Bobmojis, Bobbleheads, and Hardware Keys: How the Democratic National Committee Rebuilt Its Security After a Russian Hack

Two security chiefs who ran the DNC's defences back-to-back told Black Hat 2026 how they turned a politically focused, budget-constrained organisation into one where the chair personally called staff who skipped security enrolment.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge overhead photo of an unbranded modern smartphone on a deep slate surface, a subtle illuminated checkpoint barrier graphic implied by a s
Share

Key points

  • The Democratic National Committee (DNC) hired its first dedicated security chief in 2018, two years after Russian state hackers broke into its systems in 2016.
  • Bob Lord, the DNC's first chief security officer, replaced ageing Windows computers with Chromebooks to cut costs and shrink the number of ways attackers could get in.
  • Lord rolled out hardware security keys, small physical devices staff plug in to prove their identity, to the entire organisation before leaving the role in 2022.
  • DNC chairman Tom Perez personally phoned staff who missed the deadline to register their security keys, and every single one enrolled within days.
  • Steve Tran, Lord's successor and now chief information security officer at Lyuno, built on that foundation with cloud security upgrades and a formal security risk committee.

The Democratic National Committee is not a bank or a hospital. Its core job is winning elections. Security, as current DNC security chief Steve Tran put it at Black Hat USA 2026 in Las Vegas last week, is not the point. It just has to work anyway.

That framing matters, because the advice Lord and Tran shared at the conference translates directly to any organisation where security competes with every other priority for attention and money.

How did the DNC get here in the first place?

Russian state hackers broke into DNC systems in 2016, in an intrusion that became one of the most scrutinised breaches in American political history. Two years later, the party hired Bob Lord as its first ever chief security officer, a role that had never existed there before.

Lord, now an independent consultant, faced the classic starting position: limited budget, aging equipment, and a workforce whose job was politics, not passwords.

His answer to the equipment problem was counterintuitive. He scrapped the organisation's old Windows computers and switched staff to Chromebooks, the stripped-back laptops made by Google. Chromebooks are cheaper than replacing Windows machines, and they give attackers far fewer footholds. The organisation's existing Windows server infrastructure, specifically its Active Directory controller (the system that manages who can log in to what), was, in Lord's words, "an attack magnet." Getting rid of it removed an entire class of risk.

Tran, who took over the CSO role in 2022 and was sceptical of the Chromebook decision at first, admitted Lord proved him wrong.

What did "getting everyone enrolled" actually take?

Hardware security keys are small physical tokens, roughly the size of a USB thumb drive, that staff plug into a laptop or tap against a phone to confirm their identity. They are significantly harder for criminals to defeat than a text-message code, because a fake website cannot intercept a physical object.

Getting an entire organisation to adopt them is, as Tran put it to Lord directly during the session, "the hardest part."

DNC chairman Tom Perez made it non-negotiable. He gave the security team the first ten minutes of every all-staff meeting. When a deadline passed and some employees still had not registered their keys, Perez did not send a reminder email. He called their personal mobile phones himself. Every straggler enrolled within days.

"That's not executive buy-in or advocacy," Lord said. "That's co-ownership."

Should organisations outside politics care about any of this?

Yes. The tactical details map onto problems most workplaces recognise.

Lord skipped email scanning software not out of negligence but by design. His reasoning: by the time a malicious email lands in an inbox, the battle is already partly lost. It is more effective to build habits that stop an attack at the moment a criminal tries to get a real person to install something or hand over a password. That approach, training people to resist social engineering (meaning scams that manipulate people rather than hack machines), is harder to measure than a software filter but harder for attackers to route around.

Tran inherited those habits and spent his tenure working on the greyer judgement calls Lord's strong foundations made possible.

For customers, members, or donors of any politically affiliated organisation, the practical takeaway is the same as it is after any breach story. If you receive an unexpected message claiming to be from an organisation you support, asking you to click something or confirm your details, treat it with suspicion and contact the organisation directly through a number or address you already know.

Milestone Detail
2016 Russian state hackers break into DNC systems
2018 Bob Lord hired as DNC's first chief security officer
2018-2022 Chromebook rollout, hardware security key deployment, security culture programme
2022 Steve Tran succeeds Lord as DNC CSO
2022 onward Cloud security upgrade, knowledge management portal, security risk committee added
2026 Lord and Tran present lessons at Black Hat USA, Las Vegas

The session was first reported by Dark Reading. Lord's central lesson for any incoming security leader was blunt: "As an executive coming into the organisation, expect the unexpected."

© 2026 Threat Vectr