mnemonic security podcast

INTERPOL

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 33:00

Ever wondered how INTERPOL tackles organised crime and cyber threats?

In this episode of the mnemonic Security Podcast, we’re joined by Bjørn Watne, Global Chief Information Security Officer at INTERPOL, for a conversation on how cybercrime is evolving, and what it takes to combat it.

Bjørn draws on more than 25 years of experience across industries including law enforcement, financial services and telecoms. In his role at INTERPOL, he explains how the organisation connects and supports law enforcement across 196 countries, tackling terrorism, organised crime, financial crime, and cybercrime. He also explains how and why INTERPOL distinguishes between cybercrime and cyber-enabled crime, highlighting how traditional crimes are increasingly amplified by digital tools, AI, and cloud technologies.

During Bjørn and Robby's conversation, Bjørn outlines INTERPOL’s coordination model with local jurisdictional leads, partnerships with private expertise, and the need for neutrality, including avoiding state-on-state cyber war issues. As well as discusses the “cybercrime supply chain”, attribution challenges, and where they've observed AI do the most harm.

Send us Fan Mail

Speaker

From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.

Robby Peralta

The International Criminal Police Organization. Not usually someone you want knocking on your door, but it turns out they're pretty good company. Present in 196 countries with one shared mission. To chase the worst criminals on Earth. Cartels, traffickers, ransomware gangs, the kinds you don't want finding your IP address. INTERPOL is probably the closest we'll get to our knight in shining armor. And although today's guest didn't bring his armor, he is known in some circles as the Viking. Yeah, you were 140 something episodes ago. Yeah. You look the same. Yeah, the beard goes on and off, though. I guess you caught me two times when I actually have the beard, but yeah. How is France?

Bjørn Watne

Oh, France is beautiful.

Robby Peralta

Where are you at again? Lyon?

Bjørn Watne

Yes, in Lyon. And it's uh hour and a half to the Mediterranean Sea, two hours to Geneva, two hours to Paris. It's right in the middle of everything. Beautiful.

Robby Peralta

I'm waiting for an invite to come see you, but maybe I'll get one at the end of the podcast.

Bjørn Watne

Let's see.

Robby Peralta

So uh last time we spoke in the podcast, you were the SVP and CISO of Storebrand. Then you moved to Telenor and were SVP and CISO there. Then you were partner and chairman of the advisory board with our friends over at Tagora. What are you doing now?

Bjørn Watne

Well, I'm the global chief information security officer for INTERPOL, the international criminal police organization.

Robby Peralta

Awesome. What a career. So what are you guys up to there? Guys and girls, I should say.

Bjørn Watne

So what we do basically is that we connect and empower law enforcement agencies in 196 countries and uh provide sort of a hub for information sharing and collaboration between law enforcement globally.

Robby Peralta

Cool. Terrorism, organized crime, financial crime, and what's the last one?

Bjørn Watne

Cybercrime.

Robby Peralta

There you go. Yeah. So that's what I want to talk to you about today. First thing I want to ask you now that you how long you've been there?

Bjørn Watne

I'm on my eighth month now.

Robby Peralta

Yeah. Yeah. So how has your insight and opinion about cybercrime changed?

