Santiago Lopez de Toledo

Research & Analysis

Research

Analytical and technical work on cyber operations, insider-threat detection, and economic statecraft.

ICADE · Final Thesis · Applied ML

Machine Learning Techniques for Detecting Insider Threats

Evaluated against ReceiptVault, a modeled FinTech platform, using the CERT r4.2 dataset

Compares supervised classification models (neural network, random forest, SVM, K-NN, and a hybrid ensemble) for insider threat detection, reviewed against GDPR, DORA, ENS, and PSD2. Builds a custom cost function that weights false negatives ten times more heavily than false positives, and recommends the neural network over the higher-scoring hybrid because undocumented hyperparameters make the hybrid impossible to replicate or trust in production.

“Methodological rigor is even more important than the quantitative results obtained by a model.”
Machine LearningInsider ThreatFinTech
Read PDF →
Independent Research · Strategic Case Study

The Sony Hack and the Use of Cyber Coercion

Tracing the Lazarus Group and North Korea’s rise as a cyber power

Traces the 2014 Sony Pictures breach from initial intrusion through the Guardians of Peace’s terrorist threats, US attribution to North Korea’s Lazarus Group, and the resulting shift in how Washington treats state-sponsored attacks on private companies. Argues the operation was the first clear demonstration that a resource-poor state could use malware to deliver a political message on the world stage.

“Influence and sociopolitical disruption of a foreign state is no longer only achievable through traditional espionage, trade war, or military power, but through code.”
North KoreaLazarus GroupCyber Coercion
Read PDF →
Independent Research · Economic Intelligence

Economic Intelligence on Iran

Why Iran’s opaque financial architecture demands direct Intelligence Community collection

Applies Philip Zelikow’s framework for when the Intelligence Community should collect economic intelligence directly, rather than relying on open sources, to Iran’s state-controlled economy. Argues that the IRGC’s use of shell companies, bonyads, and informal banking channels to finance proxy militias makes OSINT alone unreliable, and that precise economic intelligence is what lets sanctions target the networks sustaining the regime.

“Modern threats are no longer defined solely by military capability but by a state’s ability to sustain political influence through economic power.”
IranEconomic StatecraftIRGC
Read PDF →