Confidence Predicts Accuracy and Other Lies About Cloud Security

Kat Traxler (Principal Security Researcher · Vectra AI)

fwd:cloudsec Europe 2025 · Day 1 · Main Room

Overview

Kat Traxler, a Principal Security Researcher at Vectra AI with a background in offensive cloud research across Google Cloud and AWS, delivered a provocative keynote arguing that the cloud security industry's fixation on posture management and least-privilege pursuit is fundamentally driven by cognitive biases rather than rational risk reduction. Drawing heavily from Daniel Kahneman's behavioral economics framework — particularly the concepts of System 1 (fast, intuitive) and System 2 (slow, analytical) thinking from Thinking Fast and Slow — Traxler made the case that the industry must redistribute cloud security responsibility across the entire security organization and break free from the "pursuing posture perfect" treadmill.

Watch on YouTube · Slides

Visual summary for Confidence Predicts Accuracy and Other Lies About Cloud Security by Kat Traxler
Visual summary for Confidence Predicts Accuracy and Other Lies About Cloud Security by Kat Traxler

Key moments

  1. 4:00 Introduces 'Pursuing Posture Perfect' — questioning whether misconfiguration remediation is the panacea we've hyped it to be
  2. 8:00 Dopamine hits from closing Jira tickets create feedback loops that prioritize measurable over impactful security work
  3. 10:00 Dissects misleading vendor metrics — 61% without root MFA and 82% exposed SageMaker notebooks lack critical context
  4. 14:00 Zero-risk bias explained — why we prefer eliminating small visible risks over reducing complex future risks
  5. 20:00 NIST framework as a 'ruler for cognitive biases' — Detect and Respond functions challenge optimism bias
  6. 26:00 Cloud security teams should fold posture work into vulnerability management — S3 misconfigs are 'the new unpatched server'
  7. 30:00 Proposal to realign incident response from host-based to identity-based threat hunting
  8. 34:00 Four-step action plan including the 'power of now' bias — immediate ticket closures vs. abstract resilience investments

Confidence Predicts Accuracy and Other Lies About Cloud Security

Speakers: Kat Traxler, Principal Security Researcher, Vectra AI

Conference: fwd:cloudsec Europe 2025

YouTube: https://www.youtube.com/watch?v=CYYT581O67Q

Overview

Kat Traxler, a Principal Security Researcher at Vectra AI with a background in offensive cloud research across Google Cloud and AWS, delivered a provocative keynote arguing that the cloud security industry's fixation on posture management and least-privilege pursuit is fundamentally driven by cognitive biases rather than rational risk reduction. Drawing heavily from Daniel Kahneman's behavioral economics framework — particularly the concepts of System 1 (fast, intuitive) and System 2 (slow, analytical) thinking from Thinking Fast and Slow — Traxler made the case that the industry must redistribute cloud security responsibility across the entire security organization and break free from the "pursuing posture perfect" treadmill.

Background

▶ Watch: Introduces 'Pursuing Posture Perfect' — questioning whether misconfiguration ... (4:00)

Traxler is no stranger to the fwd:cloudsec stage. She spoke at the inaugural 2020 conference on primitive roles in Google Cloud, followed by a 2022 talk on AWS replication service data exfiltration, and a 2023 Brussels presentation on abusing service agents in Google Cloud. Her technical pedigree makes her critique of the industry's strategic direction particularly credible — this isn't a governance theorist; it's an offensive researcher questioning whether the defensive playbook is fundamentally misaligned.

The core problem she identifies: the cloud security industry has spent 15 years obsessing over misconfiguration remediation and least-privilege perfection — activities that feel productive but may not meaningfully reduce cloud risk. This behavior, she argues, is not driven by evidence but by cognitive bias — specifically the overconfidence effect, where subjective confidence vastly exceeds objective accuracy.

Key Findings

▶ Watch: Dissects misleading vendor metrics — 61% without root MFA and 82% exposed Sag... (10:00)

Traxler's analysis centers on several behavioral economic mechanisms that keep the industry locked in a suboptimal cycle:

System 1 creates compelling stories from limited data. The industry takes isolated metrics — like "61% of organizations have a root user without MFA" or "82% of SageMaker users have exposed notebooks" — and weaves them into narratives that confirm pre-existing beliefs. These metrics lack critical context: the root user without MFA might be in an organization's standard secure-by-default configuration; the exposed SageMaker notebook might have identity-based controls mitigating the risk.

Dopamine-driven feedback loops reinforce remediation behavior. The physical act of closing Jira tickets and watching misconfiguration counts decline generates immediate psychological rewards. This present bias — overvaluing immediate gains while discounting future ones — keeps teams on a hamster wheel of reactive fixes rather than investing in harder-to-measure resilience capabilities.

Metrics have a chokehold on prioritization. Whatever can be easily measured gets prioritized, regardless of its actual risk reduction value. Dashboard trend lines and cherry-picked vendor report statistics fuel the narrative fallacy — the tendency to create compelling stories from limited data. Traxler highlighted a cloud threat report showing a technique jumping from 46th to 4th most prevalent with "16x growth" — without providing the underlying data to evaluate the claim.

