Martin Hinton (00:00) This is the Cyber Insurance News and Information Podcast. I'm Martin Hinton Executive Editor. Every week we talk to the underwriters, brokers, and security leaders shaping the market. Martin Hinton (00:11) All right then. Welcome to the Cyber Insurance News and Information Podcast. I'm the executive editor and your host today, Martin Hitten. Our guest today is Matthew Butler, Director of Cyber Risk Services at Traveler's Insurance. Matthew, thanks so much for joining us. How's your day going so far? Matthew Butler (00:24) It's going good. It's a nice sunny day outside, can't complain. It's nice and cool. Martin Hinton (00:30) Outstanding, outstanding. So Travelers out with its new Q two twenty twenty six cyber threat report. Gimme the headline. What surprised you most? what was in it that you you maybe didn't expect or, you know, you were happy to not be surprised by? Matthew Butler (00:44) Well Something that surprised me was that the Gentleman Ransomware group posted about 248 victims in Q2. And this is a lot. Like this feels like a lot. It's second most next to Qilin and this group kind of came out of nowhere in 2025. Granted, they could be and most likely are a spin-off of another group, which is why they're so advanced, why they've risen so quickly. It shows that anyone with the right connections could just come into play and cause major disruption depend on what tactics, techniques, and procedures they use. use, but nonetheless, a year time, they're number the number two on our list. Pretty scary. Pretty surprising actually. Martin Hinton (01:24) Is that unprecedented? Is that y you think that's something that that can be explained that that they were you I mean, you touched on one explanation. Is there a a a a a reincarnation or a a rebranding of an of another group with a baseline knowledge and apparatus already? But what do you think? Matthew Butler (01:41) Yeah. Well, starting from nothing is few and far between right now. Like there's a lot of groups that either get disbanded or they get their their infrastructure gets seized and they and the threat actors disappear and create their own brand and they have experience. Like any unfortunately professional, like professional team, professional company, they know what to do. They know they have defined tactics, patterns, they can they know how to run the business per se in their in their space. So if it takes a new group to create a new threat actor threat actor team or comp company, It allows them to spin up really quickly. They have they have they would already have established connections. They could establ quickly establish reputation from previous patterns of success, things like that. So it's I would say it's difficult but it's still impressive that they did it so quickly. Martin Hinton (02:41) I mean, w the w what you're I mean, it's sometimes you feel like I feel like I repeat this to people both on the podcast and in communications for other reporting and even in my social life, which makes me about the most interesting person at a dinner party, is the idea that these groups are not fly by night. These are highly organized, sophisticated organizations that should be treated as such. I mean, these are I mean, there's a whole line in in sort of conflict that you should never underestimate an adversary. And this is evidence that That that is truer than ever, don't you think? Matthew Butler (03:13) Absolutely. It's these th actor groups are highly organized. They they treat themselves as though they're companies, they still have the same goal of most for profit organizations. They wanna make a profit, they wanna generate income. it's terrifying. Martin Hinton (03:28) Yeah, I I'm you know, so the Q one report described a new baseline and elevated ransomware activity. I I'm I I feel like I'm hearing you say that Q two kind of confirms that or is it comp is it complicated or w what what do you in looking at the Q one report and Q two, where do you see trends and and what's changed from one quarter to the next? Matthew Butler (03:49) Well, for the past three quarters now, we've seen over two thousand, two thousand victims posted on a rand on leak sites. We're seeing that although there is a slight drop from last quarter, it was it wasn't a lot. We see this as more of a meaning, may it's it's creating a new baseline. activity is still up fifty-three percent from the same quarter last year, and we could see even next quarter the same the same baseline. So it could indicate that things are becoming easier for threat actors or they have really good tactics, they have really good procedures to easily or routinely gather information or up obtain exfiltrate information of their victims. Martin Hinton (04:41) You mentioned leak sites posting measure vic claimed victims not confirmed compromises. What's the error bar on this data and what does it systemically miss? Matthew Butler (04:51) Well, it depends. There is an unknown delta between actual victims and those posted on ransomware leak sites, and it varies depending on the threat actor group. Some of them, they'll post victim victim organization names for a time. Maybe they say, we have your data, it's posted out there. and they're trying to extort them. They're trying to s they're trying to spin up some fear. this is where we pick up on the data. We have dark web monitoring that looks for policy holders on these on these leak sites so we can know and we end up we end up notifying them. but other others may not post their victim organizations initially. They may wait, they may evaluate or look into the data that they've exfiltrated. They may want to see the they may want to see the Validity validity of the data they they compromise. They may want to ensure that the company is worth doing something more malicious to like insult like insult on ransomware, making a ransom. Like again, it's a business. It needs to be worth their while and worth their time to to to fully install malware or to perform malicious actions on them. Martin Hinton (06:06) I mean, yeah, so I mean, again, k keeping that idea that these are sophisticated groups in mind, I mean, that's like market research or you know, I mean to put it in a sort of cyber warfare context, that's reconnaissance, right? I mean, the idea that you would you would gather information about the in their case, the the target that you're interested in in taking advantage of and and ransomwareing that is that what we're talking about? Matthew Butler (06:31) Yeah, like you want do your research, like there is there's depending on what vari variant of like ransomware or how your how organization actors are compromising organizations, it may just be send out like go after it and see what see if it sticks and then go and then determine if the company is viable after that, or it may be their or it may be like specific targeting of an organization. So it really depends on what they're looking at at that time. but like from from our own Martin Hinton (07:02) Mm-hmm. Matthew Butler (07:03) claims data, we know that not rant not all ransomware victims get listed on a leak site. It really depends on the threat actor. Martin Hinton (07:12) And for for a ransomware I you know, I again we didn't discuss this prior, so if this is outside your area of sort of comfort or or expertise, please say so. Being met if you're the victim and you're listed on these sites, does that exacerbate the concern you might have in the future? Does it make you a a more likely victim in the future? It just I know that it may seem obvious to me, but I I I don't get paid to assume, I get paid to ask the question. So is the what is the co the consequence of being listed for a for an entity that that that's found on on one of these, you know, dark websites. Matthew Butler (07:46) I can't say much, but it it is impactful to a