The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Expert Insights Podcast
Expert Insights Podcast artwork

#91. Phishing Trends, AI Exploitation, and the Security Curve: Zenith Live Takeaways (Part 2)

Expert Insights Podcast · 2026-07-02 · 28 min

0:00--:--

Key moments - from our scoring

Substance score

56 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber12 / 20
Specificity & Evidence13 / 20
Conversational Craft9 / 20

Deepin Desai, EVP and Chief Security Officer at Zscaler, unpacks findings from the Dirt Lab 2026 phishing and initial access report, challenging the assumption that declining phishing volumes signal reduced risk. He explains that threat actors are shifting to quality-over-quantity tactics, with 95% of phishing now delivered over encrypted channels - rendering organizations without TLS inspection blind to attacks. The report documents 440,000 AI-generated phishing pages created using legitimate services like Vercel, Manas, and Black Box AI, plus emerging threats like indirect prompt injection attacks that manipulate AI agents into becoming malicious insiders. Desai identifies three critical defenses: zero-trust segmentation with deception (highest priority to contain blast radius), phishing-resistant MFA, and continuous training. He also highlights supply chain vulnerabilities - both open-source package poisoning and compromised third-party contractors - as the threats keeping him awake at night. CTO in Residence Martin Ditchburn extends the analysis to EMEA, confirming that phishing trends are consistent globally but complicated by European data sovereignty and compliance frameworks, while noting that half of surveyed decision makers still lack adequate controls despite increased board-level awareness.

Key takeaways

  • →Phishing volume decline signals quality-over-quantity evolution by threat actors using AI to create convincing attacks, not a sign of decreased threat
  • →95% of phishing now delivered over encrypted channels, making TLS inspection mandatory to detect threats and prevent credential exfiltration
  • →AI agents represent a critical vulnerability because they lack human instincts to recognize social engineering and become malicious insiders when compromised
  • →Zero trust architecture with segmentation and deception controls is the highest-priority defense to contain blast radius when users or agents are compromised
  • →Supply chain attacks through open source packages and third-party contractors pose the greatest risk at scale, with downstream impact to entire customer bases

In this episode

  1. 1Phishing Volume Decline: Evolution Over Retreat
  2. 2AI-Powered Phishing and Encrypted Channel Threats
  3. 3Services Sector Surge and Supply Chain Attack Tactics
  4. 4AI Tools Misused for Phishing Portal Creation
  5. 5Agent-to-Agent Phishing and Indirect Prompt Injection Attacks
  6. 6Defending AI Agents and Shadow AI Detection
  7. 7CISO Priorities: Zero Trust, MFA, and Continuous Training
  8. 8European Phishing Trends and Security Maturity Curve

Mentioned

ZscalerDirt LabGoogleGitHubSlackMicrosoft TeamsClaudeOpenAIVercelAWSDeepin DesaiMartin Ditchburn

Guests

Deepin DesaiMartin Ditchburn

Topics in this episode

shadow AIZscalerPrompt injection attacksZero trust architectureTLS inspectionAI phishing agentsPayout Kings ransomware campaignClaude and OpenClaw AI modelsVercel and Manus AI platformsDeepfake voice and video attacks

Questions this episode answers

Why is declining phishing volume not a sign that the threat is decreasing?

Threat actors are using quality-over-quantity tactics, and it only takes one successful phishing attack to compromise an environment unless zero trust is implemented. The decline masks evolution in attack sophistication, particularly the shift to encrypted channels and AI-generated phishing pages that are harder to detect.

What do security teams miss if they don't have TLS inspection in place?

They are blind to phishing attacks delivered over encrypted channels like GitHub, Slack, and cloud services. Without TLS inspection, organizations cannot see phishing pages coming in or detect credentials and secrets leaving their environment, as 95% of phishing activity now uses encrypted delivery.

How are threat actors using legitimate AI tools like Vercel and Manas to enable phishing?

These are legitimate products being misused to create phishing pages in minutes. The report documented 440,000 phishing pages built using AI platforms and hosted on these legitimate SaaS providers' infrastructure, making detection difficult because traffic appears legitimate.

