The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack – in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes.
Key Takeaways:
1Ransomware attacks remain similar in strategy, but have become more industrialized in recent years.
2Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors.
3An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks.
Tune in to hear more about:
1Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33)
2The impact of AI on ransomware attacks (13:52)
3How money laundering is changing (17:03)
Standout Quotes:
1“I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White
2“I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White
3“Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve returns to Business Matters with Juliette Foster. In this conversation, Steve recaps 2025 in cyber and shares what he sees as the biggest risks heading into 2026. The two also discuss resilience and compliance, as well as the growing importance of togetherness among businesses.
Key Takeaways:1Companies would be wise to conduct frequent cyber audits.
2Supply-chain disruptions can have long-lasting, reputational effects.
3How we protect the integrity of our data is at the core of cybersecurity.
Tune in to hear more about:1The relationship between government business in cyber (12:56)
2How boards should plan for a cyber attack (15:40)
3Collaborating within and across industries (22:24)
Standout Quotes:1“I've said many times that good compliance doesn't equal good security, but good security does equal, nine times out of 10, very good compliance. So where do we go with all of that? I do think that we're probably getting to a point, sadly, where we need to be viewing some of the security processes that we need to undergo in the same way as we consider financial audits.” - Steve Durbin
2“I think that the day is gone when you can rely on your defenses. So boards have to be planning for the day when the defenses fail. When an attack really starts to make an impact on your business. The starting point is to figure out how long you can be without your systems. It may sound like a strange thing to say, but that's the important starting point for me.” - Steve Durbin
3“Security is not, in my opinion anyway, a competitive advantage. And because it's not a competitive advantage, there shouldn't be this massive barrier to sharing some of the ideas, some of the attacks that are out there for the good of the industry.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around.
Key Takeaways:1Identity must be treated as a strategic risk.
2When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice.
3Choosing robust but user-friendly technology is important for attracting and retaining new talent.
Tune in to hear more about:1The deepfake challenge (6:14)
2Automated identity governance (8:33)
3Empowering a culture of trust through identity strategy (12:20)
Standout Quotes:1“I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee
2“There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee
3“The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve returns to Business Matters with Juliette Foster. The United Kingdom has a new Prime Minister: Andy Burnham, and Steve speaks with Juliette from a cyber and business perspective about what to expect from the nation's new leadership. They also discuss the importance of digital inclusion, what businesses should do to remain in control in times of uncertainty, cyber insurance, and more.
Key Takeaways:
Tune in to hear more about:1. The importance of digital inclusion (4:17) 2. Solving the cyber skills shortage (20:29) 3. How cyber insurance is changing and why it matters (22:58)
Standout Quotes:1. “For a lot of people, digital inclusion means handing people a smartphone and saying, “There you go.” It isn't just about access, it's about the knowledge that you need to actually make use of the technology that you have access to.” - Steve Durbin 2. “You want to try to maintain a solid state in between somebody saying they're going to make the acquisition and take you over, and when that completes. [...] Because the resilience is core to the effectiveness going forward of that organization. All too often, there's a tendency to fiddle with it, play with it a little bit. No. We need to understand exactly what our core components are, the crown jewels, how are we protecting them, how are they going to be impacted over a certain period by any change that goes on, and what can we do to make sure that we're doing everything possible to preserve the integrity of those crown jewels so that we can continue to operate. The last thing you want is somebody coming in and actually changing that during a handover period.” - Steve Durbin 3. “From a cyber-specific perspective, one of the things that has infuriated me constantly over the years is this obsession that we seem to have that people have to be trained in the technical skills in order to have a cyber career. That is absolute nonsense. Because the sorts of skills that you need could equally be well found with people with arts degrees. It's that curiosity. It's that ability to be able to be creative.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack – in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes.
Key Takeaways:
Tune in to hear more about:1. Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33) 2. The impact of AI on ransomware attacks (13:52) 3. How money laundering is changing (17:03)
Standout Quotes:1. “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White 2. “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White 3. “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around.
Key Takeaways:
Tune in to hear more about:1. The deepfake challenge (6:14) 2. Automated identity governance (8:33) 3. Empowering a culture of trust through identity strategy (12:20)
Standout Quotes:1. “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee 2. “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee 3. “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve speaks with James Wilkson, managing partner at AEC Global Search Consultants, an executive search and advisory firm. James and Steve discuss why today’s leaders must be flexible and emotionally intelligent, who belongs in today’s boardrooms, and how leaders can protect their personal brands online. Steve also asks James to look into the crystal ball.
Key Takeaways:
Tune in to hear more about:1. Managing different generations in the workplace (4:18) 2. How boards can upskill (12:31) 3. What will surprise leaders a year from now (18:29)
Standout Quotes:1. “I think AI, without a doubt is going to continue to accelerate and alter how we think, but just like anything else, it's just going to be an extremely robust tool down the line.” - James Wilkson 2. “And leaders today, the leaders that are well-trained at being able to relate across generations and across technology are the ones that are going to continue being the leaders, and they're going to hone the next leadership team. The ones that are resistant and the ones that are frustrated, they're just not going to sustain leadership roles that much longer.” - James Wilkson 3. “It's just a massive tsunami of discussion about AI and how it's going to change everything, and it is, but I think we're only going to briefly be led by this loss of work purpose, this loss of what... I think companies right now, the reason there's such a holdback on what do we do? We really slowed down hiring, are the entry level jobs all going to be gone? Yes, probably briefly because we're having a reaction, a knee-jerk reaction, but I think we're going to quickly find out that this is going to bring about a lot of different opportunity. So I think we'll plateau for a while, and then we'll begin utilizing humans in different roles that are still the same role that's just adapted itself to what technology has brought for us.” - James Wilkson
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve sits down with Stephanie Forbes, CEO of the Forbes Group. Stephanie is a supply chain expert who recently released Global Wealth, Local Impact: How Supply Chains Build Thriving Companies, Cultures, and Countries, a book about building supply chains using lessons from our past. She and Steve discuss what she learned in her research for the book and supply chain management principles leaders can rely on in these unsteady times. Stephanie also gives advice for small and medium-sized businesses, how to manage supply chain issues across departments, and digital risk management.
Key Takeaways:
Tune in to hear more about:1. What history teaches us about how we manage societies (2:08) 2. How supply chains will change over the next five to ten years (10:25) 3. The three questions boards should ask to secure their supply chains (25:58)
Standout Quotes:1. “If I'm only a couple of people, 10 people, then I'm probably not going to bring in a full-scale audit unless I'm importing a lot of goods, unless I have a really big tariff bill, and then it's probably worth it for me to take a look at that. So you're going to want to cherry pick the things that are really important.” - Stephanie Forbes 2. “It's going to become very difficult, I think, in another five, 10 years to buy anything that doesn't have a full life -cycle knowledge, awareness or paper trail. And that's gonna be all the way down to the ink or the physical ore, all that kind of stuff.” - Stephanie Forbes 3. “The more as a leader in your organization that you can really encourage and foster that cross-functional collaboration between your operations and whether it's procurement, supply chain, even finance, to really make sure everyone's talking the same language, it becomes a huge competitive advantage, especially when things are changing so rapidly.” - Stephanie Forbes
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve speaks with Dustin Dobbyn, an internationally recognized security expert, Marine Corps veteran, former SWAT operator, and the CEO of a fast-growing private security and executive protection firm. The two discuss management under pressure, the value of training and preparation, and awareness of supply chain risk. Dustin also makes the case for agility and flexibility in the workplace.
Key Takeaways:
Tune in to hear more about:1. Securing all levels of your supply chain (8:15) 2. A skill that veterans can bring to the cybersecurity industry (14:05) 3. Dustin’s resilience roadmap for the next five years (18:02)
Standout Quotes:1. “If you think you know it all, it's time to get out of the business.” - Dustin Dobbyn 2. “So we're seeing, especially in the corporate world for corporate security, a lot of people working remote on a flex schedule, and we're seeing a lot more productivity because of it. For leadership out there who's listening, absolutely just take that into consideration, as sometimes people work better at certain times of the day based on their schedule. And if you can get them in an environment where they're less stressed, you're going to get better work output out of them.” - Dustin Dobbyn 3. “Knowledge is power. Intelligence is what's going to keep you safe because if you have the intelligence, you're aware of what's going on, and you can prepare for worst-case scenarios.” - Dustin Dobbyn
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, one of our favorite guests returns: Peter Hinssen. A renowned keynote speaker, author and serial entrepreneur, Peter is one of the most sought-after thought leaders on radical innovation, leadership and the impact of all things digital on society and business. When Peter was last on the show, the world had just begun to recover from the Covid-19 pandemic, and generative AI was still in its infancy. This time around, Steve and Peter talk about the advancements of AI and what they mean for the C-suite, whether the tech companies have become too powerful, AI regulation, and the future of leadership. Peter also answers how we will remember this AI boom in 10 years.
Key Takeaways:
Tune in to hear more about:1. How to manage this era of volatility and constant change (3:30) 2. How leadership is changing (14:30) 3. Why small businesses might be better equipped to deal with the AI boom (21:06)
Standout Quotes:1. “We’re now in a world where the cycles move faster than ever before. The stakes are higher, and I think a lot of the instruments that we had from the past just don’t work anymore.” - Peter Hinssen 2. “The larger the company is, the more difficult it is to get that change going, and that’s why inherently smaller organizations have, I think, a competitive advantage because being agile, being nimble, and being resilient should be easier for a smaller company than a larger organization.” - Peter Hinssen 3. “When you look at the printing press moment, we had the industrialization of knowledge, where we went from monks transcribing books into an abundance of information, and then we had the Industrial Revolution, where we went from muscle to machine. I think this is where the two of them are coming together.” - Peter Hinssen
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve is in conversation with Betsy Cooper, director of the Aspen Policy Academy at the Aspen Institute. As an expert in cyber and tech policy, Betsy shares her thoughts on how policymakers can keep pace with the rapid developments in AI and quantum technology, building a futureproof compliance strategy, and AI risks. Steve and Betsy also discuss policymaking in a volatile world, how businesses can protect their image after a breach, and what can be done to get governments to care about online scams.
Key Takeaways:
Tune in to hear more about:1. Creating a “future-proof” compliance strategy (7:11) 2. Protecting your brand following a breach, data theft, or disinformation campaigns (13:35) 3. Trading access for personal information (22:31)
Standout Quotes:1. “I do think that it would be preferable to have one coherent framework. I think industry would benefit from that if we did have that sort of framework. But also, I'm not sure that we're at the level of sophistication today that we'd be able to write the best framework because we haven't experimented enough. So I actually think that having the state and local sort of sandboxes leading to future federal policy is not a bad approach.” - Betsy Cooper 2. “It's a very difficult thing to try to prove a negative, and that's why disinformation can be so powerful. But it's also a very fast-moving space, so the faster you can get in there with your counter-narrative, the more likely you are to be successful.” - Betsy Cooper 3. “I'm the mother of a five-year-old, and in order to get my five-year-old's baseball schedule, I have to download an app on my phone. There is no web access for the app that has the baseball schedule. So in order to get that baseball schedule, I have to sign away a whole bunch of privacy just to get my kid to a sports game. I think that shouldn't be allowed.” - Betsy Cooper
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s guest is Dr. Keith Morneau, an experienced cybersecurity professional who currently serves as Dean of Computer and Information Science at ECPI University. Steve and Kieth discuss the future of the cyber workforce, cyber education, and if AI is taking our jobs. Steve also asks Keith to step into the shoes of a CEO…
Key Takeaways:
Tune in to hear more about:1. How AI can help junior staff and those entering the cyber workforce (6:15) 2. Dr. Morneau’s ”prepare, practice, perform, assess” philosophy (13:23) 3. One obsolete role chief executives should stop hiring for, and one emerging role they haven't even thought about yet (21:15)
Standout Quotes:1. “We’re really still in the baby steps of AI, in the beginning stages of it. What I’ve noticed of a lot of folks, there’s AI there, but they’re not 100% understanding how it all works, how the AI actually has to be trained and all that. I think over time what we'll see is the increase in knowledge and skill set using AI for what they’re doing in their jobs should help with the bottom line over time.” - Dr. Keith Morneau 2. “The biggest issue in cybersecurity are the AI systems that are very vulnerable to attacks.” - Dr. Keith Morneau 3. “The type of person you need to look at is the person who’s able to use AI to do the job that you need them to be able to do better and faster, and be more efficient at it. What you have to be careful of is the people that are going to be obsolete are the ones that are basically fighting the AI and not using AI at all to help them, because that is pretty much they are going to be dinosaurs soon, if they’re not already dinosaurs.” - Dr. Keith Morneau
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve sits down with John “Jock" Brocas, a former military member who is now an executive mentor and strategic intuitive intelligence advisor to the C-suite. Jock is far from your typical cyber professional, but his experience working with executives gives him a compelling perspective on challenges faced in our industry. Steve and Jock discuss how we can train ourselves to block out the noise and become better at recognizing the real threats to our business, the value of mindfulness and managing stress, and why leaders must see the big picture. Jock also shares his thoughts on deepfakes, from the perspective of a medium.
Key Takeaways:
Tune in to hear more about:1. Discerning the signal from the noise () 2. How leaders can help their teams manage stress, both long-term and in acute situations () 3. Jock’s thoughts on deepfakes ()
Standout Quotes:1. “Logic and intuition are not separate. And this is the biggest mistake we make. We don't fail in making decisions, especially in the cyber world because of the amount of data we have. We fail at the discernment of maybe that data.” - Jock Brocas 2. “I think it’s important as well that looking at a more spiritual outlook to things, not religious in any way, a meditative or a contemplative side of things. And how many security professionals or cybersecurity professionals take time for themselves to actually even breathe in between doing something?” - Jock Brocas 3. “Discernment, even as a cyber professional, is important. So discernment of the self, discernment of the mind, that's important.” - Jock Brocas
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode might sound a little bit different, but it’s a really important conversation. Steve sits down with Emily Holyoake, co-founder of Not A Standard and the brain behind the FRAME Network, to talk about the human harm of cyber attacks, gender-based violence, tech-facilitated abuse, and diversity in the cybersecurity industry. Steve also asks Emily to envision the future of the cyber workforce, one that creates safety for society and people, not just machines and data.
Key Takeaways:
Tune in to hear more about:1. The SAFE Framework (1:57) 2. Why Emily pen-tests her personal life – and why you should, too (18:44) 3. Building a cyber workforce for a safer society (20:56)
Standout Quotes:1. “A person clicks on a phishing link that results in a breach. So we blame the individual instead of thinking what did the system, literally or figuratively, allow to happen that meant that person clicked on that link? But we think we've got to find the root cause. So we pick a human rather than thinking about what the system enabled.” - Emily Holyoake 2. “Every attack begins and ends with a human, fundamentally. In security, we talk so often about people being the weakest link. Fair enough, right? You can have all the technical controls in the world and it just takes one person to break that. But we wouldn't have this business, we wouldn't have this culture, we wouldn't have anything without these people. And so people are, if anything, our greatest asset.” - Emily Holyoake 3. “When you have a diverse group of people thinking about the same problem in different ways from different backgrounds, different experiences, you're going to get an infinitely richer understanding or solution to a problem.” - Emily Holyoake
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today we bring back one of our favorite guests: former US most-wanted cybercriminal Brett Johnson. It’s been seven years since he was last on the show, and much has happened in the world of cyber. Brett shares how his perspective has changed in the past few years, and gives his thoughts on how new technologies impact cyber crime. Steve and Brett discuss compliance and what Brett’s path from prison to helping law enforcement means for other cyber criminals. Brett also answers some rapid-fire questions.
Key Takeaways:
Tune in to hear more about:1. Why cybersecurity awareness training often fail (13:32) 2. If Brett’s path to redemption is still viable for today’s cyber criminals (16:57) 3. Some rapid-fire questions to Brett (21:35)
Standout Quotes:1. “Cybersecurity and security overall is not a romantic thing. It's not an exotic thing. It's simply doing the nuts and bolts of what you need to do. And the problem is that largely that's not happening in the environment. If you've got management that's more interested in butter than they are in guns, you've got those types of issues.” - Brett Johnson 2. “Cybersecurity awareness training or fraud prevention training, scam awareness, anything like that, we tend to educate at a very rational level. For scams and a lot of fraud and stuff like that, it doesn't happen at a rational level. If I'm trying to attack a person and compromise that person, I'm not doing it at a rational level. I'm doing it at an emotional level. I'm trying to get you to set reason and logic aside and to react emotionally. So all that training takes place at that rational level. You can understand it there. That doesn't mean that you understand it at the emotional level whatsoever.” - Brett Johnson 3. “Is it harder? In one respect it is because we now have people that are aware of how money is moved, what criminals seek to do with it. Banks have become more aware of a lot of the new ways to launder and funnel funds. In many ways, it's much harder, but at the same time, criminal networks have adapted to that difficulty.” - Brett Johnson
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve returns to Business Matters with Juliette Foster. The war continues to rage in Iran, and with it comes an increasing threat of cyber attacks. Steve shares his thoughts on what the conflict means for cyber investment in the private sector, British critical infrastructure, and the British government’s approach to cyber resilience. Steve and Juliette also discuss the UK Financial Minister’s Spring Statement, which didn’t include any references to cybersecurity. What does this omission signal? How will multinational companies react? Is cyber a macro economic issue? This, and more, in Steve’s latest appearance on Business Matters.
Key Takeaways:
Tune in to hear more about:1. If Steve thinks the UK Finance Minister’s spring statement will impact cyber investments (8:57) 2. The impact on UK businesses of slower economic growth in the UK (14:59) 3. The state of government cyber resilience in the UK (22:39)
Standout Quotes:1. “What you have to do is you have to look at your crown jewels and back to this minimum viable company notion that I mentioned right at the beginning of our chat. You have to understand what the most critical elements of your business are, and then you can track those through these complex supply chains. Those are the pieces you need to be protecting because that's what's gonna bring your business down or ensure that you can continue to operate.” - Steve Durbin 2. “The business climate in the UK at the moment is exceptionally tough, exceptionally demanding. I think if you look at some of the legislation that's recently come in particularly around hiring, retaining employees, the sheer cost of doing business has risen pretty much exponentially for most organizations, and that means that they have to make cuts somewhere. If they can't do it in terms of some of the core business, they will look to some of the fringe elements. So if you've got an organization that perhaps does not view cyber as being core to what they do, then that may well be somewhere where a cut is made.” - Steve Durbin 3. “I think we'll certainly see a maturing of the industry. It's a very young industry still in terms of the way that it's evolving and changing, and I think that with the benefit of a couple of years under our belt, then most organizations will have moved to a stronger position from a maturity standpoint, and I would hope certainly that we're talking very much more about resilience rather than protection.”
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode is a special one, recorded to announce an exciting and important new partnership between ISF and the organisation Prostate Cancer Research. Joining the show is PCR CEO Oliver Kemp, who for nearly a decade has worked to ensure fewer men suffer and die from prostate cancer. Steve and Oliver talk about how prostate cancer screening works and the importance of catching it early. The two also talk about the partnership and how it will help PCR’s efforts across the UK.
Key Takeaways:
Tune in to hear more about:1. What PSA is and how testing for prostate cancer is done (5:28) 2. The new partnership between ISF and PCR (18:58) 3. How AI and new technologies can help in cancer detection (22:34)
Standout Quotes:1. “I think us men are not always the best at going and looking after ourselves and we often need to be nagged to go out and do something. But if you've got prostate cancer, it's gonna get you one way or another, and it'll gradually grow inside of you. And it's far better getting it early and having a relatively simple procedure, which you can now be in and out of hospital in a single day rather than late-stage prostate cancer, which will have very different consequences.” - Oliver Kemp 2. “I think one of the great things about this partnership is first of all, we're aiming at people who often don't get tested. And there are lots of PSA tests happening across this country, but they're often focused on regional areas. So southeast of England, London has lots of testing. It has lots of the best hospitals in the world, whereas other parts of the country don't have access to that.” - Oliver Kemp 3. “And for people in cybersecurity, it's about being as proactive about your own health as you are about protecting your organization. So it isn't about waiting for symptoms. I didn't have any. Look at PSA tests. We've said on this show it's a very low cost. And the people that I've come across who've certainly taken that step, and sadly there are more of us than people might think, all tell me the same thing. And as for partners, families, friends that are listening, don't underestimate the power of your encouragement just being there. That's really important. You don't have to do anything big. It's just a quiet conversation that could genuinely help.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve speaks with Martina Navratilova. Martina is one of the most accomplished tennis players of all time, holding the record for most open era titles and Wimbledon wins. Since retiring from tennis, Martina has been a vocal advocate for gay rights and cancer awareness. In her conversation with Steve, she talks about the importance of screening and early detection, and why self-awareness and kindness to yourself are essential when you’re going through something difficult. The two also discuss adapting to change, how to read your opponents and why rehearsing matters – both on the tennis court and in the world of cyber. Martina also gives the audience a piece of advice on staying resilient in the face of uncertainty, from the perspective of a champion.
Key Takeaways:
Tune in to hear more about:1. Some news from Steve (1:33) 2. Building the right team (10:18) 3. Recovering after a breach (13:24)
Standout Quotes:1. “We tend to overreact and overcorrect. Less is more in just about everything in life. Less is more. You can always add to it. But if you go too far, you've gone too far.” - Martina Navratilova 2. “At the end of the day, if you are the big boss, you are making the decisions, you have to trust your gut. So you take all the information in, but you have to say, ‘Okay, what really feels right with my knowledge, with my intelligence, with my history, what is the best way forward?’” - Martina Navratilova 3. “No system is bulletproof no matter what. You may hit the best serve ever, but that person guessed and they get it back. It's how you bounce back from that. But nothing is bulletproof. You just need to figure out where was the breach, how can we fix it and avoid doing it again?” - Martina Navratilova
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this week’s episode, Steve sits down with conductor, pianist, comedian, and broadcaster Rainer Hersch. Rainer leans on his orchestra experience to explain how leaders outside the concert hall can build deep trust and strike a balance between discipline and adaptability in a rapidly changing world. He also reveals his secret leadership weapon: humor.
Key Takeaways:
Tune in to hear more about:1. How conductors make different parts of the orchestra function in harmony (1:53) 2. Flexibility in an orchestra and in business (6:59) 3. How Hersch uses humor in his work as a conductor (14:54)
Standout Quotes:1. “These analogies are very similar to how any large organization works. The only person actually who's got the kind of blueprint for the product that the orchestra is presenting to its customers, that is the orchestra score, is the conductor. Everybody else has just got their individual parts of the project. So coming together in that way musically, well, requires listening, it requires following in certain occasions, leading in others.” - Rainer Hersch 2. “The conductor is the person who's given that one job of examining this plain piece of writing and going, okay, this is what is intended, this is the emotion that is intended. And in order to bring that emotion out, we need to do this in a certain way, and inspiring and motivating everybody else to participate in that irrespective of how they would personally go about it.” - Rainer Hersch 3. “There are mistakes that happen in a performance, and I'm not going to stop every single mistake and go, ‘Duh-uh, bar 24 flutes.’ No. There are some things that happen, I know they will be fixed by the individual players. In a rehearsal, something happens, they miss the queue. I'll say, that'll be all right in the performance, won't it? Yes, it will. They've seen that I've seen it, and that's enough for them.” - Rainer Hersch
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve sits down with Dr. Helena Boschi, globally acclaimed psychologist, to talk about the best security system of all: the human brain. The two discuss how stress impacts performance in high stakes environments like cybersecurity, why trust and psychological safety matter more than ever, and what leaders can do to help their team stay calm, focused, and creative even when the pressure is on. Finally, Dr. Boschi also explains what neuroscience reveals about how we can train our brains to become more cyber resilient.
Key Takeaways:
Tune in to hear more about:1. How the brain can help us become better leaders (11:26) 2. Digital fatigue (19:56) 3. How leaders help teams embrace change (25:50)
Standout Quotes:1. “If you can see that if people start behaving in a much more emotional way than normal or they're struggling to make decisions or they're a bit absent-minded, time for leaders to say, let's just take a pause and let's think about what's going on. By the time these warning signs are spilled over into physical and behavioral ones, it's normally then almost too late.” - Dr. Helena Boschi 2. “In a world with endless distraction, we have got information coming at us from all directions, and we simply don't have the brain power to deal with it all. So the brain selects what it wants to focus on based on what's important to that person. So what's important for me may not be important for you. We have to select, the brain has to actively select – this is called selective attention. Selective attention also makes us blind to the things we are choosing not to focus on. And you might pick up something that I am blind to. So your selective attention might help me see what I can't see. So it's really important to surround yourself with people who disagree with you, who see the world differently, because their blindness will be different to our blindness.” - Dr. Helena Boschi 3. “Human beings are quite fallible and they're quite flawed because we have a brain that is not optimized for making the best decisions. It's optimized for making the best decisions for me, but often not for the collective. And when it comes to information security, again, it's not really optimized. If the brain is tired or hungry, it won't make great decisions. So I think coming back to basics for the brain is really important. Keeping the brain in its most healthy state is probably the best thing that cybersecurity professionals can do, and that means keeping the body very active.” - Dr. Helena Boschi
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is in conversation with Jaya Baloo, COO at Aisle. One of the world’s leading experts on quantum technology and cybersecurity, Jaya shares what the future of quantum computing looks like and what businesses can do to prepare for a quantum-prevalent world. She also offers her view of how cyber and quantum technology will co-evolve in the next 10 to 20 years.
Key Takeaways:
Tune in to hear more about:1. How to begin your journey to quantum-ready today (8:17) 2. How diversity can shape responsible development of quantum (13:48) 3. Jaya Baloo’s view on quantum in 10-20 years (15:58)
Standout Quotes:1. “ Cybersecurity is something really special here because unfortunately we do not have only from quantum, the same ability to protect as we have to attack. And I worry that the first application of these technologies beyond the sensors, the first real application from governments will be that offensive use to attack our current cryptographic stack.” - Jaya Baloo 2. “I think in general, especially now with the whole onslaught against everything DEI, I actually think it's such a shame to waste time on excluding anyone from anything. We really need the best skillset we can possibly get. And what you see is that, especially in areas like quantum, there's not enough diversity.” - Jaya Baloo 3. “So what I really think that we need to think about is how do we democratize, as much as possible, access to our defense against a potential quantum threat, and how do we democratize the availability of quantum computing in order to benefit all of humanity?” - Jaya Baloo
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve returns to Business Matters with Juliette Foster. In this conversation, Steve recaps 2025 in cyber and shares what he sees as the biggest risks heading into 2026. The two also discuss resilience and compliance, as well as the growing importance of togetherness among businesses…
Key Takeaways:
Tune in to hear more about:1. The relationship between government business in cyber (12:56) 2. How boards should plan for a cyber attack (15:40) 3. Collaborating within and across industries (22:24)
Standout Quotes:1. “I've said many times that good compliance doesn't equal good security, but good security does equal, nine times out of 10, very good compliance. So where do we go with all of that? I do think that we're probably getting to a point, sadly, where we need to be viewing some of the security processes that we need to undergo in the same way as we consider financial audits.” - Steve Durbin 2. “I think that the day is gone when you can rely on your defenses. So boards have to be planning for the day when the defenses fail. When an attack really starts to make an impact on your business. The starting point is to figure out how long you can be without your systems. It may sound like a strange thing to say, but that's the important starting point for me.” - Steve Durbin 3. “Security is not, in my opinion anyway, a competitive advantage. And because it's not a competitive advantage, there shouldn't be this massive barrier to sharing some of the ideas, some of the attacks that are out there for the good of the industry.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve sits down with Tom Hardin, aka Tipperx — best known for helping expose a massive Wall Street insider trading ring. Steve and Tom discuss early warning signs that an organization might be crossing ethical or legal lines, how to build an organizational culture that promotes openness and protects from insider threats, and how to get employees to buy into things like good cyber hygiene.
Key Takeaways:
Tune in to hear more about:1. The changing landscape of critical national infrastructure (5:46) 2. Security vs. privacy in the UK (9:27) 3. An ongoing, structural geopolitical shift (15:18)
Standout Quotes:1. “We need to make sure that we are thinking right across government when we are thinking about the approach to critical national infrastructure and how we can make it most safe for our users and for our populations.” - Sir Jeremy Fleming 2. “I still encounter plenty who haven't done one for 18 months, who haven't updated to the latest threat environment, who haven't thought about geopolitics coming into play. Haven't checked that they've still contracted with a company who's gonna help them wind back in the event that they are breached. Hasn't thought seriously about whether it's gonna pay a ransom. The implications of paying a ransom.” - Sir Jeremy Fleming 3. “The first thing is that what we're seeing now around changes in geopolitics is definitely a structural change. It's not a cyclical change. So the post 1948 Bretton Woods approach to the global order, with a whole load of United Nations agencies, World Health Organization, World Trade Organization, our approach to international aid, World Bank, these are all institutions that have changed fundamentally and won't change back.” - Sir Jeremy Fleming
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve sits down with Tom Hardin, aka Tipperx — best known for helping expose a massive Wall Street insider trading ring. Steve and Tom discuss early warning signs that an organization might be crossing ethical or legal lines, how to build an organizational culture that promotes openness and protects from insider threats, and how to get employees to buy into things like good cyber hygiene.
Key Takeaways:
Tune in to hear more about:1. The fraud triangle (4:10) 2. How cybersecurity leaders can build a culture that discourages insider risk (7:12) 3. Striking a balance between trust and control (15:12)
Standout Quotes:1. “But you don't get people to speak up by telling them to speak up. You actually have to, if you're gonna tell them to do that, you have to listen up. So I always encourage leadership to work on their listening skills.” - Tom Hardin 2. “If you have a rule that a few people break, you have a people problem. If you have a rule that a lot of people are breaking, you have a rule problem.” - Tom Hardin 3. “You could be one decision away. Never feel like it couldn't be you. Just have a healthy paranoia when you're in situations and not to feel like that could never be me crossing a line, because that's when we're most susceptible to that.” - Tom Hardin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, we bring you the second half of Emerging Threats 2026, the first episode of which we aired last year. In the previous episode, Steve outlined the threats and challenges that enterprises and business leaders will face in 2026 and beyond. Today, he answers questions from the audience. We’ll get into artificial intelligence, supply chain and geopolitical challenges, corporate governance, risk and resilience, and more.
Key Takeaways:
Tune in to hear more about:1. Managing supply-chain risk (5:07) 2. How leaders can deal with risks outside of their control (12:16) 3. An evolving cyber threat landscape (15:37)
Standout Quotes:1. “Assuming you've got your policies and your processes in place, I would suggest you have an AI committee that actually approves or otherwise the way in which these tools are then implemented across the business. Why have a committee? Because that way you can pull in representatives from different parts. You can have security, you can have IT, you can have legal and people from the mainline businesses. Everybody makes a decision based on very well-defined criteria, no comeback on any individual, and either it's approved or it isn't.” - Steve Durbin 2. “How do you avoid getting caught out? For me that's not what's happening. If you happen to be on a list. If you happen to be an organization that has something that is exceptionally interesting or useful, then somebody will want that information. Somebody will want that data. What you have to do is make yourself look pretty unattractive. So it is about all of the tedious things that we don't like. It's about patching, it's about making sure that you're making it difficult for people to access your systems. It means that your monitoring is top of its game.” - Steve Durbin 3. “What measures can we put in place to ensure our suppliers and third party partners meet our security standards? Good question that I think that requires a lot more communication. It is about being really clear as to what it is you're expecting from a security standard perspective. It's about not just setting the bar, it's about helping people to achieve what it is you're expecting them to do. And the really important piece that I would emphasize there is tell them the why. Why do you have to do it? Why is it important? This isn't about people doing tick boxes. It is about people understanding why it's important and how they can help to maintain integrity and security across the whole supply chain.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
The ISF Podcast celebrates 10 years this year. Over the decade that we’ve been in your ears every week, Steve has interviewed a lot of fascinating people: visionary business leaders, neuroscientists and physicists, world leaders, and formerly notorious cyber criminals, just to name a few. We have touched on topics like AI, the human mind, cyber resilience, leadership, and the future of technology and society.
So, to kick off 2026, we wanted to give you a look back, highlighting the very best of this first decade of the ISF Podcast. And don’t worry – we’ll link all the episodes in the show notes.
Check out our favorite episodes from the last 10 years:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve looks toward the horizon, at the threats and challenges that enterprises and business leaders will face in 2026 and beyond. He also gives advice on how everyone, from the board to the practitioner, can meet these challenges, and answers some of the questions he’s received this year.
Key Takeaways:1. Steve’s four key drivers of cyber risk heading into 2026 are AI, supply chain, quantum, and geopolitical instability. 2. Crucial to cyber resilience are strong governance and a security-conscious culture. 3. Adaptive governance and adaptive security are keys to managing the challenges of 2026 and beyond.
Tune in to hear more about:1. Steve’s four key drivers of cyber risk heading into 2026 (2:23) 2. Questions to ask, whether you’re a board member, an executive, or practitioner (16:14) 3. The changing role of the board(18:54)
Standout Quotes:1. “ Resilience really needs an organizational wide holistic approach that takes technology, it takes governance, it takes operational readiness, and really importantly, it takes people into account.” - Steve Durbin 2. “I think boards need to really take it upon themselves to absolutely recognize that cyber risk is a national risk. It is a business ending risk, and they need to ensure that they don't just have incident response and resilience in place, but that they also have a tried and tested plan, so this is good old fashioned BCP — business continuity planning — with a cyber flavor.” - Steve Durbin 3. “Cyber risk reporting has to be business outcome oriented. Boards, business executives understand revenue, operations, customer impact, legal exposure. That's the way we have to be reporting cyber risk. It's not about how many attacks we repelled, it's not about how good our systems might be. You need to translate it into business language. If you can do that, not only will you get buy-in, but you'll also have a much richer conversation about the role that cyber and therefore cybersecurity and cyber resilience play in the business.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In the second part of his interview with journalist Nick Witchell, Steve and Nick delve into the world of AI and cyber. Steve shares his thoughts on autonomous cyber defense and argues that major actors like the ISF, large private enterprises, and the UK’s National Cyber Security Centre, must lead the way and support small and medium-sized businesses in keeping pace with technological advancements. The two also discuss the future of AI, cautioning that we aren’t as prepared as we need to be…
Key Takeaways:1. Small and medium-sized businesses must receive support to stay up-to-date with new technologies. 2. As more automation is introduced into business operations, understanding of one’s crown jewels and how to protect them is increasingly important. 3. AI is advancing rapidly with evermore funding, and globally society is not preparing as well as it needs to for what’s to come.
Tune in to hear more about:1. Steve’s view on autonomous cyber defense (00:55) 2. The National Cyber Security Centre and its role in the cyber resilience of UK businesses (3:36) 3. How AI will impact jobs in cyber (7:55)
Standout Quotes:1. “You'll never get me going into an autonomous car. I just won't do it. And people will say, ‘Yes, they're being looked after by some bloke in a tower somewhere who's watching it.” I'm not buying it. I've been working in technology for far too long to know that it is fallible. And so I think we have to really move toward much more transparency in our understanding of where the AI tool is active, the data that it's using, the decisions it's making.” - Steve Durbin 2. “We are looking for large private enterprise to be working collaboratively with people like the NCSC, with people like the ISF, to really help some of these smaller organizations that don't have the luxury or resources available to them to keep a pace with [technology].” - Steve Durbin 3. “If you go back to the internet, we didn't do a good enough job of trying to forecast the way in which the internet was going to be used. We put it out there and we said, ‘Let everybody use it and let's see where it goes.” We are doing, I fear, a similar kind of thing with AI.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today's episode, Steve sits down with journalist Nick Witchell for a conversation focused on what business leaders can learn from this year's major cyber attacks and the recent AWS outage. The two also discuss cyber regulations and the challenge of operating global enterprise during significant geopolitical turmoil.
Key Takeaways:1. Boards and senior executives understand there is a threat, but many still lack knowledge of how to deal with it. 2. We are too reliant on technology; for the sake of business continuity, a backup plan must be in place. 3. High-quality simulation exercises are a crucial step toward more cyber resilience.
