Interview with a CIO:
Karla Reffold, Chief Insight Officer at Surefire Cyber
In the latest edition of Intaso’s Interview with a CIO series Lydia sits down with Karla Reffold, Chief Insight Officer at Surefire Cyber, to discuss diversity in cybersecurity, the growing role of AI and why high-quality data will be critical to the industry’s future.
About the Interviewer:
Lydia Morfett-Murdock
Lydia is Vice President at Intaso, specialising in building Engineering, Product and AI teams for cybersecurity start-ups. She has placed more than 200 professionals across these functions, supporting businesses through periods of hypergrowth and helping them build high-impact teams aligned with their commercial and strategic goals.
Karla Reffold
Karla Reffold is Chief Insight Officer at Surefire Cyber, where she leads the company’s data, research and cyber intelligence strategy. She focuses on turning cyber intelligence, telemetry and research into actionable insights that support executive decision-making, incident response and business growth.
Key Takeaways
Diversity strengthens cybersecurity teams: Surefire’s leadership team is 50% women, with Karla highlighting the value of different perspectives, experiences and ways of thinking.
Flexibility plays a vital role in inclusion: Surefire’s fully remote model helps employees balance demanding incident response work with their family life and other personal commitments.
Recognising that cyber needs broader talent pathways: Improving diversity will need organisations to look beyond traditional backgrounds, investing in training, upskilling and transferable skills.
Good AI begins with good data: Businesses with high-quality, structured and unique datasets are better positioned to use AI effectively, giving them a meaningful competitive advantage.
Not everything needs AI: Karla cautions against adding AI just for the sake of it, particularly where automation may be sufficient or where human judgement, empathy and oversight remain essential.
AI is more likely to augment people than it is to replace them: At Surefire, AI is helping teams analyse more information, identify patterns faster and support newer team members.
AI could give cyber defenders an advantage: By adopting advanced AI tools early, defenders may be able to stay ahead of threat actors who continue to rely on established attack methods.
Watch the interview:
At Surefire Cyber, Karla leads the company’s data, research and cyber intelligence strategy.
Before joining the business, she founded and scaled two successful cybersecurity companies across recruitment and events, and today works at the intersection of cyber intelligence, incident response, insurance and AI.
Surefire Cyber has a particularly diverse leadership team, especially compared with the wider cybersecurity industry. How did that come about?
Karla: Surefire’s leadership team is 50% women, and we have a high percentage of women throughout the wider business too.
Interestingly, despite all the advice I’ve probably given organisations throughout my career about improving diversity, I’m not sure we’ve deliberately implemented many of those things ourselves.
We’ve focused primarily on hiring the best people we possibly can and on finding people who align with our values. By doing that, we’ve ended up with a diverse team very organically.
Women are incredibly capable in cybersecurity, so when you focus on finding great people, it shouldn’t be surprising that many of those people are women.
Is there anything within Surefire’s culture or benefits that you think particularly supports women or families?
Karla: One thing we do really well is being fully remote. We don’t have an office anywhere, and that supports not only women, but families more broadly.
We have plenty of people with children and plenty without who value the flexibility and benefits that come with remote working. As someone with children myself, being remote is incredibly helpful. There are probably things I’m able to do without even thinking about them simply because I don’t have to be in an office from nine to five.
As an incident response company, we also have people working around the clock. Our teams respond to clients within minutes, and that kind of work isn’t always naturally conducive to a healthy work-life balance.
We’re very conscious of that, so the flexibility and schedules we’ve put in place are designed to help. We have people who can now coach their children’s sports teams, for example, or simply take a break when they need one.
Being remote, being flexible and being conscious of burnout all contribute not only to diversity, but to our culture overall.
What advice would you give to other cybersecurity firms looking to improve diversity?
Karla: We’ve been fortunate in that we’ve focused on quality and values and diversity has followed organically. But if that isn’t happening, I think organisations need to be intentional about it and recognise that diversity makes teams stronger.
In recent years, there has been some backlash against diversity initiatives. There can be an assumption that if a company has reached a certain level of diversity, it must have prioritised diversity over hiring the best person.
That doesn’t have to be the case.
A diverse team brings different ways of thinking and different life experiences. Even when you have two equally strong candidates, someone who brings a different perspective or experience can add something valuable to the wider team.
That diversity of thought is a genuine strength.
Are there particular challenges when it comes to building a more diverse cybersecurity talent pool?
Karla: It’s well documented that cybersecurity doesn’t currently have a particularly diverse candidate pool. The figures I’ve seen have women representing somewhere between 20% and 25% of the cyber workforce, despite making up a much greater proportion of the workforce overall.
