by

Lisa Ventura MBE FCIIS

A post came across my LinkedIn feed this week from a fellow practitioner and it stopped me mid scroll. Speaking at cyber security conferences is good. Seeing your peers is good. Learning from them is good. But we are our own echo chamber, and most of the talks given at cyber events belong in front of audiences who have never worked in security at all.

I have thought this for years and reading someone else say it plainly was a relief.

None Of Them Were In The Room

Picture a typical cyber security conference. Security engineers. CISOs. Analysts. Consultants. Vendors. Researchers. People who already know what phishing looks like, already use multi factor authentication, already lose sleep over ransomware.

Now picture who attackers actually beat. The finance manager who pays a fraudulent invoice. The HR coordinator who opens a CV with a malicious attachment. The warehouse supervisor who plugs in a USB stick found in the car park. The small business owner with no IT department and no budget for one. The board director who signs off security spend without understanding what she has bought.

None of them were in the room. Nobody invited them. Nobody thought of them.

So we keep presenting the evidence to people who need no persuading. We stand on stage, we show the slide with the breach costs, the room nods, everyone heads to the bar for drinks. No behaviour changes on Monday morning because nobody in the audience needed to change anything, they were already doing it anyway. Meanwhile the accountant about to wire 6 figures to a criminal has never heard a security talk in her working life.

Look at the agenda of the next event in your calendar. Count how many sessions are aimed at someone outside the profession. My guess is none, and the reason is structural. Cyber events are built to sell to cyber buyers. Sponsors want the security budget holder in the seat. Speaker slots follow the sponsorship. Nothing about that model is dishonest, but it does mean the audience is chosen by who pays, and the people criminals target are not paying.

This Was Never Only A Technology Problem

Criminals rarely attack the firewall first. They attack people, they attack process, they attack the gap between what a business assumes and what a business verifies. A fraudster who knows your invoice approval steps does not need a zero day. He needs a plausible email and a member of staff under time pressure.

The fix therefore sits with professions who would never call themselves technical. Accountants. Solicitors. Recruiters. Estate agents. Manufacturers. Farmers. Charity trustees. School governors. Hauliers. Care home managers. Every one of them holds data, moves money or runs systems criminals want. A conveyancing firm moves house deposits. A recruitment agency holds passport scans and bank details for hundreds of candidates. A haulage operator runs telematics and fuel cards across a fleet. A village primary school holds safeguarding records for every child on the roll. None of those organisations sees itself as a cyber target, and all of them are.

Cyber security hardly ever appears on the agenda at a logistics conference, a hospitality trade show, a chamber of commerce business breakfast or a county farming event. Those agendas exist. Those organisers spend months hunting for speakers with something their delegates have not heard before. Few of us have ever offered.

The Hard Audience Has The Most To Gain

We stay where we are comfortable because it is comfortable. The audience shares your vocabulary. Nobody stops you to ask what a payload is. You leave with your reputation intact and your peer group reassured.

A non cyber audience is harder work. You need to strip out the acronyms. You earn attention from people who came for something else entirely. You answer “why would a criminal bother with a business like mine” without patronising anyone. You handle the delegate who tells you his nephew does the IT and it has been fine so far. You risk a room deciding your subject is dull.

The difficulty is the point. A room of manufacturing directors holds more prospective clients than a room of your competitors, and none of them are pitching against you at the coffee stand. Explaining ransomware to a room of hauliers will make you better at explaining it to your own board, because jargon hides woolly thinking. Take the jargon away and you find out how well you understand your own subject.

There is a credibility argument too. Awareness campaigns fail when they arrive as a compliance exercise from head office. They work when someone who understands the sector stands in front of people and describes their week back to them. You cannot do that from a keynote stage in a conference centre full of analysts.

How To Build A Talk They Will Actually Book

Pick 1 industry you already know, ideally one where you have worked or hold clients, then rewrite the talk from scratch with every acronym and product name removed. Lead with their risk rather than your expertise, because a haulier cares about a stalled fleet and a missed delivery window, and a care home manager cares about resident records and a CQC inspection. Use examples from their world, because generic breach stories land badly with specialists who can spot a borrowed anecdote in seconds.

Approach the organisers yourself. Trade associations, chambers of commerce, regional business groups and professional institutes build their agendas months ahead, and most have never had a cyber security speaker come to them. Send three short paragraphs, one on the problem their members face, one on what delegates will walk away with, one on who you are. Waive the fee for the first one if the event is right and treat the reach as payment.

Finish with three actions a delegate takes the same week, in plain English. No frameworks, no maturity models, and three things they can do on Tuesday.

One Talk, 12 Months

If you speak at cyber security events, commit to 1 event in the next 12 months where nobody in the audience works in our field. Any of these will do:

  • A trade show for an industry you already understand
  • A professional institute for accountants, surveyors, solicitors or engineers
  • A chamber of commerce breakfast or regional business network
  • A school governors meeting or a multi academy trust training day
  • A county farming show or an agricultural society evening
  • A care sector conference or a charity trustees network

Then do three things. Book it before the end of this quarter, because a commitment without a date is a good intention. Write the talk for them rather than recycling the one you already own. Tell the rest of us how it went, so the next person follows you instead of guessing.

The threat grows every year. Attackers scale, share tooling and industrialise their operations, while we book the same halls and greet the same faces. Our message stops at the door of the conference centre. The people who need it are outside, running businesses, moving money and holding data, with no idea we have spent years talking about them.

Breaking the echo chamber costs each of us one talk to an audience that isn’t a cyber one.