One Adversary: The 90-Day Fusion Playbook
Every transformation eventually meets the same question at the risk committee: 2026-9-4 07:4:18 Author: www.group-ib.com(查看原文) 阅读量:3 收藏

Every transformation eventually meets the same question at the risk committee: what will be different?

For Cyber-Fraud Fusion, the first instinct is to answer with a reorganisation (merge the two teams under one head, reporting line and a dashboard) or procurement (buy-a-tool, run an RFP and install a platform that promises fusion). Both answers fail.

A reorganisation triggers a turf negotiation nobody has time for; a platform purchase demands a business case nobody can yet evidence. The organisations getting this right treat fusion as a capability with stages, and they start with the moves that cost nothing.

It helps to be concrete about what the starting point really looks like, because it is rarely dramatic. We recently documented one in a working session with the cybercrime function of a Tier-1 banking group. 

That team responsible for takedowns and threat intelligence had never worked with an anti-fraud platform. It sits alongside a Fraud and Financial Crime organisation of 400–450 people. Both report to the same Chief Information Risk Officer. They run entirely separate tools and workflows. A phishing incident detected outside the Digital Risk Protection stack is handed over by email or ticket; every site is reviewed manually; takedowns are prepared by hand; the team’s own detection script runs in parallel to Digital Risk Protection with no integration; and requests from law enforcement arrive almost daily to be answered manually, because malware cannot be mapped to infected devices, identities, and transactions.

None of this is negligence. It is what inherited architecture looks like, and every element of it is measurable, which is where the playbook begins.

The same phishing incident through a siloed hand-off versus a fused workflow. The fused path is measured in minutes and closes the loop.

The same phishing incident through a siloed hand-off versus a fused workflow. The fused path is measured in minutes and closes the loop.

Seven metrics belong on a fusion programme’s shared scorecard, and each maps to a failure the baseline above makes visible. Signal-to-action time: hours from a threat-intelligence finding to a fraud-engine action is the master metric; in a siloed institution it is bounded below by the hand-off itself.

Phishing takedown cycle time falls from days to minutes when one detection layer feeds both teams and takedowns trigger automatically.

Attribution and reporting time collapses from a daily manual burden to a query when the chain malware → devices → identities → transactions are mapped continuously.

Analyst hours per campaign compress up to ten-fold as automation absorbs the repeatable work; the documented deepfake case ran to 200-plus hours and a 25/39-day detect-and-contain cycle before fusion.

Fraud predicted pre-transaction rises as intelligence primes the engine before the session.

The false-positive rate falls on both sides as cyber and fraud signals corroborate each other.

Duplicated spend surfaces immediately: a joint tool inventory almost always finds two teams paying twice for overlapping detection; one of the first fundable numbers the programme produces.

Two practices make the scorecard persuasive rather than decorative: measure with the institution’s own numbers, through a configurable ROI model the bank fills with its own volumes and loss rates; and use the governance lever that already exists, where both functions report to one executive, the scorecard has a natural owner, and stage one of fusion needs no reorganisation at all. Only a decision.

The stages themselves deserve honest names. The matrix below defines four, across the four dimensions that matter; a CISO and a Head of Fraud should be able to read it together and agree on their current column.

Stage 0 · Siloed Stage 1 · Coordinated Stage 2 · Integrated Stage 3 · Fused
People Separate teams and reporting lines; meet at the quarterly risk committee Named virtual working group on a fixed cadence — no new headcount Cross-functional analysts co-own typologies; roles partly seconded Dedicated fusion function with a single owner and standing bench
Process Hand-offs by email and ticket; intelligence reaches fraud late or never One shared incident ritual; one typology reviewed end-to-end together Documented closed loop; signals routed automatically between functions Pre-, in-, and post-attack run as one continuous, instrumented loop
Tooling Duplicated point tools; no common data view Tool inventory done; duplicate spend identified; shared watch-lists started Shared enrichment and a common object view; consolidation underway One data model across Threat Intelligence, Digital Risk Protection, and fraud; cross-institution network layer live
Metrics Each team reports its own numbers; no shared definition of a missed signal First joint metric agreed — e.g. signal-to-action time on one typology Shared scorecard; fusion outcomes reviewed at the risk committee Procurement and risk decisions made against the fusion architecture

A quick diagnostic locates most institutions in seconds.

Stage 0: A new account-takeover scheme appears, and the fraud team builds a rule the threat-intelligence team could have primed weeks earlier.

Stage 1: Both teams sit in the same recurring review and describe that scheme in the same words, but still work from separate tools.

Stage 2: A credential the threat-intelligence team logged is automatically available to the fraud engine, and a blocked session feeds back upstream without anyone forwarding it.

The critical boundary is the first one, and crossing it is a ninety-day exercise. Move one: adopt a shared vocabulary: MITRE’s Fight Fraud Framework (F3), launched in April 2026 with Group-IB among the initial contributors, freely available as the standing language of a joint working group with one named owner drawn from the SOC, fraud operations, threat intelligence, and AML. 

Move two: walk one incident through the chain end-to-end together, marking every point where intelligence existed but never reached the team that needed it; each gap is the integration backlog, and the walk itself teaches both teams to see the same adversary.

Move three: agree on one shared metric: signal-to-action time, measured on one fraud type, and bring the result to the risk committee as a recommendation, not a request.

Ninety days of this proves the model on one scheme. It does not finish the transition, but it makes the case to finish it, in the institution’s own numbers and it changes the procurement posture for everything after: from buying tools against the silo to buying against the architecture.

A closing word on where this leads. The criminal economy solved its coordination problem years ago: specialised groups, one chain, infrastructure to cash-out. The institutions that solve theirs with one workflow inside the bank, one privacy-preserving network across banks, intelligence at the core  will not merely detect more fraud, they will see it forming, price it out of the attacker’s business model, and increasingly make it not worth attempting.

One adversary. One workflow. That is the whole idea.

Do this week. Book the first joint review before the quarter ends. The agenda writes itself: the chain drawn against the org chart, one incident walked end-to-end, one metric agreed. No budget request, no reorganisation; one meeting, one named owner, and a baseline number to improve.

This concludes One Adversary, a five-part series on Cyber-Fraud Fusion. Parts 1–4 cover the blind spot, the clock, the network, and the evidence, each stands alone.


文章来源: https://www.group-ib.com/blog/90-day-fusion-playbook/
如有侵权请联系:admin#unsafe.sh