Tune in to hear more about:1. The role of policy and regulation (3:17) 2. Why cyber simulation exercises are so important (5:45) 3. Steve’s thoughts on the recent AWS outage (7:54)
Standout Quotes:1. “Now, in the boardroom itself, in companies themselves, we have seen over the past few years an increasing awareness of the threat that these kinds of things can bring to really the future of an organization. But the challenge I think we now face is really helping boards, senior executives to transition from, yes, I get there's a threat, but what should I actually be doing about it?” - Steve Durbin 2. “I think that in the main, cloud service providers are still probably far better equipped to provide the level of service that most companies need than you'd be able to do yourself. However, we do need to take into account that things will go wrong. And we have to plan for that. So if you are an organization that can quite happily exist without access to data in a cloud provider, it doesn't have to be Amazon, it could be anybody else, then fine. I would question why you're using them in that case. If on the other hand, you are dependent on them, you have to have some backup in place.” - Steve Durbin 3. “All too often I'm seeing people particularly in the area of, say, cyber simulation exercises, because they're viewing it as a compliance exercise, going for least cost. That to me is a bit like saying I've just moved into an area where I know the burglary rate is quite high. What's the cheapest lock and door that I can get on my front door? It's madness. Not many of us would do it. We would try to work within our budget. We'd try to really figure out how important things were in our house. That's the mentality we have to adopt. So yes, you can get some of these things done very cheaply and you can tick a box, but it's not going to help you when things go wrong.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s special episode features Steve’s recent Business Matters broadcast interview with Juliette Foster, featuring conversation about critical cybersecurity challenges facing organizations today. Steve and Juliette discuss targeted phishing, the growing threat of Crime-as-a-Service, the increase in AI-driven cybercrime, and more.
Key Takeaways:1. Cyber attacks will continue to increase, and businesses must adjust. 2. Regulators must strike a balance to have clear guidelines without stifling businesses. 3. To take advantage of new technologies like AI, businesses must invest in upskilling their employees.
Tune in to hear more about:1. Why cyber crime is on the rise (2:17) 2. How cyber criminals target their victims (4:00) 3. Solving the cyber skills shortage (29:02)
Standout Quotes:1. “The bad guys only need to get lucky once and they can cause havoc. And so the sorts of numbers you are seeing are them plugging away at it, trying to break down defenses, trying to find a way through. And on the defensive side, of course, we have to be at the top of our game 24/7, and that's just impossible.” - Steve Durbin 2. “We also have very complex supply chains now that obviously are made up of small to mid-size companies. [...] So an easier way of accessing some of this high value information is often via the third party. So you don't necessarily need to be attacking the larger enterprise. You can target a smaller to mid-size, which probably doesn't have the same level of defense, maybe not the same level of awareness. And because it's in the supply chain and sharing information, you can then access through to the larger enterprise.” Steve Durbin 3. “You have to invest in actually looking at the skill sets that you need within your organization and making some hard calls, I think, as to whether or not you do have the right capabilities within your organization. That doesn't necessarily mean that you have to get rid of a lot of people. It means you probably do need to invest significantly in upskilling and training and thinking very hard about how you're going to use some of that new technology.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve sits down with Dr. Tunisha Singleton, Director of Clinical and Sport Psychology Services at University of Arizona and a leading expert in how media, technology, and culture shape the human experience. Dr. Singleton highlights that authenticity and humanity still matter despite all the technology around us, and the two discuss how business leaders can navigate an online presence where almost anything you post can be turned against you.
Key Takeaways:1. Social media is a tool that can be used for good. 2. Authenticity is key for brand-building online. 3. Posting without purpose is worse than not posting at all.
Tune in to hear more about:1. Dr. Singleton’s background (1:21) 2. How to grow your brand authentically (10:22) 3. The risks of posting too much online (15:44)
Standout Quotes:1. “At a certain point we all just have to come to grips with, we are in charge of our behaviors. We have authority, we have much more agency than we give ourselves credit for. The tech is there. But if we use it, that's up to us. How we rely on it is up to us. Are we only using Chat GPT now? So there's a bit of authority that we still have to appoint ourselves.” - Dr. Tunisha Singleton 2. “If technology is the car, then let story be the driver behind the wheel. There has to be a point in this. Where are we going? That means what are you offering? What are you giving me that can be a utility to my life, my human experience, rather than a replacement?” - Dr. Tunisha Singleton 3. ”If we want to stick out and if we want to build our brand, then shouldn't we have the use the one thing that's different than everybody else, that's our voice. So why would we want to act like everybody else? If our goal is to stand out, then be an individual.” - Dr. Tunisha Singleton
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Maria Ross keynote Speaker and Award-winning journalist welcomes Steve Durbin at the Empathy Podcast for a compelling discussion on the intersection of empathy and leadership.
Managers focus on tasks, leaders empower people. Curiosity is the defining trait of an empathetic leader, the ability to set aside ego and truly listen.
Today, Steve is in conversation with Catherine Bosley, an award-winning veteran journalist, with more than thirty years of public speaking experience. Steve and Catherine discuss the importance of protecting one’s online image, what to do when it hits the fan, and why a social media policy is something all organizations should have. Catherine also offers a reminder: pause before you post…
Key Takeaways:1. Think before you post! It will save you a whole lot of headache. 2. What you put online never goes away. 3. Today, offline events can impact your online persona, so be aware of how you appear in public.
Tune in to hear more about:1. How to shine online (4:07) 2. How to deal with negative publicity online (11:19) 3. Being online in the age of AI and deepfakes (19:03)
Standout Quotes:1. “These days, that online image or online presence is so important. It almost is more important than a resume or a portfolio.” - Catherine Bosley 2. “My first step with a response is to ignore the negative because the more you respond to the negative, especially in a defensive negative way, the more you're going to fuel that fire and the more it's going to catch on and become part of your forever and for all to see.” - Catherine Bosley 3. “Understand that people are watching and people especially are looking for those social media gold moments, and if they capture you having one of those ‘what was I thinking?’ moments, because we all have them. We're all human. We all make mistakes. Then you just don't know what that's going to do to your world on the personal side or on the professional side." - Catherine Bosley
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve sits down with Dr. Amy Athey, founder of Athey Performance. Her mission is to make the tools of elite performance accessible and human. Amy is a nationally recognized performance psychologist and executive coach with more than two decades of experience working with NCAA champions, Olympians, Navy SEALs, Fortune 500 leaders, and individuals navigating complex lives. She shares how business leaders can help their teams feel more connected to their organization’s purpose and talks about what drives high-achievers. Steve and Amy also discuss stress in the cybersecurity industry and why rest is absolutely crucial for success.
Key Takeaways:1. Leaders can address rising anxiety, burnout, and disconnection across all levels of their organization by fostering empathy, trust, and a stronger sense of shared purpose.
2. Work with elite athletes and special forces has taught Athey that in high stress environments, recovery and rest are as essential to peak performance as hard work.
3. Prioritize foundational wellness habits — consistent sleep, movement, hydration, and play — for sustainable performance and resilience.
Tune in to hear more about:1. Impact of the grind (2:56) 2. Technology and human disconnect (6:29) 3. Keeping it simple (22:17)
Standout Quotes:1. “What we came to learn and implement and certainly we've seen the results for, is that role of recovery is just as crucial as the tactics or the strategies you're using to solve that problem, the rehearsal and maybe it's the communication or in that performance domain, what you are drilling all the time to be able to execute.” - Amy Athey 2. “And even to the extent that situation permits, how can you take a step away, even turn your back on your computer, even if it's for 90 seconds? Close your eyes and take three deep breaths. We've seen the return of energy stores just from that disconnection in that moment. So when you're sympathetically engaged, basically you're in that fight or flight response, you're trying to solve that problem.” - Amy Athey 3. “And so keeping it simple with each of those. If people wanna take deep dives, certainly I could share the value of that. But some of the culture around hacking and like the quick fixes, that's what I will push up against until I'm blue in the face. Building in wellness as a foundation for performance isn't about a quick fix, if we could do just 80% of this, like how can you reduce some of the processed foods in your diet? How can you make sure you're hydrating? Movement. Then that active recovery..” - Amy Athey
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve speaks with psychologist Dr. Glen Moriarty, founder and CEO of Seven Cups, a free emotional support service with 570,000 trained volunteer listeners who support users in 189 countries. Steve and Glen explore the origins of Seven Cups, its background and its global user base, and discuss why so many feel alone in a hyper-connected online world. Glen also explains the nature of the gift economy and how we can avoid getting addicted to technology.
Key Takeaways:1. Even as more things move online, human interaction remains important. 2. Technology can be good and bad, it depends on how it’s designed. 3. The mental health care system needs better triaging so that people get the right help.
Tune in to hear more about:1. How and why Seven Cups began (1:58) 2. Technology addiction (4:59) 3. Whether Seven Cups is replacing humans with computers when it comes to mental health (9:54)
Standout Quotes:1. “Technology can be used for good or bad. And so the internet can be a source of amazing compassion and love. But it has to be deliberately designed that way. It won't happen by accident.” - Glen Moriarty 2. “Certainly there are cultural differences and different pushes and pulls, but humans we're a lot similar. The way we read emotions are universal, so it doesn't matter where you live. The emotional expression is similar. Human societies are pretty similar. Relationships are similar. There's different assumptions about I'm part of more collective society, or I'm part of a more individualistic society, but by and large, people generally struggle with feelings of sadness, feelings of worry, fear, and relationship difficulties.” - Glen Moriarty 3. “Therapists should be seeing people that can't be helped by a volunteer or a family member or a friend. They should be helping people that are in higher levels or more complex levels of distress. And so in the States, part of the challenge is that you can think about it like a pyramid or a triangle. They're at the very top and it's all clogged up there. But if we could take some of the folks that can get help for free or low cost to other folks, then that opens up the channels for more people that really need help to get help by those expert professionals.” - Glen Moriarty
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve sits down with leadership coach Dr. Sam Adeyemi. Sam is an expert in leadership who has coached C-suite executives for over two decades. Together, Steve and Sam explore the essence of who is a leader, and Sam explains why people should always be the first priority of a leader. They also discuss AI and how it will impact people and business in the coming years.
Key Takeaways:1. Leadership is about your ability to influence, not the position you hold. 2. Technology has changed the nature of leading. 3. AI will change how we work by taking over routine tasks and giving humans more time for creative challenges.
Tune in to hear more about:1. How leadership differs across cultures (4:28) 2. How technology is changing leadership (8:47) 3. How AI will change how we work (14:27)
Standout Quotes:1. “We still need to leave those spaces where we actually ask, how are you doing, to be sure the parts of their lives that are important are going well. Because those parts actually influence what they do on the job.” - Dr. Sam Adeyemi 2. “It’s like when computers first came. They made things work faster. When I was doing mathematics in high school, we used to use log tables and things like that. It was much slower getting to work through the calculations. But with calculators these days and so on, it’s faster. AI is going to create an even bigger shift than that. The computers did not take all the jobs away. However, they changed the way that we do our work. So we humans, therefore, need to move more towards creativity, and that is tied more to our uniqueness, the unique way our minds work.” - Dr. Sam Adeyemi 3. “A lot of C-suite leaders find it difficult to reinvent, and it’s one of the major reasons why people get stranded, why leaders just stagnate. Change is inevitable. It happens, the world doesn’t remain the same. The conditions that facilitated our achievement of success, those conditions have changed. The context has changed. So for us to sustain our success, for us to remain relevant, for example, we also have just got to change.” Dr. Sam Adeyemi
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve talks with Dr. Kathleen Perley, founder of DemystifAI and faculty and AI advisor to the deans at Rice Business. Dr. Perley explains why leadership matters when implementing AI in your business, and shares how to bridge the gap between tech-savvy CTOs and non-technical folks. Dr. Perley and Steve also discuss the possibilities and boundaries of artificial intelligence.
Key Takeaways:1. AI has some exciting use cases. 2. Executives should be involved in the implementation of AI. 3. Business will fall behind if they don’t embrace artificial intelligence.
Tune in to hear more about:1. How Dr. Perley got into the AI field (1:33) 2. The role of the C-suite in AI implementation (8:17) 3. Dr. Perley’s new book about AI (18:57)
Standout Quotes:1. “If you don't have at least a couple sleepless nights where you get a little bit anxious about the unknown in terms of job displacement, falls into the wrong hands—that should be a concern.” - Dr. Kathleen Perley 2. “I think part of the reason why AI implementation is failing today is that leadership issue. They're maybe unsure of this technology, don't have what they feel like is appropriate technical background to navigate it. And so they've completely delegated it, versus leaning in and learning the technology themself.” - Dr. Kathleen Perley 3. “If you have AI skills, and I'm not talking building, but leveraging these AI tools in terms of skills, you're 70% more likely to get hired. Those individuals are garnering about a 56% wage premium right now. All of your A-players, if you're not leaning into AI as an organization, are going to start looking elsewhere because they know that they need those skills and that exposure for their own career development.” - Dr. Kathleen Perley
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve speaks with Karena Man, whose expertise is connecting organizations with experts in technology as a Senior Client Partner at Korn Ferry. Karena highlights the growing awareness of cyber by boards of directors — an awareness brought on by the increase in cyber intrusions. She also emphasizes the importance of storytelling and collaboration, and she and Steve discuss AI and the preparedness of the board.
Key Takeaways:1. Boards are increasingly knowledgeable of cyber and AI. 2. CISOs must be good storytellers and cultivate relationships with other departments to be able to succeed in their role. 3. Involve board members in the processes, not just the results.
Tune in to hear more about:1. Cyber and the board (01:27) 2. AI and the board (19:30) 3. How cyber and AI will impact the board in the coming years (24:53)
Standout Quotes:1. “If we go back to what boards are really charged with, they're charged with oversight and governance. They are there to really provide guardrails in many ways, allow the organization to go fast by asking the right questions.” - Karena Man 2. “When I am also assessing and helping my clients hire their next CISO, one of the things I'm looking for is not just someone who's technically deep, but someone who has the empathy, someone who really understands what is it that the business is trying to do.” - Karena Man 3. “Anyone who's used one of the large language models, don't name any of them, I think there isn't a single person I've talked to who hasn't had a model hallucinate. Or give them a questionable answer to a query or to a task. And so there is this understanding that the technology is promising and that we should experiment with it and innovate with it within our enterprise. But there is this worry that it could be used for not so good purposes.” - Karena Man
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this week’s episode, Steve sits down with Debra Andrews, president and owner of Marketri. Marketri, a strategic marketing firm. Steve and Debra talk about what goes into creating a marketing plan that the C-suite can get on board with, and Deb shares how she and her team work to balance human knowledge with the speed of artificial intelligence. Debra also explains the role of Marketri’s AI council…
Key Takeaways:1. Using key performance measures to show growth toward a goal is integral to getting the C-suite on board with a marketing plan. 2. To gain trust for AI both inside and outside the organization, transparency is paramount. 3. AI will shrink marketing teams and marketers will need broader skillsets.
Tune in to hear more about:1. How Marketri went about incorporating AI into its operations (6:23) 2. Deb’s thoughts on the ethics of AI (10:55) 3. How AI will impact the future of marketing (13:43)
Standout Quotes:1. “When we use AI to do the copywriting, we ask it not to supplement with any extra information, only use the information you're given and through that, AI is a wonderful copywriter. It can learn your voice and tone. You can train it on your particular voice and tone, so we can train it on our client's voice and tone. So it can be very customized to that person and how they like to speak, and words they like to use and how they like to sound. But ethically means we're not using trained data in the large language models to produce our content pieces. We're using human brains, their experience, and we're leveraging the tools as copywriters.” - Deb Andrews 2. “We're not trying to hide that we're using AI and shortcutting the process or delivering something like an AI-produced post. What we share is that we're using it to help them gain competitive advantage, to have the best access to human thinking, our thinking, their thinking as far as their area of subject matter expertise, and then the best of what this technology can do, and it's extremely powerful.” - Deb Andrews 3. “I think the smaller organizations, they're just struggling to keep afloat of their workload right now. I feel like AI's had this paralyzing effect on a lot of mid-size organizations where they know AI's out there and they know it's supposed to have an impact and they're reading about companies reducing head count and not hiring.” - Deb Andrews
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve sits down with Baroness Beeban Kidron, a member of the House of Lords in the UK and a global authority on online privacy and tech regulation. They discuss the critical importance of privacy on the internet in the age of surveillance capitalism, why we need to reframe how we talk about AI and new technology, and the problems with the UK government’s current AI policy.
Key Takeaways:1. The internet has changed, making privacy online essential. 2. Regulating the internet and technology is still possible. 3. The current path the world is on when it comes to AI is highly problematic and should be taken more seriously.
Tune in to hear more about:1. Why privacy online matters more than ever (1:22) 2. How technology is impacting early childhood development (12:08) 3. Baroness Kidron’s take on the UK’s AI strategy (28:17)
Standout Quotes:1. “[The internet] is deliberately designed to keep your attention. Deliberately designed to make you come back, deliberately designed to know the most, to reveal the most. And in that context, actually, privacy becomes an incredible tool of protection for the user, particularly for children who may not understand the negotiation that they're in.” - Baroness Beeban Kidron 2. “ We have to think about what kind of world we want, what kind of world is good for us, what kind of world benefits most people, and then we build ourselves a pathway to do the most we can in that direction.” - Baroness Beeban Kidron 3. “ it is hugely important to protect the idea of copyright. It is a moral right because it is an expression of your humanity. What you write, what you draw, what you sing is yours. It is you. It is a manifestation of you. So it comes with, and in fact, in human rights law, it is specifically stated that it is your moral right to determine how that is used.” - Baroness Beeban Kidron
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Explore how CISOs can educate the board, build resilience, and invest effectively in security, with Steve Dubin, ISF CEO, and Margaret Heffernan, a Professor of Practice at the University of Bath School of Management.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, Steve speaks with Dragos Tudorache, one of the members of the European Parliament who is responsible for writing the EU’s AI Act. Dragos explains the thought process that went into developing the new law and tells Steve what organisations can expect and how they can prepare for its implementation.
Mentioned in and related to this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, ISF CEO Steve Durbin speaks with Seán Doyle, Lead for the Centre for Cybersecurity at the World Economic Forum. They discuss the role of public-private partnerships in the current cyber landscape, the importance of running tabletop exercises to promote resilience, and improving cybersecurity legislation and regulation around the world to promote economic interests.
Mentioned in this episode: Cybersecurity Technology Efficacy: Iscybersecuritythe new 'marketfor*lemons'? Research Report by Joe Hubback * ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
ISF CEO Steve Durbin sits down with strategic supply chain risk expert Omera Khan. They talk about the current risk landscape vis a vis supply chain, protecting your supply chain by building collaborative systems, and incentivizing your staff appropriately to ensure they vet suppliers with a security-first mindset.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve speaks with Jimmie Lee, a leadership expert with decades of experience as a senior leader at companies like Boeing, Meta, and Microsoft. He explains that one of the most important things a business leader can do in times of crisis, is to keep focus on the big picture and the long term goals. Jimmie and Steve also discuss how to manage a team in a post-covid workplace and building supply chain resilience — and why empathy matters more than ever.
Key Takeaways:1. Empathy for your team members is more important than ever for a thriving business. 2. Relationship-building must begin before the crisis happens. 3. Geopolitical instability is causing a shift from risk management to resilience.
Tune in to hear more about:1. If empathy can be taught (12:50) 2. How to build trust in a business environment that’s more virtual than ever (15:47) 3. Why many businesses are struggling because of today’s volatile geopolitical landscape (21:33)
Standout Quotes:1. “There's a lot of tools that I would typically lean on or go to, but the number one is honestly just empathetic connection. It is really just connecting with the leaders and help them understand that they're not alone. I think a lot of times as a leader, you get too stuck in the problems that you start trying to solve, that you focus more trying to solve them in the business, and you go deeper instead of staying up at the leadership level and start working on the business itself.” - Jimmie Lee 2. “Now you have trust to work off of. If you didn't have that trust and that mistake happened, it's an uphill climb to get to a point of good with that person now. I don't know that we're equipping our employees, that we're actually giving our teams that visibility, that knowledge, that training. […] Are we as companies, are we as leaders investing in our training budget in that kind of way to target those areas?” - Jimmie Lee 3. “I think the geopolitical landscape is potentially gonna shift the visibility and the approach and the strategy from small, medium- sized businesses and middle market to have more attention on that supply chain because. When it comes to geopolitical instability, when it comes to geo-economic macro and the micro instability, resilience is key. Resilience is the lifeblood. Resilience is your ability to last, to withstand the fluctuations, but if you don't have enough visibility and awareness of all the different components that are impacted, you can't navigate those waters.” - Jimmie Lee
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode will focus on the challenges of the cyber landscape in the United States, as Steve sits down with Yolanda Williams, who is the Cybersecurity and Infrastructure Security Agency’s cyber security coordinator in the state of Florida. Steve and Yolanda dive deep into her work communicating cyber in a region where it for many isn’t top-of-mind and how state sovereignty and lack of standardisation between local stakeholders poses unique challenges. We hope that Yolanda’s many examples of successfully working with Floridians and stakeholders across the state will resonate with listeners across the US—and perhaps across the pond, too.
Key Takeaways:1. Cyber leaders must possess the ability to shape their communication based on what the audience is looking for. 2. Organisations are much more open to cyber advice today than they were five years ago. 3. Look at the language in your contracts! Mistakes can prove costly from both a financial perspective and a cyber perspective.
Tune in to hear more about:1. How cyber connects to physical security (3:25) 2. The challenges of a lack of standardised guidelines or federal regulation (10:23) 3. The importance of keeping local backups and not only use the cloud (18:24)
Standout Quotes:1. “I hear a lot of people say, ‘dumb it down.’ But you don't want to dumb it down. You just want to make sure that you're tailoring it specifically. You may have technical folks who are looking for, okay, what was the ransomware? Who did it? Who deployed it? How was it deployed? What was the payload? All those types of things. And they want to get into the deep dive of it. A lot of individuals don't. I'll speak to healthcare individuals and they're more looking at ‘I'm not a target. I'm a small doctor's office. I'm not a target.’ And one of the things we try to get across to everyone is: you are definitely a target. If you have a US IP address, you are a target.” - Yolanda Williams 2. “There are federal guidelines for federal agencies. However, we respect our states and their sovereignty, and one of the things I found in Florida definitely was a lack of collaboration. Even from the city to the county, there's nothing structured across the board.” - Yolanda Williams 3. “One of the steps that I recommend across the board for anyone that I'm talking to is looking at the language in your contracts, making sure that language is covering, not just what you're purchasing.[…] So making sure that you're looking at that contract language and have somebody that's looking at it that understands the lexicon, understands what is required. You can't just hire somebody off the street and say, ‘Oh yeah, write this contract,’ and they don't know what should be in the contract.” - Yolanda Williams
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Financial due diligence is common practice when companies merge or one business acquires another. Cyber security due diligence, however, is not quite as common. Yet, in a world where the threat landscape changes by the day and risk is growing increasingly complex, solid cyber security practices are more important than ever.
Today, Steve and Tavia dig into this very topic, and, more specifically, what role cyber security has in a merger or an acquisition. How is a cyber security review done? Why are they important? How do we balance speed with thoroughness? How do we interpret the results? There’s a lot to dig into here.
Key Takeaways:1. Cyber due diligence is paramount in a corporate acquisition or merger. 2. Risks of not doing cyber due diligence include both financial and reputational. 3. Cyber due diligence is a team game.
Tune in to hear more about:1. Who should be responsible for conducting the cyber review (4:34) 2. How organizations can build cyber into their due diligence process (14:05) 3. Examples of where insufficient cyber due diligence proved costly (19:05)
Standout Quotes:1. “You can't play a team sport without a team. And for me, M&A is a team game. You can't go it alone. I think it would be a mistake for somebody to think that they could do this kind of work solo. Because as we've seen with cyber maturing, it now touches so many different parts of the organization. You do need to be involved.” - Steve Durbin 2. “I think people are getting it. What I'm seeing now is people get it, but they don't know how to do it. That's where the cyber professional really now has to step up.” - Steve Durbin 3. “Pre-deal, I think it is about being focused. It's about identifying, prioritizing the high risk areas that are out there that you want to look into. It's about doing things like making sure that the governance is there. It's about scanning for some of the known vulnerabilities. If you are in one particular market sector and you're buying a company in another because of expansion growth, you're going to need to be covering off a whole range of different things that perhaps might be unusual for you because you haven't been having to look into those areas.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve speaks with Lauren Farina, psychotherapist and founder of Invited Psychotherapy & Coaching. Lauren and Steve discuss how wellness is becoming a bigger part of the workplace and how we can stay mentally healthy during times of stress and pressure. Also an expert on “high-performance individuals,” Lauren shares what it means to be high-performing and why rest can be just as productive as work.
Key Takeaways:1. Being a high-performer isn’t just about work. 2. Rest is productive 3. Building psychological safety within an organization is the most important contributor to elite performance.
Tune in to hear more about:1. What the “High Performer Archetype” is (6:15) 2. The risks of not taking time to rest (11:22) 3. How leaders can improve the performance of their teams (19:33)
Standout Quotes:1. “ As many of us know, acute stress is quite good for us. But in the long term, the chronic unrelenting demands that I think remote working arrangements have placed on the workforce, really can erode our performance because our cognitive functioning is not at its peak when we're chronically stressed, our memory, our learning, our judgment, our decision making is compromised.” - Lauren Farina 2. “ There was a five -year study at Google called the Aristotle Project, and the Aristotle project found that psychological safety is the single most important factor when it comes to the elite performance of individuals and groups.“ - Lauren Farina 3. “ It is my hope that there will be an increased focus on intersectionality of performance and wellbeing and increased support of individuals and groups in cultivating wellbeing. Not only for the sake of wellbeing, but also for the sake of peak performance.” - Lauren Farina
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve Durbin and ISF Podcast Producer Tavia Gilbert are in conversation exploring the role of cybersecurity, governance and leadership in an age defined by rapid technological transformation. Artificial intelligence is now woven into daily business operations, risk models, customer engagement, and more. And while its benefits are significant, its risks are expanding just as quickly.
Key Takeaways:1. It’s becoming increasingly apparent for leaders that cyber impacts every part of the business. 2. AI will not replace humans in the workplace, but rather redefine what work humans do. 3. If you as a business leader don't have clarity about what your values and ethics are by now, you better get started.
Tune in to hear more about:1. What happens if businesses don’t implement a robust framework for ethical AI use (8:51) 2. The role of the board when implementing AI into business operations (19:49) 3. How to lead through change (24:20)
Standout Quotes:1. “When cyber is involved early, it really can become a value enabler. It helps the business make smarter bets, helps it to avoid blind spots and build that sort of trust that we're looking for into everything that it does.” - Steve Durbin 2. “AI, it does introduce huge amounts of potential, but it also introduces a new layer of risk that is more complicated, dynamic and probably difficult to manage than many people actually think or are prepared for. And one of the biggest challenges is that AI doesn't just create new vulnerabilities, it changes the nature of the threat landscape completely.” - Steve Durbin 3. “AI is not some kind of future technology. It's been around for a very long time. Certainly in cyber terms anyway, at least 10 years, if not more. It's a lifetime in cyber, so it's not a future technology, it's here. It's shaping the way that we work, that we think, and indeed that we compete. So the question isn't whether we should engage with it, it's how do we do so responsibly and effectively. And the organizations that retain control are those that lead with clarity.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Joining the podcast today is Dr. Shonna Waters, a leading researcher on the workplace of today and the future, and the Co-Founder and CEO of Fractional Insights, an organizational psychology research firm. Steve and Dr. Waters discuss the rapid transformation of the workplace, brought on by new technologies, geopolitical uncertainty, and shifting organizational priorities. They also speak about how to stay grounded when the ground around us is shaking, how security professionals can manage stress and negativity brought upon by constantly searching for threats, and how a growth mindset can help build resilience.
Key Takeaways:1. The professional environment is changing faster than we are. 2. How bridging the language gap between security and sales is challenging, but key for business success. 3. A growth mindset can build resilience.
Tune in to hear more about:1. What people look for in the workplace (1:56) 2. How to manage stress at work (18:22) 3. How a growth mindset can help us become more resilient (21:42)
Standout Quotes:1. “There's a lot going on out there, and I think that there's this general sentiment that the ground is moving under our feet. We all are feeling overstimulated and ungrounded, I think, generally speaking, and it's a really hard place to navigate as an employee. It's also a really hard place to lead from.” - Dr. Shonna Waters 2. “No matter what you're selling or producing, there is a human at the beginning of it and at the end of it, at a minimum, right? It's the concept, the leadership of it, the orchestration, no matter how much you minimize humans in the process. There's human ingenuity at the top of that chain. And then at the bottom of it, you have your customers.” - Dr. Shonna Waters 3. “There are conscious choices that you can make to lean more into that idea that you can grow and practice. And I think for any of us, one way to really encourage ourselves around that is to think back to other things that you've done that got easier over time or you were able to improve your skills.” - Dr. Shonna Waters
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Steve Durbin engages in a compelling conversation with Faisal Hoque, a world-renowned technologist and best-selling author including his recently released ‘Transcend: Unlocking Humanity in the Age of AI’.
Faisal shares his thoughts on how business leaders can preserve human values in the in the era of AI, how AI and humans can function together, and the threats posed by ceding control of our humanity to AI. Find out why he feels the government needs to provide legislative structures to protect citizens.
Key Takeaways:
1. The challenge for business leaders in preserving human values amidst the rise of AI
2. How AI is gradually diminishing human emotion in daily life
3. The risks involved in relinquishing human control to AI
Tune in to hear more about:
1. Preserving human values (1:14)
2. How government policies can influence society and the development of AI (6:15)
3. Harnessing the potential of AI whilst mitigating the risk (18:11)
Standout quotes:1. "The government needs to provide the legislative structures where citizens are protected. Things like intellectual property, privacy, and free market support." - Faisal Hoque
2. "The digital divide concerns me greatly. Not just with regard to AI, but with everything that we are doing from a technology standpoint." - Faisal Hoque
3. "Leaders' job is to create that psychological safety so that we can be productive and feel that we can actually contribute and fulfill our purpose, whatever that purpose is." - Faisal Hoque
4. "AI is going to be like electricity or internet. It is going to be part and parcel of everything and anything we do." - Faisal Hoque
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today's episode, Steve speaks with Christopher Sestito (also known as Tito), chairman of the board, CEO, and co-founder of HiddenLayer, a cyber security startup dedicated to preventing adversarial machine learning attacks. Tito shares his perspective on where the business world is currently when it comes to AI and cybersecurity. He also gives his thoughts on the state of AI regulation and what business leaders should do to protect their organizations in the age of AI.
Key Takeaways:1. AI is changing the cybersecurity game 2. Tech regulation is becoming more fragmented 3. Securing AI is really no different from securing other parts of the business
Tune in to hear more about:1. Why Christopher Sestito started HiddenLayer (1:28) 2. Why AI will play an increasingly important role in organizational cyber defense (5:47) 3. What business leaders should think about as they approach cyber in the age of AI (20:18)
Standout Quotes:1. “I think the challenge at the AI level is how fast we've moved. There's been so many advancements that if you don't have a dedicated organization looking at this, it's really just moving too quickly to ultimately have things at a sort of hardening level at the model layer itself.” - Christopher Sestito 2. “I think I'm a bit of a realist when it comes to artificial intelligence coming in. I think we are viewing a very fundamental shift in ultimately what's gonna affect workforces and skill sets required. I think that if I was entering the workforce right now, I'd be focusing heavily on the effects of artificial intelligence, how I can leverage artificial intelligence.” - Christopher Sestito 3. “Every organization really needs to pay attention to their agentic strategy right now. I think if you're engaged with other enterprise organizations, as all are, everyone's building agents right now, and those agents have a lot of autonomy in order to be able to conduct transactions, in order to be able to deal with data, to be able to interact, organization or organization. And I think every CISO is gonna need to be able to really articulate what they want to be allowed here and not because we're removing humans in the loop with these agents, we're allowing them to have quite a bit of agency in order to conduct these transactions at an incredible rate.” - Christopher Sestito
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve talks about ISF's flagship foresight report "Threat Horizon 2027: Grasping for Control." In a world defined by disruption and acceleration, this report offers not just a forecast of cyber threats, but a blueprint for resilience, and Steve walks listeners through the key themes.
Key Takeaways:
1 Flexibility will be key in an increasingly volatile world.
2 Cyber must be considered in every aspect of an organization’s operations.
3 Control is possible, even if it sometimes doesn’t feel like it.
Tune in to hear more about:
1 Why identity is becoming more and more important for businesses (2:24)
2 How senior leaders can prepare for the future (17:06)
3 Why control is still possible (21:42)
Standout Quotes:
1 “Identity is really the cornerstone of everything that we do in the digital world, and it's fast becoming one of the most critical areas for business leaders to understand and take seriously.” - Steve Durbin
2 “Leaders need to understand the economic impact of cyber risk. What are the potential costs of disruption? How would a breach affect reputation, revenue, operations? It's the reputational bit, for instance, in my case, that worries me the most. And once you start thinking in those terms. You can make many more business-aligned, informed decisions about what you are going to do because you stop looking at the cost of doing something and instead you flip it and look at the implications and associated costs of not doing it.” - Steve Durbin
3 “I think that business leaders as a group, tend to be pretty resilient individuals. I've worked a lot with entrepreneurs, and they are probably some of the most resilient that I've ever come across because they have to be. And one of the things that they always believe in, I've found, is that irrespective of what's going on around you, control is still possible. But in order to have that level of control, it takes foresight, it takes focus, and I think above all it takes flexibility and, I would say, courage.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve speaks with Tavia about how AI and other emerging technology are reshaping society, and how we as humans should react to it.
Key Takeaways:1. AI and other emerging tech can help society, but guardrails are needed. 2. The world is becoming more fragmented when it comes to how it views AI and tech. 3. With AI and new technology, we have to be increasingly cautious in our interactions in cyberspace.
Tune in to hear more about:1. Why it’s unlikely there will be international rules around AI (4:32) 2. How technology is changing how we interact – and what that means (7:12) 3. What people 50 years from now might say about how we’re currently handling emerging tech (22:28)
Standout Quotes:1. “We need to be putting in place guardrails, particularly when it comes to AI, around how it's going to be used, because we are playing with a technology, the power of which we don't fully understand yet.” - Steve Durbin 2. “I think it is about how we get the balance right. I think that it isn't about shutting down some of the technological advances that we're seeing, it is about just being a little bit more realistic about their fallibility and trying to get equilibrium back between people and tools.” - Steve Durbin 3. “I suspect that what they will do is take a look back and go, why on earth did they do that? Why on earth didn't somebody see that there was a better way? Because that's with the benefit of hindsight, isn't it? And we've got 20-20 vision when it comes to hindsight. And so I think that we are in the here and now and we need to find a way of muddling through. And I think that everybody has a responsibility to do that.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this bonus episode, Steve speaks with Dr. Ellie Pavlick, a professor of computer science at Brown University. Dr. Pavlick’s research focuses on computational models of semantics and pragmatics which emulate human inferences in artificial intelligence. Steve and Ellie discuss generative AI, developing a pipeline of talent to work with it, and perspectives on its developing uses for organisations.
Related Resources from ISF:
* ISF Podcast: The AI-Quantum Revolution: Today, tomorrow and the future
* ISF Podcast: Steve Durbin & Nicholas Witchell - The Case for Social Responsibility in AI
* ISF Podcast: Boosting Business Success: Unleashing the potential of human and AI collaboration
* Navigating Boardroom Concerns: Top 9 Cybersecurity Risks and Challenges
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
Tune in to this bonus episode where Steve is speaking with Prof. Federico Varese, a professor of criminology and head of the sociology department at Nuffield College at Oxford University. Prof. Varese talks with Steve about the history of organised crime in Russia and around the world, the mafia’s movement into cybercrime, and what the future may hold for these criminal organisations.
