Cult Products · 2026-05-12 · 35 min
Key moments - from our scoring
Substance score
63 / 100
Five dimensions, 20 points each
Matthew Tregas reframes cybersecurity from a compliance burden into a business enablement challenge. Rather than imposing hard restrictions that drive problems underground, effective security leaders must adopt a product mindset - understanding what teams are trying to accomplish and designing solutions that remove friction while protecting critical assets. He compares this to how legal teams should partner with commercial teams early in deal-making, and uses accessible building design as an analogy: good security should be normalized and invisible, not retrofitted and obstructive. The episode covers the CISO's role as 'good cop' versus governance's 'bad cop' function, the importance of risk quantification versus vague 'risk-driven' decisions, and the critical gap between reported metrics (like 94% patch rates) and actionable understanding. Tregas emphasizes anchoring security decisions to what's actually critical to business operations - examining supply chain dependencies, data flows, and third-party systems rather than deploying tools reflexively. He references the Cyber Governance Code of Practice, technical debt payback, and real examples of misaligned security investments. This will resonate with B2B operators building products under pressure, technology leaders struggling to govern security without slowing delivery, and executives trying to make cybersecurity decisions without technical backgrounds.
A CISO should act as a business partner and solution provider ('good cop') who helps teams design security in from the start, while a separate governance function serves as 'bad cop' for compliance and audit. The difference is being in the moment with teams helping them solve problems, rather than blocking and laying down hard red lines that drive behavior underground.
Quantify and systematically prioritize which threats actually matter to your business using tools like threat modeling, rather than vaguely claiming to be 'risk-driven' while ignoring all security. The goal is to identify which risks are truly company-defining (reputational, regulatory, operational) versus lower-priority ones that require less investment.
Surface-level metrics hide critical context - the 6% unpatched machines might be business-critical 24/7 production systems that can't be taken offline, making them the highest-risk assets despite the percentage. Drill-down visibility is essential to understand what metrics actually mean for operations and budget needs.
Rather than heavy investment in on-premise infrastructure hardening, focus on access control, role-based administration, data archiving, and good data hygiene within the cloud platforms themselves - the actual risk surface where the business operates, not on tools deployed to desktops.
The Cyber Governance Code of Practice provides a business-focused framework (not technical controls or ISO 27001) covering risk appetite, strategy, people, incident readiness, and governance - starting with the question 'which systems are critical to our business operations?' before deploying any tools or controls.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains substantive ideas about security as business partnering, risk quantification, and governance reframing - valuable for operators. However, it suffers from repetition (the 'crocodile nearest the boat' analogy used multiple times, similar points about assuming positive intent restated), and meandering philosophical tangents that dilute density. A smart founder would extract 4-5 core principles but sift through considerable padding.
Can we quantify that? Can we be systematic about that?
I think the security is the same. Or that CISO mindset should be one of how can I provide? So how am I a solution provider? How m am I a business partner
The framing of security as business partnership and the legal-team analogy are useful and relatively fresh. However, the core ideas - empathy in security, securing by design, risk-driven decisions, aligning security with business outcomes - are increasingly mainstream in progressive CISO thinking. The episode lacks contrarian takes or first-principles challenges; instead it reinforces existing modern security doctrine without sharp original angles.
So I think the security is the same. Or that CISO mindset should be one of how can I provide? So how am I a solution provider? How m am I a business partner for the organization
If you see a brilliant building that's been designed beautifully, it's accessible for everyone...I think security is the same
Matthew Tregas is an experienced practitioner with real operational exposure (children's services, manufacturing, cloud-first orgs, bank projects) and has contributed to the UK's Cyber Governance Code of Practice. He is credible and has done substantive work. However, he is not a founder/CEO of a major cybersecurity company, not a public company operator, and his current platform appears advisory rather than scaling a product at venture scale. For a B2B podcast focused on 'founders and leaders shaping the next wave', he is a thoughtful advisor rather than a high-caliber builder.
I was one of those whiz kit geeky kids in the 80s
I was a contributing editor on that NCSE published called How CISOs Communicate with Boards
The episode includes some concrete examples: the 94% patching metric revealing 6% of critical manufacturing machines unpatched (requiring £85,000 investment), the Google Search Appliance bank deployment surfacing unauthorized access, and the children's services client work. However, many claims lack specifics: no named companies (except Google), no performance metrics on outcomes, no revenue/cost figures beyond the £85k estimate, and frequent abstract language. Statements like 'I see businesses doing good, sensible stuff' or references to 'high profile attacks last year' offer no concrete detail.
94% of the machines are patched and up to date they've all been 94% of machines patched in the last 14 days...the 6% are uh, some machines that are running in our manufacturing facility...We need £85,000 to upgrade a whole raft of out of date devices
Google used to make physical devices...They used to make rack mounted internal servers. Google search appliance it was called...We deployed a couple of these for clients...And one of them we deployed for a bank
Phil asks good open-ended questions (role of CISO, how to reframe risk as value-add, startup challenge) and occasionally probes deeper ('talk to me about the 6%', drilling into the patching metric). However, follow-up questions are often shallow or allow long monologues without interruption or pushback. Phil does not challenge vague claims (e.g., 'people trick themselves', 'lack of imagination'), does not request specifics when examples are generic, and rarely creates productive tension. The conversation feels warm and collaborative rather than incisive; a sharper host would have extracted more concrete insights.
Let's just dig into that a little bit. And this is a good example of governance of do people feel able to cross examine or question...Talk to me about the 6%.
If I said to you tomorrow morning you're going to wake up with this burning desire to start your own startup in the cybersecurity space...what would be the thing that you would say?
Computed from the transcript - who did the talking, and the words that came up most.
Most organisations believe they have a handle on their cyber risk. They have green KPIs, patching reports, and a CISO in post. What many of them do not have is a clear view of what is actually critical to their business, and that gap is where the real exposure lives. Matthew Treagus has been helping people use technology to do interesting things since the eighties, starting with a maths teacher who lent him a computer and a curiosity that never quite went away. Over the decades, he has co-founded a digital agency, been a Partner in a management consultancy and led transformation efforts at a diverse range of businesses. He was CIO and Chief of Staff at Oxford Biomedica - a life sciences business. He now works as a fractional tech exec for a number of organisations. He was a contributor to the NCSC/DSIT Cyber Governance Code of Practice.His approach is grounded in empathy, commercial thinking, and a persistent belief that security works best when it is designed in rather than bolted on.
Transcribed and scored by The B2B Podcast Index.
Speaker A: I hear the industry talk about re risk driven. It means I'm choosing to take a high risk position. So all of that security stuff you talk to me about, I'm going to ignore it because I'm risk driven and the risk is I don't ship the product or we don't make any money. How do we get really risk driven? What are the things that we're worried about, that we're really worried about, that we really need to be addressing which other things are lower risk? Can we quantify that? Can we be systematic about that?
Speaker B: Welcome to Cult Products, a podcast by EIR Digital. I'm your host, Phil Keith Keeney Bolland and on this show we sit down with the founders and leaders shaping the next wave of cybersecurity innovation. You'll hear the stories behind how they found their first customers, defined what made them different, and built products that earned a loyal following in one of the toughest markets on earth. Let's dive in. Matthew, welcome to COP Products. Real pleasure to have you here today.
Speaker A: Thanks Phil. Thanks for having me.
Speaker B: So I think always a good place to start is what's your name and where do you come from? What's the backstory that got you where you are today?
Speaker A: Matthew Tregas. I was one of those whiz kit geeky kids in the 80s that discovered uh, technology and had a maths teacher that lent me computers. And I have been helping people use technology to do interesting things ever since. And it turns out if you help businesses to do that, you can do some fun stuff.
Speaker B: I'm sure given you know, you've worked in various different design agencies and consultancies and places like that, thinking about influencing people, thinking about stakeholder management, thinking about change management, all of those kinds of things. What's been your experience of doing that within that uh, sort of security context and why is it so important?