company's reputation. Martin Hinton (07:50) Yeah. No, that's okay. No, that that th that's a perfectly good answer. That that makes sense. You you touched on this sort of the fragmentation of this, the the idea that, you know, there were twenty group twenty of these ransomware groups go dark and then nineteen appear in a single quarter. And I know we sort of touched on this the it's impossible to know whether these are new criminals or the same people rebranding, right? That one of the things that we s I read a lot is that it's attribution is quite difficult about who who's responsible, barring there being someone who makes a claim. But when you see that sort of pattern of activity as you sort described in the Q2 report, is there is there any way to know whether or not it's you know, again, the the a a new Coke versus a a a a totally new beverage? Matthew Butler (08:34) Well, it's a mix of both. given that these criminal groups are seeking well, most threat act like the individuals within the threat actor groups, they mask their real identities. You don't know who is who, you don't know an actual person's name. It's difficult to track individual operators. But what we can be what can be tracked are groups, TTPs, tactics, techniques, and procedures. It's it's how you operate, it's like why A company or a person is successful, they go through the same tech same techniques and procedures each time because it leads to success. that pro that provides clues as to whether a new group has formed or rebranded, and also the speed at which a new group enters the scene and begins posting victims. this suggests how organized they they are. Like going back to the gentleman group, they came on really fast, like multiple courts online indicate that they are most likely linked to a another more established ransomware group that either rebranded, re rebranded or they're they're they're spin-off, maybe they were an affiliate of a ransomware as a service group, but they clearly have defined TTPs, which is why they've been so successful. for example, like like let's say we see a ransomware group, a new an let's say we see a new group mirroring a similar exploits. Let's say it's always through a VPN v a vul vulnerability in VPN. It's the number one way that getting in this group does it the same exact way as another group, and ransomware software is deployed and they have similar re reaction times afterwards. It could be the same group, could be a spin-off of the group because they've seen success in group A and bringing it to group B may could also lead to success. Martin Hinton (10:23) I mean I mean w y what you're describing there, and I I I think I mentioned in in some of our planning for this podcast that you know, I've been a journalist a long time, and only in the cyber insurance and cybersecurity area for a couple of years now, a little more than a couple. But you're describing, you know, you don't need to know the identity of a person to recognize their MO, right? That's the phrase you might hear on law and order. Is is that to to maybe the audience is not on the sort of, you know, cyber side of this, is that way to think about it that that criminals have patterns of behavior like all people and you can recognize those patterns and you might think, that's something, you know, that's the signature of so and so. I I feel like I'm on SVU right now, but but it in trying to make this a little more you know accessible for the less technical audience, is that the idea that you can see, you know, patterns of behavior that repeat over time. And even if the group is called, you know, Frank One Day and Gentleman the next, there'll be telltales within their, you know, the the way they conduct themselves that that give away who they might really be or you know, not literally, but but who who's behind them. the act. Matthew Butler (11:25) Exactly. Humans are creatures of habit. They do what works and by human nature we don't like failure. So if they if there's a small deviation that happens one time and they go back to what works, it's it's human nature to be to be as semi pr human nature be semi predictable. They wanna make sure that like yeah. Martin Hinton (11:50) Yeah. Well, I I'm just gonna say I gonna say, you I mean, I like l l I mean, this is for this is more for me to say than you to react to, but but that idea that we we as as human beings, we do things the way we did them yesterday. We're not huge fans of change. And if something worked yesterday, the the the reluctance to change that today is limited. And if if if it if it ain't broke, don't fix it. I mean, our language is littered with phrases that illustrate this fact about how we conduct ourselves and stripping away the sort of mystery and majesty of the ones and zero world that makes this, you know, box of sand work is is something that I I like to do from time to time to help people understand that this isn't as, you know, distant or complex as you might think. And and the the so that was very that's very helpful for you to just say it that way. I mean maybe I'm oversimplifying it, you know, please tell me if I am. Matthew Butler (12:42) No, I think another good example is the return to office push that many organizations had a few years ago. So I am a huge creature of habit. We don't have assigned seats at Travelers where I work. But I sit in the same seat every single day and I feel as though I'm most effective at my job when I sit in that seat. There are times when someone comes in earlier than me, not often, but it does happen, and I'm displaced. I have to go sit somewhere else. And I don't feel as though I'm in the right headspace. It I I can work, it's just different. And I think the actors on humans would operate the same way. Like if it's not what's proven the work that's been successful, you kind of deviate away from doing it. Unless you absolutely have to. Martin Hinton (13:26) Matt Matthew, I thought that was gonna tell me that's the morning you always spill your hot cup of coffee on someone so that they have to get up from your desk. but I I appreciate your your more diplomatic approach. clearly you and I are not cut from the same cloth. You Matthew Butler (13:36) Ha ha. Martin Hinton (13:37) you I mean you touch on something that's a you know, again, I I keep saying this, but just to re reiterate my understanding is that y I've done I spent about six years doing military history documentaries and some of those were contemporary. So we would be in the field with, say, US Army Special Forces. And one of my big takeaways is that they would drill into you that routine is deadly. You never walk the same way back. And it's a it's a it's actually a a creed within the the the US Army ranger training that goes back to the Revolutionary War where if you go out from your base, you never come back to your base on the same path, right? That idea that if you create something predictable, then you create vulnerability. And that is where you you you know can have and this all comes back to the idea that we are creatures of habit and that we We we reveal ourselves in the way we behave more than what we say about what we do. so that that that's that's quite an interesting sort of, you know, s aside for for this that that you know, the cause the human part of this is is very important, isn't it? 