My Controversial Take on AI Cybersecurity

Published 2025-07-05 · Updated 2026-05-23 · 8 min read · AI Security and Cybersecurity · By Sahin Boydas

Everyone is talking about AI Cybersecurity, but 99% of founders are doing it wrong. I learned the hard way so you don't have to.

“We’re screwed.” That was the subject line of an email I got from a founder I invested in. His company, a fast-growing fintech startup, had just been hit by a phishing attack. But this wasn’t your grandpa’s phishing email with bad grammar and a Nigerian prince. This was a hyper-personalized, AI-generated attack that spoofed my own writing style, referencing a private conversation we’d had just days before. It was terrifyingly convincing. And it cost them over $250,000.

This isn’t a scare tactic. This is the new reality. Everyone is talking about AI cybersecurity, but I’m telling you right now, 99% of the founders I see are completely missing the point. They’re throwing money at shiny new “AI-powered” tools, thinking a bigger tech stack is the answer. It’s not. I learned this the hard way, and it was a painful, expensive lesson. I’m sharing this so you don’t have to make the same mistakes.

The Illusion of Security

I’ve been lucky enough to have a couple of successful exits. RemoteTeam was acquired by Gusto, and MovieLaLa was acquired by Gfycat. I’ve also been an angel investor in over 200 companies, including some of the biggest names in AI like Anthropic, OpenAI, Scale AI, and Hugging Face. I’ve seen what works and what gets you killed.

Here’s the hard truth: most AI security tools are selling you a false sense of security. They’re reactive. They’re designed to catch threats that have already been identified. But the new generation of AI-powered attacks are evolving in real-time. They’re polymorphic, constantly changing their signatures to evade detection. Your fancy new tool might catch yesterday’s attack, but it’s already obsolete against tomorrow’s.

I remember back in the early days of MovieLaLa, we were so focused on growth that security was an afterthought. We had the basic firewalls and antivirus software, and we thought we were covered. Then we got hit with a DDoS attack. It was a simple, brute-force attack, but it was enough to take our site down for hours. We lost users, we lost revenue, and we lost credibility. It was a wake-up call. We realized that security wasn’t something you could just bolt on at the end. It had to be baked into the DNA of the company.

The Attacker Isn't at the Gate, They're Already Inside

We have this mental model of cybersecurity that’s straight out of a medieval castle. We’re inside, the bad guys are outside, and we just need to build a bigger wall. That’s completely wrong. The biggest threat isn’t some shadowy hacker in a hoodie. It’s your own team. It’s the well-meaning employee who clicks on a link, the overworked developer who pushes a vulnerable piece of code, the executive who uses the same password for everything.

And AI is the ultimate force multiplier for this internal threat. Think about it. That phishing attack I mentioned? It worked because the AI scraped my public data, my social media, my blog posts. It learned my voice. It knew I was an investor in that company. It crafted a message that was not just plausible, but personal. Your employees are getting hit with these attacks every single day. And it only takes one mistake.

We saw this at RemoteTeam. We were building a platform to help companies manage remote employees. We were obsessed with creating a seamless user experience. But in our rush to ship features, we let some of our security practices slip. We had a staging server that was accidentally exposed to the public internet. It had some anonymized user data on it, but it was still a major vulnerability. A security researcher found it and reported it to us. We were lucky. It could have been a disaster. We dodged a bullet, but it was another lesson learned: the biggest holes are often the ones you dig yourself.

Stop Buying More Locks, Start Teaching People How to Use the Keys

So what’s the answer? It’s not another piece of software. It’s not a bigger budget for your IT department. It’s a fundamental shift in how you think about security. It’s about building a culture of security, not just a fortress of technology.

Think about it. You can have the most advanced locks in the world, but if someone on the inside leaves the door wide open, what’s the point? That’s what’s happening in most companies. They’re so focused on the external threat that they’re ignoring the human element. And the human element is where 95% of security breaches originate.

