mnemonic security podcast

mnemonic security podcast

Download on the App Store

mnemonic security podcast episodes

  • Smartphones

    What does mobile security mean in 2022? And what are defenders doing to keep the bad guys out of our pockets?

    To provide some insight into these questions, Robby has invited someone who has worked his entire career in Android security; Dario Durando, Android Malware Analyst at the Dutch security company ThreatFabric.

    During their conversation, they chat about the top attack vectors in this space, and Dario shares his thoughts about why mobile security isn’t getting more attention. They also go into specific mobile malware, and where the malware industry seems to be going next.

    Send us Fan Mail

    45 min
  • More Drones

    As a follow up from last week’s episode on the malicious use-cases of drones with Mario Bartolome Manovel, Robby chats with Pablo Ruiz Encinas, Security Consultant at mnemonic. He recently did a course on drone security – the Drone Security Operations Certificate (DSOC) by DroneSec - and hence has a lot to say on the subject.

    Pablo did not only bring with him his drone certification to the recording, but also had something that caught Robby’s eye; a Flipper Zero (a dolphin looking device, that markets itself as a portable multi-tool for pentesters). 

    So what does Flipper have to do with drones?

    (If you haven’t had the opportunity to listen to last week’s episode on Drone Security yet, we recommend you check that out first.)

    Send us Fan Mail

    16 min
  • Drones

    Drones: malicious use-cases and how to counteract them.

    As unmanned aerial vehicles (UAVs), or drones, are growing in popularity commercially, their use-cases are also growing in numbers. 

    To discuss them from a security professional’s view point, Robby has invited Mario Bartolome Manovel, Offensive Security Engineer at Telefonica. 

    Mario talks about how drones are regulated these days, their potentially malicious use-cases and how to counteract them.

    (And If you’re interested in seeing what the drones Mario has built look like, check out our video podcast at youtube.com/mnemonic).

    Send us Fan Mail

    31 min
  • Application Programming Interfaces

    Application Programming Interfaces (APIs)

    Why is Gartner predicting that API-based attacks will become the most frequent attack vector for applications? 

    Although APIs deserve the credit for a lot of digital transformation and innovation, they’re also an attractive target for bad actors. To explain how APIs are being used these days, and why they are getting more attention as an attack vector, Robby has invited Sunil Dutt from Salt Security.

    Sunil talks about the evolution of APIs, the techniques the attackers are using, as well as Salt’s approach to addressing the problem.

    Send us Fan Mail

    29 min
  • Industrial Security Conference

    From the 14th to the 16th of November, the annual Industrial Security Conference will take place in Copenhagen, Denmark. 

    Are you interested in Operational Technology and Industrial Control System security, and
    wonder what's going on in that part of our industry? Or just curious about the conference, and some of the speakers that will be there? Robby’s caught up with a few of them to get a sneak peak into what you can expect from their presentations and demonstrations during the conference.

    In this special edition episode, he chats with the following security professionals about what they’ll be speaking about at this year’s conference and why it’s important:

    • Søren Egede Knudsen, CEO and OT expert at Egede, “S***, we have factories in Russia”
    • Tibor Földesi, Security Analyst at Norlys, “Lessons learned in CTI land”
    • Ron Brash, VP of Technical Research & Integrations, aDolus Technology, “Doctor StrangeFormat: How I learned to be an archeologist for SBOMs”
    • Andrea Son, Headhunter, CSA CPH, "The biggest threat is a lack of competence - how is the situation in Denmark, and what can we do?"
    • Martin Scheu, Security Engineer, SWITCH-CERT, “Incident Response Training in Electrical Substations”
    • Dr. Maureen McWhite, Owner, 4Gen Consulting Services LLC, “Supply chain cybersecurity with an emphasis on the transportation sector”

    Find out more about the conference and the program here: https://insightevents.dk/isc-cph/program/ 

    Send us Fan Mail

    24 min
  • LinkedIn

    Securing LinkedIn

    For this episode, Robby welcomes the CISO, and VP of Engineering for LinkedIn, Geoff Belknap.

    Geoff has more than 20 years of experience in security and network architecture, and has previously also held the CISO positions at Slack and Palantir. 

    He shares some advice on navigating the security job market, and reflects on his role at LinkedIn, the challenges of his organisation, and the journey his team has been through the last few years.

    Send us Fan Mail

    35 min
  • Nordic Choice

    Lessons learned from a real incident: Nordic Choice Hotels

    What can we learn from the Nordic Choice Hotels supply chain attack of December 2021, and how it was handled?

