Guest lecture: developing and implementing a security strategy

I had the pleasure of delivering a guest lecture on developing and implementing a cybersecurity strategy to students at the School of Information Systems and Technology Management, UNSW.
 
A security strategy is a set of decisions about what you will and won’t prioritise, made under real constraints – budget, headcount and a threat landscape that doesn’t wait for your roadmap to catch up.
 
Strategy starts with the business. If you can’t explain your security priorities in terms of what the organisation is trying to achieve, you won’t get the backing.
 
With AI, the fundamentals are still important, but the timelines are now compressed.
 
Thank you UNSW for the invitation, and to the students for the great discussion. This cohort is entering the field at a very interesting moment.

Global CISO 100

It’s great to be included in the Global CISO 100 🏆

This award recognises key pillars of our industry: innovation, strategic vision, leadership, team development and community contribution.

I’m incredibly grateful for the nomination and want to extend a big thank you to the judges and my network. Cyber security is a team effort, and I’m fortunate to work alongside an exceptional team and peer group every day.

Build Security for People – a keynote at CIO Leadership Live

I delivered a keynote at CIO Leadership Live.

For about a decade, our industry has had a favourite phrase: people are the weakest link. I made the opposite case – that the people we’ve been blaming are the most capable security asset we have, and we’ve spent that decade building systems that fight them instead of fit them.

The talk covered why training and punishment don’t work, why every workaround is actually free user research, and how you design your way to secure behaviour by making the secure path the easy path. And of course, where AI fits into all of it.

The intersection of AI and Cyber

It was great to share my thoughts on the intersection of AI and Cyber.

I kept it practical and worked through three key dimensions: how AI is changing the defender’s day-to-day, how we secure AI itself and how we defend when AI becomes the threat.

It was particularly relevant given the latest frontier model releases, like Anthropic’s Fable / Mythos (and OpenAI’s GPT-5.5-Cyber) and their applications to cybersecurity.

If attackers and defenders now have the same AI capabilities, your advantage comes not from the tools but from your people, your data and how well you’ve done the fundamentals.

Grateful to the panel and to everyone who put their hand up and got stuck into the discussion.

AWS Summit 2026: AI is moving fast, security is catching up

There is a shift happening in how the industry talks about agentic AI security. A year ago the conversation was speculative – what might go wrong, what we might do about it. Now it is specific. The platforms, primitives and patterns for operating agents safely exist as named things you can point at on a slide. The vocabulary is converging across vendors. The reference architectures are documented.

In this blog I explore the themes that mattered most, and what they mean for security teams.

More

Royal Holloway University of London adopts my book for their MSc Information Security programme

One of the UK’s leading research-intensive universities has selected the second edition of The Psychology of Information Security to be included in their flagship Information Security programme as part of their ongoing collaboration with industry professionals.

“We incorporated The Psychology of Information Security into our MSc in Information Security, where it has become part of the essential reading for the Human Aspects of Security and Privacy module. Over time, it has proven to be a valuable anchor text within the curriculum, helping to frame discussions around the human dimensions of cybersecurity in a structured and coherent way.

Students consistently appreciate the perspectives it offers, particularly its ability to bridge academic research with real-world industry practice. It not only provides a clear roadmap through a complex and wide-ranging topic, but also encourages a broad understanding of the psychological principles underpinning everyday security challenges.”

Dr Konstantinos Mersinas, PhD, CISSP

Associate Professor, Information Security Group, Royal Holloway, University of London

Visiting Professor, Keio University Tokyo, Japan 特別 招聘 准教授   慶応 大学 東京 日本

Director of Distance Learning MSc Programme in Information Security

Vice Chair, INCS-CoE (International Cyber Security Center of Excellence)

More

AI-enabled security at the speed of business

Today, organisations are caught between two opposing forces. On one side is the drive for operational efficiency through digital transformation and AI adoption. On the other is an asymmetric cyber threat landscape.

As adversaries leverage AI to increase the scale and sophistication of attacks overwhelming already stretched cyber teams, defenders must do the same by using AI to strengthen security.

The traditional security model is reactive. When a threat is detected, a human must review, validate and remediate. In the time it takes an analyst to finish their first coffee, an AI-driven adversary can exfiltrate sensitive data.

For organisations that depend on customer trust and regulatory compliance, “responding as fast as we can” is no longer within risk appetite. Humans cannot scale to match the speed of automated code.

AI is becoming central to the future of cyber defence. While much of the industry focuses on automating security operations triage, the true power of AI lies in automating complex, proactive security and compliance functions that previously required thousands of human hours.

More

My booked named #1 Amazon Best Seller

Excited that my book just hit #1 on Amazon’s bestseller list. Thank you to everyone who read, recommended, reviewed and supported this project – I couldn’t have done it without you. If you’ve read it, I’d love to hear what resonated most.

If you haven’t read it – it’s currently on offer in some Amazon stores, so get your 23% discount while you can!

And yes – it’s technically #1 in the very specific category, which is slightly amusing… I suspect it’s a hit with late-night cyber security enthusiasts rather than beach readers!

How to land cyber deliverables: from strategy to impact

It was good to moderate a discussion on bridging the gap between strategy and execution. Great, candid conversation and plenty I’ll take back to the office.

Key takeaways:

☑️ Buy-in happens when you translate risk into business impact, work across functions and deliver early, visible wins.

☑️ Common pitfall: a glossy PowerPoint deck with no delivery plan. Convert vision into smaller, time-boxed outcomes with clear owners.

☑️ What makes the difference: realistic roadmaps, measurable OKRs (outcomes not activity), empowered teams and a steady governance cadence that removes blockers.

Thanks to the panelists and everyone in the audience who challenged orthodoxies – I learned as much as I hope I gave.

More