Cyberwarfare / Nation-State Attacks
,
Events
,
Fraud Management & Cybercrime
CISO Joe Carson on How NATO’s Locked Shields Sharpens Defenders for the Next Attack
Each year, the tiny northern Atlantic Ocean island country of Berylia comes under a massive cyberattack. Hundreds of volunteers on 18 different teams must repel more than 8,000 cybrerattacks against Berylia’s critical infrastructure and government services.
See Also: Why Cloud Security Needs an AI-Powered Firewall
Berylia is a fictional place, but it’s center stage for one of the world’s largest red team-blue team exercises. Sponsored annually since 2010 by the NATO Cooperative Cyber Defence Centre of Excellence, Locked Shields has attracted thousands of volunteer cybersecurity professionals to test their mettle, including Joe Carson, chief security evangelist and advisory CISO at Segura.
“Your systems are coming down, they’re crashing, credentials are getting stolen, services are coming offline, websites are being defaced, and that means we all have to work together to keep those systems defended,” Carson said. “It’s something that we all have to prepare for, and it’s something we have to realize today: no country alone can do this by themselves.”
Locked Shields helps participants learn new defenses under pressure, collaborate with others, build relationships and establish vital communications – before the next attack happens. “Ultimately, we want to help these countries become resilient against cyberattacks – and make the world a safer place,” he said.
In this video interview with Information Security Media Group at RSAC Conference 2025, Carson also discussed:
- The evolution of NATO’s Locked Shields exercise;
- How phishing and social engineering attacks have changed with the growth of generative artificial intelligence tools;
- How cybercriminals are using AI tools to lower their costs.
Carson, who has more than 25 years of experience in enterprise security, is an ethical hacker and author of “Privileged Account Management for Dummies” and “Cybersecurity for Dummies.” Carson is a cybersecurity advisor who has served several governments as well as critical infrastructure, financial and transportation companies, and he has presented at conferences globally.