Category: Whisper Report

  • Whisper Report: What’s the biggest AI risk in HR no one talks about?

    Whisper Report: What’s the biggest AI risk in HR no one talks about?

    Published to clients: November 28, 2025                 ID: TBW2098

    Published to Readers: December 1, 2025

    Public Release Date: April 13, 2026

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract

    This Whisper Report reveals nine overlooked AI risks in HR—from loss of human connection and identity challenges to compliance, data quality, and black-box concerns. Insights from HRTech2025 experts stress the need for ethical design, integrated systems, and AI literacy to safeguard trust and organizational resilience.

    Target Audience Titles:

    • Chief Human Resources Officer (CHRO), Chief People Officer (CPO), Chief Technology Officer (CTO), Chief Information Officer (CIO), Chief Data & Analytics Officer (CDAO)
    • VP of HR Technology, VP of Talent Management, Director of HRIS (Human Resource Information Systems), Director of Data Privacy & Compliance
    • HR Technology Manager, HRIS Analyst, Data Scientist (HR Analytics), AI Ethics Specialist

    Key Takeaways

    • Keep humans in HR: Overreliance on AI erodes trust and relationships—HR must preserve human touchpoints for employee engagement.
    • Protect identity and ethics: AI adoption impacts employee identity; embed responsible AI design and ethical standards from the start.
    • Secure and integrate systems: Data security lapses and fragmented AI tools increase risk—prioritize compliance and cohesive integration.
    • Invest in AI literacy: Lack of training leads to misuse; HR teams need prompt engineering and clear goals for effective AI use. 

    What’s the biggest AI risk in HR no one talks about?

    We took the most frequently asked and most urgent technology questions straight to the human resource technology professionals gathering at HRTECH2025 held in Las Vegas. This Whisper Report addresses the question regarding the biggest AI risk in HR no one talks about? Figure 1 displays the nine risks we will now discuss.

    Figure 1. Nine Hidden AI risks in HR No One Talks About

    1.      Loss of Human Connection & Trust

    Human resources is all about managing the employees of an organization. It is one of the most critical relationships an organization has. Fountain’s Bastian Botella raises one very concerning risk. “It’s the loss of trust between employees and the company. AI is all over right anywhere from the hiring phase down to retention communication tools everywhere. Okay. At some point and I think it’s going to be sooner rather than later all employees will figure out that the human has been removed from all processes. Removed from interviews, removed from communication, removed from any touch points that they have with their employer.” BambooHR’s Paul Swenson is on the same page. “I see in HR is the over reliance on AI. HR is all about people, right? Like interacting with people and AI can sometimes pull you away from that. So HR needs to stay close to the people. Build relationships with the people that they work with in their companies. But sometimes I think an over reliance on AI can lead to people not doing as much of that which is really the bread and butter of what HR is good at and what they excel at. Right? So as we use AI we need to make sure that we’re you know remaining consistent with our relationships with the people at our companies and providing great employee experiences for our people.” In other words, let’s keeps the humans in humans resource management!

    2.      Identity & Psychological Impact

    HRTech2025’s opening keynote speaker, FranklinCovey Leadership’s Patrick Leddin observed, “a lot of people in the organization find a lot of value in the work they’re doing. It isn’t just about replacing a task and giving somebody a new task or saying this is going to be something that generative AI is going to do and you you’ll be able to do more analysis. It’s recognizing that people’s sense of self is often times connected to their work and if you take that away from them, how are you going to help them find their new identity?” Given that one of the first questions a stranger asks outside of your name is your profession, it is easy to understand how one’s profession is tied to one’s identity. What is a software engineer who no longer writes code but monitors the AI writing code?  

    3.      Identity Responsible AI & Design Standards

    Our next risk came from Eightfold AI’s Michael Dunne. “Great concern that should be attention given to is responsible AI by design.” Many of the critical aspects of a solution need to be thought of from the very beginning. TBW Advisors LLC repeatedly reminds one that security, privacy, and accessibility cannot be an afterthought. Ethical AI is right in the center and a critical part of the predesign work. Michael continued, “You having this bloom of hype around AI and the possibilities. There’s a lot of excitement but one is always take into account then how was this system built from the start and so what I like to say is people should look at their providers and see has this been done by design which means have they done understandings about managing the data what’s called feature sets and how it goes in for recommendations also understand whether the right certifications have been done around data privacy data residency and controls around the use of AI. One is for developing applications being consumers of applications and the use of that data. And you’ll see that now with a number of standards that have come out a lot of people pay attention about the EU AI act. There’s also ISO 420001.” Thus the organization’s ethical stance on how to use the data and AI should be defined in conjunction with your security and privacy policies.

    4.      Data Security & Compliance Risks

    With AI comes a lot of data and information. Darwinbox’s Eli Kameron warns that, “people are sending their data all over the place without even thinking about security. This was a problem already with APIs and it is going to explode with agentic AI particularly folks using MCP protocol servers. So a lot of folks are not thinking about the risks and the compliance risks that they are exposing themselves to when they send data everywhere.” Just because it will take your data, doesn’t mean you should be sharing it with the application. Even lower tiered paid models do not provide the privacy expected by many enterprises.

    5.      Fragmented & Siloed AI Systems

    Risk number five comes to us from Benifex’s Joe Sears. “All these different AI agents out there with different functionality. But each of these companies has their own thing that they’re doing and we need to keep that message joined up and all of the different AI needs to talk to one another. If we can integrate our AI capabilities with the wider AI capabilities that are going on, then that’s going to be that best experience for the employee.” In other words, much like what we saw with commercial UAV’s in the enterprise, AI systems are popping up by function within organizations. Enterprises should take a cohesive desired solutions approach to achieve the best ROI with their AI investments. If AI and your data is becoming siloed in your organization, be sure to schedule your inquiry with your TBW Advisors LLC’s analyst. We can provide you guidance based on first hand experience that is sure to make the difference even is the work is outsourced.

    6.      Liability & Legal Risk from Misuse

    One concerning risk was highlighted by Paychex’s Nathan Shapiro. “Over reliance on AI and even furthermore folks outside HR trying to practice because lacking the expertise can lead to dangerous things. The democratization of AI and the proliferation is fantastic and is going to really change the way we work. But lacking that expertise can run you into some significant challenges and liability. Just think about asking AI for guidance on a termination scenario with an employee and lacking the expertise to know that their age is really critical for discrimination law. What jurisdiction is going to rule on that and the liability it could create?” As long as worker’s have rights and the AI isn’t training on the complexities and nuances of those rights, it may be best to keep seasoned professionals as the humans in the loop!

    7.      Lack of AI Literacy & Training

    A tool is only useful if it is used and used properly. As Attensi’s Joanna Akar denoted, a huge risk in, “AI is actually not having the knowledge on how to use it. If you don’t know how to prompt engineer or use AI or Gen AI or whatever type of AI you’re using within your day-to-day. If we fall

    you risk not being able to follow the trend, not being able to be more efficient within the learning environment. So, it’s super important that HR people are trained in how to prompt AI or prompt engineering to make sure that they’re utilizing it in the best way possible to get the most return on investment that they can get out of their people.” Lollipop’s Jonathan Ferrell shared very similar concerns. “Lack of understanding on what AI is and what it isn’t. I think a lot of people recognize how quickly it’s able to solve immediate tasks and maybe make it feel like it’s a more complex task, but what really matters is what you’re trying to accomplish. And if you don’t know upfront what you’re trying to accomplish, you could really go in the wrong direction.” Thus to minimize this risk, start with the problem and learn how to communicate with the specific AI you are using for best results!

    8.      Data Quality & Model Reliability

    One Model’s Phil Schrader reports our next risk. “Data quality. The AI is going to be able to answer questions in new ways for organizations. But if you don’t have a quality data model to feed into it or quality reliable tools for it to use, it is going to generate noise, it is going to generate nonsense that actually moves you backward.” Or as previously highlighted in Whisper Report: What are the biggest challenges of Using Gen AI in Logistics?, you put garbage data in you get garbage out. Without quality data, it is not possible to get reliable answers.

    9.      AI is a black box

    The final risk should come as no surprise from anyone but is always important to remember. Aptia USA’s Jeff Williams reminds all, “AI is a black box the way it’s permeating everything we do on an everyday basis. And think about how little each of us really understand about what AI is, how it’s generating the answers it’s generating, and the advice it’s dispensing, and the actions that are being taken as a result. I think the fact that we are lumping AI together for things as simple as a chatbot and things as complex as fully generative large language models. I think kind of lumping all that together, calling it AI and expecting to solve all of our problems without really knowing what’s feeding it underneath, I think is a big un-discussed risk that we really need to address.” Clients will recall a similar warning arrived in Whisper Report: What’s the biggest Cybersecurity Myth in 2025? One of the biggest requirements to shine the light on the black boxes are logs. Let’s make 2026 the year all AI systems are required to provide immutable logs.

    Related playlists and Publications

    1. Playlist for Whisper Report: What’s the biggest AI risk in HR no one talks about?
    2. Playlist for Whisper Report: How should CTOs rethink org design with GenAI?
    3. Playlist for Whisper Report: What HR tech trend will disrupt engineering hiring next?
    4. Conference Whispers: HR Tech 2025
    5. Whisper Report: What are the biggest challenges of using generative AI in logistics? – TBW ADVISORS LLC
    6. Whisper Report: What’s the biggest cybersecurity myth in 2025? – TBW ADVISORS LLC

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2026 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, Whisper Club, Whispers, The Answer is always in the Whispers, Vegas Convention Library, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: What’s one casino innovation you wish existed today?

    Whisper Report: What’s one casino innovation you wish existed today?

    Published to clients: November 20, 2025                           ID: TBW2107

    Published to Readers: November 21, 2025

    Whisper Email Release:

    Public Release Date:

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract:

    “This Whisper Report explores the most desired casino innovations identified at G2E 2025. Industry experts highlighted two key areas: operational improvements for casinos—such as seamless system integration and cross-platform play—and enhanced player experiences through biometric authentication, personalized VIP services, and engagement strategies. These insights reveal opportunities for transformation and differentiation in gaming technology.”

    Target Audience Titles:

    • Chief Information Officer (CIO), Chief Operations Officer (COO), Vice President of Gaming Technology
    • Chief Data Officer, Chief Technology Officer, VP of Gaming Technology, Director of Gaming Technology, Chief AI Officer
    • Casino Systems Engineer, Gaming Platform Developer, Security & Compliance Analyst

    Key Takeaways

    • Casino operators want seamless integration across systems, from cage operations to ERP, eliminating manual QA and enabling true plug-and-play functionality.
    • Cross-platform gaming—switching between land-based and online play without disruption—is a top innovation priority for industry leaders.
    • Biometric authentication is seen as critical for secure, personalized player experiences and streamlined identity verification.
    • Personalized VIP experiences for mid-tier players, including concierge-style services, could transform engagement and loyalty in casinos.

    What’s one casino innovation you wish existed today?

    We took the most frequently asked and most urgent technology questions straight to the operation engineers and technology professionals gathering at the Global Gaming Expo held in Las Vegas better known as G2E 2025. This Whisper Report addresses the question regarding one casino innovation you wish existed today? The innovations are divided into two categories. First those focused on the casino itself and second those focused on the player experiences as depicted in Figure 1.

    For Casinos

    The first group of desired technology applies to the casinos themselves. CCT’s Wanor Franca’s focus is on the money trail. “It’s the ability to track your cage operations all the way through a revenue audit into your ERP. No solution is connecting all the data sources.” This integration issue is a common issue as Druvstar’s Melissa Aarskaug highlighted, “One innovation I wish the industry had was simple integration. Everything was plug and play and as soon as it was in implemented, it just worked. We didn’t have to do any QA testing. It just plugs and plays.” Diving in further, Incisor’s Aaron Jones highlighted, “seamless play between playing a land-based game and being able to play that game online.” Sounds like the entire industry could use a significant transformation and standardization. TBW Advisors LLC provides significant first-hand experience on digital transformation so be sure to schedule your inquiries if those integrations are bogging you down.

    For the players

    Attendees at G2E also had ideas of much wanted technology innovations that directly affect players. For one, Seon’s Matt DeLauro believes, “A casino innovation that I wish existed today would be more biometric authentication for players.” Additional research concerning biometric identification and authentication can be located in our coverage of ISC West and Identiverse.

    Once the casino knows who the player is through advanced biometric authentication, Relay’s Chris Chuang believes more players could feel special. “I feel like uh there was a way that casinos could use technology to really bring the VIP experience to every gamer, right? People want to come to Vegas and feel like a VIP. Of course, they have that for the high rollers, but how do you personalize a VIP experience for the pre high rollers who are not quite there but maybe on their way.” But what exactly would that look like? Chris continues, “I think that that would involve different ways to welcome guests to make the check-in experiences more lux and personal. Maybe a personal concierge.” A personal concierge. Looks like Continent 8 Technologies’ Justin Cosnett was on the same page. “Making sure that players don’t have a bad experience. Yes, they’re going to lose money over the longtime lifetime, but the worst thing you could possibly see is players who will come, they’ll try a game for the first time or try a website for the first time, and if their experience is all loss very quickly over a short period of time. The thing that needs to really happen is people’s back offices making sure that players can actually enjoy themselves over a longer period of time rather than being short sharp .” Of course if you are going to dream of the idea casino innovation Plotline’s Erik Regan said what we are all truly thinking. “What’s one casino innovation you wish existed today? Unlimited free play!” That’s right unlimited free play – if you are going to dream – why not dream big!

    Related playlists and Publication

    1. Whisper Report: What’s the next gaming tech that will change how we play?
    2. Whisper Report: What’s one casino innovation you wish existed today?
    3. Whisper Report: What’s the biggest risk in iGaming no one’s talking about?
    4. Whisper Report: What’s the best part about attending G2E live in Vegas?
    5. Conference Whispers: G2E 2025

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    Downloading, re-uploading, or redistributing this file is not permitted under any license.


    ©2019-2026 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, Whisper Club, and One Change a Month, Vegas Convention Library; Leading Professionals, Real Questions, Real Time, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: What’s the biggest UAV threat CIOs aren’t ready for?

    Whisper Report: What’s the biggest UAV threat CIOs aren’t ready for?

    Published to clients: October 27, 2025                                     ID: TBW2094

    Published to Readers: October 28, 2025

    Whisper Email Release: TBD

    Public/Video Release: TBD

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract

    This Whisper Report investigates the biggest UAV threat CIO’s are not ready for. CIOs are underestimating the scale and urgency of UAV-related risks. From electric infrastructure and jamming threats to data overload and geopolitical embargoes, this Whisper Report captures the 10 most pressing vulnerabilities revealed at CUAV Expo 2025 — and what enterprise leaders must do next.

    Target Audience Titles:

    • Chief Information Officer, Chief Technology Officer, Chief Information Security Officer, Chief Architect, Chief Data Officer, Chief Product Officer, Chief Experience Officer
    • VP Infrastructure, VP Security Operations, VP Data Strategy, Director of Physical Security, Director of Edge Computing, Director of OT Security
    • Red Team Lead, Incident Response Lead, Security Architects, DevSecOps Engineers, IAM Engineers, Penetration Tester  

    Key Takeaways

    • Impending bans on Chinese UAVs and rising tariffs are forcing urgent supply chain pivots.
    • Electric and communications infrastructure gaps are exposing UAV fleets to operational and security risks, especially in GPS-denied environments.
    • Most enterprises lack formal flight departments, leaving safety, training, and compliance dangerously underdeveloped.
    • Data volume and interoperability challenges are overwhelming existing IT systems, requiring new cloud and API strategies.
    • CIOs must prepare for regulatory volatility, secure delivery protocols, and the full replacement of helicopters in logistics.


    What’s the biggest UAV threat CIOs aren’t ready for?

    We took the most frequently asked and most urgent technology questions straight to the commercial UAV professionals gathering at Commercial UAV Expo 2025 held in Las Vegas. This Whisper Report addresses the question regarding what’s the biggest UAV threat that Chief Information Officers are not ready for? Figure 1 contains an image of the 10 UAV Threats that CIO’s aren’t ready for.

    1.      Embargo Risk

    The first threat was the absolute talk of the show held in Las Vegas. As GEODNET’s Amr Elkordy observed, “most people don’t realize that with the bill that passed last year, DJI might be fully banned from the US.” Or as Frontier Precision’s Wyatt Robbins shared there is a, “potential shift away from Chinese manufactured drones.” Of course, once they hit expo hall and spoke to distributors they learned the truth about their fleet. This created a flurry of activity as Wyatt went on to further explain, “companies and government agencies trying to find alternatives to maybe a DJI system or other Chinese manufacturing systems that they’re already currently buying.“

    2.      Import Costs

    If your organization still wants to purchase drones from the Asian region, you may be artificially scared off by the Tariffs. IPET’s Joy Jiang is there for you. “Tariff strategies. We are an Asian company. Our products to some company like the North American or the Europe we still have some strategies about the tariff.” In other words, don’t assume anything about the impact to cost of their products based on the Tariffs. Rather speak with those deep in the details of the manufacturers before ruling out those manufacturers. Time will tell if they will be allowed in the future US or European airspace.  

    3.      Power Burden

    Our 3rd UAV threat arriving at our organizations’ Chief Information Officer’s door comes from Sarah Abdi at Parallel Flight Technologies. “The infrastructure that is required with all electric platforms.” Intrigued, let’s hear more! “ So if you have a remote logistics application for an application and you have an electric platform, you have to have your generator, you have to have fuel to power your generator, you have to have extra batteries on hand, which actually are extremely heavy. There’s a whole lot of infrastructure required with all electric platforms, which is why we’ve taken an approach of parallel hybrid. Um, all you need is a gas tank and you refuel this aircraft and you’re back up and running.” Thus hybrid drones share the same benefits many are familiar with in hybrid cars.

    4.      Jamming Risks

    UAV’s require communication. It tells them where the controller wants them to go, it is used to send information back. It underlies the very purpose the drone was flown to begin with in many use cases.

    As Teal.io’s Robb Monkman observed, our next threat is all about the, “invisible threat of connectivity.” Robb further explained, “more recently, people are starting to talk about the need for redundancy and failover.” TUALCOM’s Nicolas Speroni was more specific. “I believe the biggest threat is jamming. And then if a UAV needs to go through a totally GPS denied environment, TUALCOM USA has solutions for both of those and the anti-jamming and terrestrial navigation products.” For additional methods of handling GPS Denial see Conference Whispers: CUAV 2025.

    5.      Ops Gaps

    Threat number 5 comes with an alert from USI’s Brad Tucker. “If you have a fleet of drones, you have a flight department.” That’s right. The only question is if you recognize and organize it. Brad continued, “that may not be something that is fully embraced as of yet, it needs to be pretty quickly, especially with the release of 108, obviously that’s going to be coming within the next 12 to 24 months. More than likely part 108 is coming in the next 12 months. So that means you have to be prepared for obviously safety protocols. You have to be prepared for training your workforce and certifying your workforce with the appropriate credentials.”

    6.      Legacy Disruption

    Now you have your flight department. Perhaps you organized your drone related employees with your Helicopter Pilots. Federico di Napoli from FlyingBaket has an update for you. “CIOS are not ready to hear about the drone is to the moment when the drone will completely substitute the helicopter for transport materials.” That is correct. For non-human cargo, the go forward solution is the simpler drone regardless of your cargo weight. So before that next expensive mechanical update to your helicopter – you may want to re-evaluate if that is the best solution based on current technology available via drones. Heavy cargo even for long periods of time is now possible. For additional information on the variety of commercial drones now available see Conference Whispers: CUAV Expo.

    7.      Secure Delivery

    Removing the human in the helicopter to send cargo can create some complexities with certain cargo. blueflite’s Ross Davis brings our next threat. “chain of custody in drone delivery”. Interesting! Let’s hear more about this challenge from Ross. “Imagine if you have a really high value item such as prescription medication or perhaps like organ. When that’s delivered to a hospital or to a patient, we need to make sure that that person is actually receiving  the person we intend to receive the object is the person who’s picked it up. So, you know, as how we address that is through scanning, QR codes, and authentication on the phone to make sure that that person is who they say they are. We could do facial recognition on the phone to basically sign into their account and we take ownership of that package.” Thus even a drone solution can require an advanced identity and access management solution to authenticate recipients and ensure proper, secure, operations. For additional research on identity and access management, see Conference Whispers: Identiverse.

    8.      Data Overload

    Aloft’s Kevin Teen highlighted one of the most overwhelming threats. “the amount of data. All the different data points.” Kevin continued to provide context, “One drone flight, you’re producing four frames a second for as long as that drone’s in the air, altitude, speed, heading, hundreds of different variables. Once you start scaling that across dozens, hundreds of pilots now include videos that we’re taking. now include survey photos. You can just imagine the scale of the data and so dealing with different buckets you know whether that’s in SharePoint or S3 and now all we have disconnected processes.” But it is not just about collecting the data as Buzz Solutions Kaitlyn Albertoli emphasized. “Once we start to scale it and embed it more into the workflows, I don’t think utilities are ready for how much that data is going to be an impact to them. But it’s an exciting problem to have.” If you find yourself overwhelmed by all the data or lost in a data silo situation, be sure to schedule an inquiry with your analyst at TBW Advisors LLC. Having advised over 1100 organizations on their transformation, We have dealt with data volumes as large as zettabytes per day. 

    9.      Systems Sync

    Central UAS’ Bill Reynolds contends that the largest threat, “is the demand for interoperability and integration with uh APIs for the massive amount of data exchange between the unmanned aircraft and the applications and the grower and farmer.” Having just been warned about the volume of data, the last thing a CIO and their team want to be concerned with is the interoperability of all the systems. This is a call to the CUAV industry to ensure standardization where possible and appropriate.  