'Cause it all matters for us. So I I I want to move on. That Kieran Martin, who founded the UK's National Cyber Center and others, argue takedowns have become sort of a whack-a-mole thing. Does your data support that or is it is is disruption still working? Matthew Butler (14:51) Yeah, so it is often a game of whack-a-mole between law enforcement and threat actors. but they are no less important. Like takedowns are takedowns do help disrupt threat actors for a time. And sometimes it gives th law enforcement greater insight into the group's TTPs and the victims they go after. this is particularly the case in if a group's infrastructure is taken down, it ceases operations, it pauses things, but because the th the actual individuals are anonymous or they can't be found, there are no arrests, the odds that the group is going to rebrand are higher. And our numbers actually demonstrate this. So in terms of whack a mole, yes, like there's a small disruption. but if the if the individuals aren't found, rebranding odds higher. And with ransomware being up year over year, even though law enforcement activity has persisted, if not grown, because of how high profile some of these some of these incidents are. it suggests that there are there is short term impact. although the law enforcement has been successful in arresting cyber threat actors from time to time and it has an impact in taking some criminals out of play it could it could influence a different set of individuals to not take as much risk or take less not take as much risk or take more risk. Like if we think of Scattered Spider, I think they were gonna dis they law enforcement started making arrests last year, with the most recent one being a couple months ago, but they were individuals from Fl individuals. They were significant they were younger individuals from Florida, from from Spain, from the UK, from Finland. Like it's we the industry saw a lot of disruption. Well a lot of incidents from scalloped spider and that disruption is definitely helpful, but like the gentleman group, other other groups can just can fragment, spin off and create new risks, new threats. Martin Hinton (17:00) I I mean i yeah, I again I mean we we I I I don't wanna belabor this point, but you're talking about, you know, if five people start a company in the year two thousand and it's a huge success and they take it public and by two thousand eight they all sp spin off and they take their proceeds from that success and they go start their own company somewhere else. It's it's you know, it it's a it's a business, a criminal business for sure, but but but it it it operates with very much the same sort of considerations and and and goals in a in a way that you know I think some people underestimate. E even people who would pretend or supposedly be sophisticated. You you you mentioned reputation. Groups with no reputation to protect have less incentive to hand over a decryption key. Are you seeing promise keeping decline? Matthew Butler (17:50) No, not not really. So if we think about these groups operating as a business, their goal, yeah their goal in many cases, they want to get paid. They they want to build a reputation, they want to maintain a reputation, they want to become more profitable. It's a business for them and income is is their motivation. So if they don't provide working decryption keys, and this isn't to say pay the ransom, like advisors still don't pay the ransom, but not providing working decryption keys if ransom is paid and not keeping your promise, although there is no honor among thieves, not keeping your promise doesn't help that group succeed. It doesn't help that group be can become more notable in the threat actor scene. So it's it's not advantageous for them to betray the trust of of a victim. Martin Hinton (18:42) Yeah, I mean, again, it it makes complete sense, right? I mean, it you you I mean the the one of the things I remember learning early on when I started doing this is the habit of, you know, getting inside a company, finding their cyber insurance policy, and then finding out what they're covered for for say ransomware and knowing what your, you know, your max payout could be that wouldn't just, you know, upset the Apple cart with regard to what they can get from an insurer. And I and I I think that what you touch on again is another point that r drives it this home. You know, they they deliver on the promise for the cost of the product. And that that that makes it all sound very legitimate, which it isn't. but it is a a matter of of great importance that people understand that these organizations are you know, designed to execute a deal and then move on to the next deal, not not get hung up and you know, have a have a thing where they've got a rebrand so people don't realize it's that place that doesn't give you your you know your encryption key back and that kind of thing. So again, I I I'm not surprised to hear that, but I mean, is there any more to say about that that you think that that's important for people? Matthew Butler (19:44) I just had a thought in my head and it immediately left. I Martin Hinton (19:49) you know what? You and I you and I would get along well because that's my specialty. I had a brilliant idea a minute ago and now it's gone. Well, I mean I I I I I one of the things that we we we we we want to talk about is is AI. Have you heard of it? This thing that's come along, these frontier AI models. i is that on your radar at all, Matthew? Matthew Butler (20:04) Who who hasn't at at this point? Like I on our team, we've developed an AI AI risk assessment service for all of our policyholders because questions around AI have grown exponentially in the past two years from when the Chat GPT was released, Cloud was released, well, Anthropic released Claude, and companies seeing employees just starting to use it. They want to use it. No one wants to feel like they're behind the curve. So we created this assess this service, an advisory service for all of our policyholders where we'll talk them through like best practices, how to implement it securely, how to reduce risk with AI with their organization. So I've heard a lot about AI. We we've done a lot of AI research in the past couple of years. Martin Hinton (20:53) So the report uses mythos as as a shorthand for a frontier model risk. be precise for me, is travelers saying criminals now have mythos class capability or is this a forecast? Matthew Butler (21:05) This is a forecast. this is yeah, this is it's definitely a forecast, although there are other models like such a such as OpenAI Soul that are starting to perform well on cyber benchmarks, it's fair to say that open source models won't be that far off. like our goal with this report is to focus on organizations on hardening against AI enhanced attacks now while the defenders still have some edge. like if we think about or we we look at models like existing models. we've seen significant advancements in those open source models after time, after more training is done, after more research is done. And as AI is getting more powerful reasoning is becoming significantly stronger. And that's the advancements that we're seeing. So if if Base models now can begin to reason more, perform better actions before p have better automations and how they how they operate. it won't be far off before capabilities become frontier grade. Like I what is it? I think the current clo anthropic sonnet clawed sonnet release, they say is very similar to the original opus release in terms of reason and power back in twenty twenty four. So the speed at which development happens is is rapid. Like even like the vi the image and video generation is getting very Martin Hinton (22:28) Yeah, I I mean I I you know, I I I Matthew Butler (22:30) good. Martin Hinton (22:32) Yeah, I mean I think that that that part of it, again, back to human beings and change, the pace of advancement, which is another word for change, is is something that in some respects it's kind of impossible for me to comprehend that, you know, the first time I used ChatGPT was only a few years ago. And what it could do now that it couldn't do then is remarkable, both as a product that you pay for and also from a more broad sort of, I guess, philosophical point of view. and you look at other You know, devices in history that maybe are similar to to AI. I mean, the the one