Ransomware as a Service: The Supply Chain Attack Epidemic
Inside the RaaS economy — how ransomware affiliates operate, why supply chain attacks are surging, and what organizations can do to protect themselves.
Allan Liska
Senior Security Architect
Recorded Future
Dr. Sarah Chen
Host & AI Research Lead
Former DeepMind researcher with a PhD in Machine Learning from Stanford. Covers AI, quantum, and computational breakthroughs.
About This Episode
In Episode 134 of The Frontier Tech Show, host Dr. Sarah Chen sits down with Allan Liska, Senior Security Architect at Recorded Future, to discuss "Ransomware as a Service: The Supply Chain Attack Epidemic." This cybersecurity podcast episode, published on March 25, 2026 as part of Season 4, runs 46:22 and covers threat landscape evolution, zero-day economics, AI-powered attacks, and defensive AI, supply chain risks, regulatory compliance, workforce shortage, cloud security. The conversation provides a deep dive into the current state of cybersecurity technology, exploring both the technical breakthroughs driving the field forward and the real-world challenges that remain.
Allan Liska brings deep expertise to this conversation. As Senior Security Architect at Recorded Future, Allan Liska offers a front-line perspective on threat landscape evolution that goes beyond surface-level analysis. The discussion covers how cybersecurity has evolved over the past year, what the key inflection points have been, and where the technology is heading in the next twelve to eighteen months. Whether you are a practitioner, investor, or simply following the cybersecurity space, this episode delivers insights you will not find elsewhere.
Listeners will come away from this episode with a clear understanding of threat landscape evolution and its implications for the broader cybersecurity landscape. The conversation covers the science, the engineering, the economics, and the policy dimensions of ransomware as a service: the supply chain attack epidemic, making it essential listening for anyone who wants to understand where cybersecurity is going in 2026 and beyond.
Key Topics Discussed
- Threat landscape evolution: The discussion explores threat landscape evolution in depth, examining current capabilities, limitations, and the trajectory of development. Allan Liska shares specific examples and data points from work at Recorded Future, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Zero-day economics: The discussion explores zero-day economics in depth, examining current capabilities, limitations, and the trajectory of development. Allan Liska shares specific examples and data points from work at Recorded Future, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- AI-powered attacks: The discussion explores AI-powered attacks in depth, examining current capabilities, limitations, and the trajectory of development. Allan Liska shares specific examples and data points from work at Recorded Future, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Defensive AI: The discussion explores defensive AI in depth, examining current capabilities, limitations, and the trajectory of development. Allan Liska shares specific examples and data points from work at Recorded Future, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Supply chain risks: The discussion explores supply chain risks in depth, examining current capabilities, limitations, and the trajectory of development. Allan Liska shares specific examples and data points from work at Recorded Future, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Regulatory compliance: The discussion explores regulatory compliance in depth, examining current capabilities, limitations, and the trajectory of development. Allan Liska shares specific examples and data points from work at Recorded Future, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Workforce shortage: The discussion explores workforce shortage in depth, examining current capabilities, limitations, and the trajectory of development. Allan Liska shares specific examples and data points from work at Recorded Future, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
- Cloud security: The discussion explores cloud security in depth, examining current capabilities, limitations, and the trajectory of development. Allan Liska shares specific examples and data points from work at Recorded Future, giving listeners a concrete sense of where the technology stands today and what milestones to watch for.
Episode Details
Inside the RaaS economy — how ransomware affiliates operate, why supply chain attacks are surging, and what organizations can do to protect themselves.
Episode Transcript
Full transcript of "Ransomware as a Service: The Supply Chain Attack Epidemic" — Episode 134 of The Frontier Tech Show with Allan Liska, Senior Security Architect at Recorded Future. (925 words)
COLD OPEN
Marcus Webb: Allan, I've been following ransomware for a while, and I have to say — what's happened in the last year feels different. Not just incremental progress, but a qualitative shift. Am I reading that right?
Allan Liska: You are. And I think the reason it feels different is that we've crossed the threshold from 'interesting science' to 'practical technology.' That's a transition that many fields never make. The fact that we're talking about the supply chain attack epidemic in terms of deployment timelines and unit economics, not just research papers — that's the signal.
Dr. Sarah Chen: Welcome to TechNova. I'm Dr. Sarah Chen.
Marcus Webb: And I'm Marcus Webb. Today we're joined by Allan Liska, Senior Security Architect at Recorded Future. Allan, welcome to the show.
Allan Liska: Thanks for having me. Looking forward to this.
SEGMENT 1: The State of the Field
Dr. Sarah Chen: Allan, for listeners who are new to this topic, can you explain what ransomware actually involves and why it matters?
