J
Jack Woods
Actor
4
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
SEP 14
SEP 21
SEP 28
Sep 17, 2026
Cyber Security Training, Awareness and Benefits of Tailored Training
17:02
17:16
17:28
17:45
17:51
17:58
G
16:30George RyanGUEST
I think potentially that's why earlier when we were saying about the tick box ones and it being generic, the problem is you need that link there that is my personal job, my personal life, my organization and without that it's really hard for it to have meaning which makes it way harder for you to retain it and actually take account of it and that's well a lot of cases why two weeks down the line it's completely forgotten and you know give me 50 weeks and i'll remember it again for a little bit

Jack WoodsGUEST
yeah and it's it's exactly right i think pointing to that behavioral change that you mentioned in terms of taking it home and things like the use of password managers and things like that where people may not necessarily be as confident using them as others.

Jack WoodsGUEST
So when you can take that home and create that behavioural change through training, it forces the culture change in the organisation as well, but not in a forceful way.

Jack WoodsGUEST
It's just a case of as soon as staff and personnel become aware of what they're doing and how they can impact information security and those behavioural changes, They tend to engage in those behavioural changes and then you see the culture shift.

Jack WoodsGUEST
And it's something that I've seen, I'm sure George has seen across organisations when we've come in and conducted training with them.

Jack WoodsGUEST
And then a year later or nine months later, we're coming in to do an internal audit or something like that.

Jack WoodsGUEST
And we see that actually they've taken that training that we provided initially that was tailored to them.
7 MINS LATER
G
25:03George RyanGUEST
Equally, you'll have other people that come in and actually they frame absolutely everything and just be like well i just got told to use it i didn't get told i couldn't do this so therefore i've done that
Physical Security Controls
15:14
15:38
17:12
17:28
19:14
G
14:34George RyanGUEST
So example of that, if you, for example, like Jack mentioned earlier, if you're relying on visitor badges, well, actually, have you got a process that at the end of the day, you collect them so no one can keep them? Are you saying people can be escorted or not? you're just relying on having a badge then that's going to give you a false sense whereas actually what you need is you need that you need the awareness the culture where people actually will challenge someone if they can't visibly see a badge um so ultimately i would say it's as always in cyber over alliance and one control to save everyone is probably where you have the biggest false sense of securities

Jack WoodsGUEST
yeah i agree i think another Another thing that kind of gives organisations a false sense of security is, like I mentioned earlier, a reception desk that doesn't do active verification, doesn't check that you're who you say you are, doesn't check that the person that you're here to meet is expecting you and that you were booked in with the reception, that kind of thing.

Jack WoodsGUEST
A lot of organisations will just assume that having someone in the reception space to kind of meet and greet visitors is enough but like george has mentioned if you're not ensuring that they've been given a badge verifying their kind of they are who they say they are and they are meeting the correct person making sure that they are escorted if they need to be making sure that no tailgating is happening coming through the main entrance that kind of thing or through access gates within the reception because ultimately people threat threat actors will always try to exploit trust so they will socially engineer those people because if you go on linkedin and you look for an organization you can find the majority of people that work at that organization so you could walk into any reception desk and say oh yeah i'm here for this organization and i'm here to see x person and if they're like okay brilliant here's a visitor badge their office is floor two corridor one you can just walk straight up there and you never know who you might find or what opportunity might present itself on the way and if someone else is kind of going into that office space as well especially in the morning or like the start of the working day if people are coming in to the office tailgating in behind them if you've got the visitor pass and you know you know the person's name that you're there to see people might just let you in because that's what you suggested.

Jack WoodsGUEST
So having those additional controls like George mentioned, not just relying on that one control, especially like reception desks, because ultimately most of the time they're employed by the landlord, not by the organisation that's based in the building.

Jack WoodsGUEST
I've seen an example of something that I've seen that was quite useful actually was organization there was a reception desk in the office kind of the building but then this organization had implemented a secondary reception desk for their offices to ensure that there was another gate that any visitor might have to go through before they can actually access the main office um so that was quite a interesting approach that i thought was actually yeah that that does mitigate some of that risk because you've essentially it's a second line of defence against someone trying to gain unauthorised access into that space.

Jack WoodsGUEST
I think probably the next thing after that would be those strengthening those physical access controls.
Establishing Control Over AI Usage
5:19
5:33
5:39
5:53
6:00
6:19
G
5:10George RyanGUEST
So we are really seeing it go from prompt and response to actually carrying out tasks almost autonomously in most cases.

Jack WoodsGUEST
Yeah, because it used to be the kind of customer service chatbots that everyone used to get frustrated with, didn't it? And yeah, kind of moving from that into what we've got now is like we say, it's been a huge kind of improvement in that.

Jack WoodsGUEST
But it's yeah, it's one of those things where you kind of you don't want to go too far.

Jack WoodsGUEST
But yeah, other kind of examples that we've seen is kind of software development assistance as well, reviewing code, making sure that it's kind of not get any issues in it, or there's no kind of common faults, anything like that.

Jack WoodsGUEST
Like you say, George, the kind of HR processes, so screening CVs and providing that recruitment support.

Jack WoodsGUEST
Some of the other things I've seen more recently is the kind of helping draft policy documentation to meet, like you say, the kind of if it can be pointed to the existing documentation within an organization, it can use that to kind of capture the way that organizations write their documents.

Jack WoodsGUEST
And so it can be used to draft policies in line with that to make sure that there's kind of alignment there and it's straightforward and everyone's happy with what it's going to look like rather than it just producing a chunk of paragraph text and not having it formatted in the correct ways and some of the other stuff I've seen more recently as well is for supply chain so kind of looking at the forecasting whether or not they're going to need additional suppliers or whether or not they need to cut back on suppliers due to kind of limited business that kind of stuff as well
14 MINS LATER
G
20:24George RyanGUEST
We can actually all learn together rather than just people kind of really varying in how much they use it and how benefit from it.
Unusual GRC Questions
11:29
12:00
12:06
G
11:17George RyanGUEST
And if you don't actually know what constitutes AI, you may be completely against the policy because you're actually not understanding what it's asking from you as such.

Jack WoodsGUEST
If there are, and it's something I spoke about earlier, if there are documents upon documents, if there are policies upon policies and you've got 30, 40 documents that you're expecting staff to read, it gets to a point where they, they'll probably just say that they've read it, even if they haven't because it, they've got day jobs that they need to be doing and they can't sit down for hours on end and read through documents that may not actually even be relevant to them.

Jack WoodsGUEST
I think kind of George has alluded to two good ones there, acceptable use and AI.

Jack WoodsGUEST
I think another one that we see organisations do and it's part of generally sometimes part of an acceptable use policy is bring your own device policy.
14 MINS LATER
A
26:51AnnieHOST
But what would you say is the hardest part of convincing senior management and leadership to care about risk before an incident happens?