The 2025 Global Study on Closing the IT Security Gap

Ransomware, network and application attacks, insider threats and denial of service attacks are just a few of the threats putting organizations on high alert. The increasing sophistication of cyber criminals—as well as these cyber criminals adopting AI–makes it more important than ever to become aggressive in closing security gaps in the IT infrastructure.

 New approaches to closing the IT security gap are needed. In 2023, organizations had an average of five security breaches over a 12-month period. This increased to an average of six incidents in 2024. With the difficulty in reducing breaches and security incidents, organizations are changing their activities and use of technology. Since 2023 the most significant changes are the use of comprehensive penetration testing (an increase of 17 percent of respondents), implementation of a secure and continuous data protection and backup strategy (an increase of 17 percent of respondents) and prioritization of rapid attack and breach detection (an increase of 16 percent of respondents). For the first time, the study asked if network detection and response (NDR) (42 percent), kernel detection/ silicon root verification (39 percent) and micro segmentation (32 percent) are new technologies deployed to close the IT security gap.

Optimizing AI technologies to close the IT security gap

 AI’s ability to close the cybersecurity gap depends upon close collaboration between network and security teams. Thirty-nine percent of respondents say their organizations have adopted AI to close the IT security gap. In addition to improving collaboration between network and security teams (34 percent of respondents), other AI priorities include aiding in threat investigations (32 percent of respondents) and detecting changes to the organizations’ security posture (30 percent of respondents).

 To have a successful AI strategy, organizations need assurances about AI accuracy, privacy safeguards and data leakage prevention. Organizations considered uncertainties about AI accuracy, difficulties in ensuring data privacy and difficulties in preventing data leakage their greatest challenges with AI (all 44 percent of respondents). Another possible deterrent to closing the IT security gap is not having the confidence that their organizations know and are able to secure all AI assets including infrastructure, models and data. Only 43 percent of respondents say their organizations are very or highly confident they have that visibility.

 Organizations considering the use of AI for business purposes need to evaluate the possible complexity the technology will add to their operations. Fifty-three percent of the 39 percent of respondents who have adopted AI are using AI for business purposes. The security risks created when AI is used for business purposes are increased complexity because of the addition of new security tools (57 percent of respondents), potential theft or leakage of confidential and sensitive data (47 percent of respondents) and the inability to recover lost data in the event of an attack or disaster (44 percent of respondents).

 Why the IT security gap continues to put organizations at risk

 Not having the necessary skilled IT professionals continues to be the number one barrier to closing the IT security gap.  While fewer organizations are reporting shortages in security staffing, skills and experience (30 percent vs. 39 of respondents in 2023), shortages are still affecting organizations’ security posture. Additional barriers to closing the IT security gap include security solutions that can’t keep up with exponentially increasing amounts of data and difficulty in complying with IT security and privacy industry standards or regulations (each 29 percent of respondents).

 Too many vendors to manage and lack of collaboration between network and security teams can weaken organizations’ cybersecurity posture. Fifty-six percent of respondents say managing multiple security vendors is challenging and, as a result, can diminish their organization’s security posture. Forty-seven percent of respondents say it is difficult to achieve collaboration between network and security teams. Such collaboration is critical to preventing friction between IT and security teams that hinder efforts to put an effective strategy in place.

 New approaches to securing the modern workplace

 Secure Access Service Edge (SASE) frameworks combine networking and security capabilities into a unified, cloud-based solution, ensuring seamless access and protection for distributed workforces and enterprise assets.

Organizations are at various stages in their SASE deployment. In 2024, 23 percent of respondents say their organizations have deployed SASE, 23 percent of respondents say they will deploy in 12 months and 19 percent of respondents say their organizations will deploy SASE sometime in the future.

Reduction of costs, improved application performance and improved security posture are priorities for deploying SASE. Thirty-seven percent of respondents say their organizations deployed SASE first to reduce costs and improve application performance for users and branches. Thirty-six percent of respondents say their organizations started their SASE journey with an SSE deployment to improve security posture and increase protection. The number one SASE deployment strategy is to engage a best-in-class SD-WAN vendor that integrates with SSE vendors (30 percent of respondents) followed by engaging a best-in-class SSE vendor that integrates with SD-WAN vendors (27 percent of respondents).

Universal Zero Trust Network Access (ZTNA) is a security framework that allows organizations to grant secure access to applications for subjects regardless of their location. Forty-eight percent of respondents say their organizations have deployed universal ZTNA in some form. According to the research, the three most important characteristics of the universal ZTNA approach are enabling least privilege access to support zero trust (35 percent of respondents), ensuring a seamless access experience for users anywhere (30 percent of respondents) and securing IoT devices and users (29 percent of respondents).

Closing IT security gaps in hybrid cloud environments.

Organizations are securing their hybrid cloud environments in multiple ways. The processes prioritized to minimize the risk in a hybrid cloud environment are the implementation of a defined cybersecurity compliance framework (46 percent of respondents) in 2024, securely shifting workloads from on-premises to the cloud (44 percent of respondents) and the modernization of IT security processes (43 percent of respondents).

Organizations are improving their ability to avoid security exploits and data breaches and secure workloads moving between on-premises and public cloud environments. Organizations appear to be making progress on several security fronts: The percentage of respondents who say challenges associated with avoiding security exploits and data decreased from 51 percent of respondents in 2023 to 43 percent of respondents in 2024. Similarly, the challenge of securing workloads moving from the edge to the cloud decreased from 43 percent in 2023 to 36 percent of respondents in 2024. The primary technology challenge continues to be enabling the free flow of data securely (46 percent of respondents).

Organizations are having greater difficulty in their ability to ensure the privacy of customer information and enable the free flow of information in the hybrid cloud environment.

Since 2023, more respondents say ensuring customers’ privacy and enabling the free flow of information has made it more difficult to secure the hybrid cloud environment (37 percent and 32 percent of respondents, respectively).

Separating storage and compute means they can be consumed, scaled, and priced independently. This allows businesses to pay for what they use and nothing more. Organizations in this research say their current security approach to compute and storage will change. The biggest changes organizations indicate they will face in separating storage and compute will be moving their current security approach to the cloud (28 percent of respondents), managing a combination of solutions from security and hybrid cloud infrastructure providers (25 percent of respondents) and requiring vendors to supply new security solutions (24 percent of respondents).

More organizations are making server decisions based on the security inherent within the platform (62 percent of respondents, a significant increase from 48 percent in 2023). Fifty-eight percent of respondents say their organizations require servers that leverage security certificates to identify that the system has not been compromised during delivery. Fifty-eight percent of respondents say data protection and recovery are key components of their organizations’ security strategy and 58 percent of respondents say their organizations require infrastructures that leverage chip and/or certificates to determine if the system has been compromised during delivery.

Best practices of high-performing organizations

Twenty-one percent of respondents reported that their organizations are highly effective in keeping up with a constantly changing threat landscape and closing their organization’s IT security gap. We refer to these organizations as “high performers” and compare their responses to the non-high performer respondents, referred to as “other”.

Collaboration between network and security teams is essential to a successful security strategy. Fifty-four percent of high performers vs. 40 percent of others have achieved collaboration.

High performers are most likely to have a vendor consolidation strategy. Too many vendors to manage affect an organization’s security posture. Fifty-nine percent of high performers vs. 51 percent of other respondents have a vendor consolidation strategy to improve ROI.

High performers are more likely to adopt AI. There is a significant difference in high performers and others adoption of AI (61 percent of respondents vs. 49 percent).

High performers place a higher value on NAC solutions and the integration of NAC functionality. Respondents were asked to rate the importance of NAC solutions and integration on a scale of 1 = not important to 10 = highly important. The importance of NAC solutions (60 percent vs. 41 percent) and integration of NAC functionality (56 percent vs. 41 percent) are rated higher by high performers.

When it comes to universal zero trust network access, high performers place notably greater importance on seamless access experience for users anywhere. High performers are more positive about seamless access and consistent enforcement at every location (34 percent of high performers vs. 26 percent of other respondents). Twenty-nine percent of high performers vs. 22 percent of the others rate consistent enforcement at every location higher than the other respondents.

High performers are more likely to make the identification and authentication of IoT devices accessing their networks critical to their organizations’ security strategy. Fifty-nine percent of high performers vs. 48 percent of the others are more focused on identifying and authenticating IoT devices with access to their organizations’ security strategy.

High performers are more likely to require infrastructure that leverages chip and/or certificates to determine if the system has been compromised during delivery. Sixty-six percent of high performers v. 49 percent of the others require infrastructure that leverages chip and/or certificates to determine if the system has been compromised during delivery.