Bjørn Watne

Well, it's more of an evolution than a revolution, I would say. As a cybersecurity professional, you deal a lot with cyber criminals or you try to prevent your organization from falling dictum of cybercriminals. But one thing that I've realized from spending time in different industries, it's that the adversary changes. When you spoke with me last time on this podcast, I was in a store brand, which is uh financial services. And the adversaries or the cyber criminals that would typically target the organization or our customers were opportunistic criminals looking for a quick win. Then I was in telecoms as well. And um as a telco, you don't hold a lot of money. So the opportunistic criminals that are looking for a quick uh return, they will not be targeting us there. But what a telco does hold is information about where people are, who they are speaking to, and what they are speaking about. And this is information that is very, very interesting for nation states, for example. Very advanced, very persistent, and very, very different than the ones we faced in financial services. And now that I need law enforcement, it changes again because as I said, we're an international organization. Every country on the world, so to say, is a member. So for nation states to uh attack us is sort of maybe not in their best interest, because they're they're a partner. And the opportunistic criminals well, there is no goal to be found here, so they should focus their energy elsewhere. But the ones that we are after, so to say, or our our function, our role is global organized crime. And it's the worst type of criminals, the organized, the big cartels, these kind of actors, and they would typically be adversaries where we would be concerned. They would try to neutralize us, they would try to hamper our operations because that would be in their best interest. That is sort of the thing that we are facing as a target, as an organization and as a target. But we typically separate cybercrime and what we call cyber-enabled crime. And with the digitalization of the world and of society, we see that traditional kinetic crimes like uh human trafficking or drug smuggling, weapons, environmental crime, they are being amplified by the use of uh cyber technology and AI and cloud and whatnot. So we need to work on both tackling the traditional criminal cartels that are now being cyber enabled, but also the cybercrime operations uh that would be in the cyber domain specifically, like uh a digital bank heist or uh something similar to that. So um actually this month, March, marks my 25th anniversary in cybersecurity, and I will say it's more of an evolution than a revolution. And now being in law enforcement, I am uh dealing with some of the criminal gangs or helping law enforcement in other regions deal with organized crimes. But I have been dealing with that organized crime or the cyber criminals as a CISO and as a cybersecurity professional for many, many years already.

Robby Peralta

25 years and no gray hair. Ah, there

Bjørn Watne

my beard is starting to

Robby Peralta

looking great. So I mean you said a bunch of cool stuff there, like cartels and organized crime. How big is that connection between cyber and scary crime that we see on movies?

Bjørn Watne

Yeah, it's quite big. Everything is more or less cyber enabled. Encrypted channels of communication, surveillance, video, audio. Digital tools are used a lot by the heavy criminal actors as as well. And if you go if you want to go into the um what we call the uh cybercrime supply chain, for example, we see that there are several layers now in uh within a successful cybercrime. First, you will have the people that actually discovers a weakness in the system, what we would call a zero-day uh vulnerability. And then there will be people, maybe they are the same, that can create a code to exploit this vulnerability. And for now, no crime has happened, right? Nobody has done anything criminal, they've discovered a vulnerability, and they've tinkered with a tool that may be able to exploit a vulnerability, but you haven't committed a crime. And then this uh information is being sold on the dark web or or through others' channels, and uh, there are other people that then will implement uh the exploitation, uh distribute the code, maybe get personal identifiable information, credit card information, passwords, accounts. There is the crime, but again, the crime maybe is not that big. And then this information again gets sold to someone else. And that someone else could be a criminal cartel, for example, where they will use the PII to get huge loans, to to um build accounts, to create uh more expensive fraud cases, uh, etc. It can build up. And then you have another one where where the money is actually then coming in, and the same cartels will uh recruit money mules to get the money laundered. We see there are several jobber advertisements of how you can work from home to earn a little bit extra money, and behind would be uh organized crime and cartels that are pulling all the strings, and they include all these elements in the criminal supply chain that per themselves does not run a huge risk because the crime is that they are committing is small or non-existent. But the people pulling the threads, they're the ones that would really be the big fish. But they're hard to catch because these different parts of the criminal supply chain are um so separated. So stitching it all together and actually catching the big fish, that is a big piece of of the job. Um it's hard to see from the surface, but there are definitely some big actors uh in the back there.

Robby Peralta

We've used the word cartel, but this kind of reminds me of like mafia movies.

Bjørn Watne

Yeah, that uh that's another expression you can use, most certainly. And um we very often publish uh results from operations that we have had together with law enforcement in different regions. And uh we recently did a few stunts in Africa. Again, this is not endemic to a certain uh continent, but uh this time we did uh we did a few uh operations in Africa. And what we would uh be able to do is to arrest criminals in the hundreds across several countries connected to the same type of criminal activity, but they were doing different parts. So mafia cartels for sure this thing is a lot more organized than uh than what meets the eye.

