Erich Kron on Deepfakes, Phishing and Public Sector Ransomware at KB4-CON 2026
At KB4-CON 2026, Techstrong TV spoke with Erich Kron, CISO Advisor at KnowBe4, about how misinformation, deepfakes and increasingly convincing phishing tactics are changing the human side of cybersecurity.
The conversation also examines the evolution of ransomware in the public sector and why security awareness, resilience and human risk management remain critical as attackers adopt more sophisticated social engineering methods.
Transcript
Hey everyone. We're back here in lovely Orlando for KB4CON 2026 coverage, continuing our day here of interviewing really what's going on, I think, at the biggest KnowBe4 user conference ever. I want to introduce you to Erich Kron.
Eric is, again, a CISO advisor for KnowBe4. It's an interesting role, and Eric, as it turns out, is the original CISO advisor at KnowBe4. So, we're going to get a chance to find out how this whole thing came to be.
But first, let's say hello to Eric. Eric, welcome to Techstrong TV. It's great to have you here, man.
Yeah, it's great to be here. I always love doing stuff like this, and I love that you mentioned how big this conference is for a user conference. It's fantastic, and it's been growing- Oh, yeah ...
growing and growing. Well, let me ask you a question. Yeah.
How long have you been at KnowBe4? Oh, wow. I'll be 10 years in July.
That's really good. So, long time. Yeah.
Long time. That is. That's unusual in this industry, right?
Yeah. Good for you. I started when there wasn't much going on in the organization.
It was like, imagine a bunch of desks over here when you're walking through the floor, but mostly empty. Mm-hmm. Really?
It's been a fantastic ride. Yeah. Well, we're going to talk from there forward, but let's go before KnowBe4.
Yeah. Give people a sense of your personal journey of how you came to be at KnowBe4. Oh, wow.
I've been in IT and security since back in the 1990s. Me too. Yeah.
Worked for Microsoft on Windows 95 front lines of- Really? if that gives you an idea. Uh-huh.
1 network- LANtastic. I haven't heard that name in a while ... back in the...
Right. Okay. So, I've been in the trenches for a long time, worked up through different things.
Spent about 10 years with the US Army as a contractor, where I ended up the security manager for the 2nd Regional Cyber Center, and that was a big infrastructure group, O&M group for the Army. We did all the post camp stations, infrastructure between them, and just kind of did all that. And then, actually for a little while, I worked for ISC Squared.
Really? ISCIS people. Sure.
I was the director of member relations and services. And then next thing I know, talk about a big job shift. I'm now a public speaker, which was an amazing switch from being in the trenches- Right ...
all the time to now doing all of these public speaking roles and things like that. What a great career arc that is, man, right? It's good for you, number one, but it's a interesting transition, right?
Yeah. It's like for people who go from writing code to all of a sudden managing product. Right.
But as crazy as it sounds, that's a very logical path, right? Yeah. Eric, let's talk about, so 10 years ago you came to KnowBe4.
What was the mission? What was your charter? What'd you think you were getting into?
I honestly had no idea. I applied for this role just kind of on a whim. Somebody, a friend of mine and a person I worked with, sent it to me and said, "Man, you would be great at this role," and it was talking about public speaking, and my wife was like, "You know what?
" So, I applied for it. Next thing I know, I'm in a meeting room with our old CEO, Stu, and it kind of just was like, "Boom. " And kind of took me off guard, right?
I'd never done anything like this. " That was my whole charter. And I'm very German, right?
Mm-hmm. I like a box. I like to have guardrails.
Rules. So, that was a little tough for me to get used to that, but started trying different things, writing articles, doing some podcasts, webinars, things like that, and found the things that I really enjoyed doing within that, and the things that people really enjoyed from me. Now, somewhere along the line, I guess I have a natural gift for taking technical things and making them understandable for non-technical folks, and so that's been something that I've enjoyed doing ever since.
I love it. Now, so that's 10 years ago. Yeah.
Let's fast-forward to today. Well, not to today, but leading up to today. When did that "get the word out" transition to being a CISO advisor?
Yeah. " My original title was tech evangelist. Mm-hmm.
And that worked on, and I'd been doing it for about a year, and we hired another guy that came in, and we just started kind of working through it, and this has really evolved throughout those years. What's interesting about it is a lot of the message has been similar, or what we're trying to do, the mission is the same, but everything's different in the technology around it. And I like to think about the way the attacks were 10 years ago.