Recommendations to close the IT security gap

To close the IT security gap organizations are making significant changes in their strategies to minimize threats within the IT infrastructure. These include implementing NDRs, conducting comprehensive penetration testing, prioritizing rapid attack and breach detection and implementing a secure and continuous data protection and back up strategy. New in this year’s research is organizations’ adoption of AI (39 percent of respondents). Organizations primary goals for AI are to improve collaboration between network and security teams, to aid in threat investigations and to detect changes in the organizations’ security posture.

Following are actions to consider in the coming year.

  • Develop an AI strategy. An effective AI deployment is dependent upon removing uncertainties about AI’s accuracy, ensuring the privacy of sensitive and confidential data and assessing the risks to prevent data leakage.
  • Consolidate vendors to reduce redundancies of solutions that increase costs and create inefficiencies for the IT security team. To achieve consolidation of vendors evaluate spend categories to identify vendor overlap and map vendors’ capabilities to determine where cuts can be made.
  • Improve cyber resiliency by taking steps to reduce the time to recover from a critical system failure caused by a cyber incident. As shown in this research, only 35 percent of respondents say recovery can be achieved in less than one hour (12 percent) or in 1 to 4 hours (23 percent). This includes making sure technologies are used efficiently and having a cybersecurity incident response plan in place to navigate a security crisis.

Part 2. Key findings

Ponemon Institute surveyed 2,120 IT and IT security practitioners in the United States (635), the United Kingdom (291), Germany (371), France (197), Australia (180) and Japan (446) in 2024 for publication in 2025. In this report, we present the 2023 and 2024 global findings. The audited findings are presented in the Appendix of this report. We have organized the findings according to the following topics.

  • Barriers to closing the IT security gap
  • Closing the IT security gap with artificial intelligence
  • Imperatives for controlling access: zero trust, NAC, SASE and universal ZTNA
  • Securing the hybrid cloud
  • The separation of compute and storage
  • Country differences
  • Best practices in closing the IT cybersecurity gap

To read the rest of this report, visit Hewlett Packard’s website.

A decade of heartbreaks: His identity has been used in hundreds of romance scams

Bob Sullivan

I sat down at his table and he had probably 100 cards and letters and gifts and boxes and he said, ‘I bet there’s at least 500 …. This isn’t nearly all of it.’ And he really lost count. There were just stacks of love letters and gifts and cards, and it just… the emotional power of sitting at his kitchen table that was just covered in evidence from women who believed that they were in love with him. — ABC News reporter Lisa Fletcher

Cards. Flowers. Candy.  Gifts that just never stop. It might sound quaint at first, even charming.  But every one of these love stories ended the same.  With Pat Marsh pleading for the sender to stop. Sometimes, that conversation happens at his front door…with anger and even violence hovering in the air.

“These people have also come to my house….And this is where it gets dangerous,” he told me for a recent episode of The Perfect Scam, the podcast I host for AARP.

“After about 6 months of this, one night… There was a knock at my door…and I was looking at a guy  and he was like… ‘you told me to come over.’ and I was like, “Dude, get outta here.” And that’s when he grabbed the door and he opened the door and tried to come in…  and my exact words were, ‘You’re playing a dangerous game. You need to get out of here.’ .. I would have shot him, if he had come into my house, I have shot him.”

“These people” are romance scam victims.  And the parade of victims who call, write and visit Pat Marsh has been relentless for nearly a decade. Marsh is a test pilot, a generally fascinating man who caught the attention of criminals back in 2017. They thought he’d make perfect bait for would-be lovers on dating sites, and by all accounts, the criminals were right.

Marsh is the victim of a particularly cruel kind of identity theft. No one can really say how many women and men have been enchanted by the fake Pat Marsh and various variations.  But here’s a hint: One police detective investigating a Pat Marsh romance scam in Easley, South Carolina – a widow who’d had $600,000 stolen — used email records to find 60 more cases.

Marsh is really the victim of industrial-scale crime, says Detective Eric Gillespie.

“The fake Pat Marsh here is actually probably a dozen if not more people,” he told me. “You’ve got professional outfits in West Africa and Southeast Asia that you might have 100 people who are the same person more or less, for lack of a better phrase.”

Even if you don’t believe you could ever be the victim of an online scam — and I think you are foolish for that — you should care about the surge in digital crime.  Pat Marsh is collateral damage in the ongoing international scam wars we are all fighting.  You can be next. All of us can get wrapped up in a scam even if we never communicate with a criminal.  That’s why these stories matter so much.

After a decade’s worth of investigations, TV news stories, and late-night door knocks, Marsh has no idea when his headaches will end.  He really has no control over it. Instead, an entire system needs to be changed. Online dating sites need to police their membership much more aggressively.  Banks and new money systems need to get better at policing suspicious transactions. And we all need to be more sympathetic about the isolation and boredom that create fertile ground for crime.

I hope you’ll listen to this two-part episode about the man with 1,000 fake lovers. If podcasts aren’t your thing, you can find a transcript here.

The 2026 Global Study on Postquantum and Cryptographic Security Trends

The purpose of this research is to provide important information about trends in post quantum, cryptographic security, PKIs and HSMs. Ponemon Institute surveyed 4,149 IT and IT security practitioners who are familiar with the use of these technologies in their organizations.

The countries in this research are the United States (552 respondents), United Kingdom/Ireland (573 respondents), Canada (396 respondents), DACH (553 respondents), Indonesia (369 respondents) and Singapore (482 respondents).

The post quantum threat is coming quickly, but will organizations be prepared? Quantum computing is a rapidly emerging technology that harnesses the laws of quantum mechanics to solve problems too complex for classical computers. The quantum threat, sometimes referred to as “post quantum”, is the inevitability that within the decade it will be capable of breaking traditional public cryptography such as RSA and ECC.

Only 38 percent of respondents say their organizations are preparing for the post-quantum threat, a slight decrease from 41 percent in last year’s report. Of these respondents, 44 percent from 2024 and 2025 are building a post-quantum cryptography strategy.

Thirty-two percent of respondents say their organizations are taking an inventory of their cryptographic assets and/or ensuring they are crypto agile. This is a decline from 38 percent of respondents in last year’s report. Testing within organizations’ systems and applications increased significantly from 10 percent of respondents to 21 percent.

The following summarizes the most significant research trends in postquantum and cryptographic trends

Organizations believe the PQ threat is imminent. Seventy-five percent of respondents agree and say a quantum computer will be capable of breaking traditional public key cryptography within 5 years (51 percent) or in 5 to 10 years (24 percent). Only 12 percent say it will never happen.

 The biggest challenge to reducing the quantum-threat and migration to post quantum cryptography (PQC) continues to be the inability to improve the discovery/inventory of their organizations’ cryptographic assets. Forty-one percent of respondents in this year’s study vs. 43 percent of respondents in last year’s study say the inability to improve visibility into their cryptographic assets is the greatest concern. Two concerns that have increased significantly are the lack of an adequate budget (39 percent in this year’s study vs. only 31 percent in last year’s study) and lack of in-house expertise (38 percent in this year’s study vs. only 28 percent in last year’s study).

Fifty percent of respondents say a successful quantum attack would have a serious impact on their organizations and industries. Fifty percent rate the potential impact as serious, but only 36 percent of respondents rate the adequacy of government policy and public-private coordination on quantum readiness as more than adequate. A successful quantum attack against organizations and industries could result in the loss of access to encrypted critical infrastructure (58 percent of respondents) and exposure of long-term sensitive data such as health records and trade secrets (59 percent of respondents).

The lack of visibility into the cryptographic estate, certificates and keys and secrets puts organizations’ cryptographic security at risk.  Only 43 percent of respondents say their organizations have full or complete visibility into their organizations’ cryptographic estate and only 43 percent of respondents say they have full or complete visibility into certificates across the organization and only 40 percent say they have full or complete visibility into keys and secrets across the organization.

Private cloud-based applications and mobile device authentication applications that use PKI credentials declined significantly from 2024. Private cloud-based applications using PKI declined the most (56 percent of respondents in 2024 vs. 32 percent of respondents this year). Mobile device authentication decreased from 60 percent of respondents to 41 percent of respondents). The top applications using PKI credentials are private networks (52 percent of respondents), SSL certificates for public facing websites and services (50 percent of respondents) and document/message signing (45 percent of respondents).

Internal corporate certificate authorities (CAs) are most often used to deploy PKIs but have declined since last year. Forty-six percent of respondents in this year’s report use CAs to deploy PKI and 60 percent of respondents in last year’s study. Business partner provided service increased the most from 18 percent of respondents in last year’s report to 40 percent of respondents in this year’s study. Private CAs running within a public cloud increased from 21 percent of respondents last year to 37 percent of respondents this year.

The most important security certification when deploying PKI infrastructure is Common Criteria EAL Level 4+ (54 percent in this year’s study vs. 57 percent of respondents in last year’s study). The second most important certification is FIPS 140-2 Level 3. However, its importance has declined significantly from 55 percent of respondents to 32 percent of respondents.