I always think about is the automobile, which obviously started without things like airbags and anti-lock brakes or even windshield wipers and stuff like that. And those things took decades to be added on. But you look at maybe a more apt comparison might be the steam engine and the energy that that provided, the fuel, the sort of advancements and growth of the economy during the industrial age. It took centuries for some of the improvements that made that adaptable to certain industries and that that sort of thing. And and the fact that that's not that doesn't seem to be happening here is is is remarkable. So it I mean it is really I you know there's a there's a joke about kids you bl don't blink because you go away for like a week and you're you know your one year old suddenly looks you know completely different when you come back a few days later. And it is absolutely that kind of feeling I have where, you know, you the new model comes out and and You know, barring there being a a a a hiccup with it, if you will, which I think has happened with a couple of them, it is, you know, if it can't do something now, it's gonna be working on a way to figure it out. And that's that's something to keep in mind. myth mythos is restricted to a small partner group. I is the dangerous capability is locked if the dangerous capability is locked up, what's the actual mechanism by which it reaches the criminal ecosystem in your in in your analysis? Matthew Butler (24:22) So I wouldn't say mythos. I would say frontier level mythos capability. It's as threat actors well well not through actors, but Martin Hinton (24:30) So so so let's let me ask the question again. The f the frontier model is sort of the, you know, if you will, the sort of the the cutting edge model is restricted to a small group, right? Th these are not generally out there. T talk to me about how that reaches a criminal e ecosystem and and the that the the way you see that. Matthew Butler (24:47) Well, it's a there are multiple just groups that have open source large language models. They can be enhanced, they can be customized, and there's just advancement behind those models. So if you if you have a goalpost that you can see like if you understand that Mythos or Soul can do XYZ and you kind of understand the mechanism of like how to get there, like what you may need. Maybe it's more compute power, maybe it's more information more it needs to learn more information. It needs like we need to increase reasoning capability or agenda capability. building that if you have a goalpost you're gonna want to figure out how to get there. It's like it's like all like all the vehicle manufacturers now. I bring up cars. I love cars. but like you see like you see advancement in one area. Like we saw Tesla have really good autopilot. not like autopilot let's say assisted driving driver assistance. It's fantastic. and we saw companies fighting to develop similar capabilities for driver AIDS and now it's one of the top selling points on a lot of vehicles. People don't want to sit in traffic. People don't want to hold the wheel like in the center of the lane. They want to have adaptive cruise control for easier trips. Like if you set a goal post, people people are going to want to get there. And I'm I'm not saying all models have the goal, like all like open source publicly available models have the goal to be mythos class. Like they want to customize it to different to different use cases for efficiency or for like a that that are that are purpose built. But like it's still a goalpost people want to hit. Martin Hinton (26:37) Yeah. Matthew Butler (26:38) Yeah. Martin Hinton (26:38) I mean, one of the things about you know, y one of your comments earlier made me think about how I spoken to a few people recently in the ransomware and the incident response space and the idea that they realized quickly that they were negotiating with an AI. And I I don't know if you mentioned earlier in this conversation, but I think you had in the prior communication that these attackers do not sleep, they do not eat. Is that showing up in the claims data yet or is that still a thesis? Or you know, I you hear a lot in the the Threat space, particularly with people, you know, out there with a product to sell. And I I guess I'm curious what your the what that your data shows. Matthew Butler (27:14) Yeah, so we are starting to see confirmed use of AI by threat actors and and one example is the use of AI chatbots during ransom negotiation, which threat actors deploy to speed up negotiation process. this increases pressure on the victim and allows less time to fully assess the impact of an incident. Again, like time is money. we've also we've also observed threat actors by and large use AI To locate and review data for exfiltration, like like we previously talked about here, like researching it, making sure it's valid. Like instead of hunting through, like looking for specific, specific or high value information, you could have an AI do it, or you could have you could have an AI tool analyze that kind of data. by and large, the use of AI by threat actors mirrors how we all you are currently using AI. It's automate it's the automation of tasks, but not fully Like if we think A like generative generative AI or AI now can make current tasks more efficient. Like if I trust to do seventy percent of the work, I still need to put in thirty percent of that to get to get it home. And we're seeing threat actors do the same exact thing. Martin Hinton (28:28) I mean, i is it sorry, go ahead, finish your so finish your thought. Matthew Butler (28:30) no, no, go ahead. Martin Hinton (28:32) Well, I was gonna say what you I I mean if if I if you could bear with me while I maybe so give you a s sort of a a s a scenario, is would that be like if you got into a a network or a company's, you know, system, if you will, whatever the right term and word is, and you were looking for valuable documents that you might take. You might you might look for, you know, all the iterations of a an ongoing contract negotiation, including the one that had just been agreed on, and then take all of those so that you can You know, it's almost like precision warfare, whereas, you know, if you go to World War Two and we're dropping bombs and hitting a whole city, now we're putting bombs in windows, if you will. Is is that sort of the the the sort of simplified way, or is that too simple a way to think about how AI's creating this sort of ability to target precise high value material and data within a company's networks? Matthew Butler (29:20) I think it depends on what you're looking for. So I'd look at it from what to do, well what a threat to what a threat actor will do once they're in your environment and then what will they do if if and when they exfiltrate from your environment. Like traditional organizations and many organizations have similar naming conventions, file structures, fi hierarchies, Again, humans are creatures of habit. We do a lot of things that we've done for a long time. But the nuances of different organizations could be could be vast. It may be a traditional like file store system. It could be stored in like on the cloud. So from when you're in if a if an if there's an automation that goes in and looks for that kind of data, if that exists, it would have to really zone in on what to look for. And that that may be an area where a human is a human with more like reason and experience could evaluate a system when they're inside of it. It may be less automated. Whereas once a data's been exfiltrated, like let once a data's been exfiltrated, you may you may submit it to a a model to analyze that data once it's out. Because running something Running something Martin Hinton (30:35) Gone. Matthew Butler (30:36) inside an environment could be significantly more like taxing