Google Cloud Speech-to-Text API (Chirp) + Gemini 2.5 Flash Non-Thinking. Treat it as a searchable index of what was broadcast, not a quotation record.
00:00:21Good afternoon and welcome to another AI Central Point show, today we will talk
00:00:25about artificial intelligence and cybersecurity. My guests today
00:00:28are Mr. Engelman from our renowned company Span
00:00:32and Petar Perković, cybersecurity consultant. Good
00:00:35evening. Thank you again for coming. I would like to start with
00:00:39a fairly general question. Namely, we know that cybersecurity
00:00:42is an extremely important and growing topic in the last
00:00:4510, or even more, maybe 15, 20 years. What specifically interests
00:00:49me from your experience, how much have things
00:00:52changed further, complicated or accelerated with
00:00:55the development of artificial intelligence as another additional
00:00:58technology whose consequences we can actually see in
00:01:01various segments, including cybersecurity,
00:01:04Krvoje? Well,
00:01:08announced, it is a once in it's certainly worse than it was, right? Well,
00:01:11there's no other way, so, uh, the method of attack hasn't changed, right,
00:01:15but artificial intelligence has given super powers to attackers, I would say,
00:01:18mm-hm, it has actually given them the ability to scale, it has given them
00:01:21an expert assistant, so what does that
00:01:25actually mean for us? It means that we can no longer be safe
00:01:28just because we are small. insignificant, but now they can scale, they can attack
00:01:32more, mm-hm, interesting, we'll come back to that part, Petre,
00:01:35I would absolutely agree with that and add that the time of attack today
00:01:39is much shorter than it used to be, simply because
00:01:43artificial intelligence accelerates the entire process of analysis,
00:01:47attack and compromise. Once a vulnerability is discovered, I
00:01:51have been following this topic, it seems to me that now the price of a good
00:01:55attack has dropped, especially in relation to quality, meaning on one hand we have higher
00:01:59quality of... potential attacks according to various criteria, a much lower
00:02:02price, so then, if it's the right word, the possibility of attack
00:02:06has been democratized. What would you say to that from
00:02:09the perspective of us ordinary people, meaning someone who
00:02:13can individually feel some consequences due to that rapid
00:02:17development that artificial intelligence has actually brought within
00:02:20cybersecurity. Well, there's a greater chance that someone will now
00:02:24target us because it's simpler, right?
00:02:27Uh, sometimes the language barrier was important here. We were
00:02:30small, who would bother us, not everyone spoke Croatian, and Google Translate was
00:02:34problematic, mm-hm, today that is no longer the case, meaning
00:02:38ChatGPT understands grammar better than me, so we can no longer
00:02:41rely on that and it allows the team
00:02:44to again scale the attack, cover more people and it allows one more
00:02:48thing, for someone to specifically target us, there is usually
00:02:52a research phase that was quite a
00:02:55manual job of digging, today you can ask an AI
00:02:58agent to create a profile of a person, to specifically
00:03:02target them, mm-hm, mm-hm, great, interesting,
00:03:05Petra,
00:03:08await us in Jersey, one of Queen. Photographs of well, certainly a large number of us have witnessed in previous years, uh,
00:03:12emails that arrived, allegedly from the tax office, allegedly from Croatian
00:03:15Post, allegedly from the Ministry of Interior, which in fact
00:03:18did not come from them, so phishing attacks are now becoming more
00:03:22sophisticated, and we can expect them
00:03:25what we are defending so we can in the future more and more with fewer and fewer obvious errors. When we talk
00:03:29about... for example, emails that arrive, we recently had a case
00:03:32in our media where various schools and kindergartens received
00:03:36similar emails, which means that now I
00:03:39assume that in theory they could be generated by someone who is
00:03:43actually not an expert, who could create that whole chain
00:03:46of various steps to actually perform a solid
00:03:50and efficient attack without being an excessive
00:03:52expert, uh, in the very act of
00:03:55cybernetically attacking institutions. Is that
00:03:58correct? Well, yes, I would emphasize another
00:04:01component, AI can
00:04:05educate us on how to stay hidden, what we need to
00:04:08do so that the police can't track us. It's not
00:04:12complicated, I mean, there were books before, you could study it, but today it's
