mnemonic security podcast

mnemonic security podcast

Download on the App Store

mnemonic security podcast episodes

  • Kiss of Death

    What does a 30-year-old timekeeping protocol have to do with taking down a phone network? 

    In this episode of the mnemonic security podcast, Robby welcomes OT security specialist Mikael Vingaard back to the podcast to share some war stories from the world of industrial security. 

    They start off talking about the Network Time Protocol (NTP), a decades-old protocol that still plays a fundamental role in keeping systems synchronised. Mikael shares the story of how renting three servers in Albania accidentally made him one of the country's main sources of NTP traffic, and how shutting them down disrupted an ISP's IP telephony. They discuss what the story reveals about dependencies we may not even know exist, and what incorrect time can mean for industrial systems.

    They also explore configuration drift in OT environments, where small and often undocumented changes accumulate over long device lifecycles. Mikael shares findings from passive network assessments, including supposedly air-gapped networks that turned out to be connected and discusses how periodic verification can help organisations understand what is actually running in their environments.

    Finally, they discuss approaches to securely scanning OT environments, testing guardrails around AI and Denmark's push for digital sovereignty.

    Send us Fan Mail

    36 min
  • The Speed of Threat

    The speed of threat: Threat intelligence and detection engineering in the age of AI

    How can security teams shorten the time from identifying a cyber threat to having detection code live in production?

    In this episode of the mnemonic security podcast, Robby is joined by Nick Maeckelberghe, Co-Founder and Managing Director at Crimson7, which empowers organizations to find and fix their security weaknesses before attackers do, combining purpose-built platforms with expert-led managed services. Robby also welcomes Jeff Schiemann back to the podcast, now a Board Advisor at Crimson7.

    Nick and Jeff discuss how security teams can shorten the OODA loop, the time it takes to observe, orient, decide and act on a threat, with the ambition of going from understanding what an attacker is doing to having detection code live in production in a matter of hours.

    They explore what it takes to keep pace with attackers as new tools and techniques emerge, and how cyber threat intelligence (CTI) and detection engineering can work together to identify and stop threats at different stages of an attack campaign. They also discuss how LLMs and other forms of AI are changing cybersecurity on both sides of the equation, as attackers move faster and defenders look for ways to analyse threats and turn what they learn into detections at the same speed.

    The conversation also turns to some future-gazing: the rise of neoclouds, the concept of "headless security services" increasingly delivered by AI, and a potential shift from identity as the attack surface to trust as the attack surface. They discuss what these developments could mean for the security industry, and how customers will distinguish between good and average security vendors as AI takes on more of the work.

    Send us Fan Mail

    41 min
  • Norway's Ace: Space (live from Arendalsuka)

    Live episode: Why is Norway investing in space? (In Norwegian)

    This week, we’re bringing you a live recording of the mnemonic security podcast from Arendalsuka, Norway’s largest political gathering held every year in the town of Arendal. Here, Robby was joined by Ole Morten Olsen from the Norwegian Space Agency to discuss why Norway is investing in space from a strategic, security and economic perspective.

    What do we actually "sell from space", and which companies are involved? How dependent are we on satellites in our daily lives, and how will technologies like Starlink influence Norway's national preparedness in the years ahead?

    Check out this episode if you want to understand what Norway is actually doing in space, and why it matters. And perhaps we'll even get an answer to whether data centres in space are a realistic prospect!

    Send us Fan Mail

    47 min
  • The Asymmetric Future

    With or without agents, the cost of failure is asymmetric for attackers and defenders.

    An attacking agent that fails risks getting caught. A defending agent that fails risks taking down its own business.

    In this episode of the mnemonic security podcast, Robby is joined by Matteo Strada, a cybersecurity engineer and researcher specialising in AI security.

    Drawing on his blog post, The Asymmetric Future of AI and Cybersecurity, they explore the guardrail paradox exposed by the recent OpenAI–Hugging Face incident, the growing case for local and open-source models in the enterprise, and how much control companies are giving up when they build critical workflows on top of frontier AI models.

    https://mstrada.me/posts/aicybersec

    Send us Fan Mail

    27 min
  • OSINT

    In a world where images can be manipulated, eyewitnesses dismissed, and official accounts contradicted by what happened on the ground, proving what is real has never been more important.

    In this episode, Robby speaks with Vladimir Zaha, a threat intelligence researcher and volunteer contributor to the Bellingcat community, about the growing role of open-source intelligence in journalism, cybersecurity, conflict monitoring, and democratic accountability.

    Vladimir explains how OSINT investigators verify images and videos, geolocate events using seemingly insignificant details, monitor activity in active conflicts, and challenge false or misleading official narratives. He also discusses his work documenting civilian harm in Ukraine, investigating the actions of enforcement agencies in the United States, and helping analyse information that may eventually support legal proceedings.

    The conversation explores how OSINT can help cybersecurity professionals understand their threat environment, how artificial intelligence is changing the investigative process, and why human verification remains essential even as collection and analysis become increasingly automated.