Allan Liska: At its core, ransomware is about threat landscape evolution. That sounds simple, but the implications are profound. When you can do zero-day economics reliably and at scale, it changes what's possible in Cybersecurity. The applications range from AI-powered attacks to defensive AI, and we're just scratching the surface.
Marcus Webb: How did we get here? What was the path from idea to reality?
Allan Liska: It was a long path — decades, in some cases. The foundational research in supply chain risks goes back years, but it was always limited by regulatory compliance. What changed is that we solved that limitation — through a combination of better technology, better understanding, and honestly, better computing power. Once the bottleneck cleared, everything downstream accelerated.
Dr. Sarah Chen: And where are we now on that path?
Allan Liska: We're in the early deployment phase. The technology works. We're proving it in real-world conditions. The next challenge is scaling — making it cheaper, more reliable, and more accessible. That's an engineering challenge, not a science challenge, and engineering challenges are solvable with enough time and resources.
SEGMENT 2: The Technical Details
Marcus Webb: Allan, I want to get into the technical details. What makes your approach different from what's been tried before?
Allan Liska: The traditional approach to ransomware relied on workforce shortage. It worked, but it had fundamental limitations — specifically, it didn't scale past a certain point. Our approach is different because we use cloud security to bypass those limitations entirely. Instead of trying to optimize within the old framework, we created a new framework.
Dr. Sarah Chen: What was the key insight that enabled that?
Allan Liska: It was actually a cross-disciplinary insight. Someone on our team had experience in supply chain, and they noticed a parallel between a problem in that field and our problem in ransomware. They brought a technique over, adapted it, and it worked. The biggest breakthroughs often come from the intersection of fields, not from deep within one field.
Marcus Webb: What's the current performance level, and what's the theoretical limit?
Allan Liska: We're currently at about 60 percent of what we believe is the theoretical limit. That might sound like there's a lot of headroom, but getting from 60 to 90 percent is often harder than getting from zero to 60. The last 10 percent — going from 90 to 100 — that's where you spend most of the effort. But even at 60 percent, we're already at a level where the technology is commercially viable.
SEGMENT 3: Real-World Impact
Dr. Sarah Chen: Let's talk about impact. Who benefits from this, and how?
Allan Liska: The impact is broad. In the near term, incident response is the primary application — and that alone justifies the investment. But the second-order effects are where it gets really interesting. Once you have ransomware working at scale, it enables things that weren't possible before — encryption and PQC, new business models, new capabilities. It's a platform technology, not just a point solution.
Marcus Webb: What about the risks? What could go wrong?
Allan Liska: I take risks seriously, and there are real ones. threat landscape evolution at scale is untested — we're confident, but there could be surprises. There's the regulatory risk — if policymakers move too slowly, deployment stalls. And there's the societal risk — any transformative technology has distributional effects, and we need to be thoughtful about who benefits and who's displaced.
Dr. Sarah Chen: How do you think about the ethical dimensions?
Allan Liska: It's something we discuss internally a lot. The technology itself is neutral — it's a tool. But how it's deployed, who has access to it, what safeguards are in place — those are choices, and they matter. I think the tech industry as a whole needs to do a better job of engaging with these questions proactively, not reactively.
SEGMENT 4: Looking Forward
Marcus Webb: Allan, what's your vision for where this field is in five years?
Allan Liska: In five years, I think ransomware will be unremarkable — and that's the goal. When a technology becomes unremarkable, it means it's become infrastructure. It's just part of how things work. That's what happened with the internet, with smartphones, with cloud computing. I think ransomware is on that same trajectory, and the five-year mark is when it crosses from 'exciting new technology' to 'standard tool that everyone uses.'
Dr. Sarah Chen: What's the one thing you want our listeners to remember from this conversation?
Allan Liska: That the future is being built right now, by people who are solving hard problems in labs and offices and factories. It's not science fiction — it's engineering. And engineering, when done well, is the most powerful force for progress that humanity has ever developed.
Marcus Webb: Allan Liska, Senior Security Architect at Recorded Future. Thank you for a really thought-provoking conversation.
Allan Liska: Thank you both. I loved this.
Dr. Sarah Chen: And thanks to all of you for listening. This is TechNova — see you next time.
Why This Episode Matters
This episode matters because cybersecurity is at a critical juncture in 2026. The conversation between Dr. Sarah Chen and Allan Liska cuts through the hype to deliver a grounded, evidence-based assessment of where threat landscape evolution actually stands. For decision-makers in technology, finance, and policy, understanding the nuances discussed here is essential for making informed bets on the future of cybersecurity.
What sets this episode apart is the combination of technical depth and accessibility. Allan Liska explains complex concepts in cybersecurity without oversimplifying, making this episode valuable for both experts and newcomers to the field. The discussion of threat landscape evolution and zero-day economics alone makes this episode worth listening to, but the broader conversation about the future direction of cybersecurity technology is what makes it truly essential.