How NOT to be Your Adversarys Best Friend - Doing What Matters... @FIRSTdotorg
How NOT to be Your Adversarys Best Friend - Doing What Matters...  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 3 hours ago
Brian Hein (CA), James Shank (Expel, US)

Cyber threat intelligence is often idolized for being “actionable” — but action alone doesn’t pay the bills or stop adversaries from profiting. This talk challenges the industry’s obsession with tactical “actionability” and reframes the mission around the outcomes that matter to the business and the adversary alike.

Building on the earlier “From Trust Groups to Action Communities” conversation, this session explores how defenders can evolve again — from action to impact. We’ll examine how threat intelligence can influence business decisions, alter adversary cost models, and measure success in real dollars, not dashboards.

Drawing from real-world community collaboration and collective defense case studies, we’ll also explore how informal “Fight Club” networks and open-action communities achieve 1000x force-multiplying effects — even when formal structures fail.

If you’re tired of vanity metrics, “pew-pew” dashboards, and over-engineered slides about IOCs, join us for a practical discussion on how to turn intelligence into outcomes that adversaries can’t afford to ignore.

---

Brian Hein lives and breathes collaboration and threat Intelligence. A German living in Canada's Capital Ottawa (via Laguna Beach, California) who has spent years conducting advanced threat research at HP's Office of the CTO and HP Security Research as well as at Flashpoint Intelligence. Brian also explored cyber threat intelligence at DTAG, one of the world’s largest carriers. After a year supporting Canadian initiatives, he joined and left Silobreaker, who supported Brian’s mission for over a decade. Brian has co-authored several books and helped develop a couple of patents. He is also active in the Wold Economic Forum’s Cybercrime Atlas initiative where he serves as a Case Lead.

James Shank joined Expel as Director of Threat Operations in 2025. Prior to Expel, James held various roles at threat intelligence companies SpyCloud and Team Cymru. James keeps the needs of the Internet information security community at the center of all his efforts. He is involved in and coordinates several community-oriented efforts to combat online threats, and notably was a part of a collaborative effort to take down Emotet. He works with community members to find innovative solutions to thorny issues that are hard to solve by individual operators.
How NOT to be Your Adversarys Best Friend - Doing What Matters...CSIRTeaming: Forging Resilient Incident Management Teams with Psychological SafetyMind the Match: Why Vulnerability Matching Is Harder Than You ThinkOpenTide: From Raw Intelligence to Structured Threat-Informed DetectionsThe Vulnerability Ecosystem’s Vendor Bias — Exposed by Open SourceRouting Security for Enterprises: Secure Your Supply ChainEmbracing the Era of Transparency: Automating VEX Application for Scalable, Context-Aware SecurityAttack or Noise?: Tracking and Evaluating the Impact of Internet-Wide Survey ScannersAI Is Writing Your Bug Reports. Can You Tell?Dark Silicon: Unmasking GPU Threats in the Age of AIAxiomatic Events that Evolved Vulnerability DatabasesOrganizational Context Matters: Security Control Effectiveness on Vulnerabilities for Prioritization
FIRST |

How NOT to be Your Adversary's Best Friend - Doing What Matters...

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER