N1HRV — broadcast 20260806 180000 UTC 333 transcript segments Google Cloud Speech-to-Text API (Chirp) + Gemini 2.5 Flash Non-Thinking Data courtesy of The GDELT Project (https://www.gdeltproject.org/), from the Internet Archive TV News Archive. Machine transcription. Treat it as a searchable index of what was broadcast, not a verbatim quotation record. [00:00:21] Good afternoon and welcome to another AI Central Point show, today we will talk [00:00:25] about artificial intelligence and cybersecurity. My guests today [00:00:28] are Mr. Engelman from our renowned company Span [00:00:32] and Petar Perković, cybersecurity consultant. Good [00:00:35] evening. Thank you again for coming. I would like to start with [00:00:39] a fairly general question. Namely, we know that cybersecurity [00:00:42] is an extremely important and growing topic in the last [00:00:45] 10, or even more, maybe 15, 20 years. What specifically interests [00:00:49] me from your experience, how much have things [00:00:52] changed further, complicated or accelerated with [00:00:55] the development of artificial intelligence as another additional [00:00:58] technology whose consequences we can actually see in [00:01:01] various segments, including cybersecurity, [00:01:04] Krvoje? Well, [00:01:08] announced, it is a once in it's certainly worse than it was, right? Well, [00:01:11] there's no other way, so, uh, the method of attack hasn't changed, right, [00:01:15] but artificial intelligence has given super powers to attackers, I would say, [00:01:18] mm-hm, it has actually given them the ability to scale, it has given them [00:01:21] an expert assistant, so what does that [00:01:25] actually mean for us? It means that we can no longer be safe [00:01:28] just because we are small. insignificant, but now they can scale, they can attack [00:01:32] more, mm-hm, interesting, we'll come back to that part, Petre, [00:01:35] I would absolutely agree with that and add that the time of attack today [00:01:39] is much shorter than it used to be, simply because [00:01:43] artificial intelligence accelerates the entire process of analysis, [00:01:47] attack and compromise. Once a vulnerability is discovered, I [00:01:51] have been following this topic, it seems to me that now the price of a good [00:01:55] attack has dropped, especially in relation to quality, meaning on one hand we have higher [00:01:59] quality of... potential attacks according to various criteria, a much lower [00:02:02] price, so then, if it's the right word, the possibility of attack [00:02:06] has been democratized. What would you say to that from [00:02:09] the perspective of us ordinary people, meaning someone who [00:02:13] can individually feel some consequences due to that rapid [00:02:17] development that artificial intelligence has actually brought within [00:02:20] cybersecurity. Well, there's a greater chance that someone will now [00:02:24] target us because it's simpler, right? [00:02:27] Uh, sometimes the language barrier was important here. We were [00:02:30] small, who would bother us, not everyone spoke Croatian, and Google Translate was [00:02:34] problematic, mm-hm, today that is no longer the case, meaning [00:02:38] ChatGPT understands grammar better than me, so we can no longer [00:02:41] rely on that and it allows the team [00:02:44] to again scale the attack, cover more people and it allows one more [00:02:48] thing, for someone to specifically target us, there is usually [00:02:52] a research phase that was quite a [00:02:55] manual job of digging, today you can ask an AI [00:02:58] agent to create a profile of a person, to specifically [00:03:02] target them, mm-hm, mm-hm, great, interesting, [00:03:05] Petra, [00:03:08] await us in Jersey, one of Queen. Photographs of well, certainly a large number of us have witnessed in previous years, uh, [00:03:12] emails that arrived, allegedly from the tax office, allegedly from Croatian [00:03:15] Post, allegedly from the Ministry of Interior, which in fact [00:03:18] did not come from them, so phishing attacks are now becoming more [00:03:22] sophisticated, and we can expect them [00:03:25] what we are defending so we can in the future more and more with fewer and fewer obvious errors. When we talk [00:03:29] about... for example, emails that arrive, we recently had a case [00:03:32] in our media where various schools and kindergartens received [00:03:36] similar emails, which means that now I [00:03:39] assume that in theory they could be generated by someone who is [00:03:43] actually not an expert, who could create that whole chain [00:03:46] of various steps to actually perform a solid [00:03:50] and efficient attack without being an excessive [00:03:52] expert, uh, in the very act of [00:03:55] cybernetically attacking institutions. Is that [00:03:58] correct? Well, yes, I would emphasize another [00:04:01] component, AI can [00:04:05] educate us on how to stay hidden, what we need to [00:04:08] do so that the police can't track us. It's not [00:04:12] complicated, I mean, there were books before, you could study it, but today it's [00:04:16] just a query, mm-hm, great, that's also an important part, so we also have [00:04:19] positive aspects where artificial intelligence can help us [00:04:23] at an individual level, yes, absolutely, [00:04:25] meaning, uh, a very specific question can [00:04:29] get a very... specific and accurate answer, usually [00:04:32] AI is quite precise and accurate. I recently [00:04:36] answered a question where a journalist asked me if we can expect [00:04:40] uh, in five or ten years, for someone to, say, [00:04:44] perfectly clone our voice or that of our relatives, and how to deal [00:04:47] with that, uh, I naturally said that this is not something that will happen [00:04:51] in 10 years, but something that was already happening last year, and this is absolutely [00:04:55] possible, and now we are already at a level where we've had such cases, meaning even video [00:04:58] can be so convincing, uh, that you, uh, that you cannot [00:05:02] distinguish it. What is perhaps the general, do people know how much [00:05:06] effort and time or recordings of someone's voice it takes to clone someone's [00:05:09] voice or, for example, to create a very convincing video of someone? Well, I would say [00:05:13] extremely little time, depending, of course, on [00:05:15] who we are talking about. If it's a public figure, all available [00:05:19] information is available on the internet, so there are various video [00:05:22] recordings and such that can be used to train artificial [00:05:26] intelligence to copy that voice and it is possible to create [00:05:30] a situation where your boss calls you and asks you to [00:05:33] pay certain bills urgently, right now, so [00:05:36] this, I would say, is not possible today, but was already possible [00:05:40] some time ago, that's a question of motivation, so, for all [00:05:44] such activities, certain resources are needed, so these [00:05:47] resources must be financed in some way, yes, I, [00:05:51] I even came across some data, I don't know if they are accurate, that three to four [00:05:55] seconds of voice are enough, meaning someone calls you on the phone for [00:05:57] some fake call and already has enough of your voice to be able [00:06:01] to clone it and then call, for example, your relatives with your voice, [00:06:05] are these accurate information? Well, I [00:06:08] think so, I've seen some demos for that, but now it goes a step further, [00:06:11] for example with... our podcast will be able to quite accurately, right, [00:06:15] clone us, but now it's not just [00:06:18] about the tone of voice and pitch, but also [00:06:22] gestures, the way of speaking, the words used, meaning all of [00:06:26] that can now be replicated, that sounds very [00:06:28] convincing, and I would just add to that [00:06:31] that perhaps it's not a good way of thinking about how we will [00:06:35] recognize it, but we need to put in place technology and processes alongside that [00:06:38] human factor to protect ourselves from these attacks. For example, if someone [00:06:42] cloned the voice of my boss, Nikola, right, and [00:06:46] he calls me and says, "Quick, transfer money to that account," I [00:06:50] can't do that, I have to contact our finance department, [00:06:53] someone there can't just do it, they have to contact [00:06:57] our vendor management who then has to change the [00:07:00] account in the system to which payment is made, then I can make [00:07:03] the payment, that's the process part, meaning security by design [00:07:07] security by design has a technological part where we can set up in ERP [00:07:11] that only a specific person can change the order to which payment is made, and another [00:07:15] person can pay it out, the point is we can no longer rely [00:07:18] on recognizing fraud, we need to have a process and technology around [00:07:22] that. I would just briefly go back to the information about three to four [00:07:25] seconds, I would say it depends on the language, so for Croatian [00:07:28] it would probably be a bit more complicated, while for English it would very likely be [00:07:32] possible, it makes sense. I'm interested now to comment a bit on the next [00:07:36] level, meaning, of course, all cybersecurity firms in [00:07:39] the last few years have included artificial intelligence in their processes and services, [00:07:43] what is happening at the organizational level, how have [00:07:46] organizations reacted to this, do we perhaps have [00:07:50] some kind of effect that we have false security in some organizations that think [00:07:53] we are now using some e-tools that are now helping us more or [00:07:57] perhaps not as much as they think, what are your experiences with [00:08:00] that? Well, every conversation with anyone who makes decisions about [00:08:04] IT and security always involves the question of AI, often [00:08:08] opening the question of whether we need 5 kg of AI to protect us, right? [00:08:11] Mm. It doesn't work that way. [00:08:14] So, uh, defense against AI is not just more AI on [00:08:18] the defensive side. Defense against AI attacks means addressing [00:08:22] the basics. It means addressing [00:08:25] eating your vegetables and exercising. We need to [00:08:28] collect quality data so that [00:08:31] AI has something to analyze, but that first step [00:08:34] is usually omitted. We need to know [00:08:37] put AI on it. Our experience is [00:08:40] mostly that attackers don't attack the part where you had your best [00:08:44] AI agent to protect you, but find an alternative route, mm-hm, [00:08:47] mm-hm, Petre, what are your experiences, you can compare, so [00:08:51] you worked in the Emirates, so you have some international [00:08:55] experience, do you see any differences between the perception of risk [00:08:59] that artificial intelligence brings, would different companies [00:09:02] answer differently to the question if you have money to invest in AI security [00:09:06] or for example in educating people, what would they actually choose? [00:09:10] Well, what I notice, especially in the Emirates and... the Arab [00:09:13] Peninsula region, is that they view AI as a potential major threat [00:09:17] given the current geopolitical situation, but also as a solution to [00:09:20] certain problems that exist, uh, [00:09:23] whether related to the state apparatus, or related [00:09:27] to business, or related to general security, [00:09:30] uh, the approach is twofold, I would say. Companies [00:09:34] that offer various cybersecurity services view AI [00:09:38] as a solution to certain problems that have existed for a long time in [00:09:41] operations, so... here we are talking about the speed of reaction in case of an [00:09:44] incident, analysis of huge amounts of data collected [00:09:48] from users and so on and so forth. End users again [00:09:51] see AI as a solution for accelerating some business [00:09:54] processes, so it's about analyzing all [00:09:58] data, contacting end users, i.e. customers, [00:10:02] and so on. Have we had any examples in Croatia? I [00:10:05] remember one of the most famous ones was from last year, I think it was about Singapore [00:10:09] where a manager of a company was on a video [00:10:12] call with actually AI avatars who actually tricked him, so he [00:10:16] paid some money. Do we have any similar [00:10:19] examples that happened in the Croatian region or [00:10:23] for example in the Emirates? Mm? For the Emirates, I officially have no [00:10:26] information. Uh, what I do know is that, I think, at the beginning of this year [00:10:30] there was an attack on the Mexican government where they managed to [00:10:33] compromise a huge amount of data and according to all available information, that attack [00:10:37] was initiated via AI, mm-hm, mm-hm, yes, we will [00:10:41] come back to that part, I think that's a story [00:10:44] where even a Claude was used to get into [00:10:48] some ministry. Hrva, do you have any interesting, uh, [00:10:51] examples/warnings to share? Well... [00:10:55] I think that the attacks we've seen recently, all have some [00:10:59] AI component in them, rarely does anyone go for [00:11:02] cloning voice and video, because it's simply not needed, there are usually [00:11:06] simpler ways. [00:11:09] My warning and advice here is to completely remove the [00:11:13] component that requires us to trust [00:11:16] an email or trust a call, meaning that a [00:11:20] system can be built so that we are largely resistant to phishing [00:11:23] attacks. So... I think that has destroyed entire business models. [00:11:27] Someone said that in America it was possible for a bank to do [00:11:30] authentication only by voice, now that part has been completely [00:11:34] removed, in that direction I'm going - so we no longer need to count on that, we don't [00:11:37] need to try to improve that process, but move on to something else, mm-hm. [00:11:41] Mm-hm, okay, uh, the last topic that interests me, which I would [00:11:44] at least partly open, is uh, actually at the state level, how much [00:11:47] information do you have, what interesting things have you found? I'm always [00:11:51] interested from Croatia's perspective, how a country like Croatia, but of course all similar [00:11:55] small countries with limited human resources and knowledge, can [00:11:59] defend themselves against some state actors, meaning some, whether it's [00:12:02] Iran, Russia, or the United States, whoever, can [00:12:06] we defend ourselves against them, how, in what way, and has that silent war [00:12:09] perhaps even started silently between countries in this [00:12:13] completely new field? Well, it's not silent, it's not [00:12:17] silent, it's not silent. I mean, the US [00:12:20] publicly announced two years ago, I think, [00:12:23] that China is repositioning itself for war, meaning [00:12:27] they are entering our critical infrastructure, they haven't pulled [00:12:30] the trigger yet, but they are there, that's how it looks. You can't just say, "I'm going to [00:12:34] hack HEP and turn off the power." No, you're there and you're waiting for that [00:12:38] moment when the trigger is pulled, when you turn off the power. Uh, [00:12:41] the Russians, there's no secret there either, they've been called out many times, [00:12:45] Ukraine, of course, that's been going on for seven or eight years now, [00:12:48] how they are there in an open [00:12:51] cyber war, right, ever since they tried and succeeded in turning off [00:12:54] the power. They had attacks, uh, against the US, which is [00:12:58] of course to be expected. How much does that spill over to us? It spills [00:13:01] over, but in scaling, approximately [00:13:05] in my opinion, as the stakes are high there, we [00:13:07] can be seen as being a NATO member, an EU member, [00:13:11] and here in the Balkans, so we are interesting to some extent [00:13:14] and it is happening. Can we defend ourselves against it? Yes, mm-hm, [00:13:18] are we defending ourselves? We are trying, yes. Now the question [00:13:21] is how much one is willing to invest. I mean, I was very glad to hear from some other colleagues [00:13:25] who said that our intelligence agencies have developed some specific [00:13:29] software that serves for some elements of that, which is a great [00:13:32] thing, but on the other hand, some said, it no longer protects us that we are [00:13:36] small, because the cost of attack has become very low, and what [00:13:39] used to be okay, like Croatia is irrelevant to us, today that may no longer be [00:13:42] the case. What are the comparisons with, uh, the countries [00:13:46] of the Gulf? Well, I think we are still not in the situation that the Gulf countries [00:13:50] are currently in, given that about a month [00:13:53] ago all financial institutions had problems with their services, [00:13:57] because in combination with a cyber attack, there was a drone attack on [00:14:00] the data center where they kept their services, so it took [00:14:04] several weeks for that to stabilize. Luckily, as I said, we are not yet at that [00:14:07] level, but I would say that precisely that, first, AI has accelerated [00:14:11] the entire process of analysis and the time needed to initiate [00:14:15] an attack. Second, as already mentioned, since Croatia [00:14:19] is part of NATO and the European Union, even though we are relatively small, we have access to services [00:14:23] and resources that potentially can be interesting to [00:14:27] large attackers. Here's a small question for speculation, [00:14:30] mm, is it a question of time and what do you think, where will [00:14:34] some equivalent of, let's say, a digital Pearl Harbor happen, meaning some [00:14:37] big attack between two countries that will really [00:14:41] resonate significantly, is something like that possible and where, in what timeframe, [00:14:45] between whom could something like that happen? Well, we already had a [00:14:48] precedent for that, well, I guess, a precedent is, let's say, [00:14:51] like that. [00:14:53] Uh, Shadow Brokers, Note 5, and when uh, WannaCry, when [00:14:57] Russia and North Korea attacked the West, in [00:15:00] quotation marks, meaning we had this worm that [00:15:03] spread and destroyed systems. That's close [00:15:07] to what might happen, mm-hm. [00:15:11] Will there be a total collapse? [00:15:13] No. If we put AI into that calculation, again all those [00:15:17] systems should be, and will be even more, [00:15:21] resilient to a level where you can... manually [00:15:24] switch something. Again, a precedent in Ukraine, they were under [00:15:28] great pressure from Russian attacks on their critical infrastructure, especially [00:15:31] electricity distribution. Then they simply got used to it, these guys with [00:15:35] computers. "These guys come and manually turn the power back on," [00:15:38] mm-hm, so [00:15:42] Pearl Harbor, no, it's not realistic at that level, I don't think so, even [00:15:45] with AI assistance, because AI still has to follow [00:15:49] protocols