How the San Francisco 49ers keep cyberattackers at bay
Secure the ball, pass, and enterprise.
• 3 min read
AI agents are starting to do more than access systems. They can invoke tools, execute workflows, and take action across business applications. As that autonomy grows, IT needs visibility into what each agent is allowed to do, what it actually did, who owns it, and how to revoke access when needed. Learn how JumpCloud helps govern AI agents alongside human and device identities.
It’s football season, and opposing NFL teams have more in common with cyberattackers than one might think—for one, they both want to rush the other team into a bad decision.
The San Francisco 49ers, pairing with cybersecurity company Doppel, is one football team trying to avoid fumbling their cyber defenses. The team’s new platform attempts to identify digital risks such as impersonation threats and brand attacks, train staff via AI-driven security simulations, and stop threats to email security.
Costa Kladianos, EVP of technology at the 49ers at Levi’s Stadium, told IT Brew that, instead of outsourcing its cybersecurity to multiple vendors, the organization opted for a holistic platform with one vendor so that they could ensure that “the platforms were talking to each other.”
“You have to come at it with the education, incredibly important, with the technical controls,” Kladianos said. “You want to have many layers, and you want all of them to work together.”
A good defense. What happens if training and awareness fails an organization? That’s exactly what Kladianos was wondering when looking for the best ways to counter social engineering threats.
“Social engineering is incredibly good, so you want to make sure that those controls are in place that can catch it when the user training isn’t enough, but you still have to have those trainings,” Kladianos said. “You still have to have the technical controls, you have to have email controls.”
Doppel’s CEO Kevin Tian stated that Doppel utilizes three cybersecurity pillars:
- Threat intel for brand or executive threats
- Training that includes agentic simulation of attacks
- Email security for detection and mitigation
Comparing playbooks. It’s no secret that sports face rampant cybersecurity threats. In June, cyber firms and organizations flagged potential threats surrounding the World Cup, advising both organizations and fans against social engineering attempts.
Kladianos said the 49ers want to keep the franchise’s reputation and security high.
“We have to be forward-leaning, but also our leadership is incredibly supportive,” Kladianos said. “They understand the importance of securing our fans, securing our players, and they give me the resources needed to do what we need to do to keep everyone safe.”
The playbook. While there are many ways an attacker can exploit an enterprise, Tian suggests IT professionals consider the most likely ways an attacker can infiltrate an organization.
“Not just for NFL teams, not just for sports teams, but for really all enterprises…it starts with social engineering,” Tian said. “Because the unit economics is so much better than trying to come up with a brand new zero-day exploit, or to try to find something broken in infrastructure.”
About the author
Caroline Nihill
Caroline Nihill is a reporter for IT Brew who primarily covers cybersecurity and the way that IT teams operate within market trends and challenges.
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
