What It’s Really Like to Become a Cybersecurity Whistleblower

Rachel Tenny, the relator whose 2022 filing led to Honeywell’s ~$2M False Claims Act settlement, walks through what it’s actually like to be the person who raises the alarm — the human side behind the press releases. The throughline: trust your instincts, get a good legal team early, and know that a real cyber event (not nitpicky gaps) drove this case.

Key takeaways:

  • “Relator,” not whistleblower. She prefers the legal term and stresses she’s careful not to relitigate — Honeywell admitted no liability, and they stopped short of claiming the company was breached via SolarWinds.
  • She was built to spot this. A counterintelligence/insider-risk PM on Honeywell’s quantum program with a threat-intel background — she saw indicators of compromise matching the SolarWinds signature and pushed for an investigation.
  • The real lesson is competing voices. One person says “investigate now,” others say “nothing to see here.” With a nation-state actor and highly sensitive defense tech, leaders have a responsibility to err on caution — you don’t need 100% certainty to respond.
  • She protected herself first. Being the lone dissenter is isolating; the risk of doing nothing was as real as the risk of acting. A good legal team coaches the legal, technical, and human parts. (The first attorney passed; a referral led to Tycko & Zavareei.)
  • The FCA needs a standard. The case had to be rebuilt around NIST 800-171 line by line — turning a cyber event into a codified legal argument. This wasn’t “onesie-twosie” roadmap gaps; it was missed warning signs on a national-level event.
  • It’s a slow, opaque grind. Years under seal, renewed every six months, much of it classified and behind closed doors — the settlement news arrived by text.
  • Advice by role: practitioners — raise concerns in terms of risk, not alarmism, and get an attorney if you’re ignored; CISOs/boards — sensitive data + nation-state = no gray area. For small businesses doing their genuine best and being transparent, FCA action is very rare.
  • The CCFI would’ve helped. Had the DOJ Civil Cyber-Fraud Initiative existed when she started, the path would’ve been far clearer — they were “feeling around in the dark.”

Transcript

Jacob: All right, folks. It is September of 2026, and in 2022, Rachel Tenny filed a False Claims Act [complaint] alleging that Honeywell failed to meet cybersecurity requirements on government contracts. Four years later, Honeywell agreed to pay just over $2 million to settle the allegations. Rachel was the whistleblower who started that case, and that’s who we’re going to talk to today.

Jason, we’ve talked about False Claims Act settlements. We’ve talked to lawyers who have run those cases for years now. But we have never talked to a whistleblower. And as far as I know, there aren’t many podcasts that have done deep-dive interviews from the whistleblower’s perspective. But that all changes today.

Jason: Jacob, as much as I enjoy talking to you every week — as much as I enjoy seeing your face across the screen, and as much as I enjoy talking about FCAs — every single time we’ve talked about one, something seemed to be missing after the episode. I didn’t feel complete. And now I feel complete. We have a whistleblower.

Jacob: We have a million questions for our whistleblower. And I’m just going to lead off with the first, most important question, to set the stage: Rachel, who are you? Who were you when you filed the claim? And what were you doing at your organization at the top?

Rachel: Sure. Well, at the time I was working as a project management specialist — that was my title on the books. In practice, I was a counterintelligence and insider risk program manager. I was brought in to do some specific work for the business in their quantum computing area. So I was there to monitor for insider risk, and also understand the counterintelligence and advise on that.

Jacob: So that’s interesting. It sounds like there’s a bunch of overlapping arenas going on all at the same time. So you had a counterintel background, but it also sounded like you guys were working on some high-speed quantum stuff. Did you have a cybersecurity background? Was that just thrown in the bucket, like a lot of cybersecurity folks at these contractors have to end up dealing with?

Rachel: I’d say the situation was pretty unusual. They created the role for me. They were looking for someone to do counterintelligence for that unit. But my background — I came to cybersecurity kind of in a circuitous route. I started off in defense intelligence doing counterterrorism. I was hired to do cyber threat intelligence, and that’s how I moved over into cybersecurity. So that’s where I ended up. And this was one of the roles I picked up that was for program management — to create something that doesn’t exist, assess what the requirements are, and then build out a program from there. And the focus was mainly on: what kind of threat actors would be interested in this program? What are our crown jewels, and what are we trying to protect?

