Out of love for the truth and the desire to bring it to light, the following propositions will be discussed. Wherefore we request that those who are unable to be present and debate orally with us will do so by letter.
- A password is not a secret if it has been reused.
- The password "123456" is not a password. It is a confession.
- Any system that stores passwords in plaintext has already been breached — it simply does not know it yet.
- Multi-factor authentication is not a burden. The breach that follows its absence is.
- Security questions whose answers are findable on your Facebook profile are theater, not protection.
- The organization that forces quarterly password resets while forbidding password managers is the wolf guarding the flock.
- Biometrics are a username, not a password. You cannot change your fingerprints after a breach.
- Software that cannot be updated is a liability dressed as a product.
- End-of-life software in production is not a legacy system. It is a standing invitation.
- The vendor who says "security through obscurity" is selling you a locked door made of paper.
- A patch left unapplied for thirty days is a choice. Own that choice.
- The EULA no one reads has already signed away more than you know.
- Default credentials in shipping hardware are not a convenience. They are a skeleton key handed to the world.
- That which is free is not free. You are the product, and you have not read the terms of your own sale.
- Privacy is not the province of those with something to hide. It is the foundation of those with something to protect.
- Data that is collected will eventually be breached. Data that is never collected cannot be stolen.
- The camera in your pocket listens more than your priest and confesses more freely.
- Metadata is not "just" metadata. Metadata is the map of your life.
- Consent obtained through a 47-page document written in legal obscurity is not consent. It is capture.
- Surveillance capitalism is feudalism with better UI.
- The network perimeter is dead. Mourn it and move on.
- All traffic should be treated as hostile until proven otherwise. Trust is earned per-packet.
- An open port is a question. Make sure you know the answer before the adversary asks it.
- The firewall configured by the person who left three years ago is a monument to false confidence.
- Critical infrastructure connected to the public internet is not modernization. It is a dare.
- Every unmonitored network segment is a room in your house you have never entered. Something is living there.
- Encryption is not optional. The alternative is a postcard.
- A backdoor installed for the righteous will be found and used by the wicked. There is no selective physics.
- Weak encryption is more dangerous than no encryption, for it breeds false confidence.
- The government that demands a key to your encryption demands a key to your mind.
- Encrypting only the data you consider sensitive is like locking only the doors you think a burglar would try.
- The most sophisticated intrusion still often begins with a phone call.
- Phishing works not because users are stupid, but because trust is the foundation of human society — and attackers have learned to wear its face.
- The employee who clicks the link is not the vulnerability. The training program that failed them is.
- Every organization has at least one person who will plug in a USB drive they found in the parking lot. Build your defenses accordingly.
- Authority, urgency, and fear are the attacker's greatest tools. Teach your people to recognize the smell of them.
- Vishing is the art of turning your helpdesk against you. The helpful are the first to be exploited.
- Data is not an asset if you cannot account for where it lives.
- The breach you do not detect is not a breach that did not happen.
- Collecting data you do not need is not strategy. It is accumulating future liability.
- A data retention policy that retains everything forever is not a policy. It is an absence of courage.
- The company that says "no data was exfiltrated" and the company that says "we do not know" are often the same company.
- Personal data is not yours. It belongs to the person it describes. Act accordingly.
- Breach notification laws are the floor of your obligation to those affected, not the ceiling.
- Trust no one by default — not the user, not the device, not the network, not the vendor.
- Zero Trust is not a product you purchase. It is a posture you earn.
- Implicit trust based on network location is how attackers become employees.
- The principle of least privilege is not a recommendation. It is a commandment.
- Every service account with domain admin rights is a loaded weapon left on a conference room table.
- Identity is the new perimeter. Defend it like one.
- Compliance is not security. A checkbox is not a shield.
- The audit that finds nothing is not evidence of virtue. It is evidence of inadequate auditing.
- A CISO without board access is a prophet without a pulpit.
- The security policy no one reads has already failed in its purpose.
- Pen testing once a year while deploying code daily is a medical checkup for a moving target.
- Risk acceptance without understanding the risk accepted is simply negligence with a signature.
- Regulations written by those who do not understand technology will always lag behind those who do.
- "The cloud" is just someone else's computer, and someone else's misconfiguration.
- A publicly exposed S3 bucket is not a cloud problem. It is a judgment problem.
- Infrastructure-as-code makes security scalable. It also makes mistakes scalable.
- The shared responsibility model means the cloud provider is not responsible for your failures. Read it again.
- Container security is not inherited from the host. It must be built in from the image.
- DevOps without DevSecOps is a production line with no quality control.
- AI will not save you from cyber threats. It will also be used to create them.
- The deepfake is the phishing email perfected.
- A model trained on your proprietary data and deployed by your adversary is a mirror turned into a weapon.
- Prompt injection is the SQL injection of the AI era. We are about to make the same mistakes again.
- Automated vulnerability discovery means the attacker's reconnaissance is faster than yours. Act accordingly.
- AI-generated code carries AI-generated vulnerabilities. Review it as though a junior developer wrote it at 2am.
- Your security is only as strong as the least secure vendor in your supply chain.
- The update mechanism that delivers software can also deliver malice. Verify everything.
- Open source dependencies are an inheritance of unknown provenance. Audit your inheritance.
- The third party with access to your systems is a door you did not build and may not control.
- Software bills of materials are not bureaucracy. They are a map of what you owe accountability for.
- The incident response plan that has never been tested is a plan in name only.
- The first hour of a breach determines the next year of recovery. Prepare accordingly.
- Paying the ransom does not guarantee decryption. It guarantees you will be targeted again.
- Backups that have not been tested for restoration are not backups. They are hopes.
- The forensics you cannot perform because logs were not kept are lessons written in invisible ink.
- Communicating a breach poorly costs more than the breach itself.
- Security is not the IT department's problem. It is the organization's problem. The IT department is merely the one blamed.
- A culture of fear around reporting mistakes ensures mistakes are hidden until they become catastrophes.
- The security team that says "no" to everything will be routed around like a blocked road.
- Security awareness training watched once a year is not security awareness. It is liability documentation.
- The organization that has never had a breach has either excellent security or no visibility. Determine which.
- Burnout in the security community is not a personal failure. It is a systemic one. The adversary does not take weekends.
- You have already been compromised. The question is whether you know it.
- The adversary only has to be right once. You have to be right every time. This asymmetry should terrify and motivate you equally.
- Security is not a destination. It is a discipline, practiced without arrival.
- Threat intelligence not acted upon is trivia.
- The breach that ruins a company was usually preventable with measures that seemed expensive before the breach.
- The security researcher who finds your vulnerability before the attacker does is not your enemy. Treat them accordingly.
- No technology solves a people problem. No policy solves a technology problem. You need both, always.
- Humility is the beginning of security wisdom. The organization certain of its defenses is certain of a lie.
- The door to which these theses are nailed is not a church door. It is every unpatched server, every reused password, every ignored alert — and it stands open, even now, waiting.
Here we stand. We can do no other.