ISF Podcast

Information Security Forum Podcast

The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.

  1. 1d ago

    SUMMER LISTENING: Rest After Stress: The Psychology of High Performance

    Today, Steve speaks with Lauren Farina, psychotherapist and founder of Invited Psychotherapy & Coaching. Lauren and Steve discuss how wellness is becoming a bigger part of the workplace and how we can stay mentally healthy during times of stress and pressure. Also an expert on “high-performance individuals,” Lauren shares what it means to be high-performing and why rest can be just as productive as work.  Key Takeaways: Being a high-performer isn’t just about work.  Rest is productive Building psychological safety within an organization is the most important contributor to elite performance.  Tune in to hear more about: What the “High Performer Archetype” is (6:15) The risks of not taking time to rest (11:22) How leaders can improve the performance of their teams (19:33) Standout Quotes: “ As many of us know, acute stress is quite good for us. But in the long term, the chronic unrelenting demands that I think remote working arrangements have placed on the workforce, really can erode our performance because our cognitive functioning is not at its peak when we're chronically stressed, our memory, our learning, our judgment, our decision making is compromised.” - Lauren Farina “ There was a five -year study at Google called the Aristotle Project, and the Aristotle project found that psychological safety is the single most important factor when it comes to the elite performance of individuals and groups.“ - Lauren Farina “ It is my hope that there will be an increased focus on intersectionality of performance and wellbeing and increased support of individuals and groups in cultivating wellbeing. Not only for the sake of wellbeing, but also for the sake of peak performance.” - Lauren Farina Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Rest After Stress: The Psychology of High Performance
  2. Aug 11

    SUMMER LISTENING: Geoff White – Ransomware Is a Business and It's Competing Against You

    In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack –  in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes.  Key Takeaways: 1 Ransomware attacks remain similar in strategy, but have become more industrialized in recent years.  2 Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors.  3 An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks. Tune in to hear more about: 1 Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33) 2 The impact of AI on ransomware attacks (13:52) 3 How money laundering is changing (17:03) Standout Quotes: 1 “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White 2 “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White 3 “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Geoff White – Ransomware Is a Business and It's Competing Against You
  3. Aug 4

    SUMMER LISTENING: Steve Durbin – How Quantum and Geopolitics Are Redefining Resilience

    Today, Steve returns to Business Matters with Juliette Foster. In this conversation, Steve recaps 2025 in cyber and shares what he sees as the biggest risks heading into 2026. The two also discuss resilience and compliance, as well as the growing importance of togetherness among businesses. Key Takeaways: 1 Companies would be wise to conduct frequent cyber audits.  2 Supply-chain disruptions can have long-lasting, reputational effects.  3 How we protect the integrity of our data is at the core of cybersecurity.  Tune in to hear more about: 1 The relationship between government business in cyber (12:56) 2 How boards should plan for a cyber attack (15:40) 3 Collaborating within and across industries (22:24) Standout Quotes: 1 “I've said many times that good compliance doesn't equal good security, but good security does equal, nine times out of 10, very good compliance. So where do we go with all of that? I do think that we're probably getting to a point, sadly, where we need to be viewing some of the security processes that we need to undergo in the same way as we consider financial audits.” - Steve Durbin 2 “I think that the day is gone when you can rely on your defenses. So boards have to be planning for the day when the defenses fail. When an attack really starts to make an impact on your business. The starting point is to figure out how long you can be without your systems. It may sound like a strange thing to say, but that's the important starting point for me.” - Steve Durbin 3 “Security is not, in my opinion anyway, a competitive advantage. And because it's not a competitive advantage, there shouldn't be this massive barrier to sharing some of the ideas, some of the attacks that are out there for the good of the industry.” - Steve Durbin  Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Steve Durbin – How Quantum and Geopolitics Are Redefining Resilience
  4. Jul 28

    SUMMER LISTENING: Alex Bovee – Identity in the Age of Agentic AI

    In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around.  Key Takeaways: 1 Identity must be treated as a strategic risk.  2 When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice.  3 Choosing robust but user-friendly technology is important for attracting and retaining new talent.  Tune in to hear more about: 1 The deepfake challenge (6:14) 2 Automated identity governance (8:33) 3 Empowering a culture of trust through identity strategy (12:20) Standout Quotes: 1 “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee  2 “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee 3 “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    SUMMER LISTENING: Alex Bovee – Identity in the Age of Agentic AI
  5. Jul 21

    Steve Durbin – When Governments Shift: Reimagining UK Cyber Strategy and Business Resilience

    Today, Steve returns to Business Matters with Juliette Foster. The United Kingdom has a new Prime Minister: Andy Burnham, and Steve speaks with Juliette from a cyber and business perspective about what to expect from the nation's new leadership. They also discuss the importance of digital inclusion, what businesses should do to remain in control in times of uncertainty, cyber insurance, and more.  Key Takeaways: As more of world becomes digitally enabled, cyber becomes increasingly important from a national defense and resilience perspective.  More organizations are moving to scenario-based planning to manage uncertainty. Governments must understand the complexity of their large projects and make sure they’ve got the best people working on them. Tune in to hear more about: The importance of digital inclusion (4:17) Solving the cyber skills shortage (20:29) How cyber insurance is changing and why it matters (22:58) Standout Quotes: “For a lot of people, digital inclusion means handing people a smartphone and saying, “There you go.” It isn't just about access, it's about the knowledge that you need to actually make use of the technology that you have access to.” - Steve Durbin “You want to try to maintain a solid state in between somebody saying they're going to make the acquisition and take you over, and when that completes. [...] Because the resilience is core to the effectiveness going forward of that organization. All too often, there's a tendency to fiddle with it, play with it a little bit. No. We need to understand exactly what our core components are, the crown jewels, how are we protecting them, how are they going to be impacted over a certain period by any change that goes on, and what can we do to make sure that we're doing everything possible to preserve the integrity of those crown jewels so that we can continue to operate. The last thing you want is somebody coming in and actually changing that during a handover period.” - Steve Durbin “From a cyber-specific perspective, one of the things that has infuriated me constantly over the years is this obsession that we seem to have that people have to be trained in the technical skills in order to have a cyber career. That is absolute nonsense. Because the sorts of skills that you need could equally be well found with people with arts degrees. It's that curiosity. It's that ability to be able to be creative.” - Steve Durbin Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    Steve Durbin – When Governments Shift: Reimagining UK Cyber Strategy and Business Resilience
  6. Jul 7

    Geoff White – Ransomware Is a Business and It's Competing Against You

    In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack –  in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes.  Key Takeaways: Ransomware attacks remain similar in strategy, but have become more industrialized in recent years.  Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors.  An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks.  Tune in to hear more about: Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33) The impact of AI on ransomware attacks (13:52) How money laundering is changing (17:03) Standout Quotes: “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    Geoff White – Ransomware Is a Business and It's Competing Against You
  7. Jun 30

    Alex Bovee – Identity in the Age of Agentic AI

    In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around.  Key Takeaways: Identity must be treated as a strategic risk.  When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice.  Choosing robust but user-friendly technology is important for attracting and retaining new talent.  Tune in to hear more about: The deepfake challenge (6:14) Automated identity governance (8:33) Empowering a culture of trust through identity strategy (12:20) Standout Quotes: “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee  “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    Alex Bovee – Identity in the Age of Agentic AI
  8. Jun 23

    James Wilkson - The Human Factor: Leadership, Risk and the AI Era

    Today, Steve speaks with James Wilkson, managing partner at AEC Global Search Consultants, an executive search and advisory firm. James and Steve discuss why today’s leaders must be flexible and emotionally intelligent, who belongs in today’s boardrooms, and how leaders can protect their personal brands online. Steve also asks James to look into the crystal ball. Key Takeaways: The most important trait for leaders today is flexibility. Today’s leaders must understand the technology they’re implementing in their organizations.  Almost everything you do is visible online today, so be careful and mind your behavior. Tune in to hear more about: Managing different generations in the workplace (4:18) How boards can upskill (12:31) What will surprise leaders a year from now (18:29) Standout Quotes: “I think AI, without a doubt is going to continue to accelerate and alter how we think, but just like anything else, it's just going to be an extremely robust tool down the line.” - James Wilkson “And leaders today, the leaders that are well-trained at being able to relate across generations and across technology are the ones that are going to continue being the leaders, and they're going to hone the next leadership team. The ones that are resistant and the ones that are frustrated, they're just not going to sustain leadership roles that much longer.” - James Wilkson “It's just a massive tsunami of discussion about AI and how it's going to change everything, and it is, but I think we're only going to briefly be led by this loss of work purpose, this loss of what... I think companies right now, the reason there's such a holdback on what do we do? We really slowed down hiring, are the entry level jobs all going to be gone? Yes, probably briefly because we're having a reaction, a knee-jerk reaction, but I think we're going to quickly find out that this is going to bring about a lot of different opportunity. So I think we'll plateau for a while, and then we'll begin utilizing humans in different roles that are still the same role that's just adapted itself to what technology has brought for us.” - James Wilkson Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.

    James Wilkson - The Human Factor: Leadership, Risk and the AI Era

Ratings & Reviews

4.6
out of 5
15 Ratings

About

The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.