Greg Nelson, CEO of RSA: “Moving to passwordless, phishing-resistant authentication should be every organisation’s top priority”

Over his 25 years in cybersecurity, Greg Nelson has watched the industry evolve, shifting from a perimeter-focused approach to one largely centred around identity. Today, as CEO of the identity security company RSA, he’s using that experience to help organisations secure their employees and themselves in the face of AI-driven threats.

Threats such as deepfakes. Greg’s concern is less about the deepfakes themselves, more the path they take to exploit security systems. “[These] attacks target the human element, which has always been our weakest link,” he explains. Social engineering campaigns were already an effective way to gain access, but with the introduction of AI generated voices, attackers can easily impersonate executives and manipulate otherwise robust security systems. As Greg puts it: “It’s very difficult to break a security control. It’s comparatively simple to convince someone to let you in.”

Combating these attacks means moving beyond employee training. As Greg sees it, “you can’t train your way out of this problem,” meaning organisations need to secure the points where social engineering sees the most success. Help desks in particular require significantly stronger defences, with Greg suggesting “bidirectional verification” as an important element, in which both the user and technician must prove their identity. From there, AI-powered risk analysis can flag anomalies and trigger additional authentication before an attacker can cause further damage.

As the traditional perimeter has disappeared and the rapid growth of AI agents and non-human identities has risen, many organisations “don’t even have a complete inventory of their non-human identities,” Greg adds, let alone the controls needed to simply manage them. With AI-driven systems expanding, security needs to understand every entity that can potentially access the organisation to maintain protection.

This shift toward identity management reflects just how far cybersecurity has come from the early 2000s. With that in mind, we began our interview by asking more about what new risks are of particular interest – concern may be a better word – to Greg.

What are some cases of deepfakes being used that particularly concern you? 

What keeps me up at night isn’t necessarily any single deepfake incident – it’s watching the convergence of AI-powered social engineering with the weak points in most organisations’ identity infrastructure. 

Cybercriminals have long figured out that it’s much easier to log in than break in. It’s very difficult to break a security control. It’s comparatively simple to convince someone to let you in. Look at MGM Resorts, Marks & Spencer, or any of the other help desk attacks that socially engineered IT personnel into giving away credentials, suspending MFA, or enrolling new devices. Those organisations lost hundreds of millions from attacks that bypassed all the technical security controls by simply manipulating the IT help desk. Imagine how many more – and more successful – those types of attacks will be with AI-generated voices that perfectly mimic your CFO’s speech patterns, cadence, and even their background knowledge of internal projects.

What makes this particularly insidious is that these attacks target the human element, which has always been our weakest link. You can deploy the most sophisticated MFA solution in the world, but if an attacker can convince your help desk to reset credentials, all those technical controls become irrelevant. Every stage in the identity lifecycle – enrolment processes, account recovery workflows, help desk procedures – is a target.

The organisation that gets this right won’t win because they deployed better technology. They will win because they stopped assuming the phone call is real.

What do you think are the best approaches to combating deepfakes?

We have to start with a hard truth: you can’t train your way out of this problem. Social engineering has been one of the most effective tools for adversaries for years: the Verizon 2026 Data Breach Investigations Report found that social engineering was “one of the most common types of attack resulting in breaches since 2018.” 

That’s before throwing deepfakes into the mix. If your security model depends on people recognizing deepfakes or detecting social engineering, then you’ve already lost.  

Organisations need to secure the vulnerable touchpoints that deepfakes typically target. Help desks have become a primary attack vector precisely because they offer a path around technical security controls. When someone calls saying they’ve lost their phone and need their credentials reset, that’s a moment of extreme vulnerability. The traditional approach – asking security questions – is completely inadequate when AI can research the answers in minutes.

What works is bidirectional verification where both parties must prove their identity through multiple factors. The user needs to prove they’re the right person. The help desk technician needs to authenticate themselves to the user as well, so attackers can’t impersonate the help desk. Both parties prove who they are. That’s the only way to close the door deepfakes are walking through.

Behavioral analytics become crucial once you move past the initial authentication. Even if an attacker successfully impersonates someone initially, their subsequent behavior will likely deviate from established patterns. Where they access data, what they download, how they navigate systems, the times they’re active – all of these create a behavioral fingerprint. AI-powered risk analytics can flag these anomalies in real time and trigger step-up authentication or restrict access before damage occurs.

What are the biggest cybersecurity challenges those in leadership roles are facing?

CISOs today are dealing with a fundamental mismatch between their security architecture and where the actual threats are coming from. We built these elaborate perimeter defenses – firewalls, intrusion detection systems, DMZs – but the castle doesn’t exist anymore. Data lives in the cloud, on mobile devices, in SaaS applications. Users work from home, from coffee shops, from hotel rooms. The perimeter dissolved years ago, but budgets and organisational structures haven’t fully caught up.

