Video summary
Wendy Nather emphasizes that effective incident response requires extensive preparation through tabletop exercises, particularly in areas like legal readiness and decision frameworks. She advises organizations to create pre-approved email templates for sharing information with providers while redacting sensitive details, ensuring they can act quickly when necessary. Additionally, she recommends establishing a clear decision framework ahead of time so that specific individuals are designated as the authority at any given moment during an incident. This preparation is crucial because procurement processes often cannot be completed overnight, and forensic logging capabilities may not be enabled by default or even available until after a breach has occurred. Therefore, teams must practice contacting suppliers immediately to escalate services like Multi-Factor Authentication (MFA) or enhanced logging before they are needed in a real crisis.
The speaker also highlights the importance of building trust with law enforcement and other external partners well before an incident occurs, noting that not all FBI field offices can handle cyber incidents and that finding the right contact takes time during high-pressure situations. She suggests practicing scenarios involving insider threats or unexpected events, such as investigating a colleague who has left their office for lunch, to ensure teams are comfortable with difficult realities. Furthermore, Nather points out that many organizations do not realize they have hidden data centers managed by third parties until something goes wrong; tabletop exercises can reveal these unknown assets through contract reviews and discovery processes. It is also vital to test infrastructure resilience, such as the ability to handle mass password changes without causing a denial-of-service situation or operating in degraded states if power fails due to flooding or other disasters.
Secure communication strategies must be rigorously tested during these simulations because relying on standard email or phone lines can fail when dealing with insider threats or compromised networks. Nather shares an anecdote where she had to use fax machines and LinkedIn connections to reach a CISO after all normal channels were blocked, illustrating the need for creative backup plans. She encourages teams to practice "being evil" by having red team members simulate attacks that exploit gaps in their own planning, such as trying to disable malware keys covertly or managing communications when key decision-makers are unreachable due to vacation policies. By simulating these worst-case scenarios, including situations where critical leaders cannot be contacted, organizations can identify weaknesses and refine their response protocols before a real event occurs.
Finally, Nather discusses the interconnected nature of modern cyber threats through examples like Blackbodo ransomware, which impacted thousands of unrelated organizations via supply chain vulnerabilities. She describes participating in high-stakes competitions like Cyber Storm 5 and Atlantic Council challenges where students brief simulated national security councils on complex international crises involving space debris physics or global satellite networks. These exercises teach participants that they cannot simply patch cargo ships overnight or cut internet cables to another country without considering legal, physical, and diplomatic consequences. Ultimately, she concludes that because the digital ecosystem is so intertwined, local incidents inevitably have worldwide ripple effects, making it essential for everyone to step outside their area of expertise and practice responding to unpredictable scenarios involving activists, nation-state actors, and private sector non-cooperation.
Read the full video transcript
sharing is I don't know a fishing email.
So they would bring a template email to
their legal team and say okay this is
what we want to share. What parts do we
have to redact? Like maybe the name of
the executive it was sent to or
something like that. But if they got
permission for this template ahead of
time, then whenever it happened, they
could go ahead and send it out. So,
these sorts of templates can be really
useful to get um to get requests done in
advance to your providers. You have even
more providers than you realize. Um,
another thing that's really good is to
have a decision framework to decide
who's going to decide ahead of time,
who's going to have the ball at any
given time. This is a really good
resource from Discernible, Inc., which
is run by Melanie Ensign and she has
great uh advice for people who have to
communicate and decide well during an
incident. So uh I really recommend
looking at that and and looking at her
decision framework to see if that's
something you want to adopt while you're
doing an incident.
Um, there are a lot of cases where you
may have to buy something really fast
during an incident and procurement
typically does not take overnight unless
you're a very small organization.
Um, I can almost guarantee you that you
will not have the level of logging that
you need for forensics. You won't have
it turned on by default. And in fact, I
know organizations where they're not
even allowed to put an agent on the
endpoint until they're pretty sure that
they've had a breach and then they can
start doing their EDR and stuff. It's a
little bit late for that, but in a lot
of cases, you have to count on the fact
that you're not going to have all of the
data that you need right now. You may
not have subscribed to the highest tier
of logging service. So, you're going to
have to get on the phone to your
supplier, to your provider, and go, "Can
we turn this up really fast because we
need this now." So, talk this out during
the tabletop. If you need to go out and
buy something, if you're not using MFA
right now, um I I I worked for Duo
Security and we had a lot of incidents
at very very big well-known companies
where they had to roll out MFA very fast
because they had an incident. So plan
for fast procurement who's going to do
it and who's going to help you. And it's
it's good to have a contact at law
enforcement that you've already talked
to, you already trust, who already knows
you. Uh in the US, it can be a problem
for example to find the right FBI field
office because not all of them can
handle a cyber incident. So, you know,
it's good to do this homework ahead of
time and know anybody else who you might
call outside and whether you have
permission to call them during a during
an incident.
So, the the exercise portion of it,
exercising this muscle, how many people
remember the target breach of many many
years ago? Um, you know, it it was the
the example of, you know, a really bad
breach that they, you know, should have
maybe should have been able to deal with
better, but they did turn everything
around after that. They really came up
with a good security program. They even
gave tours of their sock. I'd been in
there. And they did a lot of things
including spending a lot of their time
looking at headlines of other things
that have happened in other places and
going can we detect this in our
environment? What would this look like?
And if we can detect it, can we automate
that detection? So they would go ahead
and do that and then that that would
free up their analysts to go look at
something else that they couldn't
automate. So this is another good thing
to do during a tabletop.
The other thing that they did is they
had weekly calls. They had weekly
tabletop calls where all the business
leaders had to get on the phone whether
they wanted to or not. Yes, they would
whine about it, but they had they got
them used to everybody showing up on
this conference call on on the same day
and then going, "Okay, here's the
scenario. We're not going to need you
and you and you. You can you can go back
to work. We're going to need you and you
and you to do this scenario." So they
got used to this muscle and and it was
the case where the business leaders in
particular all got used to responding to
being on the call.
And I have to point out, as you probably
know, not all the incidents look like
the headlines. They don't look like the
cool stuff. There's like really really
weird
um insider things. One time I had to
investigate our own inspector general,
which is really awkward. We had to wait
for him to leave his office at 5:00 p.m.
so we could go in and image his machine.
It was It's very embarrassing. So things
that you're not planning for, you know,
practice those sorts of things. Just
roll some dice and go, what if it's this
person who's an insider? How would we
handle that?
And uh as I mentioned, it's good to
teach other departments and roles how
how it looks for them and what we're
going to need from them, especially
CISADM's uh excuse me, SR engineers.
It's a lot it's a lot fancier now than
when I was a cisadmin. But anyway, you
know, they're going to see stuff way
before you are. And it is invaluable to
have somebody come in your office and
close the door and say, "I think there's
something you need to know." Because
that's where you're going to get a lot
of really good threat intelligence. Uh
we've also done some research together
with the Sciantia Institute. I did this
when I was at Cisco and we actually
found that those who did ROSP specific
awareness training did a lot better on
their incident response than those who
hadn't. So, don't just make everybody
watch the same, oh, you need to protect
data video. Talk to everybody about what
it's going to look like for them and
what their roles are going to be.
Important details like secure
communications. Have you figured out yet
how you're going to communicate securely
in the middle of an incident?
Many years ago, I could not even get
Microsoft's Thread Intel team to send me
a working PGP key.
So, you never know until you actually
try it out. Um, another time I had to
try to get hold of one of the hardest
problems is getting hold of somebody
who's never heard from you before and
trying to convince them that you have
something that they need to know. I had
to reach out to one retailer and it was
about an insider threat who was selling
access to their point of sales systems.
So, I didn't know where this insider
was. I could not send email. I couldn't
call their help desk. I couldn't leave a
voicemail. I had no idea where they had
access to. So, I had to go through
LinkedIn and find somebody who knew that
CESO. Also, nobody answered their phone
because nobody does this anymore. So, it
it's kind of tough. The people who do
answer the phone, by the way, are
executive assistants. If you can find an
executive assistant to somebody, they're
more likely to answer the phone. But
anyway, I went through LinkedIn, found
somebody who knew the CISO, and had him
go to the CISO and say, "No, really,
Wendy Nathther needs to talk to you and
and you need to take her call." And I
got on the phone with him and said,
"Look, I have all this data. I have this
threat and tell report that was sent to
me. Do you have any fax machines in your
building? And he said, "Yeah." And I
said, "Okay, go pick one at random and
stand in front of it and tell me the
number. I'm going to send you this data
by fax."
Because that was the best thing I could
think of at the time. So work out your
secure communications in these tabletops
ahead of time. And also finally, it's
great to do a tabletop because you can
help build it and you can be evil. Well,
why should the red team have all the
fun? You know, you know your business,
you know your organization, you know how
bad things can get. Let's have some fun
and play with it.