    Send us Fan Mail

    44 min
  • Canaries and Deception Technology

    Why did the security industry stop talking about deception technology? And why should we start paying attention again?

    In this episode, Robby is joined by Andy Smith, CEO and Co-Founder of Tracebit, to discuss the evolution of deception technology and its role in modern security.

    Andy explains how organisations can deploy canaries, honey tokens and other deceptive resources in their environments to generate high-fidelity alerts when attackers move laterally, escalate privileges or attempt to access credentials and sensitive data. These alerts are designed to be both simple and highly reliable: if someone touches a fake resource, something suspicious is happening.

    The conversation explores modern deception techniques, what these look like when customers deploy them in their SOCs, how realistic decoys can be customised for different environments and the next generation of deception technology.

    Send us Fan Mail

    28 min
  • Everything Is Being Recorded

    In this episode of the mnemonic security podcast, we're joined by Joe Sullivan - former Chief Security Officer at Uber, Facebook, and Cloudflare, federal cybercrime prosecutor, and one of the most consequential figures in the history of the CISO role.

     

    The conversation explores the security implications of AI becoming part of everyday life, from AI note-takers to wearables and humanoid robots. Joe discusses the privacy, legal, and security challenges these technologies introduce, why organisations need clear policies and stronger governance to manage them, and how the role of the CISO is expanding as AI risk moves higher up the boardroom agenda.

    Send us Fan Mail

    39 min
  • Lay of the Land: How Attackers Move in '26

    The security world is a noisy place lately. What's actually going on in the trenches? 

    Candid Wüest, Principal Security Advocate at xorlab, joins Robby to cut through the hype and take a look at how attackers are actually operating in 2026.

    They open with a reference to their last discussion about LLM-infused malware, and touch upon using deception techniques such as honey tokens, fake password files and prompt injections to derail automated attackers. From there, they walk through the actual lay of the land: edge device exploits, credential abuse via infostealers, supply chain attacks targeting GitHub repositories, and why ClickFix social engineering is still working just as well as ever. They also dig into the growing connection between AI-assisted development and supply chain risk and what organisations should actually be doing about it.

    The episode closes on the bug bounty market, where AI is quietly disrupting the economics of responsible disclosure, and what that might mean for how vulnerabilities get reported, priced, and exploited going forward.

    Send us Fan Mail

    41 min
  • Auditing AI

    How do you audit machine learning models, and where do you start on your AI governance journey? 

    In this episode, Robby is joined by Gaute Brynildsen, Chief Audit Executive at Gjensidige, one of the leading Nordic insurance groups. Gjensidige has built a mature and tested approach to AI governance, and Gaute shares what they’ve learned along the way.

    Gaute explains how they went about auditing their in-house machine learning model trained solely on their own data, before expanding into broader governance across security, policies, roles, training, and risk. 

    He also covers where he recommends starting when building AI governance, highlighting the risks of shadow AI and how to monitor it, the importance of cloud competence and the value of an AI risk officer role.

    They also discuss the level of automation among organisations in the Nordics, exploring agentic agents, and whether it’s overhyped or the next real shift.

    Send us Fan Mail

    35 min
  • OpenClaw

    The AI agent everyone is talking about.

    In this episode of the mnemonic security podcast, Robby is joined by Marius Sandbu, fellow podcaster (CloudFirst Podcast and KI til Kaffen/AI with Coffee) and Cloud Evangelist at Sopra Steria. 

    Together, they dive into the potential of agentic technologies, as of now. In particular, they cover OpenClaw, the open-source autonomous AI agent that is one of the most popular repositories on GitHub right now.

    The conversation covers key risks, including remote control access, overly broad permissions and supply-chain concerns. As well as enterprise governance challenges, the need for policies and observability across different agent platforms.

    They both share what conversations they're having with customers and security teams these days, both with the "gatekeepers" and the "believers". 

    Send us Fan Mail

    33 min

About mnemonic security podcast

From the publisher's feed

Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…

More shows like mnemonic security podcast

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Misjonen med Antonsen og Golden by P4-gruppen

Misjonen med Antonsen og Golden

84 Listeners

#pengepodden by Nordnet

#pengepodden

22 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

The Daily by The New York Times

The Daily

111,874 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Nasjonal sikkerhetsmyndighet (NSM) by Nasjonal sikkerhetsmyndighet (NSM)

Nasjonal sikkerhetsmyndighet (NSM)

1 Listeners

Nerdelandslaget by Nerdelandslaget // Acast

Nerdelandslaget

7 Listeners

MEDVIND by Alexis Barnekow

MEDVIND

0 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Prompt by DR

Prompt

3 Listeners

Only in America by RADIO IIII

Only in America

25 Listeners

Plattformpodden by Hans Kristian Flaatten og Audun Fauchald Strand

Plattformpodden

0 Listeners