Skip to content
Artwork for Security Insights

Security Insights

securityinsights

A podcast that takes a deeper look at today’s most important issues in cyber security, and beyond.

Play
  • 20 episodes
  • fortnightly
  • Avg 30 min
  • English
  • S7 · E16
    Thursday · 29 min

    Cyber resilience: do boards fall short?

    A recent survey suggests that, in the UK at least, boards overestimate their organisations' ability to withstand a cyber attack. And they overstate their ability to recover from an incident, and restore even to minimum viable operations. What does that mean for security, and does it increase risk? And will pressure, from regulators, law makers, and even shareholders and investors, force boards to take cyber resilience more seriously, and view it at least on par with business continuity? Our guests are Paul Cragg, CTO at NormCyber, and Richard Beeston, Chief Operating Officer at Digital Space.

  • S7 · E15
    September 3 · 29 min

    AI: Cybsersecurity's friend, or foe?

    Recent incidents show the risks AI can pose to cybersecurity. At the same time, the security industry is putting a lot of store on AI as a way to bolster defences. So is AI a threat, or an answer to our security challenges? As the CEO of a business supplying security services to global organisations, our guest is well placed to discuss how CISOs view the risks, and benefits of artificial intelligence. And, as Raluca Saceanu, CEO of Smarttech247 puts it, there are those who are "all in" on AI, and those who view it with distrust. Interview by Stephen Pritchard.

  • S7 · E14
    August 20 · 29 min

    Hiding in silos: cyber and physical security

    Physical and cyber security are separate disciplines. But are they converging, and what can they learn from each other? Do changes in the threat landscape, from geopolitics to AI, mean physical and cyber teams need to work more closely together? And can a more joined-up approach to security improve operational resilience? Our guest is Cohesity's James Blake.

  • S7 · E13
    August 6 · 29 min

    Shadow IT, shadow AI: a new security frontier?

    Is shadow AI today as great a risk as shadow IT was over the last decade? And have we learned the security lessons from previous IT transformations, including BYOD and the cloud? In this episode, we discuss why unauthorised and uncontrolled AI tools pose growing threats to both security and data confidentiality. And we look at how agentic AI brings a whole new set of risks, as systems create their own connections without human oversight. How can cybersecurity leaders ensure the safe development of AI, without creating a whole new attack surface? Our guest is Simon Gooch, field CIO at Saviynt. Previously a director of security at Accenture, Simon has more than 25 years direct experience of cybersecurity and governance. Interview by Stephen Pritchard.

  • S7 · E12
    July 26 · 29 min

    AI vs CNI: Rob Demain, e2e-assure

    According to the NCSC, there were over 200 attacks against UK critical national infrastructure last year. Some three quarters of these are thought to be linked to state actors. On the surface, that number of attacks might seem small. But their impact could be significant. Attacks against power, water and transport can quickly bring the country to a halt. And no advanced economy can operate for long without banking and telecoms services. And the cyber risks faced by CNI operators are worsening, not least because of AI. As our guest explains, AI doesn't have to be smarter. It's enough that it's fast, works at scale, and doesn't need to take a break. This, in turn, demands a different response from cyber defenders, including their own sovereign AI capabilities. Our guest is Rob Demain, founder and CEO at e2e-assure.

  • S7 · E11
    July 9 · 29 min

    Disrupting a phishing group: an insider story

    In this episode, we hear how security researchers and law enforcement worked together to disrupt Tycoon 2FA, a phishing as a service group. How did they discover, and then counter the group's activities? And what were the results? Our guest is Robert McArdle, director of forward threat research at TrendAI.

  • S7 · E10
    June 25 · 32 min

    Cyber resilience, Resilient You

    In this episode we welcome back the Cyber Agony Aunts, Amelia Hewitt and Rebecca Taylor. As the UK's Cybersecurity and Resilience Bill works its way through Parliament, has the debate about cyber resilience changed? What does a resilient organisation look like? And above all, how do we create one, without putting cybersecurity professionals under extreme pressure? As Amelia and Rebecca explain in their second book, Resilient You, we need to take control of our own resilience and wellbeing, even as we try to build those more robust operations.

