Cloud Security Podcast

How BT Tackled 180 Years of Legacy to Build a Passwordless Future

Jul 17, 2025
Christian Schwarz, Security Director for Network Services at BT Group, shares insights from his role in modernizing security at a 180-year-old telecom giant. He discusses the challenges of managing legacy systems and discovering hundreds of thousands of hidden credentials. Transitioning to a passwordless future, he emphasizes reducing friction while enhancing security design. Intrigued by fostering a proactive security culture, he also dives into his personal passions like cycling and culinary delights, blending insights on innovation and work-life balance.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Obsolete 'Castle and Moat' Model

  • The old telco security model of "moat and a castle" is obsolete due to evolving threats.
  • Implicit trust inside the network is risky; reducing credentials lowers attack surface significantly.
ANECDOTE

Legacy Shared Password Risks

  • BT historically used single shared passwords for many network appliances managed by third parties.
  • This practice created major risks if credentials leaked, prompting the shift to dedicated, fine-grained passwords.
ADVICE

Start With Threat Modeling

  • Start secret management standardization with thorough threat modeling of your attack surfaces.
  • Tailor security approaches to specific components and real-world threats for effectiveness.
Get the Snipd Podcast app to discover more snips from this episode
Get the app