Skip to content
PodcastsBusinessThe Entropy Podcast

The Entropy Podcast

Francis Gorman
The Entropy Podcast
Latest episode

66 episodes

  • The Entropy Podcast

    Harvest Now, Litigate Later Quantum Exposure with Darren Bender

    12/07/2026 | 45 mins.
    In this episode of the Entropy Podcast, Francis Gorman sits down with Darren Bender, a Texas-based attorney, chief legal officer, and co-founder working at the intersection of law, IT, and post-quantum cryptography.
    The conversation explores a question many boards, legal teams, and security leaders are only beginning to face: when quantum computers threaten today’s encryption, who becomes liable for doing nothing?
    Darren breaks down post-quantum negligence in practical terms, explaining why “we didn’t know” may not be a credible defence for much longer. From Harvest Now, Decrypt Later attacks to board minutes, data shelf life, migration timelines, DORA compliance, procurement decisions, and third-party liability, this episode reframes quantum readiness as more than a technical challenge.
    It is a governance issue. A legal exposure issue. A fiduciary duty issue. And potentially, a future courtroom issue.
    Key Takeaways
    Post-quantum cryptography is no longer just a cybersecurity concern; it is becoming a boardroom and legal risk conversation.
    Organisations may need to show how they assessed quantum risk, prioritised critical data, and documented informed decisions.
    Board minutes, governance records, risk assessments, cryptographic inventories, and migration plans could become central evidence in future litigation.
    “Cryptographic procrastination” may become difficult to defend if organisations knew about the risk but chose not to act.
    The Mosca theorem helps boards think about whether their data shelf life plus migration time exceeds the timeline for a cryptographically relevant quantum computer.
    The Learned Hand formula offers a legal lens for comparing the burden of prevention against the probability and magnitude of future harm.
    Financial services, healthcare, energy, and critical infrastructure may be among the first sectors exposed to post-quantum liability.
    DORA and similar regulatory frameworks may create either a defensive treasure trove or a litigation minefield, depending on the quality of the paper trail.
    Supply-chain liability will be complex, with SaaS providers, cloud providers, HSM vendors, certificate authorities, and customers all potentially pulled into the same dispute.
    Procurement teams should start asking not just whether vendors are secure today, but whether they can support post-quantum migration tomorrow.
    Soundbytes
    “Quantum risk is moving from the server room to the boardroom.”
    “Harvest Now, Decrypt Later may become Harvest Now, Litigate Later.”
    “The question is not just whether encryption breaks. It is who knew, who acted, and who documented the decision.”
    “In a future lawsuit, the paper trail may matter as much as the technology.”
    “Cryptographic procrastination is not a strategy.”
    “Doing nothing may be the most expensive decision a board ever makes.”
    “Post-quantum readiness is not a light switch. It is a long fuse with a big boom at the end.”
    “If your data still has value when quantum arrives, your risk clock has already started.”
    “DORA can be a treasure trove or a minefield. It depends what your records show.”
    “Your vendors may hold the keys, but your organisation may still hold the liability.”
    “Quantum readiness is no longer just about algorithms. It is about governance, accountability, and foreseeable harm.”
    “The courtroom may become the place where quantum risk finally gets priced.”
  • The Entropy Podcast

