Roger Grimes on AI Attacks, Deepfakes and Workforce Trust | KB4-CON 2026
Roger Grimes, CISO Advisor at KnowBe4, joins Techstrong TV at KB4-CON 2026 to discuss workforce trust, AI-driven attacks and how defenders should think about the next stage of cybersecurity risk.
The conversation explores the current arms race around AI attacks, including deepfakes, attacks against AI systems, data poisoning and the rise of AI-native defense agents. Grimes also discusses why trust across the workforce is becoming more important as attackers use increasingly sophisticated tools to target people, systems and data.
Topics include workforce trust, AI-driven cyberattacks, deepfakes and deception, attacks against AI systems, data poisoning, AI-native defense agents and human risk management.
Transcript
Hey everyone. Welcome back to our coverage of KB4 CON in Orlando. We are at the World Center Marriott here, which, if you've never been here, is just a huge complex.
Not going to have any time to do the water slides or any of the golf or any of that, but nevertheless, if you get a chance to come up to Orlando, it is a great place. My next guest is Roger Grimes. Roger, welcome.
So glad to be here. Roger Grimes, as we've been interviewing a bit, another CISO advisor, one of the six global CISO advisors at KnowBe4. Roger, first of all, welcome.
Second of all, look, we talked a little bit about what a CISO advisor is here at KnowBe4, but each of you have your own kind of unique background, your own journey to the role. Let's hear a little bit about yours. First of all, I've been doing it a long time, 39, 40 years.
I got into it in 1987. My God. " John McAfee had written a book about 1989 called "Data Diddlers," a bit like that.
Uh-huh. But right early on, I kind of got into fighting hackers and fighting malware and that sort of stuff. So I did many other things in my career.
I was a PC network technician, network manager, programmer, eventually became VP of IT over a couple of decades. But the entire time, my interest was in fighting hackers and malware. I started writing early on.
I think one of my first big professional writing gigs was for IBM on a paper, trying to prove that computer viruses existed, because early on- Really? some people thought they didn't exist. So I've been writing for a long time.
I've written 16 books. Really? And probably 1,600 magazine articles.
But I did a lot of it for many decades from inside as a field guy. I know the technology well. I know PKI and patch management and APIs and active directory and that sort of stuff.
So I did lots of things. I kept writing about it the whole time and how to defend whatever it was. So I think that's what I kind of bring, is four decades of experience of actually being in the field, what it's like to be somebody that really is fighting these threats and having to implement those things.
I'm not just telling people to do something that I haven't done myself, in most cases. So I think that's what I kind of bring to this, is be able to, deep technical knowledge. I know everything from password hacking, quantum computers, patch management, PKI at a very deep level.
And I don't want to say I'm the expert in everything, but I'm pretty good in a whole lot of different technologies. I love it. How long have you been at KnowBe4?
Over eight years, and let me say, it's been my favorite job ever. As a CISO advisor, I mostly speak and write, and maybe do some consultation with CISOs and other people. It's a dream job.
I can't believe I get paid to do it. I would pay people to do what I do. Shh.
Don't say that out loud. Yeah. Right?
But no, I agree with you, man. And the other thing is, look, for people like you and I that have been around, it's really a great time to be in this industry right now. We've seen this industry, what we today call cyber, we've seen this industry grow up over the last, for me, 30 years, for you, 40 years, into...
I mean, it's huge today, right? Security is on top of mind, or at least if you listen to the surveys, it's on top of mind, top priority and everything else. But it went from really almost being a cottage industry of people who maybe read a few books and were passionate, to really being a cornerstone.
Yeah. And you ready for the biggest surprise of my career? Go ahead.
Is that the same two biggest problems, which is social engineering and patch management, are still the two biggest problems today. I'm still amazed that we're having to teach people and educate people about all these different scams. That's a big deal, and it's even more difficult today because AI-enabled deep fakes.
But even patch management. So unpatched software and firmware is involved in about 30% of problems, 30 to 40% of problems. You would think over 40 years, we'd get patch management right.
Nope, we haven't got it right. So you want to know the truth? I'm not surprised.
I'm going to give you a little insight. I co-founded several venture-backed security companies. One I did was called Still Secure back in 2001.
Mm-hmm. Yep. Yeah.
2003, we came out with a vulnerability management tool. Like many at the time, it was Nessus under the hood for scanning, but we built this whole workflow around remediation. And I thought, "This is going to solve the whole vulnerability management issue," because we could separate what's real, what's not real, tell you what you got to do to patch, and push the button to patch.
