Finding Attacker Intent Before the Breach With KELA
The Business of CybersecurityAugust 15, 2026
40
00:35:2032.36 MB

Finding Attacker Intent Before the Breach With KELA

What if criminals were discussing, selling, or preparing access to your company before anything appeared on your security dashboard?

In this episode of Business of Cybersecurity, I speak with Lewis Henderson, Director of Intelligence Communications at KELA, about the criminal economy operating beyond the corporate network. We discuss how cyber threat intelligence can reveal attacker intent earlier, giving security teams time to respond before stolen access becomes a full breach.

KELA’s State of Cybercrime 2026 research identified 2.86 billion stolen credentials in a single year. Lewis explains why that volume makes exposure a question of probability for many large organizations. He also describes how cybercrime as a service has lowered the technical barrier for attackers. Businesses may now face hundreds of lower-skilled criminals using purchased tools, credentials, and AI assistance instead of a small number of highly experienced groups.

One example begins with an employee downloading a video game containing infostealer malware. A single stolen credential reportedly provided access to 300,000 cash registers. KELA discovered the access being discussed in a criminal market, showing why monitoring attacker activity outside the network can provide warning that internal tools may miss.

We also examine alert fatigue, the limitations of point-in-time risk assessments, how criminals are experimenting with AI, and why boards should ask security leaders about threats forming across suppliers, cloud services, and the wider internet.

Are companies investing enough in understanding attacker intent, or are too many waiting for the threat to arrive at their front door? Listen to the conversation and share your thoughts with me.

Useful Links

[00:00:00] The leading issue of agentic AI in businesses right now is ensuring agents act with compliance guidelines. And Denodo applies guardrails across your entire data estate. By aligning your company's data infrastructure under one system, these guardrails perform consistently across your platform. So start scaling your business and start with Denodo. Simply visit denodo.com to learn more.

[00:00:33] What if your organisation's biggest cyber security threat isn't sitting inside your network, but being traded on the dark web long before an attack ever begins? Well, cyber criminals have built a thriving underground economy. One where stolen credentials, malware and attack services are brought and sold every single day. Well, in this episode, Lewis Henderson, Director of Intelligence Communications at KELA,

[00:01:02] is going to join me today to explain what security leaders can learn by looking beyond their own perimeter. And also learn more about why understanding attacker behaviour has become a business advantage, not just a security concern. So let me officially introduce you to him right now. So thank you for joining me on the show today, Lewis. Can you tell everyone listening a little about who you are and what you do?

[00:01:29] Yeah, so myself, I think I could call myself a veteran these days of cyber security. So I've been in the industry for over 26 years now. I work for predominantly based in the UK, but work for international companies across the US, across APAC and across EMEA during that time. And I would say my focus and my emphasis has been at the sharp end of the spear in terms of innovation.

[00:01:53] So bringing new and novel things to the market so that organisations can try and get ahead of cyber threats. So that's where I've sort of positioned myself over the last decade or couple of decades now, I should say. And now I found myself working for KELA. And so we've got a reputation that's been going for about 10 years or so now, you know,

[00:02:19] providing cyber threat intelligence to governments around the world, law enforcement agencies and large sort of private enterprises. So, yeah, that's our sort of daily routine as a cyber threat intelligence provider. So we've got to be, you know, trusted, we've got to be accurate and we've got to be reliable in those environments. So look forward to sort of discussing how we go about doing that. Yeah, it is incredibly cool work you're doing there and important work.

[00:02:48] And for people hearing about KELA for the first time, you monitor criminal underground at scale. You track dark web forums, botnet logs, closed channels, darknet markets to surface attacker intent before it reaches enterprise systems. And you've got some pretty powerful research to back up some of your work as well. And before you join me on the podcast today, I was reading that your latest research found that 2.86 billion credentials

[00:03:16] were stolen in a single year, which is a breathtaking stat. But for any business leader or anyone hearing that kind of statistic, it can sound incredibly overwhelming there. What does it actually mean in practical terms? Why should they assume that some of those credentials will belong to their organisation or people within their organisation? Yeah, it's a good point. And you also mentioned some quite scary sounding things as well, like info stealers and stuff like that.

