Skip to main content
George Ryan

George Ryan

Former Speaker of the Illinois House of Representatives

Sep 17, 2026

13:43
If they are the CFO, for example, and they are a PCI DSS certified organisation, that CFO might have more focus training for his finance team or their finance team in PCI DSS requirements than the cto might have for their team in information security requirements the standards most in most cases frameworks and standards like that are aligned in terms of requirements for information security but the specifics and the nuances will be different and so you will want those training requirements to be different for those teams so that it's relevant to what they're doing and like George has mentioned so that they can apply it kind of immediately without needing to dig further into oh well that kind of applies to us so maybe we should delve deeper into that and do it off their own back if they have training provided to them that's clear and concise and is specific to what is required of them then it's going to be much more beneficial than just that generalized training that everyone will be completing
14:55
yeah and i think when it comes to the awareness again it's going on basic psychology principles isn't it a lot of people that are doing the awareness training it's well how does this kind of how does this impact me why is this relevant to me to my organization again we mentioned earlier you know if if you're coming in and you're getting awareness training And they're telling you, you know, this is going on in the finance sector.
15:22
This is what people are kind of receiving as phishing.
15:24
But your education, you're going to be thinking, yeah, it's not relevant to me.
15:27
That doesn't impact me at all.
15:29
Likewise, if you're in finance and people are telling you about educational sector, you know, how they're getting here.
15:36
It's how can I take this home? One thing we kind of recommend when we do our awareness of training is we will tailor it.

8 MINS LATER

AnnieHOST
23:16
how is it impacted by ai yeah
AnnieHOST
10:31
and i think i think you've maybe shared one or two examples already but what would you say is the most surprising physical security weakness that you've encountered which could have led to a major information security breach?
10:44
So I knew of one which was quite interesting because I just don't think it had been considered at the time but so organisation in a shared building so everyone was using the same supply of lanyards but actually what no one had checked was that the lanyards were set to have different access controls so Ultimately, if you had a lanyard, you could walk into any of the buildings, even the ones you're not supposed to, because actually it was just the binary.
11:10
You either got access or not, rather than this location is off guards unless you've got this in place.
11:17
Obviously, that was a panic when you go into the building, you see someone, you're like, I don't think you're supposed to be here.
11:24
And again, it's not necessarily always malicious.
11:28
So someone can actually do that by accident.
11:30
You can get the wrong building by accident.

10 MINS LATER

21:50
I
13:21
honesty around its usage is probably one of the key things um so if you if you are if you are using it and you are using it to generate documentation such as policies or procedures and things like that it is always worth ensuring that there's a review kind of conducted by a human before that's rolled out and shared with the rest of the organization and potentially externally as well in the in the in regards to if you're using 27001 for example and you used ai to write your information security policy making sure that it's actually appropriate to your organization before you share that with an organization that might have requested it is uh it's definitely worthwhile
14:01
yeah i think as well because externally what people may not be aware of is uh sometimes the word document information will actually show someone if they're looking in the right spot that it's been generated with ai which can be a very difficult conversation if you outright uh to come in there was um similar to the iso as well i think um Saw it the other day, someone was asking if they could do the whole ISO process through AI.
14:28
And actually there's the question of, is the AI deemed to be a competent persons for ISO 27001? And then you get into that kind of territory.
14:37
So yeah, transparency makes life a lot easier, even if at first it's a bit to own up to that.
14:44
I think the other one, big one that we do see is the personal counts.
14:49
So what, what can happen is you get kind of those that are really into AI and.
14:57
You know, let's say the organization said, okay, we're not using this AI tool and someone's got, oh, but it's so good.
AnnieHOST
18:48
Yeah.
AnnieHOST
10:10
What's a security policy that everyone signs but nobody actually follows?
10:15
So I think from experience with clients, often it is what's in kind of the acceptable use.
10:22
Obviously, you've got the more niche policies where it's like, oh, I didn't even know we had one for that.
10:26
But acceptable use is one of those.
10:28
You kind of read it.
10:29
You acknowledge it.
10:30
And again, with the operational drift, over time, you can actually forget what's acceptable and what's not as such.

20 MINS LATER

30:44
Otherwise, we might have some big issues should this actually happen to us.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.