Detecting, mitigating and managing the modern insider threat
Insider incidents have steadily increased in recent years, but there's one threat that's causing particular concern: North Korean operatives posing as remote IT workers, quietly embedded inside legitimate organisations.
In this episode, Valeska and co-host Sonia Millen are joined by Ryan LaSalle, CEO of Nisos, a US-based human risk intelligence firm specialising in insider threats, employment fraud and executive digital risk. Ryan shares the extraordinary story of how Nisos uncovered and infiltrated a North Korean remote IT worker fraud operation after a suspected operative applied for a role at the company, ultimately exposing a network of more than 20 workers employed across multiple US organisations. Ryan explains how these operations work, the warning signs organisations should look for throughout the hiring and employment lifecycle, and why remote work has created new opportunities for nation-state actors and organised crime groups.
| The Cyber Brief is a podcast for decision-makers in cyber. Through candid conversations with the industry's best, The Cyber Brief delivers executive-level insights on cyber risk, best-practice governance and emerging threats. Leaders in the field share practical insights, real-world stories and actionable advice for boards, executives and cyber professionals. |
Episode 10: The Cyber Brief | The operative we hired: inside a North Korean fraud cell, with Ryan LaSalle, Nisos
Valeska: Welcome to The Cyber Brief, the podcast for decision-makers in cyber. Through candid conversations with the industry's best, we bring you executive-level insights on cyber risk, best practice governance, and emerging threats. We've advised on some of the world's most complex cyber incidents, and we know what it's like in the trenches. We're asking the experts for their unfiltered truths and best advice on what executives, boards, and cyber professionals should be doing now to stay ahead.
Over the past few years, we've seen insider incidents steadily increase, and that's a consistent experience globally, where over 30% of cyber incidents originate internally. It's a chilling thought, given insiders tend to have authorised access to our most critical operations and sensitive data. They're also acutely aware of our vulnerabilities. But there's a specific insider threat that is causing particular concern: North Korean operatives posing as remote IT workers quietly embedded inside Western organisations.
Hi, I'm Valeska Bloch, head of cyber at Allens. In this episode, my co-host, employment law expert Sonia Millen, and I speak with Ryan LaSalle, CEO of Nisos, a human risk intelligence firm that helps organisations detect and investigate insider threats and employment fraud and executive digital risks. In July 2025, Nisos discovered that a suspected North Korean operative, Joe, had applied for a role. Rather than reject him, they hired him, shipping a monitored laptop and uncovering a live fraud cell, a network of at least 20 operatives simultaneously employed at five US companies, none of which knew. Over 10 months, the cell generated over $4.5 million for the regime. In this episode, Ryan walks us through what happened, how these cells operate, how to detect them, and what to do if you find one inside your organisation. It's a wild story. Let's get into it.
Sonia: Well, welcome, Ryan. Thank you for joining us.
Ryan: Nice to be here.
Sonia: Let's start with hopefully an easy one. Nisos describes itself as a human risk management company. Can you tell us what that means in practice?
Ryan: Yeah. We focus all the powers of our team, who are open source intelligence analysts, on risks to people and risks by people. So, helping companies solve those two different classes of risk. What it means practically is we do a lot of work in executive digital protection, insider threat, entrusted workforce. Helping companies protect against people who want to do their executives or their people harm.
Sonia: And when do organisations tend to bring you in?
Ryan: They often tend to bring us in when there's a problem. That's usually the first time. It's often to help support an investigation. So, maybe one of their C-suite is being threatened or being doxed. Maybe they're picking up some social media chatter that looks like people may be at risk of actual physical harm, and they need to know who that person is, or maybe it's someone that they've, that they're currently investigating internally, and they need to understand the external footprint of that person. Are they selling access to the company? Are they brokering malware? Are they working in extremist groups that might work against the company, for example. They all start a little bit around enumerating the problem better, I think is probably, maybe the best way to think about it. Our team focuses on open-source intelligence, so everything we look for is the presence and digital footprints outside of a company. So if it's a threat to an executive, then we're really looking into who that digital person or persona is, and anything we can find out about them. So we try to connect the dots between lots of different data sets, their other accounts, their past footprints and behaviours. If we can find things that trace them back to who they are in real life, that's our goal almost every time when we're looking at an active threat of violence. But in an insider threat scenario, we know who the person is, so we're trying to figure out what other behaviours are they engaged in. So in that case, we're going kind of the opposite way. We're going from the person and trying to enrich more information about their other personas they have, the other places they spend time, the other behaviours that they're engaged in, and try to create a more whole picture of the person so that the company can make better decisions on what they need to do.
Valeska: How long do those investigations typically take, Ryan?
Ryan: It can really depend a lot based on the sophistication of the bad guy. If they're really, really good and have a ton of great, what we call trade craft, then it takes our people longer because they need to really spend time peeling back the onion and trying to figure it out. But in some cases, for one executive who was being threatened, we were able to find, get down to the person, their name, their address, and their picture within three hours. So it varied a lot, also based on the intensity of the threat and how many stops we needed to pull out to be able to get it done.
Sonia: And you've mentioned insider threats already, but what sort of insider threats do you typically see, and how has this evolved, if at all, over the last few years?
Ryan: A lot of the insider threats we were focused on early on were people who were trying to sabotage the company, people who were trying to steal intellectual property; maybe as they moved from one job to another, they would take data with them. People who are maybe brokering customer lists or things like that. So we had one insider threat where the people inside the company were selling the lists of their clients and customers to their family who were in organised crime, and the organised crime team would then scam the customers. So we, you know, finding the linkages between the source of the leak and the active threat against consumers in that case was part of our investigation. But we think it's changed quite a bit over the last couple of years. I think with the pandemic, the rise in all kinds of different remote work fraud has gone up quite a bit. I think the most popular one that we're seeing right now is the risk of the North Korean remote IT workers. We are also seeing a huge rise in people who engage in polywork, so where they're working multiple jobs without their employers knowing that they're working multiple jobs, or other cases are illicit outsourcing, where the person is doing their job, but they're actually brokering that work through lots of other third parties to do the work for them, so they can sort of like, again, probably work multiple jobs, work a little less hard, but have other people do the work, and they kind of bring in all the money. I think the North Korean threat is basically an encapsulation of both of those, done through a nation state.
Sonia: And what proportion do you see in terms of those threats?
Ryan: I would say most of our investigations are still malicious actors who are trying to do the company harm through sabotage, IP theft, or other for-profit schemes where the person is trying to skim something out of the company. The most sensational ones have been the ones that are more nation-state backed, and we've found increasing numbers of other countries doing the same kind of thing as North Korea.
Valeska: Let's talk a bit more about the DPRK threat because it's obviously become so prolific, particularly in the US, and obviously you've got first-hand experience with it. So in July last year, your team discovered that a suspected North Korean operative, Joe, had applied for a role at Nisos. But rather than reject the candidate, you hired him, shipped a laptop to him, which was monitored, uncovered a live fraud cell. Can you walk us through that decision? When did the team realise what was happening? What made you decide not just to reject the candidate, but to actually actively investigate?
Ryan: We've been investigating North Korean remote IT worker fraud at our clients since 2022. So the fact that three years into doing this, we had our first candidate apply to us—well, the first, let's say the first candidate who interviewed with us, we may have had multiple candidates apply to us. I think as we look back, we've seen other, other pockets of that, but they've never made it to the interview stage. When they showed up for the interview, is when we realised that something wasn't right, and that their bio and their experiences and their behaviours on camera didn't align well with each other. And at the time, our CTO was doing the interview, and his team had been one of the ones had been doing a lot of the investigations, and so his alarm bells went off immediately. He recorded the interview for us to review later to say, 'I think, I think this is actually not a person who is who they say they are', and we then spent time trying to validate and vet that they were in fact high likelihood a North Korean fraudster in our pipeline. So then we decided we'd continue to walk forward through the process, and we'd run an operation on them. The only way to really do that was to hire them. We got law enforcement involved to make sure that we were doing things above board and not risking sending money to a sanctioned entity, for example. So, we did a lot of things, sort of string him along, and really engage him along the way to keep him active, so that we could continue to monitor and learn. And that balance between like shutting something off and spending time trying to learn is always the balance. It's a risk equation that intelligence people are always trying to figure out. Like when do we stop this and make it, and end it, versus when do we let it run? Because the value of what we can learn is so much more important than turning it off.
Valeska: And when did you decide to stop it? And I should say this is obviously a case of don't try this at home.
Ryan: Yeah.
Valeska: In your case, you had, as I understand it, former CIA operatives who were assisting with the investigation internally, you were working with the FBI. You guys do this for a living, but how did you decide when to pull the pin?
