Trending Topics

Adam Khan, VP, Global Security Operations at Barracuda: “In 2008 the enemy had a heartbeat… now it runs as code that never sleeps”
Our headline says it all. In the space of two decades, Adam Khan – VP of Global Security Operations at Barracuda Networks – has witnessed the complete transformation an industry. But, as we cover in this in-depth interview, humans remain at the heart of any successful defence.
With over two decades spanning infrastructure, engineering and security (and at companies such as Priceline.com, BarnesandNoble.com and Scholastic), Adam has seen the industry from almost every angle.
By far the most drastic change is the arrival of generative AI. While cybercriminals have always adapted to new technologies, AI has fundamentally altered the speed and scale at which attacks can be carried out. It’s also knocked down the barrier to entry, requiring threat actors to simply take a malicious model and “point it at the problem”, says Adam.
The result? A threat landscape where the volume of attacks continues to rise, while the cost to the attacker falls.
Still, Adam doesn’t see AI as an advantage reserved for threat actors. Instead, he describes it as “a force multiplier for both security teams and attackers,” capable of changing how organisations defend themselves. In reducing investigation times from hours to seconds, AI enables security teams to focus less on analysis and target more on “the hard calls and the novel threats a model has never seen”.
Looking ahead, Adam believes that the organisations best positioned to succeed will be those who embrace a new model of cybersecurity, one where humans and AI may work together. With attackers already using automation to move and operate faster, security teams must do the same, whilst keeping their expertise at the centre of decision making. As Adam puts it: “the winning defensive model is not human or machine, it is human expertise amplified by autonomous AI”.
Before looking further at where the industry is heading, though, we wanted to begin by asking more about Adam’s own career path, and the events he experienced that first pulled him into the world of cybersecurity..
Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?
Adam Khan, VP of Global Security Operations at Barracuda Networks. I lead a global SOC of more than 120 analysts, engineers, and threat intelligence specialists across AMER, EMEA, and APAC, defending tens of thousands of organizations every single day.
I did not set out to work in security. I spent the first half of my career in infrastructure and site reliability, including 13 plus years at Priceline.com. Everything changed in 2008, when our platform was hit by a botnet driven denial of service campaign, the same one that hammered Amazon and eBay. What I still remember is the audacity: one of the attackers actually called Priceline to offer his help stopping the very attack he was running. My team worked the case with the FBI on conference calls that also pulled in counterparts from Amazon, Verizon, and eBay, and it ended years later in an international manhunt and the arrest of Dmitry Zubakha in Cyprus in 2012.
Being on those calls, watching an outage turn into a cross border criminal case, hooked me for life. What sets me apart since then is breadth: I have led product, customer success, engineering, and security, and that rare vantage point shapes how I attack every problem. I scaled the SOC threefold at SKOUT and helped build XDR before it even had a name. In 2008 the enemy had a heartbeat. Now it runs as code that never sleeps. You do not out hire that problem, you out automate it, with people in command. Powered by Humans, Accelerated by AI.
What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good in cybersecurity?
AI is a force multiplier for both security teams and attackers, and that symmetry is the whole story. In the wrong hands it is dangerous for one simple reason: it removes the two things that used to limit attackers, skill and time. A novice can now produce flawless phishing in any language, working malware variants, and convincing personas in minutes. We have watched the cost of launching a credible attack fall toward zero while the volume climbs relentlessly. When an attacker can generate thousands of unique lures faster than any human team can read them, the old model of analysts triaging alerts one by one is already broken. That is the uncomfortable truth a lot of leaders are not ready to say out loud.
But the same force multiplier works for the defender. AI does not get tired, does not suffer alert fatigue at 3am, and does not need a week to correlate signals across identity, email, endpoint, and cloud. Used well, it compresses investigation from hours to seconds and frees human experts to spend their judgment where it actually matters, on the hard calls and the novel threats a model has never seen.
My conviction is that the winning defensive model is not human or machine, it is human expertise amplified by autonomous AI. Defenders who keep treating AI as a feature will lose to those who rebuild their operations around it. We fight AI speed with AI speed, and keep humans firmly in command.
What are some of the major trends in ransomware professionals need to be aware of?
The headline trend is industrialization. Ransomware is a mature business now, with affiliate programs, customer support, and revenue sharing that mirror legitimate SaaS companies. Ransomware as a service means the person pulling the trigger often has no technical skill at all, which widens the pool of attackers dramatically.
AI has knocked that barrier to entry down even further. The old playbook demanded sophisticated tooling, real expertise, and methodical, hands on keyboard work to move through a target. Today an attacker just needs access to a malicious model, points it at the problem to generate an EDR bypass and spin up a fresh ransomware variant, and just like that they are in business. Skill is no longer the gate. Intent is.
Extortion has also moved well beyond encryption. Attackers steal data first and threaten to leak it, so clean backups alone no longer save you. We now see double and even triple extortion, where they pressure your customers and partners directly. Paying guarantees nothing, and increasingly it just funds the next attack on someone else.
