Skip to content
PodcastsBusinessRazorwire Cyber Security & InfoSec Insights

Razorwire Cyber Security & InfoSec Insights

Razorthorn Security | Cybersecurity & InfoSec
Razorwire Cyber Security & InfoSec Insights
Latest episode

103 episodes

  • Razorwire Cyber Security & InfoSec Insights

    Why Social Engineering Still Works & Why AI Is Making It Worse

    2026/07/29 | 55 mins.
    Social engineering has been around since humans started talking to each other. The psychology hasn't changed, but AI has made the execution almost unrecognisable.
    Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined by Richard Cassidy, Field CISO at Rubrik, and Bec McKeown, a chartered psychologist specialising in human performance under pressure.
    Social engineering isn't a technology problem, it's a human one that cybersecurity has inherited. The psychology behind it hasn't changed since Cleopatra was using it to outmanoeuvre empires, but AI has transformed the speed, scale and sophistication of every stage, from automated reconnaissance that builds a complete profile in 30 minutes to real-time voice cloning that references your actual projects and travel schedule.
    Bec and Richard bring two very different perspectives to the same problem. Bec explains how attackers engineer the conditions in which people make decisions rather than just crafting a convincing message, and why "people are the weakest link" misses the point. Richard shares what he's seeing as a practising CISO, from family members being targeted through gaming platforms to why measuring phishing click rates gives organisations a dangerous false sense of security.
    Three key talking points:
    They're not hacking people, they're shaping decisions: Social engineering works because attackers engineer the conditions under which decisions get made, not because people are careless. Bec explains why most security awareness training is solving the wrong problem by focusing on the message rather than the environment in which people are operating.
    AI has turned social engineering into an automated pipeline: What used to take weeks of manual reconnaissance now takes 30 minutes. AI-powered OSINT can build a complete profile of a target and generate a tailored attack that references their projects, travel and communication style. Combined with real-time voice cloning, these layered attacks are becoming almost impossible to distinguish from a legitimate request.
    Your family is now part of the attack surface: If the executive is too well protected, attackers go to the people around them. Children on gaming platforms are being cultivated to unknowingly share information about their parents' work and routines, and a compromised family device on a shared home network becomes a route into the corporate environment.

    The psychology behind social engineering hasn't changed in thousands of years, but the tools to exploit it have. If your defences are still built around phishing simulations and click rate metrics, this episode will make you rethink.

    On why social engineering isn't about fooling people:
    "They're not hacking people, they're shaping the conditions in which people make decisions."
    Bec McKeown
    Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
    In this episode, we covered the following topics:
    The History of Social Engineering From Cleopatra to Cold War intelligence operations, social engineering has worked for as long as humans have communicated. We discuss why the psychology behind it hasn't moved an inch.
    Influence vs Manipulation Bec explains the difference between making someone do something they don't want to do and making them want to do it, and why that distinction matters for how we build defences.
    AI-Powered Reconnaissance Find out how AI has turned open source intelligence into a fully automated pipeline that can build tailored attack scenarios from public data in under 30 minutes.
    Deepfake Voice and Video Attacks We get into why real-time voice cloning combined with genuine project data and manufactured urgency makes modern social engineering attacks almost impossible to spot.
    Layered Context Attacks Discover why the most dangerous attacks don't rely on a single trick but layer urgency, authority, familiarity and isolation together until there's no reason to doubt what you're seeing.
    Family as an Attack Surface Children on gaming platforms are being cultivated to share information about their parents' work and routines. We discuss why the family network is now a recognised route into executive environments.
    Gut Feeling and When to Trust It Bec and Richard explain why intuition is often the first signal that something is wrong and why corporate culture has trained people to ignore it.
    Confirmation Bias in Action A group of colleagues all received the same phishing email, checked with each other and decided it must be legitimate because they'd all got it. We discuss why that instinct is exactly what attackers rely on.
    Why Security Awareness Training Measures the Wrong Thing Phishing click rates going down doesn't mean your organisation is safer. We discuss why this metric wouldn't have prevented any of the major social engineering incidents of the last few years.

