Pressure Zone a podcast by Hack The Box
Pressure Zone is a game-driven cybersecurity podcast where CISOs and executives are placed inside escalating, realistic risk scenarios that mirror the complexity of today's cyber leadership. Each rung requires the guest to make a decision under pressure, explain the rationale, and translate the impact into business terms, just as they would with a board, CEO, or executive team. The episode unfolds as a structured game, creating an engaging format that reveals authentic leadership judgment, tradeoffs, and security insight without feeling like a traditional interview or sales pitch.
Each episode is built around escalating rounds: connected, sequential scenarios that move from early warning signs to high-stakes incidents, where every decision shapes the context and pressure of what comes next. Guests must assess the risk, make a clear call, and defend it in business terms. If they dodge a question or avoid a decision, they trigger a Confession Card penalty, prompting an honest, insight-revealing response such as a hard lesson learned or an unpopular opinion. This keeps the tension high while preserving the realism, pace, and authenticity of the game.
Pressure Zone a podcast by Hack The Box
The Friction Point
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Welcome to the Pressure Zone Podcast, the ultimate stress test for tech and security leaders.
What happens when security stands between a retail giant and a £500M holiday launch?
In this episode, Robert Newby steps into the hot seat to navigate "The Friction Point." Just 72 hours before the massive Golden Quarter release of a high-speed checkout feature, a critical flaw is discovered—one that bypasses every fraud trigger in the system. With millions in revenue on the line, account hijackings blowing up on social media, and an uncompromising Board, Robert must balance profit against protection.
You see, this is why I wouldn't be doing it in the first place and why exactly why our board didn't, because they knew they knew it would blow up in their faces. Um and we did have people going out and spilling oil. We had as I say, we had pressed camps outside the offices and people uh walking outside. I think we're just saying and people were um following people from the office into local bars and restaurants, sitting next to them and just listening to what they were saying because people were talking about it.
SPEAKER_02Wow. All right, I'm Christine Bartlett. Welcome to uh The Pressure Zone, the an HTB podcast where we take one security scenario and watch it spiral out of control and sometimes bring it back. And I'm joined here today with Robert Newby, the head of security business engagement for Marks and Spencer. Thank you, Rob, for joining.
SPEAKER_01Thank you.
SPEAKER_02And uh for today, you'll be stepping into uh a new company called Mike and Susie for the Pressure Zone.
SPEAKER_00All right, so great.
SPEAKER_02Uh so let's let's go after it. Today we aren't just talking about firewalls or fishing filters because that would be boring. We're talking about the big game. You sit at the intersection of profit and protection, the translator between the technical no and the business yes. Something I'm sure you're very familiar with.
SPEAKER_00Yep.
SPEAKER_02Here's the setup: it's a rainy Tuesday morning in late November. MS is 72 hours away from the golden quarter launch of Bolt Checkout, a high-speed one-click payment feature designed to dominate the Christmas rush. Projections show a 15% revenue spike, and the marketing director is popping champagne. But you just found a ghost in the code. Your final review reveals that the speed optimization bypasses every major fraud detection trigger in the system. The board, of course, is watching, the market is waiting, and the clock is ticking. Let's see if you're a bridge builder or if you're about to burn the whole thing down. Are you ready to step into the zone?
SPEAKER_01I'm ready.
SPEAKER_02All right. Question one: the go live ultimatum. The marketing director tells you that adding a verification step will cause a 20% cart abandonment rate. We don't want that. He wants the launch as is and to accept the risk. What is your move? Option A, the hard no. Block the launch entirely. Security is non-negotiable here. Option B, the risk transfer, let them launch, but only if the marketing director signs a formal liability waiver for any fraud loss. C the silent monitor mode, launch it, but you divert your entire SOC team to manually review transactions for the first 48 hours. That sounds like a nightmare. Option D.
SPEAKER_01Hopefully they're doing it anyway.
SPEAKER_02Option D, uh, the VIP sandbox, roll it out only to a small group of trusted Sparks members to test the waters first.
