Through the Looking Glass and what Alice and Bob Found there
This talk follows the trope of Bob and Alice placed into Lewis Carol's universe to highlight that the current system for cybersecurity is not working and to frame a better solution. Bob is an analyst with a traditional cyber education navigating big name tools and their disparate UIs. Alice is an analyst that has only received OJT and operates from a single looking glass. We will navigate the same threat landscape from both perspectives and highlight the differences to uncover a new framework.
In Through the Looking Glass, Alice steps into a mirrored world where the rules are different but internally consistent. In cybersecurity, we have built our own mirrored world. One made of dashboards, bolt-on tools, and expensive systems that promise clarity but often fragment the story.
This session follows two analysts navigating the same real world intrusion.
Bob is formally educated, well certified, and equipped with industry leading commercial tools. He operates across multiple dashboards: SIEM, EDR, identity, email, network telemetry. Each tool is powerful. Each has its own pane of glass, query language, and data model.
Alice received rigorous on-the-job training from seasoned operators. She knows the OSI model at a protocol deep level, how systems actually communicate, how they break, and how they are abused. She works from a unified open-source “looking glass” that aggregates all telemetry into a single investigative plane.
Through parallel storytelling and live walkthroughs of sanitized real-world cases, we will compare how each analyst approaches detection, pivoting, correlation, response, and why one consistently sees farther down the board.
We will explore:
• The operational cost of fragmented tooling and cognitive context switching
• How threat actors exploit telemetry gaps and alert fatigue
• The mismatch between traditional cybersecurity education and operational reality
• The power of protocol level literacy as a force multiplier
• The viability of open-source architectures for organizations of any size
At key decision points in the investigation, attendees will be invited to choose pivots: What would you query next? What signals matter? What layer would you examine? Audience polling and guided discussion will allow participants to experience the friction of Bob’s workflow and the acceleration of Alice’s unified view.
The same intrusion will unfold twice once through disparate panes of glass, and once through centralized telemetry making visible the investigative distance gained through correlation and architectural clarity.
Participants will leave with:
• A new mental model for how visibility architecture impacts defensive success
• Practical strategies for reducing analyst cognitive overload
• A framework for building investigative depth through OSI layer fluency
• Insight into how open source tooling, rigor, and high expectations can rival or exceed commercial stacks but for pennies on the dollar
• Perspective on training pathways that emphasize operational excellence and accountability for level of knowledge over checkbox credentials.
From small nonprofits to global enterprises, organizations face adversaries that operate like coordinated armies, often nation-state backed. Fragmentation will not keep up. Tool accumulation without integration will not keep up. We must develop analysts who understand how systems truly function and provide them with unified visibility and agency.
Alice does not succeed because she has fewer tools.
She succeeds because she sees the whole board and knows all the moves that can be made.
This session challenges prevailing assumptions about education, tooling, and what it truly takes to defend modern systems and offers a practical, achievable path forward, so that we all can be better.
Chrissy Conklin draws from 15 years of service in the United States Navy where she performed and led a wide range of cyber operations including defensive, offensive, and intelligence missions. As a civilian, she has worked towards gaining a wide range of experiences in the cyber realm to include, Universal Studios, programming and securing ride control systems and animatronic effects. Working with Northrop Grumman, the USAF, NASA, The City of San Antonio, and municipal hospital systems, she worked towards implementing, operationalizing, and maturing Security Operations Centers to detect, alert, and automate response to incidents. She has been the manager of the vulnerability and penetration testing team of a major national bank and a professor of Information Technology and Cybersecurity at Hallmark University. She is currently the Chief Mad Scientist at LegendhasIT leading the innovation division through the evolving landscape of cyber threats to enhance security operations.