
Sign up to save your podcasts
Or


Are you ready for the cybersecurity incident that could bring your business to a standstill?
On this episode of Razorwire, I sit down with Marius Poskus, a CISO and vCISO, to tackle one of the most crucial yet overlooked aspects of information security: incident response. Whether you’re leading a cyber team, supporting your board, or simply keen to sharpen your readiness, we dig into what happens when your best defences fail and chaos strikes.
We talk about what actually happens when an incident hits and why polished policies on their own aren't enough. From the practical realities CISOs face at the sharp end of an incident, through the pitfalls of security theatre, to the importance of clear communications and building resilience, we get into the lessons the playbooks often miss. Marius and I talk through wargaming, learning from unexpected scenarios and how to empower teams to make tough decisions on the fly.
Key talking points:
Wargaming the Unthinkable:
What happens when your CEO dies? When your entire C-suite is on a plane for six hours and unreachable? When someone poisons the fish at a team dinner? Jim and Marius talk about why the most valuable wargaming exercises aren't the predictable ones. Testing unusual, uncomfortable scenarios is what exposes the single points of failure nobody thought about and builds the kind of muscle memory that no written policy can replace.
Decision-making Authority in Crisis:
One of Marius's contacts had a major ransomware incident and needed to hire 200 people within hours. The biggest problem wasn't the attack itself, it was getting budget approved and contracts signed fast enough. Learn why pre-agreed access to emergency funds, signing authority and the ability to bypass normal procurement processes can be the difference between a swift response and days of lost time.
Security Theatre and Why It Falls Apart Under Pressure:
Marius has been making waves on LinkedIn talking about companies that want the appearance of security rather than the real thing. In this episode, he and Jim get into why polished policies that have never been tested crumble the moment a real incident hits, how to tell the difference between genuine preparedness and box-ticking and what it actually takes to build an incident response capability that works when it matters.
Listen and step inside the mindset every cybersecurity professional needs before the worst happens.
On testing your plan:
"You never want to run through an incident response scenario first time when the real thing happens."
Marius Poskus
Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
SolarWinds
Cited as a high-impact security incident affecting third parties and requiring significant communication. https://www.solarwinds.com/
Professor Messer
Cited as a free educational resource for CompTIA courses.
https://www.professormesser.com/
Network Chuck
Mentioned as a well-known YouTuber focused on networking tutorials and resources.
https://www.youtube.com/c/NetworkChuck
CompTIA
Reference to a popular provider of IT and cybersecurity certifications.
https://www.comptia.org/
Y2K (Year 2000 problem)
Discussed as a past example of widespread incident response planning.
https://en.wikipedia.org/wiki/Year_2000_problem
Changi Jail
Historical site referenced during a discussion of resilience and decision-making under pressure.
https://en.wikipedia.org/wiki/Changi_Prison
Rorke’s Drift
Brought up as a historical account to learn about resilience.
https://en.wikipedia.org/wiki/Battle_of_Rorke%27s_Drift
Apollo 13 (“Houston, we have a problem”)
Referenced as an example of problem solving under extreme pressure with limited resources.
https://en.wikipedia.org/wiki/Apollo_13
US Military zombie apocalypse wargaming
Referenced as an example of creative scenario planning for incident response.
https://en.wikipedia.org/wiki/CONOP_8888
The Y-Files
Referenced as a source of conspiracy theories and unusual scenarios Jim enjoys.
https://www.youtube.com/@TheYFiles
Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
For more information about us or if you have any questions you would like us to discuss email [email protected].
If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
LinkedIn: Razorthorn Security
YouTube: Razorthorn Security
TikTok: Razorwire Podcast
Instagram: Razorwire Podcast
Twitter: @RazorThornLTD
Website: www.razorthorn.com
All rights reserved. © Razorthorn Security LTD 2025
By Razorthorn SecurityAre you ready for the cybersecurity incident that could bring your business to a standstill?
On this episode of Razorwire, I sit down with Marius Poskus, a CISO and vCISO, to tackle one of the most crucial yet overlooked aspects of information security: incident response. Whether you’re leading a cyber team, supporting your board, or simply keen to sharpen your readiness, we dig into what happens when your best defences fail and chaos strikes.
We talk about what actually happens when an incident hits and why polished policies on their own aren't enough. From the practical realities CISOs face at the sharp end of an incident, through the pitfalls of security theatre, to the importance of clear communications and building resilience, we get into the lessons the playbooks often miss. Marius and I talk through wargaming, learning from unexpected scenarios and how to empower teams to make tough decisions on the fly.
Key talking points:
Wargaming the Unthinkable:
What happens when your CEO dies? When your entire C-suite is on a plane for six hours and unreachable? When someone poisons the fish at a team dinner? Jim and Marius talk about why the most valuable wargaming exercises aren't the predictable ones. Testing unusual, uncomfortable scenarios is what exposes the single points of failure nobody thought about and builds the kind of muscle memory that no written policy can replace.
Decision-making Authority in Crisis:
One of Marius's contacts had a major ransomware incident and needed to hire 200 people within hours. The biggest problem wasn't the attack itself, it was getting budget approved and contracts signed fast enough. Learn why pre-agreed access to emergency funds, signing authority and the ability to bypass normal procurement processes can be the difference between a swift response and days of lost time.
Security Theatre and Why It Falls Apart Under Pressure:
Marius has been making waves on LinkedIn talking about companies that want the appearance of security rather than the real thing. In this episode, he and Jim get into why polished policies that have never been tested crumble the moment a real incident hits, how to tell the difference between genuine preparedness and box-ticking and what it actually takes to build an incident response capability that works when it matters.
Listen and step inside the mindset every cybersecurity professional needs before the worst happens.
On testing your plan:
"You never want to run through an incident response scenario first time when the real thing happens."
Marius Poskus
Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
SolarWinds
Cited as a high-impact security incident affecting third parties and requiring significant communication. https://www.solarwinds.com/
Professor Messer
Cited as a free educational resource for CompTIA courses.
https://www.professormesser.com/
Network Chuck
Mentioned as a well-known YouTuber focused on networking tutorials and resources.
https://www.youtube.com/c/NetworkChuck
CompTIA
Reference to a popular provider of IT and cybersecurity certifications.
https://www.comptia.org/
Y2K (Year 2000 problem)
Discussed as a past example of widespread incident response planning.
https://en.wikipedia.org/wiki/Year_2000_problem
Changi Jail
Historical site referenced during a discussion of resilience and decision-making under pressure.
https://en.wikipedia.org/wiki/Changi_Prison
Rorke’s Drift
Brought up as a historical account to learn about resilience.
https://en.wikipedia.org/wiki/Battle_of_Rorke%27s_Drift
Apollo 13 (“Houston, we have a problem”)
Referenced as an example of problem solving under extreme pressure with limited resources.
https://en.wikipedia.org/wiki/Apollo_13
US Military zombie apocalypse wargaming
Referenced as an example of creative scenario planning for incident response.
https://en.wikipedia.org/wiki/CONOP_8888
The Y-Files
Referenced as a source of conspiracy theories and unusual scenarios Jim enjoys.
https://www.youtube.com/@TheYFiles
Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
For more information about us or if you have any questions you would like us to discuss email [email protected].
If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
LinkedIn: Razorthorn Security
YouTube: Razorthorn Security
TikTok: Razorwire Podcast
Instagram: Razorwire Podcast
Twitter: @RazorThornLTD
Website: www.razorthorn.com
All rights reserved. © Razorthorn Security LTD 2025