Ryan: I would say even for us, even for us, it was a little edgier than we were used to. I think people who work in the intelligence community are used to being behind a veil of secrecy, and in this case, I mean, our own company and all of our employees are out, online. So we realised that we were going to do this was a little bit, I think, a higher risk than most people were used to taking in our business. We decided to stop the operation with Joe before we ever had to pay him. So we were able to string him along, have him go through onboarding, have him go through training. We were able to make a lot of excuses for why we couldn't get started on the work yet that we'd hired him to do as a freelancer. We never paid him, and then eventually he was getting frustrated. He said, 'When's the work going to start? When are you going to pay me?' You're like, 'Actually, I don't think this is going to work out. We don't have enough work for you. Why don't you send the laptop back and we'll call it a day?' And he did, and we shut it down. But what we had done through the whole time when he was there with us, and we had access to his laptop, and he was using our laptop—
Valeska: And so, you sent him the laptop, and it had spyware on it?
Ryan: Yeah. We sent him a laptop, and it was fully monitored with all of our own material, so we could, you know, we could watch, we could see what the camera could see, we could see what was going on on the screen, we could capture the keyboard, the keystrokes, everything off the laptop because it was our machine. So we do, if he was using our machine for something malicious, then we have the rights to track and watch all of that. So that's what we did. We watched him checking his personal email every day, and a good part of his day every day was on Google, sending out job applications. He was sending out thousands of applications. In the time that we watched him, he had sent out 1600 job applications in three months. So like that's most of what his job was every day was trying to apply for new jobs, and we could see through the back and forth of his email, the companies he was applying to, the companies he was progressing into interviews with. We would call them and disclose to them that they had a probable North Korean in their midst, and they'd be like, 'How do you know?' 'Well, we're sitting on his, he's using our computer to do this, we're watching him. Our laptop is in Florida. He is not in Florida.' So we're watching that whole thing transpire. And then along the way, he happened to log into a collaboration server with a set of credentials, that he saved into his Google Wallet. And so we had all of his passwords and all of his accounts for everything, all the services he was using as part of his team, not just himself personally, and that's when it got a lot more interesting. Then we didn't need him anymore because now we're in the mothership, and that's when we started really harvesting a lot of intelligence value.
Valeska: And so, what did you discover about how the network actually operates?
Ryan: Yeah, it operates a little bit like a pyramid scheme, or like a small business. We were in a cell of about 22 North Korean remote IT workers. Many of them had very specialised roles. There was one person who was sort of the coordinator boss of everything. There was one person whose only job was to basically work with the outside world, work with the laptop farms and facilitators, who they called natives, the people in the US who were helping them host laptops in their homes, help set up bank accounts, get identities, and get identity paperwork. So there was one person whose job was doing that, and then the bulk of everyone else's job was to apply for interviews and take jobs. They had a leaderboard of tracking progress against applying for roles, getting interviews, landing jobs. They would post the offer letter when they won, when they got a job, and they would post a really sad little meme when they would lose a job, when they get fired. So it was a entirely self-sufficient encapsulated cell who were working really, really hard to make sure that they were getting as many jobs as possible and pulling as much money through each month.
Sonia: And has this threat sort of increased with the propensity for people to work remotely and the acceptance of people working remotely?
Ryan: Yeah, that's absolutely a vulnerability in the economy that they have exploited. In fact, they're penalised if they apply for jobs that are hybrid or in person. If they're wasting the time and resources of the regime by applying for a job they couldn't possibly get, they get penalised. So 100% they focus in on gig jobs, on remote work, on anything they can do as an individual contributor.
Valeska: What's the success rate for their job applications?
Ryan: Very low. I told my son who's getting ready to go to college, I was like, if you have to apply to 1600 jobs to get four, that is a bad yield, but that is about what they're getting in terms of their, in terms of their return on investment.
Valeska: And how much are they generating, though, still?
Ryan: Oh, the cell that we were watching, I think last year generated about, I think we estimated about $6 million in payroll. Some of them had four jobs, not for the whole year, but like on and off they were working multiple jobs. So the yield is low cost to them. The interviews are higher cost. It does take time to schedule and sit down into the interview. They have an AI assistant that helps them get through those interviews, that listens to the interview and translates the interview and prompts them with responses for the interview based on the persona of the job holder. That makes it a little bit easier. But for the most part, they use an AI tool to generate a resume tied to a job description. They have a bunch of personas on LinkedIn and other places that they anchor those resumes back to, and they apply indiscriminately to any job that's remote that roughly fits the bill of what they could pull down. And they get a lot of interviews, and then they get a fair number of jobs on the other side of that.
