As cyber adversaries evolve from fragmented groups into highly coordinated, professional operations, the rules of engagement are changing. Enterprises are no longer targeted based solely on who they are, but on who they are connected to. Patricia Titus, Field Chief Information Security Officer at Abnormal AI, talks through how a shift toward identity, behaviour and context-driven security is crucial in a landscape where attackers are already inside.

We are seeing state-aligned actors shift from fragmented hacktivism to highly coordinated, unified structures. How does this ‘professionalisation’ of regional conflict change the threat model for a standard enterprise that isn’t a direct target?
I don’t think anybody is out of scope. Most enterprises will be thinking I’m not a bank, I’m not a defence contractor, I’m not a target. However, that logic is so antiquated today because to be collateral damage, you just have to be in the path of it – part of the supply chain, shared infrastructure, trusted partner or even just a customer.
Hactivists are inside your environment quietly, not kicking the door down loudly like it’s been in the past. What we’re seeing now is more disciplined, centralised tasking and shared tooling. Threat models need to stop being built around what you are; and start being built around who you are connected to.
If an adversary’s attack infrastructure is pre-positioned globally and independent of their home country’s connectivity, how can defenders move beyond simple geographic blocking to stay ahead?
If you’re using geo-blocking as your primary defence, you’re essentially locking the front door, but leaving the back door wide open. Attribution by geography is already a bit of a relic, despite only starting out five years ago. These actors operate through their own infrastructure in our own regions and on our own platforms. Blocking a Russian IP range does nothing when the traffic is coming from Frankfurt.
We have to shift our mindset and start thinking about how traffic is behaving and where it is coming from. For example, anomalous authentication patterns, unusual access sequences and lateral movement that doesn’t match a human work pattern. We need to be profiling the behaviour of the session, not the flag on the packet.
Social engineering is a ‘long game’. Since technical controls can’t easily flag a legitimate-looking conversation, how do we effectively harden the human element against such patience?
Technical controls are brilliant at spotting malicious attachments. But unfortunately, they’re useless at spotting the friendly colleague who’s been building trust for three weeks on LinkedIn before sending a link.
People can’t defend against a threat that they don’t know exists. The threats today are advanced, highly scripted and highly targeted types of communications. Therefore, we have to educate them on these methods. This is where behaviour analysis is so important. If we don’t understand what’s normal behaviour in our environments, it’s very difficult to determine what’s abnormal.
We’ve been under investing in human detection capabilities. Employees are trained once a year and we call it a programme. It’s not a programme, it’s a check box. Your culture is the biggest vulnerability. You need to build a culture where you’re not seen as paranoid if you ask a question. We’ve done a great job of scaring our employees to a point where they’re too afraid to click on anything and too embarrassed to ask any questions, which means they’re paralysed.
We are seeing a trend where initial espionage access is handed off to separate groups for total environment wiping. Why is it now a critical error to treat a ‘minor’ phishing alert as anything less than a precursor to a total outage?
The kill chain has been institutionalised, which is not something we’ve seen previously. You now have one group that specialises in getting access and a completely separate group that specialises in burning everything down.
Phishing alerts used to mean someone clicked on something they shouldn’t have, and we rebooted their machine. Now, it might mean someone has established a beachhead that has access, and that access gets sold in about 48 hours. Every initial access event is a potential scene setter for something catastrophic. We have to stop measuring severity by current damage and start measuring it by potential trajectory. The fire alarm matters even before the building is on fire.
Standard MFA is clearly failing against real-time proxy kits. What is the most pragmatic architectural shift an organisation can make today to neutralise these session-hijacking techniques?
In the 90s, VPNs were the saviour, then standard MFA was the silver bullet for all of us until it wasn’t. Now, phishing resistant MFA, for example with passkeys, is the immediate answer. These break the proxy model because the credential is cryptographically bound to a legitimate origin.
But let’s be honest, most organisations can’t rip and replace their existing security structure overnight. So in the interim, layer on session level controls – short lived tokens, device binding and continuous reauthentication.
The deeper architecture shift is Zero Trust – as a genuine operating model, not a marketing aside. Assume the session is compromised and verify continuously, not just at login. A lot of us would love it if we could just log in once a day. However, we’ve moved to cloud and we’ve moved to SaaS. These are environments where you need to reauthenticate those sessions.
If there was one thing every organisation should do this week, it would be to audit what you’re protecting and get it off SMS. That is the lowest hanging, highest gross fruit in most environments. If you’re using SMS texting, that is going to be your downfall.
When attackers rotate domains every few minutes, legacy blacklists are useless. How does your behavioural AI distinguish a sophisticated, ‘never-seen-before’ domain from a legitimate business email?
Email blacklists are fundamentally reactive. By the time the domain makes it onto a list, the campaign is already over. The challenge with Artificial Intelligence is that it moves so quickly. We’re fighting yesterday’s threats with yesterday’s tools. This is where our behavioural AI model comes into play.
Behavioural AI doesn’t ask, “have I seen this domain before?” It asks, “does everything about this communication make sense in context?” It looks at the history, relationship, urgency, time of day and even the sentiment of the communication. If I’m in regular communication with someone who always starts their emails with ‘Hey Patti’, and one day it starts with ‘Good morning, Patricia’ – that’s suspicious.
Of course, humans can see some of these things in real time, however AI can operationalise it at scale. Our goal is shrinking your window of exposure from hours to seconds and getting the alert to the right person fast enough to matter. We want your SOC analysts to be looking at what’s really important – not all the noise. The noise is what can be operationalised by our AI.
Looking ahead, do you expect these actors to use Generative AI to automate the high-trust social engineering that currently requires manual effort?
It’s already happening. The capabilities that exist today are a result of attackers utilising AI. Messages are personalised, contextualised, have flawless grammar and are generated at huge scale.
The volume alone changes the economics of the attack. They’re no longer sending out email blasts, spray and pray, hoping someone will bite. They are able to send very narrowly curated information about you and make that fit the attack. A skilled social engineer can run maybe a handful of these high-quality long game operations simultaneously. With automation, that number becomes hundreds.
The defensive implication is that we can’t just rely on spotting poor grammar or dodgy domains anymore. We have to focus on the request, the context and the channel. Organisations that get ahead of this are the ones investing in AI assisted defences now, not waiting until it’s too late. Humans cannot move fast enough to defend against the speed of AI attacks.


