Iyer's claim is that security's move from good-to-have to must-have has been misread as a move to generative AI. Her worked example is a file server capped at 500 downloads a day: real traffic is around 300, so an insider with valid credentials pulls 490 and the rulebook never fires — the fix is a dynamic baseline learned from the data, not a bigger model. The same logic runs through the hour. Malware masquerades as a genuine executable, so detection has to read behaviour — registry keys, boot options, exfiltration — rather than signatures. Phishing emails are no longer poorly worded, because attackers hold the same LLMs everyone else does, so defence moves to domain age, IP reputation, link topology and Latin lookalike characters. But anomaly detection and forecasting are traditional machine learning, and Iyer refuses to pay the GPU tax for them: enterprises are late movers on generative AI precisely because their data is scarce, and scarce data never offsets the compute bill. LLMs earn their place in summarisation, context and the help-desk first response; agents earn theirs by stitching monitoring, ticketing and endpoint data into a single answer. Underneath sits what a CIO is actually buying: thirteen-plus years of in-house AI research, an owned data centre, no cross-organisation model sharing, PII stripped before inference, and a data protection impact assessment written for every feature. The stakes are that the last ten points of accuracy — 85 to 94 percent — are a math problem, and no amount of hype closes them.
Worth your time if you are
CIOs still policing file servers with static thresholds
CTOs being pitched an LLM for every security problem
Enterprise buyers who must ask whose data trains the model
Compliance leads mapping GDPR, HIPAA and geography
Engineering students wondering whether the math still matters