HP SVP suggests learning from cyber criminals and their methods
Summary: HP's senior vice president of enterprise security software suggests that we could learn a thing or two from cyber criminals — and possibly persuade them to look elsewhere for targets at the same time.
Context & Ripple Effects
The argument HP's senior vice president of enterprise security software is making — that defenders should study how criminals operate and use that knowledge to push them toward easier targets — lands six years after [[a:1177695|Symantec documented the shift toward data theft and targeted attacks driven by financial gain]], which established that attackers run organized, profit-seeking operations rather than opportunistic vandalism.
For HP specifically, the message comes at a moment when the company is repositioning around software and services: it booked an $8.8 billion charge with its Q4 results in November 2012 alongside declining sales, closed a German site with confirmed layoffs in February 2013, and completed the webOS sale to LG days before this piece ran. A high-profile security-strategy statement from an SVP is part of that pivot toward higher-margin enterprise franchises.
First-order effects
- HP's enterprise security software group gains a marketing platform built on adversary-informed defense, giving its sales teams a doctrine — study the criminal's methods, raise the attacker's cost, redirect them elsewhere — to pitch against point-product rivals.
- Enterprise customers evaluating security spend get a new framing from a major vendor: budget for understanding attacker behavior, not just blocking known threats.
Second-order effects
- Rival security vendors such as Symantec, whose own reporting has long catalogued attacker economics, are pressured to match the framing or cede the 'we think like criminals' positioning to HP.
- If deterrence-by-hardening becomes the pitch, demand shifts toward services like penetration testing and threat modeling inside enterprises, changing the mix of what security budgets buy.
Third-order effects
- The pattern points toward defender tooling that systematically repurposes attacker techniques — offense-derived methods becoming standard components of commercial defense products rather than ad-hoc research.
- It also anticipates treating cybercriminal groups as analyzable organizations with incentives and cost structures, a lens that makes deterrence strategy — shifting targets rather than only stopping attacks — a legitimate enterprise security goal.
The trend: Enterprise security is moving from pure perimeter blocking toward studying and exploiting attackers' own methods and incentives, with major vendors turning that doctrine into product strategy.