SPEAKER_01Yeah, so in reality, I wouldn't do any of those. Oh uh if I've got to pick one of those things, um then it would be the the risk transfer, but it would be done in a way that works with the business. So, first of all, I'd want to understand exactly what we are bypassing. So, what is the actual risk? So, what have we bypassed? What fraud does that open up? What types? Um, what kind of rate are we looking at in fraud? Um, what what's best case, what's worst case, um, how much money that would translate to over the whole of the GQ period? Um, and I would also bring in a bit of that uh that SOT monitoring as well. What would we how would we detect those abnormal patterns? Um but then if we're putting it into numbers, then you've got to trade off that. What's that what does that 15% upside actually mean? Where's that from? How confident are they that that is actually going to come in? What evidence do we have? Um, and does that verification actually does that create that, or does it, you know, does that does that that one click, is that actually going to be the driver for all of that uplift, or is it a combination of other things? Is it drop-off that causes that? Have we tested that? Um I've actually got quite a similar thing to that going through at the moment. So I have actually asked these exact questions. What you want to do is look at the beginning and end of the transaction and see what the the um the drop-off rate is before and after. So if you yeah, so um so you can actually see whether it has made that difference or not.
SPEAKER_02Yep, okay.
SPEAKER_01And is that just because you're doing a launch rather than is it gonna be ongoing as well? You quite often get a big uptick and then it'll carry on.
SPEAKER_02Okay. So so we're going for option B with a a nuance there based on the city.
SPEAKER_01Yeah, option B with a bit of caution for with some head really heavy hedging in there. Yeah, yeah.
SPEAKER_02So we're gonna call that. We have a little uh a little uh you know uh uh cheekiness on on each of the answers. So we're gonna call that as you're using the the signature get out of jail free card. Um but if the fraud uh hits the tabloids, do you really think the board will care about a you know, piece of paper or conversation, I guess maybe in this point?
SPEAKER_01Or will you no, well that's exactly it. So it's it's uh that that piece of paper isn't for the tabloids, that piece of paper is for me. Right. That that's covering my backside, not not the companies.
SPEAKER_02Not the companies, yeah.
SPEAKER_01So yeah, I mean you hopefully your your your media team will be well on top of anything that that needs to be in place for if there are massive fraud, but fraud isn't typically gonna hit the press anyway. It's the big events like ransomware and you know, big breaches that take out operations rather than fraud. People like to keep quiet, oddly enough.
SPEAKER_02Yeah, okay, okay. So, question number two the Sparks identity hijack. The feature is live, so we went through with it. Uh, the nightmare begins. 20,000 Sparks accounts are being drained of points via bolt checkout. The BBC is now asking if MS has been hacked. Do you disclose the flaw to regulators now or wait until the investigation is over? So your options are A, the post-close cleanup, keep it quiet, fix the hole, and disclose it as a system update later to avoid a PR disaster. B immediate disclosure, report the breach immediately to stay compliant, even if it kills the Christmas sales momentum. C the indemnity demand, force a software vendor who built the Bolt API to take the legal and financial heat. D, the hacker hunt, task your team to identify the botnet origin. If it's low level, stay quiet. If it's a major syndicate, go public.
SPEAKER_01So anytime you have a breach, you need to know a few things about it. So is it confirmed? Is it suspected? What do we know for certain? Um, that's all the same question. I know I've got three fingers up there. Um how many accounts? Is it all of them? Is it a percentage? What um how long has it been going on for? Are we still rising or have we stabilized that kind of thing? So what kind of control have we got over the situation? There is no point in going out to the ICO with a half-baked disclosure of the because all you're going to be doing is updating them again and again and again and again. You need to have a solid point. You need to let them know within 72 hours, I think it is.
SPEAKER_02Yes, yeah, yeah.
SPEAKER_01So um you wouldn't just jump straight in with, oh yeah, we've had a breach, go and tell everybody. Um so can we can we stop it is the first thing. So shut it down. I mean, having been through something fairly recently, the first thing you need to do is contain it.
SPEAKER_02Yeah.
SPEAKER_01You've got to get control over it. Shut the whole thing down if you can, and then that will hit the press. Um, we have people camped outside when we had it. Um you have to control that. And our media team was fantastic when we had the breach. Um and that just means that security can get on with it. Right. So the first step is containment. Get the get your IT teams out of the way unless they need it as part of that. So someone to rebuild the identity system is probably quite uh quite useful. Somebody for remote access you probably need as well. So having all of these things in place before that, so I'm assuming here that we had a business continuity plan.