What is indirect prompt injection and how does it threaten AI agents?

Indirect prompt injection is an attack where threat actors craft phishing pages designed to trick AI agents into performing unintended actions - such as financial transactions using stored credentials - that the agent was not originally programmed to execute. Unlike humans who realize they've been phished, compromised agents become malicious insiders.

What is the single highest-priority security control a CISO should implement if they can only choose one this quarter?

Zero trust with segmentation and deception, because it contains the blast radius by assuming users and agents will make mistakes. When adversaries use compromised identities, planted decoys catch them before they cause damage.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

Deepin Desai delivers several genuinely non-obvious points - agent-as-malicious-insider, shadow AI jumping from developer laptops into CI/CD, and indirect prompt injection targeting LLM agents - but the episode is diluted by a second guest (Martin Ditchburn) whose section is largely generic commentary and vendor positioning, pulling overall density down.

Agents, when they fall for phishing, they will become malicious insiders
one of the developer installed OpenClaw and within a week they found OpenClaw instance in their CI CD environment and they had no clue how the agent jumped from developer machine to CICD

Originality

10 / 20

The agent-phishing-agent prediction and the framing of compromised agents as 'malicious insiders who never report it' are fresh and counterintuitive; however, the bulk of the advice (zero trust, MFA, training, segmentation) is recycled standard cybersecurity doctrine, and Martin's section contributes almost no novel thinking.

It's basically a type of attack where the threat actor is able to fish the agent into doing certain tasks that it was not originally programmed to do
the agent phishing agent. It sounds cool, but people are not understanding the gravity of it

Guest Caliber

12 / 20

Deepin Desai is a legitimate senior practitioner (EVP/CSO) who clearly has hands-on threat intelligence and uses real CxO anecdotes, but the inherent vendor bias of a keynote speaker at his own company's conference limits credibility; Martin Ditchburn is a field/sales-adjacent CTO-in-Residence role whose contributions are largely vague market commentary.

in one of the discussions I was having with the CxO, they said one of the developer installed OpenClaw and within a week they found OpenClaw instance in their CI CD environment
if I've done proper segmentation and I have these decoys planted in the environment, when the adversary uses that compromised identity or the asset to do more damage, they will get caught

Specificity & Evidence

13 / 20

The Deepin segment is meaningfully specific - 440,000 AI-generated phishing pages, 95% over TLS, 121,000 throwaway cloud servers, named tools (Manus AI, Vercel, Lovable), named packages (LightLLM, Axios), and named campaigns (Payout Kings) - but Martin's segment is almost entirely free of data points or named examples, which drags the score down.

we saw about 440,000 phishing pages that were created using AI, and they were all leveraging these SaaS, service providers
about 75% of the victim Personas were either in uh, sales, HR and operations

Conversational Craft

9 / 20

The host structures questions logically and threads findings from the threat report into follow-ups, but she consistently validates rather than challenges ('Quality over quantity is a really good way to put it'), never presses on vendor self-interest or conflicting claims, and lets Martin's vague answers pass without probing for specifics.

Quality over quantity is a really good way to put it. Just because there's less of them doesn't mean they're less of a threat.
I guess you can't explain expect the same loyalty from agents

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C41%
  • Speaker B39%
  • Speaker A20%

Most-used words

phishing28organizations17threat15seeing15agents15data15attacks13agent13attack12report11zscaler10security10controls10scale9models9environment8

Episode notes

In the second part of our Zscaler’s Zenith Live coverage, we’re speaking with two more industry experts. Up first is Deepen Desai, EVP and Chief Security Officer at Zscaler, who walks us through the ThreatLabz 2026 Phishing and Initial Access Report, highlighting the key trends that you need to be aware of. That’s followed by Martyn Ditchburn, CTO in residence at Zscaler. He addresses the threat landscape from a European market perspective, looking at how phishing and AI-driven attacks are evolving and where organizations sit on the security maturity curve. This is a public episode, if you’d like to discuss this with other subscribers or gain access to bonus episodes, visit podcasts.expertinsights.com This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit podcasts.expertinsights.com

Full transcript

28 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign

Speaker B: M

Speaker A: welcome to the Expert Insights podcast. I'm Mary McDade, senior reporter here, and over the last week I've been in Vienna attending Zenith Live, Zscaler's annual conference. This week has included a series of keynotes, interviews with cybersecurity professionals, and connecting with innovators and thought leaders from across the world. In this episode, we've included two more guests who spoke with me whilst at the conference. First up, I'll be speaking with Deepin Desai, EVP and Chief Security Officer at Zscaler, followed by Martin Ditchburn, CTO in Residence at zscaler. I spoke with Deepin about Zscaler's security report, Dirt Lab's 2026 phishing and initial access report covering some of the key findings and takeaways. You've said that the volume decline isn't a sign of retreat, it's a sign of evolution in, um, the phishing trends. How do you prove that to a CISO whose board sees fewer blocked phishing emails and assumes that the problem is bear?

Speaker B: Right. So it is very important to educate the, uh, board on this because the, uh, threat landscape is evolving. Quality over quantity is what we're seeing threat actors use. And it will require education for the board members by the ciso that here are all the attacks that are happening. Here is how we're training. Here is how we're leveraging our security controls to prevent it. And the fact that we're seeing a decline in volume is a good thing. But, um, it doesn't mean that the threat has gone away. It's like it just takes one successful phishing attack to take down an environment. Unless you're doing true zero trust. Uh, um, that's how I would talk to my board about it.

Speaker A: Quality over quantity is a really good way to put it. Just because there's less of them doesn't mean they're less of a threat. 95% of phishing activity is now delivered over encrypted channels. What does that mean practically for security teams that don't have, uh, TLS inspection in place?

Speaker B: They're basically blind to those attacks. Because what we're starting to notice is, I mean, this was a trend that was there before as well. But now as the threat actors are using AI, they're using a lot of these AI platforms as well. Like, uh, in the report you will see several vendors named. We saw about 440,000 phishing pages that were created using AI, and they were all leveraging these SaaS, service providers. So they were hosted on their Platform as well we're seeing phishing Attempts, uh, where GitHub is being used, where Slack is being used. So all of these comms are happening over tls and unless you inspect, you will not see the phishing page coming in or even your credentials and secrets that are leaving your environment. That's where again, TLS inspection is must, um, for all stages of attack starting with phishing.

Speaker A: The services sector saw a 65.5 surge in phishing. What is it about billing renewals and support workflows that make them so effective as lures?

Speaker B: Yeah, if, if you saw even in my keynote I covered a uh, Payout Kings ransomware campaign where they were using AI phishing and then Microsoft Teams call where they will pretend to be an IT worker and then the uh, I believe about 75% of the victim Personas were either in uh, sales, HR and operations. And the company that they went after are manufacturing services consumer verticals. Where again the goal over there is if they're able to pop one of these IT services company consumer companies, the downstream supply chain attack that they're able to cause is significant. So it's a downstream impact that they're after, not just a target one. You will see a lot of AI services company also being uh, prone to these type of attacks because if you compromise one AI services company, every client of that services company is essentially uh, under the radar of that attack.

Speaker A: Yeah. So the report, Aziza report names specific AI tools, Manus AI Black box AI lovable AI that were used to build phishing portals in minutes. Are these purpose built criminal tools or legitimate products being misused?

Speaker B: These are all legitimate products being misused, yeah. Ah, Vercel Manas, these are all AI. I think Vercel is probably one of the faster growing one. There are multiple of them. You will see Google aws, those vendors also being abused by them.

Speaker A: The report predicts the AI agents phishing each other in 2026. Is there that we're going to be doing that? Is there a real world example yet or is this still emerging?

Speaker B: Yeah, so we did see one example where. And again this is yet to be seen at scale. But imagine a scenario where you are using Claude, Cowork or openclaw or one of those agents and then you're giving it a task to do certain activity. It will go and search the Internet using your browser session. It will come across a phishing page that was cleverly designed to phish agents. So what, what uh, it will do and you will see it in our report. There is an Example of an indirect prompt injection. It's basically a type of attack where the threat actor is able to fish the agent into doing certain tasks that it was not originally programmed to do. So um, an example I think that was shown in the report is where the page will instruct the agent to perform some financial transactions using original user's credit card or whatever information is present in the browser. It will do it. If it doesn't, if it's card rail doesn't detect that attack. So you will see more and more of this because if you think about it like when a user falls for phishing attack, they will eventually realize, oh, I clicked on it. And they will tell their IT team, hey, I need help. Agents, when they fall for phishing, they will become malicious insiders, uh, as I mentioned, even on the day one briefing. And that's where agents are your weakest link right now. So we will see more and more phishing attacks targeting them.

Speaker A: I guess you can't explain expect the same loyalty from agents. Uh, that leads on quite nicely into my next one. Um, how do you defend an AI agent against social engineering when it doesn't have the instincts that a human has?

Speaker B: Yeah, ah, it's a great question. And that's where you really need to focus on what goes in and what comes out. And you need to focus on the intent of the behavior that you're seeing when it comes to these AI agents. So, uh, you know, uh, three things. One is double down on the guardrails. You need to make sure the core model itself has strong guardrail, but then you also have a guardrail implemented that is outside the LLM. So you have that security control where you're inspecting everything that goes into the model and comes out of the model. That's the intent inspection piece that I mentioned. So someone is trying to fish the model into doing certain things that it's not originally designed to. That prompt should never land the agent. Right. So you need to have that inspection happening outside of the application. And third thing, you know you're going to see a lot of the attacks where the company didn't even knew that the agent existed in their environment. And that was very prevalent when openclaw became a thing. A lot of the employees started trying it on their laptops. And in one of the discussions I was having with the CxO, they said one of the developer installed OpenClaw and within a week they found OpenClaw instance in their CI CD environment and they had no clue how the agent jumped from developer machine to CICD because it's again all about permission that the developer had. Basically what could have happened is the developer had access to CICD environment, the agent probably took an instruction and installed itself over there as well. Uh, so the point I'm trying to make is the shadow AI is going to be another third piece that is very, very important, which you will have to pay attention to because if you don't even know that you have this AI run, phishing attacks are probably too far for you to catch.

Speaker A: Shadow AI has been a big topic of conversation. Three priorities that were highlighted are zero trust with segmentation and deception, phishing resistant, MFA and continuous training. If a CISO can only do one of those this quarter, which moves the needle the most?

Speaker B: And I would, I would, if I were the ciso, I would prioritize on zero trust, segmentation with deception. Because essentially what that allows me to do is uh, contain the blast radius. Essentially I'm making an assumption that one of my user will make a mistake, one of my agent will make a mistake. But if I've done proper segmentation and I have these decoys planted in the environment, when the adversary uses that compromised identity or the asset to do more damage, they will get caught and I will be able to mitigate. So yeah, I would prioritize that if it's only one thing that I can pick.

Speaker A: Makes sense. What's the one finding in this report that you think defenders are most likely to underestimate?

Speaker B: I think the question that you asked like, and it's not a finding, it's more of a prediction. The agent phishing agent. It sounds cool, but people are not understanding the gravity of it. Like when you phish an agent, the impact is humongous. It's the malicious insider impact that I mentioned earlier and I don't see a lot of people talking about it right now.

Speaker A: You said in your keynote this morning that supply chain attacks are what's kind of keeping you up at night right now. Of everything that you track, ransomware, nation state actors, AI threats, what is it that makes supply chain the one that worries you the most?

Speaker B: Yeah, so if you think about it, uh, even in this frontier model, right, I am doing everything I can and so is every organization that has access to those models to harden first party code, applications, environment that I control. But then there is so much open source repositories, libraries that many of these organizations are using that we don't control. If you run these models on that, there are issues in those as well. And threat actors will use those vulnerabilities to target your application, they will also poison those packages, which is evidently being observed in light LLM and Axios and many of the attacks that have happened this year, if you saw which that supply chain attack is impacting not just humans, but also agents downstream. So again, the magnitude of impact from the supply chain attack is just humongous when they're able to pop one of the popular packages. So third party code is where these supply chain attacks will become more and more lethal for global organizations. For that's a code base you don't control. And the second piece I mentioned in the keynote was the third party contractors. So these are firms that you rely on to do certain work for you. Again, the same thing apply to them as well. If they're able to either compromise their environment or insert an employee and which is what we're observing from North Korea and other places, they become part of that contractor workforce. And then you're working with a contracting firm, you're relying on them to do all the vetting and then they're becoming part of your organization. So those are the two channels that I see becoming more and more prevalent as well for attacks.

Speaker A: Some of the phishing, the drop in phishing is down to big takedown operations like Google dismantling the Lighthouse, uh, phishing network. When law enforcement tears these networks down, does it actually set the attackers back or do they just rebuild somewhere else within days?

Speaker B: In my opinion, they just rebuild somewhere else in the way they will change their approach and they will come back, uh, they will take it as an opportunity to do transformation on their end in my opinion. So any of these takedown operations, if they're followed up with arrests, that's where there is real impact because the threat actor itself was arrested. Otherwise these takedown operations will have temporary impact and then they eventually come back.

Speaker A: In the threat labs report under the 2026 predictions, deepfake voice and videos, um, becoming the most effective sector for high impact phishing was predicted. How close is that as a threat and is it a technology problem or more of a training problem?

Speaker B: Yeah, it's actually both. And the reason is many of the attacks that are happening, they will even in the payouts King one that I mentioned, there is an email which is a phishing email that is followed by a phone call or a Microsoft Teams call or a WhatsApp call or a text message. So that second channel again over, they can do deepfake where they will take your CEO's voice or your executive voice from publicly available speeches. And that is hard to correlate and connect and then say that, hey, here is the attack. So the technology problem exists. And that's also where I think you will have to double down on training, where you tell your employees, like, hey, this is happening. And then if they get a, uh, call, they would be more, more, uh, cautious and not fall for it. But yeah, it's still both technology and training problems. Training is something that's in our hand. Technology is something that will continue to evolve. Again, over there, I would again double down on that Zero trust segmentation and, um, deception, because you have to assume one of these attacks are going to be successful.

Speaker A: Attackers now scan companies from over 121,000 throwaway cloud servers. So the old defense of blocking bad IP addresses just no longer works. What actually does stop reconnaissance at that scale?

Speaker B: Great question. So that's actually one of the top recommendations that we have. Like, you need to move your external exposure behind a, uh, zero trust architecture. And Zscaler is one of them. There could be others as well, where your assets are basically dark to the Internet. So you don't have an IP address, you don't have a namespace that these attackers can go after. Now that will mean m, that we become the attack surface. But then it's much harder for them to get through and get to the destination. So reducing that external exposure is the number one recommendation over there. There is no other option. I mean, yes, you can say that, hey, I'll do a great job of patching my assets and make sure it's not vulnerable. But these AI models, as we're seeing the capability, you will always be playing cat and mouse game over there.

Speaker A: Yeah, yeah, absolutely. Thanks to Deepin for taking us through those findings. Next up, we have Martin Ditchburn, CTO in residence at Zscaler. Martin covers the threat landscape from a European market perspective, looking into how phishing and AI driven attacks are evolving and where organizations sit on the security maturity curve. As CTO in residence for emea, you're closer to the European customer base than most. Um, are the phishing trends that Zscaler is seeing globally playing out differently in Europe?

Speaker C: I don't think they are. I think we're certainly seeing a change in quality globally. Um, you know, and a lot of that is to do with the, the efficacy of the, you know, the frontier models and how they're sort of changing that. You know, we're seeing more depth than we are, you know, depth and quality, you know, in terms of speed. But, uh, certainly I'm not seeing that variance that the Trend is pretty consistent. Um, you know, if you are visible on the Internet, you are generally targeted. Um, you know, and there are, there are, you know, clearly some industries that have higher value assets. Uh, so we see increases kind of there, but across the spectrum we're seeing in all geographies and all landscapes really an increase in all sorts of threat vectors, not just the sort of, the fishing side of it.

Speaker A: Similar scale of increase or is fishing

Speaker C: is that, I would say year on year we see all of these, these trends going up. Uh, that is a natural consequence of, you know, everybody's lives being on the Internet and the, the rich source of information that people sort of put out there and companies there and certainly the way we, we interact and do businesses, um, and you know, if you look at things like global supply chain, um, your geopolitical influences, legislative changes, data sovereignty laws, the places where we tend to do business kind of changes and it changes at pace. So what you're sort of seeing is an ever presence on the Internet or through the Internet, you know, through SaaS and all those types of things, but also a combination of having to act fast. So competitive advantage is driving some of the behaviors, um, and lack of guardrails, for the lack of a better sort of term that is kind of pushing up some of the, you know, the effectiveness of these things. But as we know, threat actors find the opportunities where they live.

Speaker B: Right.

Speaker C: So uh, those trends do change and those, you know, those points of interest do change.

Speaker A: Absolutely. Um, excellent. So the threat labs report shows the uk, Germany and India all saw phishing decline by roughly a third. How much of that is coordinated enforcement versus better defenses at the organizational level?

Speaker C: I think boards across organizations are better educated and we are seeing investment in security. It's certainly a top conversation that we see happening at boards. So it isn't a surprise to us that we see, um, you know, organizations being better equipped. But I think, you know, we ran a, um, you know, a view of some of our own sort of decision makers globally and you know, still about half of those felt that they didn't have the adequate controls to, you know, um, to deal with the modern challenges in terms of, you know, security threats. So you're right. You know, we are seeing variances in terms of some attack vectors, but in truth those are just changing in terms of nature.

Speaker B: Right.

Speaker C: So we're just seeing different types of threats coming, you know, coming at organizations. Uh, but there's certainly an increase in education, visibility and certainly conversations at board level at perhaps, you know, levels we've never seen before. And I think if you look at conversations driven by certain news events with Frontier Models, there's a lot of anxiety out there. Um, that's kind of driving, you know, an interest, uh, in the right places, I think.

Speaker A: Yeah, absolutely.

Speaker C: I think the way we see it unfold, there are organizations who are burying their heads in the sand. They don't have the interest around Frontier models as an example or the latest kind of threats. Others have really great interest at the lower levels, you know, particularly the IT organization who are trying to bubble this up and the boards aren't listening. Other organizations, the boards are interested and they are listening, but the programs don't exist. In order to kind of step, uh, through quantifying where the investment needs to be made. And that's the challenge and also the opportunity of where we sort of find ourselves is where organizations on that scale, how do we bring it to life and how do we make it true to life so that those real risks are understood and targeted effectively? Because I think we, you know, if you're trying to do all controls all at once, organizations would probably struggle.

Speaker A: Yeah.

Speaker C: So we do make sure that, you know, as we step through these things, that we're being very pragmatic, we're recognizing the time it takes and of course, you know, the most effective controls at the right point.

Speaker A: Yeah, absolutely. And not causing too much friction and frustration for people. That's another big concern. European organizations are dealing with compliance alongside the AI shift. How do you see Zero Trust fitting into that regulatory picture?

Speaker C: So the frameworks themselves are designed to be technology agnostic. They're more sort of controlled. Um, Zero Trust is very effective as an architectural pivot because we displace some of those native inherent problems around direct line of sight. We deal with more of the, uh, we displace the VPN connectivity challenge in favor of, uh, m different architectures and different ways of doing it. So in actual fact, we find ourselves very easy to lean into those kind of standards because we've been thinking that way for, you know, for a period of time. And those controls and those outcomes is what we look at. I think one of the things that ZSCALE has done very well over the years is, you know, we're very much connectivity agnostic.

Speaker B: Right.

Speaker C: We can act as an overlay on all sorts of mediums. So in that regard, we don't mind whether customers are traditional connectivity or, you know, sd, WAN type connectivity. Of course we can displace those things if they choose, but we can operate wherever the user happens to be. Uh, Wherever their data happens to be and where their apps happens to be on whatever medium. And I think that's the power of where we kind of sit, which is why we kind of span those frameworks pretty well. The other side of it is that the architecture being in line means that we collect a lot of data points. So for organizations we're becoming a great source of demonstrating the effectiveness of controls so that as they apply these, um, the frameworks to them, they can actually be confident in what their current level is.

Speaker A: Mhm. Excellent. What's the conversation you're having most often with European CISOs right now that you weren't having say around a year ago?

Speaker C: We find it falls into three buckets. Um, there's certainly conversations around, uh, resilience and sovereignty. We have conversations around the B2B supply chain and some of those have been brought about by things that are very well advertised in the news media. And then we see of course, trends such as AI being a hot topic. So those are the three buckets we tend to see, you know, um, organizations globally, not just emea, but those are the things that we talk about. It does take an interesting flavor because you know, EMEA has different data requirements processing, uh, competitive advantage kind of laws. So we see nuances, you know, of those kind of things, and certainly an EMEA flavor, but um, the topics generally are very similar.

Speaker A: So you've written that security has to evolve faster than innovation with agentic AI. Where are enterprises getting that balance right and where are they getting it wrong?

Speaker C: Organizations are using AI to gain competitive advantage and they're turning their attention towards high value data sets in order to do that. Where Zscaler is really good at is that, you know, the architecture lends itself well to those data points. And turning those data points into meaningful information is something we can do very well. Importantly, we can do it at scale, you know, because you know, Zscaler is a hyperscaler in its own, you know, in, in the security sphere, the volumes of traffic, you kind of saw the keynote that, you know, 750 billion transactions per day. And I think this is where organizations, um, will, will struggle with more traditional approaches because hardware appliances can't scale to those sort of things. When we talk about innovation and speed, it is true you need to stay on top of the trends and all those types of things, but also being able to handle those large volumes of data. And that's something that we've been doing for many years. The number of data centers that we have our ability to kind of scale in billions or trillions of transactions as it kind of will be, means that whatever that threat orientation, whatever the emphasis, whichever speed an organization wants to go for competitive advantage, we can meet it.

Speaker A: Excellent. So good quote. Um, if you can be reached, you can be breached.

Speaker B: Yeah.

Speaker C: If you reach it, you can breach it.

Speaker A: Yeah. Great line. And that's kind of Zscaler line. I've got a conference. How does that change when the thing being reached is an autonomous agent and not a user?

Speaker C: So the things that we see around autonomous. Autonomous agents is that they act at speed and they can exploit multiple pathways simultaneously. So when we talk about scale, that's a very effective and important part of dealing with autonomous agents. In many ways, they have quite a lot of the hallmarks of being a user. They have a purpose, they have an established baseline. Um, you expect them to do certain things. They will access certain business systems. And, you know, ZSCALE has been in that business, you know, with users implementing segmentation, for example, or, uh, data inspection. What we're doing is we're just applying that to a new lens. Right. So we're just talking about doing it at something at a greater speed and a greater depth. But a lot of the hallmarks of compromise, uh, are very similar.

Speaker A: Interesting. I was. I've had a few conversations along those lines, and I was wondering, um, whether you would say that agents or users are. Which one you say is more unpredictable. That's been something that I've spoken to people for years is humans are unpredictable. Their behaviors are very hard to anticipate. So are agents m. Less. Is that less of an issue with them or is it more because they. They don't. You can't really dig into any psychology

Speaker C: there, I think, in terms of, um, speed. Agents always have it, for sure. And they don't sleep. So if you give an agent a task, it'll just hammer away until it completes that task. Or, um, you know, you ask it kind of stop. And humans aren't like that. So I think the unpredictability probably isn't as important as actually the effectiveness and direction of it. Um, and those things will sort of change over time as, you know, as other models come online, as other harnesses come along, that's going to kind of change over time. But, you know, there's very pragmatic things that we advise to organizations. So one is remove the shadow component. Be aware of what you have. Add the segmentation, the fine game controls, the guardrails, to make sure that those agents, and even humans, by the way.

