
The Alldus Podcast - AI in Action · 2026-06-29 · 24 min
Key moments - from our scoring
Substance score
52 / 100
Five dimensions, 20 points each
Simon Collins brings a rare combination of perspectives to AI-driven cybersecurity challenges, having worked in forensics, e-discovery, consulting, and now in-house at Allianz Global Investors. Rather than treating frontier AI models as apocalyptic, Collins frames them as a meaningful but manageable step change in the attack surface. The core issue isn't that defenders need to start over - it's that they must become excellent at fundamentals while adopting new defensive AI capabilities. His framework emphasizes three critical areas: dramatically accelerating patching cycles from the current 55-day average to 15-20 days; scanning and remediating all code vulnerabilities (including medium-severity ones previously deprioritized); and deploying AI agents that can identify, exploit, and even automatically remediate code vulnerabilities. Collins also highlights the overlooked resilience challenge: AI fails differently than traditional IT. A system that slowly makes poor decisions may go undetected, flowing bad decisions through the entire business. He advocates treating critical AI systems like key-person risks, documenting fallbacks and ensuring knowledge isn't lost as senior experts retire without developing junior talent. The discussion ranges from kill chain defense-in-depth strategies to practical adoption challenges in legacy organizations, culminating in his view that personal AI literacy is essential before scaling enterprise deployment.
Frontier AI models can find vulnerabilities, write exploits, chain multiple vulnerabilities together, and execute attacks at significantly faster pace than before - sometimes within hours or days rather than weeks - but this still represents one step in the 10-step kill chain, with eight remaining defensive layers available.
The current industry average is approximately 55 days; Collins advocates reducing this to 15-20 days to stay ahead of AI-driven vulnerability exploitation.
Organizations should focus on: accelerating patching cycles for vendor software, scanning and remediating all internally-developed code using AI tools, and deploying AI agents for 24/7 security operations center defense and alert triage.
AI fails silently differently than traditional IT - a system making poor decisions undetected can flow bad outcomes through the entire business lifecycle without obvious alerts, requiring documented fallbacks and key-person risk planning similar to human expert dependencies.
Without junior developers growing into senior roles, organizations lose the expertise needed to oversee, supervise, and manage AI systems; knowledge and skill transfer must continue even as AI augments development work.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a handful of genuinely useful practitioner framings - the kill-chain minimisation argument, the silent-failure risk of AI, and the 'must be excellent at basics' imperative - but a substantial portion of the runtime is spent explaining foundational cybersecurity concepts (phishing, zero-days, patching) at a near-introductory level, diluting overall density.
before we had to be good at the basics now we must be excellent at the basics
AI fails differently than normal IT. If the online website stops working, you can't log in. It's obvious. But what happens if the AI fails by slowly making poor decisions? That doesn't get noticed.
The 'key person risk' analogy for AI resilience and the observation that silent AI degradation is harder to detect than obvious IT outages are genuinely fresh framings; however, the broader narrative (arms race, defence-in-depth, patch faster) recycles widely-circulated security talking points without adding a distinctive new lens.
we should think of AI the same way as we think of a key person risk
we won't need junior developers we'll only need senior ones but what happens when the senior ones hopefully grow old and retire how how do we get new senior developers
Simon Collins is a genuine practitioner - DORA programme lead, expert forensic witness, and Head of Security & Resilience at a major global asset manager - giving him real operational credibility; the episode would score higher if he had revealed more scale-specific or uniquely hard-won insights rather than spending significant time on conceptual explainers.
I led our dora efforts for three years
I've had that twice in my last eight years. It's very rare. I suspect that's going to happen a lot more.
A few concrete numbers land well (55-day mean patch time, 15-20 day target, the Middle East flight-routing agent anecdote), but many claims float at abstraction - the '30 to 600 times more productive' range is enormous and goes unexplained, and named vendors, CVEs, or budget figures are absent throughout.
the average I read the other day was 55 days is the mean time to patch for vulnerabilities. That needs to be down to closer to 15 or 20.
i regularly talk to people who are software developers who are 30 to 600 times more productive
The host's questions are almost entirely open-ended scene-setters ('is this a new threat landscape,' 'what can be done about this') with no meaningful push-back; the implausibly wide '30 - 600x productivity' claim and the vague 'three and a half areas' structure both pass without a single probing follow-up, leaving the conversation as a largely uninterrupted monologue.
is this a new threat landscape is this something we've seen before is it just fancy marketing
what can be done about this and is this like one cleanup exercise where you clean it up you're done or is this kind of going to be ongoing
Computed from the transcript - who did the talking, and the words that came up most.
