
11.7K
Downloads
158
Episodes
A podcast that takes a deeper look at today’s most important issues in cyber security, and beyond.
Episodes

May 18, 2021
May 18, 2021
29 min
Critical infrastructure is on the front line of cybersecurity.
An attack on power, sanitation, healthcare, or even the banking system, could be catastrophic. But it could happen.
Back in the 1990s, ethical hacker Joe Carson was already concerned about how a power outage could disrupt medical services.
Then, it was the Y2K bug that worried the experts.
Today it is state sponsored actors.
As chief security scientist and advisory CISO at Thycotic, Carson has pitted himself against CNI’s defences, and found them wanting.
But can, and should, we do more to create practices and norms to protect these vital services?

May 4, 2021
May 4, 2021
36 min
Is cyber a new war zone? Nation states account for a growing percentage of cyber attacks. And some experts warn that state-sanctioned hacking could spill over into an all-out cyber conflict, or worse still, outright war.
But is that overstating the risk? Will state actors hold back from attacks on sectors such as energy, or healthcare? Will they stop short of causing civil unrest, or is that their goal?
Cyber is now firmly part of the "grey zone" between peace and war, where norms and behaviours are only now starting to emerge.
What steps should governments, international bodies, and the cybersecurity industry itself take to stop an accidental cyber attack becoming an international incident?
Security Insights' Stephen Pritchard discusses this, and more, with Nominet Cyber's MD, David Carroll.

Apr 20, 2021
Apr 20, 2021
29 min
It's no longer a question of if you will be hacked.
It's when.
This makes rigorous security testing all the more important. And Red Team exercises, testing defences against an adversary in real time, is one of the most effective methods.
But Red Teaming can be demanding. How should CISOs engage a red team, and what is the best way to make the exercise effective?
In this special report, we speak to Gemma Moore, of Cyberis and CREST, David Benson, of Pen Test People, and Richard Hughes of A&O IT Group.
Reporter: Stephen Pritchard

Apr 6, 2021
Apr 6, 2021
29 min
Priorities for information security professionals in 2021 include insider threats, privacy, the risks posed by state actors and, of course, the aftermath of the pandemic.
In this episode, we speak to Forrester analyst Enza Iannopollo about her firm's latest security predictions - and how CISOs should deal with them.

Mar 23, 2021
Mar 23, 2021
29 min
The information security industry faces an ongoing skills shortage: globally, over 3m jobs are unfilled.
How, then, can we close the skills gap? One answer could be encouraging more career changers to consider the profession.
In this episode, we catch up with two people who have done just that: ex British Army communications specialist, turned pentester, Holly Grace Williams, and former professional cricketer, now security engineer, Charlie Shreck.

Mar 9, 2021
Mar 9, 2021
32 min
At the start of the pandemic, businesses started out on a journey that would transform the world of work for millions.
We invited CMA founder and CEO Amar Singh to discuss the steps organisations should take, to make that transformation as secure as possible.
A year on, how have organisations fared? Which measures have worked well, and which less well?
And what steps should CISOs take now to ensure organisations stay secure as, hopefully, we start to exit lockdowns?
One year on, Security Insights invited Amar Singh back, to discuss the lessons learned -- and what to do next.

Feb 23, 2021
Feb 23, 2021
29 min
Could the internet be safer if we trust no-one?
Trust and identity are bedrocks of security. But the erosion of a clear perimeter threatens conventional ways to secure data, applications and devices.
Zero Trust looks to replace reliance on perimeter defences with a more flexible, less intrusive and more effective form of security.
But how does it work, and does it bring risks as well as benefits? We ask Elliot Rose, of PA Consulting, Ian Pratt, from HP Personal Systems, Iben Rodriguez of Gigaom and Nico Fischbach of Forcepoint for their views.

Feb 9, 2021
Feb 9, 2021
30 min
Security training and security awareness only goes so far. Instead of annual tick box exercises, organisations should aim for a permanent shift in attitudes to security, argues our guest for this episode. They need to create a security culture.
Kai Roer is an author and security expert, and founder of security culture advisory firm CLT.re, now part of KnowBe4. He talks to host Stephen Pritchard about how we can make that shift.

Jan 26, 2021
Jan 26, 2021
30 min
Just one per cent of security spending goes on training and human factors, says Melanie Oldham.
Oldham is the founder of Bob's Business. Her security training company is best known for the eponymous Bob, a put-upon business exec who battles to secure his operation.
But Bob is not alone. This industry, Oldham argues, needs to strip away the complexity that too often surrounds cyber security.
And we need to focus less on hardware and technology, and more on the people who handle data. Non-technical users often make the best security champions. That, she says, will only be more important, as remote working becomes the norm.

Jan 12, 2021
Jan 12, 2021
30 min
If security is about people, process and technology, people are often the weakest link.
In this first of three episodes looking at security training, awareness and culture, Security Insights meets Simeon Quarrie, founder of Vivida, a company that uses virtual reality and storytelling to make security training more engaing.
