Quincy Labs LogoQuincy Labs
Join ourFollow on

When the Threat Actor Is on the Call

The purpose of the call was supposed to be general support.Discovery.Context.Understanding the client organization’s systems before digging into the work.

Substack
5 min read

When the Threat Actor Is on the Call

Diamond
via Substack
View original

The purpose of the call was supposed to be general support.

Discovery.

Context.

Understanding the client organization’s systems before digging into the work.

Nothing about the beginning of the conversation suggested that the meeting itself would become part of the lesson.

Gina King was there. Marcus Wells was there as another cybersecurity professional. I was there through the lens of IAM, still building that learning path, but already understanding something that matters deeply in this space:

Access is never just technical.

Access is behavioral. Access is organizational. Access is political. Access is trust made operational.

That day, the client organization was dealing with what was understood to be a suspected cyber incident. We were listening, asking questions, and trying to understand the environment. General system categories were being discussed: access points, folders, files, permissions, and where sensitive activity may have been happening.

Then the call shifted.

Not because someone shared a dashboard.

Not because a formal incident report appeared.

Not because anyone announced that a threat actor had been identified.

The call shifted because someone on the client side appeared to think they were muted.

They weren’t.

What followed sounded, at first, like background muttering. The kind of thing people sometimes ignore on a video call because everyone is trying to stay polite and focused. No one reacted. No one interrupted. No one visibly changed their face.

But the words mattered.

The person began talking into another phone. They referenced the fact that cybersecurity vendors had been brought into the situation. Then they started describing what sounded like instructions to remove folders and delete files.

That was the moment the meeting stopped being just a meeting.

From an IAM perspective, that moment mattered because identity risk is not only about whether someone has a username and password. It is about what someone is trusted to access, what they are able to touch, what they understand about the environment, and how they behave when that access is under scrutiny.

A lot of organizations still treat cybersecurity as if the risk lives outside the building.

The attacker is imagined as someone far away. Anonymous. External. Hooded. Hidden behind infrastructure.

Sometimes that is true.

But sometimes the risk is closer.

Sometimes the risk is already in the workflow.

Sometimes it is already in the meeting.

Sometimes the threat model includes someone who knows which folders matter, which files matter, which systems matter, and when outside support has entered the room.

That is why Identity Access Management cannot be reduced to provisioning, de-provisioning, passwords, and permissions. Those are important, but they are not the whole discipline.

IAM is a business discipline because it asks larger questions:

Who has access?

Why do they have it?

What can they do with it?

Who approved that access?

When was it last reviewed?

Does their behavior still match the role they were trusted to perform?

What happens when someone uses legitimate access in a way the business did not intend?

That last question is where many organizations get exposed.

Because a system can show that someone is authorized while the business reality is telling you that something is wrong.

A user can have valid credentials and still represent a serious risk.

A folder can be accessible by design and still become part of an incident.

A meeting can be routine and still reveal that the organization’s trust model is under strain.

In that moment, the professional response was not theatrics. It was composure.

No dramatic interruption.

No visible reaction.

No accusation thrown into the room before the situation was properly understood.

The silence was tactical.

There are moments in cybersecurity where reacting too quickly can create more risk. You can alert the wrong person. You can contaminate the moment. You can turn a signal into a spectacle before the right people understand what has happened.

So we listened.

That part stayed with me.

Because people often talk about cybersecurity like it is all speed. Move fast. Shut it down. Escalate. Contain. Respond.

And yes, urgency matters.

But so does discipline.

The ability to hear something serious and not immediately perform your reaction is a skill. The ability to understand the business, technical, and human layers at the same time is a skill. The ability to know that a call may now be evidence, context, or at minimum a critical signal is a skill.

That is where my IAM learning path started to feel less abstract.

IAM is not only about systems access. It is about the organization’s assumptions about people.

It is about the gap between “this person is allowed in” and “this person is acting in the organization’s interest.”

It is about the difference between trusted access and trustworthy behavior.

That distinction matters.

Because most businesses do not fail at cybersecurity only because they lack tools. They fail because the tool does not know the full story. The access review does not capture the informal workflow. The policy does not capture the side conversation. The org chart does not capture who actually knows where everything lives.

And sometimes, leadership may not even recognize the sound of risk when it happens in real time.

Share

On that call, there was no visible reaction from the client side. The moment passed almost like background noise.

But it was not background noise.

It was a reminder that the meeting itself can become part of the attack surface.

Video calls are not neutral spaces. They are access points into organizational behavior. They reveal who is present, who is nervous, who understands the systems, who speaks with authority, who stays quiet, and who reacts when pressure enters the room.

A cybersecurity call is not just a conversation about risk.

It can become a live demonstration of it.

That is why outside perspective matters. Not because an outside person magically knows everything about the organization. They don’t. But because they may hear what insiders have normalized. They may see what leadership overlooks. They may recognize that the issue is not only technical, but operational.

The strongest cybersecurity posture is not built only on better tooling.

It is built on better interpretation.

You need people who can read logs.

You also need people who can read rooms.

You need people who understand identity.

You also need people who understand behavior.

You need people who can ask whether access still matches intent.

Because the question is not only:

“Did this person have access?”

The better question is:

“What did their access allow them to do once the organization started paying attention?”

That is the part that stays with me.

The threat actor does not always announce themselves as an outsider.

Sometimes the first signal is not a breach notification, a malware alert, or an executive escalation.

Sometimes the first signal is a person on a call who thinks they are muted.

And sometimes, the most important thing an IAM professional can do in that moment is understand that access has started telling the truth.

Connect with Me!

Enjoyed this post?

Get our latest research insights and technical deep dives delivered to your inbox.