The Evolution of Cybersecurity: Understanding Phishing 3.0 with Eyal Benishti | RSAC Conference 2025
Cybersecurity is evolving, particularly in the realm of phishing. Organizations must adapt to the shift from basic scams to advanced attacks. Phishing 3.0 emphasizes mailbox protection and communication trust. While AI aids in detecting phishing, it also empowers attackers. Automation is vital for security teams, and the future of phishing includes deepfake technology, highlighting the need for user education and proactive defense strategies.
Transcript
Good morning. Welcome to Techstrong tv, day two of our coverage, live coverage of RSAC from Moscone West in San Francisco. This is Techstrong's, 10th year of covering RSAC, but of course, our fearless leader, Alan, has been coming here for much, much longer than that.
We've been talking with cybersecurity experts about really the evolution of the security landscape. My next guest is Al Bei, the CEO and founder at Iron Scales. Al, welcome to Text on tv.
It's great to have you. Thanks Lisa. Good to be here.
I love the name Iron Scales. It's such a powerful, bold statement. Talk a little bit about, you said you founded it about 10 years ago.
What were some of the gaps in the market at the time from a security perspective that you thought we can solve this? I think there were two main gaps. I think the first one was that phishing was still making into the mailboxes.
Mm-hmm. As a security researcher and malware analyst, that was where I was finding all of the great ideas on what to investigate research. And the second is that teams were spending a lot of time dealing with this type of threats, getting them out of the mailboxes, making sure that people, um, are well.
Uh, and there was a shift, a big shift in the, in the landscape where threat actors were starting to understand what the defenders are doing, what the sex are doing, and looking for new, more clever ways to fish businesses and, and employees. Phishing has evolved so fast. It used to be clunky basic email scams that like spelling errors and it was just obvious it was a phishing scam.
0. Where are we now? 0 DeepFakes.
It's just evolving at breakneck speed. Yeah. 0 problem where FedEx was mostly sending bad links and bad attachments and trying to lu employees to click on a link or download an attachment and install some backdoor on their, um, computer.
And then it really evolved, like no, with the security email gateway was kind of scanning links and scanning attachments and making sure that all the known threats are out of the, the inbox. The threat actors, they evolved into sending emails with no links and no attachments. And instead of trying to hack your computer, they're hacking the business process.
They're trying to make you pay a, an invoice, which is not really, it's fake. Okay. Pay an invoice Or wire some money, or go and buy something or do do something that you are not supposed to do, um, as an employee.
And when you think about what cus what companies are using that day in order to protect against l they couldn't found this email because, uh, there was nothing bad. Yeah. They looked so normal.
They looked very normal. It was sexual, like the semi legitimate request to do, to go and do something. 0 era basically began and we realized that in order to really protect organizations and people against phishing, you really need to go down from the gateway level to the mailbox level.
We have to live and breed what's happening in everyone's mailbox. Really, really understand it, you know, what communication looks like, what what can be trusted, what can't be trusted, understand language. Yes.
For first time using LLMs and NLPs to extract intent out of, uh, emails and understand that these people is asking someone to pay something and really start to understand that this person really sounds like, or looks like someone is walking Like your CEO asking you to wire money or something. This impersonation of people is scary. It's always someone or something that you already know that you're Familiar with.
Exactly. Okay. Exactly.
This is kind of the basics of, uh, fishing and how you kind of gain trust and make sure that people will go and do, uh, what you're doing. And that was the phishing two point era, and we started to implement a lot of the smart AI and ML models in order to be able to build baselines Yeah. And find anomalies and things that are kind of deviating from what we consider to be a trusted communication or trusted, um, email.
It was proven to be super effective against the, again, the bcs, the business email compromise and the vendor account compromise account take over Vertex and all of the next gen type of, uh, phishing emails. The site was really not doing a great job in kind of keeping out of the the gate. 0 World Security teams were doing a lot of manual work in order manual work To keep The, the hygiene of the, uh, environment and the in books writing and running scripts, um, doing a lot of, uh, signature writing and rules writing.
And they really kinda spend a lot of time with the email security solution in order to try and keep it up to date and play this kind of catch up game with the, with the product. 0 we, we, we've realized and decided that it's time to really go and automate, I was gonna say automation. It sounds like the, the winner here.
