Episode 393: Cybersecurity Threats in the Age of AI with Tal Kollender
In this episode of the International Risk Podcast, host Dominic Bowen is joined by Tal Kollender, former military cyber specialist, cybersecurity expert, and CEO of Remedio. Tal explores the rapidly evolving cyber risk landscape and explains why businesses must rethink cybersecurity as a strategic and geopolitical risk—not simply an IT problem. Drawing on her experience working with global enterprises and at the intersection of cybersecurity, operational resilience, and geopolitical risk, she examines how nation-state attacks, AI, zero-day vulnerabilities, configuration drift, and increasingly autonomous AI tools are changing the threat landscape.
We discuss:
- Why geopolitical tensions and hybrid warfare are increasingly reaching into businesses, supply chains, networks, and cloud infrastructure
- How nation-state attackers differ from conventional cybercriminals and why their objective can be to disrupt or control critical functionality
- Why organisations are still fighting 2026 cyber threats with a 2010 security mindset
- How AI is changing the balance between attackers and defenders, including the growing challenge of zero-day vulnerabilities
- Why visibility and detection are not enough, and why businesses need to prioritise proactive, machine-speed remediation
- The emerging risks of AI agents, shadow AI, risky MCPs, malicious skills, and uncontrolled access to business systems
- Why cyber resilience needs to account for persistent, cascading, and politically motivated attacks rather than treating incidents as isolated events
- What boards and executives should be asking about cyber risk, AI governance, resilience, and remediation
- Why “hope is not a strategy” when organisations are facing an accelerating cyber threat landscape
This is a timely conversation on cyber resilience, artificial intelligence, geopolitical risk, and why businesses need to move from simply identifying vulnerabilities to actively fixing them before attackers exploit them.
The International Risk Podcast brings you conversations with global experts, frontline practitioners, and senior decision-makers who are shaping how we understand and respond to international risk. From geopolitical volatility and organised crime to cybersecurity threats and hybrid warfare, each episode explores the forces transforming our world and what smart leaders must do to navigate them. Whether you’re a board member, policymaker or risk professional, The International Risk Podcast delivers actionable insights, sharp analysis, and real-world stories that matter.
Dominic Bowen is the host of The International Risk Podcast and Europe’s leading expert on international risk and crisis management. As Head of Strategic Advisory and Partner at one of Europe’s leading risk management consulting firms, Dominic advises CEOs, boards, and senior executives across the continent on how to prepare for uncertainty and act with intent. He has spent decades working in war zones, advising multinational companies, and supporting Europe’s business leaders.
Episode 393 Transcript: Cybersecurity Threats in the Age of AI with Jennifer Parker
00:05.18
Dominic Bowen
Cyber risk is not just about malware. It’s not just about hackers and even boring technical controls. For many organization, the real exposure sits somewhere much more ordinary.
00:16.67
Dominic Bowen
It’s in misconfigured systems. It’s in slow remediation, sometimes fragmented ownership. And it’s about the fact that quite simply, our internal teams most often don’t work as fast as the adversary.
00:29.39
Dominic Bowen
Today, I’m joined by Tal Colander. She’s a former military cyber specialist who went on to architect security for global enterprises at a Dell EMC before finding her own company called Remedio.
00:42.71
Dominic Bowen
Now, she’s been doing work for some fantastically impressive companies, including Amazon, Coca-Cola, Kraft Heinz. And she works at that really interesting intersection between cybersecurity, operational resilience and and geopolitical risk. And today we’re going to be unpacking some of the topics that really matter.
01:02.61
Dominic Bowen
Tal, welcome to the International Risk Podcast.
01:06.52
Tal
Thank you so much for having me, Dominique.
01:09.27
Dominic Bowen
I’m excited about our questions today. And I think, you know, if we start quite broadly, it’s really difficult to open the news, you know, whether you just want to read about the World Cup or check the weather or or check on your stocks. um It’s impossible not to see. i mean, certainly for the last four months, it’s impossible not to see that there’s been another breach of the peace agreements or the ceasefire between Israel and America and and Iran, or to see, you know, tensions ongoing and huge humanitarian crisis in Sudan, the ongoing war between Russia’s illegal invasion of Ukraine.
01:30.41
Tal
Thank
01:44.73
Dominic Bowen
And of course, this week, um you know, NATO has been meeting in Turkey and geopolitical risk. I think that’s something that we’re all starting to realize. It’s not just something that happens over there or, or far away or in other countries.
