Activate Industry!: Moving Beyond Defense to Disruption and Active Defense
Sandra Joyce (Vice President, Google Threat Intelligence · Google Security)
RSAC 2026 Conference · Main Stage Keynote
Overview
In this compelling talk, Sandra Joyce, Vice President of Google Threat Intelligence, Google Security, articulated a critical shift in the cybersecurity paradigm: moving beyond traditional defensive postures to embrace active defense and disruption. Delivered at the RSA Conference, Joyce's presentation underscored the urgent necessity for the cybersecurity industry to proactively shape adversary outcomes rather than merely react to threats. The talk highlighted how increasingly sophisticated, coordinated, and AI-powered cyber adversaries demand a more assertive, collaborative, and systemic approach to defense.
Key moments
- 1:30 Adversary sophistication: from 8 hours to 22 seconds
- 2:20 How AI is changing the cyber threat landscape
- 4:20 Embracing active defense: going upstream to disrupt
- 5:20 Google's four pillars for threat actor disruption
- 6:05 Case study: Disrupting the IPIDEA proxy network
- 8:10 Tangible impact of the IPIDEA disruption
Activate Industry!: Moving Beyond Defense to Disruption and Active Defense
Speakers: Sandra Joyce, Vice President, Google Threat Intelligence, Google Security
Conference: RSA Conference
YouTube: https://www.youtube.com/watch?v=FkArgOq2d1A
Overview
In this compelling talk, Sandra Joyce, Vice President of Google Threat Intelligence, Google Security, articulated a critical shift in the cybersecurity paradigm: moving beyond traditional defensive postures to embrace active defense and disruption. Delivered at the RSA Conference, Joyce's presentation underscored the urgent necessity for the cybersecurity industry to proactively shape adversary outcomes rather than merely react to threats. The talk highlighted how increasingly sophisticated, coordinated, and AI-powered cyber adversaries demand a more assertive, collaborative, and systemic approach to defense.
Joyce argued that the private sector, by operating the very infrastructure that adversaries abuse, possesses a unique vantage point and technical capabilities often inaccessible to government agencies. This position enables the industry to go "upstream" and disrupt threat actors at their source, thereby shifting the economics of cybercrime to make it too costly, difficult, and risky to pursue. The core message was a call to action for the entire industry to activate, fostering radical partnerships to dismantle entire threat networks and establish a new status quo where defense is truly proactive and effective.
The talk is significant because it challenges long-held notions of cyber defense, advocating for a holistic strategy that combines legal action, public disclosure, technical takedowns, and product hardening. By presenting concrete examples of successful disruption campaigns against major threat infrastructures like residential proxy networks, certificate resellers, and state-sponsored espionage groups, Joyce illustrated the tangible impact of this active defense philosophy. It provides a roadmap for how the global community of defenders can collectively transform the narrative of cybersecurity from one of constant retreat to one of collective, formidable action.
Background
▶ Watch: Adversary sophistication: from 8 hours to 22 seconds (1:30)
Over the past decade, the cybersecurity community has successfully fostered unprecedented levels of public-private collaboration and intelligence sharing, creating a more connected and mature global defense network. However, Sandra Joyce emphasized that while this foundation is crucial, intelligence sharing alone is no longer sufficient to counter the escalating sophistication of modern adversaries. The threat landscape has undergone a fundamental shift, demanding a more proactive stance.
Adversaries are no longer isolated actors but are resilient, well-resourced entities backed by sophisticated ecosystems of contractors and intelligence services. This evolution is evident in several critical trends. First, there's a significant shift towards mass extortion groups like FIN11, which leverage zero-day exploits to compromise hundreds of organizations simultaneously. Groups such as BRICKSTORM specifically target enterprise suppliers, harvesting data for zero-day deployment and downstream pivots, demonstrating a strategic and interconnected approach to attack.
