
S6:E76 Security is ultimately a promise of trust. So what happens when that trust gets broken? Karim Toubba has had to answer that question in circumstances few CEOs would choose. He joined LastPass as their CEO only months before the company experienced a significant and highly publicized 2022 security breach. In this candid conversation, Karim acknowledges that LastPass initially communicated too slowly and explains the systemic changes, transparency, investment and cultural work required afterward. Queue up this episode of Small Business Stories for a conversation that goes well beyond passwords. Because the threat itself is changing. Karim says AI is producing a meaningful productivity advantage for small businesses, but it is simultaneously allowing malicious websites and other threats to be generated at much greater velocity. Employees are also adopting AI applications faster than many organizations can establish policies around what data those applications should be allowed to access. If people don't trust you, reassuring them that you're trustworthy isn't enough. If customers cannot see credible evidence supporting what you say, they'll increasingly turn to third-party communities and other sources to interpret your credibility for themselves. And if inaccurate or incomplete information about your organization remains unchallenged, the external interpretation of your company can begin separating from the reality inside it. That's where Karim's cybersecurity experience intersects powerfully with Dr. LL's work on misinterpretation risk. 👤 Guest Karim Toubba CEO, LastPass Cybersecurity executive with nearly three decades of industry experience ⚠️ Core Problems Credential theft remaining a major attack vector Password fatigue and poor security habits Trust erosion after a public organizational failure Employees adopting unsanctioned SaaS and AI applications Sensitive information being uploaded into AI systems AI accelerating the volume and sophistication of malicious sites Organizations confusing a security product with a secure culture 🥡 Practical Takeaways Make security easier to practice; complexity undermines adoption. Passkeys and biometrics can reduce dependence on traditional passwords. Treat every piece of information uploaded to an outside platform as something that could potentially become exposed. Understand both what AI tools employees are using and how they're using them. Cybersecurity requires technology, investment and culture not merely software. After trust is damaged, acknowledge what went wrong and provide evidence of what changed. Participate in third-party conversations about your company rather than assuming your owned communications control the narrative. Begin thinking beyond human identity: AI agents will also require identities, permissions and access controls. <h3 data-sec
Podzilla Summary coming soon
Sign up to get notified when the full AI-powered summary is ready.
Free forever for up to 3 podcasts. No credit card required.

Why You're Wasting Money on Google Ads with Andy Janaitis

Why Your Marketing Isn't Working with John Elbing

Should AI Replace Humans in Customer Service? Guest Nathan Strum has Thoughts

Why Your Google Ads Aren't Working Anymore with John Sanders
Free AI-powered recaps of Small Business Stories and your other favorite podcasts, delivered to your inbox.
Free forever for up to 3 podcasts. No credit card required.