Conversations with security leaders in the UK and the United States.
5 Oct 2026 · 38 min
Killing the Foundation: The Broken Cyber Pipeline
Dr Cephas Mpungu, Programme Leader & Lecturer in Cyber Security at University of Winchester
A university cyber security programme leader explains why graduates struggle to break into the industry, how AI is quietly removing the junior tasks that used to build analyst judgement, and what students can do instead to stand out.
2 Oct 2026 · 22 min
It's Not the Tool, It's the Process
Bruno Bossola, Co-Founder & CTO at Meterian
Bruno Bossola explains why dependency and supply chain risk keeps slipping past security teams, and why the fix is rarely another scanner but a proper process across the whole development lifecycle. He also sets out why AI coding assistants are quietly reintroducing vulnerable libraries at scale.
30 Sept 2026 · 29 min
More Tech Isn't the Answer: The Human Factor in Cyber
Joe Hubback, Partner & CISO at Elixirr
Joe Hubback explains why cyber risk quantification only really works when it's built around reasonable worst case scenarios, why third party and OT risk are often more about people than technology, and why he believes the industry's biggest blind spot is behaviour, not tooling.
28 Sept 2026 · 53 min
Most Security Problems Are Really Access Control Problems
Thomas Owen, CISO at SoSafe
Thomas Owen explains why he sees almost all security failures as access control failures rooted in human identity, and how measurable, causal testing can actually shift intrinsic staff behaviour rather than just producing a click rate on a dashboard. He also sets out where AI has changed the economics of phishing and deepfakes, and where he draws the line between protecting staff and quietly surveilling them.
25 Sept 2026 · 30 min
Don't Sweat Quantum, Sweat Your Attack Surface
Alan Simpson, Field CISO at Rapid7
A field CSO who built SOC teams from the ground up explains why board risk numbers are more storytelling than maths, why supplier questionnaires are mostly theatre, and why the weakest link line about users is wrong.
23 Sept 2026 · 45 min
Stop Blaming Users: 25 Years Breaking Ships, Planes and Yachts
Campbell Murray, Founder and Chief Security Technology Officer at Sodium Cyber Ltd
A veteran penetration tester explains why legacy technology, rigid procurement cycles and marketing-driven security purchases leave ships, planes and industrial control systems exposed, and gives a grounded assessment of how much AI is really changing offensive security today.
18 Sept 2026 · 29 min
Phishing, AI and the SME Blind Spot
Ben Oldham, Co Founder & CTO at AgencyTech
A practical look at how small agencies can protect themselves against phishing and social engineering, why identity and MFA now matter more than network boundaries, and how to bring AI into a business without losing control of governance and data.
16 Sept 2026 · 24 min
No Defences: The Honest State of AI Security
Chris Jefferson, Co-Founder & CTO at Advai
Chris Jefferson explains why AI systems fail by design rather than by accident, where language models and vision systems break under attack, and why some of these weaknesses have no real defence. He also covers the practical risks of data leakage, AI generated code, and handing tasks to autonomous agents.
14 Sept 2026 · 32 min
The Bot Is Another Employee
Nick Proud, Chief Technology Officer at Nexbotix
A practical look at treating unattended bots as machine identities with their own attack surface, why supply chain hits like JLR change how automation vendors get access to client infrastructure, and where AI-assisted coding and zero trust claims fall short in real deployments.
9 Sept 2026 · 30 min
People, Patients and Ransomware: The Real NHS Threat
Daniel Kay, Cyber Security Manager at The Health Informatics Service
A look at what it actually takes to secure NHS trusts, from managing risk on medical devices that can't simply be patched to translating cyber threats into patient safety and financial terms a hospital board will act on. Covers supplier assurance, staff retention against private sector pay, and why the NHS is far less standardised than most people assume.
7 Sept 2026 · 29 min
The Signaling Layer: Telecom's Blind Spot Attackers Love
Dmitry Kurbatov, Co-Founder & CTO at SecurityGen
A look inside the signalling layer of mobile networks, the control plane attackers exploit while most cyber teams focus elsewhere, covering SS7 and Diameter weaknesses, why 5G security depends on the older generations it still connects to, and where accountability really sits for SIM swap fraud.
3 Sept 2026 · 35 min
Criminals Move at the Speed of Code, We Move at the Speed of Policy
Neil Catton, Fractional CTO - Criminals Move at the Speed of Code, We Move at the Speed of Policy at Global Consortium Group
A fractional CTO explains why most organisations adopt AI top-down for the wrong reasons, how ungoverned use of AI tools is creating a new class of data breach nobody has priced in, and why defenders operating at the speed of policy will always trail criminals operating at the speed of code.
26 Aug 2026 · 33 min
Why the Green Tick Lies: Cyber Security Is Not a Box You Buy
Jay George, CISO & Founder at Clear Loop Security
A long-time outsourced CISO explains why vulnerability backlogs pile up, why supplier questionnaires often achieve little, and why a single cyber risk number gives boards false comfort.
20 Aug 2026 · 23 min
Why AI Might Make Your Margins Worse, Not Better
Alex Munn, CTO at Propellant.Digital
A fractional CTO explains why AI's productivity gains are more modest than the hype suggests, why the same speed can quietly create serious security risks, and why cyber and operational risk need to be managed together.
13 Aug 2026 · 25 min
80% Biology, 20% Technology: Rethinking Cyber Defence
Andy Bates, CISO & Founder at StonesThro
Andy Bates unpacks what digital sovereignty actually means, why boards are fixating on AI while neglecting cyber basics.
6 Aug 2026 · 46 min
There is no such thing as Artificial Intelligence
Richard Bennett, Field CTO at IBM & HashiCorp
Richard Bennett explains why he thinks true artificial intelligence does not yet exist, and what that means for how organisations should think about agentic AI risk. He sets out why observability, orchestration and governance matter more than chasing the latest AI tool.