Managing The Minefield of Management Cyber Explosions - Understanding what to say and when to say it
Cyber security has never been more popular—or more exhausting. After COVID, everyone wanted in. Fast forward a few years, and many of those same professionals are burned out, disillusioned, and quietly wondering what they actually signed up for.
This talk skips the polished narratives and gets into the reality of operating security inside a business. Not theory—practice. The kind where priorities shift mid-incident, “critical” risks compete with revenue, and security teams are expected to translate technical issues into decisions that executives can act on in minutes, not months.
We’ll air some of cyber’s dirty laundry: how the function is really perceived by management, why it’s still too often seen as a cost centre or a blocker, and how decades of fear-driven messaging have eroded trust rather than built it. Drawing on real-world experience, we’ll look at what happens when security has to justify itself in operational terms—during incidents, in boardrooms, and in the quiet trade-offs no framework really covers.
More importantly, we’ll challenge the language of cybersecurity. What happens when you remove the FUD and speak in terms the business actually values? What does security look like when it’s treated as an operational capability—something that enables decisions, manages uncertainty, and supports resilience—rather than a compliance exercise?
Expect candid observations, a few uncomfortable truths, and a perspective shaped by running security where it has to work, not just look good on paper.
We’ve all seen it: red dashboards, “critical” alerts, and slide decks that lean heavily on worst-case scenarios. Yet guidance like the NCSC’s Cyber Security Toolkit for Boards and principles from the Cyber Leadership Institute are clear—cyber isn’t about fear, it’s about informed decision-making, risk ownership, and organisational resilience.
So why does the day-to-day reality feel so different?
This talk takes a step away from the polished frameworks and looks at what actually happens when you try to apply them in the real world. When a board is told they own cyber risk, what does that look like in practice? When leadership is encouraged to ask better questions, are we giving them answers they can actually use? And when we say “cyber is a business enabler,” can we prove it under pressure?
Drawing on real operational experience, we’ll explore the gap between guidance and reality:
- What happens when risk appetite meets a live incident
- Why “just patch it” isn’t always a meaningful answer
- How security teams end up translating between technical truth and business priorities
- And where FUD quietly sneaks back in, even when we think we’ve moved past it
We’ll also flip the script. Using ideas grounded in NCSC guidance and cyber leadership principles, we’ll look at how to:
- Communicate risk without defaulting to fear
- Frame security in terms of operational impact and decision-making
- Help leadership engage with cyber as something they can own—not outsource to “the experts”
- And make security a function that supports the business, rather than slows it down
Expect honest stories, familiar frustrations, and practical ways to rethink how we position cybersecurity—especially when it matters most.
No silver bullets. No scare tactics. Just a clearer way to make cyber make sense.
Peter Jones is a Cyber Security and Digital Forensics professional working as a CISO with a
career covering auditing, digital forensic investigations and incident response. Peter has coauthored a number of CREST-accredited courses and co-founded the South West Cyber
Security Cluster.