Join us as we explore AI's impact on cybersecurity with Javvad Malik, lead security awareness advocate at KnowBe4, recorded live at the Data Protection & AI Summit.
In this session, cybersecurity expert Javvad Malik shares their insights into the role of AI in transforming security awareness training at KnowBe4. Christophe Bertrand of theCUBE Research hosts the conversation, examining how AI can personalize training by adapting to individual behaviors and roles. Malik’s extensive experience, spanning 25 years in the field, provides a rich backdrop to the discussion, highlighting theCUBE’s commitment to insightful tech analysis.
Key insights include how AI enhances the efficiency of cybersecurity defenses and reshapes attack strategies, such as AI-generated phishing emails. According to Malik, there is also an exploration of the dual nature of AI in organizations and its impact on human roles, raising questions about trust, compliance, and future training needs. The discussion uncovers both opportunities and challenges presented by AI in the cybersecurity landscape.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Data Protection & AI Summit. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For Data Protection & AI Summit
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Data Protection & AI Summit.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Data Protection & AI Summit. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to Data Protection & AI Summit
Please sign in with LinkedIn to continue to Data Protection & AI Summit. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Javvad Malik, KnowBe4
Join us as we explore AI's impact on cybersecurity with Javvad Malik, lead security awareness advocate at KnowBe4, recorded live at the Data Protection & AI Summit.
In this session, cybersecurity expert Javvad Malik shares their insights into the role of AI in transforming security awareness training at KnowBe4. Christophe Bertrand of theCUBE Research hosts the conversation, examining how AI can personalize training by adapting to individual behaviors and roles. Malik’s extensive experience, spanning 25 years in the field, provides a rich backdrop to the discussion, highlighting theCUBE’s commitment to insightful tech analysis.
Key insights include how AI enhances the efficiency of cybersecurity defenses and reshapes attack strategies, such as AI-generated phishing emails. According to Malik, there is also an exploration of the dual nature of AI in organizations and its impact on human roles, raising questions about trust, compliance, and future training needs. The discussion uncovers both opportunities and challenges presented by AI in the cybersecurity landscape.
In this interview from the Data Protection + AI Summit, Javvad Malik, lead security awareness advocate at KnowBe4, joins theCUBE Research’s Christophe Bertrand to reveal how AI is transforming security awareness and human risk management. Malik explains how KnowBe4 is harnessing AI’s speed, scale and contextual understanding to build dynamic risk profiles, tailor micro-training to individual roles and deliver just-in-time “nudges” when risky actions occur.
The conversation examines AI as both ally and adversary, from LLM-crafted phishing emails and in...Read more
exploreKeep Exploring
What is the role and responsibilities of a lead security awareness advocate at KnowBe4?add
What is the role and focus of an advocate at KnowBe4, and how does the company position itself in the field of cybersecurity?add
What are the ways in which AI is being utilized in the context of security awareness training at KnowBe4?add
What is just-in-time training in the context of AI integration with security systems?add
What are some alternative ways individuals might engage in training or support for cybersecurity?add
>> Hello, and welcome back. I'm Christophe Bertrand, principal analyst at theCUBE Research. We are back here in our
Data Protection & AI Summit. We are going to have a very
interesting discussion today with Javvad Malik from KnowBe4. Javvad, thank you so much
for joining us from London.
Javvad Malik
>> Oh, thank you so much for having me. It's an absolute pleasure to be here.
Christophe Bertrand
>> So, Javvad, tell us more about yourself. I'm making sure I get the right title, lead security awareness advocate, which sounds like a very cool job title. So what does that mean? What do you do? Tell us about KnowBe4, for the viewers who may not know us and know you.
