Skip to content
Artwork for The Entropy Podcast
TechnologyNewsBusiness

The Entropy Podcast

Francis Gorman

Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for unfiltered conversations on the threats, complexity, and geopolitics shaping our world.


Past guests include former senior CIA officers, leading cryptographers, digital forensics experts, and security and technology leaders from across financial services, critical infrastructure, and government, voices rarely heard together in one place.


Each episode goes beyond headlines to explore how cyber risk, emerging technology, and geopolitical instability are reshaping the way organisations operate, compete, and defend themselves. Expect candid insight on quantum risk, nation-state threats, AI, espionage, financial crime, business resilience, and the human dimensions of leadership.


Designed for CISOs, board members, founders, technologists, policy thinkers, and the professionally curious, Entropy sits at the intersection of business, technology, and cybersecurity a space for genuine conversations with unique minds, the kind that don’t fit neatly into a press release.


The name Entropy reflects the growing complexity and unpredictability of the systems we depend on, and the discipline required to lead through them.


Disclaimer: The views and opinions expressed on The Entropy Podcast are those of the host and guests in their personal capacity and do not represent the views, positions, or policies of their respective employers, affiliated organisations, or any government body. Guest appearances do not constitute endorsement by the host, and the host’s commentary does not constitute endorsement of guests’ views. Content is provided for informational and educational purposes only and does not constitute professional, legal, financial, or security advice.


One of the topics I cover a lot on this show is post quantum readiness, I believe awareness of this emerging technology is key for a safer world into the future. To support this awareness I have built a free resource to help you explore the world of quantum and learn as you go. You can find it here: www.postquantumready.com



Buy Our Swag:

We now have some slick new swag you can purchase through our Esty store.

https://theentropypodcast.etsy.com  


Watch and Subscribe

You can also watch full episodes and exclusive content on our YouTube channel:
www.youtube.com/@TheEntropyPodcast


Achievements

The Entropy Podcast delivered strong chart performance throughout 2025, demonstrating consistent international reach and listener engagement.


  • Regularly ranked within the Top 20 Technology podcasts in Ireland.
  • Achieved a Top 25 placement in the United States Technology charts, holding the position for one week.
  • Charted internationally across multiple markets, including Israel, Belgium, and the United Kingdom.



This performance reflects sustained global interest and growing recognition across key podcast markets.


Audio Quality Notice


Some episodes may feature minor variations in audio quality due to remote recording environments and external factors. We continuously strive to deliver the highest possible audio standards and appreciate your understanding.



Play
  • 21 episodes
  • weekly
  • Avg 42 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S2 · E32
    Tuesday · 38 min

    From Automation to Autonomy with Ismail Amla

    AI is moving beyond automation and into autonomy and that shift could fundamentally change how businesses operate, how decisions are made and how people work. In this episode of The Entropy Podcast, Francis Gorman sits down with Ismail Amla to explore the rise of agentic AI, digital workers and AI-native organisations. They discuss why the biggest opportunity is not simply using AI to make existing processes faster, but redesigning businesses around what intelligent systems can now do. They also examine the harder questions: what happens when AI agents begin making decisions independently, who is accountable when those decisions go wrong, how organisations can avoid agentic drift, and whether relying too heavily on AI risks weakening human judgement and curiosity. Key takeaways: Why AI is shifting from automation to autonomy How AI agents could become part of the workforce Why most AI transformation efforts fall short What leaders need to rethink, and why governance and human judgement matter more as systems become increasingly autonomous. Soundbites: “I think it is a revolution. I don’t think it’s just another tool.” “Whoever this technology is working on behalf of is responsible for every decision that’s made.”

    • Transcript
  • S2 · E31
    August 18 · 46 min

    Train Like You Fight with Snehal Antani

    In this episode of The Entropy Podcast, Francis Gorman sits down with Snehal Antani, CEO and co-founder of Horizon3.ai for a wide-ranging conversation on cybersecurity, AI, warfare, leadership and the future of work. Snehal shares lessons from building and scaling Horizon3.ai, why startups must eventually move from “pirates” to a “navy,” and how his time inside Special Operations fundamentally changed his approach to leadership. They also explore the rapidly changing cyber threat landscape: AI-powered attackers, autonomous penetration testing, deception as a defence against AI agents, the lessons emerging from Ukraine, and why organisations need to stop asking whether they are secure and start proving they are resilient and defensible. Key Takeaways Why great founders need grit, conviction and a “learn-it-all” mentality How companies transition from entrepreneurial pirates to a scalable navy Why AI could give cyber attackers effectively unlimited ammunition How defenders can use honeypots and deception to hack the hackers Why cybersecurity teams should train like they fight The growing importance of human-machine teaming in warfare Why over-reliance on AI could undermine human judgement and scepticism How AI may reshape the workforce and put increasing pressure on the “middle” Why there is no AI easy button coming for cybersecurity Why organisations must move from being “secure” to being resilient and defensible Key Soundbites “You earn the right to be on this team every single day.” “AI gives the adversary unlimited bullets.” “You don’t want to learn how to deal with a crisis in the middle of a crisis.” “We always train like we fight.” “There is no AI savior that’s going to suddenly make your lives better.” “Those obsessed with mastering their craft are going to come out on top.” “Stop saying that we’re secure… start talking about how we’re defensible.”

