Threat Picture
Latest Cybersecurity News

Lesley Carhart: Incident Response Where Computers Meet Industry

Power plants and factory controls bring different problems from office networks. Carhart's work puts those differences at the center of security.
By Charles Joseph · Updated
Share
Share
Copy URL

When a hacker gets inside a power plant, a water utility or a factory, the response team that shows up often has Lesley Carhart at the front of it.

She's the technical director of industrial incident response at Dragos, an instructor of the SANS course on spotting intruders in control systems, and, to more than 100,000 people online, simply hacks4pancakes: the person who answers the career questions nobody else will.

But the woman who now guards the grid spent years begging to be let into the field at all. Thirty phone calls, three degrees and one retirement later, she's starting over on the other side of the world.

Lesley Carhart at a Glance

  • A Chicago native, Carhart was programming in BASIC at nine and writing SQL for a web development firm at 15.
  • She served as a senior non-commissioned officer in the US Air Force Reserves, earned a network engineering degree from DePaul University and spent years in IT before anyone could tell her how to become a forensic examiner.
  • At Motorola Solutions she led the incident response team that watched over enterprise and public-safety radio customers.
  • Her 2015 blog series "Starting an InfoSec Career: The Megamix" and the "Ask Lesley" column that followed made her the industry's unofficial career counselor.
  • She joined the industrial security firm Dragos, spent four years as a principal incident responder and became its technical director of industrial incident response.
  • When a hacker raised the lye level at a Florida water plant in 2021, she was the expert the Associated Press called.
  • In March 2020 she threw together PancakesCon, a free online conference where every talk is half security and half hobby. More than 3,000 people registered.
  • DEF CON named her Hacker of the Year, and SANS gave her its Difference Makers Lifetime Achievement Award.
  • In 2025 she moved from Chicago to Melbourne to help defend Australia's critical infrastructure, and in 2026 she co-wrote a 16,000-word paper on worms still crawling through factory networks.
Sponsored

The Life of Lesley Carhart

Carhart's Early Years

Lesley Carhart grew up in Chicago and started programming in BASIC at the age of nine. By 15 a web development firm was paying her to write SQL.

She wanted to be a digital detective before the job existed. "When I originally wanted to get into computer forensics, I called something like 30 police departments and colleges for advice, but nobody had heard of the field yet," she wrote in 2015.

So she took the long way: years in IT, a bachelor's degree in network engineering from DePaul University, and service as a senior non-commissioned officer in the US Air Force Reserves, from which she's since retired. The military, she's said, is part of the reason she holds three degrees.

Finding Incident Response

The field she'd been looking for turned out to be called incident response: working out how computers and networks were hacked, then cleaning up afterward.

It suited her. "I'm wired to manage chaos and crises, so incident response is my dream job," she says in her SANS biography.

At Motorola Solutions she rose to lead the incident response team, handling security monitoring, forensics and response for enterprise customers and the public-safety radio systems that police and fire departments depend on. By 2015 she counted about eight years in security on top of roughly 15 in IT, with a team of responders reporting to her.

Sponsored

Hacks for Pancakes

Her handle came from the conference circuit. Carhart preferred volunteering and speaking at small community events, the kind that pay their speakers and staff in food, so she became hacks4pancakes.

In October 2015 she began publishing "Starting an InfoSec Career: The Megamix" on her blog, Tisiphone.net, a seven-chapter guide that ran through August 2016 and became required reading for people trying to break in. An "Ask Lesley" advice column followed in 2017, along with the résumé and interview clinics she ran at conferences.

Her following grew past 100,000 on Twitter. At KringleCon in 2019 she gave a talk titled "Over 90,000: Ups and Downs of my InfoSec Twitter Journey," which tells you the number had become a story in itself.

Into the Machines

Carhart moved to Dragos, the industrial cybersecurity company, to hunt threats inside the operational technology networks that run utilities, manufacturing and transportation. By 2019 she was its principal threat hunter, and she spent four years as a principal incident responder before being promoted to technical director of industrial incident response.

The work is less glamorous than it sounds. Her team handles commodity malware, state actors and insider cases in networks full of decades-old Windows machines that can't simply be patched or thrown away.

She also began teaching SANS ICS515, the course on finding and evicting intruders from industrial control systems.

The Oldsmar Water Plant

On February 5, 2021, an intruder got into the control system of the water treatment plant in Oldsmar, Florida, and briefly raised the level of sodium hydroxide, better known as lye, by a factor of 100. A supervisor watching a plant console saw the cursor move across the screen and reversed the change at once, and nobody was harmed.

The Associated Press called Carhart, then Dragos's principal incident responder. "In the industry, we were all expecting this to happen," she said. "We have known for a long time that municipal water utilities are extremely underfunded and under-resourced, and that makes them a soft target for cyber attacks."

Some of the small and mid-sized utilities she dealt with, she added, had no dedicated security staff at all.

Sponsored

PancakesCon

When COVID-19 lockdowns began in March 2020, Carhart built a conference in a matter of days. PancakesCon ran on March 22, 2020, as a free online event with a twist: each 40-minute talk was half introductory security content and half hobby, with titles like "Windows Forensics Basics & Homemade Pickles!"

She received 153 talk submissions, more than 3,000 people registered, and over 1,000 competed in the capture-the-flag. "The objective is to allow people to learn some new skills (infosec career-wise, and not) while they are trapped in quarantine at home or in isolation," she wrote.

The conference outlived the quarantine. PancakesCon 6 streamed free on YouTube on September 21, 2025.

Hacker of the Year

Recognition piled up. DEF CON named her Hacker of the Year, SANS gave her its Difference Makers Lifetime Achievement Award, and SC Magazine listed her as a "Power Player."

In August 2023 she keynoted Blue Team Con with a talk called "We're All Scared, Too: 10 Years of Lessons from Cybersecurity Mentorship."

Off the clock, she holds a third-degree black belt in Tang Soo Do, trains in Arnis and Kung Fu, and volunteers as a martial arts coach for pre-teens. Her own biography adds rowing and "a nice D&D game."

Starting Over in Melbourne

In April 2025 Carhart announced her "big move to Australia." She gave her last North American talks in Halifax, Milwaukee and Chicago, landed in Melbourne and spoke there the day after she arrived.

"I'm kind of starting my life over across the world and there isn't a ton of certainty for my future," she wrote. "I really want to bring my best to help secure Australian critical infrastructure."

By 2026 she was doing exactly that, still with Dragos. In July 2026 she and Jan Hoff of Dragos Germany debuted a 16,000-word academic paper on handling Conficker and other legacy worm infections in operational technology at OTCEP in Singapore, with a CyberCon Melbourne presentation to follow in October.

Sponsored

Lesley Carhart: Still Hacking for Pancakes

Carhart's story is a reminder that the people guarding the grid aren't born in the job. She spent years being told the field didn't exist, then built the on-ramp she never had, one blog chapter and one résumé clinic at a time.

She now leads industrial incident response from Melbourne, teaches the SANS course on evicting intruders from control systems, and still runs a free conference where half of every talk might be about homemade pickles.

Thirty phone calls went unanswered. She ended up answering everyone else's.

QUOTE:

"Amateurs hack systems, professionals hack people."