Discover
ISF Podcast
ISF Podcast
Author: Information Security Forum Podcast
Subscribed: 151Played: 4,816Subscribe
Share
© 263000
Description
The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.
357 Episodes
Reverse
The tables turn in this episode, as Steve becomes the guest on “Legal Owl,” a podcast by John “Jock" Brocas, the executive coach whom you might remember from one of our shows earlier this year. In this first part of two, Steve tells Jock about how he got into cyber in the first place, and the two discuss the evolution of the cyber landscape. They also dive into why law firms must begin to think more about cyber risk and resilience. Key Takeaways:
Cyber has moved from an IT issue to a business issue.
Senior staff must be aware of the risks of deepfake impersonations.
Your information is probably out there already, so focus on what to do when that information is used the wrong way.
Tune in to hear more about:
How law firms are impacted by today’s cyber risks (8:24)
Deepfakes and reputational damage (12:42)
Why you might want to make your business look unattractive (15:19)
Standout Quotes:
“COVID was a real turning point, I think, for the industry, because suddenly, pretty much overnight, we had to move to an environment where we're protecting data that's not within the strict confines of the organization. So it'll be in people's homes, it was gonna be used by people where you had no control over it at all. And so we had to adapt as an industry to that, and I think that was actually very good for us.” - Steve Durbin
“We're in an environment where you really do need to be exceptionally careful about how you manage your personal profile, how you manage personal data, how you really behave, I would say, online. And that, for some people, is quite a difficult one to get your head around.” - Steve Durbin
“I think that the days of "I'm too small to get noticed" have pretty much gone now. If you're working in any way, shape, or form with data online, you're a potential target, and you have to adopt that mindset.” - Steve Durbin
Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, ISF Chief Executive Steve Durbin talks with Dame Inga Beale, the former CEO of Lloyd’s of London, about the role that listening played when she became the first (and only) female CEO in Lloyd’s more than 300-year history. They also discuss the courage and effectiveness of simplicity in communication, a new style of leadership built on trust, and career advice for both board members and security professionals who are relatively new to the industry.More about Lloyd’s of London.Mentioned in this episode: • Dive In Festival • Read the transcript of this episode. • Subscribe to the ISF Podcast wherever you listen to podcasts. • Connect with us on LinkedIn and Twitter. • From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is joined by former FBI agent Eric O’Neill. Eric is a cyber security expert and author, but he’s probably most well-known as the man who brought down Peter Hanssen, a Russian spy who became one of the most notorious double agents in the history of US intelligence. Steve and Eric discuss cyber preparedness in today’s business world, insider threats, and cyber resilience in a rapidly changing world. Key Takeaways:
Cybercrime is a trillion-dollar business and businesses would be wise to make defending against it a top priority.
A business’ information should be segmented, with no one person having access to everything.
Deepfakes will increasingly be used to influence employees, businesses, and voters.
Tune in to hear more about:
Building a culture of cyber vigilance (5:46)
The insider threat (8:44)
Eric’s PAID strategy (20:47)
Standout Quotes:
“What most corporations and companies must worry about critically, it should be at the top of their risk portfolio, is cybercrime, which is the fastest-growing business on Earth.” - Eric O’Neill
“Every single person in IT that is a systems administrator, who can elevate privileges, who can create accounts, who can reset passwords, those tend to be the most targeted individuals in an organization, and the accounts, the individuals, the roles that attackers most want to compromise.” - Eric O’Neill
"Attackers don't care who you are, they don't care what you do, they don't care whether you're big or small. They only care whether you're vulnerable. And if you are vulnerable, you will be attacked by a cyber criminal group, and if you don't prepare ahead of the attack, then you'll be a victim.” Eric O’Neill
Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve looks toward the horizon, at the threats and challenges that enterprises and business leaders will face in 2026 and beyond. He also gives advice on how everyone, from the board to the practitioner, can meet these challenges, and answers some of the questions he’s received this year. Key Takeaways:
Steve’s four key drivers of cyber risk heading into 2026 are AI, supply chain, quantum, and geopolitical instability.
Crucial to cyber resilience are strong governance and a security-conscious culture.
Adaptive governance and adaptive security are keys to managing the challenges of 2026 and beyond.
Tune in to hear more about:
Steve’s four key drivers of cyber risk heading into 2026 (2:23)
Questions to ask, whether you’re a board member, an executive, or practitioner (16:14)
The changing role of the board (18:54)
Standout Quotes:
“ Resilience really needs an organizational wide holistic approach that takes technology, it takes governance, it takes operational readiness, and really importantly, it takes people into account.” - Steve Durbin
“I think boards need to really take it upon themselves to absolutely recognize that cyber risk is a national risk. It is a business ending risk, and they need to ensure that they don't just have incident response and resilience in place, but that they also have a tried and tested plan, so this is good old fashioned BCP — business continuity planning — with a cyber flavor.” - Steve Durbin
“Cyber risk reporting has to be business outcome oriented. Boards, business executives understand revenue, operations, customer impact, legal exposure. That's the way we have to be reporting cyber risk. It's not about how many attacks we repelled, it's not about how good our systems might be. You need to translate it into business language. If you can do that, not only will you get buy-in, but you'll also have a much richer conversation about the role that cyber and therefore cybersecurity and cyber resilience play in the business.” - Steve Durbin
Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve speaks with Lauren Farina, psychotherapist and founder of Invited Psychotherapy & Coaching. Lauren and Steve discuss how wellness is becoming a bigger part of the workplace and how we can stay mentally healthy during times of stress and pressure. Also an expert on “high-performance individuals,” Lauren shares what it means to be high-performing and why rest can be just as productive as work. Key Takeaways:
Being a high-performer isn’t just about work.
Rest is productive
Building psychological safety within an organization is the most important contributor to elite performance.
Tune in to hear more about:
What the “High Performer Archetype” is (6:15)
The risks of not taking time to rest (11:22)
How leaders can improve the performance of their teams (19:33)
Standout Quotes:
“ As many of us know, acute stress is quite good for us. But in the long term, the chronic unrelenting demands that I think remote working arrangements have placed on the workforce, really can erode our performance because our cognitive functioning is not at its peak when we're chronically stressed, our memory, our learning, our judgment, our decision making is compromised.” - Lauren Farina
“ There was a five -year study at Google called the Aristotle Project, and the Aristotle project found that psychological safety is the single most important factor when it comes to the elite performance of individuals and groups.“ - Lauren Farina
“ It is my hope that there will be an increased focus on intersectionality of performance and wellbeing and increased support of individuals and groups in cultivating wellbeing. Not only for the sake of wellbeing, but also for the sake of peak performance.” - Lauren Farina
Read the transcript of this episode Subscribe to the ISF Podcast wherever you listen to podcasts Connect with us on LinkedIn and Twitter From the Information Security Forum, the leading authority on cyber, information security, and risk management.








