Keynote: Chaotic Good and Chaotic Bad — Ensuring Collective Success in Defensive Endeavours Through Offence
Ollie Whitehouse (CTO · UK NCSC)
OffensiveCon 2026 · Day 1 · Main Stage
Overview
Ollie Whitehouse, CTO of the UK's National Cyber Security Centre (NCSC), delivered a compelling keynote address at OffensiveCon, challenging conventional notions of cybersecurity. Titled "Chaotic Good and Chaotic Bad — Ensuring Collective Success in Defensive Endeavours Through Offence," the talk provided a candid, high-level perspective from within government on the evolving threat landscape, the indispensable role of offensive security, and the profound impact of artificial intelligence on the industry. Whitehouse, with a career spanning over three decades in cyber, offered a unique blend of technical insight and strategic foresight, emphasizing the symbiotic relationship between offensive and defensive capabilities.

Key moments
- 0:30 NCSC's three key takeaways for collective success
- 2:00 Speaker's journey: pen tester to NCSC CTO
- 3:15 Why he joined government: a rapid recalibration
- 4:00 Global instability's impact on cyber: not a game
- 5:00 Cyber industry evolution: from felons to footballers
- 6:00 Challenges of hyperconnected world and supply chain attacks
- 6:50 Expanding spectrum of actors using cyber offensively
Keynote: Chaotic Good and Chaotic Bad — Ensuring Collective Success in Defensive Endeavours Through Offence
Speakers: Ollie Whitehouse, CTO, UK NCSC
Conference: OffensiveCon
YouTube: https://www.youtube.com/watch?v=Pbdt5DQ6hAQ
Overview
Ollie Whitehouse, CTO of the UK's National Cyber Security Centre (NCSC), delivered a compelling keynote address at OffensiveCon, challenging conventional notions of cybersecurity. Titled "Chaotic Good and Chaotic Bad — Ensuring Collective Success in Defensive Endeavours Through Offence," the talk provided a candid, high-level perspective from within government on the evolving threat landscape, the indispensable role of offensive security, and the profound impact of artificial intelligence on the industry. Whitehouse, with a career spanning over three decades in cyber, offered a unique blend of technical insight and strategic foresight, emphasizing the symbiotic relationship between offensive and defensive capabilities.
The core message of the presentation revolved around three critical takeaways: first, that effective defense is intrinsically linked to high-caliber offense; second, the necessity of a functioning and aligned market for offensive capabilities to ensure collective success; and third, the shared endeavor required from both government and the cybersecurity community to navigate an increasingly complex and unstable world. This talk is crucial for anyone in cybersecurity, offering a rare glimpse into the strategic thinking of a national technical authority and providing actionable insights into adapting to rapidly shifting technological and geopolitical realities.
Whitehouse's address underscored the urgency of understanding these dynamics, particularly in an era marked by unprecedented global instability, rapid technological evolution, and the disruptive force of AI. He articulated the NCSC's role in managing national cybersecurity risks, advocating for a nuanced approach that accepts inherent vulnerabilities while focusing on imposing asymmetric costs on adversaries. His call to action for the offensive community to collaborate with government agencies highlights a critical need for shared understanding and evidence-based strategies to build more resilient digital defenses.
Background
▶ Watch: NCSC's three key takeaways for collective success (0:30)
Ollie Whitehouse’s career trajectory provides a rich backdrop for his perspective, having evolved from a pen tester in the late '90s – a time he describes as "easy" with vulnerabilities found in the morning and exploits by lunchtime – through pioneering baseband research at BlackBerry in 2008-2010, to senior leadership roles in cyber defense companies, before ultimately joining the UK government in 2023. This "atypical civil service career" provided him with a stark "recalibration," revealing a totality of the threat picture that convinced him the industry was "playing the wrong game." His presence at OffensiveCon was driven by a need to share this governmental perspective, learn from the bleeding edge of the offensive community, and outline efforts to foster an ecosystem where this community can thrive.
The global context for this discussion is one of profound instability, described as the most volatile in 80 years. This instability translates directly into cyber domain challenges: regional spillover from wars, cyber effects impacting unintended targets, and even the use of hacked CCTV to support kinetic strikes. Whitehouse notes the "leveling" effect of these realities, emphasizing that "this is not a game." The market for cyber skills has matured dramatically, transforming "hackers to CISOs and CTOs," or as one colleague put it, "felons to footballers," with coveted skills now highly remunerated. Simultaneously, the hyperconnected nature of the modern era, characterized by a "fallacy of sovereignty," means that digital defense is a global, interdependent challenge. Recent incidents like the CrowdStrike outage, the LLM supply chain attack, and a breach affecting 100,000 organizations underscore the fragility of this interconnectedness.
Compounding these challenges is the rapid pace of technological evolution, which cyber defenders often struggle to match due to investment limitations. Cyber itself has become a ubiquitous tool, wielded by a vast spectrum of actors, from state-sponsored groups and sophisticated criminals to activists, signaling its enduring presence in geopolitical and economic landscapes. A significant disruptor in this environment is the AI correction, a theme Whitehouse explored in depth. He presented data indicating that AI is rapidly transforming the vulnerability discovery market, leading to revenue stream cuts for researchers and the commoditization of what were once considered "exquisite vulnerability classes." This swift shift, occurring over months rather than years, poses a significant risk to the talent pipeline and the incentive structures for individuals in the offensive community.
Underpinning these observations is the fundamental premise that "everything is vulnerable and it always will be." Achieving zero vulnerability is dismissed as a fallacy, primarily due to economic constraints (making secure tech is often economically unviable), the sheer scale, complexity, and pace of technological change, and the pervasive presence of deeply embedded legacy systems. Whitehouse highlighted the reality of operating environments where "double-digit percentage of network equipment devices" are end-of-life, and another "double-digit percentage" are not patched against known critical vulnerabilities. The globalized supply chain, with its myriad open-source repositories, international developers, and varying update cadences, further exacerbates this inherent complexity, making comprehensive vulnerability eradication an impossibility.
The threat environment itself is characterized by a growing demand for offensive capabilities globally, with over 80 countries assessed to have bought offensive cyber capabilities in 2023. This means "all it takes is a checkbook" to acquire sophisticated tools like zero-click exploits, rather than costly R&D. Adversaries exhibit world-class operational sophistication, often operating in smaller, more nimble groups. Disturbingly, irresponsible operations have led to the first deaths attributed to a cyber operation in the UK health service, underscoring the real-world consequences of miscalculation. Furthermore, the offensive community itself is increasingly becoming the target, with state adversaries employing social engineering tactics to "hunt the hunters" and acquire capabilities. This complex and rapidly shifting landscape forms the critical background against which Whitehouse outlines the NCSC’s strategic approach.
Key Findings
▶ Watch: Why he joined government: a rapid recalibration (3:15)
The talk presented several critical findings that reshape how both offensive and defensive cybersecurity communities should perceive their roles and interactions:
- Defense Through Offense: The central tenet is that effective defense is not merely reactive but actively shaped and improved by understanding and leveraging high-caliber offense. Whitehouse emphasized that the NCSC deeply values the offensive community's contribution to national security, using insights from offensive operations and research to build robust defenses.
- The Inevitability of Vulnerability: A foundational finding is the acceptance that "everything is vulnerable and it always will be." This premise dictates a shift from an unattainable goal of zero vulnerabilities to a strategic focus on imposing asymmetric cost and peril on adversaries, making their operations more expensive, difficult, and risky.
- AI's Disruptive Impact: Artificial Intelligence is causing a rapid and significant "AI correction" in the vulnerability discovery market. It is swiftly commoditizing once-exquisite vulnerability classes, leading to a "patch wave" and threatening the revenue streams and talent pipelines of security researchers. AI models, even open-source ones, are lagging only 6-8 months behind the cutting edge, fundamentally altering the economics and accessibility of offensive capabilities.
- Complex Offensive Ecosystem: The global market for offensive cyber capabilities is highly complex and expanding, with over 80 countries buying capabilities in 2023. This proliferation means that sophisticated tools are accessible via "a checkbook," bypassing traditional R&D. This market distortion presents challenges for attribution, behavior shaping, and managing proliferation risks.
- The "Hunters Becoming the Hunted": The offensive security research community itself is now a primary target for state adversaries seeking to acquire capabilities through social engineering and other means. This necessitates a heightened focus on self-defense and intellectual property protection within the community.
- Need for Market Transparency and Norms: Recognizing the existence and necessity of an offensive market, Whitehouse highlighted initiatives like the Pammal process (UK and France) to establish norms, promote transparency, and support responsible actors while disrupting irresponsible ones. This is crucial for a stable, equitable, and safe ecosystem.
- Strategic Defensive Primitives: Rather than chasing every vulnerability, the NCSC advocates for investing in architectural primitives that fundamentally raise the bar for adversaries. Examples include non-phishable multi-factor authentication (Passkeys), memory-safe CPU architectures (CHERI), cross-domain solutions (CDR), and Privileged Access Workstations (PAWs).
- Importance of Talent Pipeline: The rapid changes driven by AI pose a significant risk to the longevity of the talent pipeline. Whitehouse stressed the need to nurture foundational skills and create environments where new entrants can build deep technical understanding before relying on productivity-enhancing tools.
Technical Deep Dive
▶ Watch: Global instability's impact on cyber: not a game (4:00)
The technical core of Whitehouse's talk centered on two major areas: the profound impact of AI on vulnerability discovery and the strategic architectural primitives being championed for robust defense.
AI's Impact on Vulnerability Discovery and the Market:
Whitehouse presented compelling data illustrating the "AI correction" currently underway. He highlighted graphs showing a rapid acceleration in patching, particularly from vendors who likely had early access to advanced AI tools like Methos. This indicates that AI is significantly increasing the rate at which latent vulnerabilities are being surfaced and addressed. Critically, exquisite vulnerability classes that once commanded premium prices are now "broadly seen as commodity." This shift has occurred "extraordinarily quickly," over just a few months, impacting the revenue streams of many security researchers and bug bounty programs.
The speaker demonstrated the power of AI with a prompt described as "disgustingly effective," capable of performing tasks like binary diffing, taint flow analysis, and solver execution—work that traditionally took "hours, days, weeks, months" for human experts—in "seconds and minutes." This is not "stunt hacking" but the current operational reality. While AI models still have short-term constraints like context windows and token cost, these are rapidly improving. Open-source models are observed to be lagging only 6 to 8 months behind the most sophisticated proprietary capabilities, a gap that has even slightly increased recently, but remains remarkably short. This necessitates a critical re-evaluation of where human ingenuity maintains an "enduring edge" over AI.
Defensive Architectural Primitives:
Given the acceptance that "everything is vulnerable," the NCSC's strategy shifts from eradication to imposing asymmetric costs on adversaries through fundamental architectural changes. Whitehouse outlined several key primitives:
- CHERI (Capability Hardware Enhanced RISC Instructions): This is a CPU architecture designed to provide fine-grained memory safety and protection, directly addressing the pervasive issue of memory corruption vulnerabilities. Whitehouse noted that the "first chips which are out" are in the microcontroller space, with efforts underway to accelerate their deployment into "full kind of application grade CPU architectures." The goal is to move beyond "playing whack-a-mole on memory corruption" by fundamentally hardening the underlying hardware.
- Non-Phishable Multi-Factor Authentication (MFA), specifically Passkeys: Whitehouse stated that implementing pervasive, non-phishable MFA would mitigate approximately 60% of the breaches currently observed. This targets the human element of security, recognizing that "relying on humans to not be frail is a path to the end." Passkeys, by binding authentication to a specific device and relying on cryptographic keys rather than shared secrets, effectively eliminate common phishing vectors.
- Cross-Domain Solutions (CDS) / Content Disarm and Reconstruction (CDR): These technologies are designed to prevent malicious payloads from crossing trust boundaries. By disarming and reconstructing content, they "impose significant cost for adversaries" by making it extremely difficult for them to get their malicious code past defenses.
- Privileged Access Workstations (PAWs): This architectural approach involves placing administrators in dedicated, hardened enclaves, using laptops specifically for administrative tasks, segregated from general browsing or corporate email. This "turns out it becomes really hard to systemically compromise the environment" by isolating high-privilege accounts from common attack vectors.
The Offensive Ecosystem and Vulnerabilities Equities Process (VEP):
Whitehouse provided insight into the government's view of the offensive ecosystem. He revealed that over 80 countries bought offensive cyber capabilities in 2023, indicating a global market where sophisticated tools are readily acquired. This "checkbook" approach bypasses domestic R&D, leading to market distortions and complex proliferation challenges.
The UK manages its national risk around vulnerabilities through a Vulnerabilities Equities Process (VEP), chaired by the NCSC. This process decides how the UK government manages vulnerabilities it discovers or acquires, balancing the need for national security capabilities with the imperative to protect the broader digital ecosystem. NCSC interrogates other government entities and their suppliers about their offensive capabilities, seeking details on "origin," "who else has it," "customers," and "proliferation management," as well as "defensive options" to manage national-level risk.
To address the complexities of this market, the UK and France, through the Pammal process, are working with international partners and industry to establish norms for responsible behavior. The strategy is to "bifurcate" the market: support "responsible" actors to operate transparently and ethically, while making the "irresponsible" more "tractable and easier for us to ultimately disrupt." This includes efforts to provide "front doors" for researchers who wish to engage responsibly with nations.
Demo / Proof of Concept
▶ Watch: Challenges of hyperconnected world and supply chain attacks (6:00)
The talk did not include a live technical demonstration or proof of concept in the traditional sense. Instead, Ollie Whitehouse presented graphs illustrating the real-world impact of AI on vulnerability discovery and patching rates across various vendors, providing data-driven evidence for the "AI correction." He also humorously shared a prediction for 2030 generated by Claude, an AI model, which he found eerily accurate and indicative of the rapid changes expected. These visual aids served as conceptual proofs of the significant shifts discussed rather than showing specific exploits or defensive tools in action.
Defensive Implications
▶ Watch: Expanding spectrum of actors using cyber offensively (6:50)
The insights from Whitehouse's keynote offer several critical implications for cybersecurity defenders, urging a strategic shift in approach:
- Embrace Asymmetric Cost Imposition: Defenders must move away from the unattainable goal of absolute invulnerability. Instead, the focus should be on making adversaries' operations prohibitively expensive, time-consuming, and risky. This involves strategic investments that force attackers to expend disproportionate resources for minimal gains.
- Prioritize Architectural Primitives: Rather than chasing every individual vulnerability, organizations should prioritize implementing fundamental architectural controls. Deploying non-phishable MFA (Passkeys) can eliminate a vast percentage of common breaches. Investigating and adopting memory-safe CPU architectures like CHERI will fundamentally reduce the attack surface for memory corruption exploits. Implementing cross-domain solutions (CDR) and Privileged Access Workstations (PAWs) will significantly raise the bar for lateral movement and privileged access compromise.
- Harden Against "Hunters Becoming Hunted": Security researchers, red teams, and offensive security companies must recognize they are prime targets. They need to invest heavily in their own cybersecurity, intellectual property protection, and robust social engineering defenses to prevent their valuable capabilities from being stolen by state adversaries.
- Demand Evidence-Based Security: Defenders should be critical of "magic solutions." Instead, they must demand and seek out metricated evidence of what truly works, what frustrates sophisticated adversaries, and what genuinely adds cost to offensive operations. This requires engagement with the research community to understand real-world efficacy.
- Foster and Protect Talent Pipelines: Organizations have a vested interest in the long-term health of the cybersecurity talent pool. This means supporting foundational learning for new entrants (e.g., understanding computer architectures and operating systems at a low level before relying on AI tools) and creating supportive, high-reputation environments where talent can thrive and feel safe.
- Engage with Government and Industry Norms: For those operating in the offensive space, understanding and adhering to initiatives like the Pammal process demonstrates responsible conduct, which governments aim to support. Defenders benefit from a more transparent and regulated offensive market that reduces the proliferation of capabilities to irresponsible actors.
- Proactive Vulnerability Management with AI Awareness: While AI accelerates patching, defenders must acknowledge that AI will also accelerate vulnerability discovery for adversaries. This necessitates agile patch deployment strategies, potentially leveraging automated hot patching, and focusing on attack surface minimization alongside traditional patching.
- Know Your Supply Chain and Partners: The complexity of the global supply chain, coupled with the proliferation of offensive capabilities, means organizations must rigorously vet their vendors, customers, and employees to avoid inadvertently supporting or being compromised by adverse actors. "Know your customer and know your employer" is a critical personal and organizational imperative.
Key Takeaways
- Defense is fundamentally done with and through high-caliber offense; the two communities are interdependent and must collaborate for collective success.
- Artificial Intelligence is rapidly commoditizing vulnerability discovery, necessitating a re-evaluation of security researcher revenue models and the long-term health of the talent pipeline.
- The premise of achieving "zero vulnerability" is a fallacy; instead, cybersecurity strategy must focus on imposing asymmetric costs and peril on adversaries through strategic interventions.
- Implementing robust architectural primitives such as Passkeys, CHERI-enabled CPUs, Cross-Domain Solutions (CDR), and Privileged Access Workstations (PAWs) is crucial for building resilient defenses against sophisticated threats.
- The global offensive cyber market is complex and growing, requiring international efforts like the Pammal process to establish norms, promote transparency, and enable responsible engagement while disrupting irresponsible proliferation.
- The cybersecurity community, particularly offensive researchers, must prioritize self-defense, protect intellectual property, and actively engage with government agencies like the NCSC to provide evidence-based insights and shape effective national defense strategies.
About the Speaker(s)
Ollie Whitehouse is the Chief Technology Officer (CTO) of the UK's National Cyber Security Centre (NCSC), where he is responsible for maintaining the NCSC's role as a national technical authority for cyber security. His extensive career in cyber spans over 30 years, offering a unique blend of offensive, research, and defensive expertise.
Whitehouse began his career as a pen tester in the late 1990s, experiencing the early days of vulnerability discovery and exploitation. He later moved into research, notably conducting pioneering work on baseband exploitation at BlackBerry between 2008 and 2010. Before joining government, he held senior leadership positions in cyber defense companies, leading both red and blue teaming operations globally. In 2023, driven by a desire to "make a difference," he transitioned to government, joining an intelligence agency within the security mission. Despite now "wearing a suit," Whitehouse remains a dedicated technologist, committed to leveraging his deep technical understanding to enhance national cybersecurity.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Whitehouse delivers exactly what a strategic keynote should: real signal from someone who actually sits at the table. The AI commoditization data is the headline — vulnerability classes going commodity in months, not years, with concrete impact on researcher revenue streams. Not a policy deck recital; this is a practitioner-turned-government-CTO being unusually candid about threat realities and market distortions.
Heather Calloway (CISO) — SOLID
This is exactly the kind of strategic clarity I'd want my board to hear from a national technical authority. Whitehouse names the uncomfortable truths—everything is vulnerable, AI is reshaping the economics of offense, and we need to stop chasing zero-vulnerability fantasies and start imposing asymmetric costs. Worth your leadership team's time.