The Cost of Offense Is Collapsing. Our Defenses Cannot Stand Still.
In this blog
- The week, through the work
- Tuesday: Starting with community
- Wednesday: Putting the hard questions on the table
- Throughout the week: Testing decisions and testing technology
- Thursday: Connecting national strategy to local consequence
- Creating space for candor
- What our team heard across Black Hat
- What WWT carries forward
- Download
Black Hat is always a sprint. The volume of new research, new companies, new claims and new conversations can make it difficult to separate signal from noise. This year, however, the signal was consistent.
Offensive capability is advancing faster than many defensive programs can absorb it. AI is compressing the time between vulnerability discovery and exploitation. The cost of launching sophisticated attacks is falling. The attack surface now extends beyond endpoints and cloud workloads to browser extensions, development environments, model supply chains, AI agents, and the connectors and skills those agents can access. Critical infrastructure remains an attractive target, where a cyber incident can quickly become an operational or public-safety event.
Meanwhile, many defenders are still being asked to respond to machine-speed activity with human-speed processes.
We are living through one of the fastest periods of technological change in human history, and its advantages are not distributed evenly. Offense can experiment quickly, exploit once and move on. Defense has to protect sprawling environments, preserve uptime, manage legacy systems and get the decision right repeatedly. That asymmetry is why defensive capabilities are struggling to keep pace — and why closing the gap will take more than another product.
One reflection from our team captured the responsibility we felt heading into the week:
That responsibility shaped how WWT approached Black Hat USA 2026. Across three installations and a full week of programming, we created places to listen, test assumptions, translate technical risk into decisions, and connect people who see different parts of the same problem.
The events were distinct, but the intent was consistent: contribute something useful and leave the community stronger than we found it.
The week, through the work
Our Black Hat presence extended beyond informal community building. We hosted technical and executive discussion, hands-on decision-making, and direct public-private dialogue. Following the week in sequence makes the larger story clearer: Each event opened a different window into what defenders are facing and what it will take to respond.
Tuesday: Starting with community
The week began with Cocktails and Cyber at S Bar in Mandalay Bay. In a conference environment built around packed schedules and competing messages, the gathering created room for the conversations that rarely happen from a stage.
Customers, partners, practitioners and WWT leaders were able to compare what they were seeing before the formal programming began: where AI was producing real value, where security teams were feeling pressure, which problems were being overstated and which risks were not receiving enough attention.
Those conversations set the tone for the week. The most useful intelligence at Black Hat does not always arrive as a finished conclusion. Often, it begins as an observation someone is willing to put on the table early enough for others to challenge it.
Wednesday: Putting the hard questions on the table
Wednesday's Morning Brief brought together Rob Joyce, David Luber and Chris Konrad for a discussion about how AI is changing the threat environment and the mandate for defenders.
The team's central conclusion was direct. The playbook has not disappeared; AI has put it on fast-forward. Rob Joyce described the OpenAI-Hugging Face incident as a watershed moment with the potential to change how organizations think about infrastructure and cyber risk. Like many leaders, he expected large language models to make phishing and synthetic media more effective. He did not initially expect them to become broadly capable across the technical stages of an intrusion. That assumption no longer holds.
AI agents can research software, navigate networks, identify vulnerabilities and operate continuously without fatigue or distraction. Attackers can now iterate and scale at a rate that compounds their advantage, while many security operations centers still rely on people to review alerts, approve changes and coordinate a response.
David Luber brought another dimension into focus: Access to advanced offensive capability is widening. Five years ago, previously unknown vulnerabilities were largely the domain of well-resourced nation-states, while ransomware groups typically exploited known flaws that organizations had not patched. As AI-assisted capability becomes more available, that separation is beginning to erode.
The concern is not simply that every criminal group becomes a nation-state operator. It is that sophisticated capability becomes easier to acquire, reuse and deploy at scale. That changes the threat model for organizations that have historically treated advanced exploitation as a lower-probability risk.
The panel also surfaced a difficult operational tradeoff. For internet-facing devices, traditional test-and-deploy patch cycles may leave a window that machine-speed attackers can cross before defenders are ready. Leaders may increasingly have to weigh the risk of a self-inflicted outage against the risk of leaving a known path open to ransomware or extortion. There is no risk-free answer; there is only a decision about which risk the organization is prepared to own.
