BSides evening night three

Three Days of Noise, Some Actual Signal

Writing in the first person is exhausting; normal legal and regulatory commentary resumes Friday.

My morning started with a phone call to ISSA Vancouver. We’re coordinating a speaking engagement for my upcoming September book launch of Cyber Risk is a Myth. We picked a date and they’re confirming with their board, expecting 50 to 70 CXOs. I’m planning a brief reading followed by a practical workshop so participants can start translating technical cyber risks into actual business risks. Felt good to have something on the calendar while on my second full day of BSides.

The Numbers Don’t Hold Up

The first presentation I watched challenged the breach statistics that practitioners have been repeating for years without checking if they’re true. Adrian Sanabria’s research shows 35 companies worldwide went out of business due to a breach, excluding Chapter 11 bankruptcies. This is drastically less than the often-cited statistic that “60% of companies go out of business after a breach.”

Key findings:

  • Knights of Old (UK) was the largest at 800 employees, though they were already struggling with no cash reserves before the attack
  • Best Medical Transcription closed after the owner got banned from managing any company in New Jersey (FTP server misconfigured, Google indexed patient files)
  • AMCA (American Medical Collection Agency), a regulated entity, shut down from a data leak with class action lawsuits settling for $35 million in June 2026
  • None of these companies had over $100 million in revenue; most were under 10 employees

We keep telling business leaders that breaches put companies out of business, but the data doesn’t support that claim at scale. Trust erodes when practitioners can’t back up their warnings with evidence.

Red Teams Work Differently Than You Think

The second session analyzed 95 engagements and roughly 6000 commands that operators actually ran during testing. Every command got logged, consolidated via LLM, then manually reviewed to confirm there weren’t hallucinations in the output.

The findings contradict popular narratives:

  • Attacks unfold as spirals where operators find credentials, exploit them, discover more, repeat until hitting the target
  • Average of 12 attempts before finding anything useful
  • Lateral movement fails almost 60% of the time
  • BloodHound, SharpHound, and netexec account for about a third of environmental reconnaissance

Advice for blue teams:

  • The best operators also don’t generate the most noise; they execute the fewest commands
  • Blue teams watching for port scans are monitoring distraction while missing concentrated authentication failures from single sources against multiple targets
  • Host naming conventions help attackers move faster once they reverse engineer the pattern from IP addresses
  • Instead of obsessing over scan traffic, defenders should monitor DNS and NetBIOS queries, particularly from a single source on the network

Buyers Are Getting Wiser

Between sessions, conversations with CISOs revealed a continuing sense of exhaustion. People buying security tools increasingly feel forced to accept risk, deciding which risk is “least bad” rather than which solution is best.

  • Policy-review platforms promising to read contracts and flag obligations are being replaced by Claude doing the same work cheaper
  • DSPM (data security posture management) will likely grow through the foreseeable future
  • Private conversations continue to show skepticism about how long the AI bubble will last, though nobody mentions it at Black Hat itself

And a friend offered introductions to company founders for my job search. Small moments like that matter more than polished pitch decks.

The Human Stuff in Vegas

Happy hour at BSides featured a twenty-minute wait for a single glass of wine. For once the BSides queue was worse than Black Hat’s, though the hotel lobby bar stayed nearly empty; I’m guessing people wanted to stay around other cybersecurity professionals.

An invite-only steakhouse dinner started around seven o’clock and didn’t end until after ten. Before dinner even began, I watched a man at the bar repeatedly put his hands on a friend of mine, the hem of her dress, her knee, her outer thigh, her shoulder, despite getting nowhere. This guy wasn’t from our industry; I think he was a car dealer, though he also said he was a cybersecurity investor and that his wife had “top-secret” clearance that gave him “inside knowledge” on which companies to invest in. In between, he pushed his business card and phone number on her. This was deeply uncomfortable for me to watch, probably worse for her. When I checked in, she waved it off and said she was fine. Later, privately, she explained how exhausting it is to try to please everyone, and how that dynamic leads to exactly these interactions.

An impromptu bar tour followed. The Chandelier Bar at the Cosmopolitan was nicest despite the crowds. By comparison, Circle Bar at Mandalay felt like an overcrowded airport with bright overhead lights and a dull roar.

I got back to the hotel just after one in the morning. My room was far enough from the pool to escape the sounds from the karaoke party that was still running.

Three days of presentations, conversations, and awkward bar encounters. The presentations showed data contradicting what we collectively tell ourselves we “know”. The buyers showed skepticism about nearly everything the industry sells. And the bars showed us the human side, as well as the genuine struggles people are going through. We should pay attention to all three.

Similar Posts