Jun 8, 2026 · 54 min · 14 segments
We were honored to welcome Chris Girling, Partner, Cyber Risk and Resilience at PwC Switzerland, onto the…
Chris GirlingGuest
Paul TomsHostRoseHost

I think for many years in the world of cybersecurity, there's been a very strong doctrine around risk.

And what are the things that we're absolutely sure that a human attacker would spot? What are the things that maybe could last a bit longer that probably would go unnoticed by an attacker? And you just don't really have that anymore with AI.

I think we've just seen at the end of last week, this story about Anthropix model, which was built for security testing, breaking out of a sandbox, which people always assume that sandboxes are totally secure.

I mean, human hackers have been able to show that you can break out of sandboxes in the past as well if they're not that well protected.

But the speed that this AI achieved it at after it was given the instruction to do it and the fact that it achieved it and then reported back in a seemingly boastful way that it had achieved that, of course, got headlines and got people focused on the topic.

The reality is over the last couple of years, the speed of security has just sped up exponentially.

I think there's, I just say some data points because I love checking in on the data, but there's something like 4,000% increase of phishing, 4,000% in a couple of years, or the time that the hacker can be on your network unnoticed before they start spreading across the network.

I think the average used to be about 120 days, three or four years ago, down to about 27 minutes at the moment.

And I think Google showed last year that the average time, the number of days after a software company announces that they found a vulnerability to when hackers figure out how to take advantage of it, if you went back three years, that would be two months.

So Microsoft or someone would come out and say, we found a new vulnerability, here's a patch.

the average based on last year's data is now minus one day on average they're exploiting it before the software company even knows that it's there and it's just the whole speed of things the biggest mentality change that everybody has to i think make and we i see organizations at all different levels is recognizing that all of the optionality of security is really disappearing, and you really have to focus on speed of doing things, and to a degree you have to accept a bit more operational risk, or at least on the face of it you do.

I think the old doctrine would be you would roll out some patches on your unimportant systems, then you would have a lot of human beings go and test that everything's working, And if it's fine and they will fill in the forms, then you would deploy the patches onto your sensitive systems.

Need to be doing that in 48 hours or less now to deal with some of the challenges we've spoken about.

You have to automate all of the testing, sequence all of the patches, and just have it as a continuous process of launching new patches.

And I think if you really understand technology on a fundamental level, There's not very much more risk in doing that.

There are ways you can engineer the technology to test itself and make sure that it's secure.

But there's a huge number of people that don't have that really foundational knowledge of technology underneath it that just feel uncomfortable moving to that approach because it's so quick, because they assume that it takes on more risk.

So I think the biggest challenge everybody's facing on the one hand culturally is all of that, is dealing with the speed and having to take the hands off the controls and letting automation take over.

And the other one obviously is AI in the hands of your own people, the good guys.

Because if you think about it, the people with superpowers in the past, from an IT perspective, were all of your administrators and developers.


I think for many years in the world of cybersecurity, there's been a very strong doctrine around risk.

And what are the things that we're absolutely sure that a human attacker would spot? What are the things that maybe could last a bit longer that probably would go unnoticed by an attacker? And you just don't really have that anymore with AI.

I think we've just seen at the end of last week, this story about Anthropix model, which was built for security testing, breaking out of a sandbox, which people always assume that sandboxes are totally secure.

I mean, human hackers have been able to show that you can break out of sandboxes in the past as well if they're not that well protected.

But the speed that this AI achieved it at after it was given the instruction to do it and the fact that it achieved it and then reported back in a seemingly boastful way that it had achieved that, of course, got headlines and got people focused on the topic.

The reality is over the last couple of years, the speed of security has just sped up exponentially.

I think there's, I just say some data points because I love checking in on the data, but there's something like 4,000% increase of phishing, 4,000% in a couple of years, or the time that the hacker can be on your network unnoticed before they start spreading across the network.

I think the average used to be about 120 days, three or four years ago, down to about 27 minutes at the moment.

And I think Google showed last year that the average time, the number of days after a software company announces that they found a vulnerability to when hackers figure out how to take advantage of it, if you went back three years, that would be two months.

So Microsoft or someone would come out and say, we found a new vulnerability, here's a patch.

the average based on last year's data is now minus one day on average they're exploiting it before the software company even knows that it's there and it's just the whole speed of things the biggest mentality change that everybody has to i think make and we i see organizations at all different levels is recognizing that all of the optionality of security is really disappearing, and you really have to focus on speed of doing things, and to a degree you have to accept a bit more operational risk, or at least on the face of it you do.

I think the old doctrine would be you would roll out some patches on your unimportant systems, then you would have a lot of human beings go and test that everything's working, And if it's fine and they will fill in the forms, then you would deploy the patches onto your sensitive systems.

Need to be doing that in 48 hours or less now to deal with some of the challenges we've spoken about.

You have to automate all of the testing, sequence all of the patches, and just have it as a continuous process of launching new patches.

And I think if you really understand technology on a fundamental level, There's not very much more risk in doing that.

There are ways you can engineer the technology to test itself and make sure that it's secure.

But there's a huge number of people that don't have that really foundational knowledge of technology underneath it that just feel uncomfortable moving to that approach because it's so quick, because they assume that it takes on more risk.

So I think the biggest challenge everybody's facing on the one hand culturally is all of that, is dealing with the speed and having to take the hands off the controls and letting automation take over.

And the other one obviously is AI in the hands of your own people, the good guys.

Because if you think about it, the people with superpowers in the past, from an IT perspective, were all of your administrators and developers.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.