The biggest uncertainty and concern about the evolution of PKI are PKI technologies and external mandates and standards. When asked what the greatest areas of change and uncertainty to PKI will be, 49 percent of respondents say it is PKI technologies, an increase from 43 percent in 2024 and external mandates and standards, an increase from 37 percent of respondents in 2024. Budget and resources, increased significantly to 43 percent of respondents vs. 30 percent of respondents.

More organizations use HSMs and use HSMs to secure PKI. Sixty-six percent of respondents in this year’s research vs. 55 percent of respondents in last year’s research say their organizations use HSMs. Sixty-three percent of respondents in this year’s research vs. 51 percent of respondents in last year’s research say their organizations use HSMs to secure PKI.

The top areas of deployment to secure PKI are online roots and offline roots. According to last year’s research, 47 percent said they are deployed to secure PKI in online roots and 42 percent said they are deployed to secure PKI in offline roots.  

Part 2. Key findings

 In this section we present the research results in detail. The compete audited findings are shown in the Appendix. The report is organized according to the following topics. Whenever possible, trends in research findings from last year’s Entrust study are included. 

  • Postquantum: The Threat and the Readiness Journey
  • Cryptographic Security and Management
  • Trends in PKI Security and HSMs

To read key findings and the rest of this report, visit Entrust’s website here. 

As AI enteres the real world, it’s going to crash into the Plateau Effect

Bob Sullivan

We just learned that Waymo is recalling about 4,000 self-driving cars because they can’t read highway construction signs.

According to Road & Track, some Waymo cars “failed to recognize and drove past ramp closure signs into pre-planned freeway construction zones; Waymo recorded six of these events in April 2026 in Phoenix, Arizona. In an additional seven incidents in May 2026 in San Francisco, California, the offending Waymos drove between cones designating lane closure.”

That’s a) terrifying b) a ridiculous engineering failure.  Construction is hardly a rare condition of highway driving. How did cars not equipped for this get released into the world?

Because someone, somewhere, believes certain sacrifices must be made for progress.

Waymo’s mistake is a very bad example of the kind of real-world exception conditions that have been derailing self-driving cars for more than a decade. Those same pesky, weird realities will soon make many wild promises about artificial intelligence look a equally silly — and cost a lot of investors a lot of money.

A few years ago, I wrote a book called The Plateau Effect with Hugh Thompson, former CEO of Symantec (this piece is my opinion alone, fyi).  The concept of the book is simple: plateaus appear everywhere in life, and they bedevil everything and everyone that seems to be making quick progress. People losing weight hit plateaus; people learning guitar or a new language hit plateaus; drugs hit plateaus. Once you start to look, you see plateaus everywhere. A simple example for geeks: Finding the first 99% of bugs in software is relatively easy. Finding the last few is often a nightmare — finding the last 1 percent can take longer than finding the first 99 percent. Sometimes, they’re never found. And so it will be for AI.  The Plateau Effect looks like one of those calculus curves where you approach…but never reach…a limit.

The Plateau Effect in Learning. Anything. (phuongvu.me)

Life is full of these kinds of exception conditions.  Shit happens. One might say Murphy’s Law suggests that weird stuff like this is normal. Computers don’t do well with irregular inputs, as I’m sure you know. “That….does….not….compute…”


This is part 2 of a three-part miniseries on Artificial Intelligence.
Read part 1: Disarm AI, yes, but the Pope was just getting started
Read part 2: Artificial Intelligence needs a police blotter. Wait, it already has one!


Were a tech mogul sitting here, he’d furiously grab my keyboard at this point and tell me that millions of miles of data will solve this problem — there are only so many exception conditions on the roads, and eventually the supercomputer in the sky will be prepared to deal with all of them.  Even without The Plateau Effect, this feels foolishly optimistic to me. Exhibit A is Waymo’s current inability to deal with road construction.  But assuming that can be fixed, there will be weird, pesky, unexpected road conditions for as long as humans roam the Earth.  Dealing with the first 99% won’t be so hard.  Dealing with that last 1 percent will be very, very hard.  It’s not going to happen soon, with self-driving cars and many AI applications.

Elon Musk has been promising full self driving cars will be ready in a year or two since…2013.  There’s nothing new about this kind of hype cycle.  It’s meant to generate excitement and investment so early investors can make off with a lot of cash, funded by later investments.  And this pattern keeps working as long as investors believe in tomorrow.  Forget autonomous cars; the real future is on Mars!  And so it goes.

See, it’s easy to make a car that can ride on highways which can follow predictable patterns — roads you could drive with your eyes closed.  But when an 18-wheeler loses a tire tread and cars in front of you start to swerve and dart, well, your eyes better be open.  Another example, shared with me recently by Sean McGregor of the AI Incident database: When a dog gets loose in stop-and-go traffic, What Would Waymo Do?

But what about all the dire warnings of AI software teaching itself how to destroy humanity? First off, if you were actively building a tool that would blow up the world, wouldn’t someone at these firms throw the assembly line emergency stop switch? But more to my point here: I suspect AI investors don’t mind all these doomsday scenarios because they help build buzz. I’ve watched entire documentaries about scary AI futures that don’t even raise the question: Are we sure this stuff will actually work? The a priori assumption that we’re successfully building God is pretty valuable to these early investors.

I’m *NOT* saying none of this stuff works.  AI is great at writing perfectly trite emails, though my smartphone recently replied “how are you?” to someone on my behalf when I had no intention of asking.  That was awkward.  Can a Tesla in FSD mode drive better than a teenager playing with his smartphone? Yes, I think so. I drive a car with a lot of automated safety technology that I think works great.  But can a Tesla on autopilot deal with a dog on the highway better than a human with good judgment? Not yet. And, I’ll wager, not for a long time.

I’m harping on this point because ignorance of The Plateau Effect sets up a perfect situation for those who benefit from AI hype.   Tech moguls and PR firms generate a lot of attention and money with wild promises about tomorrow. At trade shows, I used to call this the ‘next quarter’ game.  People would hawk all kinds of great new hardware and software through amazing demos in Q3, then promise it would be ready by Q4. But in tech, Little Orphan Annie is a liar. Tomorrow is much more than a day away.

I don’t care so much about people who want to play this game with investment cash. That’s their business. What I care about is the “sacrifices” that tech firms will decide are acceptable as they run harder and harder into the Plateau Effect.  Regulators and voters have to be ready to recognize the dangers we are about to encounter, and the language that will used to distract us. Like Google itself, AI will be in beta mode for a long time.

The State of Cybersecurity Marketing Influence 2026 From awareness to selection: How buyers evaluate vendors

Enterprise cybersecurity buyers are raising the bar for technical depth, proof, and measurable outcomes. Marketers need clarity on what has changed, what still drives influence, and which approaches require reevaluation or retirement.

To address these questions, NOLA Marketing and the Ponemon Institute partnered to conduct an in-depth study of enterprise security leaders. The study reflects input from 320 enterprise cybersecurity decision-makers across mid- to large-enterprise organizations, each directly involved in cybersecurity purchases and renewals.

The research examines how CISOs and security leaders engage with marketing content, how AI is impacting the buying process, and which assets and approaches materially influence vendor evaluation and renewal. This report provides marketers with clear, data-backed insights into what resonates with today’s security leaders, and what no longer does.

Encouragingly, a majority of respondents agree that cybersecurity marketers provide information that informs purchasing decisions. Buyers continue to engage with content that marketers produce while signaling strong demand for more technically substantive assets, particularly solution briefs, website content, white papers, research reports, webinars, and technical workshops.

At the same time, the responses show areas for improvement. More than half of respondents cite gaps in marketing content, including insufficient technical and operational detail, a lack of evidence-backed claims, limited transparency about tradeoffs, and an unclear articulation of how solutions integrate with existing security stacks. Buyers indicate a need for stronger evidence-based positioning, clearer articulation of real-world performance, and tighter alignment to measurable business and risk outcomes.

The buyer journey is evolving. More than a third of respondents report using AI in the product selection process, leveraging AI overviews, chatbots, product comparisons, and even RFP drafting to accelerate research. However, trust in AI-generated outputs remains mixed, and receptiveness to on-site AI chatbots is divided, suggesting that while AI-assisted discovery is expanding, credibility and substantive content remain decisive in vendor selection.

This report presents detailed survey findings on where marketing resonates, where credibility gaps persist as buyer expectations shift, and how AI is reshaping evaluation behavior. The following analysis translates these findings into clear strategic implications for marketing strategy, content development, and go-to-market execution.

Key findings

Credibility stands out as the primary gap. Although 58% agree marketing supports decision-making, 52% say messaging lacks technical depth, and 49% cite insufficient ROI justification.

