Fault Lines With Rod Whiting
Fault Lines is a clear-eyed series of conversations about security, resilience and preparedness in a changing world. Rod Whiting cuts through the noise to explore what this means for Britain — and how ready we are for what lies ahead.
Drawing on four decades in broadcasting, including 25 years with the BBC, Rod brings a calm, questioning approach to complex issues — focusing not on alarmist headlines, but on the forces shaping events and their real-world consequences.
Each episode features informed, measured conversations with experts in defence, intelligence, emergency, and related fields. The aim is not to alarm, but to understand: what’s changing, where the risks lie, and how individuals, communities, and institutions might respond.
Fault Lines is produced alongside Rod’s Fault Lines Substack, where you’ll find further analysis and commentary exploring the same themes in more depth. 👇
https://rodwhiting.substack.com/
Fault Lines With Rod Whiting
AI And The New Cyber Threat - with Jamie Collier
Artificial intelligence is changing the cyber threat - not simply by creating new risks, but by allowing criminals and hostile states to operate faster, at greater scale, and with increasing sophistication.
This matters across the whole spectrum of digital activity - from government departments and major corporations and small businesses to essential services and individual families.
In this episode of Fault Lines, Rod Whiting speaks to Dr Jamie Collier, lead advisor at Google Threat Intelligence Group, about what Google is seeing at the sharp end of the cyber threat from its position at the heart of the global digital ecosystem. They discuss how attackers are leveraging new tools to improve their operations, moving beyond simple automated scams.
One specific area of concern is the evolving phishing tactic where criminals spend days building trust with victims before making a move. This approach to social engineering marks a shift in how hostile actors operate online. Jamie explains why defenders still hold distinct advantages and why practical steps, like multi-factor authentication, remain effective defenses for businesses and individuals alike.
For individuals, businesses, and governments alike, Jamie’s message is a useful one: prepare rather than panic.
Fault Lines - making sense of a changing world.
Contact: rod@rodwhiting.com
For more analysis like this, visit Fault Lines on Substack: 👇
https://rodwhiting.substack.com/
Contact: rod@rodwhiting.com
How AI is changing the cyber threat
SPEAKER_01Rather than actually just sending a one-off phishing email, I'm actually going to build trust with you over many days, I'm going to have a conversation with you, I'm going to use research to actually kind of build a reason for getting in touch with you. And it's only then, after a few days, that I kind of send something uh malicious.
SPEAKER_00Artificial intelligence is changing remarkably quickly. But while most of us are thinking about how it might change the way we work, communicate, or search for information, there's another race going on, largely out of sight. Cyber criminals and hostile states are using AI too. And according to the latest research from Google's Threat Intelligence Group, the way they're using it is beginning to change. From AI simply helping people carry out attacks towards systems capable of doing more of the work themselves faster and at a much greater scale. So what does that actually mean? Or does AI fundamentally change the threat we face or simply make existing threats more effective? Who needs to be concerned? What can we, as consumers of information, do to limit the potential damage? And importantly, can AI also give the defenders an advantage? Well, Jamie Collier is a lead threat intelligence advisor at Google Threat Intelligence Group where he works at the sharp end of understanding how these threats are evolving. Jamie, welcome to Fault Lines. Hi Rod, great to be here. Very good to have you with us. Jamie, like a lot of people, I use AI and I can see its enormous potential. But I'm not sure most of us appreciate just how much it's already shaping our online experience. So why should we care about any of this?
SPEAKER_01Well, I I think on the on the fret side, we see that AI is really transforming the fret landscape. I think first of all, we see that cyber fret actors are moving with much much more speed. The time between, say, a patch being available and that being turned into a workable exploit, that shrunk from well over a month to now a matter of hours. So we see much faster exploitation. We we see a lot of these cybercriminals really moving to a kind of a speed-first model, given the advantages that has when you're trying to extort a victim. I think there's also huge scale. You know, we we we we see this increased uh affordability of persistence. If if I kind of go back a few years, maintaining network persistence, well, that's a that's a complex, really resource-heavy operation. It was effectively the exclusive hallmark of a state-sponsored actor. Now we see much kind of cheaper ways to do that, and that's going to scale out a lot of those lower-tier actors uh that can now run more persistently. Um and then we also see kind of increased sophistication. We see for actors becoming much more adept at uh researching vulnerabilities, finding workable exploits. Uh we we we see far more efficiency in social engineering and building trust with uh targets. We see malware modifying on the fly based on the situation it is in. Uh so you throw all of this together, and it's it's really important that organizations and leaders appreciate the way that cybersecurity is going to be a really important part of the conversation going
Russia, China and state-sponsored cyber operations
SPEAKER_01forward.
SPEAKER_00Well, I I I think that the general uh public awareness is is starting now to sharpen up a bit. I mean, we we had the issue with uh Jaguar Land Rover last year, and uh that's widely reported as being uh the the um uh the response of an a hostile actor. I mean, taking Russia as an example, uh I read a figure yesterday, you you probably know more about this well you will know more about this than uh than I do. But uh the spend, the annual spend for Russia on on uh this kind of activity is something like £1.3 billion. And we're talking about thousands of people being involved in the in their uh disinformation uh and and cybercrime uh industry. It is an industry, if you look at it from that perspective. Do you think people are s uh are aware of this the constant threat we now face as a as a society?
SPEAKER_01I mean I I think it depends who you talk to. There'll be people in the security or the intelligence community that completely see the way that cyber operations are being embraced by effectively any intelligence agency or or military uh around the world. And ultimately, these operations don't take place in a vacuum. The cyber operations we see from Russia or China nexus groups reflect broader strategic objectives of those uh states. There's a very clear line between Russia doctrine and the way that they conduct uh cyber operations. Um but on the other hand, maybe there are people that aren't necessarily seeing all of that firsthand. You know, we're really lucky within Google that we we do a lot of the incident response. We're you know, we're doing a lot of the incident response in Ukraine, for instance, getting Russia out of those uh networks. So we get this kind of front row seat to a lot of those operations and we see just how serious they are. Um but maybe for the for people that aren't in this world uh that they maybe fail uh certainly don't appreciate just how how many intelligence agencies are now pivoting uh to cyber operations in in different ways.
SPEAKER_00So I think we're getting a sense then of why this matters. This affects all of us, right?
SPEAKER_01Yeah, it it does. I think you know the these operations they they threaten our online way of life. If you if you look at UK extortion operations, you mentioned JLR, uh MSD, these big in incidents, you know, we we saw the victim impact that had, and it wasn't just on the individual organization. I mean JLR actually uh influenced our kind of macroeconomic forecast, kind of took off um, you know, kind of percentage points off off kind of certain UK economic figures. So it just showed how macro the scale could be. And I think there are also interesting ways in which we see cyber operations blended with other other types of operations or can be psychological in nature. If if I go back to the onset of uh Russia-Ukraine conflict, for instance, we would see that actually Russia would try to target Ukrainian banks, uh, take them offline, send text messages to Ukrainians telling them that their banks were offline. And if you think about that in the context of an incoming invasion, if all of a sudden you're questioning the integrity of your financial system, you can see that that can have a destabilizing effect. So so we really see that actually these are often being blended with physical operations, they they take place in a broader context. That's always really important to appreciate.
SPEAKER_00And one of the purposes of of fault lines really was to raise the awareness level of of the of the general public, I mean people, uh to the scale of the of the threat that we face. And and it's important to qualify that. It is a threat. It's not uh, you know, we don't want to be alarmist about this or too alarmist about it, but by the same token, we know that uh that this hostile activity is taking place. We know that our uh institutions are being tested daily. You'd know better than me. But and and it's a bit like the old espionage um meme, isn't it? It's uh y y y you know, um they have to be lucky every time at thwarting an attack, whereas the the the hostile actor only has to be lucky once to create uh real chaos.
SPEAKER_01Yeah, there is some truth in that. I mean, that that's something that's often said about cybersecurity. The attacker only has to be right once. I think the only thing I would say is if you kind of flip that round, there is a lot of d defender's advantage as well, that the attacker doesn't have perfect insight into your network. Uh they are maybe at times kind of relying on guesswork, they've got to figure out how to navigate through this network. Whereas as a defender, you you effectively have a lot of cards to actually configure that network, put in the right blocks. You know, if you if we think about for a cyber operation to take place, for let's say a Russia actor to actually compromise you, they've got to get access to that network. They might have to move through that network, find the most interesting areas where the sensitive data is held, figure out how to exfiltrate that data, send it back. Um so there are opportunities to actually insert multiple uh kind of hurdles, as it were, and make it as difficult as possible, as high friction an environment as possible. So we do
The defenders have an advantage too
SPEAKER_01see that I think I think there is a there is a lot of a lot of damage that attackers can do. But if if defenders appreciate that they have those opportunities to insert multiple hurdles, and a big advocate, a big thing that we're uh we're advocating is a threat-led view that if if you want to be really good at security, you ultimately need to go, need to know what you're up against. And if you are the sort of organization that is worried about a GRU or SVR style actor targeting your network, well, the good news is we know how those actors target networks. We know how they move through the networks. We have all of that threat intelligence. And it can seem a bit doom and gloom talking about the threat so much, but the reason we do that is actually to empower organizations because if they have that information and if they know at a tactical level how these actors are gonna move through a network, then we actually find that they can be really proactive at inserting the right controls to stop those attacks being successful in the first place, but then be even more proactive in actually effectively hunting for those threats, assuming that they got in. What where what are they where are they gonna go next? And kind of constantly searching for these threats. And that can be really kind of transformative for defenders as well.
SPEAKER_00Well, I you you've touched on an important aspect of this, which is trust. Um I mean, we put all our trust into the networks, into the the tech networks that that uh operate all of the systems. I mean, Google Chrome is a great example, you know. It's um it's used by billions around the world. And we I well, I s I just speak from my own perspective. When I go online, um as I am now speaking to you, I I trust in your organization that it's going to be safe for me to do so. Um but I think it's useful actually to actually raise awareness of the fact that of the work that's going on behind the scenes to make that a reality. It's a lot of responsibility on your shoulders.
SPEAKER_01No, it is. And and I it's also a belief of mine. You know, we might talk about what can people do about these sorts of threats, but it's it's a big belief of mine that actually as much of this should be invisible for a lot of people. If I'm a lawyer or an accountant, I need to be vigilant about my security. But I've also, frankly, got better things to be getting on with. You know, I've I've got deadlines, I've got bosses to please, clients to deliver for. Um and and frankly, a lot of that, as as much of the burden as possible should be taken by security teams, by policies that actually empower people to be getting on with their roles. So that's a big, a big kind of passion point of mine is how do we make this kind of low friction for people? You know, I think I think most people listening to this podcast would probably view their cybersecurity team as the fun place, right? The ones that are stopping them opening certain links, that are kind of making them kind of into annoying security keys into their laptops to log in. And we want to make sure that we're only doing the security controls that really make a difference. If if we think about something like a physical security key that you plug in uh as part of your login, that wipes out 90% of the kind of threats out there because it just makes it so much more difficult to gain access to your environment. Whereas, you know, may maybe there are other security controls that I've introduced extremely high friction into my workflow, my day-to-day life, but maybe aren't moving the dial as much. So I always think as security professionals, we should be asking how can we make this as easy as possible? How can we have security by default settings that mean that we don't have to kind of go and change everything out of the box? It certainly when we talk at a cloud level, that's that's really a big priority, is making it as seamless as possible to be secure.
