The Internet Is Fraying, But Maybe Security Can Hold It Together

Heather Flanigan (Digital Identity and Standards Development Consultant · Spherical Cow Consulting)

BSides Seattle 2026 · Day 1 · Track 1

Overview

Heather Flanigan, a 16-year veteran of digital identity and internet standards development, presented a strategic analysis of how the global internet is fragmenting under the weight of diverging legal, policy, and regulatory pressures -- and what this means for cybersecurity practitioners. The talk, adapted from her blog series "The End of the Global Internet" on Spherical Cow Consulting, argues that the shared assumptions underlying internet infrastructure (global DNS resolution, broadly trusted root certificates, data export capability, reachability of threat intelligence sources) are becoming increasingly conditional rather than reliable.

Watch on YouTube

Visual summary for The Internet Is Fraying, But Maybe Security Can Hold It Together by Heather Flanigan
Visual summary for The Internet Is Fraying, But Maybe Security Can Hold It Together by Heather Flanigan

Key moments

  1. 2:00 Premise: shared internet assumptions are becoming conditional
  2. 6:00 Policy-driven pressures: sanctions, export controls, data sovereignty
  3. 8:00 Supply chain interdependence prevents clean hard fragmentation
  4. 10:00 Bulk telemetry data and SOC data under increasing policy scrutiny
  5. 14:00 Schrems II impact on cross-border incident response
  6. 18:00 Entrust distrust action: when PKI coordination meets enterprise reality
  7. 20:00 Actionable guidance: design for jurisdictional friction
  8. 22:00 Design for resilience over efficiency

The Internet Is Fraying, But Maybe Security Can Hold It Together

Speakers: Heather Flanigan, Digital Identity and Standards Development Consultant, Spherical Cow Consulting

Conference: BSides Seattle 2026

YouTube: https://www.youtube.com/watch?v=9Ct1tbf7_0c

Overview

Heather Flanigan, a 16-year veteran of digital identity and internet standards development, presented a strategic analysis of how the global internet is fragmenting under the weight of diverging legal, policy, and regulatory pressures -- and what this means for cybersecurity practitioners. The talk, adapted from her blog series "The End of the Global Internet" on Spherical Cow Consulting, argues that the shared assumptions underlying internet infrastructure (global DNS resolution, broadly trusted root certificates, data export capability, reachability of threat intelligence sources) are becoming increasingly conditional rather than reliable.

This is not a talk about sudden internet breakage or network partitioning. Flanigan's thesis is more subtle and more consequential: the combination of sanctions, export controls, data sovereignty rules, national cryptography requirements, trade barriers, and regional infrastructure strategies is creating a "conditional interoperability" where everything that security teams depend on now comes with an "it depends" qualifier. For security practitioners, especially those at smaller or less mature organizations, this represents a fundamental shift in operational assumptions.

Background

▶ Watch: Premise: shared internet assumptions are becoming conditional (2:00)

The internet was built on shared assumptions that have held for 30-40 years: common protocols, widely deployed cryptography, root programs that function as the CA/Browser Forum designed them, and consistent ability to move and process data across borders. Security teams build their architectures, incident response plans, and threat intelligence pipelines on these assumptions. Mature enterprises already operate with segmented networks, jurisdictional awareness, and zero trust architectures that assume networks are unreliable. But even zero trust models assume a certain level of baseline protocol function -- common DNS, common certificates, consistent data processing rules.

Flanigan makes an important distinction: zero trust is built on the idea that network location alone should never confer trust. The shift she is describing is different -- it is about legal and policy constraints becoming so deeply embedded in the infrastructure environment that technical controls cannot fully account for them. The supply chain further complicates any clean fragmentation scenario because the world's physical resources (lithium, chip lithography capabilities) are unevenly distributed, making complete isolation impractical.

Key Findings

▶ Watch: Supply chain interdependence prevents clean hard fragmentation (8:00)

The talk identified several categories where fragmentation is accelerating:

Data sovereignty and bulk telemetry: Modern SOCs legitimately centralize authentication logs, endpoint telemetry, network flows, and fraud signals. The policy scrutiny on who can receive, process, and aggregate these large-scale data sets is increasing. This will not appear as an immediate technical block but as additional legal reviews, compliance questions, and delays -- particularly devastating during incident response.

Cross-border incident response friction: Cyber incidents rarely stay local. Investigative authority must cross national boundaries, introducing mismatches in evidence admissibility, sovereign reach limits, and jurisdictional authority. The Schrems II decision (2020), which invalidated the EU-US Privacy Shield, did not stop data transfers but made them dramatically more conditional. Organizations had to reassess transfer mechanisms, implement additional safeguards, and in some cases relocate data processing entirely. Security teams felt this as additional reviews, architectural questions, and pressure to localize data.