on infrastructure that could raise more red flags. Martin Hinton (30:44) So so not unlike if you were to put fifty commandos into occupied France during World War Two, that's more likely to be detected by the enemy than say a plane flying over it or Matthew Butler (30:53) Yeah. Martin Hinton (30:54) or or someone taken out of the the area. The the the human element, right? Wha one of the things that we we we just touched on and I think you said and I reiterated was that AI's gotten a lot of people's attention. Obviously these frontier AI sort of models breaking their sandbox and all these other things that the people have been reading about. You touched on the the way that's sort of become a conversation that that that's occurring with with policy holders. But half of your claims, cyber claims trace back to a person, not a firewall. Why does the industry spend so much time of its attention on the other half? You know, I mean peop people still make the the mistakes. There's they're still matter to the attacker and and they still create problems on the defender side and the the company side. Matthew Butler (31:35) Yeah. So I will talk about that, but I want to tie that human element back to the frontier model risk and just talk about like what we've been telling organizations Martin Hinton (31:42) Please. Matthew Butler (31:43) about how to prepare for that level of risk. we've we've put an article out there, but I'll go over some of it here. companies need to be ready. We need companies need to be ready. They need to act faster, but overall we're we're pushing companies to do what we've been that that have been best practice for years. And one of those things is to accelerate patch management. if you think about these frontier models or these like more advanced reasoning models that can act more agentically, that can di given a task where it's like assessing assessing the environment, assess source code, understand how it works and determine and discover or exploit vulnerabilities from that. Like you wanna make sure that if the manufacturer has released a patch, you wanna make sure it's patched. You can no longer well, you should no lo like a company should no longer take like low and medium vulnerabilities as tech debt. They just exist. Like we need like companies need to focus on what they can do to to patch debt additionally, like it's really important to deploy some sort of managed detection and response capabilities depending on the size of the company. Or bring in a twenty four by seven, thirty sixty five kibbulli to your cyber teams. Like their actors are operate all across time zones. And if the AI doesn't sleep, doesn't need to eat, it can run all the time. So if you have someone who can respond to alerts or react faster or live, it could significantly lessen the impact for an organization. and I think we'll talk more about this in a little bit, but it's really important to harden authentication, have fishing resistance MFA. I think your your episode two episodes ago talked about MFA, and that a great episode. Highly encourage anyone else listening. If you haven't Martin Hinton (33:36) Point. Matthew Butler (33:37) listened to it, listen to it. great feedback from those two. But really focus on fishing resistant MFA, harden it, make it better, make sure that no one like there's no unused credentials. really focus on backups, and then now we'll we're seeing a little bit more of this testing incident response plans with tabletop exercises, going over. AI scenarios, thinking about like, okay, what if we see something at night? What if we think it's it's it's automated? What if we think we're engaging with a threat actor who's using a bot to communicate with us? What do we do? And those are all really important things to consider when protecting against it. Go ahead, you're breaking up a little bit. Martin Hinton (34:08) Yeah. I'm I mean you you you touch on a a a a a reality that that yeah. you you you touch on a a a reality that that in the real world, if you have a an office in midtown Manhattan or if you have a warehouse, it would be silly if you turned off your security cameras at night or on the weekends or you y you didn't lock the door all the time or you know, in in midtown Manhattan the there's a guard at the door 24 hours a day. You don't just have them there when people are working nine to five. And that that mindset moving into the digital space, again, as a as an outsider and as a layman, it it it's it's it, you know, we've put all these things we value into digital spaces and we've taken this great, you know, advantage of the frictionless reality of being able to move documents. And I'm old enough that I, you know, used to fax things and mail envelopes to to communicate with people as a function of work. And none of that's necessary anymore. And that means things happen much, much faster. which is creates vulnerability. But this idea from the security point of view that, you know, constant monitoring, that's a twenty four seven security system. You've got that in the physical world for your warehouse where you keep your products. Why wouldn't you do that for the place where you keep all of the, you know, vital communications or documents or contracts or whatever it might be, on your in your digital space. And and I, you know, I again I y you've said this already. I just it it just comes to me that That's how I think about it. I don't know if that's again, is that a silly way to think about it? You you're the expert. Matthew Butler (35:39) No, it's not. It's how I talk to a lot of CISOs, and that's what I see from a lot of successful CISOs chief information security officers. is they are really good at translating technical risk into dollar signs for their ex executive teams. You have to you have to see you have to like business leaders like they wanna make money, like like most successful businesses. They wanna make they wanna be profitable, they wanna make money. If you understand the risk as a dollar sign and you quantify it, it's much easier to sell them the solution of we need a t we need twenty four seven we need twenty four by seven staff, we need we need to hire a an outsourced stock, we need somebody looking at our environment all the time. Because if you do that when it's too late, it could make or break a company. like for a lot of small like for lot of I think we talk about this too, but for a lot of smaller companies, like one cyber incident could make or break them. If it's if they're if they're if the organization is fully based on is fully based on trust and relationships. Well, if a person believes they the company they trusted weren't wasn't doing their due diligence and due care to protect their data, they may not trust them anymore. They it may be it may be the breaking point for the organization. I we see a lot of companies that wait until an incident actually occurs to get to get twenty four by seven monitor in and it's one of our our like my team's recommendations Martin Hinton (37:08) Yeah. Matthew Butler (37:09) like do it beforehand like how can like once something I pose to these CISOs to organizations who want the extra step I I ask them how can I help you show your board the importance of these cyber controls? Like how do we make it valuable? Like what they like the data's out there. Martin Hinton (37:24) Yeah. Well, I mean, I I I made I made reference to the the the language is replete, right? Right. You close it before. You know, that that that that that idea. So we sort of started to touch on the human element and one of the things that that that we had shared in advance was that the idea that we could c go through the anatomy of a of a business email compromise claim, a BEC claim. So How does that work start to finish and and and what are the dollar figures associated with with that that sort of attack? And