    When AI, Crypto, and Quantum Collide with Dinesh Nagarajan

    05/07/2026 | 35 mins.
    In this episode, Francis Gorman speaks with Dinesh Nagarajan, Global Partner with IBM Consulting Cybersecurity Services and IBM’s global lead for data and AI security and quantum-safe security, about the collision of three major enterprise shifts: AI adoption, cryptographic modernisation, and post-quantum readiness. Dinesh argues that AI will likely be the most consequential transformation because securing AI at enterprise scale depends on trust, and that trust ultimately depends on cryptography. 
    The conversation explores why many organisations still treat AI security, cryptography, and quantum readiness as separate programmes, even though they are becoming deeply interconnected. Dinesh explains that AI has captured attention from the boardroom to engineering teams in a way few previous technology waves have, which gives it momentum, budget, and organisational visibility. But that same momentum creates risk if security, cryptographic resilience, and post-quantum planning are not built into transformation programmes early. 
    The discussion then moves into sovereign AI, geopolitical dependency, and the enterprise risk of building core workflows on platforms that may become unavailable due to political, regulatory, or commercial decisions. Dinesh frames this as a strategic consideration for businesses, especially when AI tools become central to software development, automation, and competitive advantage. 
    The second half of the episode focuses on post-quantum cryptography. Dinesh outlines how organisations should approach quantum readiness: start with awareness, assess exposure from the board level down, establish a centralised programme or centre of excellence, and embed post-quantum requirements into procurement, legal, supply chain, architecture, and existing digital transformation initiatives. His core message is that PQC is not a one-off technical remediation exercise; it is a multi-year business transformation that must be governed as a strategic risk. 
    Key takeaways
    AI security is becoming a cryptography problem
    AI at enterprise scale requires mechanisms to validate, verify, and trust agents, applications, and workflows. That trust layer depends on cryptography. 
    AI, crypto modernisation, and quantum readiness cannot stay separate
    Many organisations currently treat them as three different programmes, but Dinesh expects them to converge quickly as AI infrastructure becomes dependent on cryptographic trust. 
    AI has unusual organisational momentum
    Unlike previous technology waves, AI has captured attention from the C-suite down to engineers. That visibility can help fund and accelerate security work, including parts of the post-quantum journey. 
    Sovereign AI is becoming a serious boardroom issue
    Enterprises need to consider what happens when a critical AI platform is restricted, withdrawn, or affected by geopolitical decisions. 
    Quantum readiness is not just an IT issue
    PQC affects contracts, procurement, suppliers, cloud strategy, infrastructure, applications, data, and long-term transformation plans. 
    Boards need business-risk language, not cryptography language
    Dinesh’s recommendation is to frame quantum exposure as strategic risk: revenue disruption, transformation risk, cost escalation, technical debt, and operational fragility. 
    The first move is not scanning; it is understanding exposure
    Crypto inventory matters, but Dinesh argues the starting point should be a top-down view of how exposed the business model is to quantum-related disruption. 
    A centralised PQC capability is essential
    Organisations need a programme team or centre of excellence that can create awareness, set direction, advise functions, and coordinate action across the enterprise. 
    Existing transformation programmes should pay the “quantum tax”
    Rather than spinning up everything from scratch, organisations should embed PQC requirements into cloud migrations, digital modernisation, procurement cycles, and supplier renewals. 
    PQC is a five-to-six-year journey for many enterprises
    Dinesh describes quantum readiness as a long-running transformation, not a vulnerability patching exercise. 
    Soundbites
    These are polished for promotion and clips rather than strict verbatim transcript pulls.
    “AI security is ultimately a trust problem and trust still comes back to cryptography.”
    “The organisations that treat AI, crypto, and quantum as separate programmes are going to feel the collision later.”
    “AI has done something unusual: it has captured the imagination of the boardroom and the engineer at the same time.”
    “If every employee is going to use AI, then cryptography has to scale to that same level of adoption.”
    “Post-quantum readiness is not a technology change. It is a business transformation.”
    “The board does not need a lecture on algorithms. It needs to understand exposure, disruption, and strategic risk.”
  • The Entropy Podcast

