A Legacy of Service: Decoding the Cloak of Trust Worn by Attackers Beyond Security Training or Looking for the Malicious

Published
Written by:
Vishwa Pandagle
Vishwa Pandagle
Cybersecurity Staff Editor
Key Takeaways
  • Whitmore expects attackers to flip the extortion model on its head by holding not data but its integrity hostage, demanding payment to restore it to an untampered state. 
  • Attackers are reading the same headlines and regulations we are, and are looking for angles to turn our own environment against us.
  • Once you understand the why, the how stops being a surprise, and that is what lets you get a step ahead.
  • Blackpoint Cyber observes that the average breakout time from initial access to lateral movement is under thirty minutes. 
  • If your reporting focuses only on entry and impact, you miss the window that decided the outcome. 

In this interaction with Erin Whitmore, Head of the Adversary Pursuit Group at Blackpoint Cyber, we discuss what security means to her, what indicators she watches for, and most importantly, what drives threat detection and prevention.

From the Defense Intelligence Agency and the Office of the Director of National Intelligence to serving as a CIA Operations Officer before moving into cybersecurity, Whitmore's career reads like a spy thriller that now helps stay a step ahead of adversaries. 

Whitmore talks about how adversaries approach access and how she tells if they have internalized a principle - one that looks like it belongs to prevent detection.

When attackers are not trying to defeat your controls, they are trying to render your controls irrelevant by appearing authorized. This is why she believes that identity defense must move from gatekeeping at the door to continuous behavioral awareness inside the house.

Whitmore says that defenders must be fast, and AI is helping do that at machine speed. Because once a real credential is being used, the clock is running. 

Adversaries are abusing trust that is in place through a trusted vendor, a trusted login, a signed software update, or a help desk that wants to be helpful.

Defenders must look beyond what they are trained to look for, besides what is broken or obviously malicious, because the attacker shows up wearing legitimate trust with nothing broken to find. 

Vishwa: Ransomware groups combine data theft, extortion, and public pressure tactics. What attacker behavior caught your attention over time?

Erin: The shift that caught my attention was the move from breaking systems to corrupting trust. For years, the ransomware conversation was about encryption and downtime. You lock the files, you demand payment, and the victim either restores from backup or pays. 

That model is almost quaint now. What I watched develop was a deliberate progression toward the data itself, first theft for double extortion, then selective leaks to apply public pressure. 

In the intelligence world, we have a phrase, trust but verify, and I carried it into cyber because the tradecraft does not change when it moves online. 

Rather, only the speed and the medium do. It matters because the most dangerous thing an adversary can do is not steal your information but make you act on information you believe is true and is not. 

That is why the behavior that concerns me most now is manipulation, the quiet alteration of data rather than the theft of it.

As businesses race to adopt AI across almost every function, the data feeding those systems becomes the target, and I expect attackers to flip the extortion model on its head: instead of holding your data hostage, they hold its integrity hostage, demanding payment to restore it to a clean, verified, untampered state and to tell you what they touched. 

A group that exfiltrates data and threatens to leak it is a serious problem. A group that can quietly alter the records inside an environment, the financial figures, the medical data, the operational logs, and let a business act on the corrupted version is a categorically harder problem because the victim does not even know there is anything to recover from.

But turning back to proven extortion methods, the public pressure tactics are the part most people see like the leak sites, the countdown timers, and the press outreach. Those are theater designed to compress your decision timeline. The behavior worth watching is underneath that. These groups have become disciplined operators. They study the victim, they understand what data carries leverage, and they sequence the pressure to remove the time you would normally use to make a careful decision. That is tradecraft and not opportunism.

The other thing I would underline is that these groups stay relentlessly creative and aggressive, and they will weaponize anything including our own laws. 

The example that stays with me is from late 2023, when the ALPHV group, also known as BlackCat, filed a complaint with the Securities and Exchange Commission against one of its own victims, a lending software company, accusing it of failing to disclose the breach within the new four-day reporting window. The attacker did not just steal the data and demand payment. 

They turned the victim’s own regulatory obligations into an extortion lever using the threat of a compliance problem to compress the decision and force a faster payout. This is the sort of tactics, techniques, and procedures (TTPs), I keep an eye out for in threat actor activity. They are not working from a fixed playbook necessarily. They are reading the same headlines and regulations we are, and they are looking for any angle to turn our own environment against us.

Vishwa: Public reporting often focuses on how an intrusion began and its impact. What other aspects of an incident deserve greater attention from security leaders?

Erin: The devil is in the details. Reporting gravitates to the entry point, the phishing email, the unpatched VPN, the stolen credential, and to the aftermath, the cost, the records exposed, and the regulatory fallout. The space in between, the dwell time, the lateral movement, the decisions the attacker made once they were inside, is where defenders can learn the most, and it gets the least attention.

When I was learning this work, the discipline that mattered most was backwards planning. You start from the objective and you work back to where to begin because that is how you see the steps you would otherwise miss. 

Applied to an incident, the question is not only how did they get in, but what did they touch, what did they learn, what did they leave behind, and what were they after. 

The initial access vector tells you how to close one door. The behavior inside the environment, such as the lateral movement, the privilege escalation, and the way they establish command and control, tells you how the adversary thinks, and that is what lets you anticipate the next one. This is the part of the work I am most drawn to, which is the psychology of the threat actor.

I want to understand what motivates them, why they do what they do, and how they do it. The technical indicators only carry you so far. I want to know are they in it for the money, for the disruption, for status inside their own community, or for an objective handed down by a government. 

Each of those motives shapes how they move, what they reach for first, and how far they are willing to go.

Once you understand the why, the how stops being a surprise, and that is what lets you get a step ahead instead of staying a step behind. And here is the part that surprises people: when you backwards plan from the adversary's objective, you keep landing on the same unglamorous fundamentals. 

My own team’s threat research bears that out. The defining pattern of the past year was trusted compromise where attackers are no longer breaking in so much as logging in through a valid credential, a trusted remote session, or an IT tool the business already runs. What closes those doors is not exotic. 

It is the boring blocking and tackling, but you have to have phishing-resistant multi-factor authentication, patched appliances at your edge, least privilege, segmented access so one foothold cannot reach everything, a clear inventory of the tools and assets in your environment, and tested, immutable backups.

The boring security practices are boring precisely because they work, and most of the incidents I know about would have looked very different if one of those basics had been in place.

The other underexamined dimension is speed, specifically the gap between when something fires and when a human acts on it. An intrusion is not a single event. It is a race. Many of the major cybersecurity firms now report that the average breakout time from initial access to lateral movement is under thirty minutes. 

If your reporting focuses only on entry and impact, you miss the window that decided the outcome. Security leaders should be asking how fast their defense moved during the part of the incident no one photographs.

Vishwa: Could you share your observations on the relationship between attacker tactics and defender responses over the years?

Erin: For most of my career, the relationship was a step function. The attacker would innovate, the defender would adapt, and the gap between those two events was measured in months or years. That gap was survivable, but it isn’t anymore. By chaining reconnaissance, exploitation, and lateral movement into a single agentic workflow, the adversary has automated the offense and collapsed the timeline. 

Not to mention, attackers can now use AI to parse through stolen data and know the impact and value of what they took in seconds instead of days. This places them at a significant advantage when attempting to extort a victim.

The clearest marker of that change came in September of 2025 with the campaign Anthropic later designated GTG-1002. Anthropic attributed GTG-1002 with high confidence to a Chinese state-sponsored group. 

The threat actors subverted an agentic AI coding tool and turned it into an autonomous operator by running an estimated eighty to ninety percent of the campaign against roughly thirty targets across technology, finance, chemical manufacturing, and government.

The human operators selected the targets and approved the critical decision points, and the agents handled the rest, executing reconnaissance, vulnerability discovery, and data collection, and all at a tempo no human team could match. 

That matters for everyone, not just large enterprises, because it removes a constraint that previously protected smaller organizations. It was never cost-effective to point nation-state-grade infrastructure at a fifty-person company. 

Now, it is feasible to use these resources if the nation-state motivations and objectives align with any size target, whether it be large or small. The economics flipped, and the smaller organizations that assumed they were too small to be worth the effort are exactly the ones now in the target pool.

So, the relationship has changed shape. It used to be human against human, attacker tradecraft against defender tradecraft, with time in between. Now it is increasingly agents against agents, and the defender who is still waiting to read an alert before acting is not competing on the same terms let alone the same playing field. My view is straightforward. When the offense operates at machine speed, part of the defense must operate at machine speed too, but on the narrow set of threats where you have validated that it can act safely.

