Let's Do the Timewarp Again! A Look Back to Move Forward
Anna Westelius (Security, Privacy, and Assurance Leader · Netflix)
BSidesSF 2026 · Day 1 · AMC IMAX
Overview
In her compelling keynote at BSides SF, Anna Westelius, Head of Security, Privacy, and Assurance at Netflix, delivered an optimistic and forward-looking message titled "Let's Do the Timewarp Again! A Look Back to Move Forward." Westelius addressed the pervasive anxiety and overwhelm currently felt within the cybersecurity industry, largely driven by the rapid advancements in AI, the complexities of global supply chains, and the sheer scale of cloud computing. Her talk served as a crucial reminder that the industry has successfully navigated similar periods of dramatic technological upheaval and paradigm shifts in the past, offering a blueprint for collective action and innovation.

Key moments
- 0:00 Welcome and "Timewarp" talk theme introduction
- 2:00 Overview of the talk's agenda
- 2:30 Speaker's background and inspiration for the talk
- 4:00 Analyzing the accelerating cybersecurity paradigm shift
- 6:00 Security professionals' unique optimism and community power
Let's Do the Timewarp Again! A Look Back to Move Forward
Speakers: Anna Westelius, Head of Security, Privacy, and Assurance, Netflix
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=XHrWz-_5O9E
Overview
In her compelling keynote at BSides SF, Anna Westelius, Head of Security, Privacy, and Assurance at Netflix, delivered an optimistic and forward-looking message titled "Let's Do the Timewarp Again! A Look Back to Move Forward." Westelius addressed the pervasive anxiety and overwhelm currently felt within the cybersecurity industry, largely driven by the rapid advancements in AI, the complexities of global supply chains, and the sheer scale of cloud computing. Her talk served as a crucial reminder that the industry has successfully navigated similar periods of dramatic technological upheaval and paradigm shifts in the past, offering a blueprint for collective action and innovation.
Westelius skillfully leveraged a "time warp" analogy, drawing inspiration from the iconic musical The Rocky Horror Picture Show, to transport the audience through key historical cybersecurity challenges and their eventual resolutions. By examining how the community collectively overcame seemingly insurmountable obstacles—from the insecure early internet to devastating worm outbreaks and the initial chaos of cloud adoption—she built a powerful case for optimism. The core message is that while the current landscape presents unprecedented challenges, the industry's inherent willingness to learn, experiment, and build together, coupled with significant advancements in defensive capabilities and institutional influence, positions it uniquely to forge a safer future.
This keynote is highly relevant for all cybersecurity professionals, from individual contributors feeling the pressure of a rapidly evolving threat landscape to leaders grappling with strategic decisions. Westelius's call to action emphasizes the importance of community engagement, open sharing, and a proactive approach to designing security from the ground up rather than bolting it on. It's a powerful narrative that encourages practitioners to view the current "crisis" as an opportunity for profound, systematic change, reminding us that we are not merely characters in a story but its collective writers, directors, and stage crew.
Background
▶ Watch: Welcome and "Timewarp" talk theme introduction (0:00)
The cybersecurity industry finds itself at a pivotal moment, accelerating towards what Anna Westelius identifies as a significant paradigm shift. The prevailing sentiment among many professionals is one of stress, anxiety, and a feeling of being perpetually "behind." This unease stems from several concurrent and rapidly evolving factors: technology is more connected and accessible than ever, cybercrime has matured into a sophisticated industry, and most notably, Artificial Intelligence (AI) is fundamentally altering the principles upon which security relies. Westelius provocatively notes that non-deterministic access control, once an oxymoron, now appears to be a looming reality.
The sheer scale of modern technology, encompassing massive cloud computing, post-quantum cryptography considerations, large language models (LLMs), and increasingly global complex supply chains, challenges the very foundations of traditional security. Defensive mechanisms, which typically scale well in stable, understood environments, are struggling to keep pace with an exponentially increasing urgency to protect diverse users interacting with technology in novel ways. While AI is a dominant force in this shift, Westelius clarifies that the broader issue is one of reach, speed, and scale, and the evolving relationship between people and technology.
