In Conversation With... Vladimir Krupnov

In Conversation With... Vladimir Krupnov

In Conversation With... Vladimir Krupnov

In Conversation with Vladimir Krupnov...  How Fintechs Can Strengthen Their Defences Through Threat Intelligence

As the fintech sector continues to redefine global finance, it’s also become a prime target for sophisticated cyber threats. Few understand this landscape better than Vladimir Krupnov, Threat Intelligence Lead at Revolut, who sits at the intersection of rapid innovation and relentless adversaries. In this conversation, Vlad shares his perspective on the evolving challenges of threat intelligence in fintech — from data overload and adversary tracking to automation and intelligence sharing — and what it takes to build a truly resilient, proactive defense program in one of the world’s fastest-growing digital banks. 

The Fintech Threat Landscape

Q: Fintech is one of the most targeted sectors in cybersecurity. From your perspective, how is the threat landscape evolving, and what makes fintechs particularly attractive to attackers?

[Vlad Response:]

Fintechs sit in a pretty uncomfortable place: real money, real people, and everything happening in real time. There’s very little friction, and attackers understand that better than anyone.

What’s changed is the level of organisation on the attacker side. A lot of what we see today isn’t experimentation — it’s repeatable, scalable operations. Campaigns get tested, refined, and then pushed hard once they work. Social engineering, brand abuse, and customer-facing scams are good examples of that shift.

Fintechs are also open by design — APIs, partners, rapid expansion into new markets. That openness is necessary for growth, but it also means the attack surface keeps moving, often faster than traditional control models were designed for.

Q: How does the pace of innovation in fintech, from new products, global expansion, and API-driven ecosystems, impact the types of threats they have to anticipate?

[Vlad Response:]

Speed changes everything. New products and new markets often introduce risks that don’t show up in architecture diagrams or threat models straight away.

A lot of threats don’t come from breaking technology, but from how products are explained, marketed, or misunderstood — especially across different regions. The same feature can be abused in very different ways depending on local behaviour and trust models.

From a threat intelligence perspective, that means thinking less about isolated vulnerabilities and more about end-to-end abuse paths — how something starts small and then gets scaled.

Building and Scaling Threat Intelligence

Q. Fintechs scale at speed and operate across multiple regions, Revolut being a prime example of this. What are the biggest challenges in building and scaling an effective threat intelligence program for such fast-moving businesses?

[Vlad Response:]

The hardest part isn’t collecting intelligence — it’s making sense of it at scale. Data is never the problem. Attention is.

As the business grows, Threat Intelligence function can easily drift into either producing too much noise or becoming a bottleneck. Neither is acceptable. You constantly have to decide what really matters now, not what’s theoretically interesting.

Another challenge is consistency. Different regions face different threats, but leadership still needs a coherent picture. That requires a shared way of reasoning about risk, even if the inputs vary.

Q. Many teams struggle to separate meaningful signals from noise. What steps can security teams take to ensure their intelligence is actionable, timely, and aligned with business risk?

[Vlad Response:]

I use a very simple test: if no decision follows, it wasn’t intelligence.

Actionable intelligence should make it obvious who needs to act and why. If it takes five follow-up meetings to translate it into something operational, it’s already too late.

Feedback loops matter a lot here. Without them, CTI teams end up optimising for volume or visibility rather than actual impact.

People, Process, and Technology

Q. Threat intelligence is often viewed as a data problem, but the human element is crucial. How do you strike the right balance between automation, AI-driven tools, and human expertise?

[Vlad Response:]

Automation should absorb the noise, not the thinking.

AI is extremely useful for filtering, enrichment, and summarisation — especially when you’re dealing with large volumes of OSINT or brand monitoring. At scale, false positives aren’t just annoying; they’re risky.

But judgement still sits with people. Understanding intent, prioritising trade-offs, and deciding when something really matters — that’s not something you want fully automated.

