
What Leaders Get Wrong About Cybersecurity | Ioannis Antypas
About this episode
Support KAJ Masterclass — help sustain independent editorial work: https://kajmasterclass.com/support
=========================================
About KAJ Masterclass Media
KAJ Masterclass Media is home to a video-first, live-first, editorially independent conversation ecosystem exploring leadership, business, AI, careers, health, creativity, and the evolving human experience through thoughtful, unscripted conversations grounded in lived experience, clarity, and real-world insight.
This show is part of the KAJ Masterclass ecosystem, which includes The KAJ Masterclass LIVE, The Author's Voice with KAJ, and a growing collection of editorially independent conversation platforms.
Every conversation is designed to leave you with something meaningful to think about, understand, or apply.
🌐 https://www.kajmasterclass.com
=========================================
Host — Khudania Ajay
(KAJ) Khudania Ajay (KAJ) is an independent journalist and the host of more than 2,500 long-form conversations across leadership, business, technology, media, wellness, authorship, and the future of work.
🌐 https://www.khudaniaajay.com
LinkedIn https://www.linkedin.com/in/ajaykhudania/
=========================================
Watch. Listen. Read.
🎬 https://www.youtube.com/@kajmasterclass
🎧 https://www.kajmasterclass.com/listen
📖 https://www.kajmasterclass.com/read
=========================================
Work With KAJ
KAJ Masterclass Media welcomes thoughtful conversation proposals from leaders, entrepreneurs, authors, experts, researchers, creators, and practitioners aligned with the ecosystem’s editorial values and audience-first philosophy.
Submit your proposal:
https://www.kajmasterclass.com/work-with-kaj
=========================================
If this conversation added value, share it with someone who would genuinely benefit from it.
=========================================
From Our World
🎁 Ethnics Land — Premium Indian handloom sarees
Use code KAJ10 for 10% OFF
https://www.ethnicsland.com
=========================================
🎵 Music Credit: "Misfits (Instrumental)" by RYYZN
Become a supporter of this podcast: https://www.spreaker.com/podcast/kaj-business-money-live--6217536/support.
KAJ Masterclass Media
Independent editorial conversations helping you think better, decide better and understand the world.
https://www.kajmasterclass.com
Get every episode summarized
Each time KAJ Business & Money LIVE publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
321 searchable segments. Every word is indexed and playable.
Full transcript
KAJ Business & Money LIVE — What Leaders Get Wrong About Cybersecurity | Ioannis Antypas. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Welcome to the KJ Masterclass. Today on Business and Money, we are joined by Yannis Antipas. He is a Cybersecurity ITN compliance leader. He and we discussed with him what leaders get wrong about cyber security and much more. Welcome to the show Yannis. Thank you for having me. It's great to be here. I'm looking forward to the conversation. Welcome to the show Yannis. Welcome to India in this online form. And I'm sure not just in India, but a lot of people across the globe will benefit from what we are going to talk right now. We'll talk about what leaders get wrong about cyber security, what best they can do and much more. But before that, let's understand a bit about your journey, your background so that the audience knows who they are listening to. Great. First of all, thank you. I really appreciate that. And yes, this is a global conversation now because every leader is trying to balance growth, technology and trust.
My journey has really been about bridging worlds. I was born in Greece. I built my career in the UK and I have spent the last few years in Saudi Arabia working across cybersecurity, IT and compliance. What that gave me was perspective. Different markets move at different speeds, but the leadership challenge is often the same. How do you grow, adopt technology and while still keeping trust? That's the thread through everything I do now. I help leaders make confident decisions on cybersecurity, compliance and practical AI in plain language. And honestly, living and working across cultures taught me that good leadership starts with listening first, then bringing clarity. If you can do that, you reduce risk and make better decisions. So let's have it. Absolutely. Carry on, carry on. So yeah, that's with much from my side. What would you like to know? Thank you. Thank you for that, Yannis.
Now, to understand it from the cyber security perspective, as well as, you know, a lot of people talking about AI. Now, how should people understand cyber security when AI has taken so much of brain space, discussion space, every space in business discussions? How should you do you want people to understand cyber security in these times of artificial intelligence talks? Absolutely. I think the link between cybersecurity and AI is actually very simple. Most companies don't actually have an AI problem. They have an AI governance problem. They are moving very fast, experimenting very fast, but they haven't decided what data can be used, who is accountable, and where the boundaries are. And that's where risk starts. I have seen patterns where a well-meaning employee pays his sensitive information into a chatbot just to save time.