so maybe start by explaining what what is a a business email compromise. Matthew Butler (38:03) Yeah, so a business email compromise is when somebody it's a type type of social engineering where A company's trusted email account is either compromised or it's spoofed or it's impersonated. So I'm gonna take an example from the Internet Crime Compliance Centers, the Run by the FBI, report back in 2025. So think about You're buying a house. Like buying a house is a major milestone for a lot of individuals, especially in my generation. I think I'm 33. like people say buying a house is not possible. well, it's very difficult and it's exciting and it's there's a lot of emotions going into it. So a couple buys a couple goes to buy a house. It's say half a million dollars. the house is half a million dollars, and you go through multiple stages of closing that house. You make the offer to the seller, you have the sell you have the seller's bank, you have your bank, you have you have attorneys on both sides, real estate agents on both sides, like there's a lot of parties involved. So it's a it's a pretty stressful time. So during that purchase during the purchase, the the couple in this scenario, they received an email from who they thought was who they thought was their attorney, stating Hey, go like here's the account number the account number and the writing number for the the seller's bank. Send them the information. send them send them the send them the information, not send them the funds. let's say half a million dollars. And the point is that Well, sorry, hold on, let me let me reevaluate this in my head. So that attorney was not their actual attorney, right? Like so in the example, the att the buyer's attorney was impersonated by another by a by a threat actor with an illegitimate email spoof. not like the real attorney's account. This could be to this could be from like an actual compromise at the attorney, that gathered information, but The event the individuals who were buying the house thought that the email was legitimate. believing that they were the instructions were legitimate, the buyers then execute a bank wire. They submit almost half a million dollars to be sent over to the recipient bank, and then that fraud is gonna surface somewhere, whether you're bringing it up with your attorney, with your real estate agent, or the buyer seller, no one someone is missing something. the victims then report it to the bank, or you should report it to the to your to your own bank. and the attorney and and Both team both sides attorneys tried to reach the recipient bank directly. after that fraud was discovered, but the individuals reported who reported the fraud, they were not able to get any results. the recipient bank, which was the bank of the threat actor didn't say anything, and direct victim to bank outreach didn't work. so what had pushed things along was they filed with the IC three, the FBI. That moved the needle. Upon receiving that complaint, the the about the incident, the recovery asset team from the FBI from IC3 immediately initiated the financial fraud kill chain, which is their process to request a freeze on the fraudulent account at the recipient bank. Because of that, the team received notification from the recipient bank that the full amount was still in the account and on hold. So the dollar figure being almost half a million dollars. It was wired out, it was located, and it was frozen. full recovery and it was entirely contingent on that complaint to IC three and it being filed fast enough so that the funds hadn't moved out of their out of that second account. and like for some more data here, according to the IC3, business email compromise caused over three billion dollars in reported losses from over twenty five from almost twenty five thousand complaints. That's about $123,000 per claim on average. But something to consider is not everybody is going to make those complaints. And not everybody is going to know what to do in that area. It doesn't always need to be like buying a house. It could be a small like a a contractor who is invoicing customers for y for like landscaping work or for like home improvement and it goes to the wrong place. Like they not everything may be reported to the IC three. So that average claim could could definitely be higher. Martin Hinton (42:41) I mean, it's it's it's again, I mean, there's that that movie with Leonardo DiCaprio, Catch Me If You Can, it's just impersonation moved into the digital space, be mail business email compromise, where you make someone think they're dealing with someone they trust and they want to send money to for a service or a product. And in fact, you're being spoofed. I mean, you touch on that. I mean, if it goes into the target bank account of the criminal and that money moves. It's never coming back. But if it stays there, it's it's it's recoverable, which is you know not that common. That that's interesting. You know, one of the things that the I wanted to touch on is you know, understanding that this is possible, that your your company is susceptible to this sort of impersonation tactic through a business email compromise where they're into your trusted email system and they can, you know, mock up an invoice and and whatever tactic might be used. Part of the solution to this is and the human side of this is awareness training. does does does awareness training measurably reduce claims or is it just reduce anxiety amongst management? Is is there any evidence that supports either of those possibilities? Matthew Butler (43:49) Honestly, I don't think it has to be one or the other. I think it depends on on who you're asking. studies by companies who sell the training tend to show significant reductions in incidents, while independent research tends to be a bit more skeptical that behavioral changes can be a result. But I think both can be true. It really depends on how effective that program is. Because security training isn't or shouldn't be. a one time training. We see a lot of organizations who just do, yeah, we have security training. It's once a once a year in October for Cybersecurity Awareness Month and it's never talked about again. Like the odds of those organizations being more susceptible, more vulnerable to business email compromise, is probably higher than the company who takes a really proactive, proactive approach to it, where they maybe have trainings quarterly, with simulated phishing attacks, with and we've seen a lot of organizations now, well, a lot of the providers now offer like they try to gamify the the process. They like you get a star if you report a mil mali malicious email. You get a reward if you if you if you report X amount of emails, you get a shout out at a town hall because you're doing a great job as a cyber citizen. I think it really depends on how much how effective that how effective that program is and from my experience and talk in the companies I talk to and in previous professional experience running some of these programs, it's definitely based upon how how you work with your c with your employee base, how you understand them. Like it is there's a large human element in like you know you should know your staff and how best to reach them. And that's actually business email compromise is actually one of the highlights of our reports. It's like it's the title. Account takeovers on the rise. We're seeing a lot of business email compromise. A lot of business email compromises come from just session token theft. Like a session token exists on an endpoint. Someone clicks a malicious link that exfiltrates that session cookie, that session token, to a threat actor, and the threat actor mimics. or mimic steals that token and impersonates you and gives you access to your to your to your systems. Thinking back to the the example with the lot