01:57.59
Dominic Bowen
It reaches our own countries and and it reaches into our own companies. It reaches into our own networks, our own suppliers, our client systems. It helps us determine whether we use the cloud and what countries we we base our systems in.
02:12.66
Dominic Bowen
If we start quite broadly, just looking at these huge issues that are happening every single day, how should business leaders be thinking differently about geopolitical risk when they’re considering the impact on their cyber exposure?
02:28.28
Tal
Yeah, it’s it’s a very interesting question because there is a difference between, ah would say, like um and nation state um hackers or, you know, like attackers than a kind of a criminal. And and you see it because and a criminal or a regular hacker probably will chase you to get more money. But a state actor, they actually want your functionality. They…
02:55.80
Tal
um They went way more than just, you know, encrypting your data and and and then, oh, you need to pay me in order to get it back. um They want um the state, the state act attackers or um eventually hackers, they want to control the infrastructure to destroy your ability to operate um or to do something actually during a conflict. And,
03:24.18
Tal
One of the things that misconfiguration, this is how it gets into the picture and that it controls how systems behave how how systems behave eventually. And that’s exactly what you see. And maybe there are many things that you see on the news, but there are so many things that you don’t see that happens every, I can say today, every minute.
03:49.11
Dominic Bowen
I think that’s really relevant. There is so much. And it it amazes me that even in an environment where in Europe right now, there’s been 200, 200 hybrid attacks that have been linked to Russia. Now, this isn’t maybes. These are ones that governments are quite confident to put their hand on the chest, go out to the media, go out to the public and say, this hybrid attack was caused by Russia. So there’s been so many more that have occurred that we’re not able to say publicly can be attributable to a foreign state adversary. um So there’s so much going on.
04:17.82
Dominic Bowen
And I think at that time when so many companies are still treating cybersecurity as a technical function, it’s those it’s those geeky or those dorky IT people wearing hoodies in the in the basement.
04:29.14
Dominic Bowen
But at what point should boards be treating this as a cyber activity that really is a strategic risk risk, where it it stops becoming an IT problem and becomes ah a board level geopolitical risk? you know How do we balance where that sits and and who should be looking at it?
04:47.67
Tal
So, you know, today with the AI, everything is like, oh yeah, maybe we need we need less people in order to enable ah more functionality and um to spend more on tokens and ah um to to kind of eliminate people, but to save more money. ah And And it is always a conflict. There is a problem between am the same thing. And unfortunately, sometimes, if you just think about it, let’s take a little bit, you know, like um of what happened in the past few months.
05:20.98
Tal
we are finding that We are fighting the 2026 war with sometimes around, I don’t know, 2010 maybe mindset.
05:31.35
Tal
um The boats, they just believe that they are being targeted by genius hackers with, I don’t know, like magic exploits. And the reality is actually like that the nation state aren’t really breaking in. They are walking to the same path that you’ve been told a hundred times that is closed. But…
05:57.39
Tal
It’s open. And even if if you thought that it is closed months ago, years ago, this is the way they get in because they can, because they find a way, they find a way that um that to show you that everything is possible.
06:14.58
Dominic Bowen
I just wonder before we go on that your answers are are awesome. If you’ve got like some pillows or a blanket or even some jacket, there’s ah just quite a bit of echo around the around the room.
06:23.70
Tal
Oh, really?
06:24.58
Dominic Bowen
Sometimes I find like I’ve literally done it here. I’ve got like pillows just all beside my computer. Have you got like some pillows or some jackets or something?
06:31.84
Tal
But I’m talking for my, so what what do I need to do? Like put the pillow where?
06:35.42
Dominic Bowen
and just there’s a lot of echo There’s just a lot of echo in the room um
06:39.56
Tal
Echo, wow, okay.
06:40.92
Dominic Bowen
Like often if you’re in a cement office or a glass office, it just bounces off for quite a lot.
06:40.95
Tal
um
06:46.55
Dominic Bowen
Sometimes just some pillows or something soft breaks it up a bit.
06:47.16
Tal
Okay.
06:50.42
Tal
But you want me to bring a pillow um to do to do what?
06:55.70
Dominic Bowen
we We just need something. You know how um when you see professional studios, you know, they have that padding on the walls or curtains.
07:00.91
Tal
Yeah. I don’t know, like which should they should shawa you where should I put it in order, ah the pillow to ah to try to isolate the noise?
