Episode notes
Nate, Director of Cybersecurity, recaps a webinar on how threat actors weaponize AI to run efficient underground businesses, using it to speed up phishing, malware creation, data parsing after account compromise, and to lower the skill needed for attacks, including deepfakes. He emphasizes AI itself isn’t “bad,” but intent matters, and the best protections are fundamentals: vigilance, validation, and strong financial controls. The discussion covers why deepfakes work—circumstantial timing and emotional manipulation—and why training should focus on core red flags rather than only deepfakes. Practical wins include two-person review for large wire transfers, moving to phishing-resistant MFA/passkeys, watching for “evil proxy” credential pages, setting AI usage guardrails to avoid shadow AI, and creating an incident response plan with clear contacts ...