SPEAKER_02We had um, you hope this isn't your first go, right?
SPEAKER_01Yeah, exactly. Um you're hoping that everyone knows exactly what to do, and the IT teams will step back, let the security guys in, let them stop it, clear it up, and then uh you know come back and continue with recovery. Hopefully we've also got some backups available.
SPEAKER_02Yeah.
SPEAKER_01That would be nice. Yeah, um and that we're not just rebuilding from scratch, uh, which would be good. Um so what's your I guess it's what's your your sorry I'm getting emails. What's your fastest containment plan? Um uh can we can we disable it and restart? Can we just get can we get rid of those IDs and just say, right, well we'll deal with that offline and everyone else can carry on, or do we have to shut everything down and just start again? So where are we with it? Um is the first thing.
SPEAKER_02Okay.
SPEAKER_01I don't know which one of your options that was. I don't know that that that is an option, but we can keep going.
SPEAKER_02You actually uh personally gave me flashbacks when you were saying like out of the you know 20,000, it what was actually been impacted, what hasn't? And I I yeah, a while a long time ago I worked uh at Cisco and we had to deal with the wanna cry uh breach, which was like something and it yeah, it was a lot of those conversations, right? Like how much, what is it we need to be sure before we're gonna go out to the press with a lot of people?
SPEAKER_01Yeah, because it's really difficult to give um you I know you have to ask very black and white questions and you you've got to have an A, B, C, D. Yeah, but you can't you can't deal in absolutes. Everybody wants you to deal in absolutes in an incident, and you can't. It has to be, well, measure it. Tell me how much, how bad, how good, how little, how much, you know, where are we going with it? Because that's what you set your direction by, and that says what your next step is gonna be, how big it's gonna be, how customer experience changing it's gonna be. So if they if they're if you've got 20,000 accounts out of 50 million, try and isolate it, deal with it, put the controls back in place without anyone noticing. If it's 20,000 out of 20,001, shut the whole thing down. There's no point. It really depends on what that that that that number means.
SPEAKER_02So I think your answer aligns more closer with you know, kind of additional investigation, right? Going uh layers deeper. We kind of labeled that the the hacker hunt, right? To identify further get it more information.
SPEAKER_01So you'd absolutely do. And as you were going through, I was thinking, yeah, I'd do that. Oh no, I'd do that as well, I'd do that as well. So you do, you do little bits of all of it.
SPEAKER_02So Yeah, yeah.
SPEAKER_01But I wouldn't say anything until I knew where we were. I wouldn't go and immediately disclose anything because that's as harmful as not disclosing. But when I had enough to say, and somewhere where I mean, regulators aren't there just to punish you. This is the thing that people always think. They're they're actually there to give you help as well.
SPEAKER_02Right, right, yeah. They want to protect.
SPEAKER_01Yeah, yeah, they're there for the industry protection. So if you go to a regulator and say, We've got this problem, they will jump in and help you in the moment. It's only six months to a year down the line when they find out that you didn't do X, you didn't do Y, and you didn't call them until a week later that they're gonna jump down your throat. And then they'll be much more um, you know, much kinder to you in retrospect if you phoned them up within the allotted time and said, This is going on. I don't know if you you know if you can help me with it.
SPEAKER_02So it's almost like calling reinforcement.
SPEAKER_01Um, they're they're more oversight than reinforcement, I would say. But they they certainly they've seen it before and they know how it works and they know who can help.
SPEAKER_02So yeah, it's so question three the board's ultimatum. So provided you're doing your investigative work, right? Uh the chairman says, I don't care about a few lost loyalty loyalty points. We need the revenue to survive the quarter. Do not disable the checkout. How do you respond? A, the technical deep dive, bring the chairman into the sock and show him the live uh theft to shock him into action, which could be interesting. I don't think very many chairmen um will appreciate all the technicalness of that. Uh B, the conditional fix, agree to keep it open only if you get an immediate five million budget for fraud defense upgrade. Full negotiation. C, the resignation threat. You tell the board that if they keep it open, you're gonna walk. Um, your reputation is more than a Christmas bonus. Or D, the sandbox gamble, move all bolt transactions to a high latency network to slow down the bots, even if it slows down real customers.
