Sarah Gordon is a computer security researcher whose work bridges the technical, social, and ethical dimensions of computing. From pioneering virus research in the 1990s to contemporary investigations of artificial‑intelligence (AI) ethics, her career exemplifies a multidisciplinary approach to safeguarding digital systems and the people who use them.
Why Sarah Gordon Matters <a name="why-sarah-gordon-matters"></a>
In the early days of computer security, most research treated malware as a purely technical problem—code that needed to be detected, removed, or patched. Sarah Gordon challenged that view. She argued that virus writers, hackers, and the broader social context of computing demanded a multidisciplinary lens that incorporated psychology, linguistics, and ethics.
Her insistence on looking beyond binaries (virus / non‑virus) helped shape modern threat‑intel practices, user‑centric security design, and the emerging field of AI safety. By tracing the evolution of her contributions—from macro‑virus discovery to AI‑ethics scholarship—we can see how a single researcher’s perspective can ripple through decades of technological change.
Early Academic Foundations (Late 1980s – Mid‑1990s) <a name="early-academic-foundations"></a>
The late 1980s and early 1990s marked a period of rapid expansion in personal computing. As networks grew, so did the opportunities for malicious software. Gordon’s early scientific work focused on the human side of this emerging threat landscape.
- People‑Computer Relationship: Her research explored how users understood, mis‑understood, and interacted with malicious code. By treating virus writers as social actors rather than abstract bugs, she opened a dialogue about motivations, communication patterns, and cultural factors that influence security breaches.
- Multidisciplinary Approach: Gordon was among the first computer scientists to formally propose that computer security should be studied alongside sociology, psychology, and linguistics. This proposal pre‑dated the now‑common term “human‑centric security” and anticipated later frameworks such as usable security and security awareness programs.
These early contributions set the stage for the concrete technical breakthroughs that would follow in the mid‑1990s.
Pioneering Virus Research <a name="pioneering-virus-research"></a>
Microsoft macro‑virus breakthroughs (1995) <a name="microsoft-macro-virus"></a>
In 1995, the prevailing belief among many security professionals was that email could not be used to deliver a virus. Gordon’s investigations directly contradicted this myth. She identified two of the first “concept viruses” for Microsoft products, demonstrating that:
- Email could indeed serve as a delivery vector.
- Microsoft Word was vulnerable to macro‑based malware.
These findings were critical for two reasons:
- Technical Impact: They forced Microsoft and other software vendors to reconsider macro security settings, leading to the introduction of warning dialogs and macro‑execution restrictions that are now standard.
- Social Impact: By exposing the human‑error component—users enabling macros without understanding the risk—Gordon highlighted the importance of user education, a theme that would recur throughout her career.
First report on Linux viruses in the wild <a name="linux-viruses"></a>
While Windows‑focused research dominated headlines, Gordon turned her attention to the open‑source ecosystem. She authored the first report on Linux viruses in the wild, establishing that:
- Linux, despite its reputation for robustness, was not immune to malicious code.
- The social dynamics of open‑source communities (code sharing, package repositories) created distinct attack surfaces.
This report broadened the security community’s view of threat actors and underscored the need for cross‑platform vigilance.
Introducing a New Lexicon for Security <a name="new-lexicon"></a>
Beyond her empirical work, Gordon contributed several terminological innovations that persist in security discourse:
| Term | Definition (as introduced by Gordon) | Relevance |
|---|---|---|
| vX | Short for Virus Exchange – a conceptual space where virus writers share code, techniques, and motivations. | Provides a linguistic shortcut for discussing underground malware communities. |
| trigger foot | A phrase describing the precise user action that activates a malicious payload (e.g., clicking a link, enabling macros). | Emphasizes the human component in exploit chains. |
| meaningfulness | The perceived relevance or purpose a user attributes to an interaction, influencing whether they follow a malicious cue. | Bridges cognitive psychology with security engineering. |
Gordon’s fascination with linguistics gave her a unique ability to name abstract phenomena in ways that resonated with both technical and non‑technical audiences. These terms have been adopted in conference talks, academic papers, and even some industry threat‑intel reports.
From Industry to Academia <a name="industry-to-academia"></a>
Although Gordon’s research has always been academically oriented, she accumulated practical experience at several notable security firms:
- Dr. Solomon's Software – early exposure to commercial anti‑virus product development.
- Command Software – work on intrusion detection prototypes.
- IBM Research – collaboration on large‑scale security analytics.
- Symantec Corporation – contribution to signature‑based detection strategies.
These roles enriched her perspective, allowing her to test theoretical ideas against real‑world constraints. In 2004, she was appointed to the computer science graduate faculty of the Florida Institute of Technology, where she began mentoring the next generation of security scholars.
