Binalyze: The Culture Change Cybersecurity Can No Longer Ignore
Tech Talks DailyJune 26, 2026
3618
19:4315.01 MB

Binalyze: The Culture Change Cybersecurity Can No Longer Ignore

What if the biggest weakness in cybersecurity isn't the technology, but the way defenders communicate with each other?

Cybercriminals openly exchange techniques, vulnerabilities, and attack methods, constantly learning from one another. Meanwhile, many organizations remain reluctant to share details of breaches, investigations, or lessons learned. In this episode, I sit down with Lee Sult, Chief Investigator at Binalyze, to discuss why that imbalance is giving attackers an advantage and what the industry can do to change it.

Drawing on almost two decades in digital forensics and incident response, including work with Palantir, law enforcement agencies, and government organizations, Lee explains why cybersecurity should learn from industries such as aviation and emergency services, where every major incident becomes an opportunity for everyone to improve. We discuss why incident response needs to move beyond reacting to alerts, how proactive threat hunting can reduce attacker dwell time, and why repeatable investigation processes are becoming just as important as the security tools themselves.

We also explore the growing influence of AI, not because it is making attackers dramatically smarter, but because it is lowering the barrier to entry and increasing the volume of attacks security teams must handle. Lee shares why automation is becoming essential for investigators, how organizations can move from hours to minutes when responding to threats, and why cybersecurity is steadily becoming a boardroom issue rather than simply an IT concern.

If cybersecurity is truly an information war, what would happen if defenders became just as collaborative as the attackers they face every day? After listening, I'd love to hear your thoughts. Should organizations be more open about cyber incidents if it helps strengthen security for everyone?

Useful Links

Visit the Sponsors of the Tech Talks Network

[00:00:00] The leading issue of agentic AI in businesses right now is ensuring agents act with compliance guidelines. And Denodo applies guardrails across your entire data estate. By aligning your company's data infrastructure under one system, these guardrails perform consistently across your platform. So start scaling your business and start with Denodo. Simply visit denodo.com to learn more.

[00:00:32] Cybersecurity conversations often focus on the latest attack, the newest AI threat, or the next big breach. But in today's episode, I want to ask a much bigger question. What if the real problem is how defenders work together? My guest today is Lee Salt. He's a chief investigator at Binalyze. And today's conversation completely reframed how I think about cyber defense.

[00:01:00] And today we'll cover everything from digital forensics and automated incident response to crisis management and attacker collaboration. Because Lee is going to explain why cybersecurity should be treated less like an IT problem and more like an emergency response. And perhaps most importantly, he will also argue that attackers are winning partly because they collaborate more openly than defenders do. Real food for thought in this one.

[00:01:30] But enough for me. Let me introduce you to Lee right now. So thank you for joining me on the show today. Can you tell everyone listening a little about who you are and what you do? Sure. So my name is Lee Salt. I'm the chief investigator at Binalyze. We're an automated incident response or investigation and response company. We build digital forensics and incident response tools. For me, I've been in cybersecurity for quite a while.

[00:01:57] I did my first criminal digital forensics case about 19 years ago. I was a few years in IT and so on before that. So I've been doing this quite a while. Some notable things are I was the first forward deployed security engineer at Palantir. I helped grow that team out. I then went on to start or be a co-founder at the first cybersecurity company in Singapore. I always did digital forensics incident response consulting. We also had a powerful product that is now owned by Bitdefender.

[00:02:26] Happy to say it and exit. And if you know Bitdefender Gravity Zone, that's me. And now here I am at Binalyze at my what I call my forever home, because this is a continuation of my life's work. I absolutely love it. And I also love your job title. And listening to you talk there, chief investigator and talking about digital forensics, that's got to be an incredibly cool area to work in. Are your friends envious when you talk about this stuff? Because it sounds incredibly cool. Yeah, I'd say so.

[00:02:54] I would say it's two things. And I would say I'm two things. A serial entrepreneur, for sure. I help my friends and founders raise money and grow companies, so on. And then my real passion my whole life has been cybersecurity. And, of course, growing up with a homicide investigator as a dad who's now a police chief, it's my own career journey has similarly followed his. So I guess there's that to it as well. Yeah, I love the synergy there.

[00:03:20] And before you join me on the podcast today, I was reading how you've described cybersecurity as an information wall where defenders are losing partly because attackers collaborate more openly than the security community itself, which is crazy. But I know it's true. So why do you think the industry still struggles with transparency despite the scale of these threats and knowing that the bad actors are doing all the collaborating? What's going wrong here? You know, it's a real nuanced question.

[00:03:50] It's going to require some culture shift at some point, some eased regulations or something. It's just going to require some maturity on our side as defenders. But at the end of the day, defenders are working for governments or for private organizations or what have you. On the government side, you have limitations, security or I call it security clearance requirements. They share some information. On the private sector side, there's a couple of things.

[00:04:17] Certainly, there's some secret proprietary information folks don't want to share. But, you know, organizations are also fearful to share. If I share an indicator of compromise or an indicator of attack, that might then mean that I might then accidentally expose that my company has been attacked. That could trigger a reportable event. These types of things are not as fleshed out as they could be or not as clear as they could be.

[00:04:38] So really what it boils down to is as defenders, we don't share enough information because we have fear, uncertainty and doubt and some regulation and some impact if we do. And then attackers are just kind of a free for all. And, you know, they're free to share what they like for the most part. And I was also reading that you often compare cybersecurity with the aviation industry where incidents are thoroughly investigated and lessons are widely shared.

[00:05:04] But what would a true aviation style culture of cyber incident learning, what would that actually look like in practice? You know, it's a great question. And there's a couple of comparisons that I make. One is aviation and then one is to firefighting. But I think the underlying the underlying concept there is emergency management. And in the U.S., we have an organization called FEMA, and that is our Federal Emergency Management Administration. And what they have is a robust system for dealing with emergencies or major incidents.

[00:05:34] So say like a major hurricane or an oil spill or a cyber attack, even we're working with Texas Engineering A&M, who does a lot of that incident management training. Our Texas A&M Engineering Extension, who does a lot of that incident management training. And we're working on updating some FEMA stuff. This is the backer behind how the aviation industry addresses these incidents, learns from these incidents, and then bakes it into potentially new regulation, new incident management practice.

[00:06:01] And that's really what we need to look at, is we should probably stop looking at the cyber industry as a technical issue and start looking at this more from like a traditional emergency management or incident management perspective. Because that's how we're going to get better together. And, you know, there's always after action reviews and reports and public documentation for, like I say, the public response to Hurricane Helene just a few years ago. You can look all that stuff up, and it's not the same for cyber attacks.

[00:06:30] You can't go back and look at an attack against some large organization and actually get the real details. Most of the time, it's protected by an NDA or something like that. And I think one of the major things holding back so many organizations now are things like fear, reputational damage, regulatory scrutiny, or even legal exposure if they openly discuss breaches or security failures in public there.

[00:06:56] So how do we change that mindset without creating an even greater business risk, ironically? Yeah, you know, I think we're getting there. I think, I mean, this is where the mindset needs to shift. And I think with the recent attacks that we're seeing, the supply chain attacks that are pervasive, I mean, the numbers for those are insanely high. It's very difficult to keep up with. The wiper attacks that are coming out of the conflict in the Gulf that are having material impact on a business's ability to stay afloat.

[00:07:26] This is the type of thing where it's, you know, that's scarier than somebody going to jail or somebody getting held to a regulatory standard. Like, I think that's the type of thing with this material impact. That's what's going to change minds and start opening up some of the sharing that needs to be occurring. And I do think and I do know that there is some sharing happening in back channels, but it's not as robust as it could be or it needs to be to really thwart this or provide a win in this asymmetric warfare situation that we have.

[00:07:56] And as you said at the beginning there, you've worked with organizations, including Palantir, law enforcement agencies, and even the United States Secret Service, I believe. So I'm not sure what you're going to be able to share with me here. But from all these experiences, what separates organizations that learn quickly from incidents versus those that repeat the same mistakes expecting different results? Sure. The first thing that I'll say is I won't steal any valor from anybody.

[00:08:23] I was always a civilian contractor with these law enforcement and federal agencies. But the thing that separates it is it's twofold. It's that repeatable incident management or crisis management framework, and it's repeatable and defensible investigative practices. Historically, those investigation practices have taken quite a long time.

[00:08:43] And due to the asymmetric nature of cyber and the fact that people can hide behind VPNs and online aliases, tying that back to an individual has been hard. So you're really left with just that incident management framework and your lessons learned from how the attacker got in and which systems they targeted. That's what separates them from those that are unprepared.