00:04:16just a query, mm-hm, great, that's also an important part, so we also have
00:04:19positive aspects where artificial intelligence can help us
00:04:23at an individual level, yes, absolutely,
00:04:25meaning, uh, a very specific question can
00:04:29get a very... specific and accurate answer, usually
00:04:32AI is quite precise and accurate. I recently
00:04:36answered a question where a journalist asked me if we can expect
00:04:40uh, in five or ten years, for someone to, say,
00:04:44perfectly clone our voice or that of our relatives, and how to deal
00:04:47with that, uh, I naturally said that this is not something that will happen
00:04:51in 10 years, but something that was already happening last year, and this is absolutely
00:04:55possible, and now we are already at a level where we've had such cases, meaning even video
00:04:58can be so convincing, uh, that you, uh, that you cannot
00:05:02distinguish it. What is perhaps the general, do people know how much
00:05:06effort and time or recordings of someone's voice it takes to clone someone's
00:05:09voice or, for example, to create a very convincing video of someone? Well, I would say
00:05:13extremely little time, depending, of course, on
00:05:15who we are talking about. If it's a public figure, all available
00:05:19information is available on the internet, so there are various video
00:05:22recordings and such that can be used to train artificial
00:05:26intelligence to copy that voice and it is possible to create
00:05:30a situation where your boss calls you and asks you to
00:05:33pay certain bills urgently, right now, so
00:05:36this, I would say, is not possible today, but was already possible
00:05:40some time ago, that's a question of motivation, so, for all
00:05:44such activities, certain resources are needed, so these
00:05:47resources must be financed in some way, yes, I,
00:05:51I even came across some data, I don't know if they are accurate, that three to four
00:05:55seconds of voice are enough, meaning someone calls you on the phone for
00:05:57some fake call and already has enough of your voice to be able
00:06:01to clone it and then call, for example, your relatives with your voice,
00:06:05are these accurate information? Well, I
00:06:08think so, I've seen some demos for that, but now it goes a step further,
00:06:11for example with... our podcast will be able to quite accurately, right,
00:06:15clone us, but now it's not just
00:06:18about the tone of voice and pitch, but also
00:06:22gestures, the way of speaking, the words used, meaning all of
00:06:26that can now be replicated, that sounds very
00:06:28convincing, and I would just add to that
00:06:31that perhaps it's not a good way of thinking about how we will
00:06:35recognize it, but we need to put in place technology and processes alongside that
00:06:38human factor to protect ourselves from these attacks. For example, if someone
00:06:42cloned the voice of my boss, Nikola, right, and
00:06:46he calls me and says, "Quick, transfer money to that account," I
00:06:50can't do that, I have to contact our finance department,
00:06:53someone there can't just do it, they have to contact
00:06:57our vendor management who then has to change the
00:07:00account in the system to which payment is made, then I can make
00:07:03the payment, that's the process part, meaning security by design
00:07:07security by design has a technological part where we can set up in ERP
00:07:11that only a specific person can change the order to which payment is made, and another
00:07:15person can pay it out, the point is we can no longer rely
00:07:18on recognizing fraud, we need to have a process and technology around
00:07:22that. I would just briefly go back to the information about three to four
00:07:25seconds, I would say it depends on the language, so for Croatian
00:07:28it would probably be a bit more complicated, while for English it would very likely be
00:07:32possible, it makes sense. I'm interested now to comment a bit on the next
00:07:36level, meaning, of course, all cybersecurity firms in
00:07:39the last few years have included artificial intelligence in their processes and services,
00:07:43what is happening at the organizational level, how have
00:07:46organizations reacted to this, do we perhaps have
00:07:50some kind of effect that we have false security in some organizations that think
00:07:53we are now using some e-tools that are now helping us more or
00:07:57perhaps not as much as they think, what are your experiences with
00:08:00that? Well, every conversation with anyone who makes decisions about
00:08:04IT and security always involves the question of AI, often
00:08:08opening the question of whether we need 5 kg of AI to protect us, right?
