Kawin Boonyapredee on Human Risk Programs That Actually Work | KB4-CON 2026
Kawin Boonyapredee, CISO Advisor at KnowBe4, joins Techstrong TV at KB4-CON 2026 to discuss practical ways organizations can improve security awareness, operationalize human-risk management and build more mature programs.
The conversation explores common security-awareness mistakes, what separates mature programs from checkbox training and how security teams can move toward measurable behavior change across the workforce.
Transcript
Hey everyone. Welcome back here to our KB4 CON coverage. We are in Orlando talking security, talking AI, agentic AI.
We talked a little bit about quantum and deception and other things. Let me introduce you to our next guest. His name is Kawin Boonyapritti.
Kawin is a CISO advisor with KnowBe4. We kind of discussed what CISO advisors are. But let's, first of all, Kawin, welcome to our show.
It's great to have you on here. Thank you for having me, Alan. Kawin, I've asked each of the CISO advisors that we've interviewed the same thing.
How did you get to be a CISO advisor? What was your path? Yeah, great question, Alan.
Life is, you never really go through life planning everything, right? Nope. So for me, I come from a family of medical doctors.
Okay. So I was basically out of the womb, ready to become a doctor, basically. So everything that I did since the teenage years, working in hospitals, doing pre-med.
I was born and bred to become a doctor. But, when you discover, you grow up, and you get older, you find out that, hey, I can make a choice. There are choices.
I can choose. " I'm- How did they take that? Oh, I was so scared about them disowning me, but eventually, they accepted what I do.
Eventually. So, that was in the mid-'90s, and, eventually, I've always loved computers, and held summer jobs during my college years doing IT support. And then towards the end of '99, when I graduated, it was the tech boom.
Mm-hmm. So, everyone and every grandmother was going into IT. So fortunately, after I graduated, I got a job.
I moved up to New York City and started out my IT journey there, so in the 2000s. And, fast-forward 10 years, I had many jobs in IT, networking, systems, and eventually into information security. That's when they called it back in the 2000s.
InfoSec. You and me both. InfoSec.
Yeah. InfoSec. So, got the opportunity to work in large banks, working in a global SOC, eventually being promoted to lead the SOC.
And then after that, I got the opportunity to build an entire InfoSec program for a financial services firm in California. Really? So I moved to California, built everything up, people, process, technology.
This was, like, 20 years ago. Mm-hmm. So imagine how fortunate I was to get that opportunity to build everything top-down.
Yeah. And then what happened after that was, financial crisis hit, did some self-discovery and found my way, eventually, in Singapore 15, 16 years ago. Really?
So I've been to Singapore now. So I've gotten half my career in the US, North America, now half in Asia. Love it.
Yeah. I had a similar journey. I was told I was going to be a lawyer from about the day I was born.
Right. I wasn't smart enough to chicken out in third year, though. I went through the whole thing.
Right. Went through law school. Right.
Became an attorney, did that for a few years. Yeah. But the computers were my passion.
Right. And then when the internet went commercial in '96, '97- Yep ... I, not by any plan, just found myself- Yeah ...
starting something, and I've been- Wow ... in computers ever since, and I never looked back. Yeah.
Also, in New York- Mm-hmm ... I was down in what they called Silicon Alley back then. Remember that?
Right. Remember that? Yes.
And then, sold that company, helped take another company public during the dot-com, and then started another security company. I got into InfoSec and- Right ... that was out in Boulder, Colorado.
Oh, wow. Okay. So I was out there and- Yeah ...
so very similar kinds of paths there. It's interesting. No one ever talked to us about AI and agents, though, back then, huh?
Right. It's a crazy- Well, now it's all about- Right ... nine point nine percent.
Well, the whole world is focused on this now. Yeah. Talk to us about becoming part of KnowBe4, though.
When did that happen? I know you're the new guy. I am the newest CISO advisor of KnowBe4.
However, with 30 years of experience and, ex-CISOs, ex of information security, I'm also an ex-customer. Oh, okay. So I deployed- Those are the best kind.
So about half a decade ago, I was head of enterprise security for a large company. Mm-hmm. And, the first software bill of material, SBOM, that I had was security awareness.
" Mm-hmm. So I purchased KnowBe4, the K set, and deployed it to our 5,000 end users. And you know what?
Looking back now and reflecting, it was the best customer success story that I've ever had in my almost 30 years of experience. I love it. To see the difference it makes to just train the human.
Yeah. You look at people process technology, but it's always back to the human. Well, in security, it really is, right?
The person behind the keyboard was always that weak link. That's right. No matter how much we invested in- Mm-hmm ...
process and technology- Yeah. You can- ... it was the people ...
you can have the strongest policies, you can have the highest walls, but you have that one person that clicks on something, or lets something in, or pushes something out, game over. Right? I love it.
So I saved this question for you because, as I said, we spoke to four other CISO advisors today. Yeah. But I haven't asked them this.