    10.  Policy Shifts

    We will conclude with threat 10 and the other most talked about topic at CUAV Expo held in fabulous Las Vegas. Pelican Wire’s Frank Balsamo revealed threat number ten as, “the changing regulations in the environment that are out there from country to country.” While many are fretting FAA proposed Part 108, USA is only one country in a web of regulations. Frank went on further to explain, “as the technology evolves and becomes more available in the public to see how that plays out. in real time. So, I think as a business case, that’s going to be very interesting to watch.” In other words, it’s a nascent industry and the regulations are in the name of safety. Safe operations builds trust and helps the industry to expand. Helping the UAV industry expand is something everyone’s interest at the Commercial UAV Expo.

    Related playlists and Publications

    1. Playlist for Whisper Report: What’s the biggest UAV threat CIOs aren’t ready for?
    2. Conference Whispers: Commercial UAV Expo
    3. Conference Whispers: Identiverse

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    Downloading, re-uploading, or redistributing this file is not permitted under any license.


    Downloading, re-uploading, or redistributing this file is not permitted under any license.


    ©2019-2026 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, Whisper Club, and One Change a Month, Vegas Convention Library; Leading Professionals, Real Questions, Real Time, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: How can we leverage the creator economy to drive business growth?

    Whisper Report: How can we leverage the creator economy to drive business growth?

    Published to clients: September 29, 2025                    ID: TBW2087

    Published to Readers: September 30, 2025

    Published to Email Whispers: TBD

    Public and Video Release: TBD

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract:

    “The creator economy is no longer a niche—it’s a strategic force reshaping media, marketing, and consumer expectations. This report explores how businesses can partner with creators to unlock scalable engagement, rival traditional media in quality and speed, and adapt to a market where authenticity and agility win. Insights from NAB Show 2025 reveal why enabling creators isn’t optional—it’s essential.  “

    Target Audience Titles

    • Chief Data Officer, Chief Marketing Officer, Chief Content Officer, Chief Data Officer
    • Chief Technology Officer, Chief Digital Officer,
    • Head of AI/ML for Media or Marketing, Data Scientists, Creator Partnerships Manager, Director of Content Strategy,
    • Product Managers, Content Managers

    Key Takeaways

    • Creators connect directly with consumers, offering scalable, intimate interactions.
    • Businesses must support creators with tools, partnerships, and infrastructure.
    • Creators rival traditional media in quality, speed, and production scale.
    • The creator economy is reshaping media and consumer expectations.
    this doc is strategic not technically deep

    How can we leverage the creator economy to drive business growth?

    We took the most frequently asked and most urgent technology questions straight to the Technologists gathering at NAB Show 2025 held in Las Vegas, Nevada. This Whisper Report addresses the question regarding how can we leverage the creator economy to drive business growth? As Latakoo’s Jade Kurian  shared, “every single person out there is a content creator right and they all want to be able to take their content in put it one place and do the editing do the transfers do the transcoding.” With all these creators, a shift is coming. As Strada’s Michael Cioni observed, “the creator economy is actually the economy we should be we’re following them now we should emulate.” Figure 1 depicts the four levers of the Creator Economy that we will now dive into.

    Four levels of Creator Economy 1. Direct Audience Engagement 2. Business Enablement 3. Scale and Speed 4. Market Shift

    Direct Audience Organic Engagement

    Creators connect directly with consumers, offering scalable, intimate interactions. As DeepDub’s Oz Krakowski noted, “I think that in a world of creator economy where independent creators have a direct reach to the consumers ignoring that part of the business is a big mistake.” TightRope Dana Healy argued, “we still need to tie these new technologies to stories and creators are really good at telling stories.” Not only are they great at telling stories, but as LucidLink’s Gergana Berman reported, “we really think that the voices of individual creators and independent creators are really the trusted voices out there.” This trusted, storytelling capabilities with a direct reach results in, as Oz Krakowski observed, “unique product that very unique IP where they can reach different types of audiences and the ability to interact to have that level of interaction that is sometimes very intimate with their audiences is extremely scalable.” In conclusion per Tightrope’s Dana Healy, “the creator economy is still very valuable in the organic reach.”

    Business Collaboration & Enablement

    Businesses must support creators with tools, partnerships, and infrastructure. There is a critical question all media vendors should be asking themselves, according to Axle.ai’s Sam Bogoch. “How can we enable them to make better content and how can we help them repurpose and retarget that content better.” Latakoo’s Jade Kurian noted, “creator economy to drive business growth for us it’s really about giving creators on one-stop shopping.” Catering to the creator economy is valuable for as Strada’s Michael Cioni proposed, “they are effectively bigger than professional media and entertainment and so what we need to understand is that consumer tastes have changed and what we have been protecting through our history and traditions for a long time is no longer as relevant.” Finally, and perhaps most critical, Cinnafilm’s Dom Jackson contended, “other piece is that we have to adjust to the way that those people do business we have to make sure that our cost models match their revenue models so that we can make a compelling case that we are tools that fit with their businesses.”

    Scale, Speed, and Professionalism

    Creators rival traditional media in quality, speed, and production scale. Ross’s David Green emphasized, “The truth of the matter is some of these creators are just doing incredible things and their production quality is sometimes better than those of us who think that we’re the you know the you know the enterprise class content professionals. And when you when you look at some of the biggest content creators in the world they’re truly innovating in terms of how they’re creating this amazing content doing it flexibly doing it fast doing it on the run doing it efficiently.” David was not alone in sharing his enthusiasm for the creator economies scale. Per Dell’s Tom Burns, “size of the creator economy dwarfs what we have thought of for the last 100 years as episodic and feature production pipelines.”

    Strategic Imperative & Market Shift

    The creator economy is reshaping media and consumer expectations. DeepDub’s Oz Krakowski declares companies must collaborate with content creators, “companies and businesses have to do this in order to cannot basically cannot ignore it.” And why would you ignore it for as Axle.ai’s Sam Bogoch asserted, “the creator economy is the biggest growth area in media right now and not just the official creator economy but also things like user generated content for marketing purposes.” And there is a very good reason creator content is growing. Per Strada’s Michael Cioni, “we have to get over that and meet them where they are because the next generation of consumers 10 and 20 years from now will not be going to see movies in theaters they’re not going to watch traditional broadcast television.”

    Related playlists

    1. Whisper Report: How can AI and machine learning transform media and entertainment?
    2. Conference Whispers: NAB Show 2025 Playlist
    3. Conference Whispers: NAB Show 2025 – TBW ADVISORS LLC

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2025 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, The Answer is always in the Whispers, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: How can we build and maintain consumer trust in Fintech solutions?

    Whisper Report: How can we build and maintain consumer trust in Fintech solutions?

    Published to clients: September 9, 2025                           ID: TBW2068

    Published to Readers: September 10, 2025

    Published to Email Whispers: TBD

    Published Publicly with Video: TBD

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract:

    “Trust in fintech isn’t just about compliance—it’s a multi-dimensional strategy. This report explores how transparency, privacy, and strong identity verification shape consumer confidence. Insights from Fintech Meetup 2025 reveal how leading firms are navigating open banking, fraud prevention, and data ethics to earn and retain trust. If trust is your brand’s currency, this report is your blueprint. “

    How can we build and maintain consumer trust in Fintech solutions??

    We took the most frequently asked and most urgent technology questions straight to the Fintech experts gathering at Fintech Meetup 2025. This Whisper Report addresses the question regarding how can we build and maintain consumer trust in fintech solutions? Trust is difficult to get and easy to lose. Trust is also one of those elements that frequently goes by other names.