Javvad Malik
>> Yeah, yeah. So you're not wrong. It is a very cool job title, and I sometimes have to pinch
myself in the morning to say, "Is this what I really get paid to do? " because I get to do all the
fun parts of cybersecurity. I've worked in cybersecurity
my entire career, so coming up to 25 years now. But the last six years
I've been at KnowBe4, and as an advocate, what
that involves is doing a lot of research, speaking to
some customers and prospects, but then going out and doing presentations,
writing up research, doing podcasts, interviews,
all this kind of good stuff. So it's all the benefit
of learning from others and sharing that expertise
without the responsibility of managing a SOC, or a security team, or any of the stresses
that come along with that. So that's what I do. But KnowBe4, as a company, we are the world's leader in
security awareness training and human risk management. And what that means is that we just put the human at the center of cybersecurity for everything we do. So that involves, how do we
protect people from attacks? How do we educate them? How do we empower them, and how do we protect them when something inevitably goes wrong?
Christophe Bertrand
>> Right, and this is a
very interesting topic because there's so much
misunderstanding around what AI can do, or will
do to humans in general. And certainly, when we
double-click on the topic of cyber resiliency and the
protection of data assets, and the protection of processes, and really, the protection of
the business, in many ways, I think there's a lot of... maybe there are lots of misconceptions around whether AI is a
friend, or is AI a foe? And what will be the consequences for the cyber professionals and IT professionals
with the advent of AI, both on the attack side, the defense side, and of course, as a business
outcome and a business process? Because it's also a workload
that is going to change what businesses can produce. So I'd like to double-click
on that with you, Javvad, and then talk about the
use of AI in cybersecurity. Maybe let's look at the friendly way, because you can do lots
of great things with AI. You can literally go
analyze phishing attacks and emails a lot faster, for example. But there are many other ways that AI could can be leveraged. So what do you see today, and what are you working on at KnowBe4 as to leverage AI as your
friend, more than the enemy?
Javvad Malik
>> Yes, yes. So that's a fantastic point. And I think you're right, AI has embedded itself into every
side of the equation. You can't just say it's
purely only used for good or bad purposes, or business purposes. What we are seeing, I
suppose, in what we do, and how we're using AI, I
suppose there's three key areas. One is basically, so when
we look at AI, we say the things that it's great at is the speed and the scale at which it operates, and how it can understand the context in
which information is presented quite easily, and come up with
recommendations and so forth. So old-school, say like
security awareness training, was kind of like a one-size-fits-all. You just have this one set
of training that goes out, but with AI now, we can
actually understand people's behaviors, we can understand
people's job roles. So rather than it being a manual and laborious task, which
even on many organizations, they don't have a very good
handle off what every role does. I mean, role-based access
control is great for a broad set, but still, there's a lot of users that carry out these hybrid
functions and what have you. So AI can help us understand
what exactly the roles of people are, and they can then build out custom training for them. So if you are, say, in a job like mine and you travel a lot, then,
hey, it's really useful for me to receive regular training on how to stay safe when
traveling, what was expected to maintain my security of my devices. If I book a trip to a certain country, then it'd be really useful if
it could automatically push out relevant to that country,
say like, oh, here are some of the restrictions, or some
of the concerns we have. So don't take a personal device, or don't take this corporate
device, and only use a VPN, or whatever that might be. So building up a risk
profile off users, tailoring that training to them
is very, very powerful, and AI has helped us do that,
which you couldn't do before. The second part is the just-in- time training, or the nudges, as you call it, which is where AI can integrate with
your existing security stack. So you have firewalls, you have
network monitoring controls, you have some EDR, you
have some gateway controls. So you have a lot of visibility
into what people are doing. And what AI can do is pull
all of that out and analyze it and say, "Okay, this user's
now plugged in a USB drive. It's not a corporate-approved one. Let's send them a nudge
right in that moment and say, 'Hey, this might not be something that you want to do. How do we protect you? Or maybe you want to raise a ticket, or are you sure you want to proceed? '" And sometimes that's all people need, a little reminder in the moment as to how to interact. Yeah, sorry.
Christophe Bertrand
>> Yeah, Javvad, I love the use of AI the way you're describing it, because you're right, I've
been through, like many of us, I'm sure, extremely long and boring cyber training, and
that's just the way it was. It was necessary. I'm not arguing, we probably all needed it, but the truth is, having
this interaction now, this interactive customized nudging
when maybe you're doing something wrong, or there's
at least some probing that maybe something should
be done differently, I think that's really great because that's also how
you instill the right type of behavior when it comes to providing security to the environment,
to the data you're using, etc., as an individual. So I think that's really definitely something that I
did not quite expect to be as advanced, and certainly
something I'll be looking into more closely. So obviously that's AI helping you scale the
individualization of training, the repeated messaging, and the nudging, and of course, the best practices of security throughout your workday. So that's great. I think that allows you to do this at scale. It's going to be better quality. But let's talk about what
AI could also be doing to your employees, to your humans, when maybe they impersonate humans, or try to manipulate them. So let's go into the
negative aspect of AI here. What can you tell us about the type of manipulation you've seen, and what you're preparing
your customers for, and how do they defend themselves, really?
Javvad Malik
>> Yeah. So there's a
number of different types of manipulations going out there, and the most common ones are the ones that we can see immediately
is AI being used to generate very good phishing emails, or other social engineering attacks. And what we see with that is LLMs. And there's research that's
been carried out about this on, can LLMs be more persuasive than humans? And the answer has been
yes, unfortunately, because it doesn't get
emotional, it doesn't get tired, and it can reference hundreds of data points at the same time to come up with a convincing argument. So once you get someone in the back- and-forth, it can actually go through and convince people of it. And what we see on some of the darker side of the web where you have
these AI models without any guardrails on, is people are using this for all sorts of things. I even saw one recently where people were using it as a
pickup tool in the sense that they were using it as an automated dating profile thing. So it would automatically
swipe right on profiles, and then carry on a
conversation with someone so that it could increase your
likelihood of getting a match, which completely inauthentic, and probably not for the
right reasons anyway, but we are seeing a lot of that. The second thing we're seeing, and this is a little less
more obvious, is kind of like, which is sometimes referred
to as invisible propaganda, or algorithmic bias. And we see that a lot in social media, and how certain items get suppressed, or certain things bubble to the top. And there's been a research
done recently on TikTok, and, I mean, the same
research could apply anywhere, but they were talking about TikTok and how it shapes people's view of China. And what they found is that people that were heavy TikTok users
had a more favorable view of China and its human rights
records than non-TikTok users. And one of the reasons for that
is that if you do a search, say, for Tiananmen Square,
for example, the majority of results would give you something positive about Tiananmen Square. The second-largest section would be what they call distraction topics, which is people dancing
in Tiananmen Square, or sampling food in Tiananmen Square. And a very small percentage
would actually be referencing to the actual incident
that occurred there. So there's a lot of this kind
of bubbling up that happens. There's also been other
experiments done where if you look at a certain video, depending on your personal preferences, the comments will be
ordered in a certain way. So if you agree with a certain viewpoint, then those comments
will bubble to the top. So you think that, "Oh, most
people are agreeing with me," but if you're of a different viewpoint, other comments will bubble to the top. So this kind of like
this algorithmic bias, or the use of AI in invisible propaganda to shape views and opinions. And while this isn't like something that immediately hits an organization, but it can be used for a
long-term disinformation campaign.
Christophe Bertrand
>> Okay, that's actually scary.
I mean, we've heard about it. It's maybe one of the
most talked about issue that people see with AI when
it comes to manipulation of the news, for example,
viewpoints, it's a lot more subtle. So definitely, I can see how
that becomes an issue for any organization over time because what you're talking
about is the ability to essentially affect a brand. I mean, being a product
person, a marketer as well, I could see how a
nefarious actor could try to undermine your brand
over a period of time with this type of influencing. So definitely something to think about. Let's talk about the next wave, I think, of evolution of AI. When we prepared this conversation, I really wanted your perspective on what you think about
agents and agentic AI. And really, in a way,
you're dealing with humans, that's your focus. And of course, they're not going away, but agents, in many ways, will
replace humans in the sense that they will be performing tasks. And more importantly, not
just automating tasks. That's okay, that's great
for scale, and I love it. I can do more with less work, but I'm still the one
making the decisions. It's still my thinking,
still my objectives. It's still everything about
me making the decision. But now we're getting into a world where agents would be making
decisions about certain outcomes, and maybe
talking to other agents to make those decisions. So it becomes a very different
world when essentially non- human agents, representatives make decisions for you. What's your take about where we're at, and where we're going,
and how can you help?
Javvad Malik
>> I think we are at a
very interesting point in how AI and the speed at
which it is evolving is something that I think
we won't see the true impact for a while. But what we're already
seeing is, as a result of agents going out and trying to, or starting to automate
a ton of things, is we're seeing a lot of websites
now trying to optimize for AI crawlers and agents,
as opposed to humans, because that's where they see the future of traffic coming from. And so, you could say, if
you want to book a holiday, for example, you could
say to your travel agent, "Go out, research this. Here's my requirements, here's my budget. I want to go somewhere scenic, but I have a limp, so make
sure it's not too many steps," or what have you. And it'll go out, and it
can even book stuff for you, and it can book the flights, and accommodation, and what have you. So now you are talking about disruption of the e-commerce model. You don't have to have
accounts and everything. Your agent is going out, and there's a whole new
wave of SEO, I suppose, which is geared towards agents. So it will fundamentally change
the way in which, I suppose, how we understand a lot of the commerce to take place today to go on. But with that comes a lot
of challenges in that, well, how sure are we that the
agents themselves aren't compromised, or compromised
in a way that, well, maybe they're accepting ad
revenue, so now they're going to favor some results over others. Now it's going to force you
down a particular route. And if websites are not
optimized for humans anymore, you're going to have great
difficulty in finding an alternative solution. So what you could end up doing is forcing everyone
down a particular funnel or a pathway which eliminates choice. And I'm not saying that
agents are necessarily bad, there's a lot of benefits to it, but I think what we need
to maintain is some sort of collaborative approach
with humans and agents. I think we are way too
early in the process to completely hand over decision-making. And it is convenient. I get the convenience of it, but I think from a
integrity point of view of what we are actually receiving, I think that doesn't make sense to
hand that over quite yet. And I don't think organizations actually realize the impact this
could have as well. And we spoke about this before where I mentioned about liability. I said, "Well, as an employee, if I go off and ask my agent to do something and it does something
that's slightly illegal, where does the liability lie? " and you rightly said,
"Well, an employee is kind of like an agent off the
enterprise, so it lies with that. " But do all organizations
actually realize that? Do they understand what
their opening themselves up to when they are allowing their
employees to deploy agents, and use it to automate their tasks? And I think this is where we
can help with helping people to understand the nuance
in why this is important. What are some of the risks? And so, people can take an
informed decision, as opposed to just blindly following
down the agentic path. >> Right, and I think there is
Christophe Bertrand
>> essentially a correlation
here, in my opinion, between the fact that you need to be able to have trusted data. And so, there's a whole infrastructure conversation around that. The data has to be not corrupted, it has to be compliant, etc. So that's one aspect of the conversation. The other aspect is, the
agents then using the data to make decisions on
behalf of the business or the employees, those agents also have to be compliant in many ways. So I think what you're touching
upon here is literally sort of a snowball effect of responsibility and compliance and trust. You have to trust the data,
you have to trust the agent. So as an employee, should I
trust the agent to go do what a hundred people would do
before for me on my behalf, or the behalf of my company? Which could be a good thing. I'm not saying it's a bad thing. Yes, maybe some jobs will
morph into something else, but it could be very beneficial
to the economy as well. So I think let's not go into
that direction, take that path. I'm just saying, I don't know
if I want to trust someone to do something for me, at times, why would I go trust an
agent to go do something for me necessarily unless
certain things are in place? So I think this training, this
education needs to happen. The other point I want to bring up, and this is a bit of a
roundabout way of getting there, but the truth is, if your agent
is not programmed correctly, and maybe your data is not protected and managed correctly,
you expose your business to significant risk exposures. You could go use data you shouldn't use, you could be using data
unethically, you could be using data that should never be shared,
and that becomes a big issue. And that's a topic, by the way, we'll cover in another
summit focused on governance and compliance and AI. But I just want to point
out that it goes far beyond just the sci-fi view of
what an agent could do. It's actually a real problem today because I think a lot of these questions are not
necessarily being asked. So thank you for helping
with the education. Look, as a final topic,
I'd love to discuss with you is the future,
future of IT professionals, cyber professionals, and AI. Is it a good thing? Is it a bad thing? Is it a bright future?
