Rik Ferguson, VP Security Intelligence at Forescout: “You cannot protect what you cannot see”

Rik Ferguson is one of the most recognised names in internet security. He describes himself as a “30-year veteran” and he shares some of his battle scars in this interview – including his take on the role of governments when it comes to cybersecurity.

Rik is now VP Security Intelligence at Forescout, which helps to keep countless well-known names in the Fortune 500 safe. He’s also a founding Special Advisor to Europolโ€™s EC3 and Infosecurity Hall of Famer – not an award given out lightly.

It’s fascinating to hear direct from Rik about his working life and how he came to be one of the most trusted voices in the cybersecurity industry. Perhaps that came from talking to real people on a help desk, or perhaps because he spent 15 years at Trend Micro fighting cybercrime.

So Rik is well placed when he describes the changing challenges of ransomware, the issue of token-based persistence and how the affiliate model of ransomware – ransomware as a service with a nice cut for the providers – is expanding the threat.

It’s a fascinating interview. If you only read one this week, make it Rik’s.

Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?

My career in cybersecurity was almost entirely accidental, which I suspect is true of most people whoโ€™ve been in this field long enough. I started in 1994, in frontline tech support. As a kid, Iโ€™d absolutely wanted to be an astronaut, then an actor, then a rock star. I studied French at the University of Wales, spent a year working in a bookshop in Paris after graduation, came back to the UK during a recession, and ended up on a European help desk for Tektronix, because I spoke two languages and โ€œknew a bit about computersโ€.

The help desk years were formative in ways I didnโ€™t appreciate at the time. You spend all of every day dealing only with โ€˜broken stuffโ€™: poor protocol implementations, badly configured applications and drivers, and messed up network architecture. Then in 2000, I joined Network Associates, which later became McAfee, in a very similar role, but now I was pure play cybersecurity, figuring out not only the poor implementations and configurations, but how and why organisations were being targeted and compromised. Parallel thinking, tenacity, a refusal to give up until an issue is resolved is a skill set Iโ€™ve never lost.

Moving from there to a systems integrator as a security and privacy architect shifted my thinking entirely. Fixing broken things gave way to designing and deploying implementations that were less likely to break. I joined Trend Micro in 2007 and spent 15 years deep in threat research, tracking the evolution of cybercrime from the early days of mass-mailing worms and script kiddies through to the professionalised, state-adjacent criminal enterprises we deal with today.

I joined Forescout in 2022 to take on the same challenge from a fresh perspective and a much wider range of targets, all of IT, OT, IoT, medical devices! Research, understanding what the threat landscape looks like and where it is going, and giving organisations the tools and intelligence they need to make better decisions. Three decades in, the technology has changed beyond recognition. Human nature moves much more slowly.

The most significant shift in ransomware right now is the expansion of the target surface beyond the traditional IT estate. For years, the dominant model was encryption of Windows-based systems followed by a demand for payment. That model still exists, but threat actors have worked out that there is far more leverage in targeting the systems organisations genuinely cannot afford to have offline: the systems that support operational technology, industrial control systems, building management infrastructure, or connected medical devices. These environments were designed for availability and longevity, with security and rapid patching as afterthoughts at best. They are frequently unmanaged, often undocumented, and almost always underprotected. When a ransomware group can threaten physical operations alongside data, the negotiating dynamic changes entirely.

Token-based persistence is another trend worth paying close attention to. Alongside stolen credentials, attackers are increasingly targeting the permissions granted to connected applications. By abusing OAuth consents and refresh tokens from legitimate integrations across Microsoft 365, Salesforce, Slack and others, they can move between systems and maintain access even after passwords have been reset. Standard credential hygiene leaves this vector wide open.

The affiliate model continues to lower the barrier to entry for ransomware operations. Ransomware-as-a-service means that operational sophistication and technical capability are increasingly separated. A group rents the tools rather than building them. That drives volume, broadens the pool of potential attackers, and makes attribution harder and defence more complex. Meanwhile, double and triple extortion has become standard practice: encryption combined with data exfiltration and the threat of public disclosure. The leverage is simultaneously operational, reputational, and regulatory, and defenders need to account for all three dimensions when planning their response posture.

What are the biggest cybersecurity challenges those in leadership roles are facing?

The most fundamental challenge is tempo. The threat landscape is accelerating faster than most organisationsโ€™ operating models were designed to absorb. Vulnerability discovery is faster. Exploit development is faster. The window between disclosure and weaponisation is compressing. The processes most organisations rely on, change approval, patch scheduling, and risk sign-off, were built for a world where defenders had meaningful time on their side. That time advantage is eroding rapidly, and leadership needs to reckon with what it means to operate in an environment where human-speed response is structurally inadequate against increasingly autonomous attack chains.

Asset visibility remains the unglamorous foundation that everything else depends on. You cannot protect what you cannot see, and most organisations significantly underestimate the size and diversity of their actual attack surface. The proliferation of IoT devices, operational technology, personal devices, and cloud-connected applications means the estate leadership thinks theyโ€™re managing, and the estate actually exposed to risk are rarely the same thing. Decisions made in the boardroom about risk tolerance are often based on an incomplete picture of what the organisation actually owns and operates.

