Transparency Wars: Exposing Hidden Biases in Testing

Independent testing is designed to be impartial; but how independent is it, truly?

In a cybersecurity industry where vendors fund evaluations, influence test scopes, and leverage results for marketing, concerns about bias and transparency are both inevitable and critical. This panel will facilitate an open, candid discussion on one of the most sensitive yet essential topics in our testing ecosystem: the unseen dynamics that dictate what is tested, the methodologies employed, and how results are presented or obscured.

Key discussion points will include:

  • Should cybersecurity vendors influence test selection and methodology?
  • What are the implications when testing organizations financially depend on the vendors they evaluate?
  • Are existing transparency declarations and methodological disclosures sufficient, or merely superficial?
  • What role can or should organizations such as AMTSO play in enforcing rigorous standards for independence and comprehensive disclosure?

The session aims to critically examine if current transparency practices effectively foster trust among consumers, media, and regulatory bodies, or if the industry needs to elevate its standards further.

Luis Corrons – Gen

Luis Corrons is a cybersecurity expert with more than 25 years of experience analyzing threats and helping people protect their digital lives. He works at Gen, the global company behind Norton, Avast, AVG, and Avira, where he serves as Security Evangelist and is one of the company’s main spokespersons on threat-related topics.

Throughout his career, Luis has specialized in tracking malware and scam trends, building awareness of emerging threats, and explaining complex issues in a way that connects with both technical and non-technical audiences. He has been an active voice in the cybersecurity community since 1999, regularly speaking at international conferences such as Virus Bulletin, CARO Workshop, AVAR, APWG, and more.
Beyond his role at Gen, Luis serves as Chairman of the Board at the Anti-Malware Testing Standards Organization (AMTSO) and sits on the board of MUTE, contributing to industry-wide collaboration on testing, standards, and transparency. He is a frequent media contributor on TV, radio, and major news outlets, where he helps raise public awareness about online security and cybercrime.

Righard Zwienenberg – ESET

Zwienenberg began his work with computer viruses in 1988 after encountering his first virus issues at the Technical University of Delft. This experience sparked his interest in virus behavior, leading him to study and present solutions and detection methods ever since. Over nearly four decades, he has worked for various companies, including CSE Ltd., ThunderBYTE, Norman, and ESET. He has also held or continues to hold positions in several industry organizations, such as AMTSO, AVAR, the WildList, IEEE ICSG, and serves on the Advisory Board for Europol’s European Cyber Crime Center (EC3) and Virus Bulletin. He also runs his on computer security consultancy company (RIZSC).

Zwienenberg has been a member of CARO since late 1991. He is a frequent speaker at conferences, including Virus Bulletin, EICAR, AVAR, FIRST, APWG, RSA, InfoSec, SANS, CFET, ISOI, SANS Security Summits, IP Expo, government symposia, SCADA seminars, and other general security events. Beyond his professional work in security, his hobbies include playing drums, performing magic, modeling balloons, restoring ancient computers, and much more.

Simon Edwards – SE LABS

Simon Edwards is the founder and CEO of SE LABS, a London-based company that specialises in advanced security testing. He provides tailored security advice to large businesses and more general technical advice to small businesses and individuals.

Simon focuses on cyber security and develops ways to test computer security products and services. He built and ran the world’s first real-world anti-virus test and continues to innovate in testing that involves computer hacking.

A founder member of the Anti-Malware Testing Standards Organization (AMTSO), Simon held a Chair position on its Board of Directors for over a decade.

Simon features on the Cyber Security DE:CODED podcast, which provides security advice for businesses and individuals, recognising that people need security in both their work and personal lives.

Links:
Website: https://selabs.uk/
Podcast: https://www.decodedcyber.com
LinkedIn: https://www.linkedin.com/in/spgedwards/
Mailing list: https://selabs.uk/news

Samir Mody – K7 Computing

Samir Mody graduated from the University of Oxford in 2000 with a First-Class Masters degree in Chemical Engineering, Economics and Management. He spent over 9 years at Sophos UK, the final 3 as Threat Operations Manager of SophosLabs. Since August 2010 he has been running K7 Labs in Chennai, India. Samir has actively contributed to the IEEE Taggant System project and other industry collaborations such as AMTSO and CTA. He has co-authored and/or presented papers and participated in panel discussions at various international security conferences (EICAR, VB, AVAR). Samirs interests include reading (philosophy, politics, history, literature, and economics), sport and classical music.