Phishing for Trouble from IO (ISMS.online)

Phishing for Trouble from IO (ISMS.online)

IO (ISMS.online)
Negara Britania Raya
Genre Bisnis
Bahasa EN
Episode 22
Terbaru 23.07.2026

Phishing for Trouble is the business resilience podcast from IO (ISMS.online), a platform used by thousands of teams to manage compliance and build resilience day to day. Hosts Rebecca Harper and David Holloway talk with security leaders, specialists and business experts about compliance, security, privacy and AI risk. The show cuts through the noise to offer practical advice that listeners can take back to their teams. Episodes are honest, useful and occasionally a little awkward.

Episode

  • Built to Last: How Compliance Enables Business Resilience 23.07.2026 49mnt
    Looking back at Phishing For Trouble's second season, we've explored the challenges organisations face as technology, regulation and risk evolve, from supply chain vulnerabilities and AI governance to privacy, operational resilience and what regulators are really looking for.In this final episode, IO's Rebecca Harper and David Holloway are joined by Rik Ferguson, Vice President of Security Intelligence at Forescout Technologies and founding Special Advisor to Europol's European Cyber Crime Centre. Drawing on decades of experience, Rik reflects on the biggest lessons from the series and what organisations need to do to build resilience in an increasingly complex landscape.Featuring key moments from guests across the season, Rik shares his perspective on why compliance should be treated as the foundation for growth rather than a tick-box exercise, how organisations can prepare for an AI-driven future, what effective resilience really looks like, and why governance, visibility and culture matter just as much as technology.If you're wondering what separates organisations that simply react from those that are built to last, this episode brings the whole season together. Find out more at ISMS.online
  • Privacy as Power 09.07.2026 31mnt
    What happens when privacy stops being a legal issue and starts shaping whether your business can grow? In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore why privacy is now a commercial issue, not just a compliance one.They’re joined by Joe Jones, Director of Research and Insights at the IAPP, and Jennifer Appleton, Managing Director at ISO Quality Services, to discuss how organisations are turning privacy into a source of trust, resilience and competitive advantage.Hear why businesses are losing deals, slowing procurement and stalling expansion plans because they can’t clearly explain howdata is being used and why frameworks like GDPR and ISO 27701 are becoming essential foundations for growth.From privacy by design and AI governance to customer trust and cross-border data challenges, this episode explores why the organisations embedding privacy into the way they operate are often the ones moving faster, scaling smarter and building trust that lasts.Find out more at ISMS.online
  • What the Regulators Want 02.07.2026 19mnt
    Today, regulators don’t just want compliance, they want accountability and resilience.In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore how the shift of expectations isn’t just about speed, it’s about demonstrable, baked-in compliance.Regulators are no longer passive; they’re proactive, prescriptive, and punitive.They’re joined by Paul Vane, the Information Commissioner for the Jersey Office of the Information Commissioner, a man who has worked in privacy and data protection for over two decades and uniquely equipped to clarify how the relationship between company and regulator should work, and why sometimes it doesn’t.Hear what you should be planning for, months or years before a breach, how the mindset for crisis readiness needs to be a continuous process rather than a periodic exercise, and how themember of staff best equipped to cope, should the worst happen, often isn’t from the senior leadership team.   The ultimate ambition is to shift the culture from “responded well” to “being able to see it coming”. It’s no longer enough to simply recover in a crisis, the expectations are now to think about future risks and show some evidence of how you mitigated those dangers ahead of time.Find out more at ISMS.online
  • The Cost of Doing Nothing 25.06.2026 22mnt
    What does a cyber incident really cost a business? In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore the hidden commercial impact of weak security, poor compliance and delayed investment in resilience.They’re joined by Alan Hughes, Chief Operations Officer at Savenet Solutions, who has worked with organisations before, during and after major cyber incidents witnessing the long-term fallout that often never makes the headlines.Hear why the real damage doesn’t stop with the breach itself, from lost contracts and stalled growth to reputational harm thatcan take years to recover from.The episode explores why smaller businesses are increasingly being targeted, how supply chain requirements are reshapingcustomer expectations and why doing nothing can quickly become the most expensive decision a company makes.From ransomware attacks and failed security questionnaires to business continuity, tested backups and recovery planning, this episode looks at what separates the organisations that recover quickly from the ones left trying to rebuild.Find out more at ISMS.online
  • Scaling Securely: What High-Growth Firms Get Right 18.06.2026 21mnt
    What happens when your business grows faster than its foundations can handle?In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore why the companies that scale successfully aren’t necessarily the ones that achieve compliance fastest. They’re the ones that build security, privacy and governance into the way they operate from the very beginning.They’re joined by cyber leader Purvi Kay, whose experience spans government, aerospace and FTSE 100 boardrooms and Andy Ellis cybersecurity advisor, former Chief Security Officer at Akamai and author of 1% Leadership.Hear why “security debt” can quietly build as startups race to grow, why compliance should be treated as a product featureand how resilience becomes a competitive advantage as organisations scale.From secure-by-design principles and embedded security teams to risk appetite, customer trust and leadership accountability, this episode explores what high-growth firms get right and why resilience is about far more than passing an audit.Find out more at ISMS.online
  • You’re compliant, are you resilient? 11.06.2026 38mnt
    What happens when a cyber attack doesn’t just disrupt your business, but stops it completely? In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore why resilience has become a defining business challenge fororganisations of every size. Using the Jaguar Land Rover cyber attack as a case study, alongside insights from cybersecurity expert Pierre Noel and Professor Ciaran Martin, founding CEO of the UK National Cyber Security Centre, they unpack the growing gap between compliance and genuine operational resilience. Hear why businesses are moving from prevention to preparedness, why supply chain resilience matters now more than ever, and why the organisations best placed to survive disruption are the ones building resilience into every part of their operations.Find out more at ISMS.online
  • Boardroom to Breakroom: Building a Culture of Compliance 04.06.2026 26mnt
    Why do organisations still struggle to turn security policy into real-world behaviour? In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore how regulations like NIS2 place direct accountability on senior leaders whilst, in many organisations, compliance still lives on paper and not in practice.They’re joined by Professor Steven Furnell, Professor of Cyber Security at the University of Nottingham, an expert in the intersection of human, technological and organisationalaspects of cyber security and full of good advice on turning policy into real action. Hear how having a policy isn’t the same as people understanding how it applies directly to them and their job,the importance of moving away from ‘tick box’ compliance and how, wrongly handled, security training and tests can feel punitive, rather than supportive. Because if staff are using unapproved processes or shadow I.T. and A.I, it might actually be a clue to what resources the business is lacking and a cue to ask the questions that fillthe gaps compliantly.Find out more at ISMS.online
  • Supply Chain Dominoes: Why Their Risk Is Now Your Risk 28.05.2026 27mnt
    What happens when a third-party company suffers a security breach, way down the supply chain – and the people who suffer are your customers?In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore how, even if your systems are strong, a weak supplier can shut you down, how regulators and investors are demanding stronger supplier governance, and what you need to do about it.They’re joined by Madelein Van Der Hout, a senior analyst in cyber security and risk at Forrester who digs into the detail of recent high-profile breaches and what questions businesses should be asking, and the University of Oxford’s Professor Ciaran Martin - founding CEO of the UK National Cyber Security Centre and one of the UK’s leading voices on cyber resilience. Hear how the cost of a supply chain breach can be more than financial, ways to identify risk and dig deeper into supplier assurances, and how to cope with the regulatory landscape as it evolves and developsBecause it’s not just the disruption and damaged reputation a breach can cause, it can affect the profitability of both suppliers and clients, and employee job stability.Find out more at ISMS.online
  • AI: Trust, Ethics, and Getting It Right from the Start 21.05.2026 41mnt
    What happens when employees start using AI toolsfaster than organisations can govern them?In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore why AI governance has quickly become a business-critical issue, from shadow AI and data privacy risks to accountability, trust and emerging regulation.They’re joined by Professor Andrea Isoni, who works with organisations navigating AI governance and risk and A-LIGN’s Patrick Sullivan, VP of Strategy and Innovation, who advises businesses on AI strategy, governance and emerging technologies. Hear why governance is no longer just about compliance, but about building resilience, visibility and trust as AI becomes embedded across organisations.Find out more at ISMS.online  AI Governance hub: AI Governance | ISO 42001Readiness Checklist: Guide to AI Compliance Blog by Patrick Sullivan: Why AIGovernance Stopped Being Theoretical and What Leaders Must Do Next | A-LIGN
  • Compliance: From Checkbox to Competitive Advantage 14.05.2026 29mnt
    What happens when your biggest deal stalls at the final hurdle because procurement asks questions your business cannot answer? In this episode of Phishing for Trouble, IO’s Rebecca Harper and David Holloway explore why compliance is now a commercial issue, not just a technical one.  They’re joined by Daniel Bailey from ECI Partners who spends his time helping ambitious companies grow, and the University of Oxford’s Professor Ciaran Martin - founding CEO of the UK National Cyber Security Centre and one of the UK’s leading voices on cyber resilience.  Hear why “resilience” now shapes valuation, customer trust and long-term growth, from investor due diligence to cyber risk and boardroom accountability.Being compliant on paper can be one of the most expensive mistakes a business makes, but those companies building resilience in early are the ones moving fast, winning big and scaling smarter. Find out more at ISMS.online
  • Phishing for Trouble Returns This Thursday 14th May 11.05.2026 1mnt
    Compliance, security, privacy, AI risk. There's a lot of noise out there, and not much of it is useful when you're the one having to do the work.Phishing for Trouble is the business resilience podcast from IO (ISMS.online), the platform thousands of teams use to manage compliance and build resilience day to day. Rebecca Harper and David Holloway talk to the security leaders, specialists and business experts they actually learn from, the kind of guests who give you something to take back to your team on Monday.Honest, practical, sometimes a bit awkward. Always useful.
