Trending Topics

Rob Harrison, SVP Product Management at Sophos: “The use of AI voice deepfakes is by far the most concerning case”
Deepfakes are becoming harder to spot, but the most concerning developments may not be the ones that make the headlines.
For Rob Harrison, SVP Product Management at Sophos, AI-generated voice deepfakes represent a particularly serious threat because they remove many of the visual and linguistic clues that have traditionally helped people identify fraud. As threat actors become better at using AI to personalise social engineering attacks, even experienced employees could find it harder to distinguish a genuine interaction from one engineered to manipulate them.
Harrison brings more than 25 years of experience in technology, having worked across national security, anti-financial crime and cybersecurity. That background gives him a perspective that goes beyond the latest security tools. While generative AI is lowering the technical barrier for would-be attackers, he argues that organisations also need to address weaknesses in identity and access management, improve employee awareness and make better use of AI on the defensive side.
In this interview, Harrison discusses why voice deepfakes could prove more dangerous than their video counterparts, how organisations can strengthen their defences against increasingly convincing social engineering, and why cybersecurity leaders face a strategic challenge that cannot simply be solved by buying more technology. He also explores the role of ethical hackers and how generative AI is becoming a force multiplier for both attackers and defenders.
Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?
I’m Rob Harrison, SVP Product Management at Sophos. My focus is our Security Operations portfolio of Managed Detection and Response, Identity, Exposure Management and our MSP/MSSP strategy.
I’ve worked in technology for over 25 years, since leaving university, always drawn to problems where technology can drive better outcomes for society. That took me through national security and anti-financial crime before I moved into cybersecurity around a decade ago. The parallels with that earlier work were clear, but one thing set cybersecurity apart: few industries can improve outcomes for organisations of every size the way this one can.
What are some cases of deepfakes being used that particularly concern you?
The use of AI voice deepfakes is by far the most concerning case. While deepfaked videos are making headlines, voice deepfakes are harder to spot. Without visual cues such as poor facial masking to give them away, it’s easier for threat actors to make them sound convincing. With the use of AI, attackers can refine these deepfakes, ironing out those familiar red flags that normally ring alarm bells.
Attackers are already using it to evolve their social engineering tactics to great success. At the start of the year, we saw a wave of voice-phishing attacks targeting single-sign-on tools, syncing up on-screen instructions with vocal instructions seemingly coming from a trusted source. Where before, red flags in poorly written phishing emails were fairly easy to spot, these instances of audio fraud are provident got be a challenge for detection systems. With AI personalisation, these deepfakes could adapt the conversation as it went, fooling even the most tech-savvy targets.
These attacks are continuing to develop, and they’ll only become more dangerous. These SSO-targeted campaigns are challenging enough to combat, but what happens once they begin deepfaking executives and preying on human anxiety and psychology? Because it’s far easier to flag up a suspicious email than it is to challenge what might sound like your boss on the phone.
What do you think are the best approaches to combating deepfakes?
Attacks using deepfakes like these, especially those SSO-specific campaigns that we’ve seen so far, are symptomatic of a wider issue. Across sectors, organisations continue to harbour persistent weak points in identity and access management. In the rush to digitise and innovate, digital workplace tools have been adopted at speed, multiplying seemingly by the day, with most organisations struggling to maintain their lifecycle management tools to match.
Already, these voice-phishing kits with audio deepfakes are available for even the most opportunistic cybercriminals to buy and deploy without the need for deep technical skills, making it more crucial than ever for organisations to plug these gaps. To combat deepfakes, organisations need to move beyond just perimeter defences, instead favouring a proactive approach with specialist identity security solutions. Not just improved lifecycle management that deletes dormant credentials, prevents excessive permissions, and monitors for misconfigurations, but that can monitor externally for exposed credentials that attackers are already exploiting. It’s the best way to restrict the damage that threat groups can cause.
While it might be challenging to match the pace of attacker innovation, organisations should also prioritise employee education, updating phishing training to include deepfakes too. Employees might not be able to recognise each one, but bringing these methods to their attention might sow that seed of doubt that makes them challenge when they receive a call they’re not expecting.
