CultureAI

Podcast · On demand

Securing the Human Layer: The Evolution of Cyber Attacks

What happens when a CISO, a consultant and a researcher sit down and compare notes? An honest look at how attackers really operate today.

Join CultureAI's Oliver Simonnet as he speaks with William Jardine and Richard Moore, who unpack how security has shifted and why defending humans has become the real challenge.

Attacks gone human

The modern breach starts with people, not perimeters

Attackers are moving away from complex exploits and doubling down on social engineering, MFA fatigue and identity misuse, because it works. The podcast breaks down why human behaviour is now the primary attack surface and what that means for defenders.

app.culture.ai· Attack surfaceWhere breaches start
Social engineering
MFA fatigue
Identity misuse
Technical exploits

Human behaviour is now the primary attack surface

Your org is everywhere

SaaS, cloud, AI: you're spread across the internet

Decentralisation has "smeared" organisations across SaaS platforms, supply chains and BYOD devices, making traditional perimeter thinking obsolete. The discussion explains why this shift has created new blind spots and how attackers exploit them.

app.culture.ai· Where work happensNo perimeter
SaaS apps
Cloud
BYOD
Browsers
Supply chain
Copilots
Personal accounts
Embedded AI
Shadow IT

Perimeter thinking can’t follow work this decentralised

Traditional tools fail

Legacy controls miss what looks legitimate

Most breaches now look like normal logins and normal use of legitimate functionality, making them invisible to CASB, DLP, EDR and training alone. The podcast explores why alert fatigue, fragmented telemetry and identity ambiguity are leaving organisations exposed.

app.culture.ai· Access eventsLast hour
login: j.smith@corp — OK
file shared via SaaS — OK
session resumed, new device — OK
bulk export, legitimate credentialsLooks normal
login: a.patel@corp — OK

Future of defence

Real-time controls, not more alerts

Securing the human layer requires behaviour-aware detection and in-flow user guidance, not bigger SOC queues. With AI shaping both attacks and defence, the future is context-driven controls that help people make safer decisions in the moment.

app.culture.ai· In-flow guidance LIVE
Employee, in their AI tool
“Draft a renewal email for [customer list pasted]…”
CultureAI

This paste contains customer personal data. Remove it, or continue in the approved workspace.

Open approved toolEdit paste

Guidance in the moment, not an alert in a queue

Hosted by

Oliver Simonnet headshot

Oliver Simonnet

Lead Researcher at CultureAI

With nearly a decade of experience, Oliver has expertise that spans multiple domains, including reverse engineering, payment system technologies and artificial intelligence.

CultureAI logo

Special guest

William Jardine is a Director at Reversec, who advise their clients across assurance and pentesting, adversary simulation, advisory and GRC, and specialist technology stacks. Reversec's recent offensive security research has focused on cloud, collaborative adversary simulation exercises and GenAI.

Reversec logo

Special guest

Richard Moore is the CISO at 10x Banking, leading the organisation's security strategy and ensuring resilient, compliant protection of its cloud-native banking platform as it scales globally.

10x Banking logo

Uncover hidden AI risk

Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.