
I’m super proud to have written this book. It’s the much improved second edition – and I can’t wait to hear what you think about it.
Please leave an Amazon review if you can – this really helps beat the algorithm, and is much appreciated!
A practical approach

It was great to learn more about the state-of-the-art research in cybersecurity applications of AI, both from the attacker and defender’s perspectives at the Unprompted conference in Sydney today.
The talks from engineers at OpenAI, Google, Microsoft, TikTok, Slack and many others demonstrated the practical use cases for threat hunting, vulnerability discovery, detection and response to speed up and automate workflows.
Safety, cost management and scale were the top themes for me – you don’t always need the latest model for every task, deterministic scripts can complement your agentic AI pipelines, guardrails and alignment are still key. Best results live at the intersection of system automation and human judgment.
And, of course, it’s the people who make events like this so worthwhile – it was good to catch-up with old friends (and make some new ones) and exchange ideas and research. AI and cybersecurity is a team sport. Reach out if I can help.
I look forward to experimenting and applying technical insights at work.

I had a great time talking to Peter Davidoff from the Australian Government about the evolving approach to security.
We touched on the challenges and opportunities of securing critical national infrastructure, the increasing role of AI and practical examples of developing a defence-in-depth approach to security architecture.
A big thanks to the audience for great questions!

Security failures are rarely just a technology problem. They’re a design problem – a mismatch between how controls are built and how people actually work.
That was my message keynoting at CIO Leadership Live.
AI has amplified the security fundamentals.
☑️ Defaults beat persuasion: passkeys by default, automatic updates, SSO. The secure choice should be the easiest choice.
☑️ Shadow AI is a friction signal, not a compliance failure. If people are pasting data into unapproved chatbots, your sanctioned path is too slow. Give them a fast, safe alternative.
☑️ Build trust, not fear. Blameless reviews and visible leadership create the psychological safety people need to report incidents early.
The CIOs who win with AI won’t be the ones with the strictest rules but the ones whose guardrails make the secure way the easy way.

Two leadership programs completed 📚
The AGSM Professional Forum was about complexity – and specifically the costs that never hit a balance sheet: reputational damage, talent attrition, strategic drift. The masterclass dropped us into a scenario that escalated in real time, with no playbook and no obvious right answer. Does your week sometimes look like that?
“Learn to Lead” made the case that human connection as a strategic capability – and one that matters more, not less, as AI reshapes how we work.
Security proves it daily: the strongest controls fail without trust, judgment and people who feel safe enough to flag the thing that looks off.
I particularly liked the idea of cognitive upsizing when using AI – yes, offload tasks to the machine, but use the freed up bandwidth for deeper thinking and to solve even more ambitious challenges.
The throughline across both: lead through uncertainty instead of waiting for a certainty that isn’t coming, and pair the data with real human connection. Neither is enough on its own.
Grateful to the facilitators and the people I learned alongside.



I had the pleasure of delivering a guest lecture on developing and implementing a cybersecurity strategy to students at the School of Information Systems and Technology Management, UNSW.
A security strategy is a set of decisions about what you will and won’t prioritise, made under real constraints – budget, headcount and a threat landscape that doesn’t wait for your roadmap to catch up.
Strategy starts with the business. If you can’t explain your security priorities in terms of what the organisation is trying to achieve, you won’t get the backing.
With AI, the fundamentals are still important, but the timelines are now compressed.
Thank you UNSW for the invitation, and to the students for the great discussion. This cohort is entering the field at a very interesting moment.

I enjoyed talking to students completing their Global MBA and MSc in Digital Transformation with the University of Hull Online about human-centered approaches to cyber security.
My lecture helped reinforce the idea that cyber security is a socio-technical challenge that has deep behavioural contingencies.
Cyber is a business risk and I’m glad it’s increasingly featured in business degree curriculums beyond computer science. My book, the Psychology of Information Security, helps bridge the gap between organisational and cyber strategy.









I had a great time talking about The Psychology of Information Security at a CIO conference and signing a few copies.

It’s great to be included in the Global CISO 100 🏆
This award recognises key pillars of our industry: innovation, strategic vision, leadership, team development and community contribution.
I’m incredibly grateful for the nomination and want to extend a big thank you to the judges and my network. Cyber security is a team effort, and I’m fortunate to work alongside an exceptional team and peer group every day.

I delivered a keynote at CIO Leadership Live.
For about a decade, our industry has had a favourite phrase: people are the weakest link. I made the opposite case – that the people we’ve been blaming are the most capable security asset we have, and we’ve spent that decade building systems that fight them instead of fit them.
The talk covered why training and punishment don’t work, why every workaround is actually free user research, and how you design your way to secure behaviour by making the secure path the easy path. And of course, where AI fits into all of it.