
Sign up to save your podcasts
Or


A phishing simulation built around Cadbury chocolate failed instantly in the US, but would have caught almost anyone in the UK, and that single detail reveals something most cybersecurity programmes get wrong. Aakash Suri talks with Quadri Omoloju, an IT and cyber security manager at Thousand Heads and co-founder of AfriCyberCore and the Root Access Network, about why cyber attacks are fundamentally psychological rather than technical, and how privacy and security function as two sides of the same coin: one decides who gets the key, the other guards the door. They explore the Cybersecurity ABC framework of awareness, behaviour and culture, why regional context shapes every phishing simulation and awareness campaign, and where organisations should draw the line on feeding personal data into AI tools. Listeners will come away with a practical test for evaluating AI use against privacy risk, a clearer view of how to build genuine security culture rather than just compliance, and concrete examples of designing technology for the people who'll actually use it.
KEY TAKEAWAYS
Treat cyber attacks as psychological warfare rather than technical exploits. Quadri Omoloju frames phishing and social engineering as attacks on emotion and distraction, which means awareness training needs to target human behaviour just as much as systems and firewalls.
Tailor security awareness campaigns to local culture instead of using generic templates. A Cadbury-themed phishing simulation was spotted instantly by staff in the US because the brand isn't part of their everyday life there, while a UK audience wouldn't fall for a fake HMRC email shaped for a different country.
Build security culture in three deliberate stages: awareness, behaviour, then culture. Quadri describes how giving employees a personal "why" turned reporting phishing emails from something people hid into something shared openly on team channels, eventually leading staff to submit their own simulation ideas.
Before feeding any data into an AI tool, ask whether you'd be comfortable explaining that use to the person the data belongs to. If the answer is no, that's the signal you've crossed the line on privacy, regardless of how useful the tool seems.
Design security and privacy products by listening to the people who'll actually use them, not by importing borrowed assumptions. AfriCyberCore's approach to building for African markets, and the pivot to a board game after kids in workshops kept asking for "true gaming," both came from direct conversations with end users before anything was built.
QUOTES
"Cyber security, if in the most simplest language, is just protection of people digitally."
"Our data is the house. Privacy is the key. And cybersecurity is the bodyguard.”
"People don't know what they don't know."
"Would you be comfortable explaining to your customer that this is what I'm doing with your data?"
"Don't overthink. Just start with whatever you have and then just keep building."
HOST BIO
Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.
This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/
By Aakash SuriA phishing simulation built around Cadbury chocolate failed instantly in the US, but would have caught almost anyone in the UK, and that single detail reveals something most cybersecurity programmes get wrong. Aakash Suri talks with Quadri Omoloju, an IT and cyber security manager at Thousand Heads and co-founder of AfriCyberCore and the Root Access Network, about why cyber attacks are fundamentally psychological rather than technical, and how privacy and security function as two sides of the same coin: one decides who gets the key, the other guards the door. They explore the Cybersecurity ABC framework of awareness, behaviour and culture, why regional context shapes every phishing simulation and awareness campaign, and where organisations should draw the line on feeding personal data into AI tools. Listeners will come away with a practical test for evaluating AI use against privacy risk, a clearer view of how to build genuine security culture rather than just compliance, and concrete examples of designing technology for the people who'll actually use it.
KEY TAKEAWAYS
Treat cyber attacks as psychological warfare rather than technical exploits. Quadri Omoloju frames phishing and social engineering as attacks on emotion and distraction, which means awareness training needs to target human behaviour just as much as systems and firewalls.
Tailor security awareness campaigns to local culture instead of using generic templates. A Cadbury-themed phishing simulation was spotted instantly by staff in the US because the brand isn't part of their everyday life there, while a UK audience wouldn't fall for a fake HMRC email shaped for a different country.
Build security culture in three deliberate stages: awareness, behaviour, then culture. Quadri describes how giving employees a personal "why" turned reporting phishing emails from something people hid into something shared openly on team channels, eventually leading staff to submit their own simulation ideas.
Before feeding any data into an AI tool, ask whether you'd be comfortable explaining that use to the person the data belongs to. If the answer is no, that's the signal you've crossed the line on privacy, regardless of how useful the tool seems.
Design security and privacy products by listening to the people who'll actually use them, not by importing borrowed assumptions. AfriCyberCore's approach to building for African markets, and the pivot to a board game after kids in workshops kept asking for "true gaming," both came from direct conversations with end users before anything was built.
QUOTES
"Cyber security, if in the most simplest language, is just protection of people digitally."
"Our data is the house. Privacy is the key. And cybersecurity is the bodyguard.”
"People don't know what they don't know."
"Would you be comfortable explaining to your customer that this is what I'm doing with your data?"
"Don't overthink. Just start with whatever you have and then just keep building."
HOST BIO
Aakash is a recognised Data Privacy leader who helps organisations navigate complex regulations with clarity, confidence, and common sense. Unlike the legalese-driven privacy pros who simply regurgitate the law, Aakash breaks down what the rules actually mean, translates them into plain English, and gives businesses three SMART, pragmatic steps to demonstrate real compliance.
This Podcast has been brought to you by Disruptive Media. https://disruptivemedia.co.uk/