FC Barker, aka Freakyclown – ethical hacker, author & speaker – shares what MLSs should be preparing for in the era of AI and increasing cybersecurity threats.
- The first priority for MLS leaders must be to understand that the threat vectors have changed.
- As the MLS leader, it's your responsibility to secure the link between your members and your data.
- The human element is where breaches happen. Not because people are stupid, but because they are tired, distracted, and under pressure.
Let’s be honest about what is going on in the world right now. The cybersecurity industry is awash with fear, uncertainty, and doubt, and you, along with everyone else, are drowning in a sea of fearmongering about Artificial Intelligence. You’ve heard it all: “AI will take over”, “Robots are coming for your jobs”, and “the singularity is near”. Most of this is just marketing fluff, designed by people who don’t understand the real problem but do know how to make you emotionally react to buying their new compliance report or to selling you their new shiny dashboard that does nothing but blink red lights all day.
The truth, though, is that if you strip away the hype and corporate spin, AI is not going to magically make computers or people smarter. (If it were, I wouldn't be sitting here at 1 a.m. writing this. I'd have an agent do it for me.) The real danger is that AI has now fundamentally broken the economics of deception.
I have observed over the last 3 decades that the primary barrier to entry for an attacker was simply time and effort. To craft a convincing phishing email, they would have to manually research their target, mimic the tone, and hope it slipped past the employee’s eyes. Based on my real-world experience of simulating this type of attacker, this level of attack takes approximately 40 hours per target, as well as a slew of experience in technology to set up the anonymized infrastructure. It was slow, expensive, and limited in scale. That era, unfortunately, is now over.
Today an attacker can leverage generative AI to produce thousands of hyper-personalized, grammatically perfect, context-aware phishing emails in seconds. They can clone voices with just a few seconds of audio samples, like that time you gave that media interview.
Deepfake videos are now being produced that imitate CEOs and others of the C-Suite in increasingly larger numbers and are stealing hundreds of millions of dollars from companies around the world. This is not hyperbole; this is actually happening today. Worst of all, it’s happening at scale and at a cost-to-return ratio that any CFO could only dream of. Imagine spending less than $500 and getting $500 million back in an afternoon.
This is why the first priority for any MLS leader in this new landscape must be to understand that the threat vectors have changed! The threat has shifted from brute force to one of precision deceptions. An analogy I like to use from my days in intelligence and defense is that we have entered an era change much like the move from WW1 blanket bombs across Germany, which took thousands of bombs to knock out a single target, to the much more precise and damaging smart-bomb era of the Gulf War. The downside is that we have yet to enter the uber-cheap and terrifying UAV era we currently see in conflicts today, but I assure you that will be coming in the next five to ten years.
Like most jaded, experienced cybersecurity experts, I see the bad side of innovation, and one of the largest issues I’ve seen is the standardization of communication between systems. Back when I was starting out, there was a new World Wide Web, and to talk to different systems you had to have arcane knowledge of each and dial into each one individually. As we grew the internet and people decided that esoteric operating systems and proprietary protocols were a bad thing, we started to build systems that could talk to each other and exchange data, etc. This is where it all went wrong and frankly has led us here, to you - the MLS leader who is no longer defending a single platform. You are defending a sprawling, interconnected web of vendors, integrations, APIs, third-party tools, and now, AI-driven features that have a mind of their own. Every new integration is another potential entry point, and every new vendor is a link in the chain that can be broken.
This brings us to the second critical issue: trust in a connected world.
First, we need to stop treating AI like something magical. It isn’t magic, it’s software that ingests data and performs some fancy math and then spits the data back to you. Once you look at it like that, it becomes straightforward with normal security questions around it. Where does the data come from? Where is it going? Who stores it? Who controls it?
This is where the reality of your operational model becomes a security liability if not managed correctly. As MLS leaders, you are not just the users of technology; you are operators of an MLS ecosystem that relies on a complex web of third-party enterprise software. You license core capabilities for listing entries, search and compliance. But beyond that, you also depend on other vendors for membership management, showing services, lockbox systems, and increasingly, the AI-driven tools your agents use to interact with your platform. This means that your security posture is only as strong as the weakest link in that entire chain, and that link isn’t always under your direct control. You need to work with trusted technology partners that are committed to managing those complexities. The vendors that know that secure by design is the only way to make sure your data is secure at all points. You must apply the same level of scrutiny to every vendor in your ecosystem and ask if they are doing the same for you.
