Fortinet Cybersecurity Podcast · 2026-03-13 · 27 min
Key moments - from our scoring
Substance score
44 / 100
Five dimensions, 20 points each
Jürgen Stock, former Secretary General of Interpol, explains why cybercrime has evolved from a niche hobby into a sophisticated industrial-scale threat with organized criminal networks operating as crime-as-a-service platforms. Unlike traditional crime, modern cybercriminals can attack multiple victims globally from their homes with minimal risk and maximum profit - the inverse of physical crime economics. Stock argues that individual users, small-to-enterprise organizations, and critical infrastructure operators (electricity, water, hospitals) must fundamentally shift their risk perception, recognizing that cyber attacks are no longer an "if" but a "when." He advocates for three interconnected defenses: basic cyber hygiene (two-factor authentication, strong passwords, software updates, email vigilance), emergency preparedness plans including rehearsals and clear escalation paths to appropriate law enforcement, and robust public-private partnerships - exemplified by Interpol's Gateway initiative in Singapore, which brings major IT security firms and law enforcement together to share real-time threat intelligence across regions. Stock also warns that artificial intelligence will dramatically accelerate the threat landscape while regulators and defenders remain comparatively slow to respond.
Gateway is a joint operations center in the Interpol office in Singapore where major global IT security companies and law enforcement representatives work together 24/7 to exchange strategic information about threat patterns, enabling early detection of attacks emerging in one region (e.g., Asia) before they spread to others (e.g., Americas or Europe).
Modern cybercrime operates as an underground economy where criminals offer specialized services through platforms (like yellow pages), allowing anyone without technical expertise to rent tools and conduct ransomware or DDoS attacks with low risk and high profit. Traditional crime required perpetrators to physically travel to crime scenes with high investigation risk and lower returns.
Stock recommends two-factor authentication, regular software updates, firewalls, strong complex passwords (avoiding simple patterns like names or numbers), careful email scrutiny to detect phishing, and awareness of deepfakes - all foundational practices that block most common attacks if applied consistently.
Only 10-15% of cyber incidents are reported to law enforcement globally, making information sharing with private sector IT security companies and telecommunications providers essential for building an accurate threat assessment and coordinated response.
Pre-incident rehearsals ensure staff knows whom to contact within police (local, state, or federal), how to manage communications with customers and clients, whether to engage private IT security firms, and how to handle extortion negotiations - making response far more effective when attacks succeed.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is heavy on awareness-level platitudes and light on operational insight; the most substantive points (underground economy, crime-as-a-service, Interpol Gateway) are already well-circulated in cybersecurity discourse, and large stretches of the transcript are basic reminders any practitioner already knows.
Apply the very basic means of cybersecurity, the cyber hygiene, if I may say
we have to realize this level of threat. We should not think we are not concerned
The conceptual framing - industrialisation of crime, underground economy, crime-as-a-service, AI as emerging threat - is entirely standard 2024-era cybersecurity messaging with no contrarian or first-principles arguments introduced; the 'check every door in a village' analogy is illustrative but not novel.
it's not a question if you get attacked, it's only the question when and how you get attacked
cyber criminals are already using artificial intelligence. We are still discussing now how to use it
Jürgen Stock is a genuine top-tier practitioner - 10 years as Interpol Secretary General overseeing global law enforcement coordination - giving him rare operational authority on the topic; the score is capped because the conversation fails to extract the depth his biography warrants.
For 10 years, Jürgen Stock was the secretary general of Interpol, the international police organization
We opened a kind of center in the Interpol office in Singapore, an initiative called Gateway, where we have been bringing major global IT security companies and law enforcement representatives together
A handful of concrete data points (10-15% reporting rate, the Gateway initiative, WEF Cybercrime Atlas with ~30 companies) lift the score above baseline, but most claims are stated without source, scale, or measurable outcome, and the named attack examples (Jaguar Land Rover, M&S) are recent news references rather than deep case evidence.
only 10 15 percent of all the cyber incidents are reported to the police
the password for the security cameras at the Louvre when it was attacked and had the big jewel theft in 2025 That password was Louvre L
The host's questions are consistently surface-level awareness prompts with no pushback, no probing of contradictions, and no follow-up that forces the guest to be specific; the interview functions as a soft promotional conversation rather than an intellectually demanding exchange.
What are some of those basic cyber hygiene tasks that we should all be thinking about that sometimes we don't think about
Okay, so let's stop there and not do too much advertising for this industry
Computed from the transcript - who did the talking, and the words that came up most.
Cybercrime runs like a business, fast, scalable, and hard to stop. Jürgen Stock, Former Secretary General INTERPOL, explains how criminal networks work, why basic cyber hygiene still blocks many attacks, and how police, companies, and governments must share data to keep pace as AI speeds crime up. Watch or listen to the episode, and read the blog to understand how cybercrime works at scale.
Transcribed and scored by The B2B Podcast Index.
We opened a center in the Interpol office in Singapore, an initiative called Gateway, where we have been bringing major global IT security companies and law enforcement representatives together and exchanging strategic information about threat patterns, what is popping up perhaps in Asia, will be in the Americas or Europe tomorrow and vice versa. Hello, and welcome to Brass Tax Talking Cybersecurity, the 40Net podcast that gets straight to the point on cyber risk. I'm your host, Joe Robertson.
This season, we're taking a broad look at cybersecurity, not just as a business issue, but as a societal one. Today, we're going to discuss cybercriminality and especially how governments, businesses, and citizens should think about how we protect ourselves. And who better to talk about this than a former top cop? For 10 years, Jürgen Stock was the secretary general of Interpol, the international police organization.
He retired in 2024, but is still actively talking about what our modern society must do to protect itself from major criminal threats. And cybercrime, it's right at the top of that list. Jürgen, welcome to Brass Tacks. Hello, Joel.
Thank you very much for inviting me. It's a pleasure. Jürgen, you've got over 40 years of policing experience, first in Germany and then internationally at Interpol. So you've seen a lot over the years, but your focus now in retirement seems to be on cybercrime.
Why? Yeah, I mean, that's a good question because a lot has been changing since I started my career some decades ago in the good old physical way when criminals had to travel to a crime scene, had to leave a crime scene with all the risks, leaving fingerprints, perhaps DNA or other markings at a crime scene. These, I'd like to say these good old times, not always good old times, but these times have been changing dramatically with what we today call cybercrime. So the kind of industrialization of crime that came particularly with the internet allowing people in an unprecedented way to not leave their homes, to commit crimes, but to be connected from any point in the world that is having internet access to any other point, anywhere else in the world, and commit crimes online.
And this is a completely new world of criminality with new challenges, new risks, and of course also new opportunities for law enforcement to fight that type of crime and to be united. So, on the one hand, very interesting. On the one hand, of course, the Internet has been bringing us a lot of opportunities for growth, prosperity, well-being, economical development. On the other hand, unprecedented opportunities for criminals to attack our IT infrastructure with all the consequences.
Well, you're absolutely right. Over the last many years now, it's been increasing. We've been seeing more and more cybercrime. Just recently, we saw cyberattacks that shut down Jaguar Land Rover, for example, in 2025.
That shut down their production. Marks and Spencer was taken offline for a number of days. There have been lots of cases of hospitals and other facilities that have been held hostage to ransomware. I don't want to go so far as to say that the Internet is a no-go zone.
But do you think we're making progress protecting ourselves there? I mean, all these phenomena you have been describing, Joe, are by no means new. Ransomware attacks, it's a kind of old issue. Already happened many, many years ago.
It was perhaps around, I don't know, 2015 when the situation changed from what we described at that time, script kiddie kind of criminals who have been sitting in their garage or wherever and did attack IT infrastructure, let's say. It has been changing completely into something that we now call the underground economy, where we see criminals based on their specialization coming together, sharing their expertise and in a very new way of organizing criminal activity, attacking IT infrastructure, let's say, which at the end means it's everything between our private computers, our mobile phones, our desktops on the one hand.
On the other hand, the so-called critical infrastructures within our society. So electricity, hospitals, water supply, and so on. So this is the spectrum. It's, again, a totally different way of criminals organizing themselves compared with a traditional organized crime kind of appearance where people didn't know each other.
