BSidesNYC 0x04 Keynote: When Do We Get to Play On Easy Mode?
Wendy Nather
BSides NYC 2024 · Day 1 · Keynote
Overview
Wendy Nather, a distinguished voice in the cybersecurity community and a member of the National Academy of Sciences committee on hard problems in cybersecurity, delivered a thought-provoking keynote at BSides NYC. Her talk, "When Do We Get to Play On Easy Mode?", challenged the fundamental assumptions and persistent failures within the cybersecurity industry. Nather candidly expressed her fatigue and frustration with the industry's cyclical nature, where the same problems reappear and often worsen despite decades of effort and investment.

Key moments
- 0:00 Introduction: Why is cybersecurity still so hard?
- 2:00 2005 'hard problems' remain unsolved and harder
- 4:00 Breaches now have wider ripple and kinetic effects
- 6:00 Questioning why we persist with ineffective approaches
- 8:00 Phishing training anecdote: when good intentions backfire
BSidesNYC 0x04 Keynote: When Do We Get to Play On Easy Mode?
Speakers: Wendy Nather
Conference: BSides NYC
YouTube: https://www.youtube.com/watch?v=CyWCaxe7yi0
Overview
Wendy Nather, a distinguished voice in the cybersecurity community and a member of the National Academy of Sciences committee on hard problems in cybersecurity, delivered a thought-provoking keynote at BSides NYC. Her talk, "When Do We Get to Play On Easy Mode?", challenged the fundamental assumptions and persistent failures within the cybersecurity industry. Nather candidly expressed her fatigue and frustration with the industry's cyclical nature, where the same problems reappear and often worsen despite decades of effort and investment.
The core of Nather's presentation revolved around a critical examination of why cybersecurity remains an "industrious" and exceptionally difficult endeavor. She argued that many current approaches are not only ineffective but may also be counterproductive, leading to increased complexity, user blame, and a focus on superficial metrics rather than tangible security outcomes. This talk served as a powerful call to action, urging the industry to question ingrained practices, innovate beyond incremental fixes, and fundamentally re-evaluate how security is designed, implemented, and managed across all sectors.
Nather's insights, while explicitly stated as her personal opinions and not a preview of the National Academy of Sciences report due in December, resonated deeply with an audience grappling with the relentless challenges of digital defense. Her address underscored the urgent need for a paradigm shift, advocating for a move towards outcome-driven strategies, better design principles, and a rebalancing of responsibility to truly achieve a more secure digital landscape.
Background
▶ Watch: Introduction: Why is cybersecurity still so hard? (0:00)
Nather began by reflecting on a similar exercise conducted in 2005: enumerating the hard problems in cybersecurity. She presented a list from that era, including perennial challenges such as identity management, insider threat, availability, building scalable systems, and attack attribution. Posing the question to the audience, she highlighted that none of these problems have been definitively solved; in fact, she contended that they have all become significantly harder.
This exacerbation of challenges stems from several critical factors. The pervasive increase in complexity, driven by the widespread adoption of cloud technologies and intricate third-party dependencies, means organizations no longer operate within clearly defined, on-premise perimeters. Furthermore, the persistent reliance on legacy technology—from mainframes to outdated network hardware—forces defenders to secure an ever-growing attack surface that encompasses both the ancient and the cutting-edge, including emerging technologies like AI. Nather noted that the constraints of legacy systems often manifest in seemingly trivial ways, such as password policies limited to "six to eight characters," indicating an underlying mainframe.
The ripple effects of breaches have also expanded dramatically. Nather cited research by the Scientia Institute in collaboration with Risk Recon (a Mastercard subsidiary) on the Blackbaud ransomware incident, which reportedly impacted around a thousand other organizations, many of them nonprofits. She dubbed nonprofits "the other critical infrastructure," emphasizing that their disruption can have profound societal consequences, affecting food banks, homeless shelters, and human trafficking victim support. The increasing interconnectedness, characterized by linchpin providers (e.g., AWS US East 1 outages), means a single point of failure can cascade globally.
Other contributing factors include the rampant monetization of data, not just through ransomware but also advertising and AI training, making data security more complex. Moreover, cyberattacks now have tangible kinetic effects, as demonstrated by incidents like the Lumen event where 600,000 routers in the rural Midwest were bricked during harvest season, highlighting real-world economic and operational consequences. Despite these escalating challenges, Nather observed that the industry continues to employ the same, often ineffective, strategies that have failed for decades.