[00:03:42] So, yeah, I think what we're really good at is we're very good at our expert researchers, our expert analysts are extremely competent in infiltration. So, that method, we get into the criminal underground. And I think you'll see this theme sort of repeating. I think for business leaders, the best way that we can help them understand everything is, you know, no matter how much you think you're profit driven, that you're business driven,

[00:04:11] that you're innovative, that you have supply chains, there's a criminal underground that operates sort of very, very similarly. So, when we talk about, you know, the volumes of stolen credentials being at nearly 3 billion, you know, these numbers are completely intimidating, right? The huge, huge scale. So, now we're in this realm of like statistical probability. So, I think we've got around 20% or around three quarters of those credentials

[00:04:37] were for systems that basically help a business operation. So, see that as like cloud platforms. And we know that cloud is, you know, almost like, you know, cloud first, you know, business operations is pretty much standard these days. So, we see things like cloud platforms, email systems, identity logins. Basically, you know, it's the statistical probability that if you're a private enterprise

[00:05:05] and you are international and you're probably within the Fortune 2000s, that you will have credentials of some scale within this sort of data set. And that's purely because of the size, scope and scale of nearly 3 billion credentials being out there. You're likely to find, you know, to the tune of like three quarters of them being business related. You know, you're likely to find credentials in that group there.

[00:05:35] Many organisations are people listening in organisations today. When they hear something like the dark web, it feels like something they only need to worry about after an incident. But we are moving away from that thought process now. And from your unique vantage point here, how has threat intelligence evolved from just an investigative tool into something that can actually proactively reduce business risk? Yeah, it's a good point.

[00:06:01] So, I talked to lots of people on both sides of the camp in terms of their, you know, because we have front of house very much like the practitioners who are applying, you know, the strategy and day-to-day and then business leaders CISOs. And yeah, the way that CTIs sort of evolved a bit is that a lot of the CISOs, certainly the more innovative ones, they've got great working relationships with the board. So, and it's become more of a collaboration.

[00:06:29] So, they see, again, a CISO who's in that frame of mind, who's much more of like a business leader, will use CTI as a business advantage. And the way that they do that is by moving their lens to earlier in the attacker cycle. So, now we have to explain like why is that an advantage? So, if you've got cyber threat intelligence that's informing you earlier in the attacker cycle

[00:06:58] of their intent to do something, for example, it's going to help you shore up defences. It's going to help you spot a risk, you know, way over the horizon, even before the attacker has started building infrastructure or coordinating their efforts to be able to target you as an organisation. So, the way that a CISO with, you know, using that type of cyber threat intelligence can then go to the board and say, look, we're getting much earlier visibility in the attack cycle

[00:07:27] of these attacks that are heading in our direction. So, they've got to have this message of we've got the risk covered, you know, we can see it coming over the horizon, we know how to manage it more effectively and it helps us plan and prepare defences much earlier in advance. And certainly, you know, the customers of ours and the customers of other organisations that help them achieve this type of pre-emptive capability.

[00:07:57] And you'll see us come out with a maturity model that kind of sort of speaks to this. But the earlier you can get in the attack cycle, the more confident you can then become at making business decisions. So, boards that want to, say, for example, go on a merger and acquisition trail or they want to, you know, create a new market in a new geographical region, for example, if they do that in lockstep with a CISO that's got cyber threat intelligence

[00:08:22] that's allowing them to make these decisions and understand the risk and then manage that risk, they can now exploit that business opportunity with confidence. And that's really what it's all about. So, I think that's why we've seen cyber threat intelligence go from something's happened, let's investigate, to, you know, feeding into the business to say, look, we want to go in this direction. How much of a risk is that? What, you know, what threat actors are, you know, impacting that? Can we, do we need to invest?

[00:08:52] Do we need to, you know, partner? It helps make so many more business decisions, but ultimately the CISO can support the business more effectively and allow them to go and profit from those businesses' decisions at the board level. And I'm curious, as someone that spends every day monitoring criminal communities, what changes in attacker behaviour have surprised you most over the past year? What does it tell us about what defenders should be focusing their efforts on? What have you seen?