You have to go and automate a lot of this kind of stuff that, um, they're doing from the most kind of investigative, uh, parts of the security analyst job to the even more kind of response part, which we actually go and claw back emails back from employees mailboxes. It was a novel idea. Like, you know, it was like how you can actually go and pull back, back emails that were already, and answer was yes, you can do it if you can do it in a very short amount Already opened, Not opened.
Okay. But delivered. Delivered.
Yeah. Got It. Because we know it takes about 82 seconds from the time it was delivered to the time it's, it's opened on average.
Okay. It's 82 seconds. It's a lot of time that we can act Yes.
Not to mention if we can do it in under one second. Yeah. Which is what we can do in 99% of the, the cases.
Right. Then the problem, uh, goes away. And by doing that, first we reduce risk and second we reduce in more than 90% the amount of time the threat act that the security teams are dealing with, uh, phishing emails in order to keep them out of the mailbox.
Yeah. The automation is key there because you were saying, you know, the, with this rapid evolution of phishing, security teams don't have the time. I'm sure that's a full-time job for, for several FTEs to just monitor a business email account across employees across the globe and regions.
So the automation is critical there, especially because the sophistication of phishing is just going up and up and up. How is AI maybe a edged sword there, like leveraging it for, um, to be able to detect these really sophisticated phishing scams, but also the, the fissures having the technology at their disposal to dial up the sophistication? It's A good question.
So with the introduction of technologies like GPT for example, we've seen an increase of 1000% from 2022 to 2023 in AI generated, uh, phishing game Phishing scams. And this was 1000% before The peak. If you look at North America, uh, alone, it was close to 2000%.
It was 1700 something. Yeah. Uh, percent, which is a, a, a crazy amount of, uh, emails.
And the other thing is that phishing, phishing in 2025 or even in 2024, it's not just about email anymore. Like, you know, phishing in email used to be a synonyms like no. Yeah.
Email phishing. It was like almost, uh, the same thing. Now we're seeing new modalities kind of thing.
Produce Voice, Voice deep fake voices. That's Scary. 'cause fake videos so legit.
Oh, and videos too. Videos, Yes. So they're using modern email to phish employees.
They can use your, uh, mobile, they can use your teams slack, zoom. Wow. And we are seeing already, we're seeing kind of real cases That's that attack surface just going like this.
Now you need to kind of be able to look at all the communication channels and make sense out of all of it and detect not just AI generated stuff in the inbox, but you need to be able to detect AI generated stuff in your teams and in your stack and in your zoom and make all the relevant, uh, correlation. Because phishing now is a multi-step multimodality, multimodality, multichannel Yes, yes. Type of thing.
Omnichannel. So it's, It's evolving again, and it's evolving in a very rapid phase because AI is doubling every six months. Right.
And now, which is pretty, The acceleration is, like I said, breakneck speed and it's not gonna slow down. It's only going to somehow get faster. It's getting faster as will the sophistication of phishing.
So It's getting faster. It's open source. So everyone has access to these type of tools, uh, right now.
So they can use the, like you said, it's not just for the defenders for us to extract 10 out of images, it's for them to go and generate new type of, uh, attacks as well. Where Do you see phishing for data? Where is it going and and what's the timeframe?
Do you what, like what's next for it? 0. And this is where companies, and again, if you, if you ask Garner, they say that in less than five years, more than 50% of the organizations will have some type of deepfake security control.
Currently it's single digit, very low single digits. So Okay. It's only gonna increase.
Only gonna increase, uh, significantly. So I think we will see, um, the evolution and the adoption of the controls, uh, to control, uh, deepfake. I think we'll see a huge increase in how we are training our employees and users.
Yeah. To look at the end. We get to the point that at the trust is vCAN trust is under attack.
You can't really Absolutely. And it, but it's currency. So it's so important to be able to have that with whenever customers, business customers, consumers.
That trust is just, it's, it's required For 10 years. We're trying to teach people not to trust everything they see in their inbox. We can't Exactly.
Now we need to go and teach them. Hey, you can't even, you can't even believe things that you hear. Even if it sounds like someone that you know, or even if you see them on the other side of the screen.
Yeah. That might not be them. Right.
The CEO, the CFO, your colleagues in this country on the screen in front of you might be an AI generated version of them. And that's a big leap. Like, you know, we really struggle with getting people kind of used to the fact that email should be kind of scrutinized before.
