Lessons Learned from Doing Things the Hard Way… Every… Single… F'n... Time.

Rob Fuller (VP Cybersecurity & Digital Risk)

SAINTCON 2025 · Day 3 · Main Track 2

Overview

In his SAINTCON talk, "Lessons Learned from Doing Things the Hard Way… Every… Single… F'n... Time.", Rob Fuller, VP Cybersecurity & Digital Risk, delivers a refreshingly candid and introspective presentation that deviates from typical technical deep dives. Instead, Fuller shares a series of deeply personal and professional anecdotes, recounting pivotal moments where he learned critical lessons through significant struggle and challenge. The talk serves as a guide for navigating the cybersecurity industry, not through specific exploits or defensive strategies, but through cultivating resilience, embracing failure, and fostering a robust mindset for continuous growth and leadership.

Watch on YouTube

Visual summary for Lessons Learned from Doing Things the Hard Way… Every… Single… F'n... Time. by Rob Fuller
Visual summary for Lessons Learned from Doing Things the Hard Way… Every… Single… F'n... Time. by Rob Fuller

Key moments

  1. 0:00 Introduction: Doing things the hard way, lessons learned.
  2. 2:00 Request for feedback and speaker's diverse background.
  3. 4:40 First lesson: No one cares about your goals as much as you.
  4. 7:00 Fired from US Senate: A story of determination.
  5. 8:30 Couch to Career philosophy: Apply broadly, show determination.

Lessons Learned from Doing Things the Hard Way… Every… Single… F'n... Time.

Speakers: Rob Fuller, VP Cybersecurity & Digital Risk

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=2sK8YuqCzM8

Overview

In his SAINTCON talk, "Lessons Learned from Doing Things the Hard Way… Every… Single… F'n... Time.", Rob Fuller, VP Cybersecurity & Digital Risk, delivers a refreshingly candid and introspective presentation that deviates from typical technical deep dives. Instead, Fuller shares a series of deeply personal and professional anecdotes, recounting pivotal moments where he learned critical lessons through significant struggle and challenge. The talk serves as a guide for navigating the cybersecurity industry, not through specific exploits or defensive strategies, but through cultivating resilience, embracing failure, and fostering a robust mindset for continuous growth and leadership.

Fuller’s presentation is a powerful reminder that success in cybersecurity, and indeed in any demanding field, often hinges on more than just technical prowess. It emphasizes the importance of personal drive, effective communication, team collaboration, and the willingness to challenge one’s own assumptions. By sharing his "traumas" and "deep stories," Fuller aims to transfer hard-won wisdom to his audience, encouraging them to find "an easier path" by learning from his experiences. This talk is particularly relevant for security professionals at all career stages looking to refine their approach to work, leadership, and personal development within a rapidly evolving industry.

Background

▶ Watch: Introduction: Doing things the hard way, lessons learned. (0:00)

Rob Fuller's journey in cybersecurity spans two decades, beginning around 2005, following an eight-year stint in the Marine Corps (MOS 1371). This diverse background has equipped him with a unique perspective, blending military discipline with the innovative spirit of hacking. As a co-founder of Nova Hackers, a senior technical advisor for HBO's Silicon Valley, and a participant in the National CCDC, Fuller has accumulated a wealth of experience across various facets of the tech and security landscape. His expertise touches upon areas like Windows, Active Directory, and red teaming, though his recent passion has shifted towards leadership and introspection.

The talk emerges from Fuller's observation of the cybersecurity industry's evolution, noting both its amazing advancements and the persistent "bumps and bruises" that often accompany growth. He candidly admits to a personal predisposition for "doing things the hard way," a trait that has inadvertently forged many of the lessons he shares. Fuller's intention is not to present a "boohoo" narrative, acknowledging his privileged experiences, but rather to offer actionable insights derived from his struggles. He actively solicits "brutal" feedback, underscoring his commitment to continuous improvement—a foundational theme echoed throughout his presentation. This willingness to be vulnerable and seek critique sets the tone for a talk focused on genuine learning and growth.