No bad intent there, but of course, you have got a security problem. You have got a privacy and a trust issue in one move. So for me, cyber security today is no longer just about firewalls and tools. It's about leadership, judgment, clear rules, and how technology gets used. If leaders get that part right, they protect trust, reduce risks, and of course, get value from AI instead of just chasing it. And just to put it very simply, AI hasn't replaced cyber security. It's made cyber security more important. Most companies don't actually have the AI problem. So they are excited about the tools, but they haven't decided what data are being used. And of course, in this case, I want to highlight the safety, the usefulness, and the sustainability of merging AI and cyber security all in one. And if you get that right, you protect what we just said, the trust, the reduce, the risk, and turn the AI into a real business value instead of the expensive noise.
Absolutely, Yannis, absolutely. Let me understand it this way for my audience. Before AI, cyber security was still a big issue. Around 2021, before just AI, before the launch of chat, Gipeteen 2022. At that point also, a lot of issues were still there. And while everybody was still talking to tackle them, now we have moved so many years now towards with AI as well as in cyber security. Do you think cyber security issues have been solved to a great extent? Or do you think we have bigger challenges in terms of cyber security, especially for businesses? Yes, and that's exactly the point. Of course, the simplest way to explain it is this.
AI is the power, but cyber security and governance are the boundaries. Without those boundaries, people move fast and make small mistakes with big consequences. A simple example, of course, can be anybody pasting information that could be sensitive into any of these chatboards. Because, of course, at the end of the day, you don't own what you get, what you paste into that chatbot or into that AI tool. So the goal here is to use these tools to your benefit, but at the same time to keep those boundaries in place. So with that clear rules, clear accountability and common sense, that becomes a very big issue. And to answer your point, cyber security was already a major business issue before AI became the headline. AI changed the speed and the visibility, but it didn't create the core problem. The core problem was already there. Leaders were still treating security like a technical issue instead of a business decision.
So they were confusing compliance with security. And of course, they were asking, did we pass the audit instead of asking, are we actually ready if something goes wrong tomorrow morning? And with that being said, that's why I often say an audit is just a photograph, but the security is a film. You can look fine at one moment and still be exposed in real life. So yes, before AI, the risk was already serious. AI just made the need for strong governance, clear judgment and fast response impossible to ignore. And with the old times, AI didn't replace the old cybersecurity problems that we had. It just exposed them faster. So with that being said, that's why people are coming back to one simple idea. And that is compliance is a baseline, not a security. So with that being said, I don't think AI changed the need for strong cybersecurity.
I just think it removed the excuse to ignore it. And I would say the challenges right now are bigger, not small, because we lack the tools, but at the same time, because business has become more connected, faster and more exposed. So with that being said, cybersecurity hasn't been solved. It has been evolved. The mistakes leaders will make is thinking that cybersecurity is only an IT issue. It isn't. It's a business issue. It affects revenue, your reputation, your operation, and your trust with your clients, with employees, etc. So I have seen it all. I've seen the patterns where an organization can look compliant, but be vulnerable. That's why I often say, always chase your compliance, because that is your baseline. It is not the security. And they need for clear ownership, better awareness, faster response, and leaders who treat security as part of the business growth.
It's very, very important, because today, weak security doesn't just create risk. It can also slow the growth, lose the deals, and damage careers. Absolutely, absolutely. But I want to understand then, what do you want business leaders to understand about more about? They were aware about the business risk before also. Today also, I see even if leaders must be more aware about it, the responses that they are giving is still the old time ones. You see all those data breaches that happen often. If the same template, Jan is the use. You know, we are sorry, your data has been breached. Your name or your password or your details may have been a part of this. Go and change your password. Almost the same script, Jan is. So I want to understand, what is it that you want these business leaders to understand about cyber security?
Okay, so first thing first is cyber security is not something only for the IT team. It is for the boardroom. It is not for the server room. So, I would say start with something very simple and very small. And that is the ownership and the visibility. If you don't know what data you have, what it lives and who can access it, you are managing risk blindly. That's where most leaders should begin, not with more tools, but with more clarity. So with that being said, awareness is not the same as ownership. Many leaders know cyber risk exists, but they still treat it as an IT topic, a compliance checklist or even a conversation for after something goes wrong. That's the old response. The better response right now is to treat security as a business discipline. Who owns the critical data? Who can access it?
