Best Buddy or Biggest Bully? The AI Cyber Story
Download resourcesAbout this session
In this opening keynote, Brian Linder, head of Check Point's cyber evangelists, argues that AI is at once the defender's best ally and the attacker's biggest force multiplier. He opens with the ransomware-as-a-service economy and how generative AI lets criminals build convincing malware and phishing without coding skills, set against roughly four million unfilled cybersecurity jobs. After warning the audience about 'AI washing', he presents three Check Point responses: ThreatCloud AI, which renders verdicts in about two seconds using some 90 engines, around 50 of them AI-based, and credits those AI engines for catching zero-day-plus-one attacks in Miercom's 2024 benchmark; the Infinity AI Copilot, demonstrated granting access, checking CVE exposure and summarising blocked attacks through orchestrated prompts, with a private architecture that never sends customer data to public LLMs; and a GenAI protection layer that classifies prompts by risk and blocks disclosures such as an unannounced acquisition before they reach ChatGPT. He closes by noting ChatGPT reached 100 million users in two months and that legacy regex-based DLP cannot police generative AI use.
In this keynote, we will dive into the future of cybersecurity where AI is both our greatest ally and fiercest adversary, exploring how AI is revolutionizing our cybersecurity platform to stay ahead of cybercriminals, but we will also look at how AI brings unprecedented power to our adversaries, making cyber-attacks more sophisticated and harder to detect. Join us as we unravel this double-edged sword, revealing the exciting potentials and daunting challenges AI brings to the cybersecurity battlefield.
Key takeaways
- When a vendor claims AI, ask how many detection engines are actually model-based and what share of zero-day catches they account for.
- Before adopting an AI copilot for security operations, verify its architecture keeps your logs and policies out of public LLMs and cannot train on them.
- Blocking generative AI no longer holds; instead classify prompts by risk and stop disclosures such as deal names or source code before they leave the browser.
- Regex-based DLP misses unstructured leaks; you need context-aware classification to police copy-paste between SaaS apps and AI tools.
- Use AI to compensate for the skills gap: automate CVE exposure checks, ticket creation and daily threat briefings rather than waiting for hires you cannot make.
Speakers

Brian Linder heads Check Point’s Office of the CTO, and has appeared multiple times on NBC, CNBC, Fox, ABC, NBC, CBS, and NPR radio, is a regular on Check Point’s CISOTalk, and hosts Check Point’s Weaponizers Underground, and is regular CyberTalks… Read moreRead less
Brian Linder heads Check Point’s Office of the CTO, and has appeared multiple times on NBC, CNBC, Fox, ABC, NBC, CBS, and NPR radio, is a regular on Check Point’s CISOTalk, and hosts Check Point’s Weaponizers Underground, and is regular CyberTalks keynote presenter at Check Point's global CPX events. For 30 years, Brian has been an advisor in matters Cybersecurity at the C-level to firms big and small in financial, legal and telecommunications, on next generation cybersecurity solutions and strategies for cloud, mobile, and network. Brian holds a B.S. in computer science from Drexel University and an M.S. in Information Science from the Pennsylvania State University.