[00:09:20] Because you probably feel like you've seen it all throughout your career, but anything surprise you still? Yeah, I think I probably come back to one of my earlier points, because this was about, you know, no matter what you think of yourselves as a business and how you operate, the criminal underground is now geared up to operate as a, you know, as a service. So, you know, and put any word in front of that, you've got like malware as a service, but the one in particular that's concerning for us,

[00:09:49] and we see this is crime, cyber crime as a service. So what this means for defenders is that, you know, traditionally and historically you may have had, so let's take like financial services, for example, you would have had some very, very, you know, expert adversaries, you know, these threat actors that focus almost exclusively on financial services.

[00:10:14] They've built ecosystems which look exactly like supply chains. So at the start of that ecosystem, you've got someone developing malware. You've now got someone processing, you know, the fraudulent and the fraudulently obtained finances and cash and transferring that into Bitcoin. So you have an entire ecosystem that's now designed and geared to lower the bar to entry.

[00:10:39] So traditionally you've gone from tracking like a few expert threat actors to where we are today. And of course, you know, it wouldn't be a podcast about cyber without mentioning artificial intelligence, obviously. So, but the way that AI is, it's an enabler for this whole underground economy. So it's being used to develop tools to, you know, to do everything from like voice phishing.

[00:11:08] So, you know, impersonating someone's voice and obtaining information. So their craft of, you know, getting information out of people and infiltrating certain environments. I mean, AI is being used as a tool to accelerate that whole process. But what it's really doing is, is changing you from having to face like a handful of expert threat actors and adversaries that you knew how to track.

[00:11:33] You typically know these groups to now you could be facing hundreds of lower skilled, but they've still got the intent. They've still got the motivation. So now you have a volume problem. And that's, that's the dynamic is completely changed. So that's, that's probably the single thing that surprised us is, is how quickly that's happened over the last 12 months.

[00:11:54] So this whole concept of like cyber crime as a service has increased the volume of threat actors and just made it so much easier for criminals to be able to extort money and, and, and, and yeah, grow their own sort of personal finances. And credentials are also increasingly being stolen through info, stealer malware rather than those traditional phishing campaigns that we've seen over the years. So why has that become such a successful business model for cyber criminals?

[00:12:22] And again, from anybody listening here inside an organization that are taking this stuff more seriously, what can they do to realistically reduce their exposure to these kinds of tools? Yeah. Yeah. So I'll, I'll, I'll come onto the reduction, but I think, I think why it works as a cyber crime business model, because I think we can use that language these days. Yeah. Um, so infasteelers are, are, are good for the, the, the cyber criminals because basically it's cheap.

[00:12:50] So, and when I say cheap, that's another motivation for the cyber criminal, right? Just like you want to maximize profits. They want a lower cost. So infasteelers are cheap to operate, cheap to obtain, cheap to run. Um, and from a, um, a defender's perspective, they're really difficult because they can almost completely silent. So you've got this like scalable problem. You've got criminals that like them because they're cheap. Um, and they can, they, they, they, they can remain undetected, but they're, they're highly

[00:13:19] effective at getting full credentials off that machine. That's the entire purpose of that as well. Um, and coming onto the, like the, the, the counter, um, is that the, the problem is one of the methods is, is a multifactorial authentication. And that's an extremely strong step in the right direction, but it's not as simple these days as like turn on multifactorial authentication.

[00:13:43] So we're shifting from, you know, the identity being more related back to the actual machine and back to the actual sort of device itself. So there's, so we aren't in that business. What we can say is we can spot these patterns where the cyber criminals are finding their way around the traditional multifactorial authentication. So very much like the guidance is, is go back to your multifactorial authentication provider, um, do some research on how the criminals are avoiding that.

[00:14:12] And again, we, we, we've written research on that. We've written blogs on like how they're doing it, but, but, but the real practical advice is go back to your sort of providers with, with this information saying, look, you know, these cyber criminals are bypassing, you know, some of these traditional controls that we have. What do you have to help us around that as well? Um, because we, as a cyber threat intelligence provider, our role is to provide the evidence to provide something that's sort of actionable around that in terms of making that next decision about the threat actor or your adversary or defenses.

