> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Open Source Security Runs The Internet. Kelley Misata Says Code Is Only Half The Battle
- URL: https://www.cybrsecmedia.com/open-source-security-runs-the-internet-kelley-misata-says-code-is-only-half-the-battle/
- Published: 2026-09-16T13:19:45.000Z
- Updated: 2026-09-16T19:51:04.000Z
- Description: At CYBR.SEC.CON 2026, OISF President Kelley Misata explains why critical open source security projects like Suricata depend on more than developers — and why funding, governance, licensing and succession planning are now cybersecurity issues.
- Author: Bill Brenner
- Tags: Open-Source Security, Suricata, CYBR.SEC.CON, Article

Open source software quietly holds up enormous portions of the internet. Security teams rely on it to monitor networks, investigate attacks, build products and protect critical systems.

Yet many organizations know remarkably little about what keeps the projects they depend on alive.

Dr. Kelley Misata wants that to change.

In her CYBR.SEC.CON 2026 session, “Guardians of the Internet: What a Decade Inside Open Source Taught Me About What Really Keeps It Standing,” Misata argued that enterprises need to start treating open source as infrastructure — including the people, governance and money behind it.

For security leaders, it's about due diligence, not philanthropy.

Misata is president of the [Open Information Security Foundation (OISF)](https://oisf.net/?ref=cybrsecmedia.com), the nonprofit behind the open source [Suricata](https://suricata.io/?ref=cybrsecmedia.com) network analysis and threat detection engine. Her open source experience also includes the Tor Project, and she recently joined the Wireshark Foundation as chairperson of its board.

After more than a decade inside that ecosystem, her message is that the code is only the part everyone can see.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## Open source is everywhere

Misata starts with the sheer scale of the ecosystem. Her presentation cites 630 million total software repositories, 395 million public or open source repositories and more than 180 million active developers generating commits and pull requests continuously.

Another slide estimates that 70% to 90% of software running today includes open source components.

That represents enormous economic value, but Misata turns the statistic around. The same ecosystem that gives organizations software they otherwise would have to build or buy also transfers an extraordinary amount of responsibility onto maintainers, volunteers and the organizations supporting those projects.

The question isn't simply who is writing the code, but who is watching the house?

**Related:**

[Hunted Online, Rewired for Cybersecurity: How Kelley Misata Turned Trauma Into a MissionAfter enduring years of cyberstalking, Kelley Misata transformed personal trauma into a cybersecurity movement, helping nonprofits close dangerous security gaps the industry still doesn’t understand.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-8b3b6e10-c0a2-490e-b995-4bb210ddc92b.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Screenshot-2026-04-07-at-8.56.09---AM-a528f15c-7159-4698-b4c7-1b138e4e1bba.png)](https://www.cybrsecmedia.com/hunted-online-rewired-for-cybersecurity-how-kelley-misata-turned-trauma-into-a-mission/)

[From Cyberstalking to Cybersecurity Leadership: Kelley Misata’s Mission to Protect NonprofitsIn this episode of CYBR.SEC.CAST, the hosts sit down with Dr. Kelley Misata, CEO of Sightline Security, to explore the often-overlooked cybersecurity challenges facing nonprofit organizations.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-25661b4a-bef5-4051-9789-55469442221b.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Kelley-Misata-8225b628-57c0-428f-92d2-cfcde7db44eb.png)](https://www.cybrsecmedia.com/from-cyberstalking-to-cybersecurity-leadership-kelley-misatas-mission-to-protect-nonprofits/)

## Code is what you see above the waterline

One of Misata's slides uses an iceberg-like waterline metaphor to capture the problem. Code sits above the surface. Underneath are governance, funding, culture, long-term strategy, security hygiene and people operations.

Those things aren't likely to appear in a commit log. But they can determine whether a security project remains healthy five or 10 years from now.

That matters when organizations build critical security capabilities around software maintained outside their walls.

A project can have excellent code and still face existential problems. A key maintainer can leave. Funding can disappear. Licensing can change. Governance can break down. Security audits can become unaffordable. A foundation can take on responsibilities it lacks the people or money to fulfill.

