Understand Organizational Risks: Before any organization can get ahead of or stay informed about any type of cybersecurity threat, security teams must identify with leadership what the “crown jewels” are and what is the most important information to the organization. Understanding this information will help teams create a clear plan on how to best protect against any potential risk.
Staying Ahead with Threat Intelligence: Michael DeBolt Of Intel 471 On How to Stay Informed and Agile About New Cyber Security Threats

In the ever-evolving landscape of cybersecurity, keeping abreast of the latest threats, vulnerabilities, and emerging trends is paramount. This becomes increasingly significant as malicious AI poses new challenges. How do Chief Product Security Officers (CPSOs) stay informed about these factors relevant to their organization’s products? More importantly, how do they integrate this vital threat intelligence into their security strategies? As a part of this series, I had the pleasure of interviewing Michael DeBolt.
As Chief Intelligence Officer, Michael DeBolt is part of the Intel 471 executive team leading a globally diverse team of adversary and technical researchers, linguists, analysts, and intelligence consultants serving client CTI teams representing organizations in all shapes and sizes. Before Intel 471, Michael developed strategy and led operations as the US representative and Head of Cybercrime Intelligence at INTERPOL. As a Special Agent at the US Naval Criminal Investigative Service (NCIS), he specialized in national security cyber operations and cybercriminal undercover investigations. Michael is a proud US Marine Corps infantry veteran, having served combat tours as an infantry scout leader.
Thank you so much for joining us in this interview series! Before we dig in, our readers would like to get to know you. Can you tell us a bit about how you grew up?
I grew up as a typical midwestern kid in Michigan. I always had an interest in sports and team environments, and I enjoyed being active and exploring new things. Sometimes that got me into trouble, which of course happens as a kid.
After high school, I enlisted in the Marine Corps and had the choice to do really anything starting out. It was October 2001 shortly after 9/11, so I chose to serve as an infantryman because I wanted to be on the front lines fighting for our country. Specifically, I became an infantry scout, which means I was going ahead in front of the tanks and scouting out the battlefield that was ahead of them. There are plenty of stories from tours I did and interesting people I met during this time in my life, but you could say I grew up pretty fast.
Is there a particular story that inspired you to pursue a career in cybersecurity? We’d love to hear it.
When I was in the Marine Corps, my job in the infantry was nothing too technical. One of my side assignments was radio encryption and making sure all radios were properly secured. I kept a black box in my pocket at all times, so I could be ready and on call in case radios needed new encryption keys. This piqued my interest in learning how the technology worked and how something as simple as encrypting a radio was so effective when it came to critical communications during combat.
After leaving the Marines, I wanted to follow a path that converged law enforcement and technology, so I got my degree in Information Security and Intelligence with a focus on digital forensics. I volunteered with the local sheriff’s office doing forensic work in support of criminal investigations, and that was the beginning of my career in cybersecurity.
Can you share the most interesting story that happened to you since you began this fascinating career?
When you have worked in cybersecurity for as long as I have, you gather a lot of interesting stories as the job constantly changes. However, there is one that sticks out to me.
When I was an NCIS agent, all of my fellow agents were focused on cyber counterintelligence and national security. Think of adversarial nations who were trying to steal our country’s secrets; It was a critical mission. We wanted to know how adversaries were getting in and be able to monitor what they were getting and how we could prevent that from happening. But I quickly learned that there was a gap in our mission.
There was a rising issue of cybercrime that was impacting the Department of Defense (DoD), criminal actors were looking to hack into the DoD, steal information and sell that information in the underground markets for profit. So, I created NCIS’s first ever, proactive, undercover operation targeting cyber criminals impacting the DoD.
This led to a few cases, one most notable was against a hacking group called Team Digi7al, and it turned out that the group’s leader was an active duty sailor stationed just a few miles away from where I was investigating the case in Virginia.
This was a turning point not only for me and my career but also for NCIS, as it changed how the agency would think about and execute cybercriminal operations and investigations.
You are a successful leader. Which three character traits do you think were most instrumental to your success? Can you please share a story or example for each?
1. Taking advantage of luck and timing: Looking back, I was always embracing what came my way, and I was aware of changes happening in my environment. This helped me to seize new opportunities and capitalize on them.
2. Surrounding myself with fantastic people: The key to my own personal success and the success of my teams has truly been in the character we embody and people we surround ourselves with. I’ve had the opportunity to work with very intelligent people, who are unafraid of challenges and who prioritize doing what’s best for the team and not the individual. Working with these types of people has made me a better person over the years.
