Peter Jones
Peter Jones is a Cyber Security and Digital Forensics professional working as a CISO with a
career covering auditing, digital forensic investigations and incident response. Peter has coauthored a number of CREST-accredited courses and co-founded the South West Cyber
Security Cluster.
Session
Cyber security has never been more popular—or more exhausting. After COVID, everyone wanted in. Fast forward a few years, and many of those same professionals are burned out, disillusioned, and quietly wondering what they actually signed up for.
This talk skips the polished narratives and gets into the reality of operating security inside a business. Not theory—practice. The kind where priorities shift mid-incident, “critical” risks compete with revenue, and security teams are expected to translate technical issues into decisions that executives can act on in minutes, not months.
We’ll air some of cyber’s dirty laundry: how the function is really perceived by management, why it’s still too often seen as a cost centre or a blocker, and how decades of fear-driven messaging have eroded trust rather than built it. Drawing on real-world experience, we’ll look at what happens when security has to justify itself in operational terms—during incidents, in boardrooms, and in the quiet trade-offs no framework really covers.
More importantly, we’ll challenge the language of cybersecurity. What happens when you remove the FUD and speak in terms the business actually values? What does security look like when it’s treated as an operational capability—something that enables decisions, manages uncertainty, and supports resilience—rather than a compliance exercise?
Expect candid observations, a few uncomfortable truths, and a perspective shaped by running security where it has to work, not just look good on paper.