We’re back with the second part of Steve’s appearance on John “Jock" Brocas’ podcast “Legal Owl”. Today, Steve and Jock discuss artificial intelligence, the global powers shaping the cyber landscape, and how to get lawyers, board members, and other non-technical business people to care about cyber resilience. Steve also gives some tips for law firms looking to beef up their cyber practices.
Key Takeaways:
- Bad state actors operate all over the world, and national cyber resilience efforts must reflect that reality.
- With AI’s rapid growth, good compliance training is more important than ever.
- Many law firms still don’t grasp the need for good cyber hygiene and resilience.
- AI and cyber (4:53)
- Steve’s tips for law firms looking to commit to a more robust cyber effort (18:10)
- Steve's advice for a law firm that's suffered a breach (21:33)
- “I think the best outcome for AI is humans working collaboratively with the tool. No doubt you can get things done a lot quicker. You can get to certain points, but that doesn't mean that you stop validating and switch off the brain. You need to be looking at these things and saying, "Okay, does that actually make sense?" And questioning. And I think the assumption that because it's AI, somehow it must be absolutely right. No, it's not at that point yet. My personal hope is that it never gets to that point.” - Steve Durbin
- “I always say that good security will result in good compliance. Compliance will not necessarily result in good security.” - Steve Durbin
- “If a law firm is breached, I would hope that they have run through their resilience testing beforehand. I would hope that they have run some cyber simulation exercises where they are ready to respond to that kind of thing. If they haven't, I would say they're being negligent.” - Steve Durbin
Read the transcript of this episode
Subscribe to the ISF Podcast wherever you listen to podcasts
Connect with us on LinkedIn and Twitter
From the Information Security Forum, the leading authority on cyber, information security, and risk management.