Adam Marrè, CISO at Arctic Wolf: “The cases that worry me most are the ones that target trust” says ex-FBI investigator

After spending more than a decade with the FBI investigating cybercrime – holding positions such as SWAT Senior Team Leader and Special Agent – Adam Marrè has developed a distinct perspective on modern cybersecurity. One he’s putting to use now as Chief Information Security Officer at Arctic Wolf, helping organisations increase their resilience against increasingly sophisticated attacks. Especially deepfakes.

Organisations now work in a world where they can no longer “automatically trust what you see or hear,” Adam explains in this in-depth interview. Combined with AI’s ability to generate more convincing social engineering, this shift places trust itself at the centre of modern cybersecurity risk, demanding a new level of vigilance from organisations wishing to defend against it.

To keep pace with these threats, Adam argues that organisations must rethink their security processes. Rather than relying on trust, employees need to develop “healthy scepticism”. That’s in part because ransomware groups have evolved into sophisticated businesses, increasingly prioritising data theft and extortion. With the time between breach and major compromise now measured in hours rather than days, the “speed of detection and response has become just as important as prevention,” said Adam.

Despite these evolving threats, he maintains that effective security still starts with the fundamentals. Strong identity security, multifactor authentication and continuous monitoring remain the foundation of any successful security strategy. Rather than striving for complete coverage, the organisations that can perform best in the face of modern threats are those that can accept that attacks may always happen, and instead focus on detection, containing and recovery.

Having spent years investigating cybercrime before stepping foot into the industry, Adam has been witness to modern cyber threats firsthand. So we started by asking how that journey brought him into cybersecurity.

Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?

I’m Adam Marrè, the CISO at Arctic Wolf. Before that, I spent over a decade with the FBI investigating cybercrime, nation-state actors, and major cyber incidents.

I got into cybersecurity because I was fascinated by the challenge. Technology touches every part of our lives now, and unfortunately that means it’s become a target for criminals and nation-state groups. During my time at the FBI, I saw firsthand how a cyberattack could disrupt a business overnight. That experience stuck with me. Today, my focus is helping organizations understand the risks they’re facing and better prepare for them.

What are some cases of deepfakes being used that particularly concern you?

The cases that worry me most are the ones that target trust.

We’ve already seen situations where criminals use AI-generated voices to impersonate executives and persuade employees to send money or share sensitive information. That’s concerning because it doesn’t require exploiting a technical vulnerability – it exploits people.

As the technology improves, we’re moving toward a world where you can’t automatically trust what you see or hear. That’s a significant shift for businesses because many processes are built around assumptions of trust.

What do you think are the best approaches to combating deepfakes?

The answer isn’t just better technology – it’s better verification.

Organizations should have clear processes for validating sensitive requests, especially involving money, credentials, or confidential information. If a CEO suddenly calls asking for an urgent payment, employees should feel empowered to verify that request through another channel.

Security awareness also matters. People need to understand that AI can now convincingly imitate voices, images and video. Healthy scepticism is becoming an important security skill.

One thing we’re seeing is that ransomware continues to evolve as a business.

Many groups are focusing more on data theft and extortion than encryption alone. They know that if they can steal sensitive information, they can still pressure an organization even if backups are available.

We’re also seeing attackers move much faster. In some incidents, the gap between initial access and a major compromise can be measured in hours, not days. Speed of detection and response has become just as important as prevention.

What are the biggest cybersecurity challenges those in leadership roles are facing?

I think leaders are facing a volume problem.

There’s no shortage of security alerts, threat reports, compliance requirements and board-level concerns. The challenge is figuring out what matters and where to focus resources.

At the same time, businesses are adopting cloud services and AI while trying to innovate quickly. Security leaders must enable that innovation without exposing the organization to unnecessary risk. That’s a difficult balance.

What is your take on ethical hackers and their role in cybersecurity?

They’re incredibly valuable.

Good ethical hackers think the same way attackers do, but they’re using those skills to help organizations improve. Whether it’s penetration testing, bug bounty programs or security research, they help identify weaknesses before criminals find them.

Some of the biggest improvements we’ve seen in cybersecurity over the years have come from researchers sharing what they’ve discovered and helping organizations fix problems before they become major incidents.

What are some prevention strategies you believe every business should adopt?

The fundamentals still matter.

Use multifactor authentication. Keep systems patched. Limit unnecessary access. Train employees to recognize phishing attempts. Have a tested incident response plan and reliable backups.

Those aren’t particularly exciting recommendations, but they’re consistently effective. Most successful attacks still rely on organizations failing to do one of the basics.

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good?

Generative AI makes certain tasks easier and faster, and that benefits both defenders and attackers.

For threat actors, it can help create more convincing phishing emails, conduct research, or improve social engineering efforts. It lowers the skill barrier for some types of cybercrime.

For defenders, it can help security teams process huge amounts of information, investigate incidents more efficiently and identify threats faster. Given the cybersecurity talent shortage, that’s incredibly valuable. The technology itself isn’t inherently good or bad – it’s all about how it’s used.

Which cybersecurity best practices are being adopted with the most success by companies?

The companies that tend to perform best are the ones that focus on resilience rather than perfection.

They’re investing in identity security, multifactor authentication, continuous monitoring, and incident response planning. They accept that attacks may happen and concentrate on detecting and containing them quickly.

That’s often a more realistic approach than trying to stop every threat before it reaches the organization.

What role do you think governments play when it comes to cybersecurity?

Governments have a very important role because cybercrime isn’t something individual organizations can solve on their own.

They can help by sharing threat intelligence, supporting law enforcement efforts, strengthening critical infrastructure and encouraging collaboration between public and private sectors.

Cybercriminal groups operate globally, so defending against them often requires the same level of international cooperation.

What’s something that has drastically changed about cybersecurity since you first got started in the field?

The professionalism of the adversaries.

When I started, many threat actors were relatively small operations. Today, some cybercriminal groups operate like mature businesses. They have specialist teams, affiliate models, customer support and significant financial resources.

The scale has changed dramatically as well. Technology is far more integrated into every part of business, which means the potential impact of a cyberattack is much greater than it was a decade ago.

What advice do you have for aspiring professionals wanting to work in cybersecurity?

Be curious.

The people who succeed in cybersecurity are usually the ones who genuinely enjoy figuring things out. Technology changes constantly, so a willingness to keep learning is essential.

I’d also encourage people to build practical experience wherever they can. Labs, internships, certifications, volunteer projects, capture-the-flag events – anything that gives you hands-on exposure.

And don’t underestimate communication skills. A big part of the job is helping people understand risk and make better decisions. The ability to explain complex issues clearly is incredibly valuable.

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.