Patrick Gray: How Risky Business Grew Beyond a Podcast
Every week for nearly two decades, a journalist in a small Australian beach town has sat down to explain the week's hacks to the people who have to clean them up.
Patrick Gray's Risky Business began in February 2007 as a weekly security podcast "without the waffle." It's since grown into a media company with a news editor, a policy desk, a documentary series and a spin-off show whose co-hosts include a former director of CISA.
The business model shouldn't have worked: no scripted ads, ever, and sponsors who get interviewed instead of read out. Nearly 20 years and more than 850 episodes later, it's still going.
Patrick Gray at a Glance
- Before the podcast, Gray was a security journalist with bylines at Wired.com, The Sydney Morning Herald, The Age, BusinessWeek, The Bulletin and SecurityFocus.
- Risky Business first aired in February 2007 as a weekly show of news and in-depth interviews, running about 50 to 60 minutes.
- By 2009 it'd passed 100 episodes and, by its own account, built a following "among security professionals at the peak of the profession." By 2010 the count was past 170.
- Gray built Risky Business Media around the show, headquartered in Byron Bay, New South Wales, on a sponsorship model that swaps advertisements for interviews.
- The lineup grew into a family: Snake Oilers, where vendors pitch the audience; Soap Box; Between Two Nerds; the Seriously Risky Business policy newsletter; and the Risky Bulletin news service.
- When Australia sanctioned the alleged Medibank hacker in January 2024, Brian Krebs turned to Gray, "the Australian co-host and founder of the security news podcast Risky Business," for analysis.
- Wide World of Cyber pairs Gray with former CISA director Chris Krebs and Alex Stamos for deep dives on the biggest incidents.
- In 2026 Risky Business Media launched Risky Business Stories, a long-form documentary series, while the main show passed episode 850.
The Life of Patrick Gray
Gray's Newspaper Years
Patrick Gray came to podcasting from print. By the time Risky.biz described him in 2009 as a "veteran security journalist," he'd written for Wired.com, The Sydney Morning Herald, The Age, BusinessWeek, The Bulletin magazine and SecurityFocus.
That was a beat with a problem. Security stories were getting bigger and more technical every year, and the people who understood them best had nowhere to talk at length.
Gray's answer was to stop writing them up and start recording them.
A Podcast Without the Waffle
Risky Business first "aired," as the site puts it, in February 2007. The format was simple and has barely changed: the week's security news, discussed with a co-host, followed by an in-depth interview with someone who actually knows the subject.
The show's own description sets the tone. It's "a must-listen digest for information security pros," it says, and "a security podcast without the waffle," with a running time of roughly 50 to 60 minutes.
Each week Gray and co-host Adam Boileau talk through the news, a pairing that still anchors the show in 2026.
Risky.biz Grows Up
The podcast became a website, and the website became a small publication. By 2009 Risky.biz said the show had published more than 100 episodes and "developed a significant following among security professionals at the peak of the profession."
Gray edited the site's news section himself and promised "exclusive breaking news content" alongside the audio. A year later the episode count had passed 170.
The audience was the point. Risky Business was never aimed at the general public; it was built for the people whose pagers go off when a company gets breached.
Interviews Instead of Ads
Gray's business model was unusual for a podcast then and remains unusual now. "Risky Business doesn't do scripted advertisements," the company explains. "We record engaging interviews with them instead."
That idea became whole shows. Soap Box is a sponsor interview stretched to a full episode, and Snake Oilers is exactly what it sounds like: "three vendors stop by to pitch the audience on their products," with the audience free to judge the pitch.
By 2026 the sponsor list included Sublime Security, runZero, SpecterOps, Yubico, Tines and Push Security. The company lists its headquarters in Byron Bay, a surf town on the New South Wales coast, which is a long way from the Washington and San Francisco circuit the show covers.
Building a Newsroom
Somewhere along the way the podcast grew a staff. Risky Business Media's masthead now lists Catalin Cimpanu as news editor, Tom Uren on policy and intelligence, James Wilson as technology editor, Claire Aird as newsreader and Amberleigh Jack as producer and editor, with Gray as CEO and publisher.
Their output runs on its own feeds. Risky Bulletin delivers news bulletins and the Risky Business News newsletter three times a week, while Seriously Risky Business, the weekly policy and intelligence newsletter, is also published by Lawfare.
Between Two Nerds and sponsor interviews round out the bulletin feed. What started as one man and a microphone had become, in the company's own words, "one of the cybersecurity discipline's most respected mastheads."
The Medibank Hacker
Gray's reach shows up in other people's reporting. In January 2024, when the Australian government sanctioned Aleksandr Ermakov as the alleged hacker behind the Medibank breach, Brian Krebs called Gray for perspective.
Sanctions are easy to dismiss as toothless against a man who stays in Russia, Krebs wrote. But Gray's view was that Ermakov's alleged role as a top member of the REvil ransomware crew painted a target on him as someone likely sitting on large sums of cryptocurrency.
It was a typically Risky Business take: less about the headline than about what happens next.
Wide World of Cyber
In recent years Gray has added a show that puts him beside two of the best-known names in American security. On Wide World of Cyber he talks with Chris Krebs, the former director of CISA, and Alex Stamos about the biggest incidents of the moment.
When F5 was hacked, the three took apart what happened, whether it mattered, and, as the episode notes put it, "why private equity ownership of mid-tier cybersecurity companies is often a red flag."
Another episode dug into Microsoft's China entanglement; a third into how state adversaries attack security vendors.
Risky Business in 2026
The main show kept its pace through 2026. Episode 850 covered widespread AI-enabled attacks on Siemens programmable logic controllers; episode 854, "We're Jevpilled," landed on September 30, 2026.
The company also launched Risky Business Stories in 2026, a long-form documentary series, adding a fourth podcast feed to a lineup that already included Risky Business, Risky Bulletin and Risky Business Features.
Nearly two decades in, the man who gave up newspaper bylines for a microphone runs a newsroom bigger than many of the tech desks he once wrote for.
Patrick Gray: Still Without the Waffle
Gray's story is a reminder that the best security journalism was never going to fit in 800 words. The people who fight breaches for a living wanted an hour, every week, with someone who wouldn't waste their time.
Today Risky Business Media runs four podcast feeds and two newsletters from Byron Bay, and Gray still hosts the weekly show with Adam Boileau.
The format was set in February 2007: the news, an interview, no waffle. Episode 855 will sound a lot like episode one.
QUOTE:
"Amateurs hack systems, professionals hack people."