A self-described “recovering hacker,” Alissa Valentina Knight has spent the better part of the last three decades compromising computer networks and security systems, either illicitly or with the blessing of corporate and government leaders. The 26-year cybersecurity veteran originally started out as a teenager hunting for tips on gaining unauthorized access to classified business information on Bulletin Board Systems (BBSes). But she’s since parlayed her experience on the shadier side of computing into a thriving career that sprawls across both the Internet and real world. See sample ventures such as high-profile consulting gigs for the Pentagon, a spate of Hollywood screenwriting and production credits, and critically acclaimed books like the prescient (and somewhat terrifying) Hacking Connected Cars.
Today, the noted content creator, influencer and erstwhile IT mogul heads up the Knight Group, a venture studio that owns and operates a spate of high-tech startups. She’s just taken the wraps off her latest creation, Assail, a new agentic AI startup that’s building autonomous agents designed to assist clients around the world with functions such as automated API vulnerability and penetration testing. (“We are an adversarial AI company, empowering organizations to be able to identify and defend vulnerabilities in their modern application stack,” she explains.) Long story short: When it comes to probing the boundaries of emerging technologies and cybersecurity solutions, the leading expert – whose business ventures also include TV and video game publishing firms – has just about seen and done it all.
Curious to hear how the shape and nature of online threats is changing in the age of artificial intelligence and automation, Focal Point caught up with her between a seemingly endless spate of flights and meetings. Here, she shares her thoughts on ways that tomorrow’s cybersecurity pros can better tackle new digital dangers, how IT leaders can adapt their strategies and mindsets to tackle emerging challenges, and what comes next in an age where digital dangers evolve at the speed of LLMs.
Q&A
Focal Point: How has the rise of AI and automation changed the landscape of cyber threats for organizations in every space?
Alissa Knight: Historically, even prior to the use of AI for adversarial applications, working professionals have really struggled to keep up with a human adversary. It’s always felt like a game of catch up and reacting. Now with adversaries using large and even small language models to launch new threats and attacks, the divide between defenders and attackers is widening. It’s really a concern of velocity. We’re now operating at machine speed and lethality, where people that really don't even know how to compile an exploit are now quickly becoming able to hack systems and compromise a network.
“We’re now operating at machine speed and lethality, where people that really don't even know how to compile an exploit are now quickly becoming able to hack systems and compromise a network”Alissa Valentina Knight, CEO and Chief AI Officer, Assail
Recently, we've developed a platform using adversarial AI to identify vulnerabilities in a network. And I can tell you, the platform we've built was able to compromise seven banks in two and a half minutes. I don't know how humans can defend against something that’s that fast and that lethal. It brings up a lot of concerns regarding mean time to detection and response, which is only getting worse.
Focal Point: What are some of the security assumptions that companies rushing to adopt new AI tools and technologies are getting wrong from the beginning?
Alissa Knight: On the defense side, AI isn't a simply a feature anymore. It’s an essential capability, and you have to get on the bandwagon. AI is radically transforming the cognitive overmatch capabilities of both defensive and offensive solutions. As a result, a lot of organizations are now looking for AI-powered solutions to be able to keep up. Basically, the technology provides defenders with a level of competitive advantage in defending against attacks, and they're using it to enhance forensic and incident response capabilities as well.
But at the same time, you also have adversaries who are using AI to maximize and amplify their capabilities to compromise more networks than ever before. And to break into systems that they potentially couldn't before because either the exploit was too expensive to buy on the dark Web, they didn't have access to it, etc. What AI has done is really democratize the nature of hacking. It lets individuals who otherwise have no idea how to hack to do so and compromise systems as long as they have access to an adversarial AI model (meaning a model that has no guardrails implemented or is jailbroken).
Focal Point: When today’s criminals compromise a network or app, what are they actually targeting? Is it access? Is it data? Is it network influence? Or even access to AI models themselves?
Alissa Knight: It’s funny, when I first got into cybersecurity, it was really all about defacing websites and being able to say that I compromised the face of NASA.gov, or whatever. Now it’s a different world and hacking is very much a for-profit operation. There are transnational crime syndicates and individuals who are looking to profit off your data, ransom a company, and then sell that data on the dark Web. Add to it hostile nation states who are seeking military advantage or to build or access something that they couldn't develop on their own. And here's the thing: data is worth more than things like oil and Bitcoin, and that’s pretty much what [criminals] are looking for.
Focal Point: What are some of the signals that tell attackers that a company’s security posture, and especially AI security posture, may be on the weaker side?
Alissa Knight: I'm a big believer that the best defense is having the best offense. And if we are now in an age where adversaries are using AI, we have to ask why, as defenders, some of us are still using legacy vulnerability scanners that work off of pattern matching and not using AI as well to identify and exploit vulnerabilities in our environment? You have to use the same tactics, techniques and procedures that criminals are using to target and break into your network. So, if we as defenders have access to AI, whether it's AI-powered firewalls, security controls or whatever, we need to be leveraging the same technology that adversaries are using against us.
