Preparing for Dragons: Don't Sharpen Swords. Set Traps, Gather Intel.
Adrian Sanabria
BSidesSF 2025 — Here Be Dragons · Day 2 · Main
Overview
Most organizations are overwhelmed not by sophisticated adversaries but by distraction — an ever-expanding threat landscape amplified by vendor marketing, exotic CVEs, and side-channel attacks that will never materialize in their environment. Adrian Sanabria's BSidesSF 2025 keynote argues for a resilience-first, fundamentals-focused security strategy: reduce attack surface, build passive defenses, understand what attackers are actually doing from public data, and measure everything — including your vendors. ---

Key moments
- 4:00 Key finding: most breaches look like mediocre 2010 pen tests — attackers don't need sophistication
- 5:59 Counterintuitive: switching staff to Chromebooks eliminated whole attack categories quietly
- 7:59 Alert noise problem: SOC detection tools generate noise; second market of tools filters that noise
- 12:00 Eight-step resilience framework: from attack surface reduction to survive-and-recover planning
- 17:59 Ransomware data advantage: flush with breach postmortems showing what defenses actually work
- 22:00 Deception and threat intelligence as force multipliers: traps over swords methodology
- 25:59 Thesis: you already own the tools you need; fundamentals and configuration beat new purchases
Preparing for Dragons: Don't Sharpen Swords — Set Traps, Gather Intel
Speaker: Adrian Sanabria
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: Watch on YouTube
Reading time: ~8 minutes
TL;DR
Most organizations are overwhelmed not by sophisticated adversaries but by distraction — an ever-expanding threat landscape amplified by vendor marketing, exotic CVEs, and side-channel attacks that will never materialize in their environment. Adrian Sanabria's BSidesSF 2025 keynote argues for a resilience-first, fundamentals-focused security strategy: reduce attack surface, build passive defenses, understand what attackers are actually doing from public data, and measure everything — including your vendors.
Introduction
When Adrian Sanabria stepped onto BSidesSF 2025's largest stage — a screen he described as "definitely the biggest I've ever had the privilege to have my slides on" — he immediately acknowledged the alignment with the morning keynote from Wendy Nather, his longtime colleague from their days at 451 Research. The resonance was not coordinated; they hadn't touched their slides after Nather's talk. It was simply the product of a shared worldview: that cybersecurity spends enormous energy preparing for the wrong battles.
Sanabria's talk is built around a single corrective idea. The threat landscape is not as sophisticated as vendors and conference headlines suggest. Most breaches, when analyzed rigorously, look like a mediocre pen test from 2010 executed by junior pentesters. Fixing that problem is not about sharper swords — it's about setting better traps, building smarter defenses, and knowing where the attackers are actually coming from.
The Sophistication Myth and the Cost of Distraction
▶ Watch: Why the threat landscape narrative is wrong (06:00)
Sanabria opens with a structural critique of how the security industry frames threats. The CISO mind map — a document depicting all the areas CISOs are supposedly responsible for — keeps growing: AI safety, fraud, executive physical protection, and more get added every year. The effect is paralysis disguised as comprehensiveness.
Meanwhile, the headlines that reach practitioners are systematically biased toward novelty. Post-quantum encryption, agentic AI threats, and exotic side-channel attacks dominate conference talks and vendor pitches. What doesn't make headlines is the company that moved half its workforce to Chromebooks and eliminated whole classes of endpoint risk, or the organization whose outbound filtering neutralized a C2 channel and stopped an exploit that was technically successful.
Sanabria conducts post-mortems on breaches as part of his research practice. His observation: "I can't think of a single case where I was like, yeah, they needed a ZTNA solution. That would have stopped it." What he consistently finds instead is misconfigured systems, broken processes, and bad assumptions — not missing tools. Sonic Walls with default credentials, Ivanti and Fortinet edge devices exposed to the public internet, forgotten VPN appliances — these are the entry points. Not quantum computing.