They very often came from the same country, sometimes even from the same region. So built on knowing each other and trust changing into something again we now call the underground economy where people are using their nicknames. They are offering their criminal services in a way you know like maybe in previous times the good old yellow pages. So they come together.
You can easily rent a criminal tool. you have a hotline in case you are in trouble in executing a ransomware attack and you can you know build new coalitions you know depending on what you are planning to do you no longer need to be an expert an it expert like maybe 15 years ago everyone now with access to this underground world underground economy can start a denial of service attack a ransomware attack or anything else and that is the new level of risks but but the new level of threats against our societies and again something that appears to be crime in an industrial scale and that again is completely changing the landscape and making it so easy for criminals with a relatively low risk to make a lot of money and again that changing from the let say from the traditional crime times where you very often had high risk to be investigated and brought to justice.
And let's say little profit, smaller profits. It's now the other way around. It is low risk and very high profit for cyber criminals. So you're saying that this has moved from being a cyber crime has moved from just being a hobby for kids into a profession with its own experts.
And it's an industry that we might be calling crime as a service. Yeah, indeed. I mean, it's again, in the past, in the times of physical crime, the perpetrators had to go to the crime scene. They could not go to, let's say, to every house trying you know whether a door is open or window is open or not in the cyber arena using technical means and now we will talk perhaps about artificial intelligence at a later stage you can actually go if you if you like that that scenario you can check every door in a particular let's say in a particular village whether the door or the window is open or not so with very simple means.
And you can do it very quickly. And you can do it very quickly. And again, that's why I call that industrial scale. It was quite cumbersome and it did require a lot of preparations and doing in the past.
Now, today, you can sit at home or wherever you are on your sofa and you can attack multiple victims in a very short period of time. Okay, so let's stop there and not do too much advertising for this industry, which makes it sound very good for someone to try to do. Let's talk about what we, the good people, can do to organize ourselves, whether we're individuals or organizations or governments, what we can do to fight cybercrime. Maybe the first thing we need to do is stop and check what our own vulnerabilities are.
That's what I think you would call a threat assessment as a police officer. Wouldn't that be the term? I mean, the most important part, Joe, is changing our mindset, because, again, this is a huge threat for all of us, whether we are individuals, our kids, our parents, companies, whether they are small, medium size or big companies, or whether it's the critical infrastructures in our countries. So all these elements are under acute threat.
So I already said maybe 10 years ago, it's not a question if you get attacked, it's only the question when and how you get attacked. And unfortunately now, some 10, 15 years later, this is exactly the kind of threat we are facing because more and more countries have already been attacked. Some countries are even not aware that a virus or a malicious software is already sitting in their IT network and is searching for a good opportunity to steal data, to be activated, let's say.
So this is the new level of crime. We have to still, we have to realize this level of threat. We should not think we are not concerned. so in my company I do not have anything interesting that could be stolen.
So everybody should consider I could become a victim of this type of crime and I should at least apply the very simple basic measures to protect my systems because the good news is a lot of these attacks can be prevented if the very basic means are being used properly. We will perhaps talk about that a little later. But it means we need to change our risk perception. It's not that we can say, you know, it's somebody else who might be affected.
It's not me. Like, maybe again coming back to the traditional world, if you are living in a community and you become aware that somebody become victim of a house breaking, you might be concerned, you might consider, oh, maybe I'm the next one and I have to protect my home. If it's a cyber attack, if you become aware that maybe your neighbor has become victim of a cyber attack, you don't have the same perception. You might think, okay, it's my neighbor, it does not concern me.
But that perception is wrong, so we have to consider that we are all potentially becoming victims, that we are all potentially under attack in this kind of industrial scale way in which these attacks are being conducted. So changing awareness, establishing the very basic means of security, like you're not leaving any valuables in your car during nighttime. So do the same in cyberspace. Apply the very basic means of cybersecurity, the cyber hygiene, if I may say.