Valeska: A lot of people will be thinking you guys were able to identify that he was a fraud, but you're also expert at this. Can you talk us through the tells from application to interview to onboarding to actually employment because I imagine they're slightly different things that you might pick up at each of those stages.
Ryan: Yeah, I call them red flags, but yeah, there's different tells all along the way. Some of them are pretty straightforward for a person who's interviewing to pick up, and others require a little bit of technical know-how. For example, on their resumes, they're often using a voice over IP phone number, and so you can do a reverse lookup on those phone numbers and see that they're voice over IP. Now, plenty of people have voice over IP phone numbers. But that's just one thing. So you put one in the column for maybe fraudulent. Their email addresses often follow the same pattern: first name, last name .dev or .eng, or with a date like 0317 or something like that. And that often ties back to the person's need to keep track of all these different personas, and so different emails based on different personas. So you look at that, you look at the age of their LinkedIn profile. Many of them might have 15 years of experience, but their LinkedIn profile has only been around for three or four months. So there's like these weird disconnects that you pick up along the way if you just looked into the person as you're getting ready to interview them. Their resumes are way too perfect, so the resumes meet your job description exactly. You need seven years of a skill and a technology that didn't exist seven years ago, I guarantee you their resume has that on there. It's too perfect, and so you start being like, oh, you're so excited because you're gonna meet, you finally met the perfect candidate. It's probably too good to be true. And then when they show up, they often have a lot of camera problems. They have a lot of bandwidth problems. Pauses when they're talking. They'll use a lot of filler after you ask a question because they're waiting for the AI copilot to catch up. They used to have two screens going, and so while they're talking, while they were talking to you, they'd be reading off the other screen, and then they'd look back. They got better. They realised they kept getting caught by doing that, and so then they created AM overlay. So they've got basically closed captioning over the screen that helps them with their prompts now. But some of those tells are pretty obvious, and then as you get closer to employment, they start having very plausible but additive excuses for things. So one example might be that when you go to send them their laptop to their home because they're a remote worker, they ask to change the address. 'Oh, I'm not home. I'm visiting my mom. She's sick. I'm in another state, another city. Can you send it there?' 'Yeah, of course.' Every HR person is like, 'Oh man, you're taking care of an elderly parent. Sure, sure. We'll send it to you there.' But it's just one of the different excuses because they've lined up where the laptop farm is going to be. We also see them changing their bank account information right before the first day, or right after their first paycheque, because maybe they found a different bank account that has easier ways to turn money into crypto, and so they've rearranged that. So we see those different signs along the way, and then when they actually start work, we see others. Generally, they're the most compliant employees you've ever seen. All their training is done before the deadline. They never have to get reminded to do their security awareness training or their harassment training. They get it all done. They're the model employee when it comes to compliance. But they're not the model employee when it comes to team meetings. They're often obscured on video. What we've found oftentimes is the person who you hired is not the person who shows up for the job.
You have to be really, really attentive to keeping track of who that person is because they swap out the actual execution part of the job to somebody else. And then oftentimes because they're working so many jobs, they can't make all the meetings, and so they end up missing things and getting, because they're double-booked and they can't possibly cover everything and so they start missing stuff over time and their quality degrades. So the earlier you can find them, the less time you waste and the less money you spend. But eventually they will sort of wash out.
Sonia: And I'm guessing they can never attend an in-person interview or meeting.
Ryan: No. So that is one of the things we talk about a lot with companies is that the cost of your controls needs to be less than a flight.
Valeska: Yeah.
Ryan: If the thing that controls whether or not they're real or not is the ability to come into the office and have an interview, or you just send someone there, then that's like the ceiling of how much it should cost. But we also see that so many companies are flooded early in their pipeline. They would like to make sure that those candidates aren't even getting through. They don't want to wait until they're doing the in-person interview to be like, 'Oh, this person's not real.' Like, to not waste their time at all in the pipeline.
Valeska: And what happens when these remote workers actually get discovered? How do they tend to react?
Ryan: There's probably two different sides of it: How do they react within the company, and how they react within the cell.
Valeska: Yeah.
