The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/The Business of Cybersecurity
The Business of Cybersecurity artwork

The Internet Will Never Be This Secure Again, IEEE's Kevin Curran on AI and Cybersecurity

The Business of Cybersecurity · 2026-05-11 · 35 min

0:00--:--

Key moments - from our scoring

Substance score

61 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality13 / 20
Guest Caliber15 / 20
Specificity & Evidence10 / 20
Conversational Craft11 / 20

Kevin Curran brings 27 years of teaching experience and deep industry expertise to examine why cybersecurity has become critical to business operations - driven by regulatory compliance, high-profile breaches like Marks & Spencer and Land Rover's billion-pound losses, and the profitable criminal ecosystem that emerged with cryptocurrency. He argues the Internet will never be as secure as it is right now, as AI agents, plugins, and skills uploaded maliciously into LLM repositories create unprecedented attack vectors that most organizations aren't yet prepared for. Curran emphasizes that entry-level professionals and career switchers can thrive by pursuing industry certifications (ISACA, Security+, CompTIA) combined with hands-on platforms like TryHackMe, while experienced professionals must undergo a "metamorphosis" to become AI orchestrators rather than traditional coders. Universities urgently need to shift teaching focus from foundational principles to frameworks, agents, and prompt engineering - mirroring how the industry itself is evolving. The conversation tackles practical concerns like plugin security, local versus frontier models (Nvidia's Nemo, Open Claw, Hermes), and the need for guardian-model app stores for AI skills similar to Apple's ecosystem.

Key takeaways

  • →Junior professionals who become 'AI native' by mastering frameworks, agents, and prompt engineering can leapfrog experienced practitioners stuck in legacy approaches.
  • →Certifications in cybersecurity (ISACA, Security+, Google, Microsoft) are non-negotiable differentiators - unlike other tech fields - and are worth the investment even if only a few hundred pounds.
  • →Organizations should immediately audit and potentially rip out all uploaded skills and plugins in their AI infrastructure, as nation-state actors are likely seeding exploitable flaws before triggering them at scale.
  • →Keeping software updated on operating systems remains one of the highest-impact security practices, yet continues to be neglected despite its proven value.
  • →The talent gap persists not from lack of jobs (zero percent unemployment in cybersecurity) but from education lag - schools didn't teach cybersecurity 15 years ago, creating a structural delay in the talent pipeline.

In this episode

  1. 1The Evolution of Cybersecurity and the Talent Gap
  2. 2Why the Internet Will Never Be This Secure Again
  3. 3Career Opportunities and AI's Impact on Cybersecurity Jobs
  4. 4Certifications, Training Resources, and Breaking Into the Industry
  5. 5Rethinking Cybersecurity Education in the AI Era
  6. 6Agents, Plugins, and the New Risk Landscape
  7. 7What Junior Talent and AI-Native Professionals Bring to Security Teams

Mentioned

Kevin CurranUlster UniversityNordLayerAnthropicClaudeAmazon Web ServicesAppleGoogleDenodoTryHackMeNvidiaOpenAI

Guests

Kevin Curran

Topics in this episode

Open ClawPenetration testingAI agents and pluginsClaude Methos modelTropicat AITryHackMeNvidia NemoHermes (AI model)ISACA certificationsCompTIA Security+

Questions this episode answers

Why is cybersecurity one of the safest career bets right now?

Cybersecurity has zero percent unemployment, offers 10-15 different specializations (networking, reverse engineering, penetration testing, cloud security), and the demand is so high you can work anywhere globally. Unlike software engineering, roles must exist because regulatory compliance now mandates security postures.

What specific certifications matter most in cybersecurity hiring?

Industry certifications like ISACA, CompTIA Security+, and credentials from Google and Microsoft are proven differentiators that truly matter in cybersecurity hiring - more so than in other tech fields. Materials stay current, costs are modest (a few hundred pounds), and they're worth the investment.

How can universities keep pace with the rapid evolution of cybersecurity?

Universities must shift from teaching foundational principles (binary search, decision trees) to teaching frameworks, AI agents, prompt engineering, and orchestration. Coding is now done by machines; students need to become orchestrators who verify, validate, and work with AI tools rather than hand-code.

What is the biggest emerging threat from AI in cybersecurity?