    Resources Mentioned
    Bec McKeown
    Mind Science Ltd
    Richard Cassidy
    The Psychology of the Machines
    Rubrik
    Cialdini's Six Principles of Influence
    Gary Klein / Recognition-Primed Decision Making
    Trend Micro AI-powered OSINT research
    Deepfake fraud - regulatory warning
    Connect with your host James Rees
    Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
    Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
    With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
    For more information about us or if you have any questions you would like us to discuss email podcast@razorthorn.com.
    If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
    LinkedIn: Razorthorn Security
    YouTube: Razorthorn Security
    TikTok: Razorwire Podcast
    Instagram: Razorwire Podcast
    Twitter: @RazorThornLTD
    Website: www.razorthorn.com
    All rights reserved. © Razorthorn Security LTD 2025
  • Razorwire Cyber Security & InfoSec Insights

    Who Gets to Control AI? The Governance Crisis Nobody's Solving

    2026/07/15 | 50 mins.
    The EU just pushed back its AI Act enforcement by 16 months. The US is deregulating. China is governing through infrastructure. And the UK is doing nothing and hoping for the best.
    Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined by Richard Cassidy, Field CISO at Rubrik, and Jonathan Care, Head of the AI Practice at KuppingerCole.
    We're not in an AI revolution. We're in an AI accountability crisis with the most incredible marketing budget the technology industry has ever seen. That's how Richard Cassidy frames it, and it sets the tone for a conversation that goes well beyond the usual AI hype into the governance, sovereignty and regulation questions that nobody has convincingly answered.
    The US, EU, China and the UK have each taken fundamentally different approaches to AI governance and they're diverging, not converging. Meanwhile, the companies building the most powerful models are increasingly the ones defining how they should be used, because governments simply can't keep pace. The conversation also gets into why AI's ability to solve complex mathematical problems is starting to worry the people responsible for the cryptography that underpins modern banking, payments and secure communications.
    Three key talking points:
    Four governance models, zero compatibility
    The US over-innovates, the EU over-regulates, China governs through infrastructure and the UK has principles without law. None of these models is compatible with the others, and the largest organisations in the world operate at the intersection of all of them.
    When companies define the rules because governments can't
    Anthropic publicly refused to provide certain capabilities over concerns about surveillance and military use. That exposed the governance vacuum that exists when legislation can't keep pace with innovation. The companies building the most powerful models are now the ones deciding how they should be used.
    Cryptography is on borrowed time
    AI is solving mathematical problems that have never been solved before. The cryptography that underpins banking, payments and the digital economy is based on the assumption that certain problems are too hard to solve. If AI and quantum computing change that assumption, those foundations look fragile.

    This isn't about what AI can do. It's about who gets to decide what it should do.

    On what's really driving the AI narrative:
    "We're not in an AI revolution, we're in an AI accountability crisis that appears to have the most incredible marketing budgets we've ever seen in the history of investment in companies."
    Richard Cassidy
    Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
    In this episode, we covered the following topics:
    The EU AI Act and Why It's Already Behind
    The deadline got pushed back 16 months. We discuss what that tells us about the gap between regulatory intent and enforcement.
    US Deregulation and Innovation at Speed
    The US is betting that innovation matters more than regulation. We get into what that means for everyone else.
    China's Infrastructure-First Approach
    China isn't writing big laws. It's governing through 50-plus technical standards and sector-specific measures. We discuss why that model is fundamentally different.
    The UK's Principles Without Law
    Five non-statutory principles, enforcement delegated to existing regulators. We explore why that creates the lowest compliance burden but the highest uncertainty.
    AI Sovereignty
    Everyone says they want it. Almost nobody can explain what it means. We get into why the conversation matters.
    When the Model Builders Make the Rules
    Anthropic drew a public line on what it would and wouldn't provide. We discuss what happens when companies, not governments, define how AI is used.
    AI and the Threat to Cryptography
    AI is solving problems that have never been solved before. Find out why that has implications for the mathematics that underpins modern encryption.
    Post-Quantum Cryptography
    Discover why the convergence of AI and quantum computing could undermine the foundations the entire digital economy is built on.
    The AI Jobs Debate
    Industries predicted to be at high risk haven't seen the job losses forecast. We discuss why the "AI will take all the jobs" argument is too blunt.
    Europe's Innovation Problem
    Investment in Europe is so hard to get that you need a working company before anyone will fund you. We discuss what that means for competitiveness.

