want to break those systems as a bad actor, you need to understand all the safety controls, redundancies, and human monitoring built into them.
What are some of your first and most memorable jobs?
The first time I was sent to a remote OT site in my early 20s, it was an isolated mine in the Arctic Circle in the dead of winter. I was totally unprepared for what I was walking into, no communication, no daylight. I ended up hitchhiking to the facility, but I made it work.
You’ve talked about how it took persistence — knocking on a lot of doors — to break into cyber. What helped you stand out?
I don’t think I’m the smartest or the most technically talented. What I do have is persistence and critical thinking. I’m willing to learn anything, I stay open to new ideas, and I’m committed to lifelong learning. I also have empathy and get along with people well. Being a well-rounded, pragmatic person takes you a long way in cybersecurity.
What are some milestones you are proud of?
I’m an instructor with the SANS Institute, and I’ve been teaching this subject to audiences all over the world. I love speaking and teaching. I also spend a day each week mentoring university students. For me, it’s about building the next generation.
But what worries me is that many students today aren’t learning foundational skills. They’re not soldering, they’re not working with industrial technologies or legacy systems like COBOL. Those aren’t seen as “cool.” They’re not AI. But that knowledge is vital.
You’ve spoken about the risk of younger generations relying too heavily on tools and AI without learning the basics. Are you worried we’re losing critical knowledge?
I struggle sometimes with how to convey this without sounding like the “old person” in the room. But there really is a problem. Since I started in this field, universities everywhere have launched cybersecurity degrees, and many of them are fundamentally flawed because they don’t teach the foundations of computing.
We now have a generation that hasn’t been exposed to the inner workings of computers. Everything is point-and-click, tablets, and touchscreens, so they don’t learn at home how computers actually work. Then they enroll in cybersecurity programs, but those programs also don’t teach fundamentals. Instead, they teach how to use tools—EDR, Metasploit, whatever’s current. And tools change constantly. In cybersecurity, tools and techniques are outdated within a few years. Without foundations, students can’t adapt, and they can’t work with legacy systems. That’s a big problem.
If someone comes from computer engineering or network engineering, they at least understand how systems work at a very basic level. But so many young people today who want to be cybersecurity professionals aren’t getting those foundations. And it’s not their fault; these degree programs have enormous marketing budgets promising high salaries.
I do my best with mentoring, but I can’t compete with that. The good news is I’m not the only one saying it anymore. More people in the industry, especially those hiring, are starting to admit: “Please, tell your young people to get computer science or engineering degrees before cybersecurity.”
You were named DEF CON’s Hacker of the Year — what did that recognition mean to you?
I was very surprised, that was in 2020, when DEF CON went remote. With the pandemic, all conferences were canceled globally. The week after Chicago and much of the world went into lockdown, I thought, “Everyone’s freaking out—why not run a conference online?”
So in about two weeks, with no budget and no planning, a few friends and I pulled together a virtual conference. We streamed it over YouTube and Twitch, and it ended up drawing around 6,000 attendees. Even more surprising, about 200 people applied to speak. It was wild. For nearly six months, it was the only conference running, and people really embraced it. That effort eventually led to DEF CON running virtually too.
You’ve mentored so many in cyber. What advice do you give newcomers?
If every role sounds interesting and you can’t choose, ask people about the downsides of their jobs. Find out what a bad day looks like. Eliminate roles based on that, instead of just chasing the “cool” stuff.
Also, have a life outside tech. Work-life balance is essential. Learn the signs of burnout in yourself and others. Cybersecurity is high-burnout, so mental health is critical.
And broaden your horizons. The most saturated junior roles are SOC Analyst and Penetration Testing, but there are many other niches with openings. Don’t just believe what universities or bootcamps tell you about roles and compensation, find a mentor and explore the full spectrum.
What keeps you passionate about this field?
Teaching and mentoring. I love helping people understand not just “how to hack something” but how the world works, how systems fail, and how to prevent catastrophic failures. That’s what drives me.
How did your journey lead you to Dragos, and what’s your vision for the future?
I took the job eight years ago because of the Dragos mission. I care deeply about my work being ethical and bettering society. I might be able to make more money or gain fame moving between tech giants in the U.S., but I love what I’m doing here – practical defense of critical infrastructure in Australia, New Zealand, Singapore, and beyond.
Critical infrastructure defense can be a scary space, but I feel good about my work every morning. I also get to collaborate with some of the brightest minds in OT cybersecurity, constantly learning about how the world functions behind the scenes.
What’s a fun fact or something people don’t know about you?
I’m a fourth-degree black belt in two martial arts, and I happily continue to teach youth in Australia.
If you could hack any system in history—fictional or real—just for fun, what would you pick?
Oh, I’d want a spaceship. Maybe a TARDIS. Watch out, Doctor.
Finally, what’s the biggest misconception about securing OT and industrial systems today?
That it’s all about whether individual industrial devices are hackable. PLCs and RTUs are simple, vulnerable devices. But OT cybersecurity is really about systems of systems: computers, devices, people, processes, and safety controls. What really matters is life, safety, and process integrity.
Any final thoughts?
If you love learning how the world works, and you care about keeping everyday people safe, OT cybersecurity might be a great field for you to consider.