In this episode of Executive Connect, Amar Singh delivers a hard-hitting perspective on the real-world
applications and limitations of AI in cybersecurity. From the psychological barriers to automation
adoption, to the threats posed by third-party vendors and hostile geographies, Amar offers practical
frameworks for building digital resilience. You’ll hear eye-opening commentary on phishing, password
managers, access control, and the truth about AI buzzwords. Whether you’re a CIO, a security leader, or
just cyber-curious, this episode is a must-listen for understanding both the promise and peril of emerging
tech.
Chapters:
00:00 – Welcome & Introduction
01:00 – The Fear of AI & Automation in Business
03:00 – Top Risks of Using AI in Cybersecurity
05:45 – Education & Human Behaviour in Cybersecurity
08:15 – AI vs. AI: The Battle for Digital Defence
10:45 – Third-Party Risk Management
14:00 – IoT & Innovation: Benefits and Blind Spots
16:30 – Operational Resilience & Earthquake Analogy.
22:00 – Passwords, Passphrases & Password Managers
25:15 – ROI of Cybersecurity: Investment vs. Expense
29:30 – Building a Culture of Cyber Accountability
32:50 – Zero Trust: Buzzword or Backbone?
36:00 – Final Thoughts & Top 3 Takeaways
Melissa Aarskaug (0:1.010)
Welcome to the Executive Connect podcast, where we will explore cutting edge intersection between AI and cybersecurity. Amar will discuss how AI transforms our defense against complex cyber attacks. Whether you’re enhancing your company’s cybersecurity measures or keen on the latest digital safety, Amar’s insights are your guide to navigating today’s dynamic cybersecurity threat
Welcome Amar.
Amar Singh (0:33.568)
Greetings everybody. Melissa, thank you for having me here.
Melissa Aarskaug (0:37.026)
We’re so excited to have you here. I read recently on a Google study that 63% of security professionals believe AI will improve corporate security. From your perspective, how can organizations integrate AI in a way that complements their cybersecurity team strength?
Amar Singh (1:0.488)
Wow, we could be here for several hours. So I’m going to give you sound bites. Even if we keep the age of AI to one side, one of the biggest problems in many organizations, even today, Melissa, is the lack of automation. Now, I say it’s not lack of automation. I say it’s the belief in automation, the fear of automation, right? So AI…
I think is already offering quite a lot, has a lot more to offer, but what may be the biggest roadblock to implementing AI for the benefit of security may be the fear of what AI may do. And to summarize that, the best way to summarize it, the fear of interrupting business, right? If you’re an e-commerce.
business, if you’re high transaction business, if you’re a critical national infrastructure business, right, you don’t want AI switching off the nuclear reactor just because it’s seen something, you know. So I think there are loads of benefits of AI and we’re gonna discuss many other challenges and opportunities, but in summary, I think, organizations need to embrace AI, but that fear of
you know, disruption and interruption by AI is gonna be a massive roadblock.
Melissa Aarskaug (2:35.094)
Yeah, absolutely. I think you touched on it. So, you know, just jumping right into the risks of AI. So from your perspective, are there any like, I know, there’s a lot of risks we hear that are that’s going on right now in the world of cyber security. But from your perspective, and AI are there kind of the top potential risks? And you know, how can companies prepare for some of those risks with using AI tools?
Amar Singh (3:1.864)
Yeah, so I think one of the threat to AI, and this may be a general statement, if I may, I think, but especially in cyber and IT, one of the threats to AI is the lack of available data. Am I making sense? So, you know, chat, GPT and Bard and Copilot all brilliant because they have access to a lot of data that they are learning from.
But now imagine a large organization or a medium-sized organization brings in AI, but they’re only monitoring 25% of what they can monitor, if you see what I mean. So you now have the situation where 75% of their data is not being monitored. And then you add to the recipe, the complication of privacy, maintaining that privacy of an individual, of staff members, of clients.
you add additional pressure on AI not accidentally exposing something, which it might very well do, because we are still quite relatively early days of AI. Am I making sense? So the risk of privacy, the risk of not having sufficient learning data of an organization, because it costs a lot to gather the data and store the data. And then you’ve got the cost of AI
where you need unlimited CPU, you know, to constantly keep learning. I hope I kind of captured some key risks.
