M. Stanley Whittingham
2019 Nobel Laureate in Chemistry | Knight Bachelor, King Charles III | Founding Father of the Lithium-Ion Battery | Distinguished Professor, Binghamton University
CTO EMEA at Rapid7 | Former CISO, Publicis Groupe & Velonetic | Founder, (TL)2 Security & Host Unknown | Award-Winning Security Blogger
Thom Langford has spent over two decades navigating cybersecurity risk at the highest levels — from building global security programs as CISO at Publicis Groupe and Velonetic to his current role as CTO EMEA at Rapid7. Founder of (TL)2 Security and the Host Unknown cybersecurity collective, he makes complex topics engaging and actionable. His keynotes equip executives with strategies for risk governance, resilience, and modern threat defense.
Want to book Thom Langford as a speaker for your event? Please provide the info below and we’ll get in touch within 24h:
Cybersecurity speaker Thom Langford is one of the most distinctive voices in information security today — a seasoned executive who combines deep technical expertise with an engaging, storytelling-driven approach that makes complex security topics accessible and memorable. He currently serves as CTO EMEA at Rapid7, a leading cybersecurity company, where he helps organizations across Europe, the Middle East, and Africa unify cloud risk management with threat detection.
Langford built his reputation through senior CISO roles at major multinational organizations, including Publicis Groupe and Velonetic, where he oversaw information security risk, compliance, and business continuity at global scale. He also served as Director of European Cybersecurity at DXC Technology. With over two decades of hands-on experience building security programs from the ground up, he brings a forward-thinking and opinionated perspective on risk that is both pragmatic and refreshingly candid.
Beyond his corporate career, Langford founded (TL)2 Security, a strategic information security consultancy focused on Virtual CISO services, business alignment, and public speaking advocacy. He is also the creator of Host Unknown, a widely followed collective that produces cybersecurity education and entertainment content, blending humor with substantive industry insight. An award-winning security blogger — recognized with Best Personal Security Blog at the European Security Bloggers Awards — speaker Thom Langford regularly contributes to industry publications and appears at major global events including RSA, TEISS, and Infosecurity Europe.
As a speaker, Thom Langford delivers keynotes that cut through the jargon and speak directly to what executives and security leaders need to hear. Whether unpacking the real-world implications of AI-driven threats, rethinking risk governance for the boardroom, or challenging comfortable assumptions about organizational security posture, he leaves audiences with actionable insight delivered through wit and hard-won experience. Senior leaders consistently value his ability to make cybersecurity strategy feel relevant, urgent, and achievable.
Cybersecurity failures rarely start with missing tools — they start with dangerous assumptions. In this engaging keynote, Langford unpacks the most common strategic blind spots that undermine security programs, from over-trusting identity systems and assuming cloud apps are secure by default to neglecting continuous validation and underestimating insider threats. Drawing on real-world attack patterns and incident response experience, this session gives security leaders a practical lens to identify and address the hidden weaknesses in their defenses before attackers do.
Risk is often seen as a dirty word in business — something to be eliminated rather than understood and leveraged. In this thought-provoking session, Langford challenges conventional approaches to risk assessment and management, exploring why most organizations measure risk poorly and what practical steps leaders can take to build a risk-aware culture that supports business goals rather than blocking them. Using his signature storytelling style and real-world examples, he demystifies risk for executive and technical audiences alike.
Security leaders have finally earned their seat at the executive table — but many are still presenting the same traffic-light dashboards and audit frameworks they used a decade ago. Langford draws on his own experience as a CISO at major multinational organizations to explore how security leaders can frame cybersecurity as a business enabler rather than a cost center. This session covers how to translate security exposure into financial terms, build board-level confidence through tabletop exercises, and position the CISO as a strategic partner in organizational growth.
Modern attackers are no longer satisfied with initial compromise — ransomware, destructive tooling, and backup sabotage now target an organization's ability to recover. In this practical keynote, Langford explores how boards, regulators, and customers now judge organizations by how fast they detect, contain, and restore operations rather than whether they were breached. He offers a resilience-first framework that covers identity security, third-party risk management, crisis testing, and the cultural shift required to make cyber resilience a core business function.
| Basic Data Protection Information | |
|---|---|
| Data controller | AURUM SPEAKERS BUREAU S.L. |
| Address | Parc Audiovisual de Catalunya 1, Oficina S11, 08225 Terrassa, Spain |
| Purposes | We will use your data to respond to your requests and deliver our services to you. |
| Marketing | We will only send you marketing correspondence if you have given your prior consent, which you can do by ticking the box for that purpose. |
| Lawful basis | We will only process your data if you have given your prior consent, which you can do by ticking the box for that purpose. |
| Recipients | Generally, only our members of staff who have been duly authorised may access the data that you have provided. |
| Your Rights | You have the right to know what information we hold about you, to rectify it and to erase it, as explained in the additional information available on our website. |
| Additional Information | For more information, please see “PRIVACY POLICY” on our website. |