SPEAKER_00Yeah, because um uh speaking from experience, I mean the the the more complex the security system is, the less likely you are to engage in it. Um I think most of us are starting to get comfortable now with the two-factor uh security system that we have for things like social media. But you've always got to be one step ahead of the threat, haven't you? And and and it's it's being so I I guess that does take us really into, you know, the the issue of who should care. I mean i I think most uh organizations now understand the threat, but we've all got to be aware of it, right? Because if if one part of the of the defense falls down, that that makes it easier to exploit. I'm guessing. I mean, I'm that or if I got that wrong.
When AI itself becomes the target
SPEAKER_01No, a absolutely. And and I think the other the other thing right now with what's going on with the AI threat landscape is that just things are moving so quickly. And that we're we're really having to rethink our approach of uh security. You know, as I said, we see some of the most sophisticated actors using AI. If we take a group that we track, like Sandworm Relic, which is kind of associated with uh the GRU, you know, if that is if that actor is getting into your network, that is really bad news. This is the actor associated with taking down uh disrupting power availability in Ukraine, disrupting the Olympics, you know, they're now using AI to automate their kind of workflows, to uh develop militia scripts, uh for instance. So when when the most serious actors are kind of embracing AI, um we we need to kind of understand how does that change the threat. I think the the other piece of what is changing right now is I think we I think we're if we look at where the conversation is going, it's probably largely focused on how threats are using AI, and that's the conversation we could have. We also see that threats are now targeting AI. If if any organization is is using AI in their environment, that potentially expands their attack service. We actually see China Nexus groups that are now trying to steal companies' AI research. They realize that this is really valuable intellectual property. Or if you take AI coding assistants, they are often bringing in a load of different tools. So rather than actually target an organization directly, a lot of threat actors are now trying to poison the kind of open source, the readily available tools that these AI coding assistants are bringing in. And by doing that, they're effectively infecting something that's becoming into an organization and kind of doing effectively conducting a supply chain compromise. So I I I think with all of these things, we see threat actors innovating on the one hand, and we've got to stay ahead of them, and we we need the up-to-date threat intelligence to really understand how threats are embracing these technologies. But we also need to understand how the technology itself changing the attack surface is, changing what it what vulnerability looks like. Um that is you know, perhaps depressingly, a process with no finish line. Cybersecurity, like many elements of security, it's a constant iterative process. And and we I think we need to see it as a as a series of practices that are effectively running constantly, rather than something with a kind of clear-ang goal where we'll be secure and won't have to worry about it again.
SPEAKER_00Which which brings me to I think what is probably the the most important thing from from Faultline's perspective, which is uh how do we well, you know, what can we do about this? And and for me it's it's all about redundancy. It's it's uh it's what happens, you know, it's what if is asking yourself, what if? What if the bank gets taken out by a cyber attack? Uh what if the power station gets taken out by a cyber attack? What what if you your transport system is is taken out? That's the thing. It's it's it's what redundancy can we build in? What can we do as individuals uh to lessen the impact and and organizations, businesses, you know, to lessen the impact of of the worst happening and and the threats actually getting through this the security system.
SPEAKER_01No, absolutely. And you know, there's a number of different ways to address that. I think in terms of what can we do about it, I I think for most individuals listening, it's about a few number of small number of really simple steps. We've talked about multi-factor authentication being one of the kind of most outsized impacts you can have. And and for most people, having a few practices like that, not reusing passwords, having multi-factor authentication is going to really kind of move the dial. Um and then I think I think obviously a lot of this is going to be done by kind of security organizations. I think
What can we do — and how Google is fighting back?
SPEAKER_01within Google, we we actually believe that, and and Google threat intelligence, we believe that we can play a really active role in actually disrupting some of those threats. And I think I think right now we're in a really interesting uh space where there's a lot of private threat intelligence going out, and we there's a lot of visibility that the private sector has into cyber threats, given all the incident response work and all the visibility of these networks. And that gives us huge opportunities to actually take down a lot of the infrastructure. You know, frankly, a lot of threats are actually going to use Google infrastructure. They're going to be sending malicious emails from uh Gmail accounts they've created or malware that's hosted on Google Drive, for instance. So actually, we're taking a much more proactive view of taking that threat intelligence that we see of of threats we're observing when they're using Google infrastructure, actually kind of disabling that at source. A lot of this is also applying in the AI space. So one thing that we're also doing is strengthening AI guardrails. If if we look back a few months, there was actually a China Nexus operation that initially tried to use Gemini to get information about how they would compromise a target. Gemini uh did what it was supposed to do and didn't give them kind of valuable insights. But then they then the actor basically said, Oh, I'm actually I'm a student and I'm in a kind of capture the flag hackathon competition. So this is all innocent, and then all of a sudden Gemini started maybe providing uh some insight that we would hope it didn't. So that is a kind of constant, constant game of iterating. And as we see this guardrail was bypassed, we're then having to update those kind of those guardrails, those model classifiers, all of those sorts of things. So it's really important that we have that kind of fret-led approach uh there. We're also taking kind of legal action against a lot of these uh adversaries, try and take down infrastructure, you know, and and and do that as a community. But that though those kind of forms of uh action are very different to say what we would see from UK government, where the likes of NCSC putting out a lot of really good security advisories, you've got the government cyber coordination center that is running kind of effectively weekly hackathons experimenting with AI and probably moving faster than almost any other government in kind of embracing and experimenting with what frontier models can do. And then you've got the the AI Security Institute, which is providing you know, it's it's become a kind of global leading authority in looking at a lot of these models and what they can do and providing kind of really cutting-edge uh security research. So I I think it's a fascinating time for public-private partnership. It's a it's a fascinating time given the different contributions that that different bodies within government and private sector can make. And I'm actually really encouraged by what I see uh within the UK.
SPEAKER_00That's really interesting. And it's it's really encouraging, actually, to know that that you know we have agencies uh within our own system that that are are looking out for this. Um I I guess they they understand the the the stakes uh involved in this. Um as you say, the the threat is real.
SPEAKER_01Yeah, no, absolutely. And I think it's um it's probably since I I I began working in cyber threat intelligence, it feels like it's the the fastest moving it's ever been. Um obviously we see that playing out in very different ways. I think in I think we're probably a bit lazy in just talking about how AI is changing threat, when actually the way it would change a state-sponsored actor coming out of Russia is going to look very different from, say, a cybercrime group. We might see these actors use AI in in very different ways and embrace the technology in in very different ways. But I I think all of that just means it's it's a it's a time where um num number one, we need to be really kind of focused on having a really dynamic picture and that we're constantly being kind of fed new information and um w we need to be able to kind of change our security posture, change our kind of policy, frankly, based on where these things are
Cutting through the AI hype
SPEAKER_01moving. I also think that with all of that pace, it's probably one of the most distracting times. And I think you know your listeners, even if they're not interested in cybersecurity and AI, they probably can't help but see that there is a new headline on this every single week. And we're kind of constantly told of the next thing that we should be fearful of in terms of how AI might be used maliciously. I've I always feel maybe it's just because of my kind of threat intelligence background, that that we need perspectives that cut out a lot of that noise. And and and what we generally see is that there is a big delta between what is hypothetically possible and all the different ways that frets might emphasi emphasize and embrace. AI and the ways that they're actually doing that. And so a lot of what we're doing is we're actually there's other parts of Google that are thinking about the hypothetical threats from AI and the controls, et cetera. But what we're focused on within Google threat intelligence is looking at what are adversaries actually doing. And I think right now, for any organization, any kind of individual that's worried about these things, probably a list of kind of 50 different hypothetical concerns, but maybe actually a much smaller list of what what are the actors, what are the threats that you're worried about? Are you an organization that's worried about ransomware and cybercrime? Are you an uh organization or an individual that's going to be targeted by the GRU or the SVR or a North Korean intelligence agency? And then actually look at how those specific threats are using AI. And all of a sudden you actually get a much more focused list of issues to work on and defend against. And again, kind of going back to the conversation earlier about how threat intelligence can be empowering. I think the one thing it provides that one of the most valuable commodities right now is focus. And I think that is where you know threat intelligence, regardless of whether you're talking about cyber or threat intelligence in other spaces, it can provide real focus. And I think that's something that we see a lot of organizations kind of really needing to lean into at the moment because of all of the distraction and hype out there right now.
SPEAKER_00Gosh, that's really interesting. And uh well, uh we it which brings me back. I think we'll finish with this, it which is um for for people who are watching this and thinking, how how is this how does this relate to me? I'm finding it really interesting. I I'm pleased you you you've outlined uh the the extent of the threat and and how it's all about relevance, depending on the kind of individual you are and the kind of organization you are. But for the general um uh public uh
Prepare, don’t panic: what it means for you
SPEAKER_00we just need to be aware, don't we, that that people are trying to take down institutions, banks, um travel hubs, uh government organizations. So we just need to be a aware of it, and as you say, awareness is is half the battle, and then build some redundancy in. So if if when it comes to the bank, make sure you've got up-to-date statements uh in paper somewhere or on your laptop somewhere. Um make sure you've got some cash to get you through in case uh the tills go down. Uh make just make sure that um you you can get to work, that there is an alternative. Uh all of these things, I guess, um which we we're constantly pushing. But it's difficult, I think, for for people to to warn about these threats without causing alarm and without causing people to put their fingers in the ears and say, oh, not this again. That's the challenge for us, I think.
SPEAKER_01Yeah, it's a kind of prepare rather than panic message, I think, for for most people. Um we we see a lot of organizations doing a great job of this. You know, we've we've seen increasingly cyber threat actors targeting what we would call operational technology, the kind of the systems interacting with physical processes, you know, water treatment facilities, power plants, etc. There is a lot of security uh concern in that sector, but there is also generally an ability to segment those physical processes and have ov manual kind of overrides. Um that sort of mindset is gonna be really important. I think maybe if for f for listeners that aren't kind of as involved in the security industry, I think also appreciating the the change the change in in the way that for actors will try to build your trust and the kind of the changing nature of social engineering is gonna be really important. Um I think I think uh people probably understand that AI will create better phishing emails, right? That all of a sudden we can have phishing emails that don't have horrendous spelling mistakes in, etc. Yeah. We also see now for actors moving to what we would kind of call rapport building. So rather than actually just sending a one-off phishing email, I'm actually gonna build trust with you over many days, I'm gonna have a conversation with you, I'm gonna use research to actually kind of build a build a reason for getting in touch with you. And it's only then after a few days that I kind of send something uh malicious. So I do think that we're gonna see um more of those up more of those types of things that people need to be aware of. But ultimately a lot of those sort of operations will be quite focused on a you know small number of individuals as well. So I think it's about having an appropriate response to this. For some people, they want to get on with their lives and they want to take a full small number of steps. Other big government or private sector enterprises are going to really need a much more mature posture using threat intelligence, leaning into AI for security and defense, and really kind of elevate their posture. And it it's just about picking that appropriate level, depending on who you are, who you're being targeted by.
SPEAKER_00Fascinating. Jamie, I'm I'm I'm grateful for your time. Uh uh I think what I take from this is great reassurance, actually. Certainly the Google threat in intelligence threat people are doing as much work as is going on, and also our own government um and and agencies here in the UK are doing so much work. The other thing we take from this is that it is relevant. We do have agency as as individuals by being careful about our own security and having that redundancy built in should uh these threats come to pass. So, Jamie, thank you so much for your time. Uh much appreciated. And thank you for uh watching and listening to Pop One.