Um, another thing to do with tabletops
is discovery.
And really, sometimes people don't know
that they have other data centers. I
have a friend who who likes to read
documentation for fun. I know he's one
of those guys. And he was reading
third-party contracts for his agency and
he found out that there were two acres
of additional data center that they
didn't know they had. It was in the
contract. It was being managed by a
third party. I'm sure if things had, you
know, gone south, they would have
noticed because some large application
would have gone down. but it was running
fine, so nobody knew. And the address
was there in town. So he drove drove
over to it and sure enough like I don't
know 14,000 15,000 servers and data
centers there that nobody knew about. So
don't be don't be too surprised. You can
discover things like this when you're
doing tabletops.
Um, yeah, it's a good idea to to figure
out whether if you need everybody to
change their password at the same time,
whether your infrastructure can handle
that,
especially if you need to do it more
than once.
Uh, I was also at an organization that
had to suddenly get everybody to change
their passwords and they couldn't
because the infrastructure was melting
down. So, that turned into a DOS
situation.
and what does it look like to operate in
a degraded state? A lot of people don't
think about that and that is part of
resilience. Uh what's the minimum stuff
that you can get back up? I was working
for a bank when and we were I was based
in Chicago when the Chicago River broke
through the tunnels and flooded the
downtown including the basement which
meant you had no more power in the
Chicago border of trade building and we
had to rebuild our production backbone
in two different locations one in New
York City and one outside of Chicago. So
there were people who were actually
carrying down and this is how old this
is sun four servers
down 11 flights of stairs in the dark.
So um what's the minimum that you need
to have your operation going back into a
kind of operational state until you fix
everything else.
And then the other assumption of course
everybody's just going to come into the
office.
I have a a friend who gave a great talk.
He was working for the Texas Department
of Transportation.
He wasn't supposed to start his job yet,
but they had a ransomware incident. And
this was just as the pandemic lockdown
started. So, nobody was going into the
office. They had just finished locking
up all the badge readers. There was one
person left in the data center and he
had to stay there because he was the
firewall administrator and he had to set
up VPNs for everybody to come in
remotely.
So, uh, and the poor guy, he couldn't
leave because the door was propped open
and and the badge readers had been
disabled. So, uh, yeah, it it was a
whole it was a whole thing. His talk is
really really funny if you ever get a
chance to listen to it.
uh and identifying gaps. Very important.
Who who's really in charge of that?
Well, except for this part. I mean, we
still have um hang on.
I need my vodka. Um there are
there are so many things that people,
you know, assume or two people are going
to try to do the same thing. they're
going to step in and try to do the same
thing at the same time. So, that's a
good time to to do that. Uh, I mentioned
logs already. Do you all do you have the
logging at the level you need? No, you
don't. Does anybody think they have the
level of logging that they would need
for a forensic investigation?
No, it's not turned on. Do you HD? You
You kind of do. I'm not surprised. Uh,
only HD.
Um, and what do we expect from our
partners and our customers? How are we
going to communicate with them? Do we
have to write a tool, for example, for
them to run to find out if they're
affected by what's going on? That's
happened before. And that's why, you
know, sometimes you can't notify right
away because you you don't want to just
say, "Yeah, we don't know if you're
affected. Good luck." You want to be
able to give them something. And so we
had to wait a week or two and say,
"Okay, here's the tool that you can run
to figure out if you're affected." Uh so
practice those things as well. Um, I
heard a really great talk
by u a a large security vendor who had a
breach and they could not notify for six
weeks because they did not have per
object logging turned on for AWS
and uh they had to do this that their
stuff was running in in just a little
place called US- East1.
It took six weeks for AWS to get the
logs for them that were just for them at
a per object level till they could make
sure that they really did have this data
accessed and then they could announce.
So, these are sorts of things that you
have to have good relationships with
your providers because no matter what
your your um your contract says, you're
going to end up asking them for things
that you never thought you would. So,
and then finally, I mentioned preparing
for the unexpected. Uh, does anybody
here use chaos engineering
at all? Yay. Um, we we also found in the
research that we did that anybody who
used uh chaos monkeys or the equivalent
were uh also much better at incident
response because it would break things
that they would never have thought would
break and it surfaced a lot of things
they had to practice. Another cool thing
if you do a tabletop is have a key
persona key decision maker sit it out.