[00:14:42] Um, but yes, always go back to your provider and see what, what innovations they have. And a topic I must bring up on behalf of every security team is alert fatigue because so many teams out there, they're drowning in alerts, intelligence feeds, yet another dashboard, et cetera. So how can they distinguish between interesting threat intelligence and intelligence that actually helps them actually make better decisions, business decisions at that too? Yeah, definitely. I mean, you've hit the raw nerve.

[00:15:11] I think, I think of some senior leaders out there. It's an interesting concept. So, so a traditional SOC team, you know, security operation center or cyber threat intelligence team. To give you some idea that about 70 to 80% of the alerts that they're getting, that they then have to make a decision on about 70 to 80% of them are false positives. So what we mean by that is false flag.

[00:15:39] So they've had an alert for something they have to investigate. That's going to take time out of their day. They've got multiple screens to sort of, and can you imagine if you're the, you know, if you apply those statistics to the rest of your workforce, you'd be in a whole manner of problem like as an organization. So, so alert fatigue is genuinely one of the most mentally impactful things for a SOC team because it's, it's actually really frustrating for them because they, they want to defend,

[00:16:07] they want to do a good job for their company. That's why they're there. They love what they do. But the data that they're being fed from these various other sort of feeds, and there are hundreds of feeds out there that will have various different types of data in it. But can you imagine if like, you know, every decision you had to make 70% of the time, it was, it was incorrect or it just completely wasted your time. So it's very frustrating. Why that happens is that there are, I mean, one, the most extreme example I can think of

[00:16:36] one organization I came across had over 70 individual threat intelligence feeds coming into their, into their unit. So you've got loads of overlap, you've got loads of duplication, they've got loads of complexities. That's like problem number one. And the, and the other problem is a lot of these other providers will, will aggregate data that they haven't verified and they haven't validated. So that's another problem. And the other bit is not many of these insights are actually based on observations.

[00:17:04] Um, and that's probably where I think we distinguish the type of threat intelligence that Keller are providing is actually based on observations. So there's nothing sort of bought in and aggregated. I think that's the distinction like, um, and, and, and liken it to like how law enforcement works, right? So they can't really start and complete an investigation without providing, you know, some sort of evidence. That's, that's what powers that. So it's a very similar sort of thing where how do we distinguish between good cyber threat

[00:17:33] intelligence and suboptimal cyber threat intelligence is that when you make a decision using it, how often is that right? How often is it the right, you know, right direction? How often isn't it validated? Um, so I think, I think we can say that's, that's very much, you know, how, how someone would then assess, you know, good, good cyber threat intelligence from, from suboptimal is the, is the types of decisions that you're making. How good was that decision and did it lead to that outcome?

[00:18:02] Did it lead to a possible outcome? And then without all the effort. So I think that's, and that's another really important point. Um, and what makes it interesting for a novel is that does it apply to your organization? Does it apply to your customers? Does it apply to your supply chain? So it goes from being something that's, that's interesting could be, okay, this, this bank has been, you know, attacked, for example, et cetera, et cetera.

[00:18:29] Um, whereas actually if you're a nuclear power station, that's largely irrelevant. It could be an interesting story, but the context is completely mismatched. So that's why I think evidence-based cyber threat intelligence is really starting to get noticed. And the other thing is that how that's then measured is the context it brings to those decisions. So is it, is it relevant? Does it drive an action? Um, and, and what is the outcome of doing the action?

[00:18:56] I think these are really, really important things that, that, that the leaders need to be mindful of when they're, when they're listening either, you know, from a CISO upwards for to the board or board down to the CISO. I think these are really interesting things to talk around. Um, and, uh, yeah, cause it, again, it is, it is all about the outcome. It can be interesting, but does it drive an outcome? Um, and just to bring to life the value in having a, a more proactive approach to cyber security than a reactive one.

