Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: Why Cybersecurity Pros Must Think Like Attackers

Varonis
07/24/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Megan Garza. This afternoon, I'm joined by Dr. Dalal Alharthi, Assistant Professor of Cybersecurity at the University of Arizona. Welcome to the show, Dalal. Thank you for having me. Dalal earned her PhD in computer science from the University of California, Irvine, and has a diverse background that spans both industry and academia. She previously held positions as a cloud security engineer at Farmers Insurance, a resident engineer at Palo Alto Networks, and as a Prisma cloud consultant at Dell. Currently, she serves as an assistant professor in the Cyber Intelligence and Information Operations Department at the University of Arizona. Dalal holds two master's degrees, one in management and one in computer science, and she has earned professional certification, including AWS Cloud Solutions Dalal, you studied programming in Saudi Arabia before moving to the States in 2015. What was the biggest difference in information technology between the two countries? Working and studying in the field of computer science or information technology or cybersecurity in Saudi Arabia and then moving to study and work in the field in the United States allowed me to understand the global landscape of the field. And one of the most notable differences that I may share is, for example, in Saudi Arabia, there is a strong emphasis on digital transformation through government initiative and enhancement of government services to align with our Vision 2030 plan that we have in Saudi Arabia, while in the United States, it's a much larger, much diverse tech industry, and it's more dynamic, with an emphasis more maybe on businesses and private sector innovation. And what do you foresee as the biggest threat or risk to cybersecurity on the horizon? I would say AI-powered cyber attacks can pose the biggest cyber threat in the near future. So AI-powered cyber attacks, they are very sophisticated, very hard to detect or to defend against. And in addition to that, we always say that humans are the weakest link in the cybersecurity chain. That's why it's really significant to have a continuous education or continuous awareness programs on an individual level and on organizational levels against phishing or social engineering attacks. And when I say social engineering attacks, this means psychologically manipulating the target to either click on a link or to download an attachment or to reveal some sensitive information that they probably shouldn't, or to interact somehow with the sender to make things easier for the cyber attacker in an easier, cheaper, more effective way to gain unauthorized access to systems and to infrastructures. And what made you want to go into cybersecurity? The field of cybersecurity is in the intersection between several fields or domains that are really close to my interest and to my academic background, including management, computer science, software engineering, and also some other fields like psychology. But in addition to that, I would say the constant evolution and challenges of the field makes it really captivating field to be part of. And also, of course, in addition to that, the promising future of the field makes it an impactful career choice as well. There's so many opportunities in cybersecurity. Absolutely. And what is the most important thing to remember when working in cybersecurity? So in working in the field, it's really important to keep in mind that there is nothing that is 100 percent secure. So there are vulnerabilities or vulnerable system that we know that it's vulnerable. And there are other systems that have some vulnerabilities, but yet we haven't discovered that yet or we haven't identified that yet. So it's really important to keep that in mind and to have a goal of reducing the time between having the vulnerability and remediating or mitigating this vulnerability, which is one of the key goals that we have in cybersecurity. Also, we always say that key in cybersecurity stands for keep educating yourself. So ongoing education is really important. And I mentioned earlier that AI has significant impact on the field of cybersecurity, both positively and negatively, of course. But there's always new things. There's always new tools, new techniques. So continuous education is something really significant when you are in the field of cybersecurity. Also, one of the things that I share here is when you work in the field of cybersecurity, you work with some tools or techniques that might be used for good or for evil. So, of course, keeping in mind legal and ethical consideration is vital. Like AI, as you mentioned earlier. Absolutely. And I like what you said about key, keep educating yourself. I feel like that can apply to any career path that you're in. Absolutely. In your opinion, what is the best way to defend against a cyber attack? Being proactive is really important. Expecting that you might be targeted by a cyber attack and then act accordingly and build your own incident response accordingly is really important. That's why in most of the organizations, they have what they call the incident response runbook, where we have this written document of several scenarios of incidents that might happen, like being targeted by a ransomware or some other cyber attacks. And then what can we do to contain, to eradicate the threat? How can we respond effectively to that threat? And then maybe try to translate that into technical steps into our systems or in our infrastructure and automate what can be automated is something really important. But being proactive is the key here, of course. And again, I'd say enabling the human firewall is the best defense strategy, of course, through ongoing training and continuous education as well. Comes back to that. Keep educating yourself. Exactly. Because you helped shape the future minds of tech, can you share one thing that you wish future cybersecurity professionals knew? To build your defense strategy effectively, you might need to think from a cyber attacker's perspective or mindset. So that's why in the field of cybersecurity, we learn and we always teach something like cyber kill chain or MITRE ATT&CK or some other frameworks that helps us to understand the steps of cyber attacks. And then our goal as cybersecurity professionals is to either disrupt this chain as early as possible or to build our defense strategy also based on that. So thinking from the cyber attacker's perspective is one significant thing. And also, I would recommend reviewing the job ads in the field. And by reviewing that, they might have a better understanding of what the current market needs in terms of the skills that they might need to have, the certificates, the day to day job duties and so on. And lastly, if you weren't in cybersecurity, what would you be doing? I've always had a strong interest in forensic science. So if I'm not in the cybersecurity field, I think I would do something in the forensic science field. But also, I'm trying to currently apply my interest or my knowledge and experience in the cybersecurity field on digital forensics and more specifically on cloud forensics, which is something I work on from an industry perspective. But I'm trying now to tackle it from a researcher perspective to see what's the open issues in the field of cloud forensics and address that from a researcher perspective. You can tell that education is your passion. It's very important to you. Thank you. Thank you for your time today, Dalal. It was greatly appreciated. And as always, if our audience has any questions they'd like asked during a future Speed Data episode, please email me at pr at Varonis dot com. Thank you, Dalal. Thank you so much.

