Przejdź do treści
PodcastyBiznesFuture of Threat Intelligence

Future of Threat Intelligence

Team Cymru
Future of Threat Intelligence
Najnowszy odcinek

121 odcinków

  • Future of Threat Intelligence

    Efani's Mark Kreitzman on the SIM swap that cost Marks and Spencer 350 million euros

    17.09.2026 | 44 min.
    In our latest episode of the Future of Threat Intelligence podcast, Mark Kreitzman, Chief Cyber Evangelist at Efani, shares how organized crime is scaling SIM swap attacks with AI, why most U.S. financial institutions still rely on SMS authentication, and how Efani's reversed MVNO model locks every carrier and phone store out of customer accounts.
    Mark knows these attacks firsthand. In 2017, an attacker ported his number for 61 minutes, stole his crypto, and ported it back to hide the attack. That experience drove him to help build a secure mobile service now protecting executives, crypto holders, and high-net-worth individuals with up to $5 million in insurance backing per customer.

    Topics discussed:
    How organized crime and AI are scaling SIM swap attacks from lone hackers to industrial operations

    Efani's reversed MVNO model that locks carriers, phone stores, and support agents out of customer accounts

    Why 80% of U.S. financial institutions still default to SMS authentication

    The Marks and Spencer breach that started with a middle manager's SIM swap and cost 350 million euros

    How every data breach feeds targeting data to SIM swap attackers

    Key Takeaways:
    Separate email accounts across personal, banking, and crypto to prevent a single compromised address from exposing multiple accounts.

    Replace SMS-based authentication with authenticator apps and hardware keys wherever your financial institutions allow it.

    Audit which services are tied to your mobile number and remove phone-based recovery from high-value accounts.

    Assume your personal data is already exposed from past breaches and layer your defenses accordingly.

    Evaluate your mobile carrier's security model, because the default carrier setup prioritizes convenience over account protection.

    Monitor unexpected password reset texts or authentication codes as potential reconnaissance by attackers testing your accounts.

    Protect executive and leadership phone numbers as enterprise attack surfaces, not just personal devices.

    Listen to More Episodes:  YouTube  •  Apple  •  Spotify  •  Website
  • Future of Threat Intelligence

    Ironbridge CISO Consulting's Jim Almerico on the end of AI euphoria and the flaws emerging

    03.09.2026 | 34 min.
    The euphoria around AI is over, and the flaws are showing up at a speed nobody imagined a year ago. Jim Almerico (https://www.linkedin.com/in/jalmerico), CISO at Ironbridge CISO Consulting, tells Eli that organizations deploying AI without understanding how it operates are repeating the mistakes of the early internet and IoT eras.
    Jim shares lessons from securing PsiQuantum under a 90-day CMMC deadline for a $31 million DARPA contract, why identity access management is the foundation for governing AI agents, and how quantum computing is approaching its tipping point.

    Topics discussed:
    Why AI security mirrors early internet and IoT security failures

    Governing autonomous AI agents through identity access management

    Completing CMMC certification in 90 days for a DARPA contract

    How open defender communication would strengthen collective security

    Preparing encryption and certificates for post-quantum readiness

    Securing MCP and API connections against unintended data exposure

    Why blind trust in AI is the biggest organizational risk

    Key Takeaways: 
    Require model cards and data flow documentation before deploying AI so security teams know exactly how a system operates before they protect it.

    Clean up identity access management for knowledge workers first, because AI agents will inherit every unresolved permission in the system.

    Build AI governance around containment controls, not checklists, since the organizations behind the most advanced AI could not contain their own products.

    Demand open communication between defender teams, treating shared intelligence as the biggest force multiplier in security.

    Start quantum readiness now by inventorying encryption and certificates, even though the quantum tipping point may be years away.

    Audit MCP and API connections for unintended data exposure before integrating AI tools across organizational boundaries.

    Approach AI adoption with the understanding that both benefits and harm are real, and resist blind trust in any tool your team cannot fully explain.

    Listen to More Episodes:  YouTube  •  Apple  •  Spotify  •  Website
  • Future of Threat Intelligence

    Why the old phishing training is obsolete after deepfake attacks

    02.07.2026 | 42 min.
    Resource constraints, not attacker sophistication, are the biggest cyber threat facing state and local governments, and AI is widening the gap by making low-skill attackers faster and more convincing.
    In our latest episode of the Future of Threat Intelligence podcast, Randy Rose, VP of Security Operations and Intelligence, Center for Internet Security, shared how community defense, essential controls, and human verification hold the line as phishing and deepfake threat intelligence evolve.

    Topics discussed:
    Why resource constraints are the number one cybersecurity challenge for state and local governments

    How AI makes low-skill attackers faster while ransomware and phishing stay the top threats

    Mapping CIS Implementation Group 1 controls to top MITRE ATT&CK techniques to reduce risk

    Why traditional phishing training is obsolete after AI-written phishing and deepfake attacks

    How community defense turns one organization's attack into protection for thousands

    Key Takeaways:
    Prioritize an essential set of controls, starting with CIS Implementation Group 1, to buy down the most risk against top threats like ransomware.

    Map your controls to the top MITRE ATT&CK techniques so you know which defenses deliver the greatest impact.

    Retire phishing training built on spotting typos and odd phrasing, and train people for general skepticism instead.

    Build proactive verification, such as two-person integrity, before trusting an email, phone call, or video feed.

    Inventory access alongside hardware and software, tracking who and what has access to what, including AI and agent tools.

    Maintain and exercise an updated incident response plan, and know exactly who to call in each scenario.

    Use AI for data translation, correlation, and enrichment at scale, and reserve creative thinking and context for people.

    Listen to More Episodes:  YouTube  •  Apple  •  Spotify  •  Website
  • Future of Threat Intelligence

    Coalition's Daniel Woods on the attorney-client privilege tactic shaping every IR investigation

    18.06.2026 | 42 min.
    Daniel Woods, Principal Security Researcher at Coalition, sits at an intersection most security practitioners never access: underwriting data, claims history, and live forensics findings from the same vantage point. In this conversation, he traces how cyber insurance evolved from a 10% loss ratio product in the late 1990s to carriers reportedly hitting 130%+ during the ransomware era, and what that financial pressure forced the market to actually build. He also explains the mechanics behind why lawyers end up directing IR investigations, who that structure protects, and why every practitioner who has ever written a forensic report should understand it before an incident forces the question.

    Topics discussed:

    Early cyber insurance economics and how a near-90% profit margin shaped the market

    How California's 2003 breach notification law created the data breach litigation economy

    How the shift from on-site auditors to yes/no questionnaires left insurers blind to whether backups were actually recoverable

    Why RDP as an initial access vector dropped from roughly 80-90% of ransomware claims to around 20%

    Why insurers put lawyers in front of IR investigations and what that means for what gets documented

    The unresolved legal problem with cyber war exclusions along the nation-state/criminal contractor continuum

    Why security practitioners should be in the room during the insurance buying process, not reacting to the vulnerability report afterward

    Why cyber insurance is a broad digital risk product and not just a ransomware backstop

    Key Takeaways:

    Get your security team into the insurance buying process before the vulnerability report arrives. Once it lands, you are in reactive mode with your carrier already holding findings.

    Insurers like Coalition built their underwriting model around external perimeter scanning, specifically flagging open RDP, VPNs without MFA, and exposed attack surface before they quote. That scan is happening whether your team engages with it or not. Use it.

    The backup question on an insurance application has moved well past yes or no. Insurers now ask about recovery time, maintenance cadence, and whether backups are actually tested. A tape environment that takes two months to restore is not a recovery capability and carriers know it.

    When a lawyer is directing your IR investigation, what goes into the forensic report is a legal decision, not just a technical one. Daniel's own interview research with lawyers found that technical practitioners routinely undermine the privilege structure by writing explicit characterizations of organizational failure, things like "flagrant culture of noncompliance," that lawyers cannot shield and litigants can use. Know what you are writing before an incident forces you to find out why it matters.

    Standalone cyber policies and property policies respond very differently to nation-state incidents. Cyber insurers paid out on Sony under standalone cyber. The war exclusion fights over NotPetya happened in property insurance courts. If your coverage mix includes both, those are not equivalent protections.

    The attribution problem cuts both ways. Nation-state actors contracting ransomware groups, or using financially motivated TTPs alongside espionage operations, make war exclusion clauses nearly impossible to apply cleanly. Know where your policy language actually draws that line.

