AI Security Hype Creates New Opportunities for the Channel

Transcription

AI security is being sold at the extremes. Either it will solve every business problem that an organization has ever faced or it creates so many risks that it's leaving organizations more vulnerable than ever before and the world is going to end. Now, of course, as many people probably know at the end of the day, the truth is much more nuanced, much more practical, and much more centered in a form of reality that businesses need help returning to and that's where channel partners can continue to provide value.

I spoke with Joseph Perry, the advanced services lead at Arkova, about this very topic recently and we dug into everything from why customers sometimes feel that they need to fix every problem or not do much of anything at all, how hype and fear cycles are changing conversations with customers and opening new opportunities for channel partners to act as strategic consultants and advisors as clients face the new reality and the new risks that AI poses for their business.

We also dive into threats of today and yesterday with an AI flare and talk about what the hype cycle might look like in the future. Enjoy. When you work with customers, with organizations who are advancing on AI deployments in their businesses, whatever that might look like, what are some of the biggest security challenges you see those customers facing and potentially opening their businesses up to? >> Yeah, that's a great question and I think the answer is surprisingly universal.

Usually in cybersecurity, we have well, this business has this, that business has that. But with AI deployment in particular, I think universally the problem is defining the risk surface. It's really understanding what parts of my business does AI touch, what is the risk associated with AI touching those parts of the business, and then what strategies come up around that. And so, a lot of the the challenges that the security leaders have in defining their AI strategy comes from the fact that they're trying to define strategy against the entire world of AI or against one very specific AI project rather than sort of their organization's relationship to that technology. >> What are the kind of risks and pitfalls that come with, to your point, either maybe overextending and trying to fix every potential problem, or getting too specific and going, "Well, we'll just worry about this one thing and and the rest will follow later." Are we talking, I know I hear a lot about ransomware possibilities or just data exposure and and data leakage?

What do you see as some of those common potential issues that you tend to want your customers to to focus on first? >> Yeah, so when it comes to AI and you know, big transformative, frankly, expensive technologies, a lot of the risk comes from the adoption itself. So, yes, there are concerns when we talk about things like open claw or other, you know, AI assistants that introduce risk of malicious prompting, that introduce risk of email-based prompting and things like that.

They're definitely dangerous, but the more large-scale risk on on each of those sides, I have a concrete example. So, on the larger side of trying to, you know, fix the desert with a cup of water, trying to solve the entire world of AI with your available budget. It happens exactly sort of the way that metaphor would suggest. You take everything you have available, very often some very skilled folks with a reasonable budget and a really good, you know, time frame to work, and they find out they're being asked to solve an impossible problem.

And so, organizations will dump their entire AI-related budget, they have all of their expertise wrapped up in trying to build a holistic full AI network, you know, solving every kind of AI problem, and that just doesn't really work out in basically any case. The other side of the problem is when you too narrowly define what you mean by AI. Very often, and this is something that I had with a specific client, we will go in and we'll be talking about, you know, here's how you secure, what we really mean is your chatbot-based AIs, your LLMs, your generative AI tools.

And one of the clients that we were working with were like, "Yeah, we have some of that, we're interested in that, but we're really worried about all of these other things that we've considered AI for the last 20 years, all of our machine learning, all of our generative adversarial networks, all of these things that we've been doing since long before chatbots sort of entered the foreground. We're worried about the risks of those and how those might affect us.

And with that specific client, not only did we help, you know, finding those risks was a useful fact for them, it was a useful resource, but actually finding the ways that over the last 20 years they had solved or solved for a lot of those problems meant that when we came with solutions for that chat-based, LLM-based kind of problem, we had far more history backing it, we had far more expertise backing it, and we were able to weave it into their existing security program.

Where when we first went in with a very narrowly defined, which was based on what the RFP told us they would need, was a very narrowly defined chatbot-based assessment, we quickly realized that that was way too narrow a definition. >> Within that, you bring up an an interesting point here that I think I hear a lot from providers and partners who say, "My customer raises their hand and goes, we need to think about AI." And every customer has a different definition of what they're putting in their systems, of what they mean when they say that they want or using AI.

