After three decades fighting terrorists, Dexter Ingram has reached a conclusion cybersecurity professionals should find unsettling: Their adversaries aren't nearly as different as they might think.
Ingram, a recently retired U.S. counterterrorism official whose career stretched from the Navy and FBI to INTERPOL, Afghanistan and the State Department, spent much of his Sunday morning CruiseCon 2026 presentation drawing parallels between national security threats and modern cyberattacks.
“Every counterterrorism job I had was a cyber job in disguise,” Ingram said.
Terrorists crossed borders with stolen identities. ISIS moved propaganda from mainstream platforms to encrypted applications when governments and technology companies disrupted its communications. Extremist recruiters exploited human vulnerabilities rather than technical ones.
Cyber adversaries do much the same thing.
And according to Ingram, defenders in both worlds repeatedly make the same mistake: They treat disruption as victory.
The enemy doesn't die. It moves.
One of Ingram's slides reduced his argument to four lessons:
The enemy doesn't die. It moves. Having intelligence isn't knowing what to do with it. The clock keeps shrinking. It always comes down to people.
For security teams accustomed to watching ransomware operations disappear after law-enforcement actions only to reemerge under another name, the first lesson should sound particularly familiar.
Ingram compared terrorist organizations directly with ransomware groups. A terrorist organization loses territory; a ransomware crew loses servers. Both change names. Both shift operations to affiliates. Both eventually reappear somewhere else.
“Same playbook, different weapons,” he said.
The implication for cybersecurity defenders is that taking down infrastructure isn't enough. Organizations need to anticipate what happens after the takedown.
“Plan for the comeback, not just the win,” Ingram's warned.
That lesson came directly from his experience helping coordinate the 89-country coalition fighting ISIS. When the coalition stripped ISIS of territory, the ideology didn't disappear. Affiliates emerged elsewhere, including increasingly lethal operations across Africa.
Cyber defenders face essentially the same resilience problem.
“You have to see where that puck is going,” Ingram said. “If you're just chasing it constantly, you're going to be behind the ball.”
Intelligence without action is just data
Ingram's second lesson may be the most relevant one for SOCs drowning in alerts and telemetry.
During counterterrorism operations, U.S. forces routinely captured laptops and other material containing enormous amounts of potentially valuable intelligence. But classification restrictions, limited analytical capacity and organizational silos sometimes left that intelligence sitting unused.
Having the information wasn't the objective.
“The end goal is getting it into the hands of people that can do something with it,” Ingram said, whether that meant preventing another attack or prosecuting the people responsible for one.
Security teams should recognize the problem immediately.
Organizations can buy more telemetry, deploy another detection platform and generate another thousand alerts. None of that matters if nobody knows who owns the response — or if responding requires assembling a committee while the attacker keeps moving.
Ingram urged organizations to identify in advance who owns critical alerts and, more importantly, who has authority to act without waiting for another meeting.
That distinction — between possessing intelligence and operationalizing it — may be one of the most important connections between Ingram's counterterrorism career and today's cybersecurity environment.
The clock is getting shorter
Technology is also eroding a defensive advantage national security organizations once relied on: expertise.
Historically, executing sophisticated terrorist operations involving chemical, biological or nuclear materials required people with specialized knowledge. That requirement created friction. Finding a physician, physicist or engineer with both the necessary expertise and willingness to participate wasn't necessarily easy.
AI is beginning to change that equation. Ingram described a recent example involving an African terrorist organization trying to overcome a trench. According to Ingram, the group entered the trench dimensions and vehicle information into a chatbot and used its response to modify the vehicle so it could cross the obstacle and attack its target.
The example illustrates a larger problem for cybersecurity and national security alike: AI can compress the distance between intent and capability.
Attackers don't necessarily need to possess every skill themselves anymore. Increasingly capable AI systems can help close their knowledge gaps. That means defenders may have less time between the appearance of an adversary's intent and its ability to execute.
Terrorism and cybercrime target the same vulnerability: people
For all the technology discussed during his presentation, Ingram repeatedly returned to something decidedly low-tech.
People.
During his work countering violent extremism, Ingram saw recruiters identify people who felt forgotten, alienated or angry and offer them deceptively simple explanations for complicated problems. Different extremist movements blamed different targets, but the underlying recruitment mechanics often looked remarkably similar.
“You find somebody who has grievances. You give them simple solutions,” Ingram said.
The connection to social engineering is difficult to miss.
Attackers don't always need to hack a system when they can manipulate the person sitting in front of it.
Ingram pointed to the convergence directly. At INTERPOL, stolen identities allowed fighters to cross borders using someone else's passport. During the fight against ISIS, encrypted apps allowed propaganda networks to continue operating after they were pushed off major platforms. In countering violent extremism, recruiters exploited human weak spots.
The technology changes. The vulnerability doesn't.
“The moment you make it about technology exclusively, you're missing something,” Ingram said. “It comes down to people.”
Don't wait until you're dead in the water
Ingram's title —“Dead in the Water”— was ultimately less about terrorism than organizational paralysis.
Being dead in the water, he explained, means seeing what's happening around you but being unable to move. Bureaucracies can put organizations into exactly that position when nobody knows who should respond, intelligence doesn't reach the people who need it or leaders hesitate because acting carries professional or political risk.
Cybersecurity has its own versions of that paralysis. Alerts fire. Indicators accumulate. Everyone knows something is wrong. But nobody has explicitly been empowered to make the call.
After 30 years working threats ranging from weapons of mass destruction and ISIS to nuclear proliferation and violent extremism, Ingram's lesson for cybersecurity practitioners wasn't that counterterrorism holds some secret technical formula.
It was almost the opposite. Adversaries deceive. They adapt. They exploit people. They disappear when pressured and emerge somewhere else. And increasingly, technology allows them to do all of it faster.
Defenders therefore have to do more than detect threats. They have to be ready to move.