[00:19:24] Are you able to share an example where early visibility into activity, into a criminal underground, maybe enabled an organization to prevent a much larger attack? You don't have to name any names here, but anything that would just bring to life what happened and what lessons others might listening might be able to take from it. Yeah. I think, um, I mean, Oh God, off the top of my head, right. We've got so many examples that we, we're not sure of them, but I think the one there's

[00:19:51] one that stands out for me because it's quite, it's quite memorable by the fact that, and it starts with an employee downloading a video game. Yeah. And as an action that on the surface seems quite innocent, right? So, so, you know, everyone has a break time. Everyone needs something to do. Um, so obviously someone's downloaded something, their motivation could have been boredom, right? So they, they, they downloaded this video game and without realizing it, there was an

[00:20:19] info stealer that had been written into that program. So again, I think this really speaks to one of today's problems, which is, you know, issues in the supply chain, a risk across the supply chain. Um, and, uh, yeah, so this, this info stealer was in, in this, um, in this video game that had been downloaded by an employee. And all it did was save one, one credential.

[00:20:43] So this info stealer stole one credential and what that led to, because this person is someone, and in this, the other interesting thing is this wasn't targeted. It was completely like accidental, but obviously this, this individual that downloaded the video game that had the info stealer was in the, um, operations department for their entire global, um, cash register footprint.

[00:21:09] So this is a, a global, um, you know, this is a fortune 500 like fashion retailer, for example, that also owns all of their own infrastructure. So this one, one stolen credential gave access to 300,000 cash registers. Um, and I think that really speaks to the problem around like info sealers, like complete, you know, embedded in something that looked quite innocent.

[00:21:32] Um, you know, did its job of stealing a credential, but the impact of that, um, was access to these cash registers, which we all know are completely digital now. Um, and the, what, the way that we detected that was we found the discussions in the underground market, in the cybercrime market, for example. So it shows that we're not in the business of, of detecting, for example, like an info stealer deployment.

[00:21:57] We're in the business of surfacing when an attacker is about to, you know, either exploit your details or sell your details or exploit your credentials. So we found the discussion that related to this, someone was selling access. Um, and I think that again, speaks to another big problem where the attackers have sort of shifted to, to, to, they're not trying to hack in. They're now just buying access and logging in. So they're also simplifying this entire process.

[00:22:25] Um, but yeah, one login, um, was for sale with access to 300,000 cash registers. Um, so while it's not a bank, you know, while it's not, you know, at the nuclear power end of the, you know, situation. But I think, I think the story is about, you know, one video game led. It, uh, led to all of this and it went through completely undetected until we saw it being discussed on, on the, you know, within the underground economy where all these discussions start.

[00:22:52] So, so very much like picking up at the, in the, at the intense stage was, was key to that. Um, and I don't think we've got the final financial, um, figure in terms of, you know, this is, this is what this could have cost them. Um, but as you can imagine with an organization like that, you're running into, you know, tens, if not hundreds of millions of dollars that in, in cost avoidance, just because of that one incident. Um. Wow. That is incredible.

[00:23:20] And we have done, uh, incredibly well also to get 25 minutes into a cyber security podcast without mentioning AI, but we have to go there, I'm afraid. Of course. AI is changing almost every aspect of cyber security. So how are criminal groups using AI today in ways that security leaders could be underestimating? And where do you think the headlines are going, uh, uh, going to get ahead of reality? What do you see happening here? Yeah, I think, I think we're in a bit of unreality.

[00:23:48] I think this is why, again, we've, we've got to be really sensible about this. So AI, ultimately AI is a tool. Yeah. Um, and what it is enabling is of course, you know, like us in private sector and on the security, it's allowing us to go faster, build faster, you know, be faster, like all of those great things. And I think we need to be a bit sensible when we see headlines, like 70 to 80% of, um, of

[00:24:15] an attack being fully autonomous and fully AI driven sort of thing. If you then start to pick in the details, cause there's a headline that, that sounds like pretty scary, but actually that's a nation state level threat actor. And if you actually start to break the attack apart a little bit is that that wasn't fully autonomous in terms of they, they, they asked it to do a thing and then it came back and then the human had to intervene and then ask it to do another thing.

