Episodes

3 hours ago
3 hours ago
Can a book hold the answers to our cybersecurity challenges?
Perhaps not. But a new book from the Information Security Group at Royal Holloway, University of London, sets out to act as a primer on cybersecurity.
The target audience is both those setting out on a career in the sector, or general readers who want to understand the core principles of cybersecurity.
The book is called Cyber Security Foundations: Fundamentals, Technology and Society, published by Kogan Page. In this episode, we ask three of it authors how it came into being, and how a written text can keep pace with a fast-changing security landscape.

Thursday May 22, 2025
Verizon's DBIR: tracking security threats
Thursday May 22, 2025
Thursday May 22, 2025
Verizon's Data Breach Investigations Report is one of the longest-running research studies in the industry.
This year's report is the 18th and tracks over 20,000 incidents and 12,000 breaches.
What changes are we seeing, and what can CISOs learn from the data?
Our guest is Ashish Khanna, who runs the security solutions and consulting practice at Verizon Business. Interview by Stephen Pritchard

Thursday May 08, 2025
Beyond the Titanic: Cybersecurity in Northern Ireland
Thursday May 08, 2025
Thursday May 08, 2025
In this episode, we look at the growth of the cybersecurity industry in Northern Ireland.
What are the reasons for its success, and why does cyber play an important part in Northern Ireland's post-industrial future? And why should CISOs look there for a source of talent?
Our guest is Simon Whittaker, chair of the steering committee for NI Cyber, and CEO of Vertical Structure, now part of Instil.

Thursday Apr 24, 2025
CISO Interview: Mandy Andress, Elastic
Thursday Apr 24, 2025
Thursday Apr 24, 2025
Our guest this week is Mandy Andress is CISO at Elastic.
Elastic describes itself as a “search AI company”, and is very much at the forefront of modernising enterprise technology.
A host of businesses use Elastic's tools behind the scenes to manage their data, for security and, of course, for AI.
As CISO, Mandy Andress has the dual responsibilities of keeping Elastic secure, and advising customers on security.
In this CISO interview, we hear about her route into cybersecurity and the pressures of dealing with the increasing intensity, or velocity of cyber attacks.
And we discuss why CISOs need to be more aware than ever of their role in providing security not just within their own organisations but across national infrastructure, and the wider economy.

Thursday Apr 10, 2025
Insights Interview: Claudia Natanson, UK Cyber Security Council
Thursday Apr 10, 2025
Thursday Apr 10, 2025
Dr Claudia Natanson is CEO at the UK Cyber Security Council.
The Council, which is funded by the Government's Department for Science, Innovation and Technology, acts as an umbrella body for a range of professional bodies in cybersecurity.
It is the organisation behind chartered status for cybersecurity professionals, sets standards and publishes an ethics code, and acts as a voice of the industry: quite a broad mission for an organisation that is only a few years old.
The Council is, though, very well placed to assess the health of the cybersecurity industry across the UK. And, as Dr Natanson says, it faces a number of challenges, including recruitment, retention, diversity, and ensuring organisations understand what they need from their cybersecurity teams.
But what, exactly, does pouring the perfect pint of Guinness have to do with a successful career in cyber?
Interview by Stephen Pritchard

Wednesday Mar 26, 2025
Episode 125: Insights Interview, with James Bore
Wednesday Mar 26, 2025
Wednesday Mar 26, 2025
Our guest for the 125th episode of Security Insights is James Bore.
A well-known industry figure and speaker on cybersecurity, James runs the family consultancy firm Bores. He's also an author, book publisher, cyber skills trainer and volunteer.
In this Insights Interview, he shares his forthright -- and sometimes controversial -- views on the way forward for cybersecurity, with editor Stephen Pritchard.
Does cybersecurity blame the victim? What is the relationship between trust and security? And why is investment in security sometimes a bad thing?

Thursday Mar 13, 2025
Why CISOs quit: cyber's leadership crisis
Thursday Mar 13, 2025
Thursday Mar 13, 2025
Are CISOs leaving the industry in droves?
One survey suggests that as many as one in four senior cybersecurity leaders plans to leave the profession.
The causes include growing responsibilities, increasingly severe threats and ever-greater regulatory burdens.
The result is stress and burn out, with CISOs constantly fighting fires. As one of our guests says, CISOs suffer from an "invisibility of success".
So what can we do? The first step is to recognise the problem; the second is to help CISOs build both organisational and individual resilience.
Our guests are Darren Williams, founder and CEO of BlackFog, which commissioned the research, and Peter Coroneos, founder of mental health not for profit Cybermindz.

Thursday Feb 27, 2025
Stress testing cyber defences
Thursday Feb 27, 2025
Thursday Feb 27, 2025
How far should you push security tests?
Sometimes, the answer is "to the limit".
In this episode we look at stress testing in cybersecurity. Putting systems under pressure is the only true way to check that they will work, as intended, during a cyber attack.
But how does stress testing differ from pentesting and cyber exercises? How far is too far, and how do security teams capture the right lessons from the testing process?
Our guests are Chris McKean, solutions specialist at NetApp, and Simon Edwards, founder and CEO at SE Labs.

Thursday Feb 13, 2025
Fighting Ransomware, with Raj Samani
Thursday Feb 13, 2025
Thursday Feb 13, 2025
Ransomware remains one of the greatest cyber threats to organisations. Certainly, it is the threat at the top of most boards' agendas.
The reasons are clear enough: ransomware damages reputations, as well as the balance sheet. in the worst case scenario, a business might never recover from an attack.
And ransomware itself is becoming more sophisticated, and so more dangerous. Groups have moved on from simple phishing and RDP attacks to exploiting zero days. And they are as likely to threaten to release confidential information, as they are to encrypt it.
As our guest suggests, ransomware has moved from an attack on availability to an attack on confidentiality.
When it comes to advising on the ransomware threat, few are better placed than Raj Samani. Senior vice president and and chief scientist at Rapid7, Raj is also chief innovation officer at the Cloud Security Alliance, a special adviser at the European Cybercrime Centre and a co-founder of No More Ransom.
Here he discusses the changing ransomware threat, and how organisations should act when they are attacked, with Stephen Pritchard.

Thursday Jan 23, 2025
The eye of the storm: dealing with a cyber crisis
Thursday Jan 23, 2025
Thursday Jan 23, 2025
What happens when a cyber attack hits? What is it like to be in the eye of the storm, and how can security teams prepare?
A cyber attack is inevitably a highly stressful situation for everyone involved. But planning and exercising goes a long way to at least manage that stress.
Our guest for this episode is Dan Potter, senior director for resilience and cyber drills at Immersive Labs. He also has over 15 years' experience working in resilience in the financial services sector.
As he says, no playbook or incident response plan will be fully effective, unless the business takes the time to test it - and learn the lessons from the exercises they run.