Skip to content
Artwork for ISF Podcast
BusinessManagementTech NewsTechnologyCareers

ISF Podcast

Information Security Forum Podcast

The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.

Play
  • 21 episodes
  • weekly
  • Avg 25 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • #354
    Tuesday · 28 min

    354: SUMMER LISTENING: Emerging Threats for 2026

    Today, Steve looks toward the horizon, at the threats and challenges that enterprises and business leaders will face in 2026 and beyond. He also gives advice on how everyone, from the board to the practitioner, can meet these challenges, and answers some of the questions he’s received this year. Key Takeaways: Steve’s four key drivers of cyber risk heading into 2026 are AI, supply chain, quantum, and geopolitical instability. Crucial to cyber resilience are strong governance and a security-conscious culture. Adaptive governance and adaptive security are keys to managing the challenges of 2026 and beyond. Tune in to hear more about: Steve’s four key drivers of cyber risk heading into 2026 (2:23) Questions to ask, whether you’re a board member, an executive, or practitioner (16:14) The changing role of the board (18:54) Standout Quotes: “ Resilience really needs an organizational wide holistic approach that takes technology, it takes governance, it takes operational readiness, and really importantly, it takes people into account.” - Steve Durbin “I think boards need to really take it upon themselves to absolutely recognize that cyber risk is a national risk. It is a business ending risk, and they need to ensure that they don't just have incident response and resilience in place, but that they also have a tried and tested plan, so this is good old fashioned BCP — business continuity planning — with a cyber flavor.” - Steve Durbin “Cyber risk reporting has to be business outcome oriented. Boards, business executives understand revenue, operations, customer impact, legal exposure. That's the way we have to be reporting cyber risk. It's not about how many attacks we repelled, it's not about how good our systems might be. You need to translate it into business language. If you can do that, not only will you get buy-in, but you'll also have a much richer conversation about the role that cyber and therefore cybersecurity and cyber resilience play in the business.” - Steve Durbin Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #353
    August 18 · 26 min

    353: SUMMER LISTENING: Rest After Stress: The Psychology of High Performance

    Today, Steve speaks with Lauren Farina, psychotherapist and founder of Invited Psychotherapy & Coaching. Lauren and Steve discuss how wellness is becoming a bigger part of the workplace and how we can stay mentally healthy during times of stress and pressure. Also an expert on “high-performance individuals,” Lauren shares what it means to be high-performing and why rest can be just as productive as work. Key Takeaways: Being a high-performer isn’t just about work. Rest is productive Building psychological safety within an organization is the most important contributor to elite performance. Tune in to hear more about: What the “High Performer Archetype” is (6:15) The risks of not taking time to rest (11:22) How leaders can improve the performance of their teams (19:33) Standout Quotes: “ As many of us know, acute stress is quite good for us. But in the long term, the chronic unrelenting demands that I think remote working arrangements have placed on the workforce, really can erode our performance because our cognitive functioning is not at its peak when we're chronically stressed, our memory, our learning, our judgment, our decision making is compromised.” - Lauren Farina “ There was a five -year study at Google called the Aristotle Project, and the Aristotle project found that psychological safety is the single most important factor when it comes to the elite performance of individuals and groups.“ - Lauren Farina “ It is my hope that there will be an increased focus on intersectionality of performance and wellbeing and increased support of individuals and groups in cultivating wellbeing. Not only for the sake of wellbeing, but also for the sake of peak performance.” - Lauren Farina Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #352
    August 11 · 28 min

    352: SUMMER LISTENING: Geoff White – Ransomware Is a Business and It's Competing Against You

    In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack – in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes. Key Takeaways: 1 Ransomware attacks remain similar in strategy, but have become more industrialized in recent years. 2 Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors. 3 An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks. Tune in to hear more about: 1 Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33) 2 The impact of AI on ransomware attacks (13:52) 3 How money laundering is changing (17:03) Standout Quotes: 1 “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White 2 “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White 3 “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #351
    August 4 · 27 min

    351: SUMMER LISTENING: Steve Durbin – How Quantum and Geopolitics Are Redefining Resilience

    Today, Steve returns to Business Matters with Juliette Foster. In this conversation, Steve recaps 2025 in cyber and shares what he sees as the biggest risks heading into 2026. The two also discuss resilience and compliance, as well as the growing importance of togetherness among businesses. Key Takeaways: 1 Companies would be wise to conduct frequent cyber audits. 2 Supply-chain disruptions can have long-lasting, reputational effects. 3 How we protect the integrity of our data is at the core of cybersecurity. Tune in to hear more about: 1 The relationship between government business in cyber (12:56) 2 How boards should plan for a cyber attack (15:40) 3 Collaborating within and across industries (22:24) Standout Quotes: 1 “I've said many times that good compliance doesn't equal good security, but good security does equal, nine times out of 10, very good compliance. So where do we go with all of that? I do think that we're probably getting to a point, sadly, where we need to be viewing some of the security processes that we need to undergo in the same way as we consider financial audits.” - Steve Durbin 2 “I think that the day is gone when you can rely on your defenses. So boards have to be planning for the day when the defenses fail. When an attack really starts to make an impact on your business. The starting point is to figure out how long you can be without your systems. It may sound like a strange thing to say, but that's the important starting point for me.” - Steve Durbin 3 “Security is not, in my opinion anyway, a competitive advantage. And because it's not a competitive advantage, there shouldn't be this massive barrier to sharing some of the ideas, some of the attacks that are out there for the good of the industry.” - Steve Durbin Read the transcript of this episode
 Subscribe to the ISF Podcast wherever you listen to podcasts
 Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #350
    July 28 · 23 min

    350: SUMMER LISTENING: Alex Bovee – Identity in the Age of Agentic AI

    In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around. Key Takeaways: 1 Identity must be treated as a strategic risk. 2 When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice. 3 Choosing robust but user-friendly technology is important for attracting and retaining new talent. Tune in to hear more about: 1 The deepfake challenge (6:14) 2 Automated identity governance (8:33) 3 Empowering a culture of trust through identity strategy (12:20) Standout Quotes: 1 “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee 2 “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee 3 “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee Read the transcript of this episode
 Subscribe to the ISF Podcast wherever you listen to podcasts
 Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #349
    July 21 · 29 min

    349: Steve Durbin – When Governments Shift: Reimagining UK Cyber Strategy and Business Resilience

    Today, Steve returns to Business Matters with Juliette Foster. The United Kingdom has a new Prime Minister: Andy Burnham, and Steve speaks with Juliette from a cyber and business perspective about what to expect from the nation's new leadership. They also discuss the importance of digital inclusion, what businesses should do to remain in control in times of uncertainty, cyber insurance, and more. Key Takeaways: As more of world becomes digitally enabled, cyber becomes increasingly important from a national defense and resilience perspective. More organizations are moving to scenario-based planning to manage uncertainty. Governments must understand the complexity of their large projects and make sure they’ve got the best people working on them. Tune in to hear more about: The importance of digital inclusion (4:17) Solving the cyber skills shortage (20:29) How cyber insurance is changing and why it matters (22:58) Standout Quotes: “For a lot of people, digital inclusion means handing people a smartphone and saying, “There you go.” It isn't just about access, it's about the knowledge that you need to actually make use of the technology that you have access to.” - Steve Durbin “You want to try to maintain a solid state in between somebody saying they're going to make the acquisition and take you over, and when that completes. [...] Because the resilience is core to the effectiveness going forward of that organization. All too often, there's a tendency to fiddle with it, play with it a little bit. No. We need to understand exactly what our core components are, the crown jewels, how are we protecting them, how are they going to be impacted over a certain period by any change that goes on, and what can we do to make sure that we're doing everything possible to preserve the integrity of those crown jewels so that we can continue to operate. The last thing you want is somebody coming in and actually changing that during a handover period.” - Steve Durbin “From a cyber-specific perspective, one of the things that has infuriated me constantly over the years is this obsession that we seem to have that people have to be trained in the technical skills in order to have a cyber career. That is absolute nonsense. Because the sorts of skills that you need could equally be well found with people with arts degrees. It's that curiosity. It's that ability to be able to be creative.” - Steve Durbin Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #348
    July 7 · 28 min