Speaker A: So if you want to affect people's behavior, you need to have some empathy with them. You need to have some context. So very often from uh, any rules based or compliance or center out organization, it can be very, it's easy to criticize why is this department doing this? Or why is our commercial team run off and done this without us? Or it helps to start by assuming positive intent. And when teams, employees, clients come to me and say we need to stop this, what I ask them is, well if we're going to stop them sharing files in that way, what's our answer? Do we have a better answer? So I need to solve their problems, we need a solution centered approach. Or a client centered approach. How are we going to help this person share large files with their client rather than tell them they can't use Dropbox anymore? And I think we do have a tendency in security to lay down the hard red lines and try and block stuff. It drives the problem underground. People then start working around stuff and then we write more policies and we get mad at people. We should assume positive intent. We should. The other thing about before you criticize a man, walk a mile in his shoes, just go and do a bit more of that, a bit more listening before we try and partner rules.
Speaker B: There's a lot to unpack there, I think hear a lot people talking about engineering teams in particular who are very under pressure to ship things quickly and not putting too much friction around that process. I mean, innovation has always been happening, but, you know, now with what's happening with AI and all of those kinds of things, there's pressure to adopt new stuff quickly and not put too many barriers in the way. How would you actually describe what the role of, let's say a CISO is today?
Speaker A: So those are, uh, business partnering roles. I often use the analogy with legal teams. If you cook up a commercial deal and you've agreed it all in principle and then you go to your lawyers at the last moment and say, right, I need a contract for this. You're going to expect a world of complexity now of either you have to railroad your legal team into just doing what you ask them, probably introduce a whole load of risks and challenge for your corporate, or you have to go back to your client and undo a whole load of the conversations, which just stuff you haven't thought about. So I think the security is the same. Or that CISO mindset should be one of how can I provide? So how am I a solution provider? How m am I a business partner for the organization so that they design in the solution that we're secure? By design I mean that were a capital S and a capital D, but also a small S and a small D. I make the analogy sometimes to accessible buildings. If you see a brilliant building that's been designed beautifully, it's accessible for everyone. If you're in a wheelchair, if you are visually impaired and less impaired, you can all enjoy the space. If you watch a really rubbish old building that someone's retrofitted with a wheelchair app, it just doesn't work for anyone. It's expensive. Anybody who needs the modifications to the building will tell you it's not really very good and it looks awful and it'll fall apart and it won't work. I think security is the same if we normalize it into our thinking. Then we take cost out, we take friction out. But you have to be in the moment with the teams participating. You can't be the gatekeeper, you can't be the police. There's a separate function in some large organizations which is internal audit, governance, assurance with a capital A. Governance with a capital A. That's a different job. That's bad cop. We need our CISOs in it as good cop. Good cop, not bad cop. We need to be in there helping. It's a shorter answer.
Speaker B: Yeah, I guess it's the same as saying, you know, be an accelerator, not a break really I think interesting because I think the easiest thing in the world to do is to be really heavy handed and put the kind of maximum amount of security in place which inherently kind of comes with the maximum amount of friction. The much harder thing to do is to put the minimum amount of security in place.
Speaker A: So we talk a lot. I hear the industry talk about really risk driven. We're going to be risk driven on this, which often, if I'm a cynic when I often hear that, it means I'm choosing to take a high risk position. So all of that security stuff you talked to me about, I'm going to ignore it because I'm risk driven and the risk is I don't ship the product or we don't make any money. Okay, now there's two things in that. One, um, how do we get really risk driven? What are the things that we're worried about that we're really worried about, that we really need to be addressing which other things are lower risk. Can we quantify that? Can we be systematic about that? You know I think the use of when I see development teams just sort of remembering stuff, oh yeah, we've got this risk or this threat that we're facing into hundreds of threats. How are you systematically looking at tracking and remembering that? So I think we'll see much greater uh, systematic use of threat modeling tools or just more systematic approaches to this stuff. And then secondly, just making sure we've got the right people who are qualified to make decisions. I was asked to uh, by a CEO to support, in a quite large organization to support the product team on making some cyber risk decisions. Really solid team, brilliant engineering, customer marketing functions all nicely integrated, quite a nice low friction environment. But sometimes the product teams were making potentially very expensive risk decisions. They were making very high stakes risk decisions that I make the analogy to signing off purchase orders. So that product owner is probably allowed to sign off, I don't know, £25,000 of purchase or £5,000 of purchase order without reference to anyone else. These were kind of betting the farm grade risks. And I think that stuff, it's all good while it's working and we're doing the product releases and it's fun, that turns on you in an instant. And I, I think just making sure that our product owners are cognizant of the risks and the parameters that they have to face and when they need to make a conscious active decision on risk, not just say yeah, absolutely ignoring it to be honest. Good engineers should be normalizing this stuff in as usual. Good product owners should want that and good marketeers good product leads. These are company defining events. If you're in a high trust sector, if you're a business that you provide a tool for solicitors to manage financial transactions, if you have an information breach in that context you have a cyber outage, you're just unavailable for a week, that reputational impact is very real. Your sales team will be blaming that for the next 18 months for that revenue and rightly so.
