How Basketball Officiating Shaped a Cybersec Career

Jason Brooks (Cyber Security Professional)

Blacks in Cyber Village @ DEF CON 33 · Day 1 · Blacks in Cyber Village

Overview

In his compelling talk, "Full Court Press: How Basketball Officiating Shaped a Cybersec Career," Jason Brooks, a seasoned cybersecurity professional, draws an insightful parallel between the dynamic world of basketball—both as a player and an official—and the demanding realities of a cybersecurity career. Brooks, a US Navy veteran and second-generation technologist, leverages his unique background to illustrate how seemingly disparate experiences cultivate essential skills for success in cyber defense, threat intelligence, and Security Operations Center (SOC) operations. This presentation is a powerful argument for recognizing and valuing the transferable skills developed through diverse life experiences, particularly in team sports, as crucial assets in building a resilient and effective cybersecurity workforce.

Watch on YouTube

Visual summary for How Basketball Officiating Shaped a Cybersec Career by Jason Brooks
Visual summary for How Basketball Officiating Shaped a Cybersec Career by Jason Brooks

Key moments

  1. 0:00 Introduction: Fusing military, Silicon Valley, and sports
  2. 2:00 Speaker's dual journey: basketball and cybersecurity
  3. 4:00 Teamwork and communication: key correlation to cybersecurity
  4. 5:30 Defined roles with flexible execution in cybersecurity
  5. 7:00 Prioritization and triage: choosing technology over sports

Full Court Press: How Basketball Officiating Shaped a Cybersec Career

Speakers: Jason Brooks, Cyber Security Professional

Conference: Blacks in Cyber Village

YouTube: https://www.youtube.com/watch?v=XbSK6mvNL8c

Overview

In his compelling talk, "Full Court Press: How Basketball Officiating Shaped a Cybersec Career," Jason Brooks, a seasoned cybersecurity professional, draws an insightful parallel between the dynamic world of basketball—both as a player and an official—and the demanding realities of a cybersecurity career. Brooks, a US Navy veteran and second-generation technologist, leverages his unique background to illustrate how seemingly disparate experiences cultivate essential skills for success in cyber defense, threat intelligence, and Security Operations Center (SOC) operations. This presentation is a powerful argument for recognizing and valuing the transferable skills developed through diverse life experiences, particularly in team sports, as crucial assets in building a resilient and effective cybersecurity workforce.

Brooks's central thesis posits that the core competencies demanded on the basketball court—such as teamwork, communication, split-second decision-making, conflict management, strategic thinking, attention to detail, and resilience—are not merely soft skills but foundational pillars for navigating the complex and high-pressure landscape of cybersecurity. He challenges the conventional view that only technical prowess defines a cyber professional, advocating instead for a holistic approach that embraces a broad spectrum of human capabilities. This talk matters because it offers a vital framework for individuals to identify and articulate their unique value, and for organizations to foster more diverse and robust security teams capable of addressing multifaceted threats.

Background

▶ Watch: Introduction: Fusing military, Silicon Valley, and sports (0:00)

The cybersecurity industry, often perceived as a purely technical domain, frequently prioritizes certifications, specific tool proficiencies, and deep technical knowledge. While these elements are undoubtedly critical, there's a growing recognition that the human factor—encompassing everything from team dynamics to individual stress management—plays an equally, if not more, significant role in successful cyber defense. The problem, as Brooks subtly highlights, is that these crucial "soft skills" are rarely explicitly taught or formally valued in the same way as technical aptitudes, leading to potential skill gaps and overlooked talent.

Brooks's journey provides a compelling case study for this oversight. From a young age, basketball was his passion, evolving from a competitive player to a scorekeeper and eventually an official. This progression, particularly his stint as a scorekeeper, immersed him in the intricate rules and mechanics of the game, inadvertently fostering an attention to detail and an understanding of impartiality that would later prove invaluable. His pivotal decision in high school to prioritize robotics over basketball practice, despite being a starting player, underscores an early commitment to technology and a nascent understanding of prioritization and triage—a decision that ultimately paid off, earning him "Six Man of the Year" even while benched for his tech pursuits. This background sets the stage for his argument: that the experiences we gather, even outside traditional academic or professional tracks, are rich reservoirs of transferable skills essential for a thriving cybersecurity career.

