RSS Amplifier

TechXY · Jun 10, 2026

AI Risk and Cybersecurity with Ankur Sheth

0
Sign in to vote or save

Frank Gullo · TechXY

Ankur Sheth

Ankur Sheth has spent 25 years at the intersection of cybersecurity strategy, risk management, and enterprise transformation — advising CISOs, risk officers, and boards across North America, Europe, the Middle East, and APAC. He has seen the threat landscape evolve from a technical discipline into a boardroom priority, and now leads both cybersecurity and AI risk advisory at FTI Consulting.

This episode explores the compliance-versus-security gap still present in many organizations, why the human layer remains the most persistent vulnerability no matter how much technology you deploy, and where AI risk and cybersecurity converge.

Listen to “AI Risk and Cybersecurity with Ankur Sheth” below, or on Apple Podcasts, Spotify, YouTube, Amazon, Pandora, or wherever you get your podcasts. The episode transcript is shared below the embed.

Frank: Welcome to another episode of TechXY Turbo. My name is Frank Gullo and I am your host. On this episode, we’re joined by Ankur Sheth, who has spent 25 years at the intersection of cybersecurity strategy, risk management, and enterprise transformation, advising CISOs, risk officers, and boards across North America, Europe, the Middle East, and APAC. He has seen the threat landscape evolve from a technical discipline into a boardroom priority, and now leads both cybersecurity and AI risk advisory at FTI Consulting. Ankur, thank you so much for being here. Good to have you on the program. How are you doing today?

Ankur: Doing great. Thanks for having me, Frank.

Frank: Absolutely. Very hot topic — AI and security. So we’re going to ask a lot of questions about that. You spent over 20 years in cybersecurity, starting at PwC, building out a global advisory practice, and now stepping into a new chapter at FTI Consulting. That’s a career arc that spans the entire modern history of cyber as a discipline. How did you find your way into this field, and how has the nature of the work changed from where you started to where you are today?

Ankur: Yeah, thanks. It’s an interesting story. And firstly, I just want to say thanks for having me and I hope everyone finds this helpful and valuable. I didn’t know I was going to be in cyber when I first started. I’ve been in cyber since I graduated from college. I was actually at Penn State — and I need to talk about that later. They had created a new major that was targeting security as one aspect of consulting, but more consulting more broadly. So when I joined PwC, they threw me into a cyber practice — a sub-practice called identity management, which I didn’t know anything about at the time. Now it’s the center of security. I kind of started from there and grew from there.

It’s been an interesting journey because I started out specialized in identity management, but then became more generalized as I grew through the ranks and am now running my own practice, my own team. I really kind of fell into it, but I will say it’s been a very happy career choice. I don’t think I’m really worried about job security in this field. It’s been great over the past 20, 25 years.

Frank: A good career to fall into. So you advise CISOs, company officers, boards — the people ultimately responsible when things go wrong. In your experience, what’s the biggest gap you see between how organizations think they’re managing cyber risk and how they actually are?

Ankur: That’s been a constant theme throughout my entire tenure in this field. The disconnect between boards or even certain levels of executive management and the teams that are hands-on keyboard doing the work. The biggest disconnect is the perceived security posture — what some people think they have versus what is actually happening. There are a couple of reasons for that.

One is that a lot of organizations conflate compliance with security. Because I’m in a regulated industry — financial services, healthcare, whatever — and I have to do these certain things, that means I’m secure. But that’s not the case. No cyber professional will say that. Security goes beyond compliance. A lot of executives think, oh, I’ve been compliant with HIPAA, so I’m good. Not the case.

The second thing is visibility. A lot of the organizations we tend to work with have never done an assessment. They don’t know what they don’t know. Having a more holistic view of all the things you’re doing and not doing, and then making updates and changes as you go forward, is really important. A lot of people are just reacting — I had an incident, someone got into my network through XYZ, now let me fix that — more of a band-aid format. That’s really a technical thing versus thinking about it more holistically at the board level.