07:08.57
Dominic Bowen
normally yeah normally if you sort of put it right like you’re almost like you’re in a kid you build a pillowcase you just want that sound to stop bouncing off the walls the walls and the glass often the wall it pays a bit of a difference
07:13.99
Tal
Wow.
07:18.84
Tal
Okay, let’s…
07:22.59
Tal
How is it now? Is it better? Is it not better?
07:25.17
Dominic Bowen
it’s it’s it’s okay yeah it just
07:25.62
Tal
No.
07:28.15
Tal
Let me, let me… I can bring more, you know, but…
07:32.34
Dominic Bowen
if if If you had a couple more so you had them on both sides, that that ends up being quite a – it sounds a bit silly, you feel like.
07:36.73
Tal
Okay. Okay.
07:38.85
Dominic Bowen
It’s silly, but it works.
07:39.35
Tal
Okay. I’ll do it. I’ll do it. Just a second.
07:45.52
Tal
It’s the first time that ah that I’m hearing that ah there is a network.
07:49.53
Dominic Bowen
Oh, really?
07:50.58
Tal
Yeah. um I do podcasts and interviews all the time, which is… But that’s okay. I’m doing my best in order.
07:59.44
Dominic Bowen
No, no problems at all.
08:01.42
Tal
I’m sorry.
08:02.57
Dominic Bowen
No, no, no, no.
08:02.81
Tal
How about…
08:03.16
Dominic Bowen
It’s really fun.
08:04.78
Tal
How about now?
08:06.78
Dominic Bowen
Yeah.
08:06.92
Tal
I’m trying. not ah You know, you can’t really notice the difference.
08:11.25
Dominic Bowen
it’s’s It’s sometimes hard to difference, but if normally I don’t hear it in the interviews, but then when we do the production and then it sounds really strong, but I can actually hear it. ah I could hear it before when you were speaking. um
08:23.45
Tal
Okay.
08:23.45
Dominic Bowen
And it’s really some of the echoes really hard to edit out, you know, in the the the postpod the post-production editing, it’s quite hard to edit out.
08:24.17
Tal
That’s a,
08:31.71
Dominic Bowen
But I think that’ll be i think that’ll be that’ll be good. it sounds silly, but the pillows make a huge difference. Yeah.
08:36.86
Tal
No, no, I like it. I like, ah yeah, um I’ll definitely use it as one of my ah magic ah magic cards, you know, that I will ah i will come and say out of ah out of a sunny.
08:47.75
Tal
Yeah, but no, thank you for that.
08:48.43
Dominic Bowen
it’s uh yeah no i i’d even like in my uh even though it’s sunny i even close all the blinds in my room so it’s less glass and more more material but anyway your your answers are great but i’ll we’ll just pick the interview up from there So I think your point about artificial intelligence is is really interesting. And I love your example about, you know, we’re fighting 2026 criminals with 2010 technology. and And I see that all the time. And, you know, maybe this question’s a bit easy for you, but I think it’s important because we see artificial intelligence. It’s changing the way we both attack or the adversaries attack. But honestly, we also do attacking. but also the way we defend against these attacks. So right now, where we are today, do you see artificial intelligence giving more advantage to the attackers who are looking for weaknesses? And we’ve seen, you know, things like Fable from Claude or Anthropic.
09:42.58
Dominic Bowen
Or do you think defenders have better defences with artificial intelligence? Who’s got the upper hand today?
09:49.75
Tal
Yeah, um AI yeah becomes very popular, very popular, you know, for defenders, but also very popular for attackers. ah You can do with AI so many things that today you don’t need to be a super…
10:04.28
Tal
um and I would say like a super expert in, um in, into, you know, like hacking and know some techniques. And let me tell you something that might surprise ah the audience here. um Microsoft or other big vendors, they got, you know, from Antropic, a big, big list of things that they found.
10:25.70
Tal
Now, they need to fix it. And they need to fix it without breaking other things. It’s very hard. But on top of that, even in our company, in Remedio, we are also finding some zero days or, you know, I would say like unknown bugs, right? Like ah the thing that you cannot really fix very very easily or very fast and you haven’t heard about. So we already submitted a few zero days to big vendors, including Microsoft,
10:52.57
Tal
And there is a period of time that if they are not going to address it, we can show the world what is it that we found. Now,
11:03.80
Tal
The reason why it is very important to understand it is today, there is a waiting list, a very long waiting list for everything that is um zero day within the big vendors, because they just got such a big list from Antropic. And they are trying to address them all. And I can tell you that they are in an overflow, like they have like overload of of of zero days or again, like ah very critical bugs that it it will take them a lot of time to address. and So I believe that it’s a matter of time
11:39.45
Tal
again, with the 2010 mindset, again, like, and with the current solutions that are only give you the visibility instead of fixing it. And that is a big problem. So not only that we find zero days, we fix them. Not only that we find what others, or we fix what others can only find, but again, the concept and the mentality must change. um Today, attackers, they just rely on the fact that you just see things, just add them to your huge backlog and do nothing with them.
