Episode 16

full
Published on:

19th Nov 2025

Hacking AI and Building Trustworthy Systems: Insights from Satu Korhonen

In this episode of the Security by Default podcast, Joseph Carson and guest Satu Korhonen a passionate practitioner, researcher and founder of Helheim Labs delve into the intersection of AI and cybersecurity. They discuss the challenges and opportunities in creating trustworthy AI systems, the importance of collaboration between AI and cybersecurity professionals, and the role of regulation in ensuring AI safety. Satu shares her journey from education to AI, highlighting key moments and insights from her career. The conversation also touches on the EU AI Act, the importance of understanding AI's limitations, and the need for a balanced approach to AI development.

Key Takeaways

  • AI systems are fundamentally probability-based, not perfect.
  • Collaboration between AI and cybersecurity is crucial for safety.
  • The EU AI Act focuses on human rights and risk management.
  • Understanding AI's limitations is key to using it effectively.
  • AI can enhance productivity but requires careful implementation.
  • Training AI with both good and bad data improves its robustness.
  • AI should serve humans, not the other way around.
  • Hacking AI can reveal vulnerabilities and improve security.
  • Community events like hacker camps foster innovation and learning.
  • AI's role in society should be carefully considered and discussed.

Chapters

00:00:00 Introduction to AI and Cybersecurity

00:03:00 Satu's Journey into AI

00:09:00 Trustworthy AI and the EU AI Act

00:15:00 Challenges in AI and Cybersecurity Collaboration

00:21:00 The Role of Community and Events in AI

Resources:

https://hackai.quest/

https://helheimlabs.ai/

https://helheimlabs.ai/about-satu-korhonen/

https://www.linkedin.com/in/satu-m-korhonen/

https://why2025.org/

https://www.ccc.de/en/home

https://events.ccc.de/en/

https://disobey.fi/2026/

Show artwork for Security by Default

About the Podcast

Security by Default
Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends.
Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.

About your host

Profile picture for Joseph Carson

Joseph Carson

I am a distinguished cybersecurity professional with over 30 years of experience in enterprise security and infrastructure.

Throughout my career, I have been an active contributor to the cybersecurity community, serving as an educator, ethical hacker, and speaker at global conferences. I hold both the Certified Information Systems Security Professional (CISSP) and Offensive Security Certified Professional (OSCP) certifications as well as advise various governments, critical infrastructure organizations, and industries such as finance and transportation on cybersecurity matters.
I am the author of "Cybersecurity for Dummies," a book that has gained global recognition for helping companies integrate people, processes, and technology to strengthen their defense against cyberattacks. The book has over 50,000 readers worldwide and provides a straightforward approach to understanding cybersecurity.

In addition to my writing, I have authored numerous articles and research papers, contributing to publications such as The Wall Street Journal, USA Today, Dark Reading, and CSO Magazine. I also host the bi-weekly podcast "Security by Default" which offers insights from leading cybersecurity experts and discusses best practices for navigating security challenges.
I am dedicated to educating the next generation of cybersecurity leaders and his commitment to building a safer internet have made him a respected figure in the cybersecurity community.