Jacob: Yeah, that makes total sense with a threat intel or counterintel background like that. You’re obviously one of the people who understands better than anybody that the threats are super real. This is not a joke — they are absolutely 100% real. And in the complaints, and in the settlement, and in some of the coverage of the case, the biggest, baddest threat of them all, SolarWinds, was mentioned. So tell us about your perspective. Maybe catch everybody up on the basics — what was that, how did it relate to what you were doing and where you were located in the world here?

Rachel: Sure. So really, this story about becoming a relator — as I prefer to call it, rather than whistleblower — is that it really came down to: there are physical threats, people attempting to come in and steal intellectual property. But there are also cyber threats that are every bit as real, from a counterintelligence perspective and from an industrial espionage perspective. So protecting those crown jewels is just as important in the physical environment as it is in the cybersecurity world, in the fifth domain. So when SolarWinds hit and became a headline, that was very interesting from a counterintelligence perspective, because this is a nation-state threat actor. So I didn’t involve myself right away, but I became concerned from that perspective.

Jacob: Okay, so this would be after the SolarWinds news broke — that there was this massive, crazy intrusion into agencies, research institutions, and so on — and you were inside Honeywell at the time. So what was your perspective here? You knew the threat was real, but were you the only one aware of what was going on, or how did that look?

Rachel: Sure. So I have to be careful not to relitigate what has already been said — and that’s the challenge of trying to give an interview, toeing that line. So, understanding that — I raised several concerns to my superiors. I really thought that what I was seeing was something that matched indicators of compromise for that particular attack, based on publicly available or released information from various security companies and from CISA. So that kind of sets the stage for what happened next, which was sort of a back-and-forth between myself and the other folks that were there. And I think centering on that dialogue is probably going to be some of the most important takeaways we can talk about here.

Jason: Yeah. First and foremost, seeing the alarms from the outside, and then it raising the hairs on the back of your neck to be like, “Something has to happen here” — that’s the way to go, and then leading to the problem. Let’s talk about the problem itself. What exactly was the trigger point, or the thing you discovered that was like, “This is a problem, I need to do something about it”?

Rachel: Yeah, there were monitoring alerts that went off that were brought to my attention. I kind of crossed the physical-cyber barrier, in my role as this hybrid role. So I was seeing cybersecurity indicators, and I was also — in addition to everything else we were monitoring — seeing some of those things in the real world. And I brought those indicators to fruition and said, “I think this matches the signature that a threat actor would use,” and I really pushed for an investigation.

Now, what happened was that there were multiple competing voices on the ground at this time. So one of the things I really wanted to talk about is that, from an executive decision-maker perspective, what do you do when there’s a situation where you’ve got multiple voices inside your organization — one person saying, “Hey, this is a problem, this needs to be thoroughly investigated, there needs to be an incident response,” and then other voices saying, “No, no, no, there’s nothing to see here necessarily”? And so — we tend to think of it in black and white, and certainly, reading the complaint, I think somebody could come away and say, “Well, what were they thinking?” But there are two perspectives here, and decision-makers have to make decisions based on risk. And so, one of the key takeaways I would say is that you may be in a situation where there is someone saying, “Hey, we’ve got a real problem here, and this needs a professional remediation,” and that doesn’t mean there isn’t going to be a naysayer, or multiple people, saying, “There’s nothing to see here, this isn’t a problem, don’t listen to that person over there.” And you have to kind of make a decision. I would say, given the factors at play and what was at stake — given that this was a nation-state threat actor that was very, very sophisticated, combined with the fact that there were very high-level government contracts involved, and the technology being protected was very, very important — I would certainly say that a decision-maker in that position should err on the side of caution, and really has a responsibility to err on the side of caution and say, “You know what? I know you guys are saying maybe there’s nothing going on here and this is overkill, but you know what? We should go about mitigating the risk here. Let’s go ahead and move forward with a full investigation and incident response.” That’s what I would say.

