What human psychology can teach us about AI agent drift

I recently gave a presentation on the Behavioural Analysis for Multi-Agent Systems. The idea at its centre is simple. AI agents drift from their intended goals in much the same way people drift from security policy, and psychology has spent decades learning to read that kind of behaviour. I explore some key themes in this blog.

More

CSO30 Awards Winner

I’m proud to have been recognised as one of the top Chief Security Officers in Australia!

I couldn’t have done this without the support and commitment from my team, peers and the wider cyber security community globally.

Unprompted: at the intersection of state-of-the-art AI and cybersecurity research

It was great to learn more about the state-of-the-art research in cybersecurity applications of AI, both from the attacker and defender’s perspectives at the Unprompted conference in Sydney today.

The talks from engineers at OpenAI, Google, Microsoft, TikTok, Slack and many others demonstrated the practical use cases for threat hunting, vulnerability discovery, detection and response to speed up and automate workflows.

Safety, cost management and scale were the top themes for me – you don’t always need the latest model for every task, deterministic scripts can complement your agentic AI pipelines, guardrails and alignment are still key. Best results live at the intersection of system automation and human judgment.

And, of course, it’s the people who make events like this so worthwhile – it was good to catch-up with old friends (and make some new ones) and exchange ideas and research. AI and cybersecurity is a team sport. Reach out if I can help.

I look forward to experimenting and applying technical insights at work.

Securing critical national infrastructure

I had a great time talking to Peter Davidoff from the Australian Government about the evolving approach to security.

We touched on the challenges and opportunities of securing critical national infrastructure, the increasing role of AI and practical examples of developing a defence-in-depth approach to security architecture.

A big thanks to the audience for great questions!

Board Strategy Day

I”m very proud to have joined the board of SMART Recovery Australia with the mission to help people live a life beyond addiction through evidence-based, inclusive and empowering programs.

And no better way to start than with a strategy offsite bringing together fellow directors and the executive team for a day focusing on financial sustainability, AI governance, risk appetite and long-term impact measurement.

I look forward to contributing and applying my experience in board directorship, social impact measurement, AI in the not-for-profit sector, NFP governance, cybersecurity, strategy and leadership.

CISO Interview: Psychology and the Role of a CISO

When both attackers and defenders use AI, it’s the people who become the edge.

Attackers already run at machine speed, and faster tools only close part of that gap.

It was great to sit down with Dan Raywood to talk about building security culture and the evolving role of a CISO 👇

More

Key points from the CIO keynote

Security failures are rarely just a technology problem. They’re a design problem – a mismatch between how controls are built and how people actually work.

That was my message keynoting at CIO Leadership Live.

AI has amplified the security fundamentals.

☑️ Defaults beat persuasion: passkeys by default, automatic updates, SSO. The secure choice should be the easiest choice.
☑️ Shadow AI is a friction signal, not a compliance failure. If people are pasting data into unapproved chatbots, your sanctioned path is too slow. Give them a fast, safe alternative.
☑️ Build trust, not fear. Blameless reviews and visible leadership create the psychological safety people need to report incidents early.

The CIOs who win with AI won’t be the ones with the strictest rules but the ones whose guardrails make the secure way the easy way.

More

Human connection in a digital world

Two leadership programs completed 📚

The AGSM Professional Forum was about complexity – and specifically the costs that never hit a balance sheet: reputational damage, talent attrition, strategic drift. The masterclass dropped us into a scenario that escalated in real time, with no playbook and no obvious right answer. Does your week sometimes look like that?

“Learn to Lead” made the case that human connection as a strategic capability – and one that matters more, not less, as AI reshapes how we work.

Security proves it daily: the strongest controls fail without trust, judgment and people who feel safe enough to flag the thing that looks off.

I particularly liked the idea of cognitive upsizing when using AI – yes, offload tasks to the machine, but use the freed up bandwidth for deeper thinking and to solve even more ambitious challenges.

The throughline across both: lead through uncertainty instead of waiting for a certainty that isn’t coming, and pair the data with real human connection. Neither is enough on its own.

Grateful to the facilitators and the people I learned alongside.

Guest lecture: developing and implementing a security strategy

I had the pleasure of delivering a guest lecture on developing and implementing a cybersecurity strategy to students at the School of Information Systems and Technology Management, UNSW.
 
A security strategy is a set of decisions about what you will and won’t prioritise, made under real constraints – budget, headcount and a threat landscape that doesn’t wait for your roadmap to catch up.
 
Strategy starts with the business. If you can’t explain your security priorities in terms of what the organisation is trying to achieve, you won’t get the backing.
 
With AI, the fundamentals are still important, but the timelines are now compressed.
 
Thank you UNSW for the invitation, and to the students for the great discussion. This cohort is entering the field at a very interesting moment.

A lecture on human-centered approaches to cyber security

I enjoyed talking to students completing their Global MBA and MSc in Digital Transformation with the University of Hull Online about human-centered approaches to cyber security.

My lecture helped reinforce the idea that cyber security is a socio-technical challenge that has deep behavioural contingencies.

Cyber is a business risk and I’m glad it’s increasingly featured in business degree curriculums beyond computer science. My book, the Psychology of Information Security, helps bridge the gap between organisational and cyber strategy.