

How BT Tackled 180 Years of Legacy to Build a Passwordless Future
Jul 17, 2025
Christian Schwarz, Security Director for Network Services at BT Group, shares insights from his role in modernizing security at a 180-year-old telecom giant. He discusses the challenges of managing legacy systems and discovering hundreds of thousands of hidden credentials. Transitioning to a passwordless future, he emphasizes reducing friction while enhancing security design. Intrigued by fostering a proactive security culture, he also dives into his personal passions like cycling and culinary delights, blending insights on innovation and work-life balance.
AI Snips
Chapters
Books
Transcript
Episode notes
Obsolete 'Castle and Moat' Model
- The old telco security model of "moat and a castle" is obsolete due to evolving threats.
- Implicit trust inside the network is risky; reducing credentials lowers attack surface significantly.
Legacy Shared Password Risks
- BT historically used single shared passwords for many network appliances managed by third parties.
- This practice created major risks if credentials leaked, prompting the shift to dedicated, fine-grained passwords.
Start With Threat Modeling
- Start secret management standardization with thorough threat modeling of your attack surfaces.
- Tailor security approaches to specific components and real-world threats for effectiveness.