I used to think AI Security was just another buzzword VCs were throwing around. A solution looking for a problem.
Then a single attack, so subtle and brilliantly executed, almost tanked my company. It cost us $330,000 in direct losses, not to mention the reputational damage that’s harder to quantify. I was wrong. Dead wrong.
After the dust settled, I got obsessed. I spent three months interviewing 50 hackers—the kind of people who find vulnerabilities for a living, and sometimes for less noble reasons. I wanted to know how they think, what they see, and how they are using AI. Their answers were terrifying. But they also gave me the blueprint for a new way to think about security in the age of AI.
One hacker, a 19-year-old from Eastern Europe who goes by “Spectre,” told me something that chilled me to the bone: “You’re all looking for AI in the attack. We’re using AI to build the weapons. The attack itself looks completely normal. By the time your ‘AI threat detection’ flags it, we’re already gone.”
That’s the fundamental misunderstanding. We’re buying AI-powered shields while the attackers are building AI-powered swords.
The $330,000 Mistake
At RemoteTeam, before the acquisition by Gusto, we were growing at a breakneck pace. We had a small, brilliant engineering team. We used all the “best-in-class” security tools. We had firewalls, intrusion detection, and yes, a fancy new AI-powered threat detection platform that cost us a cool $50k a year.
It felt like we were protected. We were checking all the boxes.
The attack wasn’t a brute-force assault. It was a whisper. It started with a phishing email to a junior marketing employee. But this wasn’t your typical “Nigerian prince” scam. The email was a perfect replica of a message from our CRM provider, flagging a “billing anomaly.” It used the employee’s name, her title, and referenced a recent campaign she had just launched. The AI that generated it knew our business.
She clicked. Of course, she clicked.
From there, the attackers didn’t move for two weeks. They just watched. They used an AI to learn our internal communication patterns, our billing cycles, our approval workflows. They saw how I communicated with our finance lead. They learned the cadence, the language, the timing.
Then they struck. They initiated a wire transfer request. Not for a million dollars, but for $82,500. It was just under our automatic-flag threshold. The email looked like it came from me. The invoice it was attached to was a flawless, AI-generated fake of a real vendor we used. The system, and the human, approved it.
They did this four times over a month. Total loss: $330,000.
Our expensive AI security tool saw nothing. Why? Because each individual action was, by itself, not anomalous. The requests were within our normal payment range. The emails followed our patterns. The invoices looked real. The AI was looking for a single, loud event, a gunshot. The attackers used AI to create a series of silent, invisible steps.
The Adversarial Framework: How I Think About Security Now
That costly lesson forced me to throw out the old playbook. Box-checking security is a recipe for disaster. You can’t just buy a tool and expect to be safe. You need a framework built on an adversarial mindset. You have to think like the people trying to get in.
Here’s the exact framework I developed. It’s what I advise the 200+ companies I’ve invested in, from Scale AI to the smaller startups just finding their feet.
1. Assume Breach: Your Perimeter Is Already Gone
Stop thinking you can build an impenetrable wall. You can’t. Someone is already inside, or will be soon. The real work starts with what you do after they get in.
- What this means in practice: Heavy internal monitoring. We now log everything. Every API call, every database query, every file access. We don’t just look for weird logins; we look for weird behavior inside the network. A developer suddenly accessing financial records? An HR account trying to spin up a new server? That’s the flag.
- The hard truth: This is more expensive and requires more engineering discipline than just setting up a firewall. But it’s the only thing that works.
2. Model Your “Crown Jewels”
What is the one thing an attacker would want most? Is it your customer data? Your source code? Your financial reserves? Be brutally specific.
At my new company, we have a document that explicitly lists our three “crown jewels.” For each one, we have a separate document detailing the exact path an attacker would need to take to access it. We map out every system, every API, every human in that chain.
- Actionable Step: Run a tabletop exercise. Get your team in a room and say, “Okay, we’re Spectre. We have a foothold on this employee’s laptop. Our goal is the customer database. How do we get there?” The gaps in your defenses will become painfully obvious, fast.
3. Instrument the Attack Path, Not the Whole System
Your fancy AI security tool is trying to watch everything at once. It’s like trying to guard a palace by watching every single brick. It’s impossible. You end up with a sea of false positives and miss the real threats.
Instead, once you’ve mapped the path to your crown jewels, you instrument that path obsessively.
- Example: If the path to our source code involves a specific set of microservices, we put incredibly detailed, custom-built tripwires on those services. Any unusual call, any change in data patterns, any access outside of normal business hours triggers an immediate, high-priority alert that goes directly to our senior engineering team. Not to a generic security dashboard. To a human who can act.
This is the concept of “zero-day AI” protection. You’re not waiting for a known attack signature. You’re defining what “normal” looks like for your most critical workflows and flagging any deviation, no matter how small.
4. People, Process, Then Tools
Everyone wants to buy a tool. It’s easy. It feels productive. But the hackers I spoke to are unanimous: they exploit people and broken processes, not software vulnerabilities.
The $330k attack on my company worked because our payment approval process had a loophole. The tool didn’t matter.
- My rule of thumb: For every dollar you spend on a security tool, you should spend two dollars on training your people and hardening your internal processes. This means regular, realistic phishing simulations. It means multi-factor authentication on everything, no exceptions. It means a culture where people are rewarded for reporting something that feels “a little off.”
Stop Buying Buzzwords
I see so many founders making the same mistake I did. They hear about “AI cybersecurity” and they go out and buy the most expensive platform, thinking it’s a silver bullet. It’s not.
Most of these tools are just traditional security software with a new coat of AI paint. They are still looking for the old patterns. The new generation of attackers, armed with their own AI, are creating attacks that have no pattern.
Don’t get me wrong, AI has a role to play in defense. But it’s not as a magical black box. It’s as a tool to help your best people enforce the framework. Use AI to sift through the logs from your critical attack paths. Use it to model “normal” behavior so you can spot the deviations. But don’t for a second think it can replace a smart, paranoid human who understands your specific business.
The future of security isn’t about better AI. It’s about a better framework. It’s about thinking like your enemy. Assume they’re in. Know what they want. And watch their every move as they try to get it. That’s the lesson that cost me $330,000. I hope, for you, it’s free.
Frequently Asked Questions
How has this view evolved over time?
My thinking on most topics has changed significantly over the years. Early in my career, I held many conventional views that experience proved wrong. I try to update my beliefs when the evidence changes.
How can I apply this thinking to my own situation?
Start by identifying the core principle behind the opinion, not the specific example. Then ask yourself: does this principle apply to my context? If yes, test it in a small, low-risk way before going all in.
What's the most common pushback you get on this?
People often push back by citing exceptions or edge cases. And they're usually right that exceptions exist. But building a strategy around exceptions rather than patterns is a losing game for most founders.
What experience informs this perspective?
This perspective comes from over a decade of building companies in Silicon Valley, two successful exits (RemoteTeam to Gusto, MovieLaLa to Gfycat), and investing in 200+ startups including Anthropic, OpenAI, and Scale AI. I write about what I've lived.