[00:09:08] And as we were talking about earlier, threat actors, they openly share exploits, ransomware techniques and operational playbooks across underground communities. But again, as we said, defenders often operate in silos. And there is that mindset that is required here to improve that. But has cybersecurity unintentionally created a culture where secrecy benefits attackers more than the defenders, do you think? I would say so.

[00:09:36] I think this is common, again, in any asymmetric sort of warfare environment where attackers are free to move around at will. They're smaller groups that are much more nimble. They don't have controls that prevent the sharing of information. It's much more like a capitalist market than it is security or information control. And they take advantage of the bureaucracy and regulation of large organizations. So they're just nimble and we're the big giant. And it becomes, it very rapidly becomes a David versus Goliath situation.

[00:10:05] And we all know how that turned out. Yeah, 100%. And at Bionalyze, you focus heavily on investigation and response automation. And as we continue to see attacks accelerate and we're hearing more and more stories of security teams facing burnout, how important is automation in reducing dwell time and alert fatigue and actually helping analysts focus on the signals that really matter? I think it's mission critical. I don't think. It is mission critical.

[00:10:34] And automation, you know, it's a buzzword. But, you know, there's some things in there that really don't get surfaced as much as they need to. Number one, generally, if it's automated, it's a deterministic process. That means it's repeatable and can be made more reliable if it's not reliable enough. Second is, you know, we're not out there replacing EDRs and SEMS. The problem is, is the EDRs, the SEMS, and these other security tooling, if they'll detect things, sometimes they stop things.

[00:11:02] Sometimes attackers are circumventing those, those controls in some cases, but they give you the investigative lead. And then there's a much longer thread to pull on. And it's difficult to get access to that direct evidence or those forensic artifacts. And that's what we support. You get a lead, you, you, you effectively click a button. We can collect all the evidence. We analyze a good, a good portion of it. And we make it much, we close the timeframe from the moment you see something to the moment you're actually looking at the direct evidence there. So that, that, that's already closing the gap.

[00:11:30] And of course we can, you know, from a technical perspective, our product integrates with other things, but to close that gap. Really the thing is you get that first alert, you get the direct evidence, and then the analyst can do something with it, with context. And you, you know, we've been talking for a long time that that context needs to go from days to hours. And now, frankly, it needs to go from hours to minutes. So this is, this is what the new security tech stack is going to have to look like going forward.

[00:11:57] And we have gone 15 minutes in a tech podcast without mentioning AI, which has got to broker a few records there. But we need to bring it up because we are seeing more and more AI-assisted attacks, the rise of deepfake social engineering, and increasingly autonomous threat activity. So do you think the current security operating model is fundamentally capable of handling what's coming next? Or, or does the industry still need a complete rethink?

[00:12:24] We've, we've focused on a few areas where there is that rethink, that mindset shift is needed to change. Do you think it needs to change here too? I do. I don't know if I would say it's a rethink. It's definitely maturing from, call it version 2.0 to 3.0, something along those lines. And it comes back down to that crisis framework, you know, inevitably in a crisis, the most technical things or tactical things are unpredictable.

[00:12:48] So at a higher level, you need a way to manage resources, make resource requests, figure out who's going to make a decision, things along those lines. We've done an okay job in the industry with tabletop exercises, but now, and it finally is getting more surfaced as less of a technical problem and more of a business impact issue.

[00:13:04] So in these tabletop exercises, in these crisis management plans, we're seeing engagement from executives from other business units, the board of directors, folks are starting to engage outside parties ahead of time, instead of just like waiting to press, you know, waiting to call the emergency line for an incident response consultant later down the road. So we're in the process of that shift happening.

[00:13:28] AI makes it a little bit worse or a little bit, makes the situation worse and the impact more important to manage because the rate of attacks are higher. And I don't think, in my opinion, AI doesn't make attackers more sophisticated. It lowers the barrier of entry for other attackers. And that's the problem to solve today. Of course, with Mythos, I could also argue very easily that attacks are becoming more sophisticated. I will say one more thing.

[00:13:56] Mythos is not what scares me. Right now, it's cost prohibitive for most of the attackers out there. And it's very tightly controlled with the Glasswing program. But two years from now, when there is another version of Mythos that's affordable or locally hosted and publicly available and is not regulated or not controlled access, that's the thing that keeps me up at night right now. And this is what we're striving to build towards and what the industry needs to prepare for. It's not Mythos.

