Session 2.6e Update: When the Wolf only needs One Chance: using ATT&CK and D3FEND to Disrupt the Cyber-kill-chain
Tracks
ㅤ
| Wednesday, November 18, 2026 |
| 1:30 PM - 2:30 PM |
| Sutherland Theatre |
Presentation Outline
Rapid capability development creates a difficult safety problem. New platforms, cloud services, identity systems, autonomous tools, software supply chains, AI/LLMs, organisational Copilot, and operational technologies are being adopted faster than most organisations can assess, govern, and defend them. Innovation brings speed and advantage, but it also expands the threat surface available to threat actors, on top of unknown zero-day vulnerabilities. In this environment, safety cannot rely only on compliance checklists or static controls. It needs a shared way to understand adversary behaviour, scale defensive effort to operational risk, and make clear decisions under time pressure. “She thought she was safe after a good night and a peaceful walk. But then a shadow warned her: you will have to walk through those woods again and again. You will need to be lucky every single time. But the wolf, the wolf only needs to be lucky once.”
Cybersecurity works the same way. Organisations must protect every exposed system, identity, supplier, network path, and operational dependency. A threat actor only needs one viable pathway through the cyber kill chain. This presentation explains how MITRE ATT&CK and MITRE D3FEND can support safer innovation during rapid capability development, and disrupt the cyber kill chain early. ATT&CK provides a structured language for understanding how adversaries operate: their tactics, techniques, procedures, and likely pathways through enterprise, mobile, cloud, identity, container, network, and industrial control environments. D3FEND complements this by mapping defensive techniques can be used to model, harden, detect, isolate, deceive, evict, and restore systems.
The session focuses on proportional cyber safety: matching defensive effort to operational risk, mission urgency, technological capability, and consequence of failure. A low-risk internal service does not require the same level of assurance as an operational platform, safety-related system, identity provider, supplier gateway, or industrial control environment. However, rapid deployment should not mean accepting blind risk. ATT&CK and D3FEND offer a way to ask better questions:
• What techniques are most relevant to this system?
• Which controls reduce the most likely pathways?
• What must be monitored?
• What can fail safely?
• What must be recoverable?
The presentation also considers multi-national and allied synergy, where cyber kill chains are discussed using ATT&CK. Recent joint advisories on Scattered Spider and Volt Typhoon show how CISA, ASD’s ACSC, the AFP, the FBI, the UK NCSC, Canada’s cyber centre and other partners use shared threat language to describe adversary behaviour, map techniques and coordinate defensive guidance. These cases show why ATT&CK and D3FEND can act as common reference points between technical teams, safety professionals, leaders, suppliers and partner nations, helping align proportionate safety decisions across different operating environments.
The key takeaway is simple: innovation can advance safely when organisations share a common language, apply proportionate controls, and understand how the wolf moves through the cyber kill chain.
Speaker
Mr Nico Riquelme-Ramirez
Cybersecurity Consultant
QinetiQ
ㅤ
Biography
Meet Nico, a dedicated explorer in the dynamic fields of technology, engineering, and critical thinking. With a career rooted in Defence, Nico has led projects ranging from radar deployment across Australia to navigating the complexities of Information Warfare. Now with QinetiQ, Nico is leveraging expertise in Cyber and Information Security to help clients safeguard their critical assets and people. Before pursuing a Master's in Project Management at ANU, Nico played a key role at Seeing Machines, where he helped develop advanced driver and occupant monitoring systems designed to keep roads safer. Nico’s career also spans global experience with Procter & Gamble, where his Industrial Engineering acumen ensured the safe, and efficient production of diapers… millions of them.