#REAL THREATS
#REAL DETECTION
#REAL COMPLEXITY

Advanced Threat Scenarios: Detecting the Hardest Cases

The most dangerous insiders are rarely caught by basic indicators. This episode is for practitioners who have already built the program — and now need to sharpen the blade.
Your Program Is Built. Now What About the Threats It Wasn’t Designed to Catch?
Every insider risk program is built to catch the obvious cases — the disgruntled employee on their way out, the accidental data leak, the policy violation that triggers an alert. But the hardest threats don’t look obvious. They look normal. A trusted senior employee with decades of tenure quietly manipulating systems. A remote worker whose behavioral patterns have slowly shifted. A contractor who passed every background check — and is routing data out of the organization over months.
In this episode, three practitioners who have seen these cases firsthand examine the detection challenges that mature programs still get wrong: privileged user risk, nation-state infiltration through legitimate hiring, AI and agentic identity as a new attack surface, and the false positive problem that causes organizations to tune away their own visibility. They also take on the question security teams avoid — where does monitoring end and surveillance begin, and how do you build a program that protects the organization without destroying employee trust.
Key Discussion Topics:
Privileged user risk
Detecting slow-burn behavioral shifts in high-trust individuals
Nation-state infiltration
When the threat actor passes your background check and joins your team
AI & agentic identities
The visibility gap when employees and agents create unmapped risk
Tuning detection models
Reducing false positives without creating dangerous blind spots
Monitoring vs. surveillance
Where the line is — and how transparency changes everything
What's coming next
SaaS gaps, agentic infrastructure, and what keeps practitioners up at night
Our Speakers
Alex Waintraub 
Founder, Waintraub Cyber Solutions
Aqsa Taylor
Chief Security Evangelist, Exaforce
Anand Thangaraju
CISO, Alchemy Cyber
Peter Hadjigeorgiou
Field CISO, Teramind