Writing and speaking on cybersecurity leadership
A record of recent speaking engagements, and the future home for longer-form writing on security governance, leadership and strategy.
Selected articles
Longer-form writing on cyber security governance, leadership and culture. Newer pieces are hosted here directly; the rest are on Medium for now.
The New CISO's First 90 Days: Diagnose Before You Prescribe
Applying Michael Watkins' First 90 Days framework to CISO transitions — diagnosing whether you've inherited a start-up, turnaround, realignment or growth problem before choosing a playbook, and negotiating expectations with your boss up front rather than by accident.
Read the full article →Paths of Desire
Why the most effective security controls are the ones users never notice, and why a circumvented control is worse than no control at all — illustrated by two decades of workarounds, from disk encryption codes on Post-it notes to shadow file-sharing over mobile data.
Read the full article →The Floor is Lava
Why a cyber incident is inevitable, and how peer networks, shared threat intel and layered defences build resilience. Co-written with Ambrose Neville (University of Surrey).
Read on Medium →Phishing simulations — do they really work?
Results from phishing our own IT department, and why fast response and a no-blame reporting culture matter more than click-rate metrics.
Read on Medium →The £1m laptop
Why the data on an executive's laptop is worth far more than the device, and why leaders must visibly follow the security guidance they expect from everyone else.
Read on Medium →My home office setup
A personal walkthrough of the desk, display, chair and video-call kit behind a well-equipped home office.
Read on Medium →Achieving Cyber Essentials compliance
Practical gaps between the Cyber Essentials requirements and the Evendine question set, and the BYOD scoping challenges facing UK higher education.
Read on Medium →TL;DR — How to implement ISO 27001
A short, practical answer to a common question: read the standards, and follow them without second-guessing.
Read on Medium →Panels, keynotes and guest lectures
Gartner C-Level Communities, UK & Ireland CISO Inner Circle
Table discussion leader: "Resilient Leadership: Optimising Cybersecurity in a Dynamic World"
Gartner C-Level Communities, UK & Ireland CISO Community Town Hall
Panel member: "Fostering a Digital Native Mindset to Cybersecurity"
University of Southampton
Guest Lecture: "Advanced Topics in Security (Cyber & Physical)"
Jisc Security Conference
Keynote panel: "AI in Cyber Security: The Benefits, Pitfalls, and Implications for the Future"
Jisc Security Conference
Presentation: "The Floor is Lava: Lessons from the Field" (reprised by request, Spring 2024)
More writing, moving here
The rest of the Medium archive will move to this site over time, alongside new original writing on cyber security governance, CISO leadership and building security functions from the ground up.