Monday, 18 November 2019

Security Culture TV


A few years ago my friend Kai Roer and I got on Google Hangouts to talk about security awareness, behaviour and culture and we had some great guests join us. 

Now it's back and Kai invited me along to have a catch up, cheers bro! I'm looking forward to all the new guests, their perspectives and opinions.

You can check out the episode here and if you want to delve into the archives season one episodes are here. God I hate watching myself back!

Tuesday, 24 September 2019

Infosecurity Magazine Panel

Along with Flavius Plesu and Lauren Zink, I was invited by Info Security Magazine to be a panelist on their On Demand EMEA Online Summit.

Full agenda here: https://www.infosecurity-magazine.com/online-summits/online-summit-emea-fall-2019/

Our topic was "Building Brand Infosec: From Engaging with Employees to Driving Secure Behaviour" and I addressed the challenge of building a security champions network.

You can find the recording here and my slides are below:






Saturday, 6 July 2019

Transformational Security Awareness

During the SANS European Security Awareness Summit I had the pleasure of meeting Perry Carpenter he mentioned he was writing a book on security awareness and was going to include a section where he interviewed practitioners in the field and asked if I would like to be in it.

He explained the premise and the goal of the book and I said sure I'd be happy to be included. The book came out this summer and I've got to say he's done a great job. I would go so far as to say it's currently the best book on the topic.

Sunday, 16 June 2019

PeepSec 2019

Earlier this week I went across to Level 39 after I was invited by CybSafe to be a speaker at their annual online summit, PeepSec. The summit is focussed around opportunities and issues concerning people and technology.

They had some excellent speakers that I was humbled to be alongside. Here's the link to the main PeepSec page and a link to my interview with Oz Alashe and Sam Oliver.

Saturday, 22 December 2018

Restricted Intelligence Blog Series

I've known the good folk at Restricted Intelligence for a while now, I was in their offices recently as they had invited me in to provide a consultants perspective around information security awareness programmes.

During the visit they asked if I would write a blog series with some tips on how to increase the chances of running a perfect security awareness campaign.

Here are the links to the posts:

Part 1 - Understand your environment

Part 2 - Trust issues

Part 3 - Is you platform ready


Saturday, 8 December 2018

SANS European Security Awareness Summit

Last week, I had the privilege of presenting along Denise Beardon (Head of Information Security Engagement at Pinsent Masons) at the SANS European Security Awareness Summit.

Towards the end of 2017 Christian Toon (CISO at Pinsent Masons) asked if I could come onboard as an interim consultant to kick-start their information security engagement stream of work whilst he was searching for a permanent member of staff.

That permanent member of staff turned out to be Denise, we got along like a house on fire and together ran a firm wide security culture study to establish a baseline to measure behavioural change; the premise being that any security awareness, behaviour and culture programme must be built on solid foundations.

At the time I don't believe any other law firm in the UK had developed and run anything similar.

Denise and I got talking and decided we should do a talk together and the most obvious place was the Summit, so we submitted and were accepted!

This is a direct link to our presentation:

"Establishing a Baseline to Measure Behavioural Change"

Here's the link the landing page for the Summit archives




Friday, 2 November 2018

IISP Talking Head Piece - Security Culture


Over the last few years the discussion around security culture has come to the fore and having worked in and around this area for a while I welcome it; particularly when, one of the simplest ways to reduce risk to organisations is to have a security conscious workforce.

However, it is not as simple as proclaiming that you’re going to run a phishing or a digital footprints campaign and be done with it. As with everything in life there are fundamental activities that one need to address before just jumping into things. Here are a few recommendations to keep in mind when building your security culture programme:

Trust and Branding – How is your security function perceived across the business, do you have good levels of engagement or are you seen as the “department of no”? If the security function is not recognised as a trusted brand then you are building on poor foundations. A simple way to do this is (within reason) to share security metrics with the organisation e.g. incidents that you protected the business from and even where you failed. It humanises the team and can reap great benefits.

Understand your environment – A key task in your journey to build security culture is to understand existing attitudes and behaviours across your organisation. You cannot attempt to affect change in an environment where you are not sure on how people feel about security on a day-to-day basis.
Plan and run a security culture study. Typically, this is a combination of quantitative and qualitative data e.g. a survey combined with focus groups and one-to-one sessions with a subset of staff. This will provide insight into localised risk, ways of working across departments and inform your plan of activities.

Scaling your security function – Regardless of the size of your organisation, you can scale your security efforts buy establishing a network of individuals to help spread your message. Commonly referred to as champions, these volunteers are immensely powerful when utilised correctly. If you haven’t already thought about building such a network – think about it now!

Targeted and engaging activities

Lets be honest, asking staff to watch a ten-minute video and then do a quiz after it doesn’t work. Of course, they have their place but if your content, activities and campaigns aren’t targeted, engaging and memorable then you are wasting your time.  This is where a security culture study will help you understand what sort of content is best for your environment.

Looking ahead

Naturally, all organisations are different but fundamentally you should be aiming have some sort of alignment these recommendations.


We have to move away from the status quo security approach – we have to be more open, approachable, enabling and agile. Seek to deliver security-as-a-service, this in turn will help to affect a positive and lasting security culture across organisations.

This piece was included in the October 2018 edition of the IISP's Pulse magazine.