Chris Krebs’ clearance is gone? Good riddance! To me, this cracks the wall of denial he and CISA built around the 2020 U.S. elections. Their actions—or lack thereof—and the deafening silence of our cybersecurity community didn’t just undermine an election; they shattered the foundations of a field I’ve dedicated nearly four decades to.
Before 2020
My journey began in 1987 at age 18, serving in the Israeli Defense Forces and cutting my teeth on systems that demanded protection. From there, I climbed the ranks—overseeing regional security for a pharmaceutical giant, managing cryptography at one of Europe’s key clearing banks, manager in a huge consulting firm, and head of security of a major UK bank. I even served as a director for ISACA’s London branch—an organization renowned for its ethics and rigorous standards. For me, information security wasn’t just a job; it was a mission to safeguard the systems that keep our world running.
The election
Then came 2020. The U.S. election wasn’t just another political event—it was a stress test for every principle I held dear. In our field, we rely on three core pillars: Confidentiality, Integrity, and Availability. Yet there’s a vital fourth pillar that’s often overlooked: Authenticity. With mail-in ballots surging due to the pandemic, authenticity became the weak link. How do you verify the voter behind a ballot? How do you stop fake or improperly validated ballots from tainting the process? Add the inherent flaws in electronic voting systems, and the risks were screaming at us. Yet when I sounded the alarm, I met chilling silence.
The silence
I couldn’t believe it. Despite mounting reports of security incidents, compromised systems, and shaky processes, trusted bodies like ISACA stayed mute. Colleagues known for their candor went quiet. As someone who grew up in the scrappy, truth-driven hacker community, I felt betrayed. I reached out everywhere—emails, social media—but all I received were warnings: “You’re torching your career. Take it down.” I eventually removed my posts from my LinkedIn profile, but the damage was done—to my faith in our community.
Why the Silence?
It’s simple: in cybersecurity, unless you’re a black hat hacker, you typically end up working for governments, corporations, or solution providers. Governments and corporations prize loyalty over truth and favor stability over change, while solution providers depend on these institutions to buy their products and do their best that their employees will avoid making any controversial statement.
Bad assessments
Modern risk assessment methodologies like FAIR (Factor Analysis of Information Risk), which quantify risks in financial terms, could have exposed the true threats. Instead, CISA clung to outdated methods that masked vulnerabilities and threats while projecting false confidence. This wasn’t a mere oversight—it was a deliberate choice to bury the truth. When Chris Krebs dared to call the 2020 election “the safest in U.S. history,” the overwhelming evidence contradicted him, yet everyone I knew simply accepted the false narrative.
Vaccine rollout prequel
The 2020 election was a chilling prelude to the COVID-19 vaccine rollout. In both cases, an official narrative of "safety" was aggressively pushed—by Krebs and CISA for the election, by health authorities for the vaccines. Dissenters were ridiculed by the mainstream media, threatened with professional ruin, and abandoned by their own communities. Yet, a key difference emerged: while only a small number of health professionals resisted the vaccine claims, an even smaller fraction of cybersecurity experts challenged the election security narrative. This left me profoundly alone, as one of the very few in my field willing to uphold the truth.
Paying the price
That choice crushed me. By December 2020 I felt as if I was shouting into a void. Then, in July 2021, after I exposed Pfizer’s murky supply contracts online under #PfizerLeak, the backlash hit hard. My 34-year career was nearly destroyed. But I don’t regret it. Truth isn’t negotiable.
It's going to get worse
The fallout continues. By 2024, negligent practices have only heightened the risks. With advances in technology like AI, detecting forged signatures—and ensuring authentic votes—has now become even more challenging. As technology evolves, the task of detecting forgeries and ensuring authentic voting only gets tougher. Without robust risk assessments like FAIR and strong risk management measures, these threats will likely materialize.
The Fear Factor
Perhaps the real reason FAIR isn’t widely implemented is fear: it could expose electronic voting as too risky, potentially leading to the conclusion that such systems should be avoided altogether. By clinging to outdated risk assessment methods, stakeholders sidestep reality and preserve a political agenda that weakens voting integrity for their own control.
What to do now?
Revoking Krebs’ security clearance isn’t the end—it’s a wake-up call. It demands that we confront CISA’s failures in 2020 and acknowledge our community’s silence. I’m ready to assist pro bono in any investigation or provide consultancy on election risk management. We cannot afford to bury this truth any longer. Our profession’s integrity—and the future of free societies all around the world—hangs in the balance.
Ehden Biber
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.