00:08:11Mm. It doesn't work that way.
00:08:14So, uh, defense against AI is not just more AI on
00:08:18the defensive side. Defense against AI attacks means addressing
00:08:22the basics. It means addressing
00:08:25eating your vegetables and exercising. We need to
00:08:28collect quality data so that
00:08:31AI has something to analyze, but that first step
00:08:34is usually omitted. We need to know
00:08:37put AI on it. Our experience is
00:08:40mostly that attackers don't attack the part where you had your best
00:08:44AI agent to protect you, but find an alternative route, mm-hm,
00:08:47mm-hm, Petre, what are your experiences, you can compare, so
00:08:51you worked in the Emirates, so you have some international
00:08:55experience, do you see any differences between the perception of risk
00:08:59that artificial intelligence brings, would different companies
00:09:02answer differently to the question if you have money to invest in AI security
00:09:06or for example in educating people, what would they actually choose?
00:09:10Well, what I notice, especially in the Emirates and... the Arab
00:09:13Peninsula region, is that they view AI as a potential major threat
00:09:17given the current geopolitical situation, but also as a solution to
00:09:20certain problems that exist, uh,
00:09:23whether related to the state apparatus, or related
00:09:27to business, or related to general security,
00:09:30uh, the approach is twofold, I would say. Companies
00:09:34that offer various cybersecurity services view AI
00:09:38as a solution to certain problems that have existed for a long time in
00:09:41operations, so... here we are talking about the speed of reaction in case of an
00:09:44incident, analysis of huge amounts of data collected
00:09:48from users and so on and so forth. End users again
00:09:51see AI as a solution for accelerating some business
00:09:54processes, so it's about analyzing all
00:09:58data, contacting end users, i.e. customers,
00:10:02and so on. Have we had any examples in Croatia? I
00:10:05remember one of the most famous ones was from last year, I think it was about Singapore
00:10:09where a manager of a company was on a video
00:10:12call with actually AI avatars who actually tricked him, so he
00:10:16paid some money. Do we have any similar
00:10:19examples that happened in the Croatian region or
00:10:23for example in the Emirates? Mm? For the Emirates, I officially have no
00:10:26information. Uh, what I do know is that, I think, at the beginning of this year
00:10:30there was an attack on the Mexican government where they managed to
00:10:33compromise a huge amount of data and according to all available information, that attack
00:10:37was initiated via AI, mm-hm, mm-hm, yes, we will
00:10:41come back to that part, I think that's a story
00:10:44where even a Claude was used to get into
00:10:48some ministry. Hrva, do you have any interesting, uh,
00:10:51examples/warnings to share? Well...
00:10:55I think that the attacks we've seen recently, all have some
00:10:59AI component in them, rarely does anyone go for
00:11:02cloning voice and video, because it's simply not needed, there are usually
00:11:06simpler ways.
00:11:09My warning and advice here is to completely remove the
00:11:13component that requires us to trust
00:11:16an email or trust a call, meaning that a
00:11:20system can be built so that we are largely resistant to phishing
00:11:23attacks. So... I think that has destroyed entire business models.
00:11:27Someone said that in America it was possible for a bank to do
00:11:30authentication only by voice, now that part has been completely
00:11:34removed, in that direction I'm going - so we no longer need to count on that, we don't
00:11:37need to try to improve that process, but move on to something else, mm-hm.