    Resources Mentioned
    EU AI Act
    Anthropic
    Fable (guardrailed Mythos)
    KuppingerCole
    Rubrik
    BSA
    NIST post-quantum cryptography
    DeepMind AlphaGeometry
    World Economic Forum
    Oliver Rochford

    Connect with your host James Rees
    Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
    Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
    With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
    For more information about us or if you have any questions you would like us to discuss email podcast@razorthorn.com.
    If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
    LinkedIn: Razorthorn Security
    YouTube: Razorthorn Security
    TikTok: Razorwire Podcast
    Instagram: Razorwire Podcast
    Twitter: @RazorThornLTD
    Website: www.razorthorn.com
    All rights reserved. © Razorthorn Security LTD 2025
  • Razorwire Cyber Security & InfoSec Insights

    From ISDN to AI - Two Veterans on How Defence in Depth Has Changed

    2026/07/01 | 51 mins.
    Defence in depth has evolved every time the technology landscape has shifted. The internet, virtualisation, cloud, SaaS. AI is the next shift, and the old model isn't keeping up.
    Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined once again by Martin Voelk, co-founder of SpartanX and an ethical hacker with nearly 26 years in cybersecurity.
    Every major technology shift has forced security teams to rethink how they protect their organisations. The internet moved data outside the building. Virtualisation and cloud meant infrastructure was no longer yours to control. Each time, defence in depth had to evolve. AI is the latest shift, and it may be the one that breaks the model entirely.
    We trace the journey from on-prem data centres and ISDN routers through to a world where AI agents act autonomously, supply chains are built on unverified code and the offensive side of AI is outpacing the defensive side at a rate security teams can't match. They get into why every AI agent needs its own identity, why shadow AI is a problem most organisations haven't begun to address and why the only realistic answer to AI-powered attacks is AI-powered defence.
    Three key talking points:
    Defence in depth has always evolved, but this time it's different:
    Every previous technology shift gave security teams time to catch up. AI isn't offering that. The pace of change is faster than most organisations can respond to, and the defensive tooling hasn't kept pace with what the offensive side can already do.
    AI agents need to be treated like people:
    Every AI agent needs its own identity, authentication and authorisation policies. Without that, a compromised agent can act under a human user's name with no way to tell the difference. The legal and forensic implications are enormous and largely unsolved.
    The offensive side is winning:
    AI is finding vulnerabilities faster than teams can fix them. Alert volumes are overwhelming SOCs, attackers are using AI-generated noise to mask real attacks and human in the loop is becoming unworkable at scale. The only realistic counter is defensive AI, but it isn't mature yet.
    Defence in depth has survived every technology shift so far. AI is testing it in ways we haven't seen before. If you're responsible for securing an organisation that's adopting AI, this is the conversation to listen to.
    On why security teams are always one step behind:
    "We don't have the ability to figure out what's going on until it's already happened. We don't have that technology yet."
    James Rees
    Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
    In this episode, we covered the following topics:
    The Evolution of Defence in Depth
    From ISDN and on-prem data centres to cloud and SaaS, we trace how defence in depth has evolved with every major technology shift.
    Why AI Is Different
    Previous shifts gave security teams time to adapt. We discuss why AI isn't offering that luxury.
    Supply Chain Risk and Unverified Code
    Open source code from GitHub, AI skills downloaded from the web, integrations nobody has reviewed. Discover why the modern supply chain is built on foundations most organisations haven't verified.
    Third Party Risk Management Is Broken
    AI fills in vendor questionnaires and AI reviews the answers. We get into why the current TPRM process is fundamentally flawed.
    Shadow AI
    Learn why unapproved AI usage is one of the hardest risks to detect and why most organisations have no way of monitoring it.
    Continuous Authentication
    Single sign-on isn't enough anymore. We discuss why continuous authentication is becoming essential in environments where AI agents operate alongside human users.
    AI Agent Identity and Accountability
    Find out why every AI agent needs its own identity and access controls, and what happens when a compromised agent acts under a human user's name.
    Alert Fatigue as an Attack Vector
    Flooding a SOC with noise to mask a real attack isn't new, but AI makes it possible at a scale that's almost impossible to manage.
    Prompt Injection via Log Files
    Find out how a prompt injection hidden in a standard HTTP header was used to trick a summarisation agent into exfiltrating data.
    The Case for Defensive AI
    Offensive AI is outpacing the defensive side. We discuss why AI-powered defence is the only realistic answer and why it isn't mature yet.