[00:24:43] I'm not saying what it is because obviously we have to be careful about, you know, sharing AI techniques and things like that. Um, and so I think, yeah, when we see headlines like this, I think it's really like being sensible and going like, what does that actually mean? What's, what's behind that headline? What's that sort of story? Um, but I think I referred to earlier where the, we've seen an uplift, um, from a few tens of mentions of AI, um, in the chat forums.

[00:25:11] And when I say chat forums, these are things like the, this is how criminals are communicating with each other. Um, so we've seen, you know, the, the, the mentions increase in the hundreds, if not like thousands of percent from comparing last year to this year. And it could be anything from, you know, someone recommending using AI to improve an email, for example, and using it for language, which is the very, very simple end of the spectrum.

[00:25:37] But we're seeing everything like, um, you know, here, here is a set of prompts that we'll, will be really good at interacting with the CEO's agentic AI that he's got plugged into his calendar. And these prompts are designed to act, to interact with that agentic AI to get information out. So there's a whole cyber crime economy that's going to be growing around, you know, you know, what are the, what are the best prompts that you could, you can use?

[00:26:06] How do you instruct AI to build malicious, um, you know, malware, for example, or malicious instructions, um, all the way through to, you know, the more complex end, which is, you know, the jailbroken AI and instructions around that as well. So I think just like us on the, in the private sector, on the security side, however, we think we're being innovative and novel, there are no restrictions in the, in the criminal undergrounds, for example, you know, we have, you saw what happened with, um, Anthropic this

[00:26:35] year where they tentatively, you know, opened up access to a limited audience and then almost like immediately shut it out again. So that's because, you know, safety prevails, common sense prevails, and their motivations are more related to that. Whereas in the criminal underground, they have none of that. Their motivation is money. Their motivation is something completely different. It's disruption. Um, so they don't have the same, um, guidelines and, and regulations and compliance, and also

[00:27:04] quite frankly, morals. So that we will definitely see a whole nother set of innovations over the next sort of 12 months, as we've seen in the last 12 months, um, which are just helping them go faster, be faster, be more efficient, um, all the things that we can attach to AI, but obviously from a, from a malicious perspective. And if you can try and imagine that today we could be sitting down with a global list

[00:27:30] of board directors listening to a every world or listening to our every word scattered around the world right now, and rather than a techie or a CISO, they are a global leader. What would you want them to understand and walk away from our conversation today about cyber risks that maybe they don't fully appreciate or aware of at the moment? What would that message be? And I think the thing is, it's, it's looking far beyond your, your borders.

[00:27:56] So, so, and we have to give merit to the security teams that are in place today. Certainly the ones in the, I speak to typically in the, you know, global two thousands, they're really good. Like they're really good at that. They're within their walls, right? They know where everything is. It's it. They know how to secure it. They know how to lock it down. So I think, I think boards today can have a high degree of confidence in how competent their teams are from their internal infrastructure.

[00:28:21] But the problem is once you now start to look at, explore like where are threats coming from, where are risks coming from? It's, it's all over the horizon. It's all out there across the internet. So supply chains, you know, victims of, of cyber attacks, where your infrastructure is that you can't really put your finger on. So where it's in, in public cloud, as opposed to private cloud, which is under sort of lockdown.

[00:28:48] So I think, you know, really that, that the message to boards is now that the exposure and the risks are outside your walls and therefore outside your control. So what does that mean? Is that, that you now have to engage with your, your CISO to really say, you know, how do we, how do we now look far beyond our borders? You know, how, how good are we at understanding our, our entire landscape external to organization?

[00:29:16] How good are we at assessing risks to do with that? And I think moving that needle from a traditional risk assessment being a point in time. And this is a really important point because there's regulation in Europe, like EU DORA, there is NIST 2 that doesn't apply to like all organizations, but you can see directionally, this is what they're trying to do is they're trying to emphasize, you know, organizations now need to be proactive looking beyond their borders.

