Roger Grimes, KnowBe4
Recorded at RSAC 2026 this conversation examines human risk management, agentic artificial intelligence, workforce trust management and data-driven defense. Roger A. Grimes of KnowBe4 is chief information security officer advisor and a long-time expert in security awareness and data-driven defense. Grimes outlines human risk management, HRM, fundamentals such as training nudges and culture and explains how agentic AI reshapes human behavior threat surfaces and the operational models security teams must adopt to manage risk effectively. They also discuss the role of AI-driven orchestration and hyper-personalized awareness programs in improving defensive outcomes. Key takeaways include two complementary AI-era risks — attacks from AI such as deepfakes and AI-enabled phishing and attacks against AI such as model and data poisoning — and the need to govern both people and agents. Grimes highlights that KnowBe4 early data indicate AI-enabled campaigns reduce simulated phishing risk approximately threefold compared with human-managed programs while nudges and agent governance remain essential. This discussion emphasizes practical strategies for security awareness training, phishing simulations, workforce trust management and data-driven defense to strengthen organizational cybersecurity posture.