
Sign up to save your podcasts
Or


What does mobile security mean in 2022? And what are defenders doing to keep the bad guys out of our pockets?
To provide some insight into these questions, Robby has invited someone who has worked his entire career in Android security; Dario Durando, Android Malware Analyst at the Dutch security company ThreatFabric.
During their conversation, they chat about the top attack vectors in this space, and Dario shares his thoughts about why mobile security isn’t getting more attention. They also go into specific mobile malware, and where the malware industry seems to be going next.
Send us Fan Mail
As a follow up from last week’s episode on the malicious use-cases of drones with Mario Bartolome Manovel, Robby chats with Pablo Ruiz Encinas, Security Consultant at mnemonic. He recently did a course on drone security – the Drone Security Operations Certificate (DSOC) by DroneSec - and hence has a lot to say on the subject.
Pablo did not only bring with him his drone certification to the recording, but also had something that caught Robby’s eye; a Flipper Zero (a dolphin looking device, that markets itself as a portable multi-tool for pentesters).
So what does Flipper have to do with drones?
(If you haven’t had the opportunity to listen to last week’s episode on Drone Security yet, we recommend you check that out first.)
Send us Fan Mail
Drones: malicious use-cases and how to counteract them.
As unmanned aerial vehicles (UAVs), or drones, are growing in popularity commercially, their use-cases are also growing in numbers.
To discuss them from a security professional’s view point, Robby has invited Mario Bartolome Manovel, Offensive Security Engineer at Telefonica.
Mario talks about how drones are regulated these days, their potentially malicious use-cases and how to counteract them.
(And If you’re interested in seeing what the drones Mario has built look like, check out our video podcast at youtube.com/mnemonic).
Send us Fan Mail
Application Programming Interfaces (APIs)
Why is Gartner predicting that API-based attacks will become the most frequent attack vector for applications?
Although APIs deserve the credit for a lot of digital transformation and innovation, they’re also an attractive target for bad actors. To explain how APIs are being used these days, and why they are getting more attention as an attack vector, Robby has invited Sunil Dutt from Salt Security.
Sunil talks about the evolution of APIs, the techniques the attackers are using, as well as Salt’s approach to addressing the problem.
Send us Fan Mail
From the 14th to the 16th of November, the annual Industrial Security Conference will take place in Copenhagen, Denmark.
Are you interested in Operational Technology and Industrial Control System security, and
wonder what's going on in that part of our industry? Or just curious about the conference, and some of the speakers that will be there? Robby’s caught up with a few of them to get a sneak peak into what you can expect from their presentations and demonstrations during the conference.
In this special edition episode, he chats with the following security professionals about what they’ll be speaking about at this year’s conference and why it’s important:
Find out more about the conference and the program here: https://insightevents.dk/isc-cph/program/
Send us Fan Mail
Securing LinkedIn
For this episode, Robby welcomes the CISO, and VP of Engineering for LinkedIn, Geoff Belknap.
Geoff has more than 20 years of experience in security and network architecture, and has previously also held the CISO positions at Slack and Palantir.
He shares some advice on navigating the security job market, and reflects on his role at LinkedIn, the challenges of his organisation, and the journey his team has been through the last few years.
Send us Fan Mail
Lessons learned from a real incident: Nordic Choice Hotels
What can we learn from the Nordic Choice Hotels supply chain attack of December 2021, and how it was handled?
For this episode, we’re happy to welcome Kari Anna Fiskvik, Vice President Technology at Nordic Choice Hotels, that will share some of her lessons learned from being at the centre of attention as Nordic Choice had to shut their systems down at one of their most busy times of the year.
Kari Anna has 20 years of experience with Tech, Digital Transformation, and Business Process and Strategy, and has been named one of the Top 50 Women in Tech 2022 in Norway. She shares with us how Nordic Choice reacted to the attack, what they were able to see of the threat actor from their side of things, and their considerations around balancing security and being service-minded and a customer-friendly organisation.
Robby and Kari Anne also talk about the importance of a security partner, and communicating cybersecurity in a language that people understand.
Sound engineering by Paul Jæger
Send us Fan Mail
Threat Intelligence-Based Ethical Red-teaming
In most organisations, there’s more to security than preventive measures. This means that testing your capabilities within detection, investigation and containment can be just as relevant as looking at preventive capabilities. One way of doing so, is by following the Threat Intelligence Based Ethical Red-teaming (TIBER) framework, and simulating a real adversary and how you organisation would do against such a threat.
To explain how a TIBER test is performed and it’s most common use-cases, Robby is joined by Stan Hegt, Etical hacker, Red teamer and Co-founder of the Dutch security company Outflank. Stan also shares his observations of the evolution of red teaming, the main differences between pentesting and red teaming, and what challenges they often meet when preforming these tests.
A special thanks to Dennis Nuijens at Cqure for helping us to find our guest for this episode!
Sound engineering by Paul Jæger
Send us Fan Mail
Security leadership essentials for managers
What knowledge base should a CISO have? And what is the best approach to shaping the next generation of security leaders?
Our guest today is better equipped than most to answer these questions. Frank Kim, former CISO of and currently a Fellow and Curriculum Director at SANS Institute, joins Robby to discuss leadership essentials for security managers.
Frank shares how SANS and their classes approach teaching strategic leadership in security, and how this can help CISOs both navigate the politics in the boardroom and craft a business plan that makes sense for their entire organisation.
They also discuss to whom security ultimately report to, and how to lead, motivate and inspire security teams to get their work done.
Sound engineering by Paul Jæger
Send us Fan Mail
Zero trust vs. castle and the moat
What does zero trust have to do with electric cars?
For this episode, Robby is joined by Tony Fergusson CISO – EMEA at Zscaler. Tony has more than 25 years of experience in IT networking and security in Manufacturing, Information Technology and Financial Services, and even more importantly, he loves talking about zero trust – and has done so for more than a decade.
Tony chats with Robby about his article “What IT can learn from Tesla about disrupting the status quo”, and why he believes the zero trust security model represents "an elegantly simple" path forward. They also talk about what the biggest obstacles to the zero trust model are, and why he thinks some people and companies are scared of the zero trust concept.
Related reading: “Stop trying to make firewalls happen: What IT can learn from Tesla about disrupting the status quo“ https://revolutionaries.zscaler.com/insights/stop-trying-make-firewalls-happen-what-it-can-learn-tesla-about-disrupting-status-quo
Sound engineering by Paul Jæger
Send us Fan Mail
From the publisher's feed
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.

651 Listeners

1,028 Listeners

84 Listeners

22 Listeners

317 Listeners

111,874 Listeners

8,055 Listeners

179 Listeners

1 Listeners

7 Listeners

0 Listeners

138 Listeners

3 Listeners

25 Listeners

0 Listeners