Related Resources from ISF:
ISF Podcast, Alexander Seger — How Global Law Enforcement Fight Cybercrime
* ISF Podcast, Inside the Mind of Today’s Cybercriminals, Brett Johnson Part 1
* ISF Podcast, The Life of a Cybercriminal, Brett Johnson Part 2
* ISF Podcast - The Democratisation of Cybercrime
* Misha Glenny: The Evolution of Cybercrime with Misha Glenny, author of McMafia*
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
An interview with Steve Durbin, Chief Executive, ISF, hosted by CEO and Founder of The Drop In CEO Podcast, Deborah A. Coviello. Originally published by The Drop in CEO Podcast.
In this episode, Steve shares his unique journey from literature to cybersecurity, emphasising the importance of curiosity, learning, and fresh perspectives in leadership. The discussion delves into the evolving landscape of cybersecurity, the necessity for business leaders to adopt a resilient and informed approach to technology and risk management, and the value of continuous education and networking. Steve offers practical advice for business leaders on safeguarding against cyber threats and highlights the dynamic interplay between technology, business strategy, and security.
Episode Highlights:
01:57 Steve's Journey: From Literature to Cybersecurity
05:12 The Importance of Reading and Continuous Learning
08:02 Transitioning Careers: Embracing Technology
16:58 Information Security Forum: Mission and Impact
29:12 Practical Advice for Leaders on Cybersecurity
Discover more about the Information Security Forum (ISF), and tune in to our engaging podcasts.
Today, Steve sits down with supply chain expert Neil Coole, who currently serves as Enterprise Partnership Director at BSI. He emphasizes the need to know your organization’s supply chain story in order to stay secure and protect your brand. He and Steve talk about how regulation can go beyond a checklist and add value for companies.
Key Takeaways:
1 The covid-19 pandemic and recent conflicts have highlighted the vulnerability of today’s supply chains.
2 Standards exist as frameworks to help companies live up to responsibilities set upon them by law or consumers.
3 A harmonized assessment framework can help industries secure their supply chains and save organizations time and money.
Tune in to hear more about:
1 How standards are created and what their purpose is (8:57)
2 Protecting critical infrastructure in the US (14:09)
3 The Supplier Compliance Audit Network, a community of US-based retailers and brand owners who’s created a harmonized assessment framework for its industry (23:23)
Standout Quotes:
1 “The expectation now is on more trust, transparency and also traceability, especially things like tech-enabled traceability. What kind of tech-enabled traceability solutions is that client using to determine where the goods are coming from? What route are they taking? Who's opening up the cargo containers and possibly adulterating goods, stealing in transit, all those other things – that's a real concern today for these organizations who are moving hundreds of thousands of freight containers on an annual basis. It's a real risk that they have to live with. The solutions are there. It's just helping those organizations understand the role that standards, shall we say – a standard is a best-practice framework – can play in helping to reduce, or, in some cases, even mitigate some of those risks.” - Neil Coole
2 “There's opportunities for improvement everywhere, but from a maturity standpoint, we do view parts of the critical infrastructure sectors like energy and finance to be on the more mature end. And then there's a few in the middle that are learning some important lessons. And then there's those who are actively being targeted we read about all the time. They are the ones that I feel would benefit more from some of the guidance and support and information that's available for them to be less of an attractive target.” Neil Coole
3 “So, if you're a single supplier working for the top 10 biggest brands, the top 10 are sending out some form of assessment of you. You're getting that 300-page assessment document, not just from one supplier, you're getting it from all the suppliers. But if those suppliers become part of the same community and they agree to accept a single assessment outcome, no matter who has instigated it, everyone benefits. The supplier benefits – minimizes their disruption, they get to work with more brands in an open and trusted environment – and it just saves that complete disruption and unnecessary costs of delivering an assessment by multiple brands.” - Neil Coole
Mentioned in this episode:
• Dear Infosec
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve speaks with Kailyn Johnson, cyber intelligence and geopolitical risk lead at UK consulting firm Sibylline. Kailyn and Steve discuss the current threat landscape, focusing on areas where cyber and geopolitics overlap, and she offers some practical advice on how to contextualize security for your organization’s C-suite.
Key Takeaways:
1 The dark web is becoming more democratized, opening up the door for low-skilled threat actors to cause harm.
2 Open and frequent communication between security teams and other branches of the organization, in particular those in charge of the budget, is crucial for cyber resilience operations to receive sufficient support.
3 Staying up to date on patching, knowing your supply chains, and understanding how threats to critical infrastructure can affect you, will be key for organizations in 2025.
Tune in to hear more about:
1 How the dark web is becoming more democratized, and what means for businesses
2 Why showing the worth of the cyber team is tricky but critical for long-term success
3 What organizations can do better in 2025
Standout Quotes: 1 “So we're seeing just ransomware continuing to be a consistent risk to business operations, financial risk, reputational risk, security risks, operational risks. But alongside that, we're also then seeing the influx of a lot more low-skilled threat actors having now the capabilities to conduct sophisticated operations with the democratization of the dark web.” - Kailyn Johnson
2 “Showing off the value that these teams have to the people with budget, sometimes might help unlock a bit of that budget. If you're seeing the benefit of those teams, you're more likely to give them the budget that they might need for it, and whether that's internally or sometimes externally, if you've produced really good work, or if you've created all these detections that have helped improve the network security for your organization, how could we maybe publish that, whether it's internally to the stakeholders, or if it's for everyone, so people are seeing, actually, they're doing a really good job.” - Kailyn Johnson
3 “But sometimes you're so focused on the impact of the regulations that you sometimes then forget, actually the processes that we're doing are working. Then should we just maybe let things play out and see how they're going? I think there's always a bit of a worry of, are we always in compliance? And it's good that we have that worry, but it's also sometimes the case of, just keep doing what you're doing, and you've got your compliance teams to tell you when you're not.” - Kailyn Johnson
Mentioned in this episode:
• ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is in conversation with Dr. Kate Darling, Research Scientist at the MIT Media Lab and Research Lead at the Boston Dynamics AI Institute. Kate has spent years studying human-robot interaction, and she speaks with Steve about the fascinating impact such interactions can have on us as people, and what that means for businesses trying to incorporate robots and AI into their customer experience.
Key Takeaways:
1. It is natural for humans to project human behavior onto non-humans.
2. Using robots to help humans do their work better is smarter than replacing them.
3. More technical expertise is needed for policymaking to keep pace with new technologies.
Tune in to hear more about:
1. Why humans form emotional connections with robots
2. How a grocery store robot is scaring customers
3. Pitfalls of commercializing robotics
Standout Quotes:
1. “That's part of the reason that we do this, that we create these strong emotional connections, even with non-living things like robots, is because we have this drive, and especially in these emotionally difficult situations, it may even be something that helps people survive. So I don't think it's as black and white as just: we need to prevent this anymore, but it is something that we need to be extremely aware of and acknowledge that it's happening, so that we can address it appropriately where possible.” - Dr. Kate Darling
“So I think it's important that we're making the right choices. It's not that technology determines what happens. It really is us as a society choosing to set the right incentives for companies and invest in the right kinds of technology. And I do think that there's much more promise in that path, the path of trying to partner with these technologies and what we're trying to achieve, rather than trying to replace people or recreate something we already have.” - Dr. Kate Darling
“We've used most animals like tools and products, and some of them have been our companions, and my prediction for the future is that we're going to do the exact same thing with robots and AI, that most of them will be tools and products and some of them will be companions.” - Dr. Kate Darling
Mentioned in this episode:
• ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve speaks with best-selling author and hypnotist Paul McKenna about something that affects all of us — stress at work. Paul talks about the impact stress can have on workers and gives practical tips to care for yourself and the employees you lead, even in the fast-paced, “always-on” security industry.
Key Takeaways:
1It’s important to be mindful of signs of stress before it gets to burnout.
2Mindfulness, hypnosis, and other types of self-care can significantly reduce stress.
3For long-term success, employers should look to balance output and productivity with their employees’ mental and physical well-being.
Tune in to hear more about:
1Why we’re more stressed than ever (1:10)
2How to identify signs that may lead to burnout (3:26)
3How companies and leaders can support their employees well-being (12:32)
Standout Quotes:
1“It's right now a massive issue, anxiety, stress, fear, worry, because if you think about it, you turn on the TV, or you open a newspaper, you're under attack. It's the war, it's the virus, it's the economy, it's something or other. And so understandably, post the pandemic, we were out of the biological pandemic, but we're sort of in a psychological pandemic.” - Paul McKenna
2“ Now the thing is, addiction is about changing your state of mind and body, so drinking, drug taking, gambling, sex, shopping, television and food, particularly sugar food, are the world's drugs of choice. And everybody in the world at some point feels too much stress. They feel overwhelmed, and so they resort to something to change how they feel, some of the things I just mentioned. And in a sense, some people, they form an addiction to their work because they can, you know, forget about everything else that's going on in their life. They might not have to think about their relationship or, you know, some other stress, from their family or something. So they immerse themselves in work.” - Paul McKenna
3“Years ago, when I started corporate training, one of my colleagues, I asked him, ‘Why is it corporations pay so much money to have their staff trained?’ He said, ‘Well, I can show you,’ because look, they see that ‘days sick' goes down, the productivity goes up. So basically, by staying in the zone of balance – you've got enough output getting things done, versus balance, which is recovery time, in my mind. You get that mix right, then you're going to be more productive in the end.” - Paul McKenna
Mentioned in this episode:
•Dear Infosec
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve sits down with Duncan Wardle, the former head of innovation and creativity at Disney. Duncan talks to Steve about his current work teaching leaders to embrace creativity and inspire innovation in their teams. He suggests practical ways that leaders can create a more collaborative and fun work culture that will lead to more successful outcomes and enhance their teams’ job fulfillment.
Key Takeaways:1. We’re all born with creativity, and a great leader can unlock it within people who may have lost it along the way. 2. Creativity is the ability to have an idea; innovation is the ability to get that idea done. 3. With AI, we have the opportunity to hand off mundane tasks and give ourselves time to think, be creative, and innovate.
Tune in to hear more about:1. Why it matters to say “yes, and…” instead of “no, because…” 2. The impact of AI on creativity and innovation 3. Actions leaders can take to spark more creativity within their organizations
Standout Quotes:1. “I define creativity as the ability to have an idea, and I think we can all do that every day. I define innovation as the ability to get that done. That's the hard part.” - Duncan Wardle 2. “As leaders, we have responsibilities, we've got quarterly results, we've got bosses, we've got – but if the first two words out of our mouth are ‘no, because,’ they're the first two words when somebody comes at us with a new idea, they're not coming back in the door again, and they may have genius next week or next-. Just remind ourselves as leaders, we're not green lighting this idea for execution today. We're merely green housing it together, using ‘Yes, and.’ As leaders, if we can use ‘Yes, and’ before ‘No, because’ you can completely and utterly change your culture.” - Duncan Wardle 3. “Algorithms, and everything that AI will bring to the table, will merge with the human race, creativity, intuition, empathy, imagination, etc, we will merge to become a superhuman race.” - Duncan Wardle
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve sits down with author and leadership expert Sylvie di Giusto. Sylvie delineates five areas for everyone to consider in order to enhance their emotional intelligence. She and Steve also discuss how self-awareness and authenticity relate to situational awareness, and how improving in these areas can support career mobility.
Key Takeaways:1. The subconscious takes up 95% of the brain – use that to your advantage to gain the trust of the people you interact with. 2. Situational awareness is more important than one-size-fits-all ideas of “always smiling” or “maintaining eye contact. 3. Your appearance, behavior, communication, digital footprint, and environment all matter for how people see you.
Tune in to hear more about:1. How the meaning of emotional intelligence in business has changed over the years (01:48) 2. Sylvie di Giusto’s A.B.C.D.E. (Appearance, Behavior, Communication, Digital footprint, Environment) framework (07:50) 3. The four levels of visibility (20:05)
Standout Quotes:1. “The subconscious mind of a human takes up 95% of your brain. And 95% of your brain is where emotions live, where feelings live, where your gut feelings live. And only 5% of our brain actually transmits data, facts, figures, information. That is where your contracts are, where your proposals are, where all the facts and figures are that you deliver to your clients. [...] So, I always say, why don't you use this to your advantage, that behavior, and actually use the 95% of the brain and instantly imprint that feeling of trust in them and use it to your advantage. And before they buy into your solution, into your technical solution, let them buy into you.” - Sylvie di Giusto 2. “You have to learn to read the moment, [...] and then adjust your behavior and make more intentional choices. I think one of the biggest challenges that we have nowadays, also driven by technology because we are constantly distracted by technology, is that we run on autopilot most of the day. Most of the day, we are so in our habits, in our patterns, that we do things, say things, that we are not even aware of, and they have a macro impact on our relationships. And we have to step back and sometimes turn that autopilot off, read the room, and be more intentional with the tools that we already have.” - Sylvie di Giusto 3. “I think that authenticity means that we all play a role, but different roles, and in those roles, we are true to ourselves. [...] And in all those roles, I promise you, I'm truly authentic. But if I would try to talk with my husband the way I talk with my clients, we wouldn't have made it to 23 years, I promise you. Or if I would treat my clients like I treat my children, or if I look at home like I would on stage, and vice versa. So, yes, we are all authentic in those roles, but I think we have to accept that you just do you, no matter the circumstances – which brings us back to situational awareness – I think it's a lie that this is possible.” - Sylvie di Giusto
Mentioned in this episode:* Dear InfoSec
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is speaking with Rear Admiral Brian Luther. After more than 30 years in the US Navy and at the Pentagon, Brian is now president and CEO of the insurance firm Navy Mutual. Brian talks about what he learned about leadership in his time commanding an aircraft carrier in the Navy and how he has translated his skills into working in the private sector. He and Steve also discuss how leaders can move from a tactical mindset into a logistical one, and prepare your team for worst case scenarios.
Key Takeaways:1. There might be differences between generations or people of different cultures, but fundamentally most people want the same things, and basic respect goes a long way. 2. As a leader, don’t get bogged down in tactics. Remember to think about the logistics, so there is a plan B if something goes awry. 3. Technology can be an immensely useful tool, but don’t get overly dependent on it.
Tune in to hear more about:1. The three stages of leadership (7:46) 2. Conducting business in volatile regions (12:28) 3. How a tabletop drill can reveal important weaknesses in your organization’s crisis response (18:48)
Standout Quotes:1. “You have to very clearly articulate to the people what you want done. And if it's very specific, you say, ‘I want this done,’ and if it's generic, you say, ‘I want this outcome,’ right? You can't say I want a general outcome when you have something specific in mind, because they're going to go off and do it whatever way you want. But if you're very clear, ‘I want this done this way,’ or ‘I just want this outcome,’ and you decide, delegate, disappear, you'd be amazed at what people can do.” - Brian Luther 2. “If you go there and give them an opportunity to see you as just who you are, and learn them just as they are, you find that there's more in common than people would give credit for. So I would always say, before you go internationally, take some time to learn where you're going and respect the culture that you're going to be operating in.” - Brian Luther 3. “There are tremendous benefits associated with technology, but any strength pushed too far is a weakness [...]. Don't be overreliant on something, and you put all your eggs in that one basket and you lose it, and then you don't have a second or a third option. You should be asking yourself, ‘What if I lose this, what if they figure out a way to foil that?’ Because, remember, we put something out there, and in a strategic competition, there's move-countermove all the time. […] So use it as a tool, but don't be totally dependent on it that if someone takes that tool away from you, your whole organization collapses.” - Brian Luther
Mentioned in this episode:* Dear InfoSec
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve sits down with Paul Bartel, a senior intelligence analyst with PeakMetrics. Paul was previously with the Defense Intelligence Agency, and he speaks with Steve about his experience working in the government sector, how the public and private sectors can cooperate more effectively, and what businesses can do to protect themselves from misinformation campaigns.
Key Takeaways:
1. Generative AI is rapidly changing the nature of misinformation.
2. Social media companies must take more responsibility for moderating the content on their platforms.
3. To protect your organization from damage from misinformation, being aware of the current information environment and what information is out there about you, is key.
Tune in to hear more about:
1. Paul Bartel’s background with the Defense Intelligence Agency (1:30)
2. The three primary sources of misinformation in the US (4:40)
3. How businesses can adapt to the changing information environment (17:56)
Standout Quotes:
1. “I think one of the biggest things that we have going now, and this is obviously in every sort of sector, is the use of generative AI. So what we're seeing a lot in social media now is instead of just random accounts that might be controlled by a person or two, what you're seeing is hundreds and hundreds of bot accounts that are able to push forward a large amount of information very quickly.” - Paul Bartel
2. “The biggest thing I think that needs to start happening is the social media companies really especially need to take accountability for their own clientele base that might be spreading the misinformation.” - Paul Bartel
3. “Getting an early handle on what's being said about them, and the information environment at large, can help them [organizations] navigate a lot of the challenges that we see in an information environment that's pushing out more and more information and can change on a minute to minute, hour to hour basis.” - Paul Bartel
Mentioned in this episode:* Dear InfoSec
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today we’re listening to the second half of Steve’s recent Emerging Threats webinar for security leaders. In this episode, Steve responds to audience questions, covering everything from government regulation to supply chain to raising awareness within your organization.
Steve Durbin’s Contact Information:
steve.durbin@securityforum.org
Steve Durbin on LinkedIn
Key Takeaways:
1. Knowing what your crown jewels are and how to protect them is paramount in a volatile world.
2. The government should do what the government does well, and it should let businesses do what businesses do well. The government should provide clear guidelines, but then there should be little interference.
3. Everything begins and ends with cyber resilience. How do we deal with the aftermath of the cyber incident that inevitably will occur?
Tune in to hear more about:
1. How to get the board to care about cybersecurity and cyber risk (2:48)
2. How to avoid making regulatory compliance a tick box exercise (9:13)
3. How ISF can help make your organization more resilient (26:06)
Standout Quotes:
1. “I like bringing people into the cyber space that are not technical. That doesn't mean to say you don't need technical people in cyber – you do, your security team needs to have a combination of the two – but I do very much like bringing them in from the business because their perspective is very much more about how they're going to make use of the technologies and therefore the use and the role that cybersecurity can play in securing the critical assets. Now, because we obviously are in an industry where there's a shortage of skills, what it does do is open up the markets to attracting – if you get it right – a whole variety of people that perhaps you wouldn't normally be able to bring into cybersecurity. So not only does it give you fresh perspective, not only does it align you more closely with the business, but it also opens up a pool of talent that otherwise might not be there.” - Steve Durbin
“I don't actually differentiate very much anymore between cyber risk and enterprise risk. [...] The reason I don't is that for me, I've become very much more convinced that cyber is so integral in everything that we do, that actually you create something of a problem for yourself if you begin to differentiate between enterprise and cyber.” Steve Durbin
“We need to make it simple for our users to be able to contact somebody in security if they are at all concerned about something that they've seen either through their email, on a system. And all too often we're not doing that. I can't tell you the number of times I've spoken to organizations and they simply aren't doing some of those basics. We don't need to complicate it all the time.” Steve Durbin
Mentioned in this episode:* Dear InfoSec
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
We’re starting 2025 with a preview of the episodes ahead, featuring Steve in conversation with thought leaders and security experts from around the world. We look forward to sharing the full episodes with you this winter. Stay tuned!
Featured:•Rear Admiral Brian Luther, president and CEO of the insurance firm Navy Mutual
•Duncan Wardle, former head of Innovation and Creativity at Disney
•Dr. Kate Darling, research scientist at the MIT Media Lab, research lead at the Boston Dynamics AI Institute
•Best-selling author and hypnotist Dr. Paul McKenna
•Author and leadership expert Sylvie di Giusto
•Paul Bartel, senior intelligence analyst with PeakMetrics
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode is our annual lookahead to next year, as we present Steve’s recent Emerging Threats webinar for security leaders. You’ll get to hear Steve share some of his thoughts on the threats cybersecurity professionals should be prepared to see in 2025. And of course, he also offers suggestions on how to handle these threats.
Steve Durbin’s Contact Information:
steve.durbin@securityforum.org
Steve Durbin on Linkedin
Key Takeaways:
1. Cybersecurity is becoming more of a business issue, which presents both opportunities and challenges.
2. Supply chain, cloud storage, data integrity, and AI will be key information security issues in 2025.
3. Information security professionals must learn how to align cybersecurity objectives with business objectives.
Tune in to hear more about:
1. Key information security challenges for 2025 (4:20)
2. How to manage supply chain risks and AI-related security challenges (9:34)
3. How to align cybersecurity objectives with business objectives (20:16)
Standout Quotes:
1. “The piece that worries me the most, and I've said this for a very long time, is the data integrity. AI data sets are vulnerable to deliberate poisoning or accidental pollution. Now, if I talk to AI providers, they will tell me that their AI is sufficiently intelligent, that it can really spot these things. I don't buy it. If I'm using AI, I want to make sure that the data it's actually telling me to make decisions about has a huge amount of the traditional information security guidance around it.” - Steve Durbin
2. “The challenge for us is to align cyber risk management with the needs of the business by identifying how risk management and resilience are aligned and help to meet business objectives. That way, I can guarantee you will get the ear of the business. And if you can crack that one, then some of the other issues that we're dealing with, such as resourcing, such as alignment, such as commitment, tend to go away.” - Steve Durbin
3. “The ones that I think are really going to succeed and flourish in 2025 are going to have aligned security with the business, and are going to have put in place mechanisms for all elements to change in sync with each other. Keeping on track is going to require a huge amount of collective collaboration across the enterprise.” - Steve Durbin
Mentioned in this episode:
ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, journalist Nick Witchell speaks with Steve for the second of a two-part conversation about the coming Trump administration. Nick and Steve consider how Trump’s famously unpredictable behavior may impact business confidence and the steps business leaders can take to insulate their business from possible market changes.
Key Takeaways:
1. For business leaders, there is reason to be optimistic about the incoming Trump administration.
2. Businesses in the US can take a “sit back, wait, and see” approach and await what new policies Donald Trump introduces in the beginning of his presidency.
3. It’s always wise to invest in cyber resilience.
Tune in to hear more about:
1. How the incoming Trump Administration can benefit businesses (1:44)
2. How to “trump-proof” your business (5:02)
3. The constant need for cyber resilience, no matter who’s leading the country (8:07)
Standout Quotes:
1. “So what do you expect from any incoming elected leader? Well, you hope for clarity. You hope for a very clear set of guidelines within which you can operate. You hope for removal of ambiguity. You hope for a reduction, I would say, in unnecessary regulation. The opposite of that, that what slows business down is an increase in regulation that is perhaps unnecessary and a lack of clarity. So I think that businesses will be hoping for that clarity.” - Steve Durbin
2. “I think that certainly focusing more on the need for cyber resilience is something that business leaders need to do. I don't know that I particularly want my government to be telling me what to do. So I very much like being able to run my business in the way that I think is best suited to my needs. I'm not a fan of nanny government. What I am a fan of is clarity in government, understanding from government, and allowing me to get on and do what I'm good at.” - Steve Durbin
3. “People are desperately looking for some form of guidance, something to trust. And I think that business leaders have a relatively unique opportunity, because we do have huge responsibility to the people that work within our businesses and also to our customers. And there's a significant opportunity, I think, in that, to carve out a path that allows us to be viewed in a way that, yes, suits the needs of the business, but also fills this gap in society for something that you can actually trust, something that people know you really do stand for and can get behind.” - Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, journalist Nick Witchell speaks with Steve about the coming Trump administration will mean for businesses. In the first part of their two-part discussion, Steve and Nick consider potential changes to the US approach to tech regulation and foreign policy.
Key Takeaways:
1. The fact that cyber security wasn’t part of Donald Trump’s campaign, doesn’t necessarily mean it won’t be a focus of his presidency.
2. Election interference is about misinformation as much (if not more) as it is about hackers getting into voting systems.
3. Government must collaborate with private sector to create meaningful policies around digital security.
Tune in to hear more about:
1. Expectations and hopes for the Trump administration’s approach to cyber security (2:35)
2. Regulation of social media (6:51)
3. The importance of cooperation between government and private sector (11:43)
Standout Quotes:
1. “If we look at some of the initiatives that he [Donald Trump] has in place around, for instance, immigration, then cybersecurity is fairly core and central to some of these programs and plans, because anything that involves technology, of course, also involves cybersecurity. So I think that that's the way we're going to start seeing cyber coming into his perspective on the world. Where it touches some of his other frontline policies, then we're going to see it playing a role.” - Steve Durbin
2. “As soon as you implement technology without security, you're creating a huge problem for yourself further down the road; one which, unless you have invested ahead of time, is going to cost you a horrible amount of money to try to fix later.” - Steve Durbin
3. “You need to have people in government who've actually been there and done it, because if you haven't, then where do you begin? And so I'd like to see a lot more collaboration between government and private sector in terms of getting a lot more knowledge, frontline knowledge, into some of the things that you absolutely must do to secure this technology, rather than simply deciding that that's the way we're going to go and then leaving it up to the different departments to figure things out.” - Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
An interview with Steve Durbin, ISF CEO, by Security editor Stephen Pritchard. Originally published by Security Insights Podcast.
Cybersecurity and geopolitics are more tightly linked than ever.
The growth of online espionage, attacks by state actors, and governments turning a blind eye to cybercrime, are all increasing risk.
And the “attack surface” is growing too. More and more of what we do every day is online, and this presents more opportunities to bad actors. In a connected world, it does not take much to cause huge disruption, whether by accident or design.
The rise in ransomware over the decade shows just how vulnerable we are to cyber attack. And some of the most prolific ransomware groups have at least informal ties to nation states. But behind the scenes, the threats from state-based, not just state sanctioned, cyber attacks are growing.
This, in turn, needs a different response from organisations, and their security teams. Geopolitics is driving cybersecurity threats, in ways that could hardly be imagined in the early days of the information security business.
Our guest this week is Steve Durbin, CEO of the Information Security Forum. As he points out, a lot has changed over the last few decades, and especially in the last few years. We are now in a very risky place. And, in an increasingly connected world, cyber has the potential to be the “Achilles Heel” of our defences, he argues.
Could we see the current level of cyber threats spill over into more overt conflict? And do organisations have the resources to operate in a more dangerous world?
In this episode, ISF CEO Steve Durbin is in conversation with Raffael Marty, Executive Vice President and General Manager of Cybersecurity Management at ConnectWise. Raffael is also the author of Applied Security Visualization and the Security Data Lake. He and Steve discuss how to prevent data from being compromised, what government and private enterprise can learn from each other vis a vis cybersecurity, the pros and cons of cyberinsurance, and more.
Related ISF Resources:* Protecting the Crown Jewels: How To Secure Mission-Critical Assets
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This episode is the first part of a two-part conversation between Steve and Dr. Christopher Hand. Chris is a senior lecturer in psychology at the University of Glasgow in Scotland. He and Steve talk about trust and authenticity online, cyber-bullying in the context of work, and what we know so far about the decision to return to the office post-pandemic.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve is speaking with investigative tech journalist Geoff White, who has been covering tech and financial crime for more than 20 years. Listeners may be familiar with his popular podcast The Lazarus Heist for the BBC World Service, and now his new book, Rinsed: From Cartels to Crypto: How the Tech Industry Washes Money for the World's Deadliest Crooks, will be available from Penguin Random House next week. Steve and Geoff discuss current trends in organized cybercrime, how these criminals are—or maybe aren’t—adopting AI, and the difficulties law enforcement still faces in helping the victims of these crimes.
Key Takeaways:
1. Nation states and government agencies have been known to adopt tactics from organized crime gangs and activists – a sort of trickle-up effect.
2. As technological advancements are presenting criminals with new avenues for money laundering, law enforcement is not always able to keep up and instead is having to prioritize high level crimes.
3. The law enforcement landscape is a fast changing world, as agencies adapt and gain more awareness of cybercrime tactics relating to AI and cryptocurrencies.
Tune in to hear more about:
1. Cybercrime evolution, nation-state involvement, and tactics (3:31)
2. AI use in cybercrime, potential for innovation and defense (8:29)
3. Cybercrime and money laundering, with a focus on the role of technology and law enforcement (11:45)
4. Cybercrime, crypto, and organized crime evolution (15:59)
Standout Quotes:
1. “Sometimes the tools of organized cybercrime, gangs, nation states have also learned from hacktivists. From leaks from people like WikiLeaks or from Anonymous, they've learned the damage that a leak can do a leak of information can do. And that's fed into that disinformation piece nation states now extremely astute at getting in stealing information and then weaponizing that information to change elections, to change people's attitudes, to influence world events, the nation states have got both feet in to this cybercrime game.” -Geoff White
“I think maybe it's worth thinking like a criminal and understanding how thinking like a criminal is different to thinking like a different type of enterprise. The reason I enjoy thinking about organized crime and covering organized crime is because it's organized. These are networks, as you say, of professional, organized people. But they're not out to win customers. They're not like Microsoft and Google who wants to come out with innovation and innovative new products to win customers in their competition. No. They want to make money from victims. And frankly, as long as you're making enough money from your victims month in month out, you don't change. There's no reason to innovate. Crime gangs innovate when law enforcement and the force of authority stop them from making the money they usually make. That's when you innovate.” -Geoff White
“I think there was a time when, frankly, explaining Bitcoin to sort of rank and file police officers was a struggle. I think those days are gone … There's been this realization that things like cryptocurrency is something that law enforcement needs to be on top of.” -Geoff White
“As cryptocurrency gets larger, as more financial institutions get behind it, as governments get behind it, yes, it can make it more legitimate, it can expand the legitimacy of it. But it also creates more noise, if you like, for the criminals to hide.” -Geoff White
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
This is the second of a two-part conversation between Steve and Brian Lord, who is currently the Chief Executive Officer of Protection Group International. Prior to joining PGI, Brian served as the Deputy Director of a UK Government Agency governing the organization's Cyber and Intelligence Operations. Today, Steve and Brian discuss the proliferation of mis- and disinformation online, the potential security threats posed by AI, and the need for educating children in cyber awareness from a young age.
Key Takeaways:
1. The private sector serves as a skilled and necessary support to the public sector, working to counter mis- and disinformation campaigns, including those involving AI.
2. AI’s increasing ability to create fabricated images poses a particular threat to youth and other vulnerable users.
Tune in to hear more about:
1. Brian gives his assessment of cybersecurity threats during election years. (16:04)
2. Exploitation of vulnerable users remains a major concern in the digital space, requiring awareness, innovative countermeasures, and regulation. (31:0)
Standout Quotes:
“I think when we look at AI, we need to recognize it is a potentially long term larger threat to our institutions, our critical mass and infrastructure, and we need to put in countermeasures to be able to do that. But we also need to recognize that the most immediate impact on that is around what we call high harms, if you like. And I think that was one of the reasons the UK — over a torturously long period of time — introduced the The Online Harms Bill to be able to counter some of those issues. So we need to get AI in perspective. It is a threat. Of course it is a threat. But I see then when one looks at AI applied in the cybersecurity test, you know, automatic intelligence developing hacking techniques, bear in mind, AI is available to both sides. It's not just available to the attackers, it's available to the defenders. So what we are simply going to do is see that same kind of thing that we have in the more human-based countering the cybersecurity threat in an AI space.” -Brian Lord
“The problem we have now — now, one can counter that by the education of children, keeping them aware, and so on and so forth— the problem you have now is the ability, because of the availability of imagery online and AI's ability to create imagery, one can create an entirely fabricated image of a vulnerable target and say, this is you. Even though it isn’t … when you're looking at the most vulnerable in our society, that's a very, very difficult thing to counter, because it doesn't matter whether it's real to whoever sees it, or the fear from the most vulnerable people, people who see it, they will believe that it is real. And we've seen that.” -Brian Lord
Mentioned in this episode:
• ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve speaks with David Weisong, CIO of Information Systems at Energy Solutions, a growing company with many US government clients. He speaks with Steve about his experiences overseeing a full migration of the company’s security framework, how he got buy-in for security from the C-suite, and how he has approached the challenge of staffing.
Key Takeaways:
1. Organisations are advised to focus on protecting critical assets and closely monitoring any supply chain issues.
Security leaders and teams are also having to prepare policies for AI use and investigate cloud provider dependencies.
Security leaders and teams should be monitoring developments in quantum, staying in step with regulations and needed skills.
Tune in to hear more about:
1. Security risks in technology innovation and adoption (1:29)
The impact of quantum computing on cybersecurity and the need for organisations to prioritise legacy technology updates (6:59)
Volatility, uncertainty, and technological change in the security industry (12:45)
How technology innovations can disrupt and improve organisations (18:22)
Managing innovation in a rapidly changing digital landscape (20:40)
Limitations of accessing powerful technologies due to restrictions, threats, and security concerns (26:12)
Emerging threats and risks in technology, including quantum computing, AI, and legacy systems (32:18)
Standout Quotes:
1. “We're a professional services organisation, so our contracts are the foundation. And if they're not 100% met, then you actually don't proceed. So it became very easy to say, there's cause and effect here. And that's where that's taken a lot of … repeat exposure, I think, is one part of it, but also setting the stage that it's dynamic. It's not like, oh, yeah, we're done with that, so we can just kind of move on. It's like, we're done with this particular initiative right now. And there are more, and it will be changing probably, quarter to quarter.” - David Weisong
“There’s a lot of things that are being put onto platforms or systems that you sometimes get into the area where you might have a unique combination of things that creates problems. And so that's where I think the industry is looking at it still in a category basis. I think there's a need for a more holistic approach, dare I say, coordination or cooperation between companies and their solution offerings.” - David Weisong
“When I think about the three to five year window, I mean, there's clearly more fraud and more cybersecurity attacks. It is significant, and it's not decreasing. And so the ability for both organisations to share and for the industry that serving up different solutions, there has to be a coordination and a collaboration around that. Because the priority could change from year to year.” - David Weisong
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, Steve speaks with Steve Satterwhite, the founder and CEO of Entelligence, and author of "Above the Line: How the Golden Rule Rules the Bottom Line." He shares some simple but fresh ideas about how to find the right person for the right role, how to overcome the skills shortage, and why putting people first is the key to successful cybersecurity.
Key Takeaways:
1. Successful companies can upskill employees in technology, using positive experiences and promising opportunities.
2. Satterwhite reflects on fatherhood, emphasizing the importance of helping children discover their purpose and identity.
3. Satterwhite believes that the organisation’s role is to provide tools and systems for team members to thrive, while also acknowledging the reality of short-term employment.
4. Open-minded technology leaders who integrate technical skills with emotional intelligence thrive.
Tune in to hear more about:
1. Attracting and retaining talent in the cybersecurity industry (2:40)
2. Cybersecurity talent shortage and skills gap in enterprises (10:00)
3. Finding and upskilling cybersecurity professionals for new technologies (16:44)
4. Prioritising people in business to boost revenue and profits (21:58)
5. Prioritising emotional intelligence in technology leadership (27:06)
Standout Quotes:
1. “I believe that that culture attracts the kind of folks that are ambitious, that are hungry to learn, that are eager to move up in whatever way that they define moving up in their lives. And I think it's our job, really, as leaders, and especially here in our organisation. It’s to create that environment so that people can thrive.” - Steve Satterwhite
“Here’s a stupid analogy, but I like to use it because it's how I think about the business. It's really just to simplify it. Let's say that you're a new airline, or you have a new airline route that you want to go from Houston to Paris, and you're short of pilots to fly the big Dreamliner or the big Airbus from here to there. It's a different operation. So what we do is we go look for people that have been flying 737s most of their career. They're deeply passionate about flying, and they're really good at it, and all we need to do is just kind of upskill them in a short period of time just to fly a different airplane. It's still piloting, it’s still flying. That's what we do. So if you think about just the evolution of technology and the things that we're doing, all we're doing, constantly, at Entelligence is just upskilling people in the shortest possible time.” - Steve Satterwhite
Mentioned in this episode:
ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve sits down with Dr. Andrew Newell, Chief Scientific Officer at the British biometrics firm iProov, for a conversation about deep fakes. As technology improves, it’s becoming ever more difficult to determine what’s real and what’s fake. Steve and Andrew discuss what this will mean going forward for security, social media platforms, and everyday technology users.