I'm going to ask you this. All right What do you consider your mission as a CISO advisor at KnowBe4? That's a great question.
So I have the advantage of being an ex-CISO. So, I was constantly getting my door knocked on by every single vendor and product, a new thing, new shiny thing. Mm-hmm.
But what I always found out was that anything that relates to the largest trends and largest threats now, which is back to the human, like we said, but also the growing threat of AI, artificial intelligence. And, for me to realize that KnowBe4 has now expanded their core from just humans now to the AI digital workforce, it is going to be a game changer. So for me as a CISO advisor, I would probably put in these thought leadership pieces on what's coming up for these C-levels, for the boardrooms to understand, what do I have to stay up for?
What do I worry about? What's coming that I need to prepare for? Because cybersecurity, unfortunately, has always been very reactionary, right?
Mm-hmm. We need to get to the point that they can become proactive, and that's my role. That's my mission and vision.
I need to provide thought leadership to these top-down people to understand these are the drivers affecting your organization, your industry, and how do you tackle this? Sure. Yep.
I love it. Yeah. I should have asked this, and I didn't.
How long are you with KnowBe4 now? I'm only about two months. Okay.
Yeah. So have you had a chance to kind of test the waters here? What's the feedback been from CISOs?
So, APJ, Asia, we actually haven't had a CISO advisor for a few years. So the sales team, CSM teams, the partners that I've been meeting with these just 60 days feels like 600 days- Right ... has been astronomical.
They're like, "Kaiwin, this is fabulous. " So for me, it feels like a natural fit for me. I've been a public speaker, an adjunct professor, and speaking about and promoting and pushing cybersecurity has been my mission.
And putting this hand-in-hand with KnowBe4 has been just peanut butter and jelly together. I love it. Kaiwin, I want to ask you something specifically to APJ.
Okay. Right? Because some of the other CISO advisors, we've had two from the US, two from EMEA.
Yeah. What's different about APJ? There was a time, you and I have been in security 30 years, right?
Yeah. We used to think, well, Europe was 18 months behind the US. Mm-hmm.
Basically. Yeah. APJ, maybe two years- Mm-hmm ...
behind where we were here. But that's not the case, and it hasn't been, I think, for a while now. Right.
In many ways, APJ is leading- Mm-hmm ... especially when we talk about things like deepfakes and agentic. A part of it is because you're on the front lines there, right?
There are countries in the region that are notorious- Oh, yeah. Mm-hmm ... for malware and hacking and- Right ...
this kind of activity. Right. Do you see anything APJ specific?
So two sides of a story here. I would say APJ is quite unique because digital adoption is very, very rapid there. Less legacy.
Yeah. They're more eager to adopt than- Exactly ... those things.
So new tech of doing QR codes for payments- Yeah ... to not needing cash anymore. Mm-hmm.
It's been a trend over the past five, 10 years now. So, the unfortunate thing is that with the rapid adoption, people don't understand there are threats, different attack surfaces that come with that. " Right?
Yeah. So that's one huge thing in Asia. The other thing is that, the unfortunate thing, when I did my dissertation, I did research on the fintech industry, which is very huge there.
But there are cyber challenges, and one of the themes that came out of my research is that compliance, they always saw, was equal to security. Which in cyber, 30 years, compliance- It's the lowest common denominator. Correct.
Compliance is not the ceiling, it's the floor. Mm-hmm. It's the minimum- Right ...
you have to do- That you need to do. Yeah ... to check that box.
Box. If checkbox is what you're about, right? Yeah.
If you just want checkbox security. And look, there are industries and corporations that may just be satisfied with that. Mm-hmm.
Others that understand the threat landscape and the need to be more proactive, they have to be there and implement controls, technical, administrative, and look at the humans and AI, because AI is just taking over the world. I agree. Yeah.
Agreed with you. I agree there. So Kaiwin, I'm just kind of looking at our things here.
Mm-hmm. Typically, people know KnowBe4 security awareness training. Now, as you mentioned, we're talking about digital workforce in addition to human workforces.
Right. What do you see, and obviously you're only here 60 days, but as you said, you were a customer, you've been a CISO. What are the most common mistakes you think people are making as we roll out these agentic AI systems?
I think the biggest challenge right now is people just don't know what they don't know. Right? "But they don't have the proper guardrails to understand that these agents, they have agency, and they can chain together complex tasks using tools from outside.
Right? So imagine a new work digital workforce that has all this access to your information, to these tools, but doesn't have the ethics to understand what's right from wrong, what's private and what's not private. So it will treat every data, every information the same, whether you like it or not.
Right. Unless you classify it, but most people, unfortunately, in 30 years, data loss prevention and classification has been extremely difficult- Yeah ... if impossible.
So most- We've never cracked that nut. No. Never have.
Mm-hmm. So it goes back to this then, agentic AI, they can push trade secrets out and say, "Oh, yeah, we're going to leverage this to do something more efficient," without even blinking an eye or a digital eye, right? Mm-hmm.
