Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library

KnowBe4: Users Gonna Click, KnowBe4’s Got Your Back

Truth in IT
05/09/2025
46
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hi Mike Matchett with Small World Big Data. We are here at RSAC 2025 talking all the latest and greatest cybersecurity vendors. We are here with KnowBe4, which you've probably heard of. Uh, tell us a little bit, Roger, what does KnowBe4 really focus on in cybersecurity? I know it has something to do with social phishing and the rest of it. How would you say it? Uh, human risk management trying to decrease cybersecurity risk. That's due to humans. So a big part of that is security awareness training, where you're trying to help people recognize and avoid being scammed. That's a piece of it. Uh, coaching them, nudging them to make the right security decisions. Uh, part of our thing even involves, uh, addressing inbound email and outbound email to see if it has signs of phishing. And we tag that email to tell the users, hey, this is external. Seems to have a weird link in. It seems to have a QR code. These are things that could be, you know, a high risk. So really focusing on US cyber security risk around the humans. Let me say that 70 to 90% of data breaches involve some sort of social engineering. So it's the most important part you can do. Yeah, and I know everyone says we should put everything to the AI, which has been trained on all that human stuff, but I'm not sure automating human intelligence is going to get us all that at the end of the day. It's interesting, though, that the human human, everyone wants a human in the loop, though still. But humans are a lot of the problem with security. Um, what? How do you do training? How do you think about training somebody to be more secure? What's sort of the overall approach to getting people into a security mindset all the time? And by the way, we don't call it humans. The big problem. We say they can be the best part of your defense. But certainly, I mean, a big part of it is they even if they're aware of something, they may not care. Uh, you know, really what you're trying to do is influence human behavior and really culture throughout the organization so that everybody's kind of in this, hey, I'm going to have a healthy level of skepticism. A new message comes in asking me to do something that I've never done before that, you know, we're trying to encourage them to see that as a sign of a high risk message. Make sure that you research it. Use an alternative method outside the message before you perform it. We all get messages from our boss going, hey, I need you to do this, do that. But what we're saying is, if the message is unexpected, no matter how it comes, even if it's in person, you do something you've never done before. Slow down. Be mindful. Research a little bit before you perform it. That's a big part. But it's also, again, even putting the tools and the policy things, making policies harder for someone to take be taken advantage of. Like if you have a policy that says, hey, never pay an invoice that doesn't have, you know, an order with it. Uh, you don't want to circumvent the system, you can get in trouble. Or another policy could be make sure you lock your desktop before you whenever you leave it. Uh, never give your password out to someone calling you so you can create policies that help reduce risk? Then you have your technical tools that would be like your email scanners, your endpoint detection and stuff. And then you have the human component. And again it's a it's a huge thing. Think about it. 70 to 90% of successful attacks involve social engineering that have made it around every policy and technical defense you have. So you got to do it. All right. Look around here at the RSA conference. There's 25,000 people here. There's some common themes going on. What would you say you've been hearing and how KnowBe4 can help people with that? Yeah, certainly AI is a big deal. And what I would tell people, like so many companies, agentic autonomous Agentic AI and certainly we're big believers in that all of our stuff is agentic AI. First, we've been doing AI for seven years, but I would say make sure you're concentrating on features not, you know, if you give me a good feature that's doing something better and reducing cybersecurity risk better for me, I don't care if it's autonomous agentic AI or if it's a basic if then statement, right? Focus on the feature. But I do think you're going to see a I and I start to provide value, like we have an AI agent that helps pick the phishing templates, simulated phishing templates. And we know that if you allow our AI to do it versus the human admin, it's 17% more effective at tricking people, which sounds like a bad thing, but you're making them fellow phishing test. But that then allows you to give an additional educational opportunity. So we don't see it. We're like, oh, that allows you to educate people 17% more, and I think you're going to see a lot more of that where the Agentic AI is going to start providing real value, real decrease in cybersecurity risk. But, you know, it's funny, I hear I agentic I sometimes I want to just run away and scream. Yeah. Me too. Like I try not to say agentic ai too many times. But I just say so concentrate on the feature set and if someone tells you, oh, we've got agentic ai go. Okay, tell me what that's really giving me over what you had before. Yeah. So I understand that you are a not understand. I know you're a famous author. You've written lots of books on things. What's your what's your latest thing? My latest book I've written 15 working on my 16th and 17th one, but my latest one is called Taming the Hacker Storm a framework for Defeating Hackers and Malware. It literally I wanted to title it How you Fix all of Internet Security. It has a solution that, if followed, would significantly diminish the amount of hacking and malware on the internet. And I've been presenting it to all kinds of colleges and universities. Mit, I sent it to Cisa. Most of the people have seen it, have liked it and said, yeah, that would work. But, you know, it's funny. If implemented, it would probably work to significantly decrease hacking and malware. But you can't get people around your dinner table to agree to do anything. It's really tough to do that in a global world where people have and agencies of all sorts of other motivations, but I'm hoping to I've got about ten years. I'm 58, got about ten years before I retire, and I'm hoping that literally my life's goal is to fix internet security. And if I do it, my career will have been worth it. And if not, it will have been an utter failure. I'm not here to fix the little problems. I'm here to fix the big problems. You know, it does sound like you could put those concepts together and build a Roger Grimes Agentic AI to carry on your legacy and carry that carry that agenda forward. So let's just finish up a little bit. If someone wants to know a little bit more about KnowBe4, particularly if they're in this kind of crowd full of CISOs and the rest of it. Where would you have them start looking into stuff? Knowbe4. Com. We have a lot of information on there for CISOs to everyone on down. Or if someone wants to email me I'm Roger g r o g e r g@knowbe4.com. If you have a question you want to get some information. Certainly we can I can get that to you. All right. Thank you so much, Roger. It was a pleasure to meet you. Thank you. Take care folks.

