Reuben Koh, Director, Security Technology & Strategy, APJ at Akamai Technologies: “The most significant challenge leaders face in today’s digital landscape is the impact of AI on cyberattacks”

For Reuben Koh, what began as an interest sparked by a major security incident two decades ago has developed into a career advising organisations against those same threats. Threats that have become increasingly sophisticated. Today, as Director of Security Technology and Strategy at Akamai Technologies for Asia-Pacific and Japan (APJ), he’s helping organisations align their cybersecurity strategies in the age of AI.

And few areas have been reshaped more by AI than cybercrime. For Reuben, the rise of deepfakes has been of particular concern as cybersecurity faces a serious erosion of trust. Deepfakes have made phishing attacks “more realistic, very personal and almost impossible to detect”. At the same time, ransomware groups are increasingly using AI to execute attacks “more effectively at speed and scale”. While these are familiar threats, their focus has shifted when it comes to attack surface, with APIs now being the primary target for bad actors.

To counter these increasingly sophisticated attacks, Reuben believes organisations must assume a “untrusted until verified” approach. Combining this precaution with AI-powered threat detection, he believes organisations can respond to emerging threats without running unnecessary risk.

A key theme in Reuben’s approach is the importance of a unified security model. At the centre of this is the “never trust, always verify” philosophy, implemented through Zero Trust Network Access to ensure every access is continuously contextually inspected. With APIs increasingly forming the backbone of modern digital infrastructure, Reuben emphasises how security strategies must address their protection directly, recognising that many contemporary attacks increasingly exploit logic flaws and misconfigurations rather than conventional vulnerabilities.

With this view of the threats and defences outlined, it’s clear to see that cybersecurity is almost unrecognisable to how it looked 20 years ago. That shift is one that has shaped Reuben’s own views along his journey in the field and the perspective he brings today, as revealed by his answer to our first question below: essentially, how did it all begin?

Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?

My name is Reuben Koh, and I am the Asia Pacific and Japan Director of Security Technology & Strategy at Akamai Technologies. I work closely with enterprises and business partners to shape their security strategies, protect critical infrastructure and strengthen their security postures. I began my journey designing, building and implementing LANs and WANs. In the 2000s, one of the organisations I worked for was heavily impacted by a major security incident, which sparked my interest in cybersecurity.

I realised that despite rapid digital growth in organisations, many were unprepared for emerging cybersecurity threats. My interest and experience in cybersecurity have evolved alongside the rapidly changing landscape, leading me to work with some of the best cybersecurity vendors. 

Building resilience isn’t just about data privacy and systems security but about ensuring the smooth running of critical infrastructure, from banking and telecom to transport and government services.

Now, working with Akamai Technologies, I have helped organisations align their cybersecurity strategies with their digital transformation initiatives, which has become increasingly interesting and challenging amid the constantly evolving AI landscape.

What are some cases of deepfakes being used that particularly concern you?

The scale of deepfakes has been accelerating as advanced AI-driven impersonations make phishing attacks more realistic, very personal and almost impossible to detect. Phone calls in which a caller impersonates someone else have been happening for decades, but with AI, the attacker can include personal information about someone close to the target. 

Some of the most concerning cases of deepfakes are focused on using modern AI technologies to create media deepfakes, such as videos, images and audio that appear authentic but are entirely fabricated, leading to devastating consequences for individuals and enterprises.

[Most famously], an employee of a Hong Kong-based organisation joined a video call with scammers who used deepfake representations of his coworkers to convince him to transfer $25 million in company funds to them.

What do you think are the best approaches to combating deepfakes?

As deepfakes become more common, organisations and people can implement strategies to counter potential attacks.

In retail, for instance, using behavioural intelligence to validate inputs can help separate legitimate automation from malicious bots that may harm brand reputation and outcomes.

Generative AI has made it easier for deepfakes to deceive call centres and treasury functions into unauthorised payments, while public-facing large language models (LLMs) can risk exposing proprietary IP.

To reduce this risk, strict data guardrails and thorough vetting for validation are crucial. Emerging technologies like invisible watermarking and biometric liveness analysis are starting to take shape in aiding deepfake detection. Additional safeguards include treating all access or transaction-related audio and video as untrusted until verified.

In addition, AI-driven cybersecurity tools can analyse vast amounts of data in real time, learn patterns, and identify anomalies that could indicate potential threats. The speed of this analysis enables cybersecurity professionals to detect security incidents faster and more accurately than ever before. 