Robby Peralta

When I thought of the police, I thought it would be a yeah, the Norwegian police, the Danish police, or usually the Dutch police always comes to mind when it comes to this, but it's actually Interpol. How does that collaboration work?

Bjørn Watne

Yeah, that's interesting because as an international organization, we enjoy certain immunities, certain privileges, but we do not have jurisdiction in these different areas. So there will always be the local law enforcement in the places where we operate that will have the jurisdiction and they will typically have the lead. Interpol will be support, and Interpol will be coordination, and sometimes Interpol will lend expertise. But it will always be the uh local law enforcement in the specific state of operation that will have the lead. And that will always be the case on global operations, where we work with some countries in South America, some countries in Eastern Europe, some countries in Southeast Asia, but they are connected, they work together, the organized crime. But it will be the local law enforcement in the different regions that will have lead in that region. And in the bull will be sort of coordinating, assisting, providing expertise, information in the back as part of the team.

Robby Peralta

So back to my mafia reference, you guys usually are the uh the guys with that whiteboard and putting the pictures of the criminals on the wall and connecting the dots and and then the local the locals are kicking down doors. And I guess the larger countries, they probably have I want to say the word attache that work together with you and coordinate.

Bjørn Watne

Yeah, definitely. And there are also regional bodies as well. EUROPOL, that is probably well known for you. I I used to be on the advisory board uh to EUROPOL when I was in um in telco. So they have different advisory groups. They have uh financial services, internet security companies where mnemonic actually sits. And they also have uh communication providers where where I sat as a representative of Telenor. So in EUROPOL, uh, they have different jurisdictions in Europe. Then you have ASEANAPOL in the Asia region, AFRIPOL is in Africa. So there are we work with those, they have different mandates and different jurisdictions, and then we have ours. So it's a lot of layers and and different functions, uh, for sure.

Robby Peralta

Yeah. Wow. How many investigations do you like conduct a year if you have even a number on that when it comes to cyber?

Bjørn Watne

Yeah, no, that would be a question better better put to our um head of the cybersecurity directorate. So we are not a very big organization and we work predominantly on assisting law enforcement agencies and empowering them, but we also need to uh to run our own operation, right? We are a hundred percent independent. We uh are forced in our uh constitution to be completely political, religious, racial, independent from everything. Uh, meaning that the data that we are custodians of on behalf of our member countries, we cannot put them in Amazon Cloud or Alibaba Cloud or because either way, if you put it in one national company's cloud, another nation will probably have objections. So we have to host it ourselves. So this is very interesting because when I started working in this domain, everybody had uh IT in the basement. Uh then we went to outsourcing, then we went to offshoring, then we went to cloud. And now 25 years later, I'm actually back in a company where we have everything on-prem in our own data centers that we run and operate ourselves. And that is my role in Interpol as the uh chief information security officer. I need to make sure that all the risks towards the integrity, availability, and confidentiality of the information that we hold on behalf of the 200 member countries are under control or within the risk appetite. So uh, me and my team, we will typically work on securing Interpol, the data, and the communication channels, while we have other directorates that work on investigation support, uh training of law enforcement, et cetera. So I do not have the number for how many investigations we are involved in uh on that part, but um there are many. That's uh that's uh what I can tell you.

Robby Peralta

You were a pen tester before though, right? So going back to the on-prem days.

Bjørn Watne

No, I no, I I was never a pen tester. I I I started my career as a security analyst. It was it was later uh we had a fight with mnemonic at the time on who was the first to provide a 24-7 SOC in Norway. And uh yeah, I would still say it was us, but uh but um so I was reading the matrix and trying to find um every bad thing and every incident and investigate it. So that's where I started.

Robby Peralta

The good old days. I was just thinking how lucky you are to be a CISO in a company that actually understands cybersecurity. Like there's no other organization in the world that understands cybersecurity than Interpol, I would almost say.

Bjørn Watne

Yeah, well, that there isn't, there isn't. Um like you mentioned, we we deal with a lot of crime, types of crime. Environmental crime, for example, deforestation, uh illegal mining in South America, etc. Uh cybercrime is one domain. But um, yeah, most of uh most of the people that are seconded or working for Interpol on behalf of the country where they're from, they would be police officers. So I would argue that if you if you want to find like um the top cyber uh security expert environment to work in, it would be a company like like yours. Well, thank you, Bjørn.