Peer-driven influence leads vendor discovery. Peer recommendations rank highest at 55%, outpacing analysts, consultants, and traditional marketing channels.

Research-backed content drives selection. Research and survey reports have the strongest direct impact at 46%, exceeding that of all other asset types.

Buyers demand deeper digital evaluation assets. Website content leads demand at 45%, followed by solution briefs at 41%, signaling that buyers rely heavily on core digital and product-centric assets during evaluation.

AI is embedded into vendor research workflows. More than one-third of security leaders now use AI overviews and chatbots, with 51% using chatbots for product research and 48% using AI overviews

Impressions of cybersecurity marketing effectiveness

A majority of respondents (58%) agree that cybersecurity marketers provide the information needed to support informed purchasing decisions, with 25% strongly agreeing. This data indicates that marketing content contributes meaningfully to buyer evaluation processes.

However, 42% of respondents are either unsure or disagree. While marketing is widely regarded as beneficial, strong endorsement is not universal. The higher proportion of general agreement compared to strong agreement suggests moderate endorsement of marketing’s ability to support the purchase decision process.

In enterprise security environments, where purchases involve technical scrutiny and risk accountability, partial confidence can limit influence. Marketing meets baseline informational needs but does not consistently deliver the depth, evidence, or clarity required to fully satisfy buyer expectations.

When asked to identify the primary problems with marketing content, respondents consistently cited gaps in credibility and specificity.

Dissatisfaction centers on credibility, validation, and contextual clarity. The friction points align closely with areas that influence later-stage evaluation and justification, rather than early-stage discovery. Nearly one in two buyers report missing proof, unclear ROI, or difficulty understanding stack integration. Marketing reaches buyers and can be effective, but it often lacks the operational depth required to sustain confidence.

To read the full report, visit Nola Marketing’s website by clicking here. 

Artificial Intelligence needs a police blotter. Wait, it already has one!

Click to visit the AI incidents database

Bob Sullivan

In our world of black and white, it’s difficult to be a tech skeptic without being labeled a Luddite.  The Holy Grail is progress, so the thinking goes, and any pesky question asking threatens to stifle innovation.  Do you want us to lose to the Chinese!?!?

It’s ok, I’ve been doing this a long time.  Not so long ago, my nickname among CNBC bookers was “Big Data Hater.”  You remember the age of Big Data, don’t you?  If you don’t, it was yet another marketing moniker that took over the tech world for a few years, stoking stock valuations everywhere it went. A mini dot-com boom, if you will.  Big Data, unfortunately, often became synonymous with Bad Data, which always gives bad results, no matter how much data you shove into the GIGO machine. Today, we call these Large Language Models, which sound much more sophisticated, but suffer equally from the same garbage problem.


This is part 2 of a three-part miniseries on Artificial Intelligence.
Read part 1: Disarm AI, yes, but the Pope was just getting started 


Back then, I would protest with a glint in my eye — how can someone hate data? That’s like hating atoms! Some of my best friends are data!

I don’t hate data. Or tech.  What I hate is thoughtless “progress” without discernment about side effects and collateral damage. And I really hate when the progress … is promised, down the road — soon! — while the roadkill piles up today.  What’s the roadkill of this never-ending tech bubble cycle? Pension funds that are crushed when the bubble bursts. Workers who are laid off in the name of cost savings needed to offset investments.  Kids who end up with addiction machines in their pockets because there’s no other legitimate business model for social media. Adults who’ve sacrificed every shred of human privacy so they can be stalked by ads for items they purchased last week. And so on.

Yes, the consequences are real, and they are here — even if the innovations are…just around the corner.

I’m not arguing that AI isn’t real. Already, it’s freed an entire generation from writing trite, jibberish-laden emails back and forth at work.  AI can turn meetings that should have been an email into a summary of said email.  That could be real progress — but let me know when those meetings are actually canceled.

Can AI do a great job of writing a meeting summary for people who weren’t really paying attention anyway? Yes, absolutely. Can it pull out that one critical moment in the meeting which most attendees missed…which might very well be what was left unsaid?  Ha! (You’ll read about this in part three of this miniseries)

AI is great at writing code, getting rid of some of the grunt work of the digital age.  It helps people with blank page syndrome get a start on papers and presentations.  And it’ll do a fine job of summarizing large amounts of material for people in a hurry. A great application I read about recently involved practicing physicians who have scant time to read all the latest medical research. It can do these things today.

As for tomorrow — there seems good reason to believe AI will be great at finding needles in research haystacks, which could very well lead to amazing medical advances.  I will be the first to cheer on this work. I’m sure I’ll need it someday.

But tech titans have a decades-long pattern of racing forward with innovations, intermediate consequences be damned. Of doing things simply because we can, not because we should — in fact, not even asking if we should.  And, specific to my main work right now, of creating tools that are easy to abuse and darn near impossible to stop.

I am not a Luddite. I think tech does more good than bad. But I think in a playoff series, “good” wins in the 7th game, and probably in overtime.  It’s often a close call.  We can’t ignore the bad things that AI will do because it might slow progress a smidge. The best thing we can do is air every single one of these side effects and work to eliminate them. That’s how penetration testing has always been done. That’s the ethos of open source software. More than ever, we need to approach the coming age of AI that way.

That’s why I was so happy to learn recently about the Artificial Intelligence Incidents Database. It is what it sounds like — a list of mishaps caused by, or enabled by, AI.  I recently interviewed one of its leaders, Harvard fellow  Sean McGregor, for The Perfect Scam, a podcast I host for AARP.  McGregor is the kind of plain-speaking genius we desperately need right now.  We talked for an episode about a family who was targeted by an AI-generated photo of the family dog depicting him on an operating table, riddled with injuries from a car accident. (That was incident 1,478 in the incident database). Naturally, our conversation covered far more.

McGregor made this point: Early on, the database was full of (funny?) incidents about AI failing to work properly. But increasingly, the database is loading up on tales of fraud committed by criminals using AI.  That might be the bigger problem, he suggests — the so-called dual use problem — as AI gets better at what it does, it gets better for the bad guys.  I left our chat thinking my sarcasm about AI’s clumsy failures might very well be misplaced.

Whatever you do, don’t call someone a Luddite because they’re worried about the future. We do get to decide what kind of future we want; we don’t have to just accept what Elon Musk gives us. In fact, I’d argue, that’s a poor choice.

Tristan Harris from the Center for Humane Technology appeared on CNN this week and made a very sharp point about incentives.  In the end, AI is going to become whatever the incentives nudge it to become. Right now, the only incentive on the table is shareholder value. That means AI will principally be used to eliminate labor costs.  The End.  But we have the chance to design other incentives right now. To reduce human suffering. To build more housing.  To make mass transit far more efficient. Heck, to enable human happiness.  Whoever told you that our society’s only goal is profit sold you a very shallow future. We can, we must, do better. An honest, real-time look at AI’s failings is going to be a big part of that.

2026 Cost of Insider Risks: Global

Ponemon Institute is pleased to present the findings of the 2026 Cost of Insider Risks: Global study. Sponsored by DTEX, this is the seventh benchmark study conducted to understand the financial consequences of insider threats caused by careless or negligent employees or contractors, criminals or malicious insiders or credential thieves.

As revealed in this research, organizations face increasing costs to respond to insider security incidents. Since the 2018 study, the number of organizations represented in the research has more than doubled from 156 to 354 in 2025 and the average number of incidents discovered and analyzed in this research increased from 3,269 to 7,490 in 2025. The average time to contain the incident decreased significantly in 2025 to 67 days from 81 days in 2024. However, only 13 percent of incidents were contained in less than 30 days.

This cost study is unique in addressing the core systems and business process-related activities that drive a range of expenditures associated with a company’s response to insider negligence and criminal behaviors. In this research, we define an insider-related incident as one that results in the diminishment of a company’s core data, networks or enterprise systems. It also includes attacks perpetrated by external actors who steal the credentials of legitimate employees/users (i.e., imposter risk).

The first study was conducted in 2016 and focused exclusively on companies in North America. Since then, the research has been expanded to include organizations in EMEA and Asia-Pacific with a global headcount of less than 500 to more than 75,000. In this year’s study, we interviewed 8,750 IT and IT security practitioners in 354 organizations that experienced one or more material events caused by an insider.

The most prevalent insider security incident continues to be caused by careless or negligent employees.

According to the findings, 53 percent of incidents experienced by organizations represented in this research were due to employee negligence and the average annual cost to remediate these incidents was $10.3 million. Not as frequent are incidents involving criminal or malicious insiders (27 percent of incidents) and credential theft (20 percent of incidents). The average cost per malicious or criminal incidents is $4.7 million and the average cost for credential theft is $4.5 million.

As shown in this research, the cost of insider risk varies significantly based on the type of incident. The activities that drive costs are monitoring & surveillance, investigation, escalation, incident response, containment, ex-post analysis and remediation.

