0:00
/

Find Your "Mona Lisa" Before the Hackers Do - #0091, Toni Samson

Arte Security's Toni Samson argues that protecting the right assets is more important than protecting more of them.

While I was recording an episode with Toni Samson, co-founder and CEO of Arte Security, she told me it was important for companies and CISOs to “find your Mona Lisas.” It made me remember how a few thousand kilometers away, the actual home of the actual Mona Lisa had learned that exact lesson the hard way.

Last October, thieves walked out of the Louvre with crown jewels worth more than $100 million. French investigators later found that only one of the two cameras covering the break-in point was even working, and staff didn’t have enough screens to watch the footage that did exist. The whole operation lasted minutes.

Imagine that: The Louvre, home to the most famous painting on earth, couldn’t tell you in real time what was happening to the jewels twenty feet away. It didn’t know where its own “Mona Lisa” was, so to speak.

And a few days ago its gallery finally reopened - this time, without the stolen jewels.

That’s the trap Toni was warning me about, except she wasn’t talking about paintings. Her metaphor was directed at CISOs who need to know the most important assets in their enterprise, and make sure those are more protected than just applying blanket protection over everything. “Find your Mona Lisas,” she said. “This is the most important. You will not be able to close everything. It’s too much. It will never be fast enough.”

The value of each asset varies by company. A shoe manufacturer’s factory floor matters more than its HR files. A bank’s Mona Lisa is the data itself, sitting in very specific places. “The question now is: How can I protect my most critical things? [Because] not everything is the Mona Lisa,” she said. “Not everything needs to be protected the same.”

This is where Arte’s own work gets specific. The company helps enterprises identify what parts of their data require more attention (and protection) than others. It then specializes and tailor-makes a solution that helps them protect their Mona Lisas from theft or hacking. The company was founded with co-founder and CTO Asaf Ohayon at the end of 2025, and Toni herself comes from a background in the Israeli Ministry of Defense as Director of Critical Infrastructure & Data Center Cybersecurity.

Another example may be a hyperscale AI data center, where its Mona Lisa isn’t necessarily a database. It might be the chiller controller. Bad actors wouldn’t even need to breach a firewall to take an AI cluster offline. All they would need to do is make the room too hot to run.

This sounds obvious until you actually try to do it. Security researchers estimate that roughly a third of large businesses can see less than three-quarters of their own assets at any given time: Think of it as the digital equivalent of a museum that isn’t sure how many rooms it has, let alone what’s in them.

I asked her to help me quantify it: how do you actually know which door is the one with the painting behind it? To distinguish between the Mona Lisas and what I called “The James Spiro Original Scribble”. Her answer was to identify what you’d protect first if you could only protect one thing, and build outward from there. “Make sure your Mona Lisa is protected,” she said, “and put it as number one priority.”

Every laptop or every forgotten API endpoint is indeed an attack surface or entry point. And for a long time, the instinct in cybersecurity has always been to try to lock all of them at once. But Toni’s point is that this instinct is now outdated, because when attackers can use AI to move at machine speed, treating every asset as equally precious means treating none of them as precious enough.

The Louvre is now spending close to a billion euros to build the actual Mona Lisa her own dedicated room. Most businesses won’t get that budget. CISOs will have to actually know where their Mona Lisa hangs before someone else finds out.

[Watch a preview: “Not everything is the Mona Lisa” — Cybersecurity priorities, explained]

Discussion about this video

User's avatar

Ready for more?