> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Star Wars, 2600 and a Call to the NSA: Stephen Cravey’s Cybersecurity Origin Story
- URL: https://www.cybrsecmedia.com/star-wars-2600-and-a-call-to-the-nsa-stephen-craveys-cybersecurity-origin-story/
- Published: 2026-09-09T12:37:29.000Z
- Updated: 2026-09-09T12:59:20.000Z
- Description: Before cybersecurity was much of an industry, Stephen Cravey followed his curiosity from Star Wars and BBSs to the NSA’s Rainbow Books — and eventually into a major FBI cybercrime investigation.
- Author: Bill Brenner
- Tags: Leadership, Star Wars, 2600, NSA, Article

Ask someone entering cybersecurity today how they got started and there are plenty of recognizable paths. Cybersecurity degree programs exist. Certifications abound. There are conferences, capture-the-flag competitions, security communities, YouTube channels and seemingly endless online training options.

Stephen Cravey came up in a different world.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

His cybersecurity origin story involves Star Wars, James Bond, Apple computers, BBSs, *Neuromancer*, the alt.2600 newsgroup, a slightly terrifying phone call to the National Security Agency and, eventually, an international FBI investigation.

It was a time when the path into cybersecurity wasn't particularly well marked because cybersecurity wasn't much of a profession yet.

Cravey, now a principal security advisor and longtime CYBR.SEC.Community member, recently walked CYBR.HAK.CAST hosts Phil Wylie and Michael Farnum through how he found his way into it. It started with curiosity.

**Full episode and related article:**

[IoT Security: The Hidden Risks Inside “Dumb” DevicesStephen Cravey explains how connected locks, toothbrushes and other overlooked IoT devices can introduce serious security risks.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-3b1f4dd8-5e81-4460-bcf5-5adde0248bce.jpg)CYBR.SEC.Media, and CYBR.SEC.Media![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/Stephen-Cravey_Ghost-2c3ccdcf-12dd-4399-96de-486979167e38.png)](https://www.cybrsecmedia.com/dumb-iot-devices-with-stephen-cravey/)

[IoT Security: Your Toothbrush Is a Computer TooStephen Cravey’s CYBR.SEC.CON 2026 talk explores the security blind spots inside smart locks, appliances and everyday IoT devices — and why organizations may have little idea what is actually running on them.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-67152ebb-7f80-4b4e-bd52-0001917b1256.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/d547f331-86c2-40d5-b293-4887b43a240d-1b5de787-0b41-4c81-8230-4ae2846e854c.png)](https://www.cybrsecmedia.com/your-toothbrush-is-a-computer-are-you-securing-it-like-one/)

## Star Wars, James Bond and secret codes

Cravey remembers seeing *Star Wars* and becoming fascinated by technology.

Growing up in Houston during the rise of the Space Shuttle added fuel to that interest. James Bond introduced another fascination: espionage.

Then several things converged when he was around fourth grade.

Cravey found Martin Gardner's *Codes, Ciphers, and Secret Writing* in the library. His school began offering programming classes, where he learned Apple Logo. Around the same period, William Gibson's *Neuromancer* appeared.

From there, Cravey said, it became a “bobsled of technology.”

He learned additional programming languages, ran BBSs and eventually studied computer engineering with the idea that he might design silicon.

Then his school gave him access to a Sun SPARC lab connected to the Internet.

That changed things.

Security on those early networks bore little resemblance to what exists today. Cravey remembers the lab being compromised roughly every week or two.

“Security didn't exist,” he said. “Firewalls weren't a thing at that point.”

The Internet itself was also still taking shape. Cravey remembers using Gopher, Archie and Veronica before early web browsers such as Mosaic and Netscape arrived.

And somewhere in that early Internet, he found alt.2600.

## So he called the NSA

While exploring the alt.2600 newsgroup, Cravey found its FAQ and an entry discussing the government's Rainbow Books, a collection of computer security standards and guidance.

The instructions included a phone number for the National Security Agency.

So Cravey called it.

That might not sound especially remarkable today. At the time, Cravey recalled, Operation Sun Devil — the federal crackdown targeting computer hacking and related activity — was still fresh in people's minds.

The NSA didn't exactly strike him as an obvious friendly resource.

Someone answered with an extension number in what Cravey remembers as an extremely serious voice.

He nervously explained that he'd read something “on an internet” saying he could call and obtain educational material about information security.

The mood changed immediately.

The person on the other end enthusiastically asked for his home address so the agency could send him material.

About two weeks later, a box showed up on Cravey's front porch.

He still has the Rainbow Books on his shelf.

“That got me into information security pretty soundly,” Cravey said.

But his real introduction to cybersecurity incident response would come later.

## Apparently, he'd logged in from South Korea

Around 2000, Cravey took what he describes as his first “real job” after doing small-business consulting.

He joined Networks Online, a Houston company that has since disappeared.

He hadn't been there long when he looked through the logs and noticed something peculiar.

Apparently, Cravey had logged in from South Korea the previous day.

He hadn't.

He started digging.

What initially looked like an anomalous login led him to evidence stretching further back into the environment.

So he called the FBI.

That phone call turned into something considerably bigger than a routine compromised-account investigation.

Cravey said he spent the next six to nine months involved in what was, at the time, the largest international cybercrime investigation the FBI's Houston office had encountered.

And everyone involved was learning as they went.

“Information security and digital forensics and all that stuff were sort of super new,” Cravey said.

He describes working with FBI contacts to develop forensic techniques and figure out how to monitor the compromised systems without tipping off the intruder.

There were also calls to other organizations that had been breached, where Cravey had to explain what had happened while asking them to respond carefully enough that they didn't inadvertently expose the larger investigation.

Today, there are incident response playbooks for that.

Back then, Cravey and the investigators were figuring out parts of the playbook in real time.

## Looking at security from the other end

Cravey went on to work in digital transformation and eventually became an enterprise security architect at an engineering and defense contractor, where Farnum first met him.

His career also developed an emphasis on advanced threats.

Cravey says that background continues to influence how he evaluates security problems. Rather than primarily imagining the random script kiddie or conventional ransomware operator, he tends to examine systems through the lens of what a sophisticated nation-state adversary could do.

“I think I've got just sort of like a different perspective on cybersecurity and information security from a lot of people,” he said.

That perspective also provides a through line from the kid fascinated by codes, spies and computers to the research Cravey will bring to CYBR.SEC.CON 2026.

The technology has changed enormously. The curiosity hasn't. Neither has the question that has followed Cravey through much of his career:

What can someone make this technology do that its designers never expected?

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)