Do you think customers are starting to better define what those AI deployments actually look like, or is there still a lot of education you think in the market to come? >> Yeah, that's a great question. I would say, you know, I'm always going to plug consulting, but this is the the main value consultants can provide in these questions is coming in. I often joke that my role as a consultant is to talk to all of the folks on your team, gather their information together, and present it to you in a way that you can talk to your board about it.

I'm not coming here and inventing any information. There is some expertise absolutely being applied, but a lot of what I'm doing is talking to members of your team and servicing the problems that they deal with every single day. And that's a lot of what we're talking about when it comes to defining your organization. I talked about that risk surface thing earlier. The way I do that isn't magic, it's not some arcane trickery, it's we talk to every single technical person who has something that might relate to AI, somebody who might be using Copilot to write their code, or somebody who might be generating, you know, very complex image generation platform tools, whatever the case may be.

We talk to everybody involved, we get their understanding, we understand, you know, for some folks they might have an incredibly deep technical understanding of things like nightshade attacks and all of that kind of thing. Other folks, as far as they're concerned, AI is ChatGPT, and that's all they need to know. And so, by building that entire really broad, really deep understanding of that organization's, as I said earlier, relationship to AI. And that sounds like really fuzzy terms, but it's really, really specific.

By building an understanding of that relationship, we can then go to their security leaders and say, "When you say AI, what you mean is this, this, this, and this. And here's how you secure this, this, this, and this." You don't have to go fix the whole desert, you can just find these specific patches of it to make your problem into solve. Um and again, that that tends to really reduce the scope of effort, while also allowing the client have uh that thing that we're all desperate for in the day in the age of AI, which is confidence that they know what they're doing.

Is have some sense of, "Okay, yeah, there's this whole wide world of AI that's very scary, but the part of it that I live in, I'm comfortable that I can get a grapple on." >> I feel like the security conversation around AI and the the kind of sub- you know, governance conversations, etc., have really have reached a a fever pitch over the last few months. It feels like there are more people than ever going, "This is great, but this may be a problem.

I don't know if I've thought through this the right way." Do you see customers slowing their AI adoption because of security concerns, or do you see customers trying to do both things at once to not kind of give up that speed? >> Yeah, as much as I wish to say that everybody started listening to security consultants and security leaders, and they started making the right security decisions. Um if that were the case, we wouldn't have so many compensatory controls in the industry.

The reality is, you know, as we all know, AI is a phenomenally expensive technology. And so, I think what's really driving a lot of organizations to start not necessarily scaling back, but certainly slowing down the scale of their growth, is that question of, "How can we make sure that we're getting a return on investment?" And so, I think when you go to try and solve for that problem, you find yourself actually also having to solve for all of this AI security problems.

You say, "Okay, if if the thing AI is providing us is access, if it's making all of our interactions with customers easier, well, we've got a lot of PCI DSS questions we need to ask about that AI. If the AI is making us better because it's helping us with our drug trials, we have a lot of HIPAA questions we need to ask. And so by going back and defining for the organization what they actually want to spend all of that money on, it makes it easier for them again to define what parts of AI are actually of interest to their risk surface. >> Sure.

I want to take a couple minutes to let's talk about that services approach, the consulting approach that that you've talked about a bit. When you think about what these AI conversations have kind of caused you to create, whether that's new offerings, new service bundles, just new ways of talking to customers. Compare that for me to what you think maybe hasn't changed over the past few years. I mean, I know we we have these talks in the industry of is AI changing everything or is this all just fundamentals applied to a new tech?

How much have have you felt that balance over the past year or so? >> Yeah, um I mean, that's that's definitely the big argument in security about AI. Is AI actually changing everything or is AI basically just making some things faster and everything else is more or less the same. And I think the the reality lies in maybe a little bit in the middle, but definitely closer to the keep your fundamentals and stick to those. Um there are places in specific subsets of cybersecurity where I think it's fair to say AI is making a huge impact.

