Cybersecurity
Security outside the web bubble: OT and critical infrastructure, agents that manipulate their overseers, and behaviour as the new credential.
In Bergamo, at NoHat, I understood that people doing web security cover maybe twenty percent of real cybersecurity: in OT systems and critical infrastructure the threats and the consequences change. Since then I write about security as a problem of responsibility, not of tools: the producer who answers for a defect, the agent that during a test tries to talk the human into pressing the button, behaviour that becomes a credential. The button is still yours, but you no longer fully control the environment in which you decide.