The Digital Trojan Horse

How Quincy Castro (MBA '20) wants to design the Trojan horse out of software for good.

This summer, Christopher Nolan’s retelling of the Odyssey brought one of history’s oldest tricks back to the big screen: a giant wooden horse, left as a gift outside the walls of Troy and wheeled through the gates by the Trojans themselves. It is one of the most notable moments in the history of global warfare, a sleight-of-hand made successful because the victims willingly, yet unknowingly, sealed their own fate.

The Trojan horse trick left a lasting legacy, and its strategy has since been repurposed by adversaries who wage the online equivalent of warfare in cybersecurity. Quincy Castro, MBA ‘20, has spent time on both sides of that war, and traces it back to the vulnerability built into nearly all modern software. “Somewhere between 80 and 90 percent of any given app, on your phone or at work, is open-source software pulled in from strangers,” said Castro, “with a company's own code written on top of base code.” At its core, an application is an accumulation of other people's code carried willingly through the gate. 
 
Most of that code is harmless. The danger comes when a single piece is compromised, as the consequences are far-reaching. One component links to thousands of others and is woven through software in surprising and inconspicuous ways. This is the problem Castro has spent his career circling, and his answer is a strange one for someone on his fourth turn as Chief Information Security Officer—this time at Chainguard—where he leads security for a company working to make open source safe by default: stop inspecting the horse altogether. 

Instead, Castro imagines a world in which what is carried through the gate is safe to begin with, and the need for consistent oversight quietly disappears. “My job shouldn’t exist,” he stated, not in a declaration of modesty, but as a diagnosis of a deeper issue in cybersecurity.

Both Sides of the Wall 

Castro has spent his career gathering a rare vantage point on the problem he now aims to solve. He started at the National Security Agency, running offense from the front lines. By the time he left, he had spent years learning how the most sophisticated attackers in the world operate. He carried that into the private sector, doing security research and reverse-engineering other nations' hacking tools. He then crossed over to defense, beginning a long run of CISO roles at GE Transportation, a global transportation and manufacturing company.

Crossing that line exposed a discrepancy that still bothers him. On offense, he says, people are ninjas: sly, unshackled, unrestrained, free to work creatively and quickly. On defense, he found people “behaving—no offense to accountants—like accountants.” In other words, with a diligent, conservative, and by-the-book approach. That rigidity is baked in: the benchmark security audit used across the tech industry was born directly from financial accounting standards. That, he notes, is the problem. “The adversaries out there doing malicious stuff to technology are unshackled and unrestrained,” he says, “and yet over here, we're treating this like a bureaucratic business risk problem.”

He has worked in security his whole life, and still he pauses when asked to define what he protects. The answer is simpler than the job that surrounds it. "Security is the promise and the confidence that a system will behave as designed and as communicated," he says, "and not be susceptible to being used in ways contrary to its intended purpose."

Yet, most organizations do not treat security as a promise. Confidence stops being something built into a design and becomes something obtained retroactively, in response to one threat at a time.

"Security is the promise and the confidence that a system will behave as designed and as communicated, and not be susceptible to being used in ways contrary to its intended purpose."

— Quincy Castro, MBA '20

Working at Machine Speed

In most companies, Castro argues, security is treated as a compliance problem. A checklist, enforced by ‘traffic cops,’ there to slap wrists when a box goes unchecked. It is a mindset that made a certain kind of sense when everything moved at human speed, and there was time to hand-check the work.

But AI has changed the pace on both sides. “It makes it possible for mediocre attackers to behave with greater sophistication,” Castro explains, “chaining together weaknesses that used to demand real skill.” As frontier models start to surface entirely new categories of vulnerabilities, the asymmetry has the potential to become devastating. The effort it takes to find a flaw is a fraction of the effort it takes to fix one.

Beneath the technical threats sits a deeply human shortcoming in communication and technological fluency. Most boardrooms and C-suites, he says, are not equipped to have real conversations about trust and security, meaning the people making the biggest technological decisions often understand the least about its limitations. “Cybersecurity is the place where really geeky stuff that no one understands turns into a company-killing event in twenty-four hours,” said Castro.

A Different Kind of Security Question

Chainguard is built on the premise that most risk can be avoided with careful and precise design. Founded by former Google engineers, some with a more blunt industrial approach to technology, their guiding question was not how to optimize technology, but whether its base function was necessary, let alone operational. Most security startups, he says, take something broken and work to make it slightly less broken. Chainguard’s philosophy is the opposite: this is broken, so what if you simply did not have to do it anymore?

In practice, that means handing developers building blocks that are already secure. Codified versions of the open-source images and libraries that make up the bulk of modern software are continuously updated and delivered as a service. If the code is safe and clean before it ever reaches the user, there is nothing to scan, nothing to patch, nothing to anxiously guard. The mission, per Castro, is to make open source safe enough to use with reckless abandon.

There is a catch, and it is the same force reshaping everything else in the world. The amount of open-source code in the world is growing at unprecedented speeds, and much of it is now written by AI. It is overly ambitious to manually secure an infinitely expanding supply of code against the speed of production possible with AI. So, Chainguard uses AI to defend against the world AI is creating. 

The company recently open-sourced a framework of its own, DriftlessAF, built on a simple loop where software bots constantly compare original code against its gradual evolution and autonomously correct any observed drift. Elsewhere, its systems empower AI to make the first call on whether something looks like malware, pulling in a human, as it is necessary, to make the judgment calls. “It’s easy to forget that human beings also have their own kinds of failure modes,” he says. The goal is not to remove people, but instead to limit human focus to the questions only humans can answer.

The Strength in Being Noisy

None of this comes from an inherent security instinct, per se. It is grounded in strategic thinking, the kind that Castro traces back to his time at Booth.

He earned his MBA while running security for a multibillion-dollar manufacturer, which is its own kind of endurance test. His greatest takeaway was not another technical credential, but a refined way of thinking. Competitive strategy. Problem-solving. The willingness to look at an accepted process and ask, before contributing, whether it should exist in the first place.

For students about to walk into this unfamiliar, fast-moving version of the workforce, Castro’s advice is refreshingly unintimidating. “The best things a new graduate brings are energy, optimism, and the technical skills that have never before existed in the workforce,” he said. This is the first wave of people who moved through school fluent in AI tools; the smartest thing a leader can do is turn them loose on the inefficient, bureaucratic processes everyone else has accepted. 

So his own advice is simple: “Come on in and be a little noisy.” If something looks broken, say so. Offer the new idea. Ask the question no one else is asking.

Castro has spent a career learning how the gate that lets the online Trojan horse in gets opened, from both sides of the wall. His whole project now, at Chainguard and beyond, is to make sure that by the time the horse arrives, there is nothing hidden inside worth fearing. Even if that means—one day—designing his own job out of existence.

More from Chicago Booth