  • S7 · E9
    June 11 · 29 min

    Founder interview: Benny Czarny, OPSWAT

    Cybersecurity has its share of innovators, inventors and, of course, entrepreneurs. Benny Czarny created OPSWAT more than 20 years ago, to develop a common language for security applications. Today, the business is best known for its “firewall of data” approach to detecting and removing malware. In the first of an occasional series of interviews with founders, we speak to Czarny about his journey as an entrepreneur and as a business leader in cybersecurity. And we discuss his new book, Cybersecurity Upside Down.

  • S7 · E8
    May 28 · 29 min

    In plain sight: hunting secrets shared in code

    Security researchers have found millions of hard-coded secrets, in plain text, across both public and private code repositories. These include credentials, API keys, AI tokens and MCP configuration files. And AI is making the problem worse, with AI-assisted commits adding to this "secrets sprawl". Unless developers control how they manage secrets in their code, we are leaving the door open to malicious actors. And the growth of non-human identities (NHIs) only makes it worse. Our guest is Dwayne McDaniel, principal developer advocate at GitGuardian, which recently published their research into secrets sprawl.

  • S7 · E10
    May 14 · 29 min

    Security through community: Ameet Jugnauth, ISACA

    How can cybersecurity professionals "engineer" resilience? And why is an effective community an increasingly important part of our defence against cyber attacks? In this episide, editor Stephen Pritchard caught up with Ameet Jugnauth, president of ISACA's London Chapter at their recent conference. They discuss building resilience, why we have reached a tipping point in boards' understanding of cyber risk and why, despite a growing threat landscape, Jugnauth's outlook for the industry is positive.

  • S7 · E9
    May 1 · 29 min

    Resilience, recovery and living through a cyber attack: VNOG

    How do you live through a cyber attack, and recover from it? What lessons can you learn? And why is resilience moving up the cybersecurity agenda? In this special episode, we speak to Edwin Moraal, CISO at Dutch public safety body Veiligheidsregio Noord- en Oost-Gelderland (VNOG), about his experiences. And he's joined by Tim Pfaelzer, Veeam GM for EMEA, whose team helped with the recovery. However prepared you think you are, there are always lessons to learn.

  • S7 · E8
    April 16 · 29 min

    Quantum, cryptography and Q Day: are we ready?

    Soon, quantum computers will be able to decrypt "production grade" encryption, putting both privacy and security at risk. But how close is "Q Day", and is a cryptographically relevant quantum computer a realistic prospect? Is it something malicious actors will be able to obtain, and if so, how would they use it and what threat does that pose to confidentiality of our files, as well as our communications? Our guest today is Moona Ederveen, an author, speaker and consultant who has been studying the impact of quantum computing on security. Here, she discusses the scale of the threat, the steps organisations need to take to mitigate it, and why cybersecurity teams need to act with urgency. Listeners can also access the Post-Quantum Preparedness Framework mentions in the episode here.

  • S7 · E7
    April 2 · 29 min

    DDoS: complex attacks, persistent threats

    DDoS attacks have posed a threat since the late 1990s. And distributed denial of service attacks have proven to be hard to prevent, and to deter. Security teams are better at detecting and blocking DDoS attacks than they were. But malicious actors have not stood still. They are now using complex, multi-vector attacks rather than relying on volume alone; they are using AI to design attacks, and compromised IoT devices to launch them, according to research from NETSCOUT. In this episode, we look at how DDoS is evolving, and what CISOs can do to reduce their impact. Our guest is Darren Anstee, CTO for security at NETSCOUT.