    • Transcript
  • S2 · E30
    August 16 · 43 min

    From Quantum Risk to Competitive Advantage with Shayne De La Force

    Quantum technology promises enormous economic value, but are businesses preparing quickly enough to capture it or protect themselves from its risks? In this episode, Francis Gorman speaks with strategy leader and LFI founder Shayne De la Force about the commercial realities of quantum technology in advanced manufacturing. Drawing on decades of experience across the semiconductor, aerospace, defence and automotive sectors, Shayne explains why quantum must become a board-level economic and governance priority. They explore the cost of waiting, the challenge of securing global supply chains, the role of an embedded Chief Quantum Officer, and why businesses need to look beyond vague terms such as “quantum advantage” and “quantum readiness.” Shayne also reflects on beginning his career on a factory floor in Japan, the dangers of “synthetic seniority,” and the lessons behind his book, Strategic Entanglement, which helps deep-tech founders cross the valley of death between innovation and commercial success. Key Takeaways Quantum is an economic issue, not merely a technology issue. Business leaders should evaluate it through two lenses: increasing enterprise value and reducing risk. Waiting carries a measurable cost. Organisations that begin planning and piloting now can build stronger competitive moats, while delayed action may expose intellectual property, long-lived data and future market position. Quantum preparation needs board-level sponsorship. CISOs and technical teams require executive support, funding and governance authority to deliver meaningful readiness programmes. Advanced manufacturers face a supply-chain problem. Prime contractors may have thousands of suppliers operating at very different levels of cryptographic maturity. The weakest supplier can become the greatest source of exposure. Prioritisation is more valuable than trying to fix everything at once. Companies should identify high-exposure systems, sensitive intellectual property and long-lived data, then concentrate resources where risk reduction will have the greatest impact. Most mid-sized organisations do not need a full internal quantum department. An embedded Chief Quantum Officer model can provide access to strategy, security, physics, governance and programme-management expertise without years of internal hiring. Quantum use cases must be tied to commercial outcomes. Not every pilot will deliver immediate value. Organisations need clearly defined business problems, economic metrics and realistic pathways from experimentation to deployment. Deep-tech commercialisation must begin early. Start-ups should develop their market narrative, customer belief and commercial strategy alongside the technology—not after the product has been completed. Foundational experience still matters. Working directly with machines, infrastructure, customers and operational teams creates judgement that cannot be replaced by AI-generated ideas or “synthetic seniority.” Soundbites “Unless you are working for a not-for-profit, we are all here to drive business, growth and economic value.” “A CEO or CFO has two fundamental objectives: maximise economic value and reduce economic risk.” “The companies moving today are the ones that will have the strongest competitive moat.” “Unless you have buy-in at the top, it is very difficult to move the rest of the organisation.” “When boards see the economic risk of losing their intellectual property and long-term data, that is when the needle starts moving.” “Building an internal quantum department can take years and millions of dollars. Our embedded model gives companies access to the whole capability.” “The companies running pilots today are the ones building a competitive moat over the companies that are waiting.” “In advanced manufacturing, equipment may have a depreciation cycle of 25 or 30 years. That makes cryptographic transition a massive challenge.” “The prime contractors are preparing, but their supplier base is often their weakest link.” “Our job is to create clarity in chaos—because, right now, it is chaos.” “Can we close 80 percent of the exposure in the first 12 months and then work through the remaining 20 percent?” “The valley of death is where great technology goes to die because the commercialisation strategy was never developed.”

    • Transcript
  • S2 · E29
    August 9 · 40 min

    Nobody Reads the Plan During the Fire with Patrick Lechner

    In this episode of The Entropy Podcast, Francis Gorman speaks with Patrick Lechner, co-founder of Resimate.io and an experienced business and cyber resilience leader, about why many organisations mistake documentation for genuine readiness. Patrick challenges the obsession with business continuity plans, impact assessments and compliance evidence, arguing that resilience should be measured by outcomes: can the organisation continue operating when something critical is lost? The conversation explores the difference between security and resilience, why businesses should prepare for loss rather than attempt to predict every possible threat, and how leaders can identify their most important dependencies. Patrick also examines the role of AI, the importance of business ownership and why tabletop exercises must become honest operational conversations rather than annual corporate theatre. This is a practical discussion about building the confidence, capability and human relationships required to respond when the plan no longer matches reality. Key takeaways Resilience is not a collection of documents. Plans and frameworks are useful, but they do not prove that an organisation can sustain operations during a crisis. Prepare for loss, not every imaginable threat. Most disruptions can be reduced to losing a site, people, systems, suppliers or data. The business owns resilience. Operational leaders should decide what must continue, what level of disruption is tolerable and where investment is justified. Cybersecurity and cyber resilience are different. Security attempts to prevent incidents; resilience determines what happens when prevention fails. Dependencies must be understood across the organisation. A single failure—such as electricity, identity infrastructure or a major supplier—can create very different consequences across multiple teams. AI can amplify weak processes. Automating a poor resilience process may produce more plans and evidence without improving operational capability. Tabletop exercises should be frequent and honest. Short, regular discussions are often more valuable than one heavily scripted annual exercise. People ultimately carry the response. Trust, authority, shared principles and operational knowledge matter more during a crisis than a spreadsheet stored somewhere on the network. Soundbytes: “We were tired of resilience being measured by plans, not outcomes.” “Plans may be useless, but planning is indispensable.” “Almost every threat can be reduced to a handful of loss scenarios: losing a site, people, systems, suppliers or data.” “The board-level question is simple: how confident are we that we can sustain operations if we lose a key dependency?” “It does not matter why the electricity is gone. If it is gone, the business still has to respond.” “Investing heavily in prevention does not mean you are resilient.” “If you have bad processes today, AI is a great tool for accelerating those bad processes.” “You do not become fit by going to the gym once a year for seven hours. Tabletop exercises work the same way.” “An exercise should be an honest conversation, not a performance conversation.” “When something hits, it is the people, the trust and the shared principles that allow the organisation to respond.”