She specifically criticized several entrenched practices:
- Awareness training, particularly phishing exercises, which she argued are fundamentally flawed. Nather shared an anecdote where employees who diligently attended security training were more likely to fall for a phishing scam designed to appeal to their helpfulness, illustrating the counterintuitive outcomes of such approaches. She questioned the reliance on "fallible organic material" (humans) for detection when systems could be designed to mitigate the impact of user error.
- The pervasive use of "security spackle"—layers of products built on top of existing vulnerabilities rather than fixing the underlying issues. This has led to an industry saturated with piecemeal solutions, with organizations often deploying dozens of disparate security tools, creating significant operational complexity and management overhead. Michael Dell, for example, reportedly manages 75 different security products within his company.
- Vulnerability management, which Nather derisively called "scanning and scolding." She highlighted that identifying vulnerabilities is often the "easy part," whereas true remediation or building secure systems from the ground up remains the "real challenge." She challenged practitioners to focus on solving the remediation problem.
- The common refrain from researchers to "just patch." Nather stressed the practical difficulties of patching in real-world environments, especially with end-of-life (EOL) or end-of-support (EOS) hardware, citing the example of SOHO routers that become unpatchable and easily compromised, often without the user's knowledge, as they continue to "work fine."
Finally, Nather critiqued the tendency for security solutions to be "built by non-practitioners"—vendors focused on what sells rather than what genuinely works in the field. This disconnect, she argued, leads to products that fail to address the nuanced, real-world use cases faced by security professionals.
Key Findings
▶ Watch: 2005 'hard problems' remain unsolved and harder (2:00)
Nather's keynote unveiled several critical findings regarding the inherent difficulties and systemic flaws within the cybersecurity industry:
- Persistent and Worsening Problems: Many "hard problems" identified nearly two decades ago (e.g., identity management, insider threat, attack attribution) remain unsolved and have become more complex due to interconnectedness, cloud adoption, and legacy systems.
- Ineffectiveness of Traditional Approaches: Long-standing methods like generic security awareness training and the continuous layering of security products ("security spackle") are largely failing. Awareness training can even backfire, and product bloat creates more complexity than it solves.
- The "Easy vs. Hard" Dichotomy: The industry disproportionately focuses on "easy" tasks like detection and scanning (vulnerability management as "scanning and scolding") rather than the truly "hard" problems of effective remediation, secure design, and building resilient systems.
- Design Flaws and Practitioner Disconnect: Security tools and systems are often designed by individuals who lack practical, "in-the-wild" experience, leading to products that don't align with the complex realities and intuitive needs of actual security practitioners. The "Lathammer" analogy perfectly illustrates this gap.
- Lack of Outcome-Based Metrics: The industry struggles to define and measure what "works" in security. Metrics often focus on compliance, vulnerability counts, or spending, which do not accurately reflect actual security outcomes or the reduction of incidents.
- Rebalancing Responsibility is Crucial: Placing the burden of defense solely on individuals or small organizations (like dentist offices) is unsustainable and fundamentally flawed. A rebalancing of responsibility towards those with greater resources and influence (e.g., large vendors, governments) is necessary.
- Complexity as a Self-Inflicted Wound: The rapid pace of innovation, the desire to "reinvent the wheel," and the constant introduction of new, unproven technologies contribute significantly to the overwhelming complexity that defenders face.
- Users as Assets, Not Weakest Links: The notion of users as the "weakest link" is detrimental. Instead, Nather argued that properly trained and empowered users, given role-specific security knowledge and trust, can be an organization's greatest asset for threat intelligence and incident response.
- The Illusion of a Talent Shortage: Nather contended that the "talent shortage" is largely a myth, perpetuated by rigid and poorly defined job requirements (e.g., relying on degrees or certifications). Instead, there's a need to identify and nurture individuals with learning aptitude and intuitive security principles, regardless of formal qualifications.
Technical Deep Dive
▶ Watch: Breaches now have wider ripple and kinetic effects (4:00)
Nather's talk, while a keynote, provided a trenchant critique of various technical and architectural approaches, highlighting their shortcomings and the systemic issues they perpetuate. She pointed to the continued reliance on technologies like X.509 certificates, noting, "Is this the year of X.509 again? Some more? We started this, like, 30 years ago. It's still there." This exemplifies the industry's struggle to retire outdated or cumbersome technologies, even when their implementation remains problematic.
