Letter signed by Kelvin Taylor, Senior Agency Information Security Officer (SAISO), NASA Office of Chief Information Officer (OCIO). Mary W. Jackson NASA Headquarters, Washington, DC 20546-0001.

Most cybersecurity certifications are a piece of paper. An exam, a fee, a printed certificate. This is not. On April 28, 2026, I received formal correspondence from the National Aeronautics and Space Administration — signed by Kelvin Taylor, Senior Agency Information Security Officer (SAISO) at NASA OCIO — recognizing my work as an independent security researcher.
Your reporting has facilitated NASA's awareness of otherwise unknown vulnerabilities and helped us protect the integrity and availability of NASA information.
— Kelvin Taylor — Senior Agency Information Security Officer, NASA OCIO
What Happened
Operating under the handle l1ghtn1ng, I identified a vulnerability in NASA systems and followed the correct protocol: responsible reporting through the agency's Vulnerability Disclosure Policy (VDP). No exploitation. No premature public disclosure. The playbook of what a serious security researcher does.
The result: NASA formally acknowledged the discovery, fixed the vulnerability, and sent an official letter of appreciation. Not a digital badge. Not a website "hall of fame." Official U.S. government letterhead with a handwritten signature.
Why This Matters
Real cybersecurity is not about having the right certificate on the wall. It's about finding what others didn't, in systems others assumed were secure. NASA operates critical infrastructure — satellites, communications systems, mission data — with security standards that very few organizations in the world ever need to meet.
- Vulnerability identification in U.S. federal government infrastructure
- Responsible reporting following VDP — the most rigorous standard of coordinated disclosure
- Formal recognition by the SAISO, NASA's highest information security officer
- Zero exploitation, zero data exposure — researcher ethics, not attacker mindset
What This Says About Who Builds IronBit
IronBit — CSX Tech's cybersecurity vertical — is not run by someone who learned about security from online courses. It's run by someone who found vulnerabilities in systems NASA assumed were secure. There's a difference. A massive difference.
My security trajectory has passed through international commerce systems, high-criticality financial platforms, and U.S. government infrastructure. Each context with its own attack vectors, its own exposure surfaces. The common denominator: find it before the adversary does.
Real security — what separates research from compliance
What is the NASA Vulnerability Disclosure Policy (VDP)?
Clique para ver a respostaA formal NASA program to receive vulnerability reports from independent researchers. It follows the most rigorous coordinated disclosure standards — the researcher reports privately, NASA fixes it, and both protect the ecosystem.
What's the difference between bug bounty and VDP?
Clique para ver a respostaBug bounty pays for vulnerabilities. VDP is about ethical duty — reporting even without financial reward, because the integrity of the infrastructure matters more than the check. NASA operates a VDP, not a bounty.
Why are government systems the hardest to compromise?
Clique para ver a respostaBecause they operate with multiple layers of defense, continuous monitoring, and teams dedicated exclusively to security. Finding a vulnerability there requires a technical level that most professionals never reach.
What does "l1ghtn1ng" mean as a researcher handle?
Clique para ver a respostaIt's the identifier under which Victor Fornitani operates as an independent security researcher — separate from his executive roles, but directly informing the technical depth he brings to IronBit and every ecosystem he architects.
Mary W. Jackson NASA Headquarters, Washington, DC. Kelvin Taylor, SAISO. April 28, 2026. This isn't on any standard résumé — because most people never had a reason for it to be.
We are all in this together as a security community and your participation and expertise is commended.
— NASA · Vulnerability Disclosure Policy — Official Letter, 04/28/2026
