Risk + Safety + Security + Sciences

Applied risk sciences for the people who carry the decisions.

Tony Ridley (MSc CSyP CAS FSyl SRMCP) translates 30+ years of executive risk, security, and resilience leadership into a working podcast for novices and professionals across every environment. Drawing on operations in 40+ countries, Commonwealth critical infrastructure programmes, Australian Defence Force service, and doctoral research in transnational security, each episode turns the canon into something usable on Monday morning.

Coverage

  • Critical infrastructure, SOCI, and CIRMP
  • Travel risk and ISO 31030
  • Audit, governance, and assurance
  • Risk science and applied methodology

Companion podcast to the Risk + Safety + Security + Sciences LinkedIn newsletter (19,500+ subscribers).

tonyridley.com · linkedin.com/in/tonyridley

Listen on:

Episodes

Aug 30, 2026

26 min


In less than twenty months, the Model Context Protocol (MCP) has emerged as the de facto standard integration layer connecting AI agents to sensitive corporate systems, databases, and applications. Yet, this rapid, often shadow adoption has quietly constructed an "unverified supply chain mesh" that operates entirely beneath the traditional security perimeter. In this deep-dive interactive interview, we dissect why conventional network-perimeter firewalls are completely blind to these agentic exposures. Because large language models process instructions and data as identical linguistic tokens, a firewall cannot distinguish a malicious prompt injection from a benign user query inside legitimate, encrypted API calls. We unpack the structural mechanism of the "lethal trifecta"—where private corporate data is dangerously bridged to untrusted external content and outgoing communication channels—and explore why corporate officers and boards are legally on the hook.
What You’ll Learn in This Episode:
The Firewall Blind Spot: Why inspecting traffic at the network boundary is an inert control against natural-language-based protocol exploits.
The "Lethal Trifecta" of Agentic AI: How individually benign permissions compose into hazardous "toxic agent flows" that leak data and execute unauthorised operating system commands.
Documented Exploits in the Wild: A rundown of real-world compromises spanning April 2025 to February 2026, including CVE-2025-6514 remote code execution, credential-stealing server clones, and cross-tenant data exposures.
The Legal Duty of "Constructive Knowledge": Why these public security breaches mean boards and executive officers can no longer hide behind "paper compliance" under frameworks like CPS 230/234, work health and safety due diligence, and critical infrastructure supply chain hazard rules.
A New Governance Paradigm: Practical, non-discretionary steps to regain control, including least-privilege tool grants, provenance vetting, architectural segregation, and comprehensive audit logging of every single tool call.
Featured Reference: This episode is based on the groundbreaking board position paper, "The Unverified Mesh: Governing the Model Context Protocol Supply Chain," by Tony Ridley MSc CSyP FSyI SRMCP.

Aug 30, 2026

26 min

Aug 29, 2026

21 min

The discussion argues that organisations adopting artificial intelligence are prioritising productivity metrics while dangerously neglecting their validation capacity, or the human ability to detect and correct machine errors. 
Tony contends that over-reliance on automated systems leads to automation bias and a critical deskilling of the workforce, which eventually erodes the organization's defensive oversight.
Current governance models often mistake high output for capability, failing to recognise that removing human "friction" also removes the primary mechanism for error detection.
To mitigate these risks, we prescribe a validation-first framework in which accountability is tied to named individuals and transparent decision trails, rather than solely to technological efficiency.
 
Ultimately, the paper warns that boards face increasing legal and regulatory obligations to demonstrate meaningful human supervision over AI-assisted outputs.

Aug 29, 2026

21 min

Aug 27, 2026

24 min

In this episode, I argue that risk-informed decision-making is a superior alternative to traditional risk-based methods, which I critique as dangerously static and overconfident. While the latter assumes that initial assessments are flawless and final, the risk-informed approach treats data as evolving and provisional.
This methodology utilises an iterative process similar to scientific inquiry to account for changing variables and new evidence.
Such a strategy is particularly vital in security risk management, where human threats are active, intelligent, and constantly looking for ways to bypass existing safeguards.
Ultimately, the approach encourages professionals to prioritise real-world effectiveness by integrating continuous intelligence and situational awareness into their decision-making frameworks.

Aug 27, 2026

24 min

Aug 25, 2026

21 min

This episode examines how official travel advisories and infrastructure dashboards can lag or misrepresent real-world hazards, leading to dangerous decisions for travellers and corporations.
Using recent intelligence briefings, the hosts show how political, logistical, and technical factors distort ‘green’ signals and warn about the risks of automating travel approvals without human judgment.

Aug 25, 2026

21 min

Aug 25, 2026

12 min

This episode dismantles the common reliance on maturity scales in corporate security, arguing they create a false sense of safety against active human adversaries. Drawing on Tony Ridley’s research, it contrasts administrative reporting with real-world threat dynamics, emphasising victimology, repeat attacks, and the binary nature of being secure or insecure.
Listeners are urged to replace vague ‘maturity’ language with specific questions about readiness against identified threats and to demand evidence-based assessments rather than comforting charts.

Aug 25, 2026

12 min

Aug 23, 2026

21 min

This episode explains "resilience debt": the unseen accumulation of vulnerabilities across digital systems, physical infrastructure, and human preparedness that compounds over time.
It traces the problem to two decades of centralisation and efficiency-first decisions, shows how the pandemic accelerated risk by widening attack surfaces, and highlights how connectors like APIs act as critical weak points.
The hosts examine leadership blind spots and the limits of compliance, then outline practical solutions: enterprise security risk management (ESRM), continuous Plan-Do-Check-Act cycles, and a balance of active and passive resilience to "bounce forward" rather than just recover.

Aug 23, 2026

21 min

Aug 23, 2026

21 min

This episode unpacks the complex world of risk management through Tony Ridley’s 2023 document and his performative interrogation of an AI, revealing how algorithms and neat models can mask real danger.We explore why mathematical tools like risk matrices and Monte Carlo simulations fail when fed bad assumptions, how cognitive biases and risk homeostasis distort human judgment, and how institutional frameworks can collapse under pressure.The episode concludes with a call for proactivity: maintain situational awareness, question automated outputs, and balance quantitative models with social and cultural context to better navigate uncertainty.

Aug 23, 2026

21 min

Aug 21, 2026

19 min

This episode examines Tony Ridley’s "Risk Perspectives" framework through the Brent Spar case, showing how technically correct risk assessments can collapse when social perception and politics intervene.It explains how different disciplines use distinct base units and methods—actuarial, toxicological, probabilistic, psychological, and cultural—why they clash, and why integrated approaches like social amplification are needed to manage risk in a networked world.

Aug 21, 2026

19 min

Aug 20, 2026

23 min

In this episode, we dismantle the myth of bumbling cybercriminals and explore a framework for professional adversaries. Learn how modern threats are creative, resourceful and highly adaptive—using asymmetrical, secretive, and deceptive tactics to achieve long-term, cascading impacts.
We discuss how global disruptions such as pandemics and conflicts create opportunities for such actors, and why enterprise security must shift from blunt instruments to dynamic, intelligence-driven risk management.

Aug 20, 2026

23 min

Aug 19, 2026

18 min

This episode dives into my approach to risk assessments for critical infrastructure, explaining why static threat lists fail and how resilience requires mapping the full sequence of events from threat to societal impact.
It covers fragility curves, cascading failures and deadlocks, human factors and adaptive adversaries, and the need to combine simple inventories with advanced probabilistic models like Bayesian relationship networks.

Aug 19, 2026

18 min

Copyright 2026 All rights reserved.

Podcast Powered By Podbean

Version: 20241125