techwiki

Bart Asnot

Bart Asnot is Head of Cybersecurity at Microsoft Belgium.

Insights & takeaways

Bart Asnot's core message is that cybersecurity today cannot be separated from geopolitics, and that most people badly underestimate how early hybrid warfare actually begins. His clearest illustration is Ukraine: the invasion was preceded by "a full year" of mis- and disinformation campaigns in the eastern regions designed to shift the population's mindset before any physical action occurred 12. For Asnot this is the paradigm, not the exception, attacks on a country's stability start in the information space long before anyone fires a shot, and defenders who wait for kinetic signals are already too late.

A second recurring theme is how generative AI has flattened the skill curve for attackers. He describes the rise of AI-empowered "script kiddies", people who once needed real coding ability now generating attacks on demand, which has scaled both the volume and impact of low-skill cybercrime 12. He frames this as an inescapable trade-off of innovation itself: "Hoe meer een innovatie kan gemaakt worden voor het goede, hoe meer dat ook kan worden misbruikt voor het slechte" 12. Crucially, he does not see AI as an autonomous threat actor in its own right, at least not yet: "Wij leiden. Technologie volgt... Ik zie dat niet echt gebeuren. Ik hoop ook dat dat niet echt gebeurt" 1. Technology, in his view, remains a force multiplier for human intent, good or bad, rather than an independent agent.

On defense, Asnot is candid about limits. He repeats, in near-identical language across appearances, that "100% bescherming bestaat nooit in de digitale wereld. In die fysieke wereld eigenlijk ook niet" 12. This isn't resignation but a call for realistic risk management: security postures go stale within days as employees adopt new devices or tools, so defenders must continuously reassess acceptable versus unacceptable risk rather than chasing an unattainable perfect state 12. He backs this with scale: Microsoft ingests roughly 78 trillion security signals daily, which are anonymized and correlated by human analysts to produce confidential "nation state notifications" warning companies before state-linked actors strike 12. He also flags a structural weakness, that companies migrating to the cloud keep applying legacy on-premise security thinking to a shared-responsibility model, creating a lag that attackers, who "don't care" about rules or audits, exploit as a head start 12.

Asnot's account of who gets targeted tracks geopolitical and economic pressure points. He notes that during COVID, cybercriminals and espionage-linked states deliberately hit hospitals precisely because their security maturity was low and they had no choice but to stay operational 12. In Belgium's case, he points to the roughly 48,000 registered members of the diplomatic community as the reason government and diplomacy are now the critical target sector, citing pro-Russian groups like NoName launching DDoS attacks the day after Belgian pro-Ukraine statements 12. This leads him to a pointed observation about attribution asymmetry: opportunistic ransomware crews often self-identify to build "street cred," while genuinely targeted, state-linked attacks hide behind routers and jurisdictions across many countries, making legal or NATO-level responses nearly impossible 12.

He is also willing to defend why so much of this fight stays invisible. Publicly attributing every incident, he argues, would breed paranoia that itself serves the adversary's real goal, destabilization, so much defensive work deliberately stays under the radar 12. This coexists with a strong belief that Belgium is actually doing well: he cites European reports placing Belgium consistently "in de top drie, soms top één" of best-secured countries in Europe 12, a claim he offers as reassurance rather than complacency.

On the human side, Asnot pushes hard against the technical mystique of the field. His advice to practitioners is to "denk als een hacker... denk hoe de andere kant werkt" 12, treating adversarial thinking as a core professional discipline. But for ordinary users he wants the opposite of technical depth: he compares good cyber hygiene to driving a car, where you don't need to understand the engine, just the basic rules, password managers, 2FA, not clicking unknown links, and argues the "hoodie hacker" framing of cybersecurity as arcane and technical actively blocks mainstream awareness 12. He sums up the asymmetry defenders face bluntly: "de cyberactoren... die zien gewoon iets nieuw, iets cool en die gaan dat proberen binnen te geraken," giving attackers a persistent small head start that defense can only ever narrow, never close 12.

