Risk + Safety + Security + Sciences

Applied risk sciences for the people who carry the decisions.

Tony Ridley (MSc CSyP CAS FSyl SRMCP) translates 30+ years of executive risk, security, and resilience leadership into a working podcast for novices and professionals across every environment. Drawing on operations in 40+ countries, Commonwealth critical infrastructure programmes, Australian Defence Force service, and doctoral research in transnational security, each episode turns the canon into something usable on Monday morning.

Coverage

  • Critical infrastructure, SOCI, and CIRMP
  • Travel risk and ISO 31030
  • Audit, governance, and assurance
  • Risk science and applied methodology

Companion podcast to the Risk + Safety + Security + Sciences LinkedIn newsletter (19,500+ subscribers).

tonyridley.com · linkedin.com/in/tonyridley

Listen on:

Episodes

Jul 2, 2026

22 min

This episode examines my July 2026 board paper, Critical Mass, and the converging warnings from six independent Australian and international bodies in June 2026 that exposed systemic failures protecting the nation’s critical infrastructure.
We break down how siloed compliance, poor board technical literacy, AI-accelerated cyber threats, and hidden supply-chain risks leave power, telecoms, finance and other sectors vulnerable — and outline Ridley’s intelligence-led governance fixes (real-time threat intelligence, SBOM/AIBOM, cross-sector mapping) and the legal consequences for directors now on notice.

Jul 2, 2026

22 min

Jul 1, 2026

20 min

This episode unpacks a Federal Government guidance sheet to show how large organisations translate a qualitative risk appetite into measurable risk tolerances, limits, triggers and capacity so they can make decisions without freezing or taking reckless chances.
Using clear analogies and examples—like driving lanes and project timelines—it explains KRIs, escalation states, and a four-step process for embedding risk rules that balance safety, innovation and accountability.

Jul 1, 2026

20 min

Jul 1, 2026

20 min

This episode breaks down APRA’s June 17, 2026 letter demanding banks, insurers and superannuation funds prepare for fast-moving geopolitical shocks — from sanctions and capital trapping to AI-driven cyberattacks, disinformation and insider risks.It explains why traditional risk models fail, what regulators now require (crisis exercises, board accountability and stress testing) and what it means for consumers’ access to savings and the stability of daily financial services.

Jul 1, 2026

20 min

Jun 30, 2026

15 min

This episode demystifies how professionals map and manage uncertainty using the ISO 31000/31010 risk framework. From structured identification techniques like Delphi and Ishikawa to heavy-duty analysis with Monte Carlo simulations and bow-tie analysis, the hosts walk through the three core phases—identify, analyze, evaluate—and how to treat and report risks.Listeners learn that risk management is a continuous, documented cycle involving communication, monitoring, and decision tools like ALARP and cost–benefit analysis, and are left with the provocative idea that risk itself is a human construct shaped by how we choose to measure it.

Jun 30, 2026

15 min

Jun 28, 2026

22 min

This episode unpacks a travel risk analysis of multi-variant threat vectors, arguing that infectious diseases must be treated as a primary security threat. Using live 2026 data — the fast-growing Bundibugyo Ebola outbreak, vaccine-preventable disease resurgences in Australia, and active zoonotic threats — the discussion exposes flaws in traditional travel-risk models and introduces a six-dimension pandemic-potential scoring framework.
Listeners learn operational and legal implications for organisations: why granular, activity-based risk assessment, real-time monitoring of transit corridors, and targeted vaccination actions are now essential to meet duty-of-care obligations and to stay ahead of rapidly evolving pathogens.

Jun 28, 2026

22 min

Jun 28, 2026

22 min

In this episode, we unpack an example June 2026 board paper, The Half‑Life of Facts, and explain how knowledge decays over time and creates hidden risks for organisations. You’ll learn the science behind fact decay, why mesofacts are especially dangerous, and how citation error propagation and siloed evidence hide emerging threats.
We cover fast‑moving domains like cyber and adversary intelligence (with half‑lives of months), the legal and regulatory exposure under the SOCI Act and Australian tort law, and the operational danger of single‑loop compliance. The episode ends with practical guidance: map knowledge half‑lives, adopt a revalidation protocol using a knowledge currency matrix, and demand live adversarial intelligence rather than archived reports.

Jun 28, 2026

22 min

Jun 26, 2026

22 min

This episode decodes ASIO Director‑General Mike Burgess’s 2026 Threat Assessment and a Critical Infrastructure Security Advisory, outlining a security landscape described as dynamic, diverse, and degraded.Key revelations include nation‑state cyber pre‑positioning of critical infrastructure using living‑off‑the‑land techniques, blurred lines between foreign statecraft and local crime, supply‑chain hardware risks, rapid online radicalization of minors, and targeted coercion of diaspora communities.Implications for listeners and organisations: move to phishing‑resistant MFA, enforce strict IT/OT segregation, recognise regulatory and board‑level accountability for real‑world security effectiveness, and adopt community‑wide approaches to reduce social polarisation.

Jun 26, 2026

22 min

Jun 25, 2026

23 min

This episode breaks down the OWASP Threat and Safeguard Matrix (TASM) and shows how organisations map real-world threats to the NIST functions: identify, protect, detect, respond, and recover.Using vivid examples—deepfake CEOs tanking stock prices, loyalty-point raids, supply-chain Trojans, and risky AI behaviours—the show explains how metrics, executive alignment, and layered safeguards protect a company’s revenue and reputation, and warns about the next challenge: autonomous, self-modifying AI threats.

Jun 25, 2026

23 min

Jun 24, 2026

23 min

This episode unpacks a June 2026 board paper I wrote, arguing that remote and hybrid work should be treated like business travel for risk and duty-of-care purposes. It explains how existing frameworks (such as ISO 3103 and Australian laws) apply to at-home workers, explores psychosocial harms such as digital presenteeism and workplace violence, and warns about legal and managerial risks posed by surveillance and blanket return-to-office mandates.
Listeners will learn a practical timeline for organisations to adopt location-agnostic risk management, govern monitoring, implement right-to-disconnect policies, and rebuild distributed management to reduce legal exposure and burnout.

Jun 24, 2026

23 min

Jun 23, 2026

21 min

On June 22, 2026, the five leading cyberintelligence agencies issued an urgent joint warning that frontier A.I. has compressed the window for catastrophic cyberattacks from years to months, making breaches effectively inevitable unless organisations act now.
The statement prescribes immediate actions — reduce attack surface, accelerate patching, replace legacy systems, enforce zero-trust access, and prepare incident response — and calls for AI-driven defences and whole-of-organisation collaboration to build cyber resilience.

Jun 23, 2026

21 min

Copyright 2026 All rights reserved.

Podcast Powered By Podbean

Version: 20241125