Kit Beale works at the cutting edge of cybersecurity and intelligence, helping some of the world’s biggest organisations understand and manage the risks that come with living online. From tracking criminals online to protecting global organisations, his work sits at the intersection of technology, geopolitics and human behaviour.

 

How would you explain your job to a Radleian in two minutes?

I work for a company that was founded by former UK government cyber operatives, people who were in the relevant agencies when the internet first emerged. I’ve always been told by their former colleagues that the team know the internet better than practically anyone on the planet.

They used those skills in government to protect national interests and defend democracy, also developing quite novel offensive cyber techniques to use against hostile groups. In 2016, they left government and set up a company to provide that kind of cyber-intelligence capability commercially.

What we do now is collect and analyse huge amounts of online data and use it to investigate people and entities and their connections and behaviours online. This data can be used defensively, to protect organisations and individuals, or to identify and track bad actors online.

 

How did you get into this world?

I didn’t really take the traditional route. Starting at Radley, which I loved, I did pretty well academically, and I think they identified fairly early on that I was more of a scientist than an arts student. I took Maths, Physics, Chemistry and History, and then went to Newcastle University to study Environmental Sciences.

Through that I developed an interest in energy and risk, and I spent some summers doing placements in the energy industry, in London and in Texas, including going offshore onto production platforms. I liked the idea of working in that world, but also trying to make it safer.

After university, I joined a start-up risk-management company that worked with the London insurance market. Insurers were underwriting oil rigs, pipelines and drilling fleets all over the world, but rarely actually visited those assets, so we sent specialists out to assess and understand the risks.

About three years in, a new risk was really starting to emerge that no one fully understood: cyber. Insurers are set up for things like an oil rig blowing up or a plane crashing – whilst tragic, it is what the market is for. But what if a cyber-attack took out 100 oil rigs at once? Or grounded hundreds of planes? That would be catastrophic.

We didn’t have the answers, so we helped bring in some of these ex-government cyber specialists who were setting up their own firm. We worked with them on projects for Lloyd’s of London and others, and subsequently, they asked me to move across to their company. The growing cyber market, the ability of this team, it was a no-brainer. I joined in 2019 and now work on the commercial side (eg. sales, strategy and client relations) as well as helping shape the company and what we build.

 

Who are your typical clients?

We’re a small company (about 25 people), but we punch well above our weight. For instance, we work with a handful of the US tech giants. I can’t discuss too much of what we do for our clients as we take client confidentiality very seriously. Broadly speaking, it falls into two areas: protecting people and organisations from the wide range of threats that exist online or helping them identify individuals or entities seeking to cause them harm.

What we do is very much sector agnostic, if you have an online presence, we can help. Our client base reflects that with governments, global banks, oil and gas companies, crypto organisations and luxury brands all the way to family offices and individuals themselves.

 

What are the biggest cyber threats organisations face?

There are so many layers. You go from knowing nothing to putting some defences in place, to realising there’s a whole other level you haven’t begun to address. The problem is that there might be a thousand ways an attacker could get in that a security team has to manage… but ultimately the attacker only needs one.

AI has made this harder, because attackers now use it to scan for vulnerabilities in software at a speed and scale that simply wasn’t possible before. One of the biggest mistakes companies make is focusing too much on technology and not enough on people. Your systems might be secure, but your employees go home, use the internet, click on things, and inadvertently bring that risk back into the organisation. The human side is, and probably always will be, the hardest to manage.

 

What happens inside a company when there is a cyber attack?

People often have plans, but they don’t know how far to go until it happens. There’s an overly used Mike Tyson quote: “Everyone has a plan until they get punched in the face.” That’s very true in cyber.

Take the TalkTalk breach in 2015 – they initially said everything was under control and no customer data had been taken, but attackers were still inside the system and came back again causing far more damage. Or Marks & Spencer, more recently: they refused to pay a reported £10 million ransom, which is admirable, but the attack supposedly ended up costing around £500 million. These decisions are incredibly hard in the moment.

