Javvad Malik on AI Hype, CISO Priorities and Human Risk | KB4-CON 2026
Javvad Malik, Lead CISO Advisor at KnowBe4, joins Techstrong TV at KB4-CON 2026 to discuss what CISOs are actually worried about right now, what is hype and what is truly changing because of AI.
The conversation explores the shift from security awareness as a checkbox exercise to measurable behavior change and human-risk reduction. Malik also shares a broader CISO perspective on how security teams should evaluate emerging AI risks, prioritize what matters and prepare employees for a changing threat landscape.
Transcript
Hey everyone. We're back here in Orlando at KB4CON 2026, covering what's going on with KnowBe4 and agentic AI, and awareness, and cyber in general. Speaking of cyber in general, if you've been in the cyber community over the last, I don't know, 20 years or so, you may have seen this guy's face once or twice.
It's my friend, Javed Malik. Javed, so I started something called the Security Bloggers Network in 2005. That's right, yeah.
2005. Security blogging was fairly new back then. And then there was this guy out in London who started vlogging, video blogging.
Maybe 2007, something like that, 2007, 2008. He was the first time, and a lot of people were like, "Video? Who's going to watch that?
" Well, he was a little ahead of his time there, but he's been transcending ever since. But beyond just doing it in video, he's also one of the most respected people in the security community. Javed.
Hey man, it's great to see you here. Great to see you too. You look great.
Thank you very much. Thank you. Exciting year.
So Javed, I hope I didn't embarrass you, but you really don't have to talk about your background. No. I already gave it to you.
You gave a far better background than I could ever do. Well, I didn't want to... You're modest.
But, let's talk, you've been at KnowBe4 for seven years. That's right, yeah. When you first came here, it was a very different company than it is now.
Oh. It's been such an amazing journey, the last seven years. So when I joined, we were a private company, and even at that time, though, we were the leaders of security awareness training.
But that was everything we did. In the interim, we've gone public, we've gone private again. We've also expanded the portfolio of products that we've had.
So it's no longer just a security awareness training, although that's probably what most people still know us for. We do a lot more. We do communication security, so email in there, and now, we've just recently delved into the agentic space and protecting agents and AI.
And what does that mean for the world? Because we're looking at it as the workforce of today and tomorrow is not just a human, it's an agent and a human working together. So how do you manage all of that risk?
And that's where KnowBe4 is today. Absolutely. And your role has changed, right?
So now the title is CISO advisor. That's right. We had the pleasure of having Martin Cramer and Eric on earlier, and they've sort of defined what that is.
For them, it kind of transitioned from evangelist to actually truly being an advisor to CISOs, and not just CISOs, but to the whole exec teams and managing teams and so forth. Yeah. What does it mean for you, though, Javed?
Yeah. And I think that the distinction is really important, because I think when you're evangelizing, it's kind of like a one-way flow of traffic. Like, "Look how awesome we are.
Look at our content. " But when you pivot to an advisory capacity, it becomes a conversation. Like, "What is your challenge?
" So, like you said, we're far more engaged with the security community, our customers, and really trying to understand what are their pain points. And really listening. It's very easy on vendor side to just take the feedback and still build what you want to build.
" Even if it doesn't lead to a product sale, because what we're doing, we're building trust with the community at large. And I'm very grateful KnowBe4 allows us the opportunity to do that, and we can go out there and be effective and hopefully add value to people's lives. I love it.
We both mentioned this agentic AI and how it's kind of changed the mission. Look, it wasn't on the bingo card five years ago, right? Not at all.
This thing came on like gangbusters. Let's dive into that a little bit. You mentioned that KnowBe4 has now kind of rolled out specific products and solutions around it.
When I look at it is, we almost have two work... Well, it's one workforce, but we have two elements in the workforce, humans and digital workers. Yeah.
That's the world we're heading towards, right? And we're already here. Yeah.
Let's not kid ourselves. Is it possible, I think the answer is yes, I answered my own question, but can we train these digital workers to maybe be a little bit more security aware? Mm-hmm.
Can we correct past sins, is I guess what I'm asking. Can we correct past sins? That's an interesting one.
And I think for the immediate term, the answer is yes, given what we know about the capabilities and how they operate, how we can put guardrails around it. And I say in the immediate needs because guardrails still need an element of human oversight. And at the moment, say like you're a coder, and you put in some code and there's some guardrails, but you can still manually check the lines and say, "Okay, I don't think this is correct," and you can fix it.
Thing is like, in three years' time, if there's a new coder who's starting today, in three years' time, they might not have that skill to verify. And I think that's where the technical guardrails alone might not be sufficient becauseYou lack some. So I think it's important.
Technically, yes, we can build controls there, and that's what we're doing, and that's what the industry is trying to work towards, even the agentic providers are trying to build in better guardrails. But we can't lose sight that the human has a very important part to play in that, and we shouldn't let those skills erode out of laziness. Absolutely.
So there was a lot of talk, I was at RSA, what was it, two months ago, right? A lot of talk about human in the loop. And I get that, but I think the reality is that the scale of AI, the scale of agentics, is going to even tax the human-in-the-loop paradigm.
I think what we're actually going to wind up with is more of a human at the helm. Mm-hmm. So maybe taking the human up another level.
So that human in the loop isn't going to be able to monitor every transaction, every- Yeah ... iteration, every action. It's going to be at a much higher level because that's the only way this thing scales.
Now, how does that change KnowBe4's kind of go to market? Well, it changes it in the sense that we understand that the agentic piece is going to come bigger and bigger, and that's where you're going to need more controls and more guardrails around it. But then it ties together collectively the human element and the agentic element combined together into your organizational culture.
Culture, I think is the right word. It's in the sense that whether it's being your digital colleague or your human colleague making that decision, you want it to abide by what your organization culture is and what your values are. And if you can get that right, then it doesn't matter who's making the decision, because the output or the outcome is what you've decided.
I love it. Javed, you look around, you've been to a few of these. This one, does it feel different to you?
KB4Cons? Yeah. Yeah.
It does. I think this is the first KB4Con where our new CEO, Brian Palmer, I say new, he's been here a year. He just started just after last year's.
So he's here. We've got the new tool set. There's a whole bunch of re-engineering work that's gone in the background for the platform to make it where it is today.
So it feels like the soul is still the KnowBe4 soul, but the manifestation of it is like a startup again. It's invigorated, and it's an exciting place. Absolutely.
Javed, some people, they think this is the crest, if you will, right? That, okay, now we're getting used to this. We're going to have human at the helm, human in the loop where we can, but we've got our heads around, we got our hands wrapped around this.
We got our heads wrapped around this. If I ask you to look ahead to KB4Con 2027, you think that's going to seem naive? Absolutely.
I think if we see the last couple of years, the rate of progression has been unbelievable. Just yesterday, Perry Carpenter, my colleague, he was giving a talk, and he showed the Will Smith eating spaghetti video. Mm-hmm.
And it was just horrendous, like the mouth is in the spaghetti. Yeah. And then he showed one from a couple of weeks ago, a different video with Neil deGrasse Tyson, and you could not tell that it was AI.
You could tell because he told you that it was an AI thing. You knew before. Yeah.
But generally, you can't tell the difference. And this is only going to get further commoditized as we go forward. So does it pay to try to educate humans?
Or is it just going to be beyond human capacity to distinguish? I think it definitely pays to educate humans. And it's not about the technical correctness of something that is produced, an artifact.
In order for a scam to work, really, where if it's attacking a human, it's attacking your emotions, it's attacking you as a person. And so it becomes less about, is this a very convincing deepfake of Alan, or does this sound like how Alan talks? Is he asking for something that he doesn't normally ask?
Is he putting pressure on me? Is it invoking an emotional reaction? And those are the sort of things you can never outsource to a computer.
I agree. And I think that's the key. It's not whether this is Alan or not.
Yeah. It's what are they trying to get me to do? Yeah.
And is that something I should be doing or not? And I think that has to be the focus of this training. Yeah.
That has to be the focus of how we educate people. Absolutely. Because we're never going to...
I think it's a Whac-A-Mole game, saying, "Oh, this is a deepfake. This is real. This isn't real.
" That's playing Whac-A-Mole, and we might be right 98% of the time, but those other 2 times are going to bite you in the you-know-where and have a problem. It's more, I think, trying to insulate ourselves from what can go wrong, right, from harm there. That's right.
And I think it's about building those mental frameworks or models in people. And the analogy I often use is like, if I want to teach my kids how to cross the road safely, I don't take them to every single road in our city. I just teach them how to cross one road safely.
Right. Once they understand they have to stop, they have to find a safe place, they have to look, they can cross any road they encounter safely, and I think that's what the training should be more like. I think that's a great analogy.
Great. Hey, Javed, we're almost out of time, but for people who want to follow- Yeah ... you and what you're saying about all of this, what's the best place to follow you?
Since security, the community on Twitter kind of dispersed, I think all of us are all over the place now. Yeah. But I'm on LinkedIn.
That's a pretty good place to find me. I have my own website. You can find me on Mastodon or Bluesky, but I'm not as active as what I was on Twitter, so.
No, it's not the same. I'm also on all of those, but I find myself less and less- Yeah ... checking in there.
X, Twitter, whatever you want to call it, I have it there, but chances are it's not me. I also do go on LinkedIn a bit, too. It's one of the reasons why I love Techstrong.
It gives me a place where I can- Yeah ... do video, I could write articles, and still do that regularly now. That's it.
It's fantastic seeing you. Great to see you, man. Hey, man.
Take care, yeah. Javed Malik here on Techstrong TV. It's great having him on.
We're going to continue our coverage in a moment. Stay tuned.