Key Findings

▶ Watch: Speaker's dual journey: basketball and cybersecurity (2:00)

Jason Brooks meticulously outlines several key findings, demonstrating the profound and often surprising correlations between basketball and cybersecurity. These parallels offer a fresh perspective on the competencies essential for success in the cyber realm:

  1. Teamwork and Communication: Effective information sharing is paramount. Just as a basketball team relies on clear verbal and non-verbal communication, cybersecurity teams require precise, concise information exchange during incident response and daily operations. This includes having defined roles (e.g., Tier 1, Tier 2, Tier 3 analysts) but also fostering flexible execution, where individuals can cross-train or adapt to different responsibilities, much like a utility player in basketball.
  2. Split-Second Decision-Making: On the court, officials must make immediate calls (e.g., "block or charge") with no room for hesitation. In cybersecurity, professionals face similar high-stakes decisions during threat detection and triage, where rapid, informed choices are critical to containing a breach or mitigating a vulnerability.
  3. Impartiality and Integrity: Officials must enforce rules fairly, without bias towards either team. This translates directly to the ethical imperative of cybersecurity professionals to act with integrity, ensuring fair application of policies and procedures, whether dealing with internal teams or external threats.
  4. Conflict Management: Dealing with coaches, players, and teammates in high-pressure situations builds robust conflict resolution skills. In cybersecurity, this is vital for navigating internal "blame games" during an incident, mediating between different departments, or advocating for security best practices.
  5. Strategic Thinking and Frameworks: Both sports and cybersecurity rely on game plans and frameworks. Brooks highlights a "Prepare, Execute, Adapt, Review" model, mirroring common cybersecurity frameworks like the NIST Cybersecurity Framework or incident response playbooks. This structured approach ensures continuous improvement and readiness.
  6. Attention to Detail and Pattern Recognition: Identifying subtle cues on the court, like a player's "signature move" or a foot on a line, is analogous to spotting anomalies in logs, identifying vulnerabilities in systems, or recognizing adversary Tactics, Techniques, and Procedures (TTPs). Small details, like a misconfiguration (a common OAS Top 10 vulnerability), can have significant consequences.
  7. Adaptability and Resilience: The ability to "bounce back" from missed calls, manage intense scrutiny, and maintain mental toughness is crucial. Cybersecurity professionals frequently face high-stress scenarios, making mistakes, and dealing with constant pressure. Resilience—learning from errors and moving forward—is essential for career longevity and preventing burnout. Brooks emphasizes the importance of "halftime"—taking breaks to refresh and renew—as a critical strategy for mental well-being.

Technical Deep Dive

▶ Watch: Teamwork and communication: key correlation to cybersecurity (4:00)

While Brooks's talk doesn't delve into specific code or network protocols, it offers a profound "technical deep dive" into the application of human skills within technical cybersecurity contexts. The parallels he draws are not merely theoretical but directly actionable in the daily operations of a security professional.

Consider Teamwork and Communication in a Security Operations Center (SOC). Brooks likens "passing the ball" to information sharing during a complex security incident. When a Tier 1 analyst identifies a suspicious alert from an Endpoint Detection and Response (EDR) tool, clear and concise communication is paramount. This initial alert, akin to a pass, must be accurately relayed to a Tier 2 analyst for deeper investigation. If the incident escalates, the incident response team must communicate effectively with various stakeholders—legal, PR, management—ensuring everyone understands the scope of the breach, the containment strategies, and the eradication efforts. Defined roles, such as network forensics specialists, malware analysts, or vulnerability managers, are crucial, but Brooks emphasizes flexible execution. In a major incident, a network specialist might need to assist with system hardening, or a threat intelligence analyst might pivot to support containment efforts, demonstrating the "utility player" adaptability.

