Locknote: Conclusions & Key Takeaways from Black Hat USA 2025
Black Hat USA 2025 · Day 1 · Briefings
Overview
The Black Hat USA 2025 Locknote brought together review board veterans to synthesize the conference's central themes: the uncertain but broadly net-positive role of AI in both offense and defense, the erosion of the talent pipeline as agentic tools absorb tier-one SOC work, and the growing importance of human-centered security in an era of autonomous threats. The panel — facilitated by Black Hat founder Jeff Moss — was notably candid about what the industry has gotten wrong, and what it might still get right. ---

Key moments
- 5:00 Keynote retrospective: Mikko Hypponen's farewell implicitly signals generational shift
- 6:30 Panel observation: security community addressing AI risks faster than it addressed AppSec
- 8:30 Concern: agentic AI bots can autonomously seed and amplify wedge issues 24/7 without sleep
- 11:00 Counterintuitive finding: AI proliferation is driving people back to in-person trust verification
- 17:59 Nation-state cyber ops increasingly blend with AI-driven influence operations simultaneously
- 25:00 Structural concern: vendor incentives misaligned with societal security during AI transition
- 35:00 Conference meta-trend: human factors and societal resilience dominated BH USA 2025 keynotes
- 41:59 Community call: security professionals must engage policy and governance not just technology
Locknote: Conclusions & Key Takeaways from Black Hat USA 2025
Speakers: Jeff Moss, Founder, Black Hat; Heather Adkins, Head of Google's Office of Cybersecurity Resilience & Deputy, CISA's Cybersecurity Review Board; Daniel Cuthbert, Global Head of Security Research; Aanchal Gupta, Chief Security Officer, Adobe; Jason Haddix, CEO, Arcanum Information Security & Field CISO, Flare.io
Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas
YouTube: https://www.youtube.com/watch?v=DmXlafnjn0M
Reading time: 6 min
Type: Keynote
TL;DR
The Black Hat USA 2025 Locknote brought together review board veterans to synthesize the conference's central themes: the uncertain but broadly net-positive role of AI in both offense and defense, the erosion of the talent pipeline as agentic tools absorb tier-one SOC work, and the growing importance of human-centered security in an era of autonomous threats. The panel — facilitated by Black Hat founder Jeff Moss — was notably candid about what the industry has gotten wrong, and what it might still get right.
Introduction
Every Black Hat ends the same way — with beer, candor, and the Locknote. The closing panel is deliberately unscripted: a handful of review board members who spent the week selecting and critiquing submissions sit down to discuss what the talks, the vendor floor, and the collective anxiety of 20,000 practitioners actually revealed about the state of the industry.
This year, under a backdrop of geopolitical instability, AI hype, and genuine workforce uncertainty, the Locknote delivered something rarer than a technical disclosure: an honest reckoning with where cybersecurity stands and where it is headed.
Keynote Themes: The Surprising Emphasis on Human Factors
▶ Watch: Opening Discussion on Keynote Themes (04:00)
Jeff Moss opened by flagging something he found genuinely surprising — all four main keynotes at BH25 centered on human factors rather than deep technical exploits. The themes of community, social manipulation, and human resilience dominated the main stage in a conference otherwise obsessed with binary exploitation and network attacks.
Daniel Cuthbert pointed to Mikko Hyppönen's farewell keynote as a standout, noting how Mikko traced the evolution of the threat landscape through a distinctly human lens. "What was really refreshing this time was multiple keynotes," Cuthbert said, "because it's so important during these tough times to get the big picture of why we are all in security." Heather Adkins added that security professionals are increasingly grappling with adversaries who exploit societal divisions rather than software vulnerabilities — and the field has not yet built adequate defenses for that.
The panel observed that Mikko's historical survey was especially valuable for a community with a significant cohort of new entrants. "The history and how we solve problems as a community is so important," said Cuthbert, drawing a comparison to how early OWASP work addressed AI-class problems two decades before the current boom.
AI Arms Race: Who Actually Has the Advantage?
▶ Watch: AI Offense vs. Defense Debate (14:01)
The most heated exchange of the session was around a deceptively simple question: does AI help attackers or defenders more? Moss framed the problem in terms of feedback loops. Offensive AI receives immediate reinforcement — it gets the shell, it learns. Defensive AI is comparatively blind: a packet filter blocks something but cannot explain why that was the right call. "The feedback loops are gonna be harder in defense than offense," Moss said.
Adkins pushed back. The real advantage of AI for defenders, she argued, lies in scale — the ability to extend human expertise across massive infrastructure and volumes of code that no team could previously cover. "I think that the scale that AI brings will help defenders more than it will help attackers," she said, pointing to autonomous SOC capabilities that could shrink incident dwell time from a year to minutes.
Jason Haddix introduced a third perspective: active deception. Rather than purely reactive defense, he envisions AI-driven honeypot generation — spinning up fake services with convincing lures to waste attacker time and capture adversary tooling for analysis. "I wanna annoy the crap out of attackers," he said. "I want them to waste time going through the crap, because literally they're gonna make a mistake."
