The Entropy Podcast

The Entropy Podcast

By Francis GormanBusinessNewsTechnology
Download on the App Store

The Entropy Podcast episodes

  • Left of Boom The Intelligence Edge with Michael Freeman

    In this episode, Francis Gorman speaks with Michael Freeman, Head of Threat Intelligence at Armis, about his career path from working in U.S. intelligence and cryptography to co-founding the cybersecurity company CTCI. The discussion explores how Michaels approach to threat intelligence led to the early identification of significant vulnerabilities such as Log4j, sometimes months before they were publicly known.

    The episode covers:

    - Michaels background in crypto analysis and offensive security

    - His perspective on post-quantum cryptography and emerging risks

    - The founding and approach behind CTCI, including identifying active vulnerabilities before others in the industry

    - The challenge of false positives in commercial threat feeds

    - The importance of asset visibility and contextual vulnerability management

    - The role of AI in both enhancing cybersecurity operations and in aiding attackers

    - Michaels thoughts on modern election security, influence operations, and the broader geopolitical implications of technology

    - Risks of over-reliance on AI for critical thinking and decision-making

    The conversation emphasizes practical insights into how organizations can better understand and secure their environments in the face of rapidly evolving threats.

    37 min
  • From Frustration to Innovation Application Security with Francesco Cipollone

    In this episode of the Entropy Podcast, host Francis Gorman speaks with Francesco Cipollone, founder and CEO of Phoenix Security. They discuss the evolution of application security, the challenges faced in the industry, and the innovative approaches taken by Phoenix Security to address these issues. Francesco shares insights on the importance of collaboration between security teams and engineers, the role of AI in enhancing security measures, and the necessity of prioritizing vulnerabilities in a rapidly changing digital landscape. The conversation also touches on the reality of cybersecurity solutions and the need for organizations to adapt to new threats and technologies.

    Takeaways

    • Francesco Cipollone's journey to founding Phoenix Security.
    • The friction between security teams and engineering during cloud transformations.
    • The importance of gamifying security objectives at the business level.
    • AI can augment human capabilities but cannot replace them in decision-making.
    • Organizations must prioritize vulnerabilities effectively to keep pace with threats.
    • The need for a comprehensive understanding of application security beyond just tools.
    • The obsession with software bill of materials may distract from core security issues.
    • Collaboration between security and engineering is crucial for effective vulnerability management.
    • The rapid evolution of threats necessitates a proactive approach to security.
    • Understanding the fundamentals of security is essential for effective risk management.

    Disclaimer: The views and opinions expressed in this podcast are solely those of the host and guests, based on personal experiences. They do not represent facts and are not intended to defame or harm any individual or business. Listeners are encouraged to form their own opinions.


    34 min
  • Exploring Cybersecurity in Open Radio Access Networks with Mark Megarry

    In this episode, Francis Gorman interviews Mark Megarry, a PhD student specializing in 6G open radio access networks. They discuss Mark's journey into cybersecurity, the implications of 6G technology, and the security risks associated with open radio access networks. The conversation also covers the role of machine learning in future networks, the real-world consequences of insecure networks, and the importance of public speaking and community engagement in the cybersecurity field. Mark shares insights from his Capture the Flag competitions and emphasizes the need for resilience in network security.

    Takeaways

    • Mark transitioned from electronics to cybersecurity through hands-on experience.
    • Curiosity drives the field of cybersecurity and research.
    • 6G networks will focus on enabling new applications beyond just speed.
    • Security risks in open radio access networks often stem from misconfigurations.
    • Machine learning is becoming integral to the development of future networks.
    • Insecure networks can lead to serious privacy breaches and data theft.
    • Public speaking can be improved by sharing topics you are passionate about.
    • Community engagement is crucial for personal and professional growth in cybersecurity.
    • Capture the Flag competitions provide practical experience and learning opportunities.
    • Quantum security is a significant concern for future network specifications.
    30 min
  • Probing Low Carbon Electricity with Dr. James Merrick

    In this episode of the Entropy Podcast, Francis Gorman speaks with Dr. James Merrick about the challenges and opportunities in achieving low carbon electricity in Ireland and globally. They discuss Ireland's 2030 emissions reduction targets, the role of technology in addressing climate change, and the impact of agriculture on emissions. The conversation also explores the importance of small countries in leading climate initiatives, innovative projects in electrical systems, and the need for a rethinking of grid design to accommodate renewable energy sources. Finally, they touch on future innovations in energy generation and the translation of academic theory into practical solutions.

    Takeaways

    • Ireland's commitment to a 51% reduction in greenhouse gases is ambitious but may only achieve a 29% reduction.
    • Economic growth in Ireland has outpaced emissions reductions, showcasing a positive trend.
    • Decoupling economic growth from emissions is a significant achievement.
    • Small countries can show leadership in climate initiatives despite global challenges.
    • Agriculture's role in emissions is complex and requires nuanced understanding.
    • Technological advancements in agriculture can help reduce emissions.
    • The grid design needs to adapt to the increasing use of renewable energy sources.
    • Local energy solutions can mitigate the strain on the grid.
    • Nuclear power should be reconsidered as a viable option for decarbonization.
    • Innovative projects can lead to more efficient energy generation and consumption.
    34 min
  • Exploring Ethical AI with Louise McCormack

    In this episode of the Entropy Podcast, Francis Gorman speaks with Louise McCormack, a trustworthy AI consultant and PhD candidate, about the critical importance of trust in AI systems. They explore the ethical frameworks that govern AI, the implications of AI decision-making on society, and the need for transparency and accountability in AI technologies. The conversation delves into the potential dystopian future of AI, the impact of technology on human resilience and language, and the pressing issues of data privacy and consent in the digital age. Louise emphasizes the need for regulation and the societal responsibility to ensure that AI serves the public good rather than corporate interests.

    Takeaways

    • Trustworthy AI is defined by ethical frameworks and principles.
    • The AI Act aims to reinforce existing rights and protections.
    • There is a significant gap in understanding AI's implications.
    • Over-reliance on technology can diminish human resilience.
    • AI is changing the structure of language and communication.
    • Data profiling by private companies poses risks to democracy.
    • The impact of AI on society is poorly researched.
    • Transparency in AI algorithms is crucial for accountability.
    • Digital detox may be necessary in an AI-driven world.
    • Consent for data use needs to be revisited and regulated.
    36 min
  • The Evolving Threat Landscape with Chris Dale

    In this episode of the Entropy Podcast, host Francis Gorman speaks with Chris Dale, Chief Hacking Officer of River Security, about the dynamic and ever-evolving field of cybersecurity. They discuss the importance of penetration testing, the overlooked security risks companies face, and the role of offensive security in today's landscape. Chris shares valuable insights on how organizations can better prepare for cyber threats, the significance of education in the field, and the potential impact of generative AI on cybersecurity training. The conversation also touches on future challenges in cybersecurity, including the implications of geopolitical cyber warfare.

    Takeaways

    • Penetration testing is crucial for identifying vulnerabilities.
    • Reusing credentials across multiple services is a major risk.
    • Supply chain attacks are a growing concern in cybersecurity.
    • Offensive security plays a vital role in defense strategies.
    • Assuming a breach mindset is essential for organizations.
    • Network segmentation and least privilege are key security practices.
    • Education in cybersecurity needs to focus on timeless knowledge.
    • Generative AI can enhance understanding but has limitations.
    • Future cybersecurity challenges will involve AI-driven vulnerabilities.
    • Geopolitical tensions may lead to more sophisticated cyber warfare
    31 min
  • AI – Progress, Pitfalls, and Predictions with James "Jimmy" White

    In this episode of the Entropy Podcast, host Francis Gorman engages with Jimmy White, CTO and president of Calypso AI, discussing the evolving landscape of generative AI, the implications of new technologies like DeepSeek, and the current outlook around regulation in the AI sector. They explore the challenges of data integrity, the risks associated with AI-generated content, and the innovations in AI security. The conversation also touches on geopolitical pressures affecting AI development and predictions for the future of agent technology in the industry.

    Takeaways

    • Generative AI prompts should be direct and clear.
    • DeepSeek has both security concerns and hype surrounding it.
    • The US and EU are navigating a complex regulatory landscape.
    • Self-regulation in AI is becoming increasingly important.
    • Data integrity is crucial to avoid garbage in, garbage out.
    • Synthetic data can lead to poor decision-making in enterprises.
    • AI models are at risk of ingesting incorrect data.
    • The rise of agent technology will change the security landscape.
    • Companies need to be aware of the threats posed by generative AI.
    • The future of AI will require careful consideration of ethics and security.
    35 min
  • Bridging Safety and Security in Engineering with Dr. Bob Oates

    Discover the unexpected synergy between safety and security engineering as I chat with Dr. Bob Oates, Associate Director at Cambridge Consultants. Prepare to learn how these often considered distinct fields align in their ultimate mission to prevent harm. Bob takes us on an insightful journey, sharing insights across his distinguished career, Bob leverages a fantastic example of the groundbreaking project delivering the world’s first commercial remotely operated ship he worked on whilst with Rolls Royce to bring the topic to life. We also unravel the vital role of systems engineering in managing risks and ensuring seamless communication among diverse teams.

    Together, we explore the many considerations of safety and security in industries where the stakes are high, like shipping, aviation, and finance. We also speak around developments in post-quantum cryptography, to understand potential threats such as "harvest now, decrypt later" and the necessity of updating cryptographic practices. Bob and I emphasize the importance of preparing for these advancements, drawing parallels with safety systems to highlight the need for traceability and effective stakeholder communication. 

    Takeaways

    • Safety and security aim to prevent harm, whether accidental or malicious.
    • Quality is the foundation of both safety and security.
    • Systems engineering is crucial for connecting safety and security disciplines.
    • Remote operations introduce unique safety and security challenges.
    • Connectivity is a critical component for safety in remote systems.
    • The integration of safety and security can lead to complex design challenges.
    • Cryptography is essential for maintaining security in operational technology.
    • Quantum computing poses new threats to traditional cryptographic methods.
    • There is a skills shortage in both security and safety engineering fields.
    • Understanding the value of cryptography is vital for stakeholder engagement.
    32 min

About The Entropy Podcast

From the publisher's feed

Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for…