If you do not test your defences, who will? Are you prepared?
Many organisations invest in security controls, but still struggle to answer one simple question: would these controls stand up against a real attacker?
In this episode of Cyber Talks, Rui Shantilal talks with Bruno Morisson, Global Head of Offensive Security at Devoteam Cyber Trust, to discuss how offensive security helps teams test what is actually working.
They explore the difference between penetration testing and red teaming, what a realistic test looks like, and how organisations can move from ticking boxes to improving real resilience. They also discuss the growing influence of regulatory expectations, including DORA, as well as established threat led approaches such as TIBER EU and CBEST.
Finally, they look at the role of AI in offensive security. It is helping testers move faster, but it is also giving attackers new capabilities. The key question is how organisations can adapt without losing sight of fundamentals.
What you will learn from this episode
- What offensive security is, and what it is not
- The real difference between a pen test and a red team engagement
- What makes a security test useful for leaders, not just technical teams
- How AI is changing testing and attacker behaviour
- What DORA, TIBER EU and CBEST imply for security testing and resilience expectations
- Practical advice for anyone building a career in offensive security
Do you prefer to listen to podcasts?
We’ve got you covered! Listen to the fourth episode of Cyber Talks about Offensive Security on all podcast platforms.
Meet our guest
Bruno Morisson is Global Head of Offensive Security at Devoteam Cyber Trust, helping organisations validate cyber resilience through realistic security testing. With 20+ years in cybersecurity, he specialises in ethical hacking, red teaming, and threat-led approaches shaped by frameworks such as DORA and TIBER EU.
Meet our host
Rui Shantilal is Devoteam’s Cyber Trust VP and has been interested in technology for as long as he can remember. He focuses on resilience-driven cybersecurity, leveraging a client-centric approach, AI and cloud security to position Devoteam as an industry leader.