That does not make people less important. In fact, it makes human judgment more valuable — and forces organizations to decide where automation can remove delay, where it can improve consistency and where a person still needs to make the call.
The conversation also returned repeatedly to the fundamentals:
- Close easy entry points created by misconfigurations and shadow IT.
- Strengthen segmentation, identity and authentication.
- Treat internet-facing VPN devices and firewalls as direct-contact surfaces.
- Reduce the attack surface rather than allowing patch queues to become the strategy.
- Pair strong internal red teams with agentic capabilities instead of treating one as a substitute for the other.
The same day, Kate Kuehn and the Honorable Kirsten A. Davies convened a listening session focused on CMMC and defense cybersecurity. Policy has an intended outcome, but implementation reveals where requirements work, where they create friction and where they may need to evolve.
The session gave the people responsible for implementation a direct channel to explain what they were experiencing. That exchange is essential. Policymakers need candid feedback from operators, suppliers and practitioners. Industry needs to understand the mission, not just the requirement. Stronger security comes from bringing those perspectives together before friction hardens into failure.
Throughout the week: Testing decisions and testing technology
Across the WWT Lab and Board areas, we explored two sides of the same problem: how to make better cyber decisions and how to determine which capabilities are ready for the environment ahead.
WWT's Immersive Board Experience
The Immersive Board Experience started with a gap our team sees often. We spend a great deal of time helping technical people get better at technology, but not nearly enough time helping them communicate what they know once the decision leaves the technical room.
Participants took a board seat and worked through a mock cyber scenario from that perspective. The discussion could no longer stop at vulnerabilities, controls or product features. It had to account for operations, capital, reputation, timing and the decision leadership was actually being asked to make.
That shift is harder than it sounds. Technical truth only creates value when it can be translated clearly enough for someone else to make a sound decision.
The Innovation Lab
The Innovation Lab approached the challenge from the technology side. Claroty, Filigran, Doppel, BLACKCLOAK, Command Zero and Keyfactor brought six distinct perspectives into the room through innovation pitches and practitioner conversations. The goal was not passive consumption. Participants questioned the ideas, pressure-tested the use cases and helped sharpen the conversation.
At a moment when the market is flooded with AI and security claims, that willingness to expose an idea to scrutiny is a strength. A research tool can generate an answer. A product demonstration can show possibility. Neither can tell an organization whether a capability has been proven in its environment, against its constraints and in service of its mission. Testing and validation remain non-negotiable.
Thursday: Connecting national strategy to local consequence
At Thursday's WWT Community Breakfast, Acting CISA Director Nick Andersen joined Madison Horn for a fireside conversation grounded in what communities and infrastructure operators are experiencing now.
The discussion moved from coordinated cyber activity targeting community water systems in Minnesota to the OpenAI–Hugging Face incident and the implications of AI-enabled operations. It also addressed CISA priorities, Gold Eagle, critical infrastructure resilience and the role industry must play in connecting federal visibility with the realities facing states, local governments and operators.
The examples looked very different, but they forced the same question: Are we learning and adapting as quickly as the threat environment is changing?
That question becomes more urgent in critical infrastructure. In operational technology environments, cyber risk does not remain contained to data. It can affect the systems that move water, power communities, support transportation and keep essential services running. The convergence of physical and cyber security — and the growing national importance of data centers and compute — means resilience must be designed across systems, organizations and levels of government.
Marcela Denniston and NVIDIA opened the breakfast by sharing the work of the newly formed Open Secure AI Alliance. That perspective reinforced another theme from the week: securing AI will require shared work across an ecosystem no single company or agency controls.
Creating space for candor
WWT's women's programming added another important dimension to the week. The Women's Executive Luncheon brought together 55 leaders from across our OEM, partner and advisory community. Cheri Benedict, Madison Horn, Meghan Horstman and Leah Salzman discussed AI trends, career paths and the reality of balancing demanding work with the rest of life.
The all-women Cyber Hot or Not conversation used a lighter format to address serious questions:
- Which cyber issues are receiving justified attention?
- Which are running ahead of the evidence?
- Where is AI delivering value, and where is the market still selling aspiration as capability?
