Skip to content
ISO 9001 Certified·
Cyber Essentials Certified·
REC Corporate Member·
Public Sector Framework Supplier·
UK Wide
The Invitise podcast

Cyber Heard

The cyber angle on tech and AI. Real conversations, no scripts, no sales pitch, no corporate answers.

The angle is cyber, but the guest list is the whole of tech: founders, CEOs and CTOs alongside CISOs, security architects and SOC analysts. What is actually happening with cyber and AI, where the industry gets it wrong, and what it means for anyone building or running technology in the UK or the United States. New episodes post weekly, and every one is published on this page.

A hooded interviewer with 'Cyber Heard' on the chest, holding a microphone, asking a knight in armour 'So... what keeps you up at night?'. The knight replies 'Everything.'

Latest episode

7 Oct 2026 · 29 min

The CISO Who Says GRC Is Broken

Jake Bernardes, CISO at Gambit Security

A CISO explains why point-in-time compliance gives a false sense of assurance, how to answer the board's exposure question without hiding behind a heat map, and where AI is genuinely helping security teams connect data that used to sit in silos.

More episodes

Conversations with security leaders in the UK and the United States.

5 Oct 2026 · 38 min

Killing the Foundation: The Broken Cyber Pipeline

Dr Cephas Mpungu, Programme Leader & Lecturer in Cyber Security at University of Winchester

A university cyber security programme leader explains why graduates struggle to break into the industry, how AI is quietly removing the junior tasks that used to build analyst judgement, and what students can do instead to stand out.

2 Oct 2026 · 22 min

It's Not the Tool, It's the Process

Bruno Bossola, Co-Founder & CTO at Meterian

Bruno Bossola explains why dependency and supply chain risk keeps slipping past security teams, and why the fix is rarely another scanner but a proper process across the whole development lifecycle. He also sets out why AI coding assistants are quietly reintroducing vulnerable libraries at scale.

30 Sept 2026 · 29 min

More Tech Isn't the Answer: The Human Factor in Cyber

Joe Hubback, Partner & CISO at Elixirr

Joe Hubback explains why cyber risk quantification only really works when it's built around reasonable worst case scenarios, why third party and OT risk are often more about people than technology, and why he believes the industry's biggest blind spot is behaviour, not tooling.

28 Sept 2026 · 53 min

Most Security Problems Are Really Access Control Problems

Thomas Owen, CISO at SoSafe

Thomas Owen explains why he sees almost all security failures as access control failures rooted in human identity, and how measurable, causal testing can actually shift intrinsic staff behaviour rather than just producing a click rate on a dashboard. He also sets out where AI has changed the economics of phishing and deepfakes, and where he draws the line between protecting staff and quietly surveilling them.

25 Sept 2026 · 30 min

Don't Sweat Quantum, Sweat Your Attack Surface

Alan Simpson, Field CISO at Rapid7

A field CSO who built SOC teams from the ground up explains why board risk numbers are more storytelling than maths, why supplier questionnaires are mostly theatre, and why the weakest link line about users is wrong.

23 Sept 2026 · 45 min

Stop Blaming Users: 25 Years Breaking Ships, Planes and Yachts

Campbell Murray, Founder and Chief Security Technology Officer at Sodium Cyber Ltd

A veteran penetration tester explains why legacy technology, rigid procurement cycles and marketing-driven security purchases leave ships, planes and industrial control systems exposed, and gives a grounded assessment of how much AI is really changing offensive security today.

18 Sept 2026 · 29 min

Phishing, AI and the SME Blind Spot

Ben Oldham, Co Founder & CTO at AgencyTech

A practical look at how small agencies can protect themselves against phishing and social engineering, why identity and MFA now matter more than network boundaries, and how to bring AI into a business without losing control of governance and data.

16 Sept 2026 · 24 min

No Defences: The Honest State of AI Security

Chris Jefferson, Co-Founder & CTO at Advai

Chris Jefferson explains why AI systems fail by design rather than by accident, where language models and vision systems break under attack, and why some of these weaknesses have no real defence. He also covers the practical risks of data leakage, AI generated code, and handing tasks to autonomous agents.

14 Sept 2026 · 32 min

The Bot Is Another Employee

Nick Proud, Chief Technology Officer at Nexbotix

A practical look at treating unattended bots as machine identities with their own attack surface, why supply chain hits like JLR change how automation vendors get access to client infrastructure, and where AI-assisted coding and zero trust claims fall short in real deployments.

9 Sept 2026 · 30 min

People, Patients and Ransomware: The Real NHS Threat

Daniel Kay, Cyber Security Manager at The Health Informatics Service

A look at what it actually takes to secure NHS trusts, from managing risk on medical devices that can't simply be patched to translating cyber threats into patient safety and financial terms a hospital board will act on. Covers supplier assurance, staff retention against private sector pay, and why the NHS is far less standardised than most people assume.