3. Leaning into humility: Leaders should be open to change and willing to admit what they don’t know, especially in a field like cybersecurity. We need to have tenacious attitudes toward gaining knowledge and being open about what we need to learn. This starts from genuine humility, asking questions and approaching situations from a listen first, speak last mentality.
Are you working on any exciting new projects now? How do you think that will help people?
At Intel 471, we are always doing things to stay one step ahead of the adversary. That’s a project in and of itself, to just make sure we have the continuous coverage we need to observe when actors are shifting their behaviors, and ensure our customers are fully equipped in their fight against cyber threats. That looks different in every situation, from monitoring major news cycles to seeing its impact on the cyber underground to how cybercriminals are leveraging tools like artificial intelligence (AI).
In 2024, I led the creation of the Cyber Threat Intelligence Capability Maturity Model (CTI-CMM), which is the only vendor-agnostic maturity model with a stakeholders-first approach, allowing organizations to build a mature CTI program, evaluate progress and continuously improve during the CTI maturity journey. I worked with 28 other industry leaders of all different backgrounds to create the CTI-CMM as an all volunteer effort, and we are already seeing it be adopted by the industry, including vendors and within organizations around the world seeking to mature their threat intelligence programs.
How do emerging technologies like AI and machine learning influence the risk to the cybersecurity landscape?
There is a constant chess match being played between attackers and defenders, and we are just scratching the surface on understanding how AI is changing the game.
Cybercriminals and nation-state actors have experimented using AI and Large Language Models (LLMs) to speed up and scale the mundane tasks they face when trying to breach organizations, such as researching companies, finding cybersecurity tools, debugging code, writing basic scripts, creating content for phishing campaigns and translation.
We’re also seeing the barrier to entry start to lower even more for cybercriminals as AI becomes cheaper and more accessible via open-source models. As a result, more malicious actors are able to experiment and create more customized malicious AI tools and content that is more sophisticated, less detectable and more convincing over time– perfect for phishing and extortion schemes. That said, in 2025 I expect the use of AI by threat actors will grow but is unlikely to prove decisive. Threat actors almost certainly will continue to abuse legitimate tools to the best of their abilities, seeking logic flaws to jailbreak existing GPTs or running their own LLM instances to train datasets and serve specific malicious purposes. The use of AI technology in a variety of social-engineering schemes, its use to support the creation of malicious scripts and the appearance of AI-based tools in 2024 suggest illicit actors are beginning to figure it out, but ultimately, they still have a long way to go before AI can execute full-chain attacks on their behalf.
For the good guys, AI helps defenders do their everyday jobs more efficiently, freeing them up for critical tasks that require deeper context and understanding that human beings need to provide. With all its bells and whistles, AI will not remove the need for human interaction and human touch in threat intelligence. It’s great for filtering noise and pointing teams in the right direction, but it’s not going to help decipher subtle nuances of threat intelligence that only humans can interpret and take action on. The AI-based threat landscape is constantly evolving, and security teams will succeed most where they gain a comprehensive understanding of the threat actors, motivations and capabilities in play against their particular organization.
Could you highlight the types of cyber attacks that you find most concerning today, and why?
This probably isn’t a shock, but ransomware and extortion groups are top of mind for me. In 2024, we saw extortion-based attacks continue to be one of the most dominant threats to organizations. One notable technique that proved particularly effective in 2024 was the compromise of cloud-based service providers and, consequently, unauthorized access to datasets operated by their customers, essentially configuring a supply chain attack.
In 2024, my team and I observed at least 31 new ransomware variants emerge. Here are the top ransomware groups on my radar heading into 2025:
- Kill Security
- Nitrogen
- Sarcoma
- FunkSec
It can’t be said enough that ransomware and extortion-related attacks don’t happen out of nowhere. Underpinning these attacks is a set of precursors that lead up to a network getting encrypted and files locked or stolen. Because of this, we closely track adversaries profiting from gaining initial access belonging to victim networks. In 2024, initial access brokers targeted the following top five resources:
- RDWeb
- Windows RDP
- Outlook Web App email platform
- Fortinet VPN
- Secure shell (SSH) remote access protocol
As a community, we need to be aware of these threats and be positioned to monitor state changes as the cybercriminal landscape continues to mature at an accelerated rate.
What advice do you have for organizations that are in the early stages of developing a security strategy for AI systems? What are the key or guiding principles they should follow? Could you walk us through the recommended steps to take immediately after a cyber attack is detected?
