Ransomware, vCISO

“Ransomware is a business now – it’s time defenders ran theirs the same way” – Stacey Cameron, CISO, Halcyon

Ransomware isn’t just a cybercrime anymore; attack groups run it like a subscription service. And the industry isn't slowing down. Just today, following a major data breach, Salesforce refused to "engage, negotiate with or pay" hackers over stolen customer data - the company didn’t blink: no talks, no payout. But can all companies afford to take this stance?

I sat down with Halcyon’s Chief Information Security Officer, Stacey Cameron, to understand what makes ransomware so relentless, why resilience is the only real defense, and how security leaders can stay one step ahead.

Stacey's career story runs parallel to how the cybersecurity industry has evolved. She moved from analyst to security officer to consultant, and now leads enterprise security strategy as CISO at Halcyon. She’s seen this field from every angle.

In this conversation, we got into it all - what’s really changed (and what hasn’t) for women in cyber, why ransomware has evolved into its own industry, the way AI is reshaping both offense and defense, how Halcyon is redefining resilience by focusing entirely on ransomware defense, and why she believes “secure enablement” should replace the old mindset of “security as a blocker.”

Stacey is sharp, to the point, and real - the kind of guest who makes you pause and rethink how you look at security. I learned a lot from this one, and I think you will too.


MSSP Alert: You started as an analyst and have held roles from information security officer to CISO, plus consulting. How has that journey been, especially as a woman in security?

Stacey Cameron: Exciting. I’ve always liked taking on challenges and learning new things. When I master a skill set, I move to something else. I’m constantly learning and pushing myself, even later in my career. If someone asks, “Can you do this?” and it seems like something I should be able to do, I’ll say yes and go forward. I’ve usually been successful because it interests me.

I’ve been into tech since 13 or 14, started programming at 15, and kept going. When I went to school, cybersecurity wasn’t a major, so I did computer science. I’ve always loved math and science. I came out of school able to program but not wanting to be a programmer, so I went into more analytical work. I enjoy working with systems and people more than just algorithms and code, but having that background helped me work with technical teams and business owners.

In my first major technical job, I reported directly to a CIO and stood in for him at times. I was looking at executive-level conversations as an analyst, which helped me understand business from that level. As my technical skills grew, I kept that business alignment.

I moved from the government to the private sector when I realized my job no longer brought me joy. The private sector moved faster and was expansive. I worked across verticals - financial, education, startups, gaming - learning what makes sense to each and applying that from a cybersecurity perspective.

I also enjoy security and compliance. I understand why regulatory standards exist and the headaches they cause. Being able to pair regulator intent with business operations and explain it in plain English to system owners, managers, CEOs, and boards, helping organizations, that’s what I enjoy.

MSSP Alert: Have we made progress getting more women into cybersecurity leadership?

Stacey Cameron: From where I started to now, yes, but we still have a long way to go. I still walk into a room and look for other women. Many men don’t think to ask that; they’re just with peers they’ve always worked with.

There are positives: education is starting earlier, and there are affinity groups focused on women in cyber. My five-year-old’s school sent a note to focus on computer security, at kindergarten. That’s great. But I still meet young women who are the only ones in robotics or engineering, who aren’t taken seriously. That hurts to hear. The hope is mentors and support systems that say, “These are challenges; let’s push through and find solutions.” We are moving forward.

MSSP Alert: Why is ransomware so dominant, and why does it need a specialized defense?

Stacey Cameron: It’s profitable. Criminals do what makes money. The ecosystem evolved to Ransomware-as-a-Service, so you don’t have to be a computer genius. You subscribe, share a cut, and go. Some groups now focus on data exfiltration and extortion instead of encryption.

You also have nation-state support. These groups operate like businesses, down to customer service. The cost of goods sold is minimal.

Tactically, attackers “live off the land.” They exploit remote management tools and normal admin activity, so standard endpoint protection may not flag it. You’ll see deletion of shadow copies, file rewrites, and bring-your-own vulnerable drivers - techniques that bypass normalized endpoint protections. It keeps advancing. And people still pay ransoms, so the model persists.

MSSP Alert: How is Halcyon differentiating in ransomware defense?

Stacey Cameron: Focus. Our researchers and analysts spend their days dissecting ransomware - what attackers use and how it works. EDRs have to cover a broad landscape; we focus on what’s specific to ransomware across the attack chain.

We look for early indicators: misuse of remote management tools, deleting shadow copies, rewrite patterns - things that lead to encryption or exfiltration. We often catch activity earlier than endpoint tools because we’re tuned to ransomware. We also work with academia, law enforcement, MSPs, and others to keep improving.

We’re complementary by design. We don’t replace EDR; we enhance it. Think of your front door lock, alarm, cameras, dog—you don’t remove one to add another. And we add resiliency: if an attack happens, our key capture and decryption can reduce recovery from months of restores to days, sometimes hours.

MSSP Alert: Do buyers still treat anti-ransomware as just a feature inside endpoint/EDR?

Stacey Cameron: They do. I hear, “We have EDR/XDR; we’re covered.” But the sophistication we’re seeing bypasses those tools because activity can look like legitimate admin work. We’re honed on ransomware behaviors specifically. Customers familiar with Halcyon swear by it; others assume their tools are enough until they see the gaps.

MSSP Alert: How do you integrate without overlap or friction?

Stacey Cameron: Proofs of value are important. Let teams see what’s being missed. Our agent is designed and tested to work with other products. We don’t hog CPU, and we’re not trying to replace anything. We complement and enhance, and we bring resiliency that others may not.

MSSP Alert: MSPs and MSSPs are first responders. How do you help them make resilience part of their service?

Stacey Cameron: We work closely with partners, including MSPs, and we provide a 24×7 ransomware SOC that monitors your tenant. We don’t just alert - we reach out. If email doesn’t connect, we call and text until we reach the right contact. If you already have a SOC, we add expert eyes trained on ransomware indicators that may not look malicious enough to trigger action elsewhere.

MSSP Alert: Looking two to five years out, what worries you most, and how does that shape priorities?

Stacey Cameron: The unknowns. You handle that by staying close to the business - working with executives, VPs, and directors to understand mission-critical objectives and where the company is going in three to five years. AI is here to stay—policies, legislation, agents, and generative use. Embrace it, understand it, and securely enable the workforce.

The CISO role has evolved from purely technical to bridging IT/security and the business. Secure enablement is the goal.

MSSP Alert: Are SMBs at a disadvantage compared to larger organizations?

Stacey Cameron: There’s a gap because of resources and spending prioritization. If you’ve never been hit, it’s easy to think you’re fine. Think of it like insurance—you hope you never need it, but when you do, it matters.

SMBs should understand their threat landscape and data, get the basics right, make risk-based decisions, and stay on top of industry changes. If you can’t deploy everything at once, phase in enhancements—but keep moving.

MSSP Alert: Any final thoughts for CISOs and security leaders?

Stacey Cameron: Don’t be the “voice of no.” Explain the why. Understand what people are trying to accomplish and help them do it securely. Threats are constant - critical infrastructure, healthcare, education - often with limited resources but valuable data.

Not everyone should be a security professional. People should log in and do their jobs while we manage the perimeter and controls. To do that, we need tools that keep us ahead - an additional resilient layer like Halcyon helps users stay productive while we reduce risk.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

You can skip this ad in 5 seconds