Robby Peralta

I wasn't thinking like that, but uh that make that does also make sense. So from your vantage point, uh ransomware groups, these scam centers, do you have a team that's tracking all them?

Bjørn Watne

Uh we are tracking them, but we are also working with uh public-private partnerships uh on expert companies uh whose job is solely to be tracking them. We will provide investigation support, training to law enforcement. Um we have criminal records, we have stolen vehicles, we have stolen passports, we have uh drugs, we have uh all this information, uh all these databases on behalf of all the countries, and we can cross-reference and we can find people, we can find stolen goods, we can track the individuals, etc. But uh when it comes to expertise on different criminal groups, different tracked actors, etc., we will also definitely work with private and state uh partnerships uh that may have even more of expertise in all the different areas. So you can see us as a bit of a hub or a coordination, like a dispatch where all the information flows through.

Robby Peralta

There must be some drama since you're a member with you know every country in the world. You've heard before, we both heard before that like you know, ransomware groups get away with stuff because they're in Russia, or certain criminals get away with it because they're in this country. How is dealing with that? If you can comment.

Bjørn Watne

Yeah, it's it's an interesting question. And uh yeah, it requires a bit of finesse to answer because as I mentioned before, we're apolitical and we are uh our mission is very clear. We work on organized crime together with all the member countries. But one thing I can tell you is that no government enjoys criminal activity being done in their country. So so we see that when we are going after the organized criminal cartels, the mafias, there is a lot of collaboration between the law enforcement agencies because everybody is interested in stopping it because it erodes the economy, it provides insecurity, uncertainty. So that usually isn't a problem. I'm also being asked uh from time to time, yeah, but what about Russia is using uh cyber attacks against Ukraine or the US is using cyber attacks against Iran? And I said, well, that is not a cybercrime, that is war between two states, and that is none of my business. So I don't, well, to say I don't care it's wrong because I do care. I would like there to be no wars, but in my job and for our organization, that is this is not what we're dealing with. And if two countries are in conflict and the conflict is not in the just in the Land Sea air, but also in the cyber domain, that is not something that we will investigate or involve ourselves in at all, because that's a matter of the state, and it's it's a war between countries and not not organized crime.

Robby Peralta

It's gonna be interesting now moving forward because those lines are kind of blending, wouldn't you say?

Bjørn Watne

In certain regimes, certain states, cyber capacities, cyber warfare is a big part of the arsenal that they uh operate in. We see hybrid warfare is becoming more and more common. But again, it's it's important to make the distinction between what is espionage activities or uh things that would be managed by different agencies and different uh investigative bodies. But you are right, it's a very difficult terrain to operate in. There is a certain amount of uh fog of war or or blurred lines or grey areas, but uh I think it's important that we we um as an Interpol employee have a focus on on our mission and our duty and what it is that we do. So even if I as a private person could uh disagree uh with how a certain country is acting towards another one. If I uh let that feeling or that opinion come in the way of what we are actually doing, then I will uh sacrifice a quick gain for a much bigger one. So uh so it's important that uh we need to act professionally and we need to focus on what is our mandate and we need to be neutral because uh what we are trying to stop is uh child abuse, it's human trafficking, is international terrorism, is drug smuggling, is all these uh uh global plagues. And uh for us to be able to effectively do that, we have to be independent and we have to leave our personal opinions or political opinions at the door when we come to work. So it's uh it requires a high standard from the people working there, and it integrity, I would say, is maybe the most important assets uh that you can have uh working for an organization like Interpol.

Robby Peralta

That's a good answer. Should be a politician, beyond. I just also thought like cyber is probably the domain that is the most blurred of lines, like those other topics that you just discussed, those those are more easy. Like everybody's against child exploitation and drugs. And then you have cyber, which is probably the one that you have to tread the lightest on.

