Video: Resilience & Readiness in Insurance: Key Trends and Recommendations for 2026 | Duration: 2628s | Summary: Resilience & Readiness in Insurance: Key Trends and Recommendations for 2026 | Chapters: Welcome and Introduction (10.72s), Welcome and Introduction (58.855s), Speaker Introductions (162.23s), 2025 Cyber Landscape (210.86s), AI and Double Extortion (433.61s), Identity Abuse Drivers (573.17s), Evolving Cybersecurity Landscape (702.215s), Threat Intelligence Collaboration (834.59s), AI-Driven Security Trends (945.49s), Sector Intelligence Sharing (1078.44s), Breaking Information Silos (1270.275s), Prioritizing Intelligence Data (1425.26s), Proactive Security Testing (1724.5s), Information Advantage Importance (1932.245s), Proactive Cybersecurity Approach (2070.58s), Urgent Threat Influencing (2258.395s), Prioritizing Common Threats (2385.985s), Conclusion and Thanks (2534.875s)
Transcript for "Resilience & Readiness in Insurance: Key Trends and Recommendations for 2026":
Alright. Hello, and welcome, everyone. We're just gonna give it a few moments for everyone to join, before we get started. So feel free to get up, stretch, grab a cup of coffee, and we'll be getting started momentarily. I hope everyone is having a great Thursday and overall a great start to 2026. We have a very exciting session planned for, you all today, and we have a couple of great speakers, if I do say so myself. This is actually the first webinar that we're hosting at Filagran for the year, so very much looking forward to starting the year off hot. And alright. I see that more people have joined, so let's go ahead and get things started. So, again, hello, and welcome everyone to today's session, resilience and readiness in insurance, key trends and recommendations for 2026. My name is Adam. I'm on the marketing team here at Filigran, and I'll be moderating today's session. Before we get started, just a couple of quick housekeeping items to go over. This session is being recorded, so anyone who registered will receive an on demand version of the recording after the session is concluded. If you have any speakers or any questions for our speakers today, you can ask them by clicking on the q and a button, which is on the right hand side of your screen. We have some time planned for q and a at the end of today's session. We're gonna try our best to get to any questions that are asked by the audience, but in the case that we don't get a chance to answer your question, we will make sure to, get back to you via email afterwards. Another thing that you will see on the right hand side of your screen is a docs tab. This is just where we've listed some relevant resources, that we may or may not discuss today as well as some other, you know, pieces of content that you may wanna check out, afterwards. And that is enough of that, enough of the housekeeping. So let's go ahead and get into our session. Today, I am joined by two speakers, Darren Kingsnorth, who is head of threat intelligence at a UK insurer and Filigrand's own Jay Allmend, who's a senior solutions engineer. We're here to review some of what we saw in 2025, what to expect looking forward into 2026, and then offer some recommendations for you all. So to kick things off, I'm gonna welcome our speakers onto the stage, and I'll pass it over to them to introduce yourselves. Darren, let's go ahead and start with you. Cool. Hello, everyone. My name is Darren Kingsnorth. As Alan kind of mentioned, I'm the head of threat intelligence at UK Insurer. My background really is from decades worth of pen testing and then moving into threat intelligence space in the last five, six years. So, yeah, that's me really. Oh, I suppose it's me next. Yeah. It's, it's lovely to speak to you all. My name is Jay Allmond. I'm one of the senior solutions engineers here at Filigram. It's essentially my job to do all the nerdy stuff. I've been in cybersecurity for around ten years, and I've really enjoyed my time at Fiddagrand so far. And thanks so much for having me. Of course. No. Super happy to have you guys on here, and, again, really looking forward to this session. So as I spoke about kinda like as far as what to expect in this session, I just wanna start off with a quick set quick question for both Darren and Jay. And so looking back at 2025, and what we saw both from public reporting, What actually changed the risk landscape in 2025 in your opinion, and what did you see as more just hype? Darren, wanna start? Yeah. I mean, what a crazy year. Right? I mean, when we look at back I mean, we're nearly at, you know, February already, but what a hell of a year. We had the retail sector in The UK on fire pretty much. And a nice note to that, though, however, is in years gone by, people would have gotten out their marshmallows and similar. But, actually, what I saw on LinkedIn was actually quite a a come together as cybersecurity in terms of, you know, mental health and things like that. So that's fantastic to see. Same time, developer trust has been entirely annihilated. Obviously, all the NPM issues that we had midyear, so that's, you know, what do they trust now? And as we know, developers are generally people who do bring their money in. So being that, you know, they're not they can't be quite as bandit as they usually are. From many years