SecTor 2025 | Grand Finale: Cutting Through the Cyber Noise

Black Hat
Black HatMay 26, 2026

Why It Matters

Balancing AI adoption with basic cyber hygiene is crucial; neglecting fundamentals leaves organizations vulnerable to both new and legacy attacks, impacting national security and corporate resilience.

Key Takeaways

  • AI hype dominates SecTor, but legacy threats persist.
  • Identity and access management remain top security challenges.
  • Government assets expose thousands of outdated subdomains, increasing attack surface.
  • Nation‑state job fraud amplified by AI‑generated resumes and deepfakes.
  • Effective asset inventory and zero‑trust adoption are critical for resilience.

Summary

The SecTor 2025 Grand Finale panel wrapped up the conference by reflecting on the dominant themes that emerged over the past two days. Speakers from Quick Intelligence, Ontario’s government, and Citizen Lab highlighted how AI has become the headline topic, yet classic cyber‑risk vectors—identity theft, ransomware, and unpatched software—remain ever‑present. Key insights included the pervasiveness of AI‑driven hype, the ongoing challenges of identity and access management, and the discovery of tens of thousands of outdated government subdomains that expand the attack surface. Attendees also heard about persistent Outlook zero‑click exploits, the rise of AI‑generated deepfake resumes used for nation‑state job fraud, and the privacy implications of dashcam data. Notable moments featured Dave Mellor dismissing “sovereignty” as a buzzword, Ophy Elwazirchan praising Citizen Lab’s surveillance research, and a vivid anecdote where an AI‑engineer fabricated pen‑test findings to deceive interviewers. The panel also underscored the difficulty of asset management, with speakers noting 60,000 federal subdomains and shadow‑IT servers lingering unnoticed. The takeaway for security leaders is clear: while AI tools can accelerate detection and response, they must not distract from foundational practices. Robust asset inventories, zero‑trust architectures, and rigorous identity verification—especially in hiring—are essential to mitigate both emerging AI‑enabled threats and long‑standing vulnerabilities.

Original Description

Join our Review Board members for a powerful closing session that distills the essential cybersecurity insights from this year's conference. This dynamic panel will synthesize key takeaways from the Briefings program and forecast emerging trends that security professionals should have on their radar.
Leave SecTor with clarity on what truly matters in today's complex threat landscape.
Opheliar Chan | Chapter Co-Lead, OWASP Toronto
Dave Millier | CSO, Quick Intelligence
Maryna Neprosta | Review Board, SecTor
Tom Tran | Senior Manager of Offensive Security, Government of Ontario

Comments

Want to join the conversation?

Loading comments...