P

Simon Wijckmans

Simon Wijckmans is Founder & CEO at C/Side.

Overview

The main interview is with Simon Wijckmans, founder of client-side security company c/side, recently relocated to San Francisco and named to Forbes 30 under 30. He recounts how North Korean operatives applied to his job postings with fake identities, using AI-assisted CVs, reverse-engineered coding tests, green-screen computer vision to fake ID cards, VPNs, laptop farms in the US and even deepfaked faces/voices — a story picked up by Wired. He traces individuals to Dandong, China near the North Korean border, explains the financial motives (salaries, IP theft, credentials, direct bank/API access), and shares hiring and cybersecurity tips for SMEs. He also reflects on internet fragility (BGP built on trust), the CrowdStrike incident, Belgium's limited tech ecosystem versus San Francisco's AI-driven revival, and the middenjury exam system that enabled his early career.

Talks about

Insights & ideas

The through-line

Everything Simon Wijckmans says circles back to a single structural claim: the internet was built on trust and never rebuilt. "Het internet is gebouwd op vertrouwen in de essentie" [1][2], he says, pointing at routing protocols like BGP that simply accept whatever a neighbour claims, and at decades of hot fixes layered over a design that was never revisited. That fragility is the reason serious incidents keep recurring, and it frames his own ambition in deliberately modest terms: "Ik wil het internet veiliger maken. Dus het internet is zeer groot. Als we daar een procentje van kunnen krijgen, dan ben ik al heel tevreden" [1]. A percentage point of a very large thing is enough. He reaches for the same register when describing what security work is actually worth, joking that the true measure of progress is "de spatie tussen Frankrijk en Duitsland dat ze niet meer met elkaar vechten" [1][2].

The second half of the through-line is that attackers are rational. They go where the defence is thinnest, whether that is a browser, a job application, or an unpatched assumption. "Zo is dat ook bijvoorbeeld met fietsendiefstalen. Degene met het dikste slot die gaat blijven staan. Die met het dunste slot die verdwijnt. Zo is dat ook in cybersecurity" [2]. The practical consequence he draws is not paranoia but attentiveness: "Als iets niet helemaal koser aanvoelt, dan is het waarschijnlijk ook wel even niet zo" [1][2].

On where the attack surface moves next

The bike-lock logic explains his own product decision. As companies bought firewalls and hardened the perimeter, attackers shifted to the client side, the user's own browser, which had become the weakest link. That gap is why c/side exists [2]. The same reasoning applies to a newer vector he considers unsolved: JavaScript embedded in advertisements on news sites, which quietly conscripts ordinary visitors' browsers into DDoS attacks. Because the traffic comes from real browsers on residential IP addresses, there is no fingerprint left to filter on, and he is blunt that there is currently no solution [1][2].

He is equally clear that defensive tooling has no inherent technical advantage. Security vendors often wield exactly the same technical power as malicious actors, which turns the whole field into a cat-and-mouse game, and if defender and attacker are evenly matched the outcome is a coin flip [1][2]. His conclusion runs against the popular reading of the CrowdStrike outage: security software needs deeper operating-system access than malware in order to hold the upper hand, and the very privilege that made that bug so damaging is the privilege it should have [1][2].

On the North Korean infiltration operation

The mechanics are what he keeps returning to, because they defeat the controls companies assume are sufficient. Applicants got past a paid, advanced third-party identity verification service by holding up a green-screen plastic card and using computer vision to project a forged ID onto it live during the video call: "Ze hebben die letterlijk in green screen formaat. En ze hebben met computer vision live op the call daar valse identiteitskaarten opgeprint" [1][2]. That trick lets them mint identities at speed. On the American side the operation depends on laptop farms, local people who accept the company laptop and install VPN software so that a worker abroad appears to be sitting in the US [2]. Specific individuals traced back to Dandong, China, on the North Korean border [1][2].

It is not one job per person and it is not personal. "Maak je geen illusie. Die persoon die dat je gesproken hebt, Tommy Smith, die heeft tegelijkertijd 10 van die jobs. Het is eigenlijk gewoon een kwestie van volume voor hun" [1][2]. The escalation ladder is what makes it dangerous rather than merely fraudulent: first the US salary, multiplied across up to ten simultaneous roles; then intellectual property; then personal data and credentials sold on the dark web; and finally direct access to payment processor APIs and bank accounts, which is how crypto firms have been drained of everything [1][2].

