Risk + Safety + Security + Sciences
Applied risk sciences for the people who carry the decisions.
Tony Ridley (MSc CSyP CAS FSyl SRMCP) translates 30+ years of executive risk, security, and resilience leadership into a working podcast for novices and professionals across every environment. Drawing on operations in 40+ countries, Commonwealth critical infrastructure programmes, Australian Defence Force service, and doctoral research in transnational security, each episode turns the canon into something usable on Monday morning.
Coverage
- Critical infrastructure, SOCI, and CIRMP
- Travel risk and ISO 31030
- Audit, governance, and assurance
- Risk science and applied methodology
Companion podcast to the Risk + Safety + Security + Sciences LinkedIn newsletter (19,500+ subscribers).
tonyridley.com · linkedin.com/in/tonyridley
Listen on:
Episodes

Jul 2, 2026
Jul 2, 2026
22 min
This episode examines my July 2026 board paper, Critical Mass, and the converging warnings from six independent Australian and international bodies in June 2026 that exposed systemic failures protecting the nation’s critical infrastructure.
We break down how siloed compliance, poor board technical literacy, AI-accelerated cyber threats, and hidden supply-chain risks leave power, telecoms, finance and other sectors vulnerable — and outline Ridley’s intelligence-led governance fixes (real-time threat intelligence, SBOM/AIBOM, cross-sector mapping) and the legal consequences for directors now on notice.

Jul 1, 2026
Jul 1, 2026
20 min
This episode unpacks a Federal Government guidance sheet to show how large organisations translate a qualitative risk appetite into measurable risk tolerances, limits, triggers and capacity so they can make decisions without freezing or taking reckless chances.
Using clear analogies and examples—like driving lanes and project timelines—it explains KRIs, escalation states, and a four-step process for embedding risk rules that balance safety, innovation and accountability.

Jul 1, 2026
Jul 1, 2026
20 min
This episode breaks down APRA’s June 17, 2026 letter demanding banks, insurers and superannuation funds prepare for fast-moving geopolitical shocks — from sanctions and capital trapping to AI-driven cyberattacks, disinformation and insider risks.It explains why traditional risk models fail, what regulators now require (crisis exercises, board accountability and stress testing) and what it means for consumers’ access to savings and the stability of daily financial services.

Jun 30, 2026
Jun 30, 2026
15 min
This episode demystifies how professionals map and manage uncertainty using the ISO 31000/31010 risk framework. From structured identification techniques like Delphi and Ishikawa to heavy-duty analysis with Monte Carlo simulations and bow-tie analysis, the hosts walk through the three core phases—identify, analyze, evaluate—and how to treat and report risks.Listeners learn that risk management is a continuous, documented cycle involving communication, monitoring, and decision tools like ALARP and cost–benefit analysis, and are left with the provocative idea that risk itself is a human construct shaped by how we choose to measure it.

Jun 28, 2026
Jun 28, 2026
22 min
This episode unpacks a travel risk analysis of multi-variant threat vectors, arguing that infectious diseases must be treated as a primary security threat. Using live 2026 data — the fast-growing Bundibugyo Ebola outbreak, vaccine-preventable disease resurgences in Australia, and active zoonotic threats — the discussion exposes flaws in traditional travel-risk models and introduces a six-dimension pandemic-potential scoring framework.
Listeners learn operational and legal implications for organisations: why granular, activity-based risk assessment, real-time monitoring of transit corridors, and targeted vaccination actions are now essential to meet duty-of-care obligations and to stay ahead of rapidly evolving pathogens.

Jun 28, 2026
Jun 28, 2026
22 min
In this episode, we unpack an example June 2026 board paper, The Half‑Life of Facts, and explain how knowledge decays over time and creates hidden risks for organisations. You’ll learn the science behind fact decay, why mesofacts are especially dangerous, and how citation error propagation and siloed evidence hide emerging threats.
We cover fast‑moving domains like cyber and adversary intelligence (with half‑lives of months), the legal and regulatory exposure under the SOCI Act and Australian tort law, and the operational danger of single‑loop compliance. The episode ends with practical guidance: map knowledge half‑lives, adopt a revalidation protocol using a knowledge currency matrix, and demand live adversarial intelligence rather than archived reports.

Jun 26, 2026
Jun 26, 2026
22 min
This episode decodes ASIO Director‑General Mike Burgess’s 2026 Threat Assessment and a Critical Infrastructure Security Advisory, outlining a security landscape described as dynamic, diverse, and degraded.Key revelations include nation‑state cyber pre‑positioning of critical infrastructure using living‑off‑the‑land techniques, blurred lines between foreign statecraft and local crime, supply‑chain hardware risks, rapid online radicalization of minors, and targeted coercion of diaspora communities.Implications for listeners and organisations: move to phishing‑resistant MFA, enforce strict IT/OT segregation, recognise regulatory and board‑level accountability for real‑world security effectiveness, and adopt community‑wide approaches to reduce social polarisation.

Jun 25, 2026
Jun 25, 2026
23 min
This episode breaks down the OWASP Threat and Safeguard Matrix (TASM) and shows how organisations map real-world threats to the NIST functions: identify, protect, detect, respond, and recover.Using vivid examples—deepfake CEOs tanking stock prices, loyalty-point raids, supply-chain Trojans, and risky AI behaviours—the show explains how metrics, executive alignment, and layered safeguards protect a company’s revenue and reputation, and warns about the next challenge: autonomous, self-modifying AI threats.

Jun 24, 2026
Jun 24, 2026
23 min
This episode unpacks a June 2026 board paper I wrote, arguing that remote and hybrid work should be treated like business travel for risk and duty-of-care purposes. It explains how existing frameworks (such as ISO 3103 and Australian laws) apply to at-home workers, explores psychosocial harms such as digital presenteeism and workplace violence, and warns about legal and managerial risks posed by surveillance and blanket return-to-office mandates.
Listeners will learn a practical timeline for organisations to adopt location-agnostic risk management, govern monitoring, implement right-to-disconnect policies, and rebuild distributed management to reduce legal exposure and burnout.

Jun 23, 2026
Jun 23, 2026
21 min
On June 22, 2026, the five leading cyberintelligence agencies issued an urgent joint warning that frontier A.I. has compressed the window for catastrophic cyberattacks from years to months, making breaches effectively inevitable unless organisations act now.
The statement prescribes immediate actions — reduce attack surface, accelerate patching, replace legacy systems, enforce zero-trust access, and prepare incident response — and calls for AI-driven defences and whole-of-organisation collaboration to build cyber resilience.
