68 episodes
- Cybersecurity is entering a new era one shaped by autonomous AI attacks, machine speed defense and the looming impact of quantum computing.
In this episode, Francis Gorman speaks with Rik Ferguson, Vice President of Security Intelligence at Forescout, about why organisations must move from “assume breach” to “assume autonomy.” Rik explains the four conditions required for trusted autonomous defense: context, constraint, reversibility and transparency.
They also explore the risks of over-relying on AI in security operations, the importance of meaningful human oversight and why “harvest now, decrypt later” attacks make post-quantum readiness an urgent business priority.
Key Takeaways
AI is changing the operating model of cyberattacks.
The greatest shift is not simply that AI makes existing attacks faster. Autonomous systems may combine vulnerabilities and techniques in ways that do not reflect human logic or established attacker behaviour.
Defence cannot remain at human speed.
As attacks become increasingly automated, organisations will need defensive systems capable of detecting, containing and responding at machine speed.
Trust in autonomous security must be earned.
Rik identifies four essential conditions for trusted autonomy:
Context: Decisions must reflect the asset, its dependencies, its business importance and the wider environment.
Constraint: Autonomous actions must remain within clearly defined boundaries and guardrails.
Reversibility: Defensive interventions must be capable of being rapidly undone when they cause unintended consequences.
Transparency: Operators must understand why a decision was made, which data informed it and what the potential impact will be.
Human oversight must be meaningful.
Simply placing a person at the end of an automated process does not guarantee safety. Over-reliance on automation can reduce vigilance and leave people less capable of intervening when intervention matters most.
Paper we discussed during the episode: https://www.forescout.com/resources/wp-assume-autonomy/ - Stefan Pagels Christensen became a child star at 11, working on major film productions while most children his age were still figuring out who they were. Early fame brought attention, pressure and opportunity but it also distorted his sense of identity, value and belonging.
In this candid conversation, Stefan opens up about addiction, sobriety, ADHD and the experience that forced him to rebuild his life without status or recognition. He explains how discovering improvisation gave him a new way to understand failure, trust, communication and human connection.
Today, Stefan uses applied improv, emotional intelligence and psychological safety to help leaders create teams where people feel confident enough to contribute, challenge ideas, make mistakes and speak openly.
This is a conversation about what happens when the script disappears—and why the strongest leaders are not those with all the answers, but those who make the people around them better.
Key Takeaways
• Early success can shape self-worth in ways that take years to recognise and unlearn.
• ADHD can drive creativity, intensity and hyperfocus, but without the right support it can also contribute to burnout and destructive behaviour.
• Psychological safety begins with how leaders respond when someone speaks up, challenges an idea or makes a mistake.
• “Yes, and” does not mean agreeing with everything. It means listening fully before rejecting or building on an idea.
• Teams perform better when people stop judging themselves, stop judging others and become willing to experiment.
• Failure becomes valuable when it is treated as information rather than something to conceal.
• Great leadership is not about being the star of the scene. It is about making other people look good.
• Meaningful change begins when you stop blaming the environment and accept responsibility for your own behaviour.
Soundbites
“Leadership is improvisation. None of us knows exactly what comes next.”
“Success lies somewhere between doing nothing and failing.”
“Every time someone speaks up, they have already overcome their own fear.”
“Your job is not to be the star. Your job is to make other people look good.”
“Psychological safety is created by how you respond when someone gets it wrong.”
“You cannot change until you are willing to admit that something needs to change.”
“People do not learn courage by reading about it. They learn it by stepping forward.”
“Failure is not something to hide. It is something to recover from.”
“Say yes to the person before you judge the idea.”
“The strongest teams are not afraid of mistakes—they know how to use them.”
You can find Stefan at: https://improv.eu/
Find Stefan on LinkedIn: https://www.linkedin.com/in/stefanpagelsimprov/ - In this episode of the Entropy Podcast, Francis Gorman sits down with Darren Bender, a Texas-based attorney, chief legal officer, and co-founder working at the intersection of law, IT, and post-quantum cryptography.
The conversation explores a question many boards, legal teams, and security leaders are only beginning to face: when quantum computers threaten today’s encryption, who becomes liable for doing nothing?
Darren breaks down post-quantum negligence in practical terms, explaining why “we didn’t know” may not be a credible defence for much longer. From Harvest Now, Decrypt Later attacks to board minutes, data shelf life, migration timelines, DORA compliance, procurement decisions, and third-party liability, this episode reframes quantum readiness as more than a technical challenge.
It is a governance issue. A legal exposure issue. A fiduciary duty issue. And potentially, a future courtroom issue.
Key Takeaways
Post-quantum cryptography is no longer just a cybersecurity concern; it is becoming a boardroom and legal risk conversation.
Organisations may need to show how they assessed quantum risk, prioritised critical data, and documented informed decisions.
Board minutes, governance records, risk assessments, cryptographic inventories, and migration plans could become central evidence in future litigation.
“Cryptographic procrastination” may become difficult to defend if organisations knew about the risk but chose not to act.
The Mosca theorem helps boards think about whether their data shelf life plus migration time exceeds the timeline for a cryptographically relevant quantum computer.