Say, "Okay, you're now on vacation in
the Bahamas. Uh you don't have phone
signal. We can't get a hold of you.
Okay, let's run the exercise without you
and see what happens." Uh that there are
things like this that you have to do in
some banks. Uh when I worked for a Swiss
bank, I had to go on vacation for I
think it's like two or three weeks and
was not allowed any contact so they
could surface any fraud. But it's a
really good idea to practice having
somebody be missing whenever you have to
do really fast decisions like during an
incident.
And of course today there are ripple
effects from breaches from providers you
have never heard of. Um, has anybody
heard of the Blackbod ransomware
incident?
This was a platform that serviced a lot
of nonprofits
and uh, again, Scientia did did some
research on this and found that the
ripple effects from their ransomware
incident affected as many as a thousand
other organizations and most people had
never heard of Blackbod until this
happened. So sometimes you will find out
that you have second or third tier
providers that you don't have the
contracts with that you're relying on
your provider to manage and suddenly
something's happening there and it's
hitting you. It doesn't matter how big
an organization you have, you can still
be affected by a really small
organization.
Okay, let's get to the fun part. Here
are some of the tabletops that I've
done. Uh the first one I did was for a
Swiss bank and uh we we it was just a
few of us in the security team. We sat
in a in a conference room and talked
through it and the person who was
leading the exercise kept asking over
and over again, "Have you called the CTO
yet as this situation unfolded?" And the
guy who was investigating it kept
saying, "No, no." And our CTO was
saying, "Why haven't you called me yet?"
So, I can tell you just about every
senior leader wants to hear sooner
rather than later about an incident,
even if you don't know yet whether it's
an incident. Sometimes it can take a
while to figure out whether it is, but
they don't want to be caught unprepared.
So, uh, go and ask your bosses. I'm
pretty sure they will all say, if in
doubt, tell me sooner rather than later.
Even be prepared to say, here's what we
know. Here's what we don't know. here's
what we need to find out and here's how
long we think it's going to take us to
find out and I'll let you know again in
an hour or in five hours or whatever.
You know, I'm I'm calling AWS and
they're not calling me back or whatever.
Um but you notify them sooner rather
than later. The other thing the kind of
the flip side is that is be careful of
people on your team who are afraid to
say anything until they understand
everything.
I know it's really tough to to have to
go and say, "I don't know what's going
on." But you got to practice saying that
we don't know what's going on, but we
think this is what is happening, and
here's why we think it. And and you
know, explaining that way. Um, and the
other thing is that we only had our our
top leadership doing this exercise, but
it's really better if you run it through
first and then you take it back to your
own teams and run it with your larger
teams because everybody needs to hear
the thought process. And it's a good
thing to say, "This is what we found out
doing it with just the top team, and now
we're going to do it this way, and this
is what you should know about." And then
they're going to surface questions that
you hadn't thought of. So, uh, it it's
really good to bring it to larger teams.
The next size up, the next tabletop I
did was run by the US Department of
Homeland Security for the retail sector.
It was an exercise called Cyberstorm 5.
And, you know, it was all just very
exciting, flames and and all this sort
of stuff.
uh and and
what they had us do was all call in and
they started with a scenario. They
started with a set of injects. The
funniest thing was they started with um
the the first injects were supposed to
come from the FBI. Here are the
indicators, you know, and this is how
the exercise starts. And we all kind of
laughed quietly because we knew that the
FBI would never be the first to share
indicators. But anyway, um it was the
scenario was a uh some malware that uh
when sent certain commands or when you
tried to investigate it would brick the
system that it was on. And this was
spreading and it was, you know,
everything that what we had to do was
describe what we were going to do to the
runners of the of the the dungeon master
to run those who were running the
simulation because we couldn't just do
anything. There are all sorts of weird
things that somebody can do during a
tabletop that you're not prepared for no
matter how you thought it out. Oh yeah,
we're going to take the CEO out and give
her three martinis and domain controller
access.
Do you know what's going to happen if
they do that? I don't know. So they kind
of herded us through the scenario
[snorts] and it turned out when when
somebody was finally able to get to get
an image of an affected machine, they
were able to find a public and private
key pair that could be used to uh with
the the command and control server to
send a disable command to the malware so
that they could disable it without it
bricking.
So you know it was great. The group that
found that was the PayPal threat
intelligence team. Yay. Good for them.
Uh, and at that point, DHS said, "Okay,
the exercise is over. We're done." I was
like, "What?
