The Entropy Podcast

Francis Gorman

Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for unfiltered conversations on the threats, complexity, and geopolitics shaping our world. Past guests include former senior CIA officers, leading cryptographers, digital forensics experts, and security and technology leaders from across financial services, critical infrastructure, and government, voices rarely heard together in one place. Each episode goes beyond headlines to explore how cyber risk, emerging technology, and geopolitical instability are reshaping the way organisations operate, compete, and defend themselves. Expect candid insight on quantum risk, nation-state threats, AI, espionage, financial crime, business resilience, and the human dimensions of leadership. Designed for CISOs, board members, founders, technologists, policy thinkers, and the professionally curious, Entropy sits at the intersection of business, technology, and cybersecurity a space for genuine conversations with unique minds, the kind that don’t fit neatly into a press release. The name Entropy reflects the growing complexity and unpredictability of the systems we depend on, and the discipline required to lead through them. Disclaimer: The views and opinions expressed on The Entropy Podcast are those of the host and guests in their personal capacity and do not represent the views, positions, or policies of their respective employers, affiliated organisations, or any government body. Guest appearances do not constitute endorsement by the host, and the host’s commentary does not constitute endorsement of guests’ views. Content is provided for informational and educational purposes only and does not constitute professional, legal, financial, or security advice. One of the topics I cover a lot on this show is post quantum readiness, I believe awareness of this emerging technology is key for a safer world into the future. To support this awareness I have built a free resource to help you explore the world of quantum and learn as you go. You can find it here: www.postquantumready.com Buy Our Swag: We now have some slick new swag you can purchase through our Esty store. https://theentropypodcast.etsy.com   Watch and Subscribe You can also watch full episodes and exclusive content on our YouTube channel:www.youtube.com/@TheEntropyPodcast Achievements The Entropy Podcast delivered strong chart performance throughout 2025, demonstrating consistent international reach and listener engagement. Regularly ranked within the Top 20 Technology podcasts in Ireland.Achieved a Top 25 placement in the United States Technology charts, holding the position for one week.Charted internationally across multiple markets, including Israel, Belgium, and the United Kingdom. This performance reflects sustained global interest and growing recognition across key podcast markets. Audio Quality Notice Some episodes may feature minor variations in audio quality due to remote recording environments and external factors. We continuously strive to deliver the highest possible audio standards and appreciate your understanding.

  1. Aug 18

    Train Like You Fight with Snehal Antani

    In this episode of The Entropy Podcast, Francis Gorman sits down with Snehal Antani, CEO and co-founder of Horizon3.ai for a wide-ranging conversation on cybersecurity, AI, warfare, leadership and the future of work. Snehal shares lessons from building and scaling Horizon3.ai, why startups must eventually move from “pirates” to a “navy,” and how his time inside Special Operations fundamentally changed his approach to leadership. They also explore the rapidly changing cyber threat landscape: AI-powered attackers, autonomous penetration testing, deception as a defence against AI agents, the lessons emerging from Ukraine, and why organisations need to stop asking whether they are secure and start proving they are resilient and defensible. Key Takeaways Why great founders need grit, conviction and a “learn-it-all” mentalityHow companies transition from entrepreneurial pirates to a scalable navyWhy AI could give cyber attackers effectively unlimited ammunitionHow defenders can use honeypots and deception to hack the hackersWhy cybersecurity teams should train like they fightThe growing importance of human-machine teaming in warfareWhy over-reliance on AI could undermine human judgement and scepticismHow AI may reshape the workforce and put increasing pressure on the “middle”Why there is no AI easy button coming for cybersecurityWhy organisations must move from being “secure” to being resilient and defensibleKey Soundbites “You earn the right to be on this team every single day.” “AI gives the adversary unlimited bullets.” “You don’t want to learn how to deal with a crisis in the middle of a crisis.” “We always train like we fight.” “There is no AI savior that’s going to suddenly make your lives better.” “Those obsessed with mastering their craft are going to come out on top.” “Stop saying that we’re secure… start talking about how we’re defensible.”

    Train Like You Fight with Snehal Antani
  2. Aug 16

    From Quantum Risk to Competitive Advantage with Shayne De La Force

    Quantum technology promises enormous economic value, but are businesses preparing quickly enough to capture it or protect themselves from its risks? In this episode, Francis Gorman speaks with strategy leader and LFI founder Shayne De la Force about the commercial realities of quantum technology in advanced manufacturing. Drawing on decades of experience across the semiconductor, aerospace, defence and automotive sectors, Shayne explains why quantum must become a board-level economic and governance priority. They explore the cost of waiting, the challenge of securing global supply chains, the role of an embedded Chief Quantum Officer, and why businesses need to look beyond vague terms such as “quantum advantage” and “quantum readiness.” Shayne also reflects on beginning his career on a factory floor in Japan, the dangers of “synthetic seniority,” and the lessons behind his book, Strategic Entanglement, which helps deep-tech founders cross the valley of death between innovation and commercial success. Key Takeaways Quantum is an economic issue, not merely a technology issue. Business leaders should evaluate it through two lenses: increasing enterprise value and reducing risk.Waiting carries a measurable cost. Organisations that begin planning and piloting now can build stronger competitive moats, while delayed action may expose intellectual property, long-lived data and future market position.Quantum preparation needs board-level sponsorship. CISOs and technical teams require executive support, funding and governance authority to deliver meaningful readiness programmes.Advanced manufacturers face a supply-chain problem. Prime contractors may have thousands of suppliers operating at very different levels of cryptographic maturity. The weakest supplier can become the greatest source of exposure.Prioritisation is more valuable than trying to fix everything at once. Companies should identify high-exposure systems, sensitive intellectual property and long-lived data, then concentrate resources where risk reduction will have the greatest impact.Most mid-sized organisations do not need a full internal quantum department. An embedded Chief Quantum Officer model can provide access to strategy, security, physics, governance and programme-management expertise without years of internal hiring.Quantum use cases must be tied to commercial outcomes. Not every pilot will deliver immediate value. Organisations need clearly defined business problems, economic metrics and realistic pathways from experimentation to deployment.Deep-tech commercialisation must begin early. Start-ups should develop their market narrative, customer belief and commercial strategy alongside the technology—not after the product has been completed.Foundational experience still matters. Working directly with machines, infrastructure, customers and operational teams creates judgement that cannot be replaced by AI-generated ideas or “synthetic seniority.”Soundbites “Unless you are working for a not-for-profit, we are all here to drive business, growth and economic value.” “A CEO or CFO has two fundamental objectives: maximise economic value and reduce economic risk.” “The companies moving today are the ones that will have the strongest competitive moat.” “Unless you have buy-in at the top, it is very difficult to move the rest of the organisation.” “When boards see the economic risk of losing their intellectual property and long-term data, that is when the needle starts moving.” “Building an internal quantum department can take years and millions of dollars. Our embedded model gives companies access to the whole capability.” “The companies running pilots today are the ones building a competitive moat over the companies that are waiting.” “In advanced manufacturing, equipment may have a depreciation cycle of 25 or 30 years. That makes cryptographic transition a massive challenge.” “The prime contractors are preparing, but their supplier base is often their weakest link.” “Our job is to create clarity in chaos—because, right now, it is chaos.” “Can we close 80 percent of the exposure in the first 12 months and then work through the remaining 20 percent?” “The valley of death is where great technology goes to die because the commercialisation strategy was never developed.”

    From Quantum Risk to Competitive Advantage with Shayne De La Force
  3. Aug 9

    Nobody Reads the Plan During the Fire with Patrick Lechner

    In this episode of The Entropy Podcast, Francis Gorman speaks with Patrick Lechner, co-founder of Resimate.io and an experienced business and cyber resilience leader, about why many organisations mistake documentation for genuine readiness. Patrick challenges the obsession with business continuity plans, impact assessments and compliance evidence, arguing that resilience should be measured by outcomes: can the organisation continue operating when something critical is lost? The conversation explores the difference between security and resilience, why businesses should prepare for loss rather than attempt to predict every possible threat, and how leaders can identify their most important dependencies. Patrick also examines the role of AI, the importance of business ownership and why tabletop exercises must become honest operational conversations rather than annual corporate theatre. This is a practical discussion about building the confidence, capability and human relationships required to respond when the plan no longer matches reality.  Key takeaways Resilience is not a collection of documents. Plans and frameworks are useful, but they do not prove that an organisation can sustain operations during a crisis. Prepare for loss, not every imaginable threat. Most disruptions can be reduced to losing a site, people, systems, suppliers or data. The business owns resilience. Operational leaders should decide what must continue, what level of disruption is tolerable and where investment is justified. Cybersecurity and cyber resilience are different. Security attempts to prevent incidents; resilience determines what happens when prevention fails. Dependencies must be understood across the organisation. A single failure—such as electricity, identity infrastructure or a major supplier—can create very different consequences across multiple teams. AI can amplify weak processes. Automating a poor resilience process may produce more plans and evidence without improving operational capability. Tabletop exercises should be frequent and honest. Short, regular discussions are often more valuable than one heavily scripted annual exercise. People ultimately carry the response. Trust, authority, shared principles and operational knowledge matter more during a crisis than a spreadsheet stored somewhere on the network. Soundbytes: “We were tired of resilience being measured by plans, not outcomes.” “Plans may be useless, but planning is indispensable.” “Almost every threat can be reduced to a handful of loss scenarios: losing a site, people, systems, suppliers or data.” “The board-level question is simple: how confident are we that we can sustain operations if we lose a key dependency?” “It does not matter why the electricity is gone. If it is gone, the business still has to respond.” “Investing heavily in prevention does not mean you are resilient.” “If you have bad processes today, AI is a great tool for accelerating those bad processes.” “You do not become fit by going to the gym once a year for seven hours. Tabletop exercises work the same way.” “An exercise should be an honest conversation, not a performance conversation.” “When something hits, it is the people, the trust and the shared principles that allow the organisation to respond.”

    Nobody Reads the Plan During the Fire with Patrick Lechner
  4. Aug 2

    Welcome to the Age of Synthetic Reality with Jake Moore

    In this episode of The Entropy Podcast, Francis sits down with Jake Moore, Global Cybersecurity Advisor at ESET, to unpack one of the biggest technology shifts of our time: the collapse of trust in the digital world. From deepfakes and AI-powered scams to digital footprints, remote hiring fraud, and the rise of agentic cybercrime, Jake explains how rapidly evolving AI tools are changing the nature of deception and why individuals, businesses, and governments are struggling to keep up. The conversation explores what happens when seeing is no longer believing, how cybercriminals are already exploiting synthetic media, and why the future of cybersecurity may depend less on tools alone and more on human awareness, verification, and digital resilience. If you’ve ever wondered how close we are to a world where anyone can fake anyone, this episode is for you. Key Takeaways Deepfakes are no longer theoretical — they are already being used in scams, impersonation, and fraud. Trust online is eroding fast, as AI-generated content becomes more realistic and accessible. Remote hiring introduces new risks, including AI-assisted impersonation and fake candidates. Your digital footprint reveals more than you think, often exposing personal details that can be used against you. Cyber awareness is still the strongest defense, especially when technology alone can’t keep pace. Children need better cyber education, particularly around passwords, privacy, and digital identity. AI is scaling cybercrime, making attacks faster, cheaper, and more convincing. Agentic AI and quantum computing could create the next major wave of cybersecurity disruption. Soundbites Here are strong promotional soundbites you can use in Spotify captions, social posts, clips, or episode promos: “We’ve entered a world where seeing is no longer believing.”“Your face, your voice, and your identity are becoming easier to fake.”“The biggest cyber threat may not be malware — it may be trust itself.”“Deepfakes are no longer a future problem. They’re here now.”“Cybercriminals don’t need perfect technology — they just need believable enough.”“Your digital footprint can tell strangers more about you than you realize.”“In the age of AI, awareness is still your greatest defense.”“The next scam won’t look suspicious — it will look completely real.”“Remote work has opened the door to a new kind of identity fraud.”“We are moving into an era of synthetic reality, and most people are not ready for it.”

    Welcome to the Age of Synthetic Reality with Jake Moore
  5. Jul 25

    Will The Nodding Bird Be Running Your SOC? Maybe? with Rik Ferguson

    Cybersecurity is entering a new era one shaped by autonomous AI attacks, machine speed defense and the looming impact of quantum computing. In this episode, Francis Gorman speaks with Rik Ferguson, Vice President of Security Intelligence at Forescout, about why organisations must move from “assume breach” to “assume autonomy.” Rik explains the four conditions required for trusted autonomous defense: context, constraint, reversibility and transparency. They also explore the risks of over-relying on AI in security operations, the importance of meaningful human oversight and why “harvest now, decrypt later” attacks make post-quantum readiness an urgent business priority. Key Takeaways AI is changing the operating model of cyberattacks. The greatest shift is not simply that AI makes existing attacks faster. Autonomous systems may combine vulnerabilities and techniques in ways that do not reflect human logic or established attacker behaviour. Defence cannot remain at human speed. As attacks become increasingly automated, organisations will need defensive systems capable of detecting, containing and responding at machine speed. Trust in autonomous security must be earned. Rik identifies four essential conditions for trusted autonomy: Context: Decisions must reflect the asset, its dependencies, its business importance and the wider environment.Constraint: Autonomous actions must remain within clearly defined boundaries and guardrails.Reversibility: Defensive interventions must be capable of being rapidly undone when they cause unintended consequences.Transparency: Operators must understand why a decision was made, which data informed it and what the potential impact will be.Human oversight must be meaningful. Simply placing a person at the end of an automated process does not guarantee safety. Over-reliance on automation can reduce vigilance and leave people less capable of intervening when intervention matters most. Paper we discussed during the episode: https://www.forescout.com/resources/wp-assume-autonomy/

    Will The Nodding Bird Be Running Your SOC? Maybe? with Rik Ferguson
  6. Jul 14

    Leadership Without a Script with Stefan Pagels Christensen

    Stefan Pagels Christensen became a child star at 11, working on major film productions while most children his age were still figuring out who they were. Early fame brought attention, pressure and opportunity but it also distorted his sense of identity, value and belonging. In this candid conversation, Stefan opens up about addiction, sobriety, ADHD and the experience that forced him to rebuild his life without status or recognition. He explains how discovering improvisation gave him a new way to understand failure, trust, communication and human connection. Today, Stefan uses applied improv, emotional intelligence and psychological safety to help leaders create teams where people feel confident enough to contribute, challenge ideas, make mistakes and speak openly. This is a conversation about what happens when the script disappears—and why the strongest leaders are not those with all the answers, but those who make the people around them better. Key Takeaways • Early success can shape self-worth in ways that take years to recognise and unlearn. • ADHD can drive creativity, intensity and hyperfocus, but without the right support it can also contribute to burnout and destructive behaviour. • Psychological safety begins with how leaders respond when someone speaks up, challenges an idea or makes a mistake. • “Yes, and” does not mean agreeing with everything. It means listening fully before rejecting or building on an idea. • Teams perform better when people stop judging themselves, stop judging others and become willing to experiment. • Failure becomes valuable when it is treated as information rather than something to conceal. • Great leadership is not about being the star of the scene. It is about making other people look good. • Meaningful change begins when you stop blaming the environment and accept responsibility for your own behaviour. Soundbites “Leadership is improvisation. None of us knows exactly what comes next.” “Success lies somewhere between doing nothing and failing.” “Every time someone speaks up, they have already overcome their own fear.” “Your job is not to be the star. Your job is to make other people look good.” “Psychological safety is created by how you respond when someone gets it wrong.” “You cannot change until you are willing to admit that something needs to change.” “People do not learn courage by reading about it. They learn it by stepping forward.” “Failure is not something to hide. It is something to recover from.” “Say yes to the person before you judge the idea.” “The strongest teams are not afraid of mistakes—they know how to use them.” You can find Stefan at: https://improv.eu/ Find Stefan on LinkedIn: https://www.linkedin.com/in/stefanpagelsimprov/

    Leadership Without a Script with Stefan Pagels Christensen
  7. Jul 12

    Harvest Now, Litigate Later Quantum Exposure with Darren Bender

    In this episode of the Entropy Podcast, Francis Gorman sits down with Darren Bender, a Texas-based attorney, chief legal officer, and co-founder working at the intersection of law, IT, and post-quantum cryptography. The conversation explores a question many boards, legal teams, and security leaders are only beginning to face: when quantum computers threaten today’s encryption, who becomes liable for doing nothing? Darren breaks down post-quantum negligence in practical terms, explaining why “we didn’t know” may not be a credible defence for much longer. From Harvest Now, Decrypt Later attacks to board minutes, data shelf life, migration timelines, DORA compliance, procurement decisions, and third-party liability, this episode reframes quantum readiness as more than a technical challenge. It is a governance issue. A legal exposure issue. A fiduciary duty issue. And potentially, a future courtroom issue. Key Takeaways Post-quantum cryptography is no longer just a cybersecurity concern; it is becoming a boardroom and legal risk conversation.Organisations may need to show how they assessed quantum risk, prioritised critical data, and documented informed decisions.Board minutes, governance records, risk assessments, cryptographic inventories, and migration plans could become central evidence in future litigation.“Cryptographic procrastination” may become difficult to defend if organisations knew about the risk but chose not to act.The Mosca theorem helps boards think about whether their data shelf life plus migration time exceeds the timeline for a cryptographically relevant quantum computer.The Learned Hand formula offers a legal lens for comparing the burden of prevention against the probability and magnitude of future harm.Financial services, healthcare, energy, and critical infrastructure may be among the first sectors exposed to post-quantum liability.DORA and similar regulatory frameworks may create either a defensive treasure trove or a litigation minefield, depending on the quality of the paper trail.Supply-chain liability will be complex, with SaaS providers, cloud providers, HSM vendors, certificate authorities, and customers all potentially pulled into the same dispute.Procurement teams should start asking not just whether vendors are secure today, but whether they can support post-quantum migration tomorrow.Soundbytes “Quantum risk is moving from the server room to the boardroom.” “Harvest Now, Decrypt Later may become Harvest Now, Litigate Later.” “The question is not just whether encryption breaks. It is who knew, who acted, and who documented the decision.” “In a future lawsuit, the paper trail may matter as much as the technology.” “Cryptographic procrastination is not a strategy.” “Doing nothing may be the most expensive decision a board ever makes.” “Post-quantum readiness is not a light switch. It is a long fuse with a big boom at the end.” “If your data still has value when quantum arrives, your risk clock has already started.” “DORA can be a treasure trove or a minefield. It depends what your records show.” “Your vendors may hold the keys, but your organisation may still hold the liability.” “Quantum readiness is no longer just about algorithms. It is about governance, accountability, and foreseeable harm.” “The courtroom may become the place where quantum risk finally gets priced.”

    Harvest Now, Litigate Later Quantum Exposure with Darren Bender
  8. Jul 6

    Is Your Cyber Recovery Plan Just Fiction? with Francesco Chiarini

    In this episode of the Entropy Podcast, Francis Gorman speaks with Francesco Chiarini about why cyber resilience must go far beyond traditional cybersecurity, backups, and compliance checklists. Francesco breaks down the uncomfortable reality that many organisations are not as recoverable as they think. From ransomware spreading at scale to compromised identity systems, encrypted tooling, failed assumptions, and board-level misunderstandings, this conversation explores what really happens when the worst-case cyber scenario becomes real. The discussion covers cyber resilience versus cybersecurity, APT-grade attacks, out-of-band communications, crisis operating models, data vaulting, DORA, recovery planning, minimum viable organisations, and why resilience has to be designed before disaster strikes. This is a direct, practical conversation about building organisations that can continue operating when the normal playbook no longer works. Key Takeaways Cyber resilience is not the same as cybersecurity. Cybersecurity focuses heavily on prevention and protection; cyber resilience asks whether the organisation can still operate, recover, and adapt when prevention fails. Backups alone do not equal resilience. Francesco warns that recovery depends on architecture, governance, people, tooling, identity, sequencing, and validated operating models not just stored copies of data. Organisations need to stress-test their assumptions of recoverability. If Active Directory, communications, patching tools, or recovery platforms are compromised, the real question is: what still works? Boards often misunderstand resilience as a technology problem. Francesco argues that technology matters, but cyber resilience also requires clear accountability, capability maturity, skilled teams, and rehearsed decision-making. Cyber recovery investment is often too low. Many organisations spend heavily on prevention, detection, and protection, while underinvesting in recovery capabilities and last-resort operating models. Data vaulting and isolated recovery are essential, but incomplete on their own. They must sit inside a wider cyber resilience strategy that includes threat modelling, minimum viable operations, interoperability, deception, and recovery sequencing. Soundbytes “Your cyber recovery plan is only real if it still works when everything around it has failed.” “Backups are not resilience. They are only one piece of the survival plan.” “The worst time to design recovery is during the incident.” “Cyber resilience starts where cybersecurity assumptions break.” “If your identity stack, tooling, and communications are gone, what still works?” “Being compliant does not mean being resilient.” “Recovery is not just a technology problem. It is an organisational capability.” “Most companies know how to prevent. Far fewer know how to restart.”

    Is Your Cyber Recovery Plan Just Fiction? with Francesco Chiarini

About

Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for unfiltered conversations on the threats, complexity, and geopolitics shaping our world. Past guests include former senior CIA officers, leading cryptographers, digital forensics experts, and security and technology leaders from across financial services, critical infrastructure, and government, voices rarely heard together in one place. Each episode goes beyond headlines to explore how cyber risk, emerging technology, and geopolitical instability are reshaping the way organisations operate, compete, and defend themselves. Expect candid insight on quantum risk, nation-state threats, AI, espionage, financial crime, business resilience, and the human dimensions of leadership. Designed for CISOs, board members, founders, technologists, policy thinkers, and the professionally curious, Entropy sits at the intersection of business, technology, and cybersecurity a space for genuine conversations with unique minds, the kind that don’t fit neatly into a press release. The name Entropy reflects the growing complexity and unpredictability of the systems we depend on, and the discipline required to lead through them. Disclaimer: The views and opinions expressed on The Entropy Podcast are those of the host and guests in their personal capacity and do not represent the views, positions, or policies of their respective employers, affiliated organisations, or any government body. Guest appearances do not constitute endorsement by the host, and the host’s commentary does not constitute endorsement of guests’ views. Content is provided for informational and educational purposes only and does not constitute professional, legal, financial, or security advice. One of the topics I cover a lot on this show is post quantum readiness, I believe awareness of this emerging technology is key for a safer world into the future. To support this awareness I have built a free resource to help you explore the world of quantum and learn as you go. You can find it here: www.postquantumready.com Buy Our Swag: We now have some slick new swag you can purchase through our Esty store. https://theentropypodcast.etsy.com   Watch and Subscribe You can also watch full episodes and exclusive content on our YouTube channel:www.youtube.com/@TheEntropyPodcast Achievements The Entropy Podcast delivered strong chart performance throughout 2025, demonstrating consistent international reach and listener engagement. Regularly ranked within the Top 20 Technology podcasts in Ireland.Achieved a Top 25 placement in the United States Technology charts, holding the position for one week.Charted internationally across multiple markets, including Israel, Belgium, and the United Kingdom. This performance reflects sustained global interest and growing recognition across key podcast markets. Audio Quality Notice Some episodes may feature minor variations in audio quality due to remote recording environments and external factors. We continuously strive to deliver the highest possible audio standards and appreciate your understanding.

You Might Also Like