Jason: So I’m kind of curious. From your position — when you saw the indicators of compromise from nation-state actors that were in play here — was that the point when you thought, “Man, this is really serious, because they’re within our threshold”? Or did it become even more of a serious situation when you got to the point of contention, where one side was saying this is serious and the other side saying it’s not that serious?

Rachel: It was pretty apparent to me at the beginning what needed to happen. And this is part of the gray area that leaders have to navigate: you might not have complete, irrefutable proof that there was a cyberattack. There are indicators that say there could be a cyberattack, and then other evidence that says maybe there’s a plausible explanation for these indicators. And so that’s where, as a leader, as a decision-maker, you have to say, “Okay, what’s at risk?” In this case, I would say the risk is way too high to rely on, or to stop short of, fully investigating something in order to flesh out what’s going on.

Jacob: Yeah. Well, I’m curious — obviously the technology and the programs you guys were working on were valuable enough to get the attention of a super-nation-state actor like the one behind SolarWinds. And you see these indicators, you raise them, you’re obviously very confident, professional — this is your opinion of what’s going on. Did it surprise you that there were other voices being like, “No, this isn’t that big of a deal”? Because if you investigate and there’s nothing there, then there’s nothing there. But if there is something there and you do nothing, it’s a massive problem. Did this catch you off guard, or is that what you were expecting when you brought this up?

Rachel: It wasn’t what I was expecting at all. And I would say the voices that were saying “nothing to see here” — it stood out to me. It seemed conspicuous.

Jacob: So was it an effect of, like, they didn’t understand what you were saying? Or did you start to feel like — we said we’re not relitigating people’s motivations here, but they obviously are paying you to look out for these things, you find the things they’re paying you to find, and then you sort of get waved off. Did this make you suspicious, or did it cause you to think maybe you were missing something? What was your human reaction here, because you’re like, “What are you talking about?”

Rachel: Yeah, there’s a lot of that. There was a lot of checking myself and re-checking myself, because it’s a lot to take when you’re the sole voice saying, “Hey, I think there’s a problem here,” and it’s an unpopular opinion. So I wouldn’t be surprised if a lot of people feel that way. The saving grace, though — and I really want to hone in on this — is that having a really good legal team is super important, because a good legal team is going to be able to coach you through all of those things: the legalistic parts of it, the technical parts of it, but also the human parts of it. And I had a great legal team, and they were really willing to say, “Hey, Rachel, we know why you’re feeling this way.” A lot of people we talked to may not have 100% of the story, or may not have everything 100% right, but if you have most of your facts, then you have a level of certainty, and then you know what you need to do. And I can derive a certain confidence from having intellectual certainty about a subject.

Jacob: Let me ask you one more question and we’ll move on. I don’t know if this is something you can say or not. Were the other voices that were waving you off, or countering what you were saying — were these, let’s say, financial voices? I mean, I would imagine a company this size has internal resources, an internal security team, all these folks. Were these other technical people? Was this an ego thing? I don’t know if you actually even know, but what was the nature? Was it just on the technical side of the house, or the business side?

Rachel: You know, it’s really common that you wouldn’t be invited to some of the decision-making conversation, because you get kind of sidelined or shut out. So I don’t actually know, and I can’t really comment on what was going through their heads at the time. I would imagine that maybe some of it is about finances, but I wasn’t a part of those conversations. I was only a part of the technical conversations and the indications and warning. I should also say, just really carefully, that Honeywell hasn’t admitted liability, and we stopped short of claiming that that company was subject to a SolarWinds intrusion.

Jacob: We’ll add that banner on the screen so everybody knows. Well, okay. So you’re doing your job, you’re taking in all this information, you’re like, “We’ve got a strong enough possibility of a problem here, we need to look into this.” You’re talking to the legal team, talking to other technical folks, doing your thing. And then it gets floated up, you’re not included in the conversation, a decision to not pursue it gets made — or just no decision gets made, so nothing happens. So at what point do you finally decide, “Hey, I’m out of options here, and something needs to happen”? At what point do you cross the Rubicon and take outside actions, if you will? What was your thought process? How did you feel? What was this like for you?

