ISF Podcast podcast

S36 Ep14: Emerging Threats 2026

12/16/2025
0:00
28:08
Rewind 15 seconds
Fast Forward 15 seconds
Today, Steve looks toward the horizon, at the threats and challenges that enterprises and business leaders will face in 2026 and beyond. He also gives advice on how everyone, from the board to the practitioner, can meet these challenges, and answers some of the questions he’s received this year. 

Key Takeaways:
  1. Steve’s four key drivers of cyber risk heading into 2026 are AI, supply chain, quantum, and geopolitical instability.
  2. Crucial to cyber resilience are strong governance and a security-conscious culture.
  3. Adaptive governance and adaptive security are keys to managing the challenges of 2026 and beyond. 
Tune in to hear more about:
  1. Steve’s four key drivers of cyber risk heading into 2026 (2:23)
  2. Questions to ask, whether you’re a board member, an executive, or practitioner (16:14)
  3. The changing role of the board (18:54)
Standout Quotes:
  1. “ Resilience really needs an organizational wide holistic approach that takes technology, it takes governance, it takes operational readiness, and really importantly, it takes people into account.” - Steve Durbin
  2. “I think boards need to really take it upon themselves to absolutely recognize that cyber risk is a national risk. It is a business ending risk, and they need to ensure that they don't just have incident response and resilience in place, but that they also have a tried and tested plan, so this is good old fashioned BCP — business continuity planning — with a cyber flavor.” - Steve Durbin
  3. “Cyber risk reporting has to be business outcome oriented. Boards, business executives understand revenue, operations, customer impact, legal exposure. That's the way we have to be reporting cyber risk. It's not about how many attacks we repelled, it's not about how good our systems might be. You need to translate it into business language. If you can do that, not only will you get buy-in, but you'll also have a much richer conversation about the role that cyber and therefore cybersecurity and cyber resilience play in the business.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter

From the Information Security Forum, the leading authority on cyber, information security, and risk management.

More episodes from "ISF Podcast"