From Modded Game Controllers to IBM X-Force Red: The Chris Thompson Arc
A teenage hardware tinkerer grows up to run one of the most recognizable offensive-security brands in enterprise tech, then leaves to build something new.

Key points
- Chris Thompson began by modifying game controllers as a teenager before eventually founding IBM's X-Force Red
- X-Force Red is IBM's dedicated red-team unit, hired to actively break client defenses rather than advise on them
- Thompson has since co-founded RemoteThreat, a new offensive-security firm
- His career illustrates a recurring industry pattern: deep technical instincts built young, institutionalized at scale, then taken independent
- Whether RemoteThreat can convert that pedigree into revenue is the real question
Where does a red-team founder come from?
Chris Thompson didn't start with a certification. He started by breaking things that weren't supposed to be broken: game controllers, rewired for advantages the manufacturer never intended. It's an origin story that sounds apocryphal until you realize how many serious offensive-security practitioners describe a nearly identical childhood.
The throughline from that early curiosity to founding X-Force Red isn't as long as it looks. X-Force Red is IBM's dedicated red-team unit, the group companies call when they want someone to actually break their defenses rather than theorize about it. Thompson built that practice and led it, spending years operationalizing adversarial thinking at enterprise scale.
That's harder than it sounds. Red-teaming a financial institution is one thing. Building a team, a methodology, a sales motion that can run engagements across industries and geographies simultaneously, that's organizational work as much as technical work. The skill set stops overlapping with pure hacking fairly quickly.
Thompson has since moved on, co-founding RemoteThreat, a newer outfit whose name suggests it isn't pivoting into compliance consulting.
Should you read anything into the timing?
His trajectory illustrates a pattern the industry keeps producing: practitioners who develop deep technical instincts early, translate those into institutional programs, then exit to rebuild with fewer constraints. The IBM brand opened doors. It also came with IBM's procurement cycles, IBM's legal review, IBM's everything. We first covered X-Force Red's work on 30 June 2026, around the time AI-assisted offensive tooling started raising pointed questions about what red teams are actually for.
The game-controller detail is worth sitting with. Security educators have argued for decades about whether hacking is a mindset or a skill set. Thompson's story suggests the mindset comes first and the skills follow. What distinguishes people who end up running red teams isn't the tools they learned first but the disposition to look at a closed system and immediately wonder what happens if you push somewhere you're not supposed to.
Should you worry about the crowded boutique market?
Whether RemoteThreat becomes a meaningful player is genuinely open. The offensive-security space is full of credentialed boutiques. A co-founder with Thompson's background is a real differentiator, not a marketing claim. But differentiation and revenue are different problems, and right now machine-speed vulnerability discovery is reshaping what offensive teams are even priced to do. That's the market RemoteThreat is walking into.



