Policy Preview
Policy @ DEF CON 33 · Day 1 · Policy @ DEF CON
Overview
The provided video serves as a compelling promotional piece for the Policy @ DEF CON track, rather than a standalone technical talk. Featuring Heather West, the video extends an open invitation to hackers, policy professionals, researchers, students, and the broader community to engage in critical discussions at the intersection of cybersecurity and policy. The track is positioned as a vital forum for exploring some of the most pressing issues of our time, ranging from the intricacies of critical infrastructure protection to the ethical dilemmas of biohacking and the evolving landscape of artificial intelligence security.

Key moments
- 0:00 Introduction to Policy @ Defcon and its purpose
- 0:10 Diverse audience: hackers, policy, researchers, students
- 0:20 Workshops, panels, and live tabletop exercise
- 0:37 Key topics: AI, ransomware, critical infrastructure, biohacking
- 0:58 Invitation to join Policy @ Defcon in Las Vegas
- 1:05 Humorous closing: What happens in Vegas gets logged
Policy @ DEF CON: Bridging the Gap Between Hacking and Policy
Speakers: Heather West (representing Policy @ DEF CON)
Conference: Policy @ DEF CON
YouTube: https://www.youtube.com/watch?v=eBkduAj_Ruc
Overview
The provided video serves as a compelling promotional piece for the Policy @ DEF CON track, rather than a standalone technical talk. Featuring Heather West, the video extends an open invitation to hackers, policy professionals, researchers, students, and the broader community to engage in critical discussions at the intersection of cybersecurity and policy. The track is positioned as a vital forum for exploring some of the most pressing issues of our time, ranging from the intricacies of critical infrastructure protection to the ethical dilemmas of biohacking and the evolving landscape of artificial intelligence security.
This particular video, while brief, highlights the multifaceted nature of the Policy @ DEF CON experience, promising a diverse program including workshops, panels, and a groundbreaking live tabletop exercise. It underscores the importance of fostering dialogue in both formal and informal settings, from "dark conversations in quiet corners" to mainstage keynotes. The track's existence within the larger DEF CON ecosystem signifies a growing recognition that technical prowess alone is insufficient to address complex cyber threats; robust policy frameworks, informed by deep technical understanding, are equally indispensable. The video thus acts as a clarion call for interdisciplinary collaboration, emphasizing that the consequences of cybersecurity vulnerabilities extend far beyond technical exploits, impacting national security, economic stability, and individual rights.
Background
▶ Watch: Introduction to Policy @ Defcon and its purpose (0:00)
The necessity for a dedicated "Policy" track at a renowned hacking conference like DEF CON stems from the increasingly intertwined relationship between technology and governance. As digital systems become more pervasive in every facet of modern life, the implications of their security—or lack thereof—transcend purely technical domains, becoming matters of public policy, international law, and societal well-being. The problems discussed at Policy @ DEF CON are not merely theoretical; they are real-world challenges that demand coordinated responses from technologists, policymakers, legal experts, and industry leaders.
Historically, the cybersecurity landscape has evolved rapidly, often outpacing the legislative and regulatory mechanisms designed to govern it. This disconnect has created significant vulnerabilities and regulatory gaps. Issues such as incident reporting, ransomware response, disclosure rules for vulnerabilities, and export controls on cyber capabilities are prime examples where technical realities clash with existing or nascent policy frameworks. For instance, determining when and how organizations must report cyber incidents involves complex considerations of privacy, national security, and economic impact, requiring a delicate balance that only informed policy can achieve. Similarly, the proliferation of ransomware attacks has highlighted the urgent need for coherent national and international policies that deter attackers, aid victims, and prevent financial flows to criminal enterprises.
Furthermore, emerging technologies introduce entirely new policy challenges. The video specifically mentions artificial intelligence hacking and biohacking. AI's rapid advancement brings with it concerns about autonomous systems, algorithmic bias, and the potential for AI to be weaponized or to introduce novel vulnerabilities. Biohacking, while offering revolutionary potential in medicine and human enhancement, also raises profound ethical questions about data privacy, human augmentation, and the potential for misuse. Policy @ DEF CON aims to provide a platform where these complex, often ambiguous, issues can be debated and understood from multiple perspectives, drawing on the expertise of the hacking community to inform more effective and forward-looking policy solutions. The initiative acknowledges that effective cybersecurity policy cannot be crafted in a vacuum; it requires direct engagement with those who understand the technology at its deepest level.