Nation-state actors and hackers have likely uploaded malicious skills and LLM material into plugin repositories, waiting to exploit them at scale. Most organizations should audit and potentially remove all uploaded skills from their systems, as endpoint detection struggles to flag random encrypted packets leaving trusted applications.

How can junior professionals compete with experienced cybersecurity experts?

By becoming 'AI native' - diving deep into frameworks, agents, and how to talk to LLMs effectively. Persistence and willingness to master new tools can help junior staff jump ahead of experienced professionals locked into legacy approaches.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains meaningful ideas around AI/cybersecurity intersections, agent architectures, and the talent gap, but is significantly diluted by repetition, throat-clearing, and lengthy anecdotal asides. Kevin's core insights - that junior talent can leverage AI-native skills, that agents represent a new threat vector, that 'the internet will never be this secure again' - are buried under considerable padding about his career, media interviews, and tangential technical exploration of LLM mechanics.

The internet will never be as secure as it is now. I think well it doesn't seem that secure but when we look back we'll see oh my goodness. we, wow, I can't believe I didn't have to do this and this and this back in the start of 2026.
agents is it so understand agents how they're going to be in it but also then okay then look look at the stack and see okay well here's an agent going there but it needs credentials how do i know someone doesn't hijack my agent and take all my my my agent and scoop all my paypal account

Originality

13 / 20

Kevin offers some genuinely counterintuitive thinking - particularly the claim that junior/AI-native workers can leapfrog experienced practitioners, and the warnings about agent-based exfiltration risks. However, much of the episode recycles familiar frameworks (CIA triad, compliance drivers, talent shortage) and his extended tangent on LLM topology (valleys and peaks in parameter space) feels philosophically original but operationally vague. The 'keep software updated' advice is well-worn.

the tools the easiest way for someone for some young person is to become AI native is to go into that job and basically just have all the frameworks up all the tools figure out where AI is going to because that can easily jump ahead of someone who's stuck in the old ways
I believe actually most companies really right now should nearly rip out every skill they have or examine them because I think a lot of the nation -state hackers and even the main hackers themselves have uploaded a lot of skills, a lot of LLM material

Guest Caliber

15 / 20

Kevin Curran is well-credentialed - 27 years as a cybersecurity professor, 2,500+ media interviews, legal expert testimony, and active in industry advisory. He has legitimate seniority and breadth of exposure. However, he is primarily an academic and media commentator rather than a practitioner who has shipped products or led large-scale security operations at a major organization. His insights are informed rather than battle-hardened.

I'm professor of cyber security at Ulster University. I have been there twenty seven years in a teaching role
I do a lot of media, which is probably one of the most exceptional things about me. Two and a half thousand interviews over the last 18 years.

Specificity & Evidence

10 / 20

The episode is severely undercooked on concrete examples and data. Kevin mentions Marks & Spencer and Land Rover attacks (£1 billion impact), Claude/Anthropic's decision to withhold a model, and a few tool names (TryHackMe, Paperclip, Nvidia Nemo), but lacks specifics on metrics, timelines, named companies facing agent-based threats, or quantified risk. The discussion of how credentials are 'uploaded' or exploited is entirely speculative and lacks any corroborating evidence or case examples.

I mean, the obvious one now is AI, is to incorporate AI. And quicker than we would have thought.
the Marks and Spencers and Land Rover. I think those two attacks were responsible for over £1 billion

Conversational Craft

11 / 20

The host asks reasonable setup questions but rarely pushes back, clarifies vague claims, or demands specificity. When Kevin makes bold assertions - 'the internet will never be as secure again,' 'hackers have uploaded malicious skills' - the host accepts them without follow-up evidence or devil's advocacy. There are few sharp follow-ups on concrete risk, and the conversation drifts into Kevin's personal journey with AI rather than interrogating claims. The host does redirect once or twice but generally allows monologuing.