Rachel: Well, I was certainly a dissenting voice, and that put me in a certain position at the company. Having a dissenting voice led me to want to try to protect myself in the best way possible. I called a friend who is an attorney in DC, and I asked for her advice on what to do. She then referred me to an office — an attorney that actually had a record for taking cybersecurity-related cases. And that was the first step: actually protecting myself.

Jacob: Well, that’s really interesting. So did you feel like you were risking something by pursuing this, or did you feel like you were at risk if you didn’t pursue it? I think that’s maybe an interesting subtlety, because a lot of people say, “Well, it’s a big risk to pursue this legal process and blow the whistle.” But you were saying you feel isolated and pushed out and ignored, and you were at risk if you hadn’t done this.

Rachel: Yep. And from what I understand from my attorneys, those feelings are really common — for people in this position. So, to answer your question, it was exactly like that. It was, “What do I do? What happens if I do nothing? What happens if I do something?” And both those options didn’t give me a risk-free path forward. So I kind of had to choose one.

Jacob: That’s so interesting. I mean, you evaluate risk as a professional, of course. It was just a weighing of what needed to happen.

Jason: So I had just one question about the process as you were discussing. One of the things you had said earlier was, it’s really important to have a good legal team in your corner. And one thing I was always curious about: when you decide to be a relator, is it a thing of “I’m shopping around”? But you said you had a friend, and the friend was able to point you in the right direction — I’m sure that was very comforting, because that’s one less stressful thing to go through in this pathway. When it comes to the relator process — once you’ve selected your legal team and you’re like, “We’re going to file this” — what actually happens after you file?

Rachel: Well, I should say that the first lawyer I consulted with chose not to take my case.

Jacob: Oh, interesting.

Rachel: Yes. And that’s okay. At that point, I was like, “Okay, there’s nothing I can do,” and I moved on to, “How can I report this safely, without expecting any kind of blowback?” That’s really what I was looking to do, because I still felt there was a national security imperative, because of the sensitivity of the technology. I felt that what should have been done wasn’t done, and the situation hadn’t been resolved, and for those reasons — it’s very sensitive technology — it needed to be known, at least to the government customers. So it was by happenstance that I was referred to someone else who could help me with this, and that person referred me to another legal team, and they picked up my case. And that was Tycko & Zavareei. And I didn’t know what I was doing, and I was doing the best I could to try to figure out what the right move was. I knew in my gut that this was something big, and that I couldn’t just let it go — there was too much at stake. So I just kept going down the road of, “What’s the right thing to do in this situation?” And that’s what eventually led me to the legal team that I had. And this is all prior to the Department of Justice Civil Cyber-Fraud Initiative.

Jacob: Yeah. So this is why, maybe, that one attorney didn’t see a way forward — because there were too many legal hurdles to actually making something like this real. So where are we in the timeframe at this point? SolarWinds comes out — that was circa 2020. You guys get the fallout, the headlines, the IOCs, you’re working internally, and then this process of feeling more and more isolated and ignored — is that over weeks, months? Is this two years later that you finally reach out? Have you left the company? Where are we in the timeline at this point?

Rachel: Well, I was still working there. And I was actively working with a recruiter to try to find something else, which I did eventually. But at the time, I was still there, still trying to make good use of my time. And I wasn’t sure what was going to happen after that. So that’s kind of where we’re at in the timeline.

Jacob: And this was — you raised this internally, and then it got ignored in a matter of days? How long did that process take?

Rachel: It was almost immediate that there was pushback. It happened pretty quickly. So it was looked at pretty seriously, but it was quashed fairly quickly. So my concerns were kind of like a steady state, and as I found additional indicators, I would try to raise those concerns.

Jacob: Now, what’s interesting is — your story so far is about the indicators, the suspected activity, what you’re seeing, what you’re hearing. Other cases around False Claims Act settlements, people raised issues with direct non-compliance with known contract clauses. Did that get wrapped up in your understanding? Were you aware of those obligations while this conversation was happening? At what point did that come into the conversation? Was that after you left, or while this was happening?

