From Gamer to Leader: How to Build Resilient Cyber Teams

Matthew Radolec (Vice President, Incident Response & Cloud Operations · Varonis)

RSA Conference 2025 · Day 3 · West Stage · Keynote

Overview

Varonis VP Matthew Radolec argued at RSA Conference 2025 that the gaming community represents the most underutilized talent pool in cybersecurity — a group whose intrinsic skills in strategy, adaptability, persistence, and teamwork map directly onto the competencies security teams need. Beyond recruitment, he laid out a management model built around three gaming-derived principles: recruit gamers, give them quest lines to follow, and equip them with AI-powered tools that function as force multipliers, turning analysts into what he called "heroes of data." ---

Watch on YouTube

Visual summary for From Gamer to Leader: How to Build Resilient Cyber Teams by Matthew Radolec
Visual summary for From Gamer to Leader: How to Build Resilient Cyber Teams by Matthew Radolec

Key moments

  1. 2:10 Gamers are the most untapped cybersecurity talent pool
  2. 4:15 Cybersecurity mirrors gaming: new threats demand rapid learning
  3. 5:47 Gamer researchers found exposed Salesforce 'ghost sites' vulnerability
  4. 7:15 Threat actor names mirror gaming monster archetypes by design
  5. 8:22 46% of US gamers are female — expands women-in-cyber pipeline
  6. 11:46 Varonis AI triages 100% of alerts; auto-decides over half
  7. 14:31 Scattered Spider targets IT helpdesk with MFA fatigue attacks
  8. 17:14 Team reversed Scattered Spider beacon, eliminated command-and-control

Gamers Are the Cybersecurity Workforce You Are Overlooking

Speakers: Matthew Radolec, VP of Incident Response and Cloud Operations, Varonis

Conference: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

YouTube: https://www.youtube.com/watch?v=dxN77JMSIDg

Reading time: ~7 min

TL;DR

Varonis VP Matthew Radolec argued at RSA Conference 2025 that the gaming community represents the most underutilized talent pool in cybersecurity — a group whose intrinsic skills in strategy, adaptability, persistence, and teamwork map directly onto the competencies security teams need. Beyond recruitment, he laid out a management model built around three gaming-derived principles: recruit gamers, give them quest lines to follow, and equip them with AI-powered tools that function as force multipliers, turning analysts into what he called "heroes of data."

Introduction

Matthew Radolec opened his RSA Conference 2025 keynote with an audience poll: how many people in the room were gamers? The response — hands raised for World of Warcraft, Counter-Strike, PUBG, Candy Crush, and racing simulators — established his premise before he stated it. The security industry has a talent problem, but the solution may be hiding in plain sight.

Radolec, who has led incident response at Varonis and built the company's AI-powered managed detection and response service, traced his own career back to a Night Elf hunter raid leader position in World of Warcraft at age 13. That background, he argued, was not incidental to his professional development — it was formative. The same skills that made him effective in competitive gaming made him effective in security operations.

The talk was structured as a quest with three achievements to unlock: why to recruit gamers, how to develop them through structured challenge, and how to equip them with tools that amplify their capabilities.

Achievement One: Recruit Gamers — and Embrace What They Bring

▶ Watch: The case for recruiting gamers (2:00)

Radolec's argument for gamers as cybersecurity recruits rested on behavioral characteristics that competitive gaming selects for over time. Gamers are accustomed to rapidly shifting objectives — today's mission might involve learning about Scattered Spider's MFA bypass techniques; tomorrow's might require securing Kubernetes infrastructure. Gamers treat that kind of context-switching as a milestone rather than a disruption. They are, in Radolec's framing, intrinsically motivated by mastery and achievement in ways that map well onto a field that never stops changing.

The structural parallels between gaming and security are more than metaphorical. Radolec walked through several:

  • Bug bounties function like in-game bounty boards: find a specific vulnerability, collect a reward. Varonis Threat Labs researchers chase bug bounties as a full-time job. They discovered what they internally called "ghost sites" — abandoned Salesforce instances inadvertently exposing sensitive data — and "secret agents," vulnerable credential-exposing components of Okta infrastructure, among other findings.
  • Capture the Flag events are direct analogs to competitive game scenarios, providing blue and red teams with low-stakes, high-learning environments to sharpen detection and response skills.
  • Threat actor naming conventions — Scattered Spider, Mummy Spider, Cozy Bear, Fancy Bear — are themselves a form of gamification, casting adversaries as bosses to be understood and defeated.

▶ Watch: Threat actors as dungeon bosses (6:00)

Radolec also made a demographic argument that the audience visibly responded to: 46% of gamers in the United States are female, while only 30% of the cybersecurity workforce is women. Recruiting from the gaming community is not just a talent strategy — it is a diversity strategy with a ready-made pipeline.

Achievement Two: Give Gamers a Quest Line

▶ Watch: Building career progression as quest design (8:00)

Recruiting gamers is necessary but not sufficient. Radolec's second argument was about retention and development: gamers thrive in environments where growth is legible, progression is structured, and achievement is recognized. Without that structure, they leave.