00:11:41Mm-hm, okay, uh, the last topic that interests me, which I would
00:11:44at least partly open, is uh, actually at the state level, how much
00:11:47information do you have, what interesting things have you found? I'm always
00:11:51interested from Croatia's perspective, how a country like Croatia, but of course all similar
00:11:55small countries with limited human resources and knowledge, can
00:11:59defend themselves against some state actors, meaning some, whether it's
00:12:02Iran, Russia, or the United States, whoever, can
00:12:06we defend ourselves against them, how, in what way, and has that silent war
00:12:09perhaps even started silently between countries in this
00:12:13completely new field? Well, it's not silent, it's not
00:12:17silent, it's not silent. I mean, the US
00:12:20publicly announced two years ago, I think,
00:12:23that China is repositioning itself for war, meaning
00:12:27they are entering our critical infrastructure, they haven't pulled
00:12:30the trigger yet, but they are there, that's how it looks. You can't just say, "I'm going to
00:12:34hack HEP and turn off the power." No, you're there and you're waiting for that
00:12:38moment when the trigger is pulled, when you turn off the power. Uh,
00:12:41the Russians, there's no secret there either, they've been called out many times,
00:12:45Ukraine, of course, that's been going on for seven or eight years now,
00:12:48how they are there in an open
00:12:51cyber war, right, ever since they tried and succeeded in turning off
00:12:54the power. They had attacks, uh, against the US, which is
00:12:58of course to be expected. How much does that spill over to us? It spills
00:13:01over, but in scaling, approximately
00:13:05in my opinion, as the stakes are high there, we
00:13:07can be seen as being a NATO member, an EU member,
00:13:11and here in the Balkans, so we are interesting to some extent
00:13:14and it is happening. Can we defend ourselves against it? Yes, mm-hm,
00:13:18are we defending ourselves? We are trying, yes. Now the question
00:13:21is how much one is willing to invest. I mean, I was very glad to hear from some other colleagues
00:13:25who said that our intelligence agencies have developed some specific
00:13:29software that serves for some elements of that, which is a great
00:13:32thing, but on the other hand, some said, it no longer protects us that we are
00:13:36small, because the cost of attack has become very low, and what
00:13:39used to be okay, like Croatia is irrelevant to us, today that may no longer be
00:13:42the case. What are the comparisons with, uh, the countries
00:13:46of the Gulf? Well, I think we are still not in the situation that the Gulf countries
00:13:50are currently in, given that about a month
00:13:53ago all financial institutions had problems with their services,
00:13:57because in combination with a cyber attack, there was a drone attack on
00:14:00the data center where they kept their services, so it took
00:14:04several weeks for that to stabilize. Luckily, as I said, we are not yet at that
00:14:07level, but I would say that precisely that, first, AI has accelerated
00:14:11the entire process of analysis and the time needed to initiate
00:14:15an attack. Second, as already mentioned, since Croatia
00:14:19is part of NATO and the European Union, even though we are relatively small, we have access to services
00:14:23and resources that potentially can be interesting to
00:14:27large attackers. Here's a small question for speculation,
00:14:30mm, is it a question of time and what do you think, where will
00:14:34some equivalent of, let's say, a digital Pearl Harbor happen, meaning some
00:14:37big attack between two countries that will really
00:14:41resonate significantly, is something like that possible and where, in what timeframe,
00:14:45between whom could something like that happen? Well, we already had a
00:14:48precedent for that, well, I guess, a precedent is, let's say,
00:14:51like that.
00:14:53Uh, Shadow Brokers, Note 5, and when uh, WannaCry, when
00:14:57Russia and North Korea attacked the West, in
00:15:00quotation marks, meaning we had this worm that
00:15:03spread and destroyed systems. That's close
00:15:07to what might happen, mm-hm.
00:15:11Will there be a total collapse?
