ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Get smart - How top CISOs are leveraging the dark web to gather pre-attack intelligence

teissTalk host Jenny Radcliffe was joined by Gareth Owenson, Co-founder and CTO, Searchlight; Ben Muldoon, Senior Cyber Security Investigator, STORM Guidance; Matt Gregory, Head of Security Operations, Penguin Random House UK; and JB Benjamin, CEO/Founder, Kryotech Ltd.

 

Views on news

 

An offensive mindset is key to ensuring the best cyber defence. To ensure success, there are three main components for organizations to consider when developing a defensive strategy based on an offensive cyber model: re-envisioning recruitment, thinking like a hacker, and promoting offensive training in tangent with defensive training.

 

Traditionally, cyber has been about defence, but you need to see your network and external footprint from the hacker’s point of view. Pen testers have a close to 100 per cent success rate if they combine hacking techniques with social engineering or stolen credentials. Although there is some progress, the hacker’s mindset is still completely missing from the SME sector.

 

Pre-attack intelligence

 

Cyber defence has been focusing on antivirus stopping malware on your network, firewalls and intrusion detection systems, where the hacker is already at your door or has already penetrated your network.

 

Meanwhile, threat intelligence is looking out for threats on the forums the so-called underground economy, where criminals exchange malware or stolen credentials before they approach your network.

 

It’s also important to receive intelligence from your own sector or be aware of what attacks are happening in your country.

 

For publishers, the dark web can also provide information about titles and authors that may become the targets of cyber-attacks. But knowing how they are likely to get to you is also key. The Dark Web is a very specialised space, and you need a lot of insider knowledge to collect intelligence there. Therefore, companies either outsource it to specialists or set up their own teams of analysts.

 

As a marketplace, it’s full of valuable, as well as worthless information, so you need to deploy AI to separate the two from each other. On average, analysts see credentials into a business’s network being sold on the Dark Web 6-8 weeks before the company has a ransomware attack.

 

When talking to the C-suite and the board about monitoring the dark web, security professionals need to take the scary elements out of the narrative. There is a criminal industry called access brokers, who are making money as affiliates of ransomware groups and sell vulnerabilities and backdoors to networks. With the increased use of edge computing and processing, threat vectors keep changing. BYOD practices have also expanded the threat surface considerably. Users tend to think that if they plug their device into a Microsoft endpoint, everything will be fine – which is not the case. Meanwhile, the EU is pushing a greenlight system for software products – not unlike the traffic light system we have for food – where developers are mandated to declare a list of potential issues.

 

The panel’s advice

 

Although frameworks aren’t a panacea, they are a good way to start building your cyber defences. 

 

Although it’s impossible to know exactly what a future cyber attack will be like, the knowledge of adversary TTPs (tactics, techniques and procedures) is a rather effective method of detecting malicious activity.

 

Watch it on-demand here


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543