Hunter Storm is the Founder of Black Star Institute, a CISO, President, Advisory Board Member, SOC Black Ops Team Member, Principal Security Architect, Systems Architect, QED‑C TAC Relationship Leader, and Cyber‑Physical‑Psychological Hybrid Threat Expert with decades of experience across global Fortune 100 enterprises and critical‑infrastructure environments. She is a federal whistleblower to the Securities and Exchange Commission (SEC) regarding Wells Fargo, an experience that informs her work on institutional accountability and systemic failure.
She is the originator of the field of Human‑Layer Security and multiple adjacent disciplines through her foundational framework, Hacking Humans: The Ports and Services Model of Social Engineering (1994–2007), which established system‑level metaphors that now underpin modern socio‑technical security practice. She is also the originator of Hybrid Threat Modeling and multiple other disciplines and fields that arose from navigating two decades of hybrid threat environments in real-world operations.
Hunter Storm is also the creator of The Storm Project: AI, Cybersecurity, Quantum, and the Future of Intelligence(2023-2026), a long‑horizon research initiative examining the convergence of emerging technologies, governance, and hybrid threat dynamics. Her work spans AI, cybersecurity, quantum technologies, platform governance, and systemic risk across complex global socio‑technical systems.
She contributes to ANSI X9, FS‑ISAC, NIST, and QED‑C, shaping standards, strategy, and policy in cybersecurity, financial systems, and post‑quantum cryptography (PQC). Her research, frameworks, and advisory work place her among the small group of practitioners influencing the United States’ quantum and post‑quantum governance landscape from within the ecosystem.
Code Red Case Study
A historical walkthrough showing how every cybersecurity role works together — and why this example still matters today.
Why Hunter Storm Used This Historic Example
Students need to understand why Hunter Storm chose this incident as the example for her PBS Jobs Explained! appearance, not just what happened. She selected Code Red because:
It was the first major network‑wide incident since the Morris Worm.
It demonstrated true internet‑scale propagation, unlike the ILOVEYOU virus, which was destructive but not self‑replicating in the same way.
It was a moment when the industry realized that networked systems could fail globally, not just locally.
Hunter Storm personally performed Code Red remediation at Charles Schwab — giving her firsthand operational insight.
It’s easier to teach from a single compromised server than from a modern cloud environment with thousands of ephemeral assets.
It provides a clean, simple, visual way to show how every role in cybersecurity participates in a real incident.
And most importantly: No cybersecurity training program teaches this. Not bootcamps. Not degree programs. Not certifications. Not online courses. This case study gives students the context they’ve been missing.
The Code Red Lifecycle (Simplified)
This is the version Hunter Storm used on PBS — the one that fits on a whiteboard and makes sense to beginners.
Detection (Operations)
SOC sees anomalous traffic
IDS/IPS alerts
IR confirms worm‑like behavior
Forensics (Operations)
Disk + memory analysis
Log correlation
Root cause identified
Containment & Remediation (Operations)
Patch applied
System rebuilt
Network blocks implemented
Enterprise Response (Business & Support)
PM coordinates patch rollout
BA documents impact
Technical writer creates remediation SOP
Communications team notifies stakeholders
Risk Assessment (GRC)
Exposure evaluated
Business impact assessed
Policies updated
Vendor risk reviewed
Executive Reporting (Business/GRC)
Clear, non‑technical summary delivered
Recommendations made
Long‑term mitigation planned
How This Maps to the Three‑Column Model
This is the part that students never see in school.
Column 1 — Operations
Handles:
Detection
Investigation
Forensics
Remediation
Column 2 — Governance, Risk & Compliance
Handles:
Risk assessment
Policy updates
Audit trails
Vendor evaluation
Column 3 — Business & Support Handles:
Project management
Communication
Documentation
Executive reporting
This shows students that cybersecurity is not just “hackers vs. defenders.” It’s an ecosystem.
Why This Example Still Matters in 2026
Even though Code Red is old, the principles are timeless:
Worm propagation → today’s ransomware lateral movement
Patch management → still a top failure point
Log correlation → still foundational
Cross‑team coordination → still required
Executive reporting → still essential
Policy updates → still mandatory
Risk assessment → still the backbone of governance
And the biggest reason: It’s easier to understand one infected server than an entire cloud environment. Students need a simple, concrete example before they can understand distributed systems.
What Students Should Learn From This
Cybersecurity is a team sport
Every role matters
Incidents touch every part of the organization
You don’t need to be technical to contribute
You can start in one column and move to another
Real‑world incidents are the best teachers
History repeats itself — the patterns haven’t changed