Fred Streefland: “The Attacker Is Faster, So the CISO Needs to Be Faster Too”

Auteur zonder afbeelding icoon
Beyond Products
25 August 2026
3 min

Fred Streefland: “The Attacker Is Faster, So the CISO Needs to Be Faster Too”

“The main difference compared to two years ago is speed. A vulnerability that used to take a team of hackers thirty days to find and exploit is now discovered and exploited within 21 hours,” says Fred Streefland in the Security Innovation Stories podcast.

He began his career at the Royal Military Academy and spent sixteen years in the Royal Netherlands Air Force as an intelligence officer. He then moved into the private sector, working at IBM, Accenture and Palo Alto Networks. Today, he works at Check Point.

In this episode of Security Innovation Stories, the discussion focuses on the facts and myths surrounding AI in security: what is changing for attackers, what does this mean for the CISO, and what can Mythos teach us about the speed at which the field is evolving?

This episode of Security Innovation Stories is part of a special series around Cybersec Netherlands on 9 and 10 September at Jaarbeurs Utrecht. Fred will moderate the Tech Dome on 9 September, while Lotem Finkelstein, Director Threat Intelligence & Research at Check Point, will take to the main stage to discuss a Chinese threat actor that is relevant to Dutch technology companies.

From fighter aircraft to security teams: the OODA loop

One skill Fred took with him from his time as an intelligence officer is the ability to analyse large amounts of data and turn it into something useful. One concept that stayed with him is the OODA loop: observe, orient, decide, act.

Developed in the 1950s by American fighter pilot John Boyd, the concept was based on the idea that it was not technology itself, but the speed of the decision-making cycle that determined who won an aerial battle.

Whoever observes, analyses, decides and acts faster than the opponent wins. For Fred, that principle remains the model for understanding the value of AI in security.

“Acting, analysing and responding faster than your opponent: that is exactly what makes the AI era so interesting.”

From thirty days to 21 hours

What this acceleration looks like in practice becomes clear in the 2026 AI Security Report published by Check Point in July, to which Fred contributed.

One of the findings that surprised him most was that an individual Chinese threat actor used AI to independently build a complete attack framework within a single week. Previously, this would have required a team around six months.

“I really had a wow moment: this is interesting.”

The main difference compared to two years ago is speed. A vulnerability that previously took thirty days to discover and exploit can now be exploited within 21 hours.

For Fred, this directly relates to the OODA loop. If attackers are moving through their decision-making cycle this much faster, defenders need to move at least as quickly.

“That brings me back to my OODA loop: we need to become faster at detection, but especially at resolving those vulnerabilities.”

The CISO under pressure from three directions

This acceleration ultimately affects the CISO, who, according to Fred, is struggling worldwide with challenges coming from several directions at once: attackers becoming faster and more sophisticated, the need to secure AI applications within the organisation, and the need to use AI themselves as a force multiplier.

“I see a lot of CISOs really struggling with this. There is so much coming at them.”

His advice sounds simpler than it is: go back to basics, starting with a risk assessment before implementing AI. Only when you understand exactly where the risks are can you mitigate them effectively, including the risks introduced by AI itself.

Listen to the full conversation with Fred on Spotify or YouTube for more about the OODA loop, the 2026 AI Security Report, how Check Point applied the Mythos method itself through Project BLAST, and his tips for Cybersec Netherlands.

Register for free for Cybersec Netherlands 2026

As cyber attacks continue to threaten today’s tech landscape, this event is the premier platform for seasoned cyber security professionals and innovative start-ups to exchange knowledge and tackle cybersecurity challenges together. Organizations across all sectors will discover strategies to boost cyber resilience and safeguard critical assets. Don’t miss this chance to strengthen your cyber defenses, register for free now!