What should a professional, and we have many viewers
today watching this segment and the session, what should
they be thinking about when they think about AI? Again, friend or foe?
Opportunity? The next best job? Who knows? What do you think?
Javvad Malik
>> I'm an optimist. I think that we have wonderful
opportunities ahead of us. People who are old enough to remember working in offices prior
to getting external email, or even getting internet access
from your desktop required a whole level of different approvals. And at that time, also,
remember, people were so against. "Why are you giving people internet access from their desktop? What are they going to search
for? What's the value in this? There's so much bad
stuff that could happen, or people should already know this stuff. Why are they going to a search
engine to look up information that we hide them to know anyway? " And over time, that just
shifted to like, "Well, hey, this is really useful. " It's more about, do you
know what question to ask, and be able to implement
that in a useful way? And so, I think there's
parallels to that with AI. I think, yes, there are
going to be downsides to it, but I think the positives
outweigh them immensely. And I think even now, we
see people anecdotally in organizations, and even in their personal lives, they've used AI in
certain limited use cases, and it's worked out really well. I think one of the biggest drawbacks of AI or ChatGPT-type conversational AI is it probably doesn't push back enough. It doesn't challenge you enough. And I think that's the biggest
challenge that I'd like to see because this is one
thing we get with humans. Humans are imperfect. If you come up with an idea, they'll never say, "That's great. Let me go and do it for you."
They'll say, "Are you sure? Have you thought this through?"
And I think we need more of that built into AI in the future, and I think that might be
something that we will see. I often liken it to a bit like vinyl. It's like the imperfection, or the crackly sound that
you get with vinyl that shows that it's imperfect, and the sound isn't there
forever, that kind of like where the appeal and charm is. Even though digital music, you can have thousands upon thousands of songs just in your pocket. So I think we'll crave, or we'll need that kind of imperfection, or that humanness built in,
but I think we'll get there. So I think the future is bright. I think we'll have lots of opportunities. It'll improve many jobs and processes, and I think it will open up a whole world of new opportunities as well.
Christophe Bertrand
>> Great. Well, words of wisdom.
Javvad, thank you so much. This was a great conversation. I think, again, there's a lot that I've learned today
from this conversation because, first of all, AI can really help you
protect your infrastructure, protect your data, protect your team, too, and in the sense that they
will make the right decisions, that they will be better trained. So humans are still in the
loop. That's great news. Of course, there are risks, clearly, and as we evolve towards more agentic AI, I think it will be very
important to check back with you to see where we're at. So, Javvad, thank you so
much for your time today. It was a great conversation.
Javvad Malik
>> Thank you so much. It's been a pleasure.
Christophe Bertrand
>> And to our viewers, stay
tuned. There's more coming up. My name is Christophe Bertrand, principal analyst here
at theCUBE Research.