92: When AI Attacks: Inside the Mind of a CISO with Yaron Levi
Episode Details

Summary:

Anastassia sits down with Yaron Levi, CISO of Dolby Laboratories and one of the world's most respected security leaders, to unpack the reality of AI-powered cyberattacks: from AI-generated phishing at massive scale to the first documented AI-orchestrated cyber espionage campaign. Yaron explains why the fundamentals of security haven't changed — but the speed and volume of attacks have — and why decades of technical debt are now every organization's soft underbelly.

Yaron has over 20 years of hands-on experience across enterprise security, startups, and the intersection of AI and education. Prior to Dolby, Yaron was CISO of Blue Cross and Blue Shield of Kansas City, Deputy CISO at Cerner Corporation, an Information Security Business Partner at Intuit, and a Security Architect and Product Manager at eBay. He is a Research Fellow of the Cloud Security Alliance (CSA), a graduate of the FBI CISO Academy, a Boardroom Certified Qualified Technology Expert (QTE), and a venture advisor to multiple VCs and security startups.


Key Takeaways:

AI democratizes attack capability with LLMs lowering the bar;

The fundamentals haven't changed: Breach causes remain the same year after year (compromised credentials, misconfigurations, phishing). AI simply finds and exploits them dramatically faster;

Technical debt is the new attack surface with forgotten accounts, stale permissions, and abandoned servers;

Third-party risk needs a rethink. Questionnaires and certifications don't guarantee anything; measuring how much you can trust a partner matters more than measuring what they might be hiding;

Cybersecurity is still a young industry without one common standard. Despite ISO, NIST, and many frameworks, CISO collaboration remains largely informal — community and information sharing are essential;

Start with the business, then threat model and communicate risk with a "pyramid of security needs;" Breaches rarely kill big brands — but can kill small companies. Reputation matters, yet resilience and the ability to recover matter more; repeated, unlearned-from incidents are what truly erode trust;

Advice to vendors: be partners, not sellers;

Data quality is king. Garbage in, garbage out: AI forces organizations to audit what data they have, retire stale data, and sometimes give old data new life;

Optimism for the next generation. Like the cloud wave of 2009–2010, AI will create opportunities we can't yet imagine — it has never been easier to learn, build, and start a company.


Chapters:

00:00 Introduction to AI and Cybersecurity Challenges

03:02 The Dual Nature of AI: Opportunities and Threats

05:15 Evolving Cybersecurity Landscape: The Role of AI

10:23 Addressing Speed and Human Factors in Cybersecurity

13:05 Third-Party Risks in the Age of AI

18:38 Collaboration Among CISOs: A Collective Approach to Security

22:45 Communicating Cybersecurity Risks to Leadership

24:02 Understanding Cybersecurity Needs

26:56 The Pyramid of Security Needs

27:54 The Role of Trust in Cybersecurity

30:29 Advice for Cybersecurity Vendors

34:29 Surprising Trends in Cybersecurity

37:30 The Impact of AI on Data Analysis

40:30 Navigating the Job Market in the Age of AI


Hyperlinks:

LinkedIn Yaron Levi

X / Twitter Yaron Levi

Dark Reading author page (articles)

https://www.darkreading.com/author/yaron-levi

Anastassia Lauterbach - LinkedIn

First Public Reading, Romy, Roby and the Secrets of Sleep (1/3) 

First Public Reading, Romy, Roby and the Secrets of Sleep (2/3) 

First Public Reading, Romy, Roby and the Secrets of Sleep (3/3) 

AI Snacks with Romy and Roby

@romyandroby 

“Leading Through Disruption”

AI Edutainment

The AI Imperative Book

Romy & Roby Book

Episode cover art for 92: When AI Attacks: Inside the Mind of a CISO with Yaron Levi
00:00
30:00