Who wouldn't want that? Well, most people didn't want that, is what we found out. Yeah.
They weren't ready. Yeah, and now it's made more difficult because over half of the exploited vulnerabilities are zero-days. Well, no, there's- So there's not even a patch available.
And the trend is that's increasing every time. Yes. So in 2024, the amount of whether a vulnerability was a zero-day or not crossed over to 50%.
So- And now it's like 67%, probably going to be more. So to fight hackers and malware attacking vulnerabilities, you're going to need some type of AI-enabled tool that finds things, not only just unpatched stuff, but zero-days that don't have a patch yet. Yeah.
And you have to implement a mitigation that isn't a patch. Well, that starts with, as I say, aA patch is not the answer to a lot of these things, but there are remediations. You could isolate stuff, you could change, you could put firewall settings.
There are things you could do until you do have a patch for these things. And hopefully, because of AI, we're going to have more secure code one day. So I know from 40 years of experience that us humans have not been able to make code without vulnerabilities.
And right now, AI, because it's consuming all the human-created code, the code that AI is creating is as full as errors as the human-induced coding. But for sure, AI is going to improve to a point to where it's putting in less vulnerabilities. Yes.
So right now, AI's finding vulnerabilities. The good AI that we're going to be using is going to find and fix the vulnerabilities. And then learn it.
Yeah. And then I think even better is eventually that AI vibe code will actually have less vulnerabilities in it. So I think the net result a couple of years from now is we actually have more secure code that has less vulnerabilities.
I think that is the-- I wrote an article on this, and I did a bunch of videos on it. For me, the problem is, is this going to be a case where the operation was a success, unfortunately, the patient died on the table? Mm-hmm.
Right? Getting there is the problem. We've got this Mythos thing and the vulnerability apocalypse.
Last month, I forgot, was it 167? Microsoft's Patch Tuesday had 167 vulnerabilities. Google's had, like, 400 and something.
Yeah, we had over 48,000 last year. That's 132 a day, day after day after day of publicly announced vulnerabilities. Right.
I think it's going to at least double this year. Or if not, I'm predicting 100,000 vulnerabilities this year, half found by AI- AI ... half inserted- Inserted ...
by AI. By AI. But I think it's going to be kind of a one-time, two-year blip.
You think that's what it is? Yeah, eventually it's- It's just a rat with snake. Well, it's because AI is becoming so good at finding the vulnerabilities and it hasn't fixed them yet, I think we're going to see a one or two year, maybe three-year backlog of, oh my god, there's all these vulnerabilities.
But eventually, the AI is going to find less and less and less. It's going to start improving on the code that it is creating, and it's creating more code. So I think, I really predict this, and I put money on it, that three years from now, we're seeing less vulnerabilities.
I hope so. From your mouth to God's ears, Roger. Wouldn't it be nice after- It would be, after all this time We've been searching for our careers for more secure code.
I think- Absolutely ... I think the medicine is Mythos is the attacker. I think we're all going to have Mythos-like tools finding it and then fixing it, and eventually we're going to end with more secure code.
So, I had a similar experience when we rolled out IPS versus IDS. So the idea was, look, this is a garden variety intrusion, let's just block it. Well, no, we got to double check.
And it was very slow to adopt proactive blocking, right? Mm-hmm. Of running the note.
You got to be careful, right? You can create a self-denial of service attack if you're not careful. And all of those things.
I get it. But I do think we're in a similar arc with this whole Mythos. Because the problem is, though, with AI, it's not just that it can find the vulnerabilities.
In the wrong hands, it could also write the exploit, right? Yeah. And so because I realize now, and I didn't see it, I wish if I knew then what I knew now.
The gating factor for so much of our vulnerability and the whole web app space was human scale. How many scans, fuzzes, vulnerabilities can we find? How many are exploitable, or can we write exploits for?
How many can we actually, if you're a bad guy, how many can you actually do? Well, with AI, the floodgates are open on each of those things. Yeah.
The average time, according to the Zero Day Clock site. Yep. com.
The amount of time from the announcement of an exploitation or vulnerability to its first exploitation is now 10 hours. Right. It used to be months.
It used to be years, then months, and then even just literally a couple of weeks ago- It was days ... it was at least over a day. Now we're to 10 hours.