Ryan: We've seen a lot of people within the company exit with grace. Be like, 'Okay, sorry it didn't work out. Bye bye.' And they disappear because they don't want to make, again, they don't want to be on anyone's radar. They want to just go away. HR would like to handle everybody with respect and dignity, and with a suspicion of an insider threat, they want to give someone the opportunity to improve their performance and actually get better. Right? So, like, 'Well, it's not working out. Here's your performance improvement plan.' You don't need to give a nation-state operative a performance improvement plan. You can just let them go. What happens when you give them performance improvement plans, it gives them opportunity and a window to do more harm before they go. So we've seen that, especially in companies that have finance technology, crypto technology, or other things like that, they will use that moment to try to grab everything they can. We've seen other places where, not so much with the North Koreans, but other insider threat. That's when they start positioning destructive malware or sabotage. Once they realise that the walls are closing in. So the best thing to do for a lot of these folks is just to exit quickly. Within the cell, they react completely differently. The guys in our cell all refer to themselves by three initials, so let's say the guy's name is GDP. GDP just lost his dream job, and everyone's like, 'Oh!' And it's all, then they're on to the next job. Like, they do not care. They are fishing and cutting bait. They're just moving on. It's fine. They're rolling with the punches. They're trying to work their metrics. That's all they care about. They do not care about that other, the job. That's the difference, I think, from the company who wants to treat everyone with respect, because you should treat your employees with respect, to the criminals who are trying to victimise them and they don't care at all.
Valeska: You mentioned earlier that North Korea is not the only region where this is happening from, but obviously there's been a huge preponderance from North Korea. Do you have a sense of why they are taking these remote jobs at overseas companies? Is it to try and circumvent sanctions restrictions?
Ryan: That's 100% it. It's economic opportunity. I think … I can't remember where I read the stat that half of the income of North Korea today is funded by ransomware and IT worker scams. It's how they're buying oil. It's how they're feeding their people, I guess. It is a critical source of income for the country because the sanctions have cut them off from all of Western economy, and so that's how and why they're doing it. I think the flip side of why is this the thing that they've latched onto? I think it's fascinating because they've figured out a way to exploit this remote work trend in a way that they got there before anybody else and have gotten there bigger than anybody else. So it's kind of impressive when you think about the scale and scope of what they've done. More than the Chinese pig butchering schemes or other things like that, it seems like they've got this niche cornered.
Sonia: Is it a bit, Ryan, of necessity breeds innovation?
Ryan: They've not been the most sophisticated cyber attacker, but they have been some of the most creative. I mean, through their history. So, considering that they have almost no bandwidth into their country, it's impressive what they've been able to do, especially when it comes down to ransomware. And I think this is just an extension of the same approach of weaponising a criminal enterprise to be able to fund the regime.
Valeska: And they've been responsible for some pretty major attacks, the Sony attack, various crypto attacks, which have been globally significant.
Ryan: It's almost like why do people rob banks? It's where the money is. Like, their motivation is monetary. Sony was a little bit different because it was both. It was mostly revenge, but it was personal in any case. But almost everything else they've done has been something that's led to some financial gain for the country to get our own sanctions.
Sonia: So, Ryan, if a business leader listening to this podcast had never thought about insider threat management as a sort of a structured program, where would you advise them to start?
Ryan: Yeah, I mean, I think North Korea is just the most sensational of all the different insider threat scenarios you can think of. My sense, as a CEO myself, is I want to make sure that I have a workforce I can trust, and who can trust each other, and who feel like we've got their back and they've got ours. Like that's kind of what, the culture I'd like to create. Most CEOs and most heads of HR feel like part of that means you need to trust your employees implicitly. I've lived through too many terrible scenarios to know that works out very well. Security should not be the arbiter of trust. Security is an enabler for risk management and for HR to have a really robust program and culture around making sure that people have the tools they need, minimising risk of people having too much access, minimising the risk of people being able to act with malfeasance, and then have the right interventions when something happens. And that last piece, I think is really, really important. The right intervention in a DPRK North Korea scenario is a quick exercise of the problem. An intervention with somebody, with an employee who's got financial troubles, is going through a terrible breakup of their marriage, and is now looking for ways to monetise their access, is someone who's going through something hard and probably needs help more than they need to be excised from the organisation. And so I think the empathetic leaders who think about 'How do I help my people get through hard times without exposing the business to extra risk?' are probably the ones who are thinking about insider threat the most progressively. And that's where I think that there's a whole lot of opportunity in the space to think through both the legal and risk ramifications of insider threat, but also the whole-of-company approach to making sure that you are giving your workforce the guardrails and support that they need to protect the business and the business protect them.
