At the recent panel Risk, Rails and Rules, moderated by Jillian Godsil, industry leaders gathered to discuss how Web3 can build a safer, more resilient digital future. The conversation, anchored by perspectives from Marcos Viriato of Rayls, William Harvey of Bullish, Rei Melbardis of Nexus Mutual, and Han Verstraete of Otonomous, moved through three interconnected themes: risk, infrastructure, and regulation.
Risk: Trust, Custody and the Human Factor
The discussion opened with a familiar challenge – how to balance openness and trust in decentralised systems. “Custody remains one of the biggest risks,” said Rei Melbardis, Board Member of Nexus Mutual. “We’ve seen so many incidents in recent years, but the sophistication of phishing attacks and social engineering is what worries me most. The human element is often the weakest point.”
For William Harvey, Head of International Sales at Bullish, risk management begins with structure and accountability. “We’re an institutional exchange, so counterparty risk is always front of mind,” he said. “You ask: are we regulated in the right jurisdictions, do we have audited financials, and do we maintain liquidity? Risk starts with governance.”
Marcos Viriato, CEO of Rayls, added that mitigating operational risk depends on rigorous security practices. “Every single line of code and smart contract must be audited,” he said. “It’s expensive, but it’s necessary. You cannot cut corners on security.”
And for Han Verstraete, founder of Otonomous, risk must also be philosophical. “Freedom has a price,” he said. “Nobody likes getting hacked, but if that’s the price of self-sovereignty, we accept it. It’s how we learn and preserve decentralisation.”
Across all participants, the consensus was clear: while the technology matures, the human component of risk, training, awareness, and trust, remains the most unpredictable variable.
Rails: Building Secure and Scalable Infrastructure
From the concept of risk, the conversation turned to the “rails” – the underlying systems that support the flow of digital assets and data. Each speaker agreed that building resilient infrastructure requires more than just code; it demands culture, governance, and design.
Viriato described how Rayls separates its technical and governance layers to reduce vulnerabilities. “We’ve built systems that are completely segregated,” he said. “Our employees may find it inconvenient, with frequent password changes and secure refreshes every 24 hours, but that’s how you prevent breaches. It’s about discipline.”
Harvey spoke of the importance of internal culture at Bullish. “It’s all about a culture of security within the organisation,” he explained. “We drill our teams on phishing, issue regular tests, and use multiple verification systems. Security is not a department, it’s a mindset.”
Verstraete emphasised the role of legal and structural separation. “You need to segregate operational entities from development entities,” he said. “That’s how you contain risk and maintain resilience when something goes wrong.”
Melbardis agreed, adding that decentralisation offers an opportunity to redefine transparency. “Insurance should be able to provide real-time reporting on-chain,” he said. “Every transaction, every cover, every product visible to regulators instantly, that’s the power of blockchain.”
Together, their comments painted a picture of an industry maturing fast, aware that security cannot be outsourced or improvised. The new rails of Web3 will not just connect markets; they will embed accountability.
Rules: Regulation, Privacy and the Path Forward
The final theme, rules, explored how regulation, privacy, and innovation can coexist in the evolving digital economy.
For Melbardis, blockchain could make compliance more transparent than ever. “Regulators should love this,” he said. “Everything is on-chain and auditable in real time. Yet the frameworks still lag behind the technology.”
Viriato highlighted the tension between privacy and oversight. “We’re working with central banks in the UK and Brazil on privacy-preserving protocols,” he said. “People want private transactions, but privacy can be used for both good and bad. We need clear rules for when data can be accessed.”
Verstraete expressed concern about regulatory capture. “Big incumbents know how to play the lobbying game,” he said. “We need to protect space for innovation, for builders who can’t afford to spend fifty thousand euros just to get started.”
Harvey took a pragmatic view. “Regulation brings confidence,” he noted. “At Bullish, we operate in Germany, the US, and Hong Kong. It’s costly, but it sets a standard. What we need now are clear and consistent rules across jurisdictions.”
Despite their different perspectives, the panelists shared an optimism about the road ahead. The convergence of regulation, infrastructure, and trust could mark the next phase of maturity for Web3, one where compliance strengthens rather than constrains innovation.
As Jillian Godsil closed the discussion, she reflected on the panel’s balance of realism and vision. “You’re approaching business with consciousness,” she said, “but also with choice and responsibility.”
In an industry often marked by volatility and change, Risk, Rails and Rules brought clarity. The conclusion was clear: the future of digital finance depends on responsible innovation, guided by sound rules, resilient infrastructure, and trust.

