"Cybersecurity is a team sport" » Interview with Raj Samani

Before his talk at GoTech World 2025, we sat down with Raj Samani, SVP Chief Scientist at Rapid7, to talk about the evolving face of organized cybercrime, the growing threat of AI-driven deception, and why the fundamentals still decide most breaches. Let's have a look.
Raj Samani has spent more than 25 years in cybersecurity, working closely with both private companies and law enforcement, including the European Cybercrime Centre. That vantage point gives him a rare, ground-level read on how threats actually evolve, not just how they're discussed.
📖 A Hobby That Became a Career
Raj's path into cybersecurity didn't start with a job title, it started with a book. "It was reading 'The Cuckoo's Egg' by Cliff Stoll that first really attracted me to a career in cybersecurity," he says. "My first reaction after finishing it was, 'Wow, this is incredible. This is where I want my career to go.'"
At the time, he was working on a helpdesk, quietly taking on security work through his own initiative, rolling out governance policies, antivirus software, and investigating dial-up attacks long before it was part of his job description. The book, he says, was the turning point that showed him a career could be built out of it.
That original curiosity never really left. "Cybersecurity being a hobby hasn't changed for me," Raj explains, "and with so much happening, it's impossible not to stay motivated. No two days are the same."
💰 Cybercrime Has Become a Business, Not Just a Threat
Asked how organized cybercrime has changed and the answer isn't really about technology, it's about accessibility. "Now, even relatively inexperienced threat actors have access to those same capabilities" once reserved for nation-state actors, he says.
The numbers back it up. Ransomware groups are, in his words, "reportedly earning tens of millions of dollars per quarter and reinvesting that revenue into toolkits, infrastructure and even 'customer service' operations to negotiate with victims."
Perhaps most striking is how low the barrier to entry has fallen. "Criminals can buy credentials and compromise an organisation for less than the price of a cup of coffee," Raj notes. "If criminals don't know how to build malware, there's malware-as-a-service available for about $250. Essentially, you don't need any technical skills at all to be a cybercriminal, all you need is a means to pay."
🎭 Deepfakes: The Threat Raj Finds Genuinely Frightening
When the conversation turns to AI, Raj doesn't hide his concern. "The use of deepfakes is something that utterly scares me," he admits, pointing to real cases where executives were deceived on calls by deepfake video. "The threat is very real, and currently, there's no reliable technology to defend against it."
AI is also reshaping malware itself, enabling code that adapts and evades detection in real time. His advice is to modernize defenses in parallel, AI-driven detection, stronger training, real-time threat intelligence, without losing sight of the basics. "Why bother using AI," he asks, "when a criminal can simply exploit weak MFA controls?"
🔍 The Basics Still Decide Most Breaches
After hundreds of breach investigations; Raj is clear on one thing: sophistication rarely wins. "No matter how well prepared an organisation thinks it is, they still fall victim to breaches," he says, "often due to very basic mistakes."
Visibility tops the list, gaps like exposed services or unnecessary privileges that simply go unnoticed. Patching is another recurring failure point, with fixes delayed just long enough for attackers to slip through. Even when MFA or endpoint security exists, Raj points out it's "sometimes only partially deployed, leaving critical systems like VPNs, firewalls, and cloud services exposed."
And then there's response planning. "Many companies have plans on paper but haven't tested them under real conditions," he says — leaving basic questions like who's in charge during an incident dangerously unanswered.
🧠 What Raj Looks for in Future Cybersecurity Leaders
Certifications aren't what catch Raj's attention. "I look for individuals who are genuinely passionate about cybersecurity and have a constant desire to learn," he says. Not people who share his opinions, but people who share his drive.
That curiosity, he believes, is non-negotiable in a field that moves as fast as this one. "I don't think there's another industry that evolves as quickly as ours," he says. "That constant curiosity and commitment to growth are what make all the difference."
🤝 Treat Security as a Team Sport
Asked what he'd tell both leaders and newcomers, Raj returns to a single idea: cybersecurity only works when everyone is on board. "Cyber risk has to be collectively understood and managed by all stakeholders, from the CEO to the most junior team member," he says.
For him, transparency is what makes that possible. "If you're clear and concise about what you're doing and why from the outset, then you can not only control your organisation's narrative but ensure everyone is on board." Decentralizing security responsibility, he argues, doesn't weaken it; it's what ultimately aligns it with the business itself.


Comments