Key Takeaways:
1. Technology is the key to mitigating the threat of deep fakes, which are synthetic images or videos created to deceive.
Deep fakes are becoming increasingly sophisticated, making them hard to spot.
Newell breaks down the problem into two parts: secure identity verification and detecting synthetic images.
Incentives for verifying imagery will radically shift as deep fakes become more prevalent.
Tune in to hear more about:
Deep fake technology and its potential impact on identity verification processes (5:57)
Preventing deep fake images and videos using technology and algorithmic systems (9:57)
Deep fakes and their potential uses, including filmmaking and education (13:11)
Deep fakes and their impact on society, with a focus on technology’s role in verifying authenticity (18:43)
Standout Quotes:
1. “I think the urgency here — and this is the absolutely key part — is that we need to get the technology in place to make sure that the processes that rely on the genuineness of the person in imagery, that we can have something in place that we know works, that we know that we can trust, and is something that is very easy to use.” - Andrew Newell
“I think on the protection of identity proofing systems against the threat from deep fakes, we have a technology solution now. And the urgency is to make sure that this technology is used wherever that we need to actually guard against that threat.” - Andrew Newell
“And one of the most important things, if not the most important thing, is: when we think about a way to mitigate these threats, it has to be something that works for everybody. We cannot end up with a system that only works for certain groups in a society.” - Andrew Newell
Mentioned in this episode:* Dear Infosec
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today we bring you the second conversation with ISF CEO Steve Durbin around the increasing impact of technology on society and business. Societies have always been divided, but how future divisions may manifest feels more uncertain than ever right now. In this episode, Steve and producer Tavia Gilbert offer an analysis of potential future scenarios, as well as practical tips for what organisations can do now to prepare.
Key Takeaways:1. The future will be defined by technology and social media, leading to a shift away from traditional divisions and towards a more complex world where data and information are highly instantaneous and influential.
2. Leadership will need strong empathy, consolidation skills, and the ability to challenge/be challenged.
3. Leaders should assume imperfection and constantly update their situational awareness to make informed decisions. They also ought to prioritize simplicity and clear communication to build trust and drive success.
Tune in to hear more about:
1. Leadership and organisation in a rapidly changing world (4:44)
2. The role of businesses in society, including their potential to fill the void left by declining trust in traditional leadership models (9:58)
3. Information security and the importance of skepticism in the digital age (14:33)
4. Technology’s impact on information sharing and nationalism (18:33)
5. Trust and verification in social media and supply chains (22:35)
6. Leadership, adapting to change, and the importance of soft skills in a rapidly changing world (28:23)
Standout Quotes:1. “Businesses have a new responsibility in the modern era … provide guidelines and stability in a time of deep division.” - Steve Durbin
Mentioned in this episode:* Dear Infosec
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode is the first of three conversations with ISF CEO Steve Durbin around the coming impact of technological development on society and business. We know that new technologies have always tested organisations, and technological innovation and integration into our lives and enterprises — it’s only accelerating. We offer an analysis of potential future scenarios, as well as practical tips for what organisations can do now to prepare.
Key Takeaways:
1. Organisations must prioritise supporting smaller entities in keeping up with the fast pace of technological change.
2. Security can deliver competitive advantage, but implementation challenges persist, and security risks can become low priority in a fast-paced tech landscape.
3. Organisations face pressure to modernise technology while managing legacy systems and regulatory demands.
4. CEOs must balance competing priorities, including ESG initiatives, employee expectations, and shareholder demands.
5. Political developments may force organisations to respect local restrictions on technologies.
6. Organisations are advised to protect crown jewels, ensure data protection, and monitor supply chain partners.
7. Organisations must prepare for quantum-proof encryption and socialise policies for AI use.
Tune in to hear more about:
1. The impact of technological innovation on business and society, with a focus on adoption challenges and timing (0:00)
2. Security risks in technology innovation and adoption (1:29)
3. The impact of quantum computing on cybersecurity and the need for organizations to prioritize legacy technology updates (6:59)
4. Volatility, uncertainty, and technological change in the security industry (12:45)
5. How technology innovations can disrupt and improve organizations (18:22)
6. Managing innovation in a rapidly challenging digital landscape (20:40)
7. Limitations of accessing powerful technologies due to restrictions, threats, and security concerns (26:12)
8. Emerging threats and risks in technology, including quantum computing, AI, and legacy systems (32:18)
Standout Quotes:
1. “Organisations could certainly find themselves cut off from the supercharged processing power, because it may be developed by a government for its own ends and restricted, expensive, all of those sorts of things, so that it effectively becomes unavailable. And I think organisations, despite all of that, are going to have to operate in the shadow of this massive computing power shift when it comes about as the pace of change accelerates, innovations proliferate, traditional life cycles of technology shorten.” - Steve Durbin
“If we're going to have smaller organisations within our overall ecosystem, we need to be just sparing a bit of a thought for how they might be keeping up with such a fast pace of change and how we're going to support them in continuing to meet some of the standards and bars that were setting, so that everybody benefits, frankly.” - Steve Durbin
“So the world is also reshaping, as we're introducing AI into what we're doing. And so again, I think that the challenge from the business perspective, from the security perspective, from the technology perspective, is really about: how do you focus on what is important for your organisation, for your people, for your customers, in a world that is constantly now changing? And the speed of that change is only going to get faster. And we haven't seen that before.” - Steve Durbin
“So you're in a much better position, if you can control your innovations irrespective of what's going on. But you're never going to be able, I think, to divorce yourself completely from the market, because you operate in the market. And so the speed at which the market is evolving is going to, I think, determine — to a certain extent, anyway — your success in managing your own innovation, so you may need to be innovating more quickly than you're comfortable, just in order to try to keep up.” - Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, BBC journalist Nick Witchell interviews Steve about the threat landscape in light of a number of damaging hacks that have recently been made public. They consider the challenges regulators face given the current geopolitical situation and discuss how organisations can create a thorough cyber defense and response plan.
Key Takeaways:
1. Organisations cannot abdicate responsibility for data security, even when outsourcing to third parties. They need strong incident response plans and ongoing assessment of third-party security capabilities.
2. In terms of any country’s political agenda on cybersecurity, AI regulation is often overshadowed by other issues.
3. Few parliamentarians and ministers come from a security background, which is one reason why it’s critical to provide guidance and insight to them.
4. A more thoughtful and funded approach to security would benefit society, considering the potential impact on people’s lives and the need for effective incident response.
Tune in to hear more about:
1. Accountability and responsibility in cybersecurity (1:59)
2. Role of cybersecurity centers and national institutions (5:13)
3. Government and political involvement in cybersecurity (8:29)
4. Public awareness and the ISF’s role (12:21)
5. Risk management and security investment (16:32)
6. Concerns about technology implementation (20:14)
Standout Quotes:
1. “We (at the ISF) don't want to be one of those organisations that's constantly barracking people and complaining. We want to be holding true to some of our founding principles, which is about providing best advice, providing some of the best tools, providing some of the best insights that we gather from our own team and also from our member community. But we do need to make more noise about that, because people desperately need to understand some of the implications, and indeed, very much more importantly, what they can actually practically do about it.” - Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s conversation is a fascinating discussion on the nature of data with Jannis Kallinikos, professor of Information Systems at the London School of Economics. Jannis co-wrote the recently published book Data Rules: Reinventing the Market Economy, in which he and co-author Cristina Alaimo posit that data are a fluid cultural record, rather than a static statistical entity. He and Steve discuss the implications of this understanding of data for the security industry, from how it could change regulatory approaches to how we understand ourselves as humans in relation to data.
Key Takeaways:1. Kallinikos argues that data are not just statistical entities, but cultural entities that convey aspects of our world and reality.
Data are cultural records, not just statistical entities, and are fundamental to economic and social transformation.
Durbin and Kallinikos discuss concerns about data-driven perspectives reinforcing narrow worldviews.
Data regulation needs to reflect data’s interactive and morphing nature and serves to protect society from greedy companies.
Kallinikos warns that politics has become instinct-based, with little time for reflection.
Tune in to hear more about:
1. Data’s role in society, economy, and transformation (0:00)
Data’s impact on society, culture, and individual perspectives, with a focus on regulation and balance (7:10)
Data as a living entity, challenges for security professionals, and need for education (18:01)
Data’s impact on society and politics, with a focus on education and government’s role in protecting data (23:15)
Standout Quotes:
1. “Data are cultural elements and not statistical entities. It makes a whole lot of difference. By cultural entities, we mean that they are records by which we represent our world. and we act upon the world. We use them to produce, we use them to interact, we use them to communicate. In this respect, data are cultural records, once again, and not statistical entities or entities like those ones that contemporary data science debates.“ - Jannis Kallinikos
“Think how many things we can do that were out of reach before these beasts and these technologies and the data we produce in the facilities that they prepare for us, how many things we can do that were not virtually possible before. So there is a positive side to it. But as you English say, there is no free lunch in life. And this applies here. We win a lot. But there are also important things that we lose.“ - Jannis Kallinikos
“But these are difficult discussions to have in politics. Because they require a little bit of reflection, a step back, a little bit of time. Politics, for good or bad, has become very instinct based over the last three or four decades. Instinct based, more to react, target, and produce reactions of a particular type that are mostly emotional or instinctual.“ - Jannis Kallinikos
Mentioned in this episode:* Times Higher Education: We need a social science of data by Cristina Alaimo and Jannis Kallinikos * ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
For our special Summer Listening series, we revisit some favorite listens: episodes that cover some of the most important, and current, issues in cyber.
In today’s episode, Steve speaks with actress, voice coach, leadership consultant, and expert in core energetics, or body-led psychotherapy, Kate Montague. Kate discusses the effectiveness in taking time to reset, what happens when you stay connected to your body and your breath, how to take the temperature of the room when the rooms are remote, and more.
Learn more about Kate Montague.
Mentioned in this episode: Royal Central School of Speech and Drama * Read the transcript of this episode * Subscribe to the ISF Podcast wherever you listen to podcasts * Connect* with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
For our special Summer Listening series, we revisit some favorite listens: episodes that cover some of the most important, and current, issues in cyber.
Today, ISF CEO Steve Durbin is in conversation with Dr. Brian Cox, professor of Particle Physics at the University of Manchester. Dr. Cox worked on the ATLAS experiment at the Large Hadron Collider at CERN in Switzerland and has co-written several books on physics, including Why does E=mc2? and The Quantum Universe. He’s also known for appearances in many science programmes for BBC radio and television, including In Einstein's Shadow and the BBC Horizon series. Dr. Cox and Steve discuss how to translate a complex message to a lay audience, the need for intellectual honesty, and the value of play even in serious endeavors.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
For our special Summer Listening series, we revisit some favorite listens: episodes that cover some of the most important, and current, issues in cyber.
In this episode, ISF CEO Steve Durbin speaks with computer programmer, philanthropist, and co-founder of Apple, Steve Wozniak. Woz reminisces about the past and looks into the future of Big Tech, and considers what both could mean for the future of security.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
For our special Summer Listening series, we revisit some favorite listens: episodes that cover some of the most important, and current, issues in cyber.
In this episode, Steve speaks with a guest whose focus includes human culture, behavior, and storytelling: singer/songwriter and activist Sir Bob Geldof, lead singer of the Boomtown Rats and founding member of Band Aid, famous for raising money for Ethiopian famine relief. Steve and Sir Bob discuss the effect of the Covid19 pandemic on creativity, the political turmoil facilitated by rapidly advancing digital technology, Sir Bob’s hope for fresh ideas, the courage to embrace change, and more.
Learn more about Sir Bob Geldof and the Boomtown Rats.
Mentioned in this episode: Pete Briquette * Simon Crowe * Garry Roberts * Vladimir Putin * Xi Jinping * Recep Tayyip Erdogan * Boris Johnson * Donald Trump * Charles Darwin * Sigmund Freud * Karl Marx * Live Aid * Live 8 * QAnon * Thomas Piketty * Shoshana Zuboff * Marshall McLuhan * Novacene: The Coming Age of Hyperintelligence* by James Lovelock * Richard Branson * Bill Gates * Steve Jobs * Mark Zuckerberg * Jack Ma * Larry Page * Sergey Brin * Winston Churchill * Alan Brooke * George Bernard Shaw * Tim Berners-Lee * Johannes Gutenberg * Colin Wilson * The Rolling Stones * Mick Jagger * Keith Richards * Billie Holiday * John Lennon * Paul McCartney * Paul Allen * Steve Wozniak * Gaia Theory * Read the transcript of this episode * Subscribe to the ISF Podcast wherever you listen to podcasts * Connect with us on LinkedIn and Twitter * From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Your listens
807
2nd Aug - 8th Aug
16
see all stats
Subscribe
Next
Reggie Butler — Bringing Your Home to Work
Top Episodes
Steve Durbin — Emerging Threats for 2022
by ISF Podcast
Steve Durbin — Emerging Threats for 2022: Q&A
by ISF Podcast
CxO series – Cyber Resiliency in a defining moment in history
by ISF Podcast*
For our special Summer Listening series, we revisit some favorite listens: episodes that cover some of the most important, and current, issues in cyber.
In this evergreen episode, Steve and Tavia discuss the constantly changing world of risk, what security can do to prepare for and mitigate risk, the role of the business leader, and the impact of risk management on strategy and business direction.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Steve recently sat for an interview with veteran journalist Julie MacDonald for a feature with The European. Last week, we listened to the first part of that conversation, and today, we’re hearing the second. Julie and Steve talk about scenario planning, transparency within industries, and what good leadership looks like in this complex moment in history.
Key Takeaways:1. Durbin emphasizes AI’s dependence on data integrity and the importance of starting with good data.
2. Durbin discusses the challenges of geopolitical threats and market flux, and how organizations must prepare for an uncertain future.
3. Durbin notes increased use of ISF’s supplier assessment tools to mitigate risks due to geopolitical tensions and COVID-19.
Tune in to hear more about:1. Cyber security, AI, and data integrity (0:00)
2. Cyber security threats, vulnerabilities, and supply chain risks (3:40)
3. Risk management, leadership priorities, and the importance of collaboration (9:28)
Standout Quotes:1. “Bear in mind that when it all comes crashing down, there isn't a piece of technology in the world that will get your systems back up and running. And so don't forget the role that people have to play. So look after the people, make sure that they understand the important role that they have, because I think all too often, we talk about them being the weakest link. Actually, they're the strongest link.“ - Steve Durbin
“You have to focus on the crown jewels. That's your starting point. Very often, people will say to me, well, how much should we be spending? And my answer to that is, it depends. It depends on your risk profile, depends how nervous you are, it depends if you're going to enter new markets, it depends if you're coming out of markets. So you have to, as the leader of an organization, I think, juggle all of those things. And you have to do it in a very sort of swanlike way.“ - Steve Durbin
“You will make mistakes. And the mistake itself isn't important. What is important is how you recover from that, and how you learn from it going forward. And how you share that with other people in your organization. And how you become very much more agile to take advantage of some of the opportunities that that might open up.“ - Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Steve recently sat for an interview with veteran journalist Julie MacDonald for a feature with The European. For the next two weeks, we’ll be presenting that conversation in two parts. In the first part, Julie and Steve discuss the regulatory landscape, improving communication across the business, and how enterprises can successfully marry technology with the human element of work.
Key Takeaways:1. Durbin emphasizes the importance of alignment in creating a culture that supports risk management and growth.
2. MacDonald emphasizes the need for transparency beyond organizational borders, including collaboration with competitors and regulators.
3. Large organizations have resources to keep up with supply chain risks, while midsize and small enterprises struggle.
4. Durbin stresses the need for basic security practices and security awareness training, providing feedback in real-time to help individuals remember what they should have done.
Tune in to hear more about:1. Cybersecurity risks and how businesses can manage them effectively (0:00)
2. Cybersecurity transparency, regulation, and communication (5:13)
Standout Quotes:1. “I think for security people, what they have to be better at is understanding the role that security plays in achieving the business objectives, the business strategy, because if they can do that, then suddenly they have the ear of the business. On the other side, from the business perspective, they need to understand the role that technology plays in achieving what they're trying to do. Because technology equals security equals risk.“ - Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, author and disability diversity expert Ruth Rathblott offers a fresh perspective on how we understand and approach diversity in the workplace. She and Steve discuss how DEI can benefit both your culture and your business, and they give practical tips for leaders looking to build a more inclusive environment.
Key Takeaways:1. Leaders need to go first in being vulnerable and trustworthy.
2. Hiding is universal and exhausting, and people fear judgement and rejection for keeping secrets.
3. Unhiding can increase staff retention and engagement.
4. Leaders who adopt unhiding can be more innovative and creative, and better connect with millennials and Gen Z employees.
5. Unhiding is the key to connection, and it will make leaders stronger and drive business results in today’s pandemic of loneliness.
Tune in to hear more about:1. Diversity, equity, and inclusion with a focus on disability inclusion (0:00)
2. Hiding and sharing personal aspects of one’s identity in the workplace, with a focus on disability and diversity (5:08)
3. Leadership vulnerability and creating a safe space for teams to thrive (10:26)
4. The benefits of “unhiding” in the workplace, leading to increased trust, retention, and innovation (14:41)
5. Uncovering hidden potential through self-awareness and connection (18:49)
Standout Quotes:1. It's funny, I was talking to a woman recently. And she said, I love this concept of hiding, I love the work that you're doing, Ruth, and as a leader, I will never unhide to my team. And I said, okay, why? And she said, because I don't trust them. And it got me into the space of thinking, Steve, that either she has the wrong team, or she's the wrong leader. Because if we can't trust our teams, why are we in this business? Because that's our job is to build teams that trust us, that work with us, that get us to our next level in terms of a company. And so how do we create those spaces? And it's by leaders going first, and being vulnerable. - Ruth Rathblott
“There is a privilege in being able to unhide. I recognize that. In terms of being able, whether you're in the securities industry or in a different industry, because there are still in 2024 reasons that people would be fearful, and for good reason be fearful, of sharing parts of themselves, for retaliation, et cetera. I think where I've seen the benefit and the other side is the retention increases. People feel better about the place that they work, because they don't feel like they have to hide that part of themselves. They feel like this is a company who understands me, I'm going to stay longer. They feel more engaged with their peers, because they're not hiding.” - Ruth Rathblott
“I use the methods of therapy. I use the methods of journaling. I use the methods of meditation, to just take a pause in our lives to say, what is holding me back? Where am I hiding part of myself to fit in for fear of judgment and fear of rejection? Take that inventory or that audit on yourself. Acknowledge it.” - Ruth Rathblott
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today is the second in a two-part conversation centered on cultural fluency with global leadership strategist and corporate coach Jane Hyun. Jane is the author of Leadership Toolkit for Asians: The Definitive Resource Guide for Breaking the Bamboo Ceiling and Breaking the Bamboo Ceiling: Career Strategies for Asians, and co-author of Flex: The New Playbook for Managing Across Differences. In this episode, Steve and Jane define cultural fluency and give more tips on fostering cohesion and innovation in global teams.
Key Takeaways:
1. To be effective in a global team with diverse languages and continents, leaders must recognize and attend to cultural differences.
2. Mergers and acquisitions can fail due to cultural differences.
3. In the security industry, retention is a significant issue, and creating a fun and thriving work environment can help address it.
Tune in to hear more about:
1. Cultural fluency and its importance in leadership, particularly when working with people from different backgrounds and cultures (0:00)
2. Cultural fluency in the workplace (6:17)
Standout Quotes:1. “It's actually about building leadership capacity to work across difference. And it's not just for one cultural group or another; it’s actually for everyone. To build that cultural self awareness and to create an environment where we can ask questions, thoughtfully, that we give some room to each other.” - Jane Hyun
Mentioned in this episode:* Flex: The New Playbook for Managing Across Differences * Breaking the Bamboo Ceiling: Career Strategies for Asians * Leadership Toolkit for Asians: The Definitive Resource Guide for Breaking the Bamboo Ceiling * ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today is the first in a two-part conversation centered on cultural fluency with global leadership strategist and corporate coach Jane Hyun. Jane is the author of Breaking the Bamboo Ceiling: Career Strategies for Asians, and co-author of Flex: The New Playbook for Managing Across Differences. In this episode, Steve and Jane discuss how leaders can get the best out of their workers in a remote work environment and discuss practical ways leaders can facilitate productive meetings with teams spread out all over the world.
Key Takeaways:
1. Leaders must cultivate self-awareness and recognition of areas for improvement in personal and professional growth.
2. Innovation can be driven by bringing different cultural norms and views together virtually.
3. Culturally adaptive facilitation can lead to more innovative ideas in remote settings.
Tune in to hear more about:
1. Navigating cultural differences in business leadership (0:00)
2. Self-awareness and cultural understanding in business leadership (3:18)
3. Remote work, cultural perspectives, and effective meeting strategies (6:51)
Standout Quotes:
1. “There's no way we can keep doing things the same way. Because if we do, we're gonna get nothing different, right? We’re not going to get the innovation that we want.” - Jane Hyun
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve speaks with Amanda Fennell, a security professional with over two decades in the industry who currently serves as CISO and CIO of Prove and adjunct professor of cybersecurity at Tulane University. She talks to Steve about why a CISO must be an educator at heart, how to embrace feedback in order to grow, and how young professionals can shape their careers in security as the role of the CISO evolves.
Key Takeaways:1. Important foundational principles in security include least privilege, risk mitigation, and vulnerability management.
2. Amanda Fennell suggests that new CISOs befriend their legal officers, in order to better understand security and risk.
3. Handing change can be a key indicator of high performance in security, with those who thrive in change being more likely to be high performers.
Tune in to hear more about:1. Teaching technical skills and emotional intelligence in a technical field (2:25)
2. Security leaders’ communication and education strategies (4:35)
3. Security fundamentals and vulnerability management (10:37)
4. Evolving role of CISOs, career progression, and coping with stress in security leadership positions (13:21)
5. Managing stress and mental health in leadership roles (18:57)
Standout Quotes:1. “It was a long, long time ago. My boss sat me down for a performance review and said, you have a reputation for not taking feedback well, because you're really sure that you're right. And I took that to heart. And for a long time, I did have to fake that feedback coming to me, like, ‘Thank you for the feedback. I'll think about this. That’s so …’ You know, whatever, and just freeze your face into a smile. Now, I love it. I invite it.” -Amanda Fennel.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is speaking with investigative tech journalist Geoff White, who has been covering tech and financial crime for more than 20 years. Listeners may be familiar with his popular podcast The Lazarus Heist for the BBC World Service, and now his new book, Rinsed: From Cartels to Crypto: How the Tech Industry Washes Money for the World's Deadliest Crooks, will be available from Penguin Random House next week. Steve and Geoff discuss current trends in organized cybercrime, how these criminals are—or maybe aren’t—adopting AI, and the difficulties law enforcement still faces in helping the victims of these crimes.
Key Takeaways:
1. Nation states and government agencies have been known to adopt tactics from organized crime gangs and activists – a sort of trickle-up effect.
2. As technological advancements are presenting criminals with new avenues for money laundering, law enforcement is not always able to keep up and instead is having to prioritize high level crimes.
3. The law enforcement landscape is a fast changing world, as agencies adapt and gain more awareness of cybercrime tactics relating to AI and cryptocurrencies.
Tune in to hear more about:
1. Cybercrime evolution, nation-state involvement, and tactics (3:31)
2. AI use in cybercrime, potential for innovation and defense (8:29)
3. Cybercrime and money laundering, with a focus on the role of technology and law enforcement (11:45)
4. Cybercrime, crypto, and organized crime evolution (15:59)
Standout Quotes:
1. “Sometimes the tools of organized cybercrime, gangs, nation states have also learned from hacktivists. From leaks from people like WikiLeaks or from Anonymous, they've learned the damage that a leak can do a leak of information can do. And that's fed into that disinformation piece nation states now extremely astute at getting in stealing information and then weaponizing that information to change elections, to change people's attitudes, to influence world events, the nation states have got both feet in to this cybercrime game.” -Geoff White
“I think maybe it's worth thinking like a criminal and understanding how thinking like a criminal is different to thinking like a different type of enterprise. The reason I enjoy thinking about organized crime and covering organized crime is because it's organized. These are networks, as you say, of professional, organized people. But they're not out to win customers. They're not like Microsoft and Google who wants to come out with innovation and innovative new products to win customers in their competition. No. They want to make money from victims. And frankly, as long as you're making enough money from your victims month in month out, you don't change. There's no reason to innovate. Crime gangs innovate when law enforcement and the force of authority stop them from making the money they usually make. That's when you innovate.” -Geoff White
“I think there was a time when, frankly, explaining Bitcoin to sort of rank and file police officers was a struggle. I think those days are gone … There's been this realization that things like cryptocurrency is something that law enforcement needs to be on top of.” -Geoff White
“As cryptocurrency gets larger, as more financial institutions get behind it, as governments get behind it, yes, it can make it more legitimate, it can expand the legitimacy of it. But it also creates more noise, if you like, for the criminals to hide.” -Geoff White
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Recently, British journalist Juliette Foster interviewed Steve for a feature in The European, and today we’re listening to that conversation. Steve and Juliette explore a range of topics, including how to get buy-in to your security strategy at all levels of the organization, how much security should cost, navigating the regulatory landscape, and which industries and enterprises Steve believes could be templates for security.
Key Takeaways:1. Good cyber strategy aligns with business strategy, is quantifiable, and involves all employees.
2. Durbin suggests involving security in project planning to avoid retrofitting security measures.
3. Durbin suggests that security teams need to spend more time explaining security implications to business leaders in a way they can understand.
4. Durbin suggests that leaders must create a personal investment in security by providing feedback and justifying costs in a way that resonates with each individual’s role and responsibilities.
5. Durbin highlights the evolving regulatory landscape, with a shift from standardization to protectionism and complexity for organizations.
6. Durbin highlights the evolving threat landscape, including malware, ransomware, and phishing attacks.
Tune in to hear more about:1. Aligning cybersecurity strategy with business goals and outcomes (1:36)
2. Cybersecurity strategies, testing, and budgeting (10:42)
3. Regulation complexity and its impact on businesses (18:00)
4. Cybersecurity investment, risk management, and emerging threats (22:44)
5. Evolving cyber threats and the importance of resilience (26:58)
Standout Quotes:
1. “What is important for organizations is not to become over fixated on the threats — that’s necessary, obviously, to have a good defense — but also to figure out this whole notion of resilience. How quickly could we get our systems back up and running? How quickly could we get our organization functioning again? How are we going to recover our data? Where are we storing it? Those sorts of things.” - Steve Durbin
“... the crux of good cyber strategy is having an alignment with a business strategy happening in alignment with what it is that the organization is looking to do on a daily basis, which in the majority of cases is: increase revenue, increase shareholder value, deliver back to employees, customers, and to further the ideals of the organization.” - Steve Durbin
“So the role of the security leader in any budget cycle is to try to align whatever spend she or he wishes to have with the future direction of travel of that organization. And if you can start to do that, then the whole conversation becomes very much easier. But I'm not a huge fan of setting fairly random percentages, because I think it sends entirely the wrong message. You run the risk of overspend or underspend. And what you actually want to be doing is spending appropriately to deliver the right level of protection for your critical assets, for your company, for your employees, for your shareholders, so that you can continue to provide a thriving environment.” - Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is speaking about security leadership with executive coach and CEO and Founder of Serenity in Leadership Thom Dennis. Thom brings his expertise in psychology to bear in their discussion of the role of leaders in culture change, how to let go and trust your workforce, and practical tips for embracing the challenges leaders face day to day.
Key Takeaways:1. Fast-paced change and unease about people being away from work for extended periods of time are impacting leadership development.
2. Trust and clarity are key to successful remote work, letting go of control and setting clear objectives.
3. Incorporating breaks into work schedules serves to avoid burnout and increase productivity.
4. Thom Dennis predicts a shift in leadership thinking, where society’s demands will be prioritized over corporate standards.
Tune in to hear more about:1. Trust, fear, and delegation in leadership (3:56)
2. Creating space for focus, trust, and organizational leadership evolution (11:29)
3. Leadership evolution, prioritizing people over analysis, and fostering trust and community in organizations (17:22)
Standout Quotes:
1. Let people go. Tell them what you want them to achieve, tell them what the objectives are, and then let them get on with it. There's this sort of sense of fear that one isn't going to be in control. So I think people have got to learn to trust, and to be very clear about what it is that they're looking for. And then letting go. And I think often, you will get a far better result from that. Above anything else, I think, in forcing the briefer to be absolutely clear about what they want to achieve, that can save an awful lot of time and money in and of itself. -Thom Dennis
Some people who write and have incredibly busy jobs, they're up at five o'clock, or even four o'clock, and they’re writing for an hour, and then they go to the gym, and then they … and so on. Whatever your routine is. But if they're doing that, they're probably in bed at eight o'clock in the evening. So look, a part of this is self discipline, isn't it? It’s deciding on your routine, and then doing whatever it is that you can do to keep yourself to it. -Thom Dennis
I think we need to create quiet spaces for ourselves so that we can actually hear our inner knowing. They say that there's more signals that go from the heart to the brain than the other way around. And they've identified that there are brain type cells in the heart, and also in the gut. So all these things people have been talking about oh, well, I just go by my gut feelings, well, that's not as silly as it sounds. And I think that leaders of the future have got to become just a little bit less — not totally, but a little bit less cerebral, and more in touch with their inner knowing. — Thom Dennis
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is speaking with Erik Avakian, who served as CISO for the Commonwealth of Pennsylvania in the United States for more than twelve years before moving into the private sector, where he currently works as the technical counselor at Info-Tech Research Group. Erik brings his passion and experience to a lively conversation in which he and Steve discuss coping with change through multiple leadership turnovers, practical examples of how security leaders can demonstrate their department’s value to an organization beyond theoretical breach prevention, and overcoming challenges in the public and private sectors.
Key Takeaways:
1. Embracing change in state/local government requires technical architecture and common architecture.
2. Public sector security faces unique challenges, including political considerations.
3. It’s critical for public funds to be used efficiently while also reducing duplication of work and building knowledge sharing across agencies.
4. Security testing and phishing simulations can demonstrate return on security investment, saving time and money in the long run.
Tune in to hear more about:
1. Embracing change in security leadership in the public sector (0:00)
2. Building security foundations in public sector organizations (4:45)
3. Funding challenges in security, with tips for effective resource utilization, building strong teams, and collaboration (8:48)
4. Demonstrating security value to business leaders through cost-benefit analysis and service metrics (14:02)
5. Demonstrating security value to non-technical stakeholders through practical examples (18:33)
Standout Quotes:
1. One of the reasons I love the industry and I loved the position of CISO is you're constantly trying to just improve, right? You're not trying to rebuild every, all the time. You know that the business might want to rebuild, but you're there to constantly improve that foundation, continuingly building your team, and continually building your capabilities. So regardless of who comes and goes, you have that foundation, and you continue to grow it. - Erik Avakian
It's really about enabling the business. How can we say yes, but do things more securely and put a positive spin on it? Whereas, you know, in the past, you know, security is looked at oh, these are the guys that say no. So really, a CISO's a partner to the business, a collaborator building relationships, and really, that's been the change, right? It's gone from less of a technical kind of a thing to being a coach, being a leader, and really working and building those relationships at the business level. - Erik Avakian
I look at it as almost like a baseball team. So in the baseball world, you have a catcher, you have a pitcher, you have all these people on the field. And it's identifying what are the strengths of your team, and letting those players — if we look at it from that perspective — letting them thrive, letting them grow in the position that they're passionate about. And then you can just grow in that passion, give them the training, give them extra training, helping them build where they're really good at and what they really like to do. And then the baseball world is that example. We wouldn't necessarily make the pitcher catch — they might not be comfortable with that — or the catcher pitch, and all sorts of other things. Because they do what they do well, that's their position on the field. And what I've found is that if we can do that, we can build our teams and build rock stars out of them in the places where they really are passionate about, then we have retention.
I think my retention throughout my tenure was almost 99%, because I looked at people as to what drives them. - Erik Avakian
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve and producer Tavia Gilbert discuss the impact artificial intelligence is having on the threat landscape and how businesses can leverage this new technology and collaborate with it successfully.
Key Takeaways:
1. AI risk is best presented in business-friendly terms when seeking to engage executives at the board level.
2. Steve Durbin takes the position that AI will not replace leadership roles, as human strengths like emotional intelligence and complex decision making are still essential.
3. AI risk management must be aligned with business objectives while ethical considerations are integrated into AI development.
4. Since AI regulation will be patchy, effective mitigation and security strategies must be built in from the start.
Tune in to hear more about:
1. AI’s impact on cybersecurity, including industrialized high-impact attacks and manipulation of data (0:00)
2. AI collaboration with humans, focusing on benefits and risks (4:12)
3. AI adoption in organizations, cybersecurity risks, and board involvement (11:09)
4. AI governance, risk management, and ethics (15:42)
Standout Quotes:
1. Cyber leaders have to present security issues in terms that board level executives can understand and act on, and that's certainly the case when it comes to AI. So that means reporting AI risk in financial, economic, operational terms, not just in technical terms. If you report in technical terms, you will lose the room exceptionally quickly. It also involves aligning AI risk management with business needs by you know, identifying how AI risk management and resilience are going to help to meet business objectives. And if you can do that, as opposed to losing the room, you will certainly win the room. -Steve Durbin
AI, of course, does provide some solution to that, in that if you can provide it with enough examples of what good looks like and what bad looks like in terms of data integrity, then the systems can, to an extent, differentiate between what is correct and what is incorrect. But the fact remains that data manipulation, changing data, whether that be in software code, whether it be in information that we're storing, all of those things remain a major concern. -Steve Durbin
We can’t turn the clock back. So at the ISF, you know, our goal is to try to help organizations figure out how to use this technology wisely. So we're going to be talking about ways humans and AI complement each other, such as collaboration, automation, problem solving, monitoring, oversight, all of those sorts of areas. And I think for these to work, and for us to work effectively with AI, we need to start by recognizing the strengths both we as people and also AI models can bring to the table. -Steve Durbin
I also think that boards really need to think through the impact of what they're doing with AI on the workforce, and indeed, on other stakeholders. And last, but certainly not least, what the governance implications of the use of AI might look like. And so therefore, what new policies controls need to be implemented. -Steve Durbin
We need to be paying specific attention to things like ethical risk assessment, working to detect and mitigate bias, ensure that there is, of course, informed consent when somebody interacts with AI. And we do need, I think, to be particularly mindful about bias, you know? Bias detection, bias mitigation. Those are fundamental, because we could end up making all sorts of decisions or having the machines make decisions that we didn't really want. So there's always going to be in that area, I think, in particular, a role for human oversight of AI activities. -Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
This is the second of a two-part conversation between Steve and Brian Lord, who is currently the Chief Executive Officer of Protection Group International. Prior to joining PGI, Brian served as the Deputy Director of a UK Government Agency governing the organization's Cyber and Intelligence Operations. Today, Steve and Brian discuss the proliferation of mis- and disinformation online, the potential security threats posed by AI, and the need for educating children in cyber awareness from a young age.
Key Takeaways:
1. The private sector serves as a skilled and necessary support to the public sector, working to counter mis- and disinformation campaigns, including those involving AI.