Yes. Um, you're engaging with that right now to get them to the next level will require a lot of work, a lot of awareness and education. Um, I Was gonna say, how much of your, of your time is really spent on that awareness education piece?
Because humans are often the weakest link in the cybersecurity chain, but can be the strongest. But I imagine it's with all the generations alive today in the workforce, there are some that are more susceptible than others, but how much time do you spend teaching businesses why this is so incredibly vital to their brand reputation? So we highly encourage it.
It's part of our platform and we always say that people can, your people can be either liability or an asset. Yes. It's up to you to decide how you want to utilize it.
Absolutely. If you invest, really invest in a good program and a product that can go and give them not just the knowledge because people know about fishing. Sure.
They need better tools. They need to tools that can augment their experience with email. They need tools.
They can report back and get some feedback about what they're seeing in their inbox. And if you do that, it's not just that you get a better kind of last layer of defense, which is a must. Like, you know, there is no way even with the smartest AI on the world, that we can stop 100% of the, the attacks.
There will always be this human kinds of, um, in the loop component that we will need to kind of settle, take, take a second look and say, yes, you know what, this is fishy. Yes. This is something my security team needs to, to know about.
And not just that we need them because we want them and we actually do that. We use them in order to feed their feedback back to the machine and tell the machine, Hey, this is something that a human reported to us. Okay.
And the user expert, like, you know, security analyst validated for us, learn, adapt. This is why we call our AI adaptive ai adapt, adapt AI and get so it won't happen again. So if you are not closing this loop and you're not closing this loop quickly, you are always one step behind.
And with AI you are two steps behind. Yeah. Because they can go and generate so many different new instances of phishing that it's like Yes.
And now AI is becoming agent. Right. 0.
Sure. AI is become becoming agent, which means it'll be very autonomous in danger. Yes.
Yes. Which even means that even the threat actors, they don't really need to sit down and even prompt GPT to generate an email. They can just say, Hey, go and fish text on, find a way, find the employees.
Yep. Find their areas of interest, write the phishing email, deliver it, create the landing pages, do all the thing, and AI will go and do all this kind of things. Yes.
So we're now at the point that we cannot be, uh, reactive anymore. We can't sit back with our defenses. No.
But how do we get proactive? Is that possible with the speed with which everything is ex is evolving. You fight fire with fire.
Yeah. So if we fought against ai with ai, we are gonna fight agents with agents. Okay.
You have to build agents that will help you be more proactive about how we should go about defending our inboxes. Yeah. How we should train our users.
Even for the soc the analysts like, you know, we can do much more with the Gen d, KI in order to take over more of the responsibilities and even automate further a lot with the things that they're doing on a daily basis. 0 gen deepfake, um, issues. We have to do it uh, pretty fast.
Otherwise we catch also. Right. That speed is critical.
Last question for you as we wrap up here. What excites you from a security perspective? We've seen, like I mentioned, the threat landscape is just getting more spread out.
AI brings more complexity, yet every organization has to have an AI story. What positives do you see from a cybersecurity perspective that we're going in? I think the biggest one is our, the, for the first time in history, defenders will be able to be proactive.
Okay. We really tend to be That's good. Expensive.
That's good. We are in install, we are putting our technical controls, our anti bio, so endpoint detection response and email kind of security component. And we are sitting and waiting for something to happen and we are hoping that our defenses will catch it and stop it.
And yes, we're training our users as well, but for the first time we can go out there and say, Hey, we wanna really be proactive and understand how threat actors view us and how they're gonna attack us. Let's do it before they do it to us. Yes.
And make sure that we are ready. Let's do this continuous battle test and make sure that's not hope. Hope is not a good strategy.
No, it's not a good strategy. Being proactive and making sure that we're ready is something that is now doable and what we believe the future of cybersecurity is gonna look like. Thanks to Ai.
I like that. Aal, thank you so much for joining me on Textron. This is a fascinating conversation, the evolution of fishing.
It's gonna be so interesting and kind of scary to see where it goes. But great to know that there are proactive defenders like iron skills. Thank you for sharing your insights and your time with us today.
Thank you. It was a pleasure. I mine too.
For my guest, I'm Lisa Martin. You're watching Textron TV live from the floor of RSAC. This is day two of four days of coverage on Textron tv.
But you know that 'cause you've been watching since yesterday. Stick around. Our next guest joins us in just a minute.