SRMBOK Security Risk Management

Julian Talbot

The SRMBOK Security & Risk Management podcast explores security risk management, cybersecurity, geopolitical risk, resilience, crisis management, and emerging threats, with practical insights, tools, and analysis for security and risk professionals.

Episodes

  1. Sep 1

    SRMBOK Newsletter 63 - The Great Filter Is a Risk, Not a Prophecy | Global Security Risk Update

    The Fermi Paradox asks a simple question: in a universe this old and this big, where is everybody? One answer is the Great Filter - something that stops most species before they get off their home planet. Is it behind us, or still ahead? I don't know. Nobody does. But this week's issue argues it isn't a prophecy. It's a risk. And risk is the one thing we're actually trained to do something about. This is SRMBOK Newsletter Edition 63 for the first week of September 2026 - the whole issue, walked through on camera. The week in one breath: US-Iran escalation at Hormuz is the acute risk (escalate, or time-bound?); Ukraine is working to degrade the whole Russian system behind deep strikes while Russia lines up another energy campaign before winter; North Korea's second ballistic missile in under a week; and forty-seven people killed in two days in Haiti - a security vacuum hardening into organized territorial violence. The headlines: a national emergency over foreign-made power grid equipment that reaches into firmware and remote access; root-level backdoors in routers shipped by the million; 284 million records lost because somebody rang the help desk and sounded convincing; two Western Australians charged over the TeamPCP supply-chain attacks that touched more than a thousand organisations; Boston Scientific unable to ship stents for weeks; the ATF breach that landed on investigators' targets; the Finnish ruling on the Eagle S anchor-dragging; M23's hybrid battlefield in eastern Congo; and Russian espionage that skips malware entirely. The thread: OpenAI's disclosure that nearly 700 agents spawned by an internal model escaped a research environment and attacked Hugging Face, built their own message board, and re-established communications when it was torn down - because they were incentivised to finish impossible tasks by any means. Plus the malicious skill-file research, and the counterweight from Unit 42: AI is not changing who can write malware, and the controls you already own are still catching it. The treatments, nearly all free: the NIST AI Risk Management Framework, the OWASP GenAI LLM Top 10 2026, the new SBOM minimum elements, Thorium (CISA and Sandia's open-source malware and forensics platform), the UK Cyber Assessment Framework, the ENISA Threat Landscape, the ASD's Essential Eight becoming the Essentials series, the ASIS Foundation's Security Culture report, Heuer's Psychology of Intelligence Analysis, and Simon Whistler on being a Pegasus target. In the library: four tiers, from free essentials to an organizational licence. Use the code LIBRARY150 before the end of October and the complete library stays at that price for the life of your subscription. Eight new items this week including the SRMBOK Guide to Risk-Based Supplier Assurance, plus the free Risk Bow-Tie Method course. My new book, Control Effectiveness Assessment, is out - a deep dive into a thin wedge of risk assessment: not whether the controls are there, but whether they work and whether you have the evidence to rely on them. And the Graduate Certificate in Risk Management starts in Canberra this November; mention the newsletter when you sign up and I'll hand you signed copies of Control Effectiveness Assessment and the Traffic Light Protocol book on day one. www.srmbok.com

  2. Aug 22

    SRMBOK Newsletter 61: Funding Security Against 2027 Global Threats

    What does a security guard standing beside an aircraft at 3 AM have to do with cyber risk, geopolitics and the security threats of 2027? Quite a lot, as it turns out. In the first episode of the SRMBOK Podcast, we unpack Edition 61 of the Security Risk Management Body of Knowledge Newsletter and connect the dots between global instability, cyber threats, critical infrastructure and the practical challenge facing every security leader: how do you turn an increasingly complex threat environment into a business case that actually gets funded? In this 24-minute briefing, we explore: The emerging multipolar security environment — and how geopolitical realignment, conflict, strategic resources and supply-chain dependencies are reshaping organisational risk.The convergence of cyber and physical security — from aircraft systems and industrial controllers to water infrastructure and commercial refrigeration.The shift from “breaking in” to “logging in” — stolen credentials, identity failures, exposed API keys and the growing security implications of autonomous AI agents.Why traditional vulnerability management is struggling — as exploitation accelerates and operational technology remains exposed through surprisingly basic weaknesses.Building the business case for security — using real incidents, threat intelligence and evidence to translate technical vulnerabilities into consequences that executives and boards understand.Practical resources you can use now — including the SRMBOK Bow-Tie Field Kit, CISA Known Exploited Vulnerabilities Catalog, NIST SP 800-82 Rev. 3 and NIST CSF 2.0 resources.The episode finishes with a bigger question for risk and security leaders: In our pursuit of efficiency, lean operations and just-in-time supply chains, have we engineered out our ability to absorb the next systemic shock? Based on Edition 61 of the SRMBOK Newsletter, published 19 August 2026. Subscribe to the SRMBOK Newsletter and explore the free tools, templates and resources at SRMBOK.com. #SRMBOK #SecurityRiskManagement #Cybersecurity #RiskManagement #CriticalInfrastructure #OTSecurity #Geopolitics #ThreatIntelligence #NISTCSF #BusinessResilience

About

The SRMBOK Security & Risk Management podcast explores security risk management, cybersecurity, geopolitical risk, resilience, crisis management, and emerging threats, with practical insights, tools, and analysis for security and risk professionals.