2. AI’s increasing ability to create fabricated images poses a particular threat to youth and other vulnerable users.
Tune in to hear more about:
1. Brian gives his assessment of cybersecurity threats during election years. (16:04)
2. Exploitation of vulnerable users remains a major concern in the digital space, requiring awareness, innovative countermeasures, and regulation. (31:0)
Standout Quotes:
“I think when we look at AI, we need to recognize it is a potentially long term larger threat to our institutions, our critical mass and infrastructure, and we need to put in countermeasures to be able to do that. But we also need to recognize that the most immediate impact on that is around what we call high harms, if you like. And I think that was one of the reasons the UK — over a torturously long period of time — introduced the The Online Harms Bill to be able to counter some of those issues. So we need to get AI in perspective. It is a threat. Of course it is a threat. But I see then when one looks at AI applied in the cybersecurity test, you know, automatic intelligence developing hacking techniques, bear in mind, AI is available to both sides. It's not just available to the attackers, it's available to the defenders. So what we are simply going to do is see that same kind of thing that we have in the more human-based countering the cybersecurity threat in an AI space.” -Brian Lord
“The problem we have now — now, one can counter that by the education of children, keeping them aware, and so on and so forth— the problem you have now is the ability, because of the availability of imagery online and AI's ability to create imagery, one can create an entirely fabricated image of a vulnerable target and say, this is you. Even though it isn’t … when you're looking at the most vulnerable in our society, that's a very, very difficult thing to counter, because it doesn't matter whether it's real to whoever sees it, or the fear from the most vulnerable people, people who see it, they will believe that it is real. And we've seen that.” -Brian Lord
Mentioned in this episode:
•ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
This episode is the first of two conversations between Steve and Brian Lord, who is currently the Chief Executive Officer of Protection Group International. Prior to joining PGI, Brian served as the Deputy Director of a UK Government Agency governing the organization's Cyber and Intelligence Operations. He brings his knowledge of both the public and private sector to bear in this wide-ranging conversation. Steve and Brian touch on the challenges small-midsize enterprises face in implementing cyber defenses, what effective cooperation between government and the private sector looks like, and the role insurance may play in cybersecurity.
Key Takeaways:
1. A widespread, societal approach involving both the public and private sectors is essential in order to address the increasingly complex risk landscape of cyber attacks.
2. At the public or governmental levels, there is an increasing need to bring affordable cyber security services to small and mid-sized businesses, because failing to do so puts those businesses and major supply chains at risk.
3. The private sector serves as a skilled and necessary support to the public sector, working to counter mis- and disinformation campaigns, including those involving AI.
Tune in to hear more about:
1. The National Cybersecurity Organization is part of GCHQ, serving to set regulatory standards and safeguards, communicate novel threats, and uphold national security measures in the digital space. (5:42)
2. Steve and Brian discuss existing challenges of small organizations lacking knowledge and expertise to meet cybersecurity regulations, leading to high costs for external advice and testing. (7:40)
Standout Quotes:
1. “...If you buy an external expertise — because you have to do, because either you haven’t got the demand to employ your own, or if you did the cost of employment would be very hard — the cost of buying an external advisor becomes very high. And I think the only way that can be addressed without compromising the standards is of course, to make more people develop more skills and more knowledge. And that, in a challenging way, is a long, long term problem. That is the biggest problem we have in the UK at the moment. And actually, in a lot of countries. The cost of implementing cybersecurity can quite often outweigh, as it may be seen within a smaller business context, the benefit.” -Brian Lord
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is in conversation with AI expert Eric Siegel. A former professor at Columbia University, Eric is the founder of the long-running Machine Learning Week conference series and a bestselling author. His latest book, The AI Playbook, looks at how businesses outside Big Tech can leverage machine learning to grow. He and Steve discuss the differences between generative and predictive AI, the most effective ways to implement AI into an organization’s operations, and how we might expect this technology to be useful in the future.
Key Takeaways:1. No matter how controlled or well thought out a project is, any project relying on AI is only as good as its data inputs.
2. The more we learn to differentiate types of AI and apply their functions skillfully, the more we will learn about what is possible.
3. As predictive AI systems emerge, applying quality data analysis to a well chosen project could make a measurable difference for a company’s bottom line.
Tune in to hear more about:1. Designing a project involving predictive analytics does require quality data and specific domain areas. (3:00)
2. Generative analytics is still in early stages, and popular notions around its use currently differ from what can reasonably be expected or achieved (4:42)
3. Using AI to work with errors and improve a system requires quality data and carefully applied labels (11:59)
Standout Quotes:
1. “It's absolutely critical to have a fine scope, a reasonable scope, well defined for the first project. But the most well defined, sort of, well, scoped project is, in another way, the biggest because really what we're talking about, if you're looking at what should your first opportunity be with predictive AI that you want to pursue, it should be your largest scale operation that stands to improve the most, and that even an incremental improvement provides a tremendous bottom line. -Eric Siegel
“ … It's such a funny time, because predictive and generative are really apples and oranges. They're both built on machine learning, which learns from data to predict. But generative isn't a reference to really something specific in terms of the technology; it's just how you're using it, which is to generate new content items. So, writing a first draft in human language, like English, or of code, or creating a first image or video — these endeavors typically need a human in the loop to review everything that it's generated. They're not autonomous. And the question is, how autonomous could they be?” -Eric Siegel
“You can only predict better than guessing, which turns out to be more than sufficient to drive an improvement to the bottom line. So who's going to click, buy, lie or die, or commit an act of fraud, or turn out to cancel or be a bad debtor? These are human behaviors for those examples, or it could be a corporate client, or it could be a mechanism like a satellite, or the wheel of a train that might fail. But whatever it is, we don't have clairvoyance or a magic crystal ball. We can't expect your computers to, either. So it's about tipping the odds in these numbers games and predicting better than guessing … no matter how good the data is and how devoid of wrong values and those types of errors, you're still going to have that limitation. There’s still a ceiling. No matter how advanced the method is, it's not going to become supernatural. There's a thing called chaos theory, which basically says that even if you knew all the neurons of every cell of the person's brain, you wouldn't necessarily be able to predict very far into the future. And of course, we don’t. So it's always limited data anyway.” -Eric Siegel
“I wrote this new book, The AI Playbook, because we need an organizational practice to make sure that we're sort of planning the project not just technically but organizationally and operationally, so that it actually gets deployed and makes a difference and actually improves operations. And in general, the awareness and understanding of it and how it can be integrated into organizations is still only improving.” -Eric Siegel
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is speaking with Mariarosaria Taddeo, Professor of Digital Ethics and Defence Technologies and Dslt Ethics Fellow at the Alan Turing Institute. Mariarosaria brings her expertise as a philosopher to bear in this discussion of why and how we must develop agreed-upon ethical principles and governance for cyber warfare.
Key Takeaways:
1. As cyber attacks increase, international humanitarian law and rules of war require a conceptual shift.
2. To maintain competitive advantage while upholding their values, liberal democracies are needing to move swiftly to develop and integrate regulation of emerging digital technologies and AI.
3. Many new technologies have a direct and harmful impact on the environment, so it’s imperative that any ethical AI be developed sustainably.
Tune in to hear more about:
1. The digital revolution affects how we do things, how we think about our environment, and how we interact with the environment. (1:10)
2. Regardless of how individual countries may wield new digital capabilities, liberal democracies as such must endeavor tirelessly to develop digital systems and AI that is well considered, that is ethically sound, and that does not discriminate. (5:20)
3. New digital capabilities may produce CO2 and other environmental impacts that will need to be recognized and accounted for as new technologies are being rolled out. (10:03)
Standout Quotes:
1. “The way in which international humanitarian laws works or just war theory works is that we tell you what kind of force, when, and how you can use it to regulate the conduct of states in war. Now, fast forward to 2007, cyber attacks against Estonia, and you have a different kind of war, where you have an aggressive behavior, but we're not using force anymore. How do you regulate this new phenomenon, if so far, we have regulated war by regulating force, but now this new type of war is not a force in itself or does not imply the use of force? So this is a conceptual shift. A concept which is not radically changing, but has acquired or identifies a new phenomenon which is new compared to what we used to do before.” - Mariarosario Taddeo
“I joke with my students when they come up with this same objection, I say, well, you know, we didn't stop putting alarms and locking our doors because sooner or later, somebody will break into the house. It's the same principle. The risk is there, it’s present. They’re gonna do things faster in a more dangerous way, but if we give up to the regulations, then we might as well surrender immediately, right?” - Mariarosario Taddeo
“LLMs, for example, large language models, ChatGPT for example, they consume a lot of the resources of our environment. We did with some of the students here of AI a few years ago a study where we show that training just one round of ChatGPT-3 would produce as much CO2 as 49 cars in the US for a year. It’s a huge toll on the environment. So ethical AI means also sustainably developed.” - Mariarosario Taddeo
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
A repeat of one of our top episodes from 2023:
October is Cyber Awareness Month, and we’re marking the occasion with a series of three episodes featuring Steve in conversation with ISF’s Regional Director for Europe, the Middle East and Africa, Dan Norman. Today, Steve and Dan discuss the importance of cyber resilience and how organisations can prepare for cyber attacks.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode was recorded at ISF’s 2023 Congress in Rotterdam. Steve sat down with Tali Sharot, professor of neuroscience at University College London, to talk about her fascinating research on optimism bias. Tali offers fresh, evidence-based ideas on effective communication for security leaders seeking to present their message to their board and raise cyber awareness within the organisation.
Key Takeaways:
1. Innately, the brain is an optimist.
2. Implications for the business community.
3. Present bias means that people care more about now than the future.
4. Data is key, and pairing anecdotes with data can be more effective.
Tune in to hear more about:
1. Sharot’s research about how emotion affects memory (0:28)
2. Optimism bias has implications for the way we evaluate risk (4:25)
3. Sharot considers present bias and how it shows up in organisations (9:39)
4. Why storytelling is so effective when paired with data (15:30)
Standout Quotes:
1. “It turns out that in behavioral economics, there was quite a lot of research about this thing called the optimism bias, which is our tendency to imagine the future as better than the past, than the present. And that's exactly what I was seeing in this experiment. And that was really the first experiment that I did looking at what goes on inside the brain that causes us to have these kind of rose-colored glasses on when we think about the future.” -Tali Sharot
“What we find again and again is that people underestimate the risk. And that's, of course, a problem. And it's not just underestimating risk. People also underestimate how long projects will take to complete, how much it would cost, underestimating budgets. All these are related to this phenomena of the optimism bias. And so it's really difficult to try to convince people that their estimate is incorrect. Because what we found is that if you give people information to try to correct their estimate, and you tell them actually, it's much worse than what you thought, your risk is much higher than what you're thinking, people don't take that information and change their belief to the extent that they should. They do learn a little bit, but not enough … However, if you tell them actually, you don't have as much risk as you think, you're in a great position, then they learn really quickly.” -Tali Sharot
“The immediacy is quite important, because we have what's called a present bias. We care more about the now than the future. In general, even if we're not aware of that.” -Tali Sharot
“And what stories do, they do a few things. First of all, we're more likely to attend to stories, right to listen, they're more interesting, they're more colorful, they're more detailed, we're more likely to remember them, partially because they usually elicit more emotion than just the data. So it's good to pair the two, to have the anecdote that kind of illustrates the data that you already have in hand.” -Tali Sharot
Mentioned in this episode:* Human-centred Security: Positively influencing security behaviour * ISF Analyst Insight Podcast * books by Tali Sharot
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
This week, we’ve got another fascinating conversation recorded at the 2023 ISF Congress in Rotterdam. This time, Steve speaks with generative AI expert Nina Schick. Nina and Steve discuss how AI, along with other technological trends that are evolving at exponential speed, are shaping both geopolitics and individual lives.
Key Takeaways:
1. Generative AI is reshaping the geopolitical landscape.
2. Educating ourselves and others about the implications of quickly evolving tech in global affairs.
3. Industries struggling to regulate exponential technology.
4. There are more questions than answers as we look to the future in tech.
Tune in to hear more about:
1. AI’s geopolitical impacts (3:13)
2. Learning about how tech is impacting global affairs (9:53)
3. Regulation challenges (11:55)
4. Nina Shick’s take on the economics of generative AI (16:27)
Standout Quotes:
1. “As the oil economies of Saudi Arabia and UAE seek to diversify away from oil and energy, one of the things that they're doing is trying to become very high tech economies when artificial intelligence is absolutely leading the way with these strategies. And there's so much money going to be invested in the Gulf in the coming decade when it comes to artificial intelligence. Again, even though these are relatively small countries, they are perhaps going to punch above their weight when it comes to power that is harnessed by artificial intelligence. And that means in a military sense, in an economic sense, and ultimately, you know, a geopolitical sense.” -Nina Schick
“I think the harder thing also are the non technical solutions – you know, education, literacy – how do people get upskilled in terms of understanding the new capabilities of artificial intelligence and how they will be deployed in their respective domains? So I think it's not only that there are technical solutions, there are also societal and learning solutions which perhaps we're going to have to get on top of very, very quickly.” -Nina Schick
“Regulators have to work with industry. There's no way they can do this themselves. And already in many of the kind of more promising areas with dealing with some of the challenges, such as information integrity, when you come to questions like provenance, you see industry championing the way and supporting regulators.” -Nina Schick
“Will there be economic value associated with AI? I think, absolutely. But the question is, how's that going to be distributed? And is it going to be monopolized? So that's going to happen with regards to the tech giants, who I think will become very, very, very powerful. I think this will continue to be a priority of utmost importance to governments. I think this challenge, or this kind of race between China and the US with regards to artificial intelligence will continue to play out. I think the Middle East is going to become a strong contender. And I suspect Europe might fall behind a little bit … And actually, I think that this technology is also going to be in the hands of millions of people.” -Nina Schick
Mentioned in this episode:* Threat Horizon 2024: the Disintegration of Trust * ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
This week, we have a rare repeat guest on the podcast. Listeners may remember innovator and thought leader Peter Hinssen from the 2019 ISF Congress in Dublin. We had him back this year at ISF’s 2023 Congress in Rotterdam. He and Steve had a chance to talk about the future of work post-pandemic. Their conversation offers lots of practical tips for leaders working to prevent workforce burnout and how boards can approach adopting new technologies like AI.
Key Takeaways:
1. COVID has made lasting impacts on the future of work.
2. Annual budgets and other commonly used business practices are in the process of evolving into ones that are more malleable and adaptive.
3. Companies will need to reinvent themselves to thrive in the new “never normal.”
4. With the rise of AI and large language models, organisations do have a lot of work ahead.
Tune in to hear more about:
1. COVID’s impact on the future of work (1:40)
2. Sunsetting pre-pandemic business norms while imagining new ones (2:47)
3. Companies in every sector will be reinventing themselves in order to thrive in the new “never normal.” (6:33)
4. As AI and large language models are integrated into global business, what’s next for business leaders? (14:12)
Standout Quotes:
1. “One of the good things I think that we've gotten back from COVID or that we've retained from COVID is that I think the acceleration of the future of work has really happened. I think we're now seeing companies that clearly see that the way we did HR, employment, and work pre pandemic, we can't just hope that that is going to come back. And I think that is a fundamental change that I think was really something that the pandemic helped us with.” -Peter Hinssen
“But you know, that stronghold, that idea, that framework of an annual budget that we've held on to for such a long time is very difficult to actually give up. But I think it's exciting, because I think in this never normal, we're going to see new mechanisms and new ideas and new concepts and new governance ideas that are going to come to fruition. But at this moment, we're still very much in that transition.” -Peter Hinssen
“I really believe after a decade of unicorn applause, we're now going to have a decade of potential phoenixes out there. And I think a big part as a leader in such a phoenix transformation is to actually give your workforce, your people that sense of we're going to do this together.” -Peter Hinssen
“We're going to have to deal with that governance of content, unstructured flows, and that's a whole new kettle of fish that we have to understand. New technologies, new mechanisms, new ways of dealing with that. And I think it's going to open up a huge opportunity in terms of thinking about risk and thinking about security in that context. So I don't think you can ignore this. This is the biggest thing that I have ever seen in 30 years in IT. And if you're not on top of this, you're gonna be behind … And I think honestly, more and more boards are going to need to figure out how to build the skills and the mechanisms and the place to discuss these things that are not just compliance with the tsunami, but also the innovations that you cannot afford to miss. And I think, honestly, that's going to change the dialogue in the board quite a bit.” -Peter Hinssen
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is in conversation with Christy Pretzinger, founder, president and CEO of WriterGirl. Over the past 20 years, Christy has grown the company from a modest freelance writing business into a healthcare content consultancy. She speaks with Steve about some of the practical tools she has implemented in order to grow the company’s culture, the role of leadership in training and retaining emotionally intelligent employees, and the impact her focus as a leader on the company’s cultural balance sheet has had on their financial balance sheet.
March 8th is International Women’s Day and we want to mark the occasion and make sure you haven’t missed our many valuable episodes with Steve in conversation with women in leadership. So we’ve put together a specially curated playlist featuring the best of women in leadership, and we want to give you special access. All we ask in return is this: just rate and review the ISF podcast on Apple Podcasts, Spotify, or wherever you listen, send a screenshot of that rating and review to tavia.gilbert@securityforum.org, and I’ll send you back special access to the curated playlist.
Key Takeaways:
1. Leaders should track their cultural balance sheet just as they watch their financial balance sheet.
2. A leader who is intentional about culture increases employee retention.
3. Helping employees grow in emotional intelligence as the company grows can make work more productive and rewarding for everyone, especially clients.
4. Technology is never the answer to a people problem, and it will never replace human connection.
Tune in to hear more about:
1. Pretzinger’s story of growing her business (1:45)
2. The cultural balance sheet and how leaders can create a corporate culture based on emotional intelligence (2:40)
3. Preventing employee turnover (9:09)
4. Implementing new technological solutions with sensitivity to employee experience and client needs (11:26)
5. The need for human connection in business even was we advance technologically (15:46)
6. Building a team that works from home (16:34)
7. Intentionality when building culture (17:10)
Standout Quotes:
1. “Anyone who looks at a balance sheet knows that employee turnover is a hidden cost. It doesn't show up on a balance sheet. And I can count on one hand the number of people that have left our organization. And in fact, I don't even need the whole hand. And many people who leave continue to work with us on a contracted basis, so there is very, very little turnover. And even our younger employees expressed interest in retiring from this organization, which is really great.” - Christy Pretzinger
“We had everybody do a day-long workshop. And it was incredibly revealing. It took a lot of time. And it was very … I guess the things that I look for when we do these things are what Brené talks about is what every human wants is love and belonging. They want love and belonging, and they want to know that they matter.” - Christy Pretzinger
“About retention: I think about, obviously, a hidden cost on the balance sheet. But what I think about too, is all of that intellectual property walking out your door. You know, you've got ,we have people who have been here, I think, my longest employee is 13 years, I think. She started right after she got married, and now she has five kids. So I've literally watched her grow up. If she walked out that door, and we were so much smaller, she literally built the sales department and built the CRM tool, and still worked very heavily in contributing to that — if she walked out the door, it would be devastating. But yet, that's not going to show up on a balance sheet. .” - Christy Pretzinger
“So I still think that there is a tremendous place for — and not only a place but a need and a yearning for true human connection. And because I own a virtual organization, I know that you can have true human connection virtually, but it does require a camera.” - Christy Pretzinger
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is speaking with American football coach Randy Jackson. During his 30-year tenure coaching high school football in Texas, Randy earned a reputation for transforming struggling programs. In 2022, in a move reminiscent of Ted Lasso, he moved to Germany to coach the Potsdam Royals, and with Jackson as the offensive coordinator, the Royals went all the way to the German Bowl. When he’s not coaching football, Randy is a business consultant. Today, he and Steve talk about how he applies his experience as a football coach in the business world. They go beyond sport cliches and dig into some concrete ways leaders can build the culture of their organisation.
Key Takeaways:1. At its inception, any organisation can benefit from building relationships and establishing a shared vision.
2. Leaders will do well to speak up frequently, reminding teams of shared aims.
3. When something goes wrong (or right!) it can be a good time to reflect, or as Randy puts it, perform an autopsy.
Tune in to hear more about:1. Establishing a shared vision, charting a collective course. (3:50)
2. Staying vocal as a leader. (6:05)
3. Whether something goes to plan or not, an autopsy of the scenario can be a helpful way forward. (10:06)
Standout Quotes:1. “So this is an activity I always do, and I did this in Germany, but close your eyes and then turn around three times, and then point True north. Well, I don't know how many people are in the room, but let's say I had 50. You're going to have 50 fingers pointing in all different directions. And so what we're going to do is, people will point in the same direction if you give them something to point at. And what you're in on you're in with.”” -Randy Jackson
“And if you'll talk about it, you can achieve it, but you can't talk about it once a week – you must talk about it. So whatever you want, I think every leader should say, here are the three things I want. You got to talk about those three things every day.” -Randy Jackson
“And the autopsy is about improvement, right? It's not about finger pointing, it's about trying to figure out how the collective can, if they hit that situation, again in the future, can adapt or behave differently.” -Steve Durbin
Mentioned in this episode:* Building Tomorrow’s Security Workforce * ISF Analyst Insight Podcast * Titles by Randy Jackson
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today's installment of the ISF Podcast revisits an earlier episode published February of 2023.
In this episode, ISF CEO Steve Durbin is speaking with author and former Chief Business Officer of Google X Mo Gawdat. Mo and Steve discuss the complicated relationship humans have with technology, particularly AI, and how both individuals and businesses can navigate that wisely.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Steve is in conversation with quantum computing expert Konstantinos Karagiannis. Konstantinos is the Director of Quantum Computing Services at Protiviti, where he helps companies prepare for quantum opportunities and threats. He talks to Steve about how this nascent technology is already a security concern and what security leaders can do now to prevent problems down the road. He also offers ideas for overcoming the skills shortages that both the security and quantum computing fields face.
If you’re interested in discovering more about the technological implications of automation, machine learning and quantum computing, download the ISF’s Threat Horizon 2025: Scenarios for an uncertain future report, available to members on ISF Live. Not a member? Get in touch with your regional director today at https://www.securityforum.org/contact/.
Research:
Threat Horizon 2025: Scenarios for an uncertain future - full report (ISFLIve)
Key Takeaways:
1. It’s a big year for compliance. Per NIST, companies are asked to start their plans for migration in 2024.
2. Konstantinos sees a need for quantum programs at the university level.
3. Where quantum is today is just a glimpse of where it’s going.
Tune in to hear more about:
1. The future is now! (4:38)
2. What can be done at the university level to resource the industry (7:45)
3. Quantum computing speeds as an advantage (12:17)
Standout Quotes:
1. “It'll be time for companies, starting in 2024, to start their plans for migration. In the US, the White House has already telegraphed what's going to be expected of federal agencies. They published the NSM-10 memo, which states that once the finalists are out, you have to have a plan for migration, the timeline for deprecation of ciphers, all these steps are going to kick in.” -Konstantinos Karagiannis
“I don't see any university have that set for a quantum program. Like, you can't just go, come out, and like, we know that we can hire you to like, implement algorithms. There's no such thing. And I'd like to see that kind of preparation, so within a few years, we've got a whole crew of folks ready to at least implement algorithms. They might not be able to create a brand new one, but there's only a few dozen of them in the world anyway.” -Konstantinos Karagiannis
“Quantum works well on simulations. You could simulate up to like, 50 qubits, let's say, and you can make sure your algorithm works right. And you could torture test it. And then when you're ready to actually run it, that's when you pay for what we call shots, which is just runs on a quantum computer. So yeah, you might work on this, tweak it all month, and then you spend $1,000, let's say, and you do your runs, and you're good. You're done.” -Konstantinos Karagiannis
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode is the second part of journalist Nick Witchell’s conversation with Steve at the 2023 ISF Congress in Rotterdam. As organisations become increasingly data-driven, technologies like artificial intelligence and quantum computing will have a huge impact on data security. Today, Steve looks at how security professionals can help their organisations adopt these technologies safely and smartly.
Key Takeaways:
1. Trade policy is feeling the effects of geopolitical conflicts.
2. Major technological advancements are not without environmental impact.
3. Business leaders would do well to remember that data in any quantitity can be faulty, can be tampered with, making regulation and collaboration all the more important.
Tune in to hear more about:
1. Conflicts such as the war in Ukraine shine a particular light on organisations’ areas of vulnerability. (2:42)
2. In the context of global warming, quantum computing poses major challeges. (5:50)
3. As quantity of data increases exponentially, so does the importance of quality. (9:33)
Standout Quotes:
1. “I think that the situation in the Ukraine, in particular, was a huge wake up call for a lot of organisations and a lot of individuals. I think very few people actually understood the way in which complex supply chains today actually operate. We do take things for granted, don't we?” -Steve Durbin
“Quantum computing requires immense computing power. Immense computing power requires a huge amount of electricity and generates a huge amount of heat. So if you think about all of those things in the environmental context, we really do need to figure out how we're going to exist in a world where global warming is a reality, where we are really driving as hard as we can in pursuit of different technological answers.” -Steve Durbin
“My biggest concern, the biggest threat that I see is data that has been tampered with. Because you or I may look at something and think that doesn't look quite right, so we'll dig into it. A machine doesn't necessarily do that.” -Steve Durbin
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode is the first of two interviews with Steve Durbin in discussion with journalist Nick Witchell. Today they discuss cybersecurity in the current geopolitical moment. Steve looks at the current security landscape in that context, and touches on how security leaders can help guide their organisations in these turbulent times.
Key Takeaways:
1. Boards and CISOs need to be ready to step in with the necessary mitigation measures when increased cyber risks manifest themselves and when they are related to geopolitical tensions.
Social media presents real advantages, but when it comes to information, users must diligently consider the source.
Business leaders have many opportunities to learn from one another and gain supports as they move into the future.
Tune in to hear more about:
1. Nick Witchell asks Steve Durbin about companies’ overall readiness to address cyber risks in a global context. (4:07)
Steve Durbin reflects on misinformation and disinformation in the age of social media. (7:19)
Where business leaders can find support. (11:00)
Standout Quotes:
1. “There is, I think, probably two things that give me real comfort that we're moving in the right direction. The first thing is that there is an understanding now in the boardroom, that these things are material, and that they have to pay attention to them. And secondly, there is an enthusiasm in the boardroom to be involved in that, because they understand the implications on the things that they measure: risk, market cap, shareholders, and so on. So I think we're in probably a much better place to deal with some of these challenges this year than perhaps when we last spoke 12 months ago.” - Steve Durbin
“Personally, what I like to do is to take a number of different data points. So don't become over reliant on one particular feed, because again, within the social media space, if you think about it, you tend to lead always to people who are perhaps of a similar mind to yourself. And I think in the sorts of times that we're in at the moment, it's very important for everybody to try and get a balanced perspective, a balanced view.” - Steve Durbin
“ I think if I were to sum up the major role of the ISF at the moment, it's in that one word, support.” - Steve Durbin
Mentioned in this episode:* Threat Intelligence: React and prepare * Rehearsing Your Cyber Incident Response Capability During Periods of Instability * CISOs Role During Periods of Instability * ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
At the 2023 ISF Congress in Rotterdam, Steve sits down with keynote speaker Beau Lotto. Beau holds his PhD in Cellular and Molecular Developmental Neuroscience, and he teaches organizations how to apply scientific truths about perception to adapt and thrive in an ever-changing world. He has helped brands like Cirque du Soleil, Microsoft and L’oreal gain valuable, science-backed insights into their businesses and customers. Beau talks to Steve about how security leaders can change their way of being to effect change at their organisations, and he offers practical ways of incorporating play and diversity to improve team outcomes.
Key Takeaways:
1. Business leaders have a unique role when it comes to establishing business culture.
2. What you do is your function; what you are about is your business.
3. Authenticity is critical for buy in, and buy in is critical for success.
4. Seemingly small changes in initial conditions are powerful and can yield massive results.
5. Embracing uncertainty is a winning strategy, and it can be fun.
Tune in to hear more about:
1. The Host Effect (1:40)
2. Measuring Relevance (3:15)
3. Leading with Authenticity (8:55)
4. Transforming Initial Conditions (12:00)
5. Play as a Mindset (14:30)
Standout Quotes:
1. “... have you noticed that the personality of the party is very much the personality of the host? … it's because the brain infects and is infected by other people.”
“Your business is how and why are you relevant … what we do with my Lab of Misfits is we then measure their actual relevance on the audience. So we, in that case, we would measure the brain activity of the people during the performance, what happened to people before and after. So now what they can do is take ownership of what we call the human truth of value that they're actually in the business of.”
“You can be authentic in any situation … You don't need others to shape that for you; that's intrinsic within you. And that gives you that sense of being proactive, which is essential in times of uncertainty, which is what we're facing all the time.”
“...if you look at, say, the initial conditions of the solar system, you have Mars, let’s take Mars. If you were to alter its proximity to the Sun by one millimeter, make it a little one millimeter closer, in 10% of models the whole solar system collapses. If you take Mars and put it one millimeter further away, in 10% of the models the whole cell system explodes and goes off into space … so small change in the initial conditions can have massive transformative effects.”
“... play is actually an evolved brain state where we actually choose uncertainty. We don't avoid it. We actually want it. It's not that we hate it, but we're going to turn down our loathing of it. We actually seek it out. Right? And you know, not knowing who's going to win the Rugby World Cup is why it's fun to watch.”
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, we’re previewing some of the best moments from the episodes you’ll be hearing from the podcast this season. Most of these were recorded at ISF Congress 2023 in Rotterdam this past October, with a few others in the mix.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode features Steve’s recent presentation to ISF members on Emerging Threats for next year. He offers a picture of the evolution of cyber, and the resulting challenges and opportunities for security professionals, in 2024.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode features an interview Steve gave for Infosys, the Indian multinational IT consulting firm. Steve addresses how organisations can adopt AI securely, considers how this new technology could change the way we work, and looks at how businesses can make themselves resilient in the face of emerging threats.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
ISF CEO Steve Durbin and producer Tavia Gilbert discuss Artificial Intelligence and the Board — what they need to know, updates on evolving regulations in the EU and the US, and how security professionals can best communicate with organisational leadership on this topic.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve speaks with Dragos Tudorache, one of the members of the European Parliament who is responsible for writing the EU’s AI Act. Dragos explains the thought process that went into developing the new law and tells Steve what organisations can expect and how they can prepare for its implementation.
Mentioned in and related to this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve speaks with Clinton Mixon, Information Security Lead at The New School, and Adjunct Assistant Professor at the Center for Global Affairs at New York University. Clinton has been a leader in cyber for more than 30 years. He was one of the founders of the Air Force Cyber College, where members of the US Air Force train in cybersecurity, and he also has been responsible for running training exercises for the New York City government. Clinton and Steve talk about his work to make New York the most cyber-resilient city in the world and tips on how to include and communicate with all departments and employees on what to do in case of a crash or breach.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In today’s episode, recorded at ISF’s 2023 Congress in Rotterdam, Steve speaks with Helle Thorning-Schmidt. From 2011-2015, Helle served as Prime Minister of Denmark, the first woman ever to hold that office. Since 2020, she has served as co-chair of an independent oversight board for Meta to help its social media sites, Facebook and Instagram, answer some of their most difficult questions around freedom of expression online. Helle and Steve dive into questions of leadership, balancing regulation and freedom in online spaces, and how creating a diverse workplace culture could actually play a role in solving bigger global problems.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Steve and Tavia discuss NIS2 compliance, and what this new piece of legislation in the EU will mean for organisations doing business in Europe.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is in conversation with Dr. Christopher Ankersen. Christopher is a Clinical Professor of Global Affairs at New York University, where he leads the Global Risk Specialization program at the Center for Global Affairs. He and Steve discuss the current global threat landscape, how to plan and run effective tabletop exercises, and why it’s crucial for global security professionals to be aware of each location’s role in their business.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
This is the final episode in our series marking Cyber Awareness Month. ISF Regional Director for Europe, the Middle East and Africa Dan Norman speaks with Steve about how organisations can ensure that security is a concern for everyone, from the top down. They discuss questions of education, technology, and best practices for a post-Covid workforce.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today’s episode is the second in our series for Cyber Awareness Month. Steve is joined in the studio by ISF’s Regional Director for Europe, the Middle East and Africa, Dan Norman. Their focus today is on how organisations can overcome challenges to the security workforce.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
October is Cyber Awareness Month, and we’re marking the occasion with a series of three episodes featuring Steve in conversation with ISF’s Regional Director for Europe, the Middle East and Africa, Dan Norman. Today, Steve and Dan discuss the importance of cyber resilience and how organisations can prepare for cyber attacks.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
This is the second in a two-part conversation with Dr. Andrea Matwyshyn, professor of law at Penn State University. If you missed the first part, you can scroll back and find it in our podcast feed. Andrea’s work centers around the intersection of technology design, innovation policy, and law. Today, she and Steve talk about regulating emerging technologies and the questions tech innovators need to start asking as we move into a new era of cyber. Andrea gives us a helpful look back into history for precedents in how to approach what can feel like unprecedented times.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today in the first in a two-part series with Dr. Andrea Matwyshyn, professor of law at Penn State University. Andrea’s work centers around the intersection of technology design, innovation policy, and law. She and Steve discuss tech policy, regulation and international cooperation, and what corporate boards can do differently to succeed in a world where tech is now integral to every business.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
During the past month, you’ve heard encore presentations of some of our favorite episodes so far this year, and today, as we prepare to move forward into Season 22, we’re looking back on some of the highlights of our guest interviews from 2023.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
For our special Summer Listening series, we revisit some favorite listens: episodes that cover some of the most important, and current, issues in cyber. We conclude our Summer Listening series with a conversation from November 2022 between Steve and Deborah Wheeler, CISO at Delta Airlines, based in Atlanta, Georgia.
Deborah talks about her journey through the cybersecurity industry, and offers her perspective on how the industry can be more open to women. She and Steve also discuss the difference between compliance and security and touch on how Covid has changed Delta’s approach to hiring and personnel management.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
For our special Summer Listening series, we revisit some favorite listens: episodes that cover some of the most important, and current, issues in cyber. We continue with a conversation between journalist and long-time friend of ISF, Nick Witchell, and ISF Chief Executive Steve Durbin from October 2022.
Nick puts Steve in the 'cyber hot-seat' to face fifteen minutes of timely rapid-fire questions. Steve offers his opinion on the lessons we can learn from the ongoing Ukraine conflict, the likely ripple effects from the recent conviction of Uber's security chief, and how this will impact the future role of CISOs and their businesses.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
For our special Summer Listening series, we revisit some favorite listens: episodes that cover some of the most important, and current, issues in cyber. We'll begin with our conversation with Seán Doyle from September 2022.
ISF CEO Steve Durbin speaks with Seán Doyle, Lead for the Centre for Cybersecurity at the World Economic Forum. They discuss the role of public-private partnerships in the current cyber landscape, the importance of running tabletop exercises to promote resilience, and improving cybersecurity legislation and regulation around the world to promote economic interests.
Mentioned in this episode: * Cybersecurity Technology Efficacy: Iscybersecuritythe new 'marketforlemons'? Research Report by Joe Hubback * ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This week, Steve and Tavia have a conversation about the constantly changing world of risk, what security can do to prepare for and mitigate risk, the role of the business leader, and the impact of risk management on strategy and business direction. So just another nice casual conversation about the ever increasing intensity of the threat landscape, exactly as our podcast audience has come to expect.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve is in conversation with Dr. Keri Pearlson, Executive Director of Cybersecurity at the MIT Sloan Research Consortium. Keri tells Steve about her research, which focuses on building a culture of cybersecurity and the role leadership plays in that process, and throughout the discussion, she shares lots of practical tips and examples from case studies.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve sits down with Despina Spanou, Head of the Cabinet of the Vice President of the European Commission. Despina’s work on security consists in coordinating all areas under the heading of the EU Security Union, ranging from counter-terrorism, organised crime, and cyber-security, to hybrid threats. She and Steve discuss the initiatives within the EU to create a more secure online ecosystem, the future of cybersecurity regulations in the EU, and growing a talent pipeline on the continent.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This episode is the final installment in a four-part series looking at the ISF's report, Threat Horizon 2025: Scenarios for an Uncertain Future. Today, we’re exploring the third and final known unknown outlined in the report, The Future of International Relations: Ideologies Clash in the Hyperconnected World.
More resources from ISF related to this episode:
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This episode is the third in a four-part series looking at the ISF's latest report, Threat Horizon 2025: Scenarios for an Uncertain Future. Today, we’re exploring the second known unknown outlined in the report, “The Future of Data: Regulation plays catch-up with value.”