[00:29:45] You know, it's all about this like external exposure risk and external exposure to threats. So, and it's, and it shouldn't be seen as something extremely scary, right? So I think that's the other important thing is having a really good sensible conversation with, with security leaders like CISO, for example, on the board to say, you know, how good are we at our external exposure? How good are we at understanding threats earlier in the attack cycle and have this goal of, of

[00:30:14] attacker intent? You know, really, you know, do we know when someone wants to start to attack us? You know, how do we move the needle in that direction? Um, and you know, just being compliant for, you know, for example, a bank in Europe to EU DORA, having extremely good defense will, will, you know, and, and just that will get you fined because you're missing some of these capabilities, which now legally mandate you to be proactively hunting for these risks beyond your borders.

[00:30:44] So why am I saying this as, as, you know, as the advice is that in many, um, in many markets, um, geographic markets is that, is the, the regulation and the legislation is moving to understanding what's beyond your borders and your, your landscape and then proactively monitoring that. And then the other really important thing is continuously monitoring as well. So unlike, uh, a typical sort of risk audit that I think most of the leadership will be

[00:31:12] familiar with, these are what's called point in time. So I'll, I'll, the physical example is literally something, someone turning up with a clipboard, you know, writing stuff down and giving it a tick box and here's your report and stuff like that. And the problem is if you use that method in the cyber landscape, it's out of date within minutes. So these things are very fluid. They're very, uh, you know, dynamically sort of changing all the time as well.

[00:31:39] So boards really need to be sort of, you know, um, asking of their security teams and their security leadership, you know, what are we doing that's beyond our borders? What are we doing to discover risks, discover threats, um, in that domain? And how early in the attack cycle are we detecting someone who wants to attack us as an organization, um, and, and get very, very specific. Hopefully that's using the plainest language I can use how we would go about that.

[00:32:08] So much to take away and think about having listened to you today. And for anyone interested in going a little bit deeper, maybe look at that state of cybercrime at 2026 research report, connect with you or your team, just look into the work that you're doing there. Where would you like me to point everyone listening? Yeah. So Keller, uh, the Keller website, so K E L A. So the, um, so if you'd search on Google Keller and then state of cybercrime, um, that's the easy, hopefully the most memorable thing to do.

[00:32:37] So, so what we've done there is we've created a set of materials because admittedly the report is very dense, right? So we we've, you know, we've done 55 pages of very dense research on some key topics. Um, but they, they're all prefaced with, with executive summaries. So the entry point into that report is, is very friendly from an executive perspective. Um, and our, our intent there is to write them. So they're accessible, you know, lower the bar.

[00:33:06] Um, and, and, and especially, you know, as, as I would say, part of my role is like science communicator to, to leadership. So we write these so they can be easily understood and actionable within a couple of pages. So search for state of cybercrime record report with Keller, um, that'll give you the easy digest at the beginning. And then we encourage you to then forward that down into your organization to various security teams that will, that will benefit from it and also hopefully be positively impacted.

[00:33:35] Well, you've took us on quite a journey today from beginning there with that powerful stat, 2.86 billion credentials stolen last year and documenting how cybercriminals have been using them to that something simple example of just downloading a video game and the aftermath of that. So I will add links to everything that you mentioned. I'd urge people listening to go check those out, but more than anything, thank you for starting this conversation today. Really appreciate your time. Thank you. Appreciate it.

[00:34:02] I think today's conversation offered a fascinating look behind the curtain of the cybercriminal underground and highlighted a few uncomfortable realities. Attackers are becoming more organized, more efficient and better informed, which essentially means defenders need to think beyond traditional security tools. And Lewis shared today why understanding attacker intent can better help organizations move from

[00:34:29] just reacting to incidents to anticipating them before they even happen. But I'd love to hear your thoughts. Are businesses doing enough to understand the threats that are forming beyond their own networks? Or are too still many just waiting until an attack reaches their front door? What are you going to do differently? Or what are you doing differently? Let me know. TechTalksNetwork.com will keep this conversation going. And I'll also be back tomorrow with another one.

[00:34:59] Hopefully, I will speak with you all then. Don't be late. Bye for now. Bye for now. Bye for now.