Security1 publisher3 min readPublished
Talos tells the story instead of the matrix, and BEC's new economics fall out
Cisco Talos revives a 1990s criminology method to describe intrusions as narratives, then uses a business email compromise to show which steps AI makes cheap and where defenders can push back.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Crime script analysis is a narrative-driven technique that can be used alongside, or as an alternative to, tactics, techniques and procedures, creating human-readable stories that describe attacks in a way non-technical audiences can understand.
- Talos argues that by analyzing the attacker's workflow, defenders can identify how AI can be used to industrialize attacks, and uses a business email compromise example to demonstrate how attackers may scale the attack to target previously unprofitable victims.
- Deconstructing an attack into discrete steps allows defenders to pinpoint intervention points where defenses can be deployed, or where strategic disruption can break the script and thwart the threat actor's operation.
- Lockheed Martin's Cyber Kill Chain was one of the earliest models to describe the steps required to conduct a cyber attack, but its seven-step linear sequence is too rigid to apply to many attacks.
- The Attack Flow model of the MITRE ATT&CK framework allows TTPs to be chained together, including branches and loops, producing comprehensive graphs that can be daunting to a non-technical audience.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Cisco Talos has made the case for describing intrusions as crime scripts, a narrative technique developed in the mid-1990s as a criminology tool, used alongside or instead of tactics, techniques and procedures [1] [7]. The argument is not about presentation. Writing an attacker's workflow out as a sequence of actions, decisions and situational requirements is what exposes which steps artificial intelligence lets an attacker industrialize, and therefore which defensive interventions actually change the attacker's arithmetic [2] [3].
Talos positions the technique against the existing models rather than over them. Lockheed Martin's Cyber Kill Chain, one of the earliest attempts to describe the steps in an attack, has a seven-step linear sequence that is too rigid for many real intrusions [4]. The Attack Flow model of MITRE ATT&CK fixes the rigidity by chaining TTPs with branches and loops, producing comprehensive graphs that Talos concedes can be daunting to a non-technical audience [5]. With threats evolving and budgets shrinking, Talos argues defenders need ways to communicate threats to a wider audience [6]. Its own framing: TTPs are the building blocks, Attack Flow is the structural engineering blueprint, and crime script analysis is the architect's artistic impression of the finished building [8].
The case study is business email compromise: someone with financial authority receives a message purporting to come from a superior in the same organization, asking for an urgent payment, and if the victim is fooled the money is released and laundered quickly to disguise its origin before the scam surfaces [9]. The Talos author writes that in April he covered such an attack on a small community sports club of which he is a member [10]. The requested sum was not large, so the stated reason was plausible; what failed was the tone of the email, which raised the treasurer's suspicions and exposed the attempted fraud [11].
That small scale is the whole point. The research that BEC requires, identifying the target victim, the person to spoof and the nature of the lure, has historically limited scalability, because doing it by hand takes time and has meant the fraud is typically aimed at larger businesses [12]. Talos says AI automates that preparative work [13]. In its script, steps 1 to 4 are the manual, time-consuming part, and automating them shifts execution from higher-value fraud against a few targets to lower-value fraud against many [14]. Step 5, the personalization, can also be generated: urgent payment requests relevant to the target organization that may look credible to the recipient [15]. If analyst time was the binding constraint on target selection, removing it lowers the minimum victim size that pays [18].
The intervention argument is where the published text available to us runs out. It begins to say steps 1 to 4 can be disrupted by seeding AI with fake data, and breaks off mid-sentence [16]. The excerpt also refers to steps 1 through 5 without reproducing the step list itself [17].
Watch for the full script and the seeding detail, because that is the operational content. Note also that the control which saved the sports club was a human reading tone [11], the exact attribute step 5 automation is aimed at [19].