By adopting a combination of adaptive detection technologies and constant user awareness training, organisations can build stronger defences that combat rising deepfakes.

The integration of AI has transformed ransomware into a more serious threat. Cybercriminals can now use AI to avoid detection and execute faster, more complex attacks. AI-powered adaptive malware allows hackers to evade security measures more effectively at speed and scale. Akamai’s research has found that quadruple extortion is the newest tactic, involving four layers of pressure: encryption, data theft, Distributed Denial of Service (DDoS), and harassment.

LockBit, ALPHV/BlackCat, and CL0P are a few well-known global ransomware syndicates alongside newer groups such as Royal/BlackSuit, RansomHub, Akira, Abyss Locker, and Play continue to evolve their tactics that are increasingly driven by AI. In 2024, Abyss Locker leaked 1.5 terabytes of data from the Australian Nursing Home Foundation.

More recently, crypto miners have emerged as a new threat, employing strategies similar to those of ransomware groups. Notably, nearly 50% of the crypto mining attacks that Akamai analysed targeted nonprofit and educational organisations, possibly because they possess substantial computational resources and are less secure than other industries. In fact, more than US$724 million in cryptocurrency was extorted from strains linked to the TrickBot malware family, which ransomware groups use. By remaining aware of and vigilant against such tactics, organisations can minimise the impact of an attack.

What are the biggest cybersecurity challenges those in leadership roles are facing?

The most significant challenge leaders face in today’s digital landscape is the impact of AI on cyberattacks. As AI continues to transform enterprise operations, leaders must be flexible and adaptable to internal and external changes. Frontier AI models have also changed the dynamics of finding and fixing vulnerabilities, where security teams need to move faster than they ever have before.

AI has increased the exploitation of vulnerabilities, with web application exploits, API threats, and distributed denial-of-service (DDoS) attacks becoming more common. According to Akamai’s State of the Internet report, APIs are now the number one attack surface as attackers shift from traditional web exploits to behaviour-based threats. Unfortunately, many leaders treat these issues separately, leaving visibility gaps for exploitation.

The rise of AI-driven systems has also increased both the scale and volume of API interactions. Model endpoints, agent workflows, and tool integrations all depend on API access that was often not designed for autonomous or unbounded use. Attackers follow this dependency directly, using APIs to enumerate functionality, exploit logic flaws, and drive excessive consumption or cost-based abuse. The surge in agentic AI heightens the risk of sensitive data exposure through APIs. Since AI depends on APIs for integration and data exchange, the volume of sensitive information traversing these interfaces has increased exponentially.

In today’s AI-driven environment, leaders need to remember that securing AI truly starts with securing APIs.

What are some prevention strategies you believe every business should adopt?

Automation and AI-powered tools allow threat actors to launch sophisticated campaigns at scale with minimal cost. As a piece of tech that is highly critical, securing APIs is going to be increasingly essential for everyone, as threat actors continually evolve and adapt their attack methods. In Australia, there is ample evidence of successful API compromises in high-profile attacks, resulting in widespread impact on consumers.

The first step in securing APIs is to discover and catalogue them within the organisation. This helps security teams understand the scope of the attack surface, identify shadow APIs and evaluate the potential exposure of sensitive information. APIs should also be actively tested for vulnerabilities during development and continuously monitored for misconfigurations and logic abuses during runtime.

Ultimately, strong foundational security will be key to organisations defending against advanced threats. While AI can accelerate attack velocity, most breaches stem from preventable issues like misconfigurations and a lack of access validations. Prioritising security fundamentals will yield a higher return on investment than a narrow focus on AI-specific solutions.

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good?

Generative AI is rapidly moving from experimentation to execution. In 2025, 31% of APAC organisations were already deploying GenAI applications into production, and 64% were in the testing or pilot phase. However, along with tremendous business potential, AI also inherently increases the threat surface due to AI native threats like prompt injections and a lack of adequate protection for them. This momentum also highlights gaps in existing cloud architectures, as many enterprises struggle with multi-cloud environments due to inconsistent tools and fragmented data management. Rising cloud costs and evolving regulatory standards further challenge GenAI strategies. However, enterprises can strategically leverage GenAI to enhance their cloud and edge infrastructure, aligning deployments with specific workload needs.