Bjørn Watne

Uh well, again, we're you're back to like political questions with influence. Operations before elections or things like this, political process manipulation, etc. But again, we're back to this would not be Interpol, it would be local agencies in the different countries where these operations are taking place that deals with specifically these kind of things. And I mean, even if you look to Norway, you have uh Kripos, they have their mandate. Then you have uh NSM, they have a different one. And uh while they may share information from time to time, they do not step on each other's toes or work on the same uh domains, right? Right.

Robby Peralta

Uh at one point in the last 10 years that I've been in cyber, they said now the cybercrime industry is larger than the drug industry. How do you like you know, when you have drugs, cybercrime, and I guess scam center scam centers are a part of cybercrime. What is like the biggest since you sit in a house that has all those?

Bjørn Watne

Yeah, no, I I've heard that line being said for many years that cybercrime is now bigger than than drugs. Uh it is not.

Robby Peralta

Okay.

Bjørn Watne

That's that that that's what I would say. But I guess it it depends a little bit on how you will count. Because if it's statistics, you can always twist it to to sort of reflect what you want it to reflect. But if you travel to parts of the world outside of the Western ones, cybercrime isn't really that big. The the traditional kinetic crimes will be much more apparent than the cybercrime. Yes, you have these big uh visible, like the the central bank of Bangladesh was rubbed of millions, and uh and you have these big ransomware groups. But but again, it it uh Norwegian Hydro, for example, they were ransomed. There wasn't much money changing hands there, but they went at a great loss, they lost a lot of money. The same with the uh shipping company Mersk, several hundred thousand of dollars, but it wasn't so much money changing hands, it wasn't people getting paid, it was just people losing money because they they were a victim of a cyber attack. So so cybercrime, stealing money, if we're talking about money, not bigger than drugs. Yeah, and like with telco, the crime that we we saw, advanced persistent threat, people after information, who is speaking with whom and where are they going? This is also not money, right? But uh drugs, 100% money.

Robby Peralta

Yep.

Bjørn Watne

100% money. So also what what is cybercrime? Where do you draw the line? If if if I use the cyber domain to do my crime, is that a cybercrime or is it a cyber enabled crime?

Robby Peralta

And so Yeah, I know that's a good point. There's a lot more money lost from cybercrime than there actually is money changing hands.

Bjørn Watne

Yeah. Yeah. Interesting. That's at least how I see it now.

Robby Peralta

Uh hack back. What are your thoughts around that?

Bjørn Watne

If someone robs your house, will you want to put this person in jail or do you want to go and rob his house? Yeah.

Robby Peralta

I see your point.

Bjørn Watne

I think it's better to put him in jail.

Robby Peralta

The older I get, the more I realize and respect why there's a constitution, there's rules. You have to abide by these rules because if you don't, somebody in power one day is going to change the rules or amend the rules in their paper, and then look where we end up.

Bjørn Watne

Yeah, we see a little bit of that happening these days, don't we?

Robby Peralta

Yeah, we do. Not that we're gonna talk about that right now, but off the podcast, maybe. Yeah. Attribution. How has attribution sort of matured in your mind since stepping into your role? Yeah.

Bjørn Watne

That is a thing that is still a bit of a problem because when we're talking about hybrid warfare, it's very easy to say you shot a rocket at us because we saw the rocket and it came from you. It's very hard to deny that when you when you physically have the rocket coming. But when there is a cyber attack and you're good at hiding your track, so you use multiple jump points and and whatnot, and the effect that you cannot with 100% certainty say that it was you, it gives you that plausible deniability that everybody likes to have. And as you said uh before, that it's still difficult to, you can't really like touch the cybercrime or or or see it uh many times. It makes it hard to make the attribution. But it's at the same time, I would say that when a national agency comes out with a name that is usually very well funded. It's it's usually not, but but it's getting the like hard physical, visible evidence we seldom see and it's seldom given. But um but when we work with with cybercrime and and and criminal gangs, we find them because they um it is typically easy to follow the money, for example, because they would at some point want to collect on the money. So even if it's difficult to see where the attack is coming from, or like I mentioned, the cybercrime uh supply chain where all the different actors, but if you follow the money, then at one point you will in most uh most cases be able to uh to find out who's pulling the strings.

