Dmitry Volkov, CEO of Group-IB, told Sindhu V Kashyap, Editor, GEC Media, at GISEC why banks still split fraud and cyber security into separate teams, why his company keeps naming threat groups, and why 2 decades of faster response have left defenders exactly where they started.
Dmitry Volkov, CEO of Group-IB, founded the company more than 20 years ago as a cyber security services business handling incident response, digital forensics and cybercrime investigations. His own early work involved identifying the real people behind attacks, and speaking to GEC Media at GISEC, he said that investigative instinct remained “part of my DNA” long after his job titles had changed.
Those titles changed several times. Volkov moved from investigations to head of threat intelligence, where he built the company’s programme from scratch and automated much of the collection and analysis of data gathered from criminal communities. He went on to become chief technology officer and eventually chief executive, and when asked which stage had been hardest, he named the last. “To be CEO of the company is the hardest job,” he said, explaining that a technical mindset had to learn how to run a business across regions that differ sharply in culture and ecosystem.
Group-IB’s regional model grew out of a lesson learned when it operated in one country
In the company’s early years, Volkov saw that large, long-established vendors had no visibility of the attackers operating in his region and little understanding of how they worked, which left customers with an average solution when they needed something more advanced. His answer was to build smaller replicas of Group-IB in each region, each carrying the full technical capability of the wider company in incident response, digital forensics, cybercrime investigation and anti-fraud analysis.
Those teams mix specialists brought in from other regions with local hires, and Volkov said local people also need to manage them because only they fully understand the culture. Local staff bring a different kind of commitment, he added, because they are protecting “their families, their friends, their companies, their country”.
The same focus on people explains why Group-IB continues to name threat groups, a practice many vendors consider commercially risky. Volkov argued that stopping an attack means stopping its root cause, and that a person sits behind every tool, AI included. “If you don’t stop these people now, they are going to grow,” he said, describing criminals who learn and adapt quickly, reinvest their earnings in their own ecosystems and become more efficient with every success.
AI has already reshaped fraud while most intrusions still run on older, cheaper methods
Volkov drew a clear line between traditional cyber security incidents and fraud. Attackers who infiltrate organisations and exfiltrate data use AI only in narrow cases and still rely mostly on established techniques, because those remain cheaper and continue to work. “As soon as it becomes less effective, they will start to adopt new technology,” he said.
Scams, social engineering and deepfakes have moved much further. Fraudsters have adopted AI at every stage of those operations, and Volkov said the result is activity at massive scale that is extremely fast and difficult to detect, a new challenge now confronting anti-fraud teams.
Banks split cyber and fraud by historical accident, leaving each team with half the picture
That shift exposes a structural weakness inside most organisations that run both functions. Cyber security and anti-fraud teams look at the same attack from 2 different angles, Volkov said, and each sees only part of it. He described the separation as “just a historical approach”, in which the CISO took charge of cyber security while anti-money laundering regulation created a separate function staffed by people from a different background, with both roles eventually growing too large to merge.
Volkov stopped short of calling for both functions to sit under one person and argued instead for collaboration through a common, real-time workflow. “When you talk about fraud, it’s always real time,” he said, noting that fraud teams have little time to research or take a decision. Group-IB describes this as a cyber fraud fusion operating model, which Volkov said is already emerging in mature organisations, while those at entry level still need to fix basic controls first. Building it requires dedicated technology, consultancy support and a programme developed step by step inside each organisation.
Faster response has kept defenders one step behind for 3 decades
Asked what the industry still gets fundamentally wrong, Volkov said the approach has barely changed in the more than 30 years he has watched it. Security teams wait for a first signal, then analyse, investigate and respond, which means action begins only after something has already happened. The industry spent 20 years improving response speed, and AI now accelerates attackers as well. “You need AI to move faster. But what does it mean for you? That you are going to lose faster,” he said.
His alternative is prediction-first cyber security, which uses the signals that already exist to anticipate a threat actor’s next move and take pre-emptive action before that intent succeeds. Detection, in this model, confirms whether the prediction was right or reveals what it missed. Volkov acknowledged that the shift will be a long journey, and he paired it with a second priority for the year ahead, collective defence, bringing the conversation back to the work he began with 2 decades ago, identifying the people behind attacks and stopping them before their operations can grow.


