# How Jen Ellis Built a Bridge Between Security Researchers and Policy
## A Decade of Advocacy That Transformed Legal Protections for Cybersecurity Work
Jen Ellis has spent the last twelve years on a mission most people don't even know exists: protecting security researchers from the legal systems designed to punish them. Her efforts earned her recognition as a Member of the Order of the British Empire (MBE) this year—an honor rarely bestowed on those working in cybersecurity advocacy. But the path to that recognition began with a single moment of professional injustice that made her angry enough to change the trajectory of her entire career.
## The Moment That Changed Everything
In 2013, Ellis was working at Rapid7, managing communications for the security firm and collaborating closely with HD Moore, the creator of Metasploit and one of the most respected figures in the security research community. The two had built a productive partnership: Moore's team conducted cutting-edge technical research, and Ellis ensured the broader community understood why that work mattered.
Then the U.S. Department of Justice came calling.
Moore and his team had been conducting legitimate, good-faith security research through an initiative called Critical.io—an ambitious project designed to scan the internet systematically to identify vulnerable systems and help organizations patch before attackers could exploit them. The research was groundbreaking. It was also, according to the DoJ, potentially criminal.
"I got really, really mad about it," Ellis recalls, speaking years later about the moment she learned of the legal threats. "Not at HD—I totally understood his point of view. But I was mad that we had ticked every box to say this was legitimate, good-faith research."
Moore spent three months under the shadow of potential prosecution. The ordeal was so taxing that he questioned whether he could continue doing security research at all. For Ellis, that moment crystallized a much larger problem: the legal system was broken, and it was punishing the good guys.
## The Legal Framework That Failed
Ellis dove deep into the statutes arrayed against researchers: the Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA), and various state-level laws. What she discovered was a byzantine legal landscape written largely before cybersecurity became a mainstream concern—frameworks that conflated legitimate security research with malicious hacking.
The CFAA, enacted in 1986, made it illegal to "access a computer without authorization" or "exceed authorized access." For security researchers, this created a trap: scanning systems to find vulnerabilities could be interpreted as unauthorized access, even when the intent was defensive and the researcher operated in good faith.
The DMCA, passed in 1998, included provisions that criminalized circumventing security measures—even for research purposes or to responsibly disclose vulnerabilities. A researcher analyzing how a security system worked could face federal charges.
"The legal and judicial frameworks were acting in opposition to good guys," Ellis would later explain. Prosecutions were flying. Companies that researchers were trying to help—by disclosing vulnerabilities privately so they could patch—were launching lawsuits against those same researchers.
The chilling effect was immediate and severe. Security researchers who might have contributed to a safer internet were forced to choose between their careers and their conscience.
## What Critical.io and Project Sonar Actually Were
To understand why Ellis's anger was justified, the technical context matters. Moore's research initiative aimed to conduct internet-wide surveys—scanning the public IP space to catalog which systems were running what software and which ones were exposed to known vulnerabilities.
This work was not hacking. It was not intrusive. It was the digital equivalent of walking down a street and noting which houses had doors left ajar. The goal was to gather data that could help defenders understand the threat landscape and, critically, to contact affected organizations before attackers found those same vulnerabilities.
Project Sonar (as it would eventually be rebranded under Rapid7's banner) became one of the most valuable contributions to cybersecurity infrastructure—a foundational dataset used by defenders, researchers, and organizations worldwide to understand exposure and risk. The research that nearly landed Moore in federal prison is now considered essential infrastructure for the security community.
## The Catalyst for a Larger Movement
Ellis's anger at HD Moore's persecution became the fuel for something larger than defending a single colleague. She began advocating for legal reform—working to change the statutes, educate policymakers, and build protections for legitimate security research.
She became a vocal advocate for safe harbors for security researchers—legal provisions that protect good-faith research from prosecution under the CFAA and DMCA. She worked with industry groups, testified before lawmakers, and became a bridge between the technical security community and the political machinery that governs it.
Her work contributed to meaningful changes. The CFAA, while still controversial, has been refined over the years. The DMCA has faced growing criticism, and proposals for researcher safe harbors have gained traction. More organizations have adopted responsible disclosure policies, recognizing that researchers who find vulnerabilities are partners in defense, not threats.
## Recognition and Ongoing Impact
The MBE honor Ellis received in 2026 is unusual in cybersecurity circles. It recognizes not technical achievement but advocacy—the work of connecting a technical community with policymakers and helping to reshape legal frameworks that were fundamentally misaligned with cybersecurity's evolving needs.
But Ellis would likely argue that the real recognition lies in the changed landscape: researchers who can operate without fear of prosecution, companies that embrace responsible disclosure, and a legal system that has begun to distinguish between malicious hackers and well-intentioned security researchers.
## Why This Matters Now
The battle Ellis has fought for over a decade remains relevant. New threats emerge constantly, and with them, new questions about what researchers are permitted to study and how. AI security research, cloud infrastructure analysis, and emerging attack surfaces all exist in legal gray areas that echo the problems Moore faced in 2013.
Organizations investing in security must understand that the researchers helping to protect their systems often operate in legal jeopardy. Policymakers still struggle with how to frame laws that stop bad actors without criminalizing defense.
---
## HackWire Analysis
Jen Ellis's story reveals a critical gap in how cybersecurity is governed: technical and legal frameworks were built by different communities at different times, and they're still misaligned. The CFAA was written when the internet itself was nascent. The DMCA predates widespread vulnerability disclosure. Meanwhile, the security research community has evolved into a sophisticated ecosystem of independent researchers, vendors, and bug bounty platforms that now form the backbone of responsible defense.
What makes Ellis's advocacy work remarkable is that it required translating between worlds—convincing policy bodies that security researchers aren't a threat to national security or corporate interests, but rather essential partners in building safer systems. That translation remains ongoing. As AI security research accelerates, as supply chain attacks grow more sophisticated, and as the attack surface expands into new domains like autonomous systems and critical infrastructure, researchers will continue to operate in legal ambiguity unless the frameworks change faster.
The deeper lesson: a profession can't mature until its legal standing is resolved. HD Moore nearly left security research entirely not because of technical difficulty or market forces, but because the law treated him as a criminal for doing defensive work. How many researchers have already left? How many potential breakthroughs have been prevented by legal uncertainty? Ellis's work in connecting the security community with policymakers addresses this directly—not through technical solutions, but by ensuring that the rules governing the game don't accidentally trap the players trying to make everyone safer.
— HackWire Editorial
---
## Related Coverage