The following are the most salient findings from this research.  

 The negligent insider is the root cause of most incidents. The average number of negligent insider incidents is 13.8 in this year’s study and the average cost for each incident is $747,107. There are a variety of reasons employees can put their organizations at risk. These include not ensuring their devices are secured, not following the organization’s policies for safeguarding sensitive and confidential information and forgetting to patch and upgrade to the latest version.

 Malicious insiders accounted for an average of 6.3 incidents and the average cost per incident of $742,125.  In the context of this research, malicious insiders are employees or authorized individuals who use their data access for harmful, unethical or illegal activities. Because of their potentially wider access to an organization’s sensitive and confidential data, malicious insiders are harder to detect than incidents caused by external attackers or hackers.

 Credential theft incidents average $842,462 per incident, an increase from $779,707 in 2024 and continues to be the costliest. The average number of credential theft incidents increased from 4.8 in 2024 to 5.3 in 2025. The intent of the credential thief is to steal users’ credentials that will grant them access to critical data and information. These attackers commonly use phishing.

 Insider security incidents in 2025 cost more and their frequency is increasing.  According to the 2024 research, 57 percent of companies experienced between 21 and more than 40 incidents per year. This year, 68 percent of organizations had between 21 and more than 40 incidents.

The research analyzed the impact security technologies and activities can have on reducing costs. Privileged access management (PAM) can save an average of $6.1 million and user behavior analytics (UBA) saves $5.1 million.

Technology and disruption or downtime are the most significant financial consequences when dealing with insider incidents. The research presents the average percentage of insider cost for careless or negligent employees, criminal insiders and credential theft according to the following seven consequences: Disruption cost (downtime), direct & indirect labor, technology, cash outlays, process/workflow changes, revenue losses and overhead.

The cost incurred by technologies (30 percent of the average cost of financial consequences) involves technologies used to respond to the insider incident includes the amortized value and the licensing for software and hardware that are deployed. Business disruption includes diminished employee/user productivity (19 percent of the average cost of financial consequences).

Companies spend the most on containment of the insider security incident. An average of $247,587 is spent to contain the consequences of an insider incident. The least amount of average cost is for escalation $39,728. The faster containment occurs, the lower the cost. If it takes more than 90 days, the average cost is $21.9 million. If it takes less than 30 days, the average cost is $14.2 million.

North American companies are spending more than the average annualized cost of $19.5 million on activities that deal with insider threats. Companies in North America experienced the highest average total cost at $24 million. European companies had the next highest cost at $18.6 million.

Health and pharma have the highest average activity costs. The average activity cost for health and pharma is $28.8 million. Technology and software are the next highest at $24.2 million.

 Organizational size affects the cost. The cost of incidents varies according to organizational size. Large organizations with a headcount of more than 75,000 spent an average of $28.4 million over the past year to resolve insider-related incidents. To deal with the consequences of an insider incident, smaller-sized organizations with a headcount below 500 spent an average of $8.9 million.

Five signs that your organization is at risk

  • Employees are not trained to fully understand and apply laws, mandates, or regulatory requirements related to their work and that affect the organization’s security.
  • Employees are unaware of the steps they should take at all times to ensure that the devices they use—both company issued and BYOD—are secured at all times.
  • Employees are sending highly confidential data to an unsecured location in the cloud, exposing the organization to risk.
  • Employees break your organization’s security policies to simplify tasks.
  • Employees expose your organization to risk if they do not keep devices and services patched and upgraded to the latest versions at all times.

To read the full findings of this report, visit DTEX’s website by clicking here. 

Criminals impersonate doctor with deepfake ads, sell supplements. Could you tell?

Bob Sullivan

Dr. Maurice Sholas has a beautiful, challenging calling — he cares for very sick children.  He takes on the saddest of cases, and works with families so kids with spina bifida or traumatic injuries can still “win” at life. For some, that means gaining the ability to visit the bathroom independently.

But lately, Sholas has been put in a no-win situation by artificial intelligence.  His likeness was used to create a deepfake video hawking supplements — specifically targeting Black consumers.  Try as he might, he still hasn’t been able to remove all the various videos that have landed on places like TikTok and Twitter.

So instead of caring for very sick children, the Harvard-educated New Orleans doctor now spends time fighting AI and learning about intellectual property law.

“What’s frustrating is that it costs money, time, effort, and relationships to protect something that should be intrinsically mine, ” he told me during our interview for The Perfect Scam podcast I host for AARP.

There’s been a lot of talk about the problem of Deepfake videos and politics — how activists might change an election by, quite literally, putting words into a leader’s mouth. I believe consumers have become relatively sophisticated at spotting the more outlandish fakes — President Trump wearing Pope garments, for example.  On the other hand, fake ads — especially those involving less popular figures — can be harder to discern. And they might ultimately cause more damage.

Sholas told me he knows of at least one person who bought the supplements based on the fake videos. After telling his story on local television, a victim reached out.

Scholas is not identified in the video; his appearance is altered slightly, and a fake voice is dubbed onto it. But his lab coat nametag is visible.

There is very little a victim can do to get fake content removed from the Internet.  Sholas first reached out to the account that posted the videos, which ultimately blocked him. The very tool used to abuse his identity was now being used to prevent him from defending himself. Initially, he says, social media companies ignored his complaints.  Later, after the local story aired, some services took action, but by then, copies of the video had spread across multiple services.  He consulted a lawyer and was redirected to a PR company.

“They said the best thing you could do is hire a PR firm basically to go out there and do a sweep of the internet and push positive content to counteract whatever misinformation is there,” he said. That kind of search engine optimization could cost up to $20,000, he was told. Instead, he has taken to posting a series of self-made content.

“When someone borrows, to use a kind word, or steals, to use a real word, it puts me at risk, it puts my medical license at risk, and it puts my livelihood at risk. And to protect all of that, there’s nothing I can do as a small guy but spend more money,” he said.

Fake video is far more pervasive on social media than most people realize, says Frank McKenna, chief fraud strategist of a company called Point Predictive. He’s also the author of the popular Frank on Fraud newsletter.

“I see these all over TikTok, all over Instagram, all over Facebook. They’re inundating people’s news feeds; the social media platforms I don’t think are doing enough to kind of control the problem,” he told me.

Dr. Maurice Sholas shows a reporter the deepfake videos he found. (WLTV.com)

NBC’s Al Roker was actually the victim of a similar deepfake attack about a year ago. You can watch his interiew about it at this link.

“I think people probably don’t realize how many deep fakes they’re seeing as they scroll through social media. From my experience, it’s at least half the videos that you’re seeing ….there’s some element of AI generation in those videos. And that’s only going to get worse,” he said. “The case will be that most of the content you’re looking at online is AI-assisted in some way …  So people are going to have to get accustomed to the fact that they’re going to have to question pretty much everything. … These other celebrity deep fakes, I think, are going to surprise a lot of people, because they’re becoming more and more common.”

How hard is it to make fake videos like the ones that use Sholas’ likeness? Not hard at all, McKenna says.

“Using information off of YouTube videos, Instagram videos, or Facebook videos that you post, the criminals and scammers can take that content and put those into AI generating videos, and make you say anything that they want,” he said. “So just a few seconds of video can create these…they call them AI avatars, and they can basically make you sell vitamins or make you sell crypto investments and things like that. So it’s not hard at all, anybody can do it and a lot of scammers are.”

And, perhaps the most alarming part of this dark new trend — consumers are over-confident in their ability to spot fakes.

“The thing about AI deep fakes is 60 percent of the population thinks they can spot them, but in reality, I think a study … found that only .1% of people can actually identify those deep fakes,” he said.

Minimizing Security Risks through Effective Cyber Asset and & Exposure Management

The purpose of this research is to gain insight into how organizations manage their cyber assets and exposures across the global attack surface through continuous discovery, prioritization and timely remediation.  Ponemon Institute surveyed 617 IT and IT security practitioners in the United States who are involved in managing and addressing the attack surface across the IT footprint and are familiar with their organizations’ approach to measuring and addressing cybersecurity risk.

Discovering and tracking cyber assets involves using specialized tools to automatically find, catalog, and monitor all devices (on-prem, cloud, remote) in the IT environment, creating a real-time inventory to manage vulnerabilities, ensure compliance, and defend against threats, often using scanning, API integrations, and traffic analysis to map the complete digital footprint.

The primary systems used to discover and track cyber assets are cloud providers (49 percent of respondents) and Configuration Management Database (CMD) or IT Asset Management Platforms (ITAM) (44 percent of respondents). A CMD is a specialized database used to store information about an organization’s IT assets, their attributes and their relationships. An ITAM platform is used to manage an organization’s technology hardware and software throughout their lifecycle.