Rachel: That was after the fact. The False Claims Act is based on the requirement that you meet a standard. So it’s not “security according to Rachel” — it’s that you have to meet a certain cybersecurity standard, and part of that is incident reporting and incident response. And so, in order to bring this in and formulate a legal case around it, it became something I had to study and learn later, because I wasn’t familiar with the NIST standard. So I had to familiarize myself with it in order to build the building blocks of saying, “Hey, this is what is wrong, and this is how I can convey, within the confines of a legal system, how something like this went wrong.” So it wasn’t so much that I was a compliance person pulling out gaps and nonconformities — it was that there was a cyber event, and in order to communicate this in a way that would be acceptable to the courts and in a legal framework, my legal team and I had to really go into the weeds into 800-171 and pinpoint exactly what went wrong, and where we should have been versus where we were.

Jason: That’s fascinating. You see this one little thread, and you pull on the one little thread, and then it starts unraveling other things — and this is what it eventually led to.

Rachel: Yeah, it doesn’t always [go that way]. What I’d really like to say is that this case is not a case of onesie-twosie gaps that were on a roadmap and weren’t remediated yet, where there was some kind of frivolous misunderstanding, that there were gaps and nonconformities with 800-171. This was a pretty extraordinary case, where there was a national-level cyber event, and very sensitive technology, and warning signs were missed.

Jacob: Yeah, it gave you the handhold to kind of go from there. Right. Okay, so you bring this up, you sort of get dismissed immediately, start feeling more and more isolated, and then this long process begins. You’re looking to leave the company, you’re talking to multiple law firms and attorneys. And one of the things people have noted about the settlement was just how long the process took. This was years of time. What were those years like? Was this constant back-and-forth, care and feeding on your part? Did you bring this up to the lawyers and they just ran with it? What was that process like?

Rachel: Yeah, the process is arduous. There was a lot of work that had to go into bringing this and pulling it together. At one point, I’m advising my legal team, like, “We need to go through every single line of 800-171 and take this — what is in a narrative format right now, in a timeline — and turn it into something codified, where we can go through something.” So that was a very long and arduous process, and once again, we were feeling around in the dark, because this was before the Civil Cyber-Fraud Initiative. Most of the work was done before that announcement. So when that announcement came out, my attorneys contacted me and said, “You’re never going to believe this.” And they told me what the initiative was. There’s a lot of cynicism around SolarWinds, and it being a case study in a failure of enforcement. It was a very, very serious cyber event — it is a private company — but in terms of recourse, there just wasn’t a lot that could go on. The SEC attempted to bring an enforcement action, and they quietly dropped that. There were a lot of reasons along the way for us to be very cynical about the possibility, and I never really believed it would be a success. I just felt like this is important enough that, however far it can go to make sure this never happens again, that’s what I need to do. And so the fact that there was a settlement — that positive outcome — came as a surprise, actually.

Jason: Interesting. Well, let’s talk about the settlement — how did it come? Was it just one day, kind of, “We’re done running”? Or a case of, “We’ve gathered all the evidence we can, and the other side is like, this is where we want to end”? What was the end of it like?

Rachel: Well, what happens with the relator is that you put all of your evidence together with your legal team, and then you submit it to the government, and it’s really up to the government to perform its own independent investigation of the allegation. So in this case, we did all of this. The Civil Cyber-Fraud Initiative was then announced — and, not to imply any causation there whatsoever — but we submitted, and then everything went quiet. And that’s because, in this case, because there were contracts that were classified, they kind of closed the door and said, “This whole case, and all of the government’s investigation, is now going to happen behind closed doors.” So I received very little information or updates. Periodically, I would be asked to provide an opinion or some supplementary documentation, but it was a lot of waiting. The complaint stays under seal, and every six months the seal gets renewed. I would receive an email — this happened for years — every six months I’d just get an email, “the seal’s been renewed.” Like, “Oh, well, that’s nice, it hasn’t been dismissed yet.” So it was just a lot of waiting. And then one day, my attorneys — I get a text message, and they said, “Well, we’ve gotten word that Honeywell and the DOJ have reached a settlement, and this is what it is.”