If you work in vulnerability management right now, you're having a very complicated time just dealing with the the reports and the folks sending you patch notes to you. If you manage open-source software right now, you're having a very complicated time security-wise. Um but across the industry and in general, I think that the first and most important lesson you can have in cybersecurity is keep a cool head and solve the problem in front of you. And I think that's what the core fundamental for AI is.

And so as we're seeing, it's absolutely true to say some kinds of attacks are getting far more prevalent. Email bombing is one of my favorite examples of it doesn't get a lot of news attention, but it's an attack that's explicitly made possible by AI. And it's one of the most dangerous and powerful attacks threat actors ever come up with. This is something where 20 years ago email bombing was basically the primary form of internet-based harassment and was tremendously effective.

It was so effective in fact that we invented CAPTCHA specifically to block attacks like email bombing. Well, what's the first thing that everybody does with their fancy AI tool? They prove that it can break CAPTCHA. And so email bombing has returned as a major attack even though that's something that we think was ancient old news. I've now seen it in multiple clients and multiple environments, multiple industries, and it's a tremendously impactful where people aren't able to It's a functionally a DOS, you know, it's a denial of service that is tremendously impactful because we built a layer into the internet to stop it, which means we don't really have that multiple layers of defense.

We don't have that experience with defending against that kind of attack. And so it's a a really really common issue. So I think that we are creating you know, we have created some new or newish service lines. I would say it's more old service lines with a twist. So AI purple team being the center of that where it's purple teaming as we've always done it. We construct a series of attacks based on known threat actor behaviors. We work with your defenders to you know, perform those attacks where they can see us do it and then we report the results back.

It's a it's exactly what purple teaming has always been, but now it starts with that process of understanding your entire AI risk surface. And the tests that we build are far more customized because there's not you know, an atomic red for AI for example. Well, there are but they tend to be just malicious prompting focused and that's very low priority in testing. So we've got to do a lot more custom work in terms of the very specifics of the test, but the strategy around the test is just purple teaming the way we've always done it.

And so that's where I say it is somewhere in the middle, but it's definitely more towards that keep your fundamentals. >> Sure. Does it change the way that you talk with customers and clients? I mean I know we had that conversation a few minutes ago kind of about them coming to you and saying one thing and you going, "Okay, well, actually what you mean is probably this other thing." But how much does that change the the relationship and maybe even the stickiness that you start to feel with clients when you do end up going maybe deeper than you would have a few years ago with them. >> Yeah.

Um this is you know, I'm a firm believer that good consultants make their name by being honest brokers. You tell your client the truth and you give them the best advice you can with all the caveats that you need to give them. And then they make the decision based on the information that they have. Sometimes it goes really well, sometimes it doesn't. You know, you we we cannot rule the outcomes. We can't decide those things. Our job is to just provide the best advice we can.

And so, a lot of what I do these days is convince my clients that the sky isn't falling. It's It's find a way of telling them, "Hey, yes, this is an interesting concerning development, something we need to be aware of. No, you should not dump two years of security strategy, pivot your entire budget into this new technology that somebody's trying to sell you." And the challenge there is that you can't be too casual about it because if somebody comes back and they're like, "Well, my entire board is telling me I need to make this decision, so I I have to do something.

I have to respond to them in some way." And so, a lot of the last year, the last two years really, has been working with clients to really understand, "What is your concern here? What is the thing that you're worried about? Is it that some AI demigod is going to hack you instantly, or is it something a little bit closer to home?" And then understanding what is, you know, whether it's your board, whether it's your CISO, whoever you're talking to, what are their primary concerns?

Where are they getting those concerns from, you know, who are they hearing that from in the world so that we can address the very specific details of that. And then, once we have that understanding, once we have that relationship, if you do it right and you're not just telling the client over and over, "No, you're wrong. This is This is the way you need to do it. Do it our way." But you're actually hearing them out, you're addressing their concerns, and you're helping them address their own concerns, it's an incredible opportunity as consultant to one demonstrate a depth of technical skill, but two to show yourself to be, again, that honest broker.

