Rapid Fire Black Hat with Evgeniy Kharam
Black Hat has never been short on noise. Thousands of security professionals, hundreds of vendors, enormous booths, new technologies, new terminology, and enough marketing claims to make even an experienced practitioner wonder exactly what some products actually do. So, for this special episode of No Trust, recorded at Black Hat in Las Vegas with Evgeniy Kharam, we decided to change the format.
John Spiegel
8/25/20268 min read


Black Hat has never been short on noise. Thousands of security professionals, hundreds of vendors, enormous booths, new technologies, new terminology, and enough marketing claims to make even an experienced practitioner wonder exactly what some products actually do.
So, for this special episode of No Trust, recorded at Black Hat in Las Vegas, we decided to change the format.
With limited time and a very busy conference happening around us, we invited cybersecurity veteran, author, podcast host, and longtime friend of the show Evgeniy Kharam to join us for what was supposed to be a rapid-fire conversation.
It didn't remain particularly rapid-fire.
Instead, the questions opened up a wider conversation about how security professionals should evaluate vendors, why data protection may deserve considerably more attention than it currently receives, whether the industry is reaching peak AI hype, and why attending one of cybersecurity's biggest conferences without a plan may leave you more confused than when you arrived.
Listen Here - https://on.soundcloud.com/RgN9Mn5Ke3QysgmXit
Don't Judge a Security Vendor by Its Booth
Ask someone what stands out at Black Hat and you might expect them to name a particular attack technique or emerging technology. Evgeniy's answer was different: the sheer number of vendors — and the confusion that comes with them.
That confusion is understandable. The show floor contains established security companies alongside startups that many attendees may never have encountered before. Some relatively young companies have raised tens of millions of dollars and arrived with enormous, polished booths. The branding looks impressive. The messaging sounds impressive. But that doesn't necessarily mean someone walking past understands what the company actually does.
Evgeniy's advice is simple: give the vendor a chance, but go deeper than the booth.
His preferred approach is to remove the marketing vocabulary from the conversation entirely. Ask someone to explain, in plain English, what the product does. Better yet, ask for an analogy. If cybersecurity were a house, is the product the lock on the door? The guard dog? The camera? The window? What role does it actually perform?
It's a deceptively useful test. Descriptions about being the world's leading AI-powered cybersecurity platform don't tell a buyer much. An explanation of the problem being solved, how the technology works, where it sits in the architecture, and what happens when it fails is far more revealing.
One of Evgeniy's favorite questions is particularly useful: What would make your product fail during a proof of concept?
Most vendors are prepared to explain why their technology works. Asking where it doesn't work changes the conversation. It can reveal limitations, dependencies, architectural requirements, and whether the person you're speaking with genuinely understands the product.
And sometimes, the right person isn't the person standing at the front of the booth.
For Evgeniy, a solutions architect, sales engineer, or experienced technical salesperson may be better equipped to have that conversation. A great demo is useful, but a demo isn't a substitute for explaining the business problem and how the technology actually solves it.
Stop Showing Everyone the Same Demo
There's another lesson buried in that vendor conversation: people consume information differently.
At a conference, the default response from a vendor is often to pull up the demo or start clicking through slides. But what if the person standing in front of you doesn't want either?
Evgeniy's advice is to tell vendors how you want the product explained. Maybe you want a whiteboard discussion. Maybe you want someone to walk through the architecture verbally. Maybe you want the business problem before seeing a single screen.
It's the same skill security leaders need when communicating with a board. Know your audience, understand how they consume information, and speak their language.
The technology may be identical, but the way you communicate its value shouldn't be.
Is AI Security Really a Data Protection Conversation?
When we asked Evgeniy which cybersecurity trend was receiving too much hype, his answer probably won't surprise anyone who walked around Black Hat this year: AI security and security for AI.
The more interesting part was what he believes isn't receiving enough attention.
Data protection.
Dig beneath many of today's AI-security products and the problem frequently comes back to data. If you're monitoring what employees send into an LLM, you're concerned about data leaving the organization. If you're securing an internal model, you're concerned about protecting the information it can access. If you're controlling interactions with a chatbot, once again you're thinking about data.
The terminology may have changed, but many of the fundamental security questions haven't.
Evgeniy compared it to someone breaking into your house. A broken door matters, but what you really want to know is whether they stole anything. In a cybersecurity incident, that question becomes: what data was actually exposed or taken?
That distinction matters because organizations can spend enormous amounts of time protecting infrastructure without having a sufficiently clear understanding of the information that matters most.
What Are Your Crown Jewels?
That led naturally to another rapid-fire question: if Evgeniy could solve one security problem for every organization tomorrow, what would it be?
His answer was understanding what we're actually protecting.
Security teams routinely talk about crown jewels, but identifying them is harder than the phrase makes it sound. Organizations have duplicated data, forgotten systems, competing versions of information, and different business units with very different opinions about what's critical.
Evgeniy offered a simple way of reframing the conversation.
If you lose your laptop today, do you care?
Probably less than you would have twenty years ago. The drive is encrypted. Important information may live in cloud services rather than locally. The physical device has value, but losing it doesn't necessarily mean losing the information.
Now apply that thinking to the organization.
What happens if a critical database disappears? What happens if doctors can't access patient information? What happens if a manufacturing system stops? How much money does the organization lose for every hour that resource isn't available?
That makes the crown-jewel conversation tangible.
Rather than asking business leaders to identify their most critical information using cybersecurity terminology, ask them what happens when something isn't available. Ask how much money the organization loses. Ask which processes stop functioning.
Suddenly, security isn't about protecting an abstract database. It's about protecting the ability of the business to operate.
Security Teams Are Still Firefighting
If identifying crown jewels is so important, why haven't more organizations done it effectively?
Evgeniy's answer comes back to something security teams know extremely well: firefighting.
There is always another deployment that isn't finished, another technology that needs tuning, another compliance requirement, another audit, another integration, another incident, or another project demanding attention.
The result is an industry that often spends more time reacting than preparing.
Evgeniy compared it to maintaining a car. Preventive maintenance isn't particularly exciting, but it reduces the chances of being stranded later. Cybersecurity needs the same discipline: tuning controls, maintaining EDR and firewall deployments, ensuring logs are actually reaching the SIEM, and validating compliance before someone arrives asking for evidence.
The problem is capacity. Very few cybersecurity executives are likely to say they have all the people and resources they need.
That makes prioritization — and knowing what you're protecting — even more important.
AI Has Gone From Excitement to Exhaustion
AI inevitably returned to the conversation because, at Black Hat, it's almost impossible for it not to.
Evgeniy has seen a noticeable shift. Last year and at the beginning of this year, organizations were excited about AI. Now, that excitement is increasingly accompanied by fatigue.
Boards want AI strategies. Employees are already using AI tools whether the organization officially supports them or not. Security teams need to understand what models are being used, what information is being sent to them, how much they're costing, and what happens if increasingly important AI services suddenly become unavailable.
At the same time, the technology itself keeps changing.
A new model arrives and everyone is told to use it. A few weeks later, attention moves somewhere else. Organizations are being pushed to stay on trend before they've necessarily worked out what business problem they're trying to solve.
That can create a dangerous inversion of the normal technology decision.
Instead of identifying a problem and selecting the right technology, companies decide they need AI and then search for somewhere to put it.
Fear of competitors moving faster only increases that pressure.
AI Isn't Magic — and Neither Was Cloud
There's also a financial assumption developing around AI: that organizations can replace expensive human work with inexpensive AI.
Evgeniy isn't convinced the calculation is that simple.
Today's AI economics are still developing, and organizations need to understand not only what models can technically accomplish but what using them effectively will actually cost.
More importantly, having access to a powerful model doesn't mean an organization knows how to use it well.
Evgeniy compared it to handing someone a Formula One car. The capability of the vehicle is irrelevant if the driver doesn't know how to extract that capability.
We've seen a similar pattern before.
When cloud adoption accelerated, organizations moved workloads designed for traditional data centers directly into cloud environments and were surprised by the bill. In many cases, the problem wasn't cloud itself. The applications hadn't been architected for the environment in which they were now operating.
AI risks repeating the same mistake.
The question shouldn't simply be whether an organization has access to the latest model. It should be what the organization can actually accomplish with it, how reliably it can accomplish it, and whether the economics make sense.
Your First Cybersecurity Conference Probably Shouldn't Be Black Hat
Perhaps the most unexpected answer of the episode came when we asked Evgeniy what advice he'd give someone attending Black Hat at the beginning of their cybersecurity career.
He wouldn't tell them how to prepare.
He'd tell them not to go.
For someone brand-new to cybersecurity, Black Hat can be overwhelming. There are hundreds of vendors, countless technologies, enormous amounts of information, and an industry that contains dozens of possible career paths. Someone still trying to understand where they fit can easily leave with more questions than answers.
Evgeniy would instead recommend starting smaller: online training, local BSides events, and environments where newcomers can spend time meeting people and learning about different areas of the industry.
Then, when you do attend Black Hat or RSA, arrive with an agenda.
Know which sessions you want to attend. Know who you want to meet. Know which technologies you want to investigate. Otherwise, the scale of the event can take over and turn several days of opportunity into several days of wandering.
It's advice that applies equally well to experienced practitioners.
Black Hat rewards preparation.
Learning Cybersecurity Through the People Who Wrote the Books
The conversation finished by moving from conferences to another of Evgeniy's projects: helping cybersecurity professionals learn from the industry's authors.
Books can play different roles at different points in a cybersecurity career. Someone entering the field wants to understand where to start. Someone with ten years of experience may be trying to work out where to go next. Someone considering becoming a CISO may need to understand what the role actually entails before deciding it's the destination they want.
Then there are the people considering writing a book themselves.
Evgeniy's virtual conference concept brings authors and experienced practitioners together to address those different questions: what newcomers should read, how established professionals can navigate the next stage of their careers, and what prospective authors should know before writing their first book.
It's another version of the same theme that ran throughout our Black Hat conversation.
Cybersecurity has no shortage of information.
The challenge is working out which information actually matters.
Cutting Through the Noise
What was supposed to be a quick-fire episode ultimately became a conversation about clarity.
At Black Hat, that means looking beyond an impressive booth and asking a vendor to explain the problem they're actually solving. In AI, it means separating genuine business value from pressure to adopt technology simply because everyone else is doing it. In data security, it means knowing which information and systems actually matter to the organization. And in career development, it means choosing the learning environment that matches where you are rather than simply attending the biggest event available.
The cybersecurity industry isn't going to become quieter.
There will be more vendors, more technologies, more AI models, more terminology, and more claims about the next thing organizations absolutely have to deploy.
The skill that may matter most isn't keeping up with all of it.
It's knowing which questions to ask so you can work out what deserves your attention.
