Listen:
The Write Up
The exchanges worth stealing.
Kieren won't run phishing email tests, even though "every board always wants you to do it." His objection is that a test trains nobody. "What it does is you have a graph that your cybersecurity person can track if it goes up or down, and that's it." And the number is set by whoever writes the email, so what the board is really looking at is the security team's grammar. As for the industry's favourite metric: "Anybody that says phishing simulation is good, it is not. It is 100% terrible. Because when an incident happens, I need the trust of all of the employees. I've just spent the last 12 months tricking them to click links."
What he wants measured instead is the bit nobody practises... what happens during an incident. "We used to practise little and often. Every day we would have fire, flood, famine exercises." Cyber trains people for before and never for during, then reports what he calls plastic metrics to the board. Most tabletop exercises? Discussion workshops with a slide deck at the front. His version runs in real time with real escalation, and he refuses to say when it starts, because at Cambridge half his team turned up at the old HQ and half at the new one. "It doesn't matter if you make a bad decision. It matters if you make no decision."
Then there's blame. He won't run gotcha tests because of labelling theory, which he explains via his fourteen-year-old self: "When my mum called me a complete and utter tit, did that improve me? No. I just became more of a tit." Shame people for clicking and you get compliance and silence, so when the real one lands, nobody calls you. Which is why his answer to who carries the can when a breach turns out to be behavioural is always me. "If you need a name, me. Done. Now let's move on and find the root cause so we never repeat this." If more than one person is accountable, no one is.
Clips
Steal these.
The moments worth sending to someone.