as a pen tester, I've seen that. At the same time, it was the year of the third party. Of course, we had SalesLoft. We had, of course, retail sector. And if you do look on public reporting, you'll see, you know, many different third parties linked to that. Of course, we look at, you know, the ransomware. So, you know, ransomware just the other day, we're up to 400 plus companies already, and we had a staggering eight and a half thousand companies being compromised from ransomware, again, just reported. So when you think that number's probably double in terms of actually, you know, where people haven't had, you know, similar so much promoted and similar. Same time as well, we had the big Caesar flap. Every thought is on fire because in true cyber style, we love to build all these foundations about all these big things on top of the tiny little foundation. And so I think VM got a big shake up in terms of, you know, ultimately how we were gonna deal with, you know, the the Trump policies that have come in place. But, also, we just showcase the the lack of immaturity or the lack the immaturity of the industry still, even though we are coming on, you know, twenty, thirty plus years strong in comparison to, you know, other industries. Same time, I think we truly have now established what a modern perimeter looks like. I think we saw that with retail, and we are seeing that every single time where third parties are getting popped. So all in all, everything was on fire. And I think in terms of what did change some of those points in 2025, obviously, the introduction, the true interaction, I feel, of AI. Obviously, we had 2023, twenty twenty four people getting used to it, but I think that is I mean, you look at some of the phishing emails now, they are absolutely spotless. And there are no Nigerian princes or anything like that. They are truly in the past where they absolutely belong. I could go on, but, yeah, just just to have a few there. To be fair, actually, the one last thing I wanted to add to that was around ultimately protect response to that. So what I mean by that is things like operation endgame, a truly fantastic effort from a number of different teams up across the globe to ultimately, you know, stop a number of different initial access brokers there. But, again, they are well funded. They are agile as much as a speedboat is. And so, you know, it didn't stop for long. So I I I see many more on the horizon. Yeah. And that's nature. feel like, Darren, you've, you you've definitely stolen some of my thunder in regards to the the the AI part, but that's fine. You know, it's it's definitely something that we've we've seen a lot of in in the increased use of AI, not only from, you know, in companies, but the the threat actors. Right? It's become a lot easier now to scrape the likes of, you know, LinkedIn and and public resources to get information about and you hit the nail on the head who they should be targeting with these phishing emails. And then also using AI to to generate those phishing emails, again, nail on the head, they're they're almost pristine. They're, you know, scraping Microsoft websites to, you know, take the pictures and all that all that kind of stuff. Am I on mute, or can you hear me? I can hear you, Jay. Cool. I wanted to make sure. Sorry. Headset problems. Okay. Yeah. So AI we have to talk about AI. Right? The other part that I kind of wanted to cover, and it it was more around statistics around cyber security insurance. Obviously, we're we're here to talk about insurance. So I thought I'd touch on that, you know, at least slightly. You know, there's some statistics that the Alliance posted to say that, you know, 60% of the value of large cyber insurance claims in the first half of of twenty five, accounted for ransomware. Now we have seen an uptick in a different kind of ransomware, not the the the ransomware itself, but the the different kinds of threat actors and and the way that that's working. And this is something called double extortion. And it seems like when these attacks are, you know, actually happening, it seems like the amount of money, that that are being claimed by companies for cybersecurity insurance has actually gone up by around 40%. Now just to say, you know, a bit a bit of example of what double extortion is, these threat actors aren't just, you know, encrypting your data within the company. It seems like they're now exfiltrating the data that they can essentially double extort you. Right? Hey. We want money. We've, you know, encrypted all your data in the company. So it doesn't matter if you have a backup and restore because in the sideline, they've stolen your data. So now they have a double way to extort that company. Awesome. No. That's a that's great insight, and I think there's a lot of things. Obviously, Darren said it was a a hell of a year and, you know, a lot of things to kinda be on your toes about. Jumping, back into kind of, you know, fraud and identity, Darren, what do you think is, like, really driving, the spike in identity abuse? I know you brought up Operation Endgame, and everything. Just would love some more of your insight on that. Can you hear me? Alright. It seems that we are. having some technical difficulties. Please bear with us for one moment. Technology is always fun