But the trend I most want professionals to internalize is speed. Dwell time, the gap between intrusion and impact, is collapsing. What used to take attackers weeks now takes hours, and AI tooling is shrinking it further. That changes the entire scoreboard. For years we have optimized for better detection. That is no longer enough. If your mean time to respond is measured in hours while their time to encrypt is measured in minutes, you lose regardless of how good your detection is.
What are the biggest cybersecurity challenges those in leadership roles are facing?
The challenge every security leader will admit to is talent. The challenge fewer will admit is that hiring is no longer the answer. For years the reflex was simple: more alerts, hire more analysts. That math has broken. Alert volume is growing faster than any budget can hire against, and even if you could find the people, there are not enough trained analysts in the world to fill the gap. Building a bigger human wall against an automated flood is a losing strategy, and clinging to it is the quiet failure I see across our industry.
The second challenge is burnout, which is the direct consequence of the first. When you ask skilled people to spend their days closing false positives, they leave, and the institutional knowledge leaves with them. Turnover is a security risk, not just an HR line item.
Third is justifying spend. Boards have heard the fear pitch too many times. They want outcomes and risk reduction they can measure, not a longer list of tools.
My answer to all three is the same. Leaders have to redesign the operating model around automation that absorbs the volume, so that human experts do only the work that humans can do. That is not cost cutting. It is the only way to make the human side of security sustainable and genuinely worth staying for.
What is something that has drastically changed about cybersecurity since you first got started in the field?
When I started, security was about walls. We built a hard perimeter, trusted everything inside it, and assumed the threat was outside trying to get in. The firewall was the center of the universe. That world is gone.
Two shifts dismantled it. First, the perimeter dissolved. Cloud, mobile, and remote work mean the office network is no longer where the work happens. The new perimeter is identity. Attackers do not break in anymore, they log in, using stolen or phished credentials. If you are still spending most of your energy on the network edge, you are guarding a door in a building that has no walls.
Second, and more recent, is the arrival of speed and scale on the attacker side through automation and AI. Early in my career a sophisticated attack required a sophisticated human. Now it does not. The barrier to entry has collapsed.
What strikes me most is the pace of the pace. The interval between a new technique appearing and that technique becoming commodity used to be years. Now it is weeks. So the single biggest change is not any one technology, it is that the cycle itself accelerated to the point where a human only response model simply cannot keep up. Everything we build now starts from that reality.
What advice do you have for aspiring professionals wanting to work in cybersecurity?
My advice has changed more in the last two years than in the previous twenty. It is now extremely important for anyone entering this field to know coding languages, AI tools, and agentic workflows. That is no longer a nice to have, it is the new baseline. The analyst who can write Python, wire up an API, and orchestrate AI agents to do the heavy lifting will run circles around the one who only knows how to click through a console.
Here is the uncomfortable part. The classic entry level job, sitting in a SOC watching alerts scroll by, is exactly the work being automated first. So do not aim to be the person who triages alerts. Aim to be the person who builds the automation that triages them. Learn how AI models reason, where they fail, and how to chain them into workflows that actually close an investigation.
What has not changed is curiosity. I did not come from a traditional security background. I got hooked because one case fascinated me and I could not let it go. Certifications open doors, but curiosity and the willingness to build with your own hands are what carry a career. Set up a home lab, break things, automate your way out of the boring work, and stay relentlessly hands on. The future belongs to the professionals who command AI, not the ones who fear it.
What role do you think governments play when it comes to cybersecurity?
The public sector plays a huge role, and the most important part of it is protecting critical infrastructure. The electric grid, water systems, hospitals, pipelines, and financial rails are what modern life actually depends on, and they sit at the intersection of national security and daily survival. No private company can defend those alone, because an attack on the grid is not a corporate problem, it is a public one.
My worst fear is the day a cyberattack stops being about stolen data and becomes about physical harm. A coordinated strike that takes a city’s power offline in winter, or quietly tampers with a water treatment system, would cost lives, not just dollars. We have already seen probing attacks against exactly these systems. The capability to cause real world damage exists, and AI is lowering the skill required to wield it. My fear is that we keep treating this as a compliance exercise until the morning the lights actually do not come back on.
The other front is psychological. Not every attack targets a machine, some target the mind. State backed disinformation and AI generated propaganda now flood our information space to erode trust, inflame division, and shake confidence in elections and institutions. Deepfakes and bot driven networks produce this at a scale and believability we have never faced. An adversary does not always need to break a system when it can break the public’s faith in what is true.
So government’s role is to set baseline standards that raise the floor for everyone, share threat intelligence at machine speed in both directions, counter these influence operations, and impose real consequences on the nation state and criminal groups behind it all. Here is the daring part: frameworks and reports are not a strategy. Until there is genuine deterrence and faster intelligence sharing, we are documenting the problem instead of defending against it. This has to be a true public private mission, not a checklist.