Melissa Aarskaug (4:37.638)
Yeah, no, you make a good point. I talk often about education. I think a lot of times in cyber security, a lot of the IT teams I deal with, their job responsibilities used to be very clear, you know, set up computers, put the ink in the printer, set up the desktops, keep the infrastructure up. And I think as cyber security becomes front and center in the world today, AI, you know, layering and AI tools,
I think a lot of times, you know, it’s easy to say, oh, well, this, you know, we had a ransomware attack. It’s this administrative assistant’s fault or it’s this other marketing person’s fault. But I do, you touched a little bit on it. Education, it’s such an important part. Your employees are your first line of defense. They’re the first way in. How do you create a security centric culture where?
everybody in the organization, whether you’re proficient and understand AI tools and cybersecurity, or whether you’re in HR and marketing and cybersecurity is not your forte, how do you create a culture of cybersecurity?
Amar Singh (5:52.236)
How do you educate the human? It’s a bigger question to me. And I think some organizations do it better, but it’s also a human problem, if I may. What I mean by that is your staff member has to meet you halfway. So they’ve got to be entrusted in learning. But one of the key mantras that I give people is one of the key KPIs, the performance, if I may, is can your staff?
identify something malicious. Am I making sense? Right? Fishing, you know, we can be here three years from now and fishing will still most likely be the biggest entry vector for criminals. So I think education is absolutely key. It’s changing the interaction, the ability to automate the gaming, et cetera. I think different cultures have different challenges,
Melissa Aarskaug (6:25.858)
Yep.
Amar Singh (6:52.208)
unless you can determine after all of that education is my staff actually educated, right? You need to be able to determine one key factor which is can my staff identify a malicious content, right? And if you can do that, I think you’re ahead of the game because you can then stand up and say, hello, 75% of my staff are able to clearly identify malicious content.
Melissa Aarskaug (7:23.062)
Yeah, absolutely. I think there’s great cybersecurity learning tools. And I know from my perspective, I used to get phishing emails where it was abundantly clear that they’re phishing emails. Maybe Microsoft was spelled wrong or the logos were wrong, or it wasn’t a complete sentence. You know, fast forward to all these fantastic AI tools that are out there. And now people that, you know, English is not their first language. They can
create a phishing email that is harder to spot. I know I’ve received one recently that looks exactly like me and how I communicate. They had basically taken something I posted on social media, reworded it and sent it over to me. And even I working in cybersecurity regularly, I was shocked at how good it looked and how easy, my first instinct was to think it was real.
Amar Singh (8:20.620)
And if I may build on that, I think where AI today can add a lot of value is in these kinds of, not just for the spammers, if I may, but for us, because AI is adding tremendous value, as you highlight, Melissa, for the average spammer who has to create really good email. They are now, absolutely, as you’ve identified, I’ve seen emails that are absolutely brilliant, right?
in terms of the phishing approach and trying to trick people. But I think on the other side of the fence, organizations should start embracing AI to combat the AI coming in from the other side, if that makes sense. And that’s where you would get tremendous value, but I repeat, we speak to different types of clients, the fear of AI taking over.
Right? The, dare I say, the Terminator Skynet fear, which may be true five years from now, et cetera, but right now, that fear is keeping people away from what AI can absolutely do.
Melissa Aarskaug (9:36.234)
Yeah, absolutely. And I think, you know, we talked a little about education and kind of pivoting a little bit. You know, AI is just a tool, right? People are using the tool and it takes people to use the tool to make them work. Just like cybersecurity tools, people have to run tools to scan environments. And so I think it, you know, I look at it as just another tool for my toolbox and not something to be fearful of.
because people need to use the tools that are in their toolbox and tell the tools what to do. I think also just, you know, kind of switching gears a little bit and talking about third party. Like I’m also fearful from other third parties now and how third party risk management is really crucial in organizations now. So managing their vendors as well. So you could have the great, you know, cybersecurity team. You could have great tools.
your people can be trained, but now there’s third parties that you’re letting into your environment. Can you address a little bit about third party management?
Amar Singh (10:45.988)
That’s a full day. I think the third party risk is going to be probably, has always been and will be and is the biggest Achilles heel, if I may, of any organization. And part of that, again, comes to lack of trust. Organizations saying, OK, here are the documents you want. Don’t worry. Everything’s fine. And you know.
Sadly, the few things that you can do with third parties are contractual clauses, right? Now, in the EU and UK when the GDPR became very popular in the initial days, there was one very interesting clause that was called right to audit that many people managed to put into their new contracts. You know, I would say you should add right to on-site audit. So if you’re dealing with a massive
third party supplier who manages your IT, for example, not just write to audit, but I think you should visit their site to get a feel of who is working there. I think this opens a massive Pandora box because of working from anywhere after the pandemic. Many third parties now have allowed their staff members to work from countries that may not be hostile, sorry, that may be hostile to the West.
And they themselves don’t know because, you know, employee now works from Asia, but now moved to a different country in Asia. How do they track that risk of staff working from hostile countries? So if you add, if you add all of that, and then you rely on the third party coding and your application supporting your AI, you know, data, I think it opens a bigger box to manage than
than has ever existed.
Melissa Aarskaug (12:48.006)
Yeah, and I, great points. GDPR is one of the, you know, a frame, another framework. There’s lots of them in cyber. We’ve gotten this, we have CMMC now that’s come out. We’ve got new PCI standards. There’s a plethora of frameworks to comply with. And if you’re in, you know, healthcare, it’s you have HIPAA compliance and other, there’s other banking compliances. And so I think it’s just a lot now for organizations to say, okay, well, we might adopt this framework, but we also have to.
to pay attention to like you mentioned GDPR or HIPAA compliance. So I think it’s becoming more tricky to navigate and layering on again IoT, Internet of Things. How can companies effectively implement strategies for shifting innovation at IoT, AI? How can they…
Maybe the better question is how can they manage that when you layer technology with organizations that may be on-prem and never used IoT devices?
Amar Singh (14:0.189)
Again, a brilliant question.
Amar Singh (14:4.300)
I think if you look at it from the digital innovation side, embracing IoT, embracing technology is brilliant. But what most people don’t understand, and this may be a problem where many people who are driving digital transformation don’t necessarily understand digital, right? They just want digital, right? And I think COVID did a good thing in a way, it forced a lot of digital transformation.
if that’s one of the good things that did. But right now I think if you want to embrace IoT, you’ve got to ask yourselves, how will IoT destroy my business? Am I making sense? Right? So that’s the same kind of strategy we use when we do tabletop exercises with clients or whatever. How do we destroy your business? If you can figure that out, and then you can work backwards to try to mitigate those risks. So if you’re embracing IoT for whatever reason, that’s brilliant.
if it’s going to help you increase your profits, all of that’s brilliant. But you also at the same time as a risk assessment, say, what’s the worst case scenario? Will it have a devastating impact in my business, on my business? And then try to mitigate that risk to make sure that you can still IOT, but at least you mitigate those risks.
Melissa Aarskaug (15:28.414)
Yeah, absolutely. It made me when you said that it kind of made me chuckle a bit because I know, in industries that I work a lot of times, the marketing departments, which I love marketing, and I love marketing departments, but they’ll have grandiose visions of, you know, kiosks or apps or things they want to implement in the IT departments are like, wait, we need to get involved before we just kind of open things up for you. So I chuckle because, you know, people that are in
you know, the IT as a general term and marketing don’t always see eye to eye with these, like you mentioned, you know, what’s the worst that can happen focus there and then, you know, work backwards. So I think when we look at, you know, cyber threats that are constantly evolving, and they’re constantly changing, which would affect not only your brand, but your IoT devices, you know, everything that encompasses an organization. So I think
You know, emerging threats are always on my mind. I’m always concerned about my own personal life and my bank accounts, my home, my things. So is there, you know, how can companies develop resilience against some of these sophisticated cyber attacks?