The Learned Hand formula offers a legal lens for comparing the burden of prevention against the probability and magnitude of future harm.
Financial services, healthcare, energy, and critical infrastructure may be among the first sectors exposed to post-quantum liability.
DORA and similar regulatory frameworks may create either a defensive treasure trove or a litigation minefield, depending on the quality of the paper trail.
Supply-chain liability will be complex, with SaaS providers, cloud providers, HSM vendors, certificate authorities, and customers all potentially pulled into the same dispute.
Procurement teams should start asking not just whether vendors are secure today, but whether they can support post-quantum migration tomorrow.
Soundbytes
“Quantum risk is moving from the server room to the boardroom.”
“Harvest Now, Decrypt Later may become Harvest Now, Litigate Later.”
“The question is not just whether encryption breaks. It is who knew, who acted, and who documented the decision.”
“In a future lawsuit, the paper trail may matter as much as the technology.”
“Cryptographic procrastination is not a strategy.”
“Doing nothing may be the most expensive decision a board ever makes.”
“Post-quantum readiness is not a light switch. It is a long fuse with a big boom at the end.”
“If your data still has value when quantum arrives, your risk clock has already started.”
“DORA can be a treasure trove or a minefield. It depends what your records show.”
“Your vendors may hold the keys, but your organisation may still hold the liability.”
“Quantum readiness is no longer just about algorithms. It is about governance, accountability, and foreseeable harm.”
“The courtroom may become the place where quantum risk finally gets priced.” - In this episode, Francis Gorman speaks with Dinesh Nagarajan, Global Partner with IBM Consulting Cybersecurity Services and IBM’s global lead for data and AI security and quantum-safe security, about the collision of three major enterprise shifts: AI adoption, cryptographic modernisation, and post-quantum readiness. Dinesh argues that AI will likely be the most consequential transformation because securing AI at enterprise scale depends on trust, and that trust ultimately depends on cryptography.
The conversation explores why many organisations still treat AI security, cryptography, and quantum readiness as separate programmes, even though they are becoming deeply interconnected. Dinesh explains that AI has captured attention from the boardroom to engineering teams in a way few previous technology waves have, which gives it momentum, budget, and organisational visibility. But that same momentum creates risk if security, cryptographic resilience, and post-quantum planning are not built into transformation programmes early.
The discussion then moves into sovereign AI, geopolitical dependency, and the enterprise risk of building core workflows on platforms that may become unavailable due to political, regulatory, or commercial decisions. Dinesh frames this as a strategic consideration for businesses, especially when AI tools become central to software development, automation, and competitive advantage.
The second half of the episode focuses on post-quantum cryptography. Dinesh outlines how organisations should approach quantum readiness: start with awareness, assess exposure from the board level down, establish a centralised programme or centre of excellence, and embed post-quantum requirements into procurement, legal, supply chain, architecture, and existing digital transformation initiatives. His core message is that PQC is not a one-off technical remediation exercise; it is a multi-year business transformation that must be governed as a strategic risk.
Key takeaways
AI security is becoming a cryptography problem
AI at enterprise scale requires mechanisms to validate, verify, and trust agents, applications, and workflows. That trust layer depends on cryptography.
AI, crypto modernisation, and quantum readiness cannot stay separate
Many organisations currently treat them as three different programmes, but Dinesh expects them to converge quickly as AI infrastructure becomes dependent on cryptographic trust.
AI has unusual organisational momentum
Unlike previous technology waves, AI has captured attention from the C-suite down to engineers. That visibility can help fund and accelerate security work, including parts of the post-quantum journey.
Sovereign AI is becoming a serious boardroom issue
Enterprises need to consider what happens when a critical AI platform is restricted, withdrawn, or affected by geopolitical decisions.
Quantum readiness is not just an IT issue
PQC affects contracts, procurement, suppliers, cloud strategy, infrastructure, applications, data, and long-term transformation plans.
Boards need business-risk language, not cryptography language
Dinesh’s recommendation is to frame quantum exposure as strategic risk: revenue disruption, transformation risk, cost escalation, technical debt, and operational fragility.
The first move is not scanning; it is understanding exposure
Crypto inventory matters, but Dinesh argues the starting point should be a top-down view of how exposed the business model is to quantum-related disruption.
A centralised PQC capability is essential
Organisations need a programme team or centre of excellence that can create awareness, set direction, advise functions, and coordinate action across the enterprise.
Existing transformation programmes should pay the “quantum tax”
Rather than spinning up everything from scratch, organisations should embed PQC requirements into cloud migrations, digital modernisation, procurement cycles, and supplier renewals.
PQC is a five-to-six-year journey for many enterprises
Dinesh describes quantum readiness as a long-running transformation, not a vulnerability patching exercise.
Soundbites
These are polished for promotion and clips rather than strict verbatim transcript pulls.
“AI security is ultimately a trust problem and trust still comes back to cryptography.”
“The organisations that treat AI, crypto, and quantum as separate programmes are going to feel the collision later.”
“AI has done something unusual: it has captured the imagination of the boardroom and the engineer at the same time.”
“If every employee is going to use AI, then cryptography has to scale to that same level of adoption.”
“Post-quantum readiness is not a technology change. It is a business transformation.”
“The board does not need a lecture on algorithms. It needs to understand exposure, disruption, and strategic risk.” - In this episode of the Entropy Podcast, Francis Gorman speaks with Francesco Chiarini about why cyber resilience must go far beyond traditional cybersecurity, backups, and compliance checklists.
Francesco breaks down the uncomfortable reality that many organisations are not as recoverable as they think. From ransomware spreading at scale to compromised identity systems, encrypted tooling, failed assumptions, and board-level misunderstandings, this conversation explores what really happens when the worst-case cyber scenario becomes real.
The discussion covers cyber resilience versus cybersecurity, APT-grade attacks, out-of-band communications, crisis operating models, data vaulting, DORA, recovery planning, minimum viable organisations, and why resilience has to be designed before disaster strikes.
This is a direct, practical conversation about building organisations that can continue operating when the normal playbook no longer works.
Key Takeaways
Cyber resilience is not the same as cybersecurity. Cybersecurity focuses heavily on prevention and protection; cyber resilience asks whether the organisation can still operate, recover, and adapt when prevention fails.
Backups alone do not equal resilience. Francesco warns that recovery depends on architecture, governance, people, tooling, identity, sequencing, and validated operating models not just stored copies of data.
Organisations need to stress-test their assumptions of recoverability. If Active Directory, communications, patching tools, or recovery platforms are compromised, the real question is: what still works?
Boards often misunderstand resilience as a technology problem. Francesco argues that technology matters, but cyber resilience also requires clear accountability, capability maturity, skilled teams, and rehearsed decision-making.
Cyber recovery investment is often too low. Many organisations spend heavily on prevention, detection, and protection, while underinvesting in recovery capabilities and last-resort operating models.
Data vaulting and isolated recovery are essential, but incomplete on their own. They must sit inside a wider cyber resilience strategy that includes threat modelling, minimum viable operations, interoperability, deception, and recovery sequencing.
Soundbytes
“Your cyber recovery plan is only real if it still works when everything around it has failed.”
“Backups are not resilience. They are only one piece of the survival plan.”
“The worst time to design recovery is during the incident.”
“Cyber resilience starts where cybersecurity assumptions break.”
“If your identity stack, tooling, and communications are gone, what still works?”
“Being compliant does not mean being resilient.”
“Recovery is not just a technology problem. It is an organisational capability.”
“Most companies know how to prevent. Far fewer know how to restart.”
More Business podcasts
Trending Business podcasts
About The Entropy Podcast
Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for unfiltered conversations on the threats, complexity, and geopolitics shaping our world.Past guests include former senior CIA officers, leading cryptographers, digital forensics experts, and security and technology leaders from across financial services, critical infrastructure, and government, voices rarely heard together in one place.Each episode goes beyond headlines to explore how cyber risk, emerging technology, and geopolitical instability are reshaping the way organisations operate, compete, and defend themselves. Expect candid insight on quantum risk, nation-state threats, AI, espionage, financial crime, business resilience, and the human dimensions of leadership.Designed for CISOs, board members, founders, technologists, policy thinkers, and the professionally curious, Entropy sits at the intersection of business, technology, and cybersecurity a space for genuine conversations with unique minds, the kind that don’t fit neatly into a press release.The name Entropy reflects the growing complexity and unpredictability of the systems we depend on, and the discipline required to lead through them.Disclaimer: The views and opinions expressed on The Entropy Podcast are those of the host and guests in their personal capacity and do not represent the views, positions, or policies of their respective employers, affiliated organisations, or any government body. Guest appearances do not constitute endorsement by the host, and the host’s commentary does not constitute endorsement of guests’ views. Content is provided for informational and educational purposes only and does not constitute professional, legal, financial, or security advice.One of the topics I cover a lot on this show is post quantum readiness, I believe awareness of this emerging technology is key for a safer world into the future. To support this awareness I have built a free resource to help you explore the world of quantum and learn as you go. You can find it here: www.postquantumready.comBuy Our Swag:We now have some slick new swag you can purchase through our Esty store.https://theentropypodcast.etsy.com Watch and SubscribeYou can also watch full episodes and exclusive content on our YouTube channel:www.youtube.com/@TheEntropyPodcastAchievementsThe Entropy Podcast delivered strong chart performance throughout 2025, demonstrating consistent international reach and listener engagement.Regularly ranked within the Top 20 Technology podcasts in Ireland.Achieved a Top 25 placement in the United States Technology charts, holding the position for one week.Charted internationally across multiple markets, including Israel, Belgium, and the United Kingdom.This performance reflects sustained global interest and growing recognition across key podcast markets.Audio Quality NoticeSome episodes may feature minor variations in audio quality due to remote recording environments and external factors. We continuously strive to deliver the highest possible audio standards and appreciate your understanding.
Podcast websiteListen to The Entropy Podcast, James Reed: all about business and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


The Entropy Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.
































