CiberAfterWork: ciberseguridad en Capital Radio

CiberAfterWork: ciberseguridad en Capital Radio

By psanemeTechnology
Download on the App Store

CiberAfterWork: ciberseguridad en Capital Radio episodes

  • Episode 328: Cyber Icon 2026 and the challenges of a 360° strategy in the digital era
    This episode of Cyber Afterwork focuses on the presentation of Cyber Icon 2026, the fifth edition of the flagship cybersecurity event organized by Deloitte, which will take place on January 27 in Madrid. The guest, Xavi Gracia (Partner and Head of Cybersecurity at Deloitte), emphasizes the concept of cyber resilience, moving the conversation from how to prevent attacks to how organizations can effectively react and recover. A key technological highlight is the shift from Generative AI to Agentic AI, where autonomous agents can take real-time actions and decisions to counter sophisticated threats. The discussion also frames European regulations like DORA, NIS, and the Cyber Resilience Act (CRA) as strategic levers for business growth and transformation rather than just a compliance burden. Additionally, the episode reviews news regarding a massive data breach at the European Space Agency (ESA) and a local fraud case involving a car dealership, serving as a reminder that the perimeter no longer exists and every entity is a potential target. Finally, the experts provide advice on avoiding online scams during sales seasons, highlighting the importance of shared responsibility between users and banks in the fight against AI-enhanced phishing.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    45 min
  • Episodio 328: Cyber Icon 2026 y los desafíos de la estrategia 360 en la era digital
    Este episodio de Cyber Afterwork se centra en la presentación de la quinta edición del Cyber Icon 2026, un evento de referencia organizado por Deloitte que se celebrará el 27 de enero en Madrid para debatir sobre la ciberresiliencia y la colaboración en el ecosistema de ciberseguridad. A través de noticias como el ciberataque masivo a la Agencia Espacial Europea y estafas a pequeñas empresas, los ponentes subrayan que el riesgo es global y que la estrategia debe centrarse ahora en cómo reaccionar ante los incidentes. El invitado principal, Xavi Gracia, destaca el papel transformador de la Inteligencia Artificial agéntica en la toma de decisiones, la importancia de cumplir con marcos normativos como DORA y NIS como palancas de crecimiento, y los retos futuros de la criptografía post-cuántica. Finalmente, se ofrece una advertencia sobre fraudes online en época de rebajas, recordando la importancia de la responsabilidad compartida entre usuarios y entidades bancarias para prevenir el phishing y otros engaños potenciados por la IA.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    51 min
  • Interview Alfonso Muñoz and Dani García: their book "MCP Seguro"
    In this interview, Alfonso Muñoz and Dani García present their book "MCP Seguro," a technical guide focused on securing the Model Context Protocol (MCP), a specification launched by Anthropic to provide Large Language Models (LLMs) with extended capabilities, allowing them to interact with real-world tools and data. The authors warn that the current "fever" to integrate AI is leading many organizations to ignore security by design, resulting in critical vulnerabilities such as prompt injection, unpredictability, and the dangerous confusion between a model's reasoning and actual security authorization. To address this, they propose an approach based on common sense and technical rigor, recommending that security policies always remain outside the model, that defense-in-depth principles be applied, and that manual control mechanisms or "red buttons" be implemented to halt unexpected AI behavior.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    16 min
  • Entrevista Alfonso Muñoz y Dani García: presentan su libro MCP Seguro
    En esta entrevista, Alfonso Muñoz y Dani García presentan su libro "MCP Seguro", una guía técnica centrada en la securización del Model Context Protocol (MCP), una especificación lanzada por Anthropic para otorgar a los modelos de lenguaje (LLM) capacidades extendidas que les permiten interactuar con herramientas y datos del mundo real. Los autores advierten que la actual "fiebre" por integrar la inteligencia artificial está llevando a muchas organizaciones a ignorar la seguridad por diseño, lo que genera vulnerabilidades críticas como la inyección de prompts, la impredecibilidad de las respuestas y la peligrosa confusión entre el razonamiento del modelo y la autorización real de seguridad. Ante este escenario, proponen un enfoque basado en el sentido común y el rigor técnico, recomendando que las políticas de seguridad se mantengan siempre fuera del modelo, se apliquen principios de defensa en profundidad y se habiliten mecanismos de control manual o "botones rojos" para frenar comportamientos inesperados de la IA.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    35 min
  • Episode 327: Protecting the 'hands and feet' of artificial intelligence against emerging cyber threats
    This episode from early 2026 explores how cybersecurity and disinformation have become pillars of modern digital culture and geopolitics. The program highlights several key security incidents, such as the exposure of IDs and payment details at Endesa's Energía 21, an Instagram bug exploited by external actors to trigger massive password reset emails, and a critical vulnerability in the N8N automation software. The core discussion focuses on the Model Context Protocol (MCP), described by guests Alfonso Muñoz and Dani García as the "hands and feet" that allow Large Language Models (LLMs) to perform actions in the real world, such as managing databases or calendars. These experts warn that while MCP enables powerful integrations, it also introduces serious risks like prompt injection and the confusion of AI reasoning with proper authorization, highlighting the need for a "red button" to stop unintended actions. Finally, the episode emphasizes the importance of "security by design" and common sense, cautioning against the trend of adding unnecessary AI to every product and reminding listeners to stay alert against simple scams like fake QR code fines.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    45 min
  • Episodio 327: Securizando las "manos y pies" de la IA frente a las nuevas ciberamenazas
    En este episodio de inicios de 2026, se analiza cómo la ciberseguridad y la desinformación se han vuelto temas centrales en la cultura digital y geopolítica actual. El programa destaca noticias de impacto, como el compromiso de datos sensibles (DNI y medios de pago) en Energía 21 de Endesa, un fallo en Instagram que permitió el envío masivo de correos de reseteo de contraseñas por actores externos y una vulnerabilidad crítica en el software de automatización N8N. El tema central es la seguridad en la integración de la Inteligencia Artificial (IA) mediante el Model Context Protocol (MCP), contando con los expertos Alfonso Muñoz y Dani García, autores del libro "MCP Seguro". Los invitados explican que el MCP actúa como las "manos y pies" de los LLMs, permitiéndoles ejecutar acciones en el mundo real, como gestionar calendarios o bases de datos, pero advierten sobre riesgos graves como la inyección de prompts, la falta de autorización robusta y la necesidad de un "botón rojo" para frenar acciones imprevistas. Finalmente, se hace un llamado al sentido común y a la seguridad por diseño, alertando sobre la adopción apresurada de la IA en casos donde no es necesaria y la persistencia de fraudes básicos como las multas falsas con códigos QR.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    53 min
  • Interview Rafael Hernández- CEPSA
    In this interview, Rafael Hernández reflects on his 36-year career at Cepsa (now Moeve), detailing how cybersecurity has evolved from a purely technical industrial focus (OT) into a strategic pillar built on the balance of people, processes, and technology. He identifies digital identity as one of the greatest modern risks and notes the difficulty of convincing boards of directors to invest in prevention rather than just reacting to incidents. Hernández emphasizes that cybersecurity should be treated as a science rather than a creative "art," requiring rigorous standards similar to those found in industrial operations. A significant portion of the conversation highlights the Spanish cybersecurity community, specifically the ISMS Forum, which is characterized by a unique lack of competitiveness and a commitment to honest collaboration against a professionalized cybercrime industry that views data as its primary business. As he begins a new professional chapter, Hernández advises new generations to focus on security culture and the human factor, urging them to be patient and to integrate partners and manufacturers as essential components of the security ecosystem.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    15 min
  • Entrevista Rafael Hernández- CEPSA
    En esta entrevista, Rafael Hernández repasa su trayectoria de más de 36 años, principalmente en Cepsa (ahora Moeve), destacando la evolución de la ciberseguridad desde un ámbito puramente técnico e industrial (Mundo OT) hasta convertirse en un pilar estratégico basado en el equilibrio entre personas, procesos y tecnología. Hernández enfatiza que los mayores retos actuales residen en la identidad digital y la dificultad de concienciar a los consejos de administración sobre la inversión preventiva antes de que ocurran los incidentes, señalando que la ciberseguridad debe tratarse como una ciencia y no como un "arte" creativo. Durante el encuentro, varios colegas resaltan su papel como mentor y pionero, subrayando el valor de la comunidad de ciberseguridad en España —como el ISMS Forum—, la cual se caracteriza por una colaboración honesta, sin competitividad y centrada en el factor humano frente a un cibercrimen cada vez más profesionalizado que busca el negocio del dato. Finalmente, al iniciar una nueva etapa profesional, Hernández aconseja a las nuevas generaciones centrarse en la cultura de seguridad, ser pacientes e integrar a los partners y fabricantes como elementos esenciales para el avance del sector.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    37 min
  • Episode 326: Cybersecurity in the connected era
    This episode examines the challenges of our modern digital society, highlighting recent security incidents such as PayPal subscription scams, a major data breach fine for LastPass, and the geopolitical tensions surrounding a reported cyberattack on the Venezuelan oil company PDVSA. The program features a special interview with Rafael Hernández, the former head of cybersecurity at Cepsa, who reflects on his 36-year career and emphasizes that cybersecurity should be built on digital identity, rigorous processes, and common sense rather than just technology. The episode serves as a tribute to Hernández’s legacy, with various industry colleagues calling in to celebrate the collaborative and human spirit of the Spanish cybersecurity community. It concludes with practical privacy advice regarding the legal risks and potential fines for sharing Christmas dinner photos on social media without the consent of those pictured.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    40 min
  • Episodio 326: Ciberseguridad en la era conectada
    Este episodio analiza los desafíos de la sociedad digital actual, destacando noticias de ciberseguridad como las estafas de suscripciones falsas en PayPal, la cuantiosa multa a LastPass por una brecha de datos y las tensiones geopolíticas derivadas de un ciberataque a la petrolera venezolana PDVSA. El programa cuenta con la participación especial de Rafael Hernández, ex-responsable de ciberseguridad de Cepsa, quien reflexiona sobre sus 36 años de trayectoria, subrayando que la ciberseguridad debe basarse en la identidad digital, los procesos y el sentido común, más allá de la simple tecnología. Finalmente, el episodio rinde homenaje a la figura de Hernández mediante mensajes de colegas del sector, destacando el valor de la colaboración comunitaria, y concluye con consejos sobre la privacidad y los riesgos legales al compartir fotos de cenas de Navidad en redes sociales sin consentimiento.
    Twitter:
    @ciberafterwork
    Instagram:
    @ciberafterwork
    Panda Security:
    https://www.pandasecurity.com/es/
    +info:
    https://psaneme.com/
    https://bitlifemedia.com/
    https://www.vapasec.com/
    VAPASEC
    https://www.vapasec.com/
    https://www.vapasec.com/webprotection/
    53 min

About CiberAfterWork: ciberseguridad en Capital Radio

From the publisher's feed

Pablo San Emeterio y Mónica Valle acompañan a Eduardo Castillo en After Work para hablar sobre ciberseguridad con invitados y profesionales destacados del sector.

More shows like CiberAfterWork: ciberseguridad en Capital Radio

Nadie Sabe Nada by SER Podcast

Nadie Sabe Nada

402 Listeners