More resources from ISF related to this episode:
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This episode is the second in a special four-part series focusing on the ISF's latest report, Threat Horizon 2025: Scenarios for an Uncertain Future. Today, we’re diving into the first of three of the known unknowns outlined in the report, “The Future of Work: Location and technology collide.”
More resources from ISF related to this episode:
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This episode begins a special four episode series focusing on the ISF's latest report, Threat Horizon 2025: Scenarios for an Uncertain Future.
Today, ISF CEO Steve Durbin and ISF Podcast producer Tavia Gilbert offer an overview, setting the stage for this Threat Report. Then over the next several weeks, we'll have a deeper discussion about each of the three major threat areas featured in the report.
More resources from ISF related to this episode:
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, ISF CEO Steve Durbin and Tavia Gilbert look back on the interviews he’s done in the last three weeks with Sean Campbell, Ganesh Krishnan, and Dr. Ellie Pavlick, and discuss what they've learned from those conversations.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve speaks with Dr. Ellie Pavlick, a professor of computer science at Brown University. Dr. Pavlick’s research focuses on computational models of semantics and pragmatics which emulate human inferences in artificial intelligence. Steve and Ellie discuss generative AI, developing a pipeline of talent to work with it, and perspectives on its developing uses for organisations.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
Today Steve speaks with Ganesh Krishnan, a cybersecurity expert with over 25 years of experience protecting the digital world from cyber threats. He's been in leadership at Yahoo, LinkedIn, and other companies, and these days, he's the co-founder and CEO for Anzenna, which aims to empower employees with simple and effective security tools. Steve and Ganesh cover a lot of ground today, from using AI, to cloud security, to moving your organisation’s workforce from security training to engagement.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
This week, Steve is interviewing Sean Campbell, founder and CEO of Cascade Insights. Over the past fifteen years of growing this B2B research firm, Sean has always worked remotely. Today, he shares a lot of practical tips for managers of remote and hybrid workforces, including listening for the silences and preventing 30-minute meetings from taking over your employees’ time.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is in conversation with Jim Routh, the former CISO of MassMutual and Aetna. Jim currently works as a consultant and serves as a member of multiple boards. This week, he and Steve talk about the varied skill-sets required of cutting edge CISO’s, managing expectations of the C-Suite, the nuance between consensus and agreement, and more.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, we’re featuring the second of a two-part conversation between Steve and Dr. Christopher Hand. You’ll remember from last week that Chris is a senior lecturer in psychology at the University of Glasgow in Scotland. This week, he talks with Steve about what companies are learning about productivity post-Covid and responding to cyber abuse in the workplace.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This episode is the first part of a two-part conversation between Steve and Dr. Christopher Hand. Chris is a senior lecturer in psychology at the University of Glasgow in Scotland. He and Steve talk about trust and authenticity online, cyber-bullying in the context of work, and what we know so far about the decision to return to the office post-pandemic.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF Steve sits down for an interview with BBC journalist Kirsty Lang to talk about current threats, nation-state cybercrime, and the role of government and Big Tech in enhancing security for all.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this second installment of our two-part interview with author and former Chief Business Officer of Google X Mo Gawdat, Mo and Steve talk about balancing a culture of innovation with a culture of security, and new ways to think about risk within the current threat landscape.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today is the first of a two-part interview in which ISF CEO Steve Durbin is speaking with author and former Chief Business Officer of Google X Mo Gawdat. Mo and Steve discuss the complicated relationship humans have with technology, particularly AI, and how both individuals and businesses can navigate that wisely.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today’s episode offers a fascinating conversation with Steve and journalist Jamie Bartlett, a specialist in online culture and technology and author of several books, including The People Vs Tech: How the Internet is Killing Democracy and Radicals Chasing Utopia: Inside the Rogue Movements Trying to Change the World. Listeners may also be familiar with his BBC podcast series, The Missing Cryptoqueen, which uncovers the story of Dr Ruja Ignatova, the woman who promised to make millions rich through a cryptocurrency called OneCoin, and then disappeared. Steve and Jamie discuss current trends in cyber crime and what government, private companies, and individuals can do to fight back.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Explore how CISOs can educate the board, build resilience, and invest effectively in security, with Steve Dubin, ISF CEO, and Margaret Heffernan, a Professor of Practice at the University of Bath School of Management.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve is in conversation with author and strategist Rahaf Harfoush about balancing productivity and creativity. The two have a very practical discussion about how to give yourself and your team the time and space to focus, to think creatively, and to collaborate effectively.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
ISF CEO Steve Durbin sits down with strategic supply chain risk expert Omera Khan. They talk about the current risk landscape vis a vis supply chain, protecting your supply chain by building collaborative systems, and incentivizing your staff appropriately to ensure they vet suppliers with a security-first mindset.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This week, we’ve put together a preview of the upcoming episodes in this season of the ISF Podcast. We are excited to bring you really thoughtful and compelling interviews with luminaries in their fields. Featuring excerpts from Steve’s interviews with Omera Khan, Rahaf Harfoush, Margaret Heffernan, and Mo Gawdat.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today BBC journalist Nick Witchell interviews ISF CEO Steve Durbin. They discuss AI and its impact on security, as well as data integrity and trust in an age of disinformation.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This week, we’re featuring a presentation ISF CEO Steve Durbin made on December 7, 2022, on the Emerging Threats we expect to see in 2023.
Mentioned in this episode:* Protecting the Crown Jewels
* Steve Durbin: steve.durbin@securityforum.org
Phone: +44 (0) 7785 953800
Twitter: @stevedurbin
LinkedIn: https://www.linkedin.com/in/stevedurbin/
* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In today’s episode, which was recorded together in the studio — a rare and happy occurrence when we’re able to be together in person — ISF CEO Steve Durbin and producer Tavia Gilbert discuss the future of the security leader, including the characteristics of security leaders today compared to those likely to be required in the future, as well as the future operating model of the security function.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve speaks with Tim Carmichael, Chief Data Officer of the Chalhoub Group, a luxury retailer based in Dubai, and former Chief Data Officer of the British Army. Tim and Steve talk about what can happen when leaders empower their people to act and consider how CDOs, like CISOs, can serve as interpreters for members of the Board. They also explore strategies for hiring and keeping the best talent in a competitive market.
Mentioned in this episode:* ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, ISF CEO Steve Durbin is in conversation with Raffael Marty, Executive Vice President and General Manager of Cybersecurity Management at ConnectWise. Raffael is also the author of Applied Security Visualization and the Security Data Lake. He and Steve discuss how to prevent data from being compromised, what government and private enterprise can learn from each other vis a vis cybersecurity, the pros and cons of cyberinsurance, and more.
Related ISF Resources: * Protecting the Crown Jewels: How To Secure Mission-Critical Assets
Mentioned in this episode: * ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In today’s episode, Steve is in conversation with Deborah Wheeler, CISO at Delta Airlines, based in Atlanta, Georgia. Deborah talks about her journey through the cybersecurity industry, and offers her perspective on how the industry can be more open to women. She and Steve also discuss the difference between compliance and security and touch on how Covid has changed Delta’s approach to hiring and personnel management.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve sits down with Manchester Mayor Andy Burnham. They discuss the nuts and bolts of leading a city into the Digital Age, strategies for building consensus, and, of course, what ISF Congress participants can look forward to when they arrive in Manchester this November.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve sits down with Manchester Mayor Andy Burnham. They discuss the nuts and bolts of leading a city into the Digital Age, strategies for building consensus, and, of course, what ISF Congress participants can look forward to when they arrive in Manchester this November.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In today's episode, ISF CEO Steve Durbin talks to producer Tavia Gilbert about identifying and managing risk — not just from the perspective of the cybersecurity leader, but the business leader, who has to look deeply at the economic context of risk.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In today's episode, ISF CEO Steve Durbin talks to producer Tavia Gilbert about identifying and managing risk — not just from the perspective of the cybersecurity leader, but the business leader, who has to look deeply at the economic context of risk.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In today’s episode, journalist and long-time friend of ISF, Nick Witchell, puts Steve Durbin, ISF Chief Executive, in the 'cyber hot-seat' to face fifteen minutes of timely rapid-fire questions.
Steve offers his opinion on the lessons we can learn from the ongoing Ukraine conflict, the likely ripple effects from the recent conviction of Uber's security chief, and how this will impact the future role of CISOs and their businesses.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
In today’s episode, journalist and long-time friend of ISF, Nick Witchell, puts Steve Durbin, ISF Chief Executive, in the 'cyber hot-seat' to face fifteen minutes of timely rapid-fire questions.
Steve offers his opinion on the lessons we can learn from the ongoing Ukraine conflict, the likely ripple effects from the recent conviction of Uber's security chief, and how this will impact the future role of CISOs and their businesses.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
In today’s episode, ISF CEO Steve Durbin is in conversation with Aaron Painter. Aaron is the founder and CEO of Nametag, a company whose mission is to enable people to build more trusted relationships by preventing identity fraud. In 2017, Aaron wrote a best-selling book titled Loyal, based on his experience living and working in six countries across four continents. In Loyal, he describes his key to leadership: fostering a culture of listening. Today, he and Steve discuss how he came to write Loyal, and how his advice for workplace leaders has evolved since starting a company in the midst of the pandemic.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, ISF CEO Steve Durbin and producer Tavia Gilbert discuss how organizations can take advantage of Cybersecurity Awareness Month to educate their employees on cyber hygiene and security awareness, rehearse what to do in case of a breach, and take advantage of the free cybersecurity resources available to them.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin speaks with Seán Doyle, Lead for the Centre for Cybersecurity at the World Economic Forum. They discuss the role of public-private partnerships in the current cyber landscape, the importance of running tabletop exercises to promote resilience, and improving cybersecurity legislation and regulation around the world to promote economic interests.
Mentioned in this episode: * Cybersecurity Technology Efficacy: Iscybersecuritythe new 'marketforlemons'? Research Report by Joe Hubback * ISF Analyst Insight Podcast
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Over the past few weeks, you’ve heard encore presentations of some of our favorite episodes so far this year, and today, as we prepare to move forward into Season 14, we’re looking back on some of the highlights of our guest interviews from 2022.
Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, we’re featuring a conversation Steve had with Stephen Poloz, a world renowned economist who served as Governor of the Bank of Canada from 2013-2020. Steve and Stephen discuss some of the themes Poloz addresses in his recently released book, The Next Age of Uncertainty: How the World Can Adapt to a Riskier Future. They discuss communicating in the midst of crisis, how the fourth industrial revolution compares to past historical moments of change, and risk management and resilience amidst global turmoil.
Mentioned in this episode:
The Next Age of Uncertainty: How the World Can Adapt to a Riskier Future
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Summer Listening - Today, ISF CEO Steve Durbin is in conversation with Brett Beranek, Vice President and General Manager of security and biometrics at Nuance Communications. Steve and Brett discuss some of the potential and the challenges of biometrics in the security space, including recent advancements in deep neural networks and deep fakes.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Summer Listening - Today,Steve is speaking with Prof. Federico Varese, a professor of criminology and head of the sociology department at Nuffield College at Oxford University. Prof. Varese talks with Steve about the history of organised crime in Russia and around the world, the mafia’s movement into cybercrime, and what the future may hold for these criminal organisations.
Related Resources from ISF:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Summer Listening - Today, we’re featuring highlights of a recent “fireside chat” hosted by global tech services and consulting firm Infosys, and featuring our own ISF CEO Steve Durbin. Steve’s interviewer is his long-time colleague and friend Vishal Salvi, who serves as Chief Information Security Officer and Head of Cyber Security Practice at Infosys.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today we’re back for the second episode of a two-part conversation around ISF CEO Steve Durbin’s NovelFest presentation on “The AI Revolution: Democratisation and the Ethical Dilemma of Innovation.” If you haven’t listened to Part 1, you may want to go back to that episode and listen to it first. Last week gave us a pretty positive overview of what responsible AI could do to eliminate or to mitigate discrimination. But we know that AI is value-neutral, so the opposite of responsible AI could also become a reality. How can AI be used to facilitate digital discrimination? Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today episode is the first of two parts in which ISF CEO Steve Durbin and host Tavia Gilbert discuss a presentation he gave for the Nobel Fest in April 2022, titled, “The AI Revolution: Democratisation and the Ethical Dilemma of Innovation.” Mentioned in this episode:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, we’re featuring an interview of ISF CEO Steve Durbin by Göran Walles, CTO at NetNordic Sweden, recorded back in May 2022. Göran has more than 20 years of experience in cybersecurity, and has been CTO at NetNordic Sweden since 2018. Steve and Göran recorded this conversation in May 2022, and they discuss the double-edged sword of AI and machine learning, how it can best be implemented to defend organisations’ security, and the need-to-know basics for CISOs and cyber professionals. Relevant ISF Resources:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, we feature a presentation made by ISF CEO Steve Durbin on The CISO, Cyber, and the Board at the ISF’s Nordic Spring Conference in May 2022. This was a chapter meeting held for ISF members in the Nordic region; ISF holds meetings three times a year to give members in the same geographic region a confidential forum where they can network and exchange ideas.
In his presentation, Steve addresses five areas where CISO's need to focus in 2022. For our listeners who are CISOs or in a position where you regularly communicate with your board, you’ll find some practical ideas to help you do that. For those of you who are closer to the beginning of your career in cyber, Steve offers some insights about the nature of the relationship between cybersecurity and the overall business that you’ll find helpful as you look to develop skills relevant to the needs of your business. Mentioned in this episode: * List of various cyberattacks * Alliance graphs * IRAM 2—Qualitative Information Risk Assessment Methodology * QIRA —Quantitative Information Risk Assessment Methodology * ISF Supply chain risk management tools
To contact Steve Durbin directly: US Tel: +1 (347) 767 6772 UK Tel: +44 (0)20 3289 5884 UK Mobile: +44 (0)7785 953800 steve.durbin@securityforum.org
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin sits down with trust expert, author, and lecturer at Oxford University, Rachel Botsman. They discuss the nature of trust, how trust differs from transparency, and how to build a culture of trust within your organisation.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today is the fourth and final episode in our four-part series focusing on the ISF’s latest report, Threat Horizon 2024: The Disintegration of Trust. ISF CEO Steve Durbin and producer Tavia Gilbert discuss the final theme of the report, “Dirty data disrupts business.”
More resources from ISF related to this episode:
Read the transcript of this episode.
Subscribe to the ISF Podcast wherever you listen to podcasts.
Connect with us on LinkedIn and Twitter.
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today is the third episode in our four-part series focusing on the ISF’s latest report, Threat Horizon 2024: The Disintegration of Trust. ISF CEO Steve Durbin and producer Tavia Gilbert go deeper into the second major theme of the report, “Technology choices limit control.”
More resources from ISF related to this episode:
Read the transcript of this episode.
Subscribe to the ISF Podcast wherever you listen to podcasts.
Connect with us on LinkedIn and Twitter.
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, we have the second in a four-episode series focusing on the ISF’s latest report, Threat Horizon 2024: The Disintegration of Trust. ISF CEO Steve Durbin and producer Tavia Gilbert delve into the first major theme of the report, “Well-intentioned regulations have unintended consequences.”
More resources from ISF related to this episode:
Read the transcript of this episode.
Subscribe to the ISF Podcast wherever you listen to podcasts.
Connect with us on LinkedIn and Twitter.
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This episode begins a special four episode series focusing on the ISF's latest report, Threat Horizon 2024: The Disintegration of Trust. Today, we offer an overview, setting the stage for this Threat Report. ISF CEO Steve Durbin and producer Tavia Gilbert discuss the report’s application of the PESTLE model, forecasting the impact on the political, economic, social, technological, legal, and environmental.
More resources from ISF related to this episode:
Read the transcript of this episode.
Subscribe to the ISF Podcast wherever you listen to podcasts.
Connect with us on LinkedIn and Twitter.
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, ISF CEO Steve Durbin and host Tavia Gilbert discuss highlights from the interviews featured over the last several weeks. They consider some of Steve’s takeaways and actionable insights for security professionals from Season 11.
Mentioned in this episode:
More resources from ISF related to this episode:
Read the transcript of this episode.
Subscribe to the ISF Podcast wherever you listen to podcasts.
Connect with us on LinkedIn and Twitter.
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin is in conversation with Adam Rumanek, the founder and CEO of Aux Mode, a company that specializes in digital rights management, content strategy, and IP protection. Adam and Steve discuss the challenges of protecting content and intellectual property, how organisations can manage their risk in that area, and what to do if your content is compromised.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin is in conversation with Brett Beranek, Vice President and General Manager of security and biometrics at Nuance Communications. Steve and Brett discuss some of the potential and the challenges of biometrics in the security space, including recent advancements in deep neural networks and deep fakes.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, Steve speaks with Carl Allen, a private equity investor and co-founder of the Dealmaker Wealth Society. They discuss security across the mergers and acquisitions process, particularly for small and mid-size businesses. More ISF resources on this topic: * Information Security in Mergers and Acquisitions * Video Presentation: The Role of Information Security in Mergers and Acquisitions * Consultancy Service: Cyber Risk for Mergers and Acquisitions
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin is in conversation with Mark Ralls, President and COO of Invicti Security, a Texas-based company that provides dynamic web application security solutions. You’ll hear Mark mention what he calls the FUD approach to security — starting from fear, uncertainty and doubt. Steve and Mark talk about the cost this approach can ultimately have in relation to people, process, technology, and outsourcing. They also discuss the current threat landscape, security by design, and developing the next generation of cybersecurity talent.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today,ISF CEO Steve Durbin and producer Tavia Gilbert discuss highlights from the conversations we’ve featured on the podcast over the last several weeks. We review our season and consider takeaways, in terms of business leadership and actionable insights for our members, particularly during these times of instability.
Related Resources from ISF: * “Are 5G Networks Setting The Stage For A New Wave Of Cyberattacks?” — Forbes, 10 August 2021 * Threat Horizon 2022: Digital and Physical Worlds Collide * The New World Order (ISF Podcast, 19 January 2022) * The Race for Tech Dominance (ISF Podcast, 25 January 2022) * ISF Ransomware Support: Prepare, Respond, Resume * Review and Gap Analysis of Cybersecurity Legislation and Cybercriminality Policies in Eight Countries
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today,Steve is speaking with Prof. Federico Varese, a professor of criminology and head of the sociology department at Nuffield College at Oxford University. Prof. Varese talks with Steve about the history of organised crime in Russia and around the world, the mafia’s movement into cybercrime, and what the future may hold for these criminal organisations.
Related Resources from ISF:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, Steve sits down with Alexander Seger, head of the Cybercrime Division at the Council of Europe. They discuss ways to promote cooperation between private businesses and law enforcement agencies, the challenges of investigating and prosecuting cybercrimes across multiple jurisdictions, and recent developments with the Budapest Convention on Cybercrime that could mitigate those challenges.
Related Resources from ISF: * Mitigating Ransomware Attacks * Review and Gap Analysis of Cybersecurity Legislation and Cybercriminality Policies in Eight Countries
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, we’re featuring a conversation Steve had just last week with Stephen Poloz, a world renowned economist who served as Governor of the Bank of Canada from 2013-2020. Steve and Stephen discuss some of the themes Poloz addresses in his recently released book, The Next Age of Uncertainty: How the World Can Adapt to a Riskier Future. They discuss communicating in the midst of crisis, how the fourth industrial revolution compares to past historical moments of change, and risk management and resilience amidst global turmoil.
Mentioned in this episode:
The Next Age of Uncertainty: How the World Can Adapt to a Riskier Future
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin speaks with Marc Gibson, owner and CEO of DThree Technologies, a company that specializes in helping small-medium enterprises blend their people, processes, and technology. They talk about the unique security challenges small businesses face, how to build a culture of security in a small business environment, and career possibilities for security professionals within SMEs.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin and host Tavia Gilbert are talking all things 5G — what it is, what changes it will effect, and how we can keep our operations and supply chains secure as it rolls out.
Related ISF Resources:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Our guest today is David Thornewill, Group CISO for transportation and logistics giant DHL. Steve sat down in the ISF headquarters in London to speak with David at his home in Germany. They discuss the ever-changing role of the CISO, the challenges and practical strategies of building a culture of security in a multinational corporation with more than half a million employees, and preparing for future threats.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, we’re featuring highlights of a recent “fireside chat” hosted by global tech services and consulting firm Infosys, and featuring our own ISF CEO Steve Durbin. Steve’s interviewer is his long-time colleague and friend Vishal Salvi, who serves as Chief Information Security Officer and Head of Cyber Security Practice at Infosys.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, originally released in April 2021, we’re bringing you a conversation between ISF CEO Steve Durbin and ISF analyst Dan Norman from the 2020 ISF Congress. Steve and Dan discuss the overall direction of the security profession in the current climate and how to build a team and a culture to promote secure practices throughout your organization.
Mentioned in this episode:
Addressing Psychological Vulnerabilities
Positively Influencing Security Behavior
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin and host Tavia Gilbert discuss research he’s been conducting during the fall of 2021 around The New World Order and the Race for Tech Dominance. This is the second of two episodes focusing on this theme.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin and host Tavia Gilbert discuss research he’s been conducting during the fall of 2021 around The New World Order and the Race for Tech Dominance. This is the first of two episodes focusing on this theme.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Happy New Year to all of our listeners! It’s hard to believe we’ve been doing this podcast for five years now. Our audience keeps growing, and we’re excited to bring you more insightful guests in 2022 — the best is yet to come.
But today, we’re taking a look back. This episode features clips from some of our favorite episodes from 2021. The full episodes are linked below, in case you missed one or want to revisit the full conversations.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Last week, we featured a presentation ISF CEO Steve Durbin made on December 8, 2021, on the Emerging Threats we expect to see in 2022. This week, we’ll hear the presentation’s Q&A session, in which Steve responds to the audience questions.
Mentioned in this episode:
Phone: +44 (0) 7785 953800
Twitter: @stevedurbin
LinkedIn: https://www.linkedin.com/in/stevedurbin/
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
This week, we’re featuring a presentation ISF CEO Steve Durbin made on December 8, 2021, on the Emerging Threats we expect to see in 2022. Steve sets some context for his thinking around the threats for 2022, goes through four of what he believes will be the threats to watch out for in 2022, and then outlines some of the mitigations that organizations can adopt to protect themselves from these threats. * Demystifying Zero Trust * Protecting the Crown Jewels * Steve Durbin: steve.durbin@securityforum.org
Phone: +44 (0) 7785 953800
Twitter: @stevedurbin
LinkedIn: https://www.linkedin.com/in/stevedurbin/
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Viviane Reding, former First Vice-President of the European Commission, sits down with ISF Chief Executive, Steve Durbin to discuss the ramifications of GDPR, cybercrime, and what kind of governance in cyberspace is possible going forward.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin sits down with trust expert, author, and lecturer at Oxford University, Rachel Botsman. They discuss the nature of trust, how trust differs from transparency, and how to build a culture of trust within your organisation.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
ISF CEO Steve Durbin speaks with computer programmer, philanthropist, and co-founder of Apple, Steve Wozniak. Woz reminisces about the past and looks into the future of Big Tech, and considers what both could mean for the future of security.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin is in conversation with Max McKeown, a writer, consultant, and researcher specialising in innovation strategy, leadership and culture. He and Steve talk about effective communication, resilience, and how to lead with long-term vision when you feel overwhelmed by day-to-day tasks.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, ISF CEO Steve Durbin speaks with Dr. Sadie Creese, a professor of Cybersecurity at Oxford University. Dr. Creese is the founding Director of the Global Cyber Security Capacity Centre (GCSCC) at the Oxford Martin School and a member of the World Economic Forum’s Cyber Security Centre’s Strategic Advisory Board. She and Steve discuss the current threat landscape, deep machine learning, and educating business leaders in the basics of cybersecurity.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin is in conversation with Dr. Brian Cox, professor of Particle Physics at the University of Manchester. Dr. Cox worked on the ATLAS experiment at the Large Hadron Collider at CERN in Switzerland and has co-written several books on physics, including Why does E=mc2? and The Quantum Universe. He’s also known for appearances in many science programmes for BBC radio and television, including In Einstein's Shadow and the BBC Horizon series. Dr. Cox and Steve discuss how to translate a complex message to a lay audience, the need for intellectual honesty, and the value of play even in serious endeavors.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin and host Tavia Gilbert give a preview of the upcoming season of the ISF Podcast, which features conversations with ISF’s Digital Congress 2021 keynote speakers.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, originally released in December 2020, Steve welcomes motivational speaker, corporate consultant, and educator Reggie Butler back to the podcast. Reggie last connected with Steve in 2018 for an episode of our videocast (link below). Today’s conversation focuses on what we’ve learned through the experience of working from home during the pandemic, strategies for uniting teams even while socially distanced, and why leaders should model vulnerability and transparency now more than ever.
Learn more about Reggie Butler. Mentioned in this episode: 2018 ISF Videocast with Reggie Butler: Finding your ‘rhythm’ in business
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, ISF CEO Steve Durbin and podcast host Tavia Gilbert dive deeper into this season’s theme of Digital Transformation. We've had a handful of guests, including Jonathan Moore, Bob Phibbs, and Mel Shakir, and today Steve shares his own perspective about this current moment of Digital Transformation.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, ISF CEO Steve Durbin speaks with Mel Shakir, Managing Director of DreamIt Ventures, about his work helping cybersecurity startups reach their full potential. They discuss how helping cybersecurity startups can reach their full potential and how CISOs can keep up with changing cybersecurity software in this time of digital transformation, as well as tips for cybersecurity software vendors who might approach CISOs already feeling inundated by pitches.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin is in conversation with Bob Phibbs, “The Retail Doctor.” Bob is recognized as a leading expert on brick-and-mortar retailers, and he has consulted for, among others, Caesar’s Palace, Lego, Omega, Vera Bradley, and Yamaha. Bob shares his perspective on digital transformation in the retail market, building a solid team, and effective communication within an organisation.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, ISF CEO Steve Durbin sits down with Jonathan Moore, CTO of SpiderOak, a data security software design firm in Silicon Valley. Steve and Jonathan discuss digital transformation, creating zero trust models that work, and the future of information security and Big Tech.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, originally released in November, 2020, Steve is in conversation with philosopher, author, and speaker Anders Indset. Steve and Anders discuss the importance of leaders engaging in what he calls a “self audit,” having the strength and courage to get vulnerable, the importance of listening, and more.
Mentioned in this episode:
Read the transcript of this episode
Subscribe tothe ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security and risk management
In this episode, ISF CEO Steve Durbin speaks with Josh Jackson, Global Head of Government and Public Services for 6clicks and the Executive Director of the AI Association. As the AI Association’s leader, Jackson advocates and educates government agencies, including the U.S. Congress, about artificial intelligence. Steve and Josh discuss the future of AI, how the workforce can survive the coming robot takeover, the role of government in regulating AI and cyber, and more.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin speaks with Jonathan Brill, futurist and author of the new book, Rogue Waves: Future-Proof Your Business to Survive and Profit from Radical Change. They discuss ways organizations can prepare for the confluence of small events that can add up to major disruption, developing institutional resilience, and how to strategies to facilitate sound decision-making in the boardroom.
Mentioned in this episode:Rogue Waves: Future-Proof Your Business to Survive and Profit from Radical Change
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Our season six theme is disruption, and today ISF CEO Steve Durbin and ISF Podcast host Tavia Gilbert discuss a paper on global cyber crisis. This is a paper that the ISF wrote for the Astana Club, to which Steve is a regular contributor. Last week, we talked about how most governments seem to be struggling with how to rein in big tech companies in order to protect their citizens’ privacy. Today, we focus more on cyber attacks by both state-backed and independent actors.
Mentioned in this episode:
The Astana Club
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Our theme this season is disruption, and today, ISF CEO Steve Durbin and podcast host Tavia Gilbert discuss digital totalitarianism, a topic based on the ISF's reporting for the Astana Club, an international discussion platform that gathers prominent political figures, diplomats, and experts from the world's top analytical centers. Today’s conversation focuses on how most governments are struggling with how to rein in big tech companies in order to protect their citizens’ privacy.
Mentioned in this episode:
The Astana Club
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today is the start of a new season focusing on global disruption. It will feature a mix of conversations between Steve Durbin, CEO of the ISF, our host Tavia Gilbert, and expert guests.
This episode provides a summary of the themes that will be explored in this series, namely: * Steve Durbin’s contribution to the Astana Club Top 10 Risks for Eurasia 2021 focused on Digital Totalitarianism and the Global Cyber Crisis as the world experiences a global cyber disruption. * Jonathan Brill – Future-proof your business to survive and profit from radical change. * Josh Jackson – The positive benefits of AI.
Mentioned in this episode:
The Astana Club
Jonathan Brill
Josh Jackson
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
https://bit.ly/3dMNgcH
In this episode, originally released on January 26, 2021, ISF CEO Steve Durbin talks with Dame Inga Beale, the former CEO of Lloyd’s of London, about the role that listening played when she became the first (and only) female CEO in Lloyd’s more than 300-year history. They also discuss the courage and effectiveness of simplicity in communication, a new style of leadership built on trust, and career advice for both board members and security professionals who are relatively new to the industry.
More about Dame Inga Beale and Lloyd’s of London.
Mentioned in this episode:
Dive In Festival
Read the transcript of this episode.
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
https://bit.ly/3w4PjPz
ISF CEO Steve Durbin and Tavia Gilbert close out the Authors Roundtable season, discussing what they’ve learned from interviews over the past four episodes with Thomas Eisenmann, Michele Wucker, Michelle Seiler Tucker, and Matt Blumberg. They review what they learned from each of those conversations and link those conversations directly to the concerns of and opportunities for cybersecurity listeners.
Mentioned in this episode:Professor Thomas Eisenmann’s Why Startups Fail: A New Roadmap for Entrepreneurial Success (US and Canada) and The Failsafe Startup (outside the US and Canada)
Michele Wucker’s The Gray Rhino: How To Recognize and Act on the Obvious Dangers We Ignore and You Are What You Risk: The New Art and Science of Navigating an Uncertain World
Michelle Seiler Tucker’s Exit Rich: The 6P Method to Sell Your Business for a Huge Profit
Matt Blumberg’s Startup CEO and Startup CXO: Startup CXO: A Field Guide to Scaling Up Your Company's Critical Functions and Teams
IRAM2—Information Risk Assessment Methodology 2
Threat Horizon Report 2021
Threat Horizon Report 2022
Threat Horizon Report 2023
FAIR
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
https://bit.ly/3ycpEGv
In today’s episode, ISF CEO Steve Durbin speaks with Matt Blumberg, a technology entrepreneur and business builder based in New York City, co-founder and CEO of Bolster, and the author of Startup CEO and the new release, Startup CXO: A Field Guide to Scaling Up Your Company's Critical Functions and Teams. Steve and Matt discuss the ups and downs of starting a business in 2020, inclusion in the boardroom and beyond, and what a functional executive team looks like.
Mentioned in this episode:
Startup CXO: A Field Guide to Scaling Up Your Company's Critical Functions and TeamsStartup CEO
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
https://bit.ly/3vLxFAr
In today’s episode, ISF CEO Steve Durbin is in conversation with Michelle Seiler Tucker, speaker, author, and CEO of Seiler Tucker, a business that specializes in mergers and acquisitions.
Michelle speaks with Steve about her newest book, Exit Rich: The 6P Method to Sell Your Business for a Huge Profit. They discuss tips on selling a business at a profit, the current state of M&A business in the COVID economy, the role of cybersecurity in M&A, and more.
Mentioned in this episode:
Exit Rich: The 6P Method to Sell Your Business for a Huge Profit
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
https://bit.ly/3wCmKKo
In this episode, Steve Durbin speaks with commentator and policy analyst Michele Wucker, author of The Gray Rhino: How To Recognize and Act on the Obvious Dangers We Ignore and You Are What You Risk: The New Art and Science of Navigating an Uncertain World. Steve and Michele discuss individual and collective risk appetite, the concept of a risk ecosystem, and how to build a culture and team that can balance your organization’s risk appropriately.
Mentioned in this episode:
The Gray Rhino: How To Recognize and Act on the Obvious Dangers We Ignore
You Are What You Risk: The New Art and Science of Navigating an Uncertain World
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
https://bit.ly/3cmUjZa
Today, ISF CEO Steve Durbin is speaking with Harvard Business School Professor Thomas Eisnemann about his new book, Why Startups Fail: A New Roadmap for Entrepreneurial Success. Steve and Prof. Eisenmann look at examples of a few of the case studies included in his book that illustrate why some startups succeed, but most fail. Whether you’re an entrepreneur or not, everyone in business can learn from these failures.
Mentioned in this episode:
Why Startups Fail: A New Roadmap for Entrepreneurial Success (US and Canada)
The Failsafe Startup (outside the US and Canada)
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
https://bit.ly/3wMrLzX
In this episode, originally released in November 2020, Steve is in conversation with Dr. Hannah Fry, associate professor in the Mathematics of Cities at the Centre for Advanced Spatial Analysis at University College London, and a researcher in the patterns of human behaviour, particularly in an urban setting. In this conversation, Steve and Hannah discuss the challenge and imperative of communicating across demographics with simplicity and clarity; the power of storytelling; the moral tensions inherent in data mining; and more.
Mentioned in this episode: Hello World Jon Ronson Cambridge Analytica data scandal Drone legislation in the UK ISF Threat Horizon 2021
Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
https://bit.ly/34dFpzR
Today, ISF CEO Steve Durbin speaks with Matthew Doan, Senior Manager at BCG Platinion and Cybersecurity Policy Fellow at New America. Steve and Matthew talk about growing your skills, finding purpose at work, and what the workforce of the future might look like.
Mentioned in this episode:
Learning How to Learn with Barbara Oakley
A Brief Guide to Learning Faster (and Better) by Scott Young
Cal Newport
Simon Sinek
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In today’s episode, ISF CEO Steve Durbin considers cyber in the workplace from the perspective of a digital native and a more experienced security leader. We hear from Mehak Vohra, CEO of SkillBank and member of Gen Z, and the more experienced Rich Guida, Managing Director at Guida Associates, Inc., formerly VP of Information Security at Johnson & Johnson.
Mentioned in this episode:
ISF Podcast Season 3, Episode 1: Threat Horizon 2023: Security at a Tipping Point
The Digital Generation Will Become the Cyber-Criminal’s Dream
Five Threat Vectors Destined To Make Waves In 2021
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin is in conversation with Dr. Margaret Cunningham, principal research scientist at Forcepoint. They discuss leading a team that’s working from home, hiring and onboarding post-COVID, building your team’s communication skills, and more.
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management
Today, ISF CEO Steve Durbin is in conversation with Thomas Erl, best-selling IT author and founder of Arcitura Education, which offers vendor-neutral training and certification programs.
Steve and Thomas discuss how to resolve the skills shortage, the purpose of vendor-neutral training, the coming disruption of digital transformation, and more.
Today, we’re bringing you a conversation between ISF CEO Steve Durbin and ISF analyst Dan Norman from the 2020 ISF Congress. Steve and Dan discuss the overall direction of the security profession in the current climate and how to build a team and a culture to promote secure practices throughout your organization.
Mentioned in this episode:
Addressing Psychological Vulnerabilities
Positively Influencing Security Behavior
In today’s episode, ISF CEO Steve Durbin and producer Tavia Gilbert give an overview of the podcast’s season 4 theme: The Security Workforce of the Future.
Over the next several weeks and with a variety of guests, we’ll focus on what enterprises can do to attract, retain, and train the talent they’ll need to manage the demands of security in coming years.
Today’s episode is the last in a special four-part series in which ISF CEO Steve Durbin and producer Tavia Gilbert discuss the ISF’s latest report, Threat Horizon 2023: Security at a Tipping Point. Today, we discuss the report’s third major threat: Security fails in a brave new world.
Learn more about the ISF Threat Horizon 2023: Security at a Tipping Point.
Today’s episode is the third in a special four-episode series in which ISF CEO Steve Durbin and producer Tavia Gilbert discuss the ISF’s latest report, Threat Horizon 2023: Security at a Tipping Point. Today, we dig deeper into the report’s second threat: Identity is weaponised.
