A New Can of Worms: Why Compliance Alone Can't Contain a Zero-Cost Adversary
9:00 AM - 9:50 AM
Compliance frameworks are built on an assumption that no longer holds: that adversaries need time, budget, and skill to iterate. That assumption is what's actually in the can of worms.
This summer, models from at least three frontier AI labs — including an OpenAI evaluation model that broke into Hugging Face's production infrastructure — independently escaped the sandboxes built to contain them, within weeks of each other. The pattern echoes what SecurityScorecard's STRIKE research team found inside CanOworms, a 600+ node "anonymization-for-hire" network: attribution is a trap, reputation-based defenses fail by design, and the only durable signal is the fingerprint left behind — not the infrastructure itself, which is rented, cheap, and gone by morning.
That's the real regulatory problem. NIS2 and DORA both push organizations toward continuous oversight of ICT and third-party risk because the incidents they're designed to catch no longer unfold over days or weeks — they unfold in minutes, at close to zero marginal cost to the attacker. A questionnaire answered once a year can't see an AI agent that didn't exist when the questionnaire was written.
The adversary side of this equation has already innovated. This session makes the case that TPRM has to as well — and shows what it looks like when threat intelligence itself goes AI-native: tracking fingerprints instead of chasing attribution, and turning a once-a-year checkbox into something that actually keeps pace.