These conversations mattered because learning together requires more than sharing technical conclusions. It requires conditions where people can be honest about uncertainty, challenge the prevailing view and extend some grace to one another while the ground is moving beneath us.
Beyond the formal events, WWT leaders held dozens of customer, partner and OEM conversations throughout the week — including 23 intentional OEM meetings led by our West security organization. Those discussions focused on technology differentiation, go-to-market alignment and the problems customers are prioritizing now. They also helped us compare what we heard on stage with what organizations are funding, implementing and struggling to operationalize.
What our team heard across Black Hat
The week's events covered different audiences and issues, but the same lessons kept surfacing. Together, they form a practical agenda for defenders.
The cost of offense is collapsing
Agentic vulnerability research, AI-assisted attack chains and the growing scale of automated activity all point in the same direction. Attackers can now do more, faster and at lower cost.
This does not mean offense has won. It does mean the margin for being slow, disconnected or unprepared is shrinking. Technical debt compounds the advantage. Every unmanaged asset, excessive entitlement and legacy dependency gives speed somewhere to land.
Defenders cannot eliminate that asymmetry, but they can reduce it. The immediate questions are practical:
- What should the organization stop doing?
- What should it accelerate?
- Which manual processes are creating avoidable delay?
- Where can automation increase speed without surrendering judgment?
The fundamentals matter more at machine speed
There was no shortage of new technology at Black Hat, but the strongest conversations did not argue that established security principles had become obsolete. They argued that those principles must now operate at a different speed and scale.
Attack surface reduction, segmentation, patching, disciplined configuration, resilient architecture and strong identity remain foundational. So do culture, clear ownership and the ability to sustain those controls across a complex enterprise.
"Fall in love with the basics" may sound simple. Executing the basics consistently across cloud, enterprise IT, operational technology, AI systems and third-party environments is anything but.
Identity must extend beyond the human workforce
Enterprises are already deploying agents, but industry discussion has focused more heavily on AI as a threat than on securing the agents organizations are putting into production.
That is a gap defenders need to close. Non-human identities require boundaries. Agents need strong authentication and authorization, segmented access, controlled egress and clear accountability. Model, data and tool supply chains need the same scrutiny organizations apply to other critical software dependencies.
Zero trust cannot stop with users. It must extend to the autonomous and semi-autonomous workloads now acting on their behalf.
Validation separates possibility from capability
More vendor noise arrives every year. Platforms will remain important, and agentic workflows will change how capabilities are delivered. But understanding the use case — and what the organization is actually trying to protect — is what allows leaders to separate relevance from novelty.
AI can accelerate research and surface options. It cannot replace evidence that a control, workflow or product performs as expected in the real environment. This is where practical testing, technical depth and honest practitioner feedback become critical.
The question is not simply, "What can this technology do?" It is, "What has been proven to work here?"
What WWT carries forward
Black Hat has never had a shortage of strong opinions or strong personalities. In this environment, ego is expensive.
No vendor, enterprise, agency or expert has a complete view of what is changing. Innovation is moving too quickly, the attack surface is too distributed and the consequences cross too many institutional boundaries. The performance of certainty may feel reassuring, but it slows learning precisely when the community needs to accelerate it.
The better posture is confident humility: clarity about what we know, honesty about what we do not and enough trust to change course when someone in a different seat sees something we missed.
For defenders, coming together is not a slogan. It is a capability.
It looks like government leaders listening to operators before policy hardens into friction. It looks like technical teams learning to communicate in the language of business decisions. It looks like partners letting practitioners challenge their technology. It looks like organizations sharing lessons without waiting until every detail is polished. And it looks like pairing human judgment with automation so defenders can operate closer to the speed of the threat.
That is what responsibility looked like for WWT at Black Hat this year: convening the people who see different parts of the problem, making space for candor, testing ideas against real-world needs and turning a week of conversations into action for customers and the broader community.
We are proud of the scale of WWT's presence. We are more proud of the way our teams, customers, partners and public-sector leaders showed up inside it — with hard questions, honest answers and a willingness to learn together.
The pace of innovation will not slow down for defenders to catch up. The answer is not to protect our turf more aggressively. It is to move with greater urgency, shed the egos that keep knowledge trapped in silos and learn together at the speed this moment demands.
The mission matters more than being the organization — or the person — that had the answer first.