A particularly alarming development highlighted in Google’s 2026 M-Trends report is the dramatic reduction in the median time between initial access and the handoff to a secondary threat group. This crucial window has plummeted from eight hours in 2022 to a mere 22 seconds in 2025. This statistic reveals a shift from opportunistic selling of access to highly organized, pre-planned partnerships between criminal groups, where handovers are coordinated even before the initial breach occurs. This evolution signifies a significant increase in the organization, coordination, and overall sophistication of the cybercrime ecosystem, raising the stakes for defenders as response times dwindle.
Compounding these challenges is the adversaries' increasing embrace of Artificial Intelligence (AI), which is transforming the attack landscape in three critical ways:
- Speed: Agentic AI approaches for exploit development are enabling adversaries to outpace human-driven controls, breaking security operations that rely on human intervention.
- Scale: Adversaries are leveraging agentic AI and open-source frameworks, such as HexStrike MCP, to automate the full attack lifecycle. APT31, for instance, has been observed using these tools and agentic workflows to test attacks against targets in the United States.
- Sophistication: Threat actors are using AI to significantly improve existing capabilities across the entire intrusion lifecycle, potentially putting major capabilities like access to zero-day exploits into the hands of a broader range of well-resourced groups.
Given these rapid advancements in adversary capabilities and coordination, the traditional model of defense, primarily focused on detection and response post-breach, is increasingly inadequate. The urgency for defenders to "go upstream" and disrupt adversaries at their source has become paramount.
Key Findings
▶ Watch: Embracing active defense: going upstream to disrupt (4:20)
The central finding of Sandra Joyce's talk is that the cybersecurity industry must adopt an active defense philosophy, moving beyond reactive measures to proactively disrupt adversary operations. This approach is not "hacking back" but rather the legal and ethical use of intelligence to protect platforms and shift the economics of cyber threat operations. The ultimate goal is to make cybercrime so costly, difficult, and risky that it ceases to be a viable path for any adversary.
Google's disruption strategy, presented as a model for the industry, is built on four specific pillars:
- Civil Legal Action: Employing legal avenues to hold threat actors accountable and seize their critical infrastructure.
- Public Disclosure: Utilizing "sunlight as disinfectant" to expose attacker tools and tactics, forcing them into expensive and time-consuming retooling phases.
- Technical Takedowns: Creating a hostile environment for attackers on Google's own platforms and those of its partners through direct technical interventions.
- Product Hardening: A crucial, often overlooked pillar focused on driving product improvements and remediations to prevent adversaries from regaining access or exploiting vulnerabilities in the future.
The talk presented compelling evidence of the effectiveness of this multi-pronged disruption strategy through several detailed case studies. These included the significant degradation of the IPIDEA residential proxy network, the mass revocation of malicious certificates tied to a major certificate reseller, and the dismantling of a global espionage campaign by the PRC-nexus cyber espionage group GRIDTIDE. Each case demonstrated immediate and measurable impact, forcing adversaries to incur significant costs and operational friction.
Furthermore, Joyce highlighted that disruption is not a one-time event but a continuous process, akin to security itself, requiring ongoing action. The talk also underscored the critical role of AI in both the evolving threat landscape and as a powerful tool for defense. Google is actively leveraging AI to harden its own models, automate vulnerability hunting, and develop advanced threat models to stay ahead of AI-powered attacks.
Finally, a key finding and call to action was the necessity of a whole-of-community approach and radical partnership. Disruption, Joyce argued, cannot be achieved by tech giants alone; it requires collaboration across law enforcement, tech providers of all sizes (including SMEs), and front-line defenders. This collective action is essential to build systemic resilience, fix root causes of vulnerabilities, and ultimately break the "Whack-a-mole" cycle of individual indicator chasing, moving towards dismantling entire threat networks.
Technical Deep Dive
▶ Watch: Google's four pillars for threat actor disruption (5:20)
Sandra Joyce provided several concrete examples of Google's disruption efforts, showcasing the technical depth and multi-faceted nature of their active defense strategy. These operations illustrate how Google leverages its unique position and capabilities to tackle sophisticated threat actors.