Mike Matchett chats with Roger Grimes of KnowBe4 about tackling cybersecurity’s oldest problem: people. KnowBe4’s human risk management platform goes beyond awareness training to influence behavior, build skepticism, and shape a security-minded culture. From phishing simulations to real-time coaching and inbound email tagging, KnowBe4 helps users spot scams and take smarter actions. With social engineering behind 70–90% of attacks, KnowBe4’s people-first strategy is still one of the most effective defenses in the security stack.

Categories:
  • » Small World Big Data
  • » Cybersecurity Webinars
Channels:
  • Mike Matchett: Small World Big Data
News:
Events:
Tags:
  • rsac2025
  • matchett
  • cybersecurity
  • knowbe4
  • security
  • awareness
  • phishing
  • prevention
  • human
  • risk
  • management
  • social
  • engineering
  • email
  • security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: KnowBe4: Users Gonna Click, KnowBe4’s Got Your Back

              Upcoming Webinar Calendar

              • 10/14/2025
                01:00 PM
                10/14/2025
                Discover Netwrix's Transformation: A Journey in Brand and Product Development
                https://www.truthinit.com/index.php/channel/1540/discover-netwrixs-transformation-a-journey-in-brand-and-product-development/
              • 10/15/2025
                12:30 AM
                10/15/2025
                Achieving Cyber Resilience in APAC VMware: Effortless Recovery Strategies
                https://www.truthinit.com/index.php/channel/1543/achieving-cyber-resilience-in-apac-vmware-effortless-recovery-strategies/
              • 10/15/2025
                01:00 PM
                10/15/2025
                Managing Human Risk in an AI-Driven Threat Landscape: Are Your Defenses Evolving Fast Enough?
                https://www.truthinit.com/index.php/channel/1521/managing-human-risk-in-an-ai-driven-threat-landscape-are-your-defenses-evolving-fast-enough/
              • 10/16/2025
                06:00 AM
                10/16/2025
                EMEA Cyber Resilience Insights for VMware: Effortless Recovery Without Uncertainty
                https://www.truthinit.com/index.php/channel/1544/emea-cyber-resilience-insights-for-vmware-effortless-recovery-without-uncertainty/
              • 10/16/2025
                11:00 AM
                10/16/2025
                Trend Micro Webinar: Risk in Real Time: Agentic SIEM
                https://www.truthinit.com/index.php/channel/1372/risk-real-time-agentic-siem/
              • 10/16/2025
                12:30 PM
                10/16/2025
                Secureframe: ISO 27001 for Startups: Understanding Its Importance and Accelerating Certification
                https://www.truthinit.com/index.php/channel/1523/iso-27001-for-startups-understanding-its-importance-and-accelerating-certification/
              • 10/22/2025
                01:00 PM
                10/22/2025
                Cut Ticket Resolution Time in Half with Smarter IT Documentation
                https://www.truthinit.com/index.php/channel/1541/cut-ticket-resolution-time-in-half-with-smarter-it-documentation/
              • 10/23/2025
                12:00 PM
                10/23/2025
                360View: Preventing Data Exfiltration: Keeping Enterprise Data Secure
                https://www.truthinit.com/index.php/channel/931/360view-preventing-data-exfiltration-keeping-enterprise-data-secure/
              • 10/23/2025
                12:00 PM
                10/23/2025
                Secureframe: CMMC Series - Crafting a Readiness Roadmap for Streamlined Certification Success
                https://www.truthinit.com/index.php/channel/1535/cmmc-series-crafting-a-readiness-roadmap-for-streamlined-certification-success/
              • 10/28/2025
                12:00 PM
                10/28/2025
                Reimagining Data Security: Regain Control Over Your Information
                https://www.truthinit.com/index.php/channel/1432/reimagining-data-security-regain-control-over-your-information/
              • 10/30/2025
                06:00 AM
                10/30/2025
                Rethink secure access solutions beyond VPN and NAC in a zero trust landscape.
                https://www.truthinit.com/index.php/channel/1547/rethink-secure-access-solutions-beyond-vpn-and-nac-in-a-zero-trust-landscape/
              • 10/30/2025
                12:00 PM
                10/30/2025
                Revolutionizing Secure Access Beyond VPN and NAC for a Zero Trust Era
                https://www.truthinit.com/index.php/channel/1546/revolutionizing-secure-access-beyond-vpn-and-nac-for-a-zero-trust-era/
              • 11/06/2025
                12:00 PM
                11/06/2025
                Secureframe: CMMC Level 2 Assessment Insights: Expectations and Preparation Strategies
                https://www.truthinit.com/index.php/channel/1536/cmmc-level-2-assessment-insights-expectations-and-preparation-strategies/
              • 11/20/2025
                12:00 PM
                11/20/2025
                360View: Budget Optimization: Doing More with Less
                https://www.truthinit.com/index.php/channel/932/360view-budget-optimization-doing-more-with-less/
              • 12/11/2025
                12:00 PM
                12/11/2025
                Secureframe: Addressing the Top 5 Compliance Challenges for Startup Leaders and Solutions
                https://www.truthinit.com/index.php/channel/1526/addressing-the-top-5-compliance-challenges-for-startup-leaders-and-solutions/
              • 12/18/2025
                12:00 PM
                12/18/2025
                360View: 2026 IT Predictions & Emerging Trends
                https://www.truthinit.com/index.php/channel/933/360view-2026-it-predictions-emerging-trends/

