Skip to content
Artwork for The Cyber Security Matters Podcast

The Cyber Security Matters Podcast

The Cyber Security Matters Podcast

A series of interview with key leaders through the Cyber Security industry.

All brought to you by the Cyber Security team at neuco a specialist global recruitment and executive search firm.

Play
  • 21 episodes
  • weekly
  • Avg 38 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • September 3 · 32 min

    Why More Cybersecurity Tools Can Mean More Complexity | EP 79 | Aimée Roerink, Detectify

    In episode 79 of Cyber Security Matters, hosts Harry Baldwin and Matt Rose are joined by Aimée Roerink, Chief Marketing Officer at Detectify, for a wide-ranging discussion on cybersecurity, marketing, AI and the growing complexity facing modern security teams. Aimée offers a different perspective on the industry focused on customer value, clarity, commercial outcomes and the importance of translating complex technology into something people can actually understand and use. This fascinating conversation explores why businesses can end up with “scaling confusion” when they add more people, processes, channels and technology without first establishing clarity. Aimée discusses the dangers of buying cybersecurity tools because of fear of missing out, why AI should be treated as a means to solve a real problem rather than a reason to buy another platform, and what the rise of shadow AI can reveal about the environments employees are working in. Key Topics Covered • Clarity over complexity: Why Aimée says clarity matters more than skill, and how organisations can scale confusion without clear problems, priorities or value propositions. • Alignment beats local optimisation: How strong individual teams can still slow the wider business when they optimise towards different priorities, channels or value propositions. • Building teams that can thrive: The value of curiosity, drive, ownership, commercial judgement and low ego, plus a willingness to challenge without becoming territorial. • The changing role of marketing: Why marketing now reaches beyond lead generation into positioning, market selection, sales effectiveness, retention, pricing and revenue. • The human advantage in an AI world: Why judgement, customer insight, creativity, credibility and trust become more valuable as AI handles routine execution. • What Detectify does: How Detectify helps organisations understand their attack surface and find exploitable vulnerabilities through payload-based testing, security research, ethical hackers and AI. • Cybersecurity FOMO and tool sprawl: Why organisations buy fashionable tools without accounting for integrations, training, governance, maintenance and ownership. • Buy less, simplify more: Why a new security tool should replace, simplify or meaningfully improve something, not just add another layer. • Marketing AI without the hype: Why AI messaging should start with the customer problem, not the technology, and focus on what Alfred AI enables. • Shadow AI as a symptom: How unauthorised AI use can point to slow processes, unclear policies and inefficient workflows, not just poor employee behaviour. • Creating practical security cultures: Why secure behaviour should be built into everyday workflows so the safe option is also the clear and practical one. • Making it safe to admit mistakes: Why blame makes people hide errors, and why teams need a culture where issues can be reported quickly. • Advice for entering cybersecurity: Challenge what you see, understand what companies really do, and choose work that aligns with your values. About Aimée Roerink Aimée Roerink is the Chief Marketing Officer at Detectify, where she leads the company's marketing and commercial positioning. Aimée came into cybersecurity from a commercial leadership background rather than as a security practitioner. Across her career, she has focused on understanding complex markets, identifying where businesses can create customer value and building teams and commercial systems that turn strong products into sustainable growth. In the episode, she explains that what attracted her to cybersecurity was the combination of an urgent customer problem, sophisticated technology and an industry where trust is particularly important. Episode created by neuco neuco is a global specialist recruitment and executive search firm supporting companies across cyber security, satellite, space and defence, and media and sports technology with hiring and talent solutions.

  • July 31 · 32 min

    Incident Response at Scale: Building Better Investigators in the Age of AI | EP 78 | Lee Sult, Binalyze

    In episode 78 of Cyber Security Matters, hosts Matt Rose and Harry Baldwin are joined by Lee Sult, Chief Investigator at Binalyze, for a fascinating discussion on the realities of modern incident response and the evolving role of cybersecurity investigators. Drawing on a career that spans law enforcement, digital forensics, incident response, entrepreneurship and product development, Lee explains why understanding attackers is just as important as understanding technology, and why incident response must evolve as cyber threats become faster, more sophisticated and increasingly AI-assisted. The conversation explores Lee's journey from investigating cybercrime within law enforcement to leading investigations into some of the world's most complex cyber incidents, before diving into how Binalyze is helping democratize digital forensics for security teams worldwide. Along the way, Lee shares practical frameworks for incident response, explains why evidence collection remains one of cybersecurity's hardest problems, and offers candid advice for aspiring investigators looking to build successful careers in the industry. Key Topics Covered ● From law enforcement to cybersecurity: How Lee's early experience as a police dispatcher and digital forensic investigator shaped his perspective on incident response and crisis management. ● Thinking like an investigator: Why curiosity, authenticity and understanding attacker behaviour are the most valuable qualities for anyone pursuing a career in incident response. ● Democratizing digital forensics: How Binalyze is making enterprise-grade investigations accessible beyond elite incident response teams by simplifying evidence collection and forensic analysis. ● The four questions every investigation must answer: Lee's practical framework for determining whether attackers remain in an environment, identifying affected systems, understanding initial compromise and assessing data exposure. ● AI as a force multiplier for attackers: Why artificial intelligence isn't necessarily creating more sophisticated attacks, but dramatically lowering the barrier to entry for less experienced threat actors. ● Using AI responsibly in cyber defense: Where AI genuinely accelerates investigations, where human expertise remains essential, and why accountability can never be delegated to machines. ● Why organisations over-invest in prevention: How the industry's focus on detection and prevention has left many organisations underprepared for responding effectively when attacks inevitably succeed. ● Building high-performing security teams: The importance of diversity of thought, mentoring future leaders and creating environments where curiosity drives innovation. ● Breaking into cybersecurity in 2026: Lee's practical advice on building a home lab, showcasing technical ability and demonstrating genuine passion to stand out during the hiring process. About Lee Sult Lee Sult is the Chief Investigator at Binalyze, where he helps organisations improve their incident response capabilities through scalable digital forensics and investigative technology. His career began in law enforcement, where he worked in digital forensics before moving into incident response, ultimately spending more than a decade investigating some of the world's most complex cyber incidents. Along the way, Lee has held roles spanning consulting, product development and entrepreneurship, including serving as a founding Forward Deployed Security Engineer at Palantir and co-founding Huirangi. Today, his focus is on helping organisations investigate cyber incidents faster, empowering security teams with better forensic capabilities, and making advanced incident response accessible beyond specialist experts. This episode is brought to you by neuco.

