Skip to main content

Jack Woods

Actor

Sep 17, 2026

16:30
I think potentially that's why earlier when we were saying about the tick box ones and it being generic, the problem is you need that link there that is my personal job, my personal life, my organization and without that it's really hard for it to have meaning which makes it way harder for you to retain it and actually take account of it and that's well a lot of cases why two weeks down the line it's completely forgotten and you know give me 50 weeks and i'll remember it again for a little bit
17:02
yeah and it's it's exactly right i think pointing to that behavioral change that you mentioned in terms of taking it home and things like the use of password managers and things like that where people may not necessarily be as confident using them as others.
17:16
So when you can take that home and create that behavioural change through training, it forces the culture change in the organisation as well, but not in a forceful way.
17:28
It's just a case of as soon as staff and personnel become aware of what they're doing and how they can impact information security and those behavioural changes, They tend to engage in those behavioural changes and then you see the culture shift.
17:45
And it's something that I've seen, I'm sure George has seen across organisations when we've come in and conducted training with them.
17:51
And then a year later or nine months later, we're coming in to do an internal audit or something like that.
17:58
And we see that actually they've taken that training that we provided initially that was tailored to them.

7 MINS LATER

25:03
Equally, you'll have other people that come in and actually they frame absolutely everything and just be like well i just got told to use it i didn't get told i couldn't do this so therefore i've done that
14:34
So example of that, if you, for example, like Jack mentioned earlier, if you're relying on visitor badges, well, actually, have you got a process that at the end of the day, you collect them so no one can keep them? Are you saying people can be escorted or not? you're just relying on having a badge then that's going to give you a false sense whereas actually what you need is you need that you need the awareness the culture where people actually will challenge someone if they can't visibly see a badge um so ultimately i would say it's as always in cyber over alliance and one control to save everyone is probably where you have the biggest false sense of securities
15:14
yeah i agree i think another Another thing that kind of gives organisations a false sense of security is, like I mentioned earlier, a reception desk that doesn't do active verification, doesn't check that you're who you say you are, doesn't check that the person that you're here to meet is expecting you and that you were booked in with the reception, that kind of thing.
15:38
A lot of organisations will just assume that having someone in the reception space to kind of meet and greet visitors is enough but like george has mentioned if you're not ensuring that they've been given a badge verifying their kind of they are who they say they are and they are meeting the correct person making sure that they are escorted if they need to be making sure that no tailgating is happening coming through the main entrance that kind of thing or through access gates within the reception because ultimately people threat threat actors will always try to exploit trust so they will socially engineer those people because if you go on linkedin and you look for an organization you can find the majority of people that work at that organization so you could walk into any reception desk and say oh yeah i'm here for this organization and i'm here to see x person and if they're like okay brilliant here's a visitor badge their office is floor two corridor one you can just walk straight up there and you never know who you might find or what opportunity might present itself on the way and if someone else is kind of going into that office space as well especially in the morning or like the start of the working day if people are coming in to the office tailgating in behind them if you've got the visitor pass and you know you know the person's name that you're there to see people might just let you in because that's what you suggested.
17:12
So having those additional controls like George mentioned, not just relying on that one control, especially like reception desks, because ultimately most of the time they're employed by the landlord, not by the organisation that's based in the building.
17:28
I've seen an example of something that I've seen that was quite useful actually was organization there was a reception desk in the office kind of the building but then this organization had implemented a secondary reception desk for their offices to ensure that there was another gate that any visitor might have to go through before they can actually access the main office um so that was quite a interesting approach that i thought was actually yeah that that does mitigate some of that risk because you've essentially it's a second line of defence against someone trying to gain unauthorised access into that space.
19:11
This is our general procedures.
19:13
Yeah, I agree.
19:14
I think probably the next thing after that would be those strengthening those physical access controls.
5:10
So we are really seeing it go from prompt and response to actually carrying out tasks almost autonomously in most cases.
5:19
Yeah, because it used to be the kind of customer service chatbots that everyone used to get frustrated with, didn't it? And yeah, kind of moving from that into what we've got now is like we say, it's been a huge kind of improvement in that.
5:33
But it's yeah, it's one of those things where you kind of you don't want to go too far.
5:39
But yeah, other kind of examples that we've seen is kind of software development assistance as well, reviewing code, making sure that it's kind of not get any issues in it, or there's no kind of common faults, anything like that.
5:53
Like you say, George, the kind of HR processes, so screening CVs and providing that recruitment support.
6:00
Some of the other things I've seen more recently is the kind of helping draft policy documentation to meet, like you say, the kind of if it can be pointed to the existing documentation within an organization, it can use that to kind of capture the way that organizations write their documents.
6:19
And so it can be used to draft policies in line with that to make sure that there's kind of alignment there and it's straightforward and everyone's happy with what it's going to look like rather than it just producing a chunk of paragraph text and not having it formatted in the correct ways and some of the other stuff I've seen more recently as well is for supply chain so kind of looking at the forecasting whether or not they're going to need additional suppliers or whether or not they need to cut back on suppliers due to kind of limited business that kind of stuff as well

14 MINS LATER

20:24
We can actually all learn together rather than just people kind of really varying in how much they use it and how benefit from it.
11:17
And if you don't actually know what constitutes AI, you may be completely against the policy because you're actually not understanding what it's asking from you as such.
11:25
Yeah.
11:25
I think part of it becomes a culture problem as well.
11:29
If there are, and it's something I spoke about earlier, if there are documents upon documents, if there are policies upon policies and you've got 30, 40 documents that you're expecting staff to read, it gets to a point where they, they'll probably just say that they've read it, even if they haven't because it, they've got day jobs that they need to be doing and they can't sit down for hours on end and read through documents that may not actually even be relevant to them.
12:00
I think kind of George has alluded to two good ones there, acceptable use and AI.
12:06
I think another one that we see organisations do and it's part of generally sometimes part of an acceptable use policy is bring your own device policy.
12:15
And so the use of personal devices to access organizational data.

14 MINS LATER

AnnieHOST
26:51
But what would you say is the hardest part of convincing senior management and leadership to care about risk before an incident happens?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.