Speaker B: And I have to say the CISOs that I'm sure this isn't universally true but certainly the CISOs that I know and have spoken to are very cognizant of that. When they describe themselves it is first and foremost about enabling the business to generate revenue, make m money, not all of those things, no reputational damage, those kinds of things and make sure that that's being done.
Speaker A: I think one of the things that helps to do so I'm working with uh, a brilliant children's services business at the moment and I'm supporting their normalizing information security into their business. Now they're really good at safeguarding so everything that they do is looking after the well being of the children that within their care. So what we've done is made when we're talking to the business. Information security is just a natural progression of that. There's no weird contrivance of language but we're interested in the well being of those children. So the more you can link the security back to the business outcomes and the more you can link it to the mission or the purpose of the release, the better. I think sometimes people don't understand the, there's a lack of imagination about how bad things could get and how quickly things could get bad. And if I were to characterize businesses that I meet, there are those that haven't had an Incident of any kind of material incident. And those that have, and the behaviors, the attitudes, their, to some extent their budgets are uh, quite different. We had a phishing attack and 15 inboxes were compromised. But we got on it and it was fine. Yeah, that's good. But there's people that have been hit. If you've been hit, your view of the world is very different.
Speaker B: This is really interesting to me because it's very difficult for me to be objective because obviously I spend a lot of my time talking about cyber security with people who are in cybersecurity. But I feel like trying my best to take myself outside of uh, that. I think there has been a bit of a shift in the perception of these things. And I think actually as somebody who's worked a lot in product design and thought about all this kind of stuff, the agentic thing is kind of fascinating. For me, agentic is almost sort of limitless potential in theory and all the rest of those kind of things. And we want people to adopt it, we want them to use it, we want them to get all the benefit of it. And you can design all of that user experience as well as you like. But if people are uh, not feeling confident because of the risk and because of the security risk, then it doesn't matter. They're just not going to use it. Businesses aren't going to adopt it. So as a designer you have to be thinking about again back to empathy. If you're trying to get people to adopt and use your product successfully, cybersecurity has to be baked into your thinking, just as it would be with the safeguarding situation, all of those kind of things.
Speaker A: I think there's a macro problem here which is in larger organizations, more established old school corporates if you will, the businesses haven't been good at uh, executing technology projects. We talk to the business about this is not about software, it's a business issue. And then they say, yeah, that's right. And they look to the IT person and because they sound a bit technical, we don't govern them or we executives don't engage or lean into them. It's an IT problem. It's quote for jar's arm. I don't, that's. The world's gone digital, right? There's a digital era we're living. So if you're running a business today, that's your context. And if you can't govern, run, lead a business in that context, then you will miss opportunities. You won't be as fast or as valuable as your purpose. Bill Digital competitors. You'll expose yourself to security weaknesses, you'll expose yourself to those gaps. So I think there's a macro problem here of businesses being good at dealing with technology in general. It's very difficult if you're a leader, an executive in a business. You haven't got a mental model of how the world works and how technology works. That's been a problem for big tech projects. That problem has come home to roost now with cyber. If you want to follow the technical thinking on this, many of your audience will be aware of this guy called Ollie Whitehead is chief technology officer at the National Cybersecurity center. And he talks about cyber being one of the biggest triggers of the biggest payback of technical debt just required. We'd let this technical debt build up around security because we pressed the snooze button on it or we didn't realize, uh, it was important. It wasn't important to us at the time. The cost, the debt we chose to take at the time had a different cost to it. If you want to follow the analogy through that cost is much higher now and we've carried some interest with it and we need to pay that back. Which is really disappointing if you're a business because I need to fix a load of stuff that was done M3, 4, 5 years ago. Infrastructure upgrades to servers, upgrades to applications, all of that kit that we need to. And that's disappointing because it's got some cost and it's probably got, not got a lot of value to it and then doubly so I want to deploy some agentic A.I. that's brilliant. Um, if we haven't got our information hygiene right, those little tools are going to start surfacing all sorts of stuff that shouldn't be in there. I'm talking now about information security a bit more. Google used to make physical devices. I tell people about this and they look at me like a mud. They used to make rack mounted internal servers. Google search appliance it was called, it's on Wikipedia. They made a yellow one and a blue one, blue ones with big companies then. And we deployed a couple of these for clients. This is up to about millions of years ago now. And one of them we deployed for a bank. The IT guy we were working with, he firmly went nuts. It's supposed to uh, follow all the Microsoft rules. So the idea was it'll only search stuff and you only see in search results internally stuff you have access to. But what it did was made that stuff accessible. And the reality was there's A whole load of stuff buried on a T drive or on a shared point or whatever on a file store somewhere that nobody should have had access to but was there. And then this tool surfaced in and um, made it accessible.