  • July 27 · 46 min

    Why You Can't Ship Vulnerable Code Anymore | Ep 77 | Scott Gainey, Checkmarx

    In episode 77 of the Cyber SecurityMatters podcast, hosts Matt Rose and Harry Baldwin sit down with Scott Gainey, Chief Marketing Officer at Checkmarx, for a wide-ranging conversation on marketing transformation, leadership, and the seismic shift AI is forcing onapplication security. With nearly three decades leading marketing at companies like Cisco, Palo Alto Networks and SentinelOne, Scott brings a rare blend of go-to-market craft and deep security-category expertise and a clear-eyed viewof why AppSec has suddenly become one of the most urgent problems in cyber. Key topics covered: How Scott fell into security, marketing, and leadership, none of which he originally set out to do The leadership lessons that shaped him: Chris Young, West Point's Thayer program, and ROI rigour under private-equity ownership at KKR Why conference marketing is won before the event, not on the show floor The "go local" community trend emerging alongside the big conferences How the CMO role has changed: AI, frontier models, and a buying committee that's - 70% through its decision before sales is involved What separates great marketers: intellectual curiosity, self-drive, and field credibility The biggest shift in application security: AI's "two-front problem": more code and more vulnerabilities on one side, adversaries weaponising those same models on the other What Checkmarx does, and why deterministic and probabilistic (AI) scanning need to work together Career advice for anyone entering cybersecurity Guest bio: Scott Gainey is Chief Marketing Officer at Checkmarx, the application security company. He brings over twodecades of marketing leadership across Palo Alto Networks, SentinelOne, Cisco Security, NetApp and Nile, and has studied leadership at Stanford GSB and West Point's Thayer Leadership Development Group. Connect with Scott on LinkedIn About neuco: neuco is a Global Specialist Recruitment and Executive Search firm based in Brighton, UK. We help recruit for mid-seniorhard-to-fill roles in Cyber Security, Satellite, Space & Defence and Media & Sports Technology sectors. If hiring or talent is on the radar now or in the future, get in touch for an initial conversation today via hello@neuco-group.com.

  • July 15 · 36 min

    AI Hype vs Reality | Matthew Holland, Field Effect | EP 76

    In episode EP 76 of Cyber Security Matters, hosts Harry Baldwin and Matt Rose are joined by Matthew Holland, Founder and CEO of Field Effect, for a masterclass in building mission-driven cybersecurity companies. Matt takes us from his early days at Canada's Communications Security Establishment (CSE), where a summer job turned into a seven-year career in Tailored Access Operations, through co-founding and selling Linchpin Labs to L3 Harris, to his current mission: making enterprise-grade managed detection and response (MDR) accessible and affordable to small and medium-sized businesses. The conversation explores what it takes to compete against billion-dollar incumbents with a team of 165, why small high-performing teams consistently outperform bureaucratic giants, and the real story behind AI in cybersecurity - separating genuine innovation from marketing hype. Matt shares hard-won lessons on customer focus, the power of consistency across a 25-year career, and why solving "insanely hard problems" is both the challenge and the reward of entrepreneurship. Key Topics Covered: • From PhD plans to CSE: How a summer job at Canada's Communications Security Establishment changed Matt's career trajectory and introduced him to operating system internals and intelligence tradecraft • The Matrix generation: Early 2000s security research, breaking security boundaries, and building deep technical expertise before Google existed • The power of small teams: Why focus, mission-driven culture, and removing barriers consistently beat bureaucracy and layers of management • Building Linchpin Labs: Co-founding and scaling a privatised intelligence company, the "beer and pizza problem-solving method," and competing against Lockheed Martin and British Aerospace • Field Effect's mission: Making enterprise-grade MDR accessible and affordable to SMBs and mid-market organisations — "an insanely hard problem" • Competing with giants: Strategic lessons from going up against NSA, multi-billion dollar defence contractors, and today's trillion-dollar cybersecurity vendors About Matthew Holland: Matthew Holland is the Founder and CEO of Field Effect, a Canadian cybersecurity company headquartered in Ottawa that delivers managed detection and response (MDR) services to small and medium-sized businesses and mid-market organisations. Matt's career began at the Communications Security Establishment (CSE), Canada's national cryptologic agency, where he spent seven years in the Tailored Access Operations Group as a leading security researcher specialising in intelligence tradecraft and technology for top-secret Five Eyes projects. In 2007, Matt co-founded Linchpin Labs, growing it into a leader in the privatised intelligence industry before its acquisition by L3 Harris in 2018. Throughout his career, Matt has built a reputation for tackling complex technical challenges, competing successfully against much larger competitors, and building high-performing teams united by mission focus and work ethic. Today, Field Effect operates with approximately 165 employees, delivering enterprise-grade cybersecurity to underserved markets at scale. About neuco: neuco is a global specialist recruitment and executive search firm, helping organisations find senior and specialist talent across Satellite, Space & Defence; Media & Sports Technology; and Cyber Security. Find out more at www.neuco-group.com, or explore our Cyber Security sector.