Key Findings
▶ Watch: Workshops, panels, and live tabletop exercise (0:20)
As this video serves as a promotional announcement for the Policy @ DEF CON track rather than a presentation of specific research or a single talk, there are no "key findings" in the traditional sense of a technical paper or conference presentation. The video's purpose is to outline the scope of discussions and the types of insights attendees can expect to encounter at the event.
However, the implicit "finding" of the Policy @ DEF CON track itself is the critical and growing need for a dedicated, interdisciplinary forum where the technical realities of cybersecurity intersect with the complexities of policy. The very existence of the track underscores the "finding" that isolated technical expertise or policy development is insufficient to address modern cyber challenges. Instead, effective solutions emerge from collaborative efforts that bridge these traditional divides.
Attendees of the Policy @ DEF CON track would, however, be exposed to key findings across a multitude of critical areas. For instance, discussions on critical infrastructure might reveal findings on the efficacy of current resilience standards or the prevalence of specific attack vectors targeting essential services. Talks on ransomware could present data on attack trends, the economic impact on victims, or the effectiveness of various payment deterrence policies. Similarly, sessions on AI hacking would likely feature findings on novel adversarial machine learning techniques or the vulnerabilities inherent in specific AI models. While this promotional video does not present these findings, it acts as a gateway to a conference track where such crucial discoveries are regularly shared and debated, shaping the future of cybersecurity policy.
Technical Deep Dive
▶ Watch: Key topics: AI, ransomware, critical infrastructure, biohacking (0:37)
The promotional video, by its nature, does not offer a technical deep dive into any specific cyber security exploit, protocol vulnerability, or architectural design. Its focus is on the broader policy implications of technology, outlining the thematic areas that will be explored at the Policy @ DEF CON track. Consequently, there are no specific tool names, CVE numbers, version numbers, or detailed technical percentages to discuss from this particular input.
However, the topics highlighted in the video inherently possess deep technical underpinnings that would be explored in detail within the various workshops and panels at the conference. For example, discussions on critical infrastructure policy often necessitate an understanding of SCADA/ICS systems, operational technology (OT) security, and the specific vulnerabilities that could lead to cascading failures in sectors like energy, water, or transportation. Policy debates around incident reporting are heavily influenced by the technical challenges of detecting, analyzing, and attributing cyber incidents, including forensic methodologies and threat intelligence sharing protocols.
Furthermore, the mention of artificial intelligence hacking us all points to highly technical areas such as adversarial machine learning, data poisoning attacks, model inversion attacks, and the security implications of large language models. Policy discussions here would be informed by the technical feasibility and impact of such attacks. Similarly, biohacking involves highly specialized technical knowledge in fields like bioinformatics, genetic engineering (e.g., CRISPR technology), and the security of biological data, all of which present unique policy and ethical challenges. While this specific video does not delve into these technical minutiae, it serves as an excellent indicator of the profound technical depth that underpins the policy conversations at the Policy @ DEF CON event. The track is designed to ensure that policy discussions are grounded in a realistic understanding of technological capabilities and limitations.
Demo / Proof of Concept
▶ Watch: Invitation to join Policy @ Defcon in Las Vegas (0:58)
The provided promotional video does not feature a traditional technical demonstration or a proof of concept for a specific exploit or security tool. Its purpose is to announce the scope and activities of the Policy @ DEF CON track.
However, the video does highlight a unique and relevant form of practical engagement: "for the first time ever a live tabletop exercise at Policy @ DEF CON." While not a technical demo in the sense of showcasing code or an exploit, a live tabletop exercise serves as a highly effective and interactive proof of concept for policy and incident response strategies. In such an exercise, participants (often a mix of technical experts, policy makers, legal counsel, and public relations specialists) simulate responses to a hypothetical cyber crisis. This includes making real-time decisions regarding incident reporting, legal compliance, communication strategies, and coordination with various stakeholders.
