Why more controls do not automatically produce more resilience
A security control can be technically sound and still depend on decisions elsewhere in the organisation. Procurement applies supplier requirements. Employees work under incentives and pressure. Crisis leaders allocate authority with incomplete information. Boards decide which risks receive investment.
That interaction runs through the programme for the Richmond Cyber Security Forum, scheduled for 24 September 2026 at the Four Seasons Hotel London at Park Lane. The sessions put a practical question in front of CISOs: what conditions allow technical controls to work when people across the business have to make decisions?
Security crosses business boundaries
The programme approaches that question through supply chains, employee behaviour, crisis response, secure-by-design, AI, professional standards and executive communication.
Stuart Frost, Head of Enterprise Security and Risk Management at the UK Government, will examine accountability across vendor ecosystems, including behaviours within procurement, operations and security teams.
Janette Bonar Law, Information Security Operations Manager at Channel 4, will examine why employees bypass security policies and how workplace incentives, stress and organisational structures shape cyber-related decisions.
Barbara Aung, Chief Information Security Officer at Virgin Media O2, will examine secure-by-design: making security requirements part of software, services and technology from the design stage onward. Her session will consider how this approach can stay aligned with business objectives. Aung brings more than 25 years of IT-security experience spanning incident response, security operations, architecture and information security management.
Other sessions widen the focus. Charles White, Chief Executive Officer at The Cyber Scheme, will examine threat actor motivations, organisational exposure and why security projects can fail to deliver intended outcomes. Simon Hepburn, Visiting Professor at Aston University, will consider certification, professional standards, ethics and governance, including how CISOs can strengthen board confidence. Tamlynn Deacon, Founder of Empower Authentic Coaching, will address executive communication and presenting technical risks in business terms. Annabel Berry, Founder and Director of Leading Cyber, will examine psychological safety, pressure, boundaries and working practices.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Third-party security requires choices about assurance and continuity
Supplier security gives CISOs a clear allocation problem. Frost’s session asks how companies can target assurance work across different suppliers while maintaining continuous business delivery.
His framing connects supplier assurance with work across procurement, operations and security. Different functions can hold different responsibilities in a vendor relationship. For an executive team, that raises concrete questions: which suppliers require which assurance, who owns each decision, and how should security requirements be handled alongside continuity needs?
These are governance choices around technical controls. The supplier standard defines requirements; the operating model determines who applies them and who acts when a supplier falls short.
Resilience depends on decision rights when conditions deteriorate
Lynda Petherick, Chief Operating Officer and Chief Information Officer at New Look, and soon to be Chief Executive Officer, and Joe Kelly, Head of Information Security at New Look, will examine Gold and Silver Teams, responsibilities, response runbooks and third-party preparedness.
Petherick chairs New Look’s Gold Team, which would direct the retailer’s response during a significant business crisis. Kelly is responsible for its cyber security maturity and resilience programmes.
This structure shows why decision rights matter during an incident. A runbook can define a response process, but leaders still need to know who can set priorities, commit resources and coordinate third parties when information is incomplete and time is limited.
Technical response remains central. Clear authority gives the people receiving technical information a defined route for making and executing decisions.
AI makes evidence of effectiveness a governance requirement
Grant Ongers, Security-Advisor, Ambassador and Architect, will ask participants to evaluate AI deployment through measures including risk reduction, incident response times and control effectiveness. His discussion will also consider criteria for moving projects from pilots into enterprise deployment.
These measures give executives concrete criteria for an investment decision. Leaders can define the evidence required for broader deployment and the conditions that would stop or reset a project. This creates an explicit test for whether a pilot should progress.
Identity also appears in Ongers’ approach to production deployment. His position is that access controls for systems and users are part of the decision about how an AI system moves into production.
Executive communication is part of security governance
The boundary between technical evidence and business decisions also appears in executive communication. Deacon’s session addresses presenting technical risks in business terms, while Hepburn’s considers how CISOs can strengthen board confidence.
The closing panel, moderated by Ant Davis, Host of The Awareness Angle, will bring together Deborah Saffer, Director Information Security at Liberty Specialty Markets, Lee Howard, Chief Information Security Officer at Evri, and Kelly. It will revisit resilience, supply-chain risk, AI adoption and changes in the CISO role.
For a CISO, communication has an operational purpose. Boards and executive teams allocate investment, accept risk and set priorities. Technical evidence must reach those decision-makers in a form they can use.
Key takeaways for leaders
- Security crosses business boundaries: Leaders should treat cyber resilience as an organisation-wide responsibility. Technical controls depend on procurement decisions, employee incentives, governance structures and executive communication.
- Third-party security requires assurance and continuity choices: Define which suppliers need deeper assurance, who owns each decision and how security requirements balance with business continuity. Clear accountability helps turn supplier standards into consistent action.
- Resilience depends on clear decision rights: Crisis teams need defined authority to set priorities, commit resources and coordinate third parties under pressure. Runbooks are most effective when leaders also know who can make and execute decisions.
- AI requires evidence of effectiveness: Set measurable criteria such as risk reduction, incident response times and control effectiveness before moving AI from pilot to enterprise deployment. Access controls for systems and users should also form part of production decisions.
- Executive communication supports security governance: Present technical risks in terms boards and executives can use to allocate investment, set priorities and accept risk. Clear communication connects security evidence with business decisions.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