Not used as frequently are vulnerability scanners (28 percent of respondents). Vulnerability scanner tools automatically find security weaknesses in networks, applications and systems by comparing configurations/software against vulnerability databases.

Recommendations from the research to improve cyber asset and exposure management practices

 Consolidation of assets and sensitive data improves the visibility into asset and sensitive data disclosed or left unprotected. Forty-five percent of respondents say their organization consolidates into a single view asset and sensitive data disclosed or left unprotected and accessible to unauthorized individuals or systems.

A unified cybersecurity platform offers benefits like centralized visibility, faster threat detection and response, reduced complexity, lower costs, and simplified compliance by integrating diverse security tools into a single system, providing a holistic view, automating tasks, and streamlining management, leading to a better security posture and operational efficiency.

The inability to identify missing assets requiring security controls is a risk with potentially serious consequences.  Not identifying missing assets can cause financial loss, legal penalties, operational disruption, and data breaches. Unidentified assets can be stolen, misused or lost, leading to compliance failures and reputational damage. Proactive tracking, robust documentation, and strict protocols are crucial to prevent these consequences. Less than half of respondents (46 percent) identify assets that are missing and require security controls.

More frequent updates of asset inventories and discoveries of inconsistencies are needed to minimize security risks. Only 30 percent of respondents say asset inventories or CMDBs are updated or reconciled daily (13 percent) or monthly (17 percent) and 37 percent say the frequency of finding inconsistencies in asset and sensitive data exposed due to duplicate records, conflicting names and values is daily (17 percent) or monthly (20 percent). As a result of not regularly updating their inventories or finding inconsistencies, less than half of respondents (48 percent) are very or highly confident that their organization has a comprehensive up-to-date list of all its hardware, software and data assets. Q10

The lack of effectiveness in prioritizing risks makes remediation of security exposures or data misconfigurations difficult. Respondents were asked to identify the one biggest challenges in remediating security exposures or misconfiguration data. Twenty-six percent of respondents say risk prioritization is unclear and 24 percent of respondents say there is no clear ownership of the issue.

Contextual data in risk prioritization enriches basic threat severity scores (like CVSS) with an organization’s unique environment, business impact, and threat intelligence to focus on the most critical risks. It provides actionable insights by layering details like asset criticality (e.g., PII data), network exposure (internal/external), and exploitability to identify the most urgent vulnerabilities for remediation. This approach prevents security teams from being overwhelmed by data by applying business logic to identify high-impact threats, ensuring resources are spent effectively on what matters most to the business. Only 23 percent of respondents say contextual data is always used and 26 percent of respondents say it is used frequently.

The Continuous Threat Exposure Management (CTEM) is a proactive cybersecurity approach that combines vulnerability management, attack surface management and validation to identify, prioritize and fix security risks. Respondents were asked to rate the alignment between the CTEM framework and asset and exposure management practices on a scale from 1 = not aligned to 10 = completely aligned. Fifty-two percent of respondents say alignment with CTEM is very or completely aligned (7+ on the 10-point scale).

One of the greatest constraints to SecOps’ ability to manage cyber assets and security exposures is complexity in the IT infrastructure. Sixty percent of respondents say reducing investments in security tools and the complexity of their organizations’ IT security infrastructure is very or highly important.

Only 28 percent of respondents say their organization has a formal SLA for all highly critical or critical vulnerabilities and 27 percent of respondents say there are no formal remediation timelines or SLAs. Vulnerability Remediation SLAs (Service Level Agreements) are defined timelines for fixing security flaws. These agreements set expectations, prioritize efforts, and improve collaboration between security and IT teams to reduce risk efficiently.

Part 2. Key findings

In this section, a deeper dive into the research is presented. The complete findings are shown in the Appendix. The report is organized according to the following topics.

  • Discovering and tracking cybersecurity assets and exposures
  • Prioritization of security exposures is a challenge
  • Organizations’ approach to security exposure remediation practices
  • Cyber asset and exposure management practices

Discovering and tracking cybersecurity assets and exposures

Consolidation of assets and sensitive data improves the visibility into asset and sensitive data disclosed or left unprotected. Forty-five percent of respondents say their organization consolidates into a single view asset and sensitive data disclosed or left unprotected and accessible to unauthorized individuals or systems.

A unified cybersecurity platform offers benefits like centralized visibility, faster threat detection and response, reduced complexity, lower costs, and simplified compliance by integrating diverse security tools into a single system, providing a holistic view, automating tasks, and streamlining management, leading to better security posture and operational efficiency.

Some 63 percent of these respondents say they have a unified platform that aggregates data from all sources. Fifty-eight percent of respondents use an internal script or a database/data lake that combines data from different tools.

To read the rest of these key findings and download the entire study, visit The Axonius website. 

What’s an amygdala hijack? And why is crafting is a great cybersecurity tool?

Bob Sullivan

The most dangerous hack is a brain hack.  And criminals are getting very, very good at that.  Meanwhile, I fear, the rest of us have spent precious little time learning to defend against brain hacks.  Hopefully today’s piece will help a little. Today I’m going to discuss an important way to think about brain hacks — the amygdala hijack. And crucially, I speak with an expert who offers practical ways to calm your amygdala.  Who knew crafting could be a fraud-fighting, cybersecurity tool?

Our brains were designed thousands of years ago, in large part to help us run away from large predators.  Human brains haven’t really caught up to the digital age, and that fight or flight instinct is exploited by criminals constantly.  There’s a warrant out for your arrest; there’s child porn on your computer; wire $2 million or you will be fired…and so on.

The key for criminals is to knock us off our game, separate us from our rational selves and shove us into our reactive selves — then tell us the only way to avoid the dinosaur chasing us is to buy a bunch of gift cards or shove money into a crypto ATM. You can tell people not to do these things in a classroom or an email a zillion times — those consumers will nod their head and maybe even remember those words in the rational part of their brains.  But it won’t do a lick of good when criminals cook up just the right story at just the right time — grandma, I’m in jail! — and instinct takes over.

That’s an amygdala hijack, and it can happen to anyone.

Every time you hear the story of a terrible Internet crime and say “How could they fall for THAT? How could anyone in their right mind…”  you are feeding the problem.  You are an unwitting accomplice to these crimes.  All this quiet superiority keeps us in the situation we find ourselves in. The implicit “they should know better” keeps us from investing in training and tools that counteract these very human attacks.

It’s all part of the trap we are falling into right now; we’re playing into the hands of organized cybercrime, and it shows. Fraud is skyrocketing at extraordinary levels, by any measure.  Our grand tech tools are being used against us to feed crime gangs, foreign governments, and yes, terrorism.  These crimes pay for North Korean missiles, for heck’s sake. We are counting on the most vulnerable people in our population to form the front line in this war we’re losing. Worse yet, these foot soldiers are fighting criminals armed with billions of dollars of research and even more valuable tech tools, and they have to “win” 100% of the time.  We need a new strategy.

A big part of this will be understanding how brains work, and planning around that reality. To that end, I was thrilled to interview Austin Cusak recently. He’s an expert in behavioral science and a trainer at the FDIC.  I’ve seen him give talks on amygdala hijacking before, so I was eager to interview him about that. You can listen to our chat at The Perfect Scam podcast — and I hope you will — but if podcasts aren’t your thing, here’s a transcript of our chat.  This episode also includes an interview with a repeat romance scam victim, so we have an example to discuss.  My chat with Austin begins at about 32 minutes. Don’t miss his amygdala calming techniques at the end.

Click play to listen or click this link


————-PARTIAL TRANSCRIPT——————

[00:32:07] Bob: We are in a different world, yes, but it’s a world we need to understand. We all have questions about how someone we know might become a victim of an ongoing long-term crime like this, how a person’s heart and mind can be well hijacked. And here to help us understand that much better is Austin Cusak. He’s Assistant Professor of Leadership Development at the FDIC. He’s an expert in behavioral science.

[00:32:35] Austin Cusak: A lot of us don’t realize that our brain right now is in the exact same configuration as its been for the last 35,000 years. And so our brain is very worried about snakes in tall grass, about sabretooth cats. It’s very worried about attacks from other tribes. So the brain is going to do whatever it can to be a good member of its tribe. So we are very tribal in that category. So the current configuration of our brain is not wired for social media, it is not wired for fraud from the inside. So that’s the first thing that happens to Anola is criminal is convincing her that they are part of her group, part of her tribe, a safe person first.

[00:33:29] Bob: Once on the inside, once a criminal gets a victim to feel like a member of the same team, the same tribe, then the criminal can get to work turning off the victim’s rational side.