The tell, in his experience, is the mismatch between paper and person. Fake candidates score above 90% on take-home coding tests, because those tests get reverse-engineered or answered with AI, so a suspiciously high score is itself a red flag [1][2]. Live questioning breaks the illusion: "Stelde ik de vraag: vertel mij wat het Border Gateway Protocol doet. Die persoon wist niet meteen het antwoord, heeft het dan duidelijk in een AI geduwd en begon te praten over border checks, als in effectief fysieke border checks" [1].

On hiring so you don't get infiltrated

His advice is procedural and unglamorous. Don't hire remotely if you don't need to, and prefer local hires or trusted agencies. Never skip background checks: calling previous employers is the single hardest thing for a fraudulent candidate to fake. Meet remote hires in person. And above all, "Neem nooit iemand aan voor een job dat je zelf niet begrijpt" [2], because you cannot ask the probing follow-up question that collapses a scripted answer if you don't understand the domain [1][2].

He also treats this as a management problem rather than a screening problem. Putting KPIs or incentives on managers to fill roles quickly manufactures pressure that fraudulent candidates are built to exploit, and in that arrangement nobody wins [1][2].

On why he took the story public

The infiltration scheme has existed since COVID and was already known inside recruiting circles, but that knowledge never travelled to the people most exposed to it: startup founders and small and medium-sized businesses. Closing that gap is why he pushed the story into the media through Wired [1][2]. The same instinct informs his complaint about disclosure: governments are frequently exempt from breach notification obligations, so an incident like the Spanish blackout may never be publicly attributed even if it was a cyberattack [1][2].

On AI

He does not treat AI as a threat category of its own, even though he has watched it being used against him in interviews. His framing is expansive: "Ik denk eigenlijk dat we dit gewoon gaan gebruiken als een tool voor superhumans te maken" [1][2]. The failure mode he documents is not the model but the person hiding behind it, the candidate who pastes a question into a chatbot and confidently explains border checks [1].

On Belgium, London and San Francisco

His view of the Belgian tech economy is unsentimental: it is primarily an implementation and sales country, operating in a small economy, and ambitious founders follow the well-worn route from Europe to London to San Francisco [1][2]. What San Francisco offers is not weather or capital alone but density and accident. "Je gaat er naar een koffiebar, je wordt in de enkel gebeten door de hond van een CTO van een bedrijf waar je enorm veel van kan leren. Dat is niet iets dat je in België bij de bakker om de hoek zou tegenkomen" [1][2]. He credits AI with reviving the city dramatically over the past year, pulling in extreme amounts of global talent, and points to experienced operators, repeat investors and recycled tech wealth as things a European founder simply cannot access at home [1][2].

Belgium does get credit in one specific place. The Flemish middenjury, the central examination board that let him complete his diploma subject by subject on his own schedule, freed the time to learn technology and start his career early. "Ik kan niet genoeg de Vlaamse overheid bedanken voor het feit dat de middenjury überhaupt bestaat, want anders had ik geen opleiding gehad, had ik geen diploma gehad, had ik volledig een dropout geweest" [1][2].

On doing one thing properly

Alongside the technical arguments sits a plain operating principle about scope and honesty in the product itself: "Wij gaan geen [ __ ] verkopen of wel doen we dit en dan doen we het goed" [2]. Either the thing is done well or it isn't sold.

Takeaways

  • Treat the client side as the current soft target: as perimeter defences hardened, attackers moved to the user's browser, which is the gap c/side was founded to close [2].
  • A candidate scoring above 90% on a take-home coding test deserves more scrutiny, not less, because those tests get reverse-engineered and AI-assisted while live questioning still exposes the fake [1][2].
  • Advanced third-party identity verification is not a control you can lean on alone: green-screen cards plus live computer vision defeated a paid provider [1][2].
  • Always call previous employers, since that is the hardest element of a fabricated identity to fake, and meet remote hires in person [1][2].
  • Never hire for a role you don't understand well enough to ask a probing follow-up question, and never put speed-to-fill incentives on hiring managers [1][2].
  • Assume infiltration escalates: salary first, then intellectual property, then credentials sold on the dark web, then payment APIs and bank accounts, which has emptied crypto firms entirely [1][2].
  • Ad-embedded JavaScript DDoS using real browsers on residential IPs currently has no fingerprint to filter on and no known solution [1][2].
  • Give defensive software deeper OS access than malware has, because evenly matched attacker and defender is a coin flip, and that is the correct reading of the CrowdStrike case [1][2].

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.