『ISF Podcast』のカバーアート

ISF Podcast

ISF Podcast

著者: Information Security Forum Podcast
無料で聴く

このコンテンツについて

The ISF Podcast brings you cutting-edge conversation, tailored to CISOs, CTOs, CROs, and other global security pros. In every episode of the ISF Podcast, Chief Executive, Steve Durbin speaks with rule-breakers, collaborators, culture builders, and business creatives who manage their enterprise with vision, transparency, authenticity, and integrity. From the Information Security Forum, the leading authority on cyber, information security, and risk management.263000 マネジメント マネジメント・リーダーシップ 出世 就職活動 経済学
エピソード
  • S35 Ep4: Yolanda Williams - Cyber on the Ground: Building Resilience in a Fragmented Landscape
    2025/06/24
    Today’s episode will focus on the challenges of the cyber landscape in the United States, as Steve sits down with Yolanda Williams, who is the Cybersecurity and Infrastructure Security Agency’s cyber security coordinator in the state of Florida. Steve and Yolanda dive deep into her work communicating cyber in a region where it for many isn’t top-of-mind and how state sovereignty and lack of standardisation between local stakeholders poses unique challenges. We hope that Yolanda’s many examples of successfully working with Floridians and stakeholders across the state will resonate with listeners across the US—and perhaps across the pond, too.

    Key Takeaways:
    1. Cyber leaders must possess the ability to shape their communication based on what the audience is looking for.
    2. Organisations are much more open to cyber advice today than they were five years ago.
    3. Look at the language in your contracts! Mistakes can prove costly from both a financial perspective and a cyber perspective.
    Tune in to hear more about:
    1. How cyber connects to physical security (3:25)
    2. The challenges of a lack of standardised guidelines or federal regulation (10:23)
    3. The importance of keeping local backups and not only use the cloud (18:24)
    Standout Quotes:
    1. “I hear a lot of people say, ‘dumb it down.’ But you don't want to dumb it down. You just want to make sure that you're tailoring it specifically. You may have technical folks who are looking for, okay, what was the ransomware? Who did it? Who deployed it? How was it deployed? What was the payload? All those types of things. And they want to get into the deep dive of it. A lot of individuals don't. I'll speak to healthcare individuals and they're more looking at ‘I'm not a target. I'm a small doctor's office. I'm not a target.’ And one of the things we try to get across to everyone is: you are definitely a target. If you have a US IP address, you are a target.” - Yolanda Williams
    2. “There are federal guidelines for federal agencies. However, we respect our states and their sovereignty, and one of the things I found in Florida definitely was a lack of collaboration. Even from the city to the county, there's nothing structured across the board.” - Yolanda Williams
    3. “One of the steps that I recommend across the board for anyone that I'm talking to is looking at the language in your contracts, making sure that language is covering, not just what you're purchasing.[…] So making sure that you're looking at that contract language and have somebody that's looking at it that understands the lexicon, understands what is required. You can't just hire somebody off the street and say, ‘Oh yeah, write this contract,’ and they don't know what should be in the contract.” - Yolanda Williams
    Read the transcript of this episode
    Subscribe to the ISF Podcast wherever you listen to podcasts
    Connect with us on LinkedIn and Twitter

    From the Information Security Forum, the leading authority on cyber, information security, and risk management.
    続きを読む 一部表示
    21 分
  • S35 Ep3: The Silent Risk in M&A: Cyber Security Oversights That Cost Millions
    2025/06/17
    Financial due diligence is common practice when companies merge or one business acquires another. Cyber security due diligence, however, is not quite as common. Yet, in a world where the threat landscape changes by the day and risk is growing increasingly complex, solid cyber security practices are more important than ever.

    Today, Steve and Tavia dig into this very topic, and, more specifically, what role cyber security has in a merger or an acquisition. How is a cyber security review done? Why are they important? How do we balance speed with thoroughness? How do we interpret the results? There’s a lot to dig into here.

    Key Takeaways:
    1. Cyber due diligence is paramount in a corporate acquisition or merger.
    2. Risks of not doing cyber due diligence include both financial and reputational.
    3. Cyber due diligence is a team game.
    Tune in to hear more about:
    1. Who should be responsible for conducting the cyber review (4:34)
    2. How organizations can build cyber into their due diligence process (14:05)
    3. Examples of where insufficient cyber due diligence proved costly (19:05)
    Standout Quotes:
    1. “You can't play a team sport without a team. And for me, M&A is a team game. You can't go it alone. I think it would be a mistake for somebody to think that they could do this kind of work solo. Because as we've seen with cyber maturing, it now touches so many different parts of the organization. You do need to be involved.” - Steve Durbin
    2. “I think people are getting it. What I'm seeing now is people get it, but they don't know how to do it. That's where the cyber professional really now has to step up.” - Steve Durbin
    3. “Pre-deal, I think it is about being focused. It's about identifying, prioritizing the high risk areas that are out there that you want to look into. It's about doing things like making sure that the governance is there. It's about scanning for some of the known vulnerabilities. If you are in one particular market sector and you're buying a company in another because of expansion growth, you're going to need to be covering off a whole range of different things that perhaps might be unusual for you because you haven't been having to look into those areas.” - Steve Durbin
    Read the transcript of this episode
    Subscribe to the ISF Podcast wherever you listen to podcasts
    Connect with us on LinkedIn and Twitter

    From the Information Security Forum, the leading authority on cyber, information security, and risk management.
    続きを読む 一部表示
    34 分
  • S35 Ep2: Lauren Farina - Rest After Stress: The Psychology of High Performance
    2025/06/10
    Today, Steve speaks with Lauren Farina, psychotherapist and founder of Invited Psychotherapy & Coaching. Lauren and Steve discuss how wellness is becoming a bigger part of the workplace and how we can stay mentally healthy during times of stress and pressure. Also an expert on “high-performance individuals,” Lauren shares what it means to be high-performing and why rest can be just as productive as work.

    Key Takeaways:
    1. Being a high-performer isn’t just about work.
    2. Rest is productive
    3. Building psychological safety within an organization is the most important contributor to elite performance.
    Tune in to hear more about:
    1. What the “High Performer Archetype” is (6:15)
    2. The risks of not taking time to rest (11:22)
    3. How leaders can improve the performance of their teams (19:33)
    Standout Quotes:
    1. “ As many of us know, acute stress is quite good for us. But in the long term, the chronic unrelenting demands that I think remote working arrangements have placed on the workforce, really can erode our performance because our cognitive functioning is not at its peak when we're chronically stressed, our memory, our learning, our judgment, our decision making is compromised.” - Lauren Farina
    2. “ There was a five -year study at Google called the Aristotle Project, and the Aristotle project found that psychological safety is the single most important factor when it comes to the elite performance of individuals and groups.“ - Lauren Farina
    3. “ It is my hope that there will be an increased focus on intersectionality of performance and wellbeing and increased support of individuals and groups in cultivating wellbeing. Not only for the sake of wellbeing, but also for the sake of peak performance.” - Lauren Farina
    Read the transcript of this episode
    Subscribe to the ISF Podcast wherever you listen to podcasts
    Connect with us on LinkedIn and Twitter

    From the Information Security Forum, the leading authority on cyber, information security, and risk management.
    続きを読む 一部表示
    27 分

ISF Podcastに寄せられたリスナーの声

カスタマーレビュー:以下のタブを選択することで、他のサイトのレビューをご覧になれます。