and games. It really is. It really would. talk about the weather, but the The UK weather has been horrendous since Christmas. So there's. nothing exciting to talk about, in there. Yeah. No. Weather over here. in Boston has not been great either. Can you hear us, Sorry, Darren? guys. I have literally no idea what's going on here. I can hear you perfectly now. Well, I can't hear you perfectly now, but I'll I'll quickly resolve that on my end. That said, though, Adam, in terms of driving the spike in identity abuse, technology gaps, tax incentives, and similar, I think ultimately, it's ease of execution. It's too easy to grab credentials. I literally can in probably five minutes find a Telegram channel and grab credits. That's ultimately how available they are to us, to anybody. Telegram are doing some movement in terms of taking those down, but nowhere near enough as we see. And I know a lot of people like to say, oh, where are the bad guys? They're on a dark web. For the most part, they're really not. They're on Telegram. They're on Signal and similar. Right? And so as you can probably see, and that's why a lot of products as well are are now ultimately hoovering up those Telegram channels and similar. Also, the incentives are massive, absolutely huge. I think, again, it showcases the amount of money these operations have being that they are willing to pay 25,000 plus dollars to anybody who can ultimately give them access. In the world of increasing energy rates, increasing well, decreasing salaries in some sense, increasing energy rates, ultimately, that ultimate that all impacting us in the home, People are more willing to take those offers up in similar eye. And, obviously, as we see in many countries where, you know, who aren't as affluent as some Western countries are. So I think it really showcases that the initial access brokers are absolutely winning. They're probably winning for a long time yet. If anything, I I can't see how they can really be stopped for the sheer fact that every time you see every every single MAO report you see, Forest Hill isn't picking up on it. None of them are picking up on it really just for the sheer amount of money they are pushing into that space. That said, though, obviously, they are being combined with, you know, RAS and similar. So it's gonna be a tough year, I think. And I I can't see identity shaking up and being, you know, reduced to second place behind vulnerabilities or anything like that. In terms of ransomware, see. ransomware absolutely has evolved, but I think given the natural kind of SaaS sprawl that we are seeing, obviously, everyone is moving towards the cloud. It's covered in similar. It it really is fishing about, and I don't think that's gonna let up. And, of course, we all like to say, you know, the you know, what good looks like is asset management similar. That is much harder when you do have SaaS platforms. Obviously, we are moving towards, you know, SBOMs, software bill of materials, and similar things like that, and I definitely think that's a way forward to ultimately have at least a fighting chance against that threat and similar. How we just don't have visibility. And I think for that, situational awareness is absolutely key. Awesome. On the the topic of third party exposure, are are you seeing more collaboration between threat intelligence teams and, you know, procurement or vendor risk teams? Sorry. Just having some technical difficulties. Can you hear us? my perspective, in terms of seeing more collaboration between TI teams, I think we're seeing that in products. You know, there's some great products out there now who are combining both procurement aspects and fulfillment filling fulfilling those features as well as TI and similar. So I think everyone's getting a bit of a flavor of TI, and I think they're really seeing the power of what TI can bring to really to be honest, any any products that you're seeing out there. And, ultimately, it really comes down to that information advantage that, you know, I'll I'll go into further on. But, ultimately, it's easy if you know. Right? And I think that really comes down to, you know, those sub principles. You know, no TI webinar would be right if you didn't have some sort of Sun Tzu reference somewhere. But I think we are definitely seeing that. And, of course, if we do start to measure companies from their respective breaches and similar, I think we get a far better view in terms of, you know, whether teams should be going with those reflected products or not. Just like the aviation industry in some fashion. Right? You know, you wouldn't fly a plane if it'd been breached 14 times last year. However, we happily buy products, which to me is is kind of nuts. Right? And I don't think we're being that's you know, we are record highs of ransomware, I think people are starting to realize we we do really need to, you know, have a a significant shift change here. Awesome. And moving that was all great. And I just wanted to get your perspective as far as, like, what to expect as we look ahead to the rest of 2026. What do you think we should, you know, expect, to shape the industry within the next year? So in terms of shaping the industry, I think we are gonna see and, obviously, everyone is super keen to see, you know, Skynet, you