And you are already, let's say, well protected against these kind of threats. What are some of those basic cyber hygiene tasks that we should all be thinking about that sometimes we don't think about because we aren't focused on it, but you are? Yeah, perhaps we have all heard about these measures like two-factor authentication. Software updates on a regular basis, having a firewall, look into your mails, what is the source of this mail, does that sound familiar or does it sound strange?
if it sounds strange, make sure you think about opening an attachment or opening the mail at all. Again, with these deep fakes, this situation is getting more complex. But again, you will find a lot of basic means and recommendations on websites of police services, national centers for cyber security. And again, implementing these basic means already provides a good level of protection.
Well, one basic area that I think is important is just in passwords. It sounds obvious, but we need to have stronger passwords. When you consider that the password for the security cameras at the Louvre when it was attacked and had the big jewel theft in 2025 That password was Louvre L So not particularly secure But I understand the problem isn't easy, especially since it feels really technical. Lots of people have no idea really of the extent of the problem, do they?
Yeah, I mean, I think we all have a certain degree of awareness but nevertheless in the day-to-day work using these tools perhaps we we try to let's say suppress the risk perception if I may say so so we think it doesn't concern me everything will go right so we are not taking care of the very simple and basic cyber hygiene activities and measures and that mindset needs to change because again applying these measures already provides for a good level of protection against the most common cyber attacks there is absolutely no doubt but again that requires this perception of risk being aware and going let's say the extra mile for instance, with using a more complex password and not just one, two, three, four, five, six, or your name or your children's names or something, that makes cyber criminals work very easy to attack you successfully.
Okay, that's true. And we should be protecting ourselves. On the other hand, there are times when we do get attacked and they're successful. I know a lot of executives who don't even know who they should talk to to report a cybercrime or if they should.
Police forces in different countries and different localities will have different abilities. Obviously, part of protecting ourselves also involves the police and having them able to help us, right? Yeah. I mean, you should have an emergency plan already in place.
I mean, definitely, if you are running a small, a medium-sized or a bigger company, you should already be prepared in case you would be attacked or successfully attacked. For instance, with ransomware, that suddenly you find your systems encrypted, blocked, no access to your IT system any longer. You should be prepared in terms of a communication plan, whom to contact in such a situation. What are you going to do regarding communication with your customers, your clients, your staff?
Do you know whom to approach amongst police services? Is it the local police? Is it the state police? Is it the federal police?
You should even kind of do a rehearsal, an exercise to be prepared in case there would be a successful attack against your IT systems. So this kind of preparedness, having a plan ready, a rehearsal, That makes it easier. The situation will never be easier, but it makes it easier, let's say, to handle such a situation, to know what to do, that your staff, your team knows what to do, whom to approach, do I need an external company to try to get access to my data again? what am I going to do if there is a communication with the perpetrators who are maybe conducting a kind of extortion, blackmailing, negotiations with perpetrators.
All that are areas where there is professional help available, there is police available, but you need to know before the incident happens whom to contact. contact. So be prepared, do the exercising, do the rehearsal, and then it will be more likely to kind of overcome such a situation successfully. So you brought up the police.
Do the police these days have the tools that are necessary to investigate and to solve the cyber crimes, or do they need to involve private companies? I mean, increasingly in the so-called developed world joe definitely police in today's world is much better in reacting appropriately at various levels and again i'm coming from a from a federal system where you have local police you have state police you have federal police and that's why again i'm advocating for getting an idea whom to approach in a situation of crisis is it my local police department is a state police is it federal police should be clear.
Police themselves should get in contact with companies to already start that kind of dialogue, but police today is prepared to help in such a situation to also take concerns into consideration. For instance, that maybe a victim might think police is stopping my activities, they are pulling the plug and stopping my machines to run. This is no longer the case. So police knows how to take these issues of business continuity into consideration.
Very often it's team play between police and the kind of private emergency IT security company that helps fixing the issue so that you take into consideration the needs of securing evidence to successfully investigate the case on the one hand, but taking business continuity also into consideration on the other hand. So professional police private sector teams are available, at least in the so-called developed world, to handle these situations appropriately. And starting on the one hand, investigations, who is behind an attack?
And on the other hand, how do I ensure business continuity? Many parts on the other hand of the world still do not have the necessary skills, tools, resources to organize the same way of professional cooperation. This is where of course private companies need to have their own IT experts who help dealing with such a situation situation or and having a point of contact already in the private sector, a company that is helping to deal with such a kind of crisis situation. And how does this relate to public-private partnerships, which I've been reading about?