12:09.69
Tal
And that’s unfortunately the the the mindset that every organization is having today and they need to change it ASAP.
12:17.46
Dominic Bowen
So what should businesses around the world, big and small, be doing? We’ve all heard that you know there’s a select group of companies that have been given information from Anthropic and and companies like yours that have helped them identify where these patches and remediations need to occur. But as you said, this is going to take weeks, months, and in for some cases, might maybe even longer. So what should all of us do as as consumers and and business owners and business leaders? What should we be doing? Should we just be waiting and hoping? Or are there things that we should be doing in the interim?
12:49.53
Tal
The mindset must ah change to be more proactive rather than reactive or rather than detection only mode. Because when you just get the data without dealing with the data, without dealing with the risk and just having more and more and more risk, and that becomes a huge problem,
13:08.34
Tal
then you need to understand that you need to wake up and react and be proactive with the um current threat actors, but also the current zero days and the current exploits. And if you can fix things at scale without breaking stuff,
13:24.95
Tal
Even if sometimes things are um things might be broken, like at least you need to react fast. And that’s really important. like It’s a huge mindset that I do see some of the organizations that are having it right now, obviously, like it’s our customers. But again, it needs to be more common.
13:43.90
Tal
People need to understand that they need to change the ability only to see this is wrong, this is wrong, this is wrong. And to get a lot of um very nice PDFs and reports, you need to do something with it instead of just, um you know, pretending, yeah, now I have this amount of ah vulnerabilities. Now I have this amount of misconfigurations.
14:04.94
Tal
That’s great. But what’s next?
14:08.41
Dominic Bowen
and But is there anything that, you know, we all use Microsoft, we all use different Apple products, we all use, ah you know, the the telco providers like Ericsson and Huawei and and and all the others.
14:20.01
Dominic Bowen
While they’re going through the process of of fixing ah these identified gaps and these vulnerabilities, is there anything that companies can be doing in the meantime?
14:22.06
Tal
you
14:29.29
Dominic Bowen
Or do we just have to wait and and hope that that everything is fixed before the the hackers get a hold of the same information?
14:37.21
Tal
So hope is not a strategy, right? um
14:39.19
Dominic Bowen
Yeah.
14:39.86
Tal
I want to hope, you know, that so many things will happen, but unfortunately, um it’s not enough. We need to actually do things. And if we really want to even to connect this to the ah economic um impact, so Today, the majority of the things um is mainly done manually.
15:01.98
Tal
Now you want to save money and you want to do things again fast. And today you have maybe a machine speed detection. But now in order to…
15:13.43
Tal
trying to deal with it. You need to do a machine speed remediation. That’s the only answer. And you need, obviously, to be proactive and not waiting for Microsoft to release another zero day or Adobe to come with another version or Google to release every week another version for the Google Chrome browser or whatever it is.
15:24.24
Dominic Bowen
Mm-hmm.
15:31.84
Tal
At the end of the day, you need to be proactive. You need to work on um on the important things first, prioritize them, but fix, fix, fix, fix. You need the fix first ah fixed first mentality. That’s what you need to do. Saving a lot of money as well on the way and making sure that you can do millions of remediation and a machine speed remediation eventually that will help your organization, will help you in front of the board, will help everyone eventually to be protected or to measure their risk and um in a way better way, in a way better way. position right now um comparing to what they used to do so far.
16:11.38
Dominic Bowen
And you mentioned boards. I sit in a a lot of board rooms and have conversations with executive teams and and board members. And usually the focus is on productivity and on innovation, which is fantastic. And that’s great. And and boards should be discussing that. Executive team should be discussing that.
16:28.47
Dominic Bowen
But they also need to be discussing resilience. and Not only what could go right, but what could go wrong. How do we pursue these opportunities whilst mitigating the risks? So, you know, as so many, often the younger employees and the better educated employees are utilizing different tools to a huge extent, including things like agentic AI,
16:49.23
Dominic Bowen
um and a lot more of these automated tools. What are some of the things that that executive teams and boards should be asking about AI risk is as many of their employees and business units are racing forward, but perhaps not considering some of the risks?