  • The big cybersecurity questions facing businesses in the future 04.02.2025 35mnt
    In the final episode of the series, Rebecca Harper and David Holloway are here to recap some top tips for cyber compliance in your business.But before that, they’re reflecting on ideas from our expert guests and discussing some of the trends, questions, challenges and opportunities for information security professionals in the near future.  Whether it’s looking at changes to cyber law enforcement or policy, how to keep up with the changes in tech as a business and how you can start to get AI compliant and grow your business, explore how you can step ahead and stay ahead with great information security. "Phishing for Trouble," is the cybersecurity podcast from ⁠ISMS.online⁠ that demystifies compliance and information security in your business.To find out more about how ISMS.online can help your business master information security compliance, visit our website for a self-guided tour.Love this podcast? Share it with your colleagues and help businesses like yours learn more and stay secure online. #Informationsecuritypodcast#infosecpod#cyberattackcasestudies#UKAIpolicyandinfosec#growyourbusiness#cybersecuritypodcast#AIandinfosecMusic from #Uppbeat (free for Creators!):https://uppbeat.io/t/barry-dallas/turn-it-upLicense code: DRP9E1ZZYQJDJ1DS
  • What not to do in a disaster 28.01.2025 39mnt
    Back in May 2017, a cryptoworm virus made it into some Microsoft computing systems, locking away the data of global organisations and demanding a ransom. In panic some people paid up only to find their data never returned. The knock-on effect to health services, including hospitals, was dramatic. So what do you do if you’re faced with such a scenario? In this episode, David Holloway and Rebecca Harper talk about the right and wrong things to do in the face of a ransomware or other cyber attack. Plus they’re joined by the experts to look at how we can all plan better for the worst – so that when a data breach or cyber attack takes place, your business and your people are in the best position to recover quickly. Leading infosec thinkers Ash Patel of ECI Partners and Chloé Messdaghi, founder of Sustain Cyber and leader in responsible AI and cybersecurity, share their wisdom, as well as some hopeful advice for information security teams in the future."Phishing for Trouble," is the cybersecurity podcast from ⁠ISMS.online⁠ that demystifies compliance and informationsecurity in your business.To find out more about how ISMS.online can help your business master information security compliance, visit our website for a self-guided tour.Love this podcast? Share it with your colleagues and help businesses like yours learn more and stay secureonline.#Informationsecuritypodcast#infosecpod#cyberattackcasestudies#cybersecuritypodcast#disastermitigationpodcast
  • Safe software, safer business 21.01.2025 32mnt
    How can you protect your business from hackers? Whilst no company is safe from IT security attacks, the way your company develops, manages and uses software is key. Staying up to date with the latest advice and patches, raising awareness of hacker tactics and educating your people on how to use platforms safely is all a part of the puzzle.Rebecca Harper and David Holloway share stories of how even the biggest names can be tripped up by poor software security and how infosec and compliance is everyone’s responsibility.The brilliant Troy Hunt shares his insights into why infosec is about people, psychology and behaviour as muchas it is technology, and why so many of us are still getting caught out by simple tactics. On the bright side, we also look at some of the tools and approaches you can use to minimise your chance of being one of them."Phishing for Trouble," is the cybersecurity podcast from ⁠ISMS.online⁠ that demystifies compliance and informationsecurity in your business.To find out more about how ISMS.online can help your business master information security compliance, visit our website for a self-guided tour.Love this podcast? Share it with your colleagues and help businesses like yours learn more and stay secure online. #Informationsecuritypodcast#infosecpod#cyberattackcasestudies#cybersecuritypodcast#Compliancepodcast
  • IP, privacy and cybersecurity explained 14.01.2025 49mnt