Zero-risk bias drives the long tail of remediation. Organizations prefer completely eliminating visible, small risks over significantly reducing complex, future risks — leading to diminishing returns as cloud security teams chase posture perfection well past the point of efficacy.

Technical Deep Dive

▶ Watch: NIST framework as a 'ruler for cognitive biases' — Detect and Respond functio... (20:00)

Traxler's prescription is structured in three parts, progressing from diagnosis to framework to organizational redesign.

Engaging System 2 through frameworks. Drawing on Kahneman's analogy of a pilot's pre-flight checklist, Traxler argues that the NIST Cybersecurity Framework should serve as a "ruler for cognitive biases." NIST's greatest strength for cloud security is its technology agnosticism — it predates the cloud but forces organizations through a complete lifecycle assessment (Identify, Protect, Detect, Respond, Recover) rather than allowing them to fixate solely on Protect. The very existence of Detect and Respond functions within NIST is a direct challenge to System 1's optimism bias — NIST assumes that protection will fail.

The framework doesn't replace thinking — it directs it. Just as the Müller-Lyer illusion persists even after you prove the lines are equal, the intuitive pull toward posture perfection will persist. Frameworks provide the discipline to "trust the ruler over the illusion."

Redistributing responsibility across security functions. Traxler presented her analysis of 16 enterprise security functions — from vulnerability management to insider risk to threat hunting — asking three questions for each: what changes with cloud migration, what stays the same, and what new mindset is required?

For incident response, the shift is from suspicious hosts to compromised identities — a fundamental mindset change. Log sources explode (CloudTrail, VPC flow logs, GuardDuty) while familiar host and network logs become less reliable or disappear entirely. Core challenges like log inconsistency and correlation remain.

Realigning posture work into vulnerability management. The most concrete organizational recommendation: fold misconfiguration remediation directly into the existing vulnerability management program. A misconfigured S3 bucket is "the new unpatched server" — same workflow (data engineering, project management, prioritized remediation), different data source. This accomplishes two goals: it forces vulnerability management teams to become cloud-literate, and it converts the mountain of posture work into a scalable background process rather than the primary mission of a siloed cloud security team.

Demo / Proof of Concept

▶ Watch: Cloud security teams should fold posture work into vulnerability management —... (26:00)

No technical demonstration was included. Traxler provided a QR code linking to a PDF containing her analysis cards for all 16 enterprise security functions — examining what changes, what stays the same, what new tooling is needed, and what new mindset is required for each function in a cloud migration.

Defensive Implications

▶ Watch: Four-step action plan including the 'power of now' bias — immediate ticket cl... (34:00)

Traxler's four-step action plan for defenders:

  1. Recognize diminishing returns of any single-pronged strategy. Acknowledge that prevention-only obsession has limits. Be suspicious of metrics that confirm optimism bias.
  2. Force effortful thinking using established frameworks like NIST to structure analysis. Engage System 2 deliberately.
  3. Abandon the catch-all cloud security team. Make cloud security part of everyone's mission — threat hunters, vulnerability managers, incident responders, and leadership.
  4. Interrogate the power of now. Identify where present bias is influencing decisions. Closing a vulnerability ticket (immediate reward) feels better than designing a resilient backup system or exercising incident response (massive but abstract future reward). Actively counterbalance this bias.

Key Takeaways

  • The cloud security industry's obsession with posture management and least-privilege perfection is driven by cognitive biases — not evidence-based risk reduction.
  • Metrics without context are narrative fuel, not intelligence. Cherry-picked vendor statistics reinforce System 1 thinking rather than informing strategy.
  • NIST's technology-agnostic framework serves as a "ruler for cognitive biases" — its Detect and Respond functions directly challenge the optimism bias inherent in a Protect-only strategy.
  • Misconfiguration remediation belongs in vulnerability management — it's the same workflow with a different data source, and it frees cloud security teams from the hamster wheel.
  • The next 15 years of cloud security must distribute responsibility across all security functions rather than concentrating it in a small team of cloud security engineers.
  • The "power of now" bias causes organizations to overinvest in immediate, measurable activities (closing tickets) while underinvesting in high-impact, harder-to-measure resilience capabilities.

About the Speaker(s)

Kat Traxler is a Principal Security Researcher at Vectra AI, specializing in offensive security research in public cloud environments. She has a track record of identifying vulnerabilities and publishing research across Google Cloud and AWS, with previous fwd:cloudsec talks on primitive roles in GCP (2020), AWS replication service exfiltration (2022), and GCP service agent abuse (2023). Her work bridges offensive research with strategic industry critique.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A well-argued strategic critique of the cloud security industry's posture obsession, backed by behavioral economics rather than technical research. Traxler's offensive credentials give this talk weight that a governance-only speaker couldn't carry, but it's deliberately non-technical and doesn't deliver new vulnerabilities, tools, or techniques.

Heather Calloway (CISO) — MUST SEE

This is the talk I wish every cloud security team lead and CISO would watch. Traxler articulates with precision the organizational dysfunction that keeps cloud security programs stuck in reactive posture management, and provides a concrete framework for redistributing responsibility across the enterprise — exactly the transformation most organizations need.

→ Top-rated talks at fwd:cloudsec Europe 2025

All talks from fwd:cloudsec Europe 2025