17:07.54
Tal
um Let me tell you let me give you another angle. I believe that also, um we still don’t have robots to do everything for us. And even AI can be very risky if you don’t really control it. I mean, you can develop so many agents that they can actually destroy you rather than only help you.
17:27.29
Tal
And today employees,
17:32.31
Tal
think about the insider threat. Today, employees can be, you know, like the best employees ever, but on the other hand, they can either leave if they get a better offer um or you know, like if someone is giving them enough money, they can they can make a lot of damage internally.
17:50.17
Tal
So, The risk is also the people, like people living, people um maybe, you know, like the insider threat. um and And of course, like people creating AI agents and without enough limitations or enough borders of, hey, this is what you can, this is what you can’t.
18:10.52
Tal
um and And kind of to limit everything um to… to
18:16.31
Tal
to make sure that everything is under control because having AI agents or building something without and knowing and limiting the AI to what ah to what they can access, what they can change, this is already another huge risk that you need to add um into your resilient program.
18:39.86
Dominic Bowen
And so how how do people do it? and how How should managers and teams that are like, okay, there are these tools, they all look so great. And even things like Zapier and, and Claude code, you know, they all look so quite easy to work. They promise you the miracle of so many hours back, you know, what should teams be thinking about? Is it like, okay, let’s roll this out. Let’s start to use this tool.
19:00.76
Tal
Every tool you need eventually like to to make sure that you are 10 times yourself. okay like um you need ah Today with AI, they can measure and they can make you way more efficient. okay um and now, having the having said that, you need also to know that if you use some, let’s say, co-work on Claude,
19:24.54
Tal
it can kind of work for you. But now there is also another thing that’s even more scarier or maybe the same level. But Claude, sometimes they are waiting for your input. And um now the the latest version or or or something like that they just added, um they are not waiting for the for the user to to prompt anything. So if you are not entering an answer or you are not… um putting something like as as um as an input that they request, then it it it says, oh now I’m going to um to decide and and and to answer and instead of you. because
20:01.11
Tal
Because I didn’t see any answer came came from… ah came from a real human being.
20:04.18
Dominic Bowen
Thank
20:05.83
Tal
um And that’s really scary. Like sometimes it can be the best answers that they can bring. But on the other hand, i mean, this can destroy you. I mean, if they take like the wrong decision or if they do something that you don’t control.
20:20.18
Tal
And there is always the ups and downs. um This is why i do believe that you must have A great AI ops um in your environment, someone who actually builds things for ah internally, okay? Like to to make sure that you are working 10 times better, but on the other hand, you are not doing things that ah put the company at risk.
20:43.09
Tal
So that’s another thing, but super important. And I encourage everybody to have some AI ops to control the license, to see exactly what people are using, to see how much tokens they use, but more importantly, to see what they really let the cloud do for them or any kind of AI.
20:57.60
Dominic Bowen
Yeah, it’s very interesting. Very, very interesting and certainly a lot of fun. But you can you can see as soon as you start getting a little bit deeper into many of these tools and their their theirre prompts and then the the additional apps and APIs, you start to realize there there’s a lot of information that they start to start to hoover up.
21:17.91
Dominic Bowen
I mean, you’re you’re based in in Israel, Tal, and you’re certainly not ah not a stranger. you’ve You’ve worked for the government. You’ve worked for global enterprises. you You’ve seen and and you understand that cyber risks are definitely not things that operate in silos.
21:29.03
Tal
Thank you.
21:32.48
Dominic Bowen
they operate ah They come from transnational criminal groups, but they’re also tied to geopolitical tensions. So when companies are looking or they’re getting their brief from the the chief information security officer or the chief information officer,
21:47.29
Dominic Bowen
You know, we know that we’re living in such a fragmented world and and companies are pulled into conflicts. And we know, especially as we see this massive increase in in hybrid warfare around the world, sometimes companies are the victims of of conflicts that seem far away and and definitely conflicts that they felt they had nothing to do with and they probably don’t even understand.
22:07.45
Dominic Bowen
So when companies are doing that risk assessment and considering their cyber risks and their information security risks and their OT risks, how how should they be considering that that broader environment for for conflicts that they don’t even understand?
22:24.44
Tal
Yeah, I believe it’s not about the question of, are we secure? It’s about how much time um does it take to close known open doors? um How much time does it take to close, you know, the main configuration issues? um And the approach needs needs to be changed because you will always be at risk, okay? There is no zero risk, ever. Even if you are closed environment, air-gapped environment, does not have even access to the internet.
