Keynote: Democracy's Biggest Year: The Fight for Secure Elections Around the World
Unknown
Black Hat USA 2024 · Day 1 · Briefing
Overview
This article delves into the opening address delivered by Jeff Moss, the esteemed founder of Black Hat, which preceded the keynote panel titled "Democracy's Biggest Year: The Fight for Secure Elections Around the World" at Black Hat USA. While the keynote panel itself focused on election security, Moss's introductory remarks served as a powerful prelude, shifting the audience's perspective from traditional cybersecurity threats to a broader, more volatile landscape. His address centered on the accelerating pace of global events and the emergence of a "new bucket of problems" that challenge conventional organizational risk management and business continuity strategies.

Key moments
- 0:00 Welcome to Black Hat USA and opening remarks
- 0:40 Speaker notes: 'Things have sped up' in the world
- 1:00 Geopolitical shifts creating new, unexpected business risks
- 1:20 Supply chain risk: what if a key tech source mobilizes?
- 2:00 Case study: supporting a Kyiv-based development team during war
- 2:45 Key takeaway: employee communication and job duplication for resilience
Keynote: Democracy's Biggest Year: The Fight for Secure Elections Around the World
Speakers: Jeff Moss, Founder, Black Hat
Conference: Black Hat USA
YouTube: https://www.youtube.com/watch?v=vJxxzWgqlCQ
Overview
This article delves into the opening address delivered by Jeff Moss, the esteemed founder of Black Hat, which preceded the keynote panel titled "Democracy's Biggest Year: The Fight for Secure Elections Around the World" at Black Hat USA. While the keynote panel itself focused on election security, Moss's introductory remarks served as a powerful prelude, shifting the audience's perspective from traditional cybersecurity threats to a broader, more volatile landscape. His address centered on the accelerating pace of global events and the emergence of a "new bucket of problems" that challenge conventional organizational risk management and business continuity strategies.
Moss highlighted how geopolitical instabilities, such as the ongoing conflict in Ukraine and tensions in the Middle East, are no longer abstract concerns but direct, immediate threats to enterprise operations, supply chains, and workforce stability. He challenged the cybersecurity community to recognize and prepare for these unforeseen risks, which often lack established playbooks. The talk underscored the critical need for organizations to integrate geopolitical foresight into their strategic planning, emphasizing that the traditional scope of cybersecurity must expand to encompass these complex, non-technical externalities.
The significance of Moss's address lies in its timely call to action, urging security professionals and business leaders to re-evaluate their understanding of risk in an increasingly interconnected and unpredictable world. By sharing poignant real-world anecdotes of companies grappling with workforce mobilization, supply chain disruptions, and the unprecedented need to internally "attack" their own data due to sanctions, Moss illustrated the profound impact of global volatility. This perspective is crucial for an industry often focused on technical vulnerabilities, prompting a necessary introspection into organizational resilience against a backdrop of rapidly evolving global dynamics.
Background
▶ Watch: Welcome to Black Hat USA and opening remarks (0:00)
The context for Jeff Moss's remarks is a world experiencing unprecedented geopolitical flux, a sentiment he encapsulated by asking the audience, "who feels like things have sped up?" This acceleration, he posited, is driven by major international events including the Russian invasion of Ukraine, escalating tensions in the Middle East, and the critical importance of elections worldwide. These events create a ripple effect, translating abstract political instability into concrete operational challenges for businesses globally. The problem, as Moss articulated, is that organizations are encountering "a whole new bucket of problems [they] didn't even know [they] had," for which existing risk management frameworks and playbooks are often inadequate or entirely absent.
Prior work in cybersecurity risk management has traditionally focused on technical threats like malware, data breaches, and infrastructure vulnerabilities, alongside internal risks such as human error or insider threats. While supply chain security has gained prominence, it typically centers on software integrity, open-source vulnerabilities, and third-party vendor assessments from a technical standpoint. Moss's address, however, pushed beyond these established boundaries, highlighting how geopolitical events introduce a fundamentally different category of risk: the physical and legal availability of human capital, the operational viability of development centers in conflict zones, and the legal mandates to sever ties with entities in sanctioned regions. This represents a significant paradigm shift, compelling organizations to consider macro-level geopolitical factors as direct inputs to their micro-level operational and cybersecurity strategies.
The underlying reason this "new bucket of problems" exists is the deep globalization of technology development and supply chains, coupled with the resurgence of interstate conflict and economic warfare. Companies have distributed their operations, development teams, and sourcing across the globe to leverage talent and optimize costs, inadvertently exposing themselves to regional instabilities. When a nation mobilizes its workforce, imposes travel bans, or faces international sanctions, these geographically distributed operations become immediately vulnerable. Moss's examples vividly illustrate this: a critical software development team located in a country at war, the sudden unavailability of sales engineers due to national service requirements, or the legal imperative to delete intellectual property from a sanctioned region. These scenarios demand a proactive, geographically aware, and ethically complex approach to risk that many organizations are only now beginning to conceptualize, let alone implement.
