Rob O’Connor, EMEA CISO at Insight: “Shareholders, boards and senior execs alike don’t want to feel like they are missing out on the AI revolution”

After reading our interview with Rob O’Connor, Insight‘s CISO for the EMEA region, you may wonder how he sleeps at night. He kicks off with the horrors of deepfakes – like cyberattackers using deepfake technology to “ace” a remote job interview and then siphon off company data – before delving into all the ways that AI is now being used to better target organisations.

“Writing a good spear phishing email used to require a lot of manual research, investigating the target and crafting an email based on their role or interests,” he told us. “Now, GenAI, with the right prompt, can personalise a phishing email to everyone in the company, from the CEO down to the intern, in a few hours.”

So, as the man responsible for making sure Insight’s data is kept safe and its systems secure, what magic AI bullet is he using to keep foes at bay? The answer, naturally, is no single bullet, magic or otherwise. But Rob does outline his tactics in the full interview below, so we recommend you find out what they are.

If you head to Rob’s LinkedIn page you will discover that he leads with the concept of pragmatism, something born of his background. After graduating from Liverpool’s John Moores University – which we wrote about last month – in 2003, started his “career in networking, designing and building big datacentre cloud environments before cloud was even a thing!” he told TechFinitive.

“We called it ‘shared services’ back then. Security was synonymous with securing the networks back in those days, so I naturally fell into doing both jobs – working with firewalls and intrusion prevention systems alongside my main job.”

And now he still does two jobs, also acting as Technology Lead for Security & Compliance. To find out more, keep reading!

What are some cases of deepfakes being used that particularly concern you?

A couple spring to mind – I’ve seen recent examples of someone being invited to a Teams video call with their CEO and CFO and asked to urgently transfer a large sum of money. Except it wasn’t the CEO and CFO – it was a deepfake version of them looking and sounding exactly like them. Millions of dollars were transferred and never recovered.

Then there are the nation-state attempts, particularly from North Korea, of North Korean citizens applying for remote jobs with technology companies. They do a video interview, using deepfake technology to make them look and sound like local employees and ace the interview. Then, when the laptop and network credentials arrive, they start siphoning data out of the company.

What are the biggest cybersecurity challenges those in leadership roles are facing?

The pace of change right now is astounding. Not only is technology moving at the speed of light, but the pressure to adopt is coming from the top of organisations. Shareholders, boards and senior execs alike don’t want to feel like they are missing out on the AI revolution – and these opportunities always come with risks that need to be managed. 

Many of these risks are not yet fully mitigated, so security professionals are working hard to help the business move as quickly as possible while keeping things secure.  The fraught geopolitical situation we operate in also makes it tricky, with digital sovereignty becoming more of a concern, which adds another dimension to the challenge. It is certainly an interesting time to be in this industry!

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good?

Two things. It has lowered the bar for the skills required to carry out attacks. Discovering a vulnerability or writing an exploit previously took years of experience, putting a natural cap on the number of people who had both the motivation and skill set to carry out major attacks. GenAI has reduced the skill level dramatically.

Secondly, reduces the time barrier. Writing a good spear phishing email used to require a lot of manual research, investigating the target and crafting an email based on their role or interests, which limited the number that could be written. Now, GenAI, with the right prompt, can personalise a phishing email to everyone in the company, from the CEO down to the intern, in a few hours.

It’s not all bad news, though. AI is increasingly being used defensively within cybersecurity operations. It can help analysts triage alerts, identify patterns across huge volumes of telemetry, summarise incidents and automate containment actions at machine speed. This allows security teams to respond faster, focus skilled analysts on higher-value investigations and improve resilience against increasingly automated attacks.

Which cybersecurity best practices are being adopted with the most success by companies?

Ten years ago, to be secure meant investing in lots of different products from different vendors and cobbling them together. Only the largest companies could afford things like data loss prevention (DLP) – let alone have the skills to configure and monitor them. 

The model today has completely changed with all the major cybersecurity vendors offering platforms or ecosystems – not individual products. This has lowered the barrier to entry to achieve a decent level of security, even for small businesses. Integration comes built in, and partners offer a managed service wrap around the entire platform, removing the need for a large, internal security team.

This, together with features like multifactor authentication, endpoint detection and response (EDR), has made it much more difficult for attackers… but only where organisations have deployed them!

What’s something that has drastically changed about cybersecurity since you first got started in the field?

When I started, Cybersecurity meant firewalls. All the important stuff – servers and data – were neatly locked in a data centre, and our job was to stop the bad guys from getting in. Now organisations have literally turned inside out. With remote working and cloud, there are more critical assets outside of the organisation than there are inside. 

This has led to a fundamental change in how we achieve security. The zero trust model is the default – where instead of putting a wall around your network and keeping adversaries out, we no longer have a secure perimeter. Our data is spread across various third-party clouds, and our users access them from wherever they are in the world on mobile devices.

Where the network used to be the secure gate where we inspected for malicious traffic, now over 95% of traffic is encrypted, which blinds our security tools. Instead, the focus has shifted from network security to identity, application and cloud security. 

This has led to security being [beyond] the remit of one person; it’s more of a team effort now. We need specialists from multiple areas to come together and share their skills. It’s also not just a technical specialism; people who understand the human factors in security, and have good auditing skills, are a vital part of today’s security teams.

Also from our Interviews section

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.