Akamai Research Team.
Security Researchers: Digital Fighters Series

Akamai: “The best research happens before everyone realizes there is a problem”

Maxim Zavodchik, Senior Director of Threat Research at Akamai, discusses "the next complex problem" for security researchers, as part of CTech’s Security Researchers series.

“The best research happens before everyone realizes there is a problem,” says Maxim Zavodchik, Senior Director of Threat Research at Akamai. “Staying ahead of that curve is what motivates us.” According to Zavodchik, Akamai’s security research is built around multiple elite teams as opposed to individual heroes, bringing together more than a hundred researchers.
Within Israel’s cyber companies are small, highly specialized teams trained to think like attackers, find vulnerabilities and stay ahead of a threat landscape increasingly accelerated by AI. In this series, we meet the individuals and teams who make up this frontline of cyber: the digital fighters.
1 View gallery
Akamai Research Team
Akamai Research Team
Akamai Research Team.
(Photo: Akamai)
“Our researchers include veterans from elite IDF offensive and defensive cyber units, as well as some of the industry's most respected security researchers,” Zavodchik explains, adding that the team will often prioritize raw talent over traditional resumes. “While many of us come from a background in offensive research, building defenses that can actually stop people like us is the real challenge, and that is what we do now.”
You can read the entire interview below.
ID Card Company name: Akamai Founders: Dr. Tom Leighton and Daniel Lewin Year of founding: 1998 Current number of employees: 11,000+
Company Description:
Akamai is a global cybersecurity and cloud computing company that powers and protects life online. While originally founded to solve the internet's early speed and reliability challenges, Akamai has leveraged its globally distributed computing platform to become a major force in enterprise defense. Today, its comprehensive suite of security solutions and threat intelligence protects critical data, infrastructure, and applications against sophisticated cyber threats.
About Akamai’s Security Research Team:
Akamai Security Research is built around multiple elite teams, not just individual heroes. We bring together more than a hundred researchers with different areas of expertise, distinct missions, and complementary skill sets. While that diversity matters, a major advantage is in the collaboration. The strongest research often happens when different teams, disciplines, and perspectives intersect.
What is your background in cyber, and what led you to specialize in security research?
Our teams’ background is rooted in a shared curiosity to deconstruct complex systems. While many of us come from a background in offensive research, building defenses that can actually stop people like us is the real challenge, and that is what we do now.
We are constantly motivated to operate at the bleeding edge of new technologies and emerging threats. This mindset is reflected in our diverse composition. Our researchers include veterans from elite IDF offensive and defensive cyber units, as well as some of the industry's most respected security researchers, providing broad perspectives that prevent us from being locked into a single methodology.
Many times, we will prioritize raw talent and potential over traditional resumes. Our ranks include everyone from former software engineers to individuals who made complete career transitions into cyber. This diverse blend of backgrounds is what fuels our most innovative research.
What does your security research team look like in action?
Our research typically starts with a question or hypothesis, often inspired by a trend we are observing in the threat landscape, or real-world security challenges observed in the field through our global telemetry. Sometimes we track emerging attacker techniques, while other times we proactively examine new technologies before they become common targets.
The methodology varies depending on the problem, but it generally combines data analysis at internet scale, experimentation, reverse engineering, proof-of-concept development, and close collaboration with our engineering teams.
One of the most exciting aspects of our work is discovering patterns that only become visible when you combine technical expertise with the amount of telemetry that Akamai processes globally. A strength of our organization is the organic collaboration between these cyber experts and data scientists who apply AI and machine learning to drive unique security outcomes.
So, what is the final product? The most important outcome is translating our research into real-world impact. This means defining and creating the next generation of protections within Akamai's products, as well as sharing our findings with the broader industry. We maintain a strong presence on large-scale global stages like Black Hat, DEF CON, and RSA Conference, alongside more specialized local events.
How does the research team influence your company at large?
Research starts with curiosity, but it is always guided by impact. Ultimately, our discoveries help shape Akamai's security portfolio, product priorities, intelligence feeds, and threat detection capabilities for customers around the world.
By collaborating closely with Akamai's product teams, we help Akamai anticipate where attackers are heading, ensuring we build proactive defenses rather than simply responding after attacks become widespread.
Furthermore, our research plays a key role in strengthening Akamai’s position as a cybersecurity leader, trusted by organizations including global financial institutions and e-commerce giants.
What has been your team’s most significant security discovery to date?
Rather than pointing to a single discovery, our greatest impact comes from consistently uncovering attacker techniques before they become widely understood, and translating those insights into better protection for our customers.
For example, our research teams recently presented at Black Hat and DEF CON, sharing major security vulnerabilities, novel attack techniques and complex security challenges, including Bring Your Own EDR and The Expanding Unicode Attack Surface. More recently, to help businesses stay proactive, we focused on emerging AI technologies and identified multiple critical vulnerabilities in Model Context Protocol (MCP) implementations including one assessed at CVSS 10.0.
What characterizes Akamai research most is the team’s ability to consistently uncover high-impact security gaps in the "soft underbelly" of emerging technologies for over more than a decade. Those findings helped organizations protect themselves proactively before flaws are weaponized, enabling them to safely experiment with and adopt new technologies.
The best research happens before everyone realizes there is a problem. Staying ahead of that curve is what motivates us.
Who or what is your 'Moby Dick'?
Our "Moby Dick" is not a specific attacker or a single vulnerability, but rather the next complex problem. This includes AI-native attack techniques, autonomous offensive tooling, emerging cloud architectures, shifting security boundaries, and new technologies that adversaries have not yet fully weaponized.
How would you characterize the competition between research teams today?
While there is always a natural competition to uncover the next big threat, we remain deeply connected to the broader security research community. Our researchers come from that community and actively contribute back to it through responsible disclosure, publications, open-source tooling, and ongoing collaboration.
Today, competition is more about speed, quality, and the ability to help customers securely navigate the AI revolution, rather than secrecy. The real race is among research teams to effectively adopt AI tools into their own methodologies. At the same time, they need to keep pace with the accelerating evolution of AI technologies and quickly understand the new attack surfaces that every new model, capability, or application introduces. And as attackers increasingly use AI to make their operations faster, more scalable, and more sophisticated, the teams that will lead are those that can continue to stay one step ahead.
What is your take on the future of the human security researcher?
The role of the security researcher is evolving with AI acting as a critical force multiplier. By investing heavily in AI-driven research capabilities, we can automate the most time-consuming parts of the process. This enables us to investigate vulnerabilities, attack paths, and massive technology ecosystems at a scale that was previously impractical.
Ultimately, AI will become an essential research partner, but human intuition, creativity, and collaborative judgment will remain the central drivers behind the most meaningful security discoveries.