Amar Singh (16:46.856)
Yeah, operational resilience, a massive topic. We are kind of specialists in that area. I think the best example, if I may, the biggest natural threat in Japan, I want to pick on Japan as a country. It’s a beautiful place. But the biggest natural threat in Japan is earthquakes, right? Now imagine if you and I lived in Japan and we operated an organization there and we declined any preparation for earthquakes.
Am I making sense? Right? Now, I hope everyone listening in and you agree that would be absolute stupidity, right? Living in Japan, operating in Japan, and saying, nah, what are the chances of an earthquake hitting us? Now, if we take that same logic, if you want to operate in cyberspace, you’re gonna be hit by earthquakes in cyberspace. If you don’t acknowledge that fact,
Melissa Aarskaug (17:18.143)
Yep.
Amar Singh (17:46.316)
Because we do a very, very popular training called Cyber Incident Planning and Response. And we actually do this for clients. One of the biggest learnings, Melissa, is you and I can be sitting here planning for an earthquake. But if you and I and all the other participants don’t believe that we are going to be hit by that earthquake, then the planning session is going to be boring. And it’s not going to be interactive. And the participants are not going to absolutely put their mind to it. So.
whatever people are doing, if they want operational resilience in cyber, because people are very concerned about flooding, you know, building not being available. That’s all humans can, I mean, even non-technical humans can understand, oops, my building will not be available. So I better plan for that. I think when it comes to cyber, many non-technical people and sometimes
Amar Singh (18:44.692)
and non-techies are guilty of I’ve given you one million dollars why should I be attacked right now they’re not going to say that in Japan because they’re going to invest that million dollars but still understand that there will be an earthquake and the building might be saved but they still need to prepare am I making sense right but in cyber unless you wholeheartedly believe that you are wonderful you can’t
do the NIST prepare response, right? Because you believe that nothing shall happen to me if I put enough money in it.
Melissa Aarskaug (19:23.882)
Right. Yeah. Yeah, yeah, absolutely. You also made me think when you were saying that I was with a friend of mine this week and they were saying, I have six credit monitoring subscriptions now because six separate companies that were just attacked had hit them from healthcare to their banking. So
Amar Singh (19:25.621)
Am I making sense?
Melissa Aarskaug (19:48.966)
six of them in a Not less than 90 day period and so I’m thinking from their perspective You know They were they sent this individual an email that said clean up your password. That’s gonna fix it and You know, so I think of all these, you know, it’s a good point But you know, you don’t want to set up shop in a place that’s you know has earthquakes has a lot of these challenges
Um, but you also don’t want to set up shop in a way that you’re not clear. Like you mentioned with what your goals are, right? What are, what are we trying to protect? How are we going to protect it? Um, I also think about, um, you mentioned a little bit about GDPR, like transparency in people’s data. Um, so I’m kind of touching on a lot of different points here, but, um, I think of like my, my data with.
you know, the companies that I do business with personally. And I’m, I’m concerned, right? I’m concerned that yes, I’ve gotten great password hygiene. I’ve got, you know, but they have my data either way, where I live, what my social is, when my birthday is all my, my private data. So no matter how great my password is and how I’m using their mobile app, they still have my information and how, how can I, as a user of these products,
whether it be banking products or healthcare products, how can I as an end consumer feel safe putting in my information into these IoT mobile device apps or websites? How can I feel safe? So from your perspective, maybe the question is, I always, everybody always says robust passwords the way, and I kind of chuckle because it’s not just passwords, it’s
it’s understanding where your data is going and how it’s being used as well. So maybe, I don’t know if you have any thoughts kind of following up with kind of like password protection slash security of people’s information.
Amar Singh (22:4.200)
Wow, this is a really very good question. Again, I think quick takeaways. One, everybody should be using a password manager. That’s, I think, a baseline. Whether you’re technical or not, it doesn’t bother. In my opinion, everyone should have access to a password manager. That’s number one. Number two, the recipe, in my professional opinion, is a very simple recipe for passwords.
difficult to guess. Right? Okay. And the problem with historical password, you know, education was super complex password with 20 characters, ABC123! Who is going to remember that? Right? So in the end, that broke the principle where it was easy to guess and actually difficult to remember the other way around. So…
So for everyone listening in, I think one, you need to get a password manager because the good news, Melissa, as you know, majority of password managers these days are warning users that it’s a weak password, that their password has been breached on, you know, this particular website, et cetera, et cetera. So that is making people more secure because it’s in their face, you know, the password manager.