[00:33:41] Austin Cusak: The easiest way to kind of explain why this is happening is, so Daniel Kahneman got a Nobel Prize for his work on why the brain does what it does, over 20 years of research, and he boils it down to these two types of thinking. And so I’m going share this as just like a simplistic way for us to understand a lot of these complex things. You are either doing fast thinking, or you are doing slow thinking. Neither is bad, it’s just that your brain is going to receive input and when it’s receiving input, it’s going to say, okay, am I in danger? And if you are in danger, or perceive some type of danger, it goes right to the amygdala and it says, fast thinking, I’m going to use the emotional reactions that I know. I’m going to poke through really quick this limbic region which stores our memories. Do I associate this with something bad? Yes. I run or I fight. And then there’s the slow thinking which is what we want to have engaged which is, there’s no immediate threat. I can now take my time, go out to the prefrontal cortex, think about associations, what kind of long-term planning do I associate with this? What kind of risk assessment might there be with this? So the brain’s going to go one or two ways. And so the criminal’s goal is to prevent Anola at every stage from having this slow, rational logical thinking.

[00:35:15] Bob: So criminals want to talk past the thinking part of your brain and talk right to the instinctual part.

[00:35:22] Austin Cusak: Okay, so amygdala hacking by the way that Goldman described it, is this immediately overwhelming emotional response that our brain is perceiving as a threat that is going to trigger the fight or flight and bypass our brain’s logic mechanisms. So it is, in fact, fast thinking. It’s Kahneman’s fast thinking. That is the hijack. I personally in my experiences, I expand the amygdala hijack to not just that overwhelming emotional response, but also the hijack of the slow, insidious relationship-building, trust-building, love-bombing. It is any actions that the criminal is taking to force the victim into fast, emotional thinking all the time. It is, that is the hijack. The hijack is I only want information being received through my eyes, my ears, my skin. All that information straight to the amygdala, emotional responses. That’s the hijack. That’s why we can’t see the red flags, that’s why we ignore things. That’s why the brain says, something’s fishy, but it would be too painful for me to actually explore that road. Too painful. I’m going to avoid the pain; my emotions feel this. And part of the amygdala hijack is creating lots of cognitive dissonance, which for a criminal is a very good thing. The criminal wants to create cognitive dissonance where there are these two competing thoughts in the victim’s brain because then they can provide the answer. They can have the emotions tied to that. That’s the hijack.

[00:37:19] Bob: And when our brains are hijacked, criminals can really get down to the business of grooming and financial manipulation. It is so hard after the fact to talk about some of these stories, to compress 18-months of manipulation into a few minutes of a podcast. Even the language we’re using is rational, and we’re talking about irrational things. It’s really important to understand that all of us, under the right circumstances, say and do things based on purely emotional or instinctual responses.

[00:37:51] Austin Cusak: I tried to talk with even some of my neighbors about this and her story, and I was very disappointed in their responses to it. Well she should have known better. So it really does, like we, we tend to very quickly move into that victim attribution or the attribution bias, like we should all know better. Now that scam and how that went down, it was kind the same playbook that they used, is that they saw the opportunity, it wasn’t an immediate, I’m going to ask for money, it was a slow, them impersonating someone. They did the same thing. But she was very–, she was wary, she didn’t send them money, but the tactics didn’t change that they, the brain still needs that stability. The brain still hopes that it’s going to happen someday. So when I heard the second story, like on first blush you hear that it happened to her a second time, and the first thing that we think of is, she should have known better. It’s that attribution bias. But then when you hear her explanation of it, and how that started to go down, and how they did it, you’re like, wow these, these people and whoever is creating these textbooks that they’re following, they’re very good. Like they are very good at what they’re doing, and think of it kind of like a car salesman, and I don’t mean to demean car salesmen, but there was, there was a time where I had a friend that was going to get a car, and they were like, ah, I’m going to win this negotiation. I’m going to talk them down, and in my head, I was like, wait a second. So you’re not a negotiator, you don’t have experience doing negotiations, and you’re going to go up against someone that does this all day, every day, and you think that you’re going to like conquer them? This is you against them. This is their job. This is the full-time thing that they do day in and day out every year making small tweaks, making minor things. That’s what these criminals do. They are masters at manipulating, they are honing their craft, they are making little tweaks here and there, so when she is reaching out, right, so this is, the brain needs closure. So that’s part of it is that she has this terrible thing happen to her, and our brains are wired to seek closure.

[00:40:13] Bob: While it might be hard to understand why Anola suffered a second romance scam, in some ways the first time set her up for the second. Remember she reached out in an attempt to warn a person she thought was a victim too. The man’s image was being used as a lure by criminals.

[00:40:29] Austin Cusak: That second criminal is looking at this as, she’s already in this very heightened emotional state. It is very easy for me to now trigger her fast thinking once again by pretending to be the person that she really hopes me to be, because she’s trying to do the right thing and I can take advantage of that.

[00:40:53] Bob: So in some ways, the fact that she was already a victim made her more likely to be a victim again?

[00:41:00] Austin Cusak: I don’t know if that’s every case. I’m sure that there is probably some research that has been done on that. I would say from my understanding of just behavioral science in general, yes, absolutely. Especially if she’s been in that state of fast thinking for a very long time, she does not yet have closure, she has not yet processed everything that has happened for her. The brain is going to reach and stretch, and want to have, ’cause she would still be in the state of cognitive dissonance, I’m assuming, in that moment; where I’ve got these two competing ideas, I need an answer. And that gives the criminal a very good opportunity to start to control that narrative, provide those answers, lead that person where they want it to be.

[00:41:51] Bob: And there is another powerful tool criminals use, they’re very good at appearing to have very intimate conversations.

[00:41:59] Austin Cusak: We’re looking at criminals that are very masterful at using cognitive empathy. They’re not feeling these emotions, but there is a thing called the dark impact where you can use empathy to very much manipulate other people. I would say that a lot of the tactics of dark empathy is exactly what the cult leaders are using to manipulate, to keep manipulation, and they get very good at it.

[00:42:25] Bob: Dark empathy is a new term to me.

[00:42:27] Austin Cusak: The dark empathy?

[00:42:28] Bob: Yeah.

[00:42:29] Austin Cusak: There, there’s quite a bit of research on it that you can kind of dig in in the leadership realm, and this is why I mentioned this because it’s going back to leadership development. When we are trying to develop leaders, sometimes, and this does not happen very often, but sometimes we do come across someone who is a textbook narcissist. And I don’t mean that in kind of the, ah, they’re narcissistic. I mean that they would top off if they took an assessment for narcissism. They are drawn to tactics of leadership, because at its core, a tactic of leadership is to positively influence others towards a common goal. I can remove that positively and just influence others towards a common goal. And so the people that want to manipulate, the people who want power, find that by studying leadership, by studying how to use cognitive empathy, by studying active listening, they study those same tactics which they can then use to move upward. They can then use to shift others’ behaviors. And that’s essentially what she ran up against.

[00:43:35] Bob: Meanwhile, the victims are in the throes of a crime and what feels like a very real romance. The end is an incredibly painful moment, so is telling people about what happened. Criminals use that to their advantage too.

[00:43:50] Austin Cusak: And so just like with a lot of people not reporting these things, or not talking about these things, is because we fear that we will experience more pain of rejection, pain of betrayal if we openly talked about these types of things with people. So we avoid that pain, and that is a normal thing, it’s just kind of a crappy thing, especially in regards to this. The criminals know this. They know that we are going to avoid those feelings of embarrassment because our, again, 35,000-year-old brain says, if I show myself to be a weak link, if I show myself to be someone who can’t be trusted by this group, I might get kicked out of the tribe, then I’m dead. So this is a survival tactic that the brain is going to constantly push is I must hide these things because this could lead to a problem with the tribe, but also, I’m going to avoid this because I know that this will experience, like I will feel pain if I go down this road. And so as we start to kind of approach that pathway, like that physical pathway, the brain’s like, nope, nope, I’ll do it another day.

[00:45:07] Bob: I don’t think we talk enough about the avoid, pain avoidance element to this, because it is very painful that moment when you realize, my money’s gone forever. That’s a very painful recognition.

[00:45:17] Austin Cusak: I think the threat of betrayal of the whole thing not being real. As a personal thing, I actually had a conversation with someone very close to me who was in a religion, and some stuff came out about the religion that kind of debunked some of the founding tenets of the religion, and they stayed in it. And I was asking them, why? Why stay in it? And it was understandable and it was very hard for me to listen to them because they’re much older, and they said, my entire life I believed this. My entire life. It’s part of my identity, it’s my community. If you took this away from me, it would break me.

[0046:03] Bob: Austin really wanted to drive home a point about these powerful tactics that criminals use. Some of them are used in traditional persuasion. He already mentioned sales tactics, but you might find some of these ideas in leadership training or management training which is part of Austin’s job at FDIC.

[00:46:21] Austin Cusak: I may be a very unpopular person for saying this, Bob, but a lot of the leadership tactics that we use is exactly what the criminals use. They use the same tactics but they use it for nefarious purposes. But influencing people, the tactics, the way the brain works, it’s the same. And so in, in some cases it is us saying, these are the things that we’re going to practice so that you can positively influence. And at the same time it is you need to be aware that these people are doing these things to you so that you can actually counter them, so that you can stop them, so that you can be on the lookout for. So in that world of leadership development, there is a surprising amount of crossover in terms of both helping people and manipulating and avoiding manipulation.

[00:47:14] Bob: So there are light and dark ways to use behavioral science, right?

[00:47:18] Austin Cusak: Cialdini has his book “Influence” and his book “Pre-Suasion,” and I’m going to throw out the disclaimer that things that I say are not representative of my agency. These are my own opinions, but I do want to point out that Cialdini has done a lot of great research on this subject, specifically on influence. And he even calls it out in his books about like the tactic is the same. You can use this. It is the knife that you can use to carve something beautiful or stab someone in the back, but the brain’s going to receive it the same way.

[00:47:53] Bob: It did strike me talking with Anola that the criminals did more than just appeal to her emotions, however. Remember, they showed her an account that allegedly had $4 million in it, so they were working to counter any skepticism she might have had.

[00:48:08] Bob: So it seems to me like they, they know how to play in the rational brain space as well.

[00:48:14] Austin Cusak: Yes, so, so that is, that is part of the ethos, pathos, and logos that has been used on us since Aristotle perfected by Plato, so we’re talking what 300 and like 48 BC that we had these three compelling means of persuasion. 3–, 347BC where it is essentially what is going to be the most compelling for you? Am I going to make an appeal to character, lead with an appeal to emotion and then follow it with just enough logic to make it plausible. Those three things, ethos, pathos, and logos, is the core of marketing, like all marketing is based on that. You see a car commercial and it is a basketball player who’s famous driving the car. That’s an appeal to character. So the use of logic, the use of data to reinforce is very compelling. But that is the answer to the cognitive bias. If it’s plausible enough, if it’s data and it’s plausible enough, or if they say, look, I have these bank accounts, why would I need your money? It’s plausible enough to answer and remove the cognitive bias. And that is the insidiousness of this entire thing is that I put like, I, the criminal, am putting my victim into fast thinking. They’re making emotional decisions. The second that they start to have this, and I can feel them starting to pull away, I reinforce it with lots of love, lots of dopamine. When they start to question it, I give just enough data, just enough of a logical response to, to basically shift away from these two competing ideas so they can only hold onto this one idea. I use time pressure, I use empathy, I, right, like I reinforce these things. And then, this is the thing that is really just err, is that they just inspire the shared vision, and then they reinforce it with this is our future together. This is the compelling image. This is the dream of what’s possible with us if this happens. This is the long-term interest. You are the only one that can do this. And they paint this big, shared aspiration.

[00:50:39] Bob: Feeling like you’re on the same team with that shared vision is also a behavioral trick that well-trained criminals employ.

[00:50:47] Austin Cusak: And so when you’re in alignment with each other, the principle of this is a psychological principle called homophily. And homophily is this idea that we really gravitate towards people who like the same things we like, who we perceive are part of the same group. So a great example of this, I play a lot of Dungeons and Dragons, I’ve been playing Dungeons and Dragons since I was 8 during the Satanic panic, where we had to hide it from my mom when me and my two older brothers did this. So if I meet somebody and they also play D&D, I instantly like them. They could be a terrible human being, but I’m now giving them the benefit of the doubt because they love a thing that I love, so therefore, they can’t be that bad. And that is that concept of homophily. So Pedro did that very well. And also, what the scammers did, and like she said, I am suspicious, right. So the cognitive processes are happening, he didn’t back out at that moment, he kept going. Even multiple times when in that relationship when she called him out on things, he weathered those storms. He talked her down. He convinced her otherwise. He got outraged. He threatened to walk. And that is really hard for a couple of reasons. One is because we crave that dopamine, we crave that oxytocin, and the threat of that being yanked away very suddenly, that’s going to hurt. And the brain is going to avoid pain. And this is one of the things that we don’t necessarily recognize, is that our brain is going to process physical and mental pain the same way in the exact same area. And it wants to avoid it. So that mental pain must be avoided. The brain says, can’t have this, don’t want this.

[00:52:45] Bob: Okay, so under all this knowledge of how our brains work, and sometimes work against our own interests, what can we do to better protect ourselves from an amygdala hijack? For starters, we could teach ourselves to be more understanding of victims. Austin has a lot of very practical advice for helping someone who you’re worried is under the influence of a criminal.

[00:53:08] Austin Cusak: When we suspect someone is ignoring these types of red flags, when they are stuck in that amygdala hijack, they are not in control of this. They have someone who is manipulating them and the self-acceptance that they are being manipulated is going to hurt. It is going to cause a lot of pain. So the first thing that we want to do with that person is to use our own cognitive empathy, because if we’ve not been through something similar, it can be very challenging to allow our emotions or even our compassion in. So cognitive empathy is, I’m going to listen, I’m going to get very curious, I’m going to try to ask questions, I’m not going to give judgment, and then this is probably the first thing that I would say. Approaching this as, I know someone that I suspect is being uh, is, is being manipulated by criminals. So this is that that’s the lens I’m looking at right now. That person needs to say, okay, before I give you any advice, I will always ask if now is a good time for me to share some advice or give you a thought. I always want to give that person the locus of control. It’s not that they’re not going to receive that information, it’s is now a good time? It’s, hey, I have a real concern that I need to talk to you about. Is now a good time for me to share that? That’s the first thing is you don’t let that person off the hook, you don’t say, oh, I’ve got some, I really want to share this. Is it okay for me to share it? Is now a good time for me to share it? Let them choose the time. We want them to have that control, ’cause oftentimes they know, they’re feeling that, and there’s that initial fear, the cortisol is spiking. The adrenaline starts to flow because the brain now feels, I’m in trouble, I’m in danger. So when we say, is now a good time for me to share some thoughts or give you some advice… if they say no, that is amazing. Okay when can I do this then? Let them choose a time or they’ll say I’ll come back to you. They always come back. I use this tactic frequently. Sometimes it’s a day, sometimes it’s two days, the person almost always comes back to me and says, I am now ready to talk about this thing. But you don’t want to try and force the flag on them when they are in that state of emotion.

[00:55:42] Bob: Getting back out of the highly emotional state, out of the amygdala hijacking often requires something Austin calls calming the amygdala, talking with empathy can help others, but you can do that for yourself too.

[00:55:56] Austin Cusak: If you do physical movement, you can also have a mental shift with that movement, hence the beauty of going and getting coffee. I can’t tell you, Bob, I do a lot of coffee at work, and the code for, hey, can we get coffee, it’s not really a, I need coffee, or I want to spend time with you, the code is, I really need to get a sanity check from somebody, and I don’t really want to ask, ’cause that’s embarrassing. But in the act of walking to the coffee and walking back, that allows the person to share the thing and calm the amygdala. The other thing is breathing. So there’s been a lot of research that’s done on the, the 4×4, the breathe in for 4, hold for 4, release for 4, hold for 4. And then there’s also a lot of research that’s been done on what’s called the 478, which is where you breathe in for 4 seconds, you hold for 7 seconds, and then you do this exhale for 8 seconds. Now the reason why these work so well is because when you are breathing in a normal way, you are cueing and telling the amygdala, I am safe. I am not in danger. So even if that cortisol is starting to spike and the adrenaline is starting to spike and your body is going into fight or flight, you can calm it. Some people are like, ah, I don’t want to breathe. So just go for a walk. Just, just walk and then talk and then say, hey, I want to share this with you. But that’s it, is that those are the very first steps that always work because we have to get that amygdala calmed down before we can share something with them.

[00:57:45] Bob: Amygdala calming doesn’t have to begin with a conversation though.

[00:57:49] Austin Cusak: When someone is suspicious that they might be stuck in one of these things, there’s a lot of advice online, it’s oh, walk away or do this thing, or put your phone down or take breaks; that can be really hard to do. My number one recommendation when I am working with someone who is in one of these highly emotional states, is to try and do a hobby, try and do an activity that allows you to get into flow a little bit, meaning that it is requiring some effort but not too much effort. As an example, I started painting miniatures, these little miniatures that I use for my games. My wife started playing pickleball. I know that some people really like to knit, taking walks. There, there are lots of activities that you can, when you are doing that type of activity that is requiring the brain to hyperfocus on something and it’s requiring effort, but not too much effort, just the, the right amount, right, being in the zone, getting in the flow, that is giving enough space for the brain to say, I’m not in danger, I am going to shift from the fast into the slow thinking. It’s the same thing. We want to try and find ways to move the brain more into this slow, analytical thinking.