Split-Second Decision-Making is a constant in cybersecurity. An official's call between a "block or charge" mirrors a SOC analyst's triage decision when faced with a critical alert. Is it a legitimate user error, a false positive, or a genuine Advanced Persistent Threat (APT)? The decision to isolate a host, block an IP address at the firewall, or escalate to a Level 3 incident responder must be made rapidly, based on available logs and contextual intelligence. There's often no "coming back" from a delayed or incorrect decision, which could allow an attacker to pivot or exfiltrate data. Brooks's emphasis on impartiality and integrity also applies here; an analyst must follow established playbooks and security policies without bias, ensuring all alerts are treated with the same rigor, regardless of the affected department or individual.

Brooks vividly illustrates Conflict Management with a personal anecdote from his time as a vulnerability manager at a DoD contractor. During a security breach, different parties were engaged in a "blame game." His learned skills from basketball officiating allowed him, even as a junior personnel, to sit down the conflicting teams, facilitate open communication, and work towards a resolution and clear next steps. This highlights that cybersecurity isn't just about identifying malware or patching CVEs; it's profoundly about managing human dynamics, especially under duress. Resolving inter-departmental conflicts over security controls or compliance requirements often requires these same diplomatic and persuasive abilities.

The Strategic Thinking paradigm of "Prepare, Execute, Adapt, Review" is a direct mapping to standard cybersecurity frameworks and methodologies.

  • Prepare: This phase involves proactive measures like threat modeling, conducting vulnerability assessments and penetration tests, developing incident response plans, and gathering threat intelligence.
  • Execute: This is the active defense stage, where security controls are operationalized, monitoring systems are vigilant, and incident responders follow established playbooks to contain and eradicate threats.
  • Adapt: The cybersecurity landscape is constantly evolving. New adversary TTPs, zero-day exploits, and emerging vulnerabilities necessitate continuous adjustment of defensive tactics and security posture. This involves staying updated on MITRE ATT&CK techniques and evolving security architectures.
  • Review: Post-incident After Action Reviews (AARs) are critical. Just as a basketball team reviews game film, cybersecurity teams analyze EDR logs, SIEM data, and forensic artifacts to identify what went well, what went wrong, and how to improve future responses. This feedback loop is essential for continuous security posture improvement.

Finally, Attention to Detail and Pattern Recognition are non-negotiable in cybersecurity. Brooks's example of a "foot on the line" changing a game is analogous to a single misconfiguration in a cloud environment or an unpatched vulnerability (like those listed in the OAS Top 10 for web application security) that can open the door to a catastrophic breach. Identifying subtle anomalies in network traffic, recognizing the signature moves of a particular threat actor (e.g., specific malware families or command-and-control (C2) channels), or meticulously reviewing audit logs for suspicious activity all require a keen eye for detail. This is the essence of effective threat hunting and vulnerability management.

Demo / Proof of Concept

▶ Watch: Defined roles with flexible execution in cybersecurity (5:30)

This talk did not include a technical demonstration or proof of concept in the traditional sense, such as showcasing a new tool, an exploit, or a defensive mechanism. Instead, Jason Brooks effectively demonstrated his core thesis through compelling personal anecdotes and direct, relatable correlations between scenarios encountered in basketball and real-world cybersecurity challenges. His "proof" was the lived experience and practical wisdom derived from integrating these two seemingly disparate domains, illustrating how a diverse background directly translates into enhanced professional capability in the cybersecurity field.

Defensive Implications

▶ Watch: Prioritization and triage: choosing technology over sports (7:00)

The insights shared by Jason Brooks carry significant implications for cybersecurity defenders, urging a re-evaluation of how teams are built, skills are valued, and professionals are supported.