know, AIs, hacking AIs. I personally don't think we're far away from that. Obviously, Anthropic just released reports only well, not so long ago. And I think it we are seeing that. Obviously, the tractors are fully kitted out. They have ultimately millions of dollars of investment behind them because they have been so successful. I mean, obviously, you know, one of the chaps from SLSH, Pretty sure he got caught out just flying in a plane. He had, like, 2 and half million dollars of crypto on him. I that's a good problem to have. And so I think we we will see that when a lot of people say, no. They don't have the money compared to Google. Well, to be fair, I think they do because, ultimately, you see a lot of these companies are making millions of dollars when really they're backed up by about five people. You know, that that ultimately, a VC would love to have that in a legal sense. And so I think we are gonna see more of AI driven attacks and similar. Same time as well, deepfakes are now high quality. Five years ago, I made a deepfake. Actually, only a few months ago, I made a deepfake, and you see the difference between that. You know? And back in the day when I was pen testing, I'd used to you know, I did some pen testing on a a Liverpool company in UK. And they of course, we call them scousers, but, essentially, they have very interesting accents. And so I tried to pull a pull one off. Sounded dreadful, but nevertheless, I did get in. I think nowadays, great. Give me five minutes of video, and you've got a high quality Skalsor accent, you know, ready and ready to rock. And I think, you know, that's gonna get you in nine times out of 10. So I think we are gonna really start to see those capabilities ramp up. Awesome. And, you know, moving into the next year, and just, like, even from 2025 overall, like one thing we've seen a lot more of, in The UK is sector level intelligence sharing, where insurers don't just consume feeds, they're able to coproduce and share intelligence with each other. We have an initiative, we call FSSI, which is Filigrane's Secure Sharing Initiative, which is an intelligence sharing effort for insurance insurers in The UK. It's giving participating insurance a shared platform to publish, consume, and operationalize cyber threat intelligence together rather than, everyone just fighting it alone. Baron, from your perspective, how important is that kind of, you know, sector wide intelligence sharing for resilience, and, you know, just for insurers in The UK? So we've we've really gotta look back to the retail sector, incident. Right? I mean, LTE, what good looked would have looked like if they did have a out and out sharing platform or some sort of support there. Not to say they don't because they got some great people across the retail sector that I do frequent. But it is really around how we can share that again at the speed of cyber. Sorry to say that. It's absolutely dreadful term, but I I purely stolen from another salesperson a long time ago. But it's true. So I I really do think we do need to move forward in terms of those sharing circles. Obviously, there's lots of ice axe in operation, and they're great. Only really you see those on kind of rapid defense or very large sectors. You know, you've got oil and gas. You have financial services costs and similar. But I think we are gonna have to spread those those tentacles far and wider really to ensure that ultimately you have these, you know, sectors as nodes, then they ultimately feed into the respective country certs for the benefit of NCC and similar. So I think that truly is what good looks like. The same time, ultimately, I say all the time quite maybe facetiously in terms of, you know, when I do speak to, you know, my respective counterparts in different companies in that, you know, really, I wanna see your file. You wanna see mine. And so not to say that we're start passing logs, but it's really just that kind of drive towards we really do need to see, you know, what's happening in your space and, of course, vice versa. I think it's one of those things where it's very much a I'm smart because someone has to go first to then say, well, actually, yeah, I'm smart because and he obviously tells from there. So I think to really put a step forward, and that would have massively changed, I think, in terms of the retail sector's ability to operate. Obviously, we saw very different responses from, for example, just pulled the plug as been reported or MS who who took a different approach. But, ultimately, we really do need to move forward with sector intelligence sharing. If anybody hasn't spoken to me before, then, again, clearly, we're doing something wrong. Right? And so please, after this call, you know, please join a LinkedIn similar because there's lots of sharing circles we can, you know, get involved with and and share intelligence together. Agreed. I think that's super important. Kinda moving along, I do have a question for Jay, bringing Jay back into the mix. Is, you know, as far as recommendations go, like, can insurers ensure collaboration across, you know, teams like claims, fraud, incident response, the SOC, and third party so intelligence doesn't just stay siloed. Yeah. Great question. So this has been a hot topic for, you know, not only, you know, the the