Disrupting IPIDEA's Residential Proxy Network
One significant case study involved the disruption of IPIDEA, a residential proxy infrastructure widely abused by a vast array of malicious actors. Unlike traditional proxies, IPIDEA sold access to IP addresses owned by internet service providers (ISPs) that service residential or small business customers. This allowed attackers to route traffic through an array of consumer devices globally, effectively masking their malicious activity by hijacking legitimate IPs. This created a massive blind spot for defenders.
IPIDEA posed three critical risks:
- Botnet Facilitation: IPIDEA's Software Development Kits (SDKs) were a primary engine for building and controlling botnets, as observed with BADBOX 2.0, and more recently, the Aisuru and Kimwolf botnets.
- Exit Node Hijacking: It turned innocent users into exit nodes, causing unsuspecting consumers to be flagged or blocked by their own ISPs.
- Network Vulnerability: Applications incorporating IPIDEA's SDKs effectively punched holes in home networks, allowing bad actors to pivot to other private devices on the same network once a device became an exit node.
Google led a synchronized, multi-pronged takedown:
- Legal Action: Secured court orders to seize and shutter the command domains controlling the proxy traffic.
- Intelligence Sharing: Shared detailed technical intelligence on IPIDEA's SDKs with law enforcement and platform providers, triggering an industry-wide cleanup.
- Product Hardening (Google Play Protect): Utilized Google Play Protect, Android's built-in security, to automatically warn users to remove apps incorporating IPIDEA's SDKs and block future installation attempts.
The impact was immediate and substantial. Google observed over 550 individual threat groups (including those from China, North Korea, Russia, and Iran) utilizing IPIDEA exit nodes in a single seven-day period in January. By February 3rd, there was a 90% reduction in requests from IPIDEA IP addresses observed by Okta and a 75% drop-off in traffic from exit nodes seen by Comcast. Adversaries were directly observed "whining" about their infrastructure being taken down. While IPIDEA has attempted to rebuild some infrastructure, Google continues its disruption efforts, underscoring that disruption is a continuous process.
Revoking Malicious Certificates from a Reseller
Google identified a pivot point in the certificate reseller market where a single actor was operating an industrial-scale automated business. This reseller provided a streamlined pipeline for threat actors to acquire seemingly legitimate code-signing certificates, thereby laundering their malware and making it appear trustworthy. This single reseller served as a primary source of trust for a massive range of disparate threat groups, acting as an automated gatekeeper for malicious activity across the web.
To disrupt this operation, Google coordinated directly with Certificate Authorities (CAs) to initiate a mass revocation of compromised certificates. By sharing specific Tactics, Techniques, and Procedures (TTPs), Google not only removed existing malicious certificates but also provided CAs with the telemetry needed to sharpen their future detection capabilities.
The investigation uncovered over 100 malicious certificates tied to this single operation. The impact was immediate: adversaries were stripped of their enterprise-grade legitimacy, forcing them to pivot to less trusted individual validation certificates, which are largely untrusted by modern operating systems and security tools. Within 10 weeks, these actors migrated further to even less sophisticated services relying on shared certificates, which are significantly easier for defenders to detect, track, and revoke at scale. This action successfully amplified Google's impact across an entire network of actors.
Dismantling the GRIDTIDE Espionage Campaign
Google also worked with partners to disrupt GRIDTIDE, a suspected PRC-nexus cyber espionage group tracked since 2017, with confirmed intrusions in 42 countries across four continents. This actor sought to exploit the trust and reliability of Google's ecosystem, abusing Google Cloud for heavy lifting and Google Sheets for stealthy Command and Control (C2) mechanisms. By leveraging legitimate services, GRIDTIDE aimed to blend into normal enterprise traffic, making traditional detection incredibly difficult.