You could come in as an AI salesperson as you know, just say, "Oh, buy this tool and it's going to solve all your problems. Everything's going to be great." We know that's not true. There are no silver bullets. It just doesn't work that way. And so, taking that opportunity to be constructive and helpful and positive, but still honest and guide your client in the right direction, I think it's rare that as consultants we get such an easy opportunity for a win. >> Within that you highlight something that I think is is kind of interesting, which I feel like we've talked about the hype cycle of AI for a while, right?

Is it going to fix everything? Is it going to break everything? What does that mean? But you're almost describing a a fear cycle a little bit as well, right? That maybe there are people going the opposite direction going that the whole world's going to end, everything's falling apart, I don't want to touch it. Do you think over the next maybe 6 months to a year we'll find a middle ground or at least most people will find a middle ground between this is where it's useful, here's how I secure it, and we move on?

Or how do you kind of see the the maturity curve there continuing to develop? >> Yeah, that um if I could answer that question with confidence, I wouldn't be here. I'd be making billions on Wall Street. But I definitely have a theory. And and that theory really is predicated on I think most people are actually in that state of equilibrium right now. I think most people know, I use AI day-to-day for these things and it's useful for these things for me.

And when I try to use it for these things, it falls apart and nothing succeeds and it doesn't work. The security aspect of that has not been asked by a lot of folks, but that equilibrium of usefulness has been reached by a lot of individuals. Right now, it's really organizations that are struggling to find that space. And so I think really technically sophisticated organizations that have been moving quickly, that have been ahead of this for a long time, some of those are starting to get into that equilibrium now where they've got, you know, they say, we know how many tokens we want to spend, we know where we're applying AI, we're taking down the leaderboards, we're focusing on the actual value areas.

And their overall AI spend is definitely dropping, but it's also becoming much more targeted, much more focused. Um and I think that we are seeing less sophisticated, I don't want to say unsophisticated, but less sophisticated organizations that are still believing everything they read in the media about AI, they're still trusting whatever person comes in off the street to sell them AI, who are still trying to figure out, you know, where in the future is that going to be.

I'd love to say that in the next 6 months most folks will be in that state. I don't necessarily know. Um and I think a lot of that comes back to the point you made of of fear and hype. So, we've gotten the excitement, we've got the you know, we can sell you the future, we can sell you a utopian dream. But, there's also the the flip side of that, which is well, if the wrong person has this, if the wrong person does this thing, or if the wrong team does this thing, then now it's dystopia that we're not selling you, but we're selling you a panacea against.

And that's a really, really compelling uh argument. That's something that the human brain is naturally inclined to receive. We're very good at receiving bad news and believing bad news. We're very bad at believing good news. And so, selling on that and convincing people on that front is a really powerful technique. But again, I think in the same way that folks have reached the equilibrium of usefulness, I think a lot of folks are starting to see that equilibrium of fear where they're asking themselves, well, hang on.

When I go to ChatGPT and I ask it to create a recipe, like one in 10 times it uses a non-organic ingredient, I'm not so sure I believe that same technology can take over the entire world in an afternoon. I just don't think it makes a lot of sense for those two robots to coexist in the same platform. And I think that that it's easy for that rationality to be overridden in the early days when you're first hearing about this technology, but as time has gone on, we're seeing more and more people reach that.

So, hopefully in the next 6 to 12 months, it might take longer, we'll see. >> Well, and we're having this conversation too on the heels of the the OpenAI hugging face debacle situation, whatever you want to call it, has taken over headlines. We had the Anthropic mythos debates of of a few weeks ago, a few months ago now, as well. How do you want to see customers or leaders generally speaking, whether they're customers of yours or not, take in information like that, which on its surface is rather alarming, I think, for most people to some degree, process it and go okay, but how does that actually impact my business if it does?

Or should I just take that in go, okay, that's something to think about and then go forth with my day. >> Yeah, so, you know, shameless plug for having a good technical person on your team. Having somebody who can really do a deep dive and say, uh OpenBSD, I don't think I've seen that operating system in 25 years. I don't know how much I care about that exploit. Having somebody who can give you those layers of of experience and knowledge is really really useful.

But as an initial first pass without, you know, handing it off to whoever your expert may be, the thing that I always advise, whether they're my clients or just somebody that I'm talking to on the street, is check for the tone of what you're reading. If the thing you're reading sounds like marketing, it's probably marketing. If the thing you're reading is this incredibly advanced thing happened, it's a brand new kind of attack, we've never seen anything like it before, it's so scary, it's so exciting.

That's not how people talk about an incident normally. Normal incident reports are demure. They're 500 words or less if the company can get away with it. On this date we detected this thing, on this date we took this action, these things are still pending. Because that's the most legally protected language to use. That's what your lawyers are always going to tell you to say. Use the fewest words you possibly can to communicate the facts that the SEC will sue you if you don't communicate them.

Nothing else, nothing more, nothing less. And when we see these incident reports or we see these breathlessly fearful reports come out about, oh, we're so sorry, we had this terrible incident because of this incredibly advanced AI, well, the headline there really is about the AI. Um this is something that I've talked a lot about, you know, it's it's very easy as an organization right now. It's a little bit of a get out of jail free card if you have a major incident, you say, we got hacked by an advanced AI actor and now all anybody hears is advanced AI actor.

And they forget that what you're doing is a run-of-the-mill incident disclosure, which in most cases, unfortunately, will lead to litigation, investigation, negative, you know, outcomes, all of those challenges and externalities. If you put AI in the title, it's sort of like a few years ago when we had the Long Island blockchain company. All of a sudden the magic the magic word is in the title and the value of the whole thing changes. So, read for tone, read for intent, and then once you've read read for intent and you're like, "This kind of feels like a marketing document." That's when you pass it off to your tech folks and ask them the straightforward question, "Is this a marketing document?" And I think you'd be surprised at how often the answer is yes. >> How do you see that opportunity continuing to evolve, continuing to grow?

I mean, I'm sure most of your customers would say they aren't removing AI. It's not going to be the thing that they tried for a year and and moved on from. And most of these security topics are evergreen to some degree. So, do you see yourself continuing to innovate and expand those services? And then how do you kind of want the industry then to approach managed security, security consulting, etc. in this new world, to use the marketing term? >> Yeah, absolutely.

Um it's it's one of the coolest things about AI. It's the reason I love AI as a technology, which may be surprising to hear when you hear me talk about the industry. Uh AI's hype cycles are unlike any other technological hype cycle. They always leave something useful behind. They left behind big data, they left behind machine learning, they left behind databases in the '70s and '80s. AI hype cycles are not useless things, but they're they're overexcitable things in a way.

And so I think that what we're doing right now is we're starting to see companies, as I was talking about earlier, they they're starting to target down where are we getting ROI on our token spend, which is very dangerous question if you're an AI provider trying to sell a trillion dollars a year. It's a very powerful question if you're an AI purchaser. And so I think as companies are starting to ask these questions and their relationship to AI, to reuse my my tired phrase, begins to shift, that's where our consulting and that's where managed services need to shift as well and say, "Okay, if the primary risk for you is overspending on AI, then the security consulting we need to do here isn't just about somebody hacking into your system, but let's talk about if somebody were able to steal a token and hit your image generation endpoint a million times a second, what would that do to your overall token spend and how would that impact your organization?" And so it it really goes back to the point I made at the very beginning, which is understand that specific risk surface in that specific environment, all the places that it touches AI, and understand that at least for the next 18 months, that's going to continue to change in pretty significant ways. >> What excites you the most about the ways that you can leverage AI?

What excites you the most about the ways that customers are going to continue to need a partner like you to leverage it themselves? >> AI, it's it's what creates the hype in the fear cycles. AI inspires the human imagination like nothing else. We have been telling stories about AI since long before we had a concept of computing. Um if you consider, which I very much do, stories of the Golem to be AI, we've been doing it for thousands of years. It is fundamentally a question of creating a non-human intelligence for whatever reason a person might have.