Learn more about the ISF Threat Horizon 2023: Security at a Tipping Point.
Today’s episode is the second in a special four-episode series in which ISF CEO Steve Durbin and producer Tavia Gilbert discuss the ISF’s latest report, Threat Horizon 2023: Security at a Tipping Point. Today, we focus on the report’s first major threat: Machines seize control.
Learn more about the ISF Threat Horizon 2023: Security at a Tipping Point.
Today, we begin a special four-episode series focusing on the ISF's latest report, Threat Horizon 2023: Security at a Tipping Point. This episode sets the stage for this threat report, and over the next few weeks, we'll dig deeper into each of the three major threats featured in the report.
Learn more about the ISF Threat Horizon 2023: Security at a Tipping Point.
In today’s episode, Steve speaks with Dr. Kate Stone,a "creative scientist" whose company, Novalia, blends art and science to create fusions of new and old technology. Dr. Stone talks to Steve about the creative process, the role of analogue in the digital age, the importance of privacy and the consequences when basic rights to privacy are violated, the importance of digital friction in preserving mental health, and more.
Learn more about Dr. Kate Stone and Novalia. Mentioned in this episode: * ISF Podcast - Shoshana Zuboff—The Age of Surveillance Capitalism * Editors' Code of Practice committee * Paul Dacre * Dr. Kate Stone’s Ted Talk: The Press Trampled on My Privacy. Here’s How I Took Back My Story * "The Stag Trampled On My Throat, and the Press Trampled On My Privacy," BBC News, 14 May 2014 * ISF Podcast — Dr. Ann Cavoukian: Privacy By Design, Security By Design
Today, Steve speaks with Harvard professor, social psychologist, philosopher, and scholar Shoshana Zuboff, author of three influential books on tech and society. In this episode, she discusses the themes in her latest book, The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power, the new economic order that claims human experience is free raw material for commercial practices, the expanding attack surface for digital information warfare, and more.
Learn more about Shoshana Zuboff.
Mentioned in this episode: * The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power
From the Information Security Forum, the leading authority on cyber, information security, and risk management
In today’s episode, Steve speaks with actress, voice coach, leadership consultant, and expert in core energetics, or body-led psychotherapy, Kate Montague. Kate discusses the effectiveness in taking time to reset, what happens when you stay connected to your body and your breath, how to take the temperature of the room when the rooms are remote, and more.
Learn more about Kate Montague.
Mentioned in this episode: * Royal Central School of Speech and Drama
In this episode, ISF CEO Steve Durbin talks with Dame Inga Beale, the former CEO of Lloyd’s of London, about the role that listening played when she became the first (and only) female CEO in Lloyd’s more than 300-year history. They also discuss the courage and effectiveness of simplicity in communication, a new style of leadership built on trust, and career advice for both board members and security professionals who are relatively new to the industry.
More about Dame Inga Beale and Lloyd’s of London.
Mentioned in this episode:
Dive In Festival
Read the transcript of this episode.
Today, Steve is in conversation with Tammie Jo Shults, retired Southwest Airlines captain and former naval aviator. Captain Shults received wide acclaim when, on April 17, 2018, she and her crew successfully landed a Boeing 737 after catastrophic engine failure and rapid decompression, saving the lives of 148 people. In today’s conversation, Steve and Captain Shults discuss leadership during a time of crisis, the importance of building trust with your team, how her parents’ example led her as navigated becoming one of the first female F/A-18 Hornet pilots in the United States Navy, and more.
Learn more about Tammie Jo Schults. Mentioned in the episode: * Nerves of Steel: How I Followed My Dreams, Earned My Wings, and Faced My Greatest Challenge
Producer Tavia Gilbert talks to ISF CEO Steve Durbin about the episodes in our second season focusing on Leadership in a Time of Transition. We preview conversations with retired Southwest Airlines captain and former US naval aviator Tammie Jo Shults; global business insurance leader Dame Inga Beale, the former CEO of Lloyd’s of London and the only female CEO in its more than 300-year history; Kate Montague, an actor and expert voice coach with a background in body-led psychotherapy; Shoshana Zuboff, retired Harvard Business School professor and the author of The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power; and innovative physicist Kate Stone, a non-traditional problem solver who has creatively complex challenges, both personal and professional.
Steve will explain what links these diverse five experts, and what they have to offer you and your teams of security professionals.
Mentioned in this episode:
Kate Stone
Read the transcript of this episode.
Producer Tavia Gilbert talks to ISF Managing Director Steve Durbin about emerging security threats to expect in 2021. Steve breaks down the top five threats for security professionals to be mindful of going into 2021, and offers some tips for securing your organization against them.
Mentioned in today’s episode:
Cyber Security Strategies: Achieving cyber resilience
Read the transcript of this episode
Today, Steve welcomes motivational speaker, corporate consultant, and educator Reggie Butler back to the podcast. Reggie last connected with Steve in 2018 for an episode of our videocast (link below). Today’s conversation focuses on what we’ve learned through the experience of working from home during the pandemic, strategies for uniting teams even while socially distanced, and why leaders should model vulnerability and transparency now more than ever.
Learn more about Reggie Butler.
Mentioned in this episode: * 2018 ISF Videocast with Reggie Butler: Finding your ‘rhythm’ in business * Read the transcript of this episode * Subscribe to the ISF Podcast wherever you listen to podcasts * Connect with us on LinkedIn and Twitter * From the Information Security Forum, the leading authority on cyber, information security, and risk management
In this episode, Steve speaks with a guest whose focus includes human culture, behavior, and storytelling: singer/songwriter and activist Sir Bob Geldof, lead singer of the Boomtown Rats and founding member of Band Aid, famous for raising money for Ethiopian famine relief. Steve and Sir Bob discuss the effect of the Covid19 pandemic on creativity, the political turmoil facilitated by rapidly advancing digital technology, Sir Bob’s hope for fresh ideas, the courage to embrace change, and more.
Learn more about Sir Bob Geldof and the Boomtown Rats. Mentioned in this episode: * Pete Briquette * Simon Crowe * Garry Roberts * Vladimir Putin * Xi Jinping * Recep Tayyip Erdogan * Boris Johnson * Donald Trump * Charles Darwin * Sigmund Freud * Karl Marx * Live Aid * Live 8 * QAnon * Thomas Piketty * Shoshana Zuboff * Marshall McLuhan * Novacene: The Coming Age of Hyperintelligence by James Lovelock * Richard Branson * Bill Gates * Steve Jobs * Mark Zuckerberg * Jack Ma * Larry Page * Sergey Brin * Winston Churchill * Alan Brooke * George Bernard Shaw * Tim Berners-Lee * Johannes Gutenberg * Colin Wilson * The Rolling Stones * Mick Jagger * Keith Richards * Billie Holiday * John Lennon * Paul McCartney * Paul Allen * Steve Wozniak * Gaia Theory
Today Steve speaks with writer and researcher Brigid Schulte, author of the New York Times bestselling book on time pressure, Overwhelmed: Work, Love & Play When No One Has the Time. Formerly an award-winning journalist for The Washington Post and The Washington Post Magazine, and part of the team that won the 2008 Pulitzer Prize, Schulte is a global speaker on time, productivity, leisure, and the value of play, and she serves as the founding director of The Good Life Initiative at the nonpartisan think tank, New America. She’s also the director of The Better Life Lab, a work-family justice and gender equity program.
In today’s conversation, Steve and Brigid discuss the need for leadership — a need that, during Covid, is more urgent than ever before; how to make work work better for everyone; and the opportunity for enterprises to remeasure what they value, and reestablish the value system that threads through the heart of everything they do.
Learn more about Brigid Schulte. Mentioned in this episode: * Overwhelmed: Work, Love & Play When No One Has the Time * The Better Life Lab * Read the transcript of this episode * Subscribe to the ISF Podcast wherever you listen to podcasts * Connect with us on LinkedIn and Twitter * From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is in conversation with Dr. Hannah Fry, associate professor in the Mathematics of Cities at the Centre for Advanced Spatial Analysis at University College London, and a researcher in the patterns of human behaviour, particularly in an urban setting. In this conversation, Steve and Hannah discuss the challenge and imperative of communicating across demographics with simplicity and clarity; the power of storytelling; the moral tensions inherent in data mining; and more.
Mentioned in this episode: * Hello World * Jon Ronson * Cambridge Analytica data scandal * Drone legislation in the UK * ISF Threat Horizon 2021
Today, Steve is in conversation with philosopher, author, and speaker Anders Indset. Steve and Anders discuss the importance of leaders engaging in what he calls a “self audit,” having the strength and courage to get vulnerable, the importance of listening, and more.
Mentioned in this episode: * Arne Næss * Lofoten * The Social Dilemma * Read the transcript for this episode * Subscribe to the ISF Podcast wherever you listen to podcasts * Connect with us on LinkedIn and Twitter * From the Information Security Forum, the leading authority on cyber, information security and risk management.
Producer Tavia Gilbert talks to ISF Managing Director Steve Durbin about what we’ve gained and lost from altering our workplaces and our workflows during the pandemic; how heads of enterprises can support their teams throughout this unprecedented period of change; the difference between good leadership and great leadership; and more.
Today’s episode marks the beginning of our podcast’s fifth year of production, and we’re returning from our summer hiatus with a refreshed mission. As ever, the ISF Podcast will continue to offer cutting-edge conversations tailored to CISO’s, CTO’s, and other global security pros, as well as periodic reports on timely cybersecurity topics such as the threat horizon or human-centered security. But we want to offer you more education, information, and inspiration than ever before, so we’re going to be expanding those conversations to include leaders, writers, speakers, and more people traditionally outside of the security space. Whether we’re hearing from a musician or a CRO, the head of a global non-profit or the head of a Fortune 500 company, Steve will bring you, your teams, and your partners insights from rule-breakers, collaborators, culture-builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity.
As the ISF Podcast enters its fifth year of production, we’re celebrating with a listen back to some of the timeless insights our guests have shared over the past few years.
Featured in this episode: * Col. Chris Hadfield * Dr. Mary Aiken * Dr. Ann Cavoukian * James Arroyo OBE * Christopher Frenz * Reggie Butler * Nicholas Witchell * Dr. VS Subrahmanian * Will Houston * Jon Fisher * Sherina Edwards
Do you want to know how innovative leaders are guiding their enterprises through unprecedented global upheaval? How visionary executives hold themselves accountable to the values that guide their business? And how personal responsibility for safeguarding security can infuse corporate culture at ever level?
Welcome to the ISF Podcast, bringing you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Managing Director Steve Durbin speaks with rule breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. Subscribe today.
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
**Cyber Resiliency in a defining moment in history
Episode 1: Cyber Resilience - Reaping the Benefits** Steve Durbin, Managing Director, ISF William Beer, Member of the ISF USA planning team
Recorded 14th July 2020
30 mins
In this first episode of our CISO series, William and Steve explore how despite the unexpected, complex and far-reaching implications of COVID-19, the verdict is clear – planning pays off. They discuss and provide examples of how those who had invested in resilience planning and testing have reaped the benefits.
We’ve been encouraged to embrace IoT for its convenience and its integration into our daily lives. But what happens when the Internet of Things bites back? In today’s ISF podcast, ISF Managing Director Steve Durbin and podcast host Tavia Gilbert brings you the third episode in a series focusing on Threat Horizon 2022: When digital and physical worlds collide. In the series so far, Steve has explored threats that business enterprises will face between now and 2022, the consumer backlash to data harvesting and behavioural analytics, and the enormous threat of deepfakes. In today’s episode, Steve and Tavia look more in-depth at the threat posed by the Internet of Forgotten Things. How the cheap, easy-to-produce IoT devices of today, many of which were never intended to be patched or updated, might become the security risks of tomorrow as well as the complicated legal regulations regarding the production and use of these devices.
https://www.securityforum.org/videos-podcasts/threat-horizon-2022-internet-of-forgotten-things/
“Highly connected ecosystems of digital devices will enable organisations to harvest, repurpose, and indeed sell sensitive behavioural data about consumers without their consent, with attackers having the potential to then target and compromise poorly secured systems and databases at will.”
In today’s ISF Podcast, we bring you the second episode in a series focusing on Threat Horizon 2022: Digital and Physical World’s collide. In the previous episode, Steve Durbin, Managing Director of the ISF, and Tavia Gilbert, ISF Podcast Host, gave a broad overview of the threats that business enterprises will face between now and 2022, as well as advice for proactive leaders.
In today’s episode, Steve dives in deeper into two previously mentioned topics, starting with the consumer backlash against behavioural analytics, before moving onto the fascinating yet terrifying practice of deepfakes.
https://www.securityforum.org/videos-podcasts/threat-horizon-2022-behavioural-analytics-and-deepfakes/
“So the real challenge I think that we have to face up to here is that organizations are simply not going to be able to disentangle the digital from the physical. And they will be forced to respond to this growing blend of threats from new technologies, people, and indeed nature.”
We are heading into an era, unlike anything we've ever seen before. Digital and physical worlds are on an irreversible collision course. By 2022 organisations are not just going to be newly challenged, but in fact, plunged into crisis as ruthless attackers exploit weaknesses in immature technologies and take advantage of what is really an unprepared workforce. At the same time, natural forces will ravage infrastructure and all of this creates a perfect storm of trouble inside and outside the enterprise.
In today’s ISF podcast, we are bringing you the first in a series of episodes focusing on Threat Horizon 2022: When Digital and Physical Worlds Collide. ISF Managing Director, Steve Durbin and ISF podcast host Tavia Gilbert will be discussing the broad threat overview before diving more deeply into a couple of areas that demand more attention.
https://www.securityforum.org/videos-podcasts/threat-horizon-2022-digital-and-physical-worlds-collide/
“I think there are two different concerns here, right? There's an infrastructure issue, period, regardless of the pandemic. And then, of course, there's the additional pressure and increased precautions needed to address this current crisis that we're in.”
In today’s ISF Podcast, Steve Durbin, Managing Director of the ISF is joined by Sherina Edwards, Partner at Quarles and Brady LLP. Sherina is an energy-professional with extensive regulatory and public policy experience.
In this thought-provoking conversation, Steve and Sherina will be discussing the pressure on critical infrastructures due to the massive shift in working from home, the resulting cybersecurity concerns, and how regulatory challenges are evolving, even by the hour.
https://www.securityforum.org/videos-podcasts/sherina-edwards-the-growing-pressure-of-critical-infrastructures/
"I do think actually that one of the positive outcomes from COVID-19 will be that people will perhaps realise that the human element, the natural element, has a probably more significant role to play in society than technology. Technology should only ever be a tool. And I do wonder what the world will be like post-COVID-19."
In this week's podcast, ISF Managing Director Steve Durbin and ISF Podcast host Tavia Gilbert have an open, wide-ranging conversation about the current global crisis, from the alarming to the hopeful. They discuss the increased threat of cyber attackers, privacy concerns with telemedicine and other home-working apps, whether technology is moving closer to a brave new world, and what we can learn from this moment in history.
https://www.securityforum.org/videos-podcasts/technology-in-a-brave-new-world/
"The reason why it was so hard to get a settlement of this size wasn't because Facebook was worried that if they lost $550 million, it would hurt them. They can pay the 550. What they were worried about was setting some sort of precedent where now this is the price for privacy violations, and that's what we're fighting so hard for"
In this episode, ISF Managing Director Steve Durbin speaks with Jay Edelson, a Chicago attorney with Edelson PC whose work has earned him the title of “Cybersecurity Trailblazer” from the National Law Journal. His firm recently settled a $550 million privacy suit against Facebook on behalf of the people of Illinois.
Jay and Steve discuss that suit, the current privacy and cybersecurity legislation landscape, the influence of tech companies, facial recognition and privacy concerns with new and emerging technologies.
https://www.securityforum.org/videos-podcasts/jay-edelson-data-privacy-the-people-of-illinois-vs-facebook/
"Everything is connected, from the protocols that we use to advise and educate parents in terms of how their children interact with technology, all the way through to hard-core cyber criminal activity. It's connected."
In this ISF Podcast, Cyberpsychologist Dr Mary Aiken sits down with ISF Managing Director Steve Durbin to discuss the difference between cyberspace and real life, whether or not humans are prepared for the cyber challenges we face, the impact of technology on young children, and a fascinating potential solution to the skills shortage that could also curb cybercrime rates.
Mary specialises in the impact of technology on human behaviour, and has written extensively on issues relating to the intersection between humankind and technology – or as she describes it “where humans and technology collide.”
https://www.securityforum.org/videos-podcasts/dr-mary-aiken-cyberpsychology-and-the-impact-of-technology-on-human-behaviour/
"Then there's what I call the day after tomorrow. New ideas, new technologies, new innovations, new challenges, new players, new business models that can really change the nature of the game that you're in. And how much time do you as companies or leaders think about today, tomorrow and the day after tomorrow."
In this week's ISF Podcast, Peter Hinssen, serial entrepreneur, best selling author, keynote speaker and Founder of Nexxworks, sits down with ISF Managing Director Steve Durbin to discuss "the day after tomorrow".
Peter and Steve explore how security professionals can look past today’s tasks to prepare for the future, facilitating an innovate culture, the pace of technological transformation, how cognitive diversity could improve the workplace and more.
https://www.securityforum.org/videos-podcasts/peter-hinssen-the-day-after-tomorrow-surviving-radical-innovation/
"I think it's about understanding how you combat the remote element, how you provide advice and guidance to people about what they should be doing, how they should be working." The COVID-19 outbreak has turned many regular office goers and commuters into home workers. They have been thrust into an environment that can pose novel risks for both staff and their employers. In today's Podcast, ISF Managing Director Steve Durbin will be discussing the best practices for working from home, a topic with global relevance as workforces are suddenly adjusting to working with greater independence in greater isolation and hopefully with greater interconnectedness than ever before.
https://www.securityforum.org/videos-podcasts/covid-19-top-security-tips-for-working-from-home/
"Reputation is everything. If you lose some money, then that's bad, it's worse if you lose personal data, people's personal data, and then they're subject to cyber attacks. That's really bad. But you can make restitution for that. If you lose your reputation, you've lost everything."
In this week's ISF Podcast, James Arroyo OBE, Director of the Ditchley Foundation, sits down with ISF Managing Director Steve Durbin to discuss growing Geo-strategic tensions, recognising reputation as an organisations crown jewels and much more.
https://www.securityforum.org/videos-podcasts/james-arroyo-cyber-2025-this-time-its-personal/
"Threat Horizon is there to try to identify upcoming threats so that we are forewarned and forearmed. And what the ISF has always done with that Threat Horizon is try to pull out issues, yes, at the basic security level, but also then say, what does this actually mean from a business standpoint? And what does a business, an organization need to do in order to avoid some of those threats, mitigate some of those risks?"
In today's ISF Podcast, we're bringing you a conversation with journalist Nicholas Witchell and ISF Managing Director Steve Durbin. In this wide-ranging conversation, Steve will share his insights on the role of cyber in society and its impact on individuals and the future outlook.
https://www.securityforum.org/videos-podcasts/nicholas-witchell-steve-durbin-cyber-in-society/
"It requires persistence of professionalism. A recognising that even if I'm great at this, there are still ways for failure to happen, for it to rear its ugly head. You have to build an ever-increasing base of readiness to deal with things going wrong, readiness for failure."
In this week's special ISF Podcast, Colonel Chris Hadfield, decorated astronaut, engineer and pilot, sits down with ISF Managing Director Steve Durbin to discuss his desire to become an astronaut, the need for constant retraining and self-assessment, preparing to fail, achieving goals against the odds, the speed of technology and much more.
https://www.securityforum.org/videos-podcasts/colonel-chris-hadfield-an-astronauts-guide-to-managing-risk/
"In today's modern way of doing business, when cyber breaches and information security make or break an organisation, there is an increased need for company structure and better use of technology."
Organisations focus most of their efforts on meeting strategic and financial targets. However, the board and security leaders need to be aware that this is when cybercriminals are most likely strike – leading to reputational damage and disruption to the financial bottom line. When a security breach happens, it is the CISO who shoulders the blame.
In this podcast, Steve Durbin, Managing Director of the ISF, discusses how cyberspace is not just the responsibility of one or two individuals – but the whole organisation. When it comes to security best practices, collaboration between security leaders and the board is the key to success.
https://www.securityforum.org/videos-podcasts/the-ceo-vs-the-ciso-the-security-breach-blame-game/
“One of the criticisms around all this is that the cost of creating a cyber-resilient organisation might on the surface appear excessive. That is until a cyber crisis occurs.”
In this week’s podcast, we bring you the fifth and final episode in a series focusing on forecast 2020: the global security threat outlook.
Throughout the series, Steve Durbin, Managing Director of the ISF, has discussed the race for technology dominance, third-party supply chains, IoT and the Cloud, the growing risk of cybercrime as a business as well as the complexity of the geopolitical arena and technological confrontation between the US and China.
In today’s final episode, Steve once again sat down with Tavia Gilbert to discuss why striving for cyber resilience is a key component of a cyber risk management strategy and why the investment and planning is worth it.
https://www.securityforum.org/videos-podcasts/cyber2020-striving-for-cyber-resilience/
“The geopolitical area is set to remain fairly complex. I would also say sort of turbulent and fragile as the US and China battle it out for global dominance”
In this week’s podcast, we bring you the fourth episode in a series focusing on Forecast 2020: the global security threat outlook. Throughout the series, Steve Durbin, Managing Director of the ISF, has discussed the race for technology dominance, third-party supply chains, IoT and the Cloud as well as the growing risk of cybercrime as a business.
In this episode, Steve once again sat down with Tavia Gilbert to explore the complexity of the geopolitical arena and just how far the technological confrontation between the US and China can go.
https://www.securityforum.org/videos-podcasts/cyber2020-china-usa-and-the-geopolitical-arena/
“Cybercrime is certainly an entrepreneurial growth business. There’s no getting away from it and the arrest rate is very low. So, unfortunately, cybercrime does pay”
In this week’s podcast, we bring you the third episode in a series focusing on Forecast 2020: the global security threat outlook. Throughout the series, Steve Durbin, Managing Director of the ISF, has discussed the race for technology dominance as well as third-party supply chains, IoT and the Cloud.
In this episode, Steve sat down with Tavia Gilbert to explore the growing risk of Cybercrime, the threat from malicious insiders, the resource pool available to criminal organisations and how concerned we should be.
https://www.securityforum.org/videos-podcasts/cyber2020-entrepreneurial-cybercrime/
“So much of our critical data is now held in the cloud. Whether we put it there as individuals or organisations have put it there on our behalf. And that opens even more opportunity for cybercriminals.”
In this week’s podcast, we will be bringing the second episode in a series focusing on Forecast 2020: The Global Security Threat Outlook. In the previous episode, Steve Durbin, Managing Director of the ISF spoke about China, the USA, and the race for technology dominance.
In today’s episode, Steve sat down with Tavia Gilbert to explore the cyber threats around third-party supply chains, IoT, and the Cloud.
https://www.securityforum.org/videos-podcasts/cyber2020-third-party-iot-and-the-cloud/
“Technology has changed the world in which we live. Old norms are changing and it's clear that the next industrial revolution will not only be entirely technology-driven, but technology dependent.
In this week’s podcast, we will be bringing you the first in a series of episodes focusing on Forecast 2020: The Global Security Threat Outlook. Over this series, ISF Managing Director Steve Durbin will be discussing the top global security threats that businesses will face in 2020 or in shorthand, things that will keep you up at night.
This episode will see Steve explore the race to develop strategically important next-generation technology.
https://www.securityforum.org/videos-podcasts/cyber2020-the-race-for-technology-dominance/
“It showed that the risk was really unacceptable because you couldn't afford to lose a whole department. The impact on patient care would be fairly disastrous.”
In this week’s ISF Podcast, Christopher Frenz, AVP of Information Security for Interfaith Medical Centre, sat down with Steve Durbin, Managing Director of the ISF, to discuss how and why Interfaith implemented a zero-trust network security model, tips for getting business leaders on board with cybersecurity plans, overcoming the challenges of working in an environment with legacy devices, and much more.
https://www.securityforum.org/videos-podcasts/chris-frenz-the-zero-trust-network-security-model/
“A new approach is need, one that helps organisations to understand and manage psychological vulnerabilities and adopts technology and controls designed with human behaviour in mind. And we’ve called that human-centred security.”
In the last episode of the Information Security Forum’s Human-Centred Security podcast series we took a deep dive into how human vulnerabilities are exploited, but this episode sees Steve Durbin, Managing Director of the ISF, discuss how to manage those human vulnerabilities.
Throughout this series, Steve Durbin joined Tavia Gilbert to explore how human vulnerabilities, whether triggered through work pressure or by a malicious attacker, can lead to errors that significantly impact an organisation's reputation or even put lives at risk.
https://www.securityforum.org/videos-podcasts/human-centred-security-managing-human-vulnerabilities/
“The methods of psychological manipulation used by attackers have not just moved online since humans entered the digital era, but today's attack techniques are more sophisticated, cost-effective and expansive, allowing attackers to effectively target individuals or to attack on a considerably larger scale.”
In this podcast, Steve Durbin, Managing Director of the ISF, explores how psychological vulnerabilities present attackers with opportunities to influence and exploit humans for their own advantage.
https://www.securityforum.org/videos-podcasts/human-centred-security-exploiting-human-vulnerabilities/
“We are seeing, the EU being an important leader in trying to advocate for consumers' rights, to some degree for employees' rights, although I wouldn't say that that's super strong. I would like to see students going through more data science training so that they have better data literacy and are better able to advocate for themselves out in the world about what can and cannot be done.”
In this ISF podcast, Laura Norén, VP of Privacy and Trust at Obsidian Security sat down with Steve Durbin, Managing Director of the ISF, to discuss data privacy for employees, whether AI is suited for cybersecurity, and more.
https://www.securityforum.org/videos-podcasts/laura-noren-the-crusade-to-protect-employees-data/
“By identifying the fundamental vulnerabilities in humans and understanding how psychology works and what triggers risky behaviour, organisations can begin to understand why their employees might make errors and then begin managing that risk more effectively”
In the second part of our human-centred security series of podcasts, Steve Durbin, Managing Director of the ISF, discusses how do identify a variety of human vulnerabilities that arise in day-to-day life and in the information security sector.
https://www.securityforum.org/videos-podcasts/human-centred-security-the-human-vulnerabilities/
“Not long ago it was generally seen as a bad thing. Now we’re having clients say, ‘we want somebody who’s been through a breach’.”
In this ISF Podcast, Managing Director Steve Durbin is joined by Egon Zehnder consultant Will Houston to discuss the skills shortage, the effect of a breach on a CISO’s value and employability, and more.
https://www.securityforum.org/videos-podcasts/will-houston-the-effect-of-a-breach-on-a-cisos-value/
The latest ISF Podcast will bring the first in a series of episodes focusing on human-centred security. In this episode, Steve Durbin, Managing Director of the ISF, will discuss what the insider threat looks like and how to manage it.
“Employees and negligence are the leading causes of security incidents but remain the least reported issue. The explosion of digital devices creates real challenges for organisations of all sizes. The majority consider themselves vulnerable to insider threats and most include insider threats in their top three security concerns”
https://www.securityforum.org/videos-podcasts/isf-podcast-human-centred-security-the-insider-threat/
"Steve, given the speed of change in cyber, do you believe that a CEO should be encouraging innovative, out-of-the-box thinking from their CIO or CISO?"
In today's ISF Podcast, Steve Durbin, Managing Director, ISF, will be discussing the importance of emotional intelligence for CISOs, accepting the inevitability of security breaches and learning from those breaches.
https://www.securityforum.org/videos-podcasts/isf-podcast-innovating-your-cybersecurity/
"I think that when we look at cybersecurity today, it isn't just a technology issue. It is much bigger than that. Cyber is pretty much integrated across all of an enterprise. There isn't anything that most departments in a business won't get up to that doesn't touch cyber in some way.
In this week's ISF Podcast, Steve Durbin, Managaing Director, ISF, discusses not only the risks involved of leaving cybersecurity squarely on the shoulders of the CIO, but also how cybersecurity can enable growth and innovation.
https://www.securityforum.org/videos-podcasts/isf-podcast-leaving-the-weight-of-the-world-on-the-cios-shoulder/
"It isn't just about technology. The human piece has a key role to play in securing our environment, and so yes, for me, the Board has to be setting an example, has to be really at the top of it's game in demonstrating leadership."
In the latest ISF Podcast, we present the second of two episodes focusing on the role of the Board in cybersecurity. ISF Managing Director Steve Durbin will be discussing how the Board can address the skills shortage, as well as the evolution of the Board's role as cybersecurity further integrates into all levels of the business.
https://www.securityforum.org/videos-podcasts/isf-podcast-embedding-cyber-hygiene-into-the-organisation/
"Why is it not enough for an organization to hire a CISO and have that person report to the board periodically? Why is that not enough due diligence?"
In the latest ISF Podcast, we present the first of two episodes focusing on the role of the Board in cybersecurity. ISF Managing Director Steve Durbin will be discussing how often CISOs should be meeting with the Board and how CISOs can be more effective in communicating and in meeting the security needs of the business.
https://www.securityforum.org/videos-podcasts/isf-podcast-bridging-the-gap-between-the-ciso-and-the-board/
“Nobody is immune from attack, especially as these attacks are getting increasingly sophisticated. You have the spearphishing attacks, which are very, very highly targeted at very specific individuals. Those emails look like they're coming from friends, from professional colleagues, and emails are not the only vector. So the attacker can throw things at us from many different directions. And we've got to be cognizant of all of those.”
In the second Podcast of this two-part series, VS Subrahmanian, Professor of Computer Science at Dartmouth College, discusses the risks posed by the Internet of Things, cybersecurity awareness for the general public, and more.
https://www.securityforum.org/videos-podcasts/isf-podcast-vs-subrahmanian-cyber-security-and-the-individual/
“But over the last, I would say 15 years, what's become increasingly clear is that AI, artificial intelligence, is going to play a huge role both on the defensive side and on the offensive side. So, over the next few years, we're going to see people increasingly use AI to attack systems”
In the first of this two-part series, VS Subrahmanian, Professor of Computer Science at Dartmouth College, discusses both the threats and benefits of AI on cybersecurity with Steve Durbin, Managing Director, ISF.
https://www.securityforum.org/videos-podcasts/isf-podcast-vs-subrahmanian-ai-security-threat-or-benefit/
“You can have the best security implementations in the world, but if your users are not trained, and they click on the link, you're going to be in trouble”
In this episode of the ISF Podcast with Jon Fisher, former FBI agent and current Managing Director for Lifars, and ISF MD Steve Durbin, we will be discussing how to improve employee education in cybersecurity awareness and the best way to run a tabletop exercise.
https://www.securityforum.org/videos-podcasts/isf-podcast-jon-fisher-think-before-you-click/
“Depending on your industry, you may be targeted by a different set of actors with different tactics, and I think as the CISO or as a security practitioner, you need to know what is targeting you and you need to stay apprised of the threats that are out there and how you can help defend against them.”
In the first of this two-part series, Jon Fisher, Managing Director at Lifars and a former FBI agent discusses current and future cyber threats and cooperating with law enforcement with Steve Durbin, Managing Director, ISF.
https://www.securityforum.org/videos-podcasts/isf-podcast-jon-fisher-law-enforcement-and-business-collaboration/
"I think we've really seen the concept of a SOC grow and evolve over the past 10 years or so," says Emma Bickerstaffe, Senior Research Analyst at the Information Security Forum. As your business and the threat landscape change, how do you keep pace with your security operations centre (SOC)? Emma Bickerstaffe, Senior Research Analyst, ISF and Jamie Cowper, Product Marketing Manager at IBM Security, join the podcast for a discussion about building and enhancing a SOC, or "the eyes and ears of an organisation."
They cover business drivers for improving a SOC; perspectives on internal, external, and hybrid models; and the five core capabilities of a SOC.
https://www.securityforum.org/videos-podcasts/isf-podcast-emma-bickerstaffe-the-evolving-security-operations-centre/
In the final episode of this three-part series, Adam Levin, CEO and founder of Cyber Scout and author of Swiped: How to Protect yourself in a World Full of Scammers, Phishers and Identity Thieves, offers insights into the maturity, collaborative culture, preparation, and responsiveness required for true cyber-resilience.
https://www.securityforum.org/videos-podcasts/isf-podcast-adam-levin-is-scaring-caring-when-it-comes-to-cyber-security/
In the second episode of this three-part series, Adam Levin, author of Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves, goes into detail about the importance of creating a thorough, integrated, cyber-resilient corporate culture.
https://www.securityforum.org/videos-podcasts/isf-podcast-adam-levin-integrating-cyber-into-the-dna-of-your-business/
Breaches have become the third certainty in life and cyberwar has replaced the cold war. The truth is we are under attack every minute of every day. So how can we defend against everyday cyber threats?
In the first episode of this three-part series, Adam Levin, chairman and founder of CyberScout, co-founder of Credit.com, and author of Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves will be speaking to Steve Durbin, Managing Director, ISF on the hard truth about the insecurity of the modern technology era. Adam and Steve discuss how consumers can better protect their information, the three Ms (minimising risk exposure, monitoring systems and managing damage) and the risks that social media poses.
https://www.securityforum.org/videos-podcasts/isf-podcast-adam-levin-consumers-protecting-yourself-against-everyday-scams/
Die Umsetzung der Allgemeinen Datenschutzverordnung in Deutschland stieß auf große Kritik. Gibt es zu viel Verwirrung um unterschiedliche Rechtsvorschriften und wie effizient ist die DSGVO in Europa heute? In der letzten Folge dieser dreiteiligen Reihe gibt Axel Voss, Vertreter der deutschen CDU im Europäischen Parlament, Einblicke in die Datenschutzlandschaft und was sich Unternehmen in den nächsten Jahren vorbereiten sollten.
https://www.securityforum.org/videos-podcasts/isf-podcast-axel-voss-mit-veranderungen-datenschutzlandschaft-schritt-halten/
In today's podcast, Steve Durbin, Managing Director of the ISF talks with Dr. Ann Cavoukian, the Distinguished Expert-in-Residence of Ryerson University's Privacy by Design Centre of Excellence.
Ann Cavoukian is recognised as one of the world's leading privacy experts. Since 2017, Cavoukian has been the distinguished expert in residence of Ryerson University's Privacy by Design Centre of Excellence. In fact, Ann developed the concept of Privacy by Design and its later evolution, Security by Design.
In today's conversation, Dr. Cavoukian will discuss the necessity that businesses "bake in" security and privacy into their business plan.
https://www.securityforum.org/videos-podcasts/isf-podcast-dr-ann-cavoukian-privacy-by-design-security-by-design/
Understanding what assets are critical to your business is fundamental. Adversaries are often able to spot these assets ahead of businesses. CISOs need to be able to think like the adversary to put effective protective measures in place. In the final episode of this three-part series, Leo Taddeo, CISO at Cyxtera and former FBI agent, discusses thinking like an adversary and how the board and CISO can work together to face security threats.
https://www.securityforum.org/videos-podcasts/isf-podcast-leo-taddeo-know-what-to-protect-think-like-a-cyber-criminal/
70% of the US financial industry is located within New York City, this sits on a complex urban infrastructure. Impacting this infrastructure (through a physical or cyber-attack) will indirectly impact financial systems, causing mass disruption to businesses. In this environment, how can a CISO keep up with emerging threats? In the second part of this three-part series, Leo Taddeo, current CISO at Cyxtera and former FBI agent, offers insights into the challenges of cybercrime, physical infrastructure attack and the threats posed to the densely populated, urban area of New York City.
https://www.securityforum.org/videos-podcasts/isf-podcast-leo-taddeo-new-york-city-and-cybercrime/
In der ersten Folge dieser dreiteiligen Serie diskutiert Axel Voss, Vertreter der deutschen CDU im Europäischen Parlament, mit Sebastian Tischer, Regionaldirektor ISF, Datenschutz, DSGVO-Verordnung sowie Ethik und Technologie. Axel gibt Einblicke, wie Tech-Giganten unser soziales Leben, unsere Kultur und Gesetzgebung zunehmend beeinflussen und wie Nationalstaaten ein Gleichgewicht finden müssen, um nicht zu stark von Tech-Unternehmen abhängig zu werden.