  • July 9 · 33 min

    Rethinking Security Culture & Risk - Podcast EP 75 - Valentina Flores, Red Sentry

    Valentina Flores, Co-Founder and CEO of Red Sentry, joins hosts Harry Baldwin and Matt Rose for another fantastic edition of The Cyber Security Matters Podcast. Valentina shares her unconventional journey from cybercrime detective investigating human trafficking and child exploitation cases to building a penetration testing company focused on real-world attacker simulation and practical risk reduction. The conversation dives into why cybersecurity is fundamentally about people and psychology rather than just tools, the critical importance of diversity of thought and background in building effective security teams, and how organisations can move beyond checkbox compliance to proactive, human-centred security practices. Valentina emphasises starting simple, prioritising real risks, and fostering a culture where security is everyone’s responsibility. Key Topics Covered Valentina’s path from SVU detective to cybercrime investigations and the surprising normalcy of hacker motivations Why cybercrime is “just like every other crime” - victim psychology, criminal psychology, and real-world attacker behaviour Building Red Sentry: pivots, funding, and a non-sales-focused approach centred on teaching and simplification Diversity beyond gender/race: the value of neurodiversity, unique backgrounds (including carnival life and law enforcement), and curiosity-driven hiring Human-led penetration testing, tabletop exercises, and why third-party ethical hackers uncover what internal teams miss Security culture in practice: integrating security into every department, honest adoption of tools, and avoiding tool fatigue Advice for new cybersecurity professionals: avoid putting yourself in a box and learn every side of the business About Valentina Flores Valentina Flores is the Co-Founder and CEO of Red Sentry, a penetration testing and vulnerability management company that delivers human-led offensive security services to help organisations identify and remediate real risks before attackers exploit them. With a background as a cybercrime detective on a federal task force, she gained firsthand insight into how real-world attackers operate. Valentina is a regular speaker on hacker psychology, security culture, neurodiversity, and why organisations must prioritise understanding risk over simply buying more tools. She is also a TEDx speaker. This episode is brought to you by neuco.

  • June 29 · 36 min

    Prepare, Don't Just Prevent: How Adaptive Crisis Simulation Is Transforming Cyber Incident Response - Episode 74 - Marlow Bryant, Reflex Security

    Join hosts Harry Baldwin and Matt Rose in episode 74 of Cyber Security Matters as they sit down with Marlow Bryant, co-founder and CEO of Reflex Security. This engaging conversation explores the evolution from static tabletop exercises to dynamic, AI-powered crisis simulations that adapt in real-time to team decisions. Marlow brings a unique perspective to cybersecurity, having spent nearly a decade in venture capital as VP at Marsh Capital and Clear Sky Security Fund, where he invested in cybersecurity and AI companies including XL, Spy Cloud, Mitigate, Accurate, and Together AI. His diverse background includes an unexpected stint in stand-up comedy, providing valuable insights into reading audiences and adapting communication styles. Key Topics Covered: • The journey from venture capital to founding a cybersecurity startup • Building early-stage teams and adapting roles as companies grow • Why organizational response matters as much as technical prevention • The limitations of traditional tabletop exercises and simulation gaps • How AI is transforming incident response and crisis preparation • The future evolution of the tabletop exercise market • Career advice for cybersecurity industry newcomers About Marlow Bryant: Marlow Bryant is co-founder and CEO of Reflex Security, an adaptive crisis simulation platform that replaces static tabletop exercises with AI agent-driven simulations. Before founding Reflex, he spent nearly a decade in venture capital, investing in cybersecurity and AI companies. He brings a unique perspective to the industry, combining technical expertise with experience in comedy and audience engagement. This episode is brought to you by neuco.

  • June 23 · 30 min

    AI, Patch Management & Endpoint Security: Mike Walters on the Future of Cyber Security – Episode 73

    In this episode of Cyber Security Matters, brought to you by neuco, we speak with Mike Walters, President and Co-Founder of Action1. Mike explores why patch management remains one of the most critical, and often overlooked, areas of cyber security, how AI is transforming vulnerability management, and what organisations need to do to stay ahead of increasingly sophisticated threats. Mike reflects on the journey from co-founding Netwrix to launching Action1, sharing lessons on entrepreneurship, leadership, hiring, and building a founder-led business with long-term vision. The conversation also examines the future of autonomous patching and why endpoint security is becoming an even greater priority as AI accelerates both cyber attacks and defence. Key topics covered: How Mike’s first computer at the age of nine sparked a lifelong passion for technology and cyber security The entrepreneurial influence of the founders behind Veeam and the belief that building a global success story was possible Bootstrapping Netwrix through determination and execution without outside investment Why maintaining focus became the most valuable lesson carried into Action1 The advantages of remaining founder-led and making decisions with a long-term perspective Building high-performing teams by hiring for curiosity, adaptability, and passion over specific domain expertise Why endpoints remain one of the most vulnerable attack surfaces for organisations The importance of effective patch management and why it is often neglected despite its critical role in reducing cyber risk How customer demand established patching as Action1’s core use case The impact of AI-powered vulnerability discovery and attackers operating at machine speed The future of autonomous patch testing, with AI dramatically reducing deployment timelines Mike’s advice for cyber security professionals on continuous learning and adapting to an AI-driven landscape Guest Bio: Mike Walters is President and Co-Founder of Action1, an autonomous endpoint management platform trusted by thousands of organisations managing millions of endpoints worldwide. A serial cyber security entrepreneur, he previously co-founded Netwrix, helping grow the business into a global leader before its acquisition by TA Associates. At Action1, Mike leads product strategy and go-to-market initiatives while championing innovation through founder-led leadership. Connect with Mike on LinkedIn: linkedin.com/in/cyberwalters About neuco: neuco is a global executive search and recruitment partner specialising in Cyber Security, Media & Sports Technology, and Satellite, Space & Defence. By combining deep sector expertise with an extensive international network, neuco helps organisations secure exceptional leadership and technical talent while providing market insights through industry-focused content, events, and the Cyber Security Matters podcast.