22:55.26
Tal
You need to measure, always measure your risk and ask the right the right questions because,
23:02.84
Tal
Again, you need to have also the fact that visibility, or you need to know the fact that visibility is not enough. Visibility without remediation is just not enough.
23:14.94
Tal
And when you work also, um not only again, like if you’re talking about eventually not as only pure organization, like or solo organization, even um again, like um even if we’re talking, you know, about countries, et cetera,
23:33.50
Tal
We all know that it’s not about only what happens, you know, technology-wise, wise which is always part of the of the plan in order to do things or in order to protect against things. But you need to make sure that all of the systems, they correlate with each other. You know exactly what system A is going to do with system B and what is the eventually the when something doesn’t work, what will be the next thing that you are going to do? um And again, it’s all about living in, um even again, CIOs, CTOs, ah and CISOs like chief technology, chief information, chief information security, um officers, they all need to live in um in a risk management space. But again, not only that they will get reports of what is wrong and how secure are we and show me
24:28.18
Tal
What can I do in order to fix it? And in how much time? Because again, getting more and more data about what is wrong is just not enough these days.
24:38.46
Dominic Bowen
Yeah, unquestionably. And Tal, I’ll just take a moment to remind our listeners that if you prefer to watch your podcasts, the International WIS podcast is always available on YouTube. So please do go to YouTube and search for the International WIS podcast. And if you like our content, think about if a friend or a colleague might be interested in this episode, and please do share it with them. Doing that and liking and subscribing to our content really is so important for our success in reaching new listeners.
25:04.22
Dominic Bowen
Now, Tal, for many executives, resilience and responding to crisis is is more of a static event. It’s about how quickly we can get back to ah business operations after there has been an event.
25:13.24
Tal
you.
25:18.91
Dominic Bowen
But what I’m seeing, and and you know when I’m not traveling or working with clients to prevent crisis, I’m generally sitting in crisis management teams. I’m supporting European companies that are working through active real crises.
25:28.91
Tal
Thank
25:30.71
Dominic Bowen
And what I often see, more often than not actually, is that not only are crises often deliberately caused, but they’re persistent and they’re ongoing. It’s not a single event.
25:41.42
Dominic Bowen
It’s a repeated event and it can be cascading and spreading across the organization. And often it can be ah politically motivated as well. So when you’re looking at at cyber and information security resilience in an environment where some of the attacks and some of the crises are not static, they’re not a one-off event, but they can be something that’s continuing.
26:01.88
Dominic Bowen
What does resilience look like to you?
26:08.45
Tal
Let’s take um the striker um a case study or the striker for for example, just to measure because it was purely against the US and
26:25.85
Tal
They just started breaking into things that people were certain that they are okay or they are they are being measured and everything is secure and our firewall is um is amazing.
26:39.51
Tal
But it’s not a about that. Everything was against a configuration drift. But it’s not about, again, also like the striker is about any attack that is nationwide or any attack that is ah that is going to a specific vertical, eventually you need to understand what we do and what we recommend is that let’s take the most ah popular attacks or the recent attacks and let’s see exactly what they are abusing, what they are doing. And when you can close sometimes kind of the sources of things that you know that will prevent moving laterally, that’s eventually what you need to do.
27:20.95
Tal
Because buying more tools that will show you more things that are wrong without syncing with other tools, because everyone has its own report, everyone has its own um and findings.
27:34.81
Tal
But at the end of the day, you need to understand that um you want to reduce the risk at any given time. So um having the ability to look Overall, in there and the, let’s say the attacks in the past two to four years, and you see exactly what was the starting point, how the how they leveraged the attack, how they moved laterally, how fast it was, by the way, as part of the attack, what was the um the negotiation stage, if there was any. But, um and then you kind of measure it. You understand exactly what are the controls that you need to have. And some controls are for the short term, midterm, longterm. But at the end of the day, you need to make sure that you commit. You need to make sure that you do, that you do it and you you improve. You’re resilient, but also you improve everything in order to be more, um or to be ready for the next time. Because i always say it’s not about um if it will happen, it’s all about when it will happen.
28:36.54
Tal
And I believe that when you take those things, when you understand and we and when you calculate everything and you understand the risk and you know how to deal with it and how to be ready for the next time or how not to be like the ABC organizations that already had the experience with it, That’s exactly what makes you stronger. That’s exactly what, um and when when you do the lesson learned and you implement it and not, oh yeah, maybe, you know, I don’t i don’t believe that it will that it will ever come to me. um Don’t neglect things, just be proactive.
