
Sign up to save your podcasts
Or


Security of things
“IoT security today is like what IT security was in the early 90s”.
This is how our returning guest introduces this episode’s topic; IoT security, and how it affects organisations and companies.
For the third time, Robby is joined by Brian Contos, serial security entrepreneur and now Chief Security Officer at Phosphorus Cybersecurity, a company providing IoT and OT defense solutions for enterprise customers.
Brian explains the meaning behind his not so uplifting statement above, and shares some of the most common IoT security issues they observe among their customers. He also discusses whether certain IoT devices pose a larger threat for organisations than others do, and why it’s so difficult for many organisations to create an inventory of their IoT devices.
Sound engineering by Paul Jæger
Send us Fan Mail
mnemonic, all government agencies and the majority of organisations in the security community advise against paying ransom to the criminal groups behind ransomware extortions. There are also legal considerations that need to be considered depending on the country or industry you are operating in.
There is however, a value in knowing more about how these criminal groups work. To shed some light on this, we’ve invited someone that often has been faced with the dilemma of whether or not to pay the ransom together with his clients; Rickey Gevers, Co-Founder of Responders B.V., a Dutch incident response company. These days most of the incidents he deals with are related to ransomware, and Rickey shares his experiences from negotiating with close to 30 ransomware groups on behalf of his clients – including also helping to pay them.
He shares his advice for how to prevent and prepare against ransomware threats. As well as what concerns most of his clients have when deciding how to deal with these groups, the main challenges they meet when negotiating with them, and how negotiating with ransomware groups requires a different approach than traditional negotiating tactics.
Sound production by Paul Jæger
Send us Fan Mail
Encrypted traffic management
TLS, SSL, HTTP, keys, authentication, clients, servers and ciphers - encryption is complicated.
To help shed some light on how enterprises can remove the "blind spot" of encrypted network communication, we’ve invited David Wells, co-founder of Netronome, who is a pioneer in the SSL/SSH inspection space.
David explains why being able to see and analyse encrypted traffic is necessary in order to gain full security value out of your network data, and shares his experiences since he inadvertently invented a tool for SSL inspection in 2003.
Technical level: 4/5
Sound engineering by Paul Jæger
Send us Fan Mail
What can we actually learn about cybercrime and what really goes on inside of criminal organisations from the Conti leaks?
This episode we welcome Sergey Shykevich, who has more than a decade of experience within threat intelligence and defence. He’s currently leading the threat intelligence research group in Check Point, and Robby has invited him to share his findings after examining the data leaks from the predominantly Russian-based double extortion group Conti.
The large data leak included more than 400 000 messages and access to internal forums providing information about everything from offices, bonuses and recruitment, to organisational structure, information flow, and whether or not members are aware of the fact that they’re working for a crime syndicate.
Produced by Paul Jæger
Send us Fan Mail
Send us Fan Mail
Control Validation & Cyber Insurance
How can private-sector cyber insurers accurately understand and price risk?
To discuss this and the critical role insurance can play in risk mitigation strategy, we’re joined by Levi Gundert, Senior Vice President of Global Intelligence at the cybersecurity company Recorded Future.
Levi shares from his vast experience from the industry, from previous roles as VP of Cyber Threat Intelligence at Fidelity Investments, Technical Leader at Cisco Talos, Principal Analyst at Team Cymru and US Secret Service Special Agent within the Los Angeles Electronic Crimes Task Force (ECTF).
He’s joining the podcast to discuss his recent paper “A New Cyber Insurance Model: Continuous Control Validation”, analysing the current state of the cyber insurance market and providing a new framework for insurers to evaluate risk.
Recommended reading: https://www.recordedfuture.com/new-cyber-insurance-model-continuous-control-validation/
Produced by Paul Jæger
Send us Fan Mail
For this episode, we’re welcoming Frank Fransen, Senior Scientist - Cyber Security, and Reinder Wolthuis, Senior Consultant and Program Manager - Cyber Security, from the Dutch not for profit research and consultancy organisation, TNO.
They joined Robby to talk about the SOCCRATES research project, where TNO, mnemonic and seven other European organisations are combining efforts to build a platform for security operations centres (SOCs) and incident response teams, to help them be more efficient, better detect attacks, and make the correct decisions on how to handle them.
The research project is part of the European Union's Horizon 2020 Research and Innovation program (https://www.soccrates.eu/), and aim is to produce a platform that will be as open-source as possible.
During their conversation, Frank and Reinder share why they saw the need for a platform like this, what it’s like to coordinate a project between public and private organisations, different expertise fields and across countries borders, and what the plan is for the upcoming pilot.
Produced by Paul Jæger
Send us Fan Mail
What caused a nation like Norway to become amongst the first pioneers of satellite-based communications?
To explore this, Robby is joined by Ronny Klavenes, CISO at Space Norway, a company building and investing in space related infrastructure, especially focusing on critical infrastructure. Space Norway was established on an initiative from The Norwegian Space Agency, a government agency promoting the development of national space activities. Among other things, Space Norway owns the underwater fibre optic cable between Svalbard and mainland Norway, a key element of Norway’s infrastructure in the Arctic.
Ronny explains why Norway cares about space infrastructure, and how one approaches securing infrastructure like this. He also shares what their threat landscape look like, and how their technology can be used to among other things monitoring earthquakes and ice blocks detaching from glaciers, search and rescue services, as well as collaborations with SpaceX.
Produced by Paul Jæger
Send us Fan Mail
Deception technology
Deception as an attack tactic has been used in many forms, for many years. Both on the battleground in the physical world, and in the digital sphere.
For this episode on deception technology, Robby is joined by Ofer Israeli, Founder & CEO of Illusive, a cybersecurity company aiming to remove the vulnerable connections that enable attackers to move undetected, and replace them with deceptive versions that reveal the attacker’s presence.
Ofer explains how he suggests moving away from a reactive mind-set to avoid always playing catch-up with attackers, how deception technology has evolved beyond honeypot-based approaches, and the importance of detection for this to succeed.
Produced by Paul Jæger
Send us Fan Mail
How does one of the world’s largest cybersecurity companies collect and share their Threat Intelligence?
For this episode, Ryan Olson, Vice President of Threat Intelligence (Unit 42) at Palo Alto Networks, joins Robby for a chat about Palo Alto Networks’ telemetry pool and how Threat Intelligence has evolved over the last decade.
His team, Unit 42, are responsible for collecting, analysing and producing intelligence for a large number of organisations worldwide, and Ryan shares what goes on in the Unit 42 team when an event like Log4shell occurs.
He also looks back at the major trends they observed in 2021, and what new adversary techniques and potential attack paths interests him the most these days.
Produced by Paul Jæger
Send us Fan Mail
From the publisher's feed
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across…
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.

651 Listeners

1,028 Listeners

84 Listeners

22 Listeners

317 Listeners

111,874 Listeners

8,055 Listeners

179 Listeners

1 Listeners

7 Listeners

0 Listeners

138 Listeners

3 Listeners

25 Listeners

0 Listeners