Wait, there's so much more that you
could do with this exercise." First of
all, as I mentioned before, the
difficulty in doing secure ad hoc
communications with somebody, that is a
problem no matter where you go. trying
to call somebody and saying, "No,
really, I'm not trying to sell you
anything. I need to talk to your
security team." That's really hard to
do. I would have liked to see the
tabletop exercise include that. And then
finally, since they found the public and
private key pair, how would you get that
key pair covertly to anybody who needed
it without the threat actor finding out?
because the threat actor was still
active and could have sent, you know,
brick commands to whatever was still
infected. So, could you have stood up a
C2 as a service for retailers who didn't
know how to do this on their own, but
you could set it up so that it could
send the disable command for you. If you
had been able to set that up, how would
you communicate that to the retailers
again covertly, securely? That was the
challenge that I really wanted the
tabletop to take on because I think
that's a big problem that we we need to
figure out. But anyway, it wasn't my
exercise. I got a Secret Service
challenge point out of it. It was nice.
It was fun.
Okay, the next one up, um, I don't know
if you've heard of the Atlantic Council,
but they do, um, regular cyber 912
strategy challenges that's supposed to
be the day after a cyber 911 and what
you do about it. And this competition
takes place in a lot of different
locations around the world. And um it's
they have three rounds and uh this is
for usually college students, usually
grad students, sometimes undergrad
teams. If you have never done this, it
is a lot of fun. Uh so if you're a
college student, try to get together a
team and see if you can participate in
this. And uh there are international
teams and judges. Sometimes they're
on-site uh challenges and sometimes
they're virtual. uh sometimes teams will
will come in on Zoom from Africa or you
know Kazakhstan or whatever to take part
in these challenges. Um it it's it's
enormous. Uh what happens is they give
the teams they're usually about 20 25
teams. We give them the first
intelligence report with a set of of
fictionalized injects and they have
three weeks to create a briefing
document. Uh, in the US for this
competition, they have to pretend that
they're briefing the National Security
Council. So, they have to come up with a
briefing document. They have to come up
with a a one-page decision document and
a 10-minute presentation. And as judges,
we play the NYSE.
Now, what's really fun about this is
when I'm doing this competition in DC,
the judges sitting next to me sometimes
are on the National Security Council for
real. And so I get to listen to their
feedback that they're giving the
students. No, that's the wrong agency to
handle this. You know, you should have
done this, you should have done that. Uh
I I learn a lot. After we get to the
semifinals, they get this next set of
injects and they have overnight to again
to write a decision doc and to come up
with a 10minute briefing. This is the
night when most of these teams do not
sleep. They are just up all night
figuring out what to do with this
inject.
Uh this is what one of them looks like.
Uh I I did this one. Uh if you've ever
seen Joe Men, I got permission from him
to to use him as an example.
And then finally, intelligence report
three, the finalists, they have to read
the third set of injects and then they
have 15 minutes to prepare their
briefing and go in and brief the judges.
This is just like real life. They have
to read it really, really fast.
And then there are three winners at the
end of this.
So, you know, I get I have fun playing
as a judge because I will pretend to be
somebody on the NSC or some other policy
council and I can either play like I'm a
war hawk and I'm ready to to go to war
over this or uh I can play stupid and
say, "Yeah, I don't understand. Why
can't we just do this?" And whatever and
see how the students handle it because
they're going to be briefing real
people.
So, they learn how to present their
action plans very clearly to these
council members, whatever role they're
they're playing. Uh, they have to think
on their feet because there's a Q&A
section and as judges, we ask them
about, you know, what does this mean?
What is this doing? And and and that
sort of thing. And they have to identify
everybody
who would handle this from a from a
policy standpoint, from a government
standpoint, what they're going to say to
the public, what the president would
say, you know, if we had to make an
announcement. This is usually not just a
nationwide crisis, but an international
crisis. What are we going to say to our
allies? And I love talking a lot of the
the US militarymies take part in this
and they're very, you know, oh, you
know, we're going to we're going to deny
everything. We're going to, you know, do
a a an exercise in the Taiwan Strait.
We're going to scare these people. And
one scenario turned out to be was our
bad in the US. The NSA created a
backdoor and it was found by a bad actor
and exploited. And the NSA said, "No,
you can't get rid of it. we still need
it. So what do you say to five eyes?
What do you say to to other countries
who are being affected by this? This is
all, you know, an enormous part of the
challenge that they have to deal with.