Speaker B: It almost sounds like yes, there is a lot of shiny new sexy technology stuff. But the boring unsexy bits of this haven't gone away and actually are potentially uh, more important or potentially some things that you could kind of just get away with are now, it's now really time to kind of get into that stuff.
Speaker A: Yeah. So there's a disappointing moment to that. It comes back to some of the hygiene pieces. So I, I guess with a client about six months ago, it was a technology team. We're reporting basically some basic cyber hygiene. So yeah, 94% of the machines are patched and up to date they've all been 94% of machines patched in the last 14 days. Green. Excellent says everybody. Hang on, let's just dig into that a little bit. And this is a good example of governance of do people feel able to cross examine or question. So presented with the number 94% I've been told it's green. This KPI. Excellent. Talk to me about the 6%. Well, the 6% are uh, some machines that are running in our manufacturing facility. Okay, sounds important. Why haven't they been patched? They run 24 hours a day delivering some business critical customer, critical delivery. So we can never get maintenance windows on those machines. Right. So they're the most important machines. To conclude on that story. Some of those machines couldn't be patched because they were app support. Okay. So actually we need £85,000 to upgrade a whole raft of out of date devices. That's different from 96% or M 94% or whatever. It was green. What we're saying is 10% red. And actually I need an investment to fix it.
Speaker B: How do you think about change management and bringing people along and those kinds of things? And then I think what you've described there is that. Well actually the way that we sort of connect this is firstly data is very compelling but not just surface level data. Actually drilling into that data, uh, and then framing it around something very tangible which is, look, this is the most critical bit of your business and it's not secure right now. To what extent do you think it's possible to reframe this conversation away from pure risk and pointing at things and going this, this is really on fire into a space where it's perceived as a value add business driver?
Speaker A: I Think it's a bit too much of a stretch for most organizations right now. The reframing I would do is away from technical threats or technical issues to business risk. So what are you worried about, Mrs. Operations Director? These production machines need to run 24 hours a day.
Speaker B: Good.