00:15:13No. If we put AI into that calculation, again all those
00:15:17systems should be, and will be even more,
00:15:21resilient to a level where you can... manually
00:15:24switch something. Again, a precedent in Ukraine, they were under
00:15:28great pressure from Russian attacks on their critical infrastructure, especially
00:15:31electricity distribution. Then they simply got used to it, these guys with
00:15:35computers. "These guys come and manually turn the power back on,"
00:15:38mm-hm, so
00:15:42Pearl Harbor, no, it's not realistic at that level, I don't think so, even
00:15:45with AI assistance, because AI still has to follow
00:15:49protocols and rules, like all other people, and still communicates via the internet,
00:15:53through PayPal, if it wants to break in somewhere, it has to scan some device again, it can be
00:15:56detected to some extent, it can be prevented with hygiene,
00:15:59mm-hm, Petre, do you agree or do you think there's
00:16:03room for greater damage? I always remember those examples when, for example, some operating
00:16:07system has a patch, that is, one that hasn't been made,
00:16:11then hundreds of millions of computers can be compromised. Now, can
00:16:15AI find even more such holes and possibly exploit them
00:16:18even more efficiently? Well, according to all the information we have so far,
00:16:21it seems that AI is much faster and much more efficient in finding vulnerabilities in
00:16:25all systems and applications, but I would
00:16:28agree with Hrvoje that the chances of something that could be called Pearl Harbor
00:16:31are relatively small, primarily because all
00:16:35states, all alliances are becoming aware of the importance of rapid
00:16:38reaction and are conducting certain tests, i.e., simulations, relatively
00:16:42often. I believe that helps, or I know firsthand that it helps when
00:16:46all participants in an incident know their
00:16:49duties and responsibilities and what they must do when it
00:16:52happens. Also, of course, we have situations
00:16:55where key elements, meaning
00:16:59water, electricity, and so on, are physically separated from the rest of the internet,
00:17:02and I think that steps have also been taken
00:17:06there that would reduce the possibility of such
00:17:09a destructive event. I hope you two are right, then I would
00:17:13perhaps conclude with a very practical question,
00:17:17uh, what would you advise, what should each of us do
00:17:21to be safer tomorrow, to protect ourselves from both cyber
00:17:24and AI-powered cyber attacks? Well, I think that's
00:17:28relatively simple. So, for the end user,
00:17:32for, mm-hm, me, for my mom, the most important
00:17:35thing is that online services, meaning our Google Clouds, meaning
00:17:39our accounts, are protected with appropriate
00:17:42authentication. That means multi-factor authentication, not
00:17:46just a password. Passwords are dead, right? We no longer need to
00:17:49deal with that, but I would then say passwordless, which is today
00:17:53relatively simple and available to everyone, passwordless,
00:17:56passwordless, meaning not having that password, mm-hm, this home computer
00:18:00you have, mostly that's mostly
00:18:03a graveyard where everyone has already been hacked, but what we have on our phones is cloud service.
00:18:07It has, these are often our pictures that are important to us, mm-hm,
00:18:11we protect that.
00:18:13Anything can happen, they can leak, as we have seen in various
00:18:17cases, at a personal level, but perhaps also at an organizational level, what would
00:18:20you advise to do? Well, I think that kind of two-factor
00:18:24authentication, whether as part of some use of passphrases, if
00:18:27tokens are not practical for any reason, is definitely a good
00:18:30idea, mm, obviously employee training, i.e., training for all
00:18:34involved in important processes, is necessary precisely because of the situations
00:18:38we mentioned, voice faking, images,
00:18:42calls and so on, because such cases, such incidents will only
00:18:46increase. Here's perhaps one last question that just occurred to me for whoever wants to
00:18:49answer, do you believe that in the near future we can
00:18:53reach the level of some AI attacks that are practically made
00:18:57without humans, meaning where humans no longer participate but it's something completely AI-
00:19:00organized and executed? Is something like that realistic? I think
00:19:04it depends on what you mean by the word "participate,"
00:19:07because even today we already have situations where
00:19:11AI does most of the work, then the person just
00:19:14verifies and says: okay, or the person just set the goal, that's right, mm-hm, that's right, thank you very much
00:19:18for your time, I would like to thank everyone once again, this was
00:19:22the AI Central Point show and we'll see you soon
00:19:25in the next episodes, greetings everyone,
00:19:27goodbye.
00:30:44On this topic, in the meantime, Damir Bakić from the Možemo party joined me in the
00:30:47studio, he is a member of parliament and a representative
00:30:51in the city assembly, otherwise a person who deals with the
00:30:55issue of pensions, the pension system, Mr. Bakić, welcome to.