What are the top AI -related skills that cybersecurity professionals need now? How can they be trained in them?
Do you see anything there, any examples?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

security27course26cyber23industry12today11understand11agents11cybersecurity10back10agent10skills9data8doesn8real7listening7moment7

Episode notes

What happens when one of the world’s most experienced cybersecurity educators looks at the future of AI and quietly admits that the internet may never be this secure again? In this episode of Business of Cybersecurity, I sat down with IEEE member and cybersecurity professor Kevin Curran for a conversation that moved far beyond theory and into the real-world risks, opportunities, and uncomfortable truths shaping the next era of digital security. Kevin brought a fascinating perspective to the discussion, shaped by nearly three decades teaching computer science and cybersecurity at Ulster University, alongside years working with industry leaders, legal cases, and global media. Together, we explored how cybersecurity evolved from an afterthought into one of the most in-demand career paths in the world. Kevin explained why the rise of online commerce, social media, cloud services, and cryptocurrency completely transformed the threat landscape, creating an environment where cybercrime became financially rewarding and increasingly sophisticated. The conversation also tackled the growing cybersecurity talent gap and why AI is simultaneously creating new risks and new career opportunities.

Full transcript

35 min

Transcribed and scored by The B2B Podcast Index.

So a big thank you to Nord layer for backing the podcast and supporting the kind of real world cyber security conversations that we need more of because there's someone that records 65 plus interviews a month. I've personally seen a huge increase in browser based attacks over the past year, whether that be phishing, malicious extensions, account takeovers. The list is long and it's all happening where people spend most of their time inside the browser. So Nordlayer's new business browser that's built to address exactly that.

It blocks malicious sites before they load. It limits risky behaviors like uncontrolled downloads or data sharing and gives you visibility into how your team interacts with web apps. And it also helps you stay compliant by controlling access and enforcing policies. without the need to rely on multiple disconnected tools.

So for anyone listening that is thinking seriously about reducing risk in SAS heavy environments, this feels like a smarter and more focused approach. And you can learn more about it by visiting NordLayer .com slash browser. Let me know what you think.

But now let me introduce you to today's guest. What if the biggest cyber security threat in 2026 is not the attack that you see coming, but the one being quietly built by the very tools that we're all racing to adopt? Well my guest today is Professor Kevin Curran. He's a professor of cyber security at Ulster University and this conversation felt like sitting down with someone who has had a front row seat to the entire evolution of our digital world.

because he has spent decades teaching computing networks and cyber security, worked extensively with the industry and advised on legal cases and given thousands of media interviews translating deeply technical issues into something that everyone can understand. A man after my own heart. And what I loved about this discussion today is that it goes far beyond the usual headlines about skills shortages and cyber risk. We're going to get into why cyber security has become such a massive priority, why that talent gap still exists and how AI is already reshaping both the threat landscape and career opportunities around it.

And they'll also talk about why this could be the moment where junior talent, career switchers and AI native professionals all collide to become some of the most valuable people in the room. And there's a real sense of urgency in this conversation because we're going to talk about why keeping software updated still matters, why security certifications carry very real weight and how universities need to rethink what they teach and why agents, plugins and AI workflows All these things create a whole new layer of risk that many organisations are possibly not fully ready for yet.

So if you want a conversation that blends practical advice, big picture thinking and a few honest warnings about where this may be heading next, you're going to have a lot of fun with this one. But enough from me, let me introduce you to my guest right now. So thank you for joining me on the podcast today. Can you tell everyone listening a little about who you are and what you do?

Yeah, my name is Kevin Curran. I'm professor of cyber security at Ulster University. I have been there twenty seven years in a teaching role, so I do the usual. I teach computer networks for twenty seven years.

Not many people have the same module for twenty seven years and cyber security for the last maybe twelve years, because again, cyber security was not a subject when I was in college. And I publish my supervised research students. I work with industry. I do a lot of legal work in court cases as a legal expert.

That increases over the years because everything now is digital. And I do a lot of media, which is probably one of the most exceptional things about me. Two and a half thousand interviews over the last 18 years. Well, it's a pleasure to have you join me today There's so many things I was excited to talk with you about because when it comes to cyber security They so attractive especially for younger people now entering the workplace wanting something that will future proof their career I say to anybody that asked me I say head for cyber security one there's like 10, 15 different fields that you can enter.

Zero percent unemployment and you can work anywhere you want in the world because the demand is that high. But as you said a few moments ago, 15 years ago, nobody was teaching this stuff in school. So how do you explain the cybersecurity talent gap that we're seeing here and its potential impact on the industry because there's no shortage of demand. It's getting that talent into the funnel, isn't it?

