Operating in Chaotic Times — Resilience, Culture, and Team

▶ Watch (00:48)

Jeff Moss opened the 28th Black Hat USA by asking whether anyone in the room felt they understood what was happening. Nobody raised a hand. The Defcon badge order illustrated it: a tsunami flooded the Vietnam factory for two days, then a new August 1st tariff evaporated all freight capacity in Southeast Asia overnight. Two simultaneous disruptions. One is manageable. Two is the new normal.

His prescription: build your team before the crisis. A Canadian hospital CISO in the audience had taken a two-thirds pay cut from the private sector because the mission justified it. Culture outlasts any strategy document.

“If you optimize for absolute efficiency, you’re going to become brittle.” — Jeff Moss

The Floppy-Disk Era — When Viruses Were Pranks

▶ Watch (18:52)

Hypponen joined F-Secure in 1991 as a 21-year-old programmer and was immediately reassigned to reverse-engineer MS-DOS viruses. He collected every known virus at the time (about 150), one per floppy, analyzed each one, and had complete coverage of the entire problem. The viruses were written by teenage boys for pranks: a message after 100 reboots, music on a specific date, a walking figure replacing your program. The authors made no money and gained no fame.

Brain, from 1986, embedded a physical address in its boot sector: 730 Nizam Block, Allama Iqbal Town, Lahore, and two names, Basit and Amjad. Hypponen flew to Lahore in 2011 and knocked on the door. He walked through tracking down Brain virus authors in Lahore (23:36) on camera: Basit and Amjad answered, still at the same address 25 years later.

The Criminalization of Malware — Money, Nation-States, and Ransomware

▶ Watch (33:51)

2003 is when money arrived. Spam botnets first, then banking trojans, then ransomware. The same year, Hypponen’s team traced their first case to a government — spear-phishing targeting ministry staff. China, Russia, the United States. Stuxnet in 2010 proved software could set back a nuclear program.

The criminal ransomware model worked until 2017. Gangs built brands on reliable decryption. Then WannaCry — government ransomware using NSA’s own exploit (37:13) and NotPetya — cyber weapon disguised as ransomware (39:23) broke it. North Korea spread EternalBlue — an NSA-built exploit, stolen and sold — across US targets. Russia’s NotPetya escaped Ukraine and forced Maersk to reinstall 4,000 servers and 45,000 PCs. Neither paid out. That reputation was gone.

Security Is Better Than Ever — Why It Doesn’t Feel That Way

▶ Watch (42:52)

Security is better than it was ten years ago. Java and Flash are gone. Restricted OS models — iOS, Android, Chromebook — made mass exploitation expensive. The Xbox One has been out twelve years with no jailbreak. Pegasus costs $100,000 per target. That’s not a failure; that’s the cost of entry rising.

“When you do things right, people won’t be sure you’ve done anything at all.” — Mikko Hypponen

The wins are invisible. Ransomware fills headlines because it’s loud. Hypponen makes the scale concrete in boardrooms by opening the live LockBit victim list on Tor (45:57) — companies from Spain, Iceland, every sector, the list never ends. Attackers scan for unpatched VPN servers and take whatever they find.

AI and the Next Decade — Defenders Currently Ahead

▶ Watch (57:20)

Defenders are ahead in AI adoption right now. That lead won’t hold. In 2024, large language models discovered zero zero-days. By the time of this talk, the count had already reached a couple dozen, all found by researchers. Researchers finding bugs means patches. Attackers finding bugs means breaches. Both are coming.

“When you do things right, people won’t be sure you’ve done anything at all.” — Mikko Hypponen

Leaving Cybersecurity — From Antivirus to Anti-Drone

▶ Watch (59:49)

After 34 years at Data Fellows, F-Secure, and WithSecure, Hypponen’s notice period ends the Tuesday after this talk. Next Thursday he joins Seno Fusion, a defense contractor building drone defense systems. His reason: Finland sits two hours from the Russian border, and the war reshaping Europe runs on UAVs, marine drones, and ground drones.

“I’ve been fighting programmable threats all my life.” — Mikko Hypponen

The logic transfers directly. Malware evades detection; defenders update signatures; malware adapts again. Drones do the same thing. Same cat-and-mouse, different hardware.

Notable Quotes

If it’s smart, it’s vulnerable. Mikko Hypponen · ▶ 32:25

Money has become data. Mikko Hypponen · ▶ 42:59

When you do things right, people won’t be sure you’ve done anything at all. Mikko Hypponen · ▶ 58:24

I’ve been fighting programmable threats all my life. Mikko Hypponen · ▶ 1:01:47

If you optimize for absolute efficiency, you’re going to become brittle. Jeff Moss · ▶ 15:52

Key Takeaways

  • Treat ransomware as permanent infrastructure risk — the first decade of corporate attacks is just the beginning.
  • Invest in platform hardening over perimeter: restricted OS models have raised the real cost of mass exploitation.
  • Stop blaming users — if a dangerous link exists on their machine, the failure is yours, not theirs.

About the Speaker

Mikko Hypponen

Chief Research Officer at Withsecure. Mikko is a globally recognized cybersecurity expert and researcher with over 30 years of experience in information security.