    For this episode, we’re happy to welcome Kari Anna Fiskvik, Vice President Technology at Nordic Choice Hotels, that will share some of her lessons learned from being at the centre of attention as Nordic Choice had to shut their systems down at one of their most busy times of the year.

    Kari Anna has 20 years of experience with Tech, Digital Transformation, and Business Process and Strategy, and has been named one of the Top 50 Women in Tech 2022 in Norway. She shares with us how Nordic Choice reacted to the attack, what they were able to see of the threat actor from their side of things, and their considerations around balancing security and being service-minded and a customer-friendly organisation.

    Robby and Kari Anne also talk about the importance of a security partner, and communicating cybersecurity in a language that people understand.

    Sound engineering by Paul Jæger

    Send us Fan Mail

    30 min
  • TIBER

    Threat Intelligence-Based Ethical Red-teaming

    In most organisations, there’s more to security than preventive measures. This means that testing your capabilities within detection, investigation and containment can be just as relevant as looking at preventive capabilities. One way of doing so, is by following the Threat Intelligence Based Ethical Red-teaming (TIBER) framework, and simulating a real adversary and how you organisation would do against such a threat.

    To explain how a TIBER test is performed and it’s most common use-cases, Robby is joined by Stan Hegt, Etical hacker, Red teamer and Co-founder of the Dutch security company Outflank. Stan also shares his observations of the evolution of red teaming, the main differences between pentesting and red teaming, and what challenges they often meet when preforming these tests.

    A special thanks to Dennis Nuijens at Cqure for helping us to find our guest for this episode!

    Sound engineering by Paul Jæger

    Send us Fan Mail

    38 min
  • Security Leadership Essentials for Managers

    Security leadership essentials for managers

    What knowledge base should a CISO have? And what is the best approach to shaping the next generation of security leaders?

    Our guest today is better equipped than most to answer these questions. Frank Kim, former CISO of and currently a Fellow and Curriculum Director at SANS Institute, joins Robby to discuss leadership essentials for security managers.

    Frank shares how SANS and their classes approach teaching strategic leadership in security, and how this can help CISOs both navigate the politics in the boardroom and craft a business plan that makes sense for their entire organisation.

    They also discuss to whom security ultimately report to, and how to lead, motivate and inspire security teams to get their work done.

    Sound engineering by Paul Jæger

    Send us Fan Mail

    40 min
  • Zero Trust vs. Castle and Moat

    Zero trust vs. castle and the moat

    What does zero trust have to do with electric cars?

    For this episode, Robby is joined by Tony Fergusson CISO – EMEA at Zscaler. Tony has more than 25 years of experience in IT networking and security in Manufacturing, Information Technology and Financial Services, and even more importantly, he loves talking about zero trust – and has done so for more than a decade.

    Tony chats with Robby about his article “What IT can learn from Tesla about disrupting the status quo”, and why he believes the zero trust security model represents "an elegantly simple" path forward. They also talk about what the biggest obstacles to the zero trust model are, and why he thinks some people and companies are scared of the zero trust concept.

    Related reading: “Stop trying to make firewalls happen: What IT can learn from Tesla about disrupting the status quo“ https://revolutionaries.zscaler.com/insights/stop-trying-make-firewalls-happen-what-it-can-learn-tesla-about-disrupting-status-quo

    Sound engineering by Paul Jæger 

    Send us Fan Mail

    45 min

About mnemonic security podcast

From the publisher's feed

Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…

More shows like mnemonic security podcast

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Misjonen med Antonsen og Golden by P4-gruppen

Misjonen med Antonsen og Golden

84 Listeners

#pengepodden by Nordnet

#pengepodden

22 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

The Daily by The New York Times

The Daily

111,874 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,055 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Nasjonal sikkerhetsmyndighet (NSM) by Nasjonal sikkerhetsmyndighet (NSM)

Nasjonal sikkerhetsmyndighet (NSM)

1 Listeners

Nerdelandslaget by Nerdelandslaget // Acast

Nerdelandslaget

7 Listeners

MEDVIND by Alexis Barnekow

MEDVIND

0 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Prompt by DR

Prompt

3 Listeners

Only in America by RADIO IIII

Only in America

25 Listeners

Plattformpodden by Hans Kristian Flaatten og Audun Fauchald Strand

Plattformpodden

0 Listeners