Team Cymru
Future of Threat Intelligence
Welcome to the Future of Threat Intelligence podcast, where we explore the transformative shift from reactive detection to proactive threat management. Join us as we engage with top cybersecurity leaders and practitioners, uncovering strategies that empower organizations to anticipate and neutralize threats before they strike. Each episode is packed with actionable insights, helping you stay ahead of the curve and prepare for the trends and technologies shaping the future.
Author
Team Cymru
Category
Podcast website
Latest episode
Jul 2, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Why the old phishing training is obsolete after deepfake attacks 02.07.2026 42:58
Resource constraints, not attacker sophistication, are the biggest cyber threat facing state and local governments, and AI is widening the gap by making low-skill attackers faster and more convincing. In our latest episode of the Future of Threat Intelligence podcast, Randy Rose , VP of Security Operations and Intelligence, Center for Internet Security , shared how community defense, essential con...
Coalition's Daniel Woods on the attorney-client privilege tactic shaping every IR investigation 18.06.2026 42:46
Daniel Woods , Principal Security Researcher at Coalition , sits at an intersection most security practitioners never access: underwriting data, claims history, and live forensics findings from the same vantage point. In this conversation, he traces how cyber insurance evolved from a 10% loss ratio product in the late 1990s to carriers reportedly hitting 130%+ during the ransomware era, and what t...
How Akira hits thousands of SMBs with $50K-$150K ransoms undetected | Alex Bovicelli 04.06.2026 26:26
In part two of this conversation, Alex Bovicelli , Senior Director of Threat Intelligence at Tokio Marine HCC - Cyber & Professional Lines Group, gets into what the industry keeps getting wrong about ransomware targeting. The organizations getting hit most often are not the ones making headlines, and the attack methods used against them require far less sophistication than most practitioners...
The CVSS problem: why severity scores don't predict what gets exploited 21.05.2026 45:12
Patrick Garrity, Security Researcher at VulnCheck , has a data problem with how the industry prioritizes vulnerabilities, and the data is his own. After manually categorizing roughly 800 exploited vulnerabilities by technology type each year, what he keeps finding is that the CVSS severity distribution of exploited CVEs tracks closely with the overall CVE population. Meaning the scoring system mos...
Unit 42's Andrew Rathbun on the Sysmon Configuration Mistake Enterprises Are Making 07.05.2026 42:22
Andrew Rathbun , Senior Consultant at Palo Alto Networks Unit 42 , has spent years tearing apart Windows endpoints across ransomware, APT, insider threat, and DPRK IT worker cases. His read on the state of enterprise Windows logging is blunt: most organizations have spent significant money on detection tooling while leaving the native forensic record so truncated that proving an intrusion timeline...
Trend AI's Robert McArdle on Criminal Business Models Surviving Tech Revolutions 23.04.2026 40:03
After 18 years tracking cybercriminal operations at Trend AI , Robert McArdle , Director of Cybercrime Research, has developed a framework for predicting how threat actors adopt new technology: the answer consistently comes down to economics, not capability. He breaks down three rules of thumb his team uses: criminals want an easy life, any new technology must beat the ROI of their current model,...
Scott Scher on Why CTI Teams Forecast Instead of Predict 09.04.2026 45:16
Scott Scher , Cyber Threat Intelligence Lead, makes a distinction that reframes how intel teams should think about their own value: they are forecasters, not predictors. That shift in framing has concrete consequences for how CTI programs justify themselves internally, and Scott argues that the most meaningful metric isn't alert volume or report count, but the decisions intel has actually influenc...
You Can't Trust Your Zoom Call Anymore. Deepfakes, DPRK & the New Attack Surface 26.03.2026 42:30
Deepfakes have moved well past the uncanny valley and into active threat operations, and Tom Cross , Head of Threat Research at GetReal , has the client-side case studies to back it up. Tom explains how North Korean IT worker infiltration campaigns have transformed HR and video conferencing from administrative functions into active attack surface, albeit one that most security teams aren't mon...
Two Minds. One Reframe. A Shift That Won't Wait. 19.03.2026 42:17
Vincent Passaro , Engineering Manager at Stripe Security , didn't get there through a slide deck or a company mandate. He got there through a shower thought that followed a conversation with a friend, and it broke how he'd been thinking about building, leading, and even measuring his own team. The reframe was simple and did not start with "we're all going to be software developers...
TIG Risk Services' Duaine Labno on How Remote Hiring Became an Opening for Infiltration 12.03.2026 30:54
What happens when a DPRK IT worker operation lands inside one of your clients, and the three-letter agency you call says they can't show up? Duaine Labno , Director of Special Investigations & Threat Intelligence at TIG Risk Services , walks through exactly that case: his team built a ruse to recover the compromised laptop, staged a physical handoff at corporate HQ, filmed the courier, ran...
Thermo Fisher's Matt McKnew on the Evolution of Ransomware as a Service 05.03.2026 34:31
When Matt McKnew , Senior Manager of Incident Response at Thermo Fisher , tracked down the Nimda worm in 2001 by analyzing packet captures to identify NetBIOS saturation patterns, threat actors weren't trying to get paid; they were causing disruption. Today, he's defending against ransomware groups that operate like businesses, complete with service models and affiliate networks. Matt ex...
Tokio Marine HCC's Alex Bovicelli on the SMB Ransomware Wave the Industry Isn't Talking About 26.02.2026 37:15
Running CTI at a cyber insurance carrier and across more than tens of thousands of companies forces a triage discipline most programs never need to build. Alex Bovicelli , Senior Director of Threat Intelligence at Tokio Marine HCC , describes how his team scaled by narrowing focus to one thing: the initial access vectors threat actors are actually using right now: not CVSS scores, not spray-and-pr...