  1. Broaden Recruitment and Hiring Paradigms: Organizations should actively seek candidates with diverse backgrounds, recognizing that valuable transferable skills often come from unconventional experiences. Beyond technical certifications, look for evidence of teamwork, leadership, conflict resolution, and resilience from sports, military service, arts, or other fields. This can significantly expand the talent pool beyond traditional computer science graduates.
  2. Invest in "Soft Skill" Development: While technical training remains crucial, cybersecurity teams must also prioritize the development of communication, decision-making under pressure, conflict management, and critical thinking skills. Incorporate these into regular training programs, workshops, and mentorship initiatives, emphasizing their direct application in incident response, vulnerability management, and threat intelligence roles.
  3. Cultivate a Culture of Resilience and Well-being: Acknowledge the high-pressure nature of cybersecurity and actively promote strategies for burnout prevention. Encourage "halftime" – scheduled breaks, mental health resources, and a supportive environment where taking time to refresh is encouraged, not penalized. Leaders should model this behavior and ensure team members feel safe to recover from mistakes and learn from them.
  4. Enhance Incident Response Playbooks with Human Elements: While technical steps are vital, incident response playbooks should also explicitly address communication protocols, stakeholder management, and conflict resolution strategies during a crisis. Training scenarios should include human-centric challenges, such as dealing with a "blame game" or managing external pressure, to better prepare teams for real-world incidents.
  5. Foster Defined Roles with Flexible Execution: Encourage cross-training and skill diversification within security teams. While specific roles (e.g., SOC analyst, forensic investigator, security architect) are necessary, creating a culture where individuals can adapt and support different functions, much like a utility player, enhances overall team agility and responsiveness to evolving threats.
  6. Prioritize After Action Reviews (AARs): Implement robust AAR processes after every significant incident or exercise. Ensure these reviews are constructive, focus on systemic improvements rather than individual blame, and incorporate lessons learned into updated security policies, procedures, and playbooks. This commitment to continuous improvement mirrors the "reviewing game film" approach, allowing the team to adapt and refine its defensive strategies against new adversary TTPs.

Key Takeaways

  • Diverse backgrounds are a cybersecurity superpower: Unconventional experiences, especially in team sports, cultivate essential transferable skills that are often overlooked but critical for success in cyber.
  • Soft skills are foundational, not secondary: Communication, teamwork, decision-making under pressure, and conflict resolution are as vital as technical expertise for effective cyber defense and incident response.
  • Resilience is paramount for career longevity: The ability to learn from mistakes, manage high-pressure situations, and prioritize self-care ("halftime") is crucial to prevent burnout in a demanding field.
  • Strategic frameworks mirror real-world game plans: The "Prepare, Execute, Adapt, Review" model directly applies to cybersecurity frameworks, ensuring structured and continuous improvement in security posture.
  • Attention to detail and pattern recognition are non-negotiable: Identifying subtle anomalies in logs or misconfigurations is analogous to spotting critical plays in a game, often determining the outcome of a security incident.
  • Leaders must champion diverse teams and holistic development: Organizations should actively seek and nurture professionals from varied backgrounds, investing in both technical and human-centric skill development to build stronger, more adaptable security teams.

About the Speaker(s)

Jason Brooks is a distinguished cybersecurity professional with a rich and varied background that uniquely positions him to speak on the intersection of diverse experiences and professional success. A proud Bay Area native and a US Navy veteran, Jason brings over a decade of hands-on experience in critical cybersecurity domains, including SOC operations, threat intelligence, and cyber defense. His journey is also deeply intertwined with his passion for sports, particularly basketball, where he has excelled as both an athlete and an official. As a second-generation technologist, he has a long-standing commitment to the field, culminating in his current role as a cybersecurity engineer and consultant. Brooks's unique perspective highlights the profound value of transferable skills developed outside traditional career paths, demonstrating how discipline, teamwork, and resilience forged on the basketball court directly enhance capabilities in the complex world of cybersecurity. He is reachable via Twitter at Jason Brooks32 and via email at jbrooksbcurity.com.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A career-motivation talk dressed up with cybersecurity vocabulary. Brooks is clearly a capable practitioner with a genuine story to tell, but the analogy framework — basketball skills map to SOC skills — is surface-level inspiration, not insight. This belongs at a workforce development panel or community meetup, not as a conference session claiming substantive content.

Heather Calloway (CISO) — SOLID

Jason Brooks makes a genuine and well-intentioned argument for valuing transferable skills in cybersecurity hiring and team-building, and he delivers it with credibility rooted in lived experience. The talk serves its audience — people entering or navigating the field from non-traditional paths — but it doesn't reach the institutional or leadership level where hiring paradigms actually change.

→ Top-rated talks at Blacks in Cyber Village @ DEF CON 33

All talks from Blacks in Cyber Village @ DEF CON 33