    Four Pillars of Trust
1. Compliance
2. Transparency
3. Privacy
4. Strong Identity

    Figure 1. Four Pillars of Trust

    1.      Trust = compliance

    Trust comes in many forms and dimensions. Any single dimension is broken and your trust with your customers may be broken. The first and most basic step you can take was best stated by SecurityMetrics’ Matt Cowart, “being able to show your customers that you are not only compliant but you are up to date on what is out there.” If you are Fintech you have industry specific regulations. If you want to maintain trust, be sure to publicly state that you meet the regulations. This statement could be a simply logo on your website. However, many organizations find it valuable to not only state that they are compliant – as required but they go above and beyond. Frequently, they will reiterate they importance they place on maintaining their compliance and yes – your trust.

    2.      Trust = transparency

    The first dimension we explore is trust equals transparency. As Aries Fraud Solutions’ Lon Varns simply stated, “their solution does what it’s supposed to do. If you say you’re going to stop fraud you better stop fraud.” Furthermore, you should not do more than you said particularly when it comes to their data! Trustly’s Ross McFerrin put it, “it’s critical that that consumers understand that when they’re sharing their information by open banking we’re not accessing their information for any other reason than what they wish to do with that.” This transparency with data trust issue is not going to get any smaller. In fact, as Prove’s Zachary Finesilver put it, “as open banking becomes more important and our data becomes more accessible, how do we actually persist that trust among our ..  consumers.“ Once again, the answer is transparency. “When breaches do happen and being able to be on top of that if a breach were to occur being able to get in front  of that and be very transparent with those that were affected. That would help retain as much trust as possible,” Mathew Coward, SecurityMetrics.

    3.      Trust = privacy

    While it would be easy to say it goes without saying it, but we are going to say it anyway. Trust means privacy. Trust is not just about transparency about what you will do and notification when you fail, it is about maintaining and protecting customer’s privacy. One of the best ways to do that was shared by Trustly’s Ross McFerrin, “we ensure that we keep consumer privacy top of mind.”

    4.      Trust = strong identity

    If trust requires privacy, privacy requires strong identity. To protect a consumer’s information, a company must first ensure they are interfacing with the customer not an impostor during interactions. The technology to achieve these falls under the domain of Identity and Access Management or IAM. As Intellicheck’s Chris Meyer pointed out, “the biggest challenge right now that consumers face is the layer of friction that’s being added for that process to verify are they who they say they are.” We are all consumers in one aspect of our life. Let’s be honest, who wants to verify who you are 10 times every time you interact with a company? I sure don’t! After the first time or two, doesn’t it start to feel more like the company is incompetent as opposed to doing a great job verifying it’s you? One interesting identity solution leverages phone intelligence and complex algorithms about how you use your phone to understand if it is really you. As Prove’s Zachary Finesilver shared, “we’re tying that identity to a phone number we’re persisting that identity and making sure that we’re checking for major fraud vectors like has this phone been Sim swapped. Has it (the number) been ported? And a lot of other fraud vectors to make sure that your customer base is indeed the people are who they say they are.” See Conference Whispers: Identiverse 2024 and stay tuned for our coverage in 2025 for additional research on identity.

    *When vendors’ names or quotes are shared as examples in this document, it is to provide a concrete example of what was on display at the conference or what we heard doing our research, not an evaluation or recommendation. Evaluation and recommendation of these vendors are beyond the scope of this specific research document.  

    Related playlists

    1. Whisper Report: How can AI be effectively integrated into healthcare systems?
    2. Conference Whispers: HIMSS 2025

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2026 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, Whisper Club, Whispers, The Answer is always in the Whispers, Vegas Convention Library, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: How can telemedicine be optimized to improve patient care?

    Whisper Report: How can telemedicine be optimized to improve patient care?

    Published to clients: September 2, 2025                              ID: TBW2064

    Published to Readers: September 3, 2025

    Published to Email Whispers: October 27, 2025

    Public with Video Edition:  October 27, 2025

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract

    This report explores how telemedicine is evolving beyond convenience to deliver deeper, more personalized care. From AI-powered test result interpretation to seamless appointment coordination and continuity across care settings, experts at HIMSS25 reveal how digital tools are reshaping the patient journey. Discover how telemedicine can close access gaps, enhance understanding, and support long-term health outcomes—if systems are designed with the full patient lifecycle in mind.

    Target Audience Titles:

    • Chief Information Officer, Chief Medical Officer, Chief Data Officer, Chief Digital Officer, Chief Innovation Officer, Chief Patient Officer
    • Clinical Informatics Specialists, Telehealth program manager, Health IT Architect, Clinical Data Analyst, Biomedical Engineer, AI/ML Engineer (Health Focus), Patient Engagement Strategists, Virtual Care Coordinator

    Key Takeaways

    • AI-enhanced telemedicine can streamline appointment booking, interpret test results, and personalize care recommendations—improving speed, clarity, and access for patients.
    • Continuity of care is the next frontier—integrating telemedicine across acute, post-acute, and home health settings to support the full patient journey.
    • Access equity improves when telemedicine includes specialists and reaches underserved populations, addressing socioeconomic and geographic barriers.
    • Patient understanding is amplified when generative AI explains results and next steps in context, reducing confusion and improving engagement.
    Strategy of 4, technical depth of 2


    How can telemedicine be optimized to improve patient care??

    We took the most frequently asked and most urgent technology questions straight to the health systems technology experts gathering at the Healthcare Information and Management Systems Society (HIMSS) 2025 Global Health Conference and Exhibition or HIMSS25 for short. This Whisper Report addresses the question regarding how can telemedicine be optimized to improve patient care? Figure 1 depicts two patient care optimizations one can expects from telemedicine.

    Two benefits of Telemedicine
1. Patient Experience
2. Continuity of Care

    Patient Experience

    The first benefit many expect to experience with telemedicine is the patient experience. For example, when getting test results, AI can be leveraged for the benefit of the patient to find a doctor. As Aisera’s Daniel Caravajal suggest, “I get my test results it can recommend me doctor that’s specific on that area right and it can book the appointment right it can coordinate the calendars and basically made that experience a lot faster a lot seamless and easier to kind of interact with.” Caravajal further suggests AI can help the patient understand the results. “let’s say you get your test results. We can analyze them and give you suggestions that is the unique part about a genetic AI is not only delivering a unique use case but it’s also understanding the situation. It’s understanding the intent and making further suggestions.” Valuable to note that it is always best to confirm any such information with your actual practitioner! MinttiHealth’s Xiaoqian Zou suggests telemedicine technology can, “give everyone access to the easy health care solution and service.”

    Continuity of Care

    A critical part of the patient experience that also affects the medical care is that of continuity of care.

    As Alexander Group’s Tray Chamberlin advised, “what we think is probably the next evolution in tele medicine is that continuity of care where you’re really thinking about a patient across the entire life cycle be it acute to Post Acute to maybe even home health and integrating that tele medicine it more so that the date and Records can still communicate and we understand the holistic patient Journey.” The significant benefit of telemedicine as Chamberlin further observed, “we’re also meeting the patient where they are and so you know the inclusion of specialists in telemedicine certainly just from a socioeconomic perspective getting access to the right populations that traditionally maybe don’t have access.” For additional background on the benefits and current state of telemedicine, see the Press Conference for OnMed from CES.

    Related playlists

    1. Whisper Report: How can AI be effectively integrated into healthcare systems?
    2. Conference Whispers: HIMSS 2025
    3. OnMed Press Conference

    *When vendors’ names or quotes are shared as examples in this document, it is to provide a concrete example of what was on display at the conference or what we heard doing our research, not an evaluation or recommendation. Evaluation and recommendation of these vendors are beyond the scope of this specific research document.  

