CISO Interview: Psychology and the Role of a CISO

When both attackers and defenders use AI, it’s the people who become the edge.

Attackers already run at machine speed, and faster tools only close part of that gap.

It was great to sit down with Dan Raywood to talk about building security culture and the evolving role of a CISO 👇

More

Key points from the CIO keynote

Security failures are rarely just a technology problem. They’re a design problem – a mismatch between how controls are built and how people actually work.

That was my message keynoting at CIO Leadership Live.

AI has amplified the security fundamentals.

☑️ Defaults beat persuasion: passkeys by default, automatic updates, SSO. The secure choice should be the easiest choice.
☑️ Shadow AI is a friction signal, not a compliance failure. If people are pasting data into unapproved chatbots, your sanctioned path is too slow. Give them a fast, safe alternative.
☑️ Build trust, not fear. Blameless reviews and visible leadership create the psychological safety people need to report incidents early.

The CIOs who win with AI won’t be the ones with the strictest rules but the ones whose guardrails make the secure way the easy way.

More

Human connection in a digital world

Two leadership programs completed 📚

The AGSM Professional Forum was about complexity – and specifically the costs that never hit a balance sheet: reputational damage, talent attrition, strategic drift. The masterclass dropped us into a scenario that escalated in real time, with no playbook and no obvious right answer. Does your week sometimes look like that?

“Learn to Lead” made the case that human connection as a strategic capability – and one that matters more, not less, as AI reshapes how we work.

Security proves it daily: the strongest controls fail without trust, judgment and people who feel safe enough to flag the thing that looks off.

I particularly liked the idea of cognitive upsizing when using AI – yes, offload tasks to the machine, but use the freed up bandwidth for deeper thinking and to solve even more ambitious challenges.

The throughline across both: lead through uncertainty instead of waiting for a certainty that isn’t coming, and pair the data with real human connection. Neither is enough on its own.

Grateful to the facilitators and the people I learned alongside.

Guest lecture: developing and implementing a security strategy

I had the pleasure of delivering a guest lecture on developing and implementing a cybersecurity strategy to students at the School of Information Systems and Technology Management, UNSW.
 
A security strategy is a set of decisions about what you will and won’t prioritise, made under real constraints – budget, headcount and a threat landscape that doesn’t wait for your roadmap to catch up.
 
Strategy starts with the business. If you can’t explain your security priorities in terms of what the organisation is trying to achieve, you won’t get the backing.
 
With AI, the fundamentals are still important, but the timelines are now compressed.
 
Thank you UNSW for the invitation, and to the students for the great discussion. This cohort is entering the field at a very interesting moment.

A lecture on human-centered approaches to cyber security

I enjoyed talking to students completing their Global MBA and MSc in Digital Transformation with the University of Hull Online about human-centered approaches to cyber security.

My lecture helped reinforce the idea that cyber security is a socio-technical challenge that has deep behavioural contingencies.

Cyber is a business risk and I’m glad it’s increasingly featured in business degree curriculums beyond computer science. My book, the Psychology of Information Security, helps bridge the gap between organisational and cyber strategy.

Global CISO 100

It’s great to be included in the Global CISO 100 🏆

This award recognises key pillars of our industry: innovation, strategic vision, leadership, team development and community contribution.

I’m incredibly grateful for the nomination and want to extend a big thank you to the judges and my network. Cyber security is a team effort, and I’m fortunate to work alongside an exceptional team and peer group every day.

Build Security for People – a keynote at CIO Leadership Live

I delivered a keynote at CIO Leadership Live.

For about a decade, our industry has had a favourite phrase: people are the weakest link. I made the opposite case – that the people we’ve been blaming are the most capable security asset we have, and we’ve spent that decade building systems that fight them instead of fit them.

The talk covered why training and punishment don’t work, why every workaround is actually free user research, and how you design your way to secure behaviour by making the secure path the easy path. And of course, where AI fits into all of it.

The intersection of AI and Cyber

It was great to share my thoughts on the intersection of AI and Cyber.

I kept it practical and worked through three key dimensions: how AI is changing the defender’s day-to-day, how we secure AI itself and how we defend when AI becomes the threat.

It was particularly relevant given the latest frontier model releases, like Anthropic’s Fable / Mythos (and OpenAI’s GPT-5.5-Cyber) and their applications to cybersecurity.

If attackers and defenders now have the same AI capabilities, your advantage comes not from the tools but from your people, your data and how well you’ve done the fundamentals.

Grateful to the panel and to everyone who put their hand up and got stuck into the discussion.

Notes from i-4 Sydney

A day of sessions on AI in the SOC, OT resilience, fragmenting regulation and machine-speed response.

We build systems that assume the human in the loop has steady attention and reliable judgement. Neither is true, and it is getting less true. Every alert, prompt, exception, and “are you sure?” draws from the same depleting account. By afternoon, the analyst approving a transfer, the engineer waving through a change and the executive clicking an MFA push are all running on the same low battery.

AI does not solve this. It compresses the timeline and raises the stakes of each remaining human decision. The questions we still hand to people – is this normal? do I trust this? should I escalate? – are exactly the ones tiredness destroys first.

You cannot train your way out of the fact that attention runs out. It is a design problem. That’s precisely what I discuss in The Psychology of Information Security.