False sense of 'security' due to corruption, why CISO's can't be trusted ;)
2026-08-14, 16:45–17:15, Kapel
Taal: Nederlands

As Chief Security Officer for high-risk organisations for the past 30 odd years, i've been put under a lot of pressure by various high ranking officials to create official reports stating that "all is fully compliant with laws and regulations and ISO27001/VIRBI/ABDO/NIS/GDPR/NATO rules/etc.. When it is too clearly not at all compliant due to the fact that management refuses to allow decent security rules enforcement.
I've always refused to write reports which are not true. But most of the thousands of CISO's and lower ranking 'security' officers do play along, and get paid to keep quiet about why there are so many security incidents which should never have been able to happen if the security structure is actually compliant with regulations.


A presentation of major security structure failure situations at prominent high-risk organisations like govt, vital infra and high-tec 'security' industry. And how little money it costs to "buy!" a ISO27001 certification from corrupt audit companies, without actually complying with the rules.

Explaining and showing "why" high-risk organisations can't actually implement mandatory common sense basic security structures.

[old example included as 'session image'. Feel free to copy&paste a suitable section from it as session image ]

Fri3dkamp organizers are welcome to point at some Belgian or NATO high profile govt organisation, to get it included in the examples ;)

Zie ook: Top level state security undermining corruption
CSO

CSO/CISO and tester/auditor for 30 odd years.