Such an exercise effectively demonstrates:
- The practical application and effectiveness of existing or proposed policies under pressure.
- The gaps and weaknesses in current incident response plans.
- The challenges of inter-agency or inter-organizational coordination during a crisis.
- The human element in decision-making when facing complex, rapidly evolving cyber threats.
Therefore, while not a "demo" of a technical vulnerability, the live tabletop exercise is a crucial "proof of concept" for the efficacy and challenges of cybersecurity policy in action, making it a highly relevant and valuable component of the Policy @ DEF CON track for its target audience.
Defensive Implications
▶ Watch: Humorous closing: What happens in Vegas gets logged (1:05)
Given that the input is a promotional video for a conference track rather than a specific technical talk, it does not offer direct, actionable defensive implications in the form of specific mitigations, patches, or security tool recommendations. However, the themes articulated in the video—and by extension, the entire Policy @ DEF CON track—are profoundly relevant to strengthening defensive postures at an organizational, national, and even international level. The entire premise of the track is to translate technical understanding into effective defensive policy.
Defenders should view the topics discussed at Policy @ DEF CON as essential inputs for developing comprehensive and resilient security strategies. For instance, discussions on critical infrastructure are paramount for organizations operating in these sectors, urging them to consider not only technical safeguards but also robust incident response plans that account for operational continuity, regulatory compliance, and public safety. Understanding evolving disclosure rules and incident reporting requirements is crucial for legal and compliance teams, ensuring that organizations can navigate the complex landscape of post-breach obligations without incurring further legal or reputational damage.
The focus on ransomware directly informs defensive strategies by highlighting the importance of robust backup and recovery plans, effective network segmentation, employee training against phishing, and the ethical and legal considerations surrounding ransom payments. Furthermore, the emphasis on artificial intelligence hacking underscores the need for proactive security-by-design principles in AI development, including adversarial robustness testing and securing AI supply chains. For defenders, engaging with these policy discussions means understanding the broader context of threats, the regulatory environment they operate within, and the ethical considerations that shape acceptable defensive responses. It encourages a shift from purely technical "patch and pray" approaches to a more holistic, policy-driven security posture that integrates legal, ethical, and strategic considerations into the technical defense framework. The ultimate defensive implication is the call for informed, collaborative, and adaptable policy that empowers technical defenders rather than hindering them.
Key Takeaways
- Cybersecurity is a Policy Problem: The Policy @ DEF CON track underscores that technical solutions alone are insufficient; robust policy frameworks are critical for addressing complex cyber threats.
- Interdisciplinary Collaboration is Essential: Effective cybersecurity requires dialogue and collaboration between hackers, policy makers, researchers, legal experts, and students.
- Broad Scope of Critical Issues: The track covers a wide range of pressing topics, including critical infrastructure protection, incident reporting, ransomware response, disclosure rules, export controls, AI security, and biohacking.
- Diverse Engagement Formats: Policy @ DEF CON offers various avenues for participation, including workshops, panels, and innovative formats like a live tabletop exercise, fostering both formal and informal discussions.
- Informing Future Policy: The track aims to leverage the deep technical understanding of the hacking community to inform and shape more effective, forward-looking cybersecurity policies.
About the Speaker(s)
Heather West is featured in the promotional video as an integral part of the Policy @ DEF CON initiative. While the video does not provide a traditional speaker biography, her presence and direct invitation suggest a key organizational or leadership role within the Policy @ DEF CON track. She embodies the spirit of the track, which is to bring together diverse communities to discuss critical cybersecurity and policy topics. Her involvement highlights the commitment to fostering an environment where complex issues can be explored through workshops, panels, and interactive exercises, bridging the gap between technical expertise and policy development.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
This isn't a talk — it's a promotional video for a conference track, dressed up with five sections of AI-generated padding that say nothing. There is no research, no signal, no speaker content to evaluate, only a submission that should never have been queued for review.
Heather Calloway (CISO) — PASS
This is a promotional video for a conference track, not a talk. There is nothing to review — no argument, no findings, no accountability framing, no decisions enabled. Routing accordingly.