The value of showing up
In an era of webinars, virtual demos and AI-generated content, Black Hat MEA shows why the cybersecurity industry still invests in getting people together.
Read More
Build cyber resilience with the global Black Hat MEA community – in your inbox every week.
Why knowing isn’t the same as doing.
And to talk about this, we first want to take a moment to remind you of The Matrix (yes, the movie). Because one of the central ideas in The Matrix is that there’s a difference between understanding something intellectually and putting it into practice.
Knowing the path is one thing. Walking it is another.
We think cybersecurity is at a similar crossroads. As an industry, we know what good looks like. We know that context matters more than volume, that automation should free analysts to focus on higher-value work, and that transparency helps everyone become more resilient. And yet recent research suggests we're still struggling to turn those principles into everyday practice.
Take the security operations centre. New research from Filigran found that analysts spend around 42% of their working week investigating risks that later prove to be low priority or not exploitable. At the same time, 84% of organisations say attacks exploit vulnerabilities they already knew about but hadn't prioritised.
Visibility has improved dramatically – but turning visibility into action is a harder challenge.
As Gary Hayslip (CISO at Halcyon) put it when we spoke to him at Black Hat MEA 2025:
"Security is playing catch up to what the cyber criminals are doing."
His point wasn't just about technology. Attackers adapt quickly, while defenders often spend valuable time navigating fragmented tools and deciding what really deserves attention. It's why automation and prioritisation are becoming just as important as detection itself.

The same gap between knowing and doing appears in another area of cybersecurity: transparency.
Bitdefender's latest cybersecurity assessment found that 55.2% of IT and cybersecurity professionals reported being told to keep a breach confidential. Despite stronger disclosure requirements in many jurisdictions, the culture around incident reporting appears to be changing more slowly than the regulations themselves.
This is important because cybersecurity has always been a collective discipline. Every organisation that shares how an incident unfolded helps others strengthen their own defences.
As Yassir Abousselham (CISO at Calendly) observed, Black Hat MEA gives security professionals the opportunity to:
"Share their own experiences, their own perspectives on security."
Those conversations are one of the industry's greatest strengths. They allow practitioners to compare approaches, learn from mistakes and understand how others are tackling similar challenges. As well as building trust, transparency accelerates learning across the entire cybersecurity community.
The Matrix reminds us that understanding the truth is only the beginning. Real progress comes from acting on it.
Cybersecurity already knows the path. We know analysts need better prioritisation rather than more alerts. We know openness helps organisations learn faster than silence ever will. We know that sharing knowledge strengthens the entire community.
Walking that path means continuing to learn, challenge assumptions and exchange ideas with peers. As Abousselham said when asked why security professionals should attend Black Hat MEA:
"This is the place to be if you want to stay up to date on your knowledge."
In an industry that changes by the day, there might be no better advice than this. Better cybersecurity comes from constantly learning and sharing – and putting those lessons into practice.
Read more on the blog:
Join the newsletter to receive the latest updates in your inbox.
In an era of webinars, virtual demos and AI-generated content, Black Hat MEA shows why the cybersecurity industry still invests in getting people together.
Read More
What do a global cruise operator and a private equity firm have in common? Two US CISOs explain why cybersecurity fundamentals transcend industry.
Read More
Cybersecurity professionals say the job is getting harder. Rising complexity, relentless workloads and growing pressure are creating a talent retention challenge the industry needs to solve.
Read More