Then there’s the explosion of non-human identities. We’ve already reached the point where there are more AI identities than human identities in many organisations, and that ratio is only going to increase. Service accounts, API keys, machine identities, AI agents – these are proliferating faster than governance processes can keep up. Many organisations don’t even have a complete inventory of their non-human identities, let alone proper lifecycle management and access controls for them.

At the same time, security leaders are dealing with a talent shortage. There are roughly 83 trained cybersecurity professionals for every 100 open positions globally. They’re being asked to do more with less, to secure increasingly complex environments, and to contend with adversaries who are leveraging AI to automate and accelerate attacks.

Underlying all of this is a communication challenge. Security leaders are struggling to articulate the business value of security investments in terms that resonate with the board and executive leadership. They’re often stuck justifying security spending purely on risk mitigation rather than demonstrating how modern security approaches can improve productivity, maintain operations, and reduce operational friction. The CISOs who are succeeding are those who’ve learned to reframe security as a business enabler rather than just a cost center.

The data backs this up. According to the 2026 RSA ID IQ Report, which surveyed over 2,100 cybersecurity IT professionals, identity-related breaches exploded in the past year impacting 69% of organisations. A quarter of these organisations reported losses exceeding $10 million. Organisations put help desks attacks as a primary risk, with 65% of organisations saying they were seriously concerned that their support personnel would fall victim to a social engineering or MFA bypass attack.

What are some prevention strategies you believe every business should adopt?

If you’re still relying primarily on passwords, you’re fighting yesterday’s war with yesterday’s weapons. Passwords have been the weakest link in cybersecurity for decades. They’re expensive to manage, frustrating for users, and catastrophically vulnerable to theft, phishing, and social engineering. Yet our research shows that 57% of organisations are still using passwords for most of their authentication. That has to change.

Moving to passwordless, phishing-resistant authentication should be every organisation’s top priority. The challenge is doing it comprehensively. I see a lot of organisations celebrating when they’ve eliminated passwords from their web applications or their cloud environment. That’s great, but if you’ve only solved 80% of the problem, the risk remains. You need passwordless for desktop login, for infrastructure access, for Wi-Fi authentication, and for legacy systems. The goal is the absence of passwords entirely, not just less passwords. 

That’s easier said than done. Our report found that 52% of organisations said that a lack of complete platform support – including coverage for legacy apps and third-party systems – was preventing them from implementing passwordless. 

We’ve experienced that change ourselves by using our solutions to implement passwordless for our global workforce. The biggest lesson wasn’t technical. Change management was half the battle.

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good (in cybersecurity)?

Generative AI is being weaponized because it dramatically lowers the barrier to entry for sophisticated attacks while being difficult to control or attribute. Historically, social engineering and phishing were either broad and generic – easy to spot – or highly targeted and labor-intensive. You couldn’t have both scale and personalization. Now an attacker can use AI to scrape social media, analyze communication patterns, understand organisational hierarchies, and generate thousands of convincing, personalized phishing messages in minutes. 

The economics have completely shifted. What used to require specialized skills and weeks of preparation can now be done in hours by someone with minimal technical expertise. AI accelerates reconnaissance and attack planning. Attackers can feed AI vast amounts of data about a target organisation – job postings, public GitHub repositories, LinkedIn profiles, press releases – and have it identify potential vulnerabilities, suggest attack vectors, and even write custom malware or exploitation scripts.

On the cybersecurity side, Generative AI has a role to play in helping teams detect vulnerabilities, suggest remediation, explain complex issues, identify data anomalies, and adjust reporting in real time. But it is not an easy button or a decision-maker. Because GenAI’s outputs can be non-deterministic, hallucinated, or hard to audit, organisations need skilled people, clear controls, and rigorous validation to ensure AI-driven findings, evidence, and decisions are reliable and defensible.

Purpose-built AI is a different story. Our Risk AI engine has been doing this for over 20 years, using machine learning to assess authentication requests in real time based on hundreds of signals – geolocation, device posture, behavioral patterns, time-based anomalies. That’s the kind of analysis that’s impossible for humans to perform manually at enterprise scale. 

Which cybersecurity best practices are being adopted with the most success by companies?

The organisations I’m seeing succeed are those moving beyond checkbox compliance and isolated point solutions toward integrated, identity-centric security architectures. For the first time in years, I’m genuinely optimistic about where the industry is heading.

Comprehensive passwordless adoption is actually happening now, not just being talked about. For years, passwordless was aspirational – everyone wanted it, few actually implemented it. That’s changing rapidly. We recently published a case study with the FIDO Alliance that documents RSA’s journey to 100% passwordless operations.