    Is Your Cyber Recovery Plan Just Fiction? with Francesco Chiarini

    01/07/2026 | 40 mins.
    In this episode of the Entropy Podcast, Francis Gorman speaks with Francesco Chiarini about why cyber resilience must go far beyond traditional cybersecurity, backups, and compliance checklists.
    Francesco breaks down the uncomfortable reality that many organisations are not as recoverable as they think. From ransomware spreading at scale to compromised identity systems, encrypted tooling, failed assumptions, and board-level misunderstandings, this conversation explores what really happens when the worst-case cyber scenario becomes real.
    The discussion covers cyber resilience versus cybersecurity, APT-grade attacks, out-of-band communications, crisis operating models, data vaulting, DORA, recovery planning, minimum viable organisations, and why resilience has to be designed before disaster strikes.
    This is a direct, practical conversation about building organisations that can continue operating when the normal playbook no longer works.
    Key Takeaways
    Cyber resilience is not the same as cybersecurity. Cybersecurity focuses heavily on prevention and protection; cyber resilience asks whether the organisation can still operate, recover, and adapt when prevention fails.
    Backups alone do not equal resilience. Francesco warns that recovery depends on architecture, governance, people, tooling, identity, sequencing, and validated operating models not just stored copies of data.
    Organisations need to stress-test their assumptions of recoverability. If Active Directory, communications, patching tools, or recovery platforms are compromised, the real question is: what still works?
    Boards often misunderstand resilience as a technology problem. Francesco argues that technology matters, but cyber resilience also requires clear accountability, capability maturity, skilled teams, and rehearsed decision-making.
    Cyber recovery investment is often too low. Many organisations spend heavily on prevention, detection, and protection, while underinvesting in recovery capabilities and last-resort operating models.
    Data vaulting and isolated recovery are essential, but incomplete on their own. They must sit inside a wider cyber resilience strategy that includes threat modelling, minimum viable operations, interoperability, deception, and recovery sequencing.
    Soundbytes
    “Your cyber recovery plan is only real if it still works when everything around it has failed.”
    “Backups are not resilience. They are only one piece of the survival plan.”
    “The worst time to design recovery is during the incident.”
    “Cyber resilience starts where cybersecurity assumptions break.”
    “If your identity stack, tooling, and communications are gone, what still works?”
    “Being compliant does not mean being resilient.”
    “Recovery is not just a technology problem. It is an organisational capability.”
    “Most companies know how to prevent. Far fewer know how to restart.”
  • The Entropy Podcast

    Why Artificial Intelligence Needs a Mother with Lucy Batley

    28/06/2026 | 39 mins.
    In this episode of The Entropy Podcast, Francis Gorman sits down with Lucy Batley AI strategist, speaker, and founder of Traction Industries, named number eight in the UK's Top 100 Digital Leaders in AI in 2025 (recognised at the House of Lords). With a 30-year career spanning the birth of the internet designing for David Bowie, Audi, Barclays and the Manic Street Preachers Lucy now helps organisations adopt AI strategically, with strong governance and real business value.
    This is a conversation about why most AI investment fails to deliver, why the real barrier sits in the boardroom rather than the technology, and why the rush to deploy AI agents without securing the underlying data is heading for a reckoning. Lucy also introduces Mother, her new venture building AI on quantum-resilient infrastructure and makes the case that the most underestimated risk isn't superintelligence, but our growing dependency on the tools themselves.

    Key Takeaways
    AI is a leadership problem, not a technology problem. The organisations that win aren't the ones with the biggest budgets they're the ones whose leaders have the foresight to grasp how fundamental this shift is.
    Start with the human problem, not the tool. Most organisations don't even understand their own workflow processes. Design thinking and relentless questioning surface the real issue which is often smaller and easier to fix than anyone expected.
    ROI comes from strategy, not spend. One case study: six "AI colleagues" deployed for ~£500k returned ~£6.5M in ten months driven by an opportunity spotted in a workshop, not the technology itself.
    Security can't be an afterthought. Homegrown AI agents going into organisations without secured data are a backlash waiting to happen. Secure by design from day one.
    Quantum changes the game. With "harvest now, decrypt later" already underway and ~300 quantum computers in existence, quantum isn't theory. Mother's approach moves from algorithms and code to mathematics and physics protecting data without touching it.
    The real risk is dependency. Societies don't collapse because technology gets clever they collapse because they forget how dependent they've become.
    Stay human. AI has no experience, no conscience, and no emotion. The advantage lies in the things that make us human and using the tools to amplify them.

