Why Cybersecurity Is a People Problem Before It Is a Technology Problem
Tech Talks DailyJuly 12, 2026
3636
43:1334.66 MB

Why Cybersecurity Is a People Problem Before It Is a Technology Problem

Why do companies continue spending heavily on cybersecurity technology while human behavior, poor governance, and skills shortages leave them exposed to attacks?

In this episode of Tech Talks Daily, I speak with Phil Chapman, Cybersecurity Subject Matter Expert at Firebrand Training, about what more than two decades in the Royal Air Force, signals intelligence, counterterrorism, threat intelligence, and cybersecurity education taught him about defending companies in an increasingly complex threat environment.

Phil's career provides a fascinating perspective on how intelligence skills developed in military and national security environments can be applied to modern cyber defense. After 23 years in the RAF, including work supporting organizations such as GCHQ and the NSA, training intelligence analysts, and working in counterterrorism, Phil moved into technology training and cybersecurity education. Today, he helps companies understand their cybersecurity training needs while supporting people building careers in an industry that continues to need new talent.

A major theme throughout our conversation is Phil's belief that cybersecurity is fundamentally about people. Technology matters, but expensive security products cannot compensate for employees who do not recognize threats, executives who misunderstand their responsibilities, or companies that treat security awareness as an annual compliance exercise.

Phil explains threat intelligence in practical business terms, examining the relationship between threats, vulnerabilities, business assets, and risk. We discuss why insiders remain one of the biggest security concerns facing companies, including malicious employees and the far more common problem of accidental actions such as clicking phishing links, sharing sensitive information, or sending data to the wrong recipient.

The arrival of generative AI is making these problems harder to manage. Phil discusses how criminals are using AI to create more convincing phishing campaigns, deepfakes, social engineering attacks, and other forms of cybercrime. At the same time, employees are introducing new risks by using AI tools without understanding what happens to company data or whether appropriate policies and controls are in place.

But this episode is also about opportunity. Phil challenges the stereotype that cybersecurity careers are only for highly technical people sitting behind multiple screens writing code. He explains the different career paths available across cybersecurity engineering, threat intelligence, incident response, security operations, governance, risk, compliance, and analysis, and why skills from customer service, the military, data analysis, writing, communications, and other professions can transfer successfully into cyber roles.

For anyone considering a career change or trying to enter the technology industry, Phil offers practical advice on where to begin. Rather than chasing advanced certifications or trying to become an ethical hacker immediately, he recommends building a strong foundation, understanding networks and operating systems, staying current with the news, developing analytical thinking, and remaining curious about how criminals adapt world events and new technologies to create attacks.

We also discuss cybersecurity apprenticeships and why alternative routes into technology careers could help companies develop talent while giving people of different ages and professional backgrounds access to an industry they may previously have considered out of reach.

Finally, Phil explains why cybersecurity professionals cannot focus only on today's threats. AI is already changing both attack and defense strategies, while quantum computing is forcing companies to examine cryptography, data protection, and long-term security planning. His message to business leaders and technology professionals is clear: buying more technology will not solve every security problem. Companies need informed leadership, better governance, continuous learning, practical training, and people who understand how threats evolve.

This conversation offers business leaders a clearer understanding of cyber risk, provides technology teams with practical ideas for improving security awareness, and offers anyone considering a cybersecurity career a realistic view of the opportunities, skills, and pathways available through training and apprenticeships.

Useful Links

[00:00:03] - [Speaker 0]
Welcome back to the Tech Talks Daily podcast. Quick question. What does a metal detectorist, a saxophone player, former RAF threat intelligence analyst, and cybersecurity trainer have to teach us about staying safe in a world of AI powered attacks? Well, quite a lot as it turns out because my guest today is Phil Chapman, cybersecurity subject matter expert at Firebrand Training. And Phil brings with him a fascinating mixture of military intelligence experience, cyber education, and real world training expertise.

[00:00:40] - [Speaker 0]
He's gonna bring it all into a conversation that moves far beyond the usual fear based cybersecurity headlines because I wanna learn more about how he is using all his experience to help organizations and future cyber professionals or those looking for a career change understand how threats are spotted, interpreted, and handled in practice. So, yeah, we'll talk about why cybersecurity is ultimately a people challenge, why human behavior continues to be one of the biggest risk factors, and how AI is changing the way criminals create phishing attacks, scams, deepfakes, and social engineering campaigns. But most importantly of all, this is an episode about opportunity because Phil is gonna explain why cybersecurity is far broader than the stereotype of someone in a hoodie hacking into systems and talk about why skills from customer service, data analysis, writing, project management, governance, and even curiosity itself could all lead you to a path that will unlock a career in cybersecurity. So we'll talk about everything from apprenticeships, transferable skills, AI, quantum computing, and why the next generation of cyber talent might come from far more varied backgrounds than you might expect. So whether you are a business leader trying to improve cyber resilience in your organization, a parent or student wondering where future careers are heading, or maybe someone thinking about making a career change.

[00:02:11] - [Speaker 0]
This conversation with Phil today will offer practical advice, and we'll wash it all down with a little humor too. If that sounds like a good deal to you, you're in for a great you're in for a treat today. So enough from me. Let me introduce you to Phil right now. So thank you for joining me on the podcast today, Phil.

