Speaking at DEF CON 32 β Local Village Talk
I'm excited to announce that I'll be presenting at DEF CON 32 in Las Vegas this August. The talk focuses on bringing enterprise security practices down to earth for small businesses.
Talk Details
Title: "Enterprise Security on a Ramen Budget: Practical Defense for Small Businesses"
Track: Small Business Village
When: August 2025
Where: DEF CON 32, Las Vegas
What I'll Cover
The security industry has a problem: most resources assume unlimited budgets and dedicated teams. This talk bridges the gap.
The Problem
- Enterprise security frameworks don't scale down
- Small business advice is either too basic or too expensive
- No one talks about realistic implementations
- Vendors sell products, not solutions
The Solution
Practical, prioritized security that actually works for businesses with:
- 10-100 employees
- $0-10K security budget
- One IT person (maybe)
- Real operational constraints
Key Topics
1. The 80/20 of SMB Security
- Which controls actually matter
- What to skip (for now)
- Where to invest limited resources
2. Free and Cheap Tools That Work
- Open source alternatives
- Built-in features you're not using
- When to pay vs. DIY
3. The One-Page Security Program
- Minimum viable policies
- Simple compliance approaches
- Documentation that doesn't suck
4. When to Call for Help
- DIY vs. professional services
- Vendor evaluation for small businesses
- Building security partnerships
Why This Talk?
My Observation
At every security conference, I see:
- Highly technical talks for researchers
- Enterprise-focused vendor content
- Career development for practitioners
What I don't see: practical help for the businesses that need it most.
The Gap
Small business owners who care about security:
- Can't attend $2,000 conferences
- Don't understand researcher talks
- Can't afford enterprise solutions
- Get sold snake oil by unqualified vendors
My Goal
Give defenders practical, actionable content they can implement immediately. No theory. No product pitches. Just useful security.
Presentation Outline
-
Introduction: The SMB Security Reality (5 min)
- Why small businesses matter
- The threat landscape for SMBs
- Why enterprise advice fails
-
The Priority Framework (10 min)
- What attacks actually hit SMBs
- Prioritizing by likelihood Γ impact
- The "security pyramid" for small businesses
-
Quick Wins (15 min)
- MFA implementation
- Backup strategies that work
- Email security basics
- Endpoint protection on a budget
-
Building the Program (10 min)
- Simple policies
- Training that doesn't suck
- Incident response basics
- Vendor management
-
When to Get Help (5 min)
- Signs you need professional services
- What to look for
- What to avoid
-
Q&A (15 min)
Resources
I'll be publishing all presentation materials after DEF CON:
- Slide deck (PDF)
- One-page security program template
- Tool recommendations list
- Budget planning worksheet
- Vendor evaluation checklist
Everything will be available on our website and GitHub.
Pre-Conference Workshop
If there's interest, I'm considering a pre-conference workshop for a deeper dive:
Potential Workshop: "Build Your Security Program in 4 Hours"
Hands-on session including:
- Risk assessment exercise
- Policy drafting
- Tool setup demonstrations
- Group problem-solving
Let me know if you're interested: m1k3@msquarellc.net
DEF CON Is for Everyone
If You've Never Been
DEF CON isn't just for hackers in hoodies. It's for anyone interested in security:
- Business owners (yes, really)
- IT professionals
- Developers
- Students
- Anyone curious about security
The conference has villages focused on specific topics, many of which are approachable for beginners.
Small Business Village
The Small Business Village specifically focuses on:
- Security for small businesses
- Practical, affordable solutions
- Community support
- Accessible presentations
If you're a small business owner or work with SMBs, this is your village.
Meet Up at DEF CON
If you're attending DEF CON 32:
- Come to the talk
- Find me at the Small Business Village
- Say hello
- Ask questions
I'm always happy to chat about security challenges, offer quick advice, or just talk shop.
Can't Make DEF CON?
If you can't attend but want the content:
- Watch online β DEF CON often publishes talks afterward
- Get the materials β I'll post everything publicly
- Schedule a call β Happy to discuss your specific situation
- Follow along β I'll blog about the presentation
Looking Forward
This is my first DEF CON talk, and I'm genuinely excited. The security community has given me so muchβfrom free resources to career opportunities to lifelong friends.
This talk is my attempt to give back, specifically to the businesses that need help the most.
See you in Vegas!
Questions about the talk or DEF CON? Contact me: m1k3@msquarellc.net