              Upcoming Spotlight Events

              • Oct
                15

                Managing Human Risk in an AI-Driven Threat Landscape: Are Your Defenses Evolving Fast Enough?

                10/15/202501:00 PM ET
                • Oct
                  22

                  Cut Ticket Resolution Time in Half with Smarter IT Documentation

                  10/22/202501:00 PM ET
                  More events

                  Upcoming Industry Events

                  • Oct
                    14

                    Discover Netwrix's Transformation: A Journey in Brand and Product Development

                    10/14/202501:00 PM ET
                    • Oct
                      15

                      Achieving Cyber Resilience in APAC VMware: Effortless Recovery Strategies

                      10/15/202512:30 AM ET
                      • Oct
                        16

                        EMEA Cyber Resilience Insights for VMware: Effortless Recovery Without Uncertainty

                        10/16/202506:00 AM ET
                        More events

                        Upcoming 360 View Events

                        • Oct
                          23

                          360View: Preventing Data Exfiltration: Keeping Enterprise Data Secure

                          10/23/202512:00 PM ET
                          • Nov
                            20

                            360View: Budget Optimization: Doing More with Less

                            11/20/202512:00 PM ET
                            • Dec
                              18

                              360View: 2026 IT Predictions & Emerging Trends

                              12/18/202512:00 PM ET
                              More events

                              Recent Spotlight Events

                              • Sep
                                16

                                KnowBe4: Beyond DMARC: Closing Critical Gaps in Your Email Security Shield

                                09/16/202501:00 PM ET
                                • Sep
                                  11

                                  Cyera: An Executive’s Guide to Secure AI Adoption

                                  09/11/202501:00 PM ET
                                  • Aug
                                    13

                                    Resilience by Design: Reducing Data Risk, Downtime, and Regulatory Exposure w. Hitachi Vantara

                                    08/13/202501:00 PM ET
                                    More events

                                    Recent Industry Events

                                    • Oct
                                      09

                                      CMMC Scoping: Clarifying the Initial Step Toward CMMC Certification

                                      10/09/202512:00 PM ET
                                      • Oct
                                        02

                                        Essential Insights on SOC 2 for Startup Founders

                                        10/02/202512:00 PM ET
                                        • Sep
                                          25

                                          Netskope: Secure the Future--AI Usage & Data Security in the Enterprise

                                          09/25/202512:00 PM ET
                                          More events
                                          Truth in IT
                                          • Sponsor
                                          • About Us
                                          • Terms of Service
                                          • Privacy Policy
                                          • Contact Us
                                          • Preference Management
                                          Desktop version
                                          Standard version