What happens if a supplier is hit? How fast can we respond? That's where maturity starts. Data breaches keep repeating because the patent keeps repeating. Point in time audits. Week accountability. Low awareness. No real follow-through. So for me, the issue is not that the leaders haven't heard the warning. It's that many organizations still haven't turned that warning into a daily operating discipline. And that's the gap that costs money, trust and something. And sometimes, of course, the deal, et cetera. So what I personally want is business leaders to understand that service kit is not the ecology issue after you get breached. It is the discipline you build before one gets made. That's the shift. Too many organizations right now still responds the old way. Send the email, ask people to change the passwords, move on and learn very little.
The real question here is, why were we exposed in the first place? I have seen that patent many, many, many, many different times before. So leaders, in this day of age, they need to stop treating security as a technical side issue and start treating it as a spark of how the business operates and grows. And if you do that, you reduce the risk, you protect the trust. And frankly, you avoid losing money and deals that might come next time the pressure hits. Absolutely, Janice. Let's understand this. Why is it that leaders have been thinking like this? Is it because they knew that they are well protected in whatever their reasoning is? That is indeed an IT problem for them. And that SEO will move out after three years, four years. And it doesn't really bother him or her. Why is it? Or is it because they are not IT people? Why bother about technical stuff?
And just believe on the chief technology officer and all those IT teams and all. And then it will be all right. Is it because of that or is it, it's very taxing for their minds? Or is it that they simply do not care? Then how can you change that mindset, Janice? Of course. And partly what you said is actually correct. Many leaders are not technical. They assume cyber security belongs to the IT. Hence why they throw it to the chief technology officer or to the chief information officer or to the IT team. But the deeper issue is not a technical knowledge. It's ownership. If nothing bad has happened yet, people assume they are protected. So security becomes someone else's problem. That's the dangerous part. You do not need to be an engineer to lead on cyber. You need to actually understand business risks. The decisions about budget, priorities, supply risk, data handling and accountability.
These all are not server room decisions. They are boardroom decisions. So I do not expect every CEO to know how the technology works behind the company. But I do expect them to know what a weak security can cost in terms of money, reputation, trust and loss deals. That's why I always say security fills in the boardroom and not the server room. And to top it off, sometimes what's really happening is that this weakness has not been tested yet. So the shift for leaders is simple. Don't ask only, are we covered? Ask are we truly ready? And then you have your answer. Absolutely. So as an expert in all these, if you come into the picture, how will you get started? What will you get started with? Will you change your leaders mindset? Or will you start from somewhere else?
That is very, very good question. And I would start by saying, the biggest shift is to stop, first of all, to stop treating sabiscuit as a technical issue and start treating it as a leadership issue. You do not need to understand every tool, but you need to understand where your critical data lives, who can access it and what your supplier risk looks like. And how fast your team can respond when something goes wrong. That is where real maturity starts. The organizations that do this well do not just avoid breaches. They build trust faster. They win better deals and they make better decisions and strong decisions under pressure. In other words, good security is not just protection. It's part of the business. And what you're asking about starting with any leader or any organization, I would say this, I would start with the reality, not the theory. Before I try to change anyone's mindset, I want clarity. And I want to find out what data do we have, where does it live,
who can access it, what are the biggest dependencies, who are we dependent on, how fast can you respond, and if something goes wrong. That right there will give me the truth of every situation very quickly. I have used the same thinking in my own work with a simple self-assessment approach first, because you need to know whether the pain is real before you start prescribing solutions. Once leaders can see the actual gaps, the mindset usually starts changing on its own. So no, I wouldn't begin with a big speech. I would actually begin with visibility, ownership, and accountability. Because when leaders see the risk in the business terms, they make better decisions faster. And those decisions will protect them when it trusts and momentum of the company. Absolutely, Janice. Thank you for that. Now let me understand from how things are evolving, especially with AI and all. Recently, all these tools, especially those which would look at zero-day vulnerabilities.
Anyone who has, and there was this we'll talk about my thoughts, five and all that. And when you have zero-day vulnerabilities, that can be exposed by all these AI tools and many more that are getting developed. How do organizations with money who have got that capacity still protect themselves or from the negative people from outside who may land up with such capacity? And especially smaller businesses who do not have that great amount of bandwidth to spend so much of money. What's your take on this? AI is accelerating both attack and defense, but it doesn't change the fundamentals. If AI helps people find zero-day vulnerabilities faster, then that means the business cannot rely on tools alone or assume they are safe because they both the latest product.
