Two Scattered Spider members just pleaded guilty in the UK for the Transport for London attack, but here's what keeps me up at night: they're teenagers. Eighteen and twenty years old, orchestrating attacks on healthcare and critical infrastructure. In my 15 years across LatAm and the Caribbean, I've watched threat actors get younger and more organized, but this is different. They're not lone wolves anymore. They're part of coordinated campaigns hitting insurance, education, IT, and professional services with backdoors like Mistic since April. The infrastructure they're targeting mirrors what I see in US fintech: trusted workflows being weaponized, old credentials still working, phishing at scale. What worries me most is how cheap and accessible the tooling has become. Not elite actors. Just kids with capability and intent. Your SOC is probably drowning in alerts while missing context. You need visibility beyond the noise. When I work with US firms, the first question I ask is: during your last incident, could you actually answer what happened and why you didn't see it coming? If that makes you uncomfortable, we should talk. How are you hunting for what you're not alerting on?