TL;DR

  • AI-powered cyberattacks represent the biggest emerging threat due to their sophistication and difficulty to detect, requiring organizations to evolve their defense strategies beyond traditional approaches.
  • Humans remain the weakest link in cybersecurity, making continuous security awareness training essential to defend against social engineering and phishing attacks that exploit psychological manipulation.
  • Nothing is 100 percent secure—organizations should focus on reducing the time between vulnerability discovery and remediation rather than pursuing impossible perfect security.
  • Effective defense requires thinking like an attacker, using frameworks like MITRE ATT&CK and cyber kill chain to understand attack methodologies and disrupt them early in the process.

AI Threats and the Human Factor in Cybersecurity

Dr. Dalal Alharthi, a cybersecurity professor at the University of Arizona with extensive industry experience at Palo Alto Networks, Dell, and Farmers Insurance, identifies AI-powered cyberattacks as the most significant emerging threat facing organizations. These sophisticated attacks are increasingly difficult to detect and defend against, making traditional security measures insufficient. However, she emphasizes that humans remain the weakest link in the cybersecurity chain, with social engineering attacks exploiting psychological manipulation to trick targets into clicking malicious links, downloading harmful attachments, or revealing sensitive information. This dual threat landscape requires organizations to invest heavily in continuous security awareness training at both individual and organizational levels.

Proactive Defense Through Attacker Mindset

The interview highlights a fundamental principle for effective cybersecurity: nothing is ever 100 percent secure. Organizations must accept that vulnerabilities exist—both known and undiscovered—and focus on reducing the time between vulnerability discovery and remediation. Dr. Alharthi advocates for proactive defense strategies built around incident response runbooks that document scenarios like ransomware attacks and outline containment, eradication, and response procedures. Most critically, she advises cybersecurity professionals to think from an attacker's perspective, leveraging frameworks like the cyber kill chain and MITRE ATT&CK to understand attack methodologies and disrupt them as early as possible. This attacker mindset, combined with enabling the human firewall through ongoing education, forms the foundation of effective organizational defense.

Chapters

0:00 - Introduction
0:57 - Saudi Arabia vs. U.S. IT Landscape
2:00 - AI-Powered Cyber Threats
3:05 - Why Cybersecurity Appeals
3:46 - Nothing Is 100% Secure
5:20 - Proactive Defense Strategies
6:32 - Thinking Like an Attacker
7:34 - Cloud Forensics Research

Key Quotes

2:00 "I would say AI-powered cyber attacks can pose the biggest cyber threat in the near future."
2:20 "We always say that humans are the weakest link in the cybersecurity chain."
3:51 "It's really important to keep in mind that there is nothing that is 100 percent secure."
6:36 "To build your defense strategy effectively, you might need to think from a cyber attacker's perspective or mindset."

FAQ

What is the biggest cybersecurity threat organizations should prepare for?

According to Dr. Alharthi, AI-powered cyberattacks pose the biggest threat in the near future because they are highly sophisticated and difficult to detect or defend against. Combined with social engineering attacks that exploit human psychology, organizations face a dual challenge requiring both technical defenses and continuous security awareness training.

How should organizations approach cybersecurity defense strategy?

Organizations should be proactive by expecting they will be targeted and building incident response runbooks that document scenarios and response procedures. The key is thinking from an attacker's perspective using frameworks like MITRE ATT&CK, focusing on disrupting attack chains early, and enabling the human firewall through ongoing training and education.


Categories:
  • » Webinar Library » Varonis
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Security Operations
  • AI & Machine Learning
  • Cloud Security
  • Interview
  • Best Practices
  • AI-powered cyberattacks
  • Social engineering
  • Human factor in security
  • Incident response
  • MITRE ATT&CK framework
  • Cyber kill chain
  • Cloud forensics
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: Why Cybersecurity Pros Must Think Like Attackers

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      06

                      Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                      08/06/202602:00 PM ET
                      • Aug
                        07

                        Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                        08/07/202611:00 AM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverages and Essential Cybersecurity Insights for the Season
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverages-and-essential-cybersecurity-insights-for-the-season/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version