companies in in insurance, but but widely widely spread. Right? I think if Antti did a study and say that, on average, takes about six years to to break down silos between, you know, internal cybersecurity, and and and IT departments, right, which is a long time. So my answer to that and, you know, my answer to that, not only, you know, the customers and prospects that I work with here at Finagran is the the use of OpenCTI and workflows with an OpenCTI always helps. You have the ability to, you know, automate a lot of, the the the jobs that that people are doing. But not only that, you can assign tasks and work off of one place. What that means in in practice, right, is you can create something like an instant response case. You can have your threat hunting team, your instant responder, your SOC analyst all working off of one case. You can assign those tasks. And what that does is to slowly break the and I'm not saying that that is a a one solution that fits all. But what it does is it starts to enable the, the, yeah, the breakdown of those silos. If you're working off one place and sharing information between teams and you're not having one team sitting on email and one team in one product and, you know, the other team working off Excel. If you've got one place to store all of that information, I find that that can be very useful to, you know, reducing that six years because that's that's a long time to to kind of fully break that down. The other thing that I'll mention around that that question, right, is if these departments tend to be siloed, what you see is an increase in time of people responding. If they're not aligned and working in in the same direction, if an incident comes in, you know, between the the incident response case getting created and, you know, the the SOC team or, you know, the the detection team seeing the results of that incident, if they were working in different products and places and processes, it takes longer to actually get a proper response in, you know, within the company. Mhmm. Awesome. Thank you, Jay. Another question for both, you know, Darren and Jay is we hear a lot about analyst overload. So with so much information coming in, how do you help your team work faster and explain things in a way that leaders can act on quickly? I can jump in and answer some of this question. I don't think Darren heard that one. Choice of technology. So I suppose, from from at least my perspective, we, Filigrand, try to prioritize the data within, you know, OpenCTI and OpenAEV. We have something called priority intelligence requirements. So it's all well and good having these products and all of this information. But if you are, you know, not prioritizing this data in the right way, it it's just kind of pointless. Right? Because you have all of this information to hand, but what matters? There there's a saying that, you know, if everything is important, then nothing is important. And I think that that still goes for the, you know, the the CTI practice. Because if you're not prioritizing this data and kind of going, well, what do I act on? What is important to me today, this week, in the next month, tomorrow? Then I feel like you're not kind of, you know, reacting as as well as you could be. Now, you know, what's the other part of the question? Yeah. So getting information to to to leaders is is always been a hot topic for for customers and and prospects that that I deal with. I'm sorry. I have to talk about AI again, but, you know, while the the threat actors are using AI to help them, we at FiddleGround are using AI to help our customers and prospects. Right? We want to, you know, be able to increase that mean time of detection and response, and the use of AI within our products really does help with that. Not only does it help with that, but it allows you to kind of target your audience. Using AI, you can set the tone and, you know, it's not just something that we can do. But when you are doing this with, you know, threat intelligence within, you know, OpenCTI that you have collated, that you pay for from open source, you know, that's come from internal security systems. It really enables you to aim that, you know, to to the right people. Whether you're talking strategic or, you know, down in the weeds with, you know, IP addresses, it really allows you to hasten the the the response time of, you know, the the CTI practice as a whole. Awesome. Okay. So in terms of you know, there's always gonna be more work, and there's always gonna be more analyst overload. I say there's always gonna be more analyst overload. There shouldn't be more analyst overload. I think it all comes back to fundamentals. So PIR's case in point. I mean, ultimately, do you really need to deal with that vulnerability hand grenade? If so, it's providing value for money. Absolutely all day every day. However, if you feel that ultimately, if you are the vulnerability person, then ultimately, so be it. I'm sorry. But if there's an automated process that you can do instead, and you may have a vulnerability management team, then fantastic. You could potentially API that problem away to ensure that, ultimately, the stakeholder matrix that I think everybody should have to really showcase who do I need to support in the best way possible. Most people, that's