Slaying Dragons Together: Women in Security (Panel)
Stanley Barr, Mary C Yang, Leslie Z Anderson
BSidesSF 2025 — Here Be Dragons · Day 2 · Main
Overview
MITRE researchers Stanley Barr and Leslie Anderson, alongside marketing strategist Mary Yang, used the origin stories of MITRE ATT&CK and MITRE Engage to illustrate a broader thesis: complex security problems require multidisciplinary teams, and building those teams is a deliberate, ongoing process that starts years before any framework is published. The panel also introduced MITRE's early-stage work applying ATT&CK-style threat-informed defense to internet-enabled crimes against children.

Key moments
- 5:59 MITRE ATT&CK origin: Fort Meade Experiment shifted from IOCs to TTPs in 2013
- 7:59 Bold decision to release ATT&CK publicly was revolutionary for threat intelligence sharing
- 11:59 MITRE Engage: deception-based defensive framework born from DIB attack research
- 18:00 Multidisciplinary teams essential: technologist + marketer + strategist needed for impact
- 23:59 Case study: how community collaboration produced scalable security frameworks
- 30:00 Panelists: breaking out of isolation requires deliberately building cross-discipline trust
- 36:00 Practical guide to leveraging open communities to solve organization-specific security gaps
Slaying Dragons Together: Women in Security
Speakers: Stanley Barr (MITRE), Mary C Yang, Leslie Z Anderson (MITRE)
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: Watch the full talk
Reading time: ~8 minutes
TL;DR
MITRE researchers Stanley Barr and Leslie Anderson, alongside marketing strategist Mary Yang, used the origin stories of MITRE ATT&CK and MITRE Engage to illustrate a broader thesis: complex security problems require multidisciplinary teams, and building those teams is a deliberate, ongoing process that starts years before any framework is published. The panel also introduced MITRE's early-stage work applying ATT&CK-style threat-informed defense to internet-enabled crimes against children.
Introduction
The talk's title — "Slaying Dragons Together" — maps onto the BSidesSF conference theme of "Here Be Dragons" and onto a core argument: the dragons in cybersecurity are too large, too varied, and too fast-moving for any single discipline to slay. Technology expertise is necessary but insufficient. Marketing, strategy, law, user experience, and community relations are all part of what turns a research finding into a framework that the global security community actually adopts.
The panel's three speakers embody that argument. Barr is a MITRE security researcher who built deception operations and the technical foundations of the ENGAGE matrix. Yang ran marketing and market analysis for MITRE, helping translate Barr's technical work into something vendors and defenders could use. Anderson is a MITRE strategist who managed the business, legal, and community-building dimensions of getting both ATT&CK and Engage from internal research to public release. Their combination of skills mirrors the lesson they were there to teach.
▶ Watch: Panel introductions and the power of community (00:00)
The Power of Multidisciplinary Teams
The panel opened with an exploration of why community and cross-disciplinary collaboration matter for security work specifically. Barr framed it from the technologist's perspective: "Part of what I've found working with community is that you really do need people who have a different viewpoint than you." As a researcher, he could build technology and accumulate findings. But he needed people who could explain why anyone should care, connect the work to a corporate vision, read a Gartner report, and tell him whether his ideas were comprehensible to the practitioners he was trying to help.
Anderson's frame was organizational: at MITRE, which operates without commercial motive as a federally funded research and development center, the value of trusted relationships is the institution's most important asset. MITRE works across government and industry, and the ability to hold those conversations without a sales agenda means practitioners share information they would not share elsewhere. "It's a privilege to work at a place like MITRE because you get to be the connector across all of these communities."
▶ Watch: Benefits of community — ideation, communication, trust (02:00)
Yang's contribution was the bridge between those two perspectives: the market analyst and communicator who helped translate technical findings into language that resonated with the vendors, practitioners, and organizations the frameworks were meant to serve.
ATT&CK: The Framework That Almost Stayed Internal
▶ Watch: ATT&CK origin story and the decision to release (06:00)
The origin of MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) began as an internal project. In the early 2010s, MITRE was observing advanced persistent threats (APTs) on its own network and building capability to look inside encrypted communications and perform host forensic analysis. The goal was to understand not just the initial spear-phish and callback — the information most organizations had — but what came next: the TTPs (tactics, techniques, and procedures) adversaries used after gaining a foothold.
Blake Strom led the project. Barr was on the research team during this period. As the knowledge base grew, the realization emerged that this information had value far beyond MITRE's own defense. MITRE's then-Chief Security Officer Gary Gagnon made what Anderson described as a bold decision at the time: release the first ATT&CK matrix publicly.
"That's not the kind of stuff that was being shared publicly," Anderson said. Threat intelligence was closely held. Organizations that had been compromised kept their findings internal. Sharing TTPs openly — not just IOCs inside closed sharing groups like the FS-ISAC — was genuinely novel. A new ATT&CK version had been released just days before the BSidesSF panel.
ATT&CK is now a community-driven framework: MITRE manages it, but the TTPs it contains come from the global security community, analyzed by the ATT&CK team and incorporated into the knowledge base. The framework marked a broader shift in MITRE's advocacy for threat-informed defense — the idea that defenders should plan against the actual observed intentions and techniques of their adversaries, not just against generic vulnerability categories.
MITRE Engage: Ten Years in the Dark
▶ Watch: Deception operations, the Engage origin, and RSA 2018 (10:00)
MITRE Engage emerged from a different kind of work: active deception operations. While defenders in the mid-2000s were focused on Patch Tuesday and perimeter defense, MITRE's team was running malware in controlled environments, observing adversary behavior, and building intelligence that classified government sources could not practically provide.
