The Cyber Brief

The Cyber Brief is a podcast for decision-makers in cyber. Through candid conversations with the industry's best, The Cyber Brief delivers executive-level insights on cyber risk, best-practice governance and emerging threats. Join host Valeska Bloch, Head of Cyber at Allens, as she asks industry leaders to share practical insights, real-world stories and actionable advice for boards, executives and cyber professionals.

Episodes

Aug 12, 2026

36 min

Insider incidents have steadily increased in recent years, but there's one threat that's causing particular concern: North Korean operatives posing as remote IT workers, quietly embedded inside legitimate organisations. In this episode, Valeska and co-host Sonia Millen are joined by Ryan LaSalle, CEO of Nisos, a US-based human risk intelligence firm specialising in insider threats, employment fraud and executive digital risk. Ryan shares the extraordinary story of how Nisos uncovered and infiltrated a North Korean remote IT worker fraud operation after a suspected operative applied for a role at the company, ultimately exposing a network of more than 20 workers employed across multiple US organisations. Ryan explains how these operations work, the warning signs organisations should look for throughout the hiring and employment lifecycle, and why remote work has created new opportunities for nation-state actors and organised crime groups.
Resources from this episode:
Defending from within: a guide to insider threat management
Advisory note – DPRK information technology workers, 31 July 2026.
Joint statement on DPRK IT workers | Australian Government Department of Foreign Affairs and Trade, 31 July 2026.
Cyber risks of DPRK IT Workers, 6 November 2025.
Exposing DPRK Employment Fraud Operations and People, Process, Personas: Nisos Exposes the Human Risk in DPRK Employment Fraud Schemes
Ryan's book recommendations: This is How They Tell Me the World Ends by Nicole Perlroth, Snow Crash by Neal Stephenson and Cryptonomicon by Neal Stephenson.

Aug 12, 2026

36 min

Jul 2, 2026

38 min

Within just a few years, quantum computers could render today's encryption obsolete, exposing sensitive data and disrupting critical systems. In this episode, Valeska and co-host David Rountree are joined by Dr Vikram Sharma, Founder and CEO of QuintessenceLabs, to unpack what these advances mean for cyber risk management. Vikram explains why post-quantum transition timeframes are accelerating, what boards and executives should be doing to prepare, and why the transition will be more complex than a simple technology upgrade. Valeska, David and Vikram also discuss 'harvest now, decrypt later' attacks, why post-quantum readiness is—at its core—a governance issue, and the need to build crypto agility into future systems.
Resources from this episode:
Preparing for the post-quantum era of security
Stay ahead of the quantum threat with post-quantum cryptography | Cyber.gov.au
Guidelines for cryptography | Cyber.gov.au
Vikram's author recommendation: Yuval Harari
Vikram's TED talk: How quantum physics can make encryption stronger

Jul 2, 2026

38 min

Jun 17, 2026

50 min

As AI drives an escalation in cyber threats, ASIC is sharpening its focus on how organisations manage cyber risk. Valeska and co-host Kate Austin are joined by ASIC Commissioner Simone Constant, author of an open letter issued by ASIC calling for urgent cyber uplift across industry. Simone shares what’s driving the regulator’s heightened concern, what 'reasonable' and 'proportionate' cyber measures look like in practice, and ASIC’s expectations for meaningful board engagement. She also reflects on proposed changes to continuous disclosure and discusses the challenges facing multinational organisations with offshore cyber functions. If you’re navigating cyber risk in an AI-driven environment, this episode offers practical insights for boards and management alike.
Resources from this episode:
Board and management briefing: preparing for Mythos-class threats
ASIC's open letter to AFS licensees and market participants
Simone's series recommendation: Peaky Blinders

Jun 17, 2026

50 min

May 11, 2026

15 min

In part two of our conversation, former Prime Minister Malcolm Turnbull joins Valeska and Dominic to discuss the state of Australia's cyber startup landscape, the role of private capital and the policy settings needed to support high-growth cyber businesses. Is Australia doing enough to support its cybersecurity startup ecosystem? How can we translate innovation into genuine sovereign capability? What will it take to keep Australia's best talent and most promising companies onshore?
Resources from this episode:
Part one of our conversation with Malcolm Turnbull
Allens Accelerate, our legal practice dedicated to supporting the Australian startup and emerging companies community.

