About

I got into this because panic makes people worse at security, not better

I spent years in rooms where a security briefing was really a fear briefing: worst-case scenarios, unfamiliar acronyms, a slide of a hooded figure at a keyboard. It worked, in the sense that people left scared. It did not work in the sense that mattered — almost nobody left knowing what to actually do differently on Monday.

So I started explaining things differently: what a threat actually is, what it actually costs, and which two or three changes genuinely move the risk. Rooms started asking better questions. Boards started making faster, clearer decisions. Four books later, I still open every talk the same way — with the plain version of the threat, not the scary one.

I am not here to sell fear, and I try never to leave a room more anxious than I found it. What I offer is more useful: a clear read on what actually matters, plain language for it, and a practice that holds up under load.

Black-and-white portrait of Sam Whitlock looking straight at the camera against a black background
Background
  • Works across security, IT and board-level cyber risk (fictional)
  • Independent speaker and author
  • Speaks on request to technology and board audiences
Career details fictional
Milestones
Early days

Watched good, smart teams freeze in front of a dashboard full of red alerts. Started explaining instead of alarming.

First book

Human Firewall — the case for training people, not just buying the next tool.

On stage

First keynote. A calm explanation turned out to land better in a boardroom than a slide full of skulls.

Two more books

The Quiet Breach and Boards Don’t Click Links — the same argument, said two more ways for two more audiences.

Now

Zero Trust, Full Speed and a full slate of keynotes for teams who want the calm version.

Scroll to Top