  • S7 · E6
    March 19 · 28 min

    CISO Interview: Mike Baker, DXC Technology

    In this CISO interview, we discuss the role of a CISO in a global technology services business, the changing threat landscape -- from geopolitics to the growth of AI -- and the importance of skills, learning and cybersecurity education. Our guest is Mike Baker, vice president and global chief information officer at DXC Technology. Above all, he says, the CISO's role is to build a resilient team. Interview by Stephen Pritchard.

  • S7 · E5
    March 5 · 29 min

    Insights Interview: Haider Pasha, CSO EMEA and LATAM, Palo Alto Networks

    Over the last few years, we’ve seen the resurgence of geopolitics as a driver for cybersecurity, especially in Europe. But the return of war to the continent is just one factor changing CISOs’ views of risk. In this Insights Interview, we discuss developments in the threat landscape with Haider Pasha, CSO for EMEA at Palo Alto Networks, following the company’s recent Ignite event in London. As he describes it, Europe faces its own pressures, as malicious actors exploit differences between countries, their policies and even cultures. But security leaders in Europe, and elsewhere, also face challenges from AI, quantum computing, and a fragmented and increasingly complex regulatory landscape. So how do security teams close those gaps? Interview by Stephen Pritchard.

  • S7 · E4
    February 19 · 29 min

    Inside threat intelligence: Rafe Pilling, Sophos

    What, exactly, is threat intelligence? And how do CISOs use it? Security teams now have access to multiple sources of information on threats and threat actors. These come from industry, from law enforcement, and even their own networks and SOCs. But how effective is it against an ever-changing roster of adversaries? And how do CISOs become informed consumers of intelligence? We invited Rafe Pilling, director of threat intelligence at Sophos, to discuss how threat intelligence has developed, in the context of some of the recent attacks and threat groups.

  • S7 · E3
    February 5 · 31 min

    Sovereignty, resilience and data: Keepit CISO Kim Larsen

    What is digital sovereignty, how does it relate to data sovereignty, and to resilience? In this CISO Interview, we speak to Kim Larsen, CISO at Keepit, a service provider specialising in protecting data for SaaS applications. With a career spanning policing, government and the private sector, he has witnessed the growing influence of geopolitics on cybersecurity. And he suggests both businesses and public sector bodies need to think about not just where their data are, but how to guarantee access to their technology if the worst does happen. Interview by Stephen Pritchard

  • S7 · E2
    January 22 · 29 min

    Cybersecurity skills: a people shortage, or a skills gap?

    The cybersecurity skills gap might be narrowing. According to the latest Cybersecurity Workforce Study, from ISC2, CISOs are less concerned about the number of cyber professionals in their organisations. Instead, the focus is on whether they have the right mix of skills, to take on an increasingly complex threat landscape. We go through the results of the research, and what it might mean for cybersecurity professionals at all points in their careers, with ISC2's COO, Casey Marks. Interview by Stephen Pritchard

  • S7 · E1
    January 8 · 29 min

    Politics, geography, AI and cyber threats: 2026 and beyond.

    In the first episode of Series 7 of Security Insights,we welcome back Charl van der Walt, head of security research at Orange Cyber Defense. We discuss the key findings of his team's 2026 Security Navigator report, how AI is tipping the balance of power in favour of malicious actors, and why resilience and agility should be on the CISO's agenda for this year.

  • S6 · E24
    Dec 18, 2025 · 29 min

    Resilience in cyber: an agony aunt's view

    Cybersecurity is about building resilient organisations. But this is impossible without resilient people. Cyber defence is often a highly pressured working environment. And it can be lonely too. But if teams are unable to function at their best, attackers will exploit this. In the second of our two episodes on cyber resilience, we look at its human side. Our guests are Rebecca Taylor, threat intelligence knowledge manager and human intelligence researcher at Sophos, and Amelia Hewitt director of cyber consulting at Principle Defence. They're also known as the Cyber Agony Aunts. They discuss steps organisations, and individuals, can take to improve their resilience with Stephen Pritchard.

Showing 1–20 of 20 episodes