29:13.66
Tal
always Always measure yours yourself on then on that and make sure that the organization is ready um for the next time that ah that it will happen.
29:23.99
Dominic Bowen
Yeah, and I think your language spot on the next time it will happen, not if it will will happen. And that striker case, for for those that don’t know, was ah a global disruption to the Microsoft environment earlier this year.
29:32.51
Tal
Thank you.
29:37.66
Dominic Bowen
ah And it wasn’t the the classic ransomware story. It was related to Microsoft identity and endpoint management tools. And I think, you know, one of the lessons that that certainly many companies can learn is that it’s not just the cyber incident itself that’s important, but it’s that disruption that occur occurs to order systems and manufacturing and and shipments and and inventory. So you’ve work obviously worked with ah with a lot of very large and and influential companies, Tal. What did you get out of it And what were some of the lessons that you and your clients were able to learn?
30:08.80
Dominic Bowen
and And how are you now stronger because of those lessons learned coming out of incidents like this?
30:18.38
Tal
At the end of the day, the proactive approach of doing things and not waiting until something will happen, or maybe not to say, oh, no worries, I have an EDR, they will stop an attacker.
30:30.20
Tal
But eventually, all of the companies, all of the organizations the that that got hacked, they have an EDR. Everybody, it’s a kind of, it’s a mandatory. It’s like, I don’t know, when you have the the computer, you will have an EDR, um like an antivirus installed, and and you will have maybe an email protection as well, but they still get into the network. They still manage to leverage it.
30:54.10
Tal
And how? Not because… ah you don’t have the controls or you don’t have the tools. It’s because you when you do have the tool, but you didn’t act and you didn’t you didn’t actually take the proactive approach of, hey, let’s remediate first.
31:10.48
Dominic Bowen
Thank you.
31:10.70
Tal
Let’s not only sit and and wait um for another report from my auditors or from another tool that will show me what is wrong. I need to go and fix and I will fix the thing that I know that are highly,
31:25.56
Tal
um and popular within attackers that have zero disruption, that I can do it without any impact, of course, which is which is the disruption, but on top of that will keep me more secure and will make sure that, again, we can block something so they can um ah stop moving laterally. We did it several ah several times. and And yeah, again, obviously we We less prefer that customers are calling us when there is a crisis. We we more prefer that they are already onboarding us and they are calling us. Look, Remedio team, thank you so much. um
32:02.46
Tal
Thanks to you, we ah we prevented someone who hacked into our organization and and tried to do some lateral movement.
32:04.17
Dominic Bowen
Mm-hmm.
32:08.86
Tal
That’s exactly what we love hearing.
32:12.41
Dominic Bowen
Yeah, it would be it would be so much more enjoyable perhaps or or more productive if if we could only work with clients proactively. But alas, much of it is reactive still.
32:23.18
Dominic Bowen
As as that geopolitical environment continues to stay so hot and as organised crime right across Europe continues to penetrate businesses, large and small, at an alarming rate, I think cyber resilience is is going to be a condition for for doing business as we move forward.
32:40.15
Tal
Thank
32:40.54
Dominic Bowen
It’s definitely going to be a condition for winning contracts. And it’s definitely going to be a condition if you want to be maintaining trust with your your customers, with your stakeholders, and obviously with your your customers.
32:53.62
Dominic Bowen
So we understand that cyber resilience is is obviously a competitive ah advantage. But when you look to the the future, what are the cyber risks that concern you most? What do you think are the are the cyber risks that most business leaders and politicians are underestimating?
33:13.56
Tal
I believe they underestimate that any child can hack into their phone, their laptop, their MacBook. It doesn’t really matter.
33:27.95
Tal
That’s one thing that everyone underestimates. um Another thing, and ah by the way, the reason that they do it is because of the AI, obviously. um AI can thus can just teach you so much. can You can leverage from it.
33:42.30
Tal
And most importantly, um you can…
33:47.00
Tal
ah You can just make sure that that um that that you do it without you know extra effort and it doesn’t even cost you much. and That’s one thing for sure. another Another thing that I’m a bit scared of is, you know, um up until a year ago, i would say the chicken and the egg about, hey yeah, I found a zero day.