Jason: Wow. Now, do you feel that — settlement aside, obviously the settlement helps — but the response on all sides of the fence, does it make it worth it? Was it worth it in the long run?

Rachel: Yeah, it was worth it, because I still feel to this day that SolarWinds was one of the worst counterintelligence disasters in American history. I don’t think we even have all the details of it. So I think this was the right thing to have happen. If I had to do it all over again, I would have changed a few things. But I think I did the right thing. And that’s always been my north star.

Jacob: Yeah. That’s all anybody could ask for. I also like the fact that you can do the right thing and come out ahead. That’s rare — that’s rare out there in the world sometimes.

Rachel: I don’t think it is. I don’t think it is. I think it’s a false dichotomy, and it’s a myth to say that in order to get ahead, you’ve got to be crooked or something like that. And what I told my daughter is that you can do the right thing, and it might count against you sometimes, but it’s going to come back and benefit you later.

Jacob: There you go. Well, let’s maybe shift over. This story is fascinating — this has just been so interesting — and I think probably the most valuable thing, other than peeking into the story, is the lessons, the takeaways here. Because for a lot of people, they see the headline, they see the press release, maybe they read the settlement, they almost certainly don’t read the complaint, they don’t have this context. And the DOJ press releases are kind of aggressive — they aren’t really conveying a lot of lessons, they’re mostly freaking people out. So what should people who were in your position — in the trenches doing that kind of work — take away and learn? Is that different from what CISOs might need, from a security executive perspective, who maybe were in the room that you weren’t included in? And is that different from board members and C-suite members? How do the lessons change based on the level?

Rachel: Well, I think there are different perspectives. There’s the perspective of a practitioner, and that person has to be objective and do their best and raise concerns — put those concerns in perspective, don’t be an alarmist, don’t overblow them. I like talking in terms of risk, obviously, because risk is a gray area — it takes into account uncertainty. Sometimes you’re not 100% certain that something is a problem, but you have a certain degree, a level of certainty, and you need to convey that. My best advice to somebody who’s a practitioner: if you’re in a situation like this and you’re not being listened to, and you think there’s a bigger problem — something bigger than yourself, or bigger than your company — then seek the advice of an attorney that really knows what they’re doing, and that person can walk you through every step of the way to make sure all of the activity is completely legal, above board, and protected activity. Then you’ve got the perspective of the CISO and the board, and that’s where the risk-based decision-making and judgment really comes into play. Going back to that situation where you’ve got competing voices inside the same organization: what are you going to do with that information? And when it comes to situations where you’ve got highly sensitive defense technology and a nation-state threat actor, that combination right there — there should be no gray area. You’ve got to take that seriously, because the risk is just too high.

Jason: Yeah. So, maybe extending those lessons as well — a lot of the people who ingest this news around the False Claims Act are smaller companies, contractors. They don’t necessarily have internal teams, they don’t have counterintel folks. The C-suite at these companies are wearing a lot of different hats. What would you recommend to them? When I hear your story, I hear a lot of lawyers asking them questions, which is expensive; if the government joins the case, there’s a long process that’s involved for potentially years before anything comes out in the news. That doesn’t sound very fun. Is your advice different as the companies get smaller? I mean, they still are sometimes working with information and technologies that are just as sensitive as the Honeywells of the world.

Rachel: Yeah, absolutely. This is an American problem. We expect small businesses to stand up to nation-state threat actors — and how do you do that? I feel for small businesses that are having to deal with that. Here’s what I would say: if you are doing your best, and you’re following the rules the best you can, and you’re transparent about what you do well and what you don’t do, then — I’m not going to say you’re out of the woods, but — the situation of the government bringing a False Claims Act against a small business that’s doing its absolute best… think about that. It’s very, very rare that the government brings cases like this at all. So I would say, still adhere to the standard, do the best you can. And when your practitioners raise alarm bells, listen to them. You don’t have to be 100% sure that there’s an intrusion happening to respond.