gonna be, you know, your sizes and similar. Right? Ultimately, they're paying the dollars, and they're they're paying salaries. The same time, though, there's always other parts of the business who aren't just as important. Maybe not just important, but similar too depending on the type of operation ultimately you're involved in. Same enough. You know, do you really need to deal with the IOC? Potentially. Potentially not. And so I think that that cost benefit analysis that is definitely worth doing to say, well, actually, is this worthy of a threat intelligence analyst time? And if so, then great. You know? And I think sometimes we could all get in the the cycle of the self licking ice cream cone, you know, to to quote a sans. But but it's really true in that just because there's information doesn't mean we have to do anything with it. Whether that's a case of because we don't have teams in play to actually operate on that intelligence action intelligence. Sorry. Or whether it's just a case of, well, actually, there's only four hours in a day. I have two team members between us. Therefore, we have to deal with this and this alone because the impact that that's gonna have compared to a vulnerability that may or may not impact us. So I think cost benefit analysis, stakeholder matrix, and PIRs are really how we deal with those problems rather than assigning each other. Awesome. Moving along, again, a lot of great questions today. This one's for Jay, and it's kind of on the topic of resilience and readiness. How to make how to make sure that your security defenses actually work before real attackers have the the chance to test them for you? That's that's a great question, and it's it's a hot topic for, you know, for the ground as a whole, you know, last year and this year. But I I feel like a lot more people are starting to take their security in a different direction. Being that proactive cybersecurity kind of fundamental like security kind of fundamental to kind of sort out, thing to you're kind of defenses rather than, you know, reacting. Now we see a lot of uptake in, OpenAEV product, which essentially allows, you know, people to take their threat intelligence from OpenCTI, translate that into, you know, threat actors and injects, and then run that within their their environment. What that allows them to do is to then go, well, how did I react to this? How did my EDR react to this? How did my SIEM solution react to this? So what what that allows the the company and then the the CTI team and, the rest of them to do is go, well, if we didn't react to this, if this was to happen in real life, how much trouble are we going to be in, and what do we need to do to resolve that? Is this assault typhoon with the Cisco router that is no longer supported that we need to rip out, or or something else? So it's it's it's it's really being proactive in in in the testing. And I guess lots of people are doing, you know, pen tests, really sitting down and working out what these threat actors are doing and the different injects and ways that they're trying to get in is really, really useful for companies to start being more proactive in in their security reactions. Awesome. Awesome. And, kind of a a question, for the both of you, I guess, is, like, when gaps are identified, do you have any recommendations for feeding that back into your intelligence requirements so that it becomes a continuous loop? Yeah. I think for me, I I think it's part of that process, right, in terms of PIs and similar. So if there is, for example, a collection gap, then, again, there must be a way to compare against, you know, for example, your current collection, for example, whether that be a collection framework or similar. Everyone's a different. There's currently kind of no standard, but there is a standard, but it's not a standard. So that's lots of fun. Again, I I think ultimately, it's the feedback loop. Right? It's the int cycle in a nutshell in terms of everything should be feeding back into that direction, which is courses, UPIRs, and similar. So, ultimately, the loop itself solves that problem. But, again, you've actually gotta do the loop to to solve the problem, which sometimes people do. Yeah. I, I don't actually have much to add to that because, you know, Darren hit the hit the nail on the head again. You know, that that threat intelligence life cycle of of ingesting data, correlating, disseminating, and all the kind of lovely stuff part of that is, you know, is that life cycle and yeah. He's he's doing good. Awesome. No. This is great. Again, super happy to have you guys on here. And, you know, I do have one before we head over to q and a, I do have one kinda closing question for the both of you. If you had one piece of advice for the audience on this on this webinar and just teams that are preparing for the rest of 2026, what would that be? So for me, it would be to go again, going back to fundamentals. Right? The information advantage. For anyone to be don't go on. I'm not ex military. I've got lots of people around me who are ex ex military, and they're fantastic. And they always say about the information advantage, and I absolutely love that. And it's so true. And it's really about what do you know more than ultimately the attacker does. So for example, do you truly know about that s three bucket that's hanging out there on the Internet? Because if the attacker does first, then they're gonna you're gonna have a bad day. And that's really, I think, to me, what that is about, what I feel that is about. And I think it comes down to situational awareness and that you really need to know ultimately. From a threat intelligence perspective, you can only make an assessment on what you know about. At the same time as well, you can only really consider bias and, you know, ACHs and similar if you know about every single mitigating factor coming back to I always speak to people with intelligence around, obviously, securing your house. Truly, you don't care what their name is. You just wanna stop the burglar getting in. So I think from that perspective too in terms of prioritization of the information advantage, if I know I've got my key under that mat, does the attacker know? Well, most people know to look under the mat. Right? However, at the same time, if there is suitable steps in this in a way to result ultimately, you know, mitigate an attacker from from identifying that, then great. Actually, that might be a good place to put your key, where it'd be a fake rock using some kind of deception or, you know, potentially even counterintelligence. Or if you're like, some people I know then start collecting lots of data, which may be against some sort of illegally somewhere, but nevertheless, they were in a fantastic position to identify any would be attacker. But yeah. So I think for me, it would be the information advantage and really gaining awareness of your current environment. Awesome. Jay, what about you? It would help if I could find the mute button. I very much like the key analogy. I I I feel like, another way around that is to buy lots of different types of keys and hide your lock and see, see see if they can guess which key they need to use. Yeah. For me, it's it's kind of short and sweet, to be honest, and it's, again, a a big point for us here at Filigram is, you know, that that proactiveness in in cybersecurity rather than reacting to to the incidents. It's how is my organization going to respond to this? What do I need to do to make sure that these threat actors, you know, at least in this standpoint with the knowledge that I have, aren't going to get in? So that proactiveness for me is, and I feel like Filigram as well this year, is very, very important. Awesome. No. Thank you guys very much, and, you know, that's super helpful. Again, a lot to look forward to in the next year. The landscape is always evolving, so best to stay ahead of things. Moving along, I would like to, you know, end the end the session today with a little bit of audience q and a. Again, for anyone in the audience right now, if you do have any questions for Darren and Jay, they're great at answering questions. They're a wealth of knowledge. So please go ahead and add that in there. We did have a question on in UK for claims. The insurance fraud bureau do a great job. Do they work with cyber organizations? Sorry. Do you mean cyber organizations is in Filigran, or do you mean organizations that have cyber teams? Because from my perspective, there there is. Without going into the the increase of in terms of sharing across the industry, I would say we well, I would say parts of business do work with the IP, of course, as as naturally as you would expect. But at the same time, I think, ultimately, with cyber enabled crime, we are definitely gonna see an increase. When I do speak to people, there is more opportunities to work with them and work with, ultimately, you know, four teams and similar. Right? Because of the the vast experience that really cyber people may or may not realize they do have compared to a front of house fraud person who'd be looking for more your historical type four, really. So I think yes. And if it's not yes, it definitely will be yes soon. As I say, because of that more cyber enabled fraud, the people really are starting to see, therefore, they're starting to ask ultimately cybersecurity teams more questions, which ultimately, think is fantastic. I think in the days gone by when it was, you know, information security and similar, they there was definitely a siloing effect from what I've seen from companies having done pen tested them too. So I think we are starting to see the combination of your tools can be a benefit to me. My tools can be a benefit to you. So we are definitely seeing that for sure. Awesome. Thank you, Darren. We have another question. Do you have any tips for influencing leadership when the threats don't feel urgent yet? So there there's lots of different ways to play this, actually. So in terms of when the fix don't feel urgent yet. So for example, if you were I don't wanna say cop, but if you were a a retail or retailer within The UK as of April, May, that's definitely a good way to make sure that the threats do feel urgent because, ultimately, I think that's a fantastic way to really showcase and really bring a narrative to the understanding of whether it be leadership, whether it be board, or who whoever you report to or whoever you provide in terms of products to. Everyone compares themselves to everybody else. Right? And it's no different in the whole organization too. So I think, ultimately, if your competitor has been compromised in some fashion, then, ultimately, that is gonna get people looking at that straight away. Right? And same time as well, in terms if you use the same tech stack, I think great. Example, we had the big movie issue in 2022, I wanna say now. Everything feels a blur. You've been in cyber long enough. You feel like everything's yesterday. But, yeah, I mean, there was thousands of organizations, you know, across the planet who were impacted by that. Similar enough just like we saw with, sales often similar. Thousands of organizations. So I think that if we start to see that on a sector, then great. Every other retailer would be thinking, actually, you know, is this gonna impact us too? And then four, you know, that really is gonna change directly as result of that. And I think, really, that's where threat intelligence really does come into its own, ultimately informing decision making. And if you didn't have that to begin with, then, ultimately, you know, what's gonna lead that drive? And, yes, you can say the BBC and similar. However, the BBC only knows so much. And, really, they don't know about x company that is hanging off of, you know, your estate that's just been compromised because of their relationship with some other company. And similar with vulnerabilities too. Right? Same same exception there. Awesome. Thank you, Darren. We talked a lot at the beginning of this about, like, different threats and, you know, things that were coming to light in 2025. Are there any particular threats that really flew under the radar or teams still aren't paying enough attention to in your opinion? For me, yes. I mean, quite quite ironically, it it's the big three. So when you think identity, you know, you look at Mandiant, you look at Verizon, you look at any of the big reports that are coming out nowadays, identity, finger, ear, and stats sort of, know, 95% of stats are made up on the spot. But let's say, you know, that's roughly 30%. Right? You look at vulnerabilities as well. Again, that's 34%. Okay. We're looking at phishing or social engineering too. Again, that's another, like, 20 ish percent depending on who you look at. You're pretty much covering 80% there. And so if you were to say, actually, I've only got £5 worth of budget. Obviously, it's a bad day for you, but nevertheless, you've £5 worth of budget. I don't know why I say five. It would have been far better to say 10. So let's go with 10. £10 worth of budget. Well, actually, I'm just gonna put those, that that respective budget towards those particular items. And, again, you're playing the odds. And don't get me wrong. You don't wanna be playing the odds. But it really showcases how we do really need to delve into those problems in particular. And something that I I showcased in conference only a few months ago was around collecting information, information stealers, identifying exactly where their geo locale, and actually seeing how big your footprint is. So for example, third third party help desks and similar. Generally, on-site, probably gonna be in India. Same as well. Developers, you're looking at, you know, some of the Baltic States or same time in South America. So, again, you can start to see geographically even though you're a might be a UK company, you know, where you do need to start looking at potentially even Geoblocks. You know, even they're still a thing. They do still work. And if you are just a UK company who has only one remote worker, then god bless you, you know, geo blocked that to death, and you're in a fairly good position. But yeah. So I think we do still need to really delve into those because it's too easy to say AI, quantum. Quantum's gotta come at some point. Right? And it's probably gonna scare life out of everybody. And I think, to be fair, quantum resistant ciphers and similar are a good thing. But I think the day to day, what you're being attacked by right now should be front and center of most decisions that you make. For sure. Awesome. Thank you, Darren. Wanna give just another minute. That's it for our questions right now. I'll leave it to the audience. If you do have any other questions, please feel free to leave them in the q and a tab. And if not, you know, that we can just go ahead and wrap things up. So on behalf of myself and our team here at Filagran, I'd love to thank you for taking, the time to attend the session. We really hope you enjoyed it. Thank you. Special shout out to Darren for, taking the time out of his day to speak with us and bring his valuable insights here. We very much appreciate it. There is a survey that I'm going to launch to the audience right now that's just gonna ask you a little bit about how you enjoyed the session and ask if there's any topics that you'd like to see us present on in the future. Any feedback is greatly appreciated, and it'll help us improve our webinar program moving forward. Again, this is our first one of twenty twenty six, and we have a lot more to come in the future. So, hopefully, we can bring the most relevant sessions to you all. So on that note, thank you again for joining us, everyone, and I hope you have a great rest of your day. And best of luck moving into the rest of 2026. Thank you all. so much for listening. Chisel. Thanks a. lot. Cheers.