Risk + Safety + Security + Sciences

Applied risk sciences for the people who carry the decisions.

Tony Ridley (MSc CSyP CAS FSyl SRMCP) translates 30+ years of executive risk, security, and resilience leadership into a working podcast for novices and professionals across every environment. Drawing on operations in 40+ countries, Commonwealth critical infrastructure programmes, Australian Defence Force service, and doctoral research in transnational security, each episode turns the canon into something usable on Monday morning.

Coverage

  • Critical infrastructure, SOCI, and CIRMP
  • Travel risk and ISO 31030
  • Audit, governance, and assurance
  • Risk science and applied methodology

Companion podcast to the Risk + Safety + Security + Sciences LinkedIn newsletter (19,500+ subscribers).

tonyridley.com · linkedin.com/in/tonyridley

Listen on:

Episodes

Aug 18, 2026

20 min

This episode unpacks leaked global security briefings showing that official travel advisories, airport feeds, and corporate dashboards routinely miss real-world hazards. From unupdated government warnings and flooded transit routes to visa, health, and insurance traps that strand travellers and choke global trade, the hosts reveal how political lag, infrastructure blind spots, and bureaucratic rules create hidden risks and legal headaches for organisations and individuals.

Aug 18, 2026

20 min

Aug 16, 2026

12 min

This episode unpacks why traditional "defence in depth" is often an illusion, showing how flat networks, single sign-on, and pass-through mechanisms create direct access paths attackers exploit.
Hosts explore the limits of MFA and Zero Trust, the risks of physical and virtual tailgating, and why risk models based on layered failures can dangerously underestimate real vulnerability.

Aug 16, 2026

12 min

Aug 14, 2026

14 min

This episode traces how the idea of risk developed—from 12th-century merchants who turned chance into a tradable concept, to 18th-century actuaries who smoothed human lives into statistics, and to contemporary governments and technologies that manage uncertainty.
Along the way, it explains the hazard + outrage framework, shows how public fear can outpace actual danger (Chernobyl, cell towers, BSE), and ends with a warning about our algorithm-driven belief that the future is fully controllable and how that could make us vulnerable to true black swan events.

Aug 14, 2026

14 min

Aug 12, 2026

11 min

This episode unpacks how the Navy systematises risk using a deliberate 5-step process and a time-critical ABCD mnemonic, balancing severity and probability to maximise mission success rather than eliminate all danger.
We also examine human judgment limits, the Columbia disaster as a cautionary example, and practical takeaways for applying these frameworks to everyday decisions—tracking your "red zone" moments, using checklists, and debriefing to improve outcomes.

Aug 12, 2026

11 min

Aug 12, 2026

21 min

Risk & Security expert Tony Ridley dismantles the modern, catch‑all definition of “risk,” showing how a vague, standardised term collapses distinct ideas—hazards, threats, perils, and probabilities—into a single confusing bucket. He traces the word’s history, explains different types of uncertainty, and exposes how one-size-fits-all standards like ISO 31000 can mislead organisations and waste resources.
The episode urges precise language and practical fixes: separate hazards from probabilities, clarify intent versus capability, and always ask whether someone means a hazard, a threat, an insurance peril, or a statistical risk before making decisions.

Aug 12, 2026

21 min

Aug 11, 2026

22 min

This episode breaks down my analysis of how public and private security differ: public forces are taxpayer-funded, offender-oriented and regulated, while private security is profit-driven, selective and less regulated.
We examine the risks when those lines blur—governments outsourcing safety, hidden motives, impacts on communities and enterprises, and the need for transparency and rigorous auditing of security controls.

Aug 11, 2026

22 min

Aug 10, 2026

19 min

This episode unveils confidential global intelligence briefings for week 33 of August 2026, revealing a paradox: analytical predictions (Brier score) have never been more accurate even as hotspots like Iran, Ukraine, and Gaza escalate to highest-risk status.We break down how forecasters use strict timelines, qualitative context, and a global synthesis to turn raw data into actionable resilience plans, with case studies from intercepted attacks in Colombia to Typhoon Dolphin and compounding crises across regions.

Aug 10, 2026

19 min

Aug 9, 2026

22 min

This episode unpacks the 2026 OWASP Top 10 for LLM Applications, showing why large language models are inherently gullible and how attackers exploit that weakness with prompt injection, multimodal steganography, supply-chain poisoning, and token-exhaustion attacks.
It explains practical defences—Rule of Two, architectural authorisation, provenance auditing, token-aware cost controls, and continuous red-teaming—and highlights the real-world risks organisations must design against when deploying AI systems.

Aug 9, 2026

22 min

Aug 9, 2026

20 min

This episode explores a UK Resilience Academy paper on using military-style wargaming to build resilience in civilian and corporate organisations. It contrasts ineffective tabletop exercises with dynamic, consequence-based games like Matrix games and MegaGames that force teams to confront realistic resource limits, cascading effects, and high-pressure decisions.
Listeners learn practical formats, a four-step adoption path, and why deliberately breaking plans in safe environments helps organisations identify vulnerabilities and improve decision-making under stress.

Aug 9, 2026

20 min

Aug 8, 2026

24 min

This episode unpacks NIST's 2026 draft on AI data centre security, explaining how modern AI facilities differ from traditional servers, the specialised hardware and networking they use, and the unique risks they face— from prompt-based attacks and poisoned supply chains to silent data corruption in overheated silicon.
It also covers defences like zero-trust architectures, confidential computing, dynamic replay for fault tolerance, and human-in-the-loop governance, and examines the tension between open models and the need for locked-down security.

Aug 8, 2026

24 min

Copyright 2026 All rights reserved.

Podcast Powered By Podbean

Version: 20241125