Skip to content

Just Risky Enough

We shouldn't be bolting yet more defensive bloat onto a structurally broken ecosystem. We should be fixing the underlying architecture so we can manage risk relative to reward directly.

The most glaring omission from Black Hat last week was any recognizable concept of risk management. This shouldn't surprise anyone—the Black Hat "Business Hall" long ago morphed into an even grander monument to our industry's abject failure than RSA has been for decades.

To understand why, you have to look at how we treat failure.

I’m a fan of failure. Failure is the fastest way to learn; it is the natural state of human progress. Failing is what gives you the impetus to get up, adjust, and try again. It’s how babies learn to walk, and how engineers build rockets. Working to ensure that failure never happens simply guarantees locked-in, perpetual paralysis.

But "failure as a feature" requires actually learning from the crash. Growth requires autopsy.

The security community gets this. Back in the day, I had the privilege of participating in the DEF CON Comedy Jam (aka "The Fail Panel") IV V VI VII with a distinguished group of colleagues—a painfully frank, public analysis of the catastrophic ways we’d failed as individual practitioners over the preceding year. I brought that format back to SecTor in Toronto and have moderated 14 editions of it since. The community actively tries to learn.

The security industry, however, aggressively refuses to.

Delivered more in sorrow than in anger, the Security Industry perpetuates the very problems it creates, conveniently selling subscription licenses to cure the diseases it helped spread. It’s global racketeering—a $250 billion protection scheme predicted to top $800 billion by 2036.

Everything the industry pushes locks customers into post-implementation prevention (AI Pentesters!) and post-event detection (AI SOC!), completely bypassing the question of whether we should be building fragile systems in the first place.

Consider the Apollo 14 heat shield. Coming hot into the atmosphere, that capsule took a beating—scarred within a fraction of an inch of its capacity to survive. That shield thickness wasn't an accident; it was a calculated risk born of experimental failure. Make it thicker, and the spacecraft is too heavy to reach orbit. Make it thinner, and the crew burns up. They had to balance mission success against the terror of failure within a razor-thin margin.

As an industry, we are terrified of finding that balance. So instead of engineering better capsules, we just bolt five tons of extra lead onto the outside, pass the bill to the customer, and act shocked when the rocket can't lift off. We stay locked exactly where the vendors want us: terrified, helpless, and reaching for whatever multi-tenant security blanket they're hawking this quarter.

The average practitioner’s fear of failure is simple: "I’m going to get fired." That’s a heavy personal cost, but it pales in comparison to the costs we cheerfully externalize onto the public.

When credit card data gets compromised, the card issuer incurs a cost, sure—but so do you. You spend hours updating subscriptions, resetting password managers, and dealing with administrative friction. We all pay for PCI-DSS compliance in higher merchant fees, only to end up in Las Vegas in 2026 being handed a pen to complete a "chip and signature" transaction. Go re-watch the PCI Panels from DEF CON 15 years ago (in 2010 and 2011) and tell the class what has fundamentally changed. (Spoiler: Nothing.)

We shouldn't be bolting yet more defensive bloat onto a structurally broken ecosystem. We should be fixing the underlying architecture so we can manage risk relative to reward directly. Imagine building inherently self-securing systems and directing capital toward actual innovation rather than lining vendor pockets.

We can do better. And while we work on that, someone should start drafting the RICO indictment.

Latest