The Security Chiefs Who Finally Get to Tell Their Stories

A new documentary series lets cybersecurity leaders speak openly about hacks, burnout, and the human cost of keeping organisations safe. One episode alone involves $2 million stolen in a single phone call.

ThreatVectr Newsdesk· 4 min read
A heavy oak boardroom table viewed from a low angle, scattered with unsigned contract pages and a single ballpoint pen, harsh fluorescent overhead lighting cast
Share

Key points

  • Red Mirror Studios launched an 11-episode documentary series called "Declassified" on 28 July 2026, days before the Black Hat USA security conference in Las Vegas.
  • The series features 11 current and former chief information security officers (CISOs) from enterprise, government, and critical infrastructure organisations speaking publicly about breaches and burnout for the first time.
  • In one episode, Chainguard CISO John Sapp Jr. describes criminals stealing $2 million from a manufacturing company through a fake bank phone call.
  • Former healthcare CISO Tyson Kopczynski says the stress of protecting patients with almost no budget pushed him to leave the industry entirely.
  • The series is produced independently after the original project lost backing when investors demanded editorial changes the founders refused to make.

The people responsible for keeping your hospital, your bank, and your utility company safe from hackers are, almost by definition, not allowed to talk about what they do. When a breach happens, lawyers step in, statements get scrubbed, and the actual story stays behind closed doors. A new documentary series wants to change that.

"Declassified" is an 11-episode series produced by Red Mirror Studios, an independent film company focused on cybersecurity. The first episode aired on 28 July 2026. It was filmed in March at the RSAC Conference, one of the biggest annual security industry gatherings, held in San Francisco.

How did a $2 million theft happen in a single phone call?

Criminals stole the money using social engineering, which means they manipulated a real person into handing over access rather than breaking through any technical barrier. A bank that John Sapp Jr. worked with was adding multi-factor authentication, meaning an extra identity check beyond a password, when the criminals spotted an opportunity. They called someone and pretended to be the bank. The call sounded legitimate. Two million dollars left the account.

Sapp was CISO, meaning the top security executive, at a global medical device manufacturer with offices in Brazil when the incident happened. He now holds the same role at cloud security company Chainguard. He appears in the first episode of "Declassified" and spoke to Dark Reading about why he decided to go on camera after years of silence.

"I think it's a healing opportunity because we had to carry this stuff bottled up inside of us for so long," Sapp said.

Why don't security leaders speak out more often?

Two reasons, mainly. First, most of what a CISO knows is legally confidential. Second, speaking openly about a past breach can make it harder to get the next job. The CISO role has only existed as a formal position for about 25 years, and its norms are still being written.

Typson Kopczynski, a former CISO in finance and later in healthcare, hit his limit and left the industry entirely. Healthcare organisations typically run on tight budgets while protecting some of the most sensitive personal data imaginable, and attack fallout in that sector can affect patient care directly. The gap between the expectation and the resources available was, in his words, unbearable.

He is now a partner at White Rabbit VC, a venture capital firm, and joined the series partly to explain what the job actually looks like from the inside. "We talk in our own language typically," he said. "We're not good at telling stories because either we can't tell them because we're not allowed to, or we don't have the language to speak in those terms."

The failure mode here is obvious: when the people defending critical systems cannot describe what they do, the public cannot advocate for the resources those defenders need.

The series itself nearly never happened. Red Mirror founders Danielle Lewan and Clint Howard II previously worked on a separate project, "CISO: The Worst Job I Ever Wanted," while Lewan was director of global marketing at security company Nagomi Security. Investors later demanded they drop certain participants and rename the series, fearing the original title would put people off entering the CISO role. Lewan refused. The investors had the final say. Lewan and Howard walked.

They found new backers who shared their commitment to unedited stories and built Red Mirror Studios around that principle.

In practice, the audience for a series like this is not just other security professionals. Sapp makes the point plainly: if ordinary people understood why strong passwords and scepticism toward unexpected phone calls matter, some of the incidents described in the series would never have happened.

If your employer sends a breach notification letter, or if you get an unexpected call from your bank asking you to confirm anything at all, hang up and call the bank's published number back yourself.

© 2026 Threat Vectr