DEF CON 33 - TotalTest Simulations 2 Oh!   From Exploits to Economics - Nebu Varghese

DEF CON 33 - TotalTest Simulations 2 Oh! From Exploits to Economics - Nebu Varghese

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 25:34

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video presents a "total test" approach to security testing that moves beyond annual pentests to create continuous, measurable improvements in cybersecurity posture 0:00-0:07. The speaker argues traditional testing provides only a snapshot, while organizations need continuous monitoring to truly measure security effectiveness 1:56-2:10.

Key Takeaways:
• Annual pentests and red teams are insufficient in today's evolving threat landscape where attackers can easily port attacks across organizations 2:04-2:31
• Total test simulations involve collaboration between multiple teams (CTI, red team, risk/compliance, vulnerability management) to build realistic attack scenarios 7:42-8:02
• Organizations should measure success with specific metrics like "mean time to initial access" and "mean time to objectives" rather than just counting vulnerabilities 13:50-14:32
• "Loss Per Incident" (LPI) calculations can quantify the financial value of security improvements and demonstrate ROI to leadership 15:38-16:56
• Benchmarking against industry standards helps demonstrate security effectiveness to boards and can impact cyber insurance premiums 20:29-22:01

The total test approach transforms cybersecurity from a cost center to a strategic advantage by providing quantifiable metrics that demonstrate the financial value of security investments 18:32-18:49.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Thank you so much everyone for joining. Hello Defcon. We're here to talk about total test simulations. What that means is we're going to talk about this in terms of in the next 30 minutes. We're not going to talk about finding a new vulnerability or finding a new CV, but we're going to talk about how organizations can use that knowledge of finding stuff and finding issues and being able to measure real value and change the cost conversation from this being a cost center to a strategic advantage. So, uh, let's get straight into it. Um, I've got some fancy animation on the go, so you'll have to tolerate, uh, that a bit, but a little bit about me. uh Nebuis. I'm a senior director at FDI Consulting, cyber security practice. I'm based in London. Um I've been in the space in the offensive securi…