34:06.94
Tal
Well, every zero day, I believe it’s not really a zero day because it was revealed way, way, way before. um But I found a zero day and then they released to the vendor and then the vendor fixes it, ta-ta-ta. And then maybe you had a month, a couple of months until it is fixed.
34:21.62
Tal
I believe that the massive amount of revealing um security holes, configuration drifts, um and new things all the time, the vendors are making they’re making the vendors a hard time to close them on time, and it’s only the beginning. Think about how many organizations, they still don’t have the most ah advanced operating systems.
34:44.73
Tal
Some of them, they still have OT environments. They still have mainframe. They still have things that they cannot… really um secure or cannot really patch. um and And that makes it way more difficult. And and I believe that time doesn’t do any justice ah to to to those organizations and they are even more behind rather than, you know, like a new startup company that just, you know, like um they have, I don’t know, 10, 20, 100 employees and all of them with the latest and greatest tech. But yet, the new threats, the new vulnerabilities, ah the new AI, the
35:31.00
Tal
is definitely the next evolution. And
35:37.05
Tal
it brings a lot of good things, mainly the AI, of course, but it brings also together like many bad things that people are not even aware the amount of, the level of,
35:53.24
Tal
ah the the the level of how advanced it is and how fast um it evolves um that um very soon. Yeah, it it will, it can be actually not only your friend, but um and it can be very easy or enemy.
36:13.66
Dominic Bowen
Now, Tal, we speak about a lot of risks on the International Risk Podcast, you know, including environmental, humanitarian, cyber, financial risks. I mean, there really is no shortage. But maybe just in the last 30 seconds, can you tell us, as you look around the world, what are the international risks that concern you the most?
36:35.69
Tal
I’ll share with you um something that that I just revealed. It’s suddenly that I just revealed, I just got it official.
36:47.67
Tal
Most of our…
36:51.03
Tal
most of our will our customers, and when we asked them, look, we have the new AI govern module. And they said, oh yeah, what is it? And they said, yeah, you know, you um we cover shadow AI, we cover um any risky MCPs and skills that I will get into it in a few minutes. We cover if there is any ah configuration drift, because again, Claude can take control of your environment. So,
37:15.06
Tal
what um And they said, oh, yeah, no worries, no worries. We know exactly what we have. We don’t really, um we we control it. um and we we we We know, I mean, every asset um and what agents does it have. And and when we definitely control the um and the software that are being installed and, of course, the agents.
37:34.78
Tal
And I said, okay, I mean, we just enable it for free for all of our customers ah for um for three months because we just want you to to to be aware. I mean, even if you are already aware, what we found is that I would say, 19, let’s say 4 or 5% of our company, of the organizations, and we have hundreds of them, and they found so many glitches within their AI. um So many things that not only are misconfigured, like are clear text passwords on… cloud or cloud coworkers enabled or username that’s entered, you know, within with their Gmail accounts rather than rather than with their cop um email. and
38:19.06
Tal
We found things like people installed ah risky MCPs or let’s talk about skills. People installed malicious skills. Skill is like, you know, you kind of download skill of GitHub, of Telegram. you They kind of, you know, like they help you with many things, but you can edit the skill.
38:35.83
Tal
One of the things that you can edit, for example, and just write, hey, please bypass my EDR. Just like that. And your EDR cannot even detect it. And it goes and bypasses your EDR.
38:47.67
Tal
And we know how to detect those drifts. And we know something that we show you. We can even, of course, remediate it and we can… of course, like eliminate it immediately. So they were pretty much shocked, overwhelmed. And um to see how common it is, despite the fact that, you know, organizations are pretty certain them that they don’t have the amount of, ah and again, AI agents, shadow AI, and, and you know, like our ah risky skills. um
39:17.88
Tal
ah Let’s say that people are pretty much overwhelmed once once they see the the the results for themselves in the UI.
39:26.17
Dominic Bowen
Yeah, ah it’s concerning. It’s concerning. We could do a whole nother podcast just on that topic as well. But look, thank you very much for coming on the International Risk Podcast and and thanks just for sharing your insights.
39:33.02
Tal
yeah
39:38.60
Dominic Bowen
Really appreciate it.
39:42.84
Tal
Thank you so, so much, Dominique, and I’m wishing you all the best.
39:47.38
Dominic Bowen
Well, that was a great conversation with Tal Colander. She’s a cybersecurity expert and CEO of Remedio. Thanks very much for listening to the International Risk Podcast. We will speak again in the next couple of days.
40:00.21
Dominic Bowen
That was great, Tal. Thank you much.