Q. What frameworks, processes, or cultural practices do you believe are crucial to have when embedding threat intelligence into wider security operations?

[Vlad Response:]

CTI only works if it’s part of how the organisation operates day-to-day. If it’s treated as a separate reporting function, it won’t scale.

That means tight integration with incident response, fraud, AppSec, and even product teams. Clear ownership, clear escalation paths, and shared expectations around response time make a big difference.

Culturally, CTI needs to be comfortable saying “this doesn’t matter” as often as “this does.”

Collaboration and Regulation

Q. Intelligence sharing is often key to staying ahead of adversaries. How can Fintechs better collaborate with the broader security community to stay informed and ahead of the curve?

[Vlad Response:]

One pattern we see very clearly is the level of coordination on the attacker side. Threat actors increasingly operate as a unified ecosystem — sharing infrastructure, tooling, and successful techniques across groups and regions. That coordination allows them to scale quickly and remain resilient even when individual campaigns are disrupted.

Defenders, by contrast, have to work through a more fragmented landscape. In the US, we generally see a relatively mature and pragmatic information-sharing culture, with established trust networks and clearer operational norms around collaboration. That makes it easier to exchange timely, actionable insights while staying within legal and ethical boundaries.

In the EU, the picture is very different. Strong privacy and regulatory frameworks are essential, but they also create additional friction when it comes to cross-organisation or cross-border collaboration. As a result, sharing often becomes more cautious, which can slow down collective disruption efforts even when the intent to collaborate is there.

Emerging markets add another layer of complexity. Legal frameworks, enforcement maturity, and market practices can vary significantly, and threat actors often exploit these differences to operate across jurisdictions where coordination between defenders is harder. At the same time, local teams in these regions often see patterns early, making their perspectives especially valuable if the right channels for sharing exist.

Given these constraints, collaboration doesn’t have to mean sharing sensitive details. Even responsible, high-level sharing of patterns, tactics, and emerging trends can make a meaningful difference. In practice, some of the earliest warnings come not from tools, but from peers noticing subtle shifts before they become widespread.

The goal is selective and well-judged collaboration — narrowing the coordination gap with adversaries, while remaining compliant, thoughtful, and focused on signals that genuinely support decision-making.

Q. With growing regulatory scrutiny in financial services, how do compliance requirements shape — or sometimes complicate — threat intelligence strategy?

[Vlad Response:]

Regulators increasingly expect organisations to demonstrate understanding, not just compliance. That’s a good thing.

The challenge is that real threats evolve faster than formal requirements. CTI often ends up translating messy, real-world risk into something regulators can understand without oversimplifying it.

When done well, CTI becomes a bridge between operational reality and regulatory expectations.

5. Future Outlook and Advice

Q. What emerging threat trends — like AI-powered attacks or supply chain compromises — do you think will define the next phase of cybersecurity?

[Vlad Response:]

We’ll see more attacks that deliberately blend in. AI-driven social engineering, supply-chain abuse, and trust-based attacks are already moving in that direction, and they’re becoming harder to distinguish from legitimate activity.

The real shift is that many of the most damaging attacks won’t present themselves as incidents at all. They’ll look like normal behaviour — a familiar voice, a reasonable request, a routine system interaction — until the impact is already there.

AI and synthetic media amplify this problem. Deepfakes and generated content make it increasingly difficult to separate reality from something that’s been carefully staged. That challenges many of the assumptions security teams rely on, especially around identity, intent, and authenticity.

As a result, the next phase of cybersecurity will be less about reacting to obvious failures, and more about detecting subtle deviations in behaviour, trust, and context — before those deviations can be exploited at scale.

 Q. Finally, what advice would you give to fintech security leaders looking to mature their threat intelligence programs and build resilience for the years ahead?

[Vlad Response:]

Start with the decisions you want to enable, not the tools you want to buy.

Hire people who can think in systems, not just indicators. And build CTI to influence outcomes, not to generate reports.

Maturity is when threats stop being surprises and start being managed risks.

 

In Conversation with Vladimir Krupnov...  How Fintechs Can Strengthen Their Defences Through Threat Intelligence

As the fintech sector continues to redefine global finance, it’s also become a prime target for sophisticated cyber threats. Few understand this landscape better than Vladimir Krupnov, Threat Intelligence Lead at Revolut, who sits at the intersection of rapid innovation and relentless adversaries. In this conversation, Vlad shares his perspective on the evolving challenges of threat intelligence in fintech — from data overload and adversary tracking to automation and intelligence sharing — and what it takes to build a truly resilient, proactive defense program in one of the world’s fastest-growing digital banks. 

The Fintech Threat Landscape

Q: Fintech is one of the most targeted sectors in cybersecurity. From your perspective, how is the threat landscape evolving, and what makes fintechs particularly attractive to attackers?

[Vlad Response:]

Fintechs sit in a pretty uncomfortable place: real money, real people, and everything happening in real time. There’s very little friction, and attackers understand that better than anyone.

What’s changed is the level of organisation on the attacker side. A lot of what we see today isn’t experimentation — it’s repeatable, scalable operations. Campaigns get tested, refined, and then pushed hard once they work. Social engineering, brand abuse, and customer-facing scams are good examples of that shift.

Fintechs are also open by design — APIs, partners, rapid expansion into new markets. That openness is necessary for growth, but it also means the attack surface keeps moving, often faster than traditional control models were designed for.

Q: How does the pace of innovation in fintech, from new products, global expansion, and API-driven ecosystems, impact the types of threats they have to anticipate?

[Vlad Response:]

Speed changes everything. New products and new markets often introduce risks that don’t show up in architecture diagrams or threat models straight away.

A lot of threats don’t come from breaking technology, but from how products are explained, marketed, or misunderstood — especially across different regions. The same feature can be abused in very different ways depending on local behaviour and trust models.

From a threat intelligence perspective, that means thinking less about isolated vulnerabilities and more about end-to-end abuse paths — how something starts small and then gets scaled.

Building and Scaling Threat Intelligence

Q. Fintechs scale at speed and operate across multiple regions, Revolut being a prime example of this. What are the biggest challenges in building and scaling an effective threat intelligence program for such fast-moving businesses?

[Vlad Response:]

The hardest part isn’t collecting intelligence — it’s making sense of it at scale. Data is never the problem. Attention is.

As the business grows, Threat Intelligence function can easily drift into either producing too much noise or becoming a bottleneck. Neither is acceptable. You constantly have to decide what really matters now, not what’s theoretically interesting.

Another challenge is consistency. Different regions face different threats, but leadership still needs a coherent picture. That requires a shared way of reasoning about risk, even if the inputs vary.

Q. Many teams struggle to separate meaningful signals from noise. What steps can security teams take to ensure their intelligence is actionable, timely, and aligned with business risk?

[Vlad Response:]

I use a very simple test: if no decision follows, it wasn’t intelligence.

Actionable intelligence should make it obvious who needs to act and why. If it takes five follow-up meetings to translate it into something operational, it’s already too late.

Feedback loops matter a lot here. Without them, CTI teams end up optimising for volume or visibility rather than actual impact.

People, Process, and Technology

Q. Threat intelligence is often viewed as a data problem, but the human element is crucial. How do you strike the right balance between automation, AI-driven tools, and human expertise?

[Vlad Response:]

Automation should absorb the noise, not the thinking.

AI is extremely useful for filtering, enrichment, and summarisation — especially when you’re dealing with large volumes of OSINT or brand monitoring. At scale, false positives aren’t just annoying; they’re risky.

But judgement still sits with people. Understanding intent, prioritising trade-offs, and deciding when something really matters — that’s not something you want fully automated.

Q. What frameworks, processes, or cultural practices do you believe are crucial to have when embedding threat intelligence into wider security operations?

[Vlad Response:]

CTI only works if it’s part of how the organisation operates day-to-day. If it’s treated as a separate reporting function, it won’t scale.

That means tight integration with incident response, fraud, AppSec, and even product teams. Clear ownership, clear escalation paths, and shared expectations around response time make a big difference.

Culturally, CTI needs to be comfortable saying “this doesn’t matter” as often as “this does.”

Collaboration and Regulation

Q. Intelligence sharing is often key to staying ahead of adversaries. How can Fintechs better collaborate with the broader security community to stay informed and ahead of the curve?

[Vlad Response:]

One pattern we see very clearly is the level of coordination on the attacker side. Threat actors increasingly operate as a unified ecosystem — sharing infrastructure, tooling, and successful techniques across groups and regions. That coordination allows them to scale quickly and remain resilient even when individual campaigns are disrupted.

Defenders, by contrast, have to work through a more fragmented landscape. In the US, we generally see a relatively mature and pragmatic information-sharing culture, with established trust networks and clearer operational norms around collaboration. That makes it easier to exchange timely, actionable insights while staying within legal and ethical boundaries.

In the EU, the picture is very different. Strong privacy and regulatory frameworks are essential, but they also create additional friction when it comes to cross-organisation or cross-border collaboration. As a result, sharing often becomes more cautious, which can slow down collective disruption efforts even when the intent to collaborate is there.

Emerging markets add another layer of complexity. Legal frameworks, enforcement maturity, and market practices can vary significantly, and threat actors often exploit these differences to operate across jurisdictions where coordination between defenders is harder. At the same time, local teams in these regions often see patterns early, making their perspectives especially valuable if the right channels for sharing exist.

Given these constraints, collaboration doesn’t have to mean sharing sensitive details. Even responsible, high-level sharing of patterns, tactics, and emerging trends can make a meaningful difference. In practice, some of the earliest warnings come not from tools, but from peers noticing subtle shifts before they become widespread.

The goal is selective and well-judged collaboration — narrowing the coordination gap with adversaries, while remaining compliant, thoughtful, and focused on signals that genuinely support decision-making.

Q. With growing regulatory scrutiny in financial services, how do compliance requirements shape — or sometimes complicate — threat intelligence strategy?

[Vlad Response:]

Regulators increasingly expect organisations to demonstrate understanding, not just compliance. That’s a good thing.

The challenge is that real threats evolve faster than formal requirements. CTI often ends up translating messy, real-world risk into something regulators can understand without oversimplifying it.

When done well, CTI becomes a bridge between operational reality and regulatory expectations.

5. Future Outlook and Advice

Q. What emerging threat trends — like AI-powered attacks or supply chain compromises — do you think will define the next phase of cybersecurity?

[Vlad Response:]

We’ll see more attacks that deliberately blend in. AI-driven social engineering, supply-chain abuse, and trust-based attacks are already moving in that direction, and they’re becoming harder to distinguish from legitimate activity.

The real shift is that many of the most damaging attacks won’t present themselves as incidents at all. They’ll look like normal behaviour — a familiar voice, a reasonable request, a routine system interaction — until the impact is already there.

AI and synthetic media amplify this problem. Deepfakes and generated content make it increasingly difficult to separate reality from something that’s been carefully staged. That challenges many of the assumptions security teams rely on, especially around identity, intent, and authenticity.

As a result, the next phase of cybersecurity will be less about reacting to obvious failures, and more about detecting subtle deviations in behaviour, trust, and context — before those deviations can be exploited at scale.

 Q. Finally, what advice would you give to fintech security leaders looking to mature their threat intelligence programs and build resilience for the years ahead?

[Vlad Response:]

Start with the decisions you want to enable, not the tools you want to buy.

Hire people who can think in systems, not just indicators. And build CTI to influence outcomes, not to generate reports.

