Podcast · Tech & Cybersécurité

ISF Podcast

By Steve Durbin, Chief Executive at Information Security Forum

Steve Durbin leads the Information Security Forum, a global authority on cyber risk and enterprise information security strategy for senior security executives worldwide.

ISF Podcast

⏱ 35 min read · Readable by ChatGPT, Gemini, Claude

▶ Listen to the podcast
What ISF Podcast covers

The ISF Podcast delivers strategic conversations with enterprise security leaders on the defining challenges facing modern organizations. Each episode brings rule-breakers and visionary thinkers who address cyber risk, trust frameworks, quantum-era resilience, and the human dimensions of high-stakes security leadership. The podcast positions itself at the intersection of technology, business strategy, and organizational culture—making it essential listening for decision-makers navigating digital risk at the C-suite level.

Key facts

Explore the full catalog of ISF Podcast episodes and latest interviews on Listenly.

What this podcast really covers

The ISF Podcast establishes a framework for understanding enterprise security as a leadership discipline, not merely a technical function. Episodes systematically explore how organizations align cyber risk management with business outcomes, organizational resilience, and competitive positioning. The podcast interrogates emerging threat vectors—ransomware models that operate as competitive business entities, quantum computing's implications for encryption and authentication, agentic AI and identity governance—but always through the lens of strategic leadership decision-making. Conversations with guests like Geoff White on ransomware economics, Eric O'Neill on zero-trust and identity-based perimeter models, and Alex Bovee on AI-driven identity present security not as an IT checkbox but as a business transformation imperative. The podcast also explores the psychological and cultural dimensions of security leadership—how high-performing teams operate under stress, how listening and communication rebuild trust, and how geopolitical shifts reshape national and corporate cyber strategy.

Who this podcast is essential for

Chief Information Security Officers (CISOs) and Chief Technology Officers (CTOs) form the primary audience. These executives must balance regulatory compliance, operational risk, and emerging threat landscapes while advocating for security investment and cultural change. For them, the podcast provides strategic context and peer perspectives on how other leaders are solving similar problems.

Chief Risk Officers (CROs) and enterprise risk committees benefit from the podcast's focus on how security integrates into broader organizational resilience and governance frameworks. The episodes on geopolitics, quantum computing, and business continuity directly inform risk appetite discussions and strategic planning cycles.

Legal, compliance, and business development leaders increasingly need to understand cyber and information risk. The episode on cyber risk in the legal industry demonstrates how the podcast translates security strategy into language relevant for non-technical stakeholders making business decisions that carry security implications.

What the episodes really reveal

The ISF Podcast's recent episode catalog reveals a consistent pattern: security leaders are moving beyond threat response toward systemic resilience. Recurring themes include the normalization of ransomware as a business model (not a crime), meaning enterprises must architect themselves to survive extortion rather than prevent it; the collapse of traditional perimeter security and its replacement by identity-based trust frameworks that assume compromise; the emergence of AI agents as an entirely new class of identity and access control challenge; and the recognition that geopolitics, quantum computing, and AI convergence create a new threat paradigm that existing playbooks cannot address. Another pattern surfaces in the summer listening archive episodes: the psychology and leadership dimensions of security excellence. Episodes on rest, stress recovery, and high-performance culture suggest that security leadership effectiveness depends as much on human factors—listening, authenticity, integrity—as on technology choices. This signals a maturation in how enterprise security thinks about itself: not as a technical fortress but as an organizational capability built on trust, culture, and strategic clarity.

What this changes in practice

For organizations listening to the ISF Podcast, the immediate implication is a shift in security investment priorities. If ransomware operates as a business and identity is the new perimeter, then resources must move from perimeter defense to identity resilience, deception, recovery planning, and cyber insurance. CISO conversations with boards and CFOs become fundamentally different: instead of "how do we prevent breach," the question becomes "how do we survive compromise and maintain business continuity."

Culturally, the podcast's emphasis on authenticity, listening, and psychological resilience reshapes how security teams attract, retain, and develop talent. Security is no longer a role for purely technical specialists but for leaders who understand organizational dynamics, communicate under uncertainty, and build coalitions across functions.

Strategically, organizations need to map emerging threat categories—agentic AI, quantum readiness, geopolitical cyber capabilities—into their multi-year roadmaps and test assumptions against the scenarios the podcast's guests outline. The podcast functions as an early-warning system and strategic forum, helping CISOs and boards think beyond annual threat reports and into the structural shifts reshaping the risk landscape.

Enterprise security is no longer a defensive technical domain but a strategic capability requiring cross-functional leadership, cultural alignment, and the ability to navigate uncertainty amid quantum computing, AI acceleration, geopolitical volatility, and a ransomware ecosystem operating as normalized business.

Dive deeper into security leadership perspectives by listening to all episodes of ISF Podcast.

The podcast answers these questions

Who should listen to this podcast?

Chief information security officers, chief technology officers, chief risk officers, and enterprise security leaders responsible for organizational resilience and cyber risk strategy should listen regularly. The podcast addresses the C-level perspective on emerging threats, business continuity, and security culture that informs executive decision-making.

What are the main topics covered in each episode?

Episodes cover ransomware-as-a-business economics, identity-based zero-trust frameworks, quantum computing and encryption resilience, AI and agentic identity management, geopolitical cyber strategy, organizational psychology and high-performance leadership, legal and regulatory cyber risk, and the integration of security with business outcomes. Each conversation emphasizes how security leaders translate emerging threats into organizational strategy.

How does this podcast differ from other security content?

Rather than focusing on technical threat analysis or incident response, the ISF Podcast emphasizes leadership perspectives, strategic decision-making, and the human and organizational dimensions of security excellence. The host speaks with practitioners and thought leaders about how they build resilience, navigate uncertainty, and drive organizational culture—not just technical defenses.

What is the Information Security Forum and why does its perspective matter?

The Information Security Forum is a globally recognized authority on cyber security, information security, and risk management, working with leading organizations worldwide to develop policies and best practices. Its Chief Executive hosting the podcast ensures that discussions are grounded in real-world enterprise experience and emerging industry standards.

ISF Podcast

Discover ISF Podcast

Steve Durbin · Information Security Forum

Listen to the podcast

Découvrir ISF Podcast sur Listenly →