Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adam Meyers’s core prevention lesson is to defend against the adversary, not just the malware: use intelligence about an attacker’s capabilities and tactics to anticipate what they may do next, then connect that knowledge to defenses that can detect and contain activity quickly. Patching remains essential, but a patch does not by itself establish that a system is safe.

CyberScoop published its video interview with Meyers, then CrowdStrike’s senior vice president of intelligence, on April 21, 2023. The published description says the segment discusses China-nexus threat actors, “vulnerability rediscovery” and the continuing risk posed by vulnerabilities that have been patched. It does not provide a full transcript, so the practical guidance below draws on Meyers’s other published comments and later CrowdStrike reporting rather than attributing additional lines to the video.

What Meyers’s approach means for prevention

CrowdStrike’s biography of Meyers describes his foundational view this way: “organizations don’t have a malware problem, they have an adversary problem.” The distinction changes what a security team looks for. A malware file is one clue; an adversary’s goals, capabilities, indicators and repeatable tactics, techniques and procedures (TTPs) can help a team anticipate the next step even when a particular file or indicator changes.

In a 2014 CrowdStrike Q&A, Meyers said defenders should consider “capabilities, indicators, attribution and intentions,” combining intelligence from multiple sources with knowledge of adversary TTPs to recommend better defenses. That is not a call to treat attribution as certain in every incident. It is a way to build a useful picture from evidence and use it to guide defensive choices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Turn intelligence into an operational outcome

Meyers has described the goal as bringing together technology and information so an organization can prevent an adversary’s access attempt or detect it quickly. For security leaders, he recommends beginning with two questions: “Who is your audience? Who are you bringing this intelligence to, and what is your expected outcome?”

Those questions keep intelligence from becoming a report that is informative but unused. An operations team may need a detection to deploy; an incident-response team may need likely follow-on actions; an executive may need a risk decision. Define the recipient and the decision or action first, then select intelligence that can support it.

Why patching does not end vulnerability risk

The CyberScoop video description highlights “vulnerability rediscovery” and the risk that patched vulnerabilities can remain dangerous, including in public-sector environments. Patching is a necessary control, but applying a fix is not the same as proving that every exposed system received it, that the relevant attack path is closed, or that an attacker did not already gain access.

Make patching verifiable

  • Maintain an inventory of internet-facing and internal assets, including devices that are unmanaged or outside routine endpoint coverage.
  • Confirm which affected systems are exposed, which have been patched, and which need mitigation or isolation while a fix is unavailable.
  • Validate remediation on the systems that matter, rather than relying only on a deployment record or a general statement that patching is complete.
  • Look for signs of exploitation and persistence as well as the vulnerability itself. If an attacker entered before remediation, closing the original flaw may not remove the attacker.

These are operational implications of the risk described in the video, not a transcript of Meyers giving those specific steps. The key distinction is between reducing a vulnerability and verifying that the wider exposure and any resulting compromise have been addressed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Close gaps between identity, cloud, endpoints and network

In later comments, Meyers described attackers exploiting seams between cloud services, identity systems, enterprise environments and unmanaged devices. Separate tools can leave these connections difficult to see: an identity alert may look low-risk alone, while endpoint or cloud activity supplies the context that makes it meaningful.

Correlate identity, endpoint, cloud and network telemetry so analysts can follow activity across systems rather than treating each alert in isolation. Include unmanaged devices in asset visibility and response planning; a security boundary drawn around managed endpoints does not make activity beyond it irrelevant.

Use a cross-domain coverage check

  • Identity: Can the team connect suspicious account activity to the device, application and session involved?
  • Endpoint: Can it identify processes and behaviors associated with the account or cloud activity?
  • Cloud: Can it investigate access and changes in cloud environments alongside enterprise activity?
  • Network and unmanaged assets: Can it see relevant connections and determine how to contain devices that are not under standard endpoint management?

This is a coverage test, not a claim that one product or data source will reveal every attack. The objective is to reduce blind spots at the handoffs between systems.

Prepare to detect and contain activity quickly

Attackers may move from initial access to activity elsewhere in an environment faster than a manual, siloed investigation can keep up. CrowdStrike reporting cited by CyberScoop put average breakout time at 48 minutes for 2024, with the fastest observed time at 51 seconds; its 2026 reporting put the 2025 average at 29 minutes and the fastest observed time at 27 seconds. These are CrowdStrike-reported figures, not measurements from Meyers’s 2023 interview or tests conducted for this article.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Reporting period Average breakout time Fastest observed breakout time Source timing
2024 48 minutes 51 seconds CrowdStrike reporting published in 2025
2025 29 minutes 27 seconds CrowdStrike reporting published in 2026

The operational lesson is to avoid assuming there will be a long window for a person to notice, investigate and contain every event in sequence. Bring indicators of attack, threat intelligence, adversary tradecraft and enterprise telemetry into detection and response workflows. Where appropriate, automate protective actions and remediation, while ensuring the team can review outcomes and handle exceptions.

Design a response path before an alert arrives

  1. Identify which signals should trigger investigation or containment, including activity that spans identity, endpoint and cloud systems.
  2. Assign ownership for triage and escalation, including after-hours coverage if the organization’s risk requires it.
  3. Define which response actions can be automated and which require human approval, based on impact and reversibility.
  4. Practice the path with realistic scenarios and verify that responders can access the data and permissions needed to act.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Prioritize intelligence against your organization’s exposure

Threat intelligence is most useful when it helps an organization make a specific decision. Meyers’s audience-and-outcome questions provide a practical filter: choose the adversaries relevant to the organization’s industry, geography and technology footprint, then connect their known capabilities and TTPs to exposed systems and defensive actions.

A team need not pursue every reported actor equally. It can use intelligence to focus attention on plausible threats, select controls and detections that address the organization’s exposure, and decide what further evidence or response is needed. This keeps actor tracking tied to risk rather than turning it into an attribution exercise for its own sake.

Put the framework into practice

  1. Set the outcome. State the decision or defensive action the intelligence should enable, and name who needs to receive it.
  2. Map relevant adversaries. Combine multiple intelligence sources with evidence about capabilities, indicators, attribution, intentions and repeatable TTPs. Treat conclusions in proportion to the evidence.
  3. Connect the map to exposure. Identify affected assets, vulnerable systems, identities and cloud environments, including unmanaged devices and cross-domain paths.
  4. Verify defenses. Confirm patch coverage and mitigation, and check for signs that exploitation happened before remediation.
  5. Make response fast and testable. Connect telemetry, establish escalation and containment paths, and automate suitable actions with appropriate oversight.
  6. Reassess as conditions change. Update priorities when new evidence, technology changes or a different adversary profile changes the organization’s exposure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.