

The Science of Silence: Beyond the Detection Trap
Abstract: For decades, the cybersecurity industry has been caught in a "more is better" cycle—more tools, more alerts, and more complexity. Yet, despite mounting budgets, the "Very Sophisticated Wind Fallacy" persists: we often mistake simple architectural failures for unstoppable adversary genius. It’s time to stop trying to hear the signal through the noise and start silencing the noise at the source.
In this session, Christopher Frenz introduces a shift from additive to Subtractive Security. Drawing from a 25-year career as a CISO and scientific researcher, he will present the first mathematical framework for complexity reduction. We will move past the "Illusion of the Magician" to focus on Path Erasure Rate (PER)—a metric that measures what an attacker cannot do rather than what we hope to detect.
Key Takeaways:
The Hero vs. Silent CISO: Why our current auditing structures reward reactive firefighting over quiet, resilient environments.
Architectural Erasure: How to use IOAs, aggressive egress filtering, and web blocks to fundamentally shrink your attack surface.
The Math of Less: An introduction to the mathematical framework behind The Science of Silence and how to apply it to your AppSec program today.