NCSC Cyber Series

NCSC Cyber Series

By National Cyber Security CentreTechnology
Download on the App Store

NCSC Cyber Series episodes

  • Institutional Wilful Blindness: Part 2

    If organisations understand cyber risk, what does it actually take to turn awareness into action?

    In this second part of our two-part special on institutional wilful blindness, host Darragh continues the conversation with leadership expert and author Margaret Heffernan, Professor Genevieve Liveley, Director of the Research Institute for Sociotechnical Cyber Security (RISCS), and Kathryn, Head of Social Sciences at NCSC.

    Building on the themes explored in part one, the panel examines what prevents organisations from acting even when the risks are clear, and how leaders can create environments where cyber resilience becomes part of everyday decision-making. The discussion explores the balance between accountability and blame, the importance of curiosity and challenge in organisational culture, and why resilience is about more than technology alone.

    Together, they consider what effective leadership looks like in the face of uncertainty, how organisations can overcome complacency, and the practical steps that help move cyber security from a recognised priority to meaningful action.

    Looking ahead, the conversation explores what truly resilient organisations have in common, and how culture, people and technology can work together to strengthen cyber resilience over the long term.

    If you enjoyed this episode, please do consider leaving us a review. Follow the podcast in your app so you are notified when we release future episodes, and why not share the show with a friend or colleague who might be interested in the topics discussed today? To learn more about building cyber resilience in your organisation, head to ⁠ncsc.gov.uk⁠.

    28 min
  • Institutional Wilful Blindness

    If organisations know cyber risk is real, why do so many still fail to act before it’s too late?

    In this first part of a two-part special on institutional wilful blindness, host Darragh is joined by leadership expert and author Margaret Heffernan, Professor Genevieve Liveley, Director of the Research Institute for Sociotechnical Cyber Security (RISCS), and Kathryn, Head of Social Sciences at NCSC.

    Together, they explore why organisations often recognise cyber risks but struggle to respond effectively, and how leadership, culture and behaviour can create a gap between awareness and action. The discussion examines the stories and metaphors we use to talk about cyber security, and how these shape the way leaders understand threats, communicate uncertainty and influence decision-making.

    Looking beyond technology, the panel considers what resilient organisations look like in practice, how leaders can foster cultures that challenge complacency, and what practical steps organisations can take to move from simply understanding cyber risk to taking meaningful action.

    Part two will continue the conversation, exploring how organisations can translate these ideas into lasting change and stronger cyber resilience.

    If you enjoyed this episode, please do consider leaving us a review. Follow the podcast in your app so you are notified when we release future episodes and why not share the show with a friend or colleague who might be interested in the topics discussed today.To learn more about building cyber resilience in your organisation, head to ncsc.gov.uk.

    28 min
  • The New AI Reality

    What if the biggest artificial intelligence disaster in cyber security isn't an external hack, but a defensive AI system co-opted by an insider? 

    Welcome to the latest episode of the National Cyber Security Center's refreshed podcast, where host Darragh unpacks the revolutionary force of AI. Joined by The Economist’s Alex Hern, NCSC CTO Ollie Whitehouse, and Deputy CTO Peter Hague, the panel dives into the realities of an incredibly hyped technology.


    Together, they explore the central tension of AI acting as a "productivity enhancer for the problem factory as well as the solution factory," accelerating the capabilities of both attackers and defenders.


    The discussion examines the economics of cyber warfare, warning that well-funded attackers might overpower under-resourced utilities by treating AI as a system for "turning pounds into vulnerabilities." The experts break down the lethal trifecta of AI integration: hooking systems to untrusted content, granting access to internal secrets, and enabling external communication.


    To counter these threats, organisations must shift their risk management perspective, treating an AI system like an employee with specific, limited permissions rather than an infallible, godlike addition to the tech stack.


    Looking ahead, the guests forecast that an organisation's AI adaptability will be intrinsically linked to its existing cyber resilience. While integrating AI as a defensive tool will unearth latent vulnerabilities at an unprecedented scale, it cannot act as a panacea to bypass basic security hygiene. The panel leaves business leaders with a critical reminder: until fundamentals like patching equipment, managing identities, and implementing multi-factor authentication are mastered, AI will simply exploit these familiar attack vectors at a much more efficient and dangerous scale.


    If you enjoyed this episode, please do consider leaving us a review. Follow the podcast in your app so you are notified when we release future episodes and why not share the show with a friend or colleague who might be interested in the topics discussed today. 