The concept of "security spackle" was a central technical critique. Nather argued that the cybersecurity industry has evolved by continuously adding layers of defensive products on top of existing, unaddressed vulnerabilities. This "billion-billion-dollar industry" is built on a philosophy of detection and mitigation rather than fundamental code or architectural fixes. She vividly illustrated this bloat with her colleague's observation of a product described as "a SIM for your SIM," signifying the absurdity of ever-growing complexity and overlapping functionalities. Organizations are left with a fragmented security posture, with one survey revealing a range from four to 31 "minimum baseline" security technologies deemed necessary by professionals. This piecemeal approach, where functionalities are acquired and sometimes poorly integrated, creates an unwieldy and often ineffective security stack, exacerbating the management burden on CISOs.
Vulnerability management also came under fire for its technical limitations. Nather characterized it as "scanning and scolding," emphasizing that the technical act of identifying vulnerabilities (the "easy part") vastly overshadows the "real challenge" of effective remediation or secure-by-design development. She issued a direct challenge to the audience: "If you can figure out how to solve the remediation problem... you will get, well, a personal Nobel Prize from me." This highlights a critical technical gap: the lack of practical, scalable, and trusted automated remediation solutions.
The challenges of patching were underscored by the prevalence of legacy hardware and end-of-life (EOL) products. Nather used the example of an old, yellowed router in her home network to illustrate how working, but unsupported, devices pose significant security risks. She referenced Black Lotus Labs and Lumen's work on SOHO (Small Office/Home Office) routers, explaining that once these devices go out of support, they cannot be patched, leaving them vulnerable to complete takeover by adversaries, often without the user noticing any service interruption. This technical reality clashes with the simplistic "just patch" advice often given by researchers unfamiliar with operational constraints.
Nather employed the analogy of a Lathammer (a German roofing hammer) to critique the design philosophy of security products. She detailed the hammer's numerous, non-obvious features—a point for punching slate, a hook for pulling boards, a channel for setting nails, a textured head, specific weight and balance, vibration-dampening materials, and a durable neck—all intuitively understood and valued by experienced roofers. This contrasts sharply with security products often "built by non-practitioners" who focus on marketable features rather than deep, practical utility. Vendors, Nather argued, often rely on superficial surveys that fail to capture the nuanced, real-world use cases and intuitive needs of security professionals, leading to tools that are technically sound in isolation but fail in complex operational environments. This disconnect between builders and users is a fundamental technical and design flaw that prevents the industry from developing truly effective solutions.
Finally, Nather touched upon the limitations of current security testing methodologies. While acknowledging advancements like MITRE ATT&CK testing, she noted that these efforts are often "narrowly scoped" due to the sheer number of "fringe use cases." She argued that such tests determine if a tool "does what it says it's going to do," but not necessarily "whether it's going to work" in a broader, outcome-driven sense. This highlights a technical measurement problem: the industry lacks robust, comprehensive frameworks to assess the overall efficacy of security strategies and technologies in reducing actual incidents.
Demo / Proof of Concept
▶ Watch: Questioning why we persist with ineffective approaches (6:00)
This keynote address was a high-level, analytical presentation focusing on systemic issues and philosophical shifts rather than a demonstration of specific tools or vulnerabilities. Wendy Nather did not include a live demo or proof of concept in her talk.
Defensive Implications
▶ Watch: Phishing training anecdote: when good intentions backfire (8:00)
Nather's critique of the cybersecurity status quo leads to several critical defensive implications and calls for a fundamental re-evaluation of current strategies:
- Shift to Outcome-Based Metrics: Defenders must move beyond superficial metrics like compliance checklists, vulnerability counts, or spending percentages. Instead, the focus should be on security outcomes—measuring whether strategies actually reduce incidents and disrupt adversaries. Nather referenced Jay Healy's work at Columbia University, suggesting indicators like rapid changes in threat actor TTPs (Tactics, Techniques, and Procedures), shifts to harder TTPs, increased cost and number of ODAs (Offensive Cyber Capabilities), longer attack chains, and degraded trust within threat actor ecosystems. This requires a deeper, more analytical approach to measuring success.
- Rebalance Responsibility and Build Better Incentives: The current model, which disproportionately burdens small organizations and individuals with defense, is unsustainable. Nather lauded the latest National Cybersecurity Strategy for advocating a rebalancing of responsibility towards those with the resources and influence (e.g., large vendors, governments). Defenders should advocate for policy changes that create compelling incentives for security, aligning them with business objectives. This includes mitigating externalities, where organizations bear the cost of a breach even if they weren't directly attacked, as seen in the Blackbaud incident. True "social engineering" for CISOs and policymakers involves aligning economic, business, and legal incentives to drive collective security improvements.