[00:14:25] It's what comes next. Yeah, that is such a powerful point. And if I were able to grant you one wish or maybe manifest something positive out there, if you could change one thing about the culture of cybersecurity and what it is now and what we can change tomorrow, whether it's information sharing, breach disclosure, collaboration, leadership accountability or something completely different, what would have the biggest impact on improving collective defenses around the world?

[00:14:55] Sure. You know, I think we need to start taking a proactive approach to this. Yeah. This is where I like the fire analogy or the firefighting analogy more than I like or emergency services analogy more than I like aviation. So historically, we treated cybersecurity as a perimeter issue, firewalls, things along those lines. And then we started treating it like an onion, but still very much from a prevention rather than proactive state. And now we're very much in a when something bad happens, we want to be able to react faster.

[00:15:24] But there's a piece in the middle. And if you think about it from a firefighting or emergency services perspective, not enough folks are doing those intermediate fire inspections of their own environments to determine if there are latent risks of fire or arson. Second is, you know, emergency services, the firefighters, the ambulances that are out there on patrol. These are the eyes and the ears of the fire department for when those structure fires do occur. And the thing that we need to keep in mind in cyber is, yeah, we could relate these to structure fires.

[00:15:54] But there's an active arsonist all the time setting fires to, you know, other organizations in our community. So having that patrol element where you have, you know, those pseudo eyes and ears from those first responders out, there's mission critical. You never know when the attacker is going to find some new way in or develop some new technique to set fire to your building.

[00:16:15] So having those eyes and ears out there constantly patrolling, not just sitting in the 911 center waiting for the call to come in, not just looking at the fire alarm waiting for a green light to turn red. It's going out there and actively checking the doors, doing those types of things. This is mission critical. That's the one thing that needs to change. Love it. And we have talked a lot today about threats, what keeps you up at night and what needs to change, et cetera. But to end on a positive note, what makes you optimistic about the future? There's enough doom and gloom on our news feeds right now.

[00:16:46] What excites you or makes you optimistic about the future? The thing that makes me optimistic is people are taking, it's no longer like, oh gosh, you know, it's no longer a bunch of nerds in a closet or whatever in your parents' basement anymore that's doing these things. It's being addressed in a first-class way by nations, by governments, by we're getting budget and cybersecurity. And we're talking about it in podcasts like this one. So the fact that there's an active narrative, we all want to get better. That's the thing. It's a team effort.

[00:17:15] It's a community effort. And that's the thing that really warms my heart and what keeps me sticking around for 20 years. I love it. What a great moment to end on. And for anyone listening wanting to find out more information about anything we talked about today, find out more of the announcements that are coming out at Binalize this year, how they can help, how they can get involved, et cetera. Where would you like me to point, everyone? Yeah. Please visit us at www.binalize.com. Awesome. I'll add a link to that as well as your social channels, including your LinkedIn.

[00:17:45] I would encourage everyone listening, if you take anything away from this today, is the importance of collaboration and keeping these conversations going. So keep a lookout for those links. But more than anything, thank you, Lee, for starting this conversation today. Thank you as well. I love Lee's comparison between cybersecurity and firefighting. Because for years, organizations have focused heavily on prevention. They've been building walls, adding layers, waiting for alarms to trigger.

[00:18:13] But as attacks become faster, more automated and increasingly AI-assisted, that reactive mindset is simply no longer enough. And Lee made a compelling case today for something much more proactive. Constant inspection, stronger collaboration, better incident learning and faster access to real-time evidence, especially when something goes wrong. And when the world is lowering the barrier to entry for attackers,

[00:18:43] and they're all collaborating together, this kind of urgency is only going to increase. But this isn't all doom and gloom. Despite the threats, there's also optimism in this conversation. Cybersecurity is no longer trusted as a niche technical issue hidden in the basement. Governments, businesses, boards and entire industries are finally beginning to pay attention.

[00:19:09] And perhaps that shared awareness is the first step towards building a stronger collective defense and doing it together. That's my takeaway from this episode. But over to you. Techtalksnetwork.com. Send me a DM, voice message. Whatever is the easiest for you. I'd love to hear from you. But that's it for today. So thank you for listening as always. And I'll speak with you tomorrow. Bye for now.