A Multidisciplinary Turn: Human Behaviour & Security <a name="multidisciplinary-turn"></a>
Gordon’s educational background reflects her interdisciplinary ethos:
- Bachelor of Science (1997) – Indiana University South Bend.
- Master’s degree in Human Behaviour and Professional Counseling – (institution not specified).
- Ph.D. in Computer Science – Middlesex University.
The master’s training in human behaviour equipped her with counseling techniques and psychological theory, which she later applied to security awareness and user‑centric design. Her Ph.D. research continued to blend computer science with social science, reinforcing the thesis that technology cannot be secured in isolation from its users.
Current Focus: AI Ethics, Testing, and Emotional Mimicry <a name="current-focus"></a>
In the 2020s, Gordon pivoted toward the ethical implications of artificial‑intelligence technologies. Her current research agenda concentrates on three interrelated strands:
- Ethical Implications of AI Technologies – assessing how AI systems can reinforce bias, privacy violations, or unintended societal harms.
- Testing and Evaluation of AI Systems – developing rigorous methodologies to verify that AI behaves as intended across diverse scenarios.
- Risks of Emotional Mimicry in Human–AI Interaction – investigating how AI that simulates empathy or emotion can mislead users, create attachment, or be exploited for manipulation.
These topics echo her earlier emphasis on human perception and meaningfulness. By scrutinizing how AI systems appear trustworthy, Gordon seeks to prevent the same kinds of social engineering attacks she once documented in the realm of viruses.
Recent Publications (2024‑2025) <a name="recent-publications"></a>
Gordon’s latest contributions demonstrate her continued relevance:
- Built to Be Believed (Leanpub, 2024) – a book that explores why users often accept AI outputs without question, drawing parallels to the “trust‑by‑default” mindset that facilitated early macro‑virus spread.
- “Built to Be Believed” (Virus Bulletin, August 2025) – an article that expands on the book’s themes, providing concrete case studies of AI‑driven phishing campaigns and recommendations for designing systems that encourage healthy skepticism.
Both works synthesize her decades‑long expertise in security, linguistics, and human behaviour, positioning her as a thought leader at the intersection of cyber‑security and AI safety.
Legacy and Influence on Computer‑Security Culture <a name="legacy"></a>
Sarah Gordon’s career can be distilled into three enduring pillars:
- Human‑Centric Threat Modeling – Modern frameworks such as ATT&CK and MITRE’s CAPEC now incorporate social engineering and user behavior as core components, a trajectory traceable to Gordon’s early advocacy.
- Terminology that Shapes Discourse – The terms vX, trigger foot, and meaningfulness have entered the lexicon of security researchers, facilitating more precise conversation about attacker ecosystems and user interaction.
- Bridging Security and AI Ethics – By applying the same multidisciplinary lens to AI, Gordon has helped seed the nascent field of AI safety, influencing policy discussions, industry best practices, and academic curricula.
Her blend of technical discovery (macro‑virus and Linux virus research) with social insight (multidisciplinary approach, linguistic contributions) makes her a rare exemplar of a scholar who both discovers and interprets threats.
Relation to Apiary’s Mission (optional) <a name="apiary"></a>
Apiary focuses on bee conservation and self‑governing AI agents. While Gordon’s work does not directly involve bees, her research on ethical AI and human‑AI interaction aligns with Apiary’s commitment to responsible, self‑governing AI. Lessons from her studies on emotional mimicry can inform the design of AI agents that manage ecological data (e.g., pollinator monitoring) without misleading stakeholders—a subtle but valuable synergy.
FAQ <a name="faq"></a>
What early technical achievement made Sarah Gordon a notable figure in virus research? She discovered two of the first “concept viruses” for Microsoft products in 1995, proving that viruses could be transmitted via email and that Microsoft Word was vulnerable to macro viruses.
Which term did Gordon coin to describe a community where virus writers exchange ideas? She invented the term vX, short for Virus Exchange.
What is the focus of Gordon’s recent AI‑related publications? Her recent work, including the 2024 book Built to Be Believed and a 2025 Virus Bulletin article of the same title, examines why users tend to trust AI outputs, the ethical risks of emotional mimicry, and how to test AI systems rigorously.
When did Sarah Gordon join the graduate faculty at the Florida Institute of Technology? She was appointed to the computer science graduate faculty in 2004.
What academic degrees does Sarah Gordon hold? She earned a B.S. from Indiana University South Bend in 1997, a master’s degree in Human Behaviour and Professional Counseling, and a Ph.D. in Computer Science from Middlesex University.