Key Findings

▶ Watch: Request for feedback and speaker's diverse background. (2:00)

While not presenting technical "findings" in the traditional sense, Rob Fuller's talk unveils several profound principles and lessons learned through his "hard way" experiences. These constitute the core contributions of his presentation, offering a framework for personal and professional growth within the cybersecurity domain:

  1. Unwavering Personal Drive is Paramount: Fuller's foundational lesson, learned at age 15 working at an Arco gas station, is that "no one cares as much about you as much as you do about your goals." He recounts his father's insistence on applying for a job daily for 30 days until he was hired, a lesson in relentless pursuit. This ethos was powerfully reinforced after being fired from a position at the United States Senate. Instead of despair, his wife recognized "determination" in his face. Fuller then applied to 300 places and completed 100 interviews in just two weeks, securing a new job by the following Monday. He critiques the common excuse of job scarcity, highlighting that many are unwilling to take "any job," even a greeter at Walmart, while waiting for "senior red teaming positions." This principle underscores the necessity of radical self-reliance and an unyielding work ethic, encapsulated in his later "Fuck you, run faster" mantra.
  1. Trust Your Team and Let Go of Ego: Drawing from his Marine Corps experience, Fuller emphasizes that "you do not need to be in the room that it happened." He shares a story of discovering a "really bad incident" as a junior analyst and, driven by an "egotistical" curiosity, pushed for details from higher tiers. He eventually obtained information he shouldn't have and, critically, uploaded some of it to an "online tool" whose security he couldn't vouch for. This action risked compromising the entire investigation, led by Christopher Nut (then a corporal or sergeant), and resulted in Fuller receiving another "page 11" (non-judicial punishment), which involved cleaning bathrooms for six months. This traumatic experience taught him the importance of trusting the team, handing off responsibilities to those better equipped, and letting go of the need for hyper-fixation on every detail, especially when it could jeopardize sensitive operations.
  1. Leave Everyone and Everything Better Than You Found It: Expanding on the common adage of leaving a room better than you found it, Fuller applies this philosophy to all human interactions and environments. He learned this lesson the hard way in the Marine Corps during "field day" cleanups, where he resented picking up cigarette butts dropped by others. The constant answer from his superiors was "leave everywhere and everything better than you found it." He internalizes this as a call to teach, uplift, and contribute positively to every interaction and space, urging people to pick up "one thing that isn't yours" to collectively improve the world.
  1. Embrace the "Fuck You, Run Faster" Mindset: This provocative phrase, whispered to him by a First Sergeant during a grueling PFT (Physical Fitness Test) in Okinawa, Japan, became a powerful internal motivator. Initially a slow runner, struggling to meet the 23-minute requirement for a 3-mile run (achieving around 21:30), Fuller was pushed beyond his limits by the First Sergeant's relentless challenge. By the end of that PFT, he was at the front of the pack, having reduced his time significantly. This competitive drive, fueled by the internal voice, transformed his running ability, eventually leading him to achieve an 18-minute mile. Fuller applies this to his career, constantly striving to learn and improve when encountering "awesome talks on car hacking" or "RFID hacking," seeing it as a personal challenge to "learn all of it."
  1. Challenge All Assumptions and Be Curious, Not Judgmental: Fuller highlights the danger of preconceived notions, particularly about what constitutes a "successful" cybersecurity professional. He shares the surprising example of Matt Saburn, an "exceptionally smart appsec person" who "does not do a single lick of it outside of his job." Saburn has no home lab and doesn't even own a computer at home, yet is highly effective during work hours. This challenged Fuller's long-held assumption that success in hacking required 24/7 immersion. He advocates for the Ted Lasso quote: "Be curious, not judgmental," urging professionals to learn from everyone, regardless of their title or perceived expertise, recognizing that "every single person at every single desk in every single chair knows more than you about something." He vividly recalls being misled by "hackers" on IRC in the late 90s, who tricked him into repeatedly running init 6 on his Mandrake Linux machine, teaching him the early lessons of skepticism and the need to verify.
  1. Boundaries and Communicated Expectations are Essential: This lesson extends to both personal and professional relationships: "A boundary is a communicated respect. Unspoken expectations is premeditated resentment." Fuller illustrates this with a personal anecdote about his wife's frustration over him not taking out the trash at specific times. He realized that his wife had an unspoken expectation—a clean house before bed—which he was unknowingly failing to meet. Once this expectation was explicitly communicated, the resentment dissolved. He applies this to leadership, asserting that if a senior leader has an expectation of a manager but fails to communicate it, the leader is setting the manager "up for failure." This highlights the critical role of clear, explicit communication in fostering healthy, productive relationships and avoiding unnecessary conflict.
  1. There's No "Cheating" in Hacking (or Security): Fuller passionately argues against the adversarial "blue vs. red" mentality, stating, "you are both on the same team. Get over yourselves." He criticizes the notion that using common tools like RDP or Cobalt Strike in an engagement is "cheating." The goal, he asserts, is to make the company better. He advocates for "Attack Surface Reduction Engagements" (ASRs), which are white-boxed red team engagements where everyone knows you're coming. This approach, he argues, "speeds right past that whole I want to be invisible bull because who cares?" The focus should be on identifying and fixing root causes, not on maintaining stealth for stealth's sake. He insists that if a red team gets through undetected, or a blue team catches them easily, "You both suck at that point. That means neither of you are doing your job."
  1. Embrace Failure as the Ultimate Learning Tool: Fuller declares, "I love failure." He posits that if one succeeds, they learned nothing new; success only confirms existing knowledge. Failure, conversely, is the direct pathway to learning. He cherishes opportunities to be the "dumbest person in the room" because that's when he learns the most, challenging the common industry fear of appearing less intelligent. He shares a striking example of a failure where "putting certain DNS entries into an active directory domain controller" broke "13 factories," humorously noting, "Apparently, it's always DNS, right?" This massive failure, though impactful, provided invaluable lessons. He urges leaders and practitioners to become more comfortable with failure, recognizing its indispensable role in growth and innovation within the industry.