To counter the pervasive sense of overwhelm, Westelius adopts a storytelling framework, likening the current situation to the "crisis" plot point in a dramatic narrative. In this analogy, the crisis is not an endpoint but a moment where past learnings finally pay off, leading to a "montage" of collective effort and eventual resolution. This perspective is rooted in the industry's history: security professionals are often "blessed or cursed" with pattern-matching skills, constantly imagining worst-case scenarios. Yet, many remain in the field driven by a belief in their ability to make a difference. Westelius argues that this inherent optimism, a "superpower," becomes problematic when individuals attempt to solve these vast problems in isolation. Historically, the industry's strength has always been its community-driven innovation, where sharing principles transcend corporate boundaries, and foundational standards are often maintained by non-profit organizations tackling challenges beyond any single entity's purview.
Key Findings
▶ Watch: Overview of the talk's agenda (2:00)
Anna Westelius’s keynote illuminates two primary sets of "key findings": a retrospective on how the cybersecurity community has overcome significant challenges in the past, and a prospective look at six reasons for optimism regarding the industry's ability to tackle current and future threats.
Historical Shifts: Lessons from Past Overcomes
- The Early Internet – From Open to Encrypted by Default:
- Challenge: The early internet was designed for experimentation and connectivity, with little to no thought given to security. Traffic flowed in plaintext, credentials were often sent openly, and sensitive configurations were broadly shared. HTTPS was inconsistent, and certificates were expensive and cumbersome to manage.
- Resolution: Through years of relentless community effort, standards work, and painful incidents, the industry transitioned from encryption being the exception to the baseline expectation. Organizations like Let's Encrypt emerged, providing free and automated certificates, dramatically lowering the barrier to entry. This systematic change, rather than individual heroics, fundamentally secured internet communication.
- The Worm Outbreaks – From Vulnerable to Resilient:
- Challenge: The late 1990s and early 2000s saw a wave of devastating worm outbreaks, including the I Love You worm (infecting over 10 million Windows devices and causing billions in damages), Code Red, Slammer, Blaster, Conficker, NotPetya, and WannaCry. These exploited unpatched systems and spread rapidly across flat, open networks, often leading to manual cable-pulling to stop propagation. Vulnerability disclosure processes were immature, and information sharing was limited.
- Resolution: The community adapted by treating patching and vulnerability management as ongoing disciplines. Strategies shifted to blast radius reduction, containment, and recovery. Networks were redesigned with greater segmentation, and significant investments were made in detection and response (D&R), observability, and threat intelligence sharing. Dedicated incident response (IR) teams were formed, red teaming became standard, and crowdsourced intelligence (like bug bounties, pioneered by individuals like Casey Ellis and Katie Moussouris) reframed the relationship between researchers and organizations from adversarial to collaborative.
- The Cloud Transformation – From Lift-and-Shift to Cloud-Native Security:
- Challenge: Many companies, including Netflix in 2008, moved to the cloud without well-baked security controls or understood patterns. Early adoption often involved a "lift and shift" model, replicating on-premise flat networks in VPCs, leaving S3 buckets public, and storing root keys in wikis. Traditional security controls struggled with ephemeral infrastructure and containers, leading to initial perceptions of the cloud as inherently insecure.
- Resolution: The community stopped trying to recreate old data centers in the cloud and instead innovated with new cloud-native security primitives. Both platforms and providers developed models offering default-deny network policies, private-by-default storage, hardened templates and base images, and secure Identity and Access Management (IAM). This shift, driven significantly by community contributions, resulted in a security posture dramatically superior to many on-premise setups when implemented correctly.
Six Reasons for Optimism: Our Position for the Future
- "We're in the Room Where It Happens": Security now has significant institutional and political influence. CISOs are standard, boards review security continuously, and experts are influencing global policy. This shift from being dismissed to indispensable signifies a massive evolution in awareness.
- Designing for Humans, Not Against Them: The industry is moving away from blaming users for errors. Instead of relying on perfect awareness, security is engineered with human nature in mind. Advances in human risk management focus on improving security culture and treating employees as a crucial line of defense.
- Focusing on What Actually Matters: There's a necessary correction in the industry, moving from security "appearance" to "substance." Practitioners are prioritizing meaningful risk reduction, asking questions about vulnerability exploitability, and tailoring responses to specific risk tolerances and threat models, rather than investigating every alert or patching every vulnerability.
- Barrier to Entry Has Never Been Lower: Abstractions and new tools are democratizing security expertise. AI acts as an "infinitely patient, extremely knowledgeable tutor," enabling anyone with curiosity to learn security and allowing security engineers to become builders of systems, not just operators of products.
- Legacy Might Finally Be Tractable: One of the industry's biggest challenges, legacy code, is now potentially addressable. AI tools are demonstrating the ability to read, understand, and transform sprawling, decades-old codebases at scale, making the "burning down a decade of legacy risk" feel achievable.
- Security from Design Through Implementation: There's a heightened awareness among providers and developers about building security in from the start. This shift-left approach means security can "pave the way" from the get-go, creating stronger foundations rather than bolting on controls after the fact.
These findings collectively underscore Westelius’s core thesis: the cybersecurity community possesses a unique capacity for adaptation, innovation, and collective action that has consistently led to a safer, more robust technological landscape.
Technical Deep Dive
▶ Watch: Speaker's background and inspiration for the talk (2:30)
Anna Westelius's keynote, while strategic, implicitly highlights a deep technical evolution across several eras of cybersecurity. Her historical "time warp" illustrates how the industry has progressively engineered solutions to fundamental problems, often driven by painful incidents.
The early internet was characterized by a severe lack of security primitives. Data transmission predominantly occurred over plaintext protocols, such as early versions of HTTP and FTP, making network eavesdropping trivial. Credentials were often sent and stored openly, and sensitive system configurations were even shared on public mailing lists, demonstrating a fundamental absence of confidentiality. The initial attempts at securing communication, like HTTPS, were hindered by the high cost and complexity of managing SSL/TLS certificates. The breakthrough came with systematic changes: the maturation of protocols, browsers implementing warnings for insecure pages, and the advent of organizations like Let's Encrypt. Let's Encrypt, a certificate authority, drastically lowered the barrier to entry by providing free, automated certificates, making ubiquitous encryption a practical reality and fundamentally shifting the internet to a more secure encrypted-by-default posture.
The worm outbreaks era exposed critical flaws in system availability and resiliency. Malicious software like the I Love You worm (which leveraged social engineering and VBScript to spread via email attachments), Code Red (exploiting a buffer overflow in Microsoft IIS), Slammer (a rapid-spreading SQL Server worm), Blaster, Conficker, NotPetya, and WannaCry (both leveraging exploits like EternalBlue, reportedly developed by the NSA) demonstrated how a single unpatched vulnerability could cripple entire networks. The technical deficiencies were clear: widespread unpatched critical systems, flat open networks lacking internal segmentation, and insufficient vulnerability disclosure processes. The defensive response involved a suite of technical and procedural advancements. Organizations adopted rigorous vulnerability management and patching disciplines. Network architectures evolved to include segmentation, moving beyond a simple "inside/outside" perimeter model to limit blast radius and enhance containment capabilities. Investment poured into advanced detection and response (D&R) systems, including Security Information and Event Management (SIEM) tools and enhanced observability platforms. The sharing of threat intelligence became crucial, often facilitated by formal and informal channels, and the rise of incident response (IR) teams and red teaming formalized proactive and reactive defense strategies. The bug bounty movement further democratized vulnerability discovery, transforming adversarial hacking into a collaborative security enhancement mechanism.