    Soundbites
    "Artificial intelligence is not a technology problem, it's a leadership problem."
    "It's a technology so profound that everything else is going to have to be redesigned around it."
    "Forget about the technology — what human problems are you trying to solve?"
    "Societies rarely collapse because a technology becomes clever. They collapse because they become vulnerable."
    "Artificial intelligence needs a mother. It needs protecting."
    "We're moving away from algorithms and code to mathematics and physics. It's a completely different beast."
    "Good leader, good organisation. Bad leadership, absolute chaos."
    "We're literally in the toddler stage."
  • The Entropy Podcast

    SuperSkills for the AI Age with Rahim Hirji

    21/06/2026 | 41 mins.
    In this episode, Rahim Hirji discusses the evolving nature of intelligence, the importance of human skills in the age of AI, and how to adapt our education and mindset for the future. Discover insights on judgment, taste, curiosity, and the impact of AI on decision-making.

    This is one of those episodes that will have you questioning decisions you have made as your week unfolds. 
    Key Topics:
    The commodification of intelligence and its impact on value
    The importance of taste, judgment, and accountability in a world of abundant AI
    The concept of synthetic seniority and the blending of old and new wisdom
    Future skills needed for humans to thrive alongside AI
    The role of curiosity, boredom, and creativity in human development
    The risks of over-dependence on AI and algorithms
    Reimagining education to focus on soft skills and super skills
    The importance of questioning and understanding decision-making algorithms
    Practical self-assessment tools for future readiness
     Sound Bytes:
    "Taste, judgment, accountability are valuable now"
    "Talking to machines feels disingenuous"
    "Many decisions are made for us by algorithms"

    Check out the book: 
    https://superskillsbook.com/

    Check out the diagnostic tool:
    https://superskillsbook.com/diagnostic/

    Check out Rahim’s site:
    https://www.thesuperskills.com/
More Business podcasts
About The Entropy Podcast
Hosted by Francis Gorman, The Entropy Podcast brings together intelligence community veterans, post-quantum cryptography pioneers, CISOs, business leaders, and frontline practitioners for unfiltered conversations on the threats, complexity, and geopolitics shaping our world.Past guests include former senior CIA officers, leading cryptographers, digital forensics experts, and security and technology leaders from across financial services, critical infrastructure, and government, voices rarely heard together in one place.Each episode goes beyond headlines to explore how cyber risk, emerging technology, and geopolitical instability are reshaping the way organisations operate, compete, and defend themselves. Expect candid insight on quantum risk, nation-state threats, AI, espionage, financial crime, business resilience, and the human dimensions of leadership.Designed for CISOs, board members, founders, technologists, policy thinkers, and the professionally curious, Entropy sits at the intersection of business, technology, and cybersecurity a space for genuine conversations with unique minds, the kind that don’t fit neatly into a press release.The name Entropy reflects the growing complexity and unpredictability of the systems we depend on, and the discipline required to lead through them.Disclaimer: The views and opinions expressed on The Entropy Podcast are those of the host and guests in their personal capacity and do not represent the views, positions, or policies of their respective employers, affiliated organisations, or any government body. Guest appearances do not constitute endorsement by the host, and the host’s commentary does not constitute endorsement of guests’ views. Content is provided for informational and educational purposes only and does not constitute professional, legal, financial, or security advice.One of the topics I cover a lot on this show is post quantum readiness, I believe awareness of this emerging technology is key for a safer world into the future. To support this awareness I have built a free resource to help you explore the world of quantum and learn as you go. You can find it here: www.postquantumready.comBuy Our Swag:We now have some slick new swag you can purchase through our Esty store.https://theentropypodcast.etsy.com Watch and SubscribeYou can also watch full episodes and exclusive content on our YouTube channel:www.youtube.com/@TheEntropyPodcastAchievementsThe Entropy Podcast delivered strong chart performance throughout 2025, demonstrating consistent international reach and listener engagement.Regularly ranked within the Top 20 Technology podcasts in Ireland.Achieved a Top 25 placement in the United States Technology charts, holding the position for one week.Charted internationally across multiple markets, including Israel, Belgium, and the United Kingdom.This performance reflects sustained global interest and growing recognition across key podcast markets.Audio Quality NoticeSome episodes may feature minor variations in audio quality due to remote recording environments and external factors. We continuously strive to deliver the highest possible audio standards and appreciate your understanding.
Podcast website

Listen to The Entropy Podcast, The Martin Lewis Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features