Are those types of relationships you're talking about or does that go, do PPPs, public-private partners, go beyond what you've just talked about? I mean PPP is an important point regarding let say police work first and foremost But it starts with getting an overview how does the situation look like Because unfortunately let say globally only a small percentage of all the incidents that are taking place are being reported to police or other administrative authorities So specialized authorities for IT security, for instance.
in germany for instance but also in the united states police is saying only 10 15 percent of all the cyber incidents are reported to the police so you necessarily need information from private sector big i.t security companies who do a kind of global monitoring of the threat landscape telecommunication providers who are doing a monitoring 24 7 of the global attack landscape if you bring all these information together from police, from administrative cyber security administrative authorities and private sectors you get a very good understanding you mentioned threat assessment earlier in our conversation you get a good threat assessment but you need exchange of information by these various players if it comes to investigations a lot of of information intelligence sits exactly with these private sector companies, partners, who have the information about a particular new attack scheme, new patterns of attacks.
On the other hand, police is having important intelligence from investigations that have been conducted. If you bring all these information together in a public-private partnership, your understanding is much better, your response as a society against criminals is much stronger, and that is why I'm advocating for these kind of, yeah, at least PPP, public-private partnerships, information sharing in both directions, and the next step would be even better, considering joint centers where representatives from public sector and private sector are sitting together 24-7 and monitoring this very dynamic situation of cyber attacks.
That's something I did in Interpol. We opened a kind of center in the Interpol office in Singapore, an initiative called Gateway, where we have been bringing major global IT security companies and law enforcement representatives together and exchanging strategic information about threat patterns what is popping up perhaps in asia will be in the americas or europe tomorrow and vice versa that these kind of yeah let's say these architecture of security that meets the dynamics of today's yeah cyber crime situation and the flexibilities these cyber criminals are having, again, by having the globe, the world as a potential place to conduct their criminal activity.
That's very interesting, the example of Interpol in Singapore bringing together the private sector and the public sector. I know there are other examples, like there's a cyber crime atlas that has been put together by the World Economic Forum and something like 30 private companies together, and it's been used to solve crimes. And I think that's very important. We don't have much time left.
I guess the most important thing that I'd like us to take away from this is what your thinking is on what the primary activities that we as citizens need to keep in mind when it comes to protecting ourselves, when it comes to cybersecurity, and what is now a brave new world with criminals everywhere in a sense. I mean, again, Joe, it is raising awareness. This is an acute threat. And I'm very concerned regarding the future now with artificial intelligence.
Those agents being used kind of autonomously acting agents that are being used now increasingly to help within companies for data and analytical purposes, information handling and so on, which also can be used for criminal purposes. Of course, if a system gets infiltrated with malware, for instance. So we have to expect that the threat situation is getting worse. And that means we all have to raise the awareness about the risks, but also the opportunities to protect our systems.
But we can only do that in partnerships at a local level, at a national level and internationally. We have to stand together. We have to share information instantly. And if we are conducting these, we seem to be, let's say, well protected.
But again, cyber criminals are already using artificial intelligence. We are still discussing now how to use it, we are discussing regulations and time is our enemy. So we don't have, you know, the criminals, they don't wait for regulation. They have the resources, they use these tools immediately and they are much faster than regulators, diplomats, police services and so on.
So we all have to do what we can do within our, you know, area of influence to protect our systems. That's of utmost importance. Well, thank you very much. That's a very sobering look at cybercriminality, but with some good ideas on what we should be doing.
So, Jürgen, thank you very much for talking with us. My pleasure. Thank you very much for having me. Well, that's it for today's episode of Brass Tax Talking Cybersecurity, the 40-net podcast that gets straight to the point on cyber risk.
My guest was Jürgen Stock, former Secretary General of Interpol. I hope you found our discussion interesting, insightful, and useful. You can watch more Brass Tax Conversations on YouTube and Fortinet TV or listen on your favorite podcast platform under the Fortinet Cybersecurity Podcast channel.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.