with the the law firm, like that very well could have happened. It could someone could have been in the email box, observed who their clients were, said, okay, we don't want to send it from their actual email because we don't want to be like the threat actor won't want to be found out. They don't want to be too suspicious. So they'll make a look like domain and send on their behalf and make it look make it seem like it makes sense and hope that the the buyer, the buyer of the home doesn't recognize the difference in the email. And if you're not thinking about it, and if you're stressed out and like you have that human emotional response, you want to buy the house. You want things to go smoothly. And if pain the pain the dollar amount that you expected is now and not later, let me do it so I can close on the house quicker. Martin Hinton (47:07) I I don't know if it's me. This this is my whether it's my internet or yours, but th there's a it's slight uns instability. So I I can fix anything that shows up, but but I'm gonna ask the next questions, I'll pull this bit out. But on ransomware negotiation, the the the the if bots are negotiating, how does that change the negotiation? is there i we we touched on this a little bit, but but is there a dynamic there that you're seeing? Is it are or Are payouts going up as a result or down? Or is it too early to tell? Wha what what are you seeing in the actual sort of reality of the sort of little bit of AI bot negotiation you you're seeing? Matthew Butler (47:44) It depends. So our understanding is that bots aren't negotiating in the sense of deciding what number to accept, but rather they're using bots which have twenty-four by seven accessibility availability across all time zones to expediate the initial rounds of communication. in other words, like AI is being used more for tempo and psychological pressure. pacing negotiations allow us more time, well Without bots, the pacing of negotiations could be could allow more time for the victim to spin up their instant instant response team, apply backups, do more investigation. Whereas if you taught like if someone finds the the ransom note and tries to contact that threat actor, if they respond immediately, you are more like a human may be more not human, but like the victim may be more likely to pay that ransom because they feel that pressure, they feel as though they that's the next that that's the next step. They have to expedite, they have to expedite these exchanges in an attempt to like reign like to to get this tactic. it's the automation of urgency and not like pricing, if that makes sense. That pricing decision is still very human. So let's say if a threat actor let's say let's do 12 and 24 hours. let's say the threat actor can get an immediate contact and the victim is more willing to pay 40 like let's say the initial ransom is $2 million. The the vic if the victim is more willing to pay forty thousand dollars, which is a drastic discount, after twelve hours versus nothing in twenty four hours, you take the income, you take what you can get. So you don't so it's like any time wasted. Martin Hinton (49:24) Yeah, that meant bird in the hand beats two in the bush, Matthew Butler (49:26) Yeah. Martin Hinton (49:26) right? I I then again I'll I'll keep using old old adages to help help people understand. w we we've been talking about fifty minutes, so I wanna I wanna wrap up in an area that is, you know, perhaps one where if you own one of these businesses, you might think it doesn't matter, but the small and medium sized business space. Take a forty percent person manufacturer with no IT director. What are three controls that move their risk the most? You know, w what are three things that they should do? What top three things to help reduce their risk? Matthew Butler (49:55) All right, so the first one is gonna be multi factor authentication. I think we've been h I think many people have been hammering this for a long time. Although that's not a silver bullet. You still should d have a really good layered defense model, but multi-factor authentication, first line of defense, any systems that require or g have get priva any systems that Present access to sensitive business information or business critical applications need to have MFA, especially your email system to your other SaaS providers. We actually recommend to go beyond traditional MFA. I think it's true where organizations like if it's SMS or nothing, like text message or nothing. do SMS, but you should really focus more on fishing resistant MFA. It relies on cryptographic pro protocols that make it virtually impossible for attackers to intercept that To intercept and and to bypass or defeat MFA. So if an individual falls victim to a fission attack and then does their pass on a fake site, the attacker can't bypass that challenge. we're seeing like device bound pass keys where the pass key is generated inside like the security, the security chip processor within the device, or even using biometrics, which takes is a a biometric sample of like your face or your fingerprint and turns it into a template that allows it to match it aga to match it against what it knows and then release that to pass that challenge. other other other things to look at is endpoint detection response. Key thing. It addresses that the reality that some attacks may bypass preventative controls. modern EDR EDR solutions are going to be able to give you an early warning. they go beyond like traditional antivirus. The solution in Incorporates behavioral and analysis capabilities to detect suspicious suspicious activities, different like credential dumping, lateral movement, and encryption patterns. And that usually comes with some sort of 24 by 7 monitoring. I like I said before, that is really important. You want eyes on your system 24 by seven. it doesn't need to be it doesn't need to be automated analysis, just analysis in general, human on staff. And ransomware we see a lot of ransomware attacks occur off off hours. So having someone available or having a team available at one o'c one PM, again, it changes the impact or the severity of an incident. lastly, I really wanna I really wanna state the importance of having good backups. in severe cases, data loss or inaccessibility could lead to failure of the business. like I said before, that's why when prevention fails. backups become critical if if you're not backing up the right way, it may change how successful you are in terms of a inavailability or like ransomware situation. We suggest that organizations follow the backup strategy of the 321 rule where they have three copies of their critical data stored on two different media types and then one is offline, off site, or it's immutable. that way if a ransomware group does attack your backup systems, try to go after your backup systems, hopefully you have some sort of backup available to to restore from. So just to yeah. j just to round that up, Martin Hinton (53:24) You you I mean we we've sort of go ahead, pardon me, finish it finish what you're saying. Matthew Butler (53:28) it's it's MFA, multi factor authentication, endpoint detection response, and backups as the three that a small business should really focus on. Martin Hinton (53:38) You know, we going back to what just before that question, we were discussing the human element. One of the things that that I've said to people when asked about my view is that you have to treat all of your security in this sense as perishable, not unlike your own physical health, right? You don't go to the gym one day at the beginning of the year and think you're gonna be healthy. You you create a sustainable routine that addresses all your, you know, aches and pains or your interests. And that has to be something that like you like you touched on with the employee training where it's interactive