CypherCon 2026
Choosing Where to Hit: How Defenders Can Shape Adversary Behavior
Greg Conti & Tom Cross
Abstract:
Enterprise security teams measure success by internal metrics: tickets closed, vulnerabilities patched, mean time to respond. Adversaries do not care. If their operations remain profitable, deniable, and low risk, attacks continue no matter how well companies score themselves.
This talk starts with a simple claim: defenders lose because attackers run campaigns and defenders run tickets. Targeting, campaign design, and effects-based operations are how you flip that equation. By applying these time-tested military principles, defenders can impose pressure through shorter-term operations that shape attacker behavior, or through sustained campaigns that impose real consequences over time.
That pressure does not stop at networks. Defenders can operate across multiple domains, using the full range of their legal authorities, operational capabilities, and risk tolerance. They can act alone or with partners to apply pressure through infrastructure, money flows, platforms, identities, supply chains, courts, regulators, media cycles, and narratives. This is not a hack back debate. It is a mindset shift from passive target to an opponent that pushes back, openly or quietly.
In this talk, we break down targeting, campaign design, and effects-based operations, the same disciplines sophisticated threat actors already use. These methodologies let you impose real effects on adversaries and reverse engineer the campaigns being run against you. We show how to connect desired effects, available capabilities, business risk, and threat intelligence into deliberate operations and campaigns that shape attacker behavior, instead of letting attackers shape yours.

Greg Conti

Tom Cross
Flip that equation!
Greg Conti is a hacker, maker, and computer scientist. He is a long-time Defcon and Black Hat speaker and trainer. Currently he is a Principal at Kopidion, a cybersecurity training and strategy consultancy. Formerly, he served as Director of Security Research and Senior Security Strategist in the infosec industry, and on the West Point faculty for 16 years, where he led their cybersecurity research and education programs. During his U.S. Army and Military Intelligence career he co-created U.S. Cyber Command’s Joint Advanced Cyberwarfare Course, deployed to Iraq as Officer-in-Charge of U.S. Cyber Command’s Expeditionary Cyber Support Element, and was the first Director of the Army Cyber Institute. Greg holds a B.S. from West Point, an M.S. from Johns Hopkins University, and a Ph.D. from the Georgia Institute of Technology, all in computer science. His work may be found at gregconti.com and kopidion.com.
Tom Cross is the Head of Threat Research at GetReal Security, where he tracks threat actors and attack activity involving deepfake social engineering and impersonation. He is also a Principal at Kopidion, a cybersecurity training and strategy consultancy. His career in cybersecurity has spanned three decades, and numerous roles, including CoFounder and CTO of Drawbridge Networks, Director of Security Research at Lancope, and Manager of the IBM Internet Security Systems X-Force Advanced Research team. He has spoken at numerous security conferences, including Black Hat Briefings, Defcon, CyCon, HOPE, Source Boston, FIRST, and Security B-Sides. He has a B.S. in Computer Engineering from the Georgia Institute of Technology.