What are the biggest cybersecurity challenges those in leadership roles are facing?
Across the board, I’d say the biggest cybersecurity challenge is leadership strategy. As an industry, we talk a lot about the cybersecurity skills shortage, but we’re also experiencing a shortage of leadership, with only 1 in 10,000 organisations globally employing a CISO.
While cybersecurity tools are innovating at a rapid pace, without the skills and knowledge needed to wrap them into a strong strategy, they have limited effectiveness – like the phrase ‘all the gear but no idea’. You might have the best, top of the range tools, but unless applied correctly, their impact on cybersecurity is minimal. No matter what sector of the market you look at, there are organisations with strong technology stacks on paper, but when it comes to critically assessing those tools – they fall short. They lack the knowledge to understand whether controls are effective or to monitor how risk is changing and adapt. And when it comes to accountability, they struggle to clearly explain their security posture to executives, regulators, insurers, partners, or customers.
That’s not to say there aren’t other cybersecurity challenges facing leadership, but it’s clear there is no issue with insufficient innovation or investment from the sector itself. The gap comes when organisations fail to effectively wrap these solutions into their operations without clear strategy or clarity. Without this, cybersecurity isn’t just compromised, organisations also fall short in mapping their controls to regulatory risk and compliance frameworks. And without this knowledge and insight, will struggle to make informed business decisions.
What is your take on ethical hackers and their role in cybersecurity?
Ethical hackers play a hugely important role in modern cybersecurity and risk management. Before you even start to look at the security benefits of having ethical or ‘white hat’ hackers on side, there’s the impact it can have on young talent. It’s become common for teenagers to experiment with hacking out of pure curiosity, but by investing in ethical hacking pathways, we can guide that next generation of talent away from the criminal pipeline and protect them from being influenced by cyber criminals.
Ethical hackers also form a key pillar of Red Teams and Managed Detection and Response (MDR) services. For a successful Red Team, you need cybersecurity experts who can think like adversaries, but acting as a force for good instead. And those same skills are vital in MDR, to hunt down anomalies and neutralise human threat actor attacks, you need defenders who can put themselves in their shoes.
But it’s not the wild west. Ethical hackers need to be protected by legal frameworks with explicit, written authorization to carry out their activities, adhering to all compliance frameworks.
What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good (in cybersecurity)?
While there’s much work to be done before AI can become an autonomous attacker that works alongside threat actors, generative AI has certainly opened a lot of doors for more opportunistic, amateur attackers. Just half a decade ago, you’d have needed plenty of deep, specialised knowledge in order to carry out a cyber attack. But today, even the most low-skill threat actors can lean on LLMs to write and help refine their code and malware. It also allowed more seasoned threat actors to commercialise their operations, packing and distributing toolkits across networks for a profit. It’s so prone to exploitation precisely because it levels the playing field – anyone can use it, for good or bad.
On the other hand, it can be used in a similar method by cyber defenders. In the same way that it acts also like a force multiplier for attackers, defenders can use it to handle heavy data processing, freeing up human defenders to respond faster. It’s already been used to mitigate issues such as ‘alert fatigue’, sorting through the thousands of daily alerts that cybersecurity teams receive to streamline and categorize the responses needed. And, just as attackers are using generative AI to supercharge the design of phishing attacks, defenders can use it to carry out holistic threat analysis, scanning for suspicious metadata and process both text and visual branding elements to flag even the most sophisticated phishing attacks. Used correctly, it ensures that we can keep up with the increasing tempo of attackers.
More interviews
- Technology, AI and the Rise of the Financial Concierge – Interview with Craig Cmiel, Co-Founder of BX Partners
- Dr Elizabeth Chamberlain, Director of Sustainability at iFixit: “John Deere had more lobbyists in the building than there were congresspeople. It was wild.”
- Tim Lee, Founder of Bookipi: “We call this ‘vibe slop’: a pile of undocumented tools that are hard to secure and impossible to maintain.”