    • Transcript
  • August 2 · 38 min

    Welcome to the Age of Synthetic Reality with Jake Moore

    In this episode of The Entropy Podcast, Francis sits down with Jake Moore, Global Cybersecurity Advisor at ESET, to unpack one of the biggest technology shifts of our time: the collapse of trust in the digital world. From deepfakes and AI-powered scams to digital footprints, remote hiring fraud, and the rise of agentic cybercrime, Jake explains how rapidly evolving AI tools are changing the nature of deception and why individuals, businesses, and governments are struggling to keep up. The conversation explores what happens when seeing is no longer believing, how cybercriminals are already exploiting synthetic media, and why the future of cybersecurity may depend less on tools alone and more on human awareness, verification, and digital resilience. If you’ve ever wondered how close we are to a world where anyone can fake anyone, this episode is for you. Key Takeaways Deepfakes are no longer theoretical — they are already being used in scams, impersonation, and fraud. Trust online is eroding fast, as AI-generated content becomes more realistic and accessible. Remote hiring introduces new risks, including AI-assisted impersonation and fake candidates. Your digital footprint reveals more than you think, often exposing personal details that can be used against you. Cyber awareness is still the strongest defense, especially when technology alone can’t keep pace. Children need better cyber education, particularly around passwords, privacy, and digital identity. AI is scaling cybercrime, making attacks faster, cheaper, and more convincing. Agentic AI and quantum computing could create the next major wave of cybersecurity disruption. Soundbites Here are strong promotional soundbites you can use in Spotify captions, social posts, clips, or episode promos: “We’ve entered a world where seeing is no longer believing.” “Your face, your voice, and your identity are becoming easier to fake.” “The biggest cyber threat may not be malware — it may be trust itself.” “Deepfakes are no longer a future problem. They’re here now.” “Cybercriminals don’t need perfect technology — they just need believable enough.” “Your digital footprint can tell strangers more about you than you realize.” “In the age of AI, awareness is still your greatest defense.” “The next scam won’t look suspicious — it will look completely real.” “Remote work has opened the door to a new kind of identity fraud.” “We are moving into an era of synthetic reality, and most people are not ready for it.”

    • Transcript
  • S2 · E29
    July 25 · 41 min

    Will The Nodding Bird Be Running Your SOC? Maybe? with Rik Ferguson

    Cybersecurity is entering a new era one shaped by autonomous AI attacks, machine speed defense and the looming impact of quantum computing. In this episode, Francis Gorman speaks with Rik Ferguson, Vice President of Security Intelligence at Forescout, about why organisations must move from “assume breach” to “assume autonomy.” Rik explains the four conditions required for trusted autonomous defense: context, constraint, reversibility and transparency. They also explore the risks of over-relying on AI in security operations, the importance of meaningful human oversight and why “harvest now, decrypt later” attacks make post-quantum readiness an urgent business priority. Key Takeaways AI is changing the operating model of cyberattacks. The greatest shift is not simply that AI makes existing attacks faster. Autonomous systems may combine vulnerabilities and techniques in ways that do not reflect human logic or established attacker behaviour. Defence cannot remain at human speed. As attacks become increasingly automated, organisations will need defensive systems capable of detecting, containing and responding at machine speed. Trust in autonomous security must be earned. Rik identifies four essential conditions for trusted autonomy: Context: Decisions must reflect the asset, its dependencies, its business importance and the wider environment. Constraint: Autonomous actions must remain within clearly defined boundaries and guardrails. Reversibility: Defensive interventions must be capable of being rapidly undone when they cause unintended consequences. Transparency: Operators must understand why a decision was made, which data informed it and what the potential impact will be. Human oversight must be meaningful. Simply placing a person at the end of an automated process does not guarantee safety. Over-reliance on automation can reduce vigilance and leave people less capable of intervening when intervention matters most. Paper we discussed during the episode: https://www.forescout.com/resources/wp-assume-autonomy/

    • Transcript
  • S2 · E28
    July 14 · 1 hr 1 min

    Leadership Without a Script with Stefan Pagels Christensen

    Stefan Pagels Christensen became a child star at 11, working on major film productions while most children his age were still figuring out who they were. Early fame brought attention, pressure and opportunity but it also distorted his sense of identity, value and belonging. In this candid conversation, Stefan opens up about addiction, sobriety, ADHD and the experience that forced him to rebuild his life without status or recognition. He explains how discovering improvisation gave him a new way to understand failure, trust, communication and human connection. Today, Stefan uses applied improv, emotional intelligence and psychological safety to help leaders create teams where people feel confident enough to contribute, challenge ideas, make mistakes and speak openly. This is a conversation about what happens when the script disappears—and why the strongest leaders are not those with all the answers, but those who make the people around them better. Key Takeaways • Early success can shape self-worth in ways that take years to recognise and unlearn. • ADHD can drive creativity, intensity and hyperfocus, but without the right support it can also contribute to burnout and destructive behaviour. • Psychological safety begins with how leaders respond when someone speaks up, challenges an idea or makes a mistake. • “Yes, and” does not mean agreeing with everything. It means listening fully before rejecting or building on an idea. • Teams perform better when people stop judging themselves, stop judging others and become willing to experiment. • Failure becomes valuable when it is treated as information rather than something to conceal. • Great leadership is not about being the star of the scene. It is about making other people look good. • Meaningful change begins when you stop blaming the environment and accept responsibility for your own behaviour. Soundbites “Leadership is improvisation. None of us knows exactly what comes next.” “Success lies somewhere between doing nothing and failing.” “Every time someone speaks up, they have already overcome their own fear.” “Your job is not to be the star. Your job is to make other people look good.” “Psychological safety is created by how you respond when someone gets it wrong.” “You cannot change until you are willing to admit that something needs to change.” “People do not learn courage by reading about it. They learn it by stepping forward.” “Failure is not something to hide. It is something to recover from.” “Say yes to the person before you judge the idea.” “The strongest teams are not afraid of mistakes—they know how to use them.” You can find Stefan at: https://improv.eu/ Find Stefan on LinkedIn: https://www.linkedin.com/in/stefanpagelsimprov/

  • S2 · E27
    July 12 · 45 min

    Harvest Now, Litigate Later Quantum Exposure with Darren Bender

    In this episode of the Entropy Podcast, Francis Gorman sits down with Darren Bender, a Texas-based attorney, chief legal officer, and co-founder working at the intersection of law, IT, and post-quantum cryptography. The conversation explores a question many boards, legal teams, and security leaders are only beginning to face: when quantum computers threaten today’s encryption, who becomes liable for doing nothing? Darren breaks down post-quantum negligence in practical terms, explaining why “we didn’t know” may not be a credible defence for much longer. From Harvest Now, Decrypt Later attacks to board minutes, data shelf life, migration timelines, DORA compliance, procurement decisions, and third-party liability, this episode reframes quantum readiness as more than a technical challenge. It is a governance issue. A legal exposure issue. A fiduciary duty issue. And potentially, a future courtroom issue. Key Takeaways Post-quantum cryptography is no longer just a cybersecurity concern; it is becoming a boardroom and legal risk conversation. Organisations may need to show how they assessed quantum risk, prioritised critical data, and documented informed decisions. Board minutes, governance records, risk assessments, cryptographic inventories, and migration plans could become central evidence in future litigation. “Cryptographic procrastination” may become difficult to defend if organisations knew about the risk but chose not to act. The Mosca theorem helps boards think about whether their data shelf life plus migration time exceeds the timeline for a cryptographically relevant quantum computer. The Learned Hand formula offers a legal lens for comparing the burden of prevention against the probability and magnitude of future harm. Financial services, healthcare, energy, and critical infrastructure may be among the first sectors exposed to post-quantum liability. DORA and similar regulatory frameworks may create either a defensive treasure trove or a litigation minefield, depending on the quality of the paper trail. Supply-chain liability will be complex, with SaaS providers, cloud providers, HSM vendors, certificate authorities, and customers all potentially pulled into the same dispute. Procurement teams should start asking not just whether vendors are secure today, but whether they can support post-quantum migration tomorrow. Soundbytes “Quantum risk is moving from the server room to the boardroom.” “Harvest Now, Decrypt Later may become Harvest Now, Litigate Later.” “The question is not just whether encryption breaks. It is who knew, who acted, and who documented the decision.” “In a future lawsuit, the paper trail may matter as much as the technology.” “Cryptographic procrastination is not a strategy.” “Doing nothing may be the most expensive decision a board ever makes.” “Post-quantum readiness is not a light switch. It is a long fuse with a big boom at the end.” “If your data still has value when quantum arrives, your risk clock has already started.” “DORA can be a treasure trove or a minefield. It depends what your records show.” “Your vendors may hold the keys, but your organisation may still hold the liability.” “Quantum readiness is no longer just about algorithms. It is about governance, accountability, and foreseeable harm.” “The courtroom may become the place where quantum risk finally gets priced.”

  • S2 · E26
    July 6 · 40 min

    Is Your Cyber Recovery Plan Just Fiction? with Francesco Chiarini

    In this episode of the Entropy Podcast, Francis Gorman speaks with Francesco Chiarini about why cyber resilience must go far beyond traditional cybersecurity, backups, and compliance checklists. Francesco breaks down the uncomfortable reality that many organisations are not as recoverable as they think. From ransomware spreading at scale to compromised identity systems, encrypted tooling, failed assumptions, and board-level misunderstandings, this conversation explores what really happens when the worst-case cyber scenario becomes real. The discussion covers cyber resilience versus cybersecurity, APT-grade attacks, out-of-band communications, crisis operating models, data vaulting, DORA, recovery planning, minimum viable organisations, and why resilience has to be designed before disaster strikes. This is a direct, practical conversation about building organisations that can continue operating when the normal playbook no longer works. Key Takeaways Cyber resilience is not the same as cybersecurity. Cybersecurity focuses heavily on prevention and protection; cyber resilience asks whether the organisation can still operate, recover, and adapt when prevention fails. Backups alone do not equal resilience. Francesco warns that recovery depends on architecture, governance, people, tooling, identity, sequencing, and validated operating models not just stored copies of data. Organisations need to stress-test their assumptions of recoverability. If Active Directory, communications, patching tools, or recovery platforms are compromised, the real question is: what still works? Boards often misunderstand resilience as a technology problem. Francesco argues that technology matters, but cyber resilience also requires clear accountability, capability maturity, skilled teams, and rehearsed decision-making. Cyber recovery investment is often too low. Many organisations spend heavily on prevention, detection, and protection, while underinvesting in recovery capabilities and last-resort operating models. Data vaulting and isolated recovery are essential, but incomplete on their own. They must sit inside a wider cyber resilience strategy that includes threat modelling, minimum viable operations, interoperability, deception, and recovery sequencing. Soundbytes “Your cyber recovery plan is only real if it still works when everything around it has failed.” “Backups are not resilience. They are only one piece of the survival plan.” “The worst time to design recovery is during the incident.” “Cyber resilience starts where cybersecurity assumptions break.” “If your identity stack, tooling, and communications are gone, what still works?” “Being compliant does not mean being resilient.” “Recovery is not just a technology problem. It is an organisational capability.” “Most companies know how to prevent. Far fewer know how to restart.”

  • S2 · E25
    July 5 · 35 min

    When AI, Crypto, and Quantum Collide with Dinesh Nagarajan

    In this episode, Francis Gorman speaks with Dinesh Nagarajan, Global Partner with IBM Consulting Cybersecurity Services and IBM’s global lead for data and AI security and quantum-safe security, about the collision of three major enterprise shifts: AI adoption, cryptographic modernisation, and post-quantum readiness. Dinesh argues that AI will likely be the most consequential transformation because securing AI at enterprise scale depends on trust, and that trust ultimately depends on cryptography. The conversation explores why many organisations still treat AI security, cryptography, and quantum readiness as separate programmes, even though they are becoming deeply interconnected. Dinesh explains that AI has captured attention from the boardroom to engineering teams in a way few previous technology waves have, which gives it momentum, budget, and organisational visibility. But that same momentum creates risk if security, cryptographic resilience, and post-quantum planning are not built into transformation programmes early. The discussion then moves into sovereign AI, geopolitical dependency, and the enterprise risk of building core workflows on platforms that may become unavailable due to political, regulatory, or commercial decisions. Dinesh frames this as a strategic consideration for businesses, especially when AI tools become central to software development, automation, and competitive advantage. The second half of the episode focuses on post-quantum cryptography. Dinesh outlines how organisations should approach quantum readiness: start with awareness, assess exposure from the board level down, establish a centralised programme or centre of excellence, and embed post-quantum requirements into procurement, legal, supply chain, architecture, and existing digital transformation initiatives. His core message is that PQC is not a one-off technical remediation exercise; it is a multi-year business transformation that must be governed as a strategic risk. Key takeaways AI security is becoming a cryptography problem AI at enterprise scale requires mechanisms to validate, verify, and trust agents, applications, and workflows. That trust layer depends on cryptography. AI, crypto modernisation, and quantum readiness cannot stay separate Many organisations currently treat them as three different programmes, but Dinesh expects them to converge quickly as AI infrastructure becomes dependent on cryptographic trust. AI has unusual organisational momentum Unlike previous technology waves, AI has captured attention from the C-suite down to engineers. That visibility can help fund and accelerate security work, including parts of the post-quantum journey. Sovereign AI is becoming a serious boardroom issue Enterprises need to consider what happens when a critical AI platform is restricted, withdrawn, or affected by geopolitical decisions. Quantum readiness is not just an IT issue PQC affects contracts, procurement, suppliers, cloud strategy, infrastructure, applications, data, and long-term transformation plans. Boards need business-risk language, not cryptography language Dinesh’s recommendation is to frame quantum exposure as strategic risk: revenue disruption, transformation risk, cost escalation, technical debt, and operational fragility. The first move is not scanning; it is understanding exposure Crypto inventory matters, but Dinesh argues the starting point should be a top-down view of how exposed the business model is to quantum-related disruption. A centralised PQC capability is essential Organisations need a programme team or centre of excellence that can create awareness, set direction, advise functions, and coordinate action across the enterprise. Existing transformation programmes should pay the “quantum tax” Rather than spinning up everything from scratch, organisations should embed PQC requirements into cloud migrations, digital modernisation, procurement cycles, and supplier renewals. PQC is a five-to-six-year journey for many enterprises Dinesh describes quantum readiness as a long-running transformation, not a vulnerability patching exercise. Soundbites These are polished for promotion and clips rather than strict verbatim transcript pulls. “AI security is ultimately a trust problem and trust still comes back to cryptography.” “The organisations that treat AI, crypto, and quantum as separate programmes are going to feel the collision later.” “AI has done something unusual: it has captured the imagination of the boardroom and the engineer at the same time.” “If every employee is going to use AI, then cryptography has to scale to that same level of adoption.” “Post-quantum readiness is not a technology change. It is a business transformation.” “The board does not need a lecture on algorithms. It needs to understand exposure, disruption, and strategic risk.”

  • S2 · E25
    June 28 · 39 min

    Why Artificial Intelligence Needs a Mother with Lucy Batley

    In this episode of The Entropy Podcast, Francis Gorman sits down with Lucy Batley AI strategist, speaker, and founder of Traction Industries, named number eight in the UK's Top 100 Digital Leaders in AI in 2025 (recognised at the House of Lords). With a 30-year career spanning the birth of the internet designing for David Bowie, Audi, Barclays and the Manic Street Preachers Lucy now helps organisations adopt AI strategically, with strong governance and real business value. This is a conversation about why most AI investment fails to deliver, why the real barrier sits in the boardroom rather than the technology, and why the rush to deploy AI agents without securing the underlying data is heading for a reckoning. Lucy also introduces Mother, her new venture building AI on quantum-resilient infrastructure and makes the case that the most underestimated risk isn't superintelligence, but our growing dependency on the tools themselves. Key Takeaways AI is a leadership problem, not a technology problem. The organisations that win aren't the ones with the biggest budgets they're the ones whose leaders have the foresight to grasp how fundamental this shift is. Start with the human problem, not the tool. Most organisations don't even understand their own workflow processes. Design thinking and relentless questioning surface the real issue which is often smaller and easier to fix than anyone expected. ROI comes from strategy, not spend. One case study: six "AI colleagues" deployed for ~£500k returned ~£6.5M in ten months driven by an opportunity spotted in a workshop, not the technology itself. Security can't be an afterthought. Homegrown AI agents going into organisations without secured data are a backlash waiting to happen. Secure by design from day one. Quantum changes the game. With "harvest now, decrypt later" already underway and ~300 quantum computers in existence, quantum isn't theory. Mother's approach moves from algorithms and code to mathematics and physics protecting data without touching it. The real risk is dependency. Societies don't collapse because technology gets clever they collapse because they forget how dependent they've become. Stay human. AI has no experience, no conscience, and no emotion. The advantage lies in the things that make us human and using the tools to amplify them. Soundbites "Artificial intelligence is not a technology problem, it's a leadership problem." "It's a technology so profound that everything else is going to have to be redesigned around it." "Forget about the technology — what human problems are you trying to solve?" "Societies rarely collapse because a technology becomes clever. They collapse because they become vulnerable." "Artificial intelligence needs a mother. It needs protecting." "We're moving away from algorithms and code to mathematics and physics. It's a completely different beast." "Good leader, good organisation. Bad leadership, absolute chaos." "We're literally in the toddler stage."

  • S2 · E24
    June 21 · 41 min

    SuperSkills for the AI Age with Rahim Hirji

    In this episode, Rahim Hirji discusses the evolving nature of intelligence, the importance of human skills in the age of AI, and how to adapt our education and mindset for the future. Discover insights on judgment, taste, curiosity, and the impact of AI on decision-making. This is one of those episodes that will have you questioning decisions you have made as your week unfolds. Key Topics: The commodification of intelligence and its impact on value The importance of taste, judgment, and accountability in a world of abundant AI The concept of synthetic seniority and the blending of old and new wisdom Future skills needed for humans to thrive alongside AI The role of curiosity, boredom, and creativity in human development The risks of over-dependence on AI and algorithms Reimagining education to focus on soft skills and super skills The importance of questioning and understanding decision-making algorithms Practical self-assessment tools for future readiness Sound Bytes: "Taste, judgment, accountability are valuable now" "Talking to machines feels disingenuous" "Many decisions are made for us by algorithms" Check out the book: https://superskillsbook.com/ Check out the diagnostic tool: https://superskillsbook.com/diagnostic/ Check out Rahim’s site: https://www.thesuperskills.com/

  • S2 · E22
    June 14 · 40 min

    Strategic Compression with David Murrin

    Geopolitical forecaster and strategist David Murrin joins Francis Gorman to argue that the world isn't experiencing ordinary volatility it's in the middle of a deep, structural transition between great powers. Drawing on his "Five Stages of Empire" framework, David lays out why he believes America's decline began after 9/11, why China is rising into the vacuum, and why he sees the next decade as a period of unavoidable escalation. The conversation ranges across the war in Ukraine, the Iran nuclear question, the battle for the Pacific, the hollowing-out of Western military capability, and the subtler war being fought through economics, infiltration, and influence. It closes on Ireland's exposure as a neutral state and David's blunt verdict that there is "nowhere to hide." Key Takeaways David's "Five Stages of Empire" model frames how nations regionalise, fight a civil war, expand, peak, and decline and where he places the West today. His view that American power entered structural decline after 9/11, with China rising to fill the vacuum. The concept of "strategic compression" why rising powers are forced to act not when they choose, but when the window around them starts to close. Why he sees Ukraine and Iran as conflicts enabled and shaped by China, used as testing grounds for systems and tactics. His argument that Western societies are being degraded from within through long-running influence operations targeting domestic politics. A stark assessment of UK military readiness, and why he believes adaptability not hardware alone decides who survives modern conflict. What all of this means for a small, neutral, strategically significant state like Ireland. Soundbites "Nature absolutely abhors a vacuum. It hates it." "It's as if we're playing draughts and the Chinese are playing three-dimensional chess." "The timing of hegemonic conflicts is never at the choosing of the hegemon." "There are no neutral countries in its story, so there are no places to hide." "Stand up and be counted." Note: This episode contains forecasting and personal analysis that is, by nature, speculative and at times contested. These are David Murrin's own views, shared to open debate rather than to state fact.

    • Transcript
  • S2 · E21
    June 8 · 46 min

    The Reinvention Mindset with Aidan McCullen

    In this episode, Francis Gorman speaks with Aidan McCullen, host of "The Innovation Show" and author of "Undisruptible", about reinvention, innovation, and what real change demands. Aidan reflects on his journey from professional rugby to becoming one of Ireland’s leading voices on transformation, sharing lessons from injury, identity, curiosity, and hundreds of conversations with world-class thinkers. Together, they explore why people and companies often wait until crisis hits before adapting, why superficial change rarely works, and why mental models must shift before business models can. From Nokia’s failure to respond to the iPhone to the personal grief of letting go of an old identity, this conversation is about preparing for change before it is forced upon you and finding the resilience to build what comes next. Key Topics: The importance of mental models in change The analogy of the caterpillar and butterfly in transformation The role of curiosity in innovation Lessons from Nokia's decline and failure to adapt The concept of creative destruction and proactive change Sound Bytes: "You can't waterboard a horse." "Snow always melts from the edges." "You can't force a horse to water." You can find Aidan's book here: https://www.kennys.ie/shop/-9781119770480

    • Transcript
  • S2 · E21
    June 1 · 38 min

    The World's First Hackocracy With Geoff White

    In this episode of The Entropy Podcast, Francis Gorman sits down with British investigative journalist, author and BBC podcaster Geoff White to go inside the world of organised cybercrime and the regimes that increasingly depend on it. Geoff has spent years embedded in the underbelly of the cyber economy, from ransomware syndicates to state-sponsored hacking operations, and he brings a working journalist's eye to questions most security professionals only ever see from the defender's side. The conversation opens by dismantling the hoodie-in-a-basement myth: ransomware groups like Conti are run as businesses, with HR functions, payroll, performance management, customer support teams, and an obsession with professional polish. Geoff walks through what the leaked Conti messages reveal about how these organisations think of themselves including the striking self-description of their work as "postpaid penetration testing." The conversation then turns to North Korea, where Geoff lays out the case for what he calls a "hackocracy" — a regime increasingly funded by computer hacking. Drawing on US government estimates and his own analysis, he explains how cryptocurrency theft is keeping the North Korean state afloat, why sanctions are losing their bite, and why this should worry anyone who relies on the global supply chains that pass through the Korean peninsula. Francis and Geoff also dig into the moral and practical reality of the "don't pay the ransom" position, the weaknesses that still let attackers in, and the systemic role of money laundering as the unspoken second half of every major cybercrime story. The episode closes on the most timely thread: AI as an inherently deceptive technology. Geoff makes the case that systems like ChatGPT are designed from the ground up to fool users into thinking they're human and that this design philosophy has serious implications for the next generation of social engineering attacks. The conversation ends with a frank exchange on Anthropic's recent walk-back of its core safety commitments and what it signals about the industry's direction. Key Takeaways Ransomware gangs run themselves as businesses, not basements. The economics of ransomware are extraordinary. Money laundering is half the story. North Korea is becoming a hackocracy. A national ban on ransom payments would work eventually. . Humans are still the attack surface and AI makes that worse. Soundbites "In order to earn the kind of money that Conti was earning, the average Russian would have had to work for 400 years. So in a single ransom, you can make not just your life's money, but the money for the life of all of your family around you as well." — Geoff White "Within the next five to ten years, North Korea could become the world's first hackocracy — a regime entirely funded by computer hacking." — Geoff White "Our world is not being run by lovely rational AI. It's human beings who are deciding what happens." — Geoff White

    • Transcript
  • S2 · E20
    May 25 · 32 min

    The Comfortable Lies of Cybersecurity with Adam McElroy

    In this episode of The Entropy Podcast, Francis Gorman speaks with Adam McElroy, CTO at Eclypses, about cybersecurity, storytelling, AI, post-quantum readiness, and the evolving role of security leadership. Adam argues that modern cyber leaders must move beyond technical reporting and learn to communicate risk in ways boards and executives can act on. The conversation explores why security decisions in large enterprises take time, how AI is accelerating existing technical debt and governance gaps, and why quantum risk is no longer something organizations can comfortably defer. Adam frames post-quantum readiness as a generational risk comparable to Y2K: manageable if organizations plan early, potentially damaging if they procrastinate. A central theme is that cybersecurity is no longer just a technology problem. It is a business resilience issue involving boards, executives, architects, regulators, CISOs, CIOs, CTOs, and risk leaders. Adam also challenges the industry’s reliance on perimeter defence, arguing that organizations need to think more seriously about making data unusable if it is exfiltrated. Key Takeaways Storytelling is now a core cybersecurity leadership skill. Cybersecurity is business, not a separate technology function. AI has exposed existing technical debt faster than expected. Zero Trust is still valid, but there is no silver bullet. Organizations should assume breach and protect the data itself. “Harvest now, decrypt later” is a present-day risk. Quantum procrastination is becoming indefensible. The CISO cannot carry cyber risk alone. AI adoption needs policy, education, and discipline. Soundbytes "There is no such thing as business and technology. It’s all business at the end of the day." “AI wasn’t built to be secure, it was built to be amazing.” “The CISO cannot protect the organization by themselves.” “The dashboard will never be green in my world.”

    • Transcript
  • S2 · E19
    May 19 · 42 min

    Quantum Readiness: The Risk No One Owns with Louise Davey

    In this episode of Entropy, Francis Gorman speaks with Louise Davey, executive leader, transformation architect, and author of Quantum How, about why quantum readiness has to move beyond the technology function and into the boardroom. Louise argues that post-quantum cryptography is no longer just a cryptography, standards, or cybersecurity discussion. It is an enterprise governance and transformation challenge that affects digital trust, operational resilience, fiduciary duty, regulatory exposure, insurance, systemic financial risk, and long-term business viability. The conversation explores why boards and executive leaders often struggle to act on quantum risk, not because the threat is unclear, but because it is poorly communicated. Louise explains how quantum risk breaks traditional risk models: it is time-shifted, has unclear ownership, spans the entire digital infrastructure layer, and reaches far beyond any single technology team. The episode also covers the real-world consequences of unreadiness, from harvest-now-decrypt-later exposure to operational technology, financial services, elevators, pacemakers, insurance risk, liquidity impact, and corporate survival. But the conversation is not only about risk. Louise also makes the case that quantum readiness can be used as a once-in-a-generation transformation opportunity to reduce technical debt, strengthen governance, improve enterprise intelligence, and create lasting organisational value. Takeaways: 1. Quantum readiness is now a boardroom issue. Louise makes the case that post-quantum security has moved beyond the technical layer. It now belongs in enterprise governance, risk management, transformation strategy, and board oversight. 2. The communication gap is one of the biggest blockers. The people who understand the quantum threat are often technologists, while the people who control funding, risk appetite, and enterprise priorities are boards and executives. The challenge is translating the issue into language decision-makers can act on. 3. Traditional risk models do not handle quantum risk well. Quantum risk does not fit neatly into standard operational risk taxonomies. It is time-shifted, systemic, infrastructure-level, and difficult to assign to a single owner. 4. Digital trust may be the real asset at risk. The episode repeatedly comes back to trust. Cryptography underpins authentication, authorisation, privacy, financial transactions, customer confidence, and the resilience of modern digital business. 5. Harvest-now-decrypt-later is already a live issue. Louise stresses that quantum risk is not purely future-facing. Sensitive data may already be exposed if adversaries are collecting encrypted information today to decrypt later. 6. Boards need to understand their fiduciary exposure. If boards are made aware of the scale of the risk and still fail to act, the issue becomes one of governance failure and fiduciary responsibility. 7. This is bigger than IT and cybersecurity. Quantum risk affects financial services, insurance, operational technology, manufacturing, logistics, public safety, and the physical systems connected to digital infrastructure. and many more.... SoundBytes: “The people who understand the problem often are not the people who own the decision.” “Quantum risk challenges the way organisations think about ownership, accountability, and authority.” “Digital trust does not belong to one function. It belongs to the organisation as a whole.” “The board is the only place high enough to own a risk of this scale.” “This is not just about avoiding risk. Done properly, quantum readiness can create long-term enterprise value.”

    • Transcript
  • S2 · E18
    May 11 · 40 min

    Smarter Cyber Strategy with Leonard McAuliffe

    This episode focuses on what real cyber strategy looks like versus the outdated “framework + gap analysis” approach. Leonard McAuliffe PWC explains that most organizations confuse activity with strategy focusing on compliance, maturity scores, and annual plans instead of aligning cybersecurity to actual business risk. The conversation reframes cyber strategy as a business-aligned, risk-driven, continuously evolving discipline. It emphasizes understanding stakeholder priorities, mapping real threats to controls, and treating strategy as a living system that adapts to AI, geopolitics, and changing attack surfaces. Takeaways: 1. Most “Cyber Strategies” Aren’t Strategies They’re annual roadmaps or compliance exercises Built around frameworks (NIST, ISO) instead of business risk Improve maturity—but don’t necessarily reduce real risk 2. Strategy Must Start With the Business Engage CEO, CFO, CIO, CRO—not just security teams Understand risk appetite and critical processes Align to IT, digital, and AI strategies 3. Focus on Risk → Threats → Controls (Not Maturity Scores) Define key cyber risks (e.g., business disruption) Map threat scenarios (e.g., ransomware via phishing) Link to controls and measure effectiveness 4. Strategy is a Living System Must evolve with: AI Threat intelligence Regulatory changes Business shifts 5. Prioritization = Risk + Cost Trade-Off You can’t do everything Decisions must be explicit: What risk are we accepting? What exposure remains? 6. Regulation Shouldn’t Drive Strategy Constantly reacting to new regs derails focus Instead: Build a strong master control framework Map regulations onto it Soundbites: “Most cyber strategies look good on paper but don’t manage real risk.” “You’re improving maturity, not reducing risk.” “Cyber can’t operate in a bubble it has to enable the business.” “If you don’t fund it, you’re accepting the risk. It’s that simple.” “Boards don’t care about maturity levels they care about real threats.”

    • Transcript
  • S2 · E17
    May 4 · 50 min

    How to Recruit a President with Glenn Carle

    In this episode of The Entropy Podcast, Glenn Carle a former CIA clandestine officer with over two decades of experience breaks down how intelligence agencies think, operate, and influence outcomes over the long term. Drawing on real-world tradecraft, Glenn explains how vulnerabilities are identified, how influence is cultivated, and how narratives are seeded and amplified over time. The conversation explores the growing tension between intelligence institutions and political power, the risks facing democratic systems, and how modern geopolitics is increasingly shaped by information warfare and perception management. The discussion also ventures into controversial territory examining the possibility of long-term influence operations at the highest levels of power while highlighting the difference between evidence, interpretation, and hypothesis. This is a conversation about how power actually works beneath the surface and what happens when institutions designed to protect truth are put under pressure. Takeaways: Intelligence is about patterns, not events Influence is often long-term and indirect Vulnerability ≠ control Institutions are under pressure Information warfare shapes reality The line between analysis and speculation matters SoundBytes: “In intelligence, there are no coincidences only patterns you haven’t understood yet.” “You don’t recruit someone in a moment you shape them over time.” “Every strength can become a vulnerability in the right context.” “If telling the truth costs you your job, the system stops working.” “You don’t need the truth you need enough repetition to make something feel true.” “The most effective operations are the ones no one notices—until it’s too late.” “Understanding how something could happen is not the same as proving that it did.” This conversation explores complex and often controversial geopolitical themes from the perspective of a former intelligence officer. Some views expressed particularly around long-term intelligence operations and political influence reflect interpretation and professional judgement rather than independently verified public conclusions. Listeners are encouraged to engage critically and consult additional sources where appropriate.

  • S2 · E16
    April 27 · 32 min

    One Click to Collapse: The SME Risk with Robert Maxwell

    In this episode of the Entropy Podcast, Robert Maxwell (CEO of TGT Solutions) reframes cybersecurity from a technical concern into a core business risk especially for small and medium-sized enterprises (SMEs). He argues that cyber threats are fundamentally about cash, trust, and continuity, not just systems. A single compromised credential or phishing attack can dismantle years of work in minutes, particularly in SMEs where operations often depend on one person, one account, or one set of credentials. Maxwell introduces a key mindset shift: cybersecurity is an investment, not an expense. Like building a portfolio, incremental and consistent investment in cyber resilience pays dividends protecting revenue, relationships, and long-term business viability. The conversation also explores human vulnerability as the dominant attack vector, the risks introduced by AI adoption, and why attackers prioritize ease over sophistication. Ultimately, the episode highlights a stark reality: it’s no longer “if” a business is attacked, but “when” and how prepared it is when that moment comes. Key Takeaways: 1. Cyber is now a business problem, not an IT problem It directly impacts cashflow, supplier relationships, and customer trust—not just systems. 2. SMEs are disproportionately vulnerable Reliance on single accounts, single individuals, and weak password practices creates critical single points of failure. 3. Attackers prioritize ease, not scale or sophistication The simplest entry point—often human—is the most exploited. 4. “Too small to hack” is a dangerous myth Smaller firms are often easier targets and valuable entry points into supply chains. 5. Cybersecurity must be treated as an investment Incremental improvements (policies, training, redundancy) generate long-term “dividends” in resilience. 6. Human behavior is the biggest risk surface Phishing, credential reuse, and lack of policy enforcement remain dominant vulnerabilities. 7. AI is amplifying exposure Organizations are unintentionally leaking sensitive data through unmanaged AI usage. 8. External validation is critical Internal reviews often miss risks—independent assessments reveal blind spots. 9. Banks and institutions are shifting liability Poor cyber hygiene increasingly results in unrecoverable financial loss. 10. Timing matters Fixing issues after a breach is exponentially more expensive than proactive investment. Soundbites: “Cyber isn’t a technical issue anymore—it’s about cash.” “You can lose trust, cash, and credibility in under a minute.” “It’s not ‘if’ you get attacked—it’s ‘when’ and ‘how much they take.’” “One person, one password, one account—that’s all it takes.” “Attackers don’t look for the biggest target—they look for the easiest one.” “We were too busy… until we got hacked.” “Cybersecurity isn’t an expense. It’s an investment that pays dividends.” “The password they stole six months ago? It still works—that’s the problem.” “AI is making companies more vulnerable—and they don’t even realize it.” “You’re building a business for generations—cyber can erase it in minutes.” You can learn more about TGT solutions from their website: https://www.tgtsolutions.com/

    • Transcript
Showing 1–20 of 21 episodes