Robby Peralta

You must have really fun like work parties where you have people talking about your you know, your financial follow-the-money guys that you probably have. That must be so interesting to uh listen to what's going on. Um AI. Yeah. Uh being used by criminals today. What is your what have you found interesting around the use of AI these days?

Bjørn Watne

Yeah, the biggest problem that we've seen with AI being introduced is around fraud. The AI will make sure that you're being approached in a way that's familiar to you with the information that's uh uniquely tailored to you. These days an email can come to you in perfect Norwegian. And also we see other channels, not just emails, but uh voice video calls, even. We also see the release of um AI pen testers, for example. Yeah uh not just a vulnerability scanner, but an AI pen tester. And uh I think that is just the tip of the iceberg because this it will not be difficult to improve this AI pen tester into connecting it with business context or or uh fraud scenarios or whatever, so you can have like a fully automated weapon. Um so I think up until now it's been the the fraud and and going for for private people and users that's be the been the big problem. But uh but going forward, uh I don't know if uh Skynet is around the corner, but it um I'm starting to become a believer. So uh yeah.

Robby Peralta

There's this guy, his name is Stök, um Swedish pen tester. Yeah, uh really interesting guy, fun to follow. And he said, Yeah, I remember when I told you guys that AI wasn't gonna take your pen testing job. I was wrong. Yeah, there you go. So uh yeah.

Bjørn Watne

Yeah, it is a bit alarming, but then again, we have we have AI on the on the positive side as well. You you mentioned uh briefly that uh the detective that puts up all the different um vehicles and people's uh uh faces and then connect them with the rope. We have tools now to to do this uh digitally and using AI. And it's uh it's pretty cool, yeah.

Robby Peralta

Uh this is out of place in the conversation, but you know, as CISO of Interpol, is there anything besides the fact that you're securing your on-premise environment, which is uh something that most people have to do anymore? Is there anything unique about being the CISO of Interpol being who Interpol is?

Bjørn Watne

Yes, uh definitely. Uh in a world that is becoming so polarized and so filled with conflicts, I would say it's uh very unique to be in this position where everybody are still friends, we still work together, uh, we still have a common enemy that would be uh the organized crime and terrorism. And you get to uh to learn a lot. That's that's the maybe the biggest thing for me because I meet so many people in so many uh parts of the world that I would never have the opportunity to do if I was working for a company that I've done most of my career. So I would say I it is a privilege to uh to be here. And we we're four Norwegians in Interpol. So it's um quite unique to be an international organization doing uh doing what I do.

Robby Peralta

Uh you have an awesome job, Bjørn. It's so cool to be talked to the CISO of INTERPOL. But is there any do you have any closing thoughts or anything that you're gonna be using your time on moving forward? Anything you want to share to listeners?

Bjørn Watne

I would say that it's still the basics that matter. And for people like you and me in our daily lives, it's very small habits and very small things that would determine whether you're a target or or not. So I I would encourage everyone to try and become what I would say uh is a hard target to make it a little bit more difficult to hit you than the person next to you. Because most of the uh criminals that will target you as a private person, they will be looking for the easiest way. And if you just a centimeter more difficult than the person beside you, they will go for the person beside you. So don't be too afraid of everything. Just make sure that you are making yourself a bit harder target than your neighbor, and you will do fine. That's uh that's what I would say.

Robby Peralta

Do you think that will change in our new reality where yeah, I don't know, the scale is so different. Is that actually still the same from from now on?

Bjørn Watne

No, yeah, that will be the same because humans will be humans. And no matter what happens with the world, it will be humans that make or break security. It was like this before the industrial revolution, it was like this before the IT revolution, it will still be like like that.

Robby Peralta

Mr. Watne, thank you so much for joining us here today and keep up the great work at INTERPOL. Take care.

Bjørn Watne

Thank you, Robby. Have a good day.

Robby Peralta

Robby Peralta

Thank you. Well, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us the mail to podcastnemnemonic.no. Thank you for listening, and we'll see you next time.