Today's guest is Simon Collins, Managing Director, Head of Security & Resilience (CISO) at Allianz Global Investors . Founded in 1998, Allianz Global Investors is a leading active investment manager. As part of the Allianz Group, the firm provides investment solutions across equities, fixed income, multi-asset and private markets for institutional and retail clients worldwide. Through research-driven strategies, a commitment to sustainability and global expertise, they helps clients achieve their long-term investment objectives. Simon is an experienced cybersecurity and operational resilience leader with more than 25 years in IT, specializing in information security, cybercrime investigation, fraud prevention, and cyber resilience. He has worked with organizations, boards and regulators to strengthen security frameworks and drive industry standards. Passionate about collaboration and knowledge-sharing, Simon regularly engages with cross-industry groups and conferences to promote best practices in cybersecurity and resilience.
Transcribed and scored by The B2B Podcast Index.
The Aldis Podcast is brought to you by Aldis International, supplying your expert AI and digital transformation staffing needs across the US and Europe. Today, you are listening to our AI in Action series, where leading minds in AI from across the world share their story, success, and advice. AI in Action cuts through the hype and explores the true impact of artificial intelligence in our world today. Welcome to another All This Podcast.
I've got Simon Collins, who's Head of Security and Resilience at Allianz Global Investors. Simon, thanks very much for coming to the podcast today. Thanks for having me. Simon, for people that don't know yourself or haven't heard about your experience, Would you mind giving us a brief overview about your world in the world of AI, cyber, governance, risk, all those different things and the different roles you've had?
Yeah, so I started in IT quite a long time ago with a guy called Larry from Wicklow running cables and the whole way up through school and college. I started in transition year and lots of different hands on IT roles. Then moved across to more of a security role in consulting for several years and really focused on investigations, forensics, dealing with people when things went wrong. So did a lot of work in the e-discovery world in the early stages, did practice guides, international standards, and then pivoted to working in cybersecurity, again, consulting, where you're trying to help people not get in trouble in the first place.
And then after a few years there, I decided to jump into a role, a more in-house role, to help really build out security and resilience capability where I am now. when you think about going back did that really shape the role that you're in now in terms of having such a broad understanding from a variety of different angles you've worked in regular organizations consulting firms you've had these different kind of fingers in different types of pies yeah i think it helps gives you a good perspective i think what's quite useful i think probably the skill that i brought up all along might be a test of it today was explaining complicated technical issues.
That started when you're being cross-examined for the first time in court as an expert witness. You really have to explain. I remember sitting there in a panel and saying to the judge, have you searched with Google before? And he said, I don't have a computer.
And I said, how do you explain this using analogy of a library and books that deleted and how you can recover all this type of stuff? So that ability to explain and storytell in a way, while still sticking to the facts, because you're also dealing with highly technical people as well, who if you story tell too much, they can say, no, that's actually not a great analogy. So I think that really helped. I think when you get into then the commercial world of having that experience, I was able to explain a lot of these risk concepts to senior stakeholders where you're looking at pretty big ticket investments to solve these problems.
And I had a manager before said, it doesn't make the boat go any faster, Simon, yet we have to spend it. you're saying yeah but if we hit an iceberg we'll survive so you're you're really trying to use different storytelling and analogies to bring the messages across but really ground it in i think what i think a lot of people that i talk to nowadays particularly if we're looking to purchase a service or a product i go exactly how does that work right down to the code please i want to understand so it's trying to bridging that gap and where i am now i'm i find i'm starting to we have teams of great people who really get into the technical details and i love being able to dip back into it but i spend more time obviously explaining things now and managing than the detail but i still get to do it from time to time which is good fun we're in this kind of interesting world where we've got frontier ai models that are so powerful sometimes you can't even get access to depending on who you speak to in the world is this a new threat landscape is this something we've seen before is it just fancy marketing it's interesting you say that so you go between the fancy marketing it's no big deal and on the other side doomsday everything is gone we have to start again yeah and i was reflecting as i was traveling here like a big part of my job is to like if you're running a crisis and you're dealing with these type of things and it's like i deal with the physical security side of things as well we won't touch on that today but sometimes it is literally life and death not very often thankfully so you have to be calm you have to be balanced so in this it's somewhere in between the way i describe it and we can get into a bit detail on what it is but i'd look at it as for most organizations who are relatively well set up and weathering the storms that we've had normal cyber attackers the last several years mostly regulatory compliant this is an adaption or a step change in responding to a defense or responding to a new type of attack it's not starting again so the way we look at it is that you've got a new type of phishing email they used to put the words in an email and text then they put the words in an image that they put in the email and we had to adjust our tools to adapt to those new type of technical attacks this is bigger than that but we don't need to start again so and i think that's it's trying to having that calm balanced view in the middle of saying what we need to do yeah because you get the opinion you do need to start again with the way it's labeled and how everything's dramatically changed as well and the basics aren't no longer the basics yeah maybe if we see i think i would have a different view because where we look at it if we maybe frame this specific like with the frontier models and particularly around exploiting vulnerabilities i explain what vulnerabilities maybe for a bit of background at a moment however exploiting a vulnerability is the first step in an attack life cycle yeah and most in the industry we map it along a 10 kill chain it called because if you kill the attack at any step along the way, the earlier you kill it, the better.
Typically, what we're talking about here is these models that can exploit vulnerabilities much faster than before. It's typically step one. We've still got nine more steps. and we have you hear defense in depth layered controls we've layers of controls at every step along the way so yes one and people might say one two or three but a subset of the overall picture has changed yeah but let's not throw out all the other good stuff that we have there yeah the fact that if we think of it and maybe it might be helpful to explain vulnerabilities vulnerability being a weakness in a people process or technology that if it's exploited leads to unintended consequences yeah look when we're talking cyber attackers we're talking about the bad guys so that means like stealing data getting access to a system and shutting it down so prevent us from doing business so nice simple vulnerability is phishing email human vulnerability we convince you to click the link yep you click the link the bad guys get access to your computer we tackle that by training in awareness, fishing exercises that you know, don't click the link.
Lots of technical stuff in the background that stops it getting to you in the first place. And if you do click the link, we can block it as well. But those are the types of human vulnerabilities we're talking about. So for these frontier AI models, they're particularly good at exploiting technical vulnerabilities.
Now, technical vulnerabilities are essentially in every piece of software code ever written. They're only an issue when someone finds them. And actually, they're only an issue if someone finds them and someone exploits them. So what typically happens is that a software vendor, commercial vendor, releases a piece of software.
On day one, they believe it's perfectly good and secure. They've done their testing. Security researchers, and there's two types of them. So typically, I'll call it the good security researchers.
They go out and they test the software and they find ways to break into it. They find a vulnerability and they find a way to get into the system. they tell the software provider who pays them a fee that's how they make their money so we call them good security researchers software provider produces a patch and the first thing we know that there's a problem with the software is that there's a patch available and so we find out on the same day as the bad guys do so while we're racing to apply the patch they're racing to reverse engineer the patch to understand why it exists what vulnerability it's fixing yeah and how they can then exploit that vulnerability and that typically takes 30 60 90 days yeah so we we have time to patch before it is like exploitable they say in the wild that anyone could get a software tool and hack in so that's why we have time and every organization has a routine patching cycle the patch every month for the majority that's fine you have the other situation where the not so friendly researchers find the vulnerability and they sell it to some bad guys who start using it so the first we find out about a vulnerability they call it a zero day which is often a misused term the zero day is really what it's saying is that it's been exploited out there usually by a small number of very sophisticated nation state attackers because to get the vulnerability that nobody knows about you've got to pay and you've got to pay big typically in the millions so your average cyber criminal doesn't have this but it's been exploited and it's typically using very high value targets what happens then is that we find out about it we have zero days to batch it because we're already exposed it's already out there so that whole vulnerability life cycle is something that happens very routinely it's a huge organization thing and your iphone tells you patch it in the background if you've got 20 000 hosts that you need to patch you're patching continuously the step change and i think that's the argument as to how big a step change it is that when you have one of these AI models, they're really good at preparing speeches.
They're really good at fixing your PowerPoint, creating content. They're really good at coding. And you can use natural language, say, hey, write me code to fix this website or to do this. The big step change now is that they're also good at finding vulnerabilities, writing exploits for those vulnerabilities and running them and sometimes they'll chain three or four vulnerabilities together to actually get from step step step to actually get right into the system and that's what's coming out now that's what's coming down the line but they're still it's still exploiting vulnerability at speed at pace yeah but that's what's different about them and that's why it has people quite worried you are listening to the Aldis podcast when you're looking to scale your team or if you are interested in showcasing your company in a future episode reach out today or if you're in the market for a new role visit our website to view open positions www.
aldis.com it did feel significant for so many different types of people are talking about leaders and things like that as well which i think is great for the security industry in general just to actually kind of a kind of a kind of wider awareness what can be done about this and is this like one cleanup exercise where you clean it up you're done or is this kind of going to be ongoing so it's both what can be done and the way i think most organizations that obviously i connect with all of our peers trying to figure out what's going on making sure everyone's we're at least on the right track and the general consensus seems to be is that there is that cleanup exercise the way I describe it is that before we had to be good at the basics now we must be excellent at the basics So that falls into kind of three and a half things that I think need to be done.
One is patching. So the majority of software most companies use is provided by commercial vendors. You name all the big names, you know them. they are currently getting early access to these tools they're running them they're finding vulnerabilities and they will have in the coming weeks and months and my prediction is the rest of this year into next year floods of patches and some of those patches will be for some very serious vulnerabilities so you might in extreme cases go we need to turn off the system off the internet because it's too dangerous to leave it there until we can patch it yeah i've had that twice in my last eight years.
It's very rare. I suspect that's going to happen a lot more. So what we have to do is that we have to be absolutely brilliant at patching fast. I think the average I read the other day was 55 days is the mean time to patch for vulnerabilities.
That needs to be down to closer to 15 or 20. Really efficient. So I think a lot of organisations now are saying, how can we patch faster when our commercial vendors give us patches? And what risks are willing to take maybe we can break things from time to time the second piece so that's something we already do we just got to get better the second piece that we already do and i say we generally the industry these are the basics is code we develop ourselves the software code so no external vendors are going to give us patches for that because it's ours we wrote it so we need to go and make sure all of that code is centrally managed in these repositories and that use software scanning tools.
Use the scanning tools, close all the vulnerabilities you have, clean any backlogs, even the medium stuff that you didn't think was important before, clear the decks and clear the decks for the storm before it comes. So make sure you're doing all of those basics right. Things like a lot of organizations would say, well, we're going to block software going into production that has critical and high vulnerabilities, but we might let medium ones through. Don't let medium through anymore.
Block them as well. Get really good at the basics. So that's the stuff that we're doing. That's the just get faster and better what we're already doing, a bit more focus on it.
Where it gets into a bit more of the step change is on, maybe if we stick with the software, self-developed code for a moment, we need to get these AI tools. So yes, they're being given in these different projects to some of the big vendors, but when they're available for us, we need to get them and run them on our code and use them. And what's really interesting about some of the capability, and some of it's already there, whereby it can find the vulnerability, it can write the exploit, it can write the remediation code, it can fix the vulnerability, and it can put it into your testing environment and say, hey, I found this problem, I fixed it, run through your testing and put it into production.
in some organizations that aren't highly regulated they might go do you know what it's actually better than us so we'll let it just put it into production because the consequences of it getting wrong is no big deal we can roll it back so let's not wait till the developer wakes up the next morning lets them wake up and go hey i fixed your code overnight and it's in production so i think adopting those tools at scale and getting that's more of a step change for people to really get into mindset we're going to allow this to because this really feels like a brave new like this is a new world right to an extent we already have for several years now ai that can write code hundreds and thousands of people using it so i say it's a step change not fundamentally now a lot of people aren't using it yeah they need to do you know what i mean by that actually it's an awareness yeah to say because i regularly talk to people who are software developers who are 30 to 600 times more productive they talk about their coding and programming but i also remind them to say that you're actually only spending 20 of your day doing those different tasks you still have to do everything else which you aren't x amount more productive but still a significant amount of software developers or people aren't actually using these tools in their day-to-day work yeah yeah and if you get like big organizations that have been around for a long time using older systems older types of code and it might be the same developers for 10 20 30 years maintaining that system like that's a big ask to get them to adopt these new tools and change so i think that's really key i think they will have to so this is one of the things where it's about yeah that adjustment that change but push pushing it through getting people on board with it and for me i know personally i had i led our dora efforts for three years so i was a little bit late to the table when it came to actually properly getting hands-on into some of the AI tools.
And even just using it so much in personal capacity, really in getting used to it, so that when you bring it into your commercial capacity and in your work, it's not so scary. You've got experience. So there's a lot of work to be done around that and getting these tools in place, using the ones that are already available. I think the third area of those kind of three and a half areas is the defenders.
I had mentioned you've got your 10-step kill chain, your 24-7 security operations, your detection response we can use all of these tools there as well now there's again it's been out for years at different levels i expect a big step up now with the latest models but when the big security vendors say well here's the ai agent that means you don't have to read every one of the thousand alerts that come through 24 7 it's going to triage for you we still need human in the loop we still need this but it is like i would describe it as a true cyber arms race and in this case there's a chance that we'll get those defensive tools at least at the same time as the bad guys get their hands on them Yeah which is fascinating With all this talk about AI implementations AI adoption projects what happens to resilience So that to me is the overlooked piece In our race to get this stuff implemented I think we're forgetting as an industry, I haven't heard too much about it compared to the amount of talk on how great AI is.
Like we talk about the risks. We acknowledge, I should say, we acknowledge the risks and we talk about the benefits. But actually getting into the risks is something where I do think we need to look at a lot more. And again, not scare tactics, but like very simply, AI fails differently than normal IT.
If the online website stops working, you can't log in. It's obvious. But what happens if the AI fails by slowly making poor decisions? That doesn't get noticed.
That flows through the entire business lifecycle of whatever's dependent there. what happens and i think the really obvious question is say the ai does fail and it's obvious either we eventually catch it silently failing now with proper checks and balances you can catch it but you still come to a point similar to a traditional it system you go the computer's gone what do i do and in a way at the moment like traditional business continuity you've got your business continuity plan, you've got your key process, key people, your facilities, and you have your workarounds.
So the way I am starting to think about it, actually based on a discussion I had with somebody yesterday in the US, was we should think of AI the same way as we think of a key person risk. So if the key person in this important process, maybe it's an insurance claim, Maybe it's who decides if a cancer screening report is correct or not. If that key person disappeared, what would we do? Is there someone else who can step in that has the knowledge?
Have we written down what's happened or what needs to be done? And those type of things. So I think those are the type of things we need to start looking at. And you might be saying, OK, what is our fallback?
Leaving aside, how do we detect that it's slowly going off track? But if it's as successful as we want it to be, in three years time, five years time, maybe the doctor reviewing the scan results is AI, but doing it for three years, who could step in if we decide that there's a problem? Not just like I think in more simple things, if an AI is categorizing insurance claims, you say, OK, we can document how to categorize them and we can fall back. But if you start losing expertise.
Yeah. actually i had a good question raised by a colleague in munich who said we won't need junior developers we'll only need senior ones but what happens when the senior ones hopefully grow old and retire how how do we get new senior developers if you don't start as junior developers yes it'll be a very different job but you still need people to start and the junior developers will come equipped with ai and they'll be very different but they do need to grow into those senior roles where they can oversee and supervise the AI.
So I think there is those type of questions that go around. Yeah, I think the organization structure in general is antiquated and it just needs to start to be updated because if you even think about the different job descriptions people are doing, we know AI can be woven into so many of those tasks. So I don't necessarily see AI as just going to do all these jobs and roles, but certainly they can do tasks within the job descriptions that then you augment and you start to reimagine what that looks like.
So that's a big progress change. Yeah, and look, the advantage here is we know there's a vast amount more work to do. There are very few people are sitting there that I've got spare time. So it's how can we use this to do more, to cover more tasks?
We use things. We had a great example. Our head of resilience had on a Saturday, however many weeks ago, where we needed to figure out which flights passed through the Middle East. And the data we had was not telling us that.
but we have flight numbers and you could look it up and three minutes later there's an agent that can automatically do it all and five minutes later we say these are the people we need to talk to to say you're not coming back via the Middle East you're going to have to reroute your flight you're going to have to figure this out so there's a lot of adoption at specific we call it like use case level yeah piece by piece but it's how do we step back now and look at say look at entire business resilience team or an information security team and say in the future say we have 10 people now but in the future we've twice as much work to do do we still have 10 people but we've got 100 agents so how do you fundamentally rethink what you're doing and build it in but step by step because i think there's a lot of people who it's still a dark black box and they're going ai is going to take over so that's where i really encourage is go have you used it to do your grocery shopping have you use it to ask questions i use it to figure out how to schedule hockey matches that's where i started with it wow this is brilliant so i think being just having that certain level of ai literacy is so important i think i totally agree with you it's all about the personal usage of us and then you build confidence and thinking actually this is quite good and then suddenly everything becomes a nail and you're actually just leaning into from a kind of business perspective as well sam collins head of security and resilience at alliance global investors thank you very much for time.
Thank you. Thanks for listening to this episode of the All This Podcast. If you enjoyed today's episode, don't forget to subscribe, rate and review. We are available on Apple Podcasts, Spotify and any Android podcast of choice.
You can also head over to our website www.allthis.com to listen to more podcasts, view our open roles and stay up to date with industry news. Thanks for listening and stay tuned for more great episodes coming very soon.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.