Phishing simulations for the AI era
Sep 22, 2026 · 21m
Summary
Sam and Jack from Sublime discuss their new tailored phishing simulation product, which uses real attack data to create context-specific training for Microsoft 365 and Google Workspace users. They address the surge in AI-generated phishing campaigns and the need for automated, inspectable security measures that reduce administrative burden. The conversation highlights the evolving threat landscape, including prompt injection risks and supply chain attacks, emphasizing the importance of human-in-the-loop verification. Sublime aims to help organizations defend against these sophisticated thre…
Topics discussed
Sponsor: Mosul Apple device management platform
Introduction and guest welcome
Guest roles at Sublime Security
Debate on the SSO tax in SaaS pricing
Overview of Sublime's email security platform
Host background and the shift to cloud email
Rise of AI-generated phishing and bot traffic
Sublime's strategy: speed and attack surface reduction
Launch of tailored phishing simulation product
Multimodal attacks: voice, video, and social engineering
The challenge of highly targeted and contextual attacks
Vendor impersonation and supply chain risks
Future of phishing simulations and industry trends
Sublime roadmap and GA timeline
Enterprise challenges in the age of AI adoption
Prompt injection risks and AI security concerns
Automation, inspectability, and human-in-the-loop
Closing remarks and show notes
Listen ad-free on Castria