You cannot secure what you do not understand, and you can’t trust what you have not vetted. In an era where AI agents are becoming standard interfaces between your members and your data, the responsibility to ensure that every link in the chain is secure falls squarely on you, the leader! It’s about ensuring that the entire ecosystem, from lockbox to membership portal to listing management, meets the same high bar. That’s how you protect your members, and that’s how you maintain trust in an increasingly connected world.
Secondly, you need to move beyond MFA. Multi-Factor Authentication is a band-aid over a bullet wound. Like most security controls, it adds a tiny bit of friction to the end user, which they resent, and most importantly, it doesn’t eliminate the whole risk. Passwords are also inherently flawed; they are often reused, guessable, phishable, and stolen frequently. The future of security is not “Password + something else”; it’s passwordless. There are many such systems now to choose from: biometrics, hardware keys, passkeys, etc. These are the standards that you should be trying to implement now. You can sleep soundly knowing attacks cannot steal those keys as easily and will move on to softer targets.
The final part of this puzzle that you have to understand is that technology alone won’t save you!
This is without doubt the most important one; security is everyone’s responsibility, not just IT’s.
Too many organizations let their vendors or their IT team deal with the security problem. That’s the wrong way to deal with it. The human element is where breaches happen. Not because people are stupid or the weakest link, but because they are tired, distracted, and under pressure. An agent who is rushing to wrap up a transaction at 10 a.m. on a Friday so they can get to their kid’s birthday party is never going to carefully verify the sender of an email that looks exactly like their client. An agent who’s been using the same password for ten years isn’t going to suddenly change it significantly because IT sent a reminder.
This is why ongoing awareness training matters, not the once-a-year training everyone skipped through and forgot about by Friday because they had important work to get done and put it off as long as they could. It’s about building a culture in your company where security is part of everyday decision-making. Where staff, brokers, and agents understand why they are being asked to do something, not just what. When they feel empowered to report a suspicious thing without the fear of blame, even if they did click that dodgy link, this is better than them hiding it.
The question should not be whether your organization will encounter an AI-enabled attack; it’s inevitable. The question is: will your people recognize them? Will they know the signs? Will they have the tools and training to respond correctly? If the answer is no, then no amount of firewalls or MFA will save you.
Here are three questions I want you to ask your team:
- Are we truly prepared for how AI is changing the threat landscape, not in theory but in practice?
- Do we have a clear understanding of the risk that comes with our increasingly connected tech ecosystem, including third parties?
- Are we doing enough to keep our staff and members informed, engaged, and equipped to handle these threats on a daily basis?
If you cannot answer those questions confidently, then it’s time to act. Not with more fearmongering. Not with more compliance checklists. But with real, practical steps: tighter controls over AI capabilities, passwordless security, and a cyber-aware culture to back it all up.
Because in the end, trust isn’t something you buy, it’s something you build. It starts with understanding that the next breach won’t come from a human hacker typing commands at 3 a.m. It will come from an AI-generated email that looks exactly like the one your client sends. If we do not adapt, we’ll all be on the other side of the screen wondering how it happened.
About the author:
Author, keynote speaker, Co-Founder of Cygenta and former Head of Offensive Cyber Research at Raytheon. As an ethical hacker for the last three decades, FC has helped thousands of banks, governments and other organizations advance their security.
He has shared his expertise in mainstream media, including the BBC and ITV, as well as popular industry podcasts such as Darknet Diaries (EP66). He has also been featured in printed media around the world educating people about cyber security from a hacker’s perspective.
His time as the Head of Offensive Research at Raytheon enables him to bring to bear his knowledge of how nation states and the intelligence community work with cyber weapons and how to defend against them. The decades he has spent legally breaking into organizations, both physically and digitally, has taken him around the globe in the fight against cybercrime.
Whilst FC is his memorable real name (it really is what's on his passport!), he is often better known by his hacker handle 'Freakyclown'. The name that was given to him by bullies as a schoolboy has now been turned into a positive alter ego for FC to educate the world on cyber security issues.