7 Sept 2026 · 29 min

The Signaling Layer: Telecom's Blind Spot Attackers Love

Dmitry Kurbatov, Co-Founder & CTO at SecurityGen

A look inside the signalling layer of mobile networks, the control plane attackers exploit while most cyber teams focus elsewhere, covering SS7 and Diameter weaknesses, why 5G security depends on the older generations it still connects to, and where accountability really sits for SIM swap fraud.

3 Sept 2026 · 35 min

Criminals Move at the Speed of Code, We Move at the Speed of Policy

Neil Catton, Fractional CTO - Criminals Move at the Speed of Code, We Move at the Speed of Policy at Global Consortium Group

A fractional CTO explains why most organisations adopt AI top-down for the wrong reasons, how ungoverned use of AI tools is creating a new class of data breach nobody has priced in, and why defenders operating at the speed of policy will always trail criminals operating at the speed of code.

26 Aug 2026 · 33 min

Why the Green Tick Lies: Cyber Security Is Not a Box You Buy

Jay George, CISO & Founder at Clear Loop Security

A long-time outsourced CISO explains why vulnerability backlogs pile up, why supplier questionnaires often achieve little, and why a single cyber risk number gives boards false comfort.

20 Aug 2026 · 23 min

Why AI Might Make Your Margins Worse, Not Better

Alex Munn, CTO at Propellant.Digital

A fractional CTO explains why AI's productivity gains are more modest than the hype suggests, why the same speed can quietly create serious security risks, and why cyber and operational risk need to be managed together.

13 Aug 2026 · 25 min

80% Biology, 20% Technology: Rethinking Cyber Defence

Andy Bates, CISO & Founder at StonesThro

Andy Bates unpacks what digital sovereignty actually means, why boards are fixating on AI while neglecting cyber basics.

6 Aug 2026 · 46 min

There is no such thing as Artificial Intelligence

Richard Bennett, Field CTO at IBM & HashiCorp

Richard Bennett explains why he thinks true artificial intelligence does not yet exist, and what that means for how organisations should think about agentic AI risk. He sets out why observability, orchestration and governance matter more than chasing the latest AI tool.

Get new episodes and articles by email

One short email per release, nothing else. Unsubscribe any time.

COMMON QUESTIONS

About the podcast

The questions listeners and would-be guests ask us most.

Which UK Cyber Security podcasts are worth listening to?

Cyber Heard is a good place to start if you want the UK perspective without the marketing. Each episode is a relaxed conversation with a security leader or frontline practitioner about what is actually happening in their world: the threats they are dealing with, where the industry gets it wrong, the impact of AI, and what they would tell someone starting out today. New episodes post weekly.

Is Cyber Heard a UK podcast or a US one?

Both. The show started in the UK and we run a New York desk, so we welcome guests from either side of the Atlantic. The subject matter travels further than people expect: ransomware, board reporting, the shortage of good engineers and what AI is really doing to security work are the same conversations in London and New York. Where they genuinely differ, which is mostly regulation, hearing both is more useful than hearing one.

What is different about security in the US and the UK?

The work is close to identical; the rules around it are not. A New York security leader is dealing with NYDFS Part 500 certifications and SEC disclosure timelines, while a UK counterpart is dealing with the NIS regulations, the ICO and Cyber Essentials. Hiring differs too: notice periods here, at-will employment there. Guests from both markets tend to find the other side's constraints more interesting than their own.

What is Cyber Heard?

Cyber Heard is the invitise podcast: the cyber angle on tech and AI. The lens is always cyber, but the show is made for anyone in tech with an opinion on where cyber and AI are taking us. No scripts, no sales pitch, no corporate answers. It began as written interviews on LinkedIn and grew into a full podcast, and every episode is published on this page.

Where can I listen to Cyber Heard?

On Spotify, Apple Podcasts and YouTube, or through the RSS feed if you use another podcast app. Every episode is also published on this page, so you can watch or listen without leaving the site.

Who appears on Cyber Heard?

People from across tech in the UK and the United States, not just the security corner of it: founders, CEOs, CTOs and development leaders alongside CISOs, security architects, SOC analysts and frontline practitioners. What they share is an opinion on cyber and AI and what it means for their world. Guests speak as themselves rather than reading corporate lines, which is what keeps the conversations honest.

How do I become a guest on Cyber Heard?

Email cyberheard@invitise.com. If you work in tech and have something to say about cyber or AI, we would love to hear it, wherever you are based in the UK or the United States. You do not need to be a security specialist. Episodes are relaxed conversations, not interrogations, and there is no script to follow.

The 24-hour rule. Why slow Cyber Hiring is now a board risk. Cover and sample spreads of the invitise executive briefing.
New executive briefing · May 2026

The 24-hour rule Why slow Cyber Hiring is now a board risk

A 16-page invitise briefing for cyber, risk and people leaders. Why the hiring window has narrowed, what 24-hour mobilisation actually requires, and the four conditions that have to be true for next-morning on-site to mean something.

55%

of senior cyber roles take 6 months or longer to fill in the UK.

46 days

longer than other IT roles, senior cyber vacancies stay open.

68%

of large UK businesses now own cyber at board level.

We'll email you the PDF. No marketing list. See our privacy policy. Protected by Cloudflare Turnstile.