Jason: I mean, kind of like what Jacob pointed to — in your position, you were in a position where reacting to indicators of compromise was part of your job, evaluating those and seeing where it was at. In the majority of the small businesses you just spoke to, I can almost rest assured that either they haven’t heard of SolarWinds, or they haven’t heard of indicators of compromise or what they look like. So this is a point that is just being absolutely driven home: people need to have these provisions in place to be able to identify those things, because look what it leads to.

Rachel: Yeah.

Jacob: Yeah. Well, I guess maybe we’ll wrap it up here. This is a long journey. I guess, quick question — how fun was it that your name was in the settlement, and then in the news? Because I reached out to you after I saw your name in the press release. Was that what you were expecting? Were you expecting your name to be out there and everybody to reach out? Were you anticipating that?

Rachel: It’s been a wild ride. It’s very weird. As a cybersecurity professional, most of us are pretty locked down — my LinkedIn profile was locked down, you couldn’t see my picture, you couldn’t see anything. And so I kind of had to shift, and prepare myself emotionally and mentally, for the fact that I was going from being a very private, practitioner-level individual to someone whose name is going to be in the news. So I’m still kind of reacting and responding to that. It’s interesting. Ask me in another week, I’ll probably have a different answer.

Jacob: Yeah. Well, I think you’re doing a great job. So, with that in mind, what would you tell yourself four or five years ago, knowing what you know now — or if someone’s watching this and they’re in your position, what advice would you give yourself?

Rachel: You know, I went through so much self-doubt, because in the situation you’re in, if you are the lone dissenting voice, it is very easy to have self-doubt. So if I had to reach out to myself five years ago, I would have words of encouragement. 95% of what I would tell myself would be: trust yourself, you know what you’re doing, you’re not doing this alone — you’re asking people that know what they’re doing to help you, and it’s a team effort. My instincts were right. I needed to trust myself, trust my analytical capabilities, and put some of the self-doubt to rest. Maybe the other 5% would have to do with the waiting game — say, “Hey, this is a four-or-five-year-long process before something’s going to come to a resolution. You’ve got to move on with your life, and just live your life, and let this play out. You’ve done the right thing, so just let it go, and let go of the outcome. Whatever happens, happens, and the best you can do is just do the right thing and hope for the best.”

Jason: So I’m curious — you said the self-doubt. How much of that self-doubt would not have existed if things like the Civil Cyber-Fraud Initiative existed at the time you were making this decision? Because there was nothing to support you out there, right? You’re going into uncharted territory. Even though I’m pretty sure people have raised fraud claims against the government or organizations before, there was nothing specifically pointing toward the things you were doing.

Rachel: Yeah. Had the Civil Cyber-Fraud Initiative been in place at the time, it would have made the path from A to B much more straightforward. We would have known exactly where we were going, or the path we were trying to take. We kind of had to make it up as we went, and say, “Okay, this is what the law says, so this is what should be happening,” and then make it up as we go. It would have been much simpler, I would say.

Jacob: It’s fascinating. This has been incredible. Thank you so much for sharing your story and your perspective, and the human side of what this process is like. It’s all so cold and mechanical when it’s just policies, press releases, things like that. Is there anything we didn’t ask you, or that you want to cover or tell people, before we sign off here? Did we miss anything?

Rachel: You know, I don’t think so. I would just say — I’ve had a couple people reach out to me and ask if I would talk to them about what they were seeing in different places. And if any of those people are listening, it’s not that I’m not willing to talk to you — it’s just that I probably will respond and just try to get you to talk to an attorney, because they’re going to be in the best position to evaluate something like this.

Jacob: I think that says it all, folks. This has been super interesting. Rachel, thank you for coming on and sharing your story. I hope you can go back into delightful obscurity as a cyber professional, and you don’t have to be a public persona if you don’t want to. But thanks for coming on and saying what was going on — I know it takes a lot to share your story. So thank you so much. Make sure everybody says thanks down in the comments below. If we have questions that we didn’t get to, let us know and we’ll see if we can get some follow-up answers. But this has been amazing. Thank you so much, everybody. Like and subscribe. Don’t follow Rachel — leave her alone, she’s already done enough. And we’ll see you next week.

Jason: See you next week. Thank you.

Contact

Speak With Our Team

Scroll to Top