    TBW Advisors LLC Logo

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2025 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, The Answer is always in the Whispers, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: Can generative AI prevent supply chain disruptions?

    Whisper Report: Can generative AI prevent supply chain disruptions?

    Published to clients: August 27, 2025                                 ID: TBW2059

    Published to Readers: August 28, 2025

    Published to Email Whispers: TBD

    Published Public with Video Edition: TBD

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract:

    “This report dives into the evolving role of generative AI in logistics, revealing how it’s reshaping visibility, communication, and adaptability across global supply chains. From forecasting weather impacts to managing labor shortages and customer-driven changes, the research explores both the promise and the limitations of AI. It also introduces a provocative challenge: should supply chains adopt disruption modeling, just as IT uses threat modeling?”

    Analysis available only to clients at this time. Join the YouTube Whisper Club at the Whisper Club Level to get access to the video edition today.


    Related playlists

    1. Whisper Report: How can we manage tariff costs in our supply chain?
    2. Conference Whispers: Manifest 2024
    3. Whisper Report: What are the biggest challenges of using generative AI in logistics?

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2025 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking , The Answer is always in the Whispers, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: What’s the biggest cybersecurity myth in 2025?

    Whisper Report: What’s the biggest cybersecurity myth in 2025?

    Whisper Report: What’s the biggest cybersecurity myth in 2025?

    Published to clients: August 19, 2025               ID: TBW2090

    Published to Readers: August 20, 2025

    Whisper Email Release: TBD

    Public and Video Release: TBD

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract:

    This Whisper Report identifies eight persistent cybersecurity myths in 2025, from the belief that threats can be fully stopped to misconceptions about AI’s role in security. Experts from Black Hat USA 2025 clarify that resilience, strategic investment, adaptive training, and human oversight remain essential. AI is powerful but not a plug-and-play solution, nor a replacement for human judgment. Understanding these myths helps organizations build more realistic, effective cybersecurity strategies.  

    What’s the biggest cybersecurity myth in 2025?

    We took the most frequently asked and most urgent technology questions straight to the Cybersecurity professionals gathering at Black Hat USA 2025 held in Las Vegas. This Whisper Report addresses the question regarding what’s the biggest cybersecurity myths in 2025? Figure 1 displays the eight cybersecurity myths we uncovered we will now discuss.

    8 myths of cybersecurity in 2025:
We can stop all threatas.
The more money you Spend, the more protected you are.
Security awareness training is dead.
AI is going to replace humans.
AI is plug and play.
AI generates secure code.
AI will solve everything.
AI will not solve issues in Cybersecurity

    MYTH 1: We can Stop all Threats

    The first myth comes from Trustmi’s Corey Sienko and is that “we can stop every single threat from entering the organization” This may come as a surprise to some executives particularly those outside of cybersecurity but the expression used is always when not if you have an incident. No Need to fret, Trustmi’s Corey Sienko continues. “It’s about how do we respond to those threats and make sure that we protect the organization from losing valuable information and cards.” I believe all appreciate that clarification. Cybersecurity involves defense but it is also a game all about preparation for when and resiliency after. This topic is further discussed in Conference Whispers: Black Hat USA 2025.

    MYTH 2: The more money you spend the more protected!

    Cymulate’s Avihai Ben Yossef brings us myth number two, “The more money you spend on cyber security the more protected you are.” Ben goes on further to explain. “I think in order to really be protected in cyber security from cyber attacks is by actually knowing what you need to do in order to make sure you are protected and when once you know that you don’t need to spend too much money you need to spend you know a very focused amount of money in what matters most.” If you are surprised by this, you really need to book an inquiry with TBW Advisors so we can help you review your cybersecurity strategy. Additional research regarding critical observations on cybersecurity spend can be found in the keynote covered within Conference Whispers: Identiverse 2024.

    MYTH 3: Security awareness training is dead!

    Cybersecurity Myth number three comes to use from Dune Security’s David DellaPelle. “Security awareness training is improving readiness and reducing risk. Security awareness training is dead.” Intrigued? Let’s hear more from David. “Security awareness training as it exists today, meaning legacy security awareness training technologies are not effective at reducing risk and create friction and an adversarial relationship between the security organization and the end users. The problem is if you think about a doctor who is looking to solve a patient’s problem, the first thing they would do is take in a lot of data and run tests to exclude the possibilities. They quantify the risk before they prescribe a medicine or a surgery. And so if there’s a security awareness training solution that doesn’t automatically provide uh user adaptation, it’s uh it’s kind of falling flat on its face. Every piece of security control or adaptation should be relevant to the individual user’s risk profile and that training or that security measure should be applied automatically based on the risk profile.” Training employees only on what that specific employee personally need to get better at? Sounds optimized.

    MYTH 4: AI Is going to replace Humans

    Bringing us cybersecurity Myth 4 is StrikeReady’s Alex Lanstein. “AI is going to replace humans.”  Alex further clarifi:ed, “AI is always going to augment humans. Anybody who’s ever leveraged any AI system, any generative AI system. You see that it makes mistakes. Sometimes those mistakes are obvious, sometimes they’re subtle. And no one is ever going to turn anything over to an AI when it’s making such obvious or subtle mistakes without a human in the loop.”  Or as Elastic Security’s James Spiteri further explained, “we’re thinking about this fully autonomous security operations team. I don’t think that’s going to happen. I don’t think even think it’s the right approach to think about these things. AI and agents are phenomenal, but they are the perfect compliment to humans. They’re not they’re not there to replace humans. They’re there to make humans lives better. eliminate the stuff that humans don’t want to do and let humans do the fun things like make people excited about wanting to work in cyber and that’s what the AI is allowing us to do.”

    MYTH 5: AI is plug and play

    Brian Mehlman and his AI Agent from Cyber Innovate bring us Myth 5.  “I’m actually here with one

    of my agents,  and his name is Ralph. Ralph, can you answer the question as you see it in our world view? What’s the biggest cyber security myth here in 2025? Absolutely, Brian. Happy to jump in here. So, from our perspective, the biggest cyber security myth of 2025 is probably the idea that AI is just a plug-and-play solution, that it’s kind of a one-size fits-all magic bullet.” Ralph and Brian went on to further explain, “In reality, the myth is that AI will handle everything securely on its own. But the truth is it needs a lot of oversight, a lot of transparency, and people often underestimate the complexity inside the machine. So that’s the big myth that AI is just simple and straightforward when really it’s a lot more nuanced. And that’s my take. Uh I would add my answer. I would extend onto yours is I agree, but um I’m used to systems that have access controls, authentication controls, and audit. Uh inside the black box, we don’t have any of them. Once I log in and I authenticate, it’s a wild wild west. That has to change. Immutable logs within the system is probably something that’s going to happen at some point. Uh or some other unique uh solutions to the problem.”

    Interestingly, Ariful Huq from Exaforce observed a similar concern. “Trying to build an LLM wrapper is what I call it without really understanding the data related to the problems that you’re trying to solve. LLMS can only get you so far, right? They are large language models and summarization and contextualization but at the end of the day if you want to solve problems related to say detections  investigations LLMS can only get you so far right you really need to go back to the data go back to the fundamentals and then layer on a large language model on top of it to solve some of the problems that around like you know summarization um you know building agent workflows.” In other words, solutions are custom crafted – NOT plug and play.