His prescription for security leaders was to think like game designers. The metaphor he used was a "talent tree" — a visible path from entry-level analyst to increasingly senior roles, with defined milestones along the way. In concrete terms, this means taking a Security Operations Center analyst and giving them a structured path toward incident management: first handling investigations, then managing incidents, and ultimately becoming a major incident commander responsible for coordinating response across disparate teams and presenting executive wrap-up summaries to boards of large public and private companies.

The game design metaphor carries a practical implication: gamers do not tolerate stagnation. If the path to advancement is unclear or the work is purely repetitive, the same motivation that makes them excellent at progressive challenge will drive them to seek that challenge elsewhere. Leaders who understand this build retention into their team architecture.

Achievement Three: Equip Them with AI — the Mythical Sword

▶ Watch: AI as a force multiplier for analysts (10:00)

The third section of Radolec's talk addressed the intersection of gaming-derived talent and AI-powered tooling — the combination he argued is what actually produces exceptional security teams.

Varonis's operating model targets a 90/10 split: 90% of effort completed by the company's systems, robots, and AI; 10% by customers. That same philosophy applies internally to the ratio of work handled by AI security analysts versus human analysts.

The AI security analyst Varonis has built works alongside human analysts to investigate and triage 100% of alerts triggered for customers. It auto-decisions more than half of those alerts. What is left for humans is the genuinely complex work — the investigations that require contextual judgment: why is an HR employee accessing source code? Why is an ERP service account attempting to spin up a Kubernetes cluster in AWS and export a database as a text file?

▶ Watch: What the AI analyst handles vs. what it leaves for humans (12:00)

"AI is doing the mundane. It's saving the juiciest, the most important, and the most complex work, the best work for humans."

(12:00)

The result, Radolec argued, is not just efficiency — it is professional development. Analysts equipped with AI tools are handling a higher-quality portfolio of work faster. They develop faster. The AI analyst functions, in his framing, as a mythical sword from a role-playing game: an equipment upgrade that changes what a character can accomplish, not a replacement for the character.

The Scattered Spider Raid: Theory Into Practice

▶ Watch: Assembling a team to take on Scattered Spider (14:01)

To make the framework concrete, Radolec walked through a real engagement against Scattered Spider — a criminal group that specializes in social engineering, MFA bypass, and data extortion, commonly associated with the BlackCat and AlphaV ransomware variants.

Scattered Spider's tactics are well-documented and difficult to counter because they exploit the human layer rather than purely technical vulnerabilities. The group impersonates IT helpdesk personnel, solicits MFA codes from users, launches MFA fatigue attacks, and has been known to execute SIM-swapping to intercept authentication challenges directly.

The Varonis response team Radolec described assembled specialists across four domains: incident handlers (to work through compromised machines and logs), forensics experts (for memory dumps and binary extraction), identity experts (to address credential reuse and brute-force attempts), and security researchers (to reverse-engineer unfamiliar binaries and map command-and-control infrastructure).

Working together, the team repelled repeated access attempts by Scattered Spider, prevented the threat actor from establishing persistent footholds via remote access trojans, and — when the attackers made a mistake — obtained a copy of their beacon binary. Reverse engineering that binary gave the team full visibility into the command-and-control infrastructure and allowed them to identify and take offline every compromised account and system before data was exfiltrated.

"We slayed this spider, at least for now."

(16:00)

The use of "at least for now" was deliberate — a recognition that in cybersecurity, as in gaming, there is no final boss. The adversary respawns.

Notable Quotes

"I think gamers are the most untapped talent pool in the workforce today, and they are ideal for cybersecurity."

— Matthew Radolec (2:00)

"Forty-six percent of gamers in the US are female, while only thirty percent of the cyber workforce is women."

— Matthew Radolec (8:00)

"AI is doing the mundane. It's saving the juiciest, the most important, and the most complex work, the best work for humans."

— Matthew Radolec (12:00)

Key Takeaways

  • The gaming community — encompassing competitive, casual, and mobile gamers — represents a large, structurally underutilized talent pipeline for cybersecurity, with traits including adaptability, strategic thinking, persistence, and comfort with rapid skill acquisition.
  • Existing security industry practices — bug bounties, CTF events, named threat actor personas — are already gamified; recruiting from gaming communities extends a cultural alignment that already exists.
  • 46% of US gamers are female versus 30% of the cybersecurity workforce, making gaming-community outreach a concrete lever for improving gender diversity in the field.
  • Leaders who manage gamers effectively must design explicit career progression — structured quest lines with clear milestones — or risk losing the same motivation that makes gamers high performers.
  • AI security analysts that triage 100% of alerts and auto-decision more than half of them free human analysts to focus on complex, judgment-intensive investigations, creating a model where AI and human skills are complementary rather than competitive.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Radolec's gamer-to-security pipeline argument is not groundbreaking, but it is executed well and backed by a real operational story against Scattered Spider that earns its keep. The demographic point — 46% of gamers are women, 30% of the security workforce is women — is the sharpest insight in the talk and one of the most underused arguments for a talent diversity approach Zero has heard at RSA in years.

Heather Calloway (CISO) — WEAK

Varonis argues that the gaming population — 46% female versus 30% of the cybersecurity workforce, with natural adversarial problem-solving instincts — represents an untapped talent pipeline. Quest-line career development model proposed. AI now handles 50%+ of alert triage.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025