We interviewed Ankush Johar, Director of Infosec Ventures, Co-Founder of EliteCISOs Global, and GCA Ambassador, to learn more about his work as a serial entrepreneur and cybersecurity investor, his work with both private and public sector organizations, key lessons he’s learned throughout his career, and his top tips for getting more people to care about and invest in cybersecurity.
As a serial entrepreneur and cybersecurity investor, what are the biggest opportunities and unfilled gaps you see in the digital ecosystem today? What tools, solutions, or models hold the greatest promise for strengthening security?
As an investor who has the privilege of working closely on the ground with our investee companies, I have a thirty-thousand-foot view, but also a view on the execution, so I will be very specific.
I see three gaps clearly.
a. Human risk as a control surface, not as an audience that needs training.
Most incidents still start with a human making a pressured decision. Treat people as part of the control stack, not a training audience.
Humans are not the weakest link in cybersecurity! They are the strongest, if only our perspective is in the right place. The fault lies with us in the industry because we spend vast amounts on technology to bolster our ‘computer operating systems,’ whereas the ‘human operating system’ has not been firewalled.
Solving this is where the opportunity lies. Is it possible to empower users to be like Ironman? A combination of ‘Human + Machine.’
- Not helpless, but enabled with technology, to safeguard our organizations.
- Not as an audience that needs training, but as part of the control surface – deeply integrated.
b. AI proliferation means that the attacks today are sharper than ever.
As an example, from a technology perspective, hackers are combining generative artificial intelligence (genAI) and Model Context Protocol (MCP) servers to automate and multiply their power to hack technology, like an ‘infinitely’ scalable hacker. Having seen this in action, I have not been able to unsee this. Unless defenders think like this, this rabbit hole will go very deep.
From a human perspective, grammatical errors are no longer a signal of a suspicious email. GenAI in the hands of hackers has meant that attacks are harder to detect than ever. I coined the term “Needle Phishing” back in November 2023 to highlight how hackers using simple open source intelligence can know so much, because stolen data is being armed against those who have been stolen from (for no fault of theirs)!
The solution is to fight fire with fire.
How? By leveraging the tech before you are paid a visit by the bad guys. The same tech is available to defenders, but we need to prioritize managing risk. Identify your crown jewels, single-mindedly defend those, and then focus on compliance, not the other way round.
c. Cyber Antifragility, not cyber resilience.
This is a big one, and I’ve saved this for last.
Due credit to Mr. Taleb for coining the term ‘antifragile’ first. Now, its application and use in cyber.
We’re chasing cyber resilience. Cyber resilience is when we defend, and in case of an attack, return back to the original form. Fragile is when we break when faced with an attack. These are two states that are easy to understand, and we are familiar with these.
But “cyber antifragile” is when we defend, but in the face of an attack, we return to a stronger state than we were in. Why wait for real attacks, why not simulate them instead? To use an analogy here, our human body is designed to be antifragile – when we go to the gym and pump iron, we tear our muscles – the more they tear (within limits), the stronger they become.
The more you sweat in training, the less you bleed in battle.
Leaders need to demand cyber antifragility, not cyber resilience. They need to demand more sweat in training, so they are better prepared for battle. It is a battle out there.
Given your experience advising regulators and international bodies like the International Telecommunication Union (ITU) and the Body of European Regulators for Electronic Communications (BEREC), what are the biggest policy challenges currently facing global cyber security?
- Fragmented and expanding global regulations:
The spread of conflicting or overlapping national data protection and cybersecurity laws adds significant compliance challenges. This patchwork hinders streamlined defense, rapid information sharing, and cross-border incident response, especially for organizations active in multiple countries. Ensuring policy harmonization and cooperation is increasingly complex. We need to bring interoperability without dilution. Multinationals juggle different breach-reporting clocks, data-localization rules, and supplier attestations. I favor mutual recognition and baseline interoperability that preserve sovereignty yet lower the cost of doing security well. A 72-hour clock in one jurisdiction and 24-hour in another shouldn’t force duplicate systems and contradictory behaviors. - Proportionate supply-chain assurance.
Visibility across software supply chains and telecom interconnects is essential, but we can’t crush small suppliers. Give them clear templates, pre-approved artefact lists, and shared attestations so they can evidence good practice without a compliance team of ten. I reiterate this, when I can: Make the safe path, the fast path. This leads to sustained security. - Quantum cybersecurity is an imperative now, not tomorrow.
The RSA-2048 encryption standard would require millions of years for a conventional computer to break, but a quantum computer could theoretically do so in hours. Quantum researchers call it ‘Q-Day’, the day when quantum computers (scaled) will use Shor’s algorithm, which will break all public key systems. The convergence of AI and quantum technologies will have significant implications. It is important to prepare for both the positive and negative impacts of quantum technologies due to their disruptive potential. - Measure outcomes, not page counts.
If a control improves detection time, containment time, or secure-configuration rates, it’s useful. If it only increases the size of a binder, it isn’t. I encourage regulators to accept automated evidence feeds and sampled control tests—it raises fidelity and cuts the attack surface.