I’m not going to name any particular brands, but majority of them are informing the user, don’t use this password because it’s too easy to guess, etc. So, it’s difficult to guess, but very easy for someone. And the best way and the best advice today is use three or four passphrases, three or four words as your password. So, you know, if you like Harry Potter books, for example.
or any book that you like to read, remember page 54, paragraph 1, and take five words or three words from that paragraph 1.
Melissa Aarskaug (24:15.070)
That’s a good idea. I think I think I’ll use that more. It’s really great. Really great idea. Minor long, but not that long. So I probably need to tighten them up. One thing I hear a lot in cybersecurity from people I work with are is how expensive cybersecurity is now in all industries in all spaces. And a lot of times people will say, well,
We’re a non-revenue generating department. We’re not like the marketing department that’s doing this or the sales department that’s bringing in business. We’re just IT. So can you help me just from a ROI perspective, how do you talk to your clients from an ROI perspective and looking at cybersecurity as an investment?
versus a cost.
Amar Singh (25:15.352)
Very good question. I think we’ve got to break it down into two buckets, if I may, one is practical security. And then as we discussed earlier, the other is about monitoring detection and response, right? So let’s look at it from the practical angle. I think there is the two frameworks, if I may, one of them is the UK’s framework called Cyber Essentials. It’s a very, very tiny framework of five controls.
The other one I really like is the US, you must have obviously heard about it, the Center for Internet Security. It used to be called SANS 20, but now it’s CIS. And I think there are now 18 controls, right? Now, we work with a lot of clients. And if you look at CIS 18, for the majority of those controls, you can do a lot of good things without significant investment. Am I making sense with that, right? Because one of the fallacies
Melissa Aarskaug (26:12.798)
Yep, absolutely.
Amar Singh (26:16.420)
in techie and non techie minds is if I throw enough money at cyber we won’t be hit by the earthquake, right, which is a fallacy. So if you take a step back, don’t throw any money at what you have but actually take a practical approach similar and I think if I may introduce one sound
Amar Singh (26:44.840)
What does that mean? That means if you can control access, oh access control, right? Who has access to what and who can do what? It may be a boring topic in the grand scheme of next generation, AI, etc., etc. However, majority of advanced criminals, even nation states in most of their attacks require privileged access.
Right now, yes, they require unpatched software. I agree. But if you follow a lifecycle of an attack for the non-technical people listening in and for the techies, if you can control access and limit access, you are significantly at a very low cost increasing your protection. Number one. Number two, everyone’s heard about it, two-factor authentication.
Now, many people will say, yeah, we have switched it on, but they need to ask one question in the organization. If an administrator, Melissa, switched off 2FA, would they know? Seems like a very simple question. And let’s assume the administrator is, he or she or they are, you know, non-malicious, but they may accidentally switch off the two factor.
across the organization because they can’t get their work done. So they may have done it accidentally. It goes back into that question, do you, would you know if someone switched that off? Why am I bringing these two topics here? Because as similar to what you’re saying, for an immediate ROI, right? This practical approach of no access, no hack. And when would you know, or would you know if someone from the administrator side, the system admin, the techie,
switched off to FA, two factor authentication, because they wanted to get the job done. These two can give you without significant investment, significant return, because you are controlling who can do what.
Melissa Aarskaug (29:2.498)
I love it. That’s a really good piece of advice. I love it. That’s spot on. And I absolutely agree. I think, yep, yep. I think that the other thing too, I think low hanging fruit is education. Basic, like what are we clicking on? Like, and just, you know, companies shouldn’t be sending out.
Amar Singh (29:10.668)
I think we’re still recording.
Melissa Aarskaug (29:31.054)
the some of the emails that they’re sending out now, you know, offering free Starbucks or those kinds of things. If you can’t control it and people are clicking on everything, you need to get it like a report card, right? Okay. We did a phishing exercise and we have a hundred employees and 85 of your 100 employees clicked on something. We have a problem, right? If yeah, definitely.
