Home
Tech Grid
News Room
Interviews
CISO POV
Think Stack
Articles
Home | CISO POV | The Hardest Security Problem Isn’t Detection. It’s Knowing What to Trust.

The Hardest Security Problem Isn’t Detection. It’s Knowing What to Trust.

As CTO & Co-Founder, how do you balance building Trustmi’s fraud-prevention technology with securing the company’s own systems, people, and operations against the threats it helps customers address?

I think this balance is actually very simple. We automate the repetitive work, but never automate away our understanding of the system itself. Whether we’re building a product for Trustmi or securing our own systems, we focus on balancing automation and technical expertise.

At Trustmi, if my engineers are spending hours doing something a machine can do reliably, then that’s a waste of our security and engineering talent. We’d rather their deep, technical expertise focus on projects that require more mindshare. If a machine fails and nobody on the team notices what’s happening, that’s a very big problem. Someone needs to be there and able to fix it. We can’t just rely on a patch on top of a patch.

When it comes to the products we launch, this mentality stays the same. Machines do the analysis of hundreds of signals while senior experts still come in to review the underlying systems and are accountable for the major decisions.

What makes implementing cybersecurity initiatives particularly difficult today: technical complexity, integration friction, competing engineering priorities, resource constraints, or proving measurable impact?

Truthfully, I’m skeptical of AI hype. The market is full of hype, which makes choosing the right initiatives difficult.

Finding technology that works isn’t difficult in today’s market. Sifting through intense AI hype to figure out what fits our specific needs both economically and operationally – that’s a challenge. If a tool removed 60% of the work but still costs me 70% of what I was spending before, I didn’t exactly gain much.

As a CTO, I have so many things competing for my attention at once. It might be engineering priorities or existing processes that need fixing, or teams being stretched on a project – all of it demands my focus. When choosing an initiative to implement and put time into, it either has to remove work, remove risk, or prove its value right away. If none of those things are clear right out of the gate, then I can’t spend time digging through the AI hype to figure out how it will help us. That’s too much of a time suck when this industry moves a mile a minute.

When you evaluate cybersecurity vendors for Trustmi’s environment, who shapes the buying decision, what questions drive the process, and where do technical assessments meet business and operational realities?

Typically, our approach is simple: when we come across an interesting product or are looking to solve a specific challenge, we take a “live test” approach.

We focus on whether the technology solves a real operational problem, integrates well, performs reliably, and delivers measurable value within our environment. We do not rely only on demos or questionnaires; we prefer to run a POV against a real-world use case, using production-like or live scenarios whenever possible.

Another major factor is how well the product plays with what we already have. Our team prefers solutions that complement our existing stack, integrate cleanly with our tools and workflows, and avoid creating another silo to manage. The easier a product is to operationalize within our existing ecosystem, the stronger the case for adoption and the easier it is to justify the investment.

When comparing vendors, which factors receive the closest scrutiny—architecture, detection quality, explainability, integration depth, deployment effort, or operational overhead—and how do you weigh competing strengths?

Security design is the first priority. If the architecture or implementation shows weak security practices, we typically do not pursue the solution further, regardless of how strong the feature set may be.

The second priority is explainability. Black-box solutions are becoming a thing of the past, and that is a positive change. We need visibility into why a decision, alert, or outcome was generated so our teams can validate it, trust it, and act on it.

Detection quality is validated through the POV – we want to see how the product performs against real scenarios, not just benchmark results or demos.

The final and often deciding factor is the total cost of ownership. That goes beyond licensing and includes deployment effort, integration complexity, infrastructure requirements, ongoing tuning, and the operational overhead placed on the team. A product may be technically strong, but if it requires significant effort to maintain or creates additional operational burden, that weighs heavily in the decision.

How much friction are you willing to tolerate during deployment if a product delivers materially better protection? Where does “implementation complexity” become a deal-breaker?

If you’re solving an important problem, some deployment work is reasonable. Implementation complexity becomes a deal-breaker when the complexity is permanent. If we’re six months into using a new tool and our team is pouring hours of work into getting something to be successful inside our system, it doesn’t matter if it’s delivering 25% more protection than our previous tool. At that point, I now have additional complexity, labor, and a system that my team is struggling to understand. In no world is that a meaningful security improvement.

Trustmi operates where cybersecurity, fraud prevention, finance, and business operations intersect. What do conventional security approaches misunderstand about socially engineered fraud and the operational realities of preventing fraudulent payments?

Trustmi sits in a unique position because we focus on understanding intent. Modern fraud is no longer just misspelled emails or shared documents from unfamiliar names. It’s intentionally engineered to exploit familiarity, authority, and our need to trust others. Fraudsters are deploying convincing deepfake videos of the people we work with every day. In fact, 40% of employees have already said they or someone at their company has been a target of an impersonation attempt.

Typical email security systems may stop a phishing attack, but when an email is coming from a compromised vendor, that domain name is real. An inbox security tool can’t flag that. Socially engineered fraud requires you to determine what the communication is trying to persuade the recipient to do. That’s an entirely different playbook from conventional cybersecurity tools.

As Trustmi’s CTO, how do you see the company’s role within the broader cybersecurity ecosystem, and what would meaningful progress in socially engineered fraud prevention look like beyond detecting suspicious activity?

At Trustmi, we’re never trying to replace email or identity security. Our system has an entirely different job. We work to connect what happened in a company’s internal environment, across emails, documents, and ACH payments, to determine whether or not a fraudulent actor is at play. While conventional email security scans to find threats, Trustmi focuses on the intent behind every action.

As AI tools become cheaper and easier to scale, tomorrow’s trusted communications will look entirely different than today’s. An email from a known colleague, a familiar voice on the phone, or even a recognizable face on a video call will no longer be proof that someone is genuinely who they claim to be.

Fraudsters have learned to mimic legitimate business activities to pass through systems undetected. In 39% of attacks, bad actors used AI-generated documents, from invoices and W-9s to bank statements and existing email threads. Fraudsters may spend weeks inside a compromised vendor environment learning communication patterns before using AI to generate convincing documents that support their deception.

For businesses, scrutinizing whether a document is real is no longer enough. Now, companies have to track signals across a variety of communication channels to prove whether someone is behaving normally or if they have malicious intent. Attackers are incredibly sophisticated in their social engineering tactics. Trustmi’s role is to spot all of their methods and connect the dots before money ever moves.


About Eli Ben nun

Eli Ben nun is the Co-Founder and CEO of Trustmi, the leading behavioral AI platform for payment security, founded in Israel in 2021. Eli has a strong background in building scalable, AI-driven security platforms and maintains a passion for mentoring junior employees. Prior to Trustmi, Eli served as the Head of Product Management at Cynet Security, Product Manager at Bynet Data Communications, and co-founder and CEO of Shield128.

More about Eli:

About Trustmi

Trustmi is the leading behavioral AI platform for payment security, helping enterprises stop fraud and costly payment errors before money moves. As fraud increasingly arrives "pre-approved" - designed to pass existing controls - Trustmi provides a critical verification layer across the entire payment lifecycle. By correlating signals across email, vendor behavior, financial documents, and payment workflows, Trustmi detects sophisticated, socially engineered attacks that traditional security and finance controls miss. Trusted by global enterprises with complex payment environments, Trustmi protects over $240 billion in payments annually and has helped prevent more than $1 billion in fraud and $5 billion in payment errors. Founded in 2021, Trustmi is headquartered in New York City and backed by leading investors, including Cyberstarts and Insight Partners.

For more information, visit trustmi.ai.

Cybersecurity CISO Fraud Prevention Cyber Risk Security Leadership AI Digital Trust Social Engineering