Risk + Safety + Security + Sciences

Applied risk sciences for the people who carry the decisions.

Tony Ridley (MSc CSyP CAS FSyl SRMCP) translates 30+ years of executive risk, security, and resilience leadership into a working podcast for novices and professionals across every environment. Drawing on operations in 40+ countries, Commonwealth critical infrastructure programmes, Australian Defence Force service, and doctoral research in transnational security, each episode turns the canon into something usable on Monday morning.

Coverage

  • Critical infrastructure, SOCI, and CIRMP
  • Travel risk and ISO 31030
  • Audit, governance, and assurance
  • Risk science and applied methodology

Companion podcast to the Risk + Safety + Security + Sciences LinkedIn newsletter (19,500+ subscribers).

tonyridley.com · linkedin.com/in/tonyridley

Listen on:

Episodes

Jul 27, 2026

24 min

These executive travel risk briefings for late July 2026 provide a comprehensive global security synthesis across the EMEA, APAC, and Americas regions.
We track four confirmed forecast hits, including the scale of Mediterranean wildfires and the trajectory of an Ebola outbreak in the Democratic Republic of the Congo.
High-priority alerts focus on a fragile pause in the Gulf-Levant conflict, which is complicated by a newly emerged bidirectional front between Saudi Arabia and Houthi forces.
In the Americas, we highlight a constitutional standoff in Colombia and a significant escalation of internal armed conflict in Ecuador.
The briefings also implement rigorous governance corrections, specifically updating stale reporting on airport closures in Venezuela and the fallen status of El Fasher in Sudan.
Ultimately, the sources serve as a decision-support framework to ensure corporate duty of care and operational safety in high-risk jurisdictions.

Jul 27, 2026

24 min

Jul 26, 2026

16 min

This discussion illustrates a maturity timeline that tracks how an organisation’s approach to risk appetite evolves over time.
It categorises growth into five distinct stages, ranging from a basic risk-naive posture to a highly sophisticated risk-enabled state. 
As companies progress, they transition from utilising uncoordinated, ad hoc controls to implementing a fully embedded process characterised by continuous improvement. 
Key milestones in this journey include securing senior management commitment, establishing a unified governance framework, and maintaining regular communication across the entity.
Ultimately, the chart serves as a visual guide for achieving enterprise risk management through increasing levels of structural integration and strategic oversight.

Jul 26, 2026

16 min

Jul 26, 2026

19 min

This discussion examines a global structural crisis in air traffic management, identifying a dangerous convergence of staffing shortages, obsolete infrastructure, and weak cybersecurity.
Research indicates that the United States' national airspace is operating beyond its intended safety margins, a condition mirrored internationally by chronic vacancies in India and modernisation delays in Australia. In Europe, industrial action and low productivity in France disproportionately disrupt regional reliability, while geopolitical tensions in Asia further constrain civil flight paths.
Systematic failures, such as mid-air collisions and radar outages, are framed as predictable outcomes of long-term underinvestment rather than isolated accidents.
Consequently, we urge travel managers to move beyond generic safety ratings and perform facility-specific risk mapping to protect international itineraries. This synthesis concludes that the aviation industry's "structural fatigue" is a universal phenomenon requiring urgent organisational oversight and contingency planning.

Jul 26, 2026

19 min

Jul 24, 2026

23 min

Here, we unpack a recent Board Paper I wrote that identifies modern vehicle telematics as a significant, unmanaged security risk to Australia’s critical infrastructure. I argue that modern cars, whether personal, hired, or fleet-owned, serve as connected sensor platforms that capture sensitive audio, location, and phone data.
Despite warnings from intelligence officials and active investigations by privacy regulators, current legislative frameworks like the SOCI Act and CPS 230 fail to specifically address the vehicle as a converged attack surface. Therefore, I contend that integrating mobile devices with vehicles creates vulnerabilities that could allow attackers to bypass traditional perimeters and target critical personnel.
Consequently, my paper urges corporate boards to adopt new governance protocols, such as geofencing and strict device discipline, to mitigate these emerging threats. The findings emphasise that ignoring this rolling attack surface is no longer a defensible stance for those responsible for national resilience.

Jul 24, 2026

23 min

Jul 24, 2026

21 min

The Director’s Handbook on Cyber-Risk Oversight serves as a vital manual for corporate boards to navigate the modern digital threat landscape. Jointly produced by the National Association of Corporate Directors (NACD) and the Internet Security Alliance (ISA), this fifth edition argues that cybersecurity has evolved from a niche IT concern into a fundamental strategic risk and fiduciary duty.
 
The interview outlines six core principles to help directors integrate cyber resilience into their broader business objectives while meeting new legal and disclosure requirements. It features a comprehensive toolkit addressing emerging challenges such as artificial intelligence, ransomware, and supply chain vulnerabilities.
 
By fostering a proactive governance model, the handbook encourages leadership to treat security as a competitive advantage rather than a mere compliance checkbox. Ultimately, it emphasises that board-level engagement is essential for maintaining organisational stability and protecting shareholder value in an increasingly volatile global economy.

Jul 24, 2026

21 min

Jul 23, 2026

21 min

Managing security risk involves navigating double intangibles, where neither the identity of the adversary nor the effectiveness of defences can be fully seen or measured. Because threats are often invisible and a lack of incidents does not guarantee future safety, many organisations view security as an unnecessary expense, leading to underfunding and the use of unqualified personnel.
 
This perspective creates security decay, as decision-makers mistakenly substitute general management tasks for specialised protection. Unlike safety, where hazards are often observable, security relies on understanding the unpredictable human intent of hidden actors.
 
Professional expertise is necessary to navigate these uncertainties, as the eventual cost of a breach far exceeds the initial investment in robust preventative measures. Failing to prioritise these invisible risks leads to security theatre, in which visible actions create a false sense of protection without addressing actual vulnerabilities.

Jul 23, 2026

21 min

Jul 21, 2026

20 min

In the mid-1990s, the global financial architecture was shaken by a series of high-profile "shocks" that defied the era's sophisticated market models. The collapse of Barings Bank in 1995—precipitated by Nicholas Leeson’s unauthorised "rogue" trading—alongside scandals at Daiwa and Sumitomo, exposed a profound vulnerability. These weren't failures of credit quality or market volatility; they were failures of people, oversight, and internal systems. They were "ghosts" in the machine that the existing 1988 Basel Accord, with its rigid and non-risk-sensitive capital ratios, was never designed to capture.
 
In the wake of these disasters, regulators faced an existential crisis: how to categorise and capitalise the unquantifiable. The result was not a discovery, but a strategic invention. "Operational risk" was synthesised to transform messy, administrative failures into a formal regulatory discipline. It allowed the Basel Committee to project a visionary map of control over the internal, "micromanagerial" world of global banks.

Jul 21, 2026

20 min

Jul 21, 2026

16 min

In this episode, my example Board Paper exposes how modern risk management mistakes data for safety. The hosts unpack the differences among assessment, evaluation, and management, warn against single-number risk metrics and the Hydra Effect of excessive detection, and offer practical tools such as the Drift Register to prevent "attestation theatre." They explain four ancient strategies for managing catastrophic risk and why public dread and correlated cyber threats demand accountable human judgment beyond dashboards.

Jul 21, 2026

16 min

Jul 20, 2026

20 min

This episode unpacks a leaked Global Executive Travel Risk Briefing that reveals major failures: analysts reused outdated data for weeks, missing a catastrophic earthquake in Caracas and a rapidly spreading Ebola outbreak, while correctly forecasting a Middle East escalation.
It explains how dashboard complacency, false sourcing, and poor verification undermined credibility and why continuous live checks and an audited methodology matter for any decision-maker relying on intelligence.

Jul 20, 2026

20 min

Jul 19, 2026

20 min

The episode breaks down the UK Government's 2026 National Risk Register, explaining how modern national security depends on society-wide resilience. It covers new risks like digital resilience failures, cyberattacks on critical services, prison system bottlenecks, and evolving terrorism tactics and outlines practical steps individuals can take to reduce vulnerability.

Jul 19, 2026

20 min

Copyright 2026 All rights reserved.

Podcast Powered By Podbean

Version: 20241125