Maturity is when threats stop being surprises and start being managed risks.

 

In Conversation with Vladimir Krupnov...  How Fintechs Can Strengthen Their Defences Through Threat Intelligence

As the fintech sector continues to redefine global finance, it’s also become a prime target for sophisticated cyber threats. Few understand this landscape better than Vladimir Krupnov, Threat Intelligence Lead at Revolut, who sits at the intersection of rapid innovation and relentless adversaries. In this conversation, Vlad shares his perspective on the evolving challenges of threat intelligence in fintech — from data overload and adversary tracking to automation and intelligence sharing — and what it takes to build a truly resilient, proactive defense program in one of the world’s fastest-growing digital banks. 

The Fintech Threat Landscape

Q: Fintech is one of the most targeted sectors in cybersecurity. From your perspective, how is the threat landscape evolving, and what makes fintechs particularly attractive to attackers?

[Vlad Response:]

Fintechs sit in a pretty uncomfortable place: real money, real people, and everything happening in real time. There’s very little friction, and attackers understand that better than anyone.

What’s changed is the level of organisation on the attacker side. A lot of what we see today isn’t experimentation — it’s repeatable, scalable operations. Campaigns get tested, refined, and then pushed hard once they work. Social engineering, brand abuse, and customer-facing scams are good examples of that shift.

Fintechs are also open by design — APIs, partners, rapid expansion into new markets. That openness is necessary for growth, but it also means the attack surface keeps moving, often faster than traditional control models were designed for.

Q: How does the pace of innovation in fintech, from new products, global expansion, and API-driven ecosystems, impact the types of threats they have to anticipate?

[Vlad Response:]

Speed changes everything. New products and new markets often introduce risks that don’t show up in architecture diagrams or threat models straight away.

A lot of threats don’t come from breaking technology, but from how products are explained, marketed, or misunderstood — especially across different regions. The same feature can be abused in very different ways depending on local behaviour and trust models.

From a threat intelligence perspective, that means thinking less about isolated vulnerabilities and more about end-to-end abuse paths — how something starts small and then gets scaled.

Building and Scaling Threat Intelligence

Q. Fintechs scale at speed and operate across multiple regions, Revolut being a prime example of this. What are the biggest challenges in building and scaling an effective threat intelligence program for such fast-moving businesses?

[Vlad Response:]

The hardest part isn’t collecting intelligence — it’s making sense of it at scale. Data is never the problem. Attention is.

As the business grows, Threat Intelligence function can easily drift into either producing too much noise or becoming a bottleneck. Neither is acceptable. You constantly have to decide what really matters now, not what’s theoretically interesting.

Another challenge is consistency. Different regions face different threats, but leadership still needs a coherent picture. That requires a shared way of reasoning about risk, even if the inputs vary.

Q. Many teams struggle to separate meaningful signals from noise. What steps can security teams take to ensure their intelligence is actionable, timely, and aligned with business risk?

[Vlad Response:]

I use a very simple test: if no decision follows, it wasn’t intelligence.

Actionable intelligence should make it obvious who needs to act and why. If it takes five follow-up meetings to translate it into something operational, it’s already too late.

Feedback loops matter a lot here. Without them, CTI teams end up optimising for volume or visibility rather than actual impact.

People, Process, and Technology

Q. Threat intelligence is often viewed as a data problem, but the human element is crucial. How do you strike the right balance between automation, AI-driven tools, and human expertise?

[Vlad Response:]

Automation should absorb the noise, not the thinking.

AI is extremely useful for filtering, enrichment, and summarisation — especially when you’re dealing with large volumes of OSINT or brand monitoring. At scale, false positives aren’t just annoying; they’re risky.

But judgement still sits with people. Understanding intent, prioritising trade-offs, and deciding when something really matters — that’s not something you want fully automated.

Q. What frameworks, processes, or cultural practices do you believe are crucial to have when embedding threat intelligence into wider security operations?

