
11.7K
Downloads
158
Episodes
A podcast that takes a deeper look at today’s most important issues in cyber security, and beyond.
Episodes

Oct 2, 2025
Oct 2, 2025
29 min
DDoS – or distributed denial of service attacks – remain a serious source of disruption across the internet.
DDoS attacks continue to grow in their frequency and volume. And increasingly, they’re aligned to geopolitical events.
A driver is sites offering “DDoS for hire”. The groups behind these sites even offer DDoS as a service attacks for free. But cybercrime groups are making use of AI too.
This is leading to what researchers at NETSCOUT describe as a “digital battlefield", with DDoS attacks overwhelming underprepared defenders.
Our guest is Richard Hummel, director of threat intelligence at NETSCOUT.

Sep 18, 2025
Sep 18, 2025
29 min
Is cybersecurity's skills crisis one of its own making?
And why have initiatives to close the skills gap made relatively little impact?
In this episode, our guests Thom Langford, of Rapid7, and Lee Munson, of the ISF, discuss career changes, hiring practices, certifications and what needs to change with editor Stephen Pritchard

Sep 4, 2025
Sep 4, 2025
29 min
Education is increasingly in the crosshairs for malicous actors. Along with other public sector bodies, schools, colleges and universities are being targeted for the information they hold, as well as for extortion and ransom.
What, then, can leaders in the sector do to bolster their defences, especially when budgets are under pressure?
Our guest is Joe Rooke, director of risk insights at Recorded Future’s Insikt Group.

Aug 21, 2025
Aug 21, 2025
31 min
In this episode, we discuss whether vulnerability scores are still a viable tool when it comes to measuring cyber threats.
Both CVEs and CVSS are core security tools. But, our guest this week argues, they are often misused. In a worst case scenario, they add little to effective defence, and can divert security teams from the real threats.
Tod Beardsley is VP of security research at runZero, is on the board of the CVE Project, and is a former official at CISA.

Aug 7, 2025
Aug 7, 2025
29 min
More than three quarters of security breaches result from human behaviour.
But as an industry, we focus far more on technical security measures, than on the human element.
Human risk management sets out to change this. Its proponents aruge that by measuring what people do on networks and systems, we create a much clearer picture of risk.
In fact, they say, the risks posed by people should be on the business' risk register.
And it's only with that picture that we can implement the controls, and measures such as security awareness and training. But human risk management goes far beyond anti-phishing campaigns.
Our guest is Ashley Rose, co-founder and CEO of Living Security.
With a background in both marketing and psychology, she’s setting out to help organisations move away from focusing on devices, and to a human-centric view of security.

Jul 24, 2025
Jul 24, 2025
29 min
Artificial intelligence is often described as a "black box". We can see what we put in, and what comes out. But not how the model comes to its results.
And, unlike conventional software, large language models are non-deterministic. The same inputs can produce different results.
This makes it hard to secure AI systems, and to assure their users that they are secure.
There is already growing evidence that malicious actors are using AI to find vulnerabilities, carry out reconnaissance, and fine-tune their attacks.
But the risks posed by AI systems themselves could be even greater.
Our guest this week has set out to secure AI, by developing red team testing methods that take into account both the nature of AI, and the unique risks it poses.
Peter Garraghan is professor at Lancaster University, and founder and CEO at Mindgard.
Interview by Stephen Pritchard

Jul 3, 2025
Jul 3, 2025
29 min
Non-human identities now vastly outnumber human actors on the internet, perhaps by as many as 50 to one.
APIs, online devices and service calls now dominate internet traffic, and access requests.
And this is only set to increase, with the rise of AI and AI agents.
Could we even see "robot wars" as AI agents take on AI defenders?
A lack of visibility, and a lack of control over machine identities is not just putting systems and networks at risk.
It is changing the whole concept of identity.
Now, it's no longer a question of who has access to our systems and data, but what. And the consequences for cybersecurity are far reaching.
Our guest is Art Gilliland, CEO at Delinea. Interview by Stephen Pritchard

Jun 19, 2025
Jun 19, 2025
29 min
Managing cybersecurity is increasingly about managing risk.
It's not possible to stop every attack or prevent every breach. So CISOs need to link the likelihood and impact of an incident to the damage it does to the organisation.
But do security teams understand business risk? And do business leaders fully appreciate the threat from cyber attacks?
Our guest is Richard Seiersen, chief risk technology officer at Qualys, as well as a researcher, author, entrepreneur and former CISO.

Jun 5, 2025
Jun 5, 2025
35 min
Can a book hold the answers to our cybersecurity challenges?
Perhaps not. But a new book from the Information Security Group at Royal Holloway, University of London, sets out to act as a primer on cybersecurity.
The target audience is both those setting out on a career in the sector, or general readers who want to understand the core principles of cybersecurity.
The book is called Cyber Security Foundations: Fundamentals, Technology and Society, published by Kogan Page. In this episode, we ask three of it authors how it came into being, and how a written text can keep pace with a fast-changing security landscape.

May 22, 2025
May 22, 2025
29 min
Verizon's Data Breach Investigations Report is one of the longest-running research studies in the industry.
This year's report is the 18th and tracks over 20,000 incidents and 12,000 breaches.
What changes are we seeing, and what can CISOs learn from the data?
Our guest is Ashish Khanna, who runs the security solutions and consulting practice at Verizon Business. Interview by Stephen Pritchard