  • Russia's invasion of Ukraine was preceded by a full year of mis- and disinformation campaigns in the eastern regions to shift the population's mindset, showing hybrid warfare starts long before kinetic action.
  • Generative AI has massively scaled up 'script kiddies': attacks that used to require real coding skill can now be generated on demand, raising both the volume and impact of low-skill cybercrime.
  • Microsoft ingests ~78 trillion security signals per day, anonymizes and scrubs them, and human analysts correlate patterns to issue confidential 'nation state notifications' to companies about to be hit by state-linked actors.
  • 100% security is impossible because the risk landscape changes constantly: even a fully funded security program is outdated days later when employees adopt new devices or technologies, forcing continuous risk re-assessment.
  • During COVID, cybercriminals and espionage-focused states deliberately targeted hospitals because their maturity was low and they had to stay operational — attack waves follow geopolitical and economic shifts to whichever sector is most vulnerable.
  • Belgium's diplomatic community (~48,000 registered persons) makes government and diplomacy the new critical target sector, with pro-Russian groups like NoName launching DDoS attacks the day after Belgian pro-Ukraine announcements.
  • Attribution asymmetry: opportunistic ransomware groups often self-identify to build 'street cred', while targeted attacks are by default hidden behind routers and regions across many countries, making legal recourse nearly impossible.
  • Publicly attributing every incident would breed dangerous paranoia and actually help adversaries whose goal is destabilization — hence much cyber defense activity deliberately stays under the radar.
  • Companies migrating to cloud keep applying legacy on-prem security thinking to a shared-responsibility model, structurally lagging behind attackers who immediately probe anything new.
  • Cybersecurity culture should work like driving a car: users shouldn't need to understand the engine, just simple rules (password manager, 2FA, don't click unknown links) — the 'hoodie' technical framing must stop.
  • The Russia-Ukraine war started digitally a full year before the physical invasion, with mis- and disinformation campaigns in eastern regions to shift the population's mindset before kinetic action.
  • Generative AI has massively scaled up 'script kiddies': attackers no longer need deep technical knowledge, since AI and crawling engines let low-skill actors find vulnerabilities and reach 'actions on objective' far faster.
  • Microsoft ingests ~78 trillion security-related signals per day, anonymizes and analyzes them, and issues confidential 'nation state notifications' to customers when it has near-certain evidence of state-linked malicious activity.
  • 100% security is impossible: security leaders work with acceptable/non-acceptable risk trade-offs, and any new device or technology adopted by employees changes the threat model overnight.
  • During COVID, cybercriminals and espionage-focused states deliberately targeted hospitals because their security maturity lagged and they had to stay operational — attack waves follow geopolitical and economic shifts per industry.
  • Belgium hosts ~48,000 registered members of the international diplomatic community, making government and diplomacy the current critical target sector, with pro-Russian groups like NoName057 launching DDoS attacks after Belgian support announcements for Ukraine.
  • Attribution asymmetry defines hybrid warfare responses: opportunistic ransomware groups self-identify to build 'street cred', while targeted state attacks hide behind multiple routed countries, making legal response and NATO Article 5 triggers nearly impossible.
  • Much cyber-defense activity deliberately stays invisible: publicizing every malicious attempt would create paranoia that itself helps adversaries achieve their goal of destabilizing a country's economy and stability.
  • Companies still apply old on-prem security thinking to cloud environments, creating a structural lag that attackers — who 'don't care' about regulations and audits — exploit as a head start.
  • Cybersecurity culture should work like driving: you don't need to understand the engine, only the rules (like driving 30 km/h) — the hoodie-hacker technical complexity framing must stop for awareness to reach ordinary people.

Career

Roles
Education
  • KTA KapellenMiddelbaar onderwijs, Elektronica1993 - 1997

From public career histories · 11 entries

Media & appearances

2
  1. 1podcast
    Virtual · 28 May 2025

    Microsoft Belgium's head of cybersecurity Bart Asnot discusses hybrid warfare, nation-state attacks, and Belgium's cyber defense, after hosts speculate that OpenAI's Jony Ive hardware device will be an AI necklace.

  2. 2podcast
    Virtual · 28 May 2025

    Virtual podcast #21: speculation on OpenAI's Jony Ive hardware device (Pieter bets on an AI necklace) and a deep interview with Bart Asnot, head of cybersecurity at Microsoft Belgium, on hybrid warfare, nation-state actors, AI-empowered script kiddies, and Belgium's cyber-defense posture.

Recent mentions1