    If you’re unsure about how intellectual property can be exploited or misused in cyberspace, you could be vulnerable in the eyes of the law. Whether it’s protecting the intellectual property you handle on behalf of your customers and partners, or the security of your own IP, we’re here to help. In this episode the Privacy Professor Rebecca Herold and distinguished cyber leader Wendy Nather are here to help you understand why IP protection is a vital part of your business security. They’ll share examples to help you identify how technology and privacy can intersect around IP in your organisation as well as strategies for protecting and auditing this. And Rebecca Harper and David Holloway unpick some real-life examples of how organisations have been caught out, so you can learn from them."Phishing for Trouble," is the cybersecurity podcast from ⁠ISMS.online⁠ that demystifies compliance and informationsecurity in your business.To find out more about how ISMS.online can help your business master information security compliance, visit our website for a self-guided tour.Love this podcast? Share it with your colleagues and help businesses like yours learn more and stay secure online. #Informationsecuritypodcast#dataprivacy#intellectualproperty#ipandtech#cybersecuritypodcast#Compliancepodcast
  • Tricksters, Trapdoors, Vishing and Phishing 07.01.2025 39mnt
    How was one of the world’s biggest media companies brought to its knees by a cyber hack? This time we hear how hackers gained access to Sony Pictures in 2014 by manipulating the sociology and psychology of staff. The truth is, a company can invest millions in cybersecurity technology, but social engineering tactics can allow hackers to gain access to an organisation’s IT through the individuals that work there.  Plus, it’s not just big organisations that can be exposed to ransomware and other attacks. Whatever size your business is and whatever sector, you could be vulnerable.  So how can a company overcome the enormous threat social engineering poses to its data and information security? Becca and Dave bring you expert insights and advice into what you should be doing in your business today, supported by ISO 27001 frameworks. Geoff White is an author and investigative journalist with a special interest in organised crime and technology. He says that tech companies need to think about ALL the ways their products can be used, be that for good or harm. Javvad Malik returns with advice for anyone faced with phishing and vishing communications, and Dr Jessica Barker discusses how hacking groups can target individuals to have a devastating impact on their lives. Professor Keith Martin from Royal Holloway University is leading research into information security that could inform the tools and practises of business in the future. But one thing all our guests agree on is the power of people and culture to protect a business. They discuss how to engage staff in information security on a day-to-day basis."Phishing for Trouble," is the cybersecurity podcast from ⁠ISMS.online⁠ that demystifies compliance and informationsecurity in your business.To learn more about how ISMS.online can help your business master information security compliance, visit our website for a self-guided tour.Love this podcast? Share it with your colleagues and help businesses like yours learn more and stay secure online. #Informationsecuritypodcast#whatisphishing#socialengineering#whatisvishing#sonyhack#cybersecuritypodcast#Compliancepodcast
  • Who has the keys to your business? 17.12.2024 27mnt
    This time we’re delving into best practises for IT leaders looking to prevent data breaches through third party access. Don’t know what that is? David and Becca will be unveiling more high profile slip-ups and mishaps and exploring how you can protect against cyberattacks.How clued up are you on who has access to sensitive information, networks or other data in your business? What about individuals who have left the business and contractors with temporary access? It’s so easy to leave the door open to a cyber hack via third-parties, but it’s also easy to make a few changes that minimise the risks to your business and customers. There’s plenty of guidance around the ISO standards in this podcast too.Steve Wright is the founder of Privacy Culture, an organisation that works with global clients on data protection, privacy and cybersecurity. Steve’s 30 years in the business has given him a broad perspective on how people can adapt to changing technology and IT to stay compliant.Ash Patel of ECI Partners returns to share how businesses large and small can be prey to attacks and why compliance around third-party access is so important to investors. If your business is going to survive, cybersecurity is a part of every leader’s toolkit."Phishing for Trouble," is the cybersecurity podcast from ⁠ISMS.online⁠ that demystifies compliance and informationsecurity in your business.To learn more about how ISMS.online can help your business master information security compliance, visitour website for a self-guided tour.Love this podcast? Share it with your colleagues and help businesses like yours learn more and stay secure online. #Informationsecuritypodcast#thirdpartyaccess#thirdpartycompliance#cybersecuritypodcast#Compliancepodcast
  • Are you at the front line of defence? 10.12.2024 32mnt