Building a security culture isn’t about a one-time training session where everyone half-listens while checking their email. It’s about continuous, engaging, and practical education. It’s about making security everyone’s job. Here’s what that looks like in practice:

  • Constant, Realistic Drills: Don't just run a phishing simulation once a quarter. Do it weekly. Use AI to generate hyper-realistic attack scenarios based on current events and your own company's context. Make it a game. The employee who spots the most sophisticated phish gets a bonus or public recognition.
  • Make It Personal: Show, don't just tell. I once worked with a founder who ran a simulation that spoofed his own email, asking an employee in finance to process an urgent wire transfer. The employee almost fell for it. It was a powerful, visceral lesson that no PowerPoint presentation could ever match.
  • Reward Vigilance, Don't Punish Mistakes: If an employee clicks a malicious link and reports it immediately, they should be praised, not shamed. You want to create an environment where people feel safe to raise their hand and say, “I think I messed up.” That’s how you find out about a breach in minutes, not months.

The Unsexy Truth About AI Security

Everyone wants to talk about the cool, futuristic stuff. The AI that hunts other AIs. The quantum encryption. But the truth is, 99% of your security posture comes down to the boring, unsexy basics. And most companies are failing at them.

I’m talking about things like:

  • Multi-Factor Authentication (MFA): I can’t believe I still have to say this in 2025, but if you don’t have MFA enabled on every single service, you’re just asking for trouble. And I don’t mean SMS-based MFA, which is easily compromised. I mean a proper authenticator app or a hardware key.
  • Password Hygiene: I’ve seen founders of multi-million dollar companies use passwords like “Password123”. It’s insane. Use a password manager. Generate long, random passwords for every service. It’s not that hard.
  • Least Privilege Access: Your marketing intern doesn’t need access to your production database. Your CEO doesn’t need to be a global admin on your AWS account. Give people the minimum level of access they need to do their job. Nothing more.
  • Regular Patching: I know, I know. It’s a pain. But that zero-day vulnerability that was just announced? The attackers are already scanning for it. You need to have a process for patching your systems quickly and reliably.

This stuff isn’t glamorous. It’s not going to get you a write-up in TechCrunch. But it’s what actually works. It’s the blocking and tackling of cybersecurity. And if you can’t do the basics right, all the fancy AI tools in the world aren’t going to save you.

I remember a portfolio company that was building a cutting-edge AI for medical diagnostics. Brilliant team, amazing technology. But they had a developer who was using a personal laptop for work, and that laptop got infected with malware. The malware spread to their development environment and they had a major data breach. They had all the latest AI-powered threat detection systems, but they failed at the most basic level of device security. It was a brutal lesson in the importance of the unsexy fundamentals.

My Controversial Take

So here’s my controversial take: stop wasting your money on the latest AI cybersecurity silver bullet. You’re not going to win an arms race against an enemy that’s already inside your walls and has a superintelligence as its weapon. The game is rigged.

Instead, take that budget and invest it in your people. Invest it in training. Invest it in building a culture where every single person in your company is a human firewall. That’s your only real defense. It’s not about technology. It’s about psychology.

I’m not saying technology has no role to play. But it should be the last thing you focus on, not the first. Get the basics right. Build a human-centric security culture. And then, and only then, should you start looking at how AI can augment your defenses, not replace them.

If you’re a founder and you’re not spending at least half of your security budget on the human element, you’re going to get breached. It’s not a matter of if, but when. And when it happens, all the fancy dashboards and AI-powered alerts in the world won’t mean a thing. Don’t be the founder sending me that “We’re screwed” email. Be the one who builds a company that’s resilient from the inside out.

Frequently Asked Questions

What's the most common pushback you get on this?

People often push back by citing exceptions or edge cases. And they're usually right that exceptions exist. But building a strategy around exceptions rather than patterns is a losing game for most founders.

How can I apply this thinking to my own situation?

Start by identifying the core principle behind the opinion, not the specific example. Then ask yourself: does this principle apply to my context? If yes, test it in a small, low-risk way before going all in.

How has this view evolved over time?

My thinking on most topics has changed significantly over the years. Early in my career, I held many conventional views that experience proved wrong. I try to update my beliefs when the evidence changes.

More in AI Security and Cybersecurity

All AI Security and Cybersecurity articles · Sahin's angel investments · Startups he founded