Coalition's Daniel Woods on What Cyber Insurance Claims Reveal About Security Controls 19.02.2026 38:24
Daniel Woods , Principal Security Researcher, and his team at Coalition analyzed forensic reports across their 100,000-policyholder base and found 50% of ransomware incidents begin with VPN or firewall exploits. But here's the twist: 40-60% of those aren't vulnerability exploits at all, they're stolen credentials bypassing perimeter devices entirely. Organizations running Cisco ASA dev...
Stripe's Vincent Passaro on Fraud Taxonomies & Generating Red Team Testing Roadmaps 12.02.2026 1:08:58
Stripe 's 3-person intel team created FT3 (fraud tools, tactics & techniques), a framework modeled after MITRE ATT&CK but purpose-built for financial fraud, to eliminate the communication breakdown where "fraud" required constant reverse engineering. The structured taxonomy now powers both analyst workflows and automated fraud systems operating at transaction-millisecond spee...
Fortinet's Aamir Lakhani on Mapping Business Pain Points Attackers Exploit 05.02.2026 42:44
Fortinet processes telemetry from 50% of the next-generation firewall market, giving Aamir Lakhani , Global Director of Threat Intelligence & Adversarial AI Research, and his team visibility into a looming shift: threat actors moving from exploiting a small subset of proven CVEs to weaponizing the entire vulnerability landscape through AI automation. While defenders currently concentrate resou...
PayPal's Blake Butler on Finding Fraud Signals in Uncleaned Data 29.01.2026 42:08
PayPal 's fraud team catches credential stuffing before money moves by watching business intelligence signals that most organizations overlook: explosive traffic growth to legacy endpoints, mismatched phone numbers against account creation locales, and anomalies hidden in raw uncleaned data. Blake Butler , Senior Manager & Head of Fraud Threat Intelligence, applies infrastructure analysis...
Tidal Cyber's Scott Small on Operationalizing MITRE from Intel to Validation 22.01.2026 32:14
Tidal Cyber 's Director of Cyber Threat Intelligence Scott Small reveals how his knowledge base now tracks almost 25,000 procedure-level instances across nearly 800 MITRE ATT&CK techniques and sub-techniques, capturing the command-level detail that exposes the false promise of "100% coverage" when working at technique abstraction alone. He argues that the pre-attack reconnaissanc...
Marsh McLennan's Casey Beaumont on Vendor Breach Assessments That Cut through Legal Games 15.01.2026 39:33
When Casey Beaumont 's entire CTI team departed just before new analysts started, she found herself running threat intelligence solo for months while directing incident response, threat hunting, and red team operations. That trial by fire taught her exactly what separates tactical intelligence from strategic value, and why the best analysts invest significant personal time building trust networks...
State CISOs on Why Cyberattacks Against 1 State Attack All of America 08.01.2026 44:47
Michael Moore , CISO for the Secretary of State of Arizona 's office, explains how he acts as a virtual CISO for all 15 counties by conducting physical security assessments at election facilities and providing real-time guidance during critical events. His approach treats surprise attacks as learning opportunities that should only work once, immediately sharing adversary infrastructure and TTPs ac...
Safebooks AI’s Ahikam Kaufman on Why CFOs Need Company-Specific AI Models for Fraud Detection 25.09.2025 27:27
Unlike CISOs who work with consistent vulnerabilities across cloud environments, CFOs face company-specific financial processes that change constantly, making automation historically complex to solve before the AI era. Ahikam Kaufman , CEO & CFO of Safebooks AI , explains why machine learning is the only viable solution to detect sophisticated embezzlement schemes that regulatory compliance de...
Marsh's Sjaak Schouteren on the Golden Rule of Risk Assessment 18.09.2025 35:28
Cyber insurance has transformed from a liability-focused niche product into a comprehensive business continuity tool, but widespread misconceptions continue to prevent organizations from maximizing its strategic value. Sjaak Schouteren , Cyber Growth Leader - Europe at Marsh , offers David how they combine risk quantification with business-focused communication strategies that give security leader...
SIG's Rob van der Veer on Why "Starting Small" with AI Security Might Fail 11.09.2025 34:01
What happens when someone who's been building AI systems for 33 years confronts the security chaos of today's AI boom? Rob van der Veer , Chief AI Officer at Software Improvement Group (SIG) , spotlights how organizations are making critical mistakes by starting small with AI security — exactly the opposite of what they should do. From his early work with law enforcement AI systems to becoming a k...
Vigilocity's Karim Hijazi on Supply Chain Threat Intelligence 04.09.2025 31:51
Karim Hijazi ’s approach to threat hunting challenges conventional wisdom about endpoint security by proving that some of the most critical intelligence exists outside organizational networks. As Founder & CEO of Vigilocity , his 30-year journey from the legendary Mariposa botnet investigation to building external monitoring capabilities demonstrates why DNS analysis remains foundational to mo...
CyberHoot's Craig Taylor on Why Fear-Based Phishing Training Fails 28.08.2025 32:22
Psychology beats punishment when building human firewalls. Craig Taylor , CEO & Co-founder of CyberHoot , brings 30 years of cybersecurity experience and a psychology background to challenge the industry's fear-based training approach. His methodology replaces "gotcha" phishing simulations with positive reinforcement systems that teach users to identify threats through skill-building rather th...
The Futurum Group's Fernando Montenegro on the OODA Loop Approach to Security Strategy 21.08.2025 29:04
What happens when you apply economic principles like opportunity cost and comparative advantage to cybersecurity decision-making? Fernando Montenegro , VP & Practice Lead of Cybersecurity at The Futurum Group , demonstrates how viewing security through an economics lens reveals critical blind spots most practitioners miss. His approach transforms how organizations evaluate cloud migrations, me...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.