and rules, like all other people, and still communicates via the internet, [00:15:53] through PayPal, if it wants to break in somewhere, it has to scan some device again, it can be [00:15:56] detected to some extent, it can be prevented with hygiene, [00:15:59] mm-hm, Petre, do you agree or do you think there's [00:16:03] room for greater damage? I always remember those examples when, for example, some operating [00:16:07] system has a patch, that is, one that hasn't been made, [00:16:11] then hundreds of millions of computers can be compromised. Now, can [00:16:15] AI find even more such holes and possibly exploit them [00:16:18] even more efficiently? Well, according to all the information we have so far, [00:16:21] it seems that AI is much faster and much more efficient in finding vulnerabilities in [00:16:25] all systems and applications, but I would [00:16:28] agree with Hrvoje that the chances of something that could be called Pearl Harbor [00:16:31] are relatively small, primarily because all [00:16:35] states, all alliances are becoming aware of the importance of rapid [00:16:38] reaction and are conducting certain tests, i.e., simulations, relatively [00:16:42] often. I believe that helps, or I know firsthand that it helps when [00:16:46] all participants in an incident know their [00:16:49] duties and responsibilities and what they must do when it [00:16:52] happens. Also, of course, we have situations [00:16:55] where key elements, meaning [00:16:59] water, electricity, and so on, are physically separated from the rest of the internet, [00:17:02] and I think that steps have also been taken [00:17:06] there that would reduce the possibility of such [00:17:09] a destructive event. I hope you two are right, then I would [00:17:13] perhaps conclude with a very practical question, [00:17:17] uh, what would you advise, what should each of us do [00:17:21] to be safer tomorrow, to protect ourselves from both cyber [00:17:24] and AI-powered cyber attacks? Well, I think that's [00:17:28] relatively simple. So, for the end user, [00:17:32] for, mm-hm, me, for my mom, the most important [00:17:35] thing is that online services, meaning our Google Clouds, meaning [00:17:39] our accounts, are protected with appropriate [00:17:42] authentication. That means multi-factor authentication, not [00:17:46] just a password. Passwords are dead, right? We no longer need to [00:17:49] deal with that, but I would then say passwordless, which is today [00:17:53] relatively simple and available to everyone, passwordless, [00:17:56] passwordless, meaning not having that password, mm-hm, this home computer [00:18:00] you have, mostly that's mostly [00:18:03] a graveyard where everyone has already been hacked, but what we have on our phones is cloud service. [00:18:07] It has, these are often our pictures that are important to us, mm-hm, [00:18:11] we protect that. [00:18:13] Anything can happen, they can leak, as we have seen in various [00:18:17] cases, at a personal level, but perhaps also at an organizational level, what would [00:18:20] you advise to do? Well, I think that kind of two-factor [00:18:24] authentication, whether as part of some use of passphrases, if [00:18:27] tokens are not practical for any reason, is definitely a good [00:18:30] idea, mm, obviously employee training, i.e., training for all [00:18:34] involved in important processes, is necessary precisely because of the situations [00:18:38] we mentioned, voice faking, images, [00:18:42] calls and so on, because such cases, such incidents will only [00:18:46] increase. Here's perhaps one last question that just occurred to me for whoever wants to [00:18:49] answer, do you believe that in the near future we can [00:18:53] reach the level of some AI attacks that are practically made [00:18:57] without humans, meaning where humans no longer participate but it's something completely AI- [00:19:00] organized and executed? Is something like that realistic? I think [00:19:04] it depends on what you mean by the word "participate," [00:19:07] because even today we already have situations where [00:19:11] AI does most of the work, then the person just [00:19:14] verifies and says: okay, or the person just set the goal, that's right, mm-hm, that's right, thank you very much [00:19:18] for your time, I would like to thank everyone once again, this was [00:19:22] the AI Central Point show and we'll see you soon [00:19:25] in the next episodes, greetings everyone, [00:19:27] goodbye. [00:30:44] On this topic, in the meantime, Damir Bakić from the Možemo party joined me in the [00:30:47] studio, he is a member of parliament and a representative [00:30:51] in the city assembly, otherwise a person who deals with the [00:30:55] issue of pensions, the pension system, Mr. Bakić, welcome to.