The key learning is that success requires going all the way. Organisations that eliminate passwords from 80% of their environment but leave 20% – usually legacy systems, infrastructure, privileged access – haven’t actually solved the problem. The companies succeeding are those treating passwordless as a comprehensive transformation covering everything from desktop login to building access systems.

Organisations are also learning the hard way that cloud-only strategies introduce single points of failure. We’ve seen major cloud outages take down critical infrastructure. Smart organisations are implementing sovereign deployment strategies – maintaining control over where identity systems run, ensuring they have on-premises redundancy for cloud services, and designing for resilience even when upstream providers fail.

That’s becoming a best practice particularly in highly regulated and critical infrastructure sectors where failure simply isn’t an option.

What role do you think governments play when it comes to cybersecurity?

The uncomfortable truth is that compliance and security are not the same thing – and governments often conflate them, which can actually make us less safe.

Mandates matter. When regulators require MFA, breach disclosure, or zero trust controls, they give CISOs the executive air cover to fund security that was already necessary. The market alone won’t do it – security competes with every other business priority and usually loses. So I’m for mandates.

But here’s the problem: governments legislate on political timelines, not threat timelines. By the time a regulation is written, debated, passed, and enforced, adversaries have already moved on. And prescriptive mandates create a perverse incentive – organisations check the box and declare victory. That checkbox becomes the ceiling, not the floor.

I’ve watched organisations spend millions achieving compliance with frameworks that didn’t require them to secure the help desk, govern non-human identities, or protect against AI-powered social engineering – which is where attacks are actually happening. Fully compliant. Fully breached.

Where governments genuinely add irreplaceable value is in intelligence sharing. No private company can see what CISA sees across sectors. That aggregated threat visibility, rapidly disseminated, is something the market can’t replicate. More of that, fewer prescriptive checkbox mandates.

The best regulatory model sets outcome requirements and gets out of the way. The worst one gives organisations a false sense of security while adversaries adapt in real time.

What’s something that has drastically changed about cybersecurity since you first got started in the field?

The perimeter has completely dissolved, and identity has become the new perimeter, but budgets, organisational structures, and mindsets haven’t fully caught up to this reality.

When I started in this industry, security was fundamentally about building walls. You had a clear network perimeter, you deployed firewalls and intrusion detection systems at the boundary, and you assumed everything inside was relatively trustworthy while everything outside was potentially hostile. Your data lived in your data center, your applications ran on your servers, and your users accessed them from company-owned devices in corporate offices. Security was about controlling that boundary.

Today, that model is completely obsolete. Users access systems from unmanaged devices over untrusted networks. The boundary no longer exists, yet we’re still living with the legacy of that perimeter-centric thinking.

The other component is obviously AI. It’s an asset for both attackers and defenders and expands the attack surface. Every regulator is about to ask organisations three very difficult questions: which agents are operating in your environment, who is accountable for each, and can anyone stop them? Most organisations don’t know, and that won’t be acceptable for long. In 2024, 59 AI-regulated regulations were introduced by 42 federal agencies, more than double the prior year. Breaches involving shadow AI cost organisations an average of $670,000 more than standard incidents. The writing is on the wall.

That’s the change I didn’t see coming when I started in the industry..

What advice do you have for aspiring professionals wanting to work in cybersecurity?

The best advice I can give an aspiring cybersecurity professional is also the most counterintuitive: the technical skills matter less than you think.

Focus on identity security as a specialty. This is where the industry is headed, and frankly, there’s a significant skills gap that represents both a challenge and an opportunity. Professionals who develop deep expertise in identity – understanding authentication protocols, identity governance, privileged access management, zero trust architectures – will be in extremely high demand for years to come.

I’d advise embracing AI, but understand its limitations. We’re entering an era where AI capabilities will be table stakes for cybersecurity professionals. You need to know how to leverage AI for threat detection, how to prompt AI assistants effectively, and how to interpret AI-generated insights. But you also need to understand when AI is appropriate and when human judgment is required. Learn the difference between deterministic models that provide explainable results and generative models that operate as black boxes. Understand concepts like data poisoning, prompt injection, and adversarial AI. The cybersecurity professionals who succeed will be those who can work effectively alongside AI, not those who either blindly trust it or refuse to use it.

Recognize that cybersecurity is fundamentally about building a security culture, not just deploying technology. Humans remain the weakest link – not because people are stupid but because security is often in conflict with their primary job responsibilities. The most successful security professionals are those who can build positive security cultures, who can design security controls that users actually embrace rather than circumvent, and who understand that security isn’t something you impose on users but something you enable them to do easily. This soft skill – the ability to influence behavior and build buy-in – is often undervalued but absolutely critical for success.

About The Author

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.