    MYTH 6: AI Generates secure code

    Checkmarx’s Jonathan Rende brings us Myth 6, “AI generates secure code.” That myth should grab the attention all organizations leveraging coding agents to quickly advance their product. Jonathon continues, “It doesn’t. It doesn’t. And it will probably get better over time. And will it do a better job than a junior developer in simple mistakes that can cause vulnerabilities? Heck yeah, of course it will. But for the more complex issues, it’s not there yet. AI is not there yet.”

    MYTH 7: AI will solve Everything

    Let’s hear Myth 7 from Booli’s Joe Schorr, “the biggest cyber security uh myth is that AI is actually going to solve everything.” Joe went on to further explain, “I think if you judiciously apply AI, machine learning and very discreet task and things, it’s fantastic. I think it’s being overblown quite a bit right up at the myth level. I think that if you treat it like we treat it in Booli, we’ve got AI built in, but we don’t publish it all over everything we’ve got, but we treat it kind of like an idiot savant. It’s it does one to ask really well or does a discrete set to ask really well. It may not actually behave well in church, but you can get it to do what you want for something very very specific, which is how we do it. I think the myth is that AI is going to solve everybody’s problems.” Brian Sledge of imPAC also believes that AI will solve everything is a myth. “I think AIis best positioned more like a forcemultiplier, but I don’t think it solvesthe problems, the core problems of cybersecurity today. Um cyber security stillrequires context. It requirespolicy driven control and those thingsstill require human in the loop. And Ithink the best way to leverage AI isn’t so much in solving for cyber security,but it’s more for helping multiply andscale out what humans still need andwe’re required to do. So I don’t think Idon’t think customers should sleep onthe idea that humans still need to be very much engaged as part of cyber security. Because cyber security AIis only as good as the algorithms andthe models and the data it’s getting.” Thus believing in 2025 AI will solve everything is a stretch but will it solve something?

    MYTH 8: AI Will Not Solve Issues in Cyber Security

    Microsoft’s Thomas Roccia brings us Myth 8. “right now I think most people in in the industry in the security industry doesn’t yet believe in this technology (AI) and that’s maybe one of the one of the myths that AI will not really solve issue in cyber security. We have and I think that’s a mistake it’s probably something which is changing the way we are doing and all the past work that we did for the past 20 or 30 years uh is going to be changing and evolving thanks or because to AI so that’s something to consider.” Thus, while it may not solve everything today, it is changing how the industry works and what it is fighting against.    

    *When vendors’ names are shared as examples in this document, it is to provide a concrete example of what was on display at the conference, not an evaluation or recommendation. Evaluation and recommendation of these vendors are beyond the scope of this specific research document. Other examples products in the same category may have also been on display.

    Related playlists and Publications

    1. Conference Whispers: Black Hat USA 2025
    2. Conference Whispers: Identiverse 2024.
    3. Conference Whispers: Identiverse 2025
    4. Whisper Report: What’s the biggest cybersecurity myth in 2025.

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2025 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, The Answer is always in the Whispers, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: What are the most effective strategies for ensuring data security and privacy in customer interactions?

    Whisper Report: What are the most effective strategies for ensuring data security and privacy in customer interactions?

    Published to clients: August 4, 2025                        ID: TBW2080

    Published to Readers: August 5, 2025

    Published to Email Whispers: TBD

    Public and Video Release: TBD

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract:

    “Effective strategies for securing customer data include encryption at rest, in transit, and during compute; cautious AI adoption; and strict access controls. Removing or masking personally identifiable information (PII) and training staff on cybersecurity best practices are essential. Legal compliance, intellectual property protection, and customer trust drive the need for robust privacy measures in customer interactions.”

    What are the most effective strategies for ensuring data security and privacy in customer interactions?

    We took the most frequently asked and most urgent technology questions straight to the technologists gathering at Customer Connect Expo 2025 held at the Las Vegas Convention Center. This Whisper Report addresses the question regarding What are the most effective strategies for ensuring data security and privacy in customer interactions? There are two reasons security and privacy are critical in this space. As Ford’s Dr. Kalifa Oliver pointed out, “to first really understand the laws..” In fact, all governance program definitions start with legal requirements, then industry regulations and requirements, then internal privacy promises made to customers.  The second critical reasons for ensuring data security and privacy as Claritiv’s Sean Gigremoss reminds us, “your knowledge for your business comes from all the conversations that you’re having – that is your IP (intellectual property).”

    Figure 1. Four Pillars of Customer Data Protection

    Four Pillars of Customer Data Privacy
Defense in Depth
Caution with AI
Remove or Hid PII
Train your Teams

    Defence in Depth

    As Macy’s Siva Kannan Ganesan pointed out, “all those regulation and implementing an regulation it’s a multi-step approach like data and motion data at rest should be encrypted and you have to make sure it’s like the access strict access control and frequent evaluation of the data breach.” With security depth is always valuable. TBW Advisors LLC advises clients to not only use encryption at rest and in transit, but to leverage protections during compute leveraging Confidential Computing. For additional research, enjoy Industry Whispers: Public is Privacy – Confidential Computing in the Cloud available on TBW Advisors YouTube Channel.

    Caution with AI technologies

    TBW Advisors has frequently warned if you are not being charged for the product, you are the product. If you are the product, you should assume you do not have privacy. Today with many of the advanced AI products, even lower tier paid products do not get privacy; rather they are being used to further train the product. As Ford’s Dr. Kalifa Oliver observed, “you really got to start asking organizations that have AI technologies about their Blackbox about how the data is being trained. You have to ask them about data breaches you have to be conservative about how you implement things because I think the law is going to catch up and the hardest thing to do is trying to go back and fix it.”

    Remove or Hide PII

    One critical step to ensure privacy is to not send PII or personally identifiable information to tools. Enthu.ai’s Atul Grover denoted, “we also ensure that we deduct the PI information we deduct almost 16 kind of PIs including social security data birth credit card information …. we do that in the recording as well as all the analytics.” While removing the information is a common practice, masking data is also quite common. As Mitrol’s Pedro Lopez Slevin shared, “our banks for example you will probably have on premise data servers. Everything will be with TLS 1.2 two or higher you know and create your data. We’re talking about AI, we usually do rack so you will have to process every information into embeddings and those embeddings are..unreadable if you just put it in a vector database.”

    Train your Teams

    While the term Human in the Loop has gained popularity with generative AI and agentic solutions, cybersecurity has always known the human in the loop as being a critical risk factor. Thus in order to truly ensure data security and privacy, you must train those humans! Randy Simmons from FaxSipIt shared the common journey towards compliance. “we’ve gone through a HIPPA audit and we’re secure there we just finished the SOC 2 audit and we’re SOC 2 compliant so people have come in they’ve audited our system our policies they’ve come with recommendations or not and we pass the audit for the socks 2 audit so our staff all goes through cyber security training as well we go through a wiser cyber security training and then also we send phishing to our to our employees and see if they’re going to click and if they click on a link then guess what they’re doing they’re doing that training all over Again.” So remember, do not click on that link without checking the link is safe first!

    Related playlists and References

    1. Whisper Report: How can we integrate AI-driven customer service solutions with our existing IT infrastructure
    2. Conference Whispers: Customer Connect Expo 2025
    3. Whisper Report: What are the most effective strategies for ensuring data security and privacy in customer interactions?
    4. Playlist – Whisper Report: What are the most effective strategies for ensuring data security and privacy in customer interactions?

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2025 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, The Answer is always in the Whispers, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.

