Google's Sandra Joyce at RSAC 2026: Sharing Threat Intelligence Is No Longer Enough
Google Threat Intelligence VP Sandra Joyce told RSAC 2026 that the cybersecurity industry must move beyond sharing intelligence to actively disrupting threat actors — using legal tools, coordinated takedowns, and AI-powered defences to stay ahead of increasingly automated adversaries.

Sandra Joyce, VP of Google Threat Intelligence, delivers keynote at RSAC 2026 on active cyber defense and AI-driven threats
Sandra Joyce, Vice President at Google Threat Intelligence, took to the stage at RSAC 2026 in San Francisco with a pointed message for the cybersecurity industry: sharing threat intelligence is no longer sufficient. The sector must now operationalise it through coordinated takedowns and active disruption of threat infrastructure — before attacks reach their targets.
"We're now in a position where we can and we must actively shape the outcome of adversary behaviors," Joyce told attendees. "The private sector operates the very infrastructure that adversaries abuse."
In her keynote — titled Activate Industry!: Moving Beyond Defense to Disruption and Active Defense — Joyce outlined why organisations must stop waiting to be hit and instead proactively impose costs on threat actors.
AI Is Lowering the Bar for Attackers
A core theme of Joyce's address was the accelerating impact of AI on the threat landscape — and how it is mirroring the technology's adoption on the defensive side. Threat actors are now using AI to generate deepfakes, craft more precisely targeted spear-phishing emails, and produce malware commands on the fly — effectively using what Joyce described as "vibe coding" to amplify capabilities that would previously have required specialist technical skills.
"The sophistication that these low-level adversaries have is now higher because the bar is really lower," Joyce said. "We certainly see the potential there for maybe a low-skilled actor to actually get 10x through using AI tools."
On the defensive side, AI is also accelerating threat intelligence work — from faster malware reversal and binary analysis to improving Gmail's phishing filters, which now process and act on threat signals at a scale and speed no human team could replicate.
Active Defense: Disruption, Not Hacking Back
Joyce was careful to distinguish active defense from offensive cyber operations. The new approach uses legal authorisations and technical capabilities to impede threat groups — including court orders to take down attacker infrastructure, public exposure of hacking groups, and product improvements that prevent further intrusions — but stops well short of hacking into adversaries' systems.
The clearest illustration of this approach in action was Google's disruption of the IPIDEA residential proxy network — a coordinated legal and technical operation that Joyce highlighted as a model for industry-wide active defense. In a single seven-day period in January 2026, Google's Threat Intelligence Group observed over 550 individual threat groups using IPIDEA exit nodes to obfuscate their activities — including state-sponsored actors from China, North Korea, Iran and Russia — conducting everything from access to victim SaaS environments to large-scale password spray attacks.
Google's actions caused significant degradation of IPIDEA's proxy network and business operations, reducing the available pool of devices for proxy operators by millions. The operation was carried out in partnership with Cloudflare, Spur and Lumen's Black Lotus Labs — a model of cross-industry technical and legal cooperation that Joyce argued the rest of the sector should adopt as a standard operating posture.
27 Years of Intelligence, Now Applied to the AI Era
Joyce is a cybersecurity leader with over 27 years of intelligence experience who joined Google following its acquisition of Mandiant in 2022. Cyber Defense Magazine She serves on the Aspen Institute US Cybersecurity Group, the Ransomware Task Force Steering Committee, the Board of Visitors at the National Intelligence University, and is a visiting fellow at the National Security Institute — bringing a rare combination of military, intelligence community and private sector experience to her role leading Google's threat intelligence function.
Her message at RSAC 2026 was ultimately a call to action: as adversaries become faster, more automated and increasingly AI-augmented, passive defence and intelligence sharing alone will no longer be enough. The industry's response must match the speed and scale of the threat — and that means moving from observation to disruption.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.