[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fw_cqqDoo2okh2StI-14y2I4r0M_kJ8GUdFVXCXxfT8o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"6755beda-f431-4b12-a457-dd2886f0ee10","insider-threat-cybersecurity-professionals-convicted-for-aiding-ransomware-gang","16445842-f60b-40fd-858e-5c6131c52a70","Insider Threat: Cybersecurity Professionals Convicted for Aiding Ransomware Gang","Angelo Martino exploited his privileged position as a ransomware negotiator to secretly assist the BlackCat\u002FAlphv ransomware group, betraying the trust of his employer and the victims he was hired to protect. This case highlights the critical insider threat risk posed by individuals with deep knowledge of ransomware tactics, victim vulnerabilities, and negotiation processes. The fact that three cybersecurity professionals have now been convicted for similar crimes underscores that technical expertise does not inherently equate to trustworthiness. Organizations that hire external cybersecurity consultants or incident responders must treat these relationships as a supply chain risk requiring rigorous vetting and oversight.","**Immediate actions:**\n- Conduct thorough background checks, including criminal history and financial screening, on all cybersecurity contractors and incident response personnel before granting access.\n- Implement strict need-to-know access controls so that negotiators and consultants cannot access victim data or systems beyond their defined scope.\n\n**Long-term improvements:**\n- Establish a formal vendor and contractor vetting program that continuously monitors third-party cybersecurity partners for conflicts of interest or suspicious behavior.\n- Require dual authorization and supervision for all communications and financial transactions during ransomware negotiations to prevent unilateral insider actions.\n- Build contractual clauses with legal and financial liability provisions into agreements with all third-party incident responders and security consultants.\n\n**Detection measures:**\n- Deploy behavioral analytics and audit logging to monitor all actions taken by privileged contractors and incident response personnel during engagements.\n- Create a confidential reporting mechanism (whistleblower hotline) so employees and partners can safely report suspected insider collusion with threat actors.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 6: Access Control Management","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 PS-7: External Personnel Security","NIST SP 800-53 AU-6: Audit Record Review, Analysis, and Reporting","NIST CSF ID.SC-3: Supply Chain Risk Management","ISO\u002FIEC 27001 A.7.1: Pre-employment Screening","ISO\u002FIEC 27001 A.15.1: Information Security in Supplier Relationships","GDPR Article 28: Processor Obligations and Due Diligence","ITIL Service Transition: Supplier and Contract Management","published","2026-07-10T14:21:23.93727+00:00","2026-07-10T14:21:23.642+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.securityweek.com\u002Fthird-us-security-expert-sentenced-to-prison-for-helping-ransomware-gang\u002F","third-us-security-expert-sentenced-to-prison-for-helping-ransomware-gang-3b9499","Third US Security Expert Sentenced to Prison for Helping Ransomware Gang",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]