And then lastly, which ties this all together — technology. I can’t tell you how many times clients have said, oh yeah, I purchased the best EDR product, so I’m covered. That’s not the case. Technology is not a silver bullet. You have to build technology into the program around processes, governance, and policies. If you’ve purchased a technology and you don’t actually implement it properly or tune it properly — especially in the security world — that’s not helpful. A lot of people just think, oh, I purchased something, I’m good to go. I see that a lot at the executive level. They spend a million dollars on tools, but it’s not actually implemented properly when you talk to the technical people. That’s a gap.

Boards and executive teams often think cyber is a project — let me implement this or that and I’m good to go. But as anyone who’s been in the field for a long time knows, it’s much more than that. It’s a program. It’s constantly evolving, the threats are changing, and we need to think about it that way. How do we constantly enhance and improve our program versus implementing point solutions? That’s the gap we try to bridge every day through education — helping educate executives and boards on how to think about this risk.

Frank: Great elaboration. And I hear a lot about cost too — some firms invest so much that they feel that’s all they have to do, while others operate from a scarcity mindset. Security is more than the products you’re buying. So your playbook for really making people take it seriously — going beyond the products, you mentioned training — how else do you really help them see the importance of it?

Ankur: There’s no one answer for that because we’re dealing with people and everyone thinks differently about how they want to manage their organizations. But at a high level, especially when we’re thinking about boards, it’s about how do we translate what we’re doing on the ground in cyber into their language. And for boards, that language is risk. They think about enterprise risk, financial risk to the organization. Cyber risk is another type of risk they need to be thinking about. You can look at any analyst reports and surveys that come out and boards and executives consistently have cyber in their top 3 or 5 risks that they’re managing. At least it’s at that level now.

And how we translate it from a risk perspective — if we go a level deeper — is to a quantitative measure. If we say, hey, ransomware is costing — the IBM report said around $4 million on average in the last report — we want to reduce that risk. We can’t have that hit our company. So how do we actually bring that risk down, mitigate it, transfer it through insurance, whatever it might be? Bringing it to their language is really about what makes sense to them and how they think about running the organization. That’s really risk and financial.

Frank: Totally. I participate in our company’s annual SOC audit, so I work closely with finance and a risk register as part of that. And since we’re talking about risk — you’re leading not just cyber advisory but specifically AI risk, which is a relatively new practice area. What does AI risk mean as an advisory discipline today as the field is developing day by day? And how is it different from traditional cybersecurity risk?

Ankur: I think of AI risk like any other new type of technology risk — we can talk about quantum down the road as well. Technology risk has always been around, but as we develop and implement new technologies, we have to think about how that technology affects what we do, our systems, our processes, our people.

AI risk brings a whole different type of risk. In cyber, we’re always thinking about what if someone breaks into the network or system and gets access to information and data — we have to manage that risk. AI is a little bit different. It’s not just about someone breaking in — that can still happen — but it’s also what if the AI system itself causes harm, or fails, or breaks in a way we haven’t anticipated. Things like bias, model failures — that’s a whole other type of risk under the technology risk bucket that we haven’t really had to build for or think about in the past.

From an AI risk advisory perspective, we’re looking at how we build governance around that, how we build testing, and other processes to actually manage and mitigate that risk. It has shifted, at least for me, from our traditional cyber work into a new world of something we’ve never actually done before. And I think we’re all still figuring it out — I don’t think anyone can say they have it all squared away. Every day we’re evolving how we help clients think about managing this risk. But there are new frameworks and new regulations coming out every day, not just in the US but across the world, that are helping frame this problem. Bringing that all together is how we think about addressing it with our clients.

Frank: That makes sense. You mentioned people, process, and technology. Talk to most security professionals and they’ll say the weakest link is often the human — social engineering. As AI is involved in more sophisticated attacks, nation states, personalized targeting, how do you think the human layer is going to hold up?

Ankur: This is the tough part. Every article, every analyst report we read says the human factor is the greatest vulnerability. And it’s not wrong — that’s the most common way bad actors get into our environments. But I don’t think we can just keep blaming the human element. We’re really in an environment that’s designed to deceive us, to deceive humans. Especially with AI attacks.