Technical Deep Dive

▶ Watch: First lesson: No one cares about your goals as much as you. (4:40)

While Rob Fuller explicitly states that his talk is "not a super technical talk" and apologizes for its lack of in-depth technical content, his professional background and occasional anecdotes do touch upon areas of technical relevance, albeit through the lens of lessons learned. Fuller's expertise lies in areas such as Windows, Active Directory, and red teaming, suggesting a foundational understanding of these systems and offensive security methodologies.

One notable technical anecdote illustrates a critical lesson about trust and operational security. During his time in the Marine Corps, Fuller, as a curious Tier 1 analyst, discovered a "really bad incident." Driven by an "egotistical" desire to be involved, he pushed for details from Tier 2 and Tier 3 teams. Once he obtained some information, he made the grave error of uploading it to an "online tool" to gain more insights, without understanding where the data would go or its potential implications. This action, he reflects, "could have blown the entire investigation completely." While he doesn't detail the specific incident, the "online tool," or the type of data, this highlights the profound risk of mishandling sensitive information and the importance of adhering to established protocols, especially when dealing with critical incidents.

Another technical failure he recounts involved breaking "13 factories" by "putting certain DNS entries into an active directory domain controller." This candid admission, followed by the quip, "Apparently, it's always DNS, right?", underscores the often-unforeseen and widespread impact of misconfigurations or errors within critical infrastructure components like Active Directory and DNS. While the talk doesn't delve into the specifics of the DNS entries or the Active Directory architecture involved, it serves as a powerful testament to the learning potential embedded in significant technical failures.

Fuller also briefly mentions tools and concepts like Metasploit and windebug when comparing his technical knowledge with a colleague named Joe. He notes his own extensive knowledge of Metasploit, a popular penetration testing framework, while acknowledging his limited understanding of windebug, a powerful Windows debugger often used in forensics and reverse engineering. These mentions, while not providing a deep dive, reinforce his broad exposure to both offensive and low-level system analysis tools, further contextualizing his "hacker ethos" and continuous learning philosophy. Ultimately, the technical elements in his talk serve as examples of the "hard way" experiences that shaped his non-technical, but equally crucial, career lessons.

Demo / Proof of Concept

▶ Watch: Fired from US Senate: A story of determination. (7:00)

This talk did not include any live demonstrations, proof-of-concept exploits, or technical walkthroughs. Rob Fuller's presentation was focused entirely on sharing personal anecdotes and career lessons rather than showcasing technical capabilities.

Defensive Implications

▶ Watch: Couch to Career philosophy: Apply broadly, show determination. (8:30)

Rob Fuller's talk, though not technically focused, offers profound defensive implications by addressing the mindset, communication, and collaborative structures crucial for effective cybersecurity. Defenders can glean several actionable insights from his "hard way" lessons:

  1. Foster True Red Team-Blue Team Collaboration: Fuller's insistence that "you are both on the same team" is a critical message for defensive operations. Organizations must move beyond an adversarial "blue vs. red" dynamic and cultivate a partnership where both teams work towards the shared goal of improving the company's security posture. This means red teams providing actionable, proven findings rather than theoretical "could-haves," and blue teams being open to learning from detected attacks. The concept of Attack Surface Reduction Engagements (ASRs), where white-box testing prioritizes root cause identification over stealth, is a practical application of this principle, allowing defenders to rapidly understand and mitigate vulnerabilities without the added complexity of a hidden adversary.
  1. Implement Clear Communication and Expectation Setting: Fuller’s lesson on "unspoken expectations" leading to "premeditated resentment" is directly applicable to defensive team leadership. Security leaders must explicitly communicate roles, responsibilities, performance expectations, and project goals to their teams. Ambiguity can lead to missed objectives, frustration, and a breakdown in trust. Establishing clear boundaries and ensuring mutual understanding within the security team, and with other business units, is paramount for efficient operations and incident response. This also extends to providing continuous leadership training for managers within security teams.
  1. Embrace Failure as a Learning Opportunity: Defenders often operate in high-stakes environments where failure can have significant consequences. Fuller's emphasis on loving failure because it signifies learning is vital. Security teams should cultivate a culture where post-incident reviews (PIRs) and post-mortems are truly blameless, focusing on systemic issues and lessons learned rather than individual culpability. This encourages transparency, enables the sharing of "hard way" experiences (like the Active Directory DNS entry failure), and fosters a continuous improvement cycle essential for adapting to evolving threats.
  1. Cultivate Relentless Personal Drive and Continuous Learning: The "Fuck you, run faster" mantra translates into a defensive strategy of continuous skill development and proactive threat intelligence. Individual defenders should take ownership of their professional growth, constantly seeking to learn new techniques, understand emerging threats, and master defensive tools. This includes pursuing certifications (like the MBA, CISSP, CISM, CISA Fuller pursued) and exploring new domains, even outside of direct job requirements. An organization with highly motivated, self-driven defenders is inherently more resilient.
  1. Promote Curiosity and Challenge Assumptions: Defenders must resist the urge to be judgmental about new tools, techniques, or even less conventional team members (like Matt Saburn, the appsec expert without a home lab). A curious mindset encourages exploring alternative defensive strategies, integrating diverse perspectives, and avoiding echo chambers. Questioning established security controls, architectural assumptions, and even vendor claims can lead to more robust and innovative defensive postures. Learning from every team member, regardless of their position, can uncover blind spots and enhance collective intelligence.
  1. Trust the Process and Avoid Rogue Actions: Fuller's Marine Corps incident, where he uploaded sensitive incident details to an unknown "online tool," serves as a stark warning. Defenders, especially junior analysts, must understand and trust established incident response protocols and escalation paths. Ad-hoc, unapproved actions, no matter how well-intentioned, can compromise investigations, alert adversaries, or lead to data breaches. Building a strong sense of team trust and adherence to standard operating procedures (SOPs) is fundamental for effective defensive operations.

By internalizing these lessons, defensive teams can build a more resilient, adaptive, and collaborative security posture, moving beyond purely technical measures to address the critical human and organizational factors that underpin effective cybersecurity.

Key Takeaways

  • Radical Ownership of Career: No one, not even close friends or family, will care about your career goals as much as you do. Take aggressive, independent action to pursue your aspirations, even if it means taking jobs outside your perceived ideal path.
  • Trust and Collaboration Over Ego: In incident response and security operations, trust your team's processes and expertise. Avoid individual, ego-driven actions that could compromise sensitive investigations or undermine team efforts.
  • Embrace the "Run Faster" Mindset: Cultivate an internal drive for continuous improvement and competitiveness. View challenges and the achievements of others as motivation to learn more, work harder, and consistently push your own boundaries.
  • Clear Communication in Leadership: Uncommunicated expectations in any relationship, especially between leaders and their teams, inevitably lead to resentment. Leaders must explicitly define roles, goals, and feedback mechanisms to foster respect and prevent misunderstandings.
  • Failure as a Learning Catalyst: Do not fear failure; embrace it as the primary mechanism for learning and growth. Success only validates what you already know, while failure illuminates new pathways to knowledge and improvement.
  • Unified Security Objectives: Red and blue teams are on the same side, working towards the common goal of enhancing organizational security. Foster collaboration and mutual respect, focusing on collective improvement rather than adversarial "wins."

About the Speaker(s)

Rob Fuller is a seasoned cybersecurity professional currently serving as a VP of Cybersecurity & Digital Risk. With approximately 20 years of experience in the industry, having started around 2005, Fuller also dedicated eight years to serving in the Marine Corps (MOS 1371). His diverse background includes significant technical expertise in areas such as Windows, Active Directory, and red teaming. He is recognized as a co-founder of Nova Hackers and has lent his insights as a Senior Technical Advisor for HBO's Silicon Valley. Fuller has also been a participant in the National CCDC (Collegiate Cyber Defense Competition). Beyond his technical and leadership roles, he is deeply passionate about leadership development and personal introspection, often drawing on his own "hard way" experiences to teach and mentor others in the cybersecurity community.

All talks from SAINTCON 2025