The vendor side of this problem is equally structural. Threat-specific products — tools mapped directly to TTPs in the MITRE ATT&CK framework, or designed around particular threat actor TTPs — tend to be high-labor and low-efficacy. Security Operations Centers generate enormous alert volume, then organizations buy a second layer of products to filter that noise, then add "SecOps AI" on top to eliminate the triage burden created by layer one. "We're stacking these things on here — the fixes for the problems that are created by things that we all pay for," Sanabria observed.
An Eight-Step Framework for Resilience-Based Security
▶ Watch: The eight-step framework overview (18:00)
The core of the talk is a practical eight-step framework. Sanabria presents it not as sequential phases but as a continuous improvement loop, with feedback from failures — both your own and others' — feeding back into the process.
Step 1: Reduce attack surface. Sanabria described reviewing a vulnerability management process with an enterprise client and seeing external web servers running CUPS — the print services daemon — among hundreds of other default packages from an unmodified Red Hat Enterprise installation. Removing unnecessary packages, shutting down unused services, and closing unneeded ports doesn't just reduce vulnerability count; it makes vulnerability management tractable. The same principle applies to data: the FTC is increasingly fining companies for retaining excessive customer data. "Less mess makes everything easier."
Step 2: Shore up passive defenses. These are architectural choices that remove entire attack classes rather than blocking individual attacks. Using Chromebooks for half the workforce eliminates a large swath of endpoint attack vectors. Choosing memory-safe languages like Rust removes classes of memory corruption vulnerabilities. Carefully limiting WordPress plugin diversity to a small set of well-maintained options avoids plugin-based compromise. These choices happen at design time and pay dividends indefinitely.
Step 3: Proactive tech refresh. Sanabria cited research from Cisco and Scientia showing that proactive tech refresh is among the top drivers of employee morale — and also one of the most effective ways to eliminate attack surface. Legacy hardware bought on eBay, end-of-life systems kept running because a full migration is too painful, three-year-old server images that are immediately years behind on patches the moment eight new servers spin up — these create treadmill-like vulnerability management dynamics that no tool can solve.
Step 4: Understand the actual threat landscape. This step is about using publicly available data to inform priorities rather than relying on vendor-generated threat narratives. Scientia produced a meta-study of ransomware reports from multiple vendors, overlaying the results on the MITRE ATT&CK framework to identify what attackers are actually doing — as opposed to what's theoretically possible. The 2025 Verizon Data Breach Investigations Report provides complementary data. A specific data point Sanabria flagged: for critical exploited vulnerabilities, DBIR data shows exploitation beginning within five days of disclosure. For edge-focused devices — Fortinet, Palo Alto management ports exposed to the internet — the number drops to zero days.
Step 5: Prepare countermeasures. This is the active version of passive defense: maintaining capabilities like outbound filtering, exploit prevention, virtual patching, and the ability to neutralize C2 channels. The goal is to reduce the effectiveness of attacks that get through, not just block their entry.
Step 6: Survive and recover. Resilience in Sanabria's framework means keeping the business running during and after an incident — revenue, operations, and reputation. He used the CVE program as an example of infrastructure dependency: imagine if Let's Encrypt disappeared tomorrow and all certificates needed renewal within 24 hours. How agile is the organization to handle that? This step includes tabletop exercises grounded in realistic scenarios (not exotic black swans) and documented response plans.
Deception: The Underused Shortcut to Detection
▶ Watch: Making the case for deception technology (34:00)
One of the more pointed recommendations in the talk concerns deception technology — honeypots, honey tokens, and fake assets designed to fire the moment a legitimate attacker touches them. Sanabria argues it is "severely underused" and that the conventional wisdom about needing to be mature before deploying it is exactly backwards.