    Resources Mentioned
    SpartanX
    Martin Voelk - LinkedIn
    Kali Linux
    Docker
    Ollama
    Hugging Face
    DeepSeek
    CrowdStrike
    GitHub

    Connect with your host James Rees
    Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
    Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
    With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
    For more information about us or if you have any questions you would like us to discuss email podcast@razorthorn.com.
    If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
    LinkedIn: Razorthorn Security
    YouTube: Razorthorn Security
    TikTok: Razorwire Podcast
    Instagram: Razorwire Podcast
    Twitter: @RazorThornLTD
    Website: www.razorthorn.com
    All rights reserved. © Razorthorn Security LTD 2025
  • Razorwire Cyber Security & InfoSec Insights

    Daybreak and the Battle for AI Security: The Arms Race Accelerates

    2026/06/17 | 50 mins.
    AI used to be something security vendors built into their own products. Now OpenAI is going direct, positioning itself as the layer that security runs on. What does that mean for the rest of the industry?
    Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined again by Jon Care, Head of the AI Practice at KuppingerCole, to unpack OpenAI's launch of Daybreak.
    OpenAI launched Daybreak on 11 May 2026. It's not a security product, it's a platform play designed to embed AI-driven security directly into the development lifecycle, with a three-tier access model and a partner programme that includes Cisco, CrowdStrike, Palo Alto and a dozen other major vendors. This is OpenAI's bid to become the infrastructure that security runs on.
    But the governance questions are enormous. Who counts as a "verified defender"? Who decides? What happens when someone with access changes jobs or gets laid off? And when the same model families sit on both sides of the equation, how do you govern dual use? Jim and Jonathan argue the industry urgently needs an independent regulatory body to oversee access to these capabilities. The conversation also gets into China's response to Western chip restrictions and why the idea that any one country can control AI capability is already looking outdated.

    Three key talking points:
    Daybreak isn't a product, it's a platform land grab: OpenAI isn't selling to security vendors the way AI has traditionally been integrated into the market. It's going direct to CISOs and development teams, bypassing the existing vendor layer entirely. This episode gets into what that means for the security market and why the major vendor partnerships may not be enough to mask the disruption.
    The governance gap nobody has answered: Daybreak gates access based on "verified defender" status, but there's no public specification of what that means, no independent auditing and no appeals process. This episode raises the uncomfortable questions about who qualifies, what happens when access follows a person rather than an organisation and what model could end up benefitting the industry the most.
    You can't contain capability: China's response to Western chip restrictions has been to develop its own hardware at pace, certifying nine domestically designed AI processors for state procurement. The assumption that any single country can control access to frontier AI capability is already looking outdated and that has serious implications for everything from dual use governance to the future of the AI arms race.

    Daybreak launched on the same day Google confirmed the first AI-built zero day. If you care about where the security market is heading, this is the conversation to listen to.