Generative AI is starting to find its place in an organisation’s standard technology stack, deeply integrated into industries such as healthcare, entertainment, and education, as well as into IoT and AR/VR. Ensuring data security through Zero Trust frameworks and maintaining interoperability to avoid vendor lock-in are crucial. Collaborating with ecosystem partners can also enable businesses to accelerate Gen AI deployment and scale more effectively.

Which cybersecurity best practices are being adopted with the most success by companies?

Akamai recommends a three-stage approach to cybersecurity. It begins with the “never trust, always verify” philosophy, followed by safeguarding your application and network infrastructure, and lastly, investing in ongoing employee training.

Zero Trust Network Access (ZTNA) solutions are critical to addressing the modern threat landscape. This approach ensures secure and granular access to resources based on user identity, device security posture, and other contextual factors. 

Having a comprehensive application security program that covers not only critical applications but APIs too, continues to be crucial to every organisation as they need to deal with not just legacy injection attacks but modern API logic abuse as well. Protecting network infrastructure with robust defences against distributed denial-of-service (DDoS) attacks and other malicious traffic is vital to maintaining the uninterrupted availability of servers, applications, APIs and other network resources.

Cybersecurity best practices would be incomplete without continuous employee education and awareness programs to protect the organisation. As cyberattacks become more sophisticated, employees must stay up-to-date on emerging threats and be regularly trained in the knowledge, tools, and best practices to mitigate potential risks. 

In addition, closely monitoring network activities helps identify potential security breaches or anomalies in real time. Regular, proactive vulnerability assessments and penetration testing are also highly effective in uncovering and addressing any vulnerabilities in your security infrastructure.

What role do you think governments play when it comes to cybersecurity?

Governments play a vital role in upholding cybersecurity best practices, particularly as they rapidly digitise citizen services and enforce industry-wide regulations. Compromised AI chatbots, exploited API, or breached suppliers can quickly lead to data exposure, regulatory violations, or large-scale disruption of critical services.

Cybersecurity is no longer just about preventing breaches but also about preserving data sovereignty, ensuring operational continuity, and maintaining public trust. Consequently, governments worldwide are more invested in building on their own and advocating to the private sector – robust cyber defences, imposing stricter regulations on data protection, cross-border data flows, and incident disclosure.

With adversaries broadening their reach and attack surfaces expanding, absolute prevention becomes increasingly challenging. Governments recognise that resilience is essential, and applications and networks must be designed with this in mind. Additionally, cybersecurity is a shared responsibility, fostering public-private partnerships that encourage intelligence sharing, best practices, and strategic investments in security.

With best practice sharing combined with essential regulatory enforcement, governments can also help to drive more urgency to private sector industries on how to secure essential technologies, both current and emerging, that can be measured and continuously optimised.

What’s something that has drastically changed about cybersecurity since you first got started in the field?

The nature of threats and the threat surface have evolved to become infinitely more complex in the digital age. Cyberattacks have evolved from minor, occasional nuisances to existential threats capable of crippling even the most established enterprises. Major ransomware attacks and data breaches demonstrate that cyber warfare is real. It is no longer a question of if but when.

Modern attacks have become more systemic and can exploit vulnerabilities even in access management and endpoint detection systems. Cybercriminals often remain undetected for days or even weeks after initial penetration, quietly establishing footholds and mapping internal systems. As a result, recovery from a modern-day sophisticated cyberattack is a complex, multistage process that may take weeks or even months to complete. Now, more than ever, it is vital for organisations to prioritise and invest in strong cybersecurity measures to reduce attack surface and minimise the impact of inevitable attacks.

The last takeaway is how cyber threats can now impact the real world we live, work and play in. Consequences from cyber attacks are no longer confined to the digital realm, as we have seen in recent years. This is probably the biggest shift in the cyber landscape since I first started in this line, and also one of the reasons that keeps me going.

What advice do you have for aspiring professionals wanting to work in cybersecurity?

It is important to recognise that the industry is constantly shifting. Many cybersecurity professionals who are just starting in the field often focus solely on technical skills. However, it is equally crucial to understand the business context surrounding cybersecurity.

Effective communication of complex security concepts to non-technical stakeholders is also essential, as they need to understand why cybersecurity matters. Take the time to learn how various business units operate and what their strategic objectives are. This understanding will help align security initiatives and recommendations with wider business goals, enabling you to communicate the value of security to the organisation more effectively. Cybersecurity is a team sport, so being a great communicative team player will help tremendously if you are first starting out.

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.