    348: Geoff White – Ransomware Is a Business and It's Competing Against You

    In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack – in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes. Key Takeaways: Ransomware attacks remain similar in strategy, but have become more industrialized in recent years. Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors. An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks. Tune in to hear more about: Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33) The impact of AI on ransomware attacks (13:52) How money laundering is changing (17:03) Standout Quotes: “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #347
    June 30 · 23 min

    347: Alex Bovee – Identity in the Age of Agentic AI

    In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around. Key Takeaways: Identity must be treated as a strategic risk. When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice. Choosing robust but user-friendly technology is important for attracting and retaining new talent. Tune in to hear more about: The deepfake challenge (6:14) Automated identity governance (8:33) Empowering a culture of trust through identity strategy (12:20) Standout Quotes: “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #346
    June 23 · 21 min

    346: James Wilkson - The Human Factor: Leadership, Risk and the AI Era

    Today, Steve speaks with James Wilkson, managing partner at AEC Global Search Consultants, an executive search and advisory firm. James and Steve discuss why today’s leaders must be flexible and emotionally intelligent, who belongs in today’s boardrooms, and how leaders can protect their personal brands online. Steve also asks James to look into the crystal ball. Key Takeaways: The most important trait for leaders today is flexibility. Today’s leaders must understand the technology they’re implementing in their organizations. Almost everything you do is visible online today, so be careful and mind your behavior. Tune in to hear more about: Managing different generations in the workplace (4:18) How boards can upskill (12:31) What will surprise leaders a year from now (18:29) Standout Quotes: “I think AI, without a doubt is going to continue to accelerate and alter how we think, but just like anything else, it's just going to be an extremely robust tool down the line.” - James Wilkson “And leaders today, the leaders that are well-trained at being able to relate across generations and across technology are the ones that are going to continue being the leaders, and they're going to hone the next leadership team. The ones that are resistant and the ones that are frustrated, they're just not going to sustain leadership roles that much longer.” - James Wilkson “It's just a massive tsunami of discussion about AI and how it's going to change everything, and it is, but I think we're only going to briefly be led by this loss of work purpose, this loss of what... I think companies right now, the reason there's such a holdback on what do we do? We really slowed down hiring, are the entry level jobs all going to be gone? Yes, probably briefly because we're having a reaction, a knee-jerk reaction, but I think we're going to quickly find out that this is going to bring about a lot of different opportunity. So I think we'll plateau for a while, and then we'll begin utilizing humans in different roles that are still the same role that's just adapted itself to what technology has brought for us.” - James Wilkson Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #345
    June 16 · 28 min

    345: Stephanie Forbes - The $4.2 Trillion Problem: Why Boards Can't Afford to Ignore Supply Chain Fraud

    Today, Steve sits down with Stephanie Forbes, CEO of the Forbes Group. Stephanie is a supply chain expert who recently released Global Wealth, Local Impact: How Supply Chains Build Thriving Companies, Cultures, and Countries, a book about building supply chains using lessons from our past. She and Steve discuss what she learned in her research for the book and supply chain management principles leaders can rely on in these unsteady times. Stephanie also gives advice for small and medium-sized businesses, how to manage supply chain issues across departments, and digital risk management. Key Takeaways: Frequent reviews of internal systems and supplier compliance are key to supply chain management in uncertain times. We innovate and solve problems better when we work in teams and across departments, and it’s the leader’s job to enable and encourage such collaboration. Boards have the responsibility to ask questions and investigate whether their organizations are managing their supply chains as well and securely as they could. Tune in to hear more about: What history teaches us about how we manage societies (2:08) How supply chains will change over the next five to ten years (10:25) The three questions boards should ask to secure their supply chains (25:58) Standout Quotes: “If I'm only a couple of people, 10 people, then I'm probably not going to bring in a full-scale audit unless I'm importing a lot of goods, unless I have a really big tariff bill, and then it's probably worth it for me to take a look at that. So you're going to want to cherry pick the things that are really important.” - Stephanie Forbes “It's going to become very difficult, I think, in another five, 10 years to buy anything that doesn't have a full life -cycle knowledge, awareness or paper trail. And that's gonna be all the way down to the ink or the physical ore, all that kind of stuff.” - Stephanie Forbes “The more as a leader in your organization that you can really encourage and foster that cross-functional collaboration between your operations and whether it's procurement, supply chain, even finance, to really make sure everyone's talking the same language, it becomes a huge competitive advantage, especially when things are changing so rapidly.” - Stephanie Forbes Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #344
    June 9 · 20 min

    344: Dustin Dobbyn - Train Like Your Life Depends on It: A SWAT Operator on Cyber Resilience

    Today, Steve speaks with Dustin Dobbyn, an internationally recognized security expert, Marine Corps veteran, former SWAT operator, and the CEO of a fast-growing private security and executive protection firm. The two discuss management under pressure, the value of training and preparation, and awareness of supply chain risk. Dustin also makes the case for agility and flexibility in the workplace. Key Takeaways: Physical security and cybersecurity are no longer separate arenas and organizations must realize all forms of security impact one another. Intelligence is your greatest friend when building organizational resilience. Work schedule flexibility can significantly improve productivity. Tune in to hear more about: Securing all levels of your supply chain (8:15) A skill that veterans can bring to the cybersecurity industry (14:05) Dustin’s resilience roadmap for the next five years (18:02) Standout Quotes: “If you think you know it all, it's time to get out of the business.” - Dustin Dobbyn “So we're seeing, especially in the corporate world for corporate security, a lot of people working remote on a flex schedule, and we're seeing a lot more productivity because of it. For leadership out there who's listening, absolutely just take that into consideration, as sometimes people work better at certain times of the day based on their schedule. And if you can get them in an environment where they're less stressed, you're going to get better work output out of them.” - Dustin Dobbyn “Knowledge is power. Intelligence is what's going to keep you safe because if you have the intelligence, you're aware of what's going on, and you can prepare for worst-case scenarios.” - Dustin Dobbyn Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #343
    June 2 · 28 min

    343: Peter Hinssen - The New Never Normal: AI, the Future of Business and the Leaders We Need

    Today, one of our favorite guests returns: Peter Hinssen. A renowned keynote speaker, author and serial entrepreneur, Peter is one of the most sought-after thought leaders on radical innovation, leadership and the impact of all things digital on society and business. When Peter was last on the show, the world had just begun to recover from the Covid-19 pandemic, and generative AI was still in its infancy. This time around, Steve and Peter talk about the advancements of AI and what they mean for the C-suite, whether the tech companies have become too powerful, AI regulation, and the future of leadership. Peter also answers how we will remember this AI boom in 10 years. Key Takeaways: This period of rapid change that we’re currently going through won’t pass, but rather become the new (never) normal. Regulators must rethink their approach to create frameworks for new technology that actually work. Headcount is no longer a key measure when it comes to a business’ success. Tune in to hear more about: How to manage this era of volatility and constant change (3:30) How leadership is changing (14:30) Why small businesses might be better equipped to deal with the AI boom (21:06) Standout Quotes: “We’re now in a world where the cycles move faster than ever before. The stakes are higher, and I think a lot of the instruments that we had from the past just don’t work anymore.” - Peter Hinssen “The larger the company is, the more difficult it is to get that change going, and that’s why inherently smaller organizations have, I think, a competitive advantage because being agile, being nimble, and being resilient should be easier for a smaller company than a larger organization.” - Peter Hinssen “When you look at the printing press moment, we had the industrialization of knowledge, where we went from monks transcribing books into an abundance of information, and then we had the Industrial Revolution, where we went from muscle to machine. I think this is where the two of them are coming together.” - Peter Hinssen Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #342
    May 19 · 26 min

    342: Betsy Cooper - The Policy Gap: Navigating AI, Risk and Regulation

    In this episode, Steve is in conversation with Betsy Cooper, director of the Aspen Policy Academy at the Aspen Institute. As an expert in cyber and tech policy, Betsy shares her thoughts on how policymakers can keep pace with the rapid developments in AI and quantum technology, building a futureproof compliance strategy, and AI risks. Steve and Betsy also discuss policymaking in a volatile world, how businesses can protect their image after a breach, and what can be done to get governments to care about online scams. Key Takeaways: Legislative experiments at the local and regional levels will be key for crafting strong, sensible, tech policy on the national level. Tabletop exercises are one of the best tools for preparing the C-suite for breaches and attacks. People must start to speak up against the growing prevalence of having to trade privacy for access to the most basic online tools and sites. Tune in to hear more about: Creating a “future-proof” compliance strategy (7:11) Protecting your brand following a breach, data theft, or disinformation campaigns (13:35) Trading access for personal information (22:31) Standout Quotes: “I do think that it would be preferable to have one coherent framework. I think industry would benefit from that if we did have that sort of framework. But also, I'm not sure that we're at the level of sophistication today that we'd be able to write the best framework because we haven't experimented enough. So I actually think that having the state and local sort of sandboxes leading to future federal policy is not a bad approach.” - Betsy Cooper “It's a very difficult thing to try to prove a negative, and that's why disinformation can be so powerful. But it's also a very fast-moving space, so the faster you can get in there with your counter-narrative, the more likely you are to be successful.” - Betsy Cooper “I'm the mother of a five-year-old, and in order to get my five-year-old's baseball schedule, I have to download an app on my phone. There is no web access for the app that has the baseball schedule. So in order to get that baseball schedule, I have to sign away a whole bunch of privacy just to get my kid to a sports game. I think that shouldn't be allowed.” - Betsy Cooper Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #341
    May 12 · 24 min

    341: Dr. Keith Morneau - AI & the Resilient Workforce: Thriving in the Next Decade

    Today’s guest is Dr. Keith Morneau, an experienced cybersecurity professional who currently serves as Dean of Computer and Information Science at ECPI University. Steve and Kieth discuss the future of the cyber workforce, cyber education, and if AI is taking our jobs. Steve also asks Keith to step into the shoes of a CEO… Key Takeaways: In today’s cyber world, having an understanding of how systems interact is more important than ever. People with non-technical backgrounds are often quick learners when it comes to cyber, and bring in fresh perspectives. In new hires, executives should look for people who understand how to work with AI. Tune in to hear more about: How AI can help junior staff and those entering the cyber workforce (6:15) Dr. Morneau’s ”prepare, practice, perform, assess” philosophy (13:23) One obsolete role chief executives should stop hiring for, and one emerging role they haven't even thought about yet (21:15) Standout Quotes: “We’re really still in the baby steps of AI, in the beginning stages of it. What I’ve noticed of a lot of folks, there’s AI there, but they’re not 100% understanding how it all works, how the AI actually has to be trained and all that. I think over time what we'll see is the increase in knowledge and skill set using AI for what they’re doing in their jobs should help with the bottom line over time.” - Dr. Keith Morneau “The biggest issue in cybersecurity are the AI systems that are very vulnerable to attacks.” - Dr. Keith Morneau “The type of person you need to look at is the person who’s able to use AI to do the job that you need them to be able to do better and faster, and be more efficient at it. What you have to be careful of is the people that are going to be obsolete are the ones that are basically fighting the AI and not using AI at all to help them, because that is pretty much they are going to be dinosaurs soon, if they’re not already dinosaurs.” - Dr. Keith Morneau Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • #340
    May 5 · 23 min

    340: John "Jock" Brocas - Gut Instinct: The Intuitive Edge in Cyber Security

    In today’s episode, Steve sits down with John “Jock" Brocas, a former military member who is now an executive mentor and strategic intuitive intelligence advisor to the C-suite. Jock is far from your typical cyber professional, but his experience working with executives gives him a compelling perspective on challenges faced in our industry. Steve and Jock discuss how we can train ourselves to block out the noise and become better at recognizing the real threats to our business, the value of mindfulness and managing stress, and why leaders must see the big picture. Jock also shares his thoughts on deepfakes, from the perspective of a medium. Key Takeaways: Adopting a warrior mindset means blending logic and intuition. Taking a break, even just for a few seconds, is crucial to managing stressful situations. Meditating can help you become better at discerning what matters and what doesn’t. Tune in to hear more about: Discerning the signal from the noise () How leaders can help their teams manage stress, both long-term and in acute situations () Jock’s thoughts on deepfakes () Standout Quotes: “Logic and intuition are not separate. And this is the biggest mistake we make. We don't fail in making decisions, especially in the cyber world because of the amount of data we have. We fail at the discernment of maybe that data.” - Jock Brocas “I think it’s important as well that looking at a more spiritual outlook to things, not religious in any way, a meditative or a contemplative side of things. And how many security professionals or cybersecurity professionals take time for themselves to actually even breathe in between doing something?” - Jock Brocas “Discernment, even as a cyber professional, is important. So discernment of the self, discernment of the mind, that's important.” - Jock Brocas Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • S36 · E27
    April 28 · 24 min

    S36 Ep27: Emily Holyoake - Beyond Infrastructure: The Case for Putting People First

    Today’s episode might sound a little bit different, but it’s a really important conversation. Steve sits down with Emily Holyoake, co-founder of Not A Standard and the brain behind the FRAME Network, to talk about the human harm of cyber attacks, gender-based violence, tech-facilitated abuse, and diversity in the cybersecurity industry. Steve also asks Emily to envision the future of the cyber workforce, one that creates safety for society and people, not just machines and data. Key Takeaways: Every attack begins and ends with a human and a breach can have an existential impact on people’s lives. Attribution too often is aimed at individual humans, when we should look at the systems that enabled the person to cause the harm. Diversity within your teams enables a richer environment for problem-solving. Tune in to hear more about: The SAFE Framework (1:57) Why Emily pen-tests her personal life – and why you should, too (18:44) Building a cyber workforce for a safer society (20:56) Standout Quotes: “A person clicks on a phishing link that results in a breach. So we blame the individual instead of thinking what did the system, literally or figuratively, allow to happen that meant that person clicked on that link? But we think we've got to find the root cause. So we pick a human rather than thinking about what the system enabled.” - Emily Holyoake “Every attack begins and ends with a human, fundamentally. In security, we talk so often about people being the weakest link. Fair enough, right? You can have all the technical controls in the world and it just takes one person to break that. But we wouldn't have this business, we wouldn't have this culture, we wouldn't have anything without these people. And so people are, if anything, our greatest asset.” - Emily Holyoake “When you have a diverse group of people thinking about the same problem in different ways from different backgrounds, different experiences, you're going to get an infinitely richer understanding or solution to a problem.” - Emily Holyoake Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • S36 · E26
    April 21 · 26 min

    S36 Ep26: Brett Johnson - From Most Wanted to Most Valuable: Inside the Cybercrime Landscape

    Today we bring back one of our favorite guests: former US most-wanted cybercriminal Brett Johnson. It’s been seven years since he was last on the show, and much has happened in the world of cyber. Brett shares how his perspective has changed in the past few years, and gives his thoughts on how new technologies impact cyber crime. Steve and Brett discuss compliance and what Brett’s path from prison to helping law enforcement means for other cyber criminals. Brett also answers some rapid-fire questions. Key Takeaways: Increased ease of access to cybercrime tools and services, along with manpower problems in law enforcement, are key reasons for why cyber crime is one of the world’s largest economies today. Enterprises must shift focus from trying to block every attack to protecting their crown jewels for when an attack inevitably gets through.  Bad things happen because good people remain silent. Tune in to hear more about: Why cybersecurity awareness training often fail (13:32) If Brett’s path to redemption is still viable for today’s cyber criminals (16:57) Some rapid-fire questions to Brett (21:35) Standout Quotes: “Cybersecurity and security overall is not a romantic thing. It's not an exotic thing. It's simply doing the nuts and bolts of what you need to do. And the problem is that largely that's not happening in the environment. If you've got management that's more interested in butter than they are in guns, you've got those types of issues.” - Brett Johnson “Cybersecurity awareness training or fraud prevention training, scam awareness, anything like that, we tend to educate at a very rational level. For scams and a lot of fraud and stuff like that, it doesn't happen at a rational level. If I'm trying to attack a person and compromise that person, I'm not doing it at a rational level. I'm doing it at an emotional level. I'm trying to get you to set reason and logic aside and to react emotionally. So all that training takes place at that rational level. You can understand it there. That doesn't mean that you understand it at the emotional level whatsoever.” - Brett Johnson “Is it harder? In one respect it is because we now have people that are aware of how money is moved, what criminals seek to do with it. Banks have become more aware of a lot of the new ways to launder and funnel funds. In many ways, it's much harder, but at the same time, criminal networks have adapted to that difficulty.” - Brett Johnson Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • S36 · E25
    April 14 · 29 min

    S36 Ep25: Steve Durbin - Global Threats, UK Blind Spots: Cyber Resilience in a Volatile World

    Today, Steve returns to Business Matters with Juliette Foster. The war continues to rage in Iran, and with it comes an increasing threat of cyber attacks. Steve shares his thoughts on what the conflict means for cyber investment in the private sector, British critical infrastructure, and the British government’s approach to cyber resilience. Steve and Juliette also discuss the UK Financial Minister’s Spring Statement, which didn’t include any references to cybersecurity. What does this omission signal? How will multinational companies react? Is cyber a macro economic issue? This, and more, in Steve’s latest appearance on Business Matters. Key Takeaways: Cyber is a macroeconomic issue, not just a technical one. AI has changed the way that the threat landscape is evolving, but it's also brought benefits for cyber defence. Governments have limited abilities to support the cyber resilience of the private sector; cooperation between large enterprises supports the whole business landscape. Tune in to hear more about: If Steve thinks the UK Finance Minister’s spring statement will impact cyber investments (8:57) The impact on UK businesses of slower economic growth in the UK (14:59) The state of government cyber resilience in the UK (22:39) Standout Quotes: “What you have to do is you have to look at your crown jewels and back to this minimum viable company notion that I mentioned right at the beginning of our chat. You have to understand what the most critical elements of your business are, and then you can track those through these complex supply chains. Those are the pieces you need to be protecting because that's what's gonna bring your business down or ensure that you can continue to operate.” - Steve Durbin “The business climate in the UK at the moment is exceptionally tough, exceptionally demanding. I think if you look at some of the legislation that's recently come in particularly around hiring, retaining employees, the sheer cost of doing business has risen pretty much exponentially for most organizations, and that means that they have to make cuts somewhere. If they can't do it in terms of some of the core business, they will look to some of the fringe elements. So if you've got an organization that perhaps does not view cyber as being core to what they do, then that may well be somewhere where a cut is made.” - Steve Durbin “I think we'll certainly see a maturing of the industry. It's a very young industry still in terms of the way that it's evolving and changing, and I think that with the benefit of a couple of years under our belt, then most organizations will have moved to a stronger position from a maturity standpoint, and I would hope certainly that we're talking very much more about resilience rather than protection.” Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • S36 · E24
    March 31 · 30 min

    S36 Ep24: Special edition – From Awareness to Action: Prostate Cancer, Community and the Case for Early Detection

    Today’s episode is a special one, recorded to announce an exciting and important new partnership between ISF and the organisation Prostate Cancer Research. Joining the show is PCR CEO Oliver Kemp, who for nearly a decade has worked to ensure fewer men suffer and die from prostate cancer. Steve and Oliver talk about how prostate cancer screening works and the importance of catching it early. The two also talk about the partnership and how it will help PCR’s efforts across the UK. Key Takeaways: Early detection saves lives. If you find prostate cancer before it has reached stage 3, the survival rate is 100%. A cancer battle will affect people around you, but they will also be the people whom you can draw strength and support from. Access to cancer screening varies between regions and demographics. Tune in to hear more about: What PSA is and how testing for prostate cancer is done (5:28) The new partnership between ISF and PCR (18:58) How AI and new technologies can help in cancer detection (22:34) Standout Quotes: “I think us men are not always the best at going and looking after ourselves and we often need to be nagged to go out and do something. But if you've got prostate cancer, it's gonna get you one way or another, and it'll gradually grow inside of you. And it's far better getting it early and having a relatively simple procedure, which you can now be in and out of hospital in a single day rather than late-stage prostate cancer, which will have very different consequences.” - Oliver Kemp “I think one of the great things about this partnership is first of all, we're aiming at people who often don't get tested. And there are lots of PSA tests happening across this country, but they're often focused on regional areas. So southeast of England, London has lots of testing. It has lots of the best hospitals in the world, whereas other parts of the country don't have access to that.” - Oliver Kemp “And for people in cybersecurity, it's about being as proactive about your own health as you are about protecting your organization. So it isn't about waiting for symptoms. I didn't have any. Look at PSA tests. We've said on this show it's a very low cost. And the people that I've come across who've certainly taken that step, and sadly there are more of us than people might think, all tell me the same thing. And as for partners, families, friends that are listening, don't underestimate the power of your encouragement just being there. That's really important. You don't have to do anything big. It's just a quiet conversation that could genuinely help.” - Steve Durbin Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  • S36 · E23
    March 24 · 18 min

    S36 Ep23: Martina Navratilova - Focus, Adapt, Evolve: Serving up the secrets of success

    In today’s episode, Steve speaks with Martina Navratilova. Martina is one of the most accomplished tennis players of all time, holding the record for most open era titles and Wimbledon wins. Since retiring from tennis, Martina has been a vocal advocate for gay rights and cancer awareness. In her conversation with Steve, she talks about the importance of screening and early detection, and why self-awareness and kindness to yourself are essential when you’re going through something difficult. The two also discuss adapting to change, how to read your opponents and why rehearsing matters – both on the tennis court and in the world of cyber. Martina also gives the audience a piece of advice on staying resilient in the face of uncertainty, from the perspective of a champion. Key Takeaways: If something doesn’t feel right in your body, get tested. And even if you’re feeling fine, do that annual physical. There is no substitute for practice when it comes to crisis preparedness. Breaches will happen, it’s about how you respond – with clarity and honesty – that matters. Tune in to hear more about: Some news from Steve (1:33) Building the right team (10:18) Recovering after a breach (13:24) Standout Quotes: “We tend to overreact and overcorrect. Less is more in just about everything in life. Less is more. You can always add to it. But if you go too far, you've gone too far.” - Martina Navratilova “At the end of the day, if you are the big boss, you are making the decisions, you have to trust your gut. So you take all the information in, but you have to say, ‘Okay, what really feels right with my knowledge, with my intelligence, with my history, what is the best way forward?’” - Martina Navratilova “No system is bulletproof no matter what. You may hit the best serve ever, but that person guessed and they get it back. It's how you bounce back from that. But nothing is bulletproof. You just need to figure out where was the breach, how can we fix it and avoid doing it again?” - Martina Navratilova Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

Showing 1–20 of 21 episodes