[00:02:30] - [Speaker 0]
Can you tell everyone listening a little about who you are and what you do?

[00:02:34] - [Speaker 1]
Hi, Neil. Yeah. Great to be with you. Two great questions which are important to distinguish between the who and the what. So who am I?

[00:02:42] - [Speaker 1]
I'm Phil Chapman. I'm married with a couple of kids, currently living in the Southwest Of England, and I've got a wide range of hobbies and interests that, oddly enough, don't really center around technology or IT. So I like things like astronomy, bird watching. For my sins, I'm a metal detectorist as well. So it's quite a wide range of eclectic things that I do.

[00:03:03] - [Speaker 1]
But I'm probably lying a little bit because my telescope's got a computer attached to it. Metal detector is quite technically advanced, I suppose, really. And I play an electric saxophone, so I don't completely remove myself from tech. What am I? At the moment, I'm the commercial subject matter expert for cybersecurity at Firebrand's training.

[00:03:25] - [Speaker 1]
Now what that means is that I look at doing the training needs analysis, development of product across our vendor range for the commercial side of Firebrand training. I've been with them for about twelve years as a permanent member of staff. Previously, I was an instructor across most of the cyber tech range that we deliver. And I also spent a couple of years as the lead SME for the level three, level four cybersecurity apprenticeships that we still deliver here as well. But I moved over into this role a couple of years ago, really to fill the gap from the commercial side of things and develop our opportunities really in all target sectors, industry sectors that we now work across.

[00:04:08] - [Speaker 1]
And from a training point of view, so I still teach, and the key areas that I deliver now are our cybercrime portfolio, which is quite an interesting area to get into. And we actually deliver, bespoke products to all UK law enforcement cybercrime investigation, prevent, and protect units across The UK. We can expand that over into, other areas as well.

[00:04:32] - [Speaker 0]
Wow. There is so much to unpack there from your story. So many interesting. I've got to ask from a detective side of things. What's what's your are are you allowed to share your most famous find?

[00:04:42] - [Speaker 0]
Have you have you found anything? Have you avoided those dreaded nighthawkers? Tell me about that.

[00:04:49] - [Speaker 1]
Yeah. So so you actually kind of have to be very careful with things like that, obviously. So there is a legal requirement for reporting fines and things like that. But no no gold, unfortunately. So I'm not no one's witnessed my gold dance yet, but I've got that lined up.

[00:05:05] - [Speaker 1]
Plenty of horseshoes, Neil. So so if you ever need to shoe a horse, I'm probably your go to guy for that. But no. Really, of coins and things like that are probably the biggest finds that that I pick up. But it's quite interesting.

[00:05:20] - [Speaker 1]
I quite like the history side of things. So even even sort of going back into Victorian earlier twentieth century finds and things like that. It's quite interesting doing the research to find out what it was and who it belonged to and things like that. So that's what I like doing. But I think the key thing with that one is it it gets you out into the middle of a field in all weathers.

[00:05:40] - [Speaker 1]
Here's the mind. And it's incredible what that kind of does for you. If you're in a in a high pressure job, I wouldn't necessarily say that my job is high pressure, but if you are in that kind of situation, just to be able to do that for a couple of hours or for a day and things like that to to to get away from what it is you're doing today to day is a very healthy position to be in. So that's why I like doing it, really.

[00:06:03] - [Speaker 0]
Absolutely. Love it. Brilliant. And further into your back story there, before moving into cybersecurity education, you also worked as a threat intelligence analyst at the RAF. I mean, tell me about this journey and some of the lessons from military intelligence that maybe shaped the way you think about cyber defense today.

[00:06:23] - [Speaker 0]
Again, probably limited as to what you can share, but what what can you tell me about what you learned there?

[00:06:27] - [Speaker 1]
Yeah. I mean, it's it's probably a podcast in its own right, Neil, to be honest with you, because I I did twenty three years in the in the RAF. I initially started off in in what we called straight sigs or comms. So I worked on communication systems. I did encryption systems and things like that.

[00:06:42] - [Speaker 1]
So so early kind of introduction into the world of cryptography and all of that kind of stuff. Now here, I'm talking early eighties, which kind of dates me a little bit, of course. Yeah. So twenty three years of moving through into I then moved into the intelligence world in the mid eighties, in fact, and kind of built up, I suppose, really through the whole intelligence life cycle. So initially as an operator, was part of the collection, the analysis.

[00:07:10] - [Speaker 1]
I'm a I'm a linguist as well, so I did interpretation of of data and things like that coming in as well. And then as I started to progress through the ranks, I was quite lucky really in the fact that most of the stuff that I did was working in support of agencies such as GCHQ, NSA, lots of military intelligence units in support of both operational and tactical signals intelligence mostly, I suppose, really, but I also did some human intelligence stuff as well. I then became also was lucky enough to become an instructor as well, so I spent five years actually training Tri Service Analysts and Operators across a whole different range of different skills, suppose, really. That also then introduced me to a whole lot of different government agencies, security service, and people like that. The last three years, in fact, this is really where I kind of earned my spurs as a threat intelligence analyst per se, was I was actually seconded out of the military and spent three years doing counterterrorism.