    Cyber insurance covers more than breach response. Impersonation, deepfake fraud, and privacy violation liability are all coverable under the right policy structure. Most buyers do not realize that until they file a claim.

    Listen to more episodes: 
    Apple 
    Spotify 
    YouTube
    Website
  • Future of Threat Intelligence

    How Akira hits thousands of SMBs with $50K-$150K ransoms undetected | Alex Bovicelli

    04.06.2026 | 26 min.
    In part two of this conversation, Alex Bovicelli, Senior Director of Threat Intelligence at Tokio Marine HCC - Cyber & Professional Lines Group,  gets into what the industry keeps getting wrong about ransomware targeting. The organizations getting hit most often are not the ones making headlines, and the attack methods used against them require far less sophistication than most practitioners assume.
    Drawing from claims data across thousands of insured companies, Alex explains how groups like Akira have deliberately built around high-volume, low-ransom SMB campaigns, why unpatched MSP tooling is one of the most consistently exploited entry points most defenders aren't tracking, and how a low-tier threat actor sitting on an infected employee machine for six months can hand off access to a major ransomware group. He also breaks down how access brokers are assessing victim maturity, insurance policy status, and organizational structure to decide whether ransomware or BEC delivers the better return, which has nothing to do with CVSS scores.
    Topics discussed:
    Why SMBs face structurally different attacks than enterprises, not scaled-down versions

    Akira's volume-over-value model: ransoms in the $50K-$150K range, thousands of targets, below the threshold that attracts law enforcement attention

    Unpatched MSP tooling as a lateral movement vehicle the victim never sees coming

    How a low-tier threat actor's own machine was infected with an info stealer, exposing the 6-7 month timeline between initial access and ransomware deployment

    How access brokers assess victim maturity, insurance coverage, and org structure to choose between ransomware and BEC for maximum ROI

    Why criminal exploitability outweighs published vulnerability severity as a patching signal

    How cyber insurance claims data gives CTI teams visibility into active exploitation before it surfaces publicly

    Key Takeaways:
    Stop treating SMB ransomware exposure as a scaled-down version of enterprise risk. The attack methods, economics, and entry points are structurally different, and your defenses need to reflect that.

    Track SSL VPN brute forcing campaigns specifically. Groups like Akira have optimized these tools to run unattended and return thousands of valid credentials against organizations with no account lockout policies.

    Enforce account lockout policies and MFA on every remote access entry point. These aren't advanced controls. They're what separates organizations that get hit from those that don't at the SMB level.

    Audit your MSP's patch posture as part of your own risk assessment. If your MSP is running unpatched tooling, your organization inherits that exposure whether you know about it or not.

    Integrate info stealer log analysis into your detection pipeline. A low-tier threat actor's infected machine can expose a 6-7 month old foothold and reveal exactly how a major ransomware group obtained initial access.

    Understand that access brokers are evaluating your organization's maturity, insurance status, and whether you're centralized or decentralized before deciding whether to hit you with ransomware or BEC. Your structural profile affects how you get targeted.

    Replace CVSS as your primary patching prioritization signal. What access brokers actually care about is ease of exploitation combined with the number of available targets, and your patching sequence should mirror that logic.

    Use post-claim incident response data to validate and calibrate your pre-claim detection signals. Insurance claims data provides visibility into what is actively being exploited in the wild before it reaches the news cycle.

    Listen to more episodes: 
    Apple 
    Spotify 
    YouTube
    Website
Więcej Biznes podcastów
O Future of Threat Intelligence
Welcome to the Future of Threat Intelligence podcast, where we explore the transformative shift from reactive detection to proactive threat management. Join us as we engage with top cybersecurity leaders and practitioners, uncovering strategies that empower organizations to anticipate and neutralize threats before they strike. Each episode is packed with actionable insights, helping you stay ahead of the curve and prepare for the trends and technologies shaping the future.
Strona internetowa podcastu

Słuchaj Future of Threat Intelligence, A Bit of Optimism i wielu innych podcastów z całego świata dzięki aplikacji radio.pl

Uzyskaj bezpłatną aplikację radio.pl

  • Stacje i podcasty do zakładek
  • Strumieniuj przez Wi-Fi lub Bluetooth
  • Obsługuje Carplay & Android Auto
  • Jeszcze więcej funkcjonalności
Future of Threat Intelligence: Podcasty w grupie