Valeska: That requires really strong collaboration too between HR teams and fraud teams and cyber IT. This isn't something that can be dealt with in silos.
Ryan: Any time you do something like that in a silo, you risk misunderstanding the real problem. And I'll give you just one quick example. A long time ago, I worked on a team that was, put active badges on everybody, so you never had to badge in and out of a door. The doors open and closed because the badges were continuously active, and they were being tracked at all times through the whole facility. And the HR team thought this would be a great way to track productivity and track what people are doing. In the hospital, there were six nurses on a ward, and five of the nurses were moving in and out of all the different rooms constantly. And one nurse took an hour-long lunchbreak, and no one else did. And they're like, 'This nurse is slacking. We need to fire her.' When they actually approach the business and say, 'Like, this is this is the problem', the business is like, 'No, you don't understand how it works here. All those other nurses are working a ton, and so she went out and got them all lunch and brought it all back so they could keep going. She's actually a productivity enabler, not a drain on productivity. Your little sensors got it wrong.' When you make that decision out of context, you risk screwing it up. And so you don't want security being the arbiter, the person on the wall defending the business in this case. You really want them working with the business and with HR, and with legal, to make sure it's a whole-of-company understanding of what's going on.
Sonia: And I think you mentioned red flags a bit through this discussion, Ryan. It's also identifying red flags, but then contextualising: is there an innocent or nefarious answer for the red flag.
Ryan: You can absolutely see the evil workings behind everything all the time if you're paranoid enough, and there are also usually simpler answers. And so, trying to understand how that works and getting to those simpler answers is absolutely the way companies need to operate. I think with North Korea, when enough of those red flags add up, then it's worth trying to figure out, 'Okay, what do we have here? What's really happening?' And sometimes there is a plausible explanation. And sometimes, sometimes this is North Korea.
Sonia: And I imagine too, with different types of fraud and different types of insider threat, there's different red flags as well. And people having an awareness of when they're seeing things, to sort of consider whether or not they need to look more deeply.
Ryan: Yeah, I think that's right. If you're working multiple jobs, your ability to hold those multiple jobs separate in your head when you're working with different teams is, you slip up a lot. When you're illicitly outsourcing to other people, you don't know the work product you've just delivered. And much like kids with AI in school, like if they can't tell you the essence of what it is they just built for you, they probably didn't build it. And so I think there's a lot of that that relies on good management. That's not just an insider threat program. It really is helping people become better managers to look for those flags.
Sonia: Is people not taking leave still a red flag for some insider threats?
Ryan: Yes, it probably is a flag. It's probably not the most determinative. I do think that people right now are working in a grind culture. They're scared of losing their job, and I think not taking leave is a way to sort of like double down on making sure that they're seen as committed. But I think it also creates a big burnout risk for people, so that might actually lead to more insider risk. And I know in financial companies, especially, that risk of collusion, like they force people to take leave to be able to see what collusion things pop out of the bottom of the enterprise. So there's a lot there too.
Sonia: And what would you say are sort of two or three most actionable things that a company could do at the hiring stage to screen more effectively?
Ryan: Don't be cowed by too good to be true. If it's too good to be true, it probably is. So those perfect-match resumes are the number one red flag. The second is do a little more diligence, especially with referrals, with references and looking at profiles. So spending a little time understanding the digital footprint of the person to see if it really aligns and comports with who they say they're going to be. And then I think, look, trust your gut during those interviews. Almost every person that we've ever found, someone knew that it was wrong, that they were wrong before we ever found them, but they didn't feel like they could speak up, or they didn't feel like it was enough to go on. So those things combined usually are enough. The hiring manager can't do it alone. So that's my fourth thing as a partner. Partner with the experts who can help you navigate it, because it is, especially in this time and space, it is pretty complicated, and you're just trying to find the right candidate to fill the job. You're not a trained fraud detective.
Valeska: Is there a common mistake that you find organisations make when they first become aware that they have hired one of these operatives?