So that's a huge worry. " Right? And one of the major things that they have to realize, humans in the loop is a new thing.
Right. You have to have a human. And I was actually at a graduation two weeks ago for a secondary school.
So these are the people going into STEM- Right ... science, tech, and all that stuff. And these students, young bright minds, and they asked me, they're like, "You know what?
" I'm like, "You know what? " A lot of people get hyped and use that kind of marketing term. Mm-hmm.
But you can't look at it that way. ' Use it. Embrace it.
" I frame it a little differently. I tell people, "AI's not going to take your job. " That's a great...
I love it. Right? I love it.
Yes. And I think that's what people need to embrace. Yeah.
That's right. Right? Because if you resist- Yeah ...
that's when the car hits you- Yeah ... and you're roadkill. Correct.
If you embrace it, you 10X yourself. And that's what I tell the people at Techstrong. Again, my sons are early 20s.
Mm-hmm. I tell them and their friends. Right.
They need to be embracing this. Yes, absolutely. So if I go back to your question, being here only 60 days and seeing the new releases from KB4CON, doing agentic risk management or agent risk management, that's a game changer.
Because we're not only leveraging our 15 years of our knowledge in securing the human, we're now securing the digital workforce together. And that's what keeping most CISOs up at night. All my friends in Asia.
I agree. Yeah. I don't think it's just Asia.
I think there's a lot of CISOs up at night. Yeah. Oh, globally.
Yeah. And again, you've been a CISO, you know this. I think the CISOs, they always have a hard road.
Yeah. But what's harder today for them is the contrast, right? Mm-hmm.
Their security people are saying, "We're not sure how secure these things are. " Right. " Yeah.
" Mm-hmm. But at the same time, from up top- Mm-hmm ... they're hearing, "We need to use more AI.
We need to leverage AI. " Yes. "We're going to maybe cut heads.
" Yeah. All of a sudden, the door's opened up. " Right.
"You're not spending it on AI-" Take my money. "... " Right.
Yeah. So, what's a poor CISO to do? That's what he's hearing from up top, and he's got to take his marching orders.
Yep. " Correct. Yes.
What is a CISO to do here? It always felt like when I was a CISO, we were winning small battles, but we're losing the war, right? There is that.
Because we're against an adversary that has two things that we don't have. Mm-hmm. Time and resources.
Yeah. Agreed. And as a CISO of an organization, we're limited by the time, we're limited by the resources.
Always. So, what do we do? And I was in a part of a talk, and one quote resonated with me that we'll always be two steps behind.
Right? And this was- By definition, we are. Yeah.
Because- Absolutely. Absolutely. So, what is a CISO to do with this whole proliferation of AI, getting pressured to do it?
But vendors understand that. That's why every vendor you see is like, AI powered, AI powered, AI powered. Is that whole true?
So as a CISO, responsible CISO, you need to lift the hood. You understand exactly what do they mean by that. Because you can't just deploy something and say, "AI," but it's really just a chatbot or a person in the background doing something, which actually has happened.
Mm-hmm. Right? So as a CISO, you would probably have to look forward and do due diligence on the products and the solutions and the services that they offer.
Right? And two, protecting your environment is number one, right? Your data.
So go and understand what you have today. Leverage a technology that gives you that visibility, number one. You need to know what you have.
Right. So, shadow IT has always been a term for the past 20, 30 years- Yeah ... as you know.
Especially cloud. Shadow AI is a new thing, because people are blindly putting their data in, asking queries from ChatGPT or OpenAI or any chatbot, and not knowing that the information may be going somewhere else, right? There's been cases where people are uploading some of the data and say, "Oh, organize this for me," and this is like payroll data.
Mm-hmm. Yeah. And imagine that.
It's just getting in trouble. Yeah. Yeah.
Agreed. Yeah. Agreed.
Last question. Yeah. If we're sitting here at KB4CON 2027 looking back at 2026- Mm-hmm ...
were we successful? Absolutely. I think the future of agent risk management now, with our Ada orchestration platform to help on awareness training, is going to be the key of this year, the theme.
Because AI governance is the key word. In every organization, every industry, and every conference that I've been to, we need to talk about that. We have been talking about it.
Everyone listens up, because that's a new thing. Agentic AI is not going to go away. It's going to come into full force and come in like a big flood.
Yeah. Yeah. So looking back, if I was here a year later, I would say we are going to be on top, because we are offering a solution to a problem that many CISOs and C levels are looking at right now.
I love it. Hey, man, thank you. Thank you.
Good luck with this new position. I'm sure you're going to do great. Thank you very much.
I may have to come out to Singapore and see you there. Absolutely. Come out.
I haven't been out in two years, so it's time. Yeah. We're going to take a break.
We've got more KB4CON coverage coming at you all day today, so stay tuned for our next interview. We'll be back in a little bit.