  • June 10 · 37 min

    AI Agent Authentication & the Future of Identity Security – Ep. 72 – Brian Bell, FusionAuth

    In this episode of Cyber Security Matters, brought to you by neuco, hosts Harry Baldwin and Matt Rose sit down with Brian Bell, CEO of FusionAuth, to explore why customer identity has evolved from a back-office IT function into mission-critical infrastructure, and what the rise of AI agents means for the future of authentication and access management. Key Topics Covered How Brian's career across Japan, BCG, and consumer products shaped his approach to leadership and customer-centricity Why identity sits at the unique intersection of security, user experience, and revenue growth The evolution of CIAM from back-office IT utility to critical digital infrastructure Lessons from leading Split Software through its acquisition by Harness - balancing customers, employees, and investors What Brian looks for when hiring at growth-stage companies: the "say, do, say" framework and the Japanese concept of Shoshin (beginner's mind) How the talent landscape has shifted toward mission, culture, and leadership quality over compensation What drew Brian to FusionAuth: real business problem, massive market, developer-first architecture, and strong unit economics FusionAuth's European expansion and traction in regulated industries including US government agencies The next frontier: non-human identity, AI agent authentication, and why CIAM is the critical infrastructure layer for agentic AI Why businesses should own and control their identity infrastructure rather than being locked into multi-tenant SaaS platforms About Brian Bell Brian Bell is CEO of FusionAuth, the developer-first Customer Identity and Access Management (CIAM) platform and the only enterprise-grade hybrid deployment solution in the market. With over 20 years of experience scaling enterprise software companies through IPOs, PE deals, and strategic acquisitions, Brian previously led Split Software through its acquisition by Harness, and served as CMO at Ping Identity and Zuora. Connect with Brian on LinkedIn. About neuco This podcast is brought to you by neuco, the specialist recruitment and executive search firm for the cyber security industry. With deep sector expertise and a global network spanning 60+ countries, neuco connects the world's leading cyber security businesses with the talent they need to grow — from specialist hires to C-suite leaders. Whether you're scaling a security product company or building out a new market, neuco's dedicated cyber security recruitment team understands your world. Explore neuco's cyber security recruitment services.

  • June 3 · 38 min

    Fix It, Don't Just Find It: How AI Is Finally Solving Vulnerability Management – Episode 71 – Dominik Richter, Mondoo

    In Episode 71 of Cyber Security Matters, hosts HarryBaldwin and Matt Rose sit down with Dominik Richter, Co-Founder and CPO of Mondoo, the agentic vulnerability management platform that doesn't just findsecurity flaws, it actually fixes them. Dom's journey into cybersecurity started with the 1995 film Hackers (and yes, Angelina Jolie may have played a part), which sent him down a path of learning to break into computers, reading Phrack magazine, and exploring bulletin boards. From there, he built a career spanning Deutsche Telekom, Chef Software, and Google before founding Mondoo. About the Guest Dominik Richter is a founder, coder, and hacker who hashelped shape the DevOps and security space through projects like Chef InSpec and dev-sec.io. He co-founded VulcanoSec (acquired by Chef Software in 2015),headed security for Deutsche Telekom's first OpenStack Cloud, and worked at Google Cloud before co-founding Mondoo in 2021. At Mondoo, he leads product asCPO, building an AI-native platform that helps organisations prioritise and remediate vulnerabilities across cloud, on-prem, SaaS, endpoints, and the SDLC. Key Topics Covered ● How the 1995 film Hackers sparked Dom'scybersecurity career ● Lessons from building at Deutsche Telekom, ChefSoftware, and Google and the moments that inspired him to go the startup route(twice) ● The qualities Dom looks for when hiring in startups: noego, comfort with ambiguity, willingness to be wrong and learn ● How the hiring process has evolved at Mondoo especiallyfor engineers in the AI era, where interviews now include coding with andwithout AI agents ● The biggest learning curve: hiring salespeople ● The origin of the Mondoo name (German for"moon" tied to their extensible security graph concept) ● How AI is accelerating both attack and defence morecode, more vulnerabilities, more automation on both sides ● Where AI falls short: companies rushing to adoptwithout considering security, particularly around AI agent skills and supplychain risks ● Why coding skills changed "overnight" but theneed for people who understand customer problems is greater than ever ● What Mondoo does: agentic vulnerability managementfocused on prioritisation and remediation, not just scanning and reporting ● How Mondoo uses AI agents for prioritisation (businesscriticality, blast radius, exploitability) and remediation (producingautomation code for tools like Terraform, Chef, Ansible) ● Dom's advice: don't be afraid jump into AI, explore,and learn how to solve real problems with modern tools About neuco: neuco Group is a global specialist recruitment and executive search firm focused on the Cyber Security, Media & Sports Technology, and Satellite, Space & Defence industries. We help organisations hire niche specialist talent at mid-to-senior and executive levels, connecting businesses with professionals who possess the expertise needed to drive growth and innovation in highly competitive markets. Whether you're hiring now, planning future growth, or simply looking for expert talent market advice, we'd be delighted to help. Get in touch: hello@neuco-group.com

  • May 14 · 29 min

    Securing the Agentic Endpoint: How Manifold Is Building AI Detection & Response - Episode 70 - Mike McKenna, Manifold Security

