Find partners
ISF Podcast

ISF Podcast

Hosted by Information Security Forum Podcast

BusinessTechnologyNewsInterviews guestsExplicit

Episodes

352

Latest episode

Aug 2026

Language

EN

About the show

The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.

Listen to episodes

60 recent
August 11, 2026Episode 35228 min

352: Summer Listening: Geoff White – Ransomware Is a Business and It's Competing Against You

In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack –  in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes. Key Takeaways: 1 Ransomware attacks remain similar in strategy, but have become more industrialized in recent years.  2 Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors.  3 An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks. Tune in to hear more about: 1 Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33) 2 The impact of AI on ransomware attacks (13:52) 3 How money laundering is changing (17:03)Standout Quotes: 1 “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White 2 “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White 3 “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff WhiteRead the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

August 4, 2026Episode 35127 min

351: Summer Listening: Steve Durbin – How Quantum and Geopolitics Are Redefining Resilience

Today, Steve returns to Business Matters with Juliette Foster. In this conversation, Steve recaps 2025 in cyber and shares what he sees as the biggest risks heading into 2026. The two also discuss resilience and compliance, as well as the growing importance of togetherness among businesses.Key Takeaways: 1 Companies would be wise to conduct frequent cyber audits.  2 Supply-chain disruptions can have long-lasting, reputational effects.  3 How we protect the integrity of our data is at the core of cybersecurity. Tune in to hear more about: 1 The relationship between government business in cyber (12:56) 2 How boards should plan for a cyber attack (15:40) 3 Collaborating within and across industries (22:24)Standout Quotes: 1 “I've said many times that good compliance doesn't equal good security, but good security does equal, nine times out of 10, very good compliance. So where do we go with all of that? I do think that we're probably getting to a point, sadly, where we need to be viewing some of the security processes that we need to undergo in the same way as we consider financial audits.” - Steve Durbin 2 “I think that the day is gone when you can rely on your defenses. So boards have to be planning for the day when the defenses fail. When an attack really starts to make an impact on your business. The starting point is to figure out how long you can be without your systems. It may sound like a strange thing to say, but that's the important starting point for me.” - Steve Durbin 3 “Security is not, in my opinion anyway, a competitive advantage. And because it's not a competitive advantage, there shouldn't be this massive barrier to sharing some of the ideas, some of the attacks that are out there for the good of the industry.” - Steve Durbin Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

July 28, 2026Episode 35023 min

350: Summer Listening: Alex Bovee – Identity in the Age of Agentic AI

In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around. Key Takeaways: 1 Identity must be treated as a strategic risk.  2 When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice.  3 Choosing robust but user-friendly technology is important for attracting and retaining new talent. Tune in to hear more about: 1 The deepfake challenge (6:14) 2 Automated identity governance (8:33) 3 Empowering a culture of trust through identity strategy (12:20)Standout Quotes: 1 “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee  2 “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee 3 “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex BoveeRead the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

July 21, 2026Episode 34929 min

349: Steve Durbin – When Governments Shift: Reimagining UK Cyber Strategy and Business Resilience

Today, Steve returns to Business Matters with Juliette Foster. The United Kingdom has a new Prime Minister: Andy Burnham, and Steve speaks with Juliette from a cyber and business perspective about what to expect from the nation's new leadership. They also discuss the importance of digital inclusion, what businesses should do to remain in control in times of uncertainty, cyber insurance, and more. Key Takeaways: As more of world becomes digitally enabled, cyber becomes increasingly important from a national defense and resilience perspective.  More organizations are moving to scenario-based planning to manage uncertainty. Governments must understand the complexity of their large projects and make sure they’ve got the best people working on them. Tune in to hear more about: The importance of digital inclusion (4:17) Solving the cyber skills shortage (20:29) How cyber insurance is changing and why it matters (22:58) Standout Quotes: “For a lot of people, digital inclusion means handing people a smartphone and saying, “There you go.” It isn't just about access, it's about the knowledge that you need to actually make use of the technology that you have access to.” - Steve Durbin “You want to try to maintain a solid state in between somebody saying they're going to make the acquisition and take you over, and when that completes. [...] Because the resilience is core to the effectiveness going forward of that organization. All too often, there's a tendency to fiddle with it, play with it a little bit. No. We need to understand exactly what our core components are, the crown jewels, how are we protecting them, how are they going to be impacted over a certain period by any change that goes on, and what can we do to make sure that we're doing everything possible to preserve the integrity of those crown jewels so that we can continue to operate. The last thing you want is somebody coming in and actually changing that during a handover period.” - Steve Durbin “From a cyber-specific perspective, one of the things that has infuriated me constantly over the years is this obsession that we seem to have that people have to be trained in the technical skills in order to have a cyber career. That is absolute nonsense. Because the sorts of skills that you need could equally be well found with people with arts degrees. It's that curiosity. It's that ability to be able to be creative.” - Steve Durbin Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

July 7, 2026Episode 34828 min

348: Geoff White – Ransomware Is a Business and It's Competing Against You

In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack –  in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes. Key Takeaways: Ransomware attacks remain similar in strategy, but have become more industrialized in recent years.  Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors.  An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks.  Tune in to hear more about: Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33) The impact of AI on ransomware attacks (13:52) How money laundering is changing (17:03) Standout Quotes: “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

June 30, 2026Episode 34723 min

347: Alex Bovee – Identity in the Age of Agentic AI

In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around. Key Takeaways: Identity must be treated as a strategic risk.  When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice.  Choosing robust but user-friendly technology is important for attracting and retaining new talent.  Tune in to hear more about: The deepfake challenge (6:14) Automated identity governance (8:33) Empowering a culture of trust through identity strategy (12:20) Standout Quotes: “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee  “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

June 23, 2026Episode 34621 min

346: James Wilkson - The Human Factor: Leadership, Risk and the AI Era

Today, Steve speaks with James Wilkson, managing partner at AEC Global Search Consultants, an executive search and advisory firm. James and Steve discuss why today’s leaders must be flexible and emotionally intelligent, who belongs in today’s boardrooms, and how leaders can protect their personal brands online. Steve also asks James to look into the crystal ball.Key Takeaways: The most important trait for leaders today is flexibility. Today’s leaders must understand the technology they’re implementing in their organizations.  Almost everything you do is visible online today, so be careful and mind your behavior. Tune in to hear more about: Managing different generations in the workplace (4:18) How boards can upskill (12:31) What will surprise leaders a year from now (18:29) Standout Quotes: “I think AI, without a doubt is going to continue to accelerate and alter how we think, but just like anything else, it's just going to be an extremely robust tool down the line.” - James Wilkson “And leaders today, the leaders that are well-trained at being able to relate across generations and across technology are the ones that are going to continue being the leaders, and they're going to hone the next leadership team. The ones that are resistant and the ones that are frustrated, they're just not going to sustain leadership roles that much longer.” - James Wilkson “It's just a massive tsunami of discussion about AI and how it's going to change everything, and it is, but I think we're only going to briefly be led by this loss of work purpose, this loss of what... I think companies right now, the reason there's such a holdback on what do we do? We really slowed down hiring, are the entry level jobs all going to be gone? Yes, probably briefly because we're having a reaction, a knee-jerk reaction, but I think we're going to quickly find out that this is going to bring about a lot of different opportunity. So I think we'll plateau for a while, and then we'll begin utilizing humans in different roles that are still the same role that's just adapted itself to what technology has brought for us.” - James Wilkson Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

June 16, 2026Episode 34528 min

345: Stephanie Forbes - The $4.2 Trillion Problem: Why Boards Can't Afford to Ignore Supply Chain Fraud

Today, Steve sits down with Stephanie Forbes, CEO of the Forbes Group. Stephanie is a supply chain expert who recently released Global Wealth, Local Impact: How Supply Chains Build Thriving Companies, Cultures, and Countries, a book about building supply chains using lessons from our past. She and Steve discuss what she learned in her research for the book and supply chain management principles leaders can rely on in these unsteady times. Stephanie also gives advice for small and medium-sized businesses, how to manage supply chain issues across departments, and digital risk management. Key Takeaways: Frequent reviews of internal systems and supplier compliance are key to supply chain management in uncertain times.  We innovate and solve problems better when we work in teams and across departments, and it’s the leader’s job to enable and encourage such collaboration. Boards have the responsibility to ask questions and investigate whether their organizations are managing their supply chains as well and securely as they could.  Tune in to hear more about: What history teaches us about how we manage societies (2:08) How supply chains will change over the next five to ten years (10:25) The three questions boards should ask to secure their supply chains (25:58) Standout Quotes: “If I'm only a couple of people, 10 people, then I'm probably not going to bring in a full-scale audit unless I'm importing a lot of goods, unless I have a really big tariff bill, and then it's probably worth it for me to take a look at that. So you're going to want to cherry pick the things that are really important.” - Stephanie Forbes “It's going to become very difficult, I think, in another five, 10 years to buy anything that doesn't have a full life -cycle knowledge, awareness or paper trail. And that's gonna be all the way down to the ink or the physical ore, all that kind of stuff.” - Stephanie Forbes “The more as a leader in your organization that you can really encourage and foster that cross-functional collaboration between your operations and whether it's procurement, supply chain, even finance, to really make sure everyone's talking the same language, it becomes a huge competitive advantage, especially when things are changing so rapidly.” - Stephanie Forbes Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

June 9, 2026Episode 34420 min

344: Dustin Dobbyn - Train Like Your Life Depends on It: A SWAT Operator on Cyber Resilience

Today, Steve speaks with Dustin Dobbyn, an internationally recognized security expert, Marine Corps veteran, former SWAT operator, and the CEO of a fast-growing private security and executive protection firm. The two discuss management under pressure, the value of training and preparation, and awareness of supply chain risk. Dustin also makes the case for agility and flexibility in the workplace.  Key Takeaways: Physical security and cybersecurity are no longer separate arenas and organizations must realize all forms of security impact one another.  Intelligence is your greatest friend when building organizational resilience.  Work schedule flexibility can significantly improve productivity.  Tune in to hear more about: Securing all levels of your supply chain (8:15) A skill that veterans can bring to the cybersecurity industry (14:05) Dustin’s resilience roadmap for the next five years (18:02) Standout Quotes: “If you think you know it all, it's time to get out of the business.” - Dustin Dobbyn “So we're seeing, especially in the corporate world for corporate security, a lot of people working remote on a flex schedule, and we're seeing a lot more productivity because of it. For leadership out there who's listening, absolutely just take that into consideration, as sometimes people work better at certain times of the day based on their schedule. And if you can get them in an environment where they're less stressed, you're going to get better work output out of them.” - Dustin Dobbyn “Knowledge is power. Intelligence is what's going to keep you safe because if you have the intelligence, you're aware of what's going on, and you can prepare for worst-case scenarios.” - Dustin Dobbyn Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

June 2, 2026Episode 34328 min

343: Peter Hinssen - The New Never Normal: AI, the Future of Business and the Leaders We Need

Today, one of our favorite guests returns: Peter Hinssen. A renowned keynote speaker, author and serial entrepreneur, Peter is one of the most sought-after thought leaders on radical innovation, leadership and the impact of all things digital on society and business. When Peter was last on the show, the world had just begun to recover from the Covid-19 pandemic, and generative AI was still in its infancy. This time around, Steve and Peter talk about the advancements of AI and what they mean for the C-suite, whether the tech companies have become too powerful, AI regulation, and the future of leadership. Peter also answers how we will remember this AI boom in 10 years. Key Takeaways: This period of rapid change that we’re currently going through won’t pass, but rather become the new (never) normal. Regulators must rethink their approach to create frameworks for new technology that actually work. Headcount is no longer a key measure when it comes to a business’ success. Tune in to hear more about: How to manage this era of volatility and constant change (3:30) How leadership is changing (14:30) Why small businesses might be better equipped to deal with the AI boom (21:06) Standout Quotes: “We’re now in a world where the cycles move faster than ever before. The stakes are higher, and I think a lot of the instruments that we had from the past just don’t work anymore.” - Peter Hinssen  “The larger the company is, the more difficult it is to get that change going, and that’s why inherently smaller organizations have, I think, a competitive advantage because being agile, being nimble, and being resilient should be easier for a smaller company than a larger organization.” - Peter Hinssen “When you look at the printing press moment, we had the industrialization of knowledge, where we went from monks transcribing books into an abundance of information, and then we had the Industrial Revolution, where we went from muscle to machine. I think this is where the two of them are coming together.” - Peter Hinssen Read the transcript of this episodeSubscribe to the ISF Podcast wherever you listen to podcastsConnect with us on LinkedIn and TwitterFrom the Information Security Forum, the leading authority on cyber, information security, and risk management.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Business podcasts