    On who controls access to AI security capability:
    “OpenAI sets the criteria, OpenAI approves or denies and OpenAI monitors usage. For those of you who noticed, I said OpenAI three times in that past sentence. That was deliberate.”
    Jon Care
    Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
    In this episode, we covered the following topics:
    What Daybreak Actually Is Find out what OpenAI's Daybreak initiative involves and why it's being positioned as infrastructure rather than a product.
    A Platform Land Grab Explore why Daybreak is OpenAI's bid to own the security developer toolchain and what that means for the existing vendor ecosystem.
    Partner Asymmetry Major vendors get early and deeper access. We discuss what that means for everyone else.
    Who Counts as a "Verified Defender"? There's no public specification, no independent auditing and no appeals process. We get into why that's a problem.
    Dual Use Governance The same models are being used for offence and defence. Discover why that raises questions nobody has answered yet.
    Credential Portability What happens when someone with access to the most permissive tier gets laid off or changes jobs?
    The Case for Independent Regulation We discuss why the industry needs an equivalent of PCI DSS for AI security access, independent of any single government or vendor.
    AI vs AI Daybreak launched the same day Google confirmed the first AI-built zero day. We discuss what that signals about where the arms race is heading.
    China's Hardware Response Huawei unveiled Logic Folding and China certified nine domestically designed AI processors. The assumption that any country can gate AI capability is already outdated.
    Human in the Loop Is Dying The speed of AI development is outpacing human decision-making. We discuss why this concept may already be obsolete.

    Resources Mentioned
    OpenAI Daybreak
    Anthropic Mythos / Project Glasswing
    Microsoft MDASH
    CyberGym benchmark
    Google first AI-built zero day
    Huawei LogicFolding / Tau Scaling Law
    PCI DSS / PCI Security Standards Council
    KuppingerCole
    Bank of Dave (film)
    Snyk
    Socket
    Endor Labs
    GitHub Advanced Security

    Connect with your host James Rees
    Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
    Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
    With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
    For more information about us or if you have any questions you would like us to discuss email podcast@razorthorn.com.
    If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
    LinkedIn: Razorthorn Security
    YouTube: Razorthorn Security
    TikTok: Razorwire Podcast
    Instagram: Razorwire Podcast
    Twitter: @RazorThornLTD
    Website: www.razorthorn.com
    All rights reserved. © Razorthorn Security LTD 2025
  • Razorwire Cyber Security & InfoSec Insights

    Third Party Risk in the Age of AI. A Spotlight on Black Kite

    2026/06/03 | 50 mins.
    Your vendors are adopting AI faster than you can assess them. What does that mean for your third party risk?
    Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this Spotlight on Technology episode, I'm joined by Jeffrey Wheatman, Senior Vice President and Cyber Risk Strategist at Black Kite. Jeffrey previously spent over a decade as an analyst VP at Gartner where he launched their third party cyber risk management coverage.
    Third party risk management used to be fairly straightforward. If finance was happy and legal had done their redlining, you signed the contract and moved on. That world is gone. Organisations are now dependent on layers of vendors, suppliers and service providers, and the chain goes deeper than most security teams can see. When a logistics company can go from operational to out of business in five months after a ransomware attack, and one incident at Jaguar Land Rover can measurably affect UK GDP, the question isn't whether third party risk matters. It's whether your programme can keep up.
    This episode covers how the old model of spreadsheets and questionnaires is giving way to intelligence-led continuous monitoring, why AI has made the problem exponentially harder and how Black Kite is helping organisations cut through the complexity, from mapping supply chain connectivity and scoring ransomware susceptibility to cutting a 500-question vendor questionnaire down to 30.

    Three key talking points:
    You can't protect what you can't see: Most organisations know who their biggest vendors are. Beyond that, it gets murky fast. This episode gets into why even mature organisations still struggle to see past the first or second layer of their supply chain, why figuring out which vendors actually matter is harder than it sounds and why Jeffrey always tells people to solve their third party problem before worrying about their fourth.
    AI just made your third party programme ten times harder: Your vendors are already using AI, whether they've told you or not. The person you're speaking to may not even know, because it could be embedded two or three layers down. Meanwhile the market is flooded with AI solution claims and attackers are using it to move faster than ever. This episode covers the three ways AI is complicating third party risk and why most organisations haven't even begun to get their AI governance right.
    From questionnaires to continuous intelligence: The old model of sending out hundreds of questions, hoping for honest answers and filing the results is finished. This episode covers how the industry is moving from periodic assessment to continuous monitoring, why real data beats self-reported questionnaires and how platforms like Black Kite are helping organisations focus on the vendors that actually pose a risk.