    Mike McKenna, Co-Founder and CRO of Manifold Security, to dig into why the jump from LLMs to autonomous agents is the biggest inflexion point in cybersecurity and why most existing security tools aren't built for it. Mike's path into cyber started with a stroke of luck: his then-girlfriend (now wife) fielded a cold recruiting call for Coalfire and pointed them his way. What followed was eight years watching Coalfire scale from 100 people and $30M in revenue to a compliance powerhouse, with Mike's average deal size growing from $30–40K to $300K. A formative stint at Protect AI under three-time founder Ian Swanson showed him what elite decision-making looks like at startup speed. When Protect AI sold to Palo Alto Networks, Mike and his co-founders, Neal Swaelens and Oleksandr Yaremchuk saw the next big gap: first-generation AI security was built for chatbots, not for agents that act autonomously across enterprise systems. Key Topics Covered: How a cold call and a quick-thinking girlfriend launched a 15-year cybersecurity career The mentors who shaped Mike's sales philosophy from craft improvement to enterprise rigour Why the jump from LLMs to agents is more impactful than most people realise Hiring sales talent for a category that barely exists yet prioritising plasticity over pedigree When to transition from founder-led sales to a dedicated team How AI is changing outbound sales and the second-order consequences of flooded inboxes First-gen vs. second-gen AI security: why classifying natural language isn't enough What Manifold actually does: runtime visibility into agent behaviour on the endpoint The AI bubble debate and why the demand curve looks different from late-90s dark fibre Mike's advice for anyone considering a career in cybersecurity Mike McKenna is Co-Founder and Chief Revenue Officer at Manifold Security, an AI Detection & Response platform securing autonomous AI agents on enterprise endpoints. Before founding Manifold, Mike spent eight years at Coalfire and served as part of the early go-to-market team at Protect AI (later acquired by Palo Alto Networks). Mike and his co-founders launched Manifold out of stealth in March 2026 with an $8M seed round led by Costanoa Ventures. He holds a degree from Johns Hopkins University and is based in San Diego. Find Mike on LinkedIn: linkedin.com/in/mikemckenna9 Learn more about Manifold: manifold.security This episode of Cyber Security Matters is brought to you by neuco.

  • May 5 · 41 min

    AI Is Making Social Engineering Unstoppable, Here's What You Need to Know - Episode 69 – Bobby Ford, Doppel

    In this episode of Cyber Security Matters, hosts Harry Baldwin and Matt Rose sit down with Bobby Ford, Chief Strategy & Experience Officer at Doppel, to explore how AI is fundamentally reshaping the social engineering threat landscape. With nearly three decades in cybersecurity, from founding member of the Pentagon's Computer Incident Response Team to CISO roles at Exelis, Abbott, Unilever, and Hewlett Packard Enterprise. Bobby brings a rare blend of operational depth and strategic vision to one of the industry's most pressing challenges. Key Topics Covered: How Bobby accidentally fell into cybersecurity through a military assignment no one wanted The importance of being "gifted with opportunity" and the mentors who shaped his career Why Bobby believes there's an experience gap, not a talent gap, in cybersecurity The evolution of the CISO role, from firewall manager to business partner to two diverging paths What keeps CISOs up at night: personal liability and regulatory scrutiny Bobby's three hiring imperatives: appreciation, consistency, and the ability to listen Where the next generation of security talent will come from How AI is changing social engineering in four key ways: hyper-personalisation, volume, speed, and multi-channel attacks Why legacy technologies and awareness training alone can no longer defend against AI-enabled threats A real-world vishing simulation where help desk staff stayed on the phone with a deep fake agent for over seven minutes How AI reduces adversary reconnaissance from weeks to seconds Bobby's career advice: chase the problem, not the title. neuco are a Global Specialist Recruitment and Executive Search company in the Satellite, Space and Defence, Cyber Security and Media & Sports Technology sectors.

  • April 13 · 34 min

    Securing the Future of Software: ASPM, AI Code & the New AppSec Frontier | Episode 68 | Liav Caspi, Legit Security

    Application security has always been a balancing act but AI-generated code has tipped the scales entirely. In this episode, Harry and Matt sit down with Liav Caspi, Co-Founder & CTO of Legit Security, to explore how organisations can secure modern software pipelines without slowing development to a crawl. From his early days in Israel's elite cyber intelligence Unit 8200, to co-founding one of the most forward-thinking AppSec companies in the market today, Liav brings a rare blend of deep technical expertise and product-led thinking to one of the most urgent challenges in cybersecurity. They cover the lose-lose dilemma that inspired Legit Security's founding, why ASPM is becoming the cornerstone of enterprise security strategy, how AI is dismantling the technical moats of legacy vendors and what it means to secure software when AI agents are doing most of the building. Key Topics: Why the traditional approach to application security puts both developers and security teams in an impossible position What Application Security Posture Management (ASPM) actually means in practice, and why it's becoming essential How AI is disrupting legacy AppSec vendors like Checkmarx and Veracode and lowering barriers to entry for challengers The rise of "agentic AppSec" and what it means to secure AI-driven development pipelines Why AI fluency is now a baseline hiring requirement across every role in cybersecurity Liav's prediction that source code itself will become less relevant as AI takes over the build process The talent challenge in AppSec: finding people who understand both security and software development Guest Bio: Liav Caspi is the Co-Founder and CTO of Legit Security, where he leads the company's technology vision and product strategy. He began his career in Israel's elite cyber intelligence Unit 8200, spending around a decade in various engineering, team lead, and project management roles. He went on to serve as Senior Software Engineer and Project Lead at Argus Cyber Security, before joining Checkmarx one of the pioneers in application security where he led architecture and product management for the SCA solution. In 2021, he co-founded Legit Security, which provides an AI-native Application Security Posture Management (ASPM) platform that helps large enterprises secure their entire software development lifecycle, from code to cloud. Legit Security is purpose-built for the era of AI-powered development, securing CI/CD pipelines, coding agents, and vibe coding environments. Sponsored by neuco. Cyber Security Matters is brought to you by neuco, the specialist recruitment partner for the cybersecurity industry.

