Catherine (Cat) Karow

Catherine (Cat) Karow

Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.

Jacksonville, Florida, United States

Actions

Cat Karow spent two decades securing some of the world's most complex institutions, including Apple, the White House, Fortune 100 companies, and large-scale research infrastructure. Then her mother became the target of a sophisticated scam, and she realized the biggest security problem wasn't in the systems she was protecting. It was in the people using them.

Today, Cat is the CEO and Technical Co-Founder of ZoraSafe, an AI-powered platform helping individuals identify and avoid scams, fraud, and digital manipulation before harm occurs. Her work focuses on the rapidly evolving intersection of cybersecurity, artificial intelligence, social engineering, consumer protection, and human behavior.

A TEDx speaker, cybersecurity leader, and founder, Cat explores how emerging technologies are reshaping trust, influence, and decision-making in modern society. Her talks examine topics ranging from AI-enabled fraud and human risk to data brokers, behavioral prediction, digital rights, and the growing influence of invisible systems on everyday life.

Cat is a founding member of Hack The Box, a Global Startup Awards North America Regional Finalist, author of *The Shield* cybersecurity publication, and the forthcoming author of *SOLD: How America Built a Legal Market for Human Beings*, a book examining the hidden economy behind personal data.

A self-taught technologist, disabled founder, and former theater performer, Cat brings a rare combination of technical depth, storytelling, and systems thinking to conversations about the future of technology and its impact on people.

Area of Expertise

  • Consumer Goods & Services
  • Government, Social Sector & Education
  • Information & Communications Technology
  • Law & Regulation
  • Media & Information

Topics

  • AI & Society
  • Human Risk
  • Cybersecurity
  • Social Engineering
  • Fraud Prevention
  • Data Privacy
  • Digital Trust & Safety
  • Consumer protection
  • AI Safety
  • Technology & Society
  • Data Brokers
  • Surveillance Capitalism
  • Digital Rights
  • Product Innovation
  • Entrepreneurship
  • Women in Tech
  • Disabled Founders
  • Human-Centered Design
  • Product Design (PD)
  • Educational Technology
  • Technical Strategy
  • Product Development Life Cycle
  • Software Product Development
  • AI in Product design
  • Android
  • iOS

The Persuasion Engine: How Human Influence Became Computable

For decades, cybersecurity focused on protecting information.

At the same time, an entirely different industry was solving a different problem.

Advertising platforms learned how to capture attention.
Data brokers learned how to profile behavior.
Recommendation systems learned how to optimize engagement.
Machine learning learned how to predict decisions.

Then generative AI arrived.

Suddenly, the ability to understand people, predict people, target people, and persuade people began converging into a single operational stack.

This session argues that we are witnessing a fundamental shift in the threat landscape: persuasion itself is becoming computable.

Modern attackers no longer need to guess who to target, what to say, when to say it, or how to build trust. Increasingly, those decisions can be informed by behavioral data, optimized by machine learning, generated by AI, and delivered across coordinated channels at scale.

Drawing on examples from fraud operations, social engineering campaigns, data brokerage, behavioral targeting, and AI-enabled deception, this talk examines how influence is evolving from an art into an engineering discipline.

The result is not simply better scams.

It is the emergence of programmable persuasion as a security problem.

Attendees will leave with a new framework for understanding how behavioral intelligence, AI systems, and influence infrastructure are reshaping both offensive and defensive security.

Session Type:
Security Research / AI Security / Human Risk / Emerging Threats

Technical Level:
Intermediate

Audience:
Security researchers, threat intelligence teams, fraud investigators, red teams, blue teams, AI practitioners, security architects, and cybersecurity leaders.

Topics Covered:

Social engineering
Behavioral targeting
Data brokers
AI-enabled persuasion
Human risk
Threat modeling
Fraud operations
Influence systems

Original Contribution:

This talk introduces the concept of computable persuasion as an emerging security paradigm. Rather than treating fraud, social engineering, behavioral targeting, AI-generated content, and influence operations as separate domains, it presents them as components of a unified persuasion stack that increasingly functions as an operational capability.

Preferred Length:
45 minutes

Village Track Suitability:
AI, Threat Intelligence, Human Risk, Social Engineering, Privacy, an

AI Theater in Security: How to Tell What’s Real, Rebranded, and Useless

Security teams are being sold AI-powered everything: AI SOC analysts, AI threat detection, AI automation, AI copilots. But how much of this represents genuine capability?

