
In 2013, security researcher David Bianco published a short paper that quietly reorganized how a generation of cybersecurity defenders thought about their work. He called it the Pyramid of Pain. His argument: the artifacts defenders chased most — IP addresses, domains, file hashes — sit at the bottom of a hierarchy. They're easy to detect and just as easy for an adversary to rotate. Block an IP today, there's a new one tomorrow.
Higher up the pyramid sit tools, and above those, the tactics, techniques, and procedures, (TTPs) that comprise the actual behaviors of the actors running the operation. These are dramatically more expensive for an adversary to change. A sophisticated attacker doesn't rewrite its playbook because one company blocked its domain. That shift, from artifact to behavior, is what built the MITRE ATT&CK framework and gave an entire industry a shared vocabulary for adversary attribution.
Financial crime is not cybersecurity. The artifacts, adversaries, and regulations are different. However, the structural point holds regardless of domain: any defensive discipline built around disposable artifacts eventually hits the same ceiling.
Think about what's cheap to throw away versus what isn't. An attacker can burn an IP address in an afternoon. A criminal network can burn a bank account in days and a shell company in weeks. In both worlds, the defender who only watches the cheap, disposable layer is stuck in an endless cycle — chasing something new every time the old thing gets blocked.
What neither an attacker nor a criminal network can easily throw away is its playbook: how it actually operates, what its tradecraft looks like, how it sustains itself over time. That's the expensive layer to change, and it's the layer worth building detection around.
The lesson isn't that AML should adopt MITRE ATT&CK wholesale — the domains are too different for that. The lesson is the underlying insight: move detection up the pyramid, from disposable artifacts toward durable behavior, and you stop playing an unwinnable game of whack-a-mole.
Cybersecurity had its own version of the 1% problem before Bianco's paper reframed the conversation. Financial crime is overdue for the same shift — an approach that catalogs behaviors, attributes them to named actors, and gives analysts a shared language for what they're actually looking at, rather than another rule tuned to catch yesterday's transaction pattern.
If this tension sounds familiar in your own program, Section 2 offers a thirty-minute working session for AML leaders at regional institutions — no pitch, just a walk through your risk footprint. Let's talk.