The real question here is still the old one. Do you know what you have? Which systems matter the most to you? How quickly you can patch or how fast you can respond if something critical is exposed? I've personally seen patterns where organizations focus on the shiny layer, but the basics underneath are still weak. That's where the real danger is. So I wouldn't tell leaders to perhaps panic about AI. I would actually tell them to get serious about visibility, accountability, and AI changes that speed of the game. And of course, it puts us in the picture way before anybody else comes in and takes us down. So the one thing that we need to focus on is discipline. And if your discipline is weak, the cost can show up very quickly in money, downtime, and trust. So I would just tell them, get discipline. And once that happens and you have visibility, ownership, and accountability,
you are in a much stronger position than you were when you started. And if you don't, even a big budget can actually become very big issue to you because you would see that in reality, it doesn't really matter if your systems are weak. Absolutely. Absolutely, Janis. So in a nutshell, because you are doing a lot of work in the girl-free zone in terms of cyber security compliance and AI under Vision 2030. So a lot of things are learning from that also. Help us understand what's happening down there. Also in terms of tips for some of the, you know, some tips for leaders who, you know, who can get started with their best of cyber security for their businesses. That is a very, very good question. And I thank you for asking it. What stands out to me most in Saudi Arabia and the wider Gulf is the speed.
You have digital transformation, regulation, and AI adoption all moving at the same time. Under Vision 2030, this isn't about just buying technology. It's about building a digital and secure foundation properly. And that's a rare opportunity. In many markets, you would see security gets bolted on later. In the Gulf, and especially in Saudi Arabia, there is a real chance to build it in real time earlier if leaders are disciplined. You can see that in how seriously compliance and data protection are now being treated in the region. And the lesson for me is very simple. Fast growth is powerful. But if growth out runs your controls and governance, you can create hidden weaknesses which you want to avoid. If you build trust, accountability, and security into the growth story from the start,
you protect your money. You protect your company. You reduce the risk and you create a much stronger business. And for leaders anywhere in the world, this should be the starting point, actually. First, know where your critical and regulated data are and who can access them. Second, be very clear on ownership because awareness is not the same as our accountability. And third, stop treating sobiscuity as a tool by exercise and start treating it as an opening discipline and perhaps an operating discipline. I often say compliance is the baseline and know the security as I have mentioned in this meeting in this session multiple times. So yes, meet the standard but do not stop there. Ask whether your people know the rules, whether your suppliers create any risk and how fast your team can respond when something changes. And if leaders can get those basics right from the first go, they reduce that risk.
And perhaps what you can also do as part of your ongoing commitment to the growth of the company introduce training and employee development programs in order to ensure your team and the people who are showing up every day to work on these systems or the decisions that you are taking, they are trained on the protocols on the latest developments on the companies and of course on sobiscuity itself. Wonderful, wonderful. There is so much to learn about all this from you. Yannis and I am sure a lot of people, a lot of leaders all across the globe will benefit from what we are, you know, what we have discussed and a lot of them would want to connect with you, perhaps be your client. What's the best way for them to do so? Thank you very much. I really appreciate it and honestly if you just take one thing from this conversation, let it be this. Don't wait for the breach to take sobiscuity seriously. Start with
the visibility, the ownership and the accountability and then you build from there. And the best place to find me is Yannisantipas.com. That is I-O-A-N-N-I-S-A-N-T-Y-P-A-S and .com of course and if people want a practical starting point, I would also recommend them and invite them to download my free self-assessment at go.yannisantipas.com slash ECC-readiness and of course if they would like to connect to me on a professional level, they can find me on LinkedIn as well. Wonderful. With this, it's a wrap on this very special edition of the KJ Masterclass Live. Thank you so much indeed for joining us.
More episodes
More from KAJ Business & Money LIVE

Are You Exit-Ready? The Legal Gaps You Might Be Missing | Barbara Neilan
KAJ Business & Money LIVE

How to Finally Let Go of a Career That Doesn't Serve You | Chad Betz
KAJ Business & Money LIVE

How to Fix Toxic Culture and Keep Your Best People | Ron Cooper
KAJ Business & Money LIVE

How I Turned a Parenting Problem Into a Top-Selling Product | Paul Moore
KAJ Business & Money LIVE