This talk examines:

- Common AI-washing patterns in security products
- Rebranded classical ML
- LLM wrappers around existing workflows
- AI summarization marketed as automation
- Rule engines labeled as AI

We also provide:

- Technical evaluation frameworks
- Questions to ask vendors
- POC testing strategies
- Red flags in demos and documentation

This session aims to provide practitioners with a practical, technical approach to evaluating AI claims in security tooling.

Security teams risk making major investments based on marketing claims. This talk helps practitioners evaluate AI claims with technical rigor.

Your User Is Under Attack: Designing Products for Fear, Pressure, and Manipulation

Most product teams design for a user who does not exist.

That user is calm, attentive, technically confident, emotionally regulated, and free to make rational decisions. Real users open products while distracted, exhausted, aging, grieving, disabled, financially stressed, or being deliberately manipulated.

In those moments, ordinary product assumptions become dangerous. A confusing warning becomes an ignored warning. A buried recovery path becomes a permanent loss. A “frictionless” experience makes the attacker’s job easier. A feature that works perfectly in testing can collapse when the user is scared.

After two decades building technology and security for organizations including Apple, the White House, and Fortune 100 companies, Cat Karow confronted this failure directly when her mother was targeted by a sophisticated scam. It forced her to rethink how products should behave when users are not merely making mistakes, but operating inside an adversarial environment.

This session introduces the Adversarial User Journey, a framework for designing products around the moments when cognitive load, emotional pressure, urgency, authority, and deception distort normal behavior.

Attendees will learn how to:

• Identify where product flows assume calm and rational behavior
• Model fear, urgency, fatigue, and manipulation as product conditions
• Design warnings that interrupt action instead of decorating it
• Build safer defaults, recovery paths, and trusted escalation
• Test products under pressure, not only under ideal conditions
• Recognize when convenience creates leverage for an attacker

The next generation of product design will not be judged only by how easily users complete a task.

It will be judged by whether the product still protects them when someone else is trying to control what they do next.

1st Track

Product Teams: Leaders, Engineers, Designers & Workflows

2nd Track

Product Lifecycle: AI Augmentation & Automation

Session Format

Conference Talk
Keynote
Fireside Chat

The Product Cost of Being Wrong: What AI Roadmaps Forget to Build

AI features are often justified by the work they eliminate: faster research, instant drafts, automated decisions, fewer manual steps. But every probabilistic product creates new work around the output.

Someone must decide whether the answer is correct, complete, safe, current, and appropriate. Someone must catch the mistake, understand why it happened, repair the damage, and determine whether the system can be trusted again. That burden may fall on the user, an employee, a reviewer, a support team, or no one at all.

This session examines the hidden product cost of AI uncertainty. It introduces a framework for evaluating not only what an AI feature can produce, but everything the organization must build around it: verification, provenance, confidence signals, correction, escalation, reversibility, monitoring, and accountability.

Attendees will learn how to identify features that create more downstream work than they remove, compare AI opportunities by the cost of failure rather than novelty, and recognize when automation is simply relocating labor into review, support, and risk.

The central question is no longer only, “Can AI perform this task?”

It is, “What must the rest of the product become because the machine may be wrong?”

Session Format

Conference Talk
Keynote
Workshop

Target Audience

Product leaders, product managers, founders, engineering leaders, designers, AI teams, security and risk leaders, customer experience teams, and executives responsible for AI product strategy.

Technical Level

Intermediate

Preferred Duration

45–60 minutes

Attendee Takeaways

• A framework for evaluating the true operational cost of an AI feature
• A method for comparing AI opportunities by uncertainty, detectability, reversibility, and consequence
• A way to identify where verification labor will land before the feature ships
• Practical guidance for designing confidence signals, provenance, correction paths, escalation, and recovery
• A clearer standard for deciding when AI should assist, recommend, automate, or stay out of the workflow

Original Framework

The session introduces the Product Cost of Being Wrong framework, which evaluates AI features across six dimensions:

Error detectability
Verification burden
Reversibility
Downstream consequence
Accountability
Trust recovery

The framework helps teams distinguish between AI that creates genuine leverage and AI that merely transfers work from creation into review, correction, support, and risk.

Why This Matters

Most AI roadmaps measure model capability, adoption, speed, and cost per output. They rarely account for the product infrastructure required when outputs are uncertain.

That missing layer often determines whether an AI feature becomes valuable, expensive, dangerous, or quietly abandoned.

First Public Delivery

New for 2027

Commercial Content

None. The session is vendor-neutral and does not promote a product or service.