  • April 7 · 44 min

    Stopping Ransomware Before It Starts - Episode 67, Glenn Wilkinson, Agger Labs

    From dial-up curiosity to killing ransomware in milliseconds, Glenn Wilkinson has been inside the attacker's mind his entire career, and now he's using it to defend you. Hosts Harry Baldwin and Matt Rose sit down with Glenn Wilkinson, CEO and Co-Founder of Agger Labs, for a wide-ranging conversation covering Glenn's journey from self-taught teenage hacker in the 90s to serial founder, and a deep dive into everything ransomware where it came from, how it became a thriving criminal industry, who it's really targeting, and what businesses can actually do about it. Key topics covered: How Glenn went from dial-up internet and underground hacker forums to founding multiple cyber security companies The hard lessons of the hacker-to-founder transition why great engineers often miss the business fundamentals The origins of ransomware: from the AIDS Trojan in 1989 (distributed on a floppy disk) to CryptoLocker's Bitcoin pivot in 2013 Double and triple extortion why backups alone no longer protect you How NotPetya (2017) marked the first major nation state supply chain attack, and why cyber is now a precursor to kinetic warfare Ransomware as a Service: the industrialisation of cybercrime, affiliate models, and initial access brokers Law enforcement fighting back Operation Kronos, hack-back legislation, and the moped theft analogy AI's actual (limited) impact on ransomware today and where the real risk lies Why SMBs are consistently the most vulnerable and the least prepared What any business can do right now to reduce ransomware risk The debate around banning ransomware payments How Agger Labs fits into the modern security stack: one thing, done well About the guest: Glenn Wilkinson is an ethical hacker, keynote speaker, and 3x founder. With a computer science background from Oxford and decades of hands-on penetration testing, Glenn has legally hacked 100+ organisations, spoken at Black Hat and DEF CON, and appeared on CNN and BBC. He is the CEO and Co-Founder of Agger Labs, which builds lightweight ransomware protection that detects and kills attacks before encryption begins running from Windows 7 to the latest server editions, no signatures or AI required. Connect with Glenn: LinkedIn | glenn-wilkinson.com | agger-labs.com Cyber Security Matters is brought to you by neuco.

  • March 10 · 44 min

    People Over Product: What Really Makes Cybersecurity Startups Succeed - Episode 66, Alison Eastaway, Push Security

    In this episode of the Cyber Security Matters podcast, hosts Harry Baldwin and Matt Rose sit down with Alison Eastaway, VP of People and Culture at Push Security. Alison brings a refreshingly pragmatic perspective to the often-overlooked human infrastructure behind high-growth startups and shares why, in cybersecurity especially, the team really is everything. Alison's career is anything but conventional. Having started working at 14 in Australia and bypassed a traditional university route, she's built her expertise through hands-on experience across telco, hospitality, advertising tech, HR tech, and now cybersecurity, including a formative stint at screen, which was later acquired by Datadog. Throughout the conversation, she shares hard-won insights on hiring for culture fit in remote-first organisations, navigating today's complicated talent market, and why the best thing a great candidate can do in a first interview is simply avoid scoring an own goal. Key Topics: How Alison fell into cybersecurity and what drew her to the industry's pragmatic, low-BS culture Why she views her proudest professional achievement not as the Datadog acquisition, but as the Screen team group chat that still pings years later The "culture as a savings account" philosophy and why you need to invest before you need to draw on it The unique challenges of building and maintaining culture in fully remote or distributed teams The state of the talent market right now: why it's a buyer's market for employers, and what candidates can do to stand out amid AI-generated application noise Practical interview advice including why a first interview is really about not scoring an own goal How to handle having multiple offers on the table (and the smart question Alison always asks candidates first) What candidates switching from big companies to startups need to get right and the language mistakes that give them away Career advice for anyone looking to enter cybersecurity or move into a people and talent function Guest Bio: Alison Eastaway is a senior people and talent leader with extensive global experience across high-growth startups and scale-ups. She has led recruitment, people operations, and organisational development across Europe, the US and beyond, with leadership roles at companies including Poolside and screen the latter acquired by Datadog in 2021. Alison is currently VP of People and Culture at Push Security, where she leads global people strategy in support of long-term business growth. About neuco: We are a specialist recruitment and executive search firm, working globally in four sectors; Content & Media, Satellite & NewSpace, Connectivity & Cyber Security. If you are hiring for a new role or want to discuss your growth plans. Please do reach out to hello@neuco-group.com

  • March 2 · 48 min

    Proactive Cyber Defense & Offensive Security Leadership - Episode 65, Ray Ruemmele, Evolve Security

    In this episode of Cyber Security Matters, hosts Harry Baldwin and Matt Rose sit down with Ray Ruemmele, Chief Revenue Officer at Evolve Security. Ray shares insights from his 20+ year journey through enterprise technology, from selling typewriter ribbons at IBM to leading offensive security initiatives. The conversation explores the evolution of proactive cybersecurity, building high-performing teams, and why understanding your people is the foundation of great management. About Ray Ruemmele Ray brings over two decades of leadership experience in enterprise technology and cybersecurity. Before joining Evolve Security as CRO, he led major growth initiatives as VP of Sales at Kudelski Security and held leadership positions at IBM, Lenovo, Juniper Networks, and Okta. Ray is known for building high-performing teams that drive sustainable revenue growth and specialises in offensive, proactive cybersecurity solutions. Key Topics Discussed: Career evolution from IBM typewriter ribbons to offensive security leadership The strategic value of big company experience versus startup agility Learning strategic thinking through Harvard training and the Five Forces framework Management philosophy: Understanding what makes your people tick The 45 sales kickoffs spanning a career in enterprise tech How the COVID pivot changed sales forever and hiring for the new reality The journey from individual contributor to management Building effective sales teams: What Ray looks for in candidates Offensive security and Evolve's Academy training mission What attracted Ray to Evolve Security and the Chicago connection First year as CRO: Team assessment, tools, and the 1985 Bears analogy The Zafran partnership and building a partner ecosystem Advice for entering cybersecurity: Learning, labour, and patience About Evolve Security Evolve Security is a leader in offensive, proactive cybersecurity solutions, specialising in continuous penetration testing and security validation. The company helps organisations move from reactive security postures to proactive threat identification and remediation. Connect with Ray Ruemmele on LinkedIn: https://www.linkedin.com/in/rayruemmele/