May 11, 2026

15 min

Apr 20, 2026

35 min

Former Prime Minister Malcolm Turnbull joins Valeska and co-host Dominic Anderson for the first of a two-part discussion about cybersecurity as national security in Australia. As the 29th Prime Minister of Australia, a former lawyer, technologist, and now backer of some of the most interesting cyber companies worldwide, Malcolm brings a perspective on cybersecurity shaped by experience on every side of the problem. In this episode, Malcolm shares his views on Australia's cyber strategy, offensive cyber capabilities, escalation risk in cyber conflict, the future of Five Eyes cooperation, and whether Australia can build a genuinely sovereign cyber capability.
Resources from this episode:
National security at Allens 

Apr 20, 2026

35 min

Apr 1, 2026

41 min

Bank-grade cybersecurity is considered the gold standard of cyber best practice, but what does it look like in reality, and what can other organisations learn from it? Valeska and co-host Isabelle Guyot are joined by Martijn Verbree, Chief Information Risk Officer at The Commonwealth Bank. Martijn shares his approach to balancing innovation with security, staying ahead of the curve in a constantly evolving threat environment, and managing cyber risk at Australia's largest bank. He also shares practical insights on working with boards, the importance of multi-layered security testing, and the risks and opportunities posed by AI. If you've ever wondered what's keeping our protectors up at night, this conversation is for you.
Resources from this episode:
Martijn's podcast recommendation: Risky Business

Apr 1, 2026

41 min

Mar 4, 2026

37 min

Valeska and co-host David Rountree speak with Lieutenant General Michelle McGuinness CSC, Australia's National Cyber Security Coordinator and leader of the National Office of Cyber Security (NOCS). Michelle dives in regarding the role of NOCS, and how it approaches government coordination and consequence management during major incidents. When and how should organisations engage with government during an incident? What's best practice for incident communications? How does NOCS work with industry, regulators and other government agencies? How are organisations engaging with Australia's limited use and ransomware payment reporting regimes? Michelle also shares her approach to leadership, the importance of empathy when working with organisations under pressure, and how her military background has shaped her leadership approach.
Resources from this episode:
For more on the limited use and ransomware payment reporting regimes, see New cyber incident response obligations for Australian organisations.
National Office of Cyber Security resources, including the Australian Cyber Response Plan and 12 sector playbooks
Cyber Health Check Tool | Cyber.gov.au
Homepage | Cyber.gov.au—to report cybercrimes and security incidents
Michelle's podcast recommendation: Risky Business

Mar 4, 2026

37 min

Nov 26, 2025

31 min

Valeska and co-host Chris Kerrigan are joined by Meredith Griffanti, Senior Managing Director in Strategic Communications and Global Head of Cybersecurity & Data Privacy Communications at FTI Consulting in New York. Meredith shares practical advice on how to communicate in the midst of a cyber incident, from managing the first moments after an attack to crafting an apology, choosing a spokesperson and dealing with multiple stakeholders. Meredith, Valeska and Chris discuss the importance of preparedness and coordination, as well as how legal and communications teams should work together during a crisis.
Resources from today's episode:
Cyberwashing and backtracking: why words matter both before and after cyber incidents | LinkedIn
Cyberwashing: a key focus for data breach class actions
Meredith's book recommendation: The Ransomware Hunting Team: A Band of Misfits’ Improbable Crusade to Save the World from Cybercrime by Renee Dudley and Daniel Golden
Learn more about Meredith: Biography
Learn more about Meredith’s team: FTI Consulting Cybersecurity & Data Privacy Communications
Learn more about FTI Consulting: A global expert firm helping organizations navigate crisis and transformation

Nov 26, 2025

31 min

Nov 12, 2025

32 min

Valeska and co-host Chris Kerrigan are joined by Ryan Macfarlane, the Unit Chief of Counter Terrorism, Advanced Projects Unit at the FBI, where he worked for more than 20 years.
In one of his final interviews before announcing his retirement from the FBI, Ryan shares his insights on emerging cybersecurity threats, the maturation of cyber criminals' business models, the increasing use of AI to conduct and defend against cyber attacks, the rise of collaboration among threat actors, the complex dynamics of nation-state attacks, and the growing risk of physical violence spilling over from cyber incidents.
Ryan, Valeska and Chris also reflect on the importance of proactive relationships between the private sector and law enforcement, the value of timely intelligence sharing, and practical actions for incident response planning.
 Resources from today's episode:
National security at AllensWhy everyone is talking about AI safety and cybersecurityRyan's podcast recommendation: Darknet DiariesRyan's book recommendations: The 100-Year Marathon by Michael Pillsbury, Destined for War: Can America and China Escape Thucydides's

Nov 12, 2025

32 min

Oct 28, 2025

39 min

Though often overlooked, the psychological toll of cyber incidents in the workplace is significant. Research has placed the average level of burnout experienced by cyber professionals in line with or above that of frontline healthcare workers in the aftermath of COVID-19. Valeska and co-host Sikeli Ratu speak with Peter Coroneos, the founder of Cybermindz and a pioneer in applying military-grade trauma recovery protocols to cybersecurity. Peter shares his real-world experience and insights on the psychological impacts of cyber incidents, the dangers of blame culture, and the importance of investing in strategies that build resilience and mitigate psychosocial risk.
Resources from today's episode:
Why organisations must embed mental health and wellbeing support into cyber incident response planning
AICD's guide for directors on governing through a cyber crisis
Allens' cyber resources and contacts
Cybermindz website
Cybermindz research
Peter's show recommendation, Mr Robot
For mental health support, call Lifeline Australia on 13 11 14
 

Oct 28, 2025

39 min

Copyright 2025 All rights reserved.

Podcast Powered By Podbean

Version: 20241125