[Vlad Response:]

CTI only works if it’s part of how the organisation operates day-to-day. If it’s treated as a separate reporting function, it won’t scale.

That means tight integration with incident response, fraud, AppSec, and even product teams. Clear ownership, clear escalation paths, and shared expectations around response time make a big difference.

Culturally, CTI needs to be comfortable saying “this doesn’t matter” as often as “this does.”

Collaboration and Regulation

Q. Intelligence sharing is often key to staying ahead of adversaries. How can Fintechs better collaborate with the broader security community to stay informed and ahead of the curve?

[Vlad Response:]

One pattern we see very clearly is the level of coordination on the attacker side. Threat actors increasingly operate as a unified ecosystem — sharing infrastructure, tooling, and successful techniques across groups and regions. That coordination allows them to scale quickly and remain resilient even when individual campaigns are disrupted.

Defenders, by contrast, have to work through a more fragmented landscape. In the US, we generally see a relatively mature and pragmatic information-sharing culture, with established trust networks and clearer operational norms around collaboration. That makes it easier to exchange timely, actionable insights while staying within legal and ethical boundaries.

In the EU, the picture is very different. Strong privacy and regulatory frameworks are essential, but they also create additional friction when it comes to cross-organisation or cross-border collaboration. As a result, sharing often becomes more cautious, which can slow down collective disruption efforts even when the intent to collaborate is there.

Emerging markets add another layer of complexity. Legal frameworks, enforcement maturity, and market practices can vary significantly, and threat actors often exploit these differences to operate across jurisdictions where coordination between defenders is harder. At the same time, local teams in these regions often see patterns early, making their perspectives especially valuable if the right channels for sharing exist.

Given these constraints, collaboration doesn’t have to mean sharing sensitive details. Even responsible, high-level sharing of patterns, tactics, and emerging trends can make a meaningful difference. In practice, some of the earliest warnings come not from tools, but from peers noticing subtle shifts before they become widespread.

The goal is selective and well-judged collaboration — narrowing the coordination gap with adversaries, while remaining compliant, thoughtful, and focused on signals that genuinely support decision-making.

Q. With growing regulatory scrutiny in financial services, how do compliance requirements shape — or sometimes complicate — threat intelligence strategy?

[Vlad Response:]

Regulators increasingly expect organisations to demonstrate understanding, not just compliance. That’s a good thing.

The challenge is that real threats evolve faster than formal requirements. CTI often ends up translating messy, real-world risk into something regulators can understand without oversimplifying it.

When done well, CTI becomes a bridge between operational reality and regulatory expectations.

5. Future Outlook and Advice

Q. What emerging threat trends — like AI-powered attacks or supply chain compromises — do you think will define the next phase of cybersecurity?

[Vlad Response:]

We’ll see more attacks that deliberately blend in. AI-driven social engineering, supply-chain abuse, and trust-based attacks are already moving in that direction, and they’re becoming harder to distinguish from legitimate activity.

The real shift is that many of the most damaging attacks won’t present themselves as incidents at all. They’ll look like normal behaviour — a familiar voice, a reasonable request, a routine system interaction — until the impact is already there.

AI and synthetic media amplify this problem. Deepfakes and generated content make it increasingly difficult to separate reality from something that’s been carefully staged. That challenges many of the assumptions security teams rely on, especially around identity, intent, and authenticity.

As a result, the next phase of cybersecurity will be less about reacting to obvious failures, and more about detecting subtle deviations in behaviour, trust, and context — before those deviations can be exploited at scale.

 Q. Finally, what advice would you give to fintech security leaders looking to mature their threat intelligence programs and build resilience for the years ahead?

[Vlad Response:]

Start with the decisions you want to enable, not the tools you want to buy.

Hire people who can think in systems, not just indicators. And build CTI to influence outcomes, not to generate reports.

Maturity is when threats stop being surprises and start being managed risks.