Cult Products podcast artwork for Cyber is a business problem that needs a business partner

Cyber is a business problem that needs a business partner

Phill Keaney-BollandPhill Keaney-Bolland· Co-founder and Designer, Yaya2 min read

With Matthew Treagus, Fractional technology executive

Key takeaways

  • Risk-driven is often used as a reason to ignore risk rather than address it.
  • The CISO role is a business partnering function, not a policing one.
  • Secure by design removes cost and friction rather than adding it.
  • A 94 percent patching figure can conceal exactly the exposure that matters.
  • Moving from unconsciously incompetent to consciously incompetent is progress.

The 94 percent problem#

Matthew uses a patching statistic to make a point about how organizations misread their own data. A headline compliance figure in the nineties looks like control. It says nothing about whether the remaining percentage contains the systems the business could not run without.

This is the gap he keeps returning to. Organizations measure what is countable rather than what is critical, then mistake the count for an understanding of their exposure.

Business partner, not policeman#

The framing Matthew argues for is that the CISO is a business partnering role. Security that arrives as prohibition gets routed around. Security designed in alongside the business removes cost and friction rather than adding it, but that requires the security function to understand commercial priorities rather than only technical ones.

He brings real weight to this: former CIO and Chief of Staff at Oxford Biomedica, a partner in a management consultancy, and a contributor to the NCSC and DSIT Cyber Governance Code of Practice.

What is actually critical#

Asked what is critical to their business, organizations frequently name the wrong systems. Matthew describes the minimum viable corporation exercise as a way to find out properly, and is honest that it is uncomfortable, which is part of why it is rarely done.

AI makes information hygiene visible#

One consequence of deploying AI tools across an organization is that pre-existing information hygiene problems stop being theoretical. Permissions that were wrong but harmless become permissions that surface content to people who should not see it. Matthew also covers agentic AI, technical debt and supply chain thinking.

Phill Keaney-Bolland

Phill Keaney-Bolland

Co-founder and Designer, Yaya

Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.

Frequently asked questions