"We worked in silence for about ten years," Barr said. The deception research was internal and not discussed publicly. The shift came when MITRE's CISO decided he wanted to do for deception what ATT&CK had done for adversary techniques: take the knowledge and release it.
Yang's role in that transition was critical. She emailed every deception vendor on the market, invited them to a closed workshop at RSA 2018, and facilitated conversations between Barr's technical team and the practitioners and vendors who would ultimately use any resulting framework. Anderson noted that getting competitors into the same room to share what they were seeing in the market was "a little crazy" — but the conversations that came out of it shaped what became the Engage matrix.
▶ Watch: Engage framework development — focus groups, UX design, and vendor feedback (16:00)
How to Build a Collaborative Framework
The panel walked through the lessons learned from building both ATT&CK and Engage into actionable guidance for others attempting similar work.
Bring in user experience expertise from the start. For Engage, MITRE brought in a UX expert before the framework had taken shape. She attended Barr's initial briefings, participated in focus groups, and helped ensure the matrix was designed around how defenders think and work rather than around how the technology team had organized the underlying research. "We wanted to make the design of Engage truly user-centric versus technology-centric," Anderson said.
Establish a single, consistent point of view. A framework cannot simultaneously reflect every stakeholder's perspective. The Engage team decided the framework would represent the defender's viewpoint of every interaction — not the adversary's perspective, not the vendor's perspective, not the tool's capabilities. "We had to decide what is it, and we decided to put the defender first," Barr explained. Achieving agreement on that single viewpoint was the hardest part of the design process.
▶ Watch: Framework design principles and the single point of view problem (34:01)
Document relentlessly, then sort. The process of building Engage involved years of documented observations, focus group notes, vendor conversations, and internal debate. When it came time to design the framework, the team "dumped it all out on the table" and sorted it into coherent categories. The framework emerged from the data rather than being imposed on it.
Be willing to take lumps. Focus groups and vendor conversations revealed where the early framework was confusing, inaccessible, or irrelevant to practitioners' actual workflows. Some of the harshest feedback was from vendors who said they simply needed something they could use to sell. That feedback produced a better framework — one that served both the hands-on technologist and the vendor trying to articulate why their product mattered.
Consider compliance and legal from the beginning. Anderson noted that MITRE's CISO and general counsel had a long-standing trusted relationship before the deception operations began. Some of what the CISO asked counsel to approve had no precedent. That trust, built over years of working together, was what made it possible. "Underpinning the trust element was the relationship that our CISO had with our general counsel."
Broader Applications: Crimes Against Children
▶ Watch: Applying threat-informed frameworks to internet-enabled crimes against children (40:02)
Anderson introduced MITRE work in progress that extends the threat-informed defense approach beyond cybersecurity: a research project led by Pamela Pettercheck applying ATT&CK-style systematic categorization to internet-enabled crimes against children. Using open-source information from court records, the project is building a knowledge base of how these crimes are enabled by technology — to better inform law enforcement, prosecutors, victim services organizations, and families.
The project is still early-stage and actively seeking input from technology firms, nonprofit organizations, and policy experts. Pettercheck's contact information was included on the panel slides for those wishing to contribute.
"It's not just cybersecurity issues that can be managed through a community approach, through an open source approach," Anderson said. "It can be things that are much more broadly impactful."
Caldera and the Community Maintenance Model
The panel also noted that MITRE Caldera — the open-source adversary emulation platform built on top of ATT&CK — is currently funded through an NSF grant aimed at transitioning it toward community management. MITRE is looking for volunteer managers to help lead its continued development, with the goal of making Caldera community-managed rather than MITRE-managed over time. Anderson encouraged interested practitioners to reach out.
Notable Quotes
"You really do need people who have a different viewpoint than you. Just because it's important to you and your company doesn't mean it's important to anyone else." — Stanley Barr at 04:00
"We worked in silence for about ten years until we came to RSA in 2018. That's when we decided to open this up." — Stanley Barr at 14:00
"You're building your collaborative ecosystem every day throughout your career with every move you make." — Leslie Anderson at 36:02
Key Takeaways
- Security research requires multidisciplinary teams to achieve impact. Technology expertise produces findings; marketing, strategy, legal, and UX expertise turn those findings into frameworks that the community adopts and sustains.
- Making work public is a strategic decision that requires institutional courage. ATT&CK's public release in the early 2010s was unusual; sharing detailed adversary TTPs with the community was genuinely novel. That decision created the foundation for global adoption.
- User experience design is not optional for security frameworks. A framework built around how technologists think will not serve the full range of practitioners, vendors, and organizations that need to use it. Engage's UX expert was brought in at the start, not added at the end.
- Trust relationships with legal counsel must be built before they are needed. Deception operations and public framework releases both required legal sign-off on actions without precedent. Having a CISO and general counsel who already trusted each other was what made those approvals possible.
- The community you build throughout your career is cumulative. The vendor relationships built at RSA 2018, the focus group participants, the framework contributors — all of them continue to matter years later, even when organizational roles change.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
The ATT&CK and Engage origin stories are genuinely worth knowing — the ten years of silent deception operations before RSA 2018, the UX expert brought in before the framework had taken shape, the single-defender-viewpoint decision that was hardest to achieve. The MITRE branding is heavy throughout and the 'multidisciplinary teams matter' thesis undersells the actual interesting content.
Heather Calloway (CISO) — WEAK
The ATT&CK and Engage origin stories are interesting institutional case studies, and the multidisciplinary team argument is real. But this is a framework-building retrospective, not a security talk. The defender story is absent and the governance content is organizational rather than risk-focused.