Human expertise and insight do not leave the equation. The role just moves up a level. That expertise sets the boundaries, validates what the agents are surfacing, and owns the judgment calls that take context and hard-won experience. 

It is also the safeguard against the adversary turning the AI against us. We have already seen both in practice. Again, in GTG-1002, the threat actors hijacked an AI agent by convincing it that it was performing authorized security testing. Independently, researchers have demonstrated how injecting a small number of malicious documents into a model’s training data can install a hidden backdoor that causes it to behave in ways its operators never intended. Human expertise is what catches that by noticing when an agent is being steered, questioning an output that looks too clean, and refusing to act on a conclusion that does not square with experience.

What changes is that it is no longer the bottleneck standing between the alert and the first response. The speed of AI and agents absorbs that opening move, thus freeing human insight for the decisions where it counts most. 

There is an adage that the attacker only has to be lucky once while the defender has to be right every time. For most of my career, that math favored the attacker. 

Agents and AI are the first thing I have seen that genuinely move defenders toward being right every time because they let human expertise cover attacks with speed and scale that used to be out of reach, but you must have the human expertise. 

Without it, you have speed with no judgment, no accuracy, and no accountability.

Vishwa: Identity abuse appears in many intrusion investigations. What does that say about how adversaries approach access?

Erin: It says the adversary stopped breaking in and started logging in. Identity is now the primary attack surface. My own team's threat research found identity compromise at the center of nearly every intrusion we investigated last year. 

Erin Whitmore

That fact reframes the entire problem. We spent years building defenses to detect malicious payloads, but the modern attacker has become much craftier. They obtain valid credentials, and they operate as a legitimate user by living off the land with the access and tooling already present rather than dropping malware because a real login does not look like an attack.

Erin Whitmore
Head of the Adversary Pursuit Group at Blackpoint Cyber

This is the part of the field where my background intersects directly. Insider risk was my bread and butter, and a credential compromise is functionally an insider problem. 

The attacker is inside the perimeter, holding legitimate access, behaving in ways that are subtly wrong rather than obviously malicious. You cannot catch that by looking for known bad files. You catch it by understanding the normal pattern of life for that account and noticing when the behavior deviates from it. Impossible travel, access at hours that do not fit the user, activity that does not match how that person works. The signal is behavioral rather than just technical.

What it tells me about how adversaries approach access is that they have internalized a principle from the intelligence world, which is that the cleanest operation is the one that looks like it belongs. 

They are not trying to defeat your controls. They are trying to render your controls irrelevant by appearing authorized. That is why identity defense must move from gatekeeping at the door to continuous behavioral awareness inside the house. It must be fast because, once a real credential is being used, the clock is already running. AI is already helping us do that at machine speed.

Underneath all of this is trust itself. More and more, the adversary is not breaking anything, they are abusing trust that is already in place through a trusted vendor, a trusted login, a signed software update, or a help desk that wants to be helpful just to name a few. 

Defenders are trained to look for something broken or obviously malicious, but when the attacker shows up wearing legitimate trust, there is nothing broken to find. That is the shift I would pay attention to, and it is why I keep coming back to trust but verify. Your most trusted relationships and credentials are exactly where I would look first.

Vishwa: Supply chain compromises often expose risks that organizations did not anticipate. What patterns have you noticed in the way these incidents unfold?

Erin: The pattern I see most is that organizations map their own security and then assume the boundary of their network is the boundary of their risk. An adversary does not need to beat your defenses if they can compromise a trusted provider and island hop into every customer behind it. 

The impact radius is the part organizations consistently underestimate. Add a nation-state capability, like Russia's SVR in the SolarWinds compromise, and the impact becomes devastating.

This is especially acute in the managed service provider channel, which is where my focus is now. When one provider serves dozens of clients from shared infrastructure, a single compromised foothold does not threaten one company. It can reach every company that provider serves. 

The adversary understands that math better than most defenders do. They target the provider precisely because it is a force multiplier: one intrusion, many victims, all connected by a trust relationship they never thought to question.