There's a simple question that can identify whether or not an organization is simply just not keeping up or not able to defend against AI-powered threats: "As an IT leader, are you using AI to identify the vulnerabilities in your environment?" I guarantee you, we are now in an era of machine-on-machine warfare. It's no longer about defending our pyramids and our cloud service providers against human threats. We're now defending them against robots, against machine threats. Ultimately, it comes down to LLMs vs. LLMs.
“As an IT leader, are you using AI to identify the vulnerabilities in your environment?”Alissa Valentina Knight, CEO and Chief AI Officer, Assail
Focal Point: If you were advising an executive team, what tips would you give them to defend against these types of cyber threats, noting that many are still playing catch-up on the IT front?
Alissa Knight: I still firmly believe in 2026 that APIs remain the backdoors and side doors into our operating environments. API sprawl and shadow APIs are a massive problem. A lot of the breaches now are happening due to hackers turning their attention to APIs because they know that that's where the data is, no matter if it's financial information, PHI, PCI, HIPAA, or whatever that’s being served. My advice to leadership is to know how many APIs that you have in your environment, and which are serving regulated data. It helps to build security strategies like layers of an onion, starting from there, rather than trying to protect every single API and have an AI-powered solution to find them, exploit them, remediate them, and defend them.
Focal Point: In the age of AI and LLMs, what skills or mindset shifts do you think security teams need to adopt if they want to defend against all these increasingly automated and intelligent attacks?
Alissa Knight: I know this is a very controversial topic, but I don't believe in keeping humans in the loop. I believe that humans need to get out of the way so that AI can move at machine speed and do what we've designed it to do. Now we definitely have some maturity and some time that needs to go into developing more advanced [LLMs and automated high-tech tools]. But the scary thing is that right now the technology is the absolute worst that it's ever going to be in terms of LLM and SLM capabilities. The solutions only get more capable and challenging from here.
“We’re now operating at machine speed and lethality, where people that really don't even know how to compile an exploit are now quickly becoming able to hack systems and compromise a network.”Alissa Valentina Knight, CEO and Chief AI Officer, Assail
My advice is to learn how to use AI in your job ASAP. Don't get caught up in the debate of, "is AI going to replace me?" Look, AI is here. There's no stopping it. It's being used by our enemies to compromise our networks. And ask yourself, "What can we do to better integrate AI into our routines?" It's part of our daily jobs now and helps to make us more effective, to increase our efficacy as defenders, increase our efficacy as red teamers and penetration testers, and just help us make ourselves more secure, right? If you can't beat ‘em [AI adopters, that is], join them, I always say.
Focal Point: At the speed the field is now moving, how do you see the nature of cybercrime evolving as criminals begin using artificially intelligent off-the-shelf hacking tools and autonomous AI agents at scale?
Alissa Knight: Here's the thing: Necessity is the mother of invention. Since China and other hostile nation states are not able to get their hands on acquiring big data center GPUs like the Hopper Nvidia or the Blackwell Nvidia chips, it's really difficult for them to build, run, train, and inference on these 1 trillion-parameter models. So what are they doing? They're building small language models that are capable of running on things like the RTX 6000 with 96 gigs of DRAM. I think that that's going to continue to be the direction for our adversaries and even on the defense side.
Think about cell phones. Cell phones started out really large, then they started to get smaller and smaller over time. I think that's what's going to happen with AI, where we're starting out with these massive trillion-parameter models. We're going to realize as we make models more energy-efficient on the hardware side and more efficient, is that we're trying to make the models smaller and smaller.
So basically you can have something like an extremely lethal small language model that’s able to run on a Raspberry Pi. Or even do so on a device that fits in your pocket like a smartphone that's capable of hacking a local wireless network or hacking a local cell phone tower. Going forward, I think the models become smaller and more lethal.
Once upon a time, the technology curve took a year or even several years for new innovations to arrive. Now it's moving to more like six months. If you look at the AI companies developing frontier models, it's almost moving towards a sort of quarterly release cycle for new capabilities to boot. Innovation is now happening faster than before and we're taking much bigger leaps forward when we do.
Focal Point: Fascinating and frightening: Noting this, if there’s one overarching piece of advice you’d offer IT leaders about securing an organization in the age of AI, what would it be?
Alissa Knight: You can't protect what you don't know you have. You have to find what technologies and tools are in your IT environment and secure them by continuously running penetration testing and trying to hack them. I'm a big believer in continuous threat exposure management (CTEM). It’s important to continue to hack yourself and use the tools that the adversary is using against you before others get around to doing it.
