
Sign up to save your podcasts
Or


If organisations understand cyber risk, what does it actually take to turn awareness into action?
In this second part of our two-part special on institutional wilful blindness, host Darragh continues the conversation with leadership expert and author Margaret Heffernan, Professor Genevieve Liveley, Director of the Research Institute for Sociotechnical Cyber Security (RISCS), and Kathryn, Head of Social Sciences at NCSC.
Building on the themes explored in part one, the panel examines what prevents organisations from acting even when the risks are clear, and how leaders can create environments where cyber resilience becomes part of everyday decision-making. The discussion explores the balance between accountability and blame, the importance of curiosity and challenge in organisational culture, and why resilience is about more than technology alone.
Together, they consider what effective leadership looks like in the face of uncertainty, how organisations can overcome complacency, and the practical steps that help move cyber security from a recognised priority to meaningful action.
Looking ahead, the conversation explores what truly resilient organisations have in common, and how culture, people and technology can work together to strengthen cyber resilience over the long term.
If you enjoyed this episode, please do consider leaving us a review. Follow the podcast in your app so you are notified when we release future episodes, and why not share the show with a friend or colleague who might be interested in the topics discussed today? To learn more about building cyber resilience in your organisation, head to ncsc.gov.uk.
If organisations know cyber risk is real, why do so many still fail to act before it’s too late?
In this first part of a two-part special on institutional wilful blindness, host Darragh is joined by leadership expert and author Margaret Heffernan, Professor Genevieve Liveley, Director of the Research Institute for Sociotechnical Cyber Security (RISCS), and Kathryn, Head of Social Sciences at NCSC.
Together, they explore why organisations often recognise cyber risks but struggle to respond effectively, and how leadership, culture and behaviour can create a gap between awareness and action. The discussion examines the stories and metaphors we use to talk about cyber security, and how these shape the way leaders understand threats, communicate uncertainty and influence decision-making.
Looking beyond technology, the panel considers what resilient organisations look like in practice, how leaders can foster cultures that challenge complacency, and what practical steps organisations can take to move from simply understanding cyber risk to taking meaningful action.
Part two will continue the conversation, exploring how organisations can translate these ideas into lasting change and stronger cyber resilience.
If you enjoyed this episode, please do consider leaving us a review. Follow the podcast in your app so you are notified when we release future episodes and why not share the show with a friend or colleague who might be interested in the topics discussed today.To learn more about building cyber resilience in your organisation, head to ncsc.gov.uk.
What if the biggest artificial intelligence disaster in cyber security isn't an external hack, but a defensive AI system co-opted by an insider?
Welcome to the latest episode of the National Cyber Security Center's refreshed podcast, where host Darragh unpacks the revolutionary force of AI. Joined by The Economist’s Alex Hern, NCSC CTO Ollie Whitehouse, and Deputy CTO Peter Hague, the panel dives into the realities of an incredibly hyped technology.
Together, they explore the central tension of AI acting as a "productivity enhancer for the problem factory as well as the solution factory," accelerating the capabilities of both attackers and defenders.
The discussion examines the economics of cyber warfare, warning that well-funded attackers might overpower under-resourced utilities by treating AI as a system for "turning pounds into vulnerabilities." The experts break down the lethal trifecta of AI integration: hooking systems to untrusted content, granting access to internal secrets, and enabling external communication.
To counter these threats, organisations must shift their risk management perspective, treating an AI system like an employee with specific, limited permissions rather than an infallible, godlike addition to the tech stack.
Looking ahead, the guests forecast that an organisation's AI adaptability will be intrinsically linked to its existing cyber resilience. While integrating AI as a defensive tool will unearth latent vulnerabilities at an unprecedented scale, it cannot act as a panacea to bypass basic security hygiene. The panel leaves business leaders with a critical reminder: until fundamentals like patching equipment, managing identities, and implementing multi-factor authentication are mastered, AI will simply exploit these familiar attack vectors at a much more efficient and dangerous scale.
If you enjoyed this episode, please do consider leaving us a review. Follow the podcast in your app so you are notified when we release future episodes and why not share the show with a friend or colleague who might be interested in the topics discussed today.
In this episode of Cyber Series, we explore the foundations of effective cyber security with experts Mary Haigh (BAE Systems), Emma Philpott (IASME Consortium), and Chris Ensor (NCSC).
They discuss the purpose of Cyber Essentials, the five core technical controls, and why “getting the basics right” remains a challenge for organisations of all sizes.
From practical implementation tips to tackling ransomware and myths around Cyber Essentials, this episode highlights how businesses and government can work together to build resilient cyber practices. Learn how Cyber Essentials helps organisations protect themselves and their supply chains, and what the future holds for this vital UK standard.
In this episode of Cyber Series, Darragh sits down with Dr Jeremy Bradley (Principal TD for Crypt and High Threat Technologies), and Flo D (Deputy CTO for Cyber Policy, NCSC-CAP) to explore what “the quantum threat” really means and how organisations should prepare.
From international standards and timelines for migration, to challenges facing critical national infrastructure, our guests break down the opportunities and obstacles of post-quantum cryptography.
Whether you’re a CISO, IT leader, or simply curious about the future of cyber security, this conversation sheds light on the steps we all need to take as we enter the quantum era.
What does it mean to be a cyber professional today? In this episode, we explore how professional standards are shaping the field with guests from the Bank of England.
From qualifications to cross-sector collaboration, we unpack what’s needed to thrive in a complex threat landscape.
When a cyber incident hits, what you say and how you say it can make all the difference. In this episode of The Cyber Series, we’re joined by Nicola Hudson, Partner at Brunswick and Global Lead for Cybersecurity, Data & Privacy, and Beth Maundrill, Editor at Infosecurity Magazine.
Together, we unpack why strong communication is vital during a crisis, common mistakes organisations make, and how to prepare your messaging strategy before an incident strikes. From leadership’s role to the risks and rewards of social media, this is essential listening for anyone involved in incident response.
Want to learn more about handling effective communications in a cyber crisis? Take a look at our guidance: https://www.ncsc.gov.uk/files/NCSC-Guidance-on-effective-communications-in-a-cyber-incident.pdf?utm_source=spotify&utm_medium=podcast&utm_campaign=NCSC_Cyber_Series_comms_in_an_incident_podcast
In this episode, we are joined by Ollie Whitehouse NCSC CTO, and Google VP Cyber Security Resilience Officer, Heather Adkins to unpack passkeys.
They break down what passkeys are, why they matter, and how they’re being adopted across industries. From user experience to cost savings and security, this episode explores the future of authentication and why it might be time to move on from passwords.
Check out the NCSC’s blog on passkeys for more: https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better?utm_source=spotify&utm_medium=podcast&utm_campaign=ncsc_cyber_series_podcast_passkeys.
In this episode, we sit down with Richard Horne, our CEO, as he reflects on his first 100 days in the role.
From surprises and challenges to insights on the evolving cyber security landscape, Richard shares his experiences and key takeaways from his time in post. Tune in for an inside look at his journey so far!
Welcome to Artificial Intelligence! In this episode we’re
Discover how we’re preparing the workforce for AI’s
From the publisher's feed

2,104 Listeners

375 Listeners

653 Listeners

1,029 Listeners

318 Listeners

180 Listeners

314 Listeners

191 Listeners

73 Listeners

203 Listeners

139 Listeners

3,041 Listeners

47 Listeners

188 Listeners

58 Listeners