Google's response was designed to create maximum operational friction:
- Infrastructure Termination: All Google Cloud projects controlled by the attacker were terminated, severing persistent access to environments compromised by the novel GRIDTIDE backdoor.
- C2 Blinding: Access to Google Sheets and associated Google Cloud accounts used for C2 were disabled and revoked, blinding their command infrastructure.
- Intelligence Dissemination: A comprehensive set of Indicators of Compromise (IOCs) was released to the global community, and tailored signatures were deployed to intercept related malware, preventing migration of tactics.
- Sinkholing: In collaboration with partners, all known infrastructure, including both current and historical domains, was identified and sinkholed to further dismantle the group's reach.
These intrusions took the adversary years to build. By stripping away their underlying environment, Google ensured these operations could not be easily re-established, significantly hindering the group's global footprint.
Active Defense on the AI Frontier
Recognizing AI as the "most important frontier of all," Google applies its active defense philosophy to its AI infrastructure. As adversaries adopt AI, Google is disrupting them at the source using four key levers:
- Disabling Malicious Infrastructure: Proactively disabling projects, accounts, and assets of known bad actors who misuse Google's AI tools.
- Hardening AI Models: Operating a continuous feedback loop for Gemini and other AI models, directly feeding threat intelligence into product development. This teaches models to recognize and refuse malicious requests before an attack can be generated.
- Automating Vulnerability Hunting and Patching: Moving from manual patching to AI-driven hunting. Tools like Big Sleep are already discovering zero-days before exploitation, while CodeMender uses Gemini to automatically fix critical vulnerabilities in code.
- Developing Advanced Defenses and Threat Models: Teams at Google DeepMind are building specialized defenses for generative AI and deploying active monitoring across the ecosystem to identify misuse in real-time.
These efforts demonstrate a comprehensive, technically sophisticated approach to active defense, integrating legal, public, technical, and product-based strategies to disrupt adversaries across various attack vectors and technologies, including the emerging AI landscape.
Demo / Proof of Concept
▶ Watch: Case study: Disrupting the IPIDEA proxy network (6:05)
This talk focused on presenting the strategic framework of active defense and detailing past successful disruption operations undertaken by Google and its partners. It did not feature a live technical demonstration or a proof of concept during the presentation itself.
Defensive Implications
▶ Watch: Tangible impact of the IPIDEA disruption (8:10)
The shift to active defense and disruption carries profound implications for all defenders, necessitating a fundamental rethinking of cybersecurity strategies. Sandra Joyce outlined several key areas where the industry must adapt and collaborate:
- Building Resilience through Intelligence Feedback: Every disruption must feed intelligence back into defensive mechanisms. This continuous feedback loop is crucial for making the entire ecosystem more hostile to future abuse and ensuring that once a tactic or infrastructure is "burned," it stays burned. Defenders must integrate lessons learned from successful disruptions into their own threat intelligence platforms, security controls, and incident response playbooks.
- Systemic Protection Beyond Cleanup: The industry must move beyond simply cleaning up after attacks. The goal should be to use intelligence to build new, native protections that fix the root causes of vulnerabilities. This means not just kicking bad actors off platforms, but implementing preventative measures that make it inherently harder for them to regain access or exploit similar weaknesses in the future. This approach requires deeper collaboration between security teams and product development, emphasizing security by design.
- Embracing a Whole-of-Community Approach: Disruption is not solely the responsibility of large tech companies. Small and medium-sized enterprises (SMEs) are equally vital to this mission, often serving as crucial nodes in supply chains or as targets that can be leveraged for downstream attacks. Defenders must embrace flexible partnership models that prioritize the most effective collaborators for each specific threat, fostering information sharing and coordinated action across organizations of all sizes. This includes sharing actionable IOCs, TTPs, and even insights into adversary infrastructure.