Absolutely. When I started using. Computers and went to college, there was no passwords on computers. You went to your computer, you had your floppy disks and you took your floppy disks with you.

Then we had hard drives again. You might store something else, but everything was there. There was no need to worry about cyber because none of us had any bank details on our computers. Websites didn't really exist back then.

There was nothing confidential. All of a sudden, the web came. And then we started to do commerce on the web and then of course we have social media and then we had cameras with phones and all of our photographs were digitized. So all of a sudden a computer or a phone or a tablet became a hub.

which contained a lot of private information and a lot of banking details again. And of course, companies stored a lot of person identified information. They did this or credit cards. And there was also incentive for hackers because there was no hacking back then.

You couldn't make money. So what's happened really is, of course, private information is held and we got to keep us secure. Then a marketplace emerged for hackers and nation state hackers, you know, agencies. So for crypto, of course, and there was an incentive because the early viruses were just proof of work, proof of concepts.

You couldn't make money. Then crypto came along and all of a sudden you could or tried to remain anonymous and look for payments from ransomware and from denial of service to tax. Then also your ordinary criminals. You just look to scoop up.

All the credentials about bitcoin and whatever else so there is money to be made out there so all of a sudden the infrastructure that we all started to use became very important to secure so hands we we ended up with a brand new kind of area of computer science which is cyber security and as you said. There are so many areas into it because it's a networking aspect. There's a reverse in program code looking for exploits. There's penetration testing, cloud security.

So you pick your area as such. And it's one of the most crucial areas, of course, because now, especially, companies have to be compliant and they are subject to fines. So no longer is it You know, does the IT manager or the chief information security officer, whoever they are, whatever title they have, have to go begging to the C -suite because the C -suite already know about compliance. And again, so the budgets have increased, of course, because people have, companies have learned.

Again, there's unfortunately, you know, Marks and Spencer's may go out of business because of that cyber attack. You know, people have moved on. People will go for the cheaper prices and we're The resist the path resistance is easiest to show up and they will find other outlets again and land rover Jaguar again so. And unfortunately I feel this will be the year of the major strikes I think.

Today is the first time I've said it it came to me yesterday. The internet will never be as secure as it is now. I think well it doesn't seem that secure but when we look back we'll see oh my goodness. we, wow, I can't believe I didn't have to do this and this and this back in the start of 2026.

I hope I'm wrong because yeah. I mean, you mentioned the Marks and Spencers and Land Rover. I think those two attacks were responsible for over £1 billion alone as it shows you the scale of what we're talking about here. And I mentioned there's a lot of opportunities for students and people wanting to enter the workforce now.

But I would also argue there's an opportunity for everyone here, especially when we're talking about AI replacing or displacing certain job roles. There's a whole other heap of job roles that are being created here. How can organizations maybe make cybersecurity an attractive field for career switchers too? Because there is a great opportunity there, isn't there?

Absolutely. Again, they've got to be competitive salaries. Yeah, yeah. And again, and bring in the training as such.

But Thai people are always wanting to upscale. And people know that what I like teaching about cybersecurity because It's kind of like doing a degree in psychology, even if you didn't get a job. And the jobs are there. But you have learned things which are very important for life.

And someone who studies psychology and pays attention will not suffer the slings and arrows of someone else who has never thought about how humans operate and the common pitfalls. Same with cybersecurity, because even if I know many of my students will go into different fields within computer science, every one of them needs to know. about cyber security and the attack vectors. And it's great to have a ground up view like I have.

In other words, where I understand in cyber security to really understand it, you've got to know your communications. What's the difference in Bluetooth and Wi -Fi and Zigbee and GPS and you name the protocol, the bandwidth, whatever else, because they all have different attack vectors again. Ways get into machine and then within a machine, what is runnable? Now, that has slightly been blurred at the moment with agents because you don't know which level of the stack and it seems to have access right down to the low level.

But generally, it's great being able to know, you know, how the broader computing devices and phones and, you know, where are the real risks, of course. And after each semester, really. You know i go through everything for everything as much as you can from cryptography the primitives trust no one the cia triad confidentiality integrity availability these are the you know what we're always striving for in cyber security and then we go into pen testing the protocols whatever else but ultimately it comes down to and this is very valid for people in these coming weeks is to keep your software updated if the operating system on your device, tells you there's an update available, just take it, especially in this weather right now, given what happened.

One of the biggest events in the cybersecurity industry happened this week in the last two days, and that was Claude and Tropic have announced that their latest model, Methos, will not be given to us. but rather given to the consortium, the likes of Amazon Web Services, Apple, Google, and others, because it is so effective at finding security flows. And it's better than the greatest penetration tester on earth. So there's power there.

So that has shaken the landscape, because now we can see... again an anniversary and of course straight away you go to nation states, know the power that they have, know these flaws, whatever else. We have to see how we navigate this space in the coming months really and obviously years if we have but that has been a major wake -up call to the industry. And of course for any business leaders listening and they want to hire the staff to improve their cyber hygiene and be more compliant etc finding someone with the right certifications combined with the experience that they're looking for is a very very challenging task especially when you're looking for the right price because so many people in demand right now getting somebody at your budget can be difficult too so instead of hiring new people though how can companies effectively upscale the talent that they already have, people that want to upscale and are passionate and are looking for that entry point.

There is wonderful training, obviously, online and certificates. And it's the one industry sector within computer science where certificates really do matter a lot of the other way. I mean, you could say that. I mean, of course, data science has its whatever else.

But no, generally. A lot of other fields you generally go on your CV and your experience and maybe was in your LinkedIn profile and your heart as a developer, but cyber security, especially you're looking for the ISACA certificates and you know, the Google, Microsoft, whatever else, but and your suspend and these are have been proven and these are you know, whatever is the pen testing red team. Bluetooth, whatever you want, but certificates within cybersecurity are a must. I always encourage my students to register for, you know, some easy hits you get along the way, which are free, you know, on Amazon and cloud, you know, it's in their interest, of course, to provide free certificates.

But even the key ones are not that expensive, some of the security plus and all that, a few hundred. So that is the number one way because the materials Yeah, or kept fairly up -to -date and relevant and yeah can be more up -to -date Of course then in and then a university course because you're teaching more or less the core principles So cyber security Courses are most you know, especially when you're younger. You shouldn't really have free time You should be pushing yourself to upskilling these sectors and in fact Yeah, and there is one Trainer I use it quite a lot.

I use their free labs with my students and I mean it's it's um try hack me and i i love that i love their model and there's some great courses on there and it's not expensive and they've got different pathways and what's great about try hack me is you log on to the website you pick the module or whatever it is and it will launch your vm in one half you went down the other half is your exercises and your step by step and there's walkthroughs and you never get stuck and it just works works from anywhere on your tablet on your you know you don't need to have the old -fashioned VMs installed and trying to keep them up and what happens when your remote try hack me is a wonderful resource for people breaking into the industry.

Big thank you to Denodo for supporting the Tech Talks network and making these conversations possible. Because when your lake house stores the data, the real challenge is getting that data where it needs to go and faster. And your lake house stores the data, but Denodo helps deliver it faster. So with real -time access, built -in governance and a business -ready data marketplace, Dinodo can help your teams unlock insights without costly duplication.

And you can learn more by simply visiting dinodo .com. For schools and universities that are rethinking their approach to cyber security education, any tips there on keeping pace with the evolving industry? Because it's moving at such a rapid rate, isn't it?

Very much. I mean, the obvious one now is AI, is to incorporate AI. And quicker than we would have thought. Academia has to to move from what we were doing before, which is maybe the principles of software engineering.

How does a decision tree work? You know, binary search array because now coding is done by the machine and we become orchestrators. And then no one's really arguing with that. You know, now it's a it's a.

It really is direct in the code code or codex whatever telling what you want and of course the best people using this are the people who have planned properly broken it down into steps and verified and of course have the right skills within their the plugins and they're building gradually out their AI into test frames as well but they're not coding anymore at a certain level they're trusting. And again, so we academia we can be seen as too fine -grained in an old -fashioned way.

Now we should be moving up the stack and saying, okay, now you're speaking to the computer. Of course, you have to, of course, if you're an industry prize, you have to be able to work it out how to, you know, how to incorporate with the still same workflow the industry has, which goes on to the pipeline. There is testing there, but still you're not expected to write hand code anymore. So to be an orchestrator, to know how it works, to know how to test it.

And the same with cybersecurity. It's to see now that you're not just sitting there with a blank sheet and you go off manually and you do a pen test, but now you use kind of a tool higher than that and you're able to orchestrate and just, and again, it goes back to judgment, but people are all saying about the future of AI is it belongs to those who have good judgment and have the main expertise. and know how to use AI as the Einstein in a box, but how to verify and validate it.

And they're the ones who will get ahead. But I wouldn't dream of teaching now without incorporating AI in most steps and the frameworks. And there still is a bit of, yeah, there still is a nervous energy within the industry. Most of us, we see the agents are kind of a natural progression.

and that there's an LLM behind it. And of course, local models will become more useful, which they are now very much more widespread because of the security implications. And they can be perfect data just for the tasks that you need on a local. And then you can obviously offload or use the LLM broader models online when you need them, the frontier models.

but you can get a lot done with local models. So we bleed the agents and then it's the agent harness as well. And Nvidia, of course, have come up with Nemo Claw because Open Claw seems to be such a winner at the moment with a lot of support, but it's not for everyone. And then there's Herms, which people are moving to.

I've looked at Pier Per Clip, but I've experienced what... I've noticed a lot of other people within the AI business or within the AI sector in the last few weeks and months have experiences of burnout because I follow so hard and I don't want to miss out because I'm competitive, but there's so many options and I see it from here and there and it's hard to filter out the, especially on X which is a great place to follow AI leaders. Most of them are there so much quicker than anywhere else is on X where the conversations are taking place.

But you really get torn and I've been exhausted some days, but it was good that I know I'm not alone. And in some ways I got the whole back and the one lesson I've learned in recent weeks is not to be too quick with implementing, downloading and installing and running with because flaws are being found very much in the gold rush. And I believe actually most companies really right now should nearly rip out every skill they have or examine them because I think a lot of the nation -state hackers and even the main hackers themselves have uploaded a lot of skills, a lot of LLM material, which is generally imported as skills, knowing that they can exploit them whenever in the coming weeks, months.

And because we're just trusting too far that we've broken out of enterprise environments, out of side of firewalls, inside of the only the seat cards we've been putting in over the last few years. because it is very hard for any kind of endpoint detection system to follow every single whatever. It's really important, especially when the application there someone done those cloud desktop and then starts uploading skills and everything else. And it's just random packets going out over the, you know, out over the ether.

So I think skills will be a huge problem in the until we have. You know that kind of again and kind of a guarded app store again because we know they we know the benefits of Apple having guardianship over the app store it just is a loss safer than an app store where anyone can upload anything and it's good to have a guardian there so we need something like that for skills especially in plugins of all sorts for the AI era. Such a great point there and there's also a lot of nervous energy around AI removing some of the entry roles and of course investing in junior level roles, apprenticeships and non -traditional pathways have always been seen as a way to broaden the candidate pool and I'm sure that will continue but from your point of view what is something that maybe a junior level person could bring to a security team that maybe a security expert might lack?

Do you see anything there, any examples? persistence really and yeah the tools the easiest way for someone for some young person is to become AI native is to go into that job and basically just have all the frameworks up all the tools figure out where AI is going to because that can easily jump ahead of someone who's stuck in the old ways a developer is there 20 years and And there is a sorrow. There is a definitely universal sorrow within one. Once you understand it, I've had it.

I've gone through it in January in my bed, staring at the ceiling when I realized that I have to readjust because of AI. You know, I can see the end and I can see along the way. I can see everything, of course. And I don't know the end time for AGI, whatever else.

But but I can see my job as a professor. I can see universities have been shaken. I can see. Obviously, I can see the cybersecurity nightmare potential along the way, but but I'm also, you know, but I'm not living in fear.

I just had to readjust and I think everyone has to do that. It's just that we're ahead of the game. Austin Tech. Anyone is paying attention.

Everyone would have to go through some sort of metamorphosis. And it's fine because Ultimately, we shouldn't be defined just by the role we do. We're much larger as humans. But what I would do is just go knees deep into AI and figure out the framers, figure out about Asians, figure out about how do you talk to this machine?

I'm still trying to. I'm still trying to find out how do I talk? How do I get the best responses from it? How on earth does telling it that you are a role X?