How do you think about privacy and ethics?

Everything we do is very much legal, but when you look at how much data exists about people online, it’s quite frightening. Most of it is already in the hands of bad actors – hackers, criminals – being traded or exploited for malicious purposes.

We have copies of that data so that we can help clients understand what’s out there and clear it up. The reality is that the data already exists, so using it responsibly to protect people is in everyone’s interest.

 

Is this a competitive industry?

There are a few similar companies, but not many that have been collecting this kind of data for as long as we have – we’re consistently told our offering is genuinely unique. Competition is mainly in the broader “cybersecurity space”. Cybersecurity is complex and has so many different aspects, firstly we are more cyber intelligence, but there are a lot of companies that claim they can do everything, realistically this is not true and in the end clients will find out the hard way. The challenge is often differentiating oneself in this market where noise and brand often obscures true value.

We’re often described as the “Rolls-Royce” option. Smaller companies may need to invest in basic defences first, which will provide a significant return on investment across the board. Historically, we tend to be brought in when organisations need something more unique, specialist or advanced. However, that is evolving as we begin to productise our offering to service a wider audience, which is an exciting shift for us.

 

What kind of people thrive in this world?

You need an open, curious mind. Some people come from international relations and geopolitics. Some are coders, systems engineers or full-stack developers. Others are analysts with a psychology or investigative mindset, trying to understand what people are doing online and why.

There isn’t one background that fits. What matters is curiosity and the ability to think across technology, current affairs and human behaviour.

 

Is university still important for this sector?

I’m not sure I would have got this job without a degree, even though mine was in Environmental Sciences. You learn a lot from the university process. But I don’t think it’s essential now. Many companies are backtracking on degree requirements.

On the technical side, learning on the job can be more valuable as things are moving so fast. For analytical or commercial roles, a degree still carries weight. There are also great alternatives to a traditional degree now, like degree apprenticeships and professional qualifications, that didn’t seem to be such an option when I was 18.

If someone is genuinely interested in this sector, my honest advice would be to look at the Civil Service first. The training, the exposure, the experience of working in government, it’s pretty hard to replicate that elsewhere. The stories I hear from colleagues sound fascinating plus it looks great on the CV. In hindsight, it’s something I certainly would’ve explored.

 

What worries you most about the next decade online?

The geopolitical technology race, for instance, in AI and quantum computing. With quantum computing, whoever gets there first will be able to break all encryption and potentially dominate global systems. It’s hard to know who is ahead in this race, we’ve got to hope it is the US or the broader West, but I fear not. The future of geopolitics could depend on this.

In many ways, it’s a race between two models: a capitalist system driven by competition, and a state-controlled system where everyone works towards one goal.

 

What gives you hope?

There are a lot of brilliant companies and people out there working relentlessly to counter these threats. You go to industry events and see these startups tackling incredibly difficult problems. It’s a constant battle, but there’s a huge amount of talent and innovation.

 

What would you tell a Radleian interested in this industry?

Be open-minded. Take risks. Joining a small startup can be incredibly exciting you have to juggle multiple different roles but ultimately you see the impact of your work directly.

In the world of AI where specific roles and tasks can be automated, I think being a generalist, someone who can move across the business and adapt, is only going to become more valuable, and a start-up is probably the best ground to develop that skill.

If I were 18 now, I’d probably become an AI/ML engineer and go straight into one of the massive tech company, easier said than done but that’s where the money is. However, that may well change and there’s more than just money what really drives me now is the variety, the pace, and building something from the ground up. I always say we’re the “sexy” side of cyber: spy-novel stuff, not firewalls, every day and every job is different so it’s fascinating. The work we do is so topical, and the industry is only growing. On top of that, helping a wide array of clients with their most difficult challenges and seeing first-hand the difference we make really is rewarding.

Explore more careers