  • February 10 · 37 min

    Why $50 Bribes Are Breaching Enterprises - Ep64 - Michael Waite, Dune Security

    On this episode of Cyber Security Matters, hosts Harry Baldwin and Matt Rose sit down with Michael Waite, Co-founder and CTO of Dune Security. Michael shares his journey from enterprise consulting to building a venture-backed startup tackling one of security's stickiest problems: the human element. Episode Summary Michael discusses how traditional security awareness training fails to change human behaviour and why the threat landscape has shifted dramatically toward off-channel attacks via WhatsApp and encrypted apps. He reveals how attackers are using AI-powered voice cloning and open-source intelligence to launch sophisticated social engineering campaigns, and shares his personal security practices. Michael also explains how Dune Security uses AI defensively to quantify individual risk and drive targeted interventions that achieve a two-order-of-magnitude improvement in employee security posture. Key Topics Covered The transition from hands-on-keyboard building to strategic leadership as a startup scales How Dune's CISO Advisory Council shaped the product from day one Why soft skills and curiosity matter more than technical expertise in hiring The shift from email phishing to off-channel attacks on personal devices Real-world examples including the MGM breach and $50 bribes in lower-cost delivery centres Personal security practices anyone can adopt Using AI defensively for individual-level risk quantification Chapters 00:00 – Introduction 01:12 – How Michael got into cybersecurity 04:43 – Key influences and leadership lessons from consulting 07:05 – Mindset shift from consultant to co-founder/CTO 09:05 – Building the CISO Advisory Council 10:59 – Talent acquisition strategy and team building 13:51 – The skills shortage debate and what really matters in hiring 16:58 – The state of enterprise security and the human element 19:42 – Off-channel attacks and the WhatsApp threat 23:03 – What motivates attackers: bribes, data, and disruption 25:00 – Why no business is safe from AI-powered attacks 27:00 – Personal security tips 29:24 – AI on the defensive side: how Dune Security uses it 32:47 – Changing the "tick the box" compliance mindset 35:42 – Advice for those entering cybersecurity Guest Bio Michael Waite is the Co-founder and CTO of Dune Security, a company focused on protecting enterprises from modern social engineering threats. His career spans building secure platforms, leading large-scale cloud migrations, and scaling security solutions for Fortune 50 organisations. Under his technical leadership, Dune Security has raised $8 million in pre-seed and seed funding.

  • February 2 · 46 min

    Why Patience Beats Shortage in Cyber Security - Episode 63 - Benny Czarny, OPSWAT

    Welcome to Episode 63 of the Cyber Security Matters Podcast, brought to you by neuco. In this episode, hosts Gia Thomas and Harry Baldwin sit down with Benny Czarny, Founder and CEO of OPSWAT, for a wide-ranging conversation about rethinking cybersecurity from the ground up, the power of patience in building teams, and what inspired him to write his upcoming book Cybersecurity Upside Down. With over 20 years leading OPSWAT, Benny shares the journey behind building deep CDR (Content Disarm and Reconstruction) technology, why the industry's detection-focused mindset needs to be flipped, and how he's aiming to influence regulators worldwide. We also explore OPSWAT's exciting roadmap for 2026, including AI-powered engines, an optical firewall, a cybersecurity TV series, and ambitions for a public offering. Key topics covered: Why Benny wrote Cybersecurity Upside Down and how the book challenges industry norms The limitations of antivirus technology and why it was never designed to scan files Deep CDR explained: regenerating files to eliminate threats rather than detecting them Why cybersecurity training needs to be more holistic and less tactical The case against "talent shortage" - and why patience and training matter more Skills the next generation of cyber professionals will need, including fluency across LLM models OPSWAT's 2026 roadmap: AI prediction engine, optical firewalls, proactive DLP, and a Mythbusters-style TV series Leadership philosophy: the three honourable ways to leave a company Advice for newcomers: listen to your gut, innovate, and delight your customers Chapters: 00:00 Introduction and Guest Welcome 00:33 Benny's Journey into Cybersecurity 01:26 The Story Behind Cybersecurity Upside Down 04:37 Book Walkthrough and Key Concepts (slides) 19:21 Upcoming Technology and Announcements 22:23 OPSWAT's Cybersecurity TV Series 25:37 Advice for Writing a Book 27:52 Talent Challenges in Cybersecurity 32:04 Why Patience Beats Shortage 33:06 Skills for the Next Generation 36:55 Leadership Principles and Retention 38:06 Three Honourable Ways to Leave a Company 40:30 OPSWAT's 2026 Roadmap and IPO Ambitions 44:29 Final Advice for Aspiring Professionals About our guest: Benny Czarny is the Founder and CEO of OPSWAT, a global leader in critical infrastructure protection and cybersecurity solutions trusted by governments, utilities, and enterprises worldwide. With over two decades of experience, Benny has built OPSWAT into a company serving customers across nuclear, banking, manufacturing, and defence sectors. He is also a respected speaker and author, with his upcoming book Cybersecurity Upside Down set to challenge conventional thinking in the industry. LinkedIn: https://www.linkedin.com/in/bennyczarny/ The Cybersecurity Matters Podcast is brought to you by neuco, a global recruitment agency that specialises in sourcing brilliant people for groundbreaking companies in the cybersecurity space.

