
Sign up to save your podcasts
Or


We’re back with the second part of Steve’s appearance on John “Jock" Brocas’ podcast “Legal Owl”. Today, Steve and Jock discuss artificial intelligence, the global powers shaping the cyber landscape, and how to get lawyers, board members, and other non-technical business people to care about cyber resilience. Steve also gives some tips for law firms looking to beef up their cyber practices.
Key Takeaways:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
The tables turn in this episode, as Steve becomes the guest on “Legal Owl,” a podcast by John “Jock" Brocas, the executive coach whom you might remember from one of our shows earlier this year. In this first part of two, Steve tells Jock about how he got into cyber in the first place, and the two discuss the evolution of the cyber landscape. They also dive into why law firms must begin to think more about cyber risk and resilience.
Key Takeaways:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, ISF Chief Executive Steve Durbin talks with Dame Inga Beale, the former CEO of Lloyd’s of London, about the role that listening played when she became the first (and only) female CEO in Lloyd’s more than 300-year history. They also discuss the courage and effectiveness of simplicity in communication, a new style of leadership built on trust, and career advice for both board members and security professionals who are relatively new to the industry.
More about Lloyd’s of London.
Mentioned in this episode:
• Dive In Festival
• Read the transcript of this episode.
• Subscribe to the ISF Podcast wherever you listen to podcasts.
• Connect with us on LinkedIn and Twitter.
• From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve is joined by former FBI agent Eric O’Neill. Eric is a cyber security expert and author, but he’s probably most well-known as the man who brought down Peter Hanssen, a Russian spy who became one of the most notorious double agents in the history of US intelligence. Steve and Eric discuss cyber preparedness in today’s business world, insider threats, and cyber resilience in a rapidly changing world.
Key Takeaways:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve looks toward the horizon, at the threats and challenges that enterprises and business leaders will face in 2026 and beyond. He also gives advice on how everyone, from the board to the practitioner, can meet these challenges, and answers some of the questions he’s received this year.
Key Takeaways:
In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for criminal organizations. Today, Geoff comes on to talk about the latest installment in his podcast series The Lazarus Heist – now known as Cyber Hack – in which he dives deep into ransomware attacks. Steve and Geoff discuss the changing nature of ransomware attacks, how AI is used, crypto and ransomware laundering, and the importance of businesses having a plan to deal with an attack when it inevitably comes.
Key Takeaways:
1 Ransomware attacks remain similar in strategy, but have become more industrialized in recent years.
2 Crime groups utilizing ransomware view themselves as businesses. and view targets not as victims but as competitors.
3 An immediate, outright criminalization of paying ransoms is the wrong path forward, but if done in phases it can be the best way to solve the issue of ransomware attacks.
Tune in to hear more about:
1 Geoff’s investigation into Conti, one of the world’s most notorious ransomware gangs (7:33)
2 The impact of AI on ransomware attacks (13:52)
3 How money laundering is changing (17:03)
Standout Quotes:
1 “I think for defenders, the listeners of your podcast, understanding [ransomware] is a business and understanding you're not being attacked by a crime gang, you're being challenged by a business competitor, is a really interesting way of thinking about this. This is like a hostile takeover. The crime gangs do not think of themselves as hackers. They think of themselves as a business. Your security was weak, that's bad news for you, buddy. Our security, our technology was better, so you now have to pay us. It's effectively like a corporate raider mentality.” - Geoff White
2 “I think we're in a good place with cybersecurity, relatively speaking, where the defensive AI use is so strong and so well-funded and pumping so hard that make hay while the sun shines, get your AI defensive stuff in line, keep our advantage going, because I think the cybercrime gangs are a bit behind the curve there.” - Geoff White
3 “Let's imagine as a thought experiment,, the UK government tomorrow introduces legislation that says no more ransoms, illegal, enforceable by criminal law, illegal, criminally illegal to pay a ransom. Immediately you'll just be set with problems. Hospitals, there's points where hospitals to get the patients to survive would need to pay a ransom. Are you prepared to let people die because you don't want to pay a ransom?” - Geoff White
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve returns to Business Matters with Juliette Foster. In this conversation, Steve recaps 2025 in cyber and shares what he sees as the biggest risks heading into 2026. The two also discuss resilience and compliance, as well as the growing importance of togetherness among businesses.
Key Takeaways:
1 Companies would be wise to conduct frequent cyber audits.
2 Supply-chain disruptions can have long-lasting, reputational effects.
3 How we protect the integrity of our data is at the core of cybersecurity.
Tune in to hear more about:
1 The relationship between government business in cyber (12:56)
2 How boards should plan for a cyber attack (15:40)
3 Collaborating within and across industries (22:24)
Standout Quotes:
1 “I've said many times that good compliance doesn't equal good security, but good security does equal, nine times out of 10, very good compliance. So where do we go with all of that? I do think that we're probably getting to a point, sadly, where we need to be viewing some of the security processes that we need to undergo in the same way as we consider financial audits.” - Steve Durbin
2 “I think that the day is gone when you can rely on your defenses. So boards have to be planning for the day when the defenses fail. When an attack really starts to make an impact on your business. The starting point is to figure out how long you can be without your systems. It may sound like a strange thing to say, but that's the important starting point for me.” - Steve Durbin
3 “Security is not, in my opinion anyway, a competitive advantage. And because it's not a competitive advantage, there shouldn't be this massive barrier to sharing some of the ideas, some of the attacks that are out there for the good of the industry.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
In this episode, Steve speaks with Alex Bovee, co-founder and CEO of C1, a technology company focused on identity security online. Steve and Alex discuss why identity still often is an afterthought when businesses look at their risk profiles and how governance is changing as employees get access to more and more systems. Alex also shares his thoughts on how to translate identity management to board members and how to adapt technology so that it fits your team, not the other way around.
Key Takeaways:
1 Identity must be treated as a strategic risk.
2 When it comes to protecting your business against deepfakes, tried and true verification methods like MFA and multi-step approval processes remain best practice.
3 Choosing robust but user-friendly technology is important for attracting and retaining new talent.
Tune in to hear more about:
1 The deepfake challenge (6:14)
2 Automated identity governance (8:33)
3 Empowering a culture of trust through identity strategy (12:20)
Standout Quotes:
1 “I would say that most forward-thinking CISOs 100% view identity as one of the most important pillars in their company that they need to protect and secure.” - Alex Bovee
2 “There's different, I would say, classes of deepfake-type attacks. There's more of your broad-based social engineering type attacks, and I think one of the impacts of AI on that is that AI is able to do that at scale and in a very targeted way. I think we're gonna see a lot of asymmetry happening in those types of attacks. And then the second category is much more of your targeted attack, where you're trying to deepfake the CEO calling the CFO, asking for an immediate wire transfer to pay for something.” - Alex Bovee
3 “The best kind of security controls are the ones that are just in place that work, that are silent, and you don't know they're there, but they let you do your job.” - Alex Bovee
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
Today, Steve returns to Business Matters with Juliette Foster. The United Kingdom has a new Prime Minister: Andy Burnham, and Steve speaks with Juliette from a cyber and business perspective about what to expect from the nation's new leadership. They also discuss the importance of digital inclusion, what businesses should do to remain in control in times of uncertainty, cyber insurance, and more.
Key Takeaways:
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.
From the publisher's feed

2,279 Listeners

14,353 Listeners

817 Listeners

160 Listeners