PRESENTATIONS
Red Teams and Real Attacks: Misalignment due to Skewed Incentives
Red teamers are defenders' allies. Their goal is to help make defenders better by exposing security weaknesses. They enable defenders to know where the holes are so defenders can reinforce their defenses. But in practice, is that goal achieved?
When incentives are misaligned with outcome metrics, the value delivery fails. In practice, it’s hard to get this tuned to an efficient model for many reasons. The delivery of security outcomes red teams are meant to help suffer as a result. When red team reports are used to align resources to gaps, misaligned incentives result in prioritizing work of lower importance. This means organizations could mitigate more risk by paying attention to other, higher priority items.
To put these ideas to the test, we decided to take an objective look at incident data from our annual threat report to see if we could find mismatches between what the red team is reporting versus what real-world attackers are targeting.
This talk goes over what the data shows. We use measured results from our hundreds of protected companies to show where attackers show up and where red teams show up. We discuss some possible reasons and propose some things to consider, both for the red team and the leadership writing the rules of engagement.

