37 views
39 minutes ago

Sleepless nights and 7,000 phishing campaigns: what AI has done to the people who defend your company

KnowBe4 recently observed a phishing operation aimed at a single organisation, assembled from 7,000 separate campaigns. Millions of emails reached the company, and nearly all of them were decoys, sent to bury staff and filters under enough white noise that the real lure, dispatched off the back of the flood, would pass unnoticed.

Dr Martin J. Kraemer, CISO Advisor for Europe and the Middle East at KnowBe4, used the case to explain how AI has changed the contest between attackers and defenders, and why the change is felt most acutely in human attention, where no signature file can help.

Kraemer acknowledged that his title puzzles people. The role, which some vendors call a field CISO, exists to bring a practitioner’s perspective to security leaders who are courted daily by companies focused on licences and products. He described himself as product agnostic and said his job is to support the practice of cyber security inside organisations, advising on risk and helping CISOs see through the jungle of competing vendor claims.

Before joining KnowBe4 he spent several years in academia, completing a doctorate in cyber security at the University of Oxford, where his research examined how people use and trust technology in their homes. That work, he said, was about people and their behaviour when it comes to security, which sits comfortably alongside KnowBe4’s roots in human risk management.

Asked what AI had done to the working lives of the CISOs he advises, he replied with “sleepless nights” before explaining why. “The pace at which we are going has increased rapidly,” he said, adding that the security picture of the past two years already looks like a different game from the one playing out this year. Organisations are adopting AI because the business benefits are hard to ignore, and security teams are left racing to keep pace with decisions made elsewhere in the company.

He was generous about how those teams are coping. “They are doing a great job, as best as they can,” he said. “But it is very challenging, starting with how do you even manage shadow AI inside your organisation, and then going into how do you do full governance for AI agents.”

Shadow AI begins with people, typically employees under pressure to work faster who reach for tools their employer has never approved, usually with good intentions and little sense of where their data ends up. Governing it asks security leaders to understand motivation and habit as much as software, which is where Kraemer’s academic training and his current work meet.

Security’s reflexive scepticism about AI holds for malware and fails at the inbox

Kraemer was candid about his own profession’s instincts. “As cybersecurity experts, we are sort of a little bit conservative by nature, and we are very much inclined to say it’s nothing new,” he said. “We’ve seen this already.”

On malware, he believes that instinct is largely correct. Every piece of software is eventually translated into machine code, which contains only a finite set of instructions, and defenders have spent decades becoming very good at detecting malicious patterns at that level.

Whether a piece of malware was written by a person or generated by AI makes little difference to defences operating that deep, and in his view much of the current noise about AI-built malicious software runs well ahead of what is actually happening.

Phishing tells a different story, because its target is a human being reading an email. Generative AI and AI agents allow attackers to scale campaigns to volumes that would once have required a sizeable criminal operation, and the 7,000-campaign attack was the illustration he reached for. The industry’s early comfort, that volume had risen while quality stayed flat, no longer holds in his experience, since the quality of lures has climbed alongside their number.

The economics of crime make this worse. “They only need to jump as high as they need to,” Kraemer said of cyber criminals. “They never need to even go for the most sophisticated attack.” Attackers, in his assessment, are only beginning to use the full capability of AI, which means the pressure on employees and the teams protecting them has room to grow.

The industry’s own data captures the tension. Kraemer pointed to IBM’s research on the cost of data breaches, which shows that breaches involving AI are more expensive, while organisations that use AI in their defences suffer less costly breaches. Security leaders are therefore being asked to embrace the technology that is raising their exposure, and to govern it with products that are still maturing. CISOs know they have a governance gap, he said, and vendors are rushing to fill it. “The tool set is still evolving,” he said. “It’s not mature yet.”

Every reinvention of the CISO in 15 years has demanded a more human skill

Kraemer traced the arc of the role back a decade and a half, to a time when the CISO was typically a hacker at heart. “That was a good time for many, because that’s where most of us come from,” he said. In those years the security function usually reported into IT and was treated as a service department, with the relationship dominated by IT leadership.

That arrangement has since broken apart, and financial services regulation now requires the security function to report outside IT. Kraemer described the logic in terms of mutual accountability, since a security team that answers to IT cannot credibly hold IT in check, and IT in turn needs an independent function it can be held against.

The new reporting lines brought money and new obligations. “You get budget more easily, but also you have to speak risk,” he said of CISOs who found themselves answering to finance leadership. “You have to speak finances. You can’t just speak in technological terms.” Security leaders had to learn to quantify risk and present it as part of the organisation’s overall position, and then, as human risk management matured, to become people managers who build teams, work with business units and explain risk to colleagues with no technical background.

The next stage, as Kraemer sees it, goes further again. KnowBe4 has widened its own focus from human risk to what it calls the digital workforce, in which AI agents work alongside employees and both need to be secured and governed. Because AI is reshaping organisational structure and process, the CISO now has to speak the language of operations and of governance in its fullest sense, which he called “proper governance”, the kind that concerns how a company is run and who is accountable when something acts on its behalf.

The most dangerous gap Kraemer sees sits in how boards perceive risk

When asked where the resistance lies, Kraemer did not point to legacy technology first. “Frankly, sometimes the board does not even understand risk language properly,” he said, and some CISOs struggle with exactly that.

For highly regulated and mature sectors such as banking, defence and oil and gas are better placed, in his experience, but even there the volume of activity across the region creates its own blind spots. Boards juggling many priorities are inclined to assume that an attack will strike a neighbour before it reaches them, a belief that tends to be corrected only after the event. Kraemer described risk perception at that level as badly skewed and argued that CISOs need far more face time with their boards to change it.

The point carries an ethical weight that goes beyond budgets. Employees who click on a well-crafted lure are routinely blamed for breaches, yet the decisions that determine how exposed they are, from what tools they are given to how much time the security team has with leadership, are made several floors above them.

Sovereignty will leave CISOs arbitrating between what regulators demand and what technology can deliver today

Looking ahead, Kraemer expects sovereignty to dominate the agenda in the region, covering both data residency and the broader technological sovereignty that governments here are investing in strategically. Regulation will keep advancing, rightly in his view, and it will pull the whole technology sector along with it, although the infrastructure required can only arrive at a certain pace. Questions about which data centres are available and which AI services can run within national borders have no single answer, and AI itself, he pointed out, covers many different kinds of service with very different implications for where data sits.

That leaves CISOs squeezed between competing obligations. They must explain to regulators what is technically feasible today, seek permissions and exceptions for rules that will eventually be enforced in full, and track the roadmap for sovereign technology inside the country so that their organisations are ready when it arrives.

Kraemer sees an opportunity inside that pressure. CISOs help shape the sovereign services and products being built, he noted, because their feedback on what works and what does not in practice informs how providers develop them. “They are really sitting in a strong and important position for public and private partnerships that are urgently required here,” he said.

The UAE Cyber Security Council already provides one such point of contact between government and industry, and Kraemer regards the CISO as the person working closest to it. The security leader who once sat quietly inside IT is now expected to carry what happens in the inbox and the boardroom into the rules that will govern the country’s digital infrastructure for years to come.

Leave a Reply

Don't Miss

New ServiceNow AI specialists to automate cyber risk remediation.

ServiceNow moves to autonomous AI security with six-solution launch

ServiceNow, the AI innovation company has announced six unified security solutions under

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy