Corporations Are Missing From Every Threat Actor Map
Standard threat actor diagrams include lone hackers, patriotic collectives, mercenary groups, and nation-states. Corporations almost never appear. Conti argues this is a mistake. The largest tech companies, compared against nation-states in the cyber and cognitive domains, are competitive. With Microsoft at position 11, Apple close behind, then Nvidia, Amazon, Alphabet, and Meta at 24 in a global market-cap ranking, seven major corporations sit inside the top 24. Treating companies as purely financial actors misses what they can actually do.
The Power Balance Between Corporations and Governments
A large tech company lobbies, donates to campaigns, files lawsuits, and exits markets to pressure governments. Governments counter with laws, regulation, taxes, sanctions, and procurement authority. The balance shifts by relative size. Against a small country, a major tech company can coerce the government outright. Against a large country, the company must comply. Conti frames this as a tug-of-war. A corporation facing a smaller state operates with weaker guardrails; one facing a major power operates inside a much tighter box.
How Corporate Behavior Changes When Conflict Starts
In peacetime, companies pursue profit and follow laws. In wartime, those assumptions break. Financially motivated companies try to sustain operations on both sides of a conflict, avoid strong public positions, and look for ways to keep functioning. Governments turn coercive: the Defense Production Act lets them commandeer company capabilities for offensive warfare regardless of what leadership wants. Cross applies the MICE model (money, ideology, coercion, ego) to corporate leadership to explain when a company might act against its own financial interest, particularly during conflict.
The Capabilities Pyramid: Advertised vs. Actual
Conti describes a pyramid of capabilities any company holds. At the top sit the advertised features. Below are premium upsells. Deeper still are capabilities the company uses but does not publicize. Lower are capabilities it has chosen not to deploy. At the base are capabilities nobody inside the company has considered. A researcher hacked together augmented-reality glasses with live facial recognition years before companies marketed the feature. The threat actor does not wait for the product team to notice what is possible.
From Light Bulbs to Mega-Corps: Consumer Products as Weapons
A wifi-enabled light bulb tracks occupancy patterns and scans for Bluetooth and wifi devices. Add a microphone and motion sensor and it logs who is home and when. A robotic vacuum maps floor plans, captures audio and video from every room, and can collect DNA from debris. A cybersecurity company can silently ignore specific malware, run attribution-for-hire, and search user files across its entire customer base. A cloud provider can harvest tokens and secrets. An AI company can run synthetic persona swarms. One mega-corp with 15 portfolio companies across these categories would rival a mid-sized nation-state.
Countermeasures: Red Teams, Architecture, and Oversight
Standard misuse models cover criminals and end users. Cross and Conti add two more: a company’s own executive team, and a government that appropriates company capabilities. Companies can run “what if we were evil” red-team exercises, then build architectural controls and organizational checks before a crisis hits. NGO audits could publish certifications against specific behaviors. Government policy frameworks currently focus on critical infrastructure, but robot taxis and social media platforms are dangerous and fall outside that category. Systematic capability mapping would help close the gap.
Notable Quotes
political ideology, uh coercion or ego. Tom Cross · ▶ 13:38
it’s not what a system says it does, Greg Conti · ▶ 26:08
Why does your vacuum have a face Tom Cross · ▶ 26:21
Key Takeaways
- Corporations belong on threat actor maps: seven companies rank in the global top 24 by market cap.
- Consumer products hold layers of capabilities their makers have never publicly acknowledged or considered.
- Standard threat models miss the executive team and a hostile government as potential misuse actors.
- A “what if we were evil” red-team exercise reveals capabilities that need architectural guardrails before conflict starts.
About the Speakers
Tom Cross is an entrepreneur and technology leader with three decades of experience in the hacker community. He attended the first DefCon in 1993 and ran bulletin board systems serving the hacker community in the southeastern United States. He is currently Head of Threat Research at GetReal Security, Principal at Kopidion, and creator of FeedSeer, a news reader for Mastodon. Previously he was CoFounder and CTO of Drawbridge Networks, Director of Security Research at Lancope, and Manager of the IBM Internet Security Systems X-Force Advanced Research team. He holds a B.S. in Computer Engineering from the Georgia Institute of Technology.
Greg Conti is a hacker, maker, and computer scientist. He is a nine-time DEF CON speaker, a seven-time Black Hat speaker, and has been a Black Hat Trainer for 10 years. He teaches Adversarial Thinking at West Point, Stanford University bootcamps, and NSA/U.S. Cyber Command. Greg is Co-Founder and Principal at Kopidion. He served on the West Point faculty for 16 years, leading their cybersecurity research and education programs. During his U.S. Army career he co-created U.S. Cyber Command’s Joint Advanced Cyberwarfare Course and was the first Director of the Army Cyber Institute. He is co-author of On Cyber: Towards an Operational Art for Cyber Operations.