Social engineering attacks, phishing, number one. Well, you know what? It's still there, which is kind of ironic, right?
But our defenses have gotten better, but so have the offenses and the tools that they use. And so, we've had to kind of pivot around that to where we're trying to educate people on things, not only in the technical side, but also employees and people on the outside looking in. And I talk to a lot of leadership.
That's why we're CISO advisors. I talk to a lot of CISOs, too, and try to keep up with all this stuff that they're trying to keep the wheels on the wagon, don't always have time to put all that into research all the time. So, that's kind of what we do now, is we really try to educate people and get them to understand what the threats are we face.
Yeah. Excellent. Look, you and I have been around the block a few times.
We didn't really have agentic AI on the bingo card. Right. But it certainly has become theI don't even want to say the issue of the day, it may be the issue of the decade or the century, right?
How has that kind of changed your mission, changed the company's mission even? Yeah. Well, the LLM thing was a big deal there for a while, and we saw these huge leaps in what LLMs were doing, and that's where all the VC money was going, and of course, everybody, if you just said AI, they'd just send you a whole bunch of money and then ask later.
Mm-hmm. And we saw these huge jumps, but it's really started to get where it's smaller iterations now with the versions than we ever saw. But agentic has been bubbling under the scenes for a while, and now we're seeing it really pop up.
And what I think has changed a lot about our discussions is how we're treating AI, where before, LLMs are a product. It's what you put things into. Agents are a lot more like another employee because they're goal-driven.
They figure out how to do things and then use the tools they have, just like a person does. So we've really taken the mentality that agents are an extension of the workforce, just like other employees are. And I firmly believe within a year and a half to two years, pretty much everybody in the workforce is going to have an agent that's doing things like looking at their emails.
" We're going to see that all over the place. But a lot of people aren't thinking about what that means when it comes to giving permissions to one of these things to have access to all this. And so we're rolling it out quickly, but not necessarily understanding the risks.
And that's my big goal right now, is to help people understand the risks of that. When have we ever not rolled out something without understanding the risk? Right.
It's the security dilemma, you know what I mean? " Exactly. And we'll figure it out later.
We'll figure it out later, and then we're going to blame you anyway for it. But it has already fundamentally changed a few kind of, let's call it garden variety security. Yeah.
Not that they're not serious, very serious security risk, but things like ransomware, for instance, right? Yeah. Ransomware was a menace before agentics and AI.
It's more of a menace now. What are you seeing there, Eric? What do you think?
Yeah. I think it's funny because we used to see a lot of ransomware in a big way on the headlines all the time, and you don't see that that much anymore these days. But what people don't understand is it's still happening all the time.
Every day. It's happening SMB side instead of necessarily the huge enterprises. Right.
And so we don't hear about it every day, but it's still absolutely impacting organizations and individuals all over the place all the time. But it's kind of like, just breaches in general have gotten that way. I don't know if you remember when the Target breach happened.
Sure. " It was the world on fire, right? All these files, all this info got stolen.
" Yeah. It's just- Well, there has been a desensitive, A- Yeah ... I can't pronounce the word.
But we're desensitized- Absolutely ... to the... Because it's just an everyday thing.
Right. But I think what we need to be mindful of, and I think those of us in security know, I don't know if everyone else does, is how AI just makes this so much easier to do. Yeah.
How AI, kind of the scale of these things. Yeah. Right?
And that's where I actually feel like it does the most. People concentrate on deep fakes and like, "Oh my gosh, now it looks just like so-and-so," or whatever. Or sounds like so-and-so.
Or sounds like them. But for decades, we've had voice actors that sound just like this person, and they're like, "Oh, I'm sorry, I'm in the airport. " Yeah.
" There's always been that there. What AI has done is make it easier for people with less skills and infinitely more achievable and scalable for them. Scalable.
Because it's a volume, being a hacker and a malware guy is a volume business. Yep. Right?
If I send out 100 phishing mails and I got one person, that's okay. That's my business model. Yep.
Now, if I could send out a million mails and still get one out of 100... Yeah. My business just increased- And with the same amount of effort ...
Exactly. Right. Or less even- Yeah ...
because it's just done. And I think that's the biggest thing I think we're dealing with, is AI scale. Yeah.
And it overwhelms human defenses. Yeah. Right?
And so companies need to have solutions that are built to respond to AI scale. Yeah. Let's talk about KnowBe4 in that regard.
Yeah. How are you helping companies meet this at AI scale? Yeah.
Well, honestly, the only way to battle AI is AI. AI. No, I agree with you.
It sounds super cliché, but that's it. It works too quickly. It's on 24/7.
There is no SOC that's going to keep up with that. Agreed. We generate more and more data.
Look, when we started, 10 megabit network was like, "Woo," right? Two megabit was a standard. " Well, look at us now.
We're running two and a half gigs- 10 gig ... to the desktop, or 10 gigs around. Right.
Exactly. We're generating so much more data. Well, we have to analyze that data.
We have to look for things in there. We have to look for IOCs, right? The sheer volume of information we're sorting through will overwhelm any SOC analyst any day of the week, even the greatest, right?
So we have to use AI. We have to use these tools to keep up on that in order to keep it going, because it's being generated at such a volume, and the attacks are being generated at such a volume. But there's also another piece of that.
We have to have the technology involved, but we also have to make sure that our workforce understands when they're plugging in AI stuff and putting stuff in AI, like sending information to ChatGPT, they've got to understand what the risks of that are. It's never been a big deal in the past, but now we really have a lot of risky behaviors that happen there. And CISOs, organizations are struggling to come up with AI policies, so the people don't always have that much guidance.
And I love that we're thinking about that a lot. That's one of my roles is to try to help educate people and make them think about what are your policies. Because if you just say the policy is you can't use AI, everybody's still going to use AI, but it's completely out of control.
It's your shadow AI, to the nth degree. We need to be thinking about that. We need to be teaching people as well.
But then we also have our agents, like the agent risk manager that's out there looking at what these agents are doing. And for example, if an agent is meant to read your calendar and put things together for you, fantastic. Great.
Great job for an agent to do. But if all of a sudden that agent starts trying to delete stuff on your calendar, it shouldn't be doing that. We need to call that out.
We need to raise a flag, pull a human in the loop, and go, "Hold on a second. " Mm-hmm. And that's the kind of stuff we're doing behind the scenes.
Right. And we're so known for security awareness training, but we've been running agents, our Ada beta, which is kind of fun to say when you can say it right. Yeah.
Ada beta. Yeah. That started back in 2016.
Wow. We've been working with this stuff ever since then. We've just not ever really thrown it in the limelight.
But yeah. But now's a good time to do it, certainly, right? Absolutely.
And we're rolling out new agents that do things that are making, for example, the training a lot more personal. So instead of everybody getting the same course, if you go through your courses and you do things like you say, "Yeah, this is a thumbs up for me. I like this style," well, now it's going to weight that style towards you for your following training.
But the person next to you who doesn't like that- Is going to get a different experience ... is going to get a different kind. Right.
And that is, you know what, so that's the promise of this AI thing, right? It's perhaps the greatest education tool, educational tool that we've ever had. There's no excuse why everybody can't be more educated- Right ...
about, let's say, security in this case. Yeah. Whether it's at a company level, personal level, what have you.
Of course, I think we can't lose sight of the fact that the bad guys have this, too. Absolutely. And as you said, you almost need AI to deal with AI, right?
And so that's part of the whole thing here. Yep. 100%.
It's got to be a combination of people, process, and technology. I mean- It always is ... it always has been.
That hasn't changed. Right. Yeah, and I'm a big proponent.
I think policy has as much to do with dealing with human risk as any other part of it as well. It's got to be a piece of that, but it's got to all work together, and that's where I've seen, throughout the years, a lot of organizations were very disjointed. But I like to see, I think they're starting to realize that a little bit more and putting these things together, which kind of makes me happy.
Good. If you're happy, I'm happy. Hey, Eric, we got to wrap up.
For people who maybe want to stay more on top of this, follow what KnowBe4 is doing and what you're doing- Yeah ... around this whole governance, scaling up to deal with it, what's your advice to them? Yeah, if you want to look at what I'm doing, LinkedIn is the way to go for me.
I really try to avoid Twitter/X/a lot of the social media channels. You and me both. I hear you.
It's just not the same anymore. And sometimes the signal, the noise gets me crazy. Absolutely.
So I do most of my stuff on LinkedIn. But then I'm also on a lot of webinars and a lot of podcasts and things like that, so you can absolutely catch me on some of those, too. All right.
So. Hey, man. Thank you.
Pleasure. Great show. Keep up the great work.
We'll be in touch. Thank you. All right.
We're going to take a break. We're here at KB4Con 2026 in Orlando. We've got a lot more coming.
Stay tuned.