  • January 12 · 38 min

    Why IAM Is a People Problem - Episode 62 - Dr. Heiko Klarl, Nexis

    Welcome to Episode 62 of the Cybersecurity Matters Podcast, brought to you by neuco. In this episode, hosts Tom Wilding and Gia Thomas sit down with Dr. Heiko Klarl, CEO of Nexis, for an insightful conversation about identity and access management, cybersecurity leadership, and the evolving challenges facing enterprise security teams. With over 20 years of experience in security and IAM, Heiko shares his journey from academia to consulting to leading one of the industry's most respected authorization governance platforms. We explore why IAM projects fail despite excellent technology and smart teams, the critical role of change management, and how to build security teams that can adapt to rapid technological evolution. Key topics covered: Why identity and access management is fundamentally a people problem, not just a technology purchase The underrated importance of change management in global IAM implementations Hiring for curiosity and adaptability in fast-evolving cybersecurity roles How AI agents are exploding the complexity of identity governance The path toward passwordless authentication and what's holding it back Managing diverse teams and empowering them through trust and support Why academic foundations matter for continuous learning in cybersecurity Career advice: be kind and don't lie - and why these simple principles matter Chapters: 00:00 Introduction and Guest Welcome 01:19 Heiko's Journey into Cybersecurity 02:31 Joining Nexis: A Perfect Match 04:37 CEO Transition and Leadership Insights 07:04 Challenges in Identity and Access Management 13:12 Hiring and Managing Talent in Cybersecurity 23:40 Future of Cybersecurity and AI 35:16 Final Thoughts and Advice for Aspiring Professionals About our guest: Dr. Heiko Klarl is the CEO of Nexis, bringing over 20 years of expertise in security and identity access management. With a background spanning systems integration and consulting, Heiko combines strategic leadership with a deep philosophical understanding of technology. He specializes in enterprise authorization governance, delivering AI-powered solutions that simplify access governance, enhance security, and ensure compliance. The Cybersecurity Matters Podcast is brought to you by neuco, a global recruitment agency that specializes in sourcing brilliant people for groundbreaking companies in the cybersecurity space.

  • Dec 17, 2025 · 31 min

    Hypervisor Security & Team Building - Ep 61 - Austin Gadient, Vali Cyber

    Join us for Episode 61 of the Cybersecurity Matters Podcast as we sit down with Austin Gadient, CTO and Co-Founder of Vali Cyber, a company revolutionising Linux and hypervisor security. Austin shares his journey from the Air Force Academy's competitive hacking team to securing the nation's satellite infrastructure, and ultimately co-founding Vali Cyber after raising $20 million in funding. In this conversation, we explore the critical security gaps Austin discovered while working with satellite systems in the US Air Force, the unique challenges of protecting Linux environments where traditional Windows-focused tools fall short, and how these real-world problems led to the creation of Vali Cyber. Austin discusses the father-son founding team dynamic, managing technical and business responsibilities as a startup CTO, and building a company culture that values diverse thinking and psychological safety. Key Themes From hacking competitions to satellite security Linux security gaps in satellite systems Building startups with family as co-founders Prioritisation over balance in startup life Technical culture as competitive advantage Leadership through listening, not commanding Hiring for learning ability over experience Hypervisor security as emerging threat category Missionary selling in nascent markets Strategic investment for execution runway Chapters: 00:00 Introduction and Guest Welcome 01:04 Austin's Journey into Cybersecurity 03:52 Founding Valley Cyber 06:23 Balancing Engineering and Business 08:26 Company Culture and Team Dynamics 10:59 Industry Diversity and Talent Acquisition 18:12 Hypervisor Security and Market Education 24:10 Future of Cybersecurity and Final Thoughts About the Guest: Austin Gadient is the CTO and Co-Founder of Vali Cyber, leading the development of high-performance Linux and hypervisor security solutions. He continues to serve as a Distinguished Security Engineer in the US Air Force Reserve, managing advanced space cyber capabilities. With experience securing satellite infrastructure and driving security research, Austin brings deep technical expertise to the emerging field of hypervisor security. Website: www.valicyber.com The Cybersecurity Matters Podcast is brought to you by neuco, a global recruitment agency that specialises in sourcing brilliant people for groundbreaking companies in the cybersecurity space.

  • Dec 8, 2025 · 48 min

    Social Engineering Psychology - Ep 60 - Boris Goncharov, AMATAS & Plainsea

    In Episode 60 of the Cybersecurity Matters Podcast, we sit down with Boris Goncharov, Chief Strategy Officer at Plainsea and Co-Founder of AMATAS. With over 20 years of experience in information security, Boris brings a refreshingly unconventional perspective to cybersecurity, shaped by his background in fine art and philosophy. Boris shares his fascinating journey from aspiring painter to cybersecurity leader, revealing how his early experiences with gaming sparked an interest in understanding how systems work and can be manipulated. He discusses how creative thinking and artistic perspectives enhance security problem-solving, offering unique insights that challenge traditional approaches to the field. Key Topics Covered: From fine art and philosophy to cybersecurity leadership How gaming influenced security mindset and hacking curiosity The psychology behind social engineering attacks AI deepfakes transforming the cyber threat landscape Balancing security paranoia with business enablement Why the human factor remains the biggest vulnerability Foundational security practices that still work today The exhausting reality of constant learning in cybersecurity Career advice: stubbornness, discipline, and sacrifice required Chapters: 00:00 Introduction and Guest Welcome 01:16 Boris' Unconventional Path to Cybersecurity 07:11 The Role of Creativity in Cybersecurity 12:59 Challenges and Insights in Building Cybersecurity Teams 25:29 Leadership Realizations and Communication 30:13 The Evolution of Cybersecurity 32:51 Complexity and Security Challenges 38:43 Practical Cybersecurity Advice About Boris Goncharov: Boris Goncharov is Chief Strategy Officer at Plainsea and Co-Founder of AMATAS, with over 20 years of experience in information security. His expertise spans information security strategy and management, cloud security, social engineering, penetration testing, and physical security. Boris has led enterprise-wide security programs across diverse industries and is an experienced instructor, having taught official CEH, ECIH, and CISSP courses since 2010. He is a frequent speaker at international security conferences. About Plainsea: Plainsea provides strategic cybersecurity solutions helping organisations navigate complex security challenges and build resilient defences against evolving threats. About AMATAS: AMATAS is redefining how businesses protect themselves against emerging threats through innovative security approaches and strategic consulting. The Cybersecurity Matters Podcast is brought to you by neuco, a global recruitment agency that specialises in sourcing brilliant people for groundbreaking companies.

Showing 1–20 of 21 episodes