This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

CyberCap Interview: Samuel Bonneau (Vooban)

Download resources

About this session

A CyberCap interview with Samuel Bonneau, CISO at Vooban and founder of Fortica Cybersecurite, on a 25-plus-year path through security engineering, KPMG partnership and repeated entrepreneurship. He credits a family tradition of entrepreneurship for his willingness to fail and restart businesses, and treats perseverance and curiosity as core skills for anyone entering cybersecurity, alongside foundational networks and systems knowledge that lets a practitioner debug problems new AI-driven tools cannot explain. At Vooban, a company adopting AI aggressively, he describes securing brand-new protocols like MCP that shipped without basic authentication, and attackers increasingly using AI for voice and image spoofing and highly targeted phishing. He recommends joining communities such as CyberEco, industry conferences, and small peer groups like QG100 to trade honest vendor feedback rather than relying on marketing claims, illustrating the point with a story about catching an outdated SOC2 audit report that predated a cloud provider's newer encryption feature. On generative AI governance, he describes setting clear policies on what data can go into which tools and monitoring or blocking usage where needed, arguing the underlying risk is not new, just faster. He closes urging young attendees not to be intimidated about approaching established professionals at events like GoSec.

Key takeaways

  • Do not take a vendor's security claim at face value; ask for the underlying audit report (e.g. SOC2) and check its date against the feature actually being used.
  • Learn networking and systems fundamentals before chasing new technology; foundational knowledge is what lets you debug when a new AI tool or protocol breaks.
  • Write a clear, specific AI usage policy: which tools are approved, what data classes may go into a prompt, and monitor or block usage rather than leaving it ungoverned.
  • Join a mix of large communities (industry associations, conferences) and small peer groups (CISO circles) to get honest, practical feedback on tools, not just vendor pitches.
  • Treat perseverance as a core career skill: expect some ventures or approaches to fail, learn from each one, and keep restarting rather than stopping at the first setback.

Speakers

Samuel Bonneau
Samuel Bonneau
CISO · Vooban
Samuel Bonneau est un expert en cybersécurité avec plus de 25 ans d’expérience, reconnu pour son approche innovante, son leadership et sa capacité à générer de la croissance stratégique. Il a joué un rôle clé dans la conception et la mise en œuvre… Read moreRead less

Samuel Bonneau est un expert en cybersécurité avec plus de 25 ans d’expérience, reconnu pour son approche innovante, son leadership et sa capacité à générer de la croissance stratégique. Il a joué un rôle clé dans la conception et la mise en œuvre de stratégies de cybersécurité auprès des plus grandes entreprises canadiennes. Aujourd’hui Leader – Stratégie et services en cybersécurité IA chez Vooban, il allie cybersécurité et intelligence artificielle pour renforcer les stratégies de défense des entreprises, leur permettant de tirer parti des dernières avancées technologiques pour une protection robuste et durable.

Resources

Tags

More from GoSec 2025

Also from Samuel Bonneau

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.