There are genuine challenges when it comes to sourcing the best people, particularly for certain roles.
That means organisations may need to be more intentional about considering people from different backgrounds, understanding where transferable skills exist and creating opportunities to train, upskill and give people a pathway into cybersecurity.
AI is dominating conversations across cybersecurity. What mistakes are you seeing organisations make when it comes to their data?
Karla: One of the things we’ve done at Surefire that has put us in a very strong position is thinking carefully about how we gather, structure and share data.
I was brought in partly to make sure we had processes around that, and as a result we now have a unique and valuable dataset that we can use in a number of ways.
Not every organisation will have thought about this several years ago. There wasn’t necessarily a reason to before the explosion of AI tools we’ve seen recently.
Companies with high-quality, structured data are going to be in a much better position to enhance their products using AI than those without it.
There is also a lot of open-source cybersecurity data available, so organisations need to think about what they have that is genuinely unique. Do you have data that other people can’t easily access that gives you an edge?
Is there anything you think the cybersecurity industry is getting wrong about AI?
Karla: I’m not sure I would say organisations are necessarily getting it wrong, but there has definitely been a rush to put AI against everything.
I find it hard to believe that every cybersecurity company now talking about AI has concluded, in every case, that AI is genuinely necessary.
Not everything needs to be AI. Sometimes what you need is automation, and sometimes a process simply doesn’t need AI at all.
One area I’m pleased we’re focusing on at Surefire is understanding where the human element needs to remain front and centre.
Incident response requires a huge amount of empathy. We may eventually be able to outsource elements of technical processing to AI, but we can’t outsource the empathy involved in guiding someone through what could be one of the worst days of their professional life.
Organisations need to consider where a person still needs to be involved (from an empathy, relationship and oversight perspective) rather than rushing to add AI simply because it helps with the next fundraise or sale.
How are you using AI and data at Surefire?
Karla: We’ve been looking at where we can use our data to respond faster and deliver better outcomes for our clients.
The dataset we’ve built allows us to identify changes in threat actor behaviour more quickly and get those insights to our teams and clients.
Everything we’re doing with the data is ultimately designed to help us respond faster and provide better insights, including to our core insurance clients.
For example, how can insurers underwrite more effectively based on the data we’ve collected and analysed? And how can AI make our own analysis better and faster, or help us identify patterns that people might otherwise miss?
What impact has AI had on the way your team works day to day?
Karla: It’s had several impacts. We can produce more intelligence than we could a year ago. More isn’t always better, of course, but in this case it means our teams have access to more useful insights and can respond faster.
It also means we can give our clients more frequent updates on the trends we’re seeing. That can help them when assessing claims, supporting clients through incidents or making underwriting decisions.
AI has also been useful when training newer members of my team. I’ve brought in people who don’t have traditional intelligence backgrounds. While I’m teaching them how to think creatively and critically themselves, the AI tools we use can help them identify things they might otherwise miss, and things I might miss too.
Why was getting the data right from the beginning so important?
Karla: Clients were asking us to share data, and it became clear very quickly that there wasn’t an industry standard for how certain things should be described.
We had to work out what terminology was most commonly understood by our clients and what would make sense for the way we collected and structured information internally.
At the same time, AI was still relatively new. We could see a future where having a strong dataset would allow us to use AI for much better analysis, even though the technology wasn’t necessarily capable of doing everything we wanted at the time.
This was when AI still struggled significantly with things like maths, numbers and dates. It has improved enormously since then.
Some of the information we were collecting wasn’t immediately useful, but it has become increasingly valuable over time.
The big benefit today is that we have several years of structured data available. If we hadn’t taken that approach early on, we would now be scrambling to go back and collect the information we need.
Thankfully, we were looking ahead and thinking about what might become possible.
Looking ahead, where do you see AI and cybersecurity going over the next five years?
Karla: I have two thoughts on that.
One of the biggest concerns around AI has been whether it will replace everything we do. My experience so far is that it actually enables us to do more, and makes us busier.
Think about email. We send far more emails today than we ever sent letters. Email made communication easier, but it didn’t necessarily mean we communicated less.
I think AI will have a similar impact. It will enable people to do more rather than simply replacing them.
When it comes to cybersecurity specifically, I’m also relatively bullish about the opportunity for defenders. We have access to frontier AI models and an opportunity to use those tools to get ahead of some threats.
We’re not yet seeing threat actors embrace AI to the extent people might expect, largely because they don’t have a strong reason to. Traditional methods still work. AI might make some attacks faster, but why invest in completely new methods when existing approaches remain effective and inexpensive?
If defenders can use AI now to get ahead of where attackers may eventually go, it could give cybersecurity teams an important advantage.