Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack

Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 5 min read
A conference room table with security personnel reviewing threat assessments and hardware security keys spread across documents, with Democratic National Commit
Share

Key points

  • The Democratic National Committee (DNC) hired its first dedicated security chief in 2018, two years after Russian state hackers broke into its systems in 2016.
  • Bob Lord, the DNC's first chief security officer, replaced ageing Windows computers with Chromebooks to cut costs and reduce the ways attackers could get in.
  • Lord rolled out hardware security keys, small physical devices staff plug in to prove their identity, to the entire organisation before leaving the role in 2022.
  • DNC chairman Tom Perez personally phoned staff who missed the deadline to register their security keys, and every single one enrolled immediately after his call.
  • Steve Tran, Lord's successor, built on that foundation with cloud security upgrades and a formal security risk committee, and now serves as chief information security officer at lyuno.

The Democratic National Committee is not a bank or a hospital. Its core job is winning elections. Security, as DNC security chief Steve Tran put it at Black Hat USA 2026 in Las Vegas last week, is not the point. It just has to work anyway.

That framing matters, because the lessons Lord and Tran shared at the conference translate directly to any organisation where security competes with every other priority for attention and money.

How did the DNC get here in the first place?

Russian state hackers broke into DNC systems in 2016, in an intrusion that became one of the most scrutinised breaches in American political history. Two years later, the party hired Bob Lord as its first ever chief security officer, a role that had never existed there before.

Lord, now a consultant at Lord Consulting, faced the classic starting position: a tight budget and a workforce whose job was politics, not passwords. He also plastered stickers of his own face above urinals, in bathroom stalls and on mirrors, so staff would see a security reminder every time they washed their hands. He called them Bobmojis.

His answer to the equipment problem was counterintuitive. He scrapped old Windows computers and switched staff to Chromebooks, the stripped-back laptops made by Google. Chromebooks cost less than refreshing Windows machines, and they give attackers fewer footholds. The organisation's existing Windows server infrastructure, specifically its Active Directory controller (the system that manages who can log in to what), was, in Lord's words, "an attack magnet." Removing it cut an entire class of risk.

Tran, who took over the CSO role in 2022 and was sceptical of the Chromebook decision at first, admitted Lord proved him wrong.

What did "getting everyone enrolled" actually take?

Hardware security keys are small physical tokens, roughly the size of a USB thumb drive, that staff plug into a laptop or tap against a phone to confirm their identity. A fake website cannot intercept a physical object, which makes them far harder for criminals to defeat than a text-message code.

Getting an entire organisation to adopt them is, as Tran put it to Lord directly during the session, "the hardest part."

DNC chairman Tom Perez made it non-negotiable. He gave the security team the first ten minutes of every all-staff meeting. When a deadline passed and some employees still had not registered their keys, Perez did not send a reminder email. He called their personal mobile phones himself. They enrolled immediately.

"That's not executive buy-in or advocacy," Lord said. "That's co-ownership."

The gap between those two things is the real lesson here. Advocacy is a memo. Co-ownership is the chairman's voice on your phone at 8 a.m.

Should organisations outside politics care about any of this?

Yes. The tactical details map onto problems most workplaces recognise.

Lord skipped email scanning software not out of negligence but by design. His reasoning: by the time a malicious email lands in an inbox, the battle is already partly lost. Building habits that stop an attack at the moment a criminal tries to get a real person to install something or hand over a password is more effective. That approach, training people to resist social engineering (scams that manipulate people rather than hack machines), is harder to measure than a software filter but harder for attackers to route around.

Tran inherited those habits and spent his tenure on the greyer judgement calls Lord's foundations made possible. He added a knowledge management portal and a security risk committee, and shifted the programme toward cloud security. Our earlier story on what drives security chiefs to the edge of quitting found that executives who do not understand the problem are a primary source of burnout; the DNC model points the other way.

For donors or members of any politically affiliated organisation: if you receive an unexpected message claiming to be from a group you support, asking you to click something or confirm your details, contact the organisation directly through a number or address you already know.

Milestone Detail
2016 Russian state hackers break into DNC systems
2018 Bob Lord hired as DNC's first chief security officer
2018-2022 Chromebook rollout, hardware security key deployment, Bobmoji security culture programme
2022 Steve Tran succeeds Lord as DNC CSO
2022 onward Cloud security upgrade, knowledge management portal, security risk committee added
2026 Lord and Tran present lessons at Black Hat USA, Las Vegas

The session was first reported by Dark Reading. Lord's central lesson for any incoming security leader was blunt: "As an executive coming into the organisation, expect the unexpected."

© 2026 Threat Vectr