Speaker A: Right. You don't need any IT knowledge or you don't need to know which version of Microsoft's Windows Server we're running to talk about that problem. So if these are our critical systems and they need to run, what do you need to do to be a good client, a competent client for our technology partners and for outsourcing? We talk about supply chain in a second. To drive this positive behavior, I would encourage technical folks to go and look at decent. The Department of Science Innovation Technology and the National Cybersecurity center published about a year ago something called the Cyber Governance Code of Practice. I get quite excited about that. So I've sort of carried this geeky thing through from the 80s into, you know, what is now governance geekiness, which is quite helpful. People are paying for it. It's sort of useful. I would encourage tech folks go and look at it. It has no technology component to it. It's not ISO 27000 and what's it? It's not cyber, essentially that it's we're all good and we need our technical controls framework. I didn't mean to sound dismissive of that, but we know what that lot looks like. The governance framework is stuff that the business needs to be able to assure itself that it is doing. And my test for that, if I say to a senior business leader or the chair of the Risk and Audit Committee, how do you feel about that governance work? Is that in place? If the first thing they do is hand it to the CIO or the IT director or the CISO and say, how are we doing? That's the wrong first answer. It's broken into us if we remember the five bits. I'm pretending to not remember it now, so I don't get too geeky about it, but uh, first one is about risk appetite. Second one is about strategy, people, incident readiness and governance. But A one I was part of the team that was involved in writing it, so it's sort of there, sort of emotionally involved with it. But A1 action, A1 under risk is do we know which systems are, uh, critical to the operation of our business? And critical? Not well, be hard to manage without printers. Possibly. Maybe those two printers in that particular part of the business are really important, but. But not all of them. Right. So just taking that view of what is critical to the operation of our business and anchor everything you're doing back from that. I see businesses doing good, sensible stuff but to use the analogy, they're not focused on the crocodiles that are nearest the, the boat and they can explain why they're doing it. I think we need to anchor back to the business risks and then when we're taking actions that flow from that, are they mitigating? Are they really mitigating it? A quick example talks about supply chain. So an organization where most of its operationally critical and customer data is in third party systems. Cloud based, secured brilliant systems, absolutely the right choice for the business. Architecturally great. But then what we were quite focused on was the SOC and the securing the laptops and a whole load of sort of quite infrastructural stuff. But we didn't have any infrastructure really. Most of our business, all of our business is run on three brilliant cloud services. Right. So when we think about cyber risk and um, we think about operations or information risk as well there are we really looking at the right things are ah, we really worried about the right things actually it's about access control actually it's about some of the role based administration that we should be doing. Archiving, uh, data that just good data hygiene on other people's tools. Whole load of capabilities in the tools we weren't using. But we are busy deploying new tools on desktops because that was easier and it came to hand. Although ironically because adding cost is adding cost and may not be addressing the nearest crocodile.
Speaker B: Interesting. I'm going to give you a bit of a challenge I think which given what you just said, I think might be quite an interesting one. If I said to you tomorrow morning you're going to wake up with this burning desire to start your own startup in the cybersecurity space with a, with a technology product. So you can't say what you're already doing. What would be the thing that you would say? This is what businesses actually really need right now. This is what I can build for them and, and that will actually really move the needle and help them face these security challenges.
Speaker A: I'd like to build, I'm trying not to say the stuff that I'm already doing. So I think finding ways to help them discover or they actually use a way to sort of look at a business with X ray specs to see this is the stuff that's important. This is where the volume is, this is where the criticality is. This Other stuff, don't worry about it. I think when you ask people to think about what's critical. If I'm going to ask that question about A1, what's critical to your business? They do the thing that businesses do when they're chatting to the product owner about loading up the design sprints. They're loading up the, um, the stories and the epics. It's like we need all of this. It is beyond feasibility that we would launch a product that doesn't have this widget in it. Okay, we'll build that widget if it's that important. And then it turns out when we get nearer the deadline, you know, that widget gets thrown overboard. Nobody cared about it anyway. Somebody thought about it driving to Golf and thought they'd throw it into the Sprint. I think businesses do that a lot about what's critical and they can't see what's critical. And some of that criticality is outside of their immediate sphere of influence. It's going on elsewhere. So I wanted to be able to look at a business and see if I was an idea gates. I'm going to be distracted now thinking about how you actually do that. 10 years time telling that story to them. Well, I was chained to Phil on this podcast. I'd never really thought of it at all. Ask me this question. That's how this business got started.
Speaker B: It does feel like that challenge is becoming increasingly difficult as well because the network of technology, the nervous system within a business is so disparate and is so.
Speaker A: I love the work of the National Cybersecurity Center. If you haven't gone and looked at what they publish for free and the National Protective Services Agency Authority that between them there's a lot of good stuff that is out there to support businesses with that and if you're a ciso, is stuff you should be using or making sure your executive teams are consuming. There's some guidance that I was a contributing editor on that NCSE published called How CISOs Communicate with Boards. That's a genuinely useful thing for technologists. Um, I'll make sure you've got a link to that. One of the things NCSE talked about after some of the high profile attacks last year was you have companies need to be ready to go back and run this stuff analog. Now, I'm not a prepper. You should be driving cars with carburetors and, you know, plenty of batteries standing by. But I think when we talk, I think it's sometimes unhelpful. If you are a large retailer and you have built information systems over the years to optimize your supply chain within an inch of its life. It is challenging then to think about how you would go back to operating on paper. The concept of the minimum viable corporation. What's the minimum viable business? How do we relaunch our business in event of a crisis? Is a discipline to go through. That's one of. I think that's D1 on the code of practice and I think I'm contradicting myself. The idea that we could run our businesses on paper is nonsense. It's like the analogy now that if phone calls were still managed or data connections were still managed by people putting cables into holes and exchanges, the entire world's population would be uh, managing switching telecars and nonsense. It was just orders of magnitude more complex than how the world used to be. Which you can learn about and get nostalgic about how brilliant it all was back then. But that's not our context now. That's not our reality.
