From Firefighting to Strategizing IT Security with Giles Thornton
Fetch error
Hmmm there seems to be a problem fetching this series right now. Last successful fetch was on October 09, 2025 11:26 ()
What now? This series will be checked again in the next day. If you believe it should be working, please verify the publisher's feed link below is valid and includes actual episode links. You can contact support to request the feed be immediately fetched.
Manage episode 512561806 series 3638853
- How to balance security perfectionism with practical implementation
- Why compliance shouldn't be confused with security, and how to move beyond checkbox exercises to meaningful risk management
- The importance of brutal prioritization in security leadership
- How to effectively automate security operations while maintaining human oversight and trust
- Why building human relationships and trust networks is crucial for modern security programs
- The emerging challenges of AI governance and quantum encryption, and how to prepare for future security landscapes
YouTube Chapters:
- [00:00] Intro
- [00:43] The Culture of “Never Enough Security”
- [01:42] Do Breaches Stem from Lack of Strategy?
- [03:44] Perfect vs. Good
- [08:01] Burnout and Cybersecurity Career Path
- [10:01] From Firefighting to Proactive Security
- [11:44] Automation and AI: Hype vs. Reality
- [12:58] Building Digital Trust
- [15:38] The Power of “So What?”
- [17:56] The 47-Day TLS Shift
- [28:21] Top Concerns: AI and Quantum
- [33:20] The Nudge Theory in Cybersecurity Training
- [35:36] The Myth of Eliminating Risk
- [37:25] Tech Giles Can’t Live Without
Episode Resources:
Key Takeaways:
- [01:42] Do Breaches Stem from Lack of Strategy?
- [10:01] From Firefighting to Proactive Security
- [33:20] The Nudge Theory in Cybersecurity Training
Quotes:
- “Security's quite often a game of not being the slowest person in the race. Just start running and doing some security puts you ahead of the vast majority of others.”
- “Compliance has its own function and purpose, but thinking that you have effectively applied risk management because you've complied with the tick list is not the same thing.”
- “You need to review the risk and take reasonable action. Making people maintain a 100% rate for compliance purposes is a way for burnout.”
- “The human relationship aspect of security is quite often overlooked. There's a real requirement in security to be perceived as confident, competent and to put that persona out to the business.”
11 epizódok