The Phish Is the Payload: Reconstructing the AI Fraud Stack Behind the Message

Security teams often begin investigating where the victim first noticed the attack: the text, email, cloned voice, fake support call, or payment request.

That is usually the final delivery mechanism, not the operation.

Before contact, attackers may already have assembled breached credentials, brokered identity data, household relationships, public records, behavioral signals, recent life events, and likely sources of authority. Generative AI, voice cloning, spoofing infrastructure, and automated messaging then convert that intelligence into a personalized campaign designed to survive suspicion and move the victim across channels.

This session tears down a realistic AI-enabled fraud operation from target discovery to monetization. We will reconstruct the attacker’s data sources, enrichment workflow, identity fabrication, pretext generation, trust transitions, channel orchestration, and payment path. At each stage, we will map required inputs, tooling, dependencies, observable artifacts, and opportunities for disruption.

Attendees will leave with a reusable Human Exploit Chain model for investigating what happened before the visible lure, separating truly new AI capabilities from familiar tactics operating at greater speed and scale, and designing controls that interrupt the campaign before the victim reaches the point of no return.

Session Format

1-hour technical talk

Topics

AI Security
Social Engineering
Threat Intelligence
OSINT
Fraud and Cybercrime
Threat Modeling
Blue Team
Privacy

What will attendees walk away with?

• A method for reconstructing fraud operations beyond the email, text, or phone call that triggered the investigation
• A seven-stage model for mapping attacker data, tooling, decisions, dependencies, trust transitions, and observable artifacts
• Defensive intervention points across identity systems, communications platforms, financial controls, enterprise telemetry, and consumer protection

Level

Intermediate

Can we record your talk?

Yes. The session may be recorded and published.

First-Time Speaker?

No.

Can you present in person in Huntsville March 20?

Yes.

Workshop Logistics

Not applicable. This is a one-hour conference talk.

Stop Trying to Make Your Tech Career Make Sense

Technology careers are usually presented as ladders: choose a specialty, collect the right credentials, move through increasingly senior titles, and tell a clean story about how every role led logically to the next.

Many real careers look nothing like that.

They include layoffs, illness, caregiving, lateral moves, unfinished degrees, toxic workplaces, jobs taken for survival, unexpected opportunities, and skills acquired far outside a formal role. Women, disabled professionals, self-taught technologists, founders, and career changers are often encouraged to hide that complexity and manufacture a more conventional narrative.

Cat Karow’s career moved from repairing phones and supporting schools to research computing, cybersecurity, operations, product development, AI, executive leadership, and founding a technology company. The path did not look coherent on paper. The connections between those experiences became her greatest advantage.

This session helps attendees identify the pattern, translation, recovery, and boundary-crossing capital hidden inside a nonlinear career, then turn that experience into a clear and credible professional story.

Small Print

Session Type: Career Development / Leadership / Women in Technology / Entrepreneurship

Audience: Women in technology, career changers, self-taught professionals, founders, disabled technologists, emerging leaders, and anyone whose career does not resemble a traditional ladder.

Technical Level: All Levels

Preferred Format: 45-minute presentation plus 15-minute Q&A

Attendee Takeaways:

Identify transferable forms of career capital across unrelated roles
Build a professional narrative around recurring strengths rather than job-title chronology
Reframe pivots, interruptions, lateral moves, and unconventional experience as evidence of capability
Recognize when being difficult to categorize is a strategic advantage

The session introduces four forms of nonlinear career capital:

Pattern capital
Translation capital
Recovery capital
Boundary-crossing capital

This is a candid, practical, story-driven session rather than a motivational speech or company presentation.

First Public Delivery: New for 2026–2027

Your Warning Is Technically Correct and Completely Useless

This session examines security warnings as controls operating at the human-machine boundary, where attackers actively shape how users interpret risk.

Security teams may successfully detect a threat, generate an accurate warning, and still fail to stop the attack.

The alert appears. The user clicks through.

The block page explains the risk. The user disables the control.

The notification says the transaction may be fraudulent. The victim follows the attacker’s instructions anyway.

The failure is often blamed on the user. But attackers actively shape the conditions in which security controls are interpreted. They manufacture urgency, authority, fear, secrecy, cognitive overload, and social pressure. They coach victims around warnings, reinterpret security friction as evidence that the false story is real, and keep the target moving before doubt can form.

This session treats security warnings as controls operating inside an adversarial system.

We will decompose warnings into detection trigger, timing, message, action choices, default behavior, escalation path, recovery path, and measurable outcome. Using realistic attack narratives, we will test how common warning patterns perform when an attacker is present in the decision loop.