- Cultivating Radical Partnership: The vision for effective active defense hinges on moving past traditional competition towards radical partnership. This encompasses collaboration between law enforcement agencies, tech providers of all scales, and front-line defenders. By aligning efforts, the industry can break the perpetual "Whack-a-mole" cycle of chasing individual indicators. Instead, the focus shifts to dismantling entire networks and ecosystems that support cybercrime, proving to stakeholders and the public that defense can be truly effective and proactive. This requires trust, shared goals, and mechanisms for secure, timely information exchange.
- Leveraging AI for Defense: As adversaries increasingly weaponize AI, defenders must proactively use AI to enhance their own capabilities. This includes deploying AI for automated vulnerability hunting (e.g., Big Sleep for zero-day discovery), automated patching (e.g., CodeMender using Gemini), hardening AI models against adversarial attacks, and establishing real-time monitoring for misuse. Integrating AI into security operations is no longer optional but a strategic imperative to keep pace with the evolving threat landscape.
By adopting these defensive implications, the industry can collectively transform fragmented defensive efforts into a formidable, proactive force that significantly raises the cost and risk for adversaries, leaving them fewer places to hide.
Key Takeaways
- Active Defense is Imperative: Traditional, reactive defense and intelligence sharing are no longer sufficient against increasingly sophisticated, coordinated, and AI-powered adversaries. The industry must adopt a proactive active defense philosophy to shape adversary outcomes.
- Multi-Pillar Disruption Strategy: Effective disruption relies on a holistic approach encompassing civil legal action, public disclosure, technical takedowns, and crucial product hardening to prevent re-entry and future exploitation.
- Demonstrated Effectiveness: Case studies like the disruption of IPIDEA's residential proxy network, the mass revocation of certificates from a malicious reseller, and the dismantling of the GRIDTIDE espionage campaign showcase the tangible, measurable impact of multi-pronged disruption efforts.
- AI as a Dual-Edged Sword: While adversaries leverage AI for speed, scale, and sophistication, defenders must proactively employ AI for automated vulnerability hunting (Big Sleep), patching (CodeMender), hardening AI models (Gemini), and developing advanced threat defenses.
- The Power of Radical Partnership: True, systemic disruption requires a "whole-of-community approach" and "radical partnership" across law enforcement, tech providers of all sizes, and front-line defenders to collectively dismantle entire threat networks and shift the economics of cybercrime.
- Disruption is a Continuous Process: Like security, disruption is an ongoing journey without a finish line, requiring continuous action, intelligence feedback, and adaptation to adversary retooling attempts.
About the Speaker(s)
Sandra Joyce is the Vice President of Google Threat Intelligence at Google Security. In this role, she leads Google's efforts to understand and counter cyber threats globally, advocating for proactive strategies and industry-wide collaboration to enhance collective defense capabilities.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Sandra Joyce is a credible operator with real intelligence background and Google has done genuinely impactful disruption work — the IPIDEA takedown numbers are real, GRIDTIDE is a real campaign. But this talk, as presented, is a strategic keynote dressed up as technical content. It's a polished call-to-action from a vendor VP at RSA, which is exactly what it is: a well-produced marketing keynote for Google's threat intelligence brand. The 22-seconds-to-handoff statistic is interesting but unverified in the transcript. 'HexStrike MCP' and 'APT31 agentic workflows' are dropped without technical substantiation. 'Big Sleep' and 'CodeMender' are name-checked but not demonstrated. The…
Heather Calloway (CISO) — SOLID
Sandra Joyce makes a credible, well-evidenced case for industry-led disruption as a strategic posture — and the operational examples are real. The IPIDEA takedown, certificate revocation campaign, and GRIDTIDE dismantlement are concrete, measurable, and illustrate genuine asymmetric leverage. But the talk is most useful to organizations who already operate at Google's scale, and Joyce never quite closes the gap between what Google can do and what the rest of the industry actually can. The governance and accountability dimensions — who owns this posture inside an enterprise, how it gets authorized, how smaller organizations participate without becoming liability exposure — go largely…