ISF Podcast

Information Security Forum Podcast

The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  1. Sep 22

    Legal Owl Podcast: Steve Durbin on Cyber Risk in the Legal Industry

    The tables turn in this episode, as Steve becomes the guest on “Legal Owl,” a podcast by John “Jock" Brocas, the executive coach whom you might remember from one of our shows earlier this year. In this first part of two, Steve tells Jock about how he got into cyber in the first place, and the two discuss the evolution of the cyber landscape. They also dive into why law firms must begin to think more about cyber risk and resilience.  Key Takeaways: Cyber has moved from an IT issue to a business issue. Senior staff must be aware of the risks of deepfake impersonations.  Your information is probably out there already, so focus on what to do when that information is used the wrong way.  Tune in to hear more about: How law firms are impacted by today’s cyber risks (8:24) Deepfakes and reputational damage (12:42) Why you might want to make your business look unattractive (15:19) Standout Quotes: “COVID was a real turning point, I think, for the industry, because suddenly, pretty much overnight, we had to move to an environment where we're protecting data that's not within the strict confines of the organization. So it'll be in people's homes, it was gonna be used by people where you had no control over it at all. And so we had to adapt as an industry to that, and I think that was actually very good for us.” - Steve Durbin “We're in an environment where you really do need to be exceptionally careful about how you manage your personal profile, how you manage personal data, how you really behave, I would say, online. And that, for some people, is quite a difficult one to get your head around.” - Steve Durbin “I think that the days of "I'm too small to get noticed" have pretty much gone now. If you're working in any way, shape, or form with data online, you're a potential target, and you have to adopt that mindset.” - Steve Durbin Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    Legal Owl Podcast: Steve Durbin on Cyber Risk in the Legal Industry
  2. Sep 1

    Eric O'Neill – Hackers Don't Break In, They Log In: Trust as the New Perimeter

    Today, Steve is joined by former FBI agent Eric O’Neill. Eric is a cyber security expert and author, but he’s probably most well-known as the man who brought down Peter Hanssen, a Russian spy who became one of the most notorious double agents in the history of US intelligence. Steve and Eric discuss cyber preparedness in today’s business world, insider threats, and cyber resilience in a rapidly changing world.  Key Takeaways: Cybercrime is a trillion-dollar business and businesses would be wise to make defending against it a top priority.  A business’ information should be segmented, with no one person having access to everything. Deepfakes will increasingly be used to influence employees, businesses, and voters. Tune in to hear more about: Building a culture of cyber vigilance (5:46) The insider threat (8:44) Eric’s PAID strategy (20:47) Standout Quotes: “What most corporations and companies must worry about critically, it should be at the top of their risk portfolio, is cybercrime, which is the fastest-growing business on Earth.” - Eric O’Neill “Every single person in IT that is a systems administrator, who can elevate privileges, who can create accounts, who can reset passwords, those tend to be the most targeted individuals in an organization, and the accounts, the individuals, the roles that attackers most want to compromise.” - Eric O’Neill "Attackers don't care who you are, they don't care what you do, they don't care whether you're big or small. They only care whether you're vulnerable. And if you are vulnerable, you will be attacked by a cyber criminal group, and if you don't prepare ahead of the attack, then you'll be a victim.” Eric O’Neill Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    Eric O'Neill – Hackers Don't Break In, They Log In: Trust as the New Perimeter
  3. Aug 25

    SUMMER LISTENING: Emerging Threats for 2026

    Today, Steve looks toward the horizon, at the threats and challenges that enterprises and business leaders will face in 2026 and beyond. He also gives advice on how everyone, from the board to the practitioner, can meet these challenges, and answers some of the questions he’s received this year.  Key Takeaways: Steve’s four key drivers of cyber risk heading into 2026 are AI, supply chain, quantum, and geopolitical instability. Crucial to cyber resilience are strong governance and a security-conscious culture. Adaptive governance and adaptive security are keys to managing the challenges of 2026 and beyond.  Tune in to hear more about: Steve’s four key drivers of cyber risk heading into 2026 (2:23) Questions to ask, whether you’re a board member, an executive, or practitioner (16:14) The changing role of the board (18:54) Standout Quotes: “ Resilience really needs an organizational wide holistic approach that takes technology, it takes governance, it takes operational readiness, and really importantly, it takes people into account.” - Steve Durbin “I think boards need to really take it upon themselves to absolutely recognize that cyber risk is a national risk. It is a business ending risk, and they need to ensure that they don't just have incident response and resilience in place, but that they also have a tried and tested plan, so this is good old fashioned BCP — business continuity planning — with a cyber flavor.” - Steve Durbin “Cyber risk reporting has to be business outcome oriented. Boards, business executives understand revenue, operations, customer impact, legal exposure. That's the way we have to be reporting cyber risk. It's not about how many attacks we repelled, it's not about how good our systems might be. You need to translate it into business language. If you can do that, not only will you get buy-in, but you'll also have a much richer conversation about the role that cyber and therefore cybersecurity and cyber resilience play in the business.” - Steve Durbin Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Emerging Threats for 2026
  4. Aug 18

    SUMMER LISTENING: Rest After Stress: The Psychology of High Performance

    Today, Steve speaks with Lauren Farina, psychotherapist and founder of Invited Psychotherapy & Coaching. Lauren and Steve discuss how wellness is becoming a bigger part of the workplace and how we can stay mentally healthy during times of stress and pressure. Also an expert on “high-performance individuals,” Lauren shares what it means to be high-performing and why rest can be just as productive as work.  Key Takeaways: Being a high-performer isn’t just about work.  Rest is productive Building psychological safety within an organization is the most important contributor to elite performance.  Tune in to hear more about: What the “High Performer Archetype” is (6:15) The risks of not taking time to rest (11:22) How leaders can improve the performance of their teams (19:33) Standout Quotes: “ As many of us know, acute stress is quite good for us. But in the long term, the chronic unrelenting demands that I think remote working arrangements have placed on the workforce, really can erode our performance because our cognitive functioning is not at its peak when we're chronically stressed, our memory, our learning, our judgment, our decision making is compromised.” - Lauren Farina “ There was a five -year study at Google called the Aristotle Project, and the Aristotle project found that psychological safety is the single most important factor when it comes to the elite performance of individuals and groups.“ - Lauren Farina “ It is my hope that there will be an increased focus on intersectionality of performance and wellbeing and increased support of individuals and groups in cultivating wellbeing. Not only for the sake of wellbeing, but also for the sake of peak performance.” - Lauren Farina Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Rest After Stress: The Psychology of High Performance
  5. Aug 11

    SUMMER LISTENING: Geoff White – Ransomware Is a Business and It's Competing Against You

    In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack –  in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes.  Key Takeaways: 1 Ransomware attacks remain similar in strategy, but have become more industrialized in recent years.  2 Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors.  3 An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks. Tune in to hear more about: 1 Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33) 2 The impact of AI on ransomware attacks (13:52) 3 How money laundering is changing (17:03) Standout Quotes: 1 “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White 2 “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White 3 “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Geoff White – Ransomware Is a Business and It's Competing Against You
  6. Aug 4

    SUMMER LISTENING: Steve Durbin – How Quantum and Geopolitics Are Redefining Resilience

    Today, Steve returns to Business Matters with Juliette Foster. In this conversation, Steve recaps 2025 in cyber and shares what he sees as the biggest risks heading into 2026. The two also discuss resilience and compliance, as well as the growing importance of togetherness among businesses. Key Takeaways: 1 Companies would be wise to conduct frequent cyber audits.  2 Supply-chain disruptions can have long-lasting, reputational effects.  3 How we protect the integrity of our data is at the core of cybersecurity.  Tune in to hear more about: 1 The relationship between government business in cyber (12:56) 2 How boards should plan for a cyber attack (15:40) 3 Collaborating within and across industries (22:24) Standout Quotes: 1 “I've said many times that good compliance doesn't equal good security, but good security does equal, nine times out of 10, very good compliance. So where do we go with all of that? I do think that we're probably getting to a point, sadly, where we need to be viewing some of the security processes that we need to undergo in the same way as we consider financial audits.” - Steve Durbin 2 “I think that the day is gone when you can rely on your defenses. So boards have to be planning for the day when the defenses fail. When an attack really starts to make an impact on your business. The starting point is to figure out how long you can be without your systems. It may sound like a strange thing to say, but that's the important starting point for me.” - Steve Durbin 3 “Security is not, in my opinion anyway, a competitive advantage. And because it's not a competitive advantage, there shouldn't be this massive barrier to sharing some of the ideas, some of the attacks that are out there for the good of the industry.” - Steve Durbin  Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Steve Durbin – How Quantum and Geopolitics Are Redefining Resilience
  7. Jul 28

    SUMMER LISTENING: Alex Bovee – Identity in the Age of Agentic AI

    In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around.  Key Takeaways: 1 Identity must be treated as a strategic risk.  2 When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice.  3 Choosing robust but user-friendly technology is important for attracting and retaining new talent.  Tune in to hear more about: 1 The deepfake challenge (6:14) 2 Automated identity governance (8:33) 3 Empowering a culture of trust through identity strategy (12:20) Standout Quotes: 1 “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee  2 “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee 3 “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Alex Bovee – Identity in the Age of Agentic AI

Ratings & Reviews

4.6
out of 5
15 Ratings

About

The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.

You Might Also Like