[00:08:09] - [Speaker 1]
But this then put me more into a strategic role. So I was quite fortunate, in fact, that I've I've kinda seen it across all of those different layers, not only the whole intelligence cycle, but the way that it works strategically, tactically, and operationally, I suppose, really, also then layering in the technical side of that as well. I suppose that also then allows me to use those transferable skills when we get out into industry. Because to be honest with you, we don't reinvent the wheel Yeah. In a lot of these areas.

[00:08:38] - [Speaker 1]
You know? And I think a lot of military people like myself, you know, we're we're trained in specific job roles. We do specific things for specific operations and things like that. We kind of forget, I suppose, really, that what you're actually doing is building up quite a repertoire of these transferable skills. I'm a big fan of that, that that have a real impact in the world outside of the military and across all industry sectors.

[00:09:01] - [Speaker 0]
Well, I think you're rapidly turning into one of the coolest people I've ever spoken with there. You've you just casually dropped anti terrorism, big name security agency, linguist, instructor, as well as sax player, astronomer, and detectorist. But, I mean, fast forward to present day. I think when people hear the term threat intelligence, it can sound incredibly abstract. So for a business leader that could be listening today, can you tell me a little bit more about what you've how or how you would describe it and why it has become such an important capability for organizations of all sizes, really?

[00:09:35] - [Speaker 1]
Yeah. It's a it's a good question. And I think if you also layer in the word cyber Yeah. We we like to slap the word cyber on a lot of things these days as well into that as well. It makes it even more abstract, I think, for a lot of business leaders to really work out what are we actually talking about from a cyber threat intelligence point of view.

[00:09:53] - [Speaker 1]
So and it kind of conjures up different meanings, I suppose, really, depending upon what kind of organization you are, what kind of training you've had, I suppose, really, and and what how you really understand what the term threat is all about. But, of course, threat is a component part of risk. So we're getting down into the foundations here and the fundamentals, I suppose, really, when we're looking at things such as risk assessments. We have a threat. We have a vulnerability, and we have an impact on a business asset.

[00:10:20] - [Speaker 1]
So so getting it down into industry talk, commercial speak like that, is an important part, I suppose, really, we're trying to get into executive level into their understanding about what these threats actually are. I suppose if I I'm a I I really love when I train, especially, I really love storytelling and analogies and things like that. So so if our business, for example, was close to a river, there would be a threat of a flood coming from the river. So the the threat would actually be the river itself. If it was down to flood, the impact, of course, would could be quite catastrophic on our business.

[00:10:53] - [Speaker 1]
And it's quite easy really when you think of exact examples like that of how when an industry when a business conducts a risk assessment. It would look at those three areas and then start to think about what kind of controls are they gonna put into place to mitigate the risk. And there are lots of different ways that they can do that. They can mitigate it. They can remediate it and so on and so forth.

[00:11:14] - [Speaker 1]
And again, none of that is changed when we're looking at cyber threat intelligence as well. But so what we're deal dealing with here is picking up where the threat is coming from from cyber sources. So we talk about threat actors, and there are quite a lot of these to list through. So we go through nation state threat actors. But the biggest threat that we have from a cyber point of view is on the inside of our network.

[00:11:38] - [Speaker 1]
And that's always been the case. It's always gonna be probably the biggest area that we need to look at from a risk point of view is dealing with the inside threat. And that may be from nefarious threat actors, so disgruntled employees for want of a better term, or most importantly, and probably the biggest cause of most cyber incidents are accidental threat actors. So accidental insider action, clicking on the link, sending an email to the wrong person, wrong attachment, and all that kind of stuff. We're gonna get on to talk about AI, and that also amplifies this threat actor in what's actually happening in the workplace at this moment in time.

[00:12:20] - [Speaker 1]
I'll save that for later on.

[00:12:23] - [Speaker 0]
And I think we should also cover before we get to AI the fact that cybersecurity is almost always portrayed as a technology problem, and yet many successful attacks still exploit human behavior. So what are the most common warning signs that employees and leaders should be trained to recognize? And maybe just to bring AI into that, that has helped those attacks so much easier as well, hasn't it?

[00:12:46] - [Speaker 1]
Yeah. Absolutely. And I think you've hit the nail on the head with this. And and kind of if if this is a turning point for people to start to consider what cybersecurity is, and I've been a big advocate of the fact that cyber itself is not really a technological thing. It's not an IT thing.

[00:13:01] - [Speaker 1]
It's a people thing. And so that's a great t shirt to wear. That's a great strap to take away from this in the fact that if you get the people right, both in the employment within the world of cyber and also from a training, usually training and awareness side of things as well, you're kind of halfway to fighting the battle, I think. And it's it's always been the case, really. And I think a lot of the key indicators from a business point of view is that if you're and we talk about the kind of the goalposts here, really.

[00:13:29] - [Speaker 1]
So from an executive level, if the managing directors and the company execs are not aware of what that threat is from a cyber point of view, those are the people that are ultimately not only responsible, but, of course, they're accountable for this from an organizational point of view. The people below them, the people they employ within that sector, both the cybersecurity professionals, but more importantly, the people at the workplace, the general users, the people that are using the technology systems, those are the people that are all responsible for the cybersecurity element of things as well. So it's people all the way down through this food chain, if you like. And AI really amplifies, I suppose, really at this moment in time, the way that people generally, with a lack of training, maybe a little of ignorance about what is actually happening to the data, for example, they're causing a huge risk to organizations. But that really needs to be underpinned by good governance.