Here’s what matters: Align incentives to real-world defense, not administrative rituals.
Having worked with many mobile operators, how do you assess their cybersecurity readiness, and what still needs urgent attention? Are the challenges unique to mobile operators, or universal across telecom operators and large enterprises?
Strengths. Operators treat availability as a duty of care. Core network teams are disciplined on change control, monitoring, and incident drill cadence. That muscle is real. I can’t say this for all large enterprises. So, mobile operators are better off that way.
Assessing cyber readiness of a mobile operator:
A mobile operator’s cyber readiness can be judged by starting with the crown jewels—5G core and signaling, subscriber data, BSS/charging, eSIM/RSP, and CI/CD for CNFs—then rating control maturity across network security, cloud/Kubernetes hardening, API governance, fraud and identity (SIM-swap/port-out), ransomware resilience, and third-party/interconnect risk.
It can be validated outside-in with signaling test calls, red-teaming of CNF pipelines, and service-level drills (“can we contain an event before it becomes an outage?”).
Urgent gaps that are seen repeatedly are uneven signaling policies, immature 5G cloud controls, API sprawl without strong auth/rate limits, fragile BSS recovery for ransomware, weak eSIM/SIM-swap defenses, and thin software-supply-chain assurance (SBOM/signing/provenance).
The human layer risk of social engineering of the customer care teams is a critical one, and yet unsolved. There are robust solutions, but the uptake has been slow. Once bitten, twice shy! Those that have been hurt have moved rapidly, albeit post incidents! I wish it wasn’t like this though.
Unique vs universal. The themes—identity, email, human risk—are universal. What’s distinctive for mobile is the scale of identity operations and the inter-operator trust fabric. Both require continuous hardening and high-fidelity monitoring. And yes, this is winnable.
Many challenges are universal to telco and large enterprises—ransomware, third-party exposure, API/cloud hygiene—but four are distinctly mobile: interconnect/signaling risk, 5G core & MEC complexity, SIM lifecycle abuse, and the real-time charging/latency dynamic that turns cyber issues into customer-visible outages fast.
What key lessons have you learned over the course of your career that the cybersecurity field as a whole should take more action on today?
- Treat cyber like a P&L
Run security like a business line: a short weekly dashboard (time to detect and fix issues, restore time from drills, open critical gaps) and spend prioritized by risk reduced per dollar. After incidents, harden the weak spots so results improve quarter on quarter. - Assign true owners, beyond the CISO
Give each crown-jewel system and major risk a named business owner with budget and targets—just like revenue lines. Accountability for closing gaps sits with the business, not only with IT. - Align incentives—pay for outcomes, not paperwork
Tie bonuses, team goals, and vendor contracts to real results (faster patching, quicker recovery, fewer repeat issues), not the volume of compliance reports! - Practice the bad day
Rehearse breaches like fire drills—legal, communications, operations, and the CEO included—so decisions are fast and coordinated. Each drill should yield a permanent fix, such as quicker restores or tighter access. This compounds over time, so it is invaluable. - Identity-first Zero Trust
Most organizations have put apps behind single sign-on (SSO), so that is the key to all keys now, and all users have it, at least their own key! If that goes, so does the data they had access to, and it exposes the apps too! Ensure account takeover or a stolen password doesn’t become a company-wide incident. - Trust but verify (vendors & supply chain)
Supplier risk is enterprise risk. Questionnaires alone do not cut it, neither do once a year audits. If they know that you know that they are vulnerable, they will keep a tight grip on their security. Real-time security rating is crucial. Tier vendors by impact, require proof of hygiene, test controls in production, and maintain an always-on watch from the outside. - Protect what matters (data-centric)
Start with the data that would hurt most if leaked. Keep less of it, encrypt and monitor access, and trim exposure after every incident to shrink blast radius over time. - AI-ready controls
Treat AI like a powerful contractor: register uses, set guardrails on what it can see and produce, and test for leakage and abuse. - From visibility to automatic action
Dashboards inform, automation prevents. Pre-approved playbooks trigger instant actions for common threats (isolate a device, revoke tokens), reserving human time for unusual cases. - Governance that speeds you up
Provide pre-approved secure building blocks and a fast lane for teams that use them. This cuts delivery time while raising the security floor and reducing exceptions.
Any tips on how to get broader audiences to understand, care about, and invest in improving cybersecurity?
I have liked using mnemonics since school because I couldn’t do rote learning. This is my favorite when talking to friends, so I will reproduce it here:
AJ’s SECUREIT framework :-)
S — Strong passwords: use a password manager (one strong master password).
E — Enable updates: let phone & laptop auto-update.
C — Click carefully: don’t tap links from random texts/emails—open the official app.
U — Use 2-Step: turn on 2-Step Verification for email, bank, socials.
R — Resist sharing codes: never give anyone your one-time codes (OTP).
E — Expect scams: “urgent + money + link/code” = likely scam/fake.
I — Important backups: photos/files in cloud + one external drive.
T — Trust but verify: you will instinctively know when it is fake, just verify!