And so, the imagination that sparks and the questions that it inspires us to ask and answer are exciting questions, and they all have terribly deep security implications. And so, each time, whether it's now in the future, whether it's the next hype cycle about 10 years from now when we're talking about this again, I think it's going to be for me the answer is always I'm excited at the questions clients ask. When they say, "Hey, can we do X with AI?" A lot of times the answer is no.

A lot of times the answer is, "Yeah, that's just as far-fetched as you thought it was." But sometimes the answer is yes. And that the the space of the answer that gets yes for happens a little bit bigger with each of these hype cycles that go. And so, I'm very excited not only for the technology itself to improve and for the next time to come around and see how close we get to consciousness then, but I'm excited because I think this inspires an imagination in us in a corporate way that we don't normally get to have.

People don't usually dream big at work. And so, obviously big dreams have, you know, big concerns, and that's where security consulting comes in. Um but it's one of the coolest things about a technology, and there are very few technologies that do that for us. >> Well, Joseph, thank you again so much for taking the time today. Great conversation. I'm sure we could have it next week, and we might have different things to talk about with how fast things are moving, but I appreciate you taking some time.

If people who watch this uh struck inspiration or or want to learn more about our COVID generally speaking, where would you send them? >> Yeah, so arcovid.com is a great place to start. You can also find us on LinkedIn. We are a very broad we're full-service cybersecurity, so whether your questions are about AI or about anything else that might be related to security or security and AI and the places those things meet, we're definitely the place to go and we're happy to talk to you about it. >> Perfect. Well, thank you again so much for joining. Enjoy the rest of your day. >> Thanks so much, Victoria. Likewise.

This transcript was generated automatically from the video's captions and may contain errors.

Arcova’s Joseph Perry discusses AI security hype, emerging risks and how channel partners can become trusted strategic advisors for customers.

Aug 11, 2026
1 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

AI security conversations are increasingly dominated by extremes: AI will either solve every business problem or introduce risks organizations cannot control.

The reality is far more nuanced.

Channel Insider’s Victoria Durgin speaks with Joseph Perry, Advanced Services Lead at Arcova, about how businesses can move beyond AI hype and fear and take a more practical approach to security.

They discuss why customers often feel pressure to either solve every AI-related risk at once or avoid taking action altogether, how shifting AI threat perceptions are changing customer conversations, and why channel partners have an opportunity to become more valuable strategic advisors.

The conversation also explores how existing cyber threats are evolving with an AI twist—and what the next stage of the AI hype cycle could mean for businesses and their technology partners.

Victoria Durgin

Victoria Durgin is a technology communications professional and editorial leader specializing in channel technology, cloud marketplaces, managed service providers (MSPs), technology distribution, and partner ecosystems. As Managing Editor of Channel Insider, she oversees editorial strategy and content development focused on helping technology vendors, solution providers, and channel partners navigate an evolving IT landscape. With nearly a decade of experience spanning technology journalism, corporate communications, content strategy, and digital publishing, Victoria has developed deep expertise in the business side of technology. Her work includes creating executive thought leadership content, industry analysis, case studies, and channel-focused reporting that helps organizations better understand market trends, partner relationships, and technology buying decisions. Before leading Channel Insider, Victoria built experience across local journalism, business reporting, social media communications, and corporate marketing. She has worked closely with technology vendors, cloud providers, and managed service organizations to develop content that highlights industry innovation, business growth strategies, and successful channel partnerships. Her portfolio includes case studies featuring mid-sized MSPs across the United States, Canada, and Australia. Victoria's work has appeared in Channel Insider, The Valley Ledger, and Medium. She holds a Bachelor of Arts in Communications and Environmental Studies from Susquehanna University. Through her reporting and editorial leadership, she helps technology professionals stay informed about the trends, challenges, and opportunities shaping the global IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.