Speaker B: Interesting. What feels like more high profile cyber attacks over the past couple of years. Do you think the impact of. Do you think we'll now see more or less of those kinds of attacks? Because is it you're saying if you've been attacked you change, change your posture? I know lots of businesses are talking about we can't let that happen to us, but what's your sense of. Are the lessons being learned? Are the changes being made?
Speaker A: It's easier to understand the risk. I'm always surprised how quickly people talk away the risk though. So it's happened to them but they're higher profile and we're not a target. So there are some high profile targets, some trophy clients or trophy targets or people that might have loads of money. I forget the name of the criminal. Wasn't it? Why do you rob banks? It's like, well that's where they keep the money. Which I thought was a brilliant answer. And I think there's that with. Why have you attacked this really wealthy bank? Well, because they're likely to pay a ransom. So I think people trick themselves into thinking they're somehow not targets. They might, might not be targeted, but I think people should be a bit more open minded. And again, the National Cyber Security annual review last year has got loads of stats in which I can't remember and won't try and regurgitate about the sizes of businesses that have been attacked. And they're summarized in the annual review that they run every year about how people feel about this. I uh, do think it's on the agenda. Uh, I think there's that old thing about any capability. We move from being unconsciously incompetent where we didn't know it was a thing, we weren't really thinking about it to becoming consciously incompetent where we know it's an issue we ought to be dealing with it. I think that's where people are. The broad range of UK business has become consciously incompetent, which is a good thing. What we all now need to do is become consciously competent where we've got a plan and we think about it and we're a bit more mechanical about it. The trick is to become unconsciously competent. That's part of what we do. You don't even think about it. It's just normalized in. I think as a security industry we might like people to be over on the, the right hand side the latter part of that journey. The reality is people are just becoming consciously competent. I use that example with a client. It was English as a second language a couple of weeks ago. I think I confused them a lot with the language. So I think people are shifting. I'm not sure they necessarily know what to do. My advice to them is a uh, one, what are the things that are important to your business? And then any actions that we're taking, any plan, is it then addressing those risks? It sounds ridiculously. What are the risks? What are the systems that are critical to your business and ensure that the actions that are being taken are addressing those risks and then follow through. You'll have to dig in a bit deeper. Executive team, board team. Back to my patching example. Where are we going to patch all our machines? Did they get patched? Are they being patched? Can you prove to me that they're being patched? And we should expect auditors, any company that's going to pass audit limit. I forget what is £10 million or above. So I'd expect auditors to be looking a little harder at the general operating, general IT controls and operating risks. Certainly uh, any corporate have got those listed as their principal risks. People are going to be digging into that. There's a lack of imagination still. And I think people are preparing for coming home in the kitchens. So I come home and uh, there's a fire in the kitchen. And if I said to you right, what are you going to do now? How are you going to eat? Well we're going to shut up the kitchen. But that's horrible and it's upsetting and it's terrible but I'm still going to be able to feed my kids because I'm going to go, I'm going to go to the supermarket and I'm going to buy a microwave and I'm going to buy some ready meals and we're going to be up and running, going to be eating, we're going to be camping out in the kitchen and uh, it's probably going to be three months before the kitchen's fixed, six months before the kitchen's fixed. It's not pleasant. I'm not trying to make it sound like it's all good fun, but it's survivable. And I think what people don't plan for is I come home and the house is gone and there's no gas in the street and the power supply to the district's been shut off. Right now what I'm going to do, I'm going to log in here, you know, uh, not going to log into anything because I'm going to restore the backup onto what, where, how you do. So I, I think there's a, a lack of imagination. Feel myself repeating that. I just. And I'm not saying you need to do anything about it. Just imagine what it could be like and then make some active decisions about. Okay. I'm not preparing for that because I can't afford to. But actually sometimes just thinking about it uh, is enough. I think it's. The group chair of the co op wrote an open letter that is published in various places, was on the inside front cover of the annual the Cyber Security Center's annual review. It's worth reading. She was very generous in sharing information and very open about and could do so. It was of the nature of their business. Some PLCs are much more guarded about and there's an under reporting I'm sure of cyber incidents and the near misses which is a shame that her experience was one that should resonate with you.
Speaker B: Interesting. I think we can probably, probably link to that one. We can't finish on such a, uh, down, downbeat note as your house is blown up and the world's ending and uh, all this kind of stuff. So my last question for you. What are you optimistic about looking ahead within this space?
Speaker A: I think what I'm optimistic about is organizations investing in and realizing that they're living now in a digital era. The world has gone digital. As I said before, the threats are digital but the opportunities are digital as well. So whether that's agentic AI, whether it's actually automation that we should have been doing already, that we hadn't Done. There's a whole raft of technologies out there that can help us do what we already do much better and start to do exciting new things that were impossible without the technology. So imagining ourselves, if we were born today, how would we be? And I think if you use the cyber threat, I think right, we need to get good at uh technology that should be an empowering and enabling thing. And nobody kitchen needs to get burned down. So positive. And if we do that and we focus on the experience we want to give our employees the experience we want to give our customers. And that's tough. That change is tough. We can see in purpose built, well led technology business. Optimus is my, I'm a bit of an octopus fanboy if you look at that's a business that's purpose built and I think if you're an incumbent in that sector, uh, you can be looking at that thinking I want to do what they're doing. I think I'm already doing the same thing as them. But they're, that's how I'm just doing it. They're unconsciously competent, they're just brilliant. They're doing it. I can't quite get good at it. So that's the opportunity here. You've got to get good at technology because the world's gone digital. It's design the products we've got okay at uh, the business to support the product. It's that obsession about the user, obsession about the customer. Those are healthy product behaviors. How do we make sure the original government digital service has some brilliant design principles which is still out there and still right. And we don't just design end to end, we design front to back as well. So everything is in support of that. Uh, we do the hard work but you don't need to so you don't have to. I think that same mentality is there and I don't use the T word very often but our digital transformations are really just additions. We've added digital and we add to the complexity of our business and we need to be subtracting. And that's the advice I give clients around AI at the moment you're building agentic in what are we taking away? What, what do we replace that effort with or what is that effort displacing and just thinking about the role of humans. Very optimistic about the role of humans. And I do not buy, you know, we're not all going to be working two day weeks. I will absolutely guarantee that when new technologies come along it absolutely. It can be catastrophic for some classes of of job. You know, we used to load boats were loaded by people with grain in sacks and then at some point the railways came right up to the shoreline and steam elevators loaded grain elevators, steam powered grain elevators loaded ships and no grain sees the inside of a sack. There's a brilliant book, which I borrowed that from, called heyday, about the 1850s and it looks at technology change, but people are still busy. And then, you know, the Camel email came along and it's going to make everything quicker and simpler and, you know, Microsoft Office comes along. We're still working five days a week with. Six days a week with these.
Speaker B: I'm more optimistic. I think we'll be living in a utopian society where we'll all just be artists and musicians and everyone's having a great time after the collapse of civilization and, um, the years of war.
Speaker A: I love your work, Phil. I don't think you're right about this.
Speaker B: The survivors are going to have a great time. Thank you so much. It's been so great to chat to you today. Where can people find you and get in touch with you?
Speaker A: Trigus.com is my website. It sets out what I do and I'm Mrigus.com amazing.
Speaker B: Thank you. Thank you so much, Matthew.
Speaker A: Thanks all. Cheers. Bye.
Speaker B: Cop Products is brought to you by Yaya, helping cybersecurity companies define who they're for, what they do and how they're different. To learn more, visit Yaya Co. And don't forget to search for cult products in Apple podcasts, Spotify or wherever you listen. Follow the show so you never miss an episode. On behalf of the team at Yaya, thanks for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.