"You can set up some good fake accounts, fake data, some fake traps. Go to canarytokens.org. There's stuff you can do for free." The key properties: near-zero false positives, because nothing legitimate ever touches a canary token, and immediate detection of post-compromise activity regardless of how the attacker entered. "This should fire every time you have a pen test," he noted — meaning deception can also serve as a pen test detection metric, giving organizations a concrete measure of whether their testing is finding the same paths an attacker would use.
The Microsoft Copilot angle on monitoring queries was another concrete detection opportunity Sanabria surfaced: attackers who gain access to an enterprise environment and begin querying internal AI tools for passwords, credentials, or sensitive data leave a distinctive and alarming signal. "Somebody's searching for passwords — somebody shady is in our environment."
Measuring What Matters — Including Your Vendors
▶ Watch: Continuous improvement and vendor measurement (40:00)
The final thread in Sanabria's framework is measurement and continuous improvement — and here he is notably unsentimental about vendor relationships. The concept of "negative value" products appears explicitly: a security tool that generates no actionable intelligence but consumes four hours of analyst time per false positive has value below zero. "You can measure that in dollars," he said, describing a spreadsheet approach he used to evaluate a FireEye NX appliance that had never caught a single piece of malware and produced 100% false positives.
On managed providers and MSSPs, he pushed for regular testing. "How often has your MSSP actually brought something to your attention that was a problem versus you finding it yourself? Have you tested your MSSP?" He described creating a test file, placing it on a file server, deleting it, and asking backup admins to recover it — finding only a 10% success rate. As organizations outsource more functions to managed providers, that percentage needs to be known.
The CIS Controls 18 framework got a specific endorsement as a tool for organizing foundational work. Cowbell Cyber's insurance post-mortem data also received a mention for grounding security investment in what actually causes losses: third-party risk, Cowbell reports, accounts for 40% of breaches (compared to DBIR's 30% figure).
Notable Quotes
"Most breaches, the vast majority of the time, look like a mediocre pen test from 2010 done by junior pentesters. They're not that sophisticated. They're not evolving that much because they don't really need to." — Adrian Sanabria (08:00)
"There's not a lot of detections out there where you can get it down to zero false positives pretty easily. Deception is one of those. That's a quick way to shortcut this ability to figure out what's going on in your environment." — Adrian Sanabria (36:00)
"The idea that a product can have negative value is a very real thing. Not only does it do nothing for you, it creates overhead. It eats up people's time and resources that could be working on other things." — Adrian Sanabria (42:00)
Key Takeaways
- The sophistication myth is a distraction. Most breaches exploit unglamorous fundamentals — default credentials, unpatched edge devices, misconfigured systems — not nation-state-level techniques.
- Reduce attack surface before adding detection. Removing unnecessary services, packages, data, and legacy hardware makes every downstream security function (vulnerability management, patching, monitoring) meaningfully cheaper.
- Read the actual data. The Verizon DBIR, Scientia's ransomware meta-study, and Cowbell Cyber's insurance reports tell you what attackers are actually doing and where money is actually lost — use them to override vendor-driven priority-setting.
- Deploy deception early. Honey tokens and fake assets are cheap, near-zero false positive, and do not require organizational maturity to deploy. They should fire on every pen test.
- Measure your vendors. Security products can have negative value. MSSP performance should be tested directly. Backup recovery should be verified, not assumed.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Sanabria is one of the few people at this conference who will stand in front of an audience and say out loud that most of their security stack has negative value — and then hand them a spreadsheet methodology to measure it. The eight-step resilience framework is not revolutionary, but the delivery is blunt enough to actually land. The deception technology argument is the sharpest specific recommendation, and he's right that it is severely underused.
Heather Calloway (CISO) — STRONG ACCEPT
Sanabria's core argument — that most breaches look like a mediocre 2010 pen test because the sophistication narrative serves vendor interests more than defender needs — is correct and well-supported. The eight-step framework is practical and the deception technology argument is underrated. The measurement-focused approach to vendor accountability is the most distinctive contribution.