Hack.lu 2026

Jacob Torrey

Jacob is the Head of Labs at Thinkst Applied Research. Prior to that he managed the HW/FW/VMM security team at AWS, and was a Program Manager at DARPA's Information Innovation Office (I2O). At DARPA he managed a cyber security R&D portfolio including the Configuration Security, Transparent Computing, and Cyber Fault-tolerant Attack Recovery programs. Jacob has been a speaker and keynote at conferences around the world, from BlackHat, to SysCan, to TROOPERS and many more.


Session

10-21
17:00
30min
Bolting on security is the best we can [generally] do, so grab a wrench
Jacob Torrey

We all know the adage that security should be built-in, not bolted on. This would work great if our threat models perfectly reflected reality, and adversaries never adapted. Sadly, the real-world doesn't fit into a neat specification and design document, and adversaries alter their tactics. When looking at cyber-security as a dynamic game, defenders must adapt to survive--bolting on security is the only way to circumvent new attacks or stymie adversaries.

Regardless of how much faith you put into the fear-mongering AI hype machine, we've all seen the world we work in shift, and designing for easier updates, changes, and enhancement without impacting UX is the way forward. My entire career has been spent adding in security after-the-fact, so join me as I:

  • Explore the reasons security is hard and cannot be solved
  • Highlight wins where security has been added after the fact
  • Look at how designing for future security augmentation helps our future selves bolt-on security more quickly
  • A few areas where security can be designed in, and how lumping those areas with general cyber-security harms their outcomes
topic: hack.lu
Europe