
In this interaction, he offers valuable perspectives on strengthening cyber resilience through practical, scalable, and standards-driven approaches.
Cybersecurity is often seen as a technical issue rather than a leadership priority. How do you view this perspective?
Many businesses still see the cyber challenge as a technical one. Yet the majority of cyber incidents feature the behaviour of people and leadership front and centre – whether that’s the role of the human in facilitating a successful attack through susceptibility to social engineering, or the role of people in leading during times of crisis. The reality, in my view is that addressing cyber risk is at least 60% about leadership and people.
Having worked closely with business leaders, what do you think differentiates organisations that excel at cyber governance from those that remain reactive?
The most successful organizations in cyber governance understand that cyber security is a business risk similar to any other headline risk. They take it seriously and set the right tone from the top. They engage in cyber exercises and examine cyber from the perspective of business strategy. Such entities establish expectations regarding how they wish to receive cyber risk reports that highlight the business at the center (rather than technical reports focused on the status of vulnerability management or security awareness training statistics). Consequently, they demand that cyber security strategies and policies reflect the culture of the organization and provide employees with clarity.
In addition, they foster a tone in the organization that balances the need for strong cyber security (at all levels) with the need to be flexible in the pursuit of strategic objectives.
Organizations often implement security controls that exceed with their real risk. How does CRMG guide them to focus on the most critical protections?
At CRMG, we achieve this by focusing on systems and business capabilities that deliver value to the organization. We assist organizations in determining what is critical based on the potential impact, consistent with the Board’s guidance. We discuss the need for strong baseline protection across the board, complemented by a more nuanced approach for critical systems. To support this, we provide risk scenarios that accurately reflect the organization’s activities, engaging the business as much as possible in the process.
Throughout this process, it is recognized (in emerging standards / regulations) that a risk-based approach that is centered on the most critical aspects of operations is non-negotiable. The idea of attempting to boil the ocean is not feasible!
With cyber threats evolving rapidly, how do you ensure that risk assessments and protections remain relevant and actionable?
It is not possible for us to address every cyber threat. There will always be zero-day events. It is therefore important to focus on the organization’s ability to respond, recover, and continue with ‘business as usual’ as much as possible during a cyber incident.
Moreover, we ensure that the risk assessment process is as current as possible in terms of threat trends. This is about a mix of strong threat intelligence, solid knowledge of the organisation’s systems and network architecture (including potential routes in), and an approach that considers overlooked elements. These include factors we often fail to recognize enough — such as the role of sheer accident in cyber incidents.
How can nations and businesses share threat intelligence without compromising privacy, trust, or competitiveness?
A wide variety of institutions, including not-for-profit organizations, commercial enterprises, and government agencies facilitate the exchange of intelligence and experiences.
As a matter of course, we need to establish trust thresholds (in the sense of how much information we are willing to share? ), but ultimately, I prefer to be as collaborative as possible. As a whole, the cyber industry performs exceptionally well in this area. Recent regulations have also contributed to some degree, as some organizations are now required to share the outputs of their risk assessment processes, identify critical suppliers, and so on. In general, we just need to improve our ability to ‘join up the dots’ in order to achieve stronger, ecosystem-wide protection.
In the next 3–5 years, what shifts do you foresee in how organizations approach cyber risk management?
The continued maturing of quantitative techniques to improve the effectiveness of cyber risk management as a discipline. But be careful. Risk quantification is good at expressing risk where hard dollars are at stake, but less good where risk outcomes are more nuanced – for example in hybrid IT/OT environments, or where non-financial impacts are of more concern than financial impact. And be careful of the term ‘accuracy’ in the context of risk management. Risk is ultimately still risk and inherently involves the unknown.
Artificial intelligence will be increasingly incorporated into risk management processes in order to increase their efficiency and effectiveness. It has already begun to do so. At present, artificial intelligence is not very effective at analyzing risk inputs and drawing contextualized conclusions about possible risk outcomes. There is no doubt that this will change in time.
What key message would you like to convey to the cybersecurity community from the Black Hat platform?
I never underestimate the role of people in effective cyber risk management, and always ensure a strong linkage between risk management and overall strategy. Use methods that translate detailed — often technical — risk information into clear, actionable insights for top management, and communicate your message accordingly; when you get that right, everything else will follow.
This interaction with Simon Rycroft highlights the importance of coupling deep technical understanding with strategic, risk-based decision-making. As a cybersecurity expert, he has shaped best practices across governance, risk management, information assurance, and benchmarking. His decades of experience and commitment to enabling organisations with actionable, effective cybersecurity practices underscore the evolving yet essential principles of strong governance and assurance. As the threat landscape continues to grow in complexity, experts like Simon play a crucial role in guiding organisations toward resilient and adaptive cyber strategies.
All Content Rights Reserved by The Catalyst.








