Michael Walford-Williams on Ethical Hacking of Human Controls

Michael Walford-Williams on Ethical Hacking of Human Controls

How can we assess the level of human risk we’re running in a control framework? Unlike technology, humans aren’t always reliable and how they behave under pressure may well be different to how they behave in normal situations.

My guest on this episode, Michael Walford-Willaims is a risk professional who specialises in how to plan for when things go wrong, covering areas like business continuity, operational resilience and crisis management.

Michael helps companies by testing out the human components of control frameworks to see where there might be weaknesses. He goes into organisations and tries to ethically hack them by trying to circumvent controls with human elements — that might be trying to get a fraudulent invoice paid or simply tailgating employees to see if he can get physical access to buildings.

His work serves two purposes:

Firstly it identifies potential weaknesses in controls. If he can get a fake invoice paid, then so can a fraudster. If he can get access to buildings, then so can thieves. By seeing how easy it is to bypass controls, organisations can get a better handle on their risk profile. Until you’ve actually tested the human controls, it’s impossible to know how weak or strong they actually are.

Secondly, it serves as a training exercise. Just like a fire evacuation drill, it’s better to have employees learn what to do or not do, by experiencing a simulation, than letting them learn from real-life situations.


This is human risk management in action. Of course there are ethical components to the work that Michael does — how far is it appropriate to test out your employees and what do you if you discover they are the weakest link in your security chain?

As Michael explains, we have to also think about what impact the exercise will have on those involved in it. If you think you’ve been tricked by your employer, that you’re somehow not trusted, or that your employer is prepared to deceive you and therefore the organisation is unethical, the exercise could actually make things worse. So the expertise Michael brings isn’t just about testing the proverbial fences. It’s planning exercises that don’t cross ethical lines and then using the information gleaned from them, sensitively and intelligently.

About Michael
Michael has worked for over 15 years in various aspects of risk management and compliance with a specialism in Business Continuity and Crisis Management and more recently third party risk management. He has worked in a number of countries globally having been based in London, Singapore and New York. Working in house and for the last 7 years as a consultant, Michael has worked across many industries for some of the largest organisations in the world including some of the worlds largest banks. and through his work in the field of crisis management has worked on a number of major incidents including the Japanese Tsunami and Fukushima incident, terror attacks in Mumbai, Boston and Moscow and numerous natural disasters, and technology & infrastructure failure related incidents. In 2014 Michael worked to set up one of the UK's first CrowdFunding platforms and as head of Operations and Compliance oversaw the first successful direct FCA authorisation of a platform for both Debt and Equity-based crowdfunding. Michael continues to work as a consultant as has just set up a new brand "Westbourne" to pull together a number of offerings in the risk management space.

You can contact him via LinkedIn: https://www.linkedin.com/in/michael-walford-williams-2302a78a/

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(368)

Ella Jenkins & Pete Dyson on Why Do Cyclists Run Red Lights?

Ella Jenkins & Pete Dyson on Why Do Cyclists Run Red Lights?

Why do cyclists in London run red lights? It's against the law, and yet, if you've cycled, driven or just observed London's cyclists, you'll know that many of them don't stop when there's a red light....

31 Aug 202554min

Dr Nuno Reis on Rare Dots

Dr Nuno Reis on Rare Dots

What if the ideas that linger in the back of your mind — the ones you can’t quite explain — are the ones you most need to pay attention to?Episode SummaryIn this episode, I explore that question with ...

24 Aug 20251h 7min

Professor Christian van Nieuwberg on Radical Listening

Professor Christian van Nieuwberg on Radical Listening

Is listening a hidden superpower we’ve overlooked?  You've heard of Active Listening, but what is Radical Listening and why does it matter?Episode SummaryOn this episode, I’m joined by Professor Chris...

17 Aug 20251h 9min

Dr Sunita Sah on Defiance - how to speak up when it matters

Dr Sunita Sah on Defiance - how to speak up when it matters

Why do we follow orders or go along with things that feel wrong? Why might defiance be better than compliance? And how can we go about becoming more defiant?Episode SummaryI’ve always been fascinated ...

9 Aug 20251h 2min

Dr Libby Maman on Measuring and (Re-)building Trust

Dr Libby Maman on Measuring and (Re-)building Trust

What happens when citizens lose faith in the institutions that serve them? And how can we rebuild that trust?Episode SummaryOn this episode, I'm speaking to someone who cares passionately about this s...

2 Aug 20251h

Iain Morrison on When The Show Mustn't Go On

Iain Morrison on When The Show Mustn't Go On

We’ve all heard the phrase ‘the show must go on’.  But when shouldn’t the show go on?  To help me answer that, I’m speaking to someone who has spent 35 years managing some of Australia’s most iconic l...

26 Juli 20251h 5min

Zsike Peter on Thinkbait

Zsike Peter on Thinkbait

What if the real risk of AI isn’t job loss but brain atrophy?Episode SummaryIf you've spent any time on social media recently, you'll be familiar with the flood of low-quality AI-generated sludge. And...

19 Juli 20251h 9min

Dr Kiran Bhatti & Professor Thomas Roulet on Wellbeing Intelligence

Dr Kiran Bhatti & Professor Thomas Roulet on Wellbeing Intelligence

What if we treated mental health like a capability instead of a crisis? On this episode, I'm talking to a business school professor and a counselling psychologist about their new book that looks at pr...

12 Juli 20251h 2min

Populärt inom Vetenskap

allt-du-velat-veta
p3-dystopia
dumma-manniskor
rss-ufobortom-rimligt-tvivel
ufo-sverige
kapitalet-en-podd-om-ekonomi
svd-nyhetsartiklar
hacka-livet
rss-spraket
paranormalt-med-caroline-giertz
ufo-sverige-2
medicinvetarna
rss-vetenskapsradion
dumforklarat
sexet
det-morka-psyket
rss-dennis-world
rss-vetenskapsradion-2
rss-tidsmaskinen
halsorevolutionen