StrongestLayer’s Alan LeFort on Personalization, Evasion and First-Seen Attacks
Artificial intelligence-generated phishing has changed the signals security teams once relied on to identify malicious email. Personalized attacks can mimic trusted senders, familiar workflows and legitimate infrastructure, making suspicious messages look routine, said Alan LeFort, co-founder and CEO of StrongestLayer.
See Also: Why Healthcare Leaders Are Rethinking Their Data Strategy Before Scaling AI
Secure email gateways were built to block attacks they had seen before, but personalized, one-off emails defeat that model entirely. Awareness training also falls short.
“Do we really believe that training Sally in accounting with a 30-minute video four times a year is going to make her smarter than the AI and the cumulative knowledge of the SOC?” LeFort said.
Effective defenses must evaluate intent, evasion and personalization together giving security teams the context needed when traditional pattern-based detection fails to keep up.
In this video interview with ISMG at Black Hat USA 2026, LeFort also discussed:
- What security leaders should ask vendors to see past agentic AI marketing hype;
- Why security leaders should measure false positives and detection outcomes when evaluating AI-powered tools;
- How email could become a command-and-control channel for AI assistants exposed to prompt injection.
LeFort leads StrongestLayer AI’s strategy to help organizations defend against AI-driven threats. He has more than 25 years of cybersecurity experience and previously held leadership roles at Proofpoint, McAfee, Intel Security and HyTrust, focusing on threat protection and insider risk.