The other pattern is timing. Supply chain intrusions tend to unfold quietly because the access looks legitimate the entire way through. By the time the impact is visible, the adversary has often been moving through connected environments for a while. 

My consistent guidance is to extend the same adversarial scrutiny you apply to your own environment to the trust relationships you depend on to operate. You cannot protect what you cannot see, and most organizations have very limited visibility into the providers holding the keys to their environment.

Vishwa: Many breaches eventually become leadership and decision-making challenges. What observations have shaped your thinking on incident response?

Erin: Every serious incident I can recall stops being a technical event and becomes a leadership event, and it is usually faster than the organization expects. The technical containment is one track. 

The decisions like what to disclose, when, to whom, whether to engage breach counsel early enough to protect privilege, whether the incident is material and what disclosure clock that starts, how to communicate with clients and regulators all run on a parallel track, and that is frequently where the lasting damage is done or avoided. 

The observation that shaped my thinking most is that you cannot make good decisions for the first time during your worst day. The intelligence community drilled this into me. You rehearse. You run the scenario before it is real so that when it happens it feels like deja vu rather than panic. 

Practice how you play. You do not walk into the Super Bowl without ever having run the play, and yet organizations routinely stake their bottom line and their reputation on an incident response plan that has never been tested under pressure. The tabletop exercise, the crisis simulation, and the red team drill are not compliance checkboxes. 

They are the difference between a leadership team that executes and protects its balance sheet and one that improvises, costing the company incredible amounts of money.

The other thing I have learned is that speed and accuracy are not the same goal and confusing them is dangerous. Under pressure, there is enormous temptation to act fast just to be seen acting. 

But a fast decision made on incomplete or, worse, manipulated information can do more harm than the breach itself. 

The strongest incident leaders I have worked with hold both speed and accuracy together. They move quickly where the facts are clear, and they slow down precisely where the stakes demand verification.

Vishwa: Looking at incidents involving critical services and essential infrastructure, where do you think defender capabilities need to evolve to keep pace?

Erin: Defender capabilities must evolve toward acting in the same time domain as the threat. That is the core of it. 

When an adversary can complete lateral movement in under thirty minutes, and there are documented gaps of nearly an hour between an alert firing and a human beginning triage, the math does not work. 

You cannot hire your way out of that gap because at that point, it is structural. The only thing that closes it is a defense that can take a decisive, reversible action on a validated threat, within rules that human experts set in advance, ensuring everything outside those rules escalates to a person. For critical services, you cannot afford to be slow, and you cannot afford to be reckless. 

Moving fast enough to matter without acting carelessly is exactly where the capability gap lies. Autonomy without validation is a liability. A defense that acts on its own with no defined boundaries and no human authority layer is one false positive away from causing the disruption it was meant to prevent. So, the evolution I want to see is not full automation, and it is not human pace defense. 

It is narrow, validated autonomy. You define the specific threat patterns where the model has been measured against real analyst judgment and proven accurate, you let it act decisively on those, and you escalate everything else to a battle-tested, human expert. Narrow and validated beats broad and unproven every time especially when the target in question is essential infrastructure that could have devastating consequences. 

We touched on it earlier, but the most dangerous move an adversary can make is not to steal your data but to corrupt it, to make you act on information you believe to be true but is not. The same logic now runs in the other direction but pointed at the defender. The piece the industry still underinvests in is the integrity of the data feeding its own AI defenses. 

As we lean on AI to anticipate and respond, the adversary’s most elegant move is not to evade the model but to poison it, tainting the inputs so the system confidently tells you the threat is going left when it is going right. It is a trick play, and it is the same trick from a different angle. 

For critical/essential infrastructure, protecting the integrity of the data, and the model itself, has to be treated with the same seriousness as protecting the network it guards.

We have to stay human enough to verify what the machine tells us. That brings me back to where we started: trust but verify.

Vishwa: You've had unusually rich career transitions. What differences have you noticed in how these groups approach incidents? Were there people who helped shape your career at key moments?

Erin: To understand how I approach this work, you have to go back well before any of the technical pieces. I am third-generation service to my country. 

My grandfather was killed on an Air America flight in Vietnam and is on the first panel of the Vietnam Memorial Wall. 