and it creates sort of an incentive based reality and an engagement that that it it it helps a inform and make it clear this is important, but it also makes it a new part of your existence, right? You you're not just adding something on like you said one day in October. It is a new reality. This is a new this is a new piece of the pie that we have and we need to keep this piece of the pie with all the other pieces of the pie in mind when we do business. And part of this is is, you know, very, very new for people a as I've written about and talked about, I won't bore you with, but this idea is that that, you know, any status is perishable. And and I wonder, you know, we say perishable and that's a weird word to use in a in a digital space where with you know devices, but is that a fair sort of very simplified take? Is that you you always need to have this in mind and address it and think about it just like any other part of your business? You know, is are we doing well enough today, marketing? You know, are are we protecting our brand? Is the store clean? This is a new part of the checklist that needs to be, you know, to the new reality is a twenty four seven checklist. Is is that something to to to simple way to think about it? Matthew Butler (55:22) Yeah, that's very fair. Like s a s an effective cybersecurity program at any business should be should rely on multiple layers of defense. cybersecurity is a game of cat and mouse. a cat and mouse between defenders and actors, right? Like someone is always trying someone that's always trying to get away, get away with new techniques, new procedures, new tools to get around the layers of the fence. So if one does fall, you want to make sure you have something else to fall back on. Martin Hinton (55:53) Yep. So, I guess we're coming up on the Q three report. you got any previews? Do you got any ideas about what's coming? Matthew Butler (56:03) I think we're gonna see see a lot more companies change or start talking about how to how they've been defending themselves against Mythos, but overall like ransomware ransomware leak site numbers most likely are going to stay the same. Maybe maybe they'll increase, maybe there'll be a slight increase in incidence in Q three. their actors are human and it is the summertime. it could they take vacations. So we could see that with a return to the w return to fall, no longer on vacation, that these numbers could increase. not only does the trend line that we're seeing already continue to rise year over year in terms of the overall number of incidents, we also see an occasional seasonal spike in Q f three that we don't tend to associate with with anything else than the summer holiday, or the return from a summer holiday. Martin Hinton (57:03) S some things are some things are that simple, aren't they? You know, people are people are at the beach. Matthew Butler (57:07) Yeah. Yeah. Martin Hinton (57:09) you know, one of the things I I think is probably fair to say I've touched on is that there is this sort of disconnect about what businesses believe about cybersecurity. What's one thing that businesses believe about cybersecurity that you think is not quite right? Matthew Butler (57:23) I mentioned it before, but MFA is definitely definitely not the silver bullet that everyone says it is. It is very important in terms of like the layer defense model. It needs to be the MFA needs be enforced, needs to be comprehensive, it needs to be efficient resistant. It's a great way to protect your environment. But you also need endpoint detection response. You need that backup solution. You need somebody hands-on keyboard or somebody who can respond to an incident 24 by seven. And the list of controls just goes on. And now we have the threat of mythos or threat of like frontier models and vulnerability exploitation just on the rise that Martin Hinton (57:59) Yeah. I mean you you you you Matthew Butler (58:02) That companies need to think about. Martin Hinton (58:03) Yeah. Sorry, pardon me. Go ahead. Yeah. Well, I mean, you you I mean you you use the phrase layered defense and to you know to put it into the homeowner perspective is, you know, you lock your door. Maybe you've got a deadbolt, so you've got two different keys and two different locks on the door. You've got an alarm system, you don't let your head just grow up so that people can hide by the windows and, you know, w make their way in. We we again like the the the the mindset is very real for us in the in the in the physical world. And adapting that with the right tools, MFA, endpoint detection, into the digital space, it it's certainly there and it's our capacity. And there's a need to do it. so yeah, I mean that that that idea is is is a very good one. so we've been talking about an hour, and I think we we did pretty well to get to most of the the the stuff we said we were gonna talk about. But is there anything we didn't get to that that you think is important for people to take away? Or is there anything you want to say some more about? Matthew Butler (58:59) I think it's really important as you take as we've talked about the social engineering aspect of this and the people aspect of this. Everyone wants to do a great job at work. Everybody wants to feel successful. I would say if you see something, say something and be sure to take that pause. Really think about what you're seeing, what you're doing, the purpose of it, and be aware of your surroundings, be aware of the threats around you. Like if you wanna find out more, there are tons of articles online that talk about current threats. for f in business terms and s in technical terms, the information's out there. And it's really important to be a good cyber citizen and keep yourself safe and your company safe. Martin Hinton (59:44) here, here, it's funny. I one of my more recent I I I write a substack that's n not necessarily about cyber, but I was inspired to one write one recently after going to an insure tech conference, and a person in the audience made a comment and the line was not all friction is bad friction. And this idea that a you know sometimes slowing down and not at you know 445 on a Friday when you're trying to get that early bus to the beach and you're new and an invoice comes in and the accounts changed and you fire off a payment without double checking it, these are the moments when people are taken advantage of. And and that idea that you double check, that you go knock on a door, that you confirm with the, you know, the CFO that this is the the the right thing to do or this is actually what you want to do, that that idea that we want to slow down a little to help reduce these problems is is really there's a lot to wrestle with there, I think, at companies where efficiency and speed and getting things done and doing a good job are are quite obviously and necessarily the priorities, but but that that's so that's a good point. Well, Matthew, I don't have anything else. do you? Matthew Butler (1:00:45) I'm all set. Thanks for your time. Thanks for having me. Martin Hinton (1:00:48) Matthew Butler, my absolute pleasure. Matthew Butler, Director of Cyber Risk Services at Travelers Insurance, is who we've been speaking with today. Fascinating conversation. We've made reference to a few things, including their their risk reports. There'll be links in the show notes wherever you might be watching or listening to this. so you can find that information there. If you've got a question or a comment, please leave it where where you happen to be, and we'll do our best to answer or we'll re refer it back to Matthew and and see whether he can help out. but for now, Matthew, again, thank you so very much. I'm Martin Hinton This is the Cyber Insurance News and Information Podcast. Thank you so much for watching and in taking your time with us today. Enjoy the rest of it.