Well, I'm a big believer in trends, and if I see the trend, I'm like, that trend means it's probably, I think by the end of this year, going to be minutes. Minutes. And that's it right there, man.
Yeah. And there is this fundamental asymmetry right now in that the AI can find and exploit the vulnerability very quickly. The patcher has to verify that it is a vulnerability, has to create a patch, test the patch, then deploy it.
That's a fundamental asymmetry, meaning that the defender's always going to be behind. So we need to find things to go beyond patching, and we need more aggressive intrusion detection, more aggressive incident response, more aggressive logging, maybe some other things like inline patching or application firewalls, whatever it might be. But again, I think ultimately, we're going to see more secure code, and faster, more rich, aggressive incident response.
So you're going to have to, because if you don't, it's going to tear down your infrastructure, so. Absolutely. I very much predict in just a couple of years, because the pace of everything's increased, is in about three years, we're going to start seeing more secure code, more stable AI stuff that is able to respond confidently without taking down your infrastructure in the process.
No doubt. But we're definitely in flux because we don't have that right now. Well, this is sort of this, we're in this in-between.
Yep. Right? Intermediate stage.
But the thing that you and I have been looking for for decades, more secure code, more responsive systems- Is finally within grasp. Yeah. I know.
And there's pain right now, but I think we're- But we've had pain. Yeah. I even tell people, like, Mythos is able to find thousands of vulnerabilities.
" Like literally, it's finally doing what we've been- Always shop security. Right, exactly ... is that it's finding the vulnerabilities, and we're going to be forced to fix them and fix them faster and have more secure code because it just kind of got to the end state that we were all looking for the whole time.
So let me ask you. So you know Jen Easterly, the CEO of ISO. I know her all well.
She wrote a piece on this very much with that assumption, that we're finally going to reach sort of nirvana, right, which is what we always wanted: more secure code coming out, less crappy code. What does that mean for the security industry? Well, I think that we're always going to have jobs.
Or solid, whatever you might call it. Yeah. I think the simple stuff is going to be handled by the AIs and stuff.
And even the AIs are able to do more complex attacks, but there's a lot of things that humans so far innately see that systems don't see, or even... I'll give you a really simple example. " AI said 53 because it didn't have the scope and the context to embed itself.
Well, no, but that's the- And it's that times all kinds of problems. So I think human in the loop is always going to be an integral part of the process. That is, what you just defined right there, though, is sort of the paradox of AI is that it's so damn intelligent.
" But the example they give for that is if you go to an AI and say, "Now I need to put gas in my car, but I want to do it economically. There's a gas station just 50 meters down the road. " It'll say, "Oh, well, it makes sense to walk over," not realizing, well, how the hell am I going to get the gas in the car?
That's the AI paradox, is it doesn't take into account what effect AI's going to have. Yeah, and things that we innately know. So I think the nature of- That's why we got our securities ...
cybersecurity is evolving. But I'll throw you another thing out here, which is 70% to 90% of successful attacks involve social engineering. Human things- Yes ...
trying to trigger human emotions. Well, AI is very good at a lot of things. At triggering.
But what it's not good at is human. Yeah. And humanity and human emotions.
So I think you're going to have to have a human to really understand a human, and AI is really good at probabilistic pattern matching and looking through things and finding stuff, but I think you're going to have, the difference is the human, the cybersecurity professional, is going to be directing the AI to do particular things that they conceive and think of. We have the ability to have this huge, huge context that AI wish it could have, and be able to see and bring in a lot of different, what's called multimodal disciplines. So I think that when I see today's young cybersecurity efforts, I'm like, well, they're going to be using AI.
The AI is not going to replace them. They're going to be used as an extension of themselves and asking prompts and queries that it then helps to deliver, but it's going to take the human to kind of drive it towards what they're looking for. I love it.
I want to pivot a little bit because, hey, we're running on time. There's always the next thing on the horizon. A lot of people are saying quantum.
Mm-hmm. Post-quantum. We're going to have Q-Day.
There may not be a public announcement that Q-Day is tomorrow. We may not know about it till six months after, in fact, but Q-Day is coming, right? And the combination of AI with quantum, it could be the greatest thing for mankind.
It could be a real problem for security. I know this is something you've thought about, talked about, written about. What do you think?
Well, I think Q-Day, the day when quantum computers get sufficiently capable of where they're able to crack today's quantum-susceptible encryption stuff, like RSA, Diffie-Hellman, ElGamal, that sort of stuff, I think that's coming within a few years. I would say smart money would say a year or two within- At most ... 2030 on either side.