You've seen I know if you've seen those prompts or you tell it, you are a world leading whatever that again, I want to understand that fully, because to me, why would the how on earth would that steer it? Because wouldn't without telling you, you are a world leading expert, if I ask it a question, any of the models, why doesn't it give me the best answer? Why did I have to tell it about the role, you know? And so I again, I want to know about it, you know, I want to know about the way, you know, not so much the weights.

I want to understand it. So the best analogy is, like I said, like I see, obviously I can only see in a 3D dimension, but I see valleys and peaks within this LLM of a trillion parameters and over in some corner is a valley and is to do with tractors. And then there's a valley, maybe a layer above it, which is even larger, and that's farming. And then something to do with agriculture and the earth over there.

And then with tractors, you have whatever goes with that, you know, different things. And in other words, that the LLM itself has ridges and valleys and the sharper the ridges, the more accurate or deep it is about a topic. And that's it, because it is new. I've never had to think with Google.

You just knew, OK, keywords matter. You do a search and it'll do his best to get back to you. But with so much information coded, almost everything, you know, and we know ultimately a story in vectors and matrices, whatever, but that doesn't help. Yeah.

And then you have different representations as well. You know, the representation space, as we say. So, yeah, I'm intrigued and I'm determined to understand as much as I can about how to interact and get the best out of this beast. Absolutely.

Love it. That passion really shines through. And I'd love to get a few takeaways for people listening to maybe take away an action and think about. And we've talked about how AI is transforming the threat landscape.

But what are the top AI -related skills that cybersecurity professionals need now? How can they be trained in them? What should they be doing if they want to get involved in this and be working in this field? A quick win probably is agents.

Study agents and even be framework agnostic. It doesn't have to be Claude or it doesn't have to be Herms or whatever else. Just understand, okay, an agent is generally something. Yeah, it's a task you give and some way you've got to control it.

And an agent can also be because we're seeing the shadow organizations, not the right word, but we're seeing organizations being broken down into roles. Again, with paperclip and these frameworks where you have a CEO and then CFO and you have your again and you can you can import organizational charts which correspond to different sectors. And again, the Gary Tan one is the one I used within paperclip because it's a kind of a program and it's got audit checks for code and whatever else.

And so in other words, Understand agents and how that businesses generally look like they're moving towards agent architectures where every role is taken by an agent and an agent has a predefined task. Now, of course, then you could try to build your marketing agent from start. by telling it roughly, you know, or even shadow on the person you have in marketing at the moment. But generally, people import these marketing kind of personas and they do all the tasks go here, go there and everything else.

But understand the Asians will more or less replicate humans. There'll be a lot of Asians probably bring down social networks and everything else, but they have tasks and then you can set them to run. You can improve them. They can be self -improving, of course.

We're in this era, these magical eras, of course. where skills are and you can set out a research task and it doesn't stop. The older research loop by Andrew Carpathy, the guy behind Tesla and OpenAI, he's one of the most amazing guys on the AI. He's given away a lot of advice free.

Again, he's a guy who developed self drive, full self driving for Tesla. He was head of AI at Tesla. He's also one of the co -founders of OpenAI and a nicer guy you couldn't meet and he's adored. by people because he's kind of well most people in tech are honest actually you know it's just a fact you know we're knowledge cravers as such but we are very truthful but agents is it so understand agents how they're going to be in it but also then okay then look look at the stack and see okay well here's an agent going there but it needs credentials how do i know someone doesn't hijack my agent and take all my my my agent and scoop all my paypal account my Revolut, my bank.

It doesn't exfiltrate documentation again, because this is a new area. So therefore it's an easy way for you to jump, jump over the people who were there 20 years before you, 10, that they were in their area. But you have thought deeply about Asians and you've been researching the course, you're keeping up to date and you're seeing, okay, I'm going to look for the source of sync of everything in my, in my company or the company that just hired me. You know, where are the loopholes?

Where might our personally identifying information be leaked? What are others doing? How can I restrain the company but also give freedom to developers? Because that's a balancing act at the moment.

AI can do so much. But you're not, if you give it complete freedom by bypassing all the compliance we already have. Likewise, if you're really restrict and you ban everyone from coming in, even with your phone on them or a laptop and and you nail it down, well, then you're going to be out of business, possibly. In a year or two.

