Overview
Sage Wohns is the CEO and founder of Jericho Security [1], a company that uses artificial intelligence to address cybersecurity threats [2]. Wohns has over 10 years of experience in entrepreneurship, venture capital, and software engineering [2]. Before founding Jericho Security in February 2023 [3], Wohns cofounded and led Agolo from January 2013 to February 2023 [4], an AI startup providing information summarization for finance and news organizations that received multiple awards [2]. Wohns holds an MBA in Entrepreneurship from Columbia Business School [9], earned between 2011 and 2012 [6], and a bachelor's degree in Political Science from the University of Chicago [10]. Earlier career experience includes roles as a Lead Engineer at Rakuten [7], an Accelerator and Venture Associate at NYC Seed [5], and a Product Manager at Sonnenschein Nath & Rosenthal LLP [8].
Profile introduction
Sage Wohns is the CEO and founder of Jericho Security, a company that leverages the power of artificial intelligence to combat the evolving threats of cyberattacks. With over 10 years of experience in entrepreneurship, venture capital, and software engineering, Sage is a visionary leader and an expert in AI and cybersecurity. Before launching Jericho Security in 2023, Sage cofounded and led Agolo, a pioneering AI startup that provides fast and comprehensive information summarization for finance and news organizations. Agolo won multiple awards and recognition, including Citi's Top Business In…
Career history
- CEO & FounderFeb 2023 to presentJericho Security
- CEO & FounderJan 2013 to Feb 2023Agolo
- Accelerator and Venture AssociateMay 2011 to May 2012NYC Seed
- MBAJan 2011 to May 2012Columbia Business School
- Lead EngineerOct 2007 to Oct 2010Rakuten
- Product ManagerOct 2006 to May 2007Sonnenschein Nath & Rosenthal LLP
Education
Master of Business Administration (MBA), Entrepreneurship/Entrepreneurial Studies2011 - 2012Columbia Business School
Bachelors, Political ScienceUniversity of Chicago
- Charles Wright Academy
Insights & ideas
The through-line
Wohns keeps returning to a single claim: generative AI did not invent social engineering, it removed the economics that used to limit it. His background is in machine reading and writing at scale, and he dates the turn precisely to the moment GPT-3 arrived and one of his largest customers in the DoD "tried to classify it as a weapon because now you can socially engineer at a scale that's absolutely unprecedented with precision that's never been before humanly possible" [1]. He makes the same point about technological waves weaponising quickly and about human-centric attacks reaching an unprecedented scale in his more recent appearances [2][5][6]. The consequence he draws is about price rather than capability: "No one's worried about burning a $10 million zero day anymore when you can just for pennies create a Marco Rubio recording and distribute that" [1].
From that premise everything else follows. If attacks are cheap, personalised and infinitely iterable, the defensive stack built for templated phishing is obsolete, the population that needs defending is far larger than the enterprise market anyone has been selling to, and the most valuable asset in the field becomes data about what a high-efficacy generated attack actually looks like. His earlier work in applied AI for finance and news organisations [3][4], and his experience at Rakuten and Agolo in machine learning and natural language processing, are the foundation he now applies to cybersecurity [7].
On why the old awareness training no longer works
"The old approach of using templates, the old approach of doing like persona based attacks, it's not relevant anymore" [1]. Wohns argues that attacks are no longer keyed to org-chart position alone. They are built from breach data, leaked PII and details such as which bank a target uses, which pushes everything from phishing to spear-phishing at the individual level [1]. The training that accompanied the old tooling fails for the same reason: off-the-shelf videos are "necessarily generic because they didn't have the ability to create dynamic targeted education" [1].
He is equally dismissive of the detection heuristics people have been taught in succession. The instruction used to be to spot grammar and spelling errors, then it became to spot a deepfake, and neither survives a world where most communication is AI-enhanced and everyone drafts emails, LinkedIn posts and resumes with the same tools [1]. His formulation is blunt: "just spotting something that generative does not equal an attack. What really equals an attack is an attack" [1]. What he wants people trained on is the attack path and kill chain, which is patterned and therefore learnable, and which can be tied back to the specific data the attacker used to target them [1].
On red teaming that feeds education
Jericho's structure inverts the usual sequence. "The attack is the beginning point, but the education is really where we can add a layer of data as well as enrichment" [1]. Wohns describes a red team that trains a blue team: the blue team analyses attack information to tell a user what to look for, and the education arrives with context, showing "here's your breaches, here's where you're vulnerable, and this is how to protect yourself from these" [1]. That education can be tailored and produced in under an hour for an individual, explaining why they were targeted this way and how to stop it, and it extends to protecting colleagues as well as oneself [1]. The company's use of AI to identify and counter novel generative phishing attacks is the technical core of this [7].
The channel coverage has widened fast. A year before the conversation the product was email only, which he treats as the incumbent's blind spot, and it now spans cross-channel messaging, voice and video [1].
On the attack dataset as the real asset
Wohns describes holding "the largest data set of generated attacks in the world, and it's annotated by humans," calling it "the most valuable data set I've ever seen" [1]. Its first use is reinforcement learning for higher-efficacy attacks, which keeps the red team ahead. Its more interesting use is defensive: a triage unit trained on that attack data, and the ability to train novel defences that stop attacks in their path rather than only preparing users to recognise them [1]. He also sees the dataset opening onto attack origination and automated takedowns, all of it grounded in understanding what a high-efficacy attack looks like in this new age [1].
On an 85 to 90 percent unvended market
His macro read is that this category is barely served. "This market is still 85 to 90% unvented... it's absolutely stunning how underserved this market is globally" [1]. He points to over a billion dollars of breaches across Singapore, Korea and Japan in a matter of months as evidence of both the exposure and the opportunity, and cites a crypto fund in Taiwan and a major enterprise deployment in Japan among users [1]. The old seven billion dollar market has grown substantially with the attack surface and the proliferation of attacks [1].
