William Wright, CEO of Closed Door Security, joins Matt O’Neill on Detonation Point presented by Elastio to explore the world of offensive cybersecurity, red teaming, and modern cyber threats.
Drawing on experience across defense, critical infrastructure, financial services, and other industries, William explains how his team approaches security from an attacker’s perspective to uncover weaknesses before real adversaries can exploit them.

Thinking Like an Attacker Through Red Teaming
Red teaming goes beyond looking for technical vulnerabilities. William’s team tests both digital and physical security, using many of the same tactics a real attacker might use.
That can mean social engineering employees, gaining physical access to restricted locations, or finding a way onto an organization’s network. In one engagement involving critical infrastructure, William’s team posed as health and safety officers and was given alarm codes, Wi-Fi passwords, and access to connect to the network.
For William, these engagements often expose a simple vulnerability: trust. He explains that confidence and a believable story can be enough to get past employees who have not been empowered to question someone who appears to belong.
What Red Teams Find Inside the Network
Sometimes a security assessment uncovers problems no one expected to find.
William shares stories ranging from discovering a crew mining cryptocurrency aboard a super-yacht to encountering actual threat actors who had already compromised the same networks his team was testing. Those discoveries highlight why organizations cannot assume that strong security on paper means an attacker has not already found a way in.
How AI Is Changing Modern Cyber Threats
Artificial intelligence is also changing how quickly attackers can gather and use information. William explains that reconnaissance and open-source intelligence work that once took a team days can increasingly be completed in hours, allowing connections between people, companies, and online information to be identified at far greater speed.
AI is also making impersonation more convincing. William discusses the growing use of synthetic voice and video, including an incident where his team was sitting with a company executive while someone attempted to impersonate that same person using an AI-generated voice.
Protecting Information Beyond the Workplace
The conversation also explores how personal information shared online can become part of an attacker’s toolkit.
Through executive security reviews, William’s team has been able to piece together sensitive information about executives and their families from social media activity, sometimes through posts made by relatives and friends rather than the individuals themselves. His advice is straightforward: if you would not share something with a stranger on the street, think twice before putting it on social media.
The Growing Scale of Scam Factories and Fraud
Modern cybercrime is not limited to individual hackers. William and Matt also discuss the industrialization of fraud through large-scale scam operations.
William describes his work with an investigative journalist examining scam factories and the human trafficking and abuse behind some of these operations. Beyond the humanitarian impact, he points to the enormous volume of fraud these organizations can generate and the financial damage they can inflict on individual victims and communities.
The conversation also turns to prevention. William emphasizes the importance of verifying unexpected calls and requests rather than trusting the identity presented by a caller, especially as technology makes impersonation increasingly convincing.
Cybersecurity Careers: Experience vs. Credentials
William also shares his perspective on what it takes to build a career in cybersecurity. In 2024, he became Scotland’s first chartered cybersecurity professional, but he argues that certifications and degrees alone do not necessarily demonstrate someone’s ability to do the job.
For those pursuing offensive cybersecurity, William points to practical experience, self-directed learning, CTF competitions, bug bounties, and independent research as ways to develop skills beyond the classroom. Ultimately, he says experience and the ability to deliver can be more valuable than credentials alone.
More From the Detonation Point Blog
Continue exploring conversations on cybersecurity, fraud, and digital resilience:
- Building Cyber Resilience Against Modern Threats with Kiersten Todt
- The Evolution of Cybercrime: Ransomware, AI & Global Investigations with Jim Meehan
- Going Undercover to Infiltrate Cybercriminal Networks with Rich LaTulip
Listen to the Episode
From physical red teaming and social engineering to AI-powered reconnaissance, deepfakes, organized fraud, and the skills needed to succeed in cybersecurity, William Wright offers a firsthand look at how the threat landscape continues to evolve.
Watch or listen to Thinking Like an Attacker: Red Teaming & Modern Cyber Threats with William Wright.
YouTube | Apple Podcasts | Spotify