The communication gap between teams (IT and OT) and between teams and leadership remains stubbornly persistent. Security leaders are increasingly expected to translate complex, evolving risk into terms that resonate with boards whose primary frame of reference is financial and reputational exposure. That translation is hard to do well and getting it wrong in either direction carries real costs: underinvestment because the risk wasnโ€™t communicated compellingly, misdirected investment because the conversation was too technical to connect with strategic priorities, or actual breach. The organisations that are getting this right have shifted from talking about threats in isolation to talking about operational resilience: whether they can sustain operations under pressure and recover at a pace the business can tolerate, alongside whether they can prevent the incident in the first place.

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good (in cybersecurity)?

Iโ€™ve been talking about autonomous cyber weapons since 2017, well before the ChatGPT boom made it a mainstream concern. Back then, the reaction was largely sceptical. I reiterated the warning in 2019. The point I kept making was simple: any sufficiently capable technology will be used for both good and bad purposes, and AI was going to be no exception. The question was never whether, only when and how.

What makes generative AI particularly useful for threat actors is the compression of time and skill required to operationalise existing knowledge. Poor grammar and spelling used to be one of the most reliable signals that a phishing email was malicious for example, but that signal has disappeared entirely. Real-time campaign management and dynamic payload customisation become achievable goals for cybercriminals. Chaining known vulnerabilities into a working attack path used to require real expertise and significant effort. AI makes it faster and cheaper to iterate through variations, test assumptions, and generate the connective tissue between findings. The barriers to entry are lower, and they are coming down faster than most organisations are prepared for.

On the defensive side, AI should be helping organisations do things that human analysts simply donโ€™t have the bandwidth for: vulnerability triage at scale, dependency mapping, pattern recognition across enormous datasets, and accelerating the work that usually creates delay between detection and response. The honest caveat is that the same tempo shift affects defenders as much as attackers. Building autonomous defensive capability on top of a poorly understood environment automates confusion rather than resolving it. This is why I have been recently arguing for a mindset shift I call Assume Autonomy, the recognition that both sides of this equation are increasingly operating through autonomous systems, and that your operating model, your decision rights, and your response processes all need to be built for that reality.

What role do you think governments play when it comes to cybersecurity?

Governments play an essential role, and itโ€™s worth being clear about both their strengths and their limitations. The value they bring is structural: the authority to set and enforce standards, the capacity for international coordination that the private sector cannot replicate, and the intelligence visibility that comes from operating at a national level. When it works well, and Europolโ€™s European Cybercrime Centre is an example I can speak to directly, having been a Special Adviser since its founding, the collaboration between law enforcement, intelligence agencies, and private sector organisations produces outcomes that neither side could achieve independently. Takedowns of major criminal infrastructure, attribution of operations, disruption of affiliate programmes: these require the kind of coordination that only governments and enforcement bodies can convene.

The challenge is that the policy cycle moves at a very different speed to the threat landscape. Regulations are written based on the threat and technology picture at the time of drafting, and by the time theyโ€™re enacted, that has already shifted. Iโ€™ve spent years briefing parliamentarians and policymakers, and one lesson you absorb quickly is that good intentions and unintended consequences are not mutually exclusive. Proposals that look sensible in a policy context can create real operational problems when they meet technical reality. Mandatory encryption backdoors are the obvious perennial example: they would simultaneously weaken security for everyone while doing little to impede determined adversaries who can simply use alternative tools.

What governments need more of is genuine technical literacy at the policy level, and what the industry needs to sustain is the patience for long-cycle engagement. The messaging has to be repeated, refined, and repeated again before it shapes anything. Thatโ€™s frustrating, but itโ€™s how durable policy gets made. An industry that retreats from engagement because the process is slow produces worse outcomes for everyone.

Whatโ€™s something that has drastically changed about cybersecurity since you first got started in the field?

The proliferation and professionalisation of cybercrime is the change that dwarfs everything else. When I started, the threat landscape was dominated by individuals: curious, disruptive, sometimes malicious, but operating largely alone. The motivations were varied: notoriety, grudges, intellectual challenge, and occasionally ideology. The tools were crude by modern standards. The damage was real but (mostly) bounded.

What we have now is categorically different. Ransomware is an industry. Criminal enterprises operate with HR functions, customer service desks, negotiation specialists, and affiliate programmes. They have business models, risk management processes, and succession planning. The Conti leaks gave us an extraordinary window into an operation running with that level of organisational maturity. These are enterprises, structured and managed as such.

Alongside that, the integration of state interests into the criminal ecosystem has fundamentally changed the threat calculus. State-aligned threat actors have become increasingly comfortable using hacktivist personas as cover for operations that serve national strategic objectives, gaining plausible deniability and occasionally public sympathy. Traditionally, hacktivism was cause-driven: people who targeted organisations they believed were doing harm. Now, well-resourced state-directed groups adopt the aesthetic and the language to mask what is actually espionage and sabotage. The blurring of lines between cybercrime, hacktivism, and state operations is a part of that significant shift, and one that complicates attribution enormously.

What has barely changed is the human element. People still click links they shouldnโ€™t. I know this personally. Not long ago I fell for a credential-phishing text message myself! It was a fake Netflix payment failure notice that arrived just after I had been querying an unrecognised bank charge on my account. I caught it immediately and my password hygiene contained the damage, but the point stands. The most sophisticated threat intelligence in the world can be undone in a second by a moment of distraction. That was true in 1994, and it remains true now.

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.