In the first episode of this three part series, Axel Voss, representative of the German political party CDU in the European Parliament, discusses with Sebastian Tischer, Regional Director, ISF, data protection, the GDPR regulation and ethics and technology. Axel offers insights into how tech giants are increasingly influencing our social life, culture and legislation and how nation states need to find a balance, so as not to grow too dependent on tech corporations.
https://www.securityforum.org/videos-podcasts/isf-podcast-axel-voss-new-technologies-vs-ethics/
In the first episode of this three-part series, Leo Taddeo, Former FBI agent and current CISO of Cyxtera shares his unique history and career path from the military to law enforcement to CISO. Leo discusses with Steve Durbin, Managing Director, ISF the challenges that he has faced over the years, including technologies, Russian organised crime and more.
https://www.securityforum.org/videos-podcasts/isf-podcast-leo-taddeo-from-fbi-agent-to-ciso/
Competing in the digital marketplace will become increasingly difficult, as threat to businesses grow in speed and precision: Software and application weaknesses will continue to be leaked online with ever-decreasing time to fix them. The break-up of tech giants will plunge those reliant on their products and services into disarray and organisations rushing to deliver ambitious digital transformations will expose their vulnerabilities instead of cementing their resilience.
In the final podcast of the series, Steve Durbin Managing Director, ISF will discuss the third theme of our Threat Horizon 2021 series: Digital Competitors Rip Up the Rulebook. Steve will offer insights into the threats organisations face and the steps CISO’s can take to guard against them.
https://www.securityforum.org/videos-podcasts/isf-podcast-threat-horizon-2021-digital-competitors-rip-up-the-rulebook/
The race to develop strategically important, next-generation technologies is laying the foundation for nation state-backed espionage where intellectual property (IP) is targeted. Cloud services will become a prime target for sabotage and drones will become both the weapon and target of choice as attackers turn their attention skywards. The question is, how can organisations, who are increasingly reliant on the cloud, prepare for this environment?
In this podcast, Steve Durbin, Managing Director, ISF will discuss the second theme of our Threat Horizon 2021 series: How the Digital Cold war engulfs business. Steve offers insights into upcoming cyber threats and offers business leaders key advice to best prepare.
https://www.securityforum.org/videos-podcasts/isf-podcast-threat-horizon-2021-digital-cold-war-engulfs-business/
Today, digital connectivity is essential in everyday life, and this is only set to increase over the next two years as we see technology such as the Internet of things (IoT) playing a vital role in business success. By 2021, vast webs of intelligent devices, combined with increased speeds, automation and digitisation will bring new possibilities within reach of businesses and consumers. However, increasingly complex digital connectivity will increase the number of attack surfaces, amplifying existing dangers and creating new ones. In the second episode of our Threat Horizon podcast series, Steve Durbin, Managing Director, ISF will discuss digital connectivity and the potential vulnerabilities that this will expose.
https://www.securityforum.org/videos-podcasts/isf-podcast-threat-horizon-2021-digital-connectivity-exposes-hidden-danger/
By 2021 the world will be heavily digitised and connected. The race to develop next generation technologies will enable innovative, digital business models, yet this will leave society critically dependent on technology to function. Coupled with heightened global mistrust and rising geopolitical tensions, this will lead to cyber threats that are relentless, targeted and disruptive. In the first episode of our four part Threat Horizon 2021 series, Steve Durbin, Managing Director, ISF will identify the key threats that will effect organisations over the next 2 years and how business leaders and their teams can best prepare.
https://www.securityforum.org/videos-podcasts/isf-podcast-threat-horizon-2021-overview/
Nation-state cyber-attacks have increasingly occupied news headlines in the past few years from alleged Russian electoral interference to accusations of Iranian backed cyber-terrorist groups and Chinese theft of high-value intellectual property.
In the final episode of this two-part series, Steve Durbin, Managing Director, ISF, speaks with journalist Mike Eckel about the threats posed by nation-state-led cybercrime. Is it the government’s responsibility to protect you? Is your organisation a target? How do security teams convey the appropriate level of risk to their board? Should companies be allowed to hack back?
In this podcast, we delve into both preparation and measures business leaders can implement to defend against nation-state cyber-attacks.
https://www.securityforum.org/videos-podcasts/isf-podcast-the-enemy-is-the-state-cybersecurity-and-nation-state-attacks/
The power and influence of Russian cyber actors continue to rise, but where did this ability for cyber terrorism and espionage originate?
In the first episode of this two-part series, Steve Durbin, Managing Director ISF, speaks with journalist and Senior Washington correspondent for Radio Free Europe/ Radio Liberty Mike Eckel on the origins of Russian cyber terrorism. Together they discuss how the power and influence of Russian cyber actors have grown and the end game for Russian sponsored threat actors.
https://www.securityforum.org/videos-podcasts/isf-podcast-the-origins-of-russian-cyber-terrorism/
"In today's modern way of doing business, when cyber breaches and information security make or break an organisation, there is an increased need for company structure and better use of technology."
Organisations focus most of their efforts on meeting strategic and financial targets. However, the board and security leaders need to be aware that this is when cybercriminals are most likely strike – leading to reputational damage and disruption to the financial bottom line. When a security breach happens, it is the CISO who shoulders the blame.
In this podcast, Steve Durbin, Managing Director of the ISF, discusses how cyberspace is not just the responsibility of one or two individuals – but the whole organisation. When it comes to security best practices, collaboration between security leaders and the board is the key to success.
https://www.securityforum.org/videos-podcasts/the-ceo-vs-the-ciso-the-security-breach-blame-game/
Even after many devastating examples of the impact of cyber-attacks on business, cyber is still drastically underestimated. Organisations must implement a successful security programme, with the board who are held accountable and have a thorough understanding of the risks to prepare for and the risks they are willing to accept.
In the final episode of this three-part series, Jeff Engle, Veteran of US Army Special Operations Commands and Vice President of Federal for United Data technologies, discusses with Steve Durbin, Managing Director, ISF the responsibility business leaders have when it comes to security and why they must be proactive in their approach.
https://www.securityforum.org/videos-podcasts/isf-podcast-holding-the-board-accountable-for-security/
In the second episode of this three-part series, Jeff Engle, Veteran of US Army Special Operations Commands and Vice President of Federal for United Data technologies talks with Steve Durbin, Managing Director, ISF about the importance of effective communication and knowing your audience when collaborating with enterprises successfully to combat cyber threats.
Jeff and Steve discuss the need for security professionals to receive broader training so that they can communicate with the board on technical issues, in a language the C-suite can understand.
https://www.securityforum.org/videos-podcasts/isf-podcast-how-to-communicate-with-the-board/
People can either be your first line of defence, or your weakest link – it is up to organisational leadership and how they approach risk management to determine which one they are.
In the first episode of this three-part series, Steve Durbin, Managing Director, ISF talks with Jeff Engle, Veteran of US Army Special Operations Commands and Vice President of Federal for United Data technologies, about his background as a military veteran and a private sector cybersecurity leader. Jeff shares his insights into what the corporate world can learn from military organisation and training protocols, and how cybersecurity strategy is necessary to achieve primary business goals.
https://www.securityforum.org/videos-podcasts/isf-podcast-what-can-businesses-learn-from-military-security-strategies/
In the second episode of this series, former US most-wanted cybercriminal Brett Johnson, the ‘Original Internet Godfather’, speaks with Steve Durbin, Managing Director, ISF about his career as a cybercriminal. Brett offers an insider account, from his first scam he committed on eBay, to becoming a part of a worldwide cyber-criminal organisation.
Together, Steve and Brett discuss how the collaborative nature of cybercriminals has allowed them to evade law enforcement and commit crimes successfully.
https://www.securityforum.org/videos-podcasts/isf-podcast-the-life-of-a-cybercriminal/
The global supply chain is increasingly complex, diverse and hyper-connected so that gaining assurance of its security, safety and reliability is becoming more myth than reality. The recent rise in data breaches highlights these supply chain vulnerabilities and third parties are being heavily criticised for both inadequate preparation and protection.
In the final episode in this four-part series which explores the greatest cyber threats in 2019, Steve Durbin, Managing Director, ISF discusses the inherent risks to supply chains and how organisations can better manage data sharing with third parties to minimise the risk of a data breach.
https://www.securityforum.org/videos-podcasts/isf-podcast-the-myth-of-supply-chain-assurance/
In 2017, Cybercrime was an estimated $600 billion industry affecting approximately 2.8 million victims a day. The rise in ransomware attacks (an estimated 350%) and trend in spearfishing aimed at senior executives, is a further testament to the increasing sophistication, diligence and patience of today’s cybercriminals.
In this first of two episodes, Former US most-wanted cybercriminal Brett Johnson, the ‘Original Internet Godfather’, speaks with Steve Durbin, Managing Director, ISF about the most pressing issues presented by cybercrime. Together they discuss the threat of non-financially motivated attacks, what makes organisations attractive targets and the benefits of training us to think like criminals.
https://www.securityforum.org/videos-podcasts/isf-podcast-inside-the-mind-of-todays-cybercriminals/
Legislation by its nature is government and regulator driven, resulting in a move towards national regulation at a time when cross border collaboration is needed. Organizations will struggle to keep abreast of such developments which may also impact business models which many have taken for granted. This will be a particular challenge to cloud implementations where understanding the location of cloud data has been an oversight.
In the second episode in this four-part series which explores the greatest cyber threats in 2019, Steve Durbin, Managing Director, ISF discusses the impact of legislation on organisations, and the challenges regulators and legislators face trying to keep pace with cybersecurity.
https://www.securityforum.org/videos-podcasts/isf-podcast-the-impact-of-legislation-in-2019/
As the threat landscape evolves, digitalisation is an ongoing challenge for governments and politicians, making it increasingly difficult to secure networks, personal information and critical infrastructure. Governments must keep abreast of developments in cyber security and ensure that best practices are communicated to businesses, and awareness is raised amongst the public.
In the first of two episodes Steve Durbin, Managing Director, ISF talks with Dr Reinhard Brandl, a member of the German Parliament, about the broad challenges digitalisation raises for governments. Together they also discuss the effectiveness of the EU GDPR, and the future of legislation in cybersecurity and the role large organisations can play in this.
https://www.securityforum.org/videos-podcasts/isf-podcast-governments-and-the-challenge-of-rapid-digitalisation/
Cybercrime is now a market that is growing and increasing in sophistication, worth $600 billion in 2018 and affecting 2.7 million of us globally on a daily basis. With cybercriminals becoming increasingly strategic and patient in their approach, organisations cannot afford to ignore the increasing threats posed by such operations.
In the first episode of this four-part series which explores the emerging cyber threats in 2019, Steve Durbin, Managing Director, ISF discusses how the increasing sophistication of cybercrime and ransomware will impact businesses, and what the board can do to understand such threats and be proactive to protect their organisation.
https://www.securityforum.org/videos-podcasts/isf-podcast-the-increasing-sophistication-of-cybercrime-ransomware/
Will 2019 see cyber attacks come in isolation, or in combinations? A question organisations should think about as we see cyber space becoming increasingly connected and technology developments increasing in pace and scale.
In this podcast, Steve Durbin, Managing Director, ISF shares his predictions for the top 4 emerging cyber threats for 2019 – increased sophistication of cybercrime and ransomware, the impact of legislation, supply chain assurance and smart devices challenge data integrity. Steve also explains why getting back to basics in information security and risk management is paramount in this climate.
https://www.securityforum.org/videos-podcasts/isf-podcast-threat-horizon-2019/
Attacks from nation-states, where organisations are at risk are increasingly appearing on the threat horizon. As extortion is predicted to become one of the most common forms of cybercrime, it is imperative for the board to create a solid eco system between executives and individuals to conduct technical operations. Without a clear vision in place, CISOs will lack the transparency needed to overcome innovative attacks and face more barriers in the future.
In the second part of this podcast, Steve Durbin, Managing Director at the ISF talks with Ondrej Krehel, CEO and founder of LIFARS LLC. They discuss the impact of the escalation of cyber-attacks, the challenges this presents for CISOs, and how the c-suite and board need to prepare to counteract them effectively.
https://www.securityforum.org/videos-podcasts/isf-podcast-the-need-for-a-clear-vision/
It is an unavoidable fact that businesses and organisations’ sensitive information will be breached at some stage in the future. When a network has been compromised, proper investigation and remediation to the incident is vital, as the impact can be significant in the digital world. There are various steps that need to be taken to respond and recover from a data breach, much like the processes that are observed in a medical centre. Those steps create a tedious, disruptive process that may take more than one cyber life cycle to heal.
In this podcast, Steve Durbin, Managing Director at the ISF talks with Ondrej Krehel, CEO and founder of LIFARS LLC, an international cybersecurity and digital forensics firm specialising in remediation and resolution services. Here they discuss how data breaches are inevitable to businesses, and how organisations can prepare to effectively retaliate in the new world filled with cyber warfare.
https://www.securityforum.org/videos-podcasts/isf-podcast-a-digital-specialist-on-data-breaches/
Virtual reality has a great deal of potential for the betterment of society - but as with all new technologies, we should be aware of ethical concerns that could emerge as social problems further down the line. With this in mind, there is a need for increased legislation and guidelines to ensure both businesses and consumers don’t get caught up in the novelty of virtual reality.
In the second part of this podcast, Steve Durbin, Managing Director at the ISF talks with Emory Craig, an educator and leading expert in virtual, augmented and mixed reality. Here they discuss the dystopian elements to virtual reality, its challenges and implications, but also the steps needed to manage its legislation.
https://www.securityforum.org/videos-podcasts/virtual-reality-and-a-new-code-of-ethics/
Virtual, augmented and mixed reality has made tremendous progress over the last 4 years. Since then the landscape has dramatically shifted - consumers now experience these new technologies through devices such as smartphones and smart headsets, taking them into a whole new era. Organisations within industries such as film and medical have started implementing virtual reality to transform the way they do business.
In this podcast, Steve Durbin, Managing Director at the ISF talks with Emory Craig, an educator and leading expert in virtual, augmented and mixed reality. He is the Director of eLearning at the College of New Rochelle, and co-founder and partner at Digital Bodies. Here they discuss successful implementations of virtual, augmented and mixed reality, and the fascinating facts behind this new technology.
https://www.securityforum.org/videos-podcasts/a-futurists-insights-on-virtual-augmented-reality/
The traditional way of doing business is transforming, with businesses now required to adopt and embed cyber technology into their organisation. The shift in the way we do business isn’t just down to technology, but also cultural change – such cultural shifts include increasing business agility, shared information rather than centralised data, collaboration rather than a traditional triangle type hierarchy, and empowering one’s team to make decisions rather than exerting control over your talent.
In this podcast, Steve Durbin, Managing Director ISF discusses the 21st century workforce, and how businesses can attract and retain in an era of gig economy and short-term employee contracts, and what skill-sets are needed within a business to keep pace with the speed of technological developments.
https://www.securityforum.org/videos-podcasts/isf-podcast-doing-business-the-cyber-way/
Cyber-attacks are steadily increasing year on year. Organisations are constantly under threat with over two-thirds experiencing data breaches in 2017. Consequently, cyber security preparedness and resiliency are becoming increasingly important to the protection of an organisation’s information. One way of improving the ability to handle cyber-attacks is by running cyber security exercises.
In this podcast, Steve Durbin, Managing Director at the ISF, discusses how organisations should approach running internal cybersecurity exercises to support breach identification, prevention and response. This autumn, the ISF's 'Delivering an Effective Cyber Security Exercise' report was released to ISF Members which provides a detailed overview of the most suitable cybersecurity exercises and how to deploy them effectively. The public release for the overview of the report is November 15.
https://www.securityforum.org/videos-podcasts/isf-podcast-cyber-security-exercises/
Social media has transformed the way users behave online and offline. It has prevailed over the last decade and billions of people around the world engage with each other on these platforms on a daily, if not hourly basis. Whilst social media encourages individuality, the sharing of ideas and opinions online has created stereotypes and unrealistic benchmarks that people must attain to be accepted. Consequently, this has resulted in a multitude of mental health issues amongst individuals who believe they don’t fit the bill.
In the final episode in this three-part series, Steve Durbin, Managing Director at the ISF talks with Scott Amyx, Managing Partner at Amyx Ventures about healthy social media and technology use for kids, and whether they understand the ethical nature of sharing content online.
https://www.securityforum.org/videos-podcasts/isf-podcast-social-media-technology-habits/
‘Artificial Intelligence’ has materialised much faster than leading researchers and security professionals in the field expected and the future of it remains unknown. Thus far, consumers have engaged with virtual assistants, namely Amazon’s ‘Alexa’ or Apple’s ‘Siri’. Additionally, it is proposed that businesses can reap the benefits of increased efficiency through automating the value chain but also taking the combined approach of ‘man and machine’. Globally, a negative perception of superintelligence has been fostered, however, attention must be given to the emerging possibilities as the economic landscape evolves.
In this podcast, Steve Durbin, Managing Director at the ISF talks with Scott Amyx, Managing Partner at Amyx Ventures and author of the book ‘The Human Currency’. They discuss Artificial Intelligence (AI) and what it holds for the future of the global economy, focusing on the role that humans will play following the ‘4th Industrial Revolution.'
https://www.securityforum.org/videos-podcasts/isf-podcast-ai-machine-learning/
The ‘Internet of Things’ is a name given to exponential technologies encompassing our physical devices, vehicles, home appliances and increasingly normal everyday objects such as water bottles, that can store and exchange data. For consumers, they are often fearful of these advances and question how secure their personal data is. To overcome this issue, consumers must self-educate about personal security, moving away from a naive perspective and become mature, responsible agents when operating these data-storing devices.
In this podcast, Steve Durbin, Managing Director at the ISF, talks with Scott Amyx, Managing Partner at Amyx Ventures (a Venture Capital firm) and author of the forthcoming book ‘The Human Race’. They discuss the implications of the Internet of Things (IoT) and what the future holds - not just for businesses but also consumers.
https://www.securityforum.org/videos-podcasts/isf-podcast-scott-amyx-episode-one/
Following the introduction of GDPR and new e-privacy laws, sales and marketing teams are under pressure to think of new tactics and methods in which to collect information about existing and potential clients. Marketing relies heavily on digital engagement and therefore necessitates a strong brand image online to convert visitors on a web page to engage with the business.
In this podcast, Steve Durbin, Managing Director, ISF, discusses how marketing and sales can overcome challenges presented by recent government legislation when collating data and engaging your audience. Steve also talks about brand awareness on social media and how best to present your business in a way that will open the door to new business opportunities.
https://www.securityforum.org/videos-podcasts/isf-podcast-marketing-teams-adopt-new-tactics-to-increase-business/
The probability of a data breach for most organisations is highly likely, with it being a matter of ‘when’ not ‘if’. IT and security leaders are increasingly under pressure to not just protect the company’s reputation, stock and critical assets, but also ensure plans and systems are set up so that an organisation can properly respond to a data breach.
In this podcast, Steve Durbin, Managing Director at the ISF, discusses the importance of having a data breach plan in place, and walks us through the steps and the immediate actions organisations must take to reduce the risk of major data implications.
https://www.securityforum.org/videos-podcasts/isf-podcast-data-breach-response/
Today, acquirer companies in M&A’s are intensifying their cyber security due diligence during the negotiation period. Why? Because the cyber-risks to businesses are ever intensifying and any data vulnerabilities exposed can seriously threaten the value of a business and the overall success of the venture.
In this podcast, Steve Durbin, Managing Director at ISF, discusses the importance of the acquiring entity understanding the organisations information assets, and why cyber security due diligence should be implemented at an early stage of M&A to add value to the process and mitigate risk exposure post deal.
https://www.securityforum.org/videos-podcasts/isf-podcast-ma-best-practice-cybersecurity/
In the final part of this 3-part business leaders podcast series, Richard Guida, former CISO at Johnson & Johnson, and Steve Durbin, Managing Director at ISF, discuss what keeps CISO’s awake at night, the challenges integrating security into the product development process, and the importance of security for lay people.
https://www.securityforum.org/videos-podcasts/isf-podcast-security-product-development-process/
Artificial intelligence and machine learning are redefining cyber security, re-engineering threat detection tools and exposing sophisticated attacks – but there is a dark side. With increased use, we are seeing outcomes that go beyond the capabilities of IT and security professionals, which if not managed correctly could lead to major security issues and widen the already long-term skills gap.
In this podcast, Steve Durbin, Managing Director at ISF distinguishes the difference between machine learning and AI and discusses the pros and cons of the advancing technologies on cyber security, and particularly on the cyber workforce.
https://www.securityforum.org/videos-podcasts/isf-podcast-ai-machine-learning-contributing-to-the-skills-shortage/
A survey with ISF Members revealed that only 50% of organisations have a sufficient framework in place to manage third parties suppliers, and they don’t regularly review or update it!
With third party suppliers playing a critical role in supporting business activities, and often having access to critical business information and customer data, management and engagement with third parties as part of your breach prevention plan is essential.
In this podcast Steve Durbin, Managing Director at ISF shares what organisations must do to ensure third party suppliers have sufficient controls in place, and how to prioritise which third party suppliers need the most attention.
https://www.securityforum.org/videos-podcasts/isf-podcast-third-party-where-is-my-data/
In the second part of this 3-part business leaders podcast, Steve Durbin, Managing Director at ISF and Richard Guida, Managing Director at Guida Technologies discuss the negative impact new technology and in particular connected devices has on data security, and what this means for both businesses and consumers in the future.
https://www.securityforum.org/videos-podcasts/isf-podcast-data-security-iot-challenges/
In the first of this 3 part Business Leaders podcast, Steve Durbin, Managing Director at the ISF talks with Richard Guida, Managing Director at Guida Technology Associates about his experience as a former CISO implementing data security within a large organisation, the role technology plays and the implications this has on security and the people who work within it.
https://www.securityforum.org/videos-podcasts/isf-podcast-richard-guida-episode-1/
Increasingly organisations are incorporating mobile apps into their customer service offerings, however struggle to overcome the challenge of adequately securing apps, while ensuring ease of access is not compromised. With the added consideration of data privacy, businesses need to start focusing on security rather than just performance, but whose responsibility is it?
In this podcast Steve Durbin, Managing Director at the Information Security Forum discusses the challenges associated with acquiring, using and operating mobile apps, and provides actions to manage those challenges, while maintaining the business benefits.
https://www.securityforum.org/videos-podcasts/isf-podcast-mobingdom-for-an-app/
In this podcast, Steve Durbin, Managing Director at the Information Security Forum, shares the 5 key actions organisations can take today to demonstrate compliance, and how they can continue to build compliance into the organisations DNA beyond the deadline date. Steve also discusses the key issue of third party suppliers and their access to personal information, sharing an approach to help rationalise the number of suppliers and protect the data shared with them to support your compliance programme.
https://www.securityforum.org/videos-podcasts/isf-podcast-gdpr-too-late/
Recognising the need to build a sustainable security workforce is of real concern to organisations across all sectors, as any shortfalls in skills and capabilities could leave an organisation vulnerable to an attack on its most critical assets, impacting an organisations performance and brand reputation. But as demand outstrips supply, a sustainable security workforce is becoming more and more difficult to achieve, increasing pressure on the CISO’s role.
In this podcast Steve Durbin, Managing Director at the ISF, discusses the skills and attributes CISOs should be looking for when building a sustainable workforce, how to retain them, and the part technology will play in the future when trying to overcome the workforce shortfall.
https://www.securityforum.org/videos-podcasts/isf-podcast-buile-for-the-future/
When your most critical information assets represent 80% of your organisations total value, it’s important to know exactly what they are, where they are, and how to protect them? Until regulations such as GDPR came into focus, most organisations, while familiar with the term had no real understanding of how to define their ‘critical information assets’ and why they should be protecting them. Organisations now know that protecting these assets is crucial if they want to compete and succeed in a global market.
In this podcast, Steve Durbin, Managing Director at the Information Security Forum discusses what critical information assets mean to different organisations, how you can protect them, and what the consequences could be for an organisation if these assets were to be breached.
https://www.securityforum.org/videos-podcasts/isf-podcast-protect-critical-assets/
Insider threats account for 54% off all breaches, and are found at all levels of an organisation, from top to bottom. Numerous factors are increasing organisations’ exposure to the threats posed by insiders, and technical controls are limited. To combat these threats, organisations must invest in a deeper understanding of trust, and work to improve the trustworthiness of all insiders.
The insider threat has only intensified as people have become increasingly mobile and hyper-connected, and with technology continuously advancing, the risks posed by insiders are only set to increase.
In this podcast, Steve Durbin, Managing Director, ISF discusses the most common types of insider threats, as well as how organisations need to take a holistic approach to tackle insider threats that include both technology and people when embedding security into their organisation’s DNA.
https://www.securityforum.org/videos-podcasts/isf-podcast-who-to-your-business/
The frequency of ransomware attacks on businesses has significantly grown over the past two years, with the number of detections increasing by nearly 2000%. As the space becomes more attractive and lucrative to cyber criminals, the threat of ransomware is only set to rise in 2018 as attackers get more creative, sophisticated and persistent, and attacks from named ransomware such as WannaCry and BadRabbit become ever more prevalent.
With so many end points accessible to malware, organisations must be more vigilant than ever to protect themselves against this growing threat.
In this podcast, Steve Durbin, Managing Director, ISF addresses what organisations can do to prepare and protect against ransomware, and how focusing on the basics, as well as embedding security awareness within the organisation can help prevent such attacks.
https://www.securityforum.org/videos-podcasts/isf-podcast-rans-cyber-criminals/
The role of a CISO has evolved over the years’ and now requires someone who combines InfoSec capabilities with business requirements. They must be able to align cyber to business strategy, speaking both languages while developing reporting metrics that satisfies the board and promotes good cyber resilience across the business. All these attributes support the belief that the CISO of the future doesn’t have to come from an IT background.
In this podcast, Steve Durbin, Managing Director ISF, addresses the objectives a CISO should aim to achieve in the first 100 days in the role, and offers insights into how a CISO should work with the board and security teams to achieve these.
https://www.securityforum.org/videos-podcasts/the-ciso-reset/
With the main industries in India comprising IT Services providers, banks and conglomerates such as Tata Group, Birla Group, Mahindra, and Reliance who all manage EU personal data – Indian organisations are determining how they can comply with the EU GDPR by May 2018. India aims to achieve 25 billion digital transactions in 2017 to 2018, so complying with the GDPR is going to have to be top of the business agenda.
In this podcast, Steve Durbin addresses some of the challenges that India will face and offers insights into best practice solutions to address the requirements of the EU GDPR. Steve also discusses how Indian organisations should not view the EU GDPR as a compliance burden, but as an opportunity for culture change across the business that will lead to tangible business benefits. Find out more at www.securityforum.org.
https://www.securityforum.org/videos-podcasts/isf-podcast-eu-gn-customers-data/
When we talk about the board and cyber security, we have moved away from the board doesn’t get it, to the board gets it, to the board doesn’t feel they are sufficiently briefed when a breach takes place. But is all of this evasive talk to avoid responsibility, or is there still a lack of communication between cybersecurity professionals and the board?
In this podcast, Steve Durbin, Managing Director ISF, offers insights into the specific actions the board needs to take to embed cybersecurity into business strategy. With the May 2018 deadline for the EU GDPR fast approaching, the board should be viewing upcoming legislation as an opportunity for cultural change, rather than a compliance burden.
https://www.securityforum.org/videos-podcasts/isf-podcast-cybeions-that-matter/
The smartphone has become an extension of our work and our personal life – everyone expects to be able to access something with a click of the button. But what are some of the serious consequences that a culture of convenience has given rise to? With 21 billion connected devices estimated to be around the world by 2020 this is surely a question all technology users should be asking.
In this podcast, Steve Durbin, Managing Director, ISF, discusses the business and personal security consequences of IoT and how technology providers need to ensure security is built in rather than tapped on to IoT devices. For more information visit www.securityforum.org.
https://www.securityforum.org/videos-podcasts/isf-podcast-iot-on-my-smartphone/
As organisations of all sizes try to be more agile in responding to emerging threats, finding people with the right skill set is something of a challenge. With cyber now integrated into the DNA of business, the big question remains: how do we attract, train and retain the cyber specialists of the future?
In this podcast, Steve Durbin, Managing Director ISF, offers insights into how educational bodies and organisations, such as the ISF, can educate the next generation of cyber security professionals. Steve highlights the constantly evolving and dynamic nature of the role that makes cyber security such an attractive career path, whilst also discussing the importance of helping business people transition into the security space.
https://www.securityforum.org/videos-podcasts/isf-podcast-tacknnovation-is-key/
As organisations become increasingly dependent on data, unscrupulous competitors and cyber criminals are using falsified information as a form of attack. Falsification has been used to inflict both product and brand damage on organisations that have been too slow to protect their information. So, what steps can organisations take to protect the integrity of their data and minimise the impact upon their brand?
In this podcast, Steve Durbin, Managing Director ISF, provides solutions for businesses. Steve discusses what has contributed to the growth of falsified information, how businesses should protect the integrity of their data and how they should work collaboratively with third parties to tackle the threat.
https://www.securityforum.org/videos-podcasts/falsification-hontegrity-of-data/
Many organisations with a footprint in Europe are still unclear if the GDPR applies to them, or if they have the right team and resources to address it. The GDPR will require a collaborative effort between businesses and third parties to ensure that all areas of the information life cycle are protected – a daunting project for security teams. In this podcast, Steve Durbin, Managing Director ISF, offers top tips and insights into the steps organisations must take to comply with the GDPR – to produce a security model of ‘privacy by design’. Fundamentally, organisations will need to know what data they are storing, how they are storing it and how they are protecting it – to show regulatory bodies that they have taken every possible step to preserve the integrity of customer data.
For more information visit: www.securityforum.org
Artificial Intelligence is a growing trend across industry sectors from medical and legal to automotive and manufacturing. However, the new capabilities of AI technologies, can lead to unexpected outcomes and new risks on the threat horizon, such as: AI machines misunderstanding information, new means for criminals to extract an organisation’s mission critical information and AI technologies learning from wrong or incomplete data to make poorly informed decisions. Such cybersecurity risks raise the questions, what does the growth of AI mean for businesses and how can business leaders ensure that the benefits of AI outweigh the risks?
In this podcast, Steve Durbin, Managing Director ISF, offers insights for C-suite and business leaders into how to collaborate across the organisation to create best practice methods for deploying AI systems. Steve provides an overview of the risks associated and maps out the security by design argument to enable companies to successfully handle emerging technology and develop a robust cyber resilience strategy.
https://www.securityforum.org/videos-podcasts/4696-2/
Increasingly, organisations are waking up to the negative business impact of poor cybersecurity programmes and are taking cyber incidents more seriously in their mergers and acquisitions deals (e.g YAHOO! and Verizon). However, trying to get a grasp of the cyber profile of an organisation is extremely difficult – as integrity of information is often difficult to monitor. For companies to grow and become desirable for acquisition deals, they need to be able to demonstrate their cyber resilience strategies. Businesses must be able to prove to their stakeholders, clients, potential buyers and shareholders that they have taken every reasonable step to ensure that their mission critical information is protected.
Steve Durbin, Managing Director ISF, discusses the nature of the mergers and acquisitions process in a digital age and offers insights into how organisations can build a strong cyber resilience programme to move with confidence as they pursue new acquisitions.
https://www.securityforum.org/videos-podcasts/building-cyberseisitions-process/
In a digital age, the internet is viewed by businesses and individuals alike as a basic utility. Businesses are dependent upon it and this, in itself, is a threat that cyber criminals can take advantage of. We saw earlier in May 2017 how the NHS attack on its critical infrastructure led to a shutdown of the NHS Windows systems, causing medical professionals to have to resort to pens and paper when noting patient data. Moreover, a few years ago Russian hackers cut the internet off in Estonia in a national attack on their critical infrastructure, resulting in business grinding to a halt. The internet is a part of every businesses infrastructure, so what is the impact if this is compromised and what should a business response plan look like?
Steve Durbin, Managing Director ISF, offers solutions for C-suite leaders, should their critical infrastructure come under attack and advises how a reliance on older technology can assist an organisation through an internet attack. Fundamentally, whilst the future is becoming more and more digitised, organisations need to be planning for the day when their technology is not working.
https://www.securityforum.org/videos-podcasts/threats-to-critinet-as-a-utility/
In March 2017, the New York Department for Financial Services (DFS) implemented a Cyber Security regulation, requiring financial institutions to establish a cyber security programme to protect consumer data. But how will this affect New York businesses and what measures should they put in place to meet these requirements?
In this podcast, Steve Durbin, Managing Director of the ISF, addresses these questions and offers insights into how the ISF can help New York financial institutions put in place the mechanisms to comply with the NY DFS.
https://www.securityforum.org/videos-podcasts/isf-podcast-the-the-isf-can-help/
People remain a ‘wild card’ to the cyber security of an organisation. Many businesses recognise people as their biggest asset, yet still fail to recognise the need to secure ‘the human element’ of information security. Steve Durbin, Managing Director at the ISF, tackles the question: how can organisations make people their strongest line of defence against cyber-attack?
https://www.securityforum.org/videos-podcasts/isf-podcast-the-izon-2017-series/
The GDPR will require extreme preparation in order for organisations to meet new compliance rules. Businesses cannot rely on the government and regulatory bodies to do the work for them. In this podcast, Steve Durbin, Managing Director at the ISF, talks through the checklist of regulations, financial and operational challenges and data management that organisations must take responsibility for and address this year.
https://www.securityforum.org/videos-podcasts/isf-podcast-govent-do-it-for-you/
Cyber-crime syndicates have rapidly matured and have now become businesses. With rogue states taking advantage of these services, the resulting cyber incidents this year will be more damaging than ever before. Steve Durbin, Managing Director at the ISF, offers insights into how organisations can stay one step ahead of the increasing sophistication of cyber-criminal organisations.
https://www.securityforum.org/videos-podcasts/isf-podcast-cybeizon-2017-series/
It is expected that 28.4 billion devices will be connected in 2017. IoT devices offer a way in for cyber-attacks. So what are the risks and how will this impact privacy? In this podcast, Steve Durbin, Managing Director at the ISF, addresses how the healthcare, financial and many other industries can manage the threat of the IoT.
https://www.securityforum.org/videos-podcasts/the-internet-of-unmanaged-risks/
Organisations that suffer an incident face challenging and damaging circumstances:
• data stolen
• financial penalties
• legislative and regulatory scrutiny
• reputation damage
Steve Durbin, Managing Director at the ISF, offers guidance and practical steps, to manage through a breach in a confident and intelligent manner and plan for the day you hope never arrives.
https://www.securityforum.org/videos-podcasts/isf-podcast-manaith-steve-durbin/
ISF research shows that some of the largest organisations have misaligned cyber security practices. This podcast, in conversation with Steve Durbin, Managing Director at the ISF, addresses why it is so important for businesses to align cyber security across their enterprise and what steps they can take to make this happen.
https://www.securityforum.org/videos-podcasts/isf-podcast-aligith-steve-durbin/
It is not a matter of if – but when you will experience a cyber-attack. Steve Durbin, Managing Director at the ISF, offers insights into how ISF Members have used the ISF cyber resilience framework to prepare for inevitable cyber-attack.
https://www.securityforum.org/videos-podcasts/2-cyber-resilienreat-environment/
With CISO’s busy preparing for an inevitable cyber-attack, triggers of engagement to communicate with the board have never been more important. In this podcast Steve Durbin, Managing Director at the ISF, confronts the challenges between the CISO and the board and explains how CISO’s can exhibit C-suite leadership and engage with the board and stakeholders effectively. Search for more guidance on engaging with the board here: www.securityforum.org
https://www.securityforum.org/videos-podcasts/isf-podcast-cisoith-steve-durbin/