    37 min
  • Cyber Essentials

    In this episode of Cyber Series, we explore the foundations of effective cyber security with experts Mary Haigh (BAE Systems), Emma Philpott (IASME Consortium), and Chris Ensor (NCSC).

    They discuss the purpose of Cyber Essentials, the five core technical controls, and why “getting the basics right” remains a challenge for organisations of all sizes.

    From practical implementation tips to tackling ransomware and myths around Cyber Essentials, this episode highlights how businesses and government can work together to build resilient cyber practices. Learn how Cyber Essentials helps organisations protect themselves and their supply chains, and what the future holds for this vital UK standard.

    42 min
  • Post-Quantum Cryptography

    In this episode of Cyber Series, Darragh sits down with Dr Jeremy Bradley (Principal TD for Crypt and High Threat Technologies), and Flo D (Deputy CTO for Cyber Policy, NCSC-CAP) to explore what “the quantum threat” really means and how organisations should prepare.

    From international standards and timelines for migration, to challenges facing critical national infrastructure, our guests break down the opportunities and obstacles of post-quantum cryptography.

    Whether you’re a CISO, IT leader, or simply curious about the future of cyber security, this conversation sheds light on the steps we all need to take as we enter the quantum era.

    27 min
  • Professional Standards in cyber security

    What does it mean to be a cyber professional today? In this episode, we explore how professional standards are shaping the field with guests from the Bank of England.

    From qualifications to cross-sector collaboration, we unpack what’s needed to thrive in a complex threat landscape.

    32 min
  • Communications in an incident

    When a cyber incident hits, what you say and how you say it can make all the difference. In this episode of The Cyber Series, we’re joined by Nicola Hudson, Partner at Brunswick and Global Lead for Cybersecurity, Data & Privacy, and Beth Maundrill, Editor at Infosecurity Magazine.

    Together, we unpack why strong communication is vital during a crisis, common mistakes organisations make, and how to prepare your messaging strategy before an incident strikes. From leadership’s role to the risks and rewards of social media, this is essential listening for anyone involved in incident response.

    Want to learn more about handling effective communications in a cyber crisis? Take a look at our guidance: https://www.ncsc.gov.uk/files/NCSC-Guidance-on-effective-communications-in-a-cyber-incident.pdf?utm_source=spotify&utm_medium=podcast&utm_campaign=NCSC_Cyber_Series_comms_in_an_incident_podcast

    29 min
  • Passkeys in practice

    In this episode, we are joined by Ollie Whitehouse NCSC CTO, and Google VP Cyber Security Resilience Officer, Heather Adkins to unpack passkeys.

    They break down what passkeys are, why they matter, and how they’re being adopted across industries. From user experience to cost savings and security, this episode explores the future of authentication and why it might be time to move on from passwords.

    Check out the NCSC’s blog on passkeys for more: https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better?utm_source=spotify&utm_medium=podcast&utm_campaign=ncsc_cyber_series_podcast_passkeys.

    25 min
  • Artificial Intelligence

    Welcome to Artificial Intelligence! In this episode we’re

    joined by Viscount Camrose, Minister for AI, as we discuss the security and ethical dimensions of AI, its impact on humanity, and the balance of opportunities and risks.

    Discover how we’re preparing the workforce for AI’s

    future and upcoming regulations to protect consumers from cyber crime.

    35 min

About NCSC Cyber Series

From the publisher's feed

Introducing the new podcast series from the National Cyber Security Centre (NCSC). Join us as we dive deep into the ever-evolving world of cyber security, bringing you discussions on topical issues, emerging trends, and expert insights from our in-house experts and external guests. Each episode offers a comprehensive exploration of a specific topic, providing listeners with valuable knowledge and actionable advice.

More shows like NCSC Cyber Series

Friday Night Comedy from BBC Radio 4 by BBC Radio 4

Friday Night Comedy from BBC Radio 4

2,104 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,029 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

180 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Google DeepMind: The Podcast by Hannah Fry

Google DeepMind: The Podcast

203 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

139 Listeners

The Rest Is Politics by Goalhanger

The Rest Is Politics

3,041 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

47 Listeners

The Rest Is Money by Goalhanger

The Rest Is Money

188 Listeners

OpenAI Podcast by OpenAI

OpenAI Podcast

58 Listeners