He’s Inside The House!
Chris Mather (Whitecap Cybersecurity)
SAINTCON 2025 · Day 2 · Main Track 3
Overview
In his SAINTCON presentation, "He’s Inside The House!", Chris Mather of Whitecap Cybersecurity delivers a compelling argument for broadening the traditional scope of cybersecurity to encompass a wider array of internal threats, including negligence, management decisions, and systemic inefficiencies. Mather challenges the prevailing focus on external adversaries, asserting that organizations often overlook—or miscategorize—significant risks originating from within their own walls. This talk is crucial for security professionals, managers, and business leaders alike, as it redefines the insider threat beyond malicious actors to include accidental errors, outdated processes, and even a lack of effective communication, all of which can lead to substantial business impact.

Key moments
- 0:00 Introduction and broadening the definition of insider threat
- 2:00 Redefining threat actor and non-malicious insider threats
- 4:15 Expanding the threat model beyond network to the entire business
- 5:50 Do you include yourself in your threat model?
- 6:50 Which $10K threat is worse? External vs. internal
- 8:45 The hidden, cumulative cost of common internal issues
He’s Inside The House!
Speakers: Chris Mather, AI Entrepreneur, Whitecap Cybersecurity
Conference: SAINTCON
YouTube: https://www.youtube.com/watch?v=OJ-P_lwDFNM
Overview
In his SAINTCON presentation, "He’s Inside The House!", Chris Mather of Whitecap Cybersecurity delivers a compelling argument for broadening the traditional scope of cybersecurity to encompass a wider array of internal threats, including negligence, management decisions, and systemic inefficiencies. Mather challenges the prevailing focus on external adversaries, asserting that organizations often overlook—or miscategorize—significant risks originating from within their own walls. This talk is crucial for security professionals, managers, and business leaders alike, as it redefines the insider threat beyond malicious actors to include accidental errors, outdated processes, and even a lack of effective communication, all of which can lead to substantial business impact.
Mather's central thesis is that a truly robust security posture requires a holistic perspective, moving beyond technical vulnerabilities to integrate human factors, organizational processes, and the strategic priorities of the business. He emphasizes that the ultimate goal of cybersecurity is to protect the business itself, not just the network or code. The talk provides practical insights into how a narrow focus, often driven by compliance checklists or the allure of "silver bullet" solutions, can lead to misprioritization of resources, leaving critical assets exposed. By illustrating these points with relatable scenarios and introducing a quantitative model for risk prioritization, Mather equips attendees with a framework to identify and address overlooked internal risks more effectively.
Background
▶ Watch: Introduction and broadening the definition of insider threat (0:00)
The conventional discourse in cybersecurity predominantly revolves around external threat actors: sophisticated hackers, nation-state adversaries, and organized cybercrime syndicates attempting to breach network perimeters, exploit software vulnerabilities, or launch denial-of-service attacks. While these external threats are undoubtedly critical and warrant significant attention and resources, Chris Mather argues that this singular focus often creates a dangerous blind spot: the insider threat. Historically, "insider threat" conjures images of disgruntled employees stealing data or intentionally sabotaging systems. Mather, however, proposes a significantly expanded definition.
He posits that an insider threat is not exclusively malicious. It can stem from negligence, where employees, perhaps due to insufficient training or simple human error, inadvertently cause damage or expose sensitive information. It can also arise from accidents or systemic weaknesses that allow legitimate users to perform "stupid things" that were never anticipated during system design. Crucially, Mather includes management as a potential source of insider threat. Management decisions—such as redirecting cybersecurity resources away from high-risk areas, prioritizing compliance over actual security, or implementing inefficient processes—can inadvertently weaken an organization's defenses and increase its overall risk exposure.
This broader perspective necessitates a redefinition of the threat model. Instead of solely focusing on network connections, software loopholes, or SQL injection attacks, Mather urges organizations to expand their threat model to include users, management, and even the security professionals themselves. He challenges the audience to consider: "Do you include yourself in your threat model? Are you a single point of failure?" This introspection highlights the importance of knowledge sharing and redundancy, preventing situations where critical business functions become dependent on a single individual.
Mather illustrates the financial impact of these often-overlooked internal issues by comparing various scenarios, all valued at $10,000: an external hacker stealing money, an insider maliciously stealing money, Bob from accounting accidentally deleting critical documents, a slow network or clunky software reducing employee productivity, a server team causing downtime, or management implementing unnecessary tools or outdated processes. His point is clear: many internal issues, while not fitting the traditional "hacker" narrative, can have equivalent or even greater financial consequences for a business due to their frequency and cumulative impact. He links these to the core tenets of the CIA triad—Confidentiality, Integrity, and Availability—arguing that a perpetually slow network or system, for example, is functionally similar to a denial-of-service attack in terms of its impact on availability and productivity.
A significant part of the background Mather establishes is the pervasive issue of compliance versus actual security. He observes that many organizations, particularly those under stringent regulatory frameworks, become fixated on "checking boxes" to achieve certifications. This can lead to a misallocation of resources, where efforts are directed towards satisfying audit requirements rather than addressing the highest-priority, most impactful risks. This "security gate" analogy, where a gate appears secure but has a massive, obvious gap beside it, powerfully conveys how a narrow, compliance-driven view can create a false sense of security. The pursuit of "silver bullets"—single tools or solutions promising to solve all security problems—is also critiqued, as Mather points out that such solutions typically address only one specific type of threat, leaving organizations vulnerable to others. The call for a comprehensive security posture and reciprocal communication between technical teams and management emerges as a critical necessity to overcome these challenges.
Key Findings
▶ Watch: Expanding the threat model beyond network to the entire business (4:15)
Chris Mather's talk highlights several key findings that challenge conventional cybersecurity wisdom and offer a more robust framework for risk management:
- Expanded Definition of Insider Threat: The most significant finding is the redefinition of the insider threat. It moves beyond malicious actors to encompass negligence, accidents, systemic inefficiencies, and management decisions. This broader perspective reveals that significant business risks often originate from within an organization's legitimate operations and personnel, rather than exclusively from external hackers.
- Contextual Risk Prioritization is Paramount: Mather demonstrates that relying solely on automated tool outputs (e.g., "high-risk vulnerability") for prioritization is fundamentally flawed. Without context—such as the value of the data protected, the existing defensive controls, and the actual business impact—organizations risk misallocating resources. A vulnerability deemed "critical" by a scanner might be less impactful than a "medium" one when the surrounding environment is considered.
- The 40/20/40 Model for Objective Prioritization: To address the issue of flawed prioritization, Mather introduces a quantitative risk model (the 40/20/40 model). This model assigns weighted scores to vulnerability severity (40%), existing defenses (20%), and data value (40%) to generate a more accurate and context-aware risk score. This allows for objective re-prioritization, ensuring that resources are directed towards the most critical threats to the business.
- Communication Gap as a Critical Vulnerability: A recurring theme is the perception gap and lack of reciprocal communication between technical teams and management. Techies often focus on granular vulnerabilities, while management prioritizes compliance, budget, and high-level business goals (e.g., mergers, audits). This disconnect can lead to misaligned strategies, wasted resources, and unaddressed risks. Mather emphasizes that effective communication, where both sides understand each other's perspectives and constraints, is a foundational element of strong security.
- Balanced Security Posture Beyond "Silver Bullets": Mather critiques the reliance on "silver bullet" solutions (e.g., a single SAST tool). He argues that effective security requires a comprehensive and balanced approach that integrates multiple technologies (SAST, DAST, pen testing), robust processes, and, crucially, addresses human factors through training and empowerment.
- Business Impact as the Ultimate Metric: Ultimately, cybersecurity should protect the business. Mather urges security professionals to translate technical risks into business terms, particularly financial impact (e.g., "$10,000 in downtime per month"), to effectively communicate with management and justify resource allocation.
Technical Deep Dive
▶ Watch: Do you include yourself in your threat model? (5:50)
Mather's core technical contribution is the 40/20/40 model for contextual risk prioritization. This model is designed to move beyond raw vulnerability scanner outputs and incorporate crucial business and environmental factors into the risk assessment process. It aims to provide a more accurate, quantitative, and defensible method for determining which vulnerabilities truly warrant immediate attention and resources.
The model consists of three primary components, each assigned a specific weight:
- Vulnerability Score (40%):
- This component represents the raw severity of a vulnerability as reported by security tools (e.g., static application security testing (SAST) tools, dynamic application security testing (DAST) tools, vulnerability scanners).
- Mather acknowledges that different systems might use various qualitative ratings, such as Critical, High, Medium, Low (common in many tools), or NIST guidance (which includes a "Moderate" zone), or government classifications (Category 1, 2, or 3).
- The first step is to convert these qualitative ratings into a numerical score. For instance, a "Critical" or "Category 1" vulnerability might be assigned a base score of 83-84 (on a 0-100 scale), while a "High Moderate" or "Category 2" might be 66-67.
- This numerical vulnerability score is then multiplied by its assigned weight of 0.4 to contribute to the overall priority score.
- Defenses Score (20%):
- This component assesses the existing security controls and mitigations already in place around the vulnerable system or data.
- Mather emphasizes that a vulnerability's true risk is diminished if it is exceptionally well-defended. Examples of strong defenses include:
- An internal-only system, not accessible from the public internet.
- Information only available on an admin page.
- Two-factor authentication (2FA) required for access.
- Specific security clearances and approvals needed.
- Other limitations and robust security features (e.g., strong firewalls, intrusion prevention systems, network segmentation).
- The key insight here is that the defense score is inverted for calculation. Instead of assigning a high score for good defenses, Mather suggests a "100 minus your defense score" approach. This means that a highly secure system (e.g., a defense score of 90) would contribute a low value (100-90 = 10) to the final risk calculation, whereas a system with slim defenses (e.g., a defense score of 10) would contribute a high value (100-10 = 90). This ensures that less defense contributes to a higher overall risk score, reflecting the increased exposure.
- This adjusted defense score is then multiplied by its assigned weight of 0.2.
- Data Value (40%):
- This component quantifies the business criticality and sensitivity of the data housed within or affected by the vulnerable system.
- Mather highlights that not all data is equally valuable. Protecting employee phone numbers, for example, is less critical than safeguarding proprietary technology designs, company financials, or sensitive customer data.
- Organizations need to objectively assess the potential impact if this data were compromised, lost, or made unavailable. This assessment should consider regulatory fines, competitive disadvantage, reputational damage, and operational disruption.
- A high-value data asset (e.g., proprietary technology designs) would receive a high score (e.g., 90), while less critical data (e.g., publicly available information) would receive a lower score (e.g., 40).
- This data value score is then multiplied by its assigned weight of 0.4.
The final Priority Score is calculated by summing the weighted scores of these three components:
Priority Score = (Vulnerability Score 0.4) + ((100 - Defense Score) 0.2) + (Data Value * 0.4)
Mather provides two illustrative examples:
- Example 1 (De-prioritization): A system reports a "Critical" or "Category 1" vulnerability (base score of 84). However, it is a highly secure internal-only system with robust defenses (Defense Score of 90, so 100-90=10 for the calculation) and contains only average-value data (Data Value of 40).
- Calculation: (84 0.4) + (10 0.2) + (40 * 0.4) = 33.6 + 2 + 16 = 51.6
- Result: A score of 51.6 would re-categorize this as a "Medium" or "Moderate" (Cat 2) vulnerability, indicating it does not require immediate, critical attention despite the scanner's initial report.
- Example 2 (Re-prioritization): A system reports a "High Moderate" or "Category 2" vulnerability (base score of 67). However, it has very slim defenses (Defense Score of 10, so 100-10=90 for the calculation) and houses highly valuable proprietary technical information (Data Value of 90).
- Calculation: (67 0.4) + (90 0.2) + (90 * 0.4) = 26.8 + 18 + 36 = 80.8
- Result: A score of 80.8 would re-categorize this as a "Critical" or "High" (Cat 1) vulnerability, indicating it demands immediate attention even though the original scanner output was less severe.
This model allows organizations to move beyond a simple "fix everything critical first" approach, enabling them to make data-driven decisions that align with actual business risk and resource constraints. It provides a structured way to inject context into vulnerability management, offering a more realistic and effective prioritization strategy.
Demo / Proof of Concept
▶ Watch: Which $10K threat is worse? External vs. internal (6:50)
While Chris Mather's talk did not feature a live, interactive software demonstration in the traditional sense of exploiting a system or showcasing a tool, he effectively provided a proof of concept for his 40/20/40 risk prioritization model through a clear, step-by-step walkthrough of its application. This "demo" was presented using a conceptual spreadsheet model, illustrating how organizations can quantify and re-evaluate risks.
Mather demonstrated the model by presenting a basic spreadsheet structure, which he described as a tool to "include the defenses that you currently have as well as the value of your information you're protecting to go along with the scores that your tools are coming up with." He explained how various qualitative vulnerability ratings (e.g., Critical, High, Medium, Low from typical scanners; NIST's moderate zones; or government's Category 1, 2, 3) could be converted into a numerical score for the model.
He then walked through two distinct scenarios to showcase the model's impact:
- De-prioritizing a "Critical" Vulnerability:
- Initial State: A system reports a "Critical" or "Category 1" vulnerability, which typically would trigger immediate alarm. Mather assigned this a raw vulnerability score of 84.
- Contextual Factors: He then introduced the mitigating factors: strong existing defenses (assigned a defense score of 90, which translates to a '10' in the inverted calculation for the model), and data of only average value (assigned a data value of 40).
- Calculation: By applying the 40/20/40 weighting—(84 0.4) + (10 0.2) + (40 * 0.4)—the resulting priority score was 51.6.
- Outcome: Mather explained that a score of 51.6 would effectively re-categorize this vulnerability as "Medium" or "Moderate" (Cat 2), indicating that it does not demand the same immediate, high-priority resource allocation as a truly critical threat.
- Elevating a "Moderate" Vulnerability to "Critical":
- Initial State: Another system reports a "High Moderate" or "Category 2" vulnerability, typically considered less urgent. This was assigned a raw vulnerability score of 67.
- Contextual Factors: Critically, this system was described as having very slim defenses (assigned a defense score of 10, translating to '90' in the inverted calculation) and containing highly valuable proprietary technical information (assigned a data value of 90).
- Calculation: Applying the same weighting—(67 0.4) + (90 0.2) + (90 * 0.4)—resulted in a priority score of 80.8.
- Outcome: This score of 80.8, Mather demonstrated, would elevate the vulnerability to "Critical" or "High" (Cat 1). This highlights how a seemingly less severe technical flaw, when combined with weak defenses and high-value data, becomes an urgent business risk.
This conceptual demonstration served to concretely illustrate how the 40/20/40 model provides a framework for security teams to inject essential context into their vulnerability management processes. It moves beyond subjective judgments or raw tool outputs, offering a quantitative method to present "hard numbers" to management, fostering better-informed decisions about resource allocation and risk prioritization.
Defensive Implications
▶ Watch: The hidden, cumulative cost of common internal issues (8:45)
Chris Mather's talk offers several crucial defensive implications, urging organizations to adopt a more comprehensive and context-aware approach to cybersecurity:
- Broaden the Threat Model Beyond External Adversaries: Defenders must recognize that threats are not solely external. The insider threat encompasses not just malicious actors, but also negligent employees, accidental errors, systemic inefficiencies (e.g., slow networks, clunky software), and even management decisions that deprioritize security or implement outdated processes. Security teams should actively include these internal vectors in their threat modeling exercises.
- Implement Contextual Risk Prioritization: Stop relying solely on scanner outputs (e.g., "Critical" or "High") for vulnerability prioritization. Adopt models like the 40/20/40 model to integrate the value of the data being protected, the strength of existing defenses, and the raw vulnerability score. This ensures that resources are directed towards risks that pose the greatest actual threat to the business, rather than merely addressing the loudest alarm. This also means understanding that a low-severity vulnerability on a public-facing system containing critical data with weak defenses can be a higher priority than a critical vulnerability on an internal system with strong controls and low-value data.
- Foster Reciprocal Communication Between Tech and Management: This is paramount. Technical teams need to articulate risks in business terms (e.g., "This downtime costs $10,000 per month in lost productivity") rather than purely technical jargon. They should educate management on the true implications of security decisions. Conversely, management needs to openly communicate high-level business goals (e.g., upcoming audits, mergers, financial constraints) so technical teams can understand strategic priorities and align their efforts accordingly. This breaks down silos and ensures a unified security strategy.
- Embrace a Balanced Security Posture: Avoid the "silver bullet" mentality. A robust defense requires a combination of tools and methodologies:
- Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) for code and runtime analysis.
- Threat Modeling to proactively identify potential attack paths and weaknesses.
- Functional Testing and Penetration Testing to validate controls and uncover exploitable flaws.
- Incident Analytics to understand recurring problems and their cumulative impact (e.g., monthly server crashes costing significant downtime).
- Crucially, this balanced approach must also integrate process improvements and address human factors.
- Invest in Training and Awareness for All Personnel: Acknowledge that employees, from entry-level staff to senior management, can be both assets and vulnerabilities. Implement comprehensive and ongoing security awareness training that extends beyond basic phishing education to cover secure operational practices, data handling, and the broader impact of their actions. Ensure that training is tailored to roles and empowers users to make secure decisions.
- Evaluate and Empower Audit/Security Teams: Ensure that internal auditors and security gatekeepers possess sufficient technical understanding to differentiate between genuine vulnerabilities and false positives. Mather highlights scenarios where auditors, lacking technical depth, either block necessary releases over non-issues or allow real risks to pass due to misinterpretation. Conversely, empower technical teams to challenge misguided policies (e.g., overly complex false positive reporting processes) that hinder actual security work.
- Prioritize Business Resilience and Knowledge Sharing: Recognize that individuals can be single points of failure. Implement practices like creating an Information Assurance Repository of Knowledge (IRC) – a wiki or similar system – to document infrastructure details, project status, and operational procedures. This ensures business continuity if a critical team member leaves or is unavailable, mitigating the "hit by a Coke truck" scenario.
By adopting these defensive implications, organizations can shift from a reactive, compliance-driven security model to a proactive, risk-informed strategy that truly protects the business from its most impactful threats, regardless of their origin.
Key Takeaways
- The insider threat is broader than malicious intent: It encompasses negligence, accidental errors, systemic inefficiencies, and even management decisions, all of which can have significant business impact.
- Contextual prioritization is crucial for effective security: Relying solely on raw vulnerability scores from tools is insufficient. Organizations must incorporate the value of the data, the strength of existing defenses, and business impact to accurately prioritize risks.
- The 40/20/40 model provides a quantitative framework: This model (40% vulnerability score, 20% defenses, 40% data value) offers a structured way to inject context into risk assessment, leading to more informed and defensible prioritization decisions.
- Open, reciprocal communication between tech and management is vital: Bridging the perception gap ensures that technical risks are understood in business terms and that security strategies align with organizational goals and constraints.
- A balanced security posture is essential: Effective defense requires integrating various technical tools (SAST, DAST, pen testing), robust processes, and addressing human factors through training and empowerment, moving beyond "silver bullet" solutions.
- Ultimately, cybersecurity protects the business: Security professionals should translate technical issues into quantifiable business impacts (e.g., financial loss, productivity decline) to justify resources and drive strategic security initiatives.
About the Speaker(s)
Chris Mather is an AI entrepreneur with a strong background in cybersecurity and software development, boasting over 15 years of experience in these fields. He is affiliated with Whitecap Cybersecurity, a solutions provider. Mather's expertise spans both the technical intricacies of securing systems and the broader strategic challenges faced by businesses in managing cyber risk. His current venture into AI indicates a forward-looking perspective on emerging technologies and their implications for the security landscape. He is passionate about fostering better communication between technical teams and management to create more effective and holistic security strategies.