The podcast

Tales from The CyberLab

Security insights from the frontline - watch on YouTube or listen wherever you get your podcasts.

YouTubeSpotifyLinkedIn
Latest episode

New episodes monthly - subscribe on YouTube to never miss one.

Browse everything

Every episode and guide, in one place

Filter by what you want to do with it, the subject, or who it is pitched at.

Showing 29 of 29
Podcast episodeEpisode 26

Secure by Design Explained

What it actually means to build security into a product from the first commit rather than bolting it on before launch, and where teams most often let it slip.

Secure developmentDevelopers
With Sprintworks
Article

CyberLab Partners with CYFOR Secure for Expert Incident Response

What changes for customers now that incident response is handled by a dedicated forensics partner rather than in-house alone.

Threat landscapeBusiness leaders
Podcast episodeEpisode 25

Agentic AI in Cyber Security Explained

Agentic AI can now take actions rather than just answer questions. What that changes for defenders, and the new attack surface it opens up.

AI and emerging techThreat landscapeIT and security teams
With Sophos
Article

AI, Risk and Regulation: Three Conversations Cyber Leaders Need to Have in 2026

The three questions about AI that boards are starting to ask security leaders, and how to have answers ready before they do.

AI and emerging techCompliance and certificationBusiness leaders
Article

Why Cyber Security Testing Now Belongs in the Boardroom

Testing has moved from a technical exercise to a governance one. What that means for how results get reported and acted on.

Threat landscapeBusiness leaders
Podcast episodeEpisode 24

Digital Trust Explained

Certificates, keys and machine identity are invisible until one expires and takes a service down with it. How digital trust is managed at scale.

Identity and trustIT and security teams
With Keyfactor
Article

Cyber Security for CEOs: What Every Business Leader Needs to Know

The short version of what a chief executive actually needs to understand about cyber risk, without the acronyms.

Threat landscapeBusiness leaders
Article

CyberLab Named as CREST AI Charter Founding Signatory: What It Means

What the CREST AI Charter commits a security provider to, and why accreditation matters more as AI enters testing.

AI and emerging techCompliance and certificationBusiness leaders
Podcast episodeEpisode 23

Geopolitics and the Modern Cyber Threat Explained

Why state-aligned activity increasingly shapes the threat a normal business faces, and how to read geopolitical risk without overreacting to headlines.

Threat landscapeBusiness leaders
With Guardsix
Article

The Agentic SOC: Managed Detection and Response for the AI Era

What changes in a security operations centre when agents triage alongside analysts, and what still needs a human.

AI and emerging techThreat landscapeIT and security teams
Podcast episodeEpisode 22

Cyber Essentials: Common Cyber Threats Explained

The threats Cyber Essentials is designed to stop, explained by the body that runs the scheme - and why the basics still block the overwhelming majority of attacks.

Compliance and certificationThreat landscapeAnyone in a business
With IASME
Article

Cyber Essentials May 2026 Update: What Businesses Need to Do to Pass

The changes in the latest Cyber Essentials question set, and the ones most likely to catch out a business renewing.

Compliance and certificationAnyone in a business
Podcast episodeEpisode 21

Hacking Critical Infrastructure Explained

Water, power and transport run on technology that was never designed to face the internet. What attacking it looks like, and what defending it involves.

Critical infrastructureIT and security teams
With CyberLab
Article

Supply Chain Risk in 2026: The Hidden Threats Beyond Your Estate

Your suppliers' security is now part of yours. How to see risk you do not directly control, and what to ask for.

Threat landscapeBusiness leaders
Article

How Not To Hit The Headlines in 2026: What Recent Breaches Have Taught Us

A pattern runs through the year's biggest breaches, and most of it comes down to things a smaller business can actually fix.

Threat landscapeBusiness leaders
Article

Four Steps to Strengthen Cyber Security for the Age of Artificial Intelligence

Four practical changes that hold up as AI shifts both what attackers can do and what defenders can automate.

AI and emerging techBusiness leaders
Podcast episodeEpisode 20

Women in Cyber: International Women's Day Special

Routes into the industry, what the numbers actually look like, and the practical things that help more women build a career in security.

Careers and cultureAnyone in a business
With CyberLab
Article

Weak Passwords and Password Policies: Strengthening Access Security

Why password policy advice changed, what good looks like now, and how weak credentials still open most doors.

Identity and trustAnyone in a business
Podcast episodeEpisode 19

Protecting Innovation from Hackers Explained

Intellectual property is often a company's most valuable asset and its least protected one. How to keep research and designs out of the wrong hands.

Data protectionBusiness leaders
With Marks & Clerk
In the press
In the press

Introducing HackRisk

Technology Reseller covers the launch of HackRisk and where it fits for smaller businesses that have no dedicated security team.

Threat landscapeAnyone in a business
Technology Reseller
Podcast episodeEpisode 18

Data Loss Prevention Explained

Most data leaves an organisation through ordinary, well-intentioned behaviour. What DLP catches, what it misses, and how to roll it out without a revolt.

Data protectionIT and security teams
With Proofpoint
Podcast episodeEpisode 17

Best of 2025: 12 Cyber Lessons From This Year's Experts

The twelve things our guests said in 2025 that were worth writing down, pulled into one episode.

Threat landscapeAnyone in a business
With CyberLab
Podcast episodeEpisode 16

PCI DSS & Payment Compliance Explained

What PCI DSS asks of a business that takes card payments, which requirements cause the most trouble, and how to scope an assessment sensibly.

Compliance and certificationBusiness leaders
With CyberLab
Podcast episodeEpisode 15

The State of Ransomware in 2025 Explained

How ransomware crews operate now, what they charge, and which defences are actually deciding whether an attack succeeds.

Threat landscapeBusiness leaders
With Sophos
Podcast episodeEpisode 14

Life as an Ethical Hacker Explained

What a penetration tester does all day, how people get into the job, and what breaking into systems legally teaches you about defending them.

Careers and cultureAnyone in a business
With CyberLab
Podcast episodeEpisode 13

Adopting Microsoft Copilot Securely Explained

Copilot inherits whatever permissions your tenant already has. Why that surprises people, and what to fix before a rollout rather than after.

Cloud and productivityAI and emerging techIT and security teams
With Chess
Guide
Guide

UK Cyber Security Legislation Guide

Which laws and regulations actually apply to a UK business, what each one asks for, and the penalties for getting it wrong.

Compliance and certificationBusiness leaders
Reference guide
Guide
Guide

HackRisk vs the NCSC EASM Buyer's Guide

The NCSC's buyer's guide for external attack surface management tools, mapped honestly against what HackRisk does - and what it does not.

Threat landscapeIT and security teams
Reference guide
Guide
Guide

What is a HackRisk Score?

How your rating is calculated, what moves it, and how to read the A* to F grade that summarises your security posture.

Threat landscapeAnyone in a business
Reference guide