[00:14:23] - [Speaker 1]
So here is where we're then looking going back up the food chain into our cybersecurity professionals, most importantly at the exec level of getting their AI policy in place and getting good governance, guidance, frameworks well and truly established. And now is the time to do it if they've not already started thinking about that.

[00:14:41] - [Speaker 0]
And you're someone that's worked with organizations across many different sectors, and suspect we would both agree that we need more than a annual compliance test where staff are expected to click next 29 times, and then they tick the cybersecurity HR box for another twelve months. But where do you see the biggest cybersecurity skills gap right now? And are those gaps more about technical knowledge, or or is it more critical thinking or or something else entirely different now? Because it seems that very often, when it comes to cybersecurity, we almost very often forget our our street wise. If you're walking down a street with a you you're aware of certain risks.

[00:15:17] - [Speaker 0]
But online, people often forget that entirely.

[00:15:20] - [Speaker 1]
Yeah. Absolutely. And I think, again, it comes back to people, Neil. You know? It's a yes.

[00:15:24] - [Speaker 1]
It's very, true to say that the the good people that are involved in cybersecurity, so the professionals, You know, they're well trained. You know, they they know the risks. You know, they know the technologies that they're using, things like that. I think the key thing for them is it's often quite difficult for them to keep up with technology. And, again, we're obviously referring to AI and other systems that have come on as well, it's been it's been an evolution, I suppose, really, especially over the past twelve months in the way that AI has kind of come on leaps and bounds.

[00:15:55] - [Speaker 1]
But to be honest with you, we faced exactly the same kind of struggle when the cloud was first adopted. And those kind of technologies have the same kind of noises, I suppose, really around the fact that, you know, people are gonna lose their jobs and security within the cloud and all of those kind of things. But but again, good training, good governance, good oversight has really sort of made that more of a mainstay operation for most businesses as well. So I think again, the gaps from my point of view are more about the people side of things. So again, it's these goalposts that I've referred to at the the top level, the executives and the your users and the people at the the coal front, if you like, that are actually dealing with our data and information systems.

[00:16:34] - [Speaker 1]
Good training, good user awareness, I suppose, really. But as you said, it's got to have an impact. It's got to mean something to them at that kind of level. And finding that, okay, finding that kind of sweet spot when we do our user training and awareness sessions that are outside of the the tick box exercise from HR. You know, that's a that's a creative thing.

[00:16:55] - [Speaker 1]
And and that kind of also then works very, very nicely into the cybersecurity professional, the analysts that are working with this as well, and the different sectors, I suppose, really within cyber. And, hopefully, I'll have time to explain a little bit more about that during the podcast.

[00:17:13] - [Speaker 0]
Yeah. And I also think many companies, they invest so heavily in security tools, but then still struggle to improve their security posture there, and they end up fighting things like alert fatigue, facing burnout. We have a lot of that in cybersecurity teams. So from what you've seen here, what separates those organizations that successfully build cyber resilience from those that still remain vulnerable despite throwing a lot of money at the problem?

[00:17:39] - [Speaker 1]
Yeah. Brilliant. The and there are three I suppose, really, in my mind, there are three separate parts to this, really. Yeah. I've already alluded to the transferable skills.

[00:17:47] - [Speaker 1]
There there's kind of a a I suppose, really a bit of a stereotype about the type of people that are involved in cyber, but these transferable skills are often more useful, to be honest with you, than some of the technical skills that Brigitte learned and trained. It's all down to people. Of course, that's kind of Phil's t shirt for the month, I suppose, really, and good governance. You know, where everybody loves technology, that that's true. But the kind of underpinning thing throughout all of this is going to be good controls when we're looking at laws, regulations, standards, and policies and things like that.

[00:18:19] - [Speaker 1]
And again, a great way to look at this, I think, is that, you know, we we we all like a little bit of tech, and you can drive a fancy sports car that's got all of the latest gadgets and gizmos and technologies and things like that, and it can, you know, do super speeds and things like that. But if you don't if you're not aware of the highway code and if you don't know about the laws and the regulations that you've got to adhere to on a on a public highway, then it's only a matter of time before you're gonna have an accident, and the result is gonna be part of your negligence. And it's exactly the same when we're looking at implementing technologies and and, obviously, the change process that we put into place at a business level.

[00:18:56] - [Speaker 0]
And we did briefly mention AI earlier. It's a tech podcast, so we have to go there. And AI is indeed changing both sides of the cybersecurity equation. So how are you seeing attackers using AI differently today? And are there any new skills that defenders and business leaders and teams need to be developing to to keep pace with these changes?

[00:19:17] - [Speaker 1]
Yeah. It's a huge area, Neil, and I would love to be invited back to about the the cybercrime side of things from comes from an AI side of things. And, you would have probably have had to been living under a rock, especially over the past kind of six to twelve months, I suppose, really, for seeing the types of attacks that have been a AI generated, I suppose, really. Now the kind of numbers that we're looking at here is that and again, Firebrand has conducted some research into this as well. So we've got 77% of UK organizations actually believe that AI is increasing their cyber risk, and they'd be right with that.

[00:19:52] - [Speaker 1]
But, unfortunately, 27% of them are actually fully prepared for AI powered attacks. So now from a criminal perspective, so we're talking about nefarious threat actors here, that's increasing all the time. And so we've got areas such as Genetic AI, which is a big area at this moment in time, our frontier models, which of course, have hit the news recently. And, of course, then we get into the sort of more creative way that all criminals are creative regardless of whether that it's a it's typical kind of crime such as burglary or robbing a bank and things like that. You know, they they come up with some neat and quite creative ideas, and you have to give them the kudos for that.

[00:20:33] - [Speaker 1]
And cyber threat actors, from a criminal point of view, are equally as creative. So when we give them a gift that is creative, generative AI systems and things like that, it stands to reason that they're going to work that negatively against us as well. So more sophisticated types of social engineering attack like deepfake, obviously, phishing attacks and whaling attacks have got far more sophisticated over recent well, years, to be completely honest with you. And I suppose really, again, it comes back to that my original starting point here is that it's really the procedural controls that we need to put into place to make sure that those foundations are properly in place at an organizational level to make sure that we're aware of the risk, I suppose really, aware of the threat here as well. But we're also using the technology itself from a defensive point of view as well.

[00:21:25] - [Speaker 1]
And again, AI training has been has been aware of this or the training vendors have been aware of this for many years. And over probably, I'd say I'd like to say over probably the last six to eight months, this has really become a a a great area and opportunity for people to get trained up into across some of our vendor certification training packages as well. They've become really, really good rather than just been a kind of a bolt on needs to have kind of tick box exercise, I suppose, really, that that some training courses actually do. So so those have now become very, very good and very real world as well, I have to say.

[00:21:59] - [Speaker 0]
Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data, and Denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest. And one of the things I love about your work as well is your passion about developing future cyber We've seen over the last few years, it's one of the best jobs to enter at the moment.

[00:22:39] - [Speaker 0]
I think it's something like 0% unemployment rate. I'm not sure if that stat still holds true, but why is early exposure to cybersecurity education so important? And what could schools, employers, and governments do to encourage more people into this field? Because we're we're at a time where there's a lot of talk of jobs disappearing, and it this feels like such a a natural step for anybody interested here and a a great career that will can take you anywhere in the world.

[00:23:05] - [Speaker 1]
Yeah. I love that. And I think it is again, a ground level here is kind of awareness of what we're talking about cybersecurity, what it actually is, and what the kind of career paths structures and what that actually means. Because I think there's still a lot of ambiguity, suppose, really around cyber because we kind of certainly align it up with IT. And as I've alluded to before, cybersecurity is not IT.

[00:23:29] - [Speaker 1]
IT security is a very important part of an organization. It may actually be part of a cybersecurity package, I suppose, really on smaller organizations. But most large enterprises will break away the IT section away from their cybersecurity sections as well. And I think kind of removing that stereotype about the types of people that are employed within this sector as well is also a kind of a key advantage to us as well because it really is come one, come all. And, again, I'm lucky enough, I suppose, really, again, using my military background here, an eclectic mix of people that I've worked with, you know, through all of that time, especially with the government agencies, agencies like GCHQ, who who are really champions in this field of of getting a diverse range of people working for them, who have an amazing talent base and skills, especially from an analytical point of view.

[00:24:17] - [Speaker 1]
And just the way that they think and the way that they operate is completely diverse and different. And that's what you need. You need that kind of tapestry of people within your team, and it is about the team. Cyber itself, so just if I've got time Yeah. Go.

[00:24:30] - [Speaker 1]
It kinda breaks it kinda breaks down into three distinct regions. So we kind of and, again, what I don't like to do is is silo these or pigeonhole them, but but we have a cyber engineer, cybersecurity engineer. That's the technical, the geek, if you like. So if you like if you like networks, if you like endpoints, if you like computer systems, if you like playing around with firewalls, all that kind of thing, cybersecurity engineering. And again, a lot of that has moved up into the cloud.

[00:24:56] - [Speaker 1]
A lot of that also is driven by AI technologies as well. So if that kind of floats your boat from an early careers point of view, that's a great challenge as well. And of course, the technologies are developing all the time. Then we've the vendor responders. And again, if I was to if I was to ask a bunch of young people, you know, what does what does a cybersecurity person look like to you?

[00:25:15] - [Speaker 1]
They've probably got a hoodie with a whole load of ones and zeros as a backdrop before them. You know, they don't see the light of day. They just they work on computers, and then a weekend, they play on computers, and that's all they do. And you really don't wanna get stuck in a pub with one of them, do you? But the reality is, of course, that they're real people.

[00:25:34] - [Speaker 1]
And the defender responders are the people, the SOC analysts. These are the people that are gonna do threat intelligence analysts, for example, would fall into this category as well. Incident responders, which is an absolutely core part of any function of any business as well. And again, these are proper analysts. So these are people that are doing data analysis and things like that.

[00:25:54] - [Speaker 1]
So so from a data analytical background, you don't need a technical background to get into that. Okay? It's a great avenue of opportunity, and most large enterprises will use those. And again, AI cloud technologies feed very, very nicely into that as well. And then at the other end of the scale that kind of works more closely, I suppose, really with the governance risk and compliance side of the business, you've got your cybersecurity analysts.

[00:26:17] - [Speaker 1]
So these are risk analysts, really, that will be looking at the threats, the vulnerabilities, and the overall kind of assessments. Now these are data analysts. Again, so great background coming in. But these are also more creative, I think. So so ultimately, a penetration tester would fit into this category as well.

[00:26:34] - [Speaker 1]
And and again, most people, you know, again, if you talk start talking about cyber oh, so you hack things, do you? And do you know what? It's a very, very small part of cybersecurity is is hacking every system you got into. Yeah. It's super sexy.

[00:26:47] - [Speaker 1]
It looks great. And again, we've got TV programs that elevate the status of ethical hackers, which are great. I mean, they're and they're absolutely fantastic at what they do. But, of course, this is ultimately, what you're doing is a vulnerability test, which is part of a risk assessment. Yes.

[00:27:03] - [Speaker 1]
It's technical. Yes. It's using AI technology to do that as well. But it's only a very, very small part of this whole concept of what cybersecurity is all about. And so with these kind of three avenues of opportunity, I suppose, really, you can also move up through the management chain as well.

[00:27:19] - [Speaker 1]
So you you can progress through the operational side of things quite nicely up into a more strategic role very, very quickly as well if you're good at it. And the great news with this also is that from a Skills England perspective, is that that also maps very, nicely into the level four cybersecurity apprenticeships as well. So and to my mind, this is an absolute godsend for both young people and for organizations to get people in at that kind of talent level. They don't need to have any prerequisite technical knowledge, but they do need to be curious. They've got to be good with numbers and words, I suppose, really at a at a foundation level to to come in with this as well.

[00:27:58] - [Speaker 1]
But to be able to kind of nurture these people and when I was working on the apprentice side of the business, was probably one of the best jobs I ever had, really, working with those kind of people, young and old. So age is not a restriction here as well. And actually seeing them kind of grow, I suppose, really, within the confidence and the activities that they were doing, and they were blowing it out of the park, you know, within an eighteen month apprenticeship or twelve month to eighteen month apprenticeship. You know, they they're absolutely fantastic opportunities, and they're doing great work.

[00:28:27] - [Speaker 0]
Yeah. And it is such an important, thing to highlight here because I think many people listening will think of cybersecurity as one role, but in fact, it's probably 50 plus roles in everything from I don't know if the younger people wanting to enter penetration testing, cloud security, engineering, ethical hacking, etcetera. And people are a little bit older in the corporate space and have transferable skills for things like governance, risk, compliance. There's so many opportunities no matter what age there. But as we look ahead over the next few years, what cybersecurity skills do you think will be most valuable?

[00:29:03] - [Speaker 0]
And how should professionals, whether they're in the industry or thinking about entering it, what should they be doing to stay relevant in the threat environment as it all continues to evolve? Because there's gonna be a lot of opportunities here, isn't there?

[00:29:15] - [Speaker 1]
Yeah. There is. And I think and you're you're bang on. I couldn't agree more with what you've just said, in fact, Neil, about the way that people think, I suppose, really is is the key thing here. And, obviously, from a technology point of view over the next few years, we've got we've got to talk about AI here as well because Yeah.

[00:29:33] - [Speaker 1]
Who knows where that's gonna end up. You know, this is this is a it's almost like a daily changing playing field that we're looking at here as well. But does that excite me? Yes. It does.

[00:29:42] - [Speaker 1]
It also worries me, of course, because from a governance point of view as well. So it's a double edged sword, really. It's what AI is all is all about. But, you know, if you come from a development background, software development, data analytics, all of these kind of key skills are useful coming through. And to kind of to go back to what you just mentioned as well, you know, from an apprenticeship point of view, we've had internal colleagues from large financial organizations, for example, that have taken people from call centers and put them into a cybersecurity analytical role, and they perform brilliantly because transferable skills, their people skills, are second to none.

[00:30:17] - [Speaker 1]
You know? So when it comes to creative writing, reporting, dissemination of information, things like this, these are key people, you and those skills are absolutely essential. I think, without going too deep and meaningful into the advancements of technology, there are going to be two key areas that we need to focus on. AI, obviously, can't avoid that. And again, from a training point of view, that's going to be pretty much in every single cybersecurity portfolio that we're gonna see.

[00:30:48] - [Speaker 1]
No no two ways about it. It already is, if if I'm gonna be brutally honest with you. Another thing that's around the corner, of course, is quantum. Now this is something that I remember kind of ten, fifteen years ago, people asking me stories questions about quantum computing and and in particular, the cyber aspect of this. And I kinda remember flipping these stories.

[00:31:07] - [Speaker 1]
I don't worry. You put your head about that. You know? It's so far away that we don't really think about it. But the cold reality is now that we're probably about twelve months behind.

[00:31:16] - [Speaker 1]
So if you haven't got a quantum policy in place, if you're not thinking about quantum computing, especially the cryptography side of things, you're already too late in that market. Now, again, I'm not gonna be brave enough to predict when quantum computing is gonna come mainstream for us, but there's plenty of stuff that you can see from certain vendors, especially Microsoft who've got a great framework, in fact, and the big good people at OWASP, for example, are looking at this already. And that also the OWASP frameworks, for example, from a AI are exceptionally good points of reference as well. And so that's gonna be probably within the next five years that we're going to have to start looking at quantum becoming more mainstream. As I said, it already is in some industry sectors, and and governance side of that is already an issue, especially when we're looking at the cryptographic side of things as well, so protecting data.

[00:32:06] - [Speaker 1]
But I think the key thing here for especially for a younger audience or people that are thinking about, you know, what kind of skills do I actually need to come into the world of cybersecurity, you know, get away from the technologies. It is important that you, I suppose, really have a a passion for for technology, things like that. You know, even if even as a metal detectorist, I've got a machine that goes beep, but it tells me how deep things are and and what kind of metal it's likely to be, and I have to read numbers and crunch the data before I dig up that next horseshoe. You know, I love that kind of thing. Don't get me wrong.

[00:32:37] - [Speaker 1]
But, you know, the using the kit is something that you get trained on. Experience kind of gives you that value as well. But I think the fundamental skill is about staying curious and being creative. And it's also very, very important to get a good grounding, I suppose, really in the core subjects as well. So, you know, once again, I said before, we're not really reinventing the wheel from a cybersecurity point of view, whether we're moving into new technologies, AI, quantum, whatever it may be, because the foundations need to be in place as well.

[00:33:08] - [Speaker 1]
It's very, very important, I suppose, with people coming in not to overreach. That's that's a kind of a key takeaway, suppose, really, because people will come in saying, oh, yeah, want to be an ethical hacker. Well, you know what? You've got if you don't know how a network works, if you don't really know what an operating system is, don't really understand the way the data moves across the network, and so on and so forth, You can't really be an ethical hacker until such times as you've got that good foundation training embedded in, if if that kind of makes sense. And it's the same also for cybersecurity professionals that are already in, you know.

[00:33:38] - [Speaker 1]
You know, don't rest on your laurels. Start to build up, I suppose, really a pathway of success for you from a training point of view, don't overreach. But the core takeaway, one of the things I really used to love when I was teaching my level four apprentices was to get them looking at current affairs. Now seems a bit weird, but every time there's something on the news, my spider sense is going, oh, there's a cyber animal here. Okay.

[00:34:03] - [Speaker 1]
So, you know, and a classic example now is I don't know if you're aware that there's a a football tournament going on. You might have heard that. It's been it's been in the news. And instantly, I'm thinking, I bet there's a spike in phishing. I bet there's a spike in scamming.

[00:34:18] - [Speaker 1]
I bet there's a spike in the way that the cybersecurity, especially the cybercriminal threat actors are now using that as a leverage to start to socially engineer people. And I think I've saw a report yesterday, in fact, that there were over 17,000 new sites, fictitious sites that have been created to do with the World Cup that are getting people to come in as watering hole attacks and getting people to be socially engineered to start looking at cheap tickets and flights, and also apps as well. So mobile apps that are are are being downloaded and things like that. And all of this is just, you know, a building block. And it shows the creativity, I suppose, really of the way that cyber threat actors will see something that's newsworthy, and they will then start to run with it.

[00:35:03] - [Speaker 1]
And generally, it's to our detriment also. You know, and a lot of times, there are also ambulance chases as well. You know, if there's there's something in the news that people are worried about their health, for example, they will soon set up sites and then soon soon start spamming people fishing for information by using something that's current affairs. And I you know, and also, of course, we have to understand the direct link between the geopolitical situation that we find ourselves in, which is ever changing. So the Ukrainian conflict, The Middle East, the way that the, Dara said, the The United States kind of wax and wanes really on on the different policies and things that come across here as well.

[00:35:42] - [Speaker 1]
All of that, it sends out worrying signals across the cyber side of things as well. And it's true that that's also, though, reflected in the types of attacks, and I suppose, really the different risk assessments that a lot of organizations will put into place. So you have to stay current with that as well. So so stay focused, and I suppose really stay curious on that as well, but also create keep that creativity in place as well. And that really should ignite a lot of younger people as well who are kind of thinking, you know, is this is this the career for me?

[00:36:13] - [Speaker 1]
And hopefully, you know, the answer is, yeah. You know, you you there are definitely skills that you can bring into a good cybersecurity team.

[00:36:21] - [Speaker 0]
So much gold in your answer there because I think we're we're at a time at the moment where AI is hitting all our news feeds for removing traditional roles and removing entry level roles, but there are so many opportunities for a career in cybersecurity, which isn't just one role. As I said earlier, it's up to 50 different roles there. So for anyone listening wanting to create their own pathway to maybe prepare for a career change while, in their current role or maybe younger listeners just planning their career from scratch, looking for advice on how they can get interested in AI, cloud computing, security, data analytics, project process management. The list is endless. Or even just IT fundamentals if they're nontechies.

[00:37:04] - [Speaker 0]
Where can they find out more information on anything we talked about today?

[00:37:08] - [Speaker 1]
So, obviously, as a trading provider, we cover all of that and beyond, in fact. So we look at all the technical side of things as well and and project management as well that you've alluded to as well. AI skills obviously coming to the floor as well. So we are Firebrand Training. So you can find us at firebrand training u k.

[00:37:26] - [Speaker 1]
Take a look at and, again, it's a good idea just to take a look at the huge list, I suppose, really, of available courses there as well. But probably before you do that, just take a look at job sites. Go and do a quick search. Again, you can use AI for that to bring bring out, you know, what are the kind of the core certification tracks or the different kind of training courses that employers are looking for, and then start to build those foundations in place. And again, of course, you can always reach out directly to us as well.

[00:37:59] - [Speaker 1]
You can find me on LinkedIn as well, and I'm more than happy to speak to people about, you know, their training pathways and give them guidance on the certification tracks. I don't know all of them, of course, because, you know, I'm only one person here, but I have a team of people that look after the curriculum for me as well. And I always like to give good advice and guidance. You know, there's properly foundation advice and guidance, I suppose, really. Because, you know, I I came from the military side of things, so I transitioned into the world of tech and IT outside of the military as well.

[00:38:30] - [Speaker 1]
And I relied on, you know, the the the good guidance, I suppose, really in the opportunities that I was lucky enough to get from people like Microsoft and some of the trainers, in fact, that I worked with in my early career development outside of the military as well. And what I you know, it's a bit of payback, I suppose, really from Phil into into the cyber community because I'm passionate about it. I'm also kind of passionate about getting the right people. You know? And so when I meet people at conferences and things like that, it's always nice to have a bunch of friends rather than people say, well, actually, I would buff advice that you gave me.

[00:39:01] - [Speaker 1]
And, of course, as a training, you know, it's it's it's my neck on the line, I suppose, really as well. You know? So the the credibility has got to be there as well. So there's plenty of courses that you can find on our website. But also from a from a junior point of view, if you're new into it as well, take a look at the cybersecurity apprenticeships and also the new AI apprenticeships as well that have recently been launched as well because these are amazing, and they're great opportunities for anybody who needs to take a look at that.

[00:39:31] - [Speaker 1]
There's a lot of depth and detail that you can see on the Skills England side, and indeed, of course, Firebrand offered these as well. The beautiful thing about the way that we do it is that we also then add vendor certifications into those tracks as well, which means something to, especially to employers, at the end of your apprenticeship as well. So it kind of builds up your credentials as you actually go through the apprenticeship track as well. So lots of great advice and guidance to be found there.

[00:39:57] - [Speaker 0]
Well, I cannot thank you enough for talking about this in a language everyone can understand today about the growing need for practical threat spotting capabilities across every industry, highlighting the biggest skill gaps that you're seeing across organizations today, and most importantly of all, the opportunities available to anybody listening to this conversation of any age. If you are feeling uncertain about your career or the future and what role you want to do, I would encourage you. This is your call to action. Please go check out the information. I'll include links, to everything that you've just mentioned there in the show notes.

[00:40:32] - [Speaker 0]
Please go check that out, and I will be inviting you back on the podcast to drill a little bit deeper into any topic that you would like, whether that be the metal detector models, MineLab CTX thirty thirty versus the MineLab Safari. Leave it up to you, but we'll look forward to getting you back on. We just thank you so much for joining me today.

[00:40:50] - [Speaker 1]
My pleasure. Thanks, Neil. Thanks for having me.

[00:40:53] - [Speaker 0]
As regular listeners know of this podcast, I always say technology works best when it brings people together. And what I loved about chatting with Phil today was he always brought everything back to people. Yeah. We talked about AI, threat intelligence, quantum computing, phishing, social engineering, and technical training. But the thread running through all of this was human judgment, curiosity, awareness, and the ability to spot patterns before they become problems.

[00:41:21] - [Speaker 0]
And Phil made a very powerful point today that cybersecurity is far wider than many people think. It does include engineers, analysts, responders, risk specialists, trainers, investigators, governance professionals, management, and people with transferable skills from roles that that you might have initially thought were unrelated at first glance. I really want to encourage anyone listening who is worried about the future of work because, yes, AI is changing many roles, but cybersecurity continues to offer very real opportunities for people who can think clearly, communicate well, and stay curious. And to begin with, just learn the foundations before chasing the flashier job titles. And I I also thoroughly support Phil's reminder there that current affairs always have a cyber angle.

[00:42:10] - [Speaker 0]
Whether it be the World Cup, a health scare, a political crisis, or new technology trend, they all quickly become fuel for scams and attacks. If you have that kind of curiosity and awareness, this is something that every business school and individual are looking for. So if this episode made you think differently about cybersecurity careers or your own transferable skills, I wanna hear from you. Could cyber be a future career for you, your team, or someone in your family? Please pass them on this episode.

[00:42:40] - [Speaker 0]
You can reach me at tech talks network dot com. I will be keeping in touch with Phil, and I will be inviting him back on the show. So if there's anything that you would like me to drill down a little bit deeper on, again, let me know. Leave me a voice message at tech talks network. But that is it.

[00:42:56] - [Speaker 0]
Class is over for today. I'll be back again tomorrow with another guest, but thanks for listening, and I'll speak with you again tomorrow. Bye for now.