teissTalk host Jenny Radcliffe was joined by Gareth Owenson, Co-founder and CTO, Searchlight; Ben Muldoon, Senior Cyber Security Investigator, STORM Guidance; Matt Gregory, Head of Security Operations, Penguin Random House UK; and JB Benjamin, CEO/Founder, Kryotech Ltd.
Views on news
An offensive mindset is key to ensuring the best cyber defence. To ensure success, there are three main components for organizations to consider when developing a defensive strategy based on an offensive cyber model: re-envisioning recruitment, thinking like a hacker, and promoting offensive training in tangent with defensive training.
Traditionally, cyber has been about defence, but you need to see your network and external footprint from the hacker’s point of view. Pen testers have a close to 100 per cent success rate if they combine hacking techniques with social engineering or stolen credentials. Although there is some progress, the hacker’s mindset is still completely missing from the SME sector.
Pre-attack intelligence
Cyber defence has been focusing on antivirus stopping malware on your network, firewalls and intrusion detection systems, where the hacker is already at your door or has already penetrated your network.
Meanwhile, threat intelligence is looking out for threats on the forums the so-called underground economy, where criminals exchange malware or stolen credentials before they approach your network.
It’s also important to receive intelligence from your own sector or be aware of what attacks are happening in your country.
For publishers, the dark web can also provide information about titles and authors that may become the targets of cyber-attacks. But knowing how they are likely to get to you is also key. The Dark Web is a very specialised space, and you need a lot of insider knowledge to collect intelligence there. Therefore, companies either outsource it to specialists or set up their own teams of analysts.
As a marketplace, it’s full of valuable, as well as worthless information, so you need to deploy AI to separate the two from each other. On average, analysts see credentials into a business’s network being sold on the Dark Web 6-8 weeks before the company has a ransomware attack.
When talking to the C-suite and the board about monitoring the dark web, security professionals need to take the scary elements out of the narrative. There is a criminal industry called access brokers, who are making money as affiliates of ransomware groups and sell vulnerabilities and backdoors to networks. With the increased use of edge computing and processing, threat vectors keep changing. BYOD practices have also expanded the threat surface considerably. Users tend to think that if they plug their device into a Microsoft endpoint, everything will be fine – which is not the case. Meanwhile, the EU is pushing a greenlight system for software products – not unlike the traffic light system we have for food – where developers are mandated to declare a list of potential issues.
The panel’s advice
Although frameworks aren’t a panacea, they are a good way to start building your cyber defences.
Although it’s impossible to know exactly what a future cyber attack will be like, the knowledge of adversary TTPs (tactics, techniques and procedures) is a rather effective method of detecting malicious activity.
Watch it on-demand here.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543