Jess Figueras's Avatar

Jess Figueras

@jessfigueras

Cybersecurity, data, risk & governance, civil society. Co-founder @ Cyber Governance for Boards (CxB). Governor @ University of Westminster

344
Followers
1,024
Following
203
Posts
08.08.2023
Joined
Posts Following

Latest posts by Jess Figueras @jessfigueras

I tried to make this point in a (bad) undergraduate essay on Middlemarch in 1993 but my supervisor didn’t buy it. I feel seen!

31.01.2026 10:32 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Ed tech is profitable. It is also mostly useless Independent research identifies few learning gains

Blistering piece on ed tech in @economist.com.

β€˜Although ed-tech companies tout huge learning gains, independent research has made clear that technology rarely boosts learning in schoolsβ€”and often impairs it.’
economist.com/united-state...

24.01.2026 14:24 πŸ‘ 517 πŸ” 257 πŸ’¬ 13 πŸ“Œ 51
Two musical excerpts titled "Double Chorus of Persecutors and Persecuted" and "Chorus of the Self-Righteous". From Michael Tippett's oratorio "A Child of Our Time"

Two musical excerpts titled "Double Chorus of Persecutors and Persecuted" and "Chorus of the Self-Righteous". From Michael Tippett's oratorio "A Child of Our Time"

X | Bluesky

19.01.2026 10:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
β€œI wish it need not have happened in my time,” said Frodo.

β€œlmao" said Gandalf, β€œwell it has.”

β€œI wish it need not have happened in my time,” said Frodo. β€œlmao" said Gandalf, β€œwell it has.”

03.01.2026 10:07 πŸ‘ 1255 πŸ” 365 πŸ’¬ 1 πŸ“Œ 2

Great book.

13.12.2025 12:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
A poster advertising Christmas food, showing a plate of fuschia-coloured balls. One has been cut in half and appears to contain unidentified brightly-coloured matter. The poster text reads β€œThat’s what makes it Christmas”

A poster advertising Christmas food, showing a plate of fuschia-coloured balls. One has been cut in half and appears to contain unidentified brightly-coloured matter. The poster text reads β€œThat’s what makes it Christmas”

1. What are these objects?
2. Are they supposed to be edible?
3. What exactly makes them Christmassy?

So many questions

02.12.2025 12:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Easily the most thoughtful take on AI in education I’ve read

08.11.2025 11:33 πŸ‘ 5 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Encountered quite a convincing scam tonight.

Nice Geordie lady called, apparently from my credit card company - flagging suspicious activity and asking me about transactions and logins that sounded off. Nice and detailed, professional tone. She read me the last 4 digits of my card number.

21.05.2025 21:08 πŸ‘ 75 πŸ” 43 πŸ’¬ 12 πŸ“Œ 6

As if it's an official source which can be held accountable

18.05.2025 16:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Hell yeah!

17.05.2025 07:25 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Nice

16.05.2025 18:11 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I mean maybe the policy is about preparing kids to read increasingly miserable news headlines with equanimity. We could all do with a bit of that. Stiffen the upper lip as we pick up the morning Guardian or Telegraph.

16.05.2025 18:09 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If you see this, quote with the energy you bring to Bluesky

16.05.2025 17:43 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
EU ruling: tracking-based advertising by Google, Microsoft, Amazon, X, across Europe has no legal basis EU data protection authorities find that the consent popups that plagued Europeans for years are illegal. All data collected through them must be deleted. This decision impacts Google’s, Amazon’s and ...

Big news this evening

This EU ruling has been 7 years in the making

www.iccl.ie/digital-data...

14.05.2025 18:55 πŸ‘ 560 πŸ” 276 πŸ’¬ 15 πŸ“Œ 45
A large number of security alerts

A large number of security alerts

A really emotional and inspiring story of burnout and recovery from Andrew Barber. Jobs which look like this πŸ‘‡ 24x7 take a serious toll on cyber professionals. Our digital first responders should not need to be heroes and organisations must take care of them

#whitehallgovsec

15.05.2025 13:50 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Data Security and Protection Toolkit (DSPT) for Care Providers
What it is: A self-assessment tool mandated for all NHS partners, including adult social care providers. The ASC version is tailored to care provider's operational conditions and regulatory requirements. It is accompanied by the Better Security, Better Care programme

Data Security and Protection Toolkit (DSPT) for Care Providers What it is: A self-assessment tool mandated for all NHS partners, including adult social care providers. The ASC version is tailored to care provider's operational conditions and regulatory requirements. It is accompanied by the Better Security, Better Care programme

Cyber security of the social care sector was immature and unsophisticated until recently, says Michelle Corrigan. But the DSPT has changed that

#whitehallgovsec

15.05.2025 13:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Panel speakers listen to questions from the audience

Panel speakers listen to questions from the audience

Question from the audience: our CEO wants to know when cyber security will stop being a top red risk, given all our efforts to reduce the risk score. What do I say?

