Success in cybersecurity is when nothing occurs, plus different standout themes from two of the occasion’s keynotes
07 Aug 2025
•
,
3 min. learn

The 2025 version of the Black Hat USA convention kicked off with an deal with from founder Jeff Moss that featured a number of thought-provoking feedback.
Amongst different issues, he remarked that expertise has turn out to be political and pointed to geopolitical sanctions and bans that restrict cooperation and hit revenues, in the end slowing down innovation. In some cases, there could also be grounds to restrict the usage of some applied sciences, however referring to expertise as political actually grabbed my consideration.
One other remark was extra philosophical: do firms adapt to the tradition of expertise or do they adapt expertise to their tradition? This query is very related right this moment, as we will all relate to moments once we see an organization change path to maximise earnings on the expense of the shopper.
In my expertise, customer support is sort of at all times a chief goal for price saving – from outsourcing a name heart to low-cost labor markets by to right this moment’s use of generative AI methods because the preliminary level of contact, which successfully creates a self-help barrier to reaching a human consultant.
It’s necessary that firms suppose critically in regards to the tradition query posed. Do they need expertise to dictate or form how prospects view the corporate tradition, or do they wish to preserve the perceived tradition? The latter might require much less expertise and extra human interplay, or only a extra considerate method of deploying expertise.
As AI turns into extra widespread, the tradition query turns into much more necessary. Within the hours main as much as the convention, I skilled this firsthand: I requested the AI chatbot at my resort resort at what time the fitness center opened, and it answered promptly: 6 a.m. – 6 p.m. Then I requested the place the fitness center was situated, and the chatbot answered that it doesn’t have the reply to this and instructed me to contact the entrance desk. An interplay with a human supplied a unique response: the fitness center is open 24/7 and it’s on the threerd ground. To sum up, the service from the AI automated system was inaccurate and unhelpful, and for me it mirrored on the resort model.
Who’s accountable?
In the meantime, the keynote by cybersecurity veteran Mikko Hypponen was largely a historical past of his profession in malware analysis. As with Jeff’s deal with, there have been two fascinating feedback that caught my consideration.
First, Mikko challenged the attitude that each time a person clicks on a phishing hyperlink, the blame is often positioned squarely on the person, with the dialog then turning to the necessity for extra cybersecurity consciousness coaching.
Mikko put a unique spin on this, nevertheless, and identified that the failure is definitely with cybersecurity methods, as a result of the hyperlink ought to by no means have reached the person within the first place. That is an fascinating remark, as once we learn an article a few safety incident, we hear of it beginning with a person clicking on a hyperlink. It by no means mentions it was a hyperlink that the cybersecurity crew didn’t cease from attending to the person.
Then one other nice level – success in cybersecurity is when nothing occurs. It is a true however weird paradox that I do know many shopper cybersecurity distributors grapple with, as they want the shopper to know that their product is working and including worth.
For me, although, the remark sparked one more thought: do firms cut back their cybersecurity funding if all of the threats are detected and nothing occurs, in the end rising the danger of a cyber-incident? And with declining funding, will we re-enter the cycle of profitable cyberattacks, inflicting disruption and better cyber danger premiums, which then drives additional funding in cybersecurity and we turn out to be trapped in a endless cycle?
Mikko, a three-decade veteran of the cybersecurity business, concluded his keynote with an announcement that he’s departing the business and becoming a member of a protection contractor. I want him one of the best of luck with the brand new endeavor.