39:51Let us have a VERY frank conversation
Download resourcesAbout this session
Chris Roberts, adversarial researcher and self-described hacker, delivers the blunt state-of-the-industry talk he retitled Thanos Was Right. He argues that security keeps failing because it ignores how humans learn by touching the stove: after decades of awareness, 123456 still tops the password lists, attackers collaborate globally and only need to be lucky once, while defenders drown in incompatible tools, alert fatigue and vendor promises of total security. Spending has reached roughly 124 billion dollars a year, breaches still take around 197 days to detect, and a ransomware-linked death has just occurred in a German hospital. After dismissing the Thanos snap, AI and head-in-the-sand as options, he proposes four Cs: communicate, cooperate, coordinate and collaborate. In practice that means dropping jargon such as Kali, ponies and pineapples, bringing coffee and tabletop exercises to legal, finance and manufacturing, sharing scams and incident details with peers immediately, fixing people and process before technology, unplugging for mental health, and looking in the mirror rather than blaming hackers or nation states after a breach.
Information Security is at a painful point in its development. It has failed to deliver on many of its promises. It has held itself up as the savior to businesses and has spectacularly failed to deliver. The industry is rife with misinformation, marketing hype and false promises, how DO we navigate through this, what and how do we see the woods for the trees AND how (as an industry) do we regain trust from those charges we have so far failed to protect?
This is going to be a series of blunt statements, followed by some home truths on what AND how we have to fix our industry. How we leave security behind and talk risk, how we collaborate AND change our approach and language when dealing with businesses AND how we change the symmetry and focus from one of attack to asymmetric defense. What and how we do that will be discussed.
Key takeaways
- Stop touring the business with acronyms; explain risk in plain language (Randall Munroe's Thing Explainer is the model) and rehearse a 30-second elevator pitch for the C-suite.
- Trade part of the pen-test budget for tabletop exercises run with legal, finance and manufacturing over coffee; that is where the relationships an incident will need get built.
- When you get hit, share the scam or attack pattern with peers in your sector right away over a secure channel instead of waiting months for ISAC or government bulletins.
- Fix people and process before buying more technology: name who is accountable, write the incident-response plan before the breach and train more often than once a year.
- Protect your own capacity: block off unplugged hours and one day off per week, and lean on the Mental Health Hackers community when it gets heavy.
Speakers

Chris has most recently been working on several projects within the deception, identity, cryptography, and services space. Over the years, he founded or worked with a number of organizations specializing in OSINT/SIGINT/HUMINT research, intelligence… Read moreRead less
Chris has most recently been working on several projects within the deception, identity, cryptography, and services space. Over the years, he founded or worked with a number of organizations specializing in OSINT/SIGINT/HUMINT research, intelligence gathering, cryptography, and deception technologies. Lately, he has been working on spreading the risk, maturity, collaboration, and communication word across the industry. Since the late 90s, Chris has been deeply involved with security R&D, consulting, and advisory services in his quest to protect and defend businesses and individuals against various types of attack. He is considered one of the world’s foremost experts on counter threat intelligence and vulnerability research within the Information Security industry.
