We start with a number: 94% — the share of UK business leaders who say they’re confident they could detect and respond to a cyber attack. Then we add the counterpunch: 47% require two‑factor authentication, 31% report board‑level ownership of cyber, and just 5% hold Cyber Essentials. That mismatch is the spark for a story about confidence, evidence, and what really happens when theory meets a real incident.
In this episode two hosts trade barbed banter and hard questions, peeling back the myths that make organisations feel safe. Confidence, they argue, isn’t a security control. Saying “we’d cope with ransomware” is not the same as proving you’ve tested a restore at two in the morning. The narrative pivots on a single, simple demand: prove it.
We follow two small business case studies that bring the stakes into sharp relief. One firm clings to shared identities, ancient laptops and convenient workarounds; the other quietly accepts practical change — rolling out managed devices, conditional access and enforced MFA. Both started imperfect. One accepted reality and fixed it. The other negotiated around controls until accountability evaporated.
Along the way the episode lands hard facts: the National Cyber Security Centre handles an average of four nationally significant incidents each week, and high‑profile victims are not immune. The hosts use these data points not to terrify but to sharpen the question every board should ask: where does our confidence come from, and can we show it?
‘Compliance’ is rescued from the textbook. It becomes three things: policy (the decision you’ve made), control (the technical enforcement) and evidence (the logs, tests and restores that prove it actually works). The show dismantles compliance theatre — beautifully formatted fiction where every box is green — and replaces it with operational tests that matter.
Listeners get practical storytelling: imagine being audited six months from now and asked who accessed a client file. In one business the audit trail names individuals and shows MFA enforced. In the other, five people all log in as the same ‘Fred.’ Accountability disappears, and with it the ability to respond credibly to an incident.
There are no magic words or silver bullets: Cyber Essentials isn’t a forcefield, but it forces an organisation to answer specific questions at a point in time. The episode argues passionately that certification matters less as a guarantee and more as a discipline — a prompt to prove the controls you claim to have.
Before you turn off the show, the hosts hand you an unpretentious to‑do list: name the person who owns cyber risk, enforce strong authentication everywhere it matters, actually restore backups, reduce admin counts, and store emergency contacts where they can be reached if your cloud goes dark. Small steps, repeatedly tested, win far more than one‑off paperwork.
By the end the narrative comes full circle: confidence without demonstrable controls is denial in a suit. The episode leaves listeners both chastened and empowered — convinced that good security can be practical and affordable, but only if leaders stop saying they’re secure and start showing it.