You know how a system works — it follows a certain path and you’re trying to break or go around that path. But humans don’t have a single path of thinking. We all think differently about how we react to events and things. So the human element is of course going to be harder to protect against because everyone’s going to be different. And now with AI attacks, it’s even more amplified.

The easiest example, which people have heard about, is phishing. In the past — and by “the past” I mean 18 months ago — phishing emails were easy to identify. Misspellings, grammar that was off, things like that. But now you can run a phishing email through an AI tool and have it build something that looks perfectly correct in English or German or whatever target you have. It’s really hard to discern them now. AI has changed a lot of the human element component in terms of what we can quickly and easily distinguish from a fraud email versus a regular one.

Better training, which you mentioned, is of course super important — continuous training with AI. But we also have to assume people are going to make mistakes, and that’s okay. That’s not a bad thing. When we think about that, we think about layered defense — not just having a tool to capture phishing emails, but do you have other defenses in place so that if you do click on something or download something, it can still get stopped? We’ve been talking about layered defense for 15 years. That’s not new. But it is more amplified in today’s context because of how AI can more easily manipulate the human element.

And the culture of security has to still change. A lot of people think of security as a checkbox — do my training, be done. But organizations need to really build security into the culture. A good example: if I do something wrong, am I afraid to report it? A lot of people may say they don’t want to report it, they’ll try to handle it themselves because they don’t want to get yelled at or potentially fired. But it’s not about that. It’s not about blame. We want everyone to feel comfortable reporting if they did something wrong or if something looks off. That’s part of a broader security culture. AI has changed a lot of what we’re doing and amplified certain things like layered defense, training, and things of that nature.

Frank: Great stuff. And I think the layered approach has always made sense and continues to. I think it’s worth pointing out that some of these defenses are tech where AI is being used for good — my Microsoft Patch Tuesday has never looked so inflated as it has in recent years. So while attackers are using AI to really scale and personalize threats, defenders are embedding it into detection and response tools. From where you sit advising, which side is winning right now — is this a constant back and forth, or are you seeing security companies begin to build in the functionality themselves?

Ankur: Winning is a hard one. But I will say the bad actors are always trying to be innovative and find new ways to get by the defenses we’ve built. And we’ve heard this line in movies and all over the place — the attackers only have to get it right once, and we have to get it right all the time. That’s hard because they’re always trying to be more innovative. AI has really democratized attacks. It’s so much easier to create phishing campaigns, to create deepfakes — we’ve heard about examples where deepfakes have been used to trick people into making payments. I wouldn’t say they’re winning, but they are more cutting edge.

We have to be as defenders a little more strategic in what we’re doing, because we don’t want to open up additional holes or issues we’re not ready for. But AI has a huge upside on the defensive side too. The most obvious example is in detection and response. Machine learning has been around in these types of tools for a long time, but as we implement more advanced AI solutions into detection and response, we can analyze millions of events in seconds — which in the past would take days. That helps us identify behavior that looks anomalous or suspicious. AI is already helping us on the defensive side as well.

But the bad actors are definitely finding new and innovative ways that are making it harder for defenders — defenders are kind of on their heels. That’s just the nature of what we do. We need to think about what else we can be doing to get ahead of that curve. No cyber professional will say any organization is 100% safe. AI has only further proven that point. We always want to think about how we integrate new tools and technologies to help defend ourselves. That’s happening already, but there are going to be more and more use cases as we get deeper into this AI revolution.

Frank: I agree. And I think there’s been a shift in the field — it used to be about how do you prevent breaches, but now it’s more about assuming a breach may happen and ensuring you have resilience. You can recover your backups, etc. Do you think that shift has permeated organizations? And in that sense, what does resilience mean in that context?

Ankur: That’s a really important point. I think the shift has happened in concept. People are thinking, hey, it’s not just about prevention, we have to think about how we get back up and running if something happens. But I don’t think it’s necessarily happened operationally for every company. Everyone thinks, oh, I have to assume that something could happen or may happen, but not everyone has actually operationalized what happens next. How do I become resilient — meaning getting back up and running to a normal state, but even more importantly, getting at least critical operations back up and running.