So are there laws and precedents for
this situation? The the students are
usually in law or international
relations, policy, cyber security.
um they will say things like, "Yeah,
we're just going to patch all the cargo
ships because they're all hit by
ransomware." First of all, if you talk
to somebody who actually knows these,
you will know that cargo ships reject
just about 90% of any patches that you
wanted them to try to install. But also,
you have them all lining up at docks,
it's going to take months to patch all
of these cargo ships. I had one team
say, "Yeah, we're going to take North
Korea off the internet."
And I said, "Okay, you're going to do
that? How exactly you're going to invade
another country and go cut the cables
that lead to North Korea? Exactly. How
are you going to do this? So, um, you
know, they need a lot of help with
this sort of thing with with, you know,
practical cyber security. So, I got to
write a scenario for the competition for
Geneva. They asked for it to be in
space. So, I got to write a tabletop
about a cyber attack on satellites.
And you know this is really fun because
there's so many political issues like
between Switzerland and the EU it's not
the same uh you know what are the laws
there and everything and also there are
the laws of physics to deal with. Has
anybody heard of Kesler syndrome?
Kesler syndrome is when uh especially in
low earth orbit where there are a lot of
satellites. If something breaks up the
de the debris can hit other things and
create more debris and it increases
exponentially until suddenly you have
debris everywhere hitting everything
which is why you can't just go shoot
something down anymore.
So, um, some of the scen the elements
that I wanted the students to deal with
are the fact kind of echoing crowd
strike that you can't, you know, in in
that case you had to walk over and patch
things on site. You can't do that in
space. You can't walk over and patch it.
I had a scenario where the the uh
satellites that were taken over were
jamming the main communications
frequency,
so you couldn't stop them. And there are
policy gaps between cyber security and
space. There are space centers and there
are cyber security centers but how do
they work together if this is a cyber
attack in space?
I the scenario I decided to make it
activists because you know everybody
does nation state actors and it's kind
of boring. So these were student
activists in Switzerland who were
protesting
um a billionaire's
uh sending of thousands and thousands of
satellites into low earth orbit. That
that doesn't remind you of anybody, does
it?
Um so so this this actor in the scenario
was American. He was very clueless. He
moved to Switzerland and changed his
name to something French. Very
pretentious of him. Uh he was not
cooperative. So what do you do when the
private sector will not cooperate with
the government? That was a thing I
wanted them to explore. And there are
more and more deployments. I also had
the activists panic because they just
wanted to take out some satellites. They
didn't realize like they didn't
understand Kesler syndrome. They didn't
realize how bad this was going to be.
And uh also disinformation was making it
worse. There were a lot of armchair
satellite experts saying why don't you
do this and then the policy makers were
going in and saying yeah why don't we do
that and you know the real scientists
were going because that's stupid because
physics you can't just do this and so uh
it it was it was a great exercise
uh I outlined this last January before
the inauguration but more and more
headlines about
about satellites and about them being
deorbited and just spraying their uh the
the components all over uh and rare
elements that they're made of whether
that is destroying the ozone and
everything [snorts] and these things
started popping up after I had written
the scenario and I thought oh my god
it's coming true um the students thought
of things that I hadn't in the very last
scenario uh one of the last injects was
a little IRC transcript from to the
activist going oh my god what have we we
have to tell somebody. We didn't think
it was going to get this far. So the
students, the competing students said,
"Why don't even if the billionaire won't
talk to us and his company won't talk to
us, why don't we go talk to the
activists now now that they're scared
and you know, maybe they'll help us
figure out how to deal with this."
And one of the threat actors, it was the
the Uganosa
in in Zurich. They have a space program.
So I made them the source of some of the
activists and their team from the atsuru
actually won. So I thought that was
really cool. I was not there to hear
when they when they read the inject and
said wait a minute that's us.
So why does it matter all to us wrapping
up here because even if it's a local
tabletop exercise
it's the the world's going to come
crashing in. We are too intertwined now
as an ecosystem for it to be just one
organization that has an incident. I I
have not heard of any incidents anymore
that do not affect, you know, don't have
ripple effect somewhere. Um and even
though college students are smarter than
I was at the time, uh a lot of them
still don't have that real world nah
that's never going to happen sort of
experience with cyber security. So also
when you're doing these, try to talk
through these scenarios outside of your
areas of expertise. Don't just focus on
what you know. Go ahead and explore
because you know it's just a tabletop.
So thank you to everybody and I will
look forward to seeing you here at the
conference.
[music]
>> [music]