Key Findings
▶ Watch: Geopolitical shifts creating new, unexpected business risks (1:00)
Jeff Moss's introductory remarks, while not presenting formal research findings, offered several critical observations and insights into the evolving landscape of organizational risk. These can be distilled into key findings that challenge conventional cybersecurity and business continuity paradigms:
- Accelerated Geopolitical Risk as a Direct Business Threat: The most overarching finding is the palpable acceleration of global events and their direct, immediate impact on business operations. Moss noted a collective feeling that "things have gotten faster, right? Like the severity of things have sped up." He explicitly linked this acceleration to geopolitical events like the Russia-Ukraine conflict, the Middle East, and elections, emphasizing that these macro-level events now directly translate into micro-level business disruptions, creating "a giant bucket of other problems that's making me feel like things are speeding up. Like what do you mean I have all these risks I didn't know about?" This signifies a shift where geopolitical stability is no longer a peripheral concern but a central pillar of operational resilience.
- Vulnerability of Geographically Concentrated Talent and Supply Chains: Moss presented compelling anecdotes illustrating the extreme risks associated with concentrating critical functions, particularly software development and technical support, in geopolitically unstable regions. He cited the example of a widely used security product company whose entire development team was based in Kyiv, Ukraine. When developers faced mobilization, the company confronted an existential crisis, highlighting the fragility of a single-point-of-failure strategy for critical talent. Similarly, the hypothetical scenario of Israel mobilizing its workforce raised questions about the continuity of software updates and support for technology sourced from the region, underscoring the vulnerability of global supply chains to regional conflicts.
- The Emergence of Unprecedented Operational Challenges Lacking Playbooks: The talk revealed scenarios for which no standard operational playbooks exist. The most striking example was a company with a significant development team and critical intellectual property (IP) in Russia. Facing imminent sanctions, the company found itself in the extraordinary position of needing to "build an offensive team outside of Russia inside their company to attack their own company to delete their own company's data while bypassing their own company's security team in Russia." This extreme measure, born out of geopolitical necessity, demonstrated a level of operational complexity and ethical dilemma entirely outside traditional risk management frameworks. As Moss noted, "the CISO was like, nobody there's there's no playbook for that."
- The Criticality of Transparent Employee Communication in Crisis: Amidst these complex challenges, Moss highlighted a surprisingly fundamental, yet often overlooked, finding: the power of honest and empathetic communication with employees. In the case of the Kyiv-based development team, the company's decision to have an "honest conversation with the employees and saying it's super stressful for you, we understand that, we want to support you, we want to duplicate some of these job responsibilities outside so if you do have to get mobilized, the company survives so then after mobilization, you still have a company to come back to," proved to be "the most important thing." This approach fostered trust, allowed employees to focus, and was crucial for the company's survival and continuity. It underscores that human factors and ethical leadership are paramount in navigating geopolitical crises.
These findings collectively urge organizations to move beyond a purely technical view of cybersecurity and risk, embracing a more holistic, geographically aware, and human-centric approach to resilience in an increasingly volatile global environment.
Technical Deep Dive
▶ Watch: Supply chain risk: what if a key tech source mobilizes? (1:20)
This introductory address by Jeff Moss focused on broader geopolitical and organizational risks and the acceleration of global events. As such, it did not delve into specific technical content, code, protocols, or architectures. The discussion remained at a strategic and operational level, exploring the impact of geopolitical factors on business continuity and risk management rather than presenting technical vulnerabilities or solutions.
Demo / Proof of Concept
▶ Watch: Case study: supporting a Kyiv-based development team during war (2:00)
As an opening keynote address, this segment did not include a demonstration or proof of concept. The speaker's objective was to set the stage for the conference and the subsequent keynote panel by highlighting critical, emerging challenges facing the cybersecurity community and global businesses.
Defensive Implications
▶ Watch: Key takeaway: employee communication and job duplication for resilience (2:45)
Jeff Moss's introductory remarks, while not technical, carry profound defensive implications for organizations grappling with an increasingly complex global landscape. Defenders must broaden their perspective beyond traditional cyber threats to integrate geopolitical risk into their security posture and business continuity planning.
- Geopolitical Risk Integration into Enterprise Risk Management (ERM): Organizations must formally integrate geopolitical risk assessments into their broader ERM frameworks. This means proactively identifying regions where critical assets, data, or personnel are located and assessing the political stability, potential for conflict, and regulatory changes (e.g., sanctions) in those areas. This isn't just about identifying a nation-state actor; it's about understanding the operational impact of a nation-state's actions on your business. Security teams should collaborate closely with legal, compliance, and geopolitical intelligence teams to develop a comprehensive risk picture.
- Diversification and Resilience of Supply Chains and Workforce: The anecdotes regarding development teams in Kyiv and technology sourcing from Israel highlight the critical need for geographical diversification.
- Supply Chain Resilience: Companies must map their entire technology supply chain, identifying critical components, software vendors, and service providers. For each, assess the geopolitical stability of their operational locations. Develop strategies for diversifying suppliers, maintaining multiple vendor relationships, and establishing clear contingency plans for alternative sourcing or in-house development if a primary supplier becomes compromised or unavailable due to geopolitical events. This extends beyond software vulnerabilities to vendor viability and continuity of service.
- Workforce Resilience: For critical functions like software development, security operations, and technical support, organizations should avoid concentrating talent in single, potentially volatile regions. Implement distributed workforce models, cross-train teams across different geographies, and develop "follow-the-sun" models to ensure continuity. This requires investing in robust, secure remote work infrastructure and collaboration tools, as well as legal frameworks for international employment and data access.
- Proactive Contingency Planning for Unprecedented Scenarios: The example of a company needing to "attack their own company to delete their own company's data" due to sanctions underscores the need to plan for scenarios that lack traditional playbooks. Defenders must engage in advanced scenario planning, asking "what if" questions that extend beyond typical threat models. This includes:
- Data Sovereignty and Exfiltration: Understand where critical data resides, its legal jurisdiction, and develop mechanisms for rapid, secure data migration or deletion if required by sanctions or geopolitical shifts. This might involve robust data classification, encryption at rest and in transit, and granular access controls.
- "Offensive" Defensive Strategies: While extreme, the idea of an internal "offensive" team to protect IP from falling into the wrong hands (or to comply with sanctions) suggests a need for highly specialized capabilities. This could involve developing secure deletion protocols, remote access revocation procedures, and legal frameworks for such actions, all while navigating internal security controls.
- Legal and Compliance Preparedness: Companies need robust legal counsel to navigate rapidly changing international sanctions, data residency laws, and export controls. Security teams must be aware of these legal obligations and how they translate into technical requirements.
- Prioritizing Employee Welfare and Transparent Communication: The success story of the Kyiv development team emphasizes the human element of resilience. Defenders, often focused on systems, must also advocate for and participate in strategies that prioritize employee well-being and maintain trust during crises.
- Crisis Communication Plans: Develop clear, empathetic, and transparent communication strategies for employees in affected regions. This includes regular updates, clear guidance on company support, and pathways for feedback.
- Support Mechanisms: Provide resources for mental health, relocation assistance, or alternative work arrangements for employees affected by geopolitical events. Recognizing the "super stressful" nature of these situations and responding with support can significantly impact morale, retention, and productivity.
- Cross-Functional Collaboration: Security leaders should champion collaboration with HR, legal, and executive leadership to develop comprehensive plans that address both the technical and human aspects of geopolitical risk.
By proactively addressing these defensive implications, organizations can build a more resilient and adaptable security posture capable of navigating the "new bucket of problems" presented by an accelerating and unpredictable global environment.
Key Takeaways
- Geopolitical Risks are Now Direct Business Threats: Organizations must recognize that global instabilities (e.g., Russia-Ukraine, Middle East conflicts, elections) are no longer abstract concerns but immediate, tangible threats to business operations, supply chains, and workforce availability.
- Traditional Risk Management is Insufficient: Existing cybersecurity and business continuity playbooks often lack guidance for unprecedented geopolitical scenarios, such as mass workforce mobilization or mandated data destruction due to sanctions.
- Supply Chain and Workforce Diversification is Critical: Concentrating critical functions, like software development or technical support, in single, potentially volatile regions creates extreme vulnerabilities; geographical diversification is essential for resilience.
- Prepare for "Unthinkable" Operational Scenarios: Companies must engage in advanced contingency planning for extreme situations, including the potential need for internal "offensive" actions to protect intellectual property or comply with rapidly changing international regulations.
- Transparent and Empathetic Employee Communication is Paramount: During times of geopolitical crisis, honest, supportive, and clear communication with employees is not just ethical, but a critical factor in maintaining morale, productivity, and organizational continuity.
- Integrate Geopolitical Intelligence into Enterprise Risk Strategy: Cybersecurity professionals must expand their purview, collaborating with legal, compliance, and geopolitical intelligence teams to proactively assess and mitigate non-technical, macro-level risks.
About the Speaker(s)
Jeff Moss is the founder of Black Hat, one of the most prestigious and influential cybersecurity conferences in the world. As a leading figure in the information security community, he is known for his insights into the evolving threat landscape and his role in shaping discussions around critical cybersecurity challenges. His remarks at Black Hat USA often serve to set the tone for the conference, urging attendees to consider broader implications beyond technical specifics.