Identity and trust divergence: The Entrust distrust action (2024-2025) illustrated the real operational impact of trust coordination challenges. After compliance concerns, both Chrome and Mozilla announced staged distrust of newly issued Entrust certificates. While the web PKI worked as designed, the action triggered enterprise-wide certificate inventories (most hadn't been done), migration planning, vendor coordination, and increased PKI governance overhead. Flanigan posed the strategic question: what happens if maintaining this alignment becomes too expensive?

AI as an accelerant: Flanigan deliberately minimized the AI discussion, noting that AI does not create fragmentation -- it makes existing cracks propagate faster. If a messy policy environment exists, AI will speed up bad policy, mediocrity, and breakage.

Technical Deep Dive

▶ Watch: Schrems II impact on cross-border incident response (14:00)

The technical substance of this talk is architectural and strategic rather than exploit-focused. Flanigan's analysis centers on how the dependencies that security architectures assume -- DNS resolution, certificate trust, telemetry data flows, threat intelligence reachability -- are becoming subject to policy-shaped constraints that technical controls were not designed to handle.

The Schrems II example is instructive: Standard Contractual Clauses and Binding Corporate Rules became the fallback mechanisms for EU-US data transfers, but each required assessment of the destination country's surveillance laws, potentially requiring supplementary technical measures (encryption, pseudonymization) that add cost and complexity. For security teams, this means incident response data may be legally constrained from moving to where it can be analyzed most effectively.

The Entrust situation demonstrates a different kind of fragmentation pressure. The CA/Browser Forum process for distrust is well-established and orderly, but the enterprise impact cascades: certificate discovery across all environments, identifying dependencies on the distrusted CA, planning migration timelines, coordinating with vendors and partners, and establishing ongoing PKI governance. Flanigan's concern is that as geopolitical pressures mount, the coordination that sustains the web PKI may become a strategic vulnerability if maintaining alignment becomes too costly for any major participant.

Demo / Proof of Concept

▶ Watch: Entrust distrust action: when PKI coordination meets enterprise reality (18:00)

This talk was a strategic analysis presentation and did not include a technical demo or proof of concept. The case studies (Schrems II, Entrust distrust, data sovereignty requirements) served as the evidentiary basis for the thesis.

Defensive Implications

▶ Watch: Design for resilience over efficiency (22:00)

Flanigan offered three categories of actionable guidance:

Design for jurisdictional friction. Include legal and compliance stakeholders in purple team exercises so they understand exactly what data movement will be required during an incident. Assume that architectures may have constraints that are no longer valid and reassess data flow assumptions.

Preserve interoperability. Actively support and participate in open standards (network standards, identity standards, open-stand principles). Push back against country-level splintering from shared protocol frameworks. The alternative is proliferating incompatible protocol stacks.

Build coordination capacity. Cross-border incident response is already multi-stakeholder; it will only get more complex. Organizations that only practice the technical side of incident response will be slowed dramatically by legal and compliance coordination overhead they did not plan for. Build relationships across legal, compliance, technical, and business teams before you need them.

The overarching strategic reframe: stop designing for efficiency and start designing for resilience. The decentralized nature of DNS and BGP was designed for resilience, but much else was designed for efficiency -- one group handles this, another group handles that, location doesn't matter. Now location does matter, and resilience must take priority.

Key Takeaways

  • The global internet is not collapsing, but the shared assumptions that security architectures depend on (DNS, certificates, data movement, threat intel access) are becoming increasingly conditional due to policy divergence
  • Schrems II did not stop data transfers but made them dramatically more conditional, adding legal review overhead that directly impacts incident response timelines
  • The Entrust distrust action worked as the CA/Browser Forum intended but triggered massive enterprise remediation; the strategic question is whether such coordination can be sustained under increasing geopolitical pressure
  • Security practitioners should include lawyers in purple team exercises and design for jurisdictional friction as a baseline assumption
  • Organizations should stop designing for efficiency and start designing for resilience, especially in data architecture and incident response planning
  • AI does not create internet fragmentation -- it accelerates existing cracks in policy, process, and infrastructure

About the Speaker(s)

Heather Flanigan has spent 16 years in digital identity and internet standards development. She blogs at Spherical Cow Consulting and travels approximately 40% of the year to conferences, standards meetings, and events globally, giving her a broad perspective on how internet governance and infrastructure are evolving across different jurisdictions. The talk was adapted from her blog series "The End of the Global Internet."

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A policy-oriented talk about internet fragmentation and its impact on security operations. While the Schrems II and Entrust examples are relevant, the talk lacks technical depth -- no new research, no exploits, no tools, no measurable findings. This is an awareness talk about regulatory friction, not a technical security presentation.

Heather Calloway (CISO) — STRONG

A thoughtful strategic analysis of how policy divergence is creating operational friction for security teams, grounded in real examples (Schrems II, Entrust distrust). The talk correctly identifies that legal and jurisdictional constraints are becoming embedded in infrastructure in ways that technical controls alone cannot address. The actionable advice -- include lawyers in purple teams, design for resilience over efficiency -- is sound but the talk could be stronger with more concrete operational impact data.

→ Top-rated talks at BSides Seattle 2026

All talks from BSides Seattle 2026