Cyber Ethics: Where Do You Stand?
Tommy Gardner
S4x24 - ICS Security Conference · Day 3 · Main Stage
Overview
In his S4 conference talk, "Cyber Ethics: Where Do You Stand?", Tommy Gardner delves into the fundamental, yet often overlooked, question of ethics within the digital realm. Gardner, drawing from a rich and diverse career spanning military service, academia, and the private sector, challenges the audience to confront their personal definitions of ethics and morals, emphasizing that a shared understanding is elusive, yet critical for navigating the complexities of cybersecurity. The talk serves as a vital reminder that while technology evolves at an exponential pace, the underlying human principles that govern its use and defense remain paramount.

Key moments
- 0:00 Defining ethics, morals, and cyber ethics
- 1:00 The challenge of finding cybersecurity educators
- 2:00 Speaker's unexpected journey to teaching cyber
- 2:40 Econometrics to Data Science to Cyber security
- 3:15 First digital classified work on a submarine (1978)
- 3:45 Learning machine language and binary for programming
Cyber Ethics: Where Do You Stand?
Speakers: Tommy Gardner
Conference: S4
YouTube: https://www.youtube.com/watch?v=Oe6_cGgbqTM
Overview
In his S4 conference talk, "Cyber Ethics: Where Do You Stand?", Tommy Gardner delves into the fundamental, yet often overlooked, question of ethics within the digital realm. Gardner, drawing from a rich and diverse career spanning military service, academia, and the private sector, challenges the audience to confront their personal definitions of ethics and morals, emphasizing that a shared understanding is elusive, yet critical for navigating the complexities of cybersecurity. The talk serves as a vital reminder that while technology evolves at an exponential pace, the underlying human principles that govern its use and defense remain paramount.
Gardner's presentation is less about presenting novel technical findings and more about initiating a necessary philosophical introspection among cybersecurity professionals. He argues that a robust ethical framework is the bedrock upon which all effective security strategies must be built, influencing everything from policy development to incident response. In an era where cyber warfare, data privacy breaches, and the weaponization of information are daily realities, understanding "what is right and what is wrong" in the digital context is no longer an academic exercise but an operational imperative for every individual and organization engaged in the cyber domain.
This discussion is particularly relevant for the S4 audience, which comprises industrial control system (ICS) and operational technology (OT) security experts. The ethical considerations in protecting critical infrastructure carry profound real-world consequences, extending beyond data loss to potential physical damage, environmental harm, and threats to human life. Gardner's call to define one's ethical stance provides a crucial lens through which to evaluate the responsibilities and challenges inherent in securing the systems that underpin modern society.
Background
▶ Watch: Defining ethics, morals, and cyber ethics (0:00)
Tommy Gardner initiates his talk by directly confronting the audience with the question, "What is ethics?" He immediately highlights the inherent subjectivity of the concept, acknowledging that everyone possesses a different definition, insight, and opinion—a diversity he explicitly champions as a strength. Gardner posits that ethics is fundamentally "based on your moral framework," which in turn necessitates defining "morals" as what one is "trained to be moral, what is right and what is wrong." This foundational distinction sets the stage for a deeper exploration of cyber ethics, or ethics specifically applied to the digital world.
Gardner weaves his personal and professional journey into this philosophical inquiry, providing context for his unique perspective. His early career as a submarine officer in the U.S. Navy exposed him to high-stakes, classified operations, where ethical decision-making was paramount. He recounts an anecdote about Admiral Mel Williams, who struggled to find qualified individuals to teach cybersecurity at the graduate level. This challenge stemmed from a disconnect: those with deep cybersecurity expertise were often too valuable in their industry roles to pursue the academic qualifications (like a PhD) required for university teaching, while academics often lacked practical, cutting-edge cyber experience. This highlights a significant and ongoing problem in cybersecurity education: bridging the gap between theoretical knowledge and practical, real-world application, and cultivating the next generation of professionals.
Gardner's own path to cybersecurity was unconventional. Although his doctorate was in economics, specifically econometrics (which he describes as an early form of data science focused on making sense of "large data sets" to predict economic trends), this analytical background unexpectedly led him into the digital realm. His early exposure to computing began in 1978 on his first submarine, where he worked on a special, top-secret project involving a PDP8 computer located in the control room. This experience, coupled with a mail-order course on building microprocessors that taught him machine language and binary to program chips, provided him with a foundational, hands-on understanding of digital systems. This early, practical immersion in classified digital programs on submarines shaped his awareness of the profound implications and responsibilities associated with technology—a perspective that now informs his ethical considerations in the cyber domain. His involvement in HP's "give back to the community" policy, which encourages employees to dedicate four hours a week to public service, further exemplifies his commitment to sharing this accumulated knowledge and experience, particularly in education.
Key Findings
▶ Watch: Speaker's unexpected journey to teaching cyber (2:00)
Given the introductory and philosophical nature of Tommy Gardner's talk, it does not present "key findings" in the traditional sense of empirical research or novel technical discoveries. Instead, the core contributions of this presentation lie in its framing of fundamental questions and the identification of critical challenges that underpin the entire field of cybersecurity. Gardner's "findings" are therefore more akin to foundational premises and observations that demand collective introspection from the audience.
The primary "finding" is the inherent subjectivity and diversity of ethical frameworks. Gardner explicitly states, "Everybody has a different definition, a different insight, and a different opinion. And that's good. We're all different. We ought to think differently about things. That's why diversity is so important." This highlights that a universal, monolithic definition of cyber ethics is unattainable and, perhaps, undesirable. Instead, the strength lies in understanding and respecting these diverse perspectives while working towards a shared understanding of core principles. The implication is that effective cyber defense and policy cannot be built on an assumption of universal ethical alignment but must account for, and ideally integrate, a spectrum of viewpoints.
Another significant observation is the critical need for a clear definition of "morals" as the basis for ethics. Gardner insists, "if ethics is based on what you were trained to be moral, what is right and what is wrong? Then you got to define morals first if you want to talk about ethics." This emphasizes that superficial discussions of ethics are insufficient; a deeper dive into the underlying moral principles that guide individual and organizational behavior is essential for truly robust ethical conduct in the digital space.
Finally, Gardner implicitly "finds" a gap in cybersecurity education and mentorship. His anecdote about Admiral Mel Williams struggling to find qualified cyber educators underscores a systemic problem: the immense demand for practical cybersecurity expertise often pulls professionals away from academic roles, creating a void in the training of future generations. Gardner's own commitment to teaching, despite his primary expertise being in economics, serves as a testament to the urgent need for experienced practitioners to "give back" and bridge this educational divide, ensuring that not only technical skills but also ethical considerations are instilled in aspiring cyber professionals. These observations collectively set a critical agenda for the cybersecurity community, urging a foundational re-evaluation of how ethical considerations are understood, taught, and integrated into practice.
Technical Deep Dive
▶ Watch: Econometrics to Data Science to Cyber security (2:40)
While Tommy Gardner's talk is not a technical deep dive into a specific vulnerability, protocol, or system architecture, it provides a fascinating glimpse into the historical technical foundation that shaped his unique perspective on cyber ethics. The technical elements mentioned are primarily autobiographical, illustrating his journey into the digital world and how early exposure to computing informed his understanding of its profound implications.
Gardner's entry point into the technical realm was through econometrics, which he describes as an antecedent to modern data science. Econometrics involves the application of statistical methods to economic data, using mathematical models to develop theories or test hypotheses in economics. This discipline, focused on analyzing "large data sets" to predict economic trends, provided him with a rigorous framework for understanding complex systems and extracting meaningful patterns from vast amounts of information. This analytical rigor is directly transferable to cybersecurity, where professionals routinely grapple with immense volumes of log data, network traffic, and threat intelligence to identify anomalies and predict attacks. The transition from econometrics to data science highlights the evolving nature of data analysis, moving from purely economic applications to broader domains, including security intelligence.
His hands-on experience began in 1978 aboard a submarine, working with a PDP8 computer. The Programmed Data Processor-8 (PDP-8), first introduced by Digital Equipment Corporation (DEC) in 1965, was a landmark in computing history. It was one of the first commercially successful minicomputers, significantly smaller and less expensive than mainframes, making digital computing accessible to a wider range of applications. The PDP-8 was a 12-bit machine, meaning its central processing unit (CPU) processed data in 12-bit chunks. Its architecture was relatively simple, making it ideal for embedded systems and specialized applications, such as the classified project Gardner describes in the submarine's control room. This early exposure to a dedicated, purpose-built digital system in a critical operational environment would have ingrained a deep appreciation for the reliability, security, and ethical implications of such technology.
To interact with and program the PDP-8, Gardner learned machine language and binary. Binary is the most fundamental language of computers, a base-2 numeral system that uses only two symbols: 0 and 1. All data and instructions within a computer are ultimately represented in binary. Machine language, also known as machine code, is the lowest-level programming language directly understood by a computer's CPU. It consists of instructions and data represented as sequences of binary digits (bits). Programming in machine language is incredibly arduous, requiring a deep understanding of the CPU's architecture, registers, and instruction set. This hands-on experience, "how to solder a chip on a motherboard" and then "get it to turn on and execute simple commands" using binary and machine language, provided Gardner with an intimate understanding of how digital systems fundamentally operate. It's a level of technical depth that few contemporary cybersecurity professionals experience, as modern development relies on higher-level languages and abstraction layers.
Gardner's work on "classified programs in the digital world" from such an early stage further underscores the critical importance of trust, integrity, and ethical conduct. Operating in environments where national security is at stake, and where digital systems are integral to military operations, mandates an acute awareness of the potential for misuse, compromise, and the ethical responsibilities of those who build, maintain, and secure these systems. While the talk does not delve into the specifics of these classified programs, the context itself highlights the high-stakes environment where cyber ethics are not merely theoretical but have immediate, tangible consequences. This foundational technical journey, from econometrics to hands-on binary programming on a PDP-8 in a classified setting, forms the bedrock of Gardner's perspective on the indispensable role of ethics in all facets of the digital world.
Demo / Proof of Concept
▶ Watch: First digital classified work on a submarine (1978) (3:15)
Tommy Gardner's talk, "Cyber Ethics: Where Do You Stand?", is primarily a philosophical and introspective discussion, focusing on the fundamental definitions of ethics and morals as applied to the digital realm. As such, the presentation did not include a live demonstration or a proof of concept of any technical exploit, defensive tool, or system. The speaker's objective was to provoke thought and encourage self-reflection on ethical frameworks, rather than to showcase a specific technological capability.
Defensive Implications
▶ Watch: Learning machine language and binary for programming (3:45)
While Tommy Gardner's talk does not offer specific technical defensive strategies or countermeasure recommendations, its emphasis on defining and understanding cyber ethics has profound and pervasive implications for defensive cybersecurity. The ethical framework that individuals and organizations adopt directly influences every aspect of their defensive posture, from policy development to incident response.
Firstly, a clear ethical stance is crucial for responsible disclosure practices. Defenders often uncover vulnerabilities in third-party systems or software. Ethical considerations dictate how and when these vulnerabilities are disclosed, balancing the need to protect the public with the potential for misuse if information is released prematurely. An organization with a strong ethical foundation will prioritize responsible disclosure, working with vendors to patch issues before publicizing them, thereby minimizing harm.
Secondly, ethical principles guide the development and deployment of defensive tools and techniques. The line between legitimate defense and potentially intrusive or privacy-infringing surveillance can be blurred. For instance, the use of advanced persistent threat (APT) emulation, deep packet inspection, or insider threat monitoring tools requires careful ethical consideration to ensure that employee privacy is respected, legal boundaries are adhered to, and the tools are not misused. Organizations must establish clear ethical guidelines on what types of data can be collected, how long it can be retained, and who has access to it.
Thirdly, the talk's call to define "what is right and what is wrong" directly impacts supply chain security. Defenders are increasingly reliant on third-party software, hardware, and services. An ethical supply chain demands due diligence, not just on technical security controls, but also on the ethical practices of vendors—their data handling, labor practices, and commitment to security. Organizations with strong ethical frameworks will extend their scrutiny beyond their immediate perimeter to encompass the entire ecosystem of their digital dependencies.
Furthermore, ethical considerations are paramount in incident response. When a breach occurs, defenders face critical decisions: what information to disclose, to whom, and when; how to contain the damage without causing further harm; and how to engage with affected parties. An ethical approach prioritizes transparency, victim notification, and minimizing long-term impact, even when it might be inconvenient or costly for the organization. This extends to questions of attribution and retaliation; while tempting to "strike back," ethical guidelines often preclude such actions, focusing instead on resilience and recovery.
Finally, Gardner's emphasis on diversity and differing opinions in ethics directly applies to building diverse and ethically-minded security teams. A team composed of individuals with varied backgrounds and perspectives is more likely to identify and address a broader range of ethical dilemmas, leading to more robust and thoughtful defensive strategies. Encouraging open discussion about ethical boundaries and potential grey areas fosters a culture of integrity and accountability, which is a powerful, albeit intangible, defensive asset. In essence, the talk underscores that technical prowess without a strong ethical compass is a ship without a rudder, capable of immense power but lacking direction and prone to unintended, potentially harmful, consequences. For defenders, understanding where they stand ethically is the first step toward building truly resilient and responsible cybersecurity operations.
Key Takeaways
- Ethics are Subjective and Diverse: There is no single, universally agreed-upon definition of ethics, and this diversity of opinion is valuable and essential for robust discussions in cybersecurity.
- Morals Precede Ethics: To understand ethics, individuals and organizations must first define their underlying moral framework—their personal and collective understanding of "what is right and what is wrong."
- Cyber Ethics are Foundational: Ethical considerations are not an afterthought but form the bedrock upon which effective cybersecurity strategies, policies, and incident response plans must be built.
- Bridging the Education Gap is Critical: There is an ongoing challenge in cybersecurity education, where experienced practitioners are needed to mentor and teach the next generation, integrating both technical skills and ethical principles.
- Historical Technical Context Informs Ethical Understanding: Early, hands-on exposure to foundational computing technologies (like the PDP8, machine language, and binary) and analytical disciplines (econometrics/data science) can profoundly shape one's appreciation for the ethical implications of digital systems.
- Ethical Frameworks Guide Defensive Actions: A clear ethical stance influences every aspect of defensive cybersecurity, including responsible disclosure, the use of defensive tools, supply chain security, and incident response, ensuring actions are both effective and responsible.
About the Speaker(s)
Tommy Gardner is a seasoned professional with a distinguished career that spans military service, academia, and the private sector. He served as a submarine officer in the U.S. Navy for a significant portion of his early career, an experience that provided him with early exposure to classified digital programs and high-stakes operational environments. Gardner holds a doctorate in economics, with a specialization in econometrics, which he describes as an early form of data science focused on analyzing large datasets to predict economic trends. This background in data analysis and complex systems unexpectedly paved his way into the digital world.
His practical technical journey began in 1978, where he worked on a top-secret project involving a PDP8 computer on a submarine, gaining hands-on experience with machine language and binary programming. Beyond his professional roles, Gardner is committed to giving back to the community, actively participating in HP's policy that encourages employees to dedicate four hours a week to public service. This commitment extends to education, where he has offered to teach cybersecurity at the graduate level, leveraging his unique blend of practical experience, academic rigor, and a deep understanding of the ethical dimensions of technology.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Gardner's talk on cyber ethics, while not a technical deep dive, is a crucial foundational discussion. He effectively grounds an inherently abstract topic in his unique, hands-on technical history, from PDP8s and machine language to econometrics. This personal context, combined with his call for individual and organizational introspection on moral frameworks, elevates the session beyond mere 'awareness' to a necessary philosophical prompt for the cybersecurity community, particularly relevant for critical infrastructure defenders.
Heather Calloway (CISO) — STRONG ACCEPT
Tommy Gardner's S4 talk forcefully reminds us that ethical clarity is not a soft skill but a foundational requirement for robust cybersecurity, particularly in critical infrastructure. He compellingly argues that an organization's moral framework directly underpins its governance, risk posture, and operational decisions, from responsible disclosure to supply chain integrity. While the talk excels at provoking essential introspection and highlighting the critical need for defining one's ethical stance, it leaves the practical implementation of such a framework to the audience, serving as a powerful call to action for leaders to establish clear ethical lines that guide all defensive…