Reflections on presenting at InterCOP, hosted by INTERPOL - Josh Brody Reflections on presenting at InterCOP, hosted by INTERPOL | Josh Brody
Back

Reflections on presenting at InterCOP, hosted by INTERPOL

Reflections on Presenting at InterCOP hosted by INTERPOL

In July 2026 I presented at the 7th International Cyber Offender Prevention conference: InterCOP, hosted by INTERPOL in Lyon, France. Speakers talked about a very specific, single premise: the cyber threat is getting younger and faster, and we need better ways to stop kids before they become cases. Prevention. Interception. “Let’s get ahead of the thing instead of cleaning up after it.”

It’s a good premise. All speakers delivered on it. There was one notable missing delegation: mine.

Edit: Even more damming, between my well-connected co-presenter and I, neither of us found another American at the conference.

The room was good

The real prevention work came from people who came with a method and the scars from running it. Huge credit to the Dutch who are leading these efforts (and it’s not even close, but that’s a testament to what they’re doing and trying). Their work is genuinely interesting, and it’s clear that their government supports their efforts.

Some notes on the content, generally:

  • Behavioral intervention models that are structured and built to plan exactly where and how you interrupt a criminal phenomenon
  • Comparative work on why one kid who loves computers ends up offending and another with identical interests doesn’t
  • National survey data mapping the early, still-legal stretch of the pathway where you can actually reach someone
  • Structured deterrence programs with years of operational history behind them
  • Gamified interventions aimed at literal elementary schoolers

This was presented by European teams, mostly. Some Nordic, some further afield. The field is better for their efforts.

Almost every one of them had a government behind them. National police, or bureaus of investigation. Some agency with a prevention mandate and the budget to chase it—things unheard of in America. I didn’t see one consultant selling anything. It was people talking about government work—because they were the government, standing up to report what their country is actually doing to get ahead of youth cybercrime.

That’s the part that stuck with me. Not the quality, but the staffing.

Loud sigh, big yawn

I sat through talk after talk and eventually found a pattern: accents unfamiliar to me. I opened the agenda and looked for Americans. Homeland Security Investigations was teaming up with a Dutch researcher; a vendor was reporting intel on online communities.

Then there was me and my FBI profiler: a guy who ran illegal infrastructure and went to federal prison for it; a person who did the work inside the government on my case. Two ex-feds on different wavelengths: offender and employee, currently operating outside the machine. Inside the machine, this work apparently doesn’t have a seat.

I don’t say that to knock the Americans who were there doing other things—the investigative and intelligence work was genuinely strong. But it was investigation, attribution, understanding the ecosystem. Every other country in that room sent people to talk about stopping the thing before it starts. My government’s contribution to that specific conversation came from two men with no backing between them, let alone an endorsement.

Why

Here’s my theory, and it’s no more than a theory—I have a hunch and an argument.

US cyber enforcement is built around prosecution as the goal. Everything upstream feeds charges. Attribution, intel, the whole apparatus—it points at a courtroom. That’s it. A big, well-funded, genuinely capable—albeit imperfect—system.

There is nothing in that pipeline for prevention. The best possible outcome in prevention is a kid who never becomes a case. No arrest, no press release, no sentence. Points are scored by getting convictions; an intervention that produces nothing to charge looks, from the inside, like doing nothing.

The programs I watched come out of places where “we redirected them” is a win—fundable, reportable, good for a career. In the US, the win condition is a conviction, and a conviction requires an offense. You have to let the thing happen to score. No defense other than the defendant.

That’s the structural defect, and here’s the icky cultural version sitting on top of it: Americans are perpetually horny for justice—just look at our top TV programming. We would rather catch and punish the bad guy than quietly arrange for there to be no bad guy to catch. The former feels like righteousness and the latter feels like a rounding error.

One of them makes the news. (Disclaimer, potential bias: I very much made the news.)

I could be wrong. Maybe the US government prevention people exist and simply weren’t present—the field is young, and who gets on a plane to Lyon is half accident. I’d believe that. But something has to explain why the country with the largest cyber enforcement apparatus on earth showed up to a prevention conference with no prevention arm to speak of, and left the seat to be filled by an ex-con and a guy who quit.

Big laughs to one of my well-resonating bits:

Shoutout to every country that made it past the round of 16 at the World Cup. You all have something in common: government-run healthcare, and governments that give a shit about cybercrime prevention and intervention.

What we brought instead

For the record, the seat did get filled.

I presented with the FBI profiler who was on my case. We’re friends now and I refer to him as my FBI profiler friend. Our work presented a simple, uncomfortable idea: don’t destroy offender infrastructure, but disrupt it. Engineer small, deniable failures instead of publicly seizing the thing. A takedown ends the story: this domain has been seized is hardly effective but sexy for a press release. A minor, well-placed malfunction keeps it running and tells you enormously more—how the offender responds, what they trust, what they value, and where they’re vulnerable. Minimal interference is more behaviorally exploitable than a raid.

That’s an applicable method. It’s a deliverable the room asked for.

And it came from having been the offender on the receiving end of exactly this—not from modeling it from a desk or doing surveys. I ran the infrastructure, understood the scene, the demand, the want and the need. I also did this at a large scale. I felt what a disruption does to the person operating under it, because I was that person. You can profile that response from outside. It’s not the same as having lived inside it.

I’ve come to understand that I’m rare candy in these rooms. There’s legal exposure and reputational risk. I’d gather it’s weird to mail an invitation to the former prisoner who is fresh out of prison and just starting probation. But I’d argue that’s why it’s worth something.

What prevention loses

The US is not short on threat description. It has plenty. It is not short on investigative muscle—it has more than it knows what to do with and wastes its time regularly.

It’s short on prevention, at the government level, in a room where many countries were represented. And it’s shortest on the one perspective that turned out to have real value: someone who walked the pathway and came back to explain it.

Every other delegation had a government behind them. Mine had two guys who did this in spite of one. That should bother somebody in Washington, but it probably won’t.

Stay in the loop

Occasional essays on design, tools, and the craft of building things. No spam, unsubscribe anytime.

Ambient weather

The background of this site reflects the current weather and time of day in Saint Paul. The orbs shift in color and behavior based on what's happening outside my window.

Learn more about how this works