Black Hat USA 2026 —Las Vegas—When Bob Lord became the first chief security officer (CSO) for the Democratic National Committee (DNC) in 2018, he plastered “Bobmoji” stickers above urinals, in bathroom stalls, and on the mirrors. As employees washed their hands, avatar renderings of his face served as a security-first reminder.
To implement and maintain a strong security culture, CSOs must be willing to be “absurd,” Lord revealed during Black Hat USA 2026. Lord, now consultant at Lord Consulting, and his successor, Steve Tran, broke down how the party organization built its defenses following a 2016 hack by Russian state actors and continued evolving security.
The DNC is a cyclical organization where “the idea is to win elections, not to be more secure,” said Tran, but their recommendations and best practices can be applied to organizations across sectors.
Bobmojis weren’t the only tactic Lord used to mold a security mindset, which can take plenty of work. He also created a “Family Feud” game dupe, dubbed “Security Feud,” to instill the importance of security checklists among employees. As people shouted, “update software” and “use multifactor authentication” and Lord high-fived them during the game, he knew the theatrics were well worth it.
When Tran, now CISO at lyuno, took over the DNC CSO role in 2022, he replaced Bobmojis with bobbleheads. The predecessor and successor agreed on tactics to get people to care about security.
Expect the Unexpected
However, as Tran took over the role, some of Lord’s work didn’t meet his expectations. This is commonplace when one security leader takes over for another, Tran and Lord explained. When CSOs walk into a new role, they conduct an audit to learn the environment, people, and processes. Tran was just trying to understand what Lord was thinking, which is important for any successor to examine.
They disagreed on the importance of email scanning, and Tran was perplexed by Lord’s choice to use Chromebook computers. But auditing the cultural mindset to determine which routines changed how people think about security was one critical point where they’re on the same page.
DNC employees didn’t work with “fancy Windows machines,” as he expected. Instead, they worked on Chromebooks. Tran didn’t think that adoption was practical or possible, but Lord proved him wrong.
Not only did Chromebooks offer a more secure path, but they were also cheaper than trying to revive the organization’s aging Windows infrastructure and active directory (AD) controller, explained Lord. AD on-premises is an attack magnet, he warned.
“I walked in with a certain set of expectations,” Tran said during the session. He was happy to see hardware security keys in place, and strong multifactor authentication (MFA).
“You did the hardest part, getting a huge user base to enroll in YubiKeys and use it,” he said, turning to Lord. “The laptops were locked down, which was amazing. You got people to patch.”
On the other hand, Tran was unpleasantly surprised by the lack of email scanning. But Lord had his reasoning and the pieces Tran thought were missing were intentional on his part. Lord wasn’t trying to stop an attack at the moment of delivery, whether threat actors used email or SMS, but build resilience against social engineering scams.
“It’s much better to stop it at the moment of intrusion, whether they’re trying to get you to install software or cough up your username and password,” he said. The CSOs’ goal is to make systems resilient so that threat actors won’t simply be able to run malware or steal sensitive credentials.
“As an executive coming into the organization, expect the unexpected,” Lord said.
When the Chairman Calls, You Answer
As in many organizations, Lord faced budget constraints while working at the DNC. But he found that the chief financial officer was his “biggest ally,” which made a world of difference.
And support extended even further than that. Tom Perez, who served as DNC chairman from 2017 to 2021, had the security team speak for the first 10 minutes of every staff meeting and committed to improving security standards.
Many of his moves surprised Lord. When he and his team rolled out security keys to everyone, Perez called one day after the deadline to see if everyone had enrolled. When he found out that some stragglers remained, Perez called their personal cell phones to ensure they enrolled over the next couple of weeks.
However, it didn’t take weeks — they enrolled immediately after getting that call from the chair.
“That’s not executive buy-in or advocacy. That’s co-ownership,” Lord said.
When Tran took over as DNC CSO, he felt he inherited a strong security program thanks to his predecessor. His job then became: How does the organization continue to move forward? With a deeply imbedded security-first mindset, he focused on a cloud security upgrade, and implemented a knowledge management portal, and a security risk committee.
“You saved me so many hard parts,” Tran told Lord. “I came in to help them work with grey areas a little bit more, because not everything is black and white in security.”


