RSS Amplifier

Frankly Speaking · Aug 19, 2026

Eight Thoughts from Blackhat/Defcon

0
Sign in to vote or save

Frank Wang · Frankly Speaking

Disclaimer: Opinions expressed are solely my own and do not express the views or opinions of my employer or any other entities with which I am affiliated.

I’ve intentionally made all of my posts free and without a paywall so that my content is more accessible. If you enjoy my content and would like to support me, please consider buying a paid subscription:

Support me with a paid subscription

I’m back from Las Vegas after tackling both Black Hat USA and DEF CON for the first time in nearly five years.

My primary takeaway from surviving the week: I forgot just how massive this entire event is, and how quickly the step count adds up across the convention floors. Finding a quiet spot to sit down remains the ultimate luxury in Vegas.

Heading in, I wanted to test a specific hypothesis: whether the rise of the technical practitioner and autonomous AI is finally breaking security out of its traditional mold.

I spent the week running through early-morning breakfasts, walking the Business Hall, catching sessions, and absorbing the vibe across Mandalay Bay and the Las Vegas Convention Center.

This isn’t a dense architectural essay. I’ll be diving into specific topics in future newsletters. Consider this a debrief on the major themes, contradictions, and organizational shifts that jumped out at me.

The most telling moments of the week didn’t happen in keynotes or on the expo floor. They happened at private dinners with peers who lead security at actual AI companies.

The contrast was jarring. On the conference stages and in formal tracks, traditional security leaders were debating abstract governance, multi-year roadmaps, and slide-deck “strategy.” At the dinners, people were talking about raw tactical execution: how they are building automated context layers, testing runtime model outputs, managing autonomous agents, and shipping defensive code directly into production.

A lot of the traditional security world feels severely behind, largely because of a complete lack of hands-on technical doing. Many of the top AI security leaders are actively doing the work rather than “strategizing.” We are seeing the end of PowerPoint security and quarterly committee reviews; in an AI-native world, you have to be dynamic, hands-on, and able to move at machine speed.

The breakfast and hallway conversations were dominated by organizational anxiety. Companies are desperately looking for true leaders rather than traditional middle managers: they want hands-on player-coaches who can navigate architecture, not just administrators delegating from a distance.

At the same time, the market has developed completely unrealistic expectations for the modern CISO. Boards expect one person to be a software engineer, an enterprise organizational leader, a risk manager, a regulatory translator, and a product visionary all at once. That unicorn barely exists.

Most practitioners seem content where they are and have zero interest in joining an organization where an executive layer will be built over them without technical context. As organizations flatten in the AI era, I think we are heading toward a structural split: the CISO role will divide into peer leadership positions (a Chief Trust/Compliance Officer handling risk and audits, and a Head of Security Engineering driving technical execution). The underlying reality right now: most companies still don’t know what they actually need from security. However, I wouldn’t be surprised if we see more companies focus on the technical leader rather than an experienced people leader.

Walking the Business Hall and attending the AI Summit, I noticed a huge amount of vendor attention hyper-focused on raw LLM compute and token cost. This feels entirely misplaced.

The real problem in enterprise AI security isn’t the marginal cost of a token; it’s misuse, unvetted data sources, and the wrong people using models improperly. Many organizations are struggling to adapt their structure and processes to AI, and they just need a reset. Focusing on infrastructure cost is a distraction from the harder problems of data lineage, access boundaries, and workflow integration.

Despite the hype around agentic workflows, the majority of tools showcased on the floor are still trapped in legacy patterns: static dashboards, complex UI configurations, and alert tables.

Security practitioners don’t want to log into another bloated web dashboard every morning to manage alerts. The tools that will win are the ones that eliminate administrative friction entirely, offering conversational interfaces or background agents that handle investigations, trigger audits, and query telemetry naturally without forcing users into yet another pane of glass.

The Black Hat Startup Spotlight featured four finalists, i.e., Deception Check, Mallory, Opnova, and Perpetual Systems.

Watching the pitches and the surrounding floor dynamic highlighted how expensive, noisy, and stubbornly unchanged the cybersecurity go-to-market playbook remains. Startups spend massive sums on high-dollar booths to capture attention, but real, nuanced thought leadership is rare. Not all marketing is good marketing. The talks with the silent-disco headphone setup remain the best way to consume content on a loud floor, but you have to wonder: are buyers actually listening to these stage pitches, or are they waiting for tools that solve immediate operational pain?

Historically, Black Hat operated on the premise that security is a single, unified enterprise market. That era is over.

We are entering the age of specialized security. The market has grown large enough that we can no longer treat enterprise defense as one category:

  • Different customer personas require completely different product architectures.

  • Lean, AI-forward companies don’t care about legacy compliance dashboards; they want API-driven, background automation.

  • Traditional enterprises with heavy regulatory debt need human-in-the-loop services to bridge the chasm.

AI makes software customization viable, opening up massive opportunities to deliver security outcomes to companies that cannot compete for elite engineering talent. Traditional service providers and MSSPs are insufficient for this shift.

Autonomous agents can handle significant operational work, but agents are software. They require constant maintenance, tuning, testing, and context updates.

The debate over whether companies should build and maintain their own internal agents or rely on specialized external platforms is going to be a major build-versus-buy battleground over the next year. If you build internal agents, you inherit the ongoing burden of maintaining that software stack.

The contrast between Black Hat and DEF CON was sharper than ever.

Black Hat is dominated by talking, i.e., strategy decks, high-level AI positioning, and vendor pitches. DEF CON is defined by doing, i.e., breaking protocols, demonstrating exploits, and fixing systems in code.

The takeaway was unmistakable: the people who are actively building and breaking systems understand AI security ten times better than the people making PowerPoint slides about it. The operational problems of the AI era will not be solved by strategic committee meetings or abstract leadership. They will be solved by practitioners who understand system calls, context engineering, and runtime architectures.

No posts

Read the original on franklyspeaking.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.