    Thought cybersecurity was just about tech? Think again, because human beings are the biggest asset you have in keeping your business secure. In this episode Dave and Becca find out how social engineering tactics have caught out even the biggest organisations, and how you can learn from them. As always, some of the smartest minds in infosec are here to share their wisdom:Dr Jessica Barker MBE, founder of Cygenta, witnessed the MGM cyber hack of 2023 from her home in Las Vegas. She explains how behavioural economics plays a role in cyber attacks.Javvad Malik is a security awareness advocate for KnowBe4 and is passionate about connecting knowledge between the IT industry and the people using technology every day. Have you been Pwnd? Troy Hunt is founder of the Data Breach Notification Service “Have I Been Pwnd” which helps you find out if your data has been leaked in cyber attacks. He reflects on the increasing sophistication of social engineering.But help is at hand! All our guests agree that empowering people with knowledge in this space can help prevent hackers getting the better of you, and Javvad and Jessica take us through their steps to avoid and respond to an attack on your business."Phishing for Trouble," is the cybersecurity podcast from ISMS.online that demystifies compliance and information security in your business.To learn more about how ISMS.online can help your business master information security compliance, visit our website for a self-guided tour.Love this podcast? Share it with your colleagues and help businesses like yours learn more and stay secure online.#Informationsecuritypodcast#cybersecuritypodcast#Compliancepodcast
  • How safe is my private information? 03.12.2024 37mnt
    Data protection doesn’t have the most exciting reputation but it can be pretty dramatic when you miss it off your compliance list! From the legal consequences of data breaches to human error, not having a prevention or response plan in place can land even the biggest companies in hot water.In this podcast Dave and Becca explore the different between personal and sensitive information and what makes a strong password. Plus they share tips on how you can use compliance frameworks to help secure your organisation against cyberattacks and hacks.As always they’re joined by expert guests from the world of cybersecurity, compliance and information security:Gary Hibberd is a security consultant who runs “Consultants Like Us” He shares his tips on how to build a data protection policy that doesn’t cost you a penny.Steve Wright is the CEO and Founder of Privacy Culture. He has 30 years of cybersecurity experience and he explains just how vital it is for organisations to protect their customer data through robust processes and frameworks.Ash Patel works for ECI partners and knows just how important it is to continuously evolve your information compliance and security. In fact, he says it’s a crucial part of managing change."Phishing for Trouble," is the cybersecurity podcast that demystifies compliance and information security in your business. Links Mentioned in this episode:The General Data Protection Act
  • How secure are our services? Cybercrime and critical infrastructure 26.11.2024 36mnt
    "Phishing for Trouble," is the cybersecurity podcast that demystifies compliance and information security in your business.   We know any cyber hack is bad for business. But what about the customers and networks that rely upon the services it provides?   Dave and Becca delve into the Colonial Pipeline attack of 2021. Thousands of miles of US fuel supply came to a halt for days after the company was hit with a ransomware attack. There were massive economic impacts from this cybersecurity incident. Under immense pressure, bosses made the decision to pay up on the $4.4million bitcoin ransom. They later had to explain this decision in court.   So what went wrong in CP’s information security and compliance procedures? If a company that invests millions annually in cybersecurity AND provides such a fundamental national resource got caught out, is there hope for the rest of us? How did hackers get into the network and what can we all learn and action in our own businesses?   Rob Lee from SANS institute reflects upon learnings from his career in protecting national cybersecurity in this podcast. He’s passionate about educating and empowering organisations to take action and protect themselves there.   Rob explains how he move from the Air Force Academy to National Cybersecurity and today still advises the US government on the tech side of cyber intrusions and capabilities. For more insights into how to stay compliant and secure, visit ISMS.online to explore the ISO 27001 framework and take a tour of our platform.   #cybersecurity #compliance #informationsecurity #podcast #business #dataprotection #cyberattack #casestudy

Populer di

Podcast ini juga muncul di daftar podcast negara-negara ini.