  • Whisper Report: What are the latest advancements in decentralized identity and verifiable credentials?

    Whisper Report: What are the latest advancements in decentralized identity and verifiable credentials?

    Published to clients: July 30, 2025                                        ID: 2085

    Published to Readers: July 31, 2025

    Whisper Club: December 15, 2025

    Public: January 20, 2026

    Analyst(s): Dr. Doreen Galli

    Photojournalist(s): Dr. Doreen Galli

    Abstract:

    “Recent advancements in decentralized identity include passwordless authentication, time-bound credentials, and dynamic identity chaining. These innovations reduce risk, improve privacy, and enhance user control. Separation of authentication from authorization enables more precise access management. One-way functions protect biometric data in cloud environments. Emerging standards like SPIFFE and CSA’s agentic identity frameworks offer scalable, interoperable solutions. Together, these developments support secure, flexible identity ecosystems without relying on centralized authorities.”

    Computer Talk Radio coverage of document.

    Target Audience Titles:

    • Chief Information Security Officer, Chief Technology Officer, Chief Digital Officer, Chief Privacy Officer, Chief Product Officer, Chief Data Officer
    • Identity and Access Management Engineers, Security Architects, Cloud Infrastructure Engineers
    • Privacy Engineers, Standards and Compliance Analysts

    Key Takeaways

    • Passwordless authentication removes friction and improves security.
    • Time-bound credentials limit exposure from compromised access.
    • Identity chaining enables dynamic, temporary access provisioning.
    • Authentication and authorization are increasingly separated for clarity and control.

    What are the latest advancements in decentralized identity and verifiable credentials?


    We took the most frequently asked and most urgent technology questions straight to the Technologists gathering at Identiverse 2025 held at Mandalay Bay in Las Vegas. This Whisper Report addresses the question regarding the latest advancements in decentralized identity and verifiable credentials.  But what is a decentralized identity. Panini’s Jim Harris explained, “identity – being able to capture that information using nearfield technology and then verifying that issue issuing information with the agency that issue it to certify that customer is legitimately who they say they are so we believe that’s one of the ways we can support authentication in a digital decentralized environment.” Let’s dive into six advancements in decentralized identity for you to add to your environment as depicted in Figure 1.

    six advancements in decentralized identity
1 .passwordless
2 time bound credentials
3 identity chaining
4 separate authentication and authorization
5 one-way functions for storage
6 leverage standards

    1. Passwordless

    Frequently involved in moving authentication from something you know to something you are, Passwordless takes those pesty passwords out of the equation. As Simeio’s Octavio Lopez observed, “I’ve been seeing a lot of a lot of organizations are pushing towards passwordless.” For vendor examples that provide biometric identity options see Conference Whispers: Identiverse 2025 and Conference Whispers: ISC West 2025.

    2. Time Bound Credentials

    A favorite tactic to limit any damage from stolen credentials is to time bound them. As GitGuardian’s Dwayne McDaniel explained, “How do we not store a long-term credential but instead expose only the bit of the credential you need to verify that entity should be doing that thing and then issue a very short live jot or 509 Cert (X.509 certificate) that will expire immediately.” Any compromised short-lived credential is useless thereby limiting the blast radius in the system.

    3. Identity Chaining

    Related to time bound credentials is the dynamic identity chaining. As Apono’s Ofir Stein revealed the key to decentralization of identities is, “it’s the ability to create dynamic changes in the identity that exist in the environment. Meaning by that we keep what we call identity chaining while if I need access to some resources let’s say in cloud we create all the identities that needed for me to work and then we revoke them so dynamic approach to decentralized identity in a panel the dynamic approach is the decentralized identity when we create identity when needed and we work them when they when they don’t need them.”

    4. Separation Authentication and Authorization

    “Although commonly associated together, as the namespace identity and access management imply, the decentralized identity world is seeing a separation. Authentication — the verification you are who you say you are — is being distinguished from authorization — the granting of some authority to some resource. As GitGuardian’s Dwayne McDaniel highlighted, “we’re going to see some major advancements with this idea of I can prove on me but that doesn’t automatically authorize me for things the authorization is starting to be separated from authentication in a way that should have probably done in the first place.”

    5.One-way Functions for Storage

    As one might suspect, many identity solutions involve the cloud. The concern becomes, how to store the data in such a way that even if the data stored is compromised – the identity information is not?  Keyless’ Alex Jones elaborated on the use case. “when you’re talking about privacy in the biometric space it’s all about where your biometric data goes does it stay on the device does it stay on the cloud so within cloud-based biometrics which is what Keyless does,  there’s different ways of making sure that the biometric data on the cloud is kept really safe and this is where a decentralized biometric system come in it’s basically transforming the biometric data when it goes on the cloud so that when it’s there it is completely unrecognizable so even if the cloud server is compromised the biometric data or the data that’s stored there is kept safe.” This is the same approach we saw leveraged during our coverage of ISC West. A hash of the data is stored not the data itself. This hash function can be used against new data presented to see if the two results match properly. There is no reverse of this hash function thus the original data cannot be disclosed even if the resulting hash is compromised.

    6. Leverage Standards

    Finally, when you are creating your roadmap or architecture you do not have to reinvent the wheel. As GitGuardian’s Dwayne McDaniel denoted, “we’re seeing the standards emerge right now about 7 years ago we saw SPIFFE the secure production identity framework for everyone emerge and that came out of what Google was doing internally. Number of working group that sprung up at Netflix and they wrote a beautiful book on it called solving the bottom turtle. The CSA has just put out a new paper May 25th on how dissolve this multi- agent system problem and introducing concepts like agentic name spacing and a distributed ID like as name spaces and it’s just a fascinating time now.”

    Final note

    For those wishing to see a case study about how to bring a massive, decentralized identity solution to life, Identiverse had a keynote for you. Specifically,  a case study of the UK mobile identity deployment featuring Hannah Rutter, Deputy Director, Digital Identity of the United Kingdom. If your organization is on the decentralized identity path, there is no reason to go alone. Reduce the risk and increase your chances of success by working with TBW Advisors LLC. Schedule an inquiry at the beginning of the process and each critical step to stop missteps.

    Analysis available only to clients at this time. Join the YouTube Whisper Club at the Whisper Club Level to get access to the video edition today.

    Related playlists & References

    1. Whisper Report: How can organizations implement zero-trust security without disrupting user experience?
    2. Conference Whispers: Identiverse 2025
    3. Conference Whispers: Identiverse
    4. UK Identity Case Study Keynote
    5. CSA’s Publication, “Agentic AI Identity and Access Management: A New Approach”
    6. Conference Whispers: ISC West 2025
    7. SPIFFE

    Corporate Headquarters

    2884 Grand Helios Way

    Henderson, NV 89052

    ©2019-2026 TBW Advisors LLC. All rights reserved. TBW, Technical Business Whispers, Fact-based research and Advisory, Conference Whispers, Industry Whispers, Email Whispers, Whisper Club, Whispers, The Answer is always in the Whispers, Whisper Reports, Whisper Studies, Whisper Ranking, The Answer is always in the Whispers, and One Change a Month, are trademarks or registered trademarks of TBW Advisors LLC. This publication may not be reproduced or distributed in any form without TBW’s prior written permission. It consists of the opinions of TBW’s research organization which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, TBW disclaims all warranties as to the accuracy, completeness or adequacy of such information. TBW does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by the TBW Usage Policy. TBW research is produced independently by its research organization without influence or input from a third party. For further information, see Fact-based research publications on our website for more details.