So it's so companies have to find the balance between degrees of freedom for innovation and also like not completely getting snookered by by coding or just exfiltration of data. But agents for me would be the place to start and see how that transforms and whatever else. And in a larger scale, if it wasn't even cybersecurity would also be workflows. Again, because not everything that can be automated needs to be automated.

Some things which are automated shouldn't be and some things which aren't automated should be. So again, that's a very good skill to have to know what within the organization should be and shouldn't be. But definitely to see how those agents know and these frameworks, how do they fit in and how can we protect our users and our company from prompt injections and all these new attack vectors. So many big points there.

And for people listening, I will include a link to your LinkedIn. I know you're very active there. You post a lot of great content there. And I'll also pop up a link to try and hack me that you mentioned.

Anywhere else you'd like me to pop a link on there for anyone wanting to carry this conversation on that we started to today, because we may have. giving somebody a light bulb moment out there. So I will have links to everything that I mentioned there. I encourage people listening to, first of all, read some of the content that you're putting out there.

Great work, by the way. And also I'd love to stay in touch with you. See how this continues to evolve. The speed of change is just phenomenal at the moment.

So it'd be great to get you back on either later this year or early next year. See what's happening there. But more than anything, just thank you for taking the time to sit down with me today. Appreciate your time.

Not at all, Neil. It was lovely to meet you and I'd love to be back on again. Of course, yeah. Any time.

There was so much in that conversation today with Kevin that could easily stay with you long after this episode ends. One of the things that stood out to me is that cyber security is no longer some niche technical discipline that's sitting quietly in the corner of a business. It's now tied to resilience, trust, compliance, growth, reputation and increasingly survival. So when Kevin says the internet may never be as secure as it is right now.

That is the kind of line that should make us all sit up a little straighter. And at the same time, I do think that there is something encouraging here for all the anxiety around AI automation and changing job roles. This is opening doors for people willing to learn, adapt and move quickly. So whether you are a student, someone that wants to switch careers or someone already in tech trying to stay relevant, I think Kevin made a strong case that there is still huge values placed in curiosity, persistence and a willingness to get hands on with the tools that are shaping the next phase of this industry.

And I also loved his honesty about the human side of all this. Yeah, even experts are trying to keep up. Even people deep in the field are rethinking how they work and what they need to learn. And how fast the ground is shifting beneath them is something we all feel.

Hopefully that makes it feel less like a story about fear and more about adaptation. And maybe there is a real takeaway here that the people who do well in this next chapter won't be the ones pretending everything is under control, but the ones paying attention, asking better questions and learning fast enough to keep pace with the change. So are you and your organisation doing enough to prepare for an AI shaped cyber security future? Or are still many of you still treating it like tomorrow's problem and putting out fires today?

Love to hear your thoughts. TechTalksNetwork .com you'll find this and 4 ,000 other interviews over there. So many amazing insights from fantastic guests.

Please check those out and send me an audio message or a DM over there and I'll get straight back to you. But that's it for today so thank you for listening as always and I'll speak to you all again very soon. Bye for now.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • ERP135 - AI Assisted CodingEvolved Radio · on Open Claw85 / 100
  • Pursuing strategic partnerships to tackle Cobalt Strike abuseHealthcare Strategies · on Penetration testing85 / 100
  • Gary Martin from Scan Ninja AIEnergytech Startups · on Penetration testing77 / 100
  • S6E2: John Hammond on Security Research, Storytelling, Deception, and Getting Hired in CybersecuritySimply Defensive · on TryHackMe75 / 100
  • From Ransomware to Recovery: How One Rural Hospital Transformed Its CybersecurityEncrypted Ambition: Where Ambition Meets Encryption · on Penetration testing75 / 100
  • Illia Polosukhin of NEAR on AI Operating Systems & Blockchain InfrastructureThe Smart Economy Podcast · on Open Claw72 / 100

More from The Business of Cybersecurity

All episodes →
  • Closing the AI Vulnerability Remediation Gap With Cobalt74 / 100
  • Mimecast CISO On Why AI Has Become A Cybersecurity Risk60 / 100
  • Orange Cyberdefense On The New FCA Cyber Reporting Rules76 / 100
  • Deepfakes, AI Agents, and the Collapse of Traditional Identity Security66 / 100
  • When Identity Becomes The Front Line Of Cybersecurity71 / 100
All The Business of Cybersecurity episodes →