The Entropy Podcast

The Entropy Podcast

By Francis GormanBusinessNewsTechnology
Download on the App Store

The Entropy Podcast episodes

  • Approachability, Empathy, and Security with Tracy Z. Maleeff

    In this episode of the Entropy Podcast, host Francis Gorman speaks with Tracy Z. Maleeff, a cybersecurity expert with a unique background in library science. Tracy shares her journey from being a librarian to transitioning into cybersecurity, emphasizing the importance of research skills and empathy in the field. She discusses the significance of open source intelligence and the need for digital literacy in today's information landscape. Tracy also highlights the role of storytelling in cybersecurity, advocating for a more human-centric approach to security practices. The conversation concludes with insights into current trends and concerns in cybersecurity, including the impact of AI and the importance of protecting journalistic integrity.

    Takeaways

    • Tracy transitioned from library science to cybersecurity for longevity.
    • Empathy and approachability are crucial in cybersecurity roles.
    • Open source intelligence (OSINT) is about gathering unclassified information.
    • Digital literacy is essential for navigating today's information landscape.
    • Storytelling can change behavior and improve cybersecurity awareness.
    • Research should be substantiated with credible sources.
    • Approachability encourages users to report security issues.
    • AI poses significant challenges in information accuracy.
    • Protecting journalists is vital for a free press.
    • Cybersecurity requires a human-centric approach.

    Sound Bites

    • "I made cybersecurity my quirky hobby."
    • "You need to have a research trail."
    • "The truth is out there."

    Connect with Tracy:

    https://sherpaintelligence.substack.com/

    38 min
  • Building Cyber Awareness with Craig Taylor

    In this episode of "The Entropy Podcast", host Francis Gorman speaks with Craig Taylor, CEO of CyberHoot, about the challenges and innovations in cybersecurity awareness training. They discuss the failures of traditional phishing awareness programs, the importance of positive reinforcement in training, and the role of gamification in engaging employees. Craig shares insights on the evolving threat landscape, particularly the impact of AI on phishing attacks, and highlights the vulnerabilities of small and medium enterprises (SMEs) to cyber threats. The conversation concludes with a look at the economics of cybercrime and the future of cybersecurity training.

    Takeaways

    • Most phishing awareness programs fail due to low engagement.
    • Traditional training methods show minimal behavioral change.
    • Positive reinforcement is more effective than punishment in training.
    • Gamification can significantly increase engagement in cybersecurity training.
    • SMEs are more likely to be targeted by cyber attacks than larger enterprises.
    • AI is being used to craft more sophisticated phishing attacks.
    • Cybercrime is now one of the largest economies in the world.
    • Effective training can lead to better client retention for MSPs.
    • Continuous improvement is key in cybersecurity awareness.
    • CyberHoot offers free access to individuals for training.

    Sound Bites

    • "Humans are the weakest link."
    • "Reinforced behaviors are repeated."
    • "AI is a game changer for hackers."

    Additional Information:

    Craig has arranged for Entropy Podcast listeners to receive a 20% discount on a one-year subscription to CyberHoot. You can access it using the coupon code: The Entropy Podcast. 

    CyberHoot Resources:

    • Main Website: https://cyberhoot.com/
    • Individual Registration (Free Personal Training for Life): https://cyberhoot.com/individuals/
    • Business Registration (Direct Power Platform Signup): https://cyberhoot.com/businesses/
    • Reseller / MSP Registration (Partner Signup): https://nest.cyberhoot.com/partner-signup/
    • Newsletter Registration: https://cyberhoot.com/newsletter-signup/
    • Blog Articles: https://cyberhoot.com/blog/
    • Cybrary (Cybersecurity Library of Terms in Layperson language): https://cyberhoot.com/cybrary/
    34 min
  • Mastering Cybersecurity for Small Businesses with Paul Tracey

    In this episode, Paul Tracey, founder and CEO of Innovative Technologies, discusses the cybersecurity challenges faced by small and medium-sized businesses. He highlights the misconceptions about SME vulnerabilities, the importance of proactive security measures, and the impact of regulations like the NYS SHIELD Act. Paul also offers practical advice on protecting data while traveling and the evolving threats posed by IoT devices and AI.

    Takeaways

    • 43% of cyber attacks target SMEs. 
    • Phishing is the top entry point for attacks. 
    • No client has paid a ransom under Paul's watch. 
    • Early detection is crucial for cybersecurity. 
    • Training is key to reducing human error. 
    • Regular penetration tests are essential. 
    • IoT devices need better security measures. 
    • AI is both a threat and a defense tool. 
    • Compliance laws protect businesses. 
    • Proactive security measures are vital.
    36 min
  • OSINT Language as a Tool with Skip Schiphorst

    In this episode, Francis Gorman interviews Skip Schiphorst, an expert in Open Source Intelligence (OSINT) and language studies. They discuss the critical role of language skills in OSINT, the importance of understanding cultural naming conventions, and the methodologies for conducting multilingual research. Skip emphasizes the need for careful vetting of sources, especially in authoritarian contexts, and shares insights from his military experience that translate into the OSINT field. The conversation also touches on the use of AI and machine translation, the significance of motivation in language learning, and the broad applicability of OSINT across various sectors. Finally, Skip introduces upcoming free webinars aimed at providing foundational knowledge in OSINT methodologies.

    Takeaways

    • Language skills are a force multiplier in OSINT investigations.
    • Understanding naming conventions in different cultures is crucial for accurate research.
    • AI and machine translation should be used as tools, not crutches.
    • Methodology is key in multilingual research; keywords are essential.
    • Vetting sources and double-checking information is vital, especially in authoritarian contexts.
    • Military experience can provide valuable skills for OSINT work.
    • Motivation is the most important factor in learning a new language.
    • OSINT is applicable across various sectors, including law enforcement and business.
    • Language learning can be enhanced through movement and physical activity.
    • Free webinars can provide a great introduction to OSINT methodologies.

    Sound Bite

    "AI should be used as a tool, not a crutch."

    Information mentioned in episode:

    I-Intelligence also hosts free webinars, including the upcoming sessions on September 22nd and 26th 2025, which will introduce the basics of OSINT in foreign languages such as Russian, Arabic, and Chinese. Everyone is welcome to participate!
    Details: https://shorturl.at/jhjhS

    Beyond the classroom, Skip explores how movement can enhance language learning. He shares his dynamic, movement-based techniques on Instagram while learning Japanese:
    Follow him at https://www.instagram.com/skipmovestolearn/

    31 min
  • The Quantum Threat and Opportunity with Dr. Michele Mosca

    In this episode, Dr. Michele Mosca co-founder of the Institute for Quantum Computing, professor at the University of Waterloo, and leading voice in quantum safe cryptography, joins Francis Gorman to discuss the looming risks and opportunities of quantum computing.

    He explains how his early skepticism in the 1990s turned into conviction once quantum error correction was discovered, making scalable quantum computers a real possibility. Michele outlines his “Mosca’s theorem,” which frames the urgency of preparing for quantum threats: the time to migrate to quantum-safe cryptography must be shorter than the time it will take for adversaries to weaponize quantum computers.

    Key themes include:

    • Quantum timelines: From early doubts to today’s multi-platform race, he estimates a 10% chance of cryptographically relevant quantum computers within 5 years and 30% within 10.
    • Quantum risk: The greatest threat is to cryptographic trust, confidentiality, integrity, and authenticity of digital systems potentially destabilizing governments, finance, and infrastructure.
    • Cryptographic resilience: Organizations must adopt agility and long-term planning, building cryptographic inventories, migration strategies, and centers of excellence, rather than treating it as a lone CISO problem.
    • Lessons from Y2K and beyond: Unlike Y2K, the quantum threat won’t “break systems overnight” but will erode confidentiality and trust if not addressed early.
    • Positive opportunities: Quantum technologies also promise advances in materials, energy, healthcare, and new cryptographic tools, but only if societies prepare now.

    Michele closes by urging businesses and governments to act quickly, not out of fear, but to ensure resilience and position themselves to benefit from the quantum era.


    https://globalriskinstitute.org/publication/an-updated-methodology-for-quantum-risk-assessment/ 

    43 min
  • Beyond The Hype: AI, Quantum, and Blockchain with Marin Ivezic

    In this episode, Marin Ivezic , founder and CEO of Applied Quantum, discusses the implications of quantum technologies, particularly the potential threats posed by quantum computers to current cryptographic systems. He emphasizes the urgency for organizations to prepare for these threats through crypto agility and highlights the challenges of cryptographic procrastination. The conversation also explores the current state of artificial intelligence, its overhyped applications, and the risks of AI-driven disinformation. Finally, Marin shares insights on the evolving landscape of financial systems and the role of blockchain technology.

    Takeaways

    • Q-Day refers to the day quantum computers can break current cryptography.
    • Current dependence on cryptography makes the quantum threat significant.
    • We are not close to a quantum apocalypse yet.
    • Nation-states are likely harvesting data for future decryption.
    • Organizations need to prepare for quantum threats by 2030.
    • Crypto agility is essential for transitioning to quantum-safe cryptography.
    • Cryptographic procrastination is a challenge for decision-makers.
    • AI is powerful but faces obstacles in the West.
    • China's strategic approach to AI may give it an edge.
    • AI-driven disinformation poses a significant risk to society.


    Sound Bites

    • "Cryptographic procrastination is a real issue."
    • "China is much more strategic in AI deployment."
    • "AI allows scams to scale exponentially."
    35 min
  • Disruptions, Disinformation, and Defense with Dr. Pablo Breuer

    In this episode of The Entropy Podcast, host Francis Gorman sits down with Dr. Pablo Breuer, cybersecurity expert, retired U.S. Navy officer, and co-creator of the DISARM framework. The conversation dives into the looming post-quantum threat, the role of cyber operations in geopolitics, the rise of AI-driven disinformation, and the cultural shifts needed in cybersecurity practice. Pablo shares insights from his military career and explains why preparing for disruption now is critical for both governments and private industry.

    Takeaways:

    • Quantum Threats Are Real, But Not Immediate: The “crypto apocalypse” is likely a decade away, giving time for preparation with new encryption standards.
    • Cyber Is Geopolitical Power: From influencing elections to disrupting food supply chains, cyber touches every lever of national power.
    • Maslow’s Hierarchy of Cyber Needs: Security must be framed around basic human needs like food, shelter, and safety — not just industry sectors.
    • Disinformation Needs Structure: The DISARM framework helps organizations map how misinformation spreads and how to counter it.
    • AI & Deepfakes Demand New Thinking: Detecting “bad” won’t scale; we need to verify what’s “good” and authentic.
    • Culture Over Technology: Cyber teams must move from being the “department of no” to being racing brakes — enabling speed with safety.

    Sound Bytes:

    • “We’re probably 10 years before a crypto apocalypse.”
    • “Cyber touches every instrument of national power diplomatic, informational, military, and economic.”
    • “Don’t frame security by industry, frame it by Maslow’s hierarchy of needs.”
    • “Disinformation isn’t a silver bullet problem it’s a thousand-bullet problem.”
    • “Don’t be the department of no. Security should be like racing brakes, built to go fast, safely.”
    34 min
  • DORA the New Era of Accountability with Paul C Dwyer

    In this episode, cybersecurity expert Paul C Dwyer discusses the implications of the DORA regulation on digital resilience and operational accountability at the board level. He emphasizes the need for organizations to understand their responsibilities regarding cybersecurity and the importance of incident reporting and risk management. Paul also highlights the role of cryptography, the impact of AI on cyber warfare, and the geopolitical landscape of cyber threats. The discussion concludes with reflections on the influence of social media and the future of AI in cybersecurity.

    Takeaways

    • Digital resilience is about being prepared for incidents.
    • Board members must understand their legal responsibilities under DORA.
    • There are significant penalties for non-compliance with cybersecurity regulations.
    • Organizations need to validate their operational resilience strategies.
    • Cultural change is necessary for effective cybersecurity compliance.
    • Cryptography is a critical component of cybersecurity strategy.
    • AI is transforming the landscape of cyber warfare.
    • Geopolitical tensions are influencing cyber threat dynamics.
    • Social media can amplify misinformation and public unrest.
    • AI should be viewed as a tool for intelligence augmentation.

    Sound Bites

    • "DORA places responsibility at a board level."
    • "Leadership must understand ICT risks."
    • "Cyber threats are about control and power."
    40 min
  • The Copycat Problem Finding a Moat in AI with Daniel Yoo

    In this episode, Francis Gorman sits down with Daniel Yoo, founder and CEO of FinMate AI, to uncover the uncomfortable truths about the current AI boom. From the gold rush mentality driving rapid adoption to the hidden risks of liability, security gaps, and “copycat” startups, Daniel shares insider insights from building one of the first AI-powered note-taking tools specifically for financial advisors.

    If you’ve ever wondered whether AI is moving too fast, what risks companies are ignoring, or how regulation (and lack thereof) could shape the future, this conversation is one you can’t afford to miss.

    Soundbytes

    • "There’s a flood of money chasing AI and security isn’t even on the radar."
    • "Every advisor wants automation, but nobody wants to hold the liability."
    • "AI will become a commodity so how do you protect your moat?"
    • "Technology always promises progress, but rarely talks about fallout."
    • "The biggest danger isn’t hallucinations it’s humans blindly trusting AI."

    Takeaways

    • Why venture capital is fueling reckless AI development
    • The hidden liability risks every company faces when adopting AI
    • Why “human in the loop” is non-negotiable for financial applications
    • How copycat AI startups threaten innovation—and survival strategies
    • The overlooked cognitive and societal impacts of over-relying on AI
    • What the next phase of the AI market might really look like
    37 min
  • Enemy of the Algorithm with Chris Kubecka

    What happens when a 10 year old hacks into the U.S. government and grows up to defend nations from some of the most sophisticated cyberattacks in modern history?

    In this gripping episode, Chris Kubecka renowned cybersecurity expert and founder of HypoSec, joins us to reveal the raw, untold realities of digital warfare. From stopping a second wave of attacks on South Korea to battling Iranian disinformation networks, Chris brings deep operational insights and incredible personal stories to the mic.

    We explore:

    • How she thwarted an Iranian espionage plot and became a target of doxing and death threats
    • The inside story of the Shamoon cyberattack on Saudi Aramco, and how she helped bring a crippled oil giant back online
    • Why generative AI poses an urgent threat to privacy, truth, and global stability
    • The rise of “harvest now, decrypt later” in the post-quantum era

    Key Insights & Takeaways:

    • Why the next war won’t start with bombs but with wiped servers and weaponized information
    • The critical importance of encryption hygiene and preparing for post-quantum threats
    • Why AI-powered misinformation is undermining trust in everything from media to democracy
    • How aspiring ethical hackers can build real world skills and networks that matter
    • Why your water supply not your bank account might be the first casualty in a cyberwar

    With blunt honesty, dark humor, and unmatched expertise, Chris shows us what it really means to defend against invisible enemies in an increasingly hostile digital world.

    38 min

About The Entropy Podcast

From the publisher's feed

Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for…