My father flew Blackhawk helicopters my entire childhood, and when I was nine, before he deployed to a peacekeeping mission in Bosnia, he handed me a book about a girl living through the siege of Sarajevo and asked me to read it so I would understand why he was leaving to help people he had never met. 

Service was the backdrop I grew up in. It left me with an instinct I still lead with, which is that behind every alert and every breach there are real people depending on someone getting it right, and it is why I approach an incident as a mission rather than a ticket. However, my path was anything but a straight line in how I got to where I am today. I entered the workforce in 2009, into the teeth of the global financial crisis, when there were simply no jobs for new graduates. 

I ended up serving an AmeriCorps service term in Baltimore City public schools, and that experience shaped me more than any job I have held since. Those students were carrying things no kid should have to carry, and they showed up anyway. They taught me resilience and perseverance, not as words on a poster, but as a daily practice. I learned that capability and circumstance are not the same thing, and that the people everyone underestimates are often the ones with the most grit. 

I carry that into every incident I work now. The worst day of an organization’s life is a test of resilience, and I learned what resilience really looks like from teenagers in Baltimore City long before I learned it from any adversary. From there my path ran through the Intelligence Community. I started in counterintelligence supporting the Defense Intelligence Agency (DIA), moved to the National Geospatial- Intelligence Agency (NGA), and then, somewhat serendipitously, into a cyber policy role at the Office of the Director of National Intelligence (ODNI). 

Counterintelligence work taught me to assume the adversary is already inside and counting on looking like they belong, which is exactly how I read a credential compromise today. At NGA I learned to study a scene against a known baseline and trust the single detail that had changed, which is the same instinct I use now to find the one thing in an environment that does not fit the pattern of life. 

The cyber policy role at ODNI was the turning point in my career where my path finally bent from traditional intelligence toward cyber. I had the right security clearance, I could write, and, at that time, talent was scarce enough that those things got me in the door. I was the only woman on the team, and I knew very little about cyber, but I did not let either fact deter me. I learned from the ODNI team that you can embrace opportunity and learn more than you could ever imagine. 

They taught me to challenge myself to learn new things no matter how intimidated you might be at the start. It was a lesson I apply whenever I see a threat actor do something that challenges my assumptions and forces me to advance my knowledge. Eventually I joined the Central Intelligence Agency (CIA) as an Operations Officer, and that is where the most important lesson of my career was drilled into me. 

My mentors at the CIA taught me to never accept anything at face value, to challenge the underlying intent behind what I was seeing, and to look for what is not evident. An adversary shows you what they want you to see, and the discipline is to keep asking what sits underneath it, what they are really after, and what is being deliberately kept out of view. What ties all of this together, and what I think gives me a different lens than someone who came up purely through IT, is that a cyber incident is rarely a new problem. It is an old problem in a new medium. 

The way the world works day-to-day in geopolitics, intelligence operations, business, economies, and more plays out inside these incidents almost beat for beat. The tradecraft I studied from the Cold War is not history, it is a preview of what we are seeing now. The same deception and human-targeting techniques intelligence officers used against one another show up in how today’s adversaries social engineer their way into a network. Russian active measures from the Cold War, the influence and disinformation campaigns built to divide and mislead, are visible right now in the misinformation and disinformation campaigns we track online, only faster and at far greater scale. 

Once you have seen the physical version of the playbook, the digital version is recognizable. That is the lens I brought into the private sector, and especially into the managed detection and response world I am in now. The difference between these worlds is mindset far more than method. Colleagues used to call me Debbie Doomsday because I would walk through the scenarios no one else wanted to consider. The best defenders I have ever worked with think the same way. 

They stop asking what if we were attacked and start asking how would they attack us and how do they stop it first? The best defense really is a good offense, and it starts with refusing to take the picture in front of you at face value. As for the people who shaped me, the honest answer is that it was less any single mentor than a series of people who took a chance on someone who did not fit the standard profile, the hiring managers who valued that I could think and learn over a checklist of prior experience, and the colleagues who let me ask questions when I was the least technical person in the room. 

That is exactly what drew me to Blackpoint Cyber. The Adversary Pursuit Group, and the response operations behind it, are built on real human-led operations rather than theoretical frameworks. That is a rare foundation. I am here to push it further, and to make sure the credit for what we produce lands on the team doing the work. And of course, I am always here to help a threat actor have a very bad, no-good day.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: