Uploaded May 2026 | Updated September 2026, 10 minutes ago
Bob Lord (US)
The CVE Program is one of the most important public-interest technology infrastructures, but it was built for a very different era. Today’s defenders face adversaries who move faster, exploit automation, and operate at global scale. Meanwhile, the CVE ecosystem still relies on fragmented governance, inconsistent data quality, and processes that treat vulnerability reporting as a clerical task rather than a safety-critical function. This talk asks a simple but disruptive question: What would the CVE program look like if we designed it from scratch today? Drawing from lessons in aviation safety, transportation safety, and public health, we will explore a vision for a modern software defect registry that treats software as critical infrastructure, focuses on classes of defects rather than individual bugs, and enforces quality-by-design at the moment records are created. Attendees will see concrete examples of how this vision can work in practice, including walkthroughs of a CNA Dashboard and a User Dashboard that surface CVE record quality, recurring defect patterns, and manufacturer accountability in ways that are not possible today. These prototypes demonstrate what becomes immediately achievable when the system creates CVE records that are complete, accurate, timely, and structured for automation—giving defenders faster answers while enabling systemic analysis of how software fails over time. The goal of the session is not incremental change. It is a call to reimagine CVE as the backbone of software safety: an authoritative defect registry, an accountability mechanism for manufacturers, and an engine for eliminating entire classes of vulnerability. The talk will close with a pragmatic discussion of initial steps the community could take in 2026 to begin implementing this vision, focusing on quality-by-design requirements, opinionated tooling, and governance changes that enable meaningful progress without requiring a wholesale reset of the ecosystem.
---
Bob Lord is a cybersecurity executive and public-interest technologist with deep experience building and defending high profile digital systems. He has led major secure by design initiatives at the Institute for Security and Technology (IST) and at the Cybersecurity and Infrastructure Security Agency (CISA), where he served as a Senior Technical Advisor focused on shifting more responsibility for customer safety to software manufacturers. He was the first Chief Security Officer (CSO) at the Democratic National Committee (DNC), boosting the security of the Committee along with state parties and campaigns. Earlier in his career he was the CISO at Yahoo and the first security hire at Twitter, where he built and led the information security program from the ground up.
Bob Lord (US)
The CVE Program is one of the most important public-interest technology infrastructures, but it was built for a very different era. Today’s defenders face adversaries who move faster, exploit automation, and operate at global scale. Meanwhile, the CVE ecosystem still relies on fragmented governance, inconsistent data quality, and processes that treat vulnerability reporting as a clerical task rather than a safety-critical function. This talk asks a simple but disruptive question: What would the CVE program look like if we designed it from scratch today? Drawing from lessons in aviation safety, transportation safety, and public health, we will explore a vision for a modern software defect registry that treats software as critical infrastructure, focuses on classes of defects rather than individual bugs, and enforces quality-by-design at the moment records are created. Attendees will see concrete examples of how this vision can work in practice, including walkthroughs of a CNA Dashboard and a User Dashboard that surface CVE record quality, recurring defect patterns, and manufacturer accountability in ways that are not possible today. These prototypes demonstrate what becomes immediately achievable when the system creates CVE records that are complete, accurate, timely, and structured for automation—giving defenders faster answers while enabling systemic analysis of how software fails over time. The goal of the session is not incremental change. It is a call to reimagine CVE as the backbone of software safety: an authoritative defect registry, an accountability mechanism for manufacturers, and an engine for eliminating entire classes of vulnerability. The talk will close with a pragmatic discussion of initial steps the community could take in 2026 to begin implementing this vision, focusing on quality-by-design requirements, opinionated tooling, and governance changes that enable meaningful progress without requiring a wholesale reset of the ecosystem.
---
Bob Lord is a cybersecurity executive and public-interest technologist with deep experience building and defending high profile digital systems. He has led major secure by design initiatives at the Institute for Security and Technology (IST) and at the Cybersecurity and Infrastructure Security Agency (CISA), where he served as a Senior Technical Advisor focused on shifting more responsibility for customer safety to software manufacturers. He was the first Chief Security Officer (CSO) at the Democratic National Committee (DNC), boosting the security of the Committee along with state parties and campaigns. Earlier in his career he was the CISO at Yahoo and the first security hire at Twitter, where he built and led the information security program from the ground up.