The answer he built for that gap is a freemium model, which he was surprised nobody else offered given the problem affects everyone [1]. The reasoning is that individuals and SMBs were priced out of solutions that were previously gated, while direct-to-consumer cyber insurance is growing and often carries a requirement to use one, so the constraint is self-service rather than demand: "one click to set up a a full year of uh campaigns in less than 20 minutes" [1]. He is direct about the accessibility problem in security, where complexity and vendor sprawl deter the people who most need coverage [1].
On protecting people outside the enterprise
The question he says he gets most at speaking engagements is about grandparents and parents [1]. Where an aging population once faced a stack of postal mail, it now faces emails, SMS and voice calls, and he singles out Japan and Korea as places where demographics and attack volume intersect badly [1]. He treats this as a serious segment rather than a sentimental aside, precisely because these attacks are increasingly nation state sponsored and the victims have no professional reason to know what to look for [1].
On dual use and national security
Wohns frames the company's mission as protecting the world from threats created by generative AI, and describes founding it as "a moral imperative" once he had confirmed the size of the opportunity [1]. He notes Jericho is the only dual use technology in the field, and argues that alignment with national security is imperative to winning what he calls this war [1]. The threat data he cites supports the framing: attack proliferation over 4,000 percent, voice phishing up over 400 percent in the first half of 2024, and the North Korean campaigns targeting hiring that dominated conversation at Black Hat, all powered by the same core technology [1].
On building companies with AI
The through-line from his earlier work is that AI compresses timelines. He has discussed how AI is transforming product creation, collapsing processes that once took years and enabling faster, more adaptive business models [7], and he has spoken about combining programming with business strategy to move AI into mainstream use in finance and news organisations, and about what the founder role demands and the role models he looks to [3][4][7]. His path runs from building websites for local businesses as a teenager in Seattle through Rakuten and Agolo, where the machine learning and natural language processing foundations he now applies to cybersecurity were formed [7]. He observes that the same acceleration cuts both ways in the market, since products can now be built very quickly by very small teams [1].
Takeaways
- The decisive change is cost, not capability: generative tools mean attackers no longer need to burn expensive zero days when a convincing synthetic recording costs pennies [1].
- Template and persona-based phishing simulations are obsolete, because attacks are now assembled from breach data and leaked PII at spear-phishing granularity [1].
- Stop teaching people to detect AI-generated content: "just spotting something that generative does not equal an attack. What really equals an attack is an attack" [1].
- Jericho runs a red team that feeds a blue team, so simulated attacks generate contextual education tailored to a specific person's exposure and deliverable in under an hour [1].
- The human-annotated dataset of generated attacks powers both higher-efficacy red teaming and novel automated defences, with attack origination and takedowns as the next step [1].
- Wohns puts the market at 85 to 90 percent unvended and answers it with freemium self-service, targeting SMBs, cyber-insurance-driven demand and consumers, including aging populations in Japan and Korea [1].
Media & appearances
- The Security StrategistApple PodcastsIs Your Workforce Ready for AI-Driven Cyber Threats?"With every technological wave, technology weaponises very quickly. You can create targeted attacks at an unprecedented scale, a human-centric attack at a scale that's never been before humanly possible,” states Sage Wohns, CEO and Founder of Jericho Additional recording: The Security Strategist. Additional recording: The Security Strategist.
- The CyberVaultYouTubeHow can we secure the weakest links in the security chain... humans? The CyberVault with Sage WohnsSage Wohns, CEO and co-founder of Jericho Security, discusses how generative AI has created new threats in cybersecurity, explaining that attacks powered by AI can now be created at scale and low cost, targeting individuals with personalized spear-phishing based on leaked personal information and breach data. He describes Jericho's approach of using red team attacks combined with dynamic, targeted education to train users to recognize actual attack patterns rather than just identifying AI-generated content, and mentions the company maintains the largest dataset of generated attacks annotated by humans to develop novel defenses.
- Next Gen Case StudiesApple PodcastsHow Sage Wohns Leverages AI for Fast Growth in Cybersecurity and Business DevelopmentIn this episode of Next Gen Case Studies, host Devon Jones sits down with Sage Wohns, CEO and founder of Jericho Security. Sage shares his journey from founding his first business in the Seattle tech scene to his current work in cybersecurity, where Jericho Security uses artificial intelligence to combat phishing attacks powered by generative AI. Sage’s insights into using technology to accelerate business growth and stay ahead of cyber threats make this a fascinating conversation for anyone interested in tech-driven solutions. The episode kicks off with Sage's background, growing up in Seattle and how he began his journey in computer science and entrepreneurship. From building websites for local businesses as a teen to founding Jericho Security, Sage walks us through his evolution in the tech world. His early experiences at companies like Rakuten and Agolo helped form the foundation for his focus on machine learning and natural language processing, technologies he now leverages in cybersecurity. The conversation dives into how AI is revolutionizing product creation, speeding up processes that once took years, and enabling faster, more adaptive business models. Sage discusses how Jericho Security is using AI to identify and counter novel phishing attacks and other cyber threats.
- Absolute AIApple PodcastsSage Wohns | Getting to the Point of Mainstream AI UsageCo-Founder and CEO of Agolo, Sage Wohns, joins Melody on the podcast today to discuss his programming and business strategy experience and how he has combined them to advance the role of AI particularly in finance and news organizations. He also reveals the keys to the founder role in which he has excelled, and the role models whose example he feels are worthy of emulating. Absolute AI Homepage Innodata Agolo Homepage Additional recording: Absolute AI.
- Preventing AI-Enabled Spear Phishing at Scale with Jericho Security
CISO Series
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.