    If your third party risk programme is still running on spreadsheets and annual reviews, this episode will make you uncomfortable. And it should.

    On why most organisations don't know which vendors matter most:
    “I always badly paraphrase Animal Farm by George Orwell. All your vendors are equal, but some vendors are more equal than others. And most people don't really know how to figure that out.”
    Jeffrey Wheatman
    Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
    In this episode, we covered the following topics:
    When a Vendor Goes Down, You Go Down With Them We discuss why the conversation has shifted from data protection to operational resilience.
    The Nth Party Problem Most organisations can't see past the first or second layer of their supply chain. The web of interconnected vendors is far more complex than it looks – we talk about where to start if you haven't solved your third party basics yet.
    Concentration Risk and Single Points of Failure Heavy reliance on a handful of major cloud providers creates risks that can't easily be mitigated. We explore what you can realistically do about it.
    Three Ways AI Is Complicating Third Party Risk Discover why AI isn't just changing the threat landscape for your own organisation but fundamentally altering how you need to think about every vendor in your supply chain.
    Shadow AI in Your Supply Chain Learn why shadow AI in your vendor ecosystem is a growing risk when most organisations' AI governance isn't anywhere near ready to deal with it.
    The AI Vendor Bubble Find out why many AI companies are currently selling their services at a loss, and what this means for organisations that have built critical processes around vendors that might not survive when the economics catch up.
    Moving Beyond Spreadsheets and Questionnaires Find out why self-reported questionnaires and periodic assessments can't keep up anymore, and what's replacing them.
    How Black Kite Approaches Third Party Risk Explore what an intelligence-led approach to third party risk actually looks like in practice and why it's a fundamentally different model to what most organisations are used to.
    The Ownership Problem No two organisations agree on who owns third party risk. Find out why this inconsistency creates serious governance gaps and why it matters more than ever as the scope of the problem grows.
    Resources Mentioned
    Black Kite
    Jeffrey Wheatman on LinkedIn
    Black Kite's Third Party Risk podcast
    K&P Logistics / Knights of the Old (ransomware case study)
    Jaguar Land Rover (supply chain breach impact)
    DORA (EU banking regulation)
    MITRE ATT&CK
    OpenFair (cyber risk quantification)
    GA3 framework (Black Kite's AI governance add-on)
    Threat Tracev (Black Kite's NetFlow-based offering)
    RSA Conference
    Project Glasswing / Mythos (Anthropic)
    OpenAI Daybreak
    All rights reserved. © Razorthorn Security LTD 2025
More Business podcasts
About Razorwire Cyber Security & InfoSec Insights
Cybersecurity is evolving — and so should you. Razorwire brings the open conversations that give you the edge. Welcome to the Razorwire podcast — your resource for practical advice, expert insights, and real-world conversations on cybersecurity, information security (InfoSec), risk management, governance, security leadership, human factors, and industry trends. Our mission is to help you build a stronger cybersecurity career while supporting a dynamic, agile community of professionals committed to continuous improvement. Each episode brings you actionable advice and real experiences from your host, James Rees — an information security specialist with over 25 years of experience — and from a range of respected guests across the cybersecurity industry. Together, we explore everything from technical strategies and compliance challenges to security culture, communication skills, and leadership development. James Rees is the founder of Razorthorn Security, providing expert consultancy and testing services to a wide range of organisations, including many Fortune 500 companies. His practical, no-nonsense approach helps organisations manage cybersecurity risks effectively while strengthening resilience. The Razorwire podcast is designed for cybersecurity professionals who want to stay ahead, sharpen their skills, and confidently respond to the challenges of today's evolving threat landscape. We believe collaboration is key to stronger security — and Razorwire gives you the conversations that help you achieve it. For more information about us, or if you have questions you'd like discussed on the show, email podcast@razorthorn.com or visit www.razorthorn.com.
Podcast website

Listen to Razorwire Cyber Security & InfoSec Insights, The Money Show and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features