Article

You will be breached. What matters is what happens next.

Published on
September 8th, 2026
NIC 2026 SPEAKER SERIES "5 questions with"
Ahead of NIC 2026, we're sitting down with some of the practitioners leading sessions this October, the same five questions, put to people who spend their working lives in the trenches rather than on a stage. First up: Hasain Alshakarti, Principal Cybersecurity Advisor at Truesec, and co-lead of this year's Breaking the Kill Chain masterclass.

What do you believe that most of your peers would disagree with?

Most of the industry still treats prevention, stopping every attack with better tooling, as the goal. I don't. Breaches are inevitable. The real measure of security is how well an organization withstands an attack, recovers, and keeps operating. Resilience and recovery matter more than preventing every possible compromise.

What do teams still accept as normal, even though it creates unnecessary risk?

Keeping legacy systems alive well past their intended lifespan. Organizations hang onto outdated systems because someone might still need old data, or because a migration never quite finished. It feels like a practical compromise, but it expands your attack surface, raises maintenance costs, and leaves you running systems nobody's patching anymore. Modernization, archiving, and decommissioning aren't optional extras, they're part of a resilient security strategy.

When did something last go wrong that genuinely surprised you, and what changed afterwards?

A developer trying to locate a single Arduino device on the network used an AI-recommended scanning tool, and it triggered network-wide activity across multiple regions before anyone realized what was happening. It became a real security incident, and a clear reminder that AI can push an action well beyond its intended scope the moment appropriate controls aren't in place. Afterwards, the organization added stronger guardrails: better network segmentation, more monitoring, and real governance over how diagnostic and security tools get used.

What is one thing someone can change on Monday morning without waiting for a project, budget, or permission?

Turn on logging. It doesn't need a dedicated project, special permissions, or real budget, start by storing logs locally and making sure they're part of your routine backups. Even that basic step gives you real visibility and preserves evidence you'll be glad to have during an investigation, a recovery effort, or just making a fast decision mid-incident.

What will people experience at NIC that they cannot get from a blog post or webinar?

A direct line to people solving these problems for a living, not a summary of them. You get practical insight and firsthand experience through an actual conversation, in person, with someone who's been in the room when it went wrong. No algorithms, no auto-generated answers, just expert perspectives, real conversations, and a hundred percent AI-free learning.

Hasain is co-leading Breaking the Kill Chain: A Gamified Cyber Incident Recovery Masterclass at NIC 2026 on October 13, a full day inside a simulated enterprise breach, built with Truesec colleagues Mikael Nyström and Viktor Hedberg. He's also back on the main stage twice: Gone in 180 Minutes: From Social Engineering to Domain Dominance with Viktor Hedberg on Wednesday at 11:20am (Room 6), and Tales from Incident Response: "It's Probably Nothing" (Until It Is) with Mikael Nyström on Thursday at 11:10am (Room 1).

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.