
Episode #80
Fighting Back: Glenn Maiden on Putting a Bounty on Cybercrime
Cybercrime is not a lone hacker in a hoodie any more. It is an economy, and by some estimates a staggeringly large one. In this episode of Cyber Voices, host David Savva-Willett flips the usual script and asks not how we defend, but how we fight back. Glenn Maiden is Chief Security Officer for Fortinet Australia and Director of Threat Intelligence at FortiGuard Labs for Australia and New Zealand. He spent years in Defence and the Australian Intelligence Community working in geospatial and human terrain intelligence, including during Operation Slipper, before moving into commercial threat intelligence. He established the team behind the World Economic Forum's Cybercrime Atlas and, most recently, helped create a first of its kind cybercrime bounty program with Crime Stoppers International. The conversation covers how mapping tribal structures, community leaders and wells in a conflict zone translates to mapping the humans behind ransomware crews, why our industry has become excellent at indicators of compromise and knows almost nothing about the actual people, and what the Cybercrime Atlas found when it started pulling names, aliases, bank accounts, crypto wallets and bulletproof hosting together into targeting packages for Interpol, Europol and the FBI. David and Glenn also dig into why better defence alone was never going to be enough, the gap that sits on the people and process side rather than the technology side, and the unreported soft underbelly of an economy built on small and medium business. Glenn explains how the new bounty program works, how someone with intelligence on a threat actor can submit an anonymous tip and potentially collect a reward when that person is arrested and prosecuted, and why the same infrastructure mapping may help pull far worse criminals off the streets. There is a human side too. Glenn talks about the young man in Eastern Europe committing cybercrime to get his family out, the scam compounds operating a couple of hours to Australia's north, and his own experience of being scammed through Facebook Marketplace. He explains why he tells that story publicly and how shame keeps victims silent. Glenn closes with practical advice for CISOs, SOC leads and analysts who will never run a takedown themselves. Content note: this episode includes brief references to human trafficking, forced labour in scam centres and child exploitation material in the context of organised crime. Cyber Voices is the official podcast of the Australian Information Security Association. Share your feedback at cybervoices@aisa.org.au.