Ryan: The first thing is that you create opportunity for them by trying to handle it like a normal employee who's having a performance issue. The second is you don't call the FBI or the national police force, because they have intel, they can help you. You've been victimised, and so working with law enforcement to help, helps them get a sense of how bad the problem is, helps them put the right resources on these things, helps them work with companies in the future to avoid those problems. Those two things, I think, are the ones that we see the most often as mistakes.
Valeska: You mentioned copycats before. Where do you think this is moving? Is it moving into other geopolitical areas, different types of crime? Where's the trend going now? Especially as some of these red flags that you've mentioned are becoming more sort of widely known.
Ryan: We have seen some of the same identity theft tactics being used by Iranians to do the similar sort of thing. We've seen it through Nigerian IT workers as well, and we're starting to see some of the same identity theft for in-person work with organised crime. So they're getting people jobs who maybe wouldn't pass, normally pass a criminal investigation or a background check. Because now they have a new identity and they're able to get jobs in any kind of role in a company, usually manual labour, but we've seen that as well. So we're starting to see not exactly taking one out of the North Korean playbook, but using a lot of the same tactics.
Valeska: Before we finish up, we generally like to ask for your favorite cyber film, TV show, podcast, book.
Ryan: I'm a firm believer that cyber doesn't translate well to the big screen. Watching someone hack is like watching paint dry. I have a bunch of, I have a lot of books. This Is How They Tell Me the World Ends by Nicole Perlroth. That's a great non-fiction book. My favorite fiction book is Neal Stephenson's Snow Crash, which was the book from the '90s that established the term metaverse. And then he wrote another book early in the 2000s called Cryptonomicon, which I think is required reading for everybody in cybersecurity. It forecasts the world of cryptocurrency. It ties back the hacking of the Enigma machine in World War II and Australian signals intelligence, and there's all kinds of stuff going on in Cryptonomicon. So that's the one I think I've probably read the most. I've probably read it six times.
Valeska: And until then, the film scores will have to do the heavy lifting. Thank you so much again. Really appreciate your time.
Sonia: Thanks, Ryan.
Ryan: Nice to meet you both and hang out with you guys for a little while. Thank you.
Valeska: That was a fascinating discussion. It feels like fiction, but it's certainly not, especially when you look at some of the stats of how prolific these threats are. We've certainly been seeing first-hand a steady increase in the rise of insider threat, but interested in your reflections on some of the measures that organisations should be thinking about taking, off the back of that discussion.
Sonia: I thought what was really interesting was the need for a very clear, comprehensive screening process at the hiring stage, so that you can identify as early as possible whether one of these threats are actually present or potentially present in your organisation.
Valeska: I think as well that idea of actually there needing to be controls across every phase of the employment life cycle as well. It's not something that just stops at screening, but needs to continue throughout that employment process, as a collaboration between many different functions in an organisation.
Sonia: And I think absolutely collaboration, which also means that you have to have the right culture in the organidation that fosters collaboration and transparent communication and cooperation amongst the various functions, because what became really clear from that discussion is not one person will necessarily be able to identify the issue, and you'll have data points or red flags, as Ryan describes it, from a variety of sources. And so, you need to understand what those red flags might be, but actually, who might actually be able to identify them.
Valeska: Thought his comments on termination were really interesting as well.
Sonia: Absolutely, and I think what that tells you is that a risk-based decision will need to be made if you do identify an insider threat. That the perfect process is not necessarily going to be the best risk-based decision because you will potentially create far greater risks for the organisation by pursuing a perfect process, as opposed to dealing more immediately with the issue, given the size and scale of the potential risk and problem.
Valeska: Lots for all of us to think about.
Sonia: Indeed.
Thanks for listening to this episode of The Cyber Brief. Check the show notes for resources from this episode, or visit allens.com.au/cyber for our latest thinking; don't forget to follow to keep up to date on what's ahead for cyber risk, governance, and emerging threats as we interview some of the most respected voices in the industry.
- Defending from within: a guide to insider threat management
- Advisory note – DPRK information technology workers, 31 July 2026.
- Joint statement on DPRK IT workers | Australian Government Department of Foreign Affairs and Trade, 31 July 2026.
- Cyber risks of DPRK IT Workers, 6 November 2025.
- Exposing DPRK Employment Fraud Operations and People, Process, Personas: Nisos Exposes the Human Risk in DPRK Employment Fraud Schemes
- Ryan's book recommendations: This is How They Tell Me the World Ends by Nicole Perlroth, Snow Crash by Neal Stephenson and Cryptonomicon by Neal Stephenson.