2029, yeah. You already have a couple companies like IonQ, they've publicly announced they think they're going to have the number of logical qubits needed to do it by 2028. Yeah.
So you have a lot of companies announcing it. You- Well, no, bigger... IBM and Google have planted the flag on 2028, 29.
Yeah, yeah. And then there's even some countries said that critical infrastructure has to be prepared by 2027. Yeah.
So, it is interesting. US government, through NIST, has not updated its prediction dates of- No ... 2030 and 2035.
Well, I got to give NIST credit, and I'm not usually a big fan. " But NIST at least has gone out ahead on these post-quantum algorithms. Yeah.
Yeah, and let me say, every company should today have an official post-quantum project. Official, meaning that you have somebody in charge of the project, you have executive senior management support, and you have resources dedicated to it. And you need to be moving your entire infrastructure, every piece of software and hardware that has electricity and an IP address in it, to post-quantum- Post-quantum approved ...
whatever that means, right now, and be finished by 2029. Along with Google, let me say, I think all the cloud services, all the big providers are going to be prepared. It's the on-premises stuff that's- Yeah ...
going to be the real challenge. And it's not going to be just moving to what's called post-quantum cryptography, although that's a big part of it, but there's lots of other things that you need to do along with it, and it's going to impact... I've done hundreds of crypto migrations in my life, from DES to AES and SHA-1 to SHA-2.
The PQC, the post-quantum encryption migration, is going to impact every person, every piece of hardware and software. It's like a Y2K kind of thing. Yeah.
And it's going to be a multi-year effort. No doubt. You need to start now.
So let me say it one more time emphatically. If you do not have an official post-quantum project enabled, you need to start one today. You're late.
Get on it. Excellent, man. Thank you for that.
I appreciate it. Great meeting you, Roger. We did something a month or two ago, the Quantum Security 25, 25 greatest leaders in this whole...
quantum security thing, and I had the chance to interview most of them. " Then five years later, it was still five years out, and five years thereafter. But actually, the joke was 10 years, right?
10 year, right. Let me say- Five to 10 ... I've been talking about quantum and Q-Day for decades.
Uh-huh. " Bruce Schneier, who's an acquaintance friend of mine, was walking by me- Schneier, Bruce, yeah ... and he was the keynote.
" Years. And I realized I've been saying 10 years for 20 years. At least.
But I think- No, no, but all kidding aside, we're two to three years out at most. I think- There's too much going on ... let me say, in my book, I wrote a book on quantum and quantum computing and Q-Day in 2019, and I predicted it would happen before 2030.
I think you're dead on. But let me say, but no, I was treated like a pariah. Really?
Most people in the industry just thought I was an idiot, and this guy really doesn't know what he's doing. Well, let me tell you, I'm not seeming so idiotic today. No, I think you're right on.
" I honestly, well, what do I know? But 2028, 2029, I think. But like I said, I don't think you're going to see fireworks going off it's Q-Day.
I think you're going to find out about it when some of these, forgot what the term is. If the US government gets it, we're not going to know about it right away. Well, you know they may have it, right?
Yeah. They have a history of doing- Keeping their eyes on it, right ... things in cryptography, and we don't know about it for a few years or more.
Let me say, it could be the US or China. There's definitely a fight, right? Absolutely.
Just like in AI, everybody's scared of everybody, and everybody's trying to get there first. So, there is going to be a lag, though, from when Q-Day is here versus when it gets in the hands of the malware actors, the people who have been collecting hashed vaults. Yeah, harvest now, decrypt later.
Yep. So, God willing, we'll have some time, right? Yeah.
I certainly think that you have to have a capable adversarial actor that's going against you, but we know a lot of countries target not just military things, but large companies to steal intellectual property. It's certainly wherever the money is, is going to be attacked. North Korea is famous for stealing cryptocurrency.
If they have the ability to get a quantum computer, they're going to go after money, period. Absolutely. And that's the scary part.
But, who knows what lies in- You never know ... Fort Meade and all those places, but it's an interesting thing. Hey, man, it's a pleasure meeting you.
Yeah, yeah. Pleasure. After 40 years in the industry, it's good.
I can't believe it. Roger Grimes, CISO advisor here for Nobl4. We're at KB4CON.
We're going to be back with more.