The session introduces the Adversarial Warning Model, a framework for testing whether a control interrupts harmful action or merely transfers the decision to a compromised human state.

Attendees will leave able to threat-model attacker coaching, design safer interruption patterns, instrument behavioral outcomes, and treat ignored warnings as failed controls rather than successful notifications.

Session format

Conference session

Level

300: Advanced

Session duration

45 minutes

Technical content
Warning architecture and control decomposition
Human-machine trust boundaries
Attacker-in-the-loop decision modeling
Social-engineering pretext integration
Warning timing and contextual relevance
Default actions and forced friction
Authority and urgency manipulation
Attacker coaching around controls
Escalation and trusted-contact pathways
Recovery and reversible action design
Behavioral telemetry and outcome measurement
Security usability testing under adversarial conditions
Threat modeling at the human decision layer
Demonstration

A controlled interactive comparison of warning designs under the same attack narrative:

Passive informational warning
Standard confirm-or-cancel modal
Contextual explanation
Friction-based interruption
Delayed high-risk action
Trusted escalation
Reversible quarantine or hold

The demonstration will show why technically accurate wording can fail when timing, defaults, attacker presence, and recovery options are poorly designed.

Attendee takeaways
Threat-model warnings with the attacker present in the user’s decision loop
Distinguish notifications from controls that meaningfully interrupt harmful action
Design and instrument safer defaults, escalation, delay, and recovery around high-risk decisions
Original framework

The Adversarial Warning Model evaluates seven dimensions:

Trigger: Was the right risk detected?
Timing: Did the control appear before commitment?
Interpretation: Can the attacker plausibly explain the warning away?
Default: What happens when the user acts quickly?
Friction: Does the control meaningfully interrupt momentum?
Escalation: Can the user reach a trusted source outside the attacker’s narrative?
Recovery: Can the action be delayed, reversed, or contained?
Speaker notes

This is not a security-awareness presentation. It is a technical and behavioral analysis of warnings as security controls. The session is applicable to application security, identity, financial systems, fraud prevention, browser warnings, endpoint controls, consumer security, and enterprise workflows.

The Human Exploit Chain: How AI Turns Personal Data Into Precision Fraud

Fraud is usually analyzed at the moment of contact: the phishing email, cloned voice, fraudulent text, or urgent call. By then, the attack is already underway.

Modern social engineering begins earlier, with breached data, brokered profiles, identity resolution, relationship mapping, behavioral signals, and vulnerability discovery. Attackers combine this intelligence with generative AI, voice cloning, spoofed identities, and automated messaging to create personalized, adaptive campaigns.

This session introduces the Human Exploit Chain, a framework for mapping AI-enabled fraud from data collection and target selection through identity simulation, persuasion, multi-channel coordination, payment coercion, and repeated victimization.

Attendees will learn to analyze these campaigns as connected systems, separate new AI capabilities from accelerated old tactics, and identify practical defensive intervention points.

Session Type: Technical Conference Session / Cybercrime Research / Emerging Threats

Preferred Track: Cybercrime, AI and Cybersecurity, Threat Intelligence, Fraud, Human Factors

Technical Level: Intermediate

Preferred Duration: 45 minutes, with optional Q&A

Target Audience:

Security researchers, threat intelligence teams, fraud investigators, financial security teams, red teams, blue teams, identity specialists, privacy researchers, AI practitioners, platform security teams, and security leaders.

Technical Topics Covered:

• Data acquisition through breaches, public records, data brokers, social platforms, and compromised accounts
• Identity resolution, entity enrichment, relationship mapping, and target prioritization
• Behavioral and vulnerability profiling
• Generative AI-assisted pretexting and adaptive scripting
• Voice cloning, synthetic media, spoofing, and identity simulation
• Cross-channel attack orchestration
• Trust transitions and persuasion mechanics
• Payment coercion, mule networks, account takeover, and victim-list reuse
• Defensive telemetry and intervention opportunities
• Threat modeling for human-targeted attack systems

Original Contribution:

This session introduces the Human Exploit Chain, a security framework that models modern fraud as a connected operational system. Rather than treating phishing, impersonation, voice cloning, data brokerage, social engineering, and payment fraud as separate categories, the framework maps how they combine across seven stages:

Data acquisition
Target enrichment
Vulnerability and timing analysis
Identity construction
Persuasion execution
Channel and payment orchestration
Monetization, reuse, and repeated targeting

Each stage is evaluated through four defensive questions:

• What data does the attacker require?
• What decisions or capabilities can be automated?
• What trust transition must occur?
• Where can the operation be detected, disrupted, or delayed?

