✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Cybercrime Runs Like a Fortune 500 Company
In this episode of In Progress, CEO Doug Merritt sits down with Keith Wojcieszek, former Chief of the Secret Service's Cyber Intelligence Section, to unpack what modern cybercrime actually looks like. Keith draws on his career-defining case against Roman Seleznev, once one of the world's most prolific credit card data traffickers, to show how cybercriminal operations now run like Fortune 500 companies or cartels, with developers, brokers, and money launderers each playing a defined, well-compensated role. He also traces how ransomware economics have shifted, why many groups have dropped encryption altogether in favor of simpler extortion, and how AI is making both attackers and defenders faster. Doug and Keith also dig into what separates organizations that handle breaches well from those that don't: preparation. Drawing on incidents like the Colonial Pipeline shutdown and the Stryker attack, they argue the real vulnerability isn't how attackers get in, but how fast and far they can move once inside. It's a conversation about treating cybersecurity as a business risk rather than a purely technical one, and why boards need answers to hard questions before, not during, a crisis.
Stay in the Loop
Get exclusive access to the latest conversations with cloud leaders, industry pioneers, and technology changemakers.
Subscribe and stay ahead of what's next.
Zero spam. Unsubscribe at any time.
The Speaker
Doug Merritt is Chairman, Chief Executive Officer, and President of Aviatrix. Most recently, Doug served as Splunk President and CEO from 2015 to 2021. During his tenure as CEO, Doug led the transformation of Splunk from an on premise, perpetual license software company with the equivalent of $220 million in Annual Recurring Revenue (ARR), to a cloud-based SaaS company with ARR of $3.12 billion. In his first year at Splunk, Doug served as the Senior Vice President of Splunk’s go-to-market functions including sales, marketing, support, business development, partners, and other customer facing functions.
The Guest
Keith Wojcieszek is a noted authority on cyber and intelligence topics, specializing in cyber threat intelligence, investigations, intellectual property theft, data breaches, and computer intrusions. Before joining Prescient, he founded a global cyber threat intelligence program at an advisory firm and has served as a certified expert witness and frequent thought leader.
Keith spent over a decade with the U.S. Secret Service, where he led the Cyber Intelligence Section and managed the agency's national response to cyber investigations protecting U.S. financial infrastructure. His work targeting transnational organized crime networks led to the apprehension of sophisticated cyber criminals responsible for over $1 billion in financial losses. From 2012–2016, he also served on protection details for the President, Vice President, and senior White House officials, leading physical security operations and establishing emergency action protocols.
Key Summary
- Cybercrime is organized like a business. Roles are specialized and clearly compensated, from malware developers to money launderers, making these networks resilient and hard for law enforcement to dismantle.
- Ransomware economics are shifting. The cost of storing and servicing stolen data has led many groups to abandon encryption entirely in favor of extortion alone.
- Lateral movement, not initial access, is the real threat. Incidents like Colonial Pipeline and Stryker show that how fast attackers spread internally matters more than how they got in.
- Preparation is non-negotiable. Boards should know who's responsible for which decisions in the first 24 hours of an attack, well before one happens.
Never Miss
an Episode
Join thousands of cloud professionals following the stories, strategies, and hard-earned lessons from the architects driving enterprise transformation. Be the first to know when new episodes go live.
Zero spam. Unsubscribe at any time.
Join cloud engineers and modern architects already tuned in.
Keep exploring
Related Episodes
Assume Containment, Not Breach
Doug Merritt · Chief Executive Officer
- Why Nick argues the industry should shift from "assume breach" to "assume containment" — and what that changes about incident response - The guardrails-not-gates philosophy that lets developers move fast without becoming security experts - How Nick's team found a workable path through an "impossible" secure-SDLC mandate on SpaceX's Falcon codebase - Applying Elon Musk's first-principles reasoning to break security problems down to their core "whys" - Why Nick sees cloud security footholds as a societal and economic risk, not just a technical one

Chris Hughes: Not Prevention, But Resiliency
Doug Merritt · Chief Executive Officer
- CVEs are exploding — over 40,000 in 2025, with 2026 projections near 60,000 (some estimates up to 100,000) — while AI makes vulnerabilities easier to find and exploit. - Patching capacity has long lagged below 10% of the backlog; broken production risk and competing business priorities keep it there. - Security should shift from trying to prevent every incident to containing and recovering from the ones that happen. - "Human in the loop" doesn't scale against AI-driven attack volume — defenders need to fight AI with AI. - Security teams that act as collaborators, not blockers, avoid the shadow-IT workarounds that punitive policies create.