Amar Singh (29:51.892)
Can I add to this, Melissa? Sorry to interrupt you. Here’s another really interesting and important sound bite. Because humans are humans and we are gonna do what you’re saying because I put my hands up, although I am like yourself more paranoid, I may fall for a phishing email. I think the key is, can I admit to you? Can I phone the boss and say, hey boss, I made a mistake?
because I can only do that if I can identify. Am I making sense? So identify and admit is that sound, but I regularly tell my customers, you need to encourage one, your staff needs to be able to, ah, oops, I fell for this. But they also then need to be able to either hit the report button or admit by email or phone saying, hey, boss, you know last Friday I was really tired or I was at the pub.
and I opened an Excel macro that rebooted my laptop. I mean, that’s gold dust, you know, but the question is, are your staff encouraged to own up?
Melissa Aarskaug (31:4.502)
That’s a fantastic point, because you’re right. It made me chuckle again, because I have done that myself or clicked on something. But I think you make a great point. It’s creating a culture where it’s OK to make mistakes because we’re all human, and bringing it forward so we can fix the problem instead of scared and sweeping it under the rug. Because when we do that, that’s when the big problems happen. And
people get into our environment and they sit for days, weeks, months, and they learn what’s going on in our environment, then they make decisions. So I think that’s a really, really good point. I’m sitting here thinking like, what are the top things that are low-hanging fruits for companies that don’t cost anything that they can do? We’ve just given a few of them, right? That they can low-hanging fruit.
creating a culture where they’re able to bring that forward or they’re leveraging a managed security services company where they forward that over. They look at it, contain it, clean it up, make sure nobody else clicked on it, and they investigate it. And I think the sooner that you can have your people feel safe, like you mentioned, to forward, whoops, I made a mistake, the sooner your organization can fix it and get the smart people on the phone to figure out
what happened, if anything.
Amar Singh (32:30.252)
Absolutely.
Melissa Aarskaug (32:32.574)
Yeah, so just a couple final things. I know you mentioned some really good tips and tricks. Anything else from your mind maybe that we haven’t discussed that companies across many different sectors can focus on that’s low hanging fruit from a cybersecurity and AI perspective any closing thoughts?
Amar Singh (32:54.344)
Yeah, absolutely. Related to access control, and I know this term has been used or abused by marketing companies and agencies, zero trust. Right? You don’t, OK, and the problem with zero trust is, again, it’s one of those things, would you challenge someone who has worked at your organization every day for 10 years? In the zero trust culture, you would. Right? Because if that individual didn’t bring his or her
pass they shouldn’t be able to enter the organization as an example you know it’s fairly you don’t need great technology it’s a it’s more of an cultural organizational cultural and human cultural issue but if you can that’s when again and it relates to access control isn’t it because imagine me telling you hey Melissa I just need access to the ad it’s a friday evening you go
I’m going to give him access. Instead of saying, whoa, Friday, why do you need access, Amar? Where is the change control? Blah, blah, blah. It’s that if you can implement it, again, the ROI on this is because it just simply makes it really difficult to then succeed in an attack. I think that’s one of those things. But yeah, the other one is look at CIS 18.
I absolutely love that. A lot of it, a lot of what CIS 18 can be done on the cheap. It’s again more of a can we, are we willing to say, you know, no to someone? Are we willing to tighten access control? Are we willing to remove unwanted apps? For example, Melissa, you know, are we willing to say for corporate people that they cannot install apps without their permission?
It’s this balance of everyone wants to be very digital and modern But then again, everyone, you know at the same time you’ll be asking them to be more restrictive which The dare I say the younger folks may find very irritating But but I think if I may just close this The good the benefit is if someone doesn’t is not allowed to work, you know cnn or bbc from their website
Amar Singh (35:19.213)
Most people have a separate smartphone or tablet that they can use it on. So that again, very simple process of why do you need this website? Go and surf it on your own phone.