The session draws from documented fraud campaigns, cybersecurity and threat-intelligence reporting, consumer scam cases, data-broker practices, social engineering research, and lessons from building consumer fraud-prevention technology.

The presentation is vendor-neutral and will not promote specific commercial products.

First Public Delivery: New for 2026

Media Availability: Yes

Photography: Yes

Built for Marketing, Weaponized for Fraud: The Data Pipeline Behind Precision Scams

Many targeted scams begin before the phishing email, fake call, or stolen credential. They begin with information collected, inferred, enriched, and sold through legal data markets.

Data brokers, people-search services, public records, advertising data, and breach information can reveal where someone lives, who they trust, what they own, and when they may be vulnerable. Combined, this data becomes operational intelligence for fraud.

This session maps that pipeline from data collection and target selection through relationship mapping, impersonation, and payment coercion. It also introduces a practical framework for assessing when lawful data practices create fraud-enablement risk and where defenders, platforms, financial institutions, and policymakers can intervene before victim contact occurs.

Session Type: Law and Policy / Cybercrime / Data Protection / Emerging Threats

Technical Level: Intermediate

Preferred Duration: 45 minutes

Target Audience: Security researchers, privacy professionals, threat intelligence teams, fraud investigators, financial institutions, policymakers, platform security teams, data governance leaders, and consumer protection professionals.

Topics Covered:

• Data brokers and identity-resolution systems
• People-search platforms and public-record aggregation
• Advertising data and audience enrichment
• Breach data combined with lawful consumer information
• Household, relationship, and social-graph mapping
• Behavioral inference and vulnerability proxies
• Life-event and timing intelligence
• Fraud targeting and impersonation workflows
• Data minimization, deletion, and access controls
• Regulatory and accountability gaps
• Defensive intervention points across the data lifecycle

Original Contribution:

This session introduces the Fraud Enablement Risk Model, a framework for evaluating whether a dataset, enrichment service, or profiling capability materially increases the precision, credibility, or scalability of targeted fraud.

Rather than treating privacy, data brokerage, and cybercrime as separate domains, the session maps how they operate as one connected system.

The presentation is vendor-neutral and grounded in documented fraud patterns, data-broker practices, cybersecurity reporting, and consumer scam cases.

First Public Delivery: New for 2026

CyberBay

The Dark Web’s New Gold Rush: How AI Fuels Cybercrime as a Service (CaaS)
Full length session with Q&A

March 2026 Tampa, Florida, United States

TEDx

What if your personal data is shaping your life in ways you never agreed to? Cybersecurity architect Catherine "Cat" Karow pulls back the curtain on the hidden data broker economy and reveals how America’s surveillance-commerce system monetizes manipulation at scale. #TEDxSarasota Catherine “Cat” Karow is a cybersecurity architect and founder of ZoraSafe.
She began her career in public education IT before leading identity and access management for the University of Florida’s HiPerGator supercomputer, building its restricted data onboarding process as it scaled into one of the top five supercomputers in the world.
An early Hack The Box beta cohort member - back when access required exploitation - she later led technical initiatives for Apple, the Department of Transportation, and the White House.
After scammers targeted her mother using legally purchased personal data, Cat turned her focus to investigating the data broker industry. Her forthcoming book, SOLD: The Hidden Industry That Sells Your Data - and Shapes Your Life, explores how America’s surveillance-commerce system was constructed - and who it leaves exposed. This talk was given at a TEDx event using the TED conference format but independently organized by a local community. Learn more at https://www.ted.com/tedx

March 2026 Sarasota, Florida, United States

Simply Cyber Con 2025 Sessionize Event

November 2025 Charleston, South Carolina, United States

BSides St. Pete 2025 Sessionize Event

October 2025 St. Petersburg, Florida, United States

BSides Orlando 2025 Sessionize Event

September 2025 Orlando, Florida, United States

National Cyber Summit

National Cyber Summit is the nation’s most innovative cybersecurity-technology event, offering unique educational, collaborative, and workforce development opportunities for industry visionaries and rising leaders. NCS offers more value than similar cyber conferences with diverse focus areas, premier speakers, and unmatched accessibility. Our core focus is on three things: education, collaboration, and innovation.

September 2025 Huntsville, Alabama, United States

Catherine (Cat) Karow

Cat Karow built security for Apple, the White House, and Fortune 100s. Then her mom got scammed, and she discovered the next cybersecurity frontier wasn't infrastructure. It was human beings.

Jacksonville, Florida, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top