Answer: it will always be a top red risk. Tell your CEO to accept the new reality.

#whitehallgovsec

15.05.2025 13:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

As M&S approaches a month offline, business continuity is on everyone’s mind. David Leech says you need to define your MVP: Minimum Viable Company

#whitehallgovsec

15.05.2025 11:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

(Have just committed the conference chair’s cardinal sin by wrongly announcing lunch 1 hour early. The last morning speakers are now under extreme pressure to be even more compelling than lunch.)

#whitehallgovsec

15.05.2025 11:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
The threat to government security
National Audit Office
β€’ The size, age and diversity of government's digital estate makes it challenging to be cyber resilient
β€’ The threat is rapidly evolving and is the most sophisticated it has ever been
β€’ Cyber attacks routinely target government organisations and can have devastating effects on public services and people's lives

The threat to government security National Audit Office β€’ The size, age and diversity of government's digital estate makes it challenging to be cyber resilient β€’ The threat is rapidly evolving and is the most sophisticated it has ever been β€’ Cyber attacks routinely target government organisations and can have devastating effects on public services and people's lives

A pithy summary of the problem for government from Jonathan Pownall

#whitehallgovsec

15.05.2025 10:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

You’ve got to get your board on board, says Richard Pilkington. YES!!! This is the cyber governance structure at Clatterbridge Cancer Centre NHS trust.

#whitehallgovsec

15.05.2025 09:34 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Picture of Andrew Dillon

Picture of Andrew Dillon

More on risk prioritisation: Andrew Dillon says we shouldn’t treat users as alike when it comes to human risk. Different groups have different skills, roles, permissions etc.

Food for thought as most organisations roll out universal cyber awareness training!

#whitehallgovsec

15.05.2025 09:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Curious - how did the BBC verify that they were genuinely speaking with the criminal gang responsible?

Plus, I would not be making confident statements about someone’s English language proficiency based on a text conversation !

Reporting on stories like this is a minefield, IMHO

15.05.2025 09:16 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
The Problem:
Most organisations cannot accurately identify which suppliers pose the greatest risk and traditional assessments focus on tier-1 suppliers and procurement value.
IDENTIFY
The Solution:
β€’ A multi-dimensional risk profiling approach that considers:
β€’ Access to sensitive systems/data
β€’ Integration depth and privileges
β€’ Substitutability and concentration risk
β€’ Geographical/jurisdictional factors
How to begin? Start by mapping your suppliers against these four dimensions.

The Problem: Most organisations cannot accurately identify which suppliers pose the greatest risk and traditional assessments focus on tier-1 suppliers and procurement value. IDENTIFY The Solution: β€’ A multi-dimensional risk profiling approach that considers: β€’ Access to sensitive systems/data β€’ Integration depth and privileges β€’ Substitutability and concentration risk β€’ Geographical/jurisdictional factors How to begin? Start by mapping your suppliers against these four dimensions.

We should require higher levels of security assurance from higher risk suppliers, points out Andy Simpson. Unfortunately, procurement teams define high risk as β€˜large contract size’ rather than looking at what the supplier is actually doing!

#whitehallgovsec

15.05.2025 09:07 πŸ‘ 1 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Slide reads: β€œNORMALISATION OF DEVIANCE. Permeates into the organisation becoming acceptable to simply accept risk without knowing even what it is let alone effectively managing it”

Slide reads: β€œNORMALISATION OF DEVIANCE. Permeates into the organisation becoming acceptable to simply accept risk without knowing even what it is let alone effectively managing it”

Chairing #whitehallgovsec again today. Stuart Frost observes that organisations’ lack of action on supply chain security means we’ve accepted the risk without even knowing anything about it

15.05.2025 08:40 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Lol

12.05.2025 07:44 πŸ‘ 1 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Embrace it. It’s a socially sanctioned way for us to say that people who are older or younger than us are dreadful

07.05.2025 07:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

See you there!

06.05.2025 18:08 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Get off social media and do more of this sort of thing. The world would be a better place if we did

05.05.2025 10:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Yes. The weekend FT is also reaching new levels of silly. I suppose it’s all cope for the geopolitically-terrified.

26.04.2025 11:14 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0