I think every CISO and anyone overseeing this area will agree that we have to plan for that. But not everyone has spent money on it. The majority of money has still been spent on preventative controls. And of course that’s important — we don’t want to get hit. We’re not going to just open the doors and only plan for resilience. But what I think people haven’t really thought about is the ratio of what we’re spending on preventative versus detection, response, and resilience. Because none of us are 100% safe.

Some of that includes changing our mindset. 20, 25 years ago, everything we thought about was perimeter defense — how do we protect the gates, make sure nothing can get in. That’s not the world we live in nowadays. The assumed breach mindset is exactly that — what if someone’s already in our network? How do we prevent lateral movement? Things like zero trust are really important. Not trusting anyone, having verification happen continuously. Investment in better detection and response capabilities, including AI, that will actually help with dwell time — which right now is quite high. And actually testing your resilience plans. People love to put stuff on paper, but then won’t actually test and validate that if something happens, this will work and we’ll get back up and running in an hour or two or whatever your downtime target is.

And lastly, segmentation. Network segmentation has been around a long time, but it goes beyond just network segmentation — how do we limit the components of our environment to reduce the blast radius? If someone gets in here, they don’t have access to everything. Just this one piece gets hit. These are not easy or cheap things by any means. But it does highlight the importance of moving to a different mindset — not just trying to keep people out, but knowing something could happen and managing that more proactively internally, with all the partners and contractors and consultants that people work with nowadays. It’s not just your employees on the inside. Most organizations are still focused very heavily on the preventative side.

Frank: And I think there’s that intersection where your domain meets business continuity, and then you really get into org-wide efforts. I’ve always wondered where business continuity will grow — will that come more into this practice? Because a lot of times it’s an important next step that does get overlooked or not given as much emphasis.

Ankur: There’s a really important overlap when people think about cyber and incident response versus true business continuity and disaster recovery, because they are inherently linked. I’ve seen this in tabletops and exercises with clients — oh yeah, ERP is over here and cyber does their own stuff and then we’ll do something else. But that’s not the case. They are very quickly merging in a good way so that everyone is aware it’s not just about a cyber incident — it’s about anything. And how does that all transverse through the broader environment.

Frank: Related — we have operations in multiple countries, and you’ve worked across North America and also Europe, the Middle East, and APAC. In my experience, cyber threats don’t respect borders or politics. But defenses try to. So curious about your experience with different regulatory regimes and maturity levels. What does the global picture of cyber look like?

Ankur: Exactly to your point — as much as we are increasingly interconnected, there are a lot of differences by country and region. North America faces really the most sophisticated ecosystem. We see attacks from ransomware groups that operate under different countries, true nation-state attacks, hacktivists — they’re bigger in the US and other places. Financially motivated criminals. North America specifically takes the brunt of it when it comes to volume and scale of these types of attacks.

The US doesn’t have a very aggregated regulatory landscape. Outside of certain things like SEC requirements and certain industries, a lot of things are state by state, and that makes it fragmented. Europe, on the other hand, is very aligned in how they put out regulation, and they’re probably the most complex regulatory landscape I can think of right now. They’ve had GDPR for a long time. Recently, they have the NIS2 Act, the DORA Act, now the EU AI Act. The US tends to model a lot of what it does based off of that, and Europe tends to be ahead of the curve when it comes to actual regulatory work. But as I alluded to earlier, that can create compliance fatigue — everyone’s just worried about being compliant, which is important, but then they don’t actually become proactive. There’s a balance that has to be struck.

Working in APAC, I would say that probably has the widest maturity gap of any region. At a regional level, there are definitely countries that are ahead of the curve — South Korea and Japan. But especially in emerging economies, they have much bigger gaps. And to be fair, some of those aren’t the ones that get hit with as much cyber activity, so they may not have the same regulation and proactive measures built in — unless they’re multinational.

A global organization can have to navigate 100-plus different regulations. That’s not easy. It diverts resources to compliance rather than true security. It’s different across all the different regions. But if you’re a multinational company, there is an ecosystem of regulation you have to work through, and unfortunately that sometimes diverts attention away from the more proactive stuff that may not be captured in some of those laws. The US and North America are definitely facing the brunt of it, but I always say we’ll be the tip of the spear and help everyone else figure out what to do when we think about new technologies, processes, and tools. That’s been the case for most of what we’ve done so far.