Melissa Aarskaug (35:32.374)
Yeah, and you make another really fantastic point is if you’re not sure at the IT department and you don’t know and something seems off, ask and get your employees on the phone. Ask them why are you doing this or why are you putting a USB key at 12 o’clock at night in your computer and offloading all your files? If that’s happening, that’s a problem, right?
and ask the person and maybe the person’s like, hey Amar, I’m presenting next tomorrow, I need to get these PowerPoints on this USB stick because they needed that way. And they’re like, okay, makes sense. But ask, right? Because it could be the other way, they could be doing things, you know, not for the right reasons. And so I think you make a really good point. You know, I always say, you know,
Amar Singh (36:14.825)
Yeah, absolutely.
Melissa Aarskaug (36:26.614)
Trust but verify in the industry is trust your people, but verify when things aren’t up to the sniff test and ask. And at the end of the day, I know I spent a lot of my time in the sales marketing strategy kind of rule. And so I’m not a delivery person in my career, but a lot of times people have asked me, hey, Melissa, what about this? And I’m like, oh, it’s this. But they’ve asked.
And I’ve been able to explain. So I think you nailed it. Ask and wonder. Over.
Amar Singh (37:1.424)
On the AI front, if I may add, I thought one more thing. You know, one of the challenges with AI right now is, and this is not an accusation at any company, but I can, I can confidently say everyone’s now saying their product is AI, you know, right? And it may well not be AI or true AI like Chad GPT or Bard or Co-pilot. Right? So this, this again, then creates this snake oil industry where
As long as you say AI, your product will be sold, but the end user may not actually see the benefit and that itself then reduces the trust on what could be true AI.
Melissa Aarskaug (37:44.862)
Yeah, in AI is the buzzword right now. Everybody’s in AI and even in cybersecurity, everybody’s in cybersecurity in AI right now because they’re the popular topics, the shiny things. And if we’re five years from now, we look back and there’s gonna be a lot of convergence in that space and some will survive, others won’t. I think of it.
you know, similar to the rise of, you know, tech companies and which ones are still standing and which ones are acquiring the others. And so I agree, I think it’s the popular shiny thing now is we’re secure and we’re using AI. So I think everybody’s kind of using that now, but companies like Microsoft, like you mentioned, Copilot and ChatGPT, there’s a lot of companies that are embedding some of these tools into their products. So I think it’s great to use them.
Um, but yeah, you make a good point.
Any final thoughts before we close? I really appreciate you being on Executive Connect. Anything, maybe top three things you want to share with the listeners before we close?
Amar Singh (38:56.200)
Yeah, I mean, I can easily do that. Thank you so much for having me here. I think one, as we said earlier, is access. It’s a very good return on investment and you can do a lot of it on the cheap. Who has access, restrict access. The second point I would say is you have to admit that your organization will be attacked. I know I don’t normally say will, but the likelihood is very high.
So you’ve got to focus on not just protecting or building a wall, but actually how would you detect and respond and recover. So those are kind of things I would say. And like I said, you know, settle yourself on something like CIS 18, for example, and then, you know, very popular international framework and try to map and align yourself. Dare I say, and I know I’m going to go on record here,
The standards are too onerous. I think CIS 18 is probably the best, most, and NIST obviously, but CIS 18 as a control framework, I think for many organizations is very useful.
Melissa Aarskaug (40:4.194)
That’s great. Thank you so much for being here today, Omar. I know you’re a busy man. And that’s the executive connect podcast.
#CyberSecurity #AIinBusiness #DigitalResilience #OperationalResilience #ZeroTrust #ThirdPartyRisk
#CyberAwareness #AIandCyberSecurity #CISControls #DataPrivacy #TechLeadership #CyberCulture
#SecurityByDesign #PhishingProtection #CyberEducation #AItools #InfoSec #RiskManagement
#PasswordHygiene #ExecutiveConnect



A show for the new generation of leaders. Join us as we discover unconventional leadership strategies not traditionally associated with executive roles. Our guests include upper-level C-Suite executives charting new ways to grow their organizations, successful entrepreneurs changing the way the world does business, and experts and thought leaders from fields outside of Corporate America that can bring new insights into leadership, prosperity, and personal growth – all while connecting on a human level. No one has all the answers – but by building a community of open-minded and engaged leaders we hope to give you the tools you need to help you find your own path to success.