- Restrict Complexity for Critical Use Cases: Nather argued for a paradigm shift in software development, moving away from an "artistic model" of constant reinvention towards a "manufacturing model" for critical infrastructure and essential software. This means establishing "building codes" for software, mandating the use of pre-tested and proven components, and discouraging unnecessary innovation in foundational layers. While challenging Silicon Valley's innovation-driven ethos, this approach aims to drastically reduce the attack surface and inherent vulnerabilities in widely used systems.
- Prioritize Design and Stop Blaming Victims: A significant defensive implication is the need for better design. Nather asserted that if something is vulnerable or if users must "work really hard to do the right thing," it signifies bad design. Defenders should advocate for and contribute to the development of systems that are inherently secure and intuitive, where users don't need to be "geeks who already know everything." This means designing for a broader range of user capabilities and contexts, ensuring that security is embedded and effortless, rather than an afterthought that relies on human vigilance.
- Democratize Security and Empower Users: Instead of treating users condescendingly or as the "weakest link," defenders should empower them. Security needs to transition from a "control function" to a "business function," teaching everyone how security serves them. This involves providing role-specific training that builds expertise and trust, allowing users to make informed decisions and act as a distributed network of threat intelligence. Nather's personal anecdote about her daughter setting parental controls to manage her own study time illustrates how security can be democratized to serve individual needs and goals, fostering a proactive, rather than reactive, security culture.
- Rethink Talent Acquisition and Development: The perceived "talent shortage" is often a product of "bad job requirements" and an over-reliance on formal degrees or certifications. Defenders should broaden their hiring criteria, focusing on individuals with a strong aptitude for learning and intuitive understanding of security principles. Developing internal talent, providing opportunities for leadership, and valuing diverse backgrounds can unlock significant potential and address staffing challenges more effectively than chasing an elusive pool of "perfectly qualified" candidates.
- Question Assumptions and Share Knowledge: Nather's overarching advice for defenders is to "question all the assumptions." If a practice isn't working after decades, it's an indicator that a different approach is needed. Defenders should actively share their knowledge and responsibility, recruiting and encouraging colleagues from all backgrounds to participate in security decisions and leadership. This collective introspection and collaborative problem-solving are vital for breaking free from entrenched, ineffective patterns and moving towards a truly easier mode of security.
Key Takeaways
- Question Everything: The industry must critically re-evaluate long-standing assumptions and practices that have failed to solve persistent cybersecurity problems for decades.
- Focus on Outcomes, Not Just Compliance: Shift from measuring compliance or vulnerability counts to assessing real security outcomes, such as the actual reduction of incidents and disruption of adversary operations.
- Prioritize Secure Design: Advocate for and build systems that are inherently secure and intuitive, eliminating the need for users to be security experts or to make difficult, error-prone decisions.
- Empower Users: Treat users as a valuable asset rather than the "weakest link," providing role-specific training and entrusting them with decision-making to enhance organizational threat intelligence and response.
- Rebalance Responsibility: Support policy changes and industry shifts that rebalance the burden of cybersecurity from small, under-resourced entities to those with greater capacity and influence.
- Simplify and Standardize Critical Infrastructure: For vital systems, move towards a "manufacturing model" of software development with established "building codes" to reduce complexity and inherent vulnerabilities.
About the Speaker(s)
Wendy Nather is a highly experienced and influential figure in the cybersecurity landscape, having been in the field for a "really long time." Her extensive career has provided her with a deep understanding of the industry's persistent challenges and systemic flaws, leading her to express a candid "tiredness" with the status quo. Nather currently serves on a committee for the National Academy of Sciences, tasked with enumerating hard problems in cybersecurity that could benefit from increased government resources and research. She openly shared that she holds no degree herself and allowed her CISSP certification to lapse about a decade ago, emphasizing that formal qualifications are not the sole measure of capability or potential in the field. Her anecdotes, such as promoting a personal assistant to lead an access control group, highlight her belief in nurturing talent and recognizing intuitive understanding of security principles regardless of traditional backgrounds. Nather is known for her confident, analytical, and often provocative critiques of industry norms, advocating for fundamental shifts in thinking and practice.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Nather is sharp, credible, and says things most keynote speakers are too polished to say out loud — the critique of awareness training, security spackle, and 'scanning and scolding' is pointed and correct. But this is a strategic/executive keynote that diagnoses well and prescribes vaguely, and the diagnosis itself isn't new enough to compensate.
Heather Calloway (CISO) — STRONG ACCEPT
Nather is doing something genuinely useful here: naming the structural reasons the industry keeps failing and pointing toward where accountability actually needs to land. The talk is light on operational specificity but heavy on institutional diagnosis, and that's the right trade for this format and audience.