Frank: So far. But let’s talk about the future and the talent coming up. You’ve been involved in academic advisory roles at both Penn State and Ithaca College, and from what I understand there’s a significant talent shortage inside cybersecurity globally. Is the way we’re currently educating the next generation of cyber professionals matching what’s needed right now? What are you seeing?

Ankur: I would say it is definitely changing and changing for the positive. I’m biased because I graduated from Penn State, but they have a really great program they built out about 26 years ago that was actually designed with input from consulting firms and other large firms to help get people into the workforce. And I work with a lot of other colleges in terms of recruiting and their programs. Many of them have specific cyber programs — whether undergrad or graduate — focused on getting more people into the workforce. Reports always say there are around 4 million-plus jobs available globally in cyber. A lot of colleges have built out programs specifically for cybersecurity and now data science and AI as well, which is great.

What I would say when I advise colleges or anyone with these programs is that it’s important to have a balance of technical knowledge but also broader organizational and risk understanding. If all these individuals come out of college and all they can do is ethical hacking, for example — that’s great and important. But we need more than that. We need individuals to understand broader cyber risk, not just the hands-on technical piece.

A lot of colleges are adapting programs that aren’t just theory — actual practical learning. Case studies, capstone programs with companies. And constantly evolving the curriculum to adapt to new threats, looking at true case studies, really getting into how this is applied to the real world. I would not say we’re there yet, but I have seen a big change in a positive way since I graduated 25 years ago. Some of the candidates we see coming out of certain colleges are great — they come in and are able to work and understand what we’re doing pretty quickly and don’t need as much of an investment in uplifting them. I’ve definitely seen that shift. We’re going in the right direction, but we’re not quite there yet.

Frank: And here in Buffalo, we have TechBuffalo nearby, and I think STEM is very healthy. There are a lot of lucrative careers. What I see sometimes is the importance of specialization — I do try to encourage students to learn programming, learn networking, because those skills really help you understand the big picture technically.

So speaking of AI to close — I asked an AI to generate a closing question based on your background. Its name may be Claude.

You spent two decades helping organizations navigate cyber risk, and now you’re advising them on AI risk as a distinct discipline. If you had to make one prediction about how the relationship between AI and cybersecurity will look five years from now, what will it be?

Ankur: That’s a really interesting question. What I would say is that the relationship between thinking about AI versus cybersecurity will have dissolved. AI is going to be embedded into everything we do and will just be part of the normal conversation. It’s going to be a foundational tool built into all the other tools that we use — not going to be a separate thing. It’s going to be part of everything we do, both on the reactive side in terms of incident response and defensive work, but also on the offensive side, as threat actors are already using it. It’ll just kind of merge together. We’re already starting to see that as AI is being built into different platforms — not just in cyber but beyond. And we’re already starting to see AI roles emerge in organizations: AI security architects, chief AI officers, things like that.

I just think it’s going to be built into the broader technology ecosystem. AI risk is going to be integrated into how we think about any solution or product that has AI built into it. It’s going to be part of the normal conversation, not a separate thing we bolt on.

Frank: This has been a great conversation. Where can people find you and learn more about your work?

Ankur: I appreciate it, Frank and the team — this has been great. I work at FTI Consulting. We’re a public company, so LinkedIn is really the best place to start to learn about me, my team, or the broader practice and what we’re doing. We’re constantly posting about cyber trends and cyber threats, so if you follow us you’ll get updates on all of that. We put out threat alerts all the time to help people stay up to date on recent things happening.

You can also go to FTIconsulting.com/services/cybersecurity and find us there. Find my name and reach out if you have any questions. I’m always happy to have a conversation. Education is the number one thing we all need to be thinking about and doing. So I’m happy to just talk about what you can be doing or what you should be thinking about in the future for yourself or your organization. Thank you for the time — I appreciate it.

Frank: Great. Thank you.

No posts

Read the original on techxy.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.