The cloud transformation presented a new set of technical challenges. Early "lift and shift" migrations often involved replicating on-premise security anti-patterns: deploying flat networks within Virtual Private Clouds (VPCs), accidentally exposing S3 buckets with public access, and storing sensitive credentials like root keys in easily accessible wikis or public repositories. Traditional perimeter-based controls were ill-suited for the dynamic nature of ephemeral infrastructure and containers. The solution was a fundamental shift towards cloud-native security models. This involved leveraging provider-specific security primitives: implementing default-deny network policies to restrict traffic by default, configuring private-by-default storage for data integrity, utilizing hardened templates and base images for consistent, secure deployments, and meticulously managing Identity and Access Management (IAM) to enforce least privilege. Netflix's decision to rebuild its entire infrastructure natively in the cloud over seven years is cited as an example of this commitment to durable, secure-by-design architecture.
Looking ahead, Westelius emphasizes the transformative potential of AI. She suggests AI could lead to "non-deterministic access control," implying more dynamic and context-aware authorization systems, moving beyond static rulesets. AI is envisioned as an "infinitely patient, extremely knowledgeable tutor," capable of assisting security professionals in learning new skills, conducting research, and generating documentation. This democratizes access to advanced security knowledge and fosters a new generation of security builders who can code and develop custom tooling. Crucially, AI is presented as a powerful tool to finally tackle legacy code, a long-standing intractable problem. AI tools are now demonstrating the ability to read, understand, and transform sprawling, decades-old codebases at scale, offering the possibility of automated upgrades and remediation of deeply embedded flaws. This has the profound potential to make "strong security no longer a luxury good," enabling even resource-constrained teams to address previously out-of-reach problems. The overarching technical implication is a move towards identity-centric solutions, opinionated platforms, and repeatable patterns that engineer security in from the start, a true shift-left approach driven by both provider investment and community innovation.
Demo / Proof of Concept
▶ Watch: Analyzing the accelerating cybersecurity paradigm shift (4:00)
This keynote address did not feature a live technical demonstration or proof of concept. Instead, Anna Westelius presented a high-level strategic overview, drawing on historical patterns and expert insights to build a case for optimism and collective action within the cybersecurity community. The talk's focus was on conceptual shifts, community collaboration, and strategic directions rather than the practical implementation of specific tools or exploits.
Defensive Implications
▶ Watch: Security professionals' unique optimism and community power (6:00)
Anna Westelius’s keynote offers several critical defensive implications for cybersecurity practitioners navigating the current paradigm shift. These can be distilled into actionable strategies for individuals and organizations alike:
- Prioritize Systematic Change over Heroics: Defenders must shift from relying on individual heroic efforts to engineering security directly into systems and processes. This means advocating for and implementing secure-by-default configurations, leveraging cloud-native security primitives like default-deny network policies and secure IAM, and investing in robust vulnerability management and patching disciplines as ongoing, institutionalized practices.
- Focus on Meaningful Risk Reduction: Instead of chasing every alert or attempting to patch every vulnerability, defenders should prioritize what truly matters. This involves developing sophisticated threat models, understanding vulnerability exploitability, and aligning security efforts with the organization's specific risk tolerance. The goal is to make purposeful changes that genuinely reduce risk, rather than simply creating the appearance of security.
- Design for Humans, Not Against Them: Acknowledging human nature is crucial. Defensive controls should be engineered to be intuitive and resilient, rather than relying on perfect user attentiveness or training. Investing in human risk management and fostering a collaborative security culture where employees are seen as a "best line of defense" can significantly enhance overall security posture.
- Embrace and Leverage New Technologies, Especially AI: Defenders should actively explore and adopt AI for various security functions. This includes using AI as a learning aid, a tool for building custom security solutions, and critically, for tackling the long-standing challenge of legacy code upgrades and transformation. Organizations that lean into AI's potential for automated remediation and analysis will gain a significant advantage.
- Shift Left and Pave the Way from the Start: Security must be integrated into the entire development lifecycle, from initial design through implementation. This means collaborating closely with developers, product teams, and cloud providers to ensure that secure foundations are established from the outset. By influencing architectural decisions and leveraging secure-by-design principles, defenders can prevent security from becoming a bolted-on afterthought.
- Actively Engage in Community and Knowledge Sharing: The strength of the cybersecurity community lies in its collective intelligence. Defenders should actively participate in industry-wide knowledge sharing groups, contribute to non-profits and standard bodies (like the FIDO Alliance for phishing-resistant authentication or Let's Encrypt for encryption), and openly share defensive and offensive tactics. This collaborative approach helps "lift all ships" by turning individual painful lessons into collective early warnings and accelerating the adoption of best practices.
- Cultivate Continuous Learning and Adaptability: The industry's rapid evolution demands a commitment to lifelong learning. Defenders should intentionally seek out new perspectives, engage in hallway conversations at conferences, and challenge their existing assumptions. Sharing personal learnings and even past mistakes, particularly with those earlier in their careers, strengthens the community's overall resilience and preparedness for future challenges.
By adopting these implications, defenders can move beyond reactive postures and contribute to building a more robust, proactive, and systematically secure future.
Key Takeaways
- Resilience Through Retrospection: The cybersecurity industry has a proven track record of overcoming profound paradigm shifts—from securing the early internet to mitigating worm outbreaks and navigating cloud adoption—demonstrating its inherent capacity for collective adaptation and innovation.
- Systematic Change is the Core Win: Major security advancements, like ubiquitous HTTPS encryption and cloud-native security models with default-deny policies, stemmed from systematic changes driven by the community, rather than isolated heroic efforts.
- AI as a Force Multiplier: Artificial Intelligence is poised to democratize security expertise, enable practitioners to become builders of security systems, and finally make intractable challenges like legacy code remediation achievable, potentially transforming security from a luxury to a baseline.
- Human-Centric & Risk-Focused Defense: Future success hinges on designing security with human nature in mind, fostering a collaborative security culture, and prioritizing meaningful risk reduction based on exploitability and tailored threat models, moving beyond the mere "appearance" of security.
- Community as the Ultimate Superpower: The industry's greatest strength lies in its willingness to learn out loud, experiment, build together, and share knowledge broadly—through open source, conference contributions, non-profit engagement, and threat intelligence sharing—to collectively raise the security bar.
- Seize the Opportunity to Pave the Future: Security is now "in the room where it happens," with institutional influence and a heightened awareness for secure design. Practitioners have a unique opportunity to "shift left" and engineer security from the start, actively shaping a safer technological future rather than being passive characters in its story.
About the Speaker(s)
Anna Westelius is a distinguished leader in the cybersecurity field, currently serving as the Head of Security, Privacy, and Assurance at Netflix. With a career spanning over two decades, she has transitioned from her origins as a security researcher and analyst into a prominent technology strategist and security leader. Originally from Sweden, Anna is a passionate advocate for community engagement, having spent significant time as a community organizer, contributing to numerous conferences, and working with non-profit organizations dedicated to increasing fluency in cybersecurity and related topics. Her deep appreciation for musicals also shines through, adding a unique personal touch to her professional insights.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent, well-delivered motivational keynote from a credible CISO-lane speaker. Westelius knows her history and tells it cleanly, but the talk trades almost entirely in validated conventional wisdom — nothing here would surprise a seasoned practitioner, and the 'six reasons for optimism' framework reads like a refined conference circuit set piece rather than a signal drop.
Heather Calloway (CISO) — SOLID
A well-delivered keynote from a credible practitioner that offers genuine encouragement to a community under strain. The historical framing is honest and the optimism is earned, but the talk stops short of giving security leaders or defenders a usable decision path — it names the right forces without telling anyone what to do differently on Monday.