Speaker A: Right.

Speaker C: It's the same controls can't access systems, systems that they're not supposed to or deviate off the norm. We implement that blast radius. Um, and then the last one is review the behavior. These, you know, humans and agents have a typical role or a thing that they're doing, a task they're trying to do. And of course, if they start to deviate from that, that's a really good indicator of a problem. So understanding what they're supposed to and monitoring the deviances is quite important. And for everything else, yeah, there's quite a nice, uh, catch all, which is we've been talking a lot about the effectiveness of controls, such as deception and decoys, which has really taken a front seat when it comes to, um, AI related threats. Because one of the things that AI is really good at is consuming data and living off the data. So the more data you throw at it, the more expensive it is for those kind of threats to happen. So we're seeing an evolution of controls, but the grounding is what we've learned through users, which is, you know, why we feel really equipped to kind of scale and deal with it.

Speaker A: Yeah, makes sense. Are European enterprises adopting AI faster or more cautiously than their U.S. peers? And is regulations like NIS 2 DORA and the AI act, uh, a break in the car or a help?

Speaker C: Uh, from my experience, for me, that's yet to be proven in kind of number form. But I would say that everybody is inquisitive and everybody is turning models, you know, to gain this competitive advantage, but they are having to observe different regulatory frameworks. You know, there are differences obviously between Europe and, you know, the rest of the world that may be giving a rise of caution. I think, you know, um, the European Union has a very specific view on it, and I think nobody wants to eat away at that competitive edge. But at the same time, we do want to make sure that, you know, data sovereignty is observed, that the rights of kind of Europeans are kind of well respected. And that is kind of choosing, I guess, giving some organizations pause for thought about what models they use, where they come from, whether they invest something more locally, where that data flows to. Um, so I would say that the appetite is not any different just from my own personal conversations. Um, but the challenges of adopting it in a European way is different. Yeah, it's certainly different.

Speaker A: Yeah, that makes sense. Thank you, Martin, for speaking with me. That's all. From our roundup of Zenith Live. Head over to expertinsights.com for more exclusive interviews, cybersecurity news stories, and our shortlist of the best platforms out there.

Speaker C: You're listening to the Expert Insights podcast, home of leading cybersecurity conversations. Subscribe now to get insights from top cybersecurity leaders straight to your inbox.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Shadow AI: 7 Out of 10 Workers Use AI Their Company Can’t See | Ravi Soin, CISO SmartsheetCXO Spotlight · on shadow AI87 / 100
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ GongSecurity & GRC Decoded · on Zero trust architecture86 / 100
  • Edge AI Security: Why Secure-by-Design Engineering MattersEmbedded Insiders · on Zero trust architecture79 / 100
  • AI and Cybersecurity in SMBs: Insights from Bruno LecoqSecuring the Realm · on Zero trust architecture79 / 100
  • Autonomous Agents Need a Verified Identity with Rosalyn CuratoTo The Point - Cybersecurity · on Prompt injection attacks78 / 100
  • 32 - When AI Attacks - Part 2Cyber Compliance & Beyond · on shadow AI78 / 100

More from Expert Insights Podcast

All episodes →
  • #90. AI Agents, Zero Trust & Quantum Threats: Zenith Live Takeaways (Part 1)
  • #89. AI Is Superpowering Phishing: How Can We Fight Back?
  • #88. AI vs AI at RSAC: What 8 Security Leaders Really Think
  • #87. How AI Agents Are Reshaping Security Operations
  • #86. Why Secrets Sprawl Is One Of The Biggest Hidden Risks In Cybersecurity
Explore the best B2B Engineering & DevTools podcasts →
All Expert Insights Podcast episodes →