Something to be cautious of when building AI solutions in the cyber world is the temptation to replace everything with AI. With threat intelligence, there always needs to be a human component.
Be extra careful, conscious and methodical about where you implement AI, particularly where AI offers suggestions for security or risk decisions. It should be just that: a suggestion. Additionally, teams should be hyper critical about the models being trained at their company and the sources that AI technology is using to build models or produce assets.
The steps to take following a cyber attack truly depend on the circumstance, the nature of the attack and the type of organization that was targeted. Ideally, we would like to see better preparedness from organizations in that they have a plan or playbook in place to understand the type of events that could happen to them when a certain attack happens. This involves organizing tabletop exercises based on your threat landscape and knowing the threat actors who are targeting you the most.
Tabletop exercises and simulations are helpful in gathering critical stakeholders around the same table to discuss different scenarios. Security teams are often quite inundated, and it can be hard to carve out time for these exercises at times, but the reward of preparedness and avoiding the fallout of a cyberattack is well worth the investment.

What are the “5 Things You Need To Stay Informed And Agile About New Cyber Security Threats” and why?
Here are five things organizations can do to be better informed and protect their network. These strategies build on each other and feed into a holistic plan that empowers an organization’s threat intelligence teams to stay agile.
1. Understand Organizational Risks: Before any organization can get ahead of or stay informed about any type of cybersecurity threat, security teams must identify with leadership what the “crown jewels” are and what is the most important information to the organization. Understanding this information will help teams create a clear plan on how to best protect against any potential risk.
2. Observe What’s Going on Externally in the Cyber Threat Landscape: By leveraging threat intelligence, organizations can have a clear understanding of who is targeting them and how they are doing it. To further this understanding, security teams need to constantly monitor the threat landscape to better identify who those actors are, their intentions and their motivations. The best way to stay on top of cyber threats is to set up continuous monitoring that can point out the trends and changes in the attack surface.
3. Compare Your Threat Environment with Your Crown Jewels: Once security teams understand what their crown jewels are and who might be targeting them, they can then compare this information, analyzing their entire internal and external threat landscape to see what attacks they are most vulnerable to and where their defenses are weakest. This allows teams to navigate which controls need to be prioritized and implemented to reduce risk.
4. Monitor the Progress of the Program: Progress and measurement is essential and is the clearest way to ensure that threat intelligence teams are focusing on the right things in the threat environment. This ensures internal stakeholders that the team is maturing and taking the necessary steps continuously to better the protections they are implementing in the organization’s network.
5. Keep Your Senior Management Team Engaged & Informed: Tell your return on investment (ROI) story, share your progress and share your success. Your goal should be to make sure that your senior management, your executives and your board are all confident in your program’s ability to lower the risk profile of your organization by providing intelligence that matters on a timely and relevant basis. Having the buy-in from these stakeholders and support “from the top” enables your team’s guidance and needs to be heard and implemented.
You are a person of enormous influence. If you could inspire a movement that would bring the most amount of good to the most amount of people, what would that be? You never know what your idea can trigger. :-)
In an ideal world, I would establish a center for CTI professionals to collaborate freely with each other in a trusted environment. There are examples of this happening already in pockets, such as the ISACs, which are great but only provided on a sectorial basis, such as in finance, retail, etc.
Cyberattacks and threat actors cut across sectors, and there’s really no place for leaders and practitioners to share lessons learned for how to progress our field as a whole and make our jobs more sustainable and efficient. You need a venue and a trusted place for this where you know you won’t get punished for your honesty. I think our endeavor with CTI-CMM scratched the surface of what something like this could look like where we build programs and foster improvement and maturity together.
How can our readers further follow your work online?
Readers can follow me on LinkedIn or X, and they can keep up with Intel 471’s latest research and other updates on LinkedIn and via our weekly blog.
This was very inspiring and informative. Thank you so much for the time you spent with this interview!
David Leichner
Editor & Journalist · Authority MagazineEditor and journalist at Authority Magazine, sharing in-depth executive interviews, leadership insights, and empowering stories from world-class founders and creators.

Exclusive, curated interviews with the leaders and changemakers shaping tomorrow. Leadership lessons, industry deep dives, and executive profiles.
More from Authority Magazine
See all stories →Brandon Wade & Dana Rosewall on Why ‘Yes’ People are a Liability and the “Painful” 180-Degree Redemption Story
