Security professionals spend their careers teaching others how to prevent incidents—but expertise doesn’t make anyone immune to distraction, human error, or a well-timed attack.
In this candid keynote, John O’Neill Sr. shares what happened when the security professional became the victim. While teaching at a security conference, John discovered that his primary Microsoft 365 account had been compromised. What followed was an investigation involving malicious mailbox rules, unauthorized messages, unfamiliar devices, suspicious sign-ins, and evidence of device-code authentication abuse.
John takes the audience inside the incident, sharing what worked, what didn’t, and what it’s like to manage a breach when your own data, customers, and professional reputation are at stake.
More importantly, his experience exposes a critical security lesson: we cannot build defenses that depend on people—even experts—getting everything right. Through lessons learned the hard way, John explores how stronger identity controls, better preparation, and resilient security practices can limit the damage when human judgment inevitably fails.
Attendees will leave challenged to rethink how they prepare for compromise—before they become both the incident responder and the victim.