Open source risk, in other words, is bigger than vulnerability management.

## Licensing has become a security issue

Licensing illustrates how much the landscape has changed.

Licenses determine who can use, modify and profit from open source work. Getting those decisions wrong can introduce legal and security risks that travel downstream with the software.

Misata said what once looked primarily like a legal question increasingly isn't.

OISF this year developed an AI contribution policy for Suricata covering contributor license agreement gaps, AI-assisted submissions and circumstances where autonomous AI contributions receive a hard no.

“Five years ago that sentence wouldn't have meant anything,” her slide notes. “Today it's a governance requirement.”

AI-generated code is therefore creating another challenge for maintainers already juggling security, licensing and sustainability.

And it is only one of the pressures Misata sees ahead. Her presentation also identifies licensing pressure and geopolitical tension as issues open source organizations need to watch.

## Somebody has to pay for sustainability

Then there is money. Misata's framing is direct: “Funding is a decision — not a hope.”

Projects that become foundational infrastructure need developers, legal expertise, operational support, security testing and continuity planning. Those requirements don't disappear because the underlying software can be downloaded for free.

The investments Misata identifies include dedicated expert developers, legal and licensing oversight, organizational infrastructure, disaster recovery planning and security audit budgets.

That creates tension between open source communities and the businesses that depend on them.

The two need each other, Misata argues, but they often operate at different speeds. Businesses seek stability, predictability and support contracts. Communities value experimentation and freedom. When those priorities collide, foundations frequently end up absorbing the friction.

The challenge is finding a model that keeps both sides healthy without undermining the qualities that made the open source project valuable in the first place.

## Even saying yes can put a project at risk

Sustainability also requires knowing when *not* to take something on.

Misata describes an open source project that approached OISF this year about becoming its steward.

It sounds like an opportunity. But taking responsibility for another project raises difficult questions: Who owns the intellectual property? What happens if its maintainer walks away? Does OISF have enough resources to support it properly?

“Saying yes without asking those questions first is how foundations quietly become the reason a project fails,” Misata's presentation warns.

The same discipline applies when commercial opportunities emerge.

OISF is exploring what Misata describes as its first royalty or revenue-sharing partnership with a commercial security vendor around a community-requested plugin. But before moving forward, the organization is examining tax implications, its 501(c)(3) status and whether the arrangement would require a separate legal structure.

Her point isn't that open source foundations should avoid commercial money.

It's that good opportunities still require due diligence.

## What happens when the maintainer disappears?

Perhaps the most uncomfortable open source risk is also one of the simplest: people leave.

Projects age. Maintainers burn out, retire, change jobs or lose interest. Funding changes. The people who understand why years of architectural decisions were made may no longer be there to explain them.

Misata's resilience checklist includes maintainer succession planning, reserve budgeting, observable governance, clear licensing structures and continuity planning.

These aren't glamorous controls. They're also the kinds of things enterprises routinely demand from their own critical suppliers.

That raises an uncomfortable question for security leaders: Are organizations applying anything close to that scrutiny to the open source projects embedded throughout their security stacks?

Knowing that a dependency has no known vulnerability today doesn't tell you whether its maintainers have a succession plan, whether the foundation supporting it has adequate reserves or whether the project will still be healthy several years from now.

Software supply chain due diligence needs to look beyond the software.

## Don't just consume open source. Invest in it

Misata doesn't romanticize the open source model.

“Community isn't a guarantee,” one of her closing slides says. Licenses are complex. Money matters. Projects age. Open source isn't always the right answer, and businesses don't always give back.

Her conclusion: The responsibility must be shared.

For enterprises, that means doing more than downloading another dependency. Misata urges organizations to understand the projects they rely on, give engineers time to contribute, fund sustainability rather than merely software, make that support visible inside their organizations and invest in the open source ecosystem they consume.

That may be the larger cybersecurity lesson from a decade spent helping keep projects like Suricata standing.

Security teams spend enormous amounts of time evaluating the resilience of networks, applications, cloud providers and vendors.

Open source deserves the same scrutiny.

Because when a project becomes critical infrastructure, keeping the code secure is only part of keeping it alive.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)