What if criminals were discussing, selling, or preparing access to your company before anything appeared on your security dashboard?
In this episode of Business of Cybersecurity, I speak with Lewis Henderson, Director of Intelligence Communications at KELA, about the criminal economy operating beyond the corporate network. We discuss how cyber threat intelligence can reveal attacker intent earlier, giving security teams time to respond before stolen access becomes a full breach.
KELA’s State of Cybercrime 2026 research identified 2.86 billion stolen credentials in a single year. Lewis explains why that volume makes exposure a question of probability for many large organizations. He also describes how cybercrime as a service has lowered the technical barrier for attackers. Businesses may now face hundreds of lower-skilled criminals using purchased tools, credentials, and AI assistance instead of a small number of highly experienced groups.
One example begins with an employee downloading a video game containing infostealer malware. A single stolen credential reportedly provided access to 300,000 cash registers. KELA discovered the access being discussed in a criminal market, showing why monitoring attacker activity outside the network can provide warning that internal tools may miss.
We also examine alert fatigue, the limitations of point-in-time risk assessments, how criminals are experimenting with AI, and why boards should ask security leaders about threats forming across suppliers, cloud services, and the wider internet.
Are companies investing enough in understanding attacker intent, or are too many waiting for the threat to arrive at their front door? Listen to the conversation and share your thoughts with me.