Aanchal Gupta offered a more cautious note: attackers can operate with greater risk tolerance than defenders, who are protecting live systems and crown-jewel data. On balance, the panel concluded that AI would not produce a decisive winner in the short term — but it would fundamentally reshape what "winning" means for both sides.
The Talent Pipeline Problem
▶ Watch: SOC Workforce and AI Training Discussion (18:01)
One of the more uncomfortable threads in the Locknote concerned workforce succession. As agentic AI absorbs tier-one SOC functions — log triage, alert correlation, routine escalation — the traditional entry path into security operations disappears. Tier-one analysts learn the domain by doing repetitive, low-stakes work. If AI does that work instead, where do the next generation of tier-two analysts come from?
Adkins suggested that training would simply evolve to meet AI-assisted workflows, comparing the shift to calculators enabling mathematicians rather than replacing them. The consensus tilted toward the view that critical thinking and problem framing would become the core competencies — not packet-level fluency. But Moss acknowledged the tension: the review board had noted a persistent gap "between the dream that's being sold of complete automation and the actuality we have today."
Haddix asked the room directly how many people feared losing their jobs to AI. Almost no hands went up — which the panel took as a signal that practitioners remain confident in the irreducible complexity of real adversarial environments.
Agentic AI and the Societal Stability Problem
▶ Watch: Agentic AI and Influence Operations (10:01)
Moss raised what may be the most underappreciated threat surfaced at BH25: agentic AI optimized for social division. The concern is not theoretical. Nation-state actors — Russia in particular — have long used sentiment analysis to identify wedge issues and amplify them on both sides. AI agents make that operation faster, cheaper, and continuous. "You could have a bot that watches a news segment, sees a heated conversation, and by the time you wake up the next day, the bots could be seeded with both side-isms," Moss said.
The panel did not offer a technical solution to this, but Adkins observed a counterintuitive social response: as AI-generated content becomes harder to distinguish from authentic communication, some communities are returning to in-person connection and oral verification. "I actually think in some ways this technology may push people back together," she said — a dynamic she compared to professors returning to oral exams to defeat AI-written essays.
Cuthbert emphasized that the conference floor itself demonstrated the same impulse: attendance held strong in a year of budget uncertainty because, in unstable times, people want to look each other in the eye.
Notable Quotes
"The feedback loops are gonna be harder in defense than offense. Your packet filter blocked something — it has no idea what it just blocked."
— Jeff Moss [[▶ 14:01]](https://www.youtube.com/watch?v=DmXlafnjn0M&t=841s)
"When you focus on that word — scaling security — that's always been defense's problem. And I think the scale that AI brings will help defenders more."
— Heather Adkins [[▶ 14:01]](https://www.youtube.com/watch?v=DmXlafnjn0M&t=841s)
"We don't like to solve things on our own. We like to solve things together. That's just how this community works."
— Daniel Cuthbert [[▶ 06:00]](https://www.youtube.com/watch?v=DmXlafnjn0M&t=360s)
"There's still quite a gap from the actuality we have today to the dream that's being sold of complete automation. Security people are not going anywhere anytime soon."
— Jason Haddix [[▶ 20:02]](https://www.youtube.com/watch?v=DmXlafnjn0M&t=1202s)
Key Takeaways
- AI's advantage for defenders is scale, not speed. Agentic defensive tools can extend scarce human expertise across infrastructure at a scope no team could achieve manually — potentially compressing incident dwell time from months to minutes.
- The SOC talent pipeline needs active design. Removing tier-one work from human practitioners without building an alternative on-ramp will hollow out the next generation of security operations staff.
- Deception is an underutilized defensive weapon. AI-driven honeypot generation and adversary-wasting techniques could shift the economics of attacks without requiring defenders to outpace every offensive innovation.
- Influence operations powered by agentic AI represent a structural threat that technical security controls alone cannot address — and the industry has not yet developed meaningful countermeasures.
- Human connection remains a security variable. In a year of geopolitical and economic uncertainty, high Black Hat attendance was itself a signal: practitioners are seeking the kind of ground-truth exchange that remote communication cannot replicate.
Slides: No slides PDF is available for this session.
Reviews
Dr. Zero (Offensive Security Researcher) — ACCEPTABLE
The Locknote is a tradition, not a technical session. Jeff Moss and review board veterans talk through the conference themes and it's collegial and occasionally sharp, but nothing here constitutes a contribution to the field. Worth watching with a beer if you've already seen everything else.
Heather Calloway (CISO) — SOLID
The closing Locknote panel synthesized Black Hat 2025 around three themes: AI agents as the dominant new attack surface, the physical-cyber convergence accelerating in industrial and critical infrastructure environments, and credential and identity risk as the persistent structural failure that every other attack class continues to exploit. No new research — useful conference compass.