SPEAKER_01I I I don't think again, I wouldn't, I don't think I'd have to do any of that. My our board were absolutely brilliant during the incident, they gave us so much support and still are now, and they just want things to be secure, right? So um, I I don't think these days you'd get that as a reaction, you wouldn't have right, money's more important than security, because that's the kind of thing that does come out after the event, but uh I th in that case you would have to to have business sign-off, like actual you know, people with skin in the game. It would have to be I I'd almost want them to be the ones who are phoning out the ICR and saying, right, repeat to them what you just said to me because they're not gonna like it. Um so it's if if they're really not worried about a few loyalty points, then they need to understand again is that quantifying of things how many is it percentage-wise, um, you know what what kind what's what's the the what's the risk trade-off here? What are we what are we losing, what are we gaining? Um try and put it into a financial terms, balance it against one against the other, and so are you prepared with for that and the potential reputational business downside of it? Because and explain to them what would happen when you do say that to the ICO if customer data has been stolen and you've said actually it's more important to carry on trading, this is your exposure level there as well, because that could potentially be a lot more than you you gain from from staying live.
SPEAKER_02Right, right. So I think then we'll we'll we'll probably flip option A instead of a technical deep dive, you're looking to put the chairman on the phone.
SPEAKER_01Well, it it it's not a technical deep dive, it's a risk deep dive though. It's talking them through the business risk of it. So there's no point in taking a board through a technical risk deep dive because they'll they'll nod, but they they'll say carry on, you know, do what I said.
SPEAKER_02Right.
SPEAKER_01If you explain to them that yeah, I know you're not concerned about the loyalty point, but what about the press? What about the ICO? What about the reputational loss? If you're seen as going being very gung-ho about this, all of those things will will come into play, and that will that's at least, you know, the the the exposure of loyalty points is nothing compared to the exposure from the other three things, which are gonna be you know almost a hundred percent of your loss, and they could be absolutely vast.
SPEAKER_00Yeah.
SPEAKER_01Whereas if you actually say, No, we're we're shutting it down, we're we're gonna be careful, you can turn that into a positive. The ICO will love it. Reputationally, you can say, Yeah, hands up, we've had a breach, we we moved too fast on this. It was only that that small part of the customer platform, we've got it under control, and we're gonna push again sometime in the future, we'll have another release. It's not ideal for golden quarter, but then neither is losing your entire business. So, yeah, talking through the the the the risk side, the business risk side rather than the technical risk.
unknownOkay.
SPEAKER_02Nope, I like that. Question number four the the internal leak. Uh, as you're sorting through all of this, right? A developer on the Bolt team posts a Reddit that MS leadership knew the system was broken but launched anyway. The stock price dips. What's the PR move? A the CEO keynote, release a video emphasizing customer trust and ignoring the technical leak. Bird is down. I know, but some people don't use that up. B the targeted fire, use forensics to find the leaker and terminate them publicly to send a message. C the counter narrative, leak a story about a new sustainability AI to distract the press from the Reddit post. D, full transparency, hold an all hands and admit the trade-off was made, uh, but now but you're now fixing it.
SPEAKER_01You see, this is why I wouldn't be doing it in the first place, and why exactly why our board didn't, because they knew they knew it would blow up in their faces. Um, and we did have people going out and spilling oil. We had, as I say, we had pressed camps outside the offices, and people uh walking outside. I think were just saying, and people were um following people from the office into local bars and restaurants, sitting next to them and just listening to what they were saying because people were talking about it. So yeah, so a lot of what happened came out for us, and you know, it was almost out in the press before we knew in the in the security team a lot of the time, which was terrifying at times because there was a lot of detail out there. Um so transparency would always be my choice. I'd I always I like to operate like that anyway, yeah. Um because that way you're not gonna get any crazy surprises. So I I would choose transparently um transparency rather. Um but I and I I think having a witch hunt doesn't really help as well. Because w what do you do? What once once you've gone and found the person and asked them what they knew, and you know. Dive as as as far into it as you can. Apart from firing them, what what what do you gain from it?
SPEAKER_02Right.
SPEAKER_01You don't really gain anything, you just I mean, and it's much easier to to actually I mean, people they might believe everything they read on Reddit, but they probably shouldn't.
SPEAKER_02Well nowadays, but there's I know I do, yeah. You don't know if a human wrote it or a bot wrote it.
SPEAKER_01I was gonna say that's where AI gets all its information, so yeah, it probably is right. Yeah. Good point.
SPEAKER_02Okay, so I like that. Honesty, the best policy. Uh obviously, you know, I think you'd be seen as a you know, very uh brave man, but then obviously poses the question is you know, are your shareholders as brave as you are, right? Because when the truth comes out, there's always the the Well that's the problem.
SPEAKER_01In your scenario, that would be the wrong thing, almost the wrong thing to do because you're going against your board and CEO. But in my real world, everyone's on the same page, so we we'd be okay with that.
SPEAKER_02All right, last and final question the zero-day choice. It's Christmas Eve, the bot attack attack is peaking. You have a patch that will fix the fraud 100%, but it might actually lock 5% of legitimate accounts for 24 hours. On the busiest shopping day of the year, what's your command? A do it live, deploy the patch, 95% success is better than 100% fraud. B the manual backup, disable bolt, and force everyone back to the old slow checkout, better safe than sorry. C, the ransom play, contact the botnet operators via your old hacker gut contacts and offer a bug bounty to stop the attack until December 26th. D got real creative there.
SPEAKER_01I like it a lot. The hacker moment the hackers, that's it. Right.
SPEAKER_02Um the hacker moment sit at the terminal and try to write a precision script to target only the bot traffic yourself.
SPEAKER_01So is that uh that that five percent loss, I mean that again, I'd want to make that trade-off. Does that five percent loss uh is it gonna be more than what we lose uh if we if we just go back to manual? So if that's the trade-off, so one or the other of those, but based on the number of accounts that we would have, I would go for the five percent loss, I think, because it's not gonna be a significant loss compared to what you would lose otherwise. Otherwise, like big drop-off, yeah.
SPEAKER_02Okay. So all right, so picking option A, you roll the dice, 80% is a C in grade school, but in retail it's a terrifying margin. If it fails on Christmas Eve, do you have your LinkedIn profile updated?
SPEAKER_01Yeah, I mean, always, right? It's just a question if anyone would employ me after that, all these crazy decisions that I've had to make.
SPEAKER_02Oh, okay, good, good. I know, right? The clock has stopped. The golden quarter is either saved or in shambles. We've just watched uh 500 million retail legacy hang by a thread. Uh, Rob, you faced a friction-filled launch, a regulatory trap, a boardroom coup, and an a Christmas Eve logic bomb before we reveal your resilience score. Uh, we have to ask at any point in the last 20 or so minutes, did you miss being the one just writing the code uh without having to worry about the stock price or the chairman's temper?
SPEAKER_01Uh I never wrote code, so uh no. I was I I was always a consultant. Uh I I regret taking a permanent job now, yeah.
SPEAKER_02That's good. You've got the I I hear a lot of the strong business acumen side, and I feel like that's uh we we need those CISOs with that, so that's good too.
SPEAKER_01Um okay Yeah, I think that that's the key for me is that it would I'd I'd I I I don't like to be put on the spot with these kind of things, but I'd rather it was me being put on the spot than someone who is either completely business oriented or completely technical, because at that point we've got the big Cesaw and emotions and a clash. If I can stand in the middle and be the translator, then you tend to get better decisions being made.
SPEAKER_02Alright, so based on your answers, it looks like you are at a resilience score of 85, smart, stable, and slightly terrifying. Um, we're gonna call that the pragmatic titan. You're balanced risk, risk and strategic. Uh the verdict is you leveraged the flaw for a better budget and brought in the experts. You didn't let your ego get in the way of Ibada, and you've successfully transitioned from root to sweet.
SPEAKER_00Nice.
SPEAKER_02Uh and and then uh you play the game better than the people who wrote the rules, is the final outcome, I think.
SPEAKER_01Or strong. There you go, you see.
SPEAKER_02Yes.
SPEAKER_01Spent the last year doing it for real.
SPEAKER_02That's yeah, yeah. And and for I guess, you know, maybe for a little bit of of the folks listening, I think what you were referring to in your uh commentary was I believe you you were kind of working on the the scattered spider, right? Is that what you were referring to?
SPEAKER_01Yeah, so a year ago, this weekend just gone, we had the what was at the time the biggest retail breach in UK history, and uh were right in the middle of it. Um my I'm I run the what we call the Bisos, TSOs, and consultants, and they were the ones not involved in the initial cleanup, that was the SecOps team, but the people who recovered afterwards. So we were right in the middle of all of that cleanup, and obviously being part of the leadership team and security, I was uh party to a lot of those conversations that were going on.
SPEAKER_00So yeah.
SPEAKER_01But as I say, I think our our actual business leadership team they they they led, they really did well by managing expectations, managing what they wanted us to do, managing what they wanted tech teams to do, what the business team should be doing, and they gave us the space and they gave us the support. And I think if that had happened in a lot of other companies I've worked in, it wouldn't have been the same. And it would have been quite a lot harder. So and and they they're still supporting now, which is really important. A year on, big you know, big security change projects going on, the big changes of the way the operating model works for us in in technology. Um a lot of growth, which is really positive. When you've lost a lot of money to go and actually put money into growth, particularly in security, is a really hard thing to do. But um, yeah.
SPEAKER_02It's a it's a long game. It's not gonna be a short turnaround, right? Um, but it's worth it. Yeah. Okay. Before we let you out of the zone, Rob, we've just got one more final question that we ask every leader that survives. Don't worry, this is not uh an if or what. Um, but uh if you could send a one-sentence encrypted message to your 22-year-old self starting out in security today, or wherever you started, what would it say?
SPEAKER_01I was gonna say, I don't know what I was doing at 22, but it wasn't security. Um work harder. I was still at university when I was 22. I I I didn't even know how brutal the world was. Um I re I don't I don't know. I think um just take every opportunity that comes your way, particularly whilst you're young, um because they they get fewer and further between as you get old. I'm nearly 50 now. It's horrendous. 50 in two months, would you believe? They're really uh really old now. But um, yeah, I you you have to take, I mean, when all the AI stuff started, I mean it was probably around the same time as last year, I'd say, right, I'm I'm interested in that. I want to pick that up, I want to get really down into the weeds of it and understand it, not just use it to write LinkedIn posts. I just want to get what it's doing, what's the maths? But I'm a I'm a science nerd. Um, so what's the maths underneath it? How does it work? What would actually make it safer to use? Um, so I've I've I've been looking at actually how can you architect a way around the problems that AI is gonna bring? Um data set data uh kind of data lakes, I guess. Data like big big data is what I'm looking for. Big data. What's what's gonna be the the next thing there? What the analytics side of it, what's what's that gonna I I kind of missed the boat on data when it first came out, but my my son, my middle one, I've got three three sons. My middle one actually came in to work with me a couple of weeks ago and he was working with the developers. And I said, if you're interested in development, probably miss you by the time you're old enough to come and work here, because he's only 14 now. By the time you're old enough to come and get a job in development, there won't be a job in development, it'll be prompts, you know, you'll be right in front of like at home, anyway. So it's like so learn about the data, learn about what you can do to manipulate that data, learn about what AI does with that data, how it's using it, and what do you think the next big thing is gonna be, not what the world thinks it's gonna be. The chances are you might be thinking of something completely off the wall that actually does happen.
SPEAKER_02I mean that fresh perspective, right?
SPEAKER_01Well, exactly. The stuff we're looking at now, AI and robotics and all the when I was a kid, we were like, wow, wouldn't it be amazing if we had all of it? And we got them. You know, we've got electric cars. It's here, yeah, right.
SPEAKER_02Self-driving cars, yeah.
SPEAKER_01So exactly, exactly right. All of the things that you dreamt of as a kid are now out there, and it's like, what do you dream of now that there are all of these things? What what's next? Because you know, my my imagination's long gone, but his is ripe, you know. So when you're thinking of these things, keep on generating those thoughts, keep on generating new things because it's those ideas that become tomorrow's big things.
SPEAKER_02So yeah, no, agreed. I love that. That's awesome. Well, thank you, Rob, for for joining. Um, and and appreciate your time coming on the show. And that's a wrap for the hack the box pressure zone. Um, to our listeners, remember that you're in a world of business engagement. Uh, you aren't just protecting a perimeter, you're protecting a promise to your customers. And uh join us next time. Uh we will call on another uh CISO leader and put them in a hot seat. But until then, uh trust the math, but verify the code. I'm your host, Christine, and this was the HTV Pressure Zone podcast.