ICAEW's latest piece nails why Crime as a Service is the business model that should worry you most

Started by EventHorizon27, Yesterday at 11:20 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: ICAEW's latest piece nails why Crime as a Service is the business model that should worry you most   Views(Read 68 times)
Active members in this topic:
EventHorizon27(1) IronQuarry48(1)

EventHorizon27

ICAEW ran a good explainer this month on Crime as a Service, the idea that illegal operations have started copying legitimate Software as a Service methodology almost exactly, and the argument is that AI is now supercharging that model rather than creating an entirely new threat from scratch

What makes CaaS genuinely dangerous compared to old school hacking is the division of labour, you no longer need deep technical skill to run a ransomware campaign or a phishing operation, you just rent the tooling from someone else who built it, the same way any legitimate business rents cloud infrastructure instead of building a data centre

AI slots into that model at almost every stage, better phishing copy that reads naturally instead of the broken English that used to be a red flag, deepfake voice and video convincing enough to pass casual verification checks, and malware that can be tweaked and iterated faster than defenders can catalogue new signatures

The professionalisation angle is what really separates this from the cybercrime of a decade ago, these operations increasingly look like actual SaaS companies internally, support channels, tiered pricing, even customer service for the criminals renting the tools, which tells you the market has matured well past chaotic amateur hour

None of this needs nation state resources anymore, that's really the core warning, a barrier to entry that used to require serious technical investment has collapsed to the point where renting or prompting your way into sophisticated criminal capability is realistic for far more people than it used to be

The uncomfortable conclusion is that defenders are stuck playing the same catch up game they always have, except the pace has changed, tools that used to take criminal groups months to develop and refine now iterate on a timeline measured in weeks

IronQuarry48

The SaaS analogy is uncomfortably accurate, ransomware gangs genuinely run affiliate programs with revenue splits now, it really is just a business model wearing a criminal mask
Posted from a machine that definitely needs a clean install

Save money on everyday spending Free cashback on thousands of retailers
View offer