Trending Topics

Neil Thacker, Global Privacy & Data Protection Officer at Netskope: “Deepfakes have quickly evolved from obvious manipulations into convincing tools for fraud and impersonation”
Cybersecurity has changed dramatically over the past 20 years, and Neil Thacker has witnessed it evolve from a technical, back-office function to a boardroom issue. Today, as Global Privacy and Data Protection Officer at Netskope, he’s using that experience to help organisations balance security with the emerging technologies that offer to both revitalise and threaten at unprecedented scale.
“When I first started many attacks were relatively opportunistic and easy to identify,” he said. Today, he explains in this wide-ranging interview, cybercrime is increasingly organised, financially motivated and enhanced by the increasing presence of automation and AI. At the same time, organisations have been split between cloud platforms, remote working and AI ecosystems, expanding the attack surface to any opportunistic bad actors.
Among the emerging threats, deepfakes are a particular area of concern for Neil. He points in particular toward the rise of executive impersonation, where attackers use “AI-generated voice cloning and synthetic video” to imitate senior leaders and manipulate employees. The challenge, he explains, is that these attacks are targeting not the technology itself, but human trust.
Neil remains optimistic. AI has “enormous defensive potential,” he argues, helping organisations to identify anomalies whilst improving response times. But – and this is a consistent theme across our interviews with security experts – technology alone won’t be enough. Effective security relies both on strong governance and creating a culture where employees who feel empowered to challenge unusual requests.
With cybersecurity now facing unprecedented threats, we began our interview by asking Neil about the hottest of topics: deepfakes.
What are some cases of deepfakes being used that particularly concern you?
What concerns me most is how quickly deepfakes have evolved from relatively obvious manipulations into highly convincing tools for fraud, impersonation, and disinformation.
One area that’s especially challenging is executive impersonation. We’re seeing threat actors use AI-generated voice cloning and synthetic video to imitate senior leaders in order to authorise fraudulent payments, manipulate employees, or gain access to sensitive information. These attacks are becoming increasingly sophisticated because they exploit something fundamental: human trust.
There is also a broader societal impact. Deepfakes blur the line between what’s real and what isn’t, creating an environment where misinformation spreads faster and even authentic content can be questioned. In cybersecurity, trust and verification are everything, so any technology that undermines that foundation becomes a major challenge.
The reality is that organisations now need to think beyond traditional phishing awareness and prepare employees for AI-enhanced deception at scale. Organisations need a combination of state-of-the-art technology along with strong verification processes, clear governance, and a culture where employees feel empowered to question unusual requests, even when they appear to come from senior leadership.
What are the biggest cybersecurity challenges those in leadership roles are facing?
One of the biggest challenges today is balancing innovation with governance. Organisations want to move quickly with AI, cloud services and digital transformation initiatives, while security leaders are under pressure to ensure those technologies are adopted safely and responsibly.
AI is a perfect example. Enterprise use of AI applications has grown incredibly quickly, often faster than governance frameworks can evolve. Employees are increasingly using AI tools in their day-to-day work, sometimes without formal approval or oversight, which creates concerns around visibility, data protection, compliance, and insider risk.
As a result, security leaders are effectively being asked to do two things simultaneously: reduce risk while accelerating innovation. That balancing act has become significantly harder in the age of AI.
There’s also a growing expectation for cybersecurity leaders to translate technical risk into business language for boards, regulators, and executive teams. Communication, governance, and resilience are now just as important as technical capability.
Cybersecurity is no longer solely the responsibility of the security team. It’s an organisation-wide business issue that requires collaboration across leadership, technology, operations, and employees alike.
What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good in cybersecurity?
Generative AI dramatically lowers the barrier to entry for cybercrime. Threat actors can now create highly convincing phishing emails, fake identities, malicious code, and social engineering campaigns faster and at greater scale than ever before.
What makes generative AI particularly effective is that it mimics human communication extremely well. Traditional phishing attempts often contained obvious spelling mistakes or awkward language, whereas AI-generated attacks are far more polished, personalised, and believable. Combined with deepfakes and voice cloning, this creates a much more sophisticated threat landscape.
At the same time, organisations are adopting AI faster than governance frameworks can evolve. The technology is moving incredibly quickly, while regulation, policy, and organisational controls are still catching up. That gap creates opportunities for exploitation.
That said, AI also has enormous defensive potential. In cybersecurity, AI can help organisations identify anomalies faster, automate threat detection, improve incident response, and reduce alert fatigue for security teams. Ultimately, AI itself isn’t inherently good or bad – it’s a tool. The key is making sure innovation is accompanied by transparency, accountability, and security-by-design, so organisations can benefit from AI while managing the associated risks responsibly.
Which cybersecurity best practices are being adopted with the most success by companies?
The organisations seeing the most success are the ones taking a proactive, layered, and data-centric approach to security, rather than relying on any single technology or control.
Zero Trust has evolved from being a buzzword into a practical framework for modern organisations, particularly in hybrid working environments and cloud-first businesses. Organisations are moving away from assuming trust based on network location and instead continuously verifying users, devices, applications, and access requests.
At the same time, there’s been a major shift towards understanding where sensitive data lives, how it moves, who has access to it, and the context around that access. That becomes even more important as AI applications become embedded into everyday workflows.
We’re also seeing strong results from organisations that combine identity and access management, multi-factor authentication, user behaviour analytics, continuous monitoring, and ongoing employee education.
The most mature organisations understand that cybersecurity is a fundamental domain of business resilience and needs to be embedded across people, process, and technology. Those organisations tend to be far better positioned to adapt to new threats and emerging technologies.
What’s something that has drastically changed about cybersecurity since you first got started in the field?
The sheer speed and scale of threats.
When I first started, many attacks were relatively opportunistic and easy to identify. Today, cybercrime is highly organised, financially motivated, and increasingly powered by automation and AI.
At the same time, the attack surface has expanded dramatically. Organisations are operating across cloud environments, remote workforces, SaaS applications, personal devices, and now AI ecosystems. Security teams are responsible for protecting far more complexity than ever before.
Ultimately, cybersecurity today is about enabling trust in a digital world, and that responsibility now sits across the entire organisation, not just within the security team.
Some great reads from our Interviews and Opinions sections
- Lessons from the boardroom: How CISOs should approach compliance
- Rob O’Connor, EMEA CISO at Insight: “Shareholders, boards and senior execs alike don’t want to feel like they are missing out on the AI revolution”
- Merlin Gillespie, CTO at Cybanetix: “AI tools represent the fastest growing, least-protected entry point in the enterprise”
- What the EU age verification app controversy teaches us about digital identity and trust

