Summary:
Anastassia sits down with Yaron Levi, CISO of Dolby Laboratories and one of the world's most respected security leaders, to unpack the reality of AI-powered cyberattacks: from AI-generated phishing at massive scale to the first documented AI-orchestrated cyber espionage campaign. Yaron explains why the fundamentals of security haven't changed — but the speed and volume of attacks have — and why decades of technical debt are now every organization's soft underbelly.
Yaron has over 20 years of hands-on experience across enterprise security, startups, and the intersection of AI and education. Prior to Dolby, Yaron was CISO of Blue Cross and Blue Shield of Kansas City, Deputy CISO at Cerner Corporation, an Information Security Business Partner at Intuit, and a Security Architect and Product Manager at eBay. He is a Research Fellow of the Cloud Security Alliance (CSA), a graduate of the FBI CISO Academy, a Boardroom Certified Qualified Technology Expert (QTE), and a venture advisor to multiple VCs and security startups.
Key Takeaways:
AI democratizes attack capability with LLMs lowering the bar;
The fundamentals haven't changed: Breach causes remain the same year after year (compromised credentials, misconfigurations, phishing). AI simply finds and exploits them dramatically faster;
Technical debt is the new attack surface with forgotten accounts, stale permissions, and abandoned servers;
Third-party risk needs a rethink. Questionnaires and certifications don't guarantee anything; measuring how much you can trust a partner matters more than measuring what they might be hiding;
Cybersecurity is still a young industry without one common standard. Despite ISO, NIST, and many frameworks, CISO collaboration remains largely informal — community and information sharing are essential;
Start with the business, then threat model and communicate risk with a "pyramid of security needs;" Breaches rarely kill big brands — but can kill small companies. Reputation matters, yet resilience and the ability to recover matter more; repeated, unlearned-from incidents are what truly erode trust;
Advice to vendors: be partners, not sellers;
Data quality is king. Garbage in, garbage out: AI forces organizations to audit what data they have, retire stale data, and sometimes give old data new life;
Optimism for the next generation. Like the cloud wave of 2009–2010, AI will create opportunities we can't yet imagine — it has never been easier to learn, build, and start a company.
Chapters:
00:00 Introduction to AI and Cybersecurity Challenges
03:02 The Dual Nature of AI: Opportunities and Threats
05:15 Evolving Cybersecurity Landscape: The Role of AI
10:23 Addressing Speed and Human Factors in Cybersecurity
13:05 Third-Party Risks in the Age of AI
18:38 Collaboration Among CISOs: A Collective Approach to Security
22:45 Communicating Cybersecurity Risks to Leadership
24:02 Understanding Cybersecurity Needs
26:56 The Pyramid of Security Needs
27:54 The Role of Trust in Cybersecurity
30:29 Advice for Cybersecurity Vendors
34:29 Surprising Trends in Cybersecurity
37:30 The Impact of AI on Data Analysis
40:30 Navigating the Job Market in the Age of AI
Hyperlinks:
Dark Reading author page (articles)
https://www.darkreading.com/author/yaron-levi
Anastassia Lauterbach - LinkedIn
First Public Reading, Romy, Roby and the Secrets of Sleep (1/3)
First Public Reading, Romy, Roby and the Secrets of Sleep (2/3)
First Public Reading, Romy, Roby and the Secrets of Sleep (3/3)
