Every CISO will face this. The only question is timing.
Most CISOs cannot yet tell a bot from a human, and that gap shows up long before it reaches a security alert. Arkose Labs COO Frank Teruel breaks down the signals CISOs should watch for, and why partnering with the right vendor matters more than buying another tool.
About the speaker
Start with the fact that today they understand they're unprepared. 75% of the people we just surveyed don't know how to do attribution. They don't know whether it's a bot, a human. They don't know what to do, so they're unprepared.
What are the signals? Am I having sellables that go through the roof with no associated increase in new customer base, or do I have suddenly a spike in transaction abandonment where something's going on?
You've got to find vendors that are in the fight with this thing. It's not a matter of if, it's a matter of when it's gonna hit you.
So I think, create fusion. We were talking to a bank recently, they've created internal fusion teams, and they define fusion as data-sharing organizations.
Two things I would say. Number one, start with the fact that today they understand they're unprepared. Seventy-five percent of the people we just surveyed don't know how to do attribution — they don't know whether it's a bot or a human, they don't know what to do, so they're unprepared. So first and foremost, look at those high-value flows that are likely to be affected. Who's registering for accounts, what are they doing in those accounts? Get that information, and then realize across all these use cases, how do we share data to understand what's happening. Work with somebody who can identify risk up front, and not just tell you, but help you mitigate that risk.
So what are the signals? Am I having sellables that go through the roof with no associated increase in new customer base, or no associated increase in ridership if you're in that kind of company? Or do I have suddenly a spike in transaction abandonment where you go, my cell bill's up, transactions are down, something's going on? Look at the idea of volumes of accounts created, and look at linking, or accounts being linked. Who's involved in those decisions? Who am I relying on in that linking operation to trust that the linkage is legitimate? You've got to look at the entire surface and ask, where are those areas that could be exploited in real time?
You've got to find vendors that are in the fight with this thing. It's not a matter of if, it's a matter of when it's going to hit you. As I said, ninety-some-odd percent of respondents believe in the next twelve months they'll be hit with an agentic attack, and of that ninety percent, only a small portion feel prepared. So you've got this great imbalance in terms of what's happening. I think you create fusion — we were talking to a bank recently, and they've created internal fusion teams, which they define as data-sharing organizations. Creating those things and starting to identify those signals in advance, and recognizing that agentic is here, it's learning, it's getting better. You've got to partner — if you're a CISO today and those important workflows aren't agentic-proof, you're already behind the eight ball.