Activate Industry!: Moving Beyond Defense to Disruption and Active Defense

Activate Industry!: Moving Beyond Defense to Disruption and Active Defense

🎙 Sandra Joyce 👥 101K 📅 March 24, 2026 ⏱ 19 min 👁 2K 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

active defensedisruptionthreat actorscybercrimeAI attacks

Summary

Sandra Joyce, VP of Google Threat Intelligence, presents a keynote at RSA Conference 2026 advocating for a shift from passive intelligence sharing to proactive disruption of cyber adversaries. She highlights the evolution of cybercrime, citing a drop in median time from initial access to handoff from 8 hours to 22 seconds, indicating pre-planned partnerships. She discusses the impact of AI on attack speed, scale, and sophistication, and argues that defenders must go upstream to disrupt at the source. Google’s disruption strategy is built on four pillars: civil legal action, public disclosure, technical takedowns, and product hardening. She provides case studies: the takedown of IPIDEA residential proxy infrastructure, which reduced traffic from exit nodes by 90% for Okta and 75% for Comcast; the disruption of a certificate reseller that led to mass revocation of malicious certificates; and the takedown of GRIDTIDE, a PRC-nexus espionage campaign. She also outlines Google’s approach to securing AI, including disabling malicious infrastructure, hardening models, automating vulnerability hunting, and developing advanced defenses. She concludes by calling for industry-wide collaboration and a whole-of-community approach to make disruption the new status quo.

183 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into Google’s active defense operations, with concrete examples and metrics that demonstrate the effectiveness of disruption. The argumentation is coherent, moving from the problem (evolving adversaries and AI) to the solution (active defense) and supporting it with case studies. However, the presentation is one-sided, focusing on successes without addressing potential ethical or legal challenges, and it serves as a promotional piece for Google’s capabilities.

78 words

Title / Content Match

The title accurately reflects the content, which focuses on moving from passive defense to proactive disruption and active defense strategies.

Quality & Reliability

8/10

High credibility due to speaker's senior role at Google Threat Intelligence, concrete case studies with specific metrics, and references to industry reports (M-Trends). However, the talk is primarily a promotional narrative for Google's active defense approach, lacking independent verification or counterarguments.

Key Moments

Cited Sources

  • M-Trends 2026 Report — Referenced for statistics on handoff time and threat actor specialization.

Concurring Sources

Contribution & Novelties

The talk provides a compelling argument for proactive disruption as a necessary evolution in cybersecurity, backed by real-world examples from Google’s operations. It introduces the concept of ‘active defense’ as a strategic philosophy and outlines a practical framework (four pillars) for implementation. The case studies offer novel insights into disrupting proxy networks and certificate resellers, which are often overlooked.

Pour aller plus loin :

102 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with slightly lower technical depth and reliability, reflecting the talk's strong content but promotional nature.

Reliability 8/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.