Skip to content

SIDE QUESTSecurity Leadership

Attribution is BS: change my mind...

Attribution gets a lot of airtime. Whether it changes what a defender does on a Tuesday morning is a different question, and it is the one this talk sets out to poke at.

Samantha Swift / DefCamp 2024 /

ORIGINAL SOURCE

WATCH / DefCamp 2024

A deliberately sceptical examination of cyber threat attribution and the usefulness and reliability of attribution for defenders.

WATCH THE ORIGINAL (opens on an external site)

Originally published by DefCamp 2024. Cyber Increment did not host or publish this source.

WHY WE'RE SHARING IT

Attribution is BS is a deliberately sceptical talk. The provocation in the title is doing exactly what it looks like it is doing: inviting the audience to argue back.

The subject is cyber threat attribution, and the question underneath it is whether attribution is as useful and as reliable as the attention it attracts suggests.

What it gets into

  • What cyber threat attribution is being asked to do, and who it is being done for.
  • How reliable attribution is as a basis for decisions.
